udf: Check path length when reading symlink
[pandora-kernel.git] / fs / udf / symlink.c
1 /*
2  * symlink.c
3  *
4  * PURPOSE
5  *      Symlink handling routines for the OSTA-UDF(tm) filesystem.
6  *
7  * COPYRIGHT
8  *      This file is distributed under the terms of the GNU General Public
9  *      License (GPL). Copies of the GPL can be obtained from:
10  *              ftp://prep.ai.mit.edu/pub/gnu/GPL
11  *      Each contributing author retains all rights to their own work.
12  *
13  *  (C) 1998-2001 Ben Fennema
14  *  (C) 1999 Stelias Computing Inc
15  *
16  * HISTORY
17  *
18  *  04/16/99 blf  Created.
19  *
20  */
21
22 #include "udfdecl.h"
23 #include <asm/uaccess.h>
24 #include <linux/errno.h>
25 #include <linux/fs.h>
26 #include <linux/time.h>
27 #include <linux/mm.h>
28 #include <linux/stat.h>
29 #include <linux/pagemap.h>
30 #include <linux/buffer_head.h>
31 #include "udf_i.h"
32
33 static int udf_pc_to_char(struct super_block *sb, unsigned char *from,
34                           int fromlen, unsigned char *to, int tolen)
35 {
36         struct pathComponent *pc;
37         int elen = 0;
38         int comp_len;
39         unsigned char *p = to;
40
41         /* Reserve one byte for terminating \0 */
42         tolen--;
43         while (elen < fromlen) {
44                 pc = (struct pathComponent *)(from + elen);
45                 switch (pc->componentType) {
46                 case 1:
47                         /*
48                          * Symlink points to some place which should be agreed
49                          * upon between originator and receiver of the media. Ignore.
50                          */
51                         if (pc->lengthComponentIdent > 0)
52                                 break;
53                         /* Fall through */
54                 case 2:
55                         if (tolen == 0)
56                                 return -ENAMETOOLONG;
57                         p = to;
58                         *p++ = '/';
59                         tolen--;
60                         break;
61                 case 3:
62                         if (tolen < 3)
63                                 return -ENAMETOOLONG;
64                         memcpy(p, "../", 3);
65                         p += 3;
66                         tolen -= 3;
67                         break;
68                 case 4:
69                         if (tolen < 2)
70                                 return -ENAMETOOLONG;
71                         memcpy(p, "./", 2);
72                         p += 2;
73                         tolen -= 2;
74                         /* that would be . - just ignore */
75                         break;
76                 case 5:
77                         comp_len = udf_get_filename(sb, pc->componentIdent,
78                                                     pc->lengthComponentIdent,
79                                                     p, tolen);
80                         p += comp_len;
81                         tolen -= comp_len;
82                         if (tolen == 0)
83                                 return -ENAMETOOLONG;
84                         *p++ = '/';
85                         tolen--;
86                         break;
87                 }
88                 elen += sizeof(struct pathComponent) + pc->lengthComponentIdent;
89         }
90         if (p > to + 1)
91                 p[-1] = '\0';
92         else
93                 p[0] = '\0';
94         return 0;
95 }
96
97 static int udf_symlink_filler(struct file *file, struct page *page)
98 {
99         struct inode *inode = page->mapping->host;
100         struct buffer_head *bh = NULL;
101         unsigned char *symlink;
102         int err;
103         unsigned char *p = kmap(page);
104         struct udf_inode_info *iinfo;
105         uint32_t pos;
106
107         /* We don't support symlinks longer than one block */
108         if (inode->i_size > inode->i_sb->s_blocksize) {
109                 err = -ENAMETOOLONG;
110                 goto out_unmap;
111         }
112
113         iinfo = UDF_I(inode);
114         pos = udf_block_map(inode, 0);
115
116         down_read(&iinfo->i_data_sem);
117         if (iinfo->i_alloc_type == ICBTAG_FLAG_AD_IN_ICB) {
118                 symlink = iinfo->i_ext.i_data + iinfo->i_lenEAttr;
119         } else {
120                 bh = sb_bread(inode->i_sb, pos);
121
122                 if (!bh) {
123                         err = -EIO;
124                         goto out_unlock_inode;
125                 }
126
127                 symlink = bh->b_data;
128         }
129
130         err = udf_pc_to_char(inode->i_sb, symlink, inode->i_size, p, PAGE_SIZE);
131         brelse(bh);
132         if (err)
133                 goto out_unlock_inode;
134
135         up_read(&iinfo->i_data_sem);
136         SetPageUptodate(page);
137         kunmap(page);
138         unlock_page(page);
139         return 0;
140
141 out_unlock_inode:
142         up_read(&iinfo->i_data_sem);
143         SetPageError(page);
144 out_unmap:
145         kunmap(page);
146         unlock_page(page);
147         return err;
148 }
149
150 /*
151  * symlinks can't do much...
152  */
153 const struct address_space_operations udf_symlink_aops = {
154         .readpage               = udf_symlink_filler,
155 };