nuttx/include/nuttx
Marco Casaroli d4c6cfbd40 fs/vfs: Add ioctldir for volume ioctls via the mountpoint directory.
FIOC_REFORMAT, FIOC_OPTIMIZE, FIOC_INTEGRITY and FIOC_DUMP act on a volume,
not on any one file, but the only route into a file system has been the
per-file ioctl method.  A caller therefore has to open an unrelated file
just to name the volume it means.

For nxffs that is not merely awkward, it is a dead end.  nxffs_ioctl()
refuses FIOC_REFORMAT while any file on the volume is open:

    if (volume->ofiles)
      {
        ferr("ERROR: Open files\n");
        ret = -EBUSY;

and every open file is on that list (nxffs_open.c).  The descriptor used to
issue the command is itself such a file, so the check can never pass and
FIOC_REFORMAT is unreachable through the only interface that exposes it.

Add an optional ioctldir method to struct mountpt_operations, reached by
issuing the ioctl on a descriptor for the mountpoint directory:

    fd = open("/mnt/nxffs", O_RDONLY | O_DIRECTORY);
    ioctl(fd, FIOC_REFORMAT, 0);

It takes the same (mountpt, dir) pair as opendir/readdir/rewinddir, so it
reads as a member of the directory-operations family; the file system
recovers the volume from the mountpoint inode and may ignore dir.  The
member is placed at the end of the structure rather than beside the other
directory operations on purpose: every file system initialises
mountpt_operations positionally, so a member inserted mid-structure would
force all of them to add a slot for a method they do not implement.
Appending keeps the change to one file system.

dir_ioctl() gives that method the first chance at every command when the
directory belongs to a mounted volume and the file system provides one, and
falls back to its own handling of FIOC_FILEPATH and BIOC_FLUSH when the file
system answers -ENOTTY.  Trying the file system first is what lets a file
system override a command the VFS would otherwise answer generically; the
-ENOTTY fallback is what keeps the generic answers available to everyone
else.  A file system that leaves the method NULL is unaffected: the VFS
answers exactly as before.

The existing per-file method could not simply be reused for this.  It takes
a struct file, and every implementation that has an ioctl -- fat, romfs,
tmpfs, spiffs among them -- asserts on filep->f_priv and dereferences it,
so handing it a directory descriptor with no open file behind it would
fault.  Making the entry point separate keeps that contract intact and
makes support explicit rather than assumed.

nxffs implements it, which is what makes its FIOC_REFORMAT reachable.  The
per-file path is left in place and both share one implementation, so
nothing that works today stops working.  spiffs, which has the same shape
of volume commands, can follow.

Measured on sim:nxffs, with one file written to the volume and then the
same sequence of ioctls issued on a file descriptor, on a descriptor for the
mountpoint directory, and on a descriptor for a pseudo file system directory.
Before:

    FIOC_REFORMAT via file fd:  ret=-1 errno=16 (EBUSY, as expected)
    FIOC_REFORMAT via dir fd:   ret=-1 errno=25
    FIOC_FILEPATH via dir fd:   ret=0  "/mnt/nxffs//"
    BIOC_FLUSH    via dir fd:   ret=0
    bogus cmd     via dir fd:   ret=-1 errno=25
    FIOC_FILEPATH via /dev fd:  ret=0  "/dev//"
    bogus cmd     via /dev fd:  ret=-1 errno=25
    name still in the raw MTD image afterwards: yes

After:

    FIOC_REFORMAT via file fd:  ret=-1 errno=16 (EBUSY, as expected)
    FIOC_REFORMAT via dir fd:   ret=0
    FIOC_FILEPATH via dir fd:   ret=0  "/mnt/nxffs//"
    BIOC_FLUSH    via dir fd:   ret=0
    bogus cmd     via dir fd:   ret=-1 errno=25
    FIOC_FILEPATH via /dev fd:  ret=0  "/dev//"
    bogus cmd     via /dev fd:  ret=-1 errno=25
    name still in the raw MTD image afterwards: no

Only the FIOC_REFORMAT line on the directory descriptor changes, and the raw
MTD image confirms the volume really was erased.  FIOC_FILEPATH and
BIOC_FLUSH on a directory still answer even though nxffs is now consulted
ahead of them, an unrecognised command is still refused rather than
forwarded blindly, and a directory in the pseudo file system, which has no
ioctldir at all, is untouched.

Assisted-by: Claude Code:claude-opus-4-8
Assisted-by: Claude Code:claude-fable-5
Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-07-25 02:04:34 +02:00
..
1wire 1wire: Move onewire_valid_rom to 1wire_crc.h 2026-06-26 22:50:43 +08:00
aie
analog !arm/stm32l4: standardize public API/type prefix to stm32_ 2026-06-13 12:45:16 +08:00
audio drivers/audio/i2s: Fix unsigned integers in function signatures 2026-07-05 15:06:04 +08:00
binfmt binfmt: Add a configuration flag to store the module filename 2025-11-01 22:59:47 +08:00
can sja1000: replace enter_critical_section with spinlock 2026-01-08 09:15:04 -03:00
clk drivers/clk: use uintptr_t for register addresses 2026-06-18 21:52:33 +08:00
contactless
coresight style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
crypto drivers/crypto: add Microchip RNG90 driver 2026-06-14 18:41:09 +08:00
dma
drivers serial/uart_rpmsg: add _raw version of driver 2026-02-23 09:19:57 -03:00
eeprom mtd/at25ee: Use eeprom/spi_xx25xx internally 2025-12-17 19:03:54 +01:00
efuse
fs fs/vfs: Add ioctldir for volume ioctls via the mountpoint directory. 2026-07-25 02:04:34 +02:00
himem
hwspinlock
i2c drivers/i2c: add ioexpander-based lower-half implementation for I2C bit-bang 2026-01-01 17:08:47 +08:00
i3c style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
input drivers/mpr121: Add support to MPR121 Capacitive Keypad 2026-04-23 15:56:32 -03:00
ioexpander ioexpander/iso1i813t: add option to check errors during read 2026-03-18 15:00:48 -03:00
lcd style: Fix "the the" typo across the codebase. 2026-03-23 11:07:49 +01:00
leds !drivers/pwm: remove PWM_MULTICHAN option 2026-05-18 11:35:25 -04:00
lib lib/math32: Avoid __uint128_t casts for LDC ImportC 2026-07-21 17:11:03 -03:00
math drivers/math: use small lock to replace enter_critical_section 2026-01-08 11:17:17 +08:00
mbox
mm protect: move us_heap to userspace_data_s 2026-02-02 11:06:53 +08:00
modem style: fix checkpatch issues after debug.h move 2026-04-07 07:50:06 -03:00
motor style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
mtd drivers/mtd/gd25: add QSPI support 2026-06-21 09:43:29 -03:00
net boards/mips: Add networking support to CI20 board 2026-07-17 16:14:14 -03:00
note note/ram: support multiple noterams to dump data when panic occurs 2026-01-24 19:33:17 +08:00
nx nuttx/nx: compilation error occurs 2026-04-14 13:35:26 +08:00
pci drivers/pci:write legacy num to config space when enable legacy irq 2026-01-30 12:50:42 +08:00
pinctrl
power style: Fix "the the" typo across the codebase. 2026-03-23 11:07:49 +01:00
rc style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
regmap
reset style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
rf
rpmsg drivers/rpmsg: use NuttX atomic_t API instead of C11 atomics 2026-05-21 06:28:36 +08:00
rptun rptun: add configuring the stack of rptun as static 2026-01-19 14:18:27 +08:00
segger
sensors drivers/sensors: Add MPU6050 6-axis IMU uORB driver 2026-07-09 09:33:15 -03:00
serial drivers/serial: add job-control TTY ioctls and libc wrappers 2026-06-23 16:26:53 -03:00
spi stm32h5/qspi: add QSPIMEM_QUADDATA flag for 1-1-4 transfers 2026-06-21 09:43:29 -03:00
syslog driver/ramlog: Implement the rate limiting function for ramlog driver. 2026-01-27 03:17:05 +08:00
timers drivers/watchdog: fix capture automonitor notifier context 2026-07-17 14:59:47 +08:00
usb drivers/usbhost/usbhost_cdcecm.c: Added support for Host CDC-ECM 2026-05-06 06:20:03 +08:00
usrsock
vhost drivers/vhost: add vhost_get_vq_buffers() to collect scatter-gather buffers 2026-02-04 02:32:02 +08:00
video video/fb: fix compilation errors 2026-04-13 19:55:44 +08:00
virtio include/nuttx/virtio: allow common virtio helpers to be used by vhost 2026-02-04 02:32:02 +08:00
wireless wireless/cc1101: Add MSK/4-FSK, dynamic PATABLE ramping, and fix IOCTL safety 2026-03-11 16:05:19 +01:00
.gitignore
addrenv.h addrenv: support addrenv when mpu is used 2026-01-26 16:27:19 +08:00
allsyms.h
arch.h style: Fix "the the" typo across the codebase. 2026-03-23 11:07:49 +01:00
ascii.h
atexit.h
atomic.h include/nuttx/atomic.h: fix C++ definition conflicts 2025-12-22 15:27:39 +08:00
bits.h
board.h drivers/usbhost/usbhost_enumerate.c: Allow selecting USB configuration 2026-05-06 06:20:03 +08:00
cache.h nuttx/cache.h: fix the compile warning in sim when enable OpenAMP 2025-12-31 02:36:29 +08:00
can.h drivers/can: move CAN utils to CAN common files 2025-05-14 10:30:25 -03:00
cancelpt.h sched/cancelpt: Fix MISRA C 2012 Rule 10.4 violations 2026-02-02 21:09:40 +08:00
circbuf.h lib/circbuf: add static initialize macro helper 2024-12-17 20:48:23 +08:00
clock.h !sys/types.h: change time_t and clock_t to int64_t to align with other OSes 2026-05-19 16:21:28 +08:00
clock_notifier.h fs/timerfd: implement TFD_TIMER_CANCEL_ON_SET to detect clock changes 2026-01-30 17:20:24 +08:00
compiler.h float.h: improve long double related definitions 2026-07-02 09:02:21 -03:00
coredump.h coredump: fix issue that nvic region overlapped by board memory region 2025-01-24 09:15:56 +08:00
crc8.h libs/crc: implement AUTOSAR-compatible CRC algorithm 2026-01-30 17:32:15 +08:00
crc16.h libs/crc: implement AUTOSAR-compatible CRC algorithm 2026-01-30 17:32:15 +08:00
crc32.h libc/crc32: add IEEE-compatible crc32_ieee for Linux/zlib interop 2026-07-03 10:18:28 +08:00
crc64.h !compiler: drop CONFIG_HAVE_LONG_LONG and require long long support 2026-05-19 16:21:28 +08:00
debug.h include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
elf.h
environ.h
envpath.h
ethtool.h
event.h [!] sched/event: Remove wait object dependency from event implementation 2025-10-31 19:56:32 -03:00
fdcheck.h
fdt.h qemu/armv7a: register cfi flash 2025-02-11 17:23:44 +08:00
gdbstub.h gdbstub: change send buffer to const char 2025-01-20 20:07:13 +08:00
hashtable.h
hrtimer.h sched/hrtimer: Update the comments. 2026-02-02 13:26:22 +08:00
idr.h
init.h sched: add trace points during system startup and board initialization 2026-01-27 03:18:11 +08:00
instrument.h style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
ipcc.h style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
irq.h sched/irq: Consolidate IRQ bounds checking into IRQ_TO_NDX macro 2026-01-28 13:35:30 +08:00
kmalloc.h
kthread.h
lin.h LIN:adjust the LIN flag 2026-01-08 23:15:31 +08:00
lirc.h
list.h list: Fix the list conflicts. 2026-01-19 14:12:09 +08:00
list_type.h list: Fix the list conflicts. 2026-01-19 14:12:09 +08:00
macro.h macro: use portable variadic macros 2026-01-22 22:14:00 +08:00
memoryregion.h
mmcsd.h
module.h libc/elf: rename modlib to libelf 2025-04-11 09:43:22 +08:00
mqueue.h !sys/types.h: change time_t and clock_t to int64_t to align with other OSes 2026-05-19 16:21:28 +08:00
mutex.h sched/pthread: move pthread mutex from syscall to user-space 2026-01-22 12:40:49 -03:00
notifier.h include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
nuttx.h macro/align: Fix ALIGN_UP and ALIGN_DOWN 2025-01-11 12:13:10 +08:00
page.h style: Fix "is is" typo across the codebase. 2026-03-24 09:39:26 +08:00
panic_notifier.h
pgalloc.h mm/gran: add gran_alloc_align API 2025-05-12 15:01:37 +08:00
progmem.h
pthread.h pthread: move pthread_cond to userspace 2026-01-26 16:26:39 +08:00
queue.h
random.h
reboot_notifier.h
rwsem.h sched/sem_rw.c: Add downgrade_write API for sem_rw 2026-01-07 22:47:09 +08:00
sched.h arch, sched/signal: Fix compilation with ENABLE_PARTIAL_SIGNALS=y 2026-06-16 17:07:32 +08:00
sched_note.h note: add NOTE_DUMP_BINARY support for binary log dumping 2026-01-27 21:56:03 +08:00
scsi.h style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
sdio.h arch/arm/src/stm32{h7,f7,l4}: add 4-bit wide bus support for MMC/eMMC cards 2026-07-21 08:51:38 -03:00
sdio_slave.h style: fix spelling in code comments and strings 2025-05-23 10:48:41 +08:00
semaphore.h include/nuttx/semaphore.h: parenthesize NXSEM helper args 2026-06-05 10:35:46 -04:00
seqlock.h seqlock: Fix struct name and constants. 2025-12-22 10:22:06 -03:00
signal.h sched/signal: Remove shadow definitions to reduce unnecessary API 2025-10-14 17:40:18 +08:00
spawn.h
spinlock.h sched/spinlock: Add time statistics in func enter_critical_section(). 2026-01-27 21:59:14 +08:00
spinlock_type.h seqlock: Fix struct name and constants. 2025-12-22 10:22:06 -03:00
streams.h libc/stream: Add support for lib_scanf 2025-06-20 09:48:39 +08:00
symtab.h
tee.h drivers/misc/optee: Expanded RPC support. 2025-08-06 02:29:33 +08:00
thermal.h drivers/thermal: Add support for passive trip point 2025-02-16 11:22:41 -03:00
tls.h pthread: remove tl_lock 2026-01-26 20:56:12 +08:00
trace.h trace: fix macro line continuation formatting 2026-01-25 10:45:26 -03:00
uorb.h drivers/sensors: add initial support for fixed-point data for sensors 2026-05-02 00:56:42 +08:00
userspace.h protect: move us_heap to userspace_data_s 2026-02-02 11:06:53 +08:00
vt100.h Documentation: nsh: document the top command 2026-07-11 09:15:15 -03:00
wdog.h drivers: Fix comment typos — 'Pubic' → 'Public' across drivers and headers. 2026-07-02 13:29:48 +08:00
wqueue.h !sys/types.h: change time_t and clock_t to int64_t to align with other OSes 2026-05-19 16:21:28 +08:00
zoneinfo.h