ceph: encode encrypted name in ceph_mdsc_build_path and dentry release
authorJeff Layton <jlayton@kernel.org>
Fri, 7 Aug 2020 13:28:31 +0000 (09:28 -0400)
committerIlya Dryomov <idryomov@gmail.com>
Thu, 24 Aug 2023 09:22:37 +0000 (11:22 +0200)
commit3fd945a79e147ee10f84213976889b29049c3519
tree35f11e5ae8d4f549c216ee61229e2421e6ef951b
parent64e86f632bf148d007946c52781781eb8380d416
ceph: encode encrypted name in ceph_mdsc_build_path and dentry release

Allow ceph_mdsc_build_path to encrypt and base64 encode the filename
when the parent is encrypted and we're sending the path to the MDS. In
a similar fashion, encode encrypted dentry names if including a dentry
release in a request.

In most cases, we just encrypt the filenames and base64 encode them,
but when the name is longer than CEPH_NOHASH_NAME_MAX, we use a similar
scheme to fscrypt proper, and hash the remaning bits with sha256.

When doing this, we then send along the full crypttext of the name in
the new alternate_name field of the MClientRequest. The MDS can then
send that along in readdir responses and traces.

[ idryomov: drop duplicate include reported by Abaci Robot ]

Signed-off-by: Jeff Layton <jlayton@kernel.org>
Reviewed-by: Xiubo Li <xiubli@redhat.com>
Reviewed-and-tested-by: Luís Henriques <lhenriques@suse.de>
Reviewed-by: Milind Changire <mchangir@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
fs/ceph/caps.c
fs/ceph/crypto.c
fs/ceph/crypto.h
fs/ceph/mds_client.c
fs/ceph/mds_client.h