xref: /netbsd-src/sys/ufs/ext2fs/ext2fs_vnops.c (revision c2f76ff004a2cb67efe5b12d97bd3ef7fe89e18d)
1 /*	$NetBSD: ext2fs_vnops.c,v 1.97 2011/01/02 05:09:32 dholland Exp $	*/
2 
3 /*
4  * Copyright (c) 1982, 1986, 1989, 1993
5  *	The Regents of the University of California.  All rights reserved.
6  * (c) UNIX System Laboratories, Inc.
7  * All or some portions of this file are derived from material licensed
8  * to the University of California by American Telephone and Telegraph
9  * Co. or Unix System Laboratories, Inc. and are reproduced herein with
10  * the permission of UNIX System Laboratories, Inc.
11  *
12  * Redistribution and use in source and binary forms, with or without
13  * modification, are permitted provided that the following conditions
14  * are met:
15  * 1. Redistributions of source code must retain the above copyright
16  *    notice, this list of conditions and the following disclaimer.
17  * 2. Redistributions in binary form must reproduce the above copyright
18  *    notice, this list of conditions and the following disclaimer in the
19  *    documentation and/or other materials provided with the distribution.
20  * 3. Neither the name of the University nor the names of its contributors
21  *    may be used to endorse or promote products derived from this software
22  *    without specific prior written permission.
23  *
24  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
25  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
28  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
29  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
30  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
31  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
32  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
33  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34  * SUCH DAMAGE.
35  *
36  *	@(#)ufs_vnops.c	8.14 (Berkeley) 10/26/94
37  * Modified for ext2fs by Manuel Bouyer.
38  */
39 
40 /*
41  * Copyright (c) 1997 Manuel Bouyer.
42  *
43  * Redistribution and use in source and binary forms, with or without
44  * modification, are permitted provided that the following conditions
45  * are met:
46  * 1. Redistributions of source code must retain the above copyright
47  *    notice, this list of conditions and the following disclaimer.
48  * 2. Redistributions in binary form must reproduce the above copyright
49  *    notice, this list of conditions and the following disclaimer in the
50  *    documentation and/or other materials provided with the distribution.
51  *
52  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
53  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
54  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
55  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
56  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
57  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
58  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
59  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
60  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
61  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
62  *
63  *	@(#)ufs_vnops.c	8.14 (Berkeley) 10/26/94
64  * Modified for ext2fs by Manuel Bouyer.
65  */
66 
67 #include <sys/cdefs.h>
68 __KERNEL_RCSID(0, "$NetBSD: ext2fs_vnops.c,v 1.97 2011/01/02 05:09:32 dholland Exp $");
69 
70 #include <sys/param.h>
71 #include <sys/systm.h>
72 #include <sys/resourcevar.h>
73 #include <sys/kernel.h>
74 #include <sys/file.h>
75 #include <sys/stat.h>
76 #include <sys/buf.h>
77 #include <sys/proc.h>
78 #include <sys/mount.h>
79 #include <sys/namei.h>
80 #include <sys/vnode.h>
81 #include <sys/lockf.h>
82 #include <sys/malloc.h>
83 #include <sys/pool.h>
84 #include <sys/signalvar.h>
85 #include <sys/kauth.h>
86 
87 #include <miscfs/fifofs/fifo.h>
88 #include <miscfs/genfs/genfs.h>
89 #include <miscfs/specfs/specdev.h>
90 
91 #include <ufs/ufs/inode.h>
92 #include <ufs/ufs/ufs_extern.h>
93 #include <ufs/ufs/ufsmount.h>
94 
95 #include <ufs/ext2fs/ext2fs.h>
96 #include <ufs/ext2fs/ext2fs_extern.h>
97 #include <ufs/ext2fs/ext2fs_dir.h>
98 
99 extern int prtactive;
100 
101 static int ext2fs_chmod(struct vnode *, int, kauth_cred_t, struct lwp *);
102 static int ext2fs_chown(struct vnode *, uid_t, gid_t, kauth_cred_t,
103 				struct lwp *);
104 
105 union _qcvt {
106 	int64_t	qcvt;
107 	int32_t val[2];
108 };
109 
110 #define SETHIGH(q, h) { \
111 	union _qcvt tmp; \
112 	tmp.qcvt = (q); \
113 	tmp.val[_QUAD_HIGHWORD] = (h); \
114 	(q) = tmp.qcvt; \
115 }
116 #define SETLOW(q, l) { \
117 	union _qcvt tmp; \
118 	tmp.qcvt = (q); \
119 	tmp.val[_QUAD_LOWWORD] = (l); \
120 	(q) = tmp.qcvt; \
121 }
122 
123 /*
124  * Create a regular file
125  */
126 int
127 ext2fs_create(void *v)
128 {
129 	struct vop_create_args /* {
130 		struct vnode *a_dvp;
131 		struct vnode **a_vpp;
132 		struct componentname *a_cnp;
133 		struct vattr *a_vap;
134 	} */ *ap = v;
135 	int	error;
136 
137 	error =
138 	    ext2fs_makeinode(MAKEIMODE(ap->a_vap->va_type, ap->a_vap->va_mode),
139 			     ap->a_dvp, ap->a_vpp, ap->a_cnp);
140 
141 	if (error)
142 		return (error);
143 	VN_KNOTE(ap->a_dvp, NOTE_WRITE);
144 	return (0);
145 }
146 
147 /*
148  * Mknod vnode call
149  */
150 /* ARGSUSED */
151 int
152 ext2fs_mknod(void *v)
153 {
154 	struct vop_mknod_args /* {
155 		struct vnode *a_dvp;
156 		struct vnode **a_vpp;
157 		struct componentname *a_cnp;
158 		struct vattr *a_vap;
159 	} */ *ap = v;
160 	struct vattr *vap = ap->a_vap;
161 	struct vnode **vpp = ap->a_vpp;
162 	struct inode *ip;
163 	int error;
164 	struct mount	*mp;
165 	ino_t		ino;
166 
167 	if ((error = ext2fs_makeinode(MAKEIMODE(vap->va_type, vap->va_mode),
168 		    ap->a_dvp, vpp, ap->a_cnp)) != 0)
169 		return (error);
170 	VN_KNOTE(ap->a_dvp, NOTE_WRITE);
171 	ip = VTOI(*vpp);
172 	mp  = (*vpp)->v_mount;
173 	ino = ip->i_number;
174 	ip->i_flag |= IN_ACCESS | IN_CHANGE | IN_UPDATE;
175 	if (vap->va_rdev != VNOVAL) {
176 		/*
177 		 * Want to be able to use this to make badblock
178 		 * inodes, so don't truncate the dev number.
179 		 */
180 		ip->i_din.e2fs_din->e2di_rdev = h2fs32(vap->va_rdev);
181 	}
182 	/*
183 	 * Remove inode so that it will be reloaded by VFS_VGET and
184 	 * checked to see if it is an alias of an existing entry in
185 	 * the inode cache.
186 	 */
187 	VOP_UNLOCK(*vpp);
188 	(*vpp)->v_type = VNON;
189 	vgone(*vpp);
190 	error = VFS_VGET(mp, ino, vpp);
191 	if (error != 0) {
192 		*vpp = NULL;
193 		return (error);
194 	}
195 	return (0);
196 }
197 
198 /*
199  * Open called.
200  *
201  * Just check the APPEND flag.
202  */
203 /* ARGSUSED */
204 int
205 ext2fs_open(void *v)
206 {
207 	struct vop_open_args /* {
208 		struct vnode *a_vp;
209 		int  a_mode;
210 		kauth_cred_t a_cred;
211 	} */ *ap = v;
212 
213 	/*
214 	 * Files marked append-only must be opened for appending.
215 	 */
216 	if ((VTOI(ap->a_vp)->i_e2fs_flags & EXT2_APPEND) &&
217 		(ap->a_mode & (FWRITE | O_APPEND)) == FWRITE)
218 		return (EPERM);
219 	return (0);
220 }
221 
222 static int
223 ext2fs_check_possible(struct vnode *vp, struct inode *ip, mode_t mode)
224 {
225 
226 	/*
227 	 * Disallow write attempts on read-only file systems;
228 	 * unless the file is a socket, fifo, or a block or
229 	 * character device resident on the file system.
230 	 */
231 	if (mode & VWRITE) {
232 		switch (vp->v_type) {
233 		case VDIR:
234 		case VLNK:
235 		case VREG:
236 			if (vp->v_mount->mnt_flag & MNT_RDONLY)
237 				return (EROFS);
238 			break;
239 		default:
240 			break;
241 		}
242 	}
243 
244 	/* If immutable bit set, nobody gets to write it. */
245 	if ((mode & VWRITE) && (ip->i_e2fs_flags & EXT2_IMMUTABLE))
246 		return (EPERM);
247 
248 	return 0;
249 }
250 
251 static int
252 ext2fs_check_permitted(struct vnode *vp, struct inode *ip, mode_t mode,
253     kauth_cred_t cred)
254 {
255 
256 	return genfs_can_access(vp->v_type, ip->i_e2fs_mode & ALLPERMS,
257 	    ip->i_uid, ip->i_gid, mode, cred);
258 }
259 
260 int
261 ext2fs_access(void *v)
262 {
263 	struct vop_access_args /* {
264 		struct vnode *a_vp;
265 		int  a_mode;
266 		kauth_cred_t a_cred;
267 	} */ *ap = v;
268 	struct vnode *vp = ap->a_vp;
269 	struct inode *ip = VTOI(vp);
270 	mode_t mode = ap->a_mode;
271 	int error;
272 
273 	error = ext2fs_check_possible(vp, ip, mode);
274 	if (error)
275 		return error;
276 
277 	error = ext2fs_check_permitted(vp, ip, mode, ap->a_cred);
278 
279 	return error;
280 }
281 
282 /* ARGSUSED */
283 int
284 ext2fs_getattr(void *v)
285 {
286 	struct vop_getattr_args /* {
287 		struct vnode *a_vp;
288 		struct vattr *a_vap;
289 		kauth_cred_t a_cred;
290 	} */ *ap = v;
291 	struct vnode *vp = ap->a_vp;
292 	struct inode *ip = VTOI(vp);
293 	struct vattr *vap = ap->a_vap;
294 
295 	EXT2FS_ITIMES(ip, NULL, NULL, NULL);
296 	/*
297 	 * Copy from inode table
298 	 */
299 	vap->va_fsid = ip->i_dev;
300 	vap->va_fileid = ip->i_number;
301 	vap->va_mode = ip->i_e2fs_mode & ALLPERMS;
302 	vap->va_nlink = ip->i_e2fs_nlink;
303 	vap->va_uid = ip->i_uid;
304 	vap->va_gid = ip->i_gid;
305 	vap->va_rdev = (dev_t)fs2h32(ip->i_din.e2fs_din->e2di_rdev);
306 	vap->va_size = vp->v_size;
307 	vap->va_atime.tv_sec = ip->i_e2fs_atime;
308 	vap->va_atime.tv_nsec = 0;
309 	vap->va_mtime.tv_sec = ip->i_e2fs_mtime;
310 	vap->va_mtime.tv_nsec = 0;
311 	vap->va_ctime.tv_sec = ip->i_e2fs_ctime;
312 	vap->va_ctime.tv_nsec = 0;
313 #ifdef EXT2FS_SYSTEM_FLAGS
314 	vap->va_flags = (ip->i_e2fs_flags & EXT2_APPEND) ? SF_APPEND : 0;
315 	vap->va_flags |= (ip->i_e2fs_flags & EXT2_IMMUTABLE) ? SF_IMMUTABLE : 0;
316 #else
317 	vap->va_flags = (ip->i_e2fs_flags & EXT2_APPEND) ? UF_APPEND : 0;
318 	vap->va_flags |= (ip->i_e2fs_flags & EXT2_IMMUTABLE) ? UF_IMMUTABLE : 0;
319 #endif
320 	vap->va_gen = ip->i_e2fs_gen;
321 	/* this doesn't belong here */
322 	if (vp->v_type == VBLK)
323 		vap->va_blocksize = BLKDEV_IOSIZE;
324 	else if (vp->v_type == VCHR)
325 		vap->va_blocksize = MAXBSIZE;
326 	else
327 		vap->va_blocksize = vp->v_mount->mnt_stat.f_iosize;
328 	vap->va_bytes = dbtob((u_quad_t)ip->i_e2fs_nblock);
329 	vap->va_type = vp->v_type;
330 	vap->va_filerev = ip->i_modrev;
331 	return (0);
332 }
333 
334 /*
335  * Set attribute vnode op. called from several syscalls
336  */
337 int
338 ext2fs_setattr(void *v)
339 {
340 	struct vop_setattr_args /* {
341 		struct vnode *a_vp;
342 		struct vattr *a_vap;
343 		kauth_cred_t a_cred;
344 	} */ *ap = v;
345 	struct vattr *vap = ap->a_vap;
346 	struct vnode *vp = ap->a_vp;
347 	struct inode *ip = VTOI(vp);
348 	kauth_cred_t cred = ap->a_cred;
349 	struct lwp *l = curlwp;
350 	int error;
351 
352 	/*
353 	 * Check for unsettable attributes.
354 	 */
355 	if ((vap->va_type != VNON) || (vap->va_nlink != (nlink_t)VNOVAL) ||
356 	    (vap->va_fsid != VNOVAL) || (vap->va_fileid != VNOVAL) ||
357 	    (vap->va_blocksize != VNOVAL) || (vap->va_rdev != VNOVAL) ||
358 	    ((int)vap->va_bytes != VNOVAL) || (vap->va_gen != VNOVAL)) {
359 		return (EINVAL);
360 	}
361 	if (vap->va_flags != VNOVAL) {
362 		if (vp->v_mount->mnt_flag & MNT_RDONLY)
363 			return (EROFS);
364 		if (kauth_cred_geteuid(cred) != ip->i_uid &&
365 		    (error = kauth_authorize_generic(cred, KAUTH_GENERIC_ISSUSER,
366 		    NULL)))
367 			return (error);
368 #ifdef EXT2FS_SYSTEM_FLAGS
369 		if (kauth_authorize_generic(cred, KAUTH_GENERIC_ISSUSER,
370 		    NULL) == 0) {
371 			if ((ip->i_e2fs_flags &
372 			    (EXT2_APPEND | EXT2_IMMUTABLE)) &&
373 			    kauth_authorize_system(l->l_cred,
374 			     KAUTH_SYSTEM_CHSYSFLAGS, 0, NULL, NULL, NULL))
375 				return (EPERM);
376 			ip->i_e2fs_flags &= ~(EXT2_APPEND | EXT2_IMMUTABLE);
377 			ip->i_e2fs_flags |=
378 			    (vap->va_flags & SF_APPEND) ?  EXT2_APPEND : 0 |
379 			    (vap->va_flags & SF_IMMUTABLE) ? EXT2_IMMUTABLE : 0;
380 		} else
381 			return (EPERM);
382 #else
383 		ip->i_e2fs_flags &= ~(EXT2_APPEND | EXT2_IMMUTABLE);
384 		ip->i_e2fs_flags |=
385 		    (vap->va_flags & UF_APPEND) ? EXT2_APPEND : 0 |
386 		    (vap->va_flags & UF_IMMUTABLE) ? EXT2_IMMUTABLE : 0;
387 #endif
388 		ip->i_flag |= IN_CHANGE;
389 		if (vap->va_flags & (IMMUTABLE | APPEND))
390 			return (0);
391 	}
392 	if (ip->i_e2fs_flags & (EXT2_APPEND | EXT2_IMMUTABLE))
393 		return (EPERM);
394 	/*
395 	 * Go through the fields and update iff not VNOVAL.
396 	 */
397 	if (vap->va_uid != (uid_t)VNOVAL || vap->va_gid != (gid_t)VNOVAL) {
398 		if (vp->v_mount->mnt_flag & MNT_RDONLY)
399 			return (EROFS);
400 		error = ext2fs_chown(vp, vap->va_uid, vap->va_gid, cred, l);
401 		if (error)
402 			return (error);
403 	}
404 	if (vap->va_size != VNOVAL) {
405 		/*
406 		 * Disallow write attempts on read-only file systems;
407 		 * unless the file is a socket, fifo, or a block or
408 		 * character device resident on the file system.
409 		 */
410 		switch (vp->v_type) {
411 		case VDIR:
412 			return (EISDIR);
413 		case VLNK:
414 		case VREG:
415 			if (vp->v_mount->mnt_flag & MNT_RDONLY)
416 				return (EROFS);
417 		default:
418 			break;
419 		}
420 		error = ext2fs_truncate(vp, vap->va_size, 0, cred);
421 		if (error)
422 			return (error);
423 	}
424 	ip = VTOI(vp);
425 	if (vap->va_atime.tv_sec != VNOVAL || vap->va_mtime.tv_sec != VNOVAL) {
426 		if (vp->v_mount->mnt_flag & MNT_RDONLY)
427 			return (EROFS);
428 		error = genfs_can_chtimes(vp, vap->va_vaflags, ip->i_uid, cred);
429 		if (error)
430 			return (error);
431 		if (vap->va_atime.tv_sec != VNOVAL)
432 			if (!(vp->v_mount->mnt_flag & MNT_NOATIME))
433 				ip->i_flag |= IN_ACCESS;
434 		if (vap->va_mtime.tv_sec != VNOVAL)
435 			ip->i_flag |= IN_CHANGE | IN_UPDATE;
436 		error = ext2fs_update(vp, &vap->va_atime, &vap->va_mtime,
437 			UPDATE_WAIT);
438 		if (error)
439 			return (error);
440 	}
441 	error = 0;
442 	if (vap->va_mode != (mode_t)VNOVAL) {
443 		if (vp->v_mount->mnt_flag & MNT_RDONLY)
444 			return (EROFS);
445 		error = ext2fs_chmod(vp, (int)vap->va_mode, cred, l);
446 	}
447 	VN_KNOTE(vp, NOTE_ATTRIB);
448 	return (error);
449 }
450 
451 /*
452  * Change the mode on a file.
453  * Inode must be locked before calling.
454  */
455 static int
456 ext2fs_chmod(struct vnode *vp, int mode, kauth_cred_t cred, struct lwp *l)
457 {
458 	struct inode *ip = VTOI(vp);
459 	int error;
460 
461 	error = genfs_can_chmod(vp, cred, ip->i_uid, ip->i_gid, mode);
462 	if (error)
463 		return (error);
464 
465 	ip->i_e2fs_mode &= ~ALLPERMS;
466 	ip->i_e2fs_mode |= (mode & ALLPERMS);
467 	ip->i_flag |= IN_CHANGE;
468 	return (0);
469 }
470 
471 /*
472  * Perform chown operation on inode ip;
473  * inode must be locked prior to call.
474  */
475 static int
476 ext2fs_chown(struct vnode *vp, uid_t uid, gid_t gid, kauth_cred_t cred,
477 		struct lwp *l)
478 {
479 	struct inode *ip = VTOI(vp);
480 	uid_t ouid;
481 	gid_t ogid;
482 	int error;
483 
484 	if (uid == (uid_t)VNOVAL)
485 		uid = ip->i_uid;
486 	if (gid == (gid_t)VNOVAL)
487 		gid = ip->i_gid;
488 
489 	error = genfs_can_chown(vp, cred, ip->i_uid, ip->i_gid, uid, gid);
490 	if (error)
491 		return (error);
492 
493 	ogid = ip->i_gid;
494 	ouid = ip->i_uid;
495 
496 	ip->i_e2fs_gid = gid & 0xffff;
497 	ip->i_e2fs_uid = uid & 0xffff;
498 	if (ip->i_e2fs->e2fs.e2fs_rev > E2FS_REV0) {
499 		ip->i_e2fs_gid_high = (gid >> 16) & 0xffff;
500 		ip->i_e2fs_uid_high = (uid >> 16) & 0xffff;
501 	} else {
502 		ip->i_e2fs_gid_high = 0;
503 		ip->i_e2fs_uid_high = 0;
504 	}
505 	if (ouid != uid || ogid != gid) {
506 		ext2fs_set_inode_guid(ip);
507 		ip->i_flag |= IN_CHANGE;
508 	}
509 	if (ouid != uid && kauth_authorize_generic(cred,
510 	    KAUTH_GENERIC_ISSUSER, NULL) != 0)
511 		ip->i_e2fs_mode &= ~ISUID;
512 	if (ogid != gid && kauth_authorize_generic(cred,
513 	    KAUTH_GENERIC_ISSUSER, NULL) != 0)
514 		ip->i_e2fs_mode &= ~ISGID;
515 	return (0);
516 }
517 
518 int
519 ext2fs_remove(void *v)
520 {
521 	struct vop_remove_args /* {
522 		struct vnode *a_dvp;
523 		struct vnode *a_vp;
524 		struct componentname *a_cnp;
525 	} */ *ap = v;
526 	struct inode *ip;
527 	struct vnode *vp = ap->a_vp;
528 	struct vnode *dvp = ap->a_dvp;
529 	int error;
530 
531 	ip = VTOI(vp);
532 	if (vp->v_type == VDIR ||
533 		(ip->i_e2fs_flags & (EXT2_IMMUTABLE | EXT2_APPEND)) ||
534 		(VTOI(dvp)->i_e2fs_flags & EXT2_APPEND)) {
535 		error = EPERM;
536 	} else {
537 		error = ext2fs_dirremove(dvp, ap->a_cnp);
538 		if (error == 0) {
539 			ip->i_e2fs_nlink--;
540 			ip->i_flag |= IN_CHANGE;
541 		}
542 	}
543 
544 	VN_KNOTE(vp, NOTE_DELETE);
545 	VN_KNOTE(dvp, NOTE_WRITE);
546 	if (dvp == vp)
547 		vrele(vp);
548 	else
549 		vput(vp);
550 	vput(dvp);
551 	return (error);
552 }
553 
554 /*
555  * link vnode call
556  */
557 int
558 ext2fs_link(void *v)
559 {
560 	struct vop_link_args /* {
561 		struct vnode *a_dvp;
562 		struct vnode *a_vp;
563 		struct componentname *a_cnp;
564 	} */ *ap = v;
565 	struct vnode *dvp = ap->a_dvp;
566 	struct vnode *vp = ap->a_vp;
567 	struct componentname *cnp = ap->a_cnp;
568 	struct inode *ip;
569 	int error;
570 
571 	if (vp->v_type == VDIR) {
572 		VOP_ABORTOP(dvp, cnp);
573 		error = EISDIR;
574 		goto out2;
575 	}
576 	if (dvp->v_mount != vp->v_mount) {
577 		VOP_ABORTOP(dvp, cnp);
578 		error = EXDEV;
579 		goto out2;
580 	}
581 	if (dvp != vp && (error = vn_lock(vp, LK_EXCLUSIVE))) {
582 		VOP_ABORTOP(dvp, cnp);
583 		goto out2;
584 	}
585 	ip = VTOI(vp);
586 	if ((nlink_t)ip->i_e2fs_nlink >= LINK_MAX) {
587 		VOP_ABORTOP(dvp, cnp);
588 		error = EMLINK;
589 		goto out1;
590 	}
591 	if (ip->i_e2fs_flags & (EXT2_IMMUTABLE | EXT2_APPEND)) {
592 		VOP_ABORTOP(dvp, cnp);
593 		error = EPERM;
594 		goto out1;
595 	}
596 	ip->i_e2fs_nlink++;
597 	ip->i_flag |= IN_CHANGE;
598 	error = ext2fs_update(vp, NULL, NULL, UPDATE_WAIT);
599 	if (!error)
600 		error = ext2fs_direnter(ip, dvp, cnp);
601 	if (error) {
602 		ip->i_e2fs_nlink--;
603 		ip->i_flag |= IN_CHANGE;
604 	}
605 out1:
606 	if (dvp != vp)
607 		VOP_UNLOCK(vp);
608 out2:
609 	VN_KNOTE(vp, NOTE_LINK);
610 	VN_KNOTE(dvp, NOTE_WRITE);
611 	vput(dvp);
612 	return (error);
613 }
614 
615 /*
616  * Rename system call.
617  *	rename("foo", "bar");
618  * is essentially
619  *	unlink("bar");
620  *	link("foo", "bar");
621  *	unlink("foo");
622  * but ``atomically''.  Can't do full commit without saving state in the
623  * inode on disk which isn't feasible at this time.  Best we can do is
624  * always guarantee the target exists.
625  *
626  * Basic algorithm is:
627  *
628  * 1) Bump link count on source while we're linking it to the
629  *    target.  This also ensure the inode won't be deleted out
630  *    from underneath us while we work (it may be truncated by
631  *    a concurrent `trunc' or `open' for creation).
632  * 2) Link source to destination.  If destination already exists,
633  *    delete it first.
634  * 3) Unlink source reference to inode if still around. If a
635  *    directory was moved and the parent of the destination
636  *    is different from the source, patch the ".." entry in the
637  *    directory.
638  */
639 int
640 ext2fs_rename(void *v)
641 {
642 	struct vop_rename_args  /* {
643 		struct vnode *a_fdvp;
644 		struct vnode *a_fvp;
645 		struct componentname *a_fcnp;
646 		struct vnode *a_tdvp;
647 		struct vnode *a_tvp;
648 		struct componentname *a_tcnp;
649 	} */ *ap = v;
650 	struct vnode *tvp = ap->a_tvp;
651 	struct vnode *tdvp = ap->a_tdvp;
652 	struct vnode *fvp = ap->a_fvp;
653 	struct vnode *fdvp = ap->a_fdvp;
654 	struct componentname *tcnp = ap->a_tcnp;
655 	struct componentname *fcnp = ap->a_fcnp;
656 	struct inode *ip, *xp, *dp;
657 	struct ext2fs_dirtemplate dirbuf;
658 	int doingdirectory = 0, oldparent = 0, newparent = 0;
659 	int error = 0;
660 	u_char namlen;
661 
662 	/*
663 	 * Check for cross-device rename.
664 	 */
665 	if ((fvp->v_mount != tdvp->v_mount) ||
666 	    (tvp && (fvp->v_mount != tvp->v_mount))) {
667 		error = EXDEV;
668 abortit:
669 		VOP_ABORTOP(tdvp, tcnp); /* XXX, why not in NFS? */
670 		if (tdvp == tvp)
671 			vrele(tdvp);
672 		else
673 			vput(tdvp);
674 		if (tvp)
675 			vput(tvp);
676 		VOP_ABORTOP(fdvp, fcnp); /* XXX, why not in NFS? */
677 		vrele(fdvp);
678 		vrele(fvp);
679 		return (error);
680 	}
681 
682 	/*
683 	 * Check if just deleting a link name.
684 	 */
685 	if (tvp && ((VTOI(tvp)->i_e2fs_flags & (EXT2_IMMUTABLE | EXT2_APPEND)) ||
686 	    (VTOI(tdvp)->i_e2fs_flags & EXT2_APPEND))) {
687 		error = EPERM;
688 		goto abortit;
689 	}
690 	if (fvp == tvp) {
691 		if (fvp->v_type == VDIR) {
692 			error = EINVAL;
693 			goto abortit;
694 		}
695 
696 		/* Release destination completely. */
697 		VOP_ABORTOP(tdvp, tcnp);
698 		vput(tdvp);
699 		vput(tvp);
700 
701 		/* Delete source. */
702 		vrele(fvp);
703 		fcnp->cn_flags &= ~(MODMASK);
704 		fcnp->cn_flags |= LOCKPARENT | LOCKLEAF;
705 		fcnp->cn_nameiop = DELETE;
706 		vn_lock(fdvp, LK_EXCLUSIVE | LK_RETRY);
707 		if ((error = relookup(fdvp, &fvp, fcnp, 0))) {
708 			vput(fdvp);
709 			return (error);
710 		}
711 		return (VOP_REMOVE(fdvp, fvp, fcnp));
712 	}
713 	if ((error = vn_lock(fvp, LK_EXCLUSIVE)) != 0)
714 		goto abortit;
715 	dp = VTOI(fdvp);
716 	ip = VTOI(fvp);
717 	if ((nlink_t) ip->i_e2fs_nlink >= LINK_MAX) {
718 		VOP_UNLOCK(fvp);
719 		error = EMLINK;
720 		goto abortit;
721 	}
722 	if ((ip->i_e2fs_flags & (EXT2_IMMUTABLE | EXT2_APPEND)) ||
723 		(dp->i_e2fs_flags & EXT2_APPEND)) {
724 		VOP_UNLOCK(fvp);
725 		error = EPERM;
726 		goto abortit;
727 	}
728 	if ((ip->i_e2fs_mode & IFMT) == IFDIR) {
729 		error = VOP_ACCESS(fvp, VWRITE, tcnp->cn_cred);
730 		if (!error && tvp)
731 			error = VOP_ACCESS(tvp, VWRITE, tcnp->cn_cred);
732 		if (error) {
733 			VOP_UNLOCK(fvp);
734 			error = EACCES;
735 			goto abortit;
736 		}
737 		/*
738 		 * Avoid ".", "..", and aliases of "." for obvious reasons.
739 		 */
740 		if ((fcnp->cn_namelen == 1 && fcnp->cn_nameptr[0] == '.') ||
741 		    dp == ip ||
742 		    (fcnp->cn_flags & ISDOTDOT) ||
743 		    (tcnp->cn_flags & ISDOTDOT) ||
744 		    (ip->i_flag & IN_RENAME)) {
745 			VOP_UNLOCK(fvp);
746 			error = EINVAL;
747 			goto abortit;
748 		}
749 		ip->i_flag |= IN_RENAME;
750 		oldparent = dp->i_number;
751 		doingdirectory = 1;
752 	}
753 	VN_KNOTE(fdvp, NOTE_WRITE);		/* XXXLUKEM/XXX: right place? */
754 
755 	/*
756 	 * When the target exists, both the directory
757 	 * and target vnodes are returned locked.
758 	 */
759 	dp = VTOI(tdvp);
760 	xp = NULL;
761 	if (tvp)
762 		xp = VTOI(tvp);
763 
764 	/*
765 	 * 1) Bump link count while we're moving stuff
766 	 *    around.  If we crash somewhere before
767 	 *    completing our work, the link count
768 	 *    may be wrong, but correctable.
769 	 */
770 	ip->i_e2fs_nlink++;
771 	ip->i_flag |= IN_CHANGE;
772 	if ((error = ext2fs_update(fvp, NULL, NULL, UPDATE_WAIT)) != 0) {
773 		VOP_UNLOCK(fvp);
774 		goto bad;
775 	}
776 
777 	/*
778 	 * If ".." must be changed (ie the directory gets a new
779 	 * parent) then the source directory must not be in the
780 	 * directory hierarchy above the target, as this would
781 	 * orphan everything below the source directory. Also
782 	 * the user must have write permission in the source so
783 	 * as to be able to change "..". We must repeat the call
784 	 * to namei, as the parent directory is unlocked by the
785 	 * call to checkpath().
786 	 */
787 	error = VOP_ACCESS(fvp, VWRITE, tcnp->cn_cred);
788 	VOP_UNLOCK(fvp);
789 	if (oldparent != dp->i_number)
790 		newparent = dp->i_number;
791 	if (doingdirectory && newparent) {
792 		if (error)	/* write access check above */
793 			goto bad;
794 		if (xp != NULL)
795 			vput(tvp);
796 		vref(tdvp);     /* compensate for the ref checkpath loses */
797 		error = ext2fs_checkpath(ip, dp, tcnp->cn_cred);
798 		if (error != 0) {
799 			vrele(tdvp);
800 			goto out;
801 		}
802 		vn_lock(tdvp, LK_EXCLUSIVE | LK_RETRY);
803 		if ((error = relookup(tdvp, &tvp, tcnp, 0)) != 0) {
804 			vput(tdvp);
805 			goto out;
806 		}
807 		dp = VTOI(tdvp);
808 		xp = NULL;
809 		if (tvp)
810 			xp = VTOI(tvp);
811 	}
812 	/*
813 	 * 2) If target doesn't exist, link the target
814 	 *    to the source and unlink the source.
815 	 *    Otherwise, rewrite the target directory
816 	 *    entry to reference the source inode and
817 	 *    expunge the original entry's existence.
818 	 */
819 	if (xp == NULL) {
820 		if (dp->i_dev != ip->i_dev)
821 			panic("rename: EXDEV");
822 		/*
823 		 * Account for ".." in new directory.
824 		 * When source and destination have the same
825 		 * parent we don't fool with the link count.
826 		 */
827 		if (doingdirectory && newparent) {
828 			if ((nlink_t)dp->i_e2fs_nlink >= LINK_MAX) {
829 				error = EMLINK;
830 				goto bad;
831 			}
832 			dp->i_e2fs_nlink++;
833 			dp->i_flag |= IN_CHANGE;
834 			if ((error = ext2fs_update(tdvp, NULL, NULL,
835 			    UPDATE_WAIT)) != 0)
836 				goto bad;
837 		}
838 		error = ext2fs_direnter(ip, tdvp, tcnp);
839 		if (error != 0) {
840 			if (doingdirectory && newparent) {
841 				dp->i_e2fs_nlink--;
842 				dp->i_flag |= IN_CHANGE;
843 				(void)ext2fs_update(tdvp, NULL, NULL,
844 				    UPDATE_WAIT);
845 			}
846 			goto bad;
847 		}
848 		VN_KNOTE(tdvp, NOTE_WRITE);
849 		vput(tdvp);
850 	} else {
851 		if (xp->i_dev != dp->i_dev || xp->i_dev != ip->i_dev)
852 			panic("rename: EXDEV");
853 		/*
854 		 * Short circuit rename(foo, foo).
855 		 */
856 		if (xp->i_number == ip->i_number)
857 			panic("rename: same file");
858 		/*
859 		 * If the parent directory is "sticky", then the user must
860 		 * own the parent directory, or the destination of the rename,
861 		 * otherwise the destination may not be changed (except by
862 		 * root). This implements append-only directories.
863 		 */
864 		if ((dp->i_e2fs_mode & S_ISTXT) &&
865 		    kauth_authorize_generic(tcnp->cn_cred,
866 		     KAUTH_GENERIC_ISSUSER, NULL) != 0 &&
867 		    kauth_cred_geteuid(tcnp->cn_cred) != dp->i_uid &&
868 		    xp->i_uid != kauth_cred_geteuid(tcnp->cn_cred)) {
869 			error = EPERM;
870 			goto bad;
871 		}
872 		/*
873 		 * Target must be empty if a directory and have no links
874 		 * to it. Also, ensure source and target are compatible
875 		 * (both directories, or both not directories).
876 		 */
877 		if ((xp->i_e2fs_mode & IFMT) == IFDIR) {
878 			if (!ext2fs_dirempty(xp, dp->i_number, tcnp->cn_cred) ||
879 				xp->i_e2fs_nlink > 2) {
880 				error = ENOTEMPTY;
881 				goto bad;
882 			}
883 			if (!doingdirectory) {
884 				error = ENOTDIR;
885 				goto bad;
886 			}
887 			cache_purge(tdvp);
888 		} else if (doingdirectory) {
889 			error = EISDIR;
890 			goto bad;
891 		}
892 		error = ext2fs_dirrewrite(dp, ip, tcnp);
893 		if (error != 0)
894 			goto bad;
895 		/*
896 		 * If the target directory is in the same
897 		 * directory as the source directory,
898 		 * decrement the link count on the parent
899 		 * of the target directory.
900 		 */
901 		 if (doingdirectory && !newparent) {
902 			dp->i_e2fs_nlink--;
903 			dp->i_flag |= IN_CHANGE;
904 		}
905 		/*
906 		 * Adjust the link count of the target to
907 		 * reflect the dirrewrite above.  If this is
908 		 * a directory it is empty and there are
909 		 * no links to it, so we can squash the inode and
910 		 * any space associated with it.  We disallowed
911 		 * renaming over top of a directory with links to
912 		 * it above, as the remaining link would point to
913 		 * a directory without "." or ".." entries.
914 		 */
915 		xp->i_e2fs_nlink--;
916 		if (doingdirectory) {
917 			if (--xp->i_e2fs_nlink != 0)
918 				panic("rename: linked directory");
919 			error = ext2fs_truncate(tvp, (off_t)0, IO_SYNC,
920 			    tcnp->cn_cred);
921 		}
922 		xp->i_flag |= IN_CHANGE;
923 		VN_KNOTE(tdvp, NOTE_WRITE);
924 		vput(tdvp);
925 		VN_KNOTE(tvp, NOTE_DELETE);
926 		vput(tvp);
927 		xp = NULL;
928 	}
929 
930 	/*
931 	 * 3) Unlink the source.
932 	 */
933 	fcnp->cn_flags &= ~(MODMASK);
934 	fcnp->cn_flags |= LOCKPARENT | LOCKLEAF;
935 	vn_lock(fdvp, LK_EXCLUSIVE | LK_RETRY);
936 	if ((error = relookup(fdvp, &fvp, fcnp, 0))) {
937 		vput(fdvp);
938 		vrele(ap->a_fvp);
939 		return (error);
940 	}
941 	if (fvp != NULL) {
942 		xp = VTOI(fvp);
943 		dp = VTOI(fdvp);
944 	} else {
945 		/*
946 		 * From name has disappeared.
947 		 */
948 		if (doingdirectory)
949 			panic("ext2fs_rename: lost dir entry");
950 		vrele(ap->a_fvp);
951 		return (0);
952 	}
953 	/*
954 	 * Ensure that the directory entry still exists and has not
955 	 * changed while the new name has been entered. If the source is
956 	 * a file then the entry may have been unlinked or renamed. In
957 	 * either case there is no further work to be done. If the source
958 	 * is a directory then it cannot have been rmdir'ed; its link
959 	 * count of three would cause a rmdir to fail with ENOTEMPTY.
960 	 * The IRENAME flag ensures that it cannot be moved by another
961 	 * rename.
962 	 */
963 	if (xp != ip) {
964 		if (doingdirectory)
965 			panic("ext2fs_rename: lost dir entry");
966 	} else {
967 		/*
968 		 * If the source is a directory with a
969 		 * new parent, the link count of the old
970 		 * parent directory must be decremented
971 		 * and ".." set to point to the new parent.
972 		 */
973 		if (doingdirectory && newparent) {
974 			KASSERT(dp != NULL);
975 			dp->i_e2fs_nlink--;
976 			dp->i_flag |= IN_CHANGE;
977 			error = vn_rdwr(UIO_READ, fvp, (void *)&dirbuf,
978 				sizeof (struct ext2fs_dirtemplate), (off_t)0,
979 				UIO_SYSSPACE, IO_NODELOCKED,
980 				tcnp->cn_cred, (size_t *)0, NULL);
981 			if (error == 0) {
982 					namlen = dirbuf.dotdot_namlen;
983 				if (namlen != 2 ||
984 				    dirbuf.dotdot_name[0] != '.' ||
985 				    dirbuf.dotdot_name[1] != '.') {
986 					ufs_dirbad(xp, (doff_t)12,
987 					    "ext2fs_rename: mangled dir");
988 				} else {
989 					dirbuf.dotdot_ino = h2fs32(newparent);
990 					(void) vn_rdwr(UIO_WRITE, fvp,
991 					    (void *)&dirbuf,
992 					    sizeof (struct dirtemplate),
993 					    (off_t)0, UIO_SYSSPACE,
994 					    IO_NODELOCKED|IO_SYNC,
995 					    tcnp->cn_cred, (size_t *)0,
996 					    NULL);
997 					cache_purge(fdvp);
998 				}
999 			}
1000 		}
1001 		error = ext2fs_dirremove(fdvp, fcnp);
1002 		if (!error) {
1003 			xp->i_e2fs_nlink--;
1004 			xp->i_flag |= IN_CHANGE;
1005 		}
1006 		xp->i_flag &= ~IN_RENAME;
1007 	}
1008 	VN_KNOTE(fvp, NOTE_RENAME);
1009 	if (dp)
1010 		vput(fdvp);
1011 	if (xp)
1012 		vput(fvp);
1013 	vrele(ap->a_fvp);
1014 	return (error);
1015 
1016 bad:
1017 	if (xp)
1018 		vput(ITOV(xp));
1019 	vput(ITOV(dp));
1020 out:
1021 	if (doingdirectory)
1022 		ip->i_flag &= ~IN_RENAME;
1023 	if (vn_lock(fvp, LK_EXCLUSIVE) == 0) {
1024 		ip->i_e2fs_nlink--;
1025 		ip->i_flag |= IN_CHANGE;
1026 		vput(fvp);
1027 	} else
1028 		vrele(fvp);
1029 	vrele(fdvp);
1030 	return (error);
1031 }
1032 
1033 /*
1034  * Mkdir system call
1035  */
1036 int
1037 ext2fs_mkdir(void *v)
1038 {
1039 	struct vop_mkdir_args /* {
1040 		struct vnode *a_dvp;
1041 		struct vnode **a_vpp;
1042 		struct componentname *a_cnp;
1043 		struct vattr *a_vap;
1044 	} */ *ap = v;
1045 	struct vnode		*dvp = ap->a_dvp;
1046 	struct vattr		*vap = ap->a_vap;
1047 	struct componentname	*cnp = ap->a_cnp;
1048 	struct inode		*ip, *dp = VTOI(dvp);
1049 	struct vnode		*tvp;
1050 	struct ext2fs_dirtemplate dirtemplate;
1051 	int			error, dmode;
1052 
1053 	if ((nlink_t)dp->i_e2fs_nlink >= LINK_MAX) {
1054 		error = EMLINK;
1055 		goto out;
1056 	}
1057 	dmode = vap->va_mode & ACCESSPERMS;
1058 	dmode |= IFDIR;
1059 	/*
1060 	 * Must simulate part of ext2fs_makeinode here to acquire the inode,
1061 	 * but not have it entered in the parent directory. The entry is
1062 	 * made later after writing "." and ".." entries.
1063 	 */
1064 	if ((error = ext2fs_valloc(dvp, dmode, cnp->cn_cred, &tvp)) != 0)
1065 		goto out;
1066 	ip = VTOI(tvp);
1067 	ip->i_uid = kauth_cred_geteuid(cnp->cn_cred);
1068 	ip->i_e2fs_uid = ip->i_uid & 0xffff;
1069 	ip->i_e2fs_gid = dp->i_e2fs_gid;
1070 	if (ip->i_e2fs->e2fs.e2fs_rev > E2FS_REV0) {
1071 		ip->i_e2fs_uid_high = (ip->i_uid >> 16) & 0xffff;
1072 		ip->i_e2fs_gid_high = dp->i_e2fs_gid_high;
1073 	} else {
1074 		ip->i_e2fs_uid_high = 0;
1075 		ip->i_e2fs_gid_high = 0;
1076 	}
1077 	ip->i_gid = ip->i_e2fs_gid | (ip->i_e2fs_gid_high << 16);
1078 	ip->i_flag |= IN_ACCESS | IN_CHANGE | IN_UPDATE;
1079 	ip->i_e2fs_mode = dmode;
1080 	tvp->v_type = VDIR;	/* Rest init'd in getnewvnode(). */
1081 	ip->i_e2fs_nlink = 2;
1082 
1083 	/*
1084 	 * Bump link count in parent directory
1085 	 * to reflect work done below.  Should
1086 	 * be done before reference is created
1087 	 * so reparation is possible if we crash.
1088 	 */
1089 	dp->i_e2fs_nlink++;
1090 	dp->i_flag |= IN_CHANGE;
1091 	if ((error = ext2fs_update(dvp, NULL, NULL, UPDATE_DIROP)) != 0)
1092 		goto bad;
1093 
1094 	/* Initialize directory with "." and ".." from static template. */
1095 	memset(&dirtemplate, 0, sizeof(dirtemplate));
1096 	dirtemplate.dot_ino = h2fs32(ip->i_number);
1097 	dirtemplate.dot_reclen = h2fs16(12);
1098 	dirtemplate.dot_namlen = 1;
1099 	if (ip->i_e2fs->e2fs.e2fs_rev > E2FS_REV0 &&
1100 	    (ip->i_e2fs->e2fs.e2fs_features_incompat & EXT2F_INCOMPAT_FTYPE)) {
1101 		dirtemplate.dot_type = EXT2_FT_DIR;
1102 	}
1103 	dirtemplate.dot_name[0] = '.';
1104 	dirtemplate.dotdot_ino = h2fs32(dp->i_number);
1105     dirtemplate.dotdot_reclen = h2fs16(VTOI(dvp)->i_e2fs->e2fs_bsize - 12);
1106 	dirtemplate.dotdot_namlen = 2;
1107 	if (ip->i_e2fs->e2fs.e2fs_rev > E2FS_REV0 &&
1108 	    (ip->i_e2fs->e2fs.e2fs_features_incompat & EXT2F_INCOMPAT_FTYPE)) {
1109 		dirtemplate.dotdot_type = EXT2_FT_DIR;
1110 	}
1111 	dirtemplate.dotdot_name[0] = dirtemplate.dotdot_name[1] = '.';
1112 	error = vn_rdwr(UIO_WRITE, tvp, (void *)&dirtemplate,
1113 	    sizeof (dirtemplate), (off_t)0, UIO_SYSSPACE,
1114 	    IO_NODELOCKED|IO_SYNC, cnp->cn_cred, (size_t *)0, NULL);
1115 	if (error) {
1116 		dp->i_e2fs_nlink--;
1117 		dp->i_flag |= IN_CHANGE;
1118 		goto bad;
1119 	}
1120 	if (VTOI(dvp)->i_e2fs->e2fs_bsize > dvp->v_mount->mnt_stat.f_bsize)
1121 		panic("ext2fs_mkdir: blksize"); /* XXX should grow with balloc() */
1122 	else {
1123 		error = ext2fs_setsize(ip, VTOI(dvp)->i_e2fs->e2fs_bsize);
1124 		if (error) {
1125 			dp->i_e2fs_nlink--;
1126 			dp->i_flag |= IN_CHANGE;
1127 			goto bad;
1128 		}
1129 		ip->i_flag |= IN_CHANGE;
1130 		uvm_vnp_setsize(tvp, ext2fs_size(ip));
1131 	}
1132 
1133 	/* Directory set up, now install it's entry in the parent directory. */
1134 	error = ext2fs_direnter(ip, dvp, cnp);
1135 	if (error != 0) {
1136 		dp->i_e2fs_nlink--;
1137 		dp->i_flag |= IN_CHANGE;
1138 	}
1139 bad:
1140 	/*
1141 	 * No need to do an explicit ext2fs_truncate here, vrele will do this
1142 	 * for us because we set the link count to 0.
1143 	 */
1144 	if (error) {
1145 		ip->i_e2fs_nlink = 0;
1146 		ip->i_flag |= IN_CHANGE;
1147 		vput(tvp);
1148 	} else {
1149 		VN_KNOTE(dvp, NOTE_WRITE | NOTE_LINK);
1150 		*ap->a_vpp = tvp;
1151 	}
1152 out:
1153 	vput(dvp);
1154 	return (error);
1155 }
1156 
1157 /*
1158  * Rmdir system call.
1159  */
1160 int
1161 ext2fs_rmdir(void *v)
1162 {
1163 	struct vop_rmdir_args /* {
1164 		struct vnode *a_dvp;
1165 		struct vnode *a_vp;
1166 		struct componentname *a_cnp;
1167 	} */ *ap = v;
1168 	struct vnode *vp = ap->a_vp;
1169 	struct vnode *dvp = ap->a_dvp;
1170 	struct componentname *cnp = ap->a_cnp;
1171 	struct inode *ip, *dp;
1172 	int error;
1173 
1174 	ip = VTOI(vp);
1175 	dp = VTOI(dvp);
1176 	/*
1177 	 * No rmdir "." please.
1178 	 */
1179 	if (dp == ip) {
1180 		vrele(dvp);
1181 		vput(vp);
1182 		return (EINVAL);
1183 	}
1184 	/*
1185 	 * Verify the directory is empty (and valid).
1186 	 * (Rmdir ".." won't be valid since
1187 	 *  ".." will contain a reference to
1188 	 *  the current directory and thus be
1189 	 *  non-empty.)
1190 	 */
1191 	error = 0;
1192 	if (ip->i_e2fs_nlink != 2 ||
1193 	    !ext2fs_dirempty(ip, dp->i_number, cnp->cn_cred)) {
1194 		error = ENOTEMPTY;
1195 		goto out;
1196 	}
1197 	if ((dp->i_e2fs_flags & EXT2_APPEND) ||
1198 				 (ip->i_e2fs_flags & (EXT2_IMMUTABLE | EXT2_APPEND))) {
1199 		error = EPERM;
1200 		goto out;
1201 	}
1202 	/*
1203 	 * Delete reference to directory before purging
1204 	 * inode.  If we crash in between, the directory
1205 	 * will be reattached to lost+found,
1206 	 */
1207 	error = ext2fs_dirremove(dvp, cnp);
1208 	if (error != 0)
1209 		goto out;
1210 	dp->i_e2fs_nlink--;
1211 	dp->i_flag |= IN_CHANGE;
1212 	VN_KNOTE(dvp, NOTE_WRITE | NOTE_LINK);
1213 	cache_purge(dvp);
1214 	vput(dvp);
1215 	dvp = NULL;
1216 	/*
1217 	 * Truncate inode.  The only stuff left
1218 	 * in the directory is "." and "..".  The
1219 	 * "." reference is inconsequential since
1220 	 * we're quashing it.  The ".." reference
1221 	 * has already been adjusted above.  We've
1222 	 * removed the "." reference and the reference
1223 	 * in the parent directory, but there may be
1224 	 * other hard links so decrement by 2 and
1225 	 * worry about them later.
1226 	 */
1227 	ip->i_e2fs_nlink -= 2;
1228 	error = ext2fs_truncate(vp, (off_t)0, IO_SYNC, cnp->cn_cred);
1229 	cache_purge(ITOV(ip));
1230 out:
1231 	VN_KNOTE(vp, NOTE_DELETE);
1232 	if (dvp)
1233 		vput(dvp);
1234 	vput(vp);
1235 	return (error);
1236 }
1237 
1238 /*
1239  * symlink -- make a symbolic link
1240  */
1241 int
1242 ext2fs_symlink(void *v)
1243 {
1244 	struct vop_symlink_args /* {
1245 		struct vnode *a_dvp;
1246 		struct vnode **a_vpp;
1247 		struct componentname *a_cnp;
1248 		struct vattr *a_vap;
1249 		char *a_target;
1250 	} */ *ap = v;
1251 	struct vnode	*vp, **vpp;
1252 	struct inode	*ip;
1253 	int		len, error;
1254 
1255 	vpp = ap->a_vpp;
1256 	error = ext2fs_makeinode(IFLNK | ap->a_vap->va_mode, ap->a_dvp,
1257 			      vpp, ap->a_cnp);
1258 	if (error)
1259 		return (error);
1260 	VN_KNOTE(ap->a_dvp, NOTE_WRITE);
1261 	vp = *vpp;
1262 	len = strlen(ap->a_target);
1263 	ip = VTOI(vp);
1264 	if (len < ip->i_ump->um_maxsymlinklen) {
1265 		memcpy((char *)ip->i_din.e2fs_din->e2di_shortlink, ap->a_target, len);
1266 		error = ext2fs_setsize(ip, len);
1267 		if (error)
1268 			goto bad;
1269 		ip->i_flag |= IN_CHANGE | IN_UPDATE;
1270 		uvm_vnp_setsize(vp, len);
1271 	} else
1272 		error = vn_rdwr(UIO_WRITE, vp, ap->a_target, len, (off_t)0,
1273 		    UIO_SYSSPACE, IO_NODELOCKED, ap->a_cnp->cn_cred,
1274 		    (size_t *)0, NULL);
1275 bad:
1276 	if (error)
1277 		vput(vp);
1278 	return (error);
1279 }
1280 
1281 /*
1282  * Return target name of a symbolic link
1283  */
1284 int
1285 ext2fs_readlink(void *v)
1286 {
1287 	struct vop_readlink_args /* {
1288 		struct vnode *a_vp;
1289 		struct uio *a_uio;
1290 		kauth_cred_t a_cred;
1291 	} */ *ap = v;
1292 	struct vnode	*vp = ap->a_vp;
1293 	struct inode	*ip = VTOI(vp);
1294 	struct ufsmount	*ump = ip->i_ump;
1295 	int		isize;
1296 
1297 	isize = ext2fs_size(ip);
1298 	if (isize < ump->um_maxsymlinklen ||
1299 	    (ump->um_maxsymlinklen == 0 && ip->i_e2fs_nblock == 0)) {
1300 		uiomove((char *)ip->i_din.e2fs_din->e2di_shortlink, isize, ap->a_uio);
1301 		return (0);
1302 	}
1303 	return (VOP_READ(vp, ap->a_uio, 0, ap->a_cred));
1304 }
1305 
1306 /*
1307  * Advisory record locking support
1308  */
1309 int
1310 ext2fs_advlock(void *v)
1311 {
1312 	struct vop_advlock_args /* {
1313 		struct vnode *a_vp;
1314 		void * a_id;
1315 		int  a_op;
1316 		struct flock *a_fl;
1317 		int  a_flags;
1318 	} */ *ap = v;
1319 	struct inode *ip = VTOI(ap->a_vp);
1320 
1321 	return lf_advlock(ap, &ip->i_lockf, ext2fs_size(ip));
1322 }
1323 
1324 int
1325 ext2fs_fsync(void *v)
1326 {
1327 	struct vop_fsync_args /* {
1328 		struct vnode *a_vp;
1329 		kauth_cred_t a_cred;
1330 		int a_flags;
1331 		off_t offlo;
1332 		off_t offhi;
1333 		struct proc *a_p;
1334 	} */ *ap = v;
1335 	struct vnode *vp = ap->a_vp;
1336 	int wait;
1337 	int error;
1338 
1339 	wait = (ap->a_flags & FSYNC_WAIT) != 0;
1340 
1341 	if (vp->v_type == VBLK)
1342 		spec_fsync(v);
1343 	else
1344 		vflushbuf(vp, wait);
1345 	if ((ap->a_flags & FSYNC_DATAONLY) != 0)
1346 		error = 0;
1347 	else
1348 		error = ext2fs_update(vp, NULL, NULL, wait ? UPDATE_WAIT : 0);
1349 
1350 	if (error == 0 && ap->a_flags & FSYNC_CACHE) {
1351 		int l = 0;
1352 		error = VOP_IOCTL(VTOI(vp)->i_devvp, DIOCCACHESYNC, &l, FWRITE,
1353 		    curlwp->l_cred);
1354 	}
1355 
1356 	return error;
1357 }
1358 
1359 /*
1360  * Initialize the vnode associated with a new inode, handle aliased
1361  * vnodes.
1362  */
1363 int
1364 ext2fs_vinit(struct mount *mntp, int (**specops)(void *),
1365 	int (**fifoops)(void *), struct vnode **vpp)
1366 {
1367 	struct timeval tv;
1368 	struct inode *ip;
1369 	struct vnode *vp;
1370 
1371 	vp = *vpp;
1372 	ip = VTOI(vp);
1373 	switch(vp->v_type = IFTOVT(ip->i_e2fs_mode)) {
1374 	case VCHR:
1375 	case VBLK:
1376 		vp->v_op = specops;
1377 		spec_node_init(vp, fs2h32(ip->i_din.e2fs_din->e2di_rdev));
1378 		break;
1379 	case VFIFO:
1380 		vp->v_op = fifoops;
1381 		break;
1382 	case VNON:
1383 	case VBAD:
1384 	case VSOCK:
1385 	case VLNK:
1386 	case VDIR:
1387 	case VREG:
1388 		break;
1389 	}
1390 	if (ip->i_number == ROOTINO)
1391                 vp->v_vflag |= VV_ROOT;
1392 	/*
1393 	 * Initialize modrev times
1394 	 */
1395 	getmicrouptime(&tv);
1396 	SETHIGH(ip->i_modrev, tv.tv_sec);
1397 	SETLOW(ip->i_modrev, tv.tv_usec * 4294);
1398 	*vpp = vp;
1399 	return (0);
1400 }
1401 
1402 /*
1403  * Allocate a new inode.
1404  */
1405 int
1406 ext2fs_makeinode(int mode, struct vnode *dvp, struct vnode **vpp,
1407 		struct componentname *cnp)
1408 {
1409 	struct inode *ip, *pdir;
1410 	struct vnode *tvp;
1411 	int error, ismember = 0;
1412 
1413 	pdir = VTOI(dvp);
1414 	*vpp = NULL;
1415 	if ((mode & IFMT) == 0)
1416 		mode |= IFREG;
1417 
1418 	if ((error = ext2fs_valloc(dvp, mode, cnp->cn_cred, &tvp)) != 0) {
1419 		vput(dvp);
1420 		return (error);
1421 	}
1422 	ip = VTOI(tvp);
1423 	ip->i_uid = kauth_cred_geteuid(cnp->cn_cred);
1424 	ip->i_e2fs_uid = ip->i_uid & 0xffff;
1425 	ip->i_e2fs_gid = pdir->i_e2fs_gid;
1426 	if (ip->i_e2fs->e2fs.e2fs_rev > E2FS_REV0) {
1427 		ip->i_e2fs_uid_high = (ip->i_uid >> 16) & 0xffff;
1428 		ip->i_e2fs_gid_high = pdir->i_e2fs_gid_high;
1429 	} else {
1430 		ip->i_e2fs_uid_high = 0;
1431 		ip->i_e2fs_gid_high = 0;
1432 	}
1433 	ip->i_gid = ip->i_e2fs_gid | (ip->i_e2fs_gid_high << 16);
1434 	ip->i_flag |= IN_ACCESS | IN_CHANGE | IN_UPDATE;
1435 	ip->i_e2fs_mode = mode;
1436 	tvp->v_type = IFTOVT(mode);	/* Rest init'd in getnewvnode(). */
1437 	ip->i_e2fs_nlink = 1;
1438 	if ((ip->i_e2fs_mode & ISGID) && (kauth_cred_ismember_gid(cnp->cn_cred,
1439 	    ip->i_gid, &ismember) != 0 || !ismember) &&
1440 	    kauth_authorize_generic(cnp->cn_cred, KAUTH_GENERIC_ISSUSER, NULL))
1441 		ip->i_e2fs_mode &= ~ISGID;
1442 
1443 	/*
1444 	 * Make sure inode goes to disk before directory entry.
1445 	 */
1446 	if ((error = ext2fs_update(tvp, NULL, NULL, UPDATE_WAIT)) != 0)
1447 		goto bad;
1448 	error = ext2fs_direnter(ip, dvp, cnp);
1449 	if (error != 0)
1450 		goto bad;
1451 	vput(dvp);
1452 	*vpp = tvp;
1453 	return (0);
1454 
1455 bad:
1456 	/*
1457 	 * Write error occurred trying to update the inode
1458 	 * or the directory so must deallocate the inode.
1459 	 */
1460 	tvp->v_type = VNON;	/* Stop explosion if VBLK */
1461 	ip->i_e2fs_nlink = 0;
1462 	ip->i_flag |= IN_CHANGE;
1463 	vput(tvp);
1464 	vput(dvp);
1465 	return (error);
1466 }
1467 
1468 /*
1469  * Reclaim an inode so that it can be used for other purposes.
1470  */
1471 int
1472 ext2fs_reclaim(void *v)
1473 {
1474 	struct vop_reclaim_args /* {
1475 		struct vnode *a_vp;
1476 	} */ *ap = v;
1477 	struct vnode *vp = ap->a_vp;
1478 	struct inode *ip = VTOI(vp);
1479 	int error;
1480 
1481 	/*
1482 	 * The inode must be freed and updated before being removed
1483 	 * from its hash chain.  Other threads trying to gain a hold
1484 	 * on the inode will be stalled because it is locked (VI_XLOCK).
1485 	 */
1486 	if (ip->i_omode == 1 && (vp->v_mount->mnt_flag & MNT_RDONLY) == 0)
1487 		ext2fs_vfree(vp, ip->i_number, ip->i_e2fs_mode);
1488 	if ((error = ufs_reclaim(vp)) != 0)
1489 		return (error);
1490 	if (ip->i_din.e2fs_din != NULL)
1491 		pool_put(&ext2fs_dinode_pool, ip->i_din.e2fs_din);
1492 	genfs_node_destroy(vp);
1493 	pool_put(&ext2fs_inode_pool, vp->v_data);
1494 	vp->v_data = NULL;
1495 	return (0);
1496 }
1497 
1498 /* Global vfs data structures for ext2fs. */
1499 int (**ext2fs_vnodeop_p)(void *);
1500 const struct vnodeopv_entry_desc ext2fs_vnodeop_entries[] = {
1501 	{ &vop_default_desc, vn_default_error },
1502 	{ &vop_lookup_desc, ext2fs_lookup },		/* lookup */
1503 	{ &vop_create_desc, ext2fs_create },		/* create */
1504 	{ &vop_mknod_desc, ext2fs_mknod },		/* mknod */
1505 	{ &vop_open_desc, ext2fs_open },		/* open */
1506 	{ &vop_close_desc, ufs_close },			/* close */
1507 	{ &vop_access_desc, ext2fs_access },		/* access */
1508 	{ &vop_getattr_desc, ext2fs_getattr },		/* getattr */
1509 	{ &vop_setattr_desc, ext2fs_setattr },		/* setattr */
1510 	{ &vop_read_desc, ext2fs_read },		/* read */
1511 	{ &vop_write_desc, ext2fs_write },		/* write */
1512 	{ &vop_ioctl_desc, ufs_ioctl },			/* ioctl */
1513 	{ &vop_fcntl_desc, ufs_fcntl },			/* fcntl */
1514 	{ &vop_poll_desc, ufs_poll },			/* poll */
1515 	{ &vop_kqfilter_desc, genfs_kqfilter },		/* kqfilter */
1516 	{ &vop_revoke_desc, ufs_revoke },		/* revoke */
1517 	{ &vop_mmap_desc, ufs_mmap },			/* mmap */
1518 	{ &vop_fsync_desc, ext2fs_fsync },		/* fsync */
1519 	{ &vop_seek_desc, ufs_seek },			/* seek */
1520 	{ &vop_remove_desc, ext2fs_remove },		/* remove */
1521 	{ &vop_link_desc, ext2fs_link },		/* link */
1522 	{ &vop_rename_desc, ext2fs_rename },		/* rename */
1523 	{ &vop_mkdir_desc, ext2fs_mkdir },		/* mkdir */
1524 	{ &vop_rmdir_desc, ext2fs_rmdir },		/* rmdir */
1525 	{ &vop_symlink_desc, ext2fs_symlink },		/* symlink */
1526 	{ &vop_readdir_desc, ext2fs_readdir },		/* readdir */
1527 	{ &vop_readlink_desc, ext2fs_readlink },	/* readlink */
1528 	{ &vop_abortop_desc, ufs_abortop },		/* abortop */
1529 	{ &vop_inactive_desc, ext2fs_inactive },	/* inactive */
1530 	{ &vop_reclaim_desc, ext2fs_reclaim },		/* reclaim */
1531 	{ &vop_lock_desc, ufs_lock },			/* lock */
1532 	{ &vop_unlock_desc, ufs_unlock },		/* unlock */
1533 	{ &vop_bmap_desc, ext2fs_bmap },		/* bmap */
1534 	{ &vop_strategy_desc, ufs_strategy },		/* strategy */
1535 	{ &vop_print_desc, ufs_print },			/* print */
1536 	{ &vop_islocked_desc, ufs_islocked },		/* islocked */
1537 	{ &vop_pathconf_desc, ufs_pathconf },		/* pathconf */
1538 	{ &vop_advlock_desc, ext2fs_advlock },		/* advlock */
1539 	{ &vop_bwrite_desc, vn_bwrite },		/* bwrite */
1540 	{ &vop_getpages_desc, genfs_getpages },		/* getpages */
1541 	{ &vop_putpages_desc, genfs_putpages },		/* putpages */
1542 	{ NULL, NULL }
1543 };
1544 const struct vnodeopv_desc ext2fs_vnodeop_opv_desc =
1545 	{ &ext2fs_vnodeop_p, ext2fs_vnodeop_entries };
1546 
1547 int (**ext2fs_specop_p)(void *);
1548 const struct vnodeopv_entry_desc ext2fs_specop_entries[] = {
1549 	{ &vop_default_desc, vn_default_error },
1550 	{ &vop_lookup_desc, spec_lookup },		/* lookup */
1551 	{ &vop_create_desc, spec_create },		/* create */
1552 	{ &vop_mknod_desc, spec_mknod },		/* mknod */
1553 	{ &vop_open_desc, spec_open },			/* open */
1554 	{ &vop_close_desc, ufsspec_close },		/* close */
1555 	{ &vop_access_desc, ext2fs_access },		/* access */
1556 	{ &vop_getattr_desc, ext2fs_getattr },		/* getattr */
1557 	{ &vop_setattr_desc, ext2fs_setattr },		/* setattr */
1558 	{ &vop_read_desc, ufsspec_read },		/* read */
1559 	{ &vop_write_desc, ufsspec_write },		/* write */
1560 	{ &vop_ioctl_desc, spec_ioctl },		/* ioctl */
1561 	{ &vop_fcntl_desc, ufs_fcntl },			/* fcntl */
1562 	{ &vop_poll_desc, spec_poll },			/* poll */
1563 	{ &vop_kqfilter_desc, spec_kqfilter },		/* kqfilter */
1564 	{ &vop_revoke_desc, spec_revoke },		/* revoke */
1565 	{ &vop_mmap_desc, spec_mmap },			/* mmap */
1566 	{ &vop_fsync_desc, ext2fs_fsync },		/* fsync */
1567 	{ &vop_seek_desc, spec_seek },			/* seek */
1568 	{ &vop_remove_desc, spec_remove },		/* remove */
1569 	{ &vop_link_desc, spec_link },			/* link */
1570 	{ &vop_rename_desc, spec_rename },		/* rename */
1571 	{ &vop_mkdir_desc, spec_mkdir },		/* mkdir */
1572 	{ &vop_rmdir_desc, spec_rmdir },		/* rmdir */
1573 	{ &vop_symlink_desc, spec_symlink },		/* symlink */
1574 	{ &vop_readdir_desc, spec_readdir },		/* readdir */
1575 	{ &vop_readlink_desc, spec_readlink },		/* readlink */
1576 	{ &vop_abortop_desc, spec_abortop },		/* abortop */
1577 	{ &vop_inactive_desc, ext2fs_inactive },	/* inactive */
1578 	{ &vop_reclaim_desc, ext2fs_reclaim },		/* reclaim */
1579 	{ &vop_lock_desc, ufs_lock },			/* lock */
1580 	{ &vop_unlock_desc, ufs_unlock },		/* unlock */
1581 	{ &vop_bmap_desc, spec_bmap },			/* bmap */
1582 	{ &vop_strategy_desc, spec_strategy },		/* strategy */
1583 	{ &vop_print_desc, ufs_print },			/* print */
1584 	{ &vop_islocked_desc, ufs_islocked },		/* islocked */
1585 	{ &vop_pathconf_desc, spec_pathconf },		/* pathconf */
1586 	{ &vop_advlock_desc, spec_advlock },		/* advlock */
1587 	{ &vop_bwrite_desc, vn_bwrite },		/* bwrite */
1588 	{ &vop_getpages_desc, spec_getpages },		/* getpages */
1589 	{ &vop_putpages_desc, spec_putpages },		/* putpages */
1590 	{ NULL, NULL }
1591 };
1592 const struct vnodeopv_desc ext2fs_specop_opv_desc =
1593 	{ &ext2fs_specop_p, ext2fs_specop_entries };
1594 
1595 int (**ext2fs_fifoop_p)(void *);
1596 const struct vnodeopv_entry_desc ext2fs_fifoop_entries[] = {
1597 	{ &vop_default_desc, vn_default_error },
1598 	{ &vop_lookup_desc, vn_fifo_bypass },		/* lookup */
1599 	{ &vop_create_desc, vn_fifo_bypass },		/* create */
1600 	{ &vop_mknod_desc, vn_fifo_bypass },		/* mknod */
1601 	{ &vop_open_desc, vn_fifo_bypass },		/* open */
1602 	{ &vop_close_desc, ufsfifo_close },		/* close */
1603 	{ &vop_access_desc, ext2fs_access },		/* access */
1604 	{ &vop_getattr_desc, ext2fs_getattr },		/* getattr */
1605 	{ &vop_setattr_desc, ext2fs_setattr },		/* setattr */
1606 	{ &vop_read_desc, ufsfifo_read },		/* read */
1607 	{ &vop_write_desc, ufsfifo_write },		/* write */
1608 	{ &vop_ioctl_desc, vn_fifo_bypass },		/* ioctl */
1609 	{ &vop_fcntl_desc, ufs_fcntl },			/* fcntl */
1610 	{ &vop_poll_desc, vn_fifo_bypass },		/* poll */
1611 	{ &vop_kqfilter_desc, vn_fifo_bypass },		/* kqfilter */
1612 	{ &vop_revoke_desc, vn_fifo_bypass },		/* revoke */
1613 	{ &vop_mmap_desc, vn_fifo_bypass },		/* mmap */
1614 	{ &vop_fsync_desc, ext2fs_fsync },		/* fsync */
1615 	{ &vop_seek_desc, vn_fifo_bypass },		/* seek */
1616 	{ &vop_remove_desc, vn_fifo_bypass },		/* remove */
1617 	{ &vop_link_desc, vn_fifo_bypass },		/* link */
1618 	{ &vop_rename_desc, vn_fifo_bypass },		/* rename */
1619 	{ &vop_mkdir_desc, vn_fifo_bypass },		/* mkdir */
1620 	{ &vop_rmdir_desc, vn_fifo_bypass },		/* rmdir */
1621 	{ &vop_symlink_desc, vn_fifo_bypass },		/* symlink */
1622 	{ &vop_readdir_desc, vn_fifo_bypass },		/* readdir */
1623 	{ &vop_readlink_desc, vn_fifo_bypass },		/* readlink */
1624 	{ &vop_abortop_desc, vn_fifo_bypass },		/* abortop */
1625 	{ &vop_inactive_desc, ext2fs_inactive },	/* inactive */
1626 	{ &vop_reclaim_desc, ext2fs_reclaim },		/* reclaim */
1627 	{ &vop_lock_desc, ufs_lock },			/* lock */
1628 	{ &vop_unlock_desc, ufs_unlock },		/* unlock */
1629 	{ &vop_bmap_desc, vn_fifo_bypass },		/* bmap */
1630 	{ &vop_strategy_desc, vn_fifo_bypass },		/* strategy */
1631 	{ &vop_print_desc, ufs_print },			/* print */
1632 	{ &vop_islocked_desc, ufs_islocked },		/* islocked */
1633 	{ &vop_pathconf_desc, vn_fifo_bypass },		/* pathconf */
1634 	{ &vop_advlock_desc, vn_fifo_bypass },		/* advlock */
1635 	{ &vop_bwrite_desc, vn_bwrite },		/* bwrite */
1636 	{ &vop_putpages_desc, vn_fifo_bypass },		/* putpages */
1637 	{ NULL, NULL }
1638 };
1639 const struct vnodeopv_desc ext2fs_fifoop_opv_desc =
1640 	{ &ext2fs_fifoop_p, ext2fs_fifoop_entries };
1641