1 // SPDX-License-Identifier: LGPL-2.1
4 * Copyright (c) International Business Machines Corp., 2003, 2007
5 * Author(s): Steve French (sfrench@us.ibm.com)
10 #include <linux/posix_acl_xattr.h>
11 #include <linux/slab.h>
12 #include <linux/xattr.h>
16 #include "cifsproto.h"
17 #include "cifs_debug.h"
18 #include "cifs_fs_sb.h"
19 #include "cifs_unicode.h"
20 #include "cifs_ioctl.h"
22 #define MAX_EA_VALUE_SIZE CIFSMaxBufSize
23 #define CIFS_XATTR_CIFS_ACL "system.cifs_acl" /* DACL only */
24 #define CIFS_XATTR_CIFS_NTSD "system.cifs_ntsd" /* owner plus DACL */
25 #define CIFS_XATTR_CIFS_NTSD_FULL "system.cifs_ntsd_full" /* owner/DACL/SACL */
26 #define CIFS_XATTR_ATTRIB "cifs.dosattrib" /* full name: user.cifs.dosattrib */
27 #define CIFS_XATTR_CREATETIME "cifs.creationtime" /* user.cifs.creationtime */
29 * Although these three are just aliases for the above, need to move away from
30 * confusing users and using the 20+ year old term 'cifs' when it is no longer
31 * secure, replaced by SMB2 (then even more highly secure SMB3) many years ago
33 #define SMB3_XATTR_CIFS_ACL "system.smb3_acl" /* DACL only */
34 #define SMB3_XATTR_CIFS_NTSD "system.smb3_ntsd" /* owner plus DACL */
35 #define SMB3_XATTR_CIFS_NTSD_FULL "system.smb3_ntsd_full" /* owner/DACL/SACL */
36 #define SMB3_XATTR_ATTRIB "smb3.dosattrib" /* full name: user.smb3.dosattrib */
37 #define SMB3_XATTR_CREATETIME "smb3.creationtime" /* user.smb3.creationtime */
38 /* BB need to add server (Samba e.g) support for security and trusted prefix */
40 enum { XATTR_USER
, XATTR_CIFS_ACL
, XATTR_ACL_ACCESS
, XATTR_ACL_DEFAULT
,
41 XATTR_CIFS_NTSD
, XATTR_CIFS_NTSD_FULL
};
43 static int cifs_attrib_set(unsigned int xid
, struct cifs_tcon
*pTcon
,
44 struct inode
*inode
, const char *full_path
,
45 const void *value
, size_t size
)
47 ssize_t rc
= -EOPNOTSUPP
;
48 __u32
*pattrib
= (__u32
*)value
;
50 FILE_BASIC_INFO info_buf
;
52 if ((value
== NULL
) || (size
!= sizeof(__u32
)))
55 memset(&info_buf
, 0, sizeof(info_buf
));
57 info_buf
.Attributes
= cpu_to_le32(attrib
);
58 if (pTcon
->ses
->server
->ops
->set_file_info
)
59 rc
= pTcon
->ses
->server
->ops
->set_file_info(inode
, full_path
,
62 CIFS_I(inode
)->cifsAttrs
= attrib
;
67 static int cifs_creation_time_set(unsigned int xid
, struct cifs_tcon
*pTcon
,
68 struct inode
*inode
, const char *full_path
,
69 const void *value
, size_t size
)
71 ssize_t rc
= -EOPNOTSUPP
;
72 __u64
*pcreation_time
= (__u64
*)value
;
74 FILE_BASIC_INFO info_buf
;
76 if ((value
== NULL
) || (size
!= sizeof(__u64
)))
79 memset(&info_buf
, 0, sizeof(info_buf
));
80 creation_time
= *pcreation_time
;
81 info_buf
.CreationTime
= cpu_to_le64(creation_time
);
82 if (pTcon
->ses
->server
->ops
->set_file_info
)
83 rc
= pTcon
->ses
->server
->ops
->set_file_info(inode
, full_path
,
86 CIFS_I(inode
)->createtime
= creation_time
;
91 static int cifs_xattr_set(const struct xattr_handler
*handler
,
92 struct mnt_idmap
*idmap
,
93 struct dentry
*dentry
, struct inode
*inode
,
94 const char *name
, const void *value
,
95 size_t size
, int flags
)
99 struct super_block
*sb
= dentry
->d_sb
;
100 struct cifs_sb_info
*cifs_sb
= CIFS_SB(sb
);
101 struct tcon_link
*tlink
;
102 struct cifs_tcon
*pTcon
;
103 const char *full_path
;
106 tlink
= cifs_sb_tlink(cifs_sb
);
108 return PTR_ERR(tlink
);
109 pTcon
= tlink_tcon(tlink
);
112 page
= alloc_dentry_path();
114 full_path
= build_path_from_dentry(dentry
, page
);
115 if (IS_ERR(full_path
)) {
116 rc
= PTR_ERR(full_path
);
119 /* return dos attributes as pseudo xattr */
120 /* return alt name if available as pseudo attr */
122 /* if proc/fs/cifs/streamstoxattr is set then
123 search server for EAs or streams to
125 if (size
> MAX_EA_VALUE_SIZE
) {
126 cifs_dbg(FYI
, "size of EA value too large\n");
131 switch (handler
->flags
) {
133 cifs_dbg(FYI
, "%s:setting user xattr %s\n", __func__
, name
);
134 if ((strcmp(name
, CIFS_XATTR_ATTRIB
) == 0) ||
135 (strcmp(name
, SMB3_XATTR_ATTRIB
) == 0)) {
136 rc
= cifs_attrib_set(xid
, pTcon
, inode
, full_path
,
138 if (rc
== 0) /* force revalidate of the inode */
139 CIFS_I(inode
)->time
= 0;
141 } else if ((strcmp(name
, CIFS_XATTR_CREATETIME
) == 0) ||
142 (strcmp(name
, SMB3_XATTR_CREATETIME
) == 0)) {
143 rc
= cifs_creation_time_set(xid
, pTcon
, inode
,
144 full_path
, value
, size
);
145 if (rc
== 0) /* force revalidate of the inode */
146 CIFS_I(inode
)->time
= 0;
150 if (cifs_sb
->mnt_cifs_flags
& CIFS_MOUNT_NO_XATTR
)
153 if (pTcon
->ses
->server
->ops
->set_EA
)
154 rc
= pTcon
->ses
->server
->ops
->set_EA(xid
, pTcon
,
155 full_path
, name
, value
, (__u16
)size
,
156 cifs_sb
->local_nls
, cifs_sb
);
160 case XATTR_CIFS_NTSD
:
161 case XATTR_CIFS_NTSD_FULL
: {
162 struct cifs_ntsd
*pacl
;
166 pacl
= kmalloc(size
, GFP_KERNEL
);
170 memcpy(pacl
, value
, size
);
171 if (pTcon
->ses
->server
->ops
->set_acl
) {
175 switch (handler
->flags
) {
176 case XATTR_CIFS_NTSD_FULL
:
177 aclflags
= (CIFS_ACL_OWNER
|
182 case XATTR_CIFS_NTSD
:
183 aclflags
= (CIFS_ACL_OWNER
|
189 aclflags
= CIFS_ACL_DACL
;
192 rc
= pTcon
->ses
->server
->ops
->set_acl(pacl
,
193 size
, inode
, full_path
, aclflags
);
197 if (rc
== 0) /* force revalidate of the inode */
198 CIFS_I(inode
)->time
= 0;
206 free_dentry_path(page
);
208 cifs_put_tlink(tlink
);
212 static int cifs_attrib_get(struct dentry
*dentry
,
213 struct inode
*inode
, void *value
,
219 rc
= cifs_revalidate_dentry_attr(dentry
);
224 if ((value
== NULL
) || (size
== 0))
225 return sizeof(__u32
);
226 else if (size
< sizeof(__u32
))
229 /* return dos attributes as pseudo xattr */
230 pattribute
= (__u32
*)value
;
231 *pattribute
= CIFS_I(inode
)->cifsAttrs
;
233 return sizeof(__u32
);
236 static int cifs_creation_time_get(struct dentry
*dentry
, struct inode
*inode
,
237 void *value
, size_t size
)
242 rc
= cifs_revalidate_dentry_attr(dentry
);
246 if ((value
== NULL
) || (size
== 0))
247 return sizeof(__u64
);
248 else if (size
< sizeof(__u64
))
251 /* return dos attributes as pseudo xattr */
252 pcreatetime
= (__u64
*)value
;
253 *pcreatetime
= CIFS_I(inode
)->createtime
;
254 return sizeof(__u64
);
258 static int cifs_xattr_get(const struct xattr_handler
*handler
,
259 struct dentry
*dentry
, struct inode
*inode
,
260 const char *name
, void *value
, size_t size
)
262 ssize_t rc
= -EOPNOTSUPP
;
264 struct super_block
*sb
= dentry
->d_sb
;
265 struct cifs_sb_info
*cifs_sb
= CIFS_SB(sb
);
266 struct tcon_link
*tlink
;
267 struct cifs_tcon
*pTcon
;
268 const char *full_path
;
271 tlink
= cifs_sb_tlink(cifs_sb
);
273 return PTR_ERR(tlink
);
274 pTcon
= tlink_tcon(tlink
);
277 page
= alloc_dentry_path();
279 full_path
= build_path_from_dentry(dentry
, page
);
280 if (IS_ERR(full_path
)) {
281 rc
= PTR_ERR(full_path
);
285 /* return alt name if available as pseudo attr */
286 switch (handler
->flags
) {
288 cifs_dbg(FYI
, "%s:querying user xattr %s\n", __func__
, name
);
289 if ((strcmp(name
, CIFS_XATTR_ATTRIB
) == 0) ||
290 (strcmp(name
, SMB3_XATTR_ATTRIB
) == 0)) {
291 rc
= cifs_attrib_get(dentry
, inode
, value
, size
);
293 } else if ((strcmp(name
, CIFS_XATTR_CREATETIME
) == 0) ||
294 (strcmp(name
, SMB3_XATTR_CREATETIME
) == 0)) {
295 rc
= cifs_creation_time_get(dentry
, inode
, value
, size
);
299 if (cifs_sb
->mnt_cifs_flags
& CIFS_MOUNT_NO_XATTR
)
302 if (pTcon
->ses
->server
->ops
->query_all_EAs
)
303 rc
= pTcon
->ses
->server
->ops
->query_all_EAs(xid
, pTcon
,
304 full_path
, name
, value
, size
, cifs_sb
);
308 case XATTR_CIFS_NTSD
:
309 case XATTR_CIFS_NTSD_FULL
: {
311 * fetch owner, DACL, and SACL if asked for full descriptor,
312 * fetch owner and DACL otherwise
314 u32 acllen
, extra_info
;
315 struct cifs_ntsd
*pacl
;
317 if (pTcon
->ses
->server
->ops
->get_acl
== NULL
)
318 goto out
; /* rc already EOPNOTSUPP */
320 if (handler
->flags
== XATTR_CIFS_NTSD_FULL
) {
321 extra_info
= SACL_SECINFO
;
325 pacl
= pTcon
->ses
->server
->ops
->get_acl(cifs_sb
,
326 inode
, full_path
, &acllen
, extra_info
);
329 cifs_dbg(VFS
, "%s: error %zd getting sec desc\n",
336 memcpy(value
, pacl
, acllen
);
345 /* We could add an additional check for streams ie
346 if proc/fs/cifs/streamstoxattr is set then
347 search server for EAs or streams to
354 free_dentry_path(page
);
356 cifs_put_tlink(tlink
);
360 ssize_t
cifs_listxattr(struct dentry
*direntry
, char *data
, size_t buf_size
)
362 ssize_t rc
= -EOPNOTSUPP
;
364 struct cifs_sb_info
*cifs_sb
= CIFS_SB(direntry
->d_sb
);
365 struct tcon_link
*tlink
;
366 struct cifs_tcon
*pTcon
;
367 const char *full_path
;
370 if (unlikely(cifs_forced_shutdown(cifs_sb
)))
373 if (cifs_sb
->mnt_cifs_flags
& CIFS_MOUNT_NO_XATTR
)
376 tlink
= cifs_sb_tlink(cifs_sb
);
378 return PTR_ERR(tlink
);
379 pTcon
= tlink_tcon(tlink
);
382 page
= alloc_dentry_path();
384 full_path
= build_path_from_dentry(direntry
, page
);
385 if (IS_ERR(full_path
)) {
386 rc
= PTR_ERR(full_path
);
389 /* return dos attributes as pseudo xattr */
390 /* return alt name if available as pseudo attr */
392 /* if proc/fs/cifs/streamstoxattr is set then
393 search server for EAs or streams to
396 if (pTcon
->ses
->server
->ops
->query_all_EAs
)
397 rc
= pTcon
->ses
->server
->ops
->query_all_EAs(xid
, pTcon
,
398 full_path
, NULL
, data
, buf_size
, cifs_sb
);
400 free_dentry_path(page
);
402 cifs_put_tlink(tlink
);
406 static const struct xattr_handler cifs_user_xattr_handler
= {
407 .prefix
= XATTR_USER_PREFIX
,
409 .get
= cifs_xattr_get
,
410 .set
= cifs_xattr_set
,
413 /* os2.* attributes are treated like user.* attributes */
414 static const struct xattr_handler cifs_os2_xattr_handler
= {
415 .prefix
= XATTR_OS2_PREFIX
,
417 .get
= cifs_xattr_get
,
418 .set
= cifs_xattr_set
,
421 static const struct xattr_handler cifs_cifs_acl_xattr_handler
= {
422 .name
= CIFS_XATTR_CIFS_ACL
,
423 .flags
= XATTR_CIFS_ACL
,
424 .get
= cifs_xattr_get
,
425 .set
= cifs_xattr_set
,
429 * Although this is just an alias for the above, need to move away from
430 * confusing users and using the 20 year old term 'cifs' when it is no
431 * longer secure and was replaced by SMB2/SMB3 a long time ago, and
432 * SMB3 and later are highly secure.
434 static const struct xattr_handler smb3_acl_xattr_handler
= {
435 .name
= SMB3_XATTR_CIFS_ACL
,
436 .flags
= XATTR_CIFS_ACL
,
437 .get
= cifs_xattr_get
,
438 .set
= cifs_xattr_set
,
441 static const struct xattr_handler cifs_cifs_ntsd_xattr_handler
= {
442 .name
= CIFS_XATTR_CIFS_NTSD
,
443 .flags
= XATTR_CIFS_NTSD
,
444 .get
= cifs_xattr_get
,
445 .set
= cifs_xattr_set
,
449 * Although this is just an alias for the above, need to move away from
450 * confusing users and using the 20 year old term 'cifs' when it is no
451 * longer secure and was replaced by SMB2/SMB3 a long time ago, and
452 * SMB3 and later are highly secure.
454 static const struct xattr_handler smb3_ntsd_xattr_handler
= {
455 .name
= SMB3_XATTR_CIFS_NTSD
,
456 .flags
= XATTR_CIFS_NTSD
,
457 .get
= cifs_xattr_get
,
458 .set
= cifs_xattr_set
,
461 static const struct xattr_handler cifs_cifs_ntsd_full_xattr_handler
= {
462 .name
= CIFS_XATTR_CIFS_NTSD_FULL
,
463 .flags
= XATTR_CIFS_NTSD_FULL
,
464 .get
= cifs_xattr_get
,
465 .set
= cifs_xattr_set
,
469 * Although this is just an alias for the above, need to move away from
470 * confusing users and using the 20 year old term 'cifs' when it is no
471 * longer secure and was replaced by SMB2/SMB3 a long time ago, and
472 * SMB3 and later are highly secure.
474 static const struct xattr_handler smb3_ntsd_full_xattr_handler
= {
475 .name
= SMB3_XATTR_CIFS_NTSD_FULL
,
476 .flags
= XATTR_CIFS_NTSD_FULL
,
477 .get
= cifs_xattr_get
,
478 .set
= cifs_xattr_set
,
481 const struct xattr_handler
*cifs_xattr_handlers
[] = {
482 &cifs_user_xattr_handler
,
483 &cifs_os2_xattr_handler
,
484 &cifs_cifs_acl_xattr_handler
,
485 &smb3_acl_xattr_handler
, /* alias for above since avoiding "cifs" */
486 &cifs_cifs_ntsd_xattr_handler
,
487 &smb3_ntsd_xattr_handler
, /* alias for above since avoiding "cifs" */
488 &cifs_cifs_ntsd_full_xattr_handler
,
489 &smb3_ntsd_full_xattr_handler
, /* alias for above since avoiding "cifs" */