OSDN Git Service

mtd: fix: avoid race condition when accessing mtd->usecount
[android-x86/kernel.git] / drivers / mtd / mtd_blkdevs.c
1 /*
2  * Interface to Linux block layer for MTD 'translation layers'.
3  *
4  * Copyright © 2003-2010 David Woodhouse <dwmw2@infradead.org>
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License as published by
8  * the Free Software Foundation; either version 2 of the License, or
9  * (at your option) any later version.
10  *
11  * This program is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  * GNU General Public License for more details.
15  *
16  * You should have received a copy of the GNU General Public License
17  * along with this program; if not, write to the Free Software
18  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19  *
20  */
21
22 #include <linux/kernel.h>
23 #include <linux/slab.h>
24 #include <linux/module.h>
25 #include <linux/list.h>
26 #include <linux/fs.h>
27 #include <linux/mtd/blktrans.h>
28 #include <linux/mtd/mtd.h>
29 #include <linux/blkdev.h>
30 #include <linux/blkpg.h>
31 #include <linux/spinlock.h>
32 #include <linux/hdreg.h>
33 #include <linux/mutex.h>
34 #include <asm/uaccess.h>
35
36 #include "mtdcore.h"
37
38 static LIST_HEAD(blktrans_majors);
39 static DEFINE_MUTEX(blktrans_ref_mutex);
40
41 static void blktrans_dev_release(struct kref *kref)
42 {
43         struct mtd_blktrans_dev *dev =
44                 container_of(kref, struct mtd_blktrans_dev, ref);
45
46         dev->disk->private_data = NULL;
47         blk_cleanup_queue(dev->rq);
48         put_disk(dev->disk);
49         list_del(&dev->list);
50         kfree(dev);
51 }
52
53 static struct mtd_blktrans_dev *blktrans_dev_get(struct gendisk *disk)
54 {
55         struct mtd_blktrans_dev *dev;
56
57         mutex_lock(&blktrans_ref_mutex);
58         dev = disk->private_data;
59
60         if (!dev)
61                 goto unlock;
62         kref_get(&dev->ref);
63 unlock:
64         mutex_unlock(&blktrans_ref_mutex);
65         return dev;
66 }
67
68 static void blktrans_dev_put(struct mtd_blktrans_dev *dev)
69 {
70         mutex_lock(&blktrans_ref_mutex);
71         kref_put(&dev->ref, blktrans_dev_release);
72         mutex_unlock(&blktrans_ref_mutex);
73 }
74
75
76 static int do_blktrans_request(struct mtd_blktrans_ops *tr,
77                                struct mtd_blktrans_dev *dev,
78                                struct request *req)
79 {
80         unsigned long block, nsect;
81         char *buf;
82
83         block = blk_rq_pos(req) << 9 >> tr->blkshift;
84         nsect = blk_rq_cur_bytes(req) >> tr->blkshift;
85         buf = bio_data(req->bio);
86
87         if (req->cmd_type != REQ_TYPE_FS)
88                 return -EIO;
89
90         if (req->cmd_flags & REQ_FLUSH)
91                 return tr->flush(dev);
92
93         if (blk_rq_pos(req) + blk_rq_cur_sectors(req) >
94             get_capacity(req->rq_disk))
95                 return -EIO;
96
97         if (req->cmd_flags & REQ_DISCARD)
98                 return tr->discard(dev, block, nsect);
99
100         switch(rq_data_dir(req)) {
101         case READ:
102                 for (; nsect > 0; nsect--, block++, buf += tr->blksize)
103                         if (tr->readsect(dev, block, buf))
104                                 return -EIO;
105                 rq_flush_dcache_pages(req);
106                 return 0;
107         case WRITE:
108                 if (!tr->writesect)
109                         return -EIO;
110
111                 rq_flush_dcache_pages(req);
112                 for (; nsect > 0; nsect--, block++, buf += tr->blksize)
113                         if (tr->writesect(dev, block, buf))
114                                 return -EIO;
115                 return 0;
116         default:
117                 printk(KERN_NOTICE "Unknown request %u\n", rq_data_dir(req));
118                 return -EIO;
119         }
120 }
121
122 int mtd_blktrans_cease_background(struct mtd_blktrans_dev *dev)
123 {
124         return dev->bg_stop;
125 }
126 EXPORT_SYMBOL_GPL(mtd_blktrans_cease_background);
127
128 static void mtd_blktrans_work(struct work_struct *work)
129 {
130         struct mtd_blktrans_dev *dev =
131                 container_of(work, struct mtd_blktrans_dev, work);
132         struct mtd_blktrans_ops *tr = dev->tr;
133         struct request_queue *rq = dev->rq;
134         struct request *req = NULL;
135         int background_done = 0;
136
137         spin_lock_irq(rq->queue_lock);
138
139         while (1) {
140                 int res;
141
142                 dev->bg_stop = false;
143                 if (!req && !(req = blk_fetch_request(rq))) {
144                         if (tr->background && !background_done) {
145                                 spin_unlock_irq(rq->queue_lock);
146                                 mutex_lock(&dev->lock);
147                                 tr->background(dev);
148                                 mutex_unlock(&dev->lock);
149                                 spin_lock_irq(rq->queue_lock);
150                                 /*
151                                  * Do background processing just once per idle
152                                  * period.
153                                  */
154                                 background_done = !dev->bg_stop;
155                                 continue;
156                         }
157                         break;
158                 }
159
160                 spin_unlock_irq(rq->queue_lock);
161
162                 mutex_lock(&dev->lock);
163                 res = do_blktrans_request(dev->tr, dev, req);
164                 mutex_unlock(&dev->lock);
165
166                 spin_lock_irq(rq->queue_lock);
167
168                 if (!__blk_end_request_cur(req, res))
169                         req = NULL;
170
171                 background_done = 0;
172         }
173
174         if (req)
175                 __blk_end_request_all(req, -EIO);
176
177         spin_unlock_irq(rq->queue_lock);
178 }
179
180 static void mtd_blktrans_request(struct request_queue *rq)
181 {
182         struct mtd_blktrans_dev *dev;
183         struct request *req = NULL;
184
185         dev = rq->queuedata;
186
187         if (!dev)
188                 while ((req = blk_fetch_request(rq)) != NULL)
189                         __blk_end_request_all(req, -ENODEV);
190         else
191                 queue_work(dev->wq, &dev->work);
192 }
193
194 static int blktrans_open(struct block_device *bdev, fmode_t mode)
195 {
196         struct mtd_blktrans_dev *dev = blktrans_dev_get(bdev->bd_disk);
197         int ret = 0;
198
199         if (!dev)
200                 return -ERESTARTSYS; /* FIXME: busy loop! -arnd*/
201
202         mutex_lock(&dev->lock);
203         mutex_lock(&mtd_table_mutex);
204
205         if (dev->open)
206                 goto unlock;
207
208         kref_get(&dev->ref);
209         __module_get(dev->tr->owner);
210
211         if (!dev->mtd)
212                 goto unlock;
213
214         if (dev->tr->open) {
215                 ret = dev->tr->open(dev);
216                 if (ret)
217                         goto error_put;
218         }
219
220         ret = __get_mtd_device(dev->mtd);
221         if (ret)
222                 goto error_release;
223         dev->file_mode = mode;
224
225 unlock:
226         dev->open++;
227         mutex_unlock(&mtd_table_mutex);
228         mutex_unlock(&dev->lock);
229         blktrans_dev_put(dev);
230         return ret;
231
232 error_release:
233         if (dev->tr->release)
234                 dev->tr->release(dev);
235 error_put:
236         module_put(dev->tr->owner);
237         kref_put(&dev->ref, blktrans_dev_release);
238         mutex_unlock(&mtd_table_mutex);
239         mutex_unlock(&dev->lock);
240         blktrans_dev_put(dev);
241         return ret;
242 }
243
244 static void blktrans_release(struct gendisk *disk, fmode_t mode)
245 {
246         struct mtd_blktrans_dev *dev = blktrans_dev_get(disk);
247
248         if (!dev)
249                 return;
250
251         mutex_lock(&dev->lock);
252         mutex_lock(&mtd_table_mutex);
253
254         if (--dev->open)
255                 goto unlock;
256
257         kref_put(&dev->ref, blktrans_dev_release);
258         module_put(dev->tr->owner);
259
260         if (dev->mtd) {
261                 if (dev->tr->release)
262                         dev->tr->release(dev);
263                 __put_mtd_device(dev->mtd);
264         }
265 unlock:
266         mutex_unlock(&mtd_table_mutex);
267         mutex_unlock(&dev->lock);
268         blktrans_dev_put(dev);
269 }
270
271 static int blktrans_getgeo(struct block_device *bdev, struct hd_geometry *geo)
272 {
273         struct mtd_blktrans_dev *dev = blktrans_dev_get(bdev->bd_disk);
274         int ret = -ENXIO;
275
276         if (!dev)
277                 return ret;
278
279         mutex_lock(&dev->lock);
280
281         if (!dev->mtd)
282                 goto unlock;
283
284         ret = dev->tr->getgeo ? dev->tr->getgeo(dev, geo) : 0;
285 unlock:
286         mutex_unlock(&dev->lock);
287         blktrans_dev_put(dev);
288         return ret;
289 }
290
291 static int blktrans_ioctl(struct block_device *bdev, fmode_t mode,
292                               unsigned int cmd, unsigned long arg)
293 {
294         struct mtd_blktrans_dev *dev = blktrans_dev_get(bdev->bd_disk);
295         int ret = -ENXIO;
296
297         if (!dev)
298                 return ret;
299
300         mutex_lock(&dev->lock);
301
302         if (!dev->mtd)
303                 goto unlock;
304
305         switch (cmd) {
306         case BLKFLSBUF:
307                 ret = dev->tr->flush ? dev->tr->flush(dev) : 0;
308                 break;
309         default:
310                 ret = -ENOTTY;
311         }
312 unlock:
313         mutex_unlock(&dev->lock);
314         blktrans_dev_put(dev);
315         return ret;
316 }
317
318 static const struct block_device_operations mtd_block_ops = {
319         .owner          = THIS_MODULE,
320         .open           = blktrans_open,
321         .release        = blktrans_release,
322         .ioctl          = blktrans_ioctl,
323         .getgeo         = blktrans_getgeo,
324 };
325
326 int add_mtd_blktrans_dev(struct mtd_blktrans_dev *new)
327 {
328         struct mtd_blktrans_ops *tr = new->tr;
329         struct mtd_blktrans_dev *d;
330         int last_devnum = -1;
331         struct gendisk *gd;
332         int ret;
333
334         if (mutex_trylock(&mtd_table_mutex)) {
335                 mutex_unlock(&mtd_table_mutex);
336                 BUG();
337         }
338
339         mutex_lock(&blktrans_ref_mutex);
340         list_for_each_entry(d, &tr->devs, list) {
341                 if (new->devnum == -1) {
342                         /* Use first free number */
343                         if (d->devnum != last_devnum+1) {
344                                 /* Found a free devnum. Plug it in here */
345                                 new->devnum = last_devnum+1;
346                                 list_add_tail(&new->list, &d->list);
347                                 goto added;
348                         }
349                 } else if (d->devnum == new->devnum) {
350                         /* Required number taken */
351                         mutex_unlock(&blktrans_ref_mutex);
352                         return -EBUSY;
353                 } else if (d->devnum > new->devnum) {
354                         /* Required number was free */
355                         list_add_tail(&new->list, &d->list);
356                         goto added;
357                 }
358                 last_devnum = d->devnum;
359         }
360
361         ret = -EBUSY;
362         if (new->devnum == -1)
363                 new->devnum = last_devnum+1;
364
365         /* Check that the device and any partitions will get valid
366          * minor numbers and that the disk naming code below can cope
367          * with this number. */
368         if (new->devnum > (MINORMASK >> tr->part_bits) ||
369             (tr->part_bits && new->devnum >= 27 * 26)) {
370                 mutex_unlock(&blktrans_ref_mutex);
371                 goto error1;
372         }
373
374         list_add_tail(&new->list, &tr->devs);
375  added:
376         mutex_unlock(&blktrans_ref_mutex);
377
378         mutex_init(&new->lock);
379         kref_init(&new->ref);
380         if (!tr->writesect)
381                 new->readonly = 1;
382
383         /* Create gendisk */
384         ret = -ENOMEM;
385         gd = alloc_disk(1 << tr->part_bits);
386
387         if (!gd)
388                 goto error2;
389
390         new->disk = gd;
391         gd->private_data = new;
392         gd->major = tr->major;
393         gd->first_minor = (new->devnum) << tr->part_bits;
394         gd->fops = &mtd_block_ops;
395
396         if (tr->part_bits)
397                 if (new->devnum < 26)
398                         snprintf(gd->disk_name, sizeof(gd->disk_name),
399                                  "%s%c", tr->name, 'a' + new->devnum);
400                 else
401                         snprintf(gd->disk_name, sizeof(gd->disk_name),
402                                  "%s%c%c", tr->name,
403                                  'a' - 1 + new->devnum / 26,
404                                  'a' + new->devnum % 26);
405         else
406                 snprintf(gd->disk_name, sizeof(gd->disk_name),
407                          "%s%d", tr->name, new->devnum);
408
409         set_capacity(gd, (new->size * tr->blksize) >> 9);
410
411         /* Create the request queue */
412         spin_lock_init(&new->queue_lock);
413         new->rq = blk_init_queue(mtd_blktrans_request, &new->queue_lock);
414
415         if (!new->rq)
416                 goto error3;
417
418         if (tr->flush)
419                 blk_queue_flush(new->rq, REQ_FLUSH);
420
421         new->rq->queuedata = new;
422         blk_queue_logical_block_size(new->rq, tr->blksize);
423
424         queue_flag_set_unlocked(QUEUE_FLAG_NONROT, new->rq);
425         queue_flag_clear_unlocked(QUEUE_FLAG_ADD_RANDOM, new->rq);
426
427         if (tr->discard) {
428                 queue_flag_set_unlocked(QUEUE_FLAG_DISCARD, new->rq);
429                 new->rq->limits.max_discard_sectors = UINT_MAX;
430         }
431
432         gd->queue = new->rq;
433
434         /* Create processing workqueue */
435         new->wq = alloc_workqueue("%s%d", 0, 0,
436                                   tr->name, new->mtd->index);
437         if (!new->wq)
438                 goto error4;
439         INIT_WORK(&new->work, mtd_blktrans_work);
440
441         gd->driverfs_dev = &new->mtd->dev;
442
443         if (new->readonly)
444                 set_disk_ro(gd, 1);
445
446         add_disk(gd);
447
448         if (new->disk_attributes) {
449                 ret = sysfs_create_group(&disk_to_dev(gd)->kobj,
450                                         new->disk_attributes);
451                 WARN_ON(ret);
452         }
453         return 0;
454 error4:
455         blk_cleanup_queue(new->rq);
456 error3:
457         put_disk(new->disk);
458 error2:
459         list_del(&new->list);
460 error1:
461         return ret;
462 }
463
464 int del_mtd_blktrans_dev(struct mtd_blktrans_dev *old)
465 {
466         unsigned long flags;
467
468         if (mutex_trylock(&mtd_table_mutex)) {
469                 mutex_unlock(&mtd_table_mutex);
470                 BUG();
471         }
472
473         if (old->disk_attributes)
474                 sysfs_remove_group(&disk_to_dev(old->disk)->kobj,
475                                                 old->disk_attributes);
476
477         /* Stop new requests to arrive */
478         del_gendisk(old->disk);
479
480         /* Stop workqueue. This will perform any pending request. */
481         destroy_workqueue(old->wq);
482
483         /* Kill current requests */
484         spin_lock_irqsave(&old->queue_lock, flags);
485         old->rq->queuedata = NULL;
486         blk_start_queue(old->rq);
487         spin_unlock_irqrestore(&old->queue_lock, flags);
488
489         /* If the device is currently open, tell trans driver to close it,
490                 then put mtd device, and don't touch it again */
491         mutex_lock(&old->lock);
492         if (old->open) {
493                 if (old->tr->release)
494                         old->tr->release(old);
495                 __put_mtd_device(old->mtd);
496         }
497
498         old->mtd = NULL;
499
500         mutex_unlock(&old->lock);
501         blktrans_dev_put(old);
502         return 0;
503 }
504
505 static void blktrans_notify_remove(struct mtd_info *mtd)
506 {
507         struct mtd_blktrans_ops *tr;
508         struct mtd_blktrans_dev *dev, *next;
509
510         list_for_each_entry(tr, &blktrans_majors, list)
511                 list_for_each_entry_safe(dev, next, &tr->devs, list)
512                         if (dev->mtd == mtd)
513                                 tr->remove_dev(dev);
514 }
515
516 static void blktrans_notify_add(struct mtd_info *mtd)
517 {
518         struct mtd_blktrans_ops *tr;
519
520         if (mtd->type == MTD_ABSENT)
521                 return;
522
523         list_for_each_entry(tr, &blktrans_majors, list)
524                 tr->add_mtd(tr, mtd);
525 }
526
527 static struct mtd_notifier blktrans_notifier = {
528         .add = blktrans_notify_add,
529         .remove = blktrans_notify_remove,
530 };
531
532 int register_mtd_blktrans(struct mtd_blktrans_ops *tr)
533 {
534         struct mtd_info *mtd;
535         int ret;
536
537         /* Register the notifier if/when the first device type is
538            registered, to prevent the link/init ordering from fucking
539            us over. */
540         if (!blktrans_notifier.list.next)
541                 register_mtd_user(&blktrans_notifier);
542
543
544         mutex_lock(&mtd_table_mutex);
545
546         ret = register_blkdev(tr->major, tr->name);
547         if (ret < 0) {
548                 printk(KERN_WARNING "Unable to register %s block device on major %d: %d\n",
549                        tr->name, tr->major, ret);
550                 mutex_unlock(&mtd_table_mutex);
551                 return ret;
552         }
553
554         if (ret)
555                 tr->major = ret;
556
557         tr->blkshift = ffs(tr->blksize) - 1;
558
559         INIT_LIST_HEAD(&tr->devs);
560         list_add(&tr->list, &blktrans_majors);
561
562         mtd_for_each_device(mtd)
563                 if (mtd->type != MTD_ABSENT)
564                         tr->add_mtd(tr, mtd);
565
566         mutex_unlock(&mtd_table_mutex);
567         return 0;
568 }
569
570 int deregister_mtd_blktrans(struct mtd_blktrans_ops *tr)
571 {
572         struct mtd_blktrans_dev *dev, *next;
573
574         mutex_lock(&mtd_table_mutex);
575
576         /* Remove it from the list of active majors */
577         list_del(&tr->list);
578
579         list_for_each_entry_safe(dev, next, &tr->devs, list)
580                 tr->remove_dev(dev);
581
582         unregister_blkdev(tr->major, tr->name);
583         mutex_unlock(&mtd_table_mutex);
584
585         BUG_ON(!list_empty(&tr->devs));
586         return 0;
587 }
588
589 static void __exit mtd_blktrans_exit(void)
590 {
591         /* No race here -- if someone's currently in register_mtd_blktrans
592            we're screwed anyway. */
593         if (blktrans_notifier.list.next)
594                 unregister_mtd_user(&blktrans_notifier);
595 }
596
597 module_exit(mtd_blktrans_exit);
598
599 EXPORT_SYMBOL_GPL(register_mtd_blktrans);
600 EXPORT_SYMBOL_GPL(deregister_mtd_blktrans);
601 EXPORT_SYMBOL_GPL(add_mtd_blktrans_dev);
602 EXPORT_SYMBOL_GPL(del_mtd_blktrans_dev);
603
604 MODULE_AUTHOR("David Woodhouse <dwmw2@infradead.org>");
605 MODULE_LICENSE("GPL");
606 MODULE_DESCRIPTION("Common interface to block layer for MTD 'translation layers'");