Pull f2fs update from Jaegeuk Kim: "In this round, we've mainly focused on performance tuning and critical bug fixes occurred in low-end devices. Sheng Yong introduced lost_found feature to keep missing files during recovery instead of thrashing them. We're preparing coming fsverity implementation. And, we've got more features to communicate with users for better performance. In low-end devices, some memory-related issues were fixed, and subtle race condtions and corner cases were addressed as well. Enhancements: - large nat bitmaps for more free node ids - add three block allocation policies to pass down write hints given by user - expose extension list to user and introduce hot file extension - tune small devices seamlessly for low-end devices - set readdir_ra by default - give more resources under gc_urgent mode regarding to discard and cleaning - introduce fsync_mode to enforce posix or not - nowait aio support - add lost_found feature to keep dangling inodes - reserve bits for future fsverity feature - add test_dummy_encryption for FBE Bug fixes: - don't use highmem for dentry pages - align memory boundary for bitops - truncate preallocated blocks in write errors - guarantee i_times on fsync call - clear CP_TRIMMED_FLAG correctly - prevent node chain loop during recovery - avoid data race between atomic write and background cleaning - avoid unnecessary selinux violation warnings on resgid option - GFP_NOFS to avoid deadlock in quota and read paths - fix f2fs_skip_inode_update to allow i_size recovery In addition to the above, there are several minor bug fixes and clean-ups" Cherry-pick from origin/upstream-f2fs-stable-linux-4.9.y:ac389af190f2fs: remain written times to update inode during fsync270deeb871f2fs: make assignment of t->dentry_bitmap more readablea4fa11c8daf2fs: truncate preallocated blocks in error case4478970f0ef2fs: fix a wrong condition in f2fs_skip_inode_update29cead58f5f2fs: reserve bits for fs-verity848b293a5df2fs: Add a segment type check in inplace write2dc8f5a3a6f2fs: no need to initialize zero value for GFP_F2FS_ZERO83b9bb95a6f2fs: don't track new nat entry in nat seta33ce03ac4f2fs: clean up with F2FS_BLK_ALIGNa3f8ec8082f2fs: check blkaddr more accuratly before issue a bio034f11eadbf2fs: Set GF_NOFS in read_cache_page_gfp while doing f2fs_quota_readaa5bcfd8f4f2fs: introduce a new mount option test_dummy_encryption9b880fe6e6f2fs: introduce F2FS_FEATURE_LOST_FOUND feature80d6489a08f2fs: release locks before return in f2fs_ioc_gc_range()9f1896c490f2fs: align memory boundary for bitopsc7930ee883f2fs: remove unneeded set_cold_node()355d234640f2fs: add nowait aio supporte9a50e6b94f2fs: wrap all options with f2fs_sb_info.mount_optb6d2ec83e0f2fs: Don't overwrite all types of node to keep node chain9a95481629f2fs: introduce mount option for fsync mode4ce4eb6970f2fs: fix to restore old mount option in ->remount_fs8f711c344ef2fs: wrap sb_rdonly with f2fs_readonlyc07478ee84f2fs: avoid selinux denial on CAP_SYS_RESOURCEac734c416ff2fs: support hot file extensionf4f10221acf2fs: fix to avoid race in between atomic write and background GCe87b13ec16f2fs: do gc in greedy mode for whole range if gc_urgent mode is sete9878588def2fs: issue discard aggressively in the gc_urgent modead3ce479e6f2fs: set readdir_ra by default5aae2026bbf2fs: add auto tuning for small devices78c1fc2d8ff2fs: add mount option for segment allocation policyecd02f5646f2fs: don't stop GC if GC is contended1e72cb27d2f2fs: expose extension_list sysfs entry061839d178f2fs: fix to set KEEP_SIZE bit in f2fs_zero_range4951ebcbc4f2fs: introduce sb_lock to make encrypt pwsalt update exclusive939f6be042f2fs: remove redundant initialization of pointer 'p'39bea4bc8ef2fs: flush cp pack except cp pack 2 page at first770611eb2af2fs: clean up f2fs_sb_has_xxx functions4d8e4a8965f2fs: remove redundant check of page type when submit bioe9878588def2fs: issue discard aggressively in the gc_urgent modead3ce479e6f2fs: set readdir_ra by default5aae2026bbf2fs: add auto tuning for small devices78c1fc2d8ff2fs: add mount option for segment allocation policyecd02f5646f2fs: don't stop GC if GC is contended1e72cb27d2f2fs: expose extension_list sysfs entry061839d178f2fs: fix to set KEEP_SIZE bit in f2fs_zero_range4951ebcbc4f2fs: introduce sb_lock to make encrypt pwsalt update exclusive939f6be042f2fs: remove redundant initialization of pointer 'p'39bea4bc8ef2fs: flush cp pack except cp pack 2 page at first770611eb2af2fs: clean up f2fs_sb_has_xxx functions4d8e4a8965f2fs: remove redundant check of page type when submit biob57a37f01ff2fs: fix to handle looped node chain during recovery9ac5b8c540f2fs: handle quota for orphan inodes87c1806601f2fs: support passing down write hints to block layer with F2FS policybcdc571e8df2fs: support passing down write hints given by users to block layer92413bc12ef2fs: fix to clear CP_TRIMMED_FLAGa1afb55f97f2fs: support large nat bitmap6360391404f2fs: fix to check extent cache in f2fs_drop_extent_tree7de4fccdbcf2fs: restrict inline_xattr_size configurationaae506a8b7f2fs: fix heap mode to reset it back8fa455bb6ef2fs: fix potential corruption in area before F2FS_SUPER_OFFSET9d9cb0ef73fscrypt: fix build with pre-4.6 gcc versions401052ffc6fscrypt: remove 'ci' parameter from fscrypt_put_encryption_info()549b2061b3fscrypt: fix up fscrypt_fname_encrypted_size() for internal usec440b5091afscrypt: define fscrypt_fname_alloc_buffer() to be for presented names7d82f0e1c3ext4: switch to fscrypt ->symlink() helper functionsba4efe5604ext4: switch to fscrypt_get_symlink()b0edc2f22dfscrypt: calculate NUL-padding length in one place only62cfdd9868fscrypt: move fscrypt_symlink_data to fscrypt_private.he4e6776522fscrypt: remove fscrypt_fname_usr_to_disk()45028b5aaaf2fs: switch to fscrypt_get_symlink()f62d3d31e0f2fs: switch to fscrypt ->symlink() helper functionsda32a1633afscrypt: new helper function - fscrypt_get_symlink()a7e05c731dfscrypt: new helper functions for ->symlink()eb9c5fd896fscrypt: trim down fscrypt.h includes0a02472d8afscrypt: move fscrypt_is_dot_dotdot() to fs/crypto/fname.c9d51ca8027fscrypt: move fscrypt_valid_enc_modes() to fscrypt_private.hefbfa8c6a0fscrypt: move fscrypt_operations declaration to fscrypt_supp.h616dbd2bdcfscrypt: split fscrypt_dummy_context_enabled() into supp/notsupp versionsf0c472bcbffscrypt: move fscrypt_ctx declaration to fscrypt_supp.hbc76f39109fscrypt: move fscrypt_info_cachep declaration to fscrypt_private.hb67b07ec49fscrypt: move fscrypt_control_page() to supp/notsupp headersd8dfb89961fscrypt: move fscrypt_has_encryption_key() to supp/notsupp headers Signed-off-by: Jaegeuk Kim <jaegeuk@google.com>
251 lines
9.1 KiB
C
251 lines
9.1 KiB
C
/*
|
|
* fscrypt.h: declarations for per-file encryption
|
|
*
|
|
* Filesystems that implement per-file encryption include this header
|
|
* file with the __FS_HAS_ENCRYPTION set according to whether that filesystem
|
|
* is being built with encryption support or not.
|
|
*
|
|
* Copyright (C) 2015, Google, Inc.
|
|
*
|
|
* Written by Michael Halcrow, 2015.
|
|
* Modified by Jaegeuk Kim, 2015.
|
|
*/
|
|
#ifndef _LINUX_FSCRYPT_H
|
|
#define _LINUX_FSCRYPT_H
|
|
|
|
#include <linux/fs.h>
|
|
|
|
#define FS_CRYPTO_BLOCK_SIZE 16
|
|
|
|
struct fscrypt_ctx;
|
|
struct fscrypt_info;
|
|
|
|
struct fscrypt_str {
|
|
unsigned char *name;
|
|
u32 len;
|
|
};
|
|
|
|
struct fscrypt_name {
|
|
const struct qstr *usr_fname;
|
|
struct fscrypt_str disk_name;
|
|
u32 hash;
|
|
u32 minor_hash;
|
|
struct fscrypt_str crypto_buf;
|
|
};
|
|
|
|
#define FSTR_INIT(n, l) { .name = n, .len = l }
|
|
#define FSTR_TO_QSTR(f) QSTR_INIT((f)->name, (f)->len)
|
|
#define fname_name(p) ((p)->disk_name.name)
|
|
#define fname_len(p) ((p)->disk_name.len)
|
|
|
|
#if __FS_HAS_ENCRYPTION
|
|
#include <linux/fscrypt_supp.h>
|
|
#else
|
|
#include <linux/fscrypt_notsupp.h>
|
|
#endif
|
|
|
|
/**
|
|
* fscrypt_require_key - require an inode's encryption key
|
|
* @inode: the inode we need the key for
|
|
*
|
|
* If the inode is encrypted, set up its encryption key if not already done.
|
|
* Then require that the key be present and return -ENOKEY otherwise.
|
|
*
|
|
* No locks are needed, and the key will live as long as the struct inode --- so
|
|
* it won't go away from under you.
|
|
*
|
|
* Return: 0 on success, -ENOKEY if the key is missing, or another -errno code
|
|
* if a problem occurred while setting up the encryption key.
|
|
*/
|
|
static inline int fscrypt_require_key(struct inode *inode)
|
|
{
|
|
if (IS_ENCRYPTED(inode)) {
|
|
int err = fscrypt_get_encryption_info(inode);
|
|
|
|
if (err)
|
|
return err;
|
|
if (!fscrypt_has_encryption_key(inode))
|
|
return -ENOKEY;
|
|
}
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_prepare_link - prepare to link an inode into a possibly-encrypted directory
|
|
* @old_dentry: an existing dentry for the inode being linked
|
|
* @dir: the target directory
|
|
* @dentry: negative dentry for the target filename
|
|
*
|
|
* A new link can only be added to an encrypted directory if the directory's
|
|
* encryption key is available --- since otherwise we'd have no way to encrypt
|
|
* the filename. Therefore, we first set up the directory's encryption key (if
|
|
* not already done) and return an error if it's unavailable.
|
|
*
|
|
* We also verify that the link will not violate the constraint that all files
|
|
* in an encrypted directory tree use the same encryption policy.
|
|
*
|
|
* Return: 0 on success, -ENOKEY if the directory's encryption key is missing,
|
|
* -EPERM if the link would result in an inconsistent encryption policy, or
|
|
* another -errno code.
|
|
*/
|
|
static inline int fscrypt_prepare_link(struct dentry *old_dentry,
|
|
struct inode *dir,
|
|
struct dentry *dentry)
|
|
{
|
|
if (IS_ENCRYPTED(dir))
|
|
return __fscrypt_prepare_link(d_inode(old_dentry), dir);
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_prepare_rename - prepare for a rename between possibly-encrypted directories
|
|
* @old_dir: source directory
|
|
* @old_dentry: dentry for source file
|
|
* @new_dir: target directory
|
|
* @new_dentry: dentry for target location (may be negative unless exchanging)
|
|
* @flags: rename flags (we care at least about %RENAME_EXCHANGE)
|
|
*
|
|
* Prepare for ->rename() where the source and/or target directories may be
|
|
* encrypted. A new link can only be added to an encrypted directory if the
|
|
* directory's encryption key is available --- since otherwise we'd have no way
|
|
* to encrypt the filename. A rename to an existing name, on the other hand,
|
|
* *is* cryptographically possible without the key. However, we take the more
|
|
* conservative approach and just forbid all no-key renames.
|
|
*
|
|
* We also verify that the rename will not violate the constraint that all files
|
|
* in an encrypted directory tree use the same encryption policy.
|
|
*
|
|
* Return: 0 on success, -ENOKEY if an encryption key is missing, -EPERM if the
|
|
* rename would cause inconsistent encryption policies, or another -errno code.
|
|
*/
|
|
static inline int fscrypt_prepare_rename(struct inode *old_dir,
|
|
struct dentry *old_dentry,
|
|
struct inode *new_dir,
|
|
struct dentry *new_dentry,
|
|
unsigned int flags)
|
|
{
|
|
if (IS_ENCRYPTED(old_dir) || IS_ENCRYPTED(new_dir))
|
|
return __fscrypt_prepare_rename(old_dir, old_dentry,
|
|
new_dir, new_dentry, flags);
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_prepare_lookup - prepare to lookup a name in a possibly-encrypted directory
|
|
* @dir: directory being searched
|
|
* @dentry: filename being looked up
|
|
* @flags: lookup flags
|
|
*
|
|
* Prepare for ->lookup() in a directory which may be encrypted. Lookups can be
|
|
* done with or without the directory's encryption key; without the key,
|
|
* filenames are presented in encrypted form. Therefore, we'll try to set up
|
|
* the directory's encryption key, but even without it the lookup can continue.
|
|
*
|
|
* To allow invalidating stale dentries if the directory's encryption key is
|
|
* added later, we also install a custom ->d_revalidate() method and use the
|
|
* DCACHE_ENCRYPTED_WITH_KEY flag to indicate whether a given dentry is a
|
|
* plaintext name (flag set) or a ciphertext name (flag cleared).
|
|
*
|
|
* Return: 0 on success, -errno if a problem occurred while setting up the
|
|
* encryption key
|
|
*/
|
|
static inline int fscrypt_prepare_lookup(struct inode *dir,
|
|
struct dentry *dentry,
|
|
unsigned int flags)
|
|
{
|
|
if (IS_ENCRYPTED(dir))
|
|
return __fscrypt_prepare_lookup(dir, dentry);
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_prepare_setattr - prepare to change a possibly-encrypted inode's attributes
|
|
* @dentry: dentry through which the inode is being changed
|
|
* @attr: attributes to change
|
|
*
|
|
* Prepare for ->setattr() on a possibly-encrypted inode. On an encrypted file,
|
|
* most attribute changes are allowed even without the encryption key. However,
|
|
* without the encryption key we do have to forbid truncates. This is needed
|
|
* because the size being truncated to may not be a multiple of the filesystem
|
|
* block size, and in that case we'd have to decrypt the final block, zero the
|
|
* portion past i_size, and re-encrypt it. (We *could* allow truncating to a
|
|
* filesystem block boundary, but it's simpler to just forbid all truncates ---
|
|
* and we already forbid all other contents modifications without the key.)
|
|
*
|
|
* Return: 0 on success, -ENOKEY if the key is missing, or another -errno code
|
|
* if a problem occurred while setting up the encryption key.
|
|
*/
|
|
static inline int fscrypt_prepare_setattr(struct dentry *dentry,
|
|
struct iattr *attr)
|
|
{
|
|
if (attr->ia_valid & ATTR_SIZE)
|
|
return fscrypt_require_key(d_inode(dentry));
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_prepare_symlink - prepare to create a possibly-encrypted symlink
|
|
* @dir: directory in which the symlink is being created
|
|
* @target: plaintext symlink target
|
|
* @len: length of @target excluding null terminator
|
|
* @max_len: space the filesystem has available to store the symlink target
|
|
* @disk_link: (out) the on-disk symlink target being prepared
|
|
*
|
|
* This function computes the size the symlink target will require on-disk,
|
|
* stores it in @disk_link->len, and validates it against @max_len. An
|
|
* encrypted symlink may be longer than the original.
|
|
*
|
|
* Additionally, @disk_link->name is set to @target if the symlink will be
|
|
* unencrypted, but left NULL if the symlink will be encrypted. For encrypted
|
|
* symlinks, the filesystem must call fscrypt_encrypt_symlink() to create the
|
|
* on-disk target later. (The reason for the two-step process is that some
|
|
* filesystems need to know the size of the symlink target before creating the
|
|
* inode, e.g. to determine whether it will be a "fast" or "slow" symlink.)
|
|
*
|
|
* Return: 0 on success, -ENAMETOOLONG if the symlink target is too long,
|
|
* -ENOKEY if the encryption key is missing, or another -errno code if a problem
|
|
* occurred while setting up the encryption key.
|
|
*/
|
|
static inline int fscrypt_prepare_symlink(struct inode *dir,
|
|
const char *target,
|
|
unsigned int len,
|
|
unsigned int max_len,
|
|
struct fscrypt_str *disk_link)
|
|
{
|
|
if (IS_ENCRYPTED(dir) || fscrypt_dummy_context_enabled(dir))
|
|
return __fscrypt_prepare_symlink(dir, len, max_len, disk_link);
|
|
|
|
disk_link->name = (unsigned char *)target;
|
|
disk_link->len = len + 1;
|
|
if (disk_link->len > max_len)
|
|
return -ENAMETOOLONG;
|
|
return 0;
|
|
}
|
|
|
|
/**
|
|
* fscrypt_encrypt_symlink - encrypt the symlink target if needed
|
|
* @inode: symlink inode
|
|
* @target: plaintext symlink target
|
|
* @len: length of @target excluding null terminator
|
|
* @disk_link: (in/out) the on-disk symlink target being prepared
|
|
*
|
|
* If the symlink target needs to be encrypted, then this function encrypts it
|
|
* into @disk_link->name. fscrypt_prepare_symlink() must have been called
|
|
* previously to compute @disk_link->len. If the filesystem did not allocate a
|
|
* buffer for @disk_link->name after calling fscrypt_prepare_link(), then one
|
|
* will be kmalloc()'ed and the filesystem will be responsible for freeing it.
|
|
*
|
|
* Return: 0 on success, -errno on failure
|
|
*/
|
|
static inline int fscrypt_encrypt_symlink(struct inode *inode,
|
|
const char *target,
|
|
unsigned int len,
|
|
struct fscrypt_str *disk_link)
|
|
{
|
|
if (IS_ENCRYPTED(inode))
|
|
return __fscrypt_encrypt_symlink(inode, target, len, disk_link);
|
|
return 0;
|
|
}
|
|
|
|
#endif /* _LINUX_FSCRYPT_H */
|