7622f79cb5b418e96eeb51bf15246888f1b5d98f
[pandora-kernel.git] / fs / jffs2 / xattr.c
1 /*
2  * JFFS2 -- Journalling Flash File System, Version 2.
3  *
4  * Copyright (C) 2006  NEC Corporation
5  *
6  * Created by KaiGai Kohei <kaigai@ak.jp.nec.com>
7  *
8  * For licensing information, see the file 'LICENCE' in this directory.
9  *
10  */
11 #include <linux/kernel.h>
12 #include <linux/slab.h>
13 #include <linux/fs.h>
14 #include <linux/time.h>
15 #include <linux/pagemap.h>
16 #include <linux/highmem.h>
17 #include <linux/crc32.h>
18 #include <linux/jffs2.h>
19 #include <linux/xattr.h>
20 #include <linux/mtd/mtd.h>
21 #include "nodelist.h"
22 /* -------- xdatum related functions ----------------
23  * xattr_datum_hashkey(xprefix, xname, xvalue, xsize)
24  *   is used to calcurate xdatum hashkey. The reminder of hashkey into XATTRINDEX_HASHSIZE is
25  *   the index of the xattr name/value pair cache (c->xattrindex).
26  * is_xattr_datum_unchecked(c, xd)
27  *   returns 1, if xdatum contains any unchecked raw nodes. if all raw nodes are not
28  *   unchecked, it returns 0.
29  * unload_xattr_datum(c, xd)
30  *   is used to release xattr name/value pair and detach from c->xattrindex.
31  * reclaim_xattr_datum(c)
32  *   is used to reclaim xattr name/value pairs on the xattr name/value pair cache when
33  *   memory usage by cache is over c->xdatum_mem_threshold. Currentry, this threshold 
34  *   is hard coded as 32KiB.
35  * do_verify_xattr_datum(c, xd)
36  *   is used to load the xdatum informations without name/value pair from the medium.
37  *   It's necessary once, because those informations are not collected during mounting
38  *   process when EBS is enabled.
39  *   0 will be returned, if success. An negative return value means recoverable error, and
40  *   positive return value means unrecoverable error. Thus, caller must remove this xdatum
41  *   and xref when it returned positive value.
42  * do_load_xattr_datum(c, xd)
43  *   is used to load name/value pair from the medium.
44  *   The meanings of return value is same as do_verify_xattr_datum().
45  * load_xattr_datum(c, xd)
46  *   is used to be as a wrapper of do_verify_xattr_datum() and do_load_xattr_datum().
47  *   If xd need to call do_verify_xattr_datum() at first, it's called before calling
48  *   do_load_xattr_datum(). The meanings of return value is same as do_verify_xattr_datum().
49  * save_xattr_datum(c, xd)
50  *   is used to write xdatum to medium. xd->version will be incremented.
51  * create_xattr_datum(c, xprefix, xname, xvalue, xsize)
52  *   is used to create new xdatum and write to medium.
53  * delete_xattr_datum(c, xd)
54  *   is used to delete a xdatum. It marks xd JFFS2_XFLAGS_DEAD, and allows
55  *   GC to reclaim those physical nodes.
56  * -------------------------------------------------- */
57 static uint32_t xattr_datum_hashkey(int xprefix, const char *xname, const char *xvalue, int xsize)
58 {
59         int name_len = strlen(xname);
60
61         return crc32(xprefix, xname, name_len) ^ crc32(xprefix, xvalue, xsize);
62 }
63
64 static int is_xattr_datum_unchecked(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
65 {
66         struct jffs2_raw_node_ref *raw;
67         int rc = 0;
68
69         spin_lock(&c->erase_completion_lock);
70         for (raw=xd->node; raw != (void *)xd; raw=raw->next_in_ino) {
71                 if (ref_flags(raw) == REF_UNCHECKED) {
72                         rc = 1;
73                         break;
74                 }
75         }
76         spin_unlock(&c->erase_completion_lock);
77         return rc;
78 }
79
80 static void unload_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
81 {
82         /* must be called under down_write(xattr_sem) */
83         D1(dbg_xattr("%s: xid=%u, version=%u\n", __FUNCTION__, xd->xid, xd->version));
84         if (xd->xname) {
85                 c->xdatum_mem_usage -= (xd->name_len + 1 + xd->value_len);
86                 kfree(xd->xname);
87         }
88
89         list_del_init(&xd->xindex);
90         xd->hashkey = 0;
91         xd->xname = NULL;
92         xd->xvalue = NULL;
93 }
94
95 static void reclaim_xattr_datum(struct jffs2_sb_info *c)
96 {
97         /* must be called under down_write(xattr_sem) */
98         struct jffs2_xattr_datum *xd, *_xd;
99         uint32_t target, before;
100         static int index = 0;
101         int count;
102
103         if (c->xdatum_mem_threshold > c->xdatum_mem_usage)
104                 return;
105
106         before = c->xdatum_mem_usage;
107         target = c->xdatum_mem_usage * 4 / 5; /* 20% reduction */
108         for (count = 0; count < XATTRINDEX_HASHSIZE; count++) {
109                 list_for_each_entry_safe(xd, _xd, &c->xattrindex[index], xindex) {
110                         if (xd->flags & JFFS2_XFLAGS_HOT) {
111                                 xd->flags &= ~JFFS2_XFLAGS_HOT;
112                         } else if (!(xd->flags & JFFS2_XFLAGS_BIND)) {
113                                 unload_xattr_datum(c, xd);
114                         }
115                         if (c->xdatum_mem_usage <= target)
116                                 goto out;
117                 }
118                 index = (index+1) % XATTRINDEX_HASHSIZE;
119         }
120  out:
121         JFFS2_NOTICE("xdatum_mem_usage from %u byte to %u byte (%u byte reclaimed)\n",
122                      before, c->xdatum_mem_usage, before - c->xdatum_mem_usage);
123 }
124
125 static int do_verify_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
126 {
127         /* must be called under down_write(xattr_sem) */
128         struct jffs2_eraseblock *jeb;
129         struct jffs2_raw_node_ref *raw;
130         struct jffs2_raw_xattr rx;
131         size_t readlen;
132         uint32_t crc, offset, totlen;
133         int rc;
134
135         spin_lock(&c->erase_completion_lock);
136         offset = ref_offset(xd->node);
137         if (ref_flags(xd->node) == REF_PRISTINE)
138                 goto complete;
139         spin_unlock(&c->erase_completion_lock);
140
141         rc = jffs2_flash_read(c, offset, sizeof(rx), &readlen, (char *)&rx);
142         if (rc || readlen != sizeof(rx)) {
143                 JFFS2_WARNING("jffs2_flash_read()=%d, req=%zu, read=%zu at %#08x\n",
144                               rc, sizeof(rx), readlen, offset);
145                 return rc ? rc : -EIO;
146         }
147         crc = crc32(0, &rx, sizeof(rx) - 4);
148         if (crc != je32_to_cpu(rx.node_crc)) {
149                 JFFS2_ERROR("node CRC failed at %#08x, read=%#08x, calc=%#08x\n",
150                             offset, je32_to_cpu(rx.hdr_crc), crc);
151                 xd->flags |= JFFS2_XFLAGS_INVALID;
152                 return EIO;
153         }
154         totlen = PAD(sizeof(rx) + rx.name_len + 1 + je16_to_cpu(rx.value_len));
155         if (je16_to_cpu(rx.magic) != JFFS2_MAGIC_BITMASK
156             || je16_to_cpu(rx.nodetype) != JFFS2_NODETYPE_XATTR
157             || je32_to_cpu(rx.totlen) != totlen
158             || je32_to_cpu(rx.xid) != xd->xid
159             || je32_to_cpu(rx.version) != xd->version) {
160                 JFFS2_ERROR("inconsistent xdatum at %#08x, magic=%#04x/%#04x, "
161                             "nodetype=%#04x/%#04x, totlen=%u/%u, xid=%u/%u, version=%u/%u\n",
162                             offset, je16_to_cpu(rx.magic), JFFS2_MAGIC_BITMASK,
163                             je16_to_cpu(rx.nodetype), JFFS2_NODETYPE_XATTR,
164                             je32_to_cpu(rx.totlen), totlen,
165                             je32_to_cpu(rx.xid), xd->xid,
166                             je32_to_cpu(rx.version), xd->version);
167                 xd->flags |= JFFS2_XFLAGS_INVALID;
168                 return EIO;
169         }
170         xd->xprefix = rx.xprefix;
171         xd->name_len = rx.name_len;
172         xd->value_len = je16_to_cpu(rx.value_len);
173         xd->data_crc = je32_to_cpu(rx.data_crc);
174
175         spin_lock(&c->erase_completion_lock);
176  complete:
177         for (raw=xd->node; raw != (void *)xd; raw=raw->next_in_ino) {
178                 jeb = &c->blocks[ref_offset(raw) / c->sector_size];
179                 totlen = PAD(ref_totlen(c, jeb, raw));
180                 if (ref_flags(raw) == REF_UNCHECKED) {
181                         c->unchecked_size -= totlen; c->used_size += totlen;
182                         jeb->unchecked_size -= totlen; jeb->used_size += totlen;
183                 }
184                 raw->flash_offset = ref_offset(raw) | ((xd->node==raw) ? REF_PRISTINE : REF_NORMAL);
185         }
186         spin_unlock(&c->erase_completion_lock);
187
188         /* unchecked xdatum is chained with c->xattr_unchecked */
189         list_del_init(&xd->xindex);
190
191         dbg_xattr("success on verfying xdatum (xid=%u, version=%u)\n",
192                   xd->xid, xd->version);
193
194         return 0;
195 }
196
197 static int do_load_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
198 {
199         /* must be called under down_write(xattr_sem) */
200         char *data;
201         size_t readlen;
202         uint32_t crc, length;
203         int i, ret, retry = 0;
204
205         BUG_ON(ref_flags(xd->node) != REF_PRISTINE);
206         BUG_ON(!list_empty(&xd->xindex));
207  retry:
208         length = xd->name_len + 1 + xd->value_len;
209         data = kmalloc(length, GFP_KERNEL);
210         if (!data)
211                 return -ENOMEM;
212
213         ret = jffs2_flash_read(c, ref_offset(xd->node)+sizeof(struct jffs2_raw_xattr),
214                                length, &readlen, data);
215
216         if (ret || length!=readlen) {
217                 JFFS2_WARNING("jffs2_flash_read() returned %d, request=%d, readlen=%zu, at %#08x\n",
218                               ret, length, readlen, ref_offset(xd->node));
219                 kfree(data);
220                 return ret ? ret : -EIO;
221         }
222
223         data[xd->name_len] = '\0';
224         crc = crc32(0, data, length);
225         if (crc != xd->data_crc) {
226                 JFFS2_WARNING("node CRC failed (JFFS2_NODETYPE_XREF)"
227                               " at %#08x, read: 0x%08x calculated: 0x%08x\n",
228                               ref_offset(xd->node), xd->data_crc, crc);
229                 kfree(data);
230                 xd->flags |= JFFS2_XFLAGS_INVALID;
231                 return EIO;
232         }
233
234         xd->flags |= JFFS2_XFLAGS_HOT;
235         xd->xname = data;
236         xd->xvalue = data + xd->name_len+1;
237
238         c->xdatum_mem_usage += length;
239
240         xd->hashkey = xattr_datum_hashkey(xd->xprefix, xd->xname, xd->xvalue, xd->value_len);
241         i = xd->hashkey % XATTRINDEX_HASHSIZE;
242         list_add(&xd->xindex, &c->xattrindex[i]);
243         if (!retry) {
244                 retry = 1;
245                 reclaim_xattr_datum(c);
246                 if (!xd->xname)
247                         goto retry;
248         }
249
250         dbg_xattr("success on loading xdatum (xid=%u, xprefix=%u, xname='%s')\n",
251                   xd->xid, xd->xprefix, xd->xname);
252
253         return 0;
254 }
255
256 static int load_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
257 {
258         /* must be called under down_write(xattr_sem);
259          * rc < 0 : recoverable error, try again
260          * rc = 0 : success
261          * rc > 0 : Unrecoverable error, this node should be deleted.
262          */
263         int rc = 0;
264
265         BUG_ON(xd->flags & JFFS2_XFLAGS_DEAD);
266         if (xd->xname)
267                 return 0;
268         if (xd->flags & JFFS2_XFLAGS_INVALID)
269                 return EIO;
270         if (unlikely(is_xattr_datum_unchecked(c, xd)))
271                 rc = do_verify_xattr_datum(c, xd);
272         if (!rc)
273                 rc = do_load_xattr_datum(c, xd);
274         return rc;
275 }
276
277 static int save_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
278 {
279         /* must be called under down_write(xattr_sem) */
280         struct jffs2_raw_xattr rx;
281         struct kvec vecs[2];
282         size_t length;
283         int rc, totlen;
284         uint32_t phys_ofs = write_ofs(c);
285
286         BUG_ON(!xd->xname);
287         BUG_ON(xd->flags & (JFFS2_XFLAGS_DEAD|JFFS2_XFLAGS_INVALID));
288
289         vecs[0].iov_base = &rx;
290         vecs[0].iov_len = sizeof(rx);
291         vecs[1].iov_base = xd->xname;
292         vecs[1].iov_len = xd->name_len + 1 + xd->value_len;
293         totlen = vecs[0].iov_len + vecs[1].iov_len;
294
295         /* Setup raw-xattr */
296         memset(&rx, 0, sizeof(rx));
297         rx.magic = cpu_to_je16(JFFS2_MAGIC_BITMASK);
298         rx.nodetype = cpu_to_je16(JFFS2_NODETYPE_XATTR);
299         rx.totlen = cpu_to_je32(PAD(totlen));
300         rx.hdr_crc = cpu_to_je32(crc32(0, &rx, sizeof(struct jffs2_unknown_node) - 4));
301
302         rx.xid = cpu_to_je32(xd->xid);
303         rx.version = cpu_to_je32(++xd->version);
304         rx.xprefix = xd->xprefix;
305         rx.name_len = xd->name_len;
306         rx.value_len = cpu_to_je16(xd->value_len);
307         rx.data_crc = cpu_to_je32(crc32(0, vecs[1].iov_base, vecs[1].iov_len));
308         rx.node_crc = cpu_to_je32(crc32(0, &rx, sizeof(struct jffs2_raw_xattr) - 4));
309
310         rc = jffs2_flash_writev(c, vecs, 2, phys_ofs, &length, 0);
311         if (rc || totlen != length) {
312                 JFFS2_WARNING("jffs2_flash_writev()=%d, req=%u, wrote=%zu, at %#08x\n",
313                               rc, totlen, length, phys_ofs);
314                 rc = rc ? rc : -EIO;
315                 if (length)
316                         jffs2_add_physical_node_ref(c, phys_ofs | REF_OBSOLETE, PAD(totlen), NULL);
317
318                 return rc;
319         }
320         /* success */
321         jffs2_add_physical_node_ref(c, phys_ofs | REF_PRISTINE, PAD(totlen), (void *)xd);
322
323         dbg_xattr("success on saving xdatum (xid=%u, version=%u, xprefix=%u, xname='%s')\n",
324                   xd->xid, xd->version, xd->xprefix, xd->xname);
325
326         return 0;
327 }
328
329 static struct jffs2_xattr_datum *create_xattr_datum(struct jffs2_sb_info *c,
330                                                     int xprefix, const char *xname,
331                                                     const char *xvalue, int xsize)
332 {
333         /* must be called under down_write(xattr_sem) */
334         struct jffs2_xattr_datum *xd;
335         uint32_t hashkey, name_len;
336         char *data;
337         int i, rc;
338
339         /* Search xattr_datum has same xname/xvalue by index */
340         hashkey = xattr_datum_hashkey(xprefix, xname, xvalue, xsize);
341         i = hashkey % XATTRINDEX_HASHSIZE;
342         list_for_each_entry(xd, &c->xattrindex[i], xindex) {
343                 if (xd->hashkey==hashkey
344                     && xd->xprefix==xprefix
345                     && xd->value_len==xsize
346                     && !strcmp(xd->xname, xname)
347                     && !memcmp(xd->xvalue, xvalue, xsize)) {
348                         xd->refcnt++;
349                         return xd;
350                 }
351         }
352
353         /* Not found, Create NEW XATTR-Cache */
354         name_len = strlen(xname);
355
356         xd = jffs2_alloc_xattr_datum();
357         if (!xd)
358                 return ERR_PTR(-ENOMEM);
359
360         data = kmalloc(name_len + 1 + xsize, GFP_KERNEL);
361         if (!data) {
362                 jffs2_free_xattr_datum(xd);
363                 return ERR_PTR(-ENOMEM);
364         }
365         strcpy(data, xname);
366         memcpy(data + name_len + 1, xvalue, xsize);
367
368         xd->refcnt = 1;
369         xd->xid = ++c->highest_xid;
370         xd->flags |= JFFS2_XFLAGS_HOT;
371         xd->xprefix = xprefix;
372
373         xd->hashkey = hashkey;
374         xd->xname = data;
375         xd->xvalue = data + name_len + 1;
376         xd->name_len = name_len;
377         xd->value_len = xsize;
378         xd->data_crc = crc32(0, data, xd->name_len + 1 + xd->value_len);
379
380         rc = save_xattr_datum(c, xd);
381         if (rc) {
382                 kfree(xd->xname);
383                 jffs2_free_xattr_datum(xd);
384                 return ERR_PTR(rc);
385         }
386
387         /* Insert Hash Index */
388         i = hashkey % XATTRINDEX_HASHSIZE;
389         list_add(&xd->xindex, &c->xattrindex[i]);
390
391         c->xdatum_mem_usage += (xd->name_len + 1 + xd->value_len);
392         reclaim_xattr_datum(c);
393
394         return xd;
395 }
396
397 static void delete_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
398 {
399         /* must be called under down_write(xattr_sem) */
400         BUG_ON(xd->refcnt);
401
402         unload_xattr_datum(c, xd);
403         xd->flags |= JFFS2_XFLAGS_DEAD;
404         spin_lock(&c->erase_completion_lock);
405         if (xd->node == (void *)xd) {
406                 BUG_ON(!(xd->flags & JFFS2_XFLAGS_INVALID));
407                 jffs2_free_xattr_datum(xd);
408         } else {
409                 list_add(&xd->xindex, &c->xattr_dead_list);
410         }
411         spin_unlock(&c->erase_completion_lock);
412         dbg_xattr("xdatum(xid=%u, version=%u) was removed.\n", xd->xid, xd->version);
413 }
414
415 /* -------- xref related functions ------------------
416  * verify_xattr_ref(c, ref)
417  *   is used to load xref information from medium. Because summary data does not
418  *   contain xid/ino, it's necessary to verify once while mounting process.
419  * save_xattr_ref(c, ref)
420  *   is used to write xref to medium. If delete marker is marked, it write
421  *   a delete marker of xref into medium.
422  * create_xattr_ref(c, ic, xd)
423  *   is used to create a new xref and write to medium.
424  * delete_xattr_ref(c, ref)
425  *   is used to delete jffs2_xattr_ref. It marks xref XREF_DELETE_MARKER,
426  *   and allows GC to reclaim those physical nodes.
427  * jffs2_xattr_delete_inode(c, ic)
428  *   is called to remove xrefs related to obsolete inode when inode is unlinked.
429  * jffs2_xattr_free_inode(c, ic)
430  *   is called to release xattr related objects when unmounting. 
431  * check_xattr_ref_inode(c, ic)
432  *   is used to confirm inode does not have duplicate xattr name/value pair.
433  * -------------------------------------------------- */
434 static int verify_xattr_ref(struct jffs2_sb_info *c, struct jffs2_xattr_ref *ref)
435 {
436         struct jffs2_eraseblock *jeb;
437         struct jffs2_raw_node_ref *raw;
438         struct jffs2_raw_xref rr;
439         size_t readlen;
440         uint32_t crc, offset, totlen;
441         int rc;
442
443         spin_lock(&c->erase_completion_lock);
444         if (ref_flags(ref->node) != REF_UNCHECKED)
445                 goto complete;
446         offset = ref_offset(ref->node);
447         spin_unlock(&c->erase_completion_lock);
448
449         rc = jffs2_flash_read(c, offset, sizeof(rr), &readlen, (char *)&rr);
450         if (rc || sizeof(rr) != readlen) {
451                 JFFS2_WARNING("jffs2_flash_read()=%d, req=%zu, read=%zu, at %#08x\n",
452                               rc, sizeof(rr), readlen, offset);
453                 return rc ? rc : -EIO;
454         }
455         /* obsolete node */
456         crc = crc32(0, &rr, sizeof(rr) - 4);
457         if (crc != je32_to_cpu(rr.node_crc)) {
458                 JFFS2_ERROR("node CRC failed at %#08x, read=%#08x, calc=%#08x\n",
459                             offset, je32_to_cpu(rr.node_crc), crc);
460                 return EIO;
461         }
462         if (je16_to_cpu(rr.magic) != JFFS2_MAGIC_BITMASK
463             || je16_to_cpu(rr.nodetype) != JFFS2_NODETYPE_XREF
464             || je32_to_cpu(rr.totlen) != PAD(sizeof(rr))) {
465                 JFFS2_ERROR("inconsistent xref at %#08x, magic=%#04x/%#04x, "
466                             "nodetype=%#04x/%#04x, totlen=%u/%zu\n",
467                             offset, je16_to_cpu(rr.magic), JFFS2_MAGIC_BITMASK,
468                             je16_to_cpu(rr.nodetype), JFFS2_NODETYPE_XREF,
469                             je32_to_cpu(rr.totlen), PAD(sizeof(rr)));
470                 return EIO;
471         }
472         ref->ino = je32_to_cpu(rr.ino);
473         ref->xid = je32_to_cpu(rr.xid);
474         ref->xseqno = je32_to_cpu(rr.xseqno);
475         if (ref->xseqno > c->highest_xseqno)
476                 c->highest_xseqno = (ref->xseqno & ~XREF_DELETE_MARKER);
477
478         spin_lock(&c->erase_completion_lock);
479  complete:
480         for (raw=ref->node; raw != (void *)ref; raw=raw->next_in_ino) {
481                 jeb = &c->blocks[ref_offset(raw) / c->sector_size];
482                 totlen = PAD(ref_totlen(c, jeb, raw));
483                 if (ref_flags(raw) == REF_UNCHECKED) {
484                         c->unchecked_size -= totlen; c->used_size += totlen;
485                         jeb->unchecked_size -= totlen; jeb->used_size += totlen;
486                 }
487                 raw->flash_offset = ref_offset(raw) | ((ref->node==raw) ? REF_PRISTINE : REF_NORMAL);
488         }
489         spin_unlock(&c->erase_completion_lock);
490
491         dbg_xattr("success on verifying xref (ino=%u, xid=%u) at %#08x\n",
492                   ref->ino, ref->xid, ref_offset(ref->node));
493         return 0;
494 }
495
496 static int save_xattr_ref(struct jffs2_sb_info *c, struct jffs2_xattr_ref *ref)
497 {
498         /* must be called under down_write(xattr_sem) */
499         struct jffs2_raw_xref rr;
500         size_t length;
501         uint32_t xseqno, phys_ofs = write_ofs(c);
502         int ret;
503
504         rr.magic = cpu_to_je16(JFFS2_MAGIC_BITMASK);
505         rr.nodetype = cpu_to_je16(JFFS2_NODETYPE_XREF);
506         rr.totlen = cpu_to_je32(PAD(sizeof(rr)));
507         rr.hdr_crc = cpu_to_je32(crc32(0, &rr, sizeof(struct jffs2_unknown_node) - 4));
508
509         xseqno = (c->highest_xseqno += 2);
510         if (is_xattr_ref_dead(ref)) {
511                 xseqno |= XREF_DELETE_MARKER;
512                 rr.ino = cpu_to_je32(ref->ino);
513                 rr.xid = cpu_to_je32(ref->xid);
514         } else {
515                 rr.ino = cpu_to_je32(ref->ic->ino);
516                 rr.xid = cpu_to_je32(ref->xd->xid);
517         }
518         rr.xseqno = cpu_to_je32(xseqno);
519         rr.node_crc = cpu_to_je32(crc32(0, &rr, sizeof(rr) - 4));
520
521         ret = jffs2_flash_write(c, phys_ofs, sizeof(rr), &length, (char *)&rr);
522         if (ret || sizeof(rr) != length) {
523                 JFFS2_WARNING("jffs2_flash_write() returned %d, request=%zu, retlen=%zu, at %#08x\n",
524                               ret, sizeof(rr), length, phys_ofs);
525                 ret = ret ? ret : -EIO;
526                 if (length)
527                         jffs2_add_physical_node_ref(c, phys_ofs | REF_OBSOLETE, PAD(sizeof(rr)), NULL);
528
529                 return ret;
530         }
531         /* success */
532         ref->xseqno = xseqno;
533         jffs2_add_physical_node_ref(c, phys_ofs | REF_PRISTINE, PAD(sizeof(rr)), (void *)ref);
534
535         dbg_xattr("success on saving xref (ino=%u, xid=%u)\n", ref->ic->ino, ref->xd->xid);
536
537         return 0;
538 }
539
540 static struct jffs2_xattr_ref *create_xattr_ref(struct jffs2_sb_info *c, struct jffs2_inode_cache *ic,
541                                                 struct jffs2_xattr_datum *xd)
542 {
543         /* must be called under down_write(xattr_sem) */
544         struct jffs2_xattr_ref *ref;
545         int ret;
546
547         ref = jffs2_alloc_xattr_ref();
548         if (!ref)
549                 return ERR_PTR(-ENOMEM);
550         ref->ic = ic;
551         ref->xd = xd;
552
553         ret = save_xattr_ref(c, ref);
554         if (ret) {
555                 jffs2_free_xattr_ref(ref);
556                 return ERR_PTR(ret);
557         }
558
559         /* Chain to inode */
560         ref->next = ic->xref;
561         ic->xref = ref;
562
563         return ref; /* success */
564 }
565
566 static void delete_xattr_ref(struct jffs2_sb_info *c, struct jffs2_xattr_ref *ref)
567 {
568         /* must be called under down_write(xattr_sem) */
569         struct jffs2_xattr_datum *xd;
570
571         xd = ref->xd;
572         ref->xseqno |= XREF_DELETE_MARKER;
573         ref->ino = ref->ic->ino;
574         ref->xid = ref->xd->xid;
575         spin_lock(&c->erase_completion_lock);
576         ref->next = c->xref_dead_list;
577         c->xref_dead_list = ref;
578         spin_unlock(&c->erase_completion_lock);
579
580         dbg_xattr("xref(ino=%u, xid=%u, xseqno=%u) was removed.\n",
581                   ref->ino, ref->xid, ref->xseqno);
582
583         if (!--xd->refcnt)
584                 delete_xattr_datum(c, xd);
585 }
586
587 void jffs2_xattr_delete_inode(struct jffs2_sb_info *c, struct jffs2_inode_cache *ic)
588 {
589         /* It's called from jffs2_clear_inode() on inode removing.
590            When an inode with XATTR is removed, those XATTRs must be removed. */
591         struct jffs2_xattr_ref *ref, *_ref;
592
593         if (!ic || ic->nlink > 0)
594                 return;
595
596         down_write(&c->xattr_sem);
597         for (ref = ic->xref; ref; ref = _ref) {
598                 _ref = ref->next;
599                 delete_xattr_ref(c, ref);
600         }
601         ic->xref = NULL;
602         up_write(&c->xattr_sem);
603 }
604
605 void jffs2_xattr_free_inode(struct jffs2_sb_info *c, struct jffs2_inode_cache *ic)
606 {
607         /* It's called from jffs2_free_ino_caches() until unmounting FS. */
608         struct jffs2_xattr_datum *xd;
609         struct jffs2_xattr_ref *ref, *_ref;
610
611         down_write(&c->xattr_sem);
612         for (ref = ic->xref; ref; ref = _ref) {
613                 _ref = ref->next;
614                 xd = ref->xd;
615                 xd->refcnt--;
616                 if (!xd->refcnt) {
617                         unload_xattr_datum(c, xd);
618                         jffs2_free_xattr_datum(xd);
619                 }
620                 jffs2_free_xattr_ref(ref);
621         }
622         ic->xref = NULL;
623         up_write(&c->xattr_sem);
624 }
625
626 static int check_xattr_ref_inode(struct jffs2_sb_info *c, struct jffs2_inode_cache *ic)
627 {
628         /* success of check_xattr_ref_inode() means taht inode (ic) dose not have
629          * duplicate name/value pairs. If duplicate name/value pair would be found,
630          * one will be removed.
631          */
632         struct jffs2_xattr_ref *ref, *cmp, **pref, **pcmp;
633         int rc = 0;
634
635         if (likely(ic->flags & INO_FLAGS_XATTR_CHECKED))
636                 return 0;
637         down_write(&c->xattr_sem);
638  retry:
639         rc = 0;
640         for (ref=ic->xref, pref=&ic->xref; ref; pref=&ref->next, ref=ref->next) {
641                 if (!ref->xd->xname) {
642                         rc = load_xattr_datum(c, ref->xd);
643                         if (unlikely(rc > 0)) {
644                                 *pref = ref->next;
645                                 delete_xattr_ref(c, ref);
646                                 goto retry;
647                         } else if (unlikely(rc < 0))
648                                 goto out;
649                 }
650                 for (cmp=ref->next, pcmp=&ref->next; cmp; pcmp=&cmp->next, cmp=cmp->next) {
651                         if (!cmp->xd->xname) {
652                                 ref->xd->flags |= JFFS2_XFLAGS_BIND;
653                                 rc = load_xattr_datum(c, cmp->xd);
654                                 ref->xd->flags &= ~JFFS2_XFLAGS_BIND;
655                                 if (unlikely(rc > 0)) {
656                                         *pcmp = cmp->next;
657                                         delete_xattr_ref(c, cmp);
658                                         goto retry;
659                                 } else if (unlikely(rc < 0))
660                                         goto out;
661                         }
662                         if (ref->xd->xprefix == cmp->xd->xprefix
663                             && !strcmp(ref->xd->xname, cmp->xd->xname)) {
664                                 if (ref->xseqno > cmp->xseqno) {
665                                         *pcmp = cmp->next;
666                                         delete_xattr_ref(c, cmp);
667                                 } else {
668                                         *pref = ref->next;
669                                         delete_xattr_ref(c, ref);
670                                 }
671                                 goto retry;
672                         }
673                 }
674         }
675         ic->flags |= INO_FLAGS_XATTR_CHECKED;
676  out:
677         up_write(&c->xattr_sem);
678
679         return rc;
680 }
681
682 /* -------- xattr subsystem functions ---------------
683  * jffs2_init_xattr_subsystem(c)
684  *   is used to initialize semaphore and list_head, and some variables.
685  * jffs2_find_xattr_datum(c, xid)
686  *   is used to lookup xdatum while scanning process.
687  * jffs2_clear_xattr_subsystem(c)
688  *   is used to release any xattr related objects.
689  * jffs2_build_xattr_subsystem(c)
690  *   is used to associate xdatum and xref while super block building process.
691  * jffs2_setup_xattr_datum(c, xid, version)
692  *   is used to insert xdatum while scanning process.
693  * -------------------------------------------------- */
694 void jffs2_init_xattr_subsystem(struct jffs2_sb_info *c)
695 {
696         int i;
697
698         for (i=0; i < XATTRINDEX_HASHSIZE; i++)
699                 INIT_LIST_HEAD(&c->xattrindex[i]);
700         INIT_LIST_HEAD(&c->xattr_unchecked);
701         INIT_LIST_HEAD(&c->xattr_dead_list);
702         c->xref_dead_list = NULL;
703         c->xref_temp = NULL;
704
705         init_rwsem(&c->xattr_sem);
706         c->highest_xid = 0;
707         c->highest_xseqno = 0;
708         c->xdatum_mem_usage = 0;
709         c->xdatum_mem_threshold = 32 * 1024;    /* Default 32KB */
710 }
711
712 static struct jffs2_xattr_datum *jffs2_find_xattr_datum(struct jffs2_sb_info *c, uint32_t xid)
713 {
714         struct jffs2_xattr_datum *xd;
715         int i = xid % XATTRINDEX_HASHSIZE;
716
717         /* It's only used in scanning/building process. */
718         BUG_ON(!(c->flags & (JFFS2_SB_FLAG_SCANNING|JFFS2_SB_FLAG_BUILDING)));
719
720         list_for_each_entry(xd, &c->xattrindex[i], xindex) {
721                 if (xd->xid==xid)
722                         return xd;
723         }
724         return NULL;
725 }
726
727 void jffs2_clear_xattr_subsystem(struct jffs2_sb_info *c)
728 {
729         struct jffs2_xattr_datum *xd, *_xd;
730         struct jffs2_xattr_ref *ref, *_ref;
731         int i;
732
733         for (ref=c->xref_temp; ref; ref = _ref) {
734                 _ref = ref->next;
735                 jffs2_free_xattr_ref(ref);
736         }
737
738         for (ref=c->xref_dead_list; ref; ref = _ref) {
739                 _ref = ref->next;
740                 jffs2_free_xattr_ref(ref);
741         }
742
743         for (i=0; i < XATTRINDEX_HASHSIZE; i++) {
744                 list_for_each_entry_safe(xd, _xd, &c->xattrindex[i], xindex) {
745                         list_del(&xd->xindex);
746                         if (xd->xname)
747                                 kfree(xd->xname);
748                         jffs2_free_xattr_datum(xd);
749                 }
750         }
751
752         list_for_each_entry_safe(xd, _xd, &c->xattr_dead_list, xindex) {
753                 list_del(&xd->xindex);
754                 jffs2_free_xattr_datum(xd);
755         }
756 }
757
758 #define XREF_TMPHASH_SIZE       (128)
759 void jffs2_build_xattr_subsystem(struct jffs2_sb_info *c)
760 {
761         struct jffs2_xattr_ref *ref, *_ref;
762         struct jffs2_xattr_ref *xref_tmphash[XREF_TMPHASH_SIZE];
763         struct jffs2_xattr_datum *xd, *_xd;
764         struct jffs2_inode_cache *ic;
765         struct jffs2_raw_node_ref *raw;
766         int i, xdatum_count = 0, xdatum_unchecked_count = 0, xref_count = 0;
767         int xdatum_orphan_count = 0, xref_orphan_count = 0, xref_dead_count = 0;
768
769         BUG_ON(!(c->flags & JFFS2_SB_FLAG_BUILDING));
770
771         /* Phase.1 : Merge same xref */
772         for (i=0; i < XREF_TMPHASH_SIZE; i++)
773                 xref_tmphash[i] = NULL;
774         for (ref=c->xref_temp; ref; ref=_ref) {
775                 struct jffs2_xattr_ref *tmp;
776
777                 _ref = ref->next;
778                 if (ref_flags(ref->node) != REF_PRISTINE) {
779                         if (verify_xattr_ref(c, ref)) {
780                                 BUG_ON(ref->node->next_in_ino != (void *)ref);
781                                 ref->node->next_in_ino = NULL;
782                                 jffs2_mark_node_obsolete(c, ref->node);
783                                 jffs2_free_xattr_ref(ref);
784                                 continue;
785                         }
786                 }
787
788                 i = (ref->ino ^ ref->xid) % XREF_TMPHASH_SIZE;
789                 for (tmp=xref_tmphash[i]; tmp; tmp=tmp->next) {
790                         if (tmp->ino == ref->ino && tmp->xid == ref->xid)
791                                 break;
792                 }
793                 if (tmp) {
794                         raw = ref->node;
795                         if (ref->xseqno > tmp->xseqno) {
796                                 tmp->xseqno = ref->xseqno;
797                                 raw->next_in_ino = tmp->node;
798                                 tmp->node = raw;
799                         } else {
800                                 raw->next_in_ino = tmp->node->next_in_ino;
801                                 tmp->node->next_in_ino = raw;
802                         }
803                         jffs2_free_xattr_ref(ref);
804                         continue;
805                 } else {
806                         ref->next = xref_tmphash[i];
807                         xref_tmphash[i] = ref;
808                 }
809         }
810         c->xref_temp = NULL;
811
812         /* Phase.2 : Bind xref with inode_cache and xattr_datum */
813         for (i=0; i < XREF_TMPHASH_SIZE; i++) {
814                 for (ref=xref_tmphash[i]; ref; ref=_ref) {
815                         xref_count++;
816                         _ref = ref->next;
817                         if (is_xattr_ref_dead(ref)) {
818                                 ref->next = c->xref_dead_list;
819                                 c->xref_dead_list = ref;
820                                 xref_dead_count++;
821                                 continue;
822                         }
823                         /* At this point, ref->xid and ref->ino contain XID and inode number.
824                            ref->xd and ref->ic are not valid yet. */
825                         xd = jffs2_find_xattr_datum(c, ref->xid);
826                         ic = jffs2_get_ino_cache(c, ref->ino);
827                         if (!xd || !ic) {
828                                 dbg_xattr("xref(ino=%u, xid=%u, xseqno=%u) is orphan.\n",
829                                           ref->ino, ref->xid, ref->xseqno);
830                                 ref->xseqno |= XREF_DELETE_MARKER;
831                                 ref->next = c->xref_dead_list;
832                                 c->xref_dead_list = ref;
833                                 xref_orphan_count++;
834                                 continue;
835                         }
836                         ref->xd = xd;
837                         ref->ic = ic;
838                         xd->refcnt++;
839                         ref->next = ic->xref;
840                         ic->xref = ref;
841                 }
842         }
843
844         /* Phase.3 : Link unchecked xdatum to xattr_unchecked list */
845         for (i=0; i < XATTRINDEX_HASHSIZE; i++) {
846                 list_for_each_entry_safe(xd, _xd, &c->xattrindex[i], xindex) {
847                         xdatum_count++;
848                         list_del_init(&xd->xindex);
849                         if (!xd->refcnt) {
850                                 dbg_xattr("xdatum(xid=%u, version=%u) is orphan.\n",
851                                           xd->xid, xd->version);
852                                 xd->flags |= JFFS2_XFLAGS_DEAD;
853                                 list_add(&xd->xindex, &c->xattr_unchecked);
854                                 xdatum_orphan_count++;
855                                 continue;
856                         }
857                         if (is_xattr_datum_unchecked(c, xd)) {
858                                 dbg_xattr("unchecked xdatum(xid=%u, version=%u)\n",
859                                           xd->xid, xd->version);
860                                 list_add(&xd->xindex, &c->xattr_unchecked);
861                                 xdatum_unchecked_count++;
862                         }
863                 }
864         }
865         /* build complete */
866         JFFS2_NOTICE("complete building xattr subsystem, %u of xdatum"
867                      " (%u unchecked, %u orphan) and "
868                      "%u of xref (%u dead, %u orphan) found.\n",
869                      xdatum_count, xdatum_unchecked_count, xdatum_orphan_count,
870                      xref_count, xref_dead_count, xref_orphan_count);
871 }
872
873 struct jffs2_xattr_datum *jffs2_setup_xattr_datum(struct jffs2_sb_info *c,
874                                                   uint32_t xid, uint32_t version)
875 {
876         struct jffs2_xattr_datum *xd;
877
878         xd = jffs2_find_xattr_datum(c, xid);
879         if (!xd) {
880                 xd = jffs2_alloc_xattr_datum();
881                 if (!xd)
882                         return ERR_PTR(-ENOMEM);
883                 xd->xid = xid;
884                 xd->version = version;
885                 if (xd->xid > c->highest_xid)
886                         c->highest_xid = xd->xid;
887                 list_add_tail(&xd->xindex, &c->xattrindex[xid % XATTRINDEX_HASHSIZE]);
888         }
889         return xd;
890 }
891
892 /* -------- xattr subsystem functions ---------------
893  * xprefix_to_handler(xprefix)
894  *   is used to translate xprefix into xattr_handler.
895  * jffs2_listxattr(dentry, buffer, size)
896  *   is an implementation of listxattr handler on jffs2.
897  * do_jffs2_getxattr(inode, xprefix, xname, buffer, size)
898  *   is an implementation of getxattr handler on jffs2.
899  * do_jffs2_setxattr(inode, xprefix, xname, buffer, size, flags)
900  *   is an implementation of setxattr handler on jffs2.
901  * -------------------------------------------------- */
902 struct xattr_handler *jffs2_xattr_handlers[] = {
903         &jffs2_user_xattr_handler,
904 #ifdef CONFIG_JFFS2_FS_SECURITY
905         &jffs2_security_xattr_handler,
906 #endif
907 #ifdef CONFIG_JFFS2_FS_POSIX_ACL
908         &jffs2_acl_access_xattr_handler,
909         &jffs2_acl_default_xattr_handler,
910 #endif
911         &jffs2_trusted_xattr_handler,
912         NULL
913 };
914
915 static struct xattr_handler *xprefix_to_handler(int xprefix) {
916         struct xattr_handler *ret;
917
918         switch (xprefix) {
919         case JFFS2_XPREFIX_USER:
920                 ret = &jffs2_user_xattr_handler;
921                 break;
922 #ifdef CONFIG_JFFS2_FS_SECURITY
923         case JFFS2_XPREFIX_SECURITY:
924                 ret = &jffs2_security_xattr_handler;
925                 break;
926 #endif
927 #ifdef CONFIG_JFFS2_FS_POSIX_ACL
928         case JFFS2_XPREFIX_ACL_ACCESS:
929                 ret = &jffs2_acl_access_xattr_handler;
930                 break;
931         case JFFS2_XPREFIX_ACL_DEFAULT:
932                 ret = &jffs2_acl_default_xattr_handler;
933                 break;
934 #endif
935         case JFFS2_XPREFIX_TRUSTED:
936                 ret = &jffs2_trusted_xattr_handler;
937                 break;
938         default:
939                 ret = NULL;
940                 break;
941         }
942         return ret;
943 }
944
945 ssize_t jffs2_listxattr(struct dentry *dentry, char *buffer, size_t size)
946 {
947         struct inode *inode = dentry->d_inode;
948         struct jffs2_inode_info *f = JFFS2_INODE_INFO(inode);
949         struct jffs2_sb_info *c = JFFS2_SB_INFO(inode->i_sb);
950         struct jffs2_inode_cache *ic = f->inocache;
951         struct jffs2_xattr_ref *ref, **pref;
952         struct jffs2_xattr_datum *xd;
953         struct xattr_handler *xhandle;
954         ssize_t len, rc;
955         int retry = 0;
956
957         rc = check_xattr_ref_inode(c, ic);
958         if (unlikely(rc))
959                 return rc;
960
961         down_read(&c->xattr_sem);
962  retry:
963         len = 0;
964         for (ref=ic->xref, pref=&ic->xref; ref; pref=&ref->next, ref=ref->next) {
965                 BUG_ON(ref->ic != ic);
966                 xd = ref->xd;
967                 if (!xd->xname) {
968                         /* xdatum is unchached */
969                         if (!retry) {
970                                 retry = 1;
971                                 up_read(&c->xattr_sem);
972                                 down_write(&c->xattr_sem);
973                                 goto retry;
974                         } else {
975                                 rc = load_xattr_datum(c, xd);
976                                 if (unlikely(rc > 0)) {
977                                         *pref = ref->next;
978                                         delete_xattr_ref(c, ref);
979                                         goto retry;
980                                 } else if (unlikely(rc < 0))
981                                         goto out;
982                         }
983                 }
984                 xhandle = xprefix_to_handler(xd->xprefix);
985                 if (!xhandle)
986                         continue;
987                 if (buffer) {
988                         rc = xhandle->list(inode, buffer+len, size-len, xd->xname, xd->name_len);
989                 } else {
990                         rc = xhandle->list(inode, NULL, 0, xd->xname, xd->name_len);
991                 }
992                 if (rc < 0)
993                         goto out;
994                 len += rc;
995         }
996         rc = len;
997  out:
998         if (!retry) {
999                 up_read(&c->xattr_sem);
1000         } else {
1001                 up_write(&c->xattr_sem);
1002         }
1003         return rc;
1004 }
1005
1006 int do_jffs2_getxattr(struct inode *inode, int xprefix, const char *xname,
1007                       char *buffer, size_t size)
1008 {
1009         struct jffs2_inode_info *f = JFFS2_INODE_INFO(inode);
1010         struct jffs2_sb_info *c = JFFS2_SB_INFO(inode->i_sb);
1011         struct jffs2_inode_cache *ic = f->inocache;
1012         struct jffs2_xattr_datum *xd;
1013         struct jffs2_xattr_ref *ref, **pref;
1014         int rc, retry = 0;
1015
1016         rc = check_xattr_ref_inode(c, ic);
1017         if (unlikely(rc))
1018                 return rc;
1019
1020         down_read(&c->xattr_sem);
1021  retry:
1022         for (ref=ic->xref, pref=&ic->xref; ref; pref=&ref->next, ref=ref->next) {
1023                 BUG_ON(ref->ic!=ic);
1024
1025                 xd = ref->xd;
1026                 if (xd->xprefix != xprefix)
1027                         continue;
1028                 if (!xd->xname) {
1029                         /* xdatum is unchached */
1030                         if (!retry) {
1031                                 retry = 1;
1032                                 up_read(&c->xattr_sem);
1033                                 down_write(&c->xattr_sem);
1034                                 goto retry;
1035                         } else {
1036                                 rc = load_xattr_datum(c, xd);
1037                                 if (unlikely(rc > 0)) {
1038                                         *pref = ref->next;
1039                                         delete_xattr_ref(c, ref);
1040                                         goto retry;
1041                                 } else if (unlikely(rc < 0)) {
1042                                         goto out;
1043                                 }
1044                         }
1045                 }
1046                 if (!strcmp(xname, xd->xname)) {
1047                         rc = xd->value_len;
1048                         if (buffer) {
1049                                 if (size < rc) {
1050                                         rc = -ERANGE;
1051                                 } else {
1052                                         memcpy(buffer, xd->xvalue, rc);
1053                                 }
1054                         }
1055                         goto out;
1056                 }
1057         }
1058         rc = -ENODATA;
1059  out:
1060         if (!retry) {
1061                 up_read(&c->xattr_sem);
1062         } else {
1063                 up_write(&c->xattr_sem);
1064         }
1065         return rc;
1066 }
1067
1068 int do_jffs2_setxattr(struct inode *inode, int xprefix, const char *xname,
1069                       const char *buffer, size_t size, int flags)
1070 {
1071         struct jffs2_inode_info *f = JFFS2_INODE_INFO(inode);
1072         struct jffs2_sb_info *c = JFFS2_SB_INFO(inode->i_sb);
1073         struct jffs2_inode_cache *ic = f->inocache;
1074         struct jffs2_xattr_datum *xd;
1075         struct jffs2_xattr_ref *ref, *newref, **pref;
1076         uint32_t length, request;
1077         int rc;
1078
1079         rc = check_xattr_ref_inode(c, ic);
1080         if (unlikely(rc))
1081                 return rc;
1082
1083         request = PAD(sizeof(struct jffs2_raw_xattr) + strlen(xname) + 1 + size);
1084         rc = jffs2_reserve_space(c, request, &length,
1085                                  ALLOC_NORMAL, JFFS2_SUMMARY_XATTR_SIZE);
1086         if (rc) {
1087                 JFFS2_WARNING("jffs2_reserve_space()=%d, request=%u\n", rc, request);
1088                 return rc;
1089         }
1090
1091         /* Find existing xattr */
1092         down_write(&c->xattr_sem);
1093  retry:
1094         for (ref=ic->xref, pref=&ic->xref; ref; pref=&ref->next, ref=ref->next) {
1095                 xd = ref->xd;
1096                 if (xd->xprefix != xprefix)
1097                         continue;
1098                 if (!xd->xname) {
1099                         rc = load_xattr_datum(c, xd);
1100                         if (unlikely(rc > 0)) {
1101                                 *pref = ref->next;
1102                                 delete_xattr_ref(c, ref);
1103                                 goto retry;
1104                         } else if (unlikely(rc < 0))
1105                                 goto out;
1106                 }
1107                 if (!strcmp(xd->xname, xname)) {
1108                         if (flags & XATTR_CREATE) {
1109                                 rc = -EEXIST;
1110                                 goto out;
1111                         }
1112                         if (!buffer) {
1113                                 ref->ino = ic->ino;
1114                                 ref->xid = xd->xid;
1115                                 ref->xseqno |= XREF_DELETE_MARKER;
1116                                 rc = save_xattr_ref(c, ref);
1117                                 if (!rc) {
1118                                         *pref = ref->next;
1119                                         spin_lock(&c->erase_completion_lock);
1120                                         ref->next = c->xref_dead_list;
1121                                         c->xref_dead_list = ref;
1122                                         spin_unlock(&c->erase_completion_lock);
1123                                         if (!--xd->refcnt)
1124                                                 delete_xattr_datum(c, xd);
1125                                 } else {
1126                                         ref->ic = ic;
1127                                         ref->xd = xd;
1128                                         ref->xseqno &= ~XREF_DELETE_MARKER;
1129                                 }
1130                                 goto out;
1131                         }
1132                         goto found;
1133                 }
1134         }
1135         /* not found */
1136         if (flags & XATTR_REPLACE) {
1137                 rc = -ENODATA;
1138                 goto out;
1139         }
1140         if (!buffer) {
1141                 rc = -ENODATA;
1142                 goto out;
1143         }
1144  found:
1145         xd = create_xattr_datum(c, xprefix, xname, buffer, size);
1146         if (IS_ERR(xd)) {
1147                 rc = PTR_ERR(xd);
1148                 goto out;
1149         }
1150         up_write(&c->xattr_sem);
1151         jffs2_complete_reservation(c);
1152
1153         /* create xattr_ref */
1154         request = PAD(sizeof(struct jffs2_raw_xref));
1155         rc = jffs2_reserve_space(c, request, &length,
1156                                  ALLOC_NORMAL, JFFS2_SUMMARY_XREF_SIZE);
1157         down_write(&c->xattr_sem);
1158         if (rc) {
1159                 JFFS2_WARNING("jffs2_reserve_space()=%d, request=%u\n", rc, request);
1160                 xd->refcnt--;
1161                 if (!xd->refcnt)
1162                         delete_xattr_datum(c, xd);
1163                 up_write(&c->xattr_sem);
1164                 return rc;
1165         }
1166         if (ref)
1167                 *pref = ref->next;
1168         newref = create_xattr_ref(c, ic, xd);
1169         if (IS_ERR(newref)) {
1170                 if (ref) {
1171                         ref->next = ic->xref;
1172                         ic->xref = ref;
1173                 }
1174                 rc = PTR_ERR(newref);
1175                 xd->refcnt--;
1176                 if (!xd->refcnt)
1177                         delete_xattr_datum(c, xd);
1178         } else if (ref) {
1179                 delete_xattr_ref(c, ref);
1180         }
1181  out:
1182         up_write(&c->xattr_sem);
1183         jffs2_complete_reservation(c);
1184         return rc;
1185 }
1186
1187 /* -------- garbage collector functions -------------
1188  * jffs2_garbage_collect_xattr_datum(c, xd, raw)
1189  *   is used to move xdatum into new node.
1190  * jffs2_garbage_collect_xattr_ref(c, ref, raw)
1191  *   is used to move xref into new node.
1192  * jffs2_verify_xattr(c)
1193  *   is used to call do_verify_xattr_datum() before garbage collecting.
1194  * jffs2_release_xattr_datum(c, xd)
1195  *   is used to release an in-memory object of xdatum.
1196  * jffs2_release_xattr_ref(c, ref)
1197  *   is used to release an in-memory object of xref.
1198  * -------------------------------------------------- */
1199 int jffs2_garbage_collect_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd,
1200                                       struct jffs2_raw_node_ref *raw)
1201 {
1202         uint32_t totlen, length, old_ofs;
1203         int rc = 0;
1204
1205         down_write(&c->xattr_sem);
1206         if (xd->node != raw)
1207                 goto out;
1208         if (xd->flags & (JFFS2_XFLAGS_DEAD|JFFS2_XFLAGS_INVALID))
1209                 goto out;
1210
1211         rc = load_xattr_datum(c, xd);
1212         if (unlikely(rc)) {
1213                 rc = (rc > 0) ? 0 : rc;
1214                 goto out;
1215         }
1216         old_ofs = ref_offset(xd->node);
1217         totlen = PAD(sizeof(struct jffs2_raw_xattr)
1218                         + xd->name_len + 1 + xd->value_len);
1219         rc = jffs2_reserve_space_gc(c, totlen, &length, JFFS2_SUMMARY_XATTR_SIZE);
1220         if (rc) {
1221                 JFFS2_WARNING("jffs2_reserve_space_gc()=%d, request=%u\n", rc, totlen);
1222                 rc = rc ? rc : -EBADFD;
1223                 goto out;
1224         }
1225         rc = save_xattr_datum(c, xd);
1226         if (!rc)
1227                 dbg_xattr("xdatum (xid=%u, version=%u) GC'ed from %#08x to %08x\n",
1228                           xd->xid, xd->version, old_ofs, ref_offset(xd->node));
1229  out:
1230         if (!rc)
1231                 jffs2_mark_node_obsolete(c, raw);
1232         up_write(&c->xattr_sem);
1233         return rc;
1234 }
1235
1236 int jffs2_garbage_collect_xattr_ref(struct jffs2_sb_info *c, struct jffs2_xattr_ref *ref,
1237                                     struct jffs2_raw_node_ref *raw)
1238 {
1239         uint32_t totlen, length, old_ofs;
1240         int rc = 0;
1241
1242         down_write(&c->xattr_sem);
1243         BUG_ON(!ref->node);
1244
1245         if (ref->node != raw)
1246                 goto out;
1247         if (is_xattr_ref_dead(ref) && (raw->next_in_ino == (void *)ref))
1248                 goto out;
1249
1250         old_ofs = ref_offset(ref->node);
1251         totlen = ref_totlen(c, c->gcblock, ref->node);
1252
1253         rc = jffs2_reserve_space_gc(c, totlen, &length, JFFS2_SUMMARY_XREF_SIZE);
1254         if (rc) {
1255                 JFFS2_WARNING("%s: jffs2_reserve_space_gc() = %d, request = %u\n",
1256                               __FUNCTION__, rc, totlen);
1257                 rc = rc ? rc : -EBADFD;
1258                 goto out;
1259         }
1260         rc = save_xattr_ref(c, ref);
1261         if (!rc)
1262                 dbg_xattr("xref (ino=%u, xid=%u) GC'ed from %#08x to %08x\n",
1263                           ref->ic->ino, ref->xd->xid, old_ofs, ref_offset(ref->node));
1264  out:
1265         if (!rc)
1266                 jffs2_mark_node_obsolete(c, raw);
1267         up_write(&c->xattr_sem);
1268         return rc;
1269 }
1270
1271 int jffs2_verify_xattr(struct jffs2_sb_info *c)
1272 {
1273         struct jffs2_xattr_datum *xd, *_xd;
1274         struct jffs2_eraseblock *jeb;
1275         struct jffs2_raw_node_ref *raw;
1276         uint32_t totlen;
1277         int rc;
1278
1279         down_write(&c->xattr_sem);
1280         list_for_each_entry_safe(xd, _xd, &c->xattr_unchecked, xindex) {
1281                 rc = do_verify_xattr_datum(c, xd);
1282                 if (rc < 0)
1283                         continue;
1284                 list_del_init(&xd->xindex);
1285                 spin_lock(&c->erase_completion_lock);
1286                 for (raw=xd->node; raw != (void *)xd; raw=raw->next_in_ino) {
1287                         if (ref_flags(raw) != REF_UNCHECKED)
1288                                 continue;
1289                         jeb = &c->blocks[ref_offset(raw) / c->sector_size];
1290                         totlen = PAD(ref_totlen(c, jeb, raw));
1291                         c->unchecked_size -= totlen; c->used_size += totlen;
1292                         jeb->unchecked_size -= totlen; jeb->used_size += totlen;
1293                         raw->flash_offset = ref_offset(raw)
1294                                 | ((xd->node == (void *)raw) ? REF_PRISTINE : REF_NORMAL);
1295                 }
1296                 if (xd->flags & JFFS2_XFLAGS_DEAD)
1297                         list_add(&xd->xindex, &c->xattr_dead_list);
1298                 spin_unlock(&c->erase_completion_lock);
1299         }
1300         up_write(&c->xattr_sem);
1301         return list_empty(&c->xattr_unchecked) ? 1 : 0;
1302 }
1303
1304 void jffs2_release_xattr_datum(struct jffs2_sb_info *c, struct jffs2_xattr_datum *xd)
1305 {
1306         /* must be called under spin_lock(&c->erase_completion_lock) */
1307         if (xd->refcnt > 0 || xd->node != (void *)xd)
1308                 return;
1309
1310         list_del(&xd->xindex);
1311         jffs2_free_xattr_datum(xd);
1312 }
1313
1314 void jffs2_release_xattr_ref(struct jffs2_sb_info *c, struct jffs2_xattr_ref *ref)
1315 {
1316         /* must be called under spin_lock(&c->erase_completion_lock) */
1317         struct jffs2_xattr_ref *tmp, **ptmp;
1318
1319         if (ref->node != (void *)ref)
1320                 return;
1321
1322         for (tmp=c->xref_dead_list, ptmp=&c->xref_dead_list; tmp; ptmp=&tmp->next, tmp=tmp->next) {
1323                 if (ref == tmp) {
1324                         *ptmp = tmp->next;
1325                         break;
1326                 }
1327         }
1328         jffs2_free_xattr_ref(ref);
1329 }