1 /*
2 * Copyright (c) 2000-2015 Apple Inc. All rights reserved.
3 *
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
14 *
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17 *
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
25 *
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27 */
28 /* Copyright (c) 1995 NeXT Computer, Inc. All Rights Reserved */
29 /*
30 * Copyright (c) 1989, 1993, 1995
31 * The Regents of the University of California. All rights reserved.
32 *
33 * This code is derived from software contributed to Berkeley by
34 * Poul-Henning Kamp of the FreeBSD Project.
35 *
36 * Redistribution and use in source and binary forms, with or without
37 * modification, are permitted provided that the following conditions
38 * are met:
39 * 1. Redistributions of source code must retain the above copyright
40 * notice, this list of conditions and the following disclaimer.
41 * 2. Redistributions in binary form must reproduce the above copyright
42 * notice, this list of conditions and the following disclaimer in the
43 * documentation and/or other materials provided with the distribution.
44 * 3. All advertising materials mentioning features or use of this software
45 * must display the following acknowledgement:
46 * This product includes software developed by the University of
47 * California, Berkeley and its contributors.
48 * 4. Neither the name of the University nor the names of its contributors
49 * may be used to endorse or promote products derived from this software
50 * without specific prior written permission.
51 *
52 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
53 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
54 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
55 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
56 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
57 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
58 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
59 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
60 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
61 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
62 * SUCH DAMAGE.
63 *
64 *
65 * @(#)vfs_cache.c 8.5 (Berkeley) 3/22/95
66 */
67 /*
68 * NOTICE: This file was modified by SPARTA, Inc. in 2005 to introduce
69 * support for mandatory and extensible security protections. This notice
70 * is included in support of clause 2.2 (b) of the Apple Public License,
71 * Version 2.0.
72 */
73 #include <sys/param.h>
74 #include <sys/systm.h>
75 #include <sys/time.h>
76 #include <sys/mount_internal.h>
77 #include <sys/vnode_internal.h>
78 #include <miscfs/specfs/specdev.h>
79 #include <sys/namei.h>
80 #include <sys/errno.h>
81 #include <kern/kalloc.h>
82 #include <sys/kauth.h>
83 #include <sys/user.h>
84 #include <sys/paths.h>
85 #include <os/overflow.h>
86
87 #if CONFIG_MACF
88 #include <security/mac_framework.h>
89 #endif
90
91 /*
92 * Name caching works as follows:
93 *
94 * Names found by directory scans are retained in a cache
95 * for future reference. It is managed LRU, so frequently
96 * used names will hang around. Cache is indexed by hash value
97 * obtained from (vp, name) where vp refers to the directory
98 * containing name.
99 *
100 * If it is a "negative" entry, (i.e. for a name that is known NOT to
101 * exist) the vnode pointer will be NULL.
102 *
103 * Upon reaching the last segment of a path, if the reference
104 * is for DELETE, or NOCACHE is set (rewrite), and the
105 * name is located in the cache, it will be dropped.
106 */
107
108 /*
109 * Structures associated with name cacheing.
110 */
111
112 ZONE_DEFINE_TYPE(namecache_zone, "namecache", struct namecache, ZC_NONE);
113
114 struct smrq_list_head *nchashtbl; /* Hash Table */
115 u_long nchashmask;
116 u_long nchash; /* size of hash table - 1 */
117 long numcache; /* number of cache entries allocated */
118 int desiredNodes;
119 int desiredNegNodes;
120 int ncs_negtotal;
121 TUNABLE_WRITEABLE(int, nc_disabled, "-novfscache", 0);
122 __options_decl(nc_smr_level_t, uint32_t, {
123 NC_SMR_DISABLED = 0,
124 NC_SMR_LOOKUP = 1
125 });
126 TUNABLE(nc_smr_level_t, nc_smr_enabled, "ncsmr", NC_SMR_LOOKUP);
127 TAILQ_HEAD(, namecache) nchead; /* chain of all name cache entries */
128 TAILQ_HEAD(, namecache) neghead; /* chain of only negative cache entries */
129
130
131 #if COLLECT_STATS
132
133 struct nchstats nchstats; /* cache effectiveness statistics */
134
135 #define NCHSTAT(v) { \
136 nchstats.v++; \
137 }
138 #define NAME_CACHE_LOCK_SHARED() name_cache_lock()
139 #define NAME_CACHE_LOCK_SHARED_TO_EXCLUSIVE() TRUE
140
141 #else
142
143 #define NCHSTAT(v)
144 #define NAME_CACHE_LOCK_SHARED() name_cache_lock_shared()
145 #define NAME_CACHE_LOCK_SHARED_TO_EXCLUSIVE() name_cache_lock_shared_to_exclusive()
146
147 #endif
148
149 #define NAME_CACHE_LOCK() name_cache_lock()
150 #define NAME_CACHE_UNLOCK() name_cache_unlock()
151
152 /* vars for name cache list lock */
153 static LCK_GRP_DECLARE(namecache_lck_grp, "Name Cache");
154 static LCK_RW_DECLARE(namecache_rw_lock, &namecache_lck_grp);
155
156 typedef struct string_t {
157 LIST_ENTRY(string_t) hash_chain;
158 char *str;
159 uint32_t strbuflen;
160 uint32_t refcount;
161 } string_t;
162
163 ZONE_DEFINE_TYPE(stringcache_zone, "vfsstringcache", string_t, ZC_NONE);
164
165 static LCK_GRP_DECLARE(strcache_lck_grp, "String Cache");
166 static LCK_ATTR_DECLARE(strcache_lck_attr, 0, 0);
167 LCK_RW_DECLARE_ATTR(strtable_rw_lock, &strcache_lck_grp, &strcache_lck_attr);
168
169 static LCK_GRP_DECLARE(rootvnode_lck_grp, "rootvnode");
170 LCK_RW_DECLARE(rootvnode_rw_lock, &rootvnode_lck_grp);
171
172 #define NUM_STRCACHE_LOCKS 1024
173
174 lck_mtx_t strcache_mtx_locks[NUM_STRCACHE_LOCKS];
175
176 SYSCTL_NODE(_vfs, OID_AUTO, ncstats, CTLFLAG_RD | CTLFLAG_LOCKED, NULL, "vfs name cache stats");
177
178 SYSCTL_COMPAT_INT(_vfs_ncstats, OID_AUTO, nc_smr_enabled,
179 CTLFLAG_RD | CTLFLAG_LOCKED,
180 &nc_smr_enabled, 0, "");
181
182 #if COLLECT_NC_SMR_STATS
183 struct ncstats {
184 uint64_t cl_smr_hits;
185 uint64_t cl_smr_miss;
186 uint64_t cl_smr_negative_hits;
187 uint64_t cl_smr_fallback;
188 uint64_t cl_lock_hits;
189 uint64_t clp_next;
190 uint64_t clp_next_fail;
191 uint64_t clp_smr_next;
192 uint64_t clp_smr_next_fail;
193 uint64_t clp_smr_fallback;
194 uint64_t nc_lock_shared;
195 uint64_t nc_lock;
196 } ncstats = {0};
197
198 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, cl_smr_hits,
199 CTLFLAG_RD | CTLFLAG_LOCKED,
200 &ncstats.cl_smr_hits, "");
201 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, cl_smr_misses,
202 CTLFLAG_RD | CTLFLAG_LOCKED,
203 &ncstats.cl_smr_miss, "");
204 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, cl_smr_negative_hits,
205 CTLFLAG_RD | CTLFLAG_LOCKED,
206 &ncstats.cl_smr_negative_hits, "");
207 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, cl_smr_fallback,
208 CTLFLAG_RD | CTLFLAG_LOCKED,
209 &ncstats.cl_smr_fallback, "");
210 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, cl_lock_hits,
211 CTLFLAG_RD | CTLFLAG_LOCKED,
212 &ncstats.cl_lock_hits, "");
213 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, clp_next,
214 CTLFLAG_RD | CTLFLAG_LOCKED,
215 &ncstats.clp_next, "");
216 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, clp_next_fail,
217 CTLFLAG_RD | CTLFLAG_LOCKED,
218 &ncstats.clp_next_fail, "");
219 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, clp_smr_next,
220 CTLFLAG_RD | CTLFLAG_LOCKED,
221 &ncstats.clp_smr_next, "");
222 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, clp_smr_next_fail,
223 CTLFLAG_RD | CTLFLAG_LOCKED,
224 &ncstats.clp_smr_next_fail, "");
225 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, nc_lock_shared,
226 CTLFLAG_RD | CTLFLAG_LOCKED,
227 &ncstats.nc_lock_shared, "");
228 SYSCTL_LONG(_vfs_ncstats, OID_AUTO, nc_lock,
229 CTLFLAG_RD | CTLFLAG_LOCKED,
230 &ncstats.nc_lock, "");
231
232 #define NC_SMR_STATS(v) os_atomic_inc(&ncstats.v, relaxed)
233 #else
234 #define NC_SMR_STATS(v)
235 #endif /* COLLECT_NC_SMR_STATS */
236
237 static vnode_t cache_lookup_locked(vnode_t dvp, struct componentname *cnp, uint32_t *vidp);
238 static vnode_t cache_lookup_smr(vnode_t dvp, struct componentname *cnp, uint32_t *vidp);
239 static const char *add_name_internal(const char *, uint32_t, u_int, boolean_t, u_int);
240 static void init_string_table(void);
241 static void cache_delete(struct namecache *, int);
242 static void cache_enter_locked(vnode_t dvp, vnode_t vp, struct componentname *cnp, const char *strname);
243 static void cache_purge_locked(vnode_t vp, kauth_cred_t *credp);
244 static void namecache_smr_free(void *, size_t);
245 static void string_smr_free(void *, size_t);
246
247
248 #ifdef DUMP_STRING_TABLE
249 /*
250 * Internal dump function used for debugging
251 */
252 void dump_string_table(void);
253 #endif /* DUMP_STRING_TABLE */
254
255 static void init_crc32(void);
256 static unsigned int crc32tab[256];
257
258
259 #define NCHHASH(dvp, hash_val) \
260 (&nchashtbl[(dvp->v_id ^ (hash_val)) & nchashmask])
261
262 /*
263 * This function tries to check if a directory vp is a subdirectory of dvp
264 * only from valid v_parent pointers. It is called with the name cache lock
265 * held and does not drop the lock anytime inside the function.
266 *
267 * It returns a boolean that indicates whether or not it was able to
268 * successfully infer the parent/descendent relationship via the v_parent
269 * pointers, or if it could not infer such relationship and that the decision
270 * must be delegated to the owning filesystem.
271 *
272 * If it does not defer the decision, i.e. it was successfuly able to determine
273 * the parent/descendent relationship, *is_subdir tells the caller if vp is a
274 * subdirectory of dvp.
275 *
276 * If the decision is deferred, *next_vp is where it stopped i.e. *next_vp
277 * is the vnode whose parent is to be determined from the filesystem.
278 * *is_subdir, in this case, is not indicative of anything and should be
279 * ignored.
280 *
281 * The return value and output args should be used as follows :
282 *
283 * defer = cache_check_vnode_issubdir(vp, dvp, is_subdir, next_vp);
284 * if (!defer) {
285 * if (*is_subdir)
286 * vp is subdirectory;
287 * else
288 * vp is not a subdirectory;
289 * } else {
290 * if (*next_vp)
291 * check this vnode's parent from the filesystem
292 * else
293 * error (likely because of forced unmount).
294 * }
295 *
296 */
297 static boolean_t
cache_check_vnode_issubdir(vnode_t vp,vnode_t dvp,boolean_t * is_subdir,vnode_t * next_vp)298 cache_check_vnode_issubdir(vnode_t vp, vnode_t dvp, boolean_t *is_subdir,
299 vnode_t *next_vp)
300 {
301 vnode_t tvp = vp;
302 int defer = FALSE;
303
304 *is_subdir = FALSE;
305 *next_vp = NULLVP;
306 while (1) {
307 mount_t tmp;
308
309 if (tvp == dvp) {
310 *is_subdir = TRUE;
311 break;
312 } else if (tvp == rootvnode) {
313 /* *is_subdir = FALSE */
314 break;
315 }
316
317 tmp = tvp->v_mount;
318 while ((tvp->v_flag & VROOT) && tmp && tmp->mnt_vnodecovered &&
319 tvp != dvp && tvp != rootvnode) {
320 tvp = tmp->mnt_vnodecovered;
321 tmp = tvp->v_mount;
322 }
323
324 /*
325 * If dvp is not at the top of a mount "stack" then
326 * vp is not a subdirectory of dvp either.
327 */
328 if (tvp == dvp || tvp == rootvnode) {
329 /* *is_subdir = FALSE */
330 break;
331 }
332
333 if (!tmp) {
334 defer = TRUE;
335 *next_vp = NULLVP;
336 break;
337 }
338
339 if ((tvp->v_flag & VISHARDLINK) || !(tvp->v_parent)) {
340 defer = TRUE;
341 *next_vp = tvp;
342 break;
343 }
344
345 tvp = tvp->v_parent;
346 }
347
348 return defer;
349 }
350
351 /* maximum times retry from potentially transient errors in vnode_issubdir */
352 #define MAX_ERROR_RETRY 3
353
354 /*
355 * This function checks if a given directory (vp) is a subdirectory of dvp.
356 * It walks backwards from vp and if it hits dvp in its parent chain,
357 * it is a subdirectory. If it encounters the root directory, it is not
358 * a subdirectory.
359 *
360 * This function returns an error if it is unsuccessful and 0 on success.
361 *
362 * On entry (and exit) vp has an iocount and if this function has to take
363 * any iocounts on other vnodes in the parent chain traversal, it releases them.
364 */
365 int
vnode_issubdir(vnode_t vp,vnode_t dvp,int * is_subdir,vfs_context_t ctx)366 vnode_issubdir(vnode_t vp, vnode_t dvp, int *is_subdir, vfs_context_t ctx)
367 {
368 vnode_t start_vp, tvp;
369 vnode_t vp_with_iocount;
370 int error = 0;
371 char dotdotbuf[] = "..";
372 int error_retry_count = 0; /* retry count for potentially transient
373 * errors */
374
375 *is_subdir = FALSE;
376 tvp = start_vp = vp;
377 /*
378 * Anytime we acquire an iocount in this function, we save the vnode
379 * in this variable and release it before exiting.
380 */
381 vp_with_iocount = NULLVP;
382
383 while (1) {
384 boolean_t defer;
385 vnode_t pvp;
386 uint32_t vid = 0;
387 struct componentname cn;
388 boolean_t is_subdir_locked = FALSE;
389
390 if (tvp == dvp) {
391 *is_subdir = TRUE;
392 break;
393 } else if (tvp == rootvnode) {
394 /* *is_subdir = FALSE */
395 break;
396 }
397
398 NAME_CACHE_LOCK_SHARED();
399
400 defer = cache_check_vnode_issubdir(tvp, dvp, &is_subdir_locked,
401 &tvp);
402
403 if (defer && tvp) {
404 vid = vnode_vid(tvp);
405 vnode_hold(tvp);
406 }
407
408 NAME_CACHE_UNLOCK();
409
410 if (!defer) {
411 *is_subdir = is_subdir_locked;
412 break;
413 }
414
415 if (!tvp) {
416 if (error_retry_count++ < MAX_ERROR_RETRY) {
417 tvp = vp;
418 continue;
419 }
420 error = ENOENT;
421 break;
422 }
423
424 if (tvp != start_vp) {
425 if (vp_with_iocount) {
426 vnode_put(vp_with_iocount);
427 vp_with_iocount = NULLVP;
428 }
429
430 error = vnode_getwithvid(tvp, vid);
431 vnode_drop(tvp);
432 if (error) {
433 if (error_retry_count++ < MAX_ERROR_RETRY) {
434 tvp = vp;
435 error = 0;
436 continue;
437 }
438 break;
439 }
440 vp_with_iocount = tvp;
441 } else {
442 tvp = vnode_drop(tvp);
443 }
444
445 bzero(&cn, sizeof(cn));
446 cn.cn_nameiop = LOOKUP;
447 cn.cn_flags = ISLASTCN | ISDOTDOT;
448 cn.cn_context = ctx;
449 cn.cn_pnbuf = &dotdotbuf[0];
450 cn.cn_pnlen = sizeof(dotdotbuf);
451 cn.cn_nameptr = cn.cn_pnbuf;
452 cn.cn_namelen = 2;
453
454 pvp = NULLVP;
455 if ((error = VNOP_LOOKUP(tvp, &pvp, &cn, ctx))) {
456 break;
457 }
458
459 if (!(tvp->v_flag & VISHARDLINK) && tvp->v_parent != pvp) {
460 (void)vnode_update_identity(tvp, pvp, NULL, 0, 0,
461 VNODE_UPDATE_PARENT);
462 }
463
464 if (vp_with_iocount) {
465 vnode_put(vp_with_iocount);
466 }
467
468 vp_with_iocount = tvp = pvp;
469 }
470
471 if (vp_with_iocount) {
472 vnode_put(vp_with_iocount);
473 }
474
475 return error;
476 }
477
478 /*
479 * This function builds the path in "buff" from the supplied vnode.
480 * The length of the buffer *INCLUDING* the trailing zero byte is
481 * returned in outlen. NOTE: the length includes the trailing zero
482 * byte and thus the length is one greater than what strlen would
483 * return. This is important and lots of code elsewhere in the kernel
484 * assumes this behavior.
485 *
486 * This function can call vnop in file system if the parent vnode
487 * does not exist or when called for hardlinks via volfs path.
488 * If BUILDPATH_NO_FS_ENTER is set in flags, it only uses values present
489 * in the name cache and does not enter the file system.
490 *
491 * If BUILDPATH_CHECK_MOVED is set in flags, we return EAGAIN when
492 * we encounter ENOENT during path reconstruction. ENOENT means that
493 * one of the parents moved while we were building the path. The
494 * caller can special handle this case by calling build_path again.
495 *
496 * If BUILDPATH_VOLUME_RELATIVE is set in flags, we return path
497 * that is relative to the nearest mount point, i.e. do not
498 * cross over mount points during building the path.
499 *
500 * passed in vp must have a valid io_count reference
501 *
502 * If parent vnode is non-NULL it also must have an io count. This
503 * allows build_path_with_parent to be safely called for operations
504 * unlink, rmdir and rename that already have io counts on the target
505 * and the directory. In this way build_path_with_parent does not have
506 * to try and obtain an additional io count on the parent. Taking an
507 * io count ont the parent can lead to dead lock if a forced unmount
508 * occures at the right moment. For a fuller explaination on how this
509 * can occur see the comment for vn_getpath_with_parent.
510 *
511 */
512 int
build_path_with_parent(vnode_t first_vp,vnode_t parent_vp,char * buff,int buflen,int * outlen,size_t * mntpt_outlen,int flags,vfs_context_t ctx)513 build_path_with_parent(vnode_t first_vp, vnode_t parent_vp, char *buff, int buflen,
514 int *outlen, size_t *mntpt_outlen, int flags, vfs_context_t ctx)
515 {
516 vnode_t vp, tvp;
517 vnode_t vp_with_iocount;
518 vnode_t proc_root_dir_vp;
519 char *end;
520 char *mntpt_end;
521 const char *str;
522 unsigned int len;
523 int ret = 0;
524 int fixhardlink;
525
526 if (first_vp == NULLVP) {
527 return EINVAL;
528 }
529
530 if (buflen <= 1) {
531 return ENOSPC;
532 }
533
534 /*
535 * Grab the process fd so we can evaluate fd_rdir.
536 */
537 if (!(flags & BUILDPATH_NO_PROCROOT)) {
538 proc_root_dir_vp = vfs_context_proc(ctx)->p_fd.fd_rdir;
539 } else {
540 proc_root_dir_vp = NULL;
541 }
542
543 vp_with_iocount = NULLVP;
544 again:
545 vp = first_vp;
546
547 end = &buff[buflen - 1];
548 *end = '\0';
549 mntpt_end = NULL;
550
551 /*
552 * Catch a special corner case here: chroot to /full/path/to/dir, chdir to
553 * it, then open it. Without this check, the path to it will be
554 * /full/path/to/dir instead of "/".
555 */
556 if (proc_root_dir_vp == first_vp) {
557 *--end = '/';
558 goto out;
559 }
560
561 /*
562 * holding the NAME_CACHE_LOCK in shared mode is
563 * sufficient to stabilize both the vp->v_parent chain
564 * and the 'vp->v_mount->mnt_vnodecovered' chain
565 *
566 * if we need to drop this lock, we must first grab the v_id
567 * from the vnode we're currently working with... if that
568 * vnode doesn't already have an io_count reference (the vp
569 * passed in comes with one), we must grab a reference
570 * after we drop the NAME_CACHE_LOCK via vnode_getwithvid...
571 * deadlocks may result if you call vnode_get while holding
572 * the NAME_CACHE_LOCK... we lazily release the reference
573 * we pick up the next time we encounter a need to drop
574 * the NAME_CACHE_LOCK or before we return from this routine
575 */
576 NAME_CACHE_LOCK_SHARED();
577
578 #if CONFIG_FIRMLINKS
579 if (!(flags & BUILDPATH_NO_FIRMLINK) &&
580 (vp->v_flag & VFMLINKTARGET) && vp->v_fmlink && (vp->v_fmlink->v_type == VDIR)) {
581 vp = vp->v_fmlink;
582 }
583 #endif
584
585 /*
586 * Check if this is the root of a file system.
587 */
588 while (vp && vp->v_flag & VROOT) {
589 if (vp->v_mount == NULL) {
590 ret = EINVAL;
591 goto out_unlock;
592 }
593 if ((vp->v_mount->mnt_flag & MNT_ROOTFS) || (vp == proc_root_dir_vp)) {
594 /*
595 * It's the root of the root file system, so it's
596 * just "/".
597 */
598 *--end = '/';
599
600 goto out_unlock;
601 } else {
602 /*
603 * This the root of the volume and the caller does not
604 * want to cross mount points. Therefore just return
605 * '/' as the relative path.
606 */
607 #if CONFIG_FIRMLINKS
608 if (!(flags & BUILDPATH_NO_FIRMLINK) &&
609 (vp->v_flag & VFMLINKTARGET) && vp->v_fmlink && (vp->v_fmlink->v_type == VDIR)) {
610 vp = vp->v_fmlink;
611 } else
612 #endif
613 if (flags & BUILDPATH_VOLUME_RELATIVE) {
614 *--end = '/';
615 goto out_unlock;
616 } else {
617 vp = vp->v_mount->mnt_vnodecovered;
618 if (!mntpt_end && vp) {
619 mntpt_end = end;
620 }
621 }
622 }
623 }
624
625 while ((vp != NULLVP) && (vp->v_parent != vp)) {
626 int vid;
627
628 /*
629 * For hardlinks the v_name may be stale, so if its OK
630 * to enter a file system, ask the file system for the
631 * name and parent (below).
632 */
633 fixhardlink = (vp->v_flag & VISHARDLINK) &&
634 (vp->v_mount->mnt_kern_flag & MNTK_PATH_FROM_ID) &&
635 !(flags & BUILDPATH_NO_FS_ENTER);
636
637 if (!fixhardlink) {
638 str = vp->v_name;
639
640 if (str == NULL || *str == '\0') {
641 if (vp->v_parent != NULL) {
642 ret = EINVAL;
643 } else {
644 ret = ENOENT;
645 }
646 goto out_unlock;
647 }
648 len = (unsigned int)strlen(str);
649 /*
650 * Check that there's enough space (including space for the '/')
651 */
652 if ((unsigned int)(end - buff) < (len + 1)) {
653 ret = ENOSPC;
654 goto out_unlock;
655 }
656 /*
657 * Copy the name backwards.
658 */
659 str += len;
660
661 for (; len > 0; len--) {
662 *--end = *--str;
663 }
664 /*
665 * Add a path separator.
666 */
667 *--end = '/';
668 }
669
670 /*
671 * Walk up the parent chain.
672 */
673 if (((vp->v_parent != NULLVP) && !fixhardlink) ||
674 (flags & BUILDPATH_NO_FS_ENTER)) {
675 /*
676 * In this if () block we are not allowed to enter the filesystem
677 * to conclusively get the most accurate parent identifier.
678 * As a result, if 'vp' does not identify '/' and it
679 * does not have a valid v_parent, then error out
680 * and disallow further path construction
681 */
682 if ((vp->v_parent == NULLVP) && (rootvnode != vp)) {
683 /*
684 * Only '/' is allowed to have a NULL parent
685 * pointer. Upper level callers should ideally
686 * re-drive name lookup on receiving a ENOENT.
687 */
688 ret = ENOENT;
689
690 /* The code below will exit early if 'tvp = vp' == NULL */
691 }
692 vp = vp->v_parent;
693
694 /*
695 * if the vnode we have in hand isn't a directory and it
696 * has a v_parent, then we started with the resource fork
697 * so skip up to avoid getting a duplicate copy of the
698 * file name in the path.
699 */
700 if (vp && !vnode_isdir(vp) && vp->v_parent) {
701 vp = vp->v_parent;
702 }
703 } else {
704 /*
705 * No parent, go get it if supported.
706 */
707 struct vnode_attr va;
708 vnode_t dvp;
709
710 /*
711 * Make sure file system supports obtaining a path from id.
712 */
713 if (!(vp->v_mount->mnt_kern_flag & MNTK_PATH_FROM_ID)) {
714 ret = ENOENT;
715 goto out_unlock;
716 }
717 vid = vp->v_id;
718
719 vnode_hold(vp);
720 NAME_CACHE_UNLOCK();
721
722 if (vp != first_vp && vp != parent_vp && vp != vp_with_iocount) {
723 if (vp_with_iocount) {
724 vnode_put(vp_with_iocount);
725 vp_with_iocount = NULLVP;
726 }
727 if (vnode_getwithvid(vp, vid)) {
728 vnode_drop(vp);
729 goto again;
730 }
731 vp_with_iocount = vp;
732 }
733
734 vnode_drop(vp);
735
736 VATTR_INIT(&va);
737 VATTR_WANTED(&va, va_parentid);
738
739 if (fixhardlink) {
740 VATTR_WANTED(&va, va_name);
741 va.va_name = zalloc(ZV_NAMEI);
742 } else {
743 va.va_name = NULL;
744 }
745 /*
746 * Ask the file system for its parent id and for its name (optional).
747 */
748 ret = vnode_getattr(vp, &va, ctx);
749
750 if (ret || !VATTR_IS_SUPPORTED(&va, va_parentid)) {
751 ret = ENOENT;
752 goto out;
753 }
754
755 /*
756 * Ask the file system for the parent vnode.
757 */
758 if ((ret = VFS_VGET(vp->v_mount, (ino64_t)va.va_parentid, &dvp, ctx))) {
759 goto out;
760 }
761
762 /* No exit from here before switching vp_with_iocount to dvp */
763
764 if (fixhardlink) {
765 if (VATTR_IS_SUPPORTED(&va, va_name)) {
766 str = va.va_name;
767 } else {
768 ret = ENOENT;
769 goto bad_news;
770 }
771 len = (unsigned int)strlen(str);
772
773 /* Don't update parent for namedstream vnode. */
774 if (vp->v_flag & VISNAMEDSTREAM) {
775 vnode_update_identity(vp, NULL, str, len, 0,
776 VNODE_UPDATE_NAME);
777 } else {
778 vnode_update_identity(vp, dvp, str, len, 0,
779 VNODE_UPDATE_NAME | VNODE_UPDATE_PARENT);
780 }
781
782 /*
783 * Check that there's enough space.
784 */
785 if ((unsigned int)(end - buff) < (len + 1)) {
786 ret = ENOSPC;
787 } else {
788 /* Copy the name backwards. */
789 str += len;
790
791 for (; len > 0; len--) {
792 *--end = *--str;
793 }
794 /*
795 * Add a path separator.
796 */
797 *--end = '/';
798 }
799 bad_news:
800 zfree(ZV_NAMEI, va.va_name);
801 } else if (vp->v_parent != dvp) {
802 vnode_update_identity(vp, dvp, NULL, 0, 0, VNODE_UPDATE_PARENT);
803 }
804
805 if (vp_with_iocount) {
806 vnode_put(vp_with_iocount);
807 }
808 vp = dvp;
809 vp_with_iocount = vp;
810
811 NAME_CACHE_LOCK_SHARED();
812
813 /*
814 * if the vnode we have in hand isn't a directory and it
815 * has a v_parent, then we started with the resource fork
816 * so skip up to avoid getting a duplicate copy of the
817 * file name in the path.
818 */
819 if (vp && !vnode_isdir(vp) && vp->v_parent) {
820 vp = vp->v_parent;
821 }
822 }
823
824 if (vp && (flags & BUILDPATH_CHECKACCESS)) {
825 vid = vp->v_id;
826
827 vnode_hold(vp);
828 NAME_CACHE_UNLOCK();
829
830 if (vp != first_vp && vp != parent_vp && vp != vp_with_iocount) {
831 if (vp_with_iocount) {
832 vnode_put(vp_with_iocount);
833 vp_with_iocount = NULLVP;
834 }
835 if (vnode_getwithvid(vp, vid)) {
836 vnode_drop(vp);
837 goto again;
838 }
839 vp_with_iocount = vp;
840 }
841 vnode_drop(vp);
842
843 if ((ret = vnode_authorize(vp, NULL, KAUTH_VNODE_SEARCH, ctx))) {
844 goto out; /* no peeking */
845 }
846 NAME_CACHE_LOCK_SHARED();
847 }
848
849 /*
850 * When a mount point is crossed switch the vp.
851 * Continue until we find the root or we find
852 * a vnode that's not the root of a mounted
853 * file system.
854 */
855 tvp = vp;
856
857 while (tvp) {
858 if (tvp == proc_root_dir_vp) {
859 goto out_unlock; /* encountered the root */
860 }
861
862 #if CONFIG_FIRMLINKS
863 if (!(flags & BUILDPATH_NO_FIRMLINK) &&
864 (tvp->v_flag & VFMLINKTARGET) && tvp->v_fmlink && (tvp->v_fmlink->v_type == VDIR)) {
865 tvp = tvp->v_fmlink;
866 break;
867 }
868 #endif
869
870 if (!(tvp->v_flag & VROOT) || !tvp->v_mount) {
871 break; /* not the root of a mounted FS */
872 }
873 if (flags & BUILDPATH_VOLUME_RELATIVE) {
874 /* Do not cross over mount points */
875 tvp = NULL;
876 } else {
877 tvp = tvp->v_mount->mnt_vnodecovered;
878 if (!mntpt_end && tvp) {
879 mntpt_end = end;
880 }
881 }
882 }
883 if (tvp == NULLVP) {
884 goto out_unlock;
885 }
886 vp = tvp;
887 }
888 out_unlock:
889 NAME_CACHE_UNLOCK();
890 out:
891 if (vp_with_iocount) {
892 vnode_put(vp_with_iocount);
893 }
894 /*
895 * Slide the name down to the beginning of the buffer.
896 */
897 memmove(buff, end, &buff[buflen] - end);
898
899 /*
900 * length includes the trailing zero byte
901 */
902 *outlen = (int)(&buff[buflen] - end);
903 if (mntpt_outlen && mntpt_end) {
904 *mntpt_outlen = (size_t)*outlen - (size_t)(&buff[buflen] - mntpt_end);
905 }
906
907 /* One of the parents was moved during path reconstruction.
908 * The caller is interested in knowing whether any of the
909 * parents moved via BUILDPATH_CHECK_MOVED, so return EAGAIN.
910 */
911 if ((ret == ENOENT) && (flags & BUILDPATH_CHECK_MOVED)) {
912 ret = EAGAIN;
913 }
914
915 return ret;
916 }
917
918 int
build_path(vnode_t first_vp,char * buff,int buflen,int * outlen,int flags,vfs_context_t ctx)919 build_path(vnode_t first_vp, char *buff, int buflen, int *outlen, int flags, vfs_context_t ctx)
920 {
921 return build_path_with_parent(first_vp, NULL, buff, buflen, outlen, NULL, flags, ctx);
922 }
923
924 /*
925 * Combined version of vnode_getparent() and vnode_getname() to acquire both vnode name and parent
926 * without releasing the name cache lock in interim.
927 */
928 void
vnode_getparent_and_name(vnode_t vp,vnode_t * out_pvp,const char ** out_name)929 vnode_getparent_and_name(vnode_t vp, vnode_t *out_pvp, const char **out_name)
930 {
931 vnode_t pvp = NULLVP;
932 int locked = 0;
933 int pvid;
934
935 NAME_CACHE_LOCK_SHARED();
936 locked = 1;
937
938 if (out_name) {
939 const char *name = NULL;
940 if (vp->v_name) {
941 name = vfs_addname(vp->v_name, (unsigned int)strlen(vp->v_name), 0, 0);
942 }
943 *out_name = name;
944 }
945
946 if (!out_pvp) {
947 goto out;
948 }
949
950 pvp = vp->v_parent;
951
952 /*
953 * v_parent is stable behind the name_cache lock
954 * however, the only thing we can really guarantee
955 * is that we've grabbed a valid iocount on the
956 * parent of 'vp' at the time we took the name_cache lock...
957 * once we drop the lock, vp could get re-parented
958 */
959 if (pvp != NULLVP) {
960 pvid = pvp->v_id;
961
962 vnode_hold(pvp);
963 NAME_CACHE_UNLOCK();
964 locked = 0;
965
966 if (vnode_getwithvid(pvp, pvid) != 0) {
967 vnode_drop(pvp);
968 pvp = NULL;
969 } else {
970 vnode_drop(pvp);
971 }
972 }
973 *out_pvp = pvp;
974
975 out:
976 if (locked) {
977 NAME_CACHE_UNLOCK();
978 }
979 }
980
981 /*
982 * return NULLVP if vp's parent doesn't
983 * exist, or we can't get a valid iocount
984 * else return the parent of vp
985 */
986 vnode_t
vnode_getparent(vnode_t vp)987 vnode_getparent(vnode_t vp)
988 {
989 vnode_t pvp = NULLVP;
990 vnode_getparent_and_name(vp, &pvp, NULL);
991
992 return pvp;
993 }
994
995 /*
996 * Similar to vnode_getparent() but only returned parent vnode (with iocount
997 * held) if the actual parent vnode is different than the given 'pvp'.
998 */
999 __private_extern__ vnode_t
vnode_getparent_if_different(vnode_t vp,vnode_t pvp)1000 vnode_getparent_if_different(vnode_t vp, vnode_t pvp)
1001 {
1002 vnode_t real_pvp = NULLVP;
1003 int pvid;
1004
1005 if (vp->v_parent == pvp) {
1006 goto out;
1007 }
1008
1009 NAME_CACHE_LOCK_SHARED();
1010
1011 real_pvp = vp->v_parent;
1012 if (real_pvp == NULLVP) {
1013 NAME_CACHE_UNLOCK();
1014 goto out;
1015 }
1016
1017 /*
1018 * Do the check again after namecache lock is acquired as the parent vnode
1019 * could have changed.
1020 */
1021 if (real_pvp != pvp) {
1022 pvid = real_pvp->v_id;
1023
1024 vnode_hold(real_pvp);
1025 NAME_CACHE_UNLOCK();
1026
1027 if (vnode_getwithvid(real_pvp, pvid) != 0) {
1028 vnode_drop(real_pvp);
1029 real_pvp = NULLVP;
1030 } else {
1031 vnode_drop(real_pvp);
1032 }
1033 } else {
1034 real_pvp = NULLVP;
1035 NAME_CACHE_UNLOCK();
1036 }
1037
1038 out:
1039 return real_pvp;
1040 }
1041
1042 const char *
vnode_getname(vnode_t vp)1043 vnode_getname(vnode_t vp)
1044 {
1045 const char *name = NULL;
1046 vnode_getparent_and_name(vp, NULL, &name);
1047
1048 return name;
1049 }
1050
1051 void
vnode_putname(const char * name)1052 vnode_putname(const char *name)
1053 {
1054 if (name) {
1055 vfs_removename(name);
1056 }
1057 }
1058
1059 static const char unknown_vnodename[] = "(unknown vnode name)";
1060
1061 const char *
vnode_getname_printable(vnode_t vp)1062 vnode_getname_printable(vnode_t vp)
1063 {
1064 const char *name = vnode_getname(vp);
1065 if (name != NULL) {
1066 return name;
1067 }
1068
1069 switch (vp->v_type) {
1070 case VCHR:
1071 case VBLK:
1072 {
1073 /*
1074 * Create an artificial dev name from
1075 * major and minor device number
1076 */
1077 char dev_name[64];
1078 (void) snprintf(dev_name, sizeof(dev_name),
1079 "%c(%u, %u)", VCHR == vp->v_type ? 'c':'b',
1080 major(vp->v_rdev), minor(vp->v_rdev));
1081 /*
1082 * Add the newly created dev name to the name
1083 * cache to allow easier cleanup. Also,
1084 * vfs_addname allocates memory for the new name
1085 * and returns it.
1086 */
1087 NAME_CACHE_LOCK_SHARED();
1088 name = vfs_addname(dev_name, (unsigned int)strlen(dev_name), 0, 0);
1089 NAME_CACHE_UNLOCK();
1090 return name;
1091 }
1092 default:
1093 return unknown_vnodename;
1094 }
1095 }
1096
1097 void
vnode_putname_printable(const char * name)1098 vnode_putname_printable(const char *name)
1099 {
1100 if (name == unknown_vnodename) {
1101 return;
1102 }
1103 vnode_putname(name);
1104 }
1105
1106
1107 /*
1108 * if VNODE_UPDATE_PARENT, and we can take
1109 * a reference on dvp, then update vp with
1110 * it's new parent... if vp already has a parent,
1111 * then drop the reference vp held on it
1112 *
1113 * if VNODE_UPDATE_NAME,
1114 * then drop string ref on v_name if it exists, and if name is non-NULL
1115 * then pick up a string reference on name and record it in v_name...
1116 * optionally pass in the length and hashval of name if known
1117 *
1118 * if VNODE_UPDATE_CACHE, flush the name cache entries associated with vp
1119 */
1120 void
vnode_update_identity(vnode_t vp,vnode_t dvp,const char * name,int name_len,uint32_t name_hashval,int flags)1121 vnode_update_identity(vnode_t vp, vnode_t dvp, const char *name, int name_len, uint32_t name_hashval, int flags)
1122 {
1123 struct namecache *ncp;
1124 vnode_t old_parentvp = NULLVP;
1125 int isstream = (vp->v_flag & VISNAMEDSTREAM);
1126 int kusecountbumped = 0;
1127 kauth_cred_t tcred = NULL;
1128 const char *vname = NULL;
1129 const char *tname = NULL;
1130
1131 if (name_len < 0) {
1132 return;
1133 }
1134
1135 if (flags & VNODE_UPDATE_PARENT) {
1136 if (dvp && (vnode_ref_ext(dvp, 0, ((flags & VNODE_UPDATE_FORCE_PARENT_REF) ? VNODE_REF_FORCE : 0)) != 0)) {
1137 dvp = NULLVP;
1138 }
1139 /* Don't count a stream's parent ref during unmounts */
1140 if (isstream && dvp && (dvp != vp) && (dvp != vp->v_parent) && (dvp->v_type == VREG)) {
1141 vnode_lock_spin(dvp);
1142 ++dvp->v_kusecount;
1143 kusecountbumped = 1;
1144 vnode_unlock(dvp);
1145 }
1146 } else {
1147 dvp = NULLVP;
1148 }
1149 if ((flags & VNODE_UPDATE_NAME)) {
1150 if (name != vp->v_name) {
1151 if (name && *name) {
1152 if (name_len == 0) {
1153 name_len = (int)strlen(name);
1154 }
1155 tname = vfs_addname(name, name_len, name_hashval, 0);
1156 }
1157 } else {
1158 flags &= ~VNODE_UPDATE_NAME;
1159 }
1160 }
1161 if ((flags & (VNODE_UPDATE_PURGE | VNODE_UPDATE_PARENT | VNODE_UPDATE_CACHE | VNODE_UPDATE_NAME | VNODE_UPDATE_PURGEFIRMLINK))) {
1162 NAME_CACHE_LOCK();
1163
1164 #if CONFIG_FIRMLINKS
1165 if (flags & VNODE_UPDATE_PURGEFIRMLINK) {
1166 vnode_t old_fvp = vp->v_fmlink;
1167 if (old_fvp) {
1168 vnode_lock_spin(vp);
1169 vp->v_flag &= ~VFMLINKTARGET;
1170 vp->v_fmlink = NULLVP;
1171 vnode_unlock(vp);
1172 NAME_CACHE_UNLOCK();
1173
1174 /*
1175 * vnode_rele can result in cascading series of
1176 * usecount releases. The combination of calling
1177 * vnode_recycle and dont_reenter (3rd arg to
1178 * vnode_rele_internal) ensures we don't have
1179 * that issue.
1180 */
1181 vnode_recycle(old_fvp);
1182 vnode_rele_internal(old_fvp, O_EVTONLY, 1, 0);
1183
1184 NAME_CACHE_LOCK();
1185 }
1186 }
1187 #endif
1188
1189 if ((flags & VNODE_UPDATE_PURGE)) {
1190 if (vp->v_parent) {
1191 vp->v_parent->v_nc_generation++;
1192 }
1193
1194 while ((ncp = LIST_FIRST(&vp->v_nclinks))) {
1195 cache_delete(ncp, 1);
1196 }
1197
1198 while ((ncp = TAILQ_FIRST(&vp->v_ncchildren))) {
1199 cache_delete(ncp, 1);
1200 }
1201
1202 /*
1203 * Use a temp variable to avoid kauth_cred_drop() while NAME_CACHE_LOCK is held
1204 */
1205 tcred = vnode_cred(vp);
1206 vp->v_cred = NOCRED;
1207 vp->v_authorized_actions = 0;
1208 vp->v_cred_timestamp = 0;
1209 }
1210 if ((flags & VNODE_UPDATE_NAME)) {
1211 vname = vp->v_name;
1212 vp->v_name = tname;
1213 }
1214 if (flags & VNODE_UPDATE_PARENT) {
1215 if (dvp != vp && dvp != vp->v_parent) {
1216 old_parentvp = vp->v_parent;
1217 vp->v_parent = dvp;
1218 dvp = NULLVP;
1219
1220 if (old_parentvp) {
1221 flags |= VNODE_UPDATE_CACHE;
1222 }
1223 }
1224 }
1225 if (flags & VNODE_UPDATE_CACHE) {
1226 while ((ncp = LIST_FIRST(&vp->v_nclinks))) {
1227 cache_delete(ncp, 1);
1228 }
1229 }
1230 NAME_CACHE_UNLOCK();
1231
1232 if (vname != NULL) {
1233 vfs_removename(vname);
1234 }
1235
1236 if (IS_VALID_CRED(tcred)) {
1237 kauth_cred_unref(&tcred);
1238 }
1239 }
1240 if (dvp != NULLVP) {
1241 /* Back-out the ref we took if we lost a race for vp->v_parent. */
1242 if (kusecountbumped) {
1243 vnode_lock_spin(dvp);
1244 if (dvp->v_kusecount > 0) {
1245 --dvp->v_kusecount;
1246 }
1247 vnode_unlock(dvp);
1248 }
1249 vnode_rele(dvp);
1250 }
1251 if (old_parentvp) {
1252 struct uthread *ut;
1253 vnode_t vreclaims = NULLVP;
1254
1255 if (isstream) {
1256 vnode_lock_spin(old_parentvp);
1257 if ((old_parentvp->v_type != VDIR) && (old_parentvp->v_kusecount > 0)) {
1258 --old_parentvp->v_kusecount;
1259 }
1260 vnode_unlock(old_parentvp);
1261 }
1262 ut = current_uthread();
1263
1264 /*
1265 * indicated to vnode_rele that it shouldn't do a
1266 * vnode_reclaim at this time... instead it will
1267 * chain the vnode to the uu_vreclaims list...
1268 * we'll be responsible for calling vnode_reclaim
1269 * on each of the vnodes in this list...
1270 */
1271 ut->uu_defer_reclaims = 1;
1272 ut->uu_vreclaims = NULLVP;
1273
1274 while ((vp = old_parentvp) != NULLVP) {
1275 vnode_hold(vp);
1276 vnode_lock_spin(vp);
1277 vnode_rele_internal(vp, 0, 0, 1);
1278
1279 /*
1280 * check to see if the vnode is now in the state
1281 * that would have triggered a vnode_reclaim in vnode_rele
1282 * if it is, we save it's parent pointer and then NULL
1283 * out the v_parent field... we'll drop the reference
1284 * that was held on the next iteration of this loop...
1285 * this short circuits a potential deep recursion if we
1286 * have a long chain of parents in this state...
1287 * we'll sit in this loop until we run into
1288 * a parent in this chain that is not in this state
1289 *
1290 * make our check and the vnode_rele atomic
1291 * with respect to the current vnode we're working on
1292 * by holding the vnode lock
1293 * if vnode_rele deferred the vnode_reclaim and has put
1294 * this vnode on the list to be reaped by us, than
1295 * it has left this vnode with an iocount == 1
1296 */
1297 if (ut->uu_vreclaims == vp) {
1298 /*
1299 * This vnode is on the head of the uu_vreclaims chain
1300 * which means vnode_rele wanted to do a vnode_reclaim
1301 * on this vnode. Pull the parent pointer now so that when we do the
1302 * vnode_reclaim for each of the vnodes in the uu_vreclaims
1303 * list, we won't recurse back through here
1304 *
1305 * need to do a convert here in case vnode_rele_internal
1306 * returns with the lock held in the spin mode... it
1307 * can drop and retake the lock under certain circumstances
1308 */
1309 vnode_lock_convert(vp);
1310
1311 NAME_CACHE_LOCK();
1312 old_parentvp = vp->v_parent;
1313 vp->v_parent = NULLVP;
1314 NAME_CACHE_UNLOCK();
1315 } else {
1316 /*
1317 * we're done... we ran into a vnode that isn't
1318 * being terminated
1319 */
1320 old_parentvp = NULLVP;
1321 }
1322 vnode_drop_and_unlock(vp);
1323 }
1324 vreclaims = ut->uu_vreclaims;
1325 ut->uu_vreclaims = NULLVP;
1326 ut->uu_defer_reclaims = 0;
1327
1328 while ((vp = vreclaims) != NULLVP) {
1329 vreclaims = vp->v_defer_reclaimlist;
1330
1331 /*
1332 * vnode_put will drive the vnode_reclaim if
1333 * we are still the only reference on this vnode
1334 */
1335 vnode_put(vp);
1336 }
1337 }
1338 }
1339
1340 #if CONFIG_FIRMLINKS
1341 errno_t
vnode_setasfirmlink(vnode_t vp,vnode_t target_vp)1342 vnode_setasfirmlink(vnode_t vp, vnode_t target_vp)
1343 {
1344 int error = 0;
1345 vnode_t old_target_vp = NULLVP;
1346 vnode_t old_target_vp_v_fmlink = NULLVP;
1347 kauth_cred_t target_vp_cred = NULL;
1348 kauth_cred_t old_target_vp_cred = NULL;
1349
1350 if (!vp) {
1351 return EINVAL;
1352 }
1353
1354 if (target_vp) {
1355 if (vp->v_fmlink == target_vp) { /* Will be checked again under the name cache lock */
1356 return 0;
1357 }
1358
1359 /*
1360 * Firmlink source and target will take both a usecount
1361 * and kusecount on each other.
1362 */
1363 if ((error = vnode_ref_ext(target_vp, O_EVTONLY, VNODE_REF_FORCE))) {
1364 return error;
1365 }
1366
1367 if ((error = vnode_ref_ext(vp, O_EVTONLY, VNODE_REF_FORCE))) {
1368 vnode_rele_ext(target_vp, O_EVTONLY, 1);
1369 return error;
1370 }
1371 }
1372
1373 NAME_CACHE_LOCK();
1374
1375 old_target_vp = vp->v_fmlink;
1376 if (target_vp && (target_vp == old_target_vp)) {
1377 NAME_CACHE_UNLOCK();
1378 return 0;
1379 }
1380 vp->v_fmlink = target_vp;
1381
1382 vnode_lock_spin(vp);
1383 vp->v_flag &= ~VFMLINKTARGET;
1384 vnode_unlock(vp);
1385
1386 if (target_vp) {
1387 target_vp->v_fmlink = vp;
1388 vnode_lock_spin(target_vp);
1389 target_vp->v_flag |= VFMLINKTARGET;
1390 vnode_unlock(target_vp);
1391 cache_purge_locked(vp, &target_vp_cred);
1392 }
1393
1394 if (old_target_vp) {
1395 old_target_vp_v_fmlink = old_target_vp->v_fmlink;
1396 old_target_vp->v_fmlink = NULLVP;
1397 vnode_lock_spin(old_target_vp);
1398 old_target_vp->v_flag &= ~VFMLINKTARGET;
1399 vnode_unlock(old_target_vp);
1400 cache_purge_locked(vp, &old_target_vp_cred);
1401 }
1402
1403 NAME_CACHE_UNLOCK();
1404
1405 if (IS_VALID_CRED(target_vp_cred)) {
1406 kauth_cred_unref(&target_vp_cred);
1407 }
1408
1409 if (old_target_vp) {
1410 if (IS_VALID_CRED(old_target_vp_cred)) {
1411 kauth_cred_unref(&old_target_vp_cred);
1412 }
1413
1414 vnode_rele_ext(old_target_vp, O_EVTONLY, 1);
1415 if (old_target_vp_v_fmlink) {
1416 vnode_rele_ext(old_target_vp_v_fmlink, O_EVTONLY, 1);
1417 }
1418 }
1419
1420 return 0;
1421 }
1422
1423 errno_t
vnode_getfirmlink(vnode_t vp,vnode_t * target_vp)1424 vnode_getfirmlink(vnode_t vp, vnode_t *target_vp)
1425 {
1426 int error;
1427
1428 if (!vp->v_fmlink) {
1429 return ENODEV;
1430 }
1431
1432 NAME_CACHE_LOCK_SHARED();
1433 if (vp->v_fmlink && !(vp->v_flag & VFMLINKTARGET) &&
1434 (vnode_get(vp->v_fmlink) == 0)) {
1435 vnode_t tvp = vp->v_fmlink;
1436
1437 vnode_lock_spin(tvp);
1438 if (tvp->v_lflag & (VL_TERMINATE | VL_DEAD)) {
1439 vnode_unlock(tvp);
1440 NAME_CACHE_UNLOCK();
1441 vnode_put(tvp);
1442 return ENOENT;
1443 }
1444 if (!(tvp->v_flag & VFMLINKTARGET)) {
1445 panic("firmlink target for vnode %p does not have flag set", vp);
1446 }
1447 vnode_unlock(tvp);
1448 *target_vp = tvp;
1449 error = 0;
1450 } else {
1451 *target_vp = NULLVP;
1452 error = ENODEV;
1453 }
1454 NAME_CACHE_UNLOCK();
1455 return error;
1456 }
1457
1458 #else /* CONFIG_FIRMLINKS */
1459
1460 errno_t
vnode_setasfirmlink(__unused vnode_t vp,__unused vnode_t src_vp)1461 vnode_setasfirmlink(__unused vnode_t vp, __unused vnode_t src_vp)
1462 {
1463 return ENOTSUP;
1464 }
1465
1466 errno_t
vnode_getfirmlink(__unused vnode_t vp,__unused vnode_t * target_vp)1467 vnode_getfirmlink(__unused vnode_t vp, __unused vnode_t *target_vp)
1468 {
1469 return ENOTSUP;
1470 }
1471
1472 #endif
1473
1474 /*
1475 * Mark a vnode as having multiple hard links. HFS makes use of this
1476 * because it keeps track of each link separately, and wants to know
1477 * which link was actually used.
1478 *
1479 * This will cause the name cache to force a VNOP_LOOKUP on the vnode
1480 * so that HFS can post-process the lookup. Also, volfs will call
1481 * VNOP_GETATTR2 to determine the parent, instead of using v_parent.
1482 */
1483 void
vnode_setmultipath(vnode_t vp)1484 vnode_setmultipath(vnode_t vp)
1485 {
1486 vnode_lock_spin(vp);
1487
1488 /*
1489 * In theory, we're changing the vnode's identity as far as the
1490 * name cache is concerned, so we ought to grab the name cache lock
1491 * here. However, there is already a race, and grabbing the name
1492 * cache lock only makes the race window slightly smaller.
1493 *
1494 * The race happens because the vnode already exists in the name
1495 * cache, and could be found by one thread before another thread
1496 * can set the hard link flag.
1497 */
1498
1499 vp->v_flag |= VISHARDLINK;
1500
1501 vnode_unlock(vp);
1502 }
1503
1504
1505
1506 /*
1507 * backwards compatibility
1508 */
1509 void
vnode_uncache_credentials(vnode_t vp)1510 vnode_uncache_credentials(vnode_t vp)
1511 {
1512 vnode_uncache_authorized_action(vp, KAUTH_INVALIDATE_CACHED_RIGHTS);
1513 }
1514
1515
1516 /*
1517 * use the exclusive form of NAME_CACHE_LOCK to protect the update of the
1518 * following fields in the vnode: v_cred_timestamp, v_cred, v_authorized_actions
1519 * we use this lock so that we can look at the v_cred and v_authorized_actions
1520 * atomically while behind the NAME_CACHE_LOCK in shared mode in 'cache_lookup_path',
1521 * which is the super-hot path... if we are updating the authorized actions for this
1522 * vnode, we are already in the super-slow and far less frequented path so its not
1523 * that bad that we take the lock exclusive for this case... of course we strive
1524 * to hold it for the minimum amount of time possible
1525 */
1526
1527 void
vnode_uncache_authorized_action(vnode_t vp,kauth_action_t action)1528 vnode_uncache_authorized_action(vnode_t vp, kauth_action_t action)
1529 {
1530 kauth_cred_t tcred = NOCRED;
1531
1532 NAME_CACHE_LOCK();
1533
1534 vp->v_authorized_actions &= ~action;
1535
1536 if (action == KAUTH_INVALIDATE_CACHED_RIGHTS &&
1537 IS_VALID_CRED(vp->v_cred)) {
1538 /*
1539 * Use a temp variable to avoid kauth_cred_unref() while NAME_CACHE_LOCK is held
1540 */
1541 tcred = vnode_cred(vp);
1542 vp->v_cred = NOCRED;
1543 }
1544 NAME_CACHE_UNLOCK();
1545
1546 if (IS_VALID_CRED(tcred)) {
1547 kauth_cred_unref(&tcred);
1548 }
1549 }
1550
1551
1552 /* disable vnode_cache_is_authorized() by setting vnode_cache_defeat */
1553 static TUNABLE(int, bootarg_vnode_cache_defeat, "-vnode_cache_defeat", 0);
1554
1555 boolean_t
vnode_cache_is_authorized(vnode_t vp,vfs_context_t ctx,kauth_action_t action)1556 vnode_cache_is_authorized(vnode_t vp, vfs_context_t ctx, kauth_action_t action)
1557 {
1558 kauth_cred_t ucred;
1559 boolean_t retval = FALSE;
1560
1561 /* Boot argument to defeat rights caching */
1562 if (bootarg_vnode_cache_defeat) {
1563 return FALSE;
1564 }
1565
1566 if ((vp->v_mount->mnt_kern_flag & (MNTK_AUTH_OPAQUE | MNTK_AUTH_CACHE_TTL))) {
1567 /*
1568 * a TTL is enabled on the rights cache... handle it here
1569 * a TTL of 0 indicates that no rights should be cached
1570 */
1571 if (vp->v_mount->mnt_authcache_ttl) {
1572 if (!(vp->v_mount->mnt_kern_flag & MNTK_AUTH_CACHE_TTL)) {
1573 /*
1574 * For filesystems marked only MNTK_AUTH_OPAQUE (generally network ones),
1575 * we will only allow a SEARCH right on a directory to be cached...
1576 * that cached right always has a default TTL associated with it
1577 */
1578 if (action != KAUTH_VNODE_SEARCH || vp->v_type != VDIR) {
1579 vp = NULLVP;
1580 }
1581 }
1582 if (vp != NULLVP && vnode_cache_is_stale(vp) == TRUE) {
1583 vnode_uncache_authorized_action(vp, vp->v_authorized_actions);
1584 vp = NULLVP;
1585 }
1586 } else {
1587 vp = NULLVP;
1588 }
1589 }
1590 if (vp != NULLVP) {
1591 ucred = vfs_context_ucred(ctx);
1592
1593 NAME_CACHE_LOCK_SHARED();
1594
1595 if (vnode_cred(vp) == ucred && (vp->v_authorized_actions & action) == action) {
1596 retval = TRUE;
1597 }
1598
1599 NAME_CACHE_UNLOCK();
1600 }
1601 return retval;
1602 }
1603
1604
1605 void
vnode_cache_authorized_action(vnode_t vp,vfs_context_t ctx,kauth_action_t action)1606 vnode_cache_authorized_action(vnode_t vp, vfs_context_t ctx, kauth_action_t action)
1607 {
1608 kauth_cred_t tcred = NOCRED;
1609 kauth_cred_t ucred;
1610 struct timeval tv;
1611 boolean_t ttl_active = FALSE;
1612
1613 ucred = vfs_context_ucred(ctx);
1614
1615 if (!IS_VALID_CRED(ucred) || action == 0) {
1616 return;
1617 }
1618
1619 if ((vp->v_mount->mnt_kern_flag & (MNTK_AUTH_OPAQUE | MNTK_AUTH_CACHE_TTL))) {
1620 /*
1621 * a TTL is enabled on the rights cache... handle it here
1622 * a TTL of 0 indicates that no rights should be cached
1623 */
1624 if (vp->v_mount->mnt_authcache_ttl == 0) {
1625 return;
1626 }
1627
1628 if (!(vp->v_mount->mnt_kern_flag & MNTK_AUTH_CACHE_TTL)) {
1629 /*
1630 * only cache SEARCH action for filesystems marked
1631 * MNTK_AUTH_OPAQUE on VDIRs...
1632 * the lookup_path code will time these out
1633 */
1634 if ((action & ~KAUTH_VNODE_SEARCH) || vp->v_type != VDIR) {
1635 return;
1636 }
1637 }
1638 ttl_active = TRUE;
1639
1640 microuptime(&tv);
1641 }
1642 NAME_CACHE_LOCK();
1643
1644 tcred = vnode_cred(vp);
1645 if (tcred == ucred) {
1646 tcred = NOCRED;
1647 } else {
1648 /*
1649 * Use a temp variable to avoid kauth_cred_drop() while NAME_CACHE_LOCK is held
1650 */
1651 kauth_cred_ref(ucred);
1652 vp->v_cred = ucred;
1653 vp->v_authorized_actions = 0;
1654 }
1655 if (ttl_active == TRUE && vp->v_authorized_actions == 0) {
1656 /*
1657 * only reset the timestamnp on the
1658 * first authorization cached after the previous
1659 * timer has expired or we're switching creds...
1660 * 'vnode_cache_is_authorized' will clear the
1661 * authorized actions if the TTL is active and
1662 * it has expired
1663 */
1664 vp->v_cred_timestamp = (int)tv.tv_sec;
1665 }
1666 vp->v_authorized_actions |= action;
1667
1668 NAME_CACHE_UNLOCK();
1669
1670 if (IS_VALID_CRED(tcred)) {
1671 kauth_cred_unref(&tcred);
1672 }
1673 }
1674
1675
1676 boolean_t
vnode_cache_is_stale(vnode_t vp)1677 vnode_cache_is_stale(vnode_t vp)
1678 {
1679 struct timeval tv;
1680 boolean_t retval;
1681
1682 microuptime(&tv);
1683
1684 if ((tv.tv_sec - vp->v_cred_timestamp) > vp->v_mount->mnt_authcache_ttl) {
1685 retval = TRUE;
1686 } else {
1687 retval = FALSE;
1688 }
1689
1690 return retval;
1691 }
1692
1693 VFS_SMR_DECLARE;
1694
1695 /*
1696 * Components of nameidata (or objects it can point to) which may
1697 * need restoring in case fast path lookup fails.
1698 */
1699 struct nameidata_state {
1700 u_long ni_loopcnt;
1701 char *ni_next;
1702 u_int ni_pathlen;
1703 int32_t ni_flag;
1704 char *cn_nameptr;
1705 int cn_namelen;
1706 int cn_flags;
1707 uint32_t cn_hash;
1708 };
1709
1710 static void
save_ndp_state(struct nameidata * ndp,struct componentname * cnp,struct nameidata_state * saved_statep)1711 save_ndp_state(struct nameidata *ndp, struct componentname *cnp, struct nameidata_state *saved_statep)
1712 {
1713 saved_statep->ni_loopcnt = ndp->ni_loopcnt;
1714 saved_statep->ni_next = ndp->ni_next;
1715 saved_statep->ni_pathlen = ndp->ni_pathlen;
1716 saved_statep->ni_flag = ndp->ni_flag;
1717 saved_statep->cn_nameptr = cnp->cn_nameptr;
1718 saved_statep->cn_namelen = cnp->cn_namelen;
1719 saved_statep->cn_flags = cnp->cn_flags;
1720 saved_statep->cn_hash = cnp->cn_hash;
1721 }
1722
1723 static void
restore_ndp_state(struct nameidata * ndp,struct componentname * cnp,struct nameidata_state * saved_statep)1724 restore_ndp_state(struct nameidata *ndp, struct componentname *cnp, struct nameidata_state *saved_statep)
1725 {
1726 ndp->ni_loopcnt = saved_statep->ni_loopcnt;
1727 ndp->ni_next = saved_statep->ni_next;
1728 ndp->ni_pathlen = saved_statep->ni_pathlen;
1729 ndp->ni_flag = saved_statep->ni_flag;
1730 cnp->cn_nameptr = saved_statep->cn_nameptr;
1731 cnp->cn_namelen = saved_statep->cn_namelen;
1732 cnp->cn_flags = saved_statep->cn_flags;
1733 cnp->cn_hash = saved_statep->cn_hash;
1734 }
1735
1736 static inline bool
vid_is_same(vnode_t vp,uint32_t vid)1737 vid_is_same(vnode_t vp, uint32_t vid)
1738 {
1739 return !(os_atomic_load(&vp->v_lflag, relaxed) & (VL_DRAIN | VL_TERMINATE | VL_DEAD)) && (vnode_vid(vp) == vid);
1740 }
1741
1742 static inline bool
can_check_v_mountedhere(vnode_t vp)1743 can_check_v_mountedhere(vnode_t vp)
1744 {
1745 return (os_atomic_load(&vp->v_usecount, relaxed) > 0) &&
1746 (os_atomic_load(&vp->v_flag, relaxed) & VMOUNTEDHERE) &&
1747 !(os_atomic_load(&vp->v_lflag, relaxed) & (VL_TERMINATE | VL_DEAD) &&
1748 (vp->v_type == VDIR));
1749 }
1750
1751 /*
1752 * Returns: 0 Success
1753 * ERECYCLE vnode was recycled from underneath us. Force lookup to be re-driven from namei.
1754 * This errno value should not be seen by anyone outside of the kernel.
1755 */
1756 int
cache_lookup_path(struct nameidata * ndp,struct componentname * cnp,vnode_t dp,vfs_context_t ctx,int * dp_authorized,vnode_t last_dp)1757 cache_lookup_path(struct nameidata *ndp, struct componentname *cnp, vnode_t dp,
1758 vfs_context_t ctx, int *dp_authorized, vnode_t last_dp)
1759 {
1760 struct nameidata_state saved_state;
1761 char *cp; /* pointer into pathname argument */
1762 uint32_t vid;
1763 uint32_t vvid = 0; /* protected by vp != NULLVP */
1764 vnode_t vp = NULLVP;
1765 vnode_t tdp = NULLVP;
1766 vnode_t start_dp = dp;
1767 kauth_cred_t ucred;
1768 boolean_t ttl_enabled = FALSE;
1769 struct timeval tv;
1770 mount_t mp;
1771 mount_t dmp;
1772 unsigned int hash;
1773 int error = 0;
1774 boolean_t dotdotchecked = FALSE;
1775 bool locked = false;
1776 bool needs_lock = false;
1777 bool dp_iocount_taken = false;
1778
1779 #if CONFIG_TRIGGERS
1780 vnode_t trigger_vp;
1781 #endif /* CONFIG_TRIGGERS */
1782
1783 ucred = vfs_context_ucred(ctx);
1784 retry:
1785 if (nc_smr_enabled && !needs_lock) {
1786 save_ndp_state(ndp, cnp, &saved_state);
1787 vfs_smr_enter();
1788 } else {
1789 NAME_CACHE_LOCK_SHARED();
1790 locked = true;
1791 }
1792
1793 dmp = dp->v_mount;
1794 vid = dp->v_id;
1795 if (dmp && (dmp->mnt_kern_flag & (MNTK_AUTH_OPAQUE | MNTK_AUTH_CACHE_TTL))) {
1796 ttl_enabled = TRUE;
1797 microuptime(&tv);
1798 }
1799 for (;;) {
1800 /*
1801 * Search a directory.
1802 *
1803 * The cn_hash value is for use by cache_lookup
1804 * The last component of the filename is left accessible via
1805 * cnp->cn_nameptr for callers that need the name.
1806 */
1807 hash = 0;
1808 cp = cnp->cn_nameptr;
1809
1810 while (*cp && (*cp != '/')) {
1811 hash = crc32tab[((hash >> 24) ^ (unsigned char)*cp++)] ^ hash << 8;
1812 }
1813 /*
1814 * the crc generator can legitimately generate
1815 * a 0... however, 0 for us means that we
1816 * haven't computed a hash, so use 1 instead
1817 */
1818 if (hash == 0) {
1819 hash = 1;
1820 }
1821 cnp->cn_hash = hash;
1822 cnp->cn_namelen = (int)(cp - cnp->cn_nameptr);
1823
1824 ndp->ni_pathlen -= cnp->cn_namelen;
1825 ndp->ni_next = cp;
1826
1827 /*
1828 * Replace multiple slashes by a single slash and trailing slashes
1829 * by a null. This must be done before VNOP_LOOKUP() because some
1830 * fs's don't know about trailing slashes. Remember if there were
1831 * trailing slashes to handle symlinks, existing non-directories
1832 * and non-existing files that won't be directories specially later.
1833 */
1834 while (*cp == '/' && (cp[1] == '/' || cp[1] == '\0')) {
1835 cp++;
1836 ndp->ni_pathlen--;
1837
1838 if (*cp == '\0') {
1839 ndp->ni_flag |= NAMEI_TRAILINGSLASH;
1840 *ndp->ni_next = '\0';
1841 }
1842 }
1843 ndp->ni_next = cp;
1844
1845 cnp->cn_flags &= ~(MAKEENTRY | ISLASTCN | ISDOTDOT);
1846
1847 if (*cp == '\0') {
1848 cnp->cn_flags |= ISLASTCN;
1849 }
1850
1851 if (cnp->cn_namelen == 2 && cnp->cn_nameptr[1] == '.' && cnp->cn_nameptr[0] == '.') {
1852 cnp->cn_flags |= ISDOTDOT;
1853
1854 /* if dp is the starting directory and RESOLVE_BENEATH, we should break */
1855 if ((ndp->ni_flag & NAMEI_RESOLVE_BENEATH) && (dp == ndp->ni_usedvp)) {
1856 break;
1857 }
1858 /* Break if '..' path traversal is prohibited */
1859 if (ndp->ni_flag & NAMEI_NODOTDOT) {
1860 break;
1861 }
1862 }
1863
1864 #if NAMEDRSRCFORK
1865 /*
1866 * Process a request for a file's resource fork.
1867 *
1868 * Consume the _PATH_RSRCFORKSPEC suffix and tag the path.
1869 */
1870 if ((ndp->ni_pathlen == sizeof(_PATH_RSRCFORKSPEC)) &&
1871 (cp[1] == '.' && cp[2] == '.') &&
1872 bcmp(cp, _PATH_RSRCFORKSPEC, sizeof(_PATH_RSRCFORKSPEC)) == 0) {
1873 /* Break if path lookup on named streams is prohibited. */
1874 if (ndp->ni_flag & NAMEI_NOXATTRS) {
1875 break;
1876 }
1877
1878 /* Skip volfs file systems that don't support native streams. */
1879 if ((dmp != NULL) &&
1880 (dmp->mnt_flag & MNT_DOVOLFS) &&
1881 (dmp->mnt_kern_flag & MNTK_NAMED_STREAMS) == 0) {
1882 goto skiprsrcfork;
1883 }
1884 cnp->cn_flags |= CN_WANTSRSRCFORK;
1885 cnp->cn_flags |= ISLASTCN;
1886 ndp->ni_next[0] = '\0';
1887 ndp->ni_pathlen = 1;
1888 }
1889 skiprsrcfork:
1890 #endif
1891
1892 *dp_authorized = 0;
1893
1894 #if CONFIG_FIRMLINKS
1895 if ((cnp->cn_flags & ISDOTDOT) && (dp->v_flag & VFMLINKTARGET) && dp->v_fmlink) {
1896 /*
1897 * If this is a firmlink target then dp has to be switched to the
1898 * firmlink "source" before exiting this loop.
1899 *
1900 * For a firmlink "target", the policy is to pick the parent of the
1901 * firmlink "source" as the parent. This means that you can never
1902 * get to the "real" parent of firmlink target via a dotdot lookup.
1903 */
1904 vnode_t v_fmlink = dp->v_fmlink;
1905 uint32_t old_vid = vid;
1906 mp = dmp;
1907 if (v_fmlink) {
1908 vid = v_fmlink->v_id;
1909 dmp = v_fmlink->v_mount;
1910 if ((dp->v_fmlink == v_fmlink) && dmp) {
1911 dp = v_fmlink;
1912 } else {
1913 vid = old_vid;
1914 dmp = mp;
1915 }
1916 }
1917 }
1918 #endif
1919
1920
1921 if (ttl_enabled &&
1922 (dmp->mnt_authcache_ttl == 0 ||
1923 ((tv.tv_sec - dp->v_cred_timestamp) > dmp->mnt_authcache_ttl))) {
1924 break;
1925 }
1926
1927 /*
1928 * NAME_CACHE_LOCK holds these fields stable
1929 *
1930 * We can't cache KAUTH_VNODE_SEARCHBYANYONE for root correctly
1931 * so we make an ugly check for root here. root is always
1932 * allowed and breaking out of here only to find out that is
1933 * authorized by virtue of being root is very very expensive.
1934 * However, the check for not root is valid only for filesystems
1935 * which use local authorization.
1936 *
1937 * XXX: Remove the check for root when we can reliably set
1938 * KAUTH_VNODE_SEARCHBYANYONE as root.
1939 */
1940 int v_authorized_actions = os_atomic_load(&dp->v_authorized_actions, relaxed);
1941 if ((vnode_cred(dp) != ucred || !(v_authorized_actions & KAUTH_VNODE_SEARCH)) &&
1942 !(v_authorized_actions & KAUTH_VNODE_SEARCHBYANYONE) &&
1943 (ttl_enabled || !vfs_context_issuser(ctx))) {
1944 break;
1945 }
1946
1947 /*
1948 * indicate that we're allowed to traverse this directory...
1949 * even if we fail the cache lookup or decide to bail for
1950 * some other reason, this information is valid and is used
1951 * to avoid doing a vnode_authorize before the call to VNOP_LOOKUP
1952 */
1953 *dp_authorized = 1;
1954
1955 if ((cnp->cn_flags & (ISLASTCN | ISDOTDOT))) {
1956 if (cnp->cn_nameiop != LOOKUP) {
1957 break;
1958 }
1959 if (cnp->cn_flags & LOCKPARENT) {
1960 break;
1961 }
1962 if (cnp->cn_flags & NOCACHE) {
1963 break;
1964 }
1965
1966 if (cnp->cn_flags & ISDOTDOT) {
1967 /*
1968 * Force directory hardlinks to go to
1969 * file system for ".." requests.
1970 */
1971 if ((dp->v_flag & VISHARDLINK)) {
1972 break;
1973 }
1974 /*
1975 * Quit here only if we can't use
1976 * the parent directory pointer or
1977 * don't have one. Otherwise, we'll
1978 * use it below.
1979 */
1980 if ((dp->v_flag & VROOT) ||
1981 dp == ndp->ni_rootdir ||
1982 dp->v_parent == NULLVP) {
1983 break;
1984 }
1985 }
1986 }
1987
1988 if ((cnp->cn_flags & CN_SKIPNAMECACHE)) {
1989 /*
1990 * Force lookup to go to the filesystem with
1991 * all cnp fields set up.
1992 */
1993 break;
1994 }
1995
1996 /*
1997 * "." and ".." aren't supposed to be cached, so check
1998 * for them before checking the cache.
1999 */
2000 if (cnp->cn_namelen == 1 && cnp->cn_nameptr[0] == '.') {
2001 if ((cnp->cn_flags & ISLASTCN) && !vnode_isdir(dp)) {
2002 break;
2003 }
2004 vp = dp;
2005 vvid = vid;
2006 } else if ((cnp->cn_flags & ISDOTDOT)) {
2007 /*
2008 * If this is a chrooted process, we need to check if
2009 * the process is trying to break out of its chrooted
2010 * jail. We do that by trying to determine if dp is
2011 * a subdirectory of ndp->ni_rootdir. If we aren't
2012 * able to determine that by the v_parent pointers, we
2013 * will leave the fast path.
2014 *
2015 * Since this function may see dotdot components
2016 * many times and it has the name cache lock held for
2017 * the entire duration, we optimise this by doing this
2018 * check only once per cache_lookup_path call.
2019 * If dotdotchecked is set, it means we've done this
2020 * check once already and don't need to do it again.
2021 */
2022 if (!locked && (ndp->ni_rootdir != rootvnode)) {
2023 vfs_smr_leave();
2024 needs_lock = true;
2025 goto prep_lock_retry;
2026 } else if (locked && !dotdotchecked && (ndp->ni_rootdir != rootvnode)) {
2027 vnode_t tvp = dp;
2028 boolean_t defer = FALSE;
2029 boolean_t is_subdir = FALSE;
2030
2031 defer = cache_check_vnode_issubdir(tvp,
2032 ndp->ni_rootdir, &is_subdir, &tvp);
2033
2034 if (defer) {
2035 /* defer to Filesystem */
2036 break;
2037 } else if (!is_subdir) {
2038 /*
2039 * This process is trying to break out
2040 * of its chrooted jail, so all its
2041 * dotdot accesses will be translated to
2042 * its root directory.
2043 */
2044 vp = ndp->ni_rootdir;
2045 } else {
2046 /*
2047 * All good, let this dotdot access
2048 * proceed normally
2049 */
2050 vp = dp->v_parent;
2051 }
2052 dotdotchecked = TRUE;
2053 } else {
2054 vp = dp->v_parent;
2055 }
2056 if (!vp) {
2057 break;
2058 }
2059 vvid = vp->v_id;
2060 } else {
2061 if (!locked) {
2062 vp = cache_lookup_smr(dp, cnp, &vvid);
2063 if (!vid_is_same(dp, vid)) {
2064 vp = NULLVP;
2065 needs_lock = true;
2066 vfs_smr_leave();
2067 goto prep_lock_retry;
2068 }
2069 } else {
2070 vp = cache_lookup_locked(dp, cnp, &vvid);
2071 }
2072
2073
2074 if (!vp) {
2075 break;
2076 }
2077
2078 if ((vp->v_flag & VISHARDLINK)) {
2079 /*
2080 * The file system wants a VNOP_LOOKUP on this vnode
2081 */
2082 vp = NULL;
2083 break;
2084 }
2085
2086 #if CONFIG_FIRMLINKS
2087 vnode_t v_fmlink = vp->v_fmlink;
2088 if (v_fmlink && !(vp->v_flag & VFMLINKTARGET)) {
2089 if (cnp->cn_flags & CN_FIRMLINK_NOFOLLOW ||
2090 ((vp->v_type != VDIR) && (vp->v_type != VLNK))) {
2091 /* Leave it to the filesystem */
2092 vp = NULLVP;
2093 break;
2094 }
2095
2096 /*
2097 * Always switch to the target unless it is a VLNK
2098 * and it is the last component and we have NOFOLLOW
2099 * semantics
2100 */
2101 if (vp->v_type == VDIR) {
2102 vp = v_fmlink;
2103 vvid = vnode_vid(vp);
2104 } else if ((cnp->cn_flags & FOLLOW) ||
2105 (ndp->ni_flag & NAMEI_TRAILINGSLASH) || *ndp->ni_next == '/') {
2106 if (ndp->ni_loopcnt >= MAXSYMLINKS - 1) {
2107 vp = NULLVP;
2108 break;
2109 }
2110 ndp->ni_loopcnt++;
2111 vp = v_fmlink;
2112 vvid = vnode_vid(vp);
2113 }
2114 }
2115 #endif
2116 }
2117 if ((cnp->cn_flags & ISLASTCN)) {
2118 break;
2119 }
2120
2121 if (vp->v_type != VDIR) {
2122 if (vp->v_type != VLNK) {
2123 vp = NULL;
2124 }
2125 break;
2126 }
2127
2128 /*
2129 * v_mountedhere is PAC protected which means vp has to be a VDIR
2130 * to access that pointer as v_mountedhere. However, if we don't
2131 * have the name cache lock or an iocount (which we won't in the
2132 * !locked case) we can't guarantee that. So we try to detect it
2133 * via other fields to avoid having to dereference v_mountedhere
2134 * when we don't need to. Note that in theory if entire reclaim
2135 * happens between the time we check can_check_v_mountedhere()
2136 * and the subsequent access this will still fail but the fields
2137 * we check make that exceedingly unlikely and will result in
2138 * the chances of that happening being practically zero (but not
2139 * zero).
2140 */
2141 if ((locked || can_check_v_mountedhere(vp)) &&
2142 (mp = vp->v_mountedhere) && ((cnp->cn_flags & NOCROSSMOUNT) == 0)) {
2143 vnode_t tmp_vp;
2144 int tmp_vid;
2145
2146 if (!(locked || vid_is_same(vp, vvid))) {
2147 vp = NULL;
2148 break;
2149 }
2150 tmp_vp = mp->mnt_realrootvp;
2151 tmp_vid = mp->mnt_realrootvp_vid;
2152 if (tmp_vp == NULLVP || mp->mnt_generation != mount_generation ||
2153 tmp_vid != tmp_vp->v_id) {
2154 break;
2155 }
2156
2157 if ((mp = tmp_vp->v_mount) == NULL) {
2158 break;
2159 }
2160
2161 vp = tmp_vp;
2162 vvid = tmp_vid;
2163 dmp = mp;
2164 if (dmp->mnt_kern_flag & (MNTK_AUTH_OPAQUE | MNTK_AUTH_CACHE_TTL)) {
2165 ttl_enabled = TRUE;
2166 microuptime(&tv);
2167 } else {
2168 ttl_enabled = FALSE;
2169 }
2170 }
2171
2172 #if CONFIG_TRIGGERS
2173 /*
2174 * After traversing all mountpoints stacked here, if we have a
2175 * trigger in hand, resolve it. Note that we don't need to
2176 * leave the fast path if the mount has already happened.
2177 */
2178 if (vp->v_resolve) {
2179 break;
2180 }
2181 #endif /* CONFIG_TRIGGERS */
2182
2183 if ((ndp->ni_flag & NAMEI_LOCAL) && !(vp->v_mount->mnt_flag & MNT_LOCAL)) {
2184 /* Prevent a path lookup from ever crossing into a network filesystem */
2185 vp = NULL;
2186 break;
2187 }
2188
2189 if ((ndp->ni_flag & NAMEI_NODEVFS) && (vnode_tag(vp) == VT_DEVFS)) {
2190 /* Prevent a path lookup into `devfs` filesystem */
2191 vp = NULL;
2192 break;
2193 }
2194
2195 if ((ndp->ni_flag & NAMEI_IMMOVABLE) && (vp->v_mount->mnt_flag & MNT_REMOVABLE) && !(vp->v_mount->mnt_kern_flag & MNTK_VIRTUALDEV)) {
2196 /* prevent a path lookup into a removable filesystem */
2197 vp = NULL;
2198 break;
2199 }
2200
2201 if (!(locked || vid_is_same(vp, vvid))) {
2202 vp = NULL;
2203 break;
2204 }
2205
2206 dp = vp;
2207 vid = vvid;
2208 vp = NULLVP;
2209 vvid = 0;
2210
2211 cnp->cn_nameptr = ndp->ni_next + 1;
2212 ndp->ni_pathlen--;
2213 while (*cnp->cn_nameptr == '/') {
2214 cnp->cn_nameptr++;
2215 ndp->ni_pathlen--;
2216 }
2217 }
2218 if (!locked) {
2219 if (vp && !vnode_hold_smr(vp)) {
2220 vp = NULLVP;
2221 vvid = 0;
2222 }
2223 if (!vnode_hold_smr(dp)) {
2224 vfs_smr_leave();
2225 if (vp) {
2226 vnode_drop(vp);
2227 vp = NULLVP;
2228 vvid = 0;
2229 }
2230 goto prep_lock_retry;
2231 }
2232 vfs_smr_leave();
2233 } else {
2234 if (vp != NULLVP) {
2235 vvid = vp->v_id;
2236 vnode_hold(vp);
2237 }
2238 vid = dp->v_id;
2239
2240 vnode_hold(dp);
2241 NAME_CACHE_UNLOCK();
2242 }
2243
2244 tdp = NULLVP;
2245 if (!(cnp->cn_flags & DONOTAUTH) &&
2246 (vp != NULLVP) && (vp->v_type != VLNK) &&
2247 ((cnp->cn_flags & (ISLASTCN | LOCKPARENT | WANTPARENT | SAVESTART)) == ISLASTCN)) {
2248 /*
2249 * if we've got a child and it's the last component, and
2250 * the lookup doesn't need to return the parent then we
2251 * can skip grabbing an iocount on the parent, since all
2252 * we're going to do with it is a vnode_put just before
2253 * we return from 'lookup'. If it's a symbolic link,
2254 * we need the parent in case the link happens to be
2255 * a relative pathname.
2256 *
2257 * However, we can't make this optimisation if we have to call
2258 * a MAC hook.
2259 */
2260 tdp = dp;
2261 dp = NULLVP;
2262 } else {
2263 need_dp:
2264 /*
2265 * return the last directory we looked at
2266 * with an io reference held. If it was the one passed
2267 * in as a result of the last iteration of VNOP_LOOKUP,
2268 * it should already hold an io ref. No need to increase ref.
2269 */
2270 if (last_dp != dp) {
2271 if (dp == ndp->ni_usedvp) {
2272 /*
2273 * if this vnode matches the one passed in via USEDVP
2274 * than this context already holds an io_count... just
2275 * use vnode_get to get an extra ref for lookup to play
2276 * with... can't use the getwithvid variant here because
2277 * it will block behind a vnode_drain which would result
2278 * in a deadlock (since we already own an io_count that the
2279 * vnode_drain is waiting on)... vnode_get grabs the io_count
2280 * immediately w/o waiting... it always succeeds
2281 */
2282 vnode_get(dp);
2283 } else if ((error = vnode_getwithvid_drainok(dp, vid))) {
2284 /*
2285 * failure indicates the vnode
2286 * changed identity or is being
2287 * TERMINATED... in either case
2288 * punt this lookup.
2289 *
2290 * don't necessarily return ENOENT, though, because
2291 * we really want to go back to disk and make sure it's
2292 * there or not if someone else is changing this
2293 * vnode. That being said, the one case where we do want
2294 * to return ENOENT is when the vnode's mount point is
2295 * in the process of unmounting and we might cause a deadlock
2296 * in our attempt to take an iocount. An ENODEV error return
2297 * is from vnode_get* is an indication this but we change that
2298 * ENOENT for upper layers.
2299 */
2300 if (error == ENODEV) {
2301 error = ENOENT;
2302 } else {
2303 error = ERECYCLE;
2304 }
2305 vnode_drop(dp);
2306 if (vp) {
2307 vnode_drop(vp);
2308 }
2309 goto errorout;
2310 }
2311 dp_iocount_taken = true;
2312 }
2313 vnode_drop(dp);
2314 }
2315
2316 #if CONFIG_MACF
2317 /*
2318 * Name cache provides authorization caching (see below)
2319 * that will short circuit MAC checks in lookup().
2320 * We must perform MAC check here. On denial
2321 * dp_authorized will remain 0 and second check will
2322 * be perfomed in lookup().
2323 */
2324 if (!(cnp->cn_flags & DONOTAUTH)) {
2325 error = mac_vnode_check_lookup(ctx, dp, cnp);
2326 if (error) {
2327 *dp_authorized = 0;
2328 if (dp_iocount_taken) {
2329 vnode_put(dp);
2330 }
2331 if (vp) {
2332 vnode_drop(vp);
2333 vp = NULLVP;
2334 }
2335 goto errorout;
2336 }
2337 }
2338 #endif /* MAC */
2339
2340 if (vp != NULLVP) {
2341 if ((vnode_getwithvid_drainok(vp, vvid))) {
2342 vnode_drop(vp);
2343 vp = NULLVP;
2344
2345 /*
2346 * can't get reference on the vp we'd like
2347 * to return... if we didn't grab a reference
2348 * on the directory (due to fast path bypass),
2349 * then we need to do it now... we can't return
2350 * with both ni_dvp and ni_vp NULL, and no
2351 * error condition
2352 */
2353 if (dp == NULLVP) {
2354 dp = tdp;
2355 tdp = NULLVP;
2356 goto need_dp;
2357 }
2358 } else {
2359 vnode_drop(vp);
2360 }
2361 if (dp_iocount_taken && vp && (vp->v_type != VLNK) &&
2362 ((cnp->cn_flags & (ISLASTCN | LOCKPARENT | WANTPARENT | SAVESTART)) == ISLASTCN)) {
2363 vnode_put(dp);
2364 dp = NULLVP;
2365 }
2366 }
2367
2368 if (tdp) {
2369 vnode_drop(tdp);
2370 tdp = NULLVP;
2371 }
2372
2373 ndp->ni_dvp = dp;
2374 ndp->ni_vp = vp;
2375
2376 #if CONFIG_TRIGGERS
2377 trigger_vp = vp ? vp : dp;
2378 if ((error == 0) && (trigger_vp != NULLVP) && vnode_isdir(trigger_vp)) {
2379 error = vnode_trigger_resolve(trigger_vp, ndp, ctx);
2380 if (error) {
2381 if (vp) {
2382 vnode_put(vp);
2383 }
2384 if (dp) {
2385 vnode_put(dp);
2386 }
2387 goto errorout;
2388 }
2389 }
2390 #endif /* CONFIG_TRIGGERS */
2391
2392 errorout:
2393 /*
2394 * If we came into cache_lookup_path after an iteration of the lookup loop that
2395 * resulted in a call to VNOP_LOOKUP, then VNOP_LOOKUP returned a vnode with a io ref
2396 * on it. It is now the job of cache_lookup_path to drop the ref on this vnode
2397 * when it is no longer needed. If we get to this point, and last_dp is not NULL
2398 * and it is ALSO not the dvp we want to return to caller of this function, it MUST be
2399 * the case that we got to a subsequent path component and this previous vnode is
2400 * no longer needed. We can then drop the io ref on it.
2401 */
2402 if ((last_dp != NULLVP) && (last_dp != ndp->ni_dvp)) {
2403 vnode_put(last_dp);
2404 }
2405
2406 //initialized to 0, should be the same if no error cases occurred.
2407 return error;
2408
2409 prep_lock_retry:
2410 restore_ndp_state(ndp, cnp, &saved_state);
2411 dp = start_dp;
2412 goto retry;
2413 }
2414
2415
2416 static vnode_t
cache_lookup_locked(vnode_t dvp,struct componentname * cnp,uint32_t * vidp)2417 cache_lookup_locked(vnode_t dvp, struct componentname *cnp, uint32_t *vidp)
2418 {
2419 struct namecache *ncp;
2420 long namelen = cnp->cn_namelen;
2421 unsigned int hashval = cnp->cn_hash;
2422
2423 if (nc_disabled) {
2424 return NULL;
2425 }
2426
2427 smrq_serialized_foreach(ncp, NCHHASH(dvp, cnp->cn_hash), nc_hash) {
2428 if ((ncp->nc_dvp == dvp) && (ncp->nc_hashval == hashval)) {
2429 if (strncmp(ncp->nc_name, cnp->cn_nameptr, namelen) == 0 && ncp->nc_name[namelen] == 0) {
2430 break;
2431 }
2432 }
2433 }
2434 if (ncp == 0) {
2435 /*
2436 * We failed to find an entry
2437 */
2438 NCHSTAT(ncs_miss);
2439 NC_SMR_STATS(clp_next_fail);
2440 return NULL;
2441 }
2442 NCHSTAT(ncs_goodhits);
2443
2444 if (!ncp->nc_vp) {
2445 return NULL;
2446 }
2447
2448 *vidp = ncp->nc_vid;
2449 NC_SMR_STATS(clp_next);
2450
2451 return ncp->nc_vp;
2452 }
2453
2454 static vnode_t
cache_lookup_smr(vnode_t dvp,struct componentname * cnp,uint32_t * vidp)2455 cache_lookup_smr(vnode_t dvp, struct componentname *cnp, uint32_t *vidp)
2456 {
2457 struct namecache *ncp;
2458 long namelen = cnp->cn_namelen;
2459 unsigned int hashval = cnp->cn_hash;
2460 vnode_t vp = NULLVP;
2461 uint32_t vid = 0;
2462 uint32_t counter = 1;
2463
2464 if (nc_disabled) {
2465 return NULL;
2466 }
2467
2468 smrq_entered_foreach(ncp, NCHHASH(dvp, cnp->cn_hash), nc_hash) {
2469 counter = os_atomic_load(&ncp->nc_counter, acquire);
2470 if (!(counter & NC_VALID)) {
2471 ncp = NULL;
2472 goto out;
2473 }
2474 if ((ncp->nc_dvp == dvp) && (ncp->nc_hashval == hashval)) {
2475 const char *nc_name =
2476 os_atomic_load(&ncp->nc_name, relaxed);
2477 if (nc_name &&
2478 strncmp(nc_name, cnp->cn_nameptr, namelen) == 0 &&
2479 nc_name[namelen] == 0) {
2480 break;
2481 } else if (!nc_name) {
2482 ncp = NULL;
2483 goto out;
2484 }
2485 }
2486 }
2487
2488 /* We failed to find an entry */
2489 if (ncp == 0) {
2490 goto out;
2491 }
2492
2493 vp = ncp->nc_vp;
2494 vid = ncp->nc_vid;
2495
2496 /*
2497 * The validity of vp and vid depends on the value of the counter being
2498 * the same when we read it first in the loop and now. Anything else
2499 * and we can't use this vp & vid.
2500 * Hopefully this ncp wasn't reused 2 billion times between the time
2501 * we read it first and when we the counter value again.
2502 */
2503 if (os_atomic_load(&ncp->nc_counter, acquire) != counter) {
2504 vp = NULLVP;
2505 goto out;
2506 }
2507
2508 *vidp = vid;
2509 NC_SMR_STATS(clp_smr_next);
2510
2511 return vp;
2512
2513 out:
2514 NC_SMR_STATS(clp_smr_next_fail);
2515 return NULL;
2516 }
2517
2518
2519 unsigned int hash_string(const char *cp, int len);
2520 //
2521 // Have to take a len argument because we may only need to
2522 // hash part of a componentname.
2523 //
2524 unsigned int
hash_string(const char * cp,int len)2525 hash_string(const char *cp, int len)
2526 {
2527 unsigned hash = 0;
2528
2529 if (len) {
2530 while (len--) {
2531 hash = crc32tab[((hash >> 24) ^ (unsigned char)*cp++)] ^ hash << 8;
2532 }
2533 } else {
2534 while (*cp != '\0') {
2535 hash = crc32tab[((hash >> 24) ^ (unsigned char)*cp++)] ^ hash << 8;
2536 }
2537 }
2538 /*
2539 * the crc generator can legitimately generate
2540 * a 0... however, 0 for us means that we
2541 * haven't computed a hash, so use 1 instead
2542 */
2543 if (hash == 0) {
2544 hash = 1;
2545 }
2546 return hash;
2547 }
2548
2549
2550 /*
2551 * Lookup an entry in the cache
2552 *
2553 * We don't do this if the segment name is long, simply so the cache
2554 * can avoid holding long names (which would either waste space, or
2555 * add greatly to the complexity).
2556 *
2557 * Lookup is called with dvp pointing to the directory to search,
2558 * cnp pointing to the name of the entry being sought. If the lookup
2559 * succeeds, the vnode is returned in *vpp, and a status of -1 is
2560 * returned. If the lookup determines that the name does not exist
2561 * (negative cacheing), a status of ENOENT is returned. If the lookup
2562 * fails, a status of zero is returned.
2563 */
2564
2565 static int
cache_lookup_fallback(struct vnode * dvp,struct vnode ** vpp,struct componentname * cnp,int flags)2566 cache_lookup_fallback(struct vnode *dvp, struct vnode **vpp,
2567 struct componentname *cnp, int flags)
2568 {
2569 struct namecache *ncp;
2570 long namelen = cnp->cn_namelen;
2571 unsigned int hashval = cnp->cn_hash;
2572 boolean_t have_exclusive = FALSE;
2573 uint32_t vid;
2574 vnode_t vp;
2575
2576 NAME_CACHE_LOCK_SHARED();
2577
2578 relook:
2579 smrq_serialized_foreach(ncp, NCHHASH(dvp, cnp->cn_hash), nc_hash) {
2580 if ((ncp->nc_dvp == dvp) && (ncp->nc_hashval == hashval)) {
2581 if (strncmp(ncp->nc_name, cnp->cn_nameptr, namelen) == 0 && ncp->nc_name[namelen] == 0) {
2582 break;
2583 }
2584 }
2585 }
2586 /* We failed to find an entry */
2587 if (ncp == 0) {
2588 NCHSTAT(ncs_miss);
2589 NAME_CACHE_UNLOCK();
2590 return 0;
2591 }
2592
2593 /* We don't want to have an entry, so dump it */
2594 if ((cnp->cn_flags & MAKEENTRY) == 0) {
2595 if (have_exclusive == TRUE) {
2596 NCHSTAT(ncs_badhits);
2597 cache_delete(ncp, 1);
2598 NAME_CACHE_UNLOCK();
2599 return 0;
2600 }
2601 if (!NAME_CACHE_LOCK_SHARED_TO_EXCLUSIVE()) {
2602 NAME_CACHE_LOCK();
2603 }
2604 have_exclusive = TRUE;
2605 goto relook;
2606 }
2607 vp = ncp->nc_vp;
2608
2609 /* We found a "positive" match, return the vnode */
2610 if (vp) {
2611 NCHSTAT(ncs_goodhits);
2612
2613 vid = ncp->nc_vid;
2614 vnode_hold(vp);
2615 NAME_CACHE_UNLOCK();
2616
2617 if (vnode_getwithvid(vp, vid)) {
2618 vnode_drop(vp);
2619 #if COLLECT_STATS
2620 NAME_CACHE_LOCK();
2621 NCHSTAT(ncs_badvid);
2622 NAME_CACHE_UNLOCK();
2623 #endif
2624 return 0;
2625 }
2626 vnode_drop(vp);
2627 *vpp = vp;
2628 NC_SMR_STATS(cl_lock_hits);
2629 return -1;
2630 }
2631
2632 /* We found a negative match, and want to create it, so purge */
2633 if (cnp->cn_nameiop == CREATE || cnp->cn_nameiop == RENAME) {
2634 if (have_exclusive == TRUE) {
2635 NCHSTAT(ncs_badhits);
2636 cache_delete(ncp, 1);
2637 NAME_CACHE_UNLOCK();
2638 /*
2639 * Even though we're purging the entry, it
2640 * may be useful to the caller to know that
2641 * we got a neg hit (to, for example, avoid
2642 * an expensive IPC/RPC).
2643 */
2644 return (flags & CACHE_LOOKUP_ALLHITS) ? ENOENT : 0;
2645 }
2646 if (!NAME_CACHE_LOCK_SHARED_TO_EXCLUSIVE()) {
2647 NAME_CACHE_LOCK();
2648 }
2649 have_exclusive = TRUE;
2650 goto relook;
2651 }
2652
2653 /*
2654 * We found a "negative" match, ENOENT notifies client of this match.
2655 */
2656 NCHSTAT(ncs_neghits);
2657
2658 NAME_CACHE_UNLOCK();
2659 return ENOENT;
2660 }
2661
2662
2663
2664 /*
2665 * Lookup an entry in the cache
2666 *
2667 * Lookup is called with dvp pointing to the directory to search,
2668 * cnp pointing to the name of the entry being sought. If the lookup
2669 * succeeds, the vnode is returned in *vpp, and a status of -1 is
2670 * returned. If the lookup determines that the name does not exist
2671 * (negative cacheing), a status of ENOENT is returned. If the lookup
2672 * fails, a status of zero is returned.
2673 */
2674 int
cache_lookup_ext(struct vnode * dvp,struct vnode ** vpp,struct componentname * cnp,int flags)2675 cache_lookup_ext(struct vnode *dvp, struct vnode **vpp,
2676 struct componentname *cnp, int flags)
2677 {
2678 struct namecache *ncp;
2679 long namelen = cnp->cn_namelen;
2680 vnode_t vp;
2681 uint32_t vid = 0;
2682 uint32_t counter = 1;
2683 unsigned int hashval;
2684
2685 *vpp = NULLVP;
2686
2687 if (cnp->cn_hash == 0) {
2688 cnp->cn_hash = hash_string(cnp->cn_nameptr, cnp->cn_namelen);
2689 }
2690 hashval = cnp->cn_hash;
2691
2692 if (nc_disabled) {
2693 return 0;
2694 }
2695
2696 if (!nc_smr_enabled) {
2697 goto out_fallback;
2698 }
2699
2700 /* We don't want to have an entry, so dump it */
2701 if ((cnp->cn_flags & MAKEENTRY) == 0) {
2702 goto out_fallback;
2703 }
2704
2705 vfs_smr_enter();
2706
2707 smrq_entered_foreach(ncp, NCHHASH(dvp, cnp->cn_hash), nc_hash) {
2708 counter = os_atomic_load(&ncp->nc_counter, acquire);
2709 if (!(counter & NC_VALID)) {
2710 vfs_smr_leave();
2711 goto out_fallback;
2712 }
2713 if ((ncp->nc_dvp == dvp) && (ncp->nc_hashval == hashval)) {
2714 const char *nc_name =
2715 os_atomic_load(&ncp->nc_name, relaxed);
2716 if (nc_name &&
2717 strncmp(nc_name, cnp->cn_nameptr, namelen) == 0 &&
2718 nc_name[namelen] == 0) {
2719 break;
2720 } else if (!nc_name) {
2721 vfs_smr_leave();
2722 goto out_fallback;
2723 }
2724 }
2725 }
2726
2727 /* We failed to find an entry */
2728 if (ncp == 0) {
2729 NCHSTAT(ncs_miss);
2730 vfs_smr_leave();
2731 NC_SMR_STATS(cl_smr_miss);
2732 return 0;
2733 }
2734
2735 vp = ncp->nc_vp;
2736 vid = ncp->nc_vid;
2737
2738 /*
2739 * The validity of vp and vid depends on the value of the counter being
2740 * the same when we read it first in the loop and now. Anything else
2741 * and we can't use this vp & vid.
2742 * Hopefully this ncp wasn't reused 2 billion times between the time
2743 * we read it first and when we the counter value again.
2744 */
2745 if (os_atomic_load(&ncp->nc_counter, acquire) != counter) {
2746 vfs_smr_leave();
2747 goto out_fallback;
2748 }
2749
2750 if (vp) {
2751 bool holdcount_acquired = vnode_hold_smr(vp);
2752
2753 vfs_smr_leave();
2754
2755 if (!holdcount_acquired) {
2756 goto out_fallback;
2757 }
2758
2759 if (vnode_getwithvid(vp, vid) != 0) {
2760 vnode_drop(vp);
2761 goto out_fallback;
2762 }
2763 vnode_drop(vp);
2764 NCHSTAT(ncs_goodhits);
2765
2766 *vpp = vp;
2767 NC_SMR_STATS(cl_smr_hits);
2768 return -1;
2769 }
2770
2771 vfs_smr_leave();
2772
2773 /* We found a negative match, and want to create it, so purge */
2774 if (cnp->cn_nameiop == CREATE || cnp->cn_nameiop == RENAME) {
2775 goto out_fallback;
2776 }
2777
2778 /*
2779 * We found a "negative" match, ENOENT notifies client of this match.
2780 */
2781 NCHSTAT(ncs_neghits);
2782 NC_SMR_STATS(cl_smr_negative_hits);
2783 return ENOENT;
2784
2785 out_fallback:
2786 NC_SMR_STATS(cl_smr_fallback);
2787 return cache_lookup_fallback(dvp, vpp, cnp, flags);
2788 }
2789
2790 int
cache_lookup(struct vnode * dvp,struct vnode ** vpp,struct componentname * cnp)2791 cache_lookup(struct vnode *dvp, struct vnode **vpp, struct componentname *cnp)
2792 {
2793 return cache_lookup_ext(dvp, vpp, cnp, 0);
2794 }
2795
2796 const char *
cache_enter_create(vnode_t dvp,vnode_t vp,struct componentname * cnp)2797 cache_enter_create(vnode_t dvp, vnode_t vp, struct componentname *cnp)
2798 {
2799 const char *strname;
2800
2801 if (cnp->cn_hash == 0) {
2802 cnp->cn_hash = hash_string(cnp->cn_nameptr, cnp->cn_namelen);
2803 }
2804
2805 /*
2806 * grab 2 references on the string entered
2807 * one for the cache_enter_locked to consume
2808 * and the second to be consumed by v_name (vnode_create call point)
2809 */
2810 strname = add_name_internal(cnp->cn_nameptr, cnp->cn_namelen, cnp->cn_hash, TRUE, 0);
2811
2812 NAME_CACHE_LOCK();
2813
2814 cache_enter_locked(dvp, vp, cnp, strname);
2815
2816 NAME_CACHE_UNLOCK();
2817
2818 return strname;
2819 }
2820
2821
2822 /*
2823 * Add an entry to the cache...
2824 * but first check to see if the directory
2825 * that this entry is to be associated with has
2826 * had any cache_purges applied since we took
2827 * our identity snapshot... this check needs to
2828 * be done behind the name cache lock
2829 */
2830 void
cache_enter_with_gen(struct vnode * dvp,struct vnode * vp,struct componentname * cnp,int gen)2831 cache_enter_with_gen(struct vnode *dvp, struct vnode *vp, struct componentname *cnp, int gen)
2832 {
2833 if (cnp->cn_hash == 0) {
2834 cnp->cn_hash = hash_string(cnp->cn_nameptr, cnp->cn_namelen);
2835 }
2836
2837 NAME_CACHE_LOCK();
2838
2839 if (dvp->v_nc_generation == gen) {
2840 (void)cache_enter_locked(dvp, vp, cnp, NULL);
2841 }
2842
2843 NAME_CACHE_UNLOCK();
2844 }
2845
2846
2847 /*
2848 * Add an entry to the cache.
2849 */
2850 void
cache_enter(struct vnode * dvp,struct vnode * vp,struct componentname * cnp)2851 cache_enter(struct vnode *dvp, struct vnode *vp, struct componentname *cnp)
2852 {
2853 const char *strname;
2854
2855 if (cnp->cn_hash == 0) {
2856 cnp->cn_hash = hash_string(cnp->cn_nameptr, cnp->cn_namelen);
2857 }
2858
2859 /*
2860 * grab 1 reference on the string entered
2861 * for the cache_enter_locked to consume
2862 */
2863 strname = add_name_internal(cnp->cn_nameptr, cnp->cn_namelen, cnp->cn_hash, FALSE, 0);
2864
2865 NAME_CACHE_LOCK();
2866
2867 cache_enter_locked(dvp, vp, cnp, strname);
2868
2869 NAME_CACHE_UNLOCK();
2870 }
2871
2872
2873 static void
cache_enter_locked(struct vnode * dvp,struct vnode * vp,struct componentname * cnp,const char * strname)2874 cache_enter_locked(struct vnode *dvp, struct vnode *vp, struct componentname *cnp, const char *strname)
2875 {
2876 struct namecache *ncp, *negp;
2877 struct smrq_list_head *ncpp;
2878
2879 if (nc_disabled) {
2880 return;
2881 }
2882
2883 /*
2884 * if the entry is for -ve caching vp is null
2885 */
2886 if ((vp != NULLVP) && (LIST_FIRST(&vp->v_nclinks))) {
2887 /*
2888 * someone beat us to the punch..
2889 * this vnode is already in the cache
2890 */
2891 if (strname != NULL) {
2892 vfs_removename(strname);
2893 }
2894 return;
2895 }
2896 /*
2897 * We allocate a new entry if we are less than the maximum
2898 * allowed and the one at the front of the list is in use.
2899 * Otherwise we use the one at the front of the list.
2900 */
2901 if (numcache < desiredNodes &&
2902 ((ncp = nchead.tqh_first) == NULL ||
2903 (ncp->nc_counter & NC_VALID))) {
2904 /*
2905 * Allocate one more entry
2906 */
2907 if (nc_smr_enabled) {
2908 ncp = zalloc_smr(namecache_zone, Z_WAITOK_ZERO_NOFAIL);
2909 } else {
2910 ncp = zalloc(namecache_zone);
2911 }
2912 ncp->nc_counter = 0;
2913 numcache++;
2914 } else {
2915 /*
2916 * reuse an old entry
2917 */
2918 ncp = TAILQ_FIRST(&nchead);
2919 TAILQ_REMOVE(&nchead, ncp, nc_entry);
2920
2921 if (ncp->nc_counter & NC_VALID) {
2922 /*
2923 * still in use... we need to
2924 * delete it before re-using it
2925 */
2926 NCHSTAT(ncs_stolen);
2927 cache_delete(ncp, 0);
2928 }
2929 }
2930 NCHSTAT(ncs_enters);
2931
2932 /*
2933 * Fill in cache info, if vp is NULL this is a "negative" cache entry.
2934 */
2935 if (vp) {
2936 ncp->nc_vid = vnode_vid(vp);
2937 vnode_hold(vp);
2938 }
2939 ncp->nc_vp = vp;
2940 ncp->nc_dvp = dvp;
2941 ncp->nc_hashval = cnp->cn_hash;
2942
2943 if (strname == NULL) {
2944 ncp->nc_name = add_name_internal(cnp->cn_nameptr, cnp->cn_namelen, cnp->cn_hash, FALSE, 0);
2945 } else {
2946 ncp->nc_name = strname;
2947 }
2948
2949 //
2950 // If the bytes of the name associated with the vnode differ,
2951 // use the name associated with the vnode since the file system
2952 // may have set that explicitly in the case of a lookup on a
2953 // case-insensitive file system where the case of the looked up
2954 // name differs from what is on disk. For more details, see:
2955 // <rdar://problem/8044697> FSEvents doesn't always decompose diacritical unicode chars in the paths of the changed directories
2956 //
2957 const char *vn_name = vp ? vp->v_name : NULL;
2958 unsigned int len = vn_name ? (unsigned int)strlen(vn_name) : 0;
2959 if (vn_name && ncp && ncp->nc_name && strncmp(ncp->nc_name, vn_name, len) != 0) {
2960 unsigned int hash = hash_string(vn_name, len);
2961
2962 vfs_removename(ncp->nc_name);
2963 ncp->nc_name = add_name_internal(vn_name, len, hash, FALSE, 0);
2964 ncp->nc_hashval = hash;
2965 }
2966
2967 /*
2968 * make us the newest entry in the cache
2969 * i.e. we'll be the last to be stolen
2970 */
2971 TAILQ_INSERT_TAIL(&nchead, ncp, nc_entry);
2972
2973 ncpp = NCHHASH(dvp, cnp->cn_hash);
2974 #if DIAGNOSTIC
2975 {
2976 struct namecache *p;
2977
2978 smrq_serialized_foreach(p, ncpp, nc_hash) {
2979 if (p == ncp) {
2980 panic("cache_enter: duplicate");
2981 }
2982 }
2983 }
2984 #endif
2985 /*
2986 * make us available to be found via lookup
2987 */
2988 smrq_serialized_insert_head(ncpp, &ncp->nc_hash);
2989
2990 if (vp) {
2991 /*
2992 * add to the list of name cache entries
2993 * that point at vp
2994 */
2995 LIST_INSERT_HEAD(&vp->v_nclinks, ncp, nc_un.nc_link);
2996 } else {
2997 /*
2998 * this is a negative cache entry (vp == NULL)
2999 * stick it on the negative cache list.
3000 */
3001 TAILQ_INSERT_TAIL(&neghead, ncp, nc_un.nc_negentry);
3002
3003 ncs_negtotal++;
3004
3005 if (ncs_negtotal > desiredNegNodes) {
3006 /*
3007 * if we've reached our desired limit
3008 * of negative cache entries, delete
3009 * the oldest
3010 */
3011 negp = TAILQ_FIRST(&neghead);
3012 cache_delete(negp, 1);
3013 }
3014 }
3015
3016 /*
3017 * add us to the list of name cache entries that
3018 * are children of dvp
3019 */
3020 if (vp) {
3021 TAILQ_INSERT_TAIL(&dvp->v_ncchildren, ncp, nc_child);
3022 } else {
3023 TAILQ_INSERT_HEAD(&dvp->v_ncchildren, ncp, nc_child);
3024 }
3025
3026 /*
3027 * nc_counter represents a sequence counter and 1 bit valid flag.
3028 * When the counter value is odd, it represents a valid and in use
3029 * namecache structure. We increment the value on every state transition
3030 * (invalid to valid (here) and valid to invalid (in cache delete).
3031 * Lockless readers have to read the value before reading other fields
3032 * and ensure that the field is valid and remains the same after the fields
3033 * have been read.
3034 */
3035 uint32_t old_count = os_atomic_inc_orig(&ncp->nc_counter, release);
3036 if (old_count & NC_VALID) {
3037 /* This is a invalid to valid transition */
3038 panic("Incorrect state for old nc_counter(%d), should be even", old_count);
3039 }
3040 }
3041
3042
3043 /*
3044 * Initialize CRC-32 remainder table.
3045 */
3046 static void
init_crc32(void)3047 init_crc32(void)
3048 {
3049 /*
3050 * the CRC-32 generator polynomial is:
3051 * x^32 + x^26 + x^23 + x^22 + x^16 + x^12 + x^10
3052 * + x^8 + x^7 + x^5 + x^4 + x^2 + x + 1
3053 */
3054 unsigned int crc32_polynomial = 0x04c11db7;
3055 unsigned int i, j;
3056
3057 /*
3058 * pre-calculate the CRC-32 remainder for each possible octet encoding
3059 */
3060 for (i = 0; i < 256; i++) {
3061 unsigned int crc_rem = i << 24;
3062
3063 for (j = 0; j < 8; j++) {
3064 if (crc_rem & 0x80000000) {
3065 crc_rem = (crc_rem << 1) ^ crc32_polynomial;
3066 } else {
3067 crc_rem = (crc_rem << 1);
3068 }
3069 }
3070 crc32tab[i] = crc_rem;
3071 }
3072 }
3073
3074
3075 /*
3076 * Name cache initialization, from vfs_init() when we are booting
3077 */
3078 void
nchinit(void)3079 nchinit(void)
3080 {
3081 desiredNegNodes = (desiredvnodes / 10);
3082 desiredNodes = desiredvnodes + desiredNegNodes;
3083
3084 if (nc_smr_enabled) {
3085 zone_enable_smr(namecache_zone, VFS_SMR(), &namecache_smr_free);
3086 zone_enable_smr(stringcache_zone, VFS_SMR(), &string_smr_free);
3087 }
3088 TAILQ_INIT(&nchead);
3089 TAILQ_INIT(&neghead);
3090
3091 init_crc32();
3092
3093 nchashtbl = hashinit(MAX(CONFIG_NC_HASH, (2 * desiredNodes)), M_CACHE, &nchash);
3094 nchashmask = nchash;
3095 nchash++;
3096
3097 init_string_table();
3098
3099 for (int i = 0; i < NUM_STRCACHE_LOCKS; i++) {
3100 lck_mtx_init(&strcache_mtx_locks[i], &strcache_lck_grp, &strcache_lck_attr);
3101 }
3102 }
3103
3104 void
name_cache_lock_shared(void)3105 name_cache_lock_shared(void)
3106 {
3107 lck_rw_lock_shared(&namecache_rw_lock);
3108 NC_SMR_STATS(nc_lock_shared);
3109 }
3110
3111 void
name_cache_lock(void)3112 name_cache_lock(void)
3113 {
3114 lck_rw_lock_exclusive(&namecache_rw_lock);
3115 NC_SMR_STATS(nc_lock);
3116 }
3117
3118 boolean_t
name_cache_lock_shared_to_exclusive(void)3119 name_cache_lock_shared_to_exclusive(void)
3120 {
3121 return lck_rw_lock_shared_to_exclusive(&namecache_rw_lock);
3122 }
3123
3124 void
name_cache_unlock(void)3125 name_cache_unlock(void)
3126 {
3127 lck_rw_done(&namecache_rw_lock);
3128 }
3129
3130
3131 int
resize_namecache(int newsize)3132 resize_namecache(int newsize)
3133 {
3134 struct smrq_list_head *new_table;
3135 struct smrq_list_head *old_table;
3136 struct smrq_list_head *old_head;
3137 struct namecache *entry;
3138 uint32_t i, hashval;
3139 int dNodes, dNegNodes, nelements;
3140 u_long new_size, old_size;
3141
3142 if (newsize < 0) {
3143 return EINVAL;
3144 }
3145
3146 dNegNodes = (newsize / 10);
3147 dNodes = newsize + dNegNodes;
3148 // we don't support shrinking yet
3149 if (dNodes <= desiredNodes) {
3150 return 0;
3151 }
3152
3153 if (os_mul_overflow(dNodes, 2, &nelements)) {
3154 return EINVAL;
3155 }
3156
3157 new_table = hashinit(nelements, M_CACHE, &nchashmask);
3158 new_size = nchashmask + 1;
3159
3160 if (new_table == NULL) {
3161 return ENOMEM;
3162 }
3163
3164 NAME_CACHE_LOCK();
3165
3166 /* No need to switch if the hash table size hasn't changed. */
3167 if (new_size == nchash) {
3168 NAME_CACHE_UNLOCK();
3169 hashdestroy(new_table, M_CACHE, new_size - 1);
3170 return 0;
3171 }
3172
3173 // do the switch!
3174 old_table = nchashtbl;
3175 nchashtbl = new_table;
3176 old_size = nchash;
3177 nchash = new_size;
3178
3179 // walk the old table and insert all the entries into
3180 // the new table
3181 //
3182 for (i = 0; i < old_size; i++) {
3183 old_head = &old_table[i];
3184 smrq_serialized_foreach_safe(entry, old_head, nc_hash) {
3185 //
3186 // XXXdbg - Beware: this assumes that hash_string() does
3187 // the same thing as what happens in
3188 // lookup() over in vfs_lookup.c
3189 hashval = hash_string(entry->nc_name, 0);
3190 entry->nc_hashval = hashval;
3191
3192 smrq_serialized_insert_head(NCHHASH(entry->nc_dvp, hashval), &entry->nc_hash);
3193 }
3194 }
3195 desiredNodes = dNodes;
3196 desiredNegNodes = dNegNodes;
3197
3198 NAME_CACHE_UNLOCK();
3199 hashdestroy(old_table, M_CACHE, old_size - 1);
3200
3201 return 0;
3202 }
3203
3204 static void
namecache_smr_free(void * _ncp,__unused size_t _size)3205 namecache_smr_free(void *_ncp, __unused size_t _size)
3206 {
3207 struct namecache *ncp = _ncp;
3208
3209 bzero(ncp, sizeof(*ncp));
3210 }
3211
3212 static void
cache_delete(struct namecache * ncp,int free_entry)3213 cache_delete(struct namecache *ncp, int free_entry)
3214 {
3215 NCHSTAT(ncs_deletes);
3216
3217 /*
3218 * See comment at the end of cache_enter_locked expalining the usage of
3219 * nc_counter.
3220 */
3221 uint32_t old_count = os_atomic_inc_orig(&ncp->nc_counter, release);
3222 if (!(old_count & NC_VALID)) {
3223 /* This should be a valid to invalid transition */
3224 panic("Incorrect state for old nc_counter(%d), should be odd", old_count);
3225 }
3226
3227 if (ncp->nc_vp) {
3228 LIST_REMOVE(ncp, nc_un.nc_link);
3229 } else {
3230 TAILQ_REMOVE(&neghead, ncp, nc_un.nc_negentry);
3231 ncs_negtotal--;
3232 }
3233 TAILQ_REMOVE(&(ncp->nc_dvp->v_ncchildren), ncp, nc_child);
3234
3235 smrq_serialized_remove((NCHHASH(ncp->nc_dvp, ncp->nc_hashval)), &ncp->nc_hash);
3236
3237 const char *nc_name = ncp->nc_name;
3238 ncp->nc_name = NULL;
3239 vfs_removename(nc_name);
3240 if (ncp->nc_vp) {
3241 vnode_t vp = ncp->nc_vp;
3242
3243 ncp->nc_vp = NULLVP;
3244 vnode_drop(vp);
3245 }
3246
3247 if (free_entry) {
3248 TAILQ_REMOVE(&nchead, ncp, nc_entry);
3249 if (nc_smr_enabled) {
3250 zfree_smr(namecache_zone, ncp);
3251 } else {
3252 zfree(namecache_zone, ncp);
3253 }
3254 numcache--;
3255 }
3256 }
3257
3258
3259 /*
3260 * purge the entry associated with the
3261 * specified vnode from the name cache
3262 */
3263 static void
cache_purge_locked(vnode_t vp,kauth_cred_t * credp)3264 cache_purge_locked(vnode_t vp, kauth_cred_t *credp)
3265 {
3266 struct namecache *ncp;
3267
3268 *credp = NULL;
3269 if ((LIST_FIRST(&vp->v_nclinks) == NULL) &&
3270 (TAILQ_FIRST(&vp->v_ncchildren) == NULL) &&
3271 (vnode_cred(vp) == NOCRED) &&
3272 (vp->v_parent == NULLVP)) {
3273 return;
3274 }
3275
3276 if (vp->v_parent) {
3277 vp->v_parent->v_nc_generation++;
3278 }
3279
3280 while ((ncp = LIST_FIRST(&vp->v_nclinks))) {
3281 cache_delete(ncp, 1);
3282 }
3283
3284 while ((ncp = TAILQ_FIRST(&vp->v_ncchildren))) {
3285 cache_delete(ncp, 1);
3286 }
3287
3288 /*
3289 * Use a temp variable to avoid kauth_cred_unref() while NAME_CACHE_LOCK is held
3290 */
3291 *credp = vnode_cred(vp);
3292 vp->v_cred = NOCRED;
3293 vp->v_authorized_actions = 0;
3294 }
3295
3296 void
cache_purge(vnode_t vp)3297 cache_purge(vnode_t vp)
3298 {
3299 kauth_cred_t tcred = NULL;
3300
3301 if ((LIST_FIRST(&vp->v_nclinks) == NULL) &&
3302 (TAILQ_FIRST(&vp->v_ncchildren) == NULL) &&
3303 (vnode_cred(vp) == NOCRED) &&
3304 (vp->v_parent == NULLVP)) {
3305 return;
3306 }
3307
3308 NAME_CACHE_LOCK();
3309
3310 cache_purge_locked(vp, &tcred);
3311
3312 NAME_CACHE_UNLOCK();
3313
3314 if (IS_VALID_CRED(tcred)) {
3315 kauth_cred_unref(&tcred);
3316 }
3317 }
3318
3319 /*
3320 * Purge all negative cache entries that are children of the
3321 * given vnode. A case-insensitive file system (or any file
3322 * system that has multiple equivalent names for the same
3323 * directory entry) can use this when creating or renaming
3324 * to remove negative entries that may no longer apply.
3325 */
3326 void
cache_purge_negatives(vnode_t vp)3327 cache_purge_negatives(vnode_t vp)
3328 {
3329 struct namecache *ncp, *next_ncp;
3330
3331 NAME_CACHE_LOCK();
3332
3333 TAILQ_FOREACH_SAFE(ncp, &vp->v_ncchildren, nc_child, next_ncp) {
3334 if (ncp->nc_vp) {
3335 break;
3336 }
3337
3338 cache_delete(ncp, 1);
3339 }
3340
3341 NAME_CACHE_UNLOCK();
3342 }
3343
3344 /*
3345 * Flush all entries referencing a particular filesystem.
3346 *
3347 * Since we need to check it anyway, we will flush all the invalid
3348 * entries at the same time.
3349 */
3350 void
cache_purgevfs(struct mount * mp)3351 cache_purgevfs(struct mount *mp)
3352 {
3353 struct smrq_list_head *ncpp;
3354 struct namecache *ncp;
3355
3356 NAME_CACHE_LOCK();
3357 /* Scan hash tables for applicable entries */
3358 for (ncpp = &nchashtbl[nchash - 1]; ncpp >= nchashtbl; ncpp--) {
3359 restart:
3360 smrq_serialized_foreach(ncp, ncpp, nc_hash) {
3361 if (ncp->nc_dvp->v_mount == mp) {
3362 cache_delete(ncp, 0);
3363 goto restart;
3364 }
3365 }
3366 }
3367 NAME_CACHE_UNLOCK();
3368 }
3369
3370
3371
3372 //
3373 // String ref routines
3374 //
3375 static LIST_HEAD(stringhead, string_t) * string_ref_table;
3376 static u_long string_table_mask;
3377 static uint32_t filled_buckets = 0;
3378
3379
3380
3381
3382 static void
resize_string_ref_table(void)3383 resize_string_ref_table(void)
3384 {
3385 struct stringhead *new_table;
3386 struct stringhead *old_table;
3387 struct stringhead *old_head, *head;
3388 string_t *entry, *next;
3389 uint32_t i, hashval;
3390 u_long new_mask, old_mask;
3391
3392 /*
3393 * need to hold the table lock exclusively
3394 * in order to grow the table... need to recheck
3395 * the need to resize again after we've taken
3396 * the lock exclusively in case some other thread
3397 * beat us to the punch
3398 */
3399 lck_rw_lock_exclusive(&strtable_rw_lock);
3400
3401 if (4 * filled_buckets < ((string_table_mask + 1) * 3)) {
3402 lck_rw_done(&strtable_rw_lock);
3403 return;
3404 }
3405 assert(string_table_mask < INT32_MAX);
3406 new_table = hashinit((int)(string_table_mask + 1) * 2, M_CACHE, &new_mask);
3407
3408 if (new_table == NULL) {
3409 printf("failed to resize the hash table.\n");
3410 lck_rw_done(&strtable_rw_lock);
3411 return;
3412 }
3413
3414 // do the switch!
3415 old_table = string_ref_table;
3416 string_ref_table = new_table;
3417 old_mask = string_table_mask;
3418 string_table_mask = new_mask;
3419 filled_buckets = 0;
3420
3421 // walk the old table and insert all the entries into
3422 // the new table
3423 //
3424 for (i = 0; i <= old_mask; i++) {
3425 old_head = &old_table[i];
3426 for (entry = old_head->lh_first; entry != NULL; entry = next) {
3427 hashval = hash_string((const char *)entry->str, 0);
3428 head = &string_ref_table[hashval & string_table_mask];
3429 if (head->lh_first == NULL) {
3430 filled_buckets++;
3431 }
3432 next = entry->hash_chain.le_next;
3433 LIST_INSERT_HEAD(head, entry, hash_chain);
3434 }
3435 }
3436 lck_rw_done(&strtable_rw_lock);
3437
3438 hashdestroy(old_table, M_CACHE, old_mask);
3439 }
3440
3441
3442 static void
init_string_table(void)3443 init_string_table(void)
3444 {
3445 string_ref_table = hashinit(CONFIG_VFS_NAMES, M_CACHE, &string_table_mask);
3446 }
3447
3448
3449 const char *
vfs_addname(const char * name,uint32_t len,u_int hashval,u_int flags)3450 vfs_addname(const char *name, uint32_t len, u_int hashval, u_int flags)
3451 {
3452 return add_name_internal(name, len, hashval, FALSE, flags);
3453 }
3454
3455
3456 static const char *
add_name_internal(const char * name,uint32_t len,u_int hashval,boolean_t need_extra_ref,__unused u_int flags)3457 add_name_internal(const char *name, uint32_t len, u_int hashval, boolean_t need_extra_ref, __unused u_int flags)
3458 {
3459 struct stringhead *head;
3460 string_t *entry;
3461 uint32_t chain_len = 0;
3462 uint32_t hash_index;
3463 uint32_t lock_index;
3464 char *ptr;
3465
3466 if (len > MAXPATHLEN) {
3467 len = MAXPATHLEN;
3468 }
3469
3470 /*
3471 * if the length already accounts for the null-byte, then
3472 * subtract one so later on we don't index past the end
3473 * of the string.
3474 */
3475 if (len > 0 && name[len - 1] == '\0') {
3476 len--;
3477 }
3478 if (hashval == 0) {
3479 hashval = hash_string(name, len);
3480 }
3481
3482 /*
3483 * take this lock 'shared' to keep the hash stable
3484 * if someone else decides to grow the pool they
3485 * will take this lock exclusively
3486 */
3487 lck_rw_lock_shared(&strtable_rw_lock);
3488
3489 /*
3490 * If the table gets more than 3/4 full, resize it
3491 */
3492 if (4 * filled_buckets >= ((string_table_mask + 1) * 3)) {
3493 lck_rw_done(&strtable_rw_lock);
3494
3495 resize_string_ref_table();
3496
3497 lck_rw_lock_shared(&strtable_rw_lock);
3498 }
3499 hash_index = hashval & string_table_mask;
3500 lock_index = hash_index % NUM_STRCACHE_LOCKS;
3501
3502 head = &string_ref_table[hash_index];
3503
3504 lck_mtx_lock_spin(&strcache_mtx_locks[lock_index]);
3505
3506 for (entry = head->lh_first; entry != NULL; chain_len++, entry = entry->hash_chain.le_next) {
3507 if (strncmp(entry->str, name, len) == 0 && entry->str[len] == 0) {
3508 entry->refcount++;
3509 break;
3510 }
3511 }
3512 if (entry == NULL) {
3513 const uint32_t buflen = len + 1;
3514
3515 lck_mtx_convert_spin(&strcache_mtx_locks[lock_index]);
3516 /*
3517 * it wasn't already there so add it.
3518 */
3519 if (nc_smr_enabled) {
3520 entry = zalloc_smr(stringcache_zone, Z_WAITOK_ZERO_NOFAIL);
3521 } else {
3522 entry = zalloc(stringcache_zone);
3523 }
3524
3525 if (head->lh_first == NULL) {
3526 OSAddAtomic(1, &filled_buckets);
3527 }
3528 ptr = kalloc_data(buflen, Z_WAITOK);
3529 strncpy(ptr, name, len);
3530 ptr[len] = '\0';
3531 entry->str = ptr;
3532 entry->strbuflen = buflen;
3533 entry->refcount = 1;
3534 LIST_INSERT_HEAD(head, entry, hash_chain);
3535 }
3536 if (need_extra_ref == TRUE) {
3537 entry->refcount++;
3538 }
3539
3540 lck_mtx_unlock(&strcache_mtx_locks[lock_index]);
3541 lck_rw_done(&strtable_rw_lock);
3542
3543 return (const char *)entry->str;
3544 }
3545
3546 static void
string_smr_free(void * _entry,__unused size_t size)3547 string_smr_free(void *_entry, __unused size_t size)
3548 {
3549 string_t *entry = _entry;
3550
3551 kfree_data(entry->str, entry->strbuflen);
3552 bzero(entry, sizeof(*entry));
3553 }
3554
3555 int
vfs_removename(const char * nameref)3556 vfs_removename(const char *nameref)
3557 {
3558 struct stringhead *head;
3559 string_t *entry;
3560 uint32_t hashval;
3561 uint32_t hash_index;
3562 uint32_t lock_index;
3563 int retval = ENOENT;
3564
3565 hashval = hash_string(nameref, 0);
3566
3567 /*
3568 * take this lock 'shared' to keep the hash stable
3569 * if someone else decides to grow the pool they
3570 * will take this lock exclusively
3571 */
3572 lck_rw_lock_shared(&strtable_rw_lock);
3573 /*
3574 * must compute the head behind the table lock
3575 * since the size and location of the table
3576 * can change on the fly
3577 */
3578 hash_index = hashval & string_table_mask;
3579 lock_index = hash_index % NUM_STRCACHE_LOCKS;
3580
3581 head = &string_ref_table[hash_index];
3582
3583 lck_mtx_lock_spin(&strcache_mtx_locks[lock_index]);
3584
3585 for (entry = head->lh_first; entry != NULL; entry = entry->hash_chain.le_next) {
3586 if (entry->str == nameref) {
3587 entry->refcount--;
3588
3589 if (entry->refcount == 0) {
3590 LIST_REMOVE(entry, hash_chain);
3591
3592 if (head->lh_first == NULL) {
3593 OSAddAtomic(-1, &filled_buckets);
3594 }
3595 } else {
3596 entry = NULL;
3597 }
3598 retval = 0;
3599 break;
3600 }
3601 }
3602 lck_mtx_unlock(&strcache_mtx_locks[lock_index]);
3603 lck_rw_done(&strtable_rw_lock);
3604
3605 if (entry) {
3606 assert(entry->refcount == 0);
3607 if (nc_smr_enabled) {
3608 zfree_smr(stringcache_zone, entry);
3609 } else {
3610 kfree_data(entry->str, entry->strbuflen);
3611 entry->str = NULL;
3612 entry->strbuflen = 0;
3613 zfree(stringcache_zone, entry);
3614 }
3615 }
3616
3617 return retval;
3618 }
3619
3620
3621 #ifdef DUMP_STRING_TABLE
3622 void
dump_string_table(void)3623 dump_string_table(void)
3624 {
3625 struct stringhead *head;
3626 string_t *entry;
3627 u_long i;
3628
3629 lck_rw_lock_shared(&strtable_rw_lock);
3630
3631 for (i = 0; i <= string_table_mask; i++) {
3632 head = &string_ref_table[i];
3633 for (entry = head->lh_first; entry != NULL; entry = entry->hash_chain.le_next) {
3634 printf("%6d - %s\n", entry->refcount, entry->str);
3635 }
3636 }
3637 lck_rw_done(&strtable_rw_lock);
3638 }
3639 #endif /* DUMP_STRING_TABLE */
3640