file_table.c 9.5 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10
/*
 *  linux/fs/file_table.c
 *
 *  Copyright (C) 1991, 1992  Linus Torvalds
 *  Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
 */

#include <linux/string.h>
#include <linux/slab.h>
#include <linux/file.h>
A
Al Viro 已提交
11
#include <linux/fdtable.h>
L
Linus Torvalds 已提交
12 13 14 15
#include <linux/init.h>
#include <linux/module.h>
#include <linux/fs.h>
#include <linux/security.h>
16
#include <linux/cred.h>
L
Linus Torvalds 已提交
17
#include <linux/eventpoll.h>
18
#include <linux/rcupdate.h>
L
Linus Torvalds 已提交
19
#include <linux/mount.h>
20
#include <linux/capability.h>
L
Linus Torvalds 已提交
21
#include <linux/cdev.h>
R
Robert Love 已提交
22
#include <linux/fsnotify.h>
D
Dipankar Sarma 已提交
23 24
#include <linux/sysctl.h>
#include <linux/percpu_counter.h>
N
Nick Piggin 已提交
25
#include <linux/percpu.h>
A
Al Viro 已提交
26
#include <linux/task_work.h>
27
#include <linux/ima.h>
28
#include <linux/swap.h>
D
Dipankar Sarma 已提交
29

A
Arun Sharma 已提交
30
#include <linux/atomic.h>
L
Linus Torvalds 已提交
31

32 33
#include "internal.h"

L
Linus Torvalds 已提交
34 35 36 37 38
/* sysctl tunables... */
struct files_stat_struct files_stat = {
	.max_files = NR_FILE
};

39 40 41
/* SLAB cache for file structures */
static struct kmem_cache *filp_cachep __read_mostly;

D
Dipankar Sarma 已提交
42
static struct percpu_counter nr_files __cacheline_aligned_in_smp;
L
Linus Torvalds 已提交
43

A
Al Viro 已提交
44
static void file_free_rcu(struct rcu_head *head)
L
Linus Torvalds 已提交
45
{
D
David Howells 已提交
46 47 48
	struct file *f = container_of(head, struct file, f_u.fu_rcuhead);

	put_cred(f->f_cred);
D
Dipankar Sarma 已提交
49
	kmem_cache_free(filp_cachep, f);
L
Linus Torvalds 已提交
50 51
}

D
Dipankar Sarma 已提交
52
static inline void file_free(struct file *f)
L
Linus Torvalds 已提交
53
{
54
	security_file_free(f);
D
Dipankar Sarma 已提交
55 56
	percpu_counter_dec(&nr_files);
	call_rcu(&f->f_u.fu_rcuhead, file_free_rcu);
L
Linus Torvalds 已提交
57 58
}

D
Dipankar Sarma 已提交
59 60 61
/*
 * Return the total number of open files in the system
 */
E
Eric Dumazet 已提交
62
static long get_nr_files(void)
L
Linus Torvalds 已提交
63
{
D
Dipankar Sarma 已提交
64
	return percpu_counter_read_positive(&nr_files);
L
Linus Torvalds 已提交
65 66
}

D
Dipankar Sarma 已提交
67 68 69
/*
 * Return the maximum number of open files in the system
 */
E
Eric Dumazet 已提交
70
unsigned long get_max_files(void)
71
{
D
Dipankar Sarma 已提交
72
	return files_stat.max_files;
73
}
D
Dipankar Sarma 已提交
74 75 76 77 78 79
EXPORT_SYMBOL_GPL(get_max_files);

/*
 * Handle nr_files sysctl
 */
#if defined(CONFIG_SYSCTL) && defined(CONFIG_PROC_FS)
80
int proc_nr_files(struct ctl_table *table, int write,
D
Dipankar Sarma 已提交
81 82 83
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	files_stat.nr_files = get_nr_files();
E
Eric Dumazet 已提交
84
	return proc_doulongvec_minmax(table, write, buffer, lenp, ppos);
D
Dipankar Sarma 已提交
85 86
}
#else
87
int proc_nr_files(struct ctl_table *table, int write,
D
Dipankar Sarma 已提交
88 89 90 91 92
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	return -ENOSYS;
}
#endif
93

L
Linus Torvalds 已提交
94
/* Find an unused file structure and return a pointer to it.
95 96
 * Returns an error pointer if some error happend e.g. we over file
 * structures limit, run out of memory or operation is not permitted.
D
Dave Hansen 已提交
97 98 99 100 101 102
 *
 * Be very careful using this.  You are responsible for
 * getting write access to any mount that you might assign
 * to this filp, if it is opened for write.  If this is not
 * done, you will imbalance int the mount's writer count
 * and a warning at __fput() time.
L
Linus Torvalds 已提交
103
 */
104
struct file *alloc_empty_file(int flags, const struct cred *cred)
L
Linus Torvalds 已提交
105
{
E
Eric Dumazet 已提交
106
	static long old_max;
107 108
	struct file *f;
	int error;
L
Linus Torvalds 已提交
109 110 111 112

	/*
	 * Privileged users can go above max_files
	 */
D
Dipankar Sarma 已提交
113 114 115 116 117
	if (get_nr_files() >= files_stat.max_files && !capable(CAP_SYS_ADMIN)) {
		/*
		 * percpu_counters are inaccurate.  Do an expensive check before
		 * we go and fail.
		 */
P
Peter Zijlstra 已提交
118
		if (percpu_counter_sum_positive(&nr_files) >= files_stat.max_files)
D
Dipankar Sarma 已提交
119 120
			goto over;
	}
121

D
Denis Cheng 已提交
122
	f = kmem_cache_zalloc(filp_cachep, GFP_KERNEL);
123 124
	if (unlikely(!f))
		return ERR_PTR(-ENOMEM);
125

126
	f->f_cred = get_cred(cred);
127 128
	error = security_file_alloc(f);
	if (unlikely(error)) {
129
		file_free_rcu(&f->f_u.fu_rcuhead);
130 131
		return ERR_PTR(error);
	}
L
Linus Torvalds 已提交
132

A
Al Viro 已提交
133
	atomic_long_set(&f->f_count, 1);
134
	rwlock_init(&f->f_owner.lock);
J
Jonathan Corbet 已提交
135
	spin_lock_init(&f->f_lock);
136
	mutex_init(&f->f_pos_lock);
137
	eventpoll_init_file(f);
138 139
	f->f_flags = flags;
	f->f_mode = OPEN_FMODE(flags);
140
	/* f->f_version: 0 */
141
	percpu_counter_inc(&nr_files);
142 143 144
	return f;

over:
L
Linus Torvalds 已提交
145
	/* Ran out of filps - report that */
D
Dipankar Sarma 已提交
146
	if (get_nr_files() > old_max) {
E
Eric Dumazet 已提交
147
		pr_info("VFS: file-max limit %lu reached\n", get_max_files());
D
Dipankar Sarma 已提交
148
		old_max = get_nr_files();
L
Linus Torvalds 已提交
149
	}
150
	return ERR_PTR(-ENFILE);
L
Linus Torvalds 已提交
151 152
}

153 154
/**
 * alloc_file - allocate and initialize a 'struct file'
155 156
 *
 * @path: the (dentry, vfsmount) pair for the new file
157
 * @flags: O_... flags with which the new file will be opened
158 159
 * @fop: the 'struct file_operations' for the new file
 */
160
struct file *alloc_file(const struct path *path, int flags,
161
		const struct file_operations *fop)
162 163 164
{
	struct file *file;

165
	file = alloc_empty_file(flags, current_cred());
166
	if (IS_ERR(file))
167
		return file;
168

169
	file->f_path = *path;
170
	file->f_inode = path->dentry->d_inode;
171
	file->f_mapping = path->dentry->d_inode->i_mapping;
172
	file->f_wb_err = filemap_sample_wb_err(file->f_mapping);
173
	if ((file->f_mode & FMODE_READ) &&
A
Al Viro 已提交
174
	     likely(fop->read || fop->read_iter))
175 176
		file->f_mode |= FMODE_CAN_READ;
	if ((file->f_mode & FMODE_WRITE) &&
A
Al Viro 已提交
177
	     likely(fop->write || fop->write_iter))
178
		file->f_mode |= FMODE_CAN_WRITE;
A
Al Viro 已提交
179
	file->f_mode |= FMODE_OPENED;
180
	file->f_op = fop;
181
	if ((file->f_mode & (FMODE_READ | FMODE_WRITE)) == FMODE_READ)
182
		i_readcount_inc(path->dentry->d_inode);
A
Al Viro 已提交
183
	return file;
184
}
R
Roland Dreier 已提交
185
EXPORT_SYMBOL(alloc_file);
186

A
Al Viro 已提交
187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213
struct file *alloc_file_pseudo(struct inode *inode, struct vfsmount *mnt,
				const char *name, int flags,
				const struct file_operations *fops)
{
	static const struct dentry_operations anon_ops = {
		.d_dname = simple_dname
	};
	struct qstr this = QSTR_INIT(name, strlen(name));
	struct path path;
	struct file *file;

	path.dentry = d_alloc_pseudo(mnt->mnt_sb, &this);
	if (!path.dentry)
		return ERR_PTR(-ENOMEM);
	if (!mnt->mnt_sb->s_d_op)
		d_set_d_op(path.dentry, &anon_ops);
	path.mnt = mntget(mnt);
	d_instantiate(path.dentry, inode);
	file = alloc_file(&path, flags, fops);
	if (IS_ERR(file)) {
		ihold(inode);
		path_put(&path);
	}
	return file;
}
EXPORT_SYMBOL(alloc_file_pseudo);

A
Al Viro 已提交
214 215 216 217 218 219 220 221 222 223 224
struct file *alloc_file_clone(struct file *base, int flags,
				const struct file_operations *fops)
{
	struct file *f = alloc_file(&base->f_path, flags, fops);
	if (!IS_ERR(f)) {
		path_get(&f->f_path);
		f->f_mapping = base->f_mapping;
	}
	return f;
}

225
/* the real guts of fput() - releasing the last reference to file
L
Linus Torvalds 已提交
226
 */
227
static void __fput(struct file *file)
L
Linus Torvalds 已提交
228
{
229 230
	struct dentry *dentry = file->f_path.dentry;
	struct vfsmount *mnt = file->f_path.mnt;
231
	struct inode *inode = file->f_inode;
L
Linus Torvalds 已提交
232

A
Al Viro 已提交
233 234 235
	if (unlikely(!(file->f_mode & FMODE_OPENED)))
		goto out;

L
Linus Torvalds 已提交
236
	might_sleep();
R
Robert Love 已提交
237 238

	fsnotify_close(file);
L
Linus Torvalds 已提交
239 240 241 242 243
	/*
	 * The function eventpoll_release() should be the first called
	 * in the file cleanup chain.
	 */
	eventpoll_release(file);
244
	locks_remove_file(file);
L
Linus Torvalds 已提交
245

246
	ima_file_free(file);
A
Al Viro 已提交
247
	if (unlikely(file->f_flags & FASYNC)) {
A
Al Viro 已提交
248
		if (file->f_op->fasync)
A
Al Viro 已提交
249 250
			file->f_op->fasync(-1, file, 0);
	}
A
Al Viro 已提交
251
	if (file->f_op->release)
L
Linus Torvalds 已提交
252
		file->f_op->release(inode, file);
253 254
	if (unlikely(S_ISCHR(inode->i_mode) && inode->i_cdev != NULL &&
		     !(file->f_mode & FMODE_PATH))) {
L
Linus Torvalds 已提交
255
		cdev_put(inode->i_cdev);
256
	}
L
Linus Torvalds 已提交
257
	fops_put(file->f_op);
258
	put_pid(file->f_owner.pid);
259 260
	if ((file->f_mode & (FMODE_READ | FMODE_WRITE)) == FMODE_READ)
		i_readcount_dec(inode);
261 262 263 264
	if (file->f_mode & FMODE_WRITER) {
		put_write_access(inode);
		__mnt_drop_write(mnt);
	}
L
Linus Torvalds 已提交
265 266
	dput(dentry);
	mntput(mnt);
A
Al Viro 已提交
267 268
out:
	file_free(file);
L
Linus Torvalds 已提交
269 270
}

271
static LLIST_HEAD(delayed_fput_list);
A
Al Viro 已提交
272 273
static void delayed_fput(struct work_struct *unused)
{
274
	struct llist_node *node = llist_del_all(&delayed_fput_list);
275
	struct file *f, *t;
276

277 278
	llist_for_each_entry_safe(f, t, node, f_u.fu_llist)
		__fput(f);
A
Al Viro 已提交
279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300
}

static void ____fput(struct callback_head *work)
{
	__fput(container_of(work, struct file, f_u.fu_rcuhead));
}

/*
 * If kernel thread really needs to have the final fput() it has done
 * to complete, call this.  The only user right now is the boot - we
 * *do* need to make sure our writes to binaries on initramfs has
 * not left us with opened struct file waiting for __fput() - execve()
 * won't work without that.  Please, don't add more callers without
 * very good reasons; in particular, never call that with locks
 * held and never call that from a thread that might need to do
 * some work on any kind of umount.
 */
void flush_delayed_fput(void)
{
	delayed_fput(NULL);
}

A
Al Viro 已提交
301
static DECLARE_DELAYED_WORK(delayed_fput_work, delayed_fput);
A
Al Viro 已提交
302

303 304
void fput(struct file *file)
{
A
Al Viro 已提交
305 306
	if (atomic_long_dec_and_test(&file->f_count)) {
		struct task_struct *task = current;
307 308 309 310 311

		if (likely(!in_interrupt() && !(task->flags & PF_KTHREAD))) {
			init_task_work(&file->f_u.fu_rcuhead, ____fput);
			if (!task_work_add(task, &file->f_u.fu_rcuhead, true))
				return;
312 313
			/*
			 * After this task has run exit_task_work(),
314
			 * task_work_add() will fail.  Fall through to delayed
315 316
			 * fput to avoid leaking *file.
			 */
A
Al Viro 已提交
317
		}
318 319

		if (llist_add(&file->f_u.fu_llist, &delayed_fput_list))
A
Al Viro 已提交
320
			schedule_delayed_work(&delayed_fput_work, 1);
A
Al Viro 已提交
321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336
	}
}

/*
 * synchronous analog of fput(); for kernel threads that might be needed
 * in some umount() (and thus can't use flush_delayed_fput() without
 * risking deadlocks), need to wait for completion of __fput() and know
 * for this specific struct file it won't involve anything that would
 * need them.  Use only if you really need it - at the very least,
 * don't blindly convert fput() by kernel thread to that.
 */
void __fput_sync(struct file *file)
{
	if (atomic_long_dec_and_test(&file->f_count)) {
		struct task_struct *task = current;
		BUG_ON(!(task->flags & PF_KTHREAD));
337
		__fput(file);
A
Al Viro 已提交
338
	}
339 340 341 342
}

EXPORT_SYMBOL(fput);

343
void __init files_init(void)
344
{
345
	filp_cachep = kmem_cache_create("filp", sizeof(struct file), 0,
346
			SLAB_HWCACHE_ALIGN | SLAB_PANIC | SLAB_ACCOUNT, NULL);
347 348
	percpu_counter_init(&nr_files, 0, GFP_KERNEL);
}
349

350 351 352 353 354 355 356 357 358 359 360
/*
 * One file with associated inode and dcache is very roughly 1K. Per default
 * do not use more than 10% of our memory for files.
 */
void __init files_maxfiles_init(void)
{
	unsigned long n;
	unsigned long memreserve = (totalram_pages - nr_free_pages()) * 3/2;

	memreserve = min(memreserve, totalram_pages - 1);
	n = ((totalram_pages - memreserve) * (PAGE_SIZE / 1024)) / 10;
L
Linus Torvalds 已提交
361

E
Eric Dumazet 已提交
362
	files_stat.max_files = max_t(unsigned long, n, NR_FILE);
363
}