Whamcloud - gitweb
aa0c25cb4a50c99e85d5a4097ee1bc464e9d3718
[fs/lustre-release.git] / lustre / mdt / mdt_lib.c
1 /*
2  * GPL HEADER START
3  *
4  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License version 2 only,
8  * as published by the Free Software Foundation.
9  *
10  * This program is distributed in the hope that it will be useful, but
11  * WITHOUT ANY WARRANTY; without even the implied warranty of
12  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
13  * General Public License version 2 for more details (a copy is included
14  * in the LICENSE file that accompanied this code).
15  *
16  * You should have received a copy of the GNU General Public License
17  * version 2 along with this program; If not, see
18  * http://www.gnu.org/licenses/gpl-2.0.html
19  *
20  * GPL HEADER END
21  */
22 /*
23  * Copyright (c) 2007, 2010, Oracle and/or its affiliates. All rights reserved.
24  * Use is subject to license terms.
25  *
26  * Copyright (c) 2011, 2017, Intel Corporation.
27  */
28 /*
29  * This file is part of Lustre, http://www.lustre.org/
30  * Lustre is a trademark of Sun Microsystems, Inc.
31  *
32  * lustre/mdt/mdt_lib.c
33  *
34  * Lustre Metadata Target (mdt) request unpacking helper.
35  *
36  * Author: Peter Braam <braam@clusterfs.com>
37  * Author: Andreas Dilger <adilger@clusterfs.com>
38  * Author: Phil Schwan <phil@clusterfs.com>
39  * Author: Mike Shaver <shaver@clusterfs.com>
40  * Author: Nikita Danilov <nikita@clusterfs.com>
41  * Author: Huang Hua <huanghua@clusterfs.com>
42  * Author: Fan Yong <fanyong@clusterfs.com>
43  */
44
45 #define DEBUG_SUBSYSTEM S_MDS
46
47 #include <linux/user_namespace.h>
48 #ifdef HAVE_UIDGID_HEADER
49 # include <linux/uidgid.h>
50 #endif
51 #include "mdt_internal.h"
52 #include <uapi/linux/lnet/nidstr.h>
53 #include <lustre_nodemap.h>
54
55 typedef enum ucred_init_type {
56         NONE_INIT       = 0,
57         BODY_INIT       = 1,
58         REC_INIT        = 2
59 } ucred_init_type_t;
60
61 static __u64 get_mrc_cr_flags(struct mdt_rec_create *mrc)
62 {
63         return (__u64)(mrc->cr_flags_l) | ((__u64)mrc->cr_flags_h << 32);
64 }
65
66 void mdt_exit_ucred(struct mdt_thread_info *info)
67 {
68         struct lu_ucred   *uc  = mdt_ucred(info);
69         struct mdt_device *mdt = info->mti_mdt;
70
71         LASSERT(uc != NULL);
72         if (uc->uc_valid != UCRED_INIT) {
73                 uc->uc_suppgids[0] = uc->uc_suppgids[1] = -1;
74                 if (uc->uc_ginfo) {
75                         put_group_info(uc->uc_ginfo);
76                         uc->uc_ginfo = NULL;
77                 }
78                 if (uc->uc_identity) {
79                         mdt_identity_put(mdt->mdt_identity_cache,
80                                          uc->uc_identity);
81                         uc->uc_identity = NULL;
82                 }
83                 uc->uc_valid = UCRED_INIT;
84         }
85 }
86
87 static int match_nosquash_list(struct rw_semaphore *sem,
88                                struct list_head *nidlist,
89                                lnet_nid_t peernid)
90 {
91         int rc;
92         ENTRY;
93         down_read(sem);
94         rc = cfs_match_nid(peernid, nidlist);
95         up_read(sem);
96         RETURN(rc);
97 }
98
99 /* root_squash for inter-MDS operations */
100 static int mdt_root_squash(struct mdt_thread_info *info, lnet_nid_t peernid)
101 {
102         struct lu_ucred *ucred = mdt_ucred(info);
103         struct root_squash_info *squash = &info->mti_mdt->mdt_squash;
104         ENTRY;
105
106         LASSERT(ucred != NULL);
107         if (!squash->rsi_uid || ucred->uc_fsuid)
108                 RETURN(0);
109
110         if (match_nosquash_list(&squash->rsi_sem,
111                                 &squash->rsi_nosquash_nids,
112                                 peernid)) {
113                 CDEBUG(D_OTHER, "%s is in nosquash_nids list\n",
114                        libcfs_nid2str(peernid));
115                 RETURN(0);
116         }
117
118         CDEBUG(D_OTHER, "squash req from %s, (%d:%d/%x)=>(%d:%d/%x)\n",
119                libcfs_nid2str(peernid),
120                ucred->uc_fsuid, ucred->uc_fsgid, ucred->uc_cap,
121                squash->rsi_uid, squash->rsi_gid, 0);
122
123         ucred->uc_fsuid = squash->rsi_uid;
124         ucred->uc_fsgid = squash->rsi_gid;
125         ucred->uc_cap = 0;
126         ucred->uc_suppgids[0] = -1;
127         ucred->uc_suppgids[1] = -1;
128
129         RETURN(0);
130 }
131
132 static void ucred_set_jobid(struct mdt_thread_info *info, struct lu_ucred *uc)
133 {
134         struct ptlrpc_request   *req = mdt_info_req(info);
135         const char              *jobid = mdt_req_get_jobid(req);
136
137         /* set jobid if specified. */
138         if (jobid)
139                 strlcpy(uc->uc_jobid, jobid, sizeof(uc->uc_jobid));
140         else
141                 uc->uc_jobid[0] = '\0';
142 }
143
144 static void ucred_set_nid(struct mdt_thread_info *info, struct lu_ucred *uc)
145 {
146         if (info && info->mti_exp && info->mti_exp->exp_connection)
147                 uc->uc_nid = info->mti_exp->exp_connection->c_peer.nid;
148         else
149                 uc->uc_nid = LNET_NID_ANY;
150 }
151
152 static void ucred_set_audit_enabled(struct mdt_thread_info *info,
153                                     struct lu_ucred *uc)
154 {
155         struct lu_nodemap *nodemap = NULL;
156         bool audit = true;
157
158         if (info && info->mti_exp) {
159                 nodemap = nodemap_get_from_exp(info->mti_exp);
160                 if (nodemap && !IS_ERR(nodemap)) {
161                         audit = nodemap->nmf_enable_audit;
162                         nodemap_putref(nodemap);
163                 }
164         }
165
166         uc->uc_enable_audit = audit;
167 }
168
169 static int new_init_ucred(struct mdt_thread_info *info, ucred_init_type_t type,
170                           void *buf, bool drop_fs_cap)
171 {
172         struct ptlrpc_request *req = mdt_info_req(info);
173         struct mdt_device *mdt = info->mti_mdt;
174         struct ptlrpc_user_desc *pud = req->rq_user_desc;
175         struct lu_ucred *ucred = mdt_ucred(info);
176         struct lu_nodemap *nodemap;
177         lnet_nid_t peernid = req->rq_peer.nid;
178         __u32 perm = 0;
179         int setuid;
180         int setgid;
181         int rc = 0;
182
183         ENTRY;
184
185         LASSERT(req->rq_auth_gss);
186         LASSERT(!req->rq_auth_usr_mdt);
187         LASSERT(req->rq_user_desc);
188         LASSERT(ucred != NULL);
189
190         ucred->uc_valid = UCRED_INVALID;
191
192         nodemap = nodemap_get_from_exp(info->mti_exp);
193         if (IS_ERR(nodemap))
194                 RETURN(PTR_ERR(nodemap));
195
196         pud->pud_uid = nodemap_map_id(nodemap, NODEMAP_UID,
197                                        NODEMAP_CLIENT_TO_FS, pud->pud_uid);
198         pud->pud_gid = nodemap_map_id(nodemap, NODEMAP_GID,
199                                        NODEMAP_CLIENT_TO_FS, pud->pud_gid);
200         pud->pud_fsuid = nodemap_map_id(nodemap, NODEMAP_UID,
201                                        NODEMAP_CLIENT_TO_FS, pud->pud_fsuid);
202         pud->pud_fsgid = nodemap_map_id(nodemap, NODEMAP_GID,
203                                        NODEMAP_CLIENT_TO_FS, pud->pud_fsgid);
204
205         ucred->uc_o_uid = pud->pud_uid;
206         ucred->uc_o_gid = pud->pud_gid;
207         ucred->uc_o_fsuid = pud->pud_fsuid;
208         ucred->uc_o_fsgid = pud->pud_fsgid;
209
210         if (nodemap && ucred->uc_o_uid == nodemap->nm_squash_uid) {
211                 /* deny access before we get identity ref */
212                 if (nodemap->nmf_deny_unknown) {
213                         nodemap_putref(nodemap);
214                         RETURN(-EACCES);
215                 }
216
217                 ucred->uc_fsuid = nodemap->nm_squash_uid;
218                 ucred->uc_fsgid = nodemap->nm_squash_gid;
219                 ucred->uc_cap = 0;
220                 ucred->uc_suppgids[0] = -1;
221                 ucred->uc_suppgids[1] = -1;
222         }
223         nodemap_putref(nodemap);
224
225         if (type == BODY_INIT) {
226                 struct mdt_body *body = (struct mdt_body *)buf;
227
228                 ucred->uc_suppgids[0] = body->mbo_suppgid;
229                 ucred->uc_suppgids[1] = -1;
230         }
231
232         if (!flvr_is_rootonly(req->rq_flvr.sf_rpc) &&
233             req->rq_auth_uid != pud->pud_uid) {
234                 CDEBUG(D_SEC, "local client %s: auth uid %u "
235                        "while client claims %u:%u/%u:%u\n",
236                        libcfs_nid2str(peernid), req->rq_auth_uid,
237                        pud->pud_uid, pud->pud_gid,
238                        pud->pud_fsuid, pud->pud_fsgid);
239                 RETURN(-EACCES);
240         }
241
242         if (is_identity_get_disabled(mdt->mdt_identity_cache)) {
243                 ucred->uc_identity = NULL;
244                 perm = CFS_SETUID_PERM | CFS_SETGID_PERM | CFS_SETGRP_PERM;
245         } else {
246                 struct md_identity *identity;
247
248                 identity = mdt_identity_get(mdt->mdt_identity_cache,
249                                             pud->pud_uid);
250                 if (IS_ERR(identity)) {
251                         if (unlikely(PTR_ERR(identity) == -EREMCHG)) {
252                                 ucred->uc_identity = NULL;
253                                 perm = CFS_SETUID_PERM | CFS_SETGID_PERM |
254                                        CFS_SETGRP_PERM;
255                         } else {
256                                 CDEBUG(D_SEC,
257                                        "Deny access without identity: uid %u\n",
258                                        pud->pud_uid);
259                                 RETURN(-EACCES);
260                         }
261                 } else {
262                         ucred->uc_identity = identity;
263                         perm = mdt_identity_get_perm(ucred->uc_identity,
264                                                      peernid);
265                 }
266         }
267
268         /* find out the setuid/setgid attempt */
269         setuid = (pud->pud_uid != pud->pud_fsuid);
270         setgid = ((pud->pud_gid != pud->pud_fsgid) ||
271                   (ucred->uc_identity &&
272                    (pud->pud_gid != ucred->uc_identity->mi_gid)));
273
274         /* check permission of setuid */
275         if (setuid && !(perm & CFS_SETUID_PERM)) {
276                 CDEBUG(D_SEC, "mdt blocked setuid attempt (%u -> %u) from %s\n",
277                        pud->pud_uid, pud->pud_fsuid, libcfs_nid2str(peernid));
278                 GOTO(out, rc = -EACCES);
279         }
280
281         /* check permission of setgid */
282         if (setgid && !(perm & CFS_SETGID_PERM)) {
283                 CDEBUG(D_SEC, "mdt blocked setgid attempt (%u:%u/%u:%u -> %u) "
284                        "from %s\n", pud->pud_uid, pud->pud_gid,
285                        pud->pud_fsuid, pud->pud_fsgid,
286                        ucred->uc_identity->mi_gid, libcfs_nid2str(peernid));
287                 GOTO(out, rc = -EACCES);
288         }
289
290         if (perm & CFS_SETGRP_PERM) {
291                 if (pud->pud_ngroups) {
292                         /* setgroups for local client */
293                         ucred->uc_ginfo = groups_alloc(pud->pud_ngroups);
294                         if (!ucred->uc_ginfo) {
295                                 CERROR("failed to alloc %d groups\n",
296                                        pud->pud_ngroups);
297                                 GOTO(out, rc = -ENOMEM);
298                         }
299
300                         lustre_groups_from_list(ucred->uc_ginfo,
301                                                 pud->pud_groups);
302                         lustre_groups_sort(ucred->uc_ginfo);
303                 } else {
304                         ucred->uc_ginfo = NULL;
305                 }
306         } else {
307                 ucred->uc_suppgids[0] = -1;
308                 ucred->uc_suppgids[1] = -1;
309                 ucred->uc_ginfo = NULL;
310         }
311
312         ucred->uc_uid = pud->pud_uid;
313         ucred->uc_gid = pud->pud_gid;
314         ucred->uc_fsuid = pud->pud_fsuid;
315         ucred->uc_fsgid = pud->pud_fsgid;
316
317         /* process root_squash here. */
318         mdt_root_squash(info, peernid);
319
320         /* remove fs privilege for non-root user. */
321         if (ucred->uc_fsuid && drop_fs_cap)
322                 ucred->uc_cap = pud->pud_cap & ~CFS_CAP_FS_MASK;
323         else
324                 ucred->uc_cap = pud->pud_cap;
325         ucred->uc_valid = UCRED_NEW;
326         ucred_set_jobid(info, ucred);
327         ucred_set_nid(info, ucred);
328         ucred_set_audit_enabled(info, ucred);
329
330         EXIT;
331
332 out:
333         if (rc) {
334                 if (ucred->uc_ginfo) {
335                         put_group_info(ucred->uc_ginfo);
336                         ucred->uc_ginfo = NULL;
337                 }
338                 if (ucred->uc_identity) {
339                         mdt_identity_put(mdt->mdt_identity_cache,
340                                          ucred->uc_identity);
341                         ucred->uc_identity = NULL;
342                 }
343         }
344
345         return rc;
346 }
347
348 /**
349  * Check whether allow the client to set supplementary group IDs or not.
350  *
351  * \param[in] info      pointer to the thread context
352  * \param[in] uc        pointer to the RPC user descriptor
353  *
354  * \retval              true if allow to set supplementary group IDs
355  * \retval              false for other cases
356  */
357 bool allow_client_chgrp(struct mdt_thread_info *info, struct lu_ucred *uc)
358 {
359         __u32 perm;
360
361         /* 1. If identity_upcall is disabled,
362          *    permit local client to do anything. */
363         if (is_identity_get_disabled(info->mti_mdt->mdt_identity_cache))
364                 return true;
365
366         /* 2. If fail to get related identities, then forbid any client to
367          *    set supplementary group IDs. */
368         if (uc->uc_identity == NULL)
369                 return false;
370
371         /* 3. Check the permission in the identities. */
372         perm = mdt_identity_get_perm(uc->uc_identity,
373                                      mdt_info_req(info)->rq_peer.nid);
374         if (perm & CFS_SETGRP_PERM)
375                 return true;
376
377         return false;
378 }
379
380 int mdt_check_ucred(struct mdt_thread_info *info)
381 {
382         struct ptlrpc_request   *req = mdt_info_req(info);
383         struct mdt_device       *mdt = info->mti_mdt;
384         struct ptlrpc_user_desc *pud = req->rq_user_desc;
385         struct lu_ucred         *ucred = mdt_ucred(info);
386         struct md_identity      *identity = NULL;
387         lnet_nid_t               peernid = req->rq_peer.nid;
388         __u32                    perm = 0;
389         int                      setuid;
390         int                      setgid;
391         int                      rc = 0;
392
393         ENTRY;
394
395         LASSERT(ucred != NULL);
396         if ((ucred->uc_valid == UCRED_OLD) || (ucred->uc_valid == UCRED_NEW))
397                 RETURN(0);
398
399         if (!req->rq_auth_gss || req->rq_auth_usr_mdt || !req->rq_user_desc)
400                 RETURN(0);
401
402         /* sanity check: if we use strong authentication, we expect the
403          * uid which client claimed is true */
404         if (!flvr_is_rootonly(req->rq_flvr.sf_rpc) &&
405             req->rq_auth_uid != pud->pud_uid) {
406                 CDEBUG(D_SEC, "local client %s: auth uid %u "
407                        "while client claims %u:%u/%u:%u\n",
408                        libcfs_nid2str(peernid), req->rq_auth_uid,
409                        pud->pud_uid, pud->pud_gid,
410                        pud->pud_fsuid, pud->pud_fsgid);
411                 RETURN(-EACCES);
412         }
413
414         if (is_identity_get_disabled(mdt->mdt_identity_cache))
415                 RETURN(0);
416
417         identity = mdt_identity_get(mdt->mdt_identity_cache, pud->pud_uid);
418         if (IS_ERR(identity)) {
419                 if (unlikely(PTR_ERR(identity) == -EREMCHG)) {
420                         RETURN(0);
421                 } else {
422                         CDEBUG(D_SEC, "Deny access without identity: uid %u\n",
423                                pud->pud_uid);
424                         RETURN(-EACCES);
425                 }
426         }
427
428         perm = mdt_identity_get_perm(identity, peernid);
429         /* find out the setuid/setgid attempt */
430         setuid = (pud->pud_uid != pud->pud_fsuid);
431         setgid = (pud->pud_gid != pud->pud_fsgid ||
432                   pud->pud_gid != identity->mi_gid);
433
434         /* check permission of setuid */
435         if (setuid && !(perm & CFS_SETUID_PERM)) {
436                 CDEBUG(D_SEC, "mdt blocked setuid attempt (%u -> %u) from %s\n",
437                        pud->pud_uid, pud->pud_fsuid, libcfs_nid2str(peernid));
438                 GOTO(out, rc = -EACCES);
439         }
440
441         /* check permission of setgid */
442         if (setgid && !(perm & CFS_SETGID_PERM)) {
443                 CDEBUG(D_SEC, "mdt blocked setgid attempt (%u:%u/%u:%u -> %u) "
444                        "from %s\n", pud->pud_uid, pud->pud_gid,
445                        pud->pud_fsuid, pud->pud_fsgid, identity->mi_gid,
446                        libcfs_nid2str(peernid));
447                 GOTO(out, rc = -EACCES);
448         }
449
450         EXIT;
451
452 out:
453         mdt_identity_put(mdt->mdt_identity_cache, identity);
454         return rc;
455 }
456
457 static int old_init_ucred_common(struct mdt_thread_info *info,
458                                  struct lu_nodemap *nodemap,
459                                  bool drop_fs_cap)
460 {
461         struct lu_ucred         *uc = mdt_ucred(info);
462         struct mdt_device       *mdt = info->mti_mdt;
463         struct md_identity      *identity = NULL;
464
465         if (nodemap && uc->uc_o_uid == nodemap->nm_squash_uid) {
466                 /* deny access before we get identity ref */
467                 if (nodemap->nmf_deny_unknown)
468                         RETURN(-EACCES);
469
470                 uc->uc_fsuid = nodemap->nm_squash_uid;
471                 uc->uc_fsgid = nodemap->nm_squash_gid;
472                 uc->uc_cap = 0;
473                 uc->uc_suppgids[0] = -1;
474                 uc->uc_suppgids[1] = -1;
475         }
476
477         if (!is_identity_get_disabled(mdt->mdt_identity_cache)) {
478                 identity = mdt_identity_get(mdt->mdt_identity_cache,
479                                             uc->uc_fsuid);
480                 if (IS_ERR(identity)) {
481                         if (unlikely(PTR_ERR(identity) == -EREMCHG ||
482                                      uc->uc_cap & CFS_CAP_FS_MASK)) {
483                                 identity = NULL;
484                         } else {
485                                 CDEBUG(D_SEC, "Deny access without identity: "
486                                        "uid %u\n", uc->uc_fsuid);
487                                 RETURN(-EACCES);
488                         }
489                 }
490         }
491         uc->uc_identity = identity;
492
493         /* process root_squash here. */
494         mdt_root_squash(info, mdt_info_req(info)->rq_peer.nid);
495
496         /* remove fs privilege for non-root user. */
497         if (uc->uc_fsuid && drop_fs_cap)
498                 uc->uc_cap &= ~CFS_CAP_FS_MASK;
499         uc->uc_valid = UCRED_OLD;
500         ucred_set_jobid(info, uc);
501         ucred_set_nid(info, uc);
502         ucred_set_audit_enabled(info, uc);
503
504         EXIT;
505
506         return 0;
507 }
508
509 static int old_init_ucred(struct mdt_thread_info *info,
510                           struct mdt_body *body, bool drop_fs_cap)
511 {
512         struct lu_ucred *uc = mdt_ucred(info);
513         struct lu_nodemap *nodemap;
514         int rc;
515         ENTRY;
516
517         nodemap = nodemap_get_from_exp(info->mti_exp);
518         if (IS_ERR(nodemap))
519                 RETURN(PTR_ERR(nodemap));
520
521         body->mbo_uid = nodemap_map_id(nodemap, NODEMAP_UID,
522                                        NODEMAP_CLIENT_TO_FS, body->mbo_uid);
523         body->mbo_gid = nodemap_map_id(nodemap, NODEMAP_GID,
524                                        NODEMAP_CLIENT_TO_FS, body->mbo_gid);
525         body->mbo_fsuid = nodemap_map_id(nodemap, NODEMAP_UID,
526                                        NODEMAP_CLIENT_TO_FS, body->mbo_fsuid);
527         body->mbo_fsgid = nodemap_map_id(nodemap, NODEMAP_GID,
528                                        NODEMAP_CLIENT_TO_FS, body->mbo_fsgid);
529
530         LASSERT(uc != NULL);
531         uc->uc_valid = UCRED_INVALID;
532         uc->uc_o_uid = uc->uc_uid = body->mbo_uid;
533         uc->uc_o_gid = uc->uc_gid = body->mbo_gid;
534         uc->uc_o_fsuid = uc->uc_fsuid = body->mbo_fsuid;
535         uc->uc_o_fsgid = uc->uc_fsgid = body->mbo_fsgid;
536         uc->uc_suppgids[0] = body->mbo_suppgid;
537         uc->uc_suppgids[1] = -1;
538         uc->uc_ginfo = NULL;
539         uc->uc_cap = body->mbo_capability;
540
541         rc = old_init_ucred_common(info, nodemap, drop_fs_cap);
542         nodemap_putref(nodemap);
543
544         RETURN(rc);
545 }
546
547 static int old_init_ucred_reint(struct mdt_thread_info *info)
548 {
549         struct lu_ucred *uc = mdt_ucred(info);
550         struct lu_nodemap *nodemap;
551         int rc;
552         ENTRY;
553
554         nodemap = nodemap_get_from_exp(info->mti_exp);
555         if (IS_ERR(nodemap))
556                 RETURN(PTR_ERR(nodemap));
557
558         LASSERT(uc != NULL);
559
560         uc->uc_fsuid = nodemap_map_id(nodemap, NODEMAP_UID,
561                                       NODEMAP_CLIENT_TO_FS, uc->uc_fsuid);
562         uc->uc_fsgid = nodemap_map_id(nodemap, NODEMAP_GID,
563                                       NODEMAP_CLIENT_TO_FS, uc->uc_fsgid);
564
565         uc->uc_valid = UCRED_INVALID;
566         uc->uc_o_uid = uc->uc_o_fsuid = uc->uc_uid = uc->uc_fsuid;
567         uc->uc_o_gid = uc->uc_o_fsgid = uc->uc_gid = uc->uc_fsgid;
568         uc->uc_ginfo = NULL;
569
570         rc = old_init_ucred_common(info, nodemap, true); /* drop_fs_cap=true */
571         nodemap_putref(nodemap);
572
573         RETURN(rc);
574 }
575
576 static inline int __mdt_init_ucred(struct mdt_thread_info *info,
577                                    struct mdt_body *body,
578                                    bool drop_fs_cap)
579 {
580         struct ptlrpc_request   *req = mdt_info_req(info);
581         struct lu_ucred         *uc  = mdt_ucred(info);
582
583         LASSERT(uc != NULL);
584         if ((uc->uc_valid == UCRED_OLD) || (uc->uc_valid == UCRED_NEW))
585                 return 0;
586
587         mdt_exit_ucred(info);
588
589         if (!req->rq_auth_gss || req->rq_auth_usr_mdt || !req->rq_user_desc)
590                 return old_init_ucred(info, body, drop_fs_cap);
591         else
592                 return new_init_ucred(info, BODY_INIT, body, drop_fs_cap);
593 }
594
595 int mdt_init_ucred(struct mdt_thread_info *info, struct mdt_body *body)
596 {
597         return __mdt_init_ucred(info, body, true);
598 }
599
600 /* LU-6528 when "no_subtree_check" is set for NFS export, nfsd_set_fh_dentry()
601  * doesn't set correct fsuid explicitely, but raise capability to allow
602  * exportfs_decode_fh() to reconnect disconnected dentry into dcache. So for
603  * lookup (i.e. intent_getattr), we should keep FS capability, otherwise it
604  * will fail permission check. */
605 int mdt_init_ucred_intent_getattr(struct mdt_thread_info *info,
606                                   struct mdt_body *body)
607 {
608         return __mdt_init_ucred(info, body, false);
609 }
610
611 int mdt_init_ucred_reint(struct mdt_thread_info *info)
612 {
613         struct ptlrpc_request *req = mdt_info_req(info);
614         struct lu_ucred       *uc  = mdt_ucred(info);
615         struct md_attr        *ma  = &info->mti_attr;
616
617         LASSERT(uc != NULL);
618         if ((uc->uc_valid == UCRED_OLD) || (uc->uc_valid == UCRED_NEW))
619                 return 0;
620
621         /* LU-5564: for normal close request, skip permission check */
622         if (lustre_msg_get_opc(req->rq_reqmsg) == MDS_CLOSE &&
623             !(ma->ma_attr_flags & (MDS_HSM_RELEASE | MDS_CLOSE_LAYOUT_SWAP)))
624                 uc->uc_cap |= CFS_CAP_FS_MASK;
625
626         mdt_exit_ucred(info);
627
628         if (!req->rq_auth_gss || req->rq_auth_usr_mdt || !req->rq_user_desc)
629                 return old_init_ucred_reint(info);
630         else
631                 return new_init_ucred(info, REC_INIT, NULL, true);
632 }
633
634 /* copied from lov/lov_ea.c, just for debugging, will be removed later */
635 void mdt_dump_lmm(int level, const struct lov_mds_md *lmm, __u64 valid)
636 {
637         const struct lov_ost_data_v1 *lod;
638         __u32 lmm_magic = le32_to_cpu(lmm->lmm_magic);
639         __u16 count;
640         int i;
641
642         if (likely(!cfs_cdebug_show(level, DEBUG_SUBSYSTEM)))
643                 return;
644
645         CDEBUG(level, "objid "DOSTID", magic 0x%08X, pattern %#X\n",
646                POSTID(&lmm->lmm_oi), lmm_magic,
647                le32_to_cpu(lmm->lmm_pattern));
648
649         /* No support for compount layouts yet */
650         if (lmm_magic != LOV_MAGIC_V1 && lmm_magic != LOV_MAGIC_V3)
651                 return;
652
653         count = le16_to_cpu(((struct lov_user_md *)lmm)->lmm_stripe_count);
654         CDEBUG(level, "stripe_size=0x%x, stripe_count=0x%x\n",
655                le32_to_cpu(lmm->lmm_stripe_size), count);
656
657         /* If it's a directory or a released file, then there are
658          * no actual objects to print, so bail out. */
659         if (valid & OBD_MD_FLDIREA ||
660             le32_to_cpu(lmm->lmm_pattern) & LOV_PATTERN_F_RELEASED)
661                 return;
662
663         LASSERT(count <= LOV_MAX_STRIPE_COUNT);
664         for (i = 0, lod = lmm->lmm_objects; i < count; i++, lod++) {
665                 struct ost_id oi;
666
667                 ostid_le_to_cpu(&lod->l_ost_oi, &oi);
668                 CDEBUG(level, "stripe %u idx %u subobj "DOSTID"\n",
669                        i, le32_to_cpu(lod->l_ost_idx), POSTID(&oi));
670         }
671 }
672
673 void mdt_dump_lmv(unsigned int level, const union lmv_mds_md *lmv)
674 {
675         const struct lmv_mds_md_v1 *lmm1;
676         int                        i;
677
678         if (likely(!cfs_cdebug_show(level, DEBUG_SUBSYSTEM)))
679                 return;
680
681         lmm1 = &lmv->lmv_md_v1;
682         CDEBUG(level,
683                "magic 0x%08X, master %#X stripe_count %#x hash_type %#x\n",
684                le32_to_cpu(lmm1->lmv_magic),
685                le32_to_cpu(lmm1->lmv_master_mdt_index),
686                le32_to_cpu(lmm1->lmv_stripe_count),
687                le32_to_cpu(lmm1->lmv_hash_type));
688
689         if (le32_to_cpu(lmm1->lmv_magic) == LMV_MAGIC_STRIPE)
690                 return;
691
692         for (i = 0; i < le32_to_cpu(lmm1->lmv_stripe_count); i++) {
693                 struct lu_fid fid;
694
695                 fid_le_to_cpu(&fid, &lmm1->lmv_stripe_fids[i]);
696                 CDEBUG(level, "idx %u subobj "DFID"\n", i, PFID(&fid));
697         }
698 }
699
700 /* Shrink and/or grow reply buffers */
701 int mdt_fix_reply(struct mdt_thread_info *info)
702 {
703         struct req_capsule *pill = info->mti_pill;
704         struct mdt_body    *body;
705         int                md_size, md_packed = 0;
706         int                acl_size;
707         int                rc = 0;
708         ENTRY;
709
710         body = req_capsule_server_get(pill, &RMF_MDT_BODY);
711         LASSERT(body != NULL);
712
713         if (body->mbo_valid & (OBD_MD_FLDIREA | OBD_MD_FLEASIZE |
714                                OBD_MD_LINKNAME))
715                 md_size = body->mbo_eadatasize;
716         else
717                 md_size = 0;
718
719         acl_size = body->mbo_aclsize;
720
721         /* this replay - not send info to client */
722         if (info->mti_spec.no_create) {
723                 md_size = 0;
724                 acl_size = 0;
725         }
726
727         CDEBUG(D_INFO, "Shrink to md_size = %d cookie/acl_size = %d\n",
728                md_size, acl_size);
729 /*
730             &RMF_MDT_BODY,
731             &RMF_MDT_MD,
732             &RMF_ACL, or &RMF_LOGCOOKIES
733 (optional)  &RMF_CAPA1,
734 (optional)  &RMF_CAPA2,
735 (optional)  something else
736 */
737
738         /* MDT_MD buffer may be bigger than packed value, let's shrink all
739          * buffers before growing it */
740         if (info->mti_big_lmm_used) {
741                 /* big_lmm buffer may be used even without packing the result
742                  * into reply, just for internal server needs */
743                 if (req_capsule_has_field(pill, &RMF_MDT_MD, RCL_SERVER))
744                         md_packed = req_capsule_get_size(pill, &RMF_MDT_MD,
745                                                          RCL_SERVER);
746
747                 /* free big lmm if md_size is not needed */
748                 if (md_size == 0 || md_packed == 0) {
749                         info->mti_big_lmm_used = 0;
750                 } else {
751                         /* buffer must be allocated separately */
752                         LASSERT(info->mti_attr.ma_lmm !=
753                                 req_capsule_server_get(pill, &RMF_MDT_MD));
754                         req_capsule_shrink(pill, &RMF_MDT_MD, 0, RCL_SERVER);
755                 }
756         } else if (req_capsule_has_field(pill, &RMF_MDT_MD, RCL_SERVER)) {
757                 req_capsule_shrink(pill, &RMF_MDT_MD, md_size, RCL_SERVER);
758         }
759
760         if (info->mti_big_acl_used) {
761                 if (acl_size == 0)
762                         info->mti_big_acl_used = 0;
763                 else
764                         req_capsule_shrink(pill, &RMF_ACL, 0, RCL_SERVER);
765         } else if (req_capsule_has_field(pill, &RMF_ACL, RCL_SERVER)) {
766                 req_capsule_shrink(pill, &RMF_ACL, acl_size, RCL_SERVER);
767         } else if (req_capsule_has_field(pill, &RMF_LOGCOOKIES, RCL_SERVER)) {
768                 req_capsule_shrink(pill, &RMF_LOGCOOKIES, acl_size, RCL_SERVER);
769         }
770
771         if (req_capsule_has_field(pill, &RMF_CAPA1, RCL_SERVER) &&
772             !(body->mbo_valid & OBD_MD_FLMDSCAPA))
773                 req_capsule_shrink(pill, &RMF_CAPA1, 0, RCL_SERVER);
774
775         if (req_capsule_has_field(pill, &RMF_CAPA2, RCL_SERVER) &&
776             !(body->mbo_valid & OBD_MD_FLOSSCAPA))
777                 req_capsule_shrink(pill, &RMF_CAPA2, 0, RCL_SERVER);
778
779         /*
780          * Some more field should be shrinked if needed.
781          * This should be done by those who added fields to reply message.
782          */
783
784         /* Grow MD buffer if needed finally */
785         if (info->mti_big_lmm_used) {
786                 void *lmm;
787
788                 LASSERT(md_size > md_packed);
789                 CDEBUG(D_INFO, "Enlarge reply buffer, need extra %d bytes\n",
790                        md_size - md_packed);
791                 rc = req_capsule_server_grow(pill, &RMF_MDT_MD, md_size);
792                 if (rc) {
793                         /* we can't answer with proper LOV EA, drop flags,
794                          * the rc is also returned so this request is
795                          * considered as failed */
796                         body->mbo_valid &= ~(OBD_MD_FLDIREA | OBD_MD_FLEASIZE);
797                         /* don't return transno along with error */
798                         lustre_msg_set_transno(pill->rc_req->rq_repmsg, 0);
799                 } else {
800                         /* now we need to pack right LOV/LMV EA */
801                         lmm = req_capsule_server_get(pill, &RMF_MDT_MD);
802                         if (info->mti_attr.ma_valid & MA_LOV) {
803                                 LASSERT(req_capsule_get_size(pill, &RMF_MDT_MD,
804                                                              RCL_SERVER) ==
805                                                 info->mti_attr.ma_lmm_size);
806                                 memcpy(lmm, info->mti_attr.ma_lmm,
807                                        info->mti_attr.ma_lmm_size);
808                         } else if (info->mti_attr.ma_valid & MA_LMV) {
809                                 LASSERT(req_capsule_get_size(pill, &RMF_MDT_MD,
810                                                              RCL_SERVER) ==
811                                                 info->mti_attr.ma_lmv_size);
812                                 memcpy(lmm, info->mti_attr.ma_lmv,
813                                        info->mti_attr.ma_lmv_size);
814                         }
815                 }
816
817                 /* update mdt_max_mdsize so clients will be aware about that */
818                 if (info->mti_mdt->mdt_max_mdsize < info->mti_attr.ma_lmm_size)
819                         info->mti_mdt->mdt_max_mdsize =
820                                                 info->mti_attr.ma_lmm_size;
821                 info->mti_big_lmm_used = 0;
822         }
823
824         if (info->mti_big_acl_used) {
825                 CDEBUG(D_INFO, "Enlarge reply ACL buffer to %d bytes\n",
826                        acl_size);
827
828                 rc = req_capsule_server_grow(pill, &RMF_ACL, acl_size);
829                 if (rc) {
830                         body->mbo_valid &= ~OBD_MD_FLACL;
831                 } else {
832                         void *acl = req_capsule_server_get(pill, &RMF_ACL);
833
834                         memcpy(acl, info->mti_big_acl, acl_size);
835                 }
836
837                 info->mti_big_acl_used = 0;
838         }
839
840         RETURN(rc);
841 }
842
843
844 /* if object is dying, pack the lov/llog data,
845  * parameter info->mti_attr should be valid at this point!
846  * Also implements RAoLU policy */
847 int mdt_handle_last_unlink(struct mdt_thread_info *info, struct mdt_object *mo,
848                            struct md_attr *ma)
849 {
850         struct mdt_body *repbody = NULL;
851         const struct lu_attr *la = &ma->ma_attr;
852         struct coordinator *cdt = &info->mti_mdt->mdt_coordinator;
853         int rc;
854         __u64 need = 0;
855         struct hsm_action_item hai = {
856                 .hai_len = sizeof(hai),
857                 .hai_action = HSMA_REMOVE,
858                 .hai_extent.length = -1,
859                 .hai_cookie = 0,
860                 .hai_gid = 0,
861         };
862         __u64 compound_id;
863         int archive_id;
864
865         ENTRY;
866
867         if (mdt_info_req(info) != NULL) {
868                 repbody = req_capsule_server_get(info->mti_pill, &RMF_MDT_BODY);
869                 LASSERT(repbody != NULL);
870         } else {
871                 CDEBUG(D_INFO, "not running in a request/reply context\n");
872         }
873
874         if ((ma->ma_valid & MA_INODE) && repbody != NULL)
875                 mdt_pack_attr2body(info, repbody, la, mdt_object_fid(mo));
876
877         if (ma->ma_valid & MA_LOV) {
878                 CERROR("No need in LOV EA upon unlink\n");
879                 dump_stack();
880         }
881         if (repbody != NULL)
882                 repbody->mbo_eadatasize = 0;
883
884         /* Only check unlinked and archived if RAoLU and upon last close */
885         if (!cdt->cdt_remove_archive_on_last_unlink ||
886             atomic_read(&mo->mot_open_count) != 0)
887                 RETURN(0);
888
889         /* mdt_attr_get_complex will clear ma_valid, so check here first */
890         if ((ma->ma_valid & MA_INODE) && (ma->ma_attr.la_nlink != 0))
891                 RETURN(0);
892
893         if ((ma->ma_valid & MA_HSM) && (!(ma->ma_hsm.mh_flags & HS_EXISTS)))
894                 RETURN(0);
895
896         need |= (MA_INODE | MA_HSM) & ~ma->ma_valid;
897         if (need != 0) {
898                 /* ma->ma_valid is missing either MA_INODE, MA_HSM, or both,
899                  * try setting them */
900                 ma->ma_need |= need;
901                 rc = mdt_attr_get_complex(info, mo, ma);
902                 if (rc) {
903                         CERROR("%s: unable to fetch missing attributes of"
904                                DFID": rc=%d\n", mdt_obd_name(info->mti_mdt),
905                                PFID(mdt_object_fid(mo)), rc);
906                         RETURN(0);
907                 }
908
909                 if (need & MA_INODE) {
910                         if (ma->ma_valid & MA_INODE) {
911                                 if (ma->ma_attr.la_nlink != 0)
912                                         RETURN(0);
913                         } else {
914                                 RETURN(0);
915                         }
916                 }
917
918                 if (need & MA_HSM) {
919                         if (ma->ma_valid & MA_HSM) {
920                                 if (!(ma->ma_hsm.mh_flags & HS_EXISTS))
921                                         RETURN(0);
922                         } else {
923                                 RETURN(0);
924                         }
925                 }
926         }
927
928         /* RAoLU policy is active, last close on file has occured,
929          * file is unlinked, file is archived, so create remove request
930          * for copytool!
931          * If CDT is not running, requests will be logged for later. */
932         compound_id = atomic_inc_return(&cdt->cdt_compound_id);
933         if (ma->ma_hsm.mh_arch_id != 0)
934                 archive_id = ma->ma_hsm.mh_arch_id;
935         else
936                 archive_id = cdt->cdt_default_archive_id;
937
938         hai.hai_fid = *mdt_object_fid(mo);
939
940         rc = mdt_agent_record_add(info->mti_env, info->mti_mdt,
941                                   compound_id, archive_id, 0, &hai);
942         if (rc)
943                 CERROR("%s: unable to add HSM remove request for "DFID
944                        ": rc=%d\n", mdt_obd_name(info->mti_mdt),
945                        PFID(mdt_object_fid(mo)), rc);
946
947         RETURN(0);
948 }
949
950 static __u64 mdt_attr_valid_xlate(__u64 in, struct mdt_reint_record *rr,
951                                   struct md_attr *ma)
952 {
953         __u64 out;
954
955         out = 0;
956         if (in & MDS_ATTR_MODE)
957                 out |= LA_MODE;
958         if (in & MDS_ATTR_UID)
959                 out |= LA_UID;
960         if (in & MDS_ATTR_GID)
961                 out |= LA_GID;
962         if (in & MDS_ATTR_SIZE)
963                 out |= LA_SIZE;
964         if (in & MDS_ATTR_BLOCKS)
965                 out |= LA_BLOCKS;
966         if (in & MDS_ATTR_ATIME_SET)
967                 out |= LA_ATIME;
968         if (in & MDS_ATTR_CTIME_SET)
969                 out |= LA_CTIME;
970         if (in & MDS_ATTR_MTIME_SET)
971                 out |= LA_MTIME;
972         if (in & MDS_ATTR_ATTR_FLAG)
973                 out |= LA_FLAGS;
974         if (in & MDS_ATTR_KILL_SUID)
975                 out |= LA_KILL_SUID;
976         if (in & MDS_ATTR_KILL_SGID)
977                 out |= LA_KILL_SGID;
978         if (in & MDS_ATTR_PROJID)
979                 out |= LA_PROJID;
980
981         if (in & MDS_ATTR_FROM_OPEN)
982                 rr->rr_flags |= MRF_OPEN_TRUNC;
983         if (in & MDS_OPEN_OWNEROVERRIDE)
984                 ma->ma_attr_flags |= MDS_OWNEROVERRIDE;
985         if (in & MDS_ATTR_FORCE)
986                 ma->ma_attr_flags |= MDS_PERM_BYPASS;
987
988         in &= ~(MDS_ATTR_MODE | MDS_ATTR_UID | MDS_ATTR_GID | MDS_ATTR_PROJID |
989                 MDS_ATTR_ATIME | MDS_ATTR_MTIME | MDS_ATTR_CTIME |
990                 MDS_ATTR_ATIME_SET | MDS_ATTR_CTIME_SET | MDS_ATTR_MTIME_SET |
991                 MDS_ATTR_SIZE | MDS_ATTR_BLOCKS | MDS_ATTR_ATTR_FLAG |
992                 MDS_ATTR_FORCE | MDS_ATTR_KILL_SUID | MDS_ATTR_KILL_SGID |
993                 MDS_ATTR_FROM_OPEN | MDS_OPEN_OWNEROVERRIDE);
994         if (in != 0)
995                 CERROR("Unknown attr bits: %#llx\n", in);
996         return out;
997 }
998
999 /* unpacking */
1000
1001 int mdt_name_unpack(struct req_capsule *pill,
1002                     const struct req_msg_field *field,
1003                     struct lu_name *ln,
1004                     enum mdt_name_flags flags)
1005 {
1006         ln->ln_name = req_capsule_client_get(pill, field);
1007         ln->ln_namelen = req_capsule_get_size(pill, field, RCL_CLIENT) - 1;
1008
1009         if (!lu_name_is_valid(ln)) {
1010                 ln->ln_name = NULL;
1011                 ln->ln_namelen = 0;
1012
1013                 return -EPROTO;
1014         }
1015
1016         if ((flags & MNF_FIX_ANON) &&
1017             ln->ln_namelen == 1 && ln->ln_name[0] == '/') {
1018                 /* Newer (3.x) kernels use a name of "/" for the
1019                  * "anonymous" disconnected dentries from NFS
1020                  * filehandle conversion. See d_obtain_alias(). */
1021                 ln->ln_name = NULL;
1022                 ln->ln_namelen = 0;
1023         }
1024
1025         return 0;
1026 }
1027
1028 static int mdt_file_secctx_unpack(struct req_capsule *pill,
1029                                   const char **secctx_name,
1030                                   void **secctx, size_t *secctx_size)
1031 {
1032         const char *name;
1033         size_t name_size;
1034
1035         *secctx_name = NULL;
1036         *secctx = NULL;
1037         *secctx_size = 0;
1038
1039         if (!req_capsule_has_field(pill, &RMF_FILE_SECCTX_NAME, RCL_CLIENT) ||
1040             !req_capsule_field_present(pill, &RMF_FILE_SECCTX_NAME, RCL_CLIENT))
1041                 return 0;
1042
1043         name_size = req_capsule_get_size(pill, &RMF_FILE_SECCTX_NAME,
1044                                          RCL_CLIENT);
1045         if (name_size == 0)
1046                 return 0;
1047
1048         name = req_capsule_client_get(pill, &RMF_FILE_SECCTX_NAME);
1049         if (strnlen(name, name_size) != name_size - 1)
1050                 return -EPROTO;
1051
1052         if (!req_capsule_has_field(pill, &RMF_FILE_SECCTX, RCL_CLIENT) ||
1053             !req_capsule_field_present(pill, &RMF_FILE_SECCTX, RCL_CLIENT))
1054                 return -EPROTO;
1055
1056         *secctx_name = name;
1057         *secctx = req_capsule_client_get(pill, &RMF_FILE_SECCTX);
1058         *secctx_size = req_capsule_get_size(pill, &RMF_FILE_SECCTX, RCL_CLIENT);
1059
1060         return 0;
1061 }
1062
1063 static int mdt_setattr_unpack_rec(struct mdt_thread_info *info)
1064 {
1065         struct lu_ucred *uc = mdt_ucred(info);
1066         struct md_attr *ma = &info->mti_attr;
1067         struct lu_attr *la = &ma->ma_attr;
1068         struct req_capsule *pill = info->mti_pill;
1069         struct mdt_reint_record *rr = &info->mti_rr;
1070         struct mdt_rec_setattr *rec;
1071         struct lu_nodemap *nodemap;
1072
1073         ENTRY;
1074
1075         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1076         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1077         if (rec == NULL)
1078                 RETURN(-EFAULT);
1079
1080         /* This prior initialization is needed for old_init_ucred_reint() */
1081         uc->uc_fsuid = rec->sa_fsuid;
1082         uc->uc_fsgid = rec->sa_fsgid;
1083         uc->uc_cap   = rec->sa_cap;
1084         uc->uc_suppgids[0] = rec->sa_suppgid;
1085         uc->uc_suppgids[1] = -1;
1086
1087         rr->rr_fid1 = &rec->sa_fid;
1088         la->la_valid = mdt_attr_valid_xlate(rec->sa_valid, rr, ma);
1089         la->la_mode  = rec->sa_mode;
1090         la->la_flags = rec->sa_attr_flags;
1091
1092         nodemap = nodemap_get_from_exp(info->mti_exp);
1093         if (IS_ERR(nodemap))
1094                 RETURN(PTR_ERR(nodemap));
1095
1096         la->la_uid   = nodemap_map_id(nodemap, NODEMAP_UID,
1097                                       NODEMAP_CLIENT_TO_FS, rec->sa_uid);
1098         la->la_gid   = nodemap_map_id(nodemap, NODEMAP_GID,
1099                                       NODEMAP_CLIENT_TO_FS, rec->sa_gid);
1100         la->la_projid = rec->sa_projid;
1101         nodemap_putref(nodemap);
1102
1103         la->la_size  = rec->sa_size;
1104         la->la_blocks = rec->sa_blocks;
1105         la->la_ctime = rec->sa_ctime;
1106         la->la_atime = rec->sa_atime;
1107         la->la_mtime = rec->sa_mtime;
1108         ma->ma_valid = MA_INODE;
1109
1110         if (rec->sa_bias & MDS_DATA_MODIFIED)
1111                 ma->ma_attr_flags |= MDS_DATA_MODIFIED;
1112         else
1113                 ma->ma_attr_flags &= ~MDS_DATA_MODIFIED;
1114
1115         ma->ma_attr_flags &= ~MDS_CLOSE_INTENT;
1116         ma->ma_attr_flags |= rec->sa_bias & MDS_CLOSE_INTENT;
1117         RETURN(0);
1118 }
1119
1120 static int mdt_close_handle_unpack(struct mdt_thread_info *info)
1121 {
1122         struct req_capsule *pill = info->mti_pill;
1123         struct mdt_ioepoch *ioepoch;
1124         ENTRY;
1125
1126         if (req_capsule_get_size(pill, &RMF_MDT_EPOCH, RCL_CLIENT))
1127                 ioepoch = req_capsule_client_get(pill, &RMF_MDT_EPOCH);
1128         else
1129                 ioepoch = NULL;
1130
1131         if (ioepoch == NULL)
1132                 RETURN(-EPROTO);
1133
1134         info->mti_close_handle = ioepoch->mio_handle;
1135
1136         RETURN(0);
1137 }
1138
1139 static inline int mdt_dlmreq_unpack(struct mdt_thread_info *info) {
1140         struct req_capsule      *pill = info->mti_pill;
1141
1142         if (req_capsule_get_size(pill, &RMF_DLM_REQ, RCL_CLIENT)) {
1143                 info->mti_dlm_req = req_capsule_client_get(pill, &RMF_DLM_REQ);
1144                 if (info->mti_dlm_req == NULL)
1145                         RETURN(-EFAULT);
1146         }
1147
1148         RETURN(0);
1149 }
1150
1151 static int mdt_setattr_unpack(struct mdt_thread_info *info)
1152 {
1153         struct mdt_reint_record *rr = &info->mti_rr;
1154         struct md_attr          *ma = &info->mti_attr;
1155         struct req_capsule      *pill = info->mti_pill;
1156         int rc;
1157         ENTRY;
1158
1159         rc = mdt_setattr_unpack_rec(info);
1160         if (rc)
1161                 RETURN(rc);
1162
1163         if (req_capsule_field_present(pill, &RMF_EADATA, RCL_CLIENT)) {
1164                 rr->rr_eadata = req_capsule_client_get(pill, &RMF_EADATA);
1165                 rr->rr_eadatalen = req_capsule_get_size(pill, &RMF_EADATA,
1166                                                         RCL_CLIENT);
1167                 if (rr->rr_eadatalen > 0) {
1168                         const struct lmv_user_md        *lum;
1169
1170                         lum = rr->rr_eadata;
1171                         /* Sigh ma_valid(from req) does not indicate whether
1172                          * it will set LOV/LMV EA, so we have to check magic */
1173                         if (le32_to_cpu(lum->lum_magic) == LMV_USER_MAGIC) {
1174                                 ma->ma_valid |= MA_LMV;
1175                                 ma->ma_lmv = (void *)rr->rr_eadata;
1176                                 ma->ma_lmv_size = rr->rr_eadatalen;
1177                         } else {
1178                                 ma->ma_valid |= MA_LOV;
1179                                 ma->ma_lmm = (void *)rr->rr_eadata;
1180                                 ma->ma_lmm_size = rr->rr_eadatalen;
1181                         }
1182                 }
1183         }
1184
1185         rc = mdt_dlmreq_unpack(info);
1186         RETURN(rc);
1187 }
1188
1189 static int mdt_close_intent_unpack(struct mdt_thread_info *info)
1190 {
1191         struct md_attr          *ma = &info->mti_attr;
1192         struct req_capsule      *pill = info->mti_pill;
1193         ENTRY;
1194
1195         if (!(ma->ma_attr_flags & MDS_CLOSE_INTENT))
1196                 RETURN(0);
1197
1198         req_capsule_extend(pill, &RQF_MDS_CLOSE_INTENT);
1199
1200         if (!(req_capsule_has_field(pill, &RMF_CLOSE_DATA, RCL_CLIENT) &&
1201             req_capsule_field_present(pill, &RMF_CLOSE_DATA, RCL_CLIENT)))
1202                 RETURN(-EFAULT);
1203
1204         RETURN(0);
1205 }
1206
1207 int mdt_close_unpack(struct mdt_thread_info *info)
1208 {
1209         int rc;
1210         ENTRY;
1211
1212         rc = mdt_close_handle_unpack(info);
1213         if (rc)
1214                 RETURN(rc);
1215
1216         rc = mdt_setattr_unpack_rec(info);
1217         if (rc)
1218                 RETURN(rc);
1219
1220         rc = mdt_close_intent_unpack(info);
1221         if (rc)
1222                 RETURN(rc);
1223
1224         RETURN(mdt_init_ucred_reint(info));
1225 }
1226
1227 static int mdt_create_unpack(struct mdt_thread_info *info)
1228 {
1229         struct lu_ucred *uc  = mdt_ucred(info);
1230         struct mdt_rec_create *rec;
1231         struct lu_attr *attr = &info->mti_attr.ma_attr;
1232         struct mdt_reint_record *rr = &info->mti_rr;
1233         struct req_capsule *pill = info->mti_pill;
1234         struct md_op_spec *sp = &info->mti_spec;
1235         int rc;
1236
1237         ENTRY;
1238
1239         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1240         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1241         if (rec == NULL)
1242                 RETURN(-EFAULT);
1243
1244         /* This prior initialization is needed for old_init_ucred_reint() */
1245         uc->uc_fsuid = rec->cr_fsuid;
1246         uc->uc_fsgid = rec->cr_fsgid;
1247         uc->uc_cap   = rec->cr_cap;
1248         uc->uc_suppgids[0] = rec->cr_suppgid1;
1249         uc->uc_suppgids[1] = -1;
1250         uc->uc_umask = rec->cr_umask;
1251
1252         rr->rr_fid1 = &rec->cr_fid1;
1253         rr->rr_fid2 = &rec->cr_fid2;
1254         attr->la_mode = rec->cr_mode;
1255         attr->la_rdev  = rec->cr_rdev;
1256         attr->la_uid   = rec->cr_fsuid;
1257         attr->la_gid   = rec->cr_fsgid;
1258         attr->la_ctime = rec->cr_time;
1259         attr->la_mtime = rec->cr_time;
1260         attr->la_atime = rec->cr_time;
1261         attr->la_valid = LA_MODE | LA_RDEV | LA_UID | LA_GID | LA_TYPE |
1262                          LA_CTIME | LA_MTIME | LA_ATIME;
1263         memset(&sp->u, 0, sizeof(sp->u));
1264         sp->sp_cr_flags = get_mrc_cr_flags(rec);
1265
1266         rc = mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, 0);
1267         if (rc < 0)
1268                 RETURN(rc);
1269
1270         if (S_ISLNK(attr->la_mode)) {
1271                 const char *tgt = NULL;
1272
1273                 req_capsule_extend(pill, &RQF_MDS_REINT_CREATE_SYM);
1274                 if (req_capsule_get_size(pill, &RMF_SYMTGT, RCL_CLIENT)) {
1275                         tgt = req_capsule_client_get(pill, &RMF_SYMTGT);
1276                         sp->u.sp_symname = tgt;
1277                 }
1278                 if (tgt == NULL)
1279                         RETURN(-EFAULT);
1280         } else {
1281                 req_capsule_extend(pill, &RQF_MDS_REINT_CREATE_ACL);
1282                 if (S_ISDIR(attr->la_mode) &&
1283                     req_capsule_get_size(pill, &RMF_EADATA, RCL_CLIENT) > 0) {
1284                         sp->u.sp_ea.eadata =
1285                                 req_capsule_client_get(pill, &RMF_EADATA);
1286                         sp->u.sp_ea.eadatalen =
1287                                 req_capsule_get_size(pill, &RMF_EADATA,
1288                                                      RCL_CLIENT);
1289                         sp->sp_cr_flags |= MDS_OPEN_HAS_EA;
1290                 }
1291         }
1292
1293         rc = mdt_file_secctx_unpack(pill, &sp->sp_cr_file_secctx_name,
1294                                     &sp->sp_cr_file_secctx,
1295                                     &sp->sp_cr_file_secctx_size);
1296         if (rc < 0)
1297                 RETURN(rc);
1298
1299         rc = mdt_dlmreq_unpack(info);
1300         RETURN(rc);
1301 }
1302
1303 static int mdt_link_unpack(struct mdt_thread_info *info)
1304 {
1305         struct lu_ucred *uc  = mdt_ucred(info);
1306         struct mdt_rec_link *rec;
1307         struct lu_attr *attr = &info->mti_attr.ma_attr;
1308         struct mdt_reint_record *rr = &info->mti_rr;
1309         struct req_capsule *pill = info->mti_pill;
1310         int rc;
1311
1312         ENTRY;
1313
1314         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1315         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1316         if (rec == NULL)
1317                 RETURN(-EFAULT);
1318
1319         /* This prior initialization is needed for old_init_ucred_reint() */
1320         uc->uc_fsuid = rec->lk_fsuid;
1321         uc->uc_fsgid = rec->lk_fsgid;
1322         uc->uc_cap   = rec->lk_cap;
1323         uc->uc_suppgids[0] = rec->lk_suppgid1;
1324         uc->uc_suppgids[1] = rec->lk_suppgid2;
1325
1326         attr->la_uid = rec->lk_fsuid;
1327         attr->la_gid = rec->lk_fsgid;
1328         rr->rr_fid1 = &rec->lk_fid1;
1329         rr->rr_fid2 = &rec->lk_fid2;
1330         attr->la_ctime = rec->lk_time;
1331         attr->la_mtime = rec->lk_time;
1332         attr->la_valid = LA_UID | LA_GID | LA_CTIME | LA_MTIME;
1333
1334         rc = mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, 0);
1335         if (rc < 0)
1336                 RETURN(rc);
1337
1338         rc = mdt_dlmreq_unpack(info);
1339
1340         RETURN(rc);
1341 }
1342
1343 static int mdt_unlink_unpack(struct mdt_thread_info *info)
1344 {
1345         struct lu_ucred *uc  = mdt_ucred(info);
1346         struct mdt_rec_unlink *rec;
1347         struct md_attr *ma = &info->mti_attr;
1348         struct lu_attr *attr = &info->mti_attr.ma_attr;
1349         struct mdt_reint_record *rr = &info->mti_rr;
1350         struct req_capsule *pill = info->mti_pill;
1351         int rc;
1352
1353         ENTRY;
1354
1355         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1356         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1357         if (rec == NULL)
1358                 RETURN(-EFAULT);
1359
1360         /* This prior initialization is needed for old_init_ucred_reint() */
1361         uc->uc_fsuid = rec->ul_fsuid;
1362         uc->uc_fsgid = rec->ul_fsgid;
1363         uc->uc_cap   = rec->ul_cap;
1364         uc->uc_suppgids[0] = rec->ul_suppgid1;
1365         uc->uc_suppgids[1] = -1;
1366
1367         attr->la_uid = rec->ul_fsuid;
1368         attr->la_gid = rec->ul_fsgid;
1369         rr->rr_fid1 = &rec->ul_fid1;
1370         rr->rr_fid2 = &rec->ul_fid2;
1371         attr->la_ctime = rec->ul_time;
1372         attr->la_mtime = rec->ul_time;
1373         attr->la_mode  = rec->ul_mode;
1374         attr->la_valid = LA_UID | LA_GID | LA_CTIME | LA_MTIME | LA_MODE;
1375
1376         rc = mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, 0);
1377         if (rc < 0)
1378                 RETURN(rc);
1379
1380         if (rec->ul_bias & MDS_VTX_BYPASS)
1381                 ma->ma_attr_flags |= MDS_VTX_BYPASS;
1382         else
1383                 ma->ma_attr_flags &= ~MDS_VTX_BYPASS;
1384
1385         info->mti_spec.no_create = !!req_is_replay(mdt_info_req(info));
1386
1387         rc = mdt_dlmreq_unpack(info);
1388         RETURN(rc);
1389 }
1390
1391 static int mdt_rmentry_unpack(struct mdt_thread_info *info)
1392 {
1393         info->mti_spec.sp_rm_entry = 1;
1394         return mdt_unlink_unpack(info);
1395 }
1396
1397 static int mdt_rename_unpack(struct mdt_thread_info *info)
1398 {
1399         struct lu_ucred *uc = mdt_ucred(info);
1400         struct mdt_rec_rename *rec;
1401         struct md_attr *ma = &info->mti_attr;
1402         struct lu_attr *attr = &info->mti_attr.ma_attr;
1403         struct mdt_reint_record *rr = &info->mti_rr;
1404         struct req_capsule *pill = info->mti_pill;
1405         int rc;
1406
1407         ENTRY;
1408
1409         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1410         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1411         if (rec == NULL)
1412                 RETURN(-EFAULT);
1413
1414         /* This prior initialization is needed for old_init_ucred_reint() */
1415         uc->uc_fsuid = rec->rn_fsuid;
1416         uc->uc_fsgid = rec->rn_fsgid;
1417         uc->uc_cap   = rec->rn_cap;
1418         uc->uc_suppgids[0] = rec->rn_suppgid1;
1419         uc->uc_suppgids[1] = rec->rn_suppgid2;
1420
1421         attr->la_uid = rec->rn_fsuid;
1422         attr->la_gid = rec->rn_fsgid;
1423         rr->rr_fid1 = &rec->rn_fid1;
1424         rr->rr_fid2 = &rec->rn_fid2;
1425         attr->la_ctime = rec->rn_time;
1426         attr->la_mtime = rec->rn_time;
1427         /* rename_tgt contains the mode already */
1428         attr->la_mode = rec->rn_mode;
1429         attr->la_valid = LA_UID | LA_GID | LA_CTIME | LA_MTIME | LA_MODE;
1430
1431         rc = mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, 0);
1432         if (rc < 0)
1433                 RETURN(rc);
1434
1435         rc = mdt_name_unpack(pill, &RMF_SYMTGT, &rr->rr_tgt_name, 0);
1436         if (rc < 0)
1437                 RETURN(rc);
1438
1439         if (rec->rn_bias & MDS_VTX_BYPASS)
1440                 ma->ma_attr_flags |= MDS_VTX_BYPASS;
1441         else
1442                 ma->ma_attr_flags &= ~MDS_VTX_BYPASS;
1443
1444         if (rec->rn_bias & MDS_RENAME_MIGRATE) {
1445                 req_capsule_extend(info->mti_pill, &RQF_MDS_REINT_MIGRATE);
1446                 rc = mdt_close_handle_unpack(info);
1447                 if (rc < 0)
1448                         RETURN(rc);
1449                 info->mti_spec.sp_migrate_close = 1;
1450         }
1451
1452         info->mti_spec.no_create = !!req_is_replay(mdt_info_req(info));
1453
1454
1455         rc = mdt_dlmreq_unpack(info);
1456
1457         RETURN(rc);
1458 }
1459
1460 /*
1461  * please see comment above LOV_MAGIC_V1_DEFINED
1462  */
1463 void mdt_fix_lov_magic(struct mdt_thread_info *info, void *eadata)
1464 {
1465         struct lov_user_md_v1   *v1 = eadata;
1466
1467         LASSERT(v1);
1468
1469         if (unlikely(req_is_replay(mdt_info_req(info)))) {
1470                 if ((v1->lmm_magic & LOV_MAGIC_MASK) == LOV_MAGIC_MAGIC)
1471                         v1->lmm_magic |= LOV_MAGIC_DEFINED;
1472                 else if ((v1->lmm_magic & __swab32(LOV_MAGIC_MAGIC)) ==
1473                          __swab32(LOV_MAGIC_MAGIC))
1474                         v1->lmm_magic |= __swab32(LOV_MAGIC_DEFINED);
1475         }
1476 }
1477
1478 static int mdt_open_unpack(struct mdt_thread_info *info)
1479 {
1480         struct lu_ucred *uc = mdt_ucred(info);
1481         struct mdt_rec_create *rec;
1482         struct lu_attr *attr = &info->mti_attr.ma_attr;
1483         struct req_capsule *pill = info->mti_pill;
1484         struct mdt_reint_record *rr = &info->mti_rr;
1485         struct ptlrpc_request *req = mdt_info_req(info);
1486         struct md_op_spec *sp = &info->mti_spec;
1487         int rc;
1488         ENTRY;
1489
1490         CLASSERT(sizeof(struct mdt_rec_create) == sizeof(struct mdt_rec_reint));
1491         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1492         if (rec == NULL)
1493                 RETURN(-EFAULT);
1494
1495         /* This prior initialization is needed for old_init_ucred_reint() */
1496         uc->uc_fsuid = rec->cr_fsuid;
1497         uc->uc_fsgid = rec->cr_fsgid;
1498         uc->uc_cap   = rec->cr_cap;
1499         uc->uc_suppgids[0] = rec->cr_suppgid1;
1500         uc->uc_suppgids[1] = rec->cr_suppgid2;
1501         uc->uc_umask = rec->cr_umask;
1502
1503         rr->rr_fid1   = &rec->cr_fid1;
1504         rr->rr_fid2   = &rec->cr_fid2;
1505         rr->rr_handle = &rec->cr_old_handle;
1506         attr->la_mode = rec->cr_mode;
1507         attr->la_rdev  = rec->cr_rdev;
1508         attr->la_uid   = rec->cr_fsuid;
1509         attr->la_gid   = rec->cr_fsgid;
1510         attr->la_ctime = rec->cr_time;
1511         attr->la_mtime = rec->cr_time;
1512         attr->la_atime = rec->cr_time;
1513         attr->la_valid = LA_MODE  | LA_RDEV  | LA_UID   | LA_GID |
1514                          LA_CTIME | LA_MTIME | LA_ATIME;
1515         memset(&info->mti_spec.u, 0, sizeof(info->mti_spec.u));
1516         info->mti_spec.sp_cr_flags = get_mrc_cr_flags(rec);
1517         /* Do not trigger ASSERTION if client miss to set such flags. */
1518         if (unlikely(info->mti_spec.sp_cr_flags == 0))
1519                 RETURN(-EPROTO);
1520
1521         info->mti_cross_ref = !!(rec->cr_bias & MDS_CROSS_REF);
1522
1523         mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, MNF_FIX_ANON);
1524
1525         if (req_capsule_field_present(pill, &RMF_EADATA, RCL_CLIENT)) {
1526                 rr->rr_eadatalen = req_capsule_get_size(pill, &RMF_EADATA,
1527                                                         RCL_CLIENT);
1528                 if (rr->rr_eadatalen > 0) {
1529                         rr->rr_eadata = req_capsule_client_get(pill,
1530                                                                &RMF_EADATA);
1531                         sp->u.sp_ea.eadatalen = rr->rr_eadatalen;
1532                         sp->u.sp_ea.eadata = rr->rr_eadata;
1533                         sp->no_create = !!req_is_replay(req);
1534                         mdt_fix_lov_magic(info, rr->rr_eadata);
1535                 }
1536
1537                 /*
1538                  * Client default md_size may be 0 right after client start,
1539                  * until all osc are connected, set here just some reasonable
1540                  * value to prevent misbehavior.
1541                  */
1542                 if (rr->rr_eadatalen == 0 &&
1543                     !(info->mti_spec.sp_cr_flags & MDS_OPEN_DELAY_CREATE))
1544                         rr->rr_eadatalen = MIN_MD_SIZE;
1545         }
1546
1547         rc = mdt_file_secctx_unpack(pill, &sp->sp_cr_file_secctx_name,
1548                                     &sp->sp_cr_file_secctx,
1549                                     &sp->sp_cr_file_secctx_size);
1550
1551         RETURN(rc);
1552 }
1553
1554 static int mdt_setxattr_unpack(struct mdt_thread_info *info)
1555 {
1556         struct mdt_reint_record *rr = &info->mti_rr;
1557         struct lu_ucred *uc = mdt_ucred(info);
1558         struct lu_attr *attr = &info->mti_attr.ma_attr;
1559         struct req_capsule *pill = info->mti_pill;
1560         struct mdt_rec_setxattr *rec;
1561         int rc;
1562         ENTRY;
1563
1564
1565         CLASSERT(sizeof(struct mdt_rec_setxattr) ==
1566                  sizeof(struct mdt_rec_reint));
1567
1568         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1569         if (rec == NULL)
1570                 RETURN(-EFAULT);
1571
1572         /* This prior initialization is needed for old_init_ucred_reint() */
1573         uc->uc_fsuid  = rec->sx_fsuid;
1574         uc->uc_fsgid  = rec->sx_fsgid;
1575         uc->uc_cap    = rec->sx_cap;
1576         uc->uc_suppgids[0] = rec->sx_suppgid1;
1577         uc->uc_suppgids[1] = -1;
1578
1579         rr->rr_opcode = rec->sx_opcode;
1580         rr->rr_fid1   = &rec->sx_fid;
1581         attr->la_valid = rec->sx_valid;
1582         attr->la_ctime = rec->sx_time;
1583         attr->la_size = rec->sx_size;
1584         attr->la_flags = rec->sx_flags;
1585
1586         rc = mdt_name_unpack(pill, &RMF_NAME, &rr->rr_name, 0);
1587         if (rc < 0)
1588                 RETURN(rc);
1589
1590         if (req_capsule_field_present(pill, &RMF_EADATA, RCL_CLIENT)) {
1591                 rr->rr_eadatalen = req_capsule_get_size(pill, &RMF_EADATA,
1592                                                         RCL_CLIENT);
1593                 if (rr->rr_eadatalen > 0) {
1594                         rr->rr_eadata = req_capsule_client_get(pill,
1595                                                                &RMF_EADATA);
1596                         if (rr->rr_eadata == NULL)
1597                                 RETURN(-EFAULT);
1598                 } else {
1599                         rr->rr_eadata = NULL;
1600                 }
1601         } else if (!(attr->la_valid & OBD_MD_FLXATTRRM)) {
1602                 CDEBUG(D_INFO, "no xattr data supplied\n");
1603                 RETURN(-EFAULT);
1604         }
1605
1606         if (mdt_dlmreq_unpack(info) < 0)
1607                 RETURN(-EPROTO);
1608
1609         RETURN(0);
1610 }
1611
1612 static int mdt_resync_unpack(struct mdt_thread_info *info)
1613 {
1614         struct req_capsule      *pill = info->mti_pill;
1615         struct mdt_reint_record *rr   = &info->mti_rr;
1616         struct lu_ucred         *uc     = mdt_ucred(info);
1617         struct mdt_rec_resync   *rec;
1618         ENTRY;
1619
1620         CLASSERT(sizeof(*rec) == sizeof(struct mdt_rec_reint));
1621         rec = req_capsule_client_get(pill, &RMF_REC_REINT);
1622         if (rec == NULL)
1623                 RETURN(-EFAULT);
1624
1625         /* This prior initialization is needed for old_init_ucred_reint() */
1626         uc->uc_fsuid = rec->rs_fsuid;
1627         uc->uc_fsgid = rec->rs_fsgid;
1628         uc->uc_cap   = rec->rs_cap;
1629
1630         rr->rr_fid1   = &rec->rs_fid;
1631
1632         /* cookie doesn't need to be swapped but it has been swapped
1633          * in lustre_swab_mdt_rec_reint() as rr_mtime, so here it needs
1634          * restoring. */
1635         if (ptlrpc_req_need_swab(mdt_info_req(info)))
1636                 __swab64s(&rec->rs_handle.cookie);
1637         rr->rr_handle = &rec->rs_handle;
1638
1639         RETURN(mdt_dlmreq_unpack(info));
1640 }
1641
1642 typedef int (*reint_unpacker)(struct mdt_thread_info *info);
1643
1644 static reint_unpacker mdt_reint_unpackers[REINT_MAX] = {
1645         [REINT_SETATTR]  = mdt_setattr_unpack,
1646         [REINT_CREATE]   = mdt_create_unpack,
1647         [REINT_LINK]     = mdt_link_unpack,
1648         [REINT_UNLINK]   = mdt_unlink_unpack,
1649         [REINT_RENAME]   = mdt_rename_unpack,
1650         [REINT_OPEN]     = mdt_open_unpack,
1651         [REINT_SETXATTR] = mdt_setxattr_unpack,
1652         [REINT_RMENTRY]  = mdt_rmentry_unpack,
1653         [REINT_MIGRATE]  = mdt_rename_unpack,
1654         [REINT_RESYNC]   = mdt_resync_unpack,
1655 };
1656
1657 int mdt_reint_unpack(struct mdt_thread_info *info, __u32 op)
1658 {
1659         int rc;
1660         ENTRY;
1661
1662         memset(&info->mti_rr, 0, sizeof(info->mti_rr));
1663         if (op < REINT_MAX && mdt_reint_unpackers[op] != NULL) {
1664                 info->mti_rr.rr_opcode = op;
1665                 rc = mdt_reint_unpackers[op](info);
1666         } else {
1667                 CERROR("Unexpected opcode %d\n", op);
1668                 rc = -EFAULT;
1669         }
1670         RETURN(rc);
1671 }