file_table.c 14.6 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10
/*
 *  linux/fs/file_table.c
 *
 *  Copyright (C) 1991, 1992  Linus Torvalds
 *  Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
 */

#include <linux/string.h>
#include <linux/slab.h>
#include <linux/file.h>
A
Al Viro 已提交
11
#include <linux/fdtable.h>
L
Linus Torvalds 已提交
12 13 14 15 16
#include <linux/init.h>
#include <linux/module.h>
#include <linux/fs.h>
#include <linux/security.h>
#include <linux/eventpoll.h>
17
#include <linux/rcupdate.h>
L
Linus Torvalds 已提交
18
#include <linux/mount.h>
19
#include <linux/capability.h>
L
Linus Torvalds 已提交
20
#include <linux/cdev.h>
R
Robert Love 已提交
21
#include <linux/fsnotify.h>
D
Dipankar Sarma 已提交
22
#include <linux/sysctl.h>
N
Nick Piggin 已提交
23
#include <linux/lglock.h>
D
Dipankar Sarma 已提交
24
#include <linux/percpu_counter.h>
N
Nick Piggin 已提交
25
#include <linux/percpu.h>
A
Al Viro 已提交
26 27
#include <linux/hardirq.h>
#include <linux/task_work.h>
28
#include <linux/ima.h>
D
Dipankar Sarma 已提交
29

A
Arun Sharma 已提交
30
#include <linux/atomic.h>
L
Linus Torvalds 已提交
31

32 33
#include "internal.h"

L
Linus Torvalds 已提交
34 35 36 37 38
/* sysctl tunables... */
struct files_stat_struct files_stat = {
	.max_files = NR_FILE
};

N
Nick Piggin 已提交
39
DEFINE_LGLOCK(files_lglock);
L
Linus Torvalds 已提交
40

41 42 43
/* SLAB cache for file structures */
static struct kmem_cache *filp_cachep __read_mostly;

D
Dipankar Sarma 已提交
44
static struct percpu_counter nr_files __cacheline_aligned_in_smp;
L
Linus Torvalds 已提交
45

A
Al Viro 已提交
46
static void file_free_rcu(struct rcu_head *head)
L
Linus Torvalds 已提交
47
{
D
David Howells 已提交
48 49 50
	struct file *f = container_of(head, struct file, f_u.fu_rcuhead);

	put_cred(f->f_cred);
D
Dipankar Sarma 已提交
51
	kmem_cache_free(filp_cachep, f);
L
Linus Torvalds 已提交
52 53
}

D
Dipankar Sarma 已提交
54
static inline void file_free(struct file *f)
L
Linus Torvalds 已提交
55
{
D
Dipankar Sarma 已提交
56
	percpu_counter_dec(&nr_files);
57
	file_check_state(f);
D
Dipankar Sarma 已提交
58
	call_rcu(&f->f_u.fu_rcuhead, file_free_rcu);
L
Linus Torvalds 已提交
59 60
}

D
Dipankar Sarma 已提交
61 62 63
/*
 * Return the total number of open files in the system
 */
E
Eric Dumazet 已提交
64
static long get_nr_files(void)
L
Linus Torvalds 已提交
65
{
D
Dipankar Sarma 已提交
66
	return percpu_counter_read_positive(&nr_files);
L
Linus Torvalds 已提交
67 68
}

D
Dipankar Sarma 已提交
69 70 71
/*
 * Return the maximum number of open files in the system
 */
E
Eric Dumazet 已提交
72
unsigned long get_max_files(void)
73
{
D
Dipankar Sarma 已提交
74
	return files_stat.max_files;
75
}
D
Dipankar Sarma 已提交
76 77 78 79 80 81
EXPORT_SYMBOL_GPL(get_max_files);

/*
 * Handle nr_files sysctl
 */
#if defined(CONFIG_SYSCTL) && defined(CONFIG_PROC_FS)
82
int proc_nr_files(ctl_table *table, int write,
D
Dipankar Sarma 已提交
83 84 85
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	files_stat.nr_files = get_nr_files();
E
Eric Dumazet 已提交
86
	return proc_doulongvec_minmax(table, write, buffer, lenp, ppos);
D
Dipankar Sarma 已提交
87 88
}
#else
89
int proc_nr_files(ctl_table *table, int write,
D
Dipankar Sarma 已提交
90 91 92 93 94
                     void __user *buffer, size_t *lenp, loff_t *ppos)
{
	return -ENOSYS;
}
#endif
95

L
Linus Torvalds 已提交
96 97 98
/* Find an unused file structure and return a pointer to it.
 * Returns NULL, if there are no more free file structures or
 * we run out of memory.
D
Dave Hansen 已提交
99 100 101 102 103 104
 *
 * Be very careful using this.  You are responsible for
 * getting write access to any mount that you might assign
 * to this filp, if it is opened for write.  If this is not
 * done, you will imbalance int the mount's writer count
 * and a warning at __fput() time.
L
Linus Torvalds 已提交
105 106 107
 */
struct file *get_empty_filp(void)
{
108
	const struct cred *cred = current_cred();
E
Eric Dumazet 已提交
109
	static long old_max;
L
Linus Torvalds 已提交
110 111 112 113 114
	struct file * f;

	/*
	 * Privileged users can go above max_files
	 */
D
Dipankar Sarma 已提交
115 116 117 118 119
	if (get_nr_files() >= files_stat.max_files && !capable(CAP_SYS_ADMIN)) {
		/*
		 * percpu_counters are inaccurate.  Do an expensive check before
		 * we go and fail.
		 */
P
Peter Zijlstra 已提交
120
		if (percpu_counter_sum_positive(&nr_files) >= files_stat.max_files)
D
Dipankar Sarma 已提交
121 122
			goto over;
	}
123

D
Denis Cheng 已提交
124
	f = kmem_cache_zalloc(filp_cachep, GFP_KERNEL);
125 126 127
	if (f == NULL)
		goto fail;

D
Dipankar Sarma 已提交
128
	percpu_counter_inc(&nr_files);
129
	f->f_cred = get_cred(cred);
130 131
	if (security_file_alloc(f))
		goto fail_sec;
L
Linus Torvalds 已提交
132

133
	INIT_LIST_HEAD(&f->f_u.fu_list);
A
Al Viro 已提交
134
	atomic_long_set(&f->f_count, 1);
135
	rwlock_init(&f->f_owner.lock);
J
Jonathan Corbet 已提交
136
	spin_lock_init(&f->f_lock);
137
	eventpoll_init_file(f);
138 139 140 141
	/* f->f_version: 0 */
	return f;

over:
L
Linus Torvalds 已提交
142
	/* Ran out of filps - report that */
D
Dipankar Sarma 已提交
143
	if (get_nr_files() > old_max) {
E
Eric Dumazet 已提交
144
		pr_info("VFS: file-max limit %lu reached\n", get_max_files());
D
Dipankar Sarma 已提交
145
		old_max = get_nr_files();
L
Linus Torvalds 已提交
146
	}
147 148 149 150
	goto fail;

fail_sec:
	file_free(f);
L
Linus Torvalds 已提交
151 152 153 154
fail:
	return NULL;
}

155 156 157 158 159 160 161 162 163 164 165 166 167 168 169
/**
 * alloc_file - allocate and initialize a 'struct file'
 * @mnt: the vfsmount on which the file will reside
 * @dentry: the dentry representing the new file
 * @mode: the mode with which the new file will be opened
 * @fop: the 'struct file_operations' for the new file
 *
 * Use this instead of get_empty_filp() to get a new
 * 'struct file'.  Do so because of the same initialization
 * pitfalls reasons listed for init_file().  This is a
 * preferred interface to using init_file().
 *
 * If all the callers of init_file() are eliminated, its
 * code should be moved into this function.
 */
170 171
struct file *alloc_file(struct path *path, fmode_t mode,
		const struct file_operations *fop)
172 173 174 175 176 177 178
{
	struct file *file;

	file = get_empty_filp();
	if (!file)
		return NULL;

179 180
	file->f_path = *path;
	file->f_mapping = path->dentry->d_inode->i_mapping;
181 182
	file->f_mode = mode;
	file->f_op = fop;
183 184 185 186 187 188 189

	/*
	 * These mounts don't really matter in practice
	 * for r/o bind mounts.  They aren't userspace-
	 * visible.  We do this for consistency, and so
	 * that we can do debugging checks at __fput()
	 */
190
	if ((mode & FMODE_WRITE) && !special_file(path->dentry->d_inode->i_mode)) {
191
		file_take_write(file);
192
		WARN_ON(mnt_clone_write(path->mnt));
193
	}
194 195
	if ((mode & (FMODE_READ | FMODE_WRITE)) == FMODE_READ)
		i_readcount_inc(path->dentry->d_inode);
A
Al Viro 已提交
196
	return file;
197
}
R
Roland Dreier 已提交
198
EXPORT_SYMBOL(alloc_file);
199

200 201 202 203 204 205 206 207
/**
 * drop_file_write_access - give up ability to write to a file
 * @file: the file to which we will stop writing
 *
 * This is a central place which will give up the ability
 * to write to @file, along with access to write through
 * its vfsmount.
 */
208
static void drop_file_write_access(struct file *file)
209
{
210
	struct vfsmount *mnt = file->f_path.mnt;
211 212 213 214
	struct dentry *dentry = file->f_path.dentry;
	struct inode *inode = dentry->d_inode;

	put_write_access(inode);
215 216 217 218 219

	if (special_file(inode->i_mode))
		return;
	if (file_check_writeable(file) != 0)
		return;
220
	__mnt_drop_write(mnt);
221
	file_release_write(file);
222 223
}

224
/* the real guts of fput() - releasing the last reference to file
L
Linus Torvalds 已提交
225
 */
226
static void __fput(struct file *file)
L
Linus Torvalds 已提交
227
{
228 229
	struct dentry *dentry = file->f_path.dentry;
	struct vfsmount *mnt = file->f_path.mnt;
L
Linus Torvalds 已提交
230 231 232
	struct inode *inode = dentry->d_inode;

	might_sleep();
R
Robert Love 已提交
233 234

	fsnotify_close(file);
L
Linus Torvalds 已提交
235 236 237 238 239 240 241
	/*
	 * The function eventpoll_release() should be the first called
	 * in the file cleanup chain.
	 */
	eventpoll_release(file);
	locks_remove_flock(file);

A
Al Viro 已提交
242 243 244 245
	if (unlikely(file->f_flags & FASYNC)) {
		if (file->f_op && file->f_op->fasync)
			file->f_op->fasync(-1, file, 0);
	}
L
Linus Torvalds 已提交
246 247 248
	if (file->f_op && file->f_op->release)
		file->f_op->release(inode, file);
	security_file_free(file);
A
Al Viro 已提交
249
	ima_file_free(file);
250 251
	if (unlikely(S_ISCHR(inode->i_mode) && inode->i_cdev != NULL &&
		     !(file->f_mode & FMODE_PATH))) {
L
Linus Torvalds 已提交
252
		cdev_put(inode->i_cdev);
253
	}
L
Linus Torvalds 已提交
254
	fops_put(file->f_op);
255
	put_pid(file->f_owner.pid);
256 257
	if ((file->f_mode & (FMODE_READ | FMODE_WRITE)) == FMODE_READ)
		i_readcount_dec(inode);
258 259
	if (file->f_mode & FMODE_WRITE)
		drop_file_write_access(file);
260 261
	file->f_path.dentry = NULL;
	file->f_path.mnt = NULL;
L
Linus Torvalds 已提交
262 263 264 265 266
	file_free(file);
	dput(dentry);
	mntput(mnt);
}

A
Al Viro 已提交
267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303
static DEFINE_SPINLOCK(delayed_fput_lock);
static LIST_HEAD(delayed_fput_list);
static void delayed_fput(struct work_struct *unused)
{
	LIST_HEAD(head);
	spin_lock_irq(&delayed_fput_lock);
	list_splice_init(&delayed_fput_list, &head);
	spin_unlock_irq(&delayed_fput_lock);
	while (!list_empty(&head)) {
		struct file *f = list_first_entry(&head, struct file, f_u.fu_list);
		list_del_init(&f->f_u.fu_list);
		__fput(f);
	}
}

static void ____fput(struct callback_head *work)
{
	__fput(container_of(work, struct file, f_u.fu_rcuhead));
}

/*
 * If kernel thread really needs to have the final fput() it has done
 * to complete, call this.  The only user right now is the boot - we
 * *do* need to make sure our writes to binaries on initramfs has
 * not left us with opened struct file waiting for __fput() - execve()
 * won't work without that.  Please, don't add more callers without
 * very good reasons; in particular, never call that with locks
 * held and never call that from a thread that might need to do
 * some work on any kind of umount.
 */
void flush_delayed_fput(void)
{
	delayed_fput(NULL);
}

static DECLARE_WORK(delayed_fput_work, delayed_fput);

304 305
void fput(struct file *file)
{
A
Al Viro 已提交
306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335
	if (atomic_long_dec_and_test(&file->f_count)) {
		struct task_struct *task = current;
		file_sb_list_del(file);
		if (unlikely(in_interrupt() || task->flags & PF_KTHREAD)) {
			unsigned long flags;
			spin_lock_irqsave(&delayed_fput_lock, flags);
			list_add(&file->f_u.fu_list, &delayed_fput_list);
			schedule_work(&delayed_fput_work);
			spin_unlock_irqrestore(&delayed_fput_lock, flags);
			return;
		}
		init_task_work(&file->f_u.fu_rcuhead, ____fput);
		task_work_add(task, &file->f_u.fu_rcuhead, true);
	}
}

/*
 * synchronous analog of fput(); for kernel threads that might be needed
 * in some umount() (and thus can't use flush_delayed_fput() without
 * risking deadlocks), need to wait for completion of __fput() and know
 * for this specific struct file it won't involve anything that would
 * need them.  Use only if you really need it - at the very least,
 * don't blindly convert fput() by kernel thread to that.
 */
void __fput_sync(struct file *file)
{
	if (atomic_long_dec_and_test(&file->f_count)) {
		struct task_struct *task = current;
		file_sb_list_del(file);
		BUG_ON(!(task->flags & PF_KTHREAD));
336
		__fput(file);
A
Al Viro 已提交
337
	}
338 339 340 341
}

EXPORT_SYMBOL(fput);

342
struct file *fget(unsigned int fd)
L
Linus Torvalds 已提交
343 344 345 346
{
	struct file *file;
	struct files_struct *files = current->files;

347
	rcu_read_lock();
L
Linus Torvalds 已提交
348
	file = fcheck_files(files, fd);
349
	if (file) {
350 351 352 353
		/* File object ref couldn't be taken */
		if (file->f_mode & FMODE_PATH ||
		    !atomic_long_inc_not_zero(&file->f_count))
			file = NULL;
354 355 356
	}
	rcu_read_unlock();

L
Linus Torvalds 已提交
357 358 359 360 361
	return file;
}

EXPORT_SYMBOL(fget);

362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378
struct file *fget_raw(unsigned int fd)
{
	struct file *file;
	struct files_struct *files = current->files;

	rcu_read_lock();
	file = fcheck_files(files, fd);
	if (file) {
		/* File object ref couldn't be taken */
		if (!atomic_long_inc_not_zero(&file->f_count))
			file = NULL;
	}
	rcu_read_unlock();

	return file;
}

379 380
EXPORT_SYMBOL(fget_raw);

L
Linus Torvalds 已提交
381
/*
382 383 384 385 386 387 388 389 390 391 392 393 394 395
 * Lightweight file lookup - no refcnt increment if fd table isn't shared.
 *
 * You can use this instead of fget if you satisfy all of the following
 * conditions:
 * 1) You must call fput_light before exiting the syscall and returning control
 *    to userspace (i.e. you cannot remember the returned struct file * after
 *    returning to userspace).
 * 2) You must not call filp_close on the returned struct file * in between
 *    calls to fget_light and fput_light.
 * 3) You must not clone the current task in between the calls to fget_light
 *    and fput_light.
 *
 * The fput_needed flag returned by fget_light should be passed to the
 * corresponding fput_light.
L
Linus Torvalds 已提交
396
 */
397
struct file *fget_light(unsigned int fd, int *fput_needed)
L
Linus Torvalds 已提交
398 399 400 401
{
	struct file *file;
	struct files_struct *files = current->files;

402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428
	*fput_needed = 0;
	if (atomic_read(&files->count) == 1) {
		file = fcheck_files(files, fd);
		if (file && (file->f_mode & FMODE_PATH))
			file = NULL;
	} else {
		rcu_read_lock();
		file = fcheck_files(files, fd);
		if (file) {
			if (!(file->f_mode & FMODE_PATH) &&
			    atomic_long_inc_not_zero(&file->f_count))
				*fput_needed = 1;
			else
				/* Didn't get the reference, someone's freed */
				file = NULL;
		}
		rcu_read_unlock();
	}

	return file;
}

struct file *fget_raw_light(unsigned int fd, int *fput_needed)
{
	struct file *file;
	struct files_struct *files = current->files;

L
Linus Torvalds 已提交
429
	*fput_needed = 0;
430
	if (atomic_read(&files->count) == 1) {
L
Linus Torvalds 已提交
431 432
		file = fcheck_files(files, fd);
	} else {
433
		rcu_read_lock();
L
Linus Torvalds 已提交
434 435
		file = fcheck_files(files, fd);
		if (file) {
A
Al Viro 已提交
436
			if (atomic_long_inc_not_zero(&file->f_count))
437 438 439 440
				*fput_needed = 1;
			else
				/* Didn't get the reference, someone's freed */
				file = NULL;
L
Linus Torvalds 已提交
441
		}
442
		rcu_read_unlock();
L
Linus Torvalds 已提交
443
	}
444

L
Linus Torvalds 已提交
445 446 447 448 449
	return file;
}

void put_filp(struct file *file)
{
A
Al Viro 已提交
450
	if (atomic_long_dec_and_test(&file->f_count)) {
L
Linus Torvalds 已提交
451
		security_file_free(file);
N
Nick Piggin 已提交
452
		file_sb_list_del(file);
L
Linus Torvalds 已提交
453 454 455 456
		file_free(file);
	}
}

N
Nick Piggin 已提交
457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488
static inline int file_list_cpu(struct file *file)
{
#ifdef CONFIG_SMP
	return file->f_sb_list_cpu;
#else
	return smp_processor_id();
#endif
}

/* helper for file_sb_list_add to reduce ifdefs */
static inline void __file_sb_list_add(struct file *file, struct super_block *sb)
{
	struct list_head *list;
#ifdef CONFIG_SMP
	int cpu;
	cpu = smp_processor_id();
	file->f_sb_list_cpu = cpu;
	list = per_cpu_ptr(sb->s_files, cpu);
#else
	list = &sb->s_files;
#endif
	list_add(&file->f_u.fu_list, list);
}

/**
 * file_sb_list_add - add a file to the sb's file list
 * @file: file to add
 * @sb: sb to add it to
 *
 * Use this function to associate a file with the superblock of the inode it
 * refers to.
 */
N
Nick Piggin 已提交
489
void file_sb_list_add(struct file *file, struct super_block *sb)
L
Linus Torvalds 已提交
490
{
A
Andi Kleen 已提交
491
	lg_local_lock(&files_lglock);
N
Nick Piggin 已提交
492
	__file_sb_list_add(file, sb);
A
Andi Kleen 已提交
493
	lg_local_unlock(&files_lglock);
L
Linus Torvalds 已提交
494 495
}

N
Nick Piggin 已提交
496 497 498 499 500 501 502
/**
 * file_sb_list_del - remove a file from the sb's file list
 * @file: file to remove
 * @sb: sb to remove it from
 *
 * Use this function to remove a file from its superblock.
 */
N
Nick Piggin 已提交
503
void file_sb_list_del(struct file *file)
L
Linus Torvalds 已提交
504
{
E
Eric Dumazet 已提交
505
	if (!list_empty(&file->f_u.fu_list)) {
A
Andi Kleen 已提交
506
		lg_local_lock_cpu(&files_lglock, file_list_cpu(file));
E
Eric Dumazet 已提交
507
		list_del_init(&file->f_u.fu_list);
A
Andi Kleen 已提交
508
		lg_local_unlock_cpu(&files_lglock, file_list_cpu(file));
L
Linus Torvalds 已提交
509 510 511
	}
}

N
Nick Piggin 已提交
512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542
#ifdef CONFIG_SMP

/*
 * These macros iterate all files on all CPUs for a given superblock.
 * files_lglock must be held globally.
 */
#define do_file_list_for_each_entry(__sb, __file)		\
{								\
	int i;							\
	for_each_possible_cpu(i) {				\
		struct list_head *list;				\
		list = per_cpu_ptr((__sb)->s_files, i);		\
		list_for_each_entry((__file), list, f_u.fu_list)

#define while_file_list_for_each_entry				\
	}							\
}

#else

#define do_file_list_for_each_entry(__sb, __file)		\
{								\
	struct list_head *list;					\
	list = &(sb)->s_files;					\
	list_for_each_entry((__file), list, f_u.fu_list)

#define while_file_list_for_each_entry				\
}

#endif

543 544 545 546 547 548 549 550 551 552 553
/**
 *	mark_files_ro - mark all files read-only
 *	@sb: superblock in question
 *
 *	All files are marked read-only.  We don't care about pending
 *	delete files so this should be used in 'force' mode only.
 */
void mark_files_ro(struct super_block *sb)
{
	struct file *f;

A
Andi Kleen 已提交
554
	lg_global_lock(&files_lglock);
N
Nick Piggin 已提交
555
	do_file_list_for_each_entry(sb, f) {
556 557 558 559 560 561
		if (!S_ISREG(f->f_path.dentry->d_inode->i_mode))
		       continue;
		if (!file_count(f))
			continue;
		if (!(f->f_mode & FMODE_WRITE))
			continue;
562
		spin_lock(&f->f_lock);
563
		f->f_mode &= ~FMODE_WRITE;
564
		spin_unlock(&f->f_lock);
565 566 567
		if (file_check_writeable(f) != 0)
			continue;
		file_release_write(f);
568
		mnt_drop_write_file(f);
N
Nick Piggin 已提交
569
	} while_file_list_for_each_entry;
A
Andi Kleen 已提交
570
	lg_global_unlock(&files_lglock);
571 572
}

L
Linus Torvalds 已提交
573 574
void __init files_init(unsigned long mempages)
{ 
E
Eric Dumazet 已提交
575
	unsigned long n;
576 577 578 579 580 581

	filp_cachep = kmem_cache_create("filp", sizeof(struct file), 0,
			SLAB_HWCACHE_ALIGN | SLAB_PANIC, NULL);

	/*
	 * One file with associated inode and dcache is very roughly 1K.
L
Linus Torvalds 已提交
582 583 584 585
	 * Per default don't use more than 10% of our memory for files. 
	 */ 

	n = (mempages * (PAGE_SIZE / 1024)) / 10;
E
Eric Dumazet 已提交
586
	files_stat.max_files = max_t(unsigned long, n, NR_FILE);
587
	files_defer_init();
A
Andi Kleen 已提交
588
	lg_lock_init(&files_lglock, "files_lglock");
589
	percpu_counter_init(&nr_files, 0);
L
Linus Torvalds 已提交
590
}