2 * Copyright (c) 2000-2014 Apple Inc. All rights reserved.
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
30 * hfs_attrlist.c - HFS attribute list processing
32 * Copyright (c) 1998-2002, Apple Computer, Inc. All Rights Reserved.
35 #include <sys/param.h>
36 #include <sys/systm.h>
37 #include <sys/kernel.h>
38 #include <sys/malloc.h>
41 #include <sys/unistd.h>
42 #include <sys/mount_internal.h>
43 #include <sys/kauth.h>
44 #include <sys/fsctl.h>
46 #include <kern/locks.h>
49 #include "hfs_cnode.h"
50 #include "hfs_mount.h"
52 #include "hfs_attrlist.h"
53 #include "hfs_btreeio.h"
55 /* Packing routines: */
57 static void packnameattr(struct attrblock
*abp
, struct vnode
*vp
,
58 const u_int8_t
*name
, int namelen
);
60 static void packcommonattr(struct attrblock
*abp
, struct hfsmount
*hfsmp
,
61 struct vnode
*vp
, struct cat_desc
* cdp
,
62 struct cat_attr
* cap
, struct vfs_context
*ctx
);
64 static void packfileattr(struct attrblock
*abp
, struct hfsmount
*hfsmp
,
65 struct cat_attr
*cattrp
, struct cat_fork
*datafork
,
66 struct cat_fork
*rsrcfork
, struct vnode
*vp
);
68 static void packdirattr(struct attrblock
*abp
, struct hfsmount
*hfsmp
,
69 struct vnode
*vp
, struct cat_desc
* descp
,
70 struct cat_attr
* cattrp
);
72 static u_int32_t
hfs_real_user_access(vnode_t vp
, vfs_context_t ctx
);
74 static void get_vattr_data_for_attrs(struct attrlist
*, struct vnode_attr
*,
75 struct hfsmount
*, struct vnode
*, struct cat_desc
*, struct cat_attr
*,
76 struct cat_fork
*, struct cat_fork
*, vfs_context_t
);
78 static void vattr_data_for_common_attrs(struct attrlist
*, struct vnode_attr
*,
79 struct hfsmount
*, struct vnode
*, struct cat_desc
*, struct cat_attr
*,
82 static void vattr_data_for_dir_attrs(struct attrlist
*, struct vnode_attr
*,
83 struct hfsmount
*, struct vnode
*, struct cat_desc
*, struct cat_attr
*);
85 static void vattr_data_for_file_attrs(struct attrlist
*, struct vnode_attr
*,
86 struct hfsmount
*, struct cat_attr
*, struct cat_fork
*, struct cat_fork
*,
89 static int hfs_readdirattr_internal(struct vnode
*, struct attrlist
*,
90 struct vnode_attr
*, uio_t
, uint64_t, int, uint32_t *, int *, int *,
94 * readdirattr operation will return attributes for the items in the
95 * directory specified.
97 * It does not do . and .. entries. The problem is if you are at the root of the
98 * hfs directory and go to .. you could be crossing a mountpoint into a
99 * different (ufs) file system. The attributes that apply for it may not
100 * apply for the file system you are doing the readdirattr on. To make life
101 * simpler, this call will only return entries in its directory, hfs like.
104 hfs_vnop_readdirattr(ap
)
105 struct vnop_readdirattr_args
/* {
107 struct attrlist *a_alist;
113 u_long *a_actualcount;
114 vfs_context_t a_context;
118 struct attrlist
*alist
= ap
->a_alist
;
120 /* Check for invalid options and buffer space. */
121 if (((ap
->a_options
& ~(FSOPT_NOINMEMUPDATE
| FSOPT_NOFOLLOW
)) != 0) ||
122 (ap
->a_maxcount
<= 0)) {
126 * Reject requests for unsupported attributes.
128 if ((alist
->bitmapcount
!= ATTR_BIT_MAP_COUNT
) ||
129 (alist
->commonattr
& ~HFS_ATTR_CMN_VALID
) ||
130 (alist
->volattr
!= 0) ||
131 (alist
->dirattr
& ~HFS_ATTR_DIR_VALID
) ||
132 (alist
->fileattr
& ~HFS_ATTR_FILE_VALID
) ||
133 (alist
->forkattr
!= 0)) {
137 error
= hfs_readdirattr_internal(ap
->a_vp
, alist
, NULL
, ap
->a_uio
,
138 (uint64_t)ap
->a_options
, ap
->a_maxcount
, ap
->a_newstate
,
139 ap
->a_eofflag
, (int *)ap
->a_actualcount
, ap
->a_context
);
146 * getattrlistbulk, like readdirattr, will return attributes for the items in
147 * the directory specified.
149 * It does not do . and .. entries. The problem is if you are at the root of the
150 * hfs directory and go to .. you could be crossing a mountpoint into a
151 * different (ufs) file system. The attributes that apply for it may not
152 * apply for the file system you are doing the readdirattr on. To make life
153 * simpler, this call will only return entries in its directory, hfs like.
156 hfs_vnop_getattrlistbulk(ap
)
157 struct vnop_getattrlistbulk_args
/* {
158 struct vnodeop_desc *a_desc;
160 struct attrlist *a_alist;
161 struct vnode_attr *a_vap;
166 int32_t *a_actualcount;
167 vfs_context_t a_context;
172 error
= hfs_readdirattr_internal(ap
->a_vp
, ap
->a_alist
, ap
->a_vap
,
173 ap
->a_uio
, (uint64_t)ap
->a_options
, 0, NULL
, ap
->a_eofflag
,
174 (int *)ap
->a_actualcount
, ap
->a_context
);
180 * Common function for both hfs_vnop_readdirattr and hfs_vnop_getattrlistbulk.
181 * This either fills in a vnode_attr structure or fills in an attrbute buffer
182 * Currently the difference in behaviour required for the two vnops is keyed
183 * on whether the passed in vnode_attr pointer is null or not. If the pointer
184 * is null we fill in buffer passed and if it is not null we fill in the fields
185 * of the vnode_attr structure.
188 hfs_readdirattr_internal(struct vnode
*dvp
, struct attrlist
*alist
,
189 struct vnode_attr
*vap
, uio_t uio
, uint64_t options
, int maxcount
,
190 uint32_t *newstate
, int *eofflag
, int *actualcount
, vfs_context_t ctx
)
193 struct hfsmount
* hfsmp
;
194 u_int32_t fixedblocksize
;
195 u_int32_t maxattrblocksize
;
196 u_int32_t currattrbufsize
;
197 void *attrbufptr
= NULL
;
198 void *attrptr
= NULL
;
200 caddr_t namebuf
= NULL
;
201 struct attrblock attrblk
;
205 struct cat_desc
*lastdescp
= NULL
;
206 struct cat_entrylist
*ce_list
= NULL
;
207 directoryhint_t
*dirhint
= NULL
;
211 u_int32_t dirchg
= 0;
217 if ((uio_resid(uio
) <= 0) || (uio_iovcnt(uio
) > 1))
220 if (VTOC(dvp
)->c_bsdflags
& UF_COMPRESSED
) {
221 int compressed
= hfs_file_is_compressed(VTOC(dvp
), 0); /* 0 == take the cnode lock */
224 error
= check_for_dataless_file(dvp
, NAMESPACE_HANDLER_READ_OP
);
232 * Take an exclusive directory lock since we manipulate the directory hints
234 if ((error
= hfs_lock(VTOC(dvp
), HFS_EXCLUSIVE_LOCK
, HFS_LOCK_DEFAULT
))) {
240 dirchg
= dcp
->c_dirchangecnt
;
242 /* Extract directory index and tag (sequence number) from uio_offset */
243 index
= uio_offset(uio
) & HFS_INDEX_MASK
;
244 tag
= uio_offset(uio
) & ~HFS_INDEX_MASK
;
247 * We can't just use the valence as an optimization to avoid
248 * going to the catalog. It might be wrong (== 0), and that would
249 * cause us to avoid iterating the directory when it might actually have
250 * contents. Instead, use the catalog to tell us when we've hit EOF
254 /* Get a buffer to hold packed attributes. */
255 fixedblocksize
= (sizeof(u_int32_t
) + hfs_attrblksize(alist
)); /* 4 bytes for length */
258 maxattrblocksize
= fixedblocksize
;
259 if (alist
->commonattr
& ATTR_CMN_NAME
)
260 maxattrblocksize
+= kHFSPlusMaxFileNameBytes
+ 1;
262 MALLOC(attrbufptr
, void *, maxattrblocksize
, M_TEMP
, M_WAITOK
);
263 if (attrbufptr
== NULL
) {
267 attrptr
= attrbufptr
;
268 varptr
= (char *)attrbufptr
+ fixedblocksize
; /* Point to variable-length storage */
270 if ((alist
->commonattr
& ATTR_CMN_NAME
) && !vap
->va_name
) {
271 MALLOC(namebuf
, caddr_t
, MAXPATHLEN
, M_TEMP
, M_WAITOK
);
276 vap
->va_name
= namebuf
;
279 /* Get a detached directory hint (cnode must be locked exclusive) */
280 dirhint
= hfs_getdirhint(dcp
, ((index
- 1) & HFS_INDEX_MASK
) | tag
, TRUE
);
282 /* Hide tag from catalog layer. */
283 dirhint
->dh_index
&= HFS_INDEX_MASK
;
284 if (dirhint
->dh_index
== HFS_INDEX_MASK
) {
285 dirhint
->dh_index
= -1;
289 * Obtain a list of catalog entries and pack their attributes until
290 * the output buffer is full or maxcount entries have been packed.
294 * Constrain our list size.
296 maxentries
= uio_resid(uio
) / (fixedblocksize
+ HFS_AVERAGE_NAME_SIZE
);
297 /* There is maxcount for the bulk vnop */
299 maxentries
= min(maxentries
, maxcount
);
300 maxentries
= min(maxentries
, MAXCATENTRIES
);
301 if (maxentries
< 1) {
306 /* Initialize a catalog entry list. */
307 MALLOC(ce_list
, struct cat_entrylist
*, CE_LIST_SIZE(maxentries
), M_TEMP
, M_WAITOK
);
308 if (ce_list
== NULL
) {
312 bzero(ce_list
, CE_LIST_SIZE(maxentries
));
313 ce_list
->maxentries
= maxentries
;
316 * Populate the ce_list from the catalog file.
318 lockflags
= hfs_systemfile_lock(hfsmp
, SFL_CATALOG
, HFS_SHARED_LOCK
);
320 error
= cat_getentriesattr(hfsmp
, dirhint
, ce_list
, &reachedeof
);
321 /* Don't forget to release the descriptors later! */
323 hfs_systemfile_unlock(hfsmp
, lockflags
);
325 if ((error
== ENOENT
) || (reachedeof
!= 0)) {
334 * Check for a FS corruption in the valence. We're holding the cnode lock
335 * exclusive since we need to serialize the directory hints, so if we found
336 * that the valence reported 0, but we actually found some items here, then
337 * silently minimally self-heal and bump the valence to 1.
339 if ((dcp
->c_entries
== 0) && (ce_list
->realentries
> 0)) {
341 dcp
->c_flag
|= (C_MODIFIED
| C_FORCEUPDATE
);
342 printf("hfs_vnop_readdirattr: repairing valence to non-zero! \n");
343 /* force an update on dcp while we're still holding the lock. */
348 * Drop the directory lock so we don't deadlock when we:
349 * - acquire a child cnode lock
350 * - make calls to vnode_authorize()
351 * - make calls to kauth_cred_ismember_gid()
356 /* Process the catalog entries. */
357 for (i
= 0; i
< (int)ce_list
->realentries
; ++i
) {
358 struct cnode
*cp
= NULL
;
359 struct vnode
*vp
= NULL
;
360 struct cat_desc
* cdescp
;
361 struct cat_attr
* cattrp
;
362 struct cat_fork c_datafork
;
363 struct cat_fork c_rsrcfork
;
365 bzero(&c_datafork
, sizeof(c_datafork
));
366 bzero(&c_rsrcfork
, sizeof(c_rsrcfork
));
367 cdescp
= &ce_list
->entry
[i
].ce_desc
;
368 cattrp
= &ce_list
->entry
[i
].ce_attr
;
369 c_datafork
.cf_size
= ce_list
->entry
[i
].ce_datasize
;
370 c_datafork
.cf_blocks
= ce_list
->entry
[i
].ce_datablks
;
371 c_rsrcfork
.cf_size
= ce_list
->entry
[i
].ce_rsrcsize
;
372 c_rsrcfork
.cf_blocks
= ce_list
->entry
[i
].ce_rsrcblks
;
374 if (((alist
->commonattr
& ATTR_CMN_USERACCESS
) &&
375 (cattrp
->ca_recflags
& kHFSHasSecurityMask
))
378 ((alist
->commonattr
& ATTR_CMN_DATA_PROTECT_FLAGS
) && (vap
))
382 * Obtain vnode for our vnode_authorize() calls.
384 if (hfs_vget(hfsmp
, cattrp
->ca_fileid
, &vp
, 0, 0) != 0) {
387 } else if (vap
|| !(options
& FSOPT_NOINMEMUPDATE
)) {
388 /* Get in-memory cnode data (if any). */
389 vp
= hfs_chash_getvnode(hfsmp
, cattrp
->ca_fileid
, 0, 0, 0);
393 /* Only use cnode's decriptor for non-hardlinks */
394 if (!(cp
->c_flag
& C_HARDLINK
))
395 cdescp
= &cp
->c_desc
;
396 cattrp
= &cp
->c_attr
;
397 if (cp
->c_datafork
) {
398 c_datafork
.cf_size
= cp
->c_datafork
->ff_size
;
399 c_datafork
.cf_blocks
= cp
->c_datafork
->ff_blocks
;
401 if (cp
->c_rsrcfork
) {
402 c_rsrcfork
.cf_size
= cp
->c_rsrcfork
->ff_size
;
403 c_rsrcfork
.cf_blocks
= cp
->c_rsrcfork
->ff_blocks
;
405 /* All done with cnode. */
411 *((u_int32_t
*)attrptr
) = 0;
412 attrptr
= ((u_int32_t
*)attrptr
) + 1;
413 attrblk
.ab_attrlist
= alist
;
414 attrblk
.ab_attrbufpp
= &attrptr
;
415 attrblk
.ab_varbufpp
= &varptr
;
416 attrblk
.ab_flags
= 0;
417 attrblk
.ab_blocksize
= maxattrblocksize
;
418 attrblk
.ab_context
= ctx
;
420 /* Pack catalog entries into attribute buffer. */
421 hfs_packattrblk(&attrblk
, hfsmp
, vp
, cdescp
, cattrp
, &c_datafork
, &c_rsrcfork
, ctx
);
422 currattrbufsize
= ((char *)varptr
- (char *)attrbufptr
);
424 /* All done with vnode. */
430 /* Make sure there's enough buffer space remaining. */
431 // LP64todo - fix this!
432 if (uio_resid(uio
) < 0 ||
433 currattrbufsize
> (u_int32_t
)uio_resid(uio
)) {
436 *((u_int32_t
*)attrbufptr
) = currattrbufsize
;
437 error
= uiomove((caddr_t
)attrbufptr
, currattrbufsize
, uio
);
438 if (error
!= E_NONE
) {
441 attrptr
= attrbufptr
;
442 /* Point to variable-length storage */
443 varptr
= (char *)attrbufptr
+ fixedblocksize
;
444 /* Save the last valid catalog entry */
445 lastdescp
= &ce_list
->entry
[i
].ce_desc
;
449 /* Termination checks */
450 if ((--maxcount
<= 0) ||
451 // LP64todo - fix this!
452 uio_resid(uio
) < 0 ||
453 ((u_int32_t
)uio_resid(uio
) < (fixedblocksize
+ HFS_AVERAGE_NAME_SIZE
))){
458 size_t orig_resid
= (size_t)uio_resid(uio
);
461 get_vattr_data_for_attrs(alist
, vap
, hfsmp
, vp
, cdescp
,
462 cattrp
, &c_datafork
, &c_rsrcfork
, ctx
);
465 if ((alist
->commonattr
& ATTR_CMN_DATA_PROTECT_FLAGS
) &&
469 if (!cp_vnode_getclass(vp
, &class)) {
470 VATTR_RETURN(vap
, va_dataprotect_class
,
475 error
= vfs_attr_pack(vp
, uio
, alist
, options
, vap
,
478 /* All done with vnode. */
484 resid
= uio_resid(uio
);
486 /* Was this entry succesful ? */
487 if (error
|| resid
== orig_resid
)
490 /* Save the last valid catalog entry */
491 lastdescp
= &ce_list
->entry
[i
].ce_desc
;
495 /* Do we have the bare minimum for the next entry ? */
496 if (resid
< sizeof(uint32_t))
499 } /* for each catalog entry */
501 /* If we skipped catalog entries for reserved files that should
502 * not be listed in namespace, update the index accordingly.
504 if (ce_list
->skipentries
) {
505 index
+= ce_list
->skipentries
;
506 ce_list
->skipentries
= 0;
510 * If there are more entries then save the last name.
511 * Key this behavior based on whether or not we observed EOFFLAG.
513 * Do not use the valence as a way to determine if we hit EOF, since
514 * it can be wrong. Use the catalog's output only.
516 if ((*(eofflag
) == 0) && lastdescp
!= NULL
) {
518 /* Remember last entry */
519 if ((dirhint
->dh_desc
.cd_flags
& CD_HASBUF
) &&
520 (dirhint
->dh_desc
.cd_nameptr
!= NULL
)) {
521 dirhint
->dh_desc
.cd_flags
&= ~CD_HASBUF
;
522 vfs_removename((const char *)dirhint
->dh_desc
.cd_nameptr
);
524 dirhint
->dh_desc
.cd_namelen
= lastdescp
->cd_namelen
;
525 dirhint
->dh_desc
.cd_nameptr
= (const u_int8_t
*)
526 vfs_addname((const char *)lastdescp
->cd_nameptr
, lastdescp
->cd_namelen
, 0, 0);
527 dirhint
->dh_desc
.cd_flags
|= CD_HASBUF
;
528 dirhint
->dh_index
= index
- 1;
529 dirhint
->dh_desc
.cd_cnid
= lastdescp
->cd_cnid
;
530 dirhint
->dh_desc
.cd_hint
= lastdescp
->cd_hint
;
531 dirhint
->dh_desc
.cd_encoding
= lastdescp
->cd_encoding
;
534 /* All done with the catalog descriptors. */
535 for (i
= 0; i
< (int)ce_list
->realentries
; ++i
)
536 cat_releasedesc(&ce_list
->entry
[i
].ce_desc
);
537 ce_list
->realentries
= 0;
539 (void) hfs_lock(VTOC(dvp
), HFS_EXCLUSIVE_LOCK
, HFS_LOCK_ALLOW_NOEXISTS
);
543 /* Pack directory index and tag into uio_offset. */
544 while (tag
== 0) tag
= (++dcp
->c_dirhinttag
) << HFS_INDEX_BITS
;
545 uio_setoffset(uio
, index
| tag
);
546 dirhint
->dh_index
|= tag
;
553 * Drop directory hint on error or if there are no more entries,
554 * only if EOF was seen.
557 if ((error
!= 0) || *(eofflag
))
558 hfs_reldirhint(dcp
, dirhint
);
560 hfs_insertdirhint(dcp
, dirhint
);
563 FREE(namebuf
, M_TEMP
);
567 FREE(attrbufptr
, M_TEMP
);
569 FREE(ce_list
, M_TEMP
);
571 if (vap
&& *actualcount
&& error
)
579 /*==================== Attribute list support routines ====================*/
582 * Pack cnode attributes into an attribute block.
586 hfs_packattrblk(struct attrblock
*abp
,
587 struct hfsmount
*hfsmp
,
589 struct cat_desc
*descp
,
590 struct cat_attr
*attrp
,
591 struct cat_fork
*datafork
,
592 struct cat_fork
*rsrcfork
,
593 struct vfs_context
*ctx
)
595 struct attrlist
*attrlistp
= abp
->ab_attrlist
;
597 if (attrlistp
->commonattr
)
598 packcommonattr(abp
, hfsmp
, vp
, descp
, attrp
, ctx
);
600 if (attrlistp
->dirattr
&& S_ISDIR(attrp
->ca_mode
))
601 packdirattr(abp
, hfsmp
, vp
, descp
,attrp
);
603 if (attrlistp
->fileattr
&& !S_ISDIR(attrp
->ca_mode
))
604 packfileattr(abp
, hfsmp
, attrp
, datafork
, rsrcfork
, vp
);
609 mountpointname(struct mount
*mp
)
611 size_t namelength
= strlen(mp
->mnt_vfsstat
.f_mntonname
);
619 * Look backwards through the name string, looking for
620 * the first slash encountered (which must precede the
621 * last part of the pathname).
623 for (c
= mp
->mnt_vfsstat
.f_mntonname
+ namelength
- 1;
624 namelength
> 0; --c
, --namelength
) {
627 } else if (foundchars
) {
632 return (mp
->mnt_vfsstat
.f_mntonname
);
638 struct attrblock
*abp
,
640 const u_int8_t
*name
,
644 struct attrreference
* attr_refptr
;
647 u_int32_t attrlength
;
650 /* A cnode's name may be incorrect for the root of a mounted
651 * filesystem (it can be mounted on a different directory name
652 * than the name of the volume, such as "blah-1"). So for the
653 * root directory, it's best to return the last element of the
654 location where the volume's mounted:
656 if ((vp
!= NULL
) && vnode_isvroot(vp
) &&
657 (mpname
= mountpointname(vnode_mount(vp
)))) {
658 mpnamelen
= strlen(mpname
);
660 /* Trim off any trailing slashes: */
661 while ((mpnamelen
> 0) && (mpname
[mpnamelen
-1] == '/'))
664 /* If there's anything left, use it instead of the volume's name */
666 name
= (u_int8_t
*)mpname
;
675 varbufptr
= *abp
->ab_varbufpp
;
676 attr_refptr
= (struct attrreference
*)(*abp
->ab_attrbufpp
);
678 attrlength
= namelen
+ 1;
679 attr_refptr
->attr_dataoffset
= (char *)varbufptr
- (char *)attr_refptr
;
680 attr_refptr
->attr_length
= attrlength
;
681 (void) strncpy((char *)varbufptr
, (const char *) name
, attrlength
);
683 * Advance beyond the space just allocated and
684 * round up to the next 4-byte boundary:
686 varbufptr
= ((char *)varbufptr
) + attrlength
+ ((4 - (attrlength
& 3)) & 3);
689 *abp
->ab_attrbufpp
= attr_refptr
;
690 *abp
->ab_varbufpp
= varbufptr
;
695 struct attrblock
*abp
,
696 struct hfsmount
*hfsmp
,
698 struct cat_desc
* cdp
,
699 struct cat_attr
* cap
,
700 struct vfs_context
* ctx
)
702 attrgroup_t attr
= abp
->ab_attrlist
->commonattr
;
703 struct mount
*mp
= HFSTOVFS(hfsmp
);
704 void *attrbufptr
= *abp
->ab_attrbufpp
;
705 void *varbufptr
= *abp
->ab_varbufpp
;
706 boolean_t is_64_bit
= proc_is64bit(vfs_context_proc(ctx
));
710 if (attr
& (ATTR_CMN_OWNERID
| ATTR_CMN_GRPID
)) {
711 cuid
= kauth_cred_getuid(vfs_context_ucred(ctx
));
715 if (ATTR_CMN_NAME
& attr
) {
716 packnameattr(abp
, vp
, cdp
->cd_nameptr
, cdp
->cd_namelen
);
717 attrbufptr
= *abp
->ab_attrbufpp
;
718 varbufptr
= *abp
->ab_varbufpp
;
720 if (ATTR_CMN_DEVID
& attr
) {
721 *((dev_t
*)attrbufptr
) = hfsmp
->hfs_raw_dev
;
722 attrbufptr
= ((dev_t
*)attrbufptr
) + 1;
724 if (ATTR_CMN_FSID
& attr
) {
727 fsid
.val
[0] = hfsmp
->hfs_raw_dev
;
728 fsid
.val
[1] = vfs_typenum(mp
);
729 *((fsid_t
*)attrbufptr
) = fsid
;
730 attrbufptr
= ((fsid_t
*)attrbufptr
) + 1;
732 if (ATTR_CMN_OBJTYPE
& attr
) {
733 *((fsobj_type_t
*)attrbufptr
) = IFTOVT(cap
->ca_mode
);
734 attrbufptr
= ((fsobj_type_t
*)attrbufptr
) + 1;
736 if (ATTR_CMN_OBJTAG
& attr
) {
737 *((fsobj_tag_t
*)attrbufptr
) = VT_HFS
;
738 attrbufptr
= ((fsobj_tag_t
*)attrbufptr
) + 1;
741 * Exporting file IDs from HFS Plus:
743 * For "normal" files the c_fileid is the same value as the
744 * c_cnid. But for hard link files, they are different - the
745 * c_cnid belongs to the active directory entry (ie the link)
746 * and the c_fileid is for the actual inode (ie the data file).
748 * The stat call (getattr) will always return the c_fileid
749 * and Carbon APIs, which are hardlink-ignorant, will always
750 * receive the c_cnid (from getattrlist).
752 if (ATTR_CMN_OBJID
& attr
) {
753 ((fsobj_id_t
*)attrbufptr
)->fid_objno
= cdp
->cd_cnid
;
754 ((fsobj_id_t
*)attrbufptr
)->fid_generation
= 0;
755 attrbufptr
= ((fsobj_id_t
*)attrbufptr
) + 1;
757 if (ATTR_CMN_OBJPERMANENTID
& attr
) {
758 ((fsobj_id_t
*)attrbufptr
)->fid_objno
= cdp
->cd_cnid
;
759 ((fsobj_id_t
*)attrbufptr
)->fid_generation
= 0;
760 attrbufptr
= ((fsobj_id_t
*)attrbufptr
) + 1;
762 if (ATTR_CMN_PAROBJID
& attr
) {
763 ((fsobj_id_t
*)attrbufptr
)->fid_objno
= cdp
->cd_parentcnid
;
764 ((fsobj_id_t
*)attrbufptr
)->fid_generation
= 0;
765 attrbufptr
= ((fsobj_id_t
*)attrbufptr
) + 1;
767 if (ATTR_CMN_SCRIPT
& attr
) {
768 *((text_encoding_t
*)attrbufptr
) = cdp
->cd_encoding
;
769 attrbufptr
= ((text_encoding_t
*)attrbufptr
) + 1;
771 if (ATTR_CMN_CRTIME
& attr
) {
773 ((struct user64_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_itime
;
774 ((struct user64_timespec
*)attrbufptr
)->tv_nsec
= 0;
775 attrbufptr
= ((struct user64_timespec
*)attrbufptr
) + 1;
778 ((struct user32_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_itime
;
779 ((struct user32_timespec
*)attrbufptr
)->tv_nsec
= 0;
780 attrbufptr
= ((struct user32_timespec
*)attrbufptr
) + 1;
783 if (ATTR_CMN_MODTIME
& attr
) {
785 ((struct user64_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_mtime
;
786 ((struct user64_timespec
*)attrbufptr
)->tv_nsec
= 0;
787 attrbufptr
= ((struct user64_timespec
*)attrbufptr
) + 1;
790 ((struct user32_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_mtime
;
791 ((struct user32_timespec
*)attrbufptr
)->tv_nsec
= 0;
792 attrbufptr
= ((struct user32_timespec
*)attrbufptr
) + 1;
795 if (ATTR_CMN_CHGTIME
& attr
) {
797 ((struct user64_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_ctime
;
798 ((struct user64_timespec
*)attrbufptr
)->tv_nsec
= 0;
799 attrbufptr
= ((struct user64_timespec
*)attrbufptr
) + 1;
802 ((struct user32_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_ctime
;
803 ((struct user32_timespec
*)attrbufptr
)->tv_nsec
= 0;
804 attrbufptr
= ((struct user32_timespec
*)attrbufptr
) + 1;
807 if (ATTR_CMN_ACCTIME
& attr
) {
809 ((struct user64_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_atime
;
810 ((struct user64_timespec
*)attrbufptr
)->tv_nsec
= 0;
811 attrbufptr
= ((struct user64_timespec
*)attrbufptr
) + 1;
814 ((struct user32_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_atime
;
815 ((struct user32_timespec
*)attrbufptr
)->tv_nsec
= 0;
816 attrbufptr
= ((struct user32_timespec
*)attrbufptr
) + 1;
819 if (ATTR_CMN_BKUPTIME
& attr
) {
821 ((struct user64_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_btime
;
822 ((struct user64_timespec
*)attrbufptr
)->tv_nsec
= 0;
823 attrbufptr
= ((struct user64_timespec
*)attrbufptr
) + 1;
826 ((struct user32_timespec
*)attrbufptr
)->tv_sec
= cap
->ca_btime
;
827 ((struct user32_timespec
*)attrbufptr
)->tv_nsec
= 0;
828 attrbufptr
= ((struct user32_timespec
*)attrbufptr
) + 1;
831 if (ATTR_CMN_FNDRINFO
& attr
) {
832 u_int8_t
*finfo
= NULL
;
833 bcopy(&cap
->ca_finderinfo
, attrbufptr
, sizeof(u_int8_t
) * 32);
834 finfo
= (u_int8_t
*)attrbufptr
;
836 /* Don't expose a symlink's private type/creator. */
837 if (S_ISLNK(cap
->ca_mode
)) {
838 struct FndrFileInfo
*fip
;
840 fip
= (struct FndrFileInfo
*)attrbufptr
;
845 /* advance 16 bytes into the attrbuf */
848 /* also don't expose the date_added or write_gen_counter fields */
849 if (S_ISREG(cap
->ca_mode
) || S_ISLNK(cap
->ca_mode
)) {
850 struct FndrExtendedFileInfo
*extinfo
= (struct FndrExtendedFileInfo
*)finfo
;
851 extinfo
->document_id
= 0;
852 extinfo
->date_added
= 0;
853 extinfo
->write_gen_counter
= 0;
855 else if (S_ISDIR(cap
->ca_mode
)) {
856 struct FndrExtendedDirInfo
*extinfo
= (struct FndrExtendedDirInfo
*)finfo
;
857 extinfo
->document_id
= 0;
858 extinfo
->date_added
= 0;
859 extinfo
->write_gen_counter
= 0;
862 attrbufptr
= (char *)attrbufptr
+ sizeof(u_int8_t
) * 32;
864 if (ATTR_CMN_OWNERID
& attr
) {
865 uid_t nuid
= cap
->ca_uid
;
868 if (((unsigned int)vfs_flags(HFSTOVFS(hfsmp
))) & MNT_UNKNOWNPERMISSIONS
)
870 else if (nuid
== UNKNOWNUID
)
874 *((uid_t
*)attrbufptr
) = nuid
;
875 attrbufptr
= ((uid_t
*)attrbufptr
) + 1;
877 if (ATTR_CMN_GRPID
& attr
) {
878 gid_t ngid
= cap
->ca_gid
;
881 gid_t cgid
= kauth_cred_getgid(vfs_context_ucred(ctx
));
882 if (((unsigned int)vfs_flags(HFSTOVFS(hfsmp
))) & MNT_UNKNOWNPERMISSIONS
)
884 else if (ngid
== UNKNOWNUID
)
888 *((gid_t
*)attrbufptr
) = ngid
;
889 attrbufptr
= ((gid_t
*)attrbufptr
) + 1;
891 if (ATTR_CMN_ACCESSMASK
& attr
) {
893 * [2856576] Since we are dynamically changing the owner, also
894 * effectively turn off the set-user-id and set-group-id bits,
895 * just like chmod(2) would when changing ownership. This prevents
896 * a security hole where set-user-id programs run as whoever is
897 * logged on (or root if nobody is logged in yet!)
899 *((u_int32_t
*)attrbufptr
) = (cap
->ca_uid
== UNKNOWNUID
) ?
900 cap
->ca_mode
& ~(S_ISUID
| S_ISGID
) : cap
->ca_mode
;
901 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
903 if (ATTR_CMN_FLAGS
& attr
) {
904 *((u_int32_t
*)attrbufptr
) = cap
->ca_flags
;
905 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
907 if (ATTR_CMN_USERACCESS
& attr
) {
908 u_int32_t user_access
;
910 /* Take the long path when we have an ACL */
911 if ((vp
!= NULLVP
) && (cap
->ca_recflags
& kHFSHasSecurityMask
)) {
912 user_access
= hfs_real_user_access(vp
, abp
->ab_context
);
914 user_access
= DerivePermissionSummary(cap
->ca_uid
, cap
->ca_gid
,
915 cap
->ca_mode
, mp
, vfs_context_ucred(ctx
), 0);
917 /* Also consider READ-ONLY file system. */
918 if (vfs_flags(mp
) & MNT_RDONLY
) {
919 user_access
&= ~W_OK
;
921 /* Locked objects are not writable either */
922 if ((cap
->ca_flags
& UF_IMMUTABLE
) && (vfs_context_suser(abp
->ab_context
) != 0))
923 user_access
&= ~W_OK
;
924 if ((cap
->ca_flags
& SF_IMMUTABLE
) && (vfs_context_suser(abp
->ab_context
) == 0))
925 user_access
&= ~W_OK
;
927 *((u_int32_t
*)attrbufptr
) = user_access
;
928 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
930 if (ATTR_CMN_FILEID
& attr
) {
931 *((u_int64_t
*)attrbufptr
) = cap
->ca_fileid
;
932 attrbufptr
= ((u_int64_t
*)attrbufptr
) + 1;
934 if (ATTR_CMN_PARENTID
& attr
) {
935 *((u_int64_t
*)attrbufptr
) = cdp
->cd_parentcnid
;
936 attrbufptr
= ((u_int64_t
*)attrbufptr
) + 1;
939 *abp
->ab_attrbufpp
= attrbufptr
;
940 *abp
->ab_varbufpp
= varbufptr
;
945 struct attrblock
*abp
,
946 struct hfsmount
*hfsmp
,
948 struct cat_desc
* descp
,
949 struct cat_attr
* cattrp
)
951 attrgroup_t attr
= abp
->ab_attrlist
->dirattr
;
952 void *attrbufptr
= *abp
->ab_attrbufpp
;
956 * The DIR_LINKCOUNT is the count of real directory hard links.
957 * (i.e. its not the sum of the implied "." and ".." references
958 * typically used in stat's st_nlink field)
960 if (ATTR_DIR_LINKCOUNT
& attr
) {
961 *((u_int32_t
*)attrbufptr
) = cattrp
->ca_linkcount
;
962 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
964 if (ATTR_DIR_ENTRYCOUNT
& attr
) {
965 entries
= cattrp
->ca_entries
;
967 if (descp
->cd_parentcnid
== kHFSRootParentID
) {
968 if (hfsmp
->hfs_private_desc
[FILE_HARDLINKS
].cd_cnid
!= 0)
969 --entries
; /* hide private dir */
970 if (hfsmp
->hfs_private_desc
[DIR_HARDLINKS
].cd_cnid
!= 0)
971 --entries
; /* hide private dir */
973 ((hfsmp
->vcbAtrb
& kHFSVolumeJournaledMask
) &&
974 (hfsmp
->hfs_flags
& HFS_READ_ONLY
)))
975 entries
-= 2; /* hide the journal files */
978 *((u_int32_t
*)attrbufptr
) = entries
;
979 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
981 if (ATTR_DIR_MOUNTSTATUS
& attr
) {
982 if (vp
!= NULL
&& vnode_mountedhere(vp
) != NULL
)
983 *((u_int32_t
*)attrbufptr
) = DIR_MNTSTATUS_MNTPOINT
;
985 *((u_int32_t
*)attrbufptr
) = 0;
986 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
988 *abp
->ab_attrbufpp
= attrbufptr
;
993 struct attrblock
*abp
,
994 struct hfsmount
*hfsmp
,
995 struct cat_attr
*cattrp
,
996 struct cat_fork
*datafork
,
997 struct cat_fork
*rsrcfork
,
1000 #if !HFS_COMPRESSION
1003 attrgroup_t attr
= abp
->ab_attrlist
->fileattr
;
1004 void *attrbufptr
= *abp
->ab_attrbufpp
;
1005 void *varbufptr
= *abp
->ab_varbufpp
;
1006 u_int32_t allocblksize
;
1008 allocblksize
= HFSTOVCB(hfsmp
)->blockSize
;
1010 off_t datasize
= datafork
->cf_size
;
1011 off_t totalsize
= datasize
+ rsrcfork
->cf_size
;
1013 int handle_compressed
;
1014 handle_compressed
= (cattrp
->ca_flags
& UF_COMPRESSED
);// && hfs_file_is_compressed(VTOC(vp), 1);
1016 if (handle_compressed
) {
1017 if (attr
& (ATTR_FILE_DATALENGTH
|ATTR_FILE_TOTALSIZE
)) {
1018 if ( 0 == hfs_uncompressed_size_of_compressed_file(hfsmp
, vp
, cattrp
->ca_fileid
, &datasize
, 1) ) { /* 1 == don't take the cnode lock */
1019 /* total size of a compressed file is just the data size */
1020 totalsize
= datasize
;
1026 if (ATTR_FILE_LINKCOUNT
& attr
) {
1027 *((u_int32_t
*)attrbufptr
) = cattrp
->ca_linkcount
;
1028 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
1030 if (ATTR_FILE_TOTALSIZE
& attr
) {
1031 *((off_t
*)attrbufptr
) = totalsize
;
1032 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1034 if (ATTR_FILE_ALLOCSIZE
& attr
) {
1035 *((off_t
*)attrbufptr
) =
1036 (off_t
)cattrp
->ca_blocks
* (off_t
)allocblksize
;
1037 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1039 if (ATTR_FILE_IOBLOCKSIZE
& attr
) {
1040 *((u_int32_t
*)attrbufptr
) = hfsmp
->hfs_logBlockSize
;
1041 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
1043 if (ATTR_FILE_CLUMPSIZE
& attr
) {
1044 *((u_int32_t
*)attrbufptr
) = hfsmp
->vcbClpSiz
;
1045 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
1047 if (ATTR_FILE_DEVTYPE
& attr
) {
1048 if (S_ISBLK(cattrp
->ca_mode
) || S_ISCHR(cattrp
->ca_mode
))
1049 *((u_int32_t
*)attrbufptr
) = (u_int32_t
)cattrp
->ca_rdev
;
1051 *((u_int32_t
*)attrbufptr
) = 0;
1052 attrbufptr
= ((u_int32_t
*)attrbufptr
) + 1;
1055 if (ATTR_FILE_DATALENGTH
& attr
) {
1056 *((off_t
*)attrbufptr
) = datasize
;
1057 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1061 /* fake the data fork size on a decmpfs compressed file to reflect the
1062 * uncompressed size. This ensures proper reading and copying of these files.
1063 * NOTE: we may need to get the vnode here because the vnode parameter
1064 * passed by hfs_vnop_readdirattr() may be null.
1067 if ( handle_compressed
) {
1068 if (attr
& ATTR_FILE_DATAALLOCSIZE
) {
1069 *((off_t
*)attrbufptr
) = (off_t
)rsrcfork
->cf_blocks
* (off_t
)allocblksize
;
1070 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1072 if (attr
& ATTR_FILE_RSRCLENGTH
) {
1073 *((off_t
*)attrbufptr
) = 0;
1074 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1076 if (attr
& ATTR_FILE_RSRCALLOCSIZE
) {
1077 *((off_t
*)attrbufptr
) = 0;
1078 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1084 if (ATTR_FILE_DATAALLOCSIZE
& attr
) {
1085 *((off_t
*)attrbufptr
) = (off_t
)datafork
->cf_blocks
* (off_t
)allocblksize
;
1086 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1088 if (ATTR_FILE_RSRCLENGTH
& attr
) {
1089 *((off_t
*)attrbufptr
) = rsrcfork
->cf_size
;
1090 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1092 if (ATTR_FILE_RSRCALLOCSIZE
& attr
) {
1093 *((off_t
*)attrbufptr
) = (off_t
)rsrcfork
->cf_blocks
* (off_t
)allocblksize
;
1094 attrbufptr
= ((off_t
*)attrbufptr
) + 1;
1097 *abp
->ab_attrbufpp
= attrbufptr
;
1098 *abp
->ab_varbufpp
= varbufptr
;
1102 * Calculate the total size of an attribute block.
1106 hfs_attrblksize(struct attrlist
*attrlist
)
1110 int sizeof_timespec
;
1111 boolean_t is_64_bit
= proc_is64bit(current_proc());
1114 sizeof_timespec
= sizeof(struct user64_timespec
);
1116 sizeof_timespec
= sizeof(struct user32_timespec
);
1118 DBG_ASSERT((attrlist
->commonattr
& ~ATTR_CMN_VALIDMASK
) == 0);
1120 DBG_ASSERT((attrlist
->volattr
& ~ATTR_VOL_VALIDMASK
) == 0);
1122 DBG_ASSERT((attrlist
->dirattr
& ~ATTR_DIR_VALIDMASK
) == 0);
1124 DBG_ASSERT((attrlist
->fileattr
& ~ATTR_FILE_VALIDMASK
) == 0);
1126 DBG_ASSERT((attrlist
->forkattr
& ~ATTR_FORK_VALIDMASK
) == 0);
1130 if ((a
= attrlist
->commonattr
) != 0) {
1131 if (a
& ATTR_CMN_NAME
) size
+= sizeof(struct attrreference
);
1132 if (a
& ATTR_CMN_DEVID
) size
+= sizeof(dev_t
);
1133 if (a
& ATTR_CMN_FSID
) size
+= sizeof(fsid_t
);
1134 if (a
& ATTR_CMN_OBJTYPE
) size
+= sizeof(fsobj_type_t
);
1135 if (a
& ATTR_CMN_OBJTAG
) size
+= sizeof(fsobj_tag_t
);
1136 if (a
& ATTR_CMN_OBJID
) size
+= sizeof(fsobj_id_t
);
1137 if (a
& ATTR_CMN_OBJPERMANENTID
) size
+= sizeof(fsobj_id_t
);
1138 if (a
& ATTR_CMN_PAROBJID
) size
+= sizeof(fsobj_id_t
);
1139 if (a
& ATTR_CMN_SCRIPT
) size
+= sizeof(text_encoding_t
);
1140 if (a
& ATTR_CMN_CRTIME
) size
+= sizeof_timespec
;
1141 if (a
& ATTR_CMN_MODTIME
) size
+= sizeof_timespec
;
1142 if (a
& ATTR_CMN_CHGTIME
) size
+= sizeof_timespec
;
1143 if (a
& ATTR_CMN_ACCTIME
) size
+= sizeof_timespec
;
1144 if (a
& ATTR_CMN_BKUPTIME
) size
+= sizeof_timespec
;
1145 if (a
& ATTR_CMN_FNDRINFO
) size
+= 32 * sizeof(u_int8_t
);
1146 if (a
& ATTR_CMN_OWNERID
) size
+= sizeof(uid_t
);
1147 if (a
& ATTR_CMN_GRPID
) size
+= sizeof(gid_t
);
1148 if (a
& ATTR_CMN_ACCESSMASK
) size
+= sizeof(u_int32_t
);
1149 if (a
& ATTR_CMN_FLAGS
) size
+= sizeof(u_int32_t
);
1150 if (a
& ATTR_CMN_USERACCESS
) size
+= sizeof(u_int32_t
);
1151 if (a
& ATTR_CMN_FILEID
) size
+= sizeof(u_int64_t
);
1152 if (a
& ATTR_CMN_PARENTID
) size
+= sizeof(u_int64_t
);
1154 if ((a
= attrlist
->dirattr
) != 0) {
1155 if (a
& ATTR_DIR_LINKCOUNT
) size
+= sizeof(u_int32_t
);
1156 if (a
& ATTR_DIR_ENTRYCOUNT
) size
+= sizeof(u_int32_t
);
1157 if (a
& ATTR_DIR_MOUNTSTATUS
) size
+= sizeof(u_int32_t
);
1159 if ((a
= attrlist
->fileattr
) != 0) {
1160 if (a
& ATTR_FILE_LINKCOUNT
) size
+= sizeof(u_int32_t
);
1161 if (a
& ATTR_FILE_TOTALSIZE
) size
+= sizeof(off_t
);
1162 if (a
& ATTR_FILE_ALLOCSIZE
) size
+= sizeof(off_t
);
1163 if (a
& ATTR_FILE_IOBLOCKSIZE
) size
+= sizeof(u_int32_t
);
1164 if (a
& ATTR_FILE_CLUMPSIZE
) size
+= sizeof(u_int32_t
);
1165 if (a
& ATTR_FILE_DEVTYPE
) size
+= sizeof(u_int32_t
);
1166 if (a
& ATTR_FILE_DATALENGTH
) size
+= sizeof(off_t
);
1167 if (a
& ATTR_FILE_DATAALLOCSIZE
) size
+= sizeof(off_t
);
1168 if (a
& ATTR_FILE_RSRCLENGTH
) size
+= sizeof(off_t
);
1169 if (a
& ATTR_FILE_RSRCALLOCSIZE
) size
+= sizeof(off_t
);
1175 #define KAUTH_DIR_WRITE_RIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_ADD_FILE | \
1176 KAUTH_VNODE_ADD_SUBDIRECTORY | \
1177 KAUTH_VNODE_DELETE_CHILD)
1179 #define KAUTH_DIR_READ_RIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_LIST_DIRECTORY)
1181 #define KAUTH_DIR_EXECUTE_RIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_SEARCH)
1183 #define KAUTH_FILE_WRITE_RIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_WRITE_DATA)
1185 #define KAUTH_FILE_READRIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_READ_DATA)
1187 #define KAUTH_FILE_EXECUTE_RIGHTS (KAUTH_VNODE_ACCESS | KAUTH_VNODE_EXECUTE)
1191 * Compute the same [expensive] user_access value as getattrlist does
1194 hfs_real_user_access(vnode_t vp
, vfs_context_t ctx
)
1196 u_int32_t user_access
= 0;
1198 if (vnode_isdir(vp
)) {
1199 if (vnode_authorize(vp
, NULLVP
, KAUTH_DIR_WRITE_RIGHTS
, ctx
) == 0)
1200 user_access
|= W_OK
;
1201 if (vnode_authorize(vp
, NULLVP
, KAUTH_DIR_READ_RIGHTS
, ctx
) == 0)
1202 user_access
|= R_OK
;
1203 if (vnode_authorize(vp
, NULLVP
, KAUTH_DIR_EXECUTE_RIGHTS
, ctx
) == 0)
1204 user_access
|= X_OK
;
1206 if (vnode_authorize(vp
, NULLVP
, KAUTH_FILE_WRITE_RIGHTS
, ctx
) == 0)
1207 user_access
|= W_OK
;
1208 if (vnode_authorize(vp
, NULLVP
, KAUTH_FILE_READRIGHTS
, ctx
) == 0)
1209 user_access
|= R_OK
;
1210 if (vnode_authorize(vp
, NULLVP
, KAUTH_FILE_EXECUTE_RIGHTS
, ctx
) == 0)
1211 user_access
|= X_OK
;
1213 return (user_access
);
1218 DerivePermissionSummary(uid_t obj_uid
, gid_t obj_gid
, mode_t obj_mode
,
1219 struct mount
*mp
, kauth_cred_t cred
, __unused
struct proc
*p
)
1221 u_int32_t permissions
;
1223 if (obj_uid
== UNKNOWNUID
)
1224 obj_uid
= kauth_cred_getuid(cred
);
1226 /* User id 0 (root) always gets access. */
1227 if (!suser(cred
, NULL
)) {
1228 permissions
= R_OK
| W_OK
| X_OK
;
1232 /* Otherwise, check the owner. */
1233 if (hfs_owner_rights(VFSTOHFS(mp
), obj_uid
, cred
, NULL
, false) == 0) {
1234 permissions
= ((u_int32_t
)obj_mode
& S_IRWXU
) >> 6;
1238 /* Otherwise, check the groups. */
1239 if (! (((unsigned int)vfs_flags(mp
)) & MNT_UNKNOWNPERMISSIONS
)) {
1242 if (kauth_cred_ismember_gid(cred
, obj_gid
, &is_member
) == 0 && is_member
) {
1243 permissions
= ((u_int32_t
)obj_mode
& S_IRWXG
) >> 3;
1248 /* Otherwise, settle for 'others' access. */
1249 permissions
= (u_int32_t
)obj_mode
& S_IRWXO
;
1252 return (permissions
);
1257 * ===========================================================================
1258 * Support functions for filling up a vnode_attr structure based on attributes
1260 * ===========================================================================
1263 get_vattr_data_for_attrs(struct attrlist
*alp
, struct vnode_attr
*vap
,
1264 struct hfsmount
*hfsmp
, struct vnode
*vp
, struct cat_desc
*descp
,
1265 struct cat_attr
*atrp
, struct cat_fork
*datafork
, struct cat_fork
*rsrcfork
,
1268 if (alp
->commonattr
)
1269 vattr_data_for_common_attrs(alp
, vap
, hfsmp
, vp
, descp
, atrp
,
1272 if (alp
->dirattr
&& S_ISDIR(atrp
->ca_mode
))
1273 vattr_data_for_dir_attrs(alp
, vap
, hfsmp
, vp
, descp
, atrp
);
1275 if (alp
->fileattr
&& !S_ISDIR(atrp
->ca_mode
)) {
1276 vattr_data_for_file_attrs(alp
, vap
, hfsmp
, atrp
, datafork
,
1282 copy_name_attr(struct vnode_attr
*vap
, struct vnode
*vp
, const u_int8_t
*name
,
1287 u_int32_t attrlength
;
1290 /* A cnode's name may be incorrect for the root of a mounted
1291 * filesystem (it can be mounted on a different directory name
1292 * than the name of the volume, such as "blah-1"). So for the
1293 * root directory, it's best to return the last element of the
1294 location where the volume's mounted:
1296 if ((vp
!= NULL
) && vnode_isvroot(vp
) &&
1297 (mpname
= mountpointname(vnode_mount(vp
)))) {
1298 mpnamelen
= strlen(mpname
);
1300 /* Trim off any trailing slashes: */
1301 while ((mpnamelen
> 0) && (mpname
[mpnamelen
-1] == '/'))
1304 /* If there's anything left, use it instead of the volume's name */
1305 if (mpnamelen
> 0) {
1306 name
= (u_int8_t
*)mpname
;
1307 namelen
= mpnamelen
;
1316 attrlength
= namelen
+ 1;
1317 (void) strncpy((char *)vap
->va_name
, (const char *) name
, attrlength
);
1319 * round upto 8 and zero out the rounded up bytes.
1321 attrlength
= min(kHFSPlusMaxFileNameBytes
, ((attrlength
+ 7) & ~0x07));
1322 bzero(vap
->va_name
+ attrlength
, kHFSPlusMaxFileNameBytes
- attrlength
);
1326 vattr_data_for_common_attrs( struct attrlist
*alp
, struct vnode_attr
*vap
,
1327 struct hfsmount
*hfsmp
, struct vnode
*vp
, struct cat_desc
*cdp
,
1328 struct cat_attr
*cap
, vfs_context_t ctx
)
1330 attrgroup_t attr
= alp
->commonattr
;
1331 struct mount
*mp
= HFSTOVFS(hfsmp
);
1335 if (attr
& (ATTR_CMN_OWNERID
| ATTR_CMN_GRPID
)) {
1336 cuid
= kauth_cred_getuid(vfs_context_ucred(ctx
));
1340 if (ATTR_CMN_NAME
& attr
) {
1342 copy_name_attr(vap
, vp
, cdp
->cd_nameptr
,
1344 VATTR_SET_SUPPORTED(vap
, va_name
);
1346 VATTR_CLEAR_SUPPORTED(vap
, va_name
);
1350 if (ATTR_CMN_DEVID
& attr
) {
1351 vap
->va_devid
= hfsmp
->hfs_raw_dev
;
1352 VATTR_SET_SUPPORTED(vap
, va_devid
);
1355 if (ATTR_CMN_FSID
& attr
) {
1356 vap
->va_fsid64
.val
[0] = hfsmp
->hfs_raw_dev
;
1357 vap
->va_fsid64
.val
[1] = vfs_typenum(mp
);
1358 VATTR_SET_SUPPORTED(vap
, va_fsid64
);
1361 * We always provide the objtype even if not asked because VFS helper
1362 * functions depend on knowing the object's type.
1364 vap
->va_objtype
= IFTOVT(cap
->ca_mode
);
1365 VATTR_SET_SUPPORTED(vap
, va_objtype
);
1367 if (ATTR_CMN_OBJTAG
& attr
) {
1368 vap
->va_objtag
= VT_HFS
;
1369 VATTR_SET_SUPPORTED(vap
, va_objtag
);
1372 * Exporting file IDs from HFS Plus:
1374 * For "normal" files the c_fileid is the same value as the
1375 * c_cnid. But for hard link files, they are different - the
1376 * c_cnid belongs to the active directory entry (ie the link)
1377 * and the c_fileid is for the actual inode (ie the data file).
1379 * The stat call (getattr) will always return the c_fileid
1380 * and Carbon APIs, which are hardlink-ignorant, will always
1381 * receive the c_cnid (from getattrlist).
1383 if ((ATTR_CMN_OBJID
& attr
) ||
1384 (ATTR_CMN_OBJPERMANENTID
& attr
)) {
1385 vap
->va_linkid
= cdp
->cd_cnid
;
1386 VATTR_SET_SUPPORTED(vap
, va_linkid
);
1389 if (ATTR_CMN_PAROBJID
& attr
) {
1390 vap
->va_parentid
= cdp
->cd_parentcnid
;
1391 VATTR_SET_SUPPORTED(vap
, va_parentid
);
1394 if (ATTR_CMN_SCRIPT
& attr
) {
1395 vap
->va_encoding
= cdp
->cd_encoding
;
1396 VATTR_SET_SUPPORTED(vap
, va_encoding
);
1399 if (ATTR_CMN_CRTIME
& attr
) {
1400 vap
->va_create_time
.tv_sec
= cap
->ca_itime
;
1401 vap
->va_create_time
.tv_nsec
= 0;
1402 VATTR_SET_SUPPORTED(vap
, va_create_time
);
1405 if (ATTR_CMN_MODTIME
& attr
) {
1406 vap
->va_modify_time
.tv_sec
= cap
->ca_mtime
;
1407 vap
->va_modify_time
.tv_nsec
= 0;
1408 VATTR_SET_SUPPORTED(vap
, va_modify_time
);
1411 if (ATTR_CMN_CHGTIME
& attr
) {
1412 vap
->va_change_time
.tv_sec
= cap
->ca_ctime
;
1413 vap
->va_change_time
.tv_nsec
= 0;
1414 VATTR_SET_SUPPORTED(vap
, va_change_time
);
1417 if (ATTR_CMN_ACCTIME
& attr
) {
1418 vap
->va_access_time
.tv_sec
= cap
->ca_atime
;
1419 vap
->va_access_time
.tv_nsec
= 0;
1420 VATTR_SET_SUPPORTED(vap
, va_access_time
);
1423 if (ATTR_CMN_BKUPTIME
& attr
) {
1424 vap
->va_backup_time
.tv_sec
= cap
->ca_btime
;
1425 vap
->va_backup_time
.tv_nsec
= 0;
1426 VATTR_SET_SUPPORTED(vap
, va_backup_time
);
1429 if (ATTR_CMN_FNDRINFO
& attr
) {
1430 u_int8_t
*finfo
= NULL
;
1432 bcopy(&cap
->ca_finderinfo
, &vap
->va_finderinfo
[0],
1433 sizeof(u_int8_t
) * 32);
1434 finfo
= (u_int8_t
*)(&vap
->va_finderinfo
[0]);
1436 /* Don't expose a symlink's private type/creator. */
1437 if (S_ISLNK(cap
->ca_mode
)) {
1438 struct FndrFileInfo
*fip
;
1440 fip
= (struct FndrFileInfo
*)finfo
;
1445 /* advance 16 bytes into the attrbuf */
1448 /* also don't expose the date_added or write_gen_counter fields */
1449 if (S_ISREG(cap
->ca_mode
) || S_ISLNK(cap
->ca_mode
)) {
1450 struct FndrExtendedFileInfo
*extinfo
=
1451 (struct FndrExtendedFileInfo
*)finfo
;
1452 extinfo
->document_id
= 0;
1453 extinfo
->date_added
= 0;
1454 extinfo
->write_gen_counter
= 0;
1455 } else if (S_ISDIR(cap
->ca_mode
)) {
1456 struct FndrExtendedDirInfo
*extinfo
=
1457 (struct FndrExtendedDirInfo
*)finfo
;
1458 extinfo
->document_id
= 0;
1459 extinfo
->date_added
= 0;
1460 extinfo
->write_gen_counter
= 0;
1463 VATTR_SET_SUPPORTED(vap
, va_finderinfo
);
1466 if (ATTR_CMN_OWNERID
& attr
) {
1467 uid_t nuid
= cap
->ca_uid
;
1470 if (((unsigned int)vfs_flags(HFSTOVFS(hfsmp
))) & MNT_UNKNOWNPERMISSIONS
)
1472 else if (nuid
== UNKNOWNUID
)
1477 VATTR_SET_SUPPORTED(vap
, va_uid
);
1480 if (ATTR_CMN_GRPID
& attr
) {
1481 gid_t ngid
= cap
->ca_gid
;
1484 gid_t cgid
= kauth_cred_getgid(vfs_context_ucred(ctx
));
1485 if (((unsigned int)vfs_flags(HFSTOVFS(hfsmp
))) & MNT_UNKNOWNPERMISSIONS
)
1487 else if (ngid
== UNKNOWNUID
)
1492 VATTR_SET_SUPPORTED(vap
, va_gid
);
1495 if (ATTR_CMN_ACCESSMASK
& attr
) {
1498 * [2856576] Since we are dynamically changing the owner, also
1499 * effectively turn off the set-user-id and set-group-id bits,
1500 * just like chmod(2) would when changing ownership. This prevents
1501 * a security hole where set-user-id programs run as whoever is
1502 * logged on (or root if nobody is logged in yet!)
1504 nmode
= (cap
->ca_uid
== UNKNOWNUID
) ?
1505 cap
->ca_mode
& ~(S_ISUID
| S_ISGID
) : cap
->ca_mode
;
1507 vap
->va_mode
= nmode
;
1508 VATTR_SET_SUPPORTED(vap
, va_mode
);
1511 if (ATTR_CMN_FLAGS
& attr
) {
1512 vap
->va_flags
= cap
->ca_flags
;
1513 VATTR_SET_SUPPORTED(vap
, va_flags
);
1516 if (ATTR_CMN_GEN_COUNT
& attr
) {
1517 vap
->va_write_gencount
= hfs_get_gencount_from_blob(
1518 (const uint8_t *)cap
->ca_finderinfo
, cap
->ca_mode
);
1519 VATTR_SET_SUPPORTED(vap
, va_write_gencount
);
1522 if (ATTR_CMN_DOCUMENT_ID
& attr
) {
1523 vap
->va_document_id
= hfs_get_document_id_from_blob(
1524 (const uint8_t *)cap
->ca_finderinfo
, cap
->ca_mode
);
1525 VATTR_SET_SUPPORTED(vap
, va_document_id
);
1528 if (ATTR_CMN_USERACCESS
& attr
) {
1529 u_int32_t user_access
;
1531 /* Take the long path when we have an ACL */
1532 if ((vp
!= NULLVP
) && (cap
->ca_recflags
& kHFSHasSecurityMask
)) {
1533 user_access
= hfs_real_user_access(vp
, ctx
);
1535 user_access
= DerivePermissionSummary(cap
->ca_uid
, cap
->ca_gid
,
1536 cap
->ca_mode
, mp
, vfs_context_ucred(ctx
), 0);
1538 /* Also consider READ-ONLY file system. */
1539 if (vfs_flags(mp
) & MNT_RDONLY
) {
1540 user_access
&= ~W_OK
;
1542 /* Locked objects are not writable either */
1543 if ((cap
->ca_flags
& UF_IMMUTABLE
) && (vfs_context_suser(ctx
) != 0))
1544 user_access
&= ~W_OK
;
1545 if ((cap
->ca_flags
& SF_IMMUTABLE
) && (vfs_context_suser(ctx
) == 0))
1546 user_access
&= ~W_OK
;
1548 vap
->va_user_access
= user_access
;
1549 VATTR_SET_SUPPORTED(vap
, va_user_access
);
1553 * Right now the best we can do is tell if we *don't* have extended
1554 * security (like hfs_vnop_getattr).
1556 if (ATTR_CMN_EXTENDED_SECURITY
& attr
) {
1557 if (!(cap
->ca_recflags
& kHFSHasSecurityMask
)) {
1558 vap
->va_acl
= (kauth_acl_t
) KAUTH_FILESEC_NONE
;
1559 VATTR_SET_SUPPORTED(vap
, va_acl
);
1563 if (ATTR_CMN_FILEID
& attr
) {
1564 vap
->va_fileid
= cap
->ca_fileid
;
1565 VATTR_SET_SUPPORTED(vap
, va_fileid
);
1568 if (ATTR_CMN_PARENTID
& attr
) {
1569 vap
->va_parentid
= cdp
->cd_parentcnid
;
1570 VATTR_SET_SUPPORTED(vap
, va_parentid
);
1573 if (ATTR_CMN_ADDEDTIME
& attr
) {
1574 if (cap
->ca_recflags
& kHFSHasDateAddedMask
) {
1575 vap
->va_addedtime
.tv_sec
= hfs_get_dateadded_from_blob(
1576 (const uint8_t *)cap
->ca_finderinfo
, cap
->ca_mode
);
1577 vap
->va_addedtime
.tv_nsec
= 0;
1578 VATTR_SET_SUPPORTED(vap
, va_addedtime
);
1584 vattr_data_for_dir_attrs(struct attrlist
*alp
, struct vnode_attr
*vap
,
1585 struct hfsmount
*hfsmp
, struct vnode
*vp
, struct cat_desc
* descp
,
1586 struct cat_attr
* cattrp
)
1588 attrgroup_t attr
= alp
->dirattr
;
1592 * The DIR_LINKCOUNT is the count of real directory hard links.
1593 * (i.e. its not the sum of the implied "." and ".." references
1594 * typically used in stat's st_nlink field)
1596 if (ATTR_DIR_LINKCOUNT
& attr
) {
1597 vap
->va_dirlinkcount
= cattrp
->ca_linkcount
;
1598 VATTR_SET_SUPPORTED(vap
, va_dirlinkcount
);
1600 if (ATTR_DIR_ENTRYCOUNT
& attr
) {
1601 entries
= cattrp
->ca_entries
;
1603 if (descp
->cd_parentcnid
== kHFSRootParentID
) {
1604 if (hfsmp
->hfs_private_desc
[FILE_HARDLINKS
].cd_cnid
!= 0)
1605 --entries
; /* hide private dir */
1606 if (hfsmp
->hfs_private_desc
[DIR_HARDLINKS
].cd_cnid
!= 0)
1607 --entries
; /* hide private dir */
1609 ((hfsmp
->vcbAtrb
& kHFSVolumeJournaledMask
) &&
1610 (hfsmp
->hfs_flags
& HFS_READ_ONLY
)))
1611 entries
-= 2; /* hide the journal files */
1614 vap
->va_nchildren
= entries
;
1615 VATTR_SET_SUPPORTED(vap
, va_nchildren
);
1618 if (ATTR_DIR_MOUNTSTATUS
& attr
) {
1620 * There is not vnode_attr for mount point status.
1621 * XXX. Should there be ?
1623 u_int32_t mstatus
= 0;
1625 if (vp
!= NULL
&& vnode_mountedhere(vp
) != NULL
)
1626 mstatus
= DIR_MNTSTATUS_MNTPOINT
;
1631 vattr_data_for_file_attrs(struct attrlist
*alp
, struct vnode_attr
*vap
,
1632 struct hfsmount
*hfsmp
, struct cat_attr
*cattrp
, struct cat_fork
*datafork
,
1633 struct cat_fork
*rsrcfork
, struct vnode
*vp
)
1635 #if !HFS_COMPRESSION
1638 attrgroup_t attr
= alp
->fileattr
;
1639 off_t da_size
, rsrc_len
, rsrc_alloc
;
1640 u_int32_t allocblksize
;
1642 allocblksize
= HFSTOVCB(hfsmp
)->blockSize
;
1644 off_t datasize
= datafork
->cf_size
;
1645 off_t totalsize
= datasize
+ rsrcfork
->cf_size
;
1647 int handle_compressed
;
1648 handle_compressed
= (cattrp
->ca_flags
& UF_COMPRESSED
);// && hfs_file_is_compressed(VTOC(vp), 1);
1650 if (handle_compressed
) {
1651 if (attr
& (ATTR_FILE_DATALENGTH
|ATTR_FILE_TOTALSIZE
)) {
1652 if ( 0 == hfs_uncompressed_size_of_compressed_file(hfsmp
, vp
, cattrp
->ca_fileid
, &datasize
, 1) ) { /* 1 == don't take the cnode lock */
1653 /* total size of a compressed file is just the data size */
1654 totalsize
= datasize
;
1660 if (ATTR_FILE_LINKCOUNT
& attr
) {
1661 vap
->va_nlink
= cattrp
->ca_linkcount
;
1662 VATTR_SET_SUPPORTED(vap
, va_nlink
);
1664 if (ATTR_FILE_TOTALSIZE
& attr
) {
1665 VATTR_RETURN(vap
, va_total_size
, totalsize
);
1667 if (ATTR_FILE_ALLOCSIZE
& attr
) {
1668 VATTR_RETURN(vap
, va_total_alloc
,
1669 (off_t
)cattrp
->ca_blocks
* (off_t
)allocblksize
);
1671 if (ATTR_FILE_IOBLOCKSIZE
& attr
) {
1672 VATTR_RETURN(vap
, va_iosize
, hfsmp
->hfs_logBlockSize
);
1675 /* ATTR_FILE_CLUMPSIZE is obsolete */
1677 if (ATTR_FILE_DEVTYPE
& attr
) {
1680 if (S_ISBLK(cattrp
->ca_mode
) || S_ISCHR(cattrp
->ca_mode
))
1681 dev
= (u_int32_t
)cattrp
->ca_rdev
;
1683 VATTR_RETURN(vap
, va_rdev
, dev
);
1686 if (ATTR_FILE_DATALENGTH
& attr
) {
1687 VATTR_RETURN(vap
, va_data_size
, datasize
);
1690 /* fake the data fork size on a decmpfs compressed file to reflect the
1691 * uncompressed size. This ensures proper reading and copying of these
1693 * NOTE: we may need to get the vnode here because the vnode parameter
1694 * passed by hfs_vnop_readdirattr() may be null.
1697 if (handle_compressed
) {
1698 da_size
= (off_t
)rsrcfork
->cf_blocks
* (off_t
)allocblksize
;
1705 da_size
= (off_t
)datafork
->cf_blocks
* (off_t
)allocblksize
;
1706 rsrc_len
= rsrcfork
->cf_size
;
1707 rsrc_alloc
= (off_t
)rsrcfork
->cf_blocks
* (off_t
)allocblksize
;
1710 if (ATTR_FILE_DATAALLOCSIZE
& attr
) {
1711 VATTR_RETURN(vap
, va_data_alloc
, da_size
);
1714 if (ATTR_FILE_RSRCLENGTH
& attr
) {
1715 VATTR_RETURN(vap
, va_rsrc_length
, rsrc_len
);
1718 if (ATTR_FILE_RSRCALLOCSIZE
& attr
) {
1719 VATTR_RETURN(vap
, va_rsrc_alloc
, rsrc_alloc
);