]> Git Repo - linux.git/blob - fs/cifs/link.c
vc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF
[linux.git] / fs / cifs / link.c
1 // SPDX-License-Identifier: LGPL-2.1
2 /*
3  *
4  *   Copyright (C) International Business Machines  Corp., 2002,2008
5  *   Author(s): Steve French ([email protected])
6  *
7  */
8 #include <linux/fs.h>
9 #include <linux/stat.h>
10 #include <linux/slab.h>
11 #include <linux/namei.h>
12 #include "cifsfs.h"
13 #include "cifspdu.h"
14 #include "cifsglob.h"
15 #include "cifsproto.h"
16 #include "cifs_debug.h"
17 #include "cifs_fs_sb.h"
18 #include "cifs_unicode.h"
19 #include "smb2proto.h"
20 #include "cifs_ioctl.h"
21
22 /*
23  * M-F Symlink Functions - Begin
24  */
25
26 #define CIFS_MF_SYMLINK_LEN_OFFSET (4+1)
27 #define CIFS_MF_SYMLINK_MD5_OFFSET (CIFS_MF_SYMLINK_LEN_OFFSET+(4+1))
28 #define CIFS_MF_SYMLINK_LINK_OFFSET (CIFS_MF_SYMLINK_MD5_OFFSET+(32+1))
29 #define CIFS_MF_SYMLINK_LINK_MAXLEN (1024)
30 #define CIFS_MF_SYMLINK_FILE_SIZE \
31         (CIFS_MF_SYMLINK_LINK_OFFSET + CIFS_MF_SYMLINK_LINK_MAXLEN)
32
33 #define CIFS_MF_SYMLINK_LEN_FORMAT "XSym\n%04u\n"
34 #define CIFS_MF_SYMLINK_MD5_FORMAT "%16phN\n"
35 #define CIFS_MF_SYMLINK_MD5_ARGS(md5_hash) md5_hash
36
37 static int
38 symlink_hash(unsigned int link_len, const char *link_str, u8 *md5_hash)
39 {
40         int rc;
41         struct shash_desc *md5 = NULL;
42
43         rc = cifs_alloc_hash("md5", &md5);
44         if (rc)
45                 goto symlink_hash_err;
46
47         rc = crypto_shash_init(md5);
48         if (rc) {
49                 cifs_dbg(VFS, "%s: Could not init md5 shash\n", __func__);
50                 goto symlink_hash_err;
51         }
52         rc = crypto_shash_update(md5, link_str, link_len);
53         if (rc) {
54                 cifs_dbg(VFS, "%s: Could not update with link_str\n", __func__);
55                 goto symlink_hash_err;
56         }
57         rc = crypto_shash_final(md5, md5_hash);
58         if (rc)
59                 cifs_dbg(VFS, "%s: Could not generate md5 hash\n", __func__);
60
61 symlink_hash_err:
62         cifs_free_hash(&md5);
63         return rc;
64 }
65
66 static int
67 parse_mf_symlink(const u8 *buf, unsigned int buf_len, unsigned int *_link_len,
68                  char **_link_str)
69 {
70         int rc;
71         unsigned int link_len;
72         const char *md5_str1;
73         const char *link_str;
74         u8 md5_hash[16];
75         char md5_str2[34];
76
77         if (buf_len != CIFS_MF_SYMLINK_FILE_SIZE)
78                 return -EINVAL;
79
80         md5_str1 = (const char *)&buf[CIFS_MF_SYMLINK_MD5_OFFSET];
81         link_str = (const char *)&buf[CIFS_MF_SYMLINK_LINK_OFFSET];
82
83         rc = sscanf(buf, CIFS_MF_SYMLINK_LEN_FORMAT, &link_len);
84         if (rc != 1)
85                 return -EINVAL;
86
87         if (link_len > CIFS_MF_SYMLINK_LINK_MAXLEN)
88                 return -EINVAL;
89
90         rc = symlink_hash(link_len, link_str, md5_hash);
91         if (rc) {
92                 cifs_dbg(FYI, "%s: MD5 hash failure: %d\n", __func__, rc);
93                 return rc;
94         }
95
96         scnprintf(md5_str2, sizeof(md5_str2),
97                   CIFS_MF_SYMLINK_MD5_FORMAT,
98                   CIFS_MF_SYMLINK_MD5_ARGS(md5_hash));
99
100         if (strncmp(md5_str1, md5_str2, 17) != 0)
101                 return -EINVAL;
102
103         if (_link_str) {
104                 *_link_str = kstrndup(link_str, link_len, GFP_KERNEL);
105                 if (!*_link_str)
106                         return -ENOMEM;
107         }
108
109         *_link_len = link_len;
110         return 0;
111 }
112
113 static int
114 format_mf_symlink(u8 *buf, unsigned int buf_len, const char *link_str)
115 {
116         int rc;
117         unsigned int link_len;
118         unsigned int ofs;
119         u8 md5_hash[16];
120
121         if (buf_len != CIFS_MF_SYMLINK_FILE_SIZE)
122                 return -EINVAL;
123
124         link_len = strlen(link_str);
125
126         if (link_len > CIFS_MF_SYMLINK_LINK_MAXLEN)
127                 return -ENAMETOOLONG;
128
129         rc = symlink_hash(link_len, link_str, md5_hash);
130         if (rc) {
131                 cifs_dbg(FYI, "%s: MD5 hash failure: %d\n", __func__, rc);
132                 return rc;
133         }
134
135         scnprintf(buf, buf_len,
136                   CIFS_MF_SYMLINK_LEN_FORMAT CIFS_MF_SYMLINK_MD5_FORMAT,
137                   link_len,
138                   CIFS_MF_SYMLINK_MD5_ARGS(md5_hash));
139
140         ofs = CIFS_MF_SYMLINK_LINK_OFFSET;
141         memcpy(buf + ofs, link_str, link_len);
142
143         ofs += link_len;
144         if (ofs < CIFS_MF_SYMLINK_FILE_SIZE) {
145                 buf[ofs] = '\n';
146                 ofs++;
147         }
148
149         while (ofs < CIFS_MF_SYMLINK_FILE_SIZE) {
150                 buf[ofs] = ' ';
151                 ofs++;
152         }
153
154         return 0;
155 }
156
157 bool
158 couldbe_mf_symlink(const struct cifs_fattr *fattr)
159 {
160         if (!S_ISREG(fattr->cf_mode))
161                 /* it's not a symlink */
162                 return false;
163
164         if (fattr->cf_eof != CIFS_MF_SYMLINK_FILE_SIZE)
165                 /* it's not a symlink */
166                 return false;
167
168         return true;
169 }
170
171 static int
172 create_mf_symlink(const unsigned int xid, struct cifs_tcon *tcon,
173                   struct cifs_sb_info *cifs_sb, const char *fromName,
174                   const char *toName)
175 {
176         int rc;
177         u8 *buf;
178         unsigned int bytes_written = 0;
179
180         buf = kmalloc(CIFS_MF_SYMLINK_FILE_SIZE, GFP_KERNEL);
181         if (!buf)
182                 return -ENOMEM;
183
184         rc = format_mf_symlink(buf, CIFS_MF_SYMLINK_FILE_SIZE, toName);
185         if (rc)
186                 goto out;
187
188         if (tcon->ses->server->ops->create_mf_symlink)
189                 rc = tcon->ses->server->ops->create_mf_symlink(xid, tcon,
190                                         cifs_sb, fromName, buf, &bytes_written);
191         else
192                 rc = -EOPNOTSUPP;
193
194         if (rc)
195                 goto out;
196
197         if (bytes_written != CIFS_MF_SYMLINK_FILE_SIZE)
198                 rc = -EIO;
199 out:
200         kfree(buf);
201         return rc;
202 }
203
204 int
205 check_mf_symlink(unsigned int xid, struct cifs_tcon *tcon,
206                  struct cifs_sb_info *cifs_sb, struct cifs_fattr *fattr,
207                  const unsigned char *path)
208 {
209         int rc;
210         u8 *buf = NULL;
211         unsigned int link_len = 0;
212         unsigned int bytes_read = 0;
213         char *symlink = NULL;
214
215         if (!couldbe_mf_symlink(fattr))
216                 /* it's not a symlink */
217                 return 0;
218
219         buf = kmalloc(CIFS_MF_SYMLINK_FILE_SIZE, GFP_KERNEL);
220         if (!buf)
221                 return -ENOMEM;
222
223         if (tcon->ses->server->ops->query_mf_symlink)
224                 rc = tcon->ses->server->ops->query_mf_symlink(xid, tcon,
225                                               cifs_sb, path, buf, &bytes_read);
226         else
227                 rc = -ENOSYS;
228
229         if (rc)
230                 goto out;
231
232         if (bytes_read == 0) /* not a symlink */
233                 goto out;
234
235         rc = parse_mf_symlink(buf, bytes_read, &link_len, &symlink);
236         if (rc == -EINVAL) {
237                 /* it's not a symlink */
238                 rc = 0;
239                 goto out;
240         }
241
242         if (rc != 0)
243                 goto out;
244
245         /* it is a symlink */
246         fattr->cf_eof = link_len;
247         fattr->cf_mode &= ~S_IFMT;
248         fattr->cf_mode |= S_IFLNK | S_IRWXU | S_IRWXG | S_IRWXO;
249         fattr->cf_dtype = DT_LNK;
250         fattr->cf_symlink_target = symlink;
251 out:
252         kfree(buf);
253         return rc;
254 }
255
256 #ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
257 /*
258  * SMB 1.0 Protocol specific functions
259  */
260
261 int
262 cifs_query_mf_symlink(unsigned int xid, struct cifs_tcon *tcon,
263                       struct cifs_sb_info *cifs_sb, const unsigned char *path,
264                       char *pbuf, unsigned int *pbytes_read)
265 {
266         int rc;
267         int oplock = 0;
268         struct cifs_fid fid;
269         struct cifs_open_parms oparms;
270         struct cifs_io_parms io_parms = {0};
271         int buf_type = CIFS_NO_BUFFER;
272         FILE_ALL_INFO file_info;
273
274         oparms.tcon = tcon;
275         oparms.cifs_sb = cifs_sb;
276         oparms.desired_access = GENERIC_READ;
277         oparms.create_options = cifs_create_options(cifs_sb, CREATE_NOT_DIR);
278         oparms.disposition = FILE_OPEN;
279         oparms.path = path;
280         oparms.fid = &fid;
281         oparms.reconnect = false;
282
283         rc = CIFS_open(xid, &oparms, &oplock, &file_info);
284         if (rc)
285                 return rc;
286
287         if (file_info.EndOfFile != cpu_to_le64(CIFS_MF_SYMLINK_FILE_SIZE)) {
288                 rc = -ENOENT;
289                 /* it's not a symlink */
290                 goto out;
291         }
292
293         io_parms.netfid = fid.netfid;
294         io_parms.pid = current->tgid;
295         io_parms.tcon = tcon;
296         io_parms.offset = 0;
297         io_parms.length = CIFS_MF_SYMLINK_FILE_SIZE;
298
299         rc = CIFSSMBRead(xid, &io_parms, pbytes_read, &pbuf, &buf_type);
300 out:
301         CIFSSMBClose(xid, tcon, fid.netfid);
302         return rc;
303 }
304
305 int
306 cifs_create_mf_symlink(unsigned int xid, struct cifs_tcon *tcon,
307                        struct cifs_sb_info *cifs_sb, const unsigned char *path,
308                        char *pbuf, unsigned int *pbytes_written)
309 {
310         int rc;
311         int oplock = 0;
312         struct cifs_fid fid;
313         struct cifs_open_parms oparms;
314         struct cifs_io_parms io_parms = {0};
315
316         oparms.tcon = tcon;
317         oparms.cifs_sb = cifs_sb;
318         oparms.desired_access = GENERIC_WRITE;
319         oparms.create_options = cifs_create_options(cifs_sb, CREATE_NOT_DIR);
320         oparms.disposition = FILE_CREATE;
321         oparms.path = path;
322         oparms.fid = &fid;
323         oparms.reconnect = false;
324
325         rc = CIFS_open(xid, &oparms, &oplock, NULL);
326         if (rc)
327                 return rc;
328
329         io_parms.netfid = fid.netfid;
330         io_parms.pid = current->tgid;
331         io_parms.tcon = tcon;
332         io_parms.offset = 0;
333         io_parms.length = CIFS_MF_SYMLINK_FILE_SIZE;
334
335         rc = CIFSSMBWrite(xid, &io_parms, pbytes_written, pbuf);
336         CIFSSMBClose(xid, tcon, fid.netfid);
337         return rc;
338 }
339 #endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
340
341 /*
342  * SMB 2.1/SMB3 Protocol specific functions
343  */
344 int
345 smb3_query_mf_symlink(unsigned int xid, struct cifs_tcon *tcon,
346                       struct cifs_sb_info *cifs_sb, const unsigned char *path,
347                       char *pbuf, unsigned int *pbytes_read)
348 {
349         int rc;
350         struct cifs_fid fid;
351         struct cifs_open_parms oparms;
352         struct cifs_io_parms io_parms = {0};
353         int buf_type = CIFS_NO_BUFFER;
354         __le16 *utf16_path;
355         __u8 oplock = SMB2_OPLOCK_LEVEL_NONE;
356         struct smb2_file_all_info *pfile_info = NULL;
357
358         oparms.tcon = tcon;
359         oparms.cifs_sb = cifs_sb;
360         oparms.desired_access = GENERIC_READ;
361         oparms.create_options = cifs_create_options(cifs_sb, CREATE_NOT_DIR);
362         oparms.disposition = FILE_OPEN;
363         oparms.fid = &fid;
364         oparms.reconnect = false;
365
366         utf16_path = cifs_convert_path_to_utf16(path, cifs_sb);
367         if (utf16_path == NULL)
368                 return -ENOMEM;
369
370         pfile_info = kzalloc(sizeof(struct smb2_file_all_info) + PATH_MAX * 2,
371                              GFP_KERNEL);
372
373         if (pfile_info == NULL) {
374                 kfree(utf16_path);
375                 return  -ENOMEM;
376         }
377
378         rc = SMB2_open(xid, &oparms, utf16_path, &oplock, pfile_info, NULL,
379                        NULL, NULL);
380         if (rc)
381                 goto qmf_out_open_fail;
382
383         if (pfile_info->EndOfFile != cpu_to_le64(CIFS_MF_SYMLINK_FILE_SIZE)) {
384                 /* it's not a symlink */
385                 rc = -ENOENT; /* Is there a better rc to return? */
386                 goto qmf_out;
387         }
388
389         io_parms.netfid = fid.netfid;
390         io_parms.pid = current->tgid;
391         io_parms.tcon = tcon;
392         io_parms.offset = 0;
393         io_parms.length = CIFS_MF_SYMLINK_FILE_SIZE;
394         io_parms.persistent_fid = fid.persistent_fid;
395         io_parms.volatile_fid = fid.volatile_fid;
396         rc = SMB2_read(xid, &io_parms, pbytes_read, &pbuf, &buf_type);
397 qmf_out:
398         SMB2_close(xid, tcon, fid.persistent_fid, fid.volatile_fid);
399 qmf_out_open_fail:
400         kfree(utf16_path);
401         kfree(pfile_info);
402         return rc;
403 }
404
405 int
406 smb3_create_mf_symlink(unsigned int xid, struct cifs_tcon *tcon,
407                        struct cifs_sb_info *cifs_sb, const unsigned char *path,
408                        char *pbuf, unsigned int *pbytes_written)
409 {
410         int rc;
411         struct cifs_fid fid;
412         struct cifs_open_parms oparms;
413         struct cifs_io_parms io_parms = {0};
414         __le16 *utf16_path;
415         __u8 oplock = SMB2_OPLOCK_LEVEL_NONE;
416         struct kvec iov[2];
417
418         cifs_dbg(FYI, "%s: path: %s\n", __func__, path);
419
420         utf16_path = cifs_convert_path_to_utf16(path, cifs_sb);
421         if (!utf16_path)
422                 return -ENOMEM;
423
424         oparms.tcon = tcon;
425         oparms.cifs_sb = cifs_sb;
426         oparms.desired_access = GENERIC_WRITE;
427         oparms.create_options = cifs_create_options(cifs_sb, CREATE_NOT_DIR);
428         oparms.disposition = FILE_CREATE;
429         oparms.fid = &fid;
430         oparms.reconnect = false;
431         oparms.mode = 0644;
432
433         rc = SMB2_open(xid, &oparms, utf16_path, &oplock, NULL, NULL,
434                        NULL, NULL);
435         if (rc) {
436                 kfree(utf16_path);
437                 return rc;
438         }
439
440         io_parms.netfid = fid.netfid;
441         io_parms.pid = current->tgid;
442         io_parms.tcon = tcon;
443         io_parms.offset = 0;
444         io_parms.length = CIFS_MF_SYMLINK_FILE_SIZE;
445         io_parms.persistent_fid = fid.persistent_fid;
446         io_parms.volatile_fid = fid.volatile_fid;
447
448         /* iov[0] is reserved for smb header */
449         iov[1].iov_base = pbuf;
450         iov[1].iov_len = CIFS_MF_SYMLINK_FILE_SIZE;
451
452         rc = SMB2_write(xid, &io_parms, pbytes_written, iov, 1);
453
454         /* Make sure we wrote all of the symlink data */
455         if ((rc == 0) && (*pbytes_written != CIFS_MF_SYMLINK_FILE_SIZE))
456                 rc = -EIO;
457
458         SMB2_close(xid, tcon, fid.persistent_fid, fid.volatile_fid);
459
460         kfree(utf16_path);
461         return rc;
462 }
463
464 /*
465  * M-F Symlink Functions - End
466  */
467
468 int
469 cifs_hardlink(struct dentry *old_file, struct inode *inode,
470               struct dentry *direntry)
471 {
472         int rc = -EACCES;
473         unsigned int xid;
474         const char *from_name, *to_name;
475         void *page1, *page2;
476         struct cifs_sb_info *cifs_sb = CIFS_SB(inode->i_sb);
477         struct tcon_link *tlink;
478         struct cifs_tcon *tcon;
479         struct TCP_Server_Info *server;
480         struct cifsInodeInfo *cifsInode;
481
482         if (unlikely(cifs_forced_shutdown(cifs_sb)))
483                 return -EIO;
484
485         tlink = cifs_sb_tlink(cifs_sb);
486         if (IS_ERR(tlink))
487                 return PTR_ERR(tlink);
488         tcon = tlink_tcon(tlink);
489
490         xid = get_xid();
491         page1 = alloc_dentry_path();
492         page2 = alloc_dentry_path();
493
494         from_name = build_path_from_dentry(old_file, page1);
495         if (IS_ERR(from_name)) {
496                 rc = PTR_ERR(from_name);
497                 goto cifs_hl_exit;
498         }
499         to_name = build_path_from_dentry(direntry, page2);
500         if (IS_ERR(to_name)) {
501                 rc = PTR_ERR(to_name);
502                 goto cifs_hl_exit;
503         }
504
505 #ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
506         if (tcon->unix_ext)
507                 rc = CIFSUnixCreateHardLink(xid, tcon, from_name, to_name,
508                                             cifs_sb->local_nls,
509                                             cifs_remap(cifs_sb));
510         else {
511 #else
512         {
513 #endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
514                 server = tcon->ses->server;
515                 if (!server->ops->create_hardlink) {
516                         rc = -ENOSYS;
517                         goto cifs_hl_exit;
518                 }
519                 rc = server->ops->create_hardlink(xid, tcon, from_name, to_name,
520                                                   cifs_sb);
521                 if ((rc == -EIO) || (rc == -EINVAL))
522                         rc = -EOPNOTSUPP;
523         }
524
525         d_drop(direntry);       /* force new lookup from server of target */
526
527         /*
528          * if source file is cached (oplocked) revalidate will not go to server
529          * until the file is closed or oplock broken so update nlinks locally
530          */
531         if (d_really_is_positive(old_file)) {
532                 cifsInode = CIFS_I(d_inode(old_file));
533                 if (rc == 0) {
534                         spin_lock(&d_inode(old_file)->i_lock);
535                         inc_nlink(d_inode(old_file));
536                         spin_unlock(&d_inode(old_file)->i_lock);
537
538                         /*
539                          * parent dir timestamps will update from srv within a
540                          * second, would it really be worth it to set the parent
541                          * dir cifs inode time to zero to force revalidate
542                          * (faster) for it too?
543                          */
544                 }
545                 /*
546                  * if not oplocked will force revalidate to get info on source
547                  * file from srv.  Note Samba server prior to 4.2 has bug -
548                  * not updating src file ctime on hardlinks but Windows servers
549                  * handle it properly
550                  */
551                 cifsInode->time = 0;
552
553                 /*
554                  * Will update parent dir timestamps from srv within a second.
555                  * Would it really be worth it to set the parent dir (cifs
556                  * inode) time field to zero to force revalidate on parent
557                  * directory faster ie
558                  *
559                  * CIFS_I(inode)->time = 0;
560                  */
561         }
562
563 cifs_hl_exit:
564         free_dentry_path(page1);
565         free_dentry_path(page2);
566         free_xid(xid);
567         cifs_put_tlink(tlink);
568         return rc;
569 }
570
571 int
572 cifs_symlink(struct user_namespace *mnt_userns, struct inode *inode,
573              struct dentry *direntry, const char *symname)
574 {
575         int rc = -EOPNOTSUPP;
576         unsigned int xid;
577         struct cifs_sb_info *cifs_sb = CIFS_SB(inode->i_sb);
578         struct tcon_link *tlink;
579         struct cifs_tcon *pTcon;
580         const char *full_path;
581         void *page;
582         struct inode *newinode = NULL;
583
584         if (unlikely(cifs_forced_shutdown(cifs_sb)))
585                 return -EIO;
586
587         page = alloc_dentry_path();
588         if (!page)
589                 return -ENOMEM;
590
591         xid = get_xid();
592
593         tlink = cifs_sb_tlink(cifs_sb);
594         if (IS_ERR(tlink)) {
595                 rc = PTR_ERR(tlink);
596                 goto symlink_exit;
597         }
598         pTcon = tlink_tcon(tlink);
599
600         full_path = build_path_from_dentry(direntry, page);
601         if (IS_ERR(full_path)) {
602                 rc = PTR_ERR(full_path);
603                 goto symlink_exit;
604         }
605
606         cifs_dbg(FYI, "Full path: %s\n", full_path);
607         cifs_dbg(FYI, "symname is %s\n", symname);
608
609         /* BB what if DFS and this volume is on different share? BB */
610         if (cifs_sb->mnt_cifs_flags & CIFS_MOUNT_MF_SYMLINKS)
611                 rc = create_mf_symlink(xid, pTcon, cifs_sb, full_path, symname);
612 #ifdef CONFIG_CIFS_ALLOW_INSECURE_LEGACY
613         else if (pTcon->unix_ext)
614                 rc = CIFSUnixCreateSymLink(xid, pTcon, full_path, symname,
615                                            cifs_sb->local_nls,
616                                            cifs_remap(cifs_sb));
617 #endif /* CONFIG_CIFS_ALLOW_INSECURE_LEGACY */
618         /* else
619            rc = CIFSCreateReparseSymLink(xid, pTcon, fromName, toName,
620                                         cifs_sb_target->local_nls); */
621
622         if (rc == 0) {
623                 if (pTcon->posix_extensions)
624                         rc = smb311_posix_get_inode_info(&newinode, full_path, inode->i_sb, xid);
625                 else if (pTcon->unix_ext)
626                         rc = cifs_get_inode_info_unix(&newinode, full_path,
627                                                       inode->i_sb, xid);
628                 else
629                         rc = cifs_get_inode_info(&newinode, full_path, NULL,
630                                                  inode->i_sb, xid, NULL);
631
632                 if (rc != 0) {
633                         cifs_dbg(FYI, "Create symlink ok, getinodeinfo fail rc = %d\n",
634                                  rc);
635                 } else {
636                         d_instantiate(direntry, newinode);
637                 }
638         }
639 symlink_exit:
640         free_dentry_path(page);
641         cifs_put_tlink(tlink);
642         free_xid(xid);
643         return rc;
644 }
This page took 0.073996 seconds and 4 git commands to generate.