pseudofs_vnops.c revision 227550
1/*-
2 * Copyright (c) 2001 Dag-Erling Co�dan Sm�rgrav
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * 1. Redistributions of source code must retain the above copyright
9 *    notice, this list of conditions and the following disclaimer
10 *    in this position and unchanged.
11 * 2. Redistributions in binary form must reproduce the above copyright
12 *    notice, this list of conditions and the following disclaimer in the
13 *    documentation and/or other materials provided with the distribution.
14 * 3. The name of the author may not be used to endorse or promote products
15 *    derived from this software without specific prior written permission.
16 *
17 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
18 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
19 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
20 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
21 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
22 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
23 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
24 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
25 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
26 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27 */
28
29#include <sys/cdefs.h>
30__FBSDID("$FreeBSD: head/sys/fs/pseudofs/pseudofs_vnops.c 227550 2011-11-16 10:11:55Z pho $");
31
32#include "opt_pseudofs.h"
33
34#include <sys/param.h>
35#include <sys/kernel.h>
36#include <sys/systm.h>
37#include <sys/ctype.h>
38#include <sys/dirent.h>
39#include <sys/fcntl.h>
40#include <sys/limits.h>
41#include <sys/lock.h>
42#include <sys/malloc.h>
43#include <sys/mount.h>
44#include <sys/mutex.h>
45#include <sys/namei.h>
46#include <sys/proc.h>
47#include <sys/sbuf.h>
48#include <sys/sx.h>
49#include <sys/sysctl.h>
50#include <sys/vnode.h>
51
52#include <fs/pseudofs/pseudofs.h>
53#include <fs/pseudofs/pseudofs_internal.h>
54
55#define KASSERT_PN_IS_DIR(pn)						\
56	KASSERT((pn)->pn_type == pfstype_root ||			\
57	    (pn)->pn_type == pfstype_dir ||				\
58	    (pn)->pn_type == pfstype_procdir,				\
59	    ("%s(): VDIR vnode refers to non-directory pfs_node", __func__))
60
61#define KASSERT_PN_IS_FILE(pn)						\
62	KASSERT((pn)->pn_type == pfstype_file,				\
63	    ("%s(): VREG vnode refers to non-file pfs_node", __func__))
64
65#define KASSERT_PN_IS_LINK(pn)						\
66	KASSERT((pn)->pn_type == pfstype_symlink,			\
67	    ("%s(): VLNK vnode refers to non-link pfs_node", __func__))
68
69/*
70 * Returns the fileno, adjusted for target pid
71 */
72static uint32_t
73pn_fileno(struct pfs_node *pn, pid_t pid)
74{
75
76	KASSERT(pn->pn_fileno > 0,
77	    ("%s(): no fileno allocated", __func__));
78	if (pid != NO_PID)
79		return (pn->pn_fileno * NO_PID + pid);
80	return (pn->pn_fileno);
81}
82
83/*
84 * Returns non-zero if given file is visible to given thread.
85 */
86static int
87pfs_visible_proc(struct thread *td, struct pfs_node *pn, struct proc *proc)
88{
89	int visible;
90
91	if (proc == NULL)
92		return (0);
93
94	PROC_LOCK_ASSERT(proc, MA_OWNED);
95
96	visible = ((proc->p_flag & P_WEXIT) == 0);
97	if (visible)
98		visible = (p_cansee(td, proc) == 0);
99	if (visible && pn->pn_vis != NULL)
100		visible = pn_vis(td, proc, pn);
101	if (!visible)
102		return (0);
103	return (1);
104}
105
106static int
107pfs_visible(struct thread *td, struct pfs_node *pn, pid_t pid, struct proc **p)
108{
109	struct proc *proc;
110
111	PFS_TRACE(("%s (pid: %d, req: %d)",
112	    pn->pn_name, pid, td->td_proc->p_pid));
113
114	if (p)
115		*p = NULL;
116	if (pid == NO_PID)
117		PFS_RETURN (1);
118	if ((proc = pfind(pid)) == NULL)
119		PFS_RETURN (0);
120	if (pfs_visible_proc(td, pn, proc)) {
121		if (p)
122			*p = proc;
123		else
124			PROC_UNLOCK(proc);
125		PFS_RETURN (1);
126	}
127	PROC_UNLOCK(proc);
128	PFS_RETURN (0);
129}
130
131/*
132 * Verify permissions
133 */
134static int
135pfs_access(struct vop_access_args *va)
136{
137	struct vnode *vn = va->a_vp;
138	struct pfs_vdata *pvd = vn->v_data;
139	struct vattr vattr;
140	int error;
141
142	PFS_TRACE(("%s", pvd->pvd_pn->pn_name));
143	(void)pvd;
144
145	error = VOP_GETATTR(vn, &vattr, va->a_cred);
146	if (error)
147		PFS_RETURN (error);
148	error = vaccess(vn->v_type, vattr.va_mode, vattr.va_uid,
149	    vattr.va_gid, va->a_accmode, va->a_cred, NULL);
150	PFS_RETURN (error);
151}
152
153/*
154 * Close a file or directory
155 */
156static int
157pfs_close(struct vop_close_args *va)
158{
159	struct vnode *vn = va->a_vp;
160	struct pfs_vdata *pvd = vn->v_data;
161	struct pfs_node *pn = pvd->pvd_pn;
162	struct proc *proc;
163	int error;
164
165	PFS_TRACE(("%s", pn->pn_name));
166	pfs_assert_not_owned(pn);
167
168	/*
169	 * Do nothing unless this is the last close and the node has a
170	 * last-close handler.
171	 */
172	if (vrefcnt(vn) > 1 || pn->pn_close == NULL)
173		PFS_RETURN (0);
174
175	if (pvd->pvd_pid != NO_PID) {
176		proc = pfind(pvd->pvd_pid);
177	} else {
178		proc = NULL;
179	}
180
181	error = pn_close(va->a_td, proc, pn);
182
183	if (proc != NULL)
184		PROC_UNLOCK(proc);
185
186	PFS_RETURN (error);
187}
188
189/*
190 * Get file attributes
191 */
192static int
193pfs_getattr(struct vop_getattr_args *va)
194{
195	struct vnode *vn = va->a_vp;
196	struct pfs_vdata *pvd = vn->v_data;
197	struct pfs_node *pn = pvd->pvd_pn;
198	struct vattr *vap = va->a_vap;
199	struct proc *proc;
200	int error = 0;
201
202	PFS_TRACE(("%s", pn->pn_name));
203	pfs_assert_not_owned(pn);
204
205	if (!pfs_visible(curthread, pn, pvd->pvd_pid, &proc))
206		PFS_RETURN (ENOENT);
207
208	vap->va_type = vn->v_type;
209	vap->va_fileid = pn_fileno(pn, pvd->pvd_pid);
210	vap->va_flags = 0;
211	vap->va_blocksize = PAGE_SIZE;
212	vap->va_bytes = vap->va_size = 0;
213	vap->va_filerev = 0;
214	vap->va_fsid = vn->v_mount->mnt_stat.f_fsid.val[0];
215	vap->va_nlink = 1;
216	nanotime(&vap->va_ctime);
217	vap->va_atime = vap->va_mtime = vap->va_ctime;
218
219	switch (pn->pn_type) {
220	case pfstype_procdir:
221	case pfstype_root:
222	case pfstype_dir:
223#if 0
224		pfs_lock(pn);
225		/* compute link count */
226		pfs_unlock(pn);
227#endif
228		vap->va_mode = 0555;
229		break;
230	case pfstype_file:
231	case pfstype_symlink:
232		vap->va_mode = 0444;
233		break;
234	default:
235		printf("shouldn't be here!\n");
236		vap->va_mode = 0;
237		break;
238	}
239
240	if (proc != NULL) {
241		vap->va_uid = proc->p_ucred->cr_ruid;
242		vap->va_gid = proc->p_ucred->cr_rgid;
243	} else {
244		vap->va_uid = 0;
245		vap->va_gid = 0;
246	}
247
248	if (pn->pn_attr != NULL)
249		error = pn_attr(curthread, proc, pn, vap);
250
251	if(proc != NULL)
252		PROC_UNLOCK(proc);
253
254	PFS_RETURN (error);
255}
256
257/*
258 * Perform an ioctl
259 */
260static int
261pfs_ioctl(struct vop_ioctl_args *va)
262{
263	struct vnode *vn;
264	struct pfs_vdata *pvd;
265	struct pfs_node *pn;
266	struct proc *proc;
267	int error;
268
269	vn = va->a_vp;
270	vn_lock(vn, LK_SHARED | LK_RETRY);
271	if (vn->v_iflag & VI_DOOMED) {
272		VOP_UNLOCK(vn, 0);
273		return (EBADF);
274	}
275	pvd = vn->v_data;
276	pn = pvd->pvd_pn;
277
278	PFS_TRACE(("%s: %lx", pn->pn_name, va->a_command));
279	pfs_assert_not_owned(pn);
280
281	if (vn->v_type != VREG) {
282		VOP_UNLOCK(vn, 0);
283		PFS_RETURN (EINVAL);
284	}
285	KASSERT_PN_IS_FILE(pn);
286
287	if (pn->pn_ioctl == NULL) {
288		VOP_UNLOCK(vn, 0);
289		PFS_RETURN (ENOTTY);
290	}
291
292	/*
293	 * This is necessary because process' privileges may
294	 * have changed since the open() call.
295	 */
296	if (!pfs_visible(curthread, pn, pvd->pvd_pid, &proc)) {
297		VOP_UNLOCK(vn, 0);
298		PFS_RETURN (EIO);
299	}
300
301	error = pn_ioctl(curthread, proc, pn, va->a_command, va->a_data);
302
303	if (proc != NULL)
304		PROC_UNLOCK(proc);
305
306	VOP_UNLOCK(vn, 0);
307	PFS_RETURN (error);
308}
309
310/*
311 * Perform getextattr
312 */
313static int
314pfs_getextattr(struct vop_getextattr_args *va)
315{
316	struct vnode *vn = va->a_vp;
317	struct pfs_vdata *pvd = vn->v_data;
318	struct pfs_node *pn = pvd->pvd_pn;
319	struct proc *proc;
320	int error;
321
322	PFS_TRACE(("%s", pn->pn_name));
323	pfs_assert_not_owned(pn);
324
325	/*
326	 * This is necessary because either process' privileges may
327	 * have changed since the open() call.
328	 */
329	if (!pfs_visible(curthread, pn, pvd->pvd_pid, &proc))
330		PFS_RETURN (EIO);
331
332	if (pn->pn_getextattr == NULL)
333		error = EOPNOTSUPP;
334	else
335		error = pn_getextattr(curthread, proc, pn,
336		    va->a_attrnamespace, va->a_name, va->a_uio,
337		    va->a_size, va->a_cred);
338
339	if (proc != NULL)
340		PROC_UNLOCK(proc);
341
342	PFS_RETURN (error);
343}
344
345/*
346 * Convert a vnode to its component name
347 */
348static int
349pfs_vptocnp(struct vop_vptocnp_args *ap)
350{
351	struct vnode *vp = ap->a_vp;
352	struct vnode **dvp = ap->a_vpp;
353	struct pfs_vdata *pvd = vp->v_data;
354	struct pfs_node *pd = pvd->pvd_pn;
355	struct pfs_node *pn;
356	struct mount *mp;
357	char *buf = ap->a_buf;
358	int *buflen = ap->a_buflen;
359	char pidbuf[PFS_NAMELEN];
360	pid_t pid = pvd->pvd_pid;
361	int len, i, error, locked;
362
363	i = *buflen;
364	error = 0;
365
366	pfs_lock(pd);
367
368	if (vp->v_type == VDIR && pd->pn_type == pfstype_root) {
369		*dvp = vp;
370		vhold(*dvp);
371		pfs_unlock(pd);
372		PFS_RETURN (0);
373	} else if (vp->v_type == VDIR && pd->pn_type == pfstype_procdir) {
374		len = snprintf(pidbuf, sizeof(pidbuf), "%d", pid);
375		i -= len;
376		if (i < 0) {
377			error = ENOMEM;
378			goto failed;
379		}
380		bcopy(pidbuf, buf + i, len);
381	} else {
382		len = strlen(pd->pn_name);
383		i -= len;
384		if (i < 0) {
385			error = ENOMEM;
386			goto failed;
387		}
388		bcopy(pd->pn_name, buf + i, len);
389	}
390
391	pn = pd->pn_parent;
392	pfs_unlock(pd);
393
394	mp = vp->v_mount;
395	error = vfs_busy(mp, 0);
396	if (error)
397		return (error);
398
399	/*
400	 * vp is held by caller.
401	 */
402	locked = VOP_ISLOCKED(vp);
403	VOP_UNLOCK(vp, 0);
404
405	error = pfs_vncache_alloc(mp, dvp, pn, pid);
406	if (error) {
407		vn_lock(vp, locked | LK_RETRY);
408		vfs_unbusy(mp);
409		PFS_RETURN(error);
410	}
411
412	*buflen = i;
413	vhold(*dvp);
414	vput(*dvp);
415	vn_lock(vp, locked | LK_RETRY);
416	vfs_unbusy(mp);
417
418	PFS_RETURN (0);
419failed:
420	pfs_unlock(pd);
421	PFS_RETURN(error);
422}
423
424/*
425 * Look up a file or directory
426 */
427static int
428pfs_lookup(struct vop_cachedlookup_args *va)
429{
430	struct vnode *vn = va->a_dvp;
431	struct vnode **vpp = va->a_vpp;
432	struct componentname *cnp = va->a_cnp;
433	struct pfs_vdata *pvd = vn->v_data;
434	struct pfs_node *pd = pvd->pvd_pn;
435	struct pfs_node *pn, *pdn = NULL;
436	pid_t pid = pvd->pvd_pid;
437	char *pname;
438	int error, i, namelen, visible;
439
440	PFS_TRACE(("%.*s", (int)cnp->cn_namelen, cnp->cn_nameptr));
441	pfs_assert_not_owned(pd);
442
443	if (vn->v_type != VDIR)
444		PFS_RETURN (ENOTDIR);
445	KASSERT_PN_IS_DIR(pd);
446
447	error = VOP_ACCESS(vn, VEXEC, cnp->cn_cred, cnp->cn_thread);
448	if (error)
449		PFS_RETURN (error);
450
451	/*
452	 * Don't support DELETE or RENAME.  CREATE is supported so
453	 * that O_CREAT will work, but the lookup will still fail if
454	 * the file does not exist.
455	 */
456	if ((cnp->cn_flags & ISLASTCN) &&
457	    (cnp->cn_nameiop == DELETE || cnp->cn_nameiop == RENAME))
458		PFS_RETURN (EOPNOTSUPP);
459
460	/* shortcut: check if the name is too long */
461	if (cnp->cn_namelen >= PFS_NAMELEN)
462		PFS_RETURN (ENOENT);
463
464	/* check that parent directory is visible... */
465	if (!pfs_visible(curthread, pd, pvd->pvd_pid, NULL))
466		PFS_RETURN (ENOENT);
467
468	/* self */
469	namelen = cnp->cn_namelen;
470	pname = cnp->cn_nameptr;
471	if (namelen == 1 && pname[0] == '.') {
472		pn = pd;
473		*vpp = vn;
474		VREF(vn);
475		PFS_RETURN (0);
476	}
477
478	/* parent */
479	if (cnp->cn_flags & ISDOTDOT) {
480		if (pd->pn_type == pfstype_root)
481			PFS_RETURN (EIO);
482		VOP_UNLOCK(vn, 0);
483		KASSERT(pd->pn_parent != NULL,
484		    ("%s(): non-root directory has no parent", __func__));
485		/*
486		 * This one is tricky.  Descendents of procdir nodes
487		 * inherit their parent's process affinity, but
488		 * there's no easy reverse mapping.  For simplicity,
489		 * we assume that if this node is a procdir, its
490		 * parent isn't (which is correct as long as
491		 * descendents of procdir nodes are never procdir
492		 * nodes themselves)
493		 */
494		if (pd->pn_type == pfstype_procdir)
495			pid = NO_PID;
496		pfs_lock(pd);
497		pn = pd->pn_parent;
498		pfs_unlock(pd);
499		goto got_pnode;
500	}
501
502	pfs_lock(pd);
503
504	/* named node */
505	for (pn = pd->pn_nodes; pn != NULL; pn = pn->pn_next)
506		if (pn->pn_type == pfstype_procdir)
507			pdn = pn;
508		else if (pn->pn_name[namelen] == '\0' &&
509		    bcmp(pname, pn->pn_name, namelen) == 0) {
510			pfs_unlock(pd);
511			goto got_pnode;
512		}
513
514	/* process dependent node */
515	if ((pn = pdn) != NULL) {
516		pid = 0;
517		for (pid = 0, i = 0; i < namelen && isdigit(pname[i]); ++i)
518			if ((pid = pid * 10 + pname[i] - '0') > PID_MAX)
519				break;
520		if (i == cnp->cn_namelen) {
521			pfs_unlock(pd);
522			goto got_pnode;
523		}
524	}
525
526	pfs_unlock(pd);
527
528	PFS_RETURN (ENOENT);
529
530 got_pnode:
531	pfs_assert_not_owned(pd);
532	pfs_assert_not_owned(pn);
533	visible = pfs_visible(curthread, pn, pid, NULL);
534	if (!visible) {
535		error = ENOENT;
536		goto failed;
537	}
538
539	error = pfs_vncache_alloc(vn->v_mount, vpp, pn, pid);
540	if (error)
541		goto failed;
542
543	if (cnp->cn_flags & ISDOTDOT)
544		vn_lock(vn, LK_EXCLUSIVE|LK_RETRY);
545	if (cnp->cn_flags & MAKEENTRY && !(vn->v_iflag & VI_DOOMED))
546		cache_enter(vn, *vpp, cnp);
547	PFS_RETURN (0);
548 failed:
549	if (cnp->cn_flags & ISDOTDOT)
550		vn_lock(vn, LK_EXCLUSIVE|LK_RETRY);
551	PFS_RETURN(error);
552}
553
554/*
555 * Open a file or directory.
556 */
557static int
558pfs_open(struct vop_open_args *va)
559{
560	struct vnode *vn = va->a_vp;
561	struct pfs_vdata *pvd = vn->v_data;
562	struct pfs_node *pn = pvd->pvd_pn;
563	int mode = va->a_mode;
564
565	PFS_TRACE(("%s (mode 0x%x)", pn->pn_name, mode));
566	pfs_assert_not_owned(pn);
567
568	/* check if the requested mode is permitted */
569	if (((mode & FREAD) && !(mode & PFS_RD)) ||
570	    ((mode & FWRITE) && !(mode & PFS_WR)))
571		PFS_RETURN (EPERM);
572
573	/* we don't support locking */
574	if ((mode & O_SHLOCK) || (mode & O_EXLOCK))
575		PFS_RETURN (EOPNOTSUPP);
576
577	PFS_RETURN (0);
578}
579
580/*
581 * Read from a file
582 */
583static int
584pfs_read(struct vop_read_args *va)
585{
586	struct vnode *vn = va->a_vp;
587	struct pfs_vdata *pvd = vn->v_data;
588	struct pfs_node *pn = pvd->pvd_pn;
589	struct uio *uio = va->a_uio;
590	struct proc *proc;
591	struct sbuf *sb = NULL;
592	int error, locked;
593	unsigned int buflen, offset, resid;
594
595	PFS_TRACE(("%s", pn->pn_name));
596	pfs_assert_not_owned(pn);
597
598	if (vn->v_type != VREG)
599		PFS_RETURN (EINVAL);
600	KASSERT_PN_IS_FILE(pn);
601
602	if (!(pn->pn_flags & PFS_RD))
603		PFS_RETURN (EBADF);
604
605	if (pn->pn_fill == NULL)
606		PFS_RETURN (EIO);
607
608	/*
609	 * This is necessary because either process' privileges may
610	 * have changed since the open() call.
611	 */
612	if (!pfs_visible(curthread, pn, pvd->pvd_pid, &proc))
613		PFS_RETURN (EIO);
614	if (proc != NULL) {
615		_PHOLD(proc);
616		PROC_UNLOCK(proc);
617	}
618
619	vhold(vn);
620	locked = VOP_ISLOCKED(vn);
621	VOP_UNLOCK(vn, 0);
622
623	if (pn->pn_flags & PFS_RAWRD) {
624		PFS_TRACE(("%zd resid", uio->uio_resid));
625		error = pn_fill(curthread, proc, pn, NULL, uio);
626		PFS_TRACE(("%zd resid", uio->uio_resid));
627		goto ret;
628	}
629
630	/* beaucoup sanity checks so we don't ask for bogus allocation */
631	if (uio->uio_offset < 0 || uio->uio_resid < 0 ||
632	    (offset = uio->uio_offset) != uio->uio_offset ||
633	    (resid = uio->uio_resid) != uio->uio_resid ||
634	    (buflen = offset + resid + 1) < offset || buflen > INT_MAX) {
635		error = EINVAL;
636		goto ret;
637	}
638	if (buflen > MAXPHYS + 1)
639		buflen = MAXPHYS + 1;
640
641	sb = sbuf_new(sb, NULL, buflen, 0);
642	if (sb == NULL) {
643		error = EIO;
644		goto ret;
645	}
646
647	error = pn_fill(curthread, proc, pn, sb, uio);
648
649	if (error) {
650		sbuf_delete(sb);
651		goto ret;
652	}
653
654	sbuf_finish(sb);
655	error = uiomove_frombuf(sbuf_data(sb), sbuf_len(sb), uio);
656	sbuf_delete(sb);
657ret:
658	vn_lock(vn, locked | LK_RETRY);
659	vdrop(vn);
660	if (proc != NULL)
661		PRELE(proc);
662	PFS_RETURN (error);
663}
664
665/*
666 * Iterate through directory entries
667 */
668static int
669pfs_iterate(struct thread *td, struct proc *proc, struct pfs_node *pd,
670	    struct pfs_node **pn, struct proc **p)
671{
672	int visible;
673
674	sx_assert(&allproc_lock, SX_SLOCKED);
675	pfs_assert_owned(pd);
676 again:
677	if (*pn == NULL) {
678		/* first node */
679		*pn = pd->pn_nodes;
680	} else if ((*pn)->pn_type != pfstype_procdir) {
681		/* next node */
682		*pn = (*pn)->pn_next;
683	}
684	if (*pn != NULL && (*pn)->pn_type == pfstype_procdir) {
685		/* next process */
686		if (*p == NULL)
687			*p = LIST_FIRST(&allproc);
688		else
689			*p = LIST_NEXT(*p, p_list);
690		/* out of processes: next node */
691		if (*p == NULL)
692			*pn = (*pn)->pn_next;
693		else
694			PROC_LOCK(*p);
695	}
696
697	if ((*pn) == NULL)
698		return (-1);
699
700	if (*p != NULL) {
701		visible = pfs_visible_proc(td, *pn, *p);
702		PROC_UNLOCK(*p);
703	} else if (proc != NULL) {
704		visible = pfs_visible_proc(td, *pn, proc);
705	} else {
706		visible = 1;
707	}
708	if (!visible)
709		goto again;
710
711	return (0);
712}
713
714/* Directory entry list */
715struct pfsentry {
716	STAILQ_ENTRY(pfsentry)	link;
717	struct dirent		entry;
718};
719STAILQ_HEAD(pfsdirentlist, pfsentry);
720
721/*
722 * Return directory entries.
723 */
724static int
725pfs_readdir(struct vop_readdir_args *va)
726{
727	struct vnode *vn = va->a_vp;
728	struct pfs_vdata *pvd = vn->v_data;
729	struct pfs_node *pd = pvd->pvd_pn;
730	pid_t pid = pvd->pvd_pid;
731	struct proc *p, *proc;
732	struct pfs_node *pn;
733	struct uio *uio;
734	struct pfsentry *pfsent, *pfsent2;
735	struct pfsdirentlist lst;
736	off_t offset;
737	int error, i, resid;
738
739	STAILQ_INIT(&lst);
740	error = 0;
741	KASSERT(pd->pn_info == vn->v_mount->mnt_data,
742	    ("%s(): pn_info does not match mountpoint", __func__));
743	PFS_TRACE(("%s pid %lu", pd->pn_name, (unsigned long)pid));
744	pfs_assert_not_owned(pd);
745
746	if (vn->v_type != VDIR)
747		PFS_RETURN (ENOTDIR);
748	KASSERT_PN_IS_DIR(pd);
749	uio = va->a_uio;
750
751	/* only allow reading entire entries */
752	offset = uio->uio_offset;
753	resid = uio->uio_resid;
754	if (offset < 0 || offset % PFS_DELEN != 0 ||
755	    (resid && resid < PFS_DELEN))
756		PFS_RETURN (EINVAL);
757	if (resid == 0)
758		PFS_RETURN (0);
759
760	sx_slock(&allproc_lock);
761	pfs_lock(pd);
762
763        /* check if the directory is visible to the caller */
764        if (!pfs_visible(curthread, pd, pid, &proc)) {
765		sx_sunlock(&allproc_lock);
766		pfs_unlock(pd);
767                PFS_RETURN (ENOENT);
768	}
769	KASSERT(pid == NO_PID || proc != NULL,
770	    ("%s(): no process for pid %lu", __func__, (unsigned long)pid));
771
772	/* skip unwanted entries */
773	for (pn = NULL, p = NULL; offset > 0; offset -= PFS_DELEN) {
774		if (pfs_iterate(curthread, proc, pd, &pn, &p) == -1) {
775			/* nothing left... */
776			if (proc != NULL)
777				PROC_UNLOCK(proc);
778			pfs_unlock(pd);
779			sx_sunlock(&allproc_lock);
780			PFS_RETURN (0);
781		}
782	}
783
784	/* fill in entries */
785	while (pfs_iterate(curthread, proc, pd, &pn, &p) != -1 &&
786	    resid >= PFS_DELEN) {
787		if ((pfsent = malloc(sizeof(struct pfsentry), M_IOV,
788		    M_NOWAIT | M_ZERO)) == NULL) {
789			error = ENOMEM;
790			break;
791		}
792		pfsent->entry.d_reclen = PFS_DELEN;
793		pfsent->entry.d_fileno = pn_fileno(pn, pid);
794		/* PFS_DELEN was picked to fit PFS_NAMLEN */
795		for (i = 0; i < PFS_NAMELEN - 1 && pn->pn_name[i] != '\0'; ++i)
796			pfsent->entry.d_name[i] = pn->pn_name[i];
797		pfsent->entry.d_name[i] = 0;
798		pfsent->entry.d_namlen = i;
799		switch (pn->pn_type) {
800		case pfstype_procdir:
801			KASSERT(p != NULL,
802			    ("reached procdir node with p == NULL"));
803			pfsent->entry.d_namlen = snprintf(pfsent->entry.d_name,
804			    PFS_NAMELEN, "%d", p->p_pid);
805			/* fall through */
806		case pfstype_root:
807		case pfstype_dir:
808		case pfstype_this:
809		case pfstype_parent:
810			pfsent->entry.d_type = DT_DIR;
811			break;
812		case pfstype_file:
813			pfsent->entry.d_type = DT_REG;
814			break;
815		case pfstype_symlink:
816			pfsent->entry.d_type = DT_LNK;
817			break;
818		default:
819			panic("%s has unexpected node type: %d", pn->pn_name, pn->pn_type);
820		}
821		PFS_TRACE(("%s", pfsent->entry.d_name));
822		STAILQ_INSERT_TAIL(&lst, pfsent, link);
823		offset += PFS_DELEN;
824		resid -= PFS_DELEN;
825	}
826	if (proc != NULL)
827		PROC_UNLOCK(proc);
828	pfs_unlock(pd);
829	sx_sunlock(&allproc_lock);
830	i = 0;
831	STAILQ_FOREACH_SAFE(pfsent, &lst, link, pfsent2) {
832		if (error == 0)
833			error = uiomove(&pfsent->entry, PFS_DELEN, uio);
834		free(pfsent, M_IOV);
835		i++;
836	}
837	PFS_TRACE(("%zd bytes", i * PFS_DELEN));
838	PFS_RETURN (error);
839}
840
841/*
842 * Read a symbolic link
843 */
844static int
845pfs_readlink(struct vop_readlink_args *va)
846{
847	struct vnode *vn = va->a_vp;
848	struct pfs_vdata *pvd = vn->v_data;
849	struct pfs_node *pn = pvd->pvd_pn;
850	struct uio *uio = va->a_uio;
851	struct proc *proc = NULL;
852	char buf[PATH_MAX];
853	struct sbuf sb;
854	int error, locked;
855
856	PFS_TRACE(("%s", pn->pn_name));
857	pfs_assert_not_owned(pn);
858
859	if (vn->v_type != VLNK)
860		PFS_RETURN (EINVAL);
861	KASSERT_PN_IS_LINK(pn);
862
863	if (pn->pn_fill == NULL)
864		PFS_RETURN (EIO);
865
866	if (pvd->pvd_pid != NO_PID) {
867		if ((proc = pfind(pvd->pvd_pid)) == NULL)
868			PFS_RETURN (EIO);
869		if (proc->p_flag & P_WEXIT) {
870			PROC_UNLOCK(proc);
871			PFS_RETURN (EIO);
872		}
873		_PHOLD(proc);
874		PROC_UNLOCK(proc);
875	}
876	vhold(vn);
877	locked = VOP_ISLOCKED(vn);
878	VOP_UNLOCK(vn, 0);
879
880	/* sbuf_new() can't fail with a static buffer */
881	sbuf_new(&sb, buf, sizeof buf, 0);
882
883	error = pn_fill(curthread, proc, pn, &sb, NULL);
884
885	if (proc != NULL)
886		PRELE(proc);
887	vn_lock(vn, locked | LK_RETRY);
888	vdrop(vn);
889
890	if (error) {
891		sbuf_delete(&sb);
892		PFS_RETURN (error);
893	}
894
895	sbuf_finish(&sb);
896	error = uiomove_frombuf(sbuf_data(&sb), sbuf_len(&sb), uio);
897	sbuf_delete(&sb);
898	PFS_RETURN (error);
899}
900
901/*
902 * Reclaim a vnode
903 */
904static int
905pfs_reclaim(struct vop_reclaim_args *va)
906{
907	struct vnode *vn = va->a_vp;
908	struct pfs_vdata *pvd = vn->v_data;
909	struct pfs_node *pn = pvd->pvd_pn;
910
911	PFS_TRACE(("%s", pn->pn_name));
912	pfs_assert_not_owned(pn);
913
914	return (pfs_vncache_free(va->a_vp));
915}
916
917/*
918 * Set attributes
919 */
920static int
921pfs_setattr(struct vop_setattr_args *va)
922{
923	struct vnode *vn = va->a_vp;
924	struct pfs_vdata *pvd = vn->v_data;
925	struct pfs_node *pn = pvd->pvd_pn;
926
927	PFS_TRACE(("%s", pn->pn_name));
928	pfs_assert_not_owned(pn);
929
930	PFS_RETURN (EOPNOTSUPP);
931}
932
933/*
934 * Write to a file
935 */
936static int
937pfs_write(struct vop_write_args *va)
938{
939	struct vnode *vn = va->a_vp;
940	struct pfs_vdata *pvd = vn->v_data;
941	struct pfs_node *pn = pvd->pvd_pn;
942	struct uio *uio = va->a_uio;
943	struct proc *proc;
944	struct sbuf sb;
945	int error;
946
947	PFS_TRACE(("%s", pn->pn_name));
948	pfs_assert_not_owned(pn);
949
950	if (vn->v_type != VREG)
951		PFS_RETURN (EINVAL);
952	KASSERT_PN_IS_FILE(pn);
953
954	if (!(pn->pn_flags & PFS_WR))
955		PFS_RETURN (EBADF);
956
957	if (pn->pn_fill == NULL)
958		PFS_RETURN (EIO);
959
960	/*
961	 * This is necessary because either process' privileges may
962	 * have changed since the open() call.
963	 */
964	if (!pfs_visible(curthread, pn, pvd->pvd_pid, &proc))
965		PFS_RETURN (EIO);
966	if (proc != NULL) {
967		_PHOLD(proc);
968		PROC_UNLOCK(proc);
969	}
970
971	if (pn->pn_flags & PFS_RAWWR) {
972		error = pn_fill(curthread, proc, pn, NULL, uio);
973		if (proc != NULL)
974			PRELE(proc);
975		PFS_RETURN (error);
976	}
977
978	sbuf_uionew(&sb, uio, &error);
979	if (error) {
980		if (proc != NULL)
981			PRELE(proc);
982		PFS_RETURN (error);
983	}
984
985	error = pn_fill(curthread, proc, pn, &sb, uio);
986
987	sbuf_delete(&sb);
988	if (proc != NULL)
989		PRELE(proc);
990	PFS_RETURN (error);
991}
992
993/*
994 * Vnode operations
995 */
996struct vop_vector pfs_vnodeops = {
997	.vop_default =		&default_vnodeops,
998
999	.vop_access =		pfs_access,
1000	.vop_cachedlookup =	pfs_lookup,
1001	.vop_close =		pfs_close,
1002	.vop_create =		VOP_EOPNOTSUPP,
1003	.vop_getattr =		pfs_getattr,
1004	.vop_getextattr =	pfs_getextattr,
1005	.vop_ioctl =		pfs_ioctl,
1006	.vop_link =		VOP_EOPNOTSUPP,
1007	.vop_lookup =		vfs_cache_lookup,
1008	.vop_mkdir =		VOP_EOPNOTSUPP,
1009	.vop_mknod =		VOP_EOPNOTSUPP,
1010	.vop_open =		pfs_open,
1011	.vop_read =		pfs_read,
1012	.vop_readdir =		pfs_readdir,
1013	.vop_readlink =		pfs_readlink,
1014	.vop_reclaim =		pfs_reclaim,
1015	.vop_remove =		VOP_EOPNOTSUPP,
1016	.vop_rename =		VOP_EOPNOTSUPP,
1017	.vop_rmdir =		VOP_EOPNOTSUPP,
1018	.vop_setattr =		pfs_setattr,
1019	.vop_symlink =		VOP_EOPNOTSUPP,
1020	.vop_vptocnp =		pfs_vptocnp,
1021	.vop_write =		pfs_write,
1022	/* XXX I've probably forgotten a few that need VOP_EOPNOTSUPP */
1023};
1024