2 * Copyright (c) 1999-2004
3 * Stelian Pop <stelian@popies.net>, 1999-2004
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 * 3. Neither the name of the University nor the names of its contributors
14 * may be used to endorse or promote products derived from this software
15 * without specific prior written permission.
17 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
18 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
21 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31 static const char rcsid
[] =
32 "$Id: xattr.c,v 1.5 2008/06/09 13:25:40 stelian Exp $";
36 #include <compatlfs.h>
37 #include <compaterr.h>
38 #include <sys/types.h>
44 #include <bsdcompat.h>
45 #include <protocols/dumprestore.h>
46 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
47 # include <selinux/selinux.h>
51 #include "pathnames.h"
54 * Data structures below taken from the kernel
57 /* Maximum number of references to one attribute block */
58 #define EXT2_XATTR_REFCOUNT_MAX 1024
61 #define EXT2_XATTR_INDEX_MAX 10
62 #define EXT2_XATTR_INDEX_USER 1
63 #define EXT2_XATTR_INDEX_POSIX_ACL_ACCESS 2
64 #define EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT 3
65 #define EXT2_XATTR_INDEX_TRUSTED 4
66 #define EXT2_XATTR_INDEX_LUSTRE 5
67 #define EXT2_XATTR_INDEX_SECURITY 6
69 struct ext2_xattr_header
{
70 u_int32_t h_magic
; /* magic number for identification */
71 u_int32_t h_refcount
; /* reference count */
72 u_int32_t h_blocks
; /* number of disk blocks used */
73 u_int32_t h_hash
; /* hash value of all attributes */
74 u_int32_t h_reserved
[4]; /* zero right now */
77 struct ext3_xattr_ibody_header
{
78 u_int32_t h_magic
; /* magic number for identification */
81 struct ext2_xattr_entry
{
82 u_char e_name_len
; /* length of name */
83 u_char e_name_index
; /* attribute name index */
84 u_int16_t e_value_offs
; /* offset in disk block of value */
85 u_int32_t e_value_block
; /* disk block attribute is stored on (n/i) */
86 u_int32_t e_value_size
; /* size of attribute value */
87 u_int32_t e_hash
; /* hash value of name and value */
88 char e_name
[0]; /* attribute name */
91 #define EXT2_XATTR_PAD_BITS 2
92 #define EXT2_XATTR_PAD (1<<EXT2_XATTR_PAD_BITS)
93 #define EXT2_XATTR_ROUND (EXT2_XATTR_PAD-1)
94 #define EXT2_XATTR_LEN(name_len) \
95 (((name_len) + EXT2_XATTR_ROUND + \
96 sizeof(struct ext2_xattr_entry)) & ~EXT2_XATTR_ROUND)
97 #define EXT2_XATTR_NEXT(entry) \
98 ( (struct ext2_xattr_entry *)( \
99 (char *)(entry) + EXT2_XATTR_LEN((entry)->e_name_len)) )
100 #define EXT3_XATTR_SIZE(size) \
101 (((size) + EXT2_XATTR_ROUND) & ~EXT2_XATTR_ROUND)
103 #define HDR(buffer) ((struct ext2_xattr_header *)(buffer))
104 #define ENTRY(ptr) ((struct ext2_xattr_entry *)(ptr))
105 #define IS_LAST_ENTRY(entry) (*(__u32 *)(entry) == 0)
107 #define BFIRST(buffer) ENTRY(HDR(buffer)+1)
108 #define IFIRST(buffer) ENTRY(((struct ext3_xattr_ibody_header *)(buffer))+1)
110 #define FIRST_ENTRY(buffer) \
111 ((HDR(buffer)->h_magic == EXT2_XATTR_MAGIC2) ? \
116 * On-block xattr value offsets start at the beginning of the block, but
117 * on-inode xattr value offsets start after the initial header
118 * (ext3_xattr_ibody_header).
120 #define VALUE_OFFSET(buffer, entry) \
121 (((HDR(buffer)->h_magic == EXT2_XATTR_MAGIC2) ? \
122 (entry)->e_value_offs + sizeof(struct ext3_xattr_ibody_header) : \
123 (entry)->e_value_offs))
126 * xattr syscalls do not exist yet in libc, get our own copy here,
127 * taken from libattr.
129 #if defined (__i386__)
130 # define HAVE_XATTR_SYSCALLS 1
131 # define __NR_lsetxattr 227
132 # define __NR_lgetxattr 230
133 # define __NR_llistxattr 233
134 #elif defined (__sparc__)
135 # define HAVE_XATTR_SYSCALLS 1
136 # define __NR_lsetxattr 170
137 # define __NR_lgetxattr 173
138 # define __NR_llistxattr 179
139 #elif defined (__ia64__)
140 # define HAVE_XATTR_SYSCALLS 1
141 # define __NR_lsetxattr 1218
142 # define __NR_lgetxattr 1221
143 # define __NR_llistxattr 1224
144 #elif defined (__powerpc__)
145 # define HAVE_XATTR_SYSCALLS 1
146 # define __NR_lsetxattr 210
147 # define __NR_lgetxattr 213
148 # define __NR_llistxattr 216
149 #elif defined (__x86_64__)
150 # define HAVE_XATTR_SYSCALLS 1
151 # define __NR_lsetxattr 189
152 # define __NR_lgetxattr 192
153 # define __NR_llistxattr 195
154 #elif defined (__s390__)
155 # define HAVE_XATTR_SYSCALLS 1
156 # define __NR_lsetxattr 225
157 # define __NR_lgetxattr 228
158 # define __NR_llistxattr 231
159 #elif defined (__arm__)
160 # define HAVE_XATTR_SYSCALLS 1
161 # define __NR_SYSCALL_BASE 0x900000
162 # define __NR_lsetxattr (__NR_SYSCALL_BASE+227)
163 # define __NR_lgetxattr (__NR_SYSCALL_BASE+230)
164 # define __NR_llistxattr (__NR_SYSCALL_BASE+233)
165 #elif defined (__mips64__)
166 # define HAVE_XATTR_SYSCALLS 1
167 # define __NR_Linux 5000
168 # define __NR_lsetxattr (__NR_Linux + 218)
169 # define __NR_lgetxattr (__NR_Linux + 221)
170 # define __NR_llistxattr (__NR_Linux + 224)
171 #elif defined (__mips__)
172 # define HAVE_XATTR_SYSCALLS 1
173 # define __NR_Linux 4000
174 # define __NR_lsetxattr (__NR_Linux + 225)
175 # define __NR_lgetxattr (__NR_Linux + 228)
176 # define __NR_llistxattr (__NR_Linux + 231)
177 #elif defined (__alpha__)
178 # define HAVE_XATTR_SYSCALLS 1
179 # define __NR_lsetxattr 383
180 # define __NR_lgetxattr 386
181 # define __NR_llistxattr 389
182 #elif defined (__mc68000__)
183 # define HAVE_XATTR_SYSCALLS 1
184 # define __NR_lsetxattr 224
185 # define __NR_lgetxattr 227
186 # define __NR_llistxattr 230
188 # warning "Extended attribute syscalls undefined for this architecture"
189 # define HAVE_XATTR_SYSCALLS 0
192 #if HAVE_XATTR_SYSCALLS
193 # define SYSCALL(args...) syscall(args)
195 # define SYSCALL(args...) ( errno = ENOSYS, -1 )
198 static int lsetxattr
__P((const char *, const char *, void *, size_t, int));
199 static ssize_t lgetxattr
__P((const char *, const char *, void *, size_t));
200 static ssize_t llistxattr
__P((const char *, char *, size_t));
201 static int xattr_cb_list
__P((char *, char *, int, int, void *));
202 static int xattr_cb_set
__P((char *, char *, int, int, void *));
203 static int xattr_cb_compare
__P((char *, char *, int, int, void *));
204 static int xattr_verify
__P((char *));
205 static int xattr_count
__P((char *, int *));
206 static int xattr_walk
__P((char *, int (*)(char *, char *, int, int, void *), void *));
209 lsetxattr(const char *path
, const char *name
, void *value
, size_t size
, int flags
)
211 return SYSCALL(__NR_lsetxattr
, path
, name
, value
, size
, flags
);
215 lgetxattr(const char *path
, const char *name
, void *value
, size_t size
)
217 return SYSCALL(__NR_lgetxattr
, path
, name
, value
, size
);
221 llistxattr(const char *path
, char *list
, size_t size
)
223 return SYSCALL(__NR_llistxattr
, path
, list
, size
);
226 #define POSIX_ACL_XATTR_VERSION 0x0002
228 #define ACL_UNDEFINED_ID (-1)
230 #define ACL_USER_OBJ (0x01)
231 #define ACL_USER (0x02)
232 #define ACL_GROUP_OBJ (0x04)
233 #define ACL_GROUP (0x08)
234 #define ACL_MASK (0x10)
235 #define ACL_OTHER (0x20)
241 } posix_acl_xattr_entry
;
245 posix_acl_xattr_entry a_entries
[0];
246 } posix_acl_xattr_header
;
249 posix_acl_xattr_size(int count
)
251 return (sizeof(posix_acl_xattr_header
) +
252 (count
* sizeof(posix_acl_xattr_entry
)));
255 struct posix_acl_entry
{
257 unsigned short e_perm
;
262 unsigned int a_count
;
263 struct posix_acl_entry a_entries
[0];
266 #define EXT3_ACL_VERSION 0x0001
277 } ext3_acl_entry_short
;
283 static inline int ext3_acl_count(size_t size
)
286 size
-= sizeof(ext3_acl_header
);
287 s
= size
- 4 * sizeof(ext3_acl_entry_short
);
289 if (size
% sizeof(ext3_acl_entry_short
))
291 return size
/ sizeof(ext3_acl_entry_short
);
293 if (s
% sizeof(ext3_acl_entry
))
295 return s
/ sizeof(ext3_acl_entry
) + 4;
300 posix_acl_to_xattr(const struct posix_acl
*acl
, void *buffer
, size_t size
) {
301 posix_acl_xattr_header
*ext_acl
= (posix_acl_xattr_header
*)buffer
;
302 posix_acl_xattr_entry
*ext_entry
= ext_acl
->a_entries
;
305 real_size
= posix_acl_xattr_size(acl
->a_count
);
308 if (real_size
> size
) {
309 fprintf(stderr
, "ACL: not enough space to convert (%d %d)\n", real_size
, size
);
313 ext_acl
->a_version
= POSIX_ACL_XATTR_VERSION
;
314 #if BYTE_ORDER == BIG_ENDIAN
315 swabst("1i", (u_char
*)ext_acl
);
318 for (n
=0; n
< acl
->a_count
; n
++, ext_entry
++) {
319 ext_entry
->e_tag
= acl
->a_entries
[n
].e_tag
;
320 ext_entry
->e_perm
= acl
->a_entries
[n
].e_perm
;
321 ext_entry
->e_id
= acl
->a_entries
[n
].e_id
;
322 #if BYTE_ORDER == BIG_ENDIAN
323 swabst("2s1i", (u_char
*)ext_entry
);
329 static struct posix_acl
*
330 ext3_acl_from_disk(const void *value
, size_t size
)
332 const char *end
= (char *)value
+ size
;
334 struct posix_acl
*acl
;
338 if (size
< sizeof(ext3_acl_header
)) {
339 fprintf(stderr
, "ACL size too little\n");
342 #if BYTE_ORDER == BIG_ENDIAN
343 swabst("1i", (u_char
*)value
);
345 if (((ext3_acl_header
*)value
)->a_version
!= EXT3_ACL_VERSION
) {
346 fprintf(stderr
, "ACL version unknown\n");
349 value
= (char *)value
+ sizeof(ext3_acl_header
);
350 count
= ext3_acl_count(size
);
352 fprintf(stderr
, "ACL bad count\n");
357 acl
= malloc(sizeof(struct posix_acl
) + count
* sizeof(struct posix_acl_entry
));
359 fprintf(stderr
, "ACL malloc failed\n");
362 acl
->a_count
= count
;
364 for (n
=0; n
< count
; n
++) {
365 ext3_acl_entry
*entry
= (ext3_acl_entry
*)value
;
366 #if BYTE_ORDER == BIG_ENDIAN
367 swabst("2s", (u_char
*)entry
);
369 if ((char *)value
+ sizeof(ext3_acl_entry_short
) > end
)
371 acl
->a_entries
[n
].e_tag
= entry
->e_tag
;
372 acl
->a_entries
[n
].e_perm
= entry
->e_perm
;
373 switch(acl
->a_entries
[n
].e_tag
) {
378 value
= (char *)value
+ sizeof(ext3_acl_entry_short
);
379 acl
->a_entries
[n
].e_id
= ACL_UNDEFINED_ID
;
384 #if BYTE_ORDER == BIG_ENDIAN
385 swabst("4b1i", (u_char
*)entry
);
387 value
= (char *)value
+ sizeof(ext3_acl_entry
);
388 if ((char *)value
> end
)
390 acl
->a_entries
[n
].e_id
= entry
->e_id
;
402 fprintf(stderr
, "ACL bad entry\n");
408 * Dump code starts here :)
412 xattr_cb_list(char *name
, char *value
, int valuelen
, int isSELinux
, void *private)
415 value
[valuelen
] = '\0';
416 printf("EA: %s:%s\n", name
, value
);
422 xattr_cb_set(char *name
, char *value
, int valuelen
, int isSELinux
, void *private)
424 char *path
= (char *)private;
428 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
430 err
= lsetfilecon(path
, value
);
433 err
= lsetxattr(path
, name
, value
, valuelen
, 0);
436 warn("%s: EA set %s:%s failed", path
, name
, value
);
444 xattr_cb_compare(char *name
, char *value
, int valuelen
, int isSELinux
, void *private)
446 char *path
= (char *)private;
447 char valuef
[XATTR_MAXSIZE
];
451 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
454 security_context_t con
= NULL
;
456 if (lgetfilecon(path
, &con
) < 0) {
457 warn("%s: EA compare lgetfilecon failed\n", path
);
461 valuesz
= strlen(con
) + 1;
463 strncat(valuef
, con
, sizeof valuef
);
468 valuesz
= lgetxattr(path
, name
, valuef
, XATTR_MAXSIZE
);
470 warn("%s: EA compare lgetxattr failed\n", path
);
473 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
477 if (valuesz
!= valuelen
|| memcmp(value
, valuef
, valuelen
)) {
478 /* GAN24May06: show name and new value for user to compare */
479 fprintf(stderr
, "%s: EA %s:%s value changed to %s\n", path
, name
, value
, valuef
);
487 xattr_verify(char *buffer
)
489 struct ext2_xattr_entry
*entry
;
492 end
= buffer
+ XATTR_MAXSIZE
;
494 #if BYTE_ORDER == BIG_ENDIAN
495 swabst("4i", (u_char
*)buffer
);
498 if (HDR(buffer
)->h_magic
!= EXT2_XATTR_MAGIC
&&
499 HDR(buffer
)->h_magic
!= EXT2_XATTR_MAGIC2
) {
500 fprintf(stderr
, "error in EA block 1\n");
501 fprintf(stderr
, "magic = %x\n", HDR(buffer
)->h_magic
);
506 /* check the on-disk data structure */
507 entry
= FIRST_ENTRY(buffer
);
508 #if BYTE_ORDER == BIG_ENDIAN
509 swabst("2b1s3i", (u_char
*)entry
);
511 while (!IS_LAST_ENTRY(entry
)) {
512 struct ext2_xattr_entry
*next
= EXT2_XATTR_NEXT(entry
);
514 if ((char *)next
>= end
) {
515 fprintf(stderr
, "error in EA block\n");
519 #if BYTE_ORDER == BIG_ENDIAN
520 swabst("2b1s3i", (u_char
*)entry
);
527 xattr_count(char *buffer
, int *count
)
529 struct ext2_xattr_entry
*entry
;
532 /* list the attribute names */
533 for (entry
= FIRST_ENTRY(buffer
); !IS_LAST_ENTRY(entry
);
534 entry
= EXT2_XATTR_NEXT(entry
))
542 xattr_walk(char *buffer
, int (*xattr_cb
)(char *, char *, int, int, void *), void *private)
544 struct ext2_xattr_entry
*entry
;
546 /* list the attribute names */
547 for (entry
= FIRST_ENTRY(buffer
); !IS_LAST_ENTRY(entry
);
548 entry
= EXT2_XATTR_NEXT(entry
)) {
549 char name
[XATTR_MAXSIZE
], value
[XATTR_MAXSIZE
];
555 switch (entry
->e_name_index
) {
556 case EXT2_XATTR_INDEX_USER
:
557 strcpy(name
, "user.");
559 case EXT2_XATTR_INDEX_POSIX_ACL_ACCESS
:
560 strcpy(name
, "system.posix_acl_access");
563 case EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT
:
564 strcpy(name
, "system.posix_acl_default");
567 case EXT2_XATTR_INDEX_TRUSTED
:
568 strcpy(name
, "trusted.");
570 case EXT2_XATTR_INDEX_LUSTRE
:
571 strcpy(name
, "lustre.");
573 case EXT2_XATTR_INDEX_SECURITY
:
574 strcpy(name
, "security.");
575 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
576 convertcon
= transselinuxflag
;
580 fprintf(stderr
, "Unknown EA index\n");
585 memcpy(name
+ off
, entry
->e_name
, entry
->e_name_len
);
586 name
[off
+ entry
->e_name_len
] = '\0';
587 size
= entry
->e_value_size
;
589 memcpy(value
, buffer
+ VALUE_OFFSET(buffer
, entry
), size
);
592 struct posix_acl
*acl
;
594 acl
= ext3_acl_from_disk(value
, size
);
597 size
= posix_acl_to_xattr(acl
, value
, XATTR_MAXSIZE
);
603 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
604 if (convertcon
&& strcmp(name
, "security.selinux"))
605 convertcon
= 0; /*GAN24May06 only for selinux */
609 security_context_t con
= NULL
;
612 if (!transselinuxarg
)
613 err
= security_canonicalize_context(value
, &con
);
615 strncat(value
, transselinuxarg
, sizeof value
);
616 err
= security_canonicalize_context_raw(value
, &con
);
620 warn("%s: EA canonicalize failed\n", value
);
624 size
= strlen(con
) + 1;
626 strncat(value
, con
, sizeof value
);
631 if (xattr_cb(name
, value
, size
, convertcon
, private) != GOOD
)
639 xattr_compare(char *path
, char *buffer
)
642 char *names
= NULL
, *end_names
, *name
;
644 countf
= llistxattr(path
, NULL
, 0);
646 warn("%s: llistxattr failed", path
);
650 names
= malloc(countf
+ 1);
652 warn("%s: llistxattr failed", path
);
656 countf
= llistxattr(path
, names
, countf
);
658 warn("%s: llistxattr failed", path
);
663 names
[countf
] = '\0';
664 end_names
= names
+ countf
;
667 for (name
= names
; name
!= end_names
; name
= strchr(name
, '\0') + 1) {
676 if (xattr_verify(buffer
) == FAIL
)
679 if (xattr_count(buffer
, &countt
) == FAIL
)
685 if (countf
!= countt
) {
686 fprintf(stderr
, "%s: EA count changed from %d to %d\n", path
, countt
, countf
);
693 return xattr_walk(buffer
, xattr_cb_compare
, path
);
697 xattr_extract(char *path
, char *buffer
)
700 fprintf(stderr
, "xattr_extract(%s)\n", path
);
701 xattr_walk(buffer
, xattr_cb_list
, NULL
);
704 if (xattr_verify(buffer
) == FAIL
)
707 return xattr_walk(buffer
, xattr_cb_set
, path
);