From nobody Fri Sep 25 18:50:24 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hs0Bm66Prz6tmm3 for ; Fri, 25 Sep 2026 18:50:24 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hs0Bm5mdhz4mLV for ; Fri, 25 Sep 2026 18:50:24 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790362224; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=BDDdDvrFH3VmAgUk2g++1TRIkGJ7Urw4VK8IgZi4YWA=; b=EvTYaO9S09iE05RVG+X3du0vsUy+MOrpDIiTUWKkQYELq3yY0q9/FhRVfq6KnWUC8AyU3d kdcgeDywXQjwL4Kj9m24SuFu0FgEYD0OoaaChcO/ArgayWi61kQeICe0nBeYG5+/BVdRzj fB6Ine83pXEtvRzS9jKeGEbtXBBzmEw3YG/y59976SE8lxUfzQrWBsQzcUKvqprbjgCUfF 35JC2/hJvFWqDYdvdmIDqX0tJaPL4iIF7AS7gC7zbK6qz85GCirjW1fWpRDEQwupac2xOG ElBbYiwP4D7Y9WrLxY/l5IF4QFqLNosTfyPH1VfHerPYygQ8CKyy1BudK6bFLQ== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790362224; b=PxXaIoMih8xjfd2ILz6ch3UaeDZfhTUA9PvtxI6DmKj0CZ6EcGs32A0DEkAGcIf+RHq15I khhC0Z02atWYtllUsBeXce41XeK67aMMDQn7NLlIpL7Ttdpl4B48CiPMbFFvlIOOydFBuT idM/YCQe05hzVe7mmGD7vu9eJap6O2XTe1nmkoBrjECnopPXP47pDKkwFVOgxzHqFoZqOf dRbRrNs2sVsq8VNuIYft9R3Xa3yhiQzixCM+BO6jNKUgToS4myPNTQzJCGCNle0PTSWCYm 7HcfzOtp5fc8VZCcgMGpJ3XGha7LLYoerIhyDHN3fDeRQZY5/zTCtJHdkJ2I1g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790362224; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=BDDdDvrFH3VmAgUk2g++1TRIkGJ7Urw4VK8IgZi4YWA=; b=ItHVZTP4XP0rBDNX51ojDgHJzhifApVQDHXQXfcrlyDqKkEnnOhRCqcQRFv7/Fjq7c2kNH Ikr+ZZ8B+bwruV25baBe/tTsEmNQiiimI4Igw/s2yBxVN6RG4660G40vfF736EXt9zL7SJ NiK/Hia6pVOpdKlHK1EkI8eqNYWg0T/9Yb6Ew9V3TzT5A+TZAuBh3UFXQBozEFqrqG374K qj5vCIuJQ30AqzlkE6eP6NYb18EB4GGjzbdIopYE5LQTZ1oA3Q++J2Wti+SVcPOIyQu+So rpy7t2LRnMp3ASlaDQAALfDdxaM0gwr61GPAUOlRViomj9Y5BqwkNNz9FB5UfQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hs0Bm4rsrzLxd for ; Fri, 25 Sep 2026 18:50:24 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 31bf2 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 25 Sep 2026 18:50:24 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Alan Somers Subject: git: c5031d3b0421 - stable/15 - fusefs: fix vnode locking violations during execve List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: asomers X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: c5031d3b0421bf62e0b215012295b15107f29cec Auto-Submitted: auto-generated Date: Fri, 25 Sep 2026 18:50:24 +0000 Message-Id: <6ab6c270.31bf2.6351e178@gitrepo.freebsd.org> The branch stable/15 has been updated by asomers: URL: https://cgit.FreeBSD.org/src/commit/?id=c5031d3b0421bf62e0b215012295b15107f29cec commit c5031d3b0421bf62e0b215012295b15107f29cec Author: Alan Somers AuthorDate: 2026-06-10 20:39:22 +0000 Commit: Alan Somers CommitDate: 2026-09-25 17:32:47 +0000 fusefs: fix vnode locking violations during execve Fix two locking violations that could happen during execve, while executing a file stored on fusefs. Both would cause panics on an INVARIANTS kernel after 15.0, or a DEBUG_VFS_LOCKS kernel prior to that. Neither is likely to be noticeable on a release kernel. * Don't assume that the vnode is exclusively locked during VOP_CLOSE. It usually is thanks to !MNTK_LOOKUP_SHARED, but isn't during execve, which locks the vnode outside of the lookup path. * Totally rewrite fuse_io_invalbuf. It's had a number of problems ever since its original introduction[^1]: - Don't assume that the vnode is exclusively locked. That assumption failed during execve just like the assumption in fuse_vnop_close. - Don't livelock forever if vinvalbuf returns ENOSPC or EDQUOT. - Don't attempt to handle multiple threads calling this function at the same time. That would be impossible if the vnode truly were exclusively locked. So the code was dead. Or it would've been, if the assumption hadn't been wrong. Furthermore, both vinvalbuf and vnode_pager_clean_sync only require a shared vnode lock, and are already capable of dealing with multiple simultaneous callers. - Using fvdat->flag in this way would require some sort of mutex protection, if the vnode weren't exclusively locked. * Add new test cases that trigger both of the aforementioned panics. [^1]: https://github.com/glk/fuse-freebsd/commit/efe6eb3005e7633b4e31d5e453eacbaa0cba42fa PR: 295957 Reported by: dan.kotowski@a9development.com Sponsored by: ConnectWise Reviewed by: markj Differential Revision: https://reviews.freebsd.org/D57536 (cherry picked from commit ee1c3d38a26aa63fca8e9f86c0d456800d5e2576) --- sys/fs/fuse/fuse_io.c | 49 +------ sys/fs/fuse/fuse_node.h | 2 - sys/fs/fuse/fuse_vnops.c | 27 +++- tests/sys/fs/fusefs/Makefile | 2 + tests/sys/fs/fusefs/ext2-misc.sh | 55 +++++++ tests/sys/fs/fusefs/misc.cc | 304 +++++++++++++++++++++++++++++++++++++++ tests/sys/fs/fusefs/mockfs.cc | 2 +- tests/sys/fs/fusefs/utils.cc | 3 +- 8 files changed, 388 insertions(+), 56 deletions(-) diff --git a/sys/fs/fuse/fuse_io.c b/sys/fs/fuse/fuse_io.c index 9f864e48effc..c4fbb263557f 100644 --- a/sys/fs/fuse/fuse_io.c +++ b/sys/fs/fuse/fuse_io.c @@ -928,58 +928,13 @@ fuse_io_flushbuf(struct vnode *vp, int waitfor, struct thread *td) return (vn_fsync_buf(vp, waitfor)); } -/* - * Flush and invalidate all dirty buffers. If another process is already - * doing the flush, just wait for completion. - */ +/* Flush and invalidate all dirty buffers. */ int fuse_io_invalbuf(struct vnode *vp, struct thread *td) { - struct fuse_vnode_data *fvdat = VTOFUD(vp); - int error = 0; - if (VN_IS_DOOMED(vp)) return 0; - ASSERT_VOP_ELOCKED(vp, "fuse_io_invalbuf"); - - while (fvdat->flag & FN_FLUSHINPROG) { - struct proc *p = td->td_proc; - - if (vp->v_mount->mnt_kern_flag & MNTK_UNMOUNTF) - return EIO; - fvdat->flag |= FN_FLUSHWANT; - tsleep(&fvdat->flag, PRIBIO, "fusevinv", 2 * hz); - error = 0; - if (p != NULL) { - PROC_LOCK(p); - if (SIGNOTEMPTY(p->p_siglist) || - SIGNOTEMPTY(td->td_siglist)) - error = EINTR; - PROC_UNLOCK(p); - } - if (error == EINTR) - return EINTR; - } - fvdat->flag |= FN_FLUSHINPROG; - vnode_pager_clean_sync(vp); - error = vinvalbuf(vp, V_SAVE, PCATCH, 0); - while (error) { - if (error == ERESTART || error == EINTR) { - fvdat->flag &= ~FN_FLUSHINPROG; - if (fvdat->flag & FN_FLUSHWANT) { - fvdat->flag &= ~FN_FLUSHWANT; - wakeup(&fvdat->flag); - } - return EINTR; - } - error = vinvalbuf(vp, V_SAVE, PCATCH, 0); - } - fvdat->flag &= ~FN_FLUSHINPROG; - if (fvdat->flag & FN_FLUSHWANT) { - fvdat->flag &= ~FN_FLUSHWANT; - wakeup(&fvdat->flag); - } - return (error); + return (vinvalbuf(vp, V_SAVE, PCATCH, 0)); } diff --git a/sys/fs/fuse/fuse_node.h b/sys/fs/fuse/fuse_node.h index b6e388d01702..191a5859b031 100644 --- a/sys/fs/fuse/fuse_node.h +++ b/sys/fs/fuse/fuse_node.h @@ -71,8 +71,6 @@ #include "fuse_file.h" #define FN_REVOKED 0x00000020 -#define FN_FLUSHINPROG 0x00000040 -#define FN_FLUSHWANT 0x00000080 /* * Indicates that the file's size is dirty; the kernel has changed it but not * yet send the change to the daemon. When this bit is set, the diff --git a/sys/fs/fuse/fuse_vnops.c b/sys/fs/fuse/fuse_vnops.c index b5f65decc399..7a991f6eed5e 100644 --- a/sys/fs/fuse/fuse_vnops.c +++ b/sys/fs/fuse/fuse_vnops.c @@ -800,8 +800,10 @@ fuse_vnop_close(struct vop_close_args *ap) int fflag = ap->a_fflag; struct thread *td; struct fuse_vnode_data *fvdat = VTOFUD(vp); + struct timespec va_atime; pid_t pid; int err = 0; + bool atime_change, size_change; /* NB: a_td will be NULL from some async kernel contexts */ td = ap->a_td ? ap->a_td : curthread; @@ -818,8 +820,14 @@ fuse_vnop_close(struct vop_close_args *ap) cred = td->td_ucred; err = fuse_flush(vp, cred, pid, fflag); - ASSERT_CACHED_ATTRS_LOCKED(vp); /* For fvdat->flag */ - if (err == 0 && (fvdat->flag & FN_ATIMECHANGE) && !vfs_isrdonly(mp)) { + + CACHED_ATTR_LOCK(vp); + atime_change = fvdat->flag & FN_ATIMECHANGE; + size_change = fvdat->flag & FN_SIZECHANGE; + va_atime = fvdat->cached_attrs.va_atime; + CACHED_ATTR_UNLOCK(vp); + + if (err == 0 && atime_change && !vfs_isrdonly(mp)) { struct vattr vap; struct fuse_data *data; int dataflags; @@ -836,19 +844,28 @@ fuse_vnop_close(struct vop_close_args *ap) } if (access_e == 0) { VATTR_NULL(&vap); - ASSERT_CACHED_ATTRS_LOCKED(vp); - vap.va_atime = fvdat->cached_attrs.va_atime; + vap.va_atime = va_atime; /* * Ignore errors setting when setting atime. That * should not cause close(2) to fail. */ + CACHED_ATTR_LOCK(vp); fuse_internal_setattr(vp, &vap, td, NULL); + CACHED_ATTR_UNLOCK(vp); } } /* TODO: close the file handle, if we're sure it's no longer used */ - if ((fvdat->flag & FN_SIZECHANGE) != 0) { + if (size_change != 0) { + /* + * NB: this may panic if MNTK_SHARED_WRITES is ever enabled. + * For now it cannot, because it is illegal to use fexecve to + * execute a file descriptor open for writing, there's no way + * to dirty a file's size without writing to it, and we don't + * set MNTK_SHARED_WRITES. + */ fuse_vnode_savesize(vp, cred, pid); } + return err; } diff --git a/tests/sys/fs/fusefs/Makefile b/tests/sys/fs/fusefs/Makefile index 94570c09970e..5b045dd55cd5 100644 --- a/tests/sys/fs/fusefs/Makefile +++ b/tests/sys/fs/fusefs/Makefile @@ -5,6 +5,7 @@ PACKAGE= tests TESTSDIR= ${TESTSBASE}/sys/fs/fusefs ATF_TESTS_SH+= ctl +ATF_TESTS_SH+= ext2-misc # We could simply link all of these files into a single executable. But since # Kyua treats googletest programs as plain tests, it's better to separate them @@ -34,6 +35,7 @@ GTESTS+= link GTESTS+= locks GTESTS+= lookup GTESTS+= lseek +GTESTS+= misc GTESTS+= mkdir GTESTS+= mknod GTESTS+= mount diff --git a/tests/sys/fs/fusefs/ext2-misc.sh b/tests/sys/fs/fusefs/ext2-misc.sh new file mode 100644 index 000000000000..b2d713a1864a --- /dev/null +++ b/tests/sys/fs/fusefs/ext2-misc.sh @@ -0,0 +1,55 @@ +# SPDX-License-Identifier: BSD-2-Clause +# +# Copyright (c) 2026 ConnectWise +# All rights reserved. +# +# Redistribution and use in source and binary forms, with or without +# modification, are permitted provided that the following conditions +# are met: +# 1. Redistributions of source code must retain the above copyright +# notice, this list of conditions and the following disclaimer. +# 2. Redistributions in binary form must reproduce the above copyright +# notice, this list of conditions and the following disclaimer in the +# documentation and/or other materials provided with the distribution. +# +# THIS DOCUMENTATION IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR +# IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +# OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +# IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, +# INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +# NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +# THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + +# Regression test for https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295957 +# +# Almost any fuse file system would work, but this tests uses fusefs-ext2 +# because it's simple and its download is very small. +atf_test_case execute cleanup +execute_head() +{ + atf_set "descr" "Execute a file mounted on a fusefs file system" + atf_set "require.user" "root" + atf_set "require.progs" "fuse-ext2 mkfs.ext2" + atf_set "require.kmods" "fusefs" +} +execute_body() +{ + atf_check mkdir mnt + atf_check truncate -s 64m ext2.img + atf_check -o ignore -e ignore mkfs.ext2 ext2.img + atf_check fuse-ext2 -o rw+ ext2.img mnt + atf_check cp /usr/bin/true mnt + atf_check su -m nobody -c mnt/true +} +execute_cleanup() +{ + umount $PWD/mnt || true +} + +atf_init_test_cases() +{ + atf_add_test_case execute +} diff --git a/tests/sys/fs/fusefs/misc.cc b/tests/sys/fs/fusefs/misc.cc new file mode 100644 index 000000000000..d95356262c1f --- /dev/null +++ b/tests/sys/fs/fusefs/misc.cc @@ -0,0 +1,304 @@ +/*- + * SPDX-License-Identifier: BSD-2-Clause + * + * Copyright (c) 2026 Alan Somers + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND + * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE + * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE + * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE + * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL + * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS + * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) + * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT + * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY + * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF + * SUCH DAMAGE. + */ + +/* Miscellaneous tests that don't relate to any particular fuse operation */ + +extern "C" { +#include + +#include +#include +} + +#include "mockfs.hh" +#include "utils.hh" + +using namespace testing; + + +class Execv: public FuseTest { +public: +virtual void SetUp() { + /* Enable FUSE_ASYNC_READ to allow shared vnode locks */ + m_init_flags = FUSE_ASYNC_READ; + FuseTest::SetUp(); +} +}; +class Fexecv: public Execv {}; + +class FexecvDefaultPermissions: public Fexecv { +virtual void SetUp() { + m_default_permissions = true; + Fexecv::SetUp(); +} +}; + +/* + * Execute a file mounted on a fusefs file system. The server should get the + * FUSE_RELEASE request when sys_fexecve closes the file. + * + * Crucially, execve ignores the file system's MNTK_EXTENDED_SHARED flag. + * + * Regression test for https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=295957 + */ +TEST_F(Execv, close) +{ + const static char FULLPATH[] = "mountpoint/true"; + const static char RELPATH[] = "true"; + const static size_t BUFSIZE = 16384; + FILE *true_file; + uint64_t ino = 42; + size_t true_len; + int status; + char *buf; + + buf = new char[BUFSIZE]; + true_file = fopen("/usr/bin/true", "r"); + ASSERT_TRUE(true_file) << strerror(errno); + true_len = fread(buf, 1, BUFSIZE, true_file); + ASSERT_LT(true_len, BUFSIZE) << "Must increase BUFSIZE"; + fclose(true_file); + + fork(false, &status, [&] { + expect_lookup(RELPATH, ino, S_IFREG | 0755, true_len, 1, + UINT64_MAX); + expect_open(ino, 0, 1); + expect_read(ino, 0, true_len, true_len, buf); + expect_flush(ino, 1, ReturnErrno(ENOSYS)); + EXPECT_CALL(*m_mock, process( + ResultOf([=](auto in) { + return (in.header.opcode == FUSE_RELEASE && + in.header.nodeid == ino); + }, Eq(true)), + _) + ).Times(1) + .WillRepeatedly(Invoke(ReturnErrno(0))); + + }, [&] { + char *const argv[] = {__DECONST(char *, "true"), NULL}; + char *const env[] = {NULL}; + + execve(FULLPATH, argv, env); + fprintf(stderr, "execv: %s\n", strerror(errno)); + return 1; + }); + ASSERT_EQ(0, WEXITSTATUS(status)); + + delete[] buf; +} + +TEST_F(Fexecv, close) +{ + const static char FULLPATH[] = "mountpoint/true"; + const static char RELPATH[] = "true"; + const static size_t BUFSIZE = 16384; + FILE *true_file; + uint64_t ino = 42; + size_t true_len; + int status; + char *buf; + + buf = new char[BUFSIZE]; + true_file = fopen("/usr/bin/true", "r"); + ASSERT_TRUE(true_file) << strerror(errno); + true_len = fread(buf, 1, BUFSIZE, true_file); + ASSERT_LT(true_len, BUFSIZE) << "Must increase BUFSIZE"; + fclose(true_file); + + fork(false, &status, [&] { + expect_lookup(RELPATH, ino, S_IFREG | 0755, true_len, 1, + UINT64_MAX); + expect_open(ino, 0, 2); + expect_read(ino, 0, true_len, true_len, buf); + expect_flush(ino, 1, ReturnErrno(ENOSYS)); + EXPECT_CALL(*m_mock, process( + ResultOf([=](auto in) { + return (in.header.opcode == FUSE_RELEASE && + in.header.nodeid == ino); + }, Eq(true)), + _) + ).Times(2) + .WillRepeatedly(Invoke(ReturnErrno(0))); + + }, [&] { + char *const argv[] = {__DECONST(char *, "true"), NULL}; + char *const env[] = {NULL}; + int fd; + + fd = open(FULLPATH, O_EXEC); + if (fd < 0) { + fprintf(stderr, "open: %s\n", strerror(errno)); + return 1; + } + fexecve(fd, argv, env); + fprintf(stderr, "execv: %s\n", strerror(errno)); + return 1; + }); + ASSERT_EQ(0, WEXITSTATUS(status)); + + delete[] buf; +} + +/* + * Execute a file stored on a fusefs file system that does not implement + * FUSE_OPEN + */ +TEST_F(Fexecv, close_noopen) +{ + const static char FULLPATH[] = "mountpoint/true"; + const static char RELPATH[] = "true"; + const static size_t BUFSIZE = 16384; + FILE *true_file; + uint64_t ino = 42; + size_t true_len; + int status; + char *buf; + + buf = new char[BUFSIZE]; + true_file = fopen("/usr/bin/true", "r"); + ASSERT_TRUE(true_file) << strerror(errno); + true_len = fread(buf, 1, BUFSIZE, true_file); + ASSERT_LT(true_len, BUFSIZE) << "Must increase BUFSIZE"; + fclose(true_file); + + fork(false, &status, [&] { + expect_lookup(RELPATH, ino, S_IFREG | 0755, true_len, 1, + UINT64_MAX); + EXPECT_CALL(*m_mock, process( + ResultOf([=](auto in) { + return (in.header.opcode == FUSE_OPEN && + in.header.nodeid == ino); + }, Eq(true)), + _) + ).Times(1) + .WillOnce(Invoke(ReturnErrno(ENOSYS))); + expect_read(ino, 0, true_len, true_len, buf, -1, 0); + expect_flush(ino, 1, ReturnErrno(ENOSYS)); + }, [&] { + char *const argv[] = {__DECONST(char *, "true"), NULL}; + char *const env[] = {NULL}; + int fd; + + fd = open(FULLPATH, O_EXEC); + if (fd < 0) { + fprintf(stderr, "open: %s\n", strerror(errno)); + return 1; + } + fexecve(fd, argv, env); + fprintf(stderr, "execv: %s\n", strerror(errno)); + return 1; + }); + ASSERT_EQ(0, WEXITSTATUS(status)); + + delete[] buf; +} + +/* + * When execute a file with a dirty atime, fusefs must send FUSE_SETATTR to the + * daemon during close. + */ +TEST_F(FexecvDefaultPermissions, atime) +{ + const static char FULLPATH[] = "mountpoint/true"; + const static char RELPATH[] = "true"; + const static size_t BUFSIZE = 16384; + FILE *true_file; + uint64_t ino = 42; + size_t true_len; + int status; + char *buf; + + buf = new char[BUFSIZE]; + true_file = fopen("/usr/bin/true", "r"); + ASSERT_TRUE(true_file) << strerror(errno); + true_len = fread(buf, 1, BUFSIZE, true_file); + ASSERT_LT(true_len, BUFSIZE) << "Must increase BUFSIZE"; + fclose(true_file); + + fork(false, &status, [&] { + expect_lookup(RELPATH, ino, S_IFREG | 0777, true_len, 1, + UINT64_MAX); + EXPECT_CALL(*m_mock, process( + ResultOf([=](auto in) { + return (in.header.opcode == FUSE_GETATTR && + in.header.nodeid == FUSE_ROOT_ID); + }, Eq(true)), + _) + ).WillRepeatedly(Invoke(ReturnImmediate([=](auto i __unused, auto& out) { + SET_OUT_HEADER_LEN(out, attr); + out.body.attr.attr.ino = FUSE_ROOT_ID; + out.body.attr.attr.mode = S_IFDIR | 0777; + out.body.attr.attr.size = 0; + out.body.attr.attr_valid = UINT64_MAX; + }))); + EXPECT_CALL(*m_mock, process( + ResultOf([=](auto in) { + return (in.header.opcode == FUSE_OPEN && + in.header.nodeid == ino); + }, Eq(true)), + _) + ).Times(1) + .WillOnce(Invoke(ReturnErrno(ENOSYS))); + expect_read(ino, 0, true_len, true_len, buf, -1, 0); + expect_flush(ino, 1, ReturnErrno(ENOSYS)); + EXPECT_CALL(*m_mock, process( + ResultOf([&](auto in) { + return (in.header.opcode == FUSE_SETATTR && + in.header.nodeid == ino && + in.body.setattr.valid == FATTR_ATIME); + }, Eq(true)), + _) + ).WillOnce(Invoke(ReturnImmediate([=](auto in __unused, auto& out) { + SET_OUT_HEADER_LEN(out, attr); + out.body.attr.attr.ino = ino; + out.body.attr.attr.mode = S_IFREG | 0777; + }))); + }, [&] { + char *const argv[] = {__DECONST(char *, "true"), NULL}; + char *const env[] = {NULL}; + char buf[8]; + int fd; + + /* Note that fexecve doesn't actually require O_EXEC */ + fd = open(FULLPATH, O_RDONLY); + if (fd < 0) { + fprintf(stderr, "open: %s\n", strerror(errno)); + return 1; + } + /* Read a few bytes, just to dirty the file's atime */ + if (read(fd, buf, sizeof(buf)) < 0) { + fprintf(stderr, "read: %s\n", strerror(errno)); + return 1; + } + fexecve(fd, argv, env); + fprintf(stderr, "execv: %s\n", strerror(errno)); + return 1; + }); + ASSERT_EQ(0, WEXITSTATUS(status)); + + delete[] buf; +} diff --git a/tests/sys/fs/fusefs/mockfs.cc b/tests/sys/fs/fusefs/mockfs.cc index 046d95de3859..e1fea83c3deb 100644 --- a/tests/sys/fs/fusefs/mockfs.cc +++ b/tests/sys/fs/fusefs/mockfs.cc @@ -294,7 +294,7 @@ void MockFS::debug_request(const mockfs_buf_in &in, ssize_t buflen) in.body.read.offset, in.body.read.size); if (verbosity > 1) - printf(" flags=%#x", in.body.read.flags); + printf(" fh=%#" PRIx64 " flags=%#x", in.body.read.fh, in.body.read.flags); break; case FUSE_READDIR: printf(" fh=%#" PRIx64 " offset=%" PRIu64 " size=%u", diff --git a/tests/sys/fs/fusefs/utils.cc b/tests/sys/fs/fusefs/utils.cc index 6f6bd1650848..e0fbb9f9af8e 100644 --- a/tests/sys/fs/fusefs/utils.cc +++ b/tests/sys/fs/fusefs/utils.cc @@ -386,7 +386,8 @@ void FuseTest::expect_read(uint64_t ino, uint64_t offset, uint64_t isize, in.body.read.size == isize && (flags == -1 ? (in.body.read.flags == O_RDONLY || - in.body.read.flags == O_RDWR) + in.body.read.flags == O_RDWR || + in.body.read.flags == O_EXEC) : in.body.read.flags == (uint32_t)flags)); }, Eq(true)), _)