2 * Copyright (c) 1999-2004
3 * Stelian Pop <stelian@popies.net>, 1999-2004
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 * 3. Neither the name of the University nor the names of its contributors
14 * may be used to endorse or promote products derived from this software
15 * without specific prior written permission.
17 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
18 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
21 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31 static const char rcsid[] =
32 "$Id: xattr.c,v 1.5 2008/06/09 13:25:40 stelian Exp $";
36 #include <compatlfs.h>
37 #include <compaterr.h>
38 #include <sys/types.h>
44 #include <bsdcompat.h>
45 #include <protocols/dumprestore.h>
46 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
47 # include <selinux/selinux.h>
51 #include "pathnames.h"
54 * Data structures below taken from the kernel
57 /* Maximum number of references to one attribute block */
58 #define EXT2_XATTR_REFCOUNT_MAX 1024
61 #define EXT2_XATTR_INDEX_MAX 10
62 #define EXT2_XATTR_INDEX_USER 1
63 #define EXT2_XATTR_INDEX_POSIX_ACL_ACCESS 2
64 #define EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT 3
65 #define EXT2_XATTR_INDEX_TRUSTED 4
66 #define EXT2_XATTR_INDEX_LUSTRE 5
67 #define EXT2_XATTR_INDEX_SECURITY 6
69 struct ext2_xattr_header {
70 u_int32_t h_magic; /* magic number for identification */
71 u_int32_t h_refcount; /* reference count */
72 u_int32_t h_blocks; /* number of disk blocks used */
73 u_int32_t h_hash; /* hash value of all attributes */
74 u_int32_t h_reserved[4]; /* zero right now */
77 struct ext3_xattr_ibody_header {
78 u_int32_t h_magic; /* magic number for identification */
81 struct ext2_xattr_entry {
82 u_char e_name_len; /* length of name */
83 u_char e_name_index; /* attribute name index */
84 u_int16_t e_value_offs; /* offset in disk block of value */
85 u_int32_t e_value_block; /* disk block attribute is stored on (n/i) */
86 u_int32_t e_value_size; /* size of attribute value */
87 u_int32_t e_hash; /* hash value of name and value */
88 char e_name[0]; /* attribute name */
91 #define EXT2_XATTR_PAD_BITS 2
92 #define EXT2_XATTR_PAD (1<<EXT2_XATTR_PAD_BITS)
93 #define EXT2_XATTR_ROUND (EXT2_XATTR_PAD-1)
94 #define EXT2_XATTR_LEN(name_len) \
95 (((name_len) + EXT2_XATTR_ROUND + \
96 sizeof(struct ext2_xattr_entry)) & ~EXT2_XATTR_ROUND)
97 #define EXT2_XATTR_NEXT(entry) \
98 ( (struct ext2_xattr_entry *)( \
99 (char *)(entry) + EXT2_XATTR_LEN((entry)->e_name_len)) )
100 #define EXT3_XATTR_SIZE(size) \
101 (((size) + EXT2_XATTR_ROUND) & ~EXT2_XATTR_ROUND)
103 #define HDR(buffer) ((struct ext2_xattr_header *)(buffer))
104 #define ENTRY(ptr) ((struct ext2_xattr_entry *)(ptr))
105 #define IS_LAST_ENTRY(entry) (*(__u32 *)(entry) == 0)
107 #define BFIRST(buffer) ENTRY(HDR(buffer)+1)
108 #define IFIRST(buffer) ENTRY(((struct ext3_xattr_ibody_header *)(buffer))+1)
110 #define FIRST_ENTRY(buffer) \
111 ((HDR(buffer)->h_magic == EXT2_XATTR_MAGIC2) ? \
116 * On-block xattr value offsets start at the beginning of the block, but
117 * on-inode xattr value offsets start after the initial header
118 * (ext3_xattr_ibody_header).
120 #define VALUE_OFFSET(buffer, entry) \
121 (((HDR(buffer)->h_magic == EXT2_XATTR_MAGIC2) ? \
122 (entry)->e_value_offs + sizeof(struct ext3_xattr_ibody_header) : \
123 (entry)->e_value_offs))
126 * xattr syscalls do not exist yet in libc, get our own copy here,
127 * taken from libattr.
129 #if defined (__i386__)
130 # define HAVE_XATTR_SYSCALLS 1
131 # define __NR_lsetxattr 227
132 # define __NR_lgetxattr 230
133 # define __NR_llistxattr 233
134 #elif defined (__sparc__)
135 # define HAVE_XATTR_SYSCALLS 1
136 # define __NR_lsetxattr 170
137 # define __NR_lgetxattr 173
138 # define __NR_llistxattr 179
139 #elif defined (__ia64__)
140 # define HAVE_XATTR_SYSCALLS 1
141 # define __NR_lsetxattr 1218
142 # define __NR_lgetxattr 1221
143 # define __NR_llistxattr 1224
144 #elif defined (__powerpc__)
145 # define HAVE_XATTR_SYSCALLS 1
146 # define __NR_lsetxattr 210
147 # define __NR_lgetxattr 213
148 # define __NR_llistxattr 216
149 #elif defined (__x86_64__)
150 # define HAVE_XATTR_SYSCALLS 1
151 # define __NR_lsetxattr 189
152 # define __NR_lgetxattr 192
153 # define __NR_llistxattr 195
154 #elif defined (__s390__)
155 # define HAVE_XATTR_SYSCALLS 1
156 # define __NR_lsetxattr 225
157 # define __NR_lgetxattr 228
158 # define __NR_llistxattr 231
159 #elif defined (__arm__)
160 # define HAVE_XATTR_SYSCALLS 1
161 # define __NR_SYSCALL_BASE 0x900000
162 # define __NR_lsetxattr (__NR_SYSCALL_BASE+227)
163 # define __NR_lgetxattr (__NR_SYSCALL_BASE+230)
164 # define __NR_llistxattr (__NR_SYSCALL_BASE+233)
165 #elif defined (__mips64__)
166 # define HAVE_XATTR_SYSCALLS 1
167 # define __NR_Linux 5000
168 # define __NR_lsetxattr (__NR_Linux + 218)
169 # define __NR_lgetxattr (__NR_Linux + 221)
170 # define __NR_llistxattr (__NR_Linux + 224)
171 #elif defined (__mips__)
172 # define HAVE_XATTR_SYSCALLS 1
173 # define __NR_Linux 4000
174 # define __NR_lsetxattr (__NR_Linux + 225)
175 # define __NR_lgetxattr (__NR_Linux + 228)
176 # define __NR_llistxattr (__NR_Linux + 231)
177 #elif defined (__alpha__)
178 # define HAVE_XATTR_SYSCALLS 1
179 # define __NR_lsetxattr 383
180 # define __NR_lgetxattr 386
181 # define __NR_llistxattr 389
182 #elif defined (__mc68000__)
183 # define HAVE_XATTR_SYSCALLS 1
184 # define __NR_lsetxattr 224
185 # define __NR_lgetxattr 227
186 # define __NR_llistxattr 230
188 # warning "Extended attribute syscalls undefined for this architecture"
189 # define HAVE_XATTR_SYSCALLS 0
192 #if HAVE_XATTR_SYSCALLS
193 # define SYSCALL(args...) syscall(args)
195 # define SYSCALL(args...) ( errno = ENOSYS, -1 )
198 static int lsetxattr __P((const char *, const char *, void *, size_t, int));
199 static ssize_t lgetxattr __P((const char *, const char *, void *, size_t));
200 static ssize_t llistxattr __P((const char *, char *, size_t));
201 static int xattr_cb_list __P((char *, char *, int, int, void *));
202 static int xattr_cb_set __P((char *, char *, int, int, void *));
203 static int xattr_cb_compare __P((char *, char *, int, int, void *));
204 static int xattr_verify __P((char *));
205 static int xattr_count __P((char *, int *));
206 static int xattr_walk __P((char *, int (*)(char *, char *, int, int, void *), void *));
209 lsetxattr(const char *path, const char *name, void *value, size_t size, int flags)
211 return SYSCALL(__NR_lsetxattr, path, name, value, size, flags);
215 lgetxattr(const char *path, const char *name, void *value, size_t size)
217 return SYSCALL(__NR_lgetxattr, path, name, value, size);
221 llistxattr(const char *path, char *list, size_t size)
223 return SYSCALL(__NR_llistxattr, path, list, size);
226 #define POSIX_ACL_XATTR_VERSION 0x0002
228 #define ACL_UNDEFINED_ID (-1)
230 #define ACL_USER_OBJ (0x01)
231 #define ACL_USER (0x02)
232 #define ACL_GROUP_OBJ (0x04)
233 #define ACL_GROUP (0x08)
234 #define ACL_MASK (0x10)
235 #define ACL_OTHER (0x20)
241 } posix_acl_xattr_entry;
245 posix_acl_xattr_entry a_entries[0];
246 } posix_acl_xattr_header;
249 posix_acl_xattr_size(int count)
251 return (sizeof(posix_acl_xattr_header) +
252 (count * sizeof(posix_acl_xattr_entry)));
255 struct posix_acl_entry {
257 unsigned short e_perm;
262 unsigned int a_count;
263 struct posix_acl_entry a_entries[0];
266 #define EXT3_ACL_VERSION 0x0001
277 } ext3_acl_entry_short;
283 static inline int ext3_acl_count(size_t size)
286 size -= sizeof(ext3_acl_header);
287 s = size - 4 * sizeof(ext3_acl_entry_short);
289 if (size % sizeof(ext3_acl_entry_short))
291 return size / sizeof(ext3_acl_entry_short);
293 if (s % sizeof(ext3_acl_entry))
295 return s / sizeof(ext3_acl_entry) + 4;
300 posix_acl_to_xattr(const struct posix_acl *acl, void *buffer, size_t size) {
301 posix_acl_xattr_header *ext_acl = (posix_acl_xattr_header *)buffer;
302 posix_acl_xattr_entry *ext_entry = ext_acl->a_entries;
305 real_size = posix_acl_xattr_size(acl->a_count);
308 if (real_size > size) {
309 fprintf(stderr, "ACL: not enough space to convert (%d %d)\n", real_size, size);
313 ext_acl->a_version = POSIX_ACL_XATTR_VERSION;
314 #if BYTE_ORDER == BIG_ENDIAN
315 swabst("1i", (u_char *)ext_acl);
318 for (n=0; n < acl->a_count; n++, ext_entry++) {
319 ext_entry->e_tag = acl->a_entries[n].e_tag;
320 ext_entry->e_perm = acl->a_entries[n].e_perm;
321 ext_entry->e_id = acl->a_entries[n].e_id;
322 #if BYTE_ORDER == BIG_ENDIAN
323 swabst("2s1i", (u_char *)ext_entry);
329 static struct posix_acl *
330 ext3_acl_from_disk(const void *value, size_t size)
332 const char *end = (char *)value + size;
334 struct posix_acl *acl;
338 if (size < sizeof(ext3_acl_header)) {
339 fprintf(stderr, "ACL size too little\n");
342 #if BYTE_ORDER == BIG_ENDIAN
343 swabst("1i", (u_char *)value);
345 if (((ext3_acl_header *)value)->a_version != EXT3_ACL_VERSION) {
346 fprintf(stderr, "ACL version unknown\n");
349 value = (char *)value + sizeof(ext3_acl_header);
350 count = ext3_acl_count(size);
352 fprintf(stderr, "ACL bad count\n");
357 acl = malloc(sizeof(struct posix_acl) + count * sizeof(struct posix_acl_entry));
359 fprintf(stderr, "ACL malloc failed\n");
362 acl->a_count = count;
364 for (n=0; n < count; n++) {
365 ext3_acl_entry *entry = (ext3_acl_entry *)value;
366 #if BYTE_ORDER == BIG_ENDIAN
367 swabst("2s", (u_char *)entry);
369 if ((char *)value + sizeof(ext3_acl_entry_short) > end)
371 acl->a_entries[n].e_tag = entry->e_tag;
372 acl->a_entries[n].e_perm = entry->e_perm;
373 switch(acl->a_entries[n].e_tag) {
378 value = (char *)value + sizeof(ext3_acl_entry_short);
379 acl->a_entries[n].e_id = ACL_UNDEFINED_ID;
384 #if BYTE_ORDER == BIG_ENDIAN
385 swabst("4b1i", (u_char *)entry);
387 value = (char *)value + sizeof(ext3_acl_entry);
388 if ((char *)value > end)
390 acl->a_entries[n].e_id = entry->e_id;
402 fprintf(stderr, "ACL bad entry\n");
408 * Dump code starts here :)
412 xattr_cb_list(char *name, char *value, int valuelen, int isSELinux, void *private)
415 value[valuelen] = '\0';
416 printf("EA: %s:%s\n", name, value);
422 xattr_cb_set(char *name, char *value, int valuelen, int isSELinux, void *private)
424 char *path = (char *)private;
428 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
430 err = lsetfilecon(path, value);
433 err = lsetxattr(path, name, value, valuelen, 0);
436 warn("%s: EA set %s:%s failed", path, name, value);
444 xattr_cb_compare(char *name, char *value, int valuelen, int isSELinux, void *private)
446 char *path = (char *)private;
447 char valuef[XATTR_MAXSIZE];
451 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
454 security_context_t con = NULL;
456 if (lgetfilecon(path, &con) < 0) {
457 warn("%s: EA compare lgetfilecon failed\n", path);
461 valuesz = strlen(con) + 1;
463 strncat(valuef, con, sizeof valuef);
468 valuesz = lgetxattr(path, name, valuef, XATTR_MAXSIZE);
470 warn("%s: EA compare lgetxattr failed\n", path);
473 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
477 if (valuesz != valuelen || memcmp(value, valuef, valuelen)) {
478 /* GAN24May06: show name and new value for user to compare */
479 fprintf(stderr, "%s: EA %s:%s value changed to %s\n", path, name, value, valuef);
487 xattr_verify(char *buffer)
489 struct ext2_xattr_entry *entry;
492 end = buffer + XATTR_MAXSIZE;
494 #if BYTE_ORDER == BIG_ENDIAN
495 swabst("4i", (u_char *)buffer);
498 if (HDR(buffer)->h_magic != EXT2_XATTR_MAGIC &&
499 HDR(buffer)->h_magic != EXT2_XATTR_MAGIC2) {
500 fprintf(stderr, "error in EA block 1\n");
501 fprintf(stderr, "magic = %x\n", HDR(buffer)->h_magic);
506 /* check the on-disk data structure */
507 entry = FIRST_ENTRY(buffer);
508 #if BYTE_ORDER == BIG_ENDIAN
509 swabst("2b1s3i", (u_char *)entry);
511 while (!IS_LAST_ENTRY(entry)) {
512 struct ext2_xattr_entry *next = EXT2_XATTR_NEXT(entry);
514 if ((char *)next >= end) {
515 fprintf(stderr, "error in EA block\n");
519 #if BYTE_ORDER == BIG_ENDIAN
520 swabst("2b1s3i", (u_char *)entry);
527 xattr_count(char *buffer, int *count)
529 struct ext2_xattr_entry *entry;
532 /* list the attribute names */
533 for (entry = FIRST_ENTRY(buffer); !IS_LAST_ENTRY(entry);
534 entry = EXT2_XATTR_NEXT(entry))
542 xattr_walk(char *buffer, int (*xattr_cb)(char *, char *, int, int, void *), void *private)
544 struct ext2_xattr_entry *entry;
546 /* list the attribute names */
547 for (entry = FIRST_ENTRY(buffer); !IS_LAST_ENTRY(entry);
548 entry = EXT2_XATTR_NEXT(entry)) {
549 char name[XATTR_MAXSIZE], value[XATTR_MAXSIZE];
555 switch (entry->e_name_index) {
556 case EXT2_XATTR_INDEX_USER:
557 strcpy(name, "user.");
559 case EXT2_XATTR_INDEX_POSIX_ACL_ACCESS:
560 strcpy(name, "system.posix_acl_access");
563 case EXT2_XATTR_INDEX_POSIX_ACL_DEFAULT:
564 strcpy(name, "system.posix_acl_default");
567 case EXT2_XATTR_INDEX_TRUSTED:
568 strcpy(name, "trusted.");
570 case EXT2_XATTR_INDEX_LUSTRE:
571 strcpy(name, "lustre.");
573 case EXT2_XATTR_INDEX_SECURITY:
574 strcpy(name, "security.");
575 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
576 convertcon = transselinuxflag;
580 fprintf(stderr, "Unknown EA index\n");
585 memcpy(name + off, entry->e_name, entry->e_name_len);
586 name[off + entry->e_name_len] = '\0';
587 size = entry->e_value_size;
589 memcpy(value, buffer + VALUE_OFFSET(buffer, entry), size);
592 struct posix_acl *acl;
594 acl = ext3_acl_from_disk(value, size);
597 size = posix_acl_to_xattr(acl, value, XATTR_MAXSIZE);
603 #ifdef TRANSSELINUX /*GAN6May06 SELinux MLS */
604 if (convertcon && strcmp(name, "security.selinux"))
605 convertcon = 0; /*GAN24May06 only for selinux */
609 security_context_t con = NULL;
612 if (!transselinuxarg)
613 err = security_canonicalize_context(value, &con);
615 strncat(value, transselinuxarg, sizeof value);
616 err = security_canonicalize_context_raw(value, &con);
620 warn("%s: EA canonicalize failed\n", value);
624 size = strlen(con) + 1;
626 strncat(value, con, sizeof value);
631 if (xattr_cb(name, value, size, convertcon, private) != GOOD)
639 xattr_compare(char *path, char *buffer)
642 char *names = NULL, *end_names, *name;
644 countf = llistxattr(path, NULL, 0);
646 warn("%s: llistxattr failed", path);
650 names = malloc(countf + 1);
652 warn("%s: llistxattr failed", path);
656 countf = llistxattr(path, names, countf);
658 warn("%s: llistxattr failed", path);
663 names[countf] = '\0';
664 end_names = names + countf;
667 for (name = names; name != end_names; name = strchr(name, '\0') + 1) {
676 if (xattr_verify(buffer) == FAIL)
679 if (xattr_count(buffer, &countt) == FAIL)
685 if (countf != countt) {
686 fprintf(stderr, "%s: EA count changed from %d to %d\n", path, countt, countf);
693 return xattr_walk(buffer, xattr_cb_compare, path);
697 xattr_extract(char *path, char *buffer)
700 fprintf(stderr, "xattr_extract(%s)\n", path);
701 xattr_walk(buffer, xattr_cb_list, NULL);
704 if (xattr_verify(buffer) == FAIL)
707 return xattr_walk(buffer, xattr_cb_set, path);