xref: /linux/fs/overlayfs/overlayfs.h (revision b61104e7a6349bd2c2b3e2fb3260d87f15eda8f4)
1 /* SPDX-License-Identifier: GPL-2.0-only */
2 /*
3  *
4  * Copyright (C) 2011 Novell Inc.
5  */
6 
7 #include <linux/kernel.h>
8 #include <linux/uuid.h>
9 #include <linux/fs.h>
10 #include <linux/fsverity.h>
11 #include <linux/namei.h>
12 #include <linux/posix_acl.h>
13 #include <linux/posix_acl_xattr.h>
14 #include "ovl_entry.h"
15 
16 #undef pr_fmt
17 #define pr_fmt(fmt) "overlayfs: " fmt
18 
19 enum ovl_path_type {
20 	__OVL_PATH_UPPER	= (1 << 0),
21 	__OVL_PATH_MERGE	= (1 << 1),
22 	__OVL_PATH_ORIGIN	= (1 << 2),
23 };
24 
25 #define OVL_TYPE_UPPER(type)	((type) & __OVL_PATH_UPPER)
26 #define OVL_TYPE_MERGE(type)	((type) & __OVL_PATH_MERGE)
27 #define OVL_TYPE_ORIGIN(type)	((type) & __OVL_PATH_ORIGIN)
28 
29 #define OVL_XATTR_NAMESPACE "overlay."
30 #define OVL_XATTR_TRUSTED_PREFIX XATTR_TRUSTED_PREFIX OVL_XATTR_NAMESPACE
31 #define OVL_XATTR_TRUSTED_PREFIX_LEN (sizeof(OVL_XATTR_TRUSTED_PREFIX) - 1)
32 #define OVL_XATTR_USER_PREFIX XATTR_USER_PREFIX OVL_XATTR_NAMESPACE
33 #define OVL_XATTR_USER_PREFIX_LEN (sizeof(OVL_XATTR_USER_PREFIX) - 1)
34 
35 #define OVL_XATTR_ESCAPE_PREFIX OVL_XATTR_NAMESPACE
36 #define OVL_XATTR_ESCAPE_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_PREFIX) - 1)
37 #define OVL_XATTR_ESCAPE_TRUSTED_PREFIX OVL_XATTR_TRUSTED_PREFIX OVL_XATTR_ESCAPE_PREFIX
38 #define OVL_XATTR_ESCAPE_TRUSTED_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_TRUSTED_PREFIX) - 1)
39 #define OVL_XATTR_ESCAPE_USER_PREFIX OVL_XATTR_USER_PREFIX OVL_XATTR_ESCAPE_PREFIX
40 #define OVL_XATTR_ESCAPE_USER_PREFIX_LEN (sizeof(OVL_XATTR_ESCAPE_USER_PREFIX) - 1)
41 
42 enum ovl_xattr {
43 	OVL_XATTR_OPAQUE,
44 	OVL_XATTR_REDIRECT,
45 	OVL_XATTR_ORIGIN,
46 	OVL_XATTR_IMPURE,
47 	OVL_XATTR_NLINK,
48 	OVL_XATTR_UPPER,
49 	OVL_XATTR_UUID,
50 	OVL_XATTR_METACOPY,
51 	OVL_XATTR_PROTATTR,
52 	OVL_XATTR_XWHITEOUT,
53 };
54 
55 enum ovl_inode_flag {
56 	/* Pure upper dir that may contain non pure upper entries */
57 	OVL_IMPURE,
58 	/* Non-merge dir that may contain whiteout entries */
59 	OVL_WHITEOUTS,
60 	OVL_INDEX,
61 	OVL_UPPERDATA,
62 	/* Inode number will remain constant over copy up. */
63 	OVL_CONST_INO,
64 	OVL_HAS_DIGEST,
65 	OVL_VERIFIED_DIGEST,
66 };
67 
68 enum ovl_entry_flag {
69 	OVL_E_UPPER_ALIAS,
70 	OVL_E_OPAQUE,
71 	OVL_E_CONNECTED,
72 	/* Lower stack may contain xwhiteout entries */
73 	OVL_E_XWHITEOUTS,
74 };
75 
76 enum {
77 	OVL_REDIRECT_OFF,	/* "off" mode is never used. In effect	*/
78 	OVL_REDIRECT_FOLLOW,	/* ...it translates to either "follow"	*/
79 	OVL_REDIRECT_NOFOLLOW,	/* ...or "nofollow".			*/
80 	OVL_REDIRECT_ON,
81 };
82 
83 enum {
84 	OVL_UUID_OFF,
85 	OVL_UUID_NULL,
86 	OVL_UUID_AUTO,
87 	OVL_UUID_ON,
88 };
89 
90 enum {
91 	OVL_XINO_OFF,
92 	OVL_XINO_AUTO,
93 	OVL_XINO_ON,
94 };
95 
96 enum {
97 	OVL_VERITY_OFF,
98 	OVL_VERITY_ON,
99 	OVL_VERITY_REQUIRE,
100 };
101 
102 /*
103  * The tuple (fh,uuid) is a universal unique identifier for a copy up origin,
104  * where:
105  * origin.fh	- exported file handle of the lower file
106  * origin.uuid	- uuid of the lower filesystem
107  */
108 #define OVL_FH_VERSION	0
109 #define OVL_FH_MAGIC	0xfb
110 
111 /* CPU byte order required for fid decoding:  */
112 #define OVL_FH_FLAG_BIG_ENDIAN	(1 << 0)
113 #define OVL_FH_FLAG_ANY_ENDIAN	(1 << 1)
114 /* Is the real inode encoded in fid an upper inode? */
115 #define OVL_FH_FLAG_PATH_UPPER	(1 << 2)
116 
117 #define OVL_FH_FLAG_ALL (OVL_FH_FLAG_BIG_ENDIAN | OVL_FH_FLAG_ANY_ENDIAN | \
118 			 OVL_FH_FLAG_PATH_UPPER)
119 
120 #if defined(__LITTLE_ENDIAN)
121 #define OVL_FH_FLAG_CPU_ENDIAN 0
122 #elif defined(__BIG_ENDIAN)
123 #define OVL_FH_FLAG_CPU_ENDIAN OVL_FH_FLAG_BIG_ENDIAN
124 #else
125 #error Endianness not defined
126 #endif
127 
128 /* The type used to be returned by overlay exportfs for misaligned fid */
129 #define OVL_FILEID_V0	0xfb
130 /* The type returned by overlay exportfs for 32bit aligned fid */
131 #define OVL_FILEID_V1	0xf8
132 
133 /* On-disk format for "origin" file handle */
134 struct ovl_fb {
135 	u8 version;	/* 0 */
136 	u8 magic;	/* 0xfb */
137 	u8 len;		/* size of this header + size of fid */
138 	u8 flags;	/* OVL_FH_FLAG_* */
139 	u8 type;	/* fid_type of fid */
140 	uuid_t uuid;	/* uuid of filesystem */
141 	u32 fid[];	/* file identifier should be 32bit aligned in-memory */
142 } __packed;
143 
144 /* In-memory and on-wire format for overlay file handle */
145 struct ovl_fh {
146 	u8 padding[3];	/* make sure fb.fid is 32bit aligned */
147 	union {
148 		struct ovl_fb fb;
149 		DECLARE_FLEX_ARRAY(u8, buf);
150 	};
151 } __packed;
152 
153 #define OVL_FH_WIRE_OFFSET	offsetof(struct ovl_fh, fb)
154 #define OVL_FH_LEN(fh)		(OVL_FH_WIRE_OFFSET + (fh)->fb.len)
155 #define OVL_FH_FID_OFFSET	(OVL_FH_WIRE_OFFSET + \
156 				 offsetof(struct ovl_fb, fid))
157 
158 /* On-disk format for "metacopy" xattr (if non-zero size) */
159 struct ovl_metacopy {
160 	u8 version;	/* 0 */
161 	u8 len;         /* size of this header + used digest bytes */
162 	u8 flags;
163 	u8 digest_algo;	/* FS_VERITY_HASH_ALG_* constant, 0 for no digest */
164 	u8 digest[FS_VERITY_MAX_DIGEST_SIZE];  /* Only the used part on disk */
165 } __packed;
166 
167 #define OVL_METACOPY_MAX_SIZE (sizeof(struct ovl_metacopy))
168 #define OVL_METACOPY_MIN_SIZE (OVL_METACOPY_MAX_SIZE - FS_VERITY_MAX_DIGEST_SIZE)
169 #define OVL_METACOPY_INIT { 0, OVL_METACOPY_MIN_SIZE }
170 
171 static inline int ovl_metadata_digest_size(const struct ovl_metacopy *metacopy)
172 {
173 	if (metacopy->len < OVL_METACOPY_MIN_SIZE)
174 		return 0;
175 	return (int)metacopy->len - OVL_METACOPY_MIN_SIZE;
176 }
177 
178 /* No atime modification on underlying */
179 #define OVL_OPEN_FLAGS (O_NOATIME)
180 
181 extern const char *const ovl_xattr_table[][2];
182 static inline const char *ovl_xattr(struct ovl_fs *ofs, enum ovl_xattr ox)
183 {
184 	return ovl_xattr_table[ox][ofs->config.userxattr];
185 }
186 
187 /*
188  * When changing ownership of an upper object map the intended ownership
189  * according to the upper layer's idmapping. When an upper mount idmaps files
190  * that are stored on-disk as owned by id 1001 to id 1000 this means stat on
191  * this object will report it as being owned by id 1000 when calling stat via
192  * the upper mount.
193  * In order to change ownership of an object so stat reports id 1000 when
194  * called on an idmapped upper mount the value written to disk - i.e., the
195  * value stored in ia_*id - must 1001. The mount mapping helper will thus take
196  * care to map 1000 to 1001.
197  * The mnt idmapping helpers are nops if the upper layer isn't idmapped.
198  */
199 static inline int ovl_do_notify_change(struct ovl_fs *ofs,
200 				       struct dentry *upperdentry,
201 				       struct iattr *attr)
202 {
203 	return notify_change(ovl_upper_mnt_idmap(ofs), upperdentry, attr, NULL);
204 }
205 
206 static inline int ovl_do_rmdir(struct ovl_fs *ofs,
207 			       struct inode *dir, struct dentry *dentry)
208 {
209 	int err = vfs_rmdir(ovl_upper_mnt_idmap(ofs), dir, dentry, NULL);
210 
211 	pr_debug("rmdir(%pd2) = %i\n", dentry, err);
212 	return err;
213 }
214 
215 static inline int ovl_do_unlink(struct ovl_fs *ofs, struct inode *dir,
216 				struct dentry *dentry)
217 {
218 	int err = vfs_unlink(ovl_upper_mnt_idmap(ofs), dir, dentry, NULL);
219 
220 	pr_debug("unlink(%pd2) = %i\n", dentry, err);
221 	return err;
222 }
223 
224 static inline int ovl_do_link(struct ovl_fs *ofs, struct dentry *old_dentry,
225 			      struct inode *dir, struct dentry *new_dentry)
226 {
227 	int err = vfs_link(old_dentry, ovl_upper_mnt_idmap(ofs), dir,
228 			   new_dentry, NULL);
229 
230 	pr_debug("link(%pd2, %pd2) = %i\n", old_dentry, new_dentry, err);
231 	return err;
232 }
233 
234 static inline int ovl_do_create(struct ovl_fs *ofs,
235 				struct inode *dir, struct dentry *dentry,
236 				umode_t mode)
237 {
238 	int err = vfs_create(ovl_upper_mnt_idmap(ofs), dentry, mode, NULL);
239 
240 	pr_debug("create(%pd2, 0%o) = %i\n", dentry, mode, err);
241 	return err;
242 }
243 
244 static inline struct dentry *ovl_do_mkdir(struct ovl_fs *ofs,
245 					  struct inode *dir,
246 					  struct dentry *dentry,
247 					  umode_t mode)
248 {
249 	struct dentry *ret;
250 
251 	ret = vfs_mkdir(ovl_upper_mnt_idmap(ofs), dir, dentry, mode, NULL);
252 	pr_debug("mkdir(%pd2, 0%o) = %i\n", dentry, mode, PTR_ERR_OR_ZERO(ret));
253 	return ret;
254 }
255 
256 static inline int ovl_do_mknod(struct ovl_fs *ofs,
257 			       struct inode *dir, struct dentry *dentry,
258 			       umode_t mode, dev_t dev)
259 {
260 	int err = vfs_mknod(ovl_upper_mnt_idmap(ofs), dir, dentry, mode, dev, NULL);
261 
262 	pr_debug("mknod(%pd2, 0%o, 0%o) = %i\n", dentry, mode, dev, err);
263 	return err;
264 }
265 
266 static inline int ovl_do_symlink(struct ovl_fs *ofs,
267 				 struct inode *dir, struct dentry *dentry,
268 				 const char *oldname)
269 {
270 	int err = vfs_symlink(ovl_upper_mnt_idmap(ofs), dir, dentry, oldname, NULL);
271 
272 	pr_debug("symlink(\"%s\", %pd2) = %i\n", oldname, dentry, err);
273 	return err;
274 }
275 
276 static inline ssize_t ovl_do_getxattr(const struct path *path, const char *name,
277 				      void *value, size_t size)
278 {
279 	int err, len;
280 
281 	WARN_ON(path->dentry->d_sb != path->mnt->mnt_sb);
282 
283 	err = vfs_getxattr(mnt_idmap(path->mnt), path->dentry,
284 			       name, value, size);
285 	len = (value && err > 0) ? err : 0;
286 
287 	pr_debug("getxattr(%pd2, \"%s\", \"%*pE\", %zu, 0) = %i\n",
288 		 path->dentry, name, min(len, 48), value, size, err);
289 	return err;
290 }
291 
292 static inline ssize_t ovl_getxattr_upper(struct ovl_fs *ofs,
293 					 struct dentry *upperdentry,
294 					 enum ovl_xattr ox, void *value,
295 					 size_t size)
296 {
297 	struct path upperpath = {
298 		.dentry = upperdentry,
299 		.mnt = ovl_upper_mnt(ofs),
300 	};
301 
302 	return ovl_do_getxattr(&upperpath, ovl_xattr(ofs, ox), value, size);
303 }
304 
305 static inline ssize_t ovl_path_getxattr(struct ovl_fs *ofs,
306 					 const struct path *path,
307 					 enum ovl_xattr ox, void *value,
308 					 size_t size)
309 {
310 	return ovl_do_getxattr(path, ovl_xattr(ofs, ox), value, size);
311 }
312 
313 static inline int ovl_do_setxattr(struct ovl_fs *ofs, struct dentry *dentry,
314 				  const char *name, const void *value,
315 				  size_t size, int flags)
316 {
317 	int err = vfs_setxattr(ovl_upper_mnt_idmap(ofs), dentry, name,
318 			       value, size, flags);
319 
320 	pr_debug("setxattr(%pd2, \"%s\", \"%*pE\", %zu, %d) = %i\n",
321 		 dentry, name, min((int)size, 48), value, size, flags, err);
322 	return err;
323 }
324 
325 static inline int ovl_setxattr(struct ovl_fs *ofs, struct dentry *dentry,
326 			       enum ovl_xattr ox, const void *value,
327 			       size_t size)
328 {
329 	return ovl_do_setxattr(ofs, dentry, ovl_xattr(ofs, ox), value, size, 0);
330 }
331 
332 static inline int ovl_do_removexattr(struct ovl_fs *ofs, struct dentry *dentry,
333 				     const char *name)
334 {
335 	int err = vfs_removexattr(ovl_upper_mnt_idmap(ofs), dentry, name);
336 	pr_debug("removexattr(%pd2, \"%s\") = %i\n", dentry, name, err);
337 	return err;
338 }
339 
340 static inline int ovl_removexattr(struct ovl_fs *ofs, struct dentry *dentry,
341 				  enum ovl_xattr ox)
342 {
343 	return ovl_do_removexattr(ofs, dentry, ovl_xattr(ofs, ox));
344 }
345 
346 static inline int ovl_do_set_acl(struct ovl_fs *ofs, struct dentry *dentry,
347 				 const char *acl_name, struct posix_acl *acl)
348 {
349 	return vfs_set_acl(ovl_upper_mnt_idmap(ofs), dentry, acl_name, acl);
350 }
351 
352 static inline int ovl_do_remove_acl(struct ovl_fs *ofs, struct dentry *dentry,
353 				    const char *acl_name)
354 {
355 	return vfs_remove_acl(ovl_upper_mnt_idmap(ofs), dentry, acl_name);
356 }
357 
358 static inline int ovl_do_rename_rd(struct renamedata *rd)
359 {
360 	int err;
361 
362 	pr_debug("rename(%pd2, %pd2, 0x%x)\n", rd->old_dentry, rd->new_dentry,
363 		 rd->flags);
364 	err = vfs_rename(rd);
365 	if (err) {
366 		pr_debug("...rename(%pd2, %pd2, ...) = %i\n",
367 			 rd->old_dentry, rd->new_dentry, err);
368 	}
369 	return err;
370 }
371 
372 static inline int ovl_do_rename(struct ovl_fs *ofs, struct dentry *olddir,
373 				struct dentry *olddentry, struct dentry *newdir,
374 				struct dentry *newdentry, unsigned int flags)
375 {
376 	struct renamedata rd = {
377 		.mnt_idmap	= ovl_upper_mnt_idmap(ofs),
378 		.old_parent	= olddir,
379 		.old_dentry	= olddentry,
380 		.new_parent	= newdir,
381 		.new_dentry	= newdentry,
382 		.flags		= flags,
383 	};
384 
385 	return ovl_do_rename_rd(&rd);
386 }
387 
388 static inline int ovl_do_whiteout(struct ovl_fs *ofs,
389 				  struct inode *dir, struct dentry *dentry)
390 {
391 	int err = vfs_whiteout(ovl_upper_mnt_idmap(ofs), dir, dentry);
392 	pr_debug("whiteout(%pd2) = %i\n", dentry, err);
393 	return err;
394 }
395 
396 static inline struct file *ovl_do_tmpfile(struct ovl_fs *ofs,
397 					  struct dentry *dentry, umode_t mode)
398 {
399 	struct path path = { .mnt = ovl_upper_mnt(ofs), .dentry = dentry };
400 	struct file *file = kernel_tmpfile_open(ovl_upper_mnt_idmap(ofs), &path,
401 						mode, O_LARGEFILE | O_WRONLY,
402 						current_cred());
403 	int err = PTR_ERR_OR_ZERO(file);
404 
405 	pr_debug("tmpfile(%pd2, 0%o) = %i\n", dentry, mode, err);
406 	return file;
407 }
408 
409 static inline struct dentry *ovl_lookup_upper(struct ovl_fs *ofs,
410 					      const char *name,
411 					      struct dentry *base, int len)
412 {
413 	return lookup_one(ovl_upper_mnt_idmap(ofs), &QSTR_LEN(name, len), base);
414 }
415 
416 static inline struct dentry *ovl_lookup_upper_unlocked(struct ovl_fs *ofs,
417 						       const char *name,
418 						       struct dentry *base,
419 						       int len)
420 {
421 	return lookup_one_unlocked(ovl_upper_mnt_idmap(ofs),
422 				   &QSTR_LEN(name, len), base);
423 }
424 
425 static inline struct dentry *ovl_start_creating_upper(struct ovl_fs *ofs,
426 						      struct dentry *parent,
427 						      struct qstr *name)
428 {
429 	return start_creating(ovl_upper_mnt_idmap(ofs),
430 			      parent, name);
431 }
432 
433 static inline struct dentry *ovl_start_removing_upper(struct ovl_fs *ofs,
434 						      struct dentry *parent,
435 						      struct qstr *name)
436 {
437 	return start_removing(ovl_upper_mnt_idmap(ofs),
438 			      parent, name);
439 }
440 
441 static inline bool ovl_open_flags_need_copy_up(int flags)
442 {
443 	if (!flags)
444 		return false;
445 
446 	return ((OPEN_FMODE(flags) & FMODE_WRITE) || (flags & O_TRUNC));
447 }
448 
449 /* util.c */
450 int ovl_get_write_access(struct dentry *dentry);
451 void ovl_put_write_access(struct dentry *dentry);
452 void ovl_start_write(struct dentry *dentry);
453 void ovl_end_write(struct dentry *dentry);
454 int ovl_want_write(struct dentry *dentry);
455 void ovl_drop_write(struct dentry *dentry);
456 struct dentry *ovl_workdir(struct dentry *dentry);
457 const struct cred *ovl_override_creds(struct super_block *sb);
458 
459 EXTEND_CLASS(override_creds, _ovl, ovl_override_creds(sb), struct super_block *sb)
460 
461 #define with_ovl_creds(sb) \
462 	scoped_class(override_creds_ovl, __UNIQUE_ID(label), sb)
463 
464 static inline const struct cred *ovl_creds(struct super_block *sb)
465 {
466 	return OVL_FS(sb)->creator_cred;
467 }
468 
469 int ovl_can_decode_fh(struct super_block *sb);
470 struct dentry *ovl_indexdir(struct super_block *sb);
471 bool ovl_index_all(struct super_block *sb);
472 bool ovl_verify_lower(struct super_block *sb);
473 struct ovl_path *ovl_stack_alloc(unsigned int n);
474 void ovl_stack_cpy(struct ovl_path *dst, struct ovl_path *src, unsigned int n);
475 void ovl_stack_put(struct ovl_path *stack, unsigned int n);
476 void ovl_stack_free(struct ovl_path *stack, unsigned int n);
477 struct ovl_entry *ovl_alloc_entry(unsigned int numlower);
478 void ovl_free_entry(struct ovl_entry *oe);
479 bool ovl_dentry_remote(struct dentry *dentry);
480 void ovl_dentry_update_reval(struct dentry *dentry, struct dentry *realdentry);
481 void ovl_dentry_init_reval(struct dentry *dentry, struct dentry *upperdentry,
482 			   struct ovl_entry *oe);
483 void ovl_dentry_init_flags(struct dentry *dentry, struct dentry *upperdentry,
484 			   struct ovl_entry *oe, unsigned int mask);
485 bool ovl_dentry_weird(struct dentry *dentry);
486 
487 static inline bool ovl_dentry_casefolded(struct dentry *dentry)
488 {
489 	return sb_has_encoding(dentry->d_sb) && IS_CASEFOLDED(d_inode(dentry));
490 }
491 
492 enum ovl_path_type ovl_path_type(struct dentry *dentry);
493 void ovl_path_upper(struct dentry *dentry, struct path *path);
494 void ovl_path_lower(struct dentry *dentry, struct path *path);
495 void ovl_path_lowerdata(struct dentry *dentry, struct path *path);
496 struct inode *ovl_i_path_real(struct inode *inode, struct path *path);
497 enum ovl_path_type ovl_path_real(struct dentry *dentry, struct path *path);
498 enum ovl_path_type ovl_path_realdata(struct dentry *dentry, struct path *path);
499 struct dentry *ovl_dentry_upper(struct dentry *dentry);
500 struct dentry *ovl_dentry_lower(struct dentry *dentry);
501 struct dentry *ovl_dentry_lowerdata(struct dentry *dentry);
502 int ovl_dentry_set_lowerdata(struct dentry *dentry, struct ovl_path *datapath);
503 const struct ovl_layer *ovl_i_layer_lower(struct inode *inode);
504 const struct ovl_layer *ovl_layer_lower(struct dentry *dentry);
505 struct dentry *ovl_dentry_real(struct dentry *dentry);
506 struct dentry *ovl_i_dentry_upper(struct inode *inode);
507 struct inode *ovl_inode_upper(struct inode *inode);
508 struct inode *ovl_inode_lower(struct inode *inode);
509 struct inode *ovl_inode_lowerdata(struct inode *inode);
510 struct inode *ovl_inode_real(struct inode *inode);
511 struct inode *ovl_inode_realdata(struct inode *inode);
512 const char *ovl_lowerdata_redirect(struct inode *inode);
513 struct ovl_dir_cache *ovl_dir_cache(struct inode *inode);
514 void ovl_set_dir_cache(struct inode *inode, struct ovl_dir_cache *cache);
515 void ovl_dentry_set_flag(unsigned long flag, struct dentry *dentry);
516 void ovl_dentry_clear_flag(unsigned long flag, struct dentry *dentry);
517 bool ovl_dentry_test_flag(unsigned long flag, struct dentry *dentry);
518 bool ovl_dentry_is_opaque(struct dentry *dentry);
519 bool ovl_dentry_is_whiteout(struct dentry *dentry);
520 void ovl_dentry_set_opaque(struct dentry *dentry);
521 bool ovl_dentry_has_xwhiteouts(struct dentry *dentry);
522 void ovl_dentry_set_xwhiteouts(struct dentry *dentry);
523 void ovl_layer_set_xwhiteouts(struct ovl_fs *ofs,
524 			      const struct ovl_layer *layer);
525 bool ovl_dentry_has_upper_alias(struct dentry *dentry);
526 void ovl_dentry_set_upper_alias(struct dentry *dentry);
527 bool ovl_dentry_needs_data_copy_up(struct dentry *dentry, int flags);
528 bool ovl_dentry_needs_data_copy_up_locked(struct dentry *dentry, int flags);
529 bool ovl_has_upperdata(struct inode *inode);
530 void ovl_set_upperdata(struct inode *inode);
531 const char *ovl_dentry_get_redirect(struct dentry *dentry);
532 void ovl_dentry_set_redirect(struct dentry *dentry, const char *redirect);
533 void ovl_inode_update(struct inode *inode, struct dentry *upperdentry);
534 void ovl_dir_modified(struct dentry *dentry, bool impurity);
535 u64 ovl_inode_version_get(struct inode *inode);
536 bool ovl_is_whiteout(struct dentry *dentry);
537 bool ovl_path_is_whiteout(struct ovl_fs *ofs, const struct path *path);
538 struct file *ovl_path_open(const struct path *path, int flags);
539 int ovl_copy_up_start(struct dentry *dentry, int flags);
540 void ovl_copy_up_end(struct dentry *dentry);
541 bool ovl_already_copied_up(struct dentry *dentry, int flags);
542 char ovl_get_dir_xattr_val(struct ovl_fs *ofs, const struct path *path,
543 			   enum ovl_xattr ox);
544 bool ovl_path_check_origin_xattr(struct ovl_fs *ofs, const struct path *path);
545 bool ovl_path_check_xwhiteout_xattr(struct ovl_fs *ofs, const struct path *path);
546 bool ovl_init_uuid_xattr(struct super_block *sb, struct ovl_fs *ofs,
547 			 const struct path *upperpath);
548 
549 static inline bool ovl_upper_is_whiteout(struct ovl_fs *ofs,
550 					 struct dentry *upperdentry)
551 {
552 	struct path upperpath = {
553 		.dentry = upperdentry,
554 		.mnt = ovl_upper_mnt(ofs),
555 	};
556 	return ovl_path_is_whiteout(ofs, &upperpath);
557 }
558 
559 static inline bool ovl_check_origin_xattr(struct ovl_fs *ofs,
560 					  struct dentry *upperdentry)
561 {
562 	struct path upperpath = {
563 		.dentry = upperdentry,
564 		.mnt = ovl_upper_mnt(ofs),
565 	};
566 	return ovl_path_check_origin_xattr(ofs, &upperpath);
567 }
568 
569 int ovl_check_setxattr(struct ovl_fs *ofs, struct dentry *upperdentry,
570 		       enum ovl_xattr ox, const void *value, size_t size,
571 		       int xerr);
572 int ovl_set_impure(struct dentry *dentry, struct dentry *upperdentry);
573 bool ovl_inuse_trylock(struct dentry *dentry);
574 void ovl_inuse_unlock(struct dentry *dentry);
575 bool ovl_is_inuse(struct dentry *dentry);
576 bool ovl_need_index(struct dentry *dentry);
577 int ovl_nlink_start(struct dentry *dentry);
578 void ovl_nlink_end(struct dentry *dentry);
579 int ovl_lock_rename_workdir(struct dentry *workdir, struct dentry *work,
580 			    struct dentry *upperdir, struct dentry *upper);
581 int ovl_check_metacopy_xattr(struct ovl_fs *ofs, const struct path *path,
582 			     struct ovl_metacopy *data);
583 int ovl_set_metacopy_xattr(struct ovl_fs *ofs, struct dentry *d,
584 			   struct ovl_metacopy *metacopy);
585 bool ovl_is_metacopy_dentry(struct dentry *dentry);
586 char *ovl_get_redirect_xattr(struct ovl_fs *ofs, const struct path *path, int padding);
587 int ovl_ensure_verity_loaded(const struct path *path);
588 int ovl_validate_verity(struct ovl_fs *ofs,
589 			const struct path *metapath,
590 			const struct path *datapath);
591 int ovl_get_verity_digest(struct ovl_fs *ofs, const struct path *src,
592 			  struct ovl_metacopy *metacopy);
593 int ovl_sync_status(struct ovl_fs *ofs);
594 
595 static inline void ovl_set_flag(unsigned long flag, struct inode *inode)
596 {
597 	set_bit(flag, &OVL_I(inode)->flags);
598 }
599 
600 static inline void ovl_clear_flag(unsigned long flag, struct inode *inode)
601 {
602 	clear_bit(flag, &OVL_I(inode)->flags);
603 }
604 
605 static inline bool ovl_test_flag(unsigned long flag, struct inode *inode)
606 {
607 	return test_bit(flag, &OVL_I(inode)->flags);
608 }
609 
610 static inline bool ovl_is_impuredir(struct super_block *sb,
611 				    struct dentry *upperdentry)
612 {
613 	struct ovl_fs *ofs = OVL_FS(sb);
614 	struct path upperpath = {
615 		.dentry = upperdentry,
616 		.mnt = ovl_upper_mnt(ofs),
617 	};
618 
619 	return ovl_get_dir_xattr_val(ofs, &upperpath, OVL_XATTR_IMPURE) == 'y';
620 }
621 
622 static inline char ovl_get_opaquedir_val(struct ovl_fs *ofs,
623 					 const struct path *path)
624 {
625 	return ovl_get_dir_xattr_val(ofs, path, OVL_XATTR_OPAQUE);
626 }
627 
628 static inline bool ovl_redirect_follow(struct ovl_fs *ofs)
629 {
630 	return ofs->config.redirect_mode != OVL_REDIRECT_NOFOLLOW;
631 }
632 
633 static inline bool ovl_redirect_dir(struct ovl_fs *ofs)
634 {
635 	return ofs->config.redirect_mode == OVL_REDIRECT_ON;
636 }
637 
638 static inline bool ovl_origin_uuid(struct ovl_fs *ofs)
639 {
640 	return ofs->config.uuid != OVL_UUID_OFF;
641 }
642 
643 static inline bool ovl_has_fsid(struct ovl_fs *ofs)
644 {
645 	return ofs->config.uuid == OVL_UUID_ON ||
646 	       ofs->config.uuid == OVL_UUID_AUTO;
647 }
648 
649 /*
650  * With xino=auto, we do best effort to keep all inodes on same st_dev and
651  * d_ino consistent with st_ino.
652  * With xino=on, we do the same effort but we warn if we failed.
653  */
654 static inline bool ovl_xino_warn(struct ovl_fs *ofs)
655 {
656 	return ofs->config.xino == OVL_XINO_ON;
657 }
658 
659 /*
660  * To avoid regressions in existing setups with overlay lower offline changes,
661  * we allow lower changes only if none of the new features are used.
662  */
663 static inline bool ovl_allow_offline_changes(struct ovl_fs *ofs)
664 {
665 	return (!ofs->config.index && !ofs->config.metacopy &&
666 		!ovl_redirect_dir(ofs) && !ovl_xino_warn(ofs));
667 }
668 
669 /* All layers on same fs? */
670 static inline bool ovl_same_fs(struct ovl_fs *ofs)
671 {
672 	return ofs->xino_mode == 0;
673 }
674 
675 /* All overlay inodes have same st_dev? */
676 static inline bool ovl_same_dev(struct ovl_fs *ofs)
677 {
678 	return ofs->xino_mode >= 0;
679 }
680 
681 static inline unsigned int ovl_xino_bits(struct ovl_fs *ofs)
682 {
683 	return ovl_same_dev(ofs) ? ofs->xino_mode : 0;
684 }
685 
686 static inline void ovl_inode_lock(struct inode *inode)
687 {
688 	mutex_lock(&OVL_I(inode)->lock);
689 }
690 
691 static inline int ovl_inode_lock_interruptible(struct inode *inode)
692 {
693 	return mutex_lock_interruptible(&OVL_I(inode)->lock);
694 }
695 
696 static inline void ovl_inode_unlock(struct inode *inode)
697 {
698 	mutex_unlock(&OVL_I(inode)->lock);
699 }
700 
701 
702 /* namei.c */
703 int ovl_check_fb_len(struct ovl_fb *fb, int fb_len);
704 
705 static inline int ovl_check_fh_len(struct ovl_fh *fh, int fh_len)
706 {
707 	if (fh_len < sizeof(struct ovl_fh))
708 		return -EINVAL;
709 
710 	return ovl_check_fb_len(&fh->fb, fh_len - OVL_FH_WIRE_OFFSET);
711 }
712 
713 struct dentry *ovl_decode_real_fh(struct ovl_fs *ofs, struct ovl_fh *fh,
714 				  struct vfsmount *mnt, bool connected);
715 int ovl_check_origin_fh(struct ovl_fs *ofs, struct ovl_fh *fh, bool connected,
716 			struct dentry *upperdentry, struct ovl_path **stackp);
717 int ovl_verify_set_fh(struct ovl_fs *ofs, struct dentry *dentry,
718 		      enum ovl_xattr ox, const struct ovl_fh *fh,
719 		      bool is_upper, bool set);
720 int ovl_verify_origin_xattr(struct ovl_fs *ofs, struct dentry *dentry,
721 			    enum ovl_xattr ox, struct dentry *real,
722 			    bool is_upper, bool set);
723 struct dentry *ovl_index_upper(struct ovl_fs *ofs, struct dentry *index,
724 			       bool connected);
725 int ovl_verify_index(struct ovl_fs *ofs, struct dentry *index);
726 int ovl_get_index_name_fh(const struct ovl_fh *fh, struct qstr *name);
727 int ovl_get_index_name(struct ovl_fs *ofs, struct dentry *origin,
728 		       struct qstr *name);
729 struct dentry *ovl_get_index_fh(struct ovl_fs *ofs, struct ovl_fh *fh);
730 struct dentry *ovl_lookup_index(struct ovl_fs *ofs, struct dentry *upper,
731 				struct dentry *origin, bool verify);
732 int ovl_path_next(int idx, struct dentry *dentry, struct path *path,
733 		  const struct ovl_layer **layer);
734 int ovl_verify_lowerdata(struct dentry *dentry);
735 struct dentry *ovl_lookup(struct inode *dir, struct dentry *dentry,
736 			  unsigned int flags);
737 bool ovl_lower_positive(struct dentry *dentry);
738 
739 static inline int ovl_verify_origin_fh(struct ovl_fs *ofs, struct dentry *upper,
740 				       const struct ovl_fh *fh, bool set)
741 {
742 	return ovl_verify_set_fh(ofs, upper, OVL_XATTR_ORIGIN, fh, false, set);
743 }
744 
745 static inline int ovl_verify_origin(struct ovl_fs *ofs, struct dentry *upper,
746 				    struct dentry *origin, bool set)
747 {
748 	return ovl_verify_origin_xattr(ofs, upper, OVL_XATTR_ORIGIN, origin,
749 				       false, set);
750 }
751 
752 static inline int ovl_verify_upper(struct ovl_fs *ofs, struct dentry *index,
753 				   struct dentry *upper, bool set)
754 {
755 	return ovl_verify_origin_xattr(ofs, index, OVL_XATTR_UPPER, upper,
756 				       true, set);
757 }
758 
759 /* readdir.c */
760 extern const struct file_operations ovl_dir_operations;
761 struct file *ovl_dir_real_file(const struct file *file, bool want_upper);
762 int ovl_check_empty_dir(struct dentry *dentry, struct list_head *list);
763 void ovl_cleanup_whiteouts(struct ovl_fs *ofs, struct dentry *upper,
764 			   struct list_head *list);
765 void ovl_cache_free(struct list_head *list);
766 void ovl_dir_cache_free(struct inode *inode);
767 int ovl_check_d_type_supported(const struct path *realpath);
768 int ovl_workdir_cleanup(struct ovl_fs *ofs, struct dentry *parent,
769 			struct vfsmount *mnt, struct dentry *dentry, int level);
770 int ovl_indexdir_cleanup(struct ovl_fs *ofs);
771 
772 /*
773  * Can we iterate real dir directly?
774  *
775  * Non-merge dir may contain whiteouts from a time it was a merge upper, before
776  * lower dir was removed under it and possibly before it was rotated from upper
777  * to lower layer.
778  */
779 static inline bool ovl_dir_is_real(struct inode *dir)
780 {
781 	return !ovl_test_flag(OVL_WHITEOUTS, dir);
782 }
783 
784 /* inode.c */
785 int ovl_set_nlink_upper(struct dentry *dentry);
786 int ovl_set_nlink_lower(struct dentry *dentry);
787 unsigned int ovl_get_nlink(struct ovl_fs *ofs, struct dentry *lowerdentry,
788 			   struct dentry *upperdentry,
789 			   unsigned int fallback);
790 int ovl_permission(struct mnt_idmap *idmap, struct inode *inode,
791 		   int mask);
792 
793 #ifdef CONFIG_FS_POSIX_ACL
794 struct posix_acl *do_ovl_get_acl(struct mnt_idmap *idmap,
795 				 struct inode *inode, int type,
796 				 bool rcu, bool noperm);
797 static inline struct posix_acl *ovl_get_inode_acl(struct inode *inode, int type,
798 						  bool rcu)
799 {
800 	return do_ovl_get_acl(&nop_mnt_idmap, inode, type, rcu, true);
801 }
802 static inline struct posix_acl *ovl_get_acl(struct mnt_idmap *idmap,
803 					    struct dentry *dentry, int type)
804 {
805 	return do_ovl_get_acl(idmap, d_inode(dentry), type, false, false);
806 }
807 int ovl_set_acl(struct mnt_idmap *idmap, struct dentry *dentry,
808 		struct posix_acl *acl, int type);
809 struct posix_acl *ovl_get_acl_path(const struct path *path,
810 				   const char *acl_name, bool noperm);
811 #else
812 #define ovl_get_inode_acl	NULL
813 #define ovl_get_acl		NULL
814 #define ovl_set_acl		NULL
815 static inline struct posix_acl *ovl_get_acl_path(const struct path *path,
816 						 const char *acl_name,
817 						 bool noperm)
818 {
819 	return NULL;
820 }
821 #endif
822 
823 int ovl_update_time(struct inode *inode, int flags);
824 bool ovl_is_private_xattr(struct super_block *sb, const char *name);
825 
826 struct ovl_inode_params {
827 	struct inode *newinode;
828 	struct dentry *upperdentry;
829 	struct ovl_entry *oe;
830 	bool index;
831 	char *redirect;
832 	char *lowerdata_redirect;
833 };
834 void ovl_inode_init(struct inode *inode, struct ovl_inode_params *oip,
835 		    unsigned long ino, int fsid);
836 struct inode *ovl_new_inode(struct super_block *sb, umode_t mode, dev_t rdev);
837 struct inode *ovl_lookup_inode(struct super_block *sb, struct dentry *real,
838 			       bool is_upper);
839 bool ovl_lookup_trap_inode(struct super_block *sb, struct dentry *dir);
840 struct inode *ovl_get_trap_inode(struct super_block *sb, struct dentry *dir);
841 struct inode *ovl_get_inode(struct super_block *sb,
842 			    struct ovl_inode_params *oip);
843 void ovl_copyattr(struct inode *to);
844 
845 /* vfs fileattr flags read from overlay.protattr xattr to ovl inode */
846 #define OVL_PROT_I_FLAGS_MASK  (S_APPEND | S_IMMUTABLE)
847 /* vfs fileattr flags copied from real to ovl inode */
848 #define OVL_FATTR_I_FLAGS_MASK (OVL_PROT_I_FLAGS_MASK | S_SYNC | S_NOATIME)
849 /* vfs inode flags copied from real to ovl inode */
850 #define OVL_COPY_I_FLAGS_MASK  (OVL_FATTR_I_FLAGS_MASK | S_CASEFOLD)
851 
852 /*
853  * fileattr flags copied from lower to upper inode on copy up.
854  * We cannot copy up immutable/append-only flags, because that would prevent
855  * linking temp inode to upper dir, so we store them in xattr instead.
856  */
857 #define OVL_COPY_FS_FLAGS_MASK	(FS_SYNC_FL | FS_NOATIME_FL)
858 #define OVL_COPY_FSX_FLAGS_MASK	(FS_XFLAG_SYNC | FS_XFLAG_NOATIME)
859 #define OVL_PROT_FS_FLAGS_MASK  (FS_APPEND_FL | FS_IMMUTABLE_FL)
860 #define OVL_PROT_FSX_FLAGS_MASK (FS_XFLAG_APPEND | FS_XFLAG_IMMUTABLE)
861 
862 void ovl_check_protattr(struct inode *inode, struct dentry *upper);
863 int ovl_set_protattr(struct inode *inode, struct dentry *upper,
864 		      struct file_kattr *fa);
865 
866 static inline void ovl_copyflags(struct inode *from, struct inode *to)
867 {
868 	unsigned int mask = OVL_COPY_I_FLAGS_MASK;
869 
870 	inode_set_flags(to, from->i_flags & mask, mask);
871 }
872 
873 /* dir.c */
874 extern const struct inode_operations ovl_dir_inode_operations;
875 int ovl_cleanup_and_whiteout(struct ovl_fs *ofs, struct dentry *dir,
876 			     struct dentry *dentry);
877 struct ovl_cattr {
878 	dev_t rdev;
879 	umode_t mode;
880 	const char *link;
881 	struct dentry *hardlink;
882 };
883 
884 #define OVL_CATTR(m) (&(struct ovl_cattr) { .mode = (m) })
885 
886 struct dentry *ovl_create_real(struct ovl_fs *ofs,
887 			       struct dentry *parent, struct dentry *newdentry,
888 			       struct ovl_cattr *attr);
889 int ovl_cleanup(struct ovl_fs *ofs, struct dentry *workdir, struct dentry *dentry);
890 #define OVL_TEMPNAME_SIZE 20
891 void ovl_tempname(char name[OVL_TEMPNAME_SIZE]);
892 struct dentry *ovl_create_temp(struct ovl_fs *ofs, struct dentry *workdir,
893 			       struct ovl_cattr *attr);
894 
895 /* file.c */
896 extern const struct file_operations ovl_file_operations;
897 int ovl_real_fileattr_get(const struct path *realpath, struct file_kattr *fa);
898 int ovl_real_fileattr_set(const struct path *realpath, struct file_kattr *fa);
899 int ovl_fileattr_get(struct dentry *dentry, struct file_kattr *fa);
900 int ovl_fileattr_set(struct mnt_idmap *idmap,
901 		     struct dentry *dentry, struct file_kattr *fa);
902 struct ovl_file;
903 struct ovl_file *ovl_file_alloc(struct file *realfile);
904 void ovl_file_free(struct ovl_file *of);
905 
906 /* copy_up.c */
907 int ovl_copy_up(struct dentry *dentry);
908 int ovl_copy_up_with_data(struct dentry *dentry);
909 int ovl_maybe_copy_up(struct dentry *dentry, int flags);
910 int ovl_copy_xattr(struct super_block *sb, const struct path *path, struct dentry *new);
911 int ovl_set_attr(struct ovl_fs *ofs, struct dentry *upper, struct kstat *stat);
912 struct ovl_fh *ovl_encode_real_fh(struct ovl_fs *ofs, struct inode *realinode,
913 				  bool is_upper);
914 struct ovl_fh *ovl_get_origin_fh(struct ovl_fs *ofs, struct dentry *origin);
915 int ovl_set_origin_fh(struct ovl_fs *ofs, const struct ovl_fh *fh,
916 		      struct dentry *upper);
917 
918 /* export.c */
919 extern const struct export_operations ovl_export_operations;
920 extern const struct export_operations ovl_export_fid_operations;
921 
922 /* super.c */
923 int ovl_fill_super(struct super_block *sb, struct fs_context *fc);
924 
925 /* Will this overlay be forced to mount/remount ro? */
926 static inline bool ovl_force_readonly(struct ovl_fs *ofs)
927 {
928 	return (!ovl_upper_mnt(ofs) || !ofs->workdir);
929 }
930 
931 /* xattr.c */
932 
933 const struct xattr_handler * const *ovl_xattr_handlers(struct ovl_fs *ofs);
934 int ovl_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
935 		struct iattr *attr);
936 int ovl_getattr(struct mnt_idmap *idmap, const struct path *path,
937 		struct kstat *stat, u32 request_mask, unsigned int flags);
938 ssize_t ovl_listxattr(struct dentry *dentry, char *list, size_t size);
939