1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * This file is part of UBIFS.
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * Copyright (C) 2006-2008 Nokia Corporation.
6*4882a593Smuzhiyun *
7*4882a593Smuzhiyun * Authors: Artem Bityutskiy (Битюцкий Артём)
8*4882a593Smuzhiyun * Adrian Hunter
9*4882a593Smuzhiyun */
10*4882a593Smuzhiyun
11*4882a593Smuzhiyun /*
12*4882a593Smuzhiyun * This file implements UBIFS extended attributes support.
13*4882a593Smuzhiyun *
14*4882a593Smuzhiyun * Extended attributes are implemented as regular inodes with attached data,
15*4882a593Smuzhiyun * which limits extended attribute size to UBIFS block size (4KiB). Names of
16*4882a593Smuzhiyun * extended attributes are described by extended attribute entries (xentries),
17*4882a593Smuzhiyun * which are almost identical to directory entries, but have different key type.
18*4882a593Smuzhiyun *
19*4882a593Smuzhiyun * In other words, the situation with extended attributes is very similar to
20*4882a593Smuzhiyun * directories. Indeed, any inode (but of course not xattr inodes) may have a
21*4882a593Smuzhiyun * number of associated xentries, just like directory inodes have associated
22*4882a593Smuzhiyun * directory entries. Extended attribute entries store the name of the extended
23*4882a593Smuzhiyun * attribute, the host inode number, and the extended attribute inode number.
24*4882a593Smuzhiyun * Similarly, direntries store the name, the parent and the target inode
25*4882a593Smuzhiyun * numbers. Thus, most of the common UBIFS mechanisms may be re-used for
26*4882a593Smuzhiyun * extended attributes.
27*4882a593Smuzhiyun *
28*4882a593Smuzhiyun * The number of extended attributes is not limited, but there is Linux
29*4882a593Smuzhiyun * limitation on the maximum possible size of the list of all extended
30*4882a593Smuzhiyun * attributes associated with an inode (%XATTR_LIST_MAX), so UBIFS makes sure
31*4882a593Smuzhiyun * the sum of all extended attribute names of the inode does not exceed that
32*4882a593Smuzhiyun * limit.
33*4882a593Smuzhiyun *
34*4882a593Smuzhiyun * Extended attributes are synchronous, which means they are written to the
35*4882a593Smuzhiyun * flash media synchronously and there is no write-back for extended attribute
36*4882a593Smuzhiyun * inodes. The extended attribute values are not stored in compressed form on
37*4882a593Smuzhiyun * the media.
38*4882a593Smuzhiyun *
39*4882a593Smuzhiyun * Since extended attributes are represented by regular inodes, they are cached
40*4882a593Smuzhiyun * in the VFS inode cache. The xentries are cached in the LNC cache (see
41*4882a593Smuzhiyun * tnc.c).
42*4882a593Smuzhiyun *
43*4882a593Smuzhiyun * ACL support is not implemented.
44*4882a593Smuzhiyun */
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun #include "ubifs.h"
47*4882a593Smuzhiyun #include <linux/fs.h>
48*4882a593Smuzhiyun #include <linux/slab.h>
49*4882a593Smuzhiyun #include <linux/xattr.h>
50*4882a593Smuzhiyun
51*4882a593Smuzhiyun /*
52*4882a593Smuzhiyun * Extended attribute type constants.
53*4882a593Smuzhiyun *
54*4882a593Smuzhiyun * USER_XATTR: user extended attribute ("user.*")
55*4882a593Smuzhiyun * TRUSTED_XATTR: trusted extended attribute ("trusted.*)
56*4882a593Smuzhiyun * SECURITY_XATTR: security extended attribute ("security.*")
57*4882a593Smuzhiyun */
58*4882a593Smuzhiyun enum {
59*4882a593Smuzhiyun USER_XATTR,
60*4882a593Smuzhiyun TRUSTED_XATTR,
61*4882a593Smuzhiyun SECURITY_XATTR,
62*4882a593Smuzhiyun };
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun static const struct inode_operations empty_iops;
65*4882a593Smuzhiyun static const struct file_operations empty_fops;
66*4882a593Smuzhiyun
67*4882a593Smuzhiyun /**
68*4882a593Smuzhiyun * create_xattr - create an extended attribute.
69*4882a593Smuzhiyun * @c: UBIFS file-system description object
70*4882a593Smuzhiyun * @host: host inode
71*4882a593Smuzhiyun * @nm: extended attribute name
72*4882a593Smuzhiyun * @value: extended attribute value
73*4882a593Smuzhiyun * @size: size of extended attribute value
74*4882a593Smuzhiyun *
75*4882a593Smuzhiyun * This is a helper function which creates an extended attribute of name @nm
76*4882a593Smuzhiyun * and value @value for inode @host. The host inode is also updated on flash
77*4882a593Smuzhiyun * because the ctime and extended attribute accounting data changes. This
78*4882a593Smuzhiyun * function returns zero in case of success and a negative error code in case
79*4882a593Smuzhiyun * of failure.
80*4882a593Smuzhiyun */
create_xattr(struct ubifs_info * c,struct inode * host,const struct fscrypt_name * nm,const void * value,int size)81*4882a593Smuzhiyun static int create_xattr(struct ubifs_info *c, struct inode *host,
82*4882a593Smuzhiyun const struct fscrypt_name *nm, const void *value, int size)
83*4882a593Smuzhiyun {
84*4882a593Smuzhiyun int err, names_len;
85*4882a593Smuzhiyun struct inode *inode;
86*4882a593Smuzhiyun struct ubifs_inode *ui, *host_ui = ubifs_inode(host);
87*4882a593Smuzhiyun struct ubifs_budget_req req = { .new_ino = 1, .new_dent = 1,
88*4882a593Smuzhiyun .new_ino_d = ALIGN(size, 8), .dirtied_ino = 1,
89*4882a593Smuzhiyun .dirtied_ino_d = ALIGN(host_ui->data_len, 8) };
90*4882a593Smuzhiyun
91*4882a593Smuzhiyun if (host_ui->xattr_cnt >= ubifs_xattr_max_cnt(c)) {
92*4882a593Smuzhiyun ubifs_err(c, "inode %lu already has too many xattrs (%d), cannot create more",
93*4882a593Smuzhiyun host->i_ino, host_ui->xattr_cnt);
94*4882a593Smuzhiyun return -ENOSPC;
95*4882a593Smuzhiyun }
96*4882a593Smuzhiyun /*
97*4882a593Smuzhiyun * Linux limits the maximum size of the extended attribute names list
98*4882a593Smuzhiyun * to %XATTR_LIST_MAX. This means we should not allow creating more
99*4882a593Smuzhiyun * extended attributes if the name list becomes larger. This limitation
100*4882a593Smuzhiyun * is artificial for UBIFS, though.
101*4882a593Smuzhiyun */
102*4882a593Smuzhiyun names_len = host_ui->xattr_names + host_ui->xattr_cnt + fname_len(nm) + 1;
103*4882a593Smuzhiyun if (names_len > XATTR_LIST_MAX) {
104*4882a593Smuzhiyun ubifs_err(c, "cannot add one more xattr name to inode %lu, total names length would become %d, max. is %d",
105*4882a593Smuzhiyun host->i_ino, names_len, XATTR_LIST_MAX);
106*4882a593Smuzhiyun return -ENOSPC;
107*4882a593Smuzhiyun }
108*4882a593Smuzhiyun
109*4882a593Smuzhiyun err = ubifs_budget_space(c, &req);
110*4882a593Smuzhiyun if (err)
111*4882a593Smuzhiyun return err;
112*4882a593Smuzhiyun
113*4882a593Smuzhiyun inode = ubifs_new_inode(c, host, S_IFREG | S_IRWXUGO);
114*4882a593Smuzhiyun if (IS_ERR(inode)) {
115*4882a593Smuzhiyun err = PTR_ERR(inode);
116*4882a593Smuzhiyun goto out_budg;
117*4882a593Smuzhiyun }
118*4882a593Smuzhiyun
119*4882a593Smuzhiyun /* Re-define all operations to be "nothing" */
120*4882a593Smuzhiyun inode->i_mapping->a_ops = &empty_aops;
121*4882a593Smuzhiyun inode->i_op = &empty_iops;
122*4882a593Smuzhiyun inode->i_fop = &empty_fops;
123*4882a593Smuzhiyun
124*4882a593Smuzhiyun inode->i_flags |= S_SYNC | S_NOATIME | S_NOCMTIME;
125*4882a593Smuzhiyun ui = ubifs_inode(inode);
126*4882a593Smuzhiyun ui->xattr = 1;
127*4882a593Smuzhiyun ui->flags |= UBIFS_XATTR_FL;
128*4882a593Smuzhiyun ui->data = kmemdup(value, size, GFP_NOFS);
129*4882a593Smuzhiyun if (!ui->data) {
130*4882a593Smuzhiyun err = -ENOMEM;
131*4882a593Smuzhiyun goto out_free;
132*4882a593Smuzhiyun }
133*4882a593Smuzhiyun inode->i_size = ui->ui_size = size;
134*4882a593Smuzhiyun ui->data_len = size;
135*4882a593Smuzhiyun
136*4882a593Smuzhiyun mutex_lock(&host_ui->ui_mutex);
137*4882a593Smuzhiyun host->i_ctime = current_time(host);
138*4882a593Smuzhiyun host_ui->xattr_cnt += 1;
139*4882a593Smuzhiyun host_ui->xattr_size += CALC_DENT_SIZE(fname_len(nm));
140*4882a593Smuzhiyun host_ui->xattr_size += CALC_XATTR_BYTES(size);
141*4882a593Smuzhiyun host_ui->xattr_names += fname_len(nm);
142*4882a593Smuzhiyun
143*4882a593Smuzhiyun /*
144*4882a593Smuzhiyun * We handle UBIFS_XATTR_NAME_ENCRYPTION_CONTEXT here because we
145*4882a593Smuzhiyun * have to set the UBIFS_CRYPT_FL flag on the host inode.
146*4882a593Smuzhiyun * To avoid multiple updates of the same inode in the same operation,
147*4882a593Smuzhiyun * let's do it here.
148*4882a593Smuzhiyun */
149*4882a593Smuzhiyun if (strcmp(fname_name(nm), UBIFS_XATTR_NAME_ENCRYPTION_CONTEXT) == 0)
150*4882a593Smuzhiyun host_ui->flags |= UBIFS_CRYPT_FL;
151*4882a593Smuzhiyun
152*4882a593Smuzhiyun err = ubifs_jnl_update(c, host, nm, inode, 0, 1);
153*4882a593Smuzhiyun if (err)
154*4882a593Smuzhiyun goto out_cancel;
155*4882a593Smuzhiyun ubifs_set_inode_flags(host);
156*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
157*4882a593Smuzhiyun
158*4882a593Smuzhiyun ubifs_release_budget(c, &req);
159*4882a593Smuzhiyun insert_inode_hash(inode);
160*4882a593Smuzhiyun iput(inode);
161*4882a593Smuzhiyun return 0;
162*4882a593Smuzhiyun
163*4882a593Smuzhiyun out_cancel:
164*4882a593Smuzhiyun host_ui->xattr_cnt -= 1;
165*4882a593Smuzhiyun host_ui->xattr_size -= CALC_DENT_SIZE(fname_len(nm));
166*4882a593Smuzhiyun host_ui->xattr_size -= CALC_XATTR_BYTES(size);
167*4882a593Smuzhiyun host_ui->xattr_names -= fname_len(nm);
168*4882a593Smuzhiyun host_ui->flags &= ~UBIFS_CRYPT_FL;
169*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
170*4882a593Smuzhiyun out_free:
171*4882a593Smuzhiyun make_bad_inode(inode);
172*4882a593Smuzhiyun iput(inode);
173*4882a593Smuzhiyun out_budg:
174*4882a593Smuzhiyun ubifs_release_budget(c, &req);
175*4882a593Smuzhiyun return err;
176*4882a593Smuzhiyun }
177*4882a593Smuzhiyun
178*4882a593Smuzhiyun /**
179*4882a593Smuzhiyun * change_xattr - change an extended attribute.
180*4882a593Smuzhiyun * @c: UBIFS file-system description object
181*4882a593Smuzhiyun * @host: host inode
182*4882a593Smuzhiyun * @inode: extended attribute inode
183*4882a593Smuzhiyun * @value: extended attribute value
184*4882a593Smuzhiyun * @size: size of extended attribute value
185*4882a593Smuzhiyun *
186*4882a593Smuzhiyun * This helper function changes the value of extended attribute @inode with new
187*4882a593Smuzhiyun * data from @value. Returns zero in case of success and a negative error code
188*4882a593Smuzhiyun * in case of failure.
189*4882a593Smuzhiyun */
change_xattr(struct ubifs_info * c,struct inode * host,struct inode * inode,const void * value,int size)190*4882a593Smuzhiyun static int change_xattr(struct ubifs_info *c, struct inode *host,
191*4882a593Smuzhiyun struct inode *inode, const void *value, int size)
192*4882a593Smuzhiyun {
193*4882a593Smuzhiyun int err;
194*4882a593Smuzhiyun struct ubifs_inode *host_ui = ubifs_inode(host);
195*4882a593Smuzhiyun struct ubifs_inode *ui = ubifs_inode(inode);
196*4882a593Smuzhiyun void *buf = NULL;
197*4882a593Smuzhiyun int old_size;
198*4882a593Smuzhiyun struct ubifs_budget_req req = { .dirtied_ino = 2,
199*4882a593Smuzhiyun .dirtied_ino_d = ALIGN(size, 8) + ALIGN(host_ui->data_len, 8) };
200*4882a593Smuzhiyun
201*4882a593Smuzhiyun ubifs_assert(c, ui->data_len == inode->i_size);
202*4882a593Smuzhiyun err = ubifs_budget_space(c, &req);
203*4882a593Smuzhiyun if (err)
204*4882a593Smuzhiyun return err;
205*4882a593Smuzhiyun
206*4882a593Smuzhiyun buf = kmemdup(value, size, GFP_NOFS);
207*4882a593Smuzhiyun if (!buf) {
208*4882a593Smuzhiyun err = -ENOMEM;
209*4882a593Smuzhiyun goto out_free;
210*4882a593Smuzhiyun }
211*4882a593Smuzhiyun mutex_lock(&ui->ui_mutex);
212*4882a593Smuzhiyun kfree(ui->data);
213*4882a593Smuzhiyun ui->data = buf;
214*4882a593Smuzhiyun inode->i_size = ui->ui_size = size;
215*4882a593Smuzhiyun old_size = ui->data_len;
216*4882a593Smuzhiyun ui->data_len = size;
217*4882a593Smuzhiyun mutex_unlock(&ui->ui_mutex);
218*4882a593Smuzhiyun
219*4882a593Smuzhiyun mutex_lock(&host_ui->ui_mutex);
220*4882a593Smuzhiyun host->i_ctime = current_time(host);
221*4882a593Smuzhiyun host_ui->xattr_size -= CALC_XATTR_BYTES(old_size);
222*4882a593Smuzhiyun host_ui->xattr_size += CALC_XATTR_BYTES(size);
223*4882a593Smuzhiyun
224*4882a593Smuzhiyun /*
225*4882a593Smuzhiyun * It is important to write the host inode after the xattr inode
226*4882a593Smuzhiyun * because if the host inode gets synchronized (via 'fsync()'), then
227*4882a593Smuzhiyun * the extended attribute inode gets synchronized, because it goes
228*4882a593Smuzhiyun * before the host inode in the write-buffer.
229*4882a593Smuzhiyun */
230*4882a593Smuzhiyun err = ubifs_jnl_change_xattr(c, inode, host);
231*4882a593Smuzhiyun if (err)
232*4882a593Smuzhiyun goto out_cancel;
233*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
234*4882a593Smuzhiyun
235*4882a593Smuzhiyun ubifs_release_budget(c, &req);
236*4882a593Smuzhiyun return 0;
237*4882a593Smuzhiyun
238*4882a593Smuzhiyun out_cancel:
239*4882a593Smuzhiyun host_ui->xattr_size -= CALC_XATTR_BYTES(size);
240*4882a593Smuzhiyun host_ui->xattr_size += CALC_XATTR_BYTES(old_size);
241*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
242*4882a593Smuzhiyun make_bad_inode(inode);
243*4882a593Smuzhiyun out_free:
244*4882a593Smuzhiyun ubifs_release_budget(c, &req);
245*4882a593Smuzhiyun return err;
246*4882a593Smuzhiyun }
247*4882a593Smuzhiyun
iget_xattr(struct ubifs_info * c,ino_t inum)248*4882a593Smuzhiyun static struct inode *iget_xattr(struct ubifs_info *c, ino_t inum)
249*4882a593Smuzhiyun {
250*4882a593Smuzhiyun struct inode *inode;
251*4882a593Smuzhiyun
252*4882a593Smuzhiyun inode = ubifs_iget(c->vfs_sb, inum);
253*4882a593Smuzhiyun if (IS_ERR(inode)) {
254*4882a593Smuzhiyun ubifs_err(c, "dead extended attribute entry, error %d",
255*4882a593Smuzhiyun (int)PTR_ERR(inode));
256*4882a593Smuzhiyun return inode;
257*4882a593Smuzhiyun }
258*4882a593Smuzhiyun if (ubifs_inode(inode)->xattr)
259*4882a593Smuzhiyun return inode;
260*4882a593Smuzhiyun ubifs_err(c, "corrupt extended attribute entry");
261*4882a593Smuzhiyun iput(inode);
262*4882a593Smuzhiyun return ERR_PTR(-EINVAL);
263*4882a593Smuzhiyun }
264*4882a593Smuzhiyun
ubifs_xattr_set(struct inode * host,const char * name,const void * value,size_t size,int flags,bool check_lock)265*4882a593Smuzhiyun int ubifs_xattr_set(struct inode *host, const char *name, const void *value,
266*4882a593Smuzhiyun size_t size, int flags, bool check_lock)
267*4882a593Smuzhiyun {
268*4882a593Smuzhiyun struct inode *inode;
269*4882a593Smuzhiyun struct ubifs_info *c = host->i_sb->s_fs_info;
270*4882a593Smuzhiyun struct fscrypt_name nm = { .disk_name = FSTR_INIT((char *)name, strlen(name))};
271*4882a593Smuzhiyun struct ubifs_dent_node *xent;
272*4882a593Smuzhiyun union ubifs_key key;
273*4882a593Smuzhiyun int err;
274*4882a593Smuzhiyun
275*4882a593Smuzhiyun if (check_lock)
276*4882a593Smuzhiyun ubifs_assert(c, inode_is_locked(host));
277*4882a593Smuzhiyun
278*4882a593Smuzhiyun if (size > UBIFS_MAX_INO_DATA)
279*4882a593Smuzhiyun return -ERANGE;
280*4882a593Smuzhiyun
281*4882a593Smuzhiyun if (fname_len(&nm) > UBIFS_MAX_NLEN)
282*4882a593Smuzhiyun return -ENAMETOOLONG;
283*4882a593Smuzhiyun
284*4882a593Smuzhiyun xent = kmalloc(UBIFS_MAX_XENT_NODE_SZ, GFP_NOFS);
285*4882a593Smuzhiyun if (!xent)
286*4882a593Smuzhiyun return -ENOMEM;
287*4882a593Smuzhiyun
288*4882a593Smuzhiyun down_write(&ubifs_inode(host)->xattr_sem);
289*4882a593Smuzhiyun /*
290*4882a593Smuzhiyun * The extended attribute entries are stored in LNC, so multiple
291*4882a593Smuzhiyun * look-ups do not involve reading the flash.
292*4882a593Smuzhiyun */
293*4882a593Smuzhiyun xent_key_init(c, &key, host->i_ino, &nm);
294*4882a593Smuzhiyun err = ubifs_tnc_lookup_nm(c, &key, xent, &nm);
295*4882a593Smuzhiyun if (err) {
296*4882a593Smuzhiyun if (err != -ENOENT)
297*4882a593Smuzhiyun goto out_free;
298*4882a593Smuzhiyun
299*4882a593Smuzhiyun if (flags & XATTR_REPLACE)
300*4882a593Smuzhiyun /* We are asked not to create the xattr */
301*4882a593Smuzhiyun err = -ENODATA;
302*4882a593Smuzhiyun else
303*4882a593Smuzhiyun err = create_xattr(c, host, &nm, value, size);
304*4882a593Smuzhiyun goto out_free;
305*4882a593Smuzhiyun }
306*4882a593Smuzhiyun
307*4882a593Smuzhiyun if (flags & XATTR_CREATE) {
308*4882a593Smuzhiyun /* We are asked not to replace the xattr */
309*4882a593Smuzhiyun err = -EEXIST;
310*4882a593Smuzhiyun goto out_free;
311*4882a593Smuzhiyun }
312*4882a593Smuzhiyun
313*4882a593Smuzhiyun inode = iget_xattr(c, le64_to_cpu(xent->inum));
314*4882a593Smuzhiyun if (IS_ERR(inode)) {
315*4882a593Smuzhiyun err = PTR_ERR(inode);
316*4882a593Smuzhiyun goto out_free;
317*4882a593Smuzhiyun }
318*4882a593Smuzhiyun
319*4882a593Smuzhiyun err = change_xattr(c, host, inode, value, size);
320*4882a593Smuzhiyun iput(inode);
321*4882a593Smuzhiyun
322*4882a593Smuzhiyun out_free:
323*4882a593Smuzhiyun up_write(&ubifs_inode(host)->xattr_sem);
324*4882a593Smuzhiyun kfree(xent);
325*4882a593Smuzhiyun return err;
326*4882a593Smuzhiyun }
327*4882a593Smuzhiyun
ubifs_xattr_get(struct inode * host,const char * name,void * buf,size_t size)328*4882a593Smuzhiyun ssize_t ubifs_xattr_get(struct inode *host, const char *name, void *buf,
329*4882a593Smuzhiyun size_t size)
330*4882a593Smuzhiyun {
331*4882a593Smuzhiyun struct inode *inode;
332*4882a593Smuzhiyun struct ubifs_info *c = host->i_sb->s_fs_info;
333*4882a593Smuzhiyun struct fscrypt_name nm = { .disk_name = FSTR_INIT((char *)name, strlen(name))};
334*4882a593Smuzhiyun struct ubifs_inode *ui;
335*4882a593Smuzhiyun struct ubifs_dent_node *xent;
336*4882a593Smuzhiyun union ubifs_key key;
337*4882a593Smuzhiyun int err;
338*4882a593Smuzhiyun
339*4882a593Smuzhiyun if (fname_len(&nm) > UBIFS_MAX_NLEN)
340*4882a593Smuzhiyun return -ENAMETOOLONG;
341*4882a593Smuzhiyun
342*4882a593Smuzhiyun xent = kmalloc(UBIFS_MAX_XENT_NODE_SZ, GFP_NOFS);
343*4882a593Smuzhiyun if (!xent)
344*4882a593Smuzhiyun return -ENOMEM;
345*4882a593Smuzhiyun
346*4882a593Smuzhiyun down_read(&ubifs_inode(host)->xattr_sem);
347*4882a593Smuzhiyun xent_key_init(c, &key, host->i_ino, &nm);
348*4882a593Smuzhiyun err = ubifs_tnc_lookup_nm(c, &key, xent, &nm);
349*4882a593Smuzhiyun if (err) {
350*4882a593Smuzhiyun if (err == -ENOENT)
351*4882a593Smuzhiyun err = -ENODATA;
352*4882a593Smuzhiyun goto out_cleanup;
353*4882a593Smuzhiyun }
354*4882a593Smuzhiyun
355*4882a593Smuzhiyun inode = iget_xattr(c, le64_to_cpu(xent->inum));
356*4882a593Smuzhiyun if (IS_ERR(inode)) {
357*4882a593Smuzhiyun err = PTR_ERR(inode);
358*4882a593Smuzhiyun goto out_cleanup;
359*4882a593Smuzhiyun }
360*4882a593Smuzhiyun
361*4882a593Smuzhiyun ui = ubifs_inode(inode);
362*4882a593Smuzhiyun ubifs_assert(c, inode->i_size == ui->data_len);
363*4882a593Smuzhiyun ubifs_assert(c, ubifs_inode(host)->xattr_size > ui->data_len);
364*4882a593Smuzhiyun
365*4882a593Smuzhiyun mutex_lock(&ui->ui_mutex);
366*4882a593Smuzhiyun if (buf) {
367*4882a593Smuzhiyun /* If @buf is %NULL we are supposed to return the length */
368*4882a593Smuzhiyun if (ui->data_len > size) {
369*4882a593Smuzhiyun err = -ERANGE;
370*4882a593Smuzhiyun goto out_iput;
371*4882a593Smuzhiyun }
372*4882a593Smuzhiyun
373*4882a593Smuzhiyun memcpy(buf, ui->data, ui->data_len);
374*4882a593Smuzhiyun }
375*4882a593Smuzhiyun err = ui->data_len;
376*4882a593Smuzhiyun
377*4882a593Smuzhiyun out_iput:
378*4882a593Smuzhiyun mutex_unlock(&ui->ui_mutex);
379*4882a593Smuzhiyun iput(inode);
380*4882a593Smuzhiyun out_cleanup:
381*4882a593Smuzhiyun up_read(&ubifs_inode(host)->xattr_sem);
382*4882a593Smuzhiyun kfree(xent);
383*4882a593Smuzhiyun return err;
384*4882a593Smuzhiyun }
385*4882a593Smuzhiyun
xattr_visible(const char * name)386*4882a593Smuzhiyun static bool xattr_visible(const char *name)
387*4882a593Smuzhiyun {
388*4882a593Smuzhiyun /* File encryption related xattrs are for internal use only */
389*4882a593Smuzhiyun if (strcmp(name, UBIFS_XATTR_NAME_ENCRYPTION_CONTEXT) == 0)
390*4882a593Smuzhiyun return false;
391*4882a593Smuzhiyun
392*4882a593Smuzhiyun /* Show trusted namespace only for "power" users */
393*4882a593Smuzhiyun if (strncmp(name, XATTR_TRUSTED_PREFIX,
394*4882a593Smuzhiyun XATTR_TRUSTED_PREFIX_LEN) == 0 && !capable(CAP_SYS_ADMIN))
395*4882a593Smuzhiyun return false;
396*4882a593Smuzhiyun
397*4882a593Smuzhiyun return true;
398*4882a593Smuzhiyun }
399*4882a593Smuzhiyun
ubifs_listxattr(struct dentry * dentry,char * buffer,size_t size)400*4882a593Smuzhiyun ssize_t ubifs_listxattr(struct dentry *dentry, char *buffer, size_t size)
401*4882a593Smuzhiyun {
402*4882a593Smuzhiyun union ubifs_key key;
403*4882a593Smuzhiyun struct inode *host = d_inode(dentry);
404*4882a593Smuzhiyun struct ubifs_info *c = host->i_sb->s_fs_info;
405*4882a593Smuzhiyun struct ubifs_inode *host_ui = ubifs_inode(host);
406*4882a593Smuzhiyun struct ubifs_dent_node *xent, *pxent = NULL;
407*4882a593Smuzhiyun int err, len, written = 0;
408*4882a593Smuzhiyun struct fscrypt_name nm = {0};
409*4882a593Smuzhiyun
410*4882a593Smuzhiyun dbg_gen("ino %lu ('%pd'), buffer size %zd", host->i_ino,
411*4882a593Smuzhiyun dentry, size);
412*4882a593Smuzhiyun
413*4882a593Smuzhiyun down_read(&host_ui->xattr_sem);
414*4882a593Smuzhiyun len = host_ui->xattr_names + host_ui->xattr_cnt;
415*4882a593Smuzhiyun if (!buffer) {
416*4882a593Smuzhiyun /*
417*4882a593Smuzhiyun * We should return the minimum buffer size which will fit a
418*4882a593Smuzhiyun * null-terminated list of all the extended attribute names.
419*4882a593Smuzhiyun */
420*4882a593Smuzhiyun err = len;
421*4882a593Smuzhiyun goto out_err;
422*4882a593Smuzhiyun }
423*4882a593Smuzhiyun
424*4882a593Smuzhiyun if (len > size) {
425*4882a593Smuzhiyun err = -ERANGE;
426*4882a593Smuzhiyun goto out_err;
427*4882a593Smuzhiyun }
428*4882a593Smuzhiyun
429*4882a593Smuzhiyun lowest_xent_key(c, &key, host->i_ino);
430*4882a593Smuzhiyun while (1) {
431*4882a593Smuzhiyun xent = ubifs_tnc_next_ent(c, &key, &nm);
432*4882a593Smuzhiyun if (IS_ERR(xent)) {
433*4882a593Smuzhiyun err = PTR_ERR(xent);
434*4882a593Smuzhiyun break;
435*4882a593Smuzhiyun }
436*4882a593Smuzhiyun
437*4882a593Smuzhiyun fname_name(&nm) = xent->name;
438*4882a593Smuzhiyun fname_len(&nm) = le16_to_cpu(xent->nlen);
439*4882a593Smuzhiyun
440*4882a593Smuzhiyun if (xattr_visible(xent->name)) {
441*4882a593Smuzhiyun memcpy(buffer + written, fname_name(&nm), fname_len(&nm) + 1);
442*4882a593Smuzhiyun written += fname_len(&nm) + 1;
443*4882a593Smuzhiyun }
444*4882a593Smuzhiyun
445*4882a593Smuzhiyun kfree(pxent);
446*4882a593Smuzhiyun pxent = xent;
447*4882a593Smuzhiyun key_read(c, &xent->key, &key);
448*4882a593Smuzhiyun }
449*4882a593Smuzhiyun kfree(pxent);
450*4882a593Smuzhiyun up_read(&host_ui->xattr_sem);
451*4882a593Smuzhiyun
452*4882a593Smuzhiyun if (err != -ENOENT) {
453*4882a593Smuzhiyun ubifs_err(c, "cannot find next direntry, error %d", err);
454*4882a593Smuzhiyun return err;
455*4882a593Smuzhiyun }
456*4882a593Smuzhiyun
457*4882a593Smuzhiyun ubifs_assert(c, written <= size);
458*4882a593Smuzhiyun return written;
459*4882a593Smuzhiyun
460*4882a593Smuzhiyun out_err:
461*4882a593Smuzhiyun up_read(&host_ui->xattr_sem);
462*4882a593Smuzhiyun return err;
463*4882a593Smuzhiyun }
464*4882a593Smuzhiyun
remove_xattr(struct ubifs_info * c,struct inode * host,struct inode * inode,const struct fscrypt_name * nm)465*4882a593Smuzhiyun static int remove_xattr(struct ubifs_info *c, struct inode *host,
466*4882a593Smuzhiyun struct inode *inode, const struct fscrypt_name *nm)
467*4882a593Smuzhiyun {
468*4882a593Smuzhiyun int err;
469*4882a593Smuzhiyun struct ubifs_inode *host_ui = ubifs_inode(host);
470*4882a593Smuzhiyun struct ubifs_inode *ui = ubifs_inode(inode);
471*4882a593Smuzhiyun struct ubifs_budget_req req = { .dirtied_ino = 2, .mod_dent = 1,
472*4882a593Smuzhiyun .dirtied_ino_d = ALIGN(host_ui->data_len, 8) };
473*4882a593Smuzhiyun
474*4882a593Smuzhiyun ubifs_assert(c, ui->data_len == inode->i_size);
475*4882a593Smuzhiyun
476*4882a593Smuzhiyun err = ubifs_budget_space(c, &req);
477*4882a593Smuzhiyun if (err)
478*4882a593Smuzhiyun return err;
479*4882a593Smuzhiyun
480*4882a593Smuzhiyun mutex_lock(&host_ui->ui_mutex);
481*4882a593Smuzhiyun host->i_ctime = current_time(host);
482*4882a593Smuzhiyun host_ui->xattr_cnt -= 1;
483*4882a593Smuzhiyun host_ui->xattr_size -= CALC_DENT_SIZE(fname_len(nm));
484*4882a593Smuzhiyun host_ui->xattr_size -= CALC_XATTR_BYTES(ui->data_len);
485*4882a593Smuzhiyun host_ui->xattr_names -= fname_len(nm);
486*4882a593Smuzhiyun
487*4882a593Smuzhiyun err = ubifs_jnl_delete_xattr(c, host, inode, nm);
488*4882a593Smuzhiyun if (err)
489*4882a593Smuzhiyun goto out_cancel;
490*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
491*4882a593Smuzhiyun
492*4882a593Smuzhiyun ubifs_release_budget(c, &req);
493*4882a593Smuzhiyun return 0;
494*4882a593Smuzhiyun
495*4882a593Smuzhiyun out_cancel:
496*4882a593Smuzhiyun host_ui->xattr_cnt += 1;
497*4882a593Smuzhiyun host_ui->xattr_size += CALC_DENT_SIZE(fname_len(nm));
498*4882a593Smuzhiyun host_ui->xattr_size += CALC_XATTR_BYTES(ui->data_len);
499*4882a593Smuzhiyun host_ui->xattr_names += fname_len(nm);
500*4882a593Smuzhiyun mutex_unlock(&host_ui->ui_mutex);
501*4882a593Smuzhiyun ubifs_release_budget(c, &req);
502*4882a593Smuzhiyun make_bad_inode(inode);
503*4882a593Smuzhiyun return err;
504*4882a593Smuzhiyun }
505*4882a593Smuzhiyun
ubifs_purge_xattrs(struct inode * host)506*4882a593Smuzhiyun int ubifs_purge_xattrs(struct inode *host)
507*4882a593Smuzhiyun {
508*4882a593Smuzhiyun union ubifs_key key;
509*4882a593Smuzhiyun struct ubifs_info *c = host->i_sb->s_fs_info;
510*4882a593Smuzhiyun struct ubifs_dent_node *xent, *pxent = NULL;
511*4882a593Smuzhiyun struct inode *xino;
512*4882a593Smuzhiyun struct fscrypt_name nm = {0};
513*4882a593Smuzhiyun int err;
514*4882a593Smuzhiyun
515*4882a593Smuzhiyun if (ubifs_inode(host)->xattr_cnt <= ubifs_xattr_max_cnt(c))
516*4882a593Smuzhiyun return 0;
517*4882a593Smuzhiyun
518*4882a593Smuzhiyun ubifs_warn(c, "inode %lu has too many xattrs, doing a non-atomic deletion",
519*4882a593Smuzhiyun host->i_ino);
520*4882a593Smuzhiyun
521*4882a593Smuzhiyun down_write(&ubifs_inode(host)->xattr_sem);
522*4882a593Smuzhiyun lowest_xent_key(c, &key, host->i_ino);
523*4882a593Smuzhiyun while (1) {
524*4882a593Smuzhiyun xent = ubifs_tnc_next_ent(c, &key, &nm);
525*4882a593Smuzhiyun if (IS_ERR(xent)) {
526*4882a593Smuzhiyun err = PTR_ERR(xent);
527*4882a593Smuzhiyun break;
528*4882a593Smuzhiyun }
529*4882a593Smuzhiyun
530*4882a593Smuzhiyun fname_name(&nm) = xent->name;
531*4882a593Smuzhiyun fname_len(&nm) = le16_to_cpu(xent->nlen);
532*4882a593Smuzhiyun
533*4882a593Smuzhiyun xino = ubifs_iget(c->vfs_sb, le64_to_cpu(xent->inum));
534*4882a593Smuzhiyun if (IS_ERR(xino)) {
535*4882a593Smuzhiyun err = PTR_ERR(xino);
536*4882a593Smuzhiyun ubifs_err(c, "dead directory entry '%s', error %d",
537*4882a593Smuzhiyun xent->name, err);
538*4882a593Smuzhiyun ubifs_ro_mode(c, err);
539*4882a593Smuzhiyun kfree(pxent);
540*4882a593Smuzhiyun kfree(xent);
541*4882a593Smuzhiyun goto out_err;
542*4882a593Smuzhiyun }
543*4882a593Smuzhiyun
544*4882a593Smuzhiyun ubifs_assert(c, ubifs_inode(xino)->xattr);
545*4882a593Smuzhiyun
546*4882a593Smuzhiyun clear_nlink(xino);
547*4882a593Smuzhiyun err = remove_xattr(c, host, xino, &nm);
548*4882a593Smuzhiyun if (err) {
549*4882a593Smuzhiyun kfree(pxent);
550*4882a593Smuzhiyun kfree(xent);
551*4882a593Smuzhiyun iput(xino);
552*4882a593Smuzhiyun ubifs_err(c, "cannot remove xattr, error %d", err);
553*4882a593Smuzhiyun goto out_err;
554*4882a593Smuzhiyun }
555*4882a593Smuzhiyun
556*4882a593Smuzhiyun iput(xino);
557*4882a593Smuzhiyun
558*4882a593Smuzhiyun kfree(pxent);
559*4882a593Smuzhiyun pxent = xent;
560*4882a593Smuzhiyun key_read(c, &xent->key, &key);
561*4882a593Smuzhiyun }
562*4882a593Smuzhiyun kfree(pxent);
563*4882a593Smuzhiyun up_write(&ubifs_inode(host)->xattr_sem);
564*4882a593Smuzhiyun
565*4882a593Smuzhiyun if (err != -ENOENT) {
566*4882a593Smuzhiyun ubifs_err(c, "cannot find next direntry, error %d", err);
567*4882a593Smuzhiyun return err;
568*4882a593Smuzhiyun }
569*4882a593Smuzhiyun
570*4882a593Smuzhiyun return 0;
571*4882a593Smuzhiyun
572*4882a593Smuzhiyun out_err:
573*4882a593Smuzhiyun up_write(&ubifs_inode(host)->xattr_sem);
574*4882a593Smuzhiyun return err;
575*4882a593Smuzhiyun }
576*4882a593Smuzhiyun
577*4882a593Smuzhiyun /**
578*4882a593Smuzhiyun * ubifs_evict_xattr_inode - Evict an xattr inode.
579*4882a593Smuzhiyun * @c: UBIFS file-system description object
580*4882a593Smuzhiyun * @xattr_inum: xattr inode number
581*4882a593Smuzhiyun *
582*4882a593Smuzhiyun * When an inode that hosts xattrs is being removed we have to make sure
583*4882a593Smuzhiyun * that cached inodes of the xattrs also get removed from the inode cache
584*4882a593Smuzhiyun * otherwise we'd waste memory. This function looks up an inode from the
585*4882a593Smuzhiyun * inode cache and clears the link counter such that iput() will evict
586*4882a593Smuzhiyun * the inode.
587*4882a593Smuzhiyun */
ubifs_evict_xattr_inode(struct ubifs_info * c,ino_t xattr_inum)588*4882a593Smuzhiyun void ubifs_evict_xattr_inode(struct ubifs_info *c, ino_t xattr_inum)
589*4882a593Smuzhiyun {
590*4882a593Smuzhiyun struct inode *inode;
591*4882a593Smuzhiyun
592*4882a593Smuzhiyun inode = ilookup(c->vfs_sb, xattr_inum);
593*4882a593Smuzhiyun if (inode) {
594*4882a593Smuzhiyun clear_nlink(inode);
595*4882a593Smuzhiyun iput(inode);
596*4882a593Smuzhiyun }
597*4882a593Smuzhiyun }
598*4882a593Smuzhiyun
ubifs_xattr_remove(struct inode * host,const char * name)599*4882a593Smuzhiyun static int ubifs_xattr_remove(struct inode *host, const char *name)
600*4882a593Smuzhiyun {
601*4882a593Smuzhiyun struct inode *inode;
602*4882a593Smuzhiyun struct ubifs_info *c = host->i_sb->s_fs_info;
603*4882a593Smuzhiyun struct fscrypt_name nm = { .disk_name = FSTR_INIT((char *)name, strlen(name))};
604*4882a593Smuzhiyun struct ubifs_dent_node *xent;
605*4882a593Smuzhiyun union ubifs_key key;
606*4882a593Smuzhiyun int err;
607*4882a593Smuzhiyun
608*4882a593Smuzhiyun ubifs_assert(c, inode_is_locked(host));
609*4882a593Smuzhiyun
610*4882a593Smuzhiyun if (fname_len(&nm) > UBIFS_MAX_NLEN)
611*4882a593Smuzhiyun return -ENAMETOOLONG;
612*4882a593Smuzhiyun
613*4882a593Smuzhiyun xent = kmalloc(UBIFS_MAX_XENT_NODE_SZ, GFP_NOFS);
614*4882a593Smuzhiyun if (!xent)
615*4882a593Smuzhiyun return -ENOMEM;
616*4882a593Smuzhiyun
617*4882a593Smuzhiyun down_write(&ubifs_inode(host)->xattr_sem);
618*4882a593Smuzhiyun xent_key_init(c, &key, host->i_ino, &nm);
619*4882a593Smuzhiyun err = ubifs_tnc_lookup_nm(c, &key, xent, &nm);
620*4882a593Smuzhiyun if (err) {
621*4882a593Smuzhiyun if (err == -ENOENT)
622*4882a593Smuzhiyun err = -ENODATA;
623*4882a593Smuzhiyun goto out_free;
624*4882a593Smuzhiyun }
625*4882a593Smuzhiyun
626*4882a593Smuzhiyun inode = iget_xattr(c, le64_to_cpu(xent->inum));
627*4882a593Smuzhiyun if (IS_ERR(inode)) {
628*4882a593Smuzhiyun err = PTR_ERR(inode);
629*4882a593Smuzhiyun goto out_free;
630*4882a593Smuzhiyun }
631*4882a593Smuzhiyun
632*4882a593Smuzhiyun ubifs_assert(c, inode->i_nlink == 1);
633*4882a593Smuzhiyun clear_nlink(inode);
634*4882a593Smuzhiyun err = remove_xattr(c, host, inode, &nm);
635*4882a593Smuzhiyun if (err)
636*4882a593Smuzhiyun set_nlink(inode, 1);
637*4882a593Smuzhiyun
638*4882a593Smuzhiyun /* If @i_nlink is 0, 'iput()' will delete the inode */
639*4882a593Smuzhiyun iput(inode);
640*4882a593Smuzhiyun
641*4882a593Smuzhiyun out_free:
642*4882a593Smuzhiyun up_write(&ubifs_inode(host)->xattr_sem);
643*4882a593Smuzhiyun kfree(xent);
644*4882a593Smuzhiyun return err;
645*4882a593Smuzhiyun }
646*4882a593Smuzhiyun
647*4882a593Smuzhiyun #ifdef CONFIG_UBIFS_FS_SECURITY
init_xattrs(struct inode * inode,const struct xattr * xattr_array,void * fs_info)648*4882a593Smuzhiyun static int init_xattrs(struct inode *inode, const struct xattr *xattr_array,
649*4882a593Smuzhiyun void *fs_info)
650*4882a593Smuzhiyun {
651*4882a593Smuzhiyun const struct xattr *xattr;
652*4882a593Smuzhiyun char *name;
653*4882a593Smuzhiyun int err = 0;
654*4882a593Smuzhiyun
655*4882a593Smuzhiyun for (xattr = xattr_array; xattr->name != NULL; xattr++) {
656*4882a593Smuzhiyun name = kmalloc(XATTR_SECURITY_PREFIX_LEN +
657*4882a593Smuzhiyun strlen(xattr->name) + 1, GFP_NOFS);
658*4882a593Smuzhiyun if (!name) {
659*4882a593Smuzhiyun err = -ENOMEM;
660*4882a593Smuzhiyun break;
661*4882a593Smuzhiyun }
662*4882a593Smuzhiyun strcpy(name, XATTR_SECURITY_PREFIX);
663*4882a593Smuzhiyun strcpy(name + XATTR_SECURITY_PREFIX_LEN, xattr->name);
664*4882a593Smuzhiyun /*
665*4882a593Smuzhiyun * creating a new inode without holding the inode rwsem,
666*4882a593Smuzhiyun * no need to check whether inode is locked.
667*4882a593Smuzhiyun */
668*4882a593Smuzhiyun err = ubifs_xattr_set(inode, name, xattr->value,
669*4882a593Smuzhiyun xattr->value_len, 0, false);
670*4882a593Smuzhiyun kfree(name);
671*4882a593Smuzhiyun if (err < 0)
672*4882a593Smuzhiyun break;
673*4882a593Smuzhiyun }
674*4882a593Smuzhiyun
675*4882a593Smuzhiyun return err;
676*4882a593Smuzhiyun }
677*4882a593Smuzhiyun
ubifs_init_security(struct inode * dentry,struct inode * inode,const struct qstr * qstr)678*4882a593Smuzhiyun int ubifs_init_security(struct inode *dentry, struct inode *inode,
679*4882a593Smuzhiyun const struct qstr *qstr)
680*4882a593Smuzhiyun {
681*4882a593Smuzhiyun int err;
682*4882a593Smuzhiyun
683*4882a593Smuzhiyun err = security_inode_init_security(inode, dentry, qstr,
684*4882a593Smuzhiyun &init_xattrs, 0);
685*4882a593Smuzhiyun if (err) {
686*4882a593Smuzhiyun struct ubifs_info *c = dentry->i_sb->s_fs_info;
687*4882a593Smuzhiyun ubifs_err(c, "cannot initialize security for inode %lu, error %d",
688*4882a593Smuzhiyun inode->i_ino, err);
689*4882a593Smuzhiyun }
690*4882a593Smuzhiyun return err;
691*4882a593Smuzhiyun }
692*4882a593Smuzhiyun #endif
693*4882a593Smuzhiyun
xattr_get(const struct xattr_handler * handler,struct dentry * dentry,struct inode * inode,const char * name,void * buffer,size_t size,int flags)694*4882a593Smuzhiyun static int xattr_get(const struct xattr_handler *handler,
695*4882a593Smuzhiyun struct dentry *dentry, struct inode *inode,
696*4882a593Smuzhiyun const char *name, void *buffer, size_t size,
697*4882a593Smuzhiyun int flags)
698*4882a593Smuzhiyun {
699*4882a593Smuzhiyun dbg_gen("xattr '%s', ino %lu ('%pd'), buf size %zd", name,
700*4882a593Smuzhiyun inode->i_ino, dentry, size);
701*4882a593Smuzhiyun
702*4882a593Smuzhiyun name = xattr_full_name(handler, name);
703*4882a593Smuzhiyun return ubifs_xattr_get(inode, name, buffer, size);
704*4882a593Smuzhiyun }
705*4882a593Smuzhiyun
xattr_set(const struct xattr_handler * handler,struct dentry * dentry,struct inode * inode,const char * name,const void * value,size_t size,int flags)706*4882a593Smuzhiyun static int xattr_set(const struct xattr_handler *handler,
707*4882a593Smuzhiyun struct dentry *dentry, struct inode *inode,
708*4882a593Smuzhiyun const char *name, const void *value,
709*4882a593Smuzhiyun size_t size, int flags)
710*4882a593Smuzhiyun {
711*4882a593Smuzhiyun dbg_gen("xattr '%s', host ino %lu ('%pd'), size %zd",
712*4882a593Smuzhiyun name, inode->i_ino, dentry, size);
713*4882a593Smuzhiyun
714*4882a593Smuzhiyun name = xattr_full_name(handler, name);
715*4882a593Smuzhiyun
716*4882a593Smuzhiyun if (value)
717*4882a593Smuzhiyun return ubifs_xattr_set(inode, name, value, size, flags, true);
718*4882a593Smuzhiyun else
719*4882a593Smuzhiyun return ubifs_xattr_remove(inode, name);
720*4882a593Smuzhiyun }
721*4882a593Smuzhiyun
722*4882a593Smuzhiyun static const struct xattr_handler ubifs_user_xattr_handler = {
723*4882a593Smuzhiyun .prefix = XATTR_USER_PREFIX,
724*4882a593Smuzhiyun .get = xattr_get,
725*4882a593Smuzhiyun .set = xattr_set,
726*4882a593Smuzhiyun };
727*4882a593Smuzhiyun
728*4882a593Smuzhiyun static const struct xattr_handler ubifs_trusted_xattr_handler = {
729*4882a593Smuzhiyun .prefix = XATTR_TRUSTED_PREFIX,
730*4882a593Smuzhiyun .get = xattr_get,
731*4882a593Smuzhiyun .set = xattr_set,
732*4882a593Smuzhiyun };
733*4882a593Smuzhiyun
734*4882a593Smuzhiyun #ifdef CONFIG_UBIFS_FS_SECURITY
735*4882a593Smuzhiyun static const struct xattr_handler ubifs_security_xattr_handler = {
736*4882a593Smuzhiyun .prefix = XATTR_SECURITY_PREFIX,
737*4882a593Smuzhiyun .get = xattr_get,
738*4882a593Smuzhiyun .set = xattr_set,
739*4882a593Smuzhiyun };
740*4882a593Smuzhiyun #endif
741*4882a593Smuzhiyun
742*4882a593Smuzhiyun const struct xattr_handler *ubifs_xattr_handlers[] = {
743*4882a593Smuzhiyun &ubifs_user_xattr_handler,
744*4882a593Smuzhiyun &ubifs_trusted_xattr_handler,
745*4882a593Smuzhiyun #ifdef CONFIG_UBIFS_FS_SECURITY
746*4882a593Smuzhiyun &ubifs_security_xattr_handler,
747*4882a593Smuzhiyun #endif
748*4882a593Smuzhiyun NULL
749*4882a593Smuzhiyun };
750