s3-rpcclient: Fix Bug #7277. rpcclient was sending invalid data, causing cupsaddsmb...
[Samba.git] / source3 / modules / vfs_aio_fork.c
blobc725fa6b9061ea74ec882e67b208a3e6d81df362
1 /*
2 * Simulate the Posix AIO using mmap/fork
4 * Copyright (C) Volker Lendecke 2008
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
21 #include "includes.h"
23 struct mmap_area {
24 size_t size;
25 volatile void *ptr;
28 static int mmap_area_destructor(struct mmap_area *area)
30 munmap((void *)area->ptr, area->size);
31 return 0;
34 static struct mmap_area *mmap_area_init(TALLOC_CTX *mem_ctx, size_t size)
36 struct mmap_area *result;
37 int fd;
39 result = talloc(mem_ctx, struct mmap_area);
40 if (result == NULL) {
41 DEBUG(0, ("talloc failed\n"));
42 goto fail;
45 fd = open("/dev/zero", O_RDWR);
46 if (fd == -1) {
47 DEBUG(3, ("open(\"/dev/zero\") failed: %s\n",
48 strerror(errno)));
49 goto fail;
52 result->ptr = mmap(NULL, size, PROT_READ|PROT_WRITE,
53 MAP_SHARED|MAP_FILE, fd, 0);
54 if (result->ptr == MAP_FAILED) {
55 DEBUG(1, ("mmap failed: %s\n", strerror(errno)));
56 goto fail;
59 close(fd);
61 result->size = size;
62 talloc_set_destructor(result, mmap_area_destructor);
64 return result;
66 fail:
67 TALLOC_FREE(result);
68 return NULL;
71 struct rw_cmd {
72 size_t n;
73 SMB_OFF_T offset;
74 bool read_cmd;
77 struct rw_ret {
78 ssize_t size;
79 int ret_errno;
82 struct aio_child_list;
84 struct aio_child {
85 struct aio_child *prev, *next;
86 struct aio_child_list *list;
87 SMB_STRUCT_AIOCB *aiocb;
88 pid_t pid;
89 int sockfd;
90 struct fd_event *sock_event;
91 struct rw_ret retval;
92 struct mmap_area *map; /* ==NULL means write request */
93 bool dont_delete; /* Marked as in use since last cleanup */
94 bool cancelled;
95 bool read_cmd;
98 struct aio_child_list {
99 struct aio_child *children;
100 struct timed_event *cleanup_event;
103 static void free_aio_children(void **p)
105 TALLOC_FREE(*p);
108 static ssize_t read_fd(int fd, void *ptr, size_t nbytes, int *recvfd)
110 struct msghdr msg;
111 struct iovec iov[1];
112 ssize_t n;
113 #ifndef HAVE_MSGHDR_MSG_CONTROL
114 int newfd;
115 #endif
117 #ifdef HAVE_MSGHDR_MSG_CONTROL
118 union {
119 struct cmsghdr cm;
120 char control[CMSG_SPACE(sizeof(int))];
121 } control_un;
122 struct cmsghdr *cmptr;
124 msg.msg_control = control_un.control;
125 msg.msg_controllen = sizeof(control_un.control);
126 #else
127 #if HAVE_MSGHDR_MSG_ACCTRIGHTS
128 msg.msg_accrights = (caddr_t) &newfd;
129 msg.msg_accrightslen = sizeof(int);
130 #else
131 #error Can not pass file descriptors
132 #endif
133 #endif
135 msg.msg_name = NULL;
136 msg.msg_namelen = 0;
138 iov[0].iov_base = (void *)ptr;
139 iov[0].iov_len = nbytes;
140 msg.msg_iov = iov;
141 msg.msg_iovlen = 1;
143 if ( (n = recvmsg(fd, &msg, 0)) <= 0) {
144 return(n);
147 #ifdef HAVE_MSGHDR_MSG_CONTROL
148 if ((cmptr = CMSG_FIRSTHDR(&msg)) != NULL
149 && cmptr->cmsg_len == CMSG_LEN(sizeof(int))) {
150 if (cmptr->cmsg_level != SOL_SOCKET) {
151 DEBUG(10, ("control level != SOL_SOCKET"));
152 errno = EINVAL;
153 return -1;
155 if (cmptr->cmsg_type != SCM_RIGHTS) {
156 DEBUG(10, ("control type != SCM_RIGHTS"));
157 errno = EINVAL;
158 return -1;
160 *recvfd = *((int *) CMSG_DATA(cmptr));
161 } else {
162 *recvfd = -1; /* descriptor was not passed */
164 #else
165 if (msg.msg_accrightslen == sizeof(int)) {
166 *recvfd = newfd;
168 else {
169 *recvfd = -1; /* descriptor was not passed */
171 #endif
173 return(n);
176 static ssize_t write_fd(int fd, void *ptr, size_t nbytes, int sendfd)
178 struct msghdr msg;
179 struct iovec iov[1];
181 #ifdef HAVE_MSGHDR_MSG_CONTROL
182 union {
183 struct cmsghdr cm;
184 char control[CMSG_SPACE(sizeof(int))];
185 } control_un;
186 struct cmsghdr *cmptr;
188 ZERO_STRUCT(msg);
189 ZERO_STRUCT(control_un);
191 msg.msg_control = control_un.control;
192 msg.msg_controllen = sizeof(control_un.control);
194 cmptr = CMSG_FIRSTHDR(&msg);
195 cmptr->cmsg_len = CMSG_LEN(sizeof(int));
196 cmptr->cmsg_level = SOL_SOCKET;
197 cmptr->cmsg_type = SCM_RIGHTS;
198 *((int *) CMSG_DATA(cmptr)) = sendfd;
199 #else
200 ZERO_STRUCT(msg);
201 msg.msg_accrights = (caddr_t) &sendfd;
202 msg.msg_accrightslen = sizeof(int);
203 #endif
205 msg.msg_name = NULL;
206 msg.msg_namelen = 0;
208 ZERO_STRUCT(iov);
209 iov[0].iov_base = (void *)ptr;
210 iov[0].iov_len = nbytes;
211 msg.msg_iov = iov;
212 msg.msg_iovlen = 1;
214 return (sendmsg(fd, &msg, 0));
217 static void aio_child_cleanup(struct event_context *event_ctx,
218 struct timed_event *te,
219 struct timeval now,
220 void *private_data)
222 struct aio_child_list *list = talloc_get_type_abort(
223 private_data, struct aio_child_list);
224 struct aio_child *child, *next;
226 TALLOC_FREE(list->cleanup_event);
228 for (child = list->children; child != NULL; child = next) {
229 next = child->next;
231 if (child->aiocb != NULL) {
232 DEBUG(10, ("child %d currently active\n",
233 (int)child->pid));
234 continue;
237 if (child->dont_delete) {
238 DEBUG(10, ("Child %d was active since last cleanup\n",
239 (int)child->pid));
240 child->dont_delete = false;
241 continue;
244 DEBUG(10, ("Child %d idle for more than 30 seconds, "
245 "deleting\n", (int)child->pid));
247 TALLOC_FREE(child);
250 if (list->children != NULL) {
252 * Re-schedule the next cleanup round
254 list->cleanup_event = event_add_timed(smbd_event_context(), list,
255 timeval_add(&now, 30, 0),
256 aio_child_cleanup, list);
261 static struct aio_child_list *init_aio_children(struct vfs_handle_struct *handle)
263 struct aio_child_list *data = NULL;
265 if (SMB_VFS_HANDLE_TEST_DATA(handle)) {
266 SMB_VFS_HANDLE_GET_DATA(handle, data, struct aio_child_list,
267 return NULL);
270 if (data == NULL) {
271 data = TALLOC_ZERO_P(NULL, struct aio_child_list);
272 if (data == NULL) {
273 return NULL;
278 * Regardless of whether the child_list had been around or not, make
279 * sure that we have a cleanup timed event. This timed event will
280 * delete itself when it finds that no children are around anymore.
283 if (data->cleanup_event == NULL) {
284 data->cleanup_event = event_add_timed(smbd_event_context(), data,
285 timeval_current_ofs(30, 0),
286 aio_child_cleanup, data);
287 if (data->cleanup_event == NULL) {
288 TALLOC_FREE(data);
289 return NULL;
293 if (!SMB_VFS_HANDLE_TEST_DATA(handle)) {
294 SMB_VFS_HANDLE_SET_DATA(handle, data, free_aio_children,
295 struct aio_child_list, return False);
298 return data;
301 static void aio_child_loop(int sockfd, struct mmap_area *map)
303 while (true) {
304 int fd = -1;
305 ssize_t ret;
306 struct rw_cmd cmd_struct;
307 struct rw_ret ret_struct;
309 ret = read_fd(sockfd, &cmd_struct, sizeof(cmd_struct), &fd);
310 if (ret != sizeof(cmd_struct)) {
311 DEBUG(10, ("read_fd returned %d: %s\n", (int)ret,
312 strerror(errno)));
313 exit(1);
316 DEBUG(10, ("aio_child_loop: %s %d bytes at %d from fd %d\n",
317 cmd_struct.read_cmd ? "read" : "write",
318 (int)cmd_struct.n, (int)cmd_struct.offset, fd));
320 #ifdef ENABLE_BUILD_FARM_HACKS
323 * In the build farm, we want erratic behaviour for
324 * async I/O times
326 uint8_t randval;
327 unsigned msecs;
329 * use generate_random_buffer, we just forked from a
330 * common parent state
332 generate_random_buffer(&randval, sizeof(randval));
333 msecs = randval + 20;
334 DEBUG(10, ("delaying for %u msecs\n", msecs));
335 smb_msleep(msecs);
337 #endif
340 ZERO_STRUCT(ret_struct);
342 if (cmd_struct.read_cmd) {
343 ret_struct.size = sys_pread(
344 fd, (void *)map->ptr, cmd_struct.n,
345 cmd_struct.offset);
346 #ifdef ENABLE_BUILD_FARM_HACKS
347 ret_struct.size = MAX(1, ret_struct.size * 0.9);
348 #endif
350 else {
351 ret_struct.size = sys_pwrite(
352 fd, (void *)map->ptr, cmd_struct.n,
353 cmd_struct.offset);
356 DEBUG(10, ("aio_child_loop: syscall returned %d\n",
357 (int)ret_struct.size));
359 if (ret_struct.size == -1) {
360 ret_struct.ret_errno = errno;
364 * Close the fd before telling our parent we're done. The
365 * parent might close and re-open the file very quickly, and
366 * with system-level share modes (GPFS) we would get an
367 * unjustified SHARING_VIOLATION.
369 close(fd);
371 ret = write_data(sockfd, (char *)&ret_struct,
372 sizeof(ret_struct));
373 if (ret != sizeof(ret_struct)) {
374 DEBUG(10, ("could not write ret_struct: %s\n",
375 strerror(errno)));
376 exit(2);
381 static void handle_aio_completion(struct event_context *event_ctx,
382 struct fd_event *event, uint16 flags,
383 void *p)
385 struct aio_child *child = (struct aio_child *)p;
386 uint16 mid;
388 DEBUG(10, ("handle_aio_completion called with flags=%d\n", flags));
390 if ((flags & EVENT_FD_READ) == 0) {
391 return;
394 if (!NT_STATUS_IS_OK(read_data(child->sockfd,
395 (char *)&child->retval,
396 sizeof(child->retval)))) {
397 DEBUG(0, ("aio child %d died\n", (int)child->pid));
398 child->retval.size = -1;
399 child->retval.ret_errno = EIO;
402 if (child->cancelled) {
403 child->aiocb = NULL;
404 child->cancelled = false;
405 return;
408 if (child->read_cmd && (child->retval.size > 0)) {
409 SMB_ASSERT(child->retval.size <= child->aiocb->aio_nbytes);
410 memcpy((void *)child->aiocb->aio_buf, (void *)child->map->ptr,
411 child->retval.size);
414 mid = child->aiocb->aio_sigevent.sigev_value.sival_int;
416 DEBUG(10, ("mid %d finished\n", (int)mid));
418 smbd_aio_complete_mid(mid);
421 static int aio_child_destructor(struct aio_child *child)
423 SMB_ASSERT((child->aiocb == NULL) || child->cancelled);
424 close(child->sockfd);
425 DLIST_REMOVE(child->list->children, child);
426 return 0;
430 * We have to close all fd's in open files, we might incorrectly hold a system
431 * level share mode on a file.
434 static struct files_struct *close_fsp_fd(struct files_struct *fsp,
435 void *private_data)
437 if ((fsp->fh != NULL) && (fsp->fh->fd != -1)) {
438 close(fsp->fh->fd);
439 fsp->fh->fd = -1;
441 return NULL;
444 static NTSTATUS create_aio_child(struct aio_child_list *children,
445 size_t map_size,
446 struct aio_child **presult)
448 struct aio_child *result;
449 int fdpair[2];
450 NTSTATUS status;
452 fdpair[0] = fdpair[1] = -1;
454 result = TALLOC_ZERO_P(children, struct aio_child);
455 NT_STATUS_HAVE_NO_MEMORY(result);
457 if (socketpair(AF_UNIX, SOCK_STREAM, 0, fdpair) == -1) {
458 status = map_nt_error_from_unix(errno);
459 DEBUG(10, ("socketpair() failed: %s\n", strerror(errno)));
460 goto fail;
463 DEBUG(10, ("fdpair = %d/%d\n", fdpair[0], fdpair[1]));
465 result->map = mmap_area_init(result, map_size);
466 if (result->map == NULL) {
467 status = map_nt_error_from_unix(errno);
468 DEBUG(0, ("Could not create mmap area\n"));
469 goto fail;
472 result->pid = sys_fork();
473 if (result->pid == -1) {
474 status = map_nt_error_from_unix(errno);
475 DEBUG(0, ("fork failed: %s\n", strerror(errno)));
476 goto fail;
479 if (result->pid == 0) {
480 close(fdpair[0]);
481 result->sockfd = fdpair[1];
482 file_walk_table(close_fsp_fd, NULL);
483 aio_child_loop(result->sockfd, result->map);
486 DEBUG(10, ("Child %d created\n", result->pid));
488 result->sockfd = fdpair[0];
489 close(fdpair[1]);
491 result->sock_event = event_add_fd(smbd_event_context(), result,
492 result->sockfd, EVENT_FD_READ,
493 handle_aio_completion,
494 result);
495 if (result->sock_event == NULL) {
496 status = NT_STATUS_NO_MEMORY;
497 DEBUG(0, ("event_add_fd failed\n"));
498 goto fail;
501 result->list = children;
502 DLIST_ADD(children->children, result);
504 talloc_set_destructor(result, aio_child_destructor);
506 *presult = result;
508 return NT_STATUS_OK;
510 fail:
511 if (fdpair[0] != -1) close(fdpair[0]);
512 if (fdpair[1] != -1) close(fdpair[1]);
513 TALLOC_FREE(result);
515 return status;
518 static NTSTATUS get_idle_child(struct vfs_handle_struct *handle,
519 struct aio_child **pchild)
521 struct aio_child_list *children;
522 struct aio_child *child;
523 NTSTATUS status;
525 children = init_aio_children(handle);
526 if (children == NULL) {
527 return NT_STATUS_NO_MEMORY;
530 for (child = children->children; child != NULL; child = child->next) {
531 if (child->aiocb == NULL) {
532 /* idle */
533 break;
537 if (child == NULL) {
538 DEBUG(10, ("no idle child found, creating new one\n"));
540 status = create_aio_child(children, 128*1024, &child);
541 if (!NT_STATUS_IS_OK(status)) {
542 DEBUG(10, ("create_aio_child failed: %s\n",
543 nt_errstr(status)));
544 return status;
548 child->dont_delete = true;
550 *pchild = child;
551 return NT_STATUS_OK;
554 static int aio_fork_read(struct vfs_handle_struct *handle,
555 struct files_struct *fsp, SMB_STRUCT_AIOCB *aiocb)
557 struct aio_child *child;
558 struct rw_cmd cmd;
559 ssize_t ret;
560 NTSTATUS status;
562 if (aiocb->aio_nbytes > 128*1024) {
563 /* TODO: support variable buffers */
564 errno = EINVAL;
565 return -1;
568 status = get_idle_child(handle, &child);
569 if (!NT_STATUS_IS_OK(status)) {
570 DEBUG(10, ("Could not get an idle child\n"));
571 return -1;
574 child->read_cmd = true;
575 child->aiocb = aiocb;
576 child->retval.ret_errno = EINPROGRESS;
578 ZERO_STRUCT(cmd);
579 cmd.n = aiocb->aio_nbytes;
580 cmd.offset = aiocb->aio_offset;
581 cmd.read_cmd = child->read_cmd;
583 DEBUG(10, ("sending fd %d to child %d\n", fsp->fh->fd,
584 (int)child->pid));
586 ret = write_fd(child->sockfd, &cmd, sizeof(cmd), fsp->fh->fd);
587 if (ret == -1) {
588 DEBUG(10, ("write_fd failed: %s\n", strerror(errno)));
589 return -1;
592 return 0;
595 static int aio_fork_write(struct vfs_handle_struct *handle,
596 struct files_struct *fsp, SMB_STRUCT_AIOCB *aiocb)
598 struct aio_child *child;
599 struct rw_cmd cmd;
600 ssize_t ret;
601 NTSTATUS status;
603 if (aiocb->aio_nbytes > 128*1024) {
604 /* TODO: support variable buffers */
605 errno = EINVAL;
606 return -1;
609 status = get_idle_child(handle, &child);
610 if (!NT_STATUS_IS_OK(status)) {
611 DEBUG(10, ("Could not get an idle child\n"));
612 return -1;
615 child->read_cmd = false;
616 child->aiocb = aiocb;
617 child->retval.ret_errno = EINPROGRESS;
619 memcpy((void *)child->map->ptr, (void *)aiocb->aio_buf,
620 aiocb->aio_nbytes);
622 ZERO_STRUCT(cmd);
623 cmd.n = aiocb->aio_nbytes;
624 cmd.offset = aiocb->aio_offset;
625 cmd.read_cmd = child->read_cmd;
627 DEBUG(10, ("sending fd %d to child %d\n", fsp->fh->fd,
628 (int)child->pid));
630 ret = write_fd(child->sockfd, &cmd, sizeof(cmd), fsp->fh->fd);
631 if (ret == -1) {
632 DEBUG(10, ("write_fd failed: %s\n", strerror(errno)));
633 return -1;
636 return 0;
639 static struct aio_child *aio_fork_find_child(struct vfs_handle_struct *handle,
640 SMB_STRUCT_AIOCB *aiocb)
642 struct aio_child_list *children;
643 struct aio_child *child;
645 children = init_aio_children(handle);
646 if (children == NULL) {
647 return NULL;
650 for (child = children->children; child != NULL; child = child->next) {
651 if (child->aiocb == aiocb) {
652 return child;
656 return NULL;
659 static ssize_t aio_fork_return_fn(struct vfs_handle_struct *handle,
660 struct files_struct *fsp,
661 SMB_STRUCT_AIOCB *aiocb)
663 struct aio_child *child = aio_fork_find_child(handle, aiocb);
665 if (child == NULL) {
666 errno = EINVAL;
667 DEBUG(0, ("returning EINVAL\n"));
668 return -1;
671 child->aiocb = NULL;
673 if (child->retval.size == -1) {
674 errno = child->retval.ret_errno;
677 return child->retval.size;
680 static int aio_fork_cancel(struct vfs_handle_struct *handle,
681 struct files_struct *fsp,
682 SMB_STRUCT_AIOCB *aiocb)
684 struct aio_child_list *children;
685 struct aio_child *child;
687 children = init_aio_children(handle);
688 if (children == NULL) {
689 errno = EINVAL;
690 return -1;
693 for (child = children->children; child != NULL; child = child->next) {
694 if (child->aiocb == NULL) {
695 continue;
697 if (child->aiocb->aio_fildes != fsp->fh->fd) {
698 continue;
700 if ((aiocb != NULL) && (child->aiocb != aiocb)) {
701 continue;
705 * We let the child do its job, but we discard the result when
706 * it's finished.
709 child->cancelled = true;
712 return AIO_CANCELED;
715 static int aio_fork_error_fn(struct vfs_handle_struct *handle,
716 struct files_struct *fsp,
717 SMB_STRUCT_AIOCB *aiocb)
719 struct aio_child *child = aio_fork_find_child(handle, aiocb);
721 if (child == NULL) {
722 errno = EINVAL;
723 return -1;
726 return child->retval.ret_errno;
729 static struct vfs_fn_pointers vfs_aio_fork_fns = {
730 .aio_read = aio_fork_read,
731 .aio_write = aio_fork_write,
732 .aio_return_fn = aio_fork_return_fn,
733 .aio_cancel = aio_fork_cancel,
734 .aio_error_fn = aio_fork_error_fn,
737 NTSTATUS vfs_aio_fork_init(void);
738 NTSTATUS vfs_aio_fork_init(void)
740 return smb_register_vfs(SMB_VFS_INTERFACE_VERSION,
741 "aio_fork", &vfs_aio_fork_fns);