1789Sahrens /* 2789Sahrens * CDDL HEADER START 3789Sahrens * 4789Sahrens * The contents of this file are subject to the terms of the 51485Slling * Common Development and Distribution License (the "License"). 61485Slling * You may not use this file except in compliance with the License. 7789Sahrens * 8789Sahrens * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9789Sahrens * or http://www.opensolaris.org/os/licensing. 10789Sahrens * See the License for the specific language governing permissions 11789Sahrens * and limitations under the License. 12789Sahrens * 13789Sahrens * When distributing Covered Code, include this CDDL HEADER in each 14789Sahrens * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15789Sahrens * If applicable, add the following below this CDDL HEADER, with the 16789Sahrens * fields enclosed by brackets "[]" replaced with your own identifying 17789Sahrens * information: Portions Copyright [yyyy] [name of copyright owner] 18789Sahrens * 19789Sahrens * CDDL HEADER END 20789Sahrens */ 21789Sahrens /* 228525SEric.Schrock@Sun.COM * Copyright 2009 Sun Microsystems, Inc. All rights reserved. 23789Sahrens * Use is subject to license terms. 24789Sahrens */ 25789Sahrens 26789Sahrens #include <sys/types.h> 27789Sahrens #include <sys/param.h> 28789Sahrens #include <sys/errno.h> 29789Sahrens #include <sys/uio.h> 30789Sahrens #include <sys/buf.h> 31789Sahrens #include <sys/modctl.h> 32789Sahrens #include <sys/open.h> 33789Sahrens #include <sys/file.h> 34789Sahrens #include <sys/kmem.h> 35789Sahrens #include <sys/conf.h> 36789Sahrens #include <sys/cmn_err.h> 37789Sahrens #include <sys/stat.h> 38789Sahrens #include <sys/zfs_ioctl.h> 3910972SRic.Aleshire@Sun.COM #include <sys/zfs_vfsops.h> 405331Samw #include <sys/zfs_znode.h> 41789Sahrens #include <sys/zap.h> 42789Sahrens #include <sys/spa.h> 433912Slling #include <sys/spa_impl.h> 44789Sahrens #include <sys/vdev.h> 4510972SRic.Aleshire@Sun.COM #include <sys/priv_impl.h> 46789Sahrens #include <sys/dmu.h> 47789Sahrens #include <sys/dsl_dir.h> 48789Sahrens #include <sys/dsl_dataset.h> 49789Sahrens #include <sys/dsl_prop.h> 504543Smarks #include <sys/dsl_deleg.h> 514543Smarks #include <sys/dmu_objset.h> 52789Sahrens #include <sys/ddi.h> 53789Sahrens #include <sys/sunddi.h> 54789Sahrens #include <sys/sunldi.h> 55789Sahrens #include <sys/policy.h> 56789Sahrens #include <sys/zone.h> 57789Sahrens #include <sys/nvpair.h> 58789Sahrens #include <sys/pathname.h> 59789Sahrens #include <sys/mount.h> 60789Sahrens #include <sys/sdt.h> 61789Sahrens #include <sys/fs/zfs.h> 62789Sahrens #include <sys/zfs_ctldir.h> 635331Samw #include <sys/zfs_dir.h> 642885Sahrens #include <sys/zvol.h> 654543Smarks #include <sharefs/share.h> 665326Sek110237 #include <sys/dmu_objset.h> 67789Sahrens 68789Sahrens #include "zfs_namecheck.h" 692676Seschrock #include "zfs_prop.h" 704543Smarks #include "zfs_deleg.h" 71789Sahrens 72789Sahrens extern struct modlfs zfs_modlfs; 73789Sahrens 74789Sahrens extern void zfs_init(void); 75789Sahrens extern void zfs_fini(void); 76789Sahrens 77789Sahrens ldi_ident_t zfs_li = NULL; 78789Sahrens dev_info_t *zfs_dip; 79789Sahrens 80789Sahrens typedef int zfs_ioc_func_t(zfs_cmd_t *); 814543Smarks typedef int zfs_secpolicy_func_t(zfs_cmd_t *, cred_t *); 82789Sahrens 839234SGeorge.Wilson@Sun.COM typedef enum { 849234SGeorge.Wilson@Sun.COM NO_NAME, 859234SGeorge.Wilson@Sun.COM POOL_NAME, 869234SGeorge.Wilson@Sun.COM DATASET_NAME 879234SGeorge.Wilson@Sun.COM } zfs_ioc_namecheck_t; 889234SGeorge.Wilson@Sun.COM 89789Sahrens typedef struct zfs_ioc_vec { 90789Sahrens zfs_ioc_func_t *zvec_func; 91789Sahrens zfs_secpolicy_func_t *zvec_secpolicy; 929234SGeorge.Wilson@Sun.COM zfs_ioc_namecheck_t zvec_namecheck; 934543Smarks boolean_t zvec_his_log; 949234SGeorge.Wilson@Sun.COM boolean_t zvec_pool_check; 95789Sahrens } zfs_ioc_vec_t; 96789Sahrens 979396SMatthew.Ahrens@Sun.COM /* This array is indexed by zfs_userquota_prop_t */ 989396SMatthew.Ahrens@Sun.COM static const char *userquota_perms[] = { 999396SMatthew.Ahrens@Sun.COM ZFS_DELEG_PERM_USERUSED, 1009396SMatthew.Ahrens@Sun.COM ZFS_DELEG_PERM_USERQUOTA, 1019396SMatthew.Ahrens@Sun.COM ZFS_DELEG_PERM_GROUPUSED, 1029396SMatthew.Ahrens@Sun.COM ZFS_DELEG_PERM_GROUPQUOTA, 1039396SMatthew.Ahrens@Sun.COM }; 1049396SMatthew.Ahrens@Sun.COM 1059396SMatthew.Ahrens@Sun.COM static int zfs_ioc_userspace_upgrade(zfs_cmd_t *zc); 10611022STom.Erickson@Sun.COM static int zfs_check_settable(const char *name, nvpair_t *property, 10711022STom.Erickson@Sun.COM cred_t *cr); 10811022STom.Erickson@Sun.COM static int zfs_check_clearable(char *dataset, nvlist_t *props, 10911022STom.Erickson@Sun.COM nvlist_t **errors); 1107184Stimh static int zfs_fill_zplprops_root(uint64_t, nvlist_t *, nvlist_t *, 1117184Stimh boolean_t *); 11211022STom.Erickson@Sun.COM int zfs_set_prop_nvlist(const char *, zprop_source_t, nvlist_t *, nvlist_t **); 1137184Stimh 114789Sahrens /* _NOTE(PRINTFLIKE(4)) - this is printf-like, but lint is too whiney */ 115789Sahrens void 116789Sahrens __dprintf(const char *file, const char *func, int line, const char *fmt, ...) 117789Sahrens { 118789Sahrens const char *newfile; 119789Sahrens char buf[256]; 120789Sahrens va_list adx; 121789Sahrens 122789Sahrens /* 123789Sahrens * Get rid of annoying "../common/" prefix to filename. 124789Sahrens */ 125789Sahrens newfile = strrchr(file, '/'); 126789Sahrens if (newfile != NULL) { 127789Sahrens newfile = newfile + 1; /* Get rid of leading / */ 128789Sahrens } else { 129789Sahrens newfile = file; 130789Sahrens } 131789Sahrens 132789Sahrens va_start(adx, fmt); 133789Sahrens (void) vsnprintf(buf, sizeof (buf), fmt, adx); 134789Sahrens va_end(adx); 135789Sahrens 136789Sahrens /* 137789Sahrens * To get this data, use the zfs-dprintf probe as so: 138789Sahrens * dtrace -q -n 'zfs-dprintf \ 139789Sahrens * /stringof(arg0) == "dbuf.c"/ \ 140789Sahrens * {printf("%s: %s", stringof(arg1), stringof(arg3))}' 141789Sahrens * arg0 = file name 142789Sahrens * arg1 = function name 143789Sahrens * arg2 = line number 144789Sahrens * arg3 = message 145789Sahrens */ 146789Sahrens DTRACE_PROBE4(zfs__dprintf, 147789Sahrens char *, newfile, char *, func, int, line, char *, buf); 148789Sahrens } 149789Sahrens 1504543Smarks static void 1514715Sek110237 history_str_free(char *buf) 1524715Sek110237 { 1534715Sek110237 kmem_free(buf, HIS_MAX_RECORD_LEN); 1544715Sek110237 } 1554715Sek110237 1564715Sek110237 static char * 1574715Sek110237 history_str_get(zfs_cmd_t *zc) 1584715Sek110237 { 1594715Sek110237 char *buf; 1604715Sek110237 1614715Sek110237 if (zc->zc_history == NULL) 1624715Sek110237 return (NULL); 1634715Sek110237 1644715Sek110237 buf = kmem_alloc(HIS_MAX_RECORD_LEN, KM_SLEEP); 1654715Sek110237 if (copyinstr((void *)(uintptr_t)zc->zc_history, 1664715Sek110237 buf, HIS_MAX_RECORD_LEN, NULL) != 0) { 1674715Sek110237 history_str_free(buf); 1684715Sek110237 return (NULL); 1694715Sek110237 } 1704715Sek110237 1714715Sek110237 buf[HIS_MAX_RECORD_LEN -1] = '\0'; 1724715Sek110237 1734715Sek110237 return (buf); 1744715Sek110237 } 1754715Sek110237 1765375Stimh /* 1777042Sgw25295 * Check to see if the named dataset is currently defined as bootable 1787042Sgw25295 */ 1797042Sgw25295 static boolean_t 1807042Sgw25295 zfs_is_bootfs(const char *name) 1817042Sgw25295 { 18210298SMatthew.Ahrens@Sun.COM objset_t *os; 18310298SMatthew.Ahrens@Sun.COM 18410298SMatthew.Ahrens@Sun.COM if (dmu_objset_hold(name, FTAG, &os) == 0) { 18510298SMatthew.Ahrens@Sun.COM boolean_t ret; 18610922SJeff.Bonwick@Sun.COM ret = (dmu_objset_id(os) == spa_bootfs(dmu_objset_spa(os))); 18710298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 18810298SMatthew.Ahrens@Sun.COM return (ret); 1897042Sgw25295 } 19010298SMatthew.Ahrens@Sun.COM return (B_FALSE); 1917042Sgw25295 } 1927042Sgw25295 1937042Sgw25295 /* 1947184Stimh * zfs_earlier_version 1955375Stimh * 1965375Stimh * Return non-zero if the spa version is less than requested version. 1975375Stimh */ 1985331Samw static int 1997184Stimh zfs_earlier_version(const char *name, int version) 2005331Samw { 2015331Samw spa_t *spa; 2025331Samw 2035331Samw if (spa_open(name, &spa, FTAG) == 0) { 2045331Samw if (spa_version(spa) < version) { 2055331Samw spa_close(spa, FTAG); 2065331Samw return (1); 2075331Samw } 2085331Samw spa_close(spa, FTAG); 2095331Samw } 2105331Samw return (0); 2115331Samw } 2125331Samw 2135977Smarks /* 2146689Smaybee * zpl_earlier_version 2155977Smarks * 2166689Smaybee * Return TRUE if the ZPL version is less than requested version. 2175977Smarks */ 2186689Smaybee static boolean_t 2196689Smaybee zpl_earlier_version(const char *name, int version) 2205977Smarks { 2215977Smarks objset_t *os; 2226689Smaybee boolean_t rc = B_TRUE; 2235977Smarks 22410298SMatthew.Ahrens@Sun.COM if (dmu_objset_hold(name, FTAG, &os) == 0) { 2256689Smaybee uint64_t zplversion; 2266689Smaybee 22710298SMatthew.Ahrens@Sun.COM if (dmu_objset_type(os) != DMU_OST_ZFS) { 22810298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 22910298SMatthew.Ahrens@Sun.COM return (B_TRUE); 23010298SMatthew.Ahrens@Sun.COM } 23110298SMatthew.Ahrens@Sun.COM /* XXX reading from non-owned objset */ 2326689Smaybee if (zfs_get_zplprop(os, ZFS_PROP_VERSION, &zplversion) == 0) 2336689Smaybee rc = zplversion < version; 23410298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 2355977Smarks } 2365977Smarks return (rc); 2375977Smarks } 2385977Smarks 2394715Sek110237 static void 2404543Smarks zfs_log_history(zfs_cmd_t *zc) 2414543Smarks { 2424543Smarks spa_t *spa; 2434603Sahrens char *buf; 2444543Smarks 2454715Sek110237 if ((buf = history_str_get(zc)) == NULL) 2464577Sahrens return; 2474577Sahrens 2484715Sek110237 if (spa_open(zc->zc_name, &spa, FTAG) == 0) { 2494715Sek110237 if (spa_version(spa) >= SPA_VERSION_ZPOOL_HISTORY) 2504715Sek110237 (void) spa_history_log(spa, buf, LOG_CMD_NORMAL); 2514715Sek110237 spa_close(spa, FTAG); 2524543Smarks } 2534715Sek110237 history_str_free(buf); 2544543Smarks } 2554543Smarks 256789Sahrens /* 257789Sahrens * Policy for top-level read operations (list pools). Requires no privileges, 258789Sahrens * and can be used in the local zone, as there is no associated dataset. 259789Sahrens */ 260789Sahrens /* ARGSUSED */ 261789Sahrens static int 2624543Smarks zfs_secpolicy_none(zfs_cmd_t *zc, cred_t *cr) 263789Sahrens { 264789Sahrens return (0); 265789Sahrens } 266789Sahrens 267789Sahrens /* 268789Sahrens * Policy for dataset read operations (list children, get statistics). Requires 269789Sahrens * no privileges, but must be visible in the local zone. 270789Sahrens */ 271789Sahrens /* ARGSUSED */ 272789Sahrens static int 2734543Smarks zfs_secpolicy_read(zfs_cmd_t *zc, cred_t *cr) 274789Sahrens { 275789Sahrens if (INGLOBALZONE(curproc) || 2764543Smarks zone_dataset_visible(zc->zc_name, NULL)) 277789Sahrens return (0); 278789Sahrens 279789Sahrens return (ENOENT); 280789Sahrens } 281789Sahrens 282789Sahrens static int 283789Sahrens zfs_dozonecheck(const char *dataset, cred_t *cr) 284789Sahrens { 285789Sahrens uint64_t zoned; 286789Sahrens int writable = 1; 287789Sahrens 288789Sahrens /* 289789Sahrens * The dataset must be visible by this zone -- check this first 290789Sahrens * so they don't see EPERM on something they shouldn't know about. 291789Sahrens */ 292789Sahrens if (!INGLOBALZONE(curproc) && 293789Sahrens !zone_dataset_visible(dataset, &writable)) 294789Sahrens return (ENOENT); 295789Sahrens 296789Sahrens if (dsl_prop_get_integer(dataset, "zoned", &zoned, NULL)) 297789Sahrens return (ENOENT); 298789Sahrens 299789Sahrens if (INGLOBALZONE(curproc)) { 300789Sahrens /* 301789Sahrens * If the fs is zoned, only root can access it from the 302789Sahrens * global zone. 303789Sahrens */ 304789Sahrens if (secpolicy_zfs(cr) && zoned) 305789Sahrens return (EPERM); 306789Sahrens } else { 307789Sahrens /* 308789Sahrens * If we are in a local zone, the 'zoned' property must be set. 309789Sahrens */ 310789Sahrens if (!zoned) 311789Sahrens return (EPERM); 312789Sahrens 313789Sahrens /* must be writable by this zone */ 314789Sahrens if (!writable) 315789Sahrens return (EPERM); 316789Sahrens } 317789Sahrens return (0); 318789Sahrens } 319789Sahrens 320789Sahrens int 3214543Smarks zfs_secpolicy_write_perms(const char *name, const char *perm, cred_t *cr) 322789Sahrens { 323789Sahrens int error; 324789Sahrens 3254543Smarks error = zfs_dozonecheck(name, cr); 3264543Smarks if (error == 0) { 3274543Smarks error = secpolicy_zfs(cr); 3284670Sahrens if (error) 3294543Smarks error = dsl_deleg_access(name, perm, cr); 3304543Smarks } 3314543Smarks return (error); 3324543Smarks } 3334543Smarks 33410972SRic.Aleshire@Sun.COM /* 33510972SRic.Aleshire@Sun.COM * Policy for setting the security label property. 33610972SRic.Aleshire@Sun.COM * 33710972SRic.Aleshire@Sun.COM * Returns 0 for success, non-zero for access and other errors. 33810972SRic.Aleshire@Sun.COM */ 33910972SRic.Aleshire@Sun.COM static int 34011022STom.Erickson@Sun.COM zfs_set_slabel_policy(const char *name, char *strval, cred_t *cr) 34110972SRic.Aleshire@Sun.COM { 34210972SRic.Aleshire@Sun.COM char ds_hexsl[MAXNAMELEN]; 34310972SRic.Aleshire@Sun.COM bslabel_t ds_sl, new_sl; 34410972SRic.Aleshire@Sun.COM boolean_t new_default = FALSE; 34510972SRic.Aleshire@Sun.COM uint64_t zoned; 34610972SRic.Aleshire@Sun.COM int needed_priv = -1; 34710972SRic.Aleshire@Sun.COM int error; 34810972SRic.Aleshire@Sun.COM 34910972SRic.Aleshire@Sun.COM /* First get the existing dataset label. */ 35010972SRic.Aleshire@Sun.COM error = dsl_prop_get(name, zfs_prop_to_name(ZFS_PROP_MLSLABEL), 35110972SRic.Aleshire@Sun.COM 1, sizeof (ds_hexsl), &ds_hexsl, NULL); 35210972SRic.Aleshire@Sun.COM if (error) 35310972SRic.Aleshire@Sun.COM return (EPERM); 35410972SRic.Aleshire@Sun.COM 35510972SRic.Aleshire@Sun.COM if (strcasecmp(strval, ZFS_MLSLABEL_DEFAULT) == 0) 35610972SRic.Aleshire@Sun.COM new_default = TRUE; 35710972SRic.Aleshire@Sun.COM 35810972SRic.Aleshire@Sun.COM /* The label must be translatable */ 35910972SRic.Aleshire@Sun.COM if (!new_default && (hexstr_to_label(strval, &new_sl) != 0)) 36010972SRic.Aleshire@Sun.COM return (EINVAL); 36110972SRic.Aleshire@Sun.COM 36210972SRic.Aleshire@Sun.COM /* 36310972SRic.Aleshire@Sun.COM * In a non-global zone, disallow attempts to set a label that 36410972SRic.Aleshire@Sun.COM * doesn't match that of the zone; otherwise no other checks 36510972SRic.Aleshire@Sun.COM * are needed. 36610972SRic.Aleshire@Sun.COM */ 36710972SRic.Aleshire@Sun.COM if (!INGLOBALZONE(curproc)) { 36810972SRic.Aleshire@Sun.COM if (new_default || !blequal(&new_sl, CR_SL(CRED()))) 36910972SRic.Aleshire@Sun.COM return (EPERM); 37010972SRic.Aleshire@Sun.COM return (0); 37110972SRic.Aleshire@Sun.COM } 37210972SRic.Aleshire@Sun.COM 37310972SRic.Aleshire@Sun.COM /* 37410972SRic.Aleshire@Sun.COM * For global-zone datasets (i.e., those whose zoned property is 37510972SRic.Aleshire@Sun.COM * "off", verify that the specified new label is valid for the 37610972SRic.Aleshire@Sun.COM * global zone. 37710972SRic.Aleshire@Sun.COM */ 37810972SRic.Aleshire@Sun.COM if (dsl_prop_get_integer(name, 37910972SRic.Aleshire@Sun.COM zfs_prop_to_name(ZFS_PROP_ZONED), &zoned, NULL)) 38010972SRic.Aleshire@Sun.COM return (EPERM); 38110972SRic.Aleshire@Sun.COM if (!zoned) { 38210972SRic.Aleshire@Sun.COM if (zfs_check_global_label(name, strval) != 0) 38310972SRic.Aleshire@Sun.COM return (EPERM); 38410972SRic.Aleshire@Sun.COM } 38510972SRic.Aleshire@Sun.COM 38610972SRic.Aleshire@Sun.COM /* 38710972SRic.Aleshire@Sun.COM * If the existing dataset label is nondefault, check if the 38810972SRic.Aleshire@Sun.COM * dataset is mounted (label cannot be changed while mounted). 38910972SRic.Aleshire@Sun.COM * Get the zfsvfs; if there isn't one, then the dataset isn't 39010972SRic.Aleshire@Sun.COM * mounted (or isn't a dataset, doesn't exist, ...). 39110972SRic.Aleshire@Sun.COM */ 39210972SRic.Aleshire@Sun.COM if (strcasecmp(ds_hexsl, ZFS_MLSLABEL_DEFAULT) != 0) { 39311022STom.Erickson@Sun.COM objset_t *os; 39411022STom.Erickson@Sun.COM static char *setsl_tag = "setsl_tag"; 39511022STom.Erickson@Sun.COM 39610972SRic.Aleshire@Sun.COM /* 39710972SRic.Aleshire@Sun.COM * Try to own the dataset; abort if there is any error, 39810972SRic.Aleshire@Sun.COM * (e.g., already mounted, in use, or other error). 39910972SRic.Aleshire@Sun.COM */ 40010972SRic.Aleshire@Sun.COM error = dmu_objset_own(name, DMU_OST_ZFS, B_TRUE, 40111022STom.Erickson@Sun.COM setsl_tag, &os); 40210972SRic.Aleshire@Sun.COM if (error) 40310972SRic.Aleshire@Sun.COM return (EPERM); 40410972SRic.Aleshire@Sun.COM 40511022STom.Erickson@Sun.COM dmu_objset_disown(os, setsl_tag); 40611022STom.Erickson@Sun.COM 40710972SRic.Aleshire@Sun.COM if (new_default) { 40810972SRic.Aleshire@Sun.COM needed_priv = PRIV_FILE_DOWNGRADE_SL; 40910972SRic.Aleshire@Sun.COM goto out_check; 41010972SRic.Aleshire@Sun.COM } 41110972SRic.Aleshire@Sun.COM 41210972SRic.Aleshire@Sun.COM if (hexstr_to_label(strval, &new_sl) != 0) 41310972SRic.Aleshire@Sun.COM return (EPERM); 41410972SRic.Aleshire@Sun.COM 41510972SRic.Aleshire@Sun.COM if (blstrictdom(&ds_sl, &new_sl)) 41610972SRic.Aleshire@Sun.COM needed_priv = PRIV_FILE_DOWNGRADE_SL; 41710972SRic.Aleshire@Sun.COM else if (blstrictdom(&new_sl, &ds_sl)) 41810972SRic.Aleshire@Sun.COM needed_priv = PRIV_FILE_UPGRADE_SL; 41910972SRic.Aleshire@Sun.COM } else { 42010972SRic.Aleshire@Sun.COM /* dataset currently has a default label */ 42110972SRic.Aleshire@Sun.COM if (!new_default) 42210972SRic.Aleshire@Sun.COM needed_priv = PRIV_FILE_UPGRADE_SL; 42310972SRic.Aleshire@Sun.COM } 42410972SRic.Aleshire@Sun.COM 42510972SRic.Aleshire@Sun.COM out_check: 42610972SRic.Aleshire@Sun.COM if (needed_priv != -1) 42710972SRic.Aleshire@Sun.COM return (PRIV_POLICY(cr, needed_priv, B_FALSE, EPERM, NULL)); 42810972SRic.Aleshire@Sun.COM return (0); 42910972SRic.Aleshire@Sun.COM } 43010972SRic.Aleshire@Sun.COM 4314543Smarks static int 43211022STom.Erickson@Sun.COM zfs_secpolicy_setprop(const char *dsname, zfs_prop_t prop, nvpair_t *propval, 43311022STom.Erickson@Sun.COM cred_t *cr) 4344543Smarks { 43511022STom.Erickson@Sun.COM char *strval; 43611022STom.Erickson@Sun.COM 4374543Smarks /* 4384543Smarks * Check permissions for special properties. 4394543Smarks */ 4404543Smarks switch (prop) { 4414543Smarks case ZFS_PROP_ZONED: 4424543Smarks /* 4434543Smarks * Disallow setting of 'zoned' from within a local zone. 4444543Smarks */ 4454543Smarks if (!INGLOBALZONE(curproc)) 4464543Smarks return (EPERM); 4474543Smarks break; 448789Sahrens 4494543Smarks case ZFS_PROP_QUOTA: 4504543Smarks if (!INGLOBALZONE(curproc)) { 4514543Smarks uint64_t zoned; 4524543Smarks char setpoint[MAXNAMELEN]; 4534543Smarks /* 4544543Smarks * Unprivileged users are allowed to modify the 4554543Smarks * quota on things *under* (ie. contained by) 4564543Smarks * the thing they own. 4574543Smarks */ 45811022STom.Erickson@Sun.COM if (dsl_prop_get_integer(dsname, "zoned", &zoned, 4594543Smarks setpoint)) 4604543Smarks return (EPERM); 46111022STom.Erickson@Sun.COM if (!zoned || strlen(dsname) <= strlen(setpoint)) 4624543Smarks return (EPERM); 4634543Smarks } 4644670Sahrens break; 46510972SRic.Aleshire@Sun.COM 46610972SRic.Aleshire@Sun.COM case ZFS_PROP_MLSLABEL: 46710972SRic.Aleshire@Sun.COM if (!is_system_labeled()) 46810972SRic.Aleshire@Sun.COM return (EPERM); 46911022STom.Erickson@Sun.COM 47011022STom.Erickson@Sun.COM if (nvpair_value_string(propval, &strval) == 0) { 47111022STom.Erickson@Sun.COM int err; 47211022STom.Erickson@Sun.COM 47311022STom.Erickson@Sun.COM err = zfs_set_slabel_policy(dsname, strval, CRED()); 47411022STom.Erickson@Sun.COM if (err != 0) 47511022STom.Erickson@Sun.COM return (err); 47611022STom.Erickson@Sun.COM } 47710972SRic.Aleshire@Sun.COM break; 4784543Smarks } 4794543Smarks 48011022STom.Erickson@Sun.COM return (zfs_secpolicy_write_perms(dsname, zfs_prop_to_name(prop), cr)); 481789Sahrens } 482789Sahrens 4834543Smarks int 4844543Smarks zfs_secpolicy_fsacl(zfs_cmd_t *zc, cred_t *cr) 4854543Smarks { 4864543Smarks int error; 4874543Smarks 4884543Smarks error = zfs_dozonecheck(zc->zc_name, cr); 4894543Smarks if (error) 4904543Smarks return (error); 4914543Smarks 4924543Smarks /* 4934543Smarks * permission to set permissions will be evaluated later in 4944543Smarks * dsl_deleg_can_allow() 4954543Smarks */ 4964543Smarks return (0); 4974543Smarks } 4984543Smarks 4994543Smarks int 5004543Smarks zfs_secpolicy_rollback(zfs_cmd_t *zc, cred_t *cr) 5014543Smarks { 50210588SEric.Taylor@Sun.COM return (zfs_secpolicy_write_perms(zc->zc_name, 50310588SEric.Taylor@Sun.COM ZFS_DELEG_PERM_ROLLBACK, cr)); 5044543Smarks } 5054543Smarks 5064543Smarks int 5074543Smarks zfs_secpolicy_send(zfs_cmd_t *zc, cred_t *cr) 5084543Smarks { 5094543Smarks return (zfs_secpolicy_write_perms(zc->zc_name, 5104543Smarks ZFS_DELEG_PERM_SEND, cr)); 5114543Smarks } 5124543Smarks 5138845Samw@Sun.COM static int 5148845Samw@Sun.COM zfs_secpolicy_deleg_share(zfs_cmd_t *zc, cred_t *cr) 5158845Samw@Sun.COM { 5168845Samw@Sun.COM vnode_t *vp; 5178845Samw@Sun.COM int error; 5188845Samw@Sun.COM 5198845Samw@Sun.COM if ((error = lookupname(zc->zc_value, UIO_SYSSPACE, 5208845Samw@Sun.COM NO_FOLLOW, NULL, &vp)) != 0) 5218845Samw@Sun.COM return (error); 5228845Samw@Sun.COM 5238845Samw@Sun.COM /* Now make sure mntpnt and dataset are ZFS */ 5248845Samw@Sun.COM 5258845Samw@Sun.COM if (vp->v_vfsp->vfs_fstype != zfsfstype || 5268845Samw@Sun.COM (strcmp((char *)refstr_value(vp->v_vfsp->vfs_resource), 5278845Samw@Sun.COM zc->zc_name) != 0)) { 5288845Samw@Sun.COM VN_RELE(vp); 5298845Samw@Sun.COM return (EPERM); 5308845Samw@Sun.COM } 5318845Samw@Sun.COM 5328845Samw@Sun.COM VN_RELE(vp); 5338845Samw@Sun.COM return (dsl_deleg_access(zc->zc_name, 5348845Samw@Sun.COM ZFS_DELEG_PERM_SHARE, cr)); 5358845Samw@Sun.COM } 5368845Samw@Sun.COM 5374543Smarks int 5384543Smarks zfs_secpolicy_share(zfs_cmd_t *zc, cred_t *cr) 5394543Smarks { 5404543Smarks if (!INGLOBALZONE(curproc)) 5414543Smarks return (EPERM); 5424543Smarks 5435367Sahrens if (secpolicy_nfs(cr) == 0) { 5444543Smarks return (0); 5454543Smarks } else { 5468845Samw@Sun.COM return (zfs_secpolicy_deleg_share(zc, cr)); 5478845Samw@Sun.COM } 5488845Samw@Sun.COM } 5498845Samw@Sun.COM 5508845Samw@Sun.COM int 5518845Samw@Sun.COM zfs_secpolicy_smb_acl(zfs_cmd_t *zc, cred_t *cr) 5528845Samw@Sun.COM { 5538845Samw@Sun.COM if (!INGLOBALZONE(curproc)) 5548845Samw@Sun.COM return (EPERM); 5558845Samw@Sun.COM 5568845Samw@Sun.COM if (secpolicy_smb(cr) == 0) { 5578845Samw@Sun.COM return (0); 5588845Samw@Sun.COM } else { 5598845Samw@Sun.COM return (zfs_secpolicy_deleg_share(zc, cr)); 5604543Smarks } 5614543Smarks } 5624543Smarks 563789Sahrens static int 5644543Smarks zfs_get_parent(const char *datasetname, char *parent, int parentsize) 565789Sahrens { 566789Sahrens char *cp; 567789Sahrens 568789Sahrens /* 569789Sahrens * Remove the @bla or /bla from the end of the name to get the parent. 570789Sahrens */ 5714543Smarks (void) strncpy(parent, datasetname, parentsize); 5724543Smarks cp = strrchr(parent, '@'); 573789Sahrens if (cp != NULL) { 574789Sahrens cp[0] = '\0'; 575789Sahrens } else { 5764543Smarks cp = strrchr(parent, '/'); 577789Sahrens if (cp == NULL) 578789Sahrens return (ENOENT); 579789Sahrens cp[0] = '\0'; 580789Sahrens } 581789Sahrens 5824543Smarks return (0); 5834543Smarks } 5844543Smarks 5854543Smarks int 5864543Smarks zfs_secpolicy_destroy_perms(const char *name, cred_t *cr) 5874543Smarks { 5884543Smarks int error; 5894543Smarks 5904543Smarks if ((error = zfs_secpolicy_write_perms(name, 5914543Smarks ZFS_DELEG_PERM_MOUNT, cr)) != 0) 5924543Smarks return (error); 5934543Smarks 5944543Smarks return (zfs_secpolicy_write_perms(name, ZFS_DELEG_PERM_DESTROY, cr)); 5954543Smarks } 5964543Smarks 5974543Smarks static int 5984543Smarks zfs_secpolicy_destroy(zfs_cmd_t *zc, cred_t *cr) 5994543Smarks { 6004543Smarks return (zfs_secpolicy_destroy_perms(zc->zc_name, cr)); 6014543Smarks } 6024543Smarks 6034543Smarks /* 604*11314Swilliam.gorrell@sun.com * Destroying snapshots with delegated permissions requires 605*11314Swilliam.gorrell@sun.com * descendent mount and destroy permissions. 606*11314Swilliam.gorrell@sun.com * Reassemble the full filesystem@snap name so dsl_deleg_access() 607*11314Swilliam.gorrell@sun.com * can do the correct permission check. 608*11314Swilliam.gorrell@sun.com * 609*11314Swilliam.gorrell@sun.com * Since this routine is used when doing a recursive destroy of snapshots 610*11314Swilliam.gorrell@sun.com * and destroying snapshots requires descendent permissions, a successfull 611*11314Swilliam.gorrell@sun.com * check of the top level snapshot applies to snapshots of all descendent 612*11314Swilliam.gorrell@sun.com * datasets as well. 613*11314Swilliam.gorrell@sun.com */ 614*11314Swilliam.gorrell@sun.com static int 615*11314Swilliam.gorrell@sun.com zfs_secpolicy_destroy_snaps(zfs_cmd_t *zc, cred_t *cr) 616*11314Swilliam.gorrell@sun.com { 617*11314Swilliam.gorrell@sun.com int error; 618*11314Swilliam.gorrell@sun.com char *dsname; 619*11314Swilliam.gorrell@sun.com 620*11314Swilliam.gorrell@sun.com dsname = kmem_asprintf("%s@%s", zc->zc_name, zc->zc_value); 621*11314Swilliam.gorrell@sun.com 622*11314Swilliam.gorrell@sun.com error = zfs_secpolicy_destroy_perms(dsname, cr); 623*11314Swilliam.gorrell@sun.com 624*11314Swilliam.gorrell@sun.com strfree(dsname); 625*11314Swilliam.gorrell@sun.com return (error); 626*11314Swilliam.gorrell@sun.com } 627*11314Swilliam.gorrell@sun.com 628*11314Swilliam.gorrell@sun.com /* 6294543Smarks * Must have sys_config privilege to check the iscsi permission 6304543Smarks */ 6314543Smarks /* ARGSUSED */ 6324543Smarks static int 6334543Smarks zfs_secpolicy_iscsi(zfs_cmd_t *zc, cred_t *cr) 6344543Smarks { 6354543Smarks return (secpolicy_zfs(cr)); 6364543Smarks } 6374543Smarks 6384543Smarks int 6394543Smarks zfs_secpolicy_rename_perms(const char *from, const char *to, cred_t *cr) 6404543Smarks { 64111022STom.Erickson@Sun.COM char parentname[MAXNAMELEN]; 6424543Smarks int error; 6434543Smarks 6444543Smarks if ((error = zfs_secpolicy_write_perms(from, 6454543Smarks ZFS_DELEG_PERM_RENAME, cr)) != 0) 6464543Smarks return (error); 6474543Smarks 6484543Smarks if ((error = zfs_secpolicy_write_perms(from, 6494543Smarks ZFS_DELEG_PERM_MOUNT, cr)) != 0) 6504543Smarks return (error); 6514543Smarks 6524543Smarks if ((error = zfs_get_parent(to, parentname, 6534543Smarks sizeof (parentname))) != 0) 6544543Smarks return (error); 6554543Smarks 6564543Smarks if ((error = zfs_secpolicy_write_perms(parentname, 6574543Smarks ZFS_DELEG_PERM_CREATE, cr)) != 0) 6584543Smarks return (error); 6594543Smarks 6604543Smarks if ((error = zfs_secpolicy_write_perms(parentname, 6614543Smarks ZFS_DELEG_PERM_MOUNT, cr)) != 0) 6624543Smarks return (error); 6634543Smarks 6644543Smarks return (error); 6654543Smarks } 6664543Smarks 6674543Smarks static int 6684543Smarks zfs_secpolicy_rename(zfs_cmd_t *zc, cred_t *cr) 6694543Smarks { 6704543Smarks return (zfs_secpolicy_rename_perms(zc->zc_name, zc->zc_value, cr)); 6714543Smarks } 6724543Smarks 6734543Smarks static int 6744543Smarks zfs_secpolicy_promote(zfs_cmd_t *zc, cred_t *cr) 6754543Smarks { 67611022STom.Erickson@Sun.COM char parentname[MAXNAMELEN]; 6774543Smarks objset_t *clone; 6784543Smarks int error; 6794543Smarks 6804543Smarks error = zfs_secpolicy_write_perms(zc->zc_name, 6814543Smarks ZFS_DELEG_PERM_PROMOTE, cr); 6824543Smarks if (error) 6834543Smarks return (error); 6844543Smarks 68510298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_name, FTAG, &clone); 6864543Smarks 6874543Smarks if (error == 0) { 6884543Smarks dsl_dataset_t *pclone = NULL; 6894543Smarks dsl_dir_t *dd; 69010298SMatthew.Ahrens@Sun.COM dd = clone->os_dsl_dataset->ds_dir; 6914543Smarks 6924543Smarks rw_enter(&dd->dd_pool->dp_config_rwlock, RW_READER); 6936689Smaybee error = dsl_dataset_hold_obj(dd->dd_pool, 6946689Smaybee dd->dd_phys->dd_origin_obj, FTAG, &pclone); 6954543Smarks rw_exit(&dd->dd_pool->dp_config_rwlock); 6964543Smarks if (error) { 69710298SMatthew.Ahrens@Sun.COM dmu_objset_rele(clone, FTAG); 6984543Smarks return (error); 6994543Smarks } 7004543Smarks 7014543Smarks error = zfs_secpolicy_write_perms(zc->zc_name, 7024543Smarks ZFS_DELEG_PERM_MOUNT, cr); 7034543Smarks 7044543Smarks dsl_dataset_name(pclone, parentname); 70510298SMatthew.Ahrens@Sun.COM dmu_objset_rele(clone, FTAG); 7066689Smaybee dsl_dataset_rele(pclone, FTAG); 7074543Smarks if (error == 0) 7084543Smarks error = zfs_secpolicy_write_perms(parentname, 7094543Smarks ZFS_DELEG_PERM_PROMOTE, cr); 7104543Smarks } 7114543Smarks return (error); 7124543Smarks } 7134543Smarks 7144543Smarks static int 7154543Smarks zfs_secpolicy_receive(zfs_cmd_t *zc, cred_t *cr) 7164543Smarks { 7174543Smarks int error; 7184543Smarks 7194543Smarks if ((error = zfs_secpolicy_write_perms(zc->zc_name, 7204543Smarks ZFS_DELEG_PERM_RECEIVE, cr)) != 0) 7214543Smarks return (error); 7224543Smarks 7234543Smarks if ((error = zfs_secpolicy_write_perms(zc->zc_name, 7244543Smarks ZFS_DELEG_PERM_MOUNT, cr)) != 0) 7254543Smarks return (error); 7264543Smarks 7274543Smarks return (zfs_secpolicy_write_perms(zc->zc_name, 7284543Smarks ZFS_DELEG_PERM_CREATE, cr)); 7294543Smarks } 7304543Smarks 7314543Smarks int 7324543Smarks zfs_secpolicy_snapshot_perms(const char *name, cred_t *cr) 7334543Smarks { 73410588SEric.Taylor@Sun.COM return (zfs_secpolicy_write_perms(name, 73510588SEric.Taylor@Sun.COM ZFS_DELEG_PERM_SNAPSHOT, cr)); 7364543Smarks } 7374543Smarks 7384543Smarks static int 7394543Smarks zfs_secpolicy_snapshot(zfs_cmd_t *zc, cred_t *cr) 7404543Smarks { 7414543Smarks 7424543Smarks return (zfs_secpolicy_snapshot_perms(zc->zc_name, cr)); 7434543Smarks } 7444543Smarks 7454543Smarks static int 7464543Smarks zfs_secpolicy_create(zfs_cmd_t *zc, cred_t *cr) 7474543Smarks { 74811022STom.Erickson@Sun.COM char parentname[MAXNAMELEN]; 74911022STom.Erickson@Sun.COM int error; 7504543Smarks 7514543Smarks if ((error = zfs_get_parent(zc->zc_name, parentname, 7524543Smarks sizeof (parentname))) != 0) 7534543Smarks return (error); 7544543Smarks 7554543Smarks if (zc->zc_value[0] != '\0') { 7564543Smarks if ((error = zfs_secpolicy_write_perms(zc->zc_value, 7574543Smarks ZFS_DELEG_PERM_CLONE, cr)) != 0) 7584543Smarks return (error); 7594543Smarks } 7604543Smarks 7614543Smarks if ((error = zfs_secpolicy_write_perms(parentname, 7624543Smarks ZFS_DELEG_PERM_CREATE, cr)) != 0) 7634543Smarks return (error); 7644543Smarks 7654543Smarks error = zfs_secpolicy_write_perms(parentname, 7664543Smarks ZFS_DELEG_PERM_MOUNT, cr); 7674543Smarks 7684543Smarks return (error); 7694543Smarks } 7704543Smarks 7714543Smarks static int 7724543Smarks zfs_secpolicy_umount(zfs_cmd_t *zc, cred_t *cr) 7734543Smarks { 7744543Smarks int error; 7754543Smarks 7764543Smarks error = secpolicy_fs_unmount(cr, NULL); 7774543Smarks if (error) { 7784543Smarks error = dsl_deleg_access(zc->zc_name, ZFS_DELEG_PERM_MOUNT, cr); 7794543Smarks } 7804543Smarks return (error); 781789Sahrens } 782789Sahrens 783789Sahrens /* 784789Sahrens * Policy for pool operations - create/destroy pools, add vdevs, etc. Requires 785789Sahrens * SYS_CONFIG privilege, which is not available in a local zone. 786789Sahrens */ 787789Sahrens /* ARGSUSED */ 788789Sahrens static int 7894543Smarks zfs_secpolicy_config(zfs_cmd_t *zc, cred_t *cr) 790789Sahrens { 791789Sahrens if (secpolicy_sys_config(cr, B_FALSE) != 0) 792789Sahrens return (EPERM); 793789Sahrens 794789Sahrens return (0); 795789Sahrens } 796789Sahrens 797789Sahrens /* 7981544Seschrock * Policy for fault injection. Requires all privileges. 7991544Seschrock */ 8001544Seschrock /* ARGSUSED */ 8011544Seschrock static int 8024543Smarks zfs_secpolicy_inject(zfs_cmd_t *zc, cred_t *cr) 8031544Seschrock { 8041544Seschrock return (secpolicy_zinject(cr)); 8051544Seschrock } 8061544Seschrock 8074849Sahrens static int 8084849Sahrens zfs_secpolicy_inherit(zfs_cmd_t *zc, cred_t *cr) 8094849Sahrens { 8104849Sahrens zfs_prop_t prop = zfs_name_to_prop(zc->zc_value); 8114849Sahrens 8125094Slling if (prop == ZPROP_INVAL) { 8134849Sahrens if (!zfs_prop_user(zc->zc_value)) 8144849Sahrens return (EINVAL); 8154849Sahrens return (zfs_secpolicy_write_perms(zc->zc_name, 8164849Sahrens ZFS_DELEG_PERM_USERPROP, cr)); 8174849Sahrens } else { 81811022STom.Erickson@Sun.COM return (zfs_secpolicy_setprop(zc->zc_name, prop, 81911022STom.Erickson@Sun.COM NULL, cr)); 8204849Sahrens } 8214849Sahrens } 8224849Sahrens 8239396SMatthew.Ahrens@Sun.COM static int 8249396SMatthew.Ahrens@Sun.COM zfs_secpolicy_userspace_one(zfs_cmd_t *zc, cred_t *cr) 8259396SMatthew.Ahrens@Sun.COM { 8269396SMatthew.Ahrens@Sun.COM int err = zfs_secpolicy_read(zc, cr); 8279396SMatthew.Ahrens@Sun.COM if (err) 8289396SMatthew.Ahrens@Sun.COM return (err); 8299396SMatthew.Ahrens@Sun.COM 8309396SMatthew.Ahrens@Sun.COM if (zc->zc_objset_type >= ZFS_NUM_USERQUOTA_PROPS) 8319396SMatthew.Ahrens@Sun.COM return (EINVAL); 8329396SMatthew.Ahrens@Sun.COM 8339396SMatthew.Ahrens@Sun.COM if (zc->zc_value[0] == 0) { 8349396SMatthew.Ahrens@Sun.COM /* 8359396SMatthew.Ahrens@Sun.COM * They are asking about a posix uid/gid. If it's 8369396SMatthew.Ahrens@Sun.COM * themself, allow it. 8379396SMatthew.Ahrens@Sun.COM */ 8389396SMatthew.Ahrens@Sun.COM if (zc->zc_objset_type == ZFS_PROP_USERUSED || 8399396SMatthew.Ahrens@Sun.COM zc->zc_objset_type == ZFS_PROP_USERQUOTA) { 8409396SMatthew.Ahrens@Sun.COM if (zc->zc_guid == crgetuid(cr)) 8419396SMatthew.Ahrens@Sun.COM return (0); 8429396SMatthew.Ahrens@Sun.COM } else { 8439396SMatthew.Ahrens@Sun.COM if (groupmember(zc->zc_guid, cr)) 8449396SMatthew.Ahrens@Sun.COM return (0); 8459396SMatthew.Ahrens@Sun.COM } 8469396SMatthew.Ahrens@Sun.COM } 8479396SMatthew.Ahrens@Sun.COM 8489396SMatthew.Ahrens@Sun.COM return (zfs_secpolicy_write_perms(zc->zc_name, 8499396SMatthew.Ahrens@Sun.COM userquota_perms[zc->zc_objset_type], cr)); 8509396SMatthew.Ahrens@Sun.COM } 8519396SMatthew.Ahrens@Sun.COM 8529396SMatthew.Ahrens@Sun.COM static int 8539396SMatthew.Ahrens@Sun.COM zfs_secpolicy_userspace_many(zfs_cmd_t *zc, cred_t *cr) 8549396SMatthew.Ahrens@Sun.COM { 8559396SMatthew.Ahrens@Sun.COM int err = zfs_secpolicy_read(zc, cr); 8569396SMatthew.Ahrens@Sun.COM if (err) 8579396SMatthew.Ahrens@Sun.COM return (err); 8589396SMatthew.Ahrens@Sun.COM 8599396SMatthew.Ahrens@Sun.COM if (zc->zc_objset_type >= ZFS_NUM_USERQUOTA_PROPS) 8609396SMatthew.Ahrens@Sun.COM return (EINVAL); 8619396SMatthew.Ahrens@Sun.COM 8629396SMatthew.Ahrens@Sun.COM return (zfs_secpolicy_write_perms(zc->zc_name, 8639396SMatthew.Ahrens@Sun.COM userquota_perms[zc->zc_objset_type], cr)); 8649396SMatthew.Ahrens@Sun.COM } 8659396SMatthew.Ahrens@Sun.COM 8669396SMatthew.Ahrens@Sun.COM static int 8679396SMatthew.Ahrens@Sun.COM zfs_secpolicy_userspace_upgrade(zfs_cmd_t *zc, cred_t *cr) 8689396SMatthew.Ahrens@Sun.COM { 86911022STom.Erickson@Sun.COM return (zfs_secpolicy_setprop(zc->zc_name, ZFS_PROP_VERSION, 87011022STom.Erickson@Sun.COM NULL, cr)); 8719396SMatthew.Ahrens@Sun.COM } 8729396SMatthew.Ahrens@Sun.COM 87310242Schris.kirby@sun.com static int 87410242Schris.kirby@sun.com zfs_secpolicy_hold(zfs_cmd_t *zc, cred_t *cr) 87510242Schris.kirby@sun.com { 87610242Schris.kirby@sun.com return (zfs_secpolicy_write_perms(zc->zc_name, 87710242Schris.kirby@sun.com ZFS_DELEG_PERM_HOLD, cr)); 87810242Schris.kirby@sun.com } 87910242Schris.kirby@sun.com 88010242Schris.kirby@sun.com static int 88110242Schris.kirby@sun.com zfs_secpolicy_release(zfs_cmd_t *zc, cred_t *cr) 88210242Schris.kirby@sun.com { 88310242Schris.kirby@sun.com return (zfs_secpolicy_write_perms(zc->zc_name, 88410242Schris.kirby@sun.com ZFS_DELEG_PERM_RELEASE, cr)); 88510242Schris.kirby@sun.com } 88610242Schris.kirby@sun.com 8871544Seschrock /* 888789Sahrens * Returns the nvlist as specified by the user in the zfs_cmd_t. 889789Sahrens */ 890789Sahrens static int 8919643SEric.Taylor@Sun.COM get_nvlist(uint64_t nvl, uint64_t size, int iflag, nvlist_t **nvp) 892789Sahrens { 893789Sahrens char *packed; 894789Sahrens int error; 8955094Slling nvlist_t *list = NULL; 896789Sahrens 897789Sahrens /* 8982676Seschrock * Read in and unpack the user-supplied nvlist. 899789Sahrens */ 9005094Slling if (size == 0) 901789Sahrens return (EINVAL); 902789Sahrens 903789Sahrens packed = kmem_alloc(size, KM_SLEEP); 904789Sahrens 9059643SEric.Taylor@Sun.COM if ((error = ddi_copyin((void *)(uintptr_t)nvl, packed, size, 9069643SEric.Taylor@Sun.COM iflag)) != 0) { 907789Sahrens kmem_free(packed, size); 908789Sahrens return (error); 909789Sahrens } 910789Sahrens 9115094Slling if ((error = nvlist_unpack(packed, size, &list, 0)) != 0) { 912789Sahrens kmem_free(packed, size); 913789Sahrens return (error); 914789Sahrens } 915789Sahrens 916789Sahrens kmem_free(packed, size); 917789Sahrens 9185094Slling *nvp = list; 919789Sahrens return (0); 920789Sahrens } 921789Sahrens 922789Sahrens static int 92311022STom.Erickson@Sun.COM fit_error_list(zfs_cmd_t *zc, nvlist_t **errors) 92411022STom.Erickson@Sun.COM { 92511022STom.Erickson@Sun.COM size_t size; 92611022STom.Erickson@Sun.COM 92711022STom.Erickson@Sun.COM VERIFY(nvlist_size(*errors, &size, NV_ENCODE_NATIVE) == 0); 92811022STom.Erickson@Sun.COM 92911022STom.Erickson@Sun.COM if (size > zc->zc_nvlist_dst_size) { 93011022STom.Erickson@Sun.COM nvpair_t *more_errors; 93111022STom.Erickson@Sun.COM int n = 0; 93211022STom.Erickson@Sun.COM 93311022STom.Erickson@Sun.COM if (zc->zc_nvlist_dst_size < 1024) 93411022STom.Erickson@Sun.COM return (ENOMEM); 93511022STom.Erickson@Sun.COM 93611022STom.Erickson@Sun.COM VERIFY(nvlist_add_int32(*errors, ZPROP_N_MORE_ERRORS, 0) == 0); 93711022STom.Erickson@Sun.COM more_errors = nvlist_prev_nvpair(*errors, NULL); 93811022STom.Erickson@Sun.COM 93911022STom.Erickson@Sun.COM do { 94011022STom.Erickson@Sun.COM nvpair_t *pair = nvlist_prev_nvpair(*errors, 94111022STom.Erickson@Sun.COM more_errors); 94211022STom.Erickson@Sun.COM VERIFY(nvlist_remove_nvpair(*errors, pair) == 0); 94311022STom.Erickson@Sun.COM n++; 94411022STom.Erickson@Sun.COM VERIFY(nvlist_size(*errors, &size, 94511022STom.Erickson@Sun.COM NV_ENCODE_NATIVE) == 0); 94611022STom.Erickson@Sun.COM } while (size > zc->zc_nvlist_dst_size); 94711022STom.Erickson@Sun.COM 94811022STom.Erickson@Sun.COM VERIFY(nvlist_remove_nvpair(*errors, more_errors) == 0); 94911022STom.Erickson@Sun.COM VERIFY(nvlist_add_int32(*errors, ZPROP_N_MORE_ERRORS, n) == 0); 95011022STom.Erickson@Sun.COM ASSERT(nvlist_size(*errors, &size, NV_ENCODE_NATIVE) == 0); 95111022STom.Erickson@Sun.COM ASSERT(size <= zc->zc_nvlist_dst_size); 95211022STom.Erickson@Sun.COM } 95311022STom.Erickson@Sun.COM 95411022STom.Erickson@Sun.COM return (0); 95511022STom.Erickson@Sun.COM } 95611022STom.Erickson@Sun.COM 95711022STom.Erickson@Sun.COM static int 9582676Seschrock put_nvlist(zfs_cmd_t *zc, nvlist_t *nvl) 9592676Seschrock { 9602676Seschrock char *packed = NULL; 9612676Seschrock size_t size; 9622676Seschrock int error; 9632676Seschrock 9642676Seschrock VERIFY(nvlist_size(nvl, &size, NV_ENCODE_NATIVE) == 0); 9652676Seschrock 9662676Seschrock if (size > zc->zc_nvlist_dst_size) { 9672676Seschrock error = ENOMEM; 9682676Seschrock } else { 9694611Smarks packed = kmem_alloc(size, KM_SLEEP); 9702676Seschrock VERIFY(nvlist_pack(nvl, &packed, &size, NV_ENCODE_NATIVE, 9712676Seschrock KM_SLEEP) == 0); 9729643SEric.Taylor@Sun.COM error = ddi_copyout(packed, 9739643SEric.Taylor@Sun.COM (void *)(uintptr_t)zc->zc_nvlist_dst, size, zc->zc_iflags); 9742676Seschrock kmem_free(packed, size); 9752676Seschrock } 9762676Seschrock 9772676Seschrock zc->zc_nvlist_dst_size = size; 9782676Seschrock return (error); 9792676Seschrock } 9802676Seschrock 9812676Seschrock static int 98211185SSean.McEnroe@Sun.COM getzfsvfs(const char *dsname, zfsvfs_t **zfvp) 9839396SMatthew.Ahrens@Sun.COM { 9849396SMatthew.Ahrens@Sun.COM objset_t *os; 9859396SMatthew.Ahrens@Sun.COM int error; 9869396SMatthew.Ahrens@Sun.COM 98710298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(dsname, FTAG, &os); 9889396SMatthew.Ahrens@Sun.COM if (error) 9899396SMatthew.Ahrens@Sun.COM return (error); 99010298SMatthew.Ahrens@Sun.COM if (dmu_objset_type(os) != DMU_OST_ZFS) { 99110298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 99210298SMatthew.Ahrens@Sun.COM return (EINVAL); 99310298SMatthew.Ahrens@Sun.COM } 99410298SMatthew.Ahrens@Sun.COM 99510298SMatthew.Ahrens@Sun.COM mutex_enter(&os->os_user_ptr_lock); 99611185SSean.McEnroe@Sun.COM *zfvp = dmu_objset_get_user(os); 99711185SSean.McEnroe@Sun.COM if (*zfvp) { 99811185SSean.McEnroe@Sun.COM VFS_HOLD((*zfvp)->z_vfs); 9999396SMatthew.Ahrens@Sun.COM } else { 10009396SMatthew.Ahrens@Sun.COM error = ESRCH; 10019396SMatthew.Ahrens@Sun.COM } 100210298SMatthew.Ahrens@Sun.COM mutex_exit(&os->os_user_ptr_lock); 100310298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 10049396SMatthew.Ahrens@Sun.COM return (error); 10059396SMatthew.Ahrens@Sun.COM } 10069396SMatthew.Ahrens@Sun.COM 10079396SMatthew.Ahrens@Sun.COM /* 10089396SMatthew.Ahrens@Sun.COM * Find a zfsvfs_t for a mounted filesystem, or create our own, in which 10099396SMatthew.Ahrens@Sun.COM * case its z_vfs will be NULL, and it will be opened as the owner. 10109396SMatthew.Ahrens@Sun.COM */ 10119396SMatthew.Ahrens@Sun.COM static int 101211185SSean.McEnroe@Sun.COM zfsvfs_hold(const char *name, void *tag, zfsvfs_t **zfvp) 10139396SMatthew.Ahrens@Sun.COM { 10149396SMatthew.Ahrens@Sun.COM int error = 0; 10159396SMatthew.Ahrens@Sun.COM 101611185SSean.McEnroe@Sun.COM if (getzfsvfs(name, zfvp) != 0) 101711185SSean.McEnroe@Sun.COM error = zfsvfs_create(name, zfvp); 10189396SMatthew.Ahrens@Sun.COM if (error == 0) { 101911185SSean.McEnroe@Sun.COM rrw_enter(&(*zfvp)->z_teardown_lock, RW_READER, tag); 102011185SSean.McEnroe@Sun.COM if ((*zfvp)->z_unmounted) { 10219396SMatthew.Ahrens@Sun.COM /* 10229396SMatthew.Ahrens@Sun.COM * XXX we could probably try again, since the unmounting 10239396SMatthew.Ahrens@Sun.COM * thread should be just about to disassociate the 10249396SMatthew.Ahrens@Sun.COM * objset from the zfsvfs. 10259396SMatthew.Ahrens@Sun.COM */ 102611185SSean.McEnroe@Sun.COM rrw_exit(&(*zfvp)->z_teardown_lock, tag); 10279396SMatthew.Ahrens@Sun.COM return (EBUSY); 10289396SMatthew.Ahrens@Sun.COM } 10299396SMatthew.Ahrens@Sun.COM } 10309396SMatthew.Ahrens@Sun.COM return (error); 10319396SMatthew.Ahrens@Sun.COM } 10329396SMatthew.Ahrens@Sun.COM 10339396SMatthew.Ahrens@Sun.COM static void 10349396SMatthew.Ahrens@Sun.COM zfsvfs_rele(zfsvfs_t *zfsvfs, void *tag) 10359396SMatthew.Ahrens@Sun.COM { 10369396SMatthew.Ahrens@Sun.COM rrw_exit(&zfsvfs->z_teardown_lock, tag); 10379396SMatthew.Ahrens@Sun.COM 10389396SMatthew.Ahrens@Sun.COM if (zfsvfs->z_vfs) { 10399396SMatthew.Ahrens@Sun.COM VFS_RELE(zfsvfs->z_vfs); 10409396SMatthew.Ahrens@Sun.COM } else { 104110298SMatthew.Ahrens@Sun.COM dmu_objset_disown(zfsvfs->z_os, zfsvfs); 10429396SMatthew.Ahrens@Sun.COM zfsvfs_free(zfsvfs); 10439396SMatthew.Ahrens@Sun.COM } 10449396SMatthew.Ahrens@Sun.COM } 10459396SMatthew.Ahrens@Sun.COM 10469396SMatthew.Ahrens@Sun.COM static int 1047789Sahrens zfs_ioc_pool_create(zfs_cmd_t *zc) 1048789Sahrens { 1049789Sahrens int error; 10505094Slling nvlist_t *config, *props = NULL; 10517184Stimh nvlist_t *rootprops = NULL; 10527184Stimh nvlist_t *zplprops = NULL; 10534715Sek110237 char *buf; 1054789Sahrens 10555094Slling if (error = get_nvlist(zc->zc_nvlist_conf, zc->zc_nvlist_conf_size, 10569643SEric.Taylor@Sun.COM zc->zc_iflags, &config)) 10574988Sek110237 return (error); 10584715Sek110237 10595094Slling if (zc->zc_nvlist_src_size != 0 && (error = 10609643SEric.Taylor@Sun.COM get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 10619643SEric.Taylor@Sun.COM zc->zc_iflags, &props))) { 10625094Slling nvlist_free(config); 10635094Slling return (error); 10645094Slling } 10655094Slling 10667184Stimh if (props) { 10677184Stimh nvlist_t *nvl = NULL; 10687184Stimh uint64_t version = SPA_VERSION; 10697184Stimh 10707184Stimh (void) nvlist_lookup_uint64(props, 10717184Stimh zpool_prop_to_name(ZPOOL_PROP_VERSION), &version); 10727184Stimh if (version < SPA_VERSION_INITIAL || version > SPA_VERSION) { 10737184Stimh error = EINVAL; 10747184Stimh goto pool_props_bad; 10757184Stimh } 10767184Stimh (void) nvlist_lookup_nvlist(props, ZPOOL_ROOTFS_PROPS, &nvl); 10777184Stimh if (nvl) { 10787184Stimh error = nvlist_dup(nvl, &rootprops, KM_SLEEP); 10797184Stimh if (error != 0) { 10807184Stimh nvlist_free(config); 10817184Stimh nvlist_free(props); 10827184Stimh return (error); 10837184Stimh } 10847184Stimh (void) nvlist_remove_all(props, ZPOOL_ROOTFS_PROPS); 10857184Stimh } 10867184Stimh VERIFY(nvlist_alloc(&zplprops, NV_UNIQUE_NAME, KM_SLEEP) == 0); 10877184Stimh error = zfs_fill_zplprops_root(version, rootprops, 10887184Stimh zplprops, NULL); 10897184Stimh if (error) 10907184Stimh goto pool_props_bad; 10917184Stimh } 10927184Stimh 10934988Sek110237 buf = history_str_get(zc); 1094789Sahrens 10957184Stimh error = spa_create(zc->zc_name, config, props, buf, zplprops); 10967184Stimh 10977184Stimh /* 10987184Stimh * Set the remaining root properties 10997184Stimh */ 110011022STom.Erickson@Sun.COM if (!error && (error = zfs_set_prop_nvlist(zc->zc_name, 110111022STom.Erickson@Sun.COM ZPROP_SRC_LOCAL, rootprops, NULL)) != 0) 11027184Stimh (void) spa_destroy(zc->zc_name); 1103789Sahrens 11044988Sek110237 if (buf != NULL) 11054988Sek110237 history_str_free(buf); 11065094Slling 11077184Stimh pool_props_bad: 11087184Stimh nvlist_free(rootprops); 11097184Stimh nvlist_free(zplprops); 1110789Sahrens nvlist_free(config); 11117184Stimh nvlist_free(props); 11125094Slling 1113789Sahrens return (error); 1114789Sahrens } 1115789Sahrens 1116789Sahrens static int 1117789Sahrens zfs_ioc_pool_destroy(zfs_cmd_t *zc) 1118789Sahrens { 11194543Smarks int error; 11204543Smarks zfs_log_history(zc); 11214543Smarks error = spa_destroy(zc->zc_name); 112210588SEric.Taylor@Sun.COM if (error == 0) 112310588SEric.Taylor@Sun.COM zvol_remove_minors(zc->zc_name); 11244543Smarks return (error); 1125789Sahrens } 1126789Sahrens 1127789Sahrens static int 1128789Sahrens zfs_ioc_pool_import(zfs_cmd_t *zc) 1129789Sahrens { 11305094Slling nvlist_t *config, *props = NULL; 1131789Sahrens uint64_t guid; 113210921STim.Haley@Sun.COM int error; 1133789Sahrens 11345094Slling if ((error = get_nvlist(zc->zc_nvlist_conf, zc->zc_nvlist_conf_size, 11359643SEric.Taylor@Sun.COM zc->zc_iflags, &config)) != 0) 1136789Sahrens return (error); 1137789Sahrens 11385094Slling if (zc->zc_nvlist_src_size != 0 && (error = 11399643SEric.Taylor@Sun.COM get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 11409643SEric.Taylor@Sun.COM zc->zc_iflags, &props))) { 11415094Slling nvlist_free(config); 11425094Slling return (error); 11435094Slling } 11445094Slling 1145789Sahrens if (nvlist_lookup_uint64(config, ZPOOL_CONFIG_POOL_GUID, &guid) != 0 || 11461544Seschrock guid != zc->zc_guid) 1147789Sahrens error = EINVAL; 11486643Seschrock else if (zc->zc_cookie) 114910921STim.Haley@Sun.COM error = spa_import_verbatim(zc->zc_name, config, props); 1150789Sahrens else 11515094Slling error = spa_import(zc->zc_name, config, props); 1152789Sahrens 115310921STim.Haley@Sun.COM if (zc->zc_nvlist_dst != 0) 115410921STim.Haley@Sun.COM (void) put_nvlist(zc, config); 115510921STim.Haley@Sun.COM 1156789Sahrens nvlist_free(config); 1157789Sahrens 11585094Slling if (props) 11595094Slling nvlist_free(props); 11605094Slling 1161789Sahrens return (error); 1162789Sahrens } 1163789Sahrens 1164789Sahrens static int 1165789Sahrens zfs_ioc_pool_export(zfs_cmd_t *zc) 1166789Sahrens { 11674543Smarks int error; 11687214Slling boolean_t force = (boolean_t)zc->zc_cookie; 11698211SGeorge.Wilson@Sun.COM boolean_t hardforce = (boolean_t)zc->zc_guid; 11707214Slling 11714543Smarks zfs_log_history(zc); 11728211SGeorge.Wilson@Sun.COM error = spa_export(zc->zc_name, NULL, force, hardforce); 117310588SEric.Taylor@Sun.COM if (error == 0) 117410588SEric.Taylor@Sun.COM zvol_remove_minors(zc->zc_name); 11754543Smarks return (error); 1176789Sahrens } 1177789Sahrens 1178789Sahrens static int 1179789Sahrens zfs_ioc_pool_configs(zfs_cmd_t *zc) 1180789Sahrens { 1181789Sahrens nvlist_t *configs; 1182789Sahrens int error; 1183789Sahrens 1184789Sahrens if ((configs = spa_all_configs(&zc->zc_cookie)) == NULL) 1185789Sahrens return (EEXIST); 1186789Sahrens 11872676Seschrock error = put_nvlist(zc, configs); 1188789Sahrens 1189789Sahrens nvlist_free(configs); 1190789Sahrens 1191789Sahrens return (error); 1192789Sahrens } 1193789Sahrens 1194789Sahrens static int 1195789Sahrens zfs_ioc_pool_stats(zfs_cmd_t *zc) 1196789Sahrens { 1197789Sahrens nvlist_t *config; 1198789Sahrens int error; 11991544Seschrock int ret = 0; 1200789Sahrens 12012676Seschrock error = spa_get_stats(zc->zc_name, &config, zc->zc_value, 12022676Seschrock sizeof (zc->zc_value)); 1203789Sahrens 1204789Sahrens if (config != NULL) { 12052676Seschrock ret = put_nvlist(zc, config); 1206789Sahrens nvlist_free(config); 12071544Seschrock 12081544Seschrock /* 12091544Seschrock * The config may be present even if 'error' is non-zero. 12101544Seschrock * In this case we return success, and preserve the real errno 12111544Seschrock * in 'zc_cookie'. 12121544Seschrock */ 12131544Seschrock zc->zc_cookie = error; 1214789Sahrens } else { 12151544Seschrock ret = error; 1216789Sahrens } 1217789Sahrens 12181544Seschrock return (ret); 1219789Sahrens } 1220789Sahrens 1221789Sahrens /* 1222789Sahrens * Try to import the given pool, returning pool stats as appropriate so that 1223789Sahrens * user land knows which devices are available and overall pool health. 1224789Sahrens */ 1225789Sahrens static int 1226789Sahrens zfs_ioc_pool_tryimport(zfs_cmd_t *zc) 1227789Sahrens { 1228789Sahrens nvlist_t *tryconfig, *config; 1229789Sahrens int error; 1230789Sahrens 12315094Slling if ((error = get_nvlist(zc->zc_nvlist_conf, zc->zc_nvlist_conf_size, 12329643SEric.Taylor@Sun.COM zc->zc_iflags, &tryconfig)) != 0) 1233789Sahrens return (error); 1234789Sahrens 1235789Sahrens config = spa_tryimport(tryconfig); 1236789Sahrens 1237789Sahrens nvlist_free(tryconfig); 1238789Sahrens 1239789Sahrens if (config == NULL) 1240789Sahrens return (EINVAL); 1241789Sahrens 12422676Seschrock error = put_nvlist(zc, config); 1243789Sahrens nvlist_free(config); 1244789Sahrens 1245789Sahrens return (error); 1246789Sahrens } 1247789Sahrens 1248789Sahrens static int 1249789Sahrens zfs_ioc_pool_scrub(zfs_cmd_t *zc) 1250789Sahrens { 1251789Sahrens spa_t *spa; 1252789Sahrens int error; 1253789Sahrens 12542926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 12552926Sek110237 return (error); 12562926Sek110237 12577046Sahrens error = spa_scrub(spa, zc->zc_cookie); 12582926Sek110237 12592926Sek110237 spa_close(spa, FTAG); 12602926Sek110237 1261789Sahrens return (error); 1262789Sahrens } 1263789Sahrens 1264789Sahrens static int 1265789Sahrens zfs_ioc_pool_freeze(zfs_cmd_t *zc) 1266789Sahrens { 1267789Sahrens spa_t *spa; 1268789Sahrens int error; 1269789Sahrens 1270789Sahrens error = spa_open(zc->zc_name, &spa, FTAG); 1271789Sahrens if (error == 0) { 1272789Sahrens spa_freeze(spa); 1273789Sahrens spa_close(spa, FTAG); 1274789Sahrens } 1275789Sahrens return (error); 1276789Sahrens } 1277789Sahrens 1278789Sahrens static int 12791760Seschrock zfs_ioc_pool_upgrade(zfs_cmd_t *zc) 12801760Seschrock { 12811760Seschrock spa_t *spa; 12821760Seschrock int error; 12831760Seschrock 12842926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 12852926Sek110237 return (error); 12862926Sek110237 12875118Slling if (zc->zc_cookie < spa_version(spa) || zc->zc_cookie > SPA_VERSION) { 12885118Slling spa_close(spa, FTAG); 12895118Slling return (EINVAL); 12905118Slling } 12915118Slling 12925094Slling spa_upgrade(spa, zc->zc_cookie); 12932926Sek110237 spa_close(spa, FTAG); 12942926Sek110237 12952926Sek110237 return (error); 12962926Sek110237 } 12972926Sek110237 12982926Sek110237 static int 12992926Sek110237 zfs_ioc_pool_get_history(zfs_cmd_t *zc) 13002926Sek110237 { 13012926Sek110237 spa_t *spa; 13022926Sek110237 char *hist_buf; 13032926Sek110237 uint64_t size; 13042926Sek110237 int error; 13052926Sek110237 13062926Sek110237 if ((size = zc->zc_history_len) == 0) 13072926Sek110237 return (EINVAL); 13082926Sek110237 13092926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 13102926Sek110237 return (error); 13112926Sek110237 13124577Sahrens if (spa_version(spa) < SPA_VERSION_ZPOOL_HISTORY) { 13133863Sek110237 spa_close(spa, FTAG); 13143863Sek110237 return (ENOTSUP); 13153863Sek110237 } 13163863Sek110237 13172926Sek110237 hist_buf = kmem_alloc(size, KM_SLEEP); 13182926Sek110237 if ((error = spa_history_get(spa, &zc->zc_history_offset, 13192926Sek110237 &zc->zc_history_len, hist_buf)) == 0) { 13209643SEric.Taylor@Sun.COM error = ddi_copyout(hist_buf, 13219643SEric.Taylor@Sun.COM (void *)(uintptr_t)zc->zc_history, 13229643SEric.Taylor@Sun.COM zc->zc_history_len, zc->zc_iflags); 13232926Sek110237 } 13242926Sek110237 13252926Sek110237 spa_close(spa, FTAG); 13262926Sek110237 kmem_free(hist_buf, size); 13272926Sek110237 return (error); 13282926Sek110237 } 13292926Sek110237 13302926Sek110237 static int 13313444Sek110237 zfs_ioc_dsobj_to_dsname(zfs_cmd_t *zc) 13323444Sek110237 { 13333444Sek110237 int error; 13343444Sek110237 13353912Slling if (error = dsl_dsobj_to_dsname(zc->zc_name, zc->zc_obj, zc->zc_value)) 13363444Sek110237 return (error); 13373444Sek110237 13383444Sek110237 return (0); 13393444Sek110237 } 13403444Sek110237 134110298SMatthew.Ahrens@Sun.COM /* 134210298SMatthew.Ahrens@Sun.COM * inputs: 134310298SMatthew.Ahrens@Sun.COM * zc_name name of filesystem 134410298SMatthew.Ahrens@Sun.COM * zc_obj object to find 134510298SMatthew.Ahrens@Sun.COM * 134610298SMatthew.Ahrens@Sun.COM * outputs: 134710298SMatthew.Ahrens@Sun.COM * zc_value name of object 134810298SMatthew.Ahrens@Sun.COM */ 13493444Sek110237 static int 13503444Sek110237 zfs_ioc_obj_to_path(zfs_cmd_t *zc) 13513444Sek110237 { 135210298SMatthew.Ahrens@Sun.COM objset_t *os; 13533444Sek110237 int error; 13543444Sek110237 135510298SMatthew.Ahrens@Sun.COM /* XXX reading from objset not owned */ 135610298SMatthew.Ahrens@Sun.COM if ((error = dmu_objset_hold(zc->zc_name, FTAG, &os)) != 0) 13573444Sek110237 return (error); 135810298SMatthew.Ahrens@Sun.COM if (dmu_objset_type(os) != DMU_OST_ZFS) { 135910298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 136010298SMatthew.Ahrens@Sun.COM return (EINVAL); 136110298SMatthew.Ahrens@Sun.COM } 136210298SMatthew.Ahrens@Sun.COM error = zfs_obj_to_path(os, zc->zc_obj, zc->zc_value, 13633444Sek110237 sizeof (zc->zc_value)); 136410298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 13653444Sek110237 13663444Sek110237 return (error); 13673444Sek110237 } 13683444Sek110237 13693444Sek110237 static int 1370789Sahrens zfs_ioc_vdev_add(zfs_cmd_t *zc) 1371789Sahrens { 1372789Sahrens spa_t *spa; 1373789Sahrens int error; 13746423Sgw25295 nvlist_t *config, **l2cache, **spares; 13756423Sgw25295 uint_t nl2cache = 0, nspares = 0; 1376789Sahrens 1377789Sahrens error = spa_open(zc->zc_name, &spa, FTAG); 1378789Sahrens if (error != 0) 1379789Sahrens return (error); 1380789Sahrens 13815450Sbrendan error = get_nvlist(zc->zc_nvlist_conf, zc->zc_nvlist_conf_size, 13829643SEric.Taylor@Sun.COM zc->zc_iflags, &config); 13835450Sbrendan (void) nvlist_lookup_nvlist_array(config, ZPOOL_CONFIG_L2CACHE, 13845450Sbrendan &l2cache, &nl2cache); 13855450Sbrendan 13866423Sgw25295 (void) nvlist_lookup_nvlist_array(config, ZPOOL_CONFIG_SPARES, 13876423Sgw25295 &spares, &nspares); 13886423Sgw25295 13893912Slling /* 13903912Slling * A root pool with concatenated devices is not supported. 13916423Sgw25295 * Thus, can not add a device to a root pool. 13926423Sgw25295 * 13936423Sgw25295 * Intent log device can not be added to a rootpool because 13946423Sgw25295 * during mountroot, zil is replayed, a seperated log device 13956423Sgw25295 * can not be accessed during the mountroot time. 13966423Sgw25295 * 13976423Sgw25295 * l2cache and spare devices are ok to be added to a rootpool. 13983912Slling */ 139910922SJeff.Bonwick@Sun.COM if (spa_bootfs(spa) != 0 && nl2cache == 0 && nspares == 0) { 14003912Slling spa_close(spa, FTAG); 14013912Slling return (EDOM); 14023912Slling } 14033912Slling 14045450Sbrendan if (error == 0) { 1405789Sahrens error = spa_vdev_add(spa, config); 1406789Sahrens nvlist_free(config); 1407789Sahrens } 1408789Sahrens spa_close(spa, FTAG); 1409789Sahrens return (error); 1410789Sahrens } 1411789Sahrens 1412789Sahrens static int 1413789Sahrens zfs_ioc_vdev_remove(zfs_cmd_t *zc) 1414789Sahrens { 14152082Seschrock spa_t *spa; 14162082Seschrock int error; 14172082Seschrock 14182082Seschrock error = spa_open(zc->zc_name, &spa, FTAG); 14192082Seschrock if (error != 0) 14202082Seschrock return (error); 14212082Seschrock error = spa_vdev_remove(spa, zc->zc_guid, B_FALSE); 14222082Seschrock spa_close(spa, FTAG); 14232082Seschrock return (error); 1424789Sahrens } 1425789Sahrens 1426789Sahrens static int 14274451Seschrock zfs_ioc_vdev_set_state(zfs_cmd_t *zc) 1428789Sahrens { 1429789Sahrens spa_t *spa; 1430789Sahrens int error; 14314451Seschrock vdev_state_t newstate = VDEV_STATE_UNKNOWN; 1432789Sahrens 14332926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 1434789Sahrens return (error); 14354451Seschrock switch (zc->zc_cookie) { 14364451Seschrock case VDEV_STATE_ONLINE: 14374451Seschrock error = vdev_online(spa, zc->zc_guid, zc->zc_obj, &newstate); 14384451Seschrock break; 14394451Seschrock 14404451Seschrock case VDEV_STATE_OFFLINE: 14414451Seschrock error = vdev_offline(spa, zc->zc_guid, zc->zc_obj); 14424451Seschrock break; 1443789Sahrens 14444451Seschrock case VDEV_STATE_FAULTED: 144510817SEric.Schrock@Sun.COM if (zc->zc_obj != VDEV_AUX_ERR_EXCEEDED && 144610817SEric.Schrock@Sun.COM zc->zc_obj != VDEV_AUX_EXTERNAL) 144710817SEric.Schrock@Sun.COM zc->zc_obj = VDEV_AUX_ERR_EXCEEDED; 144810817SEric.Schrock@Sun.COM 144910817SEric.Schrock@Sun.COM error = vdev_fault(spa, zc->zc_guid, zc->zc_obj); 14504451Seschrock break; 1451789Sahrens 14524451Seschrock case VDEV_STATE_DEGRADED: 145310817SEric.Schrock@Sun.COM if (zc->zc_obj != VDEV_AUX_ERR_EXCEEDED && 145410817SEric.Schrock@Sun.COM zc->zc_obj != VDEV_AUX_EXTERNAL) 145510817SEric.Schrock@Sun.COM zc->zc_obj = VDEV_AUX_ERR_EXCEEDED; 145610817SEric.Schrock@Sun.COM 145710817SEric.Schrock@Sun.COM error = vdev_degrade(spa, zc->zc_guid, zc->zc_obj); 14584451Seschrock break; 14594451Seschrock 14604451Seschrock default: 14614451Seschrock error = EINVAL; 14624451Seschrock } 14634451Seschrock zc->zc_cookie = newstate; 1464789Sahrens spa_close(spa, FTAG); 1465789Sahrens return (error); 1466789Sahrens } 1467789Sahrens 1468789Sahrens static int 1469789Sahrens zfs_ioc_vdev_attach(zfs_cmd_t *zc) 1470789Sahrens { 1471789Sahrens spa_t *spa; 1472789Sahrens int replacing = zc->zc_cookie; 1473789Sahrens nvlist_t *config; 1474789Sahrens int error; 1475789Sahrens 14762926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 1477789Sahrens return (error); 1478789Sahrens 14795094Slling if ((error = get_nvlist(zc->zc_nvlist_conf, zc->zc_nvlist_conf_size, 14809643SEric.Taylor@Sun.COM zc->zc_iflags, &config)) == 0) { 14811544Seschrock error = spa_vdev_attach(spa, zc->zc_guid, config, replacing); 1482789Sahrens nvlist_free(config); 1483789Sahrens } 1484789Sahrens 1485789Sahrens spa_close(spa, FTAG); 1486789Sahrens return (error); 1487789Sahrens } 1488789Sahrens 1489789Sahrens static int 1490789Sahrens zfs_ioc_vdev_detach(zfs_cmd_t *zc) 1491789Sahrens { 1492789Sahrens spa_t *spa; 1493789Sahrens int error; 1494789Sahrens 14952926Sek110237 if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 1496789Sahrens return (error); 1497789Sahrens 14988241SJeff.Bonwick@Sun.COM error = spa_vdev_detach(spa, zc->zc_guid, 0, B_FALSE); 1499789Sahrens 1500789Sahrens spa_close(spa, FTAG); 1501789Sahrens return (error); 1502789Sahrens } 1503789Sahrens 1504789Sahrens static int 15051354Seschrock zfs_ioc_vdev_setpath(zfs_cmd_t *zc) 15061354Seschrock { 15071354Seschrock spa_t *spa; 15082676Seschrock char *path = zc->zc_value; 15091544Seschrock uint64_t guid = zc->zc_guid; 15101354Seschrock int error; 15111354Seschrock 15121354Seschrock error = spa_open(zc->zc_name, &spa, FTAG); 15131354Seschrock if (error != 0) 15141354Seschrock return (error); 15151354Seschrock 15161354Seschrock error = spa_vdev_setpath(spa, guid, path); 15171354Seschrock spa_close(spa, FTAG); 15181354Seschrock return (error); 15191354Seschrock } 15201354Seschrock 15219425SEric.Schrock@Sun.COM static int 15229425SEric.Schrock@Sun.COM zfs_ioc_vdev_setfru(zfs_cmd_t *zc) 15239425SEric.Schrock@Sun.COM { 15249425SEric.Schrock@Sun.COM spa_t *spa; 15259425SEric.Schrock@Sun.COM char *fru = zc->zc_value; 15269425SEric.Schrock@Sun.COM uint64_t guid = zc->zc_guid; 15279425SEric.Schrock@Sun.COM int error; 15289425SEric.Schrock@Sun.COM 15299425SEric.Schrock@Sun.COM error = spa_open(zc->zc_name, &spa, FTAG); 15309425SEric.Schrock@Sun.COM if (error != 0) 15319425SEric.Schrock@Sun.COM return (error); 15329425SEric.Schrock@Sun.COM 15339425SEric.Schrock@Sun.COM error = spa_vdev_setfru(spa, guid, fru); 15349425SEric.Schrock@Sun.COM spa_close(spa, FTAG); 15359425SEric.Schrock@Sun.COM return (error); 15369425SEric.Schrock@Sun.COM } 15379425SEric.Schrock@Sun.COM 15385367Sahrens /* 15395367Sahrens * inputs: 15405367Sahrens * zc_name name of filesystem 15415367Sahrens * zc_nvlist_dst_size size of buffer for property nvlist 15425367Sahrens * 15435367Sahrens * outputs: 15445367Sahrens * zc_objset_stats stats 15455367Sahrens * zc_nvlist_dst property nvlist 15465367Sahrens * zc_nvlist_dst_size size of property nvlist 15475367Sahrens */ 15481354Seschrock static int 1549789Sahrens zfs_ioc_objset_stats(zfs_cmd_t *zc) 1550789Sahrens { 1551789Sahrens objset_t *os = NULL; 1552789Sahrens int error; 15531356Seschrock nvlist_t *nv; 1554789Sahrens 155510298SMatthew.Ahrens@Sun.COM if (error = dmu_objset_hold(zc->zc_name, FTAG, &os)) 1556789Sahrens return (error); 1557789Sahrens 15582885Sahrens dmu_objset_fast_stat(os, &zc->zc_objset_stats); 1559789Sahrens 15602856Snd150628 if (zc->zc_nvlist_dst != 0 && 156111022STom.Erickson@Sun.COM (error = dsl_prop_get_all(os, &nv)) == 0) { 15622885Sahrens dmu_objset_stats(os, nv); 15633087Sahrens /* 15645147Srm160521 * NB: zvol_get_stats() will read the objset contents, 15653087Sahrens * which we aren't supposed to do with a 15666689Smaybee * DS_MODE_USER hold, because it could be 15673087Sahrens * inconsistent. So this is a bit of a workaround... 156810298SMatthew.Ahrens@Sun.COM * XXX reading with out owning 15693087Sahrens */ 15704577Sahrens if (!zc->zc_objset_stats.dds_inconsistent) { 15714577Sahrens if (dmu_objset_type(os) == DMU_OST_ZVOL) 15724577Sahrens VERIFY(zvol_get_stats(os, nv) == 0); 15734577Sahrens } 15742676Seschrock error = put_nvlist(zc, nv); 15751356Seschrock nvlist_free(nv); 15761356Seschrock } 1577789Sahrens 157810298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 1579789Sahrens return (error); 1580789Sahrens } 1581789Sahrens 158211022STom.Erickson@Sun.COM /* 158311022STom.Erickson@Sun.COM * inputs: 158411022STom.Erickson@Sun.COM * zc_name name of filesystem 158511022STom.Erickson@Sun.COM * zc_nvlist_dst_size size of buffer for property nvlist 158611022STom.Erickson@Sun.COM * 158711022STom.Erickson@Sun.COM * outputs: 158811022STom.Erickson@Sun.COM * zc_nvlist_dst received property nvlist 158911022STom.Erickson@Sun.COM * zc_nvlist_dst_size size of received property nvlist 159011022STom.Erickson@Sun.COM * 159111022STom.Erickson@Sun.COM * Gets received properties (distinct from local properties on or after 159211022STom.Erickson@Sun.COM * SPA_VERSION_RECVD_PROPS) for callers who want to differentiate received from 159311022STom.Erickson@Sun.COM * local property values. 159411022STom.Erickson@Sun.COM */ 159511022STom.Erickson@Sun.COM static int 159611022STom.Erickson@Sun.COM zfs_ioc_objset_recvd_props(zfs_cmd_t *zc) 159711022STom.Erickson@Sun.COM { 159811022STom.Erickson@Sun.COM objset_t *os = NULL; 159911022STom.Erickson@Sun.COM int error; 160011022STom.Erickson@Sun.COM nvlist_t *nv; 160111022STom.Erickson@Sun.COM 160211022STom.Erickson@Sun.COM if (error = dmu_objset_hold(zc->zc_name, FTAG, &os)) 160311022STom.Erickson@Sun.COM return (error); 160411022STom.Erickson@Sun.COM 160511022STom.Erickson@Sun.COM /* 160611022STom.Erickson@Sun.COM * Without this check, we would return local property values if the 160711022STom.Erickson@Sun.COM * caller has not already received properties on or after 160811022STom.Erickson@Sun.COM * SPA_VERSION_RECVD_PROPS. 160911022STom.Erickson@Sun.COM */ 161011022STom.Erickson@Sun.COM if (!dsl_prop_get_hasrecvd(os)) { 161111022STom.Erickson@Sun.COM dmu_objset_rele(os, FTAG); 161211022STom.Erickson@Sun.COM return (ENOTSUP); 161311022STom.Erickson@Sun.COM } 161411022STom.Erickson@Sun.COM 161511022STom.Erickson@Sun.COM if (zc->zc_nvlist_dst != 0 && 161611022STom.Erickson@Sun.COM (error = dsl_prop_get_received(os, &nv)) == 0) { 161711022STom.Erickson@Sun.COM error = put_nvlist(zc, nv); 161811022STom.Erickson@Sun.COM nvlist_free(nv); 161911022STom.Erickson@Sun.COM } 162011022STom.Erickson@Sun.COM 162111022STom.Erickson@Sun.COM dmu_objset_rele(os, FTAG); 162211022STom.Erickson@Sun.COM return (error); 162311022STom.Erickson@Sun.COM } 162411022STom.Erickson@Sun.COM 16255498Stimh static int 16265498Stimh nvl_add_zplprop(objset_t *os, nvlist_t *props, zfs_prop_t prop) 16275498Stimh { 16285498Stimh uint64_t value; 16295498Stimh int error; 16305498Stimh 16315498Stimh /* 16325498Stimh * zfs_get_zplprop() will either find a value or give us 16335498Stimh * the default value (if there is one). 16345498Stimh */ 16355498Stimh if ((error = zfs_get_zplprop(os, prop, &value)) != 0) 16365498Stimh return (error); 16375498Stimh VERIFY(nvlist_add_uint64(props, zfs_prop_to_name(prop), value) == 0); 16385498Stimh return (0); 16395498Stimh } 16405498Stimh 16415498Stimh /* 16425498Stimh * inputs: 16435498Stimh * zc_name name of filesystem 16445498Stimh * zc_nvlist_dst_size size of buffer for zpl property nvlist 16455498Stimh * 16465498Stimh * outputs: 16475498Stimh * zc_nvlist_dst zpl property nvlist 16485498Stimh * zc_nvlist_dst_size size of zpl property nvlist 16495498Stimh */ 16505498Stimh static int 16515498Stimh zfs_ioc_objset_zplprops(zfs_cmd_t *zc) 16525498Stimh { 16535498Stimh objset_t *os; 16545498Stimh int err; 16555498Stimh 165610298SMatthew.Ahrens@Sun.COM /* XXX reading without owning */ 165710298SMatthew.Ahrens@Sun.COM if (err = dmu_objset_hold(zc->zc_name, FTAG, &os)) 16585498Stimh return (err); 16595498Stimh 16605498Stimh dmu_objset_fast_stat(os, &zc->zc_objset_stats); 16615498Stimh 16625498Stimh /* 16635498Stimh * NB: nvl_add_zplprop() will read the objset contents, 16646689Smaybee * which we aren't supposed to do with a DS_MODE_USER 16656689Smaybee * hold, because it could be inconsistent. 16665498Stimh */ 16675498Stimh if (zc->zc_nvlist_dst != NULL && 16685498Stimh !zc->zc_objset_stats.dds_inconsistent && 16695498Stimh dmu_objset_type(os) == DMU_OST_ZFS) { 16705498Stimh nvlist_t *nv; 16715498Stimh 16725498Stimh VERIFY(nvlist_alloc(&nv, NV_UNIQUE_NAME, KM_SLEEP) == 0); 16735498Stimh if ((err = nvl_add_zplprop(os, nv, ZFS_PROP_VERSION)) == 0 && 16745498Stimh (err = nvl_add_zplprop(os, nv, ZFS_PROP_NORMALIZE)) == 0 && 16755498Stimh (err = nvl_add_zplprop(os, nv, ZFS_PROP_UTF8ONLY)) == 0 && 16765498Stimh (err = nvl_add_zplprop(os, nv, ZFS_PROP_CASE)) == 0) 16775498Stimh err = put_nvlist(zc, nv); 16785498Stimh nvlist_free(nv); 16795498Stimh } else { 16805498Stimh err = ENOENT; 16815498Stimh } 168210298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 16835498Stimh return (err); 16845498Stimh } 16855498Stimh 16869396SMatthew.Ahrens@Sun.COM static boolean_t 16879396SMatthew.Ahrens@Sun.COM dataset_name_hidden(const char *name) 16889396SMatthew.Ahrens@Sun.COM { 16899396SMatthew.Ahrens@Sun.COM /* 16909396SMatthew.Ahrens@Sun.COM * Skip over datasets that are not visible in this zone, 16919396SMatthew.Ahrens@Sun.COM * internal datasets (which have a $ in their name), and 16929396SMatthew.Ahrens@Sun.COM * temporary datasets (which have a % in their name). 16939396SMatthew.Ahrens@Sun.COM */ 16949396SMatthew.Ahrens@Sun.COM if (strchr(name, '$') != NULL) 16959396SMatthew.Ahrens@Sun.COM return (B_TRUE); 16969396SMatthew.Ahrens@Sun.COM if (strchr(name, '%') != NULL) 16979396SMatthew.Ahrens@Sun.COM return (B_TRUE); 16989396SMatthew.Ahrens@Sun.COM if (!INGLOBALZONE(curproc) && !zone_dataset_visible(name, NULL)) 16999396SMatthew.Ahrens@Sun.COM return (B_TRUE); 17009396SMatthew.Ahrens@Sun.COM return (B_FALSE); 17019396SMatthew.Ahrens@Sun.COM } 17029396SMatthew.Ahrens@Sun.COM 17035367Sahrens /* 17045367Sahrens * inputs: 17055367Sahrens * zc_name name of filesystem 17065367Sahrens * zc_cookie zap cursor 17075367Sahrens * zc_nvlist_dst_size size of buffer for property nvlist 17085367Sahrens * 17095367Sahrens * outputs: 17105367Sahrens * zc_name name of next filesystem 17119396SMatthew.Ahrens@Sun.COM * zc_cookie zap cursor 17125367Sahrens * zc_objset_stats stats 17135367Sahrens * zc_nvlist_dst property nvlist 17145367Sahrens * zc_nvlist_dst_size size of property nvlist 17155367Sahrens */ 1716789Sahrens static int 1717789Sahrens zfs_ioc_dataset_list_next(zfs_cmd_t *zc) 1718789Sahrens { 1719885Sahrens objset_t *os; 1720789Sahrens int error; 1721789Sahrens char *p; 1722789Sahrens 172310298SMatthew.Ahrens@Sun.COM if (error = dmu_objset_hold(zc->zc_name, FTAG, &os)) { 1724885Sahrens if (error == ENOENT) 1725885Sahrens error = ESRCH; 1726885Sahrens return (error); 1727789Sahrens } 1728789Sahrens 1729789Sahrens p = strrchr(zc->zc_name, '/'); 1730789Sahrens if (p == NULL || p[1] != '\0') 1731789Sahrens (void) strlcat(zc->zc_name, "/", sizeof (zc->zc_name)); 1732789Sahrens p = zc->zc_name + strlen(zc->zc_name); 1733789Sahrens 17348697SRichard.Morris@Sun.COM /* 17358697SRichard.Morris@Sun.COM * Pre-fetch the datasets. dmu_objset_prefetch() always returns 0 17368697SRichard.Morris@Sun.COM * but is not declared void because its called by dmu_objset_find(). 17378697SRichard.Morris@Sun.COM */ 17388415SRichard.Morris@Sun.COM if (zc->zc_cookie == 0) { 17398415SRichard.Morris@Sun.COM uint64_t cookie = 0; 17408415SRichard.Morris@Sun.COM int len = sizeof (zc->zc_name) - (p - zc->zc_name); 17418415SRichard.Morris@Sun.COM 17428415SRichard.Morris@Sun.COM while (dmu_dir_list_next(os, len, p, NULL, &cookie) == 0) 17438697SRichard.Morris@Sun.COM (void) dmu_objset_prefetch(p, NULL); 17448415SRichard.Morris@Sun.COM } 17458415SRichard.Morris@Sun.COM 1746789Sahrens do { 1747885Sahrens error = dmu_dir_list_next(os, 1748885Sahrens sizeof (zc->zc_name) - (p - zc->zc_name), p, 1749885Sahrens NULL, &zc->zc_cookie); 1750789Sahrens if (error == ENOENT) 1751789Sahrens error = ESRCH; 175210588SEric.Taylor@Sun.COM } while (error == 0 && dataset_name_hidden(zc->zc_name) && 175310588SEric.Taylor@Sun.COM !(zc->zc_iflags & FKIOCTL)); 175410298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 1755789Sahrens 175610588SEric.Taylor@Sun.COM /* 175710588SEric.Taylor@Sun.COM * If it's an internal dataset (ie. with a '$' in its name), 175810588SEric.Taylor@Sun.COM * don't try to get stats for it, otherwise we'll return ENOENT. 175910588SEric.Taylor@Sun.COM */ 176010588SEric.Taylor@Sun.COM if (error == 0 && strchr(zc->zc_name, '$') == NULL) 1761885Sahrens error = zfs_ioc_objset_stats(zc); /* fill in the stats */ 1762789Sahrens return (error); 1763789Sahrens } 1764789Sahrens 17655367Sahrens /* 17665367Sahrens * inputs: 17675367Sahrens * zc_name name of filesystem 17685367Sahrens * zc_cookie zap cursor 17695367Sahrens * zc_nvlist_dst_size size of buffer for property nvlist 17705367Sahrens * 17715367Sahrens * outputs: 17725367Sahrens * zc_name name of next snapshot 17735367Sahrens * zc_objset_stats stats 17745367Sahrens * zc_nvlist_dst property nvlist 17755367Sahrens * zc_nvlist_dst_size size of property nvlist 17765367Sahrens */ 1777789Sahrens static int 1778789Sahrens zfs_ioc_snapshot_list_next(zfs_cmd_t *zc) 1779789Sahrens { 1780885Sahrens objset_t *os; 1781789Sahrens int error; 1782789Sahrens 178310474SRichard.Morris@Sun.COM if (zc->zc_cookie == 0) 178410474SRichard.Morris@Sun.COM (void) dmu_objset_find(zc->zc_name, dmu_objset_prefetch, 178510474SRichard.Morris@Sun.COM NULL, DS_FIND_SNAPSHOTS); 178610474SRichard.Morris@Sun.COM 178710298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_name, FTAG, &os); 17886689Smaybee if (error) 17896689Smaybee return (error == ENOENT ? ESRCH : error); 1790789Sahrens 17911003Slling /* 17921003Slling * A dataset name of maximum length cannot have any snapshots, 17931003Slling * so exit immediately. 17941003Slling */ 17951003Slling if (strlcat(zc->zc_name, "@", sizeof (zc->zc_name)) >= MAXNAMELEN) { 179610298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 17971003Slling return (ESRCH); 1798789Sahrens } 1799789Sahrens 1800885Sahrens error = dmu_snapshot_list_next(os, 1801885Sahrens sizeof (zc->zc_name) - strlen(zc->zc_name), 18025663Sck153898 zc->zc_name + strlen(zc->zc_name), NULL, &zc->zc_cookie, NULL); 180310298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 1804885Sahrens if (error == 0) 1805885Sahrens error = zfs_ioc_objset_stats(zc); /* fill in the stats */ 18066689Smaybee else if (error == ENOENT) 18076689Smaybee error = ESRCH; 1808789Sahrens 18095367Sahrens /* if we failed, undo the @ that we tacked on to zc_name */ 18106689Smaybee if (error) 18115367Sahrens *strchr(zc->zc_name, '@') = '\0'; 1812789Sahrens return (error); 1813789Sahrens } 1814789Sahrens 181511022STom.Erickson@Sun.COM static int 181611022STom.Erickson@Sun.COM zfs_prop_set_userquota(const char *dsname, nvpair_t *pair) 181711022STom.Erickson@Sun.COM { 181811022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 181911022STom.Erickson@Sun.COM uint64_t *valary; 182011022STom.Erickson@Sun.COM unsigned int vallen; 182111022STom.Erickson@Sun.COM const char *domain; 182211022STom.Erickson@Sun.COM zfs_userquota_prop_t type; 182311022STom.Erickson@Sun.COM uint64_t rid; 182411022STom.Erickson@Sun.COM uint64_t quota; 182511022STom.Erickson@Sun.COM zfsvfs_t *zfsvfs; 182611022STom.Erickson@Sun.COM int err; 182711022STom.Erickson@Sun.COM 182811022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_NVLIST) { 182911022STom.Erickson@Sun.COM nvlist_t *attrs; 183011022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(pair, &attrs) == 0); 183111022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 183211022STom.Erickson@Sun.COM &pair) == 0); 183311022STom.Erickson@Sun.COM } 183411022STom.Erickson@Sun.COM 183511022STom.Erickson@Sun.COM VERIFY(nvpair_value_uint64_array(pair, &valary, &vallen) == 0); 183611022STom.Erickson@Sun.COM VERIFY(vallen == 3); 183711022STom.Erickson@Sun.COM type = valary[0]; 183811022STom.Erickson@Sun.COM rid = valary[1]; 183911022STom.Erickson@Sun.COM quota = valary[2]; 184011022STom.Erickson@Sun.COM /* 184111022STom.Erickson@Sun.COM * The propname is encoded as 184211022STom.Erickson@Sun.COM * userquota@<rid>-<domain>. 184311022STom.Erickson@Sun.COM */ 184411022STom.Erickson@Sun.COM domain = strchr(propname, '-') + 1; 184511022STom.Erickson@Sun.COM 184611022STom.Erickson@Sun.COM err = zfsvfs_hold(dsname, FTAG, &zfsvfs); 184711022STom.Erickson@Sun.COM if (err == 0) { 184811022STom.Erickson@Sun.COM err = zfs_set_userquota(zfsvfs, type, domain, rid, quota); 184911022STom.Erickson@Sun.COM zfsvfs_rele(zfsvfs, FTAG); 185011022STom.Erickson@Sun.COM } 185111022STom.Erickson@Sun.COM 185211022STom.Erickson@Sun.COM return (err); 185311022STom.Erickson@Sun.COM } 185411022STom.Erickson@Sun.COM 185511022STom.Erickson@Sun.COM /* 185611022STom.Erickson@Sun.COM * If the named property is one that has a special function to set its value, 185711022STom.Erickson@Sun.COM * return 0 on success and a positive error code on failure; otherwise if it is 185811022STom.Erickson@Sun.COM * not one of the special properties handled by this function, return -1. 185911022STom.Erickson@Sun.COM * 186011022STom.Erickson@Sun.COM * XXX: It would be better for callers of the properety interface if we handled 186111022STom.Erickson@Sun.COM * these special cases in dsl_prop.c (in the dsl layer). 186211022STom.Erickson@Sun.COM */ 186311022STom.Erickson@Sun.COM static int 186411022STom.Erickson@Sun.COM zfs_prop_set_special(const char *dsname, zprop_source_t source, 186511022STom.Erickson@Sun.COM nvpair_t *pair) 1866789Sahrens { 186711022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 186811022STom.Erickson@Sun.COM zfs_prop_t prop = zfs_name_to_prop(propname); 186911022STom.Erickson@Sun.COM uint64_t intval; 187011022STom.Erickson@Sun.COM int err; 187111022STom.Erickson@Sun.COM 187211022STom.Erickson@Sun.COM if (prop == ZPROP_INVAL) { 187311022STom.Erickson@Sun.COM if (zfs_prop_userquota(propname)) 187411022STom.Erickson@Sun.COM return (zfs_prop_set_userquota(dsname, pair)); 187511022STom.Erickson@Sun.COM return (-1); 187611022STom.Erickson@Sun.COM } 187711022STom.Erickson@Sun.COM 187811022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_NVLIST) { 187911022STom.Erickson@Sun.COM nvlist_t *attrs; 188011022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(pair, &attrs) == 0); 188111022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 188211022STom.Erickson@Sun.COM &pair) == 0); 188311022STom.Erickson@Sun.COM } 188411022STom.Erickson@Sun.COM 188511022STom.Erickson@Sun.COM if (zfs_prop_get_type(prop) == PROP_TYPE_STRING) 188611022STom.Erickson@Sun.COM return (-1); 188711022STom.Erickson@Sun.COM 188811022STom.Erickson@Sun.COM VERIFY(0 == nvpair_value_uint64(pair, &intval)); 188911022STom.Erickson@Sun.COM 189011022STom.Erickson@Sun.COM switch (prop) { 189111022STom.Erickson@Sun.COM case ZFS_PROP_QUOTA: 189211022STom.Erickson@Sun.COM err = dsl_dir_set_quota(dsname, source, intval); 189311022STom.Erickson@Sun.COM break; 189411022STom.Erickson@Sun.COM case ZFS_PROP_REFQUOTA: 189511022STom.Erickson@Sun.COM err = dsl_dataset_set_quota(dsname, source, intval); 189611022STom.Erickson@Sun.COM break; 189711022STom.Erickson@Sun.COM case ZFS_PROP_RESERVATION: 189811022STom.Erickson@Sun.COM err = dsl_dir_set_reservation(dsname, source, intval); 189911022STom.Erickson@Sun.COM break; 190011022STom.Erickson@Sun.COM case ZFS_PROP_REFRESERVATION: 190111022STom.Erickson@Sun.COM err = dsl_dataset_set_reservation(dsname, source, intval); 190211022STom.Erickson@Sun.COM break; 190311022STom.Erickson@Sun.COM case ZFS_PROP_VOLSIZE: 190411022STom.Erickson@Sun.COM err = zvol_set_volsize(dsname, ddi_driver_major(zfs_dip), 190511022STom.Erickson@Sun.COM intval); 190611022STom.Erickson@Sun.COM break; 190711022STom.Erickson@Sun.COM case ZFS_PROP_VERSION: 190811022STom.Erickson@Sun.COM { 190911022STom.Erickson@Sun.COM zfsvfs_t *zfsvfs; 191011022STom.Erickson@Sun.COM 191111022STom.Erickson@Sun.COM if ((err = zfsvfs_hold(dsname, FTAG, &zfsvfs)) != 0) 191211022STom.Erickson@Sun.COM break; 191311022STom.Erickson@Sun.COM 191411022STom.Erickson@Sun.COM err = zfs_set_version(zfsvfs, intval); 191511022STom.Erickson@Sun.COM zfsvfs_rele(zfsvfs, FTAG); 191611022STom.Erickson@Sun.COM 191711022STom.Erickson@Sun.COM if (err == 0 && intval >= ZPL_VERSION_USERSPACE) { 191811147SGeorge.Wilson@Sun.COM zfs_cmd_t *zc; 191911147SGeorge.Wilson@Sun.COM 192011147SGeorge.Wilson@Sun.COM zc = kmem_zalloc(sizeof (zfs_cmd_t), KM_SLEEP); 192111147SGeorge.Wilson@Sun.COM (void) strcpy(zc->zc_name, dsname); 192211147SGeorge.Wilson@Sun.COM (void) zfs_ioc_userspace_upgrade(zc); 192311147SGeorge.Wilson@Sun.COM kmem_free(zc, sizeof (zfs_cmd_t)); 192411022STom.Erickson@Sun.COM } 192511022STom.Erickson@Sun.COM break; 192611022STom.Erickson@Sun.COM } 192711022STom.Erickson@Sun.COM 192811022STom.Erickson@Sun.COM default: 192911022STom.Erickson@Sun.COM err = -1; 193011022STom.Erickson@Sun.COM } 193111022STom.Erickson@Sun.COM 193211022STom.Erickson@Sun.COM return (err); 193311022STom.Erickson@Sun.COM } 193411022STom.Erickson@Sun.COM 193511022STom.Erickson@Sun.COM /* 193611022STom.Erickson@Sun.COM * This function is best effort. If it fails to set any of the given properties, 193711022STom.Erickson@Sun.COM * it continues to set as many as it can and returns the first error 193811022STom.Erickson@Sun.COM * encountered. If the caller provides a non-NULL errlist, it also gives the 193911022STom.Erickson@Sun.COM * complete list of names of all the properties it failed to set along with the 194011022STom.Erickson@Sun.COM * corresponding error numbers. The caller is responsible for freeing the 194111022STom.Erickson@Sun.COM * returned errlist. 194211022STom.Erickson@Sun.COM * 194311022STom.Erickson@Sun.COM * If every property is set successfully, zero is returned and the list pointed 194411022STom.Erickson@Sun.COM * at by errlist is NULL. 194511022STom.Erickson@Sun.COM */ 194611022STom.Erickson@Sun.COM int 194711022STom.Erickson@Sun.COM zfs_set_prop_nvlist(const char *dsname, zprop_source_t source, nvlist_t *nvl, 194811022STom.Erickson@Sun.COM nvlist_t **errlist) 194911022STom.Erickson@Sun.COM { 195011022STom.Erickson@Sun.COM nvpair_t *pair; 195111022STom.Erickson@Sun.COM nvpair_t *propval; 195211045STom.Erickson@Sun.COM int rv = 0; 19532676Seschrock uint64_t intval; 19542676Seschrock char *strval; 19558697SRichard.Morris@Sun.COM nvlist_t *genericnvl; 195611022STom.Erickson@Sun.COM nvlist_t *errors; 195711022STom.Erickson@Sun.COM nvlist_t *retrynvl; 19584543Smarks 19598697SRichard.Morris@Sun.COM VERIFY(nvlist_alloc(&genericnvl, NV_UNIQUE_NAME, KM_SLEEP) == 0); 196011022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(&errors, NV_UNIQUE_NAME, KM_SLEEP) == 0); 196111022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(&retrynvl, NV_UNIQUE_NAME, KM_SLEEP) == 0); 196211022STom.Erickson@Sun.COM 196311022STom.Erickson@Sun.COM retry: 196411022STom.Erickson@Sun.COM pair = NULL; 196511022STom.Erickson@Sun.COM while ((pair = nvlist_next_nvpair(nvl, pair)) != NULL) { 196611022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 19674670Sahrens zfs_prop_t prop = zfs_name_to_prop(propname); 196811181STom.Erickson@Sun.COM int err = 0; 19694543Smarks 197011022STom.Erickson@Sun.COM /* decode the property value */ 197111022STom.Erickson@Sun.COM propval = pair; 197211022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_NVLIST) { 197311022STom.Erickson@Sun.COM nvlist_t *attrs; 197411022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(pair, &attrs) == 0); 197511022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 197611022STom.Erickson@Sun.COM &propval) == 0); 19774543Smarks } 19782676Seschrock 197911022STom.Erickson@Sun.COM /* Validate value type */ 198011022STom.Erickson@Sun.COM if (prop == ZPROP_INVAL) { 198111022STom.Erickson@Sun.COM if (zfs_prop_user(propname)) { 198211022STom.Erickson@Sun.COM if (nvpair_type(propval) != DATA_TYPE_STRING) 198311022STom.Erickson@Sun.COM err = EINVAL; 198411022STom.Erickson@Sun.COM } else if (zfs_prop_userquota(propname)) { 198511022STom.Erickson@Sun.COM if (nvpair_type(propval) != 198611022STom.Erickson@Sun.COM DATA_TYPE_UINT64_ARRAY) 198711022STom.Erickson@Sun.COM err = EINVAL; 19889396SMatthew.Ahrens@Sun.COM } 198911022STom.Erickson@Sun.COM } else { 199011022STom.Erickson@Sun.COM if (nvpair_type(propval) == DATA_TYPE_STRING) { 199111022STom.Erickson@Sun.COM if (zfs_prop_get_type(prop) != PROP_TYPE_STRING) 199211022STom.Erickson@Sun.COM err = EINVAL; 199311022STom.Erickson@Sun.COM } else if (nvpair_type(propval) == DATA_TYPE_UINT64) { 19942885Sahrens const char *unused; 19952885Sahrens 199611022STom.Erickson@Sun.COM VERIFY(nvpair_value_uint64(propval, 199711022STom.Erickson@Sun.COM &intval) == 0); 19982676Seschrock 19992676Seschrock switch (zfs_prop_get_type(prop)) { 20004787Sahrens case PROP_TYPE_NUMBER: 20012676Seschrock break; 20024787Sahrens case PROP_TYPE_STRING: 200311022STom.Erickson@Sun.COM err = EINVAL; 200411022STom.Erickson@Sun.COM break; 20054787Sahrens case PROP_TYPE_INDEX: 20062717Seschrock if (zfs_prop_index_to_string(prop, 200711022STom.Erickson@Sun.COM intval, &unused) != 0) 200811022STom.Erickson@Sun.COM err = EINVAL; 20092676Seschrock break; 20102676Seschrock default: 20114577Sahrens cmn_err(CE_PANIC, 20124577Sahrens "unknown property type"); 20132676Seschrock } 20142676Seschrock } else { 201511022STom.Erickson@Sun.COM err = EINVAL; 201611022STom.Erickson@Sun.COM } 201711022STom.Erickson@Sun.COM } 201811022STom.Erickson@Sun.COM 201911022STom.Erickson@Sun.COM /* Validate permissions */ 202011022STom.Erickson@Sun.COM if (err == 0) 202111022STom.Erickson@Sun.COM err = zfs_check_settable(dsname, pair, CRED()); 202211022STom.Erickson@Sun.COM 202311022STom.Erickson@Sun.COM if (err == 0) { 202411022STom.Erickson@Sun.COM err = zfs_prop_set_special(dsname, source, pair); 202511022STom.Erickson@Sun.COM if (err == -1) { 202611022STom.Erickson@Sun.COM /* 202711022STom.Erickson@Sun.COM * For better performance we build up a list of 202811022STom.Erickson@Sun.COM * properties to set in a single transaction. 202911022STom.Erickson@Sun.COM */ 203011022STom.Erickson@Sun.COM err = nvlist_add_nvpair(genericnvl, pair); 203111022STom.Erickson@Sun.COM } else if (err != 0 && nvl != retrynvl) { 203211022STom.Erickson@Sun.COM /* 203311022STom.Erickson@Sun.COM * This may be a spurious error caused by 203411022STom.Erickson@Sun.COM * receiving quota and reservation out of order. 203511022STom.Erickson@Sun.COM * Try again in a second pass. 203611022STom.Erickson@Sun.COM */ 203711022STom.Erickson@Sun.COM err = nvlist_add_nvpair(retrynvl, pair); 20382676Seschrock } 203911022STom.Erickson@Sun.COM } 204011022STom.Erickson@Sun.COM 204111022STom.Erickson@Sun.COM if (err != 0) 204211022STom.Erickson@Sun.COM VERIFY(nvlist_add_int32(errors, propname, err) == 0); 204311022STom.Erickson@Sun.COM } 204411022STom.Erickson@Sun.COM 204511022STom.Erickson@Sun.COM if (nvl != retrynvl && !nvlist_empty(retrynvl)) { 204611022STom.Erickson@Sun.COM nvl = retrynvl; 204711022STom.Erickson@Sun.COM goto retry; 204811022STom.Erickson@Sun.COM } 204911022STom.Erickson@Sun.COM 205011022STom.Erickson@Sun.COM if (!nvlist_empty(genericnvl) && 205111022STom.Erickson@Sun.COM dsl_props_set(dsname, source, genericnvl) != 0) { 205211022STom.Erickson@Sun.COM /* 205311022STom.Erickson@Sun.COM * If this fails, we still want to set as many properties as we 205411022STom.Erickson@Sun.COM * can, so try setting them individually. 205511022STom.Erickson@Sun.COM */ 205611022STom.Erickson@Sun.COM pair = NULL; 205711022STom.Erickson@Sun.COM while ((pair = nvlist_next_nvpair(genericnvl, pair)) != NULL) { 205811022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 205911181STom.Erickson@Sun.COM int err = 0; 206011022STom.Erickson@Sun.COM 206111022STom.Erickson@Sun.COM propval = pair; 206211022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_NVLIST) { 206311022STom.Erickson@Sun.COM nvlist_t *attrs; 206411022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(pair, &attrs) == 0); 206511022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 206611022STom.Erickson@Sun.COM &propval) == 0); 206711022STom.Erickson@Sun.COM } 206811022STom.Erickson@Sun.COM 206911022STom.Erickson@Sun.COM if (nvpair_type(propval) == DATA_TYPE_STRING) { 207011022STom.Erickson@Sun.COM VERIFY(nvpair_value_string(propval, 207111022STom.Erickson@Sun.COM &strval) == 0); 207211022STom.Erickson@Sun.COM err = dsl_prop_set(dsname, propname, source, 1, 207311022STom.Erickson@Sun.COM strlen(strval) + 1, strval); 207411022STom.Erickson@Sun.COM } else { 207511022STom.Erickson@Sun.COM VERIFY(nvpair_value_uint64(propval, 207611022STom.Erickson@Sun.COM &intval) == 0); 207711022STom.Erickson@Sun.COM err = dsl_prop_set(dsname, propname, source, 8, 207811022STom.Erickson@Sun.COM 1, &intval); 207911022STom.Erickson@Sun.COM } 208011022STom.Erickson@Sun.COM 208111022STom.Erickson@Sun.COM if (err != 0) { 208211022STom.Erickson@Sun.COM VERIFY(nvlist_add_int32(errors, propname, 208311022STom.Erickson@Sun.COM err) == 0); 208411022STom.Erickson@Sun.COM } 20852676Seschrock } 20862676Seschrock } 208711022STom.Erickson@Sun.COM nvlist_free(genericnvl); 208811022STom.Erickson@Sun.COM nvlist_free(retrynvl); 208911022STom.Erickson@Sun.COM 209011022STom.Erickson@Sun.COM if ((pair = nvlist_next_nvpair(errors, NULL)) == NULL) { 209111022STom.Erickson@Sun.COM nvlist_free(errors); 209211022STom.Erickson@Sun.COM errors = NULL; 209311022STom.Erickson@Sun.COM } else { 209411022STom.Erickson@Sun.COM VERIFY(nvpair_value_int32(pair, &rv) == 0); 20958697SRichard.Morris@Sun.COM } 209611022STom.Erickson@Sun.COM 209711022STom.Erickson@Sun.COM if (errlist == NULL) 209811022STom.Erickson@Sun.COM nvlist_free(errors); 209911022STom.Erickson@Sun.COM else 210011022STom.Erickson@Sun.COM *errlist = errors; 210111022STom.Erickson@Sun.COM 210211022STom.Erickson@Sun.COM return (rv); 2103789Sahrens } 2104789Sahrens 21055367Sahrens /* 21069355SMatthew.Ahrens@Sun.COM * Check that all the properties are valid user properties. 21079355SMatthew.Ahrens@Sun.COM */ 21089355SMatthew.Ahrens@Sun.COM static int 21099355SMatthew.Ahrens@Sun.COM zfs_check_userprops(char *fsname, nvlist_t *nvl) 21109355SMatthew.Ahrens@Sun.COM { 211111022STom.Erickson@Sun.COM nvpair_t *pair = NULL; 21129355SMatthew.Ahrens@Sun.COM int error = 0; 21139355SMatthew.Ahrens@Sun.COM 211411022STom.Erickson@Sun.COM while ((pair = nvlist_next_nvpair(nvl, pair)) != NULL) { 211511022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 21169355SMatthew.Ahrens@Sun.COM char *valstr; 21179355SMatthew.Ahrens@Sun.COM 21189355SMatthew.Ahrens@Sun.COM if (!zfs_prop_user(propname) || 211911022STom.Erickson@Sun.COM nvpair_type(pair) != DATA_TYPE_STRING) 21209355SMatthew.Ahrens@Sun.COM return (EINVAL); 21219355SMatthew.Ahrens@Sun.COM 21229355SMatthew.Ahrens@Sun.COM if (error = zfs_secpolicy_write_perms(fsname, 21239355SMatthew.Ahrens@Sun.COM ZFS_DELEG_PERM_USERPROP, CRED())) 21249355SMatthew.Ahrens@Sun.COM return (error); 21259355SMatthew.Ahrens@Sun.COM 21269355SMatthew.Ahrens@Sun.COM if (strlen(propname) >= ZAP_MAXNAMELEN) 21279355SMatthew.Ahrens@Sun.COM return (ENAMETOOLONG); 21289355SMatthew.Ahrens@Sun.COM 212911022STom.Erickson@Sun.COM VERIFY(nvpair_value_string(pair, &valstr) == 0); 21309355SMatthew.Ahrens@Sun.COM if (strlen(valstr) >= ZAP_MAXVALUELEN) 21319355SMatthew.Ahrens@Sun.COM return (E2BIG); 21329355SMatthew.Ahrens@Sun.COM } 21339355SMatthew.Ahrens@Sun.COM return (0); 21349355SMatthew.Ahrens@Sun.COM } 21359355SMatthew.Ahrens@Sun.COM 213611022STom.Erickson@Sun.COM static void 213711022STom.Erickson@Sun.COM props_skip(nvlist_t *props, nvlist_t *skipped, nvlist_t **newprops) 213811022STom.Erickson@Sun.COM { 213911022STom.Erickson@Sun.COM nvpair_t *pair; 214011022STom.Erickson@Sun.COM 214111022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(newprops, NV_UNIQUE_NAME, KM_SLEEP) == 0); 214211022STom.Erickson@Sun.COM 214311022STom.Erickson@Sun.COM pair = NULL; 214411022STom.Erickson@Sun.COM while ((pair = nvlist_next_nvpair(props, pair)) != NULL) { 214511022STom.Erickson@Sun.COM if (nvlist_exists(skipped, nvpair_name(pair))) 214611022STom.Erickson@Sun.COM continue; 214711022STom.Erickson@Sun.COM 214811022STom.Erickson@Sun.COM VERIFY(nvlist_add_nvpair(*newprops, pair) == 0); 214911022STom.Erickson@Sun.COM } 215011022STom.Erickson@Sun.COM } 215111022STom.Erickson@Sun.COM 215211022STom.Erickson@Sun.COM static int 215311022STom.Erickson@Sun.COM clear_received_props(objset_t *os, const char *fs, nvlist_t *props, 215411022STom.Erickson@Sun.COM nvlist_t *skipped) 215511022STom.Erickson@Sun.COM { 215611022STom.Erickson@Sun.COM int err = 0; 215711022STom.Erickson@Sun.COM nvlist_t *cleared_props = NULL; 215811022STom.Erickson@Sun.COM props_skip(props, skipped, &cleared_props); 215911022STom.Erickson@Sun.COM if (!nvlist_empty(cleared_props)) { 216011022STom.Erickson@Sun.COM /* 216111022STom.Erickson@Sun.COM * Acts on local properties until the dataset has received 216211022STom.Erickson@Sun.COM * properties at least once on or after SPA_VERSION_RECVD_PROPS. 216311022STom.Erickson@Sun.COM */ 216411022STom.Erickson@Sun.COM zprop_source_t flags = (ZPROP_SRC_NONE | 216511022STom.Erickson@Sun.COM (dsl_prop_get_hasrecvd(os) ? ZPROP_SRC_RECEIVED : 0)); 216611022STom.Erickson@Sun.COM err = zfs_set_prop_nvlist(fs, flags, cleared_props, NULL); 216711022STom.Erickson@Sun.COM } 216811022STom.Erickson@Sun.COM nvlist_free(cleared_props); 216911022STom.Erickson@Sun.COM return (err); 217011022STom.Erickson@Sun.COM } 217111022STom.Erickson@Sun.COM 21729355SMatthew.Ahrens@Sun.COM /* 21735367Sahrens * inputs: 21745367Sahrens * zc_name name of filesystem 21758697SRichard.Morris@Sun.COM * zc_value name of property to set 21765367Sahrens * zc_nvlist_src{_size} nvlist of properties to apply 217711022STom.Erickson@Sun.COM * zc_cookie received properties flag 21785367Sahrens * 217911022STom.Erickson@Sun.COM * outputs: 218011022STom.Erickson@Sun.COM * zc_nvlist_dst{_size} error for each unapplied received property 21815367Sahrens */ 2182789Sahrens static int 21832676Seschrock zfs_ioc_set_prop(zfs_cmd_t *zc) 2184789Sahrens { 21852676Seschrock nvlist_t *nvl; 218611022STom.Erickson@Sun.COM boolean_t received = zc->zc_cookie; 218711022STom.Erickson@Sun.COM zprop_source_t source = (received ? ZPROP_SRC_RECEIVED : 218811022STom.Erickson@Sun.COM ZPROP_SRC_LOCAL); 218911022STom.Erickson@Sun.COM nvlist_t *errors = NULL; 21902676Seschrock int error; 2191789Sahrens 21925094Slling if ((error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 21939643SEric.Taylor@Sun.COM zc->zc_iflags, &nvl)) != 0) 21942676Seschrock return (error); 21952676Seschrock 219611022STom.Erickson@Sun.COM if (received) { 21977265Sahrens nvlist_t *origprops; 21987265Sahrens objset_t *os; 21997265Sahrens 220010298SMatthew.Ahrens@Sun.COM if (dmu_objset_hold(zc->zc_name, FTAG, &os) == 0) { 220111022STom.Erickson@Sun.COM if (dsl_prop_get_received(os, &origprops) == 0) { 220211022STom.Erickson@Sun.COM (void) clear_received_props(os, 220311022STom.Erickson@Sun.COM zc->zc_name, origprops, nvl); 22047265Sahrens nvlist_free(origprops); 22057265Sahrens } 220611022STom.Erickson@Sun.COM 220711022STom.Erickson@Sun.COM dsl_prop_set_hasrecvd(os); 220810298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 22097265Sahrens } 22107265Sahrens } 22117265Sahrens 221211022STom.Erickson@Sun.COM error = zfs_set_prop_nvlist(zc->zc_name, source, nvl, &errors); 221311022STom.Erickson@Sun.COM 221411022STom.Erickson@Sun.COM if (zc->zc_nvlist_dst != NULL && errors != NULL) { 221511022STom.Erickson@Sun.COM (void) put_nvlist(zc, errors); 221611022STom.Erickson@Sun.COM } 221711022STom.Erickson@Sun.COM 221811022STom.Erickson@Sun.COM nvlist_free(errors); 22192676Seschrock nvlist_free(nvl); 22202676Seschrock return (error); 2221789Sahrens } 2222789Sahrens 22235367Sahrens /* 22245367Sahrens * inputs: 22255367Sahrens * zc_name name of filesystem 22265367Sahrens * zc_value name of property to inherit 222711022STom.Erickson@Sun.COM * zc_cookie revert to received value if TRUE 22285367Sahrens * 22295367Sahrens * outputs: none 22305367Sahrens */ 2231789Sahrens static int 22324849Sahrens zfs_ioc_inherit_prop(zfs_cmd_t *zc) 22334849Sahrens { 223411022STom.Erickson@Sun.COM const char *propname = zc->zc_value; 223511022STom.Erickson@Sun.COM zfs_prop_t prop = zfs_name_to_prop(propname); 223611022STom.Erickson@Sun.COM boolean_t received = zc->zc_cookie; 223711022STom.Erickson@Sun.COM zprop_source_t source = (received 223811022STom.Erickson@Sun.COM ? ZPROP_SRC_NONE /* revert to received value, if any */ 223911022STom.Erickson@Sun.COM : ZPROP_SRC_INHERITED); /* explicitly inherit */ 224011022STom.Erickson@Sun.COM 224111022STom.Erickson@Sun.COM if (received) { 224211022STom.Erickson@Sun.COM nvlist_t *dummy; 224311022STom.Erickson@Sun.COM nvpair_t *pair; 224411022STom.Erickson@Sun.COM zprop_type_t type; 224511022STom.Erickson@Sun.COM int err; 224611022STom.Erickson@Sun.COM 224711022STom.Erickson@Sun.COM /* 224811022STom.Erickson@Sun.COM * zfs_prop_set_special() expects properties in the form of an 224911022STom.Erickson@Sun.COM * nvpair with type info. 225011022STom.Erickson@Sun.COM */ 225111022STom.Erickson@Sun.COM if (prop == ZPROP_INVAL) { 225211022STom.Erickson@Sun.COM if (!zfs_prop_user(propname)) 225311022STom.Erickson@Sun.COM return (EINVAL); 225411022STom.Erickson@Sun.COM 225511022STom.Erickson@Sun.COM type = PROP_TYPE_STRING; 225611022STom.Erickson@Sun.COM } else { 225711022STom.Erickson@Sun.COM type = zfs_prop_get_type(prop); 225811022STom.Erickson@Sun.COM } 225911022STom.Erickson@Sun.COM 226011022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(&dummy, NV_UNIQUE_NAME, KM_SLEEP) == 0); 226111022STom.Erickson@Sun.COM 226211022STom.Erickson@Sun.COM switch (type) { 226311022STom.Erickson@Sun.COM case PROP_TYPE_STRING: 226411022STom.Erickson@Sun.COM VERIFY(0 == nvlist_add_string(dummy, propname, "")); 226511022STom.Erickson@Sun.COM break; 226611022STom.Erickson@Sun.COM case PROP_TYPE_NUMBER: 226711022STom.Erickson@Sun.COM case PROP_TYPE_INDEX: 226811022STom.Erickson@Sun.COM VERIFY(0 == nvlist_add_uint64(dummy, propname, 0)); 226911022STom.Erickson@Sun.COM break; 227011022STom.Erickson@Sun.COM default: 227111022STom.Erickson@Sun.COM nvlist_free(dummy); 227211022STom.Erickson@Sun.COM return (EINVAL); 227311022STom.Erickson@Sun.COM } 227411022STom.Erickson@Sun.COM 227511022STom.Erickson@Sun.COM pair = nvlist_next_nvpair(dummy, NULL); 227611022STom.Erickson@Sun.COM err = zfs_prop_set_special(zc->zc_name, source, pair); 227711022STom.Erickson@Sun.COM nvlist_free(dummy); 227811022STom.Erickson@Sun.COM if (err != -1) 227911022STom.Erickson@Sun.COM return (err); /* special property already handled */ 228011022STom.Erickson@Sun.COM } else { 228111022STom.Erickson@Sun.COM /* 228211022STom.Erickson@Sun.COM * Only check this in the non-received case. We want to allow 228311022STom.Erickson@Sun.COM * 'inherit -S' to revert non-inheritable properties like quota 228411022STom.Erickson@Sun.COM * and reservation to the received or default values even though 228511022STom.Erickson@Sun.COM * they are not considered inheritable. 228611022STom.Erickson@Sun.COM */ 228711022STom.Erickson@Sun.COM if (prop != ZPROP_INVAL && !zfs_prop_inheritable(prop)) 228811022STom.Erickson@Sun.COM return (EINVAL); 228911022STom.Erickson@Sun.COM } 229011022STom.Erickson@Sun.COM 22914849Sahrens /* the property name has been validated by zfs_secpolicy_inherit() */ 229211022STom.Erickson@Sun.COM return (dsl_prop_set(zc->zc_name, zc->zc_value, source, 0, 0, NULL)); 22934849Sahrens } 22944849Sahrens 22954849Sahrens static int 22964098Slling zfs_ioc_pool_set_props(zfs_cmd_t *zc) 22973912Slling { 22985094Slling nvlist_t *props; 22993912Slling spa_t *spa; 23005094Slling int error; 230111022STom.Erickson@Sun.COM nvpair_t *pair; 230211022STom.Erickson@Sun.COM 230311022STom.Erickson@Sun.COM if (error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 230411022STom.Erickson@Sun.COM zc->zc_iflags, &props)) 23053912Slling return (error); 23063912Slling 23078525SEric.Schrock@Sun.COM /* 23088525SEric.Schrock@Sun.COM * If the only property is the configfile, then just do a spa_lookup() 23098525SEric.Schrock@Sun.COM * to handle the faulted case. 23108525SEric.Schrock@Sun.COM */ 231111022STom.Erickson@Sun.COM pair = nvlist_next_nvpair(props, NULL); 231211022STom.Erickson@Sun.COM if (pair != NULL && strcmp(nvpair_name(pair), 23138525SEric.Schrock@Sun.COM zpool_prop_to_name(ZPOOL_PROP_CACHEFILE)) == 0 && 231411022STom.Erickson@Sun.COM nvlist_next_nvpair(props, pair) == NULL) { 23158525SEric.Schrock@Sun.COM mutex_enter(&spa_namespace_lock); 23168525SEric.Schrock@Sun.COM if ((spa = spa_lookup(zc->zc_name)) != NULL) { 23178525SEric.Schrock@Sun.COM spa_configfile_set(spa, props, B_FALSE); 23188525SEric.Schrock@Sun.COM spa_config_sync(spa, B_FALSE, B_TRUE); 23198525SEric.Schrock@Sun.COM } 23208525SEric.Schrock@Sun.COM mutex_exit(&spa_namespace_lock); 232110672SEric.Schrock@Sun.COM if (spa != NULL) { 232210672SEric.Schrock@Sun.COM nvlist_free(props); 23238525SEric.Schrock@Sun.COM return (0); 232410672SEric.Schrock@Sun.COM } 23258525SEric.Schrock@Sun.COM } 23268525SEric.Schrock@Sun.COM 23273912Slling if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) { 23285094Slling nvlist_free(props); 23293912Slling return (error); 23303912Slling } 23313912Slling 23325094Slling error = spa_prop_set(spa, props); 23333912Slling 23345094Slling nvlist_free(props); 23353912Slling spa_close(spa, FTAG); 23363912Slling 23373912Slling return (error); 23383912Slling } 23393912Slling 23403912Slling static int 23414098Slling zfs_ioc_pool_get_props(zfs_cmd_t *zc) 23423912Slling { 23433912Slling spa_t *spa; 23443912Slling int error; 23453912Slling nvlist_t *nvp = NULL; 23463912Slling 23478525SEric.Schrock@Sun.COM if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) { 23488525SEric.Schrock@Sun.COM /* 23498525SEric.Schrock@Sun.COM * If the pool is faulted, there may be properties we can still 23508525SEric.Schrock@Sun.COM * get (such as altroot and cachefile), so attempt to get them 23518525SEric.Schrock@Sun.COM * anyway. 23528525SEric.Schrock@Sun.COM */ 23538525SEric.Schrock@Sun.COM mutex_enter(&spa_namespace_lock); 23548525SEric.Schrock@Sun.COM if ((spa = spa_lookup(zc->zc_name)) != NULL) 23558525SEric.Schrock@Sun.COM error = spa_prop_get(spa, &nvp); 23568525SEric.Schrock@Sun.COM mutex_exit(&spa_namespace_lock); 23578525SEric.Schrock@Sun.COM } else { 23588525SEric.Schrock@Sun.COM error = spa_prop_get(spa, &nvp); 23598525SEric.Schrock@Sun.COM spa_close(spa, FTAG); 23608525SEric.Schrock@Sun.COM } 23613912Slling 23623912Slling if (error == 0 && zc->zc_nvlist_dst != NULL) 23633912Slling error = put_nvlist(zc, nvp); 23643912Slling else 23653912Slling error = EFAULT; 23663912Slling 23678525SEric.Schrock@Sun.COM nvlist_free(nvp); 23683912Slling return (error); 23693912Slling } 23703912Slling 23713912Slling static int 23724543Smarks zfs_ioc_iscsi_perm_check(zfs_cmd_t *zc) 23734543Smarks { 23744543Smarks nvlist_t *nvp; 23754543Smarks int error; 23764543Smarks uint32_t uid; 23774543Smarks uint32_t gid; 23784543Smarks uint32_t *groups; 23794543Smarks uint_t group_cnt; 23804543Smarks cred_t *usercred; 23814543Smarks 23825094Slling if ((error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 23839643SEric.Taylor@Sun.COM zc->zc_iflags, &nvp)) != 0) { 23844543Smarks return (error); 23854543Smarks } 23864543Smarks 23874543Smarks if ((error = nvlist_lookup_uint32(nvp, 23884543Smarks ZFS_DELEG_PERM_UID, &uid)) != 0) { 23894543Smarks nvlist_free(nvp); 23904543Smarks return (EPERM); 23914543Smarks } 23924543Smarks 23934543Smarks if ((error = nvlist_lookup_uint32(nvp, 23944543Smarks ZFS_DELEG_PERM_GID, &gid)) != 0) { 23954543Smarks nvlist_free(nvp); 23964543Smarks return (EPERM); 23974543Smarks } 23984543Smarks 23994543Smarks if ((error = nvlist_lookup_uint32_array(nvp, ZFS_DELEG_PERM_GROUPS, 24004543Smarks &groups, &group_cnt)) != 0) { 24014543Smarks nvlist_free(nvp); 24024543Smarks return (EPERM); 24034543Smarks } 24044543Smarks usercred = cralloc(); 24054543Smarks if ((crsetugid(usercred, uid, gid) != 0) || 24064543Smarks (crsetgroups(usercred, group_cnt, (gid_t *)groups) != 0)) { 24074543Smarks nvlist_free(nvp); 24084543Smarks crfree(usercred); 24094543Smarks return (EPERM); 24104543Smarks } 24114543Smarks nvlist_free(nvp); 24124543Smarks error = dsl_deleg_access(zc->zc_name, 24134787Sahrens zfs_prop_to_name(ZFS_PROP_SHAREISCSI), usercred); 24144543Smarks crfree(usercred); 24154543Smarks return (error); 24164543Smarks } 24174543Smarks 24185367Sahrens /* 24195367Sahrens * inputs: 24205367Sahrens * zc_name name of filesystem 24215367Sahrens * zc_nvlist_src{_size} nvlist of delegated permissions 24225367Sahrens * zc_perm_action allow/unallow flag 24235367Sahrens * 24245367Sahrens * outputs: none 24255367Sahrens */ 24264543Smarks static int 24274543Smarks zfs_ioc_set_fsacl(zfs_cmd_t *zc) 24284543Smarks { 24294543Smarks int error; 24304543Smarks nvlist_t *fsaclnv = NULL; 24314543Smarks 24325094Slling if ((error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 24339643SEric.Taylor@Sun.COM zc->zc_iflags, &fsaclnv)) != 0) 24344543Smarks return (error); 24354543Smarks 24364543Smarks /* 24374543Smarks * Verify nvlist is constructed correctly 24384543Smarks */ 24394543Smarks if ((error = zfs_deleg_verify_nvlist(fsaclnv)) != 0) { 24404543Smarks nvlist_free(fsaclnv); 24414543Smarks return (EINVAL); 24424543Smarks } 24434543Smarks 24444543Smarks /* 24454543Smarks * If we don't have PRIV_SYS_MOUNT, then validate 24464543Smarks * that user is allowed to hand out each permission in 24474543Smarks * the nvlist(s) 24484543Smarks */ 24494543Smarks 24504787Sahrens error = secpolicy_zfs(CRED()); 24514543Smarks if (error) { 24524787Sahrens if (zc->zc_perm_action == B_FALSE) { 24534787Sahrens error = dsl_deleg_can_allow(zc->zc_name, 24544787Sahrens fsaclnv, CRED()); 24554787Sahrens } else { 24564787Sahrens error = dsl_deleg_can_unallow(zc->zc_name, 24574787Sahrens fsaclnv, CRED()); 24584787Sahrens } 24594543Smarks } 24604543Smarks 24614543Smarks if (error == 0) 24624543Smarks error = dsl_deleg_set(zc->zc_name, fsaclnv, zc->zc_perm_action); 24634543Smarks 24644543Smarks nvlist_free(fsaclnv); 24654543Smarks return (error); 24664543Smarks } 24674543Smarks 24685367Sahrens /* 24695367Sahrens * inputs: 24705367Sahrens * zc_name name of filesystem 24715367Sahrens * 24725367Sahrens * outputs: 24735367Sahrens * zc_nvlist_src{_size} nvlist of delegated permissions 24745367Sahrens */ 24754543Smarks static int 24764543Smarks zfs_ioc_get_fsacl(zfs_cmd_t *zc) 24774543Smarks { 24784543Smarks nvlist_t *nvp; 24794543Smarks int error; 24804543Smarks 24814543Smarks if ((error = dsl_deleg_get(zc->zc_name, &nvp)) == 0) { 24824543Smarks error = put_nvlist(zc, nvp); 24834543Smarks nvlist_free(nvp); 24844543Smarks } 24854543Smarks 24864543Smarks return (error); 24874543Smarks } 24884543Smarks 24895367Sahrens /* 2490789Sahrens * Search the vfs list for a specified resource. Returns a pointer to it 2491789Sahrens * or NULL if no suitable entry is found. The caller of this routine 2492789Sahrens * is responsible for releasing the returned vfs pointer. 2493789Sahrens */ 2494789Sahrens static vfs_t * 2495789Sahrens zfs_get_vfs(const char *resource) 2496789Sahrens { 2497789Sahrens struct vfs *vfsp; 2498789Sahrens struct vfs *vfs_found = NULL; 2499789Sahrens 2500789Sahrens vfs_list_read_lock(); 2501789Sahrens vfsp = rootvfs; 2502789Sahrens do { 2503789Sahrens if (strcmp(refstr_value(vfsp->vfs_resource), resource) == 0) { 2504789Sahrens VFS_HOLD(vfsp); 2505789Sahrens vfs_found = vfsp; 2506789Sahrens break; 2507789Sahrens } 2508789Sahrens vfsp = vfsp->vfs_next; 2509789Sahrens } while (vfsp != rootvfs); 2510789Sahrens vfs_list_unlock(); 2511789Sahrens return (vfs_found); 2512789Sahrens } 2513789Sahrens 25144543Smarks /* ARGSUSED */ 2515789Sahrens static void 25164543Smarks zfs_create_cb(objset_t *os, void *arg, cred_t *cr, dmu_tx_t *tx) 2517789Sahrens { 25185331Samw zfs_creat_t *zct = arg; 25195498Stimh 25205498Stimh zfs_create_fs(os, cr, zct->zct_zplprops, tx); 25215331Samw } 25225331Samw 25235498Stimh #define ZFS_PROP_UNDEFINED ((uint64_t)-1) 25245498Stimh 25255331Samw /* 25265498Stimh * inputs: 25277184Stimh * createprops list of properties requested by creator 25287184Stimh * default_zplver zpl version to use if unspecified in createprops 25297184Stimh * fuids_ok fuids allowed in this version of the spa? 25307184Stimh * os parent objset pointer (NULL if root fs) 25315331Samw * 25325498Stimh * outputs: 25335498Stimh * zplprops values for the zplprops we attach to the master node object 25347184Stimh * is_ci true if requested file system will be purely case-insensitive 25355331Samw * 25365498Stimh * Determine the settings for utf8only, normalization and 25375498Stimh * casesensitivity. Specific values may have been requested by the 25385498Stimh * creator and/or we can inherit values from the parent dataset. If 25395498Stimh * the file system is of too early a vintage, a creator can not 25405498Stimh * request settings for these properties, even if the requested 25415498Stimh * setting is the default value. We don't actually want to create dsl 25425498Stimh * properties for these, so remove them from the source nvlist after 25435498Stimh * processing. 25445331Samw */ 25455331Samw static int 25469396SMatthew.Ahrens@Sun.COM zfs_fill_zplprops_impl(objset_t *os, uint64_t zplver, 25477184Stimh boolean_t fuids_ok, nvlist_t *createprops, nvlist_t *zplprops, 25487184Stimh boolean_t *is_ci) 25495331Samw { 25505498Stimh uint64_t sense = ZFS_PROP_UNDEFINED; 25515498Stimh uint64_t norm = ZFS_PROP_UNDEFINED; 25525498Stimh uint64_t u8 = ZFS_PROP_UNDEFINED; 25535498Stimh 25545498Stimh ASSERT(zplprops != NULL); 25555498Stimh 25565375Stimh /* 25575498Stimh * Pull out creator prop choices, if any. 25585375Stimh */ 25595498Stimh if (createprops) { 25605498Stimh (void) nvlist_lookup_uint64(createprops, 25617184Stimh zfs_prop_to_name(ZFS_PROP_VERSION), &zplver); 25627184Stimh (void) nvlist_lookup_uint64(createprops, 25635498Stimh zfs_prop_to_name(ZFS_PROP_NORMALIZE), &norm); 25645498Stimh (void) nvlist_remove_all(createprops, 25655498Stimh zfs_prop_to_name(ZFS_PROP_NORMALIZE)); 25665498Stimh (void) nvlist_lookup_uint64(createprops, 25675498Stimh zfs_prop_to_name(ZFS_PROP_UTF8ONLY), &u8); 25685498Stimh (void) nvlist_remove_all(createprops, 25695498Stimh zfs_prop_to_name(ZFS_PROP_UTF8ONLY)); 25705498Stimh (void) nvlist_lookup_uint64(createprops, 25715498Stimh zfs_prop_to_name(ZFS_PROP_CASE), &sense); 25725498Stimh (void) nvlist_remove_all(createprops, 25735498Stimh zfs_prop_to_name(ZFS_PROP_CASE)); 25745331Samw } 25755331Samw 25765375Stimh /* 25777184Stimh * If the zpl version requested is whacky or the file system 25787184Stimh * or pool is version is too "young" to support normalization 25797184Stimh * and the creator tried to set a value for one of the props, 25807184Stimh * error out. 25815498Stimh */ 25827184Stimh if ((zplver < ZPL_VERSION_INITIAL || zplver > ZPL_VERSION) || 25837184Stimh (zplver >= ZPL_VERSION_FUID && !fuids_ok) || 25847184Stimh (zplver < ZPL_VERSION_NORMALIZATION && 25855498Stimh (norm != ZFS_PROP_UNDEFINED || u8 != ZFS_PROP_UNDEFINED || 25867184Stimh sense != ZFS_PROP_UNDEFINED))) 25875498Stimh return (ENOTSUP); 25885498Stimh 25895498Stimh /* 25905498Stimh * Put the version in the zplprops 25915498Stimh */ 25925498Stimh VERIFY(nvlist_add_uint64(zplprops, 25935498Stimh zfs_prop_to_name(ZFS_PROP_VERSION), zplver) == 0); 25945498Stimh 25955498Stimh if (norm == ZFS_PROP_UNDEFINED) 25965498Stimh VERIFY(zfs_get_zplprop(os, ZFS_PROP_NORMALIZE, &norm) == 0); 25975498Stimh VERIFY(nvlist_add_uint64(zplprops, 25985498Stimh zfs_prop_to_name(ZFS_PROP_NORMALIZE), norm) == 0); 25995498Stimh 26005498Stimh /* 26015498Stimh * If we're normalizing, names must always be valid UTF-8 strings. 26025498Stimh */ 26035498Stimh if (norm) 26045498Stimh u8 = 1; 26055498Stimh if (u8 == ZFS_PROP_UNDEFINED) 26065498Stimh VERIFY(zfs_get_zplprop(os, ZFS_PROP_UTF8ONLY, &u8) == 0); 26075498Stimh VERIFY(nvlist_add_uint64(zplprops, 26085498Stimh zfs_prop_to_name(ZFS_PROP_UTF8ONLY), u8) == 0); 26095498Stimh 26105498Stimh if (sense == ZFS_PROP_UNDEFINED) 26115498Stimh VERIFY(zfs_get_zplprop(os, ZFS_PROP_CASE, &sense) == 0); 26125498Stimh VERIFY(nvlist_add_uint64(zplprops, 26135498Stimh zfs_prop_to_name(ZFS_PROP_CASE), sense) == 0); 26145498Stimh 26156492Stimh if (is_ci) 26166492Stimh *is_ci = (sense == ZFS_CASE_INSENSITIVE); 26176492Stimh 26187184Stimh return (0); 26197184Stimh } 26207184Stimh 26217184Stimh static int 26227184Stimh zfs_fill_zplprops(const char *dataset, nvlist_t *createprops, 26237184Stimh nvlist_t *zplprops, boolean_t *is_ci) 26247184Stimh { 26257184Stimh boolean_t fuids_ok = B_TRUE; 26267184Stimh uint64_t zplver = ZPL_VERSION; 26277184Stimh objset_t *os = NULL; 26287184Stimh char parentname[MAXNAMELEN]; 26297184Stimh char *cp; 26307184Stimh int error; 26317184Stimh 26327184Stimh (void) strlcpy(parentname, dataset, sizeof (parentname)); 26337184Stimh cp = strrchr(parentname, '/'); 26347184Stimh ASSERT(cp != NULL); 26357184Stimh cp[0] = '\0'; 26367184Stimh 26379396SMatthew.Ahrens@Sun.COM if (zfs_earlier_version(dataset, SPA_VERSION_USERSPACE)) 26389396SMatthew.Ahrens@Sun.COM zplver = ZPL_VERSION_USERSPACE - 1; 26397184Stimh if (zfs_earlier_version(dataset, SPA_VERSION_FUID)) { 26407184Stimh zplver = ZPL_VERSION_FUID - 1; 26417184Stimh fuids_ok = B_FALSE; 26427184Stimh } 26437184Stimh 26447184Stimh /* 26457184Stimh * Open parent object set so we can inherit zplprop values. 26467184Stimh */ 264710298SMatthew.Ahrens@Sun.COM if ((error = dmu_objset_hold(parentname, FTAG, &os)) != 0) 26487184Stimh return (error); 26497184Stimh 26507184Stimh error = zfs_fill_zplprops_impl(os, zplver, fuids_ok, createprops, 26517184Stimh zplprops, is_ci); 265210298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 26537184Stimh return (error); 26547184Stimh } 26557184Stimh 26567184Stimh static int 26577184Stimh zfs_fill_zplprops_root(uint64_t spa_vers, nvlist_t *createprops, 26587184Stimh nvlist_t *zplprops, boolean_t *is_ci) 26597184Stimh { 26607184Stimh boolean_t fuids_ok = B_TRUE; 26617184Stimh uint64_t zplver = ZPL_VERSION; 26627184Stimh int error; 26637184Stimh 26647184Stimh if (spa_vers < SPA_VERSION_FUID) { 26657184Stimh zplver = ZPL_VERSION_FUID - 1; 26667184Stimh fuids_ok = B_FALSE; 26677184Stimh } 26687184Stimh 26697184Stimh error = zfs_fill_zplprops_impl(NULL, zplver, fuids_ok, createprops, 26707184Stimh zplprops, is_ci); 26717184Stimh return (error); 2672789Sahrens } 2673789Sahrens 26745367Sahrens /* 26755367Sahrens * inputs: 26765367Sahrens * zc_objset_type type of objset to create (fs vs zvol) 26775367Sahrens * zc_name name of new objset 26785367Sahrens * zc_value name of snapshot to clone from (may be empty) 26795367Sahrens * zc_nvlist_src{_size} nvlist of properties to apply 26805367Sahrens * 26815498Stimh * outputs: none 26825367Sahrens */ 2683789Sahrens static int 2684789Sahrens zfs_ioc_create(zfs_cmd_t *zc) 2685789Sahrens { 2686789Sahrens objset_t *clone; 2687789Sahrens int error = 0; 26885331Samw zfs_creat_t zct; 26894543Smarks nvlist_t *nvprops = NULL; 26904543Smarks void (*cbfunc)(objset_t *os, void *arg, cred_t *cr, dmu_tx_t *tx); 2691789Sahrens dmu_objset_type_t type = zc->zc_objset_type; 2692789Sahrens 2693789Sahrens switch (type) { 2694789Sahrens 2695789Sahrens case DMU_OST_ZFS: 2696789Sahrens cbfunc = zfs_create_cb; 2697789Sahrens break; 2698789Sahrens 2699789Sahrens case DMU_OST_ZVOL: 2700789Sahrens cbfunc = zvol_create_cb; 2701789Sahrens break; 2702789Sahrens 2703789Sahrens default: 27042199Sahrens cbfunc = NULL; 27056423Sgw25295 break; 27062199Sahrens } 27075326Sek110237 if (strchr(zc->zc_name, '@') || 27085326Sek110237 strchr(zc->zc_name, '%')) 2709789Sahrens return (EINVAL); 2710789Sahrens 27112676Seschrock if (zc->zc_nvlist_src != NULL && 27125094Slling (error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 27139643SEric.Taylor@Sun.COM zc->zc_iflags, &nvprops)) != 0) 27142676Seschrock return (error); 27152676Seschrock 27165498Stimh zct.zct_zplprops = NULL; 27175331Samw zct.zct_props = nvprops; 27185331Samw 27192676Seschrock if (zc->zc_value[0] != '\0') { 2720789Sahrens /* 2721789Sahrens * We're creating a clone of an existing snapshot. 2722789Sahrens */ 27232676Seschrock zc->zc_value[sizeof (zc->zc_value) - 1] = '\0'; 27242676Seschrock if (dataset_namecheck(zc->zc_value, NULL, NULL) != 0) { 27254543Smarks nvlist_free(nvprops); 2726789Sahrens return (EINVAL); 27272676Seschrock } 2728789Sahrens 272910298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_value, FTAG, &clone); 27302676Seschrock if (error) { 27314543Smarks nvlist_free(nvprops); 2732789Sahrens return (error); 27332676Seschrock } 27346492Stimh 273510272SMatthew.Ahrens@Sun.COM error = dmu_objset_clone(zc->zc_name, dmu_objset_ds(clone), 0); 273610298SMatthew.Ahrens@Sun.COM dmu_objset_rele(clone, FTAG); 27375331Samw if (error) { 27385331Samw nvlist_free(nvprops); 27395331Samw return (error); 27405331Samw } 2741789Sahrens } else { 27426492Stimh boolean_t is_insensitive = B_FALSE; 27436492Stimh 27442676Seschrock if (cbfunc == NULL) { 27454543Smarks nvlist_free(nvprops); 27462199Sahrens return (EINVAL); 27472676Seschrock } 27482676Seschrock 2749789Sahrens if (type == DMU_OST_ZVOL) { 27502676Seschrock uint64_t volsize, volblocksize; 27512676Seschrock 27524543Smarks if (nvprops == NULL || 27534543Smarks nvlist_lookup_uint64(nvprops, 27542676Seschrock zfs_prop_to_name(ZFS_PROP_VOLSIZE), 27552676Seschrock &volsize) != 0) { 27564543Smarks nvlist_free(nvprops); 27572676Seschrock return (EINVAL); 27582676Seschrock } 27592676Seschrock 27604543Smarks if ((error = nvlist_lookup_uint64(nvprops, 27612676Seschrock zfs_prop_to_name(ZFS_PROP_VOLBLOCKSIZE), 27622676Seschrock &volblocksize)) != 0 && error != ENOENT) { 27634543Smarks nvlist_free(nvprops); 27642676Seschrock return (EINVAL); 27652676Seschrock } 27661133Seschrock 27672676Seschrock if (error != 0) 27682676Seschrock volblocksize = zfs_prop_default_numeric( 27692676Seschrock ZFS_PROP_VOLBLOCKSIZE); 27702676Seschrock 27712676Seschrock if ((error = zvol_check_volblocksize( 27722676Seschrock volblocksize)) != 0 || 27732676Seschrock (error = zvol_check_volsize(volsize, 27742676Seschrock volblocksize)) != 0) { 27754543Smarks nvlist_free(nvprops); 2776789Sahrens return (error); 27772676Seschrock } 27784577Sahrens } else if (type == DMU_OST_ZFS) { 27795331Samw int error; 27805331Samw 27815498Stimh /* 27825331Samw * We have to have normalization and 27835331Samw * case-folding flags correct when we do the 27845331Samw * file system creation, so go figure them out 27855498Stimh * now. 27865331Samw */ 27875498Stimh VERIFY(nvlist_alloc(&zct.zct_zplprops, 27885498Stimh NV_UNIQUE_NAME, KM_SLEEP) == 0); 27895498Stimh error = zfs_fill_zplprops(zc->zc_name, nvprops, 27907184Stimh zct.zct_zplprops, &is_insensitive); 27915331Samw if (error != 0) { 27925331Samw nvlist_free(nvprops); 27935498Stimh nvlist_free(zct.zct_zplprops); 27945331Samw return (error); 27954577Sahrens } 27962676Seschrock } 279710272SMatthew.Ahrens@Sun.COM error = dmu_objset_create(zc->zc_name, type, 27986492Stimh is_insensitive ? DS_FLAG_CI_DATASET : 0, cbfunc, &zct); 27995498Stimh nvlist_free(zct.zct_zplprops); 2800789Sahrens } 28012676Seschrock 28022676Seschrock /* 28032676Seschrock * It would be nice to do this atomically. 28042676Seschrock */ 28052676Seschrock if (error == 0) { 280611022STom.Erickson@Sun.COM error = zfs_set_prop_nvlist(zc->zc_name, ZPROP_SRC_LOCAL, 280711022STom.Erickson@Sun.COM nvprops, NULL); 280811022STom.Erickson@Sun.COM if (error != 0) 280910242Schris.kirby@sun.com (void) dmu_objset_destroy(zc->zc_name, B_FALSE); 28102676Seschrock } 28114543Smarks nvlist_free(nvprops); 2812789Sahrens return (error); 2813789Sahrens } 2814789Sahrens 28155367Sahrens /* 28165367Sahrens * inputs: 28175367Sahrens * zc_name name of filesystem 28185367Sahrens * zc_value short name of snapshot 28195367Sahrens * zc_cookie recursive flag 28209396SMatthew.Ahrens@Sun.COM * zc_nvlist_src[_size] property list 28215367Sahrens * 282210588SEric.Taylor@Sun.COM * outputs: 282310588SEric.Taylor@Sun.COM * zc_value short snapname (i.e. part after the '@') 28245367Sahrens */ 2825789Sahrens static int 28262199Sahrens zfs_ioc_snapshot(zfs_cmd_t *zc) 28272199Sahrens { 28287265Sahrens nvlist_t *nvprops = NULL; 28297265Sahrens int error; 28307265Sahrens boolean_t recursive = zc->zc_cookie; 28317265Sahrens 28322676Seschrock if (snapshot_namecheck(zc->zc_value, NULL, NULL) != 0) 28332199Sahrens return (EINVAL); 28347265Sahrens 28357265Sahrens if (zc->zc_nvlist_src != NULL && 28367265Sahrens (error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 28379643SEric.Taylor@Sun.COM zc->zc_iflags, &nvprops)) != 0) 28387265Sahrens return (error); 28397265Sahrens 28409355SMatthew.Ahrens@Sun.COM error = zfs_check_userprops(zc->zc_name, nvprops); 28419355SMatthew.Ahrens@Sun.COM if (error) 28429355SMatthew.Ahrens@Sun.COM goto out; 28439355SMatthew.Ahrens@Sun.COM 284411022STom.Erickson@Sun.COM if (!nvlist_empty(nvprops) && 28459355SMatthew.Ahrens@Sun.COM zfs_earlier_version(zc->zc_name, SPA_VERSION_SNAP_PROPS)) { 28469355SMatthew.Ahrens@Sun.COM error = ENOTSUP; 28479355SMatthew.Ahrens@Sun.COM goto out; 28487265Sahrens } 28499355SMatthew.Ahrens@Sun.COM 28509355SMatthew.Ahrens@Sun.COM error = dmu_objset_snapshot(zc->zc_name, zc->zc_value, 28519355SMatthew.Ahrens@Sun.COM nvprops, recursive); 28529355SMatthew.Ahrens@Sun.COM 28539355SMatthew.Ahrens@Sun.COM out: 28547265Sahrens nvlist_free(nvprops); 28557265Sahrens return (error); 28562199Sahrens } 28572199Sahrens 28584007Smmusante int 285911209SMatthew.Ahrens@Sun.COM zfs_unmount_snap(const char *name, void *arg) 2860789Sahrens { 28612417Sahrens vfs_t *vfsp = NULL; 28622199Sahrens 28636689Smaybee if (arg) { 28646689Smaybee char *snapname = arg; 286511209SMatthew.Ahrens@Sun.COM char *fullname = kmem_asprintf("%s@%s", name, snapname); 286611209SMatthew.Ahrens@Sun.COM vfsp = zfs_get_vfs(fullname); 286711209SMatthew.Ahrens@Sun.COM strfree(fullname); 28682417Sahrens } else if (strchr(name, '@')) { 28692199Sahrens vfsp = zfs_get_vfs(name); 28702199Sahrens } 28712199Sahrens 28722199Sahrens if (vfsp) { 28732199Sahrens /* 28742199Sahrens * Always force the unmount for snapshots. 28752199Sahrens */ 28762199Sahrens int flag = MS_FORCE; 2877789Sahrens int err; 2878789Sahrens 28792199Sahrens if ((err = vn_vfswlock(vfsp->vfs_vnodecovered)) != 0) { 28802199Sahrens VFS_RELE(vfsp); 28812199Sahrens return (err); 28822199Sahrens } 28832199Sahrens VFS_RELE(vfsp); 28842199Sahrens if ((err = dounmount(vfsp, flag, kcred)) != 0) 28852199Sahrens return (err); 28862199Sahrens } 28872199Sahrens return (0); 28882199Sahrens } 28892199Sahrens 28905367Sahrens /* 28915367Sahrens * inputs: 289210242Schris.kirby@sun.com * zc_name name of filesystem 289310242Schris.kirby@sun.com * zc_value short name of snapshot 289410242Schris.kirby@sun.com * zc_defer_destroy mark for deferred destroy 28955367Sahrens * 28965367Sahrens * outputs: none 28975367Sahrens */ 28982199Sahrens static int 28992199Sahrens zfs_ioc_destroy_snaps(zfs_cmd_t *zc) 29002199Sahrens { 29012199Sahrens int err; 2902789Sahrens 29032676Seschrock if (snapshot_namecheck(zc->zc_value, NULL, NULL) != 0) 29042199Sahrens return (EINVAL); 29052199Sahrens err = dmu_objset_find(zc->zc_name, 29062676Seschrock zfs_unmount_snap, zc->zc_value, DS_FIND_CHILDREN); 29072199Sahrens if (err) 29082199Sahrens return (err); 290910242Schris.kirby@sun.com return (dmu_snapshots_destroy(zc->zc_name, zc->zc_value, 291010242Schris.kirby@sun.com zc->zc_defer_destroy)); 29112199Sahrens } 29122199Sahrens 29135367Sahrens /* 29145367Sahrens * inputs: 29155367Sahrens * zc_name name of dataset to destroy 29165367Sahrens * zc_objset_type type of objset 291710242Schris.kirby@sun.com * zc_defer_destroy mark for deferred destroy 29185367Sahrens * 29195367Sahrens * outputs: none 29205367Sahrens */ 29212199Sahrens static int 29222199Sahrens zfs_ioc_destroy(zfs_cmd_t *zc) 29232199Sahrens { 292410588SEric.Taylor@Sun.COM int err; 29252199Sahrens if (strchr(zc->zc_name, '@') && zc->zc_objset_type == DMU_OST_ZFS) { 292610588SEric.Taylor@Sun.COM err = zfs_unmount_snap(zc->zc_name, NULL); 29272199Sahrens if (err) 29282199Sahrens return (err); 2929789Sahrens } 2930789Sahrens 293110588SEric.Taylor@Sun.COM err = dmu_objset_destroy(zc->zc_name, zc->zc_defer_destroy); 293210588SEric.Taylor@Sun.COM if (zc->zc_objset_type == DMU_OST_ZVOL && err == 0) 293310693Schris.kirby@sun.com (void) zvol_remove_minor(zc->zc_name); 293410588SEric.Taylor@Sun.COM return (err); 2935789Sahrens } 2936789Sahrens 29375367Sahrens /* 29385367Sahrens * inputs: 29395446Sahrens * zc_name name of dataset to rollback (to most recent snapshot) 29405367Sahrens * 29415367Sahrens * outputs: none 29425367Sahrens */ 2943789Sahrens static int 2944789Sahrens zfs_ioc_rollback(zfs_cmd_t *zc) 2945789Sahrens { 294610272SMatthew.Ahrens@Sun.COM dsl_dataset_t *ds, *clone; 29475446Sahrens int error; 294810272SMatthew.Ahrens@Sun.COM zfsvfs_t *zfsvfs; 294910272SMatthew.Ahrens@Sun.COM char *clone_name; 295010272SMatthew.Ahrens@Sun.COM 295110272SMatthew.Ahrens@Sun.COM error = dsl_dataset_hold(zc->zc_name, FTAG, &ds); 295210272SMatthew.Ahrens@Sun.COM if (error) 295310272SMatthew.Ahrens@Sun.COM return (error); 295410272SMatthew.Ahrens@Sun.COM 295510272SMatthew.Ahrens@Sun.COM /* must not be a snapshot */ 295610272SMatthew.Ahrens@Sun.COM if (dsl_dataset_is_snapshot(ds)) { 295710272SMatthew.Ahrens@Sun.COM dsl_dataset_rele(ds, FTAG); 295810272SMatthew.Ahrens@Sun.COM return (EINVAL); 295910272SMatthew.Ahrens@Sun.COM } 296010272SMatthew.Ahrens@Sun.COM 296110272SMatthew.Ahrens@Sun.COM /* must have a most recent snapshot */ 296210272SMatthew.Ahrens@Sun.COM if (ds->ds_phys->ds_prev_snap_txg < TXG_INITIAL) { 296310272SMatthew.Ahrens@Sun.COM dsl_dataset_rele(ds, FTAG); 296410272SMatthew.Ahrens@Sun.COM return (EINVAL); 296510272SMatthew.Ahrens@Sun.COM } 29665446Sahrens 29675446Sahrens /* 296810272SMatthew.Ahrens@Sun.COM * Create clone of most recent snapshot. 29695446Sahrens */ 297010272SMatthew.Ahrens@Sun.COM clone_name = kmem_asprintf("%s/%%rollback", zc->zc_name); 297110272SMatthew.Ahrens@Sun.COM error = dmu_objset_clone(clone_name, ds->ds_prev, DS_FLAG_INCONSISTENT); 29725446Sahrens if (error) 297310272SMatthew.Ahrens@Sun.COM goto out; 297410272SMatthew.Ahrens@Sun.COM 297510298SMatthew.Ahrens@Sun.COM error = dsl_dataset_own(clone_name, B_TRUE, FTAG, &clone); 297610272SMatthew.Ahrens@Sun.COM if (error) 297710272SMatthew.Ahrens@Sun.COM goto out; 297810272SMatthew.Ahrens@Sun.COM 297910272SMatthew.Ahrens@Sun.COM /* 298010272SMatthew.Ahrens@Sun.COM * Do clone swap. 298110272SMatthew.Ahrens@Sun.COM */ 29829396SMatthew.Ahrens@Sun.COM if (getzfsvfs(zc->zc_name, &zfsvfs) == 0) { 298310298SMatthew.Ahrens@Sun.COM error = zfs_suspend_fs(zfsvfs); 29846083Sek110237 if (error == 0) { 29856083Sek110237 int resume_err; 29866083Sek110237 298710272SMatthew.Ahrens@Sun.COM if (dsl_dataset_tryown(ds, B_FALSE, FTAG)) { 298810272SMatthew.Ahrens@Sun.COM error = dsl_dataset_clone_swap(clone, ds, 298910272SMatthew.Ahrens@Sun.COM B_TRUE); 299010272SMatthew.Ahrens@Sun.COM dsl_dataset_disown(ds, FTAG); 299110272SMatthew.Ahrens@Sun.COM ds = NULL; 299210272SMatthew.Ahrens@Sun.COM } else { 299310272SMatthew.Ahrens@Sun.COM error = EBUSY; 299410272SMatthew.Ahrens@Sun.COM } 299510298SMatthew.Ahrens@Sun.COM resume_err = zfs_resume_fs(zfsvfs, zc->zc_name); 29966083Sek110237 error = error ? error : resume_err; 29976083Sek110237 } 29985446Sahrens VFS_RELE(zfsvfs->z_vfs); 29995446Sahrens } else { 300010272SMatthew.Ahrens@Sun.COM if (dsl_dataset_tryown(ds, B_FALSE, FTAG)) { 300110272SMatthew.Ahrens@Sun.COM error = dsl_dataset_clone_swap(clone, ds, B_TRUE); 300210272SMatthew.Ahrens@Sun.COM dsl_dataset_disown(ds, FTAG); 300310272SMatthew.Ahrens@Sun.COM ds = NULL; 300410272SMatthew.Ahrens@Sun.COM } else { 300510272SMatthew.Ahrens@Sun.COM error = EBUSY; 300610272SMatthew.Ahrens@Sun.COM } 30075446Sahrens } 300810272SMatthew.Ahrens@Sun.COM 300910272SMatthew.Ahrens@Sun.COM /* 301010272SMatthew.Ahrens@Sun.COM * Destroy clone (which also closes it). 301110272SMatthew.Ahrens@Sun.COM */ 301210272SMatthew.Ahrens@Sun.COM (void) dsl_dataset_destroy(clone, FTAG, B_FALSE); 301310272SMatthew.Ahrens@Sun.COM 301410272SMatthew.Ahrens@Sun.COM out: 301510272SMatthew.Ahrens@Sun.COM strfree(clone_name); 301610272SMatthew.Ahrens@Sun.COM if (ds) 301710272SMatthew.Ahrens@Sun.COM dsl_dataset_rele(ds, FTAG); 30185446Sahrens return (error); 3019789Sahrens } 3020789Sahrens 30215367Sahrens /* 30225367Sahrens * inputs: 30235367Sahrens * zc_name old name of dataset 30245367Sahrens * zc_value new name of dataset 30255367Sahrens * zc_cookie recursive flag (only valid for snapshots) 30265367Sahrens * 30275367Sahrens * outputs: none 30285367Sahrens */ 3029789Sahrens static int 3030789Sahrens zfs_ioc_rename(zfs_cmd_t *zc) 3031789Sahrens { 30324490Svb160487 boolean_t recursive = zc->zc_cookie & 1; 30334007Smmusante 30342676Seschrock zc->zc_value[sizeof (zc->zc_value) - 1] = '\0'; 30355326Sek110237 if (dataset_namecheck(zc->zc_value, NULL, NULL) != 0 || 30365326Sek110237 strchr(zc->zc_value, '%')) 3037789Sahrens return (EINVAL); 3038789Sahrens 30394007Smmusante /* 30404007Smmusante * Unmount snapshot unless we're doing a recursive rename, 30414007Smmusante * in which case the dataset code figures out which snapshots 30424007Smmusante * to unmount. 30434007Smmusante */ 30444007Smmusante if (!recursive && strchr(zc->zc_name, '@') != NULL && 3045789Sahrens zc->zc_objset_type == DMU_OST_ZFS) { 30462199Sahrens int err = zfs_unmount_snap(zc->zc_name, NULL); 30472199Sahrens if (err) 30482199Sahrens return (err); 3049789Sahrens } 305010588SEric.Taylor@Sun.COM if (zc->zc_objset_type == DMU_OST_ZVOL) 305110588SEric.Taylor@Sun.COM (void) zvol_remove_minor(zc->zc_name); 30524007Smmusante return (dmu_objset_rename(zc->zc_name, zc->zc_value, recursive)); 3053789Sahrens } 3054789Sahrens 305511022STom.Erickson@Sun.COM static int 305611022STom.Erickson@Sun.COM zfs_check_settable(const char *dsname, nvpair_t *pair, cred_t *cr) 305711022STom.Erickson@Sun.COM { 305811022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 305911022STom.Erickson@Sun.COM boolean_t issnap = (strchr(dsname, '@') != NULL); 306011022STom.Erickson@Sun.COM zfs_prop_t prop = zfs_name_to_prop(propname); 306111022STom.Erickson@Sun.COM uint64_t intval; 306211022STom.Erickson@Sun.COM int err; 306311022STom.Erickson@Sun.COM 306411022STom.Erickson@Sun.COM if (prop == ZPROP_INVAL) { 306511022STom.Erickson@Sun.COM if (zfs_prop_user(propname)) { 306611022STom.Erickson@Sun.COM if (err = zfs_secpolicy_write_perms(dsname, 306711022STom.Erickson@Sun.COM ZFS_DELEG_PERM_USERPROP, cr)) 306811022STom.Erickson@Sun.COM return (err); 306911022STom.Erickson@Sun.COM return (0); 307011022STom.Erickson@Sun.COM } 307111022STom.Erickson@Sun.COM 307211022STom.Erickson@Sun.COM if (!issnap && zfs_prop_userquota(propname)) { 307311022STom.Erickson@Sun.COM const char *perm = NULL; 307411022STom.Erickson@Sun.COM const char *uq_prefix = 307511022STom.Erickson@Sun.COM zfs_userquota_prop_prefixes[ZFS_PROP_USERQUOTA]; 307611022STom.Erickson@Sun.COM const char *gq_prefix = 307711022STom.Erickson@Sun.COM zfs_userquota_prop_prefixes[ZFS_PROP_GROUPQUOTA]; 307811022STom.Erickson@Sun.COM 307911022STom.Erickson@Sun.COM if (strncmp(propname, uq_prefix, 308011022STom.Erickson@Sun.COM strlen(uq_prefix)) == 0) { 308111022STom.Erickson@Sun.COM perm = ZFS_DELEG_PERM_USERQUOTA; 308211022STom.Erickson@Sun.COM } else if (strncmp(propname, gq_prefix, 308311022STom.Erickson@Sun.COM strlen(gq_prefix)) == 0) { 308411022STom.Erickson@Sun.COM perm = ZFS_DELEG_PERM_GROUPQUOTA; 308511022STom.Erickson@Sun.COM } else { 308611022STom.Erickson@Sun.COM /* USERUSED and GROUPUSED are read-only */ 308711022STom.Erickson@Sun.COM return (EINVAL); 308811022STom.Erickson@Sun.COM } 308911022STom.Erickson@Sun.COM 309011022STom.Erickson@Sun.COM if (err = zfs_secpolicy_write_perms(dsname, perm, cr)) 309111022STom.Erickson@Sun.COM return (err); 309211022STom.Erickson@Sun.COM return (0); 309311022STom.Erickson@Sun.COM } 309411022STom.Erickson@Sun.COM 309511022STom.Erickson@Sun.COM return (EINVAL); 309611022STom.Erickson@Sun.COM } 309711022STom.Erickson@Sun.COM 309811022STom.Erickson@Sun.COM if (issnap) 309911022STom.Erickson@Sun.COM return (EINVAL); 310011022STom.Erickson@Sun.COM 310111022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_NVLIST) { 310211022STom.Erickson@Sun.COM /* 310311022STom.Erickson@Sun.COM * dsl_prop_get_all_impl() returns properties in this 310411022STom.Erickson@Sun.COM * format. 310511022STom.Erickson@Sun.COM */ 310611022STom.Erickson@Sun.COM nvlist_t *attrs; 310711022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(pair, &attrs) == 0); 310811022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 310911022STom.Erickson@Sun.COM &pair) == 0); 311011022STom.Erickson@Sun.COM } 311111022STom.Erickson@Sun.COM 311211022STom.Erickson@Sun.COM /* 311311022STom.Erickson@Sun.COM * Check that this value is valid for this pool version 311411022STom.Erickson@Sun.COM */ 311511022STom.Erickson@Sun.COM switch (prop) { 311611022STom.Erickson@Sun.COM case ZFS_PROP_COMPRESSION: 311711022STom.Erickson@Sun.COM /* 311811022STom.Erickson@Sun.COM * If the user specified gzip compression, make sure 311911022STom.Erickson@Sun.COM * the SPA supports it. We ignore any errors here since 312011022STom.Erickson@Sun.COM * we'll catch them later. 312111022STom.Erickson@Sun.COM */ 312211022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_UINT64 && 312311022STom.Erickson@Sun.COM nvpair_value_uint64(pair, &intval) == 0) { 312411022STom.Erickson@Sun.COM if (intval >= ZIO_COMPRESS_GZIP_1 && 312511022STom.Erickson@Sun.COM intval <= ZIO_COMPRESS_GZIP_9 && 312611022STom.Erickson@Sun.COM zfs_earlier_version(dsname, 312711022STom.Erickson@Sun.COM SPA_VERSION_GZIP_COMPRESSION)) { 312811022STom.Erickson@Sun.COM return (ENOTSUP); 312911022STom.Erickson@Sun.COM } 313011022STom.Erickson@Sun.COM 313111022STom.Erickson@Sun.COM if (intval == ZIO_COMPRESS_ZLE && 313211022STom.Erickson@Sun.COM zfs_earlier_version(dsname, 313311022STom.Erickson@Sun.COM SPA_VERSION_ZLE_COMPRESSION)) 313411022STom.Erickson@Sun.COM return (ENOTSUP); 313511022STom.Erickson@Sun.COM 313611022STom.Erickson@Sun.COM /* 313711022STom.Erickson@Sun.COM * If this is a bootable dataset then 313811022STom.Erickson@Sun.COM * verify that the compression algorithm 313911022STom.Erickson@Sun.COM * is supported for booting. We must return 314011022STom.Erickson@Sun.COM * something other than ENOTSUP since it 314111022STom.Erickson@Sun.COM * implies a downrev pool version. 314211022STom.Erickson@Sun.COM */ 314311022STom.Erickson@Sun.COM if (zfs_is_bootfs(dsname) && 314411022STom.Erickson@Sun.COM !BOOTFS_COMPRESS_VALID(intval)) { 314511022STom.Erickson@Sun.COM return (ERANGE); 314611022STom.Erickson@Sun.COM } 314711022STom.Erickson@Sun.COM } 314811022STom.Erickson@Sun.COM break; 314911022STom.Erickson@Sun.COM 315011022STom.Erickson@Sun.COM case ZFS_PROP_COPIES: 315111022STom.Erickson@Sun.COM if (zfs_earlier_version(dsname, SPA_VERSION_DITTO_BLOCKS)) 315211022STom.Erickson@Sun.COM return (ENOTSUP); 315311022STom.Erickson@Sun.COM break; 315411022STom.Erickson@Sun.COM 315511022STom.Erickson@Sun.COM case ZFS_PROP_DEDUP: 315611022STom.Erickson@Sun.COM if (zfs_earlier_version(dsname, SPA_VERSION_DEDUP)) 315711022STom.Erickson@Sun.COM return (ENOTSUP); 315811022STom.Erickson@Sun.COM break; 315911022STom.Erickson@Sun.COM 316011022STom.Erickson@Sun.COM case ZFS_PROP_SHARESMB: 316111022STom.Erickson@Sun.COM if (zpl_earlier_version(dsname, ZPL_VERSION_FUID)) 316211022STom.Erickson@Sun.COM return (ENOTSUP); 316311022STom.Erickson@Sun.COM break; 316411022STom.Erickson@Sun.COM 316511022STom.Erickson@Sun.COM case ZFS_PROP_ACLINHERIT: 316611022STom.Erickson@Sun.COM if (nvpair_type(pair) == DATA_TYPE_UINT64 && 316711022STom.Erickson@Sun.COM nvpair_value_uint64(pair, &intval) == 0) { 316811022STom.Erickson@Sun.COM if (intval == ZFS_ACL_PASSTHROUGH_X && 316911022STom.Erickson@Sun.COM zfs_earlier_version(dsname, 317011022STom.Erickson@Sun.COM SPA_VERSION_PASSTHROUGH_X)) 317111022STom.Erickson@Sun.COM return (ENOTSUP); 317211022STom.Erickson@Sun.COM } 317311022STom.Erickson@Sun.COM break; 317411022STom.Erickson@Sun.COM } 317511022STom.Erickson@Sun.COM 317611022STom.Erickson@Sun.COM return (zfs_secpolicy_setprop(dsname, prop, pair, CRED())); 317711022STom.Erickson@Sun.COM } 317811022STom.Erickson@Sun.COM 317911022STom.Erickson@Sun.COM /* 318011022STom.Erickson@Sun.COM * Removes properties from the given props list that fail permission checks 318111022STom.Erickson@Sun.COM * needed to clear them and to restore them in case of a receive error. For each 318211022STom.Erickson@Sun.COM * property, make sure we have both set and inherit permissions. 318311022STom.Erickson@Sun.COM * 318411022STom.Erickson@Sun.COM * Returns the first error encountered if any permission checks fail. If the 318511022STom.Erickson@Sun.COM * caller provides a non-NULL errlist, it also gives the complete list of names 318611022STom.Erickson@Sun.COM * of all the properties that failed a permission check along with the 318711022STom.Erickson@Sun.COM * corresponding error numbers. The caller is responsible for freeing the 318811022STom.Erickson@Sun.COM * returned errlist. 318911022STom.Erickson@Sun.COM * 319011022STom.Erickson@Sun.COM * If every property checks out successfully, zero is returned and the list 319111022STom.Erickson@Sun.COM * pointed at by errlist is NULL. 319211022STom.Erickson@Sun.COM */ 319311022STom.Erickson@Sun.COM static int 319411022STom.Erickson@Sun.COM zfs_check_clearable(char *dataset, nvlist_t *props, nvlist_t **errlist) 31956689Smaybee { 31966689Smaybee zfs_cmd_t *zc; 319711022STom.Erickson@Sun.COM nvpair_t *pair, *next_pair; 319811022STom.Erickson@Sun.COM nvlist_t *errors; 319911022STom.Erickson@Sun.COM int err, rv = 0; 32006689Smaybee 32016689Smaybee if (props == NULL) 320211022STom.Erickson@Sun.COM return (0); 320311022STom.Erickson@Sun.COM 320411022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(&errors, NV_UNIQUE_NAME, KM_SLEEP) == 0); 320511022STom.Erickson@Sun.COM 32066689Smaybee zc = kmem_alloc(sizeof (zfs_cmd_t), KM_SLEEP); 32076689Smaybee (void) strcpy(zc->zc_name, dataset); 320811022STom.Erickson@Sun.COM pair = nvlist_next_nvpair(props, NULL); 320911022STom.Erickson@Sun.COM while (pair != NULL) { 321011022STom.Erickson@Sun.COM next_pair = nvlist_next_nvpair(props, pair); 321111022STom.Erickson@Sun.COM 321211022STom.Erickson@Sun.COM (void) strcpy(zc->zc_value, nvpair_name(pair)); 321311022STom.Erickson@Sun.COM if ((err = zfs_check_settable(dataset, pair, CRED())) != 0 || 321411022STom.Erickson@Sun.COM (err = zfs_secpolicy_inherit(zc, CRED())) != 0) { 321511022STom.Erickson@Sun.COM VERIFY(nvlist_remove_nvpair(props, pair) == 0); 321611022STom.Erickson@Sun.COM VERIFY(nvlist_add_int32(errors, 321711022STom.Erickson@Sun.COM zc->zc_value, err) == 0); 321811022STom.Erickson@Sun.COM } 321911022STom.Erickson@Sun.COM pair = next_pair; 32206689Smaybee } 32216689Smaybee kmem_free(zc, sizeof (zfs_cmd_t)); 322211022STom.Erickson@Sun.COM 322311022STom.Erickson@Sun.COM if ((pair = nvlist_next_nvpair(errors, NULL)) == NULL) { 322411022STom.Erickson@Sun.COM nvlist_free(errors); 322511022STom.Erickson@Sun.COM errors = NULL; 322611022STom.Erickson@Sun.COM } else { 322711022STom.Erickson@Sun.COM VERIFY(nvpair_value_int32(pair, &rv) == 0); 322811022STom.Erickson@Sun.COM } 322911022STom.Erickson@Sun.COM 323011022STom.Erickson@Sun.COM if (errlist == NULL) 323111022STom.Erickson@Sun.COM nvlist_free(errors); 323211022STom.Erickson@Sun.COM else 323311022STom.Erickson@Sun.COM *errlist = errors; 323411022STom.Erickson@Sun.COM 323511022STom.Erickson@Sun.COM return (rv); 32366689Smaybee } 32376689Smaybee 323811022STom.Erickson@Sun.COM static boolean_t 323911022STom.Erickson@Sun.COM propval_equals(nvpair_t *p1, nvpair_t *p2) 324011022STom.Erickson@Sun.COM { 324111022STom.Erickson@Sun.COM if (nvpair_type(p1) == DATA_TYPE_NVLIST) { 324211022STom.Erickson@Sun.COM /* dsl_prop_get_all_impl() format */ 324311022STom.Erickson@Sun.COM nvlist_t *attrs; 324411022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(p1, &attrs) == 0); 324511022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 324611022STom.Erickson@Sun.COM &p1) == 0); 324711022STom.Erickson@Sun.COM } 324811022STom.Erickson@Sun.COM 324911022STom.Erickson@Sun.COM if (nvpair_type(p2) == DATA_TYPE_NVLIST) { 325011022STom.Erickson@Sun.COM nvlist_t *attrs; 325111022STom.Erickson@Sun.COM VERIFY(nvpair_value_nvlist(p2, &attrs) == 0); 325211022STom.Erickson@Sun.COM VERIFY(nvlist_lookup_nvpair(attrs, ZPROP_VALUE, 325311022STom.Erickson@Sun.COM &p2) == 0); 325411022STom.Erickson@Sun.COM } 325511022STom.Erickson@Sun.COM 325611022STom.Erickson@Sun.COM if (nvpair_type(p1) != nvpair_type(p2)) 325711022STom.Erickson@Sun.COM return (B_FALSE); 325811022STom.Erickson@Sun.COM 325911022STom.Erickson@Sun.COM if (nvpair_type(p1) == DATA_TYPE_STRING) { 326011022STom.Erickson@Sun.COM char *valstr1, *valstr2; 326111022STom.Erickson@Sun.COM 326211022STom.Erickson@Sun.COM VERIFY(nvpair_value_string(p1, (char **)&valstr1) == 0); 326311022STom.Erickson@Sun.COM VERIFY(nvpair_value_string(p2, (char **)&valstr2) == 0); 326411022STom.Erickson@Sun.COM return (strcmp(valstr1, valstr2) == 0); 326511022STom.Erickson@Sun.COM } else { 326611022STom.Erickson@Sun.COM uint64_t intval1, intval2; 326711022STom.Erickson@Sun.COM 326811022STom.Erickson@Sun.COM VERIFY(nvpair_value_uint64(p1, &intval1) == 0); 326911022STom.Erickson@Sun.COM VERIFY(nvpair_value_uint64(p2, &intval2) == 0); 327011022STom.Erickson@Sun.COM return (intval1 == intval2); 327111022STom.Erickson@Sun.COM } 327211022STom.Erickson@Sun.COM } 327311022STom.Erickson@Sun.COM 327411022STom.Erickson@Sun.COM /* 327511022STom.Erickson@Sun.COM * Remove properties from props if they are not going to change (as determined 327611022STom.Erickson@Sun.COM * by comparison with origprops). Remove them from origprops as well, since we 327711022STom.Erickson@Sun.COM * do not need to clear or restore properties that won't change. 327811022STom.Erickson@Sun.COM */ 327911022STom.Erickson@Sun.COM static void 328011022STom.Erickson@Sun.COM props_reduce(nvlist_t *props, nvlist_t *origprops) 328111022STom.Erickson@Sun.COM { 328211022STom.Erickson@Sun.COM nvpair_t *pair, *next_pair; 328311022STom.Erickson@Sun.COM 328411022STom.Erickson@Sun.COM if (origprops == NULL) 328511022STom.Erickson@Sun.COM return; /* all props need to be received */ 328611022STom.Erickson@Sun.COM 328711022STom.Erickson@Sun.COM pair = nvlist_next_nvpair(props, NULL); 328811022STom.Erickson@Sun.COM while (pair != NULL) { 328911022STom.Erickson@Sun.COM const char *propname = nvpair_name(pair); 329011022STom.Erickson@Sun.COM nvpair_t *match; 329111022STom.Erickson@Sun.COM 329211022STom.Erickson@Sun.COM next_pair = nvlist_next_nvpair(props, pair); 329311022STom.Erickson@Sun.COM 329411022STom.Erickson@Sun.COM if ((nvlist_lookup_nvpair(origprops, propname, 329511022STom.Erickson@Sun.COM &match) != 0) || !propval_equals(pair, match)) 329611022STom.Erickson@Sun.COM goto next; /* need to set received value */ 329711022STom.Erickson@Sun.COM 329811022STom.Erickson@Sun.COM /* don't clear the existing received value */ 329911022STom.Erickson@Sun.COM (void) nvlist_remove_nvpair(origprops, match); 330011022STom.Erickson@Sun.COM /* don't bother receiving the property */ 330111022STom.Erickson@Sun.COM (void) nvlist_remove_nvpair(props, pair); 330211022STom.Erickson@Sun.COM next: 330311022STom.Erickson@Sun.COM pair = next_pair; 330411022STom.Erickson@Sun.COM } 330511022STom.Erickson@Sun.COM } 330611022STom.Erickson@Sun.COM 330711022STom.Erickson@Sun.COM #ifdef DEBUG 330811022STom.Erickson@Sun.COM static boolean_t zfs_ioc_recv_inject_err; 330911022STom.Erickson@Sun.COM #endif 331011022STom.Erickson@Sun.COM 33115367Sahrens /* 33125367Sahrens * inputs: 33135367Sahrens * zc_name name of containing filesystem 33145367Sahrens * zc_nvlist_src{_size} nvlist of properties to apply 33155367Sahrens * zc_value name of snapshot to create 33165367Sahrens * zc_string name of clone origin (if DRR_FLAG_CLONE) 33175367Sahrens * zc_cookie file descriptor to recv from 33185367Sahrens * zc_begin_record the BEGIN record of the stream (not byteswapped) 33195367Sahrens * zc_guid force flag 33205367Sahrens * 33215367Sahrens * outputs: 33225367Sahrens * zc_cookie number of bytes read 332311022STom.Erickson@Sun.COM * zc_nvlist_dst{_size} error for each unapplied received property 332411022STom.Erickson@Sun.COM * zc_obj zprop_errflags_t 33255367Sahrens */ 3326789Sahrens static int 33275367Sahrens zfs_ioc_recv(zfs_cmd_t *zc) 3328789Sahrens { 3329789Sahrens file_t *fp; 33305326Sek110237 objset_t *os; 33315367Sahrens dmu_recv_cookie_t drc; 33325326Sek110237 boolean_t force = (boolean_t)zc->zc_guid; 333311022STom.Erickson@Sun.COM int fd; 333411022STom.Erickson@Sun.COM int error = 0; 333511022STom.Erickson@Sun.COM int props_error = 0; 333611022STom.Erickson@Sun.COM nvlist_t *errors; 33375367Sahrens offset_t off; 333811022STom.Erickson@Sun.COM nvlist_t *props = NULL; /* sent properties */ 333911022STom.Erickson@Sun.COM nvlist_t *origprops = NULL; /* existing properties */ 33405367Sahrens objset_t *origin = NULL; 33415367Sahrens char *tosnap; 33425367Sahrens char tofs[ZFS_MAXNAMELEN]; 334311022STom.Erickson@Sun.COM boolean_t first_recvd_props = B_FALSE; 3344789Sahrens 33453265Sahrens if (dataset_namecheck(zc->zc_value, NULL, NULL) != 0 || 33465326Sek110237 strchr(zc->zc_value, '@') == NULL || 33475326Sek110237 strchr(zc->zc_value, '%')) 33483265Sahrens return (EINVAL); 33493265Sahrens 33505367Sahrens (void) strcpy(tofs, zc->zc_value); 33515367Sahrens tosnap = strchr(tofs, '@'); 335211022STom.Erickson@Sun.COM *tosnap++ = '\0'; 33535367Sahrens 33545367Sahrens if (zc->zc_nvlist_src != NULL && 33555367Sahrens (error = get_nvlist(zc->zc_nvlist_src, zc->zc_nvlist_src_size, 33569643SEric.Taylor@Sun.COM zc->zc_iflags, &props)) != 0) 33575367Sahrens return (error); 33585367Sahrens 3359789Sahrens fd = zc->zc_cookie; 3360789Sahrens fp = getf(fd); 33615367Sahrens if (fp == NULL) { 33625367Sahrens nvlist_free(props); 3363789Sahrens return (EBADF); 33645367Sahrens } 33655326Sek110237 336611022STom.Erickson@Sun.COM VERIFY(nvlist_alloc(&errors, NV_UNIQUE_NAME, KM_SLEEP) == 0); 336711022STom.Erickson@Sun.COM 336810298SMatthew.Ahrens@Sun.COM if (props && dmu_objset_hold(tofs, FTAG, &os) == 0) { 336911022STom.Erickson@Sun.COM if ((spa_version(os->os_spa) >= SPA_VERSION_RECVD_PROPS) && 337011022STom.Erickson@Sun.COM !dsl_prop_get_hasrecvd(os)) { 337111022STom.Erickson@Sun.COM first_recvd_props = B_TRUE; 337211022STom.Erickson@Sun.COM } 337311022STom.Erickson@Sun.COM 33746689Smaybee /* 337511022STom.Erickson@Sun.COM * If new received properties are supplied, they are to 337611022STom.Erickson@Sun.COM * completely replace the existing received properties, so stash 337711022STom.Erickson@Sun.COM * away the existing ones. 33786689Smaybee */ 337911022STom.Erickson@Sun.COM if (dsl_prop_get_received(os, &origprops) == 0) { 338011022STom.Erickson@Sun.COM nvlist_t *errlist = NULL; 338111022STom.Erickson@Sun.COM /* 338211022STom.Erickson@Sun.COM * Don't bother writing a property if its value won't 338311022STom.Erickson@Sun.COM * change (and avoid the unnecessary security checks). 338411022STom.Erickson@Sun.COM * 338511022STom.Erickson@Sun.COM * The first receive after SPA_VERSION_RECVD_PROPS is a 338611022STom.Erickson@Sun.COM * special case where we blow away all local properties 338711022STom.Erickson@Sun.COM * regardless. 338811022STom.Erickson@Sun.COM */ 338911022STom.Erickson@Sun.COM if (!first_recvd_props) 339011022STom.Erickson@Sun.COM props_reduce(props, origprops); 339111022STom.Erickson@Sun.COM if (zfs_check_clearable(tofs, origprops, 339211022STom.Erickson@Sun.COM &errlist) != 0) 339311022STom.Erickson@Sun.COM (void) nvlist_merge(errors, errlist, 0); 339411022STom.Erickson@Sun.COM nvlist_free(errlist); 339511022STom.Erickson@Sun.COM } 339610298SMatthew.Ahrens@Sun.COM 339710298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 33985326Sek110237 } 33995326Sek110237 34005367Sahrens if (zc->zc_string[0]) { 340110298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_string, FTAG, &origin); 34026689Smaybee if (error) 34036689Smaybee goto out; 34045367Sahrens } 34055367Sahrens 340611007SLori.Alt@Sun.COM error = dmu_recv_begin(tofs, tosnap, zc->zc_top_ds, 340711007SLori.Alt@Sun.COM &zc->zc_begin_record, force, origin, &drc); 34085367Sahrens if (origin) 340910298SMatthew.Ahrens@Sun.COM dmu_objset_rele(origin, FTAG); 34106689Smaybee if (error) 34116689Smaybee goto out; 34125326Sek110237 34135326Sek110237 /* 341411022STom.Erickson@Sun.COM * Set properties before we receive the stream so that they are applied 341511022STom.Erickson@Sun.COM * to the new data. Note that we must call dmu_recv_stream() if 341611022STom.Erickson@Sun.COM * dmu_recv_begin() succeeds. 34175326Sek110237 */ 34185367Sahrens if (props) { 341911022STom.Erickson@Sun.COM nvlist_t *errlist; 342011022STom.Erickson@Sun.COM 342111022STom.Erickson@Sun.COM if (dmu_objset_from_ds(drc.drc_logical_ds, &os) == 0) { 342211022STom.Erickson@Sun.COM if (drc.drc_newfs) { 342311022STom.Erickson@Sun.COM if (spa_version(os->os_spa) >= 342411022STom.Erickson@Sun.COM SPA_VERSION_RECVD_PROPS) 342511022STom.Erickson@Sun.COM first_recvd_props = B_TRUE; 342611022STom.Erickson@Sun.COM } else if (origprops != NULL) { 342711022STom.Erickson@Sun.COM if (clear_received_props(os, tofs, origprops, 342811022STom.Erickson@Sun.COM first_recvd_props ? NULL : props) != 0) 342911022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NOCLEAR; 343011022STom.Erickson@Sun.COM } else { 343111022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NOCLEAR; 343211022STom.Erickson@Sun.COM } 343311022STom.Erickson@Sun.COM dsl_prop_set_hasrecvd(os); 343411022STom.Erickson@Sun.COM } else if (!drc.drc_newfs) { 343511022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NOCLEAR; 343611022STom.Erickson@Sun.COM } 343711022STom.Erickson@Sun.COM 343811022STom.Erickson@Sun.COM (void) zfs_set_prop_nvlist(tofs, ZPROP_SRC_RECEIVED, 343911022STom.Erickson@Sun.COM props, &errlist); 344011022STom.Erickson@Sun.COM (void) nvlist_merge(errors, errlist, 0); 344111022STom.Erickson@Sun.COM nvlist_free(errlist); 344211022STom.Erickson@Sun.COM } 344311022STom.Erickson@Sun.COM 344411022STom.Erickson@Sun.COM if (fit_error_list(zc, &errors) != 0 || put_nvlist(zc, errors) != 0) { 34456689Smaybee /* 344611022STom.Erickson@Sun.COM * Caller made zc->zc_nvlist_dst less than the minimum expected 344711022STom.Erickson@Sun.COM * size or supplied an invalid address. 34486689Smaybee */ 344911022STom.Erickson@Sun.COM props_error = EINVAL; 34505367Sahrens } 34515367Sahrens 34525367Sahrens off = fp->f_offset; 34535367Sahrens error = dmu_recv_stream(&drc, fp->f_vnode, &off); 34545367Sahrens 345510204SMatthew.Ahrens@Sun.COM if (error == 0) { 345610204SMatthew.Ahrens@Sun.COM zfsvfs_t *zfsvfs = NULL; 345710204SMatthew.Ahrens@Sun.COM 345810204SMatthew.Ahrens@Sun.COM if (getzfsvfs(tofs, &zfsvfs) == 0) { 345910204SMatthew.Ahrens@Sun.COM /* online recv */ 346010204SMatthew.Ahrens@Sun.COM int end_err; 346110298SMatthew.Ahrens@Sun.COM 346210298SMatthew.Ahrens@Sun.COM error = zfs_suspend_fs(zfsvfs); 346310204SMatthew.Ahrens@Sun.COM /* 346410204SMatthew.Ahrens@Sun.COM * If the suspend fails, then the recv_end will 346510204SMatthew.Ahrens@Sun.COM * likely also fail, and clean up after itself. 346610204SMatthew.Ahrens@Sun.COM */ 346710204SMatthew.Ahrens@Sun.COM end_err = dmu_recv_end(&drc); 346810204SMatthew.Ahrens@Sun.COM if (error == 0) { 346910204SMatthew.Ahrens@Sun.COM int resume_err = 347010298SMatthew.Ahrens@Sun.COM zfs_resume_fs(zfsvfs, tofs); 347110204SMatthew.Ahrens@Sun.COM error = error ? error : resume_err; 347210204SMatthew.Ahrens@Sun.COM } 347310204SMatthew.Ahrens@Sun.COM error = error ? error : end_err; 347410204SMatthew.Ahrens@Sun.COM VFS_RELE(zfsvfs->z_vfs); 347510204SMatthew.Ahrens@Sun.COM } else { 34766689Smaybee error = dmu_recv_end(&drc); 34775367Sahrens } 34786083Sek110237 } 34795367Sahrens 34805367Sahrens zc->zc_cookie = off - fp->f_offset; 34815367Sahrens if (VOP_SEEK(fp->f_vnode, fp->f_offset, &off, NULL) == 0) 34825367Sahrens fp->f_offset = off; 34832885Sahrens 348411022STom.Erickson@Sun.COM #ifdef DEBUG 348511022STom.Erickson@Sun.COM if (zfs_ioc_recv_inject_err) { 348611022STom.Erickson@Sun.COM zfs_ioc_recv_inject_err = B_FALSE; 348711022STom.Erickson@Sun.COM error = 1; 348811022STom.Erickson@Sun.COM } 348911022STom.Erickson@Sun.COM #endif 34906689Smaybee /* 34916689Smaybee * On error, restore the original props. 34926689Smaybee */ 34936689Smaybee if (error && props) { 349411022STom.Erickson@Sun.COM if (dmu_objset_hold(tofs, FTAG, &os) == 0) { 349511022STom.Erickson@Sun.COM if (clear_received_props(os, tofs, props, NULL) != 0) { 349611022STom.Erickson@Sun.COM /* 349711022STom.Erickson@Sun.COM * We failed to clear the received properties. 349811022STom.Erickson@Sun.COM * Since we may have left a $recvd value on the 349911022STom.Erickson@Sun.COM * system, we can't clear the $hasrecvd flag. 350011022STom.Erickson@Sun.COM */ 350111022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NORESTORE; 350211022STom.Erickson@Sun.COM } else if (first_recvd_props) { 350311022STom.Erickson@Sun.COM dsl_prop_unset_hasrecvd(os); 350411022STom.Erickson@Sun.COM } 350511022STom.Erickson@Sun.COM dmu_objset_rele(os, FTAG); 350611022STom.Erickson@Sun.COM } else if (!drc.drc_newfs) { 350711022STom.Erickson@Sun.COM /* We failed to clear the received properties. */ 350811022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NORESTORE; 350911022STom.Erickson@Sun.COM } 351011022STom.Erickson@Sun.COM 351111022STom.Erickson@Sun.COM if (origprops == NULL && !drc.drc_newfs) { 351211022STom.Erickson@Sun.COM /* We failed to stash the original properties. */ 351311022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NORESTORE; 351411022STom.Erickson@Sun.COM } 351511022STom.Erickson@Sun.COM 351611022STom.Erickson@Sun.COM /* 351711022STom.Erickson@Sun.COM * dsl_props_set() will not convert RECEIVED to LOCAL on or 351811022STom.Erickson@Sun.COM * after SPA_VERSION_RECVD_PROPS, so we need to specify LOCAL 351911022STom.Erickson@Sun.COM * explictly if we're restoring local properties cleared in the 352011022STom.Erickson@Sun.COM * first new-style receive. 352111022STom.Erickson@Sun.COM */ 352211022STom.Erickson@Sun.COM if (origprops != NULL && 352311022STom.Erickson@Sun.COM zfs_set_prop_nvlist(tofs, (first_recvd_props ? 352411022STom.Erickson@Sun.COM ZPROP_SRC_LOCAL : ZPROP_SRC_RECEIVED), 352511022STom.Erickson@Sun.COM origprops, NULL) != 0) { 352611022STom.Erickson@Sun.COM /* 352711022STom.Erickson@Sun.COM * We stashed the original properties but failed to 352811022STom.Erickson@Sun.COM * restore them. 352911022STom.Erickson@Sun.COM */ 353011022STom.Erickson@Sun.COM zc->zc_obj |= ZPROP_ERR_NORESTORE; 353111022STom.Erickson@Sun.COM } 35326689Smaybee } 35336689Smaybee out: 35346689Smaybee nvlist_free(props); 35356689Smaybee nvlist_free(origprops); 353611022STom.Erickson@Sun.COM nvlist_free(errors); 3537789Sahrens releasef(fd); 353811022STom.Erickson@Sun.COM 353911022STom.Erickson@Sun.COM if (error == 0) 354011022STom.Erickson@Sun.COM error = props_error; 354111022STom.Erickson@Sun.COM 3542789Sahrens return (error); 3543789Sahrens } 3544789Sahrens 35455367Sahrens /* 35465367Sahrens * inputs: 35475367Sahrens * zc_name name of snapshot to send 35485367Sahrens * zc_value short name of incremental fromsnap (may be empty) 35495367Sahrens * zc_cookie file descriptor to send stream to 35505367Sahrens * zc_obj fromorigin flag (mutually exclusive with zc_value) 35515367Sahrens * 35525367Sahrens * outputs: none 35535367Sahrens */ 3554789Sahrens static int 35555367Sahrens zfs_ioc_send(zfs_cmd_t *zc) 3556789Sahrens { 3557789Sahrens objset_t *fromsnap = NULL; 3558789Sahrens objset_t *tosnap; 3559789Sahrens file_t *fp; 3560789Sahrens int error; 35615367Sahrens offset_t off; 3562789Sahrens 356310298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_name, FTAG, &tosnap); 3564789Sahrens if (error) 3565789Sahrens return (error); 3566789Sahrens 35672676Seschrock if (zc->zc_value[0] != '\0') { 35688012SEric.Taylor@Sun.COM char *buf; 35692885Sahrens char *cp; 35702885Sahrens 35718012SEric.Taylor@Sun.COM buf = kmem_alloc(MAXPATHLEN, KM_SLEEP); 35728012SEric.Taylor@Sun.COM (void) strncpy(buf, zc->zc_name, MAXPATHLEN); 35732885Sahrens cp = strchr(buf, '@'); 35742885Sahrens if (cp) 35752885Sahrens *(cp+1) = 0; 35768012SEric.Taylor@Sun.COM (void) strncat(buf, zc->zc_value, MAXPATHLEN); 357710298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(buf, FTAG, &fromsnap); 35788012SEric.Taylor@Sun.COM kmem_free(buf, MAXPATHLEN); 3579789Sahrens if (error) { 358010298SMatthew.Ahrens@Sun.COM dmu_objset_rele(tosnap, FTAG); 3581789Sahrens return (error); 3582789Sahrens } 3583789Sahrens } 3584789Sahrens 3585789Sahrens fp = getf(zc->zc_cookie); 3586789Sahrens if (fp == NULL) { 358710298SMatthew.Ahrens@Sun.COM dmu_objset_rele(tosnap, FTAG); 3588789Sahrens if (fromsnap) 358910298SMatthew.Ahrens@Sun.COM dmu_objset_rele(fromsnap, FTAG); 3590789Sahrens return (EBADF); 3591789Sahrens } 3592789Sahrens 35935367Sahrens off = fp->f_offset; 35945367Sahrens error = dmu_sendbackup(tosnap, fromsnap, zc->zc_obj, fp->f_vnode, &off); 35955367Sahrens 35965367Sahrens if (VOP_SEEK(fp->f_vnode, fp->f_offset, &off, NULL) == 0) 35975367Sahrens fp->f_offset = off; 3598789Sahrens releasef(zc->zc_cookie); 3599789Sahrens if (fromsnap) 360010298SMatthew.Ahrens@Sun.COM dmu_objset_rele(fromsnap, FTAG); 360110298SMatthew.Ahrens@Sun.COM dmu_objset_rele(tosnap, FTAG); 3602789Sahrens return (error); 3603789Sahrens } 3604789Sahrens 36051544Seschrock static int 36061544Seschrock zfs_ioc_inject_fault(zfs_cmd_t *zc) 36071544Seschrock { 36081544Seschrock int id, error; 36091544Seschrock 36101544Seschrock error = zio_inject_fault(zc->zc_name, (int)zc->zc_guid, &id, 36111544Seschrock &zc->zc_inject_record); 36121544Seschrock 36131544Seschrock if (error == 0) 36141544Seschrock zc->zc_guid = (uint64_t)id; 36151544Seschrock 36161544Seschrock return (error); 36171544Seschrock } 36181544Seschrock 36191544Seschrock static int 36201544Seschrock zfs_ioc_clear_fault(zfs_cmd_t *zc) 36211544Seschrock { 36221544Seschrock return (zio_clear_fault((int)zc->zc_guid)); 36231544Seschrock } 36241544Seschrock 36251544Seschrock static int 36261544Seschrock zfs_ioc_inject_list_next(zfs_cmd_t *zc) 36271544Seschrock { 36281544Seschrock int id = (int)zc->zc_guid; 36291544Seschrock int error; 36301544Seschrock 36311544Seschrock error = zio_inject_list_next(&id, zc->zc_name, sizeof (zc->zc_name), 36321544Seschrock &zc->zc_inject_record); 36331544Seschrock 36341544Seschrock zc->zc_guid = id; 36351544Seschrock 36361544Seschrock return (error); 36371544Seschrock } 36381544Seschrock 36391544Seschrock static int 36401544Seschrock zfs_ioc_error_log(zfs_cmd_t *zc) 36411544Seschrock { 36421544Seschrock spa_t *spa; 36431544Seschrock int error; 36442676Seschrock size_t count = (size_t)zc->zc_nvlist_dst_size; 36451544Seschrock 36461544Seschrock if ((error = spa_open(zc->zc_name, &spa, FTAG)) != 0) 36471544Seschrock return (error); 36481544Seschrock 36492676Seschrock error = spa_get_errlog(spa, (void *)(uintptr_t)zc->zc_nvlist_dst, 36501544Seschrock &count); 36511544Seschrock if (error == 0) 36522676Seschrock zc->zc_nvlist_dst_size = count; 36531544Seschrock else 36542676Seschrock zc->zc_nvlist_dst_size = spa_get_errlog_size(spa); 36551544Seschrock 36561544Seschrock spa_close(spa, FTAG); 36571544Seschrock 36581544Seschrock return (error); 36591544Seschrock } 36601544Seschrock 36611544Seschrock static int 36621544Seschrock zfs_ioc_clear(zfs_cmd_t *zc) 36631544Seschrock { 36641544Seschrock spa_t *spa; 36651544Seschrock vdev_t *vd; 36661544Seschrock int error; 36671544Seschrock 36687294Sperrin /* 36697294Sperrin * On zpool clear we also fix up missing slogs 36707294Sperrin */ 36717294Sperrin mutex_enter(&spa_namespace_lock); 36727294Sperrin spa = spa_lookup(zc->zc_name); 36737294Sperrin if (spa == NULL) { 36747294Sperrin mutex_exit(&spa_namespace_lock); 36757294Sperrin return (EIO); 36767294Sperrin } 367710922SJeff.Bonwick@Sun.COM if (spa_get_log_state(spa) == SPA_LOG_MISSING) { 36787294Sperrin /* we need to let spa_open/spa_load clear the chains */ 367910922SJeff.Bonwick@Sun.COM spa_set_log_state(spa, SPA_LOG_CLEAR); 36807294Sperrin } 368110921STim.Haley@Sun.COM spa->spa_last_open_failed = 0; 36827294Sperrin mutex_exit(&spa_namespace_lock); 36837294Sperrin 368410921STim.Haley@Sun.COM if (zc->zc_cookie == ZPOOL_NO_REWIND) { 368510921STim.Haley@Sun.COM error = spa_open(zc->zc_name, &spa, FTAG); 368610921STim.Haley@Sun.COM } else { 368710921STim.Haley@Sun.COM nvlist_t *policy; 368810921STim.Haley@Sun.COM nvlist_t *config = NULL; 368910921STim.Haley@Sun.COM 369010921STim.Haley@Sun.COM if (zc->zc_nvlist_src == NULL) 369110921STim.Haley@Sun.COM return (EINVAL); 369210921STim.Haley@Sun.COM 369310921STim.Haley@Sun.COM if ((error = get_nvlist(zc->zc_nvlist_src, 369410921STim.Haley@Sun.COM zc->zc_nvlist_src_size, zc->zc_iflags, &policy)) == 0) { 369510921STim.Haley@Sun.COM error = spa_open_rewind(zc->zc_name, &spa, FTAG, 369610921STim.Haley@Sun.COM policy, &config); 369710921STim.Haley@Sun.COM if (config != NULL) { 369810921STim.Haley@Sun.COM (void) put_nvlist(zc, config); 369910921STim.Haley@Sun.COM nvlist_free(config); 370010921STim.Haley@Sun.COM } 370110921STim.Haley@Sun.COM nvlist_free(policy); 370210921STim.Haley@Sun.COM } 370310921STim.Haley@Sun.COM } 370410921STim.Haley@Sun.COM 370510921STim.Haley@Sun.COM if (error) 37061544Seschrock return (error); 37071544Seschrock 370810685SGeorge.Wilson@Sun.COM spa_vdev_state_enter(spa, SCL_NONE); 37091544Seschrock 37102676Seschrock if (zc->zc_guid == 0) { 37111544Seschrock vd = NULL; 37126643Seschrock } else { 37136643Seschrock vd = spa_lookup_by_guid(spa, zc->zc_guid, B_TRUE); 37145450Sbrendan if (vd == NULL) { 37157754SJeff.Bonwick@Sun.COM (void) spa_vdev_state_exit(spa, NULL, ENODEV); 37165450Sbrendan spa_close(spa, FTAG); 37175450Sbrendan return (ENODEV); 37185450Sbrendan } 37191544Seschrock } 37201544Seschrock 37217754SJeff.Bonwick@Sun.COM vdev_clear(spa, vd); 37227754SJeff.Bonwick@Sun.COM 37237754SJeff.Bonwick@Sun.COM (void) spa_vdev_state_exit(spa, NULL, 0); 37247754SJeff.Bonwick@Sun.COM 37257754SJeff.Bonwick@Sun.COM /* 37267754SJeff.Bonwick@Sun.COM * Resume any suspended I/Os. 37277754SJeff.Bonwick@Sun.COM */ 37289234SGeorge.Wilson@Sun.COM if (zio_resume(spa) != 0) 37299234SGeorge.Wilson@Sun.COM error = EIO; 37301544Seschrock 37311544Seschrock spa_close(spa, FTAG); 37321544Seschrock 37339234SGeorge.Wilson@Sun.COM return (error); 37341544Seschrock } 37351544Seschrock 37365367Sahrens /* 37375367Sahrens * inputs: 37385367Sahrens * zc_name name of filesystem 37395367Sahrens * zc_value name of origin snapshot 37405367Sahrens * 374110588SEric.Taylor@Sun.COM * outputs: 374210588SEric.Taylor@Sun.COM * zc_string name of conflicting snapshot, if there is one 37435367Sahrens */ 37441544Seschrock static int 37452082Seschrock zfs_ioc_promote(zfs_cmd_t *zc) 37462082Seschrock { 37472417Sahrens char *cp; 37482417Sahrens 37492417Sahrens /* 37502417Sahrens * We don't need to unmount *all* the origin fs's snapshots, but 37512417Sahrens * it's easier. 37522417Sahrens */ 37532676Seschrock cp = strchr(zc->zc_value, '@'); 37542417Sahrens if (cp) 37552417Sahrens *cp = '\0'; 37562676Seschrock (void) dmu_objset_find(zc->zc_value, 37572417Sahrens zfs_unmount_snap, NULL, DS_FIND_SNAPSHOTS); 375810588SEric.Taylor@Sun.COM return (dsl_dataset_promote(zc->zc_name, zc->zc_string)); 37592082Seschrock } 37602082Seschrock 37614543Smarks /* 37629396SMatthew.Ahrens@Sun.COM * Retrieve a single {user|group}{used|quota}@... property. 37639396SMatthew.Ahrens@Sun.COM * 37649396SMatthew.Ahrens@Sun.COM * inputs: 37659396SMatthew.Ahrens@Sun.COM * zc_name name of filesystem 37669396SMatthew.Ahrens@Sun.COM * zc_objset_type zfs_userquota_prop_t 37679396SMatthew.Ahrens@Sun.COM * zc_value domain name (eg. "S-1-234-567-89") 37689396SMatthew.Ahrens@Sun.COM * zc_guid RID/UID/GID 37699396SMatthew.Ahrens@Sun.COM * 37709396SMatthew.Ahrens@Sun.COM * outputs: 37719396SMatthew.Ahrens@Sun.COM * zc_cookie property value 37729396SMatthew.Ahrens@Sun.COM */ 37739396SMatthew.Ahrens@Sun.COM static int 37749396SMatthew.Ahrens@Sun.COM zfs_ioc_userspace_one(zfs_cmd_t *zc) 37759396SMatthew.Ahrens@Sun.COM { 37769396SMatthew.Ahrens@Sun.COM zfsvfs_t *zfsvfs; 37779396SMatthew.Ahrens@Sun.COM int error; 37789396SMatthew.Ahrens@Sun.COM 37799396SMatthew.Ahrens@Sun.COM if (zc->zc_objset_type >= ZFS_NUM_USERQUOTA_PROPS) 37809396SMatthew.Ahrens@Sun.COM return (EINVAL); 37819396SMatthew.Ahrens@Sun.COM 378210298SMatthew.Ahrens@Sun.COM error = zfsvfs_hold(zc->zc_name, FTAG, &zfsvfs); 37839396SMatthew.Ahrens@Sun.COM if (error) 37849396SMatthew.Ahrens@Sun.COM return (error); 37859396SMatthew.Ahrens@Sun.COM 37869396SMatthew.Ahrens@Sun.COM error = zfs_userspace_one(zfsvfs, 37879396SMatthew.Ahrens@Sun.COM zc->zc_objset_type, zc->zc_value, zc->zc_guid, &zc->zc_cookie); 37889396SMatthew.Ahrens@Sun.COM zfsvfs_rele(zfsvfs, FTAG); 37899396SMatthew.Ahrens@Sun.COM 37909396SMatthew.Ahrens@Sun.COM return (error); 37919396SMatthew.Ahrens@Sun.COM } 37929396SMatthew.Ahrens@Sun.COM 37939396SMatthew.Ahrens@Sun.COM /* 37949396SMatthew.Ahrens@Sun.COM * inputs: 37959396SMatthew.Ahrens@Sun.COM * zc_name name of filesystem 37969396SMatthew.Ahrens@Sun.COM * zc_cookie zap cursor 37979396SMatthew.Ahrens@Sun.COM * zc_objset_type zfs_userquota_prop_t 37989396SMatthew.Ahrens@Sun.COM * zc_nvlist_dst[_size] buffer to fill (not really an nvlist) 37999396SMatthew.Ahrens@Sun.COM * 38009396SMatthew.Ahrens@Sun.COM * outputs: 38019396SMatthew.Ahrens@Sun.COM * zc_nvlist_dst[_size] data buffer (array of zfs_useracct_t) 38029396SMatthew.Ahrens@Sun.COM * zc_cookie zap cursor 38039396SMatthew.Ahrens@Sun.COM */ 38049396SMatthew.Ahrens@Sun.COM static int 38059396SMatthew.Ahrens@Sun.COM zfs_ioc_userspace_many(zfs_cmd_t *zc) 38069396SMatthew.Ahrens@Sun.COM { 38079396SMatthew.Ahrens@Sun.COM zfsvfs_t *zfsvfs; 38089396SMatthew.Ahrens@Sun.COM int error; 38099396SMatthew.Ahrens@Sun.COM 381010298SMatthew.Ahrens@Sun.COM error = zfsvfs_hold(zc->zc_name, FTAG, &zfsvfs); 38119396SMatthew.Ahrens@Sun.COM if (error) 38129396SMatthew.Ahrens@Sun.COM return (error); 38139396SMatthew.Ahrens@Sun.COM 38149396SMatthew.Ahrens@Sun.COM int bufsize = zc->zc_nvlist_dst_size; 38159396SMatthew.Ahrens@Sun.COM void *buf = kmem_alloc(bufsize, KM_SLEEP); 38169396SMatthew.Ahrens@Sun.COM 38179396SMatthew.Ahrens@Sun.COM error = zfs_userspace_many(zfsvfs, zc->zc_objset_type, &zc->zc_cookie, 38189396SMatthew.Ahrens@Sun.COM buf, &zc->zc_nvlist_dst_size); 38199396SMatthew.Ahrens@Sun.COM 38209396SMatthew.Ahrens@Sun.COM if (error == 0) { 38219396SMatthew.Ahrens@Sun.COM error = xcopyout(buf, 38229396SMatthew.Ahrens@Sun.COM (void *)(uintptr_t)zc->zc_nvlist_dst, 38239396SMatthew.Ahrens@Sun.COM zc->zc_nvlist_dst_size); 38249396SMatthew.Ahrens@Sun.COM } 38259396SMatthew.Ahrens@Sun.COM kmem_free(buf, bufsize); 38269396SMatthew.Ahrens@Sun.COM zfsvfs_rele(zfsvfs, FTAG); 38279396SMatthew.Ahrens@Sun.COM 38289396SMatthew.Ahrens@Sun.COM return (error); 38299396SMatthew.Ahrens@Sun.COM } 38309396SMatthew.Ahrens@Sun.COM 38319396SMatthew.Ahrens@Sun.COM /* 38329396SMatthew.Ahrens@Sun.COM * inputs: 38339396SMatthew.Ahrens@Sun.COM * zc_name name of filesystem 38349396SMatthew.Ahrens@Sun.COM * 38359396SMatthew.Ahrens@Sun.COM * outputs: 38369396SMatthew.Ahrens@Sun.COM * none 38379396SMatthew.Ahrens@Sun.COM */ 38389396SMatthew.Ahrens@Sun.COM static int 38399396SMatthew.Ahrens@Sun.COM zfs_ioc_userspace_upgrade(zfs_cmd_t *zc) 38409396SMatthew.Ahrens@Sun.COM { 38419396SMatthew.Ahrens@Sun.COM objset_t *os; 38429396SMatthew.Ahrens@Sun.COM int error; 38439396SMatthew.Ahrens@Sun.COM zfsvfs_t *zfsvfs; 38449396SMatthew.Ahrens@Sun.COM 38459396SMatthew.Ahrens@Sun.COM if (getzfsvfs(zc->zc_name, &zfsvfs) == 0) { 384610298SMatthew.Ahrens@Sun.COM if (!dmu_objset_userused_enabled(zfsvfs->z_os)) { 38479396SMatthew.Ahrens@Sun.COM /* 38489396SMatthew.Ahrens@Sun.COM * If userused is not enabled, it may be because the 38499396SMatthew.Ahrens@Sun.COM * objset needs to be closed & reopened (to grow the 38509396SMatthew.Ahrens@Sun.COM * objset_phys_t). Suspend/resume the fs will do that. 38519396SMatthew.Ahrens@Sun.COM */ 385210298SMatthew.Ahrens@Sun.COM error = zfs_suspend_fs(zfsvfs); 385310298SMatthew.Ahrens@Sun.COM if (error == 0) 385410298SMatthew.Ahrens@Sun.COM error = zfs_resume_fs(zfsvfs, zc->zc_name); 38559396SMatthew.Ahrens@Sun.COM } 38569396SMatthew.Ahrens@Sun.COM if (error == 0) 38579396SMatthew.Ahrens@Sun.COM error = dmu_objset_userspace_upgrade(zfsvfs->z_os); 38589396SMatthew.Ahrens@Sun.COM VFS_RELE(zfsvfs->z_vfs); 38599396SMatthew.Ahrens@Sun.COM } else { 386010298SMatthew.Ahrens@Sun.COM /* XXX kind of reading contents without owning */ 386110298SMatthew.Ahrens@Sun.COM error = dmu_objset_hold(zc->zc_name, FTAG, &os); 38629396SMatthew.Ahrens@Sun.COM if (error) 38639396SMatthew.Ahrens@Sun.COM return (error); 38649396SMatthew.Ahrens@Sun.COM 38659396SMatthew.Ahrens@Sun.COM error = dmu_objset_userspace_upgrade(os); 386610298SMatthew.Ahrens@Sun.COM dmu_objset_rele(os, FTAG); 38679396SMatthew.Ahrens@Sun.COM } 38689396SMatthew.Ahrens@Sun.COM 38699396SMatthew.Ahrens@Sun.COM return (error); 38709396SMatthew.Ahrens@Sun.COM } 38719396SMatthew.Ahrens@Sun.COM 38729396SMatthew.Ahrens@Sun.COM /* 38734543Smarks * We don't want to have a hard dependency 38744543Smarks * against some special symbols in sharefs 38755331Samw * nfs, and smbsrv. Determine them if needed when 38764543Smarks * the first file system is shared. 38775331Samw * Neither sharefs, nfs or smbsrv are unloadable modules. 38784543Smarks */ 38795331Samw int (*znfsexport_fs)(void *arg); 38804543Smarks int (*zshare_fs)(enum sharefs_sys_op, share_t *, uint32_t); 38815331Samw int (*zsmbexport_fs)(void *arg, boolean_t add_share); 38825331Samw 38835331Samw int zfs_nfsshare_inited; 38845331Samw int zfs_smbshare_inited; 38855331Samw 38864543Smarks ddi_modhandle_t nfs_mod; 38874543Smarks ddi_modhandle_t sharefs_mod; 38885331Samw ddi_modhandle_t smbsrv_mod; 38894543Smarks kmutex_t zfs_share_lock; 38904543Smarks 38914543Smarks static int 38925331Samw zfs_init_sharefs() 38935331Samw { 38945331Samw int error; 38955331Samw 38965331Samw ASSERT(MUTEX_HELD(&zfs_share_lock)); 38975331Samw /* Both NFS and SMB shares also require sharetab support. */ 38985331Samw if (sharefs_mod == NULL && ((sharefs_mod = 38995331Samw ddi_modopen("fs/sharefs", 39005331Samw KRTLD_MODE_FIRST, &error)) == NULL)) { 39015331Samw return (ENOSYS); 39025331Samw } 39035331Samw if (zshare_fs == NULL && ((zshare_fs = 39045331Samw (int (*)(enum sharefs_sys_op, share_t *, uint32_t)) 39055331Samw ddi_modsym(sharefs_mod, "sharefs_impl", &error)) == NULL)) { 39065331Samw return (ENOSYS); 39075331Samw } 39085331Samw return (0); 39095331Samw } 39105331Samw 39115331Samw static int 39124543Smarks zfs_ioc_share(zfs_cmd_t *zc) 39134543Smarks { 39144543Smarks int error; 39154543Smarks int opcode; 39164543Smarks 39175331Samw switch (zc->zc_share.z_sharetype) { 39185331Samw case ZFS_SHARE_NFS: 39195331Samw case ZFS_UNSHARE_NFS: 39205331Samw if (zfs_nfsshare_inited == 0) { 39215331Samw mutex_enter(&zfs_share_lock); 39225331Samw if (nfs_mod == NULL && ((nfs_mod = ddi_modopen("fs/nfs", 39235331Samw KRTLD_MODE_FIRST, &error)) == NULL)) { 39245331Samw mutex_exit(&zfs_share_lock); 39255331Samw return (ENOSYS); 39265331Samw } 39275331Samw if (znfsexport_fs == NULL && 39285331Samw ((znfsexport_fs = (int (*)(void *)) 39295331Samw ddi_modsym(nfs_mod, 39305331Samw "nfs_export", &error)) == NULL)) { 39315331Samw mutex_exit(&zfs_share_lock); 39325331Samw return (ENOSYS); 39335331Samw } 39345331Samw error = zfs_init_sharefs(); 39355331Samw if (error) { 39365331Samw mutex_exit(&zfs_share_lock); 39375331Samw return (ENOSYS); 39385331Samw } 39395331Samw zfs_nfsshare_inited = 1; 39404543Smarks mutex_exit(&zfs_share_lock); 39414543Smarks } 39425331Samw break; 39435331Samw case ZFS_SHARE_SMB: 39445331Samw case ZFS_UNSHARE_SMB: 39455331Samw if (zfs_smbshare_inited == 0) { 39465331Samw mutex_enter(&zfs_share_lock); 39475331Samw if (smbsrv_mod == NULL && ((smbsrv_mod = 39485331Samw ddi_modopen("drv/smbsrv", 39495331Samw KRTLD_MODE_FIRST, &error)) == NULL)) { 39505331Samw mutex_exit(&zfs_share_lock); 39515331Samw return (ENOSYS); 39525331Samw } 39535331Samw if (zsmbexport_fs == NULL && ((zsmbexport_fs = 39545331Samw (int (*)(void *, boolean_t))ddi_modsym(smbsrv_mod, 39556139Sjb150015 "smb_server_share", &error)) == NULL)) { 39565331Samw mutex_exit(&zfs_share_lock); 39575331Samw return (ENOSYS); 39585331Samw } 39595331Samw error = zfs_init_sharefs(); 39605331Samw if (error) { 39615331Samw mutex_exit(&zfs_share_lock); 39625331Samw return (ENOSYS); 39635331Samw } 39645331Samw zfs_smbshare_inited = 1; 39654543Smarks mutex_exit(&zfs_share_lock); 39664543Smarks } 39675331Samw break; 39685331Samw default: 39695331Samw return (EINVAL); 39704543Smarks } 39714543Smarks 39725331Samw switch (zc->zc_share.z_sharetype) { 39735331Samw case ZFS_SHARE_NFS: 39745331Samw case ZFS_UNSHARE_NFS: 39755331Samw if (error = 39765331Samw znfsexport_fs((void *) 39775331Samw (uintptr_t)zc->zc_share.z_exportdata)) 39785331Samw return (error); 39795331Samw break; 39805331Samw case ZFS_SHARE_SMB: 39815331Samw case ZFS_UNSHARE_SMB: 39825331Samw if (error = zsmbexport_fs((void *) 39835331Samw (uintptr_t)zc->zc_share.z_exportdata, 39845331Samw zc->zc_share.z_sharetype == ZFS_SHARE_SMB ? 39858845Samw@Sun.COM B_TRUE: B_FALSE)) { 39865331Samw return (error); 39875331Samw } 39885331Samw break; 39895331Samw } 39905331Samw 39915331Samw opcode = (zc->zc_share.z_sharetype == ZFS_SHARE_NFS || 39925331Samw zc->zc_share.z_sharetype == ZFS_SHARE_SMB) ? 39934543Smarks SHAREFS_ADD : SHAREFS_REMOVE; 39944543Smarks 39955331Samw /* 39965331Samw * Add or remove share from sharetab 39975331Samw */ 39984543Smarks error = zshare_fs(opcode, 39994543Smarks (void *)(uintptr_t)zc->zc_share.z_sharedata, 40004543Smarks zc->zc_share.z_sharemax); 40014543Smarks 40024543Smarks return (error); 40034543Smarks 40044543Smarks } 40054543Smarks 40068845Samw@Sun.COM ace_t full_access[] = { 40078845Samw@Sun.COM {(uid_t)-1, ACE_ALL_PERMS, ACE_EVERYONE, 0} 40088845Samw@Sun.COM }; 40098845Samw@Sun.COM 40108845Samw@Sun.COM /* 40118845Samw@Sun.COM * Remove all ACL files in shares dir 40128845Samw@Sun.COM */ 40138845Samw@Sun.COM static int 40148845Samw@Sun.COM zfs_smb_acl_purge(znode_t *dzp) 40158845Samw@Sun.COM { 40168845Samw@Sun.COM zap_cursor_t zc; 40178845Samw@Sun.COM zap_attribute_t zap; 40188845Samw@Sun.COM zfsvfs_t *zfsvfs = dzp->z_zfsvfs; 40198845Samw@Sun.COM int error; 40208845Samw@Sun.COM 40218845Samw@Sun.COM for (zap_cursor_init(&zc, zfsvfs->z_os, dzp->z_id); 40228845Samw@Sun.COM (error = zap_cursor_retrieve(&zc, &zap)) == 0; 40238845Samw@Sun.COM zap_cursor_advance(&zc)) { 40248845Samw@Sun.COM if ((error = VOP_REMOVE(ZTOV(dzp), zap.za_name, kcred, 40258845Samw@Sun.COM NULL, 0)) != 0) 40268845Samw@Sun.COM break; 40278845Samw@Sun.COM } 40288845Samw@Sun.COM zap_cursor_fini(&zc); 40298845Samw@Sun.COM return (error); 40308845Samw@Sun.COM } 40318845Samw@Sun.COM 40328845Samw@Sun.COM static int 40338845Samw@Sun.COM zfs_ioc_smb_acl(zfs_cmd_t *zc) 40348845Samw@Sun.COM { 40358845Samw@Sun.COM vnode_t *vp; 40368845Samw@Sun.COM znode_t *dzp; 40378845Samw@Sun.COM vnode_t *resourcevp = NULL; 40388845Samw@Sun.COM znode_t *sharedir; 40398845Samw@Sun.COM zfsvfs_t *zfsvfs; 40408845Samw@Sun.COM nvlist_t *nvlist; 40418845Samw@Sun.COM char *src, *target; 40428845Samw@Sun.COM vattr_t vattr; 40438845Samw@Sun.COM vsecattr_t vsec; 40448845Samw@Sun.COM int error = 0; 40458845Samw@Sun.COM 40468845Samw@Sun.COM if ((error = lookupname(zc->zc_value, UIO_SYSSPACE, 40478845Samw@Sun.COM NO_FOLLOW, NULL, &vp)) != 0) 40488845Samw@Sun.COM return (error); 40498845Samw@Sun.COM 40508845Samw@Sun.COM /* Now make sure mntpnt and dataset are ZFS */ 40518845Samw@Sun.COM 40528845Samw@Sun.COM if (vp->v_vfsp->vfs_fstype != zfsfstype || 40538845Samw@Sun.COM (strcmp((char *)refstr_value(vp->v_vfsp->vfs_resource), 40548845Samw@Sun.COM zc->zc_name) != 0)) { 40558845Samw@Sun.COM VN_RELE(vp); 40568845Samw@Sun.COM return (EINVAL); 40578845Samw@Sun.COM } 40588845Samw@Sun.COM 40598845Samw@Sun.COM dzp = VTOZ(vp); 40608845Samw@Sun.COM zfsvfs = dzp->z_zfsvfs; 40618845Samw@Sun.COM ZFS_ENTER(zfsvfs); 40628845Samw@Sun.COM 40639030SMark.Shellenbaum@Sun.COM /* 40649030SMark.Shellenbaum@Sun.COM * Create share dir if its missing. 40659030SMark.Shellenbaum@Sun.COM */ 40669030SMark.Shellenbaum@Sun.COM mutex_enter(&zfsvfs->z_lock); 40679030SMark.Shellenbaum@Sun.COM if (zfsvfs->z_shares_dir == 0) { 40689030SMark.Shellenbaum@Sun.COM dmu_tx_t *tx; 40699030SMark.Shellenbaum@Sun.COM 40709030SMark.Shellenbaum@Sun.COM tx = dmu_tx_create(zfsvfs->z_os); 40719030SMark.Shellenbaum@Sun.COM dmu_tx_hold_zap(tx, MASTER_NODE_OBJ, TRUE, 40729030SMark.Shellenbaum@Sun.COM ZFS_SHARES_DIR); 40739030SMark.Shellenbaum@Sun.COM dmu_tx_hold_zap(tx, DMU_NEW_OBJECT, FALSE, NULL); 40749030SMark.Shellenbaum@Sun.COM error = dmu_tx_assign(tx, TXG_WAIT); 40759030SMark.Shellenbaum@Sun.COM if (error) { 40769030SMark.Shellenbaum@Sun.COM dmu_tx_abort(tx); 40779030SMark.Shellenbaum@Sun.COM } else { 40789030SMark.Shellenbaum@Sun.COM error = zfs_create_share_dir(zfsvfs, tx); 40799030SMark.Shellenbaum@Sun.COM dmu_tx_commit(tx); 40809030SMark.Shellenbaum@Sun.COM } 40819030SMark.Shellenbaum@Sun.COM if (error) { 40829030SMark.Shellenbaum@Sun.COM mutex_exit(&zfsvfs->z_lock); 40839030SMark.Shellenbaum@Sun.COM VN_RELE(vp); 40849030SMark.Shellenbaum@Sun.COM ZFS_EXIT(zfsvfs); 40859030SMark.Shellenbaum@Sun.COM return (error); 40869030SMark.Shellenbaum@Sun.COM } 40879030SMark.Shellenbaum@Sun.COM } 40889030SMark.Shellenbaum@Sun.COM mutex_exit(&zfsvfs->z_lock); 40899030SMark.Shellenbaum@Sun.COM 40909030SMark.Shellenbaum@Sun.COM ASSERT(zfsvfs->z_shares_dir); 40918845Samw@Sun.COM if ((error = zfs_zget(zfsvfs, zfsvfs->z_shares_dir, &sharedir)) != 0) { 40929030SMark.Shellenbaum@Sun.COM VN_RELE(vp); 40938845Samw@Sun.COM ZFS_EXIT(zfsvfs); 40948845Samw@Sun.COM return (error); 40958845Samw@Sun.COM } 40968845Samw@Sun.COM 40978845Samw@Sun.COM switch (zc->zc_cookie) { 40988845Samw@Sun.COM case ZFS_SMB_ACL_ADD: 40998845Samw@Sun.COM vattr.va_mask = AT_MODE|AT_UID|AT_GID|AT_TYPE; 41008845Samw@Sun.COM vattr.va_type = VREG; 41018845Samw@Sun.COM vattr.va_mode = S_IFREG|0777; 41028845Samw@Sun.COM vattr.va_uid = 0; 41038845Samw@Sun.COM vattr.va_gid = 0; 41048845Samw@Sun.COM 41058845Samw@Sun.COM vsec.vsa_mask = VSA_ACE; 41068845Samw@Sun.COM vsec.vsa_aclentp = &full_access; 41078845Samw@Sun.COM vsec.vsa_aclentsz = sizeof (full_access); 41088845Samw@Sun.COM vsec.vsa_aclcnt = 1; 41098845Samw@Sun.COM 41108845Samw@Sun.COM error = VOP_CREATE(ZTOV(sharedir), zc->zc_string, 41118845Samw@Sun.COM &vattr, EXCL, 0, &resourcevp, kcred, 0, NULL, &vsec); 41128845Samw@Sun.COM if (resourcevp) 41138845Samw@Sun.COM VN_RELE(resourcevp); 41148845Samw@Sun.COM break; 41158845Samw@Sun.COM 41168845Samw@Sun.COM case ZFS_SMB_ACL_REMOVE: 41178845Samw@Sun.COM error = VOP_REMOVE(ZTOV(sharedir), zc->zc_string, kcred, 41188845Samw@Sun.COM NULL, 0); 41198845Samw@Sun.COM break; 41208845Samw@Sun.COM 41218845Samw@Sun.COM case ZFS_SMB_ACL_RENAME: 41228845Samw@Sun.COM if ((error = get_nvlist(zc->zc_nvlist_src, 41239643SEric.Taylor@Sun.COM zc->zc_nvlist_src_size, zc->zc_iflags, &nvlist)) != 0) { 41248845Samw@Sun.COM VN_RELE(vp); 41258845Samw@Sun.COM ZFS_EXIT(zfsvfs); 41268845Samw@Sun.COM return (error); 41278845Samw@Sun.COM } 41288845Samw@Sun.COM if (nvlist_lookup_string(nvlist, ZFS_SMB_ACL_SRC, &src) || 41298845Samw@Sun.COM nvlist_lookup_string(nvlist, ZFS_SMB_ACL_TARGET, 41308845Samw@Sun.COM &target)) { 41318845Samw@Sun.COM VN_RELE(vp); 41329179SMark.Shellenbaum@Sun.COM VN_RELE(ZTOV(sharedir)); 41338845Samw@Sun.COM ZFS_EXIT(zfsvfs); 41348845Samw@Sun.COM return (error); 41358845Samw@Sun.COM } 41368845Samw@Sun.COM error = VOP_RENAME(ZTOV(sharedir), src, ZTOV(sharedir), target, 41378845Samw@Sun.COM kcred, NULL, 0); 41388845Samw@Sun.COM nvlist_free(nvlist); 41398845Samw@Sun.COM break; 41408845Samw@Sun.COM 41418845Samw@Sun.COM case ZFS_SMB_ACL_PURGE: 41428845Samw@Sun.COM error = zfs_smb_acl_purge(sharedir); 41438845Samw@Sun.COM break; 41448845Samw@Sun.COM 41458845Samw@Sun.COM default: 41468845Samw@Sun.COM error = EINVAL; 41478845Samw@Sun.COM break; 41488845Samw@Sun.COM } 41498845Samw@Sun.COM 41508845Samw@Sun.COM VN_RELE(vp); 41518845Samw@Sun.COM VN_RELE(ZTOV(sharedir)); 41528845Samw@Sun.COM 41538845Samw@Sun.COM ZFS_EXIT(zfsvfs); 41548845Samw@Sun.COM 41558845Samw@Sun.COM return (error); 41568845Samw@Sun.COM } 41578845Samw@Sun.COM 41584543Smarks /* 415910242Schris.kirby@sun.com * inputs: 416010242Schris.kirby@sun.com * zc_name name of filesystem 416110242Schris.kirby@sun.com * zc_value short name of snap 416210242Schris.kirby@sun.com * zc_string user-supplied tag for this reference 416310242Schris.kirby@sun.com * zc_cookie recursive flag 416410342Schris.kirby@sun.com * zc_temphold set if hold is temporary 416510242Schris.kirby@sun.com * 416610242Schris.kirby@sun.com * outputs: none 416710242Schris.kirby@sun.com */ 416810242Schris.kirby@sun.com static int 416910242Schris.kirby@sun.com zfs_ioc_hold(zfs_cmd_t *zc) 417010242Schris.kirby@sun.com { 417110242Schris.kirby@sun.com boolean_t recursive = zc->zc_cookie; 417210242Schris.kirby@sun.com 417310242Schris.kirby@sun.com if (snapshot_namecheck(zc->zc_value, NULL, NULL) != 0) 417410242Schris.kirby@sun.com return (EINVAL); 417510242Schris.kirby@sun.com 417610242Schris.kirby@sun.com return (dsl_dataset_user_hold(zc->zc_name, zc->zc_value, 417710342Schris.kirby@sun.com zc->zc_string, recursive, zc->zc_temphold)); 417810242Schris.kirby@sun.com } 417910242Schris.kirby@sun.com 418010242Schris.kirby@sun.com /* 418110242Schris.kirby@sun.com * inputs: 418210242Schris.kirby@sun.com * zc_name name of dataset from which we're releasing a user reference 418310242Schris.kirby@sun.com * zc_value short name of snap 418410242Schris.kirby@sun.com * zc_string user-supplied tag for this reference 418510242Schris.kirby@sun.com * zc_cookie recursive flag 418610242Schris.kirby@sun.com * 418710242Schris.kirby@sun.com * outputs: none 418810242Schris.kirby@sun.com */ 418910242Schris.kirby@sun.com static int 419010242Schris.kirby@sun.com zfs_ioc_release(zfs_cmd_t *zc) 419110242Schris.kirby@sun.com { 419210242Schris.kirby@sun.com boolean_t recursive = zc->zc_cookie; 419310242Schris.kirby@sun.com 419410242Schris.kirby@sun.com if (snapshot_namecheck(zc->zc_value, NULL, NULL) != 0) 419510242Schris.kirby@sun.com return (EINVAL); 419610242Schris.kirby@sun.com 419710242Schris.kirby@sun.com return (dsl_dataset_user_release(zc->zc_name, zc->zc_value, 419810242Schris.kirby@sun.com zc->zc_string, recursive)); 419910242Schris.kirby@sun.com } 420010242Schris.kirby@sun.com 420110242Schris.kirby@sun.com /* 420210242Schris.kirby@sun.com * inputs: 420310242Schris.kirby@sun.com * zc_name name of filesystem 420410242Schris.kirby@sun.com * 420510242Schris.kirby@sun.com * outputs: 420610242Schris.kirby@sun.com * zc_nvlist_src{_size} nvlist of snapshot holds 420710242Schris.kirby@sun.com */ 420810242Schris.kirby@sun.com static int 420910242Schris.kirby@sun.com zfs_ioc_get_holds(zfs_cmd_t *zc) 421010242Schris.kirby@sun.com { 421110242Schris.kirby@sun.com nvlist_t *nvp; 421210242Schris.kirby@sun.com int error; 421310242Schris.kirby@sun.com 421410242Schris.kirby@sun.com if ((error = dsl_dataset_get_holds(zc->zc_name, &nvp)) == 0) { 421510242Schris.kirby@sun.com error = put_nvlist(zc, nvp); 421610242Schris.kirby@sun.com nvlist_free(nvp); 421710242Schris.kirby@sun.com } 421810242Schris.kirby@sun.com 421910242Schris.kirby@sun.com return (error); 422010242Schris.kirby@sun.com } 422110242Schris.kirby@sun.com 422210242Schris.kirby@sun.com /* 42234988Sek110237 * pool create, destroy, and export don't log the history as part of 42244988Sek110237 * zfsdev_ioctl, but rather zfs_ioc_pool_create, and zfs_ioc_pool_export 42254988Sek110237 * do the logging of those commands. 42264543Smarks */ 4227789Sahrens static zfs_ioc_vec_t zfs_ioc_vec[] = { 42289234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_create, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42299234SGeorge.Wilson@Sun.COM B_FALSE }, 42309234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_destroy, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42319234SGeorge.Wilson@Sun.COM B_FALSE }, 42329234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_import, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42339234SGeorge.Wilson@Sun.COM B_FALSE }, 42349234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_export, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42359234SGeorge.Wilson@Sun.COM B_FALSE }, 42369234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_configs, zfs_secpolicy_none, NO_NAME, B_FALSE, 42379234SGeorge.Wilson@Sun.COM B_FALSE }, 42389234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_stats, zfs_secpolicy_read, POOL_NAME, B_FALSE, 42399234SGeorge.Wilson@Sun.COM B_FALSE }, 42409234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_tryimport, zfs_secpolicy_config, NO_NAME, B_FALSE, 42419234SGeorge.Wilson@Sun.COM B_FALSE }, 42429234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_scrub, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42439234SGeorge.Wilson@Sun.COM B_TRUE }, 42449234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_freeze, zfs_secpolicy_config, NO_NAME, B_FALSE, 42459234SGeorge.Wilson@Sun.COM B_FALSE }, 42469234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_upgrade, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42479234SGeorge.Wilson@Sun.COM B_TRUE }, 42489234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_get_history, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42499234SGeorge.Wilson@Sun.COM B_FALSE }, 42509234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_add, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42519234SGeorge.Wilson@Sun.COM B_TRUE }, 42529234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_remove, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42539234SGeorge.Wilson@Sun.COM B_TRUE }, 42549234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_set_state, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42559234SGeorge.Wilson@Sun.COM B_FALSE }, 42569234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_attach, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42579234SGeorge.Wilson@Sun.COM B_TRUE }, 42589234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_detach, zfs_secpolicy_config, POOL_NAME, B_TRUE, 42599234SGeorge.Wilson@Sun.COM B_TRUE }, 42609234SGeorge.Wilson@Sun.COM { zfs_ioc_vdev_setpath, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42619234SGeorge.Wilson@Sun.COM B_TRUE }, 42629425SEric.Schrock@Sun.COM { zfs_ioc_vdev_setfru, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42639425SEric.Schrock@Sun.COM B_TRUE }, 42649234SGeorge.Wilson@Sun.COM { zfs_ioc_objset_stats, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 42659234SGeorge.Wilson@Sun.COM B_FALSE }, 42669234SGeorge.Wilson@Sun.COM { zfs_ioc_objset_zplprops, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 42679234SGeorge.Wilson@Sun.COM B_FALSE }, 42689234SGeorge.Wilson@Sun.COM { zfs_ioc_dataset_list_next, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 42699234SGeorge.Wilson@Sun.COM B_FALSE }, 42709234SGeorge.Wilson@Sun.COM { zfs_ioc_snapshot_list_next, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 42719234SGeorge.Wilson@Sun.COM B_FALSE }, 42729234SGeorge.Wilson@Sun.COM { zfs_ioc_set_prop, zfs_secpolicy_none, DATASET_NAME, B_TRUE, B_TRUE }, 42739234SGeorge.Wilson@Sun.COM { zfs_ioc_create, zfs_secpolicy_create, DATASET_NAME, B_TRUE, B_TRUE }, 42749234SGeorge.Wilson@Sun.COM { zfs_ioc_destroy, zfs_secpolicy_destroy, DATASET_NAME, B_TRUE, 42759234SGeorge.Wilson@Sun.COM B_TRUE}, 42769234SGeorge.Wilson@Sun.COM { zfs_ioc_rollback, zfs_secpolicy_rollback, DATASET_NAME, B_TRUE, 42779234SGeorge.Wilson@Sun.COM B_TRUE }, 42789234SGeorge.Wilson@Sun.COM { zfs_ioc_rename, zfs_secpolicy_rename, DATASET_NAME, B_TRUE, B_TRUE }, 42799234SGeorge.Wilson@Sun.COM { zfs_ioc_recv, zfs_secpolicy_receive, DATASET_NAME, B_TRUE, B_TRUE }, 42809234SGeorge.Wilson@Sun.COM { zfs_ioc_send, zfs_secpolicy_send, DATASET_NAME, B_TRUE, B_FALSE }, 42819234SGeorge.Wilson@Sun.COM { zfs_ioc_inject_fault, zfs_secpolicy_inject, NO_NAME, B_FALSE, 42829234SGeorge.Wilson@Sun.COM B_FALSE }, 42839234SGeorge.Wilson@Sun.COM { zfs_ioc_clear_fault, zfs_secpolicy_inject, NO_NAME, B_FALSE, 42849234SGeorge.Wilson@Sun.COM B_FALSE }, 42859234SGeorge.Wilson@Sun.COM { zfs_ioc_inject_list_next, zfs_secpolicy_inject, NO_NAME, B_FALSE, 42869234SGeorge.Wilson@Sun.COM B_FALSE }, 42879234SGeorge.Wilson@Sun.COM { zfs_ioc_error_log, zfs_secpolicy_inject, POOL_NAME, B_FALSE, 42889234SGeorge.Wilson@Sun.COM B_FALSE }, 42899234SGeorge.Wilson@Sun.COM { zfs_ioc_clear, zfs_secpolicy_config, POOL_NAME, B_TRUE, B_FALSE }, 42909234SGeorge.Wilson@Sun.COM { zfs_ioc_promote, zfs_secpolicy_promote, DATASET_NAME, B_TRUE, 42919234SGeorge.Wilson@Sun.COM B_TRUE }, 4292*11314Swilliam.gorrell@sun.com { zfs_ioc_destroy_snaps, zfs_secpolicy_destroy_snaps, DATASET_NAME, 4293*11314Swilliam.gorrell@sun.com B_TRUE, B_TRUE }, 42949234SGeorge.Wilson@Sun.COM { zfs_ioc_snapshot, zfs_secpolicy_snapshot, DATASET_NAME, B_TRUE, 42959234SGeorge.Wilson@Sun.COM B_TRUE }, 42969234SGeorge.Wilson@Sun.COM { zfs_ioc_dsobj_to_dsname, zfs_secpolicy_config, POOL_NAME, B_FALSE, 42979234SGeorge.Wilson@Sun.COM B_FALSE }, 429810233SGeorge.Wilson@Sun.COM { zfs_ioc_obj_to_path, zfs_secpolicy_config, DATASET_NAME, B_FALSE, 429910233SGeorge.Wilson@Sun.COM B_TRUE }, 43009234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_set_props, zfs_secpolicy_config, POOL_NAME, B_TRUE, 43019234SGeorge.Wilson@Sun.COM B_TRUE }, 43029234SGeorge.Wilson@Sun.COM { zfs_ioc_pool_get_props, zfs_secpolicy_read, POOL_NAME, B_FALSE, 43039234SGeorge.Wilson@Sun.COM B_FALSE }, 43049234SGeorge.Wilson@Sun.COM { zfs_ioc_set_fsacl, zfs_secpolicy_fsacl, DATASET_NAME, B_TRUE, 43059234SGeorge.Wilson@Sun.COM B_TRUE }, 43069234SGeorge.Wilson@Sun.COM { zfs_ioc_get_fsacl, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 43079234SGeorge.Wilson@Sun.COM B_FALSE }, 43089234SGeorge.Wilson@Sun.COM { zfs_ioc_iscsi_perm_check, zfs_secpolicy_iscsi, DATASET_NAME, B_FALSE, 43099234SGeorge.Wilson@Sun.COM B_FALSE }, 43109234SGeorge.Wilson@Sun.COM { zfs_ioc_share, zfs_secpolicy_share, DATASET_NAME, B_FALSE, B_FALSE }, 43119234SGeorge.Wilson@Sun.COM { zfs_ioc_inherit_prop, zfs_secpolicy_inherit, DATASET_NAME, B_TRUE, 43129234SGeorge.Wilson@Sun.COM B_TRUE }, 43139234SGeorge.Wilson@Sun.COM { zfs_ioc_smb_acl, zfs_secpolicy_smb_acl, DATASET_NAME, B_FALSE, 43149396SMatthew.Ahrens@Sun.COM B_FALSE }, 43159396SMatthew.Ahrens@Sun.COM { zfs_ioc_userspace_one, zfs_secpolicy_userspace_one, 43169396SMatthew.Ahrens@Sun.COM DATASET_NAME, B_FALSE, B_FALSE }, 43179396SMatthew.Ahrens@Sun.COM { zfs_ioc_userspace_many, zfs_secpolicy_userspace_many, 43189396SMatthew.Ahrens@Sun.COM DATASET_NAME, B_FALSE, B_FALSE }, 43199396SMatthew.Ahrens@Sun.COM { zfs_ioc_userspace_upgrade, zfs_secpolicy_userspace_upgrade, 43209396SMatthew.Ahrens@Sun.COM DATASET_NAME, B_FALSE, B_TRUE }, 432110242Schris.kirby@sun.com { zfs_ioc_hold, zfs_secpolicy_hold, DATASET_NAME, B_TRUE, B_TRUE }, 432210242Schris.kirby@sun.com { zfs_ioc_release, zfs_secpolicy_release, DATASET_NAME, B_TRUE, 432310242Schris.kirby@sun.com B_TRUE }, 432410242Schris.kirby@sun.com { zfs_ioc_get_holds, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 432511022STom.Erickson@Sun.COM B_TRUE }, 432611022STom.Erickson@Sun.COM { zfs_ioc_objset_recvd_props, zfs_secpolicy_read, DATASET_NAME, B_FALSE, 432711022STom.Erickson@Sun.COM B_FALSE } 4328789Sahrens }; 4329789Sahrens 43309234SGeorge.Wilson@Sun.COM int 43319234SGeorge.Wilson@Sun.COM pool_status_check(const char *name, zfs_ioc_namecheck_t type) 43329234SGeorge.Wilson@Sun.COM { 43339234SGeorge.Wilson@Sun.COM spa_t *spa; 43349234SGeorge.Wilson@Sun.COM int error; 43359234SGeorge.Wilson@Sun.COM 43369234SGeorge.Wilson@Sun.COM ASSERT(type == POOL_NAME || type == DATASET_NAME); 43379234SGeorge.Wilson@Sun.COM 43389396SMatthew.Ahrens@Sun.COM error = spa_open(name, &spa, FTAG); 43399234SGeorge.Wilson@Sun.COM if (error == 0) { 43409234SGeorge.Wilson@Sun.COM if (spa_suspended(spa)) 43419234SGeorge.Wilson@Sun.COM error = EAGAIN; 43429234SGeorge.Wilson@Sun.COM spa_close(spa, FTAG); 43439234SGeorge.Wilson@Sun.COM } 43449234SGeorge.Wilson@Sun.COM return (error); 43459234SGeorge.Wilson@Sun.COM } 43469234SGeorge.Wilson@Sun.COM 4347789Sahrens static int 4348789Sahrens zfsdev_ioctl(dev_t dev, int cmd, intptr_t arg, int flag, cred_t *cr, int *rvalp) 4349789Sahrens { 4350789Sahrens zfs_cmd_t *zc; 4351789Sahrens uint_t vec; 43522199Sahrens int error, rc; 4353789Sahrens 4354789Sahrens if (getminor(dev) != 0) 4355789Sahrens return (zvol_ioctl(dev, cmd, arg, flag, cr, rvalp)); 4356789Sahrens 4357789Sahrens vec = cmd - ZFS_IOC; 43584787Sahrens ASSERT3U(getmajor(dev), ==, ddi_driver_major(zfs_dip)); 4359789Sahrens 4360789Sahrens if (vec >= sizeof (zfs_ioc_vec) / sizeof (zfs_ioc_vec[0])) 4361789Sahrens return (EINVAL); 4362789Sahrens 4363789Sahrens zc = kmem_zalloc(sizeof (zfs_cmd_t), KM_SLEEP); 4364789Sahrens 43659643SEric.Taylor@Sun.COM error = ddi_copyin((void *)arg, zc, sizeof (zfs_cmd_t), flag); 4366789Sahrens 436710588SEric.Taylor@Sun.COM if ((error == 0) && !(flag & FKIOCTL)) 43684543Smarks error = zfs_ioc_vec[vec].zvec_secpolicy(zc, cr); 4369789Sahrens 4370789Sahrens /* 4371789Sahrens * Ensure that all pool/dataset names are valid before we pass down to 4372789Sahrens * the lower layers. 4373789Sahrens */ 4374789Sahrens if (error == 0) { 4375789Sahrens zc->zc_name[sizeof (zc->zc_name) - 1] = '\0'; 43769643SEric.Taylor@Sun.COM zc->zc_iflags = flag & FKIOCTL; 4377789Sahrens switch (zfs_ioc_vec[vec].zvec_namecheck) { 43784577Sahrens case POOL_NAME: 4379789Sahrens if (pool_namecheck(zc->zc_name, NULL, NULL) != 0) 4380789Sahrens error = EINVAL; 43819234SGeorge.Wilson@Sun.COM if (zfs_ioc_vec[vec].zvec_pool_check) 43829234SGeorge.Wilson@Sun.COM error = pool_status_check(zc->zc_name, 43839234SGeorge.Wilson@Sun.COM zfs_ioc_vec[vec].zvec_namecheck); 4384789Sahrens break; 4385789Sahrens 43864577Sahrens case DATASET_NAME: 4387789Sahrens if (dataset_namecheck(zc->zc_name, NULL, NULL) != 0) 4388789Sahrens error = EINVAL; 43899234SGeorge.Wilson@Sun.COM if (zfs_ioc_vec[vec].zvec_pool_check) 43909234SGeorge.Wilson@Sun.COM error = pool_status_check(zc->zc_name, 43919234SGeorge.Wilson@Sun.COM zfs_ioc_vec[vec].zvec_namecheck); 4392789Sahrens break; 43932856Snd150628 43944577Sahrens case NO_NAME: 43952856Snd150628 break; 4396789Sahrens } 4397789Sahrens } 4398789Sahrens 4399789Sahrens if (error == 0) 4400789Sahrens error = zfs_ioc_vec[vec].zvec_func(zc); 4401789Sahrens 44029643SEric.Taylor@Sun.COM rc = ddi_copyout(zc, (void *)arg, sizeof (zfs_cmd_t), flag); 44034543Smarks if (error == 0) { 44042199Sahrens error = rc; 44059396SMatthew.Ahrens@Sun.COM if (zfs_ioc_vec[vec].zvec_his_log) 44064543Smarks zfs_log_history(zc); 44074543Smarks } 4408789Sahrens 4409789Sahrens kmem_free(zc, sizeof (zfs_cmd_t)); 4410789Sahrens return (error); 4411789Sahrens } 4412789Sahrens 4413789Sahrens static int 4414789Sahrens zfs_attach(dev_info_t *dip, ddi_attach_cmd_t cmd) 4415789Sahrens { 4416789Sahrens if (cmd != DDI_ATTACH) 4417789Sahrens return (DDI_FAILURE); 4418789Sahrens 4419789Sahrens if (ddi_create_minor_node(dip, "zfs", S_IFCHR, 0, 4420789Sahrens DDI_PSEUDO, 0) == DDI_FAILURE) 4421789Sahrens return (DDI_FAILURE); 4422789Sahrens 4423789Sahrens zfs_dip = dip; 4424789Sahrens 4425789Sahrens ddi_report_dev(dip); 4426789Sahrens 4427789Sahrens return (DDI_SUCCESS); 4428789Sahrens } 4429789Sahrens 4430789Sahrens static int 4431789Sahrens zfs_detach(dev_info_t *dip, ddi_detach_cmd_t cmd) 4432789Sahrens { 4433789Sahrens if (spa_busy() || zfs_busy() || zvol_busy()) 4434789Sahrens return (DDI_FAILURE); 4435789Sahrens 4436789Sahrens if (cmd != DDI_DETACH) 4437789Sahrens return (DDI_FAILURE); 4438789Sahrens 4439789Sahrens zfs_dip = NULL; 4440789Sahrens 4441789Sahrens ddi_prop_remove_all(dip); 4442789Sahrens ddi_remove_minor_node(dip, NULL); 4443789Sahrens 4444789Sahrens return (DDI_SUCCESS); 4445789Sahrens } 4446789Sahrens 4447789Sahrens /*ARGSUSED*/ 4448789Sahrens static int 4449789Sahrens zfs_info(dev_info_t *dip, ddi_info_cmd_t infocmd, void *arg, void **result) 4450789Sahrens { 4451789Sahrens switch (infocmd) { 4452789Sahrens case DDI_INFO_DEVT2DEVINFO: 4453789Sahrens *result = zfs_dip; 4454789Sahrens return (DDI_SUCCESS); 4455789Sahrens 4456789Sahrens case DDI_INFO_DEVT2INSTANCE: 4457849Sbonwick *result = (void *)0; 4458789Sahrens return (DDI_SUCCESS); 4459789Sahrens } 4460789Sahrens 4461789Sahrens return (DDI_FAILURE); 4462789Sahrens } 4463789Sahrens 4464789Sahrens /* 4465789Sahrens * OK, so this is a little weird. 4466789Sahrens * 4467789Sahrens * /dev/zfs is the control node, i.e. minor 0. 4468789Sahrens * /dev/zvol/[r]dsk/pool/dataset are the zvols, minor > 0. 4469789Sahrens * 4470789Sahrens * /dev/zfs has basically nothing to do except serve up ioctls, 4471789Sahrens * so most of the standard driver entry points are in zvol.c. 4472789Sahrens */ 4473789Sahrens static struct cb_ops zfs_cb_ops = { 4474789Sahrens zvol_open, /* open */ 4475789Sahrens zvol_close, /* close */ 4476789Sahrens zvol_strategy, /* strategy */ 4477789Sahrens nodev, /* print */ 44786423Sgw25295 zvol_dump, /* dump */ 4479789Sahrens zvol_read, /* read */ 4480789Sahrens zvol_write, /* write */ 4481789Sahrens zfsdev_ioctl, /* ioctl */ 4482789Sahrens nodev, /* devmap */ 4483789Sahrens nodev, /* mmap */ 4484789Sahrens nodev, /* segmap */ 4485789Sahrens nochpoll, /* poll */ 4486789Sahrens ddi_prop_op, /* prop_op */ 4487789Sahrens NULL, /* streamtab */ 4488789Sahrens D_NEW | D_MP | D_64BIT, /* Driver compatibility flag */ 4489789Sahrens CB_REV, /* version */ 44903638Sbillm nodev, /* async read */ 44913638Sbillm nodev, /* async write */ 4492789Sahrens }; 4493789Sahrens 4494789Sahrens static struct dev_ops zfs_dev_ops = { 4495789Sahrens DEVO_REV, /* version */ 4496789Sahrens 0, /* refcnt */ 4497789Sahrens zfs_info, /* info */ 4498789Sahrens nulldev, /* identify */ 4499789Sahrens nulldev, /* probe */ 4500789Sahrens zfs_attach, /* attach */ 4501789Sahrens zfs_detach, /* detach */ 4502789Sahrens nodev, /* reset */ 4503789Sahrens &zfs_cb_ops, /* driver operations */ 45047656SSherry.Moore@Sun.COM NULL, /* no bus operations */ 45057656SSherry.Moore@Sun.COM NULL, /* power */ 45067656SSherry.Moore@Sun.COM ddi_quiesce_not_needed, /* quiesce */ 4507789Sahrens }; 4508789Sahrens 4509789Sahrens static struct modldrv zfs_modldrv = { 45107656SSherry.Moore@Sun.COM &mod_driverops, 45117656SSherry.Moore@Sun.COM "ZFS storage pool", 45127656SSherry.Moore@Sun.COM &zfs_dev_ops 4513789Sahrens }; 4514789Sahrens 4515789Sahrens static struct modlinkage modlinkage = { 4516789Sahrens MODREV_1, 4517789Sahrens (void *)&zfs_modlfs, 4518789Sahrens (void *)&zfs_modldrv, 4519789Sahrens NULL 4520789Sahrens }; 4521789Sahrens 45224720Sfr157268 45234720Sfr157268 uint_t zfs_fsyncer_key; 45245326Sek110237 extern uint_t rrw_tsd_key; 45254720Sfr157268 4526789Sahrens int 4527789Sahrens _init(void) 4528789Sahrens { 4529789Sahrens int error; 4530789Sahrens 4531849Sbonwick spa_init(FREAD | FWRITE); 4532849Sbonwick zfs_init(); 4533849Sbonwick zvol_init(); 4534849Sbonwick 4535849Sbonwick if ((error = mod_install(&modlinkage)) != 0) { 4536849Sbonwick zvol_fini(); 4537849Sbonwick zfs_fini(); 4538849Sbonwick spa_fini(); 4539789Sahrens return (error); 4540849Sbonwick } 4541789Sahrens 45424720Sfr157268 tsd_create(&zfs_fsyncer_key, NULL); 45435326Sek110237 tsd_create(&rrw_tsd_key, NULL); 45444720Sfr157268 4545789Sahrens error = ldi_ident_from_mod(&modlinkage, &zfs_li); 4546789Sahrens ASSERT(error == 0); 45474543Smarks mutex_init(&zfs_share_lock, NULL, MUTEX_DEFAULT, NULL); 4548789Sahrens 4549789Sahrens return (0); 4550789Sahrens } 4551789Sahrens 4552789Sahrens int 4553789Sahrens _fini(void) 4554789Sahrens { 4555789Sahrens int error; 4556789Sahrens 45571544Seschrock if (spa_busy() || zfs_busy() || zvol_busy() || zio_injection_enabled) 4558789Sahrens return (EBUSY); 4559789Sahrens 4560789Sahrens if ((error = mod_remove(&modlinkage)) != 0) 4561789Sahrens return (error); 4562789Sahrens 4563789Sahrens zvol_fini(); 4564789Sahrens zfs_fini(); 4565789Sahrens spa_fini(); 45665331Samw if (zfs_nfsshare_inited) 45674543Smarks (void) ddi_modclose(nfs_mod); 45685331Samw if (zfs_smbshare_inited) 45695331Samw (void) ddi_modclose(smbsrv_mod); 45705331Samw if (zfs_nfsshare_inited || zfs_smbshare_inited) 45714543Smarks (void) ddi_modclose(sharefs_mod); 4572789Sahrens 45734720Sfr157268 tsd_destroy(&zfs_fsyncer_key); 4574789Sahrens ldi_ident_release(zfs_li); 4575789Sahrens zfs_li = NULL; 45764543Smarks mutex_destroy(&zfs_share_lock); 4577789Sahrens 4578789Sahrens return (error); 4579789Sahrens } 4580789Sahrens 4581789Sahrens int 4582789Sahrens _info(struct modinfo *modinfop) 4583789Sahrens { 4584789Sahrens return (mod_info(&modlinkage, modinfop)); 4585789Sahrens } 4586