ovl: fix sgid on directory
[cascardo/linux.git] / fs / overlayfs / dir.c
1 /*
2  *
3  * Copyright (C) 2011 Novell Inc.
4  *
5  * This program is free software; you can redistribute it and/or modify it
6  * under the terms of the GNU General Public License version 2 as published by
7  * the Free Software Foundation.
8  */
9
10 #include <linux/fs.h>
11 #include <linux/namei.h>
12 #include <linux/xattr.h>
13 #include <linux/security.h>
14 #include <linux/cred.h>
15 #include "overlayfs.h"
16
17 void ovl_cleanup(struct inode *wdir, struct dentry *wdentry)
18 {
19         int err;
20
21         dget(wdentry);
22         if (d_is_dir(wdentry))
23                 err = ovl_do_rmdir(wdir, wdentry);
24         else
25                 err = ovl_do_unlink(wdir, wdentry);
26         dput(wdentry);
27
28         if (err) {
29                 pr_err("overlayfs: cleanup of '%pd2' failed (%i)\n",
30                        wdentry, err);
31         }
32 }
33
34 struct dentry *ovl_lookup_temp(struct dentry *workdir, struct dentry *dentry)
35 {
36         struct dentry *temp;
37         char name[20];
38
39         snprintf(name, sizeof(name), "#%lx", (unsigned long) dentry);
40
41         temp = lookup_one_len(name, workdir, strlen(name));
42         if (!IS_ERR(temp) && temp->d_inode) {
43                 pr_err("overlayfs: workdir/%s already exists\n", name);
44                 dput(temp);
45                 temp = ERR_PTR(-EIO);
46         }
47
48         return temp;
49 }
50
51 /* caller holds i_mutex on workdir */
52 static struct dentry *ovl_whiteout(struct dentry *workdir,
53                                    struct dentry *dentry)
54 {
55         int err;
56         struct dentry *whiteout;
57         struct inode *wdir = workdir->d_inode;
58
59         whiteout = ovl_lookup_temp(workdir, dentry);
60         if (IS_ERR(whiteout))
61                 return whiteout;
62
63         err = ovl_do_whiteout(wdir, whiteout);
64         if (err) {
65                 dput(whiteout);
66                 whiteout = ERR_PTR(err);
67         }
68
69         return whiteout;
70 }
71
72 int ovl_create_real(struct inode *dir, struct dentry *newdentry,
73                     struct kstat *stat, const char *link,
74                     struct dentry *hardlink, bool debug)
75 {
76         int err;
77
78         if (newdentry->d_inode)
79                 return -ESTALE;
80
81         if (hardlink) {
82                 err = ovl_do_link(hardlink, dir, newdentry, debug);
83         } else {
84                 switch (stat->mode & S_IFMT) {
85                 case S_IFREG:
86                         err = ovl_do_create(dir, newdentry, stat->mode, debug);
87                         break;
88
89                 case S_IFDIR:
90                         err = ovl_do_mkdir(dir, newdentry, stat->mode, debug);
91                         break;
92
93                 case S_IFCHR:
94                 case S_IFBLK:
95                 case S_IFIFO:
96                 case S_IFSOCK:
97                         err = ovl_do_mknod(dir, newdentry,
98                                            stat->mode, stat->rdev, debug);
99                         break;
100
101                 case S_IFLNK:
102                         err = ovl_do_symlink(dir, newdentry, link, debug);
103                         break;
104
105                 default:
106                         err = -EPERM;
107                 }
108         }
109         if (!err && WARN_ON(!newdentry->d_inode)) {
110                 /*
111                  * Not quite sure if non-instantiated dentry is legal or not.
112                  * VFS doesn't seem to care so check and warn here.
113                  */
114                 err = -ENOENT;
115         }
116         return err;
117 }
118
119 static int ovl_set_opaque(struct dentry *upperdentry)
120 {
121         return ovl_do_setxattr(upperdentry, OVL_XATTR_OPAQUE, "y", 1, 0);
122 }
123
124 static void ovl_remove_opaque(struct dentry *upperdentry)
125 {
126         int err;
127
128         err = ovl_do_removexattr(upperdentry, OVL_XATTR_OPAQUE);
129         if (err) {
130                 pr_warn("overlayfs: failed to remove opaque from '%s' (%i)\n",
131                         upperdentry->d_name.name, err);
132         }
133 }
134
135 static int ovl_dir_getattr(struct vfsmount *mnt, struct dentry *dentry,
136                          struct kstat *stat)
137 {
138         int err;
139         enum ovl_path_type type;
140         struct path realpath;
141         const struct cred *old_cred;
142
143         type = ovl_path_real(dentry, &realpath);
144         old_cred = ovl_override_creds(dentry->d_sb);
145         err = vfs_getattr(&realpath, stat);
146         revert_creds(old_cred);
147         if (err)
148                 return err;
149
150         stat->dev = dentry->d_sb->s_dev;
151         stat->ino = dentry->d_inode->i_ino;
152
153         /*
154          * It's probably not worth it to count subdirs to get the
155          * correct link count.  nlink=1 seems to pacify 'find' and
156          * other utilities.
157          */
158         if (OVL_TYPE_MERGE(type))
159                 stat->nlink = 1;
160
161         return 0;
162 }
163
164 /* Common operations required to be done after creation of file on upper */
165 static void ovl_instantiate(struct dentry *dentry, struct inode *inode,
166                             struct dentry *newdentry)
167 {
168         ovl_dentry_version_inc(dentry->d_parent);
169         ovl_dentry_update(dentry, newdentry);
170         ovl_copyattr(newdentry->d_inode, inode);
171         d_instantiate(dentry, inode);
172 }
173
174 static int ovl_create_upper(struct dentry *dentry, struct inode *inode,
175                             struct kstat *stat, const char *link,
176                             struct dentry *hardlink)
177 {
178         struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
179         struct inode *udir = upperdir->d_inode;
180         struct dentry *newdentry;
181         int err;
182
183         inode_lock_nested(udir, I_MUTEX_PARENT);
184         newdentry = lookup_one_len(dentry->d_name.name, upperdir,
185                                    dentry->d_name.len);
186         err = PTR_ERR(newdentry);
187         if (IS_ERR(newdentry))
188                 goto out_unlock;
189         err = ovl_create_real(udir, newdentry, stat, link, hardlink, false);
190         if (err)
191                 goto out_dput;
192
193         ovl_instantiate(dentry, inode, newdentry);
194         newdentry = NULL;
195 out_dput:
196         dput(newdentry);
197 out_unlock:
198         inode_unlock(udir);
199         return err;
200 }
201
202 static int ovl_lock_rename_workdir(struct dentry *workdir,
203                                    struct dentry *upperdir)
204 {
205         /* Workdir should not be the same as upperdir */
206         if (workdir == upperdir)
207                 goto err;
208
209         /* Workdir should not be subdir of upperdir and vice versa */
210         if (lock_rename(workdir, upperdir) != NULL)
211                 goto err_unlock;
212
213         return 0;
214
215 err_unlock:
216         unlock_rename(workdir, upperdir);
217 err:
218         pr_err("overlayfs: failed to lock workdir+upperdir\n");
219         return -EIO;
220 }
221
222 static struct dentry *ovl_clear_empty(struct dentry *dentry,
223                                       struct list_head *list)
224 {
225         struct dentry *workdir = ovl_workdir(dentry);
226         struct inode *wdir = workdir->d_inode;
227         struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
228         struct inode *udir = upperdir->d_inode;
229         struct path upperpath;
230         struct dentry *upper;
231         struct dentry *opaquedir;
232         struct kstat stat;
233         int err;
234
235         if (WARN_ON(!workdir))
236                 return ERR_PTR(-EROFS);
237
238         err = ovl_lock_rename_workdir(workdir, upperdir);
239         if (err)
240                 goto out;
241
242         ovl_path_upper(dentry, &upperpath);
243         err = vfs_getattr(&upperpath, &stat);
244         if (err)
245                 goto out_unlock;
246
247         err = -ESTALE;
248         if (!S_ISDIR(stat.mode))
249                 goto out_unlock;
250         upper = upperpath.dentry;
251         if (upper->d_parent->d_inode != udir)
252                 goto out_unlock;
253
254         opaquedir = ovl_lookup_temp(workdir, dentry);
255         err = PTR_ERR(opaquedir);
256         if (IS_ERR(opaquedir))
257                 goto out_unlock;
258
259         err = ovl_create_real(wdir, opaquedir, &stat, NULL, NULL, true);
260         if (err)
261                 goto out_dput;
262
263         err = ovl_copy_xattr(upper, opaquedir);
264         if (err)
265                 goto out_cleanup;
266
267         err = ovl_set_opaque(opaquedir);
268         if (err)
269                 goto out_cleanup;
270
271         inode_lock(opaquedir->d_inode);
272         err = ovl_set_attr(opaquedir, &stat);
273         inode_unlock(opaquedir->d_inode);
274         if (err)
275                 goto out_cleanup;
276
277         err = ovl_do_rename(wdir, opaquedir, udir, upper, RENAME_EXCHANGE);
278         if (err)
279                 goto out_cleanup;
280
281         ovl_cleanup_whiteouts(upper, list);
282         ovl_cleanup(wdir, upper);
283         unlock_rename(workdir, upperdir);
284
285         /* dentry's upper doesn't match now, get rid of it */
286         d_drop(dentry);
287
288         return opaquedir;
289
290 out_cleanup:
291         ovl_cleanup(wdir, opaquedir);
292 out_dput:
293         dput(opaquedir);
294 out_unlock:
295         unlock_rename(workdir, upperdir);
296 out:
297         return ERR_PTR(err);
298 }
299
300 static struct dentry *ovl_check_empty_and_clear(struct dentry *dentry)
301 {
302         int err;
303         struct dentry *ret = NULL;
304         LIST_HEAD(list);
305
306         err = ovl_check_empty_dir(dentry, &list);
307         if (err)
308                 ret = ERR_PTR(err);
309         else {
310                 /*
311                  * If no upperdentry then skip clearing whiteouts.
312                  *
313                  * Can race with copy-up, since we don't hold the upperdir
314                  * mutex.  Doesn't matter, since copy-up can't create a
315                  * non-empty directory from an empty one.
316                  */
317                 if (ovl_dentry_upper(dentry))
318                         ret = ovl_clear_empty(dentry, &list);
319         }
320
321         ovl_cache_free(&list);
322
323         return ret;
324 }
325
326 static int ovl_create_over_whiteout(struct dentry *dentry, struct inode *inode,
327                                     struct kstat *stat, const char *link,
328                                     struct dentry *hardlink)
329 {
330         struct dentry *workdir = ovl_workdir(dentry);
331         struct inode *wdir = workdir->d_inode;
332         struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
333         struct inode *udir = upperdir->d_inode;
334         struct dentry *upper;
335         struct dentry *newdentry;
336         int err;
337
338         if (WARN_ON(!workdir))
339                 return -EROFS;
340
341         err = ovl_lock_rename_workdir(workdir, upperdir);
342         if (err)
343                 goto out;
344
345         newdentry = ovl_lookup_temp(workdir, dentry);
346         err = PTR_ERR(newdentry);
347         if (IS_ERR(newdentry))
348                 goto out_unlock;
349
350         upper = lookup_one_len(dentry->d_name.name, upperdir,
351                                dentry->d_name.len);
352         err = PTR_ERR(upper);
353         if (IS_ERR(upper))
354                 goto out_dput;
355
356         err = ovl_create_real(wdir, newdentry, stat, link, hardlink, true);
357         if (err)
358                 goto out_dput2;
359
360         /*
361          * mode could have been mutilated due to umask (e.g. sgid directory)
362          */
363         if (!S_ISLNK(stat->mode) && newdentry->d_inode->i_mode != stat->mode) {
364                 struct iattr attr = {
365                         .ia_valid = ATTR_MODE,
366                         .ia_mode = stat->mode,
367                 };
368                 inode_lock(newdentry->d_inode);
369                 err = notify_change(newdentry, &attr, NULL);
370                 inode_unlock(newdentry->d_inode);
371                 if (err)
372                         goto out_cleanup;
373         }
374
375         if (S_ISDIR(stat->mode)) {
376                 err = ovl_set_opaque(newdentry);
377                 if (err)
378                         goto out_cleanup;
379
380                 err = ovl_do_rename(wdir, newdentry, udir, upper,
381                                     RENAME_EXCHANGE);
382                 if (err)
383                         goto out_cleanup;
384
385                 ovl_cleanup(wdir, upper);
386         } else {
387                 err = ovl_do_rename(wdir, newdentry, udir, upper, 0);
388                 if (err)
389                         goto out_cleanup;
390         }
391         ovl_instantiate(dentry, inode, newdentry);
392         newdentry = NULL;
393 out_dput2:
394         dput(upper);
395 out_dput:
396         dput(newdentry);
397 out_unlock:
398         unlock_rename(workdir, upperdir);
399 out:
400         return err;
401
402 out_cleanup:
403         ovl_cleanup(wdir, newdentry);
404         goto out_dput2;
405 }
406
407 static int ovl_create_or_link(struct dentry *dentry, int mode, dev_t rdev,
408                               const char *link, struct dentry *hardlink)
409 {
410         int err;
411         struct inode *inode;
412         const struct cred *old_cred;
413         struct cred *override_cred;
414         struct kstat stat = {
415                 .rdev = rdev,
416         };
417
418         err = -ENOMEM;
419         inode = ovl_new_inode(dentry->d_sb, mode, dentry->d_fsdata);
420         if (!inode)
421                 goto out;
422
423         err = ovl_copy_up(dentry->d_parent);
424         if (err)
425                 goto out_iput;
426
427         inode_init_owner(inode, dentry->d_parent->d_inode, mode);
428         stat.mode = inode->i_mode;
429
430         old_cred = ovl_override_creds(dentry->d_sb);
431         err = -ENOMEM;
432         override_cred = prepare_creds();
433         if (override_cred) {
434                 override_cred->fsuid = inode->i_uid;
435                 override_cred->fsgid = inode->i_gid;
436                 put_cred(override_creds(override_cred));
437                 put_cred(override_cred);
438
439                 if (!ovl_dentry_is_opaque(dentry))
440                         err = ovl_create_upper(dentry, inode, &stat, link,
441                                                 hardlink);
442                 else
443                         err = ovl_create_over_whiteout(dentry, inode, &stat,
444                                                         link, hardlink);
445         }
446         revert_creds(old_cred);
447         if (!err) {
448                 struct inode *realinode = d_inode(ovl_dentry_upper(dentry));
449
450                 WARN_ON(inode->i_mode != realinode->i_mode);
451                 WARN_ON(!uid_eq(inode->i_uid, realinode->i_uid));
452                 WARN_ON(!gid_eq(inode->i_gid, realinode->i_gid));
453                 inode = NULL;
454         }
455 out_iput:
456         iput(inode);
457 out:
458         return err;
459 }
460
461 static int ovl_create_object(struct dentry *dentry, int mode, dev_t rdev,
462                              const char *link)
463 {
464         int err;
465
466         err = ovl_want_write(dentry);
467         if (!err) {
468                 err = ovl_create_or_link(dentry, mode, rdev, link, NULL);
469                 ovl_drop_write(dentry);
470         }
471
472         return err;
473 }
474
475 static int ovl_create(struct inode *dir, struct dentry *dentry, umode_t mode,
476                       bool excl)
477 {
478         return ovl_create_object(dentry, (mode & 07777) | S_IFREG, 0, NULL);
479 }
480
481 static int ovl_mkdir(struct inode *dir, struct dentry *dentry, umode_t mode)
482 {
483         return ovl_create_object(dentry, (mode & 07777) | S_IFDIR, 0, NULL);
484 }
485
486 static int ovl_mknod(struct inode *dir, struct dentry *dentry, umode_t mode,
487                      dev_t rdev)
488 {
489         /* Don't allow creation of "whiteout" on overlay */
490         if (S_ISCHR(mode) && rdev == WHITEOUT_DEV)
491                 return -EPERM;
492
493         return ovl_create_object(dentry, mode, rdev, NULL);
494 }
495
496 static int ovl_symlink(struct inode *dir, struct dentry *dentry,
497                        const char *link)
498 {
499         return ovl_create_object(dentry, S_IFLNK, 0, link);
500 }
501
502 static int ovl_link(struct dentry *old, struct inode *newdir,
503                     struct dentry *new)
504 {
505         int err;
506         struct dentry *upper;
507
508         err = ovl_want_write(old);
509         if (err)
510                 goto out;
511
512         err = ovl_copy_up(old);
513         if (err)
514                 goto out_drop_write;
515
516         upper = ovl_dentry_upper(old);
517         err = ovl_create_or_link(new, upper->d_inode->i_mode, 0, NULL, upper);
518
519 out_drop_write:
520         ovl_drop_write(old);
521 out:
522         return err;
523 }
524
525 static int ovl_remove_and_whiteout(struct dentry *dentry, bool is_dir)
526 {
527         struct dentry *workdir = ovl_workdir(dentry);
528         struct inode *wdir = workdir->d_inode;
529         struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
530         struct inode *udir = upperdir->d_inode;
531         struct dentry *whiteout;
532         struct dentry *upper;
533         struct dentry *opaquedir = NULL;
534         int err;
535         int flags = 0;
536
537         if (WARN_ON(!workdir))
538                 return -EROFS;
539
540         if (is_dir) {
541                 if (OVL_TYPE_MERGE_OR_LOWER(ovl_path_type(dentry))) {
542                         opaquedir = ovl_check_empty_and_clear(dentry);
543                         err = PTR_ERR(opaquedir);
544                         if (IS_ERR(opaquedir))
545                                 goto out;
546                 } else {
547                         LIST_HEAD(list);
548
549                         /*
550                          * When removing an empty opaque directory, then it
551                          * makes no sense to replace it with an exact replica of
552                          * itself.  But emptiness still needs to be checked.
553                          */
554                         err = ovl_check_empty_dir(dentry, &list);
555                         ovl_cache_free(&list);
556                         if (err)
557                                 goto out;
558                 }
559         }
560
561         err = ovl_lock_rename_workdir(workdir, upperdir);
562         if (err)
563                 goto out_dput;
564
565         upper = lookup_one_len(dentry->d_name.name, upperdir,
566                                dentry->d_name.len);
567         err = PTR_ERR(upper);
568         if (IS_ERR(upper))
569                 goto out_unlock;
570
571         err = -ESTALE;
572         if ((opaquedir && upper != opaquedir) ||
573             (!opaquedir && ovl_dentry_upper(dentry) &&
574              upper != ovl_dentry_upper(dentry))) {
575                 goto out_dput_upper;
576         }
577
578         whiteout = ovl_whiteout(workdir, dentry);
579         err = PTR_ERR(whiteout);
580         if (IS_ERR(whiteout))
581                 goto out_dput_upper;
582
583         if (d_is_dir(upper))
584                 flags = RENAME_EXCHANGE;
585
586         err = ovl_do_rename(wdir, whiteout, udir, upper, flags);
587         if (err)
588                 goto kill_whiteout;
589         if (flags)
590                 ovl_cleanup(wdir, upper);
591
592         ovl_dentry_version_inc(dentry->d_parent);
593 out_d_drop:
594         d_drop(dentry);
595         dput(whiteout);
596 out_dput_upper:
597         dput(upper);
598 out_unlock:
599         unlock_rename(workdir, upperdir);
600 out_dput:
601         dput(opaquedir);
602 out:
603         return err;
604
605 kill_whiteout:
606         ovl_cleanup(wdir, whiteout);
607         goto out_d_drop;
608 }
609
610 static int ovl_remove_upper(struct dentry *dentry, bool is_dir)
611 {
612         struct dentry *upperdir = ovl_dentry_upper(dentry->d_parent);
613         struct inode *dir = upperdir->d_inode;
614         struct dentry *upper;
615         int err;
616
617         inode_lock_nested(dir, I_MUTEX_PARENT);
618         upper = lookup_one_len(dentry->d_name.name, upperdir,
619                                dentry->d_name.len);
620         err = PTR_ERR(upper);
621         if (IS_ERR(upper))
622                 goto out_unlock;
623
624         err = -ESTALE;
625         if (upper == ovl_dentry_upper(dentry)) {
626                 if (is_dir)
627                         err = vfs_rmdir(dir, upper);
628                 else
629                         err = vfs_unlink(dir, upper, NULL);
630                 ovl_dentry_version_inc(dentry->d_parent);
631         }
632         dput(upper);
633
634         /*
635          * Keeping this dentry hashed would mean having to release
636          * upperpath/lowerpath, which could only be done if we are the
637          * sole user of this dentry.  Too tricky...  Just unhash for
638          * now.
639          */
640         if (!err)
641                 d_drop(dentry);
642 out_unlock:
643         inode_unlock(dir);
644
645         return err;
646 }
647
648 static inline int ovl_check_sticky(struct dentry *dentry)
649 {
650         struct inode *dir = ovl_dentry_real(dentry->d_parent)->d_inode;
651         struct inode *inode = ovl_dentry_real(dentry)->d_inode;
652
653         if (check_sticky(dir, inode))
654                 return -EPERM;
655
656         return 0;
657 }
658
659 static int ovl_do_remove(struct dentry *dentry, bool is_dir)
660 {
661         enum ovl_path_type type;
662         int err;
663         const struct cred *old_cred;
664
665
666         err = ovl_check_sticky(dentry);
667         if (err)
668                 goto out;
669
670         err = ovl_want_write(dentry);
671         if (err)
672                 goto out;
673
674         err = ovl_copy_up(dentry->d_parent);
675         if (err)
676                 goto out_drop_write;
677
678         type = ovl_path_type(dentry);
679
680         old_cred = ovl_override_creds(dentry->d_sb);
681         if (OVL_TYPE_PURE_UPPER(type))
682                 err = ovl_remove_upper(dentry, is_dir);
683         else
684                 err = ovl_remove_and_whiteout(dentry, is_dir);
685         revert_creds(old_cred);
686 out_drop_write:
687         ovl_drop_write(dentry);
688 out:
689         return err;
690 }
691
692 static int ovl_unlink(struct inode *dir, struct dentry *dentry)
693 {
694         return ovl_do_remove(dentry, false);
695 }
696
697 static int ovl_rmdir(struct inode *dir, struct dentry *dentry)
698 {
699         return ovl_do_remove(dentry, true);
700 }
701
702 static int ovl_rename2(struct inode *olddir, struct dentry *old,
703                        struct inode *newdir, struct dentry *new,
704                        unsigned int flags)
705 {
706         int err;
707         enum ovl_path_type old_type;
708         enum ovl_path_type new_type;
709         struct dentry *old_upperdir;
710         struct dentry *new_upperdir;
711         struct dentry *olddentry;
712         struct dentry *newdentry;
713         struct dentry *trap;
714         bool old_opaque;
715         bool new_opaque;
716         bool cleanup_whiteout = false;
717         bool overwrite = !(flags & RENAME_EXCHANGE);
718         bool is_dir = d_is_dir(old);
719         bool new_is_dir = false;
720         struct dentry *opaquedir = NULL;
721         const struct cred *old_cred = NULL;
722
723         err = -EINVAL;
724         if (flags & ~(RENAME_EXCHANGE | RENAME_NOREPLACE))
725                 goto out;
726
727         flags &= ~RENAME_NOREPLACE;
728
729         err = ovl_check_sticky(old);
730         if (err)
731                 goto out;
732
733         /* Don't copy up directory trees */
734         old_type = ovl_path_type(old);
735         err = -EXDEV;
736         if (OVL_TYPE_MERGE_OR_LOWER(old_type) && is_dir)
737                 goto out;
738
739         if (new->d_inode) {
740                 err = ovl_check_sticky(new);
741                 if (err)
742                         goto out;
743
744                 if (d_is_dir(new))
745                         new_is_dir = true;
746
747                 new_type = ovl_path_type(new);
748                 err = -EXDEV;
749                 if (!overwrite && OVL_TYPE_MERGE_OR_LOWER(new_type) && new_is_dir)
750                         goto out;
751
752                 err = 0;
753                 if (!OVL_TYPE_UPPER(new_type) && !OVL_TYPE_UPPER(old_type)) {
754                         if (ovl_dentry_lower(old)->d_inode ==
755                             ovl_dentry_lower(new)->d_inode)
756                                 goto out;
757                 }
758                 if (OVL_TYPE_UPPER(new_type) && OVL_TYPE_UPPER(old_type)) {
759                         if (ovl_dentry_upper(old)->d_inode ==
760                             ovl_dentry_upper(new)->d_inode)
761                                 goto out;
762                 }
763         } else {
764                 if (ovl_dentry_is_opaque(new))
765                         new_type = __OVL_PATH_UPPER;
766                 else
767                         new_type = __OVL_PATH_UPPER | __OVL_PATH_PURE;
768         }
769
770         err = ovl_want_write(old);
771         if (err)
772                 goto out;
773
774         err = ovl_copy_up(old);
775         if (err)
776                 goto out_drop_write;
777
778         err = ovl_copy_up(new->d_parent);
779         if (err)
780                 goto out_drop_write;
781         if (!overwrite) {
782                 err = ovl_copy_up(new);
783                 if (err)
784                         goto out_drop_write;
785         }
786
787         old_opaque = !OVL_TYPE_PURE_UPPER(old_type);
788         new_opaque = !OVL_TYPE_PURE_UPPER(new_type);
789
790         old_cred = ovl_override_creds(old->d_sb);
791
792         if (overwrite && OVL_TYPE_MERGE_OR_LOWER(new_type) && new_is_dir) {
793                 opaquedir = ovl_check_empty_and_clear(new);
794                 err = PTR_ERR(opaquedir);
795                 if (IS_ERR(opaquedir)) {
796                         opaquedir = NULL;
797                         goto out_revert_creds;
798                 }
799         }
800
801         if (overwrite) {
802                 if (old_opaque) {
803                         if (new->d_inode || !new_opaque) {
804                                 /* Whiteout source */
805                                 flags |= RENAME_WHITEOUT;
806                         } else {
807                                 /* Switch whiteouts */
808                                 flags |= RENAME_EXCHANGE;
809                         }
810                 } else if (is_dir && !new->d_inode && new_opaque) {
811                         flags |= RENAME_EXCHANGE;
812                         cleanup_whiteout = true;
813                 }
814         }
815
816         old_upperdir = ovl_dentry_upper(old->d_parent);
817         new_upperdir = ovl_dentry_upper(new->d_parent);
818
819         trap = lock_rename(new_upperdir, old_upperdir);
820
821
822         olddentry = lookup_one_len(old->d_name.name, old_upperdir,
823                                    old->d_name.len);
824         err = PTR_ERR(olddentry);
825         if (IS_ERR(olddentry))
826                 goto out_unlock;
827
828         err = -ESTALE;
829         if (olddentry != ovl_dentry_upper(old))
830                 goto out_dput_old;
831
832         newdentry = lookup_one_len(new->d_name.name, new_upperdir,
833                                    new->d_name.len);
834         err = PTR_ERR(newdentry);
835         if (IS_ERR(newdentry))
836                 goto out_dput_old;
837
838         err = -ESTALE;
839         if (ovl_dentry_upper(new)) {
840                 if (opaquedir) {
841                         if (newdentry != opaquedir)
842                                 goto out_dput;
843                 } else {
844                         if (newdentry != ovl_dentry_upper(new))
845                                 goto out_dput;
846                 }
847         } else {
848                 if (!d_is_negative(newdentry) &&
849                     (!new_opaque || !ovl_is_whiteout(newdentry)))
850                         goto out_dput;
851         }
852
853         if (olddentry == trap)
854                 goto out_dput;
855         if (newdentry == trap)
856                 goto out_dput;
857
858         if (is_dir && !old_opaque && new_opaque) {
859                 err = ovl_set_opaque(olddentry);
860                 if (err)
861                         goto out_dput;
862         }
863         if (!overwrite && new_is_dir && old_opaque && !new_opaque) {
864                 err = ovl_set_opaque(newdentry);
865                 if (err)
866                         goto out_dput;
867         }
868
869         if (old_opaque || new_opaque) {
870                 err = ovl_do_rename(old_upperdir->d_inode, olddentry,
871                                     new_upperdir->d_inode, newdentry,
872                                     flags);
873         } else {
874                 /* No debug for the plain case */
875                 BUG_ON(flags & ~RENAME_EXCHANGE);
876                 err = vfs_rename(old_upperdir->d_inode, olddentry,
877                                  new_upperdir->d_inode, newdentry,
878                                  NULL, flags);
879         }
880
881         if (err) {
882                 if (is_dir && !old_opaque && new_opaque)
883                         ovl_remove_opaque(olddentry);
884                 if (!overwrite && new_is_dir && old_opaque && !new_opaque)
885                         ovl_remove_opaque(newdentry);
886                 goto out_dput;
887         }
888
889         if (is_dir && old_opaque && !new_opaque)
890                 ovl_remove_opaque(olddentry);
891         if (!overwrite && new_is_dir && !old_opaque && new_opaque)
892                 ovl_remove_opaque(newdentry);
893
894         /*
895          * Old dentry now lives in different location. Dentries in
896          * lowerstack are stale. We cannot drop them here because
897          * access to them is lockless. This could be only pure upper
898          * or opaque directory - numlower is zero. Or upper non-dir
899          * entry - its pureness is tracked by flag opaque.
900          */
901         if (old_opaque != new_opaque) {
902                 ovl_dentry_set_opaque(old, new_opaque);
903                 if (!overwrite)
904                         ovl_dentry_set_opaque(new, old_opaque);
905         }
906
907         if (cleanup_whiteout)
908                 ovl_cleanup(old_upperdir->d_inode, newdentry);
909
910         ovl_dentry_version_inc(old->d_parent);
911         ovl_dentry_version_inc(new->d_parent);
912
913 out_dput:
914         dput(newdentry);
915 out_dput_old:
916         dput(olddentry);
917 out_unlock:
918         unlock_rename(new_upperdir, old_upperdir);
919 out_revert_creds:
920         revert_creds(old_cred);
921 out_drop_write:
922         ovl_drop_write(old);
923 out:
924         dput(opaquedir);
925         return err;
926 }
927
928 const struct inode_operations ovl_dir_inode_operations = {
929         .lookup         = ovl_lookup,
930         .mkdir          = ovl_mkdir,
931         .symlink        = ovl_symlink,
932         .unlink         = ovl_unlink,
933         .rmdir          = ovl_rmdir,
934         .rename2        = ovl_rename2,
935         .link           = ovl_link,
936         .setattr        = ovl_setattr,
937         .create         = ovl_create,
938         .mknod          = ovl_mknod,
939         .permission     = ovl_permission,
940         .getattr        = ovl_dir_getattr,
941         .setxattr       = ovl_setxattr,
942         .getxattr       = ovl_getxattr,
943         .listxattr      = ovl_listxattr,
944         .removexattr    = ovl_removexattr,
945         .get_acl        = ovl_get_acl,
946 };