The Design and Implementation of the FreeBSD Operating System, Second Edition
Now available: The Design and Implementation of the FreeBSD Operating System (Second Edition)


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]

FreeBSD/Linux Kernel Cross Reference
sys/fs/nfsserver/nfs_nfsdport.c

Version: -  FREEBSD  -  FREEBSD-13-STABLE  -  FREEBSD-13-0  -  FREEBSD-12-STABLE  -  FREEBSD-12-0  -  FREEBSD-11-STABLE  -  FREEBSD-11-0  -  FREEBSD-10-STABLE  -  FREEBSD-10-0  -  FREEBSD-9-STABLE  -  FREEBSD-9-0  -  FREEBSD-8-STABLE  -  FREEBSD-8-0  -  FREEBSD-7-STABLE  -  FREEBSD-7-0  -  FREEBSD-6-STABLE  -  FREEBSD-6-0  -  FREEBSD-5-STABLE  -  FREEBSD-5-0  -  FREEBSD-4-STABLE  -  FREEBSD-3-STABLE  -  FREEBSD22  -  l41  -  OPENBSD  -  linux-2.6  -  MK84  -  PLAN9  -  xnu-8792 
SearchContext: -  none  -  3  -  10 

    1 /*-
    2  * SPDX-License-Identifier: BSD-3-Clause
    3  *
    4  * Copyright (c) 1989, 1993
    5  *      The Regents of the University of California.  All rights reserved.
    6  *
    7  * This code is derived from software contributed to Berkeley by
    8  * Rick Macklem at The University of Guelph.
    9  *
   10  * Redistribution and use in source and binary forms, with or without
   11  * modification, are permitted provided that the following conditions
   12  * are met:
   13  * 1. Redistributions of source code must retain the above copyright
   14  *    notice, this list of conditions and the following disclaimer.
   15  * 2. Redistributions in binary form must reproduce the above copyright
   16  *    notice, this list of conditions and the following disclaimer in the
   17  *    documentation and/or other materials provided with the distribution.
   18  * 3. Neither the name of the University nor the names of its contributors
   19  *    may be used to endorse or promote products derived from this software
   20  *    without specific prior written permission.
   21  *
   22  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
   23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
   24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
   25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
   26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
   27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
   28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
   29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
   30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
   31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
   32  * SUCH DAMAGE.
   33  *
   34  */
   35 
   36 #include <sys/cdefs.h>
   37 __FBSDID("$FreeBSD: releng/12.0/sys/fs/nfsserver/nfs_nfsdport.c 340855 2018-11-23 21:08:11Z emaste $");
   38 
   39 #include <sys/capsicum.h>
   40 #include <sys/extattr.h>
   41 
   42 /*
   43  * Functions that perform the vfs operations required by the routines in
   44  * nfsd_serv.c. It is hoped that this change will make the server more
   45  * portable.
   46  */
   47 
   48 #include <fs/nfs/nfsport.h>
   49 #include <sys/hash.h>
   50 #include <sys/sysctl.h>
   51 #include <nlm/nlm_prot.h>
   52 #include <nlm/nlm.h>
   53 
   54 FEATURE(nfsd, "NFSv4 server");
   55 
   56 extern u_int32_t newnfs_true, newnfs_false, newnfs_xdrneg1;
   57 extern int nfsrv_useacl;
   58 extern int newnfs_numnfsd;
   59 extern struct mount nfsv4root_mnt;
   60 extern struct nfsrv_stablefirst nfsrv_stablefirst;
   61 extern void (*nfsd_call_servertimer)(void);
   62 extern SVCPOOL  *nfsrvd_pool;
   63 extern struct nfsv4lock nfsd_suspend_lock;
   64 extern struct nfsclienthashhead *nfsclienthash;
   65 extern struct nfslockhashhead *nfslockhash;
   66 extern struct nfssessionhash *nfssessionhash;
   67 extern int nfsrv_sessionhashsize;
   68 extern struct nfsstatsv1 nfsstatsv1;
   69 extern struct nfslayouthash *nfslayouthash;
   70 extern int nfsrv_layouthashsize;
   71 extern struct mtx nfsrv_dslock_mtx;
   72 extern int nfs_pnfsiothreads;
   73 extern struct nfsdontlisthead nfsrv_dontlisthead;
   74 extern volatile int nfsrv_dontlistlen;
   75 extern volatile int nfsrv_devidcnt;
   76 extern int nfsrv_maxpnfsmirror;
   77 struct vfsoptlist nfsv4root_opt, nfsv4root_newopt;
   78 NFSDLOCKMUTEX;
   79 NFSSTATESPINLOCK;
   80 struct nfsrchash_bucket nfsrchash_table[NFSRVCACHE_HASHSIZE];
   81 struct nfsrchash_bucket nfsrcahash_table[NFSRVCACHE_HASHSIZE];
   82 struct mtx nfsrc_udpmtx;
   83 struct mtx nfs_v4root_mutex;
   84 struct mtx nfsrv_dontlistlock_mtx;
   85 struct mtx nfsrv_recalllock_mtx;
   86 struct nfsrvfh nfs_rootfh, nfs_pubfh;
   87 int nfs_pubfhset = 0, nfs_rootfhset = 0;
   88 struct proc *nfsd_master_proc = NULL;
   89 int nfsd_debuglevel = 0;
   90 static pid_t nfsd_master_pid = (pid_t)-1;
   91 static char nfsd_master_comm[MAXCOMLEN + 1];
   92 static struct timeval nfsd_master_start;
   93 static uint32_t nfsv4_sysid = 0;
   94 static fhandle_t zerofh;
   95 
   96 static int nfssvc_srvcall(struct thread *, struct nfssvc_args *,
   97     struct ucred *);
   98 
   99 int nfsrv_enable_crossmntpt = 1;
  100 static int nfs_commit_blks;
  101 static int nfs_commit_miss;
  102 extern int nfsrv_issuedelegs;
  103 extern int nfsrv_dolocallocks;
  104 extern int nfsd_enable_stringtouid;
  105 extern struct nfsdevicehead nfsrv_devidhead;
  106 
  107 static void nfsrv_pnfscreate(struct vnode *, struct vattr *, struct ucred *,
  108     NFSPROC_T *);
  109 static void nfsrv_pnfsremovesetup(struct vnode *, NFSPROC_T *, struct vnode **,
  110     int *, char *, fhandle_t *);
  111 static void nfsrv_pnfsremove(struct vnode **, int, char *, fhandle_t *,
  112     NFSPROC_T *);
  113 static int nfsrv_proxyds(struct nfsrv_descript *, struct vnode *, off_t, int,
  114     struct ucred *, struct thread *, int, struct mbuf **, char *,
  115     struct mbuf **, struct nfsvattr *, struct acl *);
  116 static int nfsrv_setextattr(struct vnode *, struct nfsvattr *, NFSPROC_T *);
  117 static int nfsrv_readdsrpc(fhandle_t *, off_t, int, struct ucred *,
  118     NFSPROC_T *, struct nfsmount *, struct mbuf **, struct mbuf **);
  119 static int nfsrv_writedsrpc(fhandle_t *, off_t, int, struct ucred *,
  120     NFSPROC_T *, struct vnode *, struct nfsmount **, int, struct mbuf **,
  121     char *, int *);
  122 static int nfsrv_setacldsrpc(fhandle_t *, struct ucred *, NFSPROC_T *,
  123     struct vnode *, struct nfsmount **, int, struct acl *, int *);
  124 static int nfsrv_setattrdsrpc(fhandle_t *, struct ucred *, NFSPROC_T *,
  125     struct vnode *, struct nfsmount **, int, struct nfsvattr *, int *);
  126 static int nfsrv_getattrdsrpc(fhandle_t *, struct ucred *, NFSPROC_T *,
  127     struct vnode *, struct nfsmount *, struct nfsvattr *);
  128 static int nfsrv_putfhname(fhandle_t *, char *);
  129 static int nfsrv_pnfslookupds(struct vnode *, struct vnode *,
  130     struct pnfsdsfile *, struct vnode **, NFSPROC_T *);
  131 static void nfsrv_pnfssetfh(struct vnode *, struct pnfsdsfile *, char *, char *,
  132     struct vnode *, NFSPROC_T *);
  133 static int nfsrv_dsremove(struct vnode *, char *, struct ucred *, NFSPROC_T *);
  134 static int nfsrv_dssetacl(struct vnode *, struct acl *, struct ucred *,
  135     NFSPROC_T *);
  136 static int nfsrv_pnfsstatfs(struct statfs *, struct mount *);
  137 
  138 int nfs_pnfsio(task_fn_t *, void *);
  139 
  140 SYSCTL_NODE(_vfs, OID_AUTO, nfsd, CTLFLAG_RW, 0, "NFS server");
  141 SYSCTL_INT(_vfs_nfsd, OID_AUTO, mirrormnt, CTLFLAG_RW,
  142     &nfsrv_enable_crossmntpt, 0, "Enable nfsd to cross mount points");
  143 SYSCTL_INT(_vfs_nfsd, OID_AUTO, commit_blks, CTLFLAG_RW, &nfs_commit_blks,
  144     0, "");
  145 SYSCTL_INT(_vfs_nfsd, OID_AUTO, commit_miss, CTLFLAG_RW, &nfs_commit_miss,
  146     0, "");
  147 SYSCTL_INT(_vfs_nfsd, OID_AUTO, issue_delegations, CTLFLAG_RW,
  148     &nfsrv_issuedelegs, 0, "Enable nfsd to issue delegations");
  149 SYSCTL_INT(_vfs_nfsd, OID_AUTO, enable_locallocks, CTLFLAG_RW,
  150     &nfsrv_dolocallocks, 0, "Enable nfsd to acquire local locks on files");
  151 SYSCTL_INT(_vfs_nfsd, OID_AUTO, debuglevel, CTLFLAG_RW, &nfsd_debuglevel,
  152     0, "Debug level for NFS server");
  153 SYSCTL_INT(_vfs_nfsd, OID_AUTO, enable_stringtouid, CTLFLAG_RW,
  154     &nfsd_enable_stringtouid, 0, "Enable nfsd to accept numeric owner_names");
  155 static int nfsrv_pnfsgetdsattr = 1;
  156 SYSCTL_INT(_vfs_nfsd, OID_AUTO, pnfsgetdsattr, CTLFLAG_RW,
  157     &nfsrv_pnfsgetdsattr, 0, "When set getattr gets DS attributes via RPC");
  158 
  159 /*
  160  * nfsrv_dsdirsize can only be increased and only when the nfsd threads are
  161  * not running.
  162  * The dsN subdirectories for the increased values must have been created
  163  * on all DS servers before this increase is done.
  164  */
  165 u_int   nfsrv_dsdirsize = 20;
  166 static int
  167 sysctl_dsdirsize(SYSCTL_HANDLER_ARGS)
  168 {
  169         int error, newdsdirsize;
  170 
  171         newdsdirsize = nfsrv_dsdirsize;
  172         error = sysctl_handle_int(oidp, &newdsdirsize, 0, req);
  173         if (error != 0 || req->newptr == NULL)
  174                 return (error);
  175         if (newdsdirsize <= nfsrv_dsdirsize || newdsdirsize > 10000 ||
  176             newnfs_numnfsd != 0)
  177                 return (EINVAL);
  178         nfsrv_dsdirsize = newdsdirsize;
  179         return (0);
  180 }
  181 SYSCTL_PROC(_vfs_nfsd, OID_AUTO, dsdirsize, CTLTYPE_UINT | CTLFLAG_RW, 0,
  182     sizeof(nfsrv_dsdirsize), sysctl_dsdirsize, "IU",
  183     "Number of dsN subdirs on the DS servers");
  184 
  185 #define MAX_REORDERED_RPC       16
  186 #define NUM_HEURISTIC           1031
  187 #define NHUSE_INIT              64
  188 #define NHUSE_INC               16
  189 #define NHUSE_MAX               2048
  190 
  191 static struct nfsheur {
  192         struct vnode *nh_vp;    /* vp to match (unreferenced pointer) */
  193         off_t nh_nextoff;       /* next offset for sequential detection */
  194         int nh_use;             /* use count for selection */
  195         int nh_seqcount;        /* heuristic */
  196 } nfsheur[NUM_HEURISTIC];
  197 
  198 
  199 /*
  200  * Heuristic to detect sequential operation.
  201  */
  202 static struct nfsheur *
  203 nfsrv_sequential_heuristic(struct uio *uio, struct vnode *vp)
  204 {
  205         struct nfsheur *nh;
  206         int hi, try;
  207 
  208         /* Locate best candidate. */
  209         try = 32;
  210         hi = ((int)(vm_offset_t)vp / sizeof(struct vnode)) % NUM_HEURISTIC;
  211         nh = &nfsheur[hi];
  212         while (try--) {
  213                 if (nfsheur[hi].nh_vp == vp) {
  214                         nh = &nfsheur[hi];
  215                         break;
  216                 }
  217                 if (nfsheur[hi].nh_use > 0)
  218                         --nfsheur[hi].nh_use;
  219                 hi = (hi + 1) % NUM_HEURISTIC;
  220                 if (nfsheur[hi].nh_use < nh->nh_use)
  221                         nh = &nfsheur[hi];
  222         }
  223 
  224         /* Initialize hint if this is a new file. */
  225         if (nh->nh_vp != vp) {
  226                 nh->nh_vp = vp;
  227                 nh->nh_nextoff = uio->uio_offset;
  228                 nh->nh_use = NHUSE_INIT;
  229                 if (uio->uio_offset == 0)
  230                         nh->nh_seqcount = 4;
  231                 else
  232                         nh->nh_seqcount = 1;
  233         }
  234 
  235         /* Calculate heuristic. */
  236         if ((uio->uio_offset == 0 && nh->nh_seqcount > 0) ||
  237             uio->uio_offset == nh->nh_nextoff) {
  238                 /* See comments in vfs_vnops.c:sequential_heuristic(). */
  239                 nh->nh_seqcount += howmany(uio->uio_resid, 16384);
  240                 if (nh->nh_seqcount > IO_SEQMAX)
  241                         nh->nh_seqcount = IO_SEQMAX;
  242         } else if (qabs(uio->uio_offset - nh->nh_nextoff) <= MAX_REORDERED_RPC *
  243             imax(vp->v_mount->mnt_stat.f_iosize, uio->uio_resid)) {
  244                 /* Probably a reordered RPC, leave seqcount alone. */
  245         } else if (nh->nh_seqcount > 1) {
  246                 nh->nh_seqcount /= 2;
  247         } else {
  248                 nh->nh_seqcount = 0;
  249         }
  250         nh->nh_use += NHUSE_INC;
  251         if (nh->nh_use > NHUSE_MAX)
  252                 nh->nh_use = NHUSE_MAX;
  253         return (nh);
  254 }
  255 
  256 /*
  257  * Get attributes into nfsvattr structure.
  258  */
  259 int
  260 nfsvno_getattr(struct vnode *vp, struct nfsvattr *nvap,
  261     struct nfsrv_descript *nd, struct thread *p, int vpislocked,
  262     nfsattrbit_t *attrbitp)
  263 {
  264         int error, gotattr, lockedit = 0;
  265         struct nfsvattr na;
  266 
  267         if (vpislocked == 0) {
  268                 /*
  269                  * When vpislocked == 0, the vnode is either exclusively
  270                  * locked by this thread or not locked by this thread.
  271                  * As such, shared lock it, if not exclusively locked.
  272                  */
  273                 if (NFSVOPISLOCKED(vp) != LK_EXCLUSIVE) {
  274                         lockedit = 1;
  275                         NFSVOPLOCK(vp, LK_SHARED | LK_RETRY);
  276                 }
  277         }
  278 
  279         /*
  280          * Acquire the Change, Size and TimeModify attributes, as required.
  281          * This needs to be done for regular files if:
  282          * - non-NFSv4 RPCs or
  283          * - when attrbitp == NULL or
  284          * - an NFSv4 RPC with any of the above attributes in attrbitp.
  285          * A return of 0 for nfsrv_proxyds() indicates that it has acquired
  286          * these attributes.  nfsrv_proxyds() will return an error if the
  287          * server is not a pNFS one.
  288          */
  289         gotattr = 0;
  290         if (vp->v_type == VREG && nfsrv_devidcnt > 0 && (attrbitp == NULL ||
  291             (nd->nd_flag & ND_NFSV4) == 0 ||
  292             NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_CHANGE) ||
  293             NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_SIZE) ||
  294             NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_TIMEACCESS) ||
  295             NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_TIMEMODIFY))) {
  296                 error = nfsrv_proxyds(nd, vp, 0, 0, nd->nd_cred, p,
  297                     NFSPROC_GETATTR, NULL, NULL, NULL, &na, NULL);
  298                 if (error == 0)
  299                         gotattr = 1;
  300         }
  301 
  302         error = VOP_GETATTR(vp, &nvap->na_vattr, nd->nd_cred);
  303         if (lockedit != 0)
  304                 NFSVOPUNLOCK(vp, 0);
  305 
  306         /*
  307          * If we got the Change, Size and Modify Time from the DS,
  308          * replace them.
  309          */
  310         if (gotattr != 0) {
  311                 nvap->na_atime = na.na_atime;
  312                 nvap->na_mtime = na.na_mtime;
  313                 nvap->na_filerev = na.na_filerev;
  314                 nvap->na_size = na.na_size;
  315         }
  316         NFSD_DEBUG(4, "nfsvno_getattr: gotattr=%d err=%d chg=%ju\n", gotattr,
  317             error, (uintmax_t)na.na_filerev);
  318 
  319         NFSEXITCODE(error);
  320         return (error);
  321 }
  322 
  323 /*
  324  * Get a file handle for a vnode.
  325  */
  326 int
  327 nfsvno_getfh(struct vnode *vp, fhandle_t *fhp, struct thread *p)
  328 {
  329         int error;
  330 
  331         NFSBZERO((caddr_t)fhp, sizeof(fhandle_t));
  332         fhp->fh_fsid = vp->v_mount->mnt_stat.f_fsid;
  333         error = VOP_VPTOFH(vp, &fhp->fh_fid);
  334 
  335         NFSEXITCODE(error);
  336         return (error);
  337 }
  338 
  339 /*
  340  * Perform access checking for vnodes obtained from file handles that would
  341  * refer to files already opened by a Unix client. You cannot just use
  342  * vn_writechk() and VOP_ACCESSX() for two reasons.
  343  * 1 - You must check for exported rdonly as well as MNT_RDONLY for the write
  344  *     case.
  345  * 2 - The owner is to be given access irrespective of mode bits for some
  346  *     operations, so that processes that chmod after opening a file don't
  347  *     break.
  348  */
  349 int
  350 nfsvno_accchk(struct vnode *vp, accmode_t accmode, struct ucred *cred,
  351     struct nfsexstuff *exp, struct thread *p, int override, int vpislocked,
  352     u_int32_t *supportedtypep)
  353 {
  354         struct vattr vattr;
  355         int error = 0, getret = 0;
  356 
  357         if (vpislocked == 0) {
  358                 if (NFSVOPLOCK(vp, LK_SHARED) != 0) {
  359                         error = EPERM;
  360                         goto out;
  361                 }
  362         }
  363         if (accmode & VWRITE) {
  364                 /* Just vn_writechk() changed to check rdonly */
  365                 /*
  366                  * Disallow write attempts on read-only file systems;
  367                  * unless the file is a socket or a block or character
  368                  * device resident on the file system.
  369                  */
  370                 if (NFSVNO_EXRDONLY(exp) ||
  371                     (vp->v_mount->mnt_flag & MNT_RDONLY)) {
  372                         switch (vp->v_type) {
  373                         case VREG:
  374                         case VDIR:
  375                         case VLNK:
  376                                 error = EROFS;
  377                         default:
  378                                 break;
  379                         }
  380                 }
  381                 /*
  382                  * If there's shared text associated with
  383                  * the inode, try to free it up once.  If
  384                  * we fail, we can't allow writing.
  385                  */
  386                 if (VOP_IS_TEXT(vp) && error == 0)
  387                         error = ETXTBSY;
  388         }
  389         if (error != 0) {
  390                 if (vpislocked == 0)
  391                         NFSVOPUNLOCK(vp, 0);
  392                 goto out;
  393         }
  394 
  395         /*
  396          * Should the override still be applied when ACLs are enabled?
  397          */
  398         error = VOP_ACCESSX(vp, accmode, cred, p);
  399         if (error != 0 && (accmode & (VDELETE | VDELETE_CHILD))) {
  400                 /*
  401                  * Try again with VEXPLICIT_DENY, to see if the test for
  402                  * deletion is supported.
  403                  */
  404                 error = VOP_ACCESSX(vp, accmode | VEXPLICIT_DENY, cred, p);
  405                 if (error == 0) {
  406                         if (vp->v_type == VDIR) {
  407                                 accmode &= ~(VDELETE | VDELETE_CHILD);
  408                                 accmode |= VWRITE;
  409                                 error = VOP_ACCESSX(vp, accmode, cred, p);
  410                         } else if (supportedtypep != NULL) {
  411                                 *supportedtypep &= ~NFSACCESS_DELETE;
  412                         }
  413                 }
  414         }
  415 
  416         /*
  417          * Allow certain operations for the owner (reads and writes
  418          * on files that are already open).
  419          */
  420         if (override != NFSACCCHK_NOOVERRIDE &&
  421             (error == EPERM || error == EACCES)) {
  422                 if (cred->cr_uid == 0 && (override & NFSACCCHK_ALLOWROOT))
  423                         error = 0;
  424                 else if (override & NFSACCCHK_ALLOWOWNER) {
  425                         getret = VOP_GETATTR(vp, &vattr, cred);
  426                         if (getret == 0 && cred->cr_uid == vattr.va_uid)
  427                                 error = 0;
  428                 }
  429         }
  430         if (vpislocked == 0)
  431                 NFSVOPUNLOCK(vp, 0);
  432 
  433 out:
  434         NFSEXITCODE(error);
  435         return (error);
  436 }
  437 
  438 /*
  439  * Set attribute(s) vnop.
  440  */
  441 int
  442 nfsvno_setattr(struct vnode *vp, struct nfsvattr *nvap, struct ucred *cred,
  443     struct thread *p, struct nfsexstuff *exp)
  444 {
  445         u_quad_t savsize = 0;
  446         int error, savedit;
  447 
  448         /*
  449          * If this is an exported file system and a pNFS service is running,
  450          * don't VOP_SETATTR() of size for the MDS file system.
  451          */
  452         savedit = 0;
  453         error = 0;
  454         if (vp->v_type == VREG && (vp->v_mount->mnt_flag & MNT_EXPORTED) != 0 &&
  455             nfsrv_devidcnt != 0 && nvap->na_vattr.va_size != VNOVAL &&
  456             nvap->na_vattr.va_size > 0) {
  457                 savsize = nvap->na_vattr.va_size;
  458                 nvap->na_vattr.va_size = VNOVAL;
  459                 if (nvap->na_vattr.va_uid != (uid_t)VNOVAL ||
  460                     nvap->na_vattr.va_gid != (gid_t)VNOVAL ||
  461                     nvap->na_vattr.va_mode != (mode_t)VNOVAL ||
  462                     nvap->na_vattr.va_atime.tv_sec != VNOVAL ||
  463                     nvap->na_vattr.va_mtime.tv_sec != VNOVAL)
  464                         savedit = 1;
  465                 else
  466                         savedit = 2;
  467         }
  468         if (savedit != 2)
  469                 error = VOP_SETATTR(vp, &nvap->na_vattr, cred);
  470         if (savedit != 0)
  471                 nvap->na_vattr.va_size = savsize;
  472         if (error == 0 && (nvap->na_vattr.va_uid != (uid_t)VNOVAL ||
  473             nvap->na_vattr.va_gid != (gid_t)VNOVAL ||
  474             nvap->na_vattr.va_size != VNOVAL ||
  475             nvap->na_vattr.va_mode != (mode_t)VNOVAL ||
  476             nvap->na_vattr.va_atime.tv_sec != VNOVAL ||
  477             nvap->na_vattr.va_mtime.tv_sec != VNOVAL)) {
  478                 /* For a pNFS server, set the attributes on the DS file. */
  479                 error = nfsrv_proxyds(NULL, vp, 0, 0, cred, p, NFSPROC_SETATTR,
  480                     NULL, NULL, NULL, nvap, NULL);
  481                 if (error == ENOENT)
  482                         error = 0;
  483         }
  484         NFSEXITCODE(error);
  485         return (error);
  486 }
  487 
  488 /*
  489  * Set up nameidata for a lookup() call and do it.
  490  */
  491 int
  492 nfsvno_namei(struct nfsrv_descript *nd, struct nameidata *ndp,
  493     struct vnode *dp, int islocked, struct nfsexstuff *exp, struct thread *p,
  494     struct vnode **retdirp)
  495 {
  496         struct componentname *cnp = &ndp->ni_cnd;
  497         int i;
  498         struct iovec aiov;
  499         struct uio auio;
  500         int lockleaf = (cnp->cn_flags & LOCKLEAF) != 0, linklen;
  501         int error = 0;
  502         char *cp;
  503 
  504         *retdirp = NULL;
  505         cnp->cn_nameptr = cnp->cn_pnbuf;
  506         ndp->ni_lcf = 0;
  507         /*
  508          * Extract and set starting directory.
  509          */
  510         if (dp->v_type != VDIR) {
  511                 if (islocked)
  512                         vput(dp);
  513                 else
  514                         vrele(dp);
  515                 nfsvno_relpathbuf(ndp);
  516                 error = ENOTDIR;
  517                 goto out1;
  518         }
  519         if (islocked)
  520                 NFSVOPUNLOCK(dp, 0);
  521         VREF(dp);
  522         *retdirp = dp;
  523         if (NFSVNO_EXRDONLY(exp))
  524                 cnp->cn_flags |= RDONLY;
  525         ndp->ni_segflg = UIO_SYSSPACE;
  526 
  527         if (nd->nd_flag & ND_PUBLOOKUP) {
  528                 ndp->ni_loopcnt = 0;
  529                 if (cnp->cn_pnbuf[0] == '/') {
  530                         vrele(dp);
  531                         /*
  532                          * Check for degenerate pathnames here, since lookup()
  533                          * panics on them.
  534                          */
  535                         for (i = 1; i < ndp->ni_pathlen; i++)
  536                                 if (cnp->cn_pnbuf[i] != '/')
  537                                         break;
  538                         if (i == ndp->ni_pathlen) {
  539                                 error = NFSERR_ACCES;
  540                                 goto out;
  541                         }
  542                         dp = rootvnode;
  543                         VREF(dp);
  544                 }
  545         } else if ((nfsrv_enable_crossmntpt == 0 && NFSVNO_EXPORTED(exp)) ||
  546             (nd->nd_flag & ND_NFSV4) == 0) {
  547                 /*
  548                  * Only cross mount points for NFSv4 when doing a
  549                  * mount while traversing the file system above
  550                  * the mount point, unless nfsrv_enable_crossmntpt is set.
  551                  */
  552                 cnp->cn_flags |= NOCROSSMOUNT;
  553         }
  554 
  555         /*
  556          * Initialize for scan, set ni_startdir and bump ref on dp again
  557          * because lookup() will dereference ni_startdir.
  558          */
  559 
  560         cnp->cn_thread = p;
  561         ndp->ni_startdir = dp;
  562         ndp->ni_rootdir = rootvnode;
  563         ndp->ni_topdir = NULL;
  564 
  565         if (!lockleaf)
  566                 cnp->cn_flags |= LOCKLEAF;
  567         for (;;) {
  568                 cnp->cn_nameptr = cnp->cn_pnbuf;
  569                 /*
  570                  * Call lookup() to do the real work.  If an error occurs,
  571                  * ndp->ni_vp and ni_dvp are left uninitialized or NULL and
  572                  * we do not have to dereference anything before returning.
  573                  * In either case ni_startdir will be dereferenced and NULLed
  574                  * out.
  575                  */
  576                 error = lookup(ndp);
  577                 if (error)
  578                         break;
  579 
  580                 /*
  581                  * Check for encountering a symbolic link.  Trivial
  582                  * termination occurs if no symlink encountered.
  583                  */
  584                 if ((cnp->cn_flags & ISSYMLINK) == 0) {
  585                         if ((cnp->cn_flags & (SAVENAME | SAVESTART)) == 0)
  586                                 nfsvno_relpathbuf(ndp);
  587                         if (ndp->ni_vp && !lockleaf)
  588                                 NFSVOPUNLOCK(ndp->ni_vp, 0);
  589                         break;
  590                 }
  591 
  592                 /*
  593                  * Validate symlink
  594                  */
  595                 if ((cnp->cn_flags & LOCKPARENT) && ndp->ni_pathlen == 1)
  596                         NFSVOPUNLOCK(ndp->ni_dvp, 0);
  597                 if (!(nd->nd_flag & ND_PUBLOOKUP)) {
  598                         error = EINVAL;
  599                         goto badlink2;
  600                 }
  601 
  602                 if (ndp->ni_loopcnt++ >= MAXSYMLINKS) {
  603                         error = ELOOP;
  604                         goto badlink2;
  605                 }
  606                 if (ndp->ni_pathlen > 1)
  607                         cp = uma_zalloc(namei_zone, M_WAITOK);
  608                 else
  609                         cp = cnp->cn_pnbuf;
  610                 aiov.iov_base = cp;
  611                 aiov.iov_len = MAXPATHLEN;
  612                 auio.uio_iov = &aiov;
  613                 auio.uio_iovcnt = 1;
  614                 auio.uio_offset = 0;
  615                 auio.uio_rw = UIO_READ;
  616                 auio.uio_segflg = UIO_SYSSPACE;
  617                 auio.uio_td = NULL;
  618                 auio.uio_resid = MAXPATHLEN;
  619                 error = VOP_READLINK(ndp->ni_vp, &auio, cnp->cn_cred);
  620                 if (error) {
  621                 badlink1:
  622                         if (ndp->ni_pathlen > 1)
  623                                 uma_zfree(namei_zone, cp);
  624                 badlink2:
  625                         vrele(ndp->ni_dvp);
  626                         vput(ndp->ni_vp);
  627                         break;
  628                 }
  629                 linklen = MAXPATHLEN - auio.uio_resid;
  630                 if (linklen == 0) {
  631                         error = ENOENT;
  632                         goto badlink1;
  633                 }
  634                 if (linklen + ndp->ni_pathlen >= MAXPATHLEN) {
  635                         error = ENAMETOOLONG;
  636                         goto badlink1;
  637                 }
  638 
  639                 /*
  640                  * Adjust or replace path
  641                  */
  642                 if (ndp->ni_pathlen > 1) {
  643                         NFSBCOPY(ndp->ni_next, cp + linklen, ndp->ni_pathlen);
  644                         uma_zfree(namei_zone, cnp->cn_pnbuf);
  645                         cnp->cn_pnbuf = cp;
  646                 } else
  647                         cnp->cn_pnbuf[linklen] = '\0';
  648                 ndp->ni_pathlen += linklen;
  649 
  650                 /*
  651                  * Cleanup refs for next loop and check if root directory
  652                  * should replace current directory.  Normally ni_dvp
  653                  * becomes the new base directory and is cleaned up when
  654                  * we loop.  Explicitly null pointers after invalidation
  655                  * to clarify operation.
  656                  */
  657                 vput(ndp->ni_vp);
  658                 ndp->ni_vp = NULL;
  659 
  660                 if (cnp->cn_pnbuf[0] == '/') {
  661                         vrele(ndp->ni_dvp);
  662                         ndp->ni_dvp = ndp->ni_rootdir;
  663                         VREF(ndp->ni_dvp);
  664                 }
  665                 ndp->ni_startdir = ndp->ni_dvp;
  666                 ndp->ni_dvp = NULL;
  667         }
  668         if (!lockleaf)
  669                 cnp->cn_flags &= ~LOCKLEAF;
  670 
  671 out:
  672         if (error) {
  673                 nfsvno_relpathbuf(ndp);
  674                 ndp->ni_vp = NULL;
  675                 ndp->ni_dvp = NULL;
  676                 ndp->ni_startdir = NULL;
  677         } else if ((ndp->ni_cnd.cn_flags & (WANTPARENT|LOCKPARENT)) == 0) {
  678                 ndp->ni_dvp = NULL;
  679         }
  680 
  681 out1:
  682         NFSEXITCODE2(error, nd);
  683         return (error);
  684 }
  685 
  686 /*
  687  * Set up a pathname buffer and return a pointer to it and, optionally
  688  * set a hash pointer.
  689  */
  690 void
  691 nfsvno_setpathbuf(struct nameidata *ndp, char **bufpp, u_long **hashpp)
  692 {
  693         struct componentname *cnp = &ndp->ni_cnd;
  694 
  695         cnp->cn_flags |= (NOMACCHECK | HASBUF);
  696         cnp->cn_pnbuf = uma_zalloc(namei_zone, M_WAITOK);
  697         if (hashpp != NULL)
  698                 *hashpp = NULL;
  699         *bufpp = cnp->cn_pnbuf;
  700 }
  701 
  702 /*
  703  * Release the above path buffer, if not released by nfsvno_namei().
  704  */
  705 void
  706 nfsvno_relpathbuf(struct nameidata *ndp)
  707 {
  708 
  709         if ((ndp->ni_cnd.cn_flags & HASBUF) == 0)
  710                 panic("nfsrelpath");
  711         uma_zfree(namei_zone, ndp->ni_cnd.cn_pnbuf);
  712         ndp->ni_cnd.cn_flags &= ~HASBUF;
  713 }
  714 
  715 /*
  716  * Readlink vnode op into an mbuf list.
  717  */
  718 int
  719 nfsvno_readlink(struct vnode *vp, struct ucred *cred, struct thread *p,
  720     struct mbuf **mpp, struct mbuf **mpendp, int *lenp)
  721 {
  722         struct iovec iv[(NFS_MAXPATHLEN+MLEN-1)/MLEN];
  723         struct iovec *ivp = iv;
  724         struct uio io, *uiop = &io;
  725         struct mbuf *mp, *mp2 = NULL, *mp3 = NULL;
  726         int i, len, tlen, error = 0;
  727 
  728         len = 0;
  729         i = 0;
  730         while (len < NFS_MAXPATHLEN) {
  731                 NFSMGET(mp);
  732                 MCLGET(mp, M_WAITOK);
  733                 mp->m_len = M_SIZE(mp);
  734                 if (len == 0) {
  735                         mp3 = mp2 = mp;
  736                 } else {
  737                         mp2->m_next = mp;
  738                         mp2 = mp;
  739                 }
  740                 if ((len + mp->m_len) > NFS_MAXPATHLEN) {
  741                         mp->m_len = NFS_MAXPATHLEN - len;
  742                         len = NFS_MAXPATHLEN;
  743                 } else {
  744                         len += mp->m_len;
  745                 }
  746                 ivp->iov_base = mtod(mp, caddr_t);
  747                 ivp->iov_len = mp->m_len;
  748                 i++;
  749                 ivp++;
  750         }
  751         uiop->uio_iov = iv;
  752         uiop->uio_iovcnt = i;
  753         uiop->uio_offset = 0;
  754         uiop->uio_resid = len;
  755         uiop->uio_rw = UIO_READ;
  756         uiop->uio_segflg = UIO_SYSSPACE;
  757         uiop->uio_td = NULL;
  758         error = VOP_READLINK(vp, uiop, cred);
  759         if (error) {
  760                 m_freem(mp3);
  761                 *lenp = 0;
  762                 goto out;
  763         }
  764         if (uiop->uio_resid > 0) {
  765                 len -= uiop->uio_resid;
  766                 tlen = NFSM_RNDUP(len);
  767                 nfsrv_adj(mp3, NFS_MAXPATHLEN - tlen, tlen - len);
  768         }
  769         *lenp = len;
  770         *mpp = mp3;
  771         *mpendp = mp;
  772 
  773 out:
  774         NFSEXITCODE(error);
  775         return (error);
  776 }
  777 
  778 /*
  779  * Read vnode op call into mbuf list.
  780  */
  781 int
  782 nfsvno_read(struct vnode *vp, off_t off, int cnt, struct ucred *cred,
  783     struct thread *p, struct mbuf **mpp, struct mbuf **mpendp)
  784 {
  785         struct mbuf *m;
  786         int i;
  787         struct iovec *iv;
  788         struct iovec *iv2;
  789         int error = 0, len, left, siz, tlen, ioflag = 0;
  790         struct mbuf *m2 = NULL, *m3;
  791         struct uio io, *uiop = &io;
  792         struct nfsheur *nh;
  793 
  794         /*
  795          * Attempt to read from a DS file. A return of ENOENT implies
  796          * there is no DS file to read.
  797          */
  798         error = nfsrv_proxyds(NULL, vp, off, cnt, cred, p, NFSPROC_READDS, mpp,
  799             NULL, mpendp, NULL, NULL);
  800         if (error != ENOENT)
  801                 return (error);
  802 
  803         len = left = NFSM_RNDUP(cnt);
  804         m3 = NULL;
  805         /*
  806          * Generate the mbuf list with the uio_iov ref. to it.
  807          */
  808         i = 0;
  809         while (left > 0) {
  810                 NFSMGET(m);
  811                 MCLGET(m, M_WAITOK);
  812                 m->m_len = 0;
  813                 siz = min(M_TRAILINGSPACE(m), left);
  814                 left -= siz;
  815                 i++;
  816                 if (m3)
  817                         m2->m_next = m;
  818                 else
  819                         m3 = m;
  820                 m2 = m;
  821         }
  822         iv = malloc(i * sizeof (struct iovec),
  823             M_TEMP, M_WAITOK);
  824         uiop->uio_iov = iv2 = iv;
  825         m = m3;
  826         left = len;
  827         i = 0;
  828         while (left > 0) {
  829                 if (m == NULL)
  830                         panic("nfsvno_read iov");
  831                 siz = min(M_TRAILINGSPACE(m), left);
  832                 if (siz > 0) {
  833                         iv->iov_base = mtod(m, caddr_t) + m->m_len;
  834                         iv->iov_len = siz;
  835                         m->m_len += siz;
  836                         left -= siz;
  837                         iv++;
  838                         i++;
  839                 }
  840                 m = m->m_next;
  841         }
  842         uiop->uio_iovcnt = i;
  843         uiop->uio_offset = off;
  844         uiop->uio_resid = len;
  845         uiop->uio_rw = UIO_READ;
  846         uiop->uio_segflg = UIO_SYSSPACE;
  847         uiop->uio_td = NULL;
  848         nh = nfsrv_sequential_heuristic(uiop, vp);
  849         ioflag |= nh->nh_seqcount << IO_SEQSHIFT;
  850         /* XXX KDM make this more systematic? */
  851         nfsstatsv1.srvbytes[NFSV4OP_READ] += uiop->uio_resid;
  852         error = VOP_READ(vp, uiop, IO_NODELOCKED | ioflag, cred);
  853         free(iv2, M_TEMP);
  854         if (error) {
  855                 m_freem(m3);
  856                 *mpp = NULL;
  857                 goto out;
  858         }
  859         nh->nh_nextoff = uiop->uio_offset;
  860         tlen = len - uiop->uio_resid;
  861         cnt = cnt < tlen ? cnt : tlen;
  862         tlen = NFSM_RNDUP(cnt);
  863         if (tlen == 0) {
  864                 m_freem(m3);
  865                 m3 = NULL;
  866         } else if (len != tlen || tlen != cnt)
  867                 nfsrv_adj(m3, len - tlen, tlen - cnt);
  868         *mpp = m3;
  869         *mpendp = m2;
  870 
  871 out:
  872         NFSEXITCODE(error);
  873         return (error);
  874 }
  875 
  876 /*
  877  * Write vnode op from an mbuf list.
  878  */
  879 int
  880 nfsvno_write(struct vnode *vp, off_t off, int retlen, int cnt, int *stable,
  881     struct mbuf *mp, char *cp, struct ucred *cred, struct thread *p)
  882 {
  883         struct iovec *ivp;
  884         int i, len;
  885         struct iovec *iv;
  886         int ioflags, error;
  887         struct uio io, *uiop = &io;
  888         struct nfsheur *nh;
  889 
  890         /*
  891          * Attempt to write to a DS file. A return of ENOENT implies
  892          * there is no DS file to write.
  893          */
  894         error = nfsrv_proxyds(NULL, vp, off, retlen, cred, p, NFSPROC_WRITEDS,
  895             &mp, cp, NULL, NULL, NULL);
  896         if (error != ENOENT) {
  897                 *stable = NFSWRITE_FILESYNC;
  898                 return (error);
  899         }
  900 
  901         ivp = malloc(cnt * sizeof (struct iovec), M_TEMP,
  902             M_WAITOK);
  903         uiop->uio_iov = iv = ivp;
  904         uiop->uio_iovcnt = cnt;
  905         i = mtod(mp, caddr_t) + mp->m_len - cp;
  906         len = retlen;
  907         while (len > 0) {
  908                 if (mp == NULL)
  909                         panic("nfsvno_write");
  910                 if (i > 0) {
  911                         i = min(i, len);
  912                         ivp->iov_base = cp;
  913                         ivp->iov_len = i;
  914                         ivp++;
  915                         len -= i;
  916                 }
  917                 mp = mp->m_next;
  918                 if (mp) {
  919                         i = mp->m_len;
  920                         cp = mtod(mp, caddr_t);
  921                 }
  922         }
  923 
  924         if (*stable == NFSWRITE_UNSTABLE)
  925                 ioflags = IO_NODELOCKED;
  926         else
  927                 ioflags = (IO_SYNC | IO_NODELOCKED);
  928         uiop->uio_resid = retlen;
  929         uiop->uio_rw = UIO_WRITE;
  930         uiop->uio_segflg = UIO_SYSSPACE;
  931         NFSUIOPROC(uiop, p);
  932         uiop->uio_offset = off;
  933         nh = nfsrv_sequential_heuristic(uiop, vp);
  934         ioflags |= nh->nh_seqcount << IO_SEQSHIFT;
  935         /* XXX KDM make this more systematic? */
  936         nfsstatsv1.srvbytes[NFSV4OP_WRITE] += uiop->uio_resid;
  937         error = VOP_WRITE(vp, uiop, ioflags, cred);
  938         if (error == 0)
  939                 nh->nh_nextoff = uiop->uio_offset;
  940         free(iv, M_TEMP);
  941 
  942         NFSEXITCODE(error);
  943         return (error);
  944 }
  945 
  946 /*
  947  * Common code for creating a regular file (plus special files for V2).
  948  */
  949 int
  950 nfsvno_createsub(struct nfsrv_descript *nd, struct nameidata *ndp,
  951     struct vnode **vpp, struct nfsvattr *nvap, int *exclusive_flagp,
  952     int32_t *cverf, NFSDEV_T rdev, struct thread *p, struct nfsexstuff *exp)
  953 {
  954         u_quad_t tempsize;
  955         int error;
  956 
  957         error = nd->nd_repstat;
  958         if (!error && ndp->ni_vp == NULL) {
  959                 if (nvap->na_type == VREG || nvap->na_type == VSOCK) {
  960                         vrele(ndp->ni_startdir);
  961                         error = VOP_CREATE(ndp->ni_dvp,
  962                             &ndp->ni_vp, &ndp->ni_cnd, &nvap->na_vattr);
  963                         /* For a pNFS server, create the data file on a DS. */
  964                         if (error == 0 && nvap->na_type == VREG) {
  965                                 /*
  966                                  * Create a data file on a DS for a pNFS server.
  967                                  * This function just returns if not
  968                                  * running a pNFS DS or the creation fails.
  969                                  */
  970                                 nfsrv_pnfscreate(ndp->ni_vp, &nvap->na_vattr,
  971                                     nd->nd_cred, p);
  972                         }
  973                         vput(ndp->ni_dvp);
  974                         nfsvno_relpathbuf(ndp);
  975                         if (!error) {
  976                                 if (*exclusive_flagp) {
  977                                         *exclusive_flagp = 0;
  978                                         NFSVNO_ATTRINIT(nvap);
  979                                         nvap->na_atime.tv_sec = cverf[0];
  980                                         nvap->na_atime.tv_nsec = cverf[1];
  981                                         error = VOP_SETATTR(ndp->ni_vp,
  982                                             &nvap->na_vattr, nd->nd_cred);
  983                                         if (error != 0) {
  984                                                 vput(ndp->ni_vp);
  985                                                 ndp->ni_vp = NULL;
  986                                                 error = NFSERR_NOTSUPP;
  987                                         }
  988                                 }
  989                         }
  990                 /*
  991                  * NFS V2 Only. nfsrvd_mknod() does this for V3.
  992                  * (This implies, just get out on an error.)
  993                  */
  994                 } else if (nvap->na_type == VCHR || nvap->na_type == VBLK ||
  995                         nvap->na_type == VFIFO) {
  996                         if (nvap->na_type == VCHR && rdev == 0xffffffff)
  997                                 nvap->na_type = VFIFO;
  998                         if (nvap->na_type != VFIFO &&
  999                             (error = priv_check_cred(nd->nd_cred,
 1000                              PRIV_VFS_MKNOD_DEV, 0))) {
 1001                                 vrele(ndp->ni_startdir);
 1002                                 nfsvno_relpathbuf(ndp);
 1003                                 vput(ndp->ni_dvp);
 1004                                 goto out;
 1005                         }
 1006                         nvap->na_rdev = rdev;
 1007                         error = VOP_MKNOD(ndp->ni_dvp, &ndp->ni_vp,
 1008                             &ndp->ni_cnd, &nvap->na_vattr);
 1009                         vput(ndp->ni_dvp);
 1010                         nfsvno_relpathbuf(ndp);
 1011                         vrele(ndp->ni_startdir);
 1012                         if (error)
 1013                                 goto out;
 1014                 } else {
 1015                         vrele(ndp->ni_startdir);
 1016                         nfsvno_relpathbuf(ndp);
 1017                         vput(ndp->ni_dvp);
 1018                         error = ENXIO;
 1019                         goto out;
 1020                 }
 1021                 *vpp = ndp->ni_vp;
 1022         } else {
 1023                 /*
 1024                  * Handle cases where error is already set and/or
 1025                  * the file exists.
 1026                  * 1 - clean up the lookup
 1027                  * 2 - iff !error and na_size set, truncate it
 1028                  */
 1029                 vrele(ndp->ni_startdir);
 1030                 nfsvno_relpathbuf(ndp);
 1031                 *vpp = ndp->ni_vp;
 1032                 if (ndp->ni_dvp == *vpp)
 1033                         vrele(ndp->ni_dvp);
 1034                 else
 1035                         vput(ndp->ni_dvp);
 1036                 if (!error && nvap->na_size != VNOVAL) {
 1037                         error = nfsvno_accchk(*vpp, VWRITE,
 1038                             nd->nd_cred, exp, p, NFSACCCHK_NOOVERRIDE,
 1039                             NFSACCCHK_VPISLOCKED, NULL);
 1040                         if (!error) {
 1041                                 tempsize = nvap->na_size;
 1042                                 NFSVNO_ATTRINIT(nvap);
 1043                                 nvap->na_size = tempsize;
 1044                                 error = VOP_SETATTR(*vpp,
 1045                                     &nvap->na_vattr, nd->nd_cred);
 1046                         }
 1047                 }
 1048                 if (error)
 1049                         vput(*vpp);
 1050         }
 1051 
 1052 out:
 1053         NFSEXITCODE(error);
 1054         return (error);
 1055 }
 1056 
 1057 /*
 1058  * Do a mknod vnode op.
 1059  */
 1060 int
 1061 nfsvno_mknod(struct nameidata *ndp, struct nfsvattr *nvap, struct ucred *cred,
 1062     struct thread *p)
 1063 {
 1064         int error = 0;
 1065         enum vtype vtyp;
 1066 
 1067         vtyp = nvap->na_type;
 1068         /*
 1069          * Iff doesn't exist, create it.
 1070          */
 1071         if (ndp->ni_vp) {
 1072                 vrele(ndp->ni_startdir);
 1073                 nfsvno_relpathbuf(ndp);
 1074                 vput(ndp->ni_dvp);
 1075                 vrele(ndp->ni_vp);
 1076                 error = EEXIST;
 1077                 goto out;
 1078         }
 1079         if (vtyp != VCHR && vtyp != VBLK && vtyp != VSOCK && vtyp != VFIFO) {
 1080                 vrele(ndp->ni_startdir);
 1081                 nfsvno_relpathbuf(ndp);
 1082                 vput(ndp->ni_dvp);
 1083                 error = NFSERR_BADTYPE;
 1084                 goto out;
 1085         }
 1086         if (vtyp == VSOCK) {
 1087                 vrele(ndp->ni_startdir);
 1088                 error = VOP_CREATE(ndp->ni_dvp, &ndp->ni_vp,
 1089                     &ndp->ni_cnd, &nvap->na_vattr);
 1090                 vput(ndp->ni_dvp);
 1091                 nfsvno_relpathbuf(ndp);
 1092         } else {
 1093                 if (nvap->na_type != VFIFO &&
 1094                     (error = priv_check_cred(cred, PRIV_VFS_MKNOD_DEV, 0))) {
 1095                         vrele(ndp->ni_startdir);
 1096                         nfsvno_relpathbuf(ndp);
 1097                         vput(ndp->ni_dvp);
 1098                         goto out;
 1099                 }
 1100                 error = VOP_MKNOD(ndp->ni_dvp, &ndp->ni_vp,
 1101                     &ndp->ni_cnd, &nvap->na_vattr);
 1102                 vput(ndp->ni_dvp);
 1103                 nfsvno_relpathbuf(ndp);
 1104                 vrele(ndp->ni_startdir);
 1105                 /*
 1106                  * Since VOP_MKNOD returns the ni_vp, I can't
 1107                  * see any reason to do the lookup.
 1108                  */
 1109         }
 1110 
 1111 out:
 1112         NFSEXITCODE(error);
 1113         return (error);
 1114 }
 1115 
 1116 /*
 1117  * Mkdir vnode op.
 1118  */
 1119 int
 1120 nfsvno_mkdir(struct nameidata *ndp, struct nfsvattr *nvap, uid_t saved_uid,
 1121     struct ucred *cred, struct thread *p, struct nfsexstuff *exp)
 1122 {
 1123         int error = 0;
 1124 
 1125         if (ndp->ni_vp != NULL) {
 1126                 if (ndp->ni_dvp == ndp->ni_vp)
 1127                         vrele(ndp->ni_dvp);
 1128                 else
 1129                         vput(ndp->ni_dvp);
 1130                 vrele(ndp->ni_vp);
 1131                 nfsvno_relpathbuf(ndp);
 1132                 error = EEXIST;
 1133                 goto out;
 1134         }
 1135         error = VOP_MKDIR(ndp->ni_dvp, &ndp->ni_vp, &ndp->ni_cnd,
 1136             &nvap->na_vattr);
 1137         vput(ndp->ni_dvp);
 1138         nfsvno_relpathbuf(ndp);
 1139 
 1140 out:
 1141         NFSEXITCODE(error);
 1142         return (error);
 1143 }
 1144 
 1145 /*
 1146  * symlink vnode op.
 1147  */
 1148 int
 1149 nfsvno_symlink(struct nameidata *ndp, struct nfsvattr *nvap, char *pathcp,
 1150     int pathlen, int not_v2, uid_t saved_uid, struct ucred *cred, struct thread *p,
 1151     struct nfsexstuff *exp)
 1152 {
 1153         int error = 0;
 1154 
 1155         if (ndp->ni_vp) {
 1156                 vrele(ndp->ni_startdir);
 1157                 nfsvno_relpathbuf(ndp);
 1158                 if (ndp->ni_dvp == ndp->ni_vp)
 1159                         vrele(ndp->ni_dvp);
 1160                 else
 1161                         vput(ndp->ni_dvp);
 1162                 vrele(ndp->ni_vp);
 1163                 error = EEXIST;
 1164                 goto out;
 1165         }
 1166 
 1167         error = VOP_SYMLINK(ndp->ni_dvp, &ndp->ni_vp, &ndp->ni_cnd,
 1168             &nvap->na_vattr, pathcp);
 1169         vput(ndp->ni_dvp);
 1170         vrele(ndp->ni_startdir);
 1171         nfsvno_relpathbuf(ndp);
 1172         /*
 1173          * Although FreeBSD still had the lookup code in
 1174          * it for 7/current, there doesn't seem to be any
 1175          * point, since VOP_SYMLINK() returns the ni_vp.
 1176          * Just vput it for v2.
 1177          */
 1178         if (!not_v2 && !error)
 1179                 vput(ndp->ni_vp);
 1180 
 1181 out:
 1182         NFSEXITCODE(error);
 1183         return (error);
 1184 }
 1185 
 1186 /*
 1187  * Parse symbolic link arguments.
 1188  * This function has an ugly side effect. It will malloc() an area for
 1189  * the symlink and set iov_base to point to it, only if it succeeds.
 1190  * So, if it returns with uiop->uio_iov->iov_base != NULL, that must
 1191  * be FREE'd later.
 1192  */
 1193 int
 1194 nfsvno_getsymlink(struct nfsrv_descript *nd, struct nfsvattr *nvap,
 1195     struct thread *p, char **pathcpp, int *lenp)
 1196 {
 1197         u_int32_t *tl;
 1198         char *pathcp = NULL;
 1199         int error = 0, len;
 1200         struct nfsv2_sattr *sp;
 1201 
 1202         *pathcpp = NULL;
 1203         *lenp = 0;
 1204         if ((nd->nd_flag & ND_NFSV3) &&
 1205             (error = nfsrv_sattr(nd, NULL, nvap, NULL, NULL, p)))
 1206                 goto nfsmout;
 1207         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 1208         len = fxdr_unsigned(int, *tl);
 1209         if (len > NFS_MAXPATHLEN || len <= 0) {
 1210                 error = EBADRPC;
 1211                 goto nfsmout;
 1212         }
 1213         pathcp = malloc(len + 1, M_TEMP, M_WAITOK);
 1214         error = nfsrv_mtostr(nd, pathcp, len);
 1215         if (error)
 1216                 goto nfsmout;
 1217         if (nd->nd_flag & ND_NFSV2) {
 1218                 NFSM_DISSECT(sp, struct nfsv2_sattr *, NFSX_V2SATTR);
 1219                 nvap->na_mode = fxdr_unsigned(u_int16_t, sp->sa_mode);
 1220         }
 1221         *pathcpp = pathcp;
 1222         *lenp = len;
 1223         NFSEXITCODE2(0, nd);
 1224         return (0);
 1225 nfsmout:
 1226         if (pathcp)
 1227                 free(pathcp, M_TEMP);
 1228         NFSEXITCODE2(error, nd);
 1229         return (error);
 1230 }
 1231 
 1232 /*
 1233  * Remove a non-directory object.
 1234  */
 1235 int
 1236 nfsvno_removesub(struct nameidata *ndp, int is_v4, struct ucred *cred,
 1237     struct thread *p, struct nfsexstuff *exp)
 1238 {
 1239         struct vnode *vp, *dsdvp[NFSDEV_MAXMIRRORS];
 1240         int error = 0, mirrorcnt;
 1241         char fname[PNFS_FILENAME_LEN + 1];
 1242         fhandle_t fh;
 1243 
 1244         vp = ndp->ni_vp;
 1245         dsdvp[0] = NULL;
 1246         if (vp->v_type == VDIR)
 1247                 error = NFSERR_ISDIR;
 1248         else if (is_v4)
 1249                 error = nfsrv_checkremove(vp, 1, p);
 1250         if (error == 0)
 1251                 nfsrv_pnfsremovesetup(vp, p, dsdvp, &mirrorcnt, fname, &fh);
 1252         if (!error)
 1253                 error = VOP_REMOVE(ndp->ni_dvp, vp, &ndp->ni_cnd);
 1254         if (error == 0 && dsdvp[0] != NULL)
 1255                 nfsrv_pnfsremove(dsdvp, mirrorcnt, fname, &fh, p);
 1256         if (ndp->ni_dvp == vp)
 1257                 vrele(ndp->ni_dvp);
 1258         else
 1259                 vput(ndp->ni_dvp);
 1260         vput(vp);
 1261         if ((ndp->ni_cnd.cn_flags & SAVENAME) != 0)
 1262                 nfsvno_relpathbuf(ndp);
 1263         NFSEXITCODE(error);
 1264         return (error);
 1265 }
 1266 
 1267 /*
 1268  * Remove a directory.
 1269  */
 1270 int
 1271 nfsvno_rmdirsub(struct nameidata *ndp, int is_v4, struct ucred *cred,
 1272     struct thread *p, struct nfsexstuff *exp)
 1273 {
 1274         struct vnode *vp;
 1275         int error = 0;
 1276 
 1277         vp = ndp->ni_vp;
 1278         if (vp->v_type != VDIR) {
 1279                 error = ENOTDIR;
 1280                 goto out;
 1281         }
 1282         /*
 1283          * No rmdir "." please.
 1284          */
 1285         if (ndp->ni_dvp == vp) {
 1286                 error = EINVAL;
 1287                 goto out;
 1288         }
 1289         /*
 1290          * The root of a mounted filesystem cannot be deleted.
 1291          */
 1292         if (vp->v_vflag & VV_ROOT)
 1293                 error = EBUSY;
 1294 out:
 1295         if (!error)
 1296                 error = VOP_RMDIR(ndp->ni_dvp, vp, &ndp->ni_cnd);
 1297         if (ndp->ni_dvp == vp)
 1298                 vrele(ndp->ni_dvp);
 1299         else
 1300                 vput(ndp->ni_dvp);
 1301         vput(vp);
 1302         if ((ndp->ni_cnd.cn_flags & SAVENAME) != 0)
 1303                 nfsvno_relpathbuf(ndp);
 1304         NFSEXITCODE(error);
 1305         return (error);
 1306 }
 1307 
 1308 /*
 1309  * Rename vnode op.
 1310  */
 1311 int
 1312 nfsvno_rename(struct nameidata *fromndp, struct nameidata *tondp,
 1313     u_int32_t ndstat, u_int32_t ndflag, struct ucred *cred, struct thread *p)
 1314 {
 1315         struct vnode *fvp, *tvp, *tdvp, *dsdvp[NFSDEV_MAXMIRRORS];
 1316         int error = 0, mirrorcnt;
 1317         char fname[PNFS_FILENAME_LEN + 1];
 1318         fhandle_t fh;
 1319 
 1320         dsdvp[0] = NULL;
 1321         fvp = fromndp->ni_vp;
 1322         if (ndstat) {
 1323                 vrele(fromndp->ni_dvp);
 1324                 vrele(fvp);
 1325                 error = ndstat;
 1326                 goto out1;
 1327         }
 1328         tdvp = tondp->ni_dvp;
 1329         tvp = tondp->ni_vp;
 1330         if (tvp != NULL) {
 1331                 if (fvp->v_type == VDIR && tvp->v_type != VDIR) {
 1332                         error = (ndflag & ND_NFSV2) ? EISDIR : EEXIST;
 1333                         goto out;
 1334                 } else if (fvp->v_type != VDIR && tvp->v_type == VDIR) {
 1335                         error = (ndflag & ND_NFSV2) ? ENOTDIR : EEXIST;
 1336                         goto out;
 1337                 }
 1338                 if (tvp->v_type == VDIR && tvp->v_mountedhere) {
 1339                         error = (ndflag & ND_NFSV2) ? ENOTEMPTY : EXDEV;
 1340                         goto out;
 1341                 }
 1342 
 1343                 /*
 1344                  * A rename to '.' or '..' results in a prematurely
 1345                  * unlocked vnode on FreeBSD5, so I'm just going to fail that
 1346                  * here.
 1347                  */
 1348                 if ((tondp->ni_cnd.cn_namelen == 1 &&
 1349                      tondp->ni_cnd.cn_nameptr[0] == '.') ||
 1350                     (tondp->ni_cnd.cn_namelen == 2 &&
 1351                      tondp->ni_cnd.cn_nameptr[0] == '.' &&
 1352                      tondp->ni_cnd.cn_nameptr[1] == '.')) {
 1353                         error = EINVAL;
 1354                         goto out;
 1355                 }
 1356         }
 1357         if (fvp->v_type == VDIR && fvp->v_mountedhere) {
 1358                 error = (ndflag & ND_NFSV2) ? ENOTEMPTY : EXDEV;
 1359                 goto out;
 1360         }
 1361         if (fvp->v_mount != tdvp->v_mount) {
 1362                 error = (ndflag & ND_NFSV2) ? ENOTEMPTY : EXDEV;
 1363                 goto out;
 1364         }
 1365         if (fvp == tdvp) {
 1366                 error = (ndflag & ND_NFSV2) ? ENOTEMPTY : EINVAL;
 1367                 goto out;
 1368         }
 1369         if (fvp == tvp) {
 1370                 /*
 1371                  * If source and destination are the same, there is nothing to
 1372                  * do. Set error to -1 to indicate this.
 1373                  */
 1374                 error = -1;
 1375                 goto out;
 1376         }
 1377         if (ndflag & ND_NFSV4) {
 1378                 if (NFSVOPLOCK(fvp, LK_EXCLUSIVE) == 0) {
 1379                         error = nfsrv_checkremove(fvp, 0, p);
 1380                         NFSVOPUNLOCK(fvp, 0);
 1381                 } else
 1382                         error = EPERM;
 1383                 if (tvp && !error)
 1384                         error = nfsrv_checkremove(tvp, 1, p);
 1385         } else {
 1386                 /*
 1387                  * For NFSv2 and NFSv3, try to get rid of the delegation, so
 1388                  * that the NFSv4 client won't be confused by the rename.
 1389                  * Since nfsd_recalldelegation() can only be called on an
 1390                  * unlocked vnode at this point and fvp is the file that will
 1391                  * still exist after the rename, just do fvp.
 1392                  */
 1393                 nfsd_recalldelegation(fvp, p);
 1394         }
 1395         if (error == 0 && tvp != NULL) {
 1396                 nfsrv_pnfsremovesetup(tvp, p, dsdvp, &mirrorcnt, fname, &fh);
 1397                 NFSD_DEBUG(4, "nfsvno_rename: pnfsremovesetup"
 1398                     " dsdvp=%p\n", dsdvp[0]);
 1399         }
 1400 out:
 1401         if (!error) {
 1402                 error = VOP_RENAME(fromndp->ni_dvp, fromndp->ni_vp,
 1403                     &fromndp->ni_cnd, tondp->ni_dvp, tondp->ni_vp,
 1404                     &tondp->ni_cnd);
 1405         } else {
 1406                 if (tdvp == tvp)
 1407                         vrele(tdvp);
 1408                 else
 1409                         vput(tdvp);
 1410                 if (tvp)
 1411                         vput(tvp);
 1412                 vrele(fromndp->ni_dvp);
 1413                 vrele(fvp);
 1414                 if (error == -1)
 1415                         error = 0;
 1416         }
 1417 
 1418         /*
 1419          * If dsdvp[0] != NULL, it was set up by nfsrv_pnfsremovesetup() and
 1420          * if the rename succeeded, the DS file for the tvp needs to be
 1421          * removed.
 1422          */
 1423         if (error == 0 && dsdvp[0] != NULL) {
 1424                 nfsrv_pnfsremove(dsdvp, mirrorcnt, fname, &fh, p);
 1425                 NFSD_DEBUG(4, "nfsvno_rename: pnfsremove\n");
 1426         }
 1427 
 1428         vrele(tondp->ni_startdir);
 1429         nfsvno_relpathbuf(tondp);
 1430 out1:
 1431         vrele(fromndp->ni_startdir);
 1432         nfsvno_relpathbuf(fromndp);
 1433         NFSEXITCODE(error);
 1434         return (error);
 1435 }
 1436 
 1437 /*
 1438  * Link vnode op.
 1439  */
 1440 int
 1441 nfsvno_link(struct nameidata *ndp, struct vnode *vp, struct ucred *cred,
 1442     struct thread *p, struct nfsexstuff *exp)
 1443 {
 1444         struct vnode *xp;
 1445         int error = 0;
 1446 
 1447         xp = ndp->ni_vp;
 1448         if (xp != NULL) {
 1449                 error = EEXIST;
 1450         } else {
 1451                 xp = ndp->ni_dvp;
 1452                 if (vp->v_mount != xp->v_mount)
 1453                         error = EXDEV;
 1454         }
 1455         if (!error) {
 1456                 NFSVOPLOCK(vp, LK_EXCLUSIVE | LK_RETRY);
 1457                 if ((vp->v_iflag & VI_DOOMED) == 0)
 1458                         error = VOP_LINK(ndp->ni_dvp, vp, &ndp->ni_cnd);
 1459                 else
 1460                         error = EPERM;
 1461                 if (ndp->ni_dvp == vp)
 1462                         vrele(ndp->ni_dvp);
 1463                 else
 1464                         vput(ndp->ni_dvp);
 1465                 NFSVOPUNLOCK(vp, 0);
 1466         } else {
 1467                 if (ndp->ni_dvp == ndp->ni_vp)
 1468                         vrele(ndp->ni_dvp);
 1469                 else
 1470                         vput(ndp->ni_dvp);
 1471                 if (ndp->ni_vp)
 1472                         vrele(ndp->ni_vp);
 1473         }
 1474         nfsvno_relpathbuf(ndp);
 1475         NFSEXITCODE(error);
 1476         return (error);
 1477 }
 1478 
 1479 /*
 1480  * Do the fsync() appropriate for the commit.
 1481  */
 1482 int
 1483 nfsvno_fsync(struct vnode *vp, u_int64_t off, int cnt, struct ucred *cred,
 1484     struct thread *td)
 1485 {
 1486         int error = 0;
 1487 
 1488         /*
 1489          * RFC 1813 3.3.21: if count is 0, a flush from offset to the end of
 1490          * file is done.  At this time VOP_FSYNC does not accept offset and
 1491          * byte count parameters so call VOP_FSYNC the whole file for now.
 1492          * The same is true for NFSv4: RFC 3530 Sec. 14.2.3.
 1493          * File systems that do not use the buffer cache (as indicated
 1494          * by MNTK_USES_BCACHE not being set) must use VOP_FSYNC().
 1495          */
 1496         if (cnt == 0 || cnt > MAX_COMMIT_COUNT ||
 1497             (vp->v_mount->mnt_kern_flag & MNTK_USES_BCACHE) == 0) {
 1498                 /*
 1499                  * Give up and do the whole thing
 1500                  */
 1501                 if (vp->v_object &&
 1502                    (vp->v_object->flags & OBJ_MIGHTBEDIRTY)) {
 1503                         VM_OBJECT_WLOCK(vp->v_object);
 1504                         vm_object_page_clean(vp->v_object, 0, 0, OBJPC_SYNC);
 1505                         VM_OBJECT_WUNLOCK(vp->v_object);
 1506                 }
 1507                 error = VOP_FSYNC(vp, MNT_WAIT, td);
 1508         } else {
 1509                 /*
 1510                  * Locate and synchronously write any buffers that fall
 1511                  * into the requested range.  Note:  we are assuming that
 1512                  * f_iosize is a power of 2.
 1513                  */
 1514                 int iosize = vp->v_mount->mnt_stat.f_iosize;
 1515                 int iomask = iosize - 1;
 1516                 struct bufobj *bo;
 1517                 daddr_t lblkno;
 1518 
 1519                 /*
 1520                  * Align to iosize boundary, super-align to page boundary.
 1521                  */
 1522                 if (off & iomask) {
 1523                         cnt += off & iomask;
 1524                         off &= ~(u_quad_t)iomask;
 1525                 }
 1526                 if (off & PAGE_MASK) {
 1527                         cnt += off & PAGE_MASK;
 1528                         off &= ~(u_quad_t)PAGE_MASK;
 1529                 }
 1530                 lblkno = off / iosize;
 1531 
 1532                 if (vp->v_object &&
 1533                    (vp->v_object->flags & OBJ_MIGHTBEDIRTY)) {
 1534                         VM_OBJECT_WLOCK(vp->v_object);
 1535                         vm_object_page_clean(vp->v_object, off, off + cnt,
 1536                             OBJPC_SYNC);
 1537                         VM_OBJECT_WUNLOCK(vp->v_object);
 1538                 }
 1539 
 1540                 bo = &vp->v_bufobj;
 1541                 BO_LOCK(bo);
 1542                 while (cnt > 0) {
 1543                         struct buf *bp;
 1544 
 1545                         /*
 1546                          * If we have a buffer and it is marked B_DELWRI we
 1547                          * have to lock and write it.  Otherwise the prior
 1548                          * write is assumed to have already been committed.
 1549                          *
 1550                          * gbincore() can return invalid buffers now so we
 1551                          * have to check that bit as well (though B_DELWRI
 1552                          * should not be set if B_INVAL is set there could be
 1553                          * a race here since we haven't locked the buffer).
 1554                          */
 1555                         if ((bp = gbincore(&vp->v_bufobj, lblkno)) != NULL) {
 1556                                 if (BUF_LOCK(bp, LK_EXCLUSIVE | LK_SLEEPFAIL |
 1557                                     LK_INTERLOCK, BO_LOCKPTR(bo)) == ENOLCK) {
 1558                                         BO_LOCK(bo);
 1559                                         continue; /* retry */
 1560                                 }
 1561                                 if ((bp->b_flags & (B_DELWRI|B_INVAL)) ==
 1562                                     B_DELWRI) {
 1563                                         bremfree(bp);
 1564                                         bp->b_flags &= ~B_ASYNC;
 1565                                         bwrite(bp);
 1566                                         ++nfs_commit_miss;
 1567                                 } else
 1568                                         BUF_UNLOCK(bp);
 1569                                 BO_LOCK(bo);
 1570                         }
 1571                         ++nfs_commit_blks;
 1572                         if (cnt < iosize)
 1573                                 break;
 1574                         cnt -= iosize;
 1575                         ++lblkno;
 1576                 }
 1577                 BO_UNLOCK(bo);
 1578         }
 1579         NFSEXITCODE(error);
 1580         return (error);
 1581 }
 1582 
 1583 /*
 1584  * Statfs vnode op.
 1585  */
 1586 int
 1587 nfsvno_statfs(struct vnode *vp, struct statfs *sf)
 1588 {
 1589         struct statfs *tsf;
 1590         int error;
 1591 
 1592         tsf = NULL;
 1593         if (nfsrv_devidcnt > 0) {
 1594                 /* For a pNFS service, get the DS numbers. */
 1595                 tsf = malloc(sizeof(*tsf), M_TEMP, M_WAITOK | M_ZERO);
 1596                 error = nfsrv_pnfsstatfs(tsf, vp->v_mount);
 1597                 if (error != 0) {
 1598                         free(tsf, M_TEMP);
 1599                         tsf = NULL;
 1600                 }
 1601         }
 1602         error = VFS_STATFS(vp->v_mount, sf);
 1603         if (error == 0) {
 1604                 if (tsf != NULL) {
 1605                         sf->f_blocks = tsf->f_blocks;
 1606                         sf->f_bavail = tsf->f_bavail;
 1607                         sf->f_bfree = tsf->f_bfree;
 1608                         sf->f_bsize = tsf->f_bsize;
 1609                 }
 1610                 /*
 1611                  * Since NFS handles these values as unsigned on the
 1612                  * wire, there is no way to represent negative values,
 1613                  * so set them to 0. Without this, they will appear
 1614                  * to be very large positive values for clients like
 1615                  * Solaris10.
 1616                  */
 1617                 if (sf->f_bavail < 0)
 1618                         sf->f_bavail = 0;
 1619                 if (sf->f_ffree < 0)
 1620                         sf->f_ffree = 0;
 1621         }
 1622         free(tsf, M_TEMP);
 1623         NFSEXITCODE(error);
 1624         return (error);
 1625 }
 1626 
 1627 /*
 1628  * Do the vnode op stuff for Open. Similar to nfsvno_createsub(), but
 1629  * must handle nfsrv_opencheck() calls after any other access checks.
 1630  */
 1631 void
 1632 nfsvno_open(struct nfsrv_descript *nd, struct nameidata *ndp,
 1633     nfsquad_t clientid, nfsv4stateid_t *stateidp, struct nfsstate *stp,
 1634     int *exclusive_flagp, struct nfsvattr *nvap, int32_t *cverf, int create,
 1635     NFSACL_T *aclp, nfsattrbit_t *attrbitp, struct ucred *cred, struct thread *p,
 1636     struct nfsexstuff *exp, struct vnode **vpp)
 1637 {
 1638         struct vnode *vp = NULL;
 1639         u_quad_t tempsize;
 1640         struct nfsexstuff nes;
 1641 
 1642         if (ndp->ni_vp == NULL)
 1643                 nd->nd_repstat = nfsrv_opencheck(clientid,
 1644                     stateidp, stp, NULL, nd, p, nd->nd_repstat);
 1645         if (!nd->nd_repstat) {
 1646                 if (ndp->ni_vp == NULL) {
 1647                         vrele(ndp->ni_startdir);
 1648                         nd->nd_repstat = VOP_CREATE(ndp->ni_dvp,
 1649                             &ndp->ni_vp, &ndp->ni_cnd, &nvap->na_vattr);
 1650                         /* For a pNFS server, create the data file on a DS. */
 1651                         if (nd->nd_repstat == 0) {
 1652                                 /*
 1653                                  * Create a data file on a DS for a pNFS server.
 1654                                  * This function just returns if not
 1655                                  * running a pNFS DS or the creation fails.
 1656                                  */
 1657                                 nfsrv_pnfscreate(ndp->ni_vp, &nvap->na_vattr,
 1658                                     cred, p);
 1659                         }
 1660                         vput(ndp->ni_dvp);
 1661                         nfsvno_relpathbuf(ndp);
 1662                         if (!nd->nd_repstat) {
 1663                                 if (*exclusive_flagp) {
 1664                                         *exclusive_flagp = 0;
 1665                                         NFSVNO_ATTRINIT(nvap);
 1666                                         nvap->na_atime.tv_sec = cverf[0];
 1667                                         nvap->na_atime.tv_nsec = cverf[1];
 1668                                         nd->nd_repstat = VOP_SETATTR(ndp->ni_vp,
 1669                                             &nvap->na_vattr, cred);
 1670                                         if (nd->nd_repstat != 0) {
 1671                                                 vput(ndp->ni_vp);
 1672                                                 ndp->ni_vp = NULL;
 1673                                                 nd->nd_repstat = NFSERR_NOTSUPP;
 1674                                         } else
 1675                                                 NFSSETBIT_ATTRBIT(attrbitp,
 1676                                                     NFSATTRBIT_TIMEACCESS);
 1677                                 } else {
 1678                                         nfsrv_fixattr(nd, ndp->ni_vp, nvap,
 1679                                             aclp, p, attrbitp, exp);
 1680                                 }
 1681                         }
 1682                         vp = ndp->ni_vp;
 1683                 } else {
 1684                         if (ndp->ni_startdir)
 1685                                 vrele(ndp->ni_startdir);
 1686                         nfsvno_relpathbuf(ndp);
 1687                         vp = ndp->ni_vp;
 1688                         if (create == NFSV4OPEN_CREATE) {
 1689                                 if (ndp->ni_dvp == vp)
 1690                                         vrele(ndp->ni_dvp);
 1691                                 else
 1692                                         vput(ndp->ni_dvp);
 1693                         }
 1694                         if (NFSVNO_ISSETSIZE(nvap) && vp->v_type == VREG) {
 1695                                 if (ndp->ni_cnd.cn_flags & RDONLY)
 1696                                         NFSVNO_SETEXRDONLY(&nes);
 1697                                 else
 1698                                         NFSVNO_EXINIT(&nes);
 1699                                 nd->nd_repstat = nfsvno_accchk(vp, 
 1700                                     VWRITE, cred, &nes, p,
 1701                                     NFSACCCHK_NOOVERRIDE,
 1702                                     NFSACCCHK_VPISLOCKED, NULL);
 1703                                 nd->nd_repstat = nfsrv_opencheck(clientid,
 1704                                     stateidp, stp, vp, nd, p, nd->nd_repstat);
 1705                                 if (!nd->nd_repstat) {
 1706                                         tempsize = nvap->na_size;
 1707                                         NFSVNO_ATTRINIT(nvap);
 1708                                         nvap->na_size = tempsize;
 1709                                         nd->nd_repstat = VOP_SETATTR(vp,
 1710                                             &nvap->na_vattr, cred);
 1711                                 }
 1712                         } else if (vp->v_type == VREG) {
 1713                                 nd->nd_repstat = nfsrv_opencheck(clientid,
 1714                                     stateidp, stp, vp, nd, p, nd->nd_repstat);
 1715                         }
 1716                 }
 1717         } else {
 1718                 if (ndp->ni_cnd.cn_flags & HASBUF)
 1719                         nfsvno_relpathbuf(ndp);
 1720                 if (ndp->ni_startdir && create == NFSV4OPEN_CREATE) {
 1721                         vrele(ndp->ni_startdir);
 1722                         if (ndp->ni_dvp == ndp->ni_vp)
 1723                                 vrele(ndp->ni_dvp);
 1724                         else
 1725                                 vput(ndp->ni_dvp);
 1726                         if (ndp->ni_vp)
 1727                                 vput(ndp->ni_vp);
 1728                 }
 1729         }
 1730         *vpp = vp;
 1731 
 1732         NFSEXITCODE2(0, nd);
 1733 }
 1734 
 1735 /*
 1736  * Updates the file rev and sets the mtime and ctime
 1737  * to the current clock time, returning the va_filerev and va_Xtime
 1738  * values.
 1739  * Return ESTALE to indicate the vnode is VI_DOOMED.
 1740  */
 1741 int
 1742 nfsvno_updfilerev(struct vnode *vp, struct nfsvattr *nvap,
 1743     struct nfsrv_descript *nd, struct thread *p)
 1744 {
 1745         struct vattr va;
 1746 
 1747         VATTR_NULL(&va);
 1748         vfs_timestamp(&va.va_mtime);
 1749         if (NFSVOPISLOCKED(vp) != LK_EXCLUSIVE) {
 1750                 NFSVOPLOCK(vp, LK_UPGRADE | LK_RETRY);
 1751                 if ((vp->v_iflag & VI_DOOMED) != 0)
 1752                         return (ESTALE);
 1753         }
 1754         (void) VOP_SETATTR(vp, &va, nd->nd_cred);
 1755         (void) nfsvno_getattr(vp, nvap, nd, p, 1, NULL);
 1756         return (0);
 1757 }
 1758 
 1759 /*
 1760  * Glue routine to nfsv4_fillattr().
 1761  */
 1762 int
 1763 nfsvno_fillattr(struct nfsrv_descript *nd, struct mount *mp, struct vnode *vp,
 1764     struct nfsvattr *nvap, fhandle_t *fhp, int rderror, nfsattrbit_t *attrbitp,
 1765     struct ucred *cred, struct thread *p, int isdgram, int reterr,
 1766     int supports_nfsv4acls, int at_root, uint64_t mounted_on_fileno)
 1767 {
 1768         struct statfs *sf;
 1769         int error;
 1770 
 1771         sf = NULL;
 1772         if (nfsrv_devidcnt > 0 &&
 1773             (NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_SPACEAVAIL) ||
 1774              NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_SPACEFREE) ||
 1775              NFSISSET_ATTRBIT(attrbitp, NFSATTRBIT_SPACETOTAL))) {
 1776                 sf = malloc(sizeof(*sf), M_TEMP, M_WAITOK | M_ZERO);
 1777                 error = nfsrv_pnfsstatfs(sf, mp);
 1778                 if (error != 0) {
 1779                         free(sf, M_TEMP);
 1780                         sf = NULL;
 1781                 }
 1782         }
 1783         error = nfsv4_fillattr(nd, mp, vp, NULL, &nvap->na_vattr, fhp, rderror,
 1784             attrbitp, cred, p, isdgram, reterr, supports_nfsv4acls, at_root,
 1785             mounted_on_fileno, sf);
 1786         free(sf, M_TEMP);
 1787         NFSEXITCODE2(0, nd);
 1788         return (error);
 1789 }
 1790 
 1791 /* Since the Readdir vnode ops vary, put the entire functions in here. */
 1792 /*
 1793  * nfs readdir service
 1794  * - mallocs what it thinks is enough to read
 1795  *      count rounded up to a multiple of DIRBLKSIZ <= NFS_MAXREADDIR
 1796  * - calls VOP_READDIR()
 1797  * - loops around building the reply
 1798  *      if the output generated exceeds count break out of loop
 1799  *      The NFSM_CLGET macro is used here so that the reply will be packed
 1800  *      tightly in mbuf clusters.
 1801  * - it trims out records with d_fileno == 0
 1802  *      this doesn't matter for Unix clients, but they might confuse clients
 1803  *      for other os'.
 1804  * - it trims out records with d_type == DT_WHT
 1805  *      these cannot be seen through NFS (unless we extend the protocol)
 1806  *     The alternate call nfsrvd_readdirplus() does lookups as well.
 1807  * PS: The NFS protocol spec. does not clarify what the "count" byte
 1808  *      argument is a count of.. just name strings and file id's or the
 1809  *      entire reply rpc or ...
 1810  *      I tried just file name and id sizes and it confused the Sun client,
 1811  *      so I am using the full rpc size now. The "paranoia.." comment refers
 1812  *      to including the status longwords that are not a part of the dir.
 1813  *      "entry" structures, but are in the rpc.
 1814  */
 1815 int
 1816 nfsrvd_readdir(struct nfsrv_descript *nd, int isdgram,
 1817     struct vnode *vp, struct thread *p, struct nfsexstuff *exp)
 1818 {
 1819         struct dirent *dp;
 1820         u_int32_t *tl;
 1821         int dirlen;
 1822         char *cpos, *cend, *rbuf;
 1823         struct nfsvattr at;
 1824         int nlen, error = 0, getret = 1;
 1825         int siz, cnt, fullsiz, eofflag, ncookies;
 1826         u_int64_t off, toff, verf __unused;
 1827         u_long *cookies = NULL, *cookiep;
 1828         struct uio io;
 1829         struct iovec iv;
 1830         int is_ufs;
 1831 
 1832         if (nd->nd_repstat) {
 1833                 nfsrv_postopattr(nd, getret, &at);
 1834                 goto out;
 1835         }
 1836         if (nd->nd_flag & ND_NFSV2) {
 1837                 NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 1838                 off = fxdr_unsigned(u_quad_t, *tl++);
 1839         } else {
 1840                 NFSM_DISSECT(tl, u_int32_t *, 5 * NFSX_UNSIGNED);
 1841                 off = fxdr_hyper(tl);
 1842                 tl += 2;
 1843                 verf = fxdr_hyper(tl);
 1844                 tl += 2;
 1845         }
 1846         toff = off;
 1847         cnt = fxdr_unsigned(int, *tl);
 1848         if (cnt > NFS_SRVMAXDATA(nd) || cnt < 0)
 1849                 cnt = NFS_SRVMAXDATA(nd);
 1850         siz = ((cnt + DIRBLKSIZ - 1) & ~(DIRBLKSIZ - 1));
 1851         fullsiz = siz;
 1852         if (nd->nd_flag & ND_NFSV3) {
 1853                 nd->nd_repstat = getret = nfsvno_getattr(vp, &at, nd, p, 1,
 1854                     NULL);
 1855 #if 0
 1856                 /*
 1857                  * va_filerev is not sufficient as a cookie verifier,
 1858                  * since it is not supposed to change when entries are
 1859                  * removed/added unless that offset cookies returned to
 1860                  * the client are no longer valid.
 1861                  */
 1862                 if (!nd->nd_repstat && toff && verf != at.na_filerev)
 1863                         nd->nd_repstat = NFSERR_BAD_COOKIE;
 1864 #endif
 1865         }
 1866         if (!nd->nd_repstat && vp->v_type != VDIR)
 1867                 nd->nd_repstat = NFSERR_NOTDIR;
 1868         if (nd->nd_repstat == 0 && cnt == 0) {
 1869                 if (nd->nd_flag & ND_NFSV2)
 1870                         /* NFSv2 does not have NFSERR_TOOSMALL */
 1871                         nd->nd_repstat = EPERM;
 1872                 else
 1873                         nd->nd_repstat = NFSERR_TOOSMALL;
 1874         }
 1875         if (!nd->nd_repstat)
 1876                 nd->nd_repstat = nfsvno_accchk(vp, VEXEC,
 1877                     nd->nd_cred, exp, p, NFSACCCHK_NOOVERRIDE,
 1878                     NFSACCCHK_VPISLOCKED, NULL);
 1879         if (nd->nd_repstat) {
 1880                 vput(vp);
 1881                 if (nd->nd_flag & ND_NFSV3)
 1882                         nfsrv_postopattr(nd, getret, &at);
 1883                 goto out;
 1884         }
 1885         is_ufs = strcmp(vp->v_mount->mnt_vfc->vfc_name, "ufs") == 0;
 1886         rbuf = malloc(siz, M_TEMP, M_WAITOK);
 1887 again:
 1888         eofflag = 0;
 1889         if (cookies) {
 1890                 free(cookies, M_TEMP);
 1891                 cookies = NULL;
 1892         }
 1893 
 1894         iv.iov_base = rbuf;
 1895         iv.iov_len = siz;
 1896         io.uio_iov = &iv;
 1897         io.uio_iovcnt = 1;
 1898         io.uio_offset = (off_t)off;
 1899         io.uio_resid = siz;
 1900         io.uio_segflg = UIO_SYSSPACE;
 1901         io.uio_rw = UIO_READ;
 1902         io.uio_td = NULL;
 1903         nd->nd_repstat = VOP_READDIR(vp, &io, nd->nd_cred, &eofflag, &ncookies,
 1904             &cookies);
 1905         off = (u_int64_t)io.uio_offset;
 1906         if (io.uio_resid)
 1907                 siz -= io.uio_resid;
 1908 
 1909         if (!cookies && !nd->nd_repstat)
 1910                 nd->nd_repstat = NFSERR_PERM;
 1911         if (nd->nd_flag & ND_NFSV3) {
 1912                 getret = nfsvno_getattr(vp, &at, nd, p, 1, NULL);
 1913                 if (!nd->nd_repstat)
 1914                         nd->nd_repstat = getret;
 1915         }
 1916 
 1917         /*
 1918          * Handles the failed cases. nd->nd_repstat == 0 past here.
 1919          */
 1920         if (nd->nd_repstat) {
 1921                 vput(vp);
 1922                 free(rbuf, M_TEMP);
 1923                 if (cookies)
 1924                         free(cookies, M_TEMP);
 1925                 if (nd->nd_flag & ND_NFSV3)
 1926                         nfsrv_postopattr(nd, getret, &at);
 1927                 goto out;
 1928         }
 1929         /*
 1930          * If nothing read, return eof
 1931          * rpc reply
 1932          */
 1933         if (siz == 0) {
 1934                 vput(vp);
 1935                 if (nd->nd_flag & ND_NFSV2) {
 1936                         NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 1937                 } else {
 1938                         nfsrv_postopattr(nd, getret, &at);
 1939                         NFSM_BUILD(tl, u_int32_t *, 4 * NFSX_UNSIGNED);
 1940                         txdr_hyper(at.na_filerev, tl);
 1941                         tl += 2;
 1942                 }
 1943                 *tl++ = newnfs_false;
 1944                 *tl = newnfs_true;
 1945                 free(rbuf, M_TEMP);
 1946                 free(cookies, M_TEMP);
 1947                 goto out;
 1948         }
 1949 
 1950         /*
 1951          * Check for degenerate cases of nothing useful read.
 1952          * If so go try again
 1953          */
 1954         cpos = rbuf;
 1955         cend = rbuf + siz;
 1956         dp = (struct dirent *)cpos;
 1957         cookiep = cookies;
 1958 
 1959         /*
 1960          * For some reason FreeBSD's ufs_readdir() chooses to back the
 1961          * directory offset up to a block boundary, so it is necessary to
 1962          * skip over the records that precede the requested offset. This
 1963          * requires the assumption that file offset cookies monotonically
 1964          * increase.
 1965          */
 1966         while (cpos < cend && ncookies > 0 &&
 1967             (dp->d_fileno == 0 || dp->d_type == DT_WHT ||
 1968              (is_ufs == 1 && ((u_quad_t)(*cookiep)) <= toff))) {
 1969                 cpos += dp->d_reclen;
 1970                 dp = (struct dirent *)cpos;
 1971                 cookiep++;
 1972                 ncookies--;
 1973         }
 1974         if (cpos >= cend || ncookies == 0) {
 1975                 siz = fullsiz;
 1976                 toff = off;
 1977                 goto again;
 1978         }
 1979         vput(vp);
 1980 
 1981         /*
 1982          * dirlen is the size of the reply, including all XDR and must
 1983          * not exceed cnt. For NFSv2, RFC1094 didn't clearly indicate
 1984          * if the XDR should be included in "count", but to be safe, we do.
 1985          * (Include the two booleans at the end of the reply in dirlen now.)
 1986          */
 1987         if (nd->nd_flag & ND_NFSV3) {
 1988                 nfsrv_postopattr(nd, getret, &at);
 1989                 NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 1990                 txdr_hyper(at.na_filerev, tl);
 1991                 dirlen = NFSX_V3POSTOPATTR + NFSX_VERF + 2 * NFSX_UNSIGNED;
 1992         } else {
 1993                 dirlen = 2 * NFSX_UNSIGNED;
 1994         }
 1995 
 1996         /* Loop through the records and build reply */
 1997         while (cpos < cend && ncookies > 0) {
 1998                 nlen = dp->d_namlen;
 1999                 if (dp->d_fileno != 0 && dp->d_type != DT_WHT &&
 2000                         nlen <= NFS_MAXNAMLEN) {
 2001                         if (nd->nd_flag & ND_NFSV3)
 2002                                 dirlen += (6*NFSX_UNSIGNED + NFSM_RNDUP(nlen));
 2003                         else
 2004                                 dirlen += (4*NFSX_UNSIGNED + NFSM_RNDUP(nlen));
 2005                         if (dirlen > cnt) {
 2006                                 eofflag = 0;
 2007                                 break;
 2008                         }
 2009 
 2010                         /*
 2011                          * Build the directory record xdr from
 2012                          * the dirent entry.
 2013                          */
 2014                         if (nd->nd_flag & ND_NFSV3) {
 2015                                 NFSM_BUILD(tl, u_int32_t *, 3 * NFSX_UNSIGNED);
 2016                                 *tl++ = newnfs_true;
 2017                                 *tl++ = 0;
 2018                         } else {
 2019                                 NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2020                                 *tl++ = newnfs_true;
 2021                         }
 2022                         *tl = txdr_unsigned(dp->d_fileno);
 2023                         (void) nfsm_strtom(nd, dp->d_name, nlen);
 2024                         if (nd->nd_flag & ND_NFSV3) {
 2025                                 NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2026                                 *tl++ = 0;
 2027                         } else
 2028                                 NFSM_BUILD(tl, u_int32_t *, NFSX_UNSIGNED);
 2029                         *tl = txdr_unsigned(*cookiep);
 2030                 }
 2031                 cpos += dp->d_reclen;
 2032                 dp = (struct dirent *)cpos;
 2033                 cookiep++;
 2034                 ncookies--;
 2035         }
 2036         if (cpos < cend)
 2037                 eofflag = 0;
 2038         NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2039         *tl++ = newnfs_false;
 2040         if (eofflag)
 2041                 *tl = newnfs_true;
 2042         else
 2043                 *tl = newnfs_false;
 2044         free(rbuf, M_TEMP);
 2045         free(cookies, M_TEMP);
 2046 
 2047 out:
 2048         NFSEXITCODE2(0, nd);
 2049         return (0);
 2050 nfsmout:
 2051         vput(vp);
 2052         NFSEXITCODE2(error, nd);
 2053         return (error);
 2054 }
 2055 
 2056 /*
 2057  * Readdirplus for V3 and Readdir for V4.
 2058  */
 2059 int
 2060 nfsrvd_readdirplus(struct nfsrv_descript *nd, int isdgram,
 2061     struct vnode *vp, struct thread *p, struct nfsexstuff *exp)
 2062 {
 2063         struct dirent *dp;
 2064         u_int32_t *tl;
 2065         int dirlen;
 2066         char *cpos, *cend, *rbuf;
 2067         struct vnode *nvp;
 2068         fhandle_t nfh;
 2069         struct nfsvattr nva, at, *nvap = &nva;
 2070         struct mbuf *mb0, *mb1;
 2071         struct nfsreferral *refp;
 2072         int nlen, r, error = 0, getret = 1, usevget = 1;
 2073         int siz, cnt, fullsiz, eofflag, ncookies, entrycnt;
 2074         caddr_t bpos0, bpos1;
 2075         u_int64_t off, toff, verf;
 2076         u_long *cookies = NULL, *cookiep;
 2077         nfsattrbit_t attrbits, rderrbits, savbits;
 2078         struct uio io;
 2079         struct iovec iv;
 2080         struct componentname cn;
 2081         int at_root, is_ufs, is_zfs, needs_unbusy, supports_nfsv4acls;
 2082         struct mount *mp, *new_mp;
 2083         uint64_t mounted_on_fileno;
 2084 
 2085         if (nd->nd_repstat) {
 2086                 nfsrv_postopattr(nd, getret, &at);
 2087                 goto out;
 2088         }
 2089         NFSM_DISSECT(tl, u_int32_t *, 6 * NFSX_UNSIGNED);
 2090         off = fxdr_hyper(tl);
 2091         toff = off;
 2092         tl += 2;
 2093         verf = fxdr_hyper(tl);
 2094         tl += 2;
 2095         siz = fxdr_unsigned(int, *tl++);
 2096         cnt = fxdr_unsigned(int, *tl);
 2097 
 2098         /*
 2099          * Use the server's maximum data transfer size as the upper bound
 2100          * on reply datalen.
 2101          */
 2102         if (cnt > NFS_SRVMAXDATA(nd) || cnt < 0)
 2103                 cnt = NFS_SRVMAXDATA(nd);
 2104 
 2105         /*
 2106          * siz is a "hint" of how much directory information (name, fileid,
 2107          * cookie) should be in the reply. At least one client "hints" 0,
 2108          * so I set it to cnt for that case. I also round it up to the
 2109          * next multiple of DIRBLKSIZ.
 2110          * Since the size of a Readdirplus directory entry reply will always
 2111          * be greater than a directory entry returned by VOP_READDIR(), it
 2112          * does not make sense to read more than NFS_SRVMAXDATA() via
 2113          * VOP_READDIR().
 2114          */
 2115         if (siz <= 0)
 2116                 siz = cnt;
 2117         else if (siz > NFS_SRVMAXDATA(nd))
 2118                 siz = NFS_SRVMAXDATA(nd);
 2119         siz = ((siz + DIRBLKSIZ - 1) & ~(DIRBLKSIZ - 1));
 2120 
 2121         if (nd->nd_flag & ND_NFSV4) {
 2122                 error = nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
 2123                 if (error)
 2124                         goto nfsmout;
 2125                 NFSSET_ATTRBIT(&savbits, &attrbits);
 2126                 NFSCLRNOTFILLABLE_ATTRBIT(&attrbits);
 2127                 NFSZERO_ATTRBIT(&rderrbits);
 2128                 NFSSETBIT_ATTRBIT(&rderrbits, NFSATTRBIT_RDATTRERROR);
 2129         } else {
 2130                 NFSZERO_ATTRBIT(&attrbits);
 2131         }
 2132         fullsiz = siz;
 2133         nd->nd_repstat = getret = nfsvno_getattr(vp, &at, nd, p, 1, NULL);
 2134 #if 0
 2135         if (!nd->nd_repstat) {
 2136             if (off && verf != at.na_filerev) {
 2137                 /*
 2138                  * va_filerev is not sufficient as a cookie verifier,
 2139                  * since it is not supposed to change when entries are
 2140                  * removed/added unless that offset cookies returned to
 2141                  * the client are no longer valid.
 2142                  */
 2143                 if (nd->nd_flag & ND_NFSV4) {
 2144                         nd->nd_repstat = NFSERR_NOTSAME;
 2145                 } else {
 2146                         nd->nd_repstat = NFSERR_BAD_COOKIE;
 2147                 }
 2148             }
 2149         }
 2150 #endif
 2151         if (!nd->nd_repstat && vp->v_type != VDIR)
 2152                 nd->nd_repstat = NFSERR_NOTDIR;
 2153         if (!nd->nd_repstat && cnt == 0)
 2154                 nd->nd_repstat = NFSERR_TOOSMALL;
 2155         if (!nd->nd_repstat)
 2156                 nd->nd_repstat = nfsvno_accchk(vp, VEXEC,
 2157                     nd->nd_cred, exp, p, NFSACCCHK_NOOVERRIDE,
 2158                     NFSACCCHK_VPISLOCKED, NULL);
 2159         if (nd->nd_repstat) {
 2160                 vput(vp);
 2161                 if (nd->nd_flag & ND_NFSV3)
 2162                         nfsrv_postopattr(nd, getret, &at);
 2163                 goto out;
 2164         }
 2165         is_ufs = strcmp(vp->v_mount->mnt_vfc->vfc_name, "ufs") == 0;
 2166         is_zfs = strcmp(vp->v_mount->mnt_vfc->vfc_name, "zfs") == 0;
 2167 
 2168         rbuf = malloc(siz, M_TEMP, M_WAITOK);
 2169 again:
 2170         eofflag = 0;
 2171         if (cookies) {
 2172                 free(cookies, M_TEMP);
 2173                 cookies = NULL;
 2174         }
 2175 
 2176         iv.iov_base = rbuf;
 2177         iv.iov_len = siz;
 2178         io.uio_iov = &iv;
 2179         io.uio_iovcnt = 1;
 2180         io.uio_offset = (off_t)off;
 2181         io.uio_resid = siz;
 2182         io.uio_segflg = UIO_SYSSPACE;
 2183         io.uio_rw = UIO_READ;
 2184         io.uio_td = NULL;
 2185         nd->nd_repstat = VOP_READDIR(vp, &io, nd->nd_cred, &eofflag, &ncookies,
 2186             &cookies);
 2187         off = (u_int64_t)io.uio_offset;
 2188         if (io.uio_resid)
 2189                 siz -= io.uio_resid;
 2190 
 2191         getret = nfsvno_getattr(vp, &at, nd, p, 1, NULL);
 2192 
 2193         if (!cookies && !nd->nd_repstat)
 2194                 nd->nd_repstat = NFSERR_PERM;
 2195         if (!nd->nd_repstat)
 2196                 nd->nd_repstat = getret;
 2197         if (nd->nd_repstat) {
 2198                 vput(vp);
 2199                 if (cookies)
 2200                         free(cookies, M_TEMP);
 2201                 free(rbuf, M_TEMP);
 2202                 if (nd->nd_flag & ND_NFSV3)
 2203                         nfsrv_postopattr(nd, getret, &at);
 2204                 goto out;
 2205         }
 2206         /*
 2207          * If nothing read, return eof
 2208          * rpc reply
 2209          */
 2210         if (siz == 0) {
 2211                 vput(vp);
 2212                 if (nd->nd_flag & ND_NFSV3)
 2213                         nfsrv_postopattr(nd, getret, &at);
 2214                 NFSM_BUILD(tl, u_int32_t *, 4 * NFSX_UNSIGNED);
 2215                 txdr_hyper(at.na_filerev, tl);
 2216                 tl += 2;
 2217                 *tl++ = newnfs_false;
 2218                 *tl = newnfs_true;
 2219                 free(cookies, M_TEMP);
 2220                 free(rbuf, M_TEMP);
 2221                 goto out;
 2222         }
 2223 
 2224         /*
 2225          * Check for degenerate cases of nothing useful read.
 2226          * If so go try again
 2227          */
 2228         cpos = rbuf;
 2229         cend = rbuf + siz;
 2230         dp = (struct dirent *)cpos;
 2231         cookiep = cookies;
 2232 
 2233         /*
 2234          * For some reason FreeBSD's ufs_readdir() chooses to back the
 2235          * directory offset up to a block boundary, so it is necessary to
 2236          * skip over the records that precede the requested offset. This
 2237          * requires the assumption that file offset cookies monotonically
 2238          * increase.
 2239          */
 2240         while (cpos < cend && ncookies > 0 &&
 2241           (dp->d_fileno == 0 || dp->d_type == DT_WHT ||
 2242            (is_ufs == 1 && ((u_quad_t)(*cookiep)) <= toff) ||
 2243            ((nd->nd_flag & ND_NFSV4) &&
 2244             ((dp->d_namlen == 1 && dp->d_name[0] == '.') ||
 2245              (dp->d_namlen==2 && dp->d_name[0]=='.' && dp->d_name[1]=='.'))))) {
 2246                 cpos += dp->d_reclen;
 2247                 dp = (struct dirent *)cpos;
 2248                 cookiep++;
 2249                 ncookies--;
 2250         }
 2251         if (cpos >= cend || ncookies == 0) {
 2252                 siz = fullsiz;
 2253                 toff = off;
 2254                 goto again;
 2255         }
 2256 
 2257         /*
 2258          * Busy the file system so that the mount point won't go away
 2259          * and, as such, VFS_VGET() can be used safely.
 2260          */
 2261         mp = vp->v_mount;
 2262         vfs_ref(mp);
 2263         NFSVOPUNLOCK(vp, 0);
 2264         nd->nd_repstat = vfs_busy(mp, 0);
 2265         vfs_rel(mp);
 2266         if (nd->nd_repstat != 0) {
 2267                 vrele(vp);
 2268                 free(cookies, M_TEMP);
 2269                 free(rbuf, M_TEMP);
 2270                 if (nd->nd_flag & ND_NFSV3)
 2271                         nfsrv_postopattr(nd, getret, &at);
 2272                 goto out;
 2273         }
 2274 
 2275         /*
 2276          * Check to see if entries in this directory can be safely acquired
 2277          * via VFS_VGET() or if a switch to VOP_LOOKUP() is required.
 2278          * ZFS snapshot directories need VOP_LOOKUP(), so that any
 2279          * automount of the snapshot directory that is required will
 2280          * be done.
 2281          * This needs to be done here for NFSv4, since NFSv4 never does
 2282          * a VFS_VGET() for "." or "..".
 2283          */
 2284         if (is_zfs == 1) {
 2285                 r = VFS_VGET(mp, at.na_fileid, LK_SHARED, &nvp);
 2286                 if (r == EOPNOTSUPP) {
 2287                         usevget = 0;
 2288                         cn.cn_nameiop = LOOKUP;
 2289                         cn.cn_lkflags = LK_SHARED | LK_RETRY;
 2290                         cn.cn_cred = nd->nd_cred;
 2291                         cn.cn_thread = p;
 2292                 } else if (r == 0)
 2293                         vput(nvp);
 2294         }
 2295 
 2296         /*
 2297          * Save this position, in case there is an error before one entry
 2298          * is created.
 2299          */
 2300         mb0 = nd->nd_mb;
 2301         bpos0 = nd->nd_bpos;
 2302 
 2303         /*
 2304          * Fill in the first part of the reply.
 2305          * dirlen is the reply length in bytes and cannot exceed cnt.
 2306          * (Include the two booleans at the end of the reply in dirlen now,
 2307          *  so we recognize when we have exceeded cnt.)
 2308          */
 2309         if (nd->nd_flag & ND_NFSV3) {
 2310                 dirlen = NFSX_V3POSTOPATTR + NFSX_VERF + 2 * NFSX_UNSIGNED;
 2311                 nfsrv_postopattr(nd, getret, &at);
 2312         } else {
 2313                 dirlen = NFSX_VERF + 2 * NFSX_UNSIGNED;
 2314         }
 2315         NFSM_BUILD(tl, u_int32_t *, NFSX_VERF);
 2316         txdr_hyper(at.na_filerev, tl);
 2317 
 2318         /*
 2319          * Save this position, in case there is an empty reply needed.
 2320          */
 2321         mb1 = nd->nd_mb;
 2322         bpos1 = nd->nd_bpos;
 2323 
 2324         /* Loop through the records and build reply */
 2325         entrycnt = 0;
 2326         while (cpos < cend && ncookies > 0 && dirlen < cnt) {
 2327                 nlen = dp->d_namlen;
 2328                 if (dp->d_fileno != 0 && dp->d_type != DT_WHT &&
 2329                     nlen <= NFS_MAXNAMLEN &&
 2330                     ((nd->nd_flag & ND_NFSV3) || nlen > 2 ||
 2331                      (nlen==2 && (dp->d_name[0]!='.' || dp->d_name[1]!='.'))
 2332                       || (nlen == 1 && dp->d_name[0] != '.'))) {
 2333                         /*
 2334                          * Save the current position in the reply, in case
 2335                          * this entry exceeds cnt.
 2336                          */
 2337                         mb1 = nd->nd_mb;
 2338                         bpos1 = nd->nd_bpos;
 2339         
 2340                         /*
 2341                          * For readdir_and_lookup get the vnode using
 2342                          * the file number.
 2343                          */
 2344                         nvp = NULL;
 2345                         refp = NULL;
 2346                         r = 0;
 2347                         at_root = 0;
 2348                         needs_unbusy = 0;
 2349                         new_mp = mp;
 2350                         mounted_on_fileno = (uint64_t)dp->d_fileno;
 2351                         if ((nd->nd_flag & ND_NFSV3) ||
 2352                             NFSNONZERO_ATTRBIT(&savbits)) {
 2353                                 if (nd->nd_flag & ND_NFSV4)
 2354                                         refp = nfsv4root_getreferral(NULL,
 2355                                             vp, dp->d_fileno);
 2356                                 if (refp == NULL) {
 2357                                         if (usevget)
 2358                                                 r = VFS_VGET(mp, dp->d_fileno,
 2359                                                     LK_SHARED, &nvp);
 2360                                         else
 2361                                                 r = EOPNOTSUPP;
 2362                                         if (r == EOPNOTSUPP) {
 2363                                                 if (usevget) {
 2364                                                         usevget = 0;
 2365                                                         cn.cn_nameiop = LOOKUP;
 2366                                                         cn.cn_lkflags =
 2367                                                             LK_SHARED |
 2368                                                             LK_RETRY;
 2369                                                         cn.cn_cred =
 2370                                                             nd->nd_cred;
 2371                                                         cn.cn_thread = p;
 2372                                                 }
 2373                                                 cn.cn_nameptr = dp->d_name;
 2374                                                 cn.cn_namelen = nlen;
 2375                                                 cn.cn_flags = ISLASTCN |
 2376                                                     NOFOLLOW | LOCKLEAF;
 2377                                                 if (nlen == 2 &&
 2378                                                     dp->d_name[0] == '.' &&
 2379                                                     dp->d_name[1] == '.')
 2380                                                         cn.cn_flags |=
 2381                                                             ISDOTDOT;
 2382                                                 if (NFSVOPLOCK(vp, LK_SHARED)
 2383                                                     != 0) {
 2384                                                         nd->nd_repstat = EPERM;
 2385                                                         break;
 2386                                                 }
 2387                                                 if ((vp->v_vflag & VV_ROOT) != 0
 2388                                                     && (cn.cn_flags & ISDOTDOT)
 2389                                                     != 0) {
 2390                                                         vref(vp);
 2391                                                         nvp = vp;
 2392                                                         r = 0;
 2393                                                 } else {
 2394                                                         r = VOP_LOOKUP(vp, &nvp,
 2395                                                             &cn);
 2396                                                         if (vp != nvp)
 2397                                                                 NFSVOPUNLOCK(vp,
 2398                                                                     0);
 2399                                                 }
 2400                                         }
 2401 
 2402                                         /*
 2403                                          * For NFSv4, check to see if nvp is
 2404                                          * a mount point and get the mount
 2405                                          * point vnode, as required.
 2406                                          */
 2407                                         if (r == 0 &&
 2408                                             nfsrv_enable_crossmntpt != 0 &&
 2409                                             (nd->nd_flag & ND_NFSV4) != 0 &&
 2410                                             nvp->v_type == VDIR &&
 2411                                             nvp->v_mountedhere != NULL) {
 2412                                                 new_mp = nvp->v_mountedhere;
 2413                                                 r = vfs_busy(new_mp, 0);
 2414                                                 vput(nvp);
 2415                                                 nvp = NULL;
 2416                                                 if (r == 0) {
 2417                                                         r = VFS_ROOT(new_mp,
 2418                                                             LK_SHARED, &nvp);
 2419                                                         needs_unbusy = 1;
 2420                                                         if (r == 0)
 2421                                                                 at_root = 1;
 2422                                                 }
 2423                                         }
 2424                                 }
 2425                                 if (!r) {
 2426                                     if (refp == NULL &&
 2427                                         ((nd->nd_flag & ND_NFSV3) ||
 2428                                          NFSNONZERO_ATTRBIT(&attrbits))) {
 2429                                         r = nfsvno_getfh(nvp, &nfh, p);
 2430                                         if (!r)
 2431                                             r = nfsvno_getattr(nvp, nvap, nd, p,
 2432                                                 1, &attrbits);
 2433                                         if (r == 0 && is_zfs == 1 &&
 2434                                             nfsrv_enable_crossmntpt != 0 &&
 2435                                             (nd->nd_flag & ND_NFSV4) != 0 &&
 2436                                             nvp->v_type == VDIR &&
 2437                                             vp->v_mount != nvp->v_mount) {
 2438                                             /*
 2439                                              * For a ZFS snapshot, there is a
 2440                                              * pseudo mount that does not set
 2441                                              * v_mountedhere, so it needs to
 2442                                              * be detected via a different
 2443                                              * mount structure.
 2444                                              */
 2445                                             at_root = 1;
 2446                                             if (new_mp == mp)
 2447                                                 new_mp = nvp->v_mount;
 2448                                         }
 2449                                     }
 2450                                 } else {
 2451                                     nvp = NULL;
 2452                                 }
 2453                                 if (r) {
 2454                                         if (!NFSISSET_ATTRBIT(&attrbits,
 2455                                             NFSATTRBIT_RDATTRERROR)) {
 2456                                                 if (nvp != NULL)
 2457                                                         vput(nvp);
 2458                                                 if (needs_unbusy != 0)
 2459                                                         vfs_unbusy(new_mp);
 2460                                                 nd->nd_repstat = r;
 2461                                                 break;
 2462                                         }
 2463                                 }
 2464                         }
 2465 
 2466                         /*
 2467                          * Build the directory record xdr
 2468                          */
 2469                         if (nd->nd_flag & ND_NFSV3) {
 2470                                 NFSM_BUILD(tl, u_int32_t *, 3 * NFSX_UNSIGNED);
 2471                                 *tl++ = newnfs_true;
 2472                                 *tl++ = 0;
 2473                                 *tl = txdr_unsigned(dp->d_fileno);
 2474                                 dirlen += nfsm_strtom(nd, dp->d_name, nlen);
 2475                                 NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2476                                 *tl++ = 0;
 2477                                 *tl = txdr_unsigned(*cookiep);
 2478                                 nfsrv_postopattr(nd, 0, nvap);
 2479                                 dirlen += nfsm_fhtom(nd,(u_int8_t *)&nfh,0,1);
 2480                                 dirlen += (5*NFSX_UNSIGNED+NFSX_V3POSTOPATTR);
 2481                                 if (nvp != NULL)
 2482                                         vput(nvp);
 2483                         } else {
 2484                                 NFSM_BUILD(tl, u_int32_t *, 3 * NFSX_UNSIGNED);
 2485                                 *tl++ = newnfs_true;
 2486                                 *tl++ = 0;
 2487                                 *tl = txdr_unsigned(*cookiep);
 2488                                 dirlen += nfsm_strtom(nd, dp->d_name, nlen);
 2489                                 if (nvp != NULL) {
 2490                                         supports_nfsv4acls =
 2491                                             nfs_supportsnfsv4acls(nvp);
 2492                                         NFSVOPUNLOCK(nvp, 0);
 2493                                 } else
 2494                                         supports_nfsv4acls = 0;
 2495                                 if (refp != NULL) {
 2496                                         dirlen += nfsrv_putreferralattr(nd,
 2497                                             &savbits, refp, 0,
 2498                                             &nd->nd_repstat);
 2499                                         if (nd->nd_repstat) {
 2500                                                 if (nvp != NULL)
 2501                                                         vrele(nvp);
 2502                                                 if (needs_unbusy != 0)
 2503                                                         vfs_unbusy(new_mp);
 2504                                                 break;
 2505                                         }
 2506                                 } else if (r) {
 2507                                         dirlen += nfsvno_fillattr(nd, new_mp,
 2508                                             nvp, nvap, &nfh, r, &rderrbits,
 2509                                             nd->nd_cred, p, isdgram, 0,
 2510                                             supports_nfsv4acls, at_root,
 2511                                             mounted_on_fileno);
 2512                                 } else {
 2513                                         dirlen += nfsvno_fillattr(nd, new_mp,
 2514                                             nvp, nvap, &nfh, r, &attrbits,
 2515                                             nd->nd_cred, p, isdgram, 0,
 2516                                             supports_nfsv4acls, at_root,
 2517                                             mounted_on_fileno);
 2518                                 }
 2519                                 if (nvp != NULL)
 2520                                         vrele(nvp);
 2521                                 dirlen += (3 * NFSX_UNSIGNED);
 2522                         }
 2523                         if (needs_unbusy != 0)
 2524                                 vfs_unbusy(new_mp);
 2525                         if (dirlen <= cnt)
 2526                                 entrycnt++;
 2527                 }
 2528                 cpos += dp->d_reclen;
 2529                 dp = (struct dirent *)cpos;
 2530                 cookiep++;
 2531                 ncookies--;
 2532         }
 2533         vrele(vp);
 2534         vfs_unbusy(mp);
 2535 
 2536         /*
 2537          * If dirlen > cnt, we must strip off the last entry. If that
 2538          * results in an empty reply, report NFSERR_TOOSMALL.
 2539          */
 2540         if (dirlen > cnt || nd->nd_repstat) {
 2541                 if (!nd->nd_repstat && entrycnt == 0)
 2542                         nd->nd_repstat = NFSERR_TOOSMALL;
 2543                 if (nd->nd_repstat) {
 2544                         newnfs_trimtrailing(nd, mb0, bpos0);
 2545                         if (nd->nd_flag & ND_NFSV3)
 2546                                 nfsrv_postopattr(nd, getret, &at);
 2547                 } else
 2548                         newnfs_trimtrailing(nd, mb1, bpos1);
 2549                 eofflag = 0;
 2550         } else if (cpos < cend)
 2551                 eofflag = 0;
 2552         if (!nd->nd_repstat) {
 2553                 NFSM_BUILD(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2554                 *tl++ = newnfs_false;
 2555                 if (eofflag)
 2556                         *tl = newnfs_true;
 2557                 else
 2558                         *tl = newnfs_false;
 2559         }
 2560         free(cookies, M_TEMP);
 2561         free(rbuf, M_TEMP);
 2562 
 2563 out:
 2564         NFSEXITCODE2(0, nd);
 2565         return (0);
 2566 nfsmout:
 2567         vput(vp);
 2568         NFSEXITCODE2(error, nd);
 2569         return (error);
 2570 }
 2571 
 2572 /*
 2573  * Get the settable attributes out of the mbuf list.
 2574  * (Return 0 or EBADRPC)
 2575  */
 2576 int
 2577 nfsrv_sattr(struct nfsrv_descript *nd, vnode_t vp, struct nfsvattr *nvap,
 2578     nfsattrbit_t *attrbitp, NFSACL_T *aclp, struct thread *p)
 2579 {
 2580         u_int32_t *tl;
 2581         struct nfsv2_sattr *sp;
 2582         int error = 0, toclient = 0;
 2583 
 2584         switch (nd->nd_flag & (ND_NFSV2 | ND_NFSV3 | ND_NFSV4)) {
 2585         case ND_NFSV2:
 2586                 NFSM_DISSECT(sp, struct nfsv2_sattr *, NFSX_V2SATTR);
 2587                 /*
 2588                  * Some old clients didn't fill in the high order 16bits.
 2589                  * --> check the low order 2 bytes for 0xffff
 2590                  */
 2591                 if ((fxdr_unsigned(int, sp->sa_mode) & 0xffff) != 0xffff)
 2592                         nvap->na_mode = nfstov_mode(sp->sa_mode);
 2593                 if (sp->sa_uid != newnfs_xdrneg1)
 2594                         nvap->na_uid = fxdr_unsigned(uid_t, sp->sa_uid);
 2595                 if (sp->sa_gid != newnfs_xdrneg1)
 2596                         nvap->na_gid = fxdr_unsigned(gid_t, sp->sa_gid);
 2597                 if (sp->sa_size != newnfs_xdrneg1)
 2598                         nvap->na_size = fxdr_unsigned(u_quad_t, sp->sa_size);
 2599                 if (sp->sa_atime.nfsv2_sec != newnfs_xdrneg1) {
 2600 #ifdef notyet
 2601                         fxdr_nfsv2time(&sp->sa_atime, &nvap->na_atime);
 2602 #else
 2603                         nvap->na_atime.tv_sec =
 2604                                 fxdr_unsigned(u_int32_t,sp->sa_atime.nfsv2_sec);
 2605                         nvap->na_atime.tv_nsec = 0;
 2606 #endif
 2607                 }
 2608                 if (sp->sa_mtime.nfsv2_sec != newnfs_xdrneg1)
 2609                         fxdr_nfsv2time(&sp->sa_mtime, &nvap->na_mtime);
 2610                 break;
 2611         case ND_NFSV3:
 2612                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2613                 if (*tl == newnfs_true) {
 2614                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2615                         nvap->na_mode = nfstov_mode(*tl);
 2616                 }
 2617                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2618                 if (*tl == newnfs_true) {
 2619                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2620                         nvap->na_uid = fxdr_unsigned(uid_t, *tl);
 2621                 }
 2622                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2623                 if (*tl == newnfs_true) {
 2624                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2625                         nvap->na_gid = fxdr_unsigned(gid_t, *tl);
 2626                 }
 2627                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2628                 if (*tl == newnfs_true) {
 2629                         NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2630                         nvap->na_size = fxdr_hyper(tl);
 2631                 }
 2632                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2633                 switch (fxdr_unsigned(int, *tl)) {
 2634                 case NFSV3SATTRTIME_TOCLIENT:
 2635                         NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2636                         fxdr_nfsv3time(tl, &nvap->na_atime);
 2637                         toclient = 1;
 2638                         break;
 2639                 case NFSV3SATTRTIME_TOSERVER:
 2640                         vfs_timestamp(&nvap->na_atime);
 2641                         nvap->na_vaflags |= VA_UTIMES_NULL;
 2642                         break;
 2643                 }
 2644                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2645                 switch (fxdr_unsigned(int, *tl)) {
 2646                 case NFSV3SATTRTIME_TOCLIENT:
 2647                         NFSM_DISSECT(tl, u_int32_t *, 2 * NFSX_UNSIGNED);
 2648                         fxdr_nfsv3time(tl, &nvap->na_mtime);
 2649                         nvap->na_vaflags &= ~VA_UTIMES_NULL;
 2650                         break;
 2651                 case NFSV3SATTRTIME_TOSERVER:
 2652                         vfs_timestamp(&nvap->na_mtime);
 2653                         if (!toclient)
 2654                                 nvap->na_vaflags |= VA_UTIMES_NULL;
 2655                         break;
 2656                 }
 2657                 break;
 2658         case ND_NFSV4:
 2659                 error = nfsv4_sattr(nd, vp, nvap, attrbitp, aclp, p);
 2660         }
 2661 nfsmout:
 2662         NFSEXITCODE2(error, nd);
 2663         return (error);
 2664 }
 2665 
 2666 /*
 2667  * Handle the setable attributes for V4.
 2668  * Returns NFSERR_BADXDR if it can't be parsed, 0 otherwise.
 2669  */
 2670 int
 2671 nfsv4_sattr(struct nfsrv_descript *nd, vnode_t vp, struct nfsvattr *nvap,
 2672     nfsattrbit_t *attrbitp, NFSACL_T *aclp, struct thread *p)
 2673 {
 2674         u_int32_t *tl;
 2675         int attrsum = 0;
 2676         int i, j;
 2677         int error, attrsize, bitpos, aclsize, aceerr, retnotsup = 0;
 2678         int toclient = 0;
 2679         u_char *cp, namestr[NFSV4_SMALLSTR + 1];
 2680         uid_t uid;
 2681         gid_t gid;
 2682 
 2683         error = nfsrv_getattrbits(nd, attrbitp, NULL, &retnotsup);
 2684         if (error)
 2685                 goto nfsmout;
 2686         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2687         attrsize = fxdr_unsigned(int, *tl);
 2688 
 2689         /*
 2690          * Loop around getting the setable attributes. If an unsupported
 2691          * one is found, set nd_repstat == NFSERR_ATTRNOTSUPP and return.
 2692          */
 2693         if (retnotsup) {
 2694                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2695                 bitpos = NFSATTRBIT_MAX;
 2696         } else {
 2697                 bitpos = 0;
 2698         }
 2699         for (; bitpos < NFSATTRBIT_MAX; bitpos++) {
 2700             if (attrsum > attrsize) {
 2701                 error = NFSERR_BADXDR;
 2702                 goto nfsmout;
 2703             }
 2704             if (NFSISSET_ATTRBIT(attrbitp, bitpos))
 2705                 switch (bitpos) {
 2706                 case NFSATTRBIT_SIZE:
 2707                         NFSM_DISSECT(tl, u_int32_t *, NFSX_HYPER);
 2708                      if (vp != NULL && vp->v_type != VREG) {
 2709                             error = (vp->v_type == VDIR) ? NFSERR_ISDIR :
 2710                                 NFSERR_INVAL;
 2711                             goto nfsmout;
 2712                         }
 2713                         nvap->na_size = fxdr_hyper(tl);
 2714                         attrsum += NFSX_HYPER;
 2715                         break;
 2716                 case NFSATTRBIT_ACL:
 2717                         error = nfsrv_dissectacl(nd, aclp, &aceerr, &aclsize,
 2718                             p);
 2719                         if (error)
 2720                                 goto nfsmout;
 2721                         if (aceerr && !nd->nd_repstat)
 2722                                 nd->nd_repstat = aceerr;
 2723                         attrsum += aclsize;
 2724                         break;
 2725                 case NFSATTRBIT_ARCHIVE:
 2726                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2727                         if (!nd->nd_repstat)
 2728                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2729                         attrsum += NFSX_UNSIGNED;
 2730                         break;
 2731                 case NFSATTRBIT_HIDDEN:
 2732                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2733                         if (!nd->nd_repstat)
 2734                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2735                         attrsum += NFSX_UNSIGNED;
 2736                         break;
 2737                 case NFSATTRBIT_MIMETYPE:
 2738                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2739                         i = fxdr_unsigned(int, *tl);
 2740                         error = nfsm_advance(nd, NFSM_RNDUP(i), -1);
 2741                         if (error)
 2742                                 goto nfsmout;
 2743                         if (!nd->nd_repstat)
 2744                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2745                         attrsum += (NFSX_UNSIGNED + NFSM_RNDUP(i));
 2746                         break;
 2747                 case NFSATTRBIT_MODE:
 2748                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2749                         nvap->na_mode = nfstov_mode(*tl);
 2750                         attrsum += NFSX_UNSIGNED;
 2751                         break;
 2752                 case NFSATTRBIT_OWNER:
 2753                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2754                         j = fxdr_unsigned(int, *tl);
 2755                         if (j < 0) {
 2756                                 error = NFSERR_BADXDR;
 2757                                 goto nfsmout;
 2758                         }
 2759                         if (j > NFSV4_SMALLSTR)
 2760                                 cp = malloc(j + 1, M_NFSSTRING, M_WAITOK);
 2761                         else
 2762                                 cp = namestr;
 2763                         error = nfsrv_mtostr(nd, cp, j);
 2764                         if (error) {
 2765                                 if (j > NFSV4_SMALLSTR)
 2766                                         free(cp, M_NFSSTRING);
 2767                                 goto nfsmout;
 2768                         }
 2769                         if (!nd->nd_repstat) {
 2770                                 nd->nd_repstat = nfsv4_strtouid(nd, cp, j, &uid,
 2771                                     p);
 2772                                 if (!nd->nd_repstat)
 2773                                         nvap->na_uid = uid;
 2774                         }
 2775                         if (j > NFSV4_SMALLSTR)
 2776                                 free(cp, M_NFSSTRING);
 2777                         attrsum += (NFSX_UNSIGNED + NFSM_RNDUP(j));
 2778                         break;
 2779                 case NFSATTRBIT_OWNERGROUP:
 2780                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2781                         j = fxdr_unsigned(int, *tl);
 2782                         if (j < 0) {
 2783                                 error = NFSERR_BADXDR;
 2784                                 goto nfsmout;
 2785                         }
 2786                         if (j > NFSV4_SMALLSTR)
 2787                                 cp = malloc(j + 1, M_NFSSTRING, M_WAITOK);
 2788                         else
 2789                                 cp = namestr;
 2790                         error = nfsrv_mtostr(nd, cp, j);
 2791                         if (error) {
 2792                                 if (j > NFSV4_SMALLSTR)
 2793                                         free(cp, M_NFSSTRING);
 2794                                 goto nfsmout;
 2795                         }
 2796                         if (!nd->nd_repstat) {
 2797                                 nd->nd_repstat = nfsv4_strtogid(nd, cp, j, &gid,
 2798                                     p);
 2799                                 if (!nd->nd_repstat)
 2800                                         nvap->na_gid = gid;
 2801                         }
 2802                         if (j > NFSV4_SMALLSTR)
 2803                                 free(cp, M_NFSSTRING);
 2804                         attrsum += (NFSX_UNSIGNED + NFSM_RNDUP(j));
 2805                         break;
 2806                 case NFSATTRBIT_SYSTEM:
 2807                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2808                         if (!nd->nd_repstat)
 2809                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2810                         attrsum += NFSX_UNSIGNED;
 2811                         break;
 2812                 case NFSATTRBIT_TIMEACCESSSET:
 2813                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2814                         attrsum += NFSX_UNSIGNED;
 2815                         if (fxdr_unsigned(int, *tl)==NFSV4SATTRTIME_TOCLIENT) {
 2816                             NFSM_DISSECT(tl, u_int32_t *, NFSX_V4TIME);
 2817                             fxdr_nfsv4time(tl, &nvap->na_atime);
 2818                             toclient = 1;
 2819                             attrsum += NFSX_V4TIME;
 2820                         } else {
 2821                             vfs_timestamp(&nvap->na_atime);
 2822                             nvap->na_vaflags |= VA_UTIMES_NULL;
 2823                         }
 2824                         break;
 2825                 case NFSATTRBIT_TIMEBACKUP:
 2826                         NFSM_DISSECT(tl, u_int32_t *, NFSX_V4TIME);
 2827                         if (!nd->nd_repstat)
 2828                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2829                         attrsum += NFSX_V4TIME;
 2830                         break;
 2831                 case NFSATTRBIT_TIMECREATE:
 2832                         NFSM_DISSECT(tl, u_int32_t *, NFSX_V4TIME);
 2833                         if (!nd->nd_repstat)
 2834                                 nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2835                         attrsum += NFSX_V4TIME;
 2836                         break;
 2837                 case NFSATTRBIT_TIMEMODIFYSET:
 2838                         NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 2839                         attrsum += NFSX_UNSIGNED;
 2840                         if (fxdr_unsigned(int, *tl)==NFSV4SATTRTIME_TOCLIENT) {
 2841                             NFSM_DISSECT(tl, u_int32_t *, NFSX_V4TIME);
 2842                             fxdr_nfsv4time(tl, &nvap->na_mtime);
 2843                             nvap->na_vaflags &= ~VA_UTIMES_NULL;
 2844                             attrsum += NFSX_V4TIME;
 2845                         } else {
 2846                             vfs_timestamp(&nvap->na_mtime);
 2847                             if (!toclient)
 2848                                 nvap->na_vaflags |= VA_UTIMES_NULL;
 2849                         }
 2850                         break;
 2851                 default:
 2852                         nd->nd_repstat = NFSERR_ATTRNOTSUPP;
 2853                         /*
 2854                          * set bitpos so we drop out of the loop.
 2855                          */
 2856                         bitpos = NFSATTRBIT_MAX;
 2857                         break;
 2858                 }
 2859         }
 2860 
 2861         /*
 2862          * some clients pad the attrlist, so we need to skip over the
 2863          * padding.
 2864          */
 2865         if (attrsum > attrsize) {
 2866                 error = NFSERR_BADXDR;
 2867         } else {
 2868                 attrsize = NFSM_RNDUP(attrsize);
 2869                 if (attrsum < attrsize)
 2870                         error = nfsm_advance(nd, attrsize - attrsum, -1);
 2871         }
 2872 nfsmout:
 2873         NFSEXITCODE2(error, nd);
 2874         return (error);
 2875 }
 2876 
 2877 /*
 2878  * Check/setup export credentials.
 2879  */
 2880 int
 2881 nfsd_excred(struct nfsrv_descript *nd, struct nfsexstuff *exp,
 2882     struct ucred *credanon)
 2883 {
 2884         int error = 0;
 2885 
 2886         /*
 2887          * Check/setup credentials.
 2888          */
 2889         if (nd->nd_flag & ND_GSS)
 2890                 exp->nes_exflag &= ~MNT_EXPORTANON;
 2891 
 2892         /*
 2893          * Check to see if the operation is allowed for this security flavor.
 2894          * RFC2623 suggests that the NFSv3 Fsinfo RPC be allowed to
 2895          * AUTH_NONE or AUTH_SYS for file systems requiring RPCSEC_GSS.
 2896          * Also, allow Secinfo, so that it can acquire the correct flavor(s).
 2897          */
 2898         if (nfsvno_testexp(nd, exp) &&
 2899             nd->nd_procnum != NFSV4OP_SECINFO &&
 2900             nd->nd_procnum != NFSPROC_FSINFO) {
 2901                 if (nd->nd_flag & ND_NFSV4)
 2902                         error = NFSERR_WRONGSEC;
 2903                 else
 2904                         error = (NFSERR_AUTHERR | AUTH_TOOWEAK);
 2905                 goto out;
 2906         }
 2907 
 2908         /*
 2909          * Check to see if the file system is exported V4 only.
 2910          */
 2911         if (NFSVNO_EXV4ONLY(exp) && !(nd->nd_flag & ND_NFSV4)) {
 2912                 error = NFSERR_PROGNOTV4;
 2913                 goto out;
 2914         }
 2915 
 2916         /*
 2917          * Now, map the user credentials.
 2918          * (Note that ND_AUTHNONE will only be set for an NFSv3
 2919          *  Fsinfo RPC. If set for anything else, this code might need
 2920          *  to change.)
 2921          */
 2922         if (NFSVNO_EXPORTED(exp)) {
 2923                 if (((nd->nd_flag & ND_GSS) == 0 && nd->nd_cred->cr_uid == 0) ||
 2924                      NFSVNO_EXPORTANON(exp) ||
 2925                      (nd->nd_flag & ND_AUTHNONE) != 0) {
 2926                         nd->nd_cred->cr_uid = credanon->cr_uid;
 2927                         nd->nd_cred->cr_gid = credanon->cr_gid;
 2928                         crsetgroups(nd->nd_cred, credanon->cr_ngroups,
 2929                             credanon->cr_groups);
 2930                 } else if ((nd->nd_flag & ND_GSS) == 0) {
 2931                         /*
 2932                          * If using AUTH_SYS, call nfsrv_getgrpscred() to see
 2933                          * if there is a replacement credential with a group
 2934                          * list set up by "nfsuserd -manage-gids".
 2935                          * If there is no replacement, nfsrv_getgrpscred()
 2936                          * simply returns its argument.
 2937                          */
 2938                         nd->nd_cred = nfsrv_getgrpscred(nd->nd_cred);
 2939                 }
 2940         }
 2941 
 2942 out:
 2943         NFSEXITCODE2(error, nd);
 2944         return (error);
 2945 }
 2946 
 2947 /*
 2948  * Check exports.
 2949  */
 2950 int
 2951 nfsvno_checkexp(struct mount *mp, struct sockaddr *nam, struct nfsexstuff *exp,
 2952     struct ucred **credp)
 2953 {
 2954         int i, error, *secflavors;
 2955 
 2956         error = VFS_CHECKEXP(mp, nam, &exp->nes_exflag, credp,
 2957             &exp->nes_numsecflavor, &secflavors);
 2958         if (error) {
 2959                 if (nfs_rootfhset) {
 2960                         exp->nes_exflag = 0;
 2961                         exp->nes_numsecflavor = 0;
 2962                         error = 0;
 2963                 }
 2964         } else {
 2965                 /* Copy the security flavors. */
 2966                 for (i = 0; i < exp->nes_numsecflavor; i++)
 2967                         exp->nes_secflavors[i] = secflavors[i];
 2968         }
 2969         NFSEXITCODE(error);
 2970         return (error);
 2971 }
 2972 
 2973 /*
 2974  * Get a vnode for a file handle and export stuff.
 2975  */
 2976 int
 2977 nfsvno_fhtovp(struct mount *mp, fhandle_t *fhp, struct sockaddr *nam,
 2978     int lktype, struct vnode **vpp, struct nfsexstuff *exp,
 2979     struct ucred **credp)
 2980 {
 2981         int i, error, *secflavors;
 2982 
 2983         *credp = NULL;
 2984         exp->nes_numsecflavor = 0;
 2985         error = VFS_FHTOVP(mp, &fhp->fh_fid, lktype, vpp);
 2986         if (error != 0)
 2987                 /* Make sure the server replies ESTALE to the client. */
 2988                 error = ESTALE;
 2989         if (nam && !error) {
 2990                 error = VFS_CHECKEXP(mp, nam, &exp->nes_exflag, credp,
 2991                     &exp->nes_numsecflavor, &secflavors);
 2992                 if (error) {
 2993                         if (nfs_rootfhset) {
 2994                                 exp->nes_exflag = 0;
 2995                                 exp->nes_numsecflavor = 0;
 2996                                 error = 0;
 2997                         } else {
 2998                                 vput(*vpp);
 2999                         }
 3000                 } else {
 3001                         /* Copy the security flavors. */
 3002                         for (i = 0; i < exp->nes_numsecflavor; i++)
 3003                                 exp->nes_secflavors[i] = secflavors[i];
 3004                 }
 3005         }
 3006         NFSEXITCODE(error);
 3007         return (error);
 3008 }
 3009 
 3010 /*
 3011  * nfsd_fhtovp() - convert a fh to a vnode ptr
 3012  *      - look up fsid in mount list (if not found ret error)
 3013  *      - get vp and export rights by calling nfsvno_fhtovp()
 3014  *      - if cred->cr_uid == 0 or MNT_EXPORTANON set it to credanon
 3015  *        for AUTH_SYS
 3016  *      - if mpp != NULL, return the mount point so that it can
 3017  *        be used for vn_finished_write() by the caller
 3018  */
 3019 void
 3020 nfsd_fhtovp(struct nfsrv_descript *nd, struct nfsrvfh *nfp, int lktype,
 3021     struct vnode **vpp, struct nfsexstuff *exp,
 3022     struct mount **mpp, int startwrite, struct thread *p)
 3023 {
 3024         struct mount *mp;
 3025         struct ucred *credanon;
 3026         fhandle_t *fhp;
 3027 
 3028         fhp = (fhandle_t *)nfp->nfsrvfh_data;
 3029         /*
 3030          * Check for the special case of the nfsv4root_fh.
 3031          */
 3032         mp = vfs_busyfs(&fhp->fh_fsid);
 3033         if (mpp != NULL)
 3034                 *mpp = mp;
 3035         if (mp == NULL) {
 3036                 *vpp = NULL;
 3037                 nd->nd_repstat = ESTALE;
 3038                 goto out;
 3039         }
 3040 
 3041         if (startwrite) {
 3042                 vn_start_write(NULL, mpp, V_WAIT);
 3043                 if (lktype == LK_SHARED && !(MNT_SHARED_WRITES(mp)))
 3044                         lktype = LK_EXCLUSIVE;
 3045         }
 3046         nd->nd_repstat = nfsvno_fhtovp(mp, fhp, nd->nd_nam, lktype, vpp, exp,
 3047             &credanon);
 3048         vfs_unbusy(mp);
 3049 
 3050         /*
 3051          * For NFSv4 without a pseudo root fs, unexported file handles
 3052          * can be returned, so that Lookup works everywhere.
 3053          */
 3054         if (!nd->nd_repstat && exp->nes_exflag == 0 &&
 3055             !(nd->nd_flag & ND_NFSV4)) {
 3056                 vput(*vpp);
 3057                 nd->nd_repstat = EACCES;
 3058         }
 3059 
 3060         /*
 3061          * Personally, I've never seen any point in requiring a
 3062          * reserved port#, since only in the rare case where the
 3063          * clients are all boxes with secure system privileges,
 3064          * does it provide any enhanced security, but... some people
 3065          * believe it to be useful and keep putting this code back in.
 3066          * (There is also some "security checker" out there that
 3067          *  complains if the nfs server doesn't enforce this.)
 3068          * However, note the following:
 3069          * RFC3530 (NFSv4) specifies that a reserved port# not be
 3070          *      required.
 3071          * RFC2623 recommends that, if a reserved port# is checked for,
 3072          *      that there be a way to turn that off--> ifdef'd.
 3073          */
 3074 #ifdef NFS_REQRSVPORT
 3075         if (!nd->nd_repstat) {
 3076                 struct sockaddr_in *saddr;
 3077                 struct sockaddr_in6 *saddr6;
 3078 
 3079                 saddr = NFSSOCKADDR(nd->nd_nam, struct sockaddr_in *);
 3080                 saddr6 = NFSSOCKADDR(nd->nd_nam, struct sockaddr_in6 *);
 3081                 if (!(nd->nd_flag & ND_NFSV4) &&
 3082                     ((saddr->sin_family == AF_INET &&
 3083                       ntohs(saddr->sin_port) >= IPPORT_RESERVED) ||
 3084                      (saddr6->sin6_family == AF_INET6 &&
 3085                       ntohs(saddr6->sin6_port) >= IPPORT_RESERVED))) {
 3086                         vput(*vpp);
 3087                         nd->nd_repstat = (NFSERR_AUTHERR | AUTH_TOOWEAK);
 3088                 }
 3089         }
 3090 #endif  /* NFS_REQRSVPORT */
 3091 
 3092         /*
 3093          * Check/setup credentials.
 3094          */
 3095         if (!nd->nd_repstat) {
 3096                 nd->nd_saveduid = nd->nd_cred->cr_uid;
 3097                 nd->nd_repstat = nfsd_excred(nd, exp, credanon);
 3098                 if (nd->nd_repstat)
 3099                         vput(*vpp);
 3100         }
 3101         if (credanon != NULL)
 3102                 crfree(credanon);
 3103         if (nd->nd_repstat) {
 3104                 if (startwrite)
 3105                         vn_finished_write(mp);
 3106                 *vpp = NULL;
 3107                 if (mpp != NULL)
 3108                         *mpp = NULL;
 3109         }
 3110 
 3111 out:
 3112         NFSEXITCODE2(0, nd);
 3113 }
 3114 
 3115 /*
 3116  * glue for fp.
 3117  */
 3118 static int
 3119 fp_getfvp(struct thread *p, int fd, struct file **fpp, struct vnode **vpp)
 3120 {
 3121         struct filedesc *fdp;
 3122         struct file *fp;
 3123         int error = 0;
 3124 
 3125         fdp = p->td_proc->p_fd;
 3126         if (fd < 0 || fd >= fdp->fd_nfiles ||
 3127             (fp = fdp->fd_ofiles[fd].fde_file) == NULL) {
 3128                 error = EBADF;
 3129                 goto out;
 3130         }
 3131         *fpp = fp;
 3132 
 3133 out:
 3134         NFSEXITCODE(error);
 3135         return (error);
 3136 }
 3137 
 3138 /*
 3139  * Called from nfssvc() to update the exports list. Just call
 3140  * vfs_export(). This has to be done, since the v4 root fake fs isn't
 3141  * in the mount list.
 3142  */
 3143 int
 3144 nfsrv_v4rootexport(void *argp, struct ucred *cred, struct thread *p)
 3145 {
 3146         struct nfsex_args *nfsexargp = (struct nfsex_args *)argp;
 3147         int error = 0;
 3148         struct nameidata nd;
 3149         fhandle_t fh;
 3150 
 3151         error = vfs_export(&nfsv4root_mnt, &nfsexargp->export);
 3152         if ((nfsexargp->export.ex_flags & MNT_DELEXPORT) != 0)
 3153                 nfs_rootfhset = 0;
 3154         else if (error == 0) {
 3155                 if (nfsexargp->fspec == NULL) {
 3156                         error = EPERM;
 3157                         goto out;
 3158                 }
 3159                 /*
 3160                  * If fspec != NULL, this is the v4root path.
 3161                  */
 3162                 NDINIT(&nd, LOOKUP, FOLLOW, UIO_USERSPACE,
 3163                     nfsexargp->fspec, p);
 3164                 if ((error = namei(&nd)) != 0)
 3165                         goto out;
 3166                 error = nfsvno_getfh(nd.ni_vp, &fh, p);
 3167                 vrele(nd.ni_vp);
 3168                 if (!error) {
 3169                         nfs_rootfh.nfsrvfh_len = NFSX_MYFH;
 3170                         NFSBCOPY((caddr_t)&fh,
 3171                             nfs_rootfh.nfsrvfh_data,
 3172                             sizeof (fhandle_t));
 3173                         nfs_rootfhset = 1;
 3174                 }
 3175         }
 3176 
 3177 out:
 3178         NFSEXITCODE(error);
 3179         return (error);
 3180 }
 3181 
 3182 /*
 3183  * This function needs to test to see if the system is near its limit
 3184  * for memory allocation via malloc() or mget() and return True iff
 3185  * either of these resources are near their limit.
 3186  * XXX (For now, this is just a stub.)
 3187  */
 3188 int nfsrv_testmalloclimit = 0;
 3189 int
 3190 nfsrv_mallocmget_limit(void)
 3191 {
 3192         static int printmesg = 0;
 3193         static int testval = 1;
 3194 
 3195         if (nfsrv_testmalloclimit && (testval++ % 1000) == 0) {
 3196                 if ((printmesg++ % 100) == 0)
 3197                         printf("nfsd: malloc/mget near limit\n");
 3198                 return (1);
 3199         }
 3200         return (0);
 3201 }
 3202 
 3203 /*
 3204  * BSD specific initialization of a mount point.
 3205  */
 3206 void
 3207 nfsd_mntinit(void)
 3208 {
 3209         static int inited = 0;
 3210 
 3211         if (inited)
 3212                 return;
 3213         inited = 1;
 3214         nfsv4root_mnt.mnt_flag = (MNT_RDONLY | MNT_EXPORTED);
 3215         TAILQ_INIT(&nfsv4root_mnt.mnt_nvnodelist);
 3216         TAILQ_INIT(&nfsv4root_mnt.mnt_activevnodelist);
 3217         nfsv4root_mnt.mnt_export = NULL;
 3218         TAILQ_INIT(&nfsv4root_opt);
 3219         TAILQ_INIT(&nfsv4root_newopt);
 3220         nfsv4root_mnt.mnt_opt = &nfsv4root_opt;
 3221         nfsv4root_mnt.mnt_optnew = &nfsv4root_newopt;
 3222         nfsv4root_mnt.mnt_nvnodelistsize = 0;
 3223         nfsv4root_mnt.mnt_activevnodelistsize = 0;
 3224 }
 3225 
 3226 /*
 3227  * Get a vnode for a file handle, without checking exports, etc.
 3228  */
 3229 struct vnode *
 3230 nfsvno_getvp(fhandle_t *fhp)
 3231 {
 3232         struct mount *mp;
 3233         struct vnode *vp;
 3234         int error;
 3235 
 3236         mp = vfs_busyfs(&fhp->fh_fsid);
 3237         if (mp == NULL)
 3238                 return (NULL);
 3239         error = VFS_FHTOVP(mp, &fhp->fh_fid, LK_EXCLUSIVE, &vp);
 3240         vfs_unbusy(mp);
 3241         if (error)
 3242                 return (NULL);
 3243         return (vp);
 3244 }
 3245 
 3246 /*
 3247  * Do a local VOP_ADVLOCK().
 3248  */
 3249 int
 3250 nfsvno_advlock(struct vnode *vp, int ftype, u_int64_t first,
 3251     u_int64_t end, struct thread *td)
 3252 {
 3253         int error = 0;
 3254         struct flock fl;
 3255         u_int64_t tlen;
 3256 
 3257         if (nfsrv_dolocallocks == 0)
 3258                 goto out;
 3259         ASSERT_VOP_UNLOCKED(vp, "nfsvno_advlock: vp locked");
 3260 
 3261         fl.l_whence = SEEK_SET;
 3262         fl.l_type = ftype;
 3263         fl.l_start = (off_t)first;
 3264         if (end == NFS64BITSSET) {
 3265                 fl.l_len = 0;
 3266         } else {
 3267                 tlen = end - first;
 3268                 fl.l_len = (off_t)tlen;
 3269         }
 3270         /*
 3271          * For FreeBSD8, the l_pid and l_sysid must be set to the same
 3272          * values for all calls, so that all locks will be held by the
 3273          * nfsd server. (The nfsd server handles conflicts between the
 3274          * various clients.)
 3275          * Since an NFSv4 lockowner is a ClientID plus an array of up to 1024
 3276          * bytes, so it can't be put in l_sysid.
 3277          */
 3278         if (nfsv4_sysid == 0)
 3279                 nfsv4_sysid = nlm_acquire_next_sysid();
 3280         fl.l_pid = (pid_t)0;
 3281         fl.l_sysid = (int)nfsv4_sysid;
 3282 
 3283         if (ftype == F_UNLCK)
 3284                 error = VOP_ADVLOCK(vp, (caddr_t)td->td_proc, F_UNLCK, &fl,
 3285                     (F_POSIX | F_REMOTE));
 3286         else
 3287                 error = VOP_ADVLOCK(vp, (caddr_t)td->td_proc, F_SETLK, &fl,
 3288                     (F_POSIX | F_REMOTE));
 3289 
 3290 out:
 3291         NFSEXITCODE(error);
 3292         return (error);
 3293 }
 3294 
 3295 /*
 3296  * Check the nfsv4 root exports.
 3297  */
 3298 int
 3299 nfsvno_v4rootexport(struct nfsrv_descript *nd)
 3300 {
 3301         struct ucred *credanon;
 3302         int exflags, error = 0, numsecflavor, *secflavors, i;
 3303 
 3304         error = vfs_stdcheckexp(&nfsv4root_mnt, nd->nd_nam, &exflags,
 3305             &credanon, &numsecflavor, &secflavors);
 3306         if (error) {
 3307                 error = NFSERR_PROGUNAVAIL;
 3308                 goto out;
 3309         }
 3310         if (credanon != NULL)
 3311                 crfree(credanon);
 3312         for (i = 0; i < numsecflavor; i++) {
 3313                 if (secflavors[i] == AUTH_SYS)
 3314                         nd->nd_flag |= ND_EXAUTHSYS;
 3315                 else if (secflavors[i] == RPCSEC_GSS_KRB5)
 3316                         nd->nd_flag |= ND_EXGSS;
 3317                 else if (secflavors[i] == RPCSEC_GSS_KRB5I)
 3318                         nd->nd_flag |= ND_EXGSSINTEGRITY;
 3319                 else if (secflavors[i] == RPCSEC_GSS_KRB5P)
 3320                         nd->nd_flag |= ND_EXGSSPRIVACY;
 3321         }
 3322 
 3323 out:
 3324         NFSEXITCODE(error);
 3325         return (error);
 3326 }
 3327 
 3328 /*
 3329  * Nfs server pseudo system call for the nfsd's
 3330  */
 3331 /*
 3332  * MPSAFE
 3333  */
 3334 static int
 3335 nfssvc_nfsd(struct thread *td, struct nfssvc_args *uap)
 3336 {
 3337         struct file *fp;
 3338         struct nfsd_addsock_args sockarg;
 3339         struct nfsd_nfsd_args nfsdarg;
 3340         struct nfsd_nfsd_oargs onfsdarg;
 3341         struct nfsd_pnfsd_args pnfsdarg;
 3342         struct vnode *vp, *nvp, *curdvp;
 3343         struct pnfsdsfile *pf;
 3344         struct nfsdevice *ds, *fds;
 3345         cap_rights_t rights;
 3346         int buflen, error, ret;
 3347         char *buf, *cp, *cp2, *cp3;
 3348         char fname[PNFS_FILENAME_LEN + 1];
 3349 
 3350         if (uap->flag & NFSSVC_NFSDADDSOCK) {
 3351                 error = copyin(uap->argp, (caddr_t)&sockarg, sizeof (sockarg));
 3352                 if (error)
 3353                         goto out;
 3354                 /*
 3355                  * Since we don't know what rights might be required,
 3356                  * pretend that we need them all. It is better to be too
 3357                  * careful than too reckless.
 3358                  */
 3359                 error = fget(td, sockarg.sock,
 3360                     cap_rights_init(&rights, CAP_SOCK_SERVER), &fp);
 3361                 if (error != 0)
 3362                         goto out;
 3363                 if (fp->f_type != DTYPE_SOCKET) {
 3364                         fdrop(fp, td);
 3365                         error = EPERM;
 3366                         goto out;
 3367                 }
 3368                 error = nfsrvd_addsock(fp);
 3369                 fdrop(fp, td);
 3370         } else if (uap->flag & NFSSVC_NFSDNFSD) {
 3371                 if (uap->argp == NULL) {
 3372                         error = EINVAL;
 3373                         goto out;
 3374                 }
 3375                 if ((uap->flag & NFSSVC_NEWSTRUCT) == 0) {
 3376                         error = copyin(uap->argp, &onfsdarg, sizeof(onfsdarg));
 3377                         if (error == 0) {
 3378                                 nfsdarg.principal = onfsdarg.principal;
 3379                                 nfsdarg.minthreads = onfsdarg.minthreads;
 3380                                 nfsdarg.maxthreads = onfsdarg.maxthreads;
 3381                                 nfsdarg.version = 1;
 3382                                 nfsdarg.addr = NULL;
 3383                                 nfsdarg.addrlen = 0;
 3384                                 nfsdarg.dnshost = NULL;
 3385                                 nfsdarg.dnshostlen = 0;
 3386                                 nfsdarg.dspath = NULL;
 3387                                 nfsdarg.dspathlen = 0;
 3388                                 nfsdarg.mdspath = NULL;
 3389                                 nfsdarg.mdspathlen = 0;
 3390                                 nfsdarg.mirrorcnt = 1;
 3391                         }
 3392                 } else
 3393                         error = copyin(uap->argp, &nfsdarg, sizeof(nfsdarg));
 3394                 if (error)
 3395                         goto out;
 3396                 if (nfsdarg.addrlen > 0 && nfsdarg.addrlen < 10000 &&
 3397                     nfsdarg.dnshostlen > 0 && nfsdarg.dnshostlen < 10000 &&
 3398                     nfsdarg.dspathlen > 0 && nfsdarg.dspathlen < 10000 &&
 3399                     nfsdarg.mdspathlen > 0 && nfsdarg.mdspathlen < 10000 &&
 3400                     nfsdarg.mirrorcnt >= 1 &&
 3401                     nfsdarg.mirrorcnt <= NFSDEV_MAXMIRRORS &&
 3402                     nfsdarg.addr != NULL && nfsdarg.dnshost != NULL &&
 3403                     nfsdarg.dspath != NULL && nfsdarg.mdspath != NULL) {
 3404                         NFSD_DEBUG(1, "addrlen=%d dspathlen=%d dnslen=%d"
 3405                             " mdspathlen=%d mirrorcnt=%d\n", nfsdarg.addrlen,
 3406                             nfsdarg.dspathlen, nfsdarg.dnshostlen,
 3407                             nfsdarg.mdspathlen, nfsdarg.mirrorcnt);
 3408                         cp = malloc(nfsdarg.addrlen + 1, M_TEMP, M_WAITOK);
 3409                         error = copyin(nfsdarg.addr, cp, nfsdarg.addrlen);
 3410                         if (error != 0) {
 3411                                 free(cp, M_TEMP);
 3412                                 goto out;
 3413                         }
 3414                         cp[nfsdarg.addrlen] = '\0';     /* Ensure nul term. */
 3415                         nfsdarg.addr = cp;
 3416                         cp = malloc(nfsdarg.dnshostlen + 1, M_TEMP, M_WAITOK);
 3417                         error = copyin(nfsdarg.dnshost, cp, nfsdarg.dnshostlen);
 3418                         if (error != 0) {
 3419                                 free(nfsdarg.addr, M_TEMP);
 3420                                 free(cp, M_TEMP);
 3421                                 goto out;
 3422                         }
 3423                         cp[nfsdarg.dnshostlen] = '\0';  /* Ensure nul term. */
 3424                         nfsdarg.dnshost = cp;
 3425                         cp = malloc(nfsdarg.dspathlen + 1, M_TEMP, M_WAITOK);
 3426                         error = copyin(nfsdarg.dspath, cp, nfsdarg.dspathlen);
 3427                         if (error != 0) {
 3428                                 free(nfsdarg.addr, M_TEMP);
 3429                                 free(nfsdarg.dnshost, M_TEMP);
 3430                                 free(cp, M_TEMP);
 3431                                 goto out;
 3432                         }
 3433                         cp[nfsdarg.dspathlen] = '\0';   /* Ensure nul term. */
 3434                         nfsdarg.dspath = cp;
 3435                         cp = malloc(nfsdarg.mdspathlen + 1, M_TEMP, M_WAITOK);
 3436                         error = copyin(nfsdarg.mdspath, cp, nfsdarg.mdspathlen);
 3437                         if (error != 0) {
 3438                                 free(nfsdarg.addr, M_TEMP);
 3439                                 free(nfsdarg.dnshost, M_TEMP);
 3440                                 free(nfsdarg.dspath, M_TEMP);
 3441                                 free(cp, M_TEMP);
 3442                                 goto out;
 3443                         }
 3444                         cp[nfsdarg.mdspathlen] = '\0';  /* Ensure nul term. */
 3445                         nfsdarg.mdspath = cp;
 3446                 } else {
 3447                         nfsdarg.addr = NULL;
 3448                         nfsdarg.addrlen = 0;
 3449                         nfsdarg.dnshost = NULL;
 3450                         nfsdarg.dnshostlen = 0;
 3451                         nfsdarg.dspath = NULL;
 3452                         nfsdarg.dspathlen = 0;
 3453                         nfsdarg.mdspath = NULL;
 3454                         nfsdarg.mdspathlen = 0;
 3455                         nfsdarg.mirrorcnt = 1;
 3456                 }
 3457                 error = nfsrvd_nfsd(td, &nfsdarg);
 3458                 free(nfsdarg.addr, M_TEMP);
 3459                 free(nfsdarg.dnshost, M_TEMP);
 3460                 free(nfsdarg.dspath, M_TEMP);
 3461                 free(nfsdarg.mdspath, M_TEMP);
 3462         } else if (uap->flag & NFSSVC_PNFSDS) {
 3463                 error = copyin(uap->argp, &pnfsdarg, sizeof(pnfsdarg));
 3464                 if (error == 0 && (pnfsdarg.op == PNFSDOP_DELDSSERVER ||
 3465                     pnfsdarg.op == PNFSDOP_FORCEDELDS)) {
 3466                         cp = malloc(PATH_MAX + 1, M_TEMP, M_WAITOK);
 3467                         error = copyinstr(pnfsdarg.dspath, cp, PATH_MAX + 1,
 3468                             NULL);
 3469                         if (error == 0)
 3470                                 error = nfsrv_deldsserver(pnfsdarg.op, cp, td);
 3471                         free(cp, M_TEMP);
 3472                 } else if (error == 0 && pnfsdarg.op == PNFSDOP_COPYMR) {
 3473                         cp = malloc(PATH_MAX + 1, M_TEMP, M_WAITOK);
 3474                         buflen = sizeof(*pf) * NFSDEV_MAXMIRRORS;
 3475                         buf = malloc(buflen, M_TEMP, M_WAITOK);
 3476                         error = copyinstr(pnfsdarg.mdspath, cp, PATH_MAX + 1,
 3477                             NULL);
 3478                         NFSD_DEBUG(4, "pnfsdcopymr cp mdspath=%d\n", error);
 3479                         if (error == 0 && pnfsdarg.dspath != NULL) {
 3480                                 cp2 = malloc(PATH_MAX + 1, M_TEMP, M_WAITOK);
 3481                                 error = copyinstr(pnfsdarg.dspath, cp2,
 3482                                     PATH_MAX + 1, NULL);
 3483                                 NFSD_DEBUG(4, "pnfsdcopymr cp dspath=%d\n",
 3484                                     error);
 3485                         } else
 3486                                 cp2 = NULL;
 3487                         if (error == 0 && pnfsdarg.curdspath != NULL) {
 3488                                 cp3 = malloc(PATH_MAX + 1, M_TEMP, M_WAITOK);
 3489                                 error = copyinstr(pnfsdarg.curdspath, cp3,
 3490                                     PATH_MAX + 1, NULL);
 3491                                 NFSD_DEBUG(4, "pnfsdcopymr cp curdspath=%d\n",
 3492                                     error);
 3493                         } else
 3494                                 cp3 = NULL;
 3495                         curdvp = NULL;
 3496                         fds = NULL;
 3497                         if (error == 0)
 3498                                 error = nfsrv_mdscopymr(cp, cp2, cp3, buf,
 3499                                     &buflen, fname, td, &vp, &nvp, &pf, &ds,
 3500                                     &fds);
 3501                         NFSD_DEBUG(4, "nfsrv_mdscopymr=%d\n", error);
 3502                         if (error == 0) {
 3503                                 if (pf->dsf_dir >= nfsrv_dsdirsize) {
 3504                                         printf("copymr: dsdir out of range\n");
 3505                                         pf->dsf_dir = 0;
 3506                                 }
 3507                                 NFSD_DEBUG(4, "copymr: buflen=%d\n", buflen);
 3508                                 error = nfsrv_copymr(vp, nvp,
 3509                                     ds->nfsdev_dsdir[pf->dsf_dir], ds, pf,
 3510                                     (struct pnfsdsfile *)buf,
 3511                                     buflen / sizeof(*pf), td->td_ucred, td);
 3512                                 vput(vp);
 3513                                 vput(nvp);
 3514                                 if (fds != NULL && error == 0) {
 3515                                         curdvp = fds->nfsdev_dsdir[pf->dsf_dir];
 3516                                         ret = vn_lock(curdvp, LK_EXCLUSIVE);
 3517                                         if (ret == 0) {
 3518                                                 nfsrv_dsremove(curdvp, fname,
 3519                                                     td->td_ucred, td);
 3520                                                 NFSVOPUNLOCK(curdvp, 0);
 3521                                         }
 3522                                 }
 3523                                 NFSD_DEBUG(4, "nfsrv_copymr=%d\n", error);
 3524                         }
 3525                         free(cp, M_TEMP);
 3526                         free(cp2, M_TEMP);
 3527                         free(cp3, M_TEMP);
 3528                         free(buf, M_TEMP);
 3529                 }
 3530         } else {
 3531                 error = nfssvc_srvcall(td, uap, td->td_ucred);
 3532         }
 3533 
 3534 out:
 3535         NFSEXITCODE(error);
 3536         return (error);
 3537 }
 3538 
 3539 static int
 3540 nfssvc_srvcall(struct thread *p, struct nfssvc_args *uap, struct ucred *cred)
 3541 {
 3542         struct nfsex_args export;
 3543         struct file *fp = NULL;
 3544         int stablefd, len;
 3545         struct nfsd_clid adminrevoke;
 3546         struct nfsd_dumplist dumplist;
 3547         struct nfsd_dumpclients *dumpclients;
 3548         struct nfsd_dumplocklist dumplocklist;
 3549         struct nfsd_dumplocks *dumplocks;
 3550         struct nameidata nd;
 3551         vnode_t vp;
 3552         int error = EINVAL, igotlock;
 3553         struct proc *procp;
 3554         static int suspend_nfsd = 0;
 3555 
 3556         if (uap->flag & NFSSVC_PUBLICFH) {
 3557                 NFSBZERO((caddr_t)&nfs_pubfh.nfsrvfh_data,
 3558                     sizeof (fhandle_t));
 3559                 error = copyin(uap->argp,
 3560                     &nfs_pubfh.nfsrvfh_data, sizeof (fhandle_t));
 3561                 if (!error)
 3562                         nfs_pubfhset = 1;
 3563         } else if (uap->flag & NFSSVC_V4ROOTEXPORT) {
 3564                 error = copyin(uap->argp,(caddr_t)&export,
 3565                     sizeof (struct nfsex_args));
 3566                 if (!error)
 3567                         error = nfsrv_v4rootexport(&export, cred, p);
 3568         } else if (uap->flag & NFSSVC_NOPUBLICFH) {
 3569                 nfs_pubfhset = 0;
 3570                 error = 0;
 3571         } else if (uap->flag & NFSSVC_STABLERESTART) {
 3572                 error = copyin(uap->argp, (caddr_t)&stablefd,
 3573                     sizeof (int));
 3574                 if (!error)
 3575                         error = fp_getfvp(p, stablefd, &fp, &vp);
 3576                 if (!error && (NFSFPFLAG(fp) & (FREAD | FWRITE)) != (FREAD | FWRITE))
 3577                         error = EBADF;
 3578                 if (!error && newnfs_numnfsd != 0)
 3579                         error = EPERM;
 3580                 if (!error) {
 3581                         nfsrv_stablefirst.nsf_fp = fp;
 3582                         nfsrv_setupstable(p);
 3583                 }
 3584         } else if (uap->flag & NFSSVC_ADMINREVOKE) {
 3585                 error = copyin(uap->argp, (caddr_t)&adminrevoke,
 3586                     sizeof (struct nfsd_clid));
 3587                 if (!error)
 3588                         error = nfsrv_adminrevoke(&adminrevoke, p);
 3589         } else if (uap->flag & NFSSVC_DUMPCLIENTS) {
 3590                 error = copyin(uap->argp, (caddr_t)&dumplist,
 3591                     sizeof (struct nfsd_dumplist));
 3592                 if (!error && (dumplist.ndl_size < 1 ||
 3593                         dumplist.ndl_size > NFSRV_MAXDUMPLIST))
 3594                         error = EPERM;
 3595                 if (!error) {
 3596                     len = sizeof (struct nfsd_dumpclients) * dumplist.ndl_size;
 3597                     dumpclients = (struct nfsd_dumpclients *)malloc(len,
 3598                         M_TEMP, M_WAITOK);
 3599                     nfsrv_dumpclients(dumpclients, dumplist.ndl_size);
 3600                     error = copyout(dumpclients,
 3601                         CAST_USER_ADDR_T(dumplist.ndl_list), len);
 3602                     free(dumpclients, M_TEMP);
 3603                 }
 3604         } else if (uap->flag & NFSSVC_DUMPLOCKS) {
 3605                 error = copyin(uap->argp, (caddr_t)&dumplocklist,
 3606                     sizeof (struct nfsd_dumplocklist));
 3607                 if (!error && (dumplocklist.ndllck_size < 1 ||
 3608                         dumplocklist.ndllck_size > NFSRV_MAXDUMPLIST))
 3609                         error = EPERM;
 3610                 if (!error)
 3611                         error = nfsrv_lookupfilename(&nd,
 3612                                 dumplocklist.ndllck_fname, p);
 3613                 if (!error) {
 3614                         len = sizeof (struct nfsd_dumplocks) *
 3615                                 dumplocklist.ndllck_size;
 3616                         dumplocks = (struct nfsd_dumplocks *)malloc(len,
 3617                                 M_TEMP, M_WAITOK);
 3618                         nfsrv_dumplocks(nd.ni_vp, dumplocks,
 3619                             dumplocklist.ndllck_size, p);
 3620                         vput(nd.ni_vp);
 3621                         error = copyout(dumplocks,
 3622                             CAST_USER_ADDR_T(dumplocklist.ndllck_list), len);
 3623                         free(dumplocks, M_TEMP);
 3624                 }
 3625         } else if (uap->flag & NFSSVC_BACKUPSTABLE) {
 3626                 procp = p->td_proc;
 3627                 PROC_LOCK(procp);
 3628                 nfsd_master_pid = procp->p_pid;
 3629                 bcopy(procp->p_comm, nfsd_master_comm, MAXCOMLEN + 1);
 3630                 nfsd_master_start = procp->p_stats->p_start;
 3631                 nfsd_master_proc = procp;
 3632                 PROC_UNLOCK(procp);
 3633         } else if ((uap->flag & NFSSVC_SUSPENDNFSD) != 0) {
 3634                 NFSLOCKV4ROOTMUTEX();
 3635                 if (suspend_nfsd == 0) {
 3636                         /* Lock out all nfsd threads */
 3637                         do {
 3638                                 igotlock = nfsv4_lock(&nfsd_suspend_lock, 1,
 3639                                     NULL, NFSV4ROOTLOCKMUTEXPTR, NULL);
 3640                         } while (igotlock == 0 && suspend_nfsd == 0);
 3641                         suspend_nfsd = 1;
 3642                 }
 3643                 NFSUNLOCKV4ROOTMUTEX();
 3644                 error = 0;
 3645         } else if ((uap->flag & NFSSVC_RESUMENFSD) != 0) {
 3646                 NFSLOCKV4ROOTMUTEX();
 3647                 if (suspend_nfsd != 0) {
 3648                         nfsv4_unlock(&nfsd_suspend_lock, 0);
 3649                         suspend_nfsd = 0;
 3650                 }
 3651                 NFSUNLOCKV4ROOTMUTEX();
 3652                 error = 0;
 3653         }
 3654 
 3655         NFSEXITCODE(error);
 3656         return (error);
 3657 }
 3658 
 3659 /*
 3660  * Check exports.
 3661  * Returns 0 if ok, 1 otherwise.
 3662  */
 3663 int
 3664 nfsvno_testexp(struct nfsrv_descript *nd, struct nfsexstuff *exp)
 3665 {
 3666         int i;
 3667 
 3668         /*
 3669          * This seems odd, but allow the case where the security flavor
 3670          * list is empty. This happens when NFSv4 is traversing non-exported
 3671          * file systems. Exported file systems should always have a non-empty
 3672          * security flavor list.
 3673          */
 3674         if (exp->nes_numsecflavor == 0)
 3675                 return (0);
 3676 
 3677         for (i = 0; i < exp->nes_numsecflavor; i++) {
 3678                 /*
 3679                  * The tests for privacy and integrity must be first,
 3680                  * since ND_GSS is set for everything but AUTH_SYS.
 3681                  */
 3682                 if (exp->nes_secflavors[i] == RPCSEC_GSS_KRB5P &&
 3683                     (nd->nd_flag & ND_GSSPRIVACY))
 3684                         return (0);
 3685                 if (exp->nes_secflavors[i] == RPCSEC_GSS_KRB5I &&
 3686                     (nd->nd_flag & ND_GSSINTEGRITY))
 3687                         return (0);
 3688                 if (exp->nes_secflavors[i] == RPCSEC_GSS_KRB5 &&
 3689                     (nd->nd_flag & ND_GSS))
 3690                         return (0);
 3691                 if (exp->nes_secflavors[i] == AUTH_SYS &&
 3692                     (nd->nd_flag & ND_GSS) == 0)
 3693                         return (0);
 3694         }
 3695         return (1);
 3696 }
 3697 
 3698 /*
 3699  * Calculate a hash value for the fid in a file handle.
 3700  */
 3701 uint32_t
 3702 nfsrv_hashfh(fhandle_t *fhp)
 3703 {
 3704         uint32_t hashval;
 3705 
 3706         hashval = hash32_buf(&fhp->fh_fid, sizeof(struct fid), 0);
 3707         return (hashval);
 3708 }
 3709 
 3710 /*
 3711  * Calculate a hash value for the sessionid.
 3712  */
 3713 uint32_t
 3714 nfsrv_hashsessionid(uint8_t *sessionid)
 3715 {
 3716         uint32_t hashval;
 3717 
 3718         hashval = hash32_buf(sessionid, NFSX_V4SESSIONID, 0);
 3719         return (hashval);
 3720 }
 3721 
 3722 /*
 3723  * Signal the userland master nfsd to backup the stable restart file.
 3724  */
 3725 void
 3726 nfsrv_backupstable(void)
 3727 {
 3728         struct proc *procp;
 3729 
 3730         if (nfsd_master_proc != NULL) {
 3731                 procp = pfind(nfsd_master_pid);
 3732                 /* Try to make sure it is the correct process. */
 3733                 if (procp == nfsd_master_proc &&
 3734                     procp->p_stats->p_start.tv_sec ==
 3735                     nfsd_master_start.tv_sec &&
 3736                     procp->p_stats->p_start.tv_usec ==
 3737                     nfsd_master_start.tv_usec &&
 3738                     strcmp(procp->p_comm, nfsd_master_comm) == 0)
 3739                         kern_psignal(procp, SIGUSR2);
 3740                 else
 3741                         nfsd_master_proc = NULL;
 3742 
 3743                 if (procp != NULL)
 3744                         PROC_UNLOCK(procp);
 3745         }
 3746 }
 3747 
 3748 /*
 3749  * Create a DS data file for nfsrv_pnfscreate(). Called for each mirror.
 3750  * The arguments are in a structure, so that they can be passed through
 3751  * taskqueue for a kernel process to execute this function.
 3752  */
 3753 struct nfsrvdscreate {
 3754         int                     done;
 3755         int                     inprog;
 3756         struct task             tsk;
 3757         struct ucred            *tcred;
 3758         struct vnode            *dvp;
 3759         NFSPROC_T               *p;
 3760         struct pnfsdsfile       *pf;
 3761         int                     err;
 3762         fhandle_t               fh;
 3763         struct vattr            va;
 3764         struct vattr            createva;
 3765 };
 3766 
 3767 int
 3768 nfsrv_dscreate(struct vnode *dvp, struct vattr *vap, struct vattr *nvap,
 3769     fhandle_t *fhp, struct pnfsdsfile *pf, struct pnfsdsattr *dsa,
 3770     char *fnamep, struct ucred *tcred, NFSPROC_T *p, struct vnode **nvpp)
 3771 {
 3772         struct vnode *nvp;
 3773         struct nameidata named;
 3774         struct vattr va;
 3775         char *bufp;
 3776         u_long *hashp;
 3777         struct nfsnode *np;
 3778         struct nfsmount *nmp;
 3779         int error;
 3780 
 3781         NFSNAMEICNDSET(&named.ni_cnd, tcred, CREATE,
 3782             LOCKPARENT | LOCKLEAF | SAVESTART | NOCACHE);
 3783         nfsvno_setpathbuf(&named, &bufp, &hashp);
 3784         named.ni_cnd.cn_lkflags = LK_EXCLUSIVE;
 3785         named.ni_cnd.cn_thread = p;
 3786         named.ni_cnd.cn_nameptr = bufp;
 3787         if (fnamep != NULL) {
 3788                 strlcpy(bufp, fnamep, PNFS_FILENAME_LEN + 1);
 3789                 named.ni_cnd.cn_namelen = strlen(bufp);
 3790         } else
 3791                 named.ni_cnd.cn_namelen = nfsrv_putfhname(fhp, bufp);
 3792         NFSD_DEBUG(4, "nfsrv_dscreate: dvp=%p fname=%s\n", dvp, bufp);
 3793 
 3794         /* Create the date file in the DS mount. */
 3795         error = NFSVOPLOCK(dvp, LK_EXCLUSIVE);
 3796         if (error == 0) {
 3797                 error = VOP_CREATE(dvp, &nvp, &named.ni_cnd, vap);
 3798                 NFSVOPUNLOCK(dvp, 0);
 3799                 if (error == 0) {
 3800                         /* Set the ownership of the file. */
 3801                         error = VOP_SETATTR(nvp, nvap, tcred);
 3802                         NFSD_DEBUG(4, "nfsrv_dscreate:"
 3803                             " setattr-uid=%d\n", error);
 3804                         if (error != 0)
 3805                                 vput(nvp);
 3806                 }
 3807                 if (error != 0)
 3808                         printf("pNFS: pnfscreate failed=%d\n", error);
 3809         } else
 3810                 printf("pNFS: pnfscreate vnlock=%d\n", error);
 3811         if (error == 0) {
 3812                 np = VTONFS(nvp);
 3813                 nmp = VFSTONFS(nvp->v_mount);
 3814                 if (strcmp(nvp->v_mount->mnt_vfc->vfc_name, "nfs")
 3815                     != 0 || nmp->nm_nam->sa_len > sizeof(
 3816                     struct sockaddr_in6) ||
 3817                     np->n_fhp->nfh_len != NFSX_MYFH) {
 3818                         printf("Bad DS file: fstype=%s salen=%d"
 3819                             " fhlen=%d\n",
 3820                             nvp->v_mount->mnt_vfc->vfc_name,
 3821                             nmp->nm_nam->sa_len, np->n_fhp->nfh_len);
 3822                         error = ENOENT;
 3823                 }
 3824 
 3825                 /* Set extattrs for the DS on the MDS file. */
 3826                 if (error == 0) {
 3827                         if (dsa != NULL) {
 3828                                 error = VOP_GETATTR(nvp, &va, tcred);
 3829                                 if (error == 0) {
 3830                                         dsa->dsa_filerev = va.va_filerev;
 3831                                         dsa->dsa_size = va.va_size;
 3832                                         dsa->dsa_atime = va.va_atime;
 3833                                         dsa->dsa_mtime = va.va_mtime;
 3834                                 }
 3835                         }
 3836                         if (error == 0) {
 3837                                 NFSBCOPY(np->n_fhp->nfh_fh, &pf->dsf_fh,
 3838                                     NFSX_MYFH);
 3839                                 NFSBCOPY(nmp->nm_nam, &pf->dsf_sin,
 3840                                     nmp->nm_nam->sa_len);
 3841                                 NFSBCOPY(named.ni_cnd.cn_nameptr,
 3842                                     pf->dsf_filename,
 3843                                     sizeof(pf->dsf_filename));
 3844                         }
 3845                 } else
 3846                         printf("pNFS: pnfscreate can't get DS"
 3847                             " attr=%d\n", error);
 3848                 if (nvpp != NULL && error == 0)
 3849                         *nvpp = nvp;
 3850                 else
 3851                         vput(nvp);
 3852         }
 3853         nfsvno_relpathbuf(&named);
 3854         return (error);
 3855 }
 3856 
 3857 /*
 3858  * Start up the thread that will execute nfsrv_dscreate().
 3859  */
 3860 static void
 3861 start_dscreate(void *arg, int pending)
 3862 {
 3863         struct nfsrvdscreate *dsc;
 3864 
 3865         dsc = (struct nfsrvdscreate *)arg;
 3866         dsc->err = nfsrv_dscreate(dsc->dvp, &dsc->createva, &dsc->va, &dsc->fh,
 3867             dsc->pf, NULL, NULL, dsc->tcred, dsc->p, NULL);
 3868         dsc->done = 1;
 3869         NFSD_DEBUG(4, "start_dscreate: err=%d\n", dsc->err);
 3870 }
 3871 
 3872 /*
 3873  * Create a pNFS data file on the Data Server(s).
 3874  */
 3875 static void
 3876 nfsrv_pnfscreate(struct vnode *vp, struct vattr *vap, struct ucred *cred,
 3877     NFSPROC_T *p)
 3878 {
 3879         struct nfsrvdscreate *dsc, *tdsc;
 3880         struct nfsdevice *ds, *tds, *fds;
 3881         struct mount *mp;
 3882         struct pnfsdsfile *pf, *tpf;
 3883         struct pnfsdsattr dsattr;
 3884         struct vattr va;
 3885         struct vnode *dvp[NFSDEV_MAXMIRRORS];
 3886         struct nfsmount *nmp;
 3887         fhandle_t fh;
 3888         uid_t vauid;
 3889         gid_t vagid;
 3890         u_short vamode;
 3891         struct ucred *tcred;
 3892         int dsdir[NFSDEV_MAXMIRRORS], error, i, mirrorcnt, ret;
 3893         int failpos, timo;
 3894 
 3895         /* Get a DS server directory in a round-robin order. */
 3896         mirrorcnt = 1;
 3897         mp = vp->v_mount;
 3898         ds = fds = NULL;
 3899         NFSDDSLOCK();
 3900         /*
 3901          * Search for the first entry that handles this MDS fs, but use the
 3902          * first entry for all MDS fs's otherwise.
 3903          */
 3904         TAILQ_FOREACH(tds, &nfsrv_devidhead, nfsdev_list) {
 3905                 if (tds->nfsdev_nmp != NULL) {
 3906                         if (tds->nfsdev_mdsisset == 0 && ds == NULL)
 3907                                 ds = tds;
 3908                         else if (tds->nfsdev_mdsisset != 0 &&
 3909                             mp->mnt_stat.f_fsid.val[0] ==
 3910                             tds->nfsdev_mdsfsid.val[0] &&
 3911                             mp->mnt_stat.f_fsid.val[1] ==
 3912                             tds->nfsdev_mdsfsid.val[1]) {
 3913                                 ds = fds = tds;
 3914                                 break;
 3915                         }
 3916                 }
 3917         }
 3918         if (ds == NULL) {
 3919                 NFSDDSUNLOCK();
 3920                 NFSD_DEBUG(4, "nfsrv_pnfscreate: no srv\n");
 3921                 return;
 3922         }
 3923         i = dsdir[0] = ds->nfsdev_nextdir;
 3924         ds->nfsdev_nextdir = (ds->nfsdev_nextdir + 1) % nfsrv_dsdirsize;
 3925         dvp[0] = ds->nfsdev_dsdir[i];
 3926         tds = TAILQ_NEXT(ds, nfsdev_list);
 3927         if (nfsrv_maxpnfsmirror > 1 && tds != NULL) {
 3928                 TAILQ_FOREACH_FROM(tds, &nfsrv_devidhead, nfsdev_list) {
 3929                         if (tds->nfsdev_nmp != NULL &&
 3930                             ((tds->nfsdev_mdsisset == 0 && fds == NULL) ||
 3931                              (tds->nfsdev_mdsisset != 0 && fds != NULL &&
 3932                               mp->mnt_stat.f_fsid.val[0] ==
 3933                               tds->nfsdev_mdsfsid.val[0] &&
 3934                               mp->mnt_stat.f_fsid.val[1] ==
 3935                               tds->nfsdev_mdsfsid.val[1]))) {
 3936                                 dsdir[mirrorcnt] = i;
 3937                                 dvp[mirrorcnt] = tds->nfsdev_dsdir[i];
 3938                                 mirrorcnt++;
 3939                                 if (mirrorcnt >= nfsrv_maxpnfsmirror)
 3940                                         break;
 3941                         }
 3942                 }
 3943         }
 3944         /* Put at end of list to implement round-robin usage. */
 3945         TAILQ_REMOVE(&nfsrv_devidhead, ds, nfsdev_list);
 3946         TAILQ_INSERT_TAIL(&nfsrv_devidhead, ds, nfsdev_list);
 3947         NFSDDSUNLOCK();
 3948         dsc = NULL;
 3949         if (mirrorcnt > 1)
 3950                 tdsc = dsc = malloc(sizeof(*dsc) * (mirrorcnt - 1), M_TEMP,
 3951                     M_WAITOK | M_ZERO);
 3952         tpf = pf = malloc(sizeof(*pf) * nfsrv_maxpnfsmirror, M_TEMP, M_WAITOK |
 3953             M_ZERO);
 3954 
 3955         error = nfsvno_getfh(vp, &fh, p);
 3956         if (error == 0)
 3957                 error = VOP_GETATTR(vp, &va, cred);
 3958         if (error == 0) {
 3959                 /* Set the attributes for "vp" to Setattr the DS vp. */
 3960                 vauid = va.va_uid;
 3961                 vagid = va.va_gid;
 3962                 vamode = va.va_mode;
 3963                 VATTR_NULL(&va);
 3964                 va.va_uid = vauid;
 3965                 va.va_gid = vagid;
 3966                 va.va_mode = vamode;
 3967                 va.va_size = 0;
 3968         } else
 3969                 printf("pNFS: pnfscreate getfh+attr=%d\n", error);
 3970 
 3971         NFSD_DEBUG(4, "nfsrv_pnfscreate: cruid=%d crgid=%d\n", cred->cr_uid,
 3972             cred->cr_gid);
 3973         /* Make data file name based on FH. */
 3974         tcred = newnfs_getcred();
 3975 
 3976         /*
 3977          * Create the file on each DS mirror, using kernel process(es) for the
 3978          * additional mirrors.
 3979          */
 3980         failpos = -1;
 3981         for (i = 0; i < mirrorcnt - 1 && error == 0; i++, tpf++, tdsc++) {
 3982                 tpf->dsf_dir = dsdir[i];
 3983                 tdsc->tcred = tcred;
 3984                 tdsc->p = p;
 3985                 tdsc->pf = tpf;
 3986                 tdsc->createva = *vap;
 3987                 NFSBCOPY(&fh, &tdsc->fh, sizeof(fh));
 3988                 tdsc->va = va;
 3989                 tdsc->dvp = dvp[i];
 3990                 tdsc->done = 0;
 3991                 tdsc->inprog = 0;
 3992                 tdsc->err = 0;
 3993                 ret = EIO;
 3994                 if (nfs_pnfsiothreads != 0) {
 3995                         ret = nfs_pnfsio(start_dscreate, tdsc);
 3996                         NFSD_DEBUG(4, "nfsrv_pnfscreate: nfs_pnfsio=%d\n", ret);
 3997                 }
 3998                 if (ret != 0) {
 3999                         ret = nfsrv_dscreate(dvp[i], vap, &va, &fh, tpf, NULL,
 4000                             NULL, tcred, p, NULL);
 4001                         if (ret != 0) {
 4002                                 KASSERT(error == 0, ("nfsrv_dscreate err=%d",
 4003                                     error));
 4004                                 if (failpos == -1 && nfsds_failerr(ret))
 4005                                         failpos = i;
 4006                                 else
 4007                                         error = ret;
 4008                         }
 4009                 }
 4010         }
 4011         if (error == 0) {
 4012                 tpf->dsf_dir = dsdir[mirrorcnt - 1];
 4013                 error = nfsrv_dscreate(dvp[mirrorcnt - 1], vap, &va, &fh, tpf,
 4014                     &dsattr, NULL, tcred, p, NULL);
 4015                 if (failpos == -1 && mirrorcnt > 1 && nfsds_failerr(error)) {
 4016                         failpos = mirrorcnt - 1;
 4017                         error = 0;
 4018                 }
 4019         }
 4020         timo = hz / 50;         /* Wait for 20msec. */
 4021         if (timo < 1)
 4022                 timo = 1;
 4023         /* Wait for kernel task(s) to complete. */
 4024         for (tdsc = dsc, i = 0; i < mirrorcnt - 1; i++, tdsc++) {
 4025                 while (tdsc->inprog != 0 && tdsc->done == 0)
 4026                         tsleep(&tdsc->tsk, PVFS, "srvdcr", timo);
 4027                 if (tdsc->err != 0) {
 4028                         if (failpos == -1 && nfsds_failerr(tdsc->err))
 4029                                 failpos = i;
 4030                         else if (error == 0)
 4031                                 error = tdsc->err;
 4032                 }
 4033         }
 4034 
 4035         /*
 4036          * If failpos has been set, that mirror has failed, so it needs
 4037          * to be disabled.
 4038          */
 4039         if (failpos >= 0) {
 4040                 nmp = VFSTONFS(dvp[failpos]->v_mount);
 4041                 NFSLOCKMNT(nmp);
 4042                 if ((nmp->nm_privflag & (NFSMNTP_FORCEDISM |
 4043                      NFSMNTP_CANCELRPCS)) == 0) {
 4044                         nmp->nm_privflag |= NFSMNTP_CANCELRPCS;
 4045                         NFSUNLOCKMNT(nmp);
 4046                         ds = nfsrv_deldsnmp(PNFSDOP_DELDSSERVER, nmp, p);
 4047                         NFSD_DEBUG(4, "dscreatfail fail=%d ds=%p\n", failpos,
 4048                             ds);
 4049                         if (ds != NULL)
 4050                                 nfsrv_killrpcs(nmp);
 4051                         NFSLOCKMNT(nmp);
 4052                         nmp->nm_privflag &= ~NFSMNTP_CANCELRPCS;
 4053                         wakeup(nmp);
 4054                 }
 4055                 NFSUNLOCKMNT(nmp);
 4056         }
 4057 
 4058         NFSFREECRED(tcred);
 4059         if (error == 0) {
 4060                 ASSERT_VOP_ELOCKED(vp, "nfsrv_pnfscreate vp");
 4061 
 4062                 NFSD_DEBUG(4, "nfsrv_pnfscreate: mirrorcnt=%d maxmirror=%d\n",
 4063                     mirrorcnt, nfsrv_maxpnfsmirror);
 4064                 /*
 4065                  * For all mirrors that couldn't be created, fill in the
 4066                  * *pf structure, but with an IP address == 0.0.0.0.
 4067                  */
 4068                 tpf = pf + mirrorcnt;
 4069                 for (i = mirrorcnt; i < nfsrv_maxpnfsmirror; i++, tpf++) {
 4070                         *tpf = *pf;
 4071                         tpf->dsf_sin.sin_family = AF_INET;
 4072                         tpf->dsf_sin.sin_len = sizeof(struct sockaddr_in);
 4073                         tpf->dsf_sin.sin_addr.s_addr = 0;
 4074                         tpf->dsf_sin.sin_port = 0;
 4075                 }
 4076 
 4077                 error = vn_extattr_set(vp, IO_NODELOCKED,
 4078                     EXTATTR_NAMESPACE_SYSTEM, "pnfsd.dsfile",
 4079                     sizeof(*pf) * nfsrv_maxpnfsmirror, (char *)pf, p);
 4080                 if (error == 0)
 4081                         error = vn_extattr_set(vp, IO_NODELOCKED,
 4082                             EXTATTR_NAMESPACE_SYSTEM, "pnfsd.dsattr",
 4083                             sizeof(dsattr), (char *)&dsattr, p);
 4084                 if (error != 0)
 4085                         printf("pNFS: pnfscreate setextattr=%d\n",
 4086                             error);
 4087         } else
 4088                 printf("pNFS: pnfscreate=%d\n", error);
 4089         free(pf, M_TEMP);
 4090         free(dsc, M_TEMP);
 4091 }
 4092 
 4093 /*
 4094  * Get the information needed to remove the pNFS Data Server file from the
 4095  * Metadata file.  Upon success, ddvp is set non-NULL to the locked
 4096  * DS directory vnode.  The caller must unlock *ddvp when done with it.
 4097  */
 4098 static void
 4099 nfsrv_pnfsremovesetup(struct vnode *vp, NFSPROC_T *p, struct vnode **dvpp,
 4100     int *mirrorcntp, char *fname, fhandle_t *fhp)
 4101 {
 4102         struct vattr va;
 4103         struct ucred *tcred;
 4104         char *buf;
 4105         int buflen, error;
 4106 
 4107         dvpp[0] = NULL;
 4108         /* If not an exported regular file or not a pNFS server, just return. */
 4109         if (vp->v_type != VREG || (vp->v_mount->mnt_flag & MNT_EXPORTED) == 0 ||
 4110             nfsrv_devidcnt == 0)
 4111                 return;
 4112 
 4113         /* Check to see if this is the last hard link. */
 4114         tcred = newnfs_getcred();
 4115         error = VOP_GETATTR(vp, &va, tcred);
 4116         NFSFREECRED(tcred);
 4117         if (error != 0) {
 4118                 printf("pNFS: nfsrv_pnfsremovesetup getattr=%d\n", error);
 4119                 return;
 4120         }
 4121         if (va.va_nlink > 1)
 4122                 return;
 4123 
 4124         error = nfsvno_getfh(vp, fhp, p);
 4125         if (error != 0) {
 4126                 printf("pNFS: nfsrv_pnfsremovesetup getfh=%d\n", error);
 4127                 return;
 4128         }
 4129 
 4130         buflen = 1024;
 4131         buf = malloc(buflen, M_TEMP, M_WAITOK);
 4132         /* Get the directory vnode for the DS mount and the file handle. */
 4133         error = nfsrv_dsgetsockmnt(vp, 0, buf, &buflen, mirrorcntp, p, dvpp,
 4134             NULL, NULL, fname, NULL, NULL, NULL, NULL, NULL);
 4135         free(buf, M_TEMP);
 4136         if (error != 0)
 4137                 printf("pNFS: nfsrv_pnfsremovesetup getsockmnt=%d\n", error);
 4138 }
 4139 
 4140 /*
 4141  * Remove a DS data file for nfsrv_pnfsremove(). Called for each mirror.
 4142  * The arguments are in a structure, so that they can be passed through
 4143  * taskqueue for a kernel process to execute this function.
 4144  */
 4145 struct nfsrvdsremove {
 4146         int                     done;
 4147         int                     inprog;
 4148         struct task             tsk;
 4149         struct ucred            *tcred;
 4150         struct vnode            *dvp;
 4151         NFSPROC_T               *p;
 4152         int                     err;
 4153         char                    fname[PNFS_FILENAME_LEN + 1];
 4154 };
 4155 
 4156 static int
 4157 nfsrv_dsremove(struct vnode *dvp, char *fname, struct ucred *tcred,
 4158     NFSPROC_T *p)
 4159 {
 4160         struct nameidata named;
 4161         struct vnode *nvp;
 4162         char *bufp;
 4163         u_long *hashp;
 4164         int error;
 4165 
 4166         error = NFSVOPLOCK(dvp, LK_EXCLUSIVE);
 4167         if (error != 0)
 4168                 return (error);
 4169         named.ni_cnd.cn_nameiop = DELETE;
 4170         named.ni_cnd.cn_lkflags = LK_EXCLUSIVE | LK_RETRY;
 4171         named.ni_cnd.cn_cred = tcred;
 4172         named.ni_cnd.cn_thread = p;
 4173         named.ni_cnd.cn_flags = ISLASTCN | LOCKPARENT | LOCKLEAF | SAVENAME;
 4174         nfsvno_setpathbuf(&named, &bufp, &hashp);
 4175         named.ni_cnd.cn_nameptr = bufp;
 4176         named.ni_cnd.cn_namelen = strlen(fname);
 4177         strlcpy(bufp, fname, NAME_MAX);
 4178         NFSD_DEBUG(4, "nfsrv_pnfsremove: filename=%s\n", bufp);
 4179         error = VOP_LOOKUP(dvp, &nvp, &named.ni_cnd);
 4180         NFSD_DEBUG(4, "nfsrv_pnfsremove: aft LOOKUP=%d\n", error);
 4181         if (error == 0) {
 4182                 error = VOP_REMOVE(dvp, nvp, &named.ni_cnd);
 4183                 vput(nvp);
 4184         }
 4185         NFSVOPUNLOCK(dvp, 0);
 4186         nfsvno_relpathbuf(&named);
 4187         if (error != 0)
 4188                 printf("pNFS: nfsrv_pnfsremove failed=%d\n", error);
 4189         return (error);
 4190 }
 4191 
 4192 /*
 4193  * Start up the thread that will execute nfsrv_dsremove().
 4194  */
 4195 static void
 4196 start_dsremove(void *arg, int pending)
 4197 {
 4198         struct nfsrvdsremove *dsrm;
 4199 
 4200         dsrm = (struct nfsrvdsremove *)arg;
 4201         dsrm->err = nfsrv_dsremove(dsrm->dvp, dsrm->fname, dsrm->tcred,
 4202             dsrm->p);
 4203         dsrm->done = 1;
 4204         NFSD_DEBUG(4, "start_dsremove: err=%d\n", dsrm->err);
 4205 }
 4206 
 4207 /*
 4208  * Remove a pNFS data file from a Data Server.
 4209  * nfsrv_pnfsremovesetup() must have been called before the MDS file was
 4210  * removed to set up the dvp and fill in the FH.
 4211  */
 4212 static void
 4213 nfsrv_pnfsremove(struct vnode **dvp, int mirrorcnt, char *fname, fhandle_t *fhp,
 4214     NFSPROC_T *p)
 4215 {
 4216         struct ucred *tcred;
 4217         struct nfsrvdsremove *dsrm, *tdsrm;
 4218         struct nfsdevice *ds;
 4219         struct nfsmount *nmp;
 4220         int failpos, i, ret, timo;
 4221 
 4222         tcred = newnfs_getcred();
 4223         dsrm = NULL;
 4224         if (mirrorcnt > 1)
 4225                 dsrm = malloc(sizeof(*dsrm) * mirrorcnt - 1, M_TEMP, M_WAITOK);
 4226         /*
 4227          * Remove the file on each DS mirror, using kernel process(es) for the
 4228          * additional mirrors.
 4229          */
 4230         failpos = -1;
 4231         for (tdsrm = dsrm, i = 0; i < mirrorcnt - 1; i++, tdsrm++) {
 4232                 tdsrm->tcred = tcred;
 4233                 tdsrm->p = p;
 4234                 tdsrm->dvp = dvp[i];
 4235                 strlcpy(tdsrm->fname, fname, PNFS_FILENAME_LEN + 1);
 4236                 tdsrm->inprog = 0;
 4237                 tdsrm->done = 0;
 4238                 tdsrm->err = 0;
 4239                 ret = EIO;
 4240                 if (nfs_pnfsiothreads != 0) {
 4241                         ret = nfs_pnfsio(start_dsremove, tdsrm);
 4242                         NFSD_DEBUG(4, "nfsrv_pnfsremove: nfs_pnfsio=%d\n", ret);
 4243                 }
 4244                 if (ret != 0) {
 4245                         ret = nfsrv_dsremove(dvp[i], fname, tcred, p);
 4246                         if (failpos == -1 && nfsds_failerr(ret))
 4247                                 failpos = i;
 4248                 }
 4249         }
 4250         ret = nfsrv_dsremove(dvp[mirrorcnt - 1], fname, tcred, p);
 4251         if (failpos == -1 && mirrorcnt > 1 && nfsds_failerr(ret))
 4252                 failpos = mirrorcnt - 1;
 4253         timo = hz / 50;         /* Wait for 20msec. */
 4254         if (timo < 1)
 4255                 timo = 1;
 4256         /* Wait for kernel task(s) to complete. */
 4257         for (tdsrm = dsrm, i = 0; i < mirrorcnt - 1; i++, tdsrm++) {
 4258                 while (tdsrm->inprog != 0 && tdsrm->done == 0)
 4259                         tsleep(&tdsrm->tsk, PVFS, "srvdsrm", timo);
 4260                 if (failpos == -1 && nfsds_failerr(tdsrm->err))
 4261                         failpos = i;
 4262         }
 4263 
 4264         /*
 4265          * If failpos has been set, that mirror has failed, so it needs
 4266          * to be disabled.
 4267          */
 4268         if (failpos >= 0) {
 4269                 nmp = VFSTONFS(dvp[failpos]->v_mount);
 4270                 NFSLOCKMNT(nmp);
 4271                 if ((nmp->nm_privflag & (NFSMNTP_FORCEDISM |
 4272                      NFSMNTP_CANCELRPCS)) == 0) {
 4273                         nmp->nm_privflag |= NFSMNTP_CANCELRPCS;
 4274                         NFSUNLOCKMNT(nmp);
 4275                         ds = nfsrv_deldsnmp(PNFSDOP_DELDSSERVER, nmp, p);
 4276                         NFSD_DEBUG(4, "dsremovefail fail=%d ds=%p\n", failpos,
 4277                             ds);
 4278                         if (ds != NULL)
 4279                                 nfsrv_killrpcs(nmp);
 4280                         NFSLOCKMNT(nmp);
 4281                         nmp->nm_privflag &= ~NFSMNTP_CANCELRPCS;
 4282                         wakeup(nmp);
 4283                 }
 4284                 NFSUNLOCKMNT(nmp);
 4285         }
 4286 
 4287         /* Get rid all layouts for the file. */
 4288         nfsrv_freefilelayouts(fhp);
 4289 
 4290         NFSFREECRED(tcred);
 4291         free(dsrm, M_TEMP);
 4292 }
 4293 
 4294 /*
 4295  * Generate a file name based on the file handle and put it in *bufp.
 4296  * Return the number of bytes generated.
 4297  */
 4298 static int
 4299 nfsrv_putfhname(fhandle_t *fhp, char *bufp)
 4300 {
 4301         int i;
 4302         uint8_t *cp;
 4303         const uint8_t *hexdigits = "0123456789abcdef";
 4304 
 4305         cp = (uint8_t *)fhp;
 4306         for (i = 0; i < sizeof(*fhp); i++) {
 4307                 bufp[2 * i] = hexdigits[(*cp >> 4) & 0xf];
 4308                 bufp[2 * i + 1] = hexdigits[*cp++ & 0xf];
 4309         }
 4310         bufp[2 * i] = '\0';
 4311         return (2 * i);
 4312 }
 4313 
 4314 /*
 4315  * Update the Metadata file's attributes from the DS file when a Read/Write
 4316  * layout is returned.
 4317  * Basically just call nfsrv_proxyds() with procedure == NFSPROC_LAYOUTRETURN
 4318  * so that it does a nfsrv_getattrdsrpc() and nfsrv_setextattr() on the DS file.
 4319  */
 4320 int
 4321 nfsrv_updatemdsattr(struct vnode *vp, struct nfsvattr *nap, NFSPROC_T *p)
 4322 {
 4323         struct ucred *tcred;
 4324         int error;
 4325 
 4326         /* Do this as root so that it won't fail with EACCES. */
 4327         tcred = newnfs_getcred();
 4328         error = nfsrv_proxyds(NULL, vp, 0, 0, tcred, p, NFSPROC_LAYOUTRETURN,
 4329             NULL, NULL, NULL, nap, NULL);
 4330         NFSFREECRED(tcred);
 4331         return (error);
 4332 }
 4333 
 4334 /*
 4335  * Set the NFSv4 ACL on the DS file to the same ACL as the MDS file.
 4336  */
 4337 static int
 4338 nfsrv_dssetacl(struct vnode *vp, struct acl *aclp, struct ucred *cred,
 4339     NFSPROC_T *p)
 4340 {
 4341         int error;
 4342 
 4343         error = nfsrv_proxyds(NULL, vp, 0, 0, cred, p, NFSPROC_SETACL,
 4344             NULL, NULL, NULL, NULL, aclp);
 4345         return (error);
 4346 }
 4347 
 4348 static int
 4349 nfsrv_proxyds(struct nfsrv_descript *nd, struct vnode *vp, off_t off, int cnt,
 4350     struct ucred *cred, struct thread *p, int ioproc, struct mbuf **mpp,
 4351     char *cp, struct mbuf **mpp2, struct nfsvattr *nap, struct acl *aclp)
 4352 {
 4353         struct nfsmount *nmp[NFSDEV_MAXMIRRORS], *failnmp;
 4354         fhandle_t fh[NFSDEV_MAXMIRRORS];
 4355         struct vnode *dvp[NFSDEV_MAXMIRRORS];
 4356         struct nfsdevice *ds;
 4357         struct pnfsdsattr dsattr;
 4358         char *buf;
 4359         int buflen, error, failpos, i, mirrorcnt, origmircnt, trycnt;
 4360 
 4361         NFSD_DEBUG(4, "in nfsrv_proxyds\n");
 4362         /*
 4363          * If not a regular file, not exported or not a pNFS server,
 4364          * just return ENOENT.
 4365          */
 4366         if (vp->v_type != VREG || (vp->v_mount->mnt_flag & MNT_EXPORTED) == 0 ||
 4367             nfsrv_devidcnt == 0)
 4368                 return (ENOENT);
 4369 
 4370         buflen = 1024;
 4371         buf = malloc(buflen, M_TEMP, M_WAITOK);
 4372         error = 0;
 4373 
 4374         /*
 4375          * For Getattr, get the Change attribute (va_filerev) and size (va_size)
 4376          * from the MetaData file's extended attribute.
 4377          */
 4378         if (ioproc == NFSPROC_GETATTR) {
 4379                 error = vn_extattr_get(vp, IO_NODELOCKED,
 4380                     EXTATTR_NAMESPACE_SYSTEM, "pnfsd.dsattr", &buflen, buf,
 4381                     p);
 4382                 if (error == 0 && buflen != sizeof(dsattr))
 4383                         error = ENXIO;
 4384                 if (error == 0) {
 4385                         NFSBCOPY(buf, &dsattr, buflen);
 4386                         nap->na_filerev = dsattr.dsa_filerev;
 4387                         nap->na_size = dsattr.dsa_size;
 4388                         nap->na_atime = dsattr.dsa_atime;
 4389                         nap->na_mtime = dsattr.dsa_mtime;
 4390 
 4391                         /*
 4392                          * If nfsrv_pnfsgetdsattr is 0 or nfsrv_checkdsattr()
 4393                          * returns 0, just return now.  nfsrv_checkdsattr()
 4394                          * returns 0 if there is no Read/Write layout
 4395                          * plus either an Open/Write_access or Write
 4396                          * delegation issued to a client for the file.
 4397                          */
 4398                         if (nfsrv_pnfsgetdsattr == 0 ||
 4399                             nfsrv_checkdsattr(nd, vp, p) == 0) {
 4400                                 free(buf, M_TEMP);
 4401                                 return (error);
 4402                         }
 4403                 }
 4404 
 4405                 /*
 4406                  * Clear ENOATTR so the code below will attempt to do a
 4407                  * nfsrv_getattrdsrpc() to get the attributes and (re)create
 4408                  * the extended attribute.
 4409                  */
 4410                 if (error == ENOATTR)
 4411                         error = 0;
 4412         }
 4413 
 4414         origmircnt = -1;
 4415         trycnt = 0;
 4416 tryagain:
 4417         if (error == 0) {
 4418                 buflen = 1024;
 4419                 if (ioproc == NFSPROC_READDS && NFSVOPISLOCKED(vp) ==
 4420                     LK_EXCLUSIVE)
 4421                         printf("nfsrv_proxyds: Readds vp exclusively locked\n");
 4422                 error = nfsrv_dsgetsockmnt(vp, LK_SHARED, buf, &buflen,
 4423                     &mirrorcnt, p, dvp, fh, NULL, NULL, NULL, NULL, NULL,
 4424                     NULL, NULL);
 4425                 if (error == 0) {
 4426                         for (i = 0; i < mirrorcnt; i++)
 4427                                 nmp[i] = VFSTONFS(dvp[i]->v_mount);
 4428                 } else
 4429                         printf("pNFS: proxy getextattr sockaddr=%d\n", error);
 4430         } else
 4431                 printf("pNFS: nfsrv_dsgetsockmnt=%d\n", error);
 4432         if (error == 0) {
 4433                 failpos = -1;
 4434                 if (origmircnt == -1)
 4435                         origmircnt = mirrorcnt;
 4436                 /*
 4437                  * If failpos is set to a mirror#, then that mirror has
 4438                  * failed and will be disabled. For Read and Getattr, the
 4439                  * function only tries one mirror, so if that mirror has
 4440                  * failed, it will need to be retried. As such, increment
 4441                  * tryitagain for these cases.
 4442                  * For Write, Setattr and Setacl, the function tries all
 4443                  * mirrors and will not return an error for the case where
 4444                  * one mirror has failed. For these cases, the functioning
 4445                  * mirror(s) will have been modified, so a retry isn't
 4446                  * necessary. These functions will set failpos for the
 4447                  * failed mirror#.
 4448                  */
 4449                 if (ioproc == NFSPROC_READDS) {
 4450                         error = nfsrv_readdsrpc(fh, off, cnt, cred, p, nmp[0],
 4451                             mpp, mpp2);
 4452                         if (nfsds_failerr(error) && mirrorcnt > 1) {
 4453                                 /*
 4454                                  * Setting failpos will cause the mirror
 4455                                  * to be disabled and then a retry of this
 4456                                  * read is required.
 4457                                  */
 4458                                 failpos = 0;
 4459                                 error = 0;
 4460                                 trycnt++;
 4461                         }
 4462                 } else if (ioproc == NFSPROC_WRITEDS)
 4463                         error = nfsrv_writedsrpc(fh, off, cnt, cred, p, vp,
 4464                             &nmp[0], mirrorcnt, mpp, cp, &failpos);
 4465                 else if (ioproc == NFSPROC_SETATTR)
 4466                         error = nfsrv_setattrdsrpc(fh, cred, p, vp, &nmp[0],
 4467                             mirrorcnt, nap, &failpos);
 4468                 else if (ioproc == NFSPROC_SETACL)
 4469                         error = nfsrv_setacldsrpc(fh, cred, p, vp, &nmp[0],
 4470                             mirrorcnt, aclp, &failpos);
 4471                 else {
 4472                         error = nfsrv_getattrdsrpc(&fh[mirrorcnt - 1], cred, p,
 4473                             vp, nmp[mirrorcnt - 1], nap);
 4474                         if (nfsds_failerr(error) && mirrorcnt > 1) {
 4475                                 /*
 4476                                  * Setting failpos will cause the mirror
 4477                                  * to be disabled and then a retry of this
 4478                                  * getattr is required.
 4479                                  */
 4480                                 failpos = mirrorcnt - 1;
 4481                                 error = 0;
 4482                                 trycnt++;
 4483                         }
 4484                 }
 4485                 ds = NULL;
 4486                 if (failpos >= 0) {
 4487                         failnmp = nmp[failpos];
 4488                         NFSLOCKMNT(failnmp);
 4489                         if ((failnmp->nm_privflag & (NFSMNTP_FORCEDISM |
 4490                              NFSMNTP_CANCELRPCS)) == 0) {
 4491                                 failnmp->nm_privflag |= NFSMNTP_CANCELRPCS;
 4492                                 NFSUNLOCKMNT(failnmp);
 4493                                 ds = nfsrv_deldsnmp(PNFSDOP_DELDSSERVER,
 4494                                     failnmp, p);
 4495                                 NFSD_DEBUG(4, "dsldsnmp fail=%d ds=%p\n",
 4496                                     failpos, ds);
 4497                                 if (ds != NULL)
 4498                                         nfsrv_killrpcs(failnmp);
 4499                                 NFSLOCKMNT(failnmp);
 4500                                 failnmp->nm_privflag &= ~NFSMNTP_CANCELRPCS;
 4501                                 wakeup(failnmp);
 4502                         }
 4503                         NFSUNLOCKMNT(failnmp);
 4504                 }
 4505                 for (i = 0; i < mirrorcnt; i++)
 4506                         NFSVOPUNLOCK(dvp[i], 0);
 4507                 NFSD_DEBUG(4, "nfsrv_proxyds: aft RPC=%d trya=%d\n", error,
 4508                     trycnt);
 4509                 /* Try the Read/Getattr again if a mirror was deleted. */
 4510                 if (ds != NULL && trycnt > 0 && trycnt < origmircnt)
 4511                         goto tryagain;
 4512         } else {
 4513                 /* Return ENOENT for any Extended Attribute error. */
 4514                 error = ENOENT;
 4515         }
 4516         free(buf, M_TEMP);
 4517         NFSD_DEBUG(4, "nfsrv_proxyds: error=%d\n", error);
 4518         return (error);
 4519 }
 4520 
 4521 /*
 4522  * Get the DS mount point, fh and directory from the "pnfsd.dsfile" extended
 4523  * attribute.
 4524  * newnmpp - If it points to a non-NULL nmp, that is the destination and needs
 4525  *           to be checked.  If it points to a NULL nmp, then it returns
 4526  *           a suitable destination.
 4527  * curnmp - If non-NULL, it is the source mount for the copy.
 4528  */
 4529 int
 4530 nfsrv_dsgetsockmnt(struct vnode *vp, int lktype, char *buf, int *buflenp,
 4531     int *mirrorcntp, NFSPROC_T *p, struct vnode **dvpp, fhandle_t *fhp,
 4532     char *devid, char *fnamep, struct vnode **nvpp, struct nfsmount **newnmpp,
 4533     struct nfsmount *curnmp, int *ippos, int *dsdirp)
 4534 {
 4535         struct vnode *dvp, *nvp, **tdvpp;
 4536         struct mount *mp;
 4537         struct nfsmount *nmp, *newnmp;
 4538         struct sockaddr *sad;
 4539         struct sockaddr_in *sin;
 4540         struct nfsdevice *ds, *tds, *fndds;
 4541         struct pnfsdsfile *pf;
 4542         uint32_t dsdir;
 4543         int error, fhiszero, fnd, gotone, i, mirrorcnt;
 4544 
 4545         ASSERT_VOP_LOCKED(vp, "nfsrv_dsgetsockmnt vp");
 4546         *mirrorcntp = 1;
 4547         tdvpp = dvpp;
 4548         if (nvpp != NULL)
 4549                 *nvpp = NULL;
 4550         if (dvpp != NULL)
 4551                 *dvpp = NULL;
 4552         if (ippos != NULL)
 4553                 *ippos = -1;
 4554         if (newnmpp != NULL)
 4555                 newnmp = *newnmpp;
 4556         else
 4557                 newnmp = NULL;
 4558         mp = vp->v_mount;
 4559         error = vn_extattr_get(vp, IO_NODELOCKED, EXTATTR_NAMESPACE_SYSTEM,
 4560             "pnfsd.dsfile", buflenp, buf, p);
 4561         mirrorcnt = *buflenp / sizeof(*pf);
 4562         if (error == 0 && (mirrorcnt < 1 || mirrorcnt > NFSDEV_MAXMIRRORS ||
 4563             *buflenp != sizeof(*pf) * mirrorcnt))
 4564                 error = ENOATTR;
 4565 
 4566         pf = (struct pnfsdsfile *)buf;
 4567         /* If curnmp != NULL, check for a match in the mirror list. */
 4568         if (curnmp != NULL && error == 0) {
 4569                 fnd = 0;
 4570                 for (i = 0; i < mirrorcnt; i++, pf++) {
 4571                         sad = (struct sockaddr *)&pf->dsf_sin;
 4572                         if (nfsaddr2_match(sad, curnmp->nm_nam)) {
 4573                                 if (ippos != NULL)
 4574                                         *ippos = i;
 4575                                 fnd = 1;
 4576                                 break;
 4577                         }
 4578                 }
 4579                 if (fnd == 0)
 4580                         error = ENXIO;
 4581         }
 4582 
 4583         gotone = 0;
 4584         pf = (struct pnfsdsfile *)buf;
 4585         NFSD_DEBUG(4, "nfsrv_dsgetsockmnt: mirrorcnt=%d err=%d\n", mirrorcnt,
 4586             error);
 4587         for (i = 0; i < mirrorcnt && error == 0; i++, pf++) {
 4588                 fhiszero = 0;
 4589                 sad = (struct sockaddr *)&pf->dsf_sin;
 4590                 sin = &pf->dsf_sin;
 4591                 dsdir = pf->dsf_dir;
 4592                 if (dsdir >= nfsrv_dsdirsize) {
 4593                         printf("nfsrv_dsgetsockmnt: dsdir=%d\n", dsdir);
 4594                         error = ENOATTR;
 4595                 } else if (nvpp != NULL && newnmp != NULL &&
 4596                     nfsaddr2_match(sad, newnmp->nm_nam))
 4597                         error = EEXIST;
 4598                 if (error == 0) {
 4599                         if (ippos != NULL && curnmp == NULL &&
 4600                             sad->sa_family == AF_INET &&
 4601                             sin->sin_addr.s_addr == 0)
 4602                                 *ippos = i;
 4603                         if (NFSBCMP(&zerofh, &pf->dsf_fh, sizeof(zerofh)) == 0)
 4604                                 fhiszero = 1;
 4605                         /* Use the socket address to find the mount point. */
 4606                         fndds = NULL;
 4607                         NFSDDSLOCK();
 4608                         /* Find a match for the IP address. */
 4609                         TAILQ_FOREACH(ds, &nfsrv_devidhead, nfsdev_list) {
 4610                                 if (ds->nfsdev_nmp != NULL) {
 4611                                         dvp = ds->nfsdev_dvp;
 4612                                         nmp = VFSTONFS(dvp->v_mount);
 4613                                         if (nmp != ds->nfsdev_nmp)
 4614                                                 printf("different2 nmp %p %p\n",
 4615                                                     nmp, ds->nfsdev_nmp);
 4616                                         if (nfsaddr2_match(sad, nmp->nm_nam)) {
 4617                                                 fndds = ds;
 4618                                                 break;
 4619                                         }
 4620                                 }
 4621                         }
 4622                         if (fndds != NULL && newnmpp != NULL &&
 4623                             newnmp == NULL) {
 4624                                 /* Search for a place to make a mirror copy. */
 4625                                 TAILQ_FOREACH(tds, &nfsrv_devidhead,
 4626                                     nfsdev_list) {
 4627                                         if (tds->nfsdev_nmp != NULL &&
 4628                                             fndds != tds &&
 4629                                             ((tds->nfsdev_mdsisset == 0 &&
 4630                                               fndds->nfsdev_mdsisset == 0) ||
 4631                                              (tds->nfsdev_mdsisset != 0 &&
 4632                                               fndds->nfsdev_mdsisset != 0 &&
 4633                                               tds->nfsdev_mdsfsid.val[0] ==
 4634                                               mp->mnt_stat.f_fsid.val[0] &&
 4635                                               tds->nfsdev_mdsfsid.val[1] ==
 4636                                               mp->mnt_stat.f_fsid.val[1]))) {
 4637                                                 *newnmpp = tds->nfsdev_nmp;
 4638                                                 break;
 4639                                         }
 4640                                 }
 4641                                 if (tds != NULL) {
 4642                                         /*
 4643                                          * Move this entry to the end of the
 4644                                          * list, so it won't be selected as
 4645                                          * easily the next time.
 4646                                          */
 4647                                         TAILQ_REMOVE(&nfsrv_devidhead, tds,
 4648                                             nfsdev_list);
 4649                                         TAILQ_INSERT_TAIL(&nfsrv_devidhead, tds,
 4650                                             nfsdev_list);
 4651                                 }
 4652                         }
 4653                         NFSDDSUNLOCK();
 4654                         if (fndds != NULL) {
 4655                                 dvp = fndds->nfsdev_dsdir[dsdir];
 4656                                 if (lktype != 0 || fhiszero != 0 ||
 4657                                     (nvpp != NULL && *nvpp == NULL)) {
 4658                                         if (fhiszero != 0)
 4659                                                 error = vn_lock(dvp,
 4660                                                     LK_EXCLUSIVE);
 4661                                         else if (lktype != 0)
 4662                                                 error = vn_lock(dvp, lktype);
 4663                                         else
 4664                                                 error = vn_lock(dvp, LK_SHARED);
 4665                                         /*
 4666                                          * If the file handle is all 0's, try to
 4667                                          * do a Lookup against the DS to acquire
 4668                                          * it.
 4669                                          * If dvpp == NULL or the Lookup fails,
 4670                                          * unlock dvp after the call.
 4671                                          */
 4672                                         if (error == 0 && (fhiszero != 0 ||
 4673                                             (nvpp != NULL && *nvpp == NULL))) {
 4674                                                 error = nfsrv_pnfslookupds(vp,
 4675                                                     dvp, pf, &nvp, p);
 4676                                                 if (error == 0) {
 4677                                                         if (fhiszero != 0)
 4678                                                                 nfsrv_pnfssetfh(
 4679                                                                     vp, pf,
 4680                                                                     devid,
 4681                                                                     fnamep,
 4682                                                                     nvp, p);
 4683                                                         if (nvpp != NULL &&
 4684                                                             *nvpp == NULL) {
 4685                                                                 *nvpp = nvp;
 4686                                                                 *dsdirp = dsdir;
 4687                                                         } else
 4688                                                                 vput(nvp);
 4689                                                 }
 4690                                                 if (error != 0 || lktype == 0)
 4691                                                         NFSVOPUNLOCK(dvp, 0);
 4692                                         }
 4693                                 }
 4694                                 if (error == 0) {
 4695                                         gotone++;
 4696                                         NFSD_DEBUG(4, "gotone=%d\n", gotone);
 4697                                         if (devid != NULL) {
 4698                                                 NFSBCOPY(fndds->nfsdev_deviceid,
 4699                                                     devid, NFSX_V4DEVICEID);
 4700                                                 devid += NFSX_V4DEVICEID;
 4701                                         }
 4702                                         if (dvpp != NULL)
 4703                                                 *tdvpp++ = dvp;
 4704                                         if (fhp != NULL)
 4705                                                 NFSBCOPY(&pf->dsf_fh, fhp++,
 4706                                                     NFSX_MYFH);
 4707                                         if (fnamep != NULL && gotone == 1)
 4708                                                 strlcpy(fnamep,
 4709                                                     pf->dsf_filename,
 4710                                                     sizeof(pf->dsf_filename));
 4711                                 } else
 4712                                         NFSD_DEBUG(4, "nfsrv_dsgetsockmnt "
 4713                                             "err=%d\n", error);
 4714                         }
 4715                 }
 4716         }
 4717         if (error == 0 && gotone == 0)
 4718                 error = ENOENT;
 4719 
 4720         NFSD_DEBUG(4, "eo nfsrv_dsgetsockmnt: gotone=%d err=%d\n", gotone,
 4721             error);
 4722         if (error == 0)
 4723                 *mirrorcntp = gotone;
 4724         else {
 4725                 if (gotone > 0 && dvpp != NULL) {
 4726                         /*
 4727                          * If the error didn't occur on the first one and
 4728                          * dvpp != NULL, the one(s) prior to the failure will
 4729                          * have locked dvp's that need to be unlocked.
 4730                          */
 4731                         for (i = 0; i < gotone; i++) {
 4732                                 NFSVOPUNLOCK(*dvpp, 0);
 4733                                 *dvpp++ = NULL;
 4734                         }
 4735                 }
 4736                 /*
 4737                  * If it found the vnode to be copied from before a failure,
 4738                  * it needs to be vput()'d.
 4739                  */
 4740                 if (nvpp != NULL && *nvpp != NULL) {
 4741                         vput(*nvpp);
 4742                         *nvpp = NULL;
 4743                 }
 4744         }
 4745         return (error);
 4746 }
 4747 
 4748 /*
 4749  * Set the extended attribute for the Change attribute.
 4750  */
 4751 static int
 4752 nfsrv_setextattr(struct vnode *vp, struct nfsvattr *nap, NFSPROC_T *p)
 4753 {
 4754         struct pnfsdsattr dsattr;
 4755         int error;
 4756 
 4757         ASSERT_VOP_ELOCKED(vp, "nfsrv_setextattr vp");
 4758         dsattr.dsa_filerev = nap->na_filerev;
 4759         dsattr.dsa_size = nap->na_size;
 4760         dsattr.dsa_atime = nap->na_atime;
 4761         dsattr.dsa_mtime = nap->na_mtime;
 4762         error = vn_extattr_set(vp, IO_NODELOCKED, EXTATTR_NAMESPACE_SYSTEM,
 4763             "pnfsd.dsattr", sizeof(dsattr), (char *)&dsattr, p);
 4764         if (error != 0)
 4765                 printf("pNFS: setextattr=%d\n", error);
 4766         return (error);
 4767 }
 4768 
 4769 static int
 4770 nfsrv_readdsrpc(fhandle_t *fhp, off_t off, int len, struct ucred *cred,
 4771     NFSPROC_T *p, struct nfsmount *nmp, struct mbuf **mpp, struct mbuf **mpendp)
 4772 {
 4773         uint32_t *tl;
 4774         struct nfsrv_descript *nd;
 4775         nfsv4stateid_t st;
 4776         struct mbuf *m, *m2;
 4777         int error = 0, retlen, tlen, trimlen;
 4778 
 4779         NFSD_DEBUG(4, "in nfsrv_readdsrpc\n");
 4780         nd = malloc(sizeof(*nd), M_TEMP, M_WAITOK | M_ZERO);
 4781         *mpp = NULL;
 4782         /*
 4783          * Use a stateid where other is an alternating 01010 pattern and
 4784          * seqid is 0xffffffff.  This value is not defined as special by
 4785          * the RFC and is used by the FreeBSD NFS server to indicate an
 4786          * MDS->DS proxy operation.
 4787          */
 4788         st.other[0] = 0x55555555;
 4789         st.other[1] = 0x55555555;
 4790         st.other[2] = 0x55555555;
 4791         st.seqid = 0xffffffff;
 4792         nfscl_reqstart(nd, NFSPROC_READDS, nmp, (u_int8_t *)fhp, sizeof(*fhp),
 4793             NULL, NULL, 0, 0);
 4794         nfsm_stateidtom(nd, &st, NFSSTATEID_PUTSTATEID);
 4795         NFSM_BUILD(tl, uint32_t *, NFSX_UNSIGNED * 3);
 4796         txdr_hyper(off, tl);
 4797         *(tl + 2) = txdr_unsigned(len);
 4798         error = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, NULL, p, cred,
 4799             NFS_PROG, NFS_VER4, NULL, 1, NULL, NULL);
 4800         if (error != 0) {
 4801                 free(nd, M_TEMP);
 4802                 return (error);
 4803         }
 4804         if (nd->nd_repstat == 0) {
 4805                 NFSM_DISSECT(tl, u_int32_t *, NFSX_UNSIGNED);
 4806                 NFSM_STRSIZ(retlen, len);
 4807                 if (retlen > 0) {
 4808                         /* Trim off the pre-data XDR from the mbuf chain. */
 4809                         m = nd->nd_mrep;
 4810                         while (m != NULL && m != nd->nd_md) {
 4811                                 if (m->m_next == nd->nd_md) {
 4812                                         m->m_next = NULL;
 4813                                         m_freem(nd->nd_mrep);
 4814                                         nd->nd_mrep = m = nd->nd_md;
 4815                                 } else
 4816                                         m = m->m_next;
 4817                         }
 4818                         if (m == NULL) {
 4819                                 printf("nfsrv_readdsrpc: busted mbuf list\n");
 4820                                 error = ENOENT;
 4821                                 goto nfsmout;
 4822                         }
 4823         
 4824                         /*
 4825                          * Now, adjust first mbuf so that any XDR before the
 4826                          * read data is skipped over.
 4827                          */
 4828                         trimlen = nd->nd_dpos - mtod(m, char *);
 4829                         if (trimlen > 0) {
 4830                                 m->m_len -= trimlen;
 4831                                 NFSM_DATAP(m, trimlen);
 4832                         }
 4833         
 4834                         /*
 4835                          * Truncate the mbuf chain at retlen bytes of data,
 4836                          * plus XDR padding that brings the length up to a
 4837                          * multiple of 4.
 4838                          */
 4839                         tlen = NFSM_RNDUP(retlen);
 4840                         do {
 4841                                 if (m->m_len >= tlen) {
 4842                                         m->m_len = tlen;
 4843                                         tlen = 0;
 4844                                         m2 = m->m_next;
 4845                                         m->m_next = NULL;
 4846                                         m_freem(m2);
 4847                                         break;
 4848                                 }
 4849                                 tlen -= m->m_len;
 4850                                 m = m->m_next;
 4851                         } while (m != NULL);
 4852                         if (tlen > 0) {
 4853                                 printf("nfsrv_readdsrpc: busted mbuf list\n");
 4854                                 error = ENOENT;
 4855                                 goto nfsmout;
 4856                         }
 4857                         *mpp = nd->nd_mrep;
 4858                         *mpendp = m;
 4859                         nd->nd_mrep = NULL;
 4860                 }
 4861         } else
 4862                 error = nd->nd_repstat;
 4863 nfsmout:
 4864         /* If nd->nd_mrep is already NULL, this is a no-op. */
 4865         m_freem(nd->nd_mrep);
 4866         free(nd, M_TEMP);
 4867         NFSD_DEBUG(4, "nfsrv_readdsrpc error=%d\n", error);
 4868         return (error);
 4869 }
 4870 
 4871 /*
 4872  * Do a write RPC on a DS data file, using this structure for the arguments,
 4873  * so that this function can be executed by a separate kernel process.
 4874  */
 4875 struct nfsrvwritedsdorpc {
 4876         int                     done;
 4877         int                     inprog;
 4878         struct task             tsk;
 4879         fhandle_t               fh;
 4880         off_t                   off;
 4881         int                     len;
 4882         struct nfsmount         *nmp;
 4883         struct ucred            *cred;
 4884         NFSPROC_T               *p;
 4885         struct mbuf             *m;
 4886         int                     err;
 4887 };
 4888 
 4889 static int
 4890 nfsrv_writedsdorpc(struct nfsmount *nmp, fhandle_t *fhp, off_t off, int len,
 4891     struct nfsvattr *nap, struct mbuf *m, struct ucred *cred, NFSPROC_T *p)
 4892 {
 4893         uint32_t *tl;
 4894         struct nfsrv_descript *nd;
 4895         nfsattrbit_t attrbits;
 4896         nfsv4stateid_t st;
 4897         int commit, error, retlen;
 4898 
 4899         nd = malloc(sizeof(*nd), M_TEMP, M_WAITOK | M_ZERO);
 4900         nfscl_reqstart(nd, NFSPROC_WRITE, nmp, (u_int8_t *)fhp,
 4901             sizeof(fhandle_t), NULL, NULL, 0, 0);
 4902 
 4903         /*
 4904          * Use a stateid where other is an alternating 01010 pattern and
 4905          * seqid is 0xffffffff.  This value is not defined as special by
 4906          * the RFC and is used by the FreeBSD NFS server to indicate an
 4907          * MDS->DS proxy operation.
 4908          */
 4909         st.other[0] = 0x55555555;
 4910         st.other[1] = 0x55555555;
 4911         st.other[2] = 0x55555555;
 4912         st.seqid = 0xffffffff;
 4913         nfsm_stateidtom(nd, &st, NFSSTATEID_PUTSTATEID);
 4914         NFSM_BUILD(tl, u_int32_t *, NFSX_HYPER + 2 * NFSX_UNSIGNED);
 4915         txdr_hyper(off, tl);
 4916         tl += 2;
 4917         /*
 4918          * Do all writes FileSync, since the server doesn't hold onto dirty
 4919          * buffers.  Since clients should be accessing the DS servers directly
 4920          * using the pNFS layouts, this just needs to work correctly as a
 4921          * fallback.
 4922          */
 4923         *tl++ = txdr_unsigned(NFSWRITE_FILESYNC);
 4924         *tl = txdr_unsigned(len);
 4925         NFSD_DEBUG(4, "nfsrv_writedsdorpc: len=%d\n", len);
 4926 
 4927         /* Put data in mbuf chain. */
 4928         nd->nd_mb->m_next = m;
 4929 
 4930         /* Set nd_mb and nd_bpos to end of data. */
 4931         while (m->m_next != NULL)
 4932                 m = m->m_next;
 4933         nd->nd_mb = m;
 4934         nd->nd_bpos = mtod(m, char *) + m->m_len;
 4935         NFSD_DEBUG(4, "nfsrv_writedsdorpc: lastmb len=%d\n", m->m_len);
 4936 
 4937         /* Do a Getattr for Size, Change and Modify Time. */
 4938         NFSZERO_ATTRBIT(&attrbits);
 4939         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_SIZE);
 4940         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_CHANGE);
 4941         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEACCESS);
 4942         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEMODIFY);
 4943         NFSM_BUILD(tl, u_int32_t *, NFSX_UNSIGNED);
 4944         *tl = txdr_unsigned(NFSV4OP_GETATTR);
 4945         (void) nfsrv_putattrbit(nd, &attrbits);
 4946         error = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, NULL, p,
 4947             cred, NFS_PROG, NFS_VER4, NULL, 1, NULL, NULL);
 4948         if (error != 0) {
 4949                 free(nd, M_TEMP);
 4950                 return (error);
 4951         }
 4952         NFSD_DEBUG(4, "nfsrv_writedsdorpc: aft writerpc=%d\n", nd->nd_repstat);
 4953         /* Get rid of weak cache consistency data for now. */
 4954         if ((nd->nd_flag & (ND_NOMOREDATA | ND_NFSV4 | ND_V4WCCATTR)) ==
 4955             (ND_NFSV4 | ND_V4WCCATTR)) {
 4956                 error = nfsv4_loadattr(nd, NULL, nap, NULL, NULL, 0, NULL, NULL,
 4957                     NULL, NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL);
 4958                 NFSD_DEBUG(4, "nfsrv_writedsdorpc: wcc attr=%d\n", error);
 4959                 if (error != 0)
 4960                         goto nfsmout;
 4961                 /*
 4962                  * Get rid of Op# and status for next op.
 4963                  */
 4964                 NFSM_DISSECT(tl, uint32_t *, 2 * NFSX_UNSIGNED);
 4965                 if (*++tl != 0)
 4966                         nd->nd_flag |= ND_NOMOREDATA;
 4967         }
 4968         if (nd->nd_repstat == 0) {
 4969                 NFSM_DISSECT(tl, uint32_t *, 2 * NFSX_UNSIGNED + NFSX_VERF);
 4970                 retlen = fxdr_unsigned(int, *tl++);
 4971                 commit = fxdr_unsigned(int, *tl);
 4972                 if (commit != NFSWRITE_FILESYNC)
 4973                         error = NFSERR_IO;
 4974                 NFSD_DEBUG(4, "nfsrv_writedsdorpc:retlen=%d commit=%d err=%d\n",
 4975                     retlen, commit, error);
 4976         } else
 4977                 error = nd->nd_repstat;
 4978         /* We have no use for the Write Verifier since we use FileSync. */
 4979 
 4980         /*
 4981          * Get the Change, Size, Access Time and Modify Time attributes and set
 4982          * on the Metadata file, so its attributes will be what the file's
 4983          * would be if it had been written.
 4984          */
 4985         if (error == 0) {
 4986                 NFSM_DISSECT(tl, uint32_t *, 2 * NFSX_UNSIGNED);
 4987                 error = nfsv4_loadattr(nd, NULL, nap, NULL, NULL, 0, NULL, NULL,
 4988                     NULL, NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL);
 4989         }
 4990         NFSD_DEBUG(4, "nfsrv_writedsdorpc: aft loadattr=%d\n", error);
 4991 nfsmout:
 4992         m_freem(nd->nd_mrep);
 4993         free(nd, M_TEMP);
 4994         NFSD_DEBUG(4, "nfsrv_writedsdorpc error=%d\n", error);
 4995         return (error);
 4996 }
 4997 
 4998 /*
 4999  * Start up the thread that will execute nfsrv_writedsdorpc().
 5000  */
 5001 static void
 5002 start_writedsdorpc(void *arg, int pending)
 5003 {
 5004         struct nfsrvwritedsdorpc *drpc;
 5005 
 5006         drpc = (struct nfsrvwritedsdorpc *)arg;
 5007         drpc->err = nfsrv_writedsdorpc(drpc->nmp, &drpc->fh, drpc->off,
 5008             drpc->len, NULL, drpc->m, drpc->cred, drpc->p);
 5009         drpc->done = 1;
 5010         NFSD_DEBUG(4, "start_writedsdorpc: err=%d\n", drpc->err);
 5011 }
 5012 
 5013 static int
 5014 nfsrv_writedsrpc(fhandle_t *fhp, off_t off, int len, struct ucred *cred,
 5015     NFSPROC_T *p, struct vnode *vp, struct nfsmount **nmpp, int mirrorcnt,
 5016     struct mbuf **mpp, char *cp, int *failposp)
 5017 {
 5018         struct nfsrvwritedsdorpc *drpc, *tdrpc;
 5019         struct nfsvattr na;
 5020         struct mbuf *m;
 5021         int error, i, offs, ret, timo;
 5022 
 5023         NFSD_DEBUG(4, "in nfsrv_writedsrpc\n");
 5024         KASSERT(*mpp != NULL, ("nfsrv_writedsrpc: NULL mbuf chain"));
 5025         drpc = NULL;
 5026         if (mirrorcnt > 1)
 5027                 tdrpc = drpc = malloc(sizeof(*drpc) * (mirrorcnt - 1), M_TEMP,
 5028                     M_WAITOK);
 5029 
 5030         /* Calculate offset in mbuf chain that data starts. */
 5031         offs = cp - mtod(*mpp, char *);
 5032         NFSD_DEBUG(4, "nfsrv_writedsrpc: mcopy offs=%d len=%d\n", offs, len);
 5033 
 5034         /*
 5035          * Do the write RPC for every DS, using a separate kernel process
 5036          * for every DS except the last one.
 5037          */
 5038         error = 0;
 5039         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5040                 tdrpc->done = 0;
 5041                 NFSBCOPY(fhp, &tdrpc->fh, sizeof(*fhp));
 5042                 tdrpc->off = off;
 5043                 tdrpc->len = len;
 5044                 tdrpc->nmp = *nmpp;
 5045                 tdrpc->cred = cred;
 5046                 tdrpc->p = p;
 5047                 tdrpc->inprog = 0;
 5048                 tdrpc->err = 0;
 5049                 tdrpc->m = m_copym(*mpp, offs, NFSM_RNDUP(len), M_WAITOK);
 5050                 ret = EIO;
 5051                 if (nfs_pnfsiothreads != 0) {
 5052                         ret = nfs_pnfsio(start_writedsdorpc, tdrpc);
 5053                         NFSD_DEBUG(4, "nfsrv_writedsrpc: nfs_pnfsio=%d\n",
 5054                             ret);
 5055                 }
 5056                 if (ret != 0) {
 5057                         ret = nfsrv_writedsdorpc(*nmpp, fhp, off, len, NULL,
 5058                             tdrpc->m, cred, p);
 5059                         if (nfsds_failerr(ret) && *failposp == -1)
 5060                                 *failposp = i;
 5061                         else if (error == 0 && ret != 0)
 5062                                 error = ret;
 5063                 }
 5064                 nmpp++;
 5065                 fhp++;
 5066         }
 5067         m = m_copym(*mpp, offs, NFSM_RNDUP(len), M_WAITOK);
 5068         ret = nfsrv_writedsdorpc(*nmpp, fhp, off, len, &na, m, cred, p);
 5069         if (nfsds_failerr(ret) && *failposp == -1 && mirrorcnt > 1)
 5070                 *failposp = mirrorcnt - 1;
 5071         else if (error == 0 && ret != 0)
 5072                 error = ret;
 5073         if (error == 0)
 5074                 error = nfsrv_setextattr(vp, &na, p);
 5075         NFSD_DEBUG(4, "nfsrv_writedsrpc: aft setextat=%d\n", error);
 5076         tdrpc = drpc;
 5077         timo = hz / 50;         /* Wait for 20msec. */
 5078         if (timo < 1)
 5079                 timo = 1;
 5080         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5081                 /* Wait for RPCs on separate threads to complete. */
 5082                 while (tdrpc->inprog != 0 && tdrpc->done == 0)
 5083                         tsleep(&tdrpc->tsk, PVFS, "srvwrds", timo);
 5084                 if (nfsds_failerr(tdrpc->err) && *failposp == -1)
 5085                         *failposp = i;
 5086                 else if (error == 0 && tdrpc->err != 0)
 5087                         error = tdrpc->err;
 5088         }
 5089         free(drpc, M_TEMP);
 5090         return (error);
 5091 }
 5092 
 5093 static int
 5094 nfsrv_setattrdsdorpc(fhandle_t *fhp, struct ucred *cred, NFSPROC_T *p,
 5095     struct vnode *vp, struct nfsmount *nmp, struct nfsvattr *nap,
 5096     struct nfsvattr *dsnap)
 5097 {
 5098         uint32_t *tl;
 5099         struct nfsrv_descript *nd;
 5100         nfsv4stateid_t st;
 5101         nfsattrbit_t attrbits;
 5102         int error;
 5103 
 5104         NFSD_DEBUG(4, "in nfsrv_setattrdsdorpc\n");
 5105         nd = malloc(sizeof(*nd), M_TEMP, M_WAITOK | M_ZERO);
 5106         /*
 5107          * Use a stateid where other is an alternating 01010 pattern and
 5108          * seqid is 0xffffffff.  This value is not defined as special by
 5109          * the RFC and is used by the FreeBSD NFS server to indicate an
 5110          * MDS->DS proxy operation.
 5111          */
 5112         st.other[0] = 0x55555555;
 5113         st.other[1] = 0x55555555;
 5114         st.other[2] = 0x55555555;
 5115         st.seqid = 0xffffffff;
 5116         nfscl_reqstart(nd, NFSPROC_SETATTR, nmp, (u_int8_t *)fhp, sizeof(*fhp),
 5117             NULL, NULL, 0, 0);
 5118         nfsm_stateidtom(nd, &st, NFSSTATEID_PUTSTATEID);
 5119         nfscl_fillsattr(nd, &nap->na_vattr, vp, NFSSATTR_FULL, 0);
 5120 
 5121         /* Do a Getattr for Size, Change, Access Time and Modify Time. */
 5122         NFSZERO_ATTRBIT(&attrbits);
 5123         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_SIZE);
 5124         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_CHANGE);
 5125         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEACCESS);
 5126         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEMODIFY);
 5127         NFSM_BUILD(tl, u_int32_t *, NFSX_UNSIGNED);
 5128         *tl = txdr_unsigned(NFSV4OP_GETATTR);
 5129         (void) nfsrv_putattrbit(nd, &attrbits);
 5130         error = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, NULL, p, cred,
 5131             NFS_PROG, NFS_VER4, NULL, 1, NULL, NULL);
 5132         if (error != 0) {
 5133                 free(nd, M_TEMP);
 5134                 return (error);
 5135         }
 5136         NFSD_DEBUG(4, "nfsrv_setattrdsdorpc: aft setattrrpc=%d\n",
 5137             nd->nd_repstat);
 5138         /* Get rid of weak cache consistency data for now. */
 5139         if ((nd->nd_flag & (ND_NOMOREDATA | ND_NFSV4 | ND_V4WCCATTR)) ==
 5140             (ND_NFSV4 | ND_V4WCCATTR)) {
 5141                 error = nfsv4_loadattr(nd, NULL, dsnap, NULL, NULL, 0, NULL,
 5142                     NULL, NULL, NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL);
 5143                 NFSD_DEBUG(4, "nfsrv_setattrdsdorpc: wcc attr=%d\n", error);
 5144                 if (error != 0)
 5145                         goto nfsmout;
 5146                 /*
 5147                  * Get rid of Op# and status for next op.
 5148                  */
 5149                 NFSM_DISSECT(tl, uint32_t *, 2 * NFSX_UNSIGNED);
 5150                 if (*++tl != 0)
 5151                         nd->nd_flag |= ND_NOMOREDATA;
 5152         }
 5153         error = nfsrv_getattrbits(nd, &attrbits, NULL, NULL);
 5154         if (error != 0)
 5155                 goto nfsmout;
 5156         if (nd->nd_repstat != 0)
 5157                 error = nd->nd_repstat;
 5158         /*
 5159          * Get the Change, Size, Access Time and Modify Time attributes and set
 5160          * on the Metadata file, so its attributes will be what the file's
 5161          * would be if it had been written.
 5162          */
 5163         if (error == 0) {
 5164                 NFSM_DISSECT(tl, uint32_t *, 2 * NFSX_UNSIGNED);
 5165                 error = nfsv4_loadattr(nd, NULL, dsnap, NULL, NULL, 0, NULL,
 5166                     NULL, NULL, NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL);
 5167         }
 5168         NFSD_DEBUG(4, "nfsrv_setattrdsdorpc: aft setattr loadattr=%d\n", error);
 5169 nfsmout:
 5170         m_freem(nd->nd_mrep);
 5171         free(nd, M_TEMP);
 5172         NFSD_DEBUG(4, "nfsrv_setattrdsdorpc error=%d\n", error);
 5173         return (error);
 5174 }
 5175 
 5176 struct nfsrvsetattrdsdorpc {
 5177         int                     done;
 5178         int                     inprog;
 5179         struct task             tsk;
 5180         fhandle_t               fh;
 5181         struct nfsmount         *nmp;
 5182         struct vnode            *vp;
 5183         struct ucred            *cred;
 5184         NFSPROC_T               *p;
 5185         struct nfsvattr         na;
 5186         struct nfsvattr         dsna;
 5187         int                     err;
 5188 };
 5189 
 5190 /*
 5191  * Start up the thread that will execute nfsrv_setattrdsdorpc().
 5192  */
 5193 static void
 5194 start_setattrdsdorpc(void *arg, int pending)
 5195 {
 5196         struct nfsrvsetattrdsdorpc *drpc;
 5197 
 5198         drpc = (struct nfsrvsetattrdsdorpc *)arg;
 5199         drpc->err = nfsrv_setattrdsdorpc(&drpc->fh, drpc->cred, drpc->p,
 5200             drpc->vp, drpc->nmp, &drpc->na, &drpc->dsna);
 5201         drpc->done = 1;
 5202 }
 5203 
 5204 static int
 5205 nfsrv_setattrdsrpc(fhandle_t *fhp, struct ucred *cred, NFSPROC_T *p,
 5206     struct vnode *vp, struct nfsmount **nmpp, int mirrorcnt,
 5207     struct nfsvattr *nap, int *failposp)
 5208 {
 5209         struct nfsrvsetattrdsdorpc *drpc, *tdrpc;
 5210         struct nfsvattr na;
 5211         int error, i, ret, timo;
 5212 
 5213         NFSD_DEBUG(4, "in nfsrv_setattrdsrpc\n");
 5214         drpc = NULL;
 5215         if (mirrorcnt > 1)
 5216                 tdrpc = drpc = malloc(sizeof(*drpc) * (mirrorcnt - 1), M_TEMP,
 5217                     M_WAITOK);
 5218 
 5219         /*
 5220          * Do the setattr RPC for every DS, using a separate kernel process
 5221          * for every DS except the last one.
 5222          */
 5223         error = 0;
 5224         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5225                 tdrpc->done = 0;
 5226                 tdrpc->inprog = 0;
 5227                 NFSBCOPY(fhp, &tdrpc->fh, sizeof(*fhp));
 5228                 tdrpc->nmp = *nmpp;
 5229                 tdrpc->vp = vp;
 5230                 tdrpc->cred = cred;
 5231                 tdrpc->p = p;
 5232                 tdrpc->na = *nap;
 5233                 tdrpc->err = 0;
 5234                 ret = EIO;
 5235                 if (nfs_pnfsiothreads != 0) {
 5236                         ret = nfs_pnfsio(start_setattrdsdorpc, tdrpc);
 5237                         NFSD_DEBUG(4, "nfsrv_setattrdsrpc: nfs_pnfsio=%d\n",
 5238                             ret);
 5239                 }
 5240                 if (ret != 0) {
 5241                         ret = nfsrv_setattrdsdorpc(fhp, cred, p, vp, *nmpp, nap,
 5242                             &na);
 5243                         if (nfsds_failerr(ret) && *failposp == -1)
 5244                                 *failposp = i;
 5245                         else if (error == 0 && ret != 0)
 5246                                 error = ret;
 5247                 }
 5248                 nmpp++;
 5249                 fhp++;
 5250         }
 5251         ret = nfsrv_setattrdsdorpc(fhp, cred, p, vp, *nmpp, nap, &na);
 5252         if (nfsds_failerr(ret) && *failposp == -1 && mirrorcnt > 1)
 5253                 *failposp = mirrorcnt - 1;
 5254         else if (error == 0 && ret != 0)
 5255                 error = ret;
 5256         if (error == 0)
 5257                 error = nfsrv_setextattr(vp, &na, p);
 5258         NFSD_DEBUG(4, "nfsrv_setattrdsrpc: aft setextat=%d\n", error);
 5259         tdrpc = drpc;
 5260         timo = hz / 50;         /* Wait for 20msec. */
 5261         if (timo < 1)
 5262                 timo = 1;
 5263         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5264                 /* Wait for RPCs on separate threads to complete. */
 5265                 while (tdrpc->inprog != 0 && tdrpc->done == 0)
 5266                         tsleep(&tdrpc->tsk, PVFS, "srvsads", timo);
 5267                 if (nfsds_failerr(tdrpc->err) && *failposp == -1)
 5268                         *failposp = i;
 5269                 else if (error == 0 && tdrpc->err != 0)
 5270                         error = tdrpc->err;
 5271         }
 5272         free(drpc, M_TEMP);
 5273         return (error);
 5274 }
 5275 
 5276 /*
 5277  * Do a Setattr of an NFSv4 ACL on the DS file.
 5278  */
 5279 static int
 5280 nfsrv_setacldsdorpc(fhandle_t *fhp, struct ucred *cred, NFSPROC_T *p,
 5281     struct vnode *vp, struct nfsmount *nmp, struct acl *aclp)
 5282 {
 5283         struct nfsrv_descript *nd;
 5284         nfsv4stateid_t st;
 5285         nfsattrbit_t attrbits;
 5286         int error;
 5287 
 5288         NFSD_DEBUG(4, "in nfsrv_setacldsdorpc\n");
 5289         nd = malloc(sizeof(*nd), M_TEMP, M_WAITOK | M_ZERO);
 5290         /*
 5291          * Use a stateid where other is an alternating 01010 pattern and
 5292          * seqid is 0xffffffff.  This value is not defined as special by
 5293          * the RFC and is used by the FreeBSD NFS server to indicate an
 5294          * MDS->DS proxy operation.
 5295          */
 5296         st.other[0] = 0x55555555;
 5297         st.other[1] = 0x55555555;
 5298         st.other[2] = 0x55555555;
 5299         st.seqid = 0xffffffff;
 5300         nfscl_reqstart(nd, NFSPROC_SETACL, nmp, (u_int8_t *)fhp, sizeof(*fhp),
 5301             NULL, NULL, 0, 0);
 5302         nfsm_stateidtom(nd, &st, NFSSTATEID_PUTSTATEID);
 5303         NFSZERO_ATTRBIT(&attrbits);
 5304         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_ACL);
 5305         /*
 5306          * The "vp" argument to nfsv4_fillattr() is only used for vnode_type(),
 5307          * so passing in the metadata "vp" will be ok, since it is of
 5308          * the same type (VREG).
 5309          */
 5310         nfsv4_fillattr(nd, NULL, vp, aclp, NULL, NULL, 0, &attrbits, NULL,
 5311             NULL, 0, 0, 0, 0, 0, NULL);
 5312         error = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, NULL, p, cred,
 5313             NFS_PROG, NFS_VER4, NULL, 1, NULL, NULL);
 5314         if (error != 0) {
 5315                 free(nd, M_TEMP);
 5316                 return (error);
 5317         }
 5318         NFSD_DEBUG(4, "nfsrv_setacldsdorpc: aft setaclrpc=%d\n",
 5319             nd->nd_repstat);
 5320         error = nd->nd_repstat;
 5321         m_freem(nd->nd_mrep);
 5322         free(nd, M_TEMP);
 5323         return (error);
 5324 }
 5325 
 5326 struct nfsrvsetacldsdorpc {
 5327         int                     done;
 5328         int                     inprog;
 5329         struct task             tsk;
 5330         fhandle_t               fh;
 5331         struct nfsmount         *nmp;
 5332         struct vnode            *vp;
 5333         struct ucred            *cred;
 5334         NFSPROC_T               *p;
 5335         struct acl              *aclp;
 5336         int                     err;
 5337 };
 5338 
 5339 /*
 5340  * Start up the thread that will execute nfsrv_setacldsdorpc().
 5341  */
 5342 static void
 5343 start_setacldsdorpc(void *arg, int pending)
 5344 {
 5345         struct nfsrvsetacldsdorpc *drpc;
 5346 
 5347         drpc = (struct nfsrvsetacldsdorpc *)arg;
 5348         drpc->err = nfsrv_setacldsdorpc(&drpc->fh, drpc->cred, drpc->p,
 5349             drpc->vp, drpc->nmp, drpc->aclp);
 5350         drpc->done = 1;
 5351 }
 5352 
 5353 static int
 5354 nfsrv_setacldsrpc(fhandle_t *fhp, struct ucred *cred, NFSPROC_T *p,
 5355     struct vnode *vp, struct nfsmount **nmpp, int mirrorcnt, struct acl *aclp,
 5356     int *failposp)
 5357 {
 5358         struct nfsrvsetacldsdorpc *drpc, *tdrpc;
 5359         int error, i, ret, timo;
 5360 
 5361         NFSD_DEBUG(4, "in nfsrv_setacldsrpc\n");
 5362         drpc = NULL;
 5363         if (mirrorcnt > 1)
 5364                 tdrpc = drpc = malloc(sizeof(*drpc) * (mirrorcnt - 1), M_TEMP,
 5365                     M_WAITOK);
 5366 
 5367         /*
 5368          * Do the setattr RPC for every DS, using a separate kernel process
 5369          * for every DS except the last one.
 5370          */
 5371         error = 0;
 5372         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5373                 tdrpc->done = 0;
 5374                 tdrpc->inprog = 0;
 5375                 NFSBCOPY(fhp, &tdrpc->fh, sizeof(*fhp));
 5376                 tdrpc->nmp = *nmpp;
 5377                 tdrpc->vp = vp;
 5378                 tdrpc->cred = cred;
 5379                 tdrpc->p = p;
 5380                 tdrpc->aclp = aclp;
 5381                 tdrpc->err = 0;
 5382                 ret = EIO;
 5383                 if (nfs_pnfsiothreads != 0) {
 5384                         ret = nfs_pnfsio(start_setacldsdorpc, tdrpc);
 5385                         NFSD_DEBUG(4, "nfsrv_setacldsrpc: nfs_pnfsio=%d\n",
 5386                             ret);
 5387                 }
 5388                 if (ret != 0) {
 5389                         ret = nfsrv_setacldsdorpc(fhp, cred, p, vp, *nmpp,
 5390                             aclp);
 5391                         if (nfsds_failerr(ret) && *failposp == -1)
 5392                                 *failposp = i;
 5393                         else if (error == 0 && ret != 0)
 5394                                 error = ret;
 5395                 }
 5396                 nmpp++;
 5397                 fhp++;
 5398         }
 5399         ret = nfsrv_setacldsdorpc(fhp, cred, p, vp, *nmpp, aclp);
 5400         if (nfsds_failerr(ret) && *failposp == -1 && mirrorcnt > 1)
 5401                 *failposp = mirrorcnt - 1;
 5402         else if (error == 0 && ret != 0)
 5403                 error = ret;
 5404         NFSD_DEBUG(4, "nfsrv_setacldsrpc: aft setextat=%d\n", error);
 5405         tdrpc = drpc;
 5406         timo = hz / 50;         /* Wait for 20msec. */
 5407         if (timo < 1)
 5408                 timo = 1;
 5409         for (i = 0; i < mirrorcnt - 1; i++, tdrpc++) {
 5410                 /* Wait for RPCs on separate threads to complete. */
 5411                 while (tdrpc->inprog != 0 && tdrpc->done == 0)
 5412                         tsleep(&tdrpc->tsk, PVFS, "srvacds", timo);
 5413                 if (nfsds_failerr(tdrpc->err) && *failposp == -1)
 5414                         *failposp = i;
 5415                 else if (error == 0 && tdrpc->err != 0)
 5416                         error = tdrpc->err;
 5417         }
 5418         free(drpc, M_TEMP);
 5419         return (error);
 5420 }
 5421 
 5422 /*
 5423  * Getattr call to the DS for the Modify, Size and Change attributes.
 5424  */
 5425 static int
 5426 nfsrv_getattrdsrpc(fhandle_t *fhp, struct ucred *cred, NFSPROC_T *p,
 5427     struct vnode *vp, struct nfsmount *nmp, struct nfsvattr *nap)
 5428 {
 5429         struct nfsrv_descript *nd;
 5430         int error;
 5431         nfsattrbit_t attrbits;
 5432         
 5433         NFSD_DEBUG(4, "in nfsrv_getattrdsrpc\n");
 5434         nd = malloc(sizeof(*nd), M_TEMP, M_WAITOK | M_ZERO);
 5435         nfscl_reqstart(nd, NFSPROC_GETATTR, nmp, (u_int8_t *)fhp,
 5436             sizeof(fhandle_t), NULL, NULL, 0, 0);
 5437         NFSZERO_ATTRBIT(&attrbits);
 5438         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_SIZE);
 5439         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_CHANGE);
 5440         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEACCESS);
 5441         NFSSETBIT_ATTRBIT(&attrbits, NFSATTRBIT_TIMEMODIFY);
 5442         (void) nfsrv_putattrbit(nd, &attrbits);
 5443         error = newnfs_request(nd, nmp, NULL, &nmp->nm_sockreq, NULL, p, cred,
 5444             NFS_PROG, NFS_VER4, NULL, 1, NULL, NULL);
 5445         if (error != 0) {
 5446                 free(nd, M_TEMP);
 5447                 return (error);
 5448         }
 5449         NFSD_DEBUG(4, "nfsrv_getattrdsrpc: aft getattrrpc=%d\n",
 5450             nd->nd_repstat);
 5451         if (nd->nd_repstat == 0) {
 5452                 error = nfsv4_loadattr(nd, NULL, nap, NULL, NULL, 0,
 5453                     NULL, NULL, NULL, NULL, NULL, 0, NULL, NULL, NULL,
 5454                     NULL, NULL);
 5455                 /*
 5456                  * We can only save the updated values in the extended
 5457                  * attribute if the vp is exclusively locked.
 5458                  * This should happen when any of the following operations
 5459                  * occur on the vnode:
 5460                  *    Close, Delegreturn, LayoutCommit, LayoutReturn
 5461                  * As such, the updated extended attribute should get saved
 5462                  * before nfsrv_checkdsattr() returns 0 and allows the cached
 5463                  * attributes to be returned without calling this function.
 5464                  */
 5465                 if (error == 0 && VOP_ISLOCKED(vp) == LK_EXCLUSIVE) {
 5466                         error = nfsrv_setextattr(vp, nap, p);
 5467                         NFSD_DEBUG(4, "nfsrv_getattrdsrpc: aft setextat=%d\n",
 5468                             error);
 5469                 }
 5470         } else
 5471                 error = nd->nd_repstat;
 5472         m_freem(nd->nd_mrep);
 5473         free(nd, M_TEMP);
 5474         NFSD_DEBUG(4, "nfsrv_getattrdsrpc error=%d\n", error);
 5475         return (error);
 5476 }
 5477 
 5478 /*
 5479  * Get the device id and file handle for a DS file.
 5480  */
 5481 int
 5482 nfsrv_dsgetdevandfh(struct vnode *vp, NFSPROC_T *p, int *mirrorcntp,
 5483     fhandle_t *fhp, char *devid)
 5484 {
 5485         int buflen, error;
 5486         char *buf;
 5487 
 5488         buflen = 1024;
 5489         buf = malloc(buflen, M_TEMP, M_WAITOK);
 5490         error = nfsrv_dsgetsockmnt(vp, 0, buf, &buflen, mirrorcntp, p, NULL,
 5491             fhp, devid, NULL, NULL, NULL, NULL, NULL, NULL);
 5492         free(buf, M_TEMP);
 5493         return (error);
 5494 }
 5495 
 5496 /*
 5497  * Do a Lookup against the DS for the filename.
 5498  */
 5499 static int
 5500 nfsrv_pnfslookupds(struct vnode *vp, struct vnode *dvp, struct pnfsdsfile *pf,
 5501     struct vnode **nvpp, NFSPROC_T *p)
 5502 {
 5503         struct nameidata named;
 5504         struct ucred *tcred;
 5505         char *bufp;
 5506         u_long *hashp;
 5507         struct vnode *nvp;
 5508         int error;
 5509 
 5510         tcred = newnfs_getcred();
 5511         named.ni_cnd.cn_nameiop = LOOKUP;
 5512         named.ni_cnd.cn_lkflags = LK_SHARED | LK_RETRY;
 5513         named.ni_cnd.cn_cred = tcred;
 5514         named.ni_cnd.cn_thread = p;
 5515         named.ni_cnd.cn_flags = ISLASTCN | LOCKPARENT | LOCKLEAF | SAVENAME;
 5516         nfsvno_setpathbuf(&named, &bufp, &hashp);
 5517         named.ni_cnd.cn_nameptr = bufp;
 5518         named.ni_cnd.cn_namelen = strlen(pf->dsf_filename);
 5519         strlcpy(bufp, pf->dsf_filename, NAME_MAX);
 5520         NFSD_DEBUG(4, "nfsrv_pnfslookupds: filename=%s\n", bufp);
 5521         error = VOP_LOOKUP(dvp, &nvp, &named.ni_cnd);
 5522         NFSD_DEBUG(4, "nfsrv_pnfslookupds: aft LOOKUP=%d\n", error);
 5523         NFSFREECRED(tcred);
 5524         nfsvno_relpathbuf(&named);
 5525         if (error == 0)
 5526                 *nvpp = nvp;
 5527         NFSD_DEBUG(4, "eo nfsrv_pnfslookupds=%d\n", error);
 5528         return (error);
 5529 }
 5530 
 5531 /*
 5532  * Set the file handle to the correct one.
 5533  */
 5534 static void
 5535 nfsrv_pnfssetfh(struct vnode *vp, struct pnfsdsfile *pf, char *devid,
 5536     char *fnamep, struct vnode *nvp, NFSPROC_T *p)
 5537 {
 5538         struct nfsnode *np;
 5539         int ret;
 5540 
 5541         np = VTONFS(nvp);
 5542         NFSBCOPY(np->n_fhp->nfh_fh, &pf->dsf_fh, NFSX_MYFH);
 5543         /*
 5544          * We can only do a vn_set_extattr() if the vnode is exclusively
 5545          * locked and vn_start_write() has been done.  If devid != NULL or
 5546          * fnamep != NULL or the vnode is shared locked, vn_start_write()
 5547          * may not have been done.
 5548          * If not done now, it will be done on a future call.
 5549          */
 5550         if (devid == NULL && fnamep == NULL && NFSVOPISLOCKED(vp) ==
 5551             LK_EXCLUSIVE)
 5552                 ret = vn_extattr_set(vp, IO_NODELOCKED,
 5553                     EXTATTR_NAMESPACE_SYSTEM, "pnfsd.dsfile", sizeof(*pf),
 5554                     (char *)pf, p);
 5555         NFSD_DEBUG(4, "eo nfsrv_pnfssetfh=%d\n", ret);
 5556 }
 5557 
 5558 /*
 5559  * Cause RPCs waiting on "nmp" to fail.  This is called for a DS mount point
 5560  * when the DS has failed.
 5561  */
 5562 void
 5563 nfsrv_killrpcs(struct nfsmount *nmp)
 5564 {
 5565 
 5566         /*
 5567          * Call newnfs_nmcancelreqs() to cause
 5568          * any RPCs in progress on the mount point to
 5569          * fail.
 5570          * This will cause any process waiting for an
 5571          * RPC to complete while holding a vnode lock
 5572          * on the mounted-on vnode (such as "df" or
 5573          * a non-forced "umount") to fail.
 5574          * This will unlock the mounted-on vnode so
 5575          * a forced dismount can succeed.
 5576          * The NFSMNTP_CANCELRPCS flag should be set when this function is
 5577          * called.
 5578          */
 5579         newnfs_nmcancelreqs(nmp);
 5580 }
 5581 
 5582 /*
 5583  * Sum up the statfs info for each of the DSs, so that the client will
 5584  * receive the total for all DSs.
 5585  */
 5586 static int
 5587 nfsrv_pnfsstatfs(struct statfs *sf, struct mount *mp)
 5588 {
 5589         struct statfs *tsf;
 5590         struct nfsdevice *ds;
 5591         struct vnode **dvpp, **tdvpp, *dvp;
 5592         uint64_t tot;
 5593         int cnt, error = 0, i;
 5594 
 5595         if (nfsrv_devidcnt <= 0)
 5596                 return (ENXIO);
 5597         dvpp = mallocarray(nfsrv_devidcnt, sizeof(*dvpp), M_TEMP, M_WAITOK);
 5598         tsf = malloc(sizeof(*tsf), M_TEMP, M_WAITOK);
 5599 
 5600         /* Get an array of the dvps for the DSs. */
 5601         tdvpp = dvpp;
 5602         i = 0;
 5603         NFSDDSLOCK();
 5604         /* First, search for matches for same file system. */
 5605         TAILQ_FOREACH(ds, &nfsrv_devidhead, nfsdev_list) {
 5606                 if (ds->nfsdev_nmp != NULL && ds->nfsdev_mdsisset != 0 &&
 5607                     ds->nfsdev_mdsfsid.val[0] == mp->mnt_stat.f_fsid.val[0] &&
 5608                     ds->nfsdev_mdsfsid.val[1] == mp->mnt_stat.f_fsid.val[1]) {
 5609                         if (++i > nfsrv_devidcnt)
 5610                                 break;
 5611                         *tdvpp++ = ds->nfsdev_dvp;
 5612                 }
 5613         }
 5614         /*
 5615          * If no matches for same file system, total all servers not assigned
 5616          * to a file system.
 5617          */
 5618         if (i == 0) {
 5619                 TAILQ_FOREACH(ds, &nfsrv_devidhead, nfsdev_list) {
 5620                         if (ds->nfsdev_nmp != NULL &&
 5621                             ds->nfsdev_mdsisset == 0) {
 5622                                 if (++i > nfsrv_devidcnt)
 5623                                         break;
 5624                                 *tdvpp++ = ds->nfsdev_dvp;
 5625                         }
 5626                 }
 5627         }
 5628         NFSDDSUNLOCK();
 5629         cnt = i;
 5630 
 5631         /* Do a VFS_STATFS() for each of the DSs and sum them up. */
 5632         tdvpp = dvpp;
 5633         for (i = 0; i < cnt && error == 0; i++) {
 5634                 dvp = *tdvpp++;
 5635                 error = VFS_STATFS(dvp->v_mount, tsf);
 5636                 if (error == 0) {
 5637                         if (sf->f_bsize == 0) {
 5638                                 if (tsf->f_bsize > 0)
 5639                                         sf->f_bsize = tsf->f_bsize;
 5640                                 else
 5641                                         sf->f_bsize = 8192;
 5642                         }
 5643                         if (tsf->f_blocks > 0) {
 5644                                 if (sf->f_bsize != tsf->f_bsize) {
 5645                                         tot = tsf->f_blocks * tsf->f_bsize;
 5646                                         sf->f_blocks += (tot / sf->f_bsize);
 5647                                 } else
 5648                                         sf->f_blocks += tsf->f_blocks;
 5649                         }
 5650                         if (tsf->f_bfree > 0) {
 5651                                 if (sf->f_bsize != tsf->f_bsize) {
 5652                                         tot = tsf->f_bfree * tsf->f_bsize;
 5653                                         sf->f_bfree += (tot / sf->f_bsize);
 5654                                 } else
 5655                                         sf->f_bfree += tsf->f_bfree;
 5656                         }
 5657                         if (tsf->f_bavail > 0) {
 5658                                 if (sf->f_bsize != tsf->f_bsize) {
 5659                                         tot = tsf->f_bavail * tsf->f_bsize;
 5660                                         sf->f_bavail += (tot / sf->f_bsize);
 5661                                 } else
 5662                                         sf->f_bavail += tsf->f_bavail;
 5663                         }
 5664                 }
 5665         }
 5666         free(tsf, M_TEMP);
 5667         free(dvpp, M_TEMP);
 5668         return (error);
 5669 }
 5670 
 5671 /*
 5672  * Set an NFSv4 acl.
 5673  */
 5674 int
 5675 nfsrv_setacl(struct vnode *vp, NFSACL_T *aclp, struct ucred *cred, NFSPROC_T *p)
 5676 {
 5677         int error;
 5678 
 5679         if (nfsrv_useacl == 0 || nfs_supportsnfsv4acls(vp) == 0) {
 5680                 error = NFSERR_ATTRNOTSUPP;
 5681                 goto out;
 5682         }
 5683         /*
 5684          * With NFSv4 ACLs, chmod(2) may need to add additional entries.
 5685          * Make sure it has enough room for that - splitting every entry
 5686          * into two and appending "canonical six" entries at the end.
 5687          * Cribbed out of kern/vfs_acl.c - Rick M.
 5688          */
 5689         if (aclp->acl_cnt > (ACL_MAX_ENTRIES - 6) / 2) {
 5690                 error = NFSERR_ATTRNOTSUPP;
 5691                 goto out;
 5692         }
 5693         error = VOP_SETACL(vp, ACL_TYPE_NFS4, aclp, cred, p);
 5694         if (error == 0) {
 5695                 error = nfsrv_dssetacl(vp, aclp, cred, p);
 5696                 if (error == ENOENT)
 5697                         error = 0;
 5698         }
 5699 
 5700 out:
 5701         NFSEXITCODE(error);
 5702         return (error);
 5703 }
 5704 
 5705 extern int (*nfsd_call_nfsd)(struct thread *, struct nfssvc_args *);
 5706 
 5707 /*
 5708  * Called once to initialize data structures...
 5709  */
 5710 static int
 5711 nfsd_modevent(module_t mod, int type, void *data)
 5712 {
 5713         int error = 0, i;
 5714         static int loaded = 0;
 5715 
 5716         switch (type) {
 5717         case MOD_LOAD:
 5718                 if (loaded)
 5719                         goto out;
 5720                 newnfs_portinit();
 5721                 for (i = 0; i < NFSRVCACHE_HASHSIZE; i++) {
 5722                         mtx_init(&nfsrchash_table[i].mtx, "nfsrtc", NULL,
 5723                             MTX_DEF);
 5724                         mtx_init(&nfsrcahash_table[i].mtx, "nfsrtca", NULL,
 5725                             MTX_DEF);
 5726                 }
 5727                 mtx_init(&nfsrc_udpmtx, "nfsuc", NULL, MTX_DEF);
 5728                 mtx_init(&nfs_v4root_mutex, "nfs4rt", NULL, MTX_DEF);
 5729                 mtx_init(&nfsv4root_mnt.mnt_mtx, "nfs4mnt", NULL, MTX_DEF);
 5730                 mtx_init(&nfsrv_dontlistlock_mtx, "nfs4dnl", NULL, MTX_DEF);
 5731                 mtx_init(&nfsrv_recalllock_mtx, "nfs4rec", NULL, MTX_DEF);
 5732                 lockinit(&nfsv4root_mnt.mnt_explock, PVFS, "explock", 0, 0);
 5733                 nfsrvd_initcache();
 5734                 nfsd_init();
 5735                 NFSD_LOCK();
 5736                 nfsrvd_init(0);
 5737                 NFSD_UNLOCK();
 5738                 nfsd_mntinit();
 5739 #ifdef VV_DISABLEDELEG
 5740                 vn_deleg_ops.vndeleg_recall = nfsd_recalldelegation;
 5741                 vn_deleg_ops.vndeleg_disable = nfsd_disabledelegation;
 5742 #endif
 5743                 nfsd_call_servertimer = nfsrv_servertimer;
 5744                 nfsd_call_nfsd = nfssvc_nfsd;
 5745                 loaded = 1;
 5746                 break;
 5747 
 5748         case MOD_UNLOAD:
 5749                 if (newnfs_numnfsd != 0) {
 5750                         error = EBUSY;
 5751                         break;
 5752                 }
 5753 
 5754 #ifdef VV_DISABLEDELEG
 5755                 vn_deleg_ops.vndeleg_recall = NULL;
 5756                 vn_deleg_ops.vndeleg_disable = NULL;
 5757 #endif
 5758                 nfsd_call_servertimer = NULL;
 5759                 nfsd_call_nfsd = NULL;
 5760 
 5761                 /* Clean out all NFSv4 state. */
 5762                 nfsrv_throwawayallstate(curthread);
 5763 
 5764                 /* Clean the NFS server reply cache */
 5765                 nfsrvd_cleancache();
 5766 
 5767                 /* Free up the krpc server pool. */
 5768                 if (nfsrvd_pool != NULL)
 5769                         svcpool_destroy(nfsrvd_pool);
 5770 
 5771                 /* and get rid of the locks */
 5772                 for (i = 0; i < NFSRVCACHE_HASHSIZE; i++) {
 5773                         mtx_destroy(&nfsrchash_table[i].mtx);
 5774                         mtx_destroy(&nfsrcahash_table[i].mtx);
 5775                 }
 5776                 mtx_destroy(&nfsrc_udpmtx);
 5777                 mtx_destroy(&nfs_v4root_mutex);
 5778                 mtx_destroy(&nfsv4root_mnt.mnt_mtx);
 5779                 mtx_destroy(&nfsrv_dontlistlock_mtx);
 5780                 mtx_destroy(&nfsrv_recalllock_mtx);
 5781                 for (i = 0; i < nfsrv_sessionhashsize; i++)
 5782                         mtx_destroy(&nfssessionhash[i].mtx);
 5783                 if (nfslayouthash != NULL) {
 5784                         for (i = 0; i < nfsrv_layouthashsize; i++)
 5785                                 mtx_destroy(&nfslayouthash[i].mtx);
 5786                         free(nfslayouthash, M_NFSDSESSION);
 5787                 }
 5788                 lockdestroy(&nfsv4root_mnt.mnt_explock);
 5789                 free(nfsclienthash, M_NFSDCLIENT);
 5790                 free(nfslockhash, M_NFSDLOCKFILE);
 5791                 free(nfssessionhash, M_NFSDSESSION);
 5792                 loaded = 0;
 5793                 break;
 5794         default:
 5795                 error = EOPNOTSUPP;
 5796                 break;
 5797         }
 5798 
 5799 out:
 5800         NFSEXITCODE(error);
 5801         return (error);
 5802 }
 5803 static moduledata_t nfsd_mod = {
 5804         "nfsd",
 5805         nfsd_modevent,
 5806         NULL,
 5807 };
 5808 DECLARE_MODULE(nfsd, nfsd_mod, SI_SUB_VFS, SI_ORDER_ANY);
 5809 
 5810 /* So that loader and kldload(2) can find us, wherever we are.. */
 5811 MODULE_VERSION(nfsd, 1);
 5812 MODULE_DEPEND(nfsd, nfscommon, 1, 1, 1);
 5813 MODULE_DEPEND(nfsd, nfslock, 1, 1, 1);
 5814 MODULE_DEPEND(nfsd, nfslockd, 1, 1, 1);
 5815 MODULE_DEPEND(nfsd, krpc, 1, 1, 1);
 5816 MODULE_DEPEND(nfsd, nfssvc, 1, 1, 1);
 5817 

Cache object: 077c6176738a7bee20dd00eae1ed9886


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]


This page is part of the FreeBSD/Linux Linux Kernel Cross-Reference, and was automatically generated using a modified version of the LXR engine.