1/*-
2 * SPDX-License-Identifier: BSD-3-Clause
3 *
4 * Copyright (c) 1989, 1993
5 *	The Regents of the University of California.  All rights reserved.
6 *
7 * This code is derived from software contributed to Berkeley by
8 * Rick Macklem at The University of Guelph.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 *    notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 *    notice, this list of conditions and the following disclaimer in the
17 *    documentation and/or other materials provided with the distribution.
18 * 3. Neither the name of the University nor the names of its contributors
19 *    may be used to endorse or promote products derived from this software
20 *    without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 *
34 */
35
36#include <sys/cdefs.h>
37__FBSDID("$FreeBSD$");
38
39#include "opt_inet.h"
40#include "opt_inet6.h"
41
42#include <sys/capsicum.h>
43
44/*
45 * generally, I don't like #includes inside .h files, but it seems to
46 * be the easiest way to handle the port.
47 */
48#include <sys/fail.h>
49#include <sys/hash.h>
50#include <sys/sysctl.h>
51#include <fs/nfs/nfsport.h>
52#include <netinet/in_fib.h>
53#include <netinet/if_ether.h>
54#include <netinet6/ip6_var.h>
55#include <net/if_types.h>
56#include <net/route/nhop.h>
57
58#include <fs/nfsclient/nfs_kdtrace.h>
59
60#ifdef KDTRACE_HOOKS
61dtrace_nfsclient_attrcache_flush_probe_func_t
62		dtrace_nfscl_attrcache_flush_done_probe;
63uint32_t	nfscl_attrcache_flush_done_id;
64
65dtrace_nfsclient_attrcache_get_hit_probe_func_t
66		dtrace_nfscl_attrcache_get_hit_probe;
67uint32_t	nfscl_attrcache_get_hit_id;
68
69dtrace_nfsclient_attrcache_get_miss_probe_func_t
70		dtrace_nfscl_attrcache_get_miss_probe;
71uint32_t	nfscl_attrcache_get_miss_id;
72
73dtrace_nfsclient_attrcache_load_probe_func_t
74		dtrace_nfscl_attrcache_load_done_probe;
75uint32_t	nfscl_attrcache_load_done_id;
76#endif /* !KDTRACE_HOOKS */
77
78extern u_int32_t newnfs_true, newnfs_false, newnfs_xdrneg1;
79extern struct vop_vector newnfs_vnodeops;
80extern struct vop_vector newnfs_fifoops;
81extern uma_zone_t newnfsnode_zone;
82extern struct buf_ops buf_ops_newnfs;
83extern uma_zone_t ncl_pbuf_zone;
84extern short nfsv4_cbport;
85extern int nfscl_enablecallb;
86extern int nfs_numnfscbd;
87extern int nfscl_inited;
88struct mtx ncl_iod_mutex;
89NFSDLOCKMUTEX;
90extern struct mtx nfsrv_dslock_mtx;
91
92extern void (*ncl_call_invalcaches)(struct vnode *);
93
94SYSCTL_DECL(_vfs_nfs);
95static int ncl_fileid_maxwarnings = 10;
96SYSCTL_INT(_vfs_nfs, OID_AUTO, fileid_maxwarnings, CTLFLAG_RWTUN,
97    &ncl_fileid_maxwarnings, 0,
98    "Limit fileid corruption warnings; 0 is off; -1 is unlimited");
99static volatile int ncl_fileid_nwarnings;
100
101static void nfscl_warn_fileid(struct nfsmount *, struct nfsvattr *,
102    struct nfsvattr *);
103
104/*
105 * Comparison function for vfs_hash functions.
106 */
107int
108newnfs_vncmpf(struct vnode *vp, void *arg)
109{
110	struct nfsfh *nfhp = (struct nfsfh *)arg;
111	struct nfsnode *np = VTONFS(vp);
112
113	if (np->n_fhp->nfh_len != nfhp->nfh_len ||
114	    NFSBCMP(np->n_fhp->nfh_fh, nfhp->nfh_fh, nfhp->nfh_len))
115		return (1);
116	return (0);
117}
118
119/*
120 * Look up a vnode/nfsnode by file handle.
121 * Callers must check for mount points!!
122 * In all cases, a pointer to a
123 * nfsnode structure is returned.
124 * This variant takes a "struct nfsfh *" as second argument and uses
125 * that structure up, either by hanging off the nfsnode or FREEing it.
126 */
127int
128nfscl_nget(struct mount *mntp, struct vnode *dvp, struct nfsfh *nfhp,
129    struct componentname *cnp, struct thread *td, struct nfsnode **npp,
130    void *stuff, int lkflags)
131{
132	struct nfsnode *np, *dnp;
133	struct vnode *vp, *nvp;
134	struct nfsv4node *newd, *oldd;
135	int error;
136	u_int hash;
137	struct nfsmount *nmp;
138
139	nmp = VFSTONFS(mntp);
140	dnp = VTONFS(dvp);
141	*npp = NULL;
142
143	hash = fnv_32_buf(nfhp->nfh_fh, nfhp->nfh_len, FNV1_32_INIT);
144
145	error = vfs_hash_get(mntp, hash, lkflags,
146	    td, &nvp, newnfs_vncmpf, nfhp);
147	if (error == 0 && nvp != NULL) {
148		/*
149		 * I believe there is a slight chance that vgonel() could
150		 * get called on this vnode between when NFSVOPLOCK() drops
151		 * the VI_LOCK() and vget() acquires it again, so that it
152		 * hasn't yet had v_usecount incremented. If this were to
153		 * happen, the VIRF_DOOMED flag would be set, so check for
154		 * that here. Since we now have the v_usecount incremented,
155		 * we should be ok until we vrele() it, if the VIRF_DOOMED
156		 * flag isn't set now.
157		 */
158		VI_LOCK(nvp);
159		if (VN_IS_DOOMED(nvp)) {
160			VI_UNLOCK(nvp);
161			vrele(nvp);
162			error = ENOENT;
163		} else {
164			VI_UNLOCK(nvp);
165		}
166	}
167	if (error) {
168		free(nfhp, M_NFSFH);
169		return (error);
170	}
171	if (nvp != NULL) {
172		np = VTONFS(nvp);
173		/*
174		 * For NFSv4, check to see if it is the same name and
175		 * replace the name, if it is different.
176		 */
177		oldd = newd = NULL;
178		if ((nmp->nm_flag & NFSMNT_NFSV4) && np->n_v4 != NULL &&
179		    nvp->v_type == VREG &&
180		    (np->n_v4->n4_namelen != cnp->cn_namelen ||
181		     NFSBCMP(cnp->cn_nameptr, NFS4NODENAME(np->n_v4),
182		     cnp->cn_namelen) ||
183		     dnp->n_fhp->nfh_len != np->n_v4->n4_fhlen ||
184		     NFSBCMP(dnp->n_fhp->nfh_fh, np->n_v4->n4_data,
185		     dnp->n_fhp->nfh_len))) {
186		    newd = malloc(
187			sizeof (struct nfsv4node) + dnp->n_fhp->nfh_len +
188			+ cnp->cn_namelen - 1, M_NFSV4NODE, M_WAITOK);
189		    NFSLOCKNODE(np);
190		    if (newd != NULL && np->n_v4 != NULL && nvp->v_type == VREG
191			&& (np->n_v4->n4_namelen != cnp->cn_namelen ||
192			 NFSBCMP(cnp->cn_nameptr, NFS4NODENAME(np->n_v4),
193			 cnp->cn_namelen) ||
194			 dnp->n_fhp->nfh_len != np->n_v4->n4_fhlen ||
195			 NFSBCMP(dnp->n_fhp->nfh_fh, np->n_v4->n4_data,
196			 dnp->n_fhp->nfh_len))) {
197			oldd = np->n_v4;
198			np->n_v4 = newd;
199			newd = NULL;
200			np->n_v4->n4_fhlen = dnp->n_fhp->nfh_len;
201			np->n_v4->n4_namelen = cnp->cn_namelen;
202			NFSBCOPY(dnp->n_fhp->nfh_fh, np->n_v4->n4_data,
203			    dnp->n_fhp->nfh_len);
204			NFSBCOPY(cnp->cn_nameptr, NFS4NODENAME(np->n_v4),
205			    cnp->cn_namelen);
206		    }
207		    NFSUNLOCKNODE(np);
208		}
209		if (newd != NULL)
210			free(newd, M_NFSV4NODE);
211		if (oldd != NULL)
212			free(oldd, M_NFSV4NODE);
213		*npp = np;
214		free(nfhp, M_NFSFH);
215		return (0);
216	}
217	np = uma_zalloc(newnfsnode_zone, M_WAITOK | M_ZERO);
218
219	error = getnewvnode(nfs_vnode_tag, mntp, &newnfs_vnodeops, &nvp);
220	if (error) {
221		uma_zfree(newnfsnode_zone, np);
222		free(nfhp, M_NFSFH);
223		return (error);
224	}
225	vp = nvp;
226	KASSERT(vp->v_bufobj.bo_bsize != 0, ("nfscl_nget: bo_bsize == 0"));
227	vp->v_bufobj.bo_ops = &buf_ops_newnfs;
228	vp->v_data = np;
229	np->n_vnode = vp;
230	/*
231	 * Initialize the mutex even if the vnode is going to be a loser.
232	 * This simplifies the logic in reclaim, which can then unconditionally
233	 * destroy the mutex (in the case of the loser, or if hash_insert
234	 * happened to return an error no special casing is needed).
235	 */
236	mtx_init(&np->n_mtx, "NEWNFSnode lock", NULL, MTX_DEF | MTX_DUPOK);
237	lockinit(&np->n_excl, PVFS, "nfsupg", VLKTIMEOUT, LK_NOSHARE |
238	    LK_CANRECURSE);
239
240	/*
241	 * Are we getting the root? If so, make sure the vnode flags
242	 * are correct
243	 */
244	if ((nfhp->nfh_len == nmp->nm_fhsize) &&
245	    !bcmp(nfhp->nfh_fh, nmp->nm_fh, nfhp->nfh_len)) {
246		if (vp->v_type == VNON)
247			vp->v_type = VDIR;
248		vp->v_vflag |= VV_ROOT;
249	}
250
251	vp->v_vflag |= VV_VMSIZEVNLOCK;
252
253	np->n_fhp = nfhp;
254	/*
255	 * For NFSv4, we have to attach the directory file handle and
256	 * file name, so that Open Ops can be done later.
257	 */
258	if (nmp->nm_flag & NFSMNT_NFSV4) {
259		np->n_v4 = malloc(sizeof (struct nfsv4node)
260		    + dnp->n_fhp->nfh_len + cnp->cn_namelen - 1, M_NFSV4NODE,
261		    M_WAITOK);
262		np->n_v4->n4_fhlen = dnp->n_fhp->nfh_len;
263		np->n_v4->n4_namelen = cnp->cn_namelen;
264		NFSBCOPY(dnp->n_fhp->nfh_fh, np->n_v4->n4_data,
265		    dnp->n_fhp->nfh_len);
266		NFSBCOPY(cnp->cn_nameptr, NFS4NODENAME(np->n_v4),
267		    cnp->cn_namelen);
268	} else {
269		np->n_v4 = NULL;
270	}
271
272	/*
273	 * NFS supports recursive and shared locking.
274	 */
275	lockmgr(vp->v_vnlock, LK_EXCLUSIVE | LK_NOWITNESS, NULL);
276	VN_LOCK_AREC(vp);
277	VN_LOCK_ASHARE(vp);
278	error = insmntque(vp, mntp);
279	if (error != 0) {
280		*npp = NULL;
281		mtx_destroy(&np->n_mtx);
282		lockdestroy(&np->n_excl);
283		free(nfhp, M_NFSFH);
284		if (np->n_v4 != NULL)
285			free(np->n_v4, M_NFSV4NODE);
286		uma_zfree(newnfsnode_zone, np);
287		return (error);
288	}
289	error = vfs_hash_insert(vp, hash, lkflags,
290	    td, &nvp, newnfs_vncmpf, nfhp);
291	if (error)
292		return (error);
293	if (nvp != NULL) {
294		*npp = VTONFS(nvp);
295		/* vfs_hash_insert() vput()'s the losing vnode */
296		return (0);
297	}
298	*npp = np;
299
300	return (0);
301}
302
303/*
304 * Another variant of nfs_nget(). This one is only used by reopen. It
305 * takes almost the same args as nfs_nget(), but only succeeds if an entry
306 * exists in the cache. (Since files should already be "open" with a
307 * vnode ref cnt on the node when reopen calls this, it should always
308 * succeed.)
309 * Also, don't get a vnode lock, since it may already be locked by some
310 * other process that is handling it. This is ok, since all other threads
311 * on the client are blocked by the nfsc_lock being exclusively held by the
312 * caller of this function.
313 */
314int
315nfscl_ngetreopen(struct mount *mntp, u_int8_t *fhp, int fhsize,
316    struct thread *td, struct nfsnode **npp)
317{
318	struct vnode *nvp;
319	u_int hash;
320	struct nfsfh *nfhp;
321	int error;
322
323	*npp = NULL;
324	/* For forced dismounts, just return error. */
325	if (NFSCL_FORCEDISM(mntp))
326		return (EINTR);
327	nfhp = malloc(sizeof (struct nfsfh) + fhsize,
328	    M_NFSFH, M_WAITOK);
329	bcopy(fhp, &nfhp->nfh_fh[0], fhsize);
330	nfhp->nfh_len = fhsize;
331
332	hash = fnv_32_buf(fhp, fhsize, FNV1_32_INIT);
333
334	/*
335	 * First, try to get the vnode locked, but don't block for the lock.
336	 */
337	error = vfs_hash_get(mntp, hash, (LK_EXCLUSIVE | LK_NOWAIT), td, &nvp,
338	    newnfs_vncmpf, nfhp);
339	if (error == 0 && nvp != NULL) {
340		NFSVOPUNLOCK(nvp);
341	} else if (error == EBUSY) {
342		/*
343		 * It is safe so long as a vflush() with
344		 * FORCECLOSE has not been done. Since the Renew thread is
345		 * stopped and the MNTK_UNMOUNTF flag is set before doing
346		 * a vflush() with FORCECLOSE, we should be ok here.
347		 */
348		if (NFSCL_FORCEDISM(mntp))
349			error = EINTR;
350		else {
351			vfs_hash_ref(mntp, hash, td, &nvp, newnfs_vncmpf, nfhp);
352			if (nvp == NULL) {
353				error = ENOENT;
354			} else if (VN_IS_DOOMED(nvp)) {
355				error = ENOENT;
356				vrele(nvp);
357			} else {
358				error = 0;
359			}
360		}
361	}
362	free(nfhp, M_NFSFH);
363	if (error)
364		return (error);
365	if (nvp != NULL) {
366		*npp = VTONFS(nvp);
367		return (0);
368	}
369	return (EINVAL);
370}
371
372static void
373nfscl_warn_fileid(struct nfsmount *nmp, struct nfsvattr *oldnap,
374    struct nfsvattr *newnap)
375{
376	int off;
377
378	if (ncl_fileid_maxwarnings >= 0 &&
379	    ncl_fileid_nwarnings >= ncl_fileid_maxwarnings)
380		return;
381	off = 0;
382	if (ncl_fileid_maxwarnings >= 0) {
383		if (++ncl_fileid_nwarnings >= ncl_fileid_maxwarnings)
384			off = 1;
385	}
386
387	printf("newnfs: server '%s' error: fileid changed. "
388	    "fsid %jx:%jx: expected fileid %#jx, got %#jx. "
389	    "(BROKEN NFS SERVER OR MIDDLEWARE)\n",
390	    nmp->nm_com.nmcom_hostname,
391	    (uintmax_t)nmp->nm_fsid[0],
392	    (uintmax_t)nmp->nm_fsid[1],
393	    (uintmax_t)oldnap->na_fileid,
394	    (uintmax_t)newnap->na_fileid);
395
396	if (off)
397		printf("newnfs: Logged %d times about fileid corruption; "
398		    "going quiet to avoid spamming logs excessively. (Limit "
399		    "is: %d).\n", ncl_fileid_nwarnings,
400		    ncl_fileid_maxwarnings);
401}
402
403void
404ncl_copy_vattr(struct vattr *dst, struct vattr *src)
405{
406	dst->va_type = src->va_type;
407	dst->va_mode = src->va_mode;
408	dst->va_nlink = src->va_nlink;
409	dst->va_uid = src->va_uid;
410	dst->va_gid = src->va_gid;
411	dst->va_fsid = src->va_fsid;
412	dst->va_fileid = src->va_fileid;
413	dst->va_size = src->va_size;
414	dst->va_blocksize = src->va_blocksize;
415	dst->va_atime = src->va_atime;
416	dst->va_mtime = src->va_mtime;
417	dst->va_ctime = src->va_ctime;
418	dst->va_birthtime = src->va_birthtime;
419	dst->va_gen = src->va_gen;
420	dst->va_flags = src->va_flags;
421	dst->va_rdev = src->va_rdev;
422	dst->va_bytes = src->va_bytes;
423	dst->va_filerev = src->va_filerev;
424}
425
426/*
427 * Load the attribute cache (that lives in the nfsnode entry) with
428 * the attributes of the second argument and
429 * Iff vaper not NULL
430 *    copy the attributes to *vaper
431 * Similar to nfs_loadattrcache(), except the attributes are passed in
432 * instead of being parsed out of the mbuf list.
433 */
434int
435nfscl_loadattrcache(struct vnode **vpp, struct nfsvattr *nap, void *nvaper,
436    void *stuff, int writeattr, int dontshrink)
437{
438	struct vnode *vp = *vpp;
439	struct vattr *vap, *nvap = &nap->na_vattr, *vaper = nvaper;
440	struct nfsnode *np;
441	struct nfsmount *nmp;
442	struct timespec mtime_save;
443	int error, force_fid_err;
444
445	error = 0;
446
447	/*
448	 * If v_type == VNON it is a new node, so fill in the v_type,
449	 * n_mtime fields. Check to see if it represents a special
450	 * device, and if so, check for a possible alias. Once the
451	 * correct vnode has been obtained, fill in the rest of the
452	 * information.
453	 */
454	np = VTONFS(vp);
455	NFSLOCKNODE(np);
456	if (vp->v_type != nvap->va_type) {
457		vp->v_type = nvap->va_type;
458		if (vp->v_type == VFIFO)
459			vp->v_op = &newnfs_fifoops;
460		np->n_mtime = nvap->va_mtime;
461	}
462	nmp = VFSTONFS(vp->v_mount);
463	vap = &np->n_vattr.na_vattr;
464	mtime_save = vap->va_mtime;
465	if (writeattr) {
466		np->n_vattr.na_filerev = nap->na_filerev;
467		np->n_vattr.na_size = nap->na_size;
468		np->n_vattr.na_mtime = nap->na_mtime;
469		np->n_vattr.na_ctime = nap->na_ctime;
470		np->n_vattr.na_btime = nap->na_btime;
471		np->n_vattr.na_fsid = nap->na_fsid;
472		np->n_vattr.na_mode = nap->na_mode;
473	} else {
474		force_fid_err = 0;
475		KFAIL_POINT_ERROR(DEBUG_FP, nfscl_force_fileid_warning,
476		    force_fid_err);
477		/*
478		 * BROKEN NFS SERVER OR MIDDLEWARE
479		 *
480		 * Certain NFS servers (certain old proprietary filers ca.
481		 * 2006) or broken middleboxes (e.g. WAN accelerator products)
482		 * will respond to GETATTR requests with results for a
483		 * different fileid.
484		 *
485		 * The WAN accelerator we've observed not only serves stale
486		 * cache results for a given file, it also occasionally serves
487		 * results for wholly different files.  This causes surprising
488		 * problems; for example the cached size attribute of a file
489		 * may truncate down and then back up, resulting in zero
490		 * regions in file contents read by applications.  We observed
491		 * this reliably with Clang and .c files during parallel build.
492		 * A pcap revealed packet fragmentation and GETATTR RPC
493		 * responses with wholly wrong fileids.
494		 */
495		if ((np->n_vattr.na_fileid != 0 &&
496		     np->n_vattr.na_fileid != nap->na_fileid) ||
497		    force_fid_err) {
498			nfscl_warn_fileid(nmp, &np->n_vattr, nap);
499			error = EIDRM;
500			goto out;
501		}
502		NFSBCOPY((caddr_t)nap, (caddr_t)&np->n_vattr,
503		    sizeof (struct nfsvattr));
504	}
505
506	/*
507	 * For NFSv4, if the node's fsid is not equal to the mount point's
508	 * fsid, return the low order 32bits of the node's fsid. This
509	 * allows getcwd(3) to work. There is a chance that the fsid might
510	 * be the same as a local fs, but since this is in an NFS mount
511	 * point, I don't think that will cause any problems?
512	 */
513	if (NFSHASNFSV4(nmp) && NFSHASHASSETFSID(nmp) &&
514	    (nmp->nm_fsid[0] != np->n_vattr.na_filesid[0] ||
515	     nmp->nm_fsid[1] != np->n_vattr.na_filesid[1])) {
516		/*
517		 * va_fsid needs to be set to some value derived from
518		 * np->n_vattr.na_filesid that is not equal
519		 * vp->v_mount->mnt_stat.f_fsid[0], so that it changes
520		 * from the value used for the top level server volume
521		 * in the mounted subtree.
522		 */
523		vn_fsid(vp, vap);
524		if ((uint32_t)vap->va_fsid == np->n_vattr.na_filesid[0])
525			vap->va_fsid = hash32_buf(
526			    np->n_vattr.na_filesid, 2 * sizeof(uint64_t), 0);
527	} else
528		vn_fsid(vp, vap);
529	np->n_attrstamp = time_second;
530	if (vap->va_size != np->n_size) {
531		if (vap->va_type == VREG) {
532			if (dontshrink && vap->va_size < np->n_size) {
533				/*
534				 * We've been told not to shrink the file;
535				 * zero np->n_attrstamp to indicate that
536				 * the attributes are stale.
537				 */
538				vap->va_size = np->n_size;
539				np->n_attrstamp = 0;
540				KDTRACE_NFS_ATTRCACHE_FLUSH_DONE(vp);
541			} else if (np->n_flag & NMODIFIED) {
542				/*
543				 * We've modified the file: Use the larger
544				 * of our size, and the server's size.
545				 */
546				if (vap->va_size < np->n_size) {
547					vap->va_size = np->n_size;
548				} else {
549					np->n_size = vap->va_size;
550					np->n_flag |= NSIZECHANGED;
551				}
552			} else {
553				np->n_size = vap->va_size;
554				np->n_flag |= NSIZECHANGED;
555			}
556		} else {
557			np->n_size = vap->va_size;
558		}
559	}
560	/*
561	 * The following checks are added to prevent a race between (say)
562	 * a READDIR+ and a WRITE.
563	 * READDIR+, WRITE requests sent out.
564	 * READDIR+ resp, WRITE resp received on client.
565	 * However, the WRITE resp was handled before the READDIR+ resp
566	 * causing the post op attrs from the write to be loaded first
567	 * and the attrs from the READDIR+ to be loaded later. If this
568	 * happens, we have stale attrs loaded into the attrcache.
569	 * We detect this by for the mtime moving back. We invalidate the
570	 * attrcache when this happens.
571	 */
572	if (timespeccmp(&mtime_save, &vap->va_mtime, >)) {
573		/* Size changed or mtime went backwards */
574		np->n_attrstamp = 0;
575		KDTRACE_NFS_ATTRCACHE_FLUSH_DONE(vp);
576	}
577	if (vaper != NULL) {
578		ncl_copy_vattr(vaper, vap);
579		if (np->n_flag & NCHG) {
580			if (np->n_flag & NACC)
581				vaper->va_atime = np->n_atim;
582			if (np->n_flag & NUPD)
583				vaper->va_mtime = np->n_mtim;
584		}
585	}
586
587out:
588#ifdef KDTRACE_HOOKS
589	if (np->n_attrstamp != 0)
590		KDTRACE_NFS_ATTRCACHE_LOAD_DONE(vp, vap, error);
591#endif
592	(void)ncl_pager_setsize(vp, NULL);
593	return (error);
594}
595
596/*
597 * Call vnode_pager_setsize() if the size of the node changed, as
598 * recorded in nfsnode vs. v_object, or delay the call if notifying
599 * the pager is not possible at the moment.
600 *
601 * If nsizep is non-NULL, the call is delayed and the new node size is
602 * provided.  Caller should itself call vnode_pager_setsize() if
603 * function returned true.  If nsizep is NULL, function tries to call
604 * vnode_pager_setsize() itself if needed and possible, and the nfs
605 * node is unlocked unconditionally, the return value is not useful.
606 */
607bool
608ncl_pager_setsize(struct vnode *vp, u_quad_t *nsizep)
609{
610	struct nfsnode *np;
611	vm_object_t object;
612	struct vattr *vap;
613	u_quad_t nsize;
614	bool setnsize;
615
616	np = VTONFS(vp);
617	NFSASSERTNODE(np);
618
619	vap = &np->n_vattr.na_vattr;
620	nsize = vap->va_size;
621	object = vp->v_object;
622	setnsize = false;
623
624	if (object != NULL && nsize != object->un_pager.vnp.vnp_size) {
625		if (VOP_ISLOCKED(vp) == LK_EXCLUSIVE &&
626		    (curthread->td_pflags2 & TDP2_SBPAGES) == 0)
627			setnsize = true;
628		else
629			np->n_flag |= NVNSETSZSKIP;
630	}
631	if (nsizep == NULL) {
632		NFSUNLOCKNODE(np);
633		if (setnsize)
634			vnode_pager_setsize(vp, nsize);
635		setnsize = false;
636	} else {
637		*nsizep = nsize;
638	}
639	return (setnsize);
640}
641
642/*
643 * Fill in the client id name. For these bytes:
644 * 1 - they must be unique
645 * 2 - they should be persistent across client reboots
646 * 1 is more critical than 2
647 * Use the mount point's unique id plus either the uuid or, if that
648 * isn't set, random junk.
649 */
650void
651nfscl_fillclid(u_int64_t clval, char *uuid, u_int8_t *cp, u_int16_t idlen)
652{
653	int uuidlen;
654
655	/*
656	 * First, put in the 64bit mount point identifier.
657	 */
658	if (idlen >= sizeof (u_int64_t)) {
659		NFSBCOPY((caddr_t)&clval, cp, sizeof (u_int64_t));
660		cp += sizeof (u_int64_t);
661		idlen -= sizeof (u_int64_t);
662	}
663
664	/*
665	 * If uuid is non-zero length, use it.
666	 */
667	uuidlen = strlen(uuid);
668	if (uuidlen > 0 && idlen >= uuidlen) {
669		NFSBCOPY(uuid, cp, uuidlen);
670		cp += uuidlen;
671		idlen -= uuidlen;
672	}
673
674	/*
675	 * This only normally happens if the uuid isn't set.
676	 */
677	while (idlen > 0) {
678		*cp++ = (u_int8_t)(arc4random() % 256);
679		idlen--;
680	}
681}
682
683/*
684 * Fill in a lock owner name. For now, pid + the process's creation time.
685 */
686void
687nfscl_filllockowner(void *id, u_int8_t *cp, int flags)
688{
689	union {
690		u_int32_t	lval;
691		u_int8_t	cval[4];
692	} tl;
693	struct proc *p;
694
695	if (id == NULL) {
696		/* Return the single open_owner of all 0 bytes. */
697		bzero(cp, NFSV4CL_LOCKNAMELEN);
698		return;
699	}
700	if ((flags & F_POSIX) != 0) {
701		p = (struct proc *)id;
702		tl.lval = p->p_pid;
703		*cp++ = tl.cval[0];
704		*cp++ = tl.cval[1];
705		*cp++ = tl.cval[2];
706		*cp++ = tl.cval[3];
707		tl.lval = p->p_stats->p_start.tv_sec;
708		*cp++ = tl.cval[0];
709		*cp++ = tl.cval[1];
710		*cp++ = tl.cval[2];
711		*cp++ = tl.cval[3];
712		tl.lval = p->p_stats->p_start.tv_usec;
713		*cp++ = tl.cval[0];
714		*cp++ = tl.cval[1];
715		*cp++ = tl.cval[2];
716		*cp = tl.cval[3];
717	} else if ((flags & F_FLOCK) != 0) {
718		bcopy(&id, cp, sizeof(id));
719		bzero(&cp[sizeof(id)], NFSV4CL_LOCKNAMELEN - sizeof(id));
720	} else {
721		printf("nfscl_filllockowner: not F_POSIX or F_FLOCK\n");
722		bzero(cp, NFSV4CL_LOCKNAMELEN);
723	}
724}
725
726/*
727 * Find the parent process for the thread passed in as an argument.
728 * If none exists, return NULL, otherwise return a thread for the parent.
729 * (Can be any of the threads, since it is only used for td->td_proc.)
730 */
731NFSPROC_T *
732nfscl_getparent(struct thread *td)
733{
734	struct proc *p;
735	struct thread *ptd;
736
737	if (td == NULL)
738		return (NULL);
739	p = td->td_proc;
740	if (p->p_pid == 0)
741		return (NULL);
742	p = p->p_pptr;
743	if (p == NULL)
744		return (NULL);
745	ptd = TAILQ_FIRST(&p->p_threads);
746	return (ptd);
747}
748
749/*
750 * Start up the renew kernel thread.
751 */
752static void
753start_nfscl(void *arg)
754{
755	struct nfsclclient *clp;
756	struct thread *td;
757
758	clp = (struct nfsclclient *)arg;
759	td = TAILQ_FIRST(&clp->nfsc_renewthread->p_threads);
760	nfscl_renewthread(clp, td);
761	kproc_exit(0);
762}
763
764void
765nfscl_start_renewthread(struct nfsclclient *clp)
766{
767
768	kproc_create(start_nfscl, (void *)clp, &clp->nfsc_renewthread, 0, 0,
769	    "nfscl");
770}
771
772/*
773 * Handle wcc_data.
774 * For NFSv4, it assumes that nfsv4_wccattr() was used to set up the getattr
775 * as the first Op after PutFH.
776 * (For NFSv4, the postop attributes are after the Op, so they can't be
777 *  parsed here. A separate call to nfscl_postop_attr() is required.)
778 */
779int
780nfscl_wcc_data(struct nfsrv_descript *nd, struct vnode *vp,
781    struct nfsvattr *nap, int *flagp, int *wccflagp, void *stuff)
782{
783	u_int32_t *tl;
784	struct nfsnode *np = VTONFS(vp);
785	struct nfsvattr nfsva;
786	int error = 0;
787
788	if (wccflagp != NULL)
789		*wccflagp = 0;
790	if (nd->nd_flag & ND_NFSV3) {
791		*flagp = 0;
792		NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
793		if (*tl == newnfs_true) {
794			NFSM_DISSECT(tl, u_int32_t *, 6 * NFSX_UNSIGNED);
795			if (wccflagp != NULL) {
796				NFSLOCKNODE(np);
797				*wccflagp = (np->n_mtime.tv_sec ==
798				    fxdr_unsigned(u_int32_t, *(tl + 2)) &&
799				    np->n_mtime.tv_nsec ==
800				    fxdr_unsigned(u_int32_t, *(tl + 3)));
801				NFSUNLOCKNODE(np);
802			}
803		}
804		error = nfscl_postop_attr(nd, nap, flagp, stuff);
805		if (wccflagp != NULL && *flagp == 0)
806			*wccflagp = 0;
807	} else if ((nd->nd_flag & (ND_NOMOREDATA | ND_NFSV4 | ND_V4WCCATTR))
808	    == (ND_NFSV4 | ND_V4WCCATTR)) {
809		error = nfsv4_loadattr(nd, NULL, &nfsva, NULL,
810		    NULL, 0, NULL, NULL, NULL, NULL, NULL, 0,
811		    NULL, NULL, NULL, NULL, NULL);
812		if (error)
813			return (error);
814		/*
815		 * Get rid of Op# and status for next op.
816		 */
817		NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
818		if (*++tl)
819			nd->nd_flag |= ND_NOMOREDATA;
820		if (wccflagp != NULL &&
821		    nfsva.na_vattr.va_mtime.tv_sec != 0) {
822			NFSLOCKNODE(np);
823			*wccflagp = (np->n_mtime.tv_sec ==
824			    nfsva.na_vattr.va_mtime.tv_sec &&
825			    np->n_mtime.tv_nsec ==
826			    nfsva.na_vattr.va_mtime.tv_sec);
827			NFSUNLOCKNODE(np);
828		}
829	}
830nfsmout:
831	return (error);
832}
833
834/*
835 * Get postop attributes.
836 */
837int
838nfscl_postop_attr(struct nfsrv_descript *nd, struct nfsvattr *nap, int *retp,
839    void *stuff)
840{
841	u_int32_t *tl;
842	int error = 0;
843
844	*retp = 0;
845	if (nd->nd_flag & ND_NOMOREDATA)
846		return (error);
847	if (nd->nd_flag & ND_NFSV3) {
848		NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
849		*retp = fxdr_unsigned(int, *tl);
850	} else if (nd->nd_flag & ND_NFSV4) {
851		/*
852		 * For NFSv4, the postop attr are at the end, so no point
853		 * in looking if nd_repstat != 0.
854		 */
855		if (!nd->nd_repstat) {
856			NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
857			if (*(tl + 1))
858				/* should never happen since nd_repstat != 0 */
859				nd->nd_flag |= ND_NOMOREDATA;
860			else
861				*retp = 1;
862		}
863	} else if (!nd->nd_repstat) {
864		/* For NFSv2, the attributes are here iff nd_repstat == 0 */
865		*retp = 1;
866	}
867	if (*retp) {
868		error = nfsm_loadattr(nd, nap);
869		if (error)
870			*retp = 0;
871	}
872nfsmout:
873	return (error);
874}
875
876/*
877 * nfscl_request() - mostly a wrapper for newnfs_request().
878 */
879int
880nfscl_request(struct nfsrv_descript *nd, struct vnode *vp, NFSPROC_T *p,
881    struct ucred *cred, void *stuff)
882{
883	int ret, vers;
884	struct nfsmount *nmp;
885
886	nmp = VFSTONFS(vp->v_mount);
887	if (nd->nd_flag & ND_NFSV4)
888		vers = NFS_VER4;
889	else if (nd->nd_flag & ND_NFSV3)
890		vers = NFS_VER3;
891	else
892		vers = NFS_VER2;
893	ret = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, vp, p, cred,
894		NFS_PROG, vers, NULL, 1, NULL, NULL);
895	return (ret);
896}
897
898/*
899 * fill in this bsden's variant of statfs using nfsstatfs.
900 */
901void
902nfscl_loadsbinfo(struct nfsmount *nmp, struct nfsstatfs *sfp, void *statfs)
903{
904	struct statfs *sbp = (struct statfs *)statfs;
905
906	if (nmp->nm_flag & (NFSMNT_NFSV3 | NFSMNT_NFSV4)) {
907		sbp->f_bsize = NFS_FABLKSIZE;
908		sbp->f_blocks = sfp->sf_tbytes / NFS_FABLKSIZE;
909		sbp->f_bfree = sfp->sf_fbytes / NFS_FABLKSIZE;
910		/*
911		 * Although sf_abytes is uint64_t and f_bavail is int64_t,
912		 * the value after dividing by NFS_FABLKSIZE is small
913		 * enough that it will fit in 63bits, so it is ok to
914		 * assign it to f_bavail without fear that it will become
915		 * negative.
916		 */
917		sbp->f_bavail = sfp->sf_abytes / NFS_FABLKSIZE;
918		sbp->f_files = sfp->sf_tfiles;
919		/* Since f_ffree is int64_t, clip it to 63bits. */
920		if (sfp->sf_ffiles > INT64_MAX)
921			sbp->f_ffree = INT64_MAX;
922		else
923			sbp->f_ffree = sfp->sf_ffiles;
924	} else if ((nmp->nm_flag & NFSMNT_NFSV4) == 0) {
925		/*
926		 * The type casts to (int32_t) ensure that this code is
927		 * compatible with the old NFS client, in that it will
928		 * propagate bit31 to the high order bits. This may or may
929		 * not be correct for NFSv2, but since it is a legacy
930		 * environment, I'd rather retain backwards compatibility.
931		 */
932		sbp->f_bsize = (int32_t)sfp->sf_bsize;
933		sbp->f_blocks = (int32_t)sfp->sf_blocks;
934		sbp->f_bfree = (int32_t)sfp->sf_bfree;
935		sbp->f_bavail = (int32_t)sfp->sf_bavail;
936		sbp->f_files = 0;
937		sbp->f_ffree = 0;
938	}
939}
940
941/*
942 * Use the fsinfo stuff to update the mount point.
943 */
944void
945nfscl_loadfsinfo(struct nfsmount *nmp, struct nfsfsinfo *fsp)
946{
947
948	if ((nmp->nm_wsize == 0 || fsp->fs_wtpref < nmp->nm_wsize) &&
949	    fsp->fs_wtpref >= NFS_FABLKSIZE)
950		nmp->nm_wsize = (fsp->fs_wtpref + NFS_FABLKSIZE - 1) &
951		    ~(NFS_FABLKSIZE - 1);
952	if (fsp->fs_wtmax < nmp->nm_wsize && fsp->fs_wtmax > 0) {
953		nmp->nm_wsize = fsp->fs_wtmax & ~(NFS_FABLKSIZE - 1);
954		if (nmp->nm_wsize == 0)
955			nmp->nm_wsize = fsp->fs_wtmax;
956	}
957	if (nmp->nm_wsize < NFS_FABLKSIZE)
958		nmp->nm_wsize = NFS_FABLKSIZE;
959	if ((nmp->nm_rsize == 0 || fsp->fs_rtpref < nmp->nm_rsize) &&
960	    fsp->fs_rtpref >= NFS_FABLKSIZE)
961		nmp->nm_rsize = (fsp->fs_rtpref + NFS_FABLKSIZE - 1) &
962		    ~(NFS_FABLKSIZE - 1);
963	if (fsp->fs_rtmax < nmp->nm_rsize && fsp->fs_rtmax > 0) {
964		nmp->nm_rsize = fsp->fs_rtmax & ~(NFS_FABLKSIZE - 1);
965		if (nmp->nm_rsize == 0)
966			nmp->nm_rsize = fsp->fs_rtmax;
967	}
968	if (nmp->nm_rsize < NFS_FABLKSIZE)
969		nmp->nm_rsize = NFS_FABLKSIZE;
970	if ((nmp->nm_readdirsize == 0 || fsp->fs_dtpref < nmp->nm_readdirsize)
971	    && fsp->fs_dtpref >= NFS_DIRBLKSIZ)
972		nmp->nm_readdirsize = (fsp->fs_dtpref + NFS_DIRBLKSIZ - 1) &
973		    ~(NFS_DIRBLKSIZ - 1);
974	if (fsp->fs_rtmax < nmp->nm_readdirsize && fsp->fs_rtmax > 0) {
975		nmp->nm_readdirsize = fsp->fs_rtmax & ~(NFS_DIRBLKSIZ - 1);
976		if (nmp->nm_readdirsize == 0)
977			nmp->nm_readdirsize = fsp->fs_rtmax;
978	}
979	if (nmp->nm_readdirsize < NFS_DIRBLKSIZ)
980		nmp->nm_readdirsize = NFS_DIRBLKSIZ;
981	if (fsp->fs_maxfilesize > 0 &&
982	    fsp->fs_maxfilesize < nmp->nm_maxfilesize)
983		nmp->nm_maxfilesize = fsp->fs_maxfilesize;
984	nmp->nm_mountp->mnt_stat.f_iosize = newnfs_iosize(nmp);
985	nmp->nm_state |= NFSSTA_GOTFSINFO;
986}
987
988/*
989 * Lookups source address which should be used to communicate with
990 * @nmp and stores it inside @pdst.
991 *
992 * Returns 0 on success.
993 */
994u_int8_t *
995nfscl_getmyip(struct nfsmount *nmp, struct in6_addr *paddr, int *isinet6p)
996{
997#if defined(INET6) || defined(INET)
998	int fibnum;
999
1000	fibnum = curthread->td_proc->p_fibnum;
1001#endif
1002#ifdef INET
1003	if (nmp->nm_nam->sa_family == AF_INET) {
1004		struct epoch_tracker et;
1005		struct nhop_object *nh;
1006		struct sockaddr_in *sin;
1007		struct in_addr addr = {};
1008
1009		sin = (struct sockaddr_in *)nmp->nm_nam;
1010		NET_EPOCH_ENTER(et);
1011		CURVNET_SET(CRED_TO_VNET(nmp->nm_sockreq.nr_cred));
1012		nh = fib4_lookup(fibnum, sin->sin_addr, 0, NHR_NONE, 0);
1013		CURVNET_RESTORE();
1014		if (nh != NULL)
1015			addr = IA_SIN(ifatoia(nh->nh_ifa))->sin_addr;
1016		NET_EPOCH_EXIT(et);
1017		if (nh == NULL)
1018			return (NULL);
1019
1020		if (IN_LOOPBACK(ntohl(addr.s_addr))) {
1021			/* Ignore loopback addresses */
1022			return (NULL);
1023		}
1024
1025		*isinet6p = 0;
1026		*((struct in_addr *)paddr) = addr;
1027
1028		return (u_int8_t *)paddr;
1029	}
1030#endif
1031#ifdef INET6
1032	if (nmp->nm_nam->sa_family == AF_INET6) {
1033		struct epoch_tracker et;
1034		struct sockaddr_in6 *sin6;
1035		int error;
1036
1037		sin6 = (struct sockaddr_in6 *)nmp->nm_nam;
1038
1039		NET_EPOCH_ENTER(et);
1040		CURVNET_SET(CRED_TO_VNET(nmp->nm_sockreq.nr_cred));
1041		error = in6_selectsrc_addr(fibnum, &sin6->sin6_addr,
1042		    sin6->sin6_scope_id, NULL, paddr, NULL);
1043		CURVNET_RESTORE();
1044		NET_EPOCH_EXIT(et);
1045		if (error != 0)
1046			return (NULL);
1047
1048		if (IN6_IS_ADDR_LOOPBACK(paddr))
1049			return (NULL);
1050
1051		/* Scope is embedded in */
1052		*isinet6p = 1;
1053
1054		return (u_int8_t *)paddr;
1055	}
1056#endif
1057	return (NULL);
1058}
1059
1060/*
1061 * Copy NFS uid, gids from the cred structure.
1062 */
1063void
1064newnfs_copyincred(struct ucred *cr, struct nfscred *nfscr)
1065{
1066	int i;
1067
1068	KASSERT(cr->cr_ngroups >= 0,
1069	    ("newnfs_copyincred: negative cr_ngroups"));
1070	nfscr->nfsc_uid = cr->cr_uid;
1071	nfscr->nfsc_ngroups = MIN(cr->cr_ngroups, NFS_MAXGRPS + 1);
1072	for (i = 0; i < nfscr->nfsc_ngroups; i++)
1073		nfscr->nfsc_groups[i] = cr->cr_groups[i];
1074}
1075
1076/*
1077 * Do any client specific initialization.
1078 */
1079void
1080nfscl_init(void)
1081{
1082	static int inited = 0;
1083
1084	if (inited)
1085		return;
1086	inited = 1;
1087	nfscl_inited = 1;
1088	ncl_pbuf_zone = pbuf_zsecond_create("nfspbuf", nswbuf / 2);
1089}
1090
1091/*
1092 * Check each of the attributes to be set, to ensure they aren't already
1093 * the correct value. Disable setting ones already correct.
1094 */
1095int
1096nfscl_checksattr(struct vattr *vap, struct nfsvattr *nvap)
1097{
1098
1099	if (vap->va_mode != (mode_t)VNOVAL) {
1100		if (vap->va_mode == nvap->na_mode)
1101			vap->va_mode = (mode_t)VNOVAL;
1102	}
1103	if (vap->va_uid != (uid_t)VNOVAL) {
1104		if (vap->va_uid == nvap->na_uid)
1105			vap->va_uid = (uid_t)VNOVAL;
1106	}
1107	if (vap->va_gid != (gid_t)VNOVAL) {
1108		if (vap->va_gid == nvap->na_gid)
1109			vap->va_gid = (gid_t)VNOVAL;
1110	}
1111	if (vap->va_size != VNOVAL) {
1112		if (vap->va_size == nvap->na_size)
1113			vap->va_size = VNOVAL;
1114	}
1115
1116	/*
1117	 * We are normally called with only a partially initialized
1118	 * VAP.  Since the NFSv3 spec says that server may use the
1119	 * file attributes to store the verifier, the spec requires
1120	 * us to do a SETATTR RPC. FreeBSD servers store the verifier
1121	 * in atime, but we can't really assume that all servers will
1122	 * so we ensure that our SETATTR sets both atime and mtime.
1123	 * Set the VA_UTIMES_NULL flag for this case, so that
1124	 * the server's time will be used.  This is needed to
1125	 * work around a bug in some Solaris servers, where
1126	 * setting the time TOCLIENT causes the Setattr RPC
1127	 * to return NFS_OK, but not set va_mode.
1128	 */
1129	if (vap->va_mtime.tv_sec == VNOVAL) {
1130		vfs_timestamp(&vap->va_mtime);
1131		vap->va_vaflags |= VA_UTIMES_NULL;
1132	}
1133	if (vap->va_atime.tv_sec == VNOVAL)
1134		vap->va_atime = vap->va_mtime;
1135	return (1);
1136}
1137
1138/*
1139 * Map nfsv4 errors to errno.h errors.
1140 * The uid and gid arguments are only used for NFSERR_BADOWNER and that
1141 * error should only be returned for the Open, Create and Setattr Ops.
1142 * As such, most calls can just pass in 0 for those arguments.
1143 */
1144int
1145nfscl_maperr(struct thread *td, int error, uid_t uid, gid_t gid)
1146{
1147	struct proc *p;
1148
1149	if (error < 10000 || error >= NFSERR_STALEWRITEVERF)
1150		return (error);
1151	if (td != NULL)
1152		p = td->td_proc;
1153	else
1154		p = NULL;
1155	switch (error) {
1156	case NFSERR_BADOWNER:
1157		tprintf(p, LOG_INFO,
1158		    "No name and/or group mapping for uid,gid:(%d,%d)\n",
1159		    uid, gid);
1160		return (EPERM);
1161	case NFSERR_BADNAME:
1162	case NFSERR_BADCHAR:
1163		printf("nfsv4 char/name not handled by server\n");
1164		return (ENOENT);
1165	case NFSERR_STALECLIENTID:
1166	case NFSERR_STALESTATEID:
1167	case NFSERR_EXPIRED:
1168	case NFSERR_BADSTATEID:
1169	case NFSERR_BADSESSION:
1170		printf("nfsv4 recover err returned %d\n", error);
1171		return (EIO);
1172	case NFSERR_BADHANDLE:
1173	case NFSERR_SERVERFAULT:
1174	case NFSERR_BADTYPE:
1175	case NFSERR_FHEXPIRED:
1176	case NFSERR_RESOURCE:
1177	case NFSERR_MOVED:
1178	case NFSERR_NOFILEHANDLE:
1179	case NFSERR_MINORVERMISMATCH:
1180	case NFSERR_OLDSTATEID:
1181	case NFSERR_BADSEQID:
1182	case NFSERR_LEASEMOVED:
1183	case NFSERR_RECLAIMBAD:
1184	case NFSERR_BADXDR:
1185	case NFSERR_OPILLEGAL:
1186		printf("nfsv4 client/server protocol prob err=%d\n",
1187		    error);
1188		return (EIO);
1189	default:
1190		tprintf(p, LOG_INFO, "nfsv4 err=%d\n", error);
1191		return (EIO);
1192	};
1193}
1194
1195/*
1196 * Check to see if the process for this owner exists. Return 1 if it doesn't
1197 * and 0 otherwise.
1198 */
1199int
1200nfscl_procdoesntexist(u_int8_t *own)
1201{
1202	union {
1203		u_int32_t	lval;
1204		u_int8_t	cval[4];
1205	} tl;
1206	struct proc *p;
1207	pid_t pid;
1208	int i, ret = 0;
1209
1210	/* For the single open_owner of all 0 bytes, just return 0. */
1211	for (i = 0; i < NFSV4CL_LOCKNAMELEN; i++)
1212		if (own[i] != 0)
1213			break;
1214	if (i == NFSV4CL_LOCKNAMELEN)
1215		return (0);
1216
1217	tl.cval[0] = *own++;
1218	tl.cval[1] = *own++;
1219	tl.cval[2] = *own++;
1220	tl.cval[3] = *own++;
1221	pid = tl.lval;
1222	p = pfind_any_locked(pid);
1223	if (p == NULL)
1224		return (1);
1225	if (p->p_stats == NULL) {
1226		PROC_UNLOCK(p);
1227		return (0);
1228	}
1229	tl.cval[0] = *own++;
1230	tl.cval[1] = *own++;
1231	tl.cval[2] = *own++;
1232	tl.cval[3] = *own++;
1233	if (tl.lval != p->p_stats->p_start.tv_sec) {
1234		ret = 1;
1235	} else {
1236		tl.cval[0] = *own++;
1237		tl.cval[1] = *own++;
1238		tl.cval[2] = *own++;
1239		tl.cval[3] = *own;
1240		if (tl.lval != p->p_stats->p_start.tv_usec)
1241			ret = 1;
1242	}
1243	PROC_UNLOCK(p);
1244	return (ret);
1245}
1246
1247/*
1248 * - nfs pseudo system call for the client
1249 */
1250/*
1251 * MPSAFE
1252 */
1253static int
1254nfssvc_nfscl(struct thread *td, struct nfssvc_args *uap)
1255{
1256	struct file *fp;
1257	struct nfscbd_args nfscbdarg;
1258	struct nfsd_nfscbd_args nfscbdarg2;
1259	struct nameidata nd;
1260	struct nfscl_dumpmntopts dumpmntopts;
1261	cap_rights_t rights;
1262	char *buf;
1263	int error;
1264	struct mount *mp;
1265	struct nfsmount *nmp;
1266
1267	if (uap->flag & NFSSVC_CBADDSOCK) {
1268		error = copyin(uap->argp, (caddr_t)&nfscbdarg, sizeof(nfscbdarg));
1269		if (error)
1270			return (error);
1271		/*
1272		 * Since we don't know what rights might be required,
1273		 * pretend that we need them all. It is better to be too
1274		 * careful than too reckless.
1275		 */
1276		error = fget(td, nfscbdarg.sock,
1277		    cap_rights_init_one(&rights, CAP_SOCK_CLIENT), &fp);
1278		if (error)
1279			return (error);
1280		if (fp->f_type != DTYPE_SOCKET) {
1281			fdrop(fp, td);
1282			return (EPERM);
1283		}
1284		error = nfscbd_addsock(fp);
1285		fdrop(fp, td);
1286		if (!error && nfscl_enablecallb == 0) {
1287			nfsv4_cbport = nfscbdarg.port;
1288			nfscl_enablecallb = 1;
1289		}
1290	} else if (uap->flag & NFSSVC_NFSCBD) {
1291		if (uap->argp == NULL)
1292			return (EINVAL);
1293		error = copyin(uap->argp, (caddr_t)&nfscbdarg2,
1294		    sizeof(nfscbdarg2));
1295		if (error)
1296			return (error);
1297		error = nfscbd_nfsd(td, &nfscbdarg2);
1298	} else if (uap->flag & NFSSVC_DUMPMNTOPTS) {
1299		error = copyin(uap->argp, &dumpmntopts, sizeof(dumpmntopts));
1300		if (error == 0 && (dumpmntopts.ndmnt_blen < 256 ||
1301		    dumpmntopts.ndmnt_blen > 1024))
1302			error = EINVAL;
1303		if (error == 0)
1304			error = nfsrv_lookupfilename(&nd,
1305			    dumpmntopts.ndmnt_fname, td);
1306		if (error == 0 && strcmp(nd.ni_vp->v_mount->mnt_vfc->vfc_name,
1307		    "nfs") != 0) {
1308			vput(nd.ni_vp);
1309			error = EINVAL;
1310		}
1311		if (error == 0) {
1312			buf = malloc(dumpmntopts.ndmnt_blen, M_TEMP, M_WAITOK);
1313			nfscl_retopts(VFSTONFS(nd.ni_vp->v_mount), buf,
1314			    dumpmntopts.ndmnt_blen);
1315			vput(nd.ni_vp);
1316			error = copyout(buf, dumpmntopts.ndmnt_buf,
1317			    dumpmntopts.ndmnt_blen);
1318			free(buf, M_TEMP);
1319		}
1320	} else if (uap->flag & NFSSVC_FORCEDISM) {
1321		buf = malloc(MNAMELEN + 1, M_TEMP, M_WAITOK);
1322		error = copyinstr(uap->argp, buf, MNAMELEN + 1, NULL);
1323		if (error == 0) {
1324			nmp = NULL;
1325			mtx_lock(&mountlist_mtx);
1326			TAILQ_FOREACH(mp, &mountlist, mnt_list) {
1327				if (strcmp(mp->mnt_stat.f_mntonname, buf) ==
1328				    0 && strcmp(mp->mnt_stat.f_fstypename,
1329				    "nfs") == 0 && mp->mnt_data != NULL) {
1330					nmp = VFSTONFS(mp);
1331					NFSDDSLOCK();
1332					if (nfsv4_findmirror(nmp) != NULL) {
1333						NFSDDSUNLOCK();
1334						error = ENXIO;
1335						nmp = NULL;
1336						break;
1337					}
1338					mtx_lock(&nmp->nm_mtx);
1339					if ((nmp->nm_privflag &
1340					    NFSMNTP_FORCEDISM) == 0) {
1341						nmp->nm_privflag |=
1342						   (NFSMNTP_FORCEDISM |
1343						    NFSMNTP_CANCELRPCS);
1344						mtx_unlock(&nmp->nm_mtx);
1345					} else {
1346						mtx_unlock(&nmp->nm_mtx);
1347						nmp = NULL;
1348					}
1349					NFSDDSUNLOCK();
1350					break;
1351				}
1352			}
1353			mtx_unlock(&mountlist_mtx);
1354
1355			if (nmp != NULL) {
1356				/*
1357				 * Call newnfs_nmcancelreqs() to cause
1358				 * any RPCs in progress on the mount point to
1359				 * fail.
1360				 * This will cause any process waiting for an
1361				 * RPC to complete while holding a vnode lock
1362				 * on the mounted-on vnode (such as "df" or
1363				 * a non-forced "umount") to fail.
1364				 * This will unlock the mounted-on vnode so
1365				 * a forced dismount can succeed.
1366				 * Then clear NFSMNTP_CANCELRPCS and wakeup(),
1367				 * so that nfs_unmount() can complete.
1368				 */
1369				newnfs_nmcancelreqs(nmp);
1370				mtx_lock(&nmp->nm_mtx);
1371				nmp->nm_privflag &= ~NFSMNTP_CANCELRPCS;
1372				wakeup(nmp);
1373				mtx_unlock(&nmp->nm_mtx);
1374			} else if (error == 0)
1375				error = EINVAL;
1376		}
1377		free(buf, M_TEMP);
1378	} else {
1379		error = EINVAL;
1380	}
1381	return (error);
1382}
1383
1384extern int (*nfsd_call_nfscl)(struct thread *, struct nfssvc_args *);
1385
1386/*
1387 * Called once to initialize data structures...
1388 */
1389static int
1390nfscl_modevent(module_t mod, int type, void *data)
1391{
1392	int error = 0;
1393	static int loaded = 0;
1394
1395	switch (type) {
1396	case MOD_LOAD:
1397		if (loaded)
1398			return (0);
1399		newnfs_portinit();
1400		mtx_init(&ncl_iod_mutex, "ncl_iod_mutex", NULL, MTX_DEF);
1401		nfscl_init();
1402		NFSD_LOCK();
1403		nfsrvd_cbinit(0);
1404		NFSD_UNLOCK();
1405		ncl_call_invalcaches = ncl_invalcaches;
1406		nfsd_call_nfscl = nfssvc_nfscl;
1407		loaded = 1;
1408		break;
1409
1410	case MOD_UNLOAD:
1411		if (nfs_numnfscbd != 0) {
1412			error = EBUSY;
1413			break;
1414		}
1415
1416		/*
1417		 * XXX: Unloading of nfscl module is unsupported.
1418		 */
1419#if 0
1420		ncl_call_invalcaches = NULL;
1421		nfsd_call_nfscl = NULL;
1422		uma_zdestroy(ncl_pbuf_zone);
1423		/* and get rid of the mutexes */
1424		mtx_destroy(&ncl_iod_mutex);
1425		loaded = 0;
1426		break;
1427#else
1428		/* FALLTHROUGH */
1429#endif
1430	default:
1431		error = EOPNOTSUPP;
1432		break;
1433	}
1434	return error;
1435}
1436static moduledata_t nfscl_mod = {
1437	"nfscl",
1438	nfscl_modevent,
1439	NULL,
1440};
1441DECLARE_MODULE(nfscl, nfscl_mod, SI_SUB_VFS, SI_ORDER_FIRST);
1442
1443/* So that loader and kldload(2) can find us, wherever we are.. */
1444MODULE_VERSION(nfscl, 1);
1445MODULE_DEPEND(nfscl, nfscommon, 1, 1, 1);
1446MODULE_DEPEND(nfscl, krpc, 1, 1, 1);
1447MODULE_DEPEND(nfscl, nfssvc, 1, 1, 1);
1448