udf: Verify symlink size before loading it
[pandora-kernel.git] / fs / udf / symlink.c
1 /*
2  * symlink.c
3  *
4  * PURPOSE
5  *      Symlink handling routines for the OSTA-UDF(tm) filesystem.
6  *
7  * COPYRIGHT
8  *      This file is distributed under the terms of the GNU General Public
9  *      License (GPL). Copies of the GPL can be obtained from:
10  *              ftp://prep.ai.mit.edu/pub/gnu/GPL
11  *      Each contributing author retains all rights to their own work.
12  *
13  *  (C) 1998-2001 Ben Fennema
14  *  (C) 1999 Stelias Computing Inc
15  *
16  * HISTORY
17  *
18  *  04/16/99 blf  Created.
19  *
20  */
21
22 #include "udfdecl.h"
23 #include <asm/uaccess.h>
24 #include <linux/errno.h>
25 #include <linux/fs.h>
26 #include <linux/time.h>
27 #include <linux/mm.h>
28 #include <linux/stat.h>
29 #include <linux/pagemap.h>
30 #include <linux/buffer_head.h>
31 #include "udf_i.h"
32
33 static void udf_pc_to_char(struct super_block *sb, unsigned char *from,
34                            int fromlen, unsigned char *to)
35 {
36         struct pathComponent *pc;
37         int elen = 0;
38         unsigned char *p = to;
39
40         while (elen < fromlen) {
41                 pc = (struct pathComponent *)(from + elen);
42                 switch (pc->componentType) {
43                 case 1:
44                         if (pc->lengthComponentIdent == 0) {
45                                 p = to;
46                                 *p++ = '/';
47                         }
48                         break;
49                 case 3:
50                         memcpy(p, "../", 3);
51                         p += 3;
52                         break;
53                 case 4:
54                         memcpy(p, "./", 2);
55                         p += 2;
56                         /* that would be . - just ignore */
57                         break;
58                 case 5:
59                         p += udf_get_filename(sb, pc->componentIdent, p,
60                                               pc->lengthComponentIdent);
61                         *p++ = '/';
62                         break;
63                 }
64                 elen += sizeof(struct pathComponent) + pc->lengthComponentIdent;
65         }
66         if (p > to + 1)
67                 p[-1] = '\0';
68         else
69                 p[0] = '\0';
70 }
71
72 static int udf_symlink_filler(struct file *file, struct page *page)
73 {
74         struct inode *inode = page->mapping->host;
75         struct buffer_head *bh = NULL;
76         unsigned char *symlink;
77         int err;
78         unsigned char *p = kmap(page);
79         struct udf_inode_info *iinfo;
80         uint32_t pos;
81
82         /* We don't support symlinks longer than one block */
83         if (inode->i_size > inode->i_sb->s_blocksize) {
84                 err = -ENAMETOOLONG;
85                 goto out_unmap;
86         }
87
88         iinfo = UDF_I(inode);
89         pos = udf_block_map(inode, 0);
90
91         down_read(&iinfo->i_data_sem);
92         if (iinfo->i_alloc_type == ICBTAG_FLAG_AD_IN_ICB) {
93                 symlink = iinfo->i_ext.i_data + iinfo->i_lenEAttr;
94         } else {
95                 bh = sb_bread(inode->i_sb, pos);
96
97                 if (!bh) {
98                         err = -EIO;
99                         goto out_unlock_inode;
100                 }
101
102                 symlink = bh->b_data;
103         }
104
105         udf_pc_to_char(inode->i_sb, symlink, inode->i_size, p);
106         brelse(bh);
107
108         up_read(&iinfo->i_data_sem);
109         SetPageUptodate(page);
110         kunmap(page);
111         unlock_page(page);
112         return 0;
113
114 out_unlock_inode:
115         up_read(&iinfo->i_data_sem);
116         SetPageError(page);
117 out_unmap:
118         kunmap(page);
119         unlock_page(page);
120         return err;
121 }
122
123 /*
124  * symlinks can't do much...
125  */
126 const struct address_space_operations udf_symlink_aops = {
127         .readpage               = udf_symlink_filler,
128 };