2021-06-18 05:31:49 +00:00
|
|
|
/* SPDX-License-Identifier: LGPL-2.1 */
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
*
|
2008-01-25 10:12:41 +00:00
|
|
|
* Copyright (C) International Business Machines Corp., 2002,2008
|
2005-04-16 22:20:36 +00:00
|
|
|
* Author(s): Steve French (sfrench@us.ibm.com)
|
2006-08-02 21:56:33 +00:00
|
|
|
* Jeremy Allison (jra@samba.org)
|
2005-04-16 22:20:36 +00:00
|
|
|
*
|
|
|
|
*/
|
2010-06-22 15:22:50 +00:00
|
|
|
#ifndef _CIFS_GLOB_H
|
|
|
|
#define _CIFS_GLOB_H
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
#include <linux/in.h>
|
|
|
|
#include <linux/in6.h>
|
2021-02-21 01:24:11 +00:00
|
|
|
#include <linux/inet.h>
|
include cleanup: Update gfp.h and slab.h includes to prepare for breaking implicit slab.h inclusion from percpu.h
percpu.h is included by sched.h and module.h and thus ends up being
included when building most .c files. percpu.h includes slab.h which
in turn includes gfp.h making everything defined by the two files
universally available and complicating inclusion dependencies.
percpu.h -> slab.h dependency is about to be removed. Prepare for
this change by updating users of gfp and slab facilities include those
headers directly instead of assuming availability. As this conversion
needs to touch large number of source files, the following script is
used as the basis of conversion.
http://userweb.kernel.org/~tj/misc/slabh-sweep.py
The script does the followings.
* Scan files for gfp and slab usages and update includes such that
only the necessary includes are there. ie. if only gfp is used,
gfp.h, if slab is used, slab.h.
* When the script inserts a new include, it looks at the include
blocks and try to put the new include such that its order conforms
to its surrounding. It's put in the include block which contains
core kernel includes, in the same order that the rest are ordered -
alphabetical, Christmas tree, rev-Xmas-tree or at the end if there
doesn't seem to be any matching order.
* If the script can't find a place to put a new include (mostly
because the file doesn't have fitting include block), it prints out
an error message indicating which .h file needs to be added to the
file.
The conversion was done in the following steps.
1. The initial automatic conversion of all .c files updated slightly
over 4000 files, deleting around 700 includes and adding ~480 gfp.h
and ~3000 slab.h inclusions. The script emitted errors for ~400
files.
2. Each error was manually checked. Some didn't need the inclusion,
some needed manual addition while adding it to implementation .h or
embedding .c file was more appropriate for others. This step added
inclusions to around 150 files.
3. The script was run again and the output was compared to the edits
from #2 to make sure no file was left behind.
4. Several build tests were done and a couple of problems were fixed.
e.g. lib/decompress_*.c used malloc/free() wrappers around slab
APIs requiring slab.h to be added manually.
5. The script was run on all .h files but without automatically
editing them as sprinkling gfp.h and slab.h inclusions around .h
files could easily lead to inclusion dependency hell. Most gfp.h
inclusion directives were ignored as stuff from gfp.h was usually
wildly available and often used in preprocessor macros. Each
slab.h inclusion directive was examined and added manually as
necessary.
6. percpu.h was updated not to include slab.h.
7. Build test were done on the following configurations and failures
were fixed. CONFIG_GCOV_KERNEL was turned off for all tests (as my
distributed build env didn't work with gcov compiles) and a few
more options had to be turned off depending on archs to make things
build (like ipr on powerpc/64 which failed due to missing writeq).
* x86 and x86_64 UP and SMP allmodconfig and a custom test config.
* powerpc and powerpc64 SMP allmodconfig
* sparc and sparc64 SMP allmodconfig
* ia64 SMP allmodconfig
* s390 SMP allmodconfig
* alpha SMP allmodconfig
* um on x86_64 SMP allmodconfig
8. percpu.h modifications were reverted so that it could be applied as
a separate patch and serve as bisection point.
Given the fact that I had only a couple of failures from tests on step
6, I'm fairly confident about the coverage of this conversion patch.
If there is a breakage, it's likely to be something in one of the arch
headers which should be easily discoverable easily on most builds of
the specific arch.
Signed-off-by: Tejun Heo <tj@kernel.org>
Guess-its-ok-by: Christoph Lameter <cl@linux-foundation.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Lee Schermerhorn <Lee.Schermerhorn@hp.com>
2010-03-24 08:04:11 +00:00
|
|
|
#include <linux/slab.h>
|
2011-12-26 18:53:34 +00:00
|
|
|
#include <linux/mempool.h>
|
2010-07-20 20:09:02 +00:00
|
|
|
#include <linux/workqueue.h>
|
2005-04-16 22:20:36 +00:00
|
|
|
#include "cifs_fs_sb.h"
|
2007-09-24 20:25:46 +00:00
|
|
|
#include "cifsacl.h"
|
2010-10-21 19:25:08 +00:00
|
|
|
#include <crypto/internal/hash.h>
|
|
|
|
#include <linux/scatterlist.h>
|
2013-08-09 12:47:17 +00:00
|
|
|
#include <uapi/linux/cifs/cifs_mount.h>
|
2021-11-04 23:39:01 +00:00
|
|
|
#include "../smbfs_common/smb2pdu.h"
|
2012-05-28 11:19:39 +00:00
|
|
|
#include "smb2pdu.h"
|
2010-10-21 19:25:08 +00:00
|
|
|
|
2012-09-18 23:20:33 +00:00
|
|
|
#define CIFS_MAGIC_NUMBER 0xFF534D42 /* the first four bytes of SMB PDUs */
|
|
|
|
|
2018-10-16 19:47:58 +00:00
|
|
|
#define SMB_PATH_MAX 260
|
2018-06-14 13:43:16 +00:00
|
|
|
#define CIFS_PORT 445
|
|
|
|
#define RFC1001_PORT 139
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* The sizes of various internal tables and strings
|
|
|
|
*/
|
|
|
|
#define MAX_UID_INFO 16
|
|
|
|
#define MAX_SES_INFO 2
|
|
|
|
#define MAX_TCON_INFO 4
|
|
|
|
|
2013-08-09 12:47:19 +00:00
|
|
|
#define MAX_TREE_SIZE (2 + CIFS_NI_MAXHOST + 1 + CIFS_MAX_SHARE_LEN + 1)
|
2005-04-16 22:20:36 +00:00
|
|
|
|
|
|
|
#define CIFS_MIN_RCV_POOL 4
|
|
|
|
|
2012-05-21 14:20:12 +00:00
|
|
|
#define MAX_REOPEN_ATT 5 /* these many maximum attempts to reopen a file */
|
2010-12-01 09:12:28 +00:00
|
|
|
/*
|
|
|
|
* default attribute cache timeout (jiffies)
|
|
|
|
*/
|
|
|
|
#define CIFS_DEF_ACTIMEO (1 * HZ)
|
|
|
|
|
|
|
|
/*
|
|
|
|
* max attribute cache timeout (jiffies) - 2^30
|
|
|
|
*/
|
|
|
|
#define CIFS_MAX_ACTIMEO (1 << 30)
|
|
|
|
|
2019-03-29 21:31:07 +00:00
|
|
|
/*
|
|
|
|
* Max persistent and resilient handle timeout (milliseconds).
|
|
|
|
* Windows durable max was 960000 (16 minutes)
|
|
|
|
*/
|
|
|
|
#define SMB3_MAX_HANDLE_TIMEOUT 960000
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* MAX_REQ is the maximum number of requests that WE will send
|
2012-03-20 09:55:09 +00:00
|
|
|
* on one socket concurrently.
|
2005-04-16 22:20:36 +00:00
|
|
|
*/
|
2012-03-20 09:55:09 +00:00
|
|
|
#define CIFS_MAX_REQ 32767
|
2005-04-16 22:20:36 +00:00
|
|
|
|
2008-12-01 20:23:50 +00:00
|
|
|
#define RFC1001_NAME_LEN 15
|
|
|
|
#define RFC1001_NAME_LEN_WITH_NULL (RFC1001_NAME_LEN + 1)
|
|
|
|
|
2018-01-24 12:46:10 +00:00
|
|
|
/* maximum length of ip addr as a string (including ipv6 and sctp) */
|
|
|
|
#define SERVER_NAME_LENGTH 80
|
2005-04-16 22:20:36 +00:00
|
|
|
#define SERVER_NAME_LEN_WITH_NULL (SERVER_NAME_LENGTH + 1)
|
|
|
|
|
2015-12-18 18:31:36 +00:00
|
|
|
/* echo interval in seconds */
|
|
|
|
#define SMB_ECHO_INTERVAL_MIN 1
|
|
|
|
#define SMB_ECHO_INTERVAL_MAX 600
|
|
|
|
#define SMB_ECHO_INTERVAL_DEFAULT 60
|
2012-07-12 14:30:44 +00:00
|
|
|
|
2021-05-18 15:05:50 +00:00
|
|
|
/* dns resolution interval in seconds */
|
|
|
|
#define SMB_DNS_RESOLVE_INTERVAL_DEFAULT 600
|
|
|
|
|
2018-08-08 05:07:45 +00:00
|
|
|
/* maximum number of PDUs in one compound */
|
|
|
|
#define MAX_COMPOUND 5
|
|
|
|
|
2016-09-23 05:44:16 +00:00
|
|
|
/*
|
|
|
|
* Default number of credits to keep available for SMB3.
|
|
|
|
* This value is chosen somewhat arbitrarily. The Windows client
|
|
|
|
* defaults to 128 credits, the Windows server allows clients up to
|
|
|
|
* 512 credits (or 8K for later versions), and the NetApp server
|
|
|
|
* does not limit clients at all. Choose a high enough default value
|
|
|
|
* such that the client shouldn't limit performance, but allow mount
|
|
|
|
* to override (until you approach 64K, where we limit credits to 65000
|
|
|
|
* to reduce possibility of seeing more server credit overflow bugs.
|
|
|
|
*/
|
|
|
|
#define SMB2_MAX_CREDITS_AVAILABLE 32000
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
#include "cifspdu.h"
|
|
|
|
|
|
|
|
#ifndef XATTR_DOS_ATTRIB
|
|
|
|
#define XATTR_DOS_ATTRIB "user.DOSATTRIB"
|
|
|
|
#endif
|
|
|
|
|
|
|
|
/*
|
|
|
|
* CIFS vfs client Status information (based on what we know.)
|
|
|
|
*/
|
|
|
|
|
2010-10-23 16:51:40 +00:00
|
|
|
/* associated with each tcp and smb session */
|
2005-04-16 22:20:36 +00:00
|
|
|
enum statusEnum {
|
|
|
|
CifsNew = 0,
|
|
|
|
CifsGood,
|
|
|
|
CifsExiting,
|
2011-04-12 01:01:14 +00:00
|
|
|
CifsNeedReconnect,
|
|
|
|
CifsNeedNegotiate
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
enum securityEnum {
|
2013-05-26 11:00:58 +00:00
|
|
|
Unspecified = 0, /* not specified */
|
2005-04-16 22:20:36 +00:00
|
|
|
NTLMv2, /* Legacy NTLM auth with NTLMv2 hash */
|
2009-05-06 04:16:04 +00:00
|
|
|
RawNTLMSSP, /* NTLMSSP without SPNEGO, NTLMv2 hash */
|
2008-08-19 19:35:33 +00:00
|
|
|
Kerberos, /* Kerberos via SPNEGO */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2010-09-19 03:01:58 +00:00
|
|
|
struct session_key {
|
2007-07-09 07:55:14 +00:00
|
|
|
unsigned int len;
|
2010-10-21 11:42:55 +00:00
|
|
|
char *response;
|
2007-07-09 07:55:14 +00:00
|
|
|
};
|
|
|
|
|
2010-10-21 19:25:08 +00:00
|
|
|
/* crypto security descriptor definition */
|
|
|
|
struct sdesc {
|
|
|
|
struct shash_desc shash;
|
|
|
|
char ctx[];
|
|
|
|
};
|
|
|
|
|
2010-10-26 23:10:24 +00:00
|
|
|
/* crypto hashing related structure/fields, not specific to a sec mech */
|
2010-10-21 19:25:08 +00:00
|
|
|
struct cifs_secmech {
|
|
|
|
struct crypto_shash *hmacmd5; /* hmac-md5 hash function */
|
|
|
|
struct crypto_shash *md5; /* md5 hash function */
|
2012-09-18 23:20:30 +00:00
|
|
|
struct crypto_shash *hmacsha256; /* hmac-sha256 hash function */
|
2013-06-27 04:45:05 +00:00
|
|
|
struct crypto_shash *cmacaes; /* block-cipher based MAC function */
|
2018-02-16 18:19:28 +00:00
|
|
|
struct crypto_shash *sha512; /* sha512 hash function */
|
2010-10-21 19:25:08 +00:00
|
|
|
struct sdesc *sdeschmacmd5; /* ctxt to generate ntlmv2 hash, CR1 */
|
|
|
|
struct sdesc *sdescmd5; /* ctxt to generate cifs/smb signature */
|
2012-09-18 23:20:30 +00:00
|
|
|
struct sdesc *sdeschmacsha256; /* ctxt to generate smb2 signature */
|
2013-06-27 04:45:05 +00:00
|
|
|
struct sdesc *sdesccmacaes; /* ctxt to generate smb3 signature */
|
2018-02-16 18:19:28 +00:00
|
|
|
struct sdesc *sdescsha512; /* ctxt to generate smb3.11 signing key */
|
2016-11-03 23:47:37 +00:00
|
|
|
struct crypto_aead *ccmaesencrypt; /* smb3 encryption aead */
|
|
|
|
struct crypto_aead *ccmaesdecrypt; /* smb3 decryption aead */
|
2010-10-21 19:25:08 +00:00
|
|
|
};
|
|
|
|
|
2010-10-28 14:53:07 +00:00
|
|
|
/* per smb session structure/fields */
|
2010-10-21 19:25:08 +00:00
|
|
|
struct ntlmssp_auth {
|
2013-08-29 13:35:10 +00:00
|
|
|
bool sesskey_per_smbsess; /* whether session key is per smb session */
|
2010-10-21 19:25:08 +00:00
|
|
|
__u32 client_flags; /* sent by client in type 1 ntlmsssp exchange */
|
|
|
|
__u32 server_flags; /* sent by server in type 2 ntlmssp exchange */
|
|
|
|
unsigned char ciphertext[CIFS_CPHTXT_SIZE]; /* sent to server */
|
2010-10-28 14:53:07 +00:00
|
|
|
char cryptkey[CIFS_CRYPTO_KEY_SIZE]; /* used by ntlmssp */
|
2010-10-21 19:25:08 +00:00
|
|
|
};
|
|
|
|
|
2007-09-24 20:25:46 +00:00
|
|
|
struct cifs_cred {
|
|
|
|
int uid;
|
|
|
|
int gid;
|
|
|
|
int mode;
|
|
|
|
int cecount;
|
|
|
|
struct cifs_sid osid;
|
|
|
|
struct cifs_sid gsid;
|
|
|
|
struct cifs_ntace *ntaces;
|
|
|
|
struct cifs_ace *aces;
|
|
|
|
};
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
*****************************************************************
|
|
|
|
* Except the CIFS PDUs themselves all the
|
|
|
|
* globally interesting structs should go here
|
|
|
|
*****************************************************************
|
|
|
|
*/
|
|
|
|
|
2012-09-18 23:20:34 +00:00
|
|
|
/*
|
|
|
|
* A smb_rqst represents a complete request to be issued to a server. It's
|
|
|
|
* formed by a kvec array, followed by an array of pages. Page data is assumed
|
|
|
|
* to start at the beginning of the first page.
|
|
|
|
*/
|
|
|
|
struct smb_rqst {
|
|
|
|
struct kvec *rq_iov; /* array of kvecs */
|
|
|
|
unsigned int rq_nvec; /* number of kvecs in array */
|
|
|
|
struct page **rq_pages; /* pointer to array of page ptrs */
|
2018-05-30 19:47:53 +00:00
|
|
|
unsigned int rq_offset; /* the offset to the 1st page */
|
2012-09-18 23:20:34 +00:00
|
|
|
unsigned int rq_npages; /* number pages in array */
|
|
|
|
unsigned int rq_pagesz; /* page size to use */
|
|
|
|
unsigned int rq_tailsz; /* length of last page */
|
|
|
|
};
|
|
|
|
|
2012-05-15 16:21:10 +00:00
|
|
|
struct mid_q_entry;
|
|
|
|
struct TCP_Server_Info;
|
2012-02-28 11:04:17 +00:00
|
|
|
struct cifsFileInfo;
|
2012-05-17 08:18:21 +00:00
|
|
|
struct cifs_ses;
|
2012-05-25 07:11:39 +00:00
|
|
|
struct cifs_tcon;
|
2012-05-27 16:21:53 +00:00
|
|
|
struct dfs_info3_param;
|
2012-05-27 13:34:43 +00:00
|
|
|
struct cifs_fattr;
|
2020-12-10 05:07:12 +00:00
|
|
|
struct smb3_fs_context;
|
2012-09-18 23:20:26 +00:00
|
|
|
struct cifs_fid;
|
2012-09-18 23:20:28 +00:00
|
|
|
struct cifs_readdata;
|
2012-09-18 23:20:29 +00:00
|
|
|
struct cifs_writedata;
|
2012-09-18 23:20:29 +00:00
|
|
|
struct cifs_io_parms;
|
2012-09-18 23:20:32 +00:00
|
|
|
struct cifs_search_info;
|
2012-09-18 23:20:33 +00:00
|
|
|
struct cifsInodeInfo;
|
2013-07-05 08:00:30 +00:00
|
|
|
struct cifs_open_parms;
|
2019-01-16 19:12:41 +00:00
|
|
|
struct cifs_credits;
|
2012-05-15 16:21:10 +00:00
|
|
|
|
2012-05-15 16:20:51 +00:00
|
|
|
struct smb_version_operations {
|
2016-11-23 23:08:14 +00:00
|
|
|
int (*send_cancel)(struct TCP_Server_Info *, struct smb_rqst *,
|
2012-05-15 16:21:10 +00:00
|
|
|
struct mid_q_entry *);
|
2012-02-28 11:04:17 +00:00
|
|
|
bool (*compare_fids)(struct cifsFileInfo *, struct cifsFileInfo *);
|
2012-05-17 08:18:21 +00:00
|
|
|
/* setup request: allocate mid, sign message */
|
2012-09-18 23:20:35 +00:00
|
|
|
struct mid_q_entry *(*setup_request)(struct cifs_ses *,
|
2019-09-20 04:08:34 +00:00
|
|
|
struct TCP_Server_Info *,
|
|
|
|
struct smb_rqst *);
|
2012-06-01 10:26:18 +00:00
|
|
|
/* setup async request: allocate mid, sign message */
|
2012-09-18 23:20:35 +00:00
|
|
|
struct mid_q_entry *(*setup_async_request)(struct TCP_Server_Info *,
|
|
|
|
struct smb_rqst *);
|
2012-05-17 08:18:21 +00:00
|
|
|
/* check response: verify signature, map error */
|
|
|
|
int (*check_receive)(struct mid_q_entry *, struct TCP_Server_Info *,
|
|
|
|
bool);
|
2019-01-16 19:12:41 +00:00
|
|
|
void (*add_credits)(struct TCP_Server_Info *server,
|
|
|
|
const struct cifs_credits *credits,
|
|
|
|
const int optype);
|
2012-05-17 13:53:29 +00:00
|
|
|
void (*set_credits)(struct TCP_Server_Info *, const int);
|
2012-05-23 12:14:34 +00:00
|
|
|
int * (*get_credits_field)(struct TCP_Server_Info *, const int);
|
|
|
|
unsigned int (*get_credits)(struct mid_q_entry *);
|
2012-05-23 10:01:59 +00:00
|
|
|
__u64 (*get_next_mid)(struct TCP_Server_Info *);
|
2019-03-04 22:02:50 +00:00
|
|
|
void (*revert_current_mid)(struct TCP_Server_Info *server,
|
|
|
|
const unsigned int val);
|
2012-05-17 09:02:51 +00:00
|
|
|
/* data offset from read response message */
|
|
|
|
unsigned int (*read_data_offset)(char *);
|
2017-11-23 00:38:46 +00:00
|
|
|
/*
|
|
|
|
* Data length from read response message
|
|
|
|
* When in_remaining is true, the returned data length is in
|
|
|
|
* message field DataRemaining for out-of-band data read (e.g through
|
|
|
|
* Memory Registration RDMA write in SMBD).
|
|
|
|
* Otherwise, the returned data length is in message field DataLength.
|
|
|
|
*/
|
|
|
|
unsigned int (*read_data_length)(char *, bool in_remaining);
|
2012-05-17 09:02:51 +00:00
|
|
|
/* map smb to linux error */
|
|
|
|
int (*map_error)(char *, bool);
|
2012-05-17 09:25:35 +00:00
|
|
|
/* find mid corresponding to the response message */
|
|
|
|
struct mid_q_entry * (*find_mid)(struct TCP_Server_Info *, char *);
|
2018-04-22 20:45:53 +00:00
|
|
|
void (*dump_detail)(void *buf, struct TCP_Server_Info *ptcp_info);
|
2012-05-28 10:16:31 +00:00
|
|
|
void (*clear_stats)(struct cifs_tcon *);
|
|
|
|
void (*print_stats)(struct seq_file *m, struct cifs_tcon *);
|
2013-06-19 19:15:30 +00:00
|
|
|
void (*dump_share_caps)(struct seq_file *, struct cifs_tcon *);
|
2012-05-17 09:25:35 +00:00
|
|
|
/* verify the message */
|
2015-12-18 19:05:30 +00:00
|
|
|
int (*check_message)(char *, unsigned int, struct TCP_Server_Info *);
|
2012-05-17 09:25:35 +00:00
|
|
|
bool (*is_oplock_break)(char *, struct TCP_Server_Info *);
|
2021-03-08 15:00:50 +00:00
|
|
|
int (*handle_cancelled_mid)(struct mid_q_entry *, struct TCP_Server_Info *);
|
2019-10-29 23:51:19 +00:00
|
|
|
void (*downgrade_oplock)(struct TCP_Server_Info *server,
|
|
|
|
struct cifsInodeInfo *cinode, __u32 oplock,
|
|
|
|
unsigned int epoch, bool *purge_cache);
|
2012-05-23 10:31:03 +00:00
|
|
|
/* process transaction2 response */
|
|
|
|
bool (*check_trans2)(struct mid_q_entry *, struct TCP_Server_Info *,
|
|
|
|
char *, int);
|
2012-05-25 06:43:58 +00:00
|
|
|
/* check if we need to negotiate */
|
|
|
|
bool (*need_neg)(struct TCP_Server_Info *);
|
|
|
|
/* negotiate to the server */
|
|
|
|
int (*negotiate)(const unsigned int, struct cifs_ses *);
|
2012-09-18 23:20:28 +00:00
|
|
|
/* set negotiated write size */
|
2020-12-10 05:07:12 +00:00
|
|
|
unsigned int (*negotiate_wsize)(struct cifs_tcon *tcon, struct smb3_fs_context *ctx);
|
2012-09-18 23:20:28 +00:00
|
|
|
/* set negotiated read size */
|
2020-12-10 05:07:12 +00:00
|
|
|
unsigned int (*negotiate_rsize)(struct cifs_tcon *tcon, struct smb3_fs_context *ctx);
|
2012-05-25 06:54:49 +00:00
|
|
|
/* setup smb sessionn */
|
|
|
|
int (*sess_setup)(const unsigned int, struct cifs_ses *,
|
|
|
|
const struct nls_table *);
|
|
|
|
/* close smb session */
|
|
|
|
int (*logoff)(const unsigned int, struct cifs_ses *);
|
2012-05-25 07:11:39 +00:00
|
|
|
/* connect to a server share */
|
|
|
|
int (*tree_connect)(const unsigned int, struct cifs_ses *, const char *,
|
|
|
|
struct cifs_tcon *, const struct nls_table *);
|
|
|
|
/* close tree connecion */
|
|
|
|
int (*tree_disconnect)(const unsigned int, struct cifs_tcon *);
|
2012-05-27 16:21:53 +00:00
|
|
|
/* get DFS referrals */
|
|
|
|
int (*get_dfs_refer)(const unsigned int, struct cifs_ses *,
|
|
|
|
const char *, struct dfs_info3_param **,
|
|
|
|
unsigned int *, const struct nls_table *, int);
|
2012-05-27 16:48:35 +00:00
|
|
|
/* informational QFS call */
|
2020-02-03 19:46:43 +00:00
|
|
|
void (*qfs_tcon)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *);
|
2012-05-25 10:40:22 +00:00
|
|
|
/* check if a path is accessible or not */
|
|
|
|
int (*is_path_accessible)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *, const char *);
|
2012-05-27 13:34:43 +00:00
|
|
|
/* query path data from the server */
|
|
|
|
int (*query_path_info)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *, const char *,
|
2013-10-23 13:49:47 +00:00
|
|
|
FILE_ALL_INFO *, bool *, bool *);
|
2012-09-18 23:20:26 +00:00
|
|
|
/* query file data from the server */
|
|
|
|
int (*query_file_info)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_fid *, FILE_ALL_INFO *);
|
2020-10-23 03:03:14 +00:00
|
|
|
/* query reparse tag from srv to determine which type of special file */
|
|
|
|
int (*query_reparse_tag)(const unsigned int xid, struct cifs_tcon *tcon,
|
|
|
|
struct cifs_sb_info *cifs_sb, const char *path,
|
|
|
|
__u32 *reparse_tag);
|
2012-05-27 13:34:43 +00:00
|
|
|
/* get server index number */
|
|
|
|
int (*get_srv_inum)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *, const char *,
|
|
|
|
u64 *uniqueid, FILE_ALL_INFO *);
|
2012-09-18 23:20:31 +00:00
|
|
|
/* set size by path */
|
|
|
|
int (*set_path_size)(const unsigned int, struct cifs_tcon *,
|
|
|
|
const char *, __u64, struct cifs_sb_info *, bool);
|
|
|
|
/* set size by file handle */
|
|
|
|
int (*set_file_size)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifsFileInfo *, __u64, bool);
|
2012-09-18 23:20:32 +00:00
|
|
|
/* set attributes */
|
|
|
|
int (*set_file_info)(struct inode *, const char *, FILE_BASIC_INFO *,
|
|
|
|
const unsigned int);
|
2013-10-14 20:31:32 +00:00
|
|
|
int (*set_compression)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifsFileInfo *);
|
2012-05-25 10:47:16 +00:00
|
|
|
/* check if we can send an echo or nor */
|
|
|
|
bool (*can_echo)(struct TCP_Server_Info *);
|
|
|
|
/* send echo request */
|
|
|
|
int (*echo)(struct TCP_Server_Info *);
|
2012-03-17 08:41:12 +00:00
|
|
|
/* create directory */
|
2018-06-15 02:56:32 +00:00
|
|
|
int (*posix_mkdir)(const unsigned int xid, struct inode *inode,
|
|
|
|
umode_t mode, struct cifs_tcon *tcon,
|
|
|
|
const char *full_path,
|
|
|
|
struct cifs_sb_info *cifs_sb);
|
2019-09-25 05:32:13 +00:00
|
|
|
int (*mkdir)(const unsigned int xid, struct inode *inode, umode_t mode,
|
|
|
|
struct cifs_tcon *tcon, const char *name,
|
|
|
|
struct cifs_sb_info *sb);
|
2012-03-17 08:41:12 +00:00
|
|
|
/* set info on created directory */
|
|
|
|
void (*mkdir_setinfo)(struct inode *, const char *,
|
|
|
|
struct cifs_sb_info *, struct cifs_tcon *,
|
|
|
|
const unsigned int);
|
2012-07-10 12:14:18 +00:00
|
|
|
/* remove directory */
|
|
|
|
int (*rmdir)(const unsigned int, struct cifs_tcon *, const char *,
|
|
|
|
struct cifs_sb_info *);
|
2012-09-18 23:20:25 +00:00
|
|
|
/* unlink file */
|
|
|
|
int (*unlink)(const unsigned int, struct cifs_tcon *, const char *,
|
|
|
|
struct cifs_sb_info *);
|
|
|
|
/* open, rename and delete file */
|
|
|
|
int (*rename_pending_delete)(const char *, struct dentry *,
|
|
|
|
const unsigned int);
|
2012-09-18 23:20:30 +00:00
|
|
|
/* send rename request */
|
|
|
|
int (*rename)(const unsigned int, struct cifs_tcon *, const char *,
|
|
|
|
const char *, struct cifs_sb_info *);
|
2012-09-18 23:20:31 +00:00
|
|
|
/* send create hardlink request */
|
|
|
|
int (*create_hardlink)(const unsigned int, struct cifs_tcon *,
|
|
|
|
const char *, const char *,
|
|
|
|
struct cifs_sb_info *);
|
2013-08-14 15:25:21 +00:00
|
|
|
/* query symlink target */
|
|
|
|
int (*query_symlink)(const unsigned int, struct cifs_tcon *,
|
2019-04-09 22:44:46 +00:00
|
|
|
struct cifs_sb_info *, const char *,
|
|
|
|
char **, bool);
|
2012-09-18 23:20:26 +00:00
|
|
|
/* open a file for non-posix mounts */
|
2013-07-05 08:00:30 +00:00
|
|
|
int (*open)(const unsigned int, struct cifs_open_parms *,
|
|
|
|
__u32 *, FILE_ALL_INFO *);
|
2012-09-18 23:20:26 +00:00
|
|
|
/* set fid protocol-specific info */
|
|
|
|
void (*set_fid)(struct cifsFileInfo *, struct cifs_fid *, __u32);
|
2012-09-18 23:20:26 +00:00
|
|
|
/* close a file */
|
2012-09-25 07:00:07 +00:00
|
|
|
void (*close)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_fid *);
|
2019-12-03 03:46:54 +00:00
|
|
|
/* close a file, returning file attributes and timestamps */
|
|
|
|
void (*close_getattr)(const unsigned int xid, struct cifs_tcon *tcon,
|
|
|
|
struct cifsFileInfo *pfile_info);
|
2012-09-18 23:20:27 +00:00
|
|
|
/* send a flush request to the server */
|
|
|
|
int (*flush)(const unsigned int, struct cifs_tcon *, struct cifs_fid *);
|
2012-09-18 23:20:28 +00:00
|
|
|
/* async read from the server */
|
|
|
|
int (*async_readv)(struct cifs_readdata *);
|
2012-09-18 23:20:29 +00:00
|
|
|
/* async write to the server */
|
2014-02-08 02:45:12 +00:00
|
|
|
int (*async_writev)(struct cifs_writedata *,
|
|
|
|
void (*release)(struct kref *));
|
2012-09-18 23:20:29 +00:00
|
|
|
/* sync read from the server */
|
2014-09-22 10:13:55 +00:00
|
|
|
int (*sync_read)(const unsigned int, struct cifs_fid *,
|
2012-09-18 23:20:29 +00:00
|
|
|
struct cifs_io_parms *, unsigned int *, char **,
|
|
|
|
int *);
|
2012-09-18 23:20:30 +00:00
|
|
|
/* sync write to the server */
|
2014-09-22 10:13:55 +00:00
|
|
|
int (*sync_write)(const unsigned int, struct cifs_fid *,
|
2012-09-18 23:20:30 +00:00
|
|
|
struct cifs_io_parms *, unsigned int *, struct kvec *,
|
|
|
|
unsigned long);
|
2012-09-18 23:20:32 +00:00
|
|
|
/* open dir, start readdir */
|
|
|
|
int (*query_dir_first)(const unsigned int, struct cifs_tcon *,
|
|
|
|
const char *, struct cifs_sb_info *,
|
|
|
|
struct cifs_fid *, __u16,
|
|
|
|
struct cifs_search_info *);
|
|
|
|
/* continue readdir */
|
|
|
|
int (*query_dir_next)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_fid *,
|
|
|
|
__u16, struct cifs_search_info *srch_inf);
|
|
|
|
/* close dir */
|
|
|
|
int (*close_dir)(const unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_fid *);
|
|
|
|
/* calculate a size of SMB message */
|
2018-04-22 21:30:12 +00:00
|
|
|
unsigned int (*calc_smb_size)(void *buf, struct TCP_Server_Info *ptcpi);
|
2019-01-24 01:11:16 +00:00
|
|
|
/* check for STATUS_PENDING and process the response if yes */
|
|
|
|
bool (*is_status_pending)(char *buf, struct TCP_Server_Info *server);
|
2017-07-08 21:32:00 +00:00
|
|
|
/* check for STATUS_NETWORK_SESSION_EXPIRED */
|
|
|
|
bool (*is_session_expired)(char *);
|
2012-09-18 23:20:33 +00:00
|
|
|
/* send oplock break response */
|
|
|
|
int (*oplock_response)(struct cifs_tcon *, struct cifs_fid *,
|
|
|
|
struct cifsInodeInfo *);
|
2012-09-18 23:20:33 +00:00
|
|
|
/* query remote filesystem */
|
|
|
|
int (*queryfs)(const unsigned int, struct cifs_tcon *,
|
2020-02-03 19:46:43 +00:00
|
|
|
struct cifs_sb_info *, struct kstatfs *);
|
2012-09-19 13:22:43 +00:00
|
|
|
/* send mandatory brlock to the server */
|
|
|
|
int (*mand_lock)(const unsigned int, struct cifsFileInfo *, __u64,
|
|
|
|
__u64, __u32, int, int, bool);
|
|
|
|
/* unlock range of mandatory locks */
|
|
|
|
int (*mand_unlock_range)(struct cifsFileInfo *, struct file_lock *,
|
|
|
|
const unsigned int);
|
|
|
|
/* push brlocks from the cache to the server */
|
|
|
|
int (*push_mand_locks)(struct cifsFileInfo *);
|
2012-09-19 13:22:44 +00:00
|
|
|
/* get lease key of the inode */
|
2013-09-04 09:07:41 +00:00
|
|
|
void (*get_lease_key)(struct inode *, struct cifs_fid *);
|
2012-09-19 13:22:44 +00:00
|
|
|
/* set lease key of the inode */
|
2013-09-04 09:07:41 +00:00
|
|
|
void (*set_lease_key)(struct inode *, struct cifs_fid *);
|
2012-09-19 13:22:44 +00:00
|
|
|
/* generate new lease key */
|
2013-09-04 09:07:41 +00:00
|
|
|
void (*new_lease_key)(struct cifs_fid *);
|
2013-08-29 13:35:11 +00:00
|
|
|
int (*generate_signingkey)(struct cifs_ses *);
|
2020-03-31 23:21:43 +00:00
|
|
|
int (*calc_signature)(struct smb_rqst *, struct TCP_Server_Info *,
|
|
|
|
bool allocate_crypto);
|
2015-06-24 08:17:02 +00:00
|
|
|
int (*set_integrity)(const unsigned int, struct cifs_tcon *tcon,
|
|
|
|
struct cifsFileInfo *src_file);
|
2016-10-01 02:14:26 +00:00
|
|
|
int (*enum_snapshots)(const unsigned int xid, struct cifs_tcon *tcon,
|
|
|
|
struct cifsFileInfo *src_file, void __user *);
|
2020-02-06 12:00:14 +00:00
|
|
|
int (*notify)(const unsigned int xid, struct file *pfile,
|
|
|
|
void __user *pbuf);
|
2013-11-25 17:09:49 +00:00
|
|
|
int (*query_mf_symlink)(unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *, const unsigned char *,
|
|
|
|
char *, unsigned int *);
|
2013-11-25 17:09:52 +00:00
|
|
|
int (*create_mf_symlink)(unsigned int, struct cifs_tcon *,
|
|
|
|
struct cifs_sb_info *, const unsigned char *,
|
|
|
|
char *, unsigned int *);
|
2013-09-05 12:11:28 +00:00
|
|
|
/* if we can do cache read operations */
|
|
|
|
bool (*is_read_op)(__u32);
|
|
|
|
/* set oplock level for the inode */
|
2013-09-05 17:30:16 +00:00
|
|
|
void (*set_oplock_level)(struct cifsInodeInfo *, __u32, unsigned int,
|
|
|
|
bool *);
|
2013-09-04 09:07:41 +00:00
|
|
|
/* create lease context buffer for CREATE request */
|
2018-07-05 13:10:02 +00:00
|
|
|
char * (*create_lease_buf)(u8 *lease_key, u8 oplock);
|
2013-09-05 17:30:16 +00:00
|
|
|
/* parse lease context buffer and return oplock/epoch info */
|
2018-04-26 14:10:18 +00:00
|
|
|
__u8 (*parse_lease_buf)(void *buf, unsigned int *epoch, char *lkey);
|
2017-02-10 10:33:51 +00:00
|
|
|
ssize_t (*copychunk_range)(const unsigned int,
|
2017-04-04 07:12:04 +00:00
|
|
|
struct cifsFileInfo *src_file,
|
2017-02-10 10:33:51 +00:00
|
|
|
struct cifsFileInfo *target_file,
|
|
|
|
u64 src_off, u64 len, u64 dest_off);
|
2015-06-28 04:18:36 +00:00
|
|
|
int (*duplicate_extents)(const unsigned int, struct cifsFileInfo *src,
|
|
|
|
struct cifsFileInfo *target_file, u64 src_off, u64 len,
|
|
|
|
u64 dest_off);
|
2013-11-20 05:44:46 +00:00
|
|
|
int (*validate_negotiate)(const unsigned int, struct cifs_tcon *);
|
2014-01-27 05:53:43 +00:00
|
|
|
ssize_t (*query_all_EAs)(const unsigned int, struct cifs_tcon *,
|
|
|
|
const unsigned char *, const unsigned char *, char *,
|
2017-05-13 01:59:10 +00:00
|
|
|
size_t, struct cifs_sb_info *);
|
2014-01-27 05:53:43 +00:00
|
|
|
int (*set_EA)(const unsigned int, struct cifs_tcon *, const char *,
|
|
|
|
const char *, const void *, const __u16,
|
2017-08-24 01:24:56 +00:00
|
|
|
const struct nls_table *, struct cifs_sb_info *);
|
2014-02-03 05:31:47 +00:00
|
|
|
struct cifs_ntsd * (*get_acl)(struct cifs_sb_info *, struct inode *,
|
2020-12-18 17:30:12 +00:00
|
|
|
const char *, u32 *, u32);
|
2014-02-10 20:08:16 +00:00
|
|
|
struct cifs_ntsd * (*get_acl_by_fid)(struct cifs_sb_info *,
|
2020-12-18 17:30:12 +00:00
|
|
|
const struct cifs_fid *, u32 *, u32);
|
2014-02-03 05:31:47 +00:00
|
|
|
int (*set_acl)(struct cifs_ntsd *, __u32, struct inode *, const char *,
|
|
|
|
int);
|
2014-06-22 07:03:22 +00:00
|
|
|
/* writepages retry size */
|
|
|
|
unsigned int (*wp_retry_size)(struct inode *);
|
2014-06-05 15:03:27 +00:00
|
|
|
/* get mtu credits */
|
|
|
|
int (*wait_mtu_credits)(struct TCP_Server_Info *, unsigned int,
|
2019-01-16 19:12:41 +00:00
|
|
|
unsigned int *, struct cifs_credits *);
|
2019-01-24 02:15:52 +00:00
|
|
|
/* adjust previously taken mtu credits to request size */
|
|
|
|
int (*adjust_credits)(struct TCP_Server_Info *server,
|
|
|
|
struct cifs_credits *credits,
|
|
|
|
const unsigned int payload_size);
|
2014-08-18 16:49:57 +00:00
|
|
|
/* check if we need to issue closedir */
|
|
|
|
bool (*dir_needs_close)(struct cifsFileInfo *);
|
2014-08-17 13:38:47 +00:00
|
|
|
long (*fallocate)(struct file *, struct cifs_tcon *, int, loff_t,
|
|
|
|
loff_t);
|
2016-10-31 20:49:30 +00:00
|
|
|
/* init transform request - used for encryption for now */
|
2018-07-31 23:26:11 +00:00
|
|
|
int (*init_transform_rq)(struct TCP_Server_Info *, int num_rqst,
|
|
|
|
struct smb_rqst *, struct smb_rqst *);
|
2016-11-17 23:24:34 +00:00
|
|
|
int (*is_transform_hdr)(void *buf);
|
|
|
|
int (*receive_transform)(struct TCP_Server_Info *,
|
2018-08-08 05:07:45 +00:00
|
|
|
struct mid_q_entry **, char **, int *);
|
2017-01-18 10:05:57 +00:00
|
|
|
enum securityEnum (*select_sectype)(struct TCP_Server_Info *,
|
|
|
|
enum securityEnum);
|
2018-06-01 00:53:08 +00:00
|
|
|
int (*next_header)(char *);
|
2018-10-08 00:19:58 +00:00
|
|
|
/* ioctl passthrough for query_info */
|
|
|
|
int (*ioctl_query_info)(const unsigned int xid,
|
2018-10-16 19:47:58 +00:00
|
|
|
struct cifs_tcon *tcon,
|
2020-02-03 19:46:43 +00:00
|
|
|
struct cifs_sb_info *cifs_sb,
|
2018-10-16 19:47:58 +00:00
|
|
|
__le16 *path, int is_dir,
|
2018-10-08 00:19:58 +00:00
|
|
|
unsigned long p);
|
2019-03-14 05:29:17 +00:00
|
|
|
/* make unix special files (block, char, fifo, socket) */
|
|
|
|
int (*make_node)(unsigned int xid,
|
|
|
|
struct inode *inode,
|
|
|
|
struct dentry *dentry,
|
|
|
|
struct cifs_tcon *tcon,
|
2021-03-18 05:38:53 +00:00
|
|
|
const char *full_path,
|
2019-03-14 05:29:17 +00:00
|
|
|
umode_t mode,
|
|
|
|
dev_t device_number);
|
2019-04-25 06:45:29 +00:00
|
|
|
/* version specific fiemap implementation */
|
|
|
|
int (*fiemap)(struct cifs_tcon *tcon, struct cifsFileInfo *,
|
|
|
|
struct fiemap_extent_info *, u64, u64);
|
2019-05-14 21:17:02 +00:00
|
|
|
/* version specific llseek implementation */
|
|
|
|
loff_t (*llseek)(struct file *, struct cifs_tcon *, loff_t, int);
|
2020-09-18 05:37:28 +00:00
|
|
|
/* Check for STATUS_IO_TIMEOUT */
|
|
|
|
bool (*is_status_io_timeout)(char *buf);
|
2021-02-16 10:40:45 +00:00
|
|
|
/* Check for STATUS_NETWORK_NAME_DELETED */
|
|
|
|
void (*is_network_name_deleted)(char *buf, struct TCP_Server_Info *srv);
|
2012-05-15 16:20:51 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
struct smb_version_values {
|
|
|
|
char *version_string;
|
2012-10-01 17:26:22 +00:00
|
|
|
__u16 protocol_id;
|
|
|
|
__u32 req_capabilities;
|
2012-02-28 11:23:34 +00:00
|
|
|
__u32 large_lock_type;
|
|
|
|
__u32 exclusive_lock_type;
|
|
|
|
__u32 shared_lock_type;
|
|
|
|
__u32 unlock_lock_type;
|
2018-03-31 00:45:31 +00:00
|
|
|
size_t header_preamble_size;
|
2012-05-17 08:45:31 +00:00
|
|
|
size_t header_size;
|
|
|
|
size_t max_header_size;
|
2012-05-17 09:02:51 +00:00
|
|
|
size_t read_rsp_size;
|
2011-12-26 18:53:34 +00:00
|
|
|
__le16 lock_cmd;
|
2012-07-13 09:58:14 +00:00
|
|
|
unsigned int cap_unix;
|
|
|
|
unsigned int cap_nt_find;
|
|
|
|
unsigned int cap_large_files;
|
2013-06-27 16:45:00 +00:00
|
|
|
__u16 signing_enabled;
|
|
|
|
__u16 signing_required;
|
2013-09-04 09:07:41 +00:00
|
|
|
size_t create_lease_size;
|
2012-05-15 16:20:51 +00:00
|
|
|
};
|
|
|
|
|
2012-05-17 08:45:31 +00:00
|
|
|
#define HEADER_SIZE(server) (server->vals->header_size)
|
|
|
|
#define MAX_HEADER_SIZE(server) (server->vals->max_header_size)
|
|
|
|
|
2019-04-02 11:00:33 +00:00
|
|
|
/**
|
|
|
|
* CIFS superblock mount flags (mnt_cifs_flags) to consider when
|
|
|
|
* trying to reuse existing superblock for a new mount
|
|
|
|
*/
|
2011-05-26 19:35:47 +00:00
|
|
|
#define CIFS_MOUNT_MASK (CIFS_MOUNT_NO_PERM | CIFS_MOUNT_SET_UID | \
|
|
|
|
CIFS_MOUNT_SERVER_INUM | CIFS_MOUNT_DIRECT_IO | \
|
|
|
|
CIFS_MOUNT_NO_XATTR | CIFS_MOUNT_MAP_SPECIAL_CHR | \
|
2014-09-27 07:19:01 +00:00
|
|
|
CIFS_MOUNT_MAP_SFM_CHR | \
|
2011-05-26 19:35:47 +00:00
|
|
|
CIFS_MOUNT_UNX_EMUL | CIFS_MOUNT_NO_BRL | \
|
|
|
|
CIFS_MOUNT_CIFS_ACL | CIFS_MOUNT_OVERR_UID | \
|
|
|
|
CIFS_MOUNT_OVERR_GID | CIFS_MOUNT_DYNPERM | \
|
|
|
|
CIFS_MOUNT_NOPOSIXBRL | CIFS_MOUNT_NOSSYNC | \
|
|
|
|
CIFS_MOUNT_FSCACHE | CIFS_MOUNT_MF_SYMLINKS | \
|
2011-09-26 14:56:44 +00:00
|
|
|
CIFS_MOUNT_MULTIUSER | CIFS_MOUNT_STRICT_IO | \
|
2019-04-02 11:00:33 +00:00
|
|
|
CIFS_MOUNT_CIFS_BACKUPUID | CIFS_MOUNT_CIFS_BACKUPGID | \
|
2019-06-24 06:19:52 +00:00
|
|
|
CIFS_MOUNT_UID_FROM_ACL | CIFS_MOUNT_NO_HANDLE_CACHE | \
|
2019-08-28 04:58:54 +00:00
|
|
|
CIFS_MOUNT_NO_DFS | CIFS_MOUNT_MODE_FROM_SID | \
|
2019-08-30 07:12:41 +00:00
|
|
|
CIFS_MOUNT_RO_CACHE | CIFS_MOUNT_RW_CACHE)
|
2011-05-26 19:35:47 +00:00
|
|
|
|
2019-04-02 11:00:33 +00:00
|
|
|
/**
|
|
|
|
* Generic VFS superblock mount flags (s_flags) to consider when
|
|
|
|
* trying to reuse existing superblock for a new mount
|
|
|
|
*/
|
2017-11-27 21:05:09 +00:00
|
|
|
#define CIFS_MS_MASK (SB_RDONLY | SB_MANDLOCK | SB_NOEXEC | SB_NOSUID | \
|
|
|
|
SB_NODEV | SB_SYNCHRONOUS)
|
2011-05-26 19:35:47 +00:00
|
|
|
|
|
|
|
struct cifs_mnt_data {
|
|
|
|
struct cifs_sb_info *cifs_sb;
|
2020-12-10 05:07:12 +00:00
|
|
|
struct smb3_fs_context *ctx;
|
2011-05-26 19:35:47 +00:00
|
|
|
int flags;
|
|
|
|
};
|
|
|
|
|
2012-03-23 18:28:02 +00:00
|
|
|
static inline unsigned int
|
|
|
|
get_rfc1002_length(void *buf)
|
|
|
|
{
|
2014-02-23 00:35:38 +00:00
|
|
|
return be32_to_cpu(*((__be32 *)buf)) & 0xffffff;
|
2012-03-23 18:28:02 +00:00
|
|
|
}
|
|
|
|
|
2011-12-27 12:12:43 +00:00
|
|
|
static inline void
|
|
|
|
inc_rfc1001_len(void *buf, int count)
|
|
|
|
{
|
|
|
|
be32_add_cpu((__be32 *)buf, count);
|
|
|
|
}
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
struct TCP_Server_Info {
|
2008-11-13 19:45:32 +00:00
|
|
|
struct list_head tcp_ses_list;
|
|
|
|
struct list_head smb_ses_list;
|
2021-02-04 07:20:46 +00:00
|
|
|
__u64 conn_id; /* connection identifier (useful for debugging) */
|
2008-11-14 18:44:38 +00:00
|
|
|
int srv_count; /* reference counter */
|
2005-08-23 04:38:31 +00:00
|
|
|
/* 15 character server name + 0x20 16th byte indicating type = srv */
|
2008-12-01 20:23:50 +00:00
|
|
|
char server_RFC1001_name[RFC1001_NAME_LEN_WITH_NULL];
|
2012-05-15 16:20:51 +00:00
|
|
|
struct smb_version_operations *ops;
|
|
|
|
struct smb_version_values *vals;
|
2021-07-01 17:22:47 +00:00
|
|
|
/* updates to tcpStatus protected by GlobalMid_Lock */
|
cifs: TCP_Server_Info diet
Remove fields that are completely unused, and rearrange struct
according to recommendations by "pahole".
Before:
/* size: 1112, cachelines: 18, members: 49 */
/* sum members: 1086, holes: 8, sum holes: 26 */
/* bit holes: 1, sum bit holes: 7 bits */
/* last cacheline: 24 bytes */
After:
/* size: 1072, cachelines: 17, members: 42 */
/* sum members: 1065, holes: 3, sum holes: 7 */
/* last cacheline: 48 bytes */
...savings of 40 bytes per struct on x86_64. 21 bytes by field removal,
and 19 by reorganizing to eliminate holes.
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-20 18:36:50 +00:00
|
|
|
enum statusEnum tcpStatus; /* what we think the status is */
|
2007-11-16 22:22:06 +00:00
|
|
|
char *hostname; /* hostname portion of UNC string */
|
2005-04-16 22:20:36 +00:00
|
|
|
struct socket *ssocket;
|
2010-12-13 16:08:35 +00:00
|
|
|
struct sockaddr_storage dstaddr;
|
2010-09-02 00:06:02 +00:00
|
|
|
struct sockaddr_storage srcaddr; /* locally bind to this IP */
|
Make CIFS mount work in a container.
Teach cifs about network namespaces, so mounting uses adresses/routing
visible from the container rather than from init context.
A container is a chroot on steroids that changes more than just the root
filesystem the new processes see. One thing containers can isolate is
"network namespaces", meaning each container can have its own set of
ethernet interfaces, each with its own own IP address and routing to the
outside world. And if you open a socket in _userspace_ from processes
within such a container, this works fine.
But sockets opened from within the kernel still use a single global
networking context in a lot of places, meaning the new socket's address
and routing are correct for PID 1 on the host, but are _not_ what
userspace processes in the container get to use.
So when you mount a network filesystem from within in a container, the
mount code in the CIFS driver uses the host's networking context and not
the container's networking context, so it gets the wrong address, uses
the wrong routing, and may even try to go out an interface that the
container can't even access... Bad stuff.
This patch copies the mount process's network context into the CIFS
structure that stores the rest of the server information for that mount
point, and changes the socket open code to use the saved network context
instead of the global network context. I.E. "when you attempt to use
these addresses, do so relative to THIS set of network interfaces and
routing rules, not the old global context from back before we supported
containers".
The big long HOWTO sets up a test environment on the assumption you've
never used ocntainers before. It basically says:
1) configure and build a new kernel that has container support
2) build a new root filesystem that includes the userspace container
control package (LXC)
3) package/run them under KVM (so you don't have to mess up your host
system in order to play with containers).
4) set up some containers under the KVM system
5) set up contradictory routing in the KVM system and the container so
that the host and the container see different things for the same address
6) try to mount a CIFS share from both contexts so you can both force it
to work and force it to fail.
For a long drawn out test reproduction sequence, see:
http://landley.livejournal.com/47024.html
http://landley.livejournal.com/47205.html
http://landley.livejournal.com/47476.html
Signed-off-by: Rob Landley <rlandley@parallels.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-22 21:44:05 +00:00
|
|
|
#ifdef CONFIG_NET_NS
|
|
|
|
struct net *net;
|
|
|
|
#endif
|
2007-06-28 19:44:13 +00:00
|
|
|
wait_queue_head_t response_q;
|
2005-04-16 22:20:36 +00:00
|
|
|
wait_queue_head_t request_q; /* if more than maxmpx to srvr must block*/
|
|
|
|
struct list_head pending_mid_q;
|
2008-10-29 00:47:57 +00:00
|
|
|
bool noblocksnd; /* use blocking sendmsg */
|
|
|
|
bool noautotune; /* do not autotune send buf sizes */
|
2010-01-01 01:28:43 +00:00
|
|
|
bool tcp_nodelay;
|
2016-09-23 05:44:16 +00:00
|
|
|
unsigned int credits; /* send no more requests at once */
|
|
|
|
unsigned int max_credits; /* can override large 32000 default at mnt */
|
2012-02-17 14:09:12 +00:00
|
|
|
unsigned int in_flight; /* number of requests on the wire to server */
|
2019-09-10 03:57:11 +00:00
|
|
|
unsigned int max_in_flight; /* max number of requests that were on wire */
|
2012-02-06 11:59:18 +00:00
|
|
|
spinlock_t req_lock; /* protect the two values above */
|
2008-12-01 12:09:36 +00:00
|
|
|
struct mutex srv_mutex;
|
2005-04-16 22:20:36 +00:00
|
|
|
struct task_struct *tsk;
|
|
|
|
char server_GUID[16];
|
2012-05-25 06:43:58 +00:00
|
|
|
__u16 sec_mode;
|
2013-05-26 11:01:00 +00:00
|
|
|
bool sign; /* is signing enabled on this connection? */
|
2019-09-04 02:18:49 +00:00
|
|
|
bool ignore_signature:1; /* skip validation of signatures in SMB2/3 rsp */
|
cifs: TCP_Server_Info diet
Remove fields that are completely unused, and rearrange struct
according to recommendations by "pahole".
Before:
/* size: 1112, cachelines: 18, members: 49 */
/* sum members: 1086, holes: 8, sum holes: 26 */
/* bit holes: 1, sum bit holes: 7 bits */
/* last cacheline: 24 bytes */
After:
/* size: 1072, cachelines: 17, members: 42 */
/* sum members: 1065, holes: 3, sum holes: 7 */
/* last cacheline: 48 bytes */
...savings of 40 bytes per struct on x86_64. 21 bytes by field removal,
and 19 by reorganizing to eliminate holes.
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-20 18:36:50 +00:00
|
|
|
bool session_estab; /* mark when very first sess is established */
|
2012-05-23 12:18:00 +00:00
|
|
|
int echo_credits; /* echo reserved slots */
|
|
|
|
int oplock_credits; /* oplock break reserved slots */
|
|
|
|
bool echoes:1; /* enable echoes */
|
2014-05-12 23:48:12 +00:00
|
|
|
__u8 client_guid[SMB2_CLIENT_GUID_SIZE]; /* Client GUID */
|
cifs: TCP_Server_Info diet
Remove fields that are completely unused, and rearrange struct
according to recommendations by "pahole".
Before:
/* size: 1112, cachelines: 18, members: 49 */
/* sum members: 1086, holes: 8, sum holes: 26 */
/* bit holes: 1, sum bit holes: 7 bits */
/* last cacheline: 24 bytes */
After:
/* size: 1072, cachelines: 17, members: 42 */
/* sum members: 1065, holes: 3, sum holes: 7 */
/* last cacheline: 48 bytes */
...savings of 40 bytes per struct on x86_64. 21 bytes by field removal,
and 19 by reorganizing to eliminate holes.
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-20 18:36:50 +00:00
|
|
|
u16 dialect; /* dialect index that server chose */
|
2012-03-20 09:55:09 +00:00
|
|
|
bool oplocks:1; /* enable oplocks */
|
2005-04-16 22:20:36 +00:00
|
|
|
unsigned int maxReq; /* Clients should submit no more */
|
|
|
|
/* than maxReq distinct unanswered SMBs to the server when using */
|
2018-05-24 07:09:20 +00:00
|
|
|
/* multiplexed reads or writes (for SMB1/CIFS only, not SMB2/SMB3) */
|
2005-04-16 22:20:36 +00:00
|
|
|
unsigned int maxBuf; /* maxBuf specifies the maximum */
|
|
|
|
/* message size the server can send or receive for non-raw SMBs */
|
2011-02-08 23:52:32 +00:00
|
|
|
/* maxBuf is returned by SMB NegotiateProtocol so maxBuf is only 0 */
|
|
|
|
/* when socket is setup (and during reconnect) before NegProt sent */
|
[CIFS] Fix multiuser mounts so server does not invalidate earlier security contexts
When two different users mount the same Windows 2003 Server share using CIFS,
the first session mounted can be invalidated. Some servers invalidate the first
smb session when a second similar user (e.g. two users who get mapped by server to "guest")
authenticates an smb session from the same client.
By making sure that we set the 2nd and subsequent vc numbers to nonzero values,
this ensures that we will not have this problem.
Fixes Samba bug 6004, problem description follows:
How to reproduce:
- configure an "open share" (full permissions to Guest user) on Windows 2003
Server (I couldn't reproduce the problem with Samba server or Windows older
than 2003)
- mount the share twice with different users who will be authenticated as guest.
noacl,noperm,user=john,dir_mode=0700,domain=DOMAIN,rw
noacl,noperm,user=jeff,dir_mode=0700,domain=DOMAIN,rw
Result:
- just the mount point mounted last is accessible:
Signed-off-by: Steve French <sfrench@us.ibm.com>
2009-02-20 05:43:09 +00:00
|
|
|
unsigned int max_rw; /* maxRw specifies the maximum */
|
2005-04-16 22:20:36 +00:00
|
|
|
/* message size the server can send or receive for */
|
|
|
|
/* SMB_COM_WRITE_RAW or SMB_COM_READ_RAW. */
|
2012-07-13 09:58:14 +00:00
|
|
|
unsigned int capabilities; /* selective disabling of caps by smb sess */
|
2006-09-30 13:25:52 +00:00
|
|
|
int timeAdj; /* Adjust for difference in server time zone in sec */
|
2021-06-25 18:54:32 +00:00
|
|
|
__u64 CurrentMid; /* multiplex id - rotating counter, protected by GlobalMid_Lock */
|
2010-10-27 20:20:36 +00:00
|
|
|
char cryptkey[CIFS_CRYPTO_KEY_SIZE]; /* used by ntlm, ntlmv2 etc */
|
2005-08-23 04:38:31 +00:00
|
|
|
/* 16th byte of RFC1001 workstation name is always null */
|
2008-12-01 20:23:50 +00:00
|
|
|
char workstation_RFC1001_name[RFC1001_NAME_LEN_WITH_NULL];
|
2011-01-07 16:30:28 +00:00
|
|
|
__u32 sequence_number; /* for signing, protected by srv_mutex */
|
2018-09-19 07:38:17 +00:00
|
|
|
__u32 reconnect_instance; /* incremented on each reconnect */
|
2010-09-19 03:01:58 +00:00
|
|
|
struct session_key session_key;
|
2006-07-14 22:37:11 +00:00
|
|
|
unsigned long lstrp; /* when we got last response from this server */
|
2010-10-21 19:25:08 +00:00
|
|
|
struct cifs_secmech secmech; /* crypto sec mech functs, descriptors */
|
2013-05-26 11:00:59 +00:00
|
|
|
#define CIFS_NEGFLAVOR_UNENCAP 1 /* wct == 17, but no ext_sec */
|
|
|
|
#define CIFS_NEGFLAVOR_EXTENDED 2 /* wct == 17, ext_sec bit set */
|
|
|
|
char negflavor; /* NEGOTIATE response flavor */
|
2010-04-24 11:57:49 +00:00
|
|
|
/* extended security flavors that server supports */
|
cifs: TCP_Server_Info diet
Remove fields that are completely unused, and rearrange struct
according to recommendations by "pahole".
Before:
/* size: 1112, cachelines: 18, members: 49 */
/* sum members: 1086, holes: 8, sum holes: 26 */
/* bit holes: 1, sum bit holes: 7 bits */
/* last cacheline: 24 bytes */
After:
/* size: 1072, cachelines: 17, members: 42 */
/* sum members: 1065, holes: 3, sum holes: 7 */
/* last cacheline: 48 bytes */
...savings of 40 bytes per struct on x86_64. 21 bytes by field removal,
and 19 by reorganizing to eliminate holes.
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-20 18:36:50 +00:00
|
|
|
bool sec_ntlmssp; /* supports NTLMSSP */
|
|
|
|
bool sec_kerberosu2u; /* supports U2U Kerberos */
|
2010-04-24 11:57:49 +00:00
|
|
|
bool sec_kerberos; /* supports plain Kerberos */
|
|
|
|
bool sec_mskerberos; /* supports legacy MS Kerberos */
|
2011-10-19 19:29:23 +00:00
|
|
|
bool large_buf; /* is current buffer large? */
|
2017-11-07 08:54:55 +00:00
|
|
|
/* use SMBD connection instead of socket */
|
|
|
|
bool rdma;
|
|
|
|
/* point to the SMBD connection if RDMA is used instead of socket */
|
|
|
|
struct smbd_connection *smbd_conn;
|
2011-01-11 12:24:23 +00:00
|
|
|
struct delayed_work echo; /* echo ping workqueue job */
|
2021-05-18 15:05:50 +00:00
|
|
|
struct delayed_work resolve; /* dns resolution workqueue job */
|
2011-10-19 19:29:23 +00:00
|
|
|
char *smallbuf; /* pointer to current "small" buffer */
|
|
|
|
char *bigbuf; /* pointer to current "big" buffer */
|
2018-04-09 08:06:26 +00:00
|
|
|
/* Total size of this PDU. Only valid from cifs_demultiplex_thread */
|
|
|
|
unsigned int pdu_size;
|
2011-10-19 19:29:23 +00:00
|
|
|
unsigned int total_read; /* total amount of data read in this pass */
|
2019-11-21 23:26:35 +00:00
|
|
|
atomic_t in_send; /* requests trying to send */
|
|
|
|
atomic_t num_waiters; /* blocked waiting to get in sendrecv */
|
2010-07-05 12:42:15 +00:00
|
|
|
#ifdef CONFIG_CIFS_FSCACHE
|
|
|
|
struct fscache_cookie *fscache; /* client index cache cookie */
|
|
|
|
#endif
|
cifs: TCP_Server_Info diet
Remove fields that are completely unused, and rearrange struct
according to recommendations by "pahole".
Before:
/* size: 1112, cachelines: 18, members: 49 */
/* sum members: 1086, holes: 8, sum holes: 26 */
/* bit holes: 1, sum bit holes: 7 bits */
/* last cacheline: 24 bytes */
After:
/* size: 1072, cachelines: 17, members: 42 */
/* sum members: 1065, holes: 3, sum holes: 7 */
/* last cacheline: 48 bytes */
...savings of 40 bytes per struct on x86_64. 21 bytes by field removal,
and 19 by reorganizing to eliminate holes.
Signed-off-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-20 18:36:50 +00:00
|
|
|
#ifdef CONFIG_CIFS_STATS2
|
2019-03-26 18:53:21 +00:00
|
|
|
atomic_t num_cmds[NUMBER_OF_SMB2_COMMANDS]; /* total requests by cmd */
|
2018-08-04 10:24:34 +00:00
|
|
|
atomic_t smb2slowcmd[NUMBER_OF_SMB2_COMMANDS]; /* count resps > 1 sec */
|
2019-03-26 18:53:21 +00:00
|
|
|
__u64 time_per_cmd[NUMBER_OF_SMB2_COMMANDS]; /* total time per cmd */
|
|
|
|
__u32 slowest_cmd[NUMBER_OF_SMB2_COMMANDS];
|
|
|
|
__u32 fastest_cmd[NUMBER_OF_SMB2_COMMANDS];
|
2018-08-04 10:24:34 +00:00
|
|
|
#endif /* STATS2 */
|
2011-12-27 12:12:43 +00:00
|
|
|
unsigned int max_read;
|
|
|
|
unsigned int max_write;
|
2019-09-09 04:22:02 +00:00
|
|
|
unsigned int min_offload;
|
2019-04-27 03:36:08 +00:00
|
|
|
__le16 compress_algorithm;
|
2021-07-05 20:05:39 +00:00
|
|
|
__u16 signing_algorithm;
|
2018-04-09 15:47:14 +00:00
|
|
|
__le16 cipher_type;
|
2018-02-16 18:19:29 +00:00
|
|
|
/* save initital negprot hash */
|
|
|
|
__u8 preauth_sha_hash[SMB2_PREAUTH_HASH_SIZE];
|
2021-07-05 20:05:39 +00:00
|
|
|
bool signing_negotiated; /* true if valid signing context rcvd from server */
|
2018-05-20 01:45:27 +00:00
|
|
|
bool posix_ext_supported;
|
2016-11-04 18:50:31 +00:00
|
|
|
struct delayed_work reconnect; /* reconnect workqueue job */
|
|
|
|
struct mutex reconnect_mutex; /* prevent simultaneous reconnects */
|
2015-12-18 18:31:36 +00:00
|
|
|
unsigned long echo_interval;
|
2018-11-14 19:13:25 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Number of targets available for reconnect. The more targets
|
|
|
|
* the more tasks have to wait to let the demultiplex thread
|
|
|
|
* reconnect.
|
|
|
|
*/
|
|
|
|
int nr_targets;
|
2019-07-16 22:04:50 +00:00
|
|
|
bool noblockcnt; /* use non-blocking connect() */
|
2019-12-04 14:25:06 +00:00
|
|
|
bool is_channel; /* if a session channel */
|
2020-11-30 18:02:56 +00:00
|
|
|
#ifdef CONFIG_CIFS_SWN_UPCALL
|
|
|
|
bool use_swn_dstaddr;
|
|
|
|
struct sockaddr_storage swn_dstaddr;
|
|
|
|
#endif
|
2021-07-16 00:53:53 +00:00
|
|
|
#ifdef CONFIG_CIFS_DFS_UPCALL
|
|
|
|
bool is_dfs_conn; /* if a dfs connection */
|
|
|
|
#endif
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2019-01-16 19:12:41 +00:00
|
|
|
struct cifs_credits {
|
|
|
|
unsigned int value;
|
|
|
|
unsigned int instance;
|
|
|
|
};
|
|
|
|
|
2012-02-17 14:09:12 +00:00
|
|
|
static inline unsigned int
|
|
|
|
in_flight(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
unsigned int num;
|
|
|
|
spin_lock(&server->req_lock);
|
|
|
|
num = server->in_flight;
|
|
|
|
spin_unlock(&server->req_lock);
|
|
|
|
return num;
|
|
|
|
}
|
|
|
|
|
2012-02-06 11:59:18 +00:00
|
|
|
static inline bool
|
2019-03-08 02:58:20 +00:00
|
|
|
has_credits(struct TCP_Server_Info *server, int *credits, int num_credits)
|
2012-02-17 14:09:12 +00:00
|
|
|
{
|
2012-02-06 11:59:18 +00:00
|
|
|
int num;
|
2012-02-17 14:09:12 +00:00
|
|
|
spin_lock(&server->req_lock);
|
2012-03-15 10:22:27 +00:00
|
|
|
num = *credits;
|
2012-02-17 14:09:12 +00:00
|
|
|
spin_unlock(&server->req_lock);
|
2019-03-08 02:58:20 +00:00
|
|
|
return num >= num_credits;
|
2012-02-17 14:09:12 +00:00
|
|
|
}
|
|
|
|
|
2012-05-17 13:53:29 +00:00
|
|
|
static inline void
|
2019-01-16 19:22:29 +00:00
|
|
|
add_credits(struct TCP_Server_Info *server, const struct cifs_credits *credits,
|
2012-05-23 12:14:34 +00:00
|
|
|
const int optype)
|
2012-05-17 13:53:29 +00:00
|
|
|
{
|
2019-01-16 19:22:29 +00:00
|
|
|
server->ops->add_credits(server, credits, optype);
|
2012-05-17 13:53:29 +00:00
|
|
|
}
|
|
|
|
|
2014-06-05 15:03:27 +00:00
|
|
|
static inline void
|
2019-01-16 19:12:41 +00:00
|
|
|
add_credits_and_wake_if(struct TCP_Server_Info *server,
|
|
|
|
const struct cifs_credits *credits, const int optype)
|
2014-06-05 15:03:27 +00:00
|
|
|
{
|
2019-01-16 19:12:41 +00:00
|
|
|
if (credits->value) {
|
|
|
|
server->ops->add_credits(server, credits, optype);
|
2014-06-05 15:03:27 +00:00
|
|
|
wake_up(&server->request_q);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2012-05-17 13:53:29 +00:00
|
|
|
static inline void
|
|
|
|
set_credits(struct TCP_Server_Info *server, const int val)
|
|
|
|
{
|
|
|
|
server->ops->set_credits(server, val);
|
|
|
|
}
|
|
|
|
|
2019-01-24 02:15:52 +00:00
|
|
|
static inline int
|
|
|
|
adjust_credits(struct TCP_Server_Info *server, struct cifs_credits *credits,
|
|
|
|
const unsigned int payload_size)
|
|
|
|
{
|
|
|
|
return server->ops->adjust_credits ?
|
|
|
|
server->ops->adjust_credits(server, credits, payload_size) : 0;
|
|
|
|
}
|
|
|
|
|
2014-12-09 17:37:00 +00:00
|
|
|
static inline __le64
|
2013-11-02 17:50:34 +00:00
|
|
|
get_next_mid64(struct TCP_Server_Info *server)
|
2012-05-23 10:01:59 +00:00
|
|
|
{
|
2014-12-09 17:37:00 +00:00
|
|
|
return cpu_to_le64(server->ops->get_next_mid(server));
|
2012-05-23 10:01:59 +00:00
|
|
|
}
|
|
|
|
|
2013-11-02 17:50:34 +00:00
|
|
|
static inline __le16
|
|
|
|
get_next_mid(struct TCP_Server_Info *server)
|
|
|
|
{
|
2014-12-09 17:37:00 +00:00
|
|
|
__u16 mid = server->ops->get_next_mid(server);
|
2013-11-02 17:50:34 +00:00
|
|
|
/*
|
|
|
|
* The value in the SMB header should be little endian for easy
|
|
|
|
* on-the-wire decoding.
|
|
|
|
*/
|
|
|
|
return cpu_to_le16(mid);
|
|
|
|
}
|
|
|
|
|
2019-03-04 22:02:50 +00:00
|
|
|
static inline void
|
|
|
|
revert_current_mid(struct TCP_Server_Info *server, const unsigned int val)
|
|
|
|
{
|
|
|
|
if (server->ops->revert_current_mid)
|
|
|
|
server->ops->revert_current_mid(server, val);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void
|
|
|
|
revert_current_mid_from_hdr(struct TCP_Server_Info *server,
|
2021-11-04 23:39:01 +00:00
|
|
|
const struct smb2_hdr *shdr)
|
2019-03-04 22:02:50 +00:00
|
|
|
{
|
|
|
|
unsigned int num = le16_to_cpu(shdr->CreditCharge);
|
|
|
|
|
|
|
|
return revert_current_mid(server, num > 0 ? num : 1);
|
|
|
|
}
|
|
|
|
|
2013-11-02 17:50:34 +00:00
|
|
|
static inline __u16
|
|
|
|
get_mid(const struct smb_hdr *smb)
|
|
|
|
{
|
|
|
|
return le16_to_cpu(smb->Mid);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline bool
|
|
|
|
compare_mid(__u16 mid, const struct smb_hdr *smb)
|
|
|
|
{
|
|
|
|
return mid == le16_to_cpu(smb->Mid);
|
|
|
|
}
|
|
|
|
|
2012-09-18 23:20:28 +00:00
|
|
|
/*
|
|
|
|
* When the server supports very large reads and writes via POSIX extensions,
|
|
|
|
* we can allow up to 2^24-1, minus the size of a READ/WRITE_AND_X header, not
|
|
|
|
* including the RFC1001 length.
|
|
|
|
*
|
|
|
|
* Note that this might make for "interesting" allocation problems during
|
|
|
|
* writeback however as we have to allocate an array of pointers for the
|
2016-04-01 12:29:48 +00:00
|
|
|
* pages. A 16M write means ~32kb page array with PAGE_SIZE == 4096.
|
2012-09-18 23:20:28 +00:00
|
|
|
*
|
|
|
|
* For reads, there is a similar problem as we need to allocate an array
|
|
|
|
* of kvecs to handle the receive, though that should only need to be done
|
|
|
|
* once.
|
|
|
|
*/
|
|
|
|
#define CIFS_MAX_WSIZE ((1<<24) - 1 - sizeof(WRITE_REQ) + 4)
|
|
|
|
#define CIFS_MAX_RSIZE ((1<<24) - sizeof(READ_RSP) + 4)
|
|
|
|
|
|
|
|
/*
|
|
|
|
* When the server doesn't allow large posix writes, only allow a rsize/wsize
|
|
|
|
* of 2^17-1 minus the size of the call header. That allows for a read or
|
|
|
|
* write up to the maximum size described by RFC1002.
|
|
|
|
*/
|
|
|
|
#define CIFS_MAX_RFC1002_WSIZE ((1<<17) - 1 - sizeof(WRITE_REQ) + 4)
|
|
|
|
#define CIFS_MAX_RFC1002_RSIZE ((1<<17) - 1 - sizeof(READ_RSP) + 4)
|
|
|
|
|
|
|
|
/*
|
|
|
|
* The default wsize is 1M. find_get_pages seems to return a maximum of 256
|
2016-04-01 12:29:48 +00:00
|
|
|
* pages in a single call. With PAGE_SIZE == 4k, this means we can fill
|
2012-09-18 23:20:28 +00:00
|
|
|
* a single wsize request with a single call.
|
|
|
|
*/
|
|
|
|
#define CIFS_DEFAULT_IOSIZE (1024 * 1024)
|
2018-09-25 20:33:47 +00:00
|
|
|
#define SMB3_DEFAULT_IOSIZE (4 * 1024 * 1024)
|
2012-09-18 23:20:28 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Windows only supports a max of 60kb reads and 65535 byte writes. Default to
|
|
|
|
* those values when posix extensions aren't in force. In actuality here, we
|
|
|
|
* use 65536 to allow for a write that is a multiple of 4k. Most servers seem
|
|
|
|
* to be ok with the extra byte even though Windows doesn't send writes that
|
|
|
|
* are that large.
|
|
|
|
*
|
|
|
|
* Citation:
|
|
|
|
*
|
2020-06-27 10:31:25 +00:00
|
|
|
* https://blogs.msdn.com/b/openspecification/archive/2009/04/10/smb-maximum-transmit-buffer-size-and-performance-tuning.aspx
|
2012-09-18 23:20:28 +00:00
|
|
|
*/
|
|
|
|
#define CIFS_DEFAULT_NON_POSIX_RSIZE (60 * 1024)
|
|
|
|
#define CIFS_DEFAULT_NON_POSIX_WSIZE (65536)
|
|
|
|
|
Make CIFS mount work in a container.
Teach cifs about network namespaces, so mounting uses adresses/routing
visible from the container rather than from init context.
A container is a chroot on steroids that changes more than just the root
filesystem the new processes see. One thing containers can isolate is
"network namespaces", meaning each container can have its own set of
ethernet interfaces, each with its own own IP address and routing to the
outside world. And if you open a socket in _userspace_ from processes
within such a container, this works fine.
But sockets opened from within the kernel still use a single global
networking context in a lot of places, meaning the new socket's address
and routing are correct for PID 1 on the host, but are _not_ what
userspace processes in the container get to use.
So when you mount a network filesystem from within in a container, the
mount code in the CIFS driver uses the host's networking context and not
the container's networking context, so it gets the wrong address, uses
the wrong routing, and may even try to go out an interface that the
container can't even access... Bad stuff.
This patch copies the mount process's network context into the CIFS
structure that stores the rest of the server information for that mount
point, and changes the socket open code to use the saved network context
instead of the global network context. I.E. "when you attempt to use
these addresses, do so relative to THIS set of network interfaces and
routing rules, not the old global context from back before we supported
containers".
The big long HOWTO sets up a test environment on the assumption you've
never used ocntainers before. It basically says:
1) configure and build a new kernel that has container support
2) build a new root filesystem that includes the userspace container
control package (LXC)
3) package/run them under KVM (so you don't have to mess up your host
system in order to play with containers).
4) set up some containers under the KVM system
5) set up contradictory routing in the KVM system and the container so
that the host and the container see different things for the same address
6) try to mount a CIFS share from both contexts so you can both force it
to work and force it to fail.
For a long drawn out test reproduction sequence, see:
http://landley.livejournal.com/47024.html
http://landley.livejournal.com/47205.html
http://landley.livejournal.com/47476.html
Signed-off-by: Rob Landley <rlandley@parallels.com>
Reviewed-by: Jeff Layton <jlayton@redhat.com>
Signed-off-by: Steve French <sfrench@us.ibm.com>
2011-01-22 21:44:05 +00:00
|
|
|
/*
|
|
|
|
* Macros to allow the TCP_Server_Info->net field and related code to drop out
|
|
|
|
* when CONFIG_NET_NS isn't set.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifdef CONFIG_NET_NS
|
|
|
|
|
|
|
|
static inline struct net *cifs_net_ns(struct TCP_Server_Info *srv)
|
|
|
|
{
|
|
|
|
return srv->net;
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void cifs_set_net_ns(struct TCP_Server_Info *srv, struct net *net)
|
|
|
|
{
|
|
|
|
srv->net = net;
|
|
|
|
}
|
|
|
|
|
|
|
|
#else
|
|
|
|
|
|
|
|
static inline struct net *cifs_net_ns(struct TCP_Server_Info *srv)
|
|
|
|
{
|
|
|
|
return &init_net;
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void cifs_set_net_ns(struct TCP_Server_Info *srv, struct net *net)
|
|
|
|
{
|
|
|
|
}
|
|
|
|
|
|
|
|
#endif
|
|
|
|
|
2018-06-14 13:43:18 +00:00
|
|
|
struct cifs_server_iface {
|
|
|
|
size_t speed;
|
|
|
|
unsigned int rdma_capable : 1;
|
|
|
|
unsigned int rss_capable : 1;
|
|
|
|
struct sockaddr_storage sockaddr;
|
|
|
|
};
|
|
|
|
|
2019-09-20 02:32:20 +00:00
|
|
|
struct cifs_chan {
|
|
|
|
struct TCP_Server_Info *server;
|
|
|
|
__u8 signkey[SMB3_SIGN_KEY_SIZE];
|
|
|
|
};
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* Session structure. One of these for each uid session with a particular host
|
|
|
|
*/
|
2011-05-27 04:34:02 +00:00
|
|
|
struct cifs_ses {
|
2008-11-14 18:53:46 +00:00
|
|
|
struct list_head smb_ses_list;
|
2008-11-13 19:45:32 +00:00
|
|
|
struct list_head tcon_list;
|
2018-01-24 12:46:10 +00:00
|
|
|
struct cifs_tcon *tcon_ipc;
|
2010-02-25 05:36:46 +00:00
|
|
|
struct mutex session_mutex;
|
2005-04-16 22:20:36 +00:00
|
|
|
struct TCP_Server_Info *server; /* pointer to server info */
|
2008-11-14 18:53:46 +00:00
|
|
|
int ses_count; /* reference counter */
|
2021-06-24 20:28:04 +00:00
|
|
|
enum statusEnum status; /* updates protected by GlobalMid_Lock */
|
2006-06-27 06:28:30 +00:00
|
|
|
unsigned overrideSecFlg; /* if non-zero override global sec flags */
|
2005-04-29 05:41:05 +00:00
|
|
|
char *serverOS; /* name of operating system underlying server */
|
|
|
|
char *serverNOS; /* name of network operating system of server */
|
2005-04-16 22:20:36 +00:00
|
|
|
char *serverDomain; /* security realm of server */
|
2012-05-25 06:43:58 +00:00
|
|
|
__u64 Suid; /* remote smb uid */
|
2013-02-06 10:30:39 +00:00
|
|
|
kuid_t linux_uid; /* overriding owner of files on the mount */
|
|
|
|
kuid_t cred_uid; /* owner of credentials */
|
2012-07-13 09:58:14 +00:00
|
|
|
unsigned int capabilities;
|
2021-02-21 01:24:11 +00:00
|
|
|
char ip_addr[INET6_ADDRSTRLEN + 1]; /* Max ipv6 (or v4) addr string len */
|
2011-03-01 05:02:57 +00:00
|
|
|
char *user_name; /* must not be null except during init of sess
|
|
|
|
and after mount option parsing we fill it */
|
2007-06-28 19:44:13 +00:00
|
|
|
char *domainName;
|
|
|
|
char *password;
|
2010-10-13 23:15:00 +00:00
|
|
|
struct session_key auth_key;
|
2010-10-28 14:53:07 +00:00
|
|
|
struct ntlmssp_auth *ntlmssp; /* ciphertext, flags, server challenge */
|
2013-05-26 11:01:00 +00:00
|
|
|
enum securityEnum sectype; /* what security flavor was specified? */
|
|
|
|
bool sign; /* is signing required? */
|
2008-11-13 19:45:32 +00:00
|
|
|
bool need_reconnect:1; /* connection reset, uid now invalid */
|
Fix default behaviour for empty domains and add domainauto option
With commit 2b149f119 many things have been fixed/introduced.
However, the default behaviour for RawNTLMSSP authentication
seems to be wrong in case the domain is not passed on the command line.
The main points (see below) of the patch are:
- It alignes behaviour with Windows clients
- It fixes backward compatibility
- It fixes UPN
I compared this behavour with the one from a Windows 10 command line
client. When no domains are specified on the command line, I traced
the packets and observed that the client does send an empty
domain to the server.
In the linux kernel case, the empty domain is replaced by the
primary domain communicated by the SMB server.
This means that, if the credentials are valid against the local server
but that server is part of a domain, then the kernel module will
ask to authenticate against that domain and we will get LOGON failure.
I compared the packet trace from the smbclient when no domain is passed
and, in that case, a default domain from the client smb.conf is taken.
Apparently, connection succeeds anyway, because when the domain passed
is not valid (in my case WORKGROUP), then the local one is tried and
authentication succeeds. I tried with any kind of invalid domain and
the result was always a connection.
So, trying to interpret what to do and picking a valid domain if none
is passed, seems the wrong thing to do.
To this end, a new option "domainauto" has been added in case the
user wants a mechanism for guessing.
Without this patch, backward compatibility also is broken.
With kernel 3.10, the default auth mechanism was NTLM.
One of our testing servers accepted NTLM and, because no
domains are passed, authentication was local.
Moving to RawNTLMSSP forced us to change our command line
to add a fake domain to pass to prevent this mechanism to kick in.
For the same reasons, UPN is broken because the domain is specified
in the username.
The SMB server will work out the domain from the UPN and authenticate
against the right server.
Without the patch, though, given the domain is empty, it gets replaced
with another domain that could be the wrong one for the authentication.
Signed-off-by: Germano Percossi <germano.percossi@citrix.com>
Acked-by: Pavel Shilovsky <pshilov@microsoft.com>
Signed-off-by: Steve French <smfrench@gmail.com>
2016-12-15 07:01:18 +00:00
|
|
|
bool domainAuto:1;
|
2019-09-20 04:22:14 +00:00
|
|
|
bool binding:1; /* are we binding the session? */
|
2011-12-27 12:22:00 +00:00
|
|
|
__u16 session_flags;
|
2015-12-18 19:05:30 +00:00
|
|
|
__u8 smb3signingkey[SMB3_SIGN_KEY_SIZE];
|
2021-03-25 12:34:54 +00:00
|
|
|
__u8 smb3encryptionkey[SMB3_ENC_DEC_KEY_SIZE];
|
|
|
|
__u8 smb3decryptionkey[SMB3_ENC_DEC_KEY_SIZE];
|
2018-02-16 18:19:29 +00:00
|
|
|
__u8 preauth_sha_hash[SMB2_PREAUTH_HASH_SIZE];
|
2018-06-14 13:43:18 +00:00
|
|
|
|
2019-09-20 04:31:10 +00:00
|
|
|
__u8 binding_preauth_sha_hash[SMB2_PREAUTH_HASH_SIZE];
|
|
|
|
|
2018-06-14 13:43:18 +00:00
|
|
|
/*
|
|
|
|
* Network interfaces available on the server this session is
|
|
|
|
* connected to.
|
|
|
|
*
|
|
|
|
* Other channels can be opened by connecting and binding this
|
|
|
|
* session to interfaces from this list.
|
|
|
|
*
|
|
|
|
* iface_lock should be taken when accessing any of these fields
|
|
|
|
*/
|
|
|
|
spinlock_t iface_lock;
|
|
|
|
struct cifs_server_iface *iface_list;
|
|
|
|
size_t iface_count;
|
|
|
|
unsigned long iface_last_update; /* jiffies */
|
2019-09-20 02:32:20 +00:00
|
|
|
|
|
|
|
#define CIFS_MAX_CHANNELS 16
|
|
|
|
struct cifs_chan chans[CIFS_MAX_CHANNELS];
|
2020-04-24 13:24:05 +00:00
|
|
|
struct cifs_chan *binding_chan;
|
2019-09-20 02:32:20 +00:00
|
|
|
size_t chan_count;
|
|
|
|
size_t chan_max;
|
|
|
|
atomic_t chan_seq; /* round robin state */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
2012-09-19 13:22:45 +00:00
|
|
|
|
2019-09-20 04:31:10 +00:00
|
|
|
/*
|
|
|
|
* When binding a new channel, we need to access the channel which isn't fully
|
2020-04-24 13:24:05 +00:00
|
|
|
* established yet.
|
2019-09-20 04:31:10 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
static inline
|
|
|
|
struct cifs_chan *cifs_ses_binding_channel(struct cifs_ses *ses)
|
|
|
|
{
|
|
|
|
if (ses->binding)
|
2020-04-24 13:24:05 +00:00
|
|
|
return ses->binding_chan;
|
2019-09-20 04:31:10 +00:00
|
|
|
else
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
2020-04-24 13:24:05 +00:00
|
|
|
/*
|
|
|
|
* Returns the server pointer of the session. When binding a new
|
|
|
|
* channel this returns the last channel which isn't fully established
|
|
|
|
* yet.
|
|
|
|
*
|
|
|
|
* This function should be use for negprot/sess.setup codepaths. For
|
|
|
|
* the other requests see cifs_pick_channel().
|
|
|
|
*/
|
2019-09-20 04:22:14 +00:00
|
|
|
static inline
|
|
|
|
struct TCP_Server_Info *cifs_ses_server(struct cifs_ses *ses)
|
|
|
|
{
|
|
|
|
if (ses->binding)
|
2020-04-24 13:24:05 +00:00
|
|
|
return ses->binding_chan->server;
|
2019-09-20 04:22:14 +00:00
|
|
|
else
|
|
|
|
return ses->server;
|
|
|
|
}
|
|
|
|
|
2012-07-13 09:58:14 +00:00
|
|
|
static inline bool
|
|
|
|
cap_unix(struct cifs_ses *ses)
|
|
|
|
{
|
|
|
|
return ses->server->vals->cap_unix & ses->capabilities;
|
|
|
|
}
|
|
|
|
|
2018-06-13 20:48:35 +00:00
|
|
|
struct cached_fid {
|
|
|
|
bool is_valid:1; /* Do we have a useable root fid */
|
2019-03-12 03:58:31 +00:00
|
|
|
bool file_all_info_is_valid:1;
|
2019-12-10 19:44:52 +00:00
|
|
|
bool has_lease:1;
|
2021-03-08 23:07:33 +00:00
|
|
|
unsigned long time; /* jiffies of when lease was taken */
|
2018-07-30 22:48:22 +00:00
|
|
|
struct kref refcount;
|
2018-06-13 20:48:35 +00:00
|
|
|
struct cifs_fid *fid;
|
|
|
|
struct mutex fid_mutex;
|
|
|
|
struct cifs_tcon *tcon;
|
2021-03-08 23:07:31 +00:00
|
|
|
struct dentry *dentry;
|
2018-06-13 20:48:35 +00:00
|
|
|
struct work_struct lease_break;
|
2019-03-12 03:58:31 +00:00
|
|
|
struct smb2_file_all_info file_all_info;
|
2018-06-13 20:48:35 +00:00
|
|
|
};
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* there is one of these for each connection to a resource on a particular
|
2007-06-28 19:44:13 +00:00
|
|
|
* session
|
2005-04-16 22:20:36 +00:00
|
|
|
*/
|
2011-05-27 04:34:02 +00:00
|
|
|
struct cifs_tcon {
|
2008-11-15 16:12:47 +00:00
|
|
|
struct list_head tcon_list;
|
|
|
|
int tc_count;
|
2016-11-04 18:50:31 +00:00
|
|
|
struct list_head rlist; /* reconnect list */
|
2018-10-19 22:14:32 +00:00
|
|
|
atomic_t num_local_opens; /* num of all opens including disconnected */
|
|
|
|
atomic_t num_remote_opens; /* num of all network opens on server */
|
2005-04-16 22:20:36 +00:00
|
|
|
struct list_head openFileList;
|
2016-09-22 23:58:16 +00:00
|
|
|
spinlock_t open_file_lock; /* protects list above */
|
2011-05-27 04:34:02 +00:00
|
|
|
struct cifs_ses *ses; /* pointer to session associated with */
|
2006-06-04 05:53:15 +00:00
|
|
|
char treeName[MAX_TREE_SIZE + 1]; /* UNC name of resource in ASCII */
|
2005-04-16 22:20:36 +00:00
|
|
|
char *nativeFileSystem;
|
2008-12-06 01:41:21 +00:00
|
|
|
char *password; /* for share-level security */
|
2011-12-27 12:04:00 +00:00
|
|
|
__u32 tid; /* The 4 byte tree id */
|
2005-04-16 22:20:36 +00:00
|
|
|
__u16 Flags; /* optional support bits */
|
|
|
|
enum statusEnum tidStatus;
|
|
|
|
atomic_t num_smbs_sent;
|
2012-05-28 10:16:31 +00:00
|
|
|
union {
|
|
|
|
struct {
|
|
|
|
atomic_t num_writes;
|
|
|
|
atomic_t num_reads;
|
|
|
|
atomic_t num_flushes;
|
|
|
|
atomic_t num_oplock_brks;
|
|
|
|
atomic_t num_opens;
|
|
|
|
atomic_t num_closes;
|
|
|
|
atomic_t num_deletes;
|
|
|
|
atomic_t num_mkdirs;
|
|
|
|
atomic_t num_posixopens;
|
|
|
|
atomic_t num_posixmkdirs;
|
|
|
|
atomic_t num_rmdirs;
|
|
|
|
atomic_t num_renames;
|
|
|
|
atomic_t num_t2renames;
|
|
|
|
atomic_t num_ffirst;
|
|
|
|
atomic_t num_fnext;
|
|
|
|
atomic_t num_fclose;
|
|
|
|
atomic_t num_hardlinks;
|
|
|
|
atomic_t num_symlinks;
|
|
|
|
atomic_t num_locks;
|
|
|
|
atomic_t num_acl_get;
|
|
|
|
atomic_t num_acl_set;
|
|
|
|
} cifs_stats;
|
2012-05-28 11:19:39 +00:00
|
|
|
struct {
|
|
|
|
atomic_t smb2_com_sent[NUMBER_OF_SMB2_COMMANDS];
|
|
|
|
atomic_t smb2_com_failed[NUMBER_OF_SMB2_COMMANDS];
|
|
|
|
} smb2_stats;
|
2012-05-28 10:16:31 +00:00
|
|
|
} stats;
|
2005-04-16 22:20:36 +00:00
|
|
|
__u64 bytes_read;
|
|
|
|
__u64 bytes_written;
|
2016-09-22 23:58:16 +00:00
|
|
|
spinlock_t stat_lock; /* protects the two fields above */
|
2005-04-16 22:20:36 +00:00
|
|
|
FILE_SYSTEM_DEVICE_INFO fsDevInfo;
|
2006-06-04 05:53:15 +00:00
|
|
|
FILE_SYSTEM_ATTRIBUTE_INFO fsAttrInfo; /* ok if fs name truncated */
|
2005-04-16 22:20:36 +00:00
|
|
|
FILE_SYSTEM_UNIX_INFO fsUnixInfo;
|
2018-01-24 12:46:10 +00:00
|
|
|
bool ipc:1; /* set if connection to IPC$ share (always also pipe) */
|
|
|
|
bool pipe:1; /* set if connection to pipe share */
|
|
|
|
bool print:1; /* set if connection to printer share */
|
2008-04-29 00:06:05 +00:00
|
|
|
bool retry:1;
|
|
|
|
bool nocase:1;
|
2018-04-26 03:19:09 +00:00
|
|
|
bool nohandlecache:1; /* if strange server resource prob can turn off */
|
2020-05-19 08:06:57 +00:00
|
|
|
bool nodelete:1;
|
2008-05-15 16:44:38 +00:00
|
|
|
bool seal:1; /* transport encryption for this mounted share */
|
2008-04-29 00:06:05 +00:00
|
|
|
bool unix_ext:1; /* if false disable Linux extensions to CIFS protocol
|
2007-07-18 23:21:09 +00:00
|
|
|
for this mount even if server would support */
|
2018-05-21 04:41:10 +00:00
|
|
|
bool posix_extensions; /* if true SMB3.11 posix extensions enabled */
|
2008-10-23 04:42:37 +00:00
|
|
|
bool local_lease:1; /* check leases (only) on local system not remote */
|
2009-03-04 19:54:08 +00:00
|
|
|
bool broken_posix_open; /* e.g. Samba server versions < 3.3.2, 3.2.9 */
|
2014-08-12 02:05:25 +00:00
|
|
|
bool broken_sparse_sup; /* if server or share does not support sparse */
|
2008-11-13 19:45:32 +00:00
|
|
|
bool need_reconnect:1; /* connection reset, tid now invalid */
|
2016-11-29 19:31:23 +00:00
|
|
|
bool need_reopen_files:1; /* need to reopen tcon file handles */
|
2015-11-03 16:08:53 +00:00
|
|
|
bool use_resilient:1; /* use resilient instead of durable handles */
|
2015-11-03 15:15:03 +00:00
|
|
|
bool use_persistent:1; /* use persistent instead of durable handles */
|
2019-09-12 02:46:20 +00:00
|
|
|
bool no_lease:1; /* Do not request leases on files or directories */
|
2021-04-09 14:31:37 +00:00
|
|
|
bool use_witness:1; /* use witness protocol */
|
2013-06-19 19:15:30 +00:00
|
|
|
__le32 capabilities;
|
2011-12-27 12:04:00 +00:00
|
|
|
__u32 share_flags;
|
|
|
|
__u32 maximal_access;
|
|
|
|
__u32 vol_serial_number;
|
|
|
|
__le64 vol_create_time;
|
2016-11-12 04:36:20 +00:00
|
|
|
__u64 snapshot_time; /* for timewarp tokens - timestamp of snapshot */
|
2019-03-29 21:31:07 +00:00
|
|
|
__u32 handle_timeout; /* persistent and durable handle timeout in ms */
|
2013-10-10 01:55:53 +00:00
|
|
|
__u32 ss_flags; /* sector size flags */
|
|
|
|
__u32 perf_sector_size; /* best sector size for perf */
|
2013-11-15 17:26:24 +00:00
|
|
|
__u32 max_chunks;
|
|
|
|
__u32 max_bytes_chunk;
|
|
|
|
__u32 max_bytes_copy;
|
2010-07-05 12:42:27 +00:00
|
|
|
#ifdef CONFIG_CIFS_FSCACHE
|
|
|
|
u64 resource_id; /* server resource id */
|
|
|
|
struct fscache_cookie *fscache; /* cookie for share */
|
|
|
|
#endif
|
2012-09-19 13:22:45 +00:00
|
|
|
struct list_head pending_opens; /* list of incomplete opens */
|
2018-06-13 20:48:35 +00:00
|
|
|
struct cached_fid crfid; /* Cached root fid */
|
2007-07-18 23:21:09 +00:00
|
|
|
/* BB add field for back pointer to sb struct(s)? */
|
2018-11-14 18:01:21 +00:00
|
|
|
#ifdef CONFIG_CIFS_DFS_UPCALL
|
2021-06-04 22:25:30 +00:00
|
|
|
char *dfs_path; /* canonical DFS path */
|
2018-11-14 18:01:21 +00:00
|
|
|
struct list_head ulist; /* cache update list */
|
|
|
|
#endif
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2010-09-29 23:51:11 +00:00
|
|
|
/*
|
|
|
|
* This is a refcounted and timestamped container for a tcon pointer. The
|
|
|
|
* container holds a tcon reference. It is considered safe to free one of
|
|
|
|
* these when the tl_count goes to 0. The tl_time is the time of the last
|
|
|
|
* "get" on the container.
|
|
|
|
*/
|
|
|
|
struct tcon_link {
|
2010-10-28 15:16:44 +00:00
|
|
|
struct rb_node tl_rbnode;
|
2013-02-06 09:48:56 +00:00
|
|
|
kuid_t tl_uid;
|
2010-10-06 23:51:11 +00:00
|
|
|
unsigned long tl_flags;
|
|
|
|
#define TCON_LINK_MASTER 0
|
|
|
|
#define TCON_LINK_PENDING 1
|
|
|
|
#define TCON_LINK_IN_TREE 2
|
|
|
|
unsigned long tl_time;
|
|
|
|
atomic_t tl_count;
|
2011-05-27 04:34:02 +00:00
|
|
|
struct cifs_tcon *tl_tcon;
|
2010-09-29 23:51:11 +00:00
|
|
|
};
|
|
|
|
|
2010-10-06 23:51:11 +00:00
|
|
|
extern struct tcon_link *cifs_sb_tlink(struct cifs_sb_info *cifs_sb);
|
2018-07-31 23:26:11 +00:00
|
|
|
extern void smb3_free_compound_rqst(int num_rqst, struct smb_rqst *rqst);
|
2010-09-29 23:51:11 +00:00
|
|
|
|
2011-05-27 04:34:02 +00:00
|
|
|
static inline struct cifs_tcon *
|
2010-09-29 23:51:11 +00:00
|
|
|
tlink_tcon(struct tcon_link *tlink)
|
|
|
|
{
|
2010-10-06 23:51:11 +00:00
|
|
|
return tlink->tl_tcon;
|
2010-09-29 23:51:11 +00:00
|
|
|
}
|
|
|
|
|
2018-06-04 20:29:35 +00:00
|
|
|
static inline struct tcon_link *
|
|
|
|
cifs_sb_master_tlink(struct cifs_sb_info *cifs_sb)
|
|
|
|
{
|
|
|
|
return cifs_sb->master_tlink;
|
|
|
|
}
|
|
|
|
|
2010-10-06 23:51:11 +00:00
|
|
|
extern void cifs_put_tlink(struct tcon_link *tlink);
|
2010-09-29 23:51:11 +00:00
|
|
|
|
2010-09-29 23:51:11 +00:00
|
|
|
static inline struct tcon_link *
|
|
|
|
cifs_get_tlink(struct tcon_link *tlink)
|
|
|
|
{
|
2010-10-06 23:51:11 +00:00
|
|
|
if (tlink && !IS_ERR(tlink))
|
|
|
|
atomic_inc(&tlink->tl_count);
|
2010-09-29 23:51:11 +00:00
|
|
|
return tlink;
|
|
|
|
}
|
|
|
|
|
2010-09-29 23:51:11 +00:00
|
|
|
/* This function is always expected to succeed */
|
2011-05-27 04:34:02 +00:00
|
|
|
extern struct cifs_tcon *cifs_sb_master_tcon(struct cifs_sb_info *cifs_sb);
|
2010-09-29 23:51:11 +00:00
|
|
|
|
2012-09-19 13:22:45 +00:00
|
|
|
#define CIFS_OPLOCK_NO_CHANGE 0xfe
|
|
|
|
|
|
|
|
struct cifs_pending_open {
|
|
|
|
struct list_head olist;
|
|
|
|
struct tcon_link *tlink;
|
|
|
|
__u8 lease_key[16];
|
|
|
|
__u32 oplock;
|
|
|
|
};
|
|
|
|
|
2021-04-13 05:26:42 +00:00
|
|
|
struct cifs_deferred_close {
|
|
|
|
struct list_head dlist;
|
|
|
|
struct tcon_link *tlink;
|
|
|
|
__u16 netfid;
|
|
|
|
__u64 persistent_fid;
|
|
|
|
__u64 volatile_fid;
|
|
|
|
};
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
2006-08-02 21:56:33 +00:00
|
|
|
* This info hangs off the cifsFileInfo structure, pointed to by llist.
|
|
|
|
* This is used to track byte stream locks on the file
|
2005-04-16 22:20:36 +00:00
|
|
|
*/
|
|
|
|
struct cifsLockInfo {
|
2006-08-02 21:56:33 +00:00
|
|
|
struct list_head llist; /* pointer to next cifsLockInfo */
|
2011-10-22 11:33:29 +00:00
|
|
|
struct list_head blist; /* pointer to locks blocked on this */
|
|
|
|
wait_queue_head_t block_q;
|
2006-08-02 21:56:33 +00:00
|
|
|
__u64 offset;
|
|
|
|
__u64 length;
|
2010-08-17 07:26:00 +00:00
|
|
|
__u32 pid;
|
2018-10-03 23:24:38 +00:00
|
|
|
__u16 type;
|
|
|
|
__u16 flags;
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
/*
|
|
|
|
* One of these for each open instance of a file
|
|
|
|
*/
|
|
|
|
struct cifs_search_info {
|
|
|
|
loff_t index_of_last_entry;
|
|
|
|
__u16 entries_in_buffer;
|
|
|
|
__u16 info_level;
|
|
|
|
__u32 resume_key;
|
2007-06-28 19:44:13 +00:00
|
|
|
char *ntwrk_buf_start;
|
|
|
|
char *srch_entries_start;
|
2008-10-07 20:03:33 +00:00
|
|
|
char *last_entry;
|
2011-07-16 19:24:37 +00:00
|
|
|
const char *presume_name;
|
2005-04-16 22:20:36 +00:00
|
|
|
unsigned int resume_name_len;
|
2008-04-29 00:06:05 +00:00
|
|
|
bool endOfSearch:1;
|
|
|
|
bool emptyDir:1;
|
|
|
|
bool unicode:1;
|
|
|
|
bool smallBuf:1; /* so we know which buf_release function to call */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2019-10-05 15:53:58 +00:00
|
|
|
#define ACL_NO_MODE ((umode_t)(-1))
|
2013-07-05 08:00:30 +00:00
|
|
|
struct cifs_open_parms {
|
|
|
|
struct cifs_tcon *tcon;
|
|
|
|
struct cifs_sb_info *cifs_sb;
|
|
|
|
int disposition;
|
|
|
|
int desired_access;
|
|
|
|
int create_options;
|
|
|
|
const char *path;
|
|
|
|
struct cifs_fid *fid;
|
2018-06-01 00:16:54 +00:00
|
|
|
umode_t mode;
|
2013-07-09 14:40:58 +00:00
|
|
|
bool reconnect:1;
|
2013-07-05 08:00:30 +00:00
|
|
|
};
|
|
|
|
|
2012-09-18 23:20:26 +00:00
|
|
|
struct cifs_fid {
|
|
|
|
__u16 netfid;
|
2012-09-18 23:20:26 +00:00
|
|
|
__u64 persistent_fid; /* persist file id for smb2 */
|
|
|
|
__u64 volatile_fid; /* volatile file id for smb2 */
|
2012-09-19 13:22:44 +00:00
|
|
|
__u8 lease_key[SMB2_LEASE_KEY_SIZE]; /* lease key for smb2 */
|
2015-11-03 15:26:27 +00:00
|
|
|
__u8 create_guid[16];
|
cifs: fix rename() by ensuring source handle opened with DELETE bit
To rename a file in SMB2 we open it with the DELETE access and do a
special SetInfo on it. If the handle is missing the DELETE bit the
server will fail the SetInfo with STATUS_ACCESS_DENIED.
We currently try to reuse any existing opened handle we have with
cifs_get_writable_path(). That function looks for handles with WRITE
access but doesn't check for DELETE, making rename() fail if it finds
a handle to reuse. Simple reproducer below.
To select handles with the DELETE bit, this patch adds a flag argument
to cifs_get_writable_path() and find_writable_file() and the existing
'bool fsuid_only' argument is converted to a flag.
The cifsFileInfo struct only stores the UNIX open mode but not the
original SMB access flags. Since the DELETE bit is not mapped in that
mode, this patch stores the access mask in cifs_fid on file open,
which is accessible from cifsFileInfo.
Simple reproducer:
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <unistd.h>
#define E(s) perror(s), exit(1)
int main(int argc, char *argv[])
{
int fd, ret;
if (argc != 3) {
fprintf(stderr, "Usage: %s A B\n"
"create&open A in write mode, "
"rename A to B, close A\n", argv[0]);
return 0;
}
fd = openat(AT_FDCWD, argv[1], O_WRONLY|O_CREAT|O_SYNC, 0666);
if (fd == -1) E("openat()");
ret = rename(argv[1], argv[2]);
if (ret) E("rename()");
ret = close(fd);
if (ret) E("close()");
return ret;
}
$ gcc -o bugrename bugrename.c
$ ./bugrename /mnt/a /mnt/b
rename(): Permission denied
Fixes: 8de9e86c67ba ("cifs: create a helper to find a writeable handle by path name")
CC: Stable <stable@vger.kernel.org>
Signed-off-by: Aurelien Aptel <aaptel@suse.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
Reviewed-by: Paulo Alcantara (SUSE) <pc@cjr.nz>
2020-02-21 10:19:06 +00:00
|
|
|
__u32 access;
|
2012-09-19 13:22:45 +00:00
|
|
|
struct cifs_pending_open *pending_open;
|
2013-09-05 17:30:16 +00:00
|
|
|
unsigned int epoch;
|
2018-10-31 00:50:31 +00:00
|
|
|
#ifdef CONFIG_CIFS_DEBUG2
|
|
|
|
__u64 mid;
|
|
|
|
#endif /* CIFS_DEBUG2 */
|
2013-09-05 17:30:16 +00:00
|
|
|
bool purge_cache;
|
2012-09-18 23:20:26 +00:00
|
|
|
};
|
|
|
|
|
2012-09-19 13:22:43 +00:00
|
|
|
struct cifs_fid_locks {
|
|
|
|
struct list_head llist;
|
|
|
|
struct cifsFileInfo *cfile; /* fid that owns locks */
|
|
|
|
struct list_head locks; /* locks held by fid above */
|
|
|
|
};
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
struct cifsFileInfo {
|
2016-09-22 23:58:16 +00:00
|
|
|
/* following two lists are protected by tcon->open_file_lock */
|
2005-04-16 22:20:36 +00:00
|
|
|
struct list_head tlist; /* pointer to next fid owned by tcon */
|
|
|
|
struct list_head flist; /* next fid (file instance) for this inode */
|
2016-09-22 23:58:16 +00:00
|
|
|
/* lock list below protected by cifsi->lock_sem */
|
2012-09-19 13:22:43 +00:00
|
|
|
struct cifs_fid_locks *llist; /* brlocks held by this fid */
|
2013-02-06 10:23:02 +00:00
|
|
|
kuid_t uid; /* allows finding which FileInfo structure */
|
2005-04-16 22:20:36 +00:00
|
|
|
__u32 pid; /* process id who opened file */
|
2012-09-18 23:20:26 +00:00
|
|
|
struct cifs_fid fid; /* file id from remote */
|
2016-10-08 00:26:36 +00:00
|
|
|
struct list_head rlist; /* reconnect list */
|
2005-04-16 22:20:36 +00:00
|
|
|
/* BB add lock scope info here if needed */ ;
|
|
|
|
/* lock scope id (0 if none) */
|
2010-10-11 19:07:18 +00:00
|
|
|
struct dentry *dentry;
|
2010-09-29 23:51:11 +00:00
|
|
|
struct tcon_link *tlink;
|
2016-09-22 23:58:16 +00:00
|
|
|
unsigned int f_flags;
|
2008-04-29 00:06:05 +00:00
|
|
|
bool invalidHandle:1; /* file closed via session abend */
|
2020-04-10 02:42:18 +00:00
|
|
|
bool swapfile:1;
|
2009-09-21 10:47:50 +00:00
|
|
|
bool oplock_break_cancelled:1;
|
2019-10-29 23:51:19 +00:00
|
|
|
unsigned int oplock_epoch; /* epoch from the lease break */
|
|
|
|
__u32 oplock_level; /* oplock/lease level from the lease break */
|
2016-09-22 23:58:16 +00:00
|
|
|
int count;
|
|
|
|
spinlock_t file_info_lock; /* protects four flag/count fields above */
|
2009-04-09 01:14:32 +00:00
|
|
|
struct mutex fh_mutex; /* prevents reopen race after dead ses*/
|
2005-04-16 22:20:36 +00:00
|
|
|
struct cifs_search_info srch_inf;
|
2010-07-20 20:09:02 +00:00
|
|
|
struct work_struct oplock_break; /* work for oplock breaks */
|
cifs: move cifsFileInfo_put logic into a work-queue
This patch moves the final part of the cifsFileInfo_put() logic where we
need a write lock on lock_sem to be processed in a separate thread that
holds no other locks.
This is to prevent deadlocks like the one below:
> there are 6 processes looping to while trying to down_write
> cinode->lock_sem, 5 of them from _cifsFileInfo_put, and one from
> cifs_new_fileinfo
>
> and there are 5 other processes which are blocked, several of them
> waiting on either PG_writeback or PG_locked (which are both set), all
> for the same page of the file
>
> 2 inode_lock() (inode->i_rwsem) for the file
> 1 wait_on_page_writeback() for the page
> 1 down_read(inode->i_rwsem) for the inode of the directory
> 1 inode_lock()(inode->i_rwsem) for the inode of the directory
> 1 __lock_page
>
>
> so processes are blocked waiting on:
> page flags PG_locked and PG_writeback for one specific page
> inode->i_rwsem for the directory
> inode->i_rwsem for the file
> cifsInodeInflock_sem
>
>
>
> here are the more gory details (let me know if I need to provide
> anything more/better):
>
> [0 00:48:22.765] [UN] PID: 8863 TASK: ffff8c691547c5c0 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff9965007e3ba8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007e3c38] schedule at ffffffff9b6e64df
> #2 [ffff9965007e3c48] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965007e3cb8] legitimize_path at ffffffff9b0f975d
> #4 [ffff9965007e3d08] path_openat at ffffffff9b0fe55d
> #5 [ffff9965007e3dd8] do_filp_open at ffffffff9b100a33
> #6 [ffff9965007e3ee0] do_sys_open at ffffffff9b0eb2d6
> #7 [ffff9965007e3f38] do_syscall_64 at ffffffff9ae04315
> * (I think legitimize_path is bogus)
>
> in path_openat
> } else {
> const char *s = path_init(nd, flags);
> while (!(error = link_path_walk(s, nd)) &&
> (error = do_last(nd, file, op)) > 0) { <<<<
>
> do_last:
> if (open_flag & O_CREAT)
> inode_lock(dir->d_inode); <<<<
> else
> so it's trying to take inode->i_rwsem for the directory
>
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68bb8e79c0 ffff8c691158ef20 ffff8c6915bf9000 DIR /mnt/vm1_smb/
> inode.i_rwsem is ffff8c691158efc0
>
> <struct rw_semaphore 0xffff8c691158efc0>:
> owner: <struct task_struct 0xffff8c6914275d00> (UN - 8856 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 2
> 0xffff9965007e3c90 8863 reopen_file UN 0 1:29:22.926
> RWSEM_WAITING_FOR_WRITE
> 0xffff996500393e00 9802 ls UN 0 1:17:26.700
> RWSEM_WAITING_FOR_READ
>
>
> the owner of the inode.i_rwsem of the directory is:
>
> [0 00:00:00.109] [UN] PID: 8856 TASK: ffff8c6914275d00 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff99650065b828] __schedule at ffffffff9b6e6095
> #1 [ffff99650065b8b8] schedule at ffffffff9b6e64df
> #2 [ffff99650065b8c8] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff99650065b940] msleep at ffffffff9af573a9
> #4 [ffff99650065b948] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff99650065ba38] cifs_writepage_locked at ffffffffc0a0b8f3 [cifs]
> #6 [ffff99650065bab0] cifs_launder_page at ffffffffc0a0bb72 [cifs]
> #7 [ffff99650065bb30] invalidate_inode_pages2_range at ffffffff9b04d4bd
> #8 [ffff99650065bcb8] cifs_invalidate_mapping at ffffffffc0a11339 [cifs]
> #9 [ffff99650065bcd0] cifs_revalidate_mapping at ffffffffc0a1139a [cifs]
> #10 [ffff99650065bcf0] cifs_d_revalidate at ffffffffc0a014f6 [cifs]
> #11 [ffff99650065bd08] path_openat at ffffffff9b0fe7f7
> #12 [ffff99650065bdd8] do_filp_open at ffffffff9b100a33
> #13 [ffff99650065bee0] do_sys_open at ffffffff9b0eb2d6
> #14 [ffff99650065bf38] do_syscall_64 at ffffffff9ae04315
>
> cifs_launder_page is for page 0xffffd1e2c07d2480
>
> crash> page.index,mapping,flags 0xffffd1e2c07d2480
> index = 0x8
> mapping = 0xffff8c68f3cd0db0
> flags = 0xfffffc0008095
>
> PAGE-FLAG BIT VALUE
> PG_locked 0 0000001
> PG_uptodate 2 0000004
> PG_lru 4 0000010
> PG_waiters 7 0000080
> PG_writeback 15 0008000
>
>
> inode is ffff8c68f3cd0c40
> inode.i_rwsem is ffff8c68f3cd0ce0
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68a1f1b480 ffff8c68f3cd0c40 ffff8c6915bf9000 REG
> /mnt/vm1_smb/testfile.8853
>
>
> this process holds the inode->i_rwsem for the parent directory, is
> laundering a page attached to the inode of the file it's opening, and in
> _cifsFileInfo_put is trying to down_write the cifsInodeInflock_sem
> for the file itself.
>
>
> <struct rw_semaphore 0xffff8c68f3cd0ce0>:
> owner: <struct task_struct 0xffff8c6914272e80> (UN - 8854 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 1
> 0xffff9965005dfd80 8855 reopen_file UN 0 1:29:22.912
> RWSEM_WAITING_FOR_WRITE
>
> this is the inode.i_rwsem for the file
>
> the owner:
>
> [0 00:48:22.739] [UN] PID: 8854 TASK: ffff8c6914272e80 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff99650054fb38] __schedule at ffffffff9b6e6095
> #1 [ffff99650054fbc8] schedule at ffffffff9b6e64df
> #2 [ffff99650054fbd8] io_schedule at ffffffff9b6e68e2
> #3 [ffff99650054fbe8] __lock_page at ffffffff9b03c56f
> #4 [ffff99650054fc80] pagecache_get_page at ffffffff9b03dcdf
> #5 [ffff99650054fcc0] grab_cache_page_write_begin at ffffffff9b03ef4c
> #6 [ffff99650054fcd0] cifs_write_begin at ffffffffc0a064ec [cifs]
> #7 [ffff99650054fd30] generic_perform_write at ffffffff9b03bba4
> #8 [ffff99650054fda8] __generic_file_write_iter at ffffffff9b04060a
> #9 [ffff99650054fdf0] cifs_strict_writev.cold.70 at ffffffffc0a4469b [cifs]
> #10 [ffff99650054fe48] new_sync_write at ffffffff9b0ec1dd
> #11 [ffff99650054fed0] vfs_write at ffffffff9b0eed35
> #12 [ffff99650054ff00] ksys_write at ffffffff9b0eefd9
> #13 [ffff99650054ff38] do_syscall_64 at ffffffff9ae04315
>
> the process holds the inode->i_rwsem for the file to which it's writing,
> and is trying to __lock_page for the same page as in the other processes
>
>
> the other tasks:
> [0 00:00:00.028] [UN] PID: 8859 TASK: ffff8c6915479740 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff9965007b39d8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007b3a68] schedule at ffffffff9b6e64df
> #2 [ffff9965007b3a78] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007b3af0] msleep at ffffffff9af573a9
> #4 [ffff9965007b3af8] cifs_new_fileinfo.cold.61 at ffffffffc0a42a07 [cifs]
> #5 [ffff9965007b3b78] cifs_open at ffffffffc0a0709d [cifs]
> #6 [ffff9965007b3cd8] do_dentry_open at ffffffff9b0e9b7a
> #7 [ffff9965007b3d08] path_openat at ffffffff9b0fe34f
> #8 [ffff9965007b3dd8] do_filp_open at ffffffff9b100a33
> #9 [ffff9965007b3ee0] do_sys_open at ffffffff9b0eb2d6
> #10 [ffff9965007b3f38] do_syscall_64 at ffffffff9ae04315
>
> this is opening the file, and is trying to down_write cinode->lock_sem
>
>
> [0 00:00:00.041] [UN] PID: 8860 TASK: ffff8c691547ae80 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.057] [UN] PID: 8861 TASK: ffff8c6915478000 CPU: 3
> COMMAND: "reopen_file"
> [0 00:00:00.059] [UN] PID: 8858 TASK: ffff8c6914271740 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.109] [UN] PID: 8862 TASK: ffff8c691547dd00 CPU: 6
> COMMAND: "reopen_file"
> #0 [ffff9965007c3c78] __schedule at ffffffff9b6e6095
> #1 [ffff9965007c3d08] schedule at ffffffff9b6e64df
> #2 [ffff9965007c3d18] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007c3d90] msleep at ffffffff9af573a9
> #4 [ffff9965007c3d98] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff9965007c3e88] cifs_close at ffffffffc0a07aaf [cifs]
> #6 [ffff9965007c3ea0] __fput at ffffffff9b0efa6e
> #7 [ffff9965007c3ee8] task_work_run at ffffffff9aef1614
> #8 [ffff9965007c3f20] exit_to_usermode_loop at ffffffff9ae03d6f
> #9 [ffff9965007c3f38] do_syscall_64 at ffffffff9ae0444c
>
> closing the file, and trying to down_write cifsi->lock_sem
>
>
> [0 00:48:22.839] [UN] PID: 8857 TASK: ffff8c6914270000 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965006a7cc8] __schedule at ffffffff9b6e6095
> #1 [ffff9965006a7d58] schedule at ffffffff9b6e64df
> #2 [ffff9965006a7d68] io_schedule at ffffffff9b6e68e2
> #3 [ffff9965006a7d78] wait_on_page_bit at ffffffff9b03cac6
> #4 [ffff9965006a7e10] __filemap_fdatawait_range at ffffffff9b03b028
> #5 [ffff9965006a7ed8] filemap_write_and_wait at ffffffff9b040165
> #6 [ffff9965006a7ef0] cifs_flush at ffffffffc0a0c2fa [cifs]
> #7 [ffff9965006a7f10] filp_close at ffffffff9b0e93f1
> #8 [ffff9965006a7f30] __x64_sys_close at ffffffff9b0e9a0e
> #9 [ffff9965006a7f38] do_syscall_64 at ffffffff9ae04315
>
> in __filemap_fdatawait_range
> wait_on_page_writeback(page);
> for the same page of the file
>
>
>
> [0 00:48:22.718] [UN] PID: 8855 TASK: ffff8c69142745c0 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965005dfc98] __schedule at ffffffff9b6e6095
> #1 [ffff9965005dfd28] schedule at ffffffff9b6e64df
> #2 [ffff9965005dfd38] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965005dfdf0] cifs_strict_writev at ffffffffc0a0c40a [cifs]
> #4 [ffff9965005dfe48] new_sync_write at ffffffff9b0ec1dd
> #5 [ffff9965005dfed0] vfs_write at ffffffff9b0eed35
> #6 [ffff9965005dff00] ksys_write at ffffffff9b0eefd9
> #7 [ffff9965005dff38] do_syscall_64 at ffffffff9ae04315
>
> inode_lock(inode);
>
>
> and one 'ls' later on, to see whether the rest of the mount is available
> (the test file is in the root, so we get blocked up on the directory
> ->i_rwsem), so the entire mount is unavailable
>
> [0 00:36:26.473] [UN] PID: 9802 TASK: ffff8c691436ae80 CPU: 4
> COMMAND: "ls"
> #0 [ffff996500393d28] __schedule at ffffffff9b6e6095
> #1 [ffff996500393db8] schedule at ffffffff9b6e64df
> #2 [ffff996500393dc8] rwsem_down_read_slowpath at ffffffff9b6e9421
> #3 [ffff996500393e78] down_read_killable at ffffffff9b6e95e2
> #4 [ffff996500393e88] iterate_dir at ffffffff9b103c56
> #5 [ffff996500393ec8] ksys_getdents64 at ffffffff9b104b0c
> #6 [ffff996500393f30] __x64_sys_getdents64 at ffffffff9b104bb6
> #7 [ffff996500393f38] do_syscall_64 at ffffffff9ae04315
>
> in iterate_dir:
> if (shared)
> res = down_read_killable(&inode->i_rwsem); <<<<
> else
> res = down_write_killable(&inode->i_rwsem);
>
Reported-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
Signed-off-by: Ronnie Sahlberg <lsahlber@redhat.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
2019-11-03 03:06:37 +00:00
|
|
|
struct work_struct put; /* work for the final part of _put */
|
2021-04-13 05:26:42 +00:00
|
|
|
struct delayed_work deferred;
|
2021-05-05 10:56:47 +00:00
|
|
|
bool deferred_close_scheduled; /* Flag to indicate close is scheduled */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2011-05-26 06:01:59 +00:00
|
|
|
struct cifs_io_parms {
|
|
|
|
__u16 netfid;
|
2012-09-18 23:20:29 +00:00
|
|
|
__u64 persistent_fid; /* persist file id for smb2 */
|
|
|
|
__u64 volatile_fid; /* volatile file id for smb2 */
|
2011-05-26 06:01:59 +00:00
|
|
|
__u32 pid;
|
|
|
|
__u64 offset;
|
|
|
|
unsigned int length;
|
2011-05-27 04:34:02 +00:00
|
|
|
struct cifs_tcon *tcon;
|
2020-05-31 17:38:22 +00:00
|
|
|
struct TCP_Server_Info *server;
|
2011-05-26 06:01:59 +00:00
|
|
|
};
|
|
|
|
|
2017-04-25 18:52:29 +00:00
|
|
|
struct cifs_aio_ctx {
|
|
|
|
struct kref refcount;
|
|
|
|
struct list_head list;
|
|
|
|
struct mutex aio_mutex;
|
|
|
|
struct completion done;
|
|
|
|
struct iov_iter iter;
|
|
|
|
struct kiocb *iocb;
|
|
|
|
struct cifsFileInfo *cfile;
|
|
|
|
struct bio_vec *bv;
|
2017-04-25 18:52:31 +00:00
|
|
|
loff_t pos;
|
2017-04-25 18:52:29 +00:00
|
|
|
unsigned int npages;
|
|
|
|
ssize_t rc;
|
|
|
|
unsigned int len;
|
|
|
|
unsigned int total_len;
|
|
|
|
bool should_dirty;
|
2018-10-31 22:13:09 +00:00
|
|
|
/*
|
|
|
|
* Indicates if this aio_ctx is for direct_io,
|
|
|
|
* If yes, iter is a copy of the user passed iov_iter
|
|
|
|
*/
|
|
|
|
bool direct_io;
|
2017-04-25 18:52:29 +00:00
|
|
|
};
|
|
|
|
|
2012-09-18 23:20:29 +00:00
|
|
|
/* asynchronous read support */
|
|
|
|
struct cifs_readdata {
|
|
|
|
struct kref refcount;
|
|
|
|
struct list_head list;
|
|
|
|
struct completion done;
|
|
|
|
struct cifsFileInfo *cfile;
|
|
|
|
struct address_space *mapping;
|
2017-04-25 18:52:30 +00:00
|
|
|
struct cifs_aio_ctx *ctx;
|
2012-09-18 23:20:29 +00:00
|
|
|
__u64 offset;
|
|
|
|
unsigned int bytes;
|
2014-07-10 06:03:29 +00:00
|
|
|
unsigned int got_bytes;
|
2012-09-18 23:20:29 +00:00
|
|
|
pid_t pid;
|
|
|
|
int result;
|
|
|
|
struct work_struct work;
|
2012-09-19 13:22:32 +00:00
|
|
|
int (*read_into_pages)(struct TCP_Server_Info *server,
|
|
|
|
struct cifs_readdata *rdata,
|
|
|
|
unsigned int len);
|
2016-11-18 00:20:18 +00:00
|
|
|
int (*copy_into_pages)(struct TCP_Server_Info *server,
|
|
|
|
struct cifs_readdata *rdata,
|
|
|
|
struct iov_iter *iter);
|
2016-11-23 23:14:57 +00:00
|
|
|
struct kvec iov[2];
|
2020-05-31 17:38:22 +00:00
|
|
|
struct TCP_Server_Info *server;
|
2017-11-23 00:38:46 +00:00
|
|
|
#ifdef CONFIG_CIFS_SMB_DIRECT
|
|
|
|
struct smbd_mr *mr;
|
|
|
|
#endif
|
2012-09-19 13:22:32 +00:00
|
|
|
unsigned int pagesz;
|
2018-05-30 19:47:53 +00:00
|
|
|
unsigned int page_offset;
|
2012-09-19 13:22:32 +00:00
|
|
|
unsigned int tailsz;
|
2019-01-16 19:12:41 +00:00
|
|
|
struct cifs_credits credits;
|
2012-09-19 13:22:30 +00:00
|
|
|
unsigned int nr_pages;
|
2018-05-30 19:47:54 +00:00
|
|
|
struct page **pages;
|
2012-09-18 23:20:29 +00:00
|
|
|
};
|
|
|
|
|
2012-09-18 23:20:29 +00:00
|
|
|
/* asynchronous write support */
|
|
|
|
struct cifs_writedata {
|
|
|
|
struct kref refcount;
|
|
|
|
struct list_head list;
|
|
|
|
struct completion done;
|
|
|
|
enum writeback_sync_modes sync_mode;
|
|
|
|
struct work_struct work;
|
|
|
|
struct cifsFileInfo *cfile;
|
2017-04-25 18:52:31 +00:00
|
|
|
struct cifs_aio_ctx *ctx;
|
2012-09-18 23:20:29 +00:00
|
|
|
__u64 offset;
|
|
|
|
pid_t pid;
|
|
|
|
unsigned int bytes;
|
|
|
|
int result;
|
2020-05-31 17:38:22 +00:00
|
|
|
struct TCP_Server_Info *server;
|
2017-11-23 00:38:45 +00:00
|
|
|
#ifdef CONFIG_CIFS_SMB_DIRECT
|
|
|
|
struct smbd_mr *mr;
|
|
|
|
#endif
|
2012-09-18 23:20:35 +00:00
|
|
|
unsigned int pagesz;
|
2018-05-30 19:47:53 +00:00
|
|
|
unsigned int page_offset;
|
2012-09-18 23:20:35 +00:00
|
|
|
unsigned int tailsz;
|
2019-01-16 19:12:41 +00:00
|
|
|
struct cifs_credits credits;
|
2012-09-18 23:20:29 +00:00
|
|
|
unsigned int nr_pages;
|
2018-05-30 19:47:56 +00:00
|
|
|
struct page **pages;
|
2012-09-18 23:20:29 +00:00
|
|
|
};
|
|
|
|
|
2010-10-15 19:34:06 +00:00
|
|
|
/*
|
|
|
|
* Take a reference on the file private data. Must be called with
|
2016-09-22 23:58:16 +00:00
|
|
|
* cfile->file_info_lock held.
|
2010-10-15 19:34:06 +00:00
|
|
|
*/
|
2012-07-25 18:59:54 +00:00
|
|
|
static inline void
|
|
|
|
cifsFileInfo_get_locked(struct cifsFileInfo *cifs_file)
|
2009-08-31 15:07:12 +00:00
|
|
|
{
|
2010-10-15 19:34:06 +00:00
|
|
|
++cifs_file->count;
|
2009-08-31 15:07:12 +00:00
|
|
|
}
|
|
|
|
|
2012-07-25 18:59:54 +00:00
|
|
|
struct cifsFileInfo *cifsFileInfo_get(struct cifsFileInfo *cifs_file);
|
cifs: move cifsFileInfo_put logic into a work-queue
This patch moves the final part of the cifsFileInfo_put() logic where we
need a write lock on lock_sem to be processed in a separate thread that
holds no other locks.
This is to prevent deadlocks like the one below:
> there are 6 processes looping to while trying to down_write
> cinode->lock_sem, 5 of them from _cifsFileInfo_put, and one from
> cifs_new_fileinfo
>
> and there are 5 other processes which are blocked, several of them
> waiting on either PG_writeback or PG_locked (which are both set), all
> for the same page of the file
>
> 2 inode_lock() (inode->i_rwsem) for the file
> 1 wait_on_page_writeback() for the page
> 1 down_read(inode->i_rwsem) for the inode of the directory
> 1 inode_lock()(inode->i_rwsem) for the inode of the directory
> 1 __lock_page
>
>
> so processes are blocked waiting on:
> page flags PG_locked and PG_writeback for one specific page
> inode->i_rwsem for the directory
> inode->i_rwsem for the file
> cifsInodeInflock_sem
>
>
>
> here are the more gory details (let me know if I need to provide
> anything more/better):
>
> [0 00:48:22.765] [UN] PID: 8863 TASK: ffff8c691547c5c0 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff9965007e3ba8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007e3c38] schedule at ffffffff9b6e64df
> #2 [ffff9965007e3c48] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965007e3cb8] legitimize_path at ffffffff9b0f975d
> #4 [ffff9965007e3d08] path_openat at ffffffff9b0fe55d
> #5 [ffff9965007e3dd8] do_filp_open at ffffffff9b100a33
> #6 [ffff9965007e3ee0] do_sys_open at ffffffff9b0eb2d6
> #7 [ffff9965007e3f38] do_syscall_64 at ffffffff9ae04315
> * (I think legitimize_path is bogus)
>
> in path_openat
> } else {
> const char *s = path_init(nd, flags);
> while (!(error = link_path_walk(s, nd)) &&
> (error = do_last(nd, file, op)) > 0) { <<<<
>
> do_last:
> if (open_flag & O_CREAT)
> inode_lock(dir->d_inode); <<<<
> else
> so it's trying to take inode->i_rwsem for the directory
>
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68bb8e79c0 ffff8c691158ef20 ffff8c6915bf9000 DIR /mnt/vm1_smb/
> inode.i_rwsem is ffff8c691158efc0
>
> <struct rw_semaphore 0xffff8c691158efc0>:
> owner: <struct task_struct 0xffff8c6914275d00> (UN - 8856 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 2
> 0xffff9965007e3c90 8863 reopen_file UN 0 1:29:22.926
> RWSEM_WAITING_FOR_WRITE
> 0xffff996500393e00 9802 ls UN 0 1:17:26.700
> RWSEM_WAITING_FOR_READ
>
>
> the owner of the inode.i_rwsem of the directory is:
>
> [0 00:00:00.109] [UN] PID: 8856 TASK: ffff8c6914275d00 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff99650065b828] __schedule at ffffffff9b6e6095
> #1 [ffff99650065b8b8] schedule at ffffffff9b6e64df
> #2 [ffff99650065b8c8] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff99650065b940] msleep at ffffffff9af573a9
> #4 [ffff99650065b948] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff99650065ba38] cifs_writepage_locked at ffffffffc0a0b8f3 [cifs]
> #6 [ffff99650065bab0] cifs_launder_page at ffffffffc0a0bb72 [cifs]
> #7 [ffff99650065bb30] invalidate_inode_pages2_range at ffffffff9b04d4bd
> #8 [ffff99650065bcb8] cifs_invalidate_mapping at ffffffffc0a11339 [cifs]
> #9 [ffff99650065bcd0] cifs_revalidate_mapping at ffffffffc0a1139a [cifs]
> #10 [ffff99650065bcf0] cifs_d_revalidate at ffffffffc0a014f6 [cifs]
> #11 [ffff99650065bd08] path_openat at ffffffff9b0fe7f7
> #12 [ffff99650065bdd8] do_filp_open at ffffffff9b100a33
> #13 [ffff99650065bee0] do_sys_open at ffffffff9b0eb2d6
> #14 [ffff99650065bf38] do_syscall_64 at ffffffff9ae04315
>
> cifs_launder_page is for page 0xffffd1e2c07d2480
>
> crash> page.index,mapping,flags 0xffffd1e2c07d2480
> index = 0x8
> mapping = 0xffff8c68f3cd0db0
> flags = 0xfffffc0008095
>
> PAGE-FLAG BIT VALUE
> PG_locked 0 0000001
> PG_uptodate 2 0000004
> PG_lru 4 0000010
> PG_waiters 7 0000080
> PG_writeback 15 0008000
>
>
> inode is ffff8c68f3cd0c40
> inode.i_rwsem is ffff8c68f3cd0ce0
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68a1f1b480 ffff8c68f3cd0c40 ffff8c6915bf9000 REG
> /mnt/vm1_smb/testfile.8853
>
>
> this process holds the inode->i_rwsem for the parent directory, is
> laundering a page attached to the inode of the file it's opening, and in
> _cifsFileInfo_put is trying to down_write the cifsInodeInflock_sem
> for the file itself.
>
>
> <struct rw_semaphore 0xffff8c68f3cd0ce0>:
> owner: <struct task_struct 0xffff8c6914272e80> (UN - 8854 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 1
> 0xffff9965005dfd80 8855 reopen_file UN 0 1:29:22.912
> RWSEM_WAITING_FOR_WRITE
>
> this is the inode.i_rwsem for the file
>
> the owner:
>
> [0 00:48:22.739] [UN] PID: 8854 TASK: ffff8c6914272e80 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff99650054fb38] __schedule at ffffffff9b6e6095
> #1 [ffff99650054fbc8] schedule at ffffffff9b6e64df
> #2 [ffff99650054fbd8] io_schedule at ffffffff9b6e68e2
> #3 [ffff99650054fbe8] __lock_page at ffffffff9b03c56f
> #4 [ffff99650054fc80] pagecache_get_page at ffffffff9b03dcdf
> #5 [ffff99650054fcc0] grab_cache_page_write_begin at ffffffff9b03ef4c
> #6 [ffff99650054fcd0] cifs_write_begin at ffffffffc0a064ec [cifs]
> #7 [ffff99650054fd30] generic_perform_write at ffffffff9b03bba4
> #8 [ffff99650054fda8] __generic_file_write_iter at ffffffff9b04060a
> #9 [ffff99650054fdf0] cifs_strict_writev.cold.70 at ffffffffc0a4469b [cifs]
> #10 [ffff99650054fe48] new_sync_write at ffffffff9b0ec1dd
> #11 [ffff99650054fed0] vfs_write at ffffffff9b0eed35
> #12 [ffff99650054ff00] ksys_write at ffffffff9b0eefd9
> #13 [ffff99650054ff38] do_syscall_64 at ffffffff9ae04315
>
> the process holds the inode->i_rwsem for the file to which it's writing,
> and is trying to __lock_page for the same page as in the other processes
>
>
> the other tasks:
> [0 00:00:00.028] [UN] PID: 8859 TASK: ffff8c6915479740 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff9965007b39d8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007b3a68] schedule at ffffffff9b6e64df
> #2 [ffff9965007b3a78] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007b3af0] msleep at ffffffff9af573a9
> #4 [ffff9965007b3af8] cifs_new_fileinfo.cold.61 at ffffffffc0a42a07 [cifs]
> #5 [ffff9965007b3b78] cifs_open at ffffffffc0a0709d [cifs]
> #6 [ffff9965007b3cd8] do_dentry_open at ffffffff9b0e9b7a
> #7 [ffff9965007b3d08] path_openat at ffffffff9b0fe34f
> #8 [ffff9965007b3dd8] do_filp_open at ffffffff9b100a33
> #9 [ffff9965007b3ee0] do_sys_open at ffffffff9b0eb2d6
> #10 [ffff9965007b3f38] do_syscall_64 at ffffffff9ae04315
>
> this is opening the file, and is trying to down_write cinode->lock_sem
>
>
> [0 00:00:00.041] [UN] PID: 8860 TASK: ffff8c691547ae80 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.057] [UN] PID: 8861 TASK: ffff8c6915478000 CPU: 3
> COMMAND: "reopen_file"
> [0 00:00:00.059] [UN] PID: 8858 TASK: ffff8c6914271740 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.109] [UN] PID: 8862 TASK: ffff8c691547dd00 CPU: 6
> COMMAND: "reopen_file"
> #0 [ffff9965007c3c78] __schedule at ffffffff9b6e6095
> #1 [ffff9965007c3d08] schedule at ffffffff9b6e64df
> #2 [ffff9965007c3d18] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007c3d90] msleep at ffffffff9af573a9
> #4 [ffff9965007c3d98] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff9965007c3e88] cifs_close at ffffffffc0a07aaf [cifs]
> #6 [ffff9965007c3ea0] __fput at ffffffff9b0efa6e
> #7 [ffff9965007c3ee8] task_work_run at ffffffff9aef1614
> #8 [ffff9965007c3f20] exit_to_usermode_loop at ffffffff9ae03d6f
> #9 [ffff9965007c3f38] do_syscall_64 at ffffffff9ae0444c
>
> closing the file, and trying to down_write cifsi->lock_sem
>
>
> [0 00:48:22.839] [UN] PID: 8857 TASK: ffff8c6914270000 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965006a7cc8] __schedule at ffffffff9b6e6095
> #1 [ffff9965006a7d58] schedule at ffffffff9b6e64df
> #2 [ffff9965006a7d68] io_schedule at ffffffff9b6e68e2
> #3 [ffff9965006a7d78] wait_on_page_bit at ffffffff9b03cac6
> #4 [ffff9965006a7e10] __filemap_fdatawait_range at ffffffff9b03b028
> #5 [ffff9965006a7ed8] filemap_write_and_wait at ffffffff9b040165
> #6 [ffff9965006a7ef0] cifs_flush at ffffffffc0a0c2fa [cifs]
> #7 [ffff9965006a7f10] filp_close at ffffffff9b0e93f1
> #8 [ffff9965006a7f30] __x64_sys_close at ffffffff9b0e9a0e
> #9 [ffff9965006a7f38] do_syscall_64 at ffffffff9ae04315
>
> in __filemap_fdatawait_range
> wait_on_page_writeback(page);
> for the same page of the file
>
>
>
> [0 00:48:22.718] [UN] PID: 8855 TASK: ffff8c69142745c0 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965005dfc98] __schedule at ffffffff9b6e6095
> #1 [ffff9965005dfd28] schedule at ffffffff9b6e64df
> #2 [ffff9965005dfd38] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965005dfdf0] cifs_strict_writev at ffffffffc0a0c40a [cifs]
> #4 [ffff9965005dfe48] new_sync_write at ffffffff9b0ec1dd
> #5 [ffff9965005dfed0] vfs_write at ffffffff9b0eed35
> #6 [ffff9965005dff00] ksys_write at ffffffff9b0eefd9
> #7 [ffff9965005dff38] do_syscall_64 at ffffffff9ae04315
>
> inode_lock(inode);
>
>
> and one 'ls' later on, to see whether the rest of the mount is available
> (the test file is in the root, so we get blocked up on the directory
> ->i_rwsem), so the entire mount is unavailable
>
> [0 00:36:26.473] [UN] PID: 9802 TASK: ffff8c691436ae80 CPU: 4
> COMMAND: "ls"
> #0 [ffff996500393d28] __schedule at ffffffff9b6e6095
> #1 [ffff996500393db8] schedule at ffffffff9b6e64df
> #2 [ffff996500393dc8] rwsem_down_read_slowpath at ffffffff9b6e9421
> #3 [ffff996500393e78] down_read_killable at ffffffff9b6e95e2
> #4 [ffff996500393e88] iterate_dir at ffffffff9b103c56
> #5 [ffff996500393ec8] ksys_getdents64 at ffffffff9b104b0c
> #6 [ffff996500393f30] __x64_sys_getdents64 at ffffffff9b104bb6
> #7 [ffff996500393f38] do_syscall_64 at ffffffff9ae04315
>
> in iterate_dir:
> if (shared)
> res = down_read_killable(&inode->i_rwsem); <<<<
> else
> res = down_write_killable(&inode->i_rwsem);
>
Reported-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
Signed-off-by: Ronnie Sahlberg <lsahlber@redhat.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
2019-11-03 03:06:37 +00:00
|
|
|
void _cifsFileInfo_put(struct cifsFileInfo *cifs_file, bool wait_oplock_hdlr,
|
|
|
|
bool offload);
|
2010-10-15 19:34:04 +00:00
|
|
|
void cifsFileInfo_put(struct cifsFileInfo *cifs_file);
|
2009-08-31 15:07:12 +00:00
|
|
|
|
2013-09-05 09:01:06 +00:00
|
|
|
#define CIFS_CACHE_READ_FLG 1
|
|
|
|
#define CIFS_CACHE_HANDLE_FLG 2
|
2013-09-05 17:30:16 +00:00
|
|
|
#define CIFS_CACHE_RH_FLG (CIFS_CACHE_READ_FLG | CIFS_CACHE_HANDLE_FLG)
|
2013-09-05 09:01:06 +00:00
|
|
|
#define CIFS_CACHE_WRITE_FLG 4
|
2013-09-05 17:30:16 +00:00
|
|
|
#define CIFS_CACHE_RW_FLG (CIFS_CACHE_READ_FLG | CIFS_CACHE_WRITE_FLG)
|
|
|
|
#define CIFS_CACHE_RHW_FLG (CIFS_CACHE_RW_FLG | CIFS_CACHE_HANDLE_FLG)
|
2013-09-05 09:01:06 +00:00
|
|
|
|
2019-08-28 04:58:54 +00:00
|
|
|
#define CIFS_CACHE_READ(cinode) ((cinode->oplock & CIFS_CACHE_READ_FLG) || (CIFS_SB(cinode->vfs_inode.i_sb)->mnt_cifs_flags & CIFS_MOUNT_RO_CACHE))
|
2013-09-05 12:11:28 +00:00
|
|
|
#define CIFS_CACHE_HANDLE(cinode) (cinode->oplock & CIFS_CACHE_HANDLE_FLG)
|
2019-08-30 07:12:41 +00:00
|
|
|
#define CIFS_CACHE_WRITE(cinode) ((cinode->oplock & CIFS_CACHE_WRITE_FLG) || (CIFS_SB(cinode->vfs_inode.i_sb)->mnt_cifs_flags & CIFS_MOUNT_RW_CACHE))
|
2013-09-05 09:01:06 +00:00
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* One of these for each file inode
|
|
|
|
*/
|
|
|
|
|
|
|
|
struct cifsInodeInfo {
|
2011-09-22 05:53:59 +00:00
|
|
|
bool can_cache_brlcks;
|
2012-09-19 13:22:43 +00:00
|
|
|
struct list_head llist; /* locks helb by this inode */
|
2019-10-23 09:02:33 +00:00
|
|
|
/*
|
|
|
|
* NOTE: Some code paths call down_read(lock_sem) twice, so
|
2020-07-20 00:13:16 +00:00
|
|
|
* we must always use cifs_down_write() instead of down_write()
|
2019-10-23 09:02:33 +00:00
|
|
|
* for this semaphore to avoid deadlocks.
|
|
|
|
*/
|
2012-09-19 13:22:44 +00:00
|
|
|
struct rw_semaphore lock_sem; /* protect the fields above */
|
2007-06-28 19:44:13 +00:00
|
|
|
/* BB add in lists for dirty pages i.e. write caching info for oplock */
|
2005-04-16 22:20:36 +00:00
|
|
|
struct list_head openFileList;
|
2019-06-05 00:38:38 +00:00
|
|
|
spinlock_t open_file_lock; /* protects openFileList */
|
2005-04-16 22:20:36 +00:00
|
|
|
__u32 cifsAttrs; /* e.g. DOS archive bit, sparse, compressed, system */
|
2013-09-05 09:01:06 +00:00
|
|
|
unsigned int oplock; /* oplock/lease level we have */
|
2013-09-05 17:30:16 +00:00
|
|
|
unsigned int epoch; /* used to track lease state changes */
|
2014-03-11 16:11:47 +00:00
|
|
|
#define CIFS_INODE_PENDING_OPLOCK_BREAK (0) /* oplock break in progress */
|
|
|
|
#define CIFS_INODE_PENDING_WRITERS (1) /* Writes in progress */
|
2019-10-29 23:51:19 +00:00
|
|
|
#define CIFS_INODE_FLAG_UNUSED (2) /* Unused flag */
|
2014-04-30 13:31:45 +00:00
|
|
|
#define CIFS_INO_DELETE_PENDING (3) /* delete pending on server */
|
|
|
|
#define CIFS_INO_INVALID_MAPPING (4) /* pagecache is invalid */
|
2014-04-30 13:31:47 +00:00
|
|
|
#define CIFS_INO_LOCK (5) /* lock bit for synchronization */
|
2021-04-13 05:26:42 +00:00
|
|
|
#define CIFS_INO_MODIFIED_ATTR (6) /* Indicate change in mtime/ctime */
|
2021-09-17 21:50:40 +00:00
|
|
|
#define CIFS_INO_CLOSE_ON_LOCK (7) /* Not to defer the close when lock is set */
|
2014-04-30 13:31:45 +00:00
|
|
|
unsigned long flags;
|
2014-03-11 16:11:47 +00:00
|
|
|
spinlock_t writers_lock;
|
|
|
|
unsigned int writers; /* Number of writers on this inode */
|
2011-01-20 18:36:50 +00:00
|
|
|
unsigned long time; /* jiffies of last update of inode */
|
2012-03-23 18:40:56 +00:00
|
|
|
u64 server_eof; /* current file size on server -- protected by i_lock */
|
2009-06-25 04:56:52 +00:00
|
|
|
u64 uniqueid; /* server inode number */
|
2011-01-07 16:30:27 +00:00
|
|
|
u64 createtime; /* creation time on server */
|
2012-09-19 13:22:44 +00:00
|
|
|
__u8 lease_key[SMB2_LEASE_KEY_SIZE]; /* lease key for this inode */
|
2010-07-05 12:42:45 +00:00
|
|
|
#ifdef CONFIG_CIFS_FSCACHE
|
|
|
|
struct fscache_cookie *fscache;
|
|
|
|
#endif
|
2005-04-16 22:20:36 +00:00
|
|
|
struct inode vfs_inode;
|
2021-04-13 05:26:42 +00:00
|
|
|
struct list_head deferred_closes; /* list of deferred closes */
|
|
|
|
spinlock_t deferred_lock; /* protection on deferred list */
|
2021-05-17 11:28:34 +00:00
|
|
|
bool lease_granted; /* Flag to indicate whether lease or oplock is granted. */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
static inline struct cifsInodeInfo *
|
|
|
|
CIFS_I(struct inode *inode)
|
|
|
|
{
|
|
|
|
return container_of(inode, struct cifsInodeInfo, vfs_inode);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline struct cifs_sb_info *
|
|
|
|
CIFS_SB(struct super_block *sb)
|
|
|
|
{
|
|
|
|
return sb->s_fs_info;
|
|
|
|
}
|
|
|
|
|
2014-10-22 04:25:12 +00:00
|
|
|
static inline struct cifs_sb_info *
|
|
|
|
CIFS_FILE_SB(struct file *file)
|
|
|
|
{
|
|
|
|
return CIFS_SB(file_inode(file)->i_sb);
|
|
|
|
}
|
|
|
|
|
2005-09-16 03:44:50 +00:00
|
|
|
static inline char CIFS_DIR_SEP(const struct cifs_sb_info *cifs_sb)
|
2005-06-23 00:26:35 +00:00
|
|
|
{
|
|
|
|
if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_POSIX_PATHS)
|
|
|
|
return '/';
|
|
|
|
else
|
|
|
|
return '\\';
|
|
|
|
}
|
2005-04-16 22:20:36 +00:00
|
|
|
|
2011-05-27 03:50:55 +00:00
|
|
|
static inline void
|
|
|
|
convert_delimiter(char *path, char delim)
|
|
|
|
{
|
2012-11-30 00:07:51 +00:00
|
|
|
char old_delim, *pos;
|
2011-05-27 03:50:55 +00:00
|
|
|
|
|
|
|
if (delim == '/')
|
|
|
|
old_delim = '\\';
|
|
|
|
else
|
|
|
|
old_delim = '/';
|
|
|
|
|
2012-11-30 00:07:51 +00:00
|
|
|
pos = path;
|
|
|
|
while ((pos = strchr(pos, old_delim)))
|
|
|
|
*pos = delim;
|
2011-05-27 03:50:55 +00:00
|
|
|
}
|
|
|
|
|
2005-08-24 20:59:35 +00:00
|
|
|
#define cifs_stats_inc atomic_inc
|
|
|
|
|
2011-05-27 04:34:02 +00:00
|
|
|
static inline void cifs_stats_bytes_written(struct cifs_tcon *tcon,
|
2005-08-24 20:59:35 +00:00
|
|
|
unsigned int bytes)
|
|
|
|
{
|
|
|
|
if (bytes) {
|
|
|
|
spin_lock(&tcon->stat_lock);
|
|
|
|
tcon->bytes_written += bytes;
|
|
|
|
spin_unlock(&tcon->stat_lock);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2011-05-27 04:34:02 +00:00
|
|
|
static inline void cifs_stats_bytes_read(struct cifs_tcon *tcon,
|
2005-08-24 20:59:35 +00:00
|
|
|
unsigned int bytes)
|
|
|
|
{
|
|
|
|
spin_lock(&tcon->stat_lock);
|
|
|
|
tcon->bytes_read += bytes;
|
|
|
|
spin_unlock(&tcon->stat_lock);
|
|
|
|
}
|
|
|
|
|
2011-01-11 12:24:21 +00:00
|
|
|
|
|
|
|
/*
|
2011-10-19 19:29:49 +00:00
|
|
|
* This is the prototype for the mid receive function. This function is for
|
|
|
|
* receiving the rest of the SMB frame, starting with the WordCount (which is
|
|
|
|
* just after the MID in struct smb_hdr). Note:
|
|
|
|
*
|
|
|
|
* - This will be called by cifsd, with no locks held.
|
|
|
|
* - The mid will still be on the pending_mid_q.
|
|
|
|
* - mid->resp_buf will point to the current buffer.
|
|
|
|
*
|
|
|
|
* Returns zero on a successful receive, or an error. The receive state in
|
|
|
|
* the TCP_Server_Info will also be updated.
|
|
|
|
*/
|
|
|
|
typedef int (mid_receive_t)(struct TCP_Server_Info *server,
|
|
|
|
struct mid_q_entry *mid);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* This is the prototype for the mid callback function. This is called once the
|
|
|
|
* mid has been received off of the socket. When creating one, take special
|
|
|
|
* care to avoid deadlocks. Things to bear in mind:
|
2011-01-11 12:24:21 +00:00
|
|
|
*
|
2011-05-22 11:09:13 +00:00
|
|
|
* - it will be called by cifsd, with no locks held
|
|
|
|
* - the mid will be removed from any lists
|
2011-01-11 12:24:21 +00:00
|
|
|
*/
|
|
|
|
typedef void (mid_callback_t)(struct mid_q_entry *mid);
|
|
|
|
|
2016-11-16 22:06:17 +00:00
|
|
|
/*
|
|
|
|
* This is the protopyte for mid handle function. This is called once the mid
|
|
|
|
* has been recognized after decryption of the message.
|
|
|
|
*/
|
|
|
|
typedef int (mid_handle_t)(struct TCP_Server_Info *server,
|
|
|
|
struct mid_q_entry *mid);
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/* one of these for every pending CIFS request to the server */
|
|
|
|
struct mid_q_entry {
|
|
|
|
struct list_head qhead; /* mids waiting on reply from this server */
|
2018-06-25 12:05:25 +00:00
|
|
|
struct kref refcount;
|
2011-12-26 18:53:34 +00:00
|
|
|
struct TCP_Server_Info *server; /* server corresponding to this mid */
|
2012-03-23 18:28:03 +00:00
|
|
|
__u64 mid; /* multiplex id */
|
2019-03-04 22:02:50 +00:00
|
|
|
__u16 credits; /* number of credits consumed by this mid */
|
2019-11-21 19:35:13 +00:00
|
|
|
__u16 credits_received; /* number of credits from the response */
|
2012-03-23 18:28:03 +00:00
|
|
|
__u32 pid; /* process id */
|
2005-04-16 22:20:36 +00:00
|
|
|
__u32 sequence_number; /* for CIFS signing */
|
2005-10-12 02:58:06 +00:00
|
|
|
unsigned long when_alloc; /* when mid was created */
|
|
|
|
#ifdef CONFIG_CIFS_STATS2
|
|
|
|
unsigned long when_sent; /* time when smb send finished */
|
|
|
|
unsigned long when_received; /* when demux complete (taken off wire) */
|
|
|
|
#endif
|
2011-10-19 19:29:49 +00:00
|
|
|
mid_receive_t *receive; /* call receive callback */
|
2011-01-11 12:24:21 +00:00
|
|
|
mid_callback_t *callback; /* call completion callback */
|
2016-11-16 22:06:17 +00:00
|
|
|
mid_handle_t *handle; /* call handle mid callback */
|
2011-01-11 12:24:21 +00:00
|
|
|
void *callback_data; /* general purpose pointer for callback */
|
CIFS: Fix task struct use-after-free on reconnect
The task which created the MID may be gone by the time cifsd attempts to
call the callbacks on MIDs from cifs_reconnect().
This leads to a use-after-free of the task struct in cifs_wake_up_task:
==================================================================
BUG: KASAN: use-after-free in __lock_acquire+0x31a0/0x3270
Read of size 8 at addr ffff8880103e3a68 by task cifsd/630
CPU: 0 PID: 630 Comm: cifsd Not tainted 5.5.0-rc6+ #119
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.10.2-1 04/01/2014
Call Trace:
dump_stack+0x8e/0xcb
print_address_description.constprop.5+0x1d3/0x3c0
? __lock_acquire+0x31a0/0x3270
__kasan_report+0x152/0x1aa
? __lock_acquire+0x31a0/0x3270
? __lock_acquire+0x31a0/0x3270
kasan_report+0xe/0x20
__lock_acquire+0x31a0/0x3270
? __wake_up_common+0x1dc/0x630
? _raw_spin_unlock_irqrestore+0x4c/0x60
? mark_held_locks+0xf0/0xf0
? _raw_spin_unlock_irqrestore+0x39/0x60
? __wake_up_common_lock+0xd5/0x130
? __wake_up_common+0x630/0x630
lock_acquire+0x13f/0x330
? try_to_wake_up+0xa3/0x19e0
_raw_spin_lock_irqsave+0x38/0x50
? try_to_wake_up+0xa3/0x19e0
try_to_wake_up+0xa3/0x19e0
? cifs_compound_callback+0x178/0x210
? set_cpus_allowed_ptr+0x10/0x10
cifs_reconnect+0xa1c/0x15d0
? generic_ip_connect+0x1860/0x1860
? rwlock_bug.part.0+0x90/0x90
cifs_readv_from_socket+0x479/0x690
cifs_read_from_socket+0x9d/0xe0
? cifs_readv_from_socket+0x690/0x690
? mempool_resize+0x690/0x690
? rwlock_bug.part.0+0x90/0x90
? memset+0x1f/0x40
? allocate_buffers+0xff/0x340
cifs_demultiplex_thread+0x388/0x2a50
? cifs_handle_standard+0x610/0x610
? rcu_read_lock_held_common+0x120/0x120
? mark_lock+0x11b/0xc00
? __lock_acquire+0x14ed/0x3270
? __kthread_parkme+0x78/0x100
? lockdep_hardirqs_on+0x3e8/0x560
? lock_downgrade+0x6a0/0x6a0
? lockdep_hardirqs_on+0x3e8/0x560
? _raw_spin_unlock_irqrestore+0x39/0x60
? cifs_handle_standard+0x610/0x610
kthread+0x2bb/0x3a0
? kthread_create_worker_on_cpu+0xc0/0xc0
ret_from_fork+0x3a/0x50
Allocated by task 649:
save_stack+0x19/0x70
__kasan_kmalloc.constprop.5+0xa6/0xf0
kmem_cache_alloc+0x107/0x320
copy_process+0x17bc/0x5370
_do_fork+0x103/0xbf0
__x64_sys_clone+0x168/0x1e0
do_syscall_64+0x9b/0xec0
entry_SYSCALL_64_after_hwframe+0x49/0xbe
Freed by task 0:
save_stack+0x19/0x70
__kasan_slab_free+0x11d/0x160
kmem_cache_free+0xb5/0x3d0
rcu_core+0x52f/0x1230
__do_softirq+0x24d/0x962
The buggy address belongs to the object at ffff8880103e32c0
which belongs to the cache task_struct of size 6016
The buggy address is located 1960 bytes inside of
6016-byte region [ffff8880103e32c0, ffff8880103e4a40)
The buggy address belongs to the page:
page:ffffea000040f800 refcount:1 mapcount:0 mapping:ffff8880108da5c0
index:0xffff8880103e4c00 compound_mapcount: 0
raw: 4000000000010200 ffffea00001f2208 ffffea00001e3408 ffff8880108da5c0
raw: ffff8880103e4c00 0000000000050003 00000001ffffffff 0000000000000000
page dumped because: kasan: bad access detected
Memory state around the buggy address:
ffff8880103e3900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff8880103e3980: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
>ffff8880103e3a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
^
ffff8880103e3a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
ffff8880103e3b00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb
==================================================================
This can be reliably reproduced by adding the below delay to
cifs_reconnect(), running find(1) on the mount, restarting the samba
server while find is running, and killing find during the delay:
spin_unlock(&GlobalMid_Lock);
mutex_unlock(&server->srv_mutex);
+ msleep(10000);
+
cifs_dbg(FYI, "%s: issuing mid callbacks\n", __func__);
list_for_each_safe(tmp, tmp2, &retry_list) {
mid_entry = list_entry(tmp, struct mid_q_entry, qhead);
Fix this by holding a reference to the task struct until the MID is
freed.
Signed-off-by: Vincent Whitchurch <vincent.whitchurch@axis.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
CC: Stable <stable@vger.kernel.org>
Reviewed-by: Paulo Alcantara (SUSE) <pc@cjr.nz>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
2020-01-23 16:09:06 +00:00
|
|
|
struct task_struct *creator;
|
2012-03-23 18:28:02 +00:00
|
|
|
void *resp_buf; /* pointer to received SMB header */
|
2018-04-09 08:06:28 +00:00
|
|
|
unsigned int resp_buf_size;
|
2012-03-23 18:28:03 +00:00
|
|
|
int mid_state; /* wish this were enum but can not pass to wait_event */
|
2017-03-03 23:41:38 +00:00
|
|
|
unsigned int mid_flags;
|
2012-03-23 18:28:03 +00:00
|
|
|
__le16 command; /* smb command code */
|
2019-01-04 00:45:27 +00:00
|
|
|
unsigned int optype; /* operation type */
|
2012-03-23 18:28:03 +00:00
|
|
|
bool large_buf:1; /* if valid response, is pointer to large buf */
|
2008-04-29 00:06:05 +00:00
|
|
|
bool multiRsp:1; /* multiple trans2 responses for one request */
|
|
|
|
bool multiEnd:1; /* both received */
|
2016-11-17 23:24:46 +00:00
|
|
|
bool decrypted:1; /* decrypted entry */
|
2005-04-16 22:20:36 +00:00
|
|
|
};
|
|
|
|
|
2017-03-03 23:41:38 +00:00
|
|
|
struct close_cancelled_open {
|
|
|
|
struct cifs_fid fid;
|
|
|
|
struct cifs_tcon *tcon;
|
|
|
|
struct work_struct work;
|
2019-11-14 18:32:12 +00:00
|
|
|
__u64 mid;
|
|
|
|
__u16 cmd;
|
2017-03-03 23:41:38 +00:00
|
|
|
};
|
|
|
|
|
2011-08-09 18:44:44 +00:00
|
|
|
/* Make code in transport.c a little cleaner by moving
|
|
|
|
update of optional stats into function below */
|
|
|
|
static inline void cifs_in_send_inc(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
atomic_inc(&server->in_send);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void cifs_in_send_dec(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
atomic_dec(&server->in_send);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void cifs_num_waiters_inc(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
atomic_inc(&server->num_waiters);
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void cifs_num_waiters_dec(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
atomic_dec(&server->num_waiters);
|
|
|
|
}
|
|
|
|
|
2019-11-21 23:26:35 +00:00
|
|
|
#ifdef CONFIG_CIFS_STATS2
|
2011-08-09 18:44:44 +00:00
|
|
|
static inline void cifs_save_when_sent(struct mid_q_entry *mid)
|
|
|
|
{
|
|
|
|
mid->when_sent = jiffies;
|
|
|
|
}
|
|
|
|
#else
|
|
|
|
static inline void cifs_save_when_sent(struct mid_q_entry *mid)
|
|
|
|
{
|
|
|
|
}
|
|
|
|
#endif
|
2005-04-16 22:20:36 +00:00
|
|
|
|
2005-08-25 00:10:36 +00:00
|
|
|
/* for pending dnotify requests */
|
|
|
|
struct dir_notify_req {
|
2010-10-07 18:46:32 +00:00
|
|
|
struct list_head lhead;
|
|
|
|
__le16 Pid;
|
|
|
|
__le16 PidHigh;
|
|
|
|
__u16 Mid;
|
|
|
|
__u16 Tid;
|
|
|
|
__u16 Uid;
|
|
|
|
__u16 netfid;
|
|
|
|
__u32 filter; /* CompletionFilter (for multishot) */
|
|
|
|
int multishot;
|
|
|
|
struct file *pfile;
|
2005-08-25 00:10:36 +00:00
|
|
|
};
|
|
|
|
|
2008-01-25 10:12:41 +00:00
|
|
|
struct dfs_info3_param {
|
|
|
|
int flags; /* DFSREF_REFERRAL_SERVER, DFSREF_STORAGE_SERVER*/
|
2008-02-15 18:21:49 +00:00
|
|
|
int path_consumed;
|
2008-01-25 10:12:41 +00:00
|
|
|
int server_type;
|
|
|
|
int ref_flag;
|
|
|
|
char *path_name;
|
|
|
|
char *node_name;
|
2018-11-14 17:38:51 +00:00
|
|
|
int ttl;
|
2008-01-25 10:12:41 +00:00
|
|
|
};
|
|
|
|
|
2021-08-09 09:32:46 +00:00
|
|
|
struct file_list {
|
|
|
|
struct list_head list;
|
|
|
|
struct cifsFileInfo *cfile;
|
|
|
|
};
|
|
|
|
|
2009-06-25 04:56:52 +00:00
|
|
|
/*
|
|
|
|
* common struct for holding inode info when searching for or updating an
|
|
|
|
* inode with new info
|
|
|
|
*/
|
|
|
|
|
|
|
|
#define CIFS_FATTR_DFS_REFERRAL 0x1
|
2009-07-09 05:46:37 +00:00
|
|
|
#define CIFS_FATTR_DELETE_PENDING 0x2
|
|
|
|
#define CIFS_FATTR_NEED_REVAL 0x4
|
2010-05-11 18:59:55 +00:00
|
|
|
#define CIFS_FATTR_INO_COLLISION 0x8
|
2013-09-21 15:36:10 +00:00
|
|
|
#define CIFS_FATTR_UNKNOWN_NLINK 0x10
|
2018-03-31 23:13:38 +00:00
|
|
|
#define CIFS_FATTR_FAKE_ROOT_INO 0x20
|
2009-06-25 04:56:52 +00:00
|
|
|
|
|
|
|
struct cifs_fattr {
|
|
|
|
u32 cf_flags;
|
|
|
|
u32 cf_cifsattrs;
|
|
|
|
u64 cf_uniqueid;
|
|
|
|
u64 cf_eof;
|
|
|
|
u64 cf_bytes;
|
2011-01-07 16:30:27 +00:00
|
|
|
u64 cf_createtime;
|
2013-02-06 09:53:25 +00:00
|
|
|
kuid_t cf_uid;
|
|
|
|
kgid_t cf_gid;
|
2009-06-25 04:56:52 +00:00
|
|
|
umode_t cf_mode;
|
|
|
|
dev_t cf_rdev;
|
|
|
|
unsigned int cf_nlink;
|
|
|
|
unsigned int cf_dtype;
|
2018-06-19 15:27:58 +00:00
|
|
|
struct timespec64 cf_atime;
|
|
|
|
struct timespec64 cf_mtime;
|
|
|
|
struct timespec64 cf_ctime;
|
2019-12-18 21:11:37 +00:00
|
|
|
u32 cf_cifstag;
|
2009-06-25 04:56:52 +00:00
|
|
|
};
|
|
|
|
|
2008-01-25 10:12:41 +00:00
|
|
|
static inline void free_dfs_info_param(struct dfs_info3_param *param)
|
|
|
|
{
|
|
|
|
if (param) {
|
|
|
|
kfree(param->path_name);
|
|
|
|
kfree(param->node_name);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void free_dfs_info_array(struct dfs_info3_param *param,
|
|
|
|
int number_of_items)
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
if ((number_of_items == 0) || (param == NULL))
|
|
|
|
return;
|
|
|
|
for (i = 0; i < number_of_items; i++) {
|
|
|
|
kfree(param[i].path_name);
|
|
|
|
kfree(param[i].node_name);
|
|
|
|
}
|
|
|
|
kfree(param);
|
|
|
|
}
|
|
|
|
|
2019-01-08 19:15:28 +00:00
|
|
|
static inline bool is_interrupt_error(int error)
|
|
|
|
{
|
|
|
|
switch (error) {
|
|
|
|
case -EINTR:
|
|
|
|
case -ERESTARTSYS:
|
|
|
|
case -ERESTARTNOHAND:
|
|
|
|
case -ERESTARTNOINTR:
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline bool is_retryable_error(int error)
|
|
|
|
{
|
|
|
|
if (is_interrupt_error(error) || error == -EAGAIN)
|
|
|
|
return true;
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
cifs: fix rename() by ensuring source handle opened with DELETE bit
To rename a file in SMB2 we open it with the DELETE access and do a
special SetInfo on it. If the handle is missing the DELETE bit the
server will fail the SetInfo with STATUS_ACCESS_DENIED.
We currently try to reuse any existing opened handle we have with
cifs_get_writable_path(). That function looks for handles with WRITE
access but doesn't check for DELETE, making rename() fail if it finds
a handle to reuse. Simple reproducer below.
To select handles with the DELETE bit, this patch adds a flag argument
to cifs_get_writable_path() and find_writable_file() and the existing
'bool fsuid_only' argument is converted to a flag.
The cifsFileInfo struct only stores the UNIX open mode but not the
original SMB access flags. Since the DELETE bit is not mapped in that
mode, this patch stores the access mask in cifs_fid on file open,
which is accessible from cifsFileInfo.
Simple reproducer:
#include <stdio.h>
#include <stdlib.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <fcntl.h>
#include <unistd.h>
#define E(s) perror(s), exit(1)
int main(int argc, char *argv[])
{
int fd, ret;
if (argc != 3) {
fprintf(stderr, "Usage: %s A B\n"
"create&open A in write mode, "
"rename A to B, close A\n", argv[0]);
return 0;
}
fd = openat(AT_FDCWD, argv[1], O_WRONLY|O_CREAT|O_SYNC, 0666);
if (fd == -1) E("openat()");
ret = rename(argv[1], argv[2]);
if (ret) E("rename()");
ret = close(fd);
if (ret) E("close()");
return ret;
}
$ gcc -o bugrename bugrename.c
$ ./bugrename /mnt/a /mnt/b
rename(): Permission denied
Fixes: 8de9e86c67ba ("cifs: create a helper to find a writeable handle by path name")
CC: Stable <stable@vger.kernel.org>
Signed-off-by: Aurelien Aptel <aaptel@suse.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
Reviewed-by: Paulo Alcantara (SUSE) <pc@cjr.nz>
2020-02-21 10:19:06 +00:00
|
|
|
|
|
|
|
/* cifs_get_writable_file() flags */
|
|
|
|
#define FIND_WR_ANY 0
|
|
|
|
#define FIND_WR_FSUID_ONLY 1
|
|
|
|
#define FIND_WR_WITH_DELETE 2
|
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
#define MID_FREE 0
|
|
|
|
#define MID_REQUEST_ALLOCATED 1
|
|
|
|
#define MID_REQUEST_SUBMITTED 2
|
|
|
|
#define MID_RESPONSE_RECEIVED 4
|
|
|
|
#define MID_RETRY_NEEDED 8 /* session closed while this request out */
|
2011-02-10 13:03:50 +00:00
|
|
|
#define MID_RESPONSE_MALFORMED 0x10
|
2011-05-22 11:09:13 +00:00
|
|
|
#define MID_SHUTDOWN 0x20
|
2005-12-13 04:53:18 +00:00
|
|
|
|
2017-03-03 23:41:38 +00:00
|
|
|
/* Flags */
|
|
|
|
#define MID_WAIT_CANCELLED 1 /* Cancelled while waiting for response */
|
2018-08-30 00:12:59 +00:00
|
|
|
#define MID_DELETED 2 /* Mid has been dequeued/deleted */
|
2017-03-03 23:41:38 +00:00
|
|
|
|
2005-12-13 04:53:18 +00:00
|
|
|
/* Types of response buffer returned from SendReceive2 */
|
|
|
|
#define CIFS_NO_BUFFER 0 /* Response buffer not returned */
|
|
|
|
#define CIFS_SMALL_BUFFER 1
|
|
|
|
#define CIFS_LARGE_BUFFER 2
|
|
|
|
#define CIFS_IOVEC 4 /* array of response buffers */
|
2005-04-16 22:20:36 +00:00
|
|
|
|
2007-11-13 22:41:37 +00:00
|
|
|
/* Type of Request to SendReceive2 */
|
2011-01-11 12:24:23 +00:00
|
|
|
#define CIFS_BLOCKING_OP 1 /* operation can block */
|
2019-05-06 00:00:02 +00:00
|
|
|
#define CIFS_NON_BLOCKING 2 /* do not block waiting for credits */
|
2011-01-11 12:24:23 +00:00
|
|
|
#define CIFS_TIMEOUT_MASK 0x003 /* only one of above set in req */
|
2007-11-13 22:41:37 +00:00
|
|
|
#define CIFS_LOG_ERROR 0x010 /* log NT STATUS if non-zero */
|
|
|
|
#define CIFS_LARGE_BUF_OP 0x020 /* large request buffer */
|
2019-05-06 00:00:02 +00:00
|
|
|
#define CIFS_NO_RSP_BUF 0x040 /* no response buffer required */
|
2007-11-13 22:41:37 +00:00
|
|
|
|
2012-05-23 12:14:34 +00:00
|
|
|
/* Type of request operation */
|
2021-03-08 15:00:50 +00:00
|
|
|
#define CIFS_ECHO_OP 0x080 /* echo request */
|
|
|
|
#define CIFS_OBREAK_OP 0x0100 /* oplock break request */
|
|
|
|
#define CIFS_NEG_OP 0x0200 /* negotiate request */
|
|
|
|
#define CIFS_CP_CREATE_CLOSE_OP 0x0400 /* compound create+close request */
|
2021-02-04 06:49:52 +00:00
|
|
|
/* Lower bitmask values are reserved by others below. */
|
2021-03-08 15:00:50 +00:00
|
|
|
#define CIFS_SESS_OP 0x2000 /* session setup request */
|
|
|
|
#define CIFS_OP_MASK 0x2780 /* mask request type */
|
2016-10-31 20:49:30 +00:00
|
|
|
|
2021-03-08 15:00:50 +00:00
|
|
|
#define CIFS_HAS_CREDITS 0x0400 /* already has credits */
|
|
|
|
#define CIFS_TRANSFORM_REQ 0x0800 /* transform request before sending */
|
|
|
|
#define CIFS_NO_SRV_RSP 0x1000 /* there is no server response */
|
2012-05-23 12:14:34 +00:00
|
|
|
|
2006-05-31 22:40:51 +00:00
|
|
|
/* Security Flags: indicate type of session setup needed */
|
|
|
|
#define CIFSSEC_MAY_SIGN 0x00001
|
|
|
|
#define CIFSSEC_MAY_NTLMV2 0x00004
|
|
|
|
#define CIFSSEC_MAY_KRB5 0x00008
|
|
|
|
#define CIFSSEC_MAY_SEAL 0x00040 /* not supported yet */
|
2009-05-06 04:16:04 +00:00
|
|
|
#define CIFSSEC_MAY_NTLMSSP 0x00080 /* raw ntlmssp with ntlmv2 */
|
2006-05-31 22:40:51 +00:00
|
|
|
|
|
|
|
#define CIFSSEC_MUST_SIGN 0x01001
|
|
|
|
/* note that only one of the following can be set so the
|
|
|
|
result of setting MUST flags more than once will be to
|
|
|
|
require use of the stronger protocol */
|
|
|
|
#define CIFSSEC_MUST_NTLMV2 0x04004
|
|
|
|
#define CIFSSEC_MUST_KRB5 0x08008
|
2007-10-16 17:32:19 +00:00
|
|
|
#ifdef CONFIG_CIFS_UPCALL
|
2009-05-06 04:16:04 +00:00
|
|
|
#define CIFSSEC_MASK 0x8F08F /* flags supported if no weak allowed */
|
2007-06-28 19:44:13 +00:00
|
|
|
#else
|
2009-05-06 04:16:04 +00:00
|
|
|
#define CIFSSEC_MASK 0x87087 /* flags supported if no weak allowed */
|
2007-10-16 18:10:10 +00:00
|
|
|
#endif /* UPCALL */
|
2006-05-31 22:40:51 +00:00
|
|
|
#define CIFSSEC_MUST_SEAL 0x40040 /* not supported yet */
|
2009-05-06 04:16:04 +00:00
|
|
|
#define CIFSSEC_MUST_NTLMSSP 0x80080 /* raw ntlmssp with ntlmv2 */
|
2006-05-31 22:40:51 +00:00
|
|
|
|
2013-05-26 11:01:01 +00:00
|
|
|
#define CIFSSEC_DEF (CIFSSEC_MAY_SIGN | CIFSSEC_MAY_NTLMV2 | CIFSSEC_MAY_NTLMSSP)
|
2021-08-19 10:34:58 +00:00
|
|
|
#define CIFSSEC_MAX (CIFSSEC_MUST_NTLMV2)
|
|
|
|
#define CIFSSEC_AUTH_MASK (CIFSSEC_MAY_NTLMV2 | CIFSSEC_MAY_KRB5 | CIFSSEC_MAY_NTLMSSP)
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
*****************************************************************
|
|
|
|
* All constants go here
|
|
|
|
*****************************************************************
|
|
|
|
*/
|
|
|
|
|
|
|
|
#define UID_HASH (16)
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Note that ONE module should define _DECLARE_GLOBALS_HERE to cause the
|
|
|
|
* following to be declared.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/****************************************************************************
|
|
|
|
* Locking notes. All updates to global variables and lists should be
|
|
|
|
* protected by spinlocks or semaphores.
|
|
|
|
*
|
|
|
|
* Spinlocks
|
|
|
|
* ---------
|
|
|
|
* GlobalMid_Lock protects:
|
|
|
|
* list operations on pending_mid_q and oplockQ
|
|
|
|
* updates to XID counters, multiplex id and SMB sequence numbers
|
2019-03-13 23:21:38 +00:00
|
|
|
* list operations on global DnotifyReqList
|
2021-07-01 17:22:47 +00:00
|
|
|
* updates to ses->status and TCP_Server_Info->tcpStatus
|
2021-06-25 18:54:32 +00:00
|
|
|
* updates to server->CurrentMid
|
2016-09-22 23:58:16 +00:00
|
|
|
* tcp_ses_lock protects:
|
|
|
|
* list operations on tcp and SMB session lists
|
|
|
|
* tcon->open_file_lock protects the list of open files hanging off the tcon
|
2019-06-05 00:38:38 +00:00
|
|
|
* inode->open_file_lock protects the openFileList hanging off the inode
|
2016-09-22 23:58:16 +00:00
|
|
|
* cfile->file_info_lock protects counters and fields in cifs file struct
|
2005-04-16 22:20:36 +00:00
|
|
|
* f_owner.lock protects certain per file struct operations
|
|
|
|
* mapping->page_lock protects certain per page operations
|
|
|
|
*
|
2019-06-05 00:38:38 +00:00
|
|
|
* Note that the cifs_tcon.open_file_lock should be taken before
|
|
|
|
* not after the cifsInodeInfo.open_file_lock
|
|
|
|
*
|
2005-04-16 22:20:36 +00:00
|
|
|
* Semaphores
|
|
|
|
* ----------
|
2021-04-09 19:49:15 +00:00
|
|
|
* cifsInodeInfo->lock_sem protects:
|
|
|
|
* the list of locks held by the inode
|
2005-04-16 22:20:36 +00:00
|
|
|
*
|
|
|
|
****************************************************************************/
|
|
|
|
|
|
|
|
#ifdef DECLARE_GLOBALS_HERE
|
|
|
|
#define GLOBAL_EXTERN
|
|
|
|
#else
|
|
|
|
#define GLOBAL_EXTERN extern
|
|
|
|
#endif
|
|
|
|
|
2008-11-14 18:44:38 +00:00
|
|
|
/*
|
|
|
|
* the list of TCP_Server_Info structures, ie each of the sockets
|
2008-11-13 20:04:07 +00:00
|
|
|
* connecting our client to a distinct server (ip address), is
|
2008-11-14 18:44:38 +00:00
|
|
|
* chained together by cifs_tcp_ses_list. The list of all our SMB
|
2008-11-13 20:04:07 +00:00
|
|
|
* sessions (and from that the tree connections) can be found
|
2008-11-14 18:44:38 +00:00
|
|
|
* by iterating over cifs_tcp_ses_list
|
|
|
|
*/
|
|
|
|
GLOBAL_EXTERN struct list_head cifs_tcp_ses_list;
|
|
|
|
|
2008-11-15 16:12:47 +00:00
|
|
|
/*
|
|
|
|
* This lock protects the cifs_tcp_ses_list, the list of smb sessions per
|
|
|
|
* tcp session, and the list of tcon's per smb session. It also protects
|
2020-04-22 04:51:18 +00:00
|
|
|
* the reference counters for the server, smb session, and tcon. It also
|
|
|
|
* protects some fields in the TCP_Server_Info struct such as dstaddr. Finally,
|
2008-11-15 16:12:47 +00:00
|
|
|
* changes to the tcon->tidStatus should be done while holding this lock.
|
2016-09-22 23:58:16 +00:00
|
|
|
* generally the locks should be taken in order tcp_ses_lock before
|
|
|
|
* tcon->open_file_lock and that before file->file_info_lock since the
|
|
|
|
* structure order is cifs_socket-->cifs_ses-->cifs_tcon-->cifs_file
|
2008-11-15 16:12:47 +00:00
|
|
|
*/
|
2010-10-18 17:59:37 +00:00
|
|
|
GLOBAL_EXTERN spinlock_t cifs_tcp_ses_lock;
|
2008-11-20 20:00:44 +00:00
|
|
|
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* Global transaction id (XID) information
|
|
|
|
*/
|
|
|
|
GLOBAL_EXTERN unsigned int GlobalCurrentXid; /* protected by GlobalMid_Sem */
|
2006-06-04 05:53:15 +00:00
|
|
|
GLOBAL_EXTERN unsigned int GlobalTotalActiveXid; /* prot by GlobalMid_Sem */
|
2005-04-16 22:20:36 +00:00
|
|
|
GLOBAL_EXTERN unsigned int GlobalMaxActiveXid; /* prot by GlobalMid_Sem */
|
2006-06-04 05:53:15 +00:00
|
|
|
GLOBAL_EXTERN spinlock_t GlobalMid_Lock; /* protects above & list operations */
|
|
|
|
/* on midQ entries */
|
2005-04-16 22:20:36 +00:00
|
|
|
/*
|
|
|
|
* Global counters, updated atomically
|
|
|
|
*/
|
|
|
|
GLOBAL_EXTERN atomic_t sesInfoAllocCount;
|
|
|
|
GLOBAL_EXTERN atomic_t tconInfoAllocCount;
|
2021-02-04 07:20:46 +00:00
|
|
|
GLOBAL_EXTERN atomic_t tcpSesNextId;
|
2005-04-16 22:20:36 +00:00
|
|
|
GLOBAL_EXTERN atomic_t tcpSesAllocCount;
|
|
|
|
GLOBAL_EXTERN atomic_t tcpSesReconnectCount;
|
|
|
|
GLOBAL_EXTERN atomic_t tconInfoReconnectCount;
|
|
|
|
|
2008-05-23 17:38:32 +00:00
|
|
|
/* Various Debug counters */
|
2005-12-03 21:58:57 +00:00
|
|
|
GLOBAL_EXTERN atomic_t bufAllocCount; /* current number allocated */
|
|
|
|
#ifdef CONFIG_CIFS_STATS2
|
|
|
|
GLOBAL_EXTERN atomic_t totBufAllocCount; /* total allocated over all time */
|
|
|
|
GLOBAL_EXTERN atomic_t totSmBufAllocCount;
|
2018-09-18 19:05:18 +00:00
|
|
|
extern unsigned int slow_rsp_threshold; /* number of secs before logging */
|
2005-12-03 21:58:57 +00:00
|
|
|
#endif
|
|
|
|
GLOBAL_EXTERN atomic_t smBufAllocCount;
|
2005-04-16 22:20:36 +00:00
|
|
|
GLOBAL_EXTERN atomic_t midCount;
|
|
|
|
|
|
|
|
/* Misc globals */
|
2018-05-24 09:11:07 +00:00
|
|
|
extern bool enable_oplocks; /* enable or disable oplocks */
|
|
|
|
extern bool lookupCacheEnabled;
|
|
|
|
extern unsigned int global_secflags; /* if on, session setup sent
|
2005-04-16 22:20:36 +00:00
|
|
|
with more secure ntlmssp2 challenge/resp */
|
2018-05-24 09:11:07 +00:00
|
|
|
extern unsigned int sign_CIFS_PDUs; /* enable smb packet signing */
|
2020-10-15 01:24:09 +00:00
|
|
|
extern bool enable_gcm_256; /* allow optional negotiate of strongest signing (aes-gcm-256) */
|
2020-09-11 21:19:28 +00:00
|
|
|
extern bool require_gcm_256; /* require use of strongest signing (aes-gcm-256) */
|
2021-07-05 20:05:39 +00:00
|
|
|
extern bool enable_negotiate_signing; /* request use of faster (GMAC) signing if available */
|
2018-05-24 09:11:07 +00:00
|
|
|
extern bool linuxExtEnabled;/*enable Linux/Unix CIFS extensions*/
|
|
|
|
extern unsigned int CIFSMaxBufSize; /* max size not including hdr */
|
|
|
|
extern unsigned int cifs_min_rcv; /* min size of big ntwrk buf pool */
|
|
|
|
extern unsigned int cifs_min_small; /* min size of small buf pool */
|
|
|
|
extern unsigned int cifs_max_pending; /* MAX requests at once to server*/
|
|
|
|
extern bool disable_legacy_dialects; /* forbid vers=1.0 and vers=2.0 mounts */
|
2005-04-16 22:20:36 +00:00
|
|
|
|
2010-07-20 20:09:02 +00:00
|
|
|
void cifs_oplock_break(struct work_struct *work);
|
2019-03-29 09:49:12 +00:00
|
|
|
void cifs_queue_oplock_break(struct cifsFileInfo *cfile);
|
2021-04-13 05:26:42 +00:00
|
|
|
void smb2_deferred_work_close(struct work_struct *work);
|
2010-08-07 19:42:58 +00:00
|
|
|
|
2021-04-13 05:26:42 +00:00
|
|
|
extern const struct slow_work_ops cifs_oplock_break_ops;
|
2012-03-23 18:40:53 +00:00
|
|
|
extern struct workqueue_struct *cifsiod_wq;
|
2019-09-07 06:09:49 +00:00
|
|
|
extern struct workqueue_struct *decrypt_wq;
|
cifs: move cifsFileInfo_put logic into a work-queue
This patch moves the final part of the cifsFileInfo_put() logic where we
need a write lock on lock_sem to be processed in a separate thread that
holds no other locks.
This is to prevent deadlocks like the one below:
> there are 6 processes looping to while trying to down_write
> cinode->lock_sem, 5 of them from _cifsFileInfo_put, and one from
> cifs_new_fileinfo
>
> and there are 5 other processes which are blocked, several of them
> waiting on either PG_writeback or PG_locked (which are both set), all
> for the same page of the file
>
> 2 inode_lock() (inode->i_rwsem) for the file
> 1 wait_on_page_writeback() for the page
> 1 down_read(inode->i_rwsem) for the inode of the directory
> 1 inode_lock()(inode->i_rwsem) for the inode of the directory
> 1 __lock_page
>
>
> so processes are blocked waiting on:
> page flags PG_locked and PG_writeback for one specific page
> inode->i_rwsem for the directory
> inode->i_rwsem for the file
> cifsInodeInflock_sem
>
>
>
> here are the more gory details (let me know if I need to provide
> anything more/better):
>
> [0 00:48:22.765] [UN] PID: 8863 TASK: ffff8c691547c5c0 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff9965007e3ba8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007e3c38] schedule at ffffffff9b6e64df
> #2 [ffff9965007e3c48] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965007e3cb8] legitimize_path at ffffffff9b0f975d
> #4 [ffff9965007e3d08] path_openat at ffffffff9b0fe55d
> #5 [ffff9965007e3dd8] do_filp_open at ffffffff9b100a33
> #6 [ffff9965007e3ee0] do_sys_open at ffffffff9b0eb2d6
> #7 [ffff9965007e3f38] do_syscall_64 at ffffffff9ae04315
> * (I think legitimize_path is bogus)
>
> in path_openat
> } else {
> const char *s = path_init(nd, flags);
> while (!(error = link_path_walk(s, nd)) &&
> (error = do_last(nd, file, op)) > 0) { <<<<
>
> do_last:
> if (open_flag & O_CREAT)
> inode_lock(dir->d_inode); <<<<
> else
> so it's trying to take inode->i_rwsem for the directory
>
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68bb8e79c0 ffff8c691158ef20 ffff8c6915bf9000 DIR /mnt/vm1_smb/
> inode.i_rwsem is ffff8c691158efc0
>
> <struct rw_semaphore 0xffff8c691158efc0>:
> owner: <struct task_struct 0xffff8c6914275d00> (UN - 8856 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 2
> 0xffff9965007e3c90 8863 reopen_file UN 0 1:29:22.926
> RWSEM_WAITING_FOR_WRITE
> 0xffff996500393e00 9802 ls UN 0 1:17:26.700
> RWSEM_WAITING_FOR_READ
>
>
> the owner of the inode.i_rwsem of the directory is:
>
> [0 00:00:00.109] [UN] PID: 8856 TASK: ffff8c6914275d00 CPU: 3
> COMMAND: "reopen_file"
> #0 [ffff99650065b828] __schedule at ffffffff9b6e6095
> #1 [ffff99650065b8b8] schedule at ffffffff9b6e64df
> #2 [ffff99650065b8c8] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff99650065b940] msleep at ffffffff9af573a9
> #4 [ffff99650065b948] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff99650065ba38] cifs_writepage_locked at ffffffffc0a0b8f3 [cifs]
> #6 [ffff99650065bab0] cifs_launder_page at ffffffffc0a0bb72 [cifs]
> #7 [ffff99650065bb30] invalidate_inode_pages2_range at ffffffff9b04d4bd
> #8 [ffff99650065bcb8] cifs_invalidate_mapping at ffffffffc0a11339 [cifs]
> #9 [ffff99650065bcd0] cifs_revalidate_mapping at ffffffffc0a1139a [cifs]
> #10 [ffff99650065bcf0] cifs_d_revalidate at ffffffffc0a014f6 [cifs]
> #11 [ffff99650065bd08] path_openat at ffffffff9b0fe7f7
> #12 [ffff99650065bdd8] do_filp_open at ffffffff9b100a33
> #13 [ffff99650065bee0] do_sys_open at ffffffff9b0eb2d6
> #14 [ffff99650065bf38] do_syscall_64 at ffffffff9ae04315
>
> cifs_launder_page is for page 0xffffd1e2c07d2480
>
> crash> page.index,mapping,flags 0xffffd1e2c07d2480
> index = 0x8
> mapping = 0xffff8c68f3cd0db0
> flags = 0xfffffc0008095
>
> PAGE-FLAG BIT VALUE
> PG_locked 0 0000001
> PG_uptodate 2 0000004
> PG_lru 4 0000010
> PG_waiters 7 0000080
> PG_writeback 15 0008000
>
>
> inode is ffff8c68f3cd0c40
> inode.i_rwsem is ffff8c68f3cd0ce0
> DENTRY INODE SUPERBLK TYPE PATH
> ffff8c68a1f1b480 ffff8c68f3cd0c40 ffff8c6915bf9000 REG
> /mnt/vm1_smb/testfile.8853
>
>
> this process holds the inode->i_rwsem for the parent directory, is
> laundering a page attached to the inode of the file it's opening, and in
> _cifsFileInfo_put is trying to down_write the cifsInodeInflock_sem
> for the file itself.
>
>
> <struct rw_semaphore 0xffff8c68f3cd0ce0>:
> owner: <struct task_struct 0xffff8c6914272e80> (UN - 8854 -
> reopen_file), counter: 0x0000000000000003
> waitlist: 1
> 0xffff9965005dfd80 8855 reopen_file UN 0 1:29:22.912
> RWSEM_WAITING_FOR_WRITE
>
> this is the inode.i_rwsem for the file
>
> the owner:
>
> [0 00:48:22.739] [UN] PID: 8854 TASK: ffff8c6914272e80 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff99650054fb38] __schedule at ffffffff9b6e6095
> #1 [ffff99650054fbc8] schedule at ffffffff9b6e64df
> #2 [ffff99650054fbd8] io_schedule at ffffffff9b6e68e2
> #3 [ffff99650054fbe8] __lock_page at ffffffff9b03c56f
> #4 [ffff99650054fc80] pagecache_get_page at ffffffff9b03dcdf
> #5 [ffff99650054fcc0] grab_cache_page_write_begin at ffffffff9b03ef4c
> #6 [ffff99650054fcd0] cifs_write_begin at ffffffffc0a064ec [cifs]
> #7 [ffff99650054fd30] generic_perform_write at ffffffff9b03bba4
> #8 [ffff99650054fda8] __generic_file_write_iter at ffffffff9b04060a
> #9 [ffff99650054fdf0] cifs_strict_writev.cold.70 at ffffffffc0a4469b [cifs]
> #10 [ffff99650054fe48] new_sync_write at ffffffff9b0ec1dd
> #11 [ffff99650054fed0] vfs_write at ffffffff9b0eed35
> #12 [ffff99650054ff00] ksys_write at ffffffff9b0eefd9
> #13 [ffff99650054ff38] do_syscall_64 at ffffffff9ae04315
>
> the process holds the inode->i_rwsem for the file to which it's writing,
> and is trying to __lock_page for the same page as in the other processes
>
>
> the other tasks:
> [0 00:00:00.028] [UN] PID: 8859 TASK: ffff8c6915479740 CPU: 2
> COMMAND: "reopen_file"
> #0 [ffff9965007b39d8] __schedule at ffffffff9b6e6095
> #1 [ffff9965007b3a68] schedule at ffffffff9b6e64df
> #2 [ffff9965007b3a78] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007b3af0] msleep at ffffffff9af573a9
> #4 [ffff9965007b3af8] cifs_new_fileinfo.cold.61 at ffffffffc0a42a07 [cifs]
> #5 [ffff9965007b3b78] cifs_open at ffffffffc0a0709d [cifs]
> #6 [ffff9965007b3cd8] do_dentry_open at ffffffff9b0e9b7a
> #7 [ffff9965007b3d08] path_openat at ffffffff9b0fe34f
> #8 [ffff9965007b3dd8] do_filp_open at ffffffff9b100a33
> #9 [ffff9965007b3ee0] do_sys_open at ffffffff9b0eb2d6
> #10 [ffff9965007b3f38] do_syscall_64 at ffffffff9ae04315
>
> this is opening the file, and is trying to down_write cinode->lock_sem
>
>
> [0 00:00:00.041] [UN] PID: 8860 TASK: ffff8c691547ae80 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.057] [UN] PID: 8861 TASK: ffff8c6915478000 CPU: 3
> COMMAND: "reopen_file"
> [0 00:00:00.059] [UN] PID: 8858 TASK: ffff8c6914271740 CPU: 2
> COMMAND: "reopen_file"
> [0 00:00:00.109] [UN] PID: 8862 TASK: ffff8c691547dd00 CPU: 6
> COMMAND: "reopen_file"
> #0 [ffff9965007c3c78] __schedule at ffffffff9b6e6095
> #1 [ffff9965007c3d08] schedule at ffffffff9b6e64df
> #2 [ffff9965007c3d18] schedule_timeout at ffffffff9b6e9f89
> #3 [ffff9965007c3d90] msleep at ffffffff9af573a9
> #4 [ffff9965007c3d98] _cifsFileInfo_put.cold.63 at ffffffffc0a42dd6 [cifs]
> #5 [ffff9965007c3e88] cifs_close at ffffffffc0a07aaf [cifs]
> #6 [ffff9965007c3ea0] __fput at ffffffff9b0efa6e
> #7 [ffff9965007c3ee8] task_work_run at ffffffff9aef1614
> #8 [ffff9965007c3f20] exit_to_usermode_loop at ffffffff9ae03d6f
> #9 [ffff9965007c3f38] do_syscall_64 at ffffffff9ae0444c
>
> closing the file, and trying to down_write cifsi->lock_sem
>
>
> [0 00:48:22.839] [UN] PID: 8857 TASK: ffff8c6914270000 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965006a7cc8] __schedule at ffffffff9b6e6095
> #1 [ffff9965006a7d58] schedule at ffffffff9b6e64df
> #2 [ffff9965006a7d68] io_schedule at ffffffff9b6e68e2
> #3 [ffff9965006a7d78] wait_on_page_bit at ffffffff9b03cac6
> #4 [ffff9965006a7e10] __filemap_fdatawait_range at ffffffff9b03b028
> #5 [ffff9965006a7ed8] filemap_write_and_wait at ffffffff9b040165
> #6 [ffff9965006a7ef0] cifs_flush at ffffffffc0a0c2fa [cifs]
> #7 [ffff9965006a7f10] filp_close at ffffffff9b0e93f1
> #8 [ffff9965006a7f30] __x64_sys_close at ffffffff9b0e9a0e
> #9 [ffff9965006a7f38] do_syscall_64 at ffffffff9ae04315
>
> in __filemap_fdatawait_range
> wait_on_page_writeback(page);
> for the same page of the file
>
>
>
> [0 00:48:22.718] [UN] PID: 8855 TASK: ffff8c69142745c0 CPU: 7
> COMMAND: "reopen_file"
> #0 [ffff9965005dfc98] __schedule at ffffffff9b6e6095
> #1 [ffff9965005dfd28] schedule at ffffffff9b6e64df
> #2 [ffff9965005dfd38] rwsem_down_write_slowpath at ffffffff9af283d7
> #3 [ffff9965005dfdf0] cifs_strict_writev at ffffffffc0a0c40a [cifs]
> #4 [ffff9965005dfe48] new_sync_write at ffffffff9b0ec1dd
> #5 [ffff9965005dfed0] vfs_write at ffffffff9b0eed35
> #6 [ffff9965005dff00] ksys_write at ffffffff9b0eefd9
> #7 [ffff9965005dff38] do_syscall_64 at ffffffff9ae04315
>
> inode_lock(inode);
>
>
> and one 'ls' later on, to see whether the rest of the mount is available
> (the test file is in the root, so we get blocked up on the directory
> ->i_rwsem), so the entire mount is unavailable
>
> [0 00:36:26.473] [UN] PID: 9802 TASK: ffff8c691436ae80 CPU: 4
> COMMAND: "ls"
> #0 [ffff996500393d28] __schedule at ffffffff9b6e6095
> #1 [ffff996500393db8] schedule at ffffffff9b6e64df
> #2 [ffff996500393dc8] rwsem_down_read_slowpath at ffffffff9b6e9421
> #3 [ffff996500393e78] down_read_killable at ffffffff9b6e95e2
> #4 [ffff996500393e88] iterate_dir at ffffffff9b103c56
> #5 [ffff996500393ec8] ksys_getdents64 at ffffffff9b104b0c
> #6 [ffff996500393f30] __x64_sys_getdents64 at ffffffff9b104bb6
> #7 [ffff996500393f38] do_syscall_64 at ffffffff9ae04315
>
> in iterate_dir:
> if (shared)
> res = down_read_killable(&inode->i_rwsem); <<<<
> else
> res = down_write_killable(&inode->i_rwsem);
>
Reported-by: Frank Sorenson <sorenson@redhat.com>
Reviewed-by: Pavel Shilovsky <pshilov@microsoft.com>
Signed-off-by: Ronnie Sahlberg <lsahlber@redhat.com>
Signed-off-by: Steve French <stfrench@microsoft.com>
2019-11-03 03:06:37 +00:00
|
|
|
extern struct workqueue_struct *fileinfo_put_wq;
|
2017-05-03 15:54:01 +00:00
|
|
|
extern struct workqueue_struct *cifsoplockd_wq;
|
2021-04-13 05:26:42 +00:00
|
|
|
extern struct workqueue_struct *deferredclose_wq;
|
2016-05-24 10:27:44 +00:00
|
|
|
extern __u32 cifs_lock_secret;
|
2010-06-22 15:22:50 +00:00
|
|
|
|
2011-12-26 18:53:34 +00:00
|
|
|
extern mempool_t *cifs_mid_poolp;
|
|
|
|
|
2012-05-15 16:20:51 +00:00
|
|
|
/* Operations for different SMB versions */
|
|
|
|
#define SMB1_VERSION_STRING "1.0"
|
|
|
|
extern struct smb_version_operations smb1_operations;
|
|
|
|
extern struct smb_version_values smb1_values;
|
2012-10-01 17:26:22 +00:00
|
|
|
#define SMB20_VERSION_STRING "2.0"
|
2013-09-05 12:11:28 +00:00
|
|
|
extern struct smb_version_operations smb20_operations;
|
2012-10-01 17:26:22 +00:00
|
|
|
extern struct smb_version_values smb20_values;
|
2011-02-24 18:07:19 +00:00
|
|
|
#define SMB21_VERSION_STRING "2.1"
|
|
|
|
extern struct smb_version_operations smb21_operations;
|
|
|
|
extern struct smb_version_values smb21_values;
|
2017-09-17 15:41:35 +00:00
|
|
|
#define SMBDEFAULT_VERSION_STRING "default"
|
|
|
|
extern struct smb_version_values smbdefault_values;
|
|
|
|
#define SMB3ANY_VERSION_STRING "3"
|
|
|
|
extern struct smb_version_values smb3any_values;
|
2012-10-01 17:26:22 +00:00
|
|
|
#define SMB30_VERSION_STRING "3.0"
|
2012-12-09 04:08:06 +00:00
|
|
|
extern struct smb_version_operations smb30_operations;
|
2012-10-01 17:26:22 +00:00
|
|
|
extern struct smb_version_values smb30_values;
|
2013-06-13 03:48:41 +00:00
|
|
|
#define SMB302_VERSION_STRING "3.02"
|
2018-11-17 05:03:30 +00:00
|
|
|
#define ALT_SMB302_VERSION_STRING "3.0.2"
|
2013-06-13 03:48:41 +00:00
|
|
|
/*extern struct smb_version_operations smb302_operations;*/ /* not needed yet */
|
|
|
|
extern struct smb_version_values smb302_values;
|
2014-12-18 04:52:58 +00:00
|
|
|
#define SMB311_VERSION_STRING "3.1.1"
|
2015-06-24 04:37:11 +00:00
|
|
|
#define ALT_SMB311_VERSION_STRING "3.11"
|
|
|
|
extern struct smb_version_operations smb311_operations;
|
2014-12-18 04:52:58 +00:00
|
|
|
extern struct smb_version_values smb311_values;
|
2019-11-18 20:04:08 +00:00
|
|
|
|
2020-06-09 04:42:10 +00:00
|
|
|
static inline char *get_security_type_str(enum securityEnum sectype)
|
|
|
|
{
|
|
|
|
switch (sectype) {
|
|
|
|
case RawNTLMSSP:
|
|
|
|
return "RawNTLMSSP";
|
|
|
|
case Kerberos:
|
|
|
|
return "Kerberos";
|
|
|
|
case NTLMv2:
|
|
|
|
return "NTLMv2";
|
|
|
|
default:
|
|
|
|
return "Unknown";
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-11-18 20:04:08 +00:00
|
|
|
static inline bool is_smb1_server(struct TCP_Server_Info *server)
|
|
|
|
{
|
|
|
|
return strcmp(server->vals->version_string, SMB1_VERSION_STRING) == 0;
|
|
|
|
}
|
|
|
|
|
2020-08-27 14:20:19 +00:00
|
|
|
static inline bool is_tcon_dfs(struct cifs_tcon *tcon)
|
|
|
|
{
|
|
|
|
/*
|
|
|
|
* For SMB1, see MS-CIFS 2.4.55 SMB_COM_TREE_CONNECT_ANDX (0x75) and MS-CIFS 3.3.4.4 DFS
|
|
|
|
* Subsystem Notifies That a Share Is a DFS Share.
|
|
|
|
*
|
|
|
|
* For SMB2+, see MS-SMB2 2.2.10 SMB2 TREE_CONNECT Response and MS-SMB2 3.3.4.14 Server
|
|
|
|
* Application Updates a Share.
|
|
|
|
*/
|
|
|
|
if (!tcon || !tcon->ses || !tcon->ses->server)
|
|
|
|
return false;
|
|
|
|
return is_smb1_server(tcon->ses->server) ? tcon->Flags & SMB_SHARE_IS_IN_DFS :
|
|
|
|
tcon->share_flags & (SHI1005_FLAGS_DFS | SHI1005_FLAGS_DFS_ROOT);
|
|
|
|
}
|
|
|
|
|
2010-06-22 15:22:50 +00:00
|
|
|
#endif /* _CIFS_GLOB_H */
|