diff options
| author | Linus Torvalds <torvalds@linux-foundation.org> | 2014-03-03 09:36:58 -0800 | 
|---|---|---|
| committer | Al Viro <viro@zeniv.linux.org.uk> | 2014-03-10 11:44:41 -0400 | 
| commit | 9c225f2655e36a470c4f58dbbc99244c5fc7f2d4 (patch) | |
| tree | 7cb89dbc82ee1b533ff2d097fed6a4248374bd4b /include | |
| parent | 1b56e98990bcdbb20b9fab163654b9315bf158e8 (diff) | |
vfs: atomic f_pos accesses as per POSIX
Our write() system call has always been atomic in the sense that you get
the expected thread-safe contiguous write, but we haven't actually
guaranteed that concurrent writes are serialized wrt f_pos accesses, so
threads (or processes) that share a file descriptor and use "write()"
concurrently would quite likely overwrite each others data.
This violates POSIX.1-2008/SUSv4 Section XSI 2.9.7 that says:
 "2.9.7 Thread Interactions with Regular File Operations
  All of the following functions shall be atomic with respect to each
  other in the effects specified in POSIX.1-2008 when they operate on
  regular files or symbolic links: [...]"
and one of the effects is the file position update.
This unprotected file position behavior is not new behavior, and nobody
has ever cared.  Until now.  Yongzhi Pan reported unexpected behavior to
Michael Kerrisk that was due to this.
This resolves the issue with a f_pos-specific lock that is taken by
read/write/lseek on file descriptors that may be shared across threads
or processes.
Reported-by: Yongzhi Pan <panyongzhi@gmail.com>
Reported-by: Michael Kerrisk <mtk.manpages@gmail.com>
Cc: Al Viro <viro@zeniv.linux.org.uk>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Diffstat (limited to 'include')
| -rw-r--r-- | include/linux/file.h | 6 | ||||
| -rw-r--r-- | include/linux/fs.h | 6 | 
2 files changed, 9 insertions, 3 deletions
| diff --git a/include/linux/file.h b/include/linux/file.h index cbacf4faf447..f2517fa2d610 100644 --- a/include/linux/file.h +++ b/include/linux/file.h @@ -28,12 +28,14 @@ static inline void fput_light(struct file *file, int fput_needed)  struct fd {  	struct file *file; -	int need_put; +	unsigned int flags;  }; +#define FDPUT_FPUT       1 +#define FDPUT_POS_UNLOCK 2  static inline void fdput(struct fd fd)  { -	if (fd.need_put) +	if (fd.flags & FDPUT_FPUT)  		fput(fd.file);  } diff --git a/include/linux/fs.h b/include/linux/fs.h index 60829565e552..ebfde04bca06 100644 --- a/include/linux/fs.h +++ b/include/linux/fs.h @@ -123,6 +123,9 @@ typedef void (dio_iodone_t)(struct kiocb *iocb, loff_t offset,  /* File is opened with O_PATH; almost nothing can be done with it */  #define FMODE_PATH		((__force fmode_t)0x4000) +/* File needs atomic accesses to f_pos */ +#define FMODE_ATOMIC_POS	((__force fmode_t)0x8000) +  /* File was opened by fanotify and shouldn't generate fanotify events */  #define FMODE_NONOTIFY		((__force fmode_t)0x1000000) @@ -780,13 +783,14 @@ struct file {  	const struct file_operations	*f_op;  	/* -	 * Protects f_ep_links, f_flags, f_pos vs i_size in lseek SEEK_CUR. +	 * Protects f_ep_links, f_flags.  	 * Must not be taken from IRQ context.  	 */  	spinlock_t		f_lock;  	atomic_long_t		f_count;  	unsigned int 		f_flags;  	fmode_t			f_mode; +	struct mutex		f_pos_lock;  	loff_t			f_pos;  	struct fown_struct	f_owner;  	const struct cred	*f_cred; | 
