agheader.c 24.2 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0+
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * Copyright (C) 2017 Oracle.  All Rights Reserved.
 * Author: Darrick J. Wong <darrick.wong@oracle.com>
 */
#include "xfs.h"
#include "xfs_fs.h"
#include "xfs_shared.h"
#include "xfs_format.h"
#include "xfs_trans_resv.h"
#include "xfs_mount.h"
#include "xfs_defer.h"
#include "xfs_btree.h"
#include "xfs_bit.h"
#include "xfs_log_format.h"
#include "xfs_trans.h"
#include "xfs_sb.h"
#include "xfs_inode.h"
D
Darrick J. Wong 已提交
19
#include "xfs_alloc.h"
D
Darrick J. Wong 已提交
20
#include "xfs_ialloc.h"
21
#include "xfs_rmap.h"
22 23 24 25 26 27 28
#include "scrub/xfs_scrub.h"
#include "scrub/scrub.h"
#include "scrub/common.h"
#include "scrub/trace.h"

/* Superblock */

29 30
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
31
xchk_superblock_xref(
32
	struct xfs_scrub	*sc,
33
	struct xfs_buf		*bp)
34
{
35 36 37 38
	struct xfs_mount	*mp = sc->mp;
	xfs_agnumber_t		agno = sc->sm->sm_agno;
	xfs_agblock_t		agbno;
	int			error;
39

40 41
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
42 43 44

	agbno = XFS_SB_BLOCK(mp);

D
Darrick J. Wong 已提交
45 46
	error = xchk_ag_init(sc, agno, &sc->sa);
	if (!xchk_xref_process_error(sc, agno, agbno, &error))
47 48
		return;

D
Darrick J. Wong 已提交
49 50
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
51
	xchk_xref_is_owned_by(sc, agbno, 1, &XFS_RMAP_OINFO_FS);
D
Darrick J. Wong 已提交
52
	xchk_xref_is_not_shared(sc, agbno, 1);
53 54

	/* scrub teardown will take care of sc->sa for us */
55 56
}

57 58 59 60 61 62 63 64 65
/*
 * Scrub the filesystem superblock.
 *
 * Note: We do /not/ attempt to check AG 0's superblock.  Mount is
 * responsible for validating all the geometry information in sb 0, so
 * if the filesystem is capable of initiating online scrub, then clearly
 * sb 0 is ok and we can use its information to check everything else.
 */
int
D
Darrick J. Wong 已提交
66
xchk_superblock(
67
	struct xfs_scrub	*sc)
68
{
69 70 71 72 73 74 75 76
	struct xfs_mount	*mp = sc->mp;
	struct xfs_buf		*bp;
	struct xfs_dsb		*sb;
	xfs_agnumber_t		agno;
	uint32_t		v2_ok;
	__be32			features_mask;
	int			error;
	__be16			vernum_mask;
77 78 79 80 81

	agno = sc->sm->sm_agno;
	if (agno == 0)
		return 0;

82
	error = xfs_sb_read_secondary(mp, sc->tp, agno, &bp);
83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98
	/*
	 * The superblock verifier can return several different error codes
	 * if it thinks the superblock doesn't look right.  For a mount these
	 * would all get bounced back to userspace, but if we're here then the
	 * fs mounted successfully, which means that this secondary superblock
	 * is simply incorrect.  Treat all these codes the same way we treat
	 * any corruption.
	 */
	switch (error) {
	case -EINVAL:	/* also -EWRONGFS */
	case -ENOSYS:
	case -EFBIG:
		error = -EFSCORRUPTED;
	default:
		break;
	}
D
Darrick J. Wong 已提交
99
	if (!xchk_process_error(sc, agno, XFS_SB_BLOCK(mp), &error))
100 101 102 103 104 105 106 107 108 109 110
		return error;

	sb = XFS_BUF_TO_SBP(bp);

	/*
	 * Verify the geometries match.  Fields that are permanently
	 * set by mkfs are checked; fields that can be updated later
	 * (and are not propagated to backup superblocks) are preen
	 * checked.
	 */
	if (sb->sb_blocksize != cpu_to_be32(mp->m_sb.sb_blocksize))
D
Darrick J. Wong 已提交
111
		xchk_block_set_corrupt(sc, bp);
112 113

	if (sb->sb_dblocks != cpu_to_be64(mp->m_sb.sb_dblocks))
D
Darrick J. Wong 已提交
114
		xchk_block_set_corrupt(sc, bp);
115 116

	if (sb->sb_rblocks != cpu_to_be64(mp->m_sb.sb_rblocks))
D
Darrick J. Wong 已提交
117
		xchk_block_set_corrupt(sc, bp);
118 119

	if (sb->sb_rextents != cpu_to_be64(mp->m_sb.sb_rextents))
D
Darrick J. Wong 已提交
120
		xchk_block_set_corrupt(sc, bp);
121 122

	if (!uuid_equal(&sb->sb_uuid, &mp->m_sb.sb_uuid))
D
Darrick J. Wong 已提交
123
		xchk_block_set_preen(sc, bp);
124 125

	if (sb->sb_logstart != cpu_to_be64(mp->m_sb.sb_logstart))
D
Darrick J. Wong 已提交
126
		xchk_block_set_corrupt(sc, bp);
127 128

	if (sb->sb_rootino != cpu_to_be64(mp->m_sb.sb_rootino))
D
Darrick J. Wong 已提交
129
		xchk_block_set_preen(sc, bp);
130 131

	if (sb->sb_rbmino != cpu_to_be64(mp->m_sb.sb_rbmino))
D
Darrick J. Wong 已提交
132
		xchk_block_set_preen(sc, bp);
133 134

	if (sb->sb_rsumino != cpu_to_be64(mp->m_sb.sb_rsumino))
D
Darrick J. Wong 已提交
135
		xchk_block_set_preen(sc, bp);
136 137

	if (sb->sb_rextsize != cpu_to_be32(mp->m_sb.sb_rextsize))
D
Darrick J. Wong 已提交
138
		xchk_block_set_corrupt(sc, bp);
139 140

	if (sb->sb_agblocks != cpu_to_be32(mp->m_sb.sb_agblocks))
D
Darrick J. Wong 已提交
141
		xchk_block_set_corrupt(sc, bp);
142 143

	if (sb->sb_agcount != cpu_to_be32(mp->m_sb.sb_agcount))
D
Darrick J. Wong 已提交
144
		xchk_block_set_corrupt(sc, bp);
145 146

	if (sb->sb_rbmblocks != cpu_to_be32(mp->m_sb.sb_rbmblocks))
D
Darrick J. Wong 已提交
147
		xchk_block_set_corrupt(sc, bp);
148 149

	if (sb->sb_logblocks != cpu_to_be32(mp->m_sb.sb_logblocks))
D
Darrick J. Wong 已提交
150
		xchk_block_set_corrupt(sc, bp);
151 152 153 154 155 156 157 158 159 160 161 162 163

	/* Check sb_versionnum bits that are set at mkfs time. */
	vernum_mask = cpu_to_be16(~XFS_SB_VERSION_OKBITS |
				  XFS_SB_VERSION_NUMBITS |
				  XFS_SB_VERSION_ALIGNBIT |
				  XFS_SB_VERSION_DALIGNBIT |
				  XFS_SB_VERSION_SHAREDBIT |
				  XFS_SB_VERSION_LOGV2BIT |
				  XFS_SB_VERSION_SECTORBIT |
				  XFS_SB_VERSION_EXTFLGBIT |
				  XFS_SB_VERSION_DIRV2BIT);
	if ((sb->sb_versionnum & vernum_mask) !=
	    (cpu_to_be16(mp->m_sb.sb_versionnum) & vernum_mask))
D
Darrick J. Wong 已提交
164
		xchk_block_set_corrupt(sc, bp);
165 166 167 168 169 170 171

	/* Check sb_versionnum bits that can be set after mkfs time. */
	vernum_mask = cpu_to_be16(XFS_SB_VERSION_ATTRBIT |
				  XFS_SB_VERSION_NLINKBIT |
				  XFS_SB_VERSION_QUOTABIT);
	if ((sb->sb_versionnum & vernum_mask) !=
	    (cpu_to_be16(mp->m_sb.sb_versionnum) & vernum_mask))
D
Darrick J. Wong 已提交
172
		xchk_block_set_preen(sc, bp);
173 174

	if (sb->sb_sectsize != cpu_to_be16(mp->m_sb.sb_sectsize))
D
Darrick J. Wong 已提交
175
		xchk_block_set_corrupt(sc, bp);
176 177

	if (sb->sb_inodesize != cpu_to_be16(mp->m_sb.sb_inodesize))
D
Darrick J. Wong 已提交
178
		xchk_block_set_corrupt(sc, bp);
179 180

	if (sb->sb_inopblock != cpu_to_be16(mp->m_sb.sb_inopblock))
D
Darrick J. Wong 已提交
181
		xchk_block_set_corrupt(sc, bp);
182 183

	if (memcmp(sb->sb_fname, mp->m_sb.sb_fname, sizeof(sb->sb_fname)))
D
Darrick J. Wong 已提交
184
		xchk_block_set_preen(sc, bp);
185 186

	if (sb->sb_blocklog != mp->m_sb.sb_blocklog)
D
Darrick J. Wong 已提交
187
		xchk_block_set_corrupt(sc, bp);
188 189

	if (sb->sb_sectlog != mp->m_sb.sb_sectlog)
D
Darrick J. Wong 已提交
190
		xchk_block_set_corrupt(sc, bp);
191 192

	if (sb->sb_inodelog != mp->m_sb.sb_inodelog)
D
Darrick J. Wong 已提交
193
		xchk_block_set_corrupt(sc, bp);
194 195

	if (sb->sb_inopblog != mp->m_sb.sb_inopblog)
D
Darrick J. Wong 已提交
196
		xchk_block_set_corrupt(sc, bp);
197 198

	if (sb->sb_agblklog != mp->m_sb.sb_agblklog)
D
Darrick J. Wong 已提交
199
		xchk_block_set_corrupt(sc, bp);
200 201

	if (sb->sb_rextslog != mp->m_sb.sb_rextslog)
D
Darrick J. Wong 已提交
202
		xchk_block_set_corrupt(sc, bp);
203 204

	if (sb->sb_imax_pct != mp->m_sb.sb_imax_pct)
D
Darrick J. Wong 已提交
205
		xchk_block_set_preen(sc, bp);
206 207 208 209 210 211 212

	/*
	 * Skip the summary counters since we track them in memory anyway.
	 * sb_icount, sb_ifree, sb_fdblocks, sb_frexents
	 */

	if (sb->sb_uquotino != cpu_to_be64(mp->m_sb.sb_uquotino))
D
Darrick J. Wong 已提交
213
		xchk_block_set_preen(sc, bp);
214 215

	if (sb->sb_gquotino != cpu_to_be64(mp->m_sb.sb_gquotino))
D
Darrick J. Wong 已提交
216
		xchk_block_set_preen(sc, bp);
217 218 219 220 221 222 223

	/*
	 * Skip the quota flags since repair will force quotacheck.
	 * sb_qflags
	 */

	if (sb->sb_flags != mp->m_sb.sb_flags)
D
Darrick J. Wong 已提交
224
		xchk_block_set_corrupt(sc, bp);
225 226

	if (sb->sb_shared_vn != mp->m_sb.sb_shared_vn)
D
Darrick J. Wong 已提交
227
		xchk_block_set_corrupt(sc, bp);
228 229

	if (sb->sb_inoalignmt != cpu_to_be32(mp->m_sb.sb_inoalignmt))
D
Darrick J. Wong 已提交
230
		xchk_block_set_corrupt(sc, bp);
231 232

	if (sb->sb_unit != cpu_to_be32(mp->m_sb.sb_unit))
D
Darrick J. Wong 已提交
233
		xchk_block_set_preen(sc, bp);
234 235

	if (sb->sb_width != cpu_to_be32(mp->m_sb.sb_width))
D
Darrick J. Wong 已提交
236
		xchk_block_set_preen(sc, bp);
237 238

	if (sb->sb_dirblklog != mp->m_sb.sb_dirblklog)
D
Darrick J. Wong 已提交
239
		xchk_block_set_corrupt(sc, bp);
240 241

	if (sb->sb_logsectlog != mp->m_sb.sb_logsectlog)
D
Darrick J. Wong 已提交
242
		xchk_block_set_corrupt(sc, bp);
243 244

	if (sb->sb_logsectsize != cpu_to_be16(mp->m_sb.sb_logsectsize))
D
Darrick J. Wong 已提交
245
		xchk_block_set_corrupt(sc, bp);
246 247

	if (sb->sb_logsunit != cpu_to_be32(mp->m_sb.sb_logsunit))
D
Darrick J. Wong 已提交
248
		xchk_block_set_corrupt(sc, bp);
249 250 251 252

	/* Do we see any invalid bits in sb_features2? */
	if (!xfs_sb_version_hasmorebits(&mp->m_sb)) {
		if (sb->sb_features2 != 0)
D
Darrick J. Wong 已提交
253
			xchk_block_set_corrupt(sc, bp);
254 255 256 257 258 259
	} else {
		v2_ok = XFS_SB_VERSION2_OKBITS;
		if (XFS_SB_VERSION_NUM(&mp->m_sb) >= XFS_SB_VERSION_5)
			v2_ok |= XFS_SB_VERSION2_CRCBIT;

		if (!!(sb->sb_features2 & cpu_to_be32(~v2_ok)))
D
Darrick J. Wong 已提交
260
			xchk_block_set_corrupt(sc, bp);
261 262

		if (sb->sb_features2 != sb->sb_bad_features2)
D
Darrick J. Wong 已提交
263
			xchk_block_set_preen(sc, bp);
264 265 266 267 268 269 270 271 272
	}

	/* Check sb_features2 flags that are set at mkfs time. */
	features_mask = cpu_to_be32(XFS_SB_VERSION2_LAZYSBCOUNTBIT |
				    XFS_SB_VERSION2_PROJID32BIT |
				    XFS_SB_VERSION2_CRCBIT |
				    XFS_SB_VERSION2_FTYPE);
	if ((sb->sb_features2 & features_mask) !=
	    (cpu_to_be32(mp->m_sb.sb_features2) & features_mask))
D
Darrick J. Wong 已提交
273
		xchk_block_set_corrupt(sc, bp);
274 275 276 277 278

	/* Check sb_features2 flags that can be set after mkfs time. */
	features_mask = cpu_to_be32(XFS_SB_VERSION2_ATTR2BIT);
	if ((sb->sb_features2 & features_mask) !=
	    (cpu_to_be32(mp->m_sb.sb_features2) & features_mask))
D
Darrick J. Wong 已提交
279
		xchk_block_set_corrupt(sc, bp);
280 281 282 283 284 285

	if (!xfs_sb_version_hascrc(&mp->m_sb)) {
		/* all v5 fields must be zero */
		if (memchr_inv(&sb->sb_features_compat, 0,
				sizeof(struct xfs_dsb) -
				offsetof(struct xfs_dsb, sb_features_compat)))
D
Darrick J. Wong 已提交
286
			xchk_block_set_corrupt(sc, bp);
287 288 289 290 291
	} else {
		/* Check compat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_COMPAT_UNKNOWN);
		if ((sb->sb_features_compat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_compat) & features_mask))
D
Darrick J. Wong 已提交
292
			xchk_block_set_corrupt(sc, bp);
293 294 295 296 297 298 299 300 301

		/* Check ro compat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_RO_COMPAT_UNKNOWN |
					    XFS_SB_FEAT_RO_COMPAT_FINOBT |
					    XFS_SB_FEAT_RO_COMPAT_RMAPBT |
					    XFS_SB_FEAT_RO_COMPAT_REFLINK);
		if ((sb->sb_features_ro_compat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_ro_compat) &
		     features_mask))
D
Darrick J. Wong 已提交
302
			xchk_block_set_corrupt(sc, bp);
303 304 305 306 307 308 309 310 311

		/* Check incompat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_INCOMPAT_UNKNOWN |
					    XFS_SB_FEAT_INCOMPAT_FTYPE |
					    XFS_SB_FEAT_INCOMPAT_SPINODES |
					    XFS_SB_FEAT_INCOMPAT_META_UUID);
		if ((sb->sb_features_incompat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_incompat) &
		     features_mask))
D
Darrick J. Wong 已提交
312
			xchk_block_set_corrupt(sc, bp);
313 314 315 316 317 318

		/* Check log incompat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_INCOMPAT_LOG_UNKNOWN);
		if ((sb->sb_features_log_incompat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_log_incompat) &
		     features_mask))
D
Darrick J. Wong 已提交
319
			xchk_block_set_corrupt(sc, bp);
320 321 322 323

		/* Don't care about sb_crc */

		if (sb->sb_spino_align != cpu_to_be32(mp->m_sb.sb_spino_align))
D
Darrick J. Wong 已提交
324
			xchk_block_set_corrupt(sc, bp);
325 326

		if (sb->sb_pquotino != cpu_to_be64(mp->m_sb.sb_pquotino))
D
Darrick J. Wong 已提交
327
			xchk_block_set_preen(sc, bp);
328 329 330 331 332 333 334

		/* Don't care about sb_lsn */
	}

	if (xfs_sb_version_hasmetauuid(&mp->m_sb)) {
		/* The metadata UUID must be the same for all supers */
		if (!uuid_equal(&sb->sb_meta_uuid, &mp->m_sb.sb_meta_uuid))
D
Darrick J. Wong 已提交
335
			xchk_block_set_corrupt(sc, bp);
336 337 338 339 340
	}

	/* Everything else must be zero. */
	if (memchr_inv(sb + 1, 0,
			BBTOB(bp->b_length) - sizeof(struct xfs_dsb)))
D
Darrick J. Wong 已提交
341
		xchk_block_set_corrupt(sc, bp);
342

D
Darrick J. Wong 已提交
343
	xchk_superblock_xref(sc, bp);
344

345 346
	return error;
}
D
Darrick J. Wong 已提交
347 348 349

/* AGF */

350 351
/* Tally freespace record lengths. */
STATIC int
D
Darrick J. Wong 已提交
352
xchk_agf_record_bno_lengths(
353 354 355 356 357 358 359 360 361 362 363 364
	struct xfs_btree_cur		*cur,
	struct xfs_alloc_rec_incore	*rec,
	void				*priv)
{
	xfs_extlen_t			*blocks = priv;

	(*blocks) += rec->ar_blockcount;
	return 0;
}

/* Check agf_freeblks */
static inline void
D
Darrick J. Wong 已提交
365
xchk_agf_xref_freeblks(
366
	struct xfs_scrub	*sc)
367
{
368 369 370
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_extlen_t		blocks = 0;
	int			error;
371 372 373 374 375

	if (!sc->sa.bno_cur)
		return;

	error = xfs_alloc_query_all(sc->sa.bno_cur,
D
Darrick J. Wong 已提交
376 377
			xchk_agf_record_bno_lengths, &blocks);
	if (!xchk_should_check_xref(sc, &error, &sc->sa.bno_cur))
378 379
		return;
	if (blocks != be32_to_cpu(agf->agf_freeblks))
D
Darrick J. Wong 已提交
380
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
381 382
}

383 384
/* Cross reference the AGF with the cntbt (freespace by length btree) */
static inline void
D
Darrick J. Wong 已提交
385
xchk_agf_xref_cntbt(
386
	struct xfs_scrub	*sc)
387
{
388 389 390 391 392
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_agblock_t		agbno;
	xfs_extlen_t		blocks;
	int			have;
	int			error;
393 394 395 396 397 398

	if (!sc->sa.cnt_cur)
		return;

	/* Any freespace at all? */
	error = xfs_alloc_lookup_le(sc->sa.cnt_cur, 0, -1U, &have);
D
Darrick J. Wong 已提交
399
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
400 401
		return;
	if (!have) {
402
		if (agf->agf_freeblks != cpu_to_be32(0))
D
Darrick J. Wong 已提交
403
			xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
404 405 406 407 408
		return;
	}

	/* Check agf_longest */
	error = xfs_alloc_get_rec(sc->sa.cnt_cur, &agbno, &blocks, &have);
D
Darrick J. Wong 已提交
409
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
410 411
		return;
	if (!have || blocks != be32_to_cpu(agf->agf_longest))
D
Darrick J. Wong 已提交
412
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
413 414
}

415 416
/* Check the btree block counts in the AGF against the btrees. */
STATIC void
D
Darrick J. Wong 已提交
417
xchk_agf_xref_btreeblks(
418
	struct xfs_scrub	*sc)
419
{
420 421 422 423 424
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		blocks;
	xfs_agblock_t		btreeblks;
	int			error;
425 426 427 428

	/* Check agf_rmap_blocks; set up for agf_btreeblks check */
	if (sc->sa.rmap_cur) {
		error = xfs_btree_count_blocks(sc->sa.rmap_cur, &blocks);
D
Darrick J. Wong 已提交
429
		if (!xchk_should_check_xref(sc, &error, &sc->sa.rmap_cur))
430 431 432
			return;
		btreeblks = blocks - 1;
		if (blocks != be32_to_cpu(agf->agf_rmap_blocks))
D
Darrick J. Wong 已提交
433
			xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
434 435 436 437 438 439 440 441 442 443 444 445 446 447
	} else {
		btreeblks = 0;
	}

	/*
	 * No rmap cursor; we can't xref if we have the rmapbt feature.
	 * We also can't do it if we're missing the free space btree cursors.
	 */
	if ((xfs_sb_version_hasrmapbt(&mp->m_sb) && !sc->sa.rmap_cur) ||
	    !sc->sa.bno_cur || !sc->sa.cnt_cur)
		return;

	/* Check agf_btreeblks */
	error = xfs_btree_count_blocks(sc->sa.bno_cur, &blocks);
D
Darrick J. Wong 已提交
448
	if (!xchk_should_check_xref(sc, &error, &sc->sa.bno_cur))
449 450 451 452
		return;
	btreeblks += blocks - 1;

	error = xfs_btree_count_blocks(sc->sa.cnt_cur, &blocks);
D
Darrick J. Wong 已提交
453
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
454 455 456 457
		return;
	btreeblks += blocks - 1;

	if (btreeblks != be32_to_cpu(agf->agf_btreeblks))
D
Darrick J. Wong 已提交
458
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
459 460
}

461 462
/* Check agf_refcount_blocks against tree size */
static inline void
D
Darrick J. Wong 已提交
463
xchk_agf_xref_refcblks(
464
	struct xfs_scrub	*sc)
465
{
466 467 468
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_agblock_t		blocks;
	int			error;
469 470 471 472 473

	if (!sc->sa.refc_cur)
		return;

	error = xfs_btree_count_blocks(sc->sa.refc_cur, &blocks);
D
Darrick J. Wong 已提交
474
	if (!xchk_should_check_xref(sc, &error, &sc->sa.refc_cur))
475 476
		return;
	if (blocks != be32_to_cpu(agf->agf_refcount_blocks))
D
Darrick J. Wong 已提交
477
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
478 479
}

480 481
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
482
xchk_agf_xref(
483
	struct xfs_scrub	*sc)
484
{
485 486 487
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
488

489 490
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
491 492 493

	agbno = XFS_AGF_BLOCK(mp);

D
Darrick J. Wong 已提交
494
	error = xchk_ag_btcur_init(sc, &sc->sa);
495 496 497
	if (error)
		return;

D
Darrick J. Wong 已提交
498 499 500 501
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_agf_xref_freeblks(sc);
	xchk_agf_xref_cntbt(sc);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
502
	xchk_xref_is_owned_by(sc, agbno, 1, &XFS_RMAP_OINFO_FS);
D
Darrick J. Wong 已提交
503 504 505
	xchk_agf_xref_btreeblks(sc);
	xchk_xref_is_not_shared(sc, agbno, 1);
	xchk_agf_xref_refcblks(sc);
506 507

	/* scrub teardown will take care of sc->sa for us */
508 509
}

D
Darrick J. Wong 已提交
510 511
/* Scrub the AGF. */
int
D
Darrick J. Wong 已提交
512
xchk_agf(
513
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
514
{
515 516
	struct xfs_mount	*mp = sc->mp;
	struct xfs_agf		*agf;
517
	struct xfs_perag	*pag;
518 519 520 521 522 523 524 525 526
	xfs_agnumber_t		agno;
	xfs_agblock_t		agbno;
	xfs_agblock_t		eoag;
	xfs_agblock_t		agfl_first;
	xfs_agblock_t		agfl_last;
	xfs_agblock_t		agfl_count;
	xfs_agblock_t		fl_count;
	int			level;
	int			error = 0;
D
Darrick J. Wong 已提交
527 528

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
529
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
530
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
531
	if (!xchk_process_error(sc, agno, XFS_AGF_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
532
		goto out;
D
Darrick J. Wong 已提交
533
	xchk_buffer_recheck(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
534 535 536 537 538 539

	agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);

	/* Check the AG length */
	eoag = be32_to_cpu(agf->agf_length);
	if (eoag != xfs_ag_block_count(mp, agno))
D
Darrick J. Wong 已提交
540
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
541 542 543 544

	/* Check the AGF btree roots and levels */
	agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_BNO]);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
545
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
546 547 548

	agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_CNT]);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
549
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
550 551 552

	level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_BNO]);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
553
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
554 555 556

	level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_CNT]);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
557
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
558 559 560 561

	if (xfs_sb_version_hasrmapbt(&mp->m_sb)) {
		agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_RMAP]);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
562
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
563 564 565

		level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_RMAP]);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
566
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
567 568 569 570 571
	}

	if (xfs_sb_version_hasreflink(&mp->m_sb)) {
		agbno = be32_to_cpu(agf->agf_refcount_root);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
572
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
573 574 575

		level = be32_to_cpu(agf->agf_refcount_level);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
576
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
577 578 579 580 581 582 583 584 585
	}

	/* Check the AGFL counters */
	agfl_first = be32_to_cpu(agf->agf_flfirst);
	agfl_last = be32_to_cpu(agf->agf_fllast);
	agfl_count = be32_to_cpu(agf->agf_flcount);
	if (agfl_last > agfl_first)
		fl_count = agfl_last - agfl_first + 1;
	else
586
		fl_count = xfs_agfl_size(mp) - agfl_first + agfl_last + 1;
D
Darrick J. Wong 已提交
587
	if (agfl_count != 0 && fl_count != agfl_count)
D
Darrick J. Wong 已提交
588
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
589

590 591 592 593 594 595 596 597 598 599
	/* Do the incore counters match? */
	pag = xfs_perag_get(mp, agno);
	if (pag->pagf_freeblks != be32_to_cpu(agf->agf_freeblks))
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
	if (pag->pagf_flcount != be32_to_cpu(agf->agf_flcount))
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
	if (pag->pagf_btreeblks != be32_to_cpu(agf->agf_btreeblks))
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
	xfs_perag_put(pag);

D
Darrick J. Wong 已提交
600
	xchk_agf_xref(sc);
D
Darrick J. Wong 已提交
601 602 603 604 605 606
out:
	return error;
}

/* AGFL */

D
Darrick J. Wong 已提交
607
struct xchk_agfl_info {
608 609 610
	unsigned int		sz_entries;
	unsigned int		nr_entries;
	xfs_agblock_t		*entries;
611
	struct xfs_scrub	*sc;
612 613
};

614 615
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
616
xchk_agfl_block_xref(
617
	struct xfs_scrub	*sc,
618
	xfs_agblock_t		agbno)
619 620 621
{
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
622

D
Darrick J. Wong 已提交
623 624
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
625
	xchk_xref_is_owned_by(sc, agbno, 1, &XFS_RMAP_OINFO_AG);
D
Darrick J. Wong 已提交
626
	xchk_xref_is_not_shared(sc, agbno, 1);
627 628
}

D
Darrick J. Wong 已提交
629 630
/* Scrub an AGFL block. */
STATIC int
D
Darrick J. Wong 已提交
631
xchk_agfl_block(
632 633 634
	struct xfs_mount	*mp,
	xfs_agblock_t		agbno,
	void			*priv)
D
Darrick J. Wong 已提交
635
{
636
	struct xchk_agfl_info	*sai = priv;
637
	struct xfs_scrub	*sc = sai->sc;
638
	xfs_agnumber_t		agno = sc->sa.agno;
D
Darrick J. Wong 已提交
639

640 641 642 643
	if (xfs_verify_agbno(mp, agno, agbno) &&
	    sai->nr_entries < sai->sz_entries)
		sai->entries[sai->nr_entries++] = agbno;
	else
D
Darrick J. Wong 已提交
644
		xchk_block_set_corrupt(sc, sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
645

646
	xchk_agfl_block_xref(sc, agbno);
647

648 649 650
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return XFS_BTREE_QUERY_RANGE_ABORT;

D
Darrick J. Wong 已提交
651 652 653
	return 0;
}

654
static int
D
Darrick J. Wong 已提交
655
xchk_agblock_cmp(
656 657 658 659 660 661 662 663 664
	const void		*pa,
	const void		*pb)
{
	const xfs_agblock_t	*a = pa;
	const xfs_agblock_t	*b = pb;

	return (int)*a - (int)*b;
}

665 666
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
667
xchk_agfl_xref(
668
	struct xfs_scrub	*sc)
669
{
670 671 672
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
673

674 675
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
676 677 678

	agbno = XFS_AGFL_BLOCK(mp);

D
Darrick J. Wong 已提交
679
	error = xchk_ag_btcur_init(sc, &sc->sa);
680 681 682
	if (error)
		return;

D
Darrick J. Wong 已提交
683 684
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
685
	xchk_xref_is_owned_by(sc, agbno, 1, &XFS_RMAP_OINFO_FS);
D
Darrick J. Wong 已提交
686
	xchk_xref_is_not_shared(sc, agbno, 1);
687 688 689 690 691

	/*
	 * Scrub teardown will take care of sc->sa for us.  Leave sc->sa
	 * active so that the agfl block xref can use it too.
	 */
692 693
}

D
Darrick J. Wong 已提交
694 695
/* Scrub the AGFL. */
int
D
Darrick J. Wong 已提交
696
xchk_agfl(
697
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
698
{
699 700 701 702 703 704
	struct xchk_agfl_info	sai;
	struct xfs_agf		*agf;
	xfs_agnumber_t		agno;
	unsigned int		agflcount;
	unsigned int		i;
	int			error;
D
Darrick J. Wong 已提交
705 706

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
707
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
708
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
709
	if (!xchk_process_error(sc, agno, XFS_AGFL_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
710 711 712
		goto out;
	if (!sc->sa.agf_bp)
		return -EFSCORRUPTED;
D
Darrick J. Wong 已提交
713
	xchk_buffer_recheck(sc, sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
714

D
Darrick J. Wong 已提交
715
	xchk_agfl_xref(sc);
716 717 718 719

	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		goto out;

720 721 722
	/* Allocate buffer to ensure uniqueness of AGFL entries. */
	agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	agflcount = be32_to_cpu(agf->agf_flcount);
723
	if (agflcount > xfs_agfl_size(sc->mp)) {
D
Darrick J. Wong 已提交
724
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
725 726
		goto out;
	}
727
	memset(&sai, 0, sizeof(sai));
728
	sai.sc = sc;
729
	sai.sz_entries = agflcount;
730 731
	sai.entries = kmem_zalloc(sizeof(xfs_agblock_t) * agflcount,
			KM_MAYFAIL);
732 733 734 735 736
	if (!sai.entries) {
		error = -ENOMEM;
		goto out;
	}

D
Darrick J. Wong 已提交
737
	/* Check the blocks in the AGFL. */
738
	error = xfs_agfl_walk(sc->mp, XFS_BUF_TO_AGF(sc->sa.agf_bp),
D
Darrick J. Wong 已提交
739
			sc->sa.agfl_bp, xchk_agfl_block, &sai);
740 741 742 743
	if (error == XFS_BTREE_QUERY_RANGE_ABORT) {
		error = 0;
		goto out_free;
	}
744 745 746 747
	if (error)
		goto out_free;

	if (agflcount != sai.nr_entries) {
D
Darrick J. Wong 已提交
748
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
749 750 751 752 753
		goto out_free;
	}

	/* Sort entries, check for duplicates. */
	sort(sai.entries, sai.nr_entries, sizeof(sai.entries[0]),
D
Darrick J. Wong 已提交
754
			xchk_agblock_cmp, NULL);
755 756
	for (i = 1; i < sai.nr_entries; i++) {
		if (sai.entries[i] == sai.entries[i - 1]) {
D
Darrick J. Wong 已提交
757
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
758 759 760 761 762 763
			break;
		}
	}

out_free:
	kmem_free(sai.entries);
D
Darrick J. Wong 已提交
764 765 766
out:
	return error;
}
D
Darrick J. Wong 已提交
767 768 769

/* AGI */

770 771
/* Check agi_count/agi_freecount */
static inline void
D
Darrick J. Wong 已提交
772
xchk_agi_xref_icounts(
773
	struct xfs_scrub	*sc)
774
{
775 776 777 778
	struct xfs_agi		*agi = XFS_BUF_TO_AGI(sc->sa.agi_bp);
	xfs_agino_t		icount;
	xfs_agino_t		freecount;
	int			error;
779 780 781 782 783

	if (!sc->sa.ino_cur)
		return;

	error = xfs_ialloc_count_inodes(sc->sa.ino_cur, &icount, &freecount);
D
Darrick J. Wong 已提交
784
	if (!xchk_should_check_xref(sc, &error, &sc->sa.ino_cur))
785 786 787
		return;
	if (be32_to_cpu(agi->agi_count) != icount ||
	    be32_to_cpu(agi->agi_freecount) != freecount)
D
Darrick J. Wong 已提交
788
		xchk_block_xref_set_corrupt(sc, sc->sa.agi_bp);
789 790
}

791 792
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
793
xchk_agi_xref(
794
	struct xfs_scrub	*sc)
795
{
796 797 798
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
799

800 801
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
802 803 804

	agbno = XFS_AGI_BLOCK(mp);

D
Darrick J. Wong 已提交
805
	error = xchk_ag_btcur_init(sc, &sc->sa);
806 807 808
	if (error)
		return;

D
Darrick J. Wong 已提交
809 810 811
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
	xchk_agi_xref_icounts(sc);
812
	xchk_xref_is_owned_by(sc, agbno, 1, &XFS_RMAP_OINFO_FS);
D
Darrick J. Wong 已提交
813
	xchk_xref_is_not_shared(sc, agbno, 1);
814 815

	/* scrub teardown will take care of sc->sa for us */
816 817
}

D
Darrick J. Wong 已提交
818 819
/* Scrub the AGI. */
int
D
Darrick J. Wong 已提交
820
xchk_agi(
821
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
822
{
823 824
	struct xfs_mount	*mp = sc->mp;
	struct xfs_agi		*agi;
825
	struct xfs_perag	*pag;
826 827 828 829 830 831 832 833 834 835
	xfs_agnumber_t		agno;
	xfs_agblock_t		agbno;
	xfs_agblock_t		eoag;
	xfs_agino_t		agino;
	xfs_agino_t		first_agino;
	xfs_agino_t		last_agino;
	xfs_agino_t		icount;
	int			i;
	int			level;
	int			error = 0;
D
Darrick J. Wong 已提交
836 837

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
838
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
839
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
840
	if (!xchk_process_error(sc, agno, XFS_AGI_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
841
		goto out;
D
Darrick J. Wong 已提交
842
	xchk_buffer_recheck(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
843 844 845 846 847 848

	agi = XFS_BUF_TO_AGI(sc->sa.agi_bp);

	/* Check the AG length */
	eoag = be32_to_cpu(agi->agi_length);
	if (eoag != xfs_ag_block_count(mp, agno))
D
Darrick J. Wong 已提交
849
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
850 851 852 853

	/* Check btree roots and levels */
	agbno = be32_to_cpu(agi->agi_root);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
854
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
855 856 857

	level = be32_to_cpu(agi->agi_level);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
858
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
859 860 861 862

	if (xfs_sb_version_hasfinobt(&mp->m_sb)) {
		agbno = be32_to_cpu(agi->agi_free_root);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
863
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
864 865 866

		level = be32_to_cpu(agi->agi_free_level);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
867
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
868 869 870
	}

	/* Check inode counters */
871
	xfs_agino_range(mp, agno, &first_agino, &last_agino);
D
Darrick J. Wong 已提交
872 873 874
	icount = be32_to_cpu(agi->agi_count);
	if (icount > last_agino - first_agino + 1 ||
	    icount < be32_to_cpu(agi->agi_freecount))
D
Darrick J. Wong 已提交
875
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
876 877 878

	/* Check inode pointers */
	agino = be32_to_cpu(agi->agi_newino);
879
	if (!xfs_verify_agino_or_null(mp, agno, agino))
D
Darrick J. Wong 已提交
880
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
881 882

	agino = be32_to_cpu(agi->agi_dirino);
883
	if (!xfs_verify_agino_or_null(mp, agno, agino))
D
Darrick J. Wong 已提交
884
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
885 886 887 888

	/* Check unlinked inode buckets */
	for (i = 0; i < XFS_AGI_UNLINKED_BUCKETS; i++) {
		agino = be32_to_cpu(agi->agi_unlinked[i]);
889
		if (!xfs_verify_agino_or_null(mp, agno, agino))
D
Darrick J. Wong 已提交
890
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
891 892 893
	}

	if (agi->agi_pad32 != cpu_to_be32(0))
D
Darrick J. Wong 已提交
894
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
895

896 897 898 899 900 901 902 903
	/* Do the incore counters match? */
	pag = xfs_perag_get(mp, agno);
	if (pag->pagi_count != be32_to_cpu(agi->agi_count))
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
	if (pag->pagi_freecount != be32_to_cpu(agi->agi_freecount))
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
	xfs_perag_put(pag);

D
Darrick J. Wong 已提交
904
	xchk_agi_xref(sc);
D
Darrick J. Wong 已提交
905 906 907
out:
	return error;
}