xref: /freebsd/sys/fs/fuse/fuse_ipc.c (revision 723c7768299a077a93f19b26e8c27b4641751e34)
151369649SPedro F. Giffuni /*-
251369649SPedro F. Giffuni  * SPDX-License-Identifier: BSD-3-Clause
351369649SPedro F. Giffuni  *
45fe58019SAttilio Rao  * Copyright (c) 2007-2009 Google Inc. and Amit Singh
55fe58019SAttilio Rao  * All rights reserved.
65fe58019SAttilio Rao  *
75fe58019SAttilio Rao  * Redistribution and use in source and binary forms, with or without
85fe58019SAttilio Rao  * modification, are permitted provided that the following conditions are
95fe58019SAttilio Rao  * met:
105fe58019SAttilio Rao  *
115fe58019SAttilio Rao  * * Redistributions of source code must retain the above copyright
125fe58019SAttilio Rao  *   notice, this list of conditions and the following disclaimer.
135fe58019SAttilio Rao  * * Redistributions in binary form must reproduce the above
145fe58019SAttilio Rao  *   copyright notice, this list of conditions and the following disclaimer
155fe58019SAttilio Rao  *   in the documentation and/or other materials provided with the
165fe58019SAttilio Rao  *   distribution.
175fe58019SAttilio Rao  * * Neither the name of Google Inc. nor the names of its
185fe58019SAttilio Rao  *   contributors may be used to endorse or promote products derived from
195fe58019SAttilio Rao  *   this software without specific prior written permission.
205fe58019SAttilio Rao  *
215fe58019SAttilio Rao  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
225fe58019SAttilio Rao  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
235fe58019SAttilio Rao  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
245fe58019SAttilio Rao  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
255fe58019SAttilio Rao  * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
265fe58019SAttilio Rao  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
275fe58019SAttilio Rao  * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
285fe58019SAttilio Rao  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
295fe58019SAttilio Rao  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
305fe58019SAttilio Rao  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
315fe58019SAttilio Rao  * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
325fe58019SAttilio Rao  *
335fe58019SAttilio Rao  * Copyright (C) 2005 Csaba Henk.
345fe58019SAttilio Rao  * All rights reserved.
355fe58019SAttilio Rao  *
365fe58019SAttilio Rao  * Redistribution and use in source and binary forms, with or without
375fe58019SAttilio Rao  * modification, are permitted provided that the following conditions
385fe58019SAttilio Rao  * are met:
395fe58019SAttilio Rao  * 1. Redistributions of source code must retain the above copyright
405fe58019SAttilio Rao  *    notice, this list of conditions and the following disclaimer.
415fe58019SAttilio Rao  * 2. Redistributions in binary form must reproduce the above copyright
425fe58019SAttilio Rao  *    notice, this list of conditions and the following disclaimer in the
435fe58019SAttilio Rao  *    documentation and/or other materials provided with the distribution.
445fe58019SAttilio Rao  *
455fe58019SAttilio Rao  * THIS SOFTWARE IS PROVIDED BY AUTHOR AND CONTRIBUTORS ``AS IS'' AND
465fe58019SAttilio Rao  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
475fe58019SAttilio Rao  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
485fe58019SAttilio Rao  * ARE DISCLAIMED.  IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE
495fe58019SAttilio Rao  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
505fe58019SAttilio Rao  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
515fe58019SAttilio Rao  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
525fe58019SAttilio Rao  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
535fe58019SAttilio Rao  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
545fe58019SAttilio Rao  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
555fe58019SAttilio Rao  * SUCH DAMAGE.
565fe58019SAttilio Rao  */
575fe58019SAttilio Rao 
585fe58019SAttilio Rao #include <sys/cdefs.h>
595fe58019SAttilio Rao __FBSDID("$FreeBSD$");
605fe58019SAttilio Rao 
61cf169498SAlan Somers #include <sys/param.h>
625fe58019SAttilio Rao #include <sys/module.h>
635fe58019SAttilio Rao #include <sys/systm.h>
645fe58019SAttilio Rao #include <sys/errno.h>
655fe58019SAttilio Rao #include <sys/kernel.h>
665fe58019SAttilio Rao #include <sys/conf.h>
675fe58019SAttilio Rao #include <sys/uio.h>
685fe58019SAttilio Rao #include <sys/malloc.h>
695fe58019SAttilio Rao #include <sys/queue.h>
705fe58019SAttilio Rao #include <sys/lock.h>
715fe58019SAttilio Rao #include <sys/sx.h>
725fe58019SAttilio Rao #include <sys/mutex.h>
735fe58019SAttilio Rao #include <sys/proc.h>
745fe58019SAttilio Rao #include <sys/mount.h>
75cf169498SAlan Somers #include <sys/sdt.h>
765fe58019SAttilio Rao #include <sys/vnode.h>
775fe58019SAttilio Rao #include <sys/signalvar.h>
785fe58019SAttilio Rao #include <sys/syscallsubr.h>
795fe58019SAttilio Rao #include <sys/sysctl.h>
805fe58019SAttilio Rao #include <vm/uma.h>
815fe58019SAttilio Rao 
825fe58019SAttilio Rao #include "fuse.h"
835fe58019SAttilio Rao #include "fuse_node.h"
845fe58019SAttilio Rao #include "fuse_ipc.h"
855fe58019SAttilio Rao #include "fuse_internal.h"
865fe58019SAttilio Rao 
87cf169498SAlan Somers SDT_PROVIDER_DECLARE(fuse);
88cf169498SAlan Somers /*
89cf169498SAlan Somers  * Fuse trace probe:
90cf169498SAlan Somers  * arg0: verbosity.  Higher numbers give more verbose messages
91cf169498SAlan Somers  * arg1: Textual message
92cf169498SAlan Somers  */
93cf169498SAlan Somers SDT_PROBE_DEFINE2(fuse, , ipc, trace, "int", "char*");
945fe58019SAttilio Rao 
95*723c7768SAlan Somers static void fdisp_make_pid(struct fuse_dispatcher *fdip, enum fuse_opcode op,
96*723c7768SAlan Somers     struct fuse_data *data, uint64_t nid, pid_t pid, struct ucred *cred);
9712292a99SAlan Somers static void fiov_clear(struct fuse_iov *fiov);
98*723c7768SAlan Somers static void fuse_interrupt_send(struct fuse_ticket *otick);
995fe58019SAttilio Rao static struct fuse_ticket *fticket_alloc(struct fuse_data *data);
1005fe58019SAttilio Rao static void fticket_refresh(struct fuse_ticket *ftick);
1015fe58019SAttilio Rao static void fticket_destroy(struct fuse_ticket *ftick);
1025fe58019SAttilio Rao static int fticket_wait_answer(struct fuse_ticket *ftick);
10302295cafSConrad Meyer static inline int
1045fe58019SAttilio Rao fticket_aw_pull_uio(struct fuse_ticket *ftick,
1055fe58019SAttilio Rao     struct uio *uio);
1065fe58019SAttilio Rao 
1075fe58019SAttilio Rao static int fuse_body_audit(struct fuse_ticket *ftick, size_t blen);
1085fe58019SAttilio Rao 
1095fe58019SAttilio Rao static fuse_handler_t fuse_standard_handler;
1105fe58019SAttilio Rao 
111123af6ecSAlan Somers SYSCTL_NODE(_vfs, OID_AUTO, fusefs, CTLFLAG_RW, 0, "FUSE tunables");
112123af6ecSAlan Somers SYSCTL_STRING(_vfs_fusefs, OID_AUTO, version, CTLFLAG_RD,
1135fe58019SAttilio Rao     FUSE_FREEBSD_VERSION, 0, "fuse-freebsd version");
1145fe58019SAttilio Rao static int fuse_ticket_count = 0;
1155fe58019SAttilio Rao 
116123af6ecSAlan Somers SYSCTL_INT(_vfs_fusefs, OID_AUTO, ticket_count, CTLFLAG_RW,
1175fe58019SAttilio Rao     &fuse_ticket_count, 0, "number of allocated tickets");
1185fe58019SAttilio Rao static long fuse_iov_permanent_bufsize = 1 << 19;
1195fe58019SAttilio Rao 
120123af6ecSAlan Somers SYSCTL_LONG(_vfs_fusefs, OID_AUTO, iov_permanent_bufsize, CTLFLAG_RW,
1215fe58019SAttilio Rao     &fuse_iov_permanent_bufsize, 0,
1225fe58019SAttilio Rao     "limit for permanently stored buffer size for fuse_iovs");
1235fe58019SAttilio Rao static int fuse_iov_credit = 16;
1245fe58019SAttilio Rao 
125123af6ecSAlan Somers SYSCTL_INT(_vfs_fusefs, OID_AUTO, iov_credit, CTLFLAG_RW,
1265fe58019SAttilio Rao     &fuse_iov_credit, 0,
1275fe58019SAttilio Rao     "how many times is an oversized fuse_iov tolerated");
1285fe58019SAttilio Rao 
1295fe58019SAttilio Rao MALLOC_DEFINE(M_FUSEMSG, "fuse_msgbuf", "fuse message buffer");
1305fe58019SAttilio Rao static uma_zone_t ticket_zone;
1315fe58019SAttilio Rao 
132*723c7768SAlan Somers /*
133*723c7768SAlan Somers  * TODO: figure out how to timeout INTERRUPT requests, because the daemon may
134*723c7768SAlan Somers  * leagally never respond
135*723c7768SAlan Somers  *
136*723c7768SAlan Somers  * TODO: remove an INTERRUPT request if the daemon responds to the original
137*723c7768SAlan Somers  */
138*723c7768SAlan Somers static int
139*723c7768SAlan Somers fuse_interrupt_callback(struct fuse_ticket *tick, struct uio *uio)
1405fe58019SAttilio Rao {
141*723c7768SAlan Somers 	if (tick->tk_aw_ohead.error == EAGAIN) {
142*723c7768SAlan Somers 		/*
143*723c7768SAlan Somers 		 * There are two reasons we might get this:
144*723c7768SAlan Somers 		 * 1) the daemon received the INTERRUPT request before the
145*723c7768SAlan Somers 		 *    original, or
146*723c7768SAlan Somers 		 * 2) the daemon received the INTERRUPT request after it
147*723c7768SAlan Somers 		 *    completed the original request.
148*723c7768SAlan Somers 		 * In the first case we should re-send the INTERRUPT.  In the
149*723c7768SAlan Somers 		 * second, we should ignore it.
150*723c7768SAlan Somers 		 */
151*723c7768SAlan Somers 		struct fuse_interrupt_in *fii;
152*723c7768SAlan Somers 		struct fuse_data *data;
153*723c7768SAlan Somers 		struct fuse_ticket *otick, *x_tick;
154*723c7768SAlan Somers 		bool found = false;
1555fe58019SAttilio Rao 
156*723c7768SAlan Somers 		data = tick->tk_data;
157*723c7768SAlan Somers 		fii = (struct fuse_interrupt_in*)((char*)tick->tk_ms_fiov.base +
158*723c7768SAlan Somers 			sizeof(struct fuse_in_header));
159*723c7768SAlan Somers 		fuse_lck_mtx_lock(data->aw_mtx);
160*723c7768SAlan Somers 		TAILQ_FOREACH_SAFE(otick, &data->aw_head, tk_aw_link, x_tick) {
161*723c7768SAlan Somers 			if (otick->tk_unique == fii->unique) {
162*723c7768SAlan Somers 				found = true;
163*723c7768SAlan Somers 				break;
164*723c7768SAlan Somers 			}
165*723c7768SAlan Somers 		}
166*723c7768SAlan Somers 		fuse_lck_mtx_unlock(data->aw_mtx);
167*723c7768SAlan Somers 		if (found) {
168*723c7768SAlan Somers 			/* Resend */
169*723c7768SAlan Somers 			fuse_interrupt_send(otick);
170*723c7768SAlan Somers 		} else {
171*723c7768SAlan Somers 			/* Original is already complete; nothing to do */
172*723c7768SAlan Somers 		}
173*723c7768SAlan Somers 		return 0;
174*723c7768SAlan Somers 	} else {
175*723c7768SAlan Somers 		/* Illegal FUSE_INTERRUPT response */
176*723c7768SAlan Somers 		return EINVAL;
177*723c7768SAlan Somers 	}
1785fe58019SAttilio Rao }
1795fe58019SAttilio Rao 
180*723c7768SAlan Somers void
181*723c7768SAlan Somers fuse_interrupt_send(struct fuse_ticket *otick)
1825fe58019SAttilio Rao {
183*723c7768SAlan Somers 	struct fuse_dispatcher fdi;
184*723c7768SAlan Somers 	struct fuse_interrupt_in *fii;
185*723c7768SAlan Somers 	struct fuse_in_header *ftick_hdr;
186*723c7768SAlan Somers 	struct fuse_data *data = otick->tk_data;
187*723c7768SAlan Somers 	struct ucred reused_creds;
1885fe58019SAttilio Rao 
189*723c7768SAlan Somers 	ftick_hdr = fticket_in_header(otick);
190*723c7768SAlan Somers 	reused_creds.cr_uid = ftick_hdr->uid;
191*723c7768SAlan Somers 	reused_creds.cr_rgid = ftick_hdr->gid;
192*723c7768SAlan Somers 	fdisp_init(&fdi, sizeof(*fii));
193*723c7768SAlan Somers 	fdisp_make_pid(&fdi, FUSE_INTERRUPT, data, ftick_hdr->nodeid,
194*723c7768SAlan Somers 		ftick_hdr->pid, &reused_creds);
195*723c7768SAlan Somers 
196*723c7768SAlan Somers 	fii = fdi.indata;
197*723c7768SAlan Somers 	fii->unique = otick->tk_unique;
198*723c7768SAlan Somers 	fuse_insert_callback(fdi.tick, fuse_interrupt_callback);
199*723c7768SAlan Somers 
200*723c7768SAlan Somers 	fuse_insert_message(fdi.tick);
201*723c7768SAlan Somers 	fdisp_destroy(&fdi);
2025fe58019SAttilio Rao }
2035fe58019SAttilio Rao 
2045fe58019SAttilio Rao void
2055fe58019SAttilio Rao fiov_init(struct fuse_iov *fiov, size_t size)
2065fe58019SAttilio Rao {
2075fe58019SAttilio Rao 	uint32_t msize = FU_AT_LEAST(size);
2085fe58019SAttilio Rao 
2095fe58019SAttilio Rao 	fiov->len = 0;
2105fe58019SAttilio Rao 
2115fe58019SAttilio Rao 	fiov->base = malloc(msize, M_FUSEMSG, M_WAITOK | M_ZERO);
2125fe58019SAttilio Rao 
2135fe58019SAttilio Rao 	fiov->allocated_size = msize;
2145fe58019SAttilio Rao 	fiov->credit = fuse_iov_credit;
2155fe58019SAttilio Rao }
2165fe58019SAttilio Rao 
2175fe58019SAttilio Rao void
2185fe58019SAttilio Rao fiov_teardown(struct fuse_iov *fiov)
2195fe58019SAttilio Rao {
2205fe58019SAttilio Rao 	MPASS(fiov->base != NULL);
2215fe58019SAttilio Rao 	free(fiov->base, M_FUSEMSG);
2225fe58019SAttilio Rao }
2235fe58019SAttilio Rao 
2245fe58019SAttilio Rao void
2255fe58019SAttilio Rao fiov_adjust(struct fuse_iov *fiov, size_t size)
2265fe58019SAttilio Rao {
2275fe58019SAttilio Rao 	if (fiov->allocated_size < size ||
2285fe58019SAttilio Rao 	    (fuse_iov_permanent_bufsize >= 0 &&
2295fe58019SAttilio Rao 	    fiov->allocated_size - size > fuse_iov_permanent_bufsize &&
2305fe58019SAttilio Rao 	    --fiov->credit < 0)) {
2315fe58019SAttilio Rao 
2325fe58019SAttilio Rao 		fiov->base = realloc(fiov->base, FU_AT_LEAST(size), M_FUSEMSG,
2335fe58019SAttilio Rao 		    M_WAITOK | M_ZERO);
2345fe58019SAttilio Rao 		if (!fiov->base) {
2355fe58019SAttilio Rao 			panic("FUSE: realloc failed");
2365fe58019SAttilio Rao 		}
2375fe58019SAttilio Rao 		fiov->allocated_size = FU_AT_LEAST(size);
2385fe58019SAttilio Rao 		fiov->credit = fuse_iov_credit;
2398d013becSAlan Somers 		/* Clear data buffer after reallocation */
2408d013becSAlan Somers 		bzero(fiov->base, size);
2418d013becSAlan Somers 	} else if (size > fiov->len) {
2428d013becSAlan Somers 		/* Clear newly extended portion of data buffer */
2438d013becSAlan Somers 		bzero((char*)fiov->base + fiov->len, size - fiov->len);
2445fe58019SAttilio Rao 	}
2455fe58019SAttilio Rao 	fiov->len = size;
2465fe58019SAttilio Rao }
2475fe58019SAttilio Rao 
24812292a99SAlan Somers /* Clear the fiov's data buffer */
24912292a99SAlan Somers static void
25012292a99SAlan Somers fiov_clear(struct fuse_iov *fiov)
25112292a99SAlan Somers {
25212292a99SAlan Somers 	bzero(fiov->base, fiov->len);
25312292a99SAlan Somers }
25412292a99SAlan Somers 
25512292a99SAlan Somers /* Resize the fiov if needed, and clear it's buffer */
2565fe58019SAttilio Rao void
2575fe58019SAttilio Rao fiov_refresh(struct fuse_iov *fiov)
2585fe58019SAttilio Rao {
2595fe58019SAttilio Rao 	fiov_adjust(fiov, 0);
2605fe58019SAttilio Rao }
2615fe58019SAttilio Rao 
2625fe58019SAttilio Rao static int
2635fe58019SAttilio Rao fticket_ctor(void *mem, int size, void *arg, int flags)
2645fe58019SAttilio Rao {
2655fe58019SAttilio Rao 	struct fuse_ticket *ftick = mem;
2665fe58019SAttilio Rao 	struct fuse_data *data = arg;
2675fe58019SAttilio Rao 
2685fe58019SAttilio Rao 	FUSE_ASSERT_MS_DONE(ftick);
2695fe58019SAttilio Rao 	FUSE_ASSERT_AW_DONE(ftick);
2705fe58019SAttilio Rao 
2715fe58019SAttilio Rao 	ftick->tk_data = data;
2725fe58019SAttilio Rao 
2735fe58019SAttilio Rao 	if (ftick->tk_unique != 0)
2745fe58019SAttilio Rao 		fticket_refresh(ftick);
2755fe58019SAttilio Rao 
2765fe58019SAttilio Rao 	/* May be truncated to 32 bits */
2775fe58019SAttilio Rao 	ftick->tk_unique = atomic_fetchadd_long(&data->ticketer, 1);
2785fe58019SAttilio Rao 	if (ftick->tk_unique == 0)
2795fe58019SAttilio Rao 		ftick->tk_unique = atomic_fetchadd_long(&data->ticketer, 1);
2805fe58019SAttilio Rao 
2815fe58019SAttilio Rao 	refcount_init(&ftick->tk_refcount, 1);
2825fe58019SAttilio Rao 	atomic_add_acq_int(&fuse_ticket_count, 1);
2835fe58019SAttilio Rao 
2845fe58019SAttilio Rao 	return 0;
2855fe58019SAttilio Rao }
2865fe58019SAttilio Rao 
2875fe58019SAttilio Rao static void
2885fe58019SAttilio Rao fticket_dtor(void *mem, int size, void *arg)
2895fe58019SAttilio Rao {
290f220ef0bSAlan Somers #ifdef INVARIANTS
2915fe58019SAttilio Rao 	struct fuse_ticket *ftick = mem;
292f220ef0bSAlan Somers #endif
2935fe58019SAttilio Rao 
2945fe58019SAttilio Rao 	FUSE_ASSERT_MS_DONE(ftick);
2955fe58019SAttilio Rao 	FUSE_ASSERT_AW_DONE(ftick);
2965fe58019SAttilio Rao 
2975fe58019SAttilio Rao 	atomic_subtract_acq_int(&fuse_ticket_count, 1);
2985fe58019SAttilio Rao }
2995fe58019SAttilio Rao 
3005fe58019SAttilio Rao static int
3015fe58019SAttilio Rao fticket_init(void *mem, int size, int flags)
3025fe58019SAttilio Rao {
3035fe58019SAttilio Rao 	struct fuse_ticket *ftick = mem;
3045fe58019SAttilio Rao 
3055fe58019SAttilio Rao 	bzero(ftick, sizeof(struct fuse_ticket));
3065fe58019SAttilio Rao 
3075fe58019SAttilio Rao 	fiov_init(&ftick->tk_ms_fiov, sizeof(struct fuse_in_header));
3085fe58019SAttilio Rao 	ftick->tk_ms_type = FT_M_FIOV;
3095fe58019SAttilio Rao 
3105fe58019SAttilio Rao 	mtx_init(&ftick->tk_aw_mtx, "fuse answer delivery mutex", NULL, MTX_DEF);
3115fe58019SAttilio Rao 	fiov_init(&ftick->tk_aw_fiov, 0);
3125fe58019SAttilio Rao 	ftick->tk_aw_type = FT_A_FIOV;
3135fe58019SAttilio Rao 
3145fe58019SAttilio Rao 	return 0;
3155fe58019SAttilio Rao }
3165fe58019SAttilio Rao 
3175fe58019SAttilio Rao static void
3185fe58019SAttilio Rao fticket_fini(void *mem, int size)
3195fe58019SAttilio Rao {
3205fe58019SAttilio Rao 	struct fuse_ticket *ftick = mem;
3215fe58019SAttilio Rao 
3225fe58019SAttilio Rao 	fiov_teardown(&ftick->tk_ms_fiov);
3235fe58019SAttilio Rao 	fiov_teardown(&ftick->tk_aw_fiov);
3245fe58019SAttilio Rao 	mtx_destroy(&ftick->tk_aw_mtx);
3255fe58019SAttilio Rao }
3265fe58019SAttilio Rao 
32702295cafSConrad Meyer static inline struct fuse_ticket *
3285fe58019SAttilio Rao fticket_alloc(struct fuse_data *data)
3295fe58019SAttilio Rao {
3305fe58019SAttilio Rao 	return uma_zalloc_arg(ticket_zone, data, M_WAITOK);
3315fe58019SAttilio Rao }
3325fe58019SAttilio Rao 
33302295cafSConrad Meyer static inline void
3345fe58019SAttilio Rao fticket_destroy(struct fuse_ticket *ftick)
3355fe58019SAttilio Rao {
3365fe58019SAttilio Rao 	return uma_zfree(ticket_zone, ftick);
3375fe58019SAttilio Rao }
3385fe58019SAttilio Rao 
33902295cafSConrad Meyer static inline
3405fe58019SAttilio Rao void
3415fe58019SAttilio Rao fticket_refresh(struct fuse_ticket *ftick)
3425fe58019SAttilio Rao {
3435fe58019SAttilio Rao 	FUSE_ASSERT_MS_DONE(ftick);
3445fe58019SAttilio Rao 	FUSE_ASSERT_AW_DONE(ftick);
3455fe58019SAttilio Rao 
3465fe58019SAttilio Rao 	fiov_refresh(&ftick->tk_ms_fiov);
3475fe58019SAttilio Rao 	ftick->tk_ms_bufdata = NULL;
3485fe58019SAttilio Rao 	ftick->tk_ms_bufsize = 0;
3495fe58019SAttilio Rao 	ftick->tk_ms_type = FT_M_FIOV;
3505fe58019SAttilio Rao 
3515fe58019SAttilio Rao 	bzero(&ftick->tk_aw_ohead, sizeof(struct fuse_out_header));
3525fe58019SAttilio Rao 
3535fe58019SAttilio Rao 	fiov_refresh(&ftick->tk_aw_fiov);
3545fe58019SAttilio Rao 	ftick->tk_aw_errno = 0;
3555fe58019SAttilio Rao 	ftick->tk_aw_bufdata = NULL;
3565fe58019SAttilio Rao 	ftick->tk_aw_bufsize = 0;
3575fe58019SAttilio Rao 	ftick->tk_aw_type = FT_A_FIOV;
3585fe58019SAttilio Rao 
3595fe58019SAttilio Rao 	ftick->tk_flag = 0;
3605fe58019SAttilio Rao }
3615fe58019SAttilio Rao 
36212292a99SAlan Somers /* Prepar the ticket to be reused, but don't clear its data buffers */
36312292a99SAlan Somers static inline void
36412292a99SAlan Somers fticket_reset(struct fuse_ticket *ftick)
36512292a99SAlan Somers {
36612292a99SAlan Somers 	FUSE_ASSERT_MS_DONE(ftick);
36712292a99SAlan Somers 	FUSE_ASSERT_AW_DONE(ftick);
36812292a99SAlan Somers 
36912292a99SAlan Somers 	ftick->tk_ms_bufdata = NULL;
37012292a99SAlan Somers 	ftick->tk_ms_bufsize = 0;
37112292a99SAlan Somers 	ftick->tk_ms_type = FT_M_FIOV;
37212292a99SAlan Somers 
37312292a99SAlan Somers 	bzero(&ftick->tk_aw_ohead, sizeof(struct fuse_out_header));
37412292a99SAlan Somers 
37512292a99SAlan Somers 	ftick->tk_aw_errno = 0;
37612292a99SAlan Somers 	ftick->tk_aw_bufdata = NULL;
37712292a99SAlan Somers 	ftick->tk_aw_bufsize = 0;
37812292a99SAlan Somers 	ftick->tk_aw_type = FT_A_FIOV;
37912292a99SAlan Somers 
38012292a99SAlan Somers 	ftick->tk_flag = 0;
38112292a99SAlan Somers }
38212292a99SAlan Somers 
3835fe58019SAttilio Rao static int
3845fe58019SAttilio Rao fticket_wait_answer(struct fuse_ticket *ftick)
3855fe58019SAttilio Rao {
386*723c7768SAlan Somers 	struct thread *td = curthread;
387*723c7768SAlan Somers 	sigset_t blockedset, oldset;
3885fe58019SAttilio Rao 	int err = 0;
3895fe58019SAttilio Rao 	struct fuse_data *data;
3905fe58019SAttilio Rao 
391c02ccc7eSAlan Somers 	fuse_lck_mtx_lock(ftick->tk_aw_mtx);
392c02ccc7eSAlan Somers 
393*723c7768SAlan Somers 	SIGEMPTYSET(blockedset);
394*723c7768SAlan Somers 	kern_sigprocmask(td, SIG_BLOCK, &blockedset, &oldset, 0);
395*723c7768SAlan Somers retry:
3965fe58019SAttilio Rao 	if (fticket_answered(ftick)) {
3975fe58019SAttilio Rao 		goto out;
3985fe58019SAttilio Rao 	}
3995fe58019SAttilio Rao 	data = ftick->tk_data;
4005fe58019SAttilio Rao 
4015fe58019SAttilio Rao 	if (fdata_get_dead(data)) {
4025fe58019SAttilio Rao 		err = ENOTCONN;
4035fe58019SAttilio Rao 		fticket_set_answered(ftick);
4045fe58019SAttilio Rao 		goto out;
4055fe58019SAttilio Rao 	}
4065fe58019SAttilio Rao 	err = msleep(ftick, &ftick->tk_aw_mtx, PCATCH, "fu_ans",
4075fe58019SAttilio Rao 	    data->daemon_timeout * hz);
408*723c7768SAlan Somers 	kern_sigprocmask(td, SIG_SETMASK, &oldset, NULL, 0);
409*723c7768SAlan Somers 	if (err == EWOULDBLOCK) {
410*723c7768SAlan Somers 		SDT_PROBE2(fuse, , ipc, trace, 3,
411*723c7768SAlan Somers 			"fticket_wait_answer: EWOULDBLOCK");
4125fe58019SAttilio Rao #ifdef XXXIP				/* die conditionally */
4135fe58019SAttilio Rao 		if (!fdata_get_dead(data)) {
4145fe58019SAttilio Rao 			fdata_set_dead(data);
4155fe58019SAttilio Rao 		}
4165fe58019SAttilio Rao #endif
4175fe58019SAttilio Rao 		err = ETIMEDOUT;
4185fe58019SAttilio Rao 		fticket_set_answered(ftick);
419*723c7768SAlan Somers 	} else if ((err == EINTR || err == ERESTART)) {
420*723c7768SAlan Somers 		/*
421*723c7768SAlan Somers 		 * Whether we get EINTR or ERESTART depends on whether
422*723c7768SAlan Somers 		 * SA_RESTART was set by sigaction(2).
423*723c7768SAlan Somers 		 *
424*723c7768SAlan Somers 		 * Try to interrupt the operation and wait for an EINTR response
425*723c7768SAlan Somers 		 * to the original operation.  If the file system does not
426*723c7768SAlan Somers 		 * support FUSE_INTERRUPT, then we'll just wait for it to
427*723c7768SAlan Somers 		 * complete like normal.  If it does support FUSE_INTERRUPT,
428*723c7768SAlan Somers 		 * then it will either respond EINTR to the original operation,
429*723c7768SAlan Somers 		 * or EAGAIN to the interrupt.
430*723c7768SAlan Somers 		 */
431*723c7768SAlan Somers 		int sig;
432*723c7768SAlan Somers 
433*723c7768SAlan Somers 		SDT_PROBE2(fuse, , ipc, trace, 4,
434*723c7768SAlan Somers 			"fticket_wait_answer: interrupt");
435*723c7768SAlan Somers 		fuse_lck_mtx_unlock(ftick->tk_aw_mtx);
436*723c7768SAlan Somers 		fuse_interrupt_send(ftick);
437*723c7768SAlan Somers 		fuse_lck_mtx_lock(ftick->tk_aw_mtx);
438*723c7768SAlan Somers 
439*723c7768SAlan Somers 		/* TODO: return, rather than retry, for fatal signals */
440*723c7768SAlan Somers 
441*723c7768SAlan Somers 		/*
442*723c7768SAlan Somers 		 * Block the just-delivered signal while we wait for an
443*723c7768SAlan Somers 		 * interrupt response
444*723c7768SAlan Somers 		 */
445*723c7768SAlan Somers 		PROC_LOCK(td->td_proc);
446*723c7768SAlan Somers 		mtx_lock(&td->td_proc->p_sigacts->ps_mtx);
447*723c7768SAlan Somers 		sig = cursig(td);
448*723c7768SAlan Somers 		mtx_unlock(&td->td_proc->p_sigacts->ps_mtx);
449*723c7768SAlan Somers 		PROC_UNLOCK(td->td_proc);
450*723c7768SAlan Somers 		SIGADDSET(blockedset, sig);
451*723c7768SAlan Somers 		kern_sigprocmask(curthread, SIG_BLOCK, &blockedset, NULL, 0);
452*723c7768SAlan Somers 		goto retry;
453*723c7768SAlan Somers 	} else if (err) {
454*723c7768SAlan Somers 		SDT_PROBE2(fuse, , ipc, trace, 6,
455*723c7768SAlan Somers 			"fticket_wait_answer: other error");
456*723c7768SAlan Somers 	} else {
457*723c7768SAlan Somers 		SDT_PROBE2(fuse, , ipc, trace, 7, "fticket_wait_answer: OK");
4585fe58019SAttilio Rao 	}
4595fe58019SAttilio Rao out:
4605fe58019SAttilio Rao 	if (!(err || fticket_answered(ftick))) {
461cf169498SAlan Somers 		SDT_PROBE2(fuse, , ipc, trace, 1,
462cf169498SAlan Somers 			"FUSE: requester was woken up but still no answer");
4635fe58019SAttilio Rao 		err = ENXIO;
4645fe58019SAttilio Rao 	}
4655fe58019SAttilio Rao 	fuse_lck_mtx_unlock(ftick->tk_aw_mtx);
4665fe58019SAttilio Rao 
4675fe58019SAttilio Rao 	return err;
4685fe58019SAttilio Rao }
4695fe58019SAttilio Rao 
47002295cafSConrad Meyer static	inline
4715fe58019SAttilio Rao int
4725fe58019SAttilio Rao fticket_aw_pull_uio(struct fuse_ticket *ftick, struct uio *uio)
4735fe58019SAttilio Rao {
4745fe58019SAttilio Rao 	int err = 0;
4755fe58019SAttilio Rao 	size_t len = uio_resid(uio);
4765fe58019SAttilio Rao 
4775fe58019SAttilio Rao 	if (len) {
4785fe58019SAttilio Rao 		switch (ftick->tk_aw_type) {
4795fe58019SAttilio Rao 		case FT_A_FIOV:
4805fe58019SAttilio Rao 			fiov_adjust(fticket_resp(ftick), len);
4815fe58019SAttilio Rao 			err = uiomove(fticket_resp(ftick)->base, len, uio);
4825fe58019SAttilio Rao 			break;
4835fe58019SAttilio Rao 
4845fe58019SAttilio Rao 		case FT_A_BUF:
4855fe58019SAttilio Rao 			ftick->tk_aw_bufsize = len;
4865fe58019SAttilio Rao 			err = uiomove(ftick->tk_aw_bufdata, len, uio);
4875fe58019SAttilio Rao 			break;
4885fe58019SAttilio Rao 
4895fe58019SAttilio Rao 		default:
4905fe58019SAttilio Rao 			panic("FUSE: unknown answer type for ticket %p", ftick);
4915fe58019SAttilio Rao 		}
4925fe58019SAttilio Rao 	}
4935fe58019SAttilio Rao 	return err;
4945fe58019SAttilio Rao }
4955fe58019SAttilio Rao 
4965fe58019SAttilio Rao int
4975fe58019SAttilio Rao fticket_pull(struct fuse_ticket *ftick, struct uio *uio)
4985fe58019SAttilio Rao {
4995fe58019SAttilio Rao 	int err = 0;
5005fe58019SAttilio Rao 
5015fe58019SAttilio Rao 	if (ftick->tk_aw_ohead.error) {
5025fe58019SAttilio Rao 		return 0;
5035fe58019SAttilio Rao 	}
5045fe58019SAttilio Rao 	err = fuse_body_audit(ftick, uio_resid(uio));
5055fe58019SAttilio Rao 	if (!err) {
5065fe58019SAttilio Rao 		err = fticket_aw_pull_uio(ftick, uio);
5075fe58019SAttilio Rao 	}
5085fe58019SAttilio Rao 	return err;
5095fe58019SAttilio Rao }
5105fe58019SAttilio Rao 
5115fe58019SAttilio Rao struct fuse_data *
5125fe58019SAttilio Rao fdata_alloc(struct cdev *fdev, struct ucred *cred)
5135fe58019SAttilio Rao {
5145fe58019SAttilio Rao 	struct fuse_data *data;
5155fe58019SAttilio Rao 
5165fe58019SAttilio Rao 	data = malloc(sizeof(struct fuse_data), M_FUSEMSG, M_WAITOK | M_ZERO);
5175fe58019SAttilio Rao 
5185fe58019SAttilio Rao 	data->fdev = fdev;
5195fe58019SAttilio Rao 	mtx_init(&data->ms_mtx, "fuse message list mutex", NULL, MTX_DEF);
5205fe58019SAttilio Rao 	STAILQ_INIT(&data->ms_head);
5215fe58019SAttilio Rao 	mtx_init(&data->aw_mtx, "fuse answer list mutex", NULL, MTX_DEF);
5225fe58019SAttilio Rao 	TAILQ_INIT(&data->aw_head);
5235fe58019SAttilio Rao 	data->daemoncred = crhold(cred);
5245fe58019SAttilio Rao 	data->daemon_timeout = FUSE_DEFAULT_DAEMON_TIMEOUT;
5255fe58019SAttilio Rao 	sx_init(&data->rename_lock, "fuse rename lock");
5265fe58019SAttilio Rao 	data->ref = 1;
5275fe58019SAttilio Rao 
5285fe58019SAttilio Rao 	return data;
5295fe58019SAttilio Rao }
5305fe58019SAttilio Rao 
5315fe58019SAttilio Rao void
5325fe58019SAttilio Rao fdata_trydestroy(struct fuse_data *data)
5335fe58019SAttilio Rao {
5345fe58019SAttilio Rao 	data->ref--;
5355fe58019SAttilio Rao 	MPASS(data->ref >= 0);
5365fe58019SAttilio Rao 	if (data->ref != 0)
5375fe58019SAttilio Rao 		return;
5385fe58019SAttilio Rao 
5395fe58019SAttilio Rao 	/* Driving off stage all that stuff thrown at device... */
5405fe58019SAttilio Rao 	mtx_destroy(&data->ms_mtx);
5415fe58019SAttilio Rao 	mtx_destroy(&data->aw_mtx);
5425fe58019SAttilio Rao 	sx_destroy(&data->rename_lock);
5435fe58019SAttilio Rao 
5445fe58019SAttilio Rao 	crfree(data->daemoncred);
5455fe58019SAttilio Rao 
5465fe58019SAttilio Rao 	free(data, M_FUSEMSG);
5475fe58019SAttilio Rao }
5485fe58019SAttilio Rao 
5495fe58019SAttilio Rao void
5505fe58019SAttilio Rao fdata_set_dead(struct fuse_data *data)
5515fe58019SAttilio Rao {
5525fe58019SAttilio Rao 	FUSE_LOCK();
5535fe58019SAttilio Rao 	if (fdata_get_dead(data)) {
5545fe58019SAttilio Rao 		FUSE_UNLOCK();
5555fe58019SAttilio Rao 		return;
5565fe58019SAttilio Rao 	}
5575fe58019SAttilio Rao 	fuse_lck_mtx_lock(data->ms_mtx);
5585fe58019SAttilio Rao 	data->dataflags |= FSESS_DEAD;
5595fe58019SAttilio Rao 	wakeup_one(data);
5605fe58019SAttilio Rao 	selwakeuppri(&data->ks_rsel, PZERO + 1);
5615fe58019SAttilio Rao 	wakeup(&data->ticketer);
5625fe58019SAttilio Rao 	fuse_lck_mtx_unlock(data->ms_mtx);
5635fe58019SAttilio Rao 	FUSE_UNLOCK();
5645fe58019SAttilio Rao }
5655fe58019SAttilio Rao 
5665fe58019SAttilio Rao struct fuse_ticket *
5675fe58019SAttilio Rao fuse_ticket_fetch(struct fuse_data *data)
5685fe58019SAttilio Rao {
5695fe58019SAttilio Rao 	int err = 0;
5705fe58019SAttilio Rao 	struct fuse_ticket *ftick;
5715fe58019SAttilio Rao 
5725fe58019SAttilio Rao 	ftick = fticket_alloc(data);
5735fe58019SAttilio Rao 
5745fe58019SAttilio Rao 	if (!(data->dataflags & FSESS_INITED)) {
5755fe58019SAttilio Rao 		/* Sleep until get answer for INIT messsage */
5765fe58019SAttilio Rao 		FUSE_LOCK();
5775fe58019SAttilio Rao 		if (!(data->dataflags & FSESS_INITED) && data->ticketer > 2) {
5785fe58019SAttilio Rao 			err = msleep(&data->ticketer, &fuse_mtx, PCATCH | PDROP,
5795fe58019SAttilio Rao 			    "fu_ini", 0);
5805fe58019SAttilio Rao 			if (err)
5815fe58019SAttilio Rao 				fdata_set_dead(data);
5825fe58019SAttilio Rao 		} else
5835fe58019SAttilio Rao 			FUSE_UNLOCK();
5845fe58019SAttilio Rao 	}
5855fe58019SAttilio Rao 	return ftick;
5865fe58019SAttilio Rao }
5875fe58019SAttilio Rao 
5885fe58019SAttilio Rao int
5895fe58019SAttilio Rao fuse_ticket_drop(struct fuse_ticket *ftick)
5905fe58019SAttilio Rao {
5915fe58019SAttilio Rao 	int die;
5925fe58019SAttilio Rao 
5935fe58019SAttilio Rao 	die = refcount_release(&ftick->tk_refcount);
5945fe58019SAttilio Rao 	if (die)
5955fe58019SAttilio Rao 		fticket_destroy(ftick);
5965fe58019SAttilio Rao 
5975fe58019SAttilio Rao 	return die;
5985fe58019SAttilio Rao }
5995fe58019SAttilio Rao 
6005fe58019SAttilio Rao void
6015fe58019SAttilio Rao fuse_insert_callback(struct fuse_ticket *ftick, fuse_handler_t * handler)
6025fe58019SAttilio Rao {
6035fe58019SAttilio Rao 	if (fdata_get_dead(ftick->tk_data)) {
6045fe58019SAttilio Rao 		return;
6055fe58019SAttilio Rao 	}
6065fe58019SAttilio Rao 	ftick->tk_aw_handler = handler;
6075fe58019SAttilio Rao 
6085fe58019SAttilio Rao 	fuse_lck_mtx_lock(ftick->tk_data->aw_mtx);
6095fe58019SAttilio Rao 	fuse_aw_push(ftick);
6105fe58019SAttilio Rao 	fuse_lck_mtx_unlock(ftick->tk_data->aw_mtx);
6115fe58019SAttilio Rao }
6125fe58019SAttilio Rao 
6135fe58019SAttilio Rao void
6145fe58019SAttilio Rao fuse_insert_message(struct fuse_ticket *ftick)
6155fe58019SAttilio Rao {
6165fe58019SAttilio Rao 	if (ftick->tk_flag & FT_DIRTY) {
6175fe58019SAttilio Rao 		panic("FUSE: ticket reused without being refreshed");
6185fe58019SAttilio Rao 	}
6195fe58019SAttilio Rao 	ftick->tk_flag |= FT_DIRTY;
6205fe58019SAttilio Rao 
6215fe58019SAttilio Rao 	if (fdata_get_dead(ftick->tk_data)) {
6225fe58019SAttilio Rao 		return;
6235fe58019SAttilio Rao 	}
6245fe58019SAttilio Rao 	fuse_lck_mtx_lock(ftick->tk_data->ms_mtx);
6255fe58019SAttilio Rao 	fuse_ms_push(ftick);
6265fe58019SAttilio Rao 	wakeup_one(ftick->tk_data);
6275fe58019SAttilio Rao 	selwakeuppri(&ftick->tk_data->ks_rsel, PZERO + 1);
6285fe58019SAttilio Rao 	fuse_lck_mtx_unlock(ftick->tk_data->ms_mtx);
6295fe58019SAttilio Rao }
6305fe58019SAttilio Rao 
6315fe58019SAttilio Rao static int
6325fe58019SAttilio Rao fuse_body_audit(struct fuse_ticket *ftick, size_t blen)
6335fe58019SAttilio Rao {
6345fe58019SAttilio Rao 	int err = 0;
6355fe58019SAttilio Rao 	enum fuse_opcode opcode;
6365fe58019SAttilio Rao 
6375fe58019SAttilio Rao 	opcode = fticket_opcode(ftick);
6385fe58019SAttilio Rao 
6395fe58019SAttilio Rao 	switch (opcode) {
6405fe58019SAttilio Rao 	case FUSE_LOOKUP:
6415fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out)) ? 0 : EINVAL;
6425fe58019SAttilio Rao 		break;
6435fe58019SAttilio Rao 
6445fe58019SAttilio Rao 	case FUSE_FORGET:
6455fe58019SAttilio Rao 		panic("FUSE: a handler has been intalled for FUSE_FORGET");
6465fe58019SAttilio Rao 		break;
6475fe58019SAttilio Rao 
6485fe58019SAttilio Rao 	case FUSE_GETATTR:
6495fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_attr_out)) ? 0 : EINVAL;
6505fe58019SAttilio Rao 		break;
6515fe58019SAttilio Rao 
6525fe58019SAttilio Rao 	case FUSE_SETATTR:
6535fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_attr_out)) ? 0 : EINVAL;
6545fe58019SAttilio Rao 		break;
6555fe58019SAttilio Rao 
6565fe58019SAttilio Rao 	case FUSE_READLINK:
6575fe58019SAttilio Rao 		err = (PAGE_SIZE >= blen) ? 0 : EINVAL;
6585fe58019SAttilio Rao 		break;
6595fe58019SAttilio Rao 
6605fe58019SAttilio Rao 	case FUSE_SYMLINK:
6615fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out)) ? 0 : EINVAL;
6625fe58019SAttilio Rao 		break;
6635fe58019SAttilio Rao 
6645fe58019SAttilio Rao 	case FUSE_MKNOD:
6655fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out)) ? 0 : EINVAL;
6665fe58019SAttilio Rao 		break;
6675fe58019SAttilio Rao 
6685fe58019SAttilio Rao 	case FUSE_MKDIR:
6695fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out)) ? 0 : EINVAL;
6705fe58019SAttilio Rao 		break;
6715fe58019SAttilio Rao 
6725fe58019SAttilio Rao 	case FUSE_UNLINK:
6735fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
6745fe58019SAttilio Rao 		break;
6755fe58019SAttilio Rao 
6765fe58019SAttilio Rao 	case FUSE_RMDIR:
6775fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
6785fe58019SAttilio Rao 		break;
6795fe58019SAttilio Rao 
6805fe58019SAttilio Rao 	case FUSE_RENAME:
6815fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
6825fe58019SAttilio Rao 		break;
6835fe58019SAttilio Rao 
6845fe58019SAttilio Rao 	case FUSE_LINK:
6855fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out)) ? 0 : EINVAL;
6865fe58019SAttilio Rao 		break;
6875fe58019SAttilio Rao 
6885fe58019SAttilio Rao 	case FUSE_OPEN:
6895fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_open_out)) ? 0 : EINVAL;
6905fe58019SAttilio Rao 		break;
6915fe58019SAttilio Rao 
6925fe58019SAttilio Rao 	case FUSE_READ:
6935fe58019SAttilio Rao 		err = (((struct fuse_read_in *)(
6945fe58019SAttilio Rao 		    (char *)ftick->tk_ms_fiov.base +
6955fe58019SAttilio Rao 		    sizeof(struct fuse_in_header)
6965fe58019SAttilio Rao 		    ))->size >= blen) ? 0 : EINVAL;
6975fe58019SAttilio Rao 		break;
6985fe58019SAttilio Rao 
6995fe58019SAttilio Rao 	case FUSE_WRITE:
7005fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_write_out)) ? 0 : EINVAL;
7015fe58019SAttilio Rao 		break;
7025fe58019SAttilio Rao 
7035fe58019SAttilio Rao 	case FUSE_STATFS:
7045fe58019SAttilio Rao 		if (fuse_libabi_geq(ftick->tk_data, 7, 4)) {
7055fe58019SAttilio Rao 			err = (blen == sizeof(struct fuse_statfs_out)) ?
7065fe58019SAttilio Rao 			  0 : EINVAL;
7075fe58019SAttilio Rao 		} else {
7085fe58019SAttilio Rao 			err = (blen == FUSE_COMPAT_STATFS_SIZE) ? 0 : EINVAL;
7095fe58019SAttilio Rao 		}
7105fe58019SAttilio Rao 		break;
7115fe58019SAttilio Rao 
7125fe58019SAttilio Rao 	case FUSE_RELEASE:
7135fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7145fe58019SAttilio Rao 		break;
7155fe58019SAttilio Rao 
7165fe58019SAttilio Rao 	case FUSE_FSYNC:
7175fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7185fe58019SAttilio Rao 		break;
7195fe58019SAttilio Rao 
7205fe58019SAttilio Rao 	case FUSE_SETXATTR:
72104660064SFedor Uporov 		err = (blen == 0) ? 0 : EINVAL;
7225fe58019SAttilio Rao 		break;
7235fe58019SAttilio Rao 
7245fe58019SAttilio Rao 	case FUSE_GETXATTR:
7255fe58019SAttilio Rao 	case FUSE_LISTXATTR:
72604660064SFedor Uporov 		/*
72704660064SFedor Uporov 		 * These can have varying response lengths, and 0 length
72804660064SFedor Uporov 		 * isn't necessarily invalid.
72904660064SFedor Uporov 		 */
73004660064SFedor Uporov 		err = 0;
7315fe58019SAttilio Rao 		break;
7325fe58019SAttilio Rao 
7335fe58019SAttilio Rao 	case FUSE_REMOVEXATTR:
73404660064SFedor Uporov 		err = (blen == 0) ? 0 : EINVAL;
7355fe58019SAttilio Rao 		break;
7365fe58019SAttilio Rao 
7375fe58019SAttilio Rao 	case FUSE_FLUSH:
7385fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7395fe58019SAttilio Rao 		break;
7405fe58019SAttilio Rao 
7415fe58019SAttilio Rao 	case FUSE_INIT:
7425fe58019SAttilio Rao 		if (blen == sizeof(struct fuse_init_out) || blen == 8) {
7435fe58019SAttilio Rao 			err = 0;
7445fe58019SAttilio Rao 		} else {
7455fe58019SAttilio Rao 			err = EINVAL;
7465fe58019SAttilio Rao 		}
7475fe58019SAttilio Rao 		break;
7485fe58019SAttilio Rao 
7495fe58019SAttilio Rao 	case FUSE_OPENDIR:
7505fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_open_out)) ? 0 : EINVAL;
7515fe58019SAttilio Rao 		break;
7525fe58019SAttilio Rao 
7535fe58019SAttilio Rao 	case FUSE_READDIR:
7545fe58019SAttilio Rao 		err = (((struct fuse_read_in *)(
7555fe58019SAttilio Rao 		    (char *)ftick->tk_ms_fiov.base +
7565fe58019SAttilio Rao 		    sizeof(struct fuse_in_header)
7575fe58019SAttilio Rao 		    ))->size >= blen) ? 0 : EINVAL;
7585fe58019SAttilio Rao 		break;
7595fe58019SAttilio Rao 
7605fe58019SAttilio Rao 	case FUSE_RELEASEDIR:
7615fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7625fe58019SAttilio Rao 		break;
7635fe58019SAttilio Rao 
7645fe58019SAttilio Rao 	case FUSE_FSYNCDIR:
7655fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7665fe58019SAttilio Rao 		break;
7675fe58019SAttilio Rao 
7685fe58019SAttilio Rao 	case FUSE_GETLK:
769f067b609SAlan Somers 		err = (blen == sizeof(struct fuse_lk_out)) ? 0 : EINVAL;
7705fe58019SAttilio Rao 		break;
7715fe58019SAttilio Rao 
7725fe58019SAttilio Rao 	case FUSE_SETLK:
773f067b609SAlan Somers 		err = (blen == 0) ? 0 : EINVAL;
7745fe58019SAttilio Rao 		break;
7755fe58019SAttilio Rao 
7765fe58019SAttilio Rao 	case FUSE_SETLKW:
777f067b609SAlan Somers 		err = (blen == 0) ? 0 : EINVAL;
7785fe58019SAttilio Rao 		break;
7795fe58019SAttilio Rao 
7805fe58019SAttilio Rao 	case FUSE_ACCESS:
7815fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7825fe58019SAttilio Rao 		break;
7835fe58019SAttilio Rao 
7845fe58019SAttilio Rao 	case FUSE_CREATE:
7855fe58019SAttilio Rao 		err = (blen == sizeof(struct fuse_entry_out) +
7865fe58019SAttilio Rao 		    sizeof(struct fuse_open_out)) ? 0 : EINVAL;
7875fe58019SAttilio Rao 		break;
7885fe58019SAttilio Rao 
7895fe58019SAttilio Rao 	case FUSE_DESTROY:
7905fe58019SAttilio Rao 		err = (blen == 0) ? 0 : EINVAL;
7915fe58019SAttilio Rao 		break;
7925fe58019SAttilio Rao 
7935fe58019SAttilio Rao 	default:
7945fe58019SAttilio Rao 		panic("FUSE: opcodes out of sync (%d)\n", opcode);
7955fe58019SAttilio Rao 	}
7965fe58019SAttilio Rao 
7975fe58019SAttilio Rao 	return err;
7985fe58019SAttilio Rao }
7995fe58019SAttilio Rao 
80002295cafSConrad Meyer static inline void
80102295cafSConrad Meyer fuse_setup_ihead(struct fuse_in_header *ihead, struct fuse_ticket *ftick,
80202295cafSConrad Meyer     uint64_t nid, enum fuse_opcode op, size_t blen, pid_t pid,
8035fe58019SAttilio Rao     struct ucred *cred)
8045fe58019SAttilio Rao {
8055fe58019SAttilio Rao 	ihead->len = sizeof(*ihead) + blen;
8065fe58019SAttilio Rao 	ihead->unique = ftick->tk_unique;
8075fe58019SAttilio Rao 	ihead->nodeid = nid;
8085fe58019SAttilio Rao 	ihead->opcode = op;
8095fe58019SAttilio Rao 
8105fe58019SAttilio Rao 	ihead->pid = pid;
8115fe58019SAttilio Rao 	ihead->uid = cred->cr_uid;
8125fe58019SAttilio Rao 	ihead->gid = cred->cr_rgid;
8135fe58019SAttilio Rao }
8145fe58019SAttilio Rao 
8155fe58019SAttilio Rao /*
8165fe58019SAttilio Rao  * fuse_standard_handler just pulls indata and wakes up pretender.
8175fe58019SAttilio Rao  * Doesn't try to interpret data, that's left for the pretender.
8185fe58019SAttilio Rao  * Though might do a basic size verification before the pull-in takes place
8195fe58019SAttilio Rao  */
8205fe58019SAttilio Rao 
8215fe58019SAttilio Rao static int
8225fe58019SAttilio Rao fuse_standard_handler(struct fuse_ticket *ftick, struct uio *uio)
8235fe58019SAttilio Rao {
8245fe58019SAttilio Rao 	int err = 0;
8255fe58019SAttilio Rao 
8265fe58019SAttilio Rao 	err = fticket_pull(ftick, uio);
8275fe58019SAttilio Rao 
8285fe58019SAttilio Rao 	fuse_lck_mtx_lock(ftick->tk_aw_mtx);
8295fe58019SAttilio Rao 
8305fe58019SAttilio Rao 	if (!fticket_answered(ftick)) {
8315fe58019SAttilio Rao 		fticket_set_answered(ftick);
8325fe58019SAttilio Rao 		ftick->tk_aw_errno = err;
8335fe58019SAttilio Rao 		wakeup(ftick);
8345fe58019SAttilio Rao 	}
8355fe58019SAttilio Rao 	fuse_lck_mtx_unlock(ftick->tk_aw_mtx);
8365fe58019SAttilio Rao 
8375fe58019SAttilio Rao 	return err;
8385fe58019SAttilio Rao }
8395fe58019SAttilio Rao 
84012292a99SAlan Somers /*
84112292a99SAlan Somers  * Reinitialize a dispatcher from a pid and node id, without resizing or
84212292a99SAlan Somers  * clearing its data buffers
84312292a99SAlan Somers  */
84412292a99SAlan Somers static void
84512292a99SAlan Somers fdisp_refresh_pid(struct fuse_dispatcher *fdip, enum fuse_opcode op,
84612292a99SAlan Somers     struct mount *mp, uint64_t nid, pid_t pid, struct ucred *cred)
84712292a99SAlan Somers {
84812292a99SAlan Somers 	MPASS(fdip->tick);
8498d013becSAlan Somers 	MPASS2(sizeof(fdip->finh) + fdip->iosize <= fdip->tick->tk_ms_fiov.len,
8508d013becSAlan Somers 		"Must use fdisp_make_pid to increase the size of the fiov");
85112292a99SAlan Somers 	fticket_reset(fdip->tick);
85212292a99SAlan Somers 
85312292a99SAlan Somers 	FUSE_DIMALLOC(&fdip->tick->tk_ms_fiov, fdip->finh,
85412292a99SAlan Somers 	    fdip->indata, fdip->iosize);
85512292a99SAlan Somers 
85612292a99SAlan Somers 	fuse_setup_ihead(fdip->finh, fdip->tick, nid, op, fdip->iosize, pid,
85712292a99SAlan Somers 		cred);
85812292a99SAlan Somers }
85912292a99SAlan Somers 
86012292a99SAlan Somers /* Initialize a dispatcher from a pid and node id */
86112292a99SAlan Somers static void
86202295cafSConrad Meyer fdisp_make_pid(struct fuse_dispatcher *fdip, enum fuse_opcode op,
863*723c7768SAlan Somers     struct fuse_data *data, uint64_t nid, pid_t pid, struct ucred *cred)
8645fe58019SAttilio Rao {
8655fe58019SAttilio Rao 	if (fdip->tick) {
8665fe58019SAttilio Rao 		fticket_refresh(fdip->tick);
8675fe58019SAttilio Rao 	} else {
8685fe58019SAttilio Rao 		fdip->tick = fuse_ticket_fetch(data);
8695fe58019SAttilio Rao 	}
8705fe58019SAttilio Rao 
8718d013becSAlan Somers 	/* FUSE_DIMALLOC will bzero the fiovs when it enlarges them */
8725fe58019SAttilio Rao 	FUSE_DIMALLOC(&fdip->tick->tk_ms_fiov, fdip->finh,
8735fe58019SAttilio Rao 	    fdip->indata, fdip->iosize);
8745fe58019SAttilio Rao 
8755fe58019SAttilio Rao 	fuse_setup_ihead(fdip->finh, fdip->tick, nid, op, fdip->iosize, pid, cred);
8765fe58019SAttilio Rao }
8775fe58019SAttilio Rao 
8785fe58019SAttilio Rao void
87902295cafSConrad Meyer fdisp_make(struct fuse_dispatcher *fdip, enum fuse_opcode op, struct mount *mp,
88002295cafSConrad Meyer     uint64_t nid, struct thread *td, struct ucred *cred)
8815fe58019SAttilio Rao {
882*723c7768SAlan Somers 	struct fuse_data *data = fuse_get_mpdata(mp);
8835fe58019SAttilio Rao 	RECTIFY_TDCR(td, cred);
8845fe58019SAttilio Rao 
885*723c7768SAlan Somers 	return fdisp_make_pid(fdip, op, data, nid, td->td_proc->p_pid, cred);
8865fe58019SAttilio Rao }
8875fe58019SAttilio Rao 
8885fe58019SAttilio Rao void
88902295cafSConrad Meyer fdisp_make_vp(struct fuse_dispatcher *fdip, enum fuse_opcode op,
89002295cafSConrad Meyer     struct vnode *vp, struct thread *td, struct ucred *cred)
8915fe58019SAttilio Rao {
892*723c7768SAlan Somers 	struct mount *mp = vnode_mount(vp);
893*723c7768SAlan Somers 	struct fuse_data *data = fuse_get_mpdata(mp);
894*723c7768SAlan Somers 
8955fe58019SAttilio Rao 	RECTIFY_TDCR(td, cred);
896*723c7768SAlan Somers 	return fdisp_make_pid(fdip, op, data, VTOI(vp),
8975fe58019SAttilio Rao 	    td->td_proc->p_pid, cred);
8985fe58019SAttilio Rao }
8995fe58019SAttilio Rao 
90012292a99SAlan Somers /* Refresh a fuse_dispatcher so it can be reused, but don't zero its data */
90112292a99SAlan Somers void
90212292a99SAlan Somers fdisp_refresh_vp(struct fuse_dispatcher *fdip, enum fuse_opcode op,
90312292a99SAlan Somers     struct vnode *vp, struct thread *td, struct ucred *cred)
90412292a99SAlan Somers {
90512292a99SAlan Somers 	RECTIFY_TDCR(td, cred);
90612292a99SAlan Somers 	return fdisp_refresh_pid(fdip, op, vnode_mount(vp), VTOI(vp),
90712292a99SAlan Somers 	    td->td_proc->p_pid, cred);
90812292a99SAlan Somers }
90912292a99SAlan Somers 
91012292a99SAlan Somers void
91112292a99SAlan Somers fdisp_refresh(struct fuse_dispatcher *fdip)
91212292a99SAlan Somers {
91312292a99SAlan Somers 	fticket_refresh(fdip->tick);
91412292a99SAlan Somers }
91512292a99SAlan Somers 
916cf169498SAlan Somers SDT_PROBE_DEFINE2(fuse, , ipc, fdisp_wait_answ_error, "char*", "int");
917cf169498SAlan Somers 
9185fe58019SAttilio Rao int
9195fe58019SAttilio Rao fdisp_wait_answ(struct fuse_dispatcher *fdip)
9205fe58019SAttilio Rao {
9215fe58019SAttilio Rao 	int err = 0;
9225fe58019SAttilio Rao 
9235fe58019SAttilio Rao 	fdip->answ_stat = 0;
9245fe58019SAttilio Rao 	fuse_insert_callback(fdip->tick, fuse_standard_handler);
9255fe58019SAttilio Rao 	fuse_insert_message(fdip->tick);
9265fe58019SAttilio Rao 
9275fe58019SAttilio Rao 	if ((err = fticket_wait_answer(fdip->tick))) {
9285fe58019SAttilio Rao 		fuse_lck_mtx_lock(fdip->tick->tk_aw_mtx);
9295fe58019SAttilio Rao 
9305fe58019SAttilio Rao 		if (fticket_answered(fdip->tick)) {
9315fe58019SAttilio Rao 			/*
9325fe58019SAttilio Rao 	                 * Just between noticing the interrupt and getting here,
9335fe58019SAttilio Rao 	                 * the standard handler has completed his job.
9345fe58019SAttilio Rao 	                 * So we drop the ticket and exit as usual.
9355fe58019SAttilio Rao 	                 */
936cf169498SAlan Somers 			SDT_PROBE2(fuse, , ipc, fdisp_wait_answ_error,
937cf169498SAlan Somers 				"IPC: interrupted, already answered", err);
9385fe58019SAttilio Rao 			fuse_lck_mtx_unlock(fdip->tick->tk_aw_mtx);
9395fe58019SAttilio Rao 			goto out;
9405fe58019SAttilio Rao 		} else {
9415fe58019SAttilio Rao 			/*
9425fe58019SAttilio Rao 	                 * So we were faster than the standard handler.
9435fe58019SAttilio Rao 	                 * Then by setting the answered flag we get *him*
9445fe58019SAttilio Rao 	                 * to drop the ticket.
9455fe58019SAttilio Rao 	                 */
946cf169498SAlan Somers 			SDT_PROBE2(fuse, , ipc, fdisp_wait_answ_error,
947cf169498SAlan Somers 				"IPC: interrupted, setting to answered", err);
9485fe58019SAttilio Rao 			fticket_set_answered(fdip->tick);
9495fe58019SAttilio Rao 			fuse_lck_mtx_unlock(fdip->tick->tk_aw_mtx);
9505fe58019SAttilio Rao 			return err;
9515fe58019SAttilio Rao 		}
9525fe58019SAttilio Rao 	}
9535fe58019SAttilio Rao 
9545fe58019SAttilio Rao 	if (fdip->tick->tk_aw_errno) {
955cf169498SAlan Somers 		SDT_PROBE2(fuse, , ipc, fdisp_wait_answ_error,
956cf169498SAlan Somers 			"IPC: explicit EIO-ing", fdip->tick->tk_aw_errno);
9575fe58019SAttilio Rao 		err = EIO;
9585fe58019SAttilio Rao 		goto out;
9595fe58019SAttilio Rao 	}
9605fe58019SAttilio Rao 	if ((err = fdip->tick->tk_aw_ohead.error)) {
961cf169498SAlan Somers 		SDT_PROBE2(fuse, , ipc, fdisp_wait_answ_error,
962cf169498SAlan Somers 			"IPC: setting status", fdip->tick->tk_aw_ohead.error);
9635fe58019SAttilio Rao 		/*
9645fe58019SAttilio Rao 	         * This means a "proper" fuse syscall error.
9655fe58019SAttilio Rao 	         * We record this value so the caller will
9665fe58019SAttilio Rao 	         * be able to know it's not a boring messaging
9675fe58019SAttilio Rao 	         * failure, if she wishes so (and if not, she can
9685fe58019SAttilio Rao 	         * just simply propagate the return value of this routine).
9695fe58019SAttilio Rao 	         * [XXX Maybe a bitflag would do the job too,
9705fe58019SAttilio Rao 	         * if other flags needed, this will be converted thusly.]
9715fe58019SAttilio Rao 	         */
9725fe58019SAttilio Rao 		fdip->answ_stat = err;
9735fe58019SAttilio Rao 		goto out;
9745fe58019SAttilio Rao 	}
9755fe58019SAttilio Rao 	fdip->answ = fticket_resp(fdip->tick)->base;
9765fe58019SAttilio Rao 	fdip->iosize = fticket_resp(fdip->tick)->len;
9775fe58019SAttilio Rao 
9785fe58019SAttilio Rao 	return 0;
9795fe58019SAttilio Rao 
9805fe58019SAttilio Rao out:
9815fe58019SAttilio Rao 	return err;
9825fe58019SAttilio Rao }
9835fe58019SAttilio Rao 
9845fe58019SAttilio Rao void
9855fe58019SAttilio Rao fuse_ipc_init(void)
9865fe58019SAttilio Rao {
9875fe58019SAttilio Rao 	ticket_zone = uma_zcreate("fuse_ticket", sizeof(struct fuse_ticket),
9885fe58019SAttilio Rao 	    fticket_ctor, fticket_dtor, fticket_init, fticket_fini,
9895fe58019SAttilio Rao 	    UMA_ALIGN_PTR, 0);
9905fe58019SAttilio Rao }
9915fe58019SAttilio Rao 
9925fe58019SAttilio Rao void
9935fe58019SAttilio Rao fuse_ipc_destroy(void)
9945fe58019SAttilio Rao {
9955fe58019SAttilio Rao 	uma_zdestroy(ticket_zone);
9965fe58019SAttilio Rao }
997