Squashfs: fix corruption checks in squashfs_readdir()
[linux-block.git] / fs / squashfs / dir.c
CommitLineData
07972dde
PL
1/*
2 * Squashfs - a compressed read only filesystem for Linux
3 *
4 * Copyright (c) 2002, 2003, 2004, 2005, 2006, 2007, 2008
d7f2ff67 5 * Phillip Lougher <phillip@squashfs.org.uk>
07972dde
PL
6 *
7 * This program is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU General Public License
9 * as published by the Free Software Foundation; either version 2,
10 * or (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, write to the Free Software
19 * Foundation, 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
20 *
21 * dir.c
22 */
23
24/*
25 * This file implements code to read directories from disk.
26 *
27 * See namei.c for a description of directory organisation on disk.
28 */
29
30#include <linux/fs.h>
31#include <linux/vfs.h>
32#include <linux/slab.h>
07972dde
PL
33
34#include "squashfs_fs.h"
35#include "squashfs_fs_sb.h"
36#include "squashfs_fs_i.h"
37#include "squashfs.h"
38
39static const unsigned char squashfs_filetype_table[] = {
40 DT_UNKNOWN, DT_DIR, DT_REG, DT_LNK, DT_BLK, DT_CHR, DT_FIFO, DT_SOCK
41};
42
43/*
44 * Lookup offset (f_pos) in the directory index, returning the
45 * metadata block containing it.
46 *
47 * If we get an error reading the index then return the part of the index
48 * (if any) we have managed to read - the index isn't essential, just
49 * quicker.
50 */
51static int get_dir_index_using_offset(struct super_block *sb,
52 u64 *next_block, int *next_offset, u64 index_start, int index_offset,
53 int i_count, u64 f_pos)
54{
55 struct squashfs_sb_info *msblk = sb->s_fs_info;
56 int err, i, index, length = 0;
57 struct squashfs_dir_index dir_index;
58
59 TRACE("Entered get_dir_index_using_offset, i_count %d, f_pos %lld\n",
60 i_count, f_pos);
61
62 /*
63 * Translate from external f_pos to the internal f_pos. This
64 * is offset by 3 because we invent "." and ".." entries which are
65 * not actually stored in the directory.
66 */
2158d3fd 67 if (f_pos <= 3)
07972dde
PL
68 return f_pos;
69 f_pos -= 3;
70
71 for (i = 0; i < i_count; i++) {
72 err = squashfs_read_metadata(sb, &dir_index, &index_start,
73 &index_offset, sizeof(dir_index));
74 if (err < 0)
75 break;
76
77 index = le32_to_cpu(dir_index.index);
78 if (index > f_pos)
79 /*
80 * Found the index we're looking for.
81 */
82 break;
83
84 err = squashfs_read_metadata(sb, NULL, &index_start,
85 &index_offset, le32_to_cpu(dir_index.size) + 1);
86 if (err < 0)
87 break;
88
89 length = index;
90 *next_block = le32_to_cpu(dir_index.start_block) +
91 msblk->directory_table;
92 }
93
94 *next_offset = (length + *next_offset) % SQUASHFS_METADATA_SIZE;
95
96 /*
97 * Translate back from internal f_pos to external f_pos.
98 */
99 return length + 3;
100}
101
102
5f6039ce 103static int squashfs_readdir(struct file *file, struct dir_context *ctx)
07972dde 104{
496ad9aa 105 struct inode *inode = file_inode(file);
07972dde
PL
106 struct squashfs_sb_info *msblk = inode->i_sb->s_fs_info;
107 u64 block = squashfs_i(inode)->start + msblk->directory_table;
68e7f412
PL
108 int offset = squashfs_i(inode)->offset, length, type, err;
109 unsigned int inode_number, dir_count, size;
07972dde
PL
110 struct squashfs_dir_header dirh;
111 struct squashfs_dir_entry *dire;
112
113 TRACE("Entered squashfs_readdir [%llx:%x]\n", block, offset);
114
115 dire = kmalloc(sizeof(*dire) + SQUASHFS_NAME_LEN + 1, GFP_KERNEL);
116 if (dire == NULL) {
117 ERROR("Failed to allocate squashfs_dir_entry\n");
118 goto finish;
119 }
120
121 /*
122 * Return "." and ".." entries as the first two filenames in the
123 * directory. To maximise compression these two entries are not
124 * stored in the directory, and so we invent them here.
125 *
126 * It also means that the external f_pos is offset by 3 from the
127 * on-disk directory f_pos.
128 */
5f6039ce 129 while (ctx->pos < 3) {
07972dde
PL
130 char *name;
131 int i_ino;
132
5f6039ce 133 if (ctx->pos == 0) {
07972dde
PL
134 name = ".";
135 size = 1;
136 i_ino = inode->i_ino;
137 } else {
138 name = "..";
139 size = 2;
140 i_ino = squashfs_i(inode)->parent;
141 }
142
5f6039ce
AV
143 if (!dir_emit(ctx, name, size, i_ino,
144 squashfs_filetype_table[1]))
07972dde 145 goto finish;
07972dde 146
5f6039ce 147 ctx->pos += size;
07972dde
PL
148 }
149
150 length = get_dir_index_using_offset(inode->i_sb, &block, &offset,
151 squashfs_i(inode)->dir_idx_start,
152 squashfs_i(inode)->dir_idx_offset,
153 squashfs_i(inode)->dir_idx_cnt,
5f6039ce 154 ctx->pos);
07972dde
PL
155
156 while (length < i_size_read(inode)) {
157 /*
158 * Read directory header
159 */
160 err = squashfs_read_metadata(inode->i_sb, &dirh, &block,
161 &offset, sizeof(dirh));
162 if (err < 0)
163 goto failed_read;
164
165 length += sizeof(dirh);
166
167 dir_count = le32_to_cpu(dirh.count) + 1;
44cff8a9 168
4826d83d 169 if (dir_count > SQUASHFS_DIR_COUNT)
44cff8a9
PL
170 goto failed_read;
171
07972dde
PL
172 while (dir_count--) {
173 /*
174 * Read directory entry.
175 */
176 err = squashfs_read_metadata(inode->i_sb, dire, &block,
177 &offset, sizeof(*dire));
178 if (err < 0)
179 goto failed_read;
180
181 size = le16_to_cpu(dire->size) + 1;
182
44cff8a9
PL
183 /* size should never be larger than SQUASHFS_NAME_LEN */
184 if (size > SQUASHFS_NAME_LEN)
185 goto failed_read;
186
07972dde
PL
187 err = squashfs_read_metadata(inode->i_sb, dire->name,
188 &block, &offset, size);
189 if (err < 0)
190 goto failed_read;
191
192 length += sizeof(*dire) + size;
193
5f6039ce 194 if (ctx->pos >= length)
07972dde
PL
195 continue;
196
197 dire->name[size] = '\0';
198 inode_number = le32_to_cpu(dirh.inode_number) +
199 ((short) le16_to_cpu(dire->inode_number));
200 type = le16_to_cpu(dire->type);
201
5f6039ce 202 if (!dir_emit(ctx, dire->name, size,
07972dde 203 inode_number,
5f6039ce 204 squashfs_filetype_table[type]))
07972dde 205 goto finish;
07972dde 206
5f6039ce 207 ctx->pos = length;
07972dde
PL
208 }
209 }
210
211finish:
212 kfree(dire);
213 return 0;
214
215failed_read:
216 ERROR("Unable to read directory block [%llx:%x]\n", block, offset);
217 kfree(dire);
218 return 0;
219}
220
221
222const struct file_operations squashfs_dir_ops = {
223 .read = generic_read_dir,
5f6039ce 224 .iterate = squashfs_readdir,
6038f373 225 .llseek = default_llseek,
07972dde 226};