Home | History | Annotate | Line # | Download | only in nfs
nfs_export.c revision 1.1
      1  1.1  jmmv /*	$NetBSD: nfs_export.c,v 1.1 2005/09/23 12:10:33 jmmv Exp $	*/
      2  1.1  jmmv 
      3  1.1  jmmv /*-
      4  1.1  jmmv  * Copyright (c) 1997, 1998, 2004, 2005 The NetBSD Foundation, Inc.
      5  1.1  jmmv  * All rights reserved.
      6  1.1  jmmv  *
      7  1.1  jmmv  * This code is derived from software contributed to The NetBSD Foundation
      8  1.1  jmmv  * by Jason R. Thorpe of the Numerical Aerospace Simulation Facility,
      9  1.1  jmmv  * NASA Ames Research Center.
     10  1.1  jmmv  * This code is derived from software contributed to The NetBSD Foundation
     11  1.1  jmmv  * by Charles M. Hannum.
     12  1.1  jmmv  * This code is derived from software contributed to The NetBSD Foundation
     13  1.1  jmmv  * by Julio M. Merino Vidal.
     14  1.1  jmmv  *
     15  1.1  jmmv  * Redistribution and use in source and binary forms, with or without
     16  1.1  jmmv  * modification, are permitted provided that the following conditions
     17  1.1  jmmv  * are met:
     18  1.1  jmmv  * 1. Redistributions of source code must retain the above copyright
     19  1.1  jmmv  *    notice, this list of conditions and the following disclaimer.
     20  1.1  jmmv  * 2. Redistributions in binary form must reproduce the above copyright
     21  1.1  jmmv  *    notice, this list of conditions and the following disclaimer in the
     22  1.1  jmmv  *    documentation and/or other materials provided with the distribution.
     23  1.1  jmmv  * 3. All advertising materials mentioning features or use of this software
     24  1.1  jmmv  *    must display the following acknowledgement:
     25  1.1  jmmv  *	This product includes software developed by the NetBSD
     26  1.1  jmmv  *	Foundation, Inc. and its contributors.
     27  1.1  jmmv  * 4. Neither the name of The NetBSD Foundation nor the names of its
     28  1.1  jmmv  *    contributors may be used to endorse or promote products derived
     29  1.1  jmmv  *    from this software without specific prior written permission.
     30  1.1  jmmv  *
     31  1.1  jmmv  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     32  1.1  jmmv  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     33  1.1  jmmv  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     34  1.1  jmmv  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     35  1.1  jmmv  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     36  1.1  jmmv  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     37  1.1  jmmv  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     38  1.1  jmmv  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     39  1.1  jmmv  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     40  1.1  jmmv  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     41  1.1  jmmv  * POSSIBILITY OF SUCH DAMAGE.
     42  1.1  jmmv  */
     43  1.1  jmmv 
     44  1.1  jmmv /*
     45  1.1  jmmv  * Copyright (c) 1989, 1993
     46  1.1  jmmv  *	The Regents of the University of California.  All rights reserved.
     47  1.1  jmmv  * (c) UNIX System Laboratories, Inc.
     48  1.1  jmmv  * All or some portions of this file are derived from material licensed
     49  1.1  jmmv  * to the University of California by American Telephone and Telegraph
     50  1.1  jmmv  * Co. or Unix System Laboratories, Inc. and are reproduced herein with
     51  1.1  jmmv  * the permission of UNIX System Laboratories, Inc.
     52  1.1  jmmv  *
     53  1.1  jmmv  * Redistribution and use in source and binary forms, with or without
     54  1.1  jmmv  * modification, are permitted provided that the following conditions
     55  1.1  jmmv  * are met:
     56  1.1  jmmv  * 1. Redistributions of source code must retain the above copyright
     57  1.1  jmmv  *    notice, this list of conditions and the following disclaimer.
     58  1.1  jmmv  * 2. Redistributions in binary form must reproduce the above copyright
     59  1.1  jmmv  *    notice, this list of conditions and the following disclaimer in the
     60  1.1  jmmv  *    documentation and/or other materials provided with the distribution.
     61  1.1  jmmv  * 3. Neither the name of the University nor the names of its contributors
     62  1.1  jmmv  *    may be used to endorse or promote products derived from this software
     63  1.1  jmmv  *    without specific prior written permission.
     64  1.1  jmmv  *
     65  1.1  jmmv  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     66  1.1  jmmv  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     67  1.1  jmmv  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     68  1.1  jmmv  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     69  1.1  jmmv  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     70  1.1  jmmv  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     71  1.1  jmmv  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     72  1.1  jmmv  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     73  1.1  jmmv  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     74  1.1  jmmv  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     75  1.1  jmmv  * SUCH DAMAGE.
     76  1.1  jmmv  *
     77  1.1  jmmv  *	@(#)vfs_subr.c	8.13 (Berkeley) 4/18/94
     78  1.1  jmmv  */
     79  1.1  jmmv 
     80  1.1  jmmv /*
     81  1.1  jmmv  * VFS exports list management.
     82  1.1  jmmv  */
     83  1.1  jmmv 
     84  1.1  jmmv #include <sys/cdefs.h>
     85  1.1  jmmv __KERNEL_RCSID(0, "$NetBSD: nfs_export.c,v 1.1 2005/09/23 12:10:33 jmmv Exp $");
     86  1.1  jmmv 
     87  1.1  jmmv #include "opt_inet.h"
     88  1.1  jmmv 
     89  1.1  jmmv #include <sys/param.h>
     90  1.1  jmmv #include <sys/systm.h>
     91  1.1  jmmv #include <sys/queue.h>
     92  1.1  jmmv #include <sys/proc.h>
     93  1.1  jmmv #include <sys/mount.h>
     94  1.1  jmmv #include <sys/vnode.h>
     95  1.1  jmmv #include <sys/namei.h>
     96  1.1  jmmv #include <sys/errno.h>
     97  1.1  jmmv #include <sys/malloc.h>
     98  1.1  jmmv #include <sys/domain.h>
     99  1.1  jmmv #include <sys/mbuf.h>
    100  1.1  jmmv #include <sys/dirent.h>
    101  1.1  jmmv #include <sys/socket.h>		/* XXX for AF_MAX */
    102  1.1  jmmv 
    103  1.1  jmmv #include <net/radix.h>
    104  1.1  jmmv 
    105  1.1  jmmv #include <netinet/in.h>
    106  1.1  jmmv 
    107  1.1  jmmv #include <nfs/rpcv2.h>
    108  1.1  jmmv #include <nfs/nfsproto.h>
    109  1.1  jmmv #include <nfs/nfs.h>
    110  1.1  jmmv #include <nfs/nfs_var.h>
    111  1.1  jmmv 
    112  1.1  jmmv /*
    113  1.1  jmmv  * Network address lookup element.
    114  1.1  jmmv  */
    115  1.1  jmmv struct netcred {
    116  1.1  jmmv 	struct	radix_node netc_rnodes[2];
    117  1.1  jmmv 	int	netc_refcnt;
    118  1.1  jmmv 	int	netc_exflags;
    119  1.1  jmmv 	struct	ucred netc_anon;
    120  1.1  jmmv };
    121  1.1  jmmv 
    122  1.1  jmmv /*
    123  1.1  jmmv  * Network export information.
    124  1.1  jmmv  */
    125  1.1  jmmv struct netexport {
    126  1.1  jmmv 	struct	netcred ne_defexported;		      /* Default export */
    127  1.1  jmmv 	struct	radix_node_head *ne_rtable[AF_MAX+1]; /* Individual exports */
    128  1.1  jmmv };
    129  1.1  jmmv 
    130  1.1  jmmv /*
    131  1.1  jmmv  * Structures to map between standard mount points to their corresponding
    132  1.1  jmmv  * network export information.
    133  1.1  jmmv  */
    134  1.1  jmmv struct mount_netexport_pair {
    135  1.1  jmmv 	CIRCLEQ_ENTRY(mount_netexport_pair) mnp_entries;
    136  1.1  jmmv 	const struct mount *mnp_mount;
    137  1.1  jmmv 	struct netexport mnp_netexport;
    138  1.1  jmmv };
    139  1.1  jmmv CIRCLEQ_HEAD(mount_netexport_map, mount_netexport_pair)
    140  1.1  jmmv     mount_netexport_map = CIRCLEQ_HEAD_INITIALIZER(mount_netexport_map);
    141  1.1  jmmv 
    142  1.1  jmmv /* Malloc type used by the mount<->netexport map. */
    143  1.1  jmmv MALLOC_DEFINE(M_NFS_EXPORT, "nfs_export", "NFS export data");
    144  1.1  jmmv 
    145  1.1  jmmv /* Publicly exported file system. */
    146  1.1  jmmv struct nfs_public nfs_pub;
    147  1.1  jmmv 
    148  1.1  jmmv /*
    149  1.1  jmmv  * Local prototypes.
    150  1.1  jmmv  */
    151  1.1  jmmv static int init_exports(struct mount *, struct mount_netexport_pair **);
    152  1.1  jmmv static int hang_addrlist(struct mount *, struct netexport *,
    153  1.1  jmmv     const struct export_args *);
    154  1.1  jmmv static int sacheck(struct sockaddr *);
    155  1.1  jmmv static int free_netcred(struct radix_node *, void *);
    156  1.1  jmmv static void clear_exports(struct mount *, struct netexport *);
    157  1.1  jmmv static int export(struct mount *, struct netexport *,
    158  1.1  jmmv     const struct export_args *);
    159  1.1  jmmv static int setpublicfs(struct mount *, struct netexport *,
    160  1.1  jmmv     const struct export_args *);
    161  1.1  jmmv static struct netcred *export_lookup(struct mount *, struct netexport *,
    162  1.1  jmmv     struct mbuf *);
    163  1.1  jmmv 
    164  1.1  jmmv /*
    165  1.1  jmmv  * PUBLIC INTERFACE
    166  1.1  jmmv  */
    167  1.1  jmmv 
    168  1.1  jmmv /*
    169  1.1  jmmv  * Declare and initialize the file system export hooks.
    170  1.1  jmmv  */
    171  1.1  jmmv static void nfs_export_unmount(struct mount *);
    172  1.1  jmmv 
    173  1.1  jmmv struct vfs_hooks nfs_export_hooks = {
    174  1.1  jmmv 	nfs_export_unmount
    175  1.1  jmmv };
    176  1.1  jmmv VFS_HOOKS_ATTACH(nfs_export_hooks);
    177  1.1  jmmv 
    178  1.1  jmmv /*
    179  1.1  jmmv  * VFS unmount hook for NFS exports.
    180  1.1  jmmv  *
    181  1.1  jmmv  * Releases NFS exports list resources if the given mount point has some.
    182  1.1  jmmv  * As allocation happens lazily, it may be that it doesn't has this
    183  1.1  jmmv  * information, although it theorically should.
    184  1.1  jmmv  */
    185  1.1  jmmv static void
    186  1.1  jmmv nfs_export_unmount(struct mount *mp)
    187  1.1  jmmv {
    188  1.1  jmmv 	boolean_t found;
    189  1.1  jmmv 	struct mount_netexport_pair *mnp;
    190  1.1  jmmv 
    191  1.1  jmmv 	KASSERT(mp != NULL);
    192  1.1  jmmv 
    193  1.1  jmmv 	found = FALSE;
    194  1.1  jmmv 	CIRCLEQ_FOREACH(mnp, &mount_netexport_map, mnp_entries) {
    195  1.1  jmmv 		if (mnp->mnp_mount == mp) {
    196  1.1  jmmv 			found = TRUE;
    197  1.1  jmmv 			break;
    198  1.1  jmmv 		}
    199  1.1  jmmv 	}
    200  1.1  jmmv 
    201  1.1  jmmv 	if (mp->mnt_op->vfs_vptofh == NULL || mp->mnt_op->vfs_fhtovp == NULL)
    202  1.1  jmmv 		KASSERT(!found);
    203  1.1  jmmv 	else if (found) {
    204  1.1  jmmv 		if (mp->mnt_flag & MNT_EXPUBLIC)
    205  1.1  jmmv 			setpublicfs(NULL, NULL, NULL);
    206  1.1  jmmv 
    207  1.1  jmmv 		free(mnp, M_NFS_EXPORT);
    208  1.1  jmmv 	}
    209  1.1  jmmv }
    210  1.1  jmmv 
    211  1.1  jmmv /*
    212  1.1  jmmv  * Atomically set the NFS exports list of the given file system, replacing
    213  1.1  jmmv  * it with a new list of entries.
    214  1.1  jmmv  *
    215  1.1  jmmv  * Returns zero on success or an appropriate error code otherwise.
    216  1.1  jmmv  *
    217  1.1  jmmv  * Helper function for the nfssvc(2) system call (NFSSVC_SETEXPORTSLIST
    218  1.1  jmmv  * command).
    219  1.1  jmmv  */
    220  1.1  jmmv int
    221  1.1  jmmv mountd_set_exports_list(const struct mountd_exports_list *mel, struct proc *p)
    222  1.1  jmmv {
    223  1.1  jmmv 	boolean_t found;
    224  1.1  jmmv 	int error;
    225  1.1  jmmv #ifdef notyet
    226  1.1  jmmv 	/* XXX: See below to see the reason why this is disabled. */
    227  1.1  jmmv 	size_t i;
    228  1.1  jmmv #endif
    229  1.1  jmmv 	struct mount *mp;
    230  1.1  jmmv 	struct mount_netexport_pair *mnp;
    231  1.1  jmmv 	struct nameidata nd;
    232  1.1  jmmv 	struct vnode *vp;
    233  1.1  jmmv 
    234  1.1  jmmv 	if (suser(p->p_ucred, &p->p_acflag) != 0)
    235  1.1  jmmv 		return EPERM;
    236  1.1  jmmv 
    237  1.1  jmmv 	/* Lookup the file system path. */
    238  1.1  jmmv 	NDINIT(&nd, LOOKUP, FOLLOW | LOCKLEAF, UIO_USERSPACE, mel->mel_path, p);
    239  1.1  jmmv 	error = namei(&nd);
    240  1.1  jmmv 	if (error != 0)
    241  1.1  jmmv 		return error;
    242  1.1  jmmv 	vp = (struct vnode *)nd.ni_vp;
    243  1.1  jmmv 	mp = (struct mount *)vp->v_mount;
    244  1.1  jmmv 
    245  1.1  jmmv 	/* The selected file system may not support NFS exports, so ensure
    246  1.1  jmmv 	 * it does. */
    247  1.1  jmmv 	if (mp->mnt_op->vfs_vptofh == NULL && mp->mnt_op->vfs_fhtovp == NULL) {
    248  1.1  jmmv 		error = EOPNOTSUPP;
    249  1.1  jmmv 		goto out_locked;
    250  1.1  jmmv 	}
    251  1.1  jmmv 	KASSERT(mp->mnt_op->vfs_vptofh != NULL &&
    252  1.1  jmmv 	    mp->mnt_op->vfs_fhtovp != NULL);
    253  1.1  jmmv 
    254  1.1  jmmv 	/* Mark the file system busy. */
    255  1.1  jmmv 	error = vfs_busy(mp, LK_NOWAIT, NULL);
    256  1.1  jmmv 	if (error != 0)
    257  1.1  jmmv 		goto out_locked;
    258  1.1  jmmv 
    259  1.1  jmmv 	found = FALSE;
    260  1.1  jmmv 	CIRCLEQ_FOREACH(mnp, &mount_netexport_map, mnp_entries) {
    261  1.1  jmmv 		if (mnp->mnp_mount == mp) {
    262  1.1  jmmv 			found = TRUE;
    263  1.1  jmmv 			break;
    264  1.1  jmmv 		}
    265  1.1  jmmv 	}
    266  1.1  jmmv 	if (!found) {
    267  1.1  jmmv 		error = init_exports(mp, &mnp);
    268  1.1  jmmv 		if (error != 0) {
    269  1.1  jmmv 			vfs_unbusy(mp);
    270  1.1  jmmv 			goto out_locked;
    271  1.1  jmmv 		}
    272  1.1  jmmv 	}
    273  1.1  jmmv 
    274  1.1  jmmv 	/*
    275  1.1  jmmv 	 * XXX: The part marked as 'notyet' works fine from the kernel's
    276  1.1  jmmv 	 * point of view, in the sense that it is able to atomically update
    277  1.1  jmmv 	 * the complete exports list for a file system.  However, supporting
    278  1.1  jmmv 	 * this in mountd(8) requires a lot of work; so, for now, keep the
    279  1.1  jmmv 	 * old behavior of updating a single entry per call.
    280  1.1  jmmv 	 *
    281  1.1  jmmv 	 * When mountd(8) is fixed, just remove the second branch of this
    282  1.1  jmmv 	 * preprocessor conditional and enable the first one.
    283  1.1  jmmv 	 */
    284  1.1  jmmv #ifdef notyet
    285  1.1  jmmv 	clear_exports(mp, &mnp->mnp_netexport);
    286  1.1  jmmv 	for (i = 0; error == 0 && i < mel->mel_nexports; i++)
    287  1.1  jmmv 		error = export(mp, &mnp->mnp_netexport, &mel->mel_exports[i]);
    288  1.1  jmmv #else
    289  1.1  jmmv 	if (mel->mel_nexports == 0)
    290  1.1  jmmv 		clear_exports(mp, &mnp->mnp_netexport);
    291  1.1  jmmv 	else if (mel->mel_nexports == 1)
    292  1.1  jmmv 		error = export(mp, &mnp->mnp_netexport, &mel->mel_exports[0]);
    293  1.1  jmmv 	else {
    294  1.1  jmmv 		printf("mountd_set_exports_list: Cannot set more than one "
    295  1.1  jmmv 		    "entry at once (unimplemented)\n");
    296  1.1  jmmv 		error = EOPNOTSUPP;
    297  1.1  jmmv 	}
    298  1.1  jmmv #endif
    299  1.1  jmmv 
    300  1.1  jmmv 	vfs_unbusy(mp);
    301  1.1  jmmv 
    302  1.1  jmmv out_locked:
    303  1.1  jmmv 	vput(vp);
    304  1.1  jmmv 
    305  1.1  jmmv 	return 0;
    306  1.1  jmmv }
    307  1.1  jmmv 
    308  1.1  jmmv /*
    309  1.1  jmmv  * Check if the file system specified by the 'mp' mount structure is
    310  1.1  jmmv  * exported to a client with 'anon' anonymous credentials.  The 'mb'
    311  1.1  jmmv  * argument is an mbuf containing the network address of the client.
    312  1.1  jmmv  * The return parameters for the export flags for the client are returned
    313  1.1  jmmv  * in the address specified by 'wh'.
    314  1.1  jmmv  *
    315  1.1  jmmv  * This function is used exclusively by the NFS server.  It is generally
    316  1.1  jmmv  * invoked before VFS_FHTOVP to validate that client has access to the
    317  1.1  jmmv  * file system.
    318  1.1  jmmv  */
    319  1.1  jmmv int
    320  1.1  jmmv nfs_check_export(struct mount *mp, struct mbuf *mb, int *wh,
    321  1.1  jmmv     struct ucred **anon)
    322  1.1  jmmv {
    323  1.1  jmmv 	boolean_t found;
    324  1.1  jmmv 	struct mount_netexport_pair *mnp;
    325  1.1  jmmv 	struct netcred *np;
    326  1.1  jmmv 
    327  1.1  jmmv 	found = FALSE;
    328  1.1  jmmv 	CIRCLEQ_FOREACH(mnp, &mount_netexport_map, mnp_entries) {
    329  1.1  jmmv 		if (mnp->mnp_mount == mp) {
    330  1.1  jmmv 			found = TRUE;
    331  1.1  jmmv 			break;
    332  1.1  jmmv 		}
    333  1.1  jmmv 	}
    334  1.1  jmmv 	if (!found)
    335  1.1  jmmv 		return EACCES;
    336  1.1  jmmv 
    337  1.1  jmmv 	np = export_lookup(mp, &mnp->mnp_netexport, mb);
    338  1.1  jmmv 	if (np != NULL) {
    339  1.1  jmmv 		*wh = np->netc_exflags;
    340  1.1  jmmv 		*anon = &np->netc_anon;
    341  1.1  jmmv 	}
    342  1.1  jmmv 
    343  1.1  jmmv 	return np == NULL ? EACCES : 0;
    344  1.1  jmmv }
    345  1.1  jmmv 
    346  1.1  jmmv /*
    347  1.1  jmmv  * INTERNAL FUNCTIONS
    348  1.1  jmmv  */
    349  1.1  jmmv 
    350  1.1  jmmv /*
    351  1.1  jmmv  * Initializes NFS exports for the file system given in 'mp' if it supports
    352  1.1  jmmv  * file handles; this is determined by checking whether mp's vfs_vptofh and
    353  1.1  jmmv  * vfs_fhtovp operations are NULL or not.
    354  1.1  jmmv  *
    355  1.1  jmmv  * If successful, returns 0 and sets *mnpp to the address of the new
    356  1.1  jmmv  * mount_netexport_pair item; otherwise returns and appropriate error code
    357  1.1  jmmv  * and *mnpp remains unmodified.
    358  1.1  jmmv  */
    359  1.1  jmmv static int
    360  1.1  jmmv init_exports(struct mount *mp, struct mount_netexport_pair **mnpp)
    361  1.1  jmmv {
    362  1.1  jmmv 	int error;
    363  1.1  jmmv 	struct export_args ea;
    364  1.1  jmmv 	struct mount_netexport_pair *mnp;
    365  1.1  jmmv 
    366  1.1  jmmv 	KASSERT(mp != NULL);
    367  1.1  jmmv 	KASSERT(mp->mnt_op->vfs_vptofh != NULL &&
    368  1.1  jmmv 	    mp->mnt_op->vfs_fhtovp != NULL);
    369  1.1  jmmv 
    370  1.1  jmmv #ifdef DIAGNOSTIC
    371  1.1  jmmv 	/* Ensure that we do not already have this mount point. */
    372  1.1  jmmv 	CIRCLEQ_FOREACH(mnp, &mount_netexport_map, mnp_entries) {
    373  1.1  jmmv 		if (mnp->mnp_mount == mp)
    374  1.1  jmmv 			KASSERT(0);
    375  1.1  jmmv 	}
    376  1.1  jmmv #endif
    377  1.1  jmmv 
    378  1.1  jmmv 	mnp = (struct mount_netexport_pair *)
    379  1.1  jmmv 	    malloc(sizeof(struct mount_netexport_pair), M_NFS_EXPORT, M_WAITOK);
    380  1.1  jmmv 	KASSERT(mnp != NULL);
    381  1.1  jmmv 	mnp->mnp_mount = mp;
    382  1.1  jmmv 	memset(&mnp->mnp_netexport, 0, sizeof(mnp->mnp_netexport));
    383  1.1  jmmv 
    384  1.1  jmmv 	/* Set the default export entry.  Handled internally by export upon
    385  1.1  jmmv 	 * first call. */
    386  1.1  jmmv 	memset(&ea, 0, sizeof(ea));
    387  1.1  jmmv 	ea.ex_root = -2;
    388  1.1  jmmv 	if (mp->mnt_flag & MNT_RDONLY)
    389  1.1  jmmv 		ea.ex_flags |= MNT_EXRDONLY;
    390  1.1  jmmv 	error = export(mp, &mnp->mnp_netexport, &ea);
    391  1.1  jmmv 	if (error != 0)
    392  1.1  jmmv 		free(mnp, M_NFS_EXPORT);
    393  1.1  jmmv 	else {
    394  1.1  jmmv 		CIRCLEQ_INSERT_TAIL(&mount_netexport_map, mnp, mnp_entries);
    395  1.1  jmmv 		*mnpp = mnp;
    396  1.1  jmmv 	}
    397  1.1  jmmv 
    398  1.1  jmmv 	return error;
    399  1.1  jmmv }
    400  1.1  jmmv 
    401  1.1  jmmv /*
    402  1.1  jmmv  * Build hash lists of net addresses and hang them off the mount point.
    403  1.1  jmmv  * Called by export() to set up a new entry in the lists of export
    404  1.1  jmmv  * addresses.
    405  1.1  jmmv  */
    406  1.1  jmmv static int
    407  1.1  jmmv hang_addrlist(struct mount *mp, struct netexport *nep,
    408  1.1  jmmv     const struct export_args *argp)
    409  1.1  jmmv {
    410  1.1  jmmv 	int error, i;
    411  1.1  jmmv 	struct netcred *np, *enp;
    412  1.1  jmmv 	struct radix_node_head *rnh;
    413  1.1  jmmv 	struct sockaddr *saddr, *smask;
    414  1.1  jmmv 	struct domain *dom;
    415  1.1  jmmv 
    416  1.1  jmmv 	smask = NULL;
    417  1.1  jmmv 
    418  1.1  jmmv 	if (argp->ex_addrlen == 0) {
    419  1.1  jmmv 		if (mp->mnt_flag & MNT_DEFEXPORTED)
    420  1.1  jmmv 			return EPERM;
    421  1.1  jmmv 		np = &nep->ne_defexported;
    422  1.1  jmmv 		np->netc_exflags = argp->ex_flags;
    423  1.1  jmmv 		crcvt(&np->netc_anon, &argp->ex_anon);
    424  1.1  jmmv 		np->netc_anon.cr_ref = 1;
    425  1.1  jmmv 		mp->mnt_flag |= MNT_DEFEXPORTED;
    426  1.1  jmmv 		return 0;
    427  1.1  jmmv 	}
    428  1.1  jmmv 
    429  1.1  jmmv 	if (argp->ex_addrlen > MLEN || argp->ex_masklen > MLEN)
    430  1.1  jmmv 		return EINVAL;
    431  1.1  jmmv 
    432  1.1  jmmv 	i = sizeof(struct netcred) + argp->ex_addrlen + argp->ex_masklen;
    433  1.1  jmmv 	np = (struct netcred *)malloc(i, M_NETADDR, M_WAITOK);
    434  1.1  jmmv 	memset((caddr_t)np, 0, i);
    435  1.1  jmmv 	saddr = (struct sockaddr *)(np + 1);
    436  1.1  jmmv 	error = copyin(argp->ex_addr, (caddr_t)saddr, argp->ex_addrlen);
    437  1.1  jmmv 	if (error)
    438  1.1  jmmv 		goto out;
    439  1.1  jmmv 	if (saddr->sa_len > argp->ex_addrlen)
    440  1.1  jmmv 		saddr->sa_len = argp->ex_addrlen;
    441  1.1  jmmv 	if (sacheck(saddr) == -1)
    442  1.1  jmmv 		return EINVAL;
    443  1.1  jmmv 	if (argp->ex_masklen) {
    444  1.1  jmmv 		smask = (struct sockaddr *)((caddr_t)saddr + argp->ex_addrlen);
    445  1.1  jmmv 		error = copyin(argp->ex_mask, (caddr_t)smask, argp->ex_masklen);
    446  1.1  jmmv 		if (error)
    447  1.1  jmmv 			goto out;
    448  1.1  jmmv 		if (smask->sa_len > argp->ex_masklen)
    449  1.1  jmmv 			smask->sa_len = argp->ex_masklen;
    450  1.1  jmmv 		if (smask->sa_family != saddr->sa_family)
    451  1.1  jmmv 			return EINVAL;
    452  1.1  jmmv 		if (sacheck(smask) == -1)
    453  1.1  jmmv 			return EINVAL;
    454  1.1  jmmv 	}
    455  1.1  jmmv 	i = saddr->sa_family;
    456  1.1  jmmv 	if ((rnh = nep->ne_rtable[i]) == 0) {
    457  1.1  jmmv 		/*
    458  1.1  jmmv 		 * Seems silly to initialize every AF when most are not
    459  1.1  jmmv 		 * used, do so on demand here
    460  1.1  jmmv 		 */
    461  1.1  jmmv 		DOMAIN_FOREACH(dom) {
    462  1.1  jmmv 			if (dom->dom_family == i && dom->dom_rtattach) {
    463  1.1  jmmv 				dom->dom_rtattach((void **)&nep->ne_rtable[i],
    464  1.1  jmmv 					dom->dom_rtoffset);
    465  1.1  jmmv 				break;
    466  1.1  jmmv 			}
    467  1.1  jmmv 		}
    468  1.1  jmmv 		if ((rnh = nep->ne_rtable[i]) == 0) {
    469  1.1  jmmv 			error = ENOBUFS;
    470  1.1  jmmv 			goto out;
    471  1.1  jmmv 		}
    472  1.1  jmmv 	}
    473  1.1  jmmv 
    474  1.1  jmmv 	enp = (struct netcred *)(*rnh->rnh_addaddr)(saddr, smask, rnh,
    475  1.1  jmmv 	    np->netc_rnodes);
    476  1.1  jmmv 	if (enp != np) {
    477  1.1  jmmv 		if (enp == NULL) {
    478  1.1  jmmv 			enp = (struct netcred *)(*rnh->rnh_lookup)(saddr,
    479  1.1  jmmv 			    smask, rnh);
    480  1.1  jmmv 			if (enp == NULL) {
    481  1.1  jmmv 				error = EPERM;
    482  1.1  jmmv 				goto out;
    483  1.1  jmmv 			}
    484  1.1  jmmv 		} else
    485  1.1  jmmv 			enp->netc_refcnt++;
    486  1.1  jmmv 
    487  1.1  jmmv 		goto check;
    488  1.1  jmmv 	} else
    489  1.1  jmmv 		enp->netc_refcnt = 1;
    490  1.1  jmmv 
    491  1.1  jmmv 	np->netc_exflags = argp->ex_flags;
    492  1.1  jmmv 	crcvt(&np->netc_anon, &argp->ex_anon);
    493  1.1  jmmv 	np->netc_anon.cr_ref = 1;
    494  1.1  jmmv 	return 0;
    495  1.1  jmmv check:
    496  1.1  jmmv 	if (enp->netc_exflags != argp->ex_flags ||
    497  1.1  jmmv 	    crcmp(&enp->netc_anon, &argp->ex_anon) != 0)
    498  1.1  jmmv 		error = EPERM;
    499  1.1  jmmv 	else
    500  1.1  jmmv 		error = 0;
    501  1.1  jmmv out:
    502  1.1  jmmv 	free(np, M_NETADDR);
    503  1.1  jmmv 	return error;
    504  1.1  jmmv }
    505  1.1  jmmv 
    506  1.1  jmmv /*
    507  1.1  jmmv  * Ensure that the address stored in 'sa' is valid.
    508  1.1  jmmv  * Returns zero on success, otherwise -1.
    509  1.1  jmmv  */
    510  1.1  jmmv static int
    511  1.1  jmmv sacheck(struct sockaddr *sa)
    512  1.1  jmmv {
    513  1.1  jmmv 
    514  1.1  jmmv 	switch (sa->sa_family) {
    515  1.1  jmmv #ifdef INET
    516  1.1  jmmv 	case AF_INET: {
    517  1.1  jmmv 		struct sockaddr_in *sin = (struct sockaddr_in *)sa;
    518  1.1  jmmv 		char *p = (char *)sin->sin_zero;
    519  1.1  jmmv 		size_t i;
    520  1.1  jmmv 
    521  1.1  jmmv 		if (sin->sin_len != sizeof(*sin))
    522  1.1  jmmv 			return -1;
    523  1.1  jmmv 		if (sin->sin_port != 0)
    524  1.1  jmmv 			return -1;
    525  1.1  jmmv 		for (i = 0; i < sizeof(sin->sin_zero); i++)
    526  1.1  jmmv 			if (*p++ != '\0')
    527  1.1  jmmv 				return -1;
    528  1.1  jmmv 		return 0;
    529  1.1  jmmv 	}
    530  1.1  jmmv #endif
    531  1.1  jmmv #ifdef INET6
    532  1.1  jmmv 	case AF_INET6: {
    533  1.1  jmmv 		struct sockaddr_in6 *sin6 = (struct sockaddr_in6 *)sa;
    534  1.1  jmmv 
    535  1.1  jmmv 		if (sin6->sin6_len != sizeof(*sin6))
    536  1.1  jmmv 			return -1;
    537  1.1  jmmv 		if (sin6->sin6_port != 0)
    538  1.1  jmmv 			return -1;
    539  1.1  jmmv 		return 0;
    540  1.1  jmmv 	}
    541  1.1  jmmv #endif
    542  1.1  jmmv 	default:
    543  1.1  jmmv 		return -1;
    544  1.1  jmmv 	}
    545  1.1  jmmv }
    546  1.1  jmmv 
    547  1.1  jmmv /*
    548  1.1  jmmv  * Free the netcred object pointed to by the 'rn' radix node.
    549  1.1  jmmv  * 'w' holds a pointer to the radix tree head.
    550  1.1  jmmv  */
    551  1.1  jmmv static int
    552  1.1  jmmv free_netcred(struct radix_node *rn, void *w)
    553  1.1  jmmv {
    554  1.1  jmmv 	struct radix_node_head *rnh = (struct radix_node_head *)w;
    555  1.1  jmmv 	struct netcred *np = (struct netcred *)(void *)rn;
    556  1.1  jmmv 
    557  1.1  jmmv 	(*rnh->rnh_deladdr)(rn->rn_key, rn->rn_mask, rnh);
    558  1.1  jmmv 	if (--(np->netc_refcnt) <= 0)
    559  1.1  jmmv 		free(np, M_NETADDR);
    560  1.1  jmmv 	return 0;
    561  1.1  jmmv }
    562  1.1  jmmv 
    563  1.1  jmmv /*
    564  1.1  jmmv  * Clears the exports list for a given file system.
    565  1.1  jmmv  */
    566  1.1  jmmv static void
    567  1.1  jmmv clear_exports(struct mount *mp, struct netexport *nep)
    568  1.1  jmmv {
    569  1.1  jmmv 	int i;
    570  1.1  jmmv 	struct radix_node_head *rnh;
    571  1.1  jmmv 
    572  1.1  jmmv 	if (mp->mnt_flag & MNT_EXPUBLIC) {
    573  1.1  jmmv 		setpublicfs(NULL, NULL, NULL);
    574  1.1  jmmv 		mp->mnt_flag &= ~MNT_EXPUBLIC;
    575  1.1  jmmv 	}
    576  1.1  jmmv 
    577  1.1  jmmv 	for (i = 0; i <= AF_MAX; i++) {
    578  1.1  jmmv 		if ((rnh = nep->ne_rtable[i]) != NULL) {
    579  1.1  jmmv 			(*rnh->rnh_walktree)(rnh, free_netcred, rnh);
    580  1.1  jmmv 			free((caddr_t)rnh, M_RTABLE);
    581  1.1  jmmv 			nep->ne_rtable[i] = 0;
    582  1.1  jmmv 		}
    583  1.1  jmmv 	}
    584  1.1  jmmv 
    585  1.1  jmmv 	mp->mnt_flag &= ~(MNT_EXPORTED | MNT_DEFEXPORTED);
    586  1.1  jmmv }
    587  1.1  jmmv 
    588  1.1  jmmv /*
    589  1.1  jmmv  * Add a new export entry (described by an export_args structure) to the
    590  1.1  jmmv  * given file system.
    591  1.1  jmmv  */
    592  1.1  jmmv static int
    593  1.1  jmmv export(struct mount *mp, struct netexport *nep, const struct export_args *argp)
    594  1.1  jmmv {
    595  1.1  jmmv 	int error;
    596  1.1  jmmv 
    597  1.1  jmmv 	if (argp->ex_flags & MNT_EXPORTED) {
    598  1.1  jmmv 		if (argp->ex_flags & MNT_EXPUBLIC) {
    599  1.1  jmmv 			if ((error = setpublicfs(mp, nep, argp)) != 0)
    600  1.1  jmmv 				return error;
    601  1.1  jmmv 			mp->mnt_flag |= MNT_EXPUBLIC;
    602  1.1  jmmv 		}
    603  1.1  jmmv 		if ((error = hang_addrlist(mp, nep, argp)) != 0)
    604  1.1  jmmv 			return error;
    605  1.1  jmmv 		mp->mnt_flag |= MNT_EXPORTED;
    606  1.1  jmmv 	}
    607  1.1  jmmv 	return 0;
    608  1.1  jmmv }
    609  1.1  jmmv 
    610  1.1  jmmv /*
    611  1.1  jmmv  * Set the publicly exported filesystem (WebNFS).  Currently, only
    612  1.1  jmmv  * one public filesystem is possible in the spec (RFC 2054 and 2055)
    613  1.1  jmmv  */
    614  1.1  jmmv static int
    615  1.1  jmmv setpublicfs(struct mount *mp, struct netexport *nep,
    616  1.1  jmmv     const struct export_args *argp)
    617  1.1  jmmv {
    618  1.1  jmmv 	char *cp;
    619  1.1  jmmv 	int error;
    620  1.1  jmmv 	struct vnode *rvp;
    621  1.1  jmmv 
    622  1.1  jmmv 	/*
    623  1.1  jmmv 	 * mp == NULL -> invalidate the current info, the FS is
    624  1.1  jmmv 	 * no longer exported. May be called from either export
    625  1.1  jmmv 	 * or unmount, so check if it hasn't already been done.
    626  1.1  jmmv 	 */
    627  1.1  jmmv 	if (mp == NULL) {
    628  1.1  jmmv 		if (nfs_pub.np_valid) {
    629  1.1  jmmv 			nfs_pub.np_valid = 0;
    630  1.1  jmmv 			if (nfs_pub.np_index != NULL) {
    631  1.1  jmmv 				FREE(nfs_pub.np_index, M_TEMP);
    632  1.1  jmmv 				nfs_pub.np_index = NULL;
    633  1.1  jmmv 			}
    634  1.1  jmmv 		}
    635  1.1  jmmv 		return 0;
    636  1.1  jmmv 	}
    637  1.1  jmmv 
    638  1.1  jmmv 	/*
    639  1.1  jmmv 	 * Only one allowed at a time.
    640  1.1  jmmv 	 */
    641  1.1  jmmv 	if (nfs_pub.np_valid != 0 && mp != nfs_pub.np_mount)
    642  1.1  jmmv 		return EBUSY;
    643  1.1  jmmv 
    644  1.1  jmmv 	/*
    645  1.1  jmmv 	 * Get real filehandle for root of exported FS.
    646  1.1  jmmv 	 */
    647  1.1  jmmv 	memset((caddr_t)&nfs_pub.np_handle, 0, sizeof(nfs_pub.np_handle));
    648  1.1  jmmv 	nfs_pub.np_handle.fh_fsid = mp->mnt_stat.f_fsidx;
    649  1.1  jmmv 
    650  1.1  jmmv 	if ((error = VFS_ROOT(mp, &rvp)))
    651  1.1  jmmv 		return error;
    652  1.1  jmmv 
    653  1.1  jmmv 	if ((error = VFS_VPTOFH(rvp, &nfs_pub.np_handle.fh_fid)))
    654  1.1  jmmv 		return error;
    655  1.1  jmmv 
    656  1.1  jmmv 	vput(rvp);
    657  1.1  jmmv 
    658  1.1  jmmv 	/*
    659  1.1  jmmv 	 * If an indexfile was specified, pull it in.
    660  1.1  jmmv 	 */
    661  1.1  jmmv 	if (argp->ex_indexfile != NULL) {
    662  1.1  jmmv 		MALLOC(nfs_pub.np_index, char *, MAXNAMLEN + 1, M_TEMP,
    663  1.1  jmmv 		    M_WAITOK);
    664  1.1  jmmv 		error = copyinstr(argp->ex_indexfile, nfs_pub.np_index,
    665  1.1  jmmv 		    MAXNAMLEN, (size_t *)0);
    666  1.1  jmmv 		if (!error) {
    667  1.1  jmmv 			/*
    668  1.1  jmmv 			 * Check for illegal filenames.
    669  1.1  jmmv 			 */
    670  1.1  jmmv 			for (cp = nfs_pub.np_index; *cp; cp++) {
    671  1.1  jmmv 				if (*cp == '/') {
    672  1.1  jmmv 					error = EINVAL;
    673  1.1  jmmv 					break;
    674  1.1  jmmv 				}
    675  1.1  jmmv 			}
    676  1.1  jmmv 		}
    677  1.1  jmmv 		if (error) {
    678  1.1  jmmv 			FREE(nfs_pub.np_index, M_TEMP);
    679  1.1  jmmv 			return error;
    680  1.1  jmmv 		}
    681  1.1  jmmv 	}
    682  1.1  jmmv 
    683  1.1  jmmv 	nfs_pub.np_mount = mp;
    684  1.1  jmmv 	nfs_pub.np_valid = 1;
    685  1.1  jmmv 	return 0;
    686  1.1  jmmv }
    687  1.1  jmmv 
    688  1.1  jmmv /*
    689  1.1  jmmv  * Lookup an export entry in the exports list that matches the address
    690  1.1  jmmv  * stored in 'nam'.  If no entry is found, the default one is used instead
    691  1.1  jmmv  * (if available).
    692  1.1  jmmv  */
    693  1.1  jmmv static struct netcred *
    694  1.1  jmmv export_lookup(struct mount *mp, struct netexport *nep, struct mbuf *nam)
    695  1.1  jmmv {
    696  1.1  jmmv 	struct netcred *np;
    697  1.1  jmmv 	struct radix_node_head *rnh;
    698  1.1  jmmv 	struct sockaddr *saddr;
    699  1.1  jmmv 
    700  1.1  jmmv 	np = NULL;
    701  1.1  jmmv 	if (mp->mnt_flag & MNT_EXPORTED) {
    702  1.1  jmmv 		/*
    703  1.1  jmmv 		 * Lookup in the export list first.
    704  1.1  jmmv 		 */
    705  1.1  jmmv 		if (nam != NULL) {
    706  1.1  jmmv 			saddr = mtod(nam, struct sockaddr *);
    707  1.1  jmmv 			rnh = nep->ne_rtable[saddr->sa_family];
    708  1.1  jmmv 			if (rnh != NULL) {
    709  1.1  jmmv 				np = (struct netcred *)
    710  1.1  jmmv 					(*rnh->rnh_matchaddr)((caddr_t)saddr,
    711  1.1  jmmv 							      rnh);
    712  1.1  jmmv 				if (np && np->netc_rnodes->rn_flags & RNF_ROOT)
    713  1.1  jmmv 					np = NULL;
    714  1.1  jmmv 			}
    715  1.1  jmmv 		}
    716  1.1  jmmv 		/*
    717  1.1  jmmv 		 * If no address match, use the default if it exists.
    718  1.1  jmmv 		 */
    719  1.1  jmmv 		if (np == NULL && mp->mnt_flag & MNT_DEFEXPORTED)
    720  1.1  jmmv 			np = &nep->ne_defexported;
    721  1.1  jmmv 	}
    722  1.1  jmmv 	return np;
    723  1.1  jmmv }
    724