dev.c 47 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136
  1. /*
  2. FUSE: Filesystem in Userspace
  3. Copyright (C) 2001-2008 Miklos Szeredi <miklos@szeredi.hu>
  4. This program can be distributed under the terms of the GNU GPL.
  5. See the file COPYING.
  6. */
  7. #include "fuse_i.h"
  8. #include <linux/init.h>
  9. #include <linux/module.h>
  10. #include <linux/poll.h>
  11. #include <linux/uio.h>
  12. #include <linux/miscdevice.h>
  13. #include <linux/pagemap.h>
  14. #include <linux/file.h>
  15. #include <linux/slab.h>
  16. #include <linux/pipe_fs_i.h>
  17. #include <linux/swap.h>
  18. #include <linux/splice.h>
  19. MODULE_ALIAS_MISCDEV(FUSE_MINOR);
  20. MODULE_ALIAS("devname:fuse");
  21. static struct kmem_cache *fuse_req_cachep;
  22. static struct fuse_conn *fuse_get_conn(struct file *file)
  23. {
  24. /*
  25. * Lockless access is OK, because file->private data is set
  26. * once during mount and is valid until the file is released.
  27. */
  28. return file->private_data;
  29. }
  30. static void fuse_request_init(struct fuse_req *req, struct page **pages,
  31. unsigned npages)
  32. {
  33. memset(req, 0, sizeof(*req));
  34. memset(pages, 0, sizeof(*pages) * npages);
  35. INIT_LIST_HEAD(&req->list);
  36. INIT_LIST_HEAD(&req->intr_entry);
  37. init_waitqueue_head(&req->waitq);
  38. atomic_set(&req->count, 1);
  39. req->pages = pages;
  40. req->max_pages = npages;
  41. }
  42. static struct fuse_req *__fuse_request_alloc(unsigned npages, gfp_t flags)
  43. {
  44. struct fuse_req *req = kmem_cache_alloc(fuse_req_cachep, flags);
  45. if (req) {
  46. struct page **pages;
  47. if (npages <= FUSE_REQ_INLINE_PAGES)
  48. pages = req->inline_pages;
  49. else
  50. pages = kmalloc(sizeof(struct page *) * npages, flags);
  51. if (!pages) {
  52. kmem_cache_free(fuse_req_cachep, req);
  53. return NULL;
  54. }
  55. fuse_request_init(req, pages, npages);
  56. }
  57. return req;
  58. }
  59. struct fuse_req *fuse_request_alloc(unsigned npages)
  60. {
  61. return __fuse_request_alloc(npages, GFP_KERNEL);
  62. }
  63. EXPORT_SYMBOL_GPL(fuse_request_alloc);
  64. struct fuse_req *fuse_request_alloc_nofs(unsigned npages)
  65. {
  66. return __fuse_request_alloc(npages, GFP_NOFS);
  67. }
  68. void fuse_request_free(struct fuse_req *req)
  69. {
  70. if (req->pages != req->inline_pages)
  71. kfree(req->pages);
  72. kmem_cache_free(fuse_req_cachep, req);
  73. }
  74. static void block_sigs(sigset_t *oldset)
  75. {
  76. sigset_t mask;
  77. siginitsetinv(&mask, sigmask(SIGKILL));
  78. sigprocmask(SIG_BLOCK, &mask, oldset);
  79. }
  80. static void restore_sigs(sigset_t *oldset)
  81. {
  82. sigprocmask(SIG_SETMASK, oldset, NULL);
  83. }
  84. static void __fuse_get_request(struct fuse_req *req)
  85. {
  86. atomic_inc(&req->count);
  87. }
  88. /* Must be called with > 1 refcount */
  89. static void __fuse_put_request(struct fuse_req *req)
  90. {
  91. BUG_ON(atomic_read(&req->count) < 2);
  92. atomic_dec(&req->count);
  93. }
  94. static void fuse_req_init_context(struct fuse_req *req)
  95. {
  96. req->in.h.uid = from_kuid_munged(&init_user_ns, current_fsuid());
  97. req->in.h.gid = from_kgid_munged(&init_user_ns, current_fsgid());
  98. req->in.h.pid = current->pid;
  99. }
  100. struct fuse_req *fuse_get_req(struct fuse_conn *fc, unsigned npages)
  101. {
  102. struct fuse_req *req;
  103. sigset_t oldset;
  104. int intr;
  105. int err;
  106. atomic_inc(&fc->num_waiting);
  107. block_sigs(&oldset);
  108. intr = wait_event_interruptible(fc->blocked_waitq, !fc->blocked);
  109. restore_sigs(&oldset);
  110. err = -EINTR;
  111. if (intr)
  112. goto out;
  113. err = -ENOTCONN;
  114. if (!fc->connected)
  115. goto out;
  116. req = fuse_request_alloc(npages);
  117. err = -ENOMEM;
  118. if (!req)
  119. goto out;
  120. fuse_req_init_context(req);
  121. req->waiting = 1;
  122. return req;
  123. out:
  124. atomic_dec(&fc->num_waiting);
  125. return ERR_PTR(err);
  126. }
  127. EXPORT_SYMBOL_GPL(fuse_get_req);
  128. /*
  129. * Return request in fuse_file->reserved_req. However that may
  130. * currently be in use. If that is the case, wait for it to become
  131. * available.
  132. */
  133. static struct fuse_req *get_reserved_req(struct fuse_conn *fc,
  134. struct file *file)
  135. {
  136. struct fuse_req *req = NULL;
  137. struct fuse_file *ff = file->private_data;
  138. do {
  139. wait_event(fc->reserved_req_waitq, ff->reserved_req);
  140. spin_lock(&fc->lock);
  141. if (ff->reserved_req) {
  142. req = ff->reserved_req;
  143. ff->reserved_req = NULL;
  144. req->stolen_file = get_file(file);
  145. }
  146. spin_unlock(&fc->lock);
  147. } while (!req);
  148. return req;
  149. }
  150. /*
  151. * Put stolen request back into fuse_file->reserved_req
  152. */
  153. static void put_reserved_req(struct fuse_conn *fc, struct fuse_req *req)
  154. {
  155. struct file *file = req->stolen_file;
  156. struct fuse_file *ff = file->private_data;
  157. spin_lock(&fc->lock);
  158. fuse_request_init(req, req->pages, req->max_pages);
  159. BUG_ON(ff->reserved_req);
  160. ff->reserved_req = req;
  161. wake_up_all(&fc->reserved_req_waitq);
  162. spin_unlock(&fc->lock);
  163. fput(file);
  164. }
  165. /*
  166. * Gets a requests for a file operation, always succeeds
  167. *
  168. * This is used for sending the FLUSH request, which must get to
  169. * userspace, due to POSIX locks which may need to be unlocked.
  170. *
  171. * If allocation fails due to OOM, use the reserved request in
  172. * fuse_file.
  173. *
  174. * This is very unlikely to deadlock accidentally, since the
  175. * filesystem should not have it's own file open. If deadlock is
  176. * intentional, it can still be broken by "aborting" the filesystem.
  177. */
  178. struct fuse_req *fuse_get_req_nofail_nopages(struct fuse_conn *fc,
  179. struct file *file)
  180. {
  181. struct fuse_req *req;
  182. atomic_inc(&fc->num_waiting);
  183. wait_event(fc->blocked_waitq, !fc->blocked);
  184. req = fuse_request_alloc(0);
  185. if (!req)
  186. req = get_reserved_req(fc, file);
  187. fuse_req_init_context(req);
  188. req->waiting = 1;
  189. return req;
  190. }
  191. void fuse_put_request(struct fuse_conn *fc, struct fuse_req *req)
  192. {
  193. if (atomic_dec_and_test(&req->count)) {
  194. if (req->waiting)
  195. atomic_dec(&fc->num_waiting);
  196. if (req->stolen_file)
  197. put_reserved_req(fc, req);
  198. else
  199. fuse_request_free(req);
  200. }
  201. }
  202. EXPORT_SYMBOL_GPL(fuse_put_request);
  203. static unsigned len_args(unsigned numargs, struct fuse_arg *args)
  204. {
  205. unsigned nbytes = 0;
  206. unsigned i;
  207. for (i = 0; i < numargs; i++)
  208. nbytes += args[i].size;
  209. return nbytes;
  210. }
  211. static u64 fuse_get_unique(struct fuse_conn *fc)
  212. {
  213. fc->reqctr++;
  214. /* zero is special */
  215. if (fc->reqctr == 0)
  216. fc->reqctr = 1;
  217. return fc->reqctr;
  218. }
  219. static void queue_request(struct fuse_conn *fc, struct fuse_req *req)
  220. {
  221. req->in.h.len = sizeof(struct fuse_in_header) +
  222. len_args(req->in.numargs, (struct fuse_arg *) req->in.args);
  223. list_add_tail(&req->list, &fc->pending);
  224. req->state = FUSE_REQ_PENDING;
  225. if (!req->waiting) {
  226. req->waiting = 1;
  227. atomic_inc(&fc->num_waiting);
  228. }
  229. wake_up(&fc->waitq);
  230. kill_fasync(&fc->fasync, SIGIO, POLL_IN);
  231. }
  232. void fuse_queue_forget(struct fuse_conn *fc, struct fuse_forget_link *forget,
  233. u64 nodeid, u64 nlookup)
  234. {
  235. forget->forget_one.nodeid = nodeid;
  236. forget->forget_one.nlookup = nlookup;
  237. spin_lock(&fc->lock);
  238. if (fc->connected) {
  239. fc->forget_list_tail->next = forget;
  240. fc->forget_list_tail = forget;
  241. wake_up(&fc->waitq);
  242. kill_fasync(&fc->fasync, SIGIO, POLL_IN);
  243. } else {
  244. kfree(forget);
  245. }
  246. spin_unlock(&fc->lock);
  247. }
  248. static void flush_bg_queue(struct fuse_conn *fc)
  249. {
  250. while (fc->active_background < fc->max_background &&
  251. !list_empty(&fc->bg_queue)) {
  252. struct fuse_req *req;
  253. req = list_entry(fc->bg_queue.next, struct fuse_req, list);
  254. list_del(&req->list);
  255. fc->active_background++;
  256. req->in.h.unique = fuse_get_unique(fc);
  257. queue_request(fc, req);
  258. }
  259. }
  260. /*
  261. * This function is called when a request is finished. Either a reply
  262. * has arrived or it was aborted (and not yet sent) or some error
  263. * occurred during communication with userspace, or the device file
  264. * was closed. The requester thread is woken up (if still waiting),
  265. * the 'end' callback is called if given, else the reference to the
  266. * request is released
  267. *
  268. * Called with fc->lock, unlocks it
  269. */
  270. static void request_end(struct fuse_conn *fc, struct fuse_req *req)
  271. __releases(fc->lock)
  272. {
  273. void (*end) (struct fuse_conn *, struct fuse_req *) = req->end;
  274. req->end = NULL;
  275. list_del(&req->list);
  276. list_del(&req->intr_entry);
  277. req->state = FUSE_REQ_FINISHED;
  278. if (req->background) {
  279. if (fc->num_background == fc->max_background) {
  280. fc->blocked = 0;
  281. wake_up_all(&fc->blocked_waitq);
  282. }
  283. if (fc->num_background == fc->congestion_threshold &&
  284. fc->connected && fc->bdi_initialized) {
  285. clear_bdi_congested(&fc->bdi, BLK_RW_SYNC);
  286. clear_bdi_congested(&fc->bdi, BLK_RW_ASYNC);
  287. }
  288. fc->num_background--;
  289. fc->active_background--;
  290. flush_bg_queue(fc);
  291. }
  292. spin_unlock(&fc->lock);
  293. wake_up(&req->waitq);
  294. if (end)
  295. end(fc, req);
  296. fuse_put_request(fc, req);
  297. }
  298. static void wait_answer_interruptible(struct fuse_conn *fc,
  299. struct fuse_req *req)
  300. __releases(fc->lock)
  301. __acquires(fc->lock)
  302. {
  303. if (signal_pending(current))
  304. return;
  305. spin_unlock(&fc->lock);
  306. wait_event_interruptible(req->waitq, req->state == FUSE_REQ_FINISHED);
  307. spin_lock(&fc->lock);
  308. }
  309. static void queue_interrupt(struct fuse_conn *fc, struct fuse_req *req)
  310. {
  311. list_add_tail(&req->intr_entry, &fc->interrupts);
  312. wake_up(&fc->waitq);
  313. kill_fasync(&fc->fasync, SIGIO, POLL_IN);
  314. }
  315. static void request_wait_answer(struct fuse_conn *fc, struct fuse_req *req)
  316. __releases(fc->lock)
  317. __acquires(fc->lock)
  318. {
  319. if (!fc->no_interrupt) {
  320. /* Any signal may interrupt this */
  321. wait_answer_interruptible(fc, req);
  322. if (req->aborted)
  323. goto aborted;
  324. if (req->state == FUSE_REQ_FINISHED)
  325. return;
  326. req->interrupted = 1;
  327. if (req->state == FUSE_REQ_SENT)
  328. queue_interrupt(fc, req);
  329. }
  330. if (!req->force) {
  331. sigset_t oldset;
  332. /* Only fatal signals may interrupt this */
  333. block_sigs(&oldset);
  334. wait_answer_interruptible(fc, req);
  335. restore_sigs(&oldset);
  336. if (req->aborted)
  337. goto aborted;
  338. if (req->state == FUSE_REQ_FINISHED)
  339. return;
  340. /* Request is not yet in userspace, bail out */
  341. if (req->state == FUSE_REQ_PENDING) {
  342. list_del(&req->list);
  343. __fuse_put_request(req);
  344. req->out.h.error = -EINTR;
  345. return;
  346. }
  347. }
  348. /*
  349. * Either request is already in userspace, or it was forced.
  350. * Wait it out.
  351. */
  352. spin_unlock(&fc->lock);
  353. wait_event(req->waitq, req->state == FUSE_REQ_FINISHED);
  354. spin_lock(&fc->lock);
  355. if (!req->aborted)
  356. return;
  357. aborted:
  358. BUG_ON(req->state != FUSE_REQ_FINISHED);
  359. if (req->locked) {
  360. /* This is uninterruptible sleep, because data is
  361. being copied to/from the buffers of req. During
  362. locked state, there mustn't be any filesystem
  363. operation (e.g. page fault), since that could lead
  364. to deadlock */
  365. spin_unlock(&fc->lock);
  366. wait_event(req->waitq, !req->locked);
  367. spin_lock(&fc->lock);
  368. }
  369. }
  370. void fuse_request_send(struct fuse_conn *fc, struct fuse_req *req)
  371. {
  372. req->isreply = 1;
  373. spin_lock(&fc->lock);
  374. if (!fc->connected)
  375. req->out.h.error = -ENOTCONN;
  376. else if (fc->conn_error)
  377. req->out.h.error = -ECONNREFUSED;
  378. else {
  379. req->in.h.unique = fuse_get_unique(fc);
  380. queue_request(fc, req);
  381. /* acquire extra reference, since request is still needed
  382. after request_end() */
  383. __fuse_get_request(req);
  384. request_wait_answer(fc, req);
  385. }
  386. spin_unlock(&fc->lock);
  387. }
  388. EXPORT_SYMBOL_GPL(fuse_request_send);
  389. static void fuse_request_send_nowait_locked(struct fuse_conn *fc,
  390. struct fuse_req *req)
  391. {
  392. req->background = 1;
  393. fc->num_background++;
  394. if (fc->num_background == fc->max_background)
  395. fc->blocked = 1;
  396. if (fc->num_background == fc->congestion_threshold &&
  397. fc->bdi_initialized) {
  398. set_bdi_congested(&fc->bdi, BLK_RW_SYNC);
  399. set_bdi_congested(&fc->bdi, BLK_RW_ASYNC);
  400. }
  401. list_add_tail(&req->list, &fc->bg_queue);
  402. flush_bg_queue(fc);
  403. }
  404. static void fuse_request_send_nowait(struct fuse_conn *fc, struct fuse_req *req)
  405. {
  406. spin_lock(&fc->lock);
  407. if (fc->connected) {
  408. fuse_request_send_nowait_locked(fc, req);
  409. spin_unlock(&fc->lock);
  410. } else {
  411. req->out.h.error = -ENOTCONN;
  412. request_end(fc, req);
  413. }
  414. }
  415. void fuse_request_send_background(struct fuse_conn *fc, struct fuse_req *req)
  416. {
  417. req->isreply = 1;
  418. fuse_request_send_nowait(fc, req);
  419. }
  420. EXPORT_SYMBOL_GPL(fuse_request_send_background);
  421. static int fuse_request_send_notify_reply(struct fuse_conn *fc,
  422. struct fuse_req *req, u64 unique)
  423. {
  424. int err = -ENODEV;
  425. req->isreply = 0;
  426. req->in.h.unique = unique;
  427. spin_lock(&fc->lock);
  428. if (fc->connected) {
  429. queue_request(fc, req);
  430. err = 0;
  431. }
  432. spin_unlock(&fc->lock);
  433. return err;
  434. }
  435. /*
  436. * Called under fc->lock
  437. *
  438. * fc->connected must have been checked previously
  439. */
  440. void fuse_request_send_background_locked(struct fuse_conn *fc,
  441. struct fuse_req *req)
  442. {
  443. req->isreply = 1;
  444. fuse_request_send_nowait_locked(fc, req);
  445. }
  446. void fuse_force_forget(struct file *file, u64 nodeid)
  447. {
  448. struct inode *inode = file->f_path.dentry->d_inode;
  449. struct fuse_conn *fc = get_fuse_conn(inode);
  450. struct fuse_req *req;
  451. struct fuse_forget_in inarg;
  452. memset(&inarg, 0, sizeof(inarg));
  453. inarg.nlookup = 1;
  454. req = fuse_get_req_nofail_nopages(fc, file);
  455. req->in.h.opcode = FUSE_FORGET;
  456. req->in.h.nodeid = nodeid;
  457. req->in.numargs = 1;
  458. req->in.args[0].size = sizeof(inarg);
  459. req->in.args[0].value = &inarg;
  460. req->isreply = 0;
  461. fuse_request_send_nowait(fc, req);
  462. }
  463. /*
  464. * Lock the request. Up to the next unlock_request() there mustn't be
  465. * anything that could cause a page-fault. If the request was already
  466. * aborted bail out.
  467. */
  468. static int lock_request(struct fuse_conn *fc, struct fuse_req *req)
  469. {
  470. int err = 0;
  471. if (req) {
  472. spin_lock(&fc->lock);
  473. if (req->aborted)
  474. err = -ENOENT;
  475. else
  476. req->locked = 1;
  477. spin_unlock(&fc->lock);
  478. }
  479. return err;
  480. }
  481. /*
  482. * Unlock request. If it was aborted during being locked, the
  483. * requester thread is currently waiting for it to be unlocked, so
  484. * wake it up.
  485. */
  486. static void unlock_request(struct fuse_conn *fc, struct fuse_req *req)
  487. {
  488. if (req) {
  489. spin_lock(&fc->lock);
  490. req->locked = 0;
  491. if (req->aborted)
  492. wake_up(&req->waitq);
  493. spin_unlock(&fc->lock);
  494. }
  495. }
  496. struct fuse_copy_state {
  497. struct fuse_conn *fc;
  498. int write;
  499. struct fuse_req *req;
  500. const struct iovec *iov;
  501. struct pipe_buffer *pipebufs;
  502. struct pipe_buffer *currbuf;
  503. struct pipe_inode_info *pipe;
  504. unsigned long nr_segs;
  505. unsigned long seglen;
  506. unsigned long addr;
  507. struct page *pg;
  508. void *mapaddr;
  509. void *buf;
  510. unsigned len;
  511. unsigned move_pages:1;
  512. };
  513. static void fuse_copy_init(struct fuse_copy_state *cs, struct fuse_conn *fc,
  514. int write,
  515. const struct iovec *iov, unsigned long nr_segs)
  516. {
  517. memset(cs, 0, sizeof(*cs));
  518. cs->fc = fc;
  519. cs->write = write;
  520. cs->iov = iov;
  521. cs->nr_segs = nr_segs;
  522. }
  523. /* Unmap and put previous page of userspace buffer */
  524. static void fuse_copy_finish(struct fuse_copy_state *cs)
  525. {
  526. if (cs->currbuf) {
  527. struct pipe_buffer *buf = cs->currbuf;
  528. if (!cs->write) {
  529. buf->ops->unmap(cs->pipe, buf, cs->mapaddr);
  530. } else {
  531. kunmap(buf->page);
  532. buf->len = PAGE_SIZE - cs->len;
  533. }
  534. cs->currbuf = NULL;
  535. cs->mapaddr = NULL;
  536. } else if (cs->mapaddr) {
  537. kunmap(cs->pg);
  538. if (cs->write) {
  539. flush_dcache_page(cs->pg);
  540. set_page_dirty_lock(cs->pg);
  541. }
  542. put_page(cs->pg);
  543. cs->mapaddr = NULL;
  544. }
  545. }
  546. /*
  547. * Get another pagefull of userspace buffer, and map it to kernel
  548. * address space, and lock request
  549. */
  550. static int fuse_copy_fill(struct fuse_copy_state *cs)
  551. {
  552. unsigned long offset;
  553. int err;
  554. unlock_request(cs->fc, cs->req);
  555. fuse_copy_finish(cs);
  556. if (cs->pipebufs) {
  557. struct pipe_buffer *buf = cs->pipebufs;
  558. if (!cs->write) {
  559. err = buf->ops->confirm(cs->pipe, buf);
  560. if (err)
  561. return err;
  562. BUG_ON(!cs->nr_segs);
  563. cs->currbuf = buf;
  564. cs->mapaddr = buf->ops->map(cs->pipe, buf, 0);
  565. cs->len = buf->len;
  566. cs->buf = cs->mapaddr + buf->offset;
  567. cs->pipebufs++;
  568. cs->nr_segs--;
  569. } else {
  570. struct page *page;
  571. if (cs->nr_segs == cs->pipe->buffers)
  572. return -EIO;
  573. page = alloc_page(GFP_HIGHUSER);
  574. if (!page)
  575. return -ENOMEM;
  576. buf->page = page;
  577. buf->offset = 0;
  578. buf->len = 0;
  579. cs->currbuf = buf;
  580. cs->mapaddr = kmap(page);
  581. cs->buf = cs->mapaddr;
  582. cs->len = PAGE_SIZE;
  583. cs->pipebufs++;
  584. cs->nr_segs++;
  585. }
  586. } else {
  587. if (!cs->seglen) {
  588. BUG_ON(!cs->nr_segs);
  589. cs->seglen = cs->iov[0].iov_len;
  590. cs->addr = (unsigned long) cs->iov[0].iov_base;
  591. cs->iov++;
  592. cs->nr_segs--;
  593. }
  594. err = get_user_pages_fast(cs->addr, 1, cs->write, &cs->pg);
  595. if (err < 0)
  596. return err;
  597. BUG_ON(err != 1);
  598. offset = cs->addr % PAGE_SIZE;
  599. cs->mapaddr = kmap(cs->pg);
  600. cs->buf = cs->mapaddr + offset;
  601. cs->len = min(PAGE_SIZE - offset, cs->seglen);
  602. cs->seglen -= cs->len;
  603. cs->addr += cs->len;
  604. }
  605. return lock_request(cs->fc, cs->req);
  606. }
  607. /* Do as much copy to/from userspace buffer as we can */
  608. static int fuse_copy_do(struct fuse_copy_state *cs, void **val, unsigned *size)
  609. {
  610. unsigned ncpy = min(*size, cs->len);
  611. if (val) {
  612. if (cs->write)
  613. memcpy(cs->buf, *val, ncpy);
  614. else
  615. memcpy(*val, cs->buf, ncpy);
  616. *val += ncpy;
  617. }
  618. *size -= ncpy;
  619. cs->len -= ncpy;
  620. cs->buf += ncpy;
  621. return ncpy;
  622. }
  623. static int fuse_check_page(struct page *page)
  624. {
  625. if (page_mapcount(page) ||
  626. page->mapping != NULL ||
  627. page_count(page) != 1 ||
  628. (page->flags & PAGE_FLAGS_CHECK_AT_PREP &
  629. ~(1 << PG_locked |
  630. 1 << PG_referenced |
  631. 1 << PG_uptodate |
  632. 1 << PG_lru |
  633. 1 << PG_active |
  634. 1 << PG_reclaim))) {
  635. printk(KERN_WARNING "fuse: trying to steal weird page\n");
  636. printk(KERN_WARNING " page=%p index=%li flags=%08lx, count=%i, mapcount=%i, mapping=%p\n", page, page->index, page->flags, page_count(page), page_mapcount(page), page->mapping);
  637. return 1;
  638. }
  639. return 0;
  640. }
  641. static int fuse_try_move_page(struct fuse_copy_state *cs, struct page **pagep)
  642. {
  643. int err;
  644. struct page *oldpage = *pagep;
  645. struct page *newpage;
  646. struct pipe_buffer *buf = cs->pipebufs;
  647. unlock_request(cs->fc, cs->req);
  648. fuse_copy_finish(cs);
  649. err = buf->ops->confirm(cs->pipe, buf);
  650. if (err)
  651. return err;
  652. BUG_ON(!cs->nr_segs);
  653. cs->currbuf = buf;
  654. cs->len = buf->len;
  655. cs->pipebufs++;
  656. cs->nr_segs--;
  657. if (cs->len != PAGE_SIZE)
  658. goto out_fallback;
  659. if (buf->ops->steal(cs->pipe, buf) != 0)
  660. goto out_fallback;
  661. newpage = buf->page;
  662. if (WARN_ON(!PageUptodate(newpage)))
  663. return -EIO;
  664. ClearPageMappedToDisk(newpage);
  665. if (fuse_check_page(newpage) != 0)
  666. goto out_fallback_unlock;
  667. /*
  668. * This is a new and locked page, it shouldn't be mapped or
  669. * have any special flags on it
  670. */
  671. if (WARN_ON(page_mapped(oldpage)))
  672. goto out_fallback_unlock;
  673. if (WARN_ON(page_has_private(oldpage)))
  674. goto out_fallback_unlock;
  675. if (WARN_ON(PageDirty(oldpage) || PageWriteback(oldpage)))
  676. goto out_fallback_unlock;
  677. if (WARN_ON(PageMlocked(oldpage)))
  678. goto out_fallback_unlock;
  679. err = replace_page_cache_page(oldpage, newpage, GFP_KERNEL);
  680. if (err) {
  681. unlock_page(newpage);
  682. return err;
  683. }
  684. page_cache_get(newpage);
  685. if (!(buf->flags & PIPE_BUF_FLAG_LRU))
  686. lru_cache_add_file(newpage);
  687. err = 0;
  688. spin_lock(&cs->fc->lock);
  689. if (cs->req->aborted)
  690. err = -ENOENT;
  691. else
  692. *pagep = newpage;
  693. spin_unlock(&cs->fc->lock);
  694. if (err) {
  695. unlock_page(newpage);
  696. page_cache_release(newpage);
  697. return err;
  698. }
  699. unlock_page(oldpage);
  700. page_cache_release(oldpage);
  701. cs->len = 0;
  702. return 0;
  703. out_fallback_unlock:
  704. unlock_page(newpage);
  705. out_fallback:
  706. cs->mapaddr = buf->ops->map(cs->pipe, buf, 1);
  707. cs->buf = cs->mapaddr + buf->offset;
  708. err = lock_request(cs->fc, cs->req);
  709. if (err)
  710. return err;
  711. return 1;
  712. }
  713. static int fuse_ref_page(struct fuse_copy_state *cs, struct page *page,
  714. unsigned offset, unsigned count)
  715. {
  716. struct pipe_buffer *buf;
  717. if (cs->nr_segs == cs->pipe->buffers)
  718. return -EIO;
  719. unlock_request(cs->fc, cs->req);
  720. fuse_copy_finish(cs);
  721. buf = cs->pipebufs;
  722. page_cache_get(page);
  723. buf->page = page;
  724. buf->offset = offset;
  725. buf->len = count;
  726. cs->pipebufs++;
  727. cs->nr_segs++;
  728. cs->len = 0;
  729. return 0;
  730. }
  731. /*
  732. * Copy a page in the request to/from the userspace buffer. Must be
  733. * done atomically
  734. */
  735. static int fuse_copy_page(struct fuse_copy_state *cs, struct page **pagep,
  736. unsigned offset, unsigned count, int zeroing)
  737. {
  738. int err;
  739. struct page *page = *pagep;
  740. if (page && zeroing && count < PAGE_SIZE)
  741. clear_highpage(page);
  742. while (count) {
  743. if (cs->write && cs->pipebufs && page) {
  744. return fuse_ref_page(cs, page, offset, count);
  745. } else if (!cs->len) {
  746. if (cs->move_pages && page &&
  747. offset == 0 && count == PAGE_SIZE) {
  748. err = fuse_try_move_page(cs, pagep);
  749. if (err <= 0)
  750. return err;
  751. } else {
  752. err = fuse_copy_fill(cs);
  753. if (err)
  754. return err;
  755. }
  756. }
  757. if (page) {
  758. void *mapaddr = kmap_atomic(page);
  759. void *buf = mapaddr + offset;
  760. offset += fuse_copy_do(cs, &buf, &count);
  761. kunmap_atomic(mapaddr);
  762. } else
  763. offset += fuse_copy_do(cs, NULL, &count);
  764. }
  765. if (page && !cs->write)
  766. flush_dcache_page(page);
  767. return 0;
  768. }
  769. /* Copy pages in the request to/from userspace buffer */
  770. static int fuse_copy_pages(struct fuse_copy_state *cs, unsigned nbytes,
  771. int zeroing)
  772. {
  773. unsigned i;
  774. struct fuse_req *req = cs->req;
  775. unsigned offset = req->page_offset;
  776. unsigned count = min(nbytes, (unsigned) PAGE_SIZE - offset);
  777. for (i = 0; i < req->num_pages && (nbytes || zeroing); i++) {
  778. int err;
  779. err = fuse_copy_page(cs, &req->pages[i], offset, count,
  780. zeroing);
  781. if (err)
  782. return err;
  783. nbytes -= count;
  784. count = min(nbytes, (unsigned) PAGE_SIZE);
  785. offset = 0;
  786. }
  787. return 0;
  788. }
  789. /* Copy a single argument in the request to/from userspace buffer */
  790. static int fuse_copy_one(struct fuse_copy_state *cs, void *val, unsigned size)
  791. {
  792. while (size) {
  793. if (!cs->len) {
  794. int err = fuse_copy_fill(cs);
  795. if (err)
  796. return err;
  797. }
  798. fuse_copy_do(cs, &val, &size);
  799. }
  800. return 0;
  801. }
  802. /* Copy request arguments to/from userspace buffer */
  803. static int fuse_copy_args(struct fuse_copy_state *cs, unsigned numargs,
  804. unsigned argpages, struct fuse_arg *args,
  805. int zeroing)
  806. {
  807. int err = 0;
  808. unsigned i;
  809. for (i = 0; !err && i < numargs; i++) {
  810. struct fuse_arg *arg = &args[i];
  811. if (i == numargs - 1 && argpages)
  812. err = fuse_copy_pages(cs, arg->size, zeroing);
  813. else
  814. err = fuse_copy_one(cs, arg->value, arg->size);
  815. }
  816. return err;
  817. }
  818. static int forget_pending(struct fuse_conn *fc)
  819. {
  820. return fc->forget_list_head.next != NULL;
  821. }
  822. static int request_pending(struct fuse_conn *fc)
  823. {
  824. return !list_empty(&fc->pending) || !list_empty(&fc->interrupts) ||
  825. forget_pending(fc);
  826. }
  827. /* Wait until a request is available on the pending list */
  828. static void request_wait(struct fuse_conn *fc)
  829. __releases(fc->lock)
  830. __acquires(fc->lock)
  831. {
  832. DECLARE_WAITQUEUE(wait, current);
  833. add_wait_queue_exclusive(&fc->waitq, &wait);
  834. while (fc->connected && !request_pending(fc)) {
  835. set_current_state(TASK_INTERRUPTIBLE);
  836. if (signal_pending(current))
  837. break;
  838. spin_unlock(&fc->lock);
  839. schedule();
  840. spin_lock(&fc->lock);
  841. }
  842. set_current_state(TASK_RUNNING);
  843. remove_wait_queue(&fc->waitq, &wait);
  844. }
  845. /*
  846. * Transfer an interrupt request to userspace
  847. *
  848. * Unlike other requests this is assembled on demand, without a need
  849. * to allocate a separate fuse_req structure.
  850. *
  851. * Called with fc->lock held, releases it
  852. */
  853. static int fuse_read_interrupt(struct fuse_conn *fc, struct fuse_copy_state *cs,
  854. size_t nbytes, struct fuse_req *req)
  855. __releases(fc->lock)
  856. {
  857. struct fuse_in_header ih;
  858. struct fuse_interrupt_in arg;
  859. unsigned reqsize = sizeof(ih) + sizeof(arg);
  860. int err;
  861. list_del_init(&req->intr_entry);
  862. req->intr_unique = fuse_get_unique(fc);
  863. memset(&ih, 0, sizeof(ih));
  864. memset(&arg, 0, sizeof(arg));
  865. ih.len = reqsize;
  866. ih.opcode = FUSE_INTERRUPT;
  867. ih.unique = req->intr_unique;
  868. arg.unique = req->in.h.unique;
  869. spin_unlock(&fc->lock);
  870. if (nbytes < reqsize)
  871. return -EINVAL;
  872. err = fuse_copy_one(cs, &ih, sizeof(ih));
  873. if (!err)
  874. err = fuse_copy_one(cs, &arg, sizeof(arg));
  875. fuse_copy_finish(cs);
  876. return err ? err : reqsize;
  877. }
  878. static struct fuse_forget_link *dequeue_forget(struct fuse_conn *fc,
  879. unsigned max,
  880. unsigned *countp)
  881. {
  882. struct fuse_forget_link *head = fc->forget_list_head.next;
  883. struct fuse_forget_link **newhead = &head;
  884. unsigned count;
  885. for (count = 0; *newhead != NULL && count < max; count++)
  886. newhead = &(*newhead)->next;
  887. fc->forget_list_head.next = *newhead;
  888. *newhead = NULL;
  889. if (fc->forget_list_head.next == NULL)
  890. fc->forget_list_tail = &fc->forget_list_head;
  891. if (countp != NULL)
  892. *countp = count;
  893. return head;
  894. }
  895. static int fuse_read_single_forget(struct fuse_conn *fc,
  896. struct fuse_copy_state *cs,
  897. size_t nbytes)
  898. __releases(fc->lock)
  899. {
  900. int err;
  901. struct fuse_forget_link *forget = dequeue_forget(fc, 1, NULL);
  902. struct fuse_forget_in arg = {
  903. .nlookup = forget->forget_one.nlookup,
  904. };
  905. struct fuse_in_header ih = {
  906. .opcode = FUSE_FORGET,
  907. .nodeid = forget->forget_one.nodeid,
  908. .unique = fuse_get_unique(fc),
  909. .len = sizeof(ih) + sizeof(arg),
  910. };
  911. spin_unlock(&fc->lock);
  912. kfree(forget);
  913. if (nbytes < ih.len)
  914. return -EINVAL;
  915. err = fuse_copy_one(cs, &ih, sizeof(ih));
  916. if (!err)
  917. err = fuse_copy_one(cs, &arg, sizeof(arg));
  918. fuse_copy_finish(cs);
  919. if (err)
  920. return err;
  921. return ih.len;
  922. }
  923. static int fuse_read_batch_forget(struct fuse_conn *fc,
  924. struct fuse_copy_state *cs, size_t nbytes)
  925. __releases(fc->lock)
  926. {
  927. int err;
  928. unsigned max_forgets;
  929. unsigned count;
  930. struct fuse_forget_link *head;
  931. struct fuse_batch_forget_in arg = { .count = 0 };
  932. struct fuse_in_header ih = {
  933. .opcode = FUSE_BATCH_FORGET,
  934. .unique = fuse_get_unique(fc),
  935. .len = sizeof(ih) + sizeof(arg),
  936. };
  937. if (nbytes < ih.len) {
  938. spin_unlock(&fc->lock);
  939. return -EINVAL;
  940. }
  941. max_forgets = (nbytes - ih.len) / sizeof(struct fuse_forget_one);
  942. head = dequeue_forget(fc, max_forgets, &count);
  943. spin_unlock(&fc->lock);
  944. arg.count = count;
  945. ih.len += count * sizeof(struct fuse_forget_one);
  946. err = fuse_copy_one(cs, &ih, sizeof(ih));
  947. if (!err)
  948. err = fuse_copy_one(cs, &arg, sizeof(arg));
  949. while (head) {
  950. struct fuse_forget_link *forget = head;
  951. if (!err) {
  952. err = fuse_copy_one(cs, &forget->forget_one,
  953. sizeof(forget->forget_one));
  954. }
  955. head = forget->next;
  956. kfree(forget);
  957. }
  958. fuse_copy_finish(cs);
  959. if (err)
  960. return err;
  961. return ih.len;
  962. }
  963. static int fuse_read_forget(struct fuse_conn *fc, struct fuse_copy_state *cs,
  964. size_t nbytes)
  965. __releases(fc->lock)
  966. {
  967. if (fc->minor < 16 || fc->forget_list_head.next->next == NULL)
  968. return fuse_read_single_forget(fc, cs, nbytes);
  969. else
  970. return fuse_read_batch_forget(fc, cs, nbytes);
  971. }
  972. /*
  973. * Read a single request into the userspace filesystem's buffer. This
  974. * function waits until a request is available, then removes it from
  975. * the pending list and copies request data to userspace buffer. If
  976. * no reply is needed (FORGET) or request has been aborted or there
  977. * was an error during the copying then it's finished by calling
  978. * request_end(). Otherwise add it to the processing list, and set
  979. * the 'sent' flag.
  980. */
  981. static ssize_t fuse_dev_do_read(struct fuse_conn *fc, struct file *file,
  982. struct fuse_copy_state *cs, size_t nbytes)
  983. {
  984. int err;
  985. struct fuse_req *req;
  986. struct fuse_in *in;
  987. unsigned reqsize;
  988. restart:
  989. spin_lock(&fc->lock);
  990. err = -EAGAIN;
  991. if ((file->f_flags & O_NONBLOCK) && fc->connected &&
  992. !request_pending(fc))
  993. goto err_unlock;
  994. request_wait(fc);
  995. err = -ENODEV;
  996. if (!fc->connected)
  997. goto err_unlock;
  998. err = -ERESTARTSYS;
  999. if (!request_pending(fc))
  1000. goto err_unlock;
  1001. if (!list_empty(&fc->interrupts)) {
  1002. req = list_entry(fc->interrupts.next, struct fuse_req,
  1003. intr_entry);
  1004. return fuse_read_interrupt(fc, cs, nbytes, req);
  1005. }
  1006. if (forget_pending(fc)) {
  1007. if (list_empty(&fc->pending) || fc->forget_batch-- > 0)
  1008. return fuse_read_forget(fc, cs, nbytes);
  1009. if (fc->forget_batch <= -8)
  1010. fc->forget_batch = 16;
  1011. }
  1012. req = list_entry(fc->pending.next, struct fuse_req, list);
  1013. req->state = FUSE_REQ_READING;
  1014. list_move(&req->list, &fc->io);
  1015. in = &req->in;
  1016. reqsize = in->h.len;
  1017. /* If request is too large, reply with an error and restart the read */
  1018. if (nbytes < reqsize) {
  1019. req->out.h.error = -EIO;
  1020. /* SETXATTR is special, since it may contain too large data */
  1021. if (in->h.opcode == FUSE_SETXATTR)
  1022. req->out.h.error = -E2BIG;
  1023. request_end(fc, req);
  1024. goto restart;
  1025. }
  1026. spin_unlock(&fc->lock);
  1027. cs->req = req;
  1028. err = fuse_copy_one(cs, &in->h, sizeof(in->h));
  1029. if (!err)
  1030. err = fuse_copy_args(cs, in->numargs, in->argpages,
  1031. (struct fuse_arg *) in->args, 0);
  1032. fuse_copy_finish(cs);
  1033. spin_lock(&fc->lock);
  1034. req->locked = 0;
  1035. if (req->aborted) {
  1036. request_end(fc, req);
  1037. return -ENODEV;
  1038. }
  1039. if (err) {
  1040. req->out.h.error = -EIO;
  1041. request_end(fc, req);
  1042. return err;
  1043. }
  1044. if (!req->isreply)
  1045. request_end(fc, req);
  1046. else {
  1047. req->state = FUSE_REQ_SENT;
  1048. list_move_tail(&req->list, &fc->processing);
  1049. if (req->interrupted)
  1050. queue_interrupt(fc, req);
  1051. spin_unlock(&fc->lock);
  1052. }
  1053. return reqsize;
  1054. err_unlock:
  1055. spin_unlock(&fc->lock);
  1056. return err;
  1057. }
  1058. static ssize_t fuse_dev_read(struct kiocb *iocb, const struct iovec *iov,
  1059. unsigned long nr_segs, loff_t pos)
  1060. {
  1061. struct fuse_copy_state cs;
  1062. struct file *file = iocb->ki_filp;
  1063. struct fuse_conn *fc = fuse_get_conn(file);
  1064. if (!fc)
  1065. return -EPERM;
  1066. fuse_copy_init(&cs, fc, 1, iov, nr_segs);
  1067. return fuse_dev_do_read(fc, file, &cs, iov_length(iov, nr_segs));
  1068. }
  1069. static int fuse_dev_pipe_buf_steal(struct pipe_inode_info *pipe,
  1070. struct pipe_buffer *buf)
  1071. {
  1072. return 1;
  1073. }
  1074. static const struct pipe_buf_operations fuse_dev_pipe_buf_ops = {
  1075. .can_merge = 0,
  1076. .map = generic_pipe_buf_map,
  1077. .unmap = generic_pipe_buf_unmap,
  1078. .confirm = generic_pipe_buf_confirm,
  1079. .release = generic_pipe_buf_release,
  1080. .steal = fuse_dev_pipe_buf_steal,
  1081. .get = generic_pipe_buf_get,
  1082. };
  1083. static ssize_t fuse_dev_splice_read(struct file *in, loff_t *ppos,
  1084. struct pipe_inode_info *pipe,
  1085. size_t len, unsigned int flags)
  1086. {
  1087. int ret;
  1088. int page_nr = 0;
  1089. int do_wakeup = 0;
  1090. struct pipe_buffer *bufs;
  1091. struct fuse_copy_state cs;
  1092. struct fuse_conn *fc = fuse_get_conn(in);
  1093. if (!fc)
  1094. return -EPERM;
  1095. bufs = kmalloc(pipe->buffers * sizeof(struct pipe_buffer), GFP_KERNEL);
  1096. if (!bufs)
  1097. return -ENOMEM;
  1098. fuse_copy_init(&cs, fc, 1, NULL, 0);
  1099. cs.pipebufs = bufs;
  1100. cs.pipe = pipe;
  1101. ret = fuse_dev_do_read(fc, in, &cs, len);
  1102. if (ret < 0)
  1103. goto out;
  1104. ret = 0;
  1105. pipe_lock(pipe);
  1106. if (!pipe->readers) {
  1107. send_sig(SIGPIPE, current, 0);
  1108. if (!ret)
  1109. ret = -EPIPE;
  1110. goto out_unlock;
  1111. }
  1112. if (pipe->nrbufs + cs.nr_segs > pipe->buffers) {
  1113. ret = -EIO;
  1114. goto out_unlock;
  1115. }
  1116. while (page_nr < cs.nr_segs) {
  1117. int newbuf = (pipe->curbuf + pipe->nrbufs) & (pipe->buffers - 1);
  1118. struct pipe_buffer *buf = pipe->bufs + newbuf;
  1119. buf->page = bufs[page_nr].page;
  1120. buf->offset = bufs[page_nr].offset;
  1121. buf->len = bufs[page_nr].len;
  1122. buf->ops = &fuse_dev_pipe_buf_ops;
  1123. pipe->nrbufs++;
  1124. page_nr++;
  1125. ret += buf->len;
  1126. if (pipe->inode)
  1127. do_wakeup = 1;
  1128. }
  1129. out_unlock:
  1130. pipe_unlock(pipe);
  1131. if (do_wakeup) {
  1132. smp_mb();
  1133. if (waitqueue_active(&pipe->wait))
  1134. wake_up_interruptible(&pipe->wait);
  1135. kill_fasync(&pipe->fasync_readers, SIGIO, POLL_IN);
  1136. }
  1137. out:
  1138. for (; page_nr < cs.nr_segs; page_nr++)
  1139. page_cache_release(bufs[page_nr].page);
  1140. kfree(bufs);
  1141. return ret;
  1142. }
  1143. static int fuse_notify_poll(struct fuse_conn *fc, unsigned int size,
  1144. struct fuse_copy_state *cs)
  1145. {
  1146. struct fuse_notify_poll_wakeup_out outarg;
  1147. int err = -EINVAL;
  1148. if (size != sizeof(outarg))
  1149. goto err;
  1150. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1151. if (err)
  1152. goto err;
  1153. fuse_copy_finish(cs);
  1154. return fuse_notify_poll_wakeup(fc, &outarg);
  1155. err:
  1156. fuse_copy_finish(cs);
  1157. return err;
  1158. }
  1159. static int fuse_notify_inval_inode(struct fuse_conn *fc, unsigned int size,
  1160. struct fuse_copy_state *cs)
  1161. {
  1162. struct fuse_notify_inval_inode_out outarg;
  1163. int err = -EINVAL;
  1164. if (size != sizeof(outarg))
  1165. goto err;
  1166. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1167. if (err)
  1168. goto err;
  1169. fuse_copy_finish(cs);
  1170. down_read(&fc->killsb);
  1171. err = -ENOENT;
  1172. if (fc->sb) {
  1173. err = fuse_reverse_inval_inode(fc->sb, outarg.ino,
  1174. outarg.off, outarg.len);
  1175. }
  1176. up_read(&fc->killsb);
  1177. return err;
  1178. err:
  1179. fuse_copy_finish(cs);
  1180. return err;
  1181. }
  1182. static int fuse_notify_inval_entry(struct fuse_conn *fc, unsigned int size,
  1183. struct fuse_copy_state *cs)
  1184. {
  1185. struct fuse_notify_inval_entry_out outarg;
  1186. int err = -ENOMEM;
  1187. char *buf;
  1188. struct qstr name;
  1189. buf = kzalloc(FUSE_NAME_MAX + 1, GFP_KERNEL);
  1190. if (!buf)
  1191. goto err;
  1192. err = -EINVAL;
  1193. if (size < sizeof(outarg))
  1194. goto err;
  1195. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1196. if (err)
  1197. goto err;
  1198. err = -ENAMETOOLONG;
  1199. if (outarg.namelen > FUSE_NAME_MAX)
  1200. goto err;
  1201. err = -EINVAL;
  1202. if (size != sizeof(outarg) + outarg.namelen + 1)
  1203. goto err;
  1204. name.name = buf;
  1205. name.len = outarg.namelen;
  1206. err = fuse_copy_one(cs, buf, outarg.namelen + 1);
  1207. if (err)
  1208. goto err;
  1209. fuse_copy_finish(cs);
  1210. buf[outarg.namelen] = 0;
  1211. name.hash = full_name_hash(name.name, name.len);
  1212. down_read(&fc->killsb);
  1213. err = -ENOENT;
  1214. if (fc->sb)
  1215. err = fuse_reverse_inval_entry(fc->sb, outarg.parent, 0, &name);
  1216. up_read(&fc->killsb);
  1217. kfree(buf);
  1218. return err;
  1219. err:
  1220. kfree(buf);
  1221. fuse_copy_finish(cs);
  1222. return err;
  1223. }
  1224. static int fuse_notify_delete(struct fuse_conn *fc, unsigned int size,
  1225. struct fuse_copy_state *cs)
  1226. {
  1227. struct fuse_notify_delete_out outarg;
  1228. int err = -ENOMEM;
  1229. char *buf;
  1230. struct qstr name;
  1231. buf = kzalloc(FUSE_NAME_MAX + 1, GFP_KERNEL);
  1232. if (!buf)
  1233. goto err;
  1234. err = -EINVAL;
  1235. if (size < sizeof(outarg))
  1236. goto err;
  1237. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1238. if (err)
  1239. goto err;
  1240. err = -ENAMETOOLONG;
  1241. if (outarg.namelen > FUSE_NAME_MAX)
  1242. goto err;
  1243. err = -EINVAL;
  1244. if (size != sizeof(outarg) + outarg.namelen + 1)
  1245. goto err;
  1246. name.name = buf;
  1247. name.len = outarg.namelen;
  1248. err = fuse_copy_one(cs, buf, outarg.namelen + 1);
  1249. if (err)
  1250. goto err;
  1251. fuse_copy_finish(cs);
  1252. buf[outarg.namelen] = 0;
  1253. name.hash = full_name_hash(name.name, name.len);
  1254. down_read(&fc->killsb);
  1255. err = -ENOENT;
  1256. if (fc->sb)
  1257. err = fuse_reverse_inval_entry(fc->sb, outarg.parent,
  1258. outarg.child, &name);
  1259. up_read(&fc->killsb);
  1260. kfree(buf);
  1261. return err;
  1262. err:
  1263. kfree(buf);
  1264. fuse_copy_finish(cs);
  1265. return err;
  1266. }
  1267. static int fuse_notify_store(struct fuse_conn *fc, unsigned int size,
  1268. struct fuse_copy_state *cs)
  1269. {
  1270. struct fuse_notify_store_out outarg;
  1271. struct inode *inode;
  1272. struct address_space *mapping;
  1273. u64 nodeid;
  1274. int err;
  1275. pgoff_t index;
  1276. unsigned int offset;
  1277. unsigned int num;
  1278. loff_t file_size;
  1279. loff_t end;
  1280. err = -EINVAL;
  1281. if (size < sizeof(outarg))
  1282. goto out_finish;
  1283. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1284. if (err)
  1285. goto out_finish;
  1286. err = -EINVAL;
  1287. if (size - sizeof(outarg) != outarg.size)
  1288. goto out_finish;
  1289. nodeid = outarg.nodeid;
  1290. down_read(&fc->killsb);
  1291. err = -ENOENT;
  1292. if (!fc->sb)
  1293. goto out_up_killsb;
  1294. inode = ilookup5(fc->sb, nodeid, fuse_inode_eq, &nodeid);
  1295. if (!inode)
  1296. goto out_up_killsb;
  1297. mapping = inode->i_mapping;
  1298. index = outarg.offset >> PAGE_CACHE_SHIFT;
  1299. offset = outarg.offset & ~PAGE_CACHE_MASK;
  1300. file_size = i_size_read(inode);
  1301. end = outarg.offset + outarg.size;
  1302. if (end > file_size) {
  1303. file_size = end;
  1304. fuse_write_update_size(inode, file_size);
  1305. }
  1306. num = outarg.size;
  1307. while (num) {
  1308. struct page *page;
  1309. unsigned int this_num;
  1310. err = -ENOMEM;
  1311. page = find_or_create_page(mapping, index,
  1312. mapping_gfp_mask(mapping));
  1313. if (!page)
  1314. goto out_iput;
  1315. this_num = min_t(unsigned, num, PAGE_CACHE_SIZE - offset);
  1316. err = fuse_copy_page(cs, &page, offset, this_num, 0);
  1317. if (!err && offset == 0 && (num != 0 || file_size == end))
  1318. SetPageUptodate(page);
  1319. unlock_page(page);
  1320. page_cache_release(page);
  1321. if (err)
  1322. goto out_iput;
  1323. num -= this_num;
  1324. offset = 0;
  1325. index++;
  1326. }
  1327. err = 0;
  1328. out_iput:
  1329. iput(inode);
  1330. out_up_killsb:
  1331. up_read(&fc->killsb);
  1332. out_finish:
  1333. fuse_copy_finish(cs);
  1334. return err;
  1335. }
  1336. static void fuse_retrieve_end(struct fuse_conn *fc, struct fuse_req *req)
  1337. {
  1338. release_pages(req->pages, req->num_pages, 0);
  1339. }
  1340. static int fuse_retrieve(struct fuse_conn *fc, struct inode *inode,
  1341. struct fuse_notify_retrieve_out *outarg)
  1342. {
  1343. int err;
  1344. struct address_space *mapping = inode->i_mapping;
  1345. struct fuse_req *req;
  1346. pgoff_t index;
  1347. loff_t file_size;
  1348. unsigned int num;
  1349. unsigned int offset;
  1350. size_t total_len = 0;
  1351. req = fuse_get_req(fc, FUSE_MAX_PAGES_PER_REQ);
  1352. if (IS_ERR(req))
  1353. return PTR_ERR(req);
  1354. offset = outarg->offset & ~PAGE_CACHE_MASK;
  1355. req->in.h.opcode = FUSE_NOTIFY_REPLY;
  1356. req->in.h.nodeid = outarg->nodeid;
  1357. req->in.numargs = 2;
  1358. req->in.argpages = 1;
  1359. req->page_offset = offset;
  1360. req->end = fuse_retrieve_end;
  1361. index = outarg->offset >> PAGE_CACHE_SHIFT;
  1362. file_size = i_size_read(inode);
  1363. num = outarg->size;
  1364. if (outarg->offset > file_size)
  1365. num = 0;
  1366. else if (outarg->offset + num > file_size)
  1367. num = file_size - outarg->offset;
  1368. while (num && req->num_pages < FUSE_MAX_PAGES_PER_REQ) {
  1369. struct page *page;
  1370. unsigned int this_num;
  1371. page = find_get_page(mapping, index);
  1372. if (!page)
  1373. break;
  1374. this_num = min_t(unsigned, num, PAGE_CACHE_SIZE - offset);
  1375. req->pages[req->num_pages] = page;
  1376. req->num_pages++;
  1377. offset = 0;
  1378. num -= this_num;
  1379. total_len += this_num;
  1380. index++;
  1381. }
  1382. req->misc.retrieve_in.offset = outarg->offset;
  1383. req->misc.retrieve_in.size = total_len;
  1384. req->in.args[0].size = sizeof(req->misc.retrieve_in);
  1385. req->in.args[0].value = &req->misc.retrieve_in;
  1386. req->in.args[1].size = total_len;
  1387. err = fuse_request_send_notify_reply(fc, req, outarg->notify_unique);
  1388. if (err)
  1389. fuse_retrieve_end(fc, req);
  1390. return err;
  1391. }
  1392. static int fuse_notify_retrieve(struct fuse_conn *fc, unsigned int size,
  1393. struct fuse_copy_state *cs)
  1394. {
  1395. struct fuse_notify_retrieve_out outarg;
  1396. struct inode *inode;
  1397. int err;
  1398. err = -EINVAL;
  1399. if (size != sizeof(outarg))
  1400. goto copy_finish;
  1401. err = fuse_copy_one(cs, &outarg, sizeof(outarg));
  1402. if (err)
  1403. goto copy_finish;
  1404. fuse_copy_finish(cs);
  1405. down_read(&fc->killsb);
  1406. err = -ENOENT;
  1407. if (fc->sb) {
  1408. u64 nodeid = outarg.nodeid;
  1409. inode = ilookup5(fc->sb, nodeid, fuse_inode_eq, &nodeid);
  1410. if (inode) {
  1411. err = fuse_retrieve(fc, inode, &outarg);
  1412. iput(inode);
  1413. }
  1414. }
  1415. up_read(&fc->killsb);
  1416. return err;
  1417. copy_finish:
  1418. fuse_copy_finish(cs);
  1419. return err;
  1420. }
  1421. static int fuse_notify(struct fuse_conn *fc, enum fuse_notify_code code,
  1422. unsigned int size, struct fuse_copy_state *cs)
  1423. {
  1424. switch (code) {
  1425. case FUSE_NOTIFY_POLL:
  1426. return fuse_notify_poll(fc, size, cs);
  1427. case FUSE_NOTIFY_INVAL_INODE:
  1428. return fuse_notify_inval_inode(fc, size, cs);
  1429. case FUSE_NOTIFY_INVAL_ENTRY:
  1430. return fuse_notify_inval_entry(fc, size, cs);
  1431. case FUSE_NOTIFY_STORE:
  1432. return fuse_notify_store(fc, size, cs);
  1433. case FUSE_NOTIFY_RETRIEVE:
  1434. return fuse_notify_retrieve(fc, size, cs);
  1435. case FUSE_NOTIFY_DELETE:
  1436. return fuse_notify_delete(fc, size, cs);
  1437. default:
  1438. fuse_copy_finish(cs);
  1439. return -EINVAL;
  1440. }
  1441. }
  1442. /* Look up request on processing list by unique ID */
  1443. static struct fuse_req *request_find(struct fuse_conn *fc, u64 unique)
  1444. {
  1445. struct list_head *entry;
  1446. list_for_each(entry, &fc->processing) {
  1447. struct fuse_req *req;
  1448. req = list_entry(entry, struct fuse_req, list);
  1449. if (req->in.h.unique == unique || req->intr_unique == unique)
  1450. return req;
  1451. }
  1452. return NULL;
  1453. }
  1454. static int copy_out_args(struct fuse_copy_state *cs, struct fuse_out *out,
  1455. unsigned nbytes)
  1456. {
  1457. unsigned reqsize = sizeof(struct fuse_out_header);
  1458. if (out->h.error)
  1459. return nbytes != reqsize ? -EINVAL : 0;
  1460. reqsize += len_args(out->numargs, out->args);
  1461. if (reqsize < nbytes || (reqsize > nbytes && !out->argvar))
  1462. return -EINVAL;
  1463. else if (reqsize > nbytes) {
  1464. struct fuse_arg *lastarg = &out->args[out->numargs-1];
  1465. unsigned diffsize = reqsize - nbytes;
  1466. if (diffsize > lastarg->size)
  1467. return -EINVAL;
  1468. lastarg->size -= diffsize;
  1469. }
  1470. return fuse_copy_args(cs, out->numargs, out->argpages, out->args,
  1471. out->page_zeroing);
  1472. }
  1473. /*
  1474. * Write a single reply to a request. First the header is copied from
  1475. * the write buffer. The request is then searched on the processing
  1476. * list by the unique ID found in the header. If found, then remove
  1477. * it from the list and copy the rest of the buffer to the request.
  1478. * The request is finished by calling request_end()
  1479. */
  1480. static ssize_t fuse_dev_do_write(struct fuse_conn *fc,
  1481. struct fuse_copy_state *cs, size_t nbytes)
  1482. {
  1483. int err;
  1484. struct fuse_req *req;
  1485. struct fuse_out_header oh;
  1486. if (nbytes < sizeof(struct fuse_out_header))
  1487. return -EINVAL;
  1488. err = fuse_copy_one(cs, &oh, sizeof(oh));
  1489. if (err)
  1490. goto err_finish;
  1491. err = -EINVAL;
  1492. if (oh.len != nbytes)
  1493. goto err_finish;
  1494. /*
  1495. * Zero oh.unique indicates unsolicited notification message
  1496. * and error contains notification code.
  1497. */
  1498. if (!oh.unique) {
  1499. err = fuse_notify(fc, oh.error, nbytes - sizeof(oh), cs);
  1500. return err ? err : nbytes;
  1501. }
  1502. err = -EINVAL;
  1503. if (oh.error <= -1000 || oh.error > 0)
  1504. goto err_finish;
  1505. spin_lock(&fc->lock);
  1506. err = -ENOENT;
  1507. if (!fc->connected)
  1508. goto err_unlock;
  1509. req = request_find(fc, oh.unique);
  1510. if (!req)
  1511. goto err_unlock;
  1512. if (req->aborted) {
  1513. spin_unlock(&fc->lock);
  1514. fuse_copy_finish(cs);
  1515. spin_lock(&fc->lock);
  1516. request_end(fc, req);
  1517. return -ENOENT;
  1518. }
  1519. /* Is it an interrupt reply? */
  1520. if (req->intr_unique == oh.unique) {
  1521. err = -EINVAL;
  1522. if (nbytes != sizeof(struct fuse_out_header))
  1523. goto err_unlock;
  1524. if (oh.error == -ENOSYS)
  1525. fc->no_interrupt = 1;
  1526. else if (oh.error == -EAGAIN)
  1527. queue_interrupt(fc, req);
  1528. spin_unlock(&fc->lock);
  1529. fuse_copy_finish(cs);
  1530. return nbytes;
  1531. }
  1532. req->state = FUSE_REQ_WRITING;
  1533. list_move(&req->list, &fc->io);
  1534. req->out.h = oh;
  1535. req->locked = 1;
  1536. cs->req = req;
  1537. if (!req->out.page_replace)
  1538. cs->move_pages = 0;
  1539. spin_unlock(&fc->lock);
  1540. err = copy_out_args(cs, &req->out, nbytes);
  1541. fuse_copy_finish(cs);
  1542. spin_lock(&fc->lock);
  1543. req->locked = 0;
  1544. if (!err) {
  1545. if (req->aborted)
  1546. err = -ENOENT;
  1547. } else if (!req->aborted)
  1548. req->out.h.error = -EIO;
  1549. request_end(fc, req);
  1550. return err ? err : nbytes;
  1551. err_unlock:
  1552. spin_unlock(&fc->lock);
  1553. err_finish:
  1554. fuse_copy_finish(cs);
  1555. return err;
  1556. }
  1557. static ssize_t fuse_dev_write(struct kiocb *iocb, const struct iovec *iov,
  1558. unsigned long nr_segs, loff_t pos)
  1559. {
  1560. struct fuse_copy_state cs;
  1561. struct fuse_conn *fc = fuse_get_conn(iocb->ki_filp);
  1562. if (!fc)
  1563. return -EPERM;
  1564. fuse_copy_init(&cs, fc, 0, iov, nr_segs);
  1565. return fuse_dev_do_write(fc, &cs, iov_length(iov, nr_segs));
  1566. }
  1567. static ssize_t fuse_dev_splice_write(struct pipe_inode_info *pipe,
  1568. struct file *out, loff_t *ppos,
  1569. size_t len, unsigned int flags)
  1570. {
  1571. unsigned nbuf;
  1572. unsigned idx;
  1573. struct pipe_buffer *bufs;
  1574. struct fuse_copy_state cs;
  1575. struct fuse_conn *fc;
  1576. size_t rem;
  1577. ssize_t ret;
  1578. fc = fuse_get_conn(out);
  1579. if (!fc)
  1580. return -EPERM;
  1581. bufs = kmalloc(pipe->buffers * sizeof(struct pipe_buffer), GFP_KERNEL);
  1582. if (!bufs)
  1583. return -ENOMEM;
  1584. pipe_lock(pipe);
  1585. nbuf = 0;
  1586. rem = 0;
  1587. for (idx = 0; idx < pipe->nrbufs && rem < len; idx++)
  1588. rem += pipe->bufs[(pipe->curbuf + idx) & (pipe->buffers - 1)].len;
  1589. ret = -EINVAL;
  1590. if (rem < len) {
  1591. pipe_unlock(pipe);
  1592. goto out;
  1593. }
  1594. rem = len;
  1595. while (rem) {
  1596. struct pipe_buffer *ibuf;
  1597. struct pipe_buffer *obuf;
  1598. BUG_ON(nbuf >= pipe->buffers);
  1599. BUG_ON(!pipe->nrbufs);
  1600. ibuf = &pipe->bufs[pipe->curbuf];
  1601. obuf = &bufs[nbuf];
  1602. if (rem >= ibuf->len) {
  1603. *obuf = *ibuf;
  1604. ibuf->ops = NULL;
  1605. pipe->curbuf = (pipe->curbuf + 1) & (pipe->buffers - 1);
  1606. pipe->nrbufs--;
  1607. } else {
  1608. ibuf->ops->get(pipe, ibuf);
  1609. *obuf = *ibuf;
  1610. obuf->flags &= ~PIPE_BUF_FLAG_GIFT;
  1611. obuf->len = rem;
  1612. ibuf->offset += obuf->len;
  1613. ibuf->len -= obuf->len;
  1614. }
  1615. nbuf++;
  1616. rem -= obuf->len;
  1617. }
  1618. pipe_unlock(pipe);
  1619. fuse_copy_init(&cs, fc, 0, NULL, nbuf);
  1620. cs.pipebufs = bufs;
  1621. cs.pipe = pipe;
  1622. if (flags & SPLICE_F_MOVE)
  1623. cs.move_pages = 1;
  1624. ret = fuse_dev_do_write(fc, &cs, len);
  1625. for (idx = 0; idx < nbuf; idx++) {
  1626. struct pipe_buffer *buf = &bufs[idx];
  1627. buf->ops->release(pipe, buf);
  1628. }
  1629. out:
  1630. kfree(bufs);
  1631. return ret;
  1632. }
  1633. static unsigned fuse_dev_poll(struct file *file, poll_table *wait)
  1634. {
  1635. unsigned mask = POLLOUT | POLLWRNORM;
  1636. struct fuse_conn *fc = fuse_get_conn(file);
  1637. if (!fc)
  1638. return POLLERR;
  1639. poll_wait(file, &fc->waitq, wait);
  1640. spin_lock(&fc->lock);
  1641. if (!fc->connected)
  1642. mask = POLLERR;
  1643. else if (request_pending(fc))
  1644. mask |= POLLIN | POLLRDNORM;
  1645. spin_unlock(&fc->lock);
  1646. return mask;
  1647. }
  1648. /*
  1649. * Abort all requests on the given list (pending or processing)
  1650. *
  1651. * This function releases and reacquires fc->lock
  1652. */
  1653. static void end_requests(struct fuse_conn *fc, struct list_head *head)
  1654. __releases(fc->lock)
  1655. __acquires(fc->lock)
  1656. {
  1657. while (!list_empty(head)) {
  1658. struct fuse_req *req;
  1659. req = list_entry(head->next, struct fuse_req, list);
  1660. req->out.h.error = -ECONNABORTED;
  1661. request_end(fc, req);
  1662. spin_lock(&fc->lock);
  1663. }
  1664. }
  1665. /*
  1666. * Abort requests under I/O
  1667. *
  1668. * The requests are set to aborted and finished, and the request
  1669. * waiter is woken up. This will make request_wait_answer() wait
  1670. * until the request is unlocked and then return.
  1671. *
  1672. * If the request is asynchronous, then the end function needs to be
  1673. * called after waiting for the request to be unlocked (if it was
  1674. * locked).
  1675. */
  1676. static void end_io_requests(struct fuse_conn *fc)
  1677. __releases(fc->lock)
  1678. __acquires(fc->lock)
  1679. {
  1680. while (!list_empty(&fc->io)) {
  1681. struct fuse_req *req =
  1682. list_entry(fc->io.next, struct fuse_req, list);
  1683. void (*end) (struct fuse_conn *, struct fuse_req *) = req->end;
  1684. req->aborted = 1;
  1685. req->out.h.error = -ECONNABORTED;
  1686. req->state = FUSE_REQ_FINISHED;
  1687. list_del_init(&req->list);
  1688. wake_up(&req->waitq);
  1689. if (end) {
  1690. req->end = NULL;
  1691. __fuse_get_request(req);
  1692. spin_unlock(&fc->lock);
  1693. wait_event(req->waitq, !req->locked);
  1694. end(fc, req);
  1695. fuse_put_request(fc, req);
  1696. spin_lock(&fc->lock);
  1697. }
  1698. }
  1699. }
  1700. static void end_queued_requests(struct fuse_conn *fc)
  1701. __releases(fc->lock)
  1702. __acquires(fc->lock)
  1703. {
  1704. fc->max_background = UINT_MAX;
  1705. flush_bg_queue(fc);
  1706. end_requests(fc, &fc->pending);
  1707. end_requests(fc, &fc->processing);
  1708. while (forget_pending(fc))
  1709. kfree(dequeue_forget(fc, 1, NULL));
  1710. }
  1711. static void end_polls(struct fuse_conn *fc)
  1712. {
  1713. struct rb_node *p;
  1714. p = rb_first(&fc->polled_files);
  1715. while (p) {
  1716. struct fuse_file *ff;
  1717. ff = rb_entry(p, struct fuse_file, polled_node);
  1718. wake_up_interruptible_all(&ff->poll_wait);
  1719. p = rb_next(p);
  1720. }
  1721. }
  1722. /*
  1723. * Abort all requests.
  1724. *
  1725. * Emergency exit in case of a malicious or accidental deadlock, or
  1726. * just a hung filesystem.
  1727. *
  1728. * The same effect is usually achievable through killing the
  1729. * filesystem daemon and all users of the filesystem. The exception
  1730. * is the combination of an asynchronous request and the tricky
  1731. * deadlock (see Documentation/filesystems/fuse.txt).
  1732. *
  1733. * During the aborting, progression of requests from the pending and
  1734. * processing lists onto the io list, and progression of new requests
  1735. * onto the pending list is prevented by req->connected being false.
  1736. *
  1737. * Progression of requests under I/O to the processing list is
  1738. * prevented by the req->aborted flag being true for these requests.
  1739. * For this reason requests on the io list must be aborted first.
  1740. */
  1741. void fuse_abort_conn(struct fuse_conn *fc)
  1742. {
  1743. spin_lock(&fc->lock);
  1744. if (fc->connected) {
  1745. fc->connected = 0;
  1746. fc->blocked = 0;
  1747. end_io_requests(fc);
  1748. end_queued_requests(fc);
  1749. end_polls(fc);
  1750. wake_up_all(&fc->waitq);
  1751. wake_up_all(&fc->blocked_waitq);
  1752. kill_fasync(&fc->fasync, SIGIO, POLL_IN);
  1753. }
  1754. spin_unlock(&fc->lock);
  1755. }
  1756. EXPORT_SYMBOL_GPL(fuse_abort_conn);
  1757. int fuse_dev_release(struct inode *inode, struct file *file)
  1758. {
  1759. struct fuse_conn *fc = fuse_get_conn(file);
  1760. if (fc) {
  1761. spin_lock(&fc->lock);
  1762. fc->connected = 0;
  1763. fc->blocked = 0;
  1764. end_queued_requests(fc);
  1765. end_polls(fc);
  1766. wake_up_all(&fc->blocked_waitq);
  1767. spin_unlock(&fc->lock);
  1768. fuse_conn_put(fc);
  1769. }
  1770. return 0;
  1771. }
  1772. EXPORT_SYMBOL_GPL(fuse_dev_release);
  1773. static int fuse_dev_fasync(int fd, struct file *file, int on)
  1774. {
  1775. struct fuse_conn *fc = fuse_get_conn(file);
  1776. if (!fc)
  1777. return -EPERM;
  1778. /* No locking - fasync_helper does its own locking */
  1779. return fasync_helper(fd, file, on, &fc->fasync);
  1780. }
  1781. const struct file_operations fuse_dev_operations = {
  1782. .owner = THIS_MODULE,
  1783. .llseek = no_llseek,
  1784. .read = do_sync_read,
  1785. .aio_read = fuse_dev_read,
  1786. .splice_read = fuse_dev_splice_read,
  1787. .write = do_sync_write,
  1788. .aio_write = fuse_dev_write,
  1789. .splice_write = fuse_dev_splice_write,
  1790. .poll = fuse_dev_poll,
  1791. .release = fuse_dev_release,
  1792. .fasync = fuse_dev_fasync,
  1793. };
  1794. EXPORT_SYMBOL_GPL(fuse_dev_operations);
  1795. static struct miscdevice fuse_miscdevice = {
  1796. .minor = FUSE_MINOR,
  1797. .name = "fuse",
  1798. .fops = &fuse_dev_operations,
  1799. };
  1800. int __init fuse_dev_init(void)
  1801. {
  1802. int err = -ENOMEM;
  1803. fuse_req_cachep = kmem_cache_create("fuse_request",
  1804. sizeof(struct fuse_req),
  1805. 0, 0, NULL);
  1806. if (!fuse_req_cachep)
  1807. goto out;
  1808. err = misc_register(&fuse_miscdevice);
  1809. if (err)
  1810. goto out_cache_clean;
  1811. return 0;
  1812. out_cache_clean:
  1813. kmem_cache_destroy(fuse_req_cachep);
  1814. out:
  1815. return err;
  1816. }
  1817. void fuse_dev_cleanup(void)
  1818. {
  1819. misc_deregister(&fuse_miscdevice);
  1820. kmem_cache_destroy(fuse_req_cachep);
  1821. }