mirror of
https://github.com/linux-msm/laptops-kernel.git
synced 2026-08-13 14:19:53 -07:00
Merge tag 'vfs-6.19-rc1.misc' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs
Pull misc vfs updates from Christian Brauner:
"Features:
- Cheaper MAY_EXEC handling for path lookup. This elides MAY_WRITE
permission checks during path lookup and adds the
IOP_FASTPERM_MAY_EXEC flag so filesystems like btrfs can avoid
expensive permission work.
- Hide dentry_cache behind runtime const machinery.
- Add German Maglione as virtiofs co-maintainer.
Cleanups:
- Tidy up and inline step_into() and walk_component() for improved
code generation.
- Re-enable IOCB_NOWAIT writes to files. This refactors file
timestamp update logic, fixing a layering bypass in btrfs when
updating timestamps on device files and improving FMODE_NOCMTIME
handling in VFS now that nfsd started using it.
- Path lookup optimizations extracting slowpaths into dedicated
routines and adding branch prediction hints for mntput_no_expire(),
fd_install(), lookup_slow(), and various other hot paths.
- Enable clang's -fms-extensions flag, requiring a JFS rename to
avoid conflicts.
- Remove spurious exports in fs/file_attr.c.
- Stop duplicating union pipe_index declaration. This depends on the
shared kbuild branch that brings in -fms-extensions support which
is merged into this branch.
- Use MD5 library instead of crypto_shash in ecryptfs.
- Use largest_zero_folio() in iomap_dio_zero().
- Replace simple_strtol/strtoul with kstrtoint/kstrtouint in init and
initrd code.
- Various typo fixes.
Fixes:
- Fix emergency sync for btrfs. Btrfs requires an explicit sync_fs()
call with wait == 1 to commit super blocks. The emergency sync path
never passed this, leaving btrfs data uncommitted during emergency
sync.
- Use local kmap in watch_queue's post_one_notification().
- Add hint prints in sb_set_blocksize() for LBS dependency on THP"
* tag 'vfs-6.19-rc1.misc' of git://git.kernel.org/pub/scm/linux/kernel/git/vfs/vfs: (35 commits)
MAINTAINERS: add German Maglione as virtiofs co-maintainer
fs: inline step_into() and walk_component()
fs: tidy up step_into() & friends before inlining
orangefs: use inode_update_timestamps directly
btrfs: fix the comment on btrfs_update_time
btrfs: use vfs_utimes to update file timestamps
fs: export vfs_utimes
fs: lift the FMODE_NOCMTIME check into file_update_time_flags
fs: refactor file timestamp update logic
include/linux/fs.h: trivial fix: regualr -> regular
fs/splice.c: trivial fix: pipes -> pipe's
fs: mark lookup_slow() as noinline
fs: add predicts based on nd->depth
fs: move mntput_no_expire() slowpath into a dedicated routine
fs: remove spurious exports in fs/file_attr.c
watch_queue: Use local kmap in post_one_notification()
fs: touch up predicts in path lookup
fs: move fd_install() slowpath into a dedicated routine and provide commentary
fs: hide dentry_cache behind runtime const machinery
fs: touch predicts in do_dentry_open()
...
This commit is contained in:
@@ -27166,6 +27166,7 @@ F: arch/s390/include/uapi/asm/virtio-ccw.h
|
||||
F: drivers/s390/virtio/
|
||||
|
||||
VIRTIO FILE SYSTEM
|
||||
M: German Maglione <gmaglione@redhat.com>
|
||||
M: Vivek Goyal <vgoyal@redhat.com>
|
||||
M: Stefan Hajnoczi <stefanha@redhat.com>
|
||||
M: Miklos Szeredi <miklos@szeredi.hu>
|
||||
|
||||
@@ -1061,6 +1061,9 @@ NOSTDINC_FLAGS += -nostdinc
|
||||
# perform bounds checking.
|
||||
KBUILD_CFLAGS += $(call cc-option, -fstrict-flex-arrays=3)
|
||||
|
||||
# Allow including a tagged struct or union anonymously in another struct/union.
|
||||
KBUILD_CFLAGS += -fms-extensions
|
||||
|
||||
# disable invalid "can't wrap" optimizations for signed / pointers
|
||||
KBUILD_CFLAGS += -fno-strict-overflow
|
||||
|
||||
|
||||
@@ -63,7 +63,7 @@ VDSO_CFLAGS += -Wall -Wundef -Wstrict-prototypes -Wno-trigraphs \
|
||||
$(filter -Werror,$(KBUILD_CPPFLAGS)) \
|
||||
-Werror-implicit-function-declaration \
|
||||
-Wno-format-security \
|
||||
-std=gnu11
|
||||
-std=gnu11 -fms-extensions
|
||||
VDSO_CFLAGS += -O2
|
||||
# Some useful compiler-dependent flags from top-level Makefile
|
||||
VDSO_CFLAGS += $(call cc32-option,-Wno-pointer-sign)
|
||||
@@ -71,6 +71,7 @@ VDSO_CFLAGS += -fno-strict-overflow
|
||||
VDSO_CFLAGS += $(call cc32-option,-Werror=strict-prototypes)
|
||||
VDSO_CFLAGS += -Werror=date-time
|
||||
VDSO_CFLAGS += $(call cc32-option,-Werror=incompatible-pointer-types)
|
||||
VDSO_CFLAGS += $(if $(CONFIG_CC_IS_CLANG),-Wno-microsoft-anon-tag)
|
||||
|
||||
# Compile as THUMB2 or ARM. Unwinding via frame-pointers in THUMB2 is
|
||||
# unreliable.
|
||||
|
||||
@@ -19,7 +19,7 @@ ccflags-vdso := \
|
||||
cflags-vdso := $(ccflags-vdso) \
|
||||
-isystem $(shell $(CC) -print-file-name=include) \
|
||||
$(filter -W%,$(filter-out -Wa$(comma)%,$(KBUILD_CFLAGS))) \
|
||||
-std=gnu11 -O2 -g -fno-strict-aliasing -fno-common -fno-builtin \
|
||||
-std=gnu11 -fms-extensions -O2 -g -fno-strict-aliasing -fno-common -fno-builtin \
|
||||
-fno-stack-protector -fno-jump-tables -DDISABLE_BRANCH_PROFILING \
|
||||
$(call cc-option, -fno-asynchronous-unwind-tables) \
|
||||
$(call cc-option, -fno-stack-protector)
|
||||
|
||||
@@ -18,7 +18,7 @@ KBUILD_CFLAGS += -fno-PIE -mno-space-regs -mdisable-fpregs -Os
|
||||
ifndef CONFIG_64BIT
|
||||
KBUILD_CFLAGS += -mfast-indirect-calls
|
||||
endif
|
||||
KBUILD_CFLAGS += -std=gnu11
|
||||
KBUILD_CFLAGS += -std=gnu11 -fms-extensions
|
||||
|
||||
LDFLAGS_vmlinux := -X -e startup --as-needed -T
|
||||
$(obj)/vmlinux: $(obj)/vmlinux.lds $(addprefix $(obj)/, $(OBJECTS)) $(LIBGCC) FORCE
|
||||
|
||||
@@ -70,7 +70,7 @@ BOOTCPPFLAGS := -nostdinc $(LINUXINCLUDE)
|
||||
BOOTCPPFLAGS += -isystem $(shell $(BOOTCC) -print-file-name=include)
|
||||
|
||||
BOOTCFLAGS := $(BOOTTARGETFLAGS) \
|
||||
-std=gnu11 \
|
||||
-std=gnu11 -fms-extensions \
|
||||
-Wall -Wundef -Wstrict-prototypes -Wno-trigraphs \
|
||||
-fno-strict-aliasing -O2 \
|
||||
-msoft-float -mno-altivec -mno-vsx \
|
||||
@@ -86,6 +86,7 @@ BOOTARFLAGS := -crD
|
||||
|
||||
ifdef CONFIG_CC_IS_CLANG
|
||||
BOOTCFLAGS += $(CLANG_FLAGS)
|
||||
BOOTCFLAGS += -Wno-microsoft-anon-tag
|
||||
BOOTAFLAGS += $(CLANG_FLAGS)
|
||||
endif
|
||||
|
||||
|
||||
+2
-1
@@ -22,7 +22,7 @@ KBUILD_AFLAGS_DECOMPRESSOR := $(CLANG_FLAGS) -m64 -D__ASSEMBLY__
|
||||
ifndef CONFIG_AS_IS_LLVM
|
||||
KBUILD_AFLAGS_DECOMPRESSOR += $(if $(CONFIG_DEBUG_INFO),$(aflags_dwarf))
|
||||
endif
|
||||
KBUILD_CFLAGS_DECOMPRESSOR := $(CLANG_FLAGS) -m64 -O2 -mpacked-stack -std=gnu11
|
||||
KBUILD_CFLAGS_DECOMPRESSOR := $(CLANG_FLAGS) -m64 -O2 -mpacked-stack -std=gnu11 -fms-extensions
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += -DDISABLE_BRANCH_PROFILING -D__NO_FORTIFY
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += -D__DECOMPRESSOR
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += -Wno-pointer-sign
|
||||
@@ -35,6 +35,7 @@ KBUILD_CFLAGS_DECOMPRESSOR += $(call cc-disable-warning, address-of-packed-membe
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += $(if $(CONFIG_DEBUG_INFO),-g)
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += $(if $(CONFIG_DEBUG_INFO_DWARF4), $(call cc-option, -gdwarf-4,))
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += $(if $(CONFIG_CC_NO_ARRAY_BOUNDS),-Wno-array-bounds)
|
||||
KBUILD_CFLAGS_DECOMPRESSOR += $(if $(CONFIG_CC_IS_CLANG),-Wno-microsoft-anon-tag)
|
||||
|
||||
UTS_MACHINE := s390x
|
||||
STACK_SIZE := $(if $(CONFIG_KASAN),65536,$(if $(CONFIG_KMSAN),65536,16384))
|
||||
|
||||
@@ -13,7 +13,7 @@ CFLAGS_sha256.o := -D__NO_FORTIFY
|
||||
$(obj)/mem.o: $(srctree)/arch/s390/lib/mem.S FORCE
|
||||
$(call if_changed_rule,as_o_S)
|
||||
|
||||
KBUILD_CFLAGS := -std=gnu11 -fno-strict-aliasing -Wall -Wstrict-prototypes
|
||||
KBUILD_CFLAGS := -std=gnu11 -fms-extensions -fno-strict-aliasing -Wall -Wstrict-prototypes
|
||||
KBUILD_CFLAGS += -Wno-pointer-sign -Wno-sign-compare
|
||||
KBUILD_CFLAGS += -fno-zero-initialized-in-bss -fno-builtin -ffreestanding
|
||||
KBUILD_CFLAGS += -Os -m64 -msoft-float -fno-common
|
||||
@@ -21,6 +21,7 @@ KBUILD_CFLAGS += -fno-stack-protector
|
||||
KBUILD_CFLAGS += -DDISABLE_BRANCH_PROFILING
|
||||
KBUILD_CFLAGS += -D__DISABLE_EXPORTS
|
||||
KBUILD_CFLAGS += $(CLANG_FLAGS)
|
||||
KBUILD_CFLAGS += $(if $(CONFIG_CC_IS_CLANG),-Wno-microsoft-anon-tag)
|
||||
KBUILD_CFLAGS += $(call cc-option,-fno-PIE)
|
||||
KBUILD_AFLAGS := $(filter-out -DCC_USING_EXPOLINE,$(KBUILD_AFLAGS))
|
||||
KBUILD_AFLAGS += -D__DISABLE_EXPORTS
|
||||
|
||||
+3
-1
@@ -48,7 +48,8 @@ endif
|
||||
|
||||
# How to compile the 16-bit code. Note we always compile for -march=i386;
|
||||
# that way we can complain to the user if the CPU is insufficient.
|
||||
REALMODE_CFLAGS := -std=gnu11 -m16 -g -Os -DDISABLE_BRANCH_PROFILING -D__DISABLE_EXPORTS \
|
||||
REALMODE_CFLAGS := -std=gnu11 -fms-extensions -m16 -g -Os \
|
||||
-DDISABLE_BRANCH_PROFILING -D__DISABLE_EXPORTS \
|
||||
-Wall -Wstrict-prototypes -march=i386 -mregparm=3 \
|
||||
-fno-strict-aliasing -fomit-frame-pointer -fno-pic \
|
||||
-mno-mmx -mno-sse $(call cc-option,-fcf-protection=none)
|
||||
@@ -60,6 +61,7 @@ REALMODE_CFLAGS += $(cc_stack_align4)
|
||||
REALMODE_CFLAGS += $(CLANG_FLAGS)
|
||||
ifdef CONFIG_CC_IS_CLANG
|
||||
REALMODE_CFLAGS += -Wno-gnu
|
||||
REALMODE_CFLAGS += -Wno-microsoft-anon-tag
|
||||
endif
|
||||
export REALMODE_CFLAGS
|
||||
|
||||
|
||||
@@ -25,7 +25,7 @@ targets := vmlinux vmlinux.bin vmlinux.bin.gz vmlinux.bin.bz2 vmlinux.bin.lzma \
|
||||
# avoid errors with '-march=i386', and future flags may depend on the target to
|
||||
# be valid.
|
||||
KBUILD_CFLAGS := -m$(BITS) -O2 $(CLANG_FLAGS)
|
||||
KBUILD_CFLAGS += -std=gnu11
|
||||
KBUILD_CFLAGS += -std=gnu11 -fms-extensions
|
||||
KBUILD_CFLAGS += -fno-strict-aliasing -fPIE
|
||||
KBUILD_CFLAGS += -Wundef
|
||||
KBUILD_CFLAGS += -DDISABLE_BRANCH_PROFILING
|
||||
@@ -36,7 +36,10 @@ KBUILD_CFLAGS += -mno-mmx -mno-sse
|
||||
KBUILD_CFLAGS += -ffreestanding -fshort-wchar
|
||||
KBUILD_CFLAGS += -fno-stack-protector
|
||||
KBUILD_CFLAGS += $(call cc-disable-warning, address-of-packed-member)
|
||||
KBUILD_CFLAGS += $(call cc-disable-warning, gnu)
|
||||
ifdef CONFIG_CC_IS_CLANG
|
||||
KBUILD_CFLAGS += -Wno-gnu
|
||||
KBUILD_CFLAGS += -Wno-microsoft-anon-tag
|
||||
endif
|
||||
KBUILD_CFLAGS += -Wno-pointer-sign
|
||||
KBUILD_CFLAGS += -fno-asynchronous-unwind-tables
|
||||
KBUILD_CFLAGS += -D__DISABLE_EXPORTS
|
||||
|
||||
+18
-1
@@ -217,9 +217,26 @@ int set_blocksize(struct file *file, int size)
|
||||
|
||||
EXPORT_SYMBOL(set_blocksize);
|
||||
|
||||
static int sb_validate_large_blocksize(struct super_block *sb, int size)
|
||||
{
|
||||
const char *err_str = NULL;
|
||||
|
||||
if (!(sb->s_type->fs_flags & FS_LBS))
|
||||
err_str = "not supported by filesystem";
|
||||
else if (!IS_ENABLED(CONFIG_TRANSPARENT_HUGEPAGE))
|
||||
err_str = "is only supported with CONFIG_TRANSPARENT_HUGEPAGE";
|
||||
|
||||
if (!err_str)
|
||||
return 0;
|
||||
|
||||
pr_warn_ratelimited("%s: block size(%d) > page size(%lu) %s\n",
|
||||
sb->s_type->name, size, PAGE_SIZE, err_str);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
int sb_set_blocksize(struct super_block *sb, int size)
|
||||
{
|
||||
if (!(sb->s_type->fs_flags & FS_LBS) && size > PAGE_SIZE)
|
||||
if (size > PAGE_SIZE && sb_validate_large_blocksize(sb, size))
|
||||
return 0;
|
||||
if (set_blocksize(sb->s_bdev_file, size))
|
||||
return 0;
|
||||
|
||||
@@ -11,12 +11,12 @@ cflags-y := $(KBUILD_CFLAGS)
|
||||
|
||||
cflags-$(CONFIG_X86_32) := -march=i386
|
||||
cflags-$(CONFIG_X86_64) := -mcmodel=small
|
||||
cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ -std=gnu11 \
|
||||
cflags-$(CONFIG_X86) += -m$(BITS) -D__KERNEL__ -std=gnu11 -fms-extensions \
|
||||
-fPIC -fno-strict-aliasing -mno-red-zone \
|
||||
-mno-mmx -mno-sse -fshort-wchar \
|
||||
-Wno-pointer-sign \
|
||||
$(call cc-disable-warning, address-of-packed-member) \
|
||||
$(call cc-disable-warning, gnu) \
|
||||
$(if $(CONFIG_CC_IS_CLANG),-Wno-gnu -Wno-microsoft-anon-tag) \
|
||||
-fno-asynchronous-unwind-tables \
|
||||
$(CLANG_FLAGS)
|
||||
|
||||
|
||||
+13
-3
@@ -5839,6 +5839,8 @@ struct btrfs_inode *btrfs_iget(u64 ino, struct btrfs_root *root)
|
||||
if (ret)
|
||||
return ERR_PTR(ret);
|
||||
|
||||
if (S_ISDIR(inode->vfs_inode.i_mode))
|
||||
inode->vfs_inode.i_opflags |= IOP_FASTPERM_MAY_EXEC;
|
||||
unlock_new_inode(&inode->vfs_inode);
|
||||
return inode;
|
||||
}
|
||||
@@ -6291,8 +6293,8 @@ static int btrfs_dirty_inode(struct btrfs_inode *inode)
|
||||
}
|
||||
|
||||
/*
|
||||
* This is a copy of file_update_time. We need this so we can return error on
|
||||
* ENOSPC for updating the inode in the case of file write and mmap writes.
|
||||
* We need our own ->update_time so that we can return error on ENOSPC for
|
||||
* updating the inode in the case of file write and mmap writes.
|
||||
*/
|
||||
static int btrfs_update_time(struct inode *inode, int flags)
|
||||
{
|
||||
@@ -6790,8 +6792,11 @@ static int btrfs_create_common(struct inode *dir, struct dentry *dentry,
|
||||
}
|
||||
|
||||
ret = btrfs_create_new_inode(trans, &new_inode_args);
|
||||
if (!ret)
|
||||
if (!ret) {
|
||||
if (S_ISDIR(inode->i_mode))
|
||||
inode->i_opflags |= IOP_FASTPERM_MAY_EXEC;
|
||||
d_instantiate_new(dentry, inode);
|
||||
}
|
||||
|
||||
btrfs_end_transaction(trans);
|
||||
btrfs_btree_balance_dirty(fs_info);
|
||||
@@ -9170,6 +9175,11 @@ int btrfs_prealloc_file_range_trans(struct inode *inode,
|
||||
min_size, actual_len, alloc_hint, trans);
|
||||
}
|
||||
|
||||
/*
|
||||
* NOTE: in case you are adding MAY_EXEC check for directories:
|
||||
* we are marking them with IOP_FASTPERM_MAY_EXEC, allowing path lookup to
|
||||
* elide calls here.
|
||||
*/
|
||||
static int btrfs_permission(struct mnt_idmap *idmap,
|
||||
struct inode *inode, int mask)
|
||||
{
|
||||
|
||||
+4
-7
@@ -2002,14 +2002,11 @@ out:
|
||||
static void update_dev_time(const char *device_path)
|
||||
{
|
||||
struct path path;
|
||||
int ret;
|
||||
|
||||
ret = kern_path(device_path, LOOKUP_FOLLOW, &path);
|
||||
if (ret)
|
||||
return;
|
||||
|
||||
inode_update_time(d_inode(path.dentry), S_MTIME | S_CTIME | S_VERSION);
|
||||
path_put(&path);
|
||||
if (!kern_path(device_path, LOOKUP_FOLLOW, &path)) {
|
||||
vfs_utimes(&path, NULL);
|
||||
path_put(&path);
|
||||
}
|
||||
}
|
||||
|
||||
static int btrfs_rm_dev_item(struct btrfs_trans_handle *trans,
|
||||
|
||||
+4
-2
@@ -86,7 +86,8 @@ __cacheline_aligned_in_smp DEFINE_SEQLOCK(rename_lock);
|
||||
|
||||
EXPORT_SYMBOL(rename_lock);
|
||||
|
||||
static struct kmem_cache *dentry_cache __ro_after_init;
|
||||
static struct kmem_cache *__dentry_cache __ro_after_init;
|
||||
#define dentry_cache runtime_const_ptr(__dentry_cache)
|
||||
|
||||
const struct qstr empty_name = QSTR_INIT("", 0);
|
||||
EXPORT_SYMBOL(empty_name);
|
||||
@@ -3222,9 +3223,10 @@ static void __init dcache_init(void)
|
||||
* but it is probably not worth it because of the cache nature
|
||||
* of the dcache.
|
||||
*/
|
||||
dentry_cache = KMEM_CACHE_USERCOPY(dentry,
|
||||
__dentry_cache = KMEM_CACHE_USERCOPY(dentry,
|
||||
SLAB_RECLAIM_ACCOUNT|SLAB_PANIC|SLAB_ACCOUNT,
|
||||
d_shortname.string);
|
||||
runtime_const_init(ptr, __dentry_cache);
|
||||
|
||||
/* Hash may have been set up in dcache_init_early */
|
||||
if (!hashdist)
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@ config ECRYPT_FS
|
||||
depends on KEYS && CRYPTO && (ENCRYPTED_KEYS || ENCRYPTED_KEYS=n)
|
||||
select CRYPTO_ECB
|
||||
select CRYPTO_CBC
|
||||
select CRYPTO_MD5
|
||||
select CRYPTO_LIB_MD5
|
||||
help
|
||||
Encrypted filesystem that operates on the VFS layer. See
|
||||
<file:Documentation/filesystems/ecryptfs.rst> to learn more about
|
||||
|
||||
+9
-81
@@ -9,7 +9,6 @@
|
||||
* Michael C. Thompson <mcthomps@us.ibm.com>
|
||||
*/
|
||||
|
||||
#include <crypto/hash.h>
|
||||
#include <crypto/skcipher.h>
|
||||
#include <linux/fs.h>
|
||||
#include <linux/mount.h>
|
||||
@@ -48,32 +47,6 @@ void ecryptfs_from_hex(char *dst, char *src, int dst_size)
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* ecryptfs_calculate_md5 - calculates the md5 of @src
|
||||
* @dst: Pointer to 16 bytes of allocated memory
|
||||
* @crypt_stat: Pointer to crypt_stat struct for the current inode
|
||||
* @src: Data to be md5'd
|
||||
* @len: Length of @src
|
||||
*
|
||||
* Uses the allocated crypto context that crypt_stat references to
|
||||
* generate the MD5 sum of the contents of src.
|
||||
*/
|
||||
static int ecryptfs_calculate_md5(char *dst,
|
||||
struct ecryptfs_crypt_stat *crypt_stat,
|
||||
char *src, int len)
|
||||
{
|
||||
int rc = crypto_shash_tfm_digest(crypt_stat->hash_tfm, src, len, dst);
|
||||
|
||||
if (rc) {
|
||||
printk(KERN_ERR
|
||||
"%s: Error computing crypto hash; rc = [%d]\n",
|
||||
__func__, rc);
|
||||
goto out;
|
||||
}
|
||||
out:
|
||||
return rc;
|
||||
}
|
||||
|
||||
static int ecryptfs_crypto_api_algify_cipher_name(char **algified_name,
|
||||
char *cipher_name,
|
||||
char *chaining_modifier)
|
||||
@@ -104,13 +77,10 @@ out:
|
||||
*
|
||||
* Generate the initialization vector from the given root IV and page
|
||||
* offset.
|
||||
*
|
||||
* Returns zero on success; non-zero on error.
|
||||
*/
|
||||
int ecryptfs_derive_iv(char *iv, struct ecryptfs_crypt_stat *crypt_stat,
|
||||
loff_t offset)
|
||||
void ecryptfs_derive_iv(char *iv, struct ecryptfs_crypt_stat *crypt_stat,
|
||||
loff_t offset)
|
||||
{
|
||||
int rc = 0;
|
||||
char dst[MD5_DIGEST_SIZE];
|
||||
char src[ECRYPTFS_MAX_IV_BYTES + 16];
|
||||
|
||||
@@ -129,20 +99,12 @@ int ecryptfs_derive_iv(char *iv, struct ecryptfs_crypt_stat *crypt_stat,
|
||||
ecryptfs_printk(KERN_DEBUG, "source:\n");
|
||||
ecryptfs_dump_hex(src, (crypt_stat->iv_bytes + 16));
|
||||
}
|
||||
rc = ecryptfs_calculate_md5(dst, crypt_stat, src,
|
||||
(crypt_stat->iv_bytes + 16));
|
||||
if (rc) {
|
||||
ecryptfs_printk(KERN_WARNING, "Error attempting to compute "
|
||||
"MD5 while generating IV for a page\n");
|
||||
goto out;
|
||||
}
|
||||
md5(src, crypt_stat->iv_bytes + 16, dst);
|
||||
memcpy(iv, dst, crypt_stat->iv_bytes);
|
||||
if (unlikely(ecryptfs_verbosity > 0)) {
|
||||
ecryptfs_printk(KERN_DEBUG, "derived iv:\n");
|
||||
ecryptfs_dump_hex(iv, crypt_stat->iv_bytes);
|
||||
}
|
||||
out:
|
||||
return rc;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -151,29 +113,14 @@ out:
|
||||
*
|
||||
* Initialize the crypt_stat structure.
|
||||
*/
|
||||
int ecryptfs_init_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
void ecryptfs_init_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
{
|
||||
struct crypto_shash *tfm;
|
||||
int rc;
|
||||
|
||||
tfm = crypto_alloc_shash(ECRYPTFS_DEFAULT_HASH, 0, 0);
|
||||
if (IS_ERR(tfm)) {
|
||||
rc = PTR_ERR(tfm);
|
||||
ecryptfs_printk(KERN_ERR, "Error attempting to "
|
||||
"allocate crypto context; rc = [%d]\n",
|
||||
rc);
|
||||
return rc;
|
||||
}
|
||||
|
||||
memset((void *)crypt_stat, 0, sizeof(struct ecryptfs_crypt_stat));
|
||||
INIT_LIST_HEAD(&crypt_stat->keysig_list);
|
||||
mutex_init(&crypt_stat->keysig_list_mutex);
|
||||
mutex_init(&crypt_stat->cs_mutex);
|
||||
mutex_init(&crypt_stat->cs_tfm_mutex);
|
||||
crypt_stat->hash_tfm = tfm;
|
||||
crypt_stat->flags |= ECRYPTFS_STRUCT_INITIALIZED;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -187,7 +134,6 @@ void ecryptfs_destroy_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
struct ecryptfs_key_sig *key_sig, *key_sig_tmp;
|
||||
|
||||
crypto_free_skcipher(crypt_stat->tfm);
|
||||
crypto_free_shash(crypt_stat->hash_tfm);
|
||||
list_for_each_entry_safe(key_sig, key_sig_tmp,
|
||||
&crypt_stat->keysig_list, crypt_stat_list) {
|
||||
list_del(&key_sig->crypt_stat_list);
|
||||
@@ -361,14 +307,7 @@ static int crypt_extent(struct ecryptfs_crypt_stat *crypt_stat,
|
||||
int rc;
|
||||
|
||||
extent_base = (((loff_t)page_index) * (PAGE_SIZE / extent_size));
|
||||
rc = ecryptfs_derive_iv(extent_iv, crypt_stat,
|
||||
(extent_base + extent_offset));
|
||||
if (rc) {
|
||||
ecryptfs_printk(KERN_ERR, "Error attempting to derive IV for "
|
||||
"extent [0x%.16llx]; rc = [%d]\n",
|
||||
(unsigned long long)(extent_base + extent_offset), rc);
|
||||
goto out;
|
||||
}
|
||||
ecryptfs_derive_iv(extent_iv, crypt_stat, extent_base + extent_offset);
|
||||
|
||||
sg_init_table(&src_sg, 1);
|
||||
sg_init_table(&dst_sg, 1);
|
||||
@@ -609,31 +548,20 @@ void ecryptfs_set_default_sizes(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
*/
|
||||
int ecryptfs_compute_root_iv(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
{
|
||||
int rc = 0;
|
||||
char dst[MD5_DIGEST_SIZE];
|
||||
|
||||
BUG_ON(crypt_stat->iv_bytes > MD5_DIGEST_SIZE);
|
||||
BUG_ON(crypt_stat->iv_bytes <= 0);
|
||||
if (!(crypt_stat->flags & ECRYPTFS_KEY_VALID)) {
|
||||
rc = -EINVAL;
|
||||
ecryptfs_printk(KERN_WARNING, "Session key not valid; "
|
||||
"cannot generate root IV\n");
|
||||
goto out;
|
||||
}
|
||||
rc = ecryptfs_calculate_md5(dst, crypt_stat, crypt_stat->key,
|
||||
crypt_stat->key_size);
|
||||
if (rc) {
|
||||
ecryptfs_printk(KERN_WARNING, "Error attempting to compute "
|
||||
"MD5 while generating root IV\n");
|
||||
goto out;
|
||||
}
|
||||
memcpy(crypt_stat->root_iv, dst, crypt_stat->iv_bytes);
|
||||
out:
|
||||
if (rc) {
|
||||
memset(crypt_stat->root_iv, 0, crypt_stat->iv_bytes);
|
||||
crypt_stat->flags |= ECRYPTFS_SECURITY_WARNING;
|
||||
return -EINVAL;
|
||||
}
|
||||
return rc;
|
||||
md5(crypt_stat->key, crypt_stat->key_size, dst);
|
||||
memcpy(crypt_stat->root_iv, dst, crypt_stat->iv_bytes);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void ecryptfs_generate_new_key(struct ecryptfs_crypt_stat *crypt_stat)
|
||||
|
||||
@@ -14,6 +14,7 @@
|
||||
#ifndef ECRYPTFS_KERNEL_H
|
||||
#define ECRYPTFS_KERNEL_H
|
||||
|
||||
#include <crypto/md5.h>
|
||||
#include <crypto/skcipher.h>
|
||||
#include <keys/user-type.h>
|
||||
#include <keys/encrypted-type.h>
|
||||
@@ -137,8 +138,6 @@ ecryptfs_get_key_payload_data(struct key *key)
|
||||
+ MAGIC_ECRYPTFS_MARKER_SIZE_BYTES)
|
||||
#define ECRYPTFS_DEFAULT_CIPHER "aes"
|
||||
#define ECRYPTFS_DEFAULT_KEY_BYTES 16
|
||||
#define ECRYPTFS_DEFAULT_HASH "md5"
|
||||
#define ECRYPTFS_TAG_70_DIGEST ECRYPTFS_DEFAULT_HASH
|
||||
#define ECRYPTFS_TAG_1_PACKET_TYPE 0x01
|
||||
#define ECRYPTFS_TAG_3_PACKET_TYPE 0x8C
|
||||
#define ECRYPTFS_TAG_11_PACKET_TYPE 0xED
|
||||
@@ -163,8 +162,6 @@ ecryptfs_get_key_payload_data(struct key *key)
|
||||
* ECRYPTFS_MAX_IV_BYTES */
|
||||
#define ECRYPTFS_FILENAME_MIN_RANDOM_PREPEND_BYTES 16
|
||||
#define ECRYPTFS_NON_NULL 0x42 /* A reasonable substitute for NULL */
|
||||
#define MD5_DIGEST_SIZE 16
|
||||
#define ECRYPTFS_TAG_70_DIGEST_SIZE MD5_DIGEST_SIZE
|
||||
#define ECRYPTFS_TAG_70_MIN_METADATA_SIZE (1 + ECRYPTFS_MIN_PKT_LEN_SIZE \
|
||||
+ ECRYPTFS_SIG_SIZE + 1 + 1)
|
||||
#define ECRYPTFS_TAG_70_MAX_METADATA_SIZE (1 + ECRYPTFS_MAX_PKT_LEN_SIZE \
|
||||
@@ -237,8 +234,6 @@ struct ecryptfs_crypt_stat {
|
||||
unsigned int extent_mask;
|
||||
struct ecryptfs_mount_crypt_stat *mount_crypt_stat;
|
||||
struct crypto_skcipher *tfm;
|
||||
struct crypto_shash *hash_tfm; /* Crypto context for generating
|
||||
* the initialization vectors */
|
||||
unsigned char cipher[ECRYPTFS_MAX_CIPHER_NAME_SIZE + 1];
|
||||
unsigned char key[ECRYPTFS_MAX_KEY_BYTES];
|
||||
unsigned char root_iv[ECRYPTFS_MAX_IV_BYTES];
|
||||
@@ -558,7 +553,7 @@ int virt_to_scatterlist(const void *addr, int size, struct scatterlist *sg,
|
||||
int sg_size);
|
||||
int ecryptfs_compute_root_iv(struct ecryptfs_crypt_stat *crypt_stat);
|
||||
void ecryptfs_rotate_iv(unsigned char *iv);
|
||||
int ecryptfs_init_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat);
|
||||
void ecryptfs_init_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat);
|
||||
void ecryptfs_destroy_crypt_stat(struct ecryptfs_crypt_stat *crypt_stat);
|
||||
void ecryptfs_destroy_mount_crypt_stat(
|
||||
struct ecryptfs_mount_crypt_stat *mount_crypt_stat);
|
||||
@@ -693,8 +688,8 @@ ecryptfs_parse_tag_70_packet(char **filename, size_t *filename_size,
|
||||
char *data, size_t max_packet_size);
|
||||
int ecryptfs_set_f_namelen(long *namelen, long lower_namelen,
|
||||
struct ecryptfs_mount_crypt_stat *mount_crypt_stat);
|
||||
int ecryptfs_derive_iv(char *iv, struct ecryptfs_crypt_stat *crypt_stat,
|
||||
loff_t offset);
|
||||
void ecryptfs_derive_iv(char *iv, struct ecryptfs_crypt_stat *crypt_stat,
|
||||
loff_t offset);
|
||||
|
||||
extern const struct xattr_handler * const ecryptfs_xattr_handlers[];
|
||||
|
||||
|
||||
+2
-5
@@ -903,11 +903,8 @@ static int ecryptfs_setattr(struct mnt_idmap *idmap,
|
||||
struct ecryptfs_crypt_stat *crypt_stat;
|
||||
|
||||
crypt_stat = &ecryptfs_inode_to_private(d_inode(dentry))->crypt_stat;
|
||||
if (!(crypt_stat->flags & ECRYPTFS_STRUCT_INITIALIZED)) {
|
||||
rc = ecryptfs_init_crypt_stat(crypt_stat);
|
||||
if (rc)
|
||||
return rc;
|
||||
}
|
||||
if (!(crypt_stat->flags & ECRYPTFS_STRUCT_INITIALIZED))
|
||||
ecryptfs_init_crypt_stat(crypt_stat);
|
||||
inode = d_inode(dentry);
|
||||
lower_inode = ecryptfs_inode_to_lower(inode);
|
||||
lower_dentry = ecryptfs_dentry_to_lower(dentry);
|
||||
|
||||
+11
-54
@@ -11,7 +11,6 @@
|
||||
* Trevor S. Highland <trevor.highland@gmail.com>
|
||||
*/
|
||||
|
||||
#include <crypto/hash.h>
|
||||
#include <crypto/skcipher.h>
|
||||
#include <linux/string.h>
|
||||
#include <linux/pagemap.h>
|
||||
@@ -601,10 +600,7 @@ struct ecryptfs_write_tag_70_packet_silly_stack {
|
||||
struct crypto_skcipher *skcipher_tfm;
|
||||
struct skcipher_request *skcipher_req;
|
||||
char iv[ECRYPTFS_MAX_IV_BYTES];
|
||||
char hash[ECRYPTFS_TAG_70_DIGEST_SIZE];
|
||||
char tmp_hash[ECRYPTFS_TAG_70_DIGEST_SIZE];
|
||||
struct crypto_shash *hash_tfm;
|
||||
struct shash_desc *hash_desc;
|
||||
char hash[MD5_DIGEST_SIZE];
|
||||
};
|
||||
|
||||
/*
|
||||
@@ -741,51 +737,15 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
|
||||
"password tokens\n", __func__);
|
||||
goto out_free_unlock;
|
||||
}
|
||||
s->hash_tfm = crypto_alloc_shash(ECRYPTFS_TAG_70_DIGEST, 0, 0);
|
||||
if (IS_ERR(s->hash_tfm)) {
|
||||
rc = PTR_ERR(s->hash_tfm);
|
||||
printk(KERN_ERR "%s: Error attempting to "
|
||||
"allocate hash crypto context; rc = [%d]\n",
|
||||
__func__, rc);
|
||||
goto out_free_unlock;
|
||||
}
|
||||
|
||||
s->hash_desc = kmalloc(sizeof(*s->hash_desc) +
|
||||
crypto_shash_descsize(s->hash_tfm), GFP_KERNEL);
|
||||
if (!s->hash_desc) {
|
||||
rc = -ENOMEM;
|
||||
goto out_release_free_unlock;
|
||||
}
|
||||
|
||||
s->hash_desc->tfm = s->hash_tfm;
|
||||
|
||||
rc = crypto_shash_digest(s->hash_desc,
|
||||
(u8 *)s->auth_tok->token.password.session_key_encryption_key,
|
||||
s->auth_tok->token.password.session_key_encryption_key_bytes,
|
||||
s->hash);
|
||||
if (rc) {
|
||||
printk(KERN_ERR
|
||||
"%s: Error computing crypto hash; rc = [%d]\n",
|
||||
__func__, rc);
|
||||
goto out_release_free_unlock;
|
||||
}
|
||||
md5(s->auth_tok->token.password.session_key_encryption_key,
|
||||
s->auth_tok->token.password.session_key_encryption_key_bytes,
|
||||
s->hash);
|
||||
for (s->j = 0; s->j < (s->num_rand_bytes - 1); s->j++) {
|
||||
s->block_aligned_filename[s->j] =
|
||||
s->hash[(s->j % ECRYPTFS_TAG_70_DIGEST_SIZE)];
|
||||
if ((s->j % ECRYPTFS_TAG_70_DIGEST_SIZE)
|
||||
== (ECRYPTFS_TAG_70_DIGEST_SIZE - 1)) {
|
||||
rc = crypto_shash_digest(s->hash_desc, (u8 *)s->hash,
|
||||
ECRYPTFS_TAG_70_DIGEST_SIZE,
|
||||
s->tmp_hash);
|
||||
if (rc) {
|
||||
printk(KERN_ERR
|
||||
"%s: Error computing crypto hash; "
|
||||
"rc = [%d]\n", __func__, rc);
|
||||
goto out_release_free_unlock;
|
||||
}
|
||||
memcpy(s->hash, s->tmp_hash,
|
||||
ECRYPTFS_TAG_70_DIGEST_SIZE);
|
||||
}
|
||||
s->hash[s->j % MD5_DIGEST_SIZE];
|
||||
if ((s->j % MD5_DIGEST_SIZE) == (MD5_DIGEST_SIZE - 1))
|
||||
md5(s->hash, MD5_DIGEST_SIZE, s->hash);
|
||||
if (s->block_aligned_filename[s->j] == '\0')
|
||||
s->block_aligned_filename[s->j] = ECRYPTFS_NON_NULL;
|
||||
}
|
||||
@@ -798,7 +758,7 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
|
||||
"convert filename memory to scatterlist; rc = [%d]. "
|
||||
"block_aligned_filename_size = [%zd]\n", __func__, rc,
|
||||
s->block_aligned_filename_size);
|
||||
goto out_release_free_unlock;
|
||||
goto out_free_unlock;
|
||||
}
|
||||
rc = virt_to_scatterlist(&dest[s->i], s->block_aligned_filename_size,
|
||||
s->dst_sg, 2);
|
||||
@@ -807,7 +767,7 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
|
||||
"convert encrypted filename memory to scatterlist; "
|
||||
"rc = [%d]. block_aligned_filename_size = [%zd]\n",
|
||||
__func__, rc, s->block_aligned_filename_size);
|
||||
goto out_release_free_unlock;
|
||||
goto out_free_unlock;
|
||||
}
|
||||
/* The characters in the first block effectively do the job
|
||||
* of the IV here, so we just use 0's for the IV. Note the
|
||||
@@ -825,7 +785,7 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
|
||||
rc,
|
||||
s->auth_tok->token.password.session_key_encryption_key,
|
||||
mount_crypt_stat->global_default_fn_cipher_key_bytes);
|
||||
goto out_release_free_unlock;
|
||||
goto out_free_unlock;
|
||||
}
|
||||
skcipher_request_set_crypt(s->skcipher_req, s->src_sg, s->dst_sg,
|
||||
s->block_aligned_filename_size, s->iv);
|
||||
@@ -833,13 +793,11 @@ ecryptfs_write_tag_70_packet(char *dest, size_t *remaining_bytes,
|
||||
if (rc) {
|
||||
printk(KERN_ERR "%s: Error attempting to encrypt filename; "
|
||||
"rc = [%d]\n", __func__, rc);
|
||||
goto out_release_free_unlock;
|
||||
goto out_free_unlock;
|
||||
}
|
||||
s->i += s->block_aligned_filename_size;
|
||||
(*packet_size) = s->i;
|
||||
(*remaining_bytes) -= (*packet_size);
|
||||
out_release_free_unlock:
|
||||
crypto_free_shash(s->hash_tfm);
|
||||
out_free_unlock:
|
||||
kfree_sensitive(s->block_aligned_filename);
|
||||
out_unlock:
|
||||
@@ -850,7 +808,6 @@ out:
|
||||
key_put(auth_tok_key);
|
||||
}
|
||||
skcipher_request_free(s->skcipher_req);
|
||||
kfree_sensitive(s->hash_desc);
|
||||
kfree(s);
|
||||
return rc;
|
||||
}
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user