xref: /csrg-svn/sys/nfs/nfs_serv.c (revision 42467)
138418Smckusick /*
238418Smckusick  * Copyright (c) 1989 The Regents of the University of California.
338418Smckusick  * All rights reserved.
438418Smckusick  *
538418Smckusick  * This code is derived from software contributed to Berkeley by
638418Smckusick  * Rick Macklem at The University of Guelph.
738418Smckusick  *
838418Smckusick  * Redistribution and use in source and binary forms are permitted
938418Smckusick  * provided that the above copyright notice and this paragraph are
1038418Smckusick  * duplicated in all such forms and that any documentation,
1138418Smckusick  * advertising materials, and other materials related to such
1238418Smckusick  * distribution and use acknowledge that the software was developed
1338418Smckusick  * by the University of California, Berkeley.  The name of the
1438418Smckusick  * University may not be used to endorse or promote products derived
1538418Smckusick  * from this software without specific prior written permission.
1638418Smckusick  * THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR
1738418Smckusick  * IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
1838418Smckusick  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
1938418Smckusick  *
20*42467Smckusick  *	@(#)nfs_serv.c	7.21 (Berkeley) 05/30/90
2138418Smckusick  */
2238418Smckusick 
2338418Smckusick /*
2438418Smckusick  * nfs version 2 server calls to vnode ops
2538418Smckusick  * - these routines generally have 3 phases
2638418Smckusick  *   1 - break down and validate rpc request in mbuf list
2738418Smckusick  *   2 - do the vnode ops for the request
2838425Smckusick  *       (surprisingly ?? many are very similar to syscalls in vfs_syscalls.c)
2938418Smckusick  *   3 - build the rpc reply in an mbuf list
3038418Smckusick  *   nb:
3138418Smckusick  *	- do not mix the phases, since the nfsm_?? macros can return failures
3241899Smckusick  *	  on a bad rpc or similar and do not do any vrele() or vput()'s
3338418Smckusick  *
3438425Smckusick  *      - the nfsm_reply() macro generates an nfs rpc reply with the nfs
3538418Smckusick  *	error number iff error != 0 whereas
3641899Smckusick  *	returning an error from the server function implies a fatal error
3741899Smckusick  *	such as a badly constructed rpc request that should be dropped without
3841899Smckusick  *	a reply.
3938418Smckusick  */
4038418Smckusick 
4138418Smckusick #include "param.h"
4240135Smckusick #include "user.h"
4340135Smckusick #include "file.h"
4440135Smckusick #include "vnode.h"
4538418Smckusick #include "mount.h"
4638418Smckusick #include "mbuf.h"
4738418Smckusick #include "errno.h"
4842242Smckusick #include "../ufs/quota.h"
4942242Smckusick #include "../ufs/inode.h"
5038418Smckusick #include "nfsv2.h"
5138418Smckusick #include "nfs.h"
5238418Smckusick #include "xdr_subs.h"
5338418Smckusick #include "nfsm_subs.h"
5438418Smckusick 
5538418Smckusick /* Defs */
5638425Smckusick #define	TRUE	1
5738425Smckusick #define	FALSE	0
5838418Smckusick 
5938418Smckusick /* Global vars */
6038418Smckusick extern u_long nfs_procids[NFS_NPROCS];
6138418Smckusick extern u_long nfs_xdrneg1;
6238418Smckusick extern u_long nfs_false, nfs_true;
6342242Smckusick nfstype nfs_type[9]={ NFNON, NFREG, NFDIR, NFBLK, NFCHR, NFLNK, NFNON,
6442242Smckusick 		      NFCHR, NFNON };
6538418Smckusick 
6638418Smckusick /*
6738418Smckusick  * nfs getattr service
6838418Smckusick  */
6939753Smckusick nfsrv_getattr(mrep, md, dpos, cred, xid, mrq, repstat)
7038418Smckusick 	struct mbuf **mrq;
7138418Smckusick 	struct mbuf *mrep, *md;
7238418Smckusick 	caddr_t dpos;
7338418Smckusick 	struct ucred *cred;
7438418Smckusick 	u_long xid;
7539753Smckusick 	int *repstat;
7638418Smckusick {
7738884Smacklem 	register struct nfsv2_fattr *fp;
7838418Smckusick 	struct vattr va;
7938418Smckusick 	register struct vattr *vap = &va;
8038418Smckusick 	struct vnode *vp;
8138418Smckusick 	nfsv2fh_t nfh;
8238418Smckusick 	fhandle_t *fhp;
8339494Smckusick 	register u_long *p;
8439494Smckusick 	register long t1;
8539494Smckusick 	caddr_t bpos;
8639494Smckusick 	int error = 0;
8739494Smckusick 	char *cp2;
8839753Smckusick 	struct mbuf *mb, *mb2, *mreq;
8938418Smckusick 
9038418Smckusick 	fhp = &nfh.fh_generic;
9138418Smckusick 	nfsm_srvmtofh(fhp);
9238418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
9338418Smckusick 		nfsm_reply(0);
9438418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
9538418Smckusick 	vput(vp);
9638418Smckusick 	nfsm_reply(NFSX_FATTR);
9738884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
9839753Smckusick 	nfsm_srvfillattr;
9938418Smckusick 	nfsm_srvdone;
10038418Smckusick }
10138418Smckusick 
10238418Smckusick /*
10338418Smckusick  * nfs setattr service
10438418Smckusick  */
10539753Smckusick nfsrv_setattr(mrep, md, dpos, cred, xid, mrq, repstat)
10638418Smckusick 	struct mbuf **mrq;
10738418Smckusick 	struct mbuf *mrep, *md;
10838418Smckusick 	caddr_t dpos;
10938418Smckusick 	struct ucred *cred;
11038418Smckusick 	u_long xid;
11139753Smckusick 	int *repstat;
11238418Smckusick {
11338418Smckusick 	struct vattr va;
11438418Smckusick 	register struct vattr *vap = &va;
11538884Smacklem 	register struct nfsv2_sattr *sp;
11638884Smacklem 	register struct nfsv2_fattr *fp;
11738418Smckusick 	struct vnode *vp;
11838418Smckusick 	nfsv2fh_t nfh;
11938418Smckusick 	fhandle_t *fhp;
12039494Smckusick 	register u_long *p;
12139494Smckusick 	register long t1;
12239494Smckusick 	caddr_t bpos;
12339494Smckusick 	int error = 0;
12439494Smckusick 	char *cp2;
12539753Smckusick 	struct mbuf *mb, *mb2, *mreq;
12638418Smckusick 
12738418Smckusick 	fhp = &nfh.fh_generic;
12838418Smckusick 	nfsm_srvmtofh(fhp);
12938884Smacklem 	nfsm_disect(sp, struct nfsv2_sattr *, NFSX_SATTR);
13038418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
13138418Smckusick 		nfsm_reply(0);
13238450Smckusick 	if (error = nfsrv_access(vp, VWRITE, cred))
13338418Smckusick 		goto out;
13441361Smckusick 	VATTR_NULL(vap);
13538418Smckusick 	/*
13638418Smckusick 	 * Nah nah nah nah na nah
13738418Smckusick 	 * There is a bug in the Sun client that puts 0xffff in the mode
13838418Smckusick 	 * field of sattr when it should put in 0xffffffff. The u_short
13938418Smckusick 	 * doesn't sign extend.
14038418Smckusick 	 * --> check the low order 2 bytes for 0xffff
14138418Smckusick 	 */
14238884Smacklem 	if ((fxdr_unsigned(int, sp->sa_mode) & 0xffff) != 0xffff)
14338884Smacklem 		vap->va_mode = nfstov_mode(sp->sa_mode);
14438884Smacklem 	if (sp->sa_uid != nfs_xdrneg1)
14538884Smacklem 		vap->va_uid = fxdr_unsigned(uid_t, sp->sa_uid);
14638884Smacklem 	if (sp->sa_gid != nfs_xdrneg1)
14738884Smacklem 		vap->va_gid = fxdr_unsigned(gid_t, sp->sa_gid);
14839753Smckusick 	if (sp->sa_size != nfs_xdrneg1)
14938884Smacklem 		vap->va_size = fxdr_unsigned(u_long, sp->sa_size);
15039753Smckusick 	/*
15139753Smckusick 	 * The usec field of sa_atime is overloaded with the va_flags field
15239753Smckusick 	 * for 4.4BSD clients. Hopefully other clients always set both the
15339753Smckusick 	 * sec and usec fields to -1 when not setting the atime.
15439753Smckusick 	 */
15539753Smckusick 	if (sp->sa_atime.tv_sec != nfs_xdrneg1) {
15639753Smckusick 		vap->va_atime.tv_sec = fxdr_unsigned(long, sp->sa_atime.tv_sec);
15739753Smckusick 		vap->va_atime.tv_usec = 0;
15838425Smckusick 	}
15939753Smckusick 	if (sp->sa_atime.tv_usec != nfs_xdrneg1)
16039753Smckusick 		vap->va_flags = fxdr_unsigned(u_long, sp->sa_atime.tv_usec);
16138884Smacklem 	if (sp->sa_mtime.tv_sec != nfs_xdrneg1)
16238884Smacklem 		fxdr_time(&sp->sa_mtime, &vap->va_mtime);
16338418Smckusick 	if (error = VOP_SETATTR(vp, vap, cred)) {
16438418Smckusick 		vput(vp);
16538418Smckusick 		nfsm_reply(0);
16638418Smckusick 	}
16738418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
16838418Smckusick out:
16938418Smckusick 	vput(vp);
17038418Smckusick 	nfsm_reply(NFSX_FATTR);
17138884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
17239753Smckusick 	nfsm_srvfillattr;
17338418Smckusick 	nfsm_srvdone;
17438418Smckusick }
17538418Smckusick 
17638418Smckusick /*
17738418Smckusick  * nfs lookup rpc
17838418Smckusick  */
17939753Smckusick nfsrv_lookup(mrep, md, dpos, cred, xid, mrq, repstat)
18038418Smckusick 	struct mbuf **mrq;
18138418Smckusick 	struct mbuf *mrep, *md;
18238418Smckusick 	caddr_t dpos;
18338418Smckusick 	struct ucred *cred;
18438418Smckusick 	u_long xid;
18539753Smckusick 	int *repstat;
18638418Smckusick {
18738884Smacklem 	register struct nfsv2_fattr *fp;
18839343Smckusick 	struct nameidata nami;
18939343Smckusick 	register struct nameidata *ndp = &nami;
19038418Smckusick 	struct vnode *vp;
19138418Smckusick 	nfsv2fh_t nfh;
19238418Smckusick 	fhandle_t *fhp;
19339494Smckusick 	register caddr_t cp;
19439494Smckusick 	register u_long *p;
19539494Smckusick 	register long t1;
19639494Smckusick 	caddr_t bpos;
19739494Smckusick 	int error = 0;
19839494Smckusick 	char *cp2;
19939753Smckusick 	struct mbuf *mb, *mb2, *mreq;
20038418Smckusick 	long len;
20138418Smckusick 	struct vattr va, *vap = &va;
20238418Smckusick 
20339343Smckusick 	ndinit(ndp);
20438418Smckusick 	fhp = &nfh.fh_generic;
20538418Smckusick 	nfsm_srvmtofh(fhp);
20638418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
20738418Smckusick 	ndp->ni_cred = cred;
20838418Smckusick 	ndp->ni_nameiop = LOOKUP | LOCKLEAF;
20938418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
21038418Smckusick 		nfsm_reply(0);
21138418Smckusick 	vp = ndp->ni_vp;
21238418Smckusick 	bzero((caddr_t)fhp, sizeof(nfh));
21341398Smckusick 	fhp->fh_fsid = vp->v_mount->mnt_stat.f_fsid;
21438418Smckusick 	if (error = VFS_VPTOFH(vp, &fhp->fh_fid)) {
21538418Smckusick 		vput(vp);
21638418Smckusick 		nfsm_reply(0);
21738418Smckusick 	}
21838418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
21938418Smckusick 	vput(vp);
22038418Smckusick 	nfsm_reply(NFSX_FH+NFSX_FATTR);
22138418Smckusick 	nfsm_srvfhtom(fhp);
22238884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
22339753Smckusick 	nfsm_srvfillattr;
22438418Smckusick 	nfsm_srvdone;
22538418Smckusick }
22638418Smckusick 
22738418Smckusick /*
22838418Smckusick  * nfs readlink service
22938418Smckusick  */
23039753Smckusick nfsrv_readlink(mrep, md, dpos, cred, xid, mrq, repstat)
23138418Smckusick 	struct mbuf **mrq;
23238418Smckusick 	struct mbuf *mrep, *md;
23338418Smckusick 	caddr_t dpos;
23438418Smckusick 	struct ucred *cred;
23539753Smckusick 	u_long xid;
23639753Smckusick 	int *repstat;
23738418Smckusick {
23841899Smckusick 	struct iovec iv[(NFS_MAXPATHLEN+MLEN-1)/MLEN];
23938418Smckusick 	register struct iovec *ivp = iv;
24038418Smckusick 	register struct mbuf *mp;
24139494Smckusick 	register u_long *p;
24239494Smckusick 	register long t1;
24339494Smckusick 	caddr_t bpos;
24439494Smckusick 	int error = 0;
24539494Smckusick 	char *cp2;
24639753Smckusick 	struct mbuf *mb, *mb2, *mp2, *mp3, *mreq;
24738418Smckusick 	struct vnode *vp;
24838418Smckusick 	nfsv2fh_t nfh;
24938418Smckusick 	fhandle_t *fhp;
25038418Smckusick 	struct uio io, *uiop = &io;
25138418Smckusick 	int i, tlen, len;
25238418Smckusick 
25338418Smckusick 	fhp = &nfh.fh_generic;
25438418Smckusick 	nfsm_srvmtofh(fhp);
25538418Smckusick 	len = 0;
25638418Smckusick 	i = 0;
25738418Smckusick 	while (len < NFS_MAXPATHLEN) {
25838418Smckusick 		MGET(mp, M_WAIT, MT_DATA);
25941899Smckusick 		MCLGET(mp, M_WAIT);
26038418Smckusick 		mp->m_len = NFSMSIZ(mp);
26138418Smckusick 		if (len == 0)
26238418Smckusick 			mp3 = mp2 = mp;
26341899Smckusick 		else {
26438418Smckusick 			mp2->m_next = mp;
26541899Smckusick 			mp2 = mp;
26641899Smckusick 		}
26738418Smckusick 		if ((len+mp->m_len) > NFS_MAXPATHLEN) {
26838418Smckusick 			mp->m_len = NFS_MAXPATHLEN-len;
26938418Smckusick 			len = NFS_MAXPATHLEN;
27038418Smckusick 		} else
27138418Smckusick 			len += mp->m_len;
27238418Smckusick 		ivp->iov_base = mtod(mp, caddr_t);
27338418Smckusick 		ivp->iov_len = mp->m_len;
27438418Smckusick 		i++;
27538418Smckusick 		ivp++;
27638418Smckusick 	}
27738418Smckusick 	uiop->uio_iov = iv;
27838418Smckusick 	uiop->uio_iovcnt = i;
27938418Smckusick 	uiop->uio_offset = 0;
28038418Smckusick 	uiop->uio_resid = len;
28138418Smckusick 	uiop->uio_rw = UIO_READ;
28238418Smckusick 	uiop->uio_segflg = UIO_SYSSPACE;
28338418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred)) {
28438418Smckusick 		m_freem(mp3);
28538418Smckusick 		nfsm_reply(0);
28638418Smckusick 	}
28738418Smckusick 	if (vp->v_type != VLNK) {
28838418Smckusick 		error = EINVAL;
28938418Smckusick 		goto out;
29038418Smckusick 	}
29138418Smckusick 	error = VOP_READLINK(vp, uiop, cred);
29238418Smckusick out:
29338418Smckusick 	vput(vp);
29438418Smckusick 	if (error)
29538418Smckusick 		m_freem(mp3);
29638418Smckusick 	nfsm_reply(NFSX_UNSIGNED);
29738418Smckusick 	if (uiop->uio_resid > 0) {
29838418Smckusick 		len -= uiop->uio_resid;
29938418Smckusick 		tlen = nfsm_rndup(len);
30038418Smckusick 		nfsm_adj(mp3, NFS_MAXPATHLEN-tlen, tlen-len);
30138418Smckusick 	}
30238418Smckusick 	nfsm_build(p, u_long *, NFSX_UNSIGNED);
30338418Smckusick 	*p = txdr_unsigned(len);
30438418Smckusick 	mb->m_next = mp3;
30538418Smckusick 	nfsm_srvdone;
30638418Smckusick }
30738418Smckusick 
30838418Smckusick /*
30938418Smckusick  * nfs read service
31038418Smckusick  */
31139753Smckusick nfsrv_read(mrep, md, dpos, cred, xid, mrq, repstat)
31238418Smckusick 	struct mbuf **mrq;
31338418Smckusick 	struct mbuf *mrep, *md;
31438418Smckusick 	caddr_t dpos;
31538418Smckusick 	struct ucred *cred;
31638418Smckusick 	u_long xid;
31739753Smckusick 	int *repstat;
31838418Smckusick {
31941899Smckusick 	struct iovec iv[(NFS_MAXDATA+MLEN-1)/MLEN];
32041899Smckusick 	register struct mbuf *m;
32138884Smacklem 	register struct nfsv2_fattr *fp;
32239494Smckusick 	register u_long *p;
32339494Smckusick 	register long t1;
32439494Smckusick 	caddr_t bpos;
32539494Smckusick 	int error = 0;
32639494Smckusick 	char *cp2;
32739753Smckusick 	struct mbuf *mb, *mb2, *mreq;
32841899Smckusick 	struct mbuf *m2, *m3;
32938418Smckusick 	struct vnode *vp;
33038418Smckusick 	nfsv2fh_t nfh;
33138418Smckusick 	fhandle_t *fhp;
33238418Smckusick 	struct uio io, *uiop = &io;
33338418Smckusick 	struct vattr va, *vap = &va;
33441899Smckusick 	int i, cnt, len, left, siz, tlen;
33538418Smckusick 	off_t off;
33638418Smckusick 
33738418Smckusick 	fhp = &nfh.fh_generic;
33838418Smckusick 	nfsm_srvmtofh(fhp);
33938418Smckusick 	nfsm_disect(p, u_long *, NFSX_UNSIGNED);
34038418Smckusick 	off = fxdr_unsigned(off_t, *p);
34138418Smckusick 	nfsm_srvstrsiz(cnt, NFS_MAXDATA);
34238418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
34338418Smckusick 		nfsm_reply(0);
34438450Smckusick 	if (error = nfsrv_access(vp, VREAD | VEXEC, cred)) {
34538418Smckusick 		vput(vp);
34638418Smckusick 		nfsm_reply(0);
34738418Smckusick 	}
34838418Smckusick 	len = left = cnt;
34941899Smckusick 	/*
35041899Smckusick 	 * Generate the mbuf list with the uio_iov ref. to it.
35141899Smckusick 	 */
35241899Smckusick 	i = 0;
35341899Smckusick 	m3 = (struct mbuf *)0;
35442242Smckusick #ifdef lint
35542242Smckusick 	m2 = (struct mbuf *)0;
35642242Smckusick #endif /* lint */
35741899Smckusick 	while (left > 0) {
35841899Smckusick 		MGET(m, M_WAIT, MT_DATA);
35941899Smckusick 		if (left > MINCLSIZE)
36041899Smckusick 			MCLGET(m, M_WAIT);
36141899Smckusick 		m->m_len = 0;
36241899Smckusick 		siz = min(M_TRAILINGSPACE(m), left);
36341899Smckusick 		m->m_len = siz;
36441899Smckusick 		iv[i].iov_base = mtod(m, caddr_t);
36541899Smckusick 		iv[i].iov_len = siz;
36641899Smckusick 		i++;
36741899Smckusick 		left -= siz;
36841899Smckusick 		if (m3) {
36941899Smckusick 			m2->m_next = m;
37041899Smckusick 			m2 = m;
37141899Smckusick 		} else
37241899Smckusick 			m3 = m2 = m;
37341899Smckusick 	}
37441899Smckusick 	uiop->uio_iov = iv;
37541899Smckusick 	uiop->uio_iovcnt = i;
37638418Smckusick 	uiop->uio_offset = off;
37738418Smckusick 	uiop->uio_resid = cnt;
37838418Smckusick 	uiop->uio_rw = UIO_READ;
37938418Smckusick 	uiop->uio_segflg = UIO_SYSSPACE;
38039586Smckusick 	error = VOP_READ(vp, uiop, IO_NODELOCKED, cred);
38139586Smckusick 	off = uiop->uio_offset;
38238418Smckusick 	if (error) {
38341899Smckusick 		m_freem(m3);
38438418Smckusick 		vput(vp);
38538418Smckusick 		nfsm_reply(0);
38638418Smckusick 	}
38738418Smckusick 	if (error = VOP_GETATTR(vp, vap, cred))
38841899Smckusick 		m_freem(m3);
38938418Smckusick 	vput(vp);
39038418Smckusick 	nfsm_reply(NFSX_FATTR+NFSX_UNSIGNED);
39138884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
39239753Smckusick 	nfsm_srvfillattr;
39338418Smckusick 	if (uiop->uio_resid > 0) {
39438418Smckusick 		len -= uiop->uio_resid;
39538418Smckusick 		if (len > 0) {
39638418Smckusick 			tlen = nfsm_rndup(len);
39741899Smckusick 			nfsm_adj(m3, cnt-tlen, tlen-len);
39838418Smckusick 		} else {
39941899Smckusick 			m_freem(m3);
40041899Smckusick 			m3 = (struct mbuf *)0;
40138418Smckusick 		}
40238418Smckusick 	}
40338884Smacklem 	nfsm_build(p, u_long *, NFSX_UNSIGNED);
40438418Smckusick 	*p = txdr_unsigned(len);
40541899Smckusick 	mb->m_next = m3;
40638418Smckusick 	nfsm_srvdone;
40738418Smckusick }
40838418Smckusick 
40938418Smckusick /*
41038418Smckusick  * nfs write service
41138418Smckusick  */
41239753Smckusick nfsrv_write(mrep, md, dpos, cred, xid, mrq, repstat)
41338418Smckusick 	struct mbuf *mrep, *md, **mrq;
41438418Smckusick 	caddr_t dpos;
41538418Smckusick 	struct ucred *cred;
41639753Smckusick 	u_long xid;
41739753Smckusick 	int *repstat;
41838418Smckusick {
41938418Smckusick 	register struct iovec *ivp;
42038418Smckusick 	register struct mbuf *mp;
42138884Smacklem 	register struct nfsv2_fattr *fp;
42241899Smckusick 	struct iovec iv[NFS_MAXIOVEC];
42338418Smckusick 	struct vattr va;
42438418Smckusick 	register struct vattr *vap = &va;
42539494Smckusick 	register u_long *p;
42639494Smckusick 	register long t1;
42739494Smckusick 	caddr_t bpos;
42839494Smckusick 	int error = 0;
42939494Smckusick 	char *cp2;
43039753Smckusick 	struct mbuf *mb, *mb2, *mreq;
43138418Smckusick 	struct vnode *vp;
43238418Smckusick 	nfsv2fh_t nfh;
43338418Smckusick 	fhandle_t *fhp;
43438418Smckusick 	struct uio io, *uiop = &io;
43538418Smckusick 	off_t off;
43638418Smckusick 	long siz, len, xfer;
43738418Smckusick 
43838418Smckusick 	fhp = &nfh.fh_generic;
43938418Smckusick 	nfsm_srvmtofh(fhp);
44038418Smckusick 	nfsm_disect(p, u_long *, 4*NFSX_UNSIGNED);
44138418Smckusick 	off = fxdr_unsigned(off_t, *++p);
44238418Smckusick 	p += 2;
44338418Smckusick 	len = fxdr_unsigned(long, *p);
44438418Smckusick 	if (len > NFS_MAXDATA || len <= 0) {
44538418Smckusick 		error = EBADRPC;
44638418Smckusick 		nfsm_reply(0);
44738418Smckusick 	}
44838418Smckusick 	if (dpos == (mtod(md, caddr_t)+md->m_len)) {
44938418Smckusick 		mp = md->m_next;
45038418Smckusick 		if (mp == NULL) {
45138418Smckusick 			error = EBADRPC;
45238418Smckusick 			nfsm_reply(0);
45338418Smckusick 		}
45438418Smckusick 	} else {
45538418Smckusick 		mp = md;
45638418Smckusick 		siz = dpos-mtod(mp, caddr_t);
45738418Smckusick 		mp->m_len -= siz;
45838418Smckusick 		NFSMADV(mp, siz);
45938418Smckusick 	}
46038418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
46138418Smckusick 		nfsm_reply(0);
46238450Smckusick 	if (error = nfsrv_access(vp, VWRITE, cred)) {
46338418Smckusick 		vput(vp);
46438418Smckusick 		nfsm_reply(0);
46538418Smckusick 	}
46638418Smckusick 	uiop->uio_resid = 0;
46738418Smckusick 	uiop->uio_rw = UIO_WRITE;
46838418Smckusick 	uiop->uio_segflg = UIO_SYSSPACE;
46938418Smckusick 	/*
47041899Smckusick 	 * Do up to NFS_MAXIOVEC mbufs of write each iteration of the
47138418Smckusick 	 * loop until done.
47238418Smckusick 	 */
47338418Smckusick 	while (len > 0 && uiop->uio_resid == 0) {
47438418Smckusick 		ivp = iv;
47538418Smckusick 		siz = 0;
47638418Smckusick 		uiop->uio_iov = ivp;
47738418Smckusick 		uiop->uio_iovcnt = 0;
47838418Smckusick 		uiop->uio_offset = off;
47941899Smckusick 		while (len > 0 && uiop->uio_iovcnt < NFS_MAXIOVEC && mp != NULL) {
48038418Smckusick 			ivp->iov_base = mtod(mp, caddr_t);
48138418Smckusick 			if (len < mp->m_len)
48238418Smckusick 				ivp->iov_len = xfer = len;
48338418Smckusick 			else
48438418Smckusick 				ivp->iov_len = xfer = mp->m_len;
48538418Smckusick #ifdef notdef
48638418Smckusick 			/* Not Yet .. */
48738418Smckusick 			if (M_HASCL(mp) && (((u_long)ivp->iov_base) & CLOFSET) == 0)
48838418Smckusick 				ivp->iov_op = NULL;	/* what should it be ?? */
48938418Smckusick 			else
49038418Smckusick 				ivp->iov_op = NULL;
49138418Smckusick #endif
49238418Smckusick 			uiop->uio_iovcnt++;
49338418Smckusick 			ivp++;
49438418Smckusick 			len -= xfer;
49538418Smckusick 			siz += xfer;
49638418Smckusick 			mp = mp->m_next;
49738418Smckusick 		}
49838418Smckusick 		if (len > 0 && mp == NULL) {
49938418Smckusick 			error = EBADRPC;
50038418Smckusick 			vput(vp);
50138418Smckusick 			nfsm_reply(0);
50238418Smckusick 		}
50338418Smckusick 		uiop->uio_resid = siz;
50439586Smckusick 		if (error = VOP_WRITE(vp, uiop, IO_SYNC | IO_NODELOCKED,
50538418Smckusick 			cred)) {
50638418Smckusick 			vput(vp);
50738418Smckusick 			nfsm_reply(0);
50838418Smckusick 		}
50939586Smckusick 		off = uiop->uio_offset;
51038418Smckusick 	}
51138418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
51238418Smckusick 	vput(vp);
51338418Smckusick 	nfsm_reply(NFSX_FATTR);
51438884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
51539753Smckusick 	nfsm_srvfillattr;
51638418Smckusick 	nfsm_srvdone;
51738418Smckusick }
51838418Smckusick 
51938418Smckusick /*
52038418Smckusick  * nfs create service
52138418Smckusick  * now does a truncate to 0 length via. setattr if it already exists
52238418Smckusick  */
52339753Smckusick nfsrv_create(mrep, md, dpos, cred, xid, mrq, repstat)
52438418Smckusick 	struct mbuf *mrep, *md, **mrq;
52538418Smckusick 	caddr_t dpos;
52638418Smckusick 	struct ucred *cred;
52739753Smckusick 	u_long xid;
52839753Smckusick 	int *repstat;
52938418Smckusick {
53038884Smacklem 	register struct nfsv2_fattr *fp;
53138418Smckusick 	struct vattr va;
53238418Smckusick 	register struct vattr *vap = &va;
53339343Smckusick 	struct nameidata nami;
53439343Smckusick 	register struct nameidata *ndp = &nami;
53539494Smckusick 	register caddr_t cp;
53639494Smckusick 	register u_long *p;
53739494Smckusick 	register long t1;
53839494Smckusick 	caddr_t bpos;
53942242Smckusick 	long rdev;
54039494Smckusick 	int error = 0;
54139494Smckusick 	char *cp2;
54239753Smckusick 	struct mbuf *mb, *mb2, *mreq;
54338418Smckusick 	struct vnode *vp;
54438418Smckusick 	nfsv2fh_t nfh;
54538418Smckusick 	fhandle_t *fhp;
54638418Smckusick 	long len;
54738418Smckusick 
54839343Smckusick 	ndinit(ndp);
54938418Smckusick 	fhp = &nfh.fh_generic;
55038418Smckusick 	nfsm_srvmtofh(fhp);
55138418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
55238418Smckusick 	ndp->ni_cred = cred;
55338418Smckusick 	ndp->ni_nameiop = CREATE | LOCKPARENT | LOCKLEAF;
55438418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
55538418Smckusick 		nfsm_reply(0);
55641361Smckusick 	VATTR_NULL(vap);
55742242Smckusick 	nfsm_disect(p, u_long *, NFSX_SATTR);
55838418Smckusick 	/*
55938418Smckusick 	 * Iff doesn't exist, create it
56038418Smckusick 	 * otherwise just truncate to 0 length
56138418Smckusick 	 *   should I set the mode too ??
56238418Smckusick 	 */
56338418Smckusick 	if (ndp->ni_vp == NULL) {
56442242Smckusick 		vap->va_type = IFTOVT(fxdr_unsigned(u_long, *p));
56542242Smckusick 		vap->va_mode = nfstov_mode(*p);
56642242Smckusick 		rdev = fxdr_unsigned(long, *(p+3));
56742242Smckusick 		if (vap->va_type == VREG) {
56842242Smckusick 			if (error = VOP_CREATE(ndp, vap))
56942242Smckusick 				nfsm_reply(0);
57042242Smckusick 		} else if (vap->va_type == VCHR || vap->va_type == VBLK ||
57142242Smckusick 			vap->va_type == VFIFO) {
57242242Smckusick 			if (vap->va_type == VCHR && rdev == 0xffffffff)
57342242Smckusick 				vap->va_type = VFIFO;
57442242Smckusick 			if (vap->va_type == VFIFO) {
57542242Smckusick #ifndef FIFO
57642242Smckusick 				VOP_ABORTOP(ndp);
577*42467Smckusick 				vput(ndp->ni_dvp);
57842242Smckusick 				error = ENXIO;
57942242Smckusick 				nfsm_reply(0);
58042242Smckusick #endif /* FIFO */
58142242Smckusick 			} else if (error = suser(cred, (short *)0)) {
58242242Smckusick 				VOP_ABORTOP(ndp);
583*42467Smckusick 				vput(ndp->ni_dvp);
58442242Smckusick 				nfsm_reply(0);
58542242Smckusick 			} else
58642242Smckusick 				vap->va_rdev = (dev_t)rdev;
58742242Smckusick 			if (error = VOP_MKNOD(ndp, vap, cred))
58842242Smckusick 				nfsm_reply(0);
58942242Smckusick 			ndp->ni_nameiop = LOOKUP | LOCKLEAF | HASBUF;
59042242Smckusick 			if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
59142242Smckusick 				nfsm_reply(0);
59242242Smckusick 		} else {
59342242Smckusick 			VOP_ABORTOP(ndp);
594*42467Smckusick 			vput(ndp->ni_dvp);
59542242Smckusick 			error = ENXIO;
59638418Smckusick 			nfsm_reply(0);
59742242Smckusick 		}
59838425Smckusick 		vp = ndp->ni_vp;
59938418Smckusick 	} else {
60038425Smckusick 		vp = ndp->ni_vp;
60141398Smckusick 		ndp->ni_vp = NULLVP;
60238425Smckusick 		VOP_ABORTOP(ndp);
603*42467Smckusick 		vput(ndp->ni_dvp);
60438418Smckusick 		vap->va_size = 0;
60538425Smckusick 		if (error = VOP_SETATTR(vp, vap, cred))
60638418Smckusick 			nfsm_reply(0);
60738418Smckusick 	}
60838418Smckusick 	bzero((caddr_t)fhp, sizeof(nfh));
60941398Smckusick 	fhp->fh_fsid = vp->v_mount->mnt_stat.f_fsid;
61038418Smckusick 	if (error = VFS_VPTOFH(vp, &fhp->fh_fid)) {
61138418Smckusick 		vput(vp);
61238418Smckusick 		nfsm_reply(0);
61338418Smckusick 	}
61438418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
61538418Smckusick 	vput(vp);
61638418Smckusick 	nfsm_reply(NFSX_FH+NFSX_FATTR);
61738418Smckusick 	nfsm_srvfhtom(fhp);
61838884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
61939753Smckusick 	nfsm_srvfillattr;
62038418Smckusick 	return (error);
62138418Smckusick nfsmout:
62238418Smckusick 	VOP_ABORTOP(ndp);
623*42467Smckusick 	vput(ndp->ni_dvp);
624*42467Smckusick 	if (ndp->ni_vp)
625*42467Smckusick 		vput(ndp->ni_vp);
62638418Smckusick 	return (error);
62738418Smckusick }
62838418Smckusick 
62938418Smckusick /*
63038418Smckusick  * nfs remove service
63138418Smckusick  */
63239753Smckusick nfsrv_remove(mrep, md, dpos, cred, xid, mrq, repstat)
63338418Smckusick 	struct mbuf *mrep, *md, **mrq;
63438418Smckusick 	caddr_t dpos;
63538418Smckusick 	struct ucred *cred;
63639753Smckusick 	u_long xid;
63739753Smckusick 	int *repstat;
63838418Smckusick {
63939343Smckusick 	struct nameidata nami;
64039343Smckusick 	register struct nameidata *ndp = &nami;
64139494Smckusick 	register u_long *p;
64239494Smckusick 	register long t1;
64339494Smckusick 	caddr_t bpos;
64439494Smckusick 	int error = 0;
64539494Smckusick 	char *cp2;
64639753Smckusick 	struct mbuf *mb, *mreq;
64738418Smckusick 	struct vnode *vp;
64838418Smckusick 	nfsv2fh_t nfh;
64938418Smckusick 	fhandle_t *fhp;
65038418Smckusick 	long len;
65138418Smckusick 
65239343Smckusick 	ndinit(ndp);
65338418Smckusick 	fhp = &nfh.fh_generic;
65438418Smckusick 	nfsm_srvmtofh(fhp);
65538418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
65638418Smckusick 	ndp->ni_cred = cred;
65738418Smckusick 	ndp->ni_nameiop = DELETE | LOCKPARENT | LOCKLEAF;
65838418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
65938418Smckusick 		nfsm_reply(0);
66038418Smckusick 	vp = ndp->ni_vp;
66138418Smckusick 	if (vp->v_type == VDIR &&
66238418Smckusick 		(error = suser(cred, (short *)0)))
66338418Smckusick 		goto out;
66438418Smckusick 	/*
66538418Smckusick 	 * Don't unlink a mounted file.
66638418Smckusick 	 */
66738418Smckusick 	if (vp->v_flag & VROOT) {
66838418Smckusick 		error = EBUSY;
66938418Smckusick 		goto out;
67038418Smckusick 	}
67138418Smckusick 	if (vp->v_flag & VTEXT)
67238418Smckusick 		xrele(vp);	/* try once to free text */
67338418Smckusick out:
674*42467Smckusick 	if (!error) {
675*42467Smckusick 		error = VOP_REMOVE(ndp);
676*42467Smckusick 	} else {
67738418Smckusick 		VOP_ABORTOP(ndp);
678*42467Smckusick 		vput(ndp->ni_dvp);
679*42467Smckusick 		vput(vp);
680*42467Smckusick 	}
68138418Smckusick 	nfsm_reply(0);
68238418Smckusick 	nfsm_srvdone;
68338418Smckusick }
68438418Smckusick 
68538418Smckusick /*
68638418Smckusick  * nfs rename service
68738418Smckusick  */
68839753Smckusick nfsrv_rename(mrep, md, dpos, cred, xid, mrq, repstat)
68938418Smckusick 	struct mbuf *mrep, *md, **mrq;
69038418Smckusick 	caddr_t dpos;
69138418Smckusick 	struct ucred *cred;
69239753Smckusick 	u_long xid;
69339753Smckusick 	int *repstat;
69438418Smckusick {
69538425Smckusick 	register struct nameidata *ndp;
69639494Smckusick 	register u_long *p;
69739494Smckusick 	register long t1;
69839494Smckusick 	caddr_t bpos;
69939494Smckusick 	int error = 0;
70039494Smckusick 	char *cp2;
70139753Smckusick 	struct mbuf *mb, *mreq;
70239343Smckusick 	struct nameidata nami, tond;
70338418Smckusick 	struct vnode *fvp, *tvp, *tdvp;
70438418Smckusick 	nfsv2fh_t fnfh, tnfh;
70538418Smckusick 	fhandle_t *ffhp, *tfhp;
70638418Smckusick 	long len, len2;
70738418Smckusick 	int rootflg = 0;
70838418Smckusick 
70939343Smckusick 	ndp = &nami;
71039343Smckusick 	ndinit(ndp);
71138418Smckusick 	ffhp = &fnfh.fh_generic;
71238418Smckusick 	tfhp = &tnfh.fh_generic;
71338418Smckusick 	nfsm_srvmtofh(ffhp);
71438418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
71538418Smckusick 	/*
71638418Smckusick 	 * Remember if we are root so that we can reset cr_uid before
71738418Smckusick 	 * the second nfs_namei() call
71838418Smckusick 	 */
71938418Smckusick 	if (cred->cr_uid == 0)
72038418Smckusick 		rootflg++;
72138425Smckusick 	ndp->ni_cred = cred;
72238425Smckusick 	ndp->ni_nameiop = DELETE | WANTPARENT;
72338425Smckusick 	if (error = nfs_namei(ndp, ffhp, len, &md, &dpos))
72438418Smckusick 		nfsm_reply(0);
72538425Smckusick 	fvp = ndp->ni_vp;
72638418Smckusick 	nfsm_srvmtofh(tfhp);
72741899Smckusick 	nfsm_strsiz(len2, NFS_MAXNAMLEN);
72838418Smckusick 	if (rootflg)
72938418Smckusick 		cred->cr_uid = 0;
73039343Smckusick 	ndinit(&tond);
73139343Smckusick 	crhold(cred);
73239343Smckusick 	tond.ni_cred = cred;
73338425Smckusick 	tond.ni_nameiop = RENAME | LOCKPARENT | LOCKLEAF | NOCACHE;
734*42467Smckusick 	if (error = nfs_namei(&tond, tfhp, len2, &md, &dpos)) {
735*42467Smckusick 		VOP_ABORTOP(ndp);
736*42467Smckusick 		vrele(ndp->ni_dvp);
737*42467Smckusick 		vrele(fvp);
738*42467Smckusick 		goto out1;
739*42467Smckusick 	}
74038425Smckusick 	tdvp = tond.ni_dvp;
74138425Smckusick 	tvp = tond.ni_vp;
74238418Smckusick 	if (tvp != NULL) {
74338418Smckusick 		if (fvp->v_type == VDIR && tvp->v_type != VDIR) {
74438418Smckusick 			error = EISDIR;
74538418Smckusick 			goto out;
74638418Smckusick 		} else if (fvp->v_type != VDIR && tvp->v_type == VDIR) {
74738418Smckusick 			error = ENOTDIR;
74838418Smckusick 			goto out;
74938418Smckusick 		}
75038418Smckusick 	}
75138418Smckusick 	if (fvp->v_mount != tdvp->v_mount) {
75238418Smckusick 		error = EXDEV;
75338418Smckusick 		goto out;
75438418Smckusick 	}
75538418Smckusick 	if (fvp == tdvp || fvp == tvp)
75638418Smckusick 		error = EINVAL;
75738418Smckusick out:
758*42467Smckusick 	if (!error) {
75939343Smckusick 		VREF(ndp->ni_cdir);
76038451Smckusick 		VREF(tond.ni_cdir);
76138425Smckusick 		error = VOP_RENAME(ndp, &tond);
76239343Smckusick 		vrele(ndp->ni_cdir);
76338451Smckusick 		vrele(tond.ni_cdir);
764*42467Smckusick 	} else {
765*42467Smckusick 		VOP_ABORTOP(&tond);
766*42467Smckusick 		vput(tdvp);
767*42467Smckusick 		if (tvp)
768*42467Smckusick 			vput(tvp);
769*42467Smckusick 		VOP_ABORTOP(ndp);
770*42467Smckusick 		vrele(ndp->ni_dvp);
771*42467Smckusick 		vrele(fvp);
77238418Smckusick 	}
77338418Smckusick out1:
77439343Smckusick 	crfree(cred);
77538418Smckusick 	nfsm_reply(0);
77638418Smckusick 	return (error);
77738418Smckusick nfsmout:
77838425Smckusick 	VOP_ABORTOP(ndp);
779*42467Smckusick 	vrele(ndp->ni_dvp);
780*42467Smckusick 	vrele(fvp);
78138418Smckusick 	return (error);
78238418Smckusick }
78338418Smckusick 
78438418Smckusick /*
78538418Smckusick  * nfs link service
78638418Smckusick  */
78739753Smckusick nfsrv_link(mrep, md, dpos, cred, xid, mrq, repstat)
78838418Smckusick 	struct mbuf *mrep, *md, **mrq;
78938418Smckusick 	caddr_t dpos;
79038418Smckusick 	struct ucred *cred;
79139753Smckusick 	u_long xid;
79239753Smckusick 	int *repstat;
79338418Smckusick {
79439343Smckusick 	struct nameidata nami;
79539343Smckusick 	register struct nameidata *ndp = &nami;
79639494Smckusick 	register u_long *p;
79739494Smckusick 	register long t1;
79839494Smckusick 	caddr_t bpos;
79939494Smckusick 	int error = 0;
80039494Smckusick 	char *cp2;
80139753Smckusick 	struct mbuf *mb, *mreq;
80238418Smckusick 	struct vnode *vp, *xp;
80338418Smckusick 	nfsv2fh_t nfh, dnfh;
80438418Smckusick 	fhandle_t *fhp, *dfhp;
80538418Smckusick 	long len;
80638418Smckusick 
80739343Smckusick 	ndinit(ndp);
80838418Smckusick 	fhp = &nfh.fh_generic;
80938418Smckusick 	dfhp = &dnfh.fh_generic;
81038418Smckusick 	nfsm_srvmtofh(fhp);
81138418Smckusick 	nfsm_srvmtofh(dfhp);
81238418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
81338418Smckusick 	if (error = nfsrv_fhtovp(fhp, FALSE, &vp, cred))
81438418Smckusick 		nfsm_reply(0);
81538418Smckusick 	if (vp->v_type == VDIR && (error = suser(cred, NULL)))
81638418Smckusick 		goto out1;
81738418Smckusick 	ndp->ni_cred = cred;
81838418Smckusick 	ndp->ni_nameiop = CREATE | LOCKPARENT;
81938418Smckusick 	if (error = nfs_namei(ndp, dfhp, len, &md, &dpos))
82038418Smckusick 		goto out1;
82138418Smckusick 	xp = ndp->ni_vp;
82238418Smckusick 	if (xp != NULL) {
82338418Smckusick 		error = EEXIST;
82438418Smckusick 		goto out;
82538418Smckusick 	}
82638418Smckusick 	xp = ndp->ni_dvp;
82738418Smckusick 	if (vp->v_mount != xp->v_mount)
82838418Smckusick 		error = EXDEV;
82938418Smckusick out:
830*42467Smckusick 	if (!error) {
831*42467Smckusick 		error = VOP_LINK(vp, ndp);
832*42467Smckusick 	} else {
83338418Smckusick 		VOP_ABORTOP(ndp);
834*42467Smckusick 		vput(ndp->ni_dvp);
835*42467Smckusick 		if (ndp->ni_vp)
836*42467Smckusick 			vrele(ndp->ni_vp);
837*42467Smckusick 	}
83838418Smckusick out1:
83938418Smckusick 	vrele(vp);
84038418Smckusick 	nfsm_reply(0);
84138418Smckusick 	nfsm_srvdone;
84238418Smckusick }
84338418Smckusick 
84438418Smckusick /*
84538418Smckusick  * nfs symbolic link service
84638418Smckusick  */
84739753Smckusick nfsrv_symlink(mrep, md, dpos, cred, xid, mrq, repstat)
84838418Smckusick 	struct mbuf *mrep, *md, **mrq;
84938418Smckusick 	caddr_t dpos;
85038418Smckusick 	struct ucred *cred;
85139753Smckusick 	u_long xid;
85239753Smckusick 	int *repstat;
85338418Smckusick {
85438418Smckusick 	struct vattr va;
85539343Smckusick 	struct nameidata nami;
85639343Smckusick 	register struct nameidata *ndp = &nami;
85738418Smckusick 	register struct vattr *vap = &va;
85839494Smckusick 	register u_long *p;
85939494Smckusick 	register long t1;
86039494Smckusick 	caddr_t bpos;
86141899Smckusick 	struct uio io;
86241899Smckusick 	struct iovec iv;
86339494Smckusick 	int error = 0;
86441899Smckusick 	char *pathcp, *cp2;
86539753Smckusick 	struct mbuf *mb, *mreq;
86638418Smckusick 	nfsv2fh_t nfh;
86738418Smckusick 	fhandle_t *fhp;
86842242Smckusick 	long len, len2;
86938418Smckusick 
87041899Smckusick 	pathcp = (char *)0;
87139343Smckusick 	ndinit(ndp);
87238418Smckusick 	fhp = &nfh.fh_generic;
87338418Smckusick 	nfsm_srvmtofh(fhp);
87438418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
87538418Smckusick 	ndp->ni_cred = cred;
87638418Smckusick 	ndp->ni_nameiop = CREATE | LOCKPARENT;
87738418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
878*42467Smckusick 		goto out;
87941899Smckusick 	nfsm_strsiz(len2, NFS_MAXPATHLEN);
88041899Smckusick 	MALLOC(pathcp, caddr_t, len2 + 1, M_TEMP, M_WAITOK);
88141899Smckusick 	iv.iov_base = pathcp;
88241899Smckusick 	iv.iov_len = len2;
88341899Smckusick 	io.uio_resid = len2;
88441899Smckusick 	io.uio_offset = 0;
88541899Smckusick 	io.uio_iov = &iv;
88641899Smckusick 	io.uio_iovcnt = 1;
88741899Smckusick 	io.uio_segflg = UIO_SYSSPACE;
88841899Smckusick 	io.uio_rw = UIO_READ;
88941899Smckusick 	nfsm_mtouio(&io, len2);
89041899Smckusick 	*(pathcp + len2) = '\0';
891*42467Smckusick 	if (ndp->ni_vp) {
892*42467Smckusick 		VOP_ABORTOP(ndp);
893*42467Smckusick 		vput(ndp->ni_dvp);
894*42467Smckusick 		vrele(ndp->ni_vp);
89538418Smckusick 		error = EEXIST;
89638418Smckusick 		goto out;
89738418Smckusick 	}
89841361Smckusick 	VATTR_NULL(vap);
89938418Smckusick 	vap->va_mode = 0777;
900*42467Smckusick 	error = VOP_SYMLINK(ndp, vap, pathcp);
90138418Smckusick out:
90241899Smckusick 	if (pathcp)
90341899Smckusick 		FREE(pathcp, M_TEMP);
90438418Smckusick 	nfsm_reply(0);
90538418Smckusick 	return (error);
90638418Smckusick nfsmout:
90738418Smckusick 	VOP_ABORTOP(ndp);
908*42467Smckusick 	vput(ndp->ni_dvp);
909*42467Smckusick 	if (ndp->ni_vp);
910*42467Smckusick 		vrele(ndp->ni_vp);
91141899Smckusick 	if (pathcp)
91241899Smckusick 		FREE(pathcp, M_TEMP);
91338418Smckusick 	return (error);
91438418Smckusick }
91538418Smckusick 
91638418Smckusick /*
91738418Smckusick  * nfs mkdir service
91838418Smckusick  */
91939753Smckusick nfsrv_mkdir(mrep, md, dpos, cred, xid, mrq, repstat)
92038418Smckusick 	struct mbuf *mrep, *md, **mrq;
92138418Smckusick 	caddr_t dpos;
92238418Smckusick 	struct ucred *cred;
92339753Smckusick 	u_long xid;
92439753Smckusick 	int *repstat;
92538418Smckusick {
92638418Smckusick 	struct vattr va;
92738418Smckusick 	register struct vattr *vap = &va;
92838884Smacklem 	register struct nfsv2_fattr *fp;
92939343Smckusick 	struct nameidata nami;
93039343Smckusick 	register struct nameidata *ndp = &nami;
93139494Smckusick 	register caddr_t cp;
93239494Smckusick 	register u_long *p;
93339494Smckusick 	register long t1;
93439494Smckusick 	caddr_t bpos;
93539494Smckusick 	int error = 0;
93639494Smckusick 	char *cp2;
93739753Smckusick 	struct mbuf *mb, *mb2, *mreq;
93838418Smckusick 	struct vnode *vp;
93938418Smckusick 	nfsv2fh_t nfh;
94038418Smckusick 	fhandle_t *fhp;
94138418Smckusick 	long len;
94238418Smckusick 
94339343Smckusick 	ndinit(ndp);
94438418Smckusick 	fhp = &nfh.fh_generic;
94538418Smckusick 	nfsm_srvmtofh(fhp);
94638418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
94738418Smckusick 	ndp->ni_cred = cred;
94838418Smckusick 	ndp->ni_nameiop = CREATE | LOCKPARENT;
94938418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
95038418Smckusick 		nfsm_reply(0);
95138418Smckusick 	nfsm_disect(p, u_long *, NFSX_UNSIGNED);
95241361Smckusick 	VATTR_NULL(vap);
95338418Smckusick 	vap->va_type = VDIR;
95438418Smckusick 	vap->va_mode = nfstov_mode(*p++);
95538418Smckusick 	vp = ndp->ni_vp;
95638418Smckusick 	if (vp != NULL) {
95738418Smckusick 		VOP_ABORTOP(ndp);
958*42467Smckusick 		vput(ndp->ni_dvp);
959*42467Smckusick 		vrele(vp);
96038418Smckusick 		error = EEXIST;
96138418Smckusick 		nfsm_reply(0);
96238418Smckusick 	}
96338418Smckusick 	if (error = VOP_MKDIR(ndp, vap))
96438418Smckusick 		nfsm_reply(0);
96538418Smckusick 	vp = ndp->ni_vp;
96638418Smckusick 	bzero((caddr_t)fhp, sizeof(nfh));
96741398Smckusick 	fhp->fh_fsid = vp->v_mount->mnt_stat.f_fsid;
96838418Smckusick 	if (error = VFS_VPTOFH(vp, &fhp->fh_fid)) {
96938418Smckusick 		vput(vp);
97038418Smckusick 		nfsm_reply(0);
97138418Smckusick 	}
97238418Smckusick 	error = VOP_GETATTR(vp, vap, cred);
97338418Smckusick 	vput(vp);
97438418Smckusick 	nfsm_reply(NFSX_FH+NFSX_FATTR);
97538418Smckusick 	nfsm_srvfhtom(fhp);
97638884Smacklem 	nfsm_build(fp, struct nfsv2_fattr *, NFSX_FATTR);
97739753Smckusick 	nfsm_srvfillattr;
97838418Smckusick 	return (error);
97938418Smckusick nfsmout:
98038418Smckusick 	VOP_ABORTOP(ndp);
981*42467Smckusick 	vput(ndp->ni_dvp);
982*42467Smckusick 	if (ndp->ni_vp)
983*42467Smckusick 		vrele(ndp->ni_vp);
98438418Smckusick 	return (error);
98538418Smckusick }
98638418Smckusick 
98738418Smckusick /*
98838418Smckusick  * nfs rmdir service
98938418Smckusick  */
99039753Smckusick nfsrv_rmdir(mrep, md, dpos, cred, xid, mrq, repstat)
99138418Smckusick 	struct mbuf *mrep, *md, **mrq;
99238418Smckusick 	caddr_t dpos;
99338418Smckusick 	struct ucred *cred;
99439753Smckusick 	u_long xid;
99539753Smckusick 	int *repstat;
99638418Smckusick {
99739343Smckusick 	struct nameidata nami;
99839343Smckusick 	register struct nameidata *ndp = &nami;
99939494Smckusick 	register u_long *p;
100039494Smckusick 	register long t1;
100139494Smckusick 	caddr_t bpos;
100239494Smckusick 	int error = 0;
100339494Smckusick 	char *cp2;
100439753Smckusick 	struct mbuf *mb, *mreq;
100538418Smckusick 	struct vnode *vp;
100638418Smckusick 	nfsv2fh_t nfh;
100738418Smckusick 	fhandle_t *fhp;
100838418Smckusick 	long len;
100938418Smckusick 
101039343Smckusick 	ndinit(ndp);
101138418Smckusick 	fhp = &nfh.fh_generic;
101238418Smckusick 	nfsm_srvmtofh(fhp);
101338418Smckusick 	nfsm_srvstrsiz(len, NFS_MAXNAMLEN);
101438418Smckusick 	ndp->ni_cred = cred;
101538418Smckusick 	ndp->ni_nameiop = DELETE | LOCKPARENT | LOCKLEAF;
101638418Smckusick 	if (error = nfs_namei(ndp, fhp, len, &md, &dpos))
101738418Smckusick 		nfsm_reply(0);
101838418Smckusick 	vp = ndp->ni_vp;
101938418Smckusick 	if (vp->v_type != VDIR) {
102038418Smckusick 		error = ENOTDIR;
102138418Smckusick 		goto out;
102238418Smckusick 	}
102338418Smckusick 	/*
102438418Smckusick 	 * No rmdir "." please.
102538418Smckusick 	 */
102638418Smckusick 	if (ndp->ni_dvp == vp) {
102738418Smckusick 		error = EINVAL;
102838418Smckusick 		goto out;
102938418Smckusick 	}
103038418Smckusick 	/*
103138418Smckusick 	 * Don't unlink a mounted file.
103238418Smckusick 	 */
103338418Smckusick 	if (vp->v_flag & VROOT)
103438418Smckusick 		error = EBUSY;
103538418Smckusick out:
1036*42467Smckusick 	if (!error) {
1037*42467Smckusick 		error = VOP_RMDIR(ndp);
1038*42467Smckusick 	} else {
103938418Smckusick 		VOP_ABORTOP(ndp);
1040*42467Smckusick 		vput(ndp->ni_dvp);
1041*42467Smckusick 		vput(vp);
1042*42467Smckusick 	}
104338418Smckusick 	nfsm_reply(0);
104438418Smckusick 	nfsm_srvdone;
104538418Smckusick }
104638418Smckusick 
104738418Smckusick /*
104838418Smckusick  * nfs readdir service
104938418Smckusick  * - mallocs what it thinks is enough to read
105041899Smckusick  *	count rounded up to a multiple of DIRBLKSIZ <= NFS_MAXREADDIR
105138418Smckusick  * - calls VOP_READDIR()
105240115Smckusick  * - loops around building the reply
105338425Smckusick  *	if the output generated exceeds count break out of loop
105438425Smckusick  *	The nfsm_clget macro is used here so that the reply will be packed
105538425Smckusick  *	tightly in mbuf clusters.
105638418Smckusick  * - it only knows that it has encountered eof when the VOP_READDIR()
105738425Smckusick  *	reads nothing
105838418Smckusick  * - as such one readdir rpc will return eof false although you are there
105938425Smckusick  *	and then the next will return eof
106038418Smckusick  * - it trims out records with d_ino == 0
106138425Smckusick  *	this doesn't matter for Unix clients, but they might confuse clients
106238425Smckusick  *	for other os'.
106338418Smckusick  * NB: It is tempting to set eof to true if the VOP_READDIR() reads less
106438425Smckusick  *	than requested, but this may not apply to all filesystems. For
106538425Smckusick  *	example, client NFS does not { although it is never remote mounted
106638425Smckusick  *	anyhow }
106738418Smckusick  * PS: The NFS protocol spec. does not clarify what the "count" byte
106838425Smckusick  *	argument is a count of.. just name strings and file id's or the
106938425Smckusick  *	entire reply rpc or ...
107038425Smckusick  *	I tried just file name and id sizes and it confused the Sun client,
107138425Smckusick  *	so I am using the full rpc size now. The "paranoia.." comment refers
107238425Smckusick  *	to including the status longwords that are not a part of the dir.
107338425Smckusick  *	"entry" structures, but are in the rpc.
107438418Smckusick  */
107539753Smckusick nfsrv_readdir(mrep, md, dpos, cred, xid, mrq, repstat)
107638418Smckusick 	struct mbuf **mrq;
107738418Smckusick 	struct mbuf *mrep, *md;
107838418Smckusick 	caddr_t dpos;
107938418Smckusick 	struct ucred *cred;
108038418Smckusick 	u_long xid;
108139753Smckusick 	int *repstat;
108238418Smckusick {
108338418Smckusick 	register char *bp, *be;
108438418Smckusick 	register struct mbuf *mp;
108538418Smckusick 	register struct direct *dp;
108639494Smckusick 	register caddr_t cp;
108739494Smckusick 	register u_long *p;
108839494Smckusick 	register long t1;
108939494Smckusick 	caddr_t bpos;
109039494Smckusick 	int error = 0;
109139494Smckusick 	char *cp2;
109239753Smckusick 	struct mbuf *mb, *mb2, *mreq;
109338418Smckusick 	char *cpos, *cend;
109438418Smckusick 	int len, nlen, rem, xfer, tsiz, i;
109538418Smckusick 	struct vnode *vp;
109638418Smckusick 	struct mbuf *mp2, *mp3;
109738418Smckusick 	nfsv2fh_t nfh;
109838418Smckusick 	fhandle_t *fhp;
109938418Smckusick 	struct uio io;
110038418Smckusick 	struct iovec iv;
110140296Smckusick 	int siz, cnt, fullsiz, eofflag;
110238418Smckusick 	u_long on;
110338418Smckusick 	char *rbuf;
110438418Smckusick 	off_t off, toff;
110538418Smckusick 
110638418Smckusick 	fhp = &nfh.fh_generic;
110738418Smckusick 	nfsm_srvmtofh(fhp);
110838418Smckusick 	nfsm_disect(p, u_long *, 2*NFSX_UNSIGNED);
110938418Smckusick 	toff = fxdr_unsigned(off_t, *p++);
111038418Smckusick 	off = (toff & ~(DIRBLKSIZ-1));
111138418Smckusick 	on = (toff & (DIRBLKSIZ-1));
111238418Smckusick 	cnt = fxdr_unsigned(int, *p);
111341899Smckusick 	siz = ((cnt+DIRBLKSIZ-1) & ~(DIRBLKSIZ-1));
111441899Smckusick 	if (cnt > NFS_MAXREADDIR)
111541899Smckusick 		siz = NFS_MAXREADDIR;
111638418Smckusick 	fullsiz = siz;
111738418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
111838418Smckusick 		nfsm_reply(0);
111938450Smckusick 	if (error = nfsrv_access(vp, VEXEC, cred)) {
112038418Smckusick 		vput(vp);
112138418Smckusick 		nfsm_reply(0);
112238418Smckusick 	}
112338418Smckusick 	VOP_UNLOCK(vp);
112438418Smckusick 	MALLOC(rbuf, caddr_t, siz, M_TEMP, M_WAITOK);
112538418Smckusick again:
112638418Smckusick 	iv.iov_base = rbuf;
112738418Smckusick 	iv.iov_len = fullsiz;
112838418Smckusick 	io.uio_iov = &iv;
112938418Smckusick 	io.uio_iovcnt = 1;
113038418Smckusick 	io.uio_offset = off;
113138418Smckusick 	io.uio_resid = fullsiz;
113238418Smckusick 	io.uio_segflg = UIO_SYSSPACE;
113338418Smckusick 	io.uio_rw = UIO_READ;
113440296Smckusick 	error = VOP_READDIR(vp, &io, cred, &eofflag);
113539586Smckusick 	off = io.uio_offset;
113638418Smckusick 	if (error) {
113738418Smckusick 		vrele(vp);
113838418Smckusick 		free((caddr_t)rbuf, M_TEMP);
113938418Smckusick 		nfsm_reply(0);
114038418Smckusick 	}
114138418Smckusick 	if (io.uio_resid) {
114238418Smckusick 		siz -= io.uio_resid;
114338418Smckusick 
114438418Smckusick 		/*
114538418Smckusick 		 * If nothing read, return eof
114638418Smckusick 		 * rpc reply
114738418Smckusick 		 */
114838418Smckusick 		if (siz == 0) {
114938418Smckusick 			vrele(vp);
115038418Smckusick 			nfsm_reply(2*NFSX_UNSIGNED);
115138418Smckusick 			nfsm_build(p, u_long *, 2*NFSX_UNSIGNED);
115238418Smckusick 			*p++ = nfs_false;
115338418Smckusick 			*p = nfs_true;
115438418Smckusick 			FREE((caddr_t)rbuf, M_TEMP);
115538418Smckusick 			return (0);
115638418Smckusick 		}
115738418Smckusick 	}
115840115Smckusick 
115938418Smckusick 	/*
116038418Smckusick 	 * Check for degenerate cases of nothing useful read.
116140115Smckusick 	 * If so go try again
116238418Smckusick 	 */
116340115Smckusick 	cpos = rbuf + on;
116440115Smckusick 	cend = rbuf + siz;
116540115Smckusick 	dp = (struct direct *)cpos;
116640115Smckusick 	while (cpos < cend && dp->d_ino == 0) {
116740115Smckusick 		cpos += dp->d_reclen;
116840115Smckusick 		dp = (struct direct *)cpos;
116940115Smckusick 	}
117040115Smckusick 	if (cpos >= cend) {
117138418Smckusick 		toff = off;
117238418Smckusick 		siz = fullsiz;
117338418Smckusick 		on = 0;
117438418Smckusick 		goto again;
117538418Smckusick 	}
117640115Smckusick 
117740115Smckusick 	cpos = rbuf + on;
117840115Smckusick 	cend = rbuf + siz;
117940115Smckusick 	dp = (struct direct *)cpos;
118038418Smckusick 	vrele(vp);
118138425Smckusick 	len = 3*NFSX_UNSIGNED;	/* paranoia, probably can be 0 */
118238418Smckusick 	bp = be = (caddr_t)0;
118338418Smckusick 	mp3 = (struct mbuf *)0;
118438418Smckusick 	nfsm_reply(siz);
118538418Smckusick 
118638418Smckusick 	/* Loop through the records and build reply */
118738418Smckusick 	while (cpos < cend) {
118838418Smckusick 		if (dp->d_ino != 0) {
118938418Smckusick 			nlen = dp->d_namlen;
119038418Smckusick 			rem = nfsm_rndup(nlen)-nlen;
119138425Smckusick 
119238418Smckusick 			/*
119338418Smckusick 			 * As noted above, the NFS spec. is not clear about what
119438418Smckusick 			 * should be included in "count" as totalled up here in
119538418Smckusick 			 * "len".
119638418Smckusick 			 */
119738418Smckusick 			len += (4*NFSX_UNSIGNED+nlen+rem);
119841899Smckusick 			if (len > cnt) {
119941899Smckusick 				eofflag = 0;
120038418Smckusick 				break;
120141899Smckusick 			}
120238425Smckusick 
120338418Smckusick 			/* Build the directory record xdr from the direct entry */
120438418Smckusick 			nfsm_clget;
120538418Smckusick 			*p = nfs_true;
120638418Smckusick 			bp += NFSX_UNSIGNED;
120738418Smckusick 			nfsm_clget;
120838418Smckusick 			*p = txdr_unsigned(dp->d_ino);
120938418Smckusick 			bp += NFSX_UNSIGNED;
121038418Smckusick 			nfsm_clget;
121138418Smckusick 			*p = txdr_unsigned(nlen);
121238418Smckusick 			bp += NFSX_UNSIGNED;
121338425Smckusick 
121438418Smckusick 			/* And loop arround copying the name */
121538418Smckusick 			xfer = nlen;
121638418Smckusick 			cp = dp->d_name;
121738418Smckusick 			while (xfer > 0) {
121838418Smckusick 				nfsm_clget;
121938418Smckusick 				if ((bp+xfer) > be)
122038418Smckusick 					tsiz = be-bp;
122138418Smckusick 				else
122238418Smckusick 					tsiz = xfer;
122338418Smckusick 				bcopy(cp, bp, tsiz);
122438418Smckusick 				bp += tsiz;
122538418Smckusick 				xfer -= tsiz;
122638418Smckusick 				if (xfer > 0)
122738418Smckusick 					cp += tsiz;
122838418Smckusick 			}
122938418Smckusick 			/* And null pad to a long boundary */
123038418Smckusick 			for (i = 0; i < rem; i++)
123138418Smckusick 				*bp++ = '\0';
123238418Smckusick 			nfsm_clget;
123338425Smckusick 
123438418Smckusick 			/* Finish off the record */
123538418Smckusick 			toff += dp->d_reclen;
123638418Smckusick 			*p = txdr_unsigned(toff);
123738418Smckusick 			bp += NFSX_UNSIGNED;
123838418Smckusick 		} else
123938418Smckusick 			toff += dp->d_reclen;
124038418Smckusick 		cpos += dp->d_reclen;
124138418Smckusick 		dp = (struct direct *)cpos;
124238418Smckusick 	}
124338418Smckusick 	nfsm_clget;
124438418Smckusick 	*p = nfs_false;
124538418Smckusick 	bp += NFSX_UNSIGNED;
124638418Smckusick 	nfsm_clget;
124740296Smckusick 	if (eofflag)
124840296Smckusick 		*p = nfs_true;
124940296Smckusick 	else
125040296Smckusick 		*p = nfs_false;
125138418Smckusick 	bp += NFSX_UNSIGNED;
125238418Smckusick 	if (bp < be)
125338418Smckusick 		mp->m_len = bp-mtod(mp, caddr_t);
125438418Smckusick 	mb->m_next = mp3;
125538418Smckusick 	FREE(rbuf, M_TEMP);
125638418Smckusick 	nfsm_srvdone;
125738418Smckusick }
125838418Smckusick 
125938418Smckusick /*
126038418Smckusick  * nfs statfs service
126138418Smckusick  */
126239753Smckusick nfsrv_statfs(mrep, md, dpos, cred, xid, mrq, repstat)
126338418Smckusick 	struct mbuf **mrq;
126438418Smckusick 	struct mbuf *mrep, *md;
126538418Smckusick 	caddr_t dpos;
126638418Smckusick 	struct ucred *cred;
126738418Smckusick 	u_long xid;
126839753Smckusick 	int *repstat;
126938418Smckusick {
127038418Smckusick 	register struct statfs *sf;
127138884Smacklem 	register struct nfsv2_statfs *sfp;
127239494Smckusick 	register u_long *p;
127339494Smckusick 	register long t1;
127439494Smckusick 	caddr_t bpos;
127539494Smckusick 	int error = 0;
127639494Smckusick 	char *cp2;
127739753Smckusick 	struct mbuf *mb, *mb2, *mreq;
127838418Smckusick 	struct vnode *vp;
127938418Smckusick 	nfsv2fh_t nfh;
128038418Smckusick 	fhandle_t *fhp;
128138418Smckusick 	struct statfs statfs;
128238418Smckusick 
128338418Smckusick 	fhp = &nfh.fh_generic;
128438418Smckusick 	nfsm_srvmtofh(fhp);
128538418Smckusick 	if (error = nfsrv_fhtovp(fhp, TRUE, &vp, cred))
128638418Smckusick 		nfsm_reply(0);
128738418Smckusick 	sf = &statfs;
128838418Smckusick 	error = VFS_STATFS(vp->v_mount, sf);
128938418Smckusick 	vput(vp);
129038418Smckusick 	nfsm_reply(NFSX_STATFS);
129138884Smacklem 	nfsm_build(sfp, struct nfsv2_statfs *, NFSX_STATFS);
129238884Smacklem 	sfp->sf_tsize = txdr_unsigned(NFS_MAXDATA);
129338884Smacklem 	sfp->sf_bsize = txdr_unsigned(sf->f_fsize);
129438884Smacklem 	sfp->sf_blocks = txdr_unsigned(sf->f_blocks);
129538884Smacklem 	sfp->sf_bfree = txdr_unsigned(sf->f_bfree);
129638884Smacklem 	sfp->sf_bavail = txdr_unsigned(sf->f_bavail);
129738418Smckusick 	nfsm_srvdone;
129838418Smckusick }
129938418Smckusick 
130038418Smckusick /*
130138418Smckusick  * Null operation, used by clients to ping server
130238418Smckusick  */
130339494Smckusick /* ARGSUSED */
130439753Smckusick nfsrv_null(mrep, md, dpos, cred, xid, mrq, repstat)
130538418Smckusick 	struct mbuf **mrq;
130638418Smckusick 	struct mbuf *mrep, *md;
130738418Smckusick 	caddr_t dpos;
130838418Smckusick 	struct ucred *cred;
130938418Smckusick 	u_long xid;
131039753Smckusick 	int *repstat;
131138418Smckusick {
131239494Smckusick 	caddr_t bpos;
131339494Smckusick 	int error = 0;
131439753Smckusick 	struct mbuf *mb, *mreq;
131538418Smckusick 
131638418Smckusick 	error = VNOVAL;
131738418Smckusick 	nfsm_reply(0);
131839494Smckusick 	return (error);
131938418Smckusick }
132038418Smckusick 
132138418Smckusick /*
132238418Smckusick  * No operation, used for obsolete procedures
132338418Smckusick  */
132439494Smckusick /* ARGSUSED */
132539753Smckusick nfsrv_noop(mrep, md, dpos, cred, xid, mrq, repstat)
132638418Smckusick 	struct mbuf **mrq;
132738418Smckusick 	struct mbuf *mrep, *md;
132838418Smckusick 	caddr_t dpos;
132938418Smckusick 	struct ucred *cred;
133038418Smckusick 	u_long xid;
133139753Smckusick 	int *repstat;
133238418Smckusick {
133339494Smckusick 	caddr_t bpos;
133439494Smckusick 	int error = 0;
133539753Smckusick 	struct mbuf *mb, *mreq;
133638418Smckusick 
133738418Smckusick 	error = EPROCUNAVAIL;
133838418Smckusick 	nfsm_reply(0);
133939494Smckusick 	return (error);
134038418Smckusick }
134138425Smckusick 
134238450Smckusick /*
134338450Smckusick  * Perform access checking for vnodes obtained from file handles that would
134438450Smckusick  * refer to files already opened by a Unix client. You cannot just use
134538450Smckusick  * vn_writechk() and VOP_ACCESS() for two reasons.
134641398Smckusick  * 1 - You must check for MNT_EXRDONLY as well as MNT_RDONLY for the write case
134738450Smckusick  * 2 - The owner is to be given access irrespective of mode bits so that
134838450Smckusick  *     processes that chmod after opening a file don't break. I don't like
134938450Smckusick  *     this because it opens a security hole, but since the nfs server opens
135038450Smckusick  *     a security hole the size of a barn door anyhow, what the heck.
135138450Smckusick  */
135238450Smckusick nfsrv_access(vp, flags, cred)
135338450Smckusick 	register struct vnode *vp;
135438450Smckusick 	int flags;
135538450Smckusick 	register struct ucred *cred;
135638450Smckusick {
135738450Smckusick 	struct vattr vattr;
135838450Smckusick 	int error;
135938450Smckusick 	if (flags & VWRITE) {
136041398Smckusick 		/* Just vn_writechk() changed to check MNT_EXRDONLY */
136138450Smckusick 		/*
136238450Smckusick 		 * Disallow write attempts on read-only file systems;
136338450Smckusick 		 * unless the file is a socket or a block or character
136438450Smckusick 		 * device resident on the file system.
136538450Smckusick 		 */
136641398Smckusick 		if ((vp->v_mount->mnt_flag & (MNT_RDONLY | MNT_EXRDONLY)) &&
136738450Smckusick 			vp->v_type != VCHR &&
136838450Smckusick 			vp->v_type != VBLK &&
136938450Smckusick 			vp->v_type != VSOCK)
137038450Smckusick 				return (EROFS);
137138450Smckusick 		/*
137238450Smckusick 		 * If there's shared text associated with
137338450Smckusick 		 * the inode, try to free it up once.  If
137438450Smckusick 		 * we fail, we can't allow writing.
137538450Smckusick 		 */
137638450Smckusick 		if (vp->v_flag & VTEXT)
137738450Smckusick 			xrele(vp);
137838450Smckusick 		if (vp->v_flag & VTEXT)
137938450Smckusick 			return (ETXTBSY);
138038450Smckusick 		if (error = VOP_GETATTR(vp, &vattr, cred))
138138450Smckusick 			return (error);
138238450Smckusick 		if (cred->cr_uid == vattr.va_uid)
138338450Smckusick 			return (0);
138438450Smckusick 	} else {
138538450Smckusick 		if (error = VOP_GETATTR(vp, &vattr, cred))
138638450Smckusick 			return (error);
138738450Smckusick 		if (cred->cr_uid == vattr.va_uid)
138838450Smckusick 			return (0);
138938450Smckusick 	}
139038450Smckusick 	return (VOP_ACCESS(vp, flags, cred));
139138450Smckusick }
1392