Edward O'Callaghan has uploaded this change for review.

View Change

flashrom.c: Implement file-based locking semantics

This upstreams the ChromiumOS implementation of file-based locking
for multiple instances of flashrom that could be spawned either
from libflashrom (perhaps by fwupd for example) and user cli
as another example. Since flashrom is programming singleton state
of hardware from userspace there is no way to exclusively own
the address space and therefore a file-based locking semantic
is considered here.

BUG=b:217629892,b:215255210
BRANCH=none
TEST=nm -gD /build/brya/usr/lib64/libflashrom.so | grep "flock"
Test futility update with multiple instances of flashrom running.

Change-Id: I19cb4e3bf14caeb67c3e8100a20395b264c5113a
Signed-off-by: Edward O'Callaghan <quasisec@google.com>
---
M Makefile
A big_lock.c
A big_lock.h
A file_lock.c
M flashrom.c
A ipc_lock.h
M meson.build
7 files changed, 441 insertions(+), 0 deletions(-)

git pull ssh://review.coreboot.org:29418/flashrom refs/changes/13/62213/1
diff --git a/Makefile b/Makefile
index 7628142..365c282 100644
--- a/Makefile
+++ b/Makefile
@@ -388,6 +388,7 @@
# Library code.

LIB_OBJS = libflashrom.o layout.o flashrom.o udelay.o programmer.o programmer_table.o helpers.o ich_descriptors.o fmap.o
+LIB_OBJS += big_lock.o file_lock.o

###############################################################################
# Frontend related stuff.
diff --git a/big_lock.c b/big_lock.c
new file mode 100644
index 0000000..7b83f3e
--- /dev/null
+++ b/big_lock.c
@@ -0,0 +1,45 @@
+/* Copyright 2012, Google Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions are
+ * met:
+ *
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above
+ * copyright notice, this list of conditions and the following
+ * disclaimer in the documentation and/or other materials provided
+ * with the distribution.
+ * * Neither the name of Google Inc. nor the names of its
+ * contributors may be used to endorse or promote products derived
+ * from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include "big_lock.h"
+#include "ipc_lock.h"
+
+#define LOCKFILE_NAME "firmware_utility_lock"
+static struct ipc_lock big_lock = LOCKFILE_INIT(LOCKFILE_NAME);
+
+int acquire_big_lock(int timeout_secs)
+{
+ return acquire_lock(&big_lock, timeout_secs * 1000);
+}
+
+int release_big_lock(void)
+{
+ return release_lock(&big_lock);
+}
diff --git a/big_lock.h b/big_lock.h
new file mode 100644
index 0000000..a28fe44
--- /dev/null
+++ b/big_lock.h
@@ -0,0 +1,51 @@
+/* Copyright 2012, Google Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions are
+ * met:
+ *
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above
+ * copyright notice, this list of conditions and the following
+ * disclaimer in the documentation and/or other materials provided
+ * with the distribution.
+ * * Neither the name of Google Inc. nor the names of its
+ * contributors may be used to endorse or promote products derived
+ * from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#ifndef BIG_LOCK_H__
+#define BIG_LOCK_H__
+
+/*
+ * acquire_big_lock - acquire global lock
+ *
+ * returns 0 to indicate lock acquired
+ * returns >0 to indicate lock was already held
+ * returns <0 to indicate failed to acquire lock
+ */
+extern int acquire_big_lock(int timeout_secs);
+
+/*
+ * release_big_lock - release global lock
+ *
+ * returns 0 if lock was released successfully
+ * returns -1 if lock had not been held before the call
+ */
+extern int release_big_lock(void);
+
+#endif /* BIG_LOCK_H__ */
diff --git a/file_lock.c b/file_lock.c
new file mode 100644
index 0000000..4bcfeb2
--- /dev/null
+++ b/file_lock.c
@@ -0,0 +1,247 @@
+/* Copyright 2016, Google Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions are
+ * met:
+ *
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above
+ * copyright notice, this list of conditions and the following
+ * disclaimer in the documentation and/or other materials provided
+ * with the distribution.
+ * * Neither the name of Google Inc. nor the names of its
+ * contributors may be used to endorse or promote products derived
+ * from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ *
+ * Alternatively, this software may be distributed under the terms of the
+ * GNU General Public License ("GPL") version 2 as published by the Free
+ * Software Foundation.
+ *
+ * file_lock.c: Implementation for a binary semaphore using a file lock.
+ *
+ * Warning: This relies on flock() which is known to be broken on NFS.
+ *
+ * The file will remain persistent once the lock has been used. Unfortunately,
+ * unlinking the file can introduce a race condition so we leave the file
+ * in place.
+ *
+ * The current process's PID will be written to the file for debug purposes.
+ */
+
+#include <errno.h>
+#include <fcntl.h>
+#include <inttypes.h>
+#include <limits.h>
+#include <stdio.h>
+#include <stdlib.h>
+#include <string.h>
+#include <time.h>
+#include <unistd.h>
+#include <sys/file.h>
+#include <sys/types.h>
+#include <sys/stat.h>
+
+#include "flash.h"
+#include "ipc_lock.h"
+
+#define SLEEP_INTERVAL_MS 50
+
+static void msecs_to_timespec(int msecs, struct timespec *tmspec)
+{
+ tmspec->tv_sec = msecs / 1000;
+ tmspec->tv_nsec = (msecs % 1000) * 1000 * 1000;
+}
+
+static int lock_is_held(struct ipc_lock *lock)
+{
+ return lock->is_held;
+}
+
+static int test_dir(const char *path)
+{
+ struct stat s;
+
+ if (lstat(path, &s) < 0) {
+ msg_gerr("Cannot stat %s.\n", path);
+ return -1;
+ }
+
+ if (!S_ISDIR(s.st_mode)) {
+ msg_gerr("%s is not a directory.\n", path);
+ return -1;
+ }
+
+ return 0;
+}
+
+#define SYSTEM_LOCKFILE_DIR "/run/lock"
+static int file_lock_open_or_create(struct ipc_lock *lock)
+{
+ char path[PATH_MAX];
+ const char *dir = SYSTEM_LOCKFILE_DIR;
+ const char fallback[] = "/tmp";
+
+ if (test_dir(dir)) {
+ dir = fallback;
+ msg_gerr("Trying fallback directory: %s\n", dir);
+ if (test_dir(dir))
+ return -1;
+ }
+
+ if (snprintf(path, sizeof(path), "%s/%s", dir, lock->filename) < 0)
+ return -1;
+
+ lock->fd = open(path, O_RDWR | O_CREAT, 0600);
+ if (lock->fd < 0) {
+ msg_gerr("Cannot open lockfile %s", path);
+ return -1;
+ }
+
+ msg_gdbg("Opened file lock \"%s\"\n", path);
+ return 0;
+}
+
+static int file_lock_get(struct ipc_lock *lock, int timeout_msecs)
+{
+ int msecs_remaining = timeout_msecs;
+ struct timespec sleep_interval, rem;
+ int ret = -1;
+
+ if (timeout_msecs == 0)
+ return flock(lock->fd, LOCK_EX | LOCK_NB);
+
+ msecs_to_timespec(SLEEP_INTERVAL_MS, &sleep_interval);
+
+ while ((ret = flock(lock->fd, LOCK_EX | LOCK_NB)) != 0) {
+ if (errno != EWOULDBLOCK) {
+ msg_gerr("Error obtaining lock");
+ return -1;
+ }
+
+ if (msecs_remaining < SLEEP_INTERVAL_MS)
+ msecs_to_timespec(msecs_remaining, &sleep_interval);
+
+ while (nanosleep(&sleep_interval, &rem) != 0) {
+ if (errno == EINTR) {
+ sleep_interval = rem;
+ continue;
+ } else {
+ msg_gerr("nanosleep() failed");
+ return ret;
+ }
+ }
+
+ if (timeout_msecs < 0)
+ continue;
+
+ msecs_remaining -= SLEEP_INTERVAL_MS;
+ if (msecs_remaining < 0)
+ break;
+ }
+
+ if (ret != 0) {
+ msg_gerr("Timed out waiting for file lock.\n");
+ return -1;
+ }
+
+ return 0;
+}
+
+static int file_lock_write_pid(struct ipc_lock *lock)
+{
+ ssize_t len;
+ /* PIDs are usually 5 digits, but we'll reserve enough room for
+ a value of 2^32 (10 digits) out of paranoia. */
+ char pid_str[11];
+
+ if (ftruncate(lock->fd, 0) < 0) {
+ msg_gerr("Cannot truncate lockfile");
+ return -1;
+ }
+
+ snprintf(pid_str, sizeof(pid_str), "%lu", (unsigned long)getpid());
+ len = write(lock->fd, pid_str, strlen(pid_str));
+ if (len < 0) {
+ msg_gerr("Cannot write PID to lockfile");
+ return -1;
+ }
+
+ return 0;
+}
+
+static void file_lock_release(struct ipc_lock *lock)
+{
+ if (flock(lock->fd, LOCK_UN) < 0)
+ msg_gerr("Cannot release lock");
+
+ if (close(lock->fd) < 0)
+ msg_gerr("Cannot close lockfile");
+}
+
+/*
+ * timeout <0 = no timeout (try forever)
+ * timeout 0 = do not wait (return immediately)
+ * timeout >0 = wait up to $timeout milliseconds
+ *
+ * returns 0 to indicate lock acquired
+ * returns >0 to indicate lock was already held
+ * returns <0 to indicate failed to acquire lock
+ */
+int acquire_lock(struct ipc_lock *lock, int timeout_msecs)
+{
+ /* check if it is already held */
+ if (lock_is_held(lock))
+ return 1;
+
+ if (file_lock_open_or_create(lock))
+ return -1;
+
+ if (file_lock_get(lock, timeout_msecs)) {
+ lock->is_held = 0;
+ close(lock->fd);
+ return -1;
+ } else {
+ lock->is_held = 1;
+ }
+
+ /*
+ * Write PID to lockfile for debug purposes. Failure to write to
+ * the file should not be considered fatal. There might be something
+ * bad happening with the filesystem, but the lock has already been
+ * obtained and we may need our tools for diagnostics and repairs
+ * so we should continue anyway.
+ */
+ file_lock_write_pid(lock);
+ return 0;
+}
+
+/*
+ * returns 0 if lock was released successfully
+ * returns -1 if lock had not been held before the call
+ */
+int release_lock(struct ipc_lock *lock)
+{
+ if (lock_is_held(lock)) {
+ file_lock_release(lock);
+ lock->is_held = 0;
+ return 0;
+ }
+
+ msg_ginfo("%s called but lock was not held on %s.\n",
+ __func__, lock->filename);
+ return -1;
+}
diff --git a/flashrom.c b/flashrom.c
index ac61259..672b378 100644
--- a/flashrom.c
+++ b/flashrom.c
@@ -34,6 +34,8 @@
#if HAVE_UTSNAME == 1
#include <sys/utsname.h>
#endif
+
+#include "big_lock.h"
#include "flash.h"
#include "flashchips.h"
#include "programmer.h"
@@ -46,6 +48,15 @@
static const struct programmer_entry *programmer = NULL;
static const char *programmer_param = NULL;

+#ifndef USE_BIG_LOCK
+#define USE_BIG_LOCK 0
+#endif
+
+#define LOCK_TIMEOUT_SECS 180
+
+/** Big lock acquisition status. */
+static bool big_lock_acquired = false;
+
/*
* Programmers supporting multiple buses can have differing size limits on
* each bus. Store the limits for each bus in a common struct.
@@ -136,6 +147,16 @@
msg_perr("Invalid programmer specified!\n");
return -1;
}
+
+ /* Get big lock before doing any work that touches hardware. */
+ msg_gdbg("Acquiring lock (timeout=%d sec)...\n", LOCK_TIMEOUT_SECS);
+ if (acquire_big_lock(LOCK_TIMEOUT_SECS) < 0) {
+ msg_gerr("Could not acquire lock.\n");
+ return -1;
+ }
+ big_lock_acquired = true;
+ msg_gdbg("Lock acquired.\n");
+
programmer = prog;
/* Initialize all programmer specific data. */
/* Default to unlimited decode sizes. */
@@ -193,6 +214,11 @@
programmer_param = NULL;
registered_master_count = 0;

+ if (big_lock_acquired) {
+ release_big_lock();
+ big_lock_acquired = false;
+ }
+
return ret;
}

diff --git a/ipc_lock.h b/ipc_lock.h
new file mode 100644
index 0000000..7b53ffe
--- /dev/null
+++ b/ipc_lock.h
@@ -0,0 +1,69 @@
+/* Copyright 2012, Google Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions are
+ * met:
+ *
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above
+ * copyright notice, this list of conditions and the following
+ * disclaimer in the documentation and/or other materials provided
+ * with the distribution.
+ * * Neither the name of Google Inc. nor the names of its
+ * contributors may be used to endorse or promote products derived
+ * from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#ifndef IPC_LOCK_H__
+#define IPC_LOCK_H__
+
+struct ipc_lock {
+ int is_held; /* internal */
+ const char *filename; /* provided by the developer */
+ int fd; /* internal */
+};
+
+/* don't use C99 initializers here, so this can be used in C++ code */
+#define LOCKFILE_INIT(lockfile) \
+ { \
+ 0, /* is_held */ \
+ lockfile, /* filename */ \
+ -1, /* fd */ \
+ }
+
+/*
+ * acquire_lock: acquire a lock
+ *
+ * timeout <0 = no timeout (try forever)
+ * timeout 0 = do not wait (return immediately)
+ * timeout >0 = wait up to $timeout milliseconds (subject to kernel scheduling)
+ *
+ * return 0 = lock acquired
+ * return >0 = lock was already held
+ * return <0 = failed to acquire lock
+ */
+extern int acquire_lock(struct ipc_lock *lock, int timeout_msecs);
+
+/*
+ * release_lock: release a lock
+ *
+ * returns 0 if lock was released successfully
+ * returns -1 if lock had not been held before the call
+ */
+extern int release_lock(struct ipc_lock *lock);
+
+#endif /* IPC_LOCK_H__ */
diff --git a/meson.build b/meson.build
index cd9f9fb..69ceb06 100644
--- a/meson.build
+++ b/meson.build
@@ -401,11 +401,13 @@
# core modules needed by both the library and the CLI
srcs += '82802ab.c'
srcs += 'at45db.c'
+srcs += 'big_lock.c'
srcs += 'edi.c'
srcs += 'en29lv640b.c'
srcs += 'flashchips.c'
srcs += 'flashrom.c'
srcs += 'fmap.c'
+srcs += 'file_lock.c'
srcs += 'helpers.c'
srcs += 'ich_descriptors.c'
srcs += 'jedec.c'

To view, visit change 62213. To unsubscribe, or for help writing mail filters, visit settings.

Gerrit-Project: flashrom
Gerrit-Branch: master
Gerrit-Change-Id: I19cb4e3bf14caeb67c3e8100a20395b264c5113a
Gerrit-Change-Number: 62213
Gerrit-PatchSet: 1
Gerrit-Owner: Edward O'Callaghan <quasisec@chromium.org>
Gerrit-MessageType: newchange