1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32#include <linux/slab.h>
33#include <linux/poll.h>
34#include <linux/fs.h>
35#include <linux/file.h>
36#include <linux/jhash.h>
37#include <linux/init.h>
38#include <linux/futex.h>
39#include <linux/mount.h>
40#include <linux/pagemap.h>
41#include <linux/syscalls.h>
42
43#define FUTEX_HASHBITS 8
44
45
46
47
48
49
50
51
52
53union futex_key {
54 struct {
55 unsigned long pgoff;
56 struct inode *inode;
57 int offset;
58 } shared;
59 struct {
60 unsigned long uaddr;
61 struct mm_struct *mm;
62 int offset;
63 } private;
64 struct {
65 unsigned long word;
66 void *ptr;
67 int offset;
68 } both;
69};
70
71
72
73
74
75
76
77
78
79
80struct futex_q {
81 struct list_head list;
82 wait_queue_head_t waiters;
83
84
85 spinlock_t *lock_ptr;
86
87
88 union futex_key key;
89
90
91 int fd;
92 struct file *filp;
93};
94
95
96
97
98struct futex_hash_bucket {
99 spinlock_t lock;
100 struct list_head chain;
101};
102
103static struct futex_hash_bucket futex_queues[1<<FUTEX_HASHBITS];
104
105
106static struct vfsmount *futex_mnt;
107
108
109
110
111static struct futex_hash_bucket *hash_futex(union futex_key *key)
112{
113 u32 hash = jhash2((u32*)&key->both.word,
114 (sizeof(key->both.word)+sizeof(key->both.ptr))/4,
115 key->both.offset);
116 return &futex_queues[hash & ((1 << FUTEX_HASHBITS)-1)];
117}
118
119
120
121
122static inline int match_futex(union futex_key *key1, union futex_key *key2)
123{
124 return (key1->both.word == key2->both.word
125 && key1->both.ptr == key2->both.ptr
126 && key1->both.offset == key2->both.offset);
127}
128
129
130
131
132
133
134
135
136
137
138
139
140
141static int get_futex_key(unsigned long uaddr, union futex_key *key)
142{
143 struct mm_struct *mm = current->mm;
144 struct vm_area_struct *vma;
145 struct page *page;
146 int err;
147
148
149
150
151 key->both.offset = uaddr % PAGE_SIZE;
152 if (unlikely((key->both.offset % sizeof(u32)) != 0))
153 return -EINVAL;
154 uaddr -= key->both.offset;
155
156
157
158
159
160 vma = find_extend_vma(mm, uaddr);
161 if (unlikely(!vma))
162 return -EFAULT;
163
164
165
166
167 if (unlikely((vma->vm_flags & (VM_IO|VM_READ)) != VM_READ))
168 return (vma->vm_flags & VM_IO) ? -EPERM : -EACCES;
169
170
171
172
173
174
175
176
177
178
179 if (likely(!(vma->vm_flags & VM_MAYSHARE))) {
180 key->private.mm = mm;
181 key->private.uaddr = uaddr;
182 return 0;
183 }
184
185
186
187
188 key->shared.inode = vma->vm_file->f_dentry->d_inode;
189 key->both.offset++;
190 if (likely(!(vma->vm_flags & VM_NONLINEAR))) {
191 key->shared.pgoff = (((uaddr - vma->vm_start) >> PAGE_SHIFT)
192 + vma->vm_pgoff);
193 return 0;
194 }
195
196
197
198
199
200
201
202
203
204
205
206 spin_lock(¤t->mm->page_table_lock);
207 page = follow_page(mm, uaddr, 0);
208 if (likely(page != NULL)) {
209 key->shared.pgoff =
210 page->index << (PAGE_CACHE_SHIFT - PAGE_SHIFT);
211 spin_unlock(¤t->mm->page_table_lock);
212 return 0;
213 }
214 spin_unlock(¤t->mm->page_table_lock);
215
216
217
218
219 err = get_user_pages(current, mm, uaddr, 1, 0, 0, &page, NULL);
220 if (err >= 0) {
221 key->shared.pgoff =
222 page->index << (PAGE_CACHE_SHIFT - PAGE_SHIFT);
223 put_page(page);
224 return 0;
225 }
226 return err;
227}
228
229
230
231
232
233
234
235
236static inline void get_key_refs(union futex_key *key)
237{
238 if (key->both.ptr != 0) {
239 if (key->both.offset & 1)
240 atomic_inc(&key->shared.inode->i_count);
241 else
242 atomic_inc(&key->private.mm->mm_count);
243 }
244}
245
246
247
248
249
250static void drop_key_refs(union futex_key *key)
251{
252 if (key->both.ptr != 0) {
253 if (key->both.offset & 1)
254 iput(key->shared.inode);
255 else
256 mmdrop(key->private.mm);
257 }
258}
259
260static inline int get_futex_value_locked(int *dest, int __user *from)
261{
262 int ret;
263
264 inc_preempt_count();
265 ret = __copy_from_user_inatomic(dest, from, sizeof(int));
266 dec_preempt_count();
267
268 return ret ? -EFAULT : 0;
269}
270
271
272
273
274
275static void wake_futex(struct futex_q *q)
276{
277 list_del_init(&q->list);
278 if (q->filp)
279 send_sigio(&q->filp->f_owner, q->fd, POLL_IN);
280
281
282
283
284 wake_up_all(&q->waiters);
285
286
287
288
289
290
291
292
293
294 wmb();
295 q->lock_ptr = NULL;
296}
297
298
299
300
301
302static int futex_wake(unsigned long uaddr, int nr_wake)
303{
304 union futex_key key;
305 struct futex_hash_bucket *bh;
306 struct list_head *head;
307 struct futex_q *this, *next;
308 int ret;
309
310 down_read(¤t->mm->mmap_sem);
311
312 ret = get_futex_key(uaddr, &key);
313 if (unlikely(ret != 0))
314 goto out;
315
316 bh = hash_futex(&key);
317 spin_lock(&bh->lock);
318 head = &bh->chain;
319
320 list_for_each_entry_safe(this, next, head, list) {
321 if (match_futex (&this->key, &key)) {
322 wake_futex(this);
323 if (++ret >= nr_wake)
324 break;
325 }
326 }
327
328 spin_unlock(&bh->lock);
329out:
330 up_read(¤t->mm->mmap_sem);
331 return ret;
332}
333
334
335
336
337
338static int futex_requeue(unsigned long uaddr1, unsigned long uaddr2,
339 int nr_wake, int nr_requeue, int *valp)
340{
341 union futex_key key1, key2;
342 struct futex_hash_bucket *bh1, *bh2;
343 struct list_head *head1;
344 struct futex_q *this, *next;
345 int ret, drop_count = 0;
346
347 retry:
348 down_read(¤t->mm->mmap_sem);
349
350 ret = get_futex_key(uaddr1, &key1);
351 if (unlikely(ret != 0))
352 goto out;
353 ret = get_futex_key(uaddr2, &key2);
354 if (unlikely(ret != 0))
355 goto out;
356
357 bh1 = hash_futex(&key1);
358 bh2 = hash_futex(&key2);
359
360 if (bh1 < bh2)
361 spin_lock(&bh1->lock);
362 spin_lock(&bh2->lock);
363 if (bh1 > bh2)
364 spin_lock(&bh1->lock);
365
366 if (likely(valp != NULL)) {
367 int curval;
368
369 ret = get_futex_value_locked(&curval, (int __user *)uaddr1);
370
371 if (unlikely(ret)) {
372 spin_unlock(&bh1->lock);
373 if (bh1 != bh2)
374 spin_unlock(&bh2->lock);
375
376
377
378
379 up_read(¤t->mm->mmap_sem);
380
381 ret = get_user(curval, (int __user *)uaddr1);
382
383 if (!ret)
384 goto retry;
385
386 return ret;
387 }
388 if (curval != *valp) {
389 ret = -EAGAIN;
390 goto out_unlock;
391 }
392 }
393
394 head1 = &bh1->chain;
395 list_for_each_entry_safe(this, next, head1, list) {
396 if (!match_futex (&this->key, &key1))
397 continue;
398 if (++ret <= nr_wake) {
399 wake_futex(this);
400 } else {
401 list_move_tail(&this->list, &bh2->chain);
402 this->lock_ptr = &bh2->lock;
403 this->key = key2;
404 get_key_refs(&key2);
405 drop_count++;
406
407 if (ret - nr_wake >= nr_requeue)
408 break;
409
410 if (head1 == &bh2->chain && head1 != &next->list)
411 head1 = &this->list;
412 }
413 }
414
415out_unlock:
416 spin_unlock(&bh1->lock);
417 if (bh1 != bh2)
418 spin_unlock(&bh2->lock);
419
420
421 while (--drop_count >= 0)
422 drop_key_refs(&key1);
423
424out:
425 up_read(¤t->mm->mmap_sem);
426 return ret;
427}
428
429
430static inline struct futex_hash_bucket *
431queue_lock(struct futex_q *q, int fd, struct file *filp)
432{
433 struct futex_hash_bucket *hb;
434
435 q->fd = fd;
436 q->filp = filp;
437
438 init_waitqueue_head(&q->waiters);
439
440 get_key_refs(&q->key);
441 hb = hash_futex(&q->key);
442 q->lock_ptr = &hb->lock;
443
444 spin_lock(&hb->lock);
445 return hb;
446}
447
448static inline void __queue_me(struct futex_q *q, struct futex_hash_bucket *hb)
449{
450 list_add_tail(&q->list, &hb->chain);
451 spin_unlock(&hb->lock);
452}
453
454static inline void
455queue_unlock(struct futex_q *q, struct futex_hash_bucket *hb)
456{
457 spin_unlock(&hb->lock);
458 drop_key_refs(&q->key);
459}
460
461
462
463
464
465
466
467static void queue_me(struct futex_q *q, int fd, struct file *filp)
468{
469 struct futex_hash_bucket *hb;
470
471 hb = queue_lock(q, fd, filp);
472 __queue_me(q, hb);
473}
474
475
476static int unqueue_me(struct futex_q *q)
477{
478 spinlock_t *lock_ptr;
479 int ret = 0;
480
481
482 retry:
483 lock_ptr = q->lock_ptr;
484 barrier();
485 if (lock_ptr != 0) {
486 spin_lock(lock_ptr);
487
488
489
490
491
492
493
494
495
496
497
498
499
500 if (unlikely(lock_ptr != q->lock_ptr)) {
501 spin_unlock(lock_ptr);
502 goto retry;
503 }
504 WARN_ON(list_empty(&q->list));
505 list_del(&q->list);
506 spin_unlock(lock_ptr);
507 ret = 1;
508 }
509
510 drop_key_refs(&q->key);
511 return ret;
512}
513
514static int futex_wait(unsigned long uaddr, int val, unsigned long time)
515{
516 struct task_struct *curr = current;
517 DECLARE_WAITQUEUE(wait, curr);
518 struct futex_hash_bucket *hb;
519 int ret, curval;
520 struct futex_q q;
521
522 retry:
523 down_read(&curr->mm->mmap_sem);
524
525 ret = get_futex_key(uaddr, &q.key);
526 if (unlikely(ret != 0))
527 goto out_release_sem;
528
529 hb = queue_lock(&q, -1, NULL);
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551 ret = get_futex_value_locked(&curval, (int __user *)uaddr);
552
553 if (unlikely(ret)) {
554 queue_unlock(&q, hb);
555
556
557
558
559
560 up_read(&curr->mm->mmap_sem);
561
562 ret = get_user(curval, (int __user *)uaddr);
563
564 if (!ret)
565 goto retry;
566 return ret;
567 }
568 if (curval != val) {
569 ret = -EWOULDBLOCK;
570 queue_unlock(&q, hb);
571 goto out_release_sem;
572 }
573
574
575 __queue_me(&q, hb);
576
577
578
579
580
581 up_read(&curr->mm->mmap_sem);
582
583
584
585
586
587
588
589
590
591
592
593 __set_current_state(TASK_INTERRUPTIBLE);
594 add_wait_queue(&q.waiters, &wait);
595
596
597
598
599 if (likely(!list_empty(&q.list)))
600 time = schedule_timeout(time);
601 __set_current_state(TASK_RUNNING);
602
603
604
605
606
607
608
609 if (!unqueue_me(&q))
610 return 0;
611 if (time == 0)
612 return -ETIMEDOUT;
613
614
615
616
617 return -EINTR;
618
619 out_release_sem:
620 up_read(&curr->mm->mmap_sem);
621 return ret;
622}
623
624static int futex_close(struct inode *inode, struct file *filp)
625{
626 struct futex_q *q = filp->private_data;
627
628 unqueue_me(q);
629 kfree(q);
630 return 0;
631}
632
633
634static unsigned int futex_poll(struct file *filp,
635 struct poll_table_struct *wait)
636{
637 struct futex_q *q = filp->private_data;
638 int ret = 0;
639
640 poll_wait(filp, &q->waiters, wait);
641
642
643
644
645
646 if (list_empty(&q->list))
647 ret = POLLIN | POLLRDNORM;
648
649 return ret;
650}
651
652static struct file_operations futex_fops = {
653 .release = futex_close,
654 .poll = futex_poll,
655};
656
657
658
659
660
661static int futex_fd(unsigned long uaddr, int signal)
662{
663 struct futex_q *q;
664 struct file *filp;
665 int ret, err;
666
667 ret = -EINVAL;
668 if (signal < 0 || signal > _NSIG)
669 goto out;
670
671 ret = get_unused_fd();
672 if (ret < 0)
673 goto out;
674 filp = get_empty_filp();
675 if (!filp) {
676 put_unused_fd(ret);
677 ret = -ENFILE;
678 goto out;
679 }
680 filp->f_op = &futex_fops;
681 filp->f_vfsmnt = mntget(futex_mnt);
682 filp->f_dentry = dget(futex_mnt->mnt_root);
683 filp->f_mapping = filp->f_dentry->d_inode->i_mapping;
684
685 if (signal) {
686 int err;
687 err = f_setown(filp, current->pid, 1);
688 if (err < 0) {
689 put_unused_fd(ret);
690 put_filp(filp);
691 ret = err;
692 goto out;
693 }
694 filp->f_owner.signum = signal;
695 }
696
697 q = kmalloc(sizeof(*q), GFP_KERNEL);
698 if (!q) {
699 put_unused_fd(ret);
700 put_filp(filp);
701 ret = -ENOMEM;
702 goto out;
703 }
704
705 down_read(¤t->mm->mmap_sem);
706 err = get_futex_key(uaddr, &q->key);
707
708 if (unlikely(err != 0)) {
709 up_read(¤t->mm->mmap_sem);
710 put_unused_fd(ret);
711 put_filp(filp);
712 kfree(q);
713 return err;
714 }
715
716
717
718
719
720 filp->private_data = q;
721
722 queue_me(q, ret, filp);
723 up_read(¤t->mm->mmap_sem);
724
725
726 fd_install(ret, filp);
727out:
728 return ret;
729}
730
731long do_futex(unsigned long uaddr, int op, int val, unsigned long timeout,
732 unsigned long uaddr2, int val2, int val3)
733{
734 int ret;
735
736 switch (op) {
737 case FUTEX_WAIT:
738 ret = futex_wait(uaddr, val, timeout);
739 break;
740 case FUTEX_WAKE:
741 ret = futex_wake(uaddr, val);
742 break;
743 case FUTEX_FD:
744
745 ret = futex_fd(uaddr, val);
746 break;
747 case FUTEX_REQUEUE:
748 ret = futex_requeue(uaddr, uaddr2, val, val2, NULL);
749 break;
750 case FUTEX_CMP_REQUEUE:
751 ret = futex_requeue(uaddr, uaddr2, val, val2, &val3);
752 break;
753 default:
754 ret = -ENOSYS;
755 }
756 return ret;
757}
758
759
760asmlinkage long sys_futex(u32 __user *uaddr, int op, int val,
761 struct timespec __user *utime, u32 __user *uaddr2,
762 int val3)
763{
764 struct timespec t;
765 unsigned long timeout = MAX_SCHEDULE_TIMEOUT;
766 int val2 = 0;
767
768 if (utime && (op == FUTEX_WAIT)) {
769 if (copy_from_user(&t, utime, sizeof(t)) != 0)
770 return -EFAULT;
771 if ((t.tv_sec < 0) || (((unsigned) t.tv_nsec) >= NSEC_PER_SEC))
772 return -EINVAL;
773 timeout = timespec_to_jiffies(&t) + 1;
774 }
775
776
777
778 if (op >= FUTEX_REQUEUE)
779 val2 = (int) (unsigned long) utime;
780
781 return do_futex((unsigned long)uaddr, op, val, timeout,
782 (unsigned long)uaddr2, val2, val3);
783}
784
785static struct super_block *
786futexfs_get_sb(struct file_system_type *fs_type,
787 int flags, const char *dev_name, void *data)
788{
789 return get_sb_pseudo(fs_type, "futex", NULL, 0xBAD1DEA);
790}
791
792static struct file_system_type futex_fs_type = {
793 .name = "futexfs",
794 .get_sb = futexfs_get_sb,
795 .kill_sb = kill_anon_super,
796};
797
798static int __init init(void)
799{
800 unsigned int i;
801
802 register_filesystem(&futex_fs_type);
803 futex_mnt = kern_mount(&futex_fs_type);
804
805 for (i = 0; i < ARRAY_SIZE(futex_queues); i++) {
806 INIT_LIST_HEAD(&futex_queues[i].chain);
807 futex_queues[i].lock = SPIN_LOCK_UNLOCKED;
808 }
809 return 0;
810}
811__initcall(init);
812