blob: d8b5bfcbdd30b027aae6c9eae937b566b7b2043d [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001#include <linux/reiserfs_fs.h>
2#include <linux/errno.h>
3#include <linux/fs.h>
4#include <linux/pagemap.h>
5#include <linux/xattr.h>
6#include <linux/reiserfs_xattr.h>
Jeff Mahoney57fe60d2009-03-30 14:02:41 -04007#include <linux/security.h>
Linus Torvalds1da177e2005-04-16 15:20:36 -07008#include <asm/uaccess.h>
9
Linus Torvalds1da177e2005-04-16 15:20:36 -070010static int
Christoph Hellwig431547b2009-11-13 09:52:56 +000011security_get(struct dentry *dentry, const char *name, void *buffer, size_t size,
12 int handler_flags)
Linus Torvalds1da177e2005-04-16 15:20:36 -070013{
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070014 if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX))
15 return -EINVAL;
Linus Torvalds1da177e2005-04-16 15:20:36 -070016
Christoph Hellwig431547b2009-11-13 09:52:56 +000017 if (IS_PRIVATE(dentry->d_inode))
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070018 return -EPERM;
Linus Torvalds1da177e2005-04-16 15:20:36 -070019
Christoph Hellwig431547b2009-11-13 09:52:56 +000020 return reiserfs_xattr_get(dentry->d_inode, name, buffer, size);
Linus Torvalds1da177e2005-04-16 15:20:36 -070021}
22
23static int
Christoph Hellwig431547b2009-11-13 09:52:56 +000024security_set(struct dentry *dentry, const char *name, const void *buffer,
25 size_t size, int flags, int handler_flags)
Linus Torvalds1da177e2005-04-16 15:20:36 -070026{
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070027 if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX))
28 return -EINVAL;
Linus Torvalds1da177e2005-04-16 15:20:36 -070029
Christoph Hellwig431547b2009-11-13 09:52:56 +000030 if (IS_PRIVATE(dentry->d_inode))
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070031 return -EPERM;
Linus Torvalds1da177e2005-04-16 15:20:36 -070032
Christoph Hellwig431547b2009-11-13 09:52:56 +000033 return reiserfs_xattr_set(dentry->d_inode, name, buffer, size, flags);
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070034}
35
Christoph Hellwig431547b2009-11-13 09:52:56 +000036static size_t security_list(struct dentry *dentry, char *list, size_t list_len,
37 const char *name, size_t namelen, int handler_flags)
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070038{
Jeff Mahoney48b32a32009-03-30 14:02:38 -040039 const size_t len = namelen + 1;
Linus Torvalds1da177e2005-04-16 15:20:36 -070040
Christoph Hellwig431547b2009-11-13 09:52:56 +000041 if (IS_PRIVATE(dentry->d_inode))
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070042 return 0;
Linus Torvalds1da177e2005-04-16 15:20:36 -070043
Jeff Mahoney48b32a32009-03-30 14:02:38 -040044 if (list && len <= list_len) {
45 memcpy(list, name, namelen);
46 list[namelen] = '\0';
47 }
Linus Torvaldsbd4c6252005-07-12 20:21:28 -070048
49 return len;
Linus Torvalds1da177e2005-04-16 15:20:36 -070050}
51
Jeff Mahoney57fe60d2009-03-30 14:02:41 -040052/* Initializes the security context for a new inode and returns the number
53 * of blocks needed for the transaction. If successful, reiserfs_security
54 * must be released using reiserfs_security_free when the caller is done. */
55int reiserfs_security_init(struct inode *dir, struct inode *inode,
56 struct reiserfs_security_handle *sec)
57{
58 int blocks = 0;
Jeff Mahoneyb82bb722009-05-05 15:30:16 -040059 int error;
60
61 sec->name = NULL;
62
63 /* Don't add selinux attributes on xattrs - they'll never get used */
64 if (IS_PRIVATE(dir))
65 return 0;
66
67 error = security_inode_init_security(inode, dir, &sec->name,
68 &sec->value, &sec->length);
Jeff Mahoney57fe60d2009-03-30 14:02:41 -040069 if (error) {
70 if (error == -EOPNOTSUPP)
71 error = 0;
72
73 sec->name = NULL;
74 sec->value = NULL;
75 sec->length = 0;
76 return error;
77 }
78
79 if (sec->length) {
80 blocks = reiserfs_xattr_jcreate_nblocks(inode) +
81 reiserfs_xattr_nblocks(inode, sec->length);
82 /* We don't want to count the directories twice if we have
83 * a default ACL. */
84 REISERFS_I(inode)->i_flags |= i_has_xattr_dir;
85 }
86 return blocks;
87}
88
89int reiserfs_security_write(struct reiserfs_transaction_handle *th,
90 struct inode *inode,
91 struct reiserfs_security_handle *sec)
92{
93 int error;
94 if (strlen(sec->name) < sizeof(XATTR_SECURITY_PREFIX))
95 return -EINVAL;
96
97 error = reiserfs_xattr_set_handle(th, inode, sec->name, sec->value,
98 sec->length, XATTR_CREATE);
99 if (error == -ENODATA || error == -EOPNOTSUPP)
100 error = 0;
101
102 return error;
103}
104
105void reiserfs_security_free(struct reiserfs_security_handle *sec)
106{
107 kfree(sec->name);
108 kfree(sec->value);
109 sec->name = NULL;
110 sec->value = NULL;
111}
112
Jeff Mahoney48b32a32009-03-30 14:02:38 -0400113struct xattr_handler reiserfs_xattr_security_handler = {
Linus Torvalds1da177e2005-04-16 15:20:36 -0700114 .prefix = XATTR_SECURITY_PREFIX,
115 .get = security_get,
116 .set = security_set,
Linus Torvalds1da177e2005-04-16 15:20:36 -0700117 .list = security_list,
118};