readdir.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590
  1. // SPDX-License-Identifier: GPL-2.0
  2. /*
  3. * linux/fs/readdir.c
  4. *
  5. * Copyright (C) 1995 Linus Torvalds
  6. */
  7. #include <linux/stddef.h>
  8. #include <linux/kernel.h>
  9. #include <linux/export.h>
  10. #include <linux/time.h>
  11. #include <linux/mm.h>
  12. #include <linux/errno.h>
  13. #include <linux/stat.h>
  14. #include <linux/file.h>
  15. #include <linux/fs.h>
  16. #include <linux/fsnotify.h>
  17. #include <linux/dirent.h>
  18. #include <linux/security.h>
  19. #include <linux/syscalls.h>
  20. #include <linux/unistd.h>
  21. #include <linux/compat.h>
  22. #include <linux/uaccess.h>
  23. /*
  24. * Some filesystems were never converted to '->iterate_shared()'
  25. * and their directory iterators want the inode lock held for
  26. * writing. This wrapper allows for converting from the shared
  27. * semantics to the exclusive inode use.
  28. */
  29. int wrap_directory_iterator(struct file *file,
  30. struct dir_context *ctx,
  31. int (*iter)(struct file *, struct dir_context *))
  32. {
  33. struct inode *inode = file_inode(file);
  34. int ret;
  35. /*
  36. * We'd love to have an 'inode_upgrade_trylock()' operation,
  37. * see the comment in mmap_upgrade_trylock() in mm/memory.c.
  38. *
  39. * But considering this is for "filesystems that never got
  40. * converted", it really doesn't matter.
  41. *
  42. * Also note that since we have to return with the lock held
  43. * for reading, we can't use the "killable()" locking here,
  44. * since we do need to get the lock even if we're dying.
  45. *
  46. * We could do the write part killably and then get the read
  47. * lock unconditionally if it mattered, but see above on why
  48. * this does the very simplistic conversion.
  49. */
  50. up_read(&inode->i_rwsem);
  51. down_write(&inode->i_rwsem);
  52. /*
  53. * Since we dropped the inode lock, we should do the
  54. * DEADDIR test again. See 'iterate_dir()' below.
  55. *
  56. * Note that we don't need to re-do the f_pos games,
  57. * since the file must be locked wrt f_pos anyway.
  58. */
  59. ret = -ENOENT;
  60. if (!IS_DEADDIR(inode))
  61. ret = iter(file, ctx);
  62. downgrade_write(&inode->i_rwsem);
  63. return ret;
  64. }
  65. EXPORT_SYMBOL(wrap_directory_iterator);
  66. /*
  67. * Note the "unsafe_put_user()" semantics: we goto a
  68. * label for errors.
  69. */
  70. #define unsafe_copy_dirent_name(_dst, _src, _len, label) do { \
  71. char __user *dst = (_dst); \
  72. const char *src = (_src); \
  73. size_t len = (_len); \
  74. unsafe_put_user(0, dst+len, label); \
  75. unsafe_copy_to_user(dst, src, len, label); \
  76. } while (0)
  77. int iterate_dir(struct file *file, struct dir_context *ctx)
  78. {
  79. struct inode *inode = file_inode(file);
  80. int res = -ENOTDIR;
  81. if (!file->f_op->iterate_shared)
  82. goto out;
  83. res = security_file_permission(file, MAY_READ);
  84. if (res)
  85. goto out;
  86. res = fsnotify_file_perm(file, MAY_READ);
  87. if (res)
  88. goto out;
  89. res = down_read_killable(&inode->i_rwsem);
  90. if (res)
  91. goto out;
  92. res = -ENOENT;
  93. if (!IS_DEADDIR(inode)) {
  94. ctx->pos = file->f_pos;
  95. res = file->f_op->iterate_shared(file, ctx);
  96. file->f_pos = ctx->pos;
  97. fsnotify_access(file);
  98. file_accessed(file);
  99. }
  100. inode_unlock_shared(inode);
  101. out:
  102. return res;
  103. }
  104. EXPORT_SYMBOL(iterate_dir);
  105. /*
  106. * POSIX says that a dirent name cannot contain NULL or a '/'.
  107. *
  108. * It's not 100% clear what we should really do in this case.
  109. * The filesystem is clearly corrupted, but returning a hard
  110. * error means that you now don't see any of the other names
  111. * either, so that isn't a perfect alternative.
  112. *
  113. * And if you return an error, what error do you use? Several
  114. * filesystems seem to have decided on EUCLEAN being the error
  115. * code for EFSCORRUPTED, and that may be the error to use. Or
  116. * just EIO, which is perhaps more obvious to users.
  117. *
  118. * In order to see the other file names in the directory, the
  119. * caller might want to make this a "soft" error: skip the
  120. * entry, and return the error at the end instead.
  121. *
  122. * Note that this should likely do a "memchr(name, 0, len)"
  123. * check too, since that would be filesystem corruption as
  124. * well. However, that case can't actually confuse user space,
  125. * which has to do a strlen() on the name anyway to find the
  126. * filename length, and the above "soft error" worry means
  127. * that it's probably better left alone until we have that
  128. * issue clarified.
  129. *
  130. * Note the PATH_MAX check - it's arbitrary but the real
  131. * kernel limit on a possible path component, not NAME_MAX,
  132. * which is the technical standard limit.
  133. */
  134. static int verify_dirent_name(const char *name, int len)
  135. {
  136. if (len <= 0 || len >= PATH_MAX)
  137. return -EIO;
  138. if (memchr(name, '/', len))
  139. return -EIO;
  140. return 0;
  141. }
  142. /*
  143. * Traditional linux readdir() handling..
  144. *
  145. * "count=1" is a special case, meaning that the buffer is one
  146. * dirent-structure in size and that the code can't handle more
  147. * anyway. Thus the special "fillonedir()" function for that
  148. * case (the low-level handlers don't need to care about this).
  149. */
  150. #ifdef __ARCH_WANT_OLD_READDIR
  151. struct old_linux_dirent {
  152. unsigned long d_ino;
  153. unsigned long d_offset;
  154. unsigned short d_namlen;
  155. char d_name[];
  156. };
  157. struct readdir_callback {
  158. struct dir_context ctx;
  159. struct old_linux_dirent __user * dirent;
  160. int result;
  161. };
  162. static bool fillonedir(struct dir_context *ctx, const char *name, int namlen,
  163. loff_t offset, u64 ino, unsigned int d_type)
  164. {
  165. struct readdir_callback *buf =
  166. container_of(ctx, struct readdir_callback, ctx);
  167. struct old_linux_dirent __user * dirent;
  168. unsigned long d_ino;
  169. if (buf->result)
  170. return false;
  171. buf->result = verify_dirent_name(name, namlen);
  172. if (buf->result)
  173. return false;
  174. d_ino = ino;
  175. if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
  176. buf->result = -EOVERFLOW;
  177. return false;
  178. }
  179. buf->result++;
  180. dirent = buf->dirent;
  181. if (!user_write_access_begin(dirent,
  182. (unsigned long)(dirent->d_name + namlen + 1) -
  183. (unsigned long)dirent))
  184. goto efault;
  185. unsafe_put_user(d_ino, &dirent->d_ino, efault_end);
  186. unsafe_put_user(offset, &dirent->d_offset, efault_end);
  187. unsafe_put_user(namlen, &dirent->d_namlen, efault_end);
  188. unsafe_copy_dirent_name(dirent->d_name, name, namlen, efault_end);
  189. user_write_access_end();
  190. return true;
  191. efault_end:
  192. user_write_access_end();
  193. efault:
  194. buf->result = -EFAULT;
  195. return false;
  196. }
  197. SYSCALL_DEFINE3(old_readdir, unsigned int, fd,
  198. struct old_linux_dirent __user *, dirent, unsigned int, count)
  199. {
  200. int error;
  201. struct fd f = fdget_pos(fd);
  202. struct readdir_callback buf = {
  203. .ctx.actor = fillonedir,
  204. .dirent = dirent
  205. };
  206. if (!fd_file(f))
  207. return -EBADF;
  208. error = iterate_dir(fd_file(f), &buf.ctx);
  209. if (buf.result)
  210. error = buf.result;
  211. fdput_pos(f);
  212. return error;
  213. }
  214. #endif /* __ARCH_WANT_OLD_READDIR */
  215. /*
  216. * New, all-improved, singing, dancing, iBCS2-compliant getdents()
  217. * interface.
  218. */
  219. struct linux_dirent {
  220. unsigned long d_ino;
  221. unsigned long d_off;
  222. unsigned short d_reclen;
  223. char d_name[];
  224. };
  225. struct getdents_callback {
  226. struct dir_context ctx;
  227. struct linux_dirent __user * current_dir;
  228. int prev_reclen;
  229. int count;
  230. int error;
  231. };
  232. static bool filldir(struct dir_context *ctx, const char *name, int namlen,
  233. loff_t offset, u64 ino, unsigned int d_type)
  234. {
  235. struct linux_dirent __user *dirent, *prev;
  236. struct getdents_callback *buf =
  237. container_of(ctx, struct getdents_callback, ctx);
  238. unsigned long d_ino;
  239. int reclen = ALIGN(offsetof(struct linux_dirent, d_name) + namlen + 2,
  240. sizeof(long));
  241. int prev_reclen;
  242. buf->error = verify_dirent_name(name, namlen);
  243. if (unlikely(buf->error))
  244. return false;
  245. buf->error = -EINVAL; /* only used if we fail.. */
  246. if (reclen > buf->count)
  247. return false;
  248. d_ino = ino;
  249. if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
  250. buf->error = -EOVERFLOW;
  251. return false;
  252. }
  253. prev_reclen = buf->prev_reclen;
  254. if (prev_reclen && signal_pending(current))
  255. return false;
  256. dirent = buf->current_dir;
  257. prev = (void __user *) dirent - prev_reclen;
  258. if (!user_write_access_begin(prev, reclen + prev_reclen))
  259. goto efault;
  260. /* This might be 'dirent->d_off', but if so it will get overwritten */
  261. unsafe_put_user(offset, &prev->d_off, efault_end);
  262. unsafe_put_user(d_ino, &dirent->d_ino, efault_end);
  263. unsafe_put_user(reclen, &dirent->d_reclen, efault_end);
  264. unsafe_put_user(d_type, (char __user *) dirent + reclen - 1, efault_end);
  265. unsafe_copy_dirent_name(dirent->d_name, name, namlen, efault_end);
  266. user_write_access_end();
  267. buf->current_dir = (void __user *)dirent + reclen;
  268. buf->prev_reclen = reclen;
  269. buf->count -= reclen;
  270. return true;
  271. efault_end:
  272. user_write_access_end();
  273. efault:
  274. buf->error = -EFAULT;
  275. return false;
  276. }
  277. SYSCALL_DEFINE3(getdents, unsigned int, fd,
  278. struct linux_dirent __user *, dirent, unsigned int, count)
  279. {
  280. struct fd f;
  281. struct getdents_callback buf = {
  282. .ctx.actor = filldir,
  283. .count = count,
  284. .current_dir = dirent
  285. };
  286. int error;
  287. f = fdget_pos(fd);
  288. if (!fd_file(f))
  289. return -EBADF;
  290. error = iterate_dir(fd_file(f), &buf.ctx);
  291. if (error >= 0)
  292. error = buf.error;
  293. if (buf.prev_reclen) {
  294. struct linux_dirent __user * lastdirent;
  295. lastdirent = (void __user *)buf.current_dir - buf.prev_reclen;
  296. if (put_user(buf.ctx.pos, &lastdirent->d_off))
  297. error = -EFAULT;
  298. else
  299. error = count - buf.count;
  300. }
  301. fdput_pos(f);
  302. return error;
  303. }
  304. struct getdents_callback64 {
  305. struct dir_context ctx;
  306. struct linux_dirent64 __user * current_dir;
  307. int prev_reclen;
  308. int count;
  309. int error;
  310. };
  311. static bool filldir64(struct dir_context *ctx, const char *name, int namlen,
  312. loff_t offset, u64 ino, unsigned int d_type)
  313. {
  314. struct linux_dirent64 __user *dirent, *prev;
  315. struct getdents_callback64 *buf =
  316. container_of(ctx, struct getdents_callback64, ctx);
  317. int reclen = ALIGN(offsetof(struct linux_dirent64, d_name) + namlen + 1,
  318. sizeof(u64));
  319. int prev_reclen;
  320. buf->error = verify_dirent_name(name, namlen);
  321. if (unlikely(buf->error))
  322. return false;
  323. buf->error = -EINVAL; /* only used if we fail.. */
  324. if (reclen > buf->count)
  325. return false;
  326. prev_reclen = buf->prev_reclen;
  327. if (prev_reclen && signal_pending(current))
  328. return false;
  329. dirent = buf->current_dir;
  330. prev = (void __user *)dirent - prev_reclen;
  331. if (!user_write_access_begin(prev, reclen + prev_reclen))
  332. goto efault;
  333. /* This might be 'dirent->d_off', but if so it will get overwritten */
  334. unsafe_put_user(offset, &prev->d_off, efault_end);
  335. unsafe_put_user(ino, &dirent->d_ino, efault_end);
  336. unsafe_put_user(reclen, &dirent->d_reclen, efault_end);
  337. unsafe_put_user(d_type, &dirent->d_type, efault_end);
  338. unsafe_copy_dirent_name(dirent->d_name, name, namlen, efault_end);
  339. user_write_access_end();
  340. buf->prev_reclen = reclen;
  341. buf->current_dir = (void __user *)dirent + reclen;
  342. buf->count -= reclen;
  343. return true;
  344. efault_end:
  345. user_write_access_end();
  346. efault:
  347. buf->error = -EFAULT;
  348. return false;
  349. }
  350. SYSCALL_DEFINE3(getdents64, unsigned int, fd,
  351. struct linux_dirent64 __user *, dirent, unsigned int, count)
  352. {
  353. struct fd f;
  354. struct getdents_callback64 buf = {
  355. .ctx.actor = filldir64,
  356. .count = count,
  357. .current_dir = dirent
  358. };
  359. int error;
  360. f = fdget_pos(fd);
  361. if (!fd_file(f))
  362. return -EBADF;
  363. error = iterate_dir(fd_file(f), &buf.ctx);
  364. if (error >= 0)
  365. error = buf.error;
  366. if (buf.prev_reclen) {
  367. struct linux_dirent64 __user * lastdirent;
  368. typeof(lastdirent->d_off) d_off = buf.ctx.pos;
  369. lastdirent = (void __user *) buf.current_dir - buf.prev_reclen;
  370. if (put_user(d_off, &lastdirent->d_off))
  371. error = -EFAULT;
  372. else
  373. error = count - buf.count;
  374. }
  375. fdput_pos(f);
  376. return error;
  377. }
  378. #ifdef CONFIG_COMPAT
  379. struct compat_old_linux_dirent {
  380. compat_ulong_t d_ino;
  381. compat_ulong_t d_offset;
  382. unsigned short d_namlen;
  383. char d_name[];
  384. };
  385. struct compat_readdir_callback {
  386. struct dir_context ctx;
  387. struct compat_old_linux_dirent __user *dirent;
  388. int result;
  389. };
  390. static bool compat_fillonedir(struct dir_context *ctx, const char *name,
  391. int namlen, loff_t offset, u64 ino,
  392. unsigned int d_type)
  393. {
  394. struct compat_readdir_callback *buf =
  395. container_of(ctx, struct compat_readdir_callback, ctx);
  396. struct compat_old_linux_dirent __user *dirent;
  397. compat_ulong_t d_ino;
  398. if (buf->result)
  399. return false;
  400. buf->result = verify_dirent_name(name, namlen);
  401. if (buf->result)
  402. return false;
  403. d_ino = ino;
  404. if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
  405. buf->result = -EOVERFLOW;
  406. return false;
  407. }
  408. buf->result++;
  409. dirent = buf->dirent;
  410. if (!user_write_access_begin(dirent,
  411. (unsigned long)(dirent->d_name + namlen + 1) -
  412. (unsigned long)dirent))
  413. goto efault;
  414. unsafe_put_user(d_ino, &dirent->d_ino, efault_end);
  415. unsafe_put_user(offset, &dirent->d_offset, efault_end);
  416. unsafe_put_user(namlen, &dirent->d_namlen, efault_end);
  417. unsafe_copy_dirent_name(dirent->d_name, name, namlen, efault_end);
  418. user_write_access_end();
  419. return true;
  420. efault_end:
  421. user_write_access_end();
  422. efault:
  423. buf->result = -EFAULT;
  424. return false;
  425. }
  426. COMPAT_SYSCALL_DEFINE3(old_readdir, unsigned int, fd,
  427. struct compat_old_linux_dirent __user *, dirent, unsigned int, count)
  428. {
  429. int error;
  430. struct fd f = fdget_pos(fd);
  431. struct compat_readdir_callback buf = {
  432. .ctx.actor = compat_fillonedir,
  433. .dirent = dirent
  434. };
  435. if (!fd_file(f))
  436. return -EBADF;
  437. error = iterate_dir(fd_file(f), &buf.ctx);
  438. if (buf.result)
  439. error = buf.result;
  440. fdput_pos(f);
  441. return error;
  442. }
  443. struct compat_linux_dirent {
  444. compat_ulong_t d_ino;
  445. compat_ulong_t d_off;
  446. unsigned short d_reclen;
  447. char d_name[];
  448. };
  449. struct compat_getdents_callback {
  450. struct dir_context ctx;
  451. struct compat_linux_dirent __user *current_dir;
  452. int prev_reclen;
  453. int count;
  454. int error;
  455. };
  456. static bool compat_filldir(struct dir_context *ctx, const char *name, int namlen,
  457. loff_t offset, u64 ino, unsigned int d_type)
  458. {
  459. struct compat_linux_dirent __user *dirent, *prev;
  460. struct compat_getdents_callback *buf =
  461. container_of(ctx, struct compat_getdents_callback, ctx);
  462. compat_ulong_t d_ino;
  463. int reclen = ALIGN(offsetof(struct compat_linux_dirent, d_name) +
  464. namlen + 2, sizeof(compat_long_t));
  465. int prev_reclen;
  466. buf->error = verify_dirent_name(name, namlen);
  467. if (unlikely(buf->error))
  468. return false;
  469. buf->error = -EINVAL; /* only used if we fail.. */
  470. if (reclen > buf->count)
  471. return false;
  472. d_ino = ino;
  473. if (sizeof(d_ino) < sizeof(ino) && d_ino != ino) {
  474. buf->error = -EOVERFLOW;
  475. return false;
  476. }
  477. prev_reclen = buf->prev_reclen;
  478. if (prev_reclen && signal_pending(current))
  479. return false;
  480. dirent = buf->current_dir;
  481. prev = (void __user *) dirent - prev_reclen;
  482. if (!user_write_access_begin(prev, reclen + prev_reclen))
  483. goto efault;
  484. unsafe_put_user(offset, &prev->d_off, efault_end);
  485. unsafe_put_user(d_ino, &dirent->d_ino, efault_end);
  486. unsafe_put_user(reclen, &dirent->d_reclen, efault_end);
  487. unsafe_put_user(d_type, (char __user *) dirent + reclen - 1, efault_end);
  488. unsafe_copy_dirent_name(dirent->d_name, name, namlen, efault_end);
  489. user_write_access_end();
  490. buf->prev_reclen = reclen;
  491. buf->current_dir = (void __user *)dirent + reclen;
  492. buf->count -= reclen;
  493. return true;
  494. efault_end:
  495. user_write_access_end();
  496. efault:
  497. buf->error = -EFAULT;
  498. return false;
  499. }
  500. COMPAT_SYSCALL_DEFINE3(getdents, unsigned int, fd,
  501. struct compat_linux_dirent __user *, dirent, unsigned int, count)
  502. {
  503. struct fd f;
  504. struct compat_getdents_callback buf = {
  505. .ctx.actor = compat_filldir,
  506. .current_dir = dirent,
  507. .count = count
  508. };
  509. int error;
  510. f = fdget_pos(fd);
  511. if (!fd_file(f))
  512. return -EBADF;
  513. error = iterate_dir(fd_file(f), &buf.ctx);
  514. if (error >= 0)
  515. error = buf.error;
  516. if (buf.prev_reclen) {
  517. struct compat_linux_dirent __user * lastdirent;
  518. lastdirent = (void __user *)buf.current_dir - buf.prev_reclen;
  519. if (put_user(buf.ctx.pos, &lastdirent->d_off))
  520. error = -EFAULT;
  521. else
  522. error = count - buf.count;
  523. }
  524. fdput_pos(f);
  525. return error;
  526. }
  527. #endif