xref: /freebsd/sys/fs/fdescfs/fdesc_vnops.c (revision 60fde7ce5d7bf5d94290720ea53db5701ab406a8)
1 /*-
2  * SPDX-License-Identifier: BSD-3-Clause
3  *
4  * Copyright (c) 1992, 1993
5  *	The Regents of the University of California.  All rights reserved.
6  *
7  * This code is derived from software donated to Berkeley by
8  * Jan-Simon Pendry.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  * 3. Neither the name of the University nor the names of its contributors
19  *    may be used to endorse or promote products derived from this software
20  *    without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32  * SUCH DAMAGE.
33  *
34  *	@(#)fdesc_vnops.c	8.9 (Berkeley) 1/21/94
35  *
36  * $FreeBSD$
37  */
38 
39 /*
40  * /dev/fd Filesystem
41  */
42 
43 #include <sys/param.h>
44 #include <sys/systm.h>
45 #include <sys/capsicum.h>
46 #include <sys/conf.h>
47 #include <sys/dirent.h>
48 #include <sys/filedesc.h>
49 #include <sys/kernel.h>	/* boottime */
50 #include <sys/lock.h>
51 #include <sys/mutex.h>
52 #include <sys/malloc.h>
53 #include <sys/file.h>	/* Must come after sys/malloc.h */
54 #include <sys/mount.h>
55 #include <sys/namei.h>
56 #include <sys/proc.h>
57 #include <sys/stat.h>
58 #include <sys/syscallsubr.h>
59 #include <sys/unistd.h>
60 #include <sys/vnode.h>
61 
62 #include <fs/fdescfs/fdesc.h>
63 
64 #define	NFDCACHE 4
65 #define FD_NHASH(ix) \
66 	(&fdhashtbl[(ix) & fdhash])
67 static LIST_HEAD(fdhashhead, fdescnode) *fdhashtbl;
68 static u_long fdhash;
69 
70 struct mtx fdesc_hashmtx;
71 
72 static vop_getattr_t	fdesc_getattr;
73 static vop_lookup_t	fdesc_lookup;
74 static vop_open_t	fdesc_open;
75 static vop_pathconf_t	fdesc_pathconf;
76 static vop_readdir_t	fdesc_readdir;
77 static vop_readlink_t	fdesc_readlink;
78 static vop_reclaim_t	fdesc_reclaim;
79 static vop_setattr_t	fdesc_setattr;
80 
81 static struct vop_vector fdesc_vnodeops = {
82 	.vop_default =		&default_vnodeops,
83 
84 	.vop_access =		VOP_NULL,
85 	.vop_getattr =		fdesc_getattr,
86 	.vop_lookup =		fdesc_lookup,
87 	.vop_open =		fdesc_open,
88 	.vop_pathconf =		fdesc_pathconf,
89 	.vop_readdir =		fdesc_readdir,
90 	.vop_readlink =		fdesc_readlink,
91 	.vop_reclaim =		fdesc_reclaim,
92 	.vop_setattr =		fdesc_setattr,
93 };
94 
95 static void fdesc_insmntque_dtr(struct vnode *, void *);
96 static void fdesc_remove_entry(struct fdescnode *);
97 
98 /*
99  * Initialise cache headers
100  */
101 int
102 fdesc_init(struct vfsconf *vfsp)
103 {
104 
105 	mtx_init(&fdesc_hashmtx, "fdescfs_hash", NULL, MTX_DEF);
106 	fdhashtbl = hashinit(NFDCACHE, M_CACHE, &fdhash);
107 	return (0);
108 }
109 
110 /*
111  * Uninit ready for unload.
112  */
113 int
114 fdesc_uninit(struct vfsconf *vfsp)
115 {
116 
117 	hashdestroy(fdhashtbl, M_CACHE, fdhash);
118 	mtx_destroy(&fdesc_hashmtx);
119 	return (0);
120 }
121 
122 /*
123  * If allocating vnode fails, call this.
124  */
125 static void
126 fdesc_insmntque_dtr(struct vnode *vp, void *arg)
127 {
128 
129 	vgone(vp);
130 	vput(vp);
131 }
132 
133 /*
134  * Remove an entry from the hash if it exists.
135  */
136 static void
137 fdesc_remove_entry(struct fdescnode *fd)
138 {
139 	struct fdhashhead *fc;
140 	struct fdescnode *fd2;
141 
142 	fc = FD_NHASH(fd->fd_ix);
143 	mtx_lock(&fdesc_hashmtx);
144 	LIST_FOREACH(fd2, fc, fd_hash) {
145 		if (fd == fd2) {
146 			LIST_REMOVE(fd, fd_hash);
147 			break;
148 		}
149 	}
150 	mtx_unlock(&fdesc_hashmtx);
151 }
152 
153 int
154 fdesc_allocvp(fdntype ftype, unsigned fd_fd, int ix, struct mount *mp,
155     struct vnode **vpp)
156 {
157 	struct fdescmount *fmp;
158 	struct fdhashhead *fc;
159 	struct fdescnode *fd, *fd2;
160 	struct vnode *vp, *vp2;
161 	struct thread *td;
162 	int error;
163 
164 	td = curthread;
165 	fc = FD_NHASH(ix);
166 loop:
167 	mtx_lock(&fdesc_hashmtx);
168 	/*
169 	 * If a forced unmount is progressing, we need to drop it. The flags are
170 	 * protected by the hashmtx.
171 	 */
172 	fmp = mp->mnt_data;
173 	if (fmp == NULL || fmp->flags & FMNT_UNMOUNTF) {
174 		mtx_unlock(&fdesc_hashmtx);
175 		return (-1);
176 	}
177 
178 	LIST_FOREACH(fd, fc, fd_hash) {
179 		if (fd->fd_ix == ix && fd->fd_vnode->v_mount == mp) {
180 			/* Get reference to vnode in case it's being free'd */
181 			vp = fd->fd_vnode;
182 			VI_LOCK(vp);
183 			mtx_unlock(&fdesc_hashmtx);
184 			if (vget(vp, LK_EXCLUSIVE | LK_INTERLOCK, td))
185 				goto loop;
186 			*vpp = vp;
187 			return (0);
188 		}
189 	}
190 	mtx_unlock(&fdesc_hashmtx);
191 
192 	fd = malloc(sizeof(struct fdescnode), M_TEMP, M_WAITOK);
193 
194 	error = getnewvnode("fdescfs", mp, &fdesc_vnodeops, &vp);
195 	if (error) {
196 		free(fd, M_TEMP);
197 		return (error);
198 	}
199 	vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
200 	vp->v_data = fd;
201 	fd->fd_vnode = vp;
202 	fd->fd_type = ftype;
203 	fd->fd_fd = fd_fd;
204 	fd->fd_ix = ix;
205 	if (ftype == Fdesc && fmp->flags & FMNT_LINRDLNKF)
206 		vp->v_vflag |= VV_READLINK;
207 	error = insmntque1(vp, mp, fdesc_insmntque_dtr, NULL);
208 	if (error != 0) {
209 		*vpp = NULLVP;
210 		return (error);
211 	}
212 
213 	/* Make sure that someone didn't beat us when inserting the vnode. */
214 	mtx_lock(&fdesc_hashmtx);
215 	/*
216 	 * If a forced unmount is progressing, we need to drop it. The flags are
217 	 * protected by the hashmtx.
218 	 */
219 	fmp = mp->mnt_data;
220 	if (fmp == NULL || fmp->flags & FMNT_UNMOUNTF) {
221 		mtx_unlock(&fdesc_hashmtx);
222 		vgone(vp);
223 		vput(vp);
224 		*vpp = NULLVP;
225 		return (-1);
226 	}
227 
228 	LIST_FOREACH(fd2, fc, fd_hash) {
229 		if (fd2->fd_ix == ix && fd2->fd_vnode->v_mount == mp) {
230 			/* Get reference to vnode in case it's being free'd */
231 			vp2 = fd2->fd_vnode;
232 			VI_LOCK(vp2);
233 			mtx_unlock(&fdesc_hashmtx);
234 			error = vget(vp2, LK_EXCLUSIVE | LK_INTERLOCK, td);
235 			/* Someone beat us, dec use count and wait for reclaim */
236 			vgone(vp);
237 			vput(vp);
238 			/* If we didn't get it, return no vnode. */
239 			if (error)
240 				vp2 = NULLVP;
241 			*vpp = vp2;
242 			return (error);
243 		}
244 	}
245 
246 	/* If we came here, we can insert it safely. */
247 	LIST_INSERT_HEAD(fc, fd, fd_hash);
248 	mtx_unlock(&fdesc_hashmtx);
249 	*vpp = vp;
250 	return (0);
251 }
252 
253 struct fdesc_get_ino_args {
254 	fdntype ftype;
255 	unsigned fd_fd;
256 	int ix;
257 	struct file *fp;
258 	struct thread *td;
259 };
260 
261 static int
262 fdesc_get_ino_alloc(struct mount *mp, void *arg, int lkflags,
263     struct vnode **rvp)
264 {
265 	struct fdesc_get_ino_args *a;
266 	int error;
267 
268 	a = arg;
269 	error = fdesc_allocvp(a->ftype, a->fd_fd, a->ix, mp, rvp);
270 	fdrop(a->fp, a->td);
271 	return (error);
272 }
273 
274 
275 /*
276  * vp is the current namei directory
277  * ndp is the name to locate in that directory...
278  */
279 static int
280 fdesc_lookup(struct vop_lookup_args *ap)
281 {
282 	struct vnode **vpp = ap->a_vpp;
283 	struct vnode *dvp = ap->a_dvp;
284 	struct componentname *cnp = ap->a_cnp;
285 	char *pname = cnp->cn_nameptr;
286 	struct thread *td = cnp->cn_thread;
287 	struct file *fp;
288 	struct fdesc_get_ino_args arg;
289 	cap_rights_t rights;
290 	int nlen = cnp->cn_namelen;
291 	u_int fd, fd1;
292 	int error;
293 	struct vnode *fvp;
294 
295 	if ((cnp->cn_flags & ISLASTCN) &&
296 	    (cnp->cn_nameiop == DELETE || cnp->cn_nameiop == RENAME)) {
297 		error = EROFS;
298 		goto bad;
299 	}
300 
301 	if (cnp->cn_namelen == 1 && *pname == '.') {
302 		*vpp = dvp;
303 		VREF(dvp);
304 		return (0);
305 	}
306 
307 	if (VTOFDESC(dvp)->fd_type != Froot) {
308 		error = ENOTDIR;
309 		goto bad;
310 	}
311 
312 	fd = 0;
313 	/* the only time a leading 0 is acceptable is if it's "0" */
314 	if (*pname == '0' && nlen != 1) {
315 		error = ENOENT;
316 		goto bad;
317 	}
318 	while (nlen--) {
319 		if (*pname < '0' || *pname > '9') {
320 			error = ENOENT;
321 			goto bad;
322 		}
323 		fd1 = 10 * fd + *pname++ - '0';
324 		if (fd1 < fd) {
325 			error = ENOENT;
326 			goto bad;
327 		}
328 		fd = fd1;
329 	}
330 
331 	/*
332 	 * No rights to check since 'fp' isn't actually used.
333 	 */
334 	if ((error = fget(td, fd, cap_rights_init(&rights), &fp)) != 0)
335 		goto bad;
336 
337 	/* Check if we're looking up ourselves. */
338 	if (VTOFDESC(dvp)->fd_ix == FD_DESC + fd) {
339 		/*
340 		 * In case we're holding the last reference to the file, the dvp
341 		 * will be re-acquired.
342 		 */
343 		vhold(dvp);
344 		VOP_UNLOCK(dvp, 0);
345 		fdrop(fp, td);
346 
347 		/* Re-aquire the lock afterwards. */
348 		vn_lock(dvp, LK_RETRY | LK_EXCLUSIVE);
349 		vdrop(dvp);
350 		fvp = dvp;
351 		if ((dvp->v_iflag & VI_DOOMED) != 0)
352 			error = ENOENT;
353 	} else {
354 		/*
355 		 * Unlock our root node (dvp) when doing this, since we might
356 		 * deadlock since the vnode might be locked by another thread
357 		 * and the root vnode lock will be obtained afterwards (in case
358 		 * we're looking up the fd of the root vnode), which will be the
359 		 * opposite lock order. Vhold the root vnode first so we don't
360 		 * lose it.
361 		 */
362 		arg.ftype = Fdesc;
363 		arg.fd_fd = fd;
364 		arg.ix = FD_DESC + fd;
365 		arg.fp = fp;
366 		arg.td = td;
367 		error = vn_vget_ino_gen(dvp, fdesc_get_ino_alloc, &arg,
368 		    LK_EXCLUSIVE, &fvp);
369 	}
370 
371 	if (error)
372 		goto bad;
373 	*vpp = fvp;
374 	return (0);
375 
376 bad:
377 	*vpp = NULL;
378 	return (error);
379 }
380 
381 static int
382 fdesc_open(struct vop_open_args *ap)
383 {
384 	struct vnode *vp = ap->a_vp;
385 
386 	if (VTOFDESC(vp)->fd_type == Froot)
387 		return (0);
388 
389 	/*
390 	 * XXX Kludge: set td->td_proc->p_dupfd to contain the value of the file
391 	 * descriptor being sought for duplication. The error return ensures
392 	 * that the vnode for this device will be released by vn_open. Open
393 	 * will detect this special error and take the actions in dupfdopen.
394 	 * Other callers of vn_open or VOP_OPEN will simply report the
395 	 * error.
396 	 */
397 	ap->a_td->td_dupfd = VTOFDESC(vp)->fd_fd;	/* XXX */
398 	return (ENODEV);
399 }
400 
401 static int
402 fdesc_pathconf(struct vop_pathconf_args *ap)
403 {
404 	struct vnode *vp = ap->a_vp;
405 	int error;
406 
407 	switch (ap->a_name) {
408 	case _PC_NAME_MAX:
409 		*ap->a_retval = NAME_MAX;
410 		return (0);
411 	case _PC_LINK_MAX:
412 		if (VTOFDESC(vp)->fd_type == Froot)
413 			*ap->a_retval = 2;
414 		else
415 			*ap->a_retval = 1;
416 		return (0);
417 	default:
418 		if (VTOFDESC(vp)->fd_type == Froot)
419 			return (vop_stdpathconf(ap));
420 		vref(vp);
421 		VOP_UNLOCK(vp, 0);
422 		error = kern_fpathconf(curthread, VTOFDESC(vp)->fd_fd,
423 		    ap->a_name, ap->a_retval);
424 		vn_lock(vp, LK_SHARED | LK_RETRY);
425 		vunref(vp);
426 		return (error);
427 	}
428 }
429 
430 static int
431 fdesc_getattr(struct vop_getattr_args *ap)
432 {
433 	struct vnode *vp = ap->a_vp;
434 	struct vattr *vap = ap->a_vap;
435 	struct timeval boottime;
436 
437 	getboottime(&boottime);
438 	vap->va_mode = S_IRUSR|S_IXUSR|S_IRGRP|S_IXGRP|S_IROTH|S_IXOTH;
439 	vap->va_fileid = VTOFDESC(vp)->fd_ix;
440 	vap->va_uid = 0;
441 	vap->va_gid = 0;
442 	vap->va_blocksize = DEV_BSIZE;
443 	vap->va_atime.tv_sec = boottime.tv_sec;
444 	vap->va_atime.tv_nsec = 0;
445 	vap->va_mtime = vap->va_atime;
446 	vap->va_ctime = vap->va_mtime;
447 	vap->va_gen = 0;
448 	vap->va_flags = 0;
449 	vap->va_bytes = 0;
450 	vap->va_filerev = 0;
451 
452 	switch (VTOFDESC(vp)->fd_type) {
453 	case Froot:
454 		vap->va_type = VDIR;
455 		vap->va_nlink = 2;
456 		vap->va_size = DEV_BSIZE;
457 		vap->va_rdev = NODEV;
458 		break;
459 
460 	case Fdesc:
461 		vap->va_type = (vp->v_vflag & VV_READLINK) == 0 ? VCHR : VLNK;
462 		vap->va_nlink = 1;
463 		vap->va_size = 0;
464 		vap->va_rdev = makedev(0, vap->va_fileid);
465 		break;
466 
467 	default:
468 		panic("fdesc_getattr");
469 		break;
470 	}
471 
472 	vp->v_type = vap->va_type;
473 	return (0);
474 }
475 
476 static int
477 fdesc_setattr(struct vop_setattr_args *ap)
478 {
479 	struct vattr *vap = ap->a_vap;
480 	struct vnode *vp;
481 	struct mount *mp;
482 	struct file *fp;
483 	struct thread *td = curthread;
484 	cap_rights_t rights;
485 	unsigned fd;
486 	int error;
487 
488 	/*
489 	 * Can't mess with the root vnode
490 	 */
491 	if (VTOFDESC(ap->a_vp)->fd_type == Froot)
492 		return (EACCES);
493 
494 	fd = VTOFDESC(ap->a_vp)->fd_fd;
495 
496 	/*
497 	 * Allow setattr where there is an underlying vnode.
498 	 */
499 	error = getvnode(td, fd,
500 	    cap_rights_init(&rights, CAP_EXTATTR_SET), &fp);
501 	if (error) {
502 		/*
503 		 * getvnode() returns EINVAL if the file descriptor is not
504 		 * backed by a vnode.  Silently drop all changes except
505 		 * chflags(2) in this case.
506 		 */
507 		if (error == EINVAL) {
508 			if (vap->va_flags != VNOVAL)
509 				error = EOPNOTSUPP;
510 			else
511 				error = 0;
512 		}
513 		return (error);
514 	}
515 	vp = fp->f_vnode;
516 	if ((error = vn_start_write(vp, &mp, V_WAIT | PCATCH)) == 0) {
517 		vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
518 		error = VOP_SETATTR(vp, ap->a_vap, ap->a_cred);
519 		VOP_UNLOCK(vp, 0);
520 		vn_finished_write(mp);
521 	}
522 	fdrop(fp, td);
523 	return (error);
524 }
525 
526 #define UIO_MX _GENERIC_DIRLEN(10) /* number of symbols in INT_MAX printout */
527 
528 static int
529 fdesc_readdir(struct vop_readdir_args *ap)
530 {
531 	struct fdescmount *fmp;
532 	struct uio *uio = ap->a_uio;
533 	struct filedesc *fdp;
534 	struct dirent d;
535 	struct dirent *dp = &d;
536 	int error, i, off, fcnt;
537 
538 	if (VTOFDESC(ap->a_vp)->fd_type != Froot)
539 		panic("fdesc_readdir: not dir");
540 
541 	fmp = VFSTOFDESC(ap->a_vp->v_mount);
542 	if (ap->a_ncookies != NULL)
543 		*ap->a_ncookies = 0;
544 
545 	off = (int)uio->uio_offset;
546 	if (off != uio->uio_offset || off < 0 || (u_int)off % UIO_MX != 0 ||
547 	    uio->uio_resid < UIO_MX)
548 		return (EINVAL);
549 	i = (u_int)off / UIO_MX;
550 	fdp = uio->uio_td->td_proc->p_fd;
551 	error = 0;
552 
553 	fcnt = i - 2;		/* The first two nodes are `.' and `..' */
554 
555 	FILEDESC_SLOCK(fdp);
556 	while (i < fdp->fd_nfiles + 2 && uio->uio_resid >= UIO_MX) {
557 		bzero((caddr_t)dp, UIO_MX);
558 		switch (i) {
559 		case 0:	/* `.' */
560 		case 1: /* `..' */
561 			dp->d_fileno = i + FD_ROOT;
562 			dp->d_namlen = i + 1;
563 			dp->d_reclen = UIO_MX;
564 			bcopy("..", dp->d_name, dp->d_namlen);
565 			dp->d_name[i + 1] = '\0';
566 			dp->d_type = DT_DIR;
567 			break;
568 		default:
569 			if (fdp->fd_ofiles[fcnt].fde_file == NULL)
570 				break;
571 			dp->d_namlen = sprintf(dp->d_name, "%d", fcnt);
572 			dp->d_reclen = UIO_MX;
573 			dp->d_type = (fmp->flags & FMNT_LINRDLNKF) == 0 ?
574 			    DT_CHR : DT_LNK;
575 			dp->d_fileno = i + FD_DESC;
576 			break;
577 		}
578 		if (dp->d_namlen != 0) {
579 			/*
580 			 * And ship to userland
581 			 */
582 			FILEDESC_SUNLOCK(fdp);
583 			error = uiomove(dp, UIO_MX, uio);
584 			if (error)
585 				goto done;
586 			FILEDESC_SLOCK(fdp);
587 		}
588 		i++;
589 		fcnt++;
590 	}
591 	FILEDESC_SUNLOCK(fdp);
592 
593 done:
594 	uio->uio_offset = i * UIO_MX;
595 	return (error);
596 }
597 
598 static int
599 fdesc_reclaim(struct vop_reclaim_args *ap)
600 {
601 	struct vnode *vp;
602 	struct fdescnode *fd;
603 
604  	vp = ap->a_vp;
605  	fd = VTOFDESC(vp);
606 	fdesc_remove_entry(fd);
607 	free(vp->v_data, M_TEMP);
608 	vp->v_data = NULL;
609 	return (0);
610 }
611 
612 static int
613 fdesc_readlink(struct vop_readlink_args *va)
614 {
615 	struct vnode *vp, *vn;
616 	cap_rights_t rights;
617 	struct thread *td;
618 	struct uio *uio;
619 	struct file *fp;
620 	char *freepath, *fullpath;
621 	size_t pathlen;
622 	int lockflags, fd_fd;
623 	int error;
624 
625 	freepath = NULL;
626 	vn = va->a_vp;
627 	if (VTOFDESC(vn)->fd_type != Fdesc)
628 		panic("fdesc_readlink: not fdescfs link");
629 	fd_fd = ((struct fdescnode *)vn->v_data)->fd_fd;
630 	lockflags = VOP_ISLOCKED(vn);
631 	VOP_UNLOCK(vn, 0);
632 
633 	td = curthread;
634 	error = fget_cap(td, fd_fd, cap_rights_init(&rights), &fp, NULL);
635 	if (error != 0)
636 		goto out;
637 
638 	switch (fp->f_type) {
639 	case DTYPE_VNODE:
640 		vp = fp->f_vnode;
641 		error = vn_fullpath(td, vp, &fullpath, &freepath);
642 		break;
643 	default:
644 		fullpath = "anon_inode:[unknown]";
645 		break;
646 	}
647 	if (error == 0) {
648 		uio = va->a_uio;
649 		pathlen = strlen(fullpath);
650 		error = uiomove(fullpath, pathlen, uio);
651 	}
652 	if (freepath != NULL)
653 		free(freepath, M_TEMP);
654 	fdrop(fp, td);
655 
656 out:
657 	vn_lock(vn, lockflags | LK_RETRY);
658 	return (error);
659 }
660