file_table.c 11.1 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10
/*
 *  linux/fs/file_table.c
 *
 *  Copyright (C) 1991, 1992  Linus Torvalds
 *  Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
 */

#include <linux/string.h>
#include <linux/slab.h>
#include <linux/file.h>
A
Al Viro 已提交
11
#include <linux/fdtable.h>
L
Linus Torvalds 已提交
12 13 14 15
#include <linux/init.h>
#include <linux/module.h>
#include <linux/fs.h>
#include <linux/security.h>
M
Mimi Zohar 已提交
16
#include <linux/ima.h>
L
Linus Torvalds 已提交
17
#include <linux/eventpoll.h>
18
#include <linux/rcupdate.h>
L
Linus Torvalds 已提交
19
#include <linux/mount.h>
20
#include <linux/capability.h>
L
Linus Torvalds 已提交
21
#include <linux/cdev.h>
R
Robert Love 已提交
22
#include <linux/fsnotify.h>
D
Dipankar Sarma 已提交
23 24 25 26
#include <linux/sysctl.h>
#include <linux/percpu_counter.h>

#include <asm/atomic.h>
L
Linus Torvalds 已提交
27 28 29 30 31 32 33

/* sysctl tunables... */
struct files_stat_struct files_stat = {
	.max_files = NR_FILE
};

/* public. Not pretty! */
D
Dipankar Sarma 已提交
34
__cacheline_aligned_in_smp DEFINE_SPINLOCK(files_lock);
L
Linus Torvalds 已提交
35

36 37 38
/* SLAB cache for file structures */
static struct kmem_cache *filp_cachep __read_mostly;

D
Dipankar Sarma 已提交
39
static struct percpu_counter nr_files __cacheline_aligned_in_smp;
L
Linus Torvalds 已提交
40

D
Dipankar Sarma 已提交
41
static inline void file_free_rcu(struct rcu_head *head)
L
Linus Torvalds 已提交
42
{
D
David Howells 已提交
43 44 45
	struct file *f = container_of(head, struct file, f_u.fu_rcuhead);

	put_cred(f->f_cred);
D
Dipankar Sarma 已提交
46
	kmem_cache_free(filp_cachep, f);
L
Linus Torvalds 已提交
47 48
}

D
Dipankar Sarma 已提交
49
static inline void file_free(struct file *f)
L
Linus Torvalds 已提交
50
{
D
Dipankar Sarma 已提交
51
	percpu_counter_dec(&nr_files);
52
	file_check_state(f);
D
Dipankar Sarma 已提交
53
	call_rcu(&f->f_u.fu_rcuhead, file_free_rcu);
L
Linus Torvalds 已提交
54 55
}

D
Dipankar Sarma 已提交
56 57 58 59
/*
 * Return the total number of open files in the system
 */
static int get_nr_files(void)
L
Linus Torvalds 已提交
60
{
D
Dipankar Sarma 已提交
61
	return percpu_counter_read_positive(&nr_files);
L
Linus Torvalds 已提交
62 63
}

D
Dipankar Sarma 已提交
64 65 66 67
/*
 * Return the maximum number of open files in the system
 */
int get_max_files(void)
68
{
D
Dipankar Sarma 已提交
69
	return files_stat.max_files;
70
}
D
Dipankar Sarma 已提交
71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89
EXPORT_SYMBOL_GPL(get_max_files);

/*
 * Handle nr_files sysctl
 */
#if defined(CONFIG_SYSCTL) && defined(CONFIG_PROC_FS)
int proc_nr_files(ctl_table *table, int write, struct file *filp,
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	files_stat.nr_files = get_nr_files();
	return proc_dointvec(table, write, filp, buffer, lenp, ppos);
}
#else
int proc_nr_files(ctl_table *table, int write, struct file *filp,
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	return -ENOSYS;
}
#endif
90

L
Linus Torvalds 已提交
91 92 93
/* Find an unused file structure and return a pointer to it.
 * Returns NULL, if there are no more free file structures or
 * we run out of memory.
D
Dave Hansen 已提交
94 95 96 97 98 99
 *
 * Be very careful using this.  You are responsible for
 * getting write access to any mount that you might assign
 * to this filp, if it is opened for write.  If this is not
 * done, you will imbalance int the mount's writer count
 * and a warning at __fput() time.
L
Linus Torvalds 已提交
100 101 102
 */
struct file *get_empty_filp(void)
{
103
	const struct cred *cred = current_cred();
104
	static int old_max;
L
Linus Torvalds 已提交
105 106 107 108 109
	struct file * f;

	/*
	 * Privileged users can go above max_files
	 */
D
Dipankar Sarma 已提交
110 111 112 113 114
	if (get_nr_files() >= files_stat.max_files && !capable(CAP_SYS_ADMIN)) {
		/*
		 * percpu_counters are inaccurate.  Do an expensive check before
		 * we go and fail.
		 */
P
Peter Zijlstra 已提交
115
		if (percpu_counter_sum_positive(&nr_files) >= files_stat.max_files)
D
Dipankar Sarma 已提交
116 117
			goto over;
	}
118

D
Denis Cheng 已提交
119
	f = kmem_cache_zalloc(filp_cachep, GFP_KERNEL);
120 121 122
	if (f == NULL)
		goto fail;

D
Dipankar Sarma 已提交
123
	percpu_counter_inc(&nr_files);
124 125
	if (security_file_alloc(f))
		goto fail_sec;
L
Linus Torvalds 已提交
126

127
	INIT_LIST_HEAD(&f->f_u.fu_list);
A
Al Viro 已提交
128
	atomic_long_set(&f->f_count, 1);
129
	rwlock_init(&f->f_owner.lock);
D
David Howells 已提交
130
	f->f_cred = get_cred(cred);
J
Jonathan Corbet 已提交
131
	spin_lock_init(&f->f_lock);
132
	eventpoll_init_file(f);
133 134 135 136
	/* f->f_version: 0 */
	return f;

over:
L
Linus Torvalds 已提交
137
	/* Ran out of filps - report that */
D
Dipankar Sarma 已提交
138
	if (get_nr_files() > old_max) {
L
Linus Torvalds 已提交
139
		printk(KERN_INFO "VFS: file-max limit %d reached\n",
D
Dipankar Sarma 已提交
140 141
					get_max_files());
		old_max = get_nr_files();
L
Linus Torvalds 已提交
142
	}
143 144 145 146
	goto fail;

fail_sec:
	file_free(f);
L
Linus Torvalds 已提交
147 148 149 150 151 152
fail:
	return NULL;
}

EXPORT_SYMBOL(get_empty_filp);

153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168
/**
 * alloc_file - allocate and initialize a 'struct file'
 * @mnt: the vfsmount on which the file will reside
 * @dentry: the dentry representing the new file
 * @mode: the mode with which the new file will be opened
 * @fop: the 'struct file_operations' for the new file
 *
 * Use this instead of get_empty_filp() to get a new
 * 'struct file'.  Do so because of the same initialization
 * pitfalls reasons listed for init_file().  This is a
 * preferred interface to using init_file().
 *
 * If all the callers of init_file() are eliminated, its
 * code should be moved into this function.
 */
struct file *alloc_file(struct vfsmount *mnt, struct dentry *dentry,
169
		fmode_t mode, const struct file_operations *fop)
170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199
{
	struct file *file;

	file = get_empty_filp();
	if (!file)
		return NULL;

	init_file(file, mnt, dentry, mode, fop);
	return file;
}
EXPORT_SYMBOL(alloc_file);

/**
 * init_file - initialize a 'struct file'
 * @file: the already allocated 'struct file' to initialized
 * @mnt: the vfsmount on which the file resides
 * @dentry: the dentry representing this file
 * @mode: the mode the file is opened with
 * @fop: the 'struct file_operations' for this file
 *
 * Use this instead of setting the members directly.  Doing so
 * avoids making mistakes like forgetting the mntget() or
 * forgetting to take a write on the mnt.
 *
 * Note: This is a crappy interface.  It is here to make
 * merging with the existing users of get_empty_filp()
 * who have complex failure logic easier.  All users
 * of this should be moving to alloc_file().
 */
int init_file(struct file *file, struct vfsmount *mnt, struct dentry *dentry,
200
	   fmode_t mode, const struct file_operations *fop)
201 202 203 204 205 206 207
{
	int error = 0;
	file->f_path.dentry = dentry;
	file->f_path.mnt = mntget(mnt);
	file->f_mapping = dentry->d_inode->i_mapping;
	file->f_mode = mode;
	file->f_op = fop;
208 209 210 211 212 213 214 215

	/*
	 * These mounts don't really matter in practice
	 * for r/o bind mounts.  They aren't userspace-
	 * visible.  We do this for consistency, and so
	 * that we can do debugging checks at __fput()
	 */
	if ((mode & FMODE_WRITE) && !special_file(dentry->d_inode->i_mode)) {
216
		file_take_write(file);
N
npiggin@suse.de 已提交
217
		error = mnt_clone_write(mnt);
218 219
		WARN_ON(error);
	}
220 221 222 223
	return error;
}
EXPORT_SYMBOL(init_file);

224
void fput(struct file *file)
L
Linus Torvalds 已提交
225
{
A
Al Viro 已提交
226
	if (atomic_long_dec_and_test(&file->f_count))
L
Linus Torvalds 已提交
227 228 229 230 231
		__fput(file);
}

EXPORT_SYMBOL(fput);

232 233 234 235 236 237 238 239 240 241
/**
 * drop_file_write_access - give up ability to write to a file
 * @file: the file to which we will stop writing
 *
 * This is a central place which will give up the ability
 * to write to @file, along with access to write through
 * its vfsmount.
 */
void drop_file_write_access(struct file *file)
{
242
	struct vfsmount *mnt = file->f_path.mnt;
243 244 245 246
	struct dentry *dentry = file->f_path.dentry;
	struct inode *inode = dentry->d_inode;

	put_write_access(inode);
247 248 249 250 251 252 253

	if (special_file(inode->i_mode))
		return;
	if (file_check_writeable(file) != 0)
		return;
	mnt_drop_write(mnt);
	file_release_write(file);
254 255 256
}
EXPORT_SYMBOL_GPL(drop_file_write_access);

L
Linus Torvalds 已提交
257 258 259
/* __fput is called from task context when aio completion releases the last
 * last use of a struct file *.  Do not use otherwise.
 */
260
void __fput(struct file *file)
L
Linus Torvalds 已提交
261
{
262 263
	struct dentry *dentry = file->f_path.dentry;
	struct vfsmount *mnt = file->f_path.mnt;
L
Linus Torvalds 已提交
264 265 266
	struct inode *inode = dentry->d_inode;

	might_sleep();
R
Robert Love 已提交
267 268

	fsnotify_close(file);
L
Linus Torvalds 已提交
269 270 271 272 273 274 275
	/*
	 * The function eventpoll_release() should be the first called
	 * in the file cleanup chain.
	 */
	eventpoll_release(file);
	locks_remove_flock(file);

A
Al Viro 已提交
276 277 278 279
	if (unlikely(file->f_flags & FASYNC)) {
		if (file->f_op && file->f_op->fasync)
			file->f_op->fasync(-1, file, 0);
	}
L
Linus Torvalds 已提交
280 281 282
	if (file->f_op && file->f_op->release)
		file->f_op->release(inode, file);
	security_file_free(file);
M
Mimi Zohar 已提交
283
	ima_file_free(file);
284
	if (unlikely(S_ISCHR(inode->i_mode) && inode->i_cdev != NULL))
L
Linus Torvalds 已提交
285 286
		cdev_put(inode->i_cdev);
	fops_put(file->f_op);
287
	put_pid(file->f_owner.pid);
L
Linus Torvalds 已提交
288
	file_kill(file);
289 290
	if (file->f_mode & FMODE_WRITE)
		drop_file_write_access(file);
291 292
	file->f_path.dentry = NULL;
	file->f_path.mnt = NULL;
L
Linus Torvalds 已提交
293 294 295 296 297
	file_free(file);
	dput(dentry);
	mntput(mnt);
}

298
struct file *fget(unsigned int fd)
L
Linus Torvalds 已提交
299 300 301 302
{
	struct file *file;
	struct files_struct *files = current->files;

303
	rcu_read_lock();
L
Linus Torvalds 已提交
304
	file = fcheck_files(files, fd);
305
	if (file) {
A
Al Viro 已提交
306
		if (!atomic_long_inc_not_zero(&file->f_count)) {
307 308 309 310 311 312 313
			/* File object ref couldn't be taken */
			rcu_read_unlock();
			return NULL;
		}
	}
	rcu_read_unlock();

L
Linus Torvalds 已提交
314 315 316 317 318 319 320 321 322 323 324 325
	return file;
}

EXPORT_SYMBOL(fget);

/*
 * Lightweight file lookup - no refcnt increment if fd table isn't shared. 
 * You can use this only if it is guranteed that the current task already 
 * holds a refcnt to that file. That check has to be done at fget() only
 * and a flag is returned to be passed to the corresponding fput_light().
 * There must not be a cloning between an fget_light/fput_light pair.
 */
326
struct file *fget_light(unsigned int fd, int *fput_needed)
L
Linus Torvalds 已提交
327 328 329 330 331 332 333 334
{
	struct file *file;
	struct files_struct *files = current->files;

	*fput_needed = 0;
	if (likely((atomic_read(&files->count) == 1))) {
		file = fcheck_files(files, fd);
	} else {
335
		rcu_read_lock();
L
Linus Torvalds 已提交
336 337
		file = fcheck_files(files, fd);
		if (file) {
A
Al Viro 已提交
338
			if (atomic_long_inc_not_zero(&file->f_count))
339 340 341 342
				*fput_needed = 1;
			else
				/* Didn't get the reference, someone's freed */
				file = NULL;
L
Linus Torvalds 已提交
343
		}
344
		rcu_read_unlock();
L
Linus Torvalds 已提交
345
	}
346

L
Linus Torvalds 已提交
347 348 349 350 351 352
	return file;
}


void put_filp(struct file *file)
{
A
Al Viro 已提交
353
	if (atomic_long_dec_and_test(&file->f_count)) {
L
Linus Torvalds 已提交
354 355 356 357 358 359 360 361 362 363 364
		security_file_free(file);
		file_kill(file);
		file_free(file);
	}
}

void file_move(struct file *file, struct list_head *list)
{
	if (!list)
		return;
	file_list_lock();
E
Eric Dumazet 已提交
365
	list_move(&file->f_u.fu_list, list);
L
Linus Torvalds 已提交
366 367 368 369 370
	file_list_unlock();
}

void file_kill(struct file *file)
{
E
Eric Dumazet 已提交
371
	if (!list_empty(&file->f_u.fu_list)) {
L
Linus Torvalds 已提交
372
		file_list_lock();
E
Eric Dumazet 已提交
373
		list_del_init(&file->f_u.fu_list);
L
Linus Torvalds 已提交
374 375 376 377 378 379
		file_list_unlock();
	}
}

int fs_may_remount_ro(struct super_block *sb)
{
380
	struct file *file;
L
Linus Torvalds 已提交
381 382 383

	/* Check that no files are currently opened for writing. */
	file_list_lock();
384
	list_for_each_entry(file, &sb->s_files, f_u.fu_list) {
385
		struct inode *inode = file->f_path.dentry->d_inode;
L
Linus Torvalds 已提交
386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401

		/* File with pending delete? */
		if (inode->i_nlink == 0)
			goto too_bad;

		/* Writeable file? */
		if (S_ISREG(inode->i_mode) && (file->f_mode & FMODE_WRITE))
			goto too_bad;
	}
	file_list_unlock();
	return 1; /* Tis' cool bro. */
too_bad:
	file_list_unlock();
	return 0;
}

402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439
/**
 *	mark_files_ro - mark all files read-only
 *	@sb: superblock in question
 *
 *	All files are marked read-only.  We don't care about pending
 *	delete files so this should be used in 'force' mode only.
 */
void mark_files_ro(struct super_block *sb)
{
	struct file *f;

retry:
	file_list_lock();
	list_for_each_entry(f, &sb->s_files, f_u.fu_list) {
		struct vfsmount *mnt;
		if (!S_ISREG(f->f_path.dentry->d_inode->i_mode))
		       continue;
		if (!file_count(f))
			continue;
		if (!(f->f_mode & FMODE_WRITE))
			continue;
		f->f_mode &= ~FMODE_WRITE;
		if (file_check_writeable(f) != 0)
			continue;
		file_release_write(f);
		mnt = mntget(f->f_path.mnt);
		file_list_unlock();
		/*
		 * This can sleep, so we can't hold
		 * the file_list_lock() spinlock.
		 */
		mnt_drop_write(mnt);
		mntput(mnt);
		goto retry;
	}
	file_list_unlock();
}

L
Linus Torvalds 已提交
440 441 442
void __init files_init(unsigned long mempages)
{ 
	int n; 
443 444 445 446 447 448

	filp_cachep = kmem_cache_create("filp", sizeof(struct file), 0,
			SLAB_HWCACHE_ALIGN | SLAB_PANIC, NULL);

	/*
	 * One file with associated inode and dcache is very roughly 1K.
L
Linus Torvalds 已提交
449 450 451 452 453 454 455
	 * Per default don't use more than 10% of our memory for files. 
	 */ 

	n = (mempages * (PAGE_SIZE / 1024)) / 10;
	files_stat.max_files = n; 
	if (files_stat.max_files < NR_FILE)
		files_stat.max_files = NR_FILE;
456
	files_defer_init();
457
	percpu_counter_init(&nr_files, 0);
L
Linus Torvalds 已提交
458
}