18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci * Copyright (C) 2017 Red Hat, Inc.
48c2ecf20Sopenharmony_ci */
58c2ecf20Sopenharmony_ci
68c2ecf20Sopenharmony_ci#include <linux/cred.h>
78c2ecf20Sopenharmony_ci#include <linux/file.h>
88c2ecf20Sopenharmony_ci#include <linux/mount.h>
98c2ecf20Sopenharmony_ci#include <linux/xattr.h>
108c2ecf20Sopenharmony_ci#include <linux/uio.h>
118c2ecf20Sopenharmony_ci#include <linux/uaccess.h>
128c2ecf20Sopenharmony_ci#include <linux/splice.h>
138c2ecf20Sopenharmony_ci#include <linux/security.h>
148c2ecf20Sopenharmony_ci#include <linux/mm.h>
158c2ecf20Sopenharmony_ci#include <linux/fs.h>
168c2ecf20Sopenharmony_ci#include "overlayfs.h"
178c2ecf20Sopenharmony_ci
188c2ecf20Sopenharmony_cistruct ovl_aio_req {
198c2ecf20Sopenharmony_ci	struct kiocb iocb;
208c2ecf20Sopenharmony_ci	refcount_t ref;
218c2ecf20Sopenharmony_ci	struct kiocb *orig_iocb;
228c2ecf20Sopenharmony_ci};
238c2ecf20Sopenharmony_ci
248c2ecf20Sopenharmony_cistatic struct kmem_cache *ovl_aio_request_cachep;
258c2ecf20Sopenharmony_ci
268c2ecf20Sopenharmony_cistatic char ovl_whatisit(struct inode *inode, struct inode *realinode)
278c2ecf20Sopenharmony_ci{
288c2ecf20Sopenharmony_ci	if (realinode != ovl_inode_upper(inode))
298c2ecf20Sopenharmony_ci		return 'l';
308c2ecf20Sopenharmony_ci	if (ovl_has_upperdata(inode))
318c2ecf20Sopenharmony_ci		return 'u';
328c2ecf20Sopenharmony_ci	else
338c2ecf20Sopenharmony_ci		return 'm';
348c2ecf20Sopenharmony_ci}
358c2ecf20Sopenharmony_ci
368c2ecf20Sopenharmony_ci/* No atime modificaton nor notify on underlying */
378c2ecf20Sopenharmony_ci#define OVL_OPEN_FLAGS (O_NOATIME | FMODE_NONOTIFY)
388c2ecf20Sopenharmony_ci
398c2ecf20Sopenharmony_cistatic struct file *ovl_open_realfile(const struct file *file,
408c2ecf20Sopenharmony_ci				      struct inode *realinode)
418c2ecf20Sopenharmony_ci{
428c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
438c2ecf20Sopenharmony_ci	struct file *realfile;
448c2ecf20Sopenharmony_ci	const struct cred *old_cred;
458c2ecf20Sopenharmony_ci	int flags = file->f_flags | OVL_OPEN_FLAGS;
468c2ecf20Sopenharmony_ci	int acc_mode = ACC_MODE(flags);
478c2ecf20Sopenharmony_ci	int err;
488c2ecf20Sopenharmony_ci
498c2ecf20Sopenharmony_ci	if (flags & O_APPEND)
508c2ecf20Sopenharmony_ci		acc_mode |= MAY_APPEND;
518c2ecf20Sopenharmony_ci
528c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(inode->i_sb);
538c2ecf20Sopenharmony_ci	err = inode_permission(realinode, MAY_OPEN | acc_mode);
548c2ecf20Sopenharmony_ci	if (err) {
558c2ecf20Sopenharmony_ci		realfile = ERR_PTR(err);
568c2ecf20Sopenharmony_ci	} else if (!inode_owner_or_capable(realinode)) {
578c2ecf20Sopenharmony_ci		realfile = ERR_PTR(-EPERM);
588c2ecf20Sopenharmony_ci	} else {
598c2ecf20Sopenharmony_ci		realfile = open_with_fake_path(&file->f_path, flags, realinode,
608c2ecf20Sopenharmony_ci					       current_cred());
618c2ecf20Sopenharmony_ci	}
628c2ecf20Sopenharmony_ci	revert_creds(old_cred);
638c2ecf20Sopenharmony_ci
648c2ecf20Sopenharmony_ci	pr_debug("open(%p[%pD2/%c], 0%o) -> (%p, 0%o)\n",
658c2ecf20Sopenharmony_ci		 file, file, ovl_whatisit(inode, realinode), file->f_flags,
668c2ecf20Sopenharmony_ci		 realfile, IS_ERR(realfile) ? 0 : realfile->f_flags);
678c2ecf20Sopenharmony_ci
688c2ecf20Sopenharmony_ci	return realfile;
698c2ecf20Sopenharmony_ci}
708c2ecf20Sopenharmony_ci
718c2ecf20Sopenharmony_ci#define OVL_SETFL_MASK (O_APPEND | O_NONBLOCK | O_NDELAY | O_DIRECT)
728c2ecf20Sopenharmony_ci
738c2ecf20Sopenharmony_cistatic int ovl_change_flags(struct file *file, unsigned int flags)
748c2ecf20Sopenharmony_ci{
758c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
768c2ecf20Sopenharmony_ci	int err;
778c2ecf20Sopenharmony_ci
788c2ecf20Sopenharmony_ci	flags |= OVL_OPEN_FLAGS;
798c2ecf20Sopenharmony_ci
808c2ecf20Sopenharmony_ci	/* If some flag changed that cannot be changed then something's amiss */
818c2ecf20Sopenharmony_ci	if (WARN_ON((file->f_flags ^ flags) & ~OVL_SETFL_MASK))
828c2ecf20Sopenharmony_ci		return -EIO;
838c2ecf20Sopenharmony_ci
848c2ecf20Sopenharmony_ci	flags &= OVL_SETFL_MASK;
858c2ecf20Sopenharmony_ci
868c2ecf20Sopenharmony_ci	if (((flags ^ file->f_flags) & O_APPEND) && IS_APPEND(inode))
878c2ecf20Sopenharmony_ci		return -EPERM;
888c2ecf20Sopenharmony_ci
898c2ecf20Sopenharmony_ci	if (flags & O_DIRECT) {
908c2ecf20Sopenharmony_ci		if (!file->f_mapping->a_ops ||
918c2ecf20Sopenharmony_ci		    !file->f_mapping->a_ops->direct_IO)
928c2ecf20Sopenharmony_ci			return -EINVAL;
938c2ecf20Sopenharmony_ci	}
948c2ecf20Sopenharmony_ci
958c2ecf20Sopenharmony_ci	if (file->f_op->check_flags) {
968c2ecf20Sopenharmony_ci		err = file->f_op->check_flags(flags);
978c2ecf20Sopenharmony_ci		if (err)
988c2ecf20Sopenharmony_ci			return err;
998c2ecf20Sopenharmony_ci	}
1008c2ecf20Sopenharmony_ci
1018c2ecf20Sopenharmony_ci	spin_lock(&file->f_lock);
1028c2ecf20Sopenharmony_ci	file->f_flags = (file->f_flags & ~OVL_SETFL_MASK) | flags;
1038c2ecf20Sopenharmony_ci	spin_unlock(&file->f_lock);
1048c2ecf20Sopenharmony_ci
1058c2ecf20Sopenharmony_ci	return 0;
1068c2ecf20Sopenharmony_ci}
1078c2ecf20Sopenharmony_ci
1088c2ecf20Sopenharmony_cistatic int ovl_real_fdget_meta(const struct file *file, struct fd *real,
1098c2ecf20Sopenharmony_ci			       bool allow_meta)
1108c2ecf20Sopenharmony_ci{
1118c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
1128c2ecf20Sopenharmony_ci	struct inode *realinode;
1138c2ecf20Sopenharmony_ci
1148c2ecf20Sopenharmony_ci	real->flags = 0;
1158c2ecf20Sopenharmony_ci	real->file = file->private_data;
1168c2ecf20Sopenharmony_ci
1178c2ecf20Sopenharmony_ci	if (allow_meta)
1188c2ecf20Sopenharmony_ci		realinode = ovl_inode_real(inode);
1198c2ecf20Sopenharmony_ci	else
1208c2ecf20Sopenharmony_ci		realinode = ovl_inode_realdata(inode);
1218c2ecf20Sopenharmony_ci
1228c2ecf20Sopenharmony_ci	/* Has it been copied up since we'd opened it? */
1238c2ecf20Sopenharmony_ci	if (unlikely(file_inode(real->file) != realinode)) {
1248c2ecf20Sopenharmony_ci		real->flags = FDPUT_FPUT;
1258c2ecf20Sopenharmony_ci		real->file = ovl_open_realfile(file, realinode);
1268c2ecf20Sopenharmony_ci
1278c2ecf20Sopenharmony_ci		return PTR_ERR_OR_ZERO(real->file);
1288c2ecf20Sopenharmony_ci	}
1298c2ecf20Sopenharmony_ci
1308c2ecf20Sopenharmony_ci	/* Did the flags change since open? */
1318c2ecf20Sopenharmony_ci	if (unlikely((file->f_flags ^ real->file->f_flags) & ~OVL_OPEN_FLAGS))
1328c2ecf20Sopenharmony_ci		return ovl_change_flags(real->file, file->f_flags);
1338c2ecf20Sopenharmony_ci
1348c2ecf20Sopenharmony_ci	return 0;
1358c2ecf20Sopenharmony_ci}
1368c2ecf20Sopenharmony_ci
1378c2ecf20Sopenharmony_cistatic int ovl_real_fdget(const struct file *file, struct fd *real)
1388c2ecf20Sopenharmony_ci{
1398c2ecf20Sopenharmony_ci	if (d_is_dir(file_dentry(file))) {
1408c2ecf20Sopenharmony_ci		real->flags = 0;
1418c2ecf20Sopenharmony_ci		real->file = ovl_dir_real_file(file, false);
1428c2ecf20Sopenharmony_ci
1438c2ecf20Sopenharmony_ci		return PTR_ERR_OR_ZERO(real->file);
1448c2ecf20Sopenharmony_ci	}
1458c2ecf20Sopenharmony_ci
1468c2ecf20Sopenharmony_ci	return ovl_real_fdget_meta(file, real, false);
1478c2ecf20Sopenharmony_ci}
1488c2ecf20Sopenharmony_ci
1498c2ecf20Sopenharmony_cistatic int ovl_open(struct inode *inode, struct file *file)
1508c2ecf20Sopenharmony_ci{
1518c2ecf20Sopenharmony_ci	struct file *realfile;
1528c2ecf20Sopenharmony_ci	int err;
1538c2ecf20Sopenharmony_ci
1548c2ecf20Sopenharmony_ci	err = ovl_maybe_copy_up(file_dentry(file), file->f_flags);
1558c2ecf20Sopenharmony_ci	if (err)
1568c2ecf20Sopenharmony_ci		return err;
1578c2ecf20Sopenharmony_ci
1588c2ecf20Sopenharmony_ci	/* No longer need these flags, so don't pass them on to underlying fs */
1598c2ecf20Sopenharmony_ci	file->f_flags &= ~(O_CREAT | O_EXCL | O_NOCTTY | O_TRUNC);
1608c2ecf20Sopenharmony_ci
1618c2ecf20Sopenharmony_ci	realfile = ovl_open_realfile(file, ovl_inode_realdata(inode));
1628c2ecf20Sopenharmony_ci	if (IS_ERR(realfile))
1638c2ecf20Sopenharmony_ci		return PTR_ERR(realfile);
1648c2ecf20Sopenharmony_ci
1658c2ecf20Sopenharmony_ci	file->private_data = realfile;
1668c2ecf20Sopenharmony_ci
1678c2ecf20Sopenharmony_ci	return 0;
1688c2ecf20Sopenharmony_ci}
1698c2ecf20Sopenharmony_ci
1708c2ecf20Sopenharmony_cistatic int ovl_release(struct inode *inode, struct file *file)
1718c2ecf20Sopenharmony_ci{
1728c2ecf20Sopenharmony_ci	fput(file->private_data);
1738c2ecf20Sopenharmony_ci
1748c2ecf20Sopenharmony_ci	return 0;
1758c2ecf20Sopenharmony_ci}
1768c2ecf20Sopenharmony_ci
1778c2ecf20Sopenharmony_cistatic loff_t ovl_llseek(struct file *file, loff_t offset, int whence)
1788c2ecf20Sopenharmony_ci{
1798c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
1808c2ecf20Sopenharmony_ci	struct fd real;
1818c2ecf20Sopenharmony_ci	const struct cred *old_cred;
1828c2ecf20Sopenharmony_ci	loff_t ret;
1838c2ecf20Sopenharmony_ci
1848c2ecf20Sopenharmony_ci	/*
1858c2ecf20Sopenharmony_ci	 * The two special cases below do not need to involve real fs,
1868c2ecf20Sopenharmony_ci	 * so we can optimizing concurrent callers.
1878c2ecf20Sopenharmony_ci	 */
1888c2ecf20Sopenharmony_ci	if (offset == 0) {
1898c2ecf20Sopenharmony_ci		if (whence == SEEK_CUR)
1908c2ecf20Sopenharmony_ci			return file->f_pos;
1918c2ecf20Sopenharmony_ci
1928c2ecf20Sopenharmony_ci		if (whence == SEEK_SET)
1938c2ecf20Sopenharmony_ci			return vfs_setpos(file, 0, 0);
1948c2ecf20Sopenharmony_ci	}
1958c2ecf20Sopenharmony_ci
1968c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
1978c2ecf20Sopenharmony_ci	if (ret)
1988c2ecf20Sopenharmony_ci		return ret;
1998c2ecf20Sopenharmony_ci
2008c2ecf20Sopenharmony_ci	/*
2018c2ecf20Sopenharmony_ci	 * Overlay file f_pos is the master copy that is preserved
2028c2ecf20Sopenharmony_ci	 * through copy up and modified on read/write, but only real
2038c2ecf20Sopenharmony_ci	 * fs knows how to SEEK_HOLE/SEEK_DATA and real fs may impose
2048c2ecf20Sopenharmony_ci	 * limitations that are more strict than ->s_maxbytes for specific
2058c2ecf20Sopenharmony_ci	 * files, so we use the real file to perform seeks.
2068c2ecf20Sopenharmony_ci	 */
2078c2ecf20Sopenharmony_ci	ovl_inode_lock(inode);
2088c2ecf20Sopenharmony_ci	real.file->f_pos = file->f_pos;
2098c2ecf20Sopenharmony_ci
2108c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(inode->i_sb);
2118c2ecf20Sopenharmony_ci	ret = vfs_llseek(real.file, offset, whence);
2128c2ecf20Sopenharmony_ci	revert_creds(old_cred);
2138c2ecf20Sopenharmony_ci
2148c2ecf20Sopenharmony_ci	file->f_pos = real.file->f_pos;
2158c2ecf20Sopenharmony_ci	ovl_inode_unlock(inode);
2168c2ecf20Sopenharmony_ci
2178c2ecf20Sopenharmony_ci	fdput(real);
2188c2ecf20Sopenharmony_ci
2198c2ecf20Sopenharmony_ci	return ret;
2208c2ecf20Sopenharmony_ci}
2218c2ecf20Sopenharmony_ci
2228c2ecf20Sopenharmony_cistatic void ovl_file_accessed(struct file *file)
2238c2ecf20Sopenharmony_ci{
2248c2ecf20Sopenharmony_ci	struct inode *inode, *upperinode;
2258c2ecf20Sopenharmony_ci
2268c2ecf20Sopenharmony_ci	if (file->f_flags & O_NOATIME)
2278c2ecf20Sopenharmony_ci		return;
2288c2ecf20Sopenharmony_ci
2298c2ecf20Sopenharmony_ci	inode = file_inode(file);
2308c2ecf20Sopenharmony_ci	upperinode = ovl_inode_upper(inode);
2318c2ecf20Sopenharmony_ci
2328c2ecf20Sopenharmony_ci	if (!upperinode)
2338c2ecf20Sopenharmony_ci		return;
2348c2ecf20Sopenharmony_ci
2358c2ecf20Sopenharmony_ci	if ((!timespec64_equal(&inode->i_mtime, &upperinode->i_mtime) ||
2368c2ecf20Sopenharmony_ci	     !timespec64_equal(&inode->i_ctime, &upperinode->i_ctime))) {
2378c2ecf20Sopenharmony_ci		inode->i_mtime = upperinode->i_mtime;
2388c2ecf20Sopenharmony_ci		inode->i_ctime = upperinode->i_ctime;
2398c2ecf20Sopenharmony_ci	}
2408c2ecf20Sopenharmony_ci
2418c2ecf20Sopenharmony_ci	touch_atime(&file->f_path);
2428c2ecf20Sopenharmony_ci}
2438c2ecf20Sopenharmony_ci
2448c2ecf20Sopenharmony_cistatic rwf_t ovl_iocb_to_rwf(int ifl)
2458c2ecf20Sopenharmony_ci{
2468c2ecf20Sopenharmony_ci	rwf_t flags = 0;
2478c2ecf20Sopenharmony_ci
2488c2ecf20Sopenharmony_ci	if (ifl & IOCB_NOWAIT)
2498c2ecf20Sopenharmony_ci		flags |= RWF_NOWAIT;
2508c2ecf20Sopenharmony_ci	if (ifl & IOCB_HIPRI)
2518c2ecf20Sopenharmony_ci		flags |= RWF_HIPRI;
2528c2ecf20Sopenharmony_ci	if (ifl & IOCB_DSYNC)
2538c2ecf20Sopenharmony_ci		flags |= RWF_DSYNC;
2548c2ecf20Sopenharmony_ci	if (ifl & IOCB_SYNC)
2558c2ecf20Sopenharmony_ci		flags |= RWF_SYNC;
2568c2ecf20Sopenharmony_ci
2578c2ecf20Sopenharmony_ci	return flags;
2588c2ecf20Sopenharmony_ci}
2598c2ecf20Sopenharmony_ci
2608c2ecf20Sopenharmony_cistatic inline void ovl_aio_put(struct ovl_aio_req *aio_req)
2618c2ecf20Sopenharmony_ci{
2628c2ecf20Sopenharmony_ci	if (refcount_dec_and_test(&aio_req->ref)) {
2638c2ecf20Sopenharmony_ci		fput(aio_req->iocb.ki_filp);
2648c2ecf20Sopenharmony_ci		kmem_cache_free(ovl_aio_request_cachep, aio_req);
2658c2ecf20Sopenharmony_ci	}
2668c2ecf20Sopenharmony_ci}
2678c2ecf20Sopenharmony_ci
2688c2ecf20Sopenharmony_cistatic void ovl_aio_cleanup_handler(struct ovl_aio_req *aio_req)
2698c2ecf20Sopenharmony_ci{
2708c2ecf20Sopenharmony_ci	struct kiocb *iocb = &aio_req->iocb;
2718c2ecf20Sopenharmony_ci	struct kiocb *orig_iocb = aio_req->orig_iocb;
2728c2ecf20Sopenharmony_ci
2738c2ecf20Sopenharmony_ci	if (iocb->ki_flags & IOCB_WRITE) {
2748c2ecf20Sopenharmony_ci		struct inode *inode = file_inode(orig_iocb->ki_filp);
2758c2ecf20Sopenharmony_ci
2768c2ecf20Sopenharmony_ci		/* Actually acquired in ovl_write_iter() */
2778c2ecf20Sopenharmony_ci		__sb_writers_acquired(file_inode(iocb->ki_filp)->i_sb,
2788c2ecf20Sopenharmony_ci				      SB_FREEZE_WRITE);
2798c2ecf20Sopenharmony_ci		file_end_write(iocb->ki_filp);
2808c2ecf20Sopenharmony_ci		ovl_copyattr(ovl_inode_real(inode), inode);
2818c2ecf20Sopenharmony_ci	}
2828c2ecf20Sopenharmony_ci
2838c2ecf20Sopenharmony_ci	orig_iocb->ki_pos = iocb->ki_pos;
2848c2ecf20Sopenharmony_ci	ovl_aio_put(aio_req);
2858c2ecf20Sopenharmony_ci}
2868c2ecf20Sopenharmony_ci
2878c2ecf20Sopenharmony_cistatic void ovl_aio_rw_complete(struct kiocb *iocb, long res, long res2)
2888c2ecf20Sopenharmony_ci{
2898c2ecf20Sopenharmony_ci	struct ovl_aio_req *aio_req = container_of(iocb,
2908c2ecf20Sopenharmony_ci						   struct ovl_aio_req, iocb);
2918c2ecf20Sopenharmony_ci	struct kiocb *orig_iocb = aio_req->orig_iocb;
2928c2ecf20Sopenharmony_ci
2938c2ecf20Sopenharmony_ci	ovl_aio_cleanup_handler(aio_req);
2948c2ecf20Sopenharmony_ci	orig_iocb->ki_complete(orig_iocb, res, res2);
2958c2ecf20Sopenharmony_ci}
2968c2ecf20Sopenharmony_ci
2978c2ecf20Sopenharmony_cistatic ssize_t ovl_read_iter(struct kiocb *iocb, struct iov_iter *iter)
2988c2ecf20Sopenharmony_ci{
2998c2ecf20Sopenharmony_ci	struct file *file = iocb->ki_filp;
3008c2ecf20Sopenharmony_ci	struct fd real;
3018c2ecf20Sopenharmony_ci	const struct cred *old_cred;
3028c2ecf20Sopenharmony_ci	ssize_t ret;
3038c2ecf20Sopenharmony_ci
3048c2ecf20Sopenharmony_ci	if (!iov_iter_count(iter))
3058c2ecf20Sopenharmony_ci		return 0;
3068c2ecf20Sopenharmony_ci
3078c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
3088c2ecf20Sopenharmony_ci	if (ret)
3098c2ecf20Sopenharmony_ci		return ret;
3108c2ecf20Sopenharmony_ci
3118c2ecf20Sopenharmony_ci	ret = -EINVAL;
3128c2ecf20Sopenharmony_ci	if (iocb->ki_flags & IOCB_DIRECT &&
3138c2ecf20Sopenharmony_ci	    (!real.file->f_mapping->a_ops ||
3148c2ecf20Sopenharmony_ci	     !real.file->f_mapping->a_ops->direct_IO))
3158c2ecf20Sopenharmony_ci		goto out_fdput;
3168c2ecf20Sopenharmony_ci
3178c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file)->i_sb);
3188c2ecf20Sopenharmony_ci	if (is_sync_kiocb(iocb)) {
3198c2ecf20Sopenharmony_ci		ret = vfs_iter_read(real.file, iter, &iocb->ki_pos,
3208c2ecf20Sopenharmony_ci				    ovl_iocb_to_rwf(iocb->ki_flags));
3218c2ecf20Sopenharmony_ci	} else {
3228c2ecf20Sopenharmony_ci		struct ovl_aio_req *aio_req;
3238c2ecf20Sopenharmony_ci
3248c2ecf20Sopenharmony_ci		ret = -ENOMEM;
3258c2ecf20Sopenharmony_ci		aio_req = kmem_cache_zalloc(ovl_aio_request_cachep, GFP_KERNEL);
3268c2ecf20Sopenharmony_ci		if (!aio_req)
3278c2ecf20Sopenharmony_ci			goto out;
3288c2ecf20Sopenharmony_ci
3298c2ecf20Sopenharmony_ci		real.flags = 0;
3308c2ecf20Sopenharmony_ci		aio_req->orig_iocb = iocb;
3318c2ecf20Sopenharmony_ci		kiocb_clone(&aio_req->iocb, iocb, get_file(real.file));
3328c2ecf20Sopenharmony_ci		aio_req->iocb.ki_complete = ovl_aio_rw_complete;
3338c2ecf20Sopenharmony_ci		refcount_set(&aio_req->ref, 2);
3348c2ecf20Sopenharmony_ci		ret = vfs_iocb_iter_read(real.file, &aio_req->iocb, iter);
3358c2ecf20Sopenharmony_ci		ovl_aio_put(aio_req);
3368c2ecf20Sopenharmony_ci		if (ret != -EIOCBQUEUED)
3378c2ecf20Sopenharmony_ci			ovl_aio_cleanup_handler(aio_req);
3388c2ecf20Sopenharmony_ci	}
3398c2ecf20Sopenharmony_ciout:
3408c2ecf20Sopenharmony_ci	revert_creds(old_cred);
3418c2ecf20Sopenharmony_ci	ovl_file_accessed(file);
3428c2ecf20Sopenharmony_ciout_fdput:
3438c2ecf20Sopenharmony_ci	fdput(real);
3448c2ecf20Sopenharmony_ci
3458c2ecf20Sopenharmony_ci	return ret;
3468c2ecf20Sopenharmony_ci}
3478c2ecf20Sopenharmony_ci
3488c2ecf20Sopenharmony_cistatic ssize_t ovl_write_iter(struct kiocb *iocb, struct iov_iter *iter)
3498c2ecf20Sopenharmony_ci{
3508c2ecf20Sopenharmony_ci	struct file *file = iocb->ki_filp;
3518c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
3528c2ecf20Sopenharmony_ci	struct fd real;
3538c2ecf20Sopenharmony_ci	const struct cred *old_cred;
3548c2ecf20Sopenharmony_ci	ssize_t ret;
3558c2ecf20Sopenharmony_ci	int ifl = iocb->ki_flags;
3568c2ecf20Sopenharmony_ci
3578c2ecf20Sopenharmony_ci	if (!iov_iter_count(iter))
3588c2ecf20Sopenharmony_ci		return 0;
3598c2ecf20Sopenharmony_ci
3608c2ecf20Sopenharmony_ci	inode_lock(inode);
3618c2ecf20Sopenharmony_ci	/* Update mode */
3628c2ecf20Sopenharmony_ci	ovl_copyattr(ovl_inode_real(inode), inode);
3638c2ecf20Sopenharmony_ci	ret = file_remove_privs(file);
3648c2ecf20Sopenharmony_ci	if (ret)
3658c2ecf20Sopenharmony_ci		goto out_unlock;
3668c2ecf20Sopenharmony_ci
3678c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
3688c2ecf20Sopenharmony_ci	if (ret)
3698c2ecf20Sopenharmony_ci		goto out_unlock;
3708c2ecf20Sopenharmony_ci
3718c2ecf20Sopenharmony_ci	ret = -EINVAL;
3728c2ecf20Sopenharmony_ci	if (iocb->ki_flags & IOCB_DIRECT &&
3738c2ecf20Sopenharmony_ci	    (!real.file->f_mapping->a_ops ||
3748c2ecf20Sopenharmony_ci	     !real.file->f_mapping->a_ops->direct_IO))
3758c2ecf20Sopenharmony_ci		goto out_fdput;
3768c2ecf20Sopenharmony_ci
3778c2ecf20Sopenharmony_ci	if (!ovl_should_sync(OVL_FS(inode->i_sb)))
3788c2ecf20Sopenharmony_ci		ifl &= ~(IOCB_DSYNC | IOCB_SYNC);
3798c2ecf20Sopenharmony_ci
3808c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file)->i_sb);
3818c2ecf20Sopenharmony_ci	if (is_sync_kiocb(iocb)) {
3828c2ecf20Sopenharmony_ci		file_start_write(real.file);
3838c2ecf20Sopenharmony_ci		ret = vfs_iter_write(real.file, iter, &iocb->ki_pos,
3848c2ecf20Sopenharmony_ci				     ovl_iocb_to_rwf(ifl));
3858c2ecf20Sopenharmony_ci		file_end_write(real.file);
3868c2ecf20Sopenharmony_ci		/* Update size */
3878c2ecf20Sopenharmony_ci		ovl_copyattr(ovl_inode_real(inode), inode);
3888c2ecf20Sopenharmony_ci	} else {
3898c2ecf20Sopenharmony_ci		struct ovl_aio_req *aio_req;
3908c2ecf20Sopenharmony_ci
3918c2ecf20Sopenharmony_ci		ret = -ENOMEM;
3928c2ecf20Sopenharmony_ci		aio_req = kmem_cache_zalloc(ovl_aio_request_cachep, GFP_KERNEL);
3938c2ecf20Sopenharmony_ci		if (!aio_req)
3948c2ecf20Sopenharmony_ci			goto out;
3958c2ecf20Sopenharmony_ci
3968c2ecf20Sopenharmony_ci		file_start_write(real.file);
3978c2ecf20Sopenharmony_ci		/* Pacify lockdep, same trick as done in aio_write() */
3988c2ecf20Sopenharmony_ci		__sb_writers_release(file_inode(real.file)->i_sb,
3998c2ecf20Sopenharmony_ci				     SB_FREEZE_WRITE);
4008c2ecf20Sopenharmony_ci		real.flags = 0;
4018c2ecf20Sopenharmony_ci		aio_req->orig_iocb = iocb;
4028c2ecf20Sopenharmony_ci		kiocb_clone(&aio_req->iocb, iocb, get_file(real.file));
4038c2ecf20Sopenharmony_ci		aio_req->iocb.ki_flags = ifl;
4048c2ecf20Sopenharmony_ci		aio_req->iocb.ki_complete = ovl_aio_rw_complete;
4058c2ecf20Sopenharmony_ci		refcount_set(&aio_req->ref, 2);
4068c2ecf20Sopenharmony_ci		ret = vfs_iocb_iter_write(real.file, &aio_req->iocb, iter);
4078c2ecf20Sopenharmony_ci		ovl_aio_put(aio_req);
4088c2ecf20Sopenharmony_ci		if (ret != -EIOCBQUEUED)
4098c2ecf20Sopenharmony_ci			ovl_aio_cleanup_handler(aio_req);
4108c2ecf20Sopenharmony_ci	}
4118c2ecf20Sopenharmony_ciout:
4128c2ecf20Sopenharmony_ci	revert_creds(old_cred);
4138c2ecf20Sopenharmony_ciout_fdput:
4148c2ecf20Sopenharmony_ci	fdput(real);
4158c2ecf20Sopenharmony_ci
4168c2ecf20Sopenharmony_ciout_unlock:
4178c2ecf20Sopenharmony_ci	inode_unlock(inode);
4188c2ecf20Sopenharmony_ci
4198c2ecf20Sopenharmony_ci	return ret;
4208c2ecf20Sopenharmony_ci}
4218c2ecf20Sopenharmony_ci
4228c2ecf20Sopenharmony_ci/*
4238c2ecf20Sopenharmony_ci * Calling iter_file_splice_write() directly from overlay's f_op may deadlock
4248c2ecf20Sopenharmony_ci * due to lock order inversion between pipe->mutex in iter_file_splice_write()
4258c2ecf20Sopenharmony_ci * and file_start_write(real.file) in ovl_write_iter().
4268c2ecf20Sopenharmony_ci *
4278c2ecf20Sopenharmony_ci * So do everything ovl_write_iter() does and call iter_file_splice_write() on
4288c2ecf20Sopenharmony_ci * the real file.
4298c2ecf20Sopenharmony_ci */
4308c2ecf20Sopenharmony_cistatic ssize_t ovl_splice_write(struct pipe_inode_info *pipe, struct file *out,
4318c2ecf20Sopenharmony_ci				loff_t *ppos, size_t len, unsigned int flags)
4328c2ecf20Sopenharmony_ci{
4338c2ecf20Sopenharmony_ci	struct fd real;
4348c2ecf20Sopenharmony_ci	const struct cred *old_cred;
4358c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(out);
4368c2ecf20Sopenharmony_ci	struct inode *realinode = ovl_inode_real(inode);
4378c2ecf20Sopenharmony_ci	ssize_t ret;
4388c2ecf20Sopenharmony_ci
4398c2ecf20Sopenharmony_ci	inode_lock(inode);
4408c2ecf20Sopenharmony_ci	/* Update mode */
4418c2ecf20Sopenharmony_ci	ovl_copyattr(realinode, inode);
4428c2ecf20Sopenharmony_ci	ret = file_remove_privs(out);
4438c2ecf20Sopenharmony_ci	if (ret)
4448c2ecf20Sopenharmony_ci		goto out_unlock;
4458c2ecf20Sopenharmony_ci
4468c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(out, &real);
4478c2ecf20Sopenharmony_ci	if (ret)
4488c2ecf20Sopenharmony_ci		goto out_unlock;
4498c2ecf20Sopenharmony_ci
4508c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(inode->i_sb);
4518c2ecf20Sopenharmony_ci	file_start_write(real.file);
4528c2ecf20Sopenharmony_ci
4538c2ecf20Sopenharmony_ci	ret = iter_file_splice_write(pipe, real.file, ppos, len, flags);
4548c2ecf20Sopenharmony_ci
4558c2ecf20Sopenharmony_ci	file_end_write(real.file);
4568c2ecf20Sopenharmony_ci	/* Update size */
4578c2ecf20Sopenharmony_ci	ovl_copyattr(realinode, inode);
4588c2ecf20Sopenharmony_ci	revert_creds(old_cred);
4598c2ecf20Sopenharmony_ci	fdput(real);
4608c2ecf20Sopenharmony_ci
4618c2ecf20Sopenharmony_ciout_unlock:
4628c2ecf20Sopenharmony_ci	inode_unlock(inode);
4638c2ecf20Sopenharmony_ci
4648c2ecf20Sopenharmony_ci	return ret;
4658c2ecf20Sopenharmony_ci}
4668c2ecf20Sopenharmony_ci
4678c2ecf20Sopenharmony_cistatic int ovl_fsync(struct file *file, loff_t start, loff_t end, int datasync)
4688c2ecf20Sopenharmony_ci{
4698c2ecf20Sopenharmony_ci	struct fd real;
4708c2ecf20Sopenharmony_ci	const struct cred *old_cred;
4718c2ecf20Sopenharmony_ci	int ret;
4728c2ecf20Sopenharmony_ci
4738c2ecf20Sopenharmony_ci	ret = ovl_sync_status(OVL_FS(file_inode(file)->i_sb));
4748c2ecf20Sopenharmony_ci	if (ret <= 0)
4758c2ecf20Sopenharmony_ci		return ret;
4768c2ecf20Sopenharmony_ci
4778c2ecf20Sopenharmony_ci	ret = ovl_real_fdget_meta(file, &real, !datasync);
4788c2ecf20Sopenharmony_ci	if (ret)
4798c2ecf20Sopenharmony_ci		return ret;
4808c2ecf20Sopenharmony_ci
4818c2ecf20Sopenharmony_ci	/* Don't sync lower file for fear of receiving EROFS error */
4828c2ecf20Sopenharmony_ci	if (file_inode(real.file) == ovl_inode_upper(file_inode(file))) {
4838c2ecf20Sopenharmony_ci		old_cred = ovl_override_creds(file_inode(file)->i_sb);
4848c2ecf20Sopenharmony_ci		ret = vfs_fsync_range(real.file, start, end, datasync);
4858c2ecf20Sopenharmony_ci		revert_creds(old_cred);
4868c2ecf20Sopenharmony_ci	}
4878c2ecf20Sopenharmony_ci
4888c2ecf20Sopenharmony_ci	fdput(real);
4898c2ecf20Sopenharmony_ci
4908c2ecf20Sopenharmony_ci	return ret;
4918c2ecf20Sopenharmony_ci}
4928c2ecf20Sopenharmony_ci
4938c2ecf20Sopenharmony_cistatic int ovl_mmap(struct file *file, struct vm_area_struct *vma)
4948c2ecf20Sopenharmony_ci{
4958c2ecf20Sopenharmony_ci	struct file *realfile = file->private_data;
4968c2ecf20Sopenharmony_ci	const struct cred *old_cred;
4978c2ecf20Sopenharmony_ci	int ret;
4988c2ecf20Sopenharmony_ci
4998c2ecf20Sopenharmony_ci	if (!realfile->f_op->mmap)
5008c2ecf20Sopenharmony_ci		return -ENODEV;
5018c2ecf20Sopenharmony_ci
5028c2ecf20Sopenharmony_ci	if (WARN_ON(file != vma->vm_file))
5038c2ecf20Sopenharmony_ci		return -EIO;
5048c2ecf20Sopenharmony_ci
5058c2ecf20Sopenharmony_ci	vma->vm_file = get_file(realfile);
5068c2ecf20Sopenharmony_ci
5078c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file)->i_sb);
5088c2ecf20Sopenharmony_ci	ret = call_mmap(vma->vm_file, vma);
5098c2ecf20Sopenharmony_ci	revert_creds(old_cred);
5108c2ecf20Sopenharmony_ci
5118c2ecf20Sopenharmony_ci	if (ret) {
5128c2ecf20Sopenharmony_ci		/* Drop reference count from new vm_file value */
5138c2ecf20Sopenharmony_ci		fput(realfile);
5148c2ecf20Sopenharmony_ci	} else {
5158c2ecf20Sopenharmony_ci		/* Drop reference count from previous vm_file value */
5168c2ecf20Sopenharmony_ci		fput(file);
5178c2ecf20Sopenharmony_ci	}
5188c2ecf20Sopenharmony_ci
5198c2ecf20Sopenharmony_ci	ovl_file_accessed(file);
5208c2ecf20Sopenharmony_ci
5218c2ecf20Sopenharmony_ci	return ret;
5228c2ecf20Sopenharmony_ci}
5238c2ecf20Sopenharmony_ci
5248c2ecf20Sopenharmony_cistatic long ovl_fallocate(struct file *file, int mode, loff_t offset, loff_t len)
5258c2ecf20Sopenharmony_ci{
5268c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
5278c2ecf20Sopenharmony_ci	struct fd real;
5288c2ecf20Sopenharmony_ci	const struct cred *old_cred;
5298c2ecf20Sopenharmony_ci	int ret;
5308c2ecf20Sopenharmony_ci
5318c2ecf20Sopenharmony_ci	inode_lock(inode);
5328c2ecf20Sopenharmony_ci	/* Update mode */
5338c2ecf20Sopenharmony_ci	ovl_copyattr(ovl_inode_real(inode), inode);
5348c2ecf20Sopenharmony_ci	ret = file_remove_privs(file);
5358c2ecf20Sopenharmony_ci	if (ret)
5368c2ecf20Sopenharmony_ci		goto out_unlock;
5378c2ecf20Sopenharmony_ci
5388c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
5398c2ecf20Sopenharmony_ci	if (ret)
5408c2ecf20Sopenharmony_ci		goto out_unlock;
5418c2ecf20Sopenharmony_ci
5428c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file)->i_sb);
5438c2ecf20Sopenharmony_ci	ret = vfs_fallocate(real.file, mode, offset, len);
5448c2ecf20Sopenharmony_ci	revert_creds(old_cred);
5458c2ecf20Sopenharmony_ci
5468c2ecf20Sopenharmony_ci	/* Update size */
5478c2ecf20Sopenharmony_ci	ovl_copyattr(ovl_inode_real(inode), inode);
5488c2ecf20Sopenharmony_ci
5498c2ecf20Sopenharmony_ci	fdput(real);
5508c2ecf20Sopenharmony_ci
5518c2ecf20Sopenharmony_ciout_unlock:
5528c2ecf20Sopenharmony_ci	inode_unlock(inode);
5538c2ecf20Sopenharmony_ci
5548c2ecf20Sopenharmony_ci	return ret;
5558c2ecf20Sopenharmony_ci}
5568c2ecf20Sopenharmony_ci
5578c2ecf20Sopenharmony_cistatic int ovl_fadvise(struct file *file, loff_t offset, loff_t len, int advice)
5588c2ecf20Sopenharmony_ci{
5598c2ecf20Sopenharmony_ci	struct fd real;
5608c2ecf20Sopenharmony_ci	const struct cred *old_cred;
5618c2ecf20Sopenharmony_ci	int ret;
5628c2ecf20Sopenharmony_ci
5638c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
5648c2ecf20Sopenharmony_ci	if (ret)
5658c2ecf20Sopenharmony_ci		return ret;
5668c2ecf20Sopenharmony_ci
5678c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file)->i_sb);
5688c2ecf20Sopenharmony_ci	ret = vfs_fadvise(real.file, offset, len, advice);
5698c2ecf20Sopenharmony_ci	revert_creds(old_cred);
5708c2ecf20Sopenharmony_ci
5718c2ecf20Sopenharmony_ci	fdput(real);
5728c2ecf20Sopenharmony_ci
5738c2ecf20Sopenharmony_ci	return ret;
5748c2ecf20Sopenharmony_ci}
5758c2ecf20Sopenharmony_ci
5768c2ecf20Sopenharmony_cistatic long ovl_real_ioctl(struct file *file, unsigned int cmd,
5778c2ecf20Sopenharmony_ci			   unsigned long arg)
5788c2ecf20Sopenharmony_ci{
5798c2ecf20Sopenharmony_ci	struct fd real;
5808c2ecf20Sopenharmony_ci	long ret;
5818c2ecf20Sopenharmony_ci
5828c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file, &real);
5838c2ecf20Sopenharmony_ci	if (ret)
5848c2ecf20Sopenharmony_ci		return ret;
5858c2ecf20Sopenharmony_ci
5868c2ecf20Sopenharmony_ci	ret = security_file_ioctl(real.file, cmd, arg);
5878c2ecf20Sopenharmony_ci	if (!ret) {
5888c2ecf20Sopenharmony_ci		/*
5898c2ecf20Sopenharmony_ci		 * Don't override creds, since we currently can't safely check
5908c2ecf20Sopenharmony_ci		 * permissions before doing so.
5918c2ecf20Sopenharmony_ci		 */
5928c2ecf20Sopenharmony_ci		ret = vfs_ioctl(real.file, cmd, arg);
5938c2ecf20Sopenharmony_ci	}
5948c2ecf20Sopenharmony_ci
5958c2ecf20Sopenharmony_ci	fdput(real);
5968c2ecf20Sopenharmony_ci
5978c2ecf20Sopenharmony_ci	return ret;
5988c2ecf20Sopenharmony_ci}
5998c2ecf20Sopenharmony_ci
6008c2ecf20Sopenharmony_cistatic long ovl_ioctl_set_flags(struct file *file, unsigned int cmd,
6018c2ecf20Sopenharmony_ci				unsigned long arg)
6028c2ecf20Sopenharmony_ci{
6038c2ecf20Sopenharmony_ci	long ret;
6048c2ecf20Sopenharmony_ci	struct inode *inode = file_inode(file);
6058c2ecf20Sopenharmony_ci
6068c2ecf20Sopenharmony_ci	if (!inode_owner_or_capable(inode))
6078c2ecf20Sopenharmony_ci		return -EACCES;
6088c2ecf20Sopenharmony_ci
6098c2ecf20Sopenharmony_ci	ret = mnt_want_write_file(file);
6108c2ecf20Sopenharmony_ci	if (ret)
6118c2ecf20Sopenharmony_ci		return ret;
6128c2ecf20Sopenharmony_ci
6138c2ecf20Sopenharmony_ci	inode_lock(inode);
6148c2ecf20Sopenharmony_ci
6158c2ecf20Sopenharmony_ci	/*
6168c2ecf20Sopenharmony_ci	 * Prevent copy up if immutable and has no CAP_LINUX_IMMUTABLE
6178c2ecf20Sopenharmony_ci	 * capability.
6188c2ecf20Sopenharmony_ci	 */
6198c2ecf20Sopenharmony_ci	ret = -EPERM;
6208c2ecf20Sopenharmony_ci	if (!ovl_has_upperdata(inode) && IS_IMMUTABLE(inode) &&
6218c2ecf20Sopenharmony_ci	    !capable(CAP_LINUX_IMMUTABLE))
6228c2ecf20Sopenharmony_ci		goto unlock;
6238c2ecf20Sopenharmony_ci
6248c2ecf20Sopenharmony_ci	ret = ovl_maybe_copy_up(file_dentry(file), O_WRONLY);
6258c2ecf20Sopenharmony_ci	if (ret)
6268c2ecf20Sopenharmony_ci		goto unlock;
6278c2ecf20Sopenharmony_ci
6288c2ecf20Sopenharmony_ci	ret = ovl_real_ioctl(file, cmd, arg);
6298c2ecf20Sopenharmony_ci
6308c2ecf20Sopenharmony_ci	ovl_copyflags(ovl_inode_real(inode), inode);
6318c2ecf20Sopenharmony_ciunlock:
6328c2ecf20Sopenharmony_ci	inode_unlock(inode);
6338c2ecf20Sopenharmony_ci
6348c2ecf20Sopenharmony_ci	mnt_drop_write_file(file);
6358c2ecf20Sopenharmony_ci
6368c2ecf20Sopenharmony_ci	return ret;
6378c2ecf20Sopenharmony_ci
6388c2ecf20Sopenharmony_ci}
6398c2ecf20Sopenharmony_ci
6408c2ecf20Sopenharmony_cilong ovl_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
6418c2ecf20Sopenharmony_ci{
6428c2ecf20Sopenharmony_ci	long ret;
6438c2ecf20Sopenharmony_ci
6448c2ecf20Sopenharmony_ci	switch (cmd) {
6458c2ecf20Sopenharmony_ci	case FS_IOC_GETFLAGS:
6468c2ecf20Sopenharmony_ci	case FS_IOC_FSGETXATTR:
6478c2ecf20Sopenharmony_ci		ret = ovl_real_ioctl(file, cmd, arg);
6488c2ecf20Sopenharmony_ci		break;
6498c2ecf20Sopenharmony_ci
6508c2ecf20Sopenharmony_ci	case FS_IOC_FSSETXATTR:
6518c2ecf20Sopenharmony_ci	case FS_IOC_SETFLAGS:
6528c2ecf20Sopenharmony_ci		ret = ovl_ioctl_set_flags(file, cmd, arg);
6538c2ecf20Sopenharmony_ci		break;
6548c2ecf20Sopenharmony_ci
6558c2ecf20Sopenharmony_ci	default:
6568c2ecf20Sopenharmony_ci		ret = -ENOTTY;
6578c2ecf20Sopenharmony_ci	}
6588c2ecf20Sopenharmony_ci
6598c2ecf20Sopenharmony_ci	return ret;
6608c2ecf20Sopenharmony_ci}
6618c2ecf20Sopenharmony_ci
6628c2ecf20Sopenharmony_ci#ifdef CONFIG_COMPAT
6638c2ecf20Sopenharmony_cilong ovl_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
6648c2ecf20Sopenharmony_ci{
6658c2ecf20Sopenharmony_ci	switch (cmd) {
6668c2ecf20Sopenharmony_ci	case FS_IOC32_GETFLAGS:
6678c2ecf20Sopenharmony_ci		cmd = FS_IOC_GETFLAGS;
6688c2ecf20Sopenharmony_ci		break;
6698c2ecf20Sopenharmony_ci
6708c2ecf20Sopenharmony_ci	case FS_IOC32_SETFLAGS:
6718c2ecf20Sopenharmony_ci		cmd = FS_IOC_SETFLAGS;
6728c2ecf20Sopenharmony_ci		break;
6738c2ecf20Sopenharmony_ci
6748c2ecf20Sopenharmony_ci	default:
6758c2ecf20Sopenharmony_ci		return -ENOIOCTLCMD;
6768c2ecf20Sopenharmony_ci	}
6778c2ecf20Sopenharmony_ci
6788c2ecf20Sopenharmony_ci	return ovl_ioctl(file, cmd, arg);
6798c2ecf20Sopenharmony_ci}
6808c2ecf20Sopenharmony_ci#endif
6818c2ecf20Sopenharmony_ci
6828c2ecf20Sopenharmony_cienum ovl_copyop {
6838c2ecf20Sopenharmony_ci	OVL_COPY,
6848c2ecf20Sopenharmony_ci	OVL_CLONE,
6858c2ecf20Sopenharmony_ci	OVL_DEDUPE,
6868c2ecf20Sopenharmony_ci};
6878c2ecf20Sopenharmony_ci
6888c2ecf20Sopenharmony_cistatic loff_t ovl_copyfile(struct file *file_in, loff_t pos_in,
6898c2ecf20Sopenharmony_ci			    struct file *file_out, loff_t pos_out,
6908c2ecf20Sopenharmony_ci			    loff_t len, unsigned int flags, enum ovl_copyop op)
6918c2ecf20Sopenharmony_ci{
6928c2ecf20Sopenharmony_ci	struct inode *inode_out = file_inode(file_out);
6938c2ecf20Sopenharmony_ci	struct fd real_in, real_out;
6948c2ecf20Sopenharmony_ci	const struct cred *old_cred;
6958c2ecf20Sopenharmony_ci	loff_t ret;
6968c2ecf20Sopenharmony_ci
6978c2ecf20Sopenharmony_ci	inode_lock(inode_out);
6988c2ecf20Sopenharmony_ci	if (op != OVL_DEDUPE) {
6998c2ecf20Sopenharmony_ci		/* Update mode */
7008c2ecf20Sopenharmony_ci		ovl_copyattr(ovl_inode_real(inode_out), inode_out);
7018c2ecf20Sopenharmony_ci		ret = file_remove_privs(file_out);
7028c2ecf20Sopenharmony_ci		if (ret)
7038c2ecf20Sopenharmony_ci			goto out_unlock;
7048c2ecf20Sopenharmony_ci	}
7058c2ecf20Sopenharmony_ci
7068c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file_out, &real_out);
7078c2ecf20Sopenharmony_ci	if (ret)
7088c2ecf20Sopenharmony_ci		goto out_unlock;
7098c2ecf20Sopenharmony_ci
7108c2ecf20Sopenharmony_ci	ret = ovl_real_fdget(file_in, &real_in);
7118c2ecf20Sopenharmony_ci	if (ret) {
7128c2ecf20Sopenharmony_ci		fdput(real_out);
7138c2ecf20Sopenharmony_ci		goto out_unlock;
7148c2ecf20Sopenharmony_ci	}
7158c2ecf20Sopenharmony_ci
7168c2ecf20Sopenharmony_ci	old_cred = ovl_override_creds(file_inode(file_out)->i_sb);
7178c2ecf20Sopenharmony_ci	switch (op) {
7188c2ecf20Sopenharmony_ci	case OVL_COPY:
7198c2ecf20Sopenharmony_ci		ret = vfs_copy_file_range(real_in.file, pos_in,
7208c2ecf20Sopenharmony_ci					  real_out.file, pos_out, len, flags);
7218c2ecf20Sopenharmony_ci		break;
7228c2ecf20Sopenharmony_ci
7238c2ecf20Sopenharmony_ci	case OVL_CLONE:
7248c2ecf20Sopenharmony_ci		ret = vfs_clone_file_range(real_in.file, pos_in,
7258c2ecf20Sopenharmony_ci					   real_out.file, pos_out, len, flags);
7268c2ecf20Sopenharmony_ci		break;
7278c2ecf20Sopenharmony_ci
7288c2ecf20Sopenharmony_ci	case OVL_DEDUPE:
7298c2ecf20Sopenharmony_ci		ret = vfs_dedupe_file_range_one(real_in.file, pos_in,
7308c2ecf20Sopenharmony_ci						real_out.file, pos_out, len,
7318c2ecf20Sopenharmony_ci						flags);
7328c2ecf20Sopenharmony_ci		break;
7338c2ecf20Sopenharmony_ci	}
7348c2ecf20Sopenharmony_ci	revert_creds(old_cred);
7358c2ecf20Sopenharmony_ci
7368c2ecf20Sopenharmony_ci	/* Update size */
7378c2ecf20Sopenharmony_ci	ovl_copyattr(ovl_inode_real(inode_out), inode_out);
7388c2ecf20Sopenharmony_ci
7398c2ecf20Sopenharmony_ci	fdput(real_in);
7408c2ecf20Sopenharmony_ci	fdput(real_out);
7418c2ecf20Sopenharmony_ci
7428c2ecf20Sopenharmony_ciout_unlock:
7438c2ecf20Sopenharmony_ci	inode_unlock(inode_out);
7448c2ecf20Sopenharmony_ci
7458c2ecf20Sopenharmony_ci	return ret;
7468c2ecf20Sopenharmony_ci}
7478c2ecf20Sopenharmony_ci
7488c2ecf20Sopenharmony_cistatic ssize_t ovl_copy_file_range(struct file *file_in, loff_t pos_in,
7498c2ecf20Sopenharmony_ci				   struct file *file_out, loff_t pos_out,
7508c2ecf20Sopenharmony_ci				   size_t len, unsigned int flags)
7518c2ecf20Sopenharmony_ci{
7528c2ecf20Sopenharmony_ci	return ovl_copyfile(file_in, pos_in, file_out, pos_out, len, flags,
7538c2ecf20Sopenharmony_ci			    OVL_COPY);
7548c2ecf20Sopenharmony_ci}
7558c2ecf20Sopenharmony_ci
7568c2ecf20Sopenharmony_cistatic loff_t ovl_remap_file_range(struct file *file_in, loff_t pos_in,
7578c2ecf20Sopenharmony_ci				   struct file *file_out, loff_t pos_out,
7588c2ecf20Sopenharmony_ci				   loff_t len, unsigned int remap_flags)
7598c2ecf20Sopenharmony_ci{
7608c2ecf20Sopenharmony_ci	enum ovl_copyop op;
7618c2ecf20Sopenharmony_ci
7628c2ecf20Sopenharmony_ci	if (remap_flags & ~(REMAP_FILE_DEDUP | REMAP_FILE_ADVISORY))
7638c2ecf20Sopenharmony_ci		return -EINVAL;
7648c2ecf20Sopenharmony_ci
7658c2ecf20Sopenharmony_ci	if (remap_flags & REMAP_FILE_DEDUP)
7668c2ecf20Sopenharmony_ci		op = OVL_DEDUPE;
7678c2ecf20Sopenharmony_ci	else
7688c2ecf20Sopenharmony_ci		op = OVL_CLONE;
7698c2ecf20Sopenharmony_ci
7708c2ecf20Sopenharmony_ci	/*
7718c2ecf20Sopenharmony_ci	 * Don't copy up because of a dedupe request, this wouldn't make sense
7728c2ecf20Sopenharmony_ci	 * most of the time (data would be duplicated instead of deduplicated).
7738c2ecf20Sopenharmony_ci	 */
7748c2ecf20Sopenharmony_ci	if (op == OVL_DEDUPE &&
7758c2ecf20Sopenharmony_ci	    (!ovl_inode_upper(file_inode(file_in)) ||
7768c2ecf20Sopenharmony_ci	     !ovl_inode_upper(file_inode(file_out))))
7778c2ecf20Sopenharmony_ci		return -EPERM;
7788c2ecf20Sopenharmony_ci
7798c2ecf20Sopenharmony_ci	return ovl_copyfile(file_in, pos_in, file_out, pos_out, len,
7808c2ecf20Sopenharmony_ci			    remap_flags, op);
7818c2ecf20Sopenharmony_ci}
7828c2ecf20Sopenharmony_ci
7838c2ecf20Sopenharmony_ciconst struct file_operations ovl_file_operations = {
7848c2ecf20Sopenharmony_ci	.open		= ovl_open,
7858c2ecf20Sopenharmony_ci	.release	= ovl_release,
7868c2ecf20Sopenharmony_ci	.llseek		= ovl_llseek,
7878c2ecf20Sopenharmony_ci	.read_iter	= ovl_read_iter,
7888c2ecf20Sopenharmony_ci	.write_iter	= ovl_write_iter,
7898c2ecf20Sopenharmony_ci	.fsync		= ovl_fsync,
7908c2ecf20Sopenharmony_ci	.mmap		= ovl_mmap,
7918c2ecf20Sopenharmony_ci	.fallocate	= ovl_fallocate,
7928c2ecf20Sopenharmony_ci	.fadvise	= ovl_fadvise,
7938c2ecf20Sopenharmony_ci	.unlocked_ioctl	= ovl_ioctl,
7948c2ecf20Sopenharmony_ci#ifdef CONFIG_COMPAT
7958c2ecf20Sopenharmony_ci	.compat_ioctl	= ovl_compat_ioctl,
7968c2ecf20Sopenharmony_ci#endif
7978c2ecf20Sopenharmony_ci	.splice_read    = generic_file_splice_read,
7988c2ecf20Sopenharmony_ci	.splice_write   = ovl_splice_write,
7998c2ecf20Sopenharmony_ci
8008c2ecf20Sopenharmony_ci	.copy_file_range	= ovl_copy_file_range,
8018c2ecf20Sopenharmony_ci	.remap_file_range	= ovl_remap_file_range,
8028c2ecf20Sopenharmony_ci};
8038c2ecf20Sopenharmony_ci
8048c2ecf20Sopenharmony_ciint __init ovl_aio_request_cache_init(void)
8058c2ecf20Sopenharmony_ci{
8068c2ecf20Sopenharmony_ci	ovl_aio_request_cachep = kmem_cache_create("ovl_aio_req",
8078c2ecf20Sopenharmony_ci						   sizeof(struct ovl_aio_req),
8088c2ecf20Sopenharmony_ci						   0, SLAB_HWCACHE_ALIGN, NULL);
8098c2ecf20Sopenharmony_ci	if (!ovl_aio_request_cachep)
8108c2ecf20Sopenharmony_ci		return -ENOMEM;
8118c2ecf20Sopenharmony_ci
8128c2ecf20Sopenharmony_ci	return 0;
8138c2ecf20Sopenharmony_ci}
8148c2ecf20Sopenharmony_ci
8158c2ecf20Sopenharmony_civoid ovl_aio_request_cache_destroy(void)
8168c2ecf20Sopenharmony_ci{
8178c2ecf20Sopenharmony_ci	kmem_cache_destroy(ovl_aio_request_cachep);
8188c2ecf20Sopenharmony_ci}
819