nfsd: Avoid taking state_lock while holding inode lock in nfsd_break_one_deleg
[pandora-kernel.git] / fs / nfsd / nfs4state.c
1 /*
2 *  Copyright (c) 2001 The Regents of the University of Michigan.
3 *  All rights reserved.
4 *
5 *  Kendrick Smith <kmsmith@umich.edu>
6 *  Andy Adamson <kandros@umich.edu>
7 *
8 *  Redistribution and use in source and binary forms, with or without
9 *  modification, are permitted provided that the following conditions
10 *  are met:
11 *
12 *  1. Redistributions of source code must retain the above copyright
13 *     notice, this list of conditions and the following disclaimer.
14 *  2. Redistributions in binary form must reproduce the above copyright
15 *     notice, this list of conditions and the following disclaimer in the
16 *     documentation and/or other materials provided with the distribution.
17 *  3. Neither the name of the University nor the names of its
18 *     contributors may be used to endorse or promote products derived
19 *     from this software without specific prior written permission.
20 *
21 *  THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
22 *  WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
23 *  MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
24 *  DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
25 *  FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26 *  CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27 *  SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28 *  BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
29 *  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
30 *  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
31 *  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32 *
33 */
34
35 #include <linux/file.h>
36 #include <linux/fs.h>
37 #include <linux/slab.h>
38 #include <linux/namei.h>
39 #include <linux/swap.h>
40 #include <linux/pagemap.h>
41 #include <linux/ratelimit.h>
42 #include <linux/sunrpc/svcauth_gss.h>
43 #include <linux/sunrpc/addr.h>
44 #include <linux/hash.h>
45 #include "xdr4.h"
46 #include "xdr4cb.h"
47 #include "vfs.h"
48 #include "current_stateid.h"
49
50 #include "netns.h"
51
52 #define NFSDDBG_FACILITY                NFSDDBG_PROC
53
54 #define all_ones {{~0,~0},~0}
55 static const stateid_t one_stateid = {
56         .si_generation = ~0,
57         .si_opaque = all_ones,
58 };
59 static const stateid_t zero_stateid = {
60         /* all fields zero */
61 };
62 static const stateid_t currentstateid = {
63         .si_generation = 1,
64 };
65
66 static u64 current_sessionid = 1;
67
68 #define ZERO_STATEID(stateid) (!memcmp((stateid), &zero_stateid, sizeof(stateid_t)))
69 #define ONE_STATEID(stateid)  (!memcmp((stateid), &one_stateid, sizeof(stateid_t)))
70 #define CURRENT_STATEID(stateid) (!memcmp((stateid), &currentstateid, sizeof(stateid_t)))
71
72 /* forward declarations */
73 static int check_for_locks(struct nfs4_file *filp, struct nfs4_lockowner *lowner);
74
75 /* Locking: */
76
77 /* Currently used for almost all code touching nfsv4 state: */
78 static DEFINE_MUTEX(client_mutex);
79
80 /*
81  * Currently used for the del_recall_lru and file hash table.  In an
82  * effort to decrease the scope of the client_mutex, this spinlock may
83  * eventually cover more:
84  */
85 static DEFINE_SPINLOCK(state_lock);
86
87 static struct kmem_cache *openowner_slab;
88 static struct kmem_cache *lockowner_slab;
89 static struct kmem_cache *file_slab;
90 static struct kmem_cache *stateid_slab;
91 static struct kmem_cache *deleg_slab;
92
93 void
94 nfs4_lock_state(void)
95 {
96         mutex_lock(&client_mutex);
97 }
98
99 static void free_session(struct nfsd4_session *);
100
101 static bool is_session_dead(struct nfsd4_session *ses)
102 {
103         return ses->se_flags & NFS4_SESSION_DEAD;
104 }
105
106 static __be32 mark_session_dead_locked(struct nfsd4_session *ses, int ref_held_by_me)
107 {
108         if (atomic_read(&ses->se_ref) > ref_held_by_me)
109                 return nfserr_jukebox;
110         ses->se_flags |= NFS4_SESSION_DEAD;
111         return nfs_ok;
112 }
113
114 void
115 nfs4_unlock_state(void)
116 {
117         mutex_unlock(&client_mutex);
118 }
119
120 static bool is_client_expired(struct nfs4_client *clp)
121 {
122         return clp->cl_time == 0;
123 }
124
125 static __be32 mark_client_expired_locked(struct nfs4_client *clp)
126 {
127         if (atomic_read(&clp->cl_refcount))
128                 return nfserr_jukebox;
129         clp->cl_time = 0;
130         return nfs_ok;
131 }
132
133 static __be32 mark_client_expired(struct nfs4_client *clp)
134 {
135         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
136         __be32 ret;
137
138         spin_lock(&nn->client_lock);
139         ret = mark_client_expired_locked(clp);
140         spin_unlock(&nn->client_lock);
141         return ret;
142 }
143
144 static __be32 get_client_locked(struct nfs4_client *clp)
145 {
146         if (is_client_expired(clp))
147                 return nfserr_expired;
148         atomic_inc(&clp->cl_refcount);
149         return nfs_ok;
150 }
151
152 /* must be called under the client_lock */
153 static inline void
154 renew_client_locked(struct nfs4_client *clp)
155 {
156         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
157
158         if (is_client_expired(clp)) {
159                 WARN_ON(1);
160                 printk("%s: client (clientid %08x/%08x) already expired\n",
161                         __func__,
162                         clp->cl_clientid.cl_boot,
163                         clp->cl_clientid.cl_id);
164                 return;
165         }
166
167         dprintk("renewing client (clientid %08x/%08x)\n",
168                         clp->cl_clientid.cl_boot,
169                         clp->cl_clientid.cl_id);
170         list_move_tail(&clp->cl_lru, &nn->client_lru);
171         clp->cl_time = get_seconds();
172 }
173
174 static inline void
175 renew_client(struct nfs4_client *clp)
176 {
177         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
178
179         spin_lock(&nn->client_lock);
180         renew_client_locked(clp);
181         spin_unlock(&nn->client_lock);
182 }
183
184 static void put_client_renew_locked(struct nfs4_client *clp)
185 {
186         if (!atomic_dec_and_test(&clp->cl_refcount))
187                 return;
188         if (!is_client_expired(clp))
189                 renew_client_locked(clp);
190 }
191
192 static void put_client_renew(struct nfs4_client *clp)
193 {
194         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
195
196         if (!atomic_dec_and_lock(&clp->cl_refcount, &nn->client_lock))
197                 return;
198         if (!is_client_expired(clp))
199                 renew_client_locked(clp);
200         spin_unlock(&nn->client_lock);
201 }
202
203 static __be32 nfsd4_get_session_locked(struct nfsd4_session *ses)
204 {
205         __be32 status;
206
207         if (is_session_dead(ses))
208                 return nfserr_badsession;
209         status = get_client_locked(ses->se_client);
210         if (status)
211                 return status;
212         atomic_inc(&ses->se_ref);
213         return nfs_ok;
214 }
215
216 static void nfsd4_put_session_locked(struct nfsd4_session *ses)
217 {
218         struct nfs4_client *clp = ses->se_client;
219
220         if (atomic_dec_and_test(&ses->se_ref) && is_session_dead(ses))
221                 free_session(ses);
222         put_client_renew_locked(clp);
223 }
224
225 static void nfsd4_put_session(struct nfsd4_session *ses)
226 {
227         struct nfs4_client *clp = ses->se_client;
228         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
229
230         spin_lock(&nn->client_lock);
231         nfsd4_put_session_locked(ses);
232         spin_unlock(&nn->client_lock);
233 }
234
235
236 static inline u32
237 opaque_hashval(const void *ptr, int nbytes)
238 {
239         unsigned char *cptr = (unsigned char *) ptr;
240
241         u32 x = 0;
242         while (nbytes--) {
243                 x *= 37;
244                 x += *cptr++;
245         }
246         return x;
247 }
248
249 static void nfsd4_free_file(struct nfs4_file *f)
250 {
251         kmem_cache_free(file_slab, f);
252 }
253
254 static inline void
255 put_nfs4_file(struct nfs4_file *fi)
256 {
257         might_lock(&state_lock);
258
259         if (atomic_dec_and_lock(&fi->fi_ref, &state_lock)) {
260                 hlist_del(&fi->fi_hash);
261                 spin_unlock(&state_lock);
262                 iput(fi->fi_inode);
263                 nfsd4_free_file(fi);
264         }
265 }
266
267 static inline void
268 get_nfs4_file(struct nfs4_file *fi)
269 {
270         atomic_inc(&fi->fi_ref);
271 }
272
273 static struct file *
274 __nfs4_get_fd(struct nfs4_file *f, int oflag)
275 {
276         if (f->fi_fds[oflag])
277                 return get_file(f->fi_fds[oflag]);
278         return NULL;
279 }
280
281 static struct file *
282 find_writeable_file_locked(struct nfs4_file *f)
283 {
284         struct file *ret;
285
286         lockdep_assert_held(&f->fi_lock);
287
288         ret = __nfs4_get_fd(f, O_WRONLY);
289         if (!ret)
290                 ret = __nfs4_get_fd(f, O_RDWR);
291         return ret;
292 }
293
294 static struct file *
295 find_writeable_file(struct nfs4_file *f)
296 {
297         struct file *ret;
298
299         spin_lock(&f->fi_lock);
300         ret = find_writeable_file_locked(f);
301         spin_unlock(&f->fi_lock);
302
303         return ret;
304 }
305
306 static struct file *find_readable_file_locked(struct nfs4_file *f)
307 {
308         struct file *ret;
309
310         lockdep_assert_held(&f->fi_lock);
311
312         ret = __nfs4_get_fd(f, O_RDONLY);
313         if (!ret)
314                 ret = __nfs4_get_fd(f, O_RDWR);
315         return ret;
316 }
317
318 static struct file *
319 find_readable_file(struct nfs4_file *f)
320 {
321         struct file *ret;
322
323         spin_lock(&f->fi_lock);
324         ret = find_readable_file_locked(f);
325         spin_unlock(&f->fi_lock);
326
327         return ret;
328 }
329
330 static struct file *
331 find_any_file(struct nfs4_file *f)
332 {
333         struct file *ret;
334
335         spin_lock(&f->fi_lock);
336         ret = __nfs4_get_fd(f, O_RDWR);
337         if (!ret) {
338                 ret = __nfs4_get_fd(f, O_WRONLY);
339                 if (!ret)
340                         ret = __nfs4_get_fd(f, O_RDONLY);
341         }
342         spin_unlock(&f->fi_lock);
343         return ret;
344 }
345
346 static int num_delegations;
347 unsigned long max_delegations;
348
349 /*
350  * Open owner state (share locks)
351  */
352
353 /* hash tables for lock and open owners */
354 #define OWNER_HASH_BITS              8
355 #define OWNER_HASH_SIZE             (1 << OWNER_HASH_BITS)
356 #define OWNER_HASH_MASK             (OWNER_HASH_SIZE - 1)
357
358 static unsigned int ownerstr_hashval(u32 clientid, struct xdr_netobj *ownername)
359 {
360         unsigned int ret;
361
362         ret = opaque_hashval(ownername->data, ownername->len);
363         ret += clientid;
364         return ret & OWNER_HASH_MASK;
365 }
366
367 /* hash table for nfs4_file */
368 #define FILE_HASH_BITS                   8
369 #define FILE_HASH_SIZE                  (1 << FILE_HASH_BITS)
370
371 static unsigned int file_hashval(struct inode *ino)
372 {
373         /* XXX: why are we hashing on inode pointer, anyway? */
374         return hash_ptr(ino, FILE_HASH_BITS);
375 }
376
377 static struct hlist_head file_hashtbl[FILE_HASH_SIZE];
378
379 static void
380 __nfs4_file_get_access(struct nfs4_file *fp, u32 access)
381 {
382         lockdep_assert_held(&fp->fi_lock);
383
384         if (access & NFS4_SHARE_ACCESS_WRITE)
385                 atomic_inc(&fp->fi_access[O_WRONLY]);
386         if (access & NFS4_SHARE_ACCESS_READ)
387                 atomic_inc(&fp->fi_access[O_RDONLY]);
388 }
389
390 static __be32
391 nfs4_file_get_access(struct nfs4_file *fp, u32 access)
392 {
393         lockdep_assert_held(&fp->fi_lock);
394
395         /* Does this access mode make sense? */
396         if (access & ~NFS4_SHARE_ACCESS_BOTH)
397                 return nfserr_inval;
398
399         /* Does it conflict with a deny mode already set? */
400         if ((access & fp->fi_share_deny) != 0)
401                 return nfserr_share_denied;
402
403         __nfs4_file_get_access(fp, access);
404         return nfs_ok;
405 }
406
407 static __be32 nfs4_file_check_deny(struct nfs4_file *fp, u32 deny)
408 {
409         /* Common case is that there is no deny mode. */
410         if (deny) {
411                 /* Does this deny mode make sense? */
412                 if (deny & ~NFS4_SHARE_DENY_BOTH)
413                         return nfserr_inval;
414
415                 if ((deny & NFS4_SHARE_DENY_READ) &&
416                     atomic_read(&fp->fi_access[O_RDONLY]))
417                         return nfserr_share_denied;
418
419                 if ((deny & NFS4_SHARE_DENY_WRITE) &&
420                     atomic_read(&fp->fi_access[O_WRONLY]))
421                         return nfserr_share_denied;
422         }
423         return nfs_ok;
424 }
425
426 static void __nfs4_file_put_access(struct nfs4_file *fp, int oflag)
427 {
428         might_lock(&fp->fi_lock);
429
430         if (atomic_dec_and_lock(&fp->fi_access[oflag], &fp->fi_lock)) {
431                 struct file *f1 = NULL;
432                 struct file *f2 = NULL;
433
434                 swap(f1, fp->fi_fds[oflag]);
435                 if (atomic_read(&fp->fi_access[1 - oflag]) == 0)
436                         swap(f2, fp->fi_fds[O_RDWR]);
437                 spin_unlock(&fp->fi_lock);
438                 if (f1)
439                         fput(f1);
440                 if (f2)
441                         fput(f2);
442         }
443 }
444
445 static void nfs4_file_put_access(struct nfs4_file *fp, u32 access)
446 {
447         WARN_ON_ONCE(access & ~NFS4_SHARE_ACCESS_BOTH);
448
449         if (access & NFS4_SHARE_ACCESS_WRITE)
450                 __nfs4_file_put_access(fp, O_WRONLY);
451         if (access & NFS4_SHARE_ACCESS_READ)
452                 __nfs4_file_put_access(fp, O_RDONLY);
453 }
454
455 static struct nfs4_stid *nfs4_alloc_stid(struct nfs4_client *cl, struct
456 kmem_cache *slab)
457 {
458         struct idr *stateids = &cl->cl_stateids;
459         struct nfs4_stid *stid;
460         int new_id;
461
462         stid = kmem_cache_alloc(slab, GFP_KERNEL);
463         if (!stid)
464                 return NULL;
465
466         new_id = idr_alloc_cyclic(stateids, stid, 0, 0, GFP_KERNEL);
467         if (new_id < 0)
468                 goto out_free;
469         stid->sc_client = cl;
470         stid->sc_type = 0;
471         stid->sc_stateid.si_opaque.so_id = new_id;
472         stid->sc_stateid.si_opaque.so_clid = cl->cl_clientid;
473         /* Will be incremented before return to client: */
474         stid->sc_stateid.si_generation = 0;
475
476         /*
477          * It shouldn't be a problem to reuse an opaque stateid value.
478          * I don't think it is for 4.1.  But with 4.0 I worry that, for
479          * example, a stray write retransmission could be accepted by
480          * the server when it should have been rejected.  Therefore,
481          * adopt a trick from the sctp code to attempt to maximize the
482          * amount of time until an id is reused, by ensuring they always
483          * "increase" (mod INT_MAX):
484          */
485         return stid;
486 out_free:
487         kmem_cache_free(slab, stid);
488         return NULL;
489 }
490
491 static struct nfs4_ol_stateid * nfs4_alloc_stateid(struct nfs4_client *clp)
492 {
493         return openlockstateid(nfs4_alloc_stid(clp, stateid_slab));
494 }
495
496 /*
497  * When we recall a delegation, we should be careful not to hand it
498  * out again straight away.
499  * To ensure this we keep a pair of bloom filters ('new' and 'old')
500  * in which the filehandles of recalled delegations are "stored".
501  * If a filehandle appear in either filter, a delegation is blocked.
502  * When a delegation is recalled, the filehandle is stored in the "new"
503  * filter.
504  * Every 30 seconds we swap the filters and clear the "new" one,
505  * unless both are empty of course.
506  *
507  * Each filter is 256 bits.  We hash the filehandle to 32bit and use the
508  * low 3 bytes as hash-table indices.
509  *
510  * 'state_lock', which is always held when block_delegations() is called,
511  * is used to manage concurrent access.  Testing does not need the lock
512  * except when swapping the two filters.
513  */
514 static struct bloom_pair {
515         int     entries, old_entries;
516         time_t  swap_time;
517         int     new; /* index into 'set' */
518         DECLARE_BITMAP(set[2], 256);
519 } blocked_delegations;
520
521 static int delegation_blocked(struct knfsd_fh *fh)
522 {
523         u32 hash;
524         struct bloom_pair *bd = &blocked_delegations;
525
526         if (bd->entries == 0)
527                 return 0;
528         if (seconds_since_boot() - bd->swap_time > 30) {
529                 spin_lock(&state_lock);
530                 if (seconds_since_boot() - bd->swap_time > 30) {
531                         bd->entries -= bd->old_entries;
532                         bd->old_entries = bd->entries;
533                         memset(bd->set[bd->new], 0,
534                                sizeof(bd->set[0]));
535                         bd->new = 1-bd->new;
536                         bd->swap_time = seconds_since_boot();
537                 }
538                 spin_unlock(&state_lock);
539         }
540         hash = arch_fast_hash(&fh->fh_base, fh->fh_size, 0);
541         if (test_bit(hash&255, bd->set[0]) &&
542             test_bit((hash>>8)&255, bd->set[0]) &&
543             test_bit((hash>>16)&255, bd->set[0]))
544                 return 1;
545
546         if (test_bit(hash&255, bd->set[1]) &&
547             test_bit((hash>>8)&255, bd->set[1]) &&
548             test_bit((hash>>16)&255, bd->set[1]))
549                 return 1;
550
551         return 0;
552 }
553
554 static void block_delegations(struct knfsd_fh *fh)
555 {
556         u32 hash;
557         struct bloom_pair *bd = &blocked_delegations;
558
559         lockdep_assert_held(&state_lock);
560
561         hash = arch_fast_hash(&fh->fh_base, fh->fh_size, 0);
562
563         __set_bit(hash&255, bd->set[bd->new]);
564         __set_bit((hash>>8)&255, bd->set[bd->new]);
565         __set_bit((hash>>16)&255, bd->set[bd->new]);
566         if (bd->entries == 0)
567                 bd->swap_time = seconds_since_boot();
568         bd->entries += 1;
569 }
570
571 static struct nfs4_delegation *
572 alloc_init_deleg(struct nfs4_client *clp, struct nfs4_ol_stateid *stp, struct svc_fh *current_fh)
573 {
574         struct nfs4_delegation *dp;
575
576         dprintk("NFSD alloc_init_deleg\n");
577         if (num_delegations > max_delegations)
578                 return NULL;
579         if (delegation_blocked(&current_fh->fh_handle))
580                 return NULL;
581         dp = delegstateid(nfs4_alloc_stid(clp, deleg_slab));
582         if (dp == NULL)
583                 return dp;
584         /*
585          * delegation seqid's are never incremented.  The 4.1 special
586          * meaning of seqid 0 isn't meaningful, really, but let's avoid
587          * 0 anyway just for consistency and use 1:
588          */
589         dp->dl_stid.sc_stateid.si_generation = 1;
590         num_delegations++;
591         INIT_LIST_HEAD(&dp->dl_perfile);
592         INIT_LIST_HEAD(&dp->dl_perclnt);
593         INIT_LIST_HEAD(&dp->dl_recall_lru);
594         dp->dl_file = NULL;
595         dp->dl_type = NFS4_OPEN_DELEGATE_READ;
596         fh_copy_shallow(&dp->dl_fh, &current_fh->fh_handle);
597         dp->dl_time = 0;
598         atomic_set(&dp->dl_count, 1);
599         INIT_WORK(&dp->dl_recall.cb_work, nfsd4_run_cb_recall);
600         return dp;
601 }
602
603 static void remove_stid(struct nfs4_stid *s)
604 {
605         struct idr *stateids = &s->sc_client->cl_stateids;
606
607         idr_remove(stateids, s->sc_stateid.si_opaque.so_id);
608 }
609
610 static void nfs4_free_stid(struct kmem_cache *slab, struct nfs4_stid *s)
611 {
612         kmem_cache_free(slab, s);
613 }
614
615 void
616 nfs4_put_delegation(struct nfs4_delegation *dp)
617 {
618         if (atomic_dec_and_test(&dp->dl_count)) {
619                 nfs4_free_stid(deleg_slab, &dp->dl_stid);
620                 num_delegations--;
621         }
622 }
623
624 static void nfs4_put_deleg_lease(struct nfs4_file *fp)
625 {
626         if (!fp->fi_lease)
627                 return;
628         if (atomic_dec_and_test(&fp->fi_delegees)) {
629                 vfs_setlease(fp->fi_deleg_file, F_UNLCK, &fp->fi_lease);
630                 fp->fi_lease = NULL;
631                 fput(fp->fi_deleg_file);
632                 fp->fi_deleg_file = NULL;
633         }
634 }
635
636 static void unhash_stid(struct nfs4_stid *s)
637 {
638         s->sc_type = 0;
639 }
640
641 static void
642 hash_delegation_locked(struct nfs4_delegation *dp, struct nfs4_file *fp)
643 {
644         lockdep_assert_held(&state_lock);
645
646         dp->dl_stid.sc_type = NFS4_DELEG_STID;
647         spin_lock(&fp->fi_lock);
648         list_add(&dp->dl_perfile, &fp->fi_delegations);
649         spin_unlock(&fp->fi_lock);
650         list_add(&dp->dl_perclnt, &dp->dl_stid.sc_client->cl_delegations);
651 }
652
653 /* Called under the state lock. */
654 static void
655 unhash_delegation(struct nfs4_delegation *dp)
656 {
657         struct nfs4_file *fp = dp->dl_file;
658
659         spin_lock(&state_lock);
660         list_del_init(&dp->dl_perclnt);
661         list_del_init(&dp->dl_recall_lru);
662         spin_lock(&fp->fi_lock);
663         list_del_init(&dp->dl_perfile);
664         spin_unlock(&fp->fi_lock);
665         spin_unlock(&state_lock);
666         if (fp) {
667                 nfs4_put_deleg_lease(fp);
668                 put_nfs4_file(fp);
669                 dp->dl_file = NULL;
670         }
671 }
672
673
674
675 static void destroy_revoked_delegation(struct nfs4_delegation *dp)
676 {
677         list_del_init(&dp->dl_recall_lru);
678         remove_stid(&dp->dl_stid);
679         nfs4_put_delegation(dp);
680 }
681
682 static void destroy_delegation(struct nfs4_delegation *dp)
683 {
684         unhash_delegation(dp);
685         remove_stid(&dp->dl_stid);
686         nfs4_put_delegation(dp);
687 }
688
689 static void revoke_delegation(struct nfs4_delegation *dp)
690 {
691         struct nfs4_client *clp = dp->dl_stid.sc_client;
692
693         if (clp->cl_minorversion == 0)
694                 destroy_delegation(dp);
695         else {
696                 unhash_delegation(dp);
697                 dp->dl_stid.sc_type = NFS4_REVOKED_DELEG_STID;
698                 list_add(&dp->dl_recall_lru, &clp->cl_revoked);
699         }
700 }
701
702 /* 
703  * SETCLIENTID state 
704  */
705
706 static unsigned int clientid_hashval(u32 id)
707 {
708         return id & CLIENT_HASH_MASK;
709 }
710
711 static unsigned int clientstr_hashval(const char *name)
712 {
713         return opaque_hashval(name, 8) & CLIENT_HASH_MASK;
714 }
715
716 /*
717  * We store the NONE, READ, WRITE, and BOTH bits separately in the
718  * st_{access,deny}_bmap field of the stateid, in order to track not
719  * only what share bits are currently in force, but also what
720  * combinations of share bits previous opens have used.  This allows us
721  * to enforce the recommendation of rfc 3530 14.2.19 that the server
722  * return an error if the client attempt to downgrade to a combination
723  * of share bits not explicable by closing some of its previous opens.
724  *
725  * XXX: This enforcement is actually incomplete, since we don't keep
726  * track of access/deny bit combinations; so, e.g., we allow:
727  *
728  *      OPEN allow read, deny write
729  *      OPEN allow both, deny none
730  *      DOWNGRADE allow read, deny none
731  *
732  * which we should reject.
733  */
734 static unsigned int
735 bmap_to_share_mode(unsigned long bmap) {
736         int i;
737         unsigned int access = 0;
738
739         for (i = 1; i < 4; i++) {
740                 if (test_bit(i, &bmap))
741                         access |= i;
742         }
743         return access;
744 }
745
746 /* set share access for a given stateid */
747 static inline void
748 set_access(u32 access, struct nfs4_ol_stateid *stp)
749 {
750         unsigned char mask = 1 << access;
751
752         WARN_ON_ONCE(access > NFS4_SHARE_ACCESS_BOTH);
753         stp->st_access_bmap |= mask;
754 }
755
756 /* clear share access for a given stateid */
757 static inline void
758 clear_access(u32 access, struct nfs4_ol_stateid *stp)
759 {
760         unsigned char mask = 1 << access;
761
762         WARN_ON_ONCE(access > NFS4_SHARE_ACCESS_BOTH);
763         stp->st_access_bmap &= ~mask;
764 }
765
766 /* test whether a given stateid has access */
767 static inline bool
768 test_access(u32 access, struct nfs4_ol_stateid *stp)
769 {
770         unsigned char mask = 1 << access;
771
772         return (bool)(stp->st_access_bmap & mask);
773 }
774
775 /* set share deny for a given stateid */
776 static inline void
777 set_deny(u32 deny, struct nfs4_ol_stateid *stp)
778 {
779         unsigned char mask = 1 << deny;
780
781         WARN_ON_ONCE(deny > NFS4_SHARE_DENY_BOTH);
782         stp->st_deny_bmap |= mask;
783 }
784
785 /* clear share deny for a given stateid */
786 static inline void
787 clear_deny(u32 deny, struct nfs4_ol_stateid *stp)
788 {
789         unsigned char mask = 1 << deny;
790
791         WARN_ON_ONCE(deny > NFS4_SHARE_DENY_BOTH);
792         stp->st_deny_bmap &= ~mask;
793 }
794
795 /* test whether a given stateid is denying specific access */
796 static inline bool
797 test_deny(u32 deny, struct nfs4_ol_stateid *stp)
798 {
799         unsigned char mask = 1 << deny;
800
801         return (bool)(stp->st_deny_bmap & mask);
802 }
803
804 static int nfs4_access_to_omode(u32 access)
805 {
806         switch (access & NFS4_SHARE_ACCESS_BOTH) {
807         case NFS4_SHARE_ACCESS_READ:
808                 return O_RDONLY;
809         case NFS4_SHARE_ACCESS_WRITE:
810                 return O_WRONLY;
811         case NFS4_SHARE_ACCESS_BOTH:
812                 return O_RDWR;
813         }
814         WARN_ON_ONCE(1);
815         return O_RDONLY;
816 }
817
818 /*
819  * A stateid that had a deny mode associated with it is being released
820  * or downgraded. Recalculate the deny mode on the file.
821  */
822 static void
823 recalculate_deny_mode(struct nfs4_file *fp)
824 {
825         struct nfs4_ol_stateid *stp;
826
827         spin_lock(&fp->fi_lock);
828         fp->fi_share_deny = 0;
829         list_for_each_entry(stp, &fp->fi_stateids, st_perfile)
830                 fp->fi_share_deny |= bmap_to_share_mode(stp->st_deny_bmap);
831         spin_unlock(&fp->fi_lock);
832 }
833
834 static void
835 reset_union_bmap_deny(u32 deny, struct nfs4_ol_stateid *stp)
836 {
837         int i;
838         bool change = false;
839
840         for (i = 1; i < 4; i++) {
841                 if ((i & deny) != i) {
842                         change = true;
843                         clear_deny(i, stp);
844                 }
845         }
846
847         /* Recalculate per-file deny mode if there was a change */
848         if (change)
849                 recalculate_deny_mode(stp->st_file);
850 }
851
852 /* release all access and file references for a given stateid */
853 static void
854 release_all_access(struct nfs4_ol_stateid *stp)
855 {
856         int i;
857         struct nfs4_file *fp = stp->st_file;
858
859         if (fp && stp->st_deny_bmap != 0)
860                 recalculate_deny_mode(fp);
861
862         for (i = 1; i < 4; i++) {
863                 if (test_access(i, stp))
864                         nfs4_file_put_access(stp->st_file, i);
865                 clear_access(i, stp);
866         }
867 }
868
869 static void unhash_generic_stateid(struct nfs4_ol_stateid *stp)
870 {
871         struct nfs4_file *fp = stp->st_file;
872
873         spin_lock(&fp->fi_lock);
874         list_del(&stp->st_perfile);
875         spin_unlock(&fp->fi_lock);
876         list_del(&stp->st_perstateowner);
877 }
878
879 static void close_generic_stateid(struct nfs4_ol_stateid *stp)
880 {
881         release_all_access(stp);
882         put_nfs4_file(stp->st_file);
883         stp->st_file = NULL;
884 }
885
886 static void free_generic_stateid(struct nfs4_ol_stateid *stp)
887 {
888         remove_stid(&stp->st_stid);
889         nfs4_free_stid(stateid_slab, &stp->st_stid);
890 }
891
892 static void __release_lock_stateid(struct nfs4_ol_stateid *stp)
893 {
894         struct file *file;
895
896         list_del(&stp->st_locks);
897         unhash_generic_stateid(stp);
898         unhash_stid(&stp->st_stid);
899         file = find_any_file(stp->st_file);
900         if (file)
901                 filp_close(file, (fl_owner_t)lockowner(stp->st_stateowner));
902         close_generic_stateid(stp);
903         free_generic_stateid(stp);
904 }
905
906 static void unhash_lockowner(struct nfs4_lockowner *lo)
907 {
908         struct nfs4_ol_stateid *stp;
909
910         list_del(&lo->lo_owner.so_strhash);
911         while (!list_empty(&lo->lo_owner.so_stateids)) {
912                 stp = list_first_entry(&lo->lo_owner.so_stateids,
913                                 struct nfs4_ol_stateid, st_perstateowner);
914                 __release_lock_stateid(stp);
915         }
916 }
917
918 static void nfs4_free_lockowner(struct nfs4_lockowner *lo)
919 {
920         kfree(lo->lo_owner.so_owner.data);
921         kmem_cache_free(lockowner_slab, lo);
922 }
923
924 static void release_lockowner(struct nfs4_lockowner *lo)
925 {
926         unhash_lockowner(lo);
927         nfs4_free_lockowner(lo);
928 }
929
930 static void release_lockowner_if_empty(struct nfs4_lockowner *lo)
931 {
932         if (list_empty(&lo->lo_owner.so_stateids))
933                 release_lockowner(lo);
934 }
935
936 static void release_lock_stateid(struct nfs4_ol_stateid *stp)
937 {
938         struct nfs4_lockowner *lo;
939
940         lo = lockowner(stp->st_stateowner);
941         __release_lock_stateid(stp);
942         release_lockowner_if_empty(lo);
943 }
944
945 static void release_open_stateid_locks(struct nfs4_ol_stateid *open_stp)
946 {
947         struct nfs4_ol_stateid *stp;
948
949         while (!list_empty(&open_stp->st_locks)) {
950                 stp = list_entry(open_stp->st_locks.next,
951                                 struct nfs4_ol_stateid, st_locks);
952                 release_lock_stateid(stp);
953         }
954 }
955
956 static void unhash_open_stateid(struct nfs4_ol_stateid *stp)
957 {
958         unhash_generic_stateid(stp);
959         release_open_stateid_locks(stp);
960         close_generic_stateid(stp);
961 }
962
963 static void release_open_stateid(struct nfs4_ol_stateid *stp)
964 {
965         unhash_open_stateid(stp);
966         free_generic_stateid(stp);
967 }
968
969 static void unhash_openowner(struct nfs4_openowner *oo)
970 {
971         struct nfs4_ol_stateid *stp;
972
973         list_del(&oo->oo_owner.so_strhash);
974         list_del(&oo->oo_perclient);
975         while (!list_empty(&oo->oo_owner.so_stateids)) {
976                 stp = list_first_entry(&oo->oo_owner.so_stateids,
977                                 struct nfs4_ol_stateid, st_perstateowner);
978                 release_open_stateid(stp);
979         }
980 }
981
982 static void release_last_closed_stateid(struct nfs4_openowner *oo)
983 {
984         struct nfs4_ol_stateid *s = oo->oo_last_closed_stid;
985
986         if (s) {
987                 free_generic_stateid(s);
988                 oo->oo_last_closed_stid = NULL;
989         }
990 }
991
992 static void nfs4_free_openowner(struct nfs4_openowner *oo)
993 {
994         kfree(oo->oo_owner.so_owner.data);
995         kmem_cache_free(openowner_slab, oo);
996 }
997
998 static void release_openowner(struct nfs4_openowner *oo)
999 {
1000         unhash_openowner(oo);
1001         list_del(&oo->oo_close_lru);
1002         release_last_closed_stateid(oo);
1003         nfs4_free_openowner(oo);
1004 }
1005
1006 static inline int
1007 hash_sessionid(struct nfs4_sessionid *sessionid)
1008 {
1009         struct nfsd4_sessionid *sid = (struct nfsd4_sessionid *)sessionid;
1010
1011         return sid->sequence % SESSION_HASH_SIZE;
1012 }
1013
1014 #ifdef NFSD_DEBUG
1015 static inline void
1016 dump_sessionid(const char *fn, struct nfs4_sessionid *sessionid)
1017 {
1018         u32 *ptr = (u32 *)(&sessionid->data[0]);
1019         dprintk("%s: %u:%u:%u:%u\n", fn, ptr[0], ptr[1], ptr[2], ptr[3]);
1020 }
1021 #else
1022 static inline void
1023 dump_sessionid(const char *fn, struct nfs4_sessionid *sessionid)
1024 {
1025 }
1026 #endif
1027
1028 /*
1029  * Bump the seqid on cstate->replay_owner, and clear replay_owner if it
1030  * won't be used for replay.
1031  */
1032 void nfsd4_bump_seqid(struct nfsd4_compound_state *cstate, __be32 nfserr)
1033 {
1034         struct nfs4_stateowner *so = cstate->replay_owner;
1035
1036         if (nfserr == nfserr_replay_me)
1037                 return;
1038
1039         if (!seqid_mutating_err(ntohl(nfserr))) {
1040                 cstate->replay_owner = NULL;
1041                 return;
1042         }
1043         if (!so)
1044                 return;
1045         if (so->so_is_open_owner)
1046                 release_last_closed_stateid(openowner(so));
1047         so->so_seqid++;
1048         return;
1049 }
1050
1051 static void
1052 gen_sessionid(struct nfsd4_session *ses)
1053 {
1054         struct nfs4_client *clp = ses->se_client;
1055         struct nfsd4_sessionid *sid;
1056
1057         sid = (struct nfsd4_sessionid *)ses->se_sessionid.data;
1058         sid->clientid = clp->cl_clientid;
1059         sid->sequence = current_sessionid++;
1060         sid->reserved = 0;
1061 }
1062
1063 /*
1064  * The protocol defines ca_maxresponssize_cached to include the size of
1065  * the rpc header, but all we need to cache is the data starting after
1066  * the end of the initial SEQUENCE operation--the rest we regenerate
1067  * each time.  Therefore we can advertise a ca_maxresponssize_cached
1068  * value that is the number of bytes in our cache plus a few additional
1069  * bytes.  In order to stay on the safe side, and not promise more than
1070  * we can cache, those additional bytes must be the minimum possible: 24
1071  * bytes of rpc header (xid through accept state, with AUTH_NULL
1072  * verifier), 12 for the compound header (with zero-length tag), and 44
1073  * for the SEQUENCE op response:
1074  */
1075 #define NFSD_MIN_HDR_SEQ_SZ  (24 + 12 + 44)
1076
1077 static void
1078 free_session_slots(struct nfsd4_session *ses)
1079 {
1080         int i;
1081
1082         for (i = 0; i < ses->se_fchannel.maxreqs; i++)
1083                 kfree(ses->se_slots[i]);
1084 }
1085
1086 /*
1087  * We don't actually need to cache the rpc and session headers, so we
1088  * can allocate a little less for each slot:
1089  */
1090 static inline u32 slot_bytes(struct nfsd4_channel_attrs *ca)
1091 {
1092         u32 size;
1093
1094         if (ca->maxresp_cached < NFSD_MIN_HDR_SEQ_SZ)
1095                 size = 0;
1096         else
1097                 size = ca->maxresp_cached - NFSD_MIN_HDR_SEQ_SZ;
1098         return size + sizeof(struct nfsd4_slot);
1099 }
1100
1101 /*
1102  * XXX: If we run out of reserved DRC memory we could (up to a point)
1103  * re-negotiate active sessions and reduce their slot usage to make
1104  * room for new connections. For now we just fail the create session.
1105  */
1106 static u32 nfsd4_get_drc_mem(struct nfsd4_channel_attrs *ca)
1107 {
1108         u32 slotsize = slot_bytes(ca);
1109         u32 num = ca->maxreqs;
1110         int avail;
1111
1112         spin_lock(&nfsd_drc_lock);
1113         avail = min((unsigned long)NFSD_MAX_MEM_PER_SESSION,
1114                     nfsd_drc_max_mem - nfsd_drc_mem_used);
1115         num = min_t(int, num, avail / slotsize);
1116         nfsd_drc_mem_used += num * slotsize;
1117         spin_unlock(&nfsd_drc_lock);
1118
1119         return num;
1120 }
1121
1122 static void nfsd4_put_drc_mem(struct nfsd4_channel_attrs *ca)
1123 {
1124         int slotsize = slot_bytes(ca);
1125
1126         spin_lock(&nfsd_drc_lock);
1127         nfsd_drc_mem_used -= slotsize * ca->maxreqs;
1128         spin_unlock(&nfsd_drc_lock);
1129 }
1130
1131 static struct nfsd4_session *alloc_session(struct nfsd4_channel_attrs *fattrs,
1132                                            struct nfsd4_channel_attrs *battrs)
1133 {
1134         int numslots = fattrs->maxreqs;
1135         int slotsize = slot_bytes(fattrs);
1136         struct nfsd4_session *new;
1137         int mem, i;
1138
1139         BUILD_BUG_ON(NFSD_MAX_SLOTS_PER_SESSION * sizeof(struct nfsd4_slot *)
1140                         + sizeof(struct nfsd4_session) > PAGE_SIZE);
1141         mem = numslots * sizeof(struct nfsd4_slot *);
1142
1143         new = kzalloc(sizeof(*new) + mem, GFP_KERNEL);
1144         if (!new)
1145                 return NULL;
1146         /* allocate each struct nfsd4_slot and data cache in one piece */
1147         for (i = 0; i < numslots; i++) {
1148                 new->se_slots[i] = kzalloc(slotsize, GFP_KERNEL);
1149                 if (!new->se_slots[i])
1150                         goto out_free;
1151         }
1152
1153         memcpy(&new->se_fchannel, fattrs, sizeof(struct nfsd4_channel_attrs));
1154         memcpy(&new->se_bchannel, battrs, sizeof(struct nfsd4_channel_attrs));
1155
1156         return new;
1157 out_free:
1158         while (i--)
1159                 kfree(new->se_slots[i]);
1160         kfree(new);
1161         return NULL;
1162 }
1163
1164 static void free_conn(struct nfsd4_conn *c)
1165 {
1166         svc_xprt_put(c->cn_xprt);
1167         kfree(c);
1168 }
1169
1170 static void nfsd4_conn_lost(struct svc_xpt_user *u)
1171 {
1172         struct nfsd4_conn *c = container_of(u, struct nfsd4_conn, cn_xpt_user);
1173         struct nfs4_client *clp = c->cn_session->se_client;
1174
1175         spin_lock(&clp->cl_lock);
1176         if (!list_empty(&c->cn_persession)) {
1177                 list_del(&c->cn_persession);
1178                 free_conn(c);
1179         }
1180         nfsd4_probe_callback(clp);
1181         spin_unlock(&clp->cl_lock);
1182 }
1183
1184 static struct nfsd4_conn *alloc_conn(struct svc_rqst *rqstp, u32 flags)
1185 {
1186         struct nfsd4_conn *conn;
1187
1188         conn = kmalloc(sizeof(struct nfsd4_conn), GFP_KERNEL);
1189         if (!conn)
1190                 return NULL;
1191         svc_xprt_get(rqstp->rq_xprt);
1192         conn->cn_xprt = rqstp->rq_xprt;
1193         conn->cn_flags = flags;
1194         INIT_LIST_HEAD(&conn->cn_xpt_user.list);
1195         return conn;
1196 }
1197
1198 static void __nfsd4_hash_conn(struct nfsd4_conn *conn, struct nfsd4_session *ses)
1199 {
1200         conn->cn_session = ses;
1201         list_add(&conn->cn_persession, &ses->se_conns);
1202 }
1203
1204 static void nfsd4_hash_conn(struct nfsd4_conn *conn, struct nfsd4_session *ses)
1205 {
1206         struct nfs4_client *clp = ses->se_client;
1207
1208         spin_lock(&clp->cl_lock);
1209         __nfsd4_hash_conn(conn, ses);
1210         spin_unlock(&clp->cl_lock);
1211 }
1212
1213 static int nfsd4_register_conn(struct nfsd4_conn *conn)
1214 {
1215         conn->cn_xpt_user.callback = nfsd4_conn_lost;
1216         return register_xpt_user(conn->cn_xprt, &conn->cn_xpt_user);
1217 }
1218
1219 static void nfsd4_init_conn(struct svc_rqst *rqstp, struct nfsd4_conn *conn, struct nfsd4_session *ses)
1220 {
1221         int ret;
1222
1223         nfsd4_hash_conn(conn, ses);
1224         ret = nfsd4_register_conn(conn);
1225         if (ret)
1226                 /* oops; xprt is already down: */
1227                 nfsd4_conn_lost(&conn->cn_xpt_user);
1228         if (conn->cn_flags & NFS4_CDFC4_BACK) {
1229                 /* callback channel may be back up */
1230                 nfsd4_probe_callback(ses->se_client);
1231         }
1232 }
1233
1234 static struct nfsd4_conn *alloc_conn_from_crses(struct svc_rqst *rqstp, struct nfsd4_create_session *cses)
1235 {
1236         u32 dir = NFS4_CDFC4_FORE;
1237
1238         if (cses->flags & SESSION4_BACK_CHAN)
1239                 dir |= NFS4_CDFC4_BACK;
1240         return alloc_conn(rqstp, dir);
1241 }
1242
1243 /* must be called under client_lock */
1244 static void nfsd4_del_conns(struct nfsd4_session *s)
1245 {
1246         struct nfs4_client *clp = s->se_client;
1247         struct nfsd4_conn *c;
1248
1249         spin_lock(&clp->cl_lock);
1250         while (!list_empty(&s->se_conns)) {
1251                 c = list_first_entry(&s->se_conns, struct nfsd4_conn, cn_persession);
1252                 list_del_init(&c->cn_persession);
1253                 spin_unlock(&clp->cl_lock);
1254
1255                 unregister_xpt_user(c->cn_xprt, &c->cn_xpt_user);
1256                 free_conn(c);
1257
1258                 spin_lock(&clp->cl_lock);
1259         }
1260         spin_unlock(&clp->cl_lock);
1261 }
1262
1263 static void __free_session(struct nfsd4_session *ses)
1264 {
1265         free_session_slots(ses);
1266         kfree(ses);
1267 }
1268
1269 static void free_session(struct nfsd4_session *ses)
1270 {
1271         struct nfsd_net *nn = net_generic(ses->se_client->net, nfsd_net_id);
1272
1273         lockdep_assert_held(&nn->client_lock);
1274         nfsd4_del_conns(ses);
1275         nfsd4_put_drc_mem(&ses->se_fchannel);
1276         __free_session(ses);
1277 }
1278
1279 static void init_session(struct svc_rqst *rqstp, struct nfsd4_session *new, struct nfs4_client *clp, struct nfsd4_create_session *cses)
1280 {
1281         int idx;
1282         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
1283
1284         new->se_client = clp;
1285         gen_sessionid(new);
1286
1287         INIT_LIST_HEAD(&new->se_conns);
1288
1289         new->se_cb_seq_nr = 1;
1290         new->se_flags = cses->flags;
1291         new->se_cb_prog = cses->callback_prog;
1292         new->se_cb_sec = cses->cb_sec;
1293         atomic_set(&new->se_ref, 0);
1294         idx = hash_sessionid(&new->se_sessionid);
1295         spin_lock(&nn->client_lock);
1296         list_add(&new->se_hash, &nn->sessionid_hashtbl[idx]);
1297         spin_lock(&clp->cl_lock);
1298         list_add(&new->se_perclnt, &clp->cl_sessions);
1299         spin_unlock(&clp->cl_lock);
1300         spin_unlock(&nn->client_lock);
1301
1302         if (cses->flags & SESSION4_BACK_CHAN) {
1303                 struct sockaddr *sa = svc_addr(rqstp);
1304                 /*
1305                  * This is a little silly; with sessions there's no real
1306                  * use for the callback address.  Use the peer address
1307                  * as a reasonable default for now, but consider fixing
1308                  * the rpc client not to require an address in the
1309                  * future:
1310                  */
1311                 rpc_copy_addr((struct sockaddr *)&clp->cl_cb_conn.cb_addr, sa);
1312                 clp->cl_cb_conn.cb_addrlen = svc_addr_len(sa);
1313         }
1314 }
1315
1316 /* caller must hold client_lock */
1317 static struct nfsd4_session *
1318 __find_in_sessionid_hashtbl(struct nfs4_sessionid *sessionid, struct net *net)
1319 {
1320         struct nfsd4_session *elem;
1321         int idx;
1322         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
1323
1324         dump_sessionid(__func__, sessionid);
1325         idx = hash_sessionid(sessionid);
1326         /* Search in the appropriate list */
1327         list_for_each_entry(elem, &nn->sessionid_hashtbl[idx], se_hash) {
1328                 if (!memcmp(elem->se_sessionid.data, sessionid->data,
1329                             NFS4_MAX_SESSIONID_LEN)) {
1330                         return elem;
1331                 }
1332         }
1333
1334         dprintk("%s: session not found\n", __func__);
1335         return NULL;
1336 }
1337
1338 static struct nfsd4_session *
1339 find_in_sessionid_hashtbl(struct nfs4_sessionid *sessionid, struct net *net,
1340                 __be32 *ret)
1341 {
1342         struct nfsd4_session *session;
1343         __be32 status = nfserr_badsession;
1344
1345         session = __find_in_sessionid_hashtbl(sessionid, net);
1346         if (!session)
1347                 goto out;
1348         status = nfsd4_get_session_locked(session);
1349         if (status)
1350                 session = NULL;
1351 out:
1352         *ret = status;
1353         return session;
1354 }
1355
1356 /* caller must hold client_lock */
1357 static void
1358 unhash_session(struct nfsd4_session *ses)
1359 {
1360         list_del(&ses->se_hash);
1361         spin_lock(&ses->se_client->cl_lock);
1362         list_del(&ses->se_perclnt);
1363         spin_unlock(&ses->se_client->cl_lock);
1364 }
1365
1366 /* SETCLIENTID and SETCLIENTID_CONFIRM Helper functions */
1367 static int
1368 STALE_CLIENTID(clientid_t *clid, struct nfsd_net *nn)
1369 {
1370         if (clid->cl_boot == nn->boot_time)
1371                 return 0;
1372         dprintk("NFSD stale clientid (%08x/%08x) boot_time %08lx\n",
1373                 clid->cl_boot, clid->cl_id, nn->boot_time);
1374         return 1;
1375 }
1376
1377 /* 
1378  * XXX Should we use a slab cache ?
1379  * This type of memory management is somewhat inefficient, but we use it
1380  * anyway since SETCLIENTID is not a common operation.
1381  */
1382 static struct nfs4_client *alloc_client(struct xdr_netobj name)
1383 {
1384         struct nfs4_client *clp;
1385
1386         clp = kzalloc(sizeof(struct nfs4_client), GFP_KERNEL);
1387         if (clp == NULL)
1388                 return NULL;
1389         clp->cl_name.data = kmemdup(name.data, name.len, GFP_KERNEL);
1390         if (clp->cl_name.data == NULL) {
1391                 kfree(clp);
1392                 return NULL;
1393         }
1394         clp->cl_name.len = name.len;
1395         INIT_LIST_HEAD(&clp->cl_sessions);
1396         idr_init(&clp->cl_stateids);
1397         atomic_set(&clp->cl_refcount, 0);
1398         clp->cl_cb_state = NFSD4_CB_UNKNOWN;
1399         INIT_LIST_HEAD(&clp->cl_idhash);
1400         INIT_LIST_HEAD(&clp->cl_openowners);
1401         INIT_LIST_HEAD(&clp->cl_delegations);
1402         INIT_LIST_HEAD(&clp->cl_lru);
1403         INIT_LIST_HEAD(&clp->cl_callbacks);
1404         INIT_LIST_HEAD(&clp->cl_revoked);
1405         spin_lock_init(&clp->cl_lock);
1406         rpc_init_wait_queue(&clp->cl_cb_waitq, "Backchannel slot table");
1407         return clp;
1408 }
1409
1410 static void
1411 free_client(struct nfs4_client *clp)
1412 {
1413         struct nfsd_net __maybe_unused *nn = net_generic(clp->net, nfsd_net_id);
1414
1415         lockdep_assert_held(&nn->client_lock);
1416         while (!list_empty(&clp->cl_sessions)) {
1417                 struct nfsd4_session *ses;
1418                 ses = list_entry(clp->cl_sessions.next, struct nfsd4_session,
1419                                 se_perclnt);
1420                 list_del(&ses->se_perclnt);
1421                 WARN_ON_ONCE(atomic_read(&ses->se_ref));
1422                 free_session(ses);
1423         }
1424         rpc_destroy_wait_queue(&clp->cl_cb_waitq);
1425         free_svc_cred(&clp->cl_cred);
1426         kfree(clp->cl_name.data);
1427         idr_destroy(&clp->cl_stateids);
1428         kfree(clp);
1429 }
1430
1431 /* must be called under the client_lock */
1432 static inline void
1433 unhash_client_locked(struct nfs4_client *clp)
1434 {
1435         struct nfsd4_session *ses;
1436
1437         list_del(&clp->cl_lru);
1438         spin_lock(&clp->cl_lock);
1439         list_for_each_entry(ses, &clp->cl_sessions, se_perclnt)
1440                 list_del_init(&ses->se_hash);
1441         spin_unlock(&clp->cl_lock);
1442 }
1443
1444 static void
1445 destroy_client(struct nfs4_client *clp)
1446 {
1447         struct nfs4_openowner *oo;
1448         struct nfs4_delegation *dp;
1449         struct list_head reaplist;
1450         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
1451
1452         INIT_LIST_HEAD(&reaplist);
1453         spin_lock(&state_lock);
1454         while (!list_empty(&clp->cl_delegations)) {
1455                 dp = list_entry(clp->cl_delegations.next, struct nfs4_delegation, dl_perclnt);
1456                 list_del_init(&dp->dl_perclnt);
1457                 /* Ensure that deleg break won't try to requeue it */
1458                 ++dp->dl_time;
1459                 list_move(&dp->dl_recall_lru, &reaplist);
1460         }
1461         spin_unlock(&state_lock);
1462         while (!list_empty(&reaplist)) {
1463                 dp = list_entry(reaplist.next, struct nfs4_delegation, dl_recall_lru);
1464                 destroy_delegation(dp);
1465         }
1466         list_splice_init(&clp->cl_revoked, &reaplist);
1467         while (!list_empty(&reaplist)) {
1468                 dp = list_entry(reaplist.next, struct nfs4_delegation, dl_recall_lru);
1469                 destroy_revoked_delegation(dp);
1470         }
1471         while (!list_empty(&clp->cl_openowners)) {
1472                 oo = list_entry(clp->cl_openowners.next, struct nfs4_openowner, oo_perclient);
1473                 release_openowner(oo);
1474         }
1475         nfsd4_shutdown_callback(clp);
1476         if (clp->cl_cb_conn.cb_xprt)
1477                 svc_xprt_put(clp->cl_cb_conn.cb_xprt);
1478         list_del(&clp->cl_idhash);
1479         if (test_bit(NFSD4_CLIENT_CONFIRMED, &clp->cl_flags))
1480                 rb_erase(&clp->cl_namenode, &nn->conf_name_tree);
1481         else
1482                 rb_erase(&clp->cl_namenode, &nn->unconf_name_tree);
1483         spin_lock(&nn->client_lock);
1484         unhash_client_locked(clp);
1485         WARN_ON_ONCE(atomic_read(&clp->cl_refcount));
1486         free_client(clp);
1487         spin_unlock(&nn->client_lock);
1488 }
1489
1490 static void expire_client(struct nfs4_client *clp)
1491 {
1492         nfsd4_client_record_remove(clp);
1493         destroy_client(clp);
1494 }
1495
1496 static void copy_verf(struct nfs4_client *target, nfs4_verifier *source)
1497 {
1498         memcpy(target->cl_verifier.data, source->data,
1499                         sizeof(target->cl_verifier.data));
1500 }
1501
1502 static void copy_clid(struct nfs4_client *target, struct nfs4_client *source)
1503 {
1504         target->cl_clientid.cl_boot = source->cl_clientid.cl_boot; 
1505         target->cl_clientid.cl_id = source->cl_clientid.cl_id; 
1506 }
1507
1508 static int copy_cred(struct svc_cred *target, struct svc_cred *source)
1509 {
1510         if (source->cr_principal) {
1511                 target->cr_principal =
1512                                 kstrdup(source->cr_principal, GFP_KERNEL);
1513                 if (target->cr_principal == NULL)
1514                         return -ENOMEM;
1515         } else
1516                 target->cr_principal = NULL;
1517         target->cr_flavor = source->cr_flavor;
1518         target->cr_uid = source->cr_uid;
1519         target->cr_gid = source->cr_gid;
1520         target->cr_group_info = source->cr_group_info;
1521         get_group_info(target->cr_group_info);
1522         target->cr_gss_mech = source->cr_gss_mech;
1523         if (source->cr_gss_mech)
1524                 gss_mech_get(source->cr_gss_mech);
1525         return 0;
1526 }
1527
1528 static long long
1529 compare_blob(const struct xdr_netobj *o1, const struct xdr_netobj *o2)
1530 {
1531         long long res;
1532
1533         res = o1->len - o2->len;
1534         if (res)
1535                 return res;
1536         return (long long)memcmp(o1->data, o2->data, o1->len);
1537 }
1538
1539 static int same_name(const char *n1, const char *n2)
1540 {
1541         return 0 == memcmp(n1, n2, HEXDIR_LEN);
1542 }
1543
1544 static int
1545 same_verf(nfs4_verifier *v1, nfs4_verifier *v2)
1546 {
1547         return 0 == memcmp(v1->data, v2->data, sizeof(v1->data));
1548 }
1549
1550 static int
1551 same_clid(clientid_t *cl1, clientid_t *cl2)
1552 {
1553         return (cl1->cl_boot == cl2->cl_boot) && (cl1->cl_id == cl2->cl_id);
1554 }
1555
1556 static bool groups_equal(struct group_info *g1, struct group_info *g2)
1557 {
1558         int i;
1559
1560         if (g1->ngroups != g2->ngroups)
1561                 return false;
1562         for (i=0; i<g1->ngroups; i++)
1563                 if (!gid_eq(GROUP_AT(g1, i), GROUP_AT(g2, i)))
1564                         return false;
1565         return true;
1566 }
1567
1568 /*
1569  * RFC 3530 language requires clid_inuse be returned when the
1570  * "principal" associated with a requests differs from that previously
1571  * used.  We use uid, gid's, and gss principal string as our best
1572  * approximation.  We also don't want to allow non-gss use of a client
1573  * established using gss: in theory cr_principal should catch that
1574  * change, but in practice cr_principal can be null even in the gss case
1575  * since gssd doesn't always pass down a principal string.
1576  */
1577 static bool is_gss_cred(struct svc_cred *cr)
1578 {
1579         /* Is cr_flavor one of the gss "pseudoflavors"?: */
1580         return (cr->cr_flavor > RPC_AUTH_MAXFLAVOR);
1581 }
1582
1583
1584 static bool
1585 same_creds(struct svc_cred *cr1, struct svc_cred *cr2)
1586 {
1587         if ((is_gss_cred(cr1) != is_gss_cred(cr2))
1588                 || (!uid_eq(cr1->cr_uid, cr2->cr_uid))
1589                 || (!gid_eq(cr1->cr_gid, cr2->cr_gid))
1590                 || !groups_equal(cr1->cr_group_info, cr2->cr_group_info))
1591                 return false;
1592         if (cr1->cr_principal == cr2->cr_principal)
1593                 return true;
1594         if (!cr1->cr_principal || !cr2->cr_principal)
1595                 return false;
1596         return 0 == strcmp(cr1->cr_principal, cr2->cr_principal);
1597 }
1598
1599 static bool svc_rqst_integrity_protected(struct svc_rqst *rqstp)
1600 {
1601         struct svc_cred *cr = &rqstp->rq_cred;
1602         u32 service;
1603
1604         if (!cr->cr_gss_mech)
1605                 return false;
1606         service = gss_pseudoflavor_to_service(cr->cr_gss_mech, cr->cr_flavor);
1607         return service == RPC_GSS_SVC_INTEGRITY ||
1608                service == RPC_GSS_SVC_PRIVACY;
1609 }
1610
1611 static bool mach_creds_match(struct nfs4_client *cl, struct svc_rqst *rqstp)
1612 {
1613         struct svc_cred *cr = &rqstp->rq_cred;
1614
1615         if (!cl->cl_mach_cred)
1616                 return true;
1617         if (cl->cl_cred.cr_gss_mech != cr->cr_gss_mech)
1618                 return false;
1619         if (!svc_rqst_integrity_protected(rqstp))
1620                 return false;
1621         if (!cr->cr_principal)
1622                 return false;
1623         return 0 == strcmp(cl->cl_cred.cr_principal, cr->cr_principal);
1624 }
1625
1626 static void gen_clid(struct nfs4_client *clp, struct nfsd_net *nn)
1627 {
1628         static u32 current_clientid = 1;
1629
1630         clp->cl_clientid.cl_boot = nn->boot_time;
1631         clp->cl_clientid.cl_id = current_clientid++; 
1632 }
1633
1634 static void gen_confirm(struct nfs4_client *clp)
1635 {
1636         __be32 verf[2];
1637         static u32 i;
1638
1639         /*
1640          * This is opaque to client, so no need to byte-swap. Use
1641          * __force to keep sparse happy
1642          */
1643         verf[0] = (__force __be32)get_seconds();
1644         verf[1] = (__force __be32)i++;
1645         memcpy(clp->cl_confirm.data, verf, sizeof(clp->cl_confirm.data));
1646 }
1647
1648 static struct nfs4_stid *find_stateid(struct nfs4_client *cl, stateid_t *t)
1649 {
1650         struct nfs4_stid *ret;
1651
1652         ret = idr_find(&cl->cl_stateids, t->si_opaque.so_id);
1653         if (!ret || !ret->sc_type)
1654                 return NULL;
1655         return ret;
1656 }
1657
1658 static struct nfs4_stid *find_stateid_by_type(struct nfs4_client *cl, stateid_t *t, char typemask)
1659 {
1660         struct nfs4_stid *s;
1661
1662         s = find_stateid(cl, t);
1663         if (!s)
1664                 return NULL;
1665         if (typemask & s->sc_type)
1666                 return s;
1667         return NULL;
1668 }
1669
1670 static struct nfs4_client *create_client(struct xdr_netobj name,
1671                 struct svc_rqst *rqstp, nfs4_verifier *verf)
1672 {
1673         struct nfs4_client *clp;
1674         struct sockaddr *sa = svc_addr(rqstp);
1675         int ret;
1676         struct net *net = SVC_NET(rqstp);
1677         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
1678
1679         clp = alloc_client(name);
1680         if (clp == NULL)
1681                 return NULL;
1682
1683         ret = copy_cred(&clp->cl_cred, &rqstp->rq_cred);
1684         if (ret) {
1685                 spin_lock(&nn->client_lock);
1686                 free_client(clp);
1687                 spin_unlock(&nn->client_lock);
1688                 return NULL;
1689         }
1690         INIT_WORK(&clp->cl_cb_null.cb_work, nfsd4_run_cb_null);
1691         clp->cl_time = get_seconds();
1692         clear_bit(0, &clp->cl_cb_slot_busy);
1693         copy_verf(clp, verf);
1694         rpc_copy_addr((struct sockaddr *) &clp->cl_addr, sa);
1695         gen_confirm(clp);
1696         clp->cl_cb_session = NULL;
1697         clp->net = net;
1698         return clp;
1699 }
1700
1701 static void
1702 add_clp_to_name_tree(struct nfs4_client *new_clp, struct rb_root *root)
1703 {
1704         struct rb_node **new = &(root->rb_node), *parent = NULL;
1705         struct nfs4_client *clp;
1706
1707         while (*new) {
1708                 clp = rb_entry(*new, struct nfs4_client, cl_namenode);
1709                 parent = *new;
1710
1711                 if (compare_blob(&clp->cl_name, &new_clp->cl_name) > 0)
1712                         new = &((*new)->rb_left);
1713                 else
1714                         new = &((*new)->rb_right);
1715         }
1716
1717         rb_link_node(&new_clp->cl_namenode, parent, new);
1718         rb_insert_color(&new_clp->cl_namenode, root);
1719 }
1720
1721 static struct nfs4_client *
1722 find_clp_in_name_tree(struct xdr_netobj *name, struct rb_root *root)
1723 {
1724         long long cmp;
1725         struct rb_node *node = root->rb_node;
1726         struct nfs4_client *clp;
1727
1728         while (node) {
1729                 clp = rb_entry(node, struct nfs4_client, cl_namenode);
1730                 cmp = compare_blob(&clp->cl_name, name);
1731                 if (cmp > 0)
1732                         node = node->rb_left;
1733                 else if (cmp < 0)
1734                         node = node->rb_right;
1735                 else
1736                         return clp;
1737         }
1738         return NULL;
1739 }
1740
1741 static void
1742 add_to_unconfirmed(struct nfs4_client *clp)
1743 {
1744         unsigned int idhashval;
1745         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
1746
1747         clear_bit(NFSD4_CLIENT_CONFIRMED, &clp->cl_flags);
1748         add_clp_to_name_tree(clp, &nn->unconf_name_tree);
1749         idhashval = clientid_hashval(clp->cl_clientid.cl_id);
1750         list_add(&clp->cl_idhash, &nn->unconf_id_hashtbl[idhashval]);
1751         renew_client(clp);
1752 }
1753
1754 static void
1755 move_to_confirmed(struct nfs4_client *clp)
1756 {
1757         unsigned int idhashval = clientid_hashval(clp->cl_clientid.cl_id);
1758         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
1759
1760         dprintk("NFSD: move_to_confirm nfs4_client %p\n", clp);
1761         list_move(&clp->cl_idhash, &nn->conf_id_hashtbl[idhashval]);
1762         rb_erase(&clp->cl_namenode, &nn->unconf_name_tree);
1763         add_clp_to_name_tree(clp, &nn->conf_name_tree);
1764         set_bit(NFSD4_CLIENT_CONFIRMED, &clp->cl_flags);
1765         renew_client(clp);
1766 }
1767
1768 static struct nfs4_client *
1769 find_client_in_id_table(struct list_head *tbl, clientid_t *clid, bool sessions)
1770 {
1771         struct nfs4_client *clp;
1772         unsigned int idhashval = clientid_hashval(clid->cl_id);
1773
1774         list_for_each_entry(clp, &tbl[idhashval], cl_idhash) {
1775                 if (same_clid(&clp->cl_clientid, clid)) {
1776                         if ((bool)clp->cl_minorversion != sessions)
1777                                 return NULL;
1778                         renew_client(clp);
1779                         return clp;
1780                 }
1781         }
1782         return NULL;
1783 }
1784
1785 static struct nfs4_client *
1786 find_confirmed_client(clientid_t *clid, bool sessions, struct nfsd_net *nn)
1787 {
1788         struct list_head *tbl = nn->conf_id_hashtbl;
1789
1790         return find_client_in_id_table(tbl, clid, sessions);
1791 }
1792
1793 static struct nfs4_client *
1794 find_unconfirmed_client(clientid_t *clid, bool sessions, struct nfsd_net *nn)
1795 {
1796         struct list_head *tbl = nn->unconf_id_hashtbl;
1797
1798         return find_client_in_id_table(tbl, clid, sessions);
1799 }
1800
1801 static bool clp_used_exchangeid(struct nfs4_client *clp)
1802 {
1803         return clp->cl_exchange_flags != 0;
1804
1805
1806 static struct nfs4_client *
1807 find_confirmed_client_by_name(struct xdr_netobj *name, struct nfsd_net *nn)
1808 {
1809         return find_clp_in_name_tree(name, &nn->conf_name_tree);
1810 }
1811
1812 static struct nfs4_client *
1813 find_unconfirmed_client_by_name(struct xdr_netobj *name, struct nfsd_net *nn)
1814 {
1815         return find_clp_in_name_tree(name, &nn->unconf_name_tree);
1816 }
1817
1818 static void
1819 gen_callback(struct nfs4_client *clp, struct nfsd4_setclientid *se, struct svc_rqst *rqstp)
1820 {
1821         struct nfs4_cb_conn *conn = &clp->cl_cb_conn;
1822         struct sockaddr *sa = svc_addr(rqstp);
1823         u32 scopeid = rpc_get_scope_id(sa);
1824         unsigned short expected_family;
1825
1826         /* Currently, we only support tcp and tcp6 for the callback channel */
1827         if (se->se_callback_netid_len == 3 &&
1828             !memcmp(se->se_callback_netid_val, "tcp", 3))
1829                 expected_family = AF_INET;
1830         else if (se->se_callback_netid_len == 4 &&
1831                  !memcmp(se->se_callback_netid_val, "tcp6", 4))
1832                 expected_family = AF_INET6;
1833         else
1834                 goto out_err;
1835
1836         conn->cb_addrlen = rpc_uaddr2sockaddr(clp->net, se->se_callback_addr_val,
1837                                             se->se_callback_addr_len,
1838                                             (struct sockaddr *)&conn->cb_addr,
1839                                             sizeof(conn->cb_addr));
1840
1841         if (!conn->cb_addrlen || conn->cb_addr.ss_family != expected_family)
1842                 goto out_err;
1843
1844         if (conn->cb_addr.ss_family == AF_INET6)
1845                 ((struct sockaddr_in6 *)&conn->cb_addr)->sin6_scope_id = scopeid;
1846
1847         conn->cb_prog = se->se_callback_prog;
1848         conn->cb_ident = se->se_callback_ident;
1849         memcpy(&conn->cb_saddr, &rqstp->rq_daddr, rqstp->rq_daddrlen);
1850         return;
1851 out_err:
1852         conn->cb_addr.ss_family = AF_UNSPEC;
1853         conn->cb_addrlen = 0;
1854         dprintk(KERN_INFO "NFSD: this client (clientid %08x/%08x) "
1855                 "will not receive delegations\n",
1856                 clp->cl_clientid.cl_boot, clp->cl_clientid.cl_id);
1857
1858         return;
1859 }
1860
1861 /*
1862  * Cache a reply. nfsd4_check_resp_size() has bounded the cache size.
1863  */
1864 static void
1865 nfsd4_store_cache_entry(struct nfsd4_compoundres *resp)
1866 {
1867         struct xdr_buf *buf = resp->xdr.buf;
1868         struct nfsd4_slot *slot = resp->cstate.slot;
1869         unsigned int base;
1870
1871         dprintk("--> %s slot %p\n", __func__, slot);
1872
1873         slot->sl_opcnt = resp->opcnt;
1874         slot->sl_status = resp->cstate.status;
1875
1876         slot->sl_flags |= NFSD4_SLOT_INITIALIZED;
1877         if (nfsd4_not_cached(resp)) {
1878                 slot->sl_datalen = 0;
1879                 return;
1880         }
1881         base = resp->cstate.data_offset;
1882         slot->sl_datalen = buf->len - base;
1883         if (read_bytes_from_xdr_buf(buf, base, slot->sl_data, slot->sl_datalen))
1884                 WARN("%s: sessions DRC could not cache compound\n", __func__);
1885         return;
1886 }
1887
1888 /*
1889  * Encode the replay sequence operation from the slot values.
1890  * If cachethis is FALSE encode the uncached rep error on the next
1891  * operation which sets resp->p and increments resp->opcnt for
1892  * nfs4svc_encode_compoundres.
1893  *
1894  */
1895 static __be32
1896 nfsd4_enc_sequence_replay(struct nfsd4_compoundargs *args,
1897                           struct nfsd4_compoundres *resp)
1898 {
1899         struct nfsd4_op *op;
1900         struct nfsd4_slot *slot = resp->cstate.slot;
1901
1902         /* Encode the replayed sequence operation */
1903         op = &args->ops[resp->opcnt - 1];
1904         nfsd4_encode_operation(resp, op);
1905
1906         /* Return nfserr_retry_uncached_rep in next operation. */
1907         if (args->opcnt > 1 && !(slot->sl_flags & NFSD4_SLOT_CACHETHIS)) {
1908                 op = &args->ops[resp->opcnt++];
1909                 op->status = nfserr_retry_uncached_rep;
1910                 nfsd4_encode_operation(resp, op);
1911         }
1912         return op->status;
1913 }
1914
1915 /*
1916  * The sequence operation is not cached because we can use the slot and
1917  * session values.
1918  */
1919 static __be32
1920 nfsd4_replay_cache_entry(struct nfsd4_compoundres *resp,
1921                          struct nfsd4_sequence *seq)
1922 {
1923         struct nfsd4_slot *slot = resp->cstate.slot;
1924         struct xdr_stream *xdr = &resp->xdr;
1925         __be32 *p;
1926         __be32 status;
1927
1928         dprintk("--> %s slot %p\n", __func__, slot);
1929
1930         status = nfsd4_enc_sequence_replay(resp->rqstp->rq_argp, resp);
1931         if (status)
1932                 return status;
1933
1934         p = xdr_reserve_space(xdr, slot->sl_datalen);
1935         if (!p) {
1936                 WARN_ON_ONCE(1);
1937                 return nfserr_serverfault;
1938         }
1939         xdr_encode_opaque_fixed(p, slot->sl_data, slot->sl_datalen);
1940         xdr_commit_encode(xdr);
1941
1942         resp->opcnt = slot->sl_opcnt;
1943         return slot->sl_status;
1944 }
1945
1946 /*
1947  * Set the exchange_id flags returned by the server.
1948  */
1949 static void
1950 nfsd4_set_ex_flags(struct nfs4_client *new, struct nfsd4_exchange_id *clid)
1951 {
1952         /* pNFS is not supported */
1953         new->cl_exchange_flags |= EXCHGID4_FLAG_USE_NON_PNFS;
1954
1955         /* Referrals are supported, Migration is not. */
1956         new->cl_exchange_flags |= EXCHGID4_FLAG_SUPP_MOVED_REFER;
1957
1958         /* set the wire flags to return to client. */
1959         clid->flags = new->cl_exchange_flags;
1960 }
1961
1962 static bool client_has_state(struct nfs4_client *clp)
1963 {
1964         /*
1965          * Note clp->cl_openowners check isn't quite right: there's no
1966          * need to count owners without stateid's.
1967          *
1968          * Also note we should probably be using this in 4.0 case too.
1969          */
1970         return !list_empty(&clp->cl_openowners)
1971                 || !list_empty(&clp->cl_delegations)
1972                 || !list_empty(&clp->cl_sessions);
1973 }
1974
1975 __be32
1976 nfsd4_exchange_id(struct svc_rqst *rqstp,
1977                   struct nfsd4_compound_state *cstate,
1978                   struct nfsd4_exchange_id *exid)
1979 {
1980         struct nfs4_client *unconf, *conf, *new;
1981         __be32 status;
1982         char                    addr_str[INET6_ADDRSTRLEN];
1983         nfs4_verifier           verf = exid->verifier;
1984         struct sockaddr         *sa = svc_addr(rqstp);
1985         bool    update = exid->flags & EXCHGID4_FLAG_UPD_CONFIRMED_REC_A;
1986         struct nfsd_net         *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
1987
1988         rpc_ntop(sa, addr_str, sizeof(addr_str));
1989         dprintk("%s rqstp=%p exid=%p clname.len=%u clname.data=%p "
1990                 "ip_addr=%s flags %x, spa_how %d\n",
1991                 __func__, rqstp, exid, exid->clname.len, exid->clname.data,
1992                 addr_str, exid->flags, exid->spa_how);
1993
1994         if (exid->flags & ~EXCHGID4_FLAG_MASK_A)
1995                 return nfserr_inval;
1996
1997         switch (exid->spa_how) {
1998         case SP4_MACH_CRED:
1999                 if (!svc_rqst_integrity_protected(rqstp))
2000                         return nfserr_inval;
2001         case SP4_NONE:
2002                 break;
2003         default:                                /* checked by xdr code */
2004                 WARN_ON_ONCE(1);
2005         case SP4_SSV:
2006                 return nfserr_encr_alg_unsupp;
2007         }
2008
2009         /* Cases below refer to rfc 5661 section 18.35.4: */
2010         nfs4_lock_state();
2011         conf = find_confirmed_client_by_name(&exid->clname, nn);
2012         if (conf) {
2013                 bool creds_match = same_creds(&conf->cl_cred, &rqstp->rq_cred);
2014                 bool verfs_match = same_verf(&verf, &conf->cl_verifier);
2015
2016                 if (update) {
2017                         if (!clp_used_exchangeid(conf)) { /* buggy client */
2018                                 status = nfserr_inval;
2019                                 goto out;
2020                         }
2021                         if (!mach_creds_match(conf, rqstp)) {
2022                                 status = nfserr_wrong_cred;
2023                                 goto out;
2024                         }
2025                         if (!creds_match) { /* case 9 */
2026                                 status = nfserr_perm;
2027                                 goto out;
2028                         }
2029                         if (!verfs_match) { /* case 8 */
2030                                 status = nfserr_not_same;
2031                                 goto out;
2032                         }
2033                         /* case 6 */
2034                         exid->flags |= EXCHGID4_FLAG_CONFIRMED_R;
2035                         new = conf;
2036                         goto out_copy;
2037                 }
2038                 if (!creds_match) { /* case 3 */
2039                         if (client_has_state(conf)) {
2040                                 status = nfserr_clid_inuse;
2041                                 goto out;
2042                         }
2043                         expire_client(conf);
2044                         goto out_new;
2045                 }
2046                 if (verfs_match) { /* case 2 */
2047                         conf->cl_exchange_flags |= EXCHGID4_FLAG_CONFIRMED_R;
2048                         new = conf;
2049                         goto out_copy;
2050                 }
2051                 /* case 5, client reboot */
2052                 goto out_new;
2053         }
2054
2055         if (update) { /* case 7 */
2056                 status = nfserr_noent;
2057                 goto out;
2058         }
2059
2060         unconf  = find_unconfirmed_client_by_name(&exid->clname, nn);
2061         if (unconf) /* case 4, possible retry or client restart */
2062                 expire_client(unconf);
2063
2064         /* case 1 (normal case) */
2065 out_new:
2066         new = create_client(exid->clname, rqstp, &verf);
2067         if (new == NULL) {
2068                 status = nfserr_jukebox;
2069                 goto out;
2070         }
2071         new->cl_minorversion = cstate->minorversion;
2072         new->cl_mach_cred = (exid->spa_how == SP4_MACH_CRED);
2073
2074         gen_clid(new, nn);
2075         add_to_unconfirmed(new);
2076 out_copy:
2077         exid->clientid.cl_boot = new->cl_clientid.cl_boot;
2078         exid->clientid.cl_id = new->cl_clientid.cl_id;
2079
2080         exid->seqid = new->cl_cs_slot.sl_seqid + 1;
2081         nfsd4_set_ex_flags(new, exid);
2082
2083         dprintk("nfsd4_exchange_id seqid %d flags %x\n",
2084                 new->cl_cs_slot.sl_seqid, new->cl_exchange_flags);
2085         status = nfs_ok;
2086
2087 out:
2088         nfs4_unlock_state();
2089         return status;
2090 }
2091
2092 static __be32
2093 check_slot_seqid(u32 seqid, u32 slot_seqid, int slot_inuse)
2094 {
2095         dprintk("%s enter. seqid %d slot_seqid %d\n", __func__, seqid,
2096                 slot_seqid);
2097
2098         /* The slot is in use, and no response has been sent. */
2099         if (slot_inuse) {
2100                 if (seqid == slot_seqid)
2101                         return nfserr_jukebox;
2102                 else
2103                         return nfserr_seq_misordered;
2104         }
2105         /* Note unsigned 32-bit arithmetic handles wraparound: */
2106         if (likely(seqid == slot_seqid + 1))
2107                 return nfs_ok;
2108         if (seqid == slot_seqid)
2109                 return nfserr_replay_cache;
2110         return nfserr_seq_misordered;
2111 }
2112
2113 /*
2114  * Cache the create session result into the create session single DRC
2115  * slot cache by saving the xdr structure. sl_seqid has been set.
2116  * Do this for solo or embedded create session operations.
2117  */
2118 static void
2119 nfsd4_cache_create_session(struct nfsd4_create_session *cr_ses,
2120                            struct nfsd4_clid_slot *slot, __be32 nfserr)
2121 {
2122         slot->sl_status = nfserr;
2123         memcpy(&slot->sl_cr_ses, cr_ses, sizeof(*cr_ses));
2124 }
2125
2126 static __be32
2127 nfsd4_replay_create_session(struct nfsd4_create_session *cr_ses,
2128                             struct nfsd4_clid_slot *slot)
2129 {
2130         memcpy(cr_ses, &slot->sl_cr_ses, sizeof(*cr_ses));
2131         return slot->sl_status;
2132 }
2133
2134 #define NFSD_MIN_REQ_HDR_SEQ_SZ ((\
2135                         2 * 2 + /* credential,verifier: AUTH_NULL, length 0 */ \
2136                         1 +     /* MIN tag is length with zero, only length */ \
2137                         3 +     /* version, opcount, opcode */ \
2138                         XDR_QUADLEN(NFS4_MAX_SESSIONID_LEN) + \
2139                                 /* seqid, slotID, slotID, cache */ \
2140                         4 ) * sizeof(__be32))
2141
2142 #define NFSD_MIN_RESP_HDR_SEQ_SZ ((\
2143                         2 +     /* verifier: AUTH_NULL, length 0 */\
2144                         1 +     /* status */ \
2145                         1 +     /* MIN tag is length with zero, only length */ \
2146                         3 +     /* opcount, opcode, opstatus*/ \
2147                         XDR_QUADLEN(NFS4_MAX_SESSIONID_LEN) + \
2148                                 /* seqid, slotID, slotID, slotID, status */ \
2149                         5 ) * sizeof(__be32))
2150
2151 static __be32 check_forechannel_attrs(struct nfsd4_channel_attrs *ca, struct nfsd_net *nn)
2152 {
2153         u32 maxrpc = nn->nfsd_serv->sv_max_mesg;
2154
2155         if (ca->maxreq_sz < NFSD_MIN_REQ_HDR_SEQ_SZ)
2156                 return nfserr_toosmall;
2157         if (ca->maxresp_sz < NFSD_MIN_RESP_HDR_SEQ_SZ)
2158                 return nfserr_toosmall;
2159         ca->headerpadsz = 0;
2160         ca->maxreq_sz = min_t(u32, ca->maxreq_sz, maxrpc);
2161         ca->maxresp_sz = min_t(u32, ca->maxresp_sz, maxrpc);
2162         ca->maxops = min_t(u32, ca->maxops, NFSD_MAX_OPS_PER_COMPOUND);
2163         ca->maxresp_cached = min_t(u32, ca->maxresp_cached,
2164                         NFSD_SLOT_CACHE_SIZE + NFSD_MIN_HDR_SEQ_SZ);
2165         ca->maxreqs = min_t(u32, ca->maxreqs, NFSD_MAX_SLOTS_PER_SESSION);
2166         /*
2167          * Note decreasing slot size below client's request may make it
2168          * difficult for client to function correctly, whereas
2169          * decreasing the number of slots will (just?) affect
2170          * performance.  When short on memory we therefore prefer to
2171          * decrease number of slots instead of their size.  Clients that
2172          * request larger slots than they need will get poor results:
2173          */
2174         ca->maxreqs = nfsd4_get_drc_mem(ca);
2175         if (!ca->maxreqs)
2176                 return nfserr_jukebox;
2177
2178         return nfs_ok;
2179 }
2180
2181 #define NFSD_CB_MAX_REQ_SZ      ((NFS4_enc_cb_recall_sz + \
2182                                  RPC_MAX_HEADER_WITH_AUTH) * sizeof(__be32))
2183 #define NFSD_CB_MAX_RESP_SZ     ((NFS4_dec_cb_recall_sz + \
2184                                  RPC_MAX_REPHEADER_WITH_AUTH) * sizeof(__be32))
2185
2186 static __be32 check_backchannel_attrs(struct nfsd4_channel_attrs *ca)
2187 {
2188         ca->headerpadsz = 0;
2189
2190         /*
2191          * These RPC_MAX_HEADER macros are overkill, especially since we
2192          * don't even do gss on the backchannel yet.  But this is still
2193          * less than 1k.  Tighten up this estimate in the unlikely event
2194          * it turns out to be a problem for some client:
2195          */
2196         if (ca->maxreq_sz < NFSD_CB_MAX_REQ_SZ)
2197                 return nfserr_toosmall;
2198         if (ca->maxresp_sz < NFSD_CB_MAX_RESP_SZ)
2199                 return nfserr_toosmall;
2200         ca->maxresp_cached = 0;
2201         if (ca->maxops < 2)
2202                 return nfserr_toosmall;
2203
2204         return nfs_ok;
2205 }
2206
2207 static __be32 nfsd4_check_cb_sec(struct nfsd4_cb_sec *cbs)
2208 {
2209         switch (cbs->flavor) {
2210         case RPC_AUTH_NULL:
2211         case RPC_AUTH_UNIX:
2212                 return nfs_ok;
2213         default:
2214                 /*
2215                  * GSS case: the spec doesn't allow us to return this
2216                  * error.  But it also doesn't allow us not to support
2217                  * GSS.
2218                  * I'd rather this fail hard than return some error the
2219                  * client might think it can already handle:
2220                  */
2221                 return nfserr_encr_alg_unsupp;
2222         }
2223 }
2224
2225 __be32
2226 nfsd4_create_session(struct svc_rqst *rqstp,
2227                      struct nfsd4_compound_state *cstate,
2228                      struct nfsd4_create_session *cr_ses)
2229 {
2230         struct sockaddr *sa = svc_addr(rqstp);
2231         struct nfs4_client *conf, *unconf;
2232         struct nfsd4_session *new;
2233         struct nfsd4_conn *conn;
2234         struct nfsd4_clid_slot *cs_slot = NULL;
2235         __be32 status = 0;
2236         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
2237
2238         if (cr_ses->flags & ~SESSION4_FLAG_MASK_A)
2239                 return nfserr_inval;
2240         status = nfsd4_check_cb_sec(&cr_ses->cb_sec);
2241         if (status)
2242                 return status;
2243         status = check_forechannel_attrs(&cr_ses->fore_channel, nn);
2244         if (status)
2245                 return status;
2246         status = check_backchannel_attrs(&cr_ses->back_channel);
2247         if (status)
2248                 goto out_release_drc_mem;
2249         status = nfserr_jukebox;
2250         new = alloc_session(&cr_ses->fore_channel, &cr_ses->back_channel);
2251         if (!new)
2252                 goto out_release_drc_mem;
2253         conn = alloc_conn_from_crses(rqstp, cr_ses);
2254         if (!conn)
2255                 goto out_free_session;
2256
2257         nfs4_lock_state();
2258         unconf = find_unconfirmed_client(&cr_ses->clientid, true, nn);
2259         conf = find_confirmed_client(&cr_ses->clientid, true, nn);
2260         WARN_ON_ONCE(conf && unconf);
2261
2262         if (conf) {
2263                 status = nfserr_wrong_cred;
2264                 if (!mach_creds_match(conf, rqstp))
2265                         goto out_free_conn;
2266                 cs_slot = &conf->cl_cs_slot;
2267                 status = check_slot_seqid(cr_ses->seqid, cs_slot->sl_seqid, 0);
2268                 if (status == nfserr_replay_cache) {
2269                         status = nfsd4_replay_create_session(cr_ses, cs_slot);
2270                         goto out_free_conn;
2271                 } else if (cr_ses->seqid != cs_slot->sl_seqid + 1) {
2272                         status = nfserr_seq_misordered;
2273                         goto out_free_conn;
2274                 }
2275         } else if (unconf) {
2276                 struct nfs4_client *old;
2277                 if (!same_creds(&unconf->cl_cred, &rqstp->rq_cred) ||
2278                     !rpc_cmp_addr(sa, (struct sockaddr *) &unconf->cl_addr)) {
2279                         status = nfserr_clid_inuse;
2280                         goto out_free_conn;
2281                 }
2282                 status = nfserr_wrong_cred;
2283                 if (!mach_creds_match(unconf, rqstp))
2284                         goto out_free_conn;
2285                 cs_slot = &unconf->cl_cs_slot;
2286                 status = check_slot_seqid(cr_ses->seqid, cs_slot->sl_seqid, 0);
2287                 if (status) {
2288                         /* an unconfirmed replay returns misordered */
2289                         status = nfserr_seq_misordered;
2290                         goto out_free_conn;
2291                 }
2292                 old = find_confirmed_client_by_name(&unconf->cl_name, nn);
2293                 if (old) {
2294                         status = mark_client_expired(old);
2295                         if (status)
2296                                 goto out_free_conn;
2297                         expire_client(old);
2298                 }
2299                 move_to_confirmed(unconf);
2300                 conf = unconf;
2301         } else {
2302                 status = nfserr_stale_clientid;
2303                 goto out_free_conn;
2304         }
2305         status = nfs_ok;
2306         /*
2307          * We do not support RDMA or persistent sessions
2308          */
2309         cr_ses->flags &= ~SESSION4_PERSIST;
2310         cr_ses->flags &= ~SESSION4_RDMA;
2311
2312         init_session(rqstp, new, conf, cr_ses);
2313         nfsd4_init_conn(rqstp, conn, new);
2314
2315         memcpy(cr_ses->sessionid.data, new->se_sessionid.data,
2316                NFS4_MAX_SESSIONID_LEN);
2317         cs_slot->sl_seqid++;
2318         cr_ses->seqid = cs_slot->sl_seqid;
2319
2320         /* cache solo and embedded create sessions under the state lock */
2321         nfsd4_cache_create_session(cr_ses, cs_slot, status);
2322         nfs4_unlock_state();
2323         return status;
2324 out_free_conn:
2325         nfs4_unlock_state();
2326         free_conn(conn);
2327 out_free_session:
2328         __free_session(new);
2329 out_release_drc_mem:
2330         nfsd4_put_drc_mem(&cr_ses->fore_channel);
2331         return status;
2332 }
2333
2334 static __be32 nfsd4_map_bcts_dir(u32 *dir)
2335 {
2336         switch (*dir) {
2337         case NFS4_CDFC4_FORE:
2338         case NFS4_CDFC4_BACK:
2339                 return nfs_ok;
2340         case NFS4_CDFC4_FORE_OR_BOTH:
2341         case NFS4_CDFC4_BACK_OR_BOTH:
2342                 *dir = NFS4_CDFC4_BOTH;
2343                 return nfs_ok;
2344         };
2345         return nfserr_inval;
2346 }
2347
2348 __be32 nfsd4_backchannel_ctl(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate, struct nfsd4_backchannel_ctl *bc)
2349 {
2350         struct nfsd4_session *session = cstate->session;
2351         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
2352         __be32 status;
2353
2354         status = nfsd4_check_cb_sec(&bc->bc_cb_sec);
2355         if (status)
2356                 return status;
2357         spin_lock(&nn->client_lock);
2358         session->se_cb_prog = bc->bc_cb_program;
2359         session->se_cb_sec = bc->bc_cb_sec;
2360         spin_unlock(&nn->client_lock);
2361
2362         nfsd4_probe_callback(session->se_client);
2363
2364         return nfs_ok;
2365 }
2366
2367 __be32 nfsd4_bind_conn_to_session(struct svc_rqst *rqstp,
2368                      struct nfsd4_compound_state *cstate,
2369                      struct nfsd4_bind_conn_to_session *bcts)
2370 {
2371         __be32 status;
2372         struct nfsd4_conn *conn;
2373         struct nfsd4_session *session;
2374         struct net *net = SVC_NET(rqstp);
2375         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
2376
2377         if (!nfsd4_last_compound_op(rqstp))
2378                 return nfserr_not_only_op;
2379         nfs4_lock_state();
2380         spin_lock(&nn->client_lock);
2381         session = find_in_sessionid_hashtbl(&bcts->sessionid, net, &status);
2382         spin_unlock(&nn->client_lock);
2383         if (!session)
2384                 goto out_no_session;
2385         status = nfserr_wrong_cred;
2386         if (!mach_creds_match(session->se_client, rqstp))
2387                 goto out;
2388         status = nfsd4_map_bcts_dir(&bcts->dir);
2389         if (status)
2390                 goto out;
2391         conn = alloc_conn(rqstp, bcts->dir);
2392         status = nfserr_jukebox;
2393         if (!conn)
2394                 goto out;
2395         nfsd4_init_conn(rqstp, conn, session);
2396         status = nfs_ok;
2397 out:
2398         nfsd4_put_session(session);
2399 out_no_session:
2400         nfs4_unlock_state();
2401         return status;
2402 }
2403
2404 static bool nfsd4_compound_in_session(struct nfsd4_session *session, struct nfs4_sessionid *sid)
2405 {
2406         if (!session)
2407                 return 0;
2408         return !memcmp(sid, &session->se_sessionid, sizeof(*sid));
2409 }
2410
2411 __be32
2412 nfsd4_destroy_session(struct svc_rqst *r,
2413                       struct nfsd4_compound_state *cstate,
2414                       struct nfsd4_destroy_session *sessionid)
2415 {
2416         struct nfsd4_session *ses;
2417         __be32 status;
2418         int ref_held_by_me = 0;
2419         struct net *net = SVC_NET(r);
2420         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
2421
2422         nfs4_lock_state();
2423         status = nfserr_not_only_op;
2424         if (nfsd4_compound_in_session(cstate->session, &sessionid->sessionid)) {
2425                 if (!nfsd4_last_compound_op(r))
2426                         goto out;
2427                 ref_held_by_me++;
2428         }
2429         dump_sessionid(__func__, &sessionid->sessionid);
2430         spin_lock(&nn->client_lock);
2431         ses = find_in_sessionid_hashtbl(&sessionid->sessionid, net, &status);
2432         if (!ses)
2433                 goto out_client_lock;
2434         status = nfserr_wrong_cred;
2435         if (!mach_creds_match(ses->se_client, r))
2436                 goto out_put_session;
2437         status = mark_session_dead_locked(ses, 1 + ref_held_by_me);
2438         if (status)
2439                 goto out_put_session;
2440         unhash_session(ses);
2441         spin_unlock(&nn->client_lock);
2442
2443         nfsd4_probe_callback_sync(ses->se_client);
2444
2445         spin_lock(&nn->client_lock);
2446         status = nfs_ok;
2447 out_put_session:
2448         nfsd4_put_session_locked(ses);
2449 out_client_lock:
2450         spin_unlock(&nn->client_lock);
2451 out:
2452         nfs4_unlock_state();
2453         return status;
2454 }
2455
2456 static struct nfsd4_conn *__nfsd4_find_conn(struct svc_xprt *xpt, struct nfsd4_session *s)
2457 {
2458         struct nfsd4_conn *c;
2459
2460         list_for_each_entry(c, &s->se_conns, cn_persession) {
2461                 if (c->cn_xprt == xpt) {
2462                         return c;
2463                 }
2464         }
2465         return NULL;
2466 }
2467
2468 static __be32 nfsd4_sequence_check_conn(struct nfsd4_conn *new, struct nfsd4_session *ses)
2469 {
2470         struct nfs4_client *clp = ses->se_client;
2471         struct nfsd4_conn *c;
2472         __be32 status = nfs_ok;
2473         int ret;
2474
2475         spin_lock(&clp->cl_lock);
2476         c = __nfsd4_find_conn(new->cn_xprt, ses);
2477         if (c)
2478                 goto out_free;
2479         status = nfserr_conn_not_bound_to_session;
2480         if (clp->cl_mach_cred)
2481                 goto out_free;
2482         __nfsd4_hash_conn(new, ses);
2483         spin_unlock(&clp->cl_lock);
2484         ret = nfsd4_register_conn(new);
2485         if (ret)
2486                 /* oops; xprt is already down: */
2487                 nfsd4_conn_lost(&new->cn_xpt_user);
2488         return nfs_ok;
2489 out_free:
2490         spin_unlock(&clp->cl_lock);
2491         free_conn(new);
2492         return status;
2493 }
2494
2495 static bool nfsd4_session_too_many_ops(struct svc_rqst *rqstp, struct nfsd4_session *session)
2496 {
2497         struct nfsd4_compoundargs *args = rqstp->rq_argp;
2498
2499         return args->opcnt > session->se_fchannel.maxops;
2500 }
2501
2502 static bool nfsd4_request_too_big(struct svc_rqst *rqstp,
2503                                   struct nfsd4_session *session)
2504 {
2505         struct xdr_buf *xb = &rqstp->rq_arg;
2506
2507         return xb->len > session->se_fchannel.maxreq_sz;
2508 }
2509
2510 __be32
2511 nfsd4_sequence(struct svc_rqst *rqstp,
2512                struct nfsd4_compound_state *cstate,
2513                struct nfsd4_sequence *seq)
2514 {
2515         struct nfsd4_compoundres *resp = rqstp->rq_resp;
2516         struct xdr_stream *xdr = &resp->xdr;
2517         struct nfsd4_session *session;
2518         struct nfs4_client *clp;
2519         struct nfsd4_slot *slot;
2520         struct nfsd4_conn *conn;
2521         __be32 status;
2522         int buflen;
2523         struct net *net = SVC_NET(rqstp);
2524         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
2525
2526         if (resp->opcnt != 1)
2527                 return nfserr_sequence_pos;
2528
2529         /*
2530          * Will be either used or freed by nfsd4_sequence_check_conn
2531          * below.
2532          */
2533         conn = alloc_conn(rqstp, NFS4_CDFC4_FORE);
2534         if (!conn)
2535                 return nfserr_jukebox;
2536
2537         spin_lock(&nn->client_lock);
2538         session = find_in_sessionid_hashtbl(&seq->sessionid, net, &status);
2539         if (!session)
2540                 goto out_no_session;
2541         clp = session->se_client;
2542
2543         status = nfserr_too_many_ops;
2544         if (nfsd4_session_too_many_ops(rqstp, session))
2545                 goto out_put_session;
2546
2547         status = nfserr_req_too_big;
2548         if (nfsd4_request_too_big(rqstp, session))
2549                 goto out_put_session;
2550
2551         status = nfserr_badslot;
2552         if (seq->slotid >= session->se_fchannel.maxreqs)
2553                 goto out_put_session;
2554
2555         slot = session->se_slots[seq->slotid];
2556         dprintk("%s: slotid %d\n", __func__, seq->slotid);
2557
2558         /* We do not negotiate the number of slots yet, so set the
2559          * maxslots to the session maxreqs which is used to encode
2560          * sr_highest_slotid and the sr_target_slot id to maxslots */
2561         seq->maxslots = session->se_fchannel.maxreqs;
2562
2563         status = check_slot_seqid(seq->seqid, slot->sl_seqid,
2564                                         slot->sl_flags & NFSD4_SLOT_INUSE);
2565         if (status == nfserr_replay_cache) {
2566                 status = nfserr_seq_misordered;
2567                 if (!(slot->sl_flags & NFSD4_SLOT_INITIALIZED))
2568                         goto out_put_session;
2569                 cstate->slot = slot;
2570                 cstate->session = session;
2571                 cstate->clp = clp;
2572                 /* Return the cached reply status and set cstate->status
2573                  * for nfsd4_proc_compound processing */
2574                 status = nfsd4_replay_cache_entry(resp, seq);
2575                 cstate->status = nfserr_replay_cache;
2576                 goto out;
2577         }
2578         if (status)
2579                 goto out_put_session;
2580
2581         status = nfsd4_sequence_check_conn(conn, session);
2582         conn = NULL;
2583         if (status)
2584                 goto out_put_session;
2585
2586         buflen = (seq->cachethis) ?
2587                         session->se_fchannel.maxresp_cached :
2588                         session->se_fchannel.maxresp_sz;
2589         status = (seq->cachethis) ? nfserr_rep_too_big_to_cache :
2590                                     nfserr_rep_too_big;
2591         if (xdr_restrict_buflen(xdr, buflen - rqstp->rq_auth_slack))
2592                 goto out_put_session;
2593         svc_reserve(rqstp, buflen);
2594
2595         status = nfs_ok;
2596         /* Success! bump slot seqid */
2597         slot->sl_seqid = seq->seqid;
2598         slot->sl_flags |= NFSD4_SLOT_INUSE;
2599         if (seq->cachethis)
2600                 slot->sl_flags |= NFSD4_SLOT_CACHETHIS;
2601         else
2602                 slot->sl_flags &= ~NFSD4_SLOT_CACHETHIS;
2603
2604         cstate->slot = slot;
2605         cstate->session = session;
2606         cstate->clp = clp;
2607
2608 out:
2609         switch (clp->cl_cb_state) {
2610         case NFSD4_CB_DOWN:
2611                 seq->status_flags = SEQ4_STATUS_CB_PATH_DOWN;
2612                 break;
2613         case NFSD4_CB_FAULT:
2614                 seq->status_flags = SEQ4_STATUS_BACKCHANNEL_FAULT;
2615                 break;
2616         default:
2617                 seq->status_flags = 0;
2618         }
2619         if (!list_empty(&clp->cl_revoked))
2620                 seq->status_flags |= SEQ4_STATUS_RECALLABLE_STATE_REVOKED;
2621 out_no_session:
2622         if (conn)
2623                 free_conn(conn);
2624         spin_unlock(&nn->client_lock);
2625         return status;
2626 out_put_session:
2627         nfsd4_put_session_locked(session);
2628         goto out_no_session;
2629 }
2630
2631 void
2632 nfsd4_sequence_done(struct nfsd4_compoundres *resp)
2633 {
2634         struct nfsd4_compound_state *cs = &resp->cstate;
2635
2636         if (nfsd4_has_session(cs)) {
2637                 if (cs->status != nfserr_replay_cache) {
2638                         nfsd4_store_cache_entry(resp);
2639                         cs->slot->sl_flags &= ~NFSD4_SLOT_INUSE;
2640                 }
2641                 /* Drop session reference that was taken in nfsd4_sequence() */
2642                 nfsd4_put_session(cs->session);
2643         } else if (cs->clp)
2644                 put_client_renew(cs->clp);
2645 }
2646
2647 __be32
2648 nfsd4_destroy_clientid(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate, struct nfsd4_destroy_clientid *dc)
2649 {
2650         struct nfs4_client *conf, *unconf, *clp;
2651         __be32 status = 0;
2652         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
2653
2654         nfs4_lock_state();
2655         unconf = find_unconfirmed_client(&dc->clientid, true, nn);
2656         conf = find_confirmed_client(&dc->clientid, true, nn);
2657         WARN_ON_ONCE(conf && unconf);
2658
2659         if (conf) {
2660                 clp = conf;
2661
2662                 if (client_has_state(conf)) {
2663                         status = nfserr_clientid_busy;
2664                         goto out;
2665                 }
2666         } else if (unconf)
2667                 clp = unconf;
2668         else {
2669                 status = nfserr_stale_clientid;
2670                 goto out;
2671         }
2672         if (!mach_creds_match(clp, rqstp)) {
2673                 status = nfserr_wrong_cred;
2674                 goto out;
2675         }
2676         expire_client(clp);
2677 out:
2678         nfs4_unlock_state();
2679         return status;
2680 }
2681
2682 __be32
2683 nfsd4_reclaim_complete(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate, struct nfsd4_reclaim_complete *rc)
2684 {
2685         __be32 status = 0;
2686
2687         if (rc->rca_one_fs) {
2688                 if (!cstate->current_fh.fh_dentry)
2689                         return nfserr_nofilehandle;
2690                 /*
2691                  * We don't take advantage of the rca_one_fs case.
2692                  * That's OK, it's optional, we can safely ignore it.
2693                  */
2694                  return nfs_ok;
2695         }
2696
2697         nfs4_lock_state();
2698         status = nfserr_complete_already;
2699         if (test_and_set_bit(NFSD4_CLIENT_RECLAIM_COMPLETE,
2700                              &cstate->session->se_client->cl_flags))
2701                 goto out;
2702
2703         status = nfserr_stale_clientid;
2704         if (is_client_expired(cstate->session->se_client))
2705                 /*
2706                  * The following error isn't really legal.
2707                  * But we only get here if the client just explicitly
2708                  * destroyed the client.  Surely it no longer cares what
2709                  * error it gets back on an operation for the dead
2710                  * client.
2711                  */
2712                 goto out;
2713
2714         status = nfs_ok;
2715         nfsd4_client_record_create(cstate->session->se_client);
2716 out:
2717         nfs4_unlock_state();
2718         return status;
2719 }
2720
2721 __be32
2722 nfsd4_setclientid(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
2723                   struct nfsd4_setclientid *setclid)
2724 {
2725         struct xdr_netobj       clname = setclid->se_name;
2726         nfs4_verifier           clverifier = setclid->se_verf;
2727         struct nfs4_client      *conf, *unconf, *new;
2728         __be32                  status;
2729         struct nfsd_net         *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
2730
2731         /* Cases below refer to rfc 3530 section 14.2.33: */
2732         nfs4_lock_state();
2733         conf = find_confirmed_client_by_name(&clname, nn);
2734         if (conf) {
2735                 /* case 0: */
2736                 status = nfserr_clid_inuse;
2737                 if (clp_used_exchangeid(conf))
2738                         goto out;
2739                 if (!same_creds(&conf->cl_cred, &rqstp->rq_cred)) {
2740                         char addr_str[INET6_ADDRSTRLEN];
2741                         rpc_ntop((struct sockaddr *) &conf->cl_addr, addr_str,
2742                                  sizeof(addr_str));
2743                         dprintk("NFSD: setclientid: string in use by client "
2744                                 "at %s\n", addr_str);
2745                         goto out;
2746                 }
2747         }
2748         unconf = find_unconfirmed_client_by_name(&clname, nn);
2749         if (unconf)
2750                 expire_client(unconf);
2751         status = nfserr_jukebox;
2752         new = create_client(clname, rqstp, &clverifier);
2753         if (new == NULL)
2754                 goto out;
2755         if (conf && same_verf(&conf->cl_verifier, &clverifier))
2756                 /* case 1: probable callback update */
2757                 copy_clid(new, conf);
2758         else /* case 4 (new client) or cases 2, 3 (client reboot): */
2759                 gen_clid(new, nn);
2760         new->cl_minorversion = 0;
2761         gen_callback(new, setclid, rqstp);
2762         add_to_unconfirmed(new);
2763         setclid->se_clientid.cl_boot = new->cl_clientid.cl_boot;
2764         setclid->se_clientid.cl_id = new->cl_clientid.cl_id;
2765         memcpy(setclid->se_confirm.data, new->cl_confirm.data, sizeof(setclid->se_confirm.data));
2766         status = nfs_ok;
2767 out:
2768         nfs4_unlock_state();
2769         return status;
2770 }
2771
2772
2773 __be32
2774 nfsd4_setclientid_confirm(struct svc_rqst *rqstp,
2775                          struct nfsd4_compound_state *cstate,
2776                          struct nfsd4_setclientid_confirm *setclientid_confirm)
2777 {
2778         struct nfs4_client *conf, *unconf;
2779         nfs4_verifier confirm = setclientid_confirm->sc_confirm; 
2780         clientid_t * clid = &setclientid_confirm->sc_clientid;
2781         __be32 status;
2782         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
2783
2784         if (STALE_CLIENTID(clid, nn))
2785                 return nfserr_stale_clientid;
2786         nfs4_lock_state();
2787
2788         conf = find_confirmed_client(clid, false, nn);
2789         unconf = find_unconfirmed_client(clid, false, nn);
2790         /*
2791          * We try hard to give out unique clientid's, so if we get an
2792          * attempt to confirm the same clientid with a different cred,
2793          * there's a bug somewhere.  Let's charitably assume it's our
2794          * bug.
2795          */
2796         status = nfserr_serverfault;
2797         if (unconf && !same_creds(&unconf->cl_cred, &rqstp->rq_cred))
2798                 goto out;
2799         if (conf && !same_creds(&conf->cl_cred, &rqstp->rq_cred))
2800                 goto out;
2801         /* cases below refer to rfc 3530 section 14.2.34: */
2802         if (!unconf || !same_verf(&confirm, &unconf->cl_confirm)) {
2803                 if (conf && !unconf) /* case 2: probable retransmit */
2804                         status = nfs_ok;
2805                 else /* case 4: client hasn't noticed we rebooted yet? */
2806                         status = nfserr_stale_clientid;
2807                 goto out;
2808         }
2809         status = nfs_ok;
2810         if (conf) { /* case 1: callback update */
2811                 nfsd4_change_callback(conf, &unconf->cl_cb_conn);
2812                 nfsd4_probe_callback(conf);
2813                 expire_client(unconf);
2814         } else { /* case 3: normal case; new or rebooted client */
2815                 conf = find_confirmed_client_by_name(&unconf->cl_name, nn);
2816                 if (conf) {
2817                         status = mark_client_expired(conf);
2818                         if (status)
2819                                 goto out;
2820                         expire_client(conf);
2821                 }
2822                 move_to_confirmed(unconf);
2823                 nfsd4_probe_callback(unconf);
2824         }
2825 out:
2826         nfs4_unlock_state();
2827         return status;
2828 }
2829
2830 static struct nfs4_file *nfsd4_alloc_file(void)
2831 {
2832         return kmem_cache_alloc(file_slab, GFP_KERNEL);
2833 }
2834
2835 /* OPEN Share state helper functions */
2836 static void nfsd4_init_file(struct nfs4_file *fp, struct inode *ino)
2837 {
2838         unsigned int hashval = file_hashval(ino);
2839
2840         lockdep_assert_held(&state_lock);
2841
2842         atomic_set(&fp->fi_ref, 1);
2843         spin_lock_init(&fp->fi_lock);
2844         INIT_LIST_HEAD(&fp->fi_stateids);
2845         INIT_LIST_HEAD(&fp->fi_delegations);
2846         ihold(ino);
2847         fp->fi_inode = ino;
2848         fp->fi_had_conflict = false;
2849         fp->fi_lease = NULL;
2850         fp->fi_share_deny = 0;
2851         memset(fp->fi_fds, 0, sizeof(fp->fi_fds));
2852         memset(fp->fi_access, 0, sizeof(fp->fi_access));
2853         hlist_add_head(&fp->fi_hash, &file_hashtbl[hashval]);
2854 }
2855
2856 void
2857 nfsd4_free_slabs(void)
2858 {
2859         kmem_cache_destroy(openowner_slab);
2860         kmem_cache_destroy(lockowner_slab);
2861         kmem_cache_destroy(file_slab);
2862         kmem_cache_destroy(stateid_slab);
2863         kmem_cache_destroy(deleg_slab);
2864 }
2865
2866 int
2867 nfsd4_init_slabs(void)
2868 {
2869         openowner_slab = kmem_cache_create("nfsd4_openowners",
2870                         sizeof(struct nfs4_openowner), 0, 0, NULL);
2871         if (openowner_slab == NULL)
2872                 goto out;
2873         lockowner_slab = kmem_cache_create("nfsd4_lockowners",
2874                         sizeof(struct nfs4_lockowner), 0, 0, NULL);
2875         if (lockowner_slab == NULL)
2876                 goto out_free_openowner_slab;
2877         file_slab = kmem_cache_create("nfsd4_files",
2878                         sizeof(struct nfs4_file), 0, 0, NULL);
2879         if (file_slab == NULL)
2880                 goto out_free_lockowner_slab;
2881         stateid_slab = kmem_cache_create("nfsd4_stateids",
2882                         sizeof(struct nfs4_ol_stateid), 0, 0, NULL);
2883         if (stateid_slab == NULL)
2884                 goto out_free_file_slab;
2885         deleg_slab = kmem_cache_create("nfsd4_delegations",
2886                         sizeof(struct nfs4_delegation), 0, 0, NULL);
2887         if (deleg_slab == NULL)
2888                 goto out_free_stateid_slab;
2889         return 0;
2890
2891 out_free_stateid_slab:
2892         kmem_cache_destroy(stateid_slab);
2893 out_free_file_slab:
2894         kmem_cache_destroy(file_slab);
2895 out_free_lockowner_slab:
2896         kmem_cache_destroy(lockowner_slab);
2897 out_free_openowner_slab:
2898         kmem_cache_destroy(openowner_slab);
2899 out:
2900         dprintk("nfsd4: out of memory while initializing nfsv4\n");
2901         return -ENOMEM;
2902 }
2903
2904 static void init_nfs4_replay(struct nfs4_replay *rp)
2905 {
2906         rp->rp_status = nfserr_serverfault;
2907         rp->rp_buflen = 0;
2908         rp->rp_buf = rp->rp_ibuf;
2909 }
2910
2911 static inline void *alloc_stateowner(struct kmem_cache *slab, struct xdr_netobj *owner, struct nfs4_client *clp)
2912 {
2913         struct nfs4_stateowner *sop;
2914
2915         sop = kmem_cache_alloc(slab, GFP_KERNEL);
2916         if (!sop)
2917                 return NULL;
2918
2919         sop->so_owner.data = kmemdup(owner->data, owner->len, GFP_KERNEL);
2920         if (!sop->so_owner.data) {
2921                 kmem_cache_free(slab, sop);
2922                 return NULL;
2923         }
2924         sop->so_owner.len = owner->len;
2925
2926         INIT_LIST_HEAD(&sop->so_stateids);
2927         sop->so_client = clp;
2928         init_nfs4_replay(&sop->so_replay);
2929         return sop;
2930 }
2931
2932 static void hash_openowner(struct nfs4_openowner *oo, struct nfs4_client *clp, unsigned int strhashval)
2933 {
2934         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
2935
2936         list_add(&oo->oo_owner.so_strhash, &nn->ownerstr_hashtbl[strhashval]);
2937         list_add(&oo->oo_perclient, &clp->cl_openowners);
2938 }
2939
2940 static struct nfs4_openowner *
2941 alloc_init_open_stateowner(unsigned int strhashval, struct nfsd4_open *open,
2942                            struct nfsd4_compound_state *cstate)
2943 {
2944         struct nfs4_client *clp = cstate->clp;
2945         struct nfs4_openowner *oo;
2946
2947         oo = alloc_stateowner(openowner_slab, &open->op_owner, clp);
2948         if (!oo)
2949                 return NULL;
2950         oo->oo_owner.so_is_open_owner = 1;
2951         oo->oo_owner.so_seqid = open->op_seqid;
2952         oo->oo_flags = NFS4_OO_NEW;
2953         if (nfsd4_has_session(cstate))
2954                 oo->oo_flags |= NFS4_OO_CONFIRMED;
2955         oo->oo_time = 0;
2956         oo->oo_last_closed_stid = NULL;
2957         INIT_LIST_HEAD(&oo->oo_close_lru);
2958         hash_openowner(oo, clp, strhashval);
2959         return oo;
2960 }
2961
2962 static void init_open_stateid(struct nfs4_ol_stateid *stp, struct nfs4_file *fp, struct nfsd4_open *open) {
2963         struct nfs4_openowner *oo = open->op_openowner;
2964
2965         stp->st_stid.sc_type = NFS4_OPEN_STID;
2966         INIT_LIST_HEAD(&stp->st_locks);
2967         list_add(&stp->st_perstateowner, &oo->oo_owner.so_stateids);
2968         stp->st_stateowner = &oo->oo_owner;
2969         get_nfs4_file(fp);
2970         stp->st_file = fp;
2971         stp->st_access_bmap = 0;
2972         stp->st_deny_bmap = 0;
2973         set_access(open->op_share_access, stp);
2974         set_deny(open->op_share_deny, stp);
2975         stp->st_openstp = NULL;
2976         spin_lock(&fp->fi_lock);
2977         list_add(&stp->st_perfile, &fp->fi_stateids);
2978         spin_unlock(&fp->fi_lock);
2979 }
2980
2981 static void
2982 move_to_close_lru(struct nfs4_openowner *oo, struct net *net)
2983 {
2984         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
2985
2986         dprintk("NFSD: move_to_close_lru nfs4_openowner %p\n", oo);
2987
2988         list_move_tail(&oo->oo_close_lru, &nn->close_lru);
2989         oo->oo_time = get_seconds();
2990 }
2991
2992 static int
2993 same_owner_str(struct nfs4_stateowner *sop, struct xdr_netobj *owner,
2994                                                         clientid_t *clid)
2995 {
2996         return (sop->so_owner.len == owner->len) &&
2997                 0 == memcmp(sop->so_owner.data, owner->data, owner->len) &&
2998                 (sop->so_client->cl_clientid.cl_id == clid->cl_id);
2999 }
3000
3001 static struct nfs4_openowner *
3002 find_openstateowner_str(unsigned int hashval, struct nfsd4_open *open,
3003                         bool sessions, struct nfsd_net *nn)
3004 {
3005         struct nfs4_stateowner *so;
3006         struct nfs4_openowner *oo;
3007         struct nfs4_client *clp;
3008
3009         list_for_each_entry(so, &nn->ownerstr_hashtbl[hashval], so_strhash) {
3010                 if (!so->so_is_open_owner)
3011                         continue;
3012                 if (same_owner_str(so, &open->op_owner, &open->op_clientid)) {
3013                         oo = openowner(so);
3014                         clp = oo->oo_owner.so_client;
3015                         if ((bool)clp->cl_minorversion != sessions)
3016                                 return NULL;
3017                         renew_client(oo->oo_owner.so_client);
3018                         return oo;
3019                 }
3020         }
3021         return NULL;
3022 }
3023
3024 /* search file_hashtbl[] for file */
3025 static struct nfs4_file *
3026 find_file_locked(struct inode *ino)
3027 {
3028         unsigned int hashval = file_hashval(ino);
3029         struct nfs4_file *fp;
3030
3031         lockdep_assert_held(&state_lock);
3032
3033         hlist_for_each_entry(fp, &file_hashtbl[hashval], fi_hash) {
3034                 if (fp->fi_inode == ino) {
3035                         get_nfs4_file(fp);
3036                         return fp;
3037                 }
3038         }
3039         return NULL;
3040 }
3041
3042 static struct nfs4_file *
3043 find_file(struct inode *ino)
3044 {
3045         struct nfs4_file *fp;
3046
3047         spin_lock(&state_lock);
3048         fp = find_file_locked(ino);
3049         spin_unlock(&state_lock);
3050         return fp;
3051 }
3052
3053 static struct nfs4_file *
3054 find_or_add_file(struct inode *ino, struct nfs4_file *new)
3055 {
3056         struct nfs4_file *fp;
3057
3058         spin_lock(&state_lock);
3059         fp = find_file_locked(ino);
3060         if (fp == NULL) {
3061                 nfsd4_init_file(new, ino);
3062                 fp = new;
3063         }
3064         spin_unlock(&state_lock);
3065
3066         return fp;
3067 }
3068
3069 /*
3070  * Called to check deny when READ with all zero stateid or
3071  * WRITE with all zero or all one stateid
3072  */
3073 static __be32
3074 nfs4_share_conflict(struct svc_fh *current_fh, unsigned int deny_type)
3075 {
3076         struct inode *ino = current_fh->fh_dentry->d_inode;
3077         struct nfs4_file *fp;
3078         __be32 ret = nfs_ok;
3079
3080         fp = find_file(ino);
3081         if (!fp)
3082                 return ret;
3083         /* Check for conflicting share reservations */
3084         spin_lock(&fp->fi_lock);
3085         if (fp->fi_share_deny & deny_type)
3086                 ret = nfserr_locked;
3087         spin_unlock(&fp->fi_lock);
3088         put_nfs4_file(fp);
3089         return ret;
3090 }
3091
3092 void nfsd4_prepare_cb_recall(struct nfs4_delegation *dp)
3093 {
3094         struct nfs4_client *clp = dp->dl_stid.sc_client;
3095         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
3096
3097         /*
3098          * We can't do this in nfsd_break_deleg_cb because it is
3099          * already holding inode->i_lock
3100          */
3101         spin_lock(&state_lock);
3102         block_delegations(&dp->dl_fh);
3103         /*
3104          * If the dl_time != 0, then we know that it has already been
3105          * queued for a lease break. Don't queue it again.
3106          */
3107         if (dp->dl_time == 0) {
3108                 dp->dl_time = get_seconds();
3109                 list_add_tail(&dp->dl_recall_lru, &nn->del_recall_lru);
3110         }
3111         spin_unlock(&state_lock);
3112 }
3113
3114 static void nfsd_break_one_deleg(struct nfs4_delegation *dp)
3115 {
3116         /*
3117          * We're assuming the state code never drops its reference
3118          * without first removing the lease.  Since we're in this lease
3119          * callback (and since the lease code is serialized by the kernel
3120          * lock) we know the server hasn't removed the lease yet, we know
3121          * it's safe to take a reference.
3122          */
3123         atomic_inc(&dp->dl_count);
3124         nfsd4_cb_recall(dp);
3125 }
3126
3127 /* Called from break_lease() with i_lock held. */
3128 static void nfsd_break_deleg_cb(struct file_lock *fl)
3129 {
3130         struct nfs4_file *fp = (struct nfs4_file *)fl->fl_owner;
3131         struct nfs4_delegation *dp;
3132
3133         if (!fp) {
3134                 WARN(1, "(%p)->fl_owner NULL\n", fl);
3135                 return;
3136         }
3137         if (fp->fi_had_conflict) {
3138                 WARN(1, "duplicate break on %p\n", fp);
3139                 return;
3140         }
3141         /*
3142          * We don't want the locks code to timeout the lease for us;
3143          * we'll remove it ourself if a delegation isn't returned
3144          * in time:
3145          */
3146         fl->fl_break_time = 0;
3147
3148         fp->fi_had_conflict = true;
3149         spin_lock(&fp->fi_lock);
3150         list_for_each_entry(dp, &fp->fi_delegations, dl_perfile)
3151                 nfsd_break_one_deleg(dp);
3152         spin_unlock(&fp->fi_lock);
3153 }
3154
3155 static
3156 int nfsd_change_deleg_cb(struct file_lock **onlist, int arg)
3157 {
3158         if (arg & F_UNLCK)
3159                 return lease_modify(onlist, arg);
3160         else
3161                 return -EAGAIN;
3162 }
3163
3164 static const struct lock_manager_operations nfsd_lease_mng_ops = {
3165         .lm_break = nfsd_break_deleg_cb,
3166         .lm_change = nfsd_change_deleg_cb,
3167 };
3168
3169 static __be32 nfsd4_check_seqid(struct nfsd4_compound_state *cstate, struct nfs4_stateowner *so, u32 seqid)
3170 {
3171         if (nfsd4_has_session(cstate))
3172                 return nfs_ok;
3173         if (seqid == so->so_seqid - 1)
3174                 return nfserr_replay_me;
3175         if (seqid == so->so_seqid)
3176                 return nfs_ok;
3177         return nfserr_bad_seqid;
3178 }
3179
3180 static __be32 lookup_clientid(clientid_t *clid,
3181                 struct nfsd4_compound_state *cstate,
3182                 struct nfsd_net *nn)
3183 {
3184         struct nfs4_client *found;
3185
3186         if (cstate->clp) {
3187                 found = cstate->clp;
3188                 if (!same_clid(&found->cl_clientid, clid))
3189                         return nfserr_stale_clientid;
3190                 return nfs_ok;
3191         }
3192
3193         if (STALE_CLIENTID(clid, nn))
3194                 return nfserr_stale_clientid;
3195
3196         /*
3197          * For v4.1+ we get the client in the SEQUENCE op. If we don't have one
3198          * cached already then we know this is for is for v4.0 and "sessions"
3199          * will be false.
3200          */
3201         WARN_ON_ONCE(cstate->session);
3202         found = find_confirmed_client(clid, false, nn);
3203         if (!found)
3204                 return nfserr_expired;
3205
3206         /* Cache the nfs4_client in cstate! */
3207         cstate->clp = found;
3208         atomic_inc(&found->cl_refcount);
3209         return nfs_ok;
3210 }
3211
3212 __be32
3213 nfsd4_process_open1(struct nfsd4_compound_state *cstate,
3214                     struct nfsd4_open *open, struct nfsd_net *nn)
3215 {
3216         clientid_t *clientid = &open->op_clientid;
3217         struct nfs4_client *clp = NULL;
3218         unsigned int strhashval;
3219         struct nfs4_openowner *oo = NULL;
3220         __be32 status;
3221
3222         if (STALE_CLIENTID(&open->op_clientid, nn))
3223                 return nfserr_stale_clientid;
3224         /*
3225          * In case we need it later, after we've already created the
3226          * file and don't want to risk a further failure:
3227          */
3228         open->op_file = nfsd4_alloc_file();
3229         if (open->op_file == NULL)
3230                 return nfserr_jukebox;
3231
3232         status = lookup_clientid(clientid, cstate, nn);
3233         if (status)
3234                 return status;
3235         clp = cstate->clp;
3236
3237         strhashval = ownerstr_hashval(clientid->cl_id, &open->op_owner);
3238         oo = find_openstateowner_str(strhashval, open, cstate->minorversion, nn);
3239         open->op_openowner = oo;
3240         if (!oo) {
3241                 goto new_owner;
3242         }
3243         if (!(oo->oo_flags & NFS4_OO_CONFIRMED)) {
3244                 /* Replace unconfirmed owners without checking for replay. */
3245                 release_openowner(oo);
3246                 open->op_openowner = NULL;
3247                 goto new_owner;
3248         }
3249         status = nfsd4_check_seqid(cstate, &oo->oo_owner, open->op_seqid);
3250         if (status)
3251                 return status;
3252         goto alloc_stateid;
3253 new_owner:
3254         oo = alloc_init_open_stateowner(strhashval, open, cstate);
3255         if (oo == NULL)
3256                 return nfserr_jukebox;
3257         open->op_openowner = oo;
3258 alloc_stateid:
3259         open->op_stp = nfs4_alloc_stateid(clp);
3260         if (!open->op_stp)
3261                 return nfserr_jukebox;
3262         return nfs_ok;
3263 }
3264
3265 static inline __be32
3266 nfs4_check_delegmode(struct nfs4_delegation *dp, int flags)
3267 {
3268         if ((flags & WR_STATE) && (dp->dl_type == NFS4_OPEN_DELEGATE_READ))
3269                 return nfserr_openmode;
3270         else
3271                 return nfs_ok;
3272 }
3273
3274 static int share_access_to_flags(u32 share_access)
3275 {
3276         return share_access == NFS4_SHARE_ACCESS_READ ? RD_STATE : WR_STATE;
3277 }
3278
3279 static struct nfs4_delegation *find_deleg_stateid(struct nfs4_client *cl, stateid_t *s)
3280 {
3281         struct nfs4_stid *ret;
3282
3283         ret = find_stateid_by_type(cl, s, NFS4_DELEG_STID);
3284         if (!ret)
3285                 return NULL;
3286         return delegstateid(ret);
3287 }
3288
3289 static bool nfsd4_is_deleg_cur(struct nfsd4_open *open)
3290 {
3291         return open->op_claim_type == NFS4_OPEN_CLAIM_DELEGATE_CUR ||
3292                open->op_claim_type == NFS4_OPEN_CLAIM_DELEG_CUR_FH;
3293 }
3294
3295 static __be32
3296 nfs4_check_deleg(struct nfs4_client *cl, struct nfsd4_open *open,
3297                 struct nfs4_delegation **dp)
3298 {
3299         int flags;
3300         __be32 status = nfserr_bad_stateid;
3301
3302         *dp = find_deleg_stateid(cl, &open->op_delegate_stateid);
3303         if (*dp == NULL)
3304                 goto out;
3305         flags = share_access_to_flags(open->op_share_access);
3306         status = nfs4_check_delegmode(*dp, flags);
3307         if (status)
3308                 *dp = NULL;
3309 out:
3310         if (!nfsd4_is_deleg_cur(open))
3311                 return nfs_ok;
3312         if (status)
3313                 return status;
3314         open->op_openowner->oo_flags |= NFS4_OO_CONFIRMED;
3315         return nfs_ok;
3316 }
3317
3318 static struct nfs4_ol_stateid *
3319 nfsd4_find_existing_open(struct nfs4_file *fp, struct nfsd4_open *open)
3320 {
3321         struct nfs4_ol_stateid *local, *ret = NULL;
3322         struct nfs4_openowner *oo = open->op_openowner;
3323
3324         spin_lock(&fp->fi_lock);
3325         list_for_each_entry(local, &fp->fi_stateids, st_perfile) {
3326                 /* ignore lock owners */
3327                 if (local->st_stateowner->so_is_open_owner == 0)
3328                         continue;
3329                 if (local->st_stateowner == &oo->oo_owner) {
3330                         ret = local;
3331                         break;
3332                 }
3333         }
3334         spin_unlock(&fp->fi_lock);
3335         return ret;
3336 }
3337
3338 static inline int nfs4_access_to_access(u32 nfs4_access)
3339 {
3340         int flags = 0;
3341
3342         if (nfs4_access & NFS4_SHARE_ACCESS_READ)
3343                 flags |= NFSD_MAY_READ;
3344         if (nfs4_access & NFS4_SHARE_ACCESS_WRITE)
3345                 flags |= NFSD_MAY_WRITE;
3346         return flags;
3347 }
3348
3349 static inline __be32
3350 nfsd4_truncate(struct svc_rqst *rqstp, struct svc_fh *fh,
3351                 struct nfsd4_open *open)
3352 {
3353         struct iattr iattr = {
3354                 .ia_valid = ATTR_SIZE,
3355                 .ia_size = 0,
3356         };
3357         if (!open->op_truncate)
3358                 return 0;
3359         if (!(open->op_share_access & NFS4_SHARE_ACCESS_WRITE))
3360                 return nfserr_inval;
3361         return nfsd_setattr(rqstp, fh, &iattr, 0, (time_t)0);
3362 }
3363
3364 static __be32 nfs4_get_vfs_file(struct svc_rqst *rqstp, struct nfs4_file *fp,
3365                 struct svc_fh *cur_fh, struct nfs4_ol_stateid *stp,
3366                 struct nfsd4_open *open)
3367 {
3368         struct file *filp = NULL;
3369         __be32 status;
3370         int oflag = nfs4_access_to_omode(open->op_share_access);
3371         int access = nfs4_access_to_access(open->op_share_access);
3372         unsigned char old_access_bmap, old_deny_bmap;
3373
3374         spin_lock(&fp->fi_lock);
3375
3376         /*
3377          * Are we trying to set a deny mode that would conflict with
3378          * current access?
3379          */
3380         status = nfs4_file_check_deny(fp, open->op_share_deny);
3381         if (status != nfs_ok) {
3382                 spin_unlock(&fp->fi_lock);
3383                 goto out;
3384         }
3385
3386         /* set access to the file */
3387         status = nfs4_file_get_access(fp, open->op_share_access);
3388         if (status != nfs_ok) {
3389                 spin_unlock(&fp->fi_lock);
3390                 goto out;
3391         }
3392
3393         /* Set access bits in stateid */
3394         old_access_bmap = stp->st_access_bmap;
3395         set_access(open->op_share_access, stp);
3396
3397         /* Set new deny mask */
3398         old_deny_bmap = stp->st_deny_bmap;
3399         set_deny(open->op_share_deny, stp);
3400         fp->fi_share_deny |= (open->op_share_deny & NFS4_SHARE_DENY_BOTH);
3401
3402         if (!fp->fi_fds[oflag]) {
3403                 spin_unlock(&fp->fi_lock);
3404                 status = nfsd_open(rqstp, cur_fh, S_IFREG, access, &filp);
3405                 if (status)
3406                         goto out_put_access;
3407                 spin_lock(&fp->fi_lock);
3408                 if (!fp->fi_fds[oflag]) {
3409                         fp->fi_fds[oflag] = filp;
3410                         filp = NULL;
3411                 }
3412         }
3413         spin_unlock(&fp->fi_lock);
3414         if (filp)
3415                 fput(filp);
3416
3417         status = nfsd4_truncate(rqstp, cur_fh, open);
3418         if (status)
3419                 goto out_put_access;
3420 out:
3421         return status;
3422 out_put_access:
3423         stp->st_access_bmap = old_access_bmap;
3424         nfs4_file_put_access(fp, open->op_share_access);
3425         reset_union_bmap_deny(bmap_to_share_mode(old_deny_bmap), stp);
3426         goto out;
3427 }
3428
3429 static __be32
3430 nfs4_upgrade_open(struct svc_rqst *rqstp, struct nfs4_file *fp, struct svc_fh *cur_fh, struct nfs4_ol_stateid *stp, struct nfsd4_open *open)
3431 {
3432         __be32 status;
3433         unsigned char old_deny_bmap;
3434
3435         if (!test_access(open->op_share_access, stp))
3436                 return nfs4_get_vfs_file(rqstp, fp, cur_fh, stp, open);
3437
3438         /* test and set deny mode */
3439         spin_lock(&fp->fi_lock);
3440         status = nfs4_file_check_deny(fp, open->op_share_deny);
3441         if (status == nfs_ok) {
3442                 old_deny_bmap = stp->st_deny_bmap;
3443                 set_deny(open->op_share_deny, stp);
3444                 fp->fi_share_deny |=
3445                                 (open->op_share_deny & NFS4_SHARE_DENY_BOTH);
3446         }
3447         spin_unlock(&fp->fi_lock);
3448
3449         if (status != nfs_ok)
3450                 return status;
3451
3452         status = nfsd4_truncate(rqstp, cur_fh, open);
3453         if (status != nfs_ok)
3454                 reset_union_bmap_deny(old_deny_bmap, stp);
3455         return status;
3456 }
3457
3458 static void
3459 nfs4_set_claim_prev(struct nfsd4_open *open, bool has_session)
3460 {
3461         open->op_openowner->oo_flags |= NFS4_OO_CONFIRMED;
3462 }
3463
3464 /* Should we give out recallable state?: */
3465 static bool nfsd4_cb_channel_good(struct nfs4_client *clp)
3466 {
3467         if (clp->cl_cb_state == NFSD4_CB_UP)
3468                 return true;
3469         /*
3470          * In the sessions case, since we don't have to establish a
3471          * separate connection for callbacks, we assume it's OK
3472          * until we hear otherwise:
3473          */
3474         return clp->cl_minorversion && clp->cl_cb_state == NFSD4_CB_UNKNOWN;
3475 }
3476
3477 static struct file_lock *nfs4_alloc_init_lease(struct nfs4_delegation *dp, int flag)
3478 {
3479         struct file_lock *fl;
3480
3481         fl = locks_alloc_lock();
3482         if (!fl)
3483                 return NULL;
3484         locks_init_lock(fl);
3485         fl->fl_lmops = &nfsd_lease_mng_ops;
3486         fl->fl_flags = FL_DELEG;
3487         fl->fl_type = flag == NFS4_OPEN_DELEGATE_READ? F_RDLCK: F_WRLCK;
3488         fl->fl_end = OFFSET_MAX;
3489         fl->fl_owner = (fl_owner_t)(dp->dl_file);
3490         fl->fl_pid = current->tgid;
3491         return fl;
3492 }
3493
3494 static int nfs4_setlease(struct nfs4_delegation *dp)
3495 {
3496         struct nfs4_file *fp = dp->dl_file;
3497         struct file_lock *fl;
3498         int status;
3499
3500         fl = nfs4_alloc_init_lease(dp, NFS4_OPEN_DELEGATE_READ);
3501         if (!fl)
3502                 return -ENOMEM;
3503         fl->fl_file = find_readable_file(fp);
3504         status = vfs_setlease(fl->fl_file, fl->fl_type, &fl);
3505         if (status)
3506                 goto out_free;
3507         fp->fi_lease = fl;
3508         fp->fi_deleg_file = fl->fl_file;
3509         atomic_set(&fp->fi_delegees, 1);
3510         spin_lock(&state_lock);
3511         hash_delegation_locked(dp, fp);
3512         spin_unlock(&state_lock);
3513         return 0;
3514 out_free:
3515         if (fl->fl_file)
3516                 fput(fl->fl_file);
3517         locks_free_lock(fl);
3518         return status;
3519 }
3520
3521 static int nfs4_set_delegation(struct nfs4_delegation *dp, struct nfs4_file *fp)
3522 {
3523         if (fp->fi_had_conflict)
3524                 return -EAGAIN;
3525         get_nfs4_file(fp);
3526         dp->dl_file = fp;
3527         if (!fp->fi_lease)
3528                 return nfs4_setlease(dp);
3529         spin_lock(&state_lock);
3530         atomic_inc(&fp->fi_delegees);
3531         if (fp->fi_had_conflict) {
3532                 spin_unlock(&state_lock);
3533                 return -EAGAIN;
3534         }
3535         hash_delegation_locked(dp, fp);
3536         spin_unlock(&state_lock);
3537         return 0;
3538 }
3539
3540 static void nfsd4_open_deleg_none_ext(struct nfsd4_open *open, int status)
3541 {
3542         open->op_delegate_type = NFS4_OPEN_DELEGATE_NONE_EXT;
3543         if (status == -EAGAIN)
3544                 open->op_why_no_deleg = WND4_CONTENTION;
3545         else {
3546                 open->op_why_no_deleg = WND4_RESOURCE;
3547                 switch (open->op_deleg_want) {
3548                 case NFS4_SHARE_WANT_READ_DELEG:
3549                 case NFS4_SHARE_WANT_WRITE_DELEG:
3550                 case NFS4_SHARE_WANT_ANY_DELEG:
3551                         break;
3552                 case NFS4_SHARE_WANT_CANCEL:
3553                         open->op_why_no_deleg = WND4_CANCELLED;
3554                         break;
3555                 case NFS4_SHARE_WANT_NO_DELEG:
3556                         WARN_ON_ONCE(1);
3557                 }
3558         }
3559 }
3560
3561 /*
3562  * Attempt to hand out a delegation.
3563  *
3564  * Note we don't support write delegations, and won't until the vfs has
3565  * proper support for them.
3566  */
3567 static void
3568 nfs4_open_delegation(struct net *net, struct svc_fh *fh,
3569                      struct nfsd4_open *open, struct nfs4_ol_stateid *stp)
3570 {
3571         struct nfs4_delegation *dp;
3572         struct nfs4_openowner *oo = container_of(stp->st_stateowner, struct nfs4_openowner, oo_owner);
3573         int cb_up;
3574         int status = 0;
3575
3576         cb_up = nfsd4_cb_channel_good(oo->oo_owner.so_client);
3577         open->op_recall = 0;
3578         switch (open->op_claim_type) {
3579                 case NFS4_OPEN_CLAIM_PREVIOUS:
3580                         if (!cb_up)
3581                                 open->op_recall = 1;
3582                         if (open->op_delegate_type != NFS4_OPEN_DELEGATE_READ)
3583                                 goto out_no_deleg;
3584                         break;
3585                 case NFS4_OPEN_CLAIM_NULL:
3586                 case NFS4_OPEN_CLAIM_FH:
3587                         /*
3588                          * Let's not give out any delegations till everyone's
3589                          * had the chance to reclaim theirs....
3590                          */
3591                         if (locks_in_grace(net))
3592                                 goto out_no_deleg;
3593                         if (!cb_up || !(oo->oo_flags & NFS4_OO_CONFIRMED))
3594                                 goto out_no_deleg;
3595                         /*
3596                          * Also, if the file was opened for write or
3597                          * create, there's a good chance the client's
3598                          * about to write to it, resulting in an
3599                          * immediate recall (since we don't support
3600                          * write delegations):
3601                          */
3602                         if (open->op_share_access & NFS4_SHARE_ACCESS_WRITE)
3603                                 goto out_no_deleg;
3604                         if (open->op_create == NFS4_OPEN_CREATE)
3605                                 goto out_no_deleg;
3606                         break;
3607                 default:
3608                         goto out_no_deleg;
3609         }
3610         dp = alloc_init_deleg(oo->oo_owner.so_client, stp, fh);
3611         if (dp == NULL)
3612                 goto out_no_deleg;
3613         status = nfs4_set_delegation(dp, stp->st_file);
3614         if (status)
3615                 goto out_free;
3616
3617         memcpy(&open->op_delegate_stateid, &dp->dl_stid.sc_stateid, sizeof(dp->dl_stid.sc_stateid));
3618
3619         dprintk("NFSD: delegation stateid=" STATEID_FMT "\n",
3620                 STATEID_VAL(&dp->dl_stid.sc_stateid));
3621         open->op_delegate_type = NFS4_OPEN_DELEGATE_READ;
3622         return;
3623 out_free:
3624         destroy_delegation(dp);
3625 out_no_deleg:
3626         open->op_delegate_type = NFS4_OPEN_DELEGATE_NONE;
3627         if (open->op_claim_type == NFS4_OPEN_CLAIM_PREVIOUS &&
3628             open->op_delegate_type != NFS4_OPEN_DELEGATE_NONE) {
3629                 dprintk("NFSD: WARNING: refusing delegation reclaim\n");
3630                 open->op_recall = 1;
3631         }
3632
3633         /* 4.1 client asking for a delegation? */
3634         if (open->op_deleg_want)
3635                 nfsd4_open_deleg_none_ext(open, status);
3636         return;
3637 }
3638
3639 static void nfsd4_deleg_xgrade_none_ext(struct nfsd4_open *open,
3640                                         struct nfs4_delegation *dp)
3641 {
3642         if (open->op_deleg_want == NFS4_SHARE_WANT_READ_DELEG &&
3643             dp->dl_type == NFS4_OPEN_DELEGATE_WRITE) {
3644                 open->op_delegate_type = NFS4_OPEN_DELEGATE_NONE_EXT;
3645                 open->op_why_no_deleg = WND4_NOT_SUPP_DOWNGRADE;
3646         } else if (open->op_deleg_want == NFS4_SHARE_WANT_WRITE_DELEG &&
3647                    dp->dl_type == NFS4_OPEN_DELEGATE_WRITE) {
3648                 open->op_delegate_type = NFS4_OPEN_DELEGATE_NONE_EXT;
3649                 open->op_why_no_deleg = WND4_NOT_SUPP_UPGRADE;
3650         }
3651         /* Otherwise the client must be confused wanting a delegation
3652          * it already has, therefore we don't return
3653          * NFS4_OPEN_DELEGATE_NONE_EXT and reason.
3654          */
3655 }
3656
3657 /*
3658  * called with nfs4_lock_state() held.
3659  */
3660 __be32
3661 nfsd4_process_open2(struct svc_rqst *rqstp, struct svc_fh *current_fh, struct nfsd4_open *open)
3662 {
3663         struct nfsd4_compoundres *resp = rqstp->rq_resp;
3664         struct nfs4_client *cl = open->op_openowner->oo_owner.so_client;
3665         struct nfs4_file *fp = NULL;
3666         struct inode *ino = current_fh->fh_dentry->d_inode;
3667         struct nfs4_ol_stateid *stp = NULL;
3668         struct nfs4_delegation *dp = NULL;
3669         __be32 status;
3670
3671         /*
3672          * Lookup file; if found, lookup stateid and check open request,
3673          * and check for delegations in the process of being recalled.
3674          * If not found, create the nfs4_file struct
3675          */
3676         fp = find_or_add_file(ino, open->op_file);
3677         if (fp != open->op_file) {
3678                 status = nfs4_check_deleg(cl, open, &dp);
3679                 if (status)
3680                         goto out;
3681                 stp = nfsd4_find_existing_open(fp, open);
3682         } else {
3683                 open->op_file = NULL;
3684                 status = nfserr_bad_stateid;
3685                 if (nfsd4_is_deleg_cur(open))
3686                         goto out;
3687                 status = nfserr_jukebox;
3688         }
3689
3690         /*
3691          * OPEN the file, or upgrade an existing OPEN.
3692          * If truncate fails, the OPEN fails.
3693          */
3694         if (stp) {
3695                 /* Stateid was found, this is an OPEN upgrade */
3696                 status = nfs4_upgrade_open(rqstp, fp, current_fh, stp, open);
3697                 if (status)
3698                         goto out;
3699         } else {
3700                 stp = open->op_stp;
3701                 open->op_stp = NULL;
3702                 init_open_stateid(stp, fp, open);
3703                 status = nfs4_get_vfs_file(rqstp, fp, current_fh, stp, open);
3704                 if (status) {
3705                         release_open_stateid(stp);
3706                         goto out;
3707                 }
3708         }
3709         update_stateid(&stp->st_stid.sc_stateid);
3710         memcpy(&open->op_stateid, &stp->st_stid.sc_stateid, sizeof(stateid_t));
3711
3712         if (nfsd4_has_session(&resp->cstate)) {
3713                 if (open->op_deleg_want & NFS4_SHARE_WANT_NO_DELEG) {
3714                         open->op_delegate_type = NFS4_OPEN_DELEGATE_NONE_EXT;
3715                         open->op_why_no_deleg = WND4_NOT_WANTED;
3716                         goto nodeleg;
3717                 }
3718         }
3719
3720         /*
3721         * Attempt to hand out a delegation. No error return, because the
3722         * OPEN succeeds even if we fail.
3723         */
3724         nfs4_open_delegation(SVC_NET(rqstp), current_fh, open, stp);
3725 nodeleg:
3726         status = nfs_ok;
3727
3728         dprintk("%s: stateid=" STATEID_FMT "\n", __func__,
3729                 STATEID_VAL(&stp->st_stid.sc_stateid));
3730 out:
3731         /* 4.1 client trying to upgrade/downgrade delegation? */
3732         if (open->op_delegate_type == NFS4_OPEN_DELEGATE_NONE && dp &&
3733             open->op_deleg_want)
3734                 nfsd4_deleg_xgrade_none_ext(open, dp);
3735
3736         if (fp)
3737                 put_nfs4_file(fp);
3738         if (status == 0 && open->op_claim_type == NFS4_OPEN_CLAIM_PREVIOUS)
3739                 nfs4_set_claim_prev(open, nfsd4_has_session(&resp->cstate));
3740         /*
3741         * To finish the open response, we just need to set the rflags.
3742         */
3743         open->op_rflags = NFS4_OPEN_RESULT_LOCKTYPE_POSIX;
3744         if (!(open->op_openowner->oo_flags & NFS4_OO_CONFIRMED) &&
3745             !nfsd4_has_session(&resp->cstate))
3746                 open->op_rflags |= NFS4_OPEN_RESULT_CONFIRM;
3747
3748         return status;
3749 }
3750
3751 void nfsd4_cleanup_open_state(struct nfsd4_open *open, __be32 status)
3752 {
3753         if (open->op_openowner) {
3754                 struct nfs4_openowner *oo = open->op_openowner;
3755
3756                 if (!list_empty(&oo->oo_owner.so_stateids))
3757                         list_del_init(&oo->oo_close_lru);
3758                 if (oo->oo_flags & NFS4_OO_NEW) {
3759                         if (status) {
3760                                 release_openowner(oo);
3761                                 open->op_openowner = NULL;
3762                         } else
3763                                 oo->oo_flags &= ~NFS4_OO_NEW;
3764                 }
3765         }
3766         if (open->op_file)
3767                 nfsd4_free_file(open->op_file);
3768         if (open->op_stp)
3769                 free_generic_stateid(open->op_stp);
3770 }
3771
3772 __be32
3773 nfsd4_renew(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
3774             clientid_t *clid)
3775 {
3776         struct nfs4_client *clp;
3777         __be32 status;
3778         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
3779
3780         nfs4_lock_state();
3781         dprintk("process_renew(%08x/%08x): starting\n", 
3782                         clid->cl_boot, clid->cl_id);
3783         status = lookup_clientid(clid, cstate, nn);
3784         if (status)
3785                 goto out;
3786         clp = cstate->clp;
3787         status = nfserr_cb_path_down;
3788         if (!list_empty(&clp->cl_delegations)
3789                         && clp->cl_cb_state != NFSD4_CB_UP)
3790                 goto out;
3791         status = nfs_ok;
3792 out:
3793         nfs4_unlock_state();
3794         return status;
3795 }
3796
3797 static void
3798 nfsd4_end_grace(struct nfsd_net *nn)
3799 {
3800         /* do nothing if grace period already ended */
3801         if (nn->grace_ended)
3802                 return;
3803
3804         dprintk("NFSD: end of grace period\n");
3805         nn->grace_ended = true;
3806         nfsd4_record_grace_done(nn, nn->boot_time);
3807         locks_end_grace(&nn->nfsd4_manager);
3808         /*
3809          * Now that every NFSv4 client has had the chance to recover and
3810          * to see the (possibly new, possibly shorter) lease time, we
3811          * can safely set the next grace time to the current lease time:
3812          */
3813         nn->nfsd4_grace = nn->nfsd4_lease;
3814 }
3815
3816 static time_t
3817 nfs4_laundromat(struct nfsd_net *nn)
3818 {
3819         struct nfs4_client *clp;
3820         struct nfs4_openowner *oo;
3821         struct nfs4_delegation *dp;
3822         struct list_head *pos, *next, reaplist;
3823         time_t cutoff = get_seconds() - nn->nfsd4_lease;
3824         time_t t, new_timeo = nn->nfsd4_lease;
3825
3826         nfs4_lock_state();
3827
3828         dprintk("NFSD: laundromat service - starting\n");
3829         nfsd4_end_grace(nn);
3830         INIT_LIST_HEAD(&reaplist);
3831         spin_lock(&nn->client_lock);
3832         list_for_each_safe(pos, next, &nn->client_lru) {
3833                 clp = list_entry(pos, struct nfs4_client, cl_lru);
3834                 if (time_after((unsigned long)clp->cl_time, (unsigned long)cutoff)) {
3835                         t = clp->cl_time - cutoff;
3836                         new_timeo = min(new_timeo, t);
3837                         break;
3838                 }
3839                 if (mark_client_expired_locked(clp)) {
3840                         dprintk("NFSD: client in use (clientid %08x)\n",
3841                                 clp->cl_clientid.cl_id);
3842                         continue;
3843                 }
3844                 list_move(&clp->cl_lru, &reaplist);
3845         }
3846         spin_unlock(&nn->client_lock);
3847         list_for_each_safe(pos, next, &reaplist) {
3848                 clp = list_entry(pos, struct nfs4_client, cl_lru);
3849                 dprintk("NFSD: purging unused client (clientid %08x)\n",
3850                         clp->cl_clientid.cl_id);
3851                 expire_client(clp);
3852         }
3853         spin_lock(&state_lock);
3854         list_for_each_safe(pos, next, &nn->del_recall_lru) {
3855                 dp = list_entry (pos, struct nfs4_delegation, dl_recall_lru);
3856                 if (net_generic(dp->dl_stid.sc_client->net, nfsd_net_id) != nn)
3857                         continue;
3858                 if (time_after((unsigned long)dp->dl_time, (unsigned long)cutoff)) {
3859                         t = dp->dl_time - cutoff;
3860                         new_timeo = min(new_timeo, t);
3861                         break;
3862                 }
3863                 list_move(&dp->dl_recall_lru, &reaplist);
3864         }
3865         spin_unlock(&state_lock);
3866         list_for_each_safe(pos, next, &reaplist) {
3867                 dp = list_entry (pos, struct nfs4_delegation, dl_recall_lru);
3868                 revoke_delegation(dp);
3869         }
3870         list_for_each_safe(pos, next, &nn->close_lru) {
3871                 oo = container_of(pos, struct nfs4_openowner, oo_close_lru);
3872                 if (time_after((unsigned long)oo->oo_time, (unsigned long)cutoff)) {
3873                         t = oo->oo_time - cutoff;
3874                         new_timeo = min(new_timeo, t);
3875                         break;
3876                 }
3877                 release_openowner(oo);
3878         }
3879         new_timeo = max_t(time_t, new_timeo, NFSD_LAUNDROMAT_MINTIMEOUT);
3880         nfs4_unlock_state();
3881         return new_timeo;
3882 }
3883
3884 static struct workqueue_struct *laundry_wq;
3885 static void laundromat_main(struct work_struct *);
3886
3887 static void
3888 laundromat_main(struct work_struct *laundry)
3889 {
3890         time_t t;
3891         struct delayed_work *dwork = container_of(laundry, struct delayed_work,
3892                                                   work);
3893         struct nfsd_net *nn = container_of(dwork, struct nfsd_net,
3894                                            laundromat_work);
3895
3896         t = nfs4_laundromat(nn);
3897         dprintk("NFSD: laundromat_main - sleeping for %ld seconds\n", t);
3898         queue_delayed_work(laundry_wq, &nn->laundromat_work, t*HZ);
3899 }
3900
3901 static inline __be32 nfs4_check_fh(struct svc_fh *fhp, struct nfs4_ol_stateid *stp)
3902 {
3903         if (fhp->fh_dentry->d_inode != stp->st_file->fi_inode)
3904                 return nfserr_bad_stateid;
3905         return nfs_ok;
3906 }
3907
3908 static inline int
3909 access_permit_read(struct nfs4_ol_stateid *stp)
3910 {
3911         return test_access(NFS4_SHARE_ACCESS_READ, stp) ||
3912                 test_access(NFS4_SHARE_ACCESS_BOTH, stp) ||
3913                 test_access(NFS4_SHARE_ACCESS_WRITE, stp);
3914 }
3915
3916 static inline int
3917 access_permit_write(struct nfs4_ol_stateid *stp)
3918 {
3919         return test_access(NFS4_SHARE_ACCESS_WRITE, stp) ||
3920                 test_access(NFS4_SHARE_ACCESS_BOTH, stp);
3921 }
3922
3923 static
3924 __be32 nfs4_check_openmode(struct nfs4_ol_stateid *stp, int flags)
3925 {
3926         __be32 status = nfserr_openmode;
3927
3928         /* For lock stateid's, we test the parent open, not the lock: */
3929         if (stp->st_openstp)
3930                 stp = stp->st_openstp;
3931         if ((flags & WR_STATE) && !access_permit_write(stp))
3932                 goto out;
3933         if ((flags & RD_STATE) && !access_permit_read(stp))
3934                 goto out;
3935         status = nfs_ok;
3936 out:
3937         return status;
3938 }
3939
3940 static inline __be32
3941 check_special_stateids(struct net *net, svc_fh *current_fh, stateid_t *stateid, int flags)
3942 {
3943         if (ONE_STATEID(stateid) && (flags & RD_STATE))
3944                 return nfs_ok;
3945         else if (locks_in_grace(net)) {
3946                 /* Answer in remaining cases depends on existence of
3947                  * conflicting state; so we must wait out the grace period. */
3948                 return nfserr_grace;
3949         } else if (flags & WR_STATE)
3950                 return nfs4_share_conflict(current_fh,
3951                                 NFS4_SHARE_DENY_WRITE);
3952         else /* (flags & RD_STATE) && ZERO_STATEID(stateid) */
3953                 return nfs4_share_conflict(current_fh,
3954                                 NFS4_SHARE_DENY_READ);
3955 }
3956
3957 /*
3958  * Allow READ/WRITE during grace period on recovered state only for files
3959  * that are not able to provide mandatory locking.
3960  */
3961 static inline int
3962 grace_disallows_io(struct net *net, struct inode *inode)
3963 {
3964         return locks_in_grace(net) && mandatory_lock(inode);
3965 }
3966
3967 /* Returns true iff a is later than b: */
3968 static bool stateid_generation_after(stateid_t *a, stateid_t *b)
3969 {
3970         return (s32)(a->si_generation - b->si_generation) > 0;
3971 }
3972
3973 static __be32 check_stateid_generation(stateid_t *in, stateid_t *ref, bool has_session)
3974 {
3975         /*
3976          * When sessions are used the stateid generation number is ignored
3977          * when it is zero.
3978          */
3979         if (has_session && in->si_generation == 0)
3980                 return nfs_ok;
3981
3982         if (in->si_generation == ref->si_generation)
3983                 return nfs_ok;
3984
3985         /* If the client sends us a stateid from the future, it's buggy: */
3986         if (stateid_generation_after(in, ref))
3987                 return nfserr_bad_stateid;
3988         /*
3989          * However, we could see a stateid from the past, even from a
3990          * non-buggy client.  For example, if the client sends a lock
3991          * while some IO is outstanding, the lock may bump si_generation
3992          * while the IO is still in flight.  The client could avoid that
3993          * situation by waiting for responses on all the IO requests,
3994          * but better performance may result in retrying IO that
3995          * receives an old_stateid error if requests are rarely
3996          * reordered in flight:
3997          */
3998         return nfserr_old_stateid;
3999 }
4000
4001 static __be32 nfsd4_validate_stateid(struct nfs4_client *cl, stateid_t *stateid)
4002 {
4003         struct nfs4_stid *s;
4004         struct nfs4_ol_stateid *ols;
4005         __be32 status;
4006
4007         if (ZERO_STATEID(stateid) || ONE_STATEID(stateid))
4008                 return nfserr_bad_stateid;
4009         /* Client debugging aid. */
4010         if (!same_clid(&stateid->si_opaque.so_clid, &cl->cl_clientid)) {
4011                 char addr_str[INET6_ADDRSTRLEN];
4012                 rpc_ntop((struct sockaddr *)&cl->cl_addr, addr_str,
4013                                  sizeof(addr_str));
4014                 pr_warn_ratelimited("NFSD: client %s testing state ID "
4015                                         "with incorrect client ID\n", addr_str);
4016                 return nfserr_bad_stateid;
4017         }
4018         s = find_stateid(cl, stateid);
4019         if (!s)
4020                 return nfserr_bad_stateid;
4021         status = check_stateid_generation(stateid, &s->sc_stateid, 1);
4022         if (status)
4023                 return status;
4024         switch (s->sc_type) {
4025         case NFS4_DELEG_STID:
4026                 return nfs_ok;
4027         case NFS4_REVOKED_DELEG_STID:
4028                 return nfserr_deleg_revoked;
4029         case NFS4_OPEN_STID:
4030         case NFS4_LOCK_STID:
4031                 ols = openlockstateid(s);
4032                 if (ols->st_stateowner->so_is_open_owner
4033                                 && !(openowner(ols->st_stateowner)->oo_flags
4034                                                 & NFS4_OO_CONFIRMED))
4035                         return nfserr_bad_stateid;
4036                 return nfs_ok;
4037         default:
4038                 printk("unknown stateid type %x\n", s->sc_type);
4039         case NFS4_CLOSED_STID:
4040                 return nfserr_bad_stateid;
4041         }
4042 }
4043
4044 static __be32
4045 nfsd4_lookup_stateid(struct nfsd4_compound_state *cstate,
4046                      stateid_t *stateid, unsigned char typemask,
4047                      struct nfs4_stid **s, struct nfsd_net *nn)
4048 {
4049         __be32 status;
4050
4051         if (ZERO_STATEID(stateid) || ONE_STATEID(stateid))
4052                 return nfserr_bad_stateid;
4053         status = lookup_clientid(&stateid->si_opaque.so_clid, cstate, nn);
4054         if (status == nfserr_stale_clientid) {
4055                 if (cstate->session)
4056                         return nfserr_bad_stateid;
4057                 return nfserr_stale_stateid;
4058         }
4059         if (status)
4060                 return status;
4061         *s = find_stateid_by_type(cstate->clp, stateid, typemask);
4062         if (!*s)
4063                 return nfserr_bad_stateid;
4064         return nfs_ok;
4065 }
4066
4067 /*
4068 * Checks for stateid operations
4069 */
4070 __be32
4071 nfs4_preprocess_stateid_op(struct net *net, struct nfsd4_compound_state *cstate,
4072                            stateid_t *stateid, int flags, struct file **filpp)
4073 {
4074         struct nfs4_stid *s;
4075         struct nfs4_ol_stateid *stp = NULL;
4076         struct nfs4_delegation *dp = NULL;
4077         struct svc_fh *current_fh = &cstate->current_fh;
4078         struct inode *ino = current_fh->fh_dentry->d_inode;
4079         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
4080         struct file *file = NULL;
4081         __be32 status;
4082
4083         if (filpp)
4084                 *filpp = NULL;
4085
4086         if (grace_disallows_io(net, ino))
4087                 return nfserr_grace;
4088
4089         if (ZERO_STATEID(stateid) || ONE_STATEID(stateid))
4090                 return check_special_stateids(net, current_fh, stateid, flags);
4091
4092         nfs4_lock_state();
4093
4094         status = nfsd4_lookup_stateid(cstate, stateid,
4095                                 NFS4_DELEG_STID|NFS4_OPEN_STID|NFS4_LOCK_STID,
4096                                 &s, nn);
4097         if (status)
4098                 goto out;
4099         status = check_stateid_generation(stateid, &s->sc_stateid, nfsd4_has_session(cstate));
4100         if (status)
4101                 goto out;
4102         switch (s->sc_type) {
4103         case NFS4_DELEG_STID:
4104                 dp = delegstateid(s);
4105                 status = nfs4_check_delegmode(dp, flags);
4106                 if (status)
4107                         goto out;
4108                 if (filpp) {
4109                         file = dp->dl_file->fi_deleg_file;
4110                         if (!file) {
4111                                 WARN_ON_ONCE(1);
4112                                 status = nfserr_serverfault;
4113                                 goto out;
4114                         }
4115                         get_file(file);
4116                 }
4117                 break;
4118         case NFS4_OPEN_STID:
4119         case NFS4_LOCK_STID:
4120                 stp = openlockstateid(s);
4121                 status = nfs4_check_fh(current_fh, stp);
4122                 if (status)
4123                         goto out;
4124                 if (stp->st_stateowner->so_is_open_owner
4125                     && !(openowner(stp->st_stateowner)->oo_flags & NFS4_OO_CONFIRMED))
4126                         goto out;
4127                 status = nfs4_check_openmode(stp, flags);
4128                 if (status)
4129                         goto out;
4130                 if (filpp) {
4131                         if (flags & RD_STATE)
4132                                 file = find_readable_file(stp->st_file);
4133                         else
4134                                 file = find_writeable_file(stp->st_file);
4135                 }
4136                 break;
4137         default:
4138                 status = nfserr_bad_stateid;
4139                 goto out;
4140         }
4141         status = nfs_ok;
4142         if (file)
4143                 *filpp = file;
4144 out:
4145         nfs4_unlock_state();
4146         return status;
4147 }
4148
4149 static __be32
4150 nfsd4_free_lock_stateid(struct nfs4_ol_stateid *stp)
4151 {
4152         struct nfs4_lockowner *lo = lockowner(stp->st_stateowner);
4153
4154         if (check_for_locks(stp->st_file, lo))
4155                 return nfserr_locks_held;
4156         release_lockowner_if_empty(lo);
4157         return nfs_ok;
4158 }
4159
4160 /*
4161  * Test if the stateid is valid
4162  */
4163 __be32
4164 nfsd4_test_stateid(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4165                    struct nfsd4_test_stateid *test_stateid)
4166 {
4167         struct nfsd4_test_stateid_id *stateid;
4168         struct nfs4_client *cl = cstate->session->se_client;
4169
4170         nfs4_lock_state();
4171         list_for_each_entry(stateid, &test_stateid->ts_stateid_list, ts_id_list)
4172                 stateid->ts_id_status =
4173                         nfsd4_validate_stateid(cl, &stateid->ts_id_stateid);
4174         nfs4_unlock_state();
4175
4176         return nfs_ok;
4177 }
4178
4179 __be32
4180 nfsd4_free_stateid(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4181                    struct nfsd4_free_stateid *free_stateid)
4182 {
4183         stateid_t *stateid = &free_stateid->fr_stateid;
4184         struct nfs4_stid *s;
4185         struct nfs4_delegation *dp;
4186         struct nfs4_client *cl = cstate->session->se_client;
4187         __be32 ret = nfserr_bad_stateid;
4188
4189         nfs4_lock_state();
4190         s = find_stateid(cl, stateid);
4191         if (!s)
4192                 goto out;
4193         switch (s->sc_type) {
4194         case NFS4_DELEG_STID:
4195                 ret = nfserr_locks_held;
4196                 goto out;
4197         case NFS4_OPEN_STID:
4198         case NFS4_LOCK_STID:
4199                 ret = check_stateid_generation(stateid, &s->sc_stateid, 1);
4200                 if (ret)
4201                         goto out;
4202                 if (s->sc_type == NFS4_LOCK_STID)
4203                         ret = nfsd4_free_lock_stateid(openlockstateid(s));
4204                 else
4205                         ret = nfserr_locks_held;
4206                 break;
4207         case NFS4_REVOKED_DELEG_STID:
4208                 dp = delegstateid(s);
4209                 destroy_revoked_delegation(dp);
4210                 ret = nfs_ok;
4211                 break;
4212         default:
4213                 ret = nfserr_bad_stateid;
4214         }
4215 out:
4216         nfs4_unlock_state();
4217         return ret;
4218 }
4219
4220 static inline int
4221 setlkflg (int type)
4222 {
4223         return (type == NFS4_READW_LT || type == NFS4_READ_LT) ?
4224                 RD_STATE : WR_STATE;
4225 }
4226
4227 static __be32 nfs4_seqid_op_checks(struct nfsd4_compound_state *cstate, stateid_t *stateid, u32 seqid, struct nfs4_ol_stateid *stp)
4228 {
4229         struct svc_fh *current_fh = &cstate->current_fh;
4230         struct nfs4_stateowner *sop = stp->st_stateowner;
4231         __be32 status;
4232
4233         status = nfsd4_check_seqid(cstate, sop, seqid);
4234         if (status)
4235                 return status;
4236         if (stp->st_stid.sc_type == NFS4_CLOSED_STID
4237                 || stp->st_stid.sc_type == NFS4_REVOKED_DELEG_STID)
4238                 /*
4239                  * "Closed" stateid's exist *only* to return
4240                  * nfserr_replay_me from the previous step, and
4241                  * revoked delegations are kept only for free_stateid.
4242                  */
4243                 return nfserr_bad_stateid;
4244         status = check_stateid_generation(stateid, &stp->st_stid.sc_stateid, nfsd4_has_session(cstate));
4245         if (status)
4246                 return status;
4247         return nfs4_check_fh(current_fh, stp);
4248 }
4249
4250 /* 
4251  * Checks for sequence id mutating operations. 
4252  */
4253 static __be32
4254 nfs4_preprocess_seqid_op(struct nfsd4_compound_state *cstate, u32 seqid,
4255                          stateid_t *stateid, char typemask,
4256                          struct nfs4_ol_stateid **stpp,
4257                          struct nfsd_net *nn)
4258 {
4259         __be32 status;
4260         struct nfs4_stid *s;
4261         struct nfs4_ol_stateid *stp = NULL;
4262
4263         dprintk("NFSD: %s: seqid=%d stateid = " STATEID_FMT "\n", __func__,
4264                 seqid, STATEID_VAL(stateid));
4265
4266         *stpp = NULL;
4267         status = nfsd4_lookup_stateid(cstate, stateid, typemask, &s, nn);
4268         if (status)
4269                 return status;
4270         stp = openlockstateid(s);
4271         if (!nfsd4_has_session(cstate))
4272                 cstate->replay_owner = stp->st_stateowner;
4273
4274         status = nfs4_seqid_op_checks(cstate, stateid, seqid, stp);
4275         if (!status)
4276                 *stpp = stp;
4277         return status;
4278 }
4279
4280 static __be32 nfs4_preprocess_confirmed_seqid_op(struct nfsd4_compound_state *cstate, u32 seqid,
4281                                                  stateid_t *stateid, struct nfs4_ol_stateid **stpp, struct nfsd_net *nn)
4282 {
4283         __be32 status;
4284         struct nfs4_openowner *oo;
4285
4286         status = nfs4_preprocess_seqid_op(cstate, seqid, stateid,
4287                                                 NFS4_OPEN_STID, stpp, nn);
4288         if (status)
4289                 return status;
4290         oo = openowner((*stpp)->st_stateowner);
4291         if (!(oo->oo_flags & NFS4_OO_CONFIRMED))
4292                 return nfserr_bad_stateid;
4293         return nfs_ok;
4294 }
4295
4296 __be32
4297 nfsd4_open_confirm(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4298                    struct nfsd4_open_confirm *oc)
4299 {
4300         __be32 status;
4301         struct nfs4_openowner *oo;
4302         struct nfs4_ol_stateid *stp;
4303         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
4304
4305         dprintk("NFSD: nfsd4_open_confirm on file %pd\n",
4306                         cstate->current_fh.fh_dentry);
4307
4308         status = fh_verify(rqstp, &cstate->current_fh, S_IFREG, 0);
4309         if (status)
4310                 return status;
4311
4312         nfs4_lock_state();
4313
4314         status = nfs4_preprocess_seqid_op(cstate,
4315                                         oc->oc_seqid, &oc->oc_req_stateid,
4316                                         NFS4_OPEN_STID, &stp, nn);
4317         if (status)
4318                 goto out;
4319         oo = openowner(stp->st_stateowner);
4320         status = nfserr_bad_stateid;
4321         if (oo->oo_flags & NFS4_OO_CONFIRMED)
4322                 goto out;
4323         oo->oo_flags |= NFS4_OO_CONFIRMED;
4324         update_stateid(&stp->st_stid.sc_stateid);
4325         memcpy(&oc->oc_resp_stateid, &stp->st_stid.sc_stateid, sizeof(stateid_t));
4326         dprintk("NFSD: %s: success, seqid=%d stateid=" STATEID_FMT "\n",
4327                 __func__, oc->oc_seqid, STATEID_VAL(&stp->st_stid.sc_stateid));
4328
4329         nfsd4_client_record_create(oo->oo_owner.so_client);
4330         status = nfs_ok;
4331 out:
4332         nfsd4_bump_seqid(cstate, status);
4333         if (!cstate->replay_owner)
4334                 nfs4_unlock_state();
4335         return status;
4336 }
4337
4338 static inline void nfs4_stateid_downgrade_bit(struct nfs4_ol_stateid *stp, u32 access)
4339 {
4340         if (!test_access(access, stp))
4341                 return;
4342         nfs4_file_put_access(stp->st_file, access);
4343         clear_access(access, stp);
4344 }
4345
4346 static inline void nfs4_stateid_downgrade(struct nfs4_ol_stateid *stp, u32 to_access)
4347 {
4348         switch (to_access) {
4349         case NFS4_SHARE_ACCESS_READ:
4350                 nfs4_stateid_downgrade_bit(stp, NFS4_SHARE_ACCESS_WRITE);
4351                 nfs4_stateid_downgrade_bit(stp, NFS4_SHARE_ACCESS_BOTH);
4352                 break;
4353         case NFS4_SHARE_ACCESS_WRITE:
4354                 nfs4_stateid_downgrade_bit(stp, NFS4_SHARE_ACCESS_READ);
4355                 nfs4_stateid_downgrade_bit(stp, NFS4_SHARE_ACCESS_BOTH);
4356                 break;
4357         case NFS4_SHARE_ACCESS_BOTH:
4358                 break;
4359         default:
4360                 WARN_ON_ONCE(1);
4361         }
4362 }
4363
4364 __be32
4365 nfsd4_open_downgrade(struct svc_rqst *rqstp,
4366                      struct nfsd4_compound_state *cstate,
4367                      struct nfsd4_open_downgrade *od)
4368 {
4369         __be32 status;
4370         struct nfs4_ol_stateid *stp;
4371         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
4372
4373         dprintk("NFSD: nfsd4_open_downgrade on file %pd\n", 
4374                         cstate->current_fh.fh_dentry);
4375
4376         /* We don't yet support WANT bits: */
4377         if (od->od_deleg_want)
4378                 dprintk("NFSD: %s: od_deleg_want=0x%x ignored\n", __func__,
4379                         od->od_deleg_want);
4380
4381         nfs4_lock_state();
4382         status = nfs4_preprocess_confirmed_seqid_op(cstate, od->od_seqid,
4383                                         &od->od_stateid, &stp, nn);
4384         if (status)
4385                 goto out; 
4386         status = nfserr_inval;
4387         if (!test_access(od->od_share_access, stp)) {
4388                 dprintk("NFSD: access not a subset of current bitmap: 0x%hhx, input access=%08x\n",
4389                         stp->st_access_bmap, od->od_share_access);
4390                 goto out;
4391         }
4392         if (!test_deny(od->od_share_deny, stp)) {
4393                 dprintk("NFSD: deny not a subset of current bitmap: 0x%hhx, input deny=%08x\n",
4394                         stp->st_deny_bmap, od->od_share_deny);
4395                 goto out;
4396         }
4397         nfs4_stateid_downgrade(stp, od->od_share_access);
4398
4399         reset_union_bmap_deny(od->od_share_deny, stp);
4400
4401         update_stateid(&stp->st_stid.sc_stateid);
4402         memcpy(&od->od_stateid, &stp->st_stid.sc_stateid, sizeof(stateid_t));
4403         status = nfs_ok;
4404 out:
4405         nfsd4_bump_seqid(cstate, status);
4406         if (!cstate->replay_owner)
4407                 nfs4_unlock_state();
4408         return status;
4409 }
4410
4411 static void nfsd4_close_open_stateid(struct nfs4_ol_stateid *s)
4412 {
4413         struct nfs4_client *clp = s->st_stid.sc_client;
4414         struct nfs4_openowner *oo = openowner(s->st_stateowner);
4415
4416         s->st_stid.sc_type = NFS4_CLOSED_STID;
4417         unhash_open_stateid(s);
4418
4419         if (clp->cl_minorversion) {
4420                 free_generic_stateid(s);
4421                 if (list_empty(&oo->oo_owner.so_stateids))
4422                         release_openowner(oo);
4423         } else {
4424                 oo->oo_last_closed_stid = s;
4425                 /*
4426                  * In the 4.0 case we need to keep the owners around a
4427                  * little while to handle CLOSE replay.
4428                  */
4429                 if (list_empty(&oo->oo_owner.so_stateids))
4430                         move_to_close_lru(oo, clp->net);
4431         }
4432 }
4433
4434 /*
4435  * nfs4_unlock_state() called after encode
4436  */
4437 __be32
4438 nfsd4_close(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4439             struct nfsd4_close *close)
4440 {
4441         __be32 status;
4442         struct nfs4_ol_stateid *stp;
4443         struct net *net = SVC_NET(rqstp);
4444         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
4445
4446         dprintk("NFSD: nfsd4_close on file %pd\n", 
4447                         cstate->current_fh.fh_dentry);
4448
4449         nfs4_lock_state();
4450         status = nfs4_preprocess_seqid_op(cstate, close->cl_seqid,
4451                                         &close->cl_stateid,
4452                                         NFS4_OPEN_STID|NFS4_CLOSED_STID,
4453                                         &stp, nn);
4454         nfsd4_bump_seqid(cstate, status);
4455         if (status)
4456                 goto out; 
4457         update_stateid(&stp->st_stid.sc_stateid);
4458         memcpy(&close->cl_stateid, &stp->st_stid.sc_stateid, sizeof(stateid_t));
4459
4460         nfsd4_close_open_stateid(stp);
4461 out:
4462         if (!cstate->replay_owner)
4463                 nfs4_unlock_state();
4464         return status;
4465 }
4466
4467 __be32
4468 nfsd4_delegreturn(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4469                   struct nfsd4_delegreturn *dr)
4470 {
4471         struct nfs4_delegation *dp;
4472         stateid_t *stateid = &dr->dr_stateid;
4473         struct nfs4_stid *s;
4474         __be32 status;
4475         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
4476
4477         if ((status = fh_verify(rqstp, &cstate->current_fh, S_IFREG, 0)))
4478                 return status;
4479
4480         nfs4_lock_state();
4481         status = nfsd4_lookup_stateid(cstate, stateid, NFS4_DELEG_STID, &s, nn);
4482         if (status)
4483                 goto out;
4484         dp = delegstateid(s);
4485         status = check_stateid_generation(stateid, &dp->dl_stid.sc_stateid, nfsd4_has_session(cstate));
4486         if (status)
4487                 goto out;
4488
4489         destroy_delegation(dp);
4490 out:
4491         nfs4_unlock_state();
4492
4493         return status;
4494 }
4495
4496
4497 #define LOFF_OVERFLOW(start, len)      ((u64)(len) > ~(u64)(start))
4498
4499 static inline u64
4500 end_offset(u64 start, u64 len)
4501 {
4502         u64 end;
4503
4504         end = start + len;
4505         return end >= start ? end: NFS4_MAX_UINT64;
4506 }
4507
4508 /* last octet in a range */
4509 static inline u64
4510 last_byte_offset(u64 start, u64 len)
4511 {
4512         u64 end;
4513
4514         WARN_ON_ONCE(!len);
4515         end = start + len;
4516         return end > start ? end - 1: NFS4_MAX_UINT64;
4517 }
4518
4519 /*
4520  * TODO: Linux file offsets are _signed_ 64-bit quantities, which means that
4521  * we can't properly handle lock requests that go beyond the (2^63 - 1)-th
4522  * byte, because of sign extension problems.  Since NFSv4 calls for 64-bit
4523  * locking, this prevents us from being completely protocol-compliant.  The
4524  * real solution to this problem is to start using unsigned file offsets in
4525  * the VFS, but this is a very deep change!
4526  */
4527 static inline void
4528 nfs4_transform_lock_offset(struct file_lock *lock)
4529 {
4530         if (lock->fl_start < 0)
4531                 lock->fl_start = OFFSET_MAX;
4532         if (lock->fl_end < 0)
4533                 lock->fl_end = OFFSET_MAX;
4534 }
4535
4536 /* Hack!: For now, we're defining this just so we can use a pointer to it
4537  * as a unique cookie to identify our (NFSv4's) posix locks. */
4538 static const struct lock_manager_operations nfsd_posix_mng_ops  = {
4539 };
4540
4541 static inline void
4542 nfs4_set_lock_denied(struct file_lock *fl, struct nfsd4_lock_denied *deny)
4543 {
4544         struct nfs4_lockowner *lo;
4545
4546         if (fl->fl_lmops == &nfsd_posix_mng_ops) {
4547                 lo = (struct nfs4_lockowner *) fl->fl_owner;
4548                 deny->ld_owner.data = kmemdup(lo->lo_owner.so_owner.data,
4549                                         lo->lo_owner.so_owner.len, GFP_KERNEL);
4550                 if (!deny->ld_owner.data)
4551                         /* We just don't care that much */
4552                         goto nevermind;
4553                 deny->ld_owner.len = lo->lo_owner.so_owner.len;
4554                 deny->ld_clientid = lo->lo_owner.so_client->cl_clientid;
4555         } else {
4556 nevermind:
4557                 deny->ld_owner.len = 0;
4558                 deny->ld_owner.data = NULL;
4559                 deny->ld_clientid.cl_boot = 0;
4560                 deny->ld_clientid.cl_id = 0;
4561         }
4562         deny->ld_start = fl->fl_start;
4563         deny->ld_length = NFS4_MAX_UINT64;
4564         if (fl->fl_end != NFS4_MAX_UINT64)
4565                 deny->ld_length = fl->fl_end - fl->fl_start + 1;        
4566         deny->ld_type = NFS4_READ_LT;
4567         if (fl->fl_type != F_RDLCK)
4568                 deny->ld_type = NFS4_WRITE_LT;
4569 }
4570
4571 static struct nfs4_lockowner *
4572 find_lockowner_str(clientid_t *clid, struct xdr_netobj *owner,
4573                 struct nfsd_net *nn)
4574 {
4575         unsigned int strhashval = ownerstr_hashval(clid->cl_id, owner);
4576         struct nfs4_stateowner *so;
4577
4578         list_for_each_entry(so, &nn->ownerstr_hashtbl[strhashval], so_strhash) {
4579                 if (so->so_is_open_owner)
4580                         continue;
4581                 if (!same_owner_str(so, owner, clid))
4582                         continue;
4583                 return lockowner(so);
4584         }
4585         return NULL;
4586 }
4587
4588 /*
4589  * Alloc a lock owner structure.
4590  * Called in nfsd4_lock - therefore, OPEN and OPEN_CONFIRM (if needed) has 
4591  * occurred. 
4592  *
4593  * strhashval = ownerstr_hashval
4594  */
4595 static struct nfs4_lockowner *
4596 alloc_init_lock_stateowner(unsigned int strhashval, struct nfs4_client *clp, struct nfs4_ol_stateid *open_stp, struct nfsd4_lock *lock) {
4597         struct nfs4_lockowner *lo;
4598         struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
4599
4600         lo = alloc_stateowner(lockowner_slab, &lock->lk_new_owner, clp);
4601         if (!lo)
4602                 return NULL;
4603         INIT_LIST_HEAD(&lo->lo_owner.so_stateids);
4604         lo->lo_owner.so_is_open_owner = 0;
4605         /* It is the openowner seqid that will be incremented in encode in the
4606          * case of new lockowners; so increment the lock seqid manually: */
4607         lo->lo_owner.so_seqid = lock->lk_new_lock_seqid + 1;
4608         list_add(&lo->lo_owner.so_strhash, &nn->ownerstr_hashtbl[strhashval]);
4609         return lo;
4610 }
4611
4612 static struct nfs4_ol_stateid *
4613 alloc_init_lock_stateid(struct nfs4_lockowner *lo, struct nfs4_file *fp, struct nfs4_ol_stateid *open_stp)
4614 {
4615         struct nfs4_ol_stateid *stp;
4616         struct nfs4_client *clp = lo->lo_owner.so_client;
4617
4618         stp = nfs4_alloc_stateid(clp);
4619         if (stp == NULL)
4620                 return NULL;
4621         stp->st_stid.sc_type = NFS4_LOCK_STID;
4622         list_add(&stp->st_perstateowner, &lo->lo_owner.so_stateids);
4623         stp->st_stateowner = &lo->lo_owner;
4624         get_nfs4_file(fp);
4625         stp->st_file = fp;
4626         stp->st_access_bmap = 0;
4627         stp->st_deny_bmap = open_stp->st_deny_bmap;
4628         stp->st_openstp = open_stp;
4629         list_add(&stp->st_locks, &open_stp->st_locks);
4630         spin_lock(&fp->fi_lock);
4631         list_add(&stp->st_perfile, &fp->fi_stateids);
4632         spin_unlock(&fp->fi_lock);
4633         return stp;
4634 }
4635
4636 static struct nfs4_ol_stateid *
4637 find_lock_stateid(struct nfs4_lockowner *lo, struct nfs4_file *fp)
4638 {
4639         struct nfs4_ol_stateid *lst;
4640
4641         list_for_each_entry(lst, &lo->lo_owner.so_stateids, st_perstateowner) {
4642                 if (lst->st_file == fp)
4643                         return lst;
4644         }
4645         return NULL;
4646 }
4647
4648
4649 static int
4650 check_lock_length(u64 offset, u64 length)
4651 {
4652         return ((length == 0)  || ((length != NFS4_MAX_UINT64) &&
4653              LOFF_OVERFLOW(offset, length)));
4654 }
4655
4656 static void get_lock_access(struct nfs4_ol_stateid *lock_stp, u32 access)
4657 {
4658         struct nfs4_file *fp = lock_stp->st_file;
4659
4660         lockdep_assert_held(&fp->fi_lock);
4661
4662         if (test_access(access, lock_stp))
4663                 return;
4664         __nfs4_file_get_access(fp, access);
4665         set_access(access, lock_stp);
4666 }
4667
4668 static __be32 lookup_or_create_lock_state(struct nfsd4_compound_state *cstate, struct nfs4_ol_stateid *ost, struct nfsd4_lock *lock, struct nfs4_ol_stateid **lst, bool *new)
4669 {
4670         struct nfs4_file *fi = ost->st_file;
4671         struct nfs4_openowner *oo = openowner(ost->st_stateowner);
4672         struct nfs4_client *cl = oo->oo_owner.so_client;
4673         struct nfs4_lockowner *lo;
4674         unsigned int strhashval;
4675         struct nfsd_net *nn = net_generic(cl->net, nfsd_net_id);
4676
4677         lo = find_lockowner_str(&cl->cl_clientid, &lock->v.new.owner, nn);
4678         if (!lo) {
4679                 strhashval = ownerstr_hashval(cl->cl_clientid.cl_id,
4680                                 &lock->v.new.owner);
4681                 lo = alloc_init_lock_stateowner(strhashval, cl, ost, lock);
4682                 if (lo == NULL)
4683                         return nfserr_jukebox;
4684         } else {
4685                 /* with an existing lockowner, seqids must be the same */
4686                 if (!cstate->minorversion &&
4687                     lock->lk_new_lock_seqid != lo->lo_owner.so_seqid)
4688                         return nfserr_bad_seqid;
4689         }
4690
4691         *lst = find_lock_stateid(lo, fi);
4692         if (*lst == NULL) {
4693                 *lst = alloc_init_lock_stateid(lo, fi, ost);
4694                 if (*lst == NULL) {
4695                         release_lockowner_if_empty(lo);
4696                         return nfserr_jukebox;
4697                 }
4698                 *new = true;
4699         }
4700         return nfs_ok;
4701 }
4702
4703 /*
4704  *  LOCK operation 
4705  */
4706 __be32
4707 nfsd4_lock(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4708            struct nfsd4_lock *lock)
4709 {
4710         struct nfs4_openowner *open_sop = NULL;
4711         struct nfs4_lockowner *lock_sop = NULL;
4712         struct nfs4_ol_stateid *lock_stp;
4713         struct nfs4_file *fp;
4714         struct file *filp = NULL;
4715         struct file_lock *file_lock = NULL;
4716         struct file_lock *conflock = NULL;
4717         __be32 status = 0;
4718         bool new_state = false;
4719         int lkflg;
4720         int err;
4721         struct net *net = SVC_NET(rqstp);
4722         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
4723
4724         dprintk("NFSD: nfsd4_lock: start=%Ld length=%Ld\n",
4725                 (long long) lock->lk_offset,
4726                 (long long) lock->lk_length);
4727
4728         if (check_lock_length(lock->lk_offset, lock->lk_length))
4729                  return nfserr_inval;
4730
4731         if ((status = fh_verify(rqstp, &cstate->current_fh,
4732                                 S_IFREG, NFSD_MAY_LOCK))) {
4733                 dprintk("NFSD: nfsd4_lock: permission denied!\n");
4734                 return status;
4735         }
4736
4737         nfs4_lock_state();
4738
4739         if (lock->lk_is_new) {
4740                 struct nfs4_ol_stateid *open_stp = NULL;
4741
4742                 if (nfsd4_has_session(cstate))
4743                         /* See rfc 5661 18.10.3: given clientid is ignored: */
4744                         memcpy(&lock->v.new.clientid,
4745                                 &cstate->session->se_client->cl_clientid,
4746                                 sizeof(clientid_t));
4747
4748                 status = nfserr_stale_clientid;
4749                 if (STALE_CLIENTID(&lock->lk_new_clientid, nn))
4750                         goto out;
4751
4752                 /* validate and update open stateid and open seqid */
4753                 status = nfs4_preprocess_confirmed_seqid_op(cstate,
4754                                         lock->lk_new_open_seqid,
4755                                         &lock->lk_new_open_stateid,
4756                                         &open_stp, nn);
4757                 if (status)
4758                         goto out;
4759                 open_sop = openowner(open_stp->st_stateowner);
4760                 status = nfserr_bad_stateid;
4761                 if (!same_clid(&open_sop->oo_owner.so_client->cl_clientid,
4762                                                 &lock->v.new.clientid))
4763                         goto out;
4764                 status = lookup_or_create_lock_state(cstate, open_stp, lock,
4765                                                         &lock_stp, &new_state);
4766         } else
4767                 status = nfs4_preprocess_seqid_op(cstate,
4768                                        lock->lk_old_lock_seqid,
4769                                        &lock->lk_old_lock_stateid,
4770                                        NFS4_LOCK_STID, &lock_stp, nn);
4771         if (status)
4772                 goto out;
4773         lock_sop = lockowner(lock_stp->st_stateowner);
4774
4775         lkflg = setlkflg(lock->lk_type);
4776         status = nfs4_check_openmode(lock_stp, lkflg);
4777         if (status)
4778                 goto out;
4779
4780         status = nfserr_grace;
4781         if (locks_in_grace(net) && !lock->lk_reclaim)
4782                 goto out;
4783         status = nfserr_no_grace;
4784         if (!locks_in_grace(net) && lock->lk_reclaim)
4785                 goto out;
4786
4787         file_lock = locks_alloc_lock();
4788         if (!file_lock) {
4789                 dprintk("NFSD: %s: unable to allocate lock!\n", __func__);
4790                 status = nfserr_jukebox;
4791                 goto out;
4792         }
4793
4794         fp = lock_stp->st_file;
4795         locks_init_lock(file_lock);
4796         switch (lock->lk_type) {
4797                 case NFS4_READ_LT:
4798                 case NFS4_READW_LT:
4799                         spin_lock(&fp->fi_lock);
4800                         filp = find_readable_file_locked(fp);
4801                         if (filp)
4802                                 get_lock_access(lock_stp, NFS4_SHARE_ACCESS_READ);
4803                         spin_unlock(&fp->fi_lock);
4804                         file_lock->fl_type = F_RDLCK;
4805                         break;
4806                 case NFS4_WRITE_LT:
4807                 case NFS4_WRITEW_LT:
4808                         spin_lock(&fp->fi_lock);
4809                         filp = find_writeable_file_locked(fp);
4810                         if (filp)
4811                                 get_lock_access(lock_stp, NFS4_SHARE_ACCESS_WRITE);
4812                         spin_unlock(&fp->fi_lock);
4813                         file_lock->fl_type = F_WRLCK;
4814                         break;
4815                 default:
4816                         status = nfserr_inval;
4817                 goto out;
4818         }
4819         if (!filp) {
4820                 status = nfserr_openmode;
4821                 goto out;
4822         }
4823         file_lock->fl_owner = (fl_owner_t)lock_sop;
4824         file_lock->fl_pid = current->tgid;
4825         file_lock->fl_file = filp;
4826         file_lock->fl_flags = FL_POSIX;
4827         file_lock->fl_lmops = &nfsd_posix_mng_ops;
4828         file_lock->fl_start = lock->lk_offset;
4829         file_lock->fl_end = last_byte_offset(lock->lk_offset, lock->lk_length);
4830         nfs4_transform_lock_offset(file_lock);
4831
4832         conflock = locks_alloc_lock();
4833         if (!conflock) {
4834                 dprintk("NFSD: %s: unable to allocate lock!\n", __func__);
4835                 status = nfserr_jukebox;
4836                 goto out;
4837         }
4838
4839         err = vfs_lock_file(filp, F_SETLK, file_lock, conflock);
4840         switch (-err) {
4841         case 0: /* success! */
4842                 update_stateid(&lock_stp->st_stid.sc_stateid);
4843                 memcpy(&lock->lk_resp_stateid, &lock_stp->st_stid.sc_stateid, 
4844                                 sizeof(stateid_t));
4845                 status = 0;
4846                 break;
4847         case (EAGAIN):          /* conflock holds conflicting lock */
4848                 status = nfserr_denied;
4849                 dprintk("NFSD: nfsd4_lock: conflicting lock found!\n");
4850                 nfs4_set_lock_denied(conflock, &lock->lk_denied);
4851                 break;
4852         case (EDEADLK):
4853                 status = nfserr_deadlock;
4854                 break;
4855         default:
4856                 dprintk("NFSD: nfsd4_lock: vfs_lock_file() failed! status %d\n",err);
4857                 status = nfserrno(err);
4858                 break;
4859         }
4860 out:
4861         if (filp)
4862                 fput(filp);
4863         if (status && new_state)
4864                 release_lock_stateid(lock_stp);
4865         nfsd4_bump_seqid(cstate, status);
4866         if (!cstate->replay_owner)
4867                 nfs4_unlock_state();
4868         if (file_lock)
4869                 locks_free_lock(file_lock);
4870         if (conflock)
4871                 locks_free_lock(conflock);
4872         return status;
4873 }
4874
4875 /*
4876  * The NFSv4 spec allows a client to do a LOCKT without holding an OPEN,
4877  * so we do a temporary open here just to get an open file to pass to
4878  * vfs_test_lock.  (Arguably perhaps test_lock should be done with an
4879  * inode operation.)
4880  */
4881 static __be32 nfsd_test_lock(struct svc_rqst *rqstp, struct svc_fh *fhp, struct file_lock *lock)
4882 {
4883         struct file *file;
4884         __be32 err = nfsd_open(rqstp, fhp, S_IFREG, NFSD_MAY_READ, &file);
4885         if (!err) {
4886                 err = nfserrno(vfs_test_lock(file, lock));
4887                 nfsd_close(file);
4888         }
4889         return err;
4890 }
4891
4892 /*
4893  * LOCKT operation
4894  */
4895 __be32
4896 nfsd4_lockt(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4897             struct nfsd4_lockt *lockt)
4898 {
4899         struct file_lock *file_lock = NULL;
4900         struct nfs4_lockowner *lo;
4901         __be32 status;
4902         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
4903
4904         if (locks_in_grace(SVC_NET(rqstp)))
4905                 return nfserr_grace;
4906
4907         if (check_lock_length(lockt->lt_offset, lockt->lt_length))
4908                  return nfserr_inval;
4909
4910         nfs4_lock_state();
4911
4912         if (!nfsd4_has_session(cstate)) {
4913                 status = lookup_clientid(&lockt->lt_clientid, cstate, nn);
4914                 if (status)
4915                         goto out;
4916         }
4917
4918         if ((status = fh_verify(rqstp, &cstate->current_fh, S_IFREG, 0)))
4919                 goto out;
4920
4921         file_lock = locks_alloc_lock();
4922         if (!file_lock) {
4923                 dprintk("NFSD: %s: unable to allocate lock!\n", __func__);
4924                 status = nfserr_jukebox;
4925                 goto out;
4926         }
4927         locks_init_lock(file_lock);
4928         switch (lockt->lt_type) {
4929                 case NFS4_READ_LT:
4930                 case NFS4_READW_LT:
4931                         file_lock->fl_type = F_RDLCK;
4932                 break;
4933                 case NFS4_WRITE_LT:
4934                 case NFS4_WRITEW_LT:
4935                         file_lock->fl_type = F_WRLCK;
4936                 break;
4937                 default:
4938                         dprintk("NFSD: nfs4_lockt: bad lock type!\n");
4939                         status = nfserr_inval;
4940                 goto out;
4941         }
4942
4943         lo = find_lockowner_str(&lockt->lt_clientid, &lockt->lt_owner, nn);
4944         if (lo)
4945                 file_lock->fl_owner = (fl_owner_t)lo;
4946         file_lock->fl_pid = current->tgid;
4947         file_lock->fl_flags = FL_POSIX;
4948
4949         file_lock->fl_start = lockt->lt_offset;
4950         file_lock->fl_end = last_byte_offset(lockt->lt_offset, lockt->lt_length);
4951
4952         nfs4_transform_lock_offset(file_lock);
4953
4954         status = nfsd_test_lock(rqstp, &cstate->current_fh, file_lock);
4955         if (status)
4956                 goto out;
4957
4958         if (file_lock->fl_type != F_UNLCK) {
4959                 status = nfserr_denied;
4960                 nfs4_set_lock_denied(file_lock, &lockt->lt_denied);
4961         }
4962 out:
4963         nfs4_unlock_state();
4964         if (file_lock)
4965                 locks_free_lock(file_lock);
4966         return status;
4967 }
4968
4969 __be32
4970 nfsd4_locku(struct svc_rqst *rqstp, struct nfsd4_compound_state *cstate,
4971             struct nfsd4_locku *locku)
4972 {
4973         struct nfs4_ol_stateid *stp;
4974         struct file *filp = NULL;
4975         struct file_lock *file_lock = NULL;
4976         __be32 status;
4977         int err;
4978         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
4979
4980         dprintk("NFSD: nfsd4_locku: start=%Ld length=%Ld\n",
4981                 (long long) locku->lu_offset,
4982                 (long long) locku->lu_length);
4983
4984         if (check_lock_length(locku->lu_offset, locku->lu_length))
4985                  return nfserr_inval;
4986
4987         nfs4_lock_state();
4988                                                                                 
4989         status = nfs4_preprocess_seqid_op(cstate, locku->lu_seqid,
4990                                         &locku->lu_stateid, NFS4_LOCK_STID,
4991                                         &stp, nn);
4992         if (status)
4993                 goto out;
4994         filp = find_any_file(stp->st_file);
4995         if (!filp) {
4996                 status = nfserr_lock_range;
4997                 goto out;
4998         }
4999         file_lock = locks_alloc_lock();
5000         if (!file_lock) {
5001                 dprintk("NFSD: %s: unable to allocate lock!\n", __func__);
5002                 status = nfserr_jukebox;
5003                 goto fput;
5004         }
5005         locks_init_lock(file_lock);
5006         file_lock->fl_type = F_UNLCK;
5007         file_lock->fl_owner = (fl_owner_t)lockowner(stp->st_stateowner);
5008         file_lock->fl_pid = current->tgid;
5009         file_lock->fl_file = filp;
5010         file_lock->fl_flags = FL_POSIX;
5011         file_lock->fl_lmops = &nfsd_posix_mng_ops;
5012         file_lock->fl_start = locku->lu_offset;
5013
5014         file_lock->fl_end = last_byte_offset(locku->lu_offset,
5015                                                 locku->lu_length);
5016         nfs4_transform_lock_offset(file_lock);
5017
5018         err = vfs_lock_file(filp, F_SETLK, file_lock, NULL);
5019         if (err) {
5020                 dprintk("NFSD: nfs4_locku: vfs_lock_file failed!\n");
5021                 goto out_nfserr;
5022         }
5023         update_stateid(&stp->st_stid.sc_stateid);
5024         memcpy(&locku->lu_stateid, &stp->st_stid.sc_stateid, sizeof(stateid_t));
5025 fput:
5026         fput(filp);
5027 out:
5028         nfsd4_bump_seqid(cstate, status);
5029         if (!cstate->replay_owner)
5030                 nfs4_unlock_state();
5031         if (file_lock)
5032                 locks_free_lock(file_lock);
5033         return status;
5034
5035 out_nfserr:
5036         status = nfserrno(err);
5037         goto fput;
5038 }
5039
5040 /*
5041  * returns
5042  *      1: locks held by lockowner
5043  *      0: no locks held by lockowner
5044  */
5045 static int
5046 check_for_locks(struct nfs4_file *filp, struct nfs4_lockowner *lowner)
5047 {
5048         struct file_lock **flpp;
5049         struct inode *inode = filp->fi_inode;
5050         int status = 0;
5051
5052         spin_lock(&inode->i_lock);
5053         for (flpp = &inode->i_flock; *flpp != NULL; flpp = &(*flpp)->fl_next) {
5054                 if ((*flpp)->fl_owner == (fl_owner_t)lowner) {
5055                         status = 1;
5056                         goto out;
5057                 }
5058         }
5059 out:
5060         spin_unlock(&inode->i_lock);
5061         return status;
5062 }
5063
5064 __be32
5065 nfsd4_release_lockowner(struct svc_rqst *rqstp,
5066                         struct nfsd4_compound_state *cstate,
5067                         struct nfsd4_release_lockowner *rlockowner)
5068 {
5069         clientid_t *clid = &rlockowner->rl_clientid;
5070         struct nfs4_stateowner *sop = NULL, *tmp;
5071         struct nfs4_lockowner *lo;
5072         struct nfs4_ol_stateid *stp;
5073         struct xdr_netobj *owner = &rlockowner->rl_owner;
5074         unsigned int hashval = ownerstr_hashval(clid->cl_id, owner);
5075         __be32 status;
5076         struct nfsd_net *nn = net_generic(SVC_NET(rqstp), nfsd_net_id);
5077
5078         dprintk("nfsd4_release_lockowner clientid: (%08x/%08x):\n",
5079                 clid->cl_boot, clid->cl_id);
5080
5081         nfs4_lock_state();
5082
5083         status = lookup_clientid(clid, cstate, nn);
5084         if (status)
5085                 goto out;
5086
5087         status = nfserr_locks_held;
5088
5089         /* Find the matching lock stateowner */
5090         list_for_each_entry(tmp, &nn->ownerstr_hashtbl[hashval], so_strhash) {
5091                 if (tmp->so_is_open_owner)
5092                         continue;
5093                 if (same_owner_str(tmp, owner, clid)) {
5094                         sop = tmp;
5095                         break;
5096                 }
5097         }
5098
5099         /* No matching owner found, maybe a replay? Just declare victory... */
5100         if (!sop) {
5101                 status = nfs_ok;
5102                 goto out;
5103         }
5104
5105         lo = lockowner(sop);
5106         /* see if there are still any locks associated with it */
5107         list_for_each_entry(stp, &sop->so_stateids, st_perstateowner) {
5108                 if (check_for_locks(stp->st_file, lo))
5109                         goto out;
5110         }
5111
5112         status = nfs_ok;
5113         release_lockowner(lo);
5114 out:
5115         nfs4_unlock_state();
5116         return status;
5117 }
5118
5119 static inline struct nfs4_client_reclaim *
5120 alloc_reclaim(void)
5121 {
5122         return kmalloc(sizeof(struct nfs4_client_reclaim), GFP_KERNEL);
5123 }
5124
5125 bool
5126 nfs4_has_reclaimed_state(const char *name, struct nfsd_net *nn)
5127 {
5128         struct nfs4_client_reclaim *crp;
5129
5130         crp = nfsd4_find_reclaim_client(name, nn);
5131         return (crp && crp->cr_clp);
5132 }
5133
5134 /*
5135  * failure => all reset bets are off, nfserr_no_grace...
5136  */
5137 struct nfs4_client_reclaim *
5138 nfs4_client_to_reclaim(const char *name, struct nfsd_net *nn)
5139 {
5140         unsigned int strhashval;
5141         struct nfs4_client_reclaim *crp;
5142
5143         dprintk("NFSD nfs4_client_to_reclaim NAME: %.*s\n", HEXDIR_LEN, name);
5144         crp = alloc_reclaim();
5145         if (crp) {
5146                 strhashval = clientstr_hashval(name);
5147                 INIT_LIST_HEAD(&crp->cr_strhash);
5148                 list_add(&crp->cr_strhash, &nn->reclaim_str_hashtbl[strhashval]);
5149                 memcpy(crp->cr_recdir, name, HEXDIR_LEN);
5150                 crp->cr_clp = NULL;
5151                 nn->reclaim_str_hashtbl_size++;
5152         }
5153         return crp;
5154 }
5155
5156 void
5157 nfs4_remove_reclaim_record(struct nfs4_client_reclaim *crp, struct nfsd_net *nn)
5158 {
5159         list_del(&crp->cr_strhash);
5160         kfree(crp);
5161         nn->reclaim_str_hashtbl_size--;
5162 }
5163
5164 void
5165 nfs4_release_reclaim(struct nfsd_net *nn)
5166 {
5167         struct nfs4_client_reclaim *crp = NULL;
5168         int i;
5169
5170         for (i = 0; i < CLIENT_HASH_SIZE; i++) {
5171                 while (!list_empty(&nn->reclaim_str_hashtbl[i])) {
5172                         crp = list_entry(nn->reclaim_str_hashtbl[i].next,
5173                                         struct nfs4_client_reclaim, cr_strhash);
5174                         nfs4_remove_reclaim_record(crp, nn);
5175                 }
5176         }
5177         WARN_ON_ONCE(nn->reclaim_str_hashtbl_size);
5178 }
5179
5180 /*
5181  * called from OPEN, CLAIM_PREVIOUS with a new clientid. */
5182 struct nfs4_client_reclaim *
5183 nfsd4_find_reclaim_client(const char *recdir, struct nfsd_net *nn)
5184 {
5185         unsigned int strhashval;
5186         struct nfs4_client_reclaim *crp = NULL;
5187
5188         dprintk("NFSD: nfs4_find_reclaim_client for recdir %s\n", recdir);
5189
5190         strhashval = clientstr_hashval(recdir);
5191         list_for_each_entry(crp, &nn->reclaim_str_hashtbl[strhashval], cr_strhash) {
5192                 if (same_name(crp->cr_recdir, recdir)) {
5193                         return crp;
5194                 }
5195         }
5196         return NULL;
5197 }
5198
5199 /*
5200 * Called from OPEN. Look for clientid in reclaim list.
5201 */
5202 __be32
5203 nfs4_check_open_reclaim(clientid_t *clid,
5204                 struct nfsd4_compound_state *cstate,
5205                 struct nfsd_net *nn)
5206 {
5207         __be32 status;
5208
5209         /* find clientid in conf_id_hashtbl */
5210         status = lookup_clientid(clid, cstate, nn);
5211         if (status)
5212                 return nfserr_reclaim_bad;
5213
5214         if (nfsd4_client_record_check(cstate->clp))
5215                 return nfserr_reclaim_bad;
5216
5217         return nfs_ok;
5218 }
5219
5220 #ifdef CONFIG_NFSD_FAULT_INJECTION
5221
5222 u64 nfsd_forget_client(struct nfs4_client *clp, u64 max)
5223 {
5224         if (mark_client_expired(clp))
5225                 return 0;
5226         expire_client(clp);
5227         return 1;
5228 }
5229
5230 u64 nfsd_print_client(struct nfs4_client *clp, u64 num)
5231 {
5232         char buf[INET6_ADDRSTRLEN];
5233         rpc_ntop((struct sockaddr *)&clp->cl_addr, buf, sizeof(buf));
5234         printk(KERN_INFO "NFS Client: %s\n", buf);
5235         return 1;
5236 }
5237
5238 static void nfsd_print_count(struct nfs4_client *clp, unsigned int count,
5239                              const char *type)
5240 {
5241         char buf[INET6_ADDRSTRLEN];
5242         rpc_ntop((struct sockaddr *)&clp->cl_addr, buf, sizeof(buf));
5243         printk(KERN_INFO "NFS Client: %s has %u %s\n", buf, count, type);
5244 }
5245
5246 static u64 nfsd_foreach_client_lock(struct nfs4_client *clp, u64 max,
5247                                     void (*func)(struct nfs4_ol_stateid *))
5248 {
5249         struct nfs4_openowner *oop;
5250         struct nfs4_ol_stateid *stp, *st_next;
5251         struct nfs4_ol_stateid *lst, *lst_next;
5252         u64 count = 0;
5253
5254         list_for_each_entry(oop, &clp->cl_openowners, oo_perclient) {
5255                 list_for_each_entry_safe(stp, st_next,
5256                                 &oop->oo_owner.so_stateids, st_perstateowner) {
5257                         list_for_each_entry_safe(lst, lst_next,
5258                                         &stp->st_locks, st_locks) {
5259                                 if (func)
5260                                         func(lst);
5261                                 if (++count == max)
5262                                         return count;
5263                         }
5264                 }
5265         }
5266
5267         return count;
5268 }
5269
5270 u64 nfsd_forget_client_locks(struct nfs4_client *clp, u64 max)
5271 {
5272         return nfsd_foreach_client_lock(clp, max, release_lock_stateid);
5273 }
5274
5275 u64 nfsd_print_client_locks(struct nfs4_client *clp, u64 max)
5276 {
5277         u64 count = nfsd_foreach_client_lock(clp, max, NULL);
5278         nfsd_print_count(clp, count, "locked files");
5279         return count;
5280 }
5281
5282 static u64 nfsd_foreach_client_open(struct nfs4_client *clp, u64 max, void (*func)(struct nfs4_openowner *))
5283 {
5284         struct nfs4_openowner *oop, *next;
5285         u64 count = 0;
5286
5287         list_for_each_entry_safe(oop, next, &clp->cl_openowners, oo_perclient) {
5288                 if (func)
5289                         func(oop);
5290                 if (++count == max)
5291                         break;
5292         }
5293
5294         return count;
5295 }
5296
5297 u64 nfsd_forget_client_openowners(struct nfs4_client *clp, u64 max)
5298 {
5299         return nfsd_foreach_client_open(clp, max, release_openowner);
5300 }
5301
5302 u64 nfsd_print_client_openowners(struct nfs4_client *clp, u64 max)
5303 {
5304         u64 count = nfsd_foreach_client_open(clp, max, NULL);
5305         nfsd_print_count(clp, count, "open files");
5306         return count;
5307 }
5308
5309 static u64 nfsd_find_all_delegations(struct nfs4_client *clp, u64 max,
5310                                      struct list_head *victims)
5311 {
5312         struct nfs4_delegation *dp, *next;
5313         u64 count = 0;
5314
5315         lockdep_assert_held(&state_lock);
5316         list_for_each_entry_safe(dp, next, &clp->cl_delegations, dl_perclnt) {
5317                 if (victims) {
5318                         /*
5319                          * It's not safe to mess with delegations that have a
5320                          * non-zero dl_time. They might have already been broken
5321                          * and could be processed by the laundromat outside of
5322                          * the state_lock. Just leave them be.
5323                          */
5324                         if (dp->dl_time != 0)
5325                                 continue;
5326
5327                         /*
5328                          * Increment dl_time to ensure that delegation breaks
5329                          * don't monkey with it now that we are.
5330                          */
5331                         ++dp->dl_time;
5332                         list_move(&dp->dl_recall_lru, victims);
5333                 }
5334                 if (++count == max)
5335                         break;
5336         }
5337         return count;
5338 }
5339
5340 u64 nfsd_forget_client_delegations(struct nfs4_client *clp, u64 max)
5341 {
5342         struct nfs4_delegation *dp, *next;
5343         LIST_HEAD(victims);
5344         u64 count;
5345
5346         spin_lock(&state_lock);
5347         count = nfsd_find_all_delegations(clp, max, &victims);
5348         spin_unlock(&state_lock);
5349
5350         list_for_each_entry_safe(dp, next, &victims, dl_recall_lru)
5351                 revoke_delegation(dp);
5352
5353         return count;
5354 }
5355
5356 u64 nfsd_recall_client_delegations(struct nfs4_client *clp, u64 max)
5357 {
5358         struct nfs4_delegation *dp;
5359         LIST_HEAD(victims);
5360         u64 count;
5361
5362         spin_lock(&state_lock);
5363         count = nfsd_find_all_delegations(clp, max, &victims);
5364         while (!list_empty(&victims)) {
5365                 dp = list_first_entry(&victims, struct nfs4_delegation,
5366                                         dl_recall_lru);
5367                 list_del_init(&dp->dl_recall_lru);
5368                 dp->dl_time = 0;
5369                 nfsd_break_one_deleg(dp);
5370         }
5371         spin_unlock(&state_lock);
5372
5373         return count;
5374 }
5375
5376 u64 nfsd_print_client_delegations(struct nfs4_client *clp, u64 max)
5377 {
5378         u64 count = 0;
5379
5380         spin_lock(&state_lock);
5381         count = nfsd_find_all_delegations(clp, max, NULL);
5382         spin_unlock(&state_lock);
5383
5384         nfsd_print_count(clp, count, "delegations");
5385         return count;
5386 }
5387
5388 u64 nfsd_for_n_state(u64 max, u64 (*func)(struct nfs4_client *, u64))
5389 {
5390         struct nfs4_client *clp, *next;
5391         u64 count = 0;
5392         struct nfsd_net *nn = net_generic(current->nsproxy->net_ns, nfsd_net_id);
5393
5394         if (!nfsd_netns_ready(nn))
5395                 return 0;
5396
5397         list_for_each_entry_safe(clp, next, &nn->client_lru, cl_lru) {
5398                 count += func(clp, max - count);
5399                 if ((max != 0) && (count >= max))
5400                         break;
5401         }
5402
5403         return count;
5404 }
5405
5406 struct nfs4_client *nfsd_find_client(struct sockaddr_storage *addr, size_t addr_size)
5407 {
5408         struct nfs4_client *clp;
5409         struct nfsd_net *nn = net_generic(current->nsproxy->net_ns, nfsd_net_id);
5410
5411         if (!nfsd_netns_ready(nn))
5412                 return NULL;
5413
5414         list_for_each_entry(clp, &nn->client_lru, cl_lru) {
5415                 if (memcmp(&clp->cl_addr, addr, addr_size) == 0)
5416                         return clp;
5417         }
5418         return NULL;
5419 }
5420
5421 #endif /* CONFIG_NFSD_FAULT_INJECTION */
5422
5423 /*
5424  * Since the lifetime of a delegation isn't limited to that of an open, a
5425  * client may quite reasonably hang on to a delegation as long as it has
5426  * the inode cached.  This becomes an obvious problem the first time a
5427  * client's inode cache approaches the size of the server's total memory.
5428  *
5429  * For now we avoid this problem by imposing a hard limit on the number
5430  * of delegations, which varies according to the server's memory size.
5431  */
5432 static void
5433 set_max_delegations(void)
5434 {
5435         /*
5436          * Allow at most 4 delegations per megabyte of RAM.  Quick
5437          * estimates suggest that in the worst case (where every delegation
5438          * is for a different inode), a delegation could take about 1.5K,
5439          * giving a worst case usage of about 6% of memory.
5440          */
5441         max_delegations = nr_free_buffer_pages() >> (20 - 2 - PAGE_SHIFT);
5442 }
5443
5444 static int nfs4_state_create_net(struct net *net)
5445 {
5446         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
5447         int i;
5448
5449         nn->conf_id_hashtbl = kmalloc(sizeof(struct list_head) *
5450                         CLIENT_HASH_SIZE, GFP_KERNEL);
5451         if (!nn->conf_id_hashtbl)
5452                 goto err;
5453         nn->unconf_id_hashtbl = kmalloc(sizeof(struct list_head) *
5454                         CLIENT_HASH_SIZE, GFP_KERNEL);
5455         if (!nn->unconf_id_hashtbl)
5456                 goto err_unconf_id;
5457         nn->ownerstr_hashtbl = kmalloc(sizeof(struct list_head) *
5458                         OWNER_HASH_SIZE, GFP_KERNEL);
5459         if (!nn->ownerstr_hashtbl)
5460                 goto err_ownerstr;
5461         nn->sessionid_hashtbl = kmalloc(sizeof(struct list_head) *
5462                         SESSION_HASH_SIZE, GFP_KERNEL);
5463         if (!nn->sessionid_hashtbl)
5464                 goto err_sessionid;
5465
5466         for (i = 0; i < CLIENT_HASH_SIZE; i++) {
5467                 INIT_LIST_HEAD(&nn->conf_id_hashtbl[i]);
5468                 INIT_LIST_HEAD(&nn->unconf_id_hashtbl[i]);
5469         }
5470         for (i = 0; i < OWNER_HASH_SIZE; i++)
5471                 INIT_LIST_HEAD(&nn->ownerstr_hashtbl[i]);
5472         for (i = 0; i < SESSION_HASH_SIZE; i++)
5473                 INIT_LIST_HEAD(&nn->sessionid_hashtbl[i]);
5474         nn->conf_name_tree = RB_ROOT;
5475         nn->unconf_name_tree = RB_ROOT;
5476         INIT_LIST_HEAD(&nn->client_lru);
5477         INIT_LIST_HEAD(&nn->close_lru);
5478         INIT_LIST_HEAD(&nn->del_recall_lru);
5479         spin_lock_init(&nn->client_lock);
5480
5481         INIT_DELAYED_WORK(&nn->laundromat_work, laundromat_main);
5482         get_net(net);
5483
5484         return 0;
5485
5486 err_sessionid:
5487         kfree(nn->ownerstr_hashtbl);
5488 err_ownerstr:
5489         kfree(nn->unconf_id_hashtbl);
5490 err_unconf_id:
5491         kfree(nn->conf_id_hashtbl);
5492 err:
5493         return -ENOMEM;
5494 }
5495
5496 static void
5497 nfs4_state_destroy_net(struct net *net)
5498 {
5499         int i;
5500         struct nfs4_client *clp = NULL;
5501         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
5502
5503         for (i = 0; i < CLIENT_HASH_SIZE; i++) {
5504                 while (!list_empty(&nn->conf_id_hashtbl[i])) {
5505                         clp = list_entry(nn->conf_id_hashtbl[i].next, struct nfs4_client, cl_idhash);
5506                         destroy_client(clp);
5507                 }
5508         }
5509
5510         for (i = 0; i < CLIENT_HASH_SIZE; i++) {
5511                 while (!list_empty(&nn->unconf_id_hashtbl[i])) {
5512                         clp = list_entry(nn->unconf_id_hashtbl[i].next, struct nfs4_client, cl_idhash);
5513                         destroy_client(clp);
5514                 }
5515         }
5516
5517         kfree(nn->sessionid_hashtbl);
5518         kfree(nn->ownerstr_hashtbl);
5519         kfree(nn->unconf_id_hashtbl);
5520         kfree(nn->conf_id_hashtbl);
5521         put_net(net);
5522 }
5523
5524 int
5525 nfs4_state_start_net(struct net *net)
5526 {
5527         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
5528         int ret;
5529
5530         ret = nfs4_state_create_net(net);
5531         if (ret)
5532                 return ret;
5533         nfsd4_client_tracking_init(net);
5534         nn->boot_time = get_seconds();
5535         locks_start_grace(net, &nn->nfsd4_manager);
5536         nn->grace_ended = false;
5537         printk(KERN_INFO "NFSD: starting %ld-second grace period (net %p)\n",
5538                nn->nfsd4_grace, net);
5539         queue_delayed_work(laundry_wq, &nn->laundromat_work, nn->nfsd4_grace * HZ);
5540         return 0;
5541 }
5542
5543 /* initialization to perform when the nfsd service is started: */
5544
5545 int
5546 nfs4_state_start(void)
5547 {
5548         int ret;
5549
5550         ret = set_callback_cred();
5551         if (ret)
5552                 return -ENOMEM;
5553         laundry_wq = create_singlethread_workqueue("nfsd4");
5554         if (laundry_wq == NULL) {
5555                 ret = -ENOMEM;
5556                 goto out_recovery;
5557         }
5558         ret = nfsd4_create_callback_queue();
5559         if (ret)
5560                 goto out_free_laundry;
5561
5562         set_max_delegations();
5563
5564         return 0;
5565
5566 out_free_laundry:
5567         destroy_workqueue(laundry_wq);
5568 out_recovery:
5569         return ret;
5570 }
5571
5572 void
5573 nfs4_state_shutdown_net(struct net *net)
5574 {
5575         struct nfs4_delegation *dp = NULL;
5576         struct list_head *pos, *next, reaplist;
5577         struct nfsd_net *nn = net_generic(net, nfsd_net_id);
5578
5579         cancel_delayed_work_sync(&nn->laundromat_work);
5580         locks_end_grace(&nn->nfsd4_manager);
5581
5582         nfs4_lock_state();
5583         INIT_LIST_HEAD(&reaplist);
5584         spin_lock(&state_lock);
5585         list_for_each_safe(pos, next, &nn->del_recall_lru) {
5586                 dp = list_entry (pos, struct nfs4_delegation, dl_recall_lru);
5587                 list_move(&dp->dl_recall_lru, &reaplist);
5588         }
5589         spin_unlock(&state_lock);
5590         list_for_each_safe(pos, next, &reaplist) {
5591                 dp = list_entry (pos, struct nfs4_delegation, dl_recall_lru);
5592                 destroy_delegation(dp);
5593         }
5594
5595         nfsd4_client_tracking_exit(net);
5596         nfs4_state_destroy_net(net);
5597         nfs4_unlock_state();
5598 }
5599
5600 void
5601 nfs4_state_shutdown(void)
5602 {
5603         destroy_workqueue(laundry_wq);
5604         nfsd4_destroy_callback_queue();
5605 }
5606
5607 static void
5608 get_stateid(struct nfsd4_compound_state *cstate, stateid_t *stateid)
5609 {
5610         if (HAS_STATE_ID(cstate, CURRENT_STATE_ID_FLAG) && CURRENT_STATEID(stateid))
5611                 memcpy(stateid, &cstate->current_stateid, sizeof(stateid_t));
5612 }
5613
5614 static void
5615 put_stateid(struct nfsd4_compound_state *cstate, stateid_t *stateid)
5616 {
5617         if (cstate->minorversion) {
5618                 memcpy(&cstate->current_stateid, stateid, sizeof(stateid_t));
5619                 SET_STATE_ID(cstate, CURRENT_STATE_ID_FLAG);
5620         }
5621 }
5622
5623 void
5624 clear_current_stateid(struct nfsd4_compound_state *cstate)
5625 {
5626         CLEAR_STATE_ID(cstate, CURRENT_STATE_ID_FLAG);
5627 }
5628
5629 /*
5630  * functions to set current state id
5631  */
5632 void
5633 nfsd4_set_opendowngradestateid(struct nfsd4_compound_state *cstate, struct nfsd4_open_downgrade *odp)
5634 {
5635         put_stateid(cstate, &odp->od_stateid);
5636 }
5637
5638 void
5639 nfsd4_set_openstateid(struct nfsd4_compound_state *cstate, struct nfsd4_open *open)
5640 {
5641         put_stateid(cstate, &open->op_stateid);
5642 }
5643
5644 void
5645 nfsd4_set_closestateid(struct nfsd4_compound_state *cstate, struct nfsd4_close *close)
5646 {
5647         put_stateid(cstate, &close->cl_stateid);
5648 }
5649
5650 void
5651 nfsd4_set_lockstateid(struct nfsd4_compound_state *cstate, struct nfsd4_lock *lock)
5652 {
5653         put_stateid(cstate, &lock->lk_resp_stateid);
5654 }
5655
5656 /*
5657  * functions to consume current state id
5658  */
5659
5660 void
5661 nfsd4_get_opendowngradestateid(struct nfsd4_compound_state *cstate, struct nfsd4_open_downgrade *odp)
5662 {
5663         get_stateid(cstate, &odp->od_stateid);
5664 }
5665
5666 void
5667 nfsd4_get_delegreturnstateid(struct nfsd4_compound_state *cstate, struct nfsd4_delegreturn *drp)
5668 {
5669         get_stateid(cstate, &drp->dr_stateid);
5670 }
5671
5672 void
5673 nfsd4_get_freestateid(struct nfsd4_compound_state *cstate, struct nfsd4_free_stateid *fsp)
5674 {
5675         get_stateid(cstate, &fsp->fr_stateid);
5676 }
5677
5678 void
5679 nfsd4_get_setattrstateid(struct nfsd4_compound_state *cstate, struct nfsd4_setattr *setattr)
5680 {
5681         get_stateid(cstate, &setattr->sa_stateid);
5682 }
5683
5684 void
5685 nfsd4_get_closestateid(struct nfsd4_compound_state *cstate, struct nfsd4_close *close)
5686 {
5687         get_stateid(cstate, &close->cl_stateid);
5688 }
5689
5690 void
5691 nfsd4_get_lockustateid(struct nfsd4_compound_state *cstate, struct nfsd4_locku *locku)
5692 {
5693         get_stateid(cstate, &locku->lu_stateid);
5694 }
5695
5696 void
5697 nfsd4_get_readstateid(struct nfsd4_compound_state *cstate, struct nfsd4_read *read)
5698 {
5699         get_stateid(cstate, &read->rd_stateid);
5700 }
5701
5702 void
5703 nfsd4_get_writestateid(struct nfsd4_compound_state *cstate, struct nfsd4_write *write)
5704 {
5705         get_stateid(cstate, &write->wr_stateid);
5706 }