From: Al Viro <viro@ZenIV.linux.org.uk>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [RFC] st_nlink after rmdir() and rename()
Date: Thu, 3 Mar 2011 03:24:54 +0000 [thread overview]
Message-ID: <20110303032454.GI22723@ZenIV.linux.org.uk> (raw)
We have an interesting problem. Consider the following sequence
of syscalls:
mkdir("foo", 0777);
mkdir("bar", 0777);
fd1 = open("foo", O_DIRECTORY);
fd2 = open("bar", O_DIRECTORY);
rename("foo", "bar"); /* kill old bar */
rmdir("bar"); /* kill old foo */
fstat(fd1, &buf1);
fstat(fd2, &buf2);
What should be in buf1.st_nlink and buf2.st_nlink, if none of these
syscalls fail? Note that in both cases any lookups in victim directory
will fail and so will readdir; as far as VFS is concerned, the effect of
such rmdir() and rename() on their victims are identical. In particular,
both . and .. are gone, as explicitly required by POSIX in case of rmdir().
Surprisingly, the results are *NOT* identical wrt fstat(); for most of
the filesystems we will get 0 in both cases (as expected), but some will
leave 1 in buf2.st_nlink. What we have is
0 0: ext*, xfs, jfs, reiserfs, ocfs2, gfs2, nilfs, exofs, udf, ubifs,
minix, sysv, ufs, msdos, vfat, hfs+
0 1: ramfs, shmem, hugetlbfs, jffs2, omfs, hfs[*], apparently nfs as well
hell knows: ncpfs, fuse, ecryptfs, coda, cifs, ceph, btrfs, affs
1 1: (unless I'm misreading it) logfs
completely FUBAR wrt fstat(): hostfs[**]
-EEXIST on rename(): cgroup
-EINVAL on rename(): hpfs
server ought to fail such rename(): 9p
apparently fails rename(): smbfs
completely broken rename(): pohmelfs[***]
[*] yes, different from hfs+; the code is clearly broken, since it simply
does unlink() on target, without even verifying that it's empty. And
yes, it's trivial fs corruption...
[**] even open() + unlink() + fstat() will report original st_nlink, etc.
[***] new_dir is target's _parent_ directory and it's not required to be
empty; it's never going to be NULL, while we are at it. Code makes no
sense...
The variant with st_nlink getting to 0 in both cases is definitely the most
common and at least for local filesystems I think it should be mandatory.
I.e. ramfs and friends, jffs2, omfs and hfs should all switch to it.
Comments would be welcome; I really don't know the protocols of most of
the network filesystems well enough to tell what'll happen in these
situations.
Al, digging through i_nlink code audit...
next reply other threads:[~2011-03-03 3:24 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-03 3:24 Al Viro [this message]
2011-03-03 4:42 ` [RFC] st_nlink after rmdir() and rename() Al Viro
2011-03-03 5:17 ` Linus Torvalds
2011-03-03 6:03 ` Al Viro
2011-03-03 20:05 ` Linus Torvalds
2011-03-03 20:05 ` Linus Torvalds
2011-03-03 20:46 ` OGAWA Hirofumi
2011-03-03 20:50 ` OGAWA Hirofumi
2011-03-03 21:02 ` Linus Torvalds
2011-03-03 21:30 ` Al Viro
2011-03-03 21:37 ` OGAWA Hirofumi
2011-03-03 21:52 ` Linus Torvalds
2011-03-03 22:26 ` OGAWA Hirofumi
2011-03-03 22:37 ` Linus Torvalds
2011-03-03 23:14 ` OGAWA Hirofumi
2011-03-03 23:12 ` Al Viro
2011-03-03 22:57 ` Al Viro
2011-03-03 23:07 ` Al Viro
2011-03-04 6:55 ` omfs fixes Al Viro
2011-03-04 15:24 ` Bob Copeland
2011-03-03 21:23 ` [RFC] st_nlink after rmdir() and rename() Al Viro
2011-03-03 14:34 ` Theodore Tso
2011-03-03 16:17 ` Andreas Schwab
2011-03-03 19:16 ` Al Viro
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20110303032454.GI22723@ZenIV.linux.org.uk \
--to=viro@zeniv.linux.org.uk \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.