autofs4 - fix autofs4_expire_indirect() traversal
[firefly-linux-kernel-4.4.55.git] / fs / autofs4 / expire.c
1 /* -*- c -*- --------------------------------------------------------------- *
2  *
3  * linux/fs/autofs/expire.c
4  *
5  *  Copyright 1997-1998 Transmeta Corporation -- All Rights Reserved
6  *  Copyright 1999-2000 Jeremy Fitzhardinge <jeremy@goop.org>
7  *  Copyright 2001-2006 Ian Kent <raven@themaw.net>
8  *
9  * This file is part of the Linux kernel and is made available under
10  * the terms of the GNU General Public License, version 2, or at your
11  * option, any later version, incorporated herein by reference.
12  *
13  * ------------------------------------------------------------------------- */
14
15 #include "autofs_i.h"
16
17 static unsigned long now;
18
19 /* Check if a dentry can be expired */
20 static inline int autofs4_can_expire(struct dentry *dentry,
21                                         unsigned long timeout, int do_now)
22 {
23         struct autofs_info *ino = autofs4_dentry_ino(dentry);
24
25         /* dentry in the process of being deleted */
26         if (ino == NULL)
27                 return 0;
28
29         if (!do_now) {
30                 /* Too young to die */
31                 if (!timeout || time_after(ino->last_used + timeout, now))
32                         return 0;
33
34                 /* update last_used here :-
35                    - obviously makes sense if it is in use now
36                    - less obviously, prevents rapid-fire expire
37                      attempts if expire fails the first time */
38                 ino->last_used = now;
39         }
40         return 1;
41 }
42
43 /* Check a mount point for busyness */
44 static int autofs4_mount_busy(struct vfsmount *mnt, struct dentry *dentry)
45 {
46         struct dentry *top = dentry;
47         struct path path = {.mnt = mnt, .dentry = dentry};
48         int status = 1;
49
50         DPRINTK("dentry %p %.*s",
51                 dentry, (int)dentry->d_name.len, dentry->d_name.name);
52
53         path_get(&path);
54
55         if (!follow_down_one(&path))
56                 goto done;
57
58         if (is_autofs4_dentry(path.dentry)) {
59                 struct autofs_sb_info *sbi = autofs4_sbi(path.dentry->d_sb);
60
61                 /* This is an autofs submount, we can't expire it */
62                 if (autofs_type_indirect(sbi->type))
63                         goto done;
64
65                 /*
66                  * Otherwise it's an offset mount and we need to check
67                  * if we can umount its mount, if there is one.
68                  */
69                 if (!d_mountpoint(path.dentry)) {
70                         status = 0;
71                         goto done;
72                 }
73         }
74
75         /* Update the expiry counter if fs is busy */
76         if (!may_umount_tree(path.mnt)) {
77                 struct autofs_info *ino = autofs4_dentry_ino(top);
78                 ino->last_used = jiffies;
79                 goto done;
80         }
81
82         status = 0;
83 done:
84         DPRINTK("returning = %d", status);
85         path_put(&path);
86         return status;
87 }
88
89 /*
90  * Calculate and dget next entry in the subdirs list under root.
91  */
92 static struct dentry *get_next_positive_subdir(struct dentry *prev,
93                                                 struct dentry *root)
94 {
95         struct list_head *next;
96         struct dentry *p, *q;
97
98         spin_lock(&autofs4_lock);
99
100         if (prev == NULL) {
101                 spin_lock(&root->d_lock);
102                 prev = dget_dlock(root);
103                 next = prev->d_subdirs.next;
104                 p = prev;
105                 goto start;
106         }
107
108         p = prev;
109         spin_lock(&p->d_lock);
110 again:
111         next = p->d_u.d_child.next;
112 start:
113         if (next == &root->d_subdirs) {
114                 spin_unlock(&p->d_lock);
115                 spin_unlock(&autofs4_lock);
116                 dput(prev);
117                 return NULL;
118         }
119
120         q = list_entry(next, struct dentry, d_u.d_child);
121
122         spin_lock_nested(&q->d_lock, DENTRY_D_LOCK_NESTED);
123         /* Negative dentry - try next */
124         if (!simple_positive(q)) {
125                 spin_unlock(&p->d_lock);
126                 p = q;
127                 goto again;
128         }
129         dget_dlock(q);
130         spin_unlock(&q->d_lock);
131         spin_unlock(&p->d_lock);
132         spin_unlock(&autofs4_lock);
133
134         dput(prev);
135
136         return q;
137 }
138
139 /*
140  * Calculate and dget next entry in top down tree traversal.
141  */
142 static struct dentry *get_next_positive_dentry(struct dentry *prev,
143                                                 struct dentry *root)
144 {
145         struct list_head *next;
146         struct dentry *p, *ret;
147
148         if (prev == NULL)
149                 return dget(root);
150
151         spin_lock(&autofs4_lock);
152 relock:
153         p = prev;
154         spin_lock(&p->d_lock);
155 again:
156         next = p->d_subdirs.next;
157         if (next == &p->d_subdirs) {
158                 while (1) {
159                         struct dentry *parent;
160
161                         if (p == root) {
162                                 spin_unlock(&p->d_lock);
163                                 spin_unlock(&autofs4_lock);
164                                 dput(prev);
165                                 return NULL;
166                         }
167
168                         parent = p->d_parent;
169                         if (!spin_trylock(&parent->d_lock)) {
170                                 spin_unlock(&p->d_lock);
171                                 cpu_relax();
172                                 goto relock;
173                         }
174                         spin_unlock(&p->d_lock);
175                         next = p->d_u.d_child.next;
176                         p = parent;
177                         if (next != &parent->d_subdirs)
178                                 break;
179                 }
180         }
181         ret = list_entry(next, struct dentry, d_u.d_child);
182
183         spin_lock_nested(&ret->d_lock, DENTRY_D_LOCK_NESTED);
184         /* Negative dentry - try next */
185         if (!simple_positive(ret)) {
186                 spin_unlock(&p->d_lock);
187                 p = ret;
188                 goto again;
189         }
190         dget_dlock(ret);
191         spin_unlock(&ret->d_lock);
192         spin_unlock(&p->d_lock);
193         spin_unlock(&autofs4_lock);
194
195         dput(prev);
196
197         return ret;
198 }
199
200 /*
201  * Check a direct mount point for busyness.
202  * Direct mounts have similar expiry semantics to tree mounts.
203  * The tree is not busy iff no mountpoints are busy and there are no
204  * autofs submounts.
205  */
206 static int autofs4_direct_busy(struct vfsmount *mnt,
207                                 struct dentry *top,
208                                 unsigned long timeout,
209                                 int do_now)
210 {
211         DPRINTK("top %p %.*s",
212                 top, (int) top->d_name.len, top->d_name.name);
213
214         /* If it's busy update the expiry counters */
215         if (!may_umount_tree(mnt)) {
216                 struct autofs_info *ino = autofs4_dentry_ino(top);
217                 if (ino)
218                         ino->last_used = jiffies;
219                 return 1;
220         }
221
222         /* Timeout of a direct mount is determined by its top dentry */
223         if (!autofs4_can_expire(top, timeout, do_now))
224                 return 1;
225
226         return 0;
227 }
228
229 /* Check a directory tree of mount points for busyness
230  * The tree is not busy iff no mountpoints are busy
231  */
232 static int autofs4_tree_busy(struct vfsmount *mnt,
233                              struct dentry *top,
234                              unsigned long timeout,
235                              int do_now)
236 {
237         struct autofs_info *top_ino = autofs4_dentry_ino(top);
238         struct dentry *p;
239
240         DPRINTK("top %p %.*s",
241                 top, (int)top->d_name.len, top->d_name.name);
242
243         /* Negative dentry - give up */
244         if (!simple_positive(top))
245                 return 1;
246
247         p = NULL;
248         while ((p = get_next_positive_dentry(p, top))) {
249                 DPRINTK("dentry %p %.*s",
250                         p, (int) p->d_name.len, p->d_name.name);
251
252                 /*
253                  * Is someone visiting anywhere in the subtree ?
254                  * If there's no mount we need to check the usage
255                  * count for the autofs dentry.
256                  * If the fs is busy update the expiry counter.
257                  */
258                 if (d_mountpoint(p)) {
259                         if (autofs4_mount_busy(mnt, p)) {
260                                 top_ino->last_used = jiffies;
261                                 dput(p);
262                                 return 1;
263                         }
264                 } else {
265                         struct autofs_info *ino = autofs4_dentry_ino(p);
266                         unsigned int ino_count = atomic_read(&ino->count);
267
268                         /*
269                          * Clean stale dentries below that have not been
270                          * invalidated after a mount fail during lookup
271                          */
272                         d_invalidate(p);
273
274                         /* allow for dget above and top is already dgot */
275                         if (p == top)
276                                 ino_count += 2;
277                         else
278                                 ino_count++;
279
280                         if (p->d_count > ino_count) {
281                                 top_ino->last_used = jiffies;
282                                 dput(p);
283                                 return 1;
284                         }
285                 }
286         }
287
288         /* Timeout of a tree mount is ultimately determined by its top dentry */
289         if (!autofs4_can_expire(top, timeout, do_now))
290                 return 1;
291
292         return 0;
293 }
294
295 static struct dentry *autofs4_check_leaves(struct vfsmount *mnt,
296                                            struct dentry *parent,
297                                            unsigned long timeout,
298                                            int do_now)
299 {
300         struct dentry *p;
301
302         DPRINTK("parent %p %.*s",
303                 parent, (int)parent->d_name.len, parent->d_name.name);
304
305         p = NULL;
306         while ((p = get_next_positive_dentry(p, parent))) {
307                 DPRINTK("dentry %p %.*s",
308                         p, (int) p->d_name.len, p->d_name.name);
309
310                 if (d_mountpoint(p)) {
311                         /* Can we umount this guy */
312                         if (autofs4_mount_busy(mnt, p))
313                                 continue;
314
315                         /* Can we expire this guy */
316                         if (autofs4_can_expire(p, timeout, do_now))
317                                 return p;
318                 }
319         }
320         return NULL;
321 }
322
323 /* Check if we can expire a direct mount (possibly a tree) */
324 struct dentry *autofs4_expire_direct(struct super_block *sb,
325                                      struct vfsmount *mnt,
326                                      struct autofs_sb_info *sbi,
327                                      int how)
328 {
329         unsigned long timeout;
330         struct dentry *root = dget(sb->s_root);
331         int do_now = how & AUTOFS_EXP_IMMEDIATE;
332         struct autofs_info *ino;
333
334         if (!root)
335                 return NULL;
336
337         now = jiffies;
338         timeout = sbi->exp_timeout;
339
340         spin_lock(&sbi->fs_lock);
341         ino = autofs4_dentry_ino(root);
342         /* No point expiring a pending mount */
343         if (ino->flags & AUTOFS_INF_PENDING)
344                 goto out;
345         if (!autofs4_direct_busy(mnt, root, timeout, do_now)) {
346                 struct autofs_info *ino = autofs4_dentry_ino(root);
347                 ino->flags |= AUTOFS_INF_EXPIRING;
348                 init_completion(&ino->expire_complete);
349                 spin_unlock(&sbi->fs_lock);
350                 return root;
351         }
352 out:
353         spin_unlock(&sbi->fs_lock);
354         dput(root);
355
356         return NULL;
357 }
358
359 /*
360  * Find an eligible tree to time-out
361  * A tree is eligible if :-
362  *  - it is unused by any user process
363  *  - it has been unused for exp_timeout time
364  */
365 struct dentry *autofs4_expire_indirect(struct super_block *sb,
366                                        struct vfsmount *mnt,
367                                        struct autofs_sb_info *sbi,
368                                        int how)
369 {
370         unsigned long timeout;
371         struct dentry *root = sb->s_root;
372         struct dentry *dentry;
373         struct dentry *expired = NULL;
374         int do_now = how & AUTOFS_EXP_IMMEDIATE;
375         int exp_leaves = how & AUTOFS_EXP_LEAVES;
376         struct autofs_info *ino;
377         unsigned int ino_count;
378
379         if (!root)
380                 return NULL;
381
382         now = jiffies;
383         timeout = sbi->exp_timeout;
384
385         dentry = NULL;
386         while ((dentry = get_next_positive_subdir(dentry, root))) {
387                 spin_lock(&sbi->fs_lock);
388                 ino = autofs4_dentry_ino(dentry);
389                 /* No point expiring a pending mount */
390                 if (ino->flags & AUTOFS_INF_PENDING)
391                         goto next;
392
393                 /*
394                  * Case 1: (i) indirect mount or top level pseudo direct mount
395                  *         (autofs-4.1).
396                  *         (ii) indirect mount with offset mount, check the "/"
397                  *         offset (autofs-5.0+).
398                  */
399                 if (d_mountpoint(dentry)) {
400                         DPRINTK("checking mountpoint %p %.*s",
401                                 dentry, (int)dentry->d_name.len, dentry->d_name.name);
402
403                         /* Path walk currently on this dentry? */
404                         ino_count = atomic_read(&ino->count) + 2;
405                         if (dentry->d_count > ino_count)
406                                 goto next;
407
408                         /* Can we umount this guy */
409                         if (autofs4_mount_busy(mnt, dentry))
410                                 goto next;
411
412                         /* Can we expire this guy */
413                         if (autofs4_can_expire(dentry, timeout, do_now)) {
414                                 expired = dentry;
415                                 goto found;
416                         }
417                         goto next;
418                 }
419
420                 if (simple_empty(dentry))
421                         goto next;
422
423                 /* Case 2: tree mount, expire iff entire tree is not busy */
424                 if (!exp_leaves) {
425                         /* Path walk currently on this dentry? */
426                         ino_count = atomic_read(&ino->count) + 1;
427                         if (dentry->d_count > ino_count)
428                                 goto next;
429
430                         if (!autofs4_tree_busy(mnt, dentry, timeout, do_now)) {
431                                 expired = dentry;
432                                 goto found;
433                         }
434                 /*
435                  * Case 3: pseudo direct mount, expire individual leaves
436                  *         (autofs-4.1).
437                  */
438                 } else {
439                         /* Path walk currently on this dentry? */
440                         ino_count = atomic_read(&ino->count) + 1;
441                         if (dentry->d_count > ino_count)
442                                 goto next;
443
444                         expired = autofs4_check_leaves(mnt, dentry, timeout, do_now);
445                         if (expired) {
446                                 dput(dentry);
447                                 goto found;
448                         }
449                 }
450 next:
451                 spin_unlock(&sbi->fs_lock);
452         }
453         return NULL;
454
455 found:
456         DPRINTK("returning %p %.*s",
457                 expired, (int)expired->d_name.len, expired->d_name.name);
458         ino = autofs4_dentry_ino(expired);
459         ino->flags |= AUTOFS_INF_EXPIRING;
460         init_completion(&ino->expire_complete);
461         spin_unlock(&sbi->fs_lock);
462         spin_lock(&autofs4_lock);
463         spin_lock(&expired->d_parent->d_lock);
464         spin_lock_nested(&expired->d_lock, DENTRY_D_LOCK_NESTED);
465         list_move(&expired->d_parent->d_subdirs, &expired->d_u.d_child);
466         spin_unlock(&expired->d_lock);
467         spin_unlock(&expired->d_parent->d_lock);
468         spin_unlock(&autofs4_lock);
469         return expired;
470 }
471
472 int autofs4_expire_wait(struct dentry *dentry)
473 {
474         struct autofs_sb_info *sbi = autofs4_sbi(dentry->d_sb);
475         struct autofs_info *ino = autofs4_dentry_ino(dentry);
476         int status;
477
478         /* Block on any pending expire */
479         spin_lock(&sbi->fs_lock);
480         if (ino->flags & AUTOFS_INF_EXPIRING) {
481                 spin_unlock(&sbi->fs_lock);
482
483                 DPRINTK("waiting for expire %p name=%.*s",
484                          dentry, dentry->d_name.len, dentry->d_name.name);
485
486                 status = autofs4_wait(sbi, dentry, NFY_NONE);
487                 wait_for_completion(&ino->expire_complete);
488
489                 DPRINTK("expire done status=%d", status);
490
491                 if (d_unhashed(dentry))
492                         return -EAGAIN;
493
494                 return status;
495         }
496         spin_unlock(&sbi->fs_lock);
497
498         return 0;
499 }
500
501 /* Perform an expiry operation */
502 int autofs4_expire_run(struct super_block *sb,
503                       struct vfsmount *mnt,
504                       struct autofs_sb_info *sbi,
505                       struct autofs_packet_expire __user *pkt_p)
506 {
507         struct autofs_packet_expire pkt;
508         struct autofs_info *ino;
509         struct dentry *dentry;
510         int ret = 0;
511
512         memset(&pkt,0,sizeof pkt);
513
514         pkt.hdr.proto_version = sbi->version;
515         pkt.hdr.type = autofs_ptype_expire;
516
517         if ((dentry = autofs4_expire_indirect(sb, mnt, sbi, 0)) == NULL)
518                 return -EAGAIN;
519
520         pkt.len = dentry->d_name.len;
521         memcpy(pkt.name, dentry->d_name.name, pkt.len);
522         pkt.name[pkt.len] = '\0';
523         dput(dentry);
524
525         if ( copy_to_user(pkt_p, &pkt, sizeof(struct autofs_packet_expire)) )
526                 ret = -EFAULT;
527
528         spin_lock(&sbi->fs_lock);
529         ino = autofs4_dentry_ino(dentry);
530         ino->flags &= ~AUTOFS_INF_EXPIRING;
531         complete_all(&ino->expire_complete);
532         spin_unlock(&sbi->fs_lock);
533
534         return ret;
535 }
536
537 int autofs4_do_expire_multi(struct super_block *sb, struct vfsmount *mnt,
538                             struct autofs_sb_info *sbi, int when)
539 {
540         struct dentry *dentry;
541         int ret = -EAGAIN;
542
543         if (autofs_type_trigger(sbi->type))
544                 dentry = autofs4_expire_direct(sb, mnt, sbi, when);
545         else
546                 dentry = autofs4_expire_indirect(sb, mnt, sbi, when);
547
548         if (dentry) {
549                 struct autofs_info *ino = autofs4_dentry_ino(dentry);
550
551                 /* This is synchronous because it makes the daemon a
552                    little easier */
553                 ret = autofs4_wait(sbi, dentry, NFY_EXPIRE);
554
555                 spin_lock(&sbi->fs_lock);
556                 ino->flags &= ~AUTOFS_INF_EXPIRING;
557                 spin_lock(&dentry->d_lock);
558                 if (!ret) {
559                         if ((IS_ROOT(dentry) ||
560                             (autofs_type_indirect(sbi->type) &&
561                              IS_ROOT(dentry->d_parent))) &&
562                             !(dentry->d_flags & DCACHE_NEED_AUTOMOUNT))
563                                 __managed_dentry_set_automount(dentry);
564                 }
565                 spin_unlock(&dentry->d_lock);
566                 complete_all(&ino->expire_complete);
567                 spin_unlock(&sbi->fs_lock);
568                 dput(dentry);
569         }
570
571         return ret;
572 }
573
574 /* Call repeatedly until it returns -EAGAIN, meaning there's nothing
575    more to be done */
576 int autofs4_expire_multi(struct super_block *sb, struct vfsmount *mnt,
577                         struct autofs_sb_info *sbi, int __user *arg)
578 {
579         int do_now = 0;
580
581         if (arg && get_user(do_now, arg))
582                 return -EFAULT;
583
584         return autofs4_do_expire_multi(sb, mnt, sbi, do_now);
585 }
586