2016-09-22 23:28:11 +02:00
|
|
|
package fusefrontend_reverse
|
|
|
|
|
|
|
|
import (
|
2017-07-29 16:13:38 +02:00
|
|
|
"log"
|
2018-01-17 21:36:38 +01:00
|
|
|
"path/filepath"
|
2016-09-22 23:28:11 +02:00
|
|
|
"syscall"
|
|
|
|
|
2018-01-17 21:36:38 +01:00
|
|
|
"golang.org/x/sys/unix"
|
|
|
|
|
2016-09-22 23:28:11 +02:00
|
|
|
"github.com/hanwen/go-fuse/fuse"
|
|
|
|
"github.com/hanwen/go-fuse/fuse/nodefs"
|
2017-04-01 15:49:53 +02:00
|
|
|
|
2017-08-06 23:12:27 +02:00
|
|
|
"github.com/rfjakob/gocryptfs/internal/nametransform"
|
2017-05-28 18:09:02 +02:00
|
|
|
"github.com/rfjakob/gocryptfs/internal/pathiv"
|
2018-01-17 21:36:38 +01:00
|
|
|
"github.com/rfjakob/gocryptfs/internal/syscallcompat"
|
2017-04-01 15:49:53 +02:00
|
|
|
"github.com/rfjakob/gocryptfs/internal/tlog"
|
2016-09-22 23:28:11 +02:00
|
|
|
)
|
|
|
|
|
2017-04-01 17:19:15 +02:00
|
|
|
const (
|
|
|
|
// virtualFileMode is the mode to use for virtual files (gocryptfs.diriv and
|
|
|
|
// *.name). They are always readable, as stated in func Access
|
|
|
|
virtualFileMode = syscall.S_IFREG | 0444
|
2017-07-29 16:13:38 +02:00
|
|
|
// inoBaseDirIV is the start of the inode number range that is used
|
|
|
|
// for virtual gocryptfs.diriv files. inoBaseNameFile is the thing for
|
|
|
|
// *.name files.
|
2017-04-01 17:19:15 +02:00
|
|
|
// The value 10^19 is just below 2^60. A power of 10 has been chosen so the
|
|
|
|
// "ls -li" output (which is base-10) is easy to read.
|
2017-07-29 16:13:38 +02:00
|
|
|
// 10^19 is the largest power of 10 that is smaller than
|
|
|
|
// INT64_MAX (=UINT64_MAX/2). This avoids signedness issues.
|
|
|
|
inoBaseDirIV = uint64(1000000000000000000)
|
|
|
|
inoBaseNameFile = uint64(2000000000000000000)
|
|
|
|
// inoBaseMin marks the start of the inode number space that is
|
|
|
|
// reserved for virtual files. It is the lowest of the inoBaseXXX values
|
|
|
|
// above.
|
|
|
|
inoBaseMin = inoBaseDirIV
|
2017-04-01 17:19:15 +02:00
|
|
|
)
|
|
|
|
|
2016-11-10 00:38:01 +01:00
|
|
|
func (rfs *ReverseFS) newDirIVFile(cRelPath string) (nodefs.File, fuse.Status) {
|
2017-08-06 23:12:27 +02:00
|
|
|
cDir := nametransform.Dir(cRelPath)
|
2018-01-17 21:36:38 +01:00
|
|
|
dir, err := rfs.decryptPath(cDir)
|
2016-09-28 23:30:13 +02:00
|
|
|
if err != nil {
|
|
|
|
return nil, fuse.ToStatus(err)
|
|
|
|
}
|
2018-01-17 21:36:38 +01:00
|
|
|
iv := pathiv.Derive(cDir, pathiv.PurposeDirIV)
|
|
|
|
return rfs.newVirtualFile(iv, rfs.args.Cipherdir, dir, inoBaseDirIV)
|
2016-09-28 23:30:13 +02:00
|
|
|
}
|
|
|
|
|
2016-09-22 23:28:11 +02:00
|
|
|
type virtualFile struct {
|
|
|
|
// Embed nodefs.defaultFile for a ENOSYS implementation of all methods
|
|
|
|
nodefs.File
|
|
|
|
// file content
|
|
|
|
content []byte
|
2018-01-17 21:36:38 +01:00
|
|
|
// backing directory
|
|
|
|
cipherdir string
|
|
|
|
// path to a parent file (relative to cipherdir)
|
2016-09-22 23:28:11 +02:00
|
|
|
parentFile string
|
2017-07-29 16:13:38 +02:00
|
|
|
// inode number of a virtual file is inode of parent file plus inoBase
|
|
|
|
inoBase uint64
|
2016-09-22 23:28:11 +02:00
|
|
|
}
|
|
|
|
|
2017-04-01 14:17:54 +02:00
|
|
|
// newVirtualFile creates a new in-memory file that does not have a representation
|
|
|
|
// on disk. "content" is the file content. Timestamps and file owner are copied
|
2018-01-17 21:36:38 +01:00
|
|
|
// from "parentFile" (plaintext path relative to "cipherdir").
|
|
|
|
// For a "gocryptfs.diriv" file, you would use the parent directory as
|
|
|
|
// "parentFile".
|
|
|
|
func (rfs *ReverseFS) newVirtualFile(content []byte, cipherdir string, parentFile string, inoBase uint64) (nodefs.File, fuse.Status) {
|
2017-07-29 16:13:38 +02:00
|
|
|
if inoBase < inoBaseMin {
|
|
|
|
log.Panicf("BUG: virtual inode number base %d is below reserved space", inoBase)
|
|
|
|
}
|
2016-09-22 23:28:11 +02:00
|
|
|
return &virtualFile{
|
|
|
|
File: nodefs.NewDefaultFile(),
|
|
|
|
content: content,
|
2018-01-17 21:36:38 +01:00
|
|
|
cipherdir: cipherdir,
|
2016-09-22 23:28:11 +02:00
|
|
|
parentFile: parentFile,
|
2017-07-29 16:13:38 +02:00
|
|
|
inoBase: inoBase,
|
2016-09-22 23:28:11 +02:00
|
|
|
}, fuse.OK
|
|
|
|
}
|
|
|
|
|
|
|
|
// Read - FUSE call
|
|
|
|
func (f *virtualFile) Read(buf []byte, off int64) (resultData fuse.ReadResult, status fuse.Status) {
|
|
|
|
if off >= int64(len(f.content)) {
|
|
|
|
return nil, fuse.OK
|
|
|
|
}
|
|
|
|
end := int(off) + len(buf)
|
|
|
|
if end > len(f.content) {
|
|
|
|
end = len(f.content)
|
|
|
|
}
|
|
|
|
return fuse.ReadResultData(f.content[off:end]), fuse.OK
|
|
|
|
}
|
|
|
|
|
|
|
|
// GetAttr - FUSE call
|
|
|
|
func (f *virtualFile) GetAttr(a *fuse.Attr) fuse.Status {
|
2018-01-17 21:36:38 +01:00
|
|
|
dir := filepath.Dir(f.parentFile)
|
2018-09-08 17:41:17 +02:00
|
|
|
dirfd, err := syscallcompat.OpenDirNofollow(f.cipherdir, dir)
|
2018-01-17 21:36:38 +01:00
|
|
|
if err != nil {
|
|
|
|
return fuse.ToStatus(err)
|
|
|
|
}
|
|
|
|
defer syscall.Close(dirfd)
|
|
|
|
name := filepath.Base(f.parentFile)
|
|
|
|
var st unix.Stat_t
|
|
|
|
err = syscallcompat.Fstatat(dirfd, name, &st, unix.AT_SYMLINK_NOFOLLOW)
|
2016-09-22 23:28:11 +02:00
|
|
|
if err != nil {
|
2018-01-17 21:36:38 +01:00
|
|
|
tlog.Debug.Printf("GetAttr: Fstatat %q: %v\n", f.parentFile, err)
|
2016-09-22 23:28:11 +02:00
|
|
|
return fuse.ToStatus(err)
|
|
|
|
}
|
2017-07-29 16:13:38 +02:00
|
|
|
if st.Ino > inoBaseMin {
|
2017-04-01 17:19:15 +02:00
|
|
|
tlog.Warn.Printf("virtualFile.GetAttr: parent file inode number %d crosses reserved space, max=%d. Returning EOVERFLOW.",
|
2017-07-29 16:13:38 +02:00
|
|
|
st.Ino, inoBaseMin)
|
2017-04-01 17:19:15 +02:00
|
|
|
return fuse.ToStatus(syscall.EOVERFLOW)
|
|
|
|
}
|
2017-07-29 16:13:38 +02:00
|
|
|
st.Ino = st.Ino + f.inoBase
|
2016-09-22 23:28:11 +02:00
|
|
|
st.Size = int64(len(f.content))
|
2017-03-27 22:47:45 +02:00
|
|
|
st.Mode = virtualFileMode
|
2016-09-22 23:28:11 +02:00
|
|
|
st.Nlink = 1
|
2018-01-17 21:36:38 +01:00
|
|
|
st2 := syscallcompat.Unix2syscall(st)
|
|
|
|
a.FromStat(&st2)
|
2016-09-22 23:28:11 +02:00
|
|
|
return fuse.OK
|
|
|
|
}
|