BKL: Remove BKL from ncpfs
[pandora-kernel.git] / fs / ncpfs / ioctl.c
1 /*
2  *  ioctl.c
3  *
4  *  Copyright (C) 1995, 1996 by Volker Lendecke
5  *  Modified 1997 Peter Waltenberg, Bill Hawes, David Woodhouse for 2.1 dcache
6  *  Modified 1998, 1999 Wolfram Pienkoss for NLS
7  *
8  */
9
10 #include <linux/capability.h>
11 #include <linux/compat.h>
12 #include <linux/errno.h>
13 #include <linux/fs.h>
14 #include <linux/ioctl.h>
15 #include <linux/time.h>
16 #include <linux/mm.h>
17 #include <linux/mount.h>
18 #include <linux/slab.h>
19 #include <linux/highuid.h>
20 #include <linux/smp_lock.h>
21 #include <linux/vmalloc.h>
22 #include <linux/sched.h>
23
24 #include <linux/ncp_fs.h>
25
26 #include <asm/uaccess.h>
27
28 #include "ncplib_kernel.h"
29
30 /* maximum limit for ncp_objectname_ioctl */
31 #define NCP_OBJECT_NAME_MAX_LEN 4096
32 /* maximum limit for ncp_privatedata_ioctl */
33 #define NCP_PRIVATE_DATA_MAX_LEN 8192
34 /* maximum negotiable packet size */
35 #define NCP_PACKET_SIZE_INTERNAL 65536
36
37 static int
38 ncp_get_fs_info(struct ncp_server * server, struct inode *inode,
39                 struct ncp_fs_info __user *arg)
40 {
41         struct ncp_fs_info info;
42
43         if (copy_from_user(&info, arg, sizeof(info)))
44                 return -EFAULT;
45
46         if (info.version != NCP_GET_FS_INFO_VERSION) {
47                 DPRINTK("info.version invalid: %d\n", info.version);
48                 return -EINVAL;
49         }
50         /* TODO: info.addr = server->m.serv_addr; */
51         SET_UID(info.mounted_uid, server->m.mounted_uid);
52         info.connection         = server->connection;
53         info.buffer_size        = server->buffer_size;
54         info.volume_number      = NCP_FINFO(inode)->volNumber;
55         info.directory_id       = NCP_FINFO(inode)->DosDirNum;
56
57         if (copy_to_user(arg, &info, sizeof(info)))
58                 return -EFAULT;
59         return 0;
60 }
61
62 static int
63 ncp_get_fs_info_v2(struct ncp_server * server, struct inode *inode,
64                    struct ncp_fs_info_v2 __user * arg)
65 {
66         struct ncp_fs_info_v2 info2;
67
68         if (copy_from_user(&info2, arg, sizeof(info2)))
69                 return -EFAULT;
70
71         if (info2.version != NCP_GET_FS_INFO_VERSION_V2) {
72                 DPRINTK("info.version invalid: %d\n", info2.version);
73                 return -EINVAL;
74         }
75         info2.mounted_uid   = server->m.mounted_uid;
76         info2.connection    = server->connection;
77         info2.buffer_size   = server->buffer_size;
78         info2.volume_number = NCP_FINFO(inode)->volNumber;
79         info2.directory_id  = NCP_FINFO(inode)->DosDirNum;
80         info2.dummy1 = info2.dummy2 = info2.dummy3 = 0;
81
82         if (copy_to_user(arg, &info2, sizeof(info2)))
83                 return -EFAULT;
84         return 0;
85 }
86
87 #ifdef CONFIG_COMPAT
88 struct compat_ncp_objectname_ioctl
89 {
90         s32             auth_type;
91         u32             object_name_len;
92         compat_caddr_t  object_name;    /* a userspace data, in most cases user name */
93 };
94
95 struct compat_ncp_fs_info_v2 {
96         s32 version;
97         u32 mounted_uid;
98         u32 connection;
99         u32 buffer_size;
100
101         u32 volume_number;
102         u32 directory_id;
103
104         u32 dummy1;
105         u32 dummy2;
106         u32 dummy3;
107 };
108
109 struct compat_ncp_ioctl_request {
110         u32 function;
111         u32 size;
112         compat_caddr_t data;
113 };
114
115 struct compat_ncp_privatedata_ioctl
116 {
117         u32             len;
118         compat_caddr_t  data;           /* ~1000 for NDS */
119 };
120
121 #define NCP_IOC_GET_FS_INFO_V2_32       _IOWR('n', 4, struct compat_ncp_fs_info_v2)
122 #define NCP_IOC_NCPREQUEST_32           _IOR('n', 1, struct compat_ncp_ioctl_request)
123 #define NCP_IOC_GETOBJECTNAME_32        _IOWR('n', 9, struct compat_ncp_objectname_ioctl)
124 #define NCP_IOC_SETOBJECTNAME_32        _IOR('n', 9, struct compat_ncp_objectname_ioctl)
125 #define NCP_IOC_GETPRIVATEDATA_32       _IOWR('n', 10, struct compat_ncp_privatedata_ioctl)
126 #define NCP_IOC_SETPRIVATEDATA_32       _IOR('n', 10, struct compat_ncp_privatedata_ioctl)
127
128 static int
129 ncp_get_compat_fs_info_v2(struct ncp_server * server, struct inode *inode,
130                    struct compat_ncp_fs_info_v2 __user * arg)
131 {
132         struct compat_ncp_fs_info_v2 info2;
133
134         if (copy_from_user(&info2, arg, sizeof(info2)))
135                 return -EFAULT;
136
137         if (info2.version != NCP_GET_FS_INFO_VERSION_V2) {
138                 DPRINTK("info.version invalid: %d\n", info2.version);
139                 return -EINVAL;
140         }
141         info2.mounted_uid   = server->m.mounted_uid;
142         info2.connection    = server->connection;
143         info2.buffer_size   = server->buffer_size;
144         info2.volume_number = NCP_FINFO(inode)->volNumber;
145         info2.directory_id  = NCP_FINFO(inode)->DosDirNum;
146         info2.dummy1 = info2.dummy2 = info2.dummy3 = 0;
147
148         if (copy_to_user(arg, &info2, sizeof(info2)))
149                 return -EFAULT;
150         return 0;
151 }
152 #endif
153
154 #define NCP_IOC_GETMOUNTUID16           _IOW('n', 2, u16)
155 #define NCP_IOC_GETMOUNTUID32           _IOW('n', 2, u32)
156 #define NCP_IOC_GETMOUNTUID64           _IOW('n', 2, u64)
157
158 #ifdef CONFIG_NCPFS_NLS
159 /* Here we are select the iocharset and the codepage for NLS.
160  * Thanks Petr Vandrovec for idea and many hints.
161  */
162 static int
163 ncp_set_charsets(struct ncp_server* server, struct ncp_nls_ioctl __user *arg)
164 {
165         struct ncp_nls_ioctl user;
166         struct nls_table *codepage;
167         struct nls_table *iocharset;
168         struct nls_table *oldset_io;
169         struct nls_table *oldset_cp;
170         int utf8;
171         int err;
172
173         if (copy_from_user(&user, arg, sizeof(user)))
174                 return -EFAULT;
175
176         codepage = NULL;
177         user.codepage[NCP_IOCSNAME_LEN] = 0;
178         if (!user.codepage[0] || !strcmp(user.codepage, "default"))
179                 codepage = load_nls_default();
180         else {
181                 codepage = load_nls(user.codepage);
182                 if (!codepage) {
183                         return -EBADRQC;
184                 }
185         }
186
187         iocharset = NULL;
188         user.iocharset[NCP_IOCSNAME_LEN] = 0;
189         if (!user.iocharset[0] || !strcmp(user.iocharset, "default")) {
190                 iocharset = load_nls_default();
191                 utf8 = 0;
192         } else if (!strcmp(user.iocharset, "utf8")) {
193                 iocharset = load_nls_default();
194                 utf8 = 1;
195         } else {
196                 iocharset = load_nls(user.iocharset);
197                 if (!iocharset) {
198                         unload_nls(codepage);
199                         return -EBADRQC;
200                 }
201                 utf8 = 0;
202         }
203
204         mutex_lock(&server->root_setup_lock);
205         if (server->root_setuped) {
206                 oldset_cp = codepage;
207                 oldset_io = iocharset;
208                 err = -EBUSY;
209         } else {
210                 if (utf8)
211                         NCP_SET_FLAG(server, NCP_FLAG_UTF8);
212                 else
213                         NCP_CLR_FLAG(server, NCP_FLAG_UTF8);
214                 oldset_cp = server->nls_vol;
215                 server->nls_vol = codepage;
216                 oldset_io = server->nls_io;
217                 server->nls_io = iocharset;
218                 err = 0;
219         }
220         mutex_unlock(&server->root_setup_lock);
221         unload_nls(oldset_cp);
222         unload_nls(oldset_io);
223
224         return err;
225 }
226
227 static int
228 ncp_get_charsets(struct ncp_server* server, struct ncp_nls_ioctl __user *arg)
229 {
230         struct ncp_nls_ioctl user;
231         int len;
232
233         memset(&user, 0, sizeof(user));
234         mutex_lock(&server->root_setup_lock);
235         if (server->nls_vol && server->nls_vol->charset) {
236                 len = strlen(server->nls_vol->charset);
237                 if (len > NCP_IOCSNAME_LEN)
238                         len = NCP_IOCSNAME_LEN;
239                 strncpy(user.codepage, server->nls_vol->charset, len);
240                 user.codepage[len] = 0;
241         }
242
243         if (NCP_IS_FLAG(server, NCP_FLAG_UTF8))
244                 strcpy(user.iocharset, "utf8");
245         else if (server->nls_io && server->nls_io->charset) {
246                 len = strlen(server->nls_io->charset);
247                 if (len > NCP_IOCSNAME_LEN)
248                         len = NCP_IOCSNAME_LEN;
249                 strncpy(user.iocharset, server->nls_io->charset, len);
250                 user.iocharset[len] = 0;
251         }
252         mutex_unlock(&server->root_setup_lock);
253
254         if (copy_to_user(arg, &user, sizeof(user)))
255                 return -EFAULT;
256         return 0;
257 }
258 #endif /* CONFIG_NCPFS_NLS */
259
260 static long __ncp_ioctl(struct inode *inode, unsigned int cmd, unsigned long arg)
261 {
262         struct ncp_server *server = NCP_SERVER(inode);
263         int result;
264         struct ncp_ioctl_request request;
265         char* bouncebuffer;
266         void __user *argp = (void __user *)arg;
267
268         switch (cmd) {
269 #ifdef CONFIG_COMPAT
270         case NCP_IOC_NCPREQUEST_32:
271 #endif
272         case NCP_IOC_NCPREQUEST:
273 #ifdef CONFIG_COMPAT
274                 if (cmd == NCP_IOC_NCPREQUEST_32) {
275                         struct compat_ncp_ioctl_request request32;
276                         if (copy_from_user(&request32, argp, sizeof(request32)))
277                                 return -EFAULT;
278                         request.function = request32.function;
279                         request.size = request32.size;
280                         request.data = compat_ptr(request32.data);
281                 } else
282 #endif
283                 if (copy_from_user(&request, argp, sizeof(request)))
284                         return -EFAULT;
285
286                 if ((request.function > 255)
287                     || (request.size >
288                   NCP_PACKET_SIZE - sizeof(struct ncp_request_header))) {
289                         return -EINVAL;
290                 }
291                 bouncebuffer = vmalloc(NCP_PACKET_SIZE_INTERNAL);
292                 if (!bouncebuffer)
293                         return -ENOMEM;
294                 if (copy_from_user(bouncebuffer, request.data, request.size)) {
295                         vfree(bouncebuffer);
296                         return -EFAULT;
297                 }
298                 ncp_lock_server(server);
299
300                 /* FIXME: We hack around in the server's structures
301                    here to be able to use ncp_request */
302
303                 server->has_subfunction = 0;
304                 server->current_size = request.size;
305                 memcpy(server->packet, bouncebuffer, request.size);
306
307                 result = ncp_request2(server, request.function,
308                         bouncebuffer, NCP_PACKET_SIZE_INTERNAL);
309                 if (result < 0)
310                         result = -EIO;
311                 else
312                         result = server->reply_size;
313                 ncp_unlock_server(server);
314                 DPRINTK("ncp_ioctl: copy %d bytes\n",
315                         result);
316                 if (result >= 0)
317                         if (copy_to_user(request.data, bouncebuffer, result))
318                                 result = -EFAULT;
319                 vfree(bouncebuffer);
320                 return result;
321
322         case NCP_IOC_CONN_LOGGED_IN:
323
324                 if (!(server->m.int_flags & NCP_IMOUNT_LOGGEDIN_POSSIBLE))
325                         return -EINVAL;
326                 mutex_lock(&server->root_setup_lock);
327                 if (server->root_setuped)
328                         result = -EBUSY;
329                 else {
330                         result = ncp_conn_logged_in(inode->i_sb);
331                         if (result == 0)
332                                 server->root_setuped = 1;
333                 }
334                 mutex_unlock(&server->root_setup_lock);
335                 return result;
336
337         case NCP_IOC_GET_FS_INFO:
338                 return ncp_get_fs_info(server, inode, argp);
339
340         case NCP_IOC_GET_FS_INFO_V2:
341                 return ncp_get_fs_info_v2(server, inode, argp);
342
343 #ifdef CONFIG_COMPAT
344         case NCP_IOC_GET_FS_INFO_V2_32:
345                 return ncp_get_compat_fs_info_v2(server, inode, argp);
346 #endif
347         /* we have too many combinations of CONFIG_COMPAT,
348          * CONFIG_64BIT and CONFIG_UID16, so just handle
349          * any of the possible ioctls */
350         case NCP_IOC_GETMOUNTUID16:
351                 {
352                         u16 uid;
353
354                         SET_UID(uid, server->m.mounted_uid);
355                         if (put_user(uid, (u16 __user *)argp))
356                                 return -EFAULT;
357                         return 0;
358                 }
359         case NCP_IOC_GETMOUNTUID32:
360                 if (put_user(server->m.mounted_uid,
361                              (u32 __user *)argp))
362                         return -EFAULT;
363                 return 0;
364         case NCP_IOC_GETMOUNTUID64:
365                 if (put_user(server->m.mounted_uid,
366                              (u64 __user *)argp))
367                         return -EFAULT;
368                 return 0;
369
370         case NCP_IOC_GETROOT:
371                 {
372                         struct ncp_setroot_ioctl sr;
373
374                         result = -EACCES;
375                         mutex_lock(&server->root_setup_lock);
376                         if (server->m.mounted_vol[0]) {
377                                 struct dentry* dentry = inode->i_sb->s_root;
378
379                                 if (dentry) {
380                                         struct inode* s_inode = dentry->d_inode;
381
382                                         if (s_inode) {
383                                                 sr.volNumber = NCP_FINFO(s_inode)->volNumber;
384                                                 sr.dirEntNum = NCP_FINFO(s_inode)->dirEntNum;
385                                                 sr.namespace = server->name_space[sr.volNumber];
386                                                 result = 0;
387                                         } else
388                                                 DPRINTK("ncpfs: s_root->d_inode==NULL\n");
389                                 } else
390                                         DPRINTK("ncpfs: s_root==NULL\n");
391                         } else {
392                                 sr.volNumber = -1;
393                                 sr.namespace = 0;
394                                 sr.dirEntNum = 0;
395                                 result = 0;
396                         }
397                         mutex_unlock(&server->root_setup_lock);
398                         if (!result && copy_to_user(argp, &sr, sizeof(sr)))
399                                 result = -EFAULT;
400                         return result;
401                 }
402
403         case NCP_IOC_SETROOT:
404                 {
405                         struct ncp_setroot_ioctl sr;
406                         __u32 vnum;
407                         __le32 de;
408                         __le32 dosde;
409                         struct dentry* dentry;
410
411                         if (copy_from_user(&sr, argp, sizeof(sr)))
412                                 return -EFAULT;
413                         mutex_lock(&server->root_setup_lock);
414                         if (server->root_setuped)
415                                 result = -EBUSY;
416                         else {
417                                 if (sr.volNumber < 0) {
418                                         server->m.mounted_vol[0] = 0;
419                                         vnum = NCP_NUMBER_OF_VOLUMES;
420                                         de = 0;
421                                         dosde = 0;
422                                         result = 0;
423                                 } else if (sr.volNumber >= NCP_NUMBER_OF_VOLUMES) {
424                                         result = -EINVAL;
425                                 } else if (ncp_mount_subdir(server, sr.volNumber,
426                                                         sr.namespace, sr.dirEntNum,
427                                                         &vnum, &de, &dosde)) {
428                                         result = -ENOENT;
429                                 } else
430                                         result = 0;
431
432                                 if (result == 0) {
433                                         dentry = inode->i_sb->s_root;
434                                         if (dentry) {
435                                                 struct inode* s_inode = dentry->d_inode;
436
437                                                 if (s_inode) {
438                                                         NCP_FINFO(s_inode)->volNumber = vnum;
439                                                         NCP_FINFO(s_inode)->dirEntNum = de;
440                                                         NCP_FINFO(s_inode)->DosDirNum = dosde;
441                                                         server->root_setuped = 1;
442                                                 } else {
443                                                         DPRINTK("ncpfs: s_root->d_inode==NULL\n");
444                                                         result = -EIO;
445                                                 }
446                                         } else {
447                                                 DPRINTK("ncpfs: s_root==NULL\n");
448                                                 result = -EIO;
449                                         }
450                                 }
451                                 result = 0;
452                         }
453                         mutex_unlock(&server->root_setup_lock);
454
455                         return result;
456                 }
457
458 #ifdef CONFIG_NCPFS_PACKET_SIGNING
459         case NCP_IOC_SIGN_INIT:
460                 {
461                         struct ncp_sign_init sign;
462
463                         if (argp)
464                                 if (copy_from_user(&sign, argp, sizeof(sign)))
465                                         return -EFAULT;
466                         ncp_lock_server(server);
467                         mutex_lock(&server->rcv.creq_mutex);
468                         if (argp) {
469                                 if (server->sign_wanted) {
470                                         memcpy(server->sign_root,sign.sign_root,8);
471                                         memcpy(server->sign_last,sign.sign_last,16);
472                                         server->sign_active = 1;
473                                 }
474                                 /* ignore when signatures not wanted */
475                         } else {
476                                 server->sign_active = 0;
477                         }
478                         mutex_unlock(&server->rcv.creq_mutex);
479                         ncp_unlock_server(server);
480                         return 0;
481                 }
482
483         case NCP_IOC_SIGN_WANTED:
484                 {
485                         int state;
486
487                         ncp_lock_server(server);
488                         state = server->sign_wanted;
489                         ncp_unlock_server(server);
490                         if (put_user(state, (int __user *)argp))
491                                 return -EFAULT;
492                         return 0;
493                 }
494
495         case NCP_IOC_SET_SIGN_WANTED:
496                 {
497                         int newstate;
498
499                         /* get only low 8 bits... */
500                         if (get_user(newstate, (unsigned char __user *)argp))
501                                 return -EFAULT;
502                         result = 0;
503                         ncp_lock_server(server);
504                         if (server->sign_active) {
505                                 /* cannot turn signatures OFF when active */
506                                 if (!newstate)
507                                         result = -EINVAL;
508                         } else {
509                                 server->sign_wanted = newstate != 0;
510                         }
511                         ncp_unlock_server(server);
512                         return result;
513                 }
514
515 #endif /* CONFIG_NCPFS_PACKET_SIGNING */
516
517 #ifdef CONFIG_NCPFS_IOCTL_LOCKING
518         case NCP_IOC_LOCKUNLOCK:
519                 {
520                         struct ncp_lock_ioctl    rqdata;
521
522                         if (copy_from_user(&rqdata, argp, sizeof(rqdata)))
523                                 return -EFAULT;
524                         if (rqdata.origin != 0)
525                                 return -EINVAL;
526                         /* check for cmd */
527                         switch (rqdata.cmd) {
528                                 case NCP_LOCK_EX:
529                                 case NCP_LOCK_SH:
530                                                 if (rqdata.timeout == 0)
531                                                         rqdata.timeout = NCP_LOCK_DEFAULT_TIMEOUT;
532                                                 else if (rqdata.timeout > NCP_LOCK_MAX_TIMEOUT)
533                                                         rqdata.timeout = NCP_LOCK_MAX_TIMEOUT;
534                                                 break;
535                                 case NCP_LOCK_LOG:
536                                                 rqdata.timeout = NCP_LOCK_DEFAULT_TIMEOUT;      /* has no effect */
537                                 case NCP_LOCK_CLEAR:
538                                                 break;
539                                 default:
540                                                 return -EINVAL;
541                         }
542                         /* locking needs both read and write access */
543                         if ((result = ncp_make_open(inode, O_RDWR)) != 0)
544                         {
545                                 return result;
546                         }
547                         result = -EISDIR;
548                         if (!S_ISREG(inode->i_mode))
549                                 goto outrel;
550                         if (rqdata.cmd == NCP_LOCK_CLEAR)
551                         {
552                                 result = ncp_ClearPhysicalRecord(NCP_SERVER(inode),
553                                                         NCP_FINFO(inode)->file_handle,
554                                                         rqdata.offset,
555                                                         rqdata.length);
556                                 if (result > 0) result = 0;     /* no such lock */
557                         }
558                         else
559                         {
560                                 int lockcmd;
561
562                                 switch (rqdata.cmd)
563                                 {
564                                         case NCP_LOCK_EX:  lockcmd=1; break;
565                                         case NCP_LOCK_SH:  lockcmd=3; break;
566                                         default:           lockcmd=0; break;
567                                 }
568                                 result = ncp_LogPhysicalRecord(NCP_SERVER(inode),
569                                                         NCP_FINFO(inode)->file_handle,
570                                                         lockcmd,
571                                                         rqdata.offset,
572                                                         rqdata.length,
573                                                         rqdata.timeout);
574                                 if (result > 0) result = -EAGAIN;
575                         }
576 outrel:
577                         ncp_inode_close(inode);
578                         return result;
579                 }
580 #endif  /* CONFIG_NCPFS_IOCTL_LOCKING */
581
582 #ifdef CONFIG_COMPAT
583         case NCP_IOC_GETOBJECTNAME_32:
584                 {
585                         struct compat_ncp_objectname_ioctl user;
586                         size_t outl;
587
588                         if (copy_from_user(&user, argp, sizeof(user)))
589                                 return -EFAULT;
590                         down_read(&server->auth_rwsem);
591                         user.auth_type = server->auth.auth_type;
592                         outl = user.object_name_len;
593                         user.object_name_len = server->auth.object_name_len;
594                         if (outl > user.object_name_len)
595                                 outl = user.object_name_len;
596                         result = 0;
597                         if (outl) {
598                                 if (copy_to_user(compat_ptr(user.object_name),
599                                                  server->auth.object_name,
600                                                  outl))
601                                         result = -EFAULT;
602                         }
603                         up_read(&server->auth_rwsem);
604                         if (!result && copy_to_user(argp, &user, sizeof(user)))
605                                 result = -EFAULT;
606                         return result;
607                 }
608 #endif
609
610         case NCP_IOC_GETOBJECTNAME:
611                 {
612                         struct ncp_objectname_ioctl user;
613                         size_t outl;
614
615                         if (copy_from_user(&user, argp, sizeof(user)))
616                                 return -EFAULT;
617                         down_read(&server->auth_rwsem);
618                         user.auth_type = server->auth.auth_type;
619                         outl = user.object_name_len;
620                         user.object_name_len = server->auth.object_name_len;
621                         if (outl > user.object_name_len)
622                                 outl = user.object_name_len;
623                         result = 0;
624                         if (outl) {
625                                 if (copy_to_user(user.object_name,
626                                                  server->auth.object_name,
627                                                  outl))
628                                         result = -EFAULT;
629                         }
630                         up_read(&server->auth_rwsem);
631                         if (!result && copy_to_user(argp, &user, sizeof(user)))
632                                 result = -EFAULT;
633                         return result;
634                 }
635
636 #ifdef CONFIG_COMPAT
637         case NCP_IOC_SETOBJECTNAME_32:
638 #endif
639         case NCP_IOC_SETOBJECTNAME:
640                 {
641                         struct ncp_objectname_ioctl user;
642                         void* newname;
643                         void* oldname;
644                         size_t oldnamelen;
645                         void* oldprivate;
646                         size_t oldprivatelen;
647
648 #ifdef CONFIG_COMPAT
649                         if (cmd == NCP_IOC_SETOBJECTNAME_32) {
650                                 struct compat_ncp_objectname_ioctl user32;
651                                 if (copy_from_user(&user32, argp, sizeof(user32)))
652                                         return -EFAULT;
653                                 user.auth_type = user32.auth_type;
654                                 user.object_name_len = user32.object_name_len;
655                                 user.object_name = compat_ptr(user32.object_name);
656                         } else
657 #endif
658                         if (copy_from_user(&user, argp, sizeof(user)))
659                                 return -EFAULT;
660
661                         if (user.object_name_len > NCP_OBJECT_NAME_MAX_LEN)
662                                 return -ENOMEM;
663                         if (user.object_name_len) {
664                                 newname = memdup_user(user.object_name,
665                                                       user.object_name_len);
666                                 if (IS_ERR(newname))
667                                         return PTR_ERR(newname);
668                         } else {
669                                 newname = NULL;
670                         }
671                         down_write(&server->auth_rwsem);
672                         oldname = server->auth.object_name;
673                         oldnamelen = server->auth.object_name_len;
674                         oldprivate = server->priv.data;
675                         oldprivatelen = server->priv.len;
676                         server->auth.auth_type = user.auth_type;
677                         server->auth.object_name_len = user.object_name_len;
678                         server->auth.object_name = newname;
679                         server->priv.len = 0;
680                         server->priv.data = NULL;
681                         up_write(&server->auth_rwsem);
682                         kfree(oldprivate);
683                         kfree(oldname);
684                         return 0;
685                 }
686
687 #ifdef CONFIG_COMPAT
688         case NCP_IOC_GETPRIVATEDATA_32:
689 #endif
690         case NCP_IOC_GETPRIVATEDATA:
691                 {
692                         struct ncp_privatedata_ioctl user;
693                         size_t outl;
694
695 #ifdef CONFIG_COMPAT
696                         if (cmd == NCP_IOC_GETPRIVATEDATA_32) {
697                                 struct compat_ncp_privatedata_ioctl user32;
698                                 if (copy_from_user(&user32, argp, sizeof(user32)))
699                                         return -EFAULT;
700                                 user.len = user32.len;
701                                 user.data = compat_ptr(user32.data);
702                         } else
703 #endif
704                         if (copy_from_user(&user, argp, sizeof(user)))
705                                 return -EFAULT;
706
707                         down_read(&server->auth_rwsem);
708                         outl = user.len;
709                         user.len = server->priv.len;
710                         if (outl > user.len) outl = user.len;
711                         result = 0;
712                         if (outl) {
713                                 if (copy_to_user(user.data,
714                                                  server->priv.data,
715                                                  outl))
716                                         result = -EFAULT;
717                         }
718                         up_read(&server->auth_rwsem);
719                         if (result)
720                                 return result;
721 #ifdef CONFIG_COMPAT
722                         if (cmd == NCP_IOC_GETPRIVATEDATA_32) {
723                                 struct compat_ncp_privatedata_ioctl user32;
724                                 user32.len = user.len;
725                                 user32.data = (unsigned long) user.data;
726                                 if (copy_to_user(argp, &user32, sizeof(user32)))
727                                         return -EFAULT;
728                         } else
729 #endif
730                         if (copy_to_user(argp, &user, sizeof(user)))
731                                 return -EFAULT;
732
733                         return 0;
734                 }
735
736 #ifdef CONFIG_COMPAT
737         case NCP_IOC_SETPRIVATEDATA_32:
738 #endif
739         case NCP_IOC_SETPRIVATEDATA:
740                 {
741                         struct ncp_privatedata_ioctl user;
742                         void* new;
743                         void* old;
744                         size_t oldlen;
745
746 #ifdef CONFIG_COMPAT
747                         if (cmd == NCP_IOC_SETPRIVATEDATA_32) {
748                                 struct compat_ncp_privatedata_ioctl user32;
749                                 if (copy_from_user(&user32, argp, sizeof(user32)))
750                                         return -EFAULT;
751                                 user.len = user32.len;
752                                 user.data = compat_ptr(user32.data);
753                         } else
754 #endif
755                         if (copy_from_user(&user, argp, sizeof(user)))
756                                 return -EFAULT;
757
758                         if (user.len > NCP_PRIVATE_DATA_MAX_LEN)
759                                 return -ENOMEM;
760                         if (user.len) {
761                                 new = memdup_user(user.data, user.len);
762                                 if (IS_ERR(new))
763                                         return PTR_ERR(new);
764                         } else {
765                                 new = NULL;
766                         }
767                         down_write(&server->auth_rwsem);
768                         old = server->priv.data;
769                         oldlen = server->priv.len;
770                         server->priv.len = user.len;
771                         server->priv.data = new;
772                         up_write(&server->auth_rwsem);
773                         kfree(old);
774                         return 0;
775                 }
776
777 #ifdef CONFIG_NCPFS_NLS
778         case NCP_IOC_SETCHARSETS:
779                 return ncp_set_charsets(server, argp);
780
781         case NCP_IOC_GETCHARSETS:
782                 return ncp_get_charsets(server, argp);
783
784 #endif /* CONFIG_NCPFS_NLS */
785
786         case NCP_IOC_SETDENTRYTTL:
787                 {
788                         u_int32_t user;
789
790                         if (copy_from_user(&user, argp, sizeof(user)))
791                                 return -EFAULT;
792                         /* 20 secs at most... */
793                         if (user > 20000)
794                                 return -EINVAL;
795                         user = (user * HZ) / 1000;
796                         atomic_set(&server->dentry_ttl, user);
797                         return 0;
798                 }
799
800         case NCP_IOC_GETDENTRYTTL:
801                 {
802                         u_int32_t user = (atomic_read(&server->dentry_ttl) * 1000) / HZ;
803                         if (copy_to_user(argp, &user, sizeof(user)))
804                                 return -EFAULT;
805                         return 0;
806                 }
807
808         }
809         return -EINVAL;
810 }
811
812 long ncp_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
813 {
814         struct inode *inode = filp->f_dentry->d_inode;
815         struct ncp_server *server = NCP_SERVER(inode);
816         uid_t uid = current_uid();
817         int need_drop_write = 0;
818         long ret;
819
820         switch (cmd) {
821         case NCP_IOC_SETCHARSETS:
822         case NCP_IOC_CONN_LOGGED_IN:
823         case NCP_IOC_SETROOT:
824                 if (!capable(CAP_SYS_ADMIN)) {
825                         ret = -EACCES;
826                         goto out;
827                 }
828                 break;
829         }
830         if (server->m.mounted_uid != uid) {
831                 switch (cmd) {
832                 /*
833                  * Only mount owner can issue these ioctls.  Information
834                  * necessary to authenticate to other NDS servers are
835                  * stored here.
836                  */
837                 case NCP_IOC_GETOBJECTNAME:
838                 case NCP_IOC_SETOBJECTNAME:
839                 case NCP_IOC_GETPRIVATEDATA:
840                 case NCP_IOC_SETPRIVATEDATA:
841 #ifdef CONFIG_COMPAT
842                 case NCP_IOC_GETOBJECTNAME_32:
843                 case NCP_IOC_SETOBJECTNAME_32:
844                 case NCP_IOC_GETPRIVATEDATA_32:
845                 case NCP_IOC_SETPRIVATEDATA_32:
846 #endif
847                         ret = -EACCES;
848                         goto out;
849                 /*
850                  * These require write access on the inode if user id
851                  * does not match.  Note that they do not write to the
852                  * file...  But old code did mnt_want_write, so I keep
853                  * it as is.  Of course not for mountpoint owner, as
854                  * that breaks read-only mounts altogether as ncpmount
855                  * needs working NCP_IOC_NCPREQUEST and
856                  * NCP_IOC_GET_FS_INFO.  Some of these codes (setdentryttl,
857                  * signinit, setsignwanted) should be probably restricted
858                  * to owner only, or even more to CAP_SYS_ADMIN).
859                  */
860                 case NCP_IOC_GET_FS_INFO:
861                 case NCP_IOC_GET_FS_INFO_V2:
862                 case NCP_IOC_NCPREQUEST:
863                 case NCP_IOC_SETDENTRYTTL:
864                 case NCP_IOC_SIGN_INIT:
865                 case NCP_IOC_LOCKUNLOCK:
866                 case NCP_IOC_SET_SIGN_WANTED:
867 #ifdef CONFIG_COMPAT
868                 case NCP_IOC_GET_FS_INFO_V2_32:
869                 case NCP_IOC_NCPREQUEST_32:
870 #endif
871                         ret = mnt_want_write_file(filp);
872                         if (ret)
873                                 goto out;
874                         need_drop_write = 1;
875                         ret = inode_permission(inode, MAY_WRITE);
876                         if (ret)
877                                 goto outDropWrite;
878                         break;
879                 /*
880                  * Read access required.
881                  */
882                 case NCP_IOC_GETMOUNTUID16:
883                 case NCP_IOC_GETMOUNTUID32:
884                 case NCP_IOC_GETMOUNTUID64:
885                 case NCP_IOC_GETROOT:
886                 case NCP_IOC_SIGN_WANTED:
887                         ret = inode_permission(inode, MAY_READ);
888                         if (ret)
889                                 goto out;
890                         break;
891                 /*
892                  * Anybody can read these.
893                  */
894                 case NCP_IOC_GETCHARSETS:
895                 case NCP_IOC_GETDENTRYTTL:
896                 default:
897                 /* Three codes below are protected by CAP_SYS_ADMIN above. */
898                 case NCP_IOC_SETCHARSETS:
899                 case NCP_IOC_CONN_LOGGED_IN:
900                 case NCP_IOC_SETROOT:
901                         break;
902                 }
903         }
904         ret = __ncp_ioctl(inode, cmd, arg);
905 outDropWrite:
906         if (need_drop_write)
907                 mnt_drop_write(filp->f_path.mnt);
908 out:
909         return ret;
910 }
911
912 #ifdef CONFIG_COMPAT
913 long ncp_compat_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
914 {
915         long ret;
916
917         arg = (unsigned long) compat_ptr(arg);
918         ret = ncp_ioctl(file, cmd, arg);
919         return ret;
920 }
921 #endif