All of lore.kernel.org
 help / color / mirror / Atom feed
From: xiubli@redhat.com
To: idryomov@gmail.com, ceph-devel@vger.kernel.org
Cc: jlayton@kernel.org, vshankar@redhat.com, mchangir@redhat.com,
	lhenriques@suse.de, Xiubo Li <xiubli@redhat.com>
Subject: [PATCH v17 19/71] ceph: add base64 endcoding routines for encrypted names
Date: Thu, 23 Mar 2023 14:54:33 +0800	[thread overview]
Message-ID: <20230323065525.201322-20-xiubli@redhat.com> (raw)
In-Reply-To: <20230323065525.201322-1-xiubli@redhat.com>

From: Luís Henriques <lhenriques@suse.de>

The base64url encoding used by fscrypt includes the '_' character, which
may cause problems in snapshot names (if the name starts with '_').
Thus, use the base64 encoding defined for IMAP mailbox names (RFC 3501),
which uses '+' and ',' instead of '-' and '_'.

Signed-off-by: Luís Henriques <lhenriques@suse.de>
Reviewed-by: Xiubo Li <xiubli@redhat.com>
Signed-off-by: Jeff Layton <jlayton@kernel.org>
---
 fs/ceph/crypto.c | 60 ++++++++++++++++++++++++++++++++++++++++++++++++
 fs/ceph/crypto.h | 32 ++++++++++++++++++++++++++
 2 files changed, 92 insertions(+)

diff --git a/fs/ceph/crypto.c b/fs/ceph/crypto.c
index fd3192917e8d..947ac98119aa 100644
--- a/fs/ceph/crypto.c
+++ b/fs/ceph/crypto.c
@@ -1,4 +1,11 @@
 // SPDX-License-Identifier: GPL-2.0
+/*
+ * The base64 encode/decode code was copied from fscrypt:
+ * Copyright (C) 2015, Google, Inc.
+ * Copyright (C) 2015, Motorola Mobility
+ * Written by Uday Savagaonkar, 2014.
+ * Modified by Jaegeuk Kim, 2015.
+ */
 #include <linux/ceph/ceph_debug.h>
 #include <linux/xattr.h>
 #include <linux/fscrypt.h>
@@ -7,6 +14,59 @@
 #include "mds_client.h"
 #include "crypto.h"
 
+/*
+ * The base64url encoding used by fscrypt includes the '_' character, which may
+ * cause problems in snapshot names (which can not starts with '_').  Thus, we
+ * used the base64 encoding defined for IMAP mailbox names (RFC 3501) instead,
+ * which replaces '-' and '_' by '+' and ','.
+ */
+static const char base64_table[65] =
+        "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+,";
+
+int ceph_base64_encode(const u8 *src, int srclen, char *dst)
+{
+	u32 ac = 0;
+	int bits = 0;
+	int i;
+	char *cp = dst;
+
+	for (i = 0; i < srclen; i++) {
+		ac = (ac << 8) | src[i];
+		bits += 8;
+		do {
+			bits -= 6;
+			*cp++ = base64_table[(ac >> bits) & 0x3f];
+		} while (bits >= 6);
+	}
+	if (bits)
+		*cp++ = base64_table[(ac << (6 - bits)) & 0x3f];
+	return cp - dst;
+}
+
+int ceph_base64_decode(const char *src, int srclen, u8 *dst)
+{
+	u32 ac = 0;
+	int bits = 0;
+	int i;
+	u8 *bp = dst;
+
+	for (i = 0; i < srclen; i++) {
+		const char *p = strchr(base64_table, src[i]);
+
+		if (p == NULL || src[i] == 0)
+			return -1;
+		ac = (ac << 6) | (p - base64_table);
+		bits += 6;
+		if (bits >= 8) {
+			bits -= 8;
+			*bp++ = (u8)(ac >> bits);
+		}
+	}
+	if (ac & ((1 << bits) - 1))
+		return -1;
+	return bp - dst;
+}
+
 static int ceph_crypt_get_context(struct inode *inode, void *ctx, size_t len)
 {
 	struct ceph_inode_info *ci = ceph_inode(inode);
diff --git a/fs/ceph/crypto.h b/fs/ceph/crypto.h
index cb00fe42d5b7..f5d38d8a1995 100644
--- a/fs/ceph/crypto.h
+++ b/fs/ceph/crypto.h
@@ -27,6 +27,38 @@ static inline u32 ceph_fscrypt_auth_len(struct ceph_fscrypt_auth *fa)
 }
 
 #ifdef CONFIG_FS_ENCRYPTION
+/*
+ * We want to encrypt filenames when creating them, but the encrypted
+ * versions of those names may have illegal characters in them. To mitigate
+ * that, we base64 encode them, but that gives us a result that can exceed
+ * NAME_MAX.
+ *
+ * Follow a similar scheme to fscrypt itself, and cap the filename to a
+ * smaller size. If the ciphertext name is longer than the value below, then
+ * sha256 hash the remaining bytes.
+ *
+ * For the fscrypt_nokey_name struct the dirhash[2] member is useless in ceph
+ * so the corresponding struct will be:
+ *
+ * struct fscrypt_ceph_nokey_name {
+ *	u8 bytes[157];
+ *	u8 sha256[SHA256_DIGEST_SIZE];
+ * }; // 180 bytes => 240 bytes base64-encoded, which is <= NAME_MAX (255)
+ *
+ * (240 bytes is the maximum size allowed for snapshot names to take into
+ *  account the format: '_<SNAPSHOT-NAME>_<INODE-NUMBER>'.)
+ *
+ * Note that for long names that end up having their tail portion hashed, we
+ * must also store the full encrypted name (in the dentry's alternate_name
+ * field).
+ */
+#define CEPH_NOHASH_NAME_MAX (180 - SHA256_DIGEST_SIZE)
+
+#define CEPH_BASE64_CHARS(nbytes) DIV_ROUND_UP((nbytes) * 4, 3)
+
+int ceph_base64_encode(const u8 *src, int srclen, char *dst);
+int ceph_base64_decode(const char *src, int srclen, u8 *dst);
+
 void ceph_fscrypt_set_ops(struct super_block *sb);
 
 void ceph_fscrypt_free_dummy_policy(struct ceph_fs_client *fsc);
-- 
2.31.1


  parent reply	other threads:[~2023-03-23  6:57 UTC|newest]

Thread overview: 77+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-03-23  6:54 [PATCH v17 00/71] ceph+fscrypt: full support xiubli
2023-03-23  6:54 ` [PATCH v17 01/71] libceph: add spinlock around osd->o_requests xiubli
2023-03-23  6:54 ` [PATCH v17 02/71] libceph: define struct ceph_sparse_extent and add some helpers xiubli
2023-03-23  6:54 ` [PATCH v17 03/71] libceph: add sparse read support to msgr2 crc state machine xiubli
2023-03-23  6:54 ` [PATCH v17 04/71] libceph: add sparse read support to OSD client xiubli
2023-03-23  6:54 ` [PATCH v17 05/71] libceph: support sparse reads on msgr2 secure codepath xiubli
2023-03-23  6:54 ` [PATCH v17 06/71] libceph: add sparse read support to msgr1 xiubli
2023-03-23  6:54 ` [PATCH v17 07/71] ceph: add new mount option to enable sparse reads xiubli
2023-03-23  6:54 ` [PATCH v17 08/71] ceph: preallocate inode for ops that may create one xiubli
2023-03-23  6:54 ` [PATCH v17 09/71] ceph: make ceph_msdc_build_path use ref-walk xiubli
2023-03-23  6:54 ` [PATCH v17 10/71] libceph: add new iov_iter-based ceph_msg_data_type and ceph_osd_data_type xiubli
2023-03-23  6:54 ` [PATCH v17 11/71] ceph: use osd_req_op_extent_osd_iter for netfs reads xiubli
2023-03-23  6:54 ` [PATCH v17 12/71] ceph: fscrypt_auth handling for ceph xiubli
2023-03-23  6:54 ` [PATCH v17 13/71] ceph: ensure that we accept a new context from MDS for new inodes xiubli
2023-03-23  6:54 ` [PATCH v17 14/71] ceph: add support for fscrypt_auth/fscrypt_file to cap messages xiubli
2023-03-23  6:54 ` [PATCH v17 15/71] ceph: implement -o test_dummy_encryption mount option xiubli
2023-03-23  6:54 ` [PATCH v17 16/71] ceph: decode alternate_name in lease info xiubli
2023-03-23  6:54 ` [PATCH v17 17/71] ceph: add fscrypt ioctls xiubli
2023-03-23  6:54 ` [PATCH v17 18/71] ceph: make the ioctl cmd more readable in debug log xiubli
2023-03-23  6:54 ` xiubli [this message]
2023-03-23  6:54 ` [PATCH v17 20/71] ceph: add encrypted fname handling to ceph_mdsc_build_path xiubli
2023-03-23  6:54 ` [PATCH v17 21/71] ceph: send altname in MClientRequest xiubli
2023-03-23  6:54 ` [PATCH v17 22/71] ceph: encode encrypted name in dentry release xiubli
2023-03-23  6:54 ` [PATCH v17 23/71] ceph: properly set DCACHE_NOKEY_NAME flag in lookup xiubli
2023-03-23  6:54 ` [PATCH v17 24/71] ceph: set DCACHE_NOKEY_NAME in atomic open xiubli
2023-03-23  6:54 ` [PATCH v17 25/71] ceph: make d_revalidate call fscrypt revalidator for encrypted dentries xiubli
2023-03-23  6:54 ` [PATCH v17 26/71] ceph: add helpers for converting names for userland presentation xiubli
2023-03-23  6:54 ` [PATCH v17 27/71] ceph: fix base64 encoded name's length check in ceph_fname_to_usr() xiubli
2023-03-23  6:54 ` [PATCH v17 28/71] ceph: add fscrypt support to ceph_fill_trace xiubli
2023-03-23  6:54 ` [PATCH v17 29/71] ceph: pass the request to parse_reply_info_readdir() xiubli
2023-03-23  6:54 ` [PATCH v17 30/71] ceph: add ceph_encode_encrypted_dname() helper xiubli
2023-03-23  6:54 ` [PATCH v17 31/71] ceph: add support to readdir for encrypted filenames xiubli
2023-03-23  6:54 ` [PATCH v17 32/71] ceph: create symlinks with encrypted and base64-encoded targets xiubli
2023-03-23  6:54 ` [PATCH v17 33/71] ceph: make ceph_get_name decrypt filenames xiubli
2023-03-23  6:54 ` [PATCH v17 34/71] ceph: add a new ceph.fscrypt.auth vxattr xiubli
2023-03-23  6:54 ` [PATCH v17 35/71] ceph: add some fscrypt guardrails xiubli
2023-03-23  6:54 ` [PATCH v17 36/71] ceph: allow encrypting a directory while not having Ax caps xiubli
2023-03-23  6:54 ` [PATCH v17 37/71] ceph: mark directory as non-complete after loading key xiubli
2023-03-23  6:54 ` [PATCH v17 38/71] ceph: don't allow changing layout on encrypted files/directories xiubli
2023-03-23  6:54 ` [PATCH v17 39/71] libceph: add CEPH_OSD_OP_ASSERT_VER support xiubli
2023-03-23  6:54 ` [PATCH v17 40/71] ceph: size handling for encrypted inodes in cap updates xiubli
2023-03-23  6:54 ` [PATCH v17 41/71] ceph: fscrypt_file field handling in MClientRequest messages xiubli
2023-03-23  6:54 ` [PATCH v17 42/71] ceph: get file size from fscrypt_file when present in inode traces xiubli
2023-03-23  6:54 ` [PATCH v17 43/71] ceph: handle fscrypt fields in cap messages from MDS xiubli
2023-03-23  6:54 ` [PATCH v17 44/71] ceph: update WARN_ON message to pr_warn xiubli
2023-03-23  6:54 ` [PATCH v17 45/71] ceph: add __ceph_get_caps helper support xiubli
2023-03-23  6:55 ` [PATCH v17 46/71] ceph: add __ceph_sync_read " xiubli
2023-03-23  6:55 ` [PATCH v17 47/71] ceph: add object version support for sync read xiubli
2023-03-23  6:55 ` [PATCH v17 48/71] ceph: add infrastructure for file encryption and decryption xiubli
2023-03-23  6:55 ` [PATCH v17 49/71] ceph: add truncate size handling support for fscrypt xiubli
2023-03-23  6:55 ` [PATCH v17 50/71] libceph: allow ceph_osdc_new_request to accept a multi-op read xiubli
2023-03-23  6:55 ` [PATCH v17 51/71] ceph: disable fallocate for encrypted inodes xiubli
2023-03-23  6:55 ` [PATCH v17 52/71] ceph: disable copy offload on " xiubli
2023-03-23  6:55 ` [PATCH v17 53/71] ceph: don't use special DIO path for " xiubli
2023-03-23  6:55 ` [PATCH v17 54/71] ceph: align data in pages in ceph_sync_write xiubli
2023-03-23  6:55 ` [PATCH v17 55/71] ceph: add read/modify/write to ceph_sync_write xiubli
2023-03-23  6:55 ` [PATCH v17 56/71] ceph: plumb in decryption during sync reads xiubli
2023-03-23  6:55 ` [PATCH v17 57/71] ceph: add fscrypt decryption support to ceph_netfs_issue_op xiubli
2023-03-23  6:55 ` [PATCH v17 58/71] ceph: set i_blkbits to crypto block size for encrypted inodes xiubli
2023-03-23  6:55 ` [PATCH v17 59/71] ceph: add encryption support to writepage xiubli
2023-03-23  6:55 ` [PATCH v17 60/71] ceph: fscrypt support for writepages xiubli
2023-03-23  6:55 ` [PATCH v17 61/71] ceph: invalidate pages when doing direct/sync writes xiubli
2023-03-23  6:55 ` [PATCH v17 62/71] ceph: add support for encrypted snapshot names xiubli
2023-03-23  6:55 ` [PATCH v17 63/71] ceph: add support for handling " xiubli
2023-03-23  6:55 ` [PATCH v17 64/71] ceph: update documentation regarding snapshot naming limitations xiubli
2023-03-23  6:55 ` [PATCH v17 65/71] ceph: prevent snapshots to be created in encrypted locked directories xiubli
2023-03-23  6:55 ` [PATCH v17 66/71] ceph: report STATX_ATTR_ENCRYPTED on encrypted inodes xiubli
2023-03-23  6:55 ` [PATCH v17 67/71] libceph: defer removing the req from osdc just after req->r_callback xiubli
2023-03-23  6:55 ` [PATCH v17 68/71] ceph: drop the messages from MDS when unmounting xiubli
2023-03-30  4:51   ` Xiubo Li
2023-03-23  6:55 ` [PATCH v17 69/71] ceph: fix updating the i_truncate_pagecache_size for fscrypt xiubli
2023-03-23  6:55 ` [PATCH v17 70/71] ceph: switch ceph_open() to use new fscrypt helper xiubli
2023-03-23  6:55 ` [PATCH v17 71/71] ceph: switch ceph_open_atomic() to use the " xiubli
2023-04-03 14:28 ` [PATCH v17 00/71] ceph+fscrypt: full support Luís Henriques
2023-04-04  0:42   ` Xiubo Li
2023-04-12  8:43     ` Venky Shankar
2023-04-12 10:18       ` Xiubo Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20230323065525.201322-20-xiubli@redhat.com \
    --to=xiubli@redhat.com \
    --cc=ceph-devel@vger.kernel.org \
    --cc=idryomov@gmail.com \
    --cc=jlayton@kernel.org \
    --cc=lhenriques@suse.de \
    --cc=mchangir@redhat.com \
    --cc=vshankar@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.