]>
git.saurik.com Git - apple/xnu.git/blob - bsd/hfs/hfs_quota.c
2 * Copyright (c) 2002-2005 Apple Computer, Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
29 * Copyright (c) 1982, 1986, 1990, 1993, 1995
30 * The Regents of the University of California. All rights reserved.
32 * This code is derived from software contributed to Berkeley by
33 * Robert Elz at The University of Melbourne.
35 * Redistribution and use in source and binary forms, with or without
36 * modification, are permitted provided that the following conditions
38 * 1. Redistributions of source code must retain the above copyright
39 * notice, this list of conditions and the following disclaimer.
40 * 2. Redistributions in binary form must reproduce the above copyright
41 * notice, this list of conditions and the following disclaimer in the
42 * documentation and/or other materials provided with the distribution.
43 * 3. All advertising materials mentioning features or use of this software
44 * must display the following acknowledgement:
45 * This product includes software developed by the University of
46 * California, Berkeley and its contributors.
47 * 4. Neither the name of the University nor the names of its contributors
48 * may be used to endorse or promote products derived from this software
49 * without specific prior written permission.
51 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
52 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
53 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
54 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
55 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
56 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
57 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
58 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
59 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
60 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
64 * derived from @(#)ufs_quota.c 8.5 (Berkeley) 5/20/95
67 #include <sys/param.h>
68 #include <sys/kernel.h>
69 #include <sys/systm.h>
70 #include <sys/mount.h>
71 #include <sys/malloc.h>
74 #include <sys/kauth.h>
75 #include <sys/vnode.h>
76 #include <sys/vnode_internal.h>
77 #include <sys/quota.h>
78 #include <sys/proc_internal.h>
79 #include <kern/kalloc.h>
82 #include <hfs/hfs_cnode.h>
83 #include <hfs/hfs_quota.h>
84 #include <hfs/hfs_mount.h>
88 * Quota name to error message mapping.
91 static char *quotatypes
[] = INITQFNAMES
;
95 * Set up the quotas for a cnode.
97 * This routine completely defines the semantics of quotas.
98 * If other criterion want to be used to establish quotas, the
99 * MAXQUOTAS value in quotas.h should be increased, and the
100 * additional dquots set up here.
104 register struct cnode
*cp
;
106 struct hfsmount
*hfsmp
;
110 vp
= cp
->c_vp
? cp
->c_vp
: cp
->c_rsrc_vp
;
113 * Set up the user quota based on file uid.
114 * EINVAL means that quotas are not enabled.
116 if (cp
->c_dquot
[USRQUOTA
] == NODQUOT
&&
118 dqget(cp
->c_uid
, &hfsmp
->hfs_qfiles
[USRQUOTA
], USRQUOTA
, &cp
->c_dquot
[USRQUOTA
])) &&
122 * Set up the group quota based on file gid.
123 * EINVAL means that quotas are not enabled.
125 if (cp
->c_dquot
[GRPQUOTA
] == NODQUOT
&&
127 dqget(cp
->c_gid
, &hfsmp
->hfs_qfiles
[GRPQUOTA
], GRPQUOTA
, &cp
->c_dquot
[GRPQUOTA
])) &&
134 * Update disk usage, and take corrective action.
137 hfs_chkdq(cp
, change
, cred
, flags
)
138 register struct cnode
*cp
;
143 register struct dquot
*dq
;
150 if ((flags
& CHOWN
) == 0)
156 for (i
= 0; i
< MAXQUOTAS
; i
++) {
157 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
161 ncurbytes
= dq
->dq_curbytes
+ change
;
163 dq
->dq_curbytes
= ncurbytes
;
166 dq
->dq_flags
&= ~DQ_BLKS
;
167 dq
->dq_flags
|= DQ_MOD
;
175 * This use of proc_ucred() is safe because kernproc credential never
178 if (!IS_VALID_CRED(cred
))
179 cred
= proc_ucred(kernproc
);
180 if (suser(cred
, NULL
) || proc_forcequota(p
)) {
181 for (i
= 0; i
< MAXQUOTAS
; i
++) {
182 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
184 error
= hfs_chkdqchg(cp
, change
, cred
, i
);
190 if ((flags
& FORCE
) || error
== 0) {
191 for (i
= 0; i
< MAXQUOTAS
; i
++) {
192 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
196 dq
->dq_curbytes
+= change
;
197 dq
->dq_flags
|= DQ_MOD
;
206 * Check for a valid change to a users allocation.
207 * Issue an error message if appropriate.
210 hfs_chkdqchg(cp
, change
, cred
, type
)
216 register struct dquot
*dq
= cp
->c_dquot
[type
];
218 struct vnode
*vp
= cp
->c_vp
? cp
->c_vp
: cp
->c_rsrc_vp
;
222 ncurbytes
= dq
->dq_curbytes
+ change
;
224 * If user would exceed their hard limit, disallow space allocation.
226 if (ncurbytes
>= dq
->dq_bhardlimit
&& dq
->dq_bhardlimit
) {
227 if ((dq
->dq_flags
& DQ_BLKS
) == 0 &&
228 cp
->c_uid
== kauth_cred_getuid(cred
)) {
230 printf("\nwrite failed, %s disk limit reached\n",
233 dq
->dq_flags
|= DQ_BLKS
;
240 * If user is over their soft limit for too long, disallow space
241 * allocation. Reset time limit as they cross their soft limit.
243 if (ncurbytes
>= dq
->dq_bsoftlimit
&& dq
->dq_bsoftlimit
) {
247 if (dq
->dq_curbytes
< dq
->dq_bsoftlimit
) {
248 dq
->dq_btime
= tv
.tv_sec
+
249 VTOHFS(vp
)->hfs_qfiles
[type
].qf_btime
;
251 if (cp
->c_uid
== kauth_cred_getuid(cred
))
252 printf("\nwarning, %s %s\n",
253 quotatypes
[type
], "disk quota exceeded");
259 if (tv
.tv_sec
> dq
->dq_btime
) {
260 if ((dq
->dq_flags
& DQ_BLKS
) == 0 &&
261 cp
->c_uid
== kauth_cred_getuid(cred
)) {
263 printf("\nwrite failed, %s %s\n",
265 "disk quota exceeded for too long");
267 dq
->dq_flags
|= DQ_BLKS
;
280 * Check the inode limit, applying corrective action.
283 hfs_chkiq(cp
, change
, cred
, flags
)
284 register struct cnode
*cp
;
289 register struct dquot
*dq
;
291 int ncurinodes
, error
=0;
295 if ((flags
& CHOWN
) == 0)
301 for (i
= 0; i
< MAXQUOTAS
; i
++) {
302 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
306 ncurinodes
= dq
->dq_curinodes
+ change
;
308 dq
->dq_curinodes
= ncurinodes
;
310 dq
->dq_curinodes
= 0;
311 dq
->dq_flags
&= ~DQ_INODS
;
312 dq
->dq_flags
|= DQ_MOD
;
320 * This use of proc_ucred() is safe because kernproc credential never
323 if (!IS_VALID_CRED(cred
))
324 cred
= proc_ucred(kernproc
);
325 if (suser(cred
, NULL
) || proc_forcequota(p
)) {
326 for (i
= 0; i
< MAXQUOTAS
; i
++) {
327 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
329 error
= hfs_chkiqchg(cp
, change
, cred
, i
);
335 if ((flags
& FORCE
) || error
== 0) {
336 for (i
= 0; i
< MAXQUOTAS
; i
++) {
337 if ((dq
= cp
->c_dquot
[i
]) == NODQUOT
)
341 dq
->dq_curinodes
+= change
;
342 dq
->dq_flags
|= DQ_MOD
;
351 * Check for a valid change to a users allocation.
352 * Issue an error message if appropriate.
355 hfs_chkiqchg(cp
, change
, cred
, type
)
361 register struct dquot
*dq
= cp
->c_dquot
[type
];
362 unsigned long ncurinodes
;
363 struct vnode
*vp
= cp
->c_vp
? cp
->c_vp
: cp
->c_rsrc_vp
;
367 ncurinodes
= dq
->dq_curinodes
+ change
;
369 * If user would exceed their hard limit, disallow cnode allocation.
371 if (ncurinodes
>= dq
->dq_ihardlimit
&& dq
->dq_ihardlimit
) {
372 if ((dq
->dq_flags
& DQ_INODS
) == 0 &&
373 cp
->c_uid
== kauth_cred_getuid(cred
)) {
375 printf("\nwrite failed, %s cnode limit reached\n",
378 dq
->dq_flags
|= DQ_INODS
;
385 * If user is over their soft limit for too long, disallow cnode
386 * allocation. Reset time limit as they cross their soft limit.
388 if (ncurinodes
>= dq
->dq_isoftlimit
&& dq
->dq_isoftlimit
) {
392 if (dq
->dq_curinodes
< dq
->dq_isoftlimit
) {
393 dq
->dq_itime
= tv
.tv_sec
+
394 VTOHFS(vp
)->hfs_qfiles
[type
].qf_itime
;
396 if (cp
->c_uid
== kauth_cred_getuid(cred
))
397 printf("\nwarning, %s %s\n",
398 quotatypes
[type
], "cnode quota exceeded");
404 if (tv
.tv_sec
> dq
->dq_itime
) {
405 if ((dq
->dq_flags
& DQ_INODS
) == 0 &&
406 cp
->c_uid
== kauth_cred_getuid(cred
)) {
408 printf("\nwrite failed, %s %s\n",
410 "cnode quota exceeded for too long");
412 dq
->dq_flags
|= DQ_INODS
;
426 * On filesystems with quotas enabled, it is an error for a file to change
427 * size and not to have a dquot structure associated with it.
431 register struct cnode
*cp
;
433 struct vnode
*vp
= cp
->c_vp
? cp
->c_vp
: cp
->c_rsrc_vp
;
434 struct hfsmount
*hfsmp
= VTOHFS(vp
);
437 for (i
= 0; i
< MAXQUOTAS
; i
++) {
438 if (hfsmp
->hfs_qfiles
[i
].qf_vp
== NULLVP
)
440 if (cp
->c_dquot
[i
] == NODQUOT
) {
441 vprint("chkdquot: missing dquot", vp
);
442 panic("missing dquot");
449 * Code to process quotactl commands.
453 * Q_QUOTAON - set up a quota file for a particular file system.
455 struct hfs_quotaon_cargs
{
460 hfs_quotaon_callback(struct vnode
*vp
, void *cargs
)
462 struct hfs_quotaon_cargs
*args
;
464 args
= (struct hfs_quotaon_cargs
*)cargs
;
466 args
->error
= hfs_getinoquota(VTOC(vp
));
468 return (VNODE_RETURNED_DONE
);
470 return (VNODE_RETURNED
);
474 hfs_quotaon(p
, mp
, type
, fnamep
)
480 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
481 struct quotafile
*qfp
;
484 struct hfs_quotaon_cargs args
;
486 /* Finish setting up quota structures. */
489 qfp
= &hfsmp
->hfs_qfiles
[type
];
491 if ( (qf_get(qfp
, QTF_OPENING
)) )
494 error
= vnode_open(fnamep
, FREAD
|FWRITE
, 0, 0, &vp
, NULL
);
498 if (!vnode_isreg(vp
)) {
499 (void) vnode_close(vp
, FREAD
|FWRITE
, NULL
);
503 vfs_setflags(mp
, (u_int64_t
)((unsigned int)MNT_QUOTA
));
504 HFS_MOUNT_LOCK(hfsmp
, TRUE
)
505 hfsmp
->hfs_flags
|= HFS_QUOTAS
;
506 HFS_MOUNT_UNLOCK(hfsmp
, TRUE
);
507 vnode_setnoflush(vp
);
509 * Save the credential of the process that turned on quotas.
511 qfp
->qf_cred
= kauth_cred_proc_ref(p
);
514 * Finish initializing the quota file
516 error
= dqfileopen(qfp
, type
);
518 (void) vnode_close(vp
, FREAD
|FWRITE
, NULL
);
520 if (IS_VALID_CRED(qfp
->qf_cred
))
521 kauth_cred_unref(&qfp
->qf_cred
);
525 qf_put(qfp
, QTF_OPENING
);
528 * Search vnodes associated with this mount point,
529 * adding references to quota file being opened.
530 * NB: only need to add dquot's for cnodes being modified.
532 * hfs_quota_callback will be called for each vnode open for
533 * 'write' (VNODE_WRITEABLE) hung off of this mount point
534 * the vnode will be in an 'unbusy' state (VNODE_WAIT) and
535 * properly referenced and unreferenced around the callback
539 vnode_iterate(mp
, VNODE_WRITEABLE
| VNODE_WAIT
, hfs_quotaon_callback
, (void *)&args
);
544 hfs_quotaoff(p
, mp
, type
);
549 qf_put(qfp
, QTF_OPENING
);
556 * Q_QUOTAOFF - turn off disk quotas for a filesystem.
558 struct hfs_quotaoff_cargs
{
563 hfs_quotaoff_callback(struct vnode
*vp
, void *cargs
)
565 struct hfs_quotaoff_cargs
*args
;
569 args
= (struct hfs_quotaoff_cargs
*)cargs
;
573 dq
= cp
->c_dquot
[args
->type
];
574 cp
->c_dquot
[args
->type
] = NODQUOT
;
578 return (VNODE_RETURNED
);
582 hfs_quotaoff(__unused
struct proc
*p
, struct mount
*mp
, register int type
)
585 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
586 struct quotafile
*qfp
;
588 struct hfs_quotaoff_cargs args
;
591 * If quotas haven't been initialized, there's no work to be done.
593 if (!dqisinitialized())
596 qfp
= &hfsmp
->hfs_qfiles
[type
];
598 if ( (qf_get(qfp
, QTF_CLOSING
)) )
603 * Sync out any orpaned dirty dquot entries.
608 * Search vnodes associated with this mount point,
609 * deleting any references to quota file being closed.
611 * hfs_quotaoff_callback will be called for each vnode
612 * hung off of this mount point
613 * the vnode will be in an 'unbusy' state (VNODE_WAIT) and
614 * properly referenced and unreferenced around the callback
618 vnode_iterate(mp
, VNODE_WAIT
, hfs_quotaoff_callback
, (void *)&args
);
621 /* Finish tearing down the quota file */
622 dqfileclose(qfp
, type
);
624 vnode_clearnoflush(qvp
);
625 error
= vnode_close(qvp
, FREAD
|FWRITE
, NULL
);
629 if (IS_VALID_CRED(qfp
->qf_cred
))
630 kauth_cred_unref(&qfp
->qf_cred
);
631 for (type
= 0; type
< MAXQUOTAS
; type
++)
632 if (hfsmp
->hfs_qfiles
[type
].qf_vp
!= NULLVP
)
634 if (type
== MAXQUOTAS
) {
635 vfs_clearflags(mp
, (u_int64_t
)((unsigned int)MNT_QUOTA
));
636 HFS_MOUNT_LOCK(hfsmp
, TRUE
)
637 hfsmp
->hfs_flags
&= ~HFS_QUOTAS
;
638 HFS_MOUNT_UNLOCK(hfsmp
, TRUE
);
641 qf_put(qfp
, QTF_CLOSING
);
647 * Q_GETQUOTA - return current values in a dqblk structure.
650 hfs_getquota(mp
, id
, type
, datap
)
659 error
= dqget(id
, &VFSTOHFS(mp
)->hfs_qfiles
[type
], type
, &dq
);
664 bcopy(&dq
->dq_dqb
, datap
, sizeof(dq
->dq_dqb
));
673 * Q_SETQUOTA - assign an entire dqblk structure.
676 hfs_setquota(mp
, id
, type
, datap
)
683 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
684 struct dqblk
* newlimp
= (struct dqblk
*) datap
;
688 error
= dqget(id
, &hfsmp
->hfs_qfiles
[type
], type
, &dq
);
694 * Copy all but the current values.
695 * Reset time limit if previously had no soft limit or were
696 * under it, but now have a soft limit and are over it.
698 newlimp
->dqb_curbytes
= dq
->dq_curbytes
;
699 newlimp
->dqb_curinodes
= dq
->dq_curinodes
;
700 if (dq
->dq_id
!= 0) {
701 newlimp
->dqb_btime
= dq
->dq_btime
;
702 newlimp
->dqb_itime
= dq
->dq_itime
;
704 if (newlimp
->dqb_bsoftlimit
&&
705 dq
->dq_curbytes
>= newlimp
->dqb_bsoftlimit
&&
706 (dq
->dq_bsoftlimit
== 0 || dq
->dq_curbytes
< dq
->dq_bsoftlimit
)) {
708 newlimp
->dqb_btime
= tv
.tv_sec
+ hfsmp
->hfs_qfiles
[type
].qf_btime
;
710 if (newlimp
->dqb_isoftlimit
&&
711 dq
->dq_curinodes
>= newlimp
->dqb_isoftlimit
&&
712 (dq
->dq_isoftlimit
== 0 || dq
->dq_curinodes
< dq
->dq_isoftlimit
)) {
714 newlimp
->dqb_itime
= tv
.tv_sec
+ hfsmp
->hfs_qfiles
[type
].qf_itime
;
716 bcopy(newlimp
, &dq
->dq_dqb
, sizeof(dq
->dq_dqb
));
717 if (dq
->dq_curbytes
< dq
->dq_bsoftlimit
)
718 dq
->dq_flags
&= ~DQ_BLKS
;
719 if (dq
->dq_curinodes
< dq
->dq_isoftlimit
)
720 dq
->dq_flags
&= ~DQ_INODS
;
721 if (dq
->dq_isoftlimit
== 0 && dq
->dq_bsoftlimit
== 0 &&
722 dq
->dq_ihardlimit
== 0 && dq
->dq_bhardlimit
== 0)
723 dq
->dq_flags
|= DQ_FAKE
;
725 dq
->dq_flags
&= ~DQ_FAKE
;
726 dq
->dq_flags
|= DQ_MOD
;
735 * Q_SETUSE - set current cnode and byte usage.
738 hfs_setuse(mp
, id
, type
, datap
)
744 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
748 struct dqblk
*quotablkp
= (struct dqblk
*) datap
;
750 error
= dqget(id
, &hfsmp
->hfs_qfiles
[type
], type
, &dq
);
756 * Reset time limit if have a soft limit and were
757 * previously under it, but are now over it.
759 if (dq
->dq_bsoftlimit
&& dq
->dq_curbytes
< dq
->dq_bsoftlimit
&&
760 quotablkp
->dqb_curbytes
>= dq
->dq_bsoftlimit
) {
762 dq
->dq_btime
= tv
.tv_sec
+ hfsmp
->hfs_qfiles
[type
].qf_btime
;
764 if (dq
->dq_isoftlimit
&& dq
->dq_curinodes
< dq
->dq_isoftlimit
&&
765 quotablkp
->dqb_curinodes
>= dq
->dq_isoftlimit
) {
767 dq
->dq_itime
= tv
.tv_sec
+ hfsmp
->hfs_qfiles
[type
].qf_itime
;
769 dq
->dq_curbytes
= quotablkp
->dqb_curbytes
;
770 dq
->dq_curinodes
= quotablkp
->dqb_curinodes
;
771 if (dq
->dq_curbytes
< dq
->dq_bsoftlimit
)
772 dq
->dq_flags
&= ~DQ_BLKS
;
773 if (dq
->dq_curinodes
< dq
->dq_isoftlimit
)
774 dq
->dq_flags
&= ~DQ_INODS
;
775 dq
->dq_flags
|= DQ_MOD
;
785 * Q_SYNC - sync quota files to disk.
788 hfs_qsync_callback(struct vnode
*vp
, __unused
void *cargs
)
796 for (i
= 0; i
< MAXQUOTAS
; i
++) {
798 if (dq
!= NODQUOT
&& (dq
->dq_flags
& DQ_MOD
))
801 return (VNODE_RETURNED
);
808 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
811 if (!dqisinitialized())
815 * Check if the mount point has any quotas.
816 * If not, simply return.
818 for (i
= 0; i
< MAXQUOTAS
; i
++)
819 if (hfsmp
->hfs_qfiles
[i
].qf_vp
!= NULLVP
)
825 * Sync out any orpaned dirty dquot entries.
827 for (i
= 0; i
< MAXQUOTAS
; i
++)
828 if (hfsmp
->hfs_qfiles
[i
].qf_vp
!= NULLVP
)
829 dqsync_orphans(&hfsmp
->hfs_qfiles
[i
]);
832 * Search vnodes associated with this mount point,
833 * synchronizing any modified dquot structures.
835 * hfs_qsync_callback will be called for each vnode
836 * hung off of this mount point
838 * properly referenced and unreferenced around the callback
840 vnode_iterate(mp
, 0, hfs_qsync_callback
, (void *)NULL
);
846 * Q_QUOTASTAT - get quota on/off status
849 hfs_quotastat(mp
, type
, datap
)
854 struct hfsmount
*hfsmp
= VFSTOHFS(mp
);
858 if ((((unsigned int)vfs_flags(mp
)) & MNT_QUOTA
) && (hfsmp
->hfs_qfiles
[type
].qf_vp
!= NULLVP
))
859 qstat
= 1; /* quotas are on for this type */
861 qstat
= 0; /* quotas are off for this type */
863 *((int *)datap
) = qstat
;