nfsd41: enforce NFS4ERR_SEQUENCE_POS operation order rules for minorversion != 0...
[linux-2.6] / fs / nfsd / nfs4proc.c
1 /*
2  *  fs/nfsd/nfs4proc.c
3  *
4  *  Server-side procedures for NFSv4.
5  *
6  *  Copyright (c) 2002 The Regents of the University of Michigan.
7  *  All rights reserved.
8  *
9  *  Kendrick Smith <kmsmith@umich.edu>
10  *  Andy Adamson   <andros@umich.edu>
11  *
12  *  Redistribution and use in source and binary forms, with or without
13  *  modification, are permitted provided that the following conditions
14  *  are met:
15  *
16  *  1. Redistributions of source code must retain the above copyright
17  *     notice, this list of conditions and the following disclaimer.
18  *  2. Redistributions in binary form must reproduce the above copyright
19  *     notice, this list of conditions and the following disclaimer in the
20  *     documentation and/or other materials provided with the distribution.
21  *  3. Neither the name of the University nor the names of its
22  *     contributors may be used to endorse or promote products derived
23  *     from this software without specific prior written permission.
24  *
25  *  THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
26  *  WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
27  *  MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
28  *  DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
29  *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
30  *  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
31  *  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
32  *  BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
33  *  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
34  *  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
35  *  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
36  */
37
38 #include <linux/param.h>
39 #include <linux/major.h>
40 #include <linux/slab.h>
41 #include <linux/file.h>
42
43 #include <linux/sunrpc/svc.h>
44 #include <linux/nfsd/nfsd.h>
45 #include <linux/nfsd/cache.h>
46 #include <linux/nfs4.h>
47 #include <linux/nfsd/state.h>
48 #include <linux/nfsd/xdr4.h>
49 #include <linux/nfs4_acl.h>
50 #include <linux/sunrpc/gss_api.h>
51
52 #define NFSDDBG_FACILITY                NFSDDBG_PROC
53
54 static inline void
55 fh_dup2(struct svc_fh *dst, struct svc_fh *src)
56 {
57         fh_put(dst);
58         dget(src->fh_dentry);
59         if (src->fh_export)
60                 cache_get(&src->fh_export->h);
61         *dst = *src;
62 }
63
64 static __be32
65 do_open_permission(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open, int accmode)
66 {
67         __be32 status;
68
69         if (open->op_truncate &&
70                 !(open->op_share_access & NFS4_SHARE_ACCESS_WRITE))
71                 return nfserr_inval;
72
73         if (open->op_share_access & NFS4_SHARE_ACCESS_READ)
74                 accmode |= NFSD_MAY_READ;
75         if (open->op_share_access & NFS4_SHARE_ACCESS_WRITE)
76                 accmode |= (NFSD_MAY_WRITE | NFSD_MAY_TRUNC);
77         if (open->op_share_deny & NFS4_SHARE_DENY_WRITE)
78                 accmode |= NFSD_MAY_WRITE;
79
80         status = fh_verify(rqstp, current_fh, S_IFREG, accmode);
81
82         return status;
83 }
84
85 static __be32
86 do_open_lookup(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open)
87 {
88         struct svc_fh resfh;
89         __be32 status;
90         int created = 0;
91
92         fh_init(&resfh, NFS4_FHSIZE);
93         open->op_truncate = 0;
94
95         if (open->op_create) {
96                 /*
97                  * Note: create modes (UNCHECKED,GUARDED...) are the same
98                  * in NFSv4 as in v3.
99                  */
100                 status = nfsd_create_v3(rqstp, current_fh, open->op_fname.data,
101                                         open->op_fname.len, &open->op_iattr,
102                                         &resfh, open->op_createmode,
103                                         (u32 *)open->op_verf.data,
104                                         &open->op_truncate, &created);
105
106                 /*
107                  * Following rfc 3530 14.2.16, use the returned bitmask
108                  * to indicate which attributes we used to store the
109                  * verifier:
110                  */
111                 if (open->op_createmode == NFS4_CREATE_EXCLUSIVE && status == 0)
112                         open->op_bmval[1] = (FATTR4_WORD1_TIME_ACCESS |
113                                                 FATTR4_WORD1_TIME_MODIFY);
114         } else {
115                 status = nfsd_lookup(rqstp, current_fh,
116                                      open->op_fname.data, open->op_fname.len, &resfh);
117                 fh_unlock(current_fh);
118         }
119         if (status)
120                 goto out;
121
122         set_change_info(&open->op_cinfo, current_fh);
123         fh_dup2(current_fh, &resfh);
124
125         /* set reply cache */
126         fh_copy_shallow(&open->op_stateowner->so_replay.rp_openfh,
127                         &resfh.fh_handle);
128         if (!created)
129                 status = do_open_permission(rqstp, current_fh, open,
130                                             NFSD_MAY_NOP);
131
132 out:
133         fh_put(&resfh);
134         return status;
135 }
136
137 static __be32
138 do_open_fhandle(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open)
139 {
140         __be32 status;
141
142         /* Only reclaims from previously confirmed clients are valid */
143         if ((status = nfs4_check_open_reclaim(&open->op_clientid)))
144                 return status;
145
146         /* We don't know the target directory, and therefore can not
147         * set the change info
148         */
149
150         memset(&open->op_cinfo, 0, sizeof(struct nfsd4_change_info));
151
152         /* set replay cache */
153         fh_copy_shallow(&open->op_stateowner->so_replay.rp_openfh,
154                         &current_fh->fh_handle);
155
156         open->op_truncate = (open->op_iattr.ia_valid & ATTR_SIZE) &&
157                 (open->op_iattr.ia_size == 0);
158
159         status = do_open_permission(rqstp, current_fh, open,
160                                     NFSD_MAY_OWNER_OVERRIDE);
161
162         return status;
163 }
164
165
166 static __be32
167 nfsd4_open(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
168            struct nfsd4_open *open)
169 {
170         __be32 status;
171         dprintk("NFSD: nfsd4_open filename %.*s op_stateowner %p\n",
172                 (int)open->op_fname.len, open->op_fname.data,
173                 open->op_stateowner);
174
175         /* This check required by spec. */
176         if (open->op_create && open->op_claim_type != NFS4_OPEN_CLAIM_NULL)
177                 return nfserr_inval;
178
179         nfs4_lock_state();
180
181         /* check seqid for replay. set nfs4_owner */
182         status = nfsd4_process_open1(open);
183         if (status == nfserr_replay_me) {
184                 struct nfs4_replay *rp = &open->op_stateowner->so_replay;
185                 fh_put(&cstate->current_fh);
186                 fh_copy_shallow(&cstate->current_fh.fh_handle,
187                                 &rp->rp_openfh);
188                 status = fh_verify(rqstp, &cstate->current_fh, 0, NFSD_MAY_NOP);
189                 if (status)
190                         dprintk("nfsd4_open: replay failed"
191                                 " restoring previous filehandle\n");
192                 else
193                         status = nfserr_replay_me;
194         }
195         if (status)
196                 goto out;
197
198         /* Openowner is now set, so sequence id will get bumped.  Now we need
199          * these checks before we do any creates: */
200         status = nfserr_grace;
201         if (locks_in_grace() && open->op_claim_type != NFS4_OPEN_CLAIM_PREVIOUS)
202                 goto out;
203         status = nfserr_no_grace;
204         if (!locks_in_grace() && open->op_claim_type == NFS4_OPEN_CLAIM_PREVIOUS)
205                 goto out;
206
207         switch (open->op_claim_type) {
208                 case NFS4_OPEN_CLAIM_DELEGATE_CUR:
209                 case NFS4_OPEN_CLAIM_NULL:
210                         /*
211                          * (1) set CURRENT_FH to the file being opened,
212                          * creating it if necessary, (2) set open->op_cinfo,
213                          * (3) set open->op_truncate if the file is to be
214                          * truncated after opening, (4) do permission checking.
215                          */
216                         status = do_open_lookup(rqstp, &cstate->current_fh,
217                                                 open);
218                         if (status)
219                                 goto out;
220                         break;
221                 case NFS4_OPEN_CLAIM_PREVIOUS:
222                         open->op_stateowner->so_confirmed = 1;
223                         /*
224                          * The CURRENT_FH is already set to the file being
225                          * opened.  (1) set open->op_cinfo, (2) set
226                          * open->op_truncate if the file is to be truncated
227                          * after opening, (3) do permission checking.
228                         */
229                         status = do_open_fhandle(rqstp, &cstate->current_fh,
230                                                  open);
231                         if (status)
232                                 goto out;
233                         break;
234                 case NFS4_OPEN_CLAIM_DELEGATE_PREV:
235                         open->op_stateowner->so_confirmed = 1;
236                         dprintk("NFSD: unsupported OPEN claim type %d\n",
237                                 open->op_claim_type);
238                         status = nfserr_notsupp;
239                         goto out;
240                 default:
241                         dprintk("NFSD: Invalid OPEN claim type %d\n",
242                                 open->op_claim_type);
243                         status = nfserr_inval;
244                         goto out;
245         }
246         /*
247          * nfsd4_process_open2() does the actual opening of the file.  If
248          * successful, it (1) truncates the file if open->op_truncate was
249          * set, (2) sets open->op_stateid, (3) sets open->op_delegation.
250          */
251         status = nfsd4_process_open2(rqstp, &cstate->current_fh, open);
252 out:
253         if (open->op_stateowner) {
254                 nfs4_get_stateowner(open->op_stateowner);
255                 cstate->replay_owner = open->op_stateowner;
256         }
257         nfs4_unlock_state();
258         return status;
259 }
260
261 /*
262  * filehandle-manipulating ops.
263  */
264 static __be32
265 nfsd4_getfh(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
266             struct svc_fh **getfh)
267 {
268         if (!cstate->current_fh.fh_dentry)
269                 return nfserr_nofilehandle;
270
271         *getfh = &cstate->current_fh;
272         return nfs_ok;
273 }
274
275 static __be32
276 nfsd4_putfh(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
277             struct nfsd4_putfh *putfh)
278 {
279         fh_put(&cstate->current_fh);
280         cstate->current_fh.fh_handle.fh_size = putfh->pf_fhlen;
281         memcpy(&cstate->current_fh.fh_handle.fh_base, putfh->pf_fhval,
282                putfh->pf_fhlen);
283         return fh_verify(rqstp, &cstate->current_fh, 0, NFSD_MAY_NOP);
284 }
285
286 static __be32
287 nfsd4_putrootfh(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
288                 void *arg)
289 {
290         __be32 status;
291
292         fh_put(&cstate->current_fh);
293         status = exp_pseudoroot(rqstp, &cstate->current_fh);
294         return status;
295 }
296
297 static __be32
298 nfsd4_restorefh(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
299                 void *arg)
300 {
301         if (!cstate->save_fh.fh_dentry)
302                 return nfserr_restorefh;
303
304         fh_dup2(&cstate->current_fh, &cstate->save_fh);
305         return nfs_ok;
306 }
307
308 static __be32
309 nfsd4_savefh(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
310              void *arg)
311 {
312         if (!cstate->current_fh.fh_dentry)
313                 return nfserr_nofilehandle;
314
315         fh_dup2(&cstate->save_fh, &cstate->current_fh);
316         return nfs_ok;
317 }
318
319 /*
320  * misc nfsv4 ops
321  */
322 static __be32
323 nfsd4_access(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
324              struct nfsd4_access *access)
325 {
326         if (access->ac_req_access & ~NFS3_ACCESS_FULL)
327                 return nfserr_inval;
328
329         access->ac_resp_access = access->ac_req_access;
330         return nfsd_access(rqstp, &cstate->current_fh, &access->ac_resp_access,
331                            &access->ac_supported);
332 }
333
334 static __be32
335 nfsd4_commit(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
336              struct nfsd4_commit *commit)
337 {
338         __be32 status;
339
340         u32 *p = (u32 *)commit->co_verf.data;
341         *p++ = nfssvc_boot.tv_sec;
342         *p++ = nfssvc_boot.tv_usec;
343
344         status = nfsd_commit(rqstp, &cstate->current_fh, commit->co_offset,
345                              commit->co_count);
346         if (status == nfserr_symlink)
347                 status = nfserr_inval;
348         return status;
349 }
350
351 static __be32
352 nfsd4_create(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
353              struct nfsd4_create *create)
354 {
355         struct svc_fh resfh;
356         __be32 status;
357         dev_t rdev;
358
359         fh_init(&resfh, NFS4_FHSIZE);
360
361         status = fh_verify(rqstp, &cstate->current_fh, S_IFDIR,
362                            NFSD_MAY_CREATE);
363         if (status == nfserr_symlink)
364                 status = nfserr_notdir;
365         if (status)
366                 return status;
367
368         switch (create->cr_type) {
369         case NF4LNK:
370                 /* ugh! we have to null-terminate the linktext, or
371                  * vfs_symlink() will choke.  it is always safe to
372                  * null-terminate by brute force, since at worst we
373                  * will overwrite the first byte of the create namelen
374                  * in the XDR buffer, which has already been extracted
375                  * during XDR decode.
376                  */
377                 create->cr_linkname[create->cr_linklen] = 0;
378
379                 status = nfsd_symlink(rqstp, &cstate->current_fh,
380                                       create->cr_name, create->cr_namelen,
381                                       create->cr_linkname, create->cr_linklen,
382                                       &resfh, &create->cr_iattr);
383                 break;
384
385         case NF4BLK:
386                 rdev = MKDEV(create->cr_specdata1, create->cr_specdata2);
387                 if (MAJOR(rdev) != create->cr_specdata1 ||
388                     MINOR(rdev) != create->cr_specdata2)
389                         return nfserr_inval;
390                 status = nfsd_create(rqstp, &cstate->current_fh,
391                                      create->cr_name, create->cr_namelen,
392                                      &create->cr_iattr, S_IFBLK, rdev, &resfh);
393                 break;
394
395         case NF4CHR:
396                 rdev = MKDEV(create->cr_specdata1, create->cr_specdata2);
397                 if (MAJOR(rdev) != create->cr_specdata1 ||
398                     MINOR(rdev) != create->cr_specdata2)
399                         return nfserr_inval;
400                 status = nfsd_create(rqstp, &cstate->current_fh,
401                                      create->cr_name, create->cr_namelen,
402                                      &create->cr_iattr,S_IFCHR, rdev, &resfh);
403                 break;
404
405         case NF4SOCK:
406                 status = nfsd_create(rqstp, &cstate->current_fh,
407                                      create->cr_name, create->cr_namelen,
408                                      &create->cr_iattr, S_IFSOCK, 0, &resfh);
409                 break;
410
411         case NF4FIFO:
412                 status = nfsd_create(rqstp, &cstate->current_fh,
413                                      create->cr_name, create->cr_namelen,
414                                      &create->cr_iattr, S_IFIFO, 0, &resfh);
415                 break;
416
417         case NF4DIR:
418                 create->cr_iattr.ia_valid &= ~ATTR_SIZE;
419                 status = nfsd_create(rqstp, &cstate->current_fh,
420                                      create->cr_name, create->cr_namelen,
421                                      &create->cr_iattr, S_IFDIR, 0, &resfh);
422                 break;
423
424         default:
425                 status = nfserr_badtype;
426         }
427
428         if (!status) {
429                 fh_unlock(&cstate->current_fh);
430                 set_change_info(&create->cr_cinfo, &cstate->current_fh);
431                 fh_dup2(&cstate->current_fh, &resfh);
432         }
433
434         fh_put(&resfh);
435         return status;
436 }
437
438 static __be32
439 nfsd4_getattr(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
440               struct nfsd4_getattr *getattr)
441 {
442         __be32 status;
443
444         status = fh_verify(rqstp, &cstate->current_fh, 0, NFSD_MAY_NOP);
445         if (status)
446                 return status;
447
448         if (getattr->ga_bmval[1] & NFSD_WRITEONLY_ATTRS_WORD1)
449                 return nfserr_inval;
450
451         getattr->ga_bmval[0] &= NFSD_SUPPORTED_ATTRS_WORD0;
452         getattr->ga_bmval[1] &= NFSD_SUPPORTED_ATTRS_WORD1;
453
454         getattr->ga_fhp = &cstate->current_fh;
455         return nfs_ok;
456 }
457
458 static __be32
459 nfsd4_link(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
460            struct nfsd4_link *link)
461 {
462         __be32 status = nfserr_nofilehandle;
463
464         if (!cstate->save_fh.fh_dentry)
465                 return status;
466         status = nfsd_link(rqstp, &cstate->current_fh,
467                            link->li_name, link->li_namelen, &cstate->save_fh);
468         if (!status)
469                 set_change_info(&link->li_cinfo, &cstate->current_fh);
470         return status;
471 }
472
473 static __be32
474 nfsd4_lookupp(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
475               void *arg)
476 {
477         struct svc_fh tmp_fh;
478         __be32 ret;
479
480         fh_init(&tmp_fh, NFS4_FHSIZE);
481         ret = exp_pseudoroot(rqstp, &tmp_fh);
482         if (ret)
483                 return ret;
484         if (tmp_fh.fh_dentry == cstate->current_fh.fh_dentry) {
485                 fh_put(&tmp_fh);
486                 return nfserr_noent;
487         }
488         fh_put(&tmp_fh);
489         return nfsd_lookup(rqstp, &cstate->current_fh,
490                            "..", 2, &cstate->current_fh);
491 }
492
493 static __be32
494 nfsd4_lookup(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
495              struct nfsd4_lookup *lookup)
496 {
497         return nfsd_lookup(rqstp, &cstate->current_fh,
498                            lookup->lo_name, lookup->lo_len,
499                            &cstate->current_fh);
500 }
501
502 static __be32
503 nfsd4_read(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
504            struct nfsd4_read *read)
505 {
506         __be32 status;
507
508         /* no need to check permission - this will be done in nfsd_read() */
509
510         read->rd_filp = NULL;
511         if (read->rd_offset >= OFFSET_MAX)
512                 return nfserr_inval;
513
514         nfs4_lock_state();
515         /* check stateid */
516         if ((status = nfs4_preprocess_stateid_op(&cstate->current_fh,
517                                 &read->rd_stateid,
518                                 RD_STATE, &read->rd_filp))) {
519                 dprintk("NFSD: nfsd4_read: couldn't process stateid!\n");
520                 goto out;
521         }
522         if (read->rd_filp)
523                 get_file(read->rd_filp);
524         status = nfs_ok;
525 out:
526         nfs4_unlock_state();
527         read->rd_rqstp = rqstp;
528         read->rd_fhp = &cstate->current_fh;
529         return status;
530 }
531
532 static __be32
533 nfsd4_readdir(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
534               struct nfsd4_readdir *readdir)
535 {
536         u64 cookie = readdir->rd_cookie;
537         static const nfs4_verifier zeroverf;
538
539         /* no need to check permission - this will be done in nfsd_readdir() */
540
541         if (readdir->rd_bmval[1] & NFSD_WRITEONLY_ATTRS_WORD1)
542                 return nfserr_inval;
543
544         readdir->rd_bmval[0] &= NFSD_SUPPORTED_ATTRS_WORD0;
545         readdir->rd_bmval[1] &= NFSD_SUPPORTED_ATTRS_WORD1;
546
547         if ((cookie > ~(u32)0) || (cookie == 1) || (cookie == 2) ||
548             (cookie == 0 && memcmp(readdir->rd_verf.data, zeroverf.data, NFS4_VERIFIER_SIZE)))
549                 return nfserr_bad_cookie;
550
551         readdir->rd_rqstp = rqstp;
552         readdir->rd_fhp = &cstate->current_fh;
553         return nfs_ok;
554 }
555
556 static __be32
557 nfsd4_readlink(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
558                struct nfsd4_readlink *readlink)
559 {
560         readlink->rl_rqstp = rqstp;
561         readlink->rl_fhp = &cstate->current_fh;
562         return nfs_ok;
563 }
564
565 static __be32
566 nfsd4_remove(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
567              struct nfsd4_remove *remove)
568 {
569         __be32 status;
570
571         if (locks_in_grace())
572                 return nfserr_grace;
573         status = nfsd_unlink(rqstp, &cstate->current_fh, 0,
574                              remove->rm_name, remove->rm_namelen);
575         if (status == nfserr_symlink)
576                 return nfserr_notdir;
577         if (!status) {
578                 fh_unlock(&cstate->current_fh);
579                 set_change_info(&remove->rm_cinfo, &cstate->current_fh);
580         }
581         return status;
582 }
583
584 static __be32
585 nfsd4_rename(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
586              struct nfsd4_rename *rename)
587 {
588         __be32 status = nfserr_nofilehandle;
589
590         if (!cstate->save_fh.fh_dentry)
591                 return status;
592         if (locks_in_grace() && !(cstate->save_fh.fh_export->ex_flags
593                                         & NFSEXP_NOSUBTREECHECK))
594                 return nfserr_grace;
595         status = nfsd_rename(rqstp, &cstate->save_fh, rename->rn_sname,
596                              rename->rn_snamelen, &cstate->current_fh,
597                              rename->rn_tname, rename->rn_tnamelen);
598
599         /* the underlying filesystem returns different error's than required
600          * by NFSv4. both save_fh and current_fh have been verified.. */
601         if (status == nfserr_isdir)
602                 status = nfserr_exist;
603         else if ((status == nfserr_notdir) &&
604                   (S_ISDIR(cstate->save_fh.fh_dentry->d_inode->i_mode) &&
605                    S_ISDIR(cstate->current_fh.fh_dentry->d_inode->i_mode)))
606                 status = nfserr_exist;
607         else if (status == nfserr_symlink)
608                 status = nfserr_notdir;
609
610         if (!status) {
611                 set_change_info(&rename->rn_sinfo, &cstate->current_fh);
612                 set_change_info(&rename->rn_tinfo, &cstate->save_fh);
613         }
614         return status;
615 }
616
617 static __be32
618 nfsd4_secinfo(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
619               struct nfsd4_secinfo *secinfo)
620 {
621         struct svc_fh resfh;
622         struct svc_export *exp;
623         struct dentry *dentry;
624         __be32 err;
625
626         fh_init(&resfh, NFS4_FHSIZE);
627         err = nfsd_lookup_dentry(rqstp, &cstate->current_fh,
628                                     secinfo->si_name, secinfo->si_namelen,
629                                     &exp, &dentry);
630         if (err)
631                 return err;
632         if (dentry->d_inode == NULL) {
633                 exp_put(exp);
634                 err = nfserr_noent;
635         } else
636                 secinfo->si_exp = exp;
637         dput(dentry);
638         return err;
639 }
640
641 static __be32
642 nfsd4_setattr(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
643               struct nfsd4_setattr *setattr)
644 {
645         __be32 status = nfs_ok;
646
647         if (setattr->sa_iattr.ia_valid & ATTR_SIZE) {
648                 nfs4_lock_state();
649                 status = nfs4_preprocess_stateid_op(&cstate->current_fh,
650                         &setattr->sa_stateid, WR_STATE, NULL);
651                 nfs4_unlock_state();
652                 if (status) {
653                         dprintk("NFSD: nfsd4_setattr: couldn't process stateid!\n");
654                         return status;
655                 }
656         }
657         status = mnt_want_write(cstate->current_fh.fh_export->ex_path.mnt);
658         if (status)
659                 return status;
660         status = nfs_ok;
661         if (setattr->sa_acl != NULL)
662                 status = nfsd4_set_nfs4_acl(rqstp, &cstate->current_fh,
663                                             setattr->sa_acl);
664         if (status)
665                 goto out;
666         status = nfsd_setattr(rqstp, &cstate->current_fh, &setattr->sa_iattr,
667                                 0, (time_t)0);
668 out:
669         mnt_drop_write(cstate->current_fh.fh_export->ex_path.mnt);
670         return status;
671 }
672
673 static __be32
674 nfsd4_write(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
675             struct nfsd4_write *write)
676 {
677         stateid_t *stateid = &write->wr_stateid;
678         struct file *filp = NULL;
679         u32 *p;
680         __be32 status = nfs_ok;
681         unsigned long cnt;
682
683         /* no need to check permission - this will be done in nfsd_write() */
684
685         if (write->wr_offset >= OFFSET_MAX)
686                 return nfserr_inval;
687
688         nfs4_lock_state();
689         status = nfs4_preprocess_stateid_op(&cstate->current_fh, stateid,
690                                         WR_STATE, &filp);
691         if (filp)
692                 get_file(filp);
693         nfs4_unlock_state();
694
695         if (status) {
696                 dprintk("NFSD: nfsd4_write: couldn't process stateid!\n");
697                 return status;
698         }
699
700         cnt = write->wr_buflen;
701         write->wr_how_written = write->wr_stable_how;
702         p = (u32 *)write->wr_verifier.data;
703         *p++ = nfssvc_boot.tv_sec;
704         *p++ = nfssvc_boot.tv_usec;
705
706         status =  nfsd_write(rqstp, &cstate->current_fh, filp,
707                              write->wr_offset, rqstp->rq_vec, write->wr_vlen,
708                              &cnt, &write->wr_how_written);
709         if (filp)
710                 fput(filp);
711
712         write->wr_bytes_written = cnt;
713
714         if (status == nfserr_symlink)
715                 status = nfserr_inval;
716         return status;
717 }
718
719 /* This routine never returns NFS_OK!  If there are no other errors, it
720  * will return NFSERR_SAME or NFSERR_NOT_SAME depending on whether the
721  * attributes matched.  VERIFY is implemented by mapping NFSERR_SAME
722  * to NFS_OK after the call; NVERIFY by mapping NFSERR_NOT_SAME to NFS_OK.
723  */
724 static __be32
725 _nfsd4_verify(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
726              struct nfsd4_verify *verify)
727 {
728         __be32 *buf, *p;
729         int count;
730         __be32 status;
731
732         status = fh_verify(rqstp, &cstate->current_fh, 0, NFSD_MAY_NOP);
733         if (status)
734                 return status;
735
736         if ((verify->ve_bmval[0] & ~NFSD_SUPPORTED_ATTRS_WORD0)
737             || (verify->ve_bmval[1] & ~NFSD_SUPPORTED_ATTRS_WORD1))
738                 return nfserr_attrnotsupp;
739         if ((verify->ve_bmval[0] & FATTR4_WORD0_RDATTR_ERROR)
740             || (verify->ve_bmval[1] & NFSD_WRITEONLY_ATTRS_WORD1))
741                 return nfserr_inval;
742         if (verify->ve_attrlen & 3)
743                 return nfserr_inval;
744
745         /* count in words:
746          *   bitmap_len(1) + bitmap(2) + attr_len(1) = 4
747          */
748         count = 4 + (verify->ve_attrlen >> 2);
749         buf = kmalloc(count << 2, GFP_KERNEL);
750         if (!buf)
751                 return nfserr_resource;
752
753         status = nfsd4_encode_fattr(&cstate->current_fh,
754                                     cstate->current_fh.fh_export,
755                                     cstate->current_fh.fh_dentry, buf,
756                                     &count, verify->ve_bmval,
757                                     rqstp, 0);
758
759         /* this means that nfsd4_encode_fattr() ran out of space */
760         if (status == nfserr_resource && count == 0)
761                 status = nfserr_not_same;
762         if (status)
763                 goto out_kfree;
764
765         p = buf + 3;
766         status = nfserr_not_same;
767         if (ntohl(*p++) != verify->ve_attrlen)
768                 goto out_kfree;
769         if (!memcmp(p, verify->ve_attrval, verify->ve_attrlen))
770                 status = nfserr_same;
771
772 out_kfree:
773         kfree(buf);
774         return status;
775 }
776
777 static __be32
778 nfsd4_nverify(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
779               struct nfsd4_verify *verify)
780 {
781         __be32 status;
782
783         status = _nfsd4_verify(rqstp, cstate, verify);
784         return status == nfserr_not_same ? nfs_ok : status;
785 }
786
787 static __be32
788 nfsd4_verify(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
789              struct nfsd4_verify *verify)
790 {
791         __be32 status;
792
793         status = _nfsd4_verify(rqstp, cstate, verify);
794         return status == nfserr_same ? nfs_ok : status;
795 }
796
797 /*
798  * NULL call.
799  */
800 static __be32
801 nfsd4_proc_null(struct svc_rqst *rqstp, void *argp, void *resp)
802 {
803         return nfs_ok;
804 }
805
806 static inline void nfsd4_increment_op_stats(u32 opnum)
807 {
808         if (opnum >= FIRST_NFS4_OP && opnum <= LAST_NFS4_OP)
809                 nfsdstats.nfs4_opcount[opnum]++;
810 }
811
812 typedef __be32(*nfsd4op_func)(struct svc_rqst *, struct nfsd4_compound_state *,
813                               void *);
814 enum nfsd4_op_flags {
815         ALLOWED_WITHOUT_FH = 1 << 0,    /* No current filehandle required */
816         ALLOWED_ON_ABSENT_FS = 2 << 0,  /* ops processed on absent fs */
817         ALLOWED_AS_FIRST_OP = 3 << 0,   /* ops reqired first in compound */
818 };
819
820 struct nfsd4_operation {
821         nfsd4op_func op_func;
822         u32 op_flags;
823         char *op_name;
824 };
825
826 static struct nfsd4_operation nfsd4_ops[];
827
828 static const char *nfsd4_op_name(unsigned opnum);
829
830 /*
831  * Enforce NFSv4.1 COMPOUND ordering rules.
832  *
833  * TODO:
834  * - enforce NFS4ERR_NOT_ONLY_OP,
835  * - DESTROY_SESSION MUST be the final operation in the COMPOUND request.
836  */
837 static bool nfs41_op_ordering_ok(struct nfsd4_compoundargs *args)
838 {
839         if (args->minorversion && args->opcnt > 0) {
840                 struct nfsd4_op *op = &args->ops[0];
841                 return (op->status == nfserr_op_illegal) ||
842                        (nfsd4_ops[op->opnum].op_flags & ALLOWED_AS_FIRST_OP);
843         }
844         return true;
845 }
846
847 /*
848  * COMPOUND call.
849  */
850 static __be32
851 nfsd4_proc_compound(struct svc_rqst *rqstp,
852                     struct nfsd4_compoundargs *args,
853                     struct nfsd4_compoundres *resp)
854 {
855         struct nfsd4_op *op;
856         struct nfsd4_operation *opdesc;
857         struct nfsd4_compound_state *cstate = &resp->cstate;
858         int             slack_bytes;
859         __be32          status;
860
861         resp->xbuf = &rqstp->rq_res;
862         resp->p = rqstp->rq_res.head[0].iov_base +
863                                                 rqstp->rq_res.head[0].iov_len;
864         resp->tagp = resp->p;
865         /* reserve space for: taglen, tag, and opcnt */
866         resp->p += 2 + XDR_QUADLEN(args->taglen);
867         resp->end = rqstp->rq_res.head[0].iov_base + PAGE_SIZE;
868         resp->taglen = args->taglen;
869         resp->tag = args->tag;
870         resp->opcnt = 0;
871         resp->rqstp = rqstp;
872         resp->cstate.replay_owner = NULL;
873         fh_init(&resp->cstate.current_fh, NFS4_FHSIZE);
874         fh_init(&resp->cstate.save_fh, NFS4_FHSIZE);
875         /* Use the deferral mechanism only for NFSv4.0 compounds */
876         rqstp->rq_usedeferral = (args->minorversion == 0);
877
878         /*
879          * According to RFC3010, this takes precedence over all other errors.
880          */
881         status = nfserr_minor_vers_mismatch;
882         if (args->minorversion > NFSD_SUPPORTED_MINOR_VERSION)
883                 goto out;
884
885         if (!nfs41_op_ordering_ok(args)) {
886                 op = &args->ops[0];
887                 op->status = nfserr_sequence_pos;
888                 goto encode_op;
889         }
890
891         status = nfs_ok;
892         while (!status && resp->opcnt < args->opcnt) {
893                 op = &args->ops[resp->opcnt++];
894
895                 dprintk("nfsv4 compound op #%d/%d: %d (%s)\n",
896                         resp->opcnt, args->opcnt, op->opnum,
897                         nfsd4_op_name(op->opnum));
898
899                 /*
900                  * The XDR decode routines may have pre-set op->status;
901                  * for example, if there is a miscellaneous XDR error
902                  * it will be set to nfserr_bad_xdr.
903                  */
904                 if (op->status)
905                         goto encode_op;
906
907                 /* We must be able to encode a successful response to
908                  * this operation, with enough room left over to encode a
909                  * failed response to the next operation.  If we don't
910                  * have enough room, fail with ERR_RESOURCE.
911                  */
912                 slack_bytes = (char *)resp->end - (char *)resp->p;
913                 if (slack_bytes < COMPOUND_SLACK_SPACE
914                                 + COMPOUND_ERR_SLACK_SPACE) {
915                         BUG_ON(slack_bytes < COMPOUND_ERR_SLACK_SPACE);
916                         op->status = nfserr_resource;
917                         goto encode_op;
918                 }
919
920                 opdesc = &nfsd4_ops[op->opnum];
921
922                 if (!cstate->current_fh.fh_dentry) {
923                         if (!(opdesc->op_flags & ALLOWED_WITHOUT_FH)) {
924                                 op->status = nfserr_nofilehandle;
925                                 goto encode_op;
926                         }
927                 } else if (cstate->current_fh.fh_export->ex_fslocs.migrated &&
928                           !(opdesc->op_flags & ALLOWED_ON_ABSENT_FS)) {
929                         op->status = nfserr_moved;
930                         goto encode_op;
931                 }
932
933                 if (opdesc->op_func)
934                         op->status = opdesc->op_func(rqstp, cstate, &op->u);
935                 else
936                         BUG_ON(op->status == nfs_ok);
937
938 encode_op:
939                 if (op->status == nfserr_replay_me) {
940                         op->replay = &cstate->replay_owner->so_replay;
941                         nfsd4_encode_replay(resp, op);
942                         status = op->status = op->replay->rp_status;
943                 } else {
944                         nfsd4_encode_operation(resp, op);
945                         status = op->status;
946                 }
947
948                 dprintk("nfsv4 compound op %p opcnt %d #%d: %d: status %d\n",
949                         args->ops, args->opcnt, resp->opcnt, op->opnum,
950                         be32_to_cpu(status));
951
952                 if (cstate->replay_owner) {
953                         nfs4_put_stateowner(cstate->replay_owner);
954                         cstate->replay_owner = NULL;
955                 }
956                 /* XXX Ugh, we need to get rid of this kind of special case: */
957                 if (op->opnum == OP_READ && op->u.read.rd_filp)
958                         fput(op->u.read.rd_filp);
959
960                 nfsd4_increment_op_stats(op->opnum);
961         }
962         if (!rqstp->rq_usedeferral && status == nfserr_dropit) {
963                 dprintk("%s Dropit - send NFS4ERR_DELAY\n", __func__);
964                 status = nfserr_jukebox;
965         }
966
967         fh_put(&resp->cstate.current_fh);
968         fh_put(&resp->cstate.save_fh);
969         BUG_ON(resp->cstate.replay_owner);
970 out:
971         nfsd4_release_compoundargs(args);
972         /* Reset deferral mechanism for RPC deferrals */
973         rqstp->rq_usedeferral = 1;
974         dprintk("nfsv4 compound returned %d\n", ntohl(status));
975         return status;
976 }
977
978 static struct nfsd4_operation nfsd4_ops[] = {
979         [OP_ACCESS] = {
980                 .op_func = (nfsd4op_func)nfsd4_access,
981                 .op_name = "OP_ACCESS",
982         },
983         [OP_CLOSE] = {
984                 .op_func = (nfsd4op_func)nfsd4_close,
985                 .op_name = "OP_CLOSE",
986         },
987         [OP_COMMIT] = {
988                 .op_func = (nfsd4op_func)nfsd4_commit,
989                 .op_name = "OP_COMMIT",
990         },
991         [OP_CREATE] = {
992                 .op_func = (nfsd4op_func)nfsd4_create,
993                 .op_name = "OP_CREATE",
994         },
995         [OP_DELEGRETURN] = {
996                 .op_func = (nfsd4op_func)nfsd4_delegreturn,
997                 .op_name = "OP_DELEGRETURN",
998         },
999         [OP_GETATTR] = {
1000                 .op_func = (nfsd4op_func)nfsd4_getattr,
1001                 .op_flags = ALLOWED_ON_ABSENT_FS,
1002                 .op_name = "OP_GETATTR",
1003         },
1004         [OP_GETFH] = {
1005                 .op_func = (nfsd4op_func)nfsd4_getfh,
1006                 .op_name = "OP_GETFH",
1007         },
1008         [OP_LINK] = {
1009                 .op_func = (nfsd4op_func)nfsd4_link,
1010                 .op_name = "OP_LINK",
1011         },
1012         [OP_LOCK] = {
1013                 .op_func = (nfsd4op_func)nfsd4_lock,
1014                 .op_name = "OP_LOCK",
1015         },
1016         [OP_LOCKT] = {
1017                 .op_func = (nfsd4op_func)nfsd4_lockt,
1018                 .op_name = "OP_LOCKT",
1019         },
1020         [OP_LOCKU] = {
1021                 .op_func = (nfsd4op_func)nfsd4_locku,
1022                 .op_name = "OP_LOCKU",
1023         },
1024         [OP_LOOKUP] = {
1025                 .op_func = (nfsd4op_func)nfsd4_lookup,
1026                 .op_name = "OP_LOOKUP",
1027         },
1028         [OP_LOOKUPP] = {
1029                 .op_func = (nfsd4op_func)nfsd4_lookupp,
1030                 .op_name = "OP_LOOKUPP",
1031         },
1032         [OP_NVERIFY] = {
1033                 .op_func = (nfsd4op_func)nfsd4_nverify,
1034                 .op_name = "OP_NVERIFY",
1035         },
1036         [OP_OPEN] = {
1037                 .op_func = (nfsd4op_func)nfsd4_open,
1038                 .op_name = "OP_OPEN",
1039         },
1040         [OP_OPEN_CONFIRM] = {
1041                 .op_func = (nfsd4op_func)nfsd4_open_confirm,
1042                 .op_name = "OP_OPEN_CONFIRM",
1043         },
1044         [OP_OPEN_DOWNGRADE] = {
1045                 .op_func = (nfsd4op_func)nfsd4_open_downgrade,
1046                 .op_name = "OP_OPEN_DOWNGRADE",
1047         },
1048         [OP_PUTFH] = {
1049                 .op_func = (nfsd4op_func)nfsd4_putfh,
1050                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1051                 .op_name = "OP_PUTFH",
1052         },
1053         [OP_PUTPUBFH] = {
1054                 .op_func = (nfsd4op_func)nfsd4_putrootfh,
1055                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1056                 .op_name = "OP_PUTPUBFH",
1057         },
1058         [OP_PUTROOTFH] = {
1059                 .op_func = (nfsd4op_func)nfsd4_putrootfh,
1060                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1061                 .op_name = "OP_PUTROOTFH",
1062         },
1063         [OP_READ] = {
1064                 .op_func = (nfsd4op_func)nfsd4_read,
1065                 .op_name = "OP_READ",
1066         },
1067         [OP_READDIR] = {
1068                 .op_func = (nfsd4op_func)nfsd4_readdir,
1069                 .op_name = "OP_READDIR",
1070         },
1071         [OP_READLINK] = {
1072                 .op_func = (nfsd4op_func)nfsd4_readlink,
1073                 .op_name = "OP_READLINK",
1074         },
1075         [OP_REMOVE] = {
1076                 .op_func = (nfsd4op_func)nfsd4_remove,
1077                 .op_name = "OP_REMOVE",
1078         },
1079         [OP_RENAME] = {
1080                 .op_name = "OP_RENAME",
1081                 .op_func = (nfsd4op_func)nfsd4_rename,
1082         },
1083         [OP_RENEW] = {
1084                 .op_func = (nfsd4op_func)nfsd4_renew,
1085                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1086                 .op_name = "OP_RENEW",
1087         },
1088         [OP_RESTOREFH] = {
1089                 .op_func = (nfsd4op_func)nfsd4_restorefh,
1090                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1091                 .op_name = "OP_RESTOREFH",
1092         },
1093         [OP_SAVEFH] = {
1094                 .op_func = (nfsd4op_func)nfsd4_savefh,
1095                 .op_name = "OP_SAVEFH",
1096         },
1097         [OP_SECINFO] = {
1098                 .op_func = (nfsd4op_func)nfsd4_secinfo,
1099                 .op_name = "OP_SECINFO",
1100         },
1101         [OP_SETATTR] = {
1102                 .op_func = (nfsd4op_func)nfsd4_setattr,
1103                 .op_name = "OP_SETATTR",
1104         },
1105         [OP_SETCLIENTID] = {
1106                 .op_func = (nfsd4op_func)nfsd4_setclientid,
1107                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1108                 .op_name = "OP_SETCLIENTID",
1109         },
1110         [OP_SETCLIENTID_CONFIRM] = {
1111                 .op_func = (nfsd4op_func)nfsd4_setclientid_confirm,
1112                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1113                 .op_name = "OP_SETCLIENTID_CONFIRM",
1114         },
1115         [OP_VERIFY] = {
1116                 .op_func = (nfsd4op_func)nfsd4_verify,
1117                 .op_name = "OP_VERIFY",
1118         },
1119         [OP_WRITE] = {
1120                 .op_func = (nfsd4op_func)nfsd4_write,
1121                 .op_name = "OP_WRITE",
1122         },
1123         [OP_RELEASE_LOCKOWNER] = {
1124                 .op_func = (nfsd4op_func)nfsd4_release_lockowner,
1125                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_ON_ABSENT_FS,
1126                 .op_name = "OP_RELEASE_LOCKOWNER",
1127         },
1128
1129         /* NFSv4.1 operations */
1130         [OP_EXCHANGE_ID] = {
1131                 .op_func = (nfsd4op_func)nfsd4_exchange_id,
1132                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_AS_FIRST_OP,
1133                 .op_name = "OP_EXCHANGE_ID",
1134         },
1135         [OP_CREATE_SESSION] = {
1136                 .op_func = (nfsd4op_func)nfsd4_create_session,
1137                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_AS_FIRST_OP,
1138                 .op_name = "OP_CREATE_SESSION",
1139         },
1140         [OP_DESTROY_SESSION] = {
1141                 .op_func = (nfsd4op_func)nfsd4_destroy_session,
1142                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_AS_FIRST_OP,
1143                 .op_name = "OP_DESTROY_SESSION",
1144         },
1145         [OP_SEQUENCE] = {
1146                 .op_func = (nfsd4op_func)nfsd4_sequence,
1147                 .op_flags = ALLOWED_WITHOUT_FH | ALLOWED_AS_FIRST_OP,
1148                 .op_name = "OP_SEQUENCE",
1149         },
1150 };
1151
1152 static const char *nfsd4_op_name(unsigned opnum)
1153 {
1154         if (opnum < ARRAY_SIZE(nfsd4_ops))
1155                 return nfsd4_ops[opnum].op_name;
1156         return "unknown_operation";
1157 }
1158
1159 #define nfs4svc_decode_voidargs         NULL
1160 #define nfs4svc_release_void            NULL
1161 #define nfsd4_voidres                   nfsd4_voidargs
1162 #define nfs4svc_release_compound        NULL
1163 struct nfsd4_voidargs { int dummy; };
1164
1165 #define PROC(name, argt, rest, relt, cache, respsize)   \
1166  { (svc_procfunc) nfsd4_proc_##name,            \
1167    (kxdrproc_t) nfs4svc_decode_##argt##args,    \
1168    (kxdrproc_t) nfs4svc_encode_##rest##res,     \
1169    (kxdrproc_t) nfs4svc_release_##relt,         \
1170    sizeof(struct nfsd4_##argt##args),           \
1171    sizeof(struct nfsd4_##rest##res),            \
1172    0,                                           \
1173    cache,                                       \
1174    respsize,                                    \
1175  }
1176
1177 /*
1178  * TODO: At the present time, the NFSv4 server does not do XID caching
1179  * of requests.  Implementing XID caching would not be a serious problem,
1180  * although it would require a mild change in interfaces since one
1181  * doesn't know whether an NFSv4 request is idempotent until after the
1182  * XDR decode.  However, XID caching totally confuses pynfs (Peter
1183  * Astrand's regression testsuite for NFSv4 servers), which reuses
1184  * XID's liberally, so I've left it unimplemented until pynfs generates
1185  * better XID's.
1186  */
1187 static struct svc_procedure             nfsd_procedures4[2] = {
1188   PROC(null,     void,          void,           void,     RC_NOCACHE, 1),
1189   PROC(compound, compound,      compound,       compound, RC_NOCACHE, NFSD_BUFSIZE/4)
1190 };
1191
1192 struct svc_version      nfsd_version4 = {
1193                 .vs_vers        = 4,
1194                 .vs_nproc       = 2,
1195                 .vs_proc        = nfsd_procedures4,
1196                 .vs_dispatch    = nfsd_dispatch,
1197                 .vs_xdrsize     = NFS4_SVC_XDRSIZE,
1198 };
1199
1200 /*
1201  * Local variables:
1202  *  c-basic-offset: 8
1203  * End:
1204  */