xattr_security.c revision 6cb4aff0a77cc0e6bae9475d62205319e3ebbf3f
1#include <linux/reiserfs_fs.h>
2#include <linux/errno.h>
3#include <linux/fs.h>
4#include <linux/pagemap.h>
5#include <linux/xattr.h>
6#include <linux/reiserfs_xattr.h>
7#include <linux/security.h>
8#include <asm/uaccess.h>
9
10static int
11security_get(struct dentry *dentry, const char *name, void *buffer, size_t size,
12		int handler_flags)
13{
14	if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX))
15		return -EINVAL;
16
17	if (IS_PRIVATE(dentry->d_inode))
18		return -EPERM;
19
20	return reiserfs_xattr_get(dentry->d_inode, name, buffer, size);
21}
22
23static int
24security_set(struct dentry *dentry, const char *name, const void *buffer,
25	     size_t size, int flags, int handler_flags)
26{
27	if (strlen(name) < sizeof(XATTR_SECURITY_PREFIX))
28		return -EINVAL;
29
30	if (IS_PRIVATE(dentry->d_inode))
31		return -EPERM;
32
33	return reiserfs_xattr_set(dentry->d_inode, name, buffer, size, flags);
34}
35
36static size_t security_list(struct dentry *dentry, char *list, size_t list_len,
37			    const char *name, size_t namelen, int handler_flags)
38{
39	const size_t len = namelen + 1;
40
41	if (IS_PRIVATE(dentry->d_inode))
42		return 0;
43
44	if (list && len <= list_len) {
45		memcpy(list, name, namelen);
46		list[namelen] = '\0';
47	}
48
49	return len;
50}
51
52/* Initializes the security context for a new inode and returns the number
53 * of blocks needed for the transaction. If successful, reiserfs_security
54 * must be released using reiserfs_security_free when the caller is done. */
55int reiserfs_security_init(struct inode *dir, struct inode *inode,
56			   struct reiserfs_security_handle *sec)
57{
58	int blocks = 0;
59	int error;
60
61	sec->name = NULL;
62
63	/* Don't add selinux attributes on xattrs - they'll never get used */
64	if (IS_PRIVATE(dir))
65		return 0;
66
67	error = security_inode_init_security(inode, dir, &sec->name,
68					     &sec->value, &sec->length);
69	if (error) {
70		if (error == -EOPNOTSUPP)
71			error = 0;
72
73		sec->name = NULL;
74		sec->value = NULL;
75		sec->length = 0;
76		return error;
77	}
78
79	if (sec->length && reiserfs_xattrs_initialized(inode->i_sb)) {
80		blocks = reiserfs_xattr_jcreate_nblocks(inode) +
81			 reiserfs_xattr_nblocks(inode, sec->length);
82		/* We don't want to count the directories twice if we have
83		 * a default ACL. */
84		REISERFS_I(inode)->i_flags |= i_has_xattr_dir;
85	}
86	return blocks;
87}
88
89int reiserfs_security_write(struct reiserfs_transaction_handle *th,
90			    struct inode *inode,
91			    struct reiserfs_security_handle *sec)
92{
93	int error;
94	if (strlen(sec->name) < sizeof(XATTR_SECURITY_PREFIX))
95		return -EINVAL;
96
97	error = reiserfs_xattr_set_handle(th, inode, sec->name, sec->value,
98					  sec->length, XATTR_CREATE);
99	if (error == -ENODATA || error == -EOPNOTSUPP)
100		error = 0;
101
102	return error;
103}
104
105void reiserfs_security_free(struct reiserfs_security_handle *sec)
106{
107	kfree(sec->name);
108	kfree(sec->value);
109	sec->name = NULL;
110	sec->value = NULL;
111}
112
113struct xattr_handler reiserfs_xattr_security_handler = {
114	.prefix = XATTR_SECURITY_PREFIX,
115	.get = security_get,
116	.set = security_set,
117	.list = security_list,
118};
119