xfs: Use scnprintf() for avoiding potential buffer overflow
[linux-block.git] / fs / xfs / xfs_dir2_readdir.c
CommitLineData
0b61f8a4 1// SPDX-License-Identifier: GPL-2.0
4a8af273
DC
2/*
3 * Copyright (c) 2000-2005 Silicon Graphics, Inc.
4 * Copyright (c) 2013 Red Hat, Inc.
5 * All Rights Reserved.
4a8af273
DC
6 */
7#include "xfs.h"
8#include "xfs_fs.h"
5467b34b 9#include "xfs_shared.h"
a4fbe6ab 10#include "xfs_format.h"
239880ef
DC
11#include "xfs_log_format.h"
12#include "xfs_trans_resv.h"
4a8af273 13#include "xfs_mount.h"
4a8af273 14#include "xfs_inode.h"
2b9ab5ab 15#include "xfs_dir2.h"
4a8af273 16#include "xfs_dir2_priv.h"
4a8af273
DC
17#include "xfs_trace.h"
18#include "xfs_bmap.h"
239880ef 19#include "xfs_trans.h"
04df34ac 20#include "xfs_error.h"
4a8af273 21
0cb97766
DC
22/*
23 * Directory file type support functions
24 */
25static unsigned char xfs_dir3_filetype_table[] = {
26 DT_UNKNOWN, DT_REG, DT_DIR, DT_CHR, DT_BLK,
27 DT_FIFO, DT_SOCK, DT_LNK, DT_WHT,
28};
29
a5c46e5e 30unsigned char
0cb97766
DC
31xfs_dir3_get_dtype(
32 struct xfs_mount *mp,
c8ce540d 33 uint8_t filetype)
0cb97766
DC
34{
35 if (!xfs_sb_version_hasftype(&mp->m_sb))
36 return DT_UNKNOWN;
37
38 if (filetype >= XFS_DIR3_FT_MAX)
39 return DT_UNKNOWN;
40
41 return xfs_dir3_filetype_table[filetype];
42}
0cb97766 43
4a8af273
DC
44STATIC int
45xfs_dir2_sf_getdents(
53f82db0 46 struct xfs_da_args *args,
4a8af273
DC
47 struct dir_context *ctx)
48{
49 int i; /* shortform entry number */
53f82db0 50 struct xfs_inode *dp = args->dp; /* incore directory inode */
50f6bb6b 51 struct xfs_mount *mp = dp->i_mount;
4a8af273
DC
52 xfs_dir2_dataptr_t off; /* current entry's offset */
53 xfs_dir2_sf_entry_t *sfep; /* shortform directory entry */
54 xfs_dir2_sf_hdr_t *sfp; /* shortform structure */
55 xfs_dir2_dataptr_t dot_offset;
56 xfs_dir2_dataptr_t dotdot_offset;
57 xfs_ino_t ino;
53f82db0 58 struct xfs_da_geometry *geo = args->geo;
4a8af273
DC
59
60 ASSERT(dp->i_df.if_flags & XFS_IFINLINE);
4a8af273
DC
61 ASSERT(dp->i_df.if_bytes == dp->i_d.di_size);
62 ASSERT(dp->i_df.if_u1.if_data != NULL);
63
64 sfp = (xfs_dir2_sf_hdr_t *)dp->i_df.if_u1.if_data;
65
4a8af273
DC
66 /*
67 * If the block number in the offset is out of range, we're done.
68 */
7dda6e86 69 if (xfs_dir2_dataptr_to_db(geo, ctx->pos) > geo->datablk)
4a8af273
DC
70 return 0;
71
72 /*
16823104
CH
73 * Precalculate offsets for "." and ".." as we will always need them.
74 * This relies on the fact that directories always start with the
75 * entries for "." and "..".
4a8af273 76 */
7dda6e86 77 dot_offset = xfs_dir2_db_off_to_dataptr(geo, geo->datablk,
d73e1cee 78 geo->data_entry_offset);
7dda6e86 79 dotdot_offset = xfs_dir2_db_off_to_dataptr(geo, geo->datablk,
d73e1cee 80 geo->data_entry_offset +
fdbb8c5b 81 xfs_dir2_data_entsize(mp, sizeof(".") - 1));
4a8af273
DC
82
83 /*
84 * Put . entry unless we're starting past it.
85 */
86 if (ctx->pos <= dot_offset) {
87 ctx->pos = dot_offset & 0x7fffffff;
88 if (!dir_emit(ctx, ".", 1, dp->i_ino, DT_DIR))
89 return 0;
90 }
91
92 /*
93 * Put .. entry unless we're starting past it.
94 */
95 if (ctx->pos <= dotdot_offset) {
84915e1b 96 ino = xfs_dir2_sf_get_parent_ino(sfp);
4a8af273
DC
97 ctx->pos = dotdot_offset & 0x7fffffff;
98 if (!dir_emit(ctx, "..", 2, ino, DT_DIR))
99 return 0;
100 }
101
102 /*
103 * Loop while there are more entries and put'ing works.
104 */
105 sfep = xfs_dir2_sf_firstentry(sfp);
106 for (i = 0; i < sfp->count; i++) {
c8ce540d 107 uint8_t filetype;
0cb97766 108
7dda6e86 109 off = xfs_dir2_db_off_to_dataptr(geo, geo->datablk,
4a8af273
DC
110 xfs_dir2_sf_get_offset(sfep));
111
112 if (ctx->pos > off) {
50f6bb6b 113 sfep = xfs_dir2_sf_nextentry(mp, sfp, sfep);
4a8af273
DC
114 continue;
115 }
116
93b1e96a 117 ino = xfs_dir2_sf_get_ino(mp, sfp, sfep);
4501ed2a 118 filetype = xfs_dir2_sf_get_ftype(mp, sfep);
4a8af273 119 ctx->pos = off & 0x7fffffff;
a71895c5
DW
120 if (XFS_IS_CORRUPT(dp->i_mount,
121 !xfs_dir2_namecheck(sfep->name,
122 sfep->namelen)))
04df34ac 123 return -EFSCORRUPTED;
0cb97766 124 if (!dir_emit(ctx, (char *)sfep->name, sfep->namelen, ino,
50f6bb6b 125 xfs_dir3_get_dtype(mp, filetype)))
4a8af273 126 return 0;
50f6bb6b 127 sfep = xfs_dir2_sf_nextentry(mp, sfp, sfep);
4a8af273
DC
128 }
129
7dda6e86 130 ctx->pos = xfs_dir2_db_off_to_dataptr(geo, geo->datablk + 1, 0) &
53f82db0 131 0x7fffffff;
4a8af273
DC
132 return 0;
133}
134
135/*
136 * Readdir for block directories.
137 */
138STATIC int
139xfs_dir2_block_getdents(
53f82db0 140 struct xfs_da_args *args,
4a8af273
DC
141 struct dir_context *ctx)
142{
53f82db0 143 struct xfs_inode *dp = args->dp; /* incore directory inode */
4a8af273 144 struct xfs_buf *bp; /* buffer for block */
4a8af273 145 int error; /* error return value */
4a8af273
DC
146 int wantoff; /* starting block offset */
147 xfs_off_t cook;
53f82db0 148 struct xfs_da_geometry *geo = args->geo;
dbad7c99 149 int lock_mode;
263dde86
CH
150 unsigned int offset;
151 unsigned int end;
4a8af273 152
4a8af273
DC
153 /*
154 * If the block number in the offset is out of range, we're done.
155 */
7dda6e86 156 if (xfs_dir2_dataptr_to_db(geo, ctx->pos) > geo->datablk)
4a8af273
DC
157 return 0;
158
dbad7c99 159 lock_mode = xfs_ilock_data_map_shared(dp);
acb9553c 160 error = xfs_dir3_block_read(args->trans, dp, &bp);
dbad7c99 161 xfs_iunlock(dp, lock_mode);
4a8af273
DC
162 if (error)
163 return error;
164
165 /*
166 * Extract the byte offset we start at from the seek pointer.
167 * We'll skip entries before this.
168 */
30028030 169 wantoff = xfs_dir2_dataptr_to_off(geo, ctx->pos);
4a8af273 170 xfs_dir3_data_check(dp, bp);
4a8af273
DC
171
172 /*
173 * Loop over the data portion of the block.
174 * Each object is a real entry (dep) or an unused one (dup).
175 */
d73e1cee 176 offset = geo->data_entry_offset;
5c072127 177 end = xfs_dir3_data_end_offset(geo, bp->b_addr);
263dde86
CH
178 while (offset < end) {
179 struct xfs_dir2_data_unused *dup = bp->b_addr + offset;
180 struct xfs_dir2_data_entry *dep = bp->b_addr + offset;
c8ce540d 181 uint8_t filetype;
0cb97766 182
4a8af273
DC
183 /*
184 * Unused, skip it.
185 */
186 if (be16_to_cpu(dup->freetag) == XFS_DIR2_DATA_FREE_TAG) {
263dde86 187 offset += be16_to_cpu(dup->length);
4a8af273
DC
188 continue;
189 }
190
4a8af273
DC
191 /*
192 * Bump pointer for the next iteration.
193 */
fdbb8c5b 194 offset += xfs_dir2_data_entsize(dp->i_mount, dep->namelen);
263dde86 195
4a8af273
DC
196 /*
197 * The entry is before the desired starting point, skip it.
198 */
263dde86 199 if (offset < wantoff)
4a8af273
DC
200 continue;
201
263dde86 202 cook = xfs_dir2_db_off_to_dataptr(geo, geo->datablk, offset);
4a8af273
DC
203
204 ctx->pos = cook & 0x7fffffff;
59b8b465 205 filetype = xfs_dir2_data_get_ftype(dp->i_mount, dep);
4a8af273
DC
206 /*
207 * If it didn't fit, set the final offset to here & return.
208 */
a71895c5
DW
209 if (XFS_IS_CORRUPT(dp->i_mount,
210 !xfs_dir2_namecheck(dep->name,
211 dep->namelen))) {
04df34ac
DW
212 error = -EFSCORRUPTED;
213 goto out_rele;
214 }
4a8af273 215 if (!dir_emit(ctx, (char *)dep->name, dep->namelen,
0cb97766 216 be64_to_cpu(dep->inumber),
04df34ac
DW
217 xfs_dir3_get_dtype(dp->i_mount, filetype)))
218 goto out_rele;
4a8af273
DC
219 }
220
221 /*
222 * Reached the end of the block.
223 * Set the offset to a non-existent block 1 and return.
224 */
7dda6e86 225 ctx->pos = xfs_dir2_db_off_to_dataptr(geo, geo->datablk + 1, 0) &
53f82db0 226 0x7fffffff;
04df34ac 227out_rele:
acb9553c 228 xfs_trans_brelse(args->trans, bp);
04df34ac 229 return error;
4a8af273
DC
230}
231
d205a7d0
DW
232/*
233 * Read a directory block and initiate readahead for blocks beyond that.
234 * We maintain a sliding readahead window of the remaining space in the
235 * buffer rounded up to the nearest block.
236 */
4a8af273
DC
237STATIC int
238xfs_dir2_leaf_readbuf(
53f82db0 239 struct xfs_da_args *args,
4a8af273 240 size_t bufsize,
d205a7d0
DW
241 xfs_dir2_off_t *cur_off,
242 xfs_dablk_t *ra_blk,
243 struct xfs_buf **bpp)
4a8af273 244{
53f82db0 245 struct xfs_inode *dp = args->dp;
9f541801 246 struct xfs_buf *bp = NULL;
d205a7d0
DW
247 struct xfs_da_geometry *geo = args->geo;
248 struct xfs_ifork *ifp = XFS_IFORK_PTR(dp, XFS_DATA_FORK);
249 struct xfs_bmbt_irec map;
4a8af273 250 struct blk_plug plug;
d205a7d0
DW
251 xfs_dir2_off_t new_off;
252 xfs_dablk_t next_ra;
253 xfs_dablk_t map_off;
254 xfs_dablk_t last_da;
b2b1712a 255 struct xfs_iext_cursor icur;
d205a7d0 256 int ra_want;
4a8af273 257 int error = 0;
4a8af273 258
d205a7d0
DW
259 if (!(ifp->if_flags & XFS_IFEXTENTS)) {
260 error = xfs_iread_extents(args->trans, dp, XFS_DATA_FORK);
4a8af273 261 if (error)
d205a7d0 262 goto out;
4a8af273
DC
263 }
264
265 /*
d205a7d0
DW
266 * Look for mapped directory blocks at or above the current offset.
267 * Truncate down to the nearest directory block to start the scanning
268 * operation.
4a8af273 269 */
d205a7d0
DW
270 last_da = xfs_dir2_byte_to_da(geo, XFS_DIR2_LEAF_OFFSET);
271 map_off = xfs_dir2_db_to_da(geo, xfs_dir2_byte_to_db(geo, *cur_off));
b2b1712a 272 if (!xfs_iext_lookup_extent(dp, ifp, map_off, &icur, &map))
4a8af273 273 goto out;
d205a7d0
DW
274 if (map.br_startoff >= last_da)
275 goto out;
276 xfs_trim_extent(&map, map_off, last_da - map_off);
4a8af273 277
d205a7d0
DW
278 /* Read the directory block of that first mapping. */
279 new_off = xfs_dir2_da_to_byte(geo, map.br_startoff);
280 if (new_off > *cur_off)
281 *cur_off = new_off;
cd2c9f1b 282 error = xfs_dir3_data_read(args->trans, dp, map.br_startoff, 0, &bp);
4a8af273 283 if (error)
d205a7d0 284 goto out;
4a8af273
DC
285
286 /*
d205a7d0
DW
287 * Start readahead for the next bufsize's worth of dir data blocks.
288 * We may have already issued readahead for some of that range;
289 * ra_blk tracks the last block we tried to read(ahead).
4a8af273 290 */
d205a7d0
DW
291 ra_want = howmany(bufsize + geo->blksize, (1 << geo->fsblog));
292 if (*ra_blk >= last_da)
293 goto out;
294 else if (*ra_blk == 0)
295 *ra_blk = map.br_startoff;
296 next_ra = map.br_startoff + geo->fsbcount;
297 if (next_ra >= last_da)
298 goto out_no_ra;
299 if (map.br_blockcount < geo->fsbcount &&
b2b1712a 300 !xfs_iext_next_extent(ifp, &icur, &map))
d205a7d0
DW
301 goto out_no_ra;
302 if (map.br_startoff >= last_da)
303 goto out_no_ra;
304 xfs_trim_extent(&map, next_ra, last_da - next_ra);
305
306 /* Start ra for each dir (not fs) block that has a mapping. */
4a8af273 307 blk_start_plug(&plug);
d205a7d0
DW
308 while (ra_want > 0) {
309 next_ra = roundup((xfs_dablk_t)map.br_startoff, geo->fsbcount);
310 while (ra_want > 0 &&
311 next_ra < map.br_startoff + map.br_blockcount) {
312 if (next_ra >= last_da) {
313 *ra_blk = last_da;
314 break;
315 }
316 if (next_ra > *ra_blk) {
06566fda
CH
317 xfs_dir3_data_readahead(dp, next_ra,
318 XFS_DABUF_MAP_HOLE_OK);
d205a7d0 319 *ra_blk = next_ra;
4a8af273 320 }
d205a7d0
DW
321 ra_want -= geo->fsbcount;
322 next_ra += geo->fsbcount;
323 }
b2b1712a 324 if (!xfs_iext_next_extent(ifp, &icur, &map)) {
d205a7d0
DW
325 *ra_blk = last_da;
326 break;
4a8af273
DC
327 }
328 }
329 blk_finish_plug(&plug);
330
331out:
332 *bpp = bp;
333 return error;
d205a7d0
DW
334out_no_ra:
335 *ra_blk = last_da;
336 goto out;
4a8af273
DC
337}
338
339/*
340 * Getdents (readdir) for leaf and node directories.
341 * This reads the data blocks only, so is the same for both forms.
342 */
343STATIC int
344xfs_dir2_leaf_getdents(
53f82db0 345 struct xfs_da_args *args,
4a8af273
DC
346 struct dir_context *ctx,
347 size_t bufsize)
348{
53f82db0 349 struct xfs_inode *dp = args->dp;
fdbb8c5b 350 struct xfs_mount *mp = dp->i_mount;
4a8af273 351 struct xfs_buf *bp = NULL; /* data block buffer */
4a8af273
DC
352 xfs_dir2_data_entry_t *dep; /* data entry */
353 xfs_dir2_data_unused_t *dup; /* unused entry */
53f82db0 354 struct xfs_da_geometry *geo = args->geo;
d205a7d0
DW
355 xfs_dablk_t rablk = 0; /* current readahead block */
356 xfs_dir2_off_t curoff; /* current overall offset */
357 int length; /* temporary length value */
358 int byteoff; /* offset in current block */
359 int lock_mode;
2f4369a8 360 unsigned int offset = 0;
d205a7d0 361 int error = 0; /* error return value */
4a8af273
DC
362
363 /*
364 * If the offset is at or past the largest allowed value,
365 * give up right away.
366 */
367 if (ctx->pos >= XFS_DIR2_MAX_DATAPTR)
368 return 0;
369
4a8af273
DC
370 /*
371 * Inside the loop we keep the main offset value as a byte offset
372 * in the directory file.
373 */
25994053 374 curoff = xfs_dir2_dataptr_to_byte(ctx->pos);
4a8af273 375
4a8af273
DC
376 /*
377 * Loop over directory entries until we reach the end offset.
378 * Get more blocks and readahead as necessary.
379 */
380 while (curoff < XFS_DIR2_LEAF_OFFSET) {
c8ce540d 381 uint8_t filetype;
0cb97766 382
4a8af273
DC
383 /*
384 * If we have no buffer, or we're off the end of the
385 * current buffer, need to get another one.
386 */
2f4369a8 387 if (!bp || offset >= geo->blksize) {
9f541801 388 if (bp) {
d205a7d0 389 xfs_trans_brelse(args->trans, bp);
9f541801 390 bp = NULL;
9f541801 391 }
4a8af273 392
dbad7c99 393 lock_mode = xfs_ilock_data_map_shared(dp);
d205a7d0
DW
394 error = xfs_dir2_leaf_readbuf(args, bufsize, &curoff,
395 &rablk, &bp);
dbad7c99 396 xfs_iunlock(dp, lock_mode);
d205a7d0 397 if (error || !bp)
4a8af273
DC
398 break;
399
4a8af273
DC
400 xfs_dir3_data_check(dp, bp);
401 /*
402 * Find our position in the block.
403 */
d73e1cee 404 offset = geo->data_entry_offset;
53f82db0 405 byteoff = xfs_dir2_byte_to_off(geo, curoff);
4a8af273
DC
406 /*
407 * Skip past the header.
408 */
409 if (byteoff == 0)
d73e1cee 410 curoff += geo->data_entry_offset;
4a8af273
DC
411 /*
412 * Skip past entries until we reach our offset.
413 */
414 else {
2f4369a8
CH
415 while (offset < byteoff) {
416 dup = bp->b_addr + offset;
4a8af273
DC
417
418 if (be16_to_cpu(dup->freetag)
419 == XFS_DIR2_DATA_FREE_TAG) {
420
421 length = be16_to_cpu(dup->length);
2f4369a8 422 offset += length;
4a8af273
DC
423 continue;
424 }
2f4369a8 425 dep = bp->b_addr + offset;
fdbb8c5b
CH
426 length = xfs_dir2_data_entsize(mp,
427 dep->namelen);
2f4369a8 428 offset += length;
4a8af273
DC
429 }
430 /*
431 * Now set our real offset.
432 */
433 curoff =
30028030
DC
434 xfs_dir2_db_off_to_byte(geo,
435 xfs_dir2_byte_to_db(geo, curoff),
2f4369a8
CH
436 offset);
437 if (offset >= geo->blksize)
4a8af273 438 continue;
4a8af273
DC
439 }
440 }
2f4369a8 441
4a8af273 442 /*
2f4369a8 443 * We have a pointer to an entry. Is it a live one?
4a8af273 444 */
2f4369a8
CH
445 dup = bp->b_addr + offset;
446
4a8af273
DC
447 /*
448 * No, it's unused, skip over it.
449 */
450 if (be16_to_cpu(dup->freetag) == XFS_DIR2_DATA_FREE_TAG) {
451 length = be16_to_cpu(dup->length);
2f4369a8 452 offset += length;
4a8af273
DC
453 curoff += length;
454 continue;
455 }
456
2f4369a8 457 dep = bp->b_addr + offset;
fdbb8c5b 458 length = xfs_dir2_data_entsize(mp, dep->namelen);
59b8b465 459 filetype = xfs_dir2_data_get_ftype(mp, dep);
4a8af273 460
25994053 461 ctx->pos = xfs_dir2_byte_to_dataptr(curoff) & 0x7fffffff;
a71895c5
DW
462 if (XFS_IS_CORRUPT(dp->i_mount,
463 !xfs_dir2_namecheck(dep->name,
464 dep->namelen))) {
04df34ac
DW
465 error = -EFSCORRUPTED;
466 break;
467 }
4a8af273 468 if (!dir_emit(ctx, (char *)dep->name, dep->namelen,
0cb97766 469 be64_to_cpu(dep->inumber),
53f82db0 470 xfs_dir3_get_dtype(dp->i_mount, filetype)))
4a8af273
DC
471 break;
472
473 /*
474 * Advance to next entry in the block.
475 */
2f4369a8 476 offset += length;
4a8af273
DC
477 curoff += length;
478 /* bufsize may have just been a guess; don't go negative */
479 bufsize = bufsize > length ? bufsize - length : 0;
480 }
481
482 /*
483 * All done. Set output offset value to current offset.
484 */
25994053 485 if (curoff > xfs_dir2_dataptr_to_byte(XFS_DIR2_MAX_DATAPTR))
4a8af273
DC
486 ctx->pos = XFS_DIR2_MAX_DATAPTR & 0x7fffffff;
487 else
25994053 488 ctx->pos = xfs_dir2_byte_to_dataptr(curoff) & 0x7fffffff;
4a8af273 489 if (bp)
acb9553c 490 xfs_trans_brelse(args->trans, bp);
4a8af273
DC
491 return error;
492}
493
494/*
495 * Read a directory.
acb9553c
DW
496 *
497 * If supplied, the transaction collects locked dir buffers to avoid
498 * nested buffer deadlocks. This function does not dirty the
499 * transaction. The caller should ensure that the inode is locked
500 * before calling this function.
4a8af273
DC
501 */
502int
503xfs_readdir(
acb9553c 504 struct xfs_trans *tp,
53f82db0
DC
505 struct xfs_inode *dp,
506 struct dir_context *ctx,
507 size_t bufsize)
4a8af273 508{
35f46c5f 509 struct xfs_da_args args = { NULL };
53f82db0
DC
510 int rval;
511 int v;
4a8af273
DC
512
513 trace_xfs_readdir(dp);
514
515 if (XFS_FORCED_SHUTDOWN(dp->i_mount))
2451337d 516 return -EIO;
4a8af273 517
c19b3b05 518 ASSERT(S_ISDIR(VFS_I(dp)->i_mode));
ff6d6af2 519 XFS_STATS_INC(dp->i_mount, xs_dir_getdents);
4a8af273 520
53f82db0
DC
521 args.dp = dp;
522 args.geo = dp->i_mount->m_dir_geo;
acb9553c 523 args.trans = tp;
53f82db0 524
4a8af273 525 if (dp->i_d.di_format == XFS_DINODE_FMT_LOCAL)
53f82db0
DC
526 rval = xfs_dir2_sf_getdents(&args, ctx);
527 else if ((rval = xfs_dir2_isblock(&args, &v)))
4a8af273
DC
528 ;
529 else if (v)
53f82db0 530 rval = xfs_dir2_block_getdents(&args, ctx);
4a8af273 531 else
53f82db0 532 rval = xfs_dir2_leaf_getdents(&args, ctx, bufsize);
40194ecc 533
4a8af273
DC
534 return rval;
535}