Commit cffa18c
committed
fs: serialize littlefs access with a recursive mutex
littlefs is not thread-safe, yet FS is called from three different
FreeRTOS tasks: the SystemTask (fs.Init, controller loads at boot), the
display task (settings and alarm saves from the settings screens,
watchface resource loading) and the BLE host task (FSService performs
full littlefs I/O inside GATT access callbacks, and DFU writes during a
BLE file transfer can run while the user navigates settings screens).
Nothing serializes these calls today. The SpiMaster semaphore only
serializes individual bus transactions; the shared lfs_t state (caches,
open-file list, lookahead) is unprotected, so a BLE filesystem transfer
racing a settings save can corrupt filesystem state.
Take a recursive mutex in every public FS method and expose a RAII
FS::Lock so callers can hold the lock across multi-call sequences. The
recursive type matters: a caller holding FS::Lock still goes through the
public methods. Holding the lock across a sequence is needed wherever an
open file handle must not race a Rename or Delete of the same file,
since lfs_dir_commit invalidates such handles in the mlist.
Cost: one FreeRTOS recursive mutex and one pointer, no API change.
Callers that never overlapped are unaffected; overlapping callers now
briefly wait instead of interleaving inside littlefs.1 parent 8d7a04e commit cffa18c
2 files changed
Lines changed: 46 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| 5 | + | |
5 | 6 | | |
6 | 7 | | |
7 | 8 | | |
| |||
26 | 27 | | |
27 | 28 | | |
28 | 29 | | |
| 30 | + | |
| 31 | + | |
29 | 32 | | |
30 | 33 | | |
31 | 34 | | |
| 35 | + | |
32 | 36 | | |
33 | 37 | | |
34 | 38 | | |
| |||
54 | 58 | | |
55 | 59 | | |
56 | 60 | | |
| 61 | + | |
57 | 62 | | |
58 | 63 | | |
59 | 64 | | |
60 | 65 | | |
| 66 | + | |
61 | 67 | | |
62 | 68 | | |
63 | 69 | | |
64 | 70 | | |
| 71 | + | |
65 | 72 | | |
66 | 73 | | |
67 | 74 | | |
68 | 75 | | |
| 76 | + | |
69 | 77 | | |
70 | 78 | | |
71 | 79 | | |
72 | 80 | | |
| 81 | + | |
73 | 82 | | |
74 | 83 | | |
75 | 84 | | |
76 | 85 | | |
| 86 | + | |
77 | 87 | | |
78 | 88 | | |
79 | 89 | | |
80 | 90 | | |
| 91 | + | |
81 | 92 | | |
82 | 93 | | |
83 | 94 | | |
84 | 95 | | |
| 96 | + | |
85 | 97 | | |
86 | 98 | | |
87 | 99 | | |
88 | 100 | | |
| 101 | + | |
89 | 102 | | |
90 | 103 | | |
91 | 104 | | |
92 | 105 | | |
| 106 | + | |
93 | 107 | | |
94 | 108 | | |
95 | 109 | | |
96 | 110 | | |
| 111 | + | |
97 | 112 | | |
98 | 113 | | |
99 | 114 | | |
100 | 115 | | |
| 116 | + | |
101 | 117 | | |
102 | 118 | | |
103 | 119 | | |
104 | 120 | | |
| 121 | + | |
105 | 122 | | |
106 | 123 | | |
107 | 124 | | |
108 | 125 | | |
| 126 | + | |
109 | 127 | | |
110 | 128 | | |
111 | 129 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
| 7 | + | |
6 | 8 | | |
7 | 9 | | |
8 | 10 | | |
9 | 11 | | |
10 | 12 | | |
11 | 13 | | |
12 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
13 | 40 | | |
14 | 41 | | |
15 | 42 | | |
| |||
41 | 68 | | |
42 | 69 | | |
43 | 70 | | |
| 71 | + | |
44 | 72 | | |
45 | 73 | | |
46 | 74 | | |
| |||
0 commit comments