agheader.c 23.9 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0+
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * Copyright (C) 2017 Oracle.  All Rights Reserved.
 * Author: Darrick J. Wong <darrick.wong@oracle.com>
 */
#include "xfs.h"
#include "xfs_fs.h"
#include "xfs_shared.h"
#include "xfs_format.h"
#include "xfs_trans_resv.h"
#include "xfs_mount.h"
#include "xfs_defer.h"
#include "xfs_btree.h"
#include "xfs_bit.h"
#include "xfs_log_format.h"
#include "xfs_trans.h"
#include "xfs_sb.h"
#include "xfs_inode.h"
D
Darrick J. Wong 已提交
19
#include "xfs_alloc.h"
D
Darrick J. Wong 已提交
20
#include "xfs_ialloc.h"
21
#include "xfs_rmap.h"
22 23 24 25 26 27 28
#include "scrub/xfs_scrub.h"
#include "scrub/scrub.h"
#include "scrub/common.h"
#include "scrub/trace.h"

/* Superblock */

29 30
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
31
xchk_superblock_xref(
32
	struct xfs_scrub	*sc,
33
	struct xfs_buf		*bp)
34
{
35 36 37 38 39
	struct xfs_owner_info	oinfo;
	struct xfs_mount	*mp = sc->mp;
	xfs_agnumber_t		agno = sc->sm->sm_agno;
	xfs_agblock_t		agbno;
	int			error;
40

41 42
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
43 44 45

	agbno = XFS_SB_BLOCK(mp);

D
Darrick J. Wong 已提交
46 47
	error = xchk_ag_init(sc, agno, &sc->sa);
	if (!xchk_xref_process_error(sc, agno, agbno, &error))
48 49
		return;

D
Darrick J. Wong 已提交
50 51
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
52
	xfs_rmap_ag_owner(&oinfo, XFS_RMAP_OWN_FS);
D
Darrick J. Wong 已提交
53 54
	xchk_xref_is_owned_by(sc, agbno, 1, &oinfo);
	xchk_xref_is_not_shared(sc, agbno, 1);
55 56

	/* scrub teardown will take care of sc->sa for us */
57 58
}

59 60 61 62 63 64 65 66 67
/*
 * Scrub the filesystem superblock.
 *
 * Note: We do /not/ attempt to check AG 0's superblock.  Mount is
 * responsible for validating all the geometry information in sb 0, so
 * if the filesystem is capable of initiating online scrub, then clearly
 * sb 0 is ok and we can use its information to check everything else.
 */
int
D
Darrick J. Wong 已提交
68
xchk_superblock(
69
	struct xfs_scrub	*sc)
70
{
71 72 73 74 75 76 77 78
	struct xfs_mount	*mp = sc->mp;
	struct xfs_buf		*bp;
	struct xfs_dsb		*sb;
	xfs_agnumber_t		agno;
	uint32_t		v2_ok;
	__be32			features_mask;
	int			error;
	__be16			vernum_mask;
79 80 81 82 83

	agno = sc->sm->sm_agno;
	if (agno == 0)
		return 0;

84
	error = xfs_sb_read_secondary(mp, sc->tp, agno, &bp);
85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
	/*
	 * The superblock verifier can return several different error codes
	 * if it thinks the superblock doesn't look right.  For a mount these
	 * would all get bounced back to userspace, but if we're here then the
	 * fs mounted successfully, which means that this secondary superblock
	 * is simply incorrect.  Treat all these codes the same way we treat
	 * any corruption.
	 */
	switch (error) {
	case -EINVAL:	/* also -EWRONGFS */
	case -ENOSYS:
	case -EFBIG:
		error = -EFSCORRUPTED;
	default:
		break;
	}
D
Darrick J. Wong 已提交
101
	if (!xchk_process_error(sc, agno, XFS_SB_BLOCK(mp), &error))
102 103 104 105 106 107 108 109 110 111 112
		return error;

	sb = XFS_BUF_TO_SBP(bp);

	/*
	 * Verify the geometries match.  Fields that are permanently
	 * set by mkfs are checked; fields that can be updated later
	 * (and are not propagated to backup superblocks) are preen
	 * checked.
	 */
	if (sb->sb_blocksize != cpu_to_be32(mp->m_sb.sb_blocksize))
D
Darrick J. Wong 已提交
113
		xchk_block_set_corrupt(sc, bp);
114 115

	if (sb->sb_dblocks != cpu_to_be64(mp->m_sb.sb_dblocks))
D
Darrick J. Wong 已提交
116
		xchk_block_set_corrupt(sc, bp);
117 118

	if (sb->sb_rblocks != cpu_to_be64(mp->m_sb.sb_rblocks))
D
Darrick J. Wong 已提交
119
		xchk_block_set_corrupt(sc, bp);
120 121

	if (sb->sb_rextents != cpu_to_be64(mp->m_sb.sb_rextents))
D
Darrick J. Wong 已提交
122
		xchk_block_set_corrupt(sc, bp);
123 124

	if (!uuid_equal(&sb->sb_uuid, &mp->m_sb.sb_uuid))
D
Darrick J. Wong 已提交
125
		xchk_block_set_preen(sc, bp);
126 127

	if (sb->sb_logstart != cpu_to_be64(mp->m_sb.sb_logstart))
D
Darrick J. Wong 已提交
128
		xchk_block_set_corrupt(sc, bp);
129 130

	if (sb->sb_rootino != cpu_to_be64(mp->m_sb.sb_rootino))
D
Darrick J. Wong 已提交
131
		xchk_block_set_preen(sc, bp);
132 133

	if (sb->sb_rbmino != cpu_to_be64(mp->m_sb.sb_rbmino))
D
Darrick J. Wong 已提交
134
		xchk_block_set_preen(sc, bp);
135 136

	if (sb->sb_rsumino != cpu_to_be64(mp->m_sb.sb_rsumino))
D
Darrick J. Wong 已提交
137
		xchk_block_set_preen(sc, bp);
138 139

	if (sb->sb_rextsize != cpu_to_be32(mp->m_sb.sb_rextsize))
D
Darrick J. Wong 已提交
140
		xchk_block_set_corrupt(sc, bp);
141 142

	if (sb->sb_agblocks != cpu_to_be32(mp->m_sb.sb_agblocks))
D
Darrick J. Wong 已提交
143
		xchk_block_set_corrupt(sc, bp);
144 145

	if (sb->sb_agcount != cpu_to_be32(mp->m_sb.sb_agcount))
D
Darrick J. Wong 已提交
146
		xchk_block_set_corrupt(sc, bp);
147 148

	if (sb->sb_rbmblocks != cpu_to_be32(mp->m_sb.sb_rbmblocks))
D
Darrick J. Wong 已提交
149
		xchk_block_set_corrupt(sc, bp);
150 151

	if (sb->sb_logblocks != cpu_to_be32(mp->m_sb.sb_logblocks))
D
Darrick J. Wong 已提交
152
		xchk_block_set_corrupt(sc, bp);
153 154 155 156 157 158 159 160 161 162 163 164 165

	/* Check sb_versionnum bits that are set at mkfs time. */
	vernum_mask = cpu_to_be16(~XFS_SB_VERSION_OKBITS |
				  XFS_SB_VERSION_NUMBITS |
				  XFS_SB_VERSION_ALIGNBIT |
				  XFS_SB_VERSION_DALIGNBIT |
				  XFS_SB_VERSION_SHAREDBIT |
				  XFS_SB_VERSION_LOGV2BIT |
				  XFS_SB_VERSION_SECTORBIT |
				  XFS_SB_VERSION_EXTFLGBIT |
				  XFS_SB_VERSION_DIRV2BIT);
	if ((sb->sb_versionnum & vernum_mask) !=
	    (cpu_to_be16(mp->m_sb.sb_versionnum) & vernum_mask))
D
Darrick J. Wong 已提交
166
		xchk_block_set_corrupt(sc, bp);
167 168 169 170 171 172 173

	/* Check sb_versionnum bits that can be set after mkfs time. */
	vernum_mask = cpu_to_be16(XFS_SB_VERSION_ATTRBIT |
				  XFS_SB_VERSION_NLINKBIT |
				  XFS_SB_VERSION_QUOTABIT);
	if ((sb->sb_versionnum & vernum_mask) !=
	    (cpu_to_be16(mp->m_sb.sb_versionnum) & vernum_mask))
D
Darrick J. Wong 已提交
174
		xchk_block_set_preen(sc, bp);
175 176

	if (sb->sb_sectsize != cpu_to_be16(mp->m_sb.sb_sectsize))
D
Darrick J. Wong 已提交
177
		xchk_block_set_corrupt(sc, bp);
178 179

	if (sb->sb_inodesize != cpu_to_be16(mp->m_sb.sb_inodesize))
D
Darrick J. Wong 已提交
180
		xchk_block_set_corrupt(sc, bp);
181 182

	if (sb->sb_inopblock != cpu_to_be16(mp->m_sb.sb_inopblock))
D
Darrick J. Wong 已提交
183
		xchk_block_set_corrupt(sc, bp);
184 185

	if (memcmp(sb->sb_fname, mp->m_sb.sb_fname, sizeof(sb->sb_fname)))
D
Darrick J. Wong 已提交
186
		xchk_block_set_preen(sc, bp);
187 188

	if (sb->sb_blocklog != mp->m_sb.sb_blocklog)
D
Darrick J. Wong 已提交
189
		xchk_block_set_corrupt(sc, bp);
190 191

	if (sb->sb_sectlog != mp->m_sb.sb_sectlog)
D
Darrick J. Wong 已提交
192
		xchk_block_set_corrupt(sc, bp);
193 194

	if (sb->sb_inodelog != mp->m_sb.sb_inodelog)
D
Darrick J. Wong 已提交
195
		xchk_block_set_corrupt(sc, bp);
196 197

	if (sb->sb_inopblog != mp->m_sb.sb_inopblog)
D
Darrick J. Wong 已提交
198
		xchk_block_set_corrupt(sc, bp);
199 200

	if (sb->sb_agblklog != mp->m_sb.sb_agblklog)
D
Darrick J. Wong 已提交
201
		xchk_block_set_corrupt(sc, bp);
202 203

	if (sb->sb_rextslog != mp->m_sb.sb_rextslog)
D
Darrick J. Wong 已提交
204
		xchk_block_set_corrupt(sc, bp);
205 206

	if (sb->sb_imax_pct != mp->m_sb.sb_imax_pct)
D
Darrick J. Wong 已提交
207
		xchk_block_set_preen(sc, bp);
208 209 210 211 212 213 214

	/*
	 * Skip the summary counters since we track them in memory anyway.
	 * sb_icount, sb_ifree, sb_fdblocks, sb_frexents
	 */

	if (sb->sb_uquotino != cpu_to_be64(mp->m_sb.sb_uquotino))
D
Darrick J. Wong 已提交
215
		xchk_block_set_preen(sc, bp);
216 217

	if (sb->sb_gquotino != cpu_to_be64(mp->m_sb.sb_gquotino))
D
Darrick J. Wong 已提交
218
		xchk_block_set_preen(sc, bp);
219 220 221 222 223 224 225

	/*
	 * Skip the quota flags since repair will force quotacheck.
	 * sb_qflags
	 */

	if (sb->sb_flags != mp->m_sb.sb_flags)
D
Darrick J. Wong 已提交
226
		xchk_block_set_corrupt(sc, bp);
227 228

	if (sb->sb_shared_vn != mp->m_sb.sb_shared_vn)
D
Darrick J. Wong 已提交
229
		xchk_block_set_corrupt(sc, bp);
230 231

	if (sb->sb_inoalignmt != cpu_to_be32(mp->m_sb.sb_inoalignmt))
D
Darrick J. Wong 已提交
232
		xchk_block_set_corrupt(sc, bp);
233 234

	if (sb->sb_unit != cpu_to_be32(mp->m_sb.sb_unit))
D
Darrick J. Wong 已提交
235
		xchk_block_set_preen(sc, bp);
236 237

	if (sb->sb_width != cpu_to_be32(mp->m_sb.sb_width))
D
Darrick J. Wong 已提交
238
		xchk_block_set_preen(sc, bp);
239 240

	if (sb->sb_dirblklog != mp->m_sb.sb_dirblklog)
D
Darrick J. Wong 已提交
241
		xchk_block_set_corrupt(sc, bp);
242 243

	if (sb->sb_logsectlog != mp->m_sb.sb_logsectlog)
D
Darrick J. Wong 已提交
244
		xchk_block_set_corrupt(sc, bp);
245 246

	if (sb->sb_logsectsize != cpu_to_be16(mp->m_sb.sb_logsectsize))
D
Darrick J. Wong 已提交
247
		xchk_block_set_corrupt(sc, bp);
248 249

	if (sb->sb_logsunit != cpu_to_be32(mp->m_sb.sb_logsunit))
D
Darrick J. Wong 已提交
250
		xchk_block_set_corrupt(sc, bp);
251 252 253 254

	/* Do we see any invalid bits in sb_features2? */
	if (!xfs_sb_version_hasmorebits(&mp->m_sb)) {
		if (sb->sb_features2 != 0)
D
Darrick J. Wong 已提交
255
			xchk_block_set_corrupt(sc, bp);
256 257 258 259 260 261
	} else {
		v2_ok = XFS_SB_VERSION2_OKBITS;
		if (XFS_SB_VERSION_NUM(&mp->m_sb) >= XFS_SB_VERSION_5)
			v2_ok |= XFS_SB_VERSION2_CRCBIT;

		if (!!(sb->sb_features2 & cpu_to_be32(~v2_ok)))
D
Darrick J. Wong 已提交
262
			xchk_block_set_corrupt(sc, bp);
263 264

		if (sb->sb_features2 != sb->sb_bad_features2)
D
Darrick J. Wong 已提交
265
			xchk_block_set_preen(sc, bp);
266 267 268 269 270 271 272 273 274
	}

	/* Check sb_features2 flags that are set at mkfs time. */
	features_mask = cpu_to_be32(XFS_SB_VERSION2_LAZYSBCOUNTBIT |
				    XFS_SB_VERSION2_PROJID32BIT |
				    XFS_SB_VERSION2_CRCBIT |
				    XFS_SB_VERSION2_FTYPE);
	if ((sb->sb_features2 & features_mask) !=
	    (cpu_to_be32(mp->m_sb.sb_features2) & features_mask))
D
Darrick J. Wong 已提交
275
		xchk_block_set_corrupt(sc, bp);
276 277 278 279 280

	/* Check sb_features2 flags that can be set after mkfs time. */
	features_mask = cpu_to_be32(XFS_SB_VERSION2_ATTR2BIT);
	if ((sb->sb_features2 & features_mask) !=
	    (cpu_to_be32(mp->m_sb.sb_features2) & features_mask))
D
Darrick J. Wong 已提交
281
		xchk_block_set_corrupt(sc, bp);
282 283 284 285 286 287

	if (!xfs_sb_version_hascrc(&mp->m_sb)) {
		/* all v5 fields must be zero */
		if (memchr_inv(&sb->sb_features_compat, 0,
				sizeof(struct xfs_dsb) -
				offsetof(struct xfs_dsb, sb_features_compat)))
D
Darrick J. Wong 已提交
288
			xchk_block_set_corrupt(sc, bp);
289 290 291 292 293
	} else {
		/* Check compat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_COMPAT_UNKNOWN);
		if ((sb->sb_features_compat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_compat) & features_mask))
D
Darrick J. Wong 已提交
294
			xchk_block_set_corrupt(sc, bp);
295 296 297 298 299 300 301 302 303

		/* Check ro compat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_RO_COMPAT_UNKNOWN |
					    XFS_SB_FEAT_RO_COMPAT_FINOBT |
					    XFS_SB_FEAT_RO_COMPAT_RMAPBT |
					    XFS_SB_FEAT_RO_COMPAT_REFLINK);
		if ((sb->sb_features_ro_compat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_ro_compat) &
		     features_mask))
D
Darrick J. Wong 已提交
304
			xchk_block_set_corrupt(sc, bp);
305 306 307 308 309 310 311 312 313

		/* Check incompat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_INCOMPAT_UNKNOWN |
					    XFS_SB_FEAT_INCOMPAT_FTYPE |
					    XFS_SB_FEAT_INCOMPAT_SPINODES |
					    XFS_SB_FEAT_INCOMPAT_META_UUID);
		if ((sb->sb_features_incompat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_incompat) &
		     features_mask))
D
Darrick J. Wong 已提交
314
			xchk_block_set_corrupt(sc, bp);
315 316 317 318 319 320

		/* Check log incompat flags; all are set at mkfs time. */
		features_mask = cpu_to_be32(XFS_SB_FEAT_INCOMPAT_LOG_UNKNOWN);
		if ((sb->sb_features_log_incompat & features_mask) !=
		    (cpu_to_be32(mp->m_sb.sb_features_log_incompat) &
		     features_mask))
D
Darrick J. Wong 已提交
321
			xchk_block_set_corrupt(sc, bp);
322 323 324 325

		/* Don't care about sb_crc */

		if (sb->sb_spino_align != cpu_to_be32(mp->m_sb.sb_spino_align))
D
Darrick J. Wong 已提交
326
			xchk_block_set_corrupt(sc, bp);
327 328

		if (sb->sb_pquotino != cpu_to_be64(mp->m_sb.sb_pquotino))
D
Darrick J. Wong 已提交
329
			xchk_block_set_preen(sc, bp);
330 331 332 333 334 335 336

		/* Don't care about sb_lsn */
	}

	if (xfs_sb_version_hasmetauuid(&mp->m_sb)) {
		/* The metadata UUID must be the same for all supers */
		if (!uuid_equal(&sb->sb_meta_uuid, &mp->m_sb.sb_meta_uuid))
D
Darrick J. Wong 已提交
337
			xchk_block_set_corrupt(sc, bp);
338 339 340 341 342
	}

	/* Everything else must be zero. */
	if (memchr_inv(sb + 1, 0,
			BBTOB(bp->b_length) - sizeof(struct xfs_dsb)))
D
Darrick J. Wong 已提交
343
		xchk_block_set_corrupt(sc, bp);
344

D
Darrick J. Wong 已提交
345
	xchk_superblock_xref(sc, bp);
346

347 348
	return error;
}
D
Darrick J. Wong 已提交
349 350 351

/* AGF */

352 353
/* Tally freespace record lengths. */
STATIC int
D
Darrick J. Wong 已提交
354
xchk_agf_record_bno_lengths(
355 356 357 358 359 360 361 362 363 364 365 366
	struct xfs_btree_cur		*cur,
	struct xfs_alloc_rec_incore	*rec,
	void				*priv)
{
	xfs_extlen_t			*blocks = priv;

	(*blocks) += rec->ar_blockcount;
	return 0;
}

/* Check agf_freeblks */
static inline void
D
Darrick J. Wong 已提交
367
xchk_agf_xref_freeblks(
368
	struct xfs_scrub	*sc)
369
{
370 371 372
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_extlen_t		blocks = 0;
	int			error;
373 374 375 376 377

	if (!sc->sa.bno_cur)
		return;

	error = xfs_alloc_query_all(sc->sa.bno_cur,
D
Darrick J. Wong 已提交
378 379
			xchk_agf_record_bno_lengths, &blocks);
	if (!xchk_should_check_xref(sc, &error, &sc->sa.bno_cur))
380 381
		return;
	if (blocks != be32_to_cpu(agf->agf_freeblks))
D
Darrick J. Wong 已提交
382
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
383 384
}

385 386
/* Cross reference the AGF with the cntbt (freespace by length btree) */
static inline void
D
Darrick J. Wong 已提交
387
xchk_agf_xref_cntbt(
388
	struct xfs_scrub	*sc)
389
{
390 391 392 393 394
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_agblock_t		agbno;
	xfs_extlen_t		blocks;
	int			have;
	int			error;
395 396 397 398 399 400

	if (!sc->sa.cnt_cur)
		return;

	/* Any freespace at all? */
	error = xfs_alloc_lookup_le(sc->sa.cnt_cur, 0, -1U, &have);
D
Darrick J. Wong 已提交
401
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
402 403 404
		return;
	if (!have) {
		if (agf->agf_freeblks != be32_to_cpu(0))
D
Darrick J. Wong 已提交
405
			xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
406 407 408 409 410
		return;
	}

	/* Check agf_longest */
	error = xfs_alloc_get_rec(sc->sa.cnt_cur, &agbno, &blocks, &have);
D
Darrick J. Wong 已提交
411
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
412 413
		return;
	if (!have || blocks != be32_to_cpu(agf->agf_longest))
D
Darrick J. Wong 已提交
414
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
415 416
}

417 418
/* Check the btree block counts in the AGF against the btrees. */
STATIC void
D
Darrick J. Wong 已提交
419
xchk_agf_xref_btreeblks(
420
	struct xfs_scrub	*sc)
421
{
422 423 424 425 426
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		blocks;
	xfs_agblock_t		btreeblks;
	int			error;
427 428 429 430

	/* Check agf_rmap_blocks; set up for agf_btreeblks check */
	if (sc->sa.rmap_cur) {
		error = xfs_btree_count_blocks(sc->sa.rmap_cur, &blocks);
D
Darrick J. Wong 已提交
431
		if (!xchk_should_check_xref(sc, &error, &sc->sa.rmap_cur))
432 433 434
			return;
		btreeblks = blocks - 1;
		if (blocks != be32_to_cpu(agf->agf_rmap_blocks))
D
Darrick J. Wong 已提交
435
			xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
436 437 438 439 440 441 442 443 444 445 446 447 448 449
	} else {
		btreeblks = 0;
	}

	/*
	 * No rmap cursor; we can't xref if we have the rmapbt feature.
	 * We also can't do it if we're missing the free space btree cursors.
	 */
	if ((xfs_sb_version_hasrmapbt(&mp->m_sb) && !sc->sa.rmap_cur) ||
	    !sc->sa.bno_cur || !sc->sa.cnt_cur)
		return;

	/* Check agf_btreeblks */
	error = xfs_btree_count_blocks(sc->sa.bno_cur, &blocks);
D
Darrick J. Wong 已提交
450
	if (!xchk_should_check_xref(sc, &error, &sc->sa.bno_cur))
451 452 453 454
		return;
	btreeblks += blocks - 1;

	error = xfs_btree_count_blocks(sc->sa.cnt_cur, &blocks);
D
Darrick J. Wong 已提交
455
	if (!xchk_should_check_xref(sc, &error, &sc->sa.cnt_cur))
456 457 458 459
		return;
	btreeblks += blocks - 1;

	if (btreeblks != be32_to_cpu(agf->agf_btreeblks))
D
Darrick J. Wong 已提交
460
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
461 462
}

463 464
/* Check agf_refcount_blocks against tree size */
static inline void
D
Darrick J. Wong 已提交
465
xchk_agf_xref_refcblks(
466
	struct xfs_scrub	*sc)
467
{
468 469 470
	struct xfs_agf		*agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	xfs_agblock_t		blocks;
	int			error;
471 472 473 474 475

	if (!sc->sa.refc_cur)
		return;

	error = xfs_btree_count_blocks(sc->sa.refc_cur, &blocks);
D
Darrick J. Wong 已提交
476
	if (!xchk_should_check_xref(sc, &error, &sc->sa.refc_cur))
477 478
		return;
	if (blocks != be32_to_cpu(agf->agf_refcount_blocks))
D
Darrick J. Wong 已提交
479
		xchk_block_xref_set_corrupt(sc, sc->sa.agf_bp);
480 481
}

482 483
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
484
xchk_agf_xref(
485
	struct xfs_scrub	*sc)
486
{
487 488 489 490
	struct xfs_owner_info	oinfo;
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
491

492 493
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
494 495 496

	agbno = XFS_AGF_BLOCK(mp);

D
Darrick J. Wong 已提交
497
	error = xchk_ag_btcur_init(sc, &sc->sa);
498 499 500
	if (error)
		return;

D
Darrick J. Wong 已提交
501 502 503 504
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_agf_xref_freeblks(sc);
	xchk_agf_xref_cntbt(sc);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
505
	xfs_rmap_ag_owner(&oinfo, XFS_RMAP_OWN_FS);
D
Darrick J. Wong 已提交
506 507 508 509
	xchk_xref_is_owned_by(sc, agbno, 1, &oinfo);
	xchk_agf_xref_btreeblks(sc);
	xchk_xref_is_not_shared(sc, agbno, 1);
	xchk_agf_xref_refcblks(sc);
510 511

	/* scrub teardown will take care of sc->sa for us */
512 513
}

D
Darrick J. Wong 已提交
514 515
/* Scrub the AGF. */
int
D
Darrick J. Wong 已提交
516
xchk_agf(
517
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
518
{
519 520 521 522 523 524 525 526 527 528 529
	struct xfs_mount	*mp = sc->mp;
	struct xfs_agf		*agf;
	xfs_agnumber_t		agno;
	xfs_agblock_t		agbno;
	xfs_agblock_t		eoag;
	xfs_agblock_t		agfl_first;
	xfs_agblock_t		agfl_last;
	xfs_agblock_t		agfl_count;
	xfs_agblock_t		fl_count;
	int			level;
	int			error = 0;
D
Darrick J. Wong 已提交
530 531

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
532
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
533
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
534
	if (!xchk_process_error(sc, agno, XFS_AGF_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
535
		goto out;
D
Darrick J. Wong 已提交
536
	xchk_buffer_recheck(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
537 538 539 540 541 542

	agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);

	/* Check the AG length */
	eoag = be32_to_cpu(agf->agf_length);
	if (eoag != xfs_ag_block_count(mp, agno))
D
Darrick J. Wong 已提交
543
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
544 545 546 547

	/* Check the AGF btree roots and levels */
	agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_BNO]);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
548
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
549 550 551

	agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_CNT]);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
552
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
553 554 555

	level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_BNO]);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
556
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
557 558 559

	level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_CNT]);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
560
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
561 562 563 564

	if (xfs_sb_version_hasrmapbt(&mp->m_sb)) {
		agbno = be32_to_cpu(agf->agf_roots[XFS_BTNUM_RMAP]);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
565
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
566 567 568

		level = be32_to_cpu(agf->agf_levels[XFS_BTNUM_RMAP]);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
569
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
570 571 572 573 574
	}

	if (xfs_sb_version_hasreflink(&mp->m_sb)) {
		agbno = be32_to_cpu(agf->agf_refcount_root);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
575
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
576 577 578

		level = be32_to_cpu(agf->agf_refcount_level);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
579
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
580 581 582 583 584 585 586 587 588
	}

	/* Check the AGFL counters */
	agfl_first = be32_to_cpu(agf->agf_flfirst);
	agfl_last = be32_to_cpu(agf->agf_fllast);
	agfl_count = be32_to_cpu(agf->agf_flcount);
	if (agfl_last > agfl_first)
		fl_count = agfl_last - agfl_first + 1;
	else
589
		fl_count = xfs_agfl_size(mp) - agfl_first + agfl_last + 1;
D
Darrick J. Wong 已提交
590
	if (agfl_count != 0 && fl_count != agfl_count)
D
Darrick J. Wong 已提交
591
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
D
Darrick J. Wong 已提交
592

D
Darrick J. Wong 已提交
593
	xchk_agf_xref(sc);
D
Darrick J. Wong 已提交
594 595 596 597 598 599
out:
	return error;
}

/* AGFL */

D
Darrick J. Wong 已提交
600
struct xchk_agfl_info {
601 602 603 604
	struct xfs_owner_info	oinfo;
	unsigned int		sz_entries;
	unsigned int		nr_entries;
	xfs_agblock_t		*entries;
605
	struct xfs_scrub	*sc;
606 607
};

608 609
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
610
xchk_agfl_block_xref(
611
	struct xfs_scrub	*sc,
612 613
	xfs_agblock_t		agbno,
	struct xfs_owner_info	*oinfo)
614 615 616
{
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
617

D
Darrick J. Wong 已提交
618 619 620 621
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
	xchk_xref_is_owned_by(sc, agbno, 1, oinfo);
	xchk_xref_is_not_shared(sc, agbno, 1);
622 623
}

D
Darrick J. Wong 已提交
624 625
/* Scrub an AGFL block. */
STATIC int
D
Darrick J. Wong 已提交
626
xchk_agfl_block(
627 628 629
	struct xfs_mount	*mp,
	xfs_agblock_t		agbno,
	void			*priv)
D
Darrick J. Wong 已提交
630
{
631
	struct xchk_agfl_info	*sai = priv;
632
	struct xfs_scrub	*sc = sai->sc;
633
	xfs_agnumber_t		agno = sc->sa.agno;
D
Darrick J. Wong 已提交
634

635 636 637 638
	if (xfs_verify_agbno(mp, agno, agbno) &&
	    sai->nr_entries < sai->sz_entries)
		sai->entries[sai->nr_entries++] = agbno;
	else
D
Darrick J. Wong 已提交
639
		xchk_block_set_corrupt(sc, sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
640

D
Darrick J. Wong 已提交
641
	xchk_agfl_block_xref(sc, agbno, priv);
642

643 644 645
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return XFS_BTREE_QUERY_RANGE_ABORT;

D
Darrick J. Wong 已提交
646 647 648
	return 0;
}

649
static int
D
Darrick J. Wong 已提交
650
xchk_agblock_cmp(
651 652 653 654 655 656 657 658 659
	const void		*pa,
	const void		*pb)
{
	const xfs_agblock_t	*a = pa;
	const xfs_agblock_t	*b = pb;

	return (int)*a - (int)*b;
}

660 661
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
662
xchk_agfl_xref(
663
	struct xfs_scrub	*sc)
664
{
665 666 667 668
	struct xfs_owner_info	oinfo;
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
669

670 671
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
672 673 674

	agbno = XFS_AGFL_BLOCK(mp);

D
Darrick J. Wong 已提交
675
	error = xchk_ag_btcur_init(sc, &sc->sa);
676 677 678
	if (error)
		return;

D
Darrick J. Wong 已提交
679 680
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
681
	xfs_rmap_ag_owner(&oinfo, XFS_RMAP_OWN_FS);
D
Darrick J. Wong 已提交
682 683
	xchk_xref_is_owned_by(sc, agbno, 1, &oinfo);
	xchk_xref_is_not_shared(sc, agbno, 1);
684 685 686 687 688

	/*
	 * Scrub teardown will take care of sc->sa for us.  Leave sc->sa
	 * active so that the agfl block xref can use it too.
	 */
689 690
}

D
Darrick J. Wong 已提交
691 692
/* Scrub the AGFL. */
int
D
Darrick J. Wong 已提交
693
xchk_agfl(
694
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
695
{
696 697 698 699 700 701
	struct xchk_agfl_info	sai;
	struct xfs_agf		*agf;
	xfs_agnumber_t		agno;
	unsigned int		agflcount;
	unsigned int		i;
	int			error;
D
Darrick J. Wong 已提交
702 703

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
704
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
705
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
706
	if (!xchk_process_error(sc, agno, XFS_AGFL_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
707 708 709
		goto out;
	if (!sc->sa.agf_bp)
		return -EFSCORRUPTED;
D
Darrick J. Wong 已提交
710
	xchk_buffer_recheck(sc, sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
711

D
Darrick J. Wong 已提交
712
	xchk_agfl_xref(sc);
713 714 715 716

	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		goto out;

717 718 719
	/* Allocate buffer to ensure uniqueness of AGFL entries. */
	agf = XFS_BUF_TO_AGF(sc->sa.agf_bp);
	agflcount = be32_to_cpu(agf->agf_flcount);
720
	if (agflcount > xfs_agfl_size(sc->mp)) {
D
Darrick J. Wong 已提交
721
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
722 723
		goto out;
	}
724
	memset(&sai, 0, sizeof(sai));
725
	sai.sc = sc;
726
	sai.sz_entries = agflcount;
727 728
	sai.entries = kmem_zalloc(sizeof(xfs_agblock_t) * agflcount,
			KM_MAYFAIL);
729 730 731 732 733
	if (!sai.entries) {
		error = -ENOMEM;
		goto out;
	}

D
Darrick J. Wong 已提交
734
	/* Check the blocks in the AGFL. */
735
	xfs_rmap_ag_owner(&sai.oinfo, XFS_RMAP_OWN_AG);
736
	error = xfs_agfl_walk(sc->mp, XFS_BUF_TO_AGF(sc->sa.agf_bp),
D
Darrick J. Wong 已提交
737
			sc->sa.agfl_bp, xchk_agfl_block, &sai);
738 739 740 741
	if (error == XFS_BTREE_QUERY_RANGE_ABORT) {
		error = 0;
		goto out_free;
	}
742 743 744 745
	if (error)
		goto out_free;

	if (agflcount != sai.nr_entries) {
D
Darrick J. Wong 已提交
746
		xchk_block_set_corrupt(sc, sc->sa.agf_bp);
747 748 749 750 751
		goto out_free;
	}

	/* Sort entries, check for duplicates. */
	sort(sai.entries, sai.nr_entries, sizeof(sai.entries[0]),
D
Darrick J. Wong 已提交
752
			xchk_agblock_cmp, NULL);
753 754
	for (i = 1; i < sai.nr_entries; i++) {
		if (sai.entries[i] == sai.entries[i - 1]) {
D
Darrick J. Wong 已提交
755
			xchk_block_set_corrupt(sc, sc->sa.agf_bp);
756 757 758 759 760 761
			break;
		}
	}

out_free:
	kmem_free(sai.entries);
D
Darrick J. Wong 已提交
762 763 764
out:
	return error;
}
D
Darrick J. Wong 已提交
765 766 767

/* AGI */

768 769
/* Check agi_count/agi_freecount */
static inline void
D
Darrick J. Wong 已提交
770
xchk_agi_xref_icounts(
771
	struct xfs_scrub	*sc)
772
{
773 774 775 776
	struct xfs_agi		*agi = XFS_BUF_TO_AGI(sc->sa.agi_bp);
	xfs_agino_t		icount;
	xfs_agino_t		freecount;
	int			error;
777 778 779 780 781

	if (!sc->sa.ino_cur)
		return;

	error = xfs_ialloc_count_inodes(sc->sa.ino_cur, &icount, &freecount);
D
Darrick J. Wong 已提交
782
	if (!xchk_should_check_xref(sc, &error, &sc->sa.ino_cur))
783 784 785
		return;
	if (be32_to_cpu(agi->agi_count) != icount ||
	    be32_to_cpu(agi->agi_freecount) != freecount)
D
Darrick J. Wong 已提交
786
		xchk_block_xref_set_corrupt(sc, sc->sa.agi_bp);
787 788
}

789 790
/* Cross-reference with the other btrees. */
STATIC void
D
Darrick J. Wong 已提交
791
xchk_agi_xref(
792
	struct xfs_scrub	*sc)
793
{
794 795 796 797
	struct xfs_owner_info	oinfo;
	struct xfs_mount	*mp = sc->mp;
	xfs_agblock_t		agbno;
	int			error;
798

799 800
	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return;
801 802 803

	agbno = XFS_AGI_BLOCK(mp);

D
Darrick J. Wong 已提交
804
	error = xchk_ag_btcur_init(sc, &sc->sa);
805 806 807
	if (error)
		return;

D
Darrick J. Wong 已提交
808 809 810
	xchk_xref_is_used_space(sc, agbno, 1);
	xchk_xref_is_not_inode_chunk(sc, agbno, 1);
	xchk_agi_xref_icounts(sc);
811
	xfs_rmap_ag_owner(&oinfo, XFS_RMAP_OWN_FS);
D
Darrick J. Wong 已提交
812 813
	xchk_xref_is_owned_by(sc, agbno, 1, &oinfo);
	xchk_xref_is_not_shared(sc, agbno, 1);
814 815

	/* scrub teardown will take care of sc->sa for us */
816 817
}

D
Darrick J. Wong 已提交
818 819
/* Scrub the AGI. */
int
D
Darrick J. Wong 已提交
820
xchk_agi(
821
	struct xfs_scrub	*sc)
D
Darrick J. Wong 已提交
822
{
823 824 825 826 827 828 829 830 831 832 833 834
	struct xfs_mount	*mp = sc->mp;
	struct xfs_agi		*agi;
	xfs_agnumber_t		agno;
	xfs_agblock_t		agbno;
	xfs_agblock_t		eoag;
	xfs_agino_t		agino;
	xfs_agino_t		first_agino;
	xfs_agino_t		last_agino;
	xfs_agino_t		icount;
	int			i;
	int			level;
	int			error = 0;
D
Darrick J. Wong 已提交
835 836

	agno = sc->sa.agno = sc->sm->sm_agno;
D
Darrick J. Wong 已提交
837
	error = xchk_ag_read_headers(sc, agno, &sc->sa.agi_bp,
D
Darrick J. Wong 已提交
838
			&sc->sa.agf_bp, &sc->sa.agfl_bp);
D
Darrick J. Wong 已提交
839
	if (!xchk_process_error(sc, agno, XFS_AGI_BLOCK(sc->mp), &error))
D
Darrick J. Wong 已提交
840
		goto out;
D
Darrick J. Wong 已提交
841
	xchk_buffer_recheck(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
842 843 844 845 846 847

	agi = XFS_BUF_TO_AGI(sc->sa.agi_bp);

	/* Check the AG length */
	eoag = be32_to_cpu(agi->agi_length);
	if (eoag != xfs_ag_block_count(mp, agno))
D
Darrick J. Wong 已提交
848
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
849 850 851 852

	/* Check btree roots and levels */
	agbno = be32_to_cpu(agi->agi_root);
	if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
853
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
854 855 856

	level = be32_to_cpu(agi->agi_level);
	if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
857
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
858 859 860 861

	if (xfs_sb_version_hasfinobt(&mp->m_sb)) {
		agbno = be32_to_cpu(agi->agi_free_root);
		if (!xfs_verify_agbno(mp, agno, agbno))
D
Darrick J. Wong 已提交
862
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
863 864 865

		level = be32_to_cpu(agi->agi_free_level);
		if (level <= 0 || level > XFS_BTREE_MAXLEVELS)
D
Darrick J. Wong 已提交
866
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
867 868 869
	}

	/* Check inode counters */
870
	xfs_agino_range(mp, agno, &first_agino, &last_agino);
D
Darrick J. Wong 已提交
871 872 873
	icount = be32_to_cpu(agi->agi_count);
	if (icount > last_agino - first_agino + 1 ||
	    icount < be32_to_cpu(agi->agi_freecount))
D
Darrick J. Wong 已提交
874
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
875 876 877 878

	/* Check inode pointers */
	agino = be32_to_cpu(agi->agi_newino);
	if (agino != NULLAGINO && !xfs_verify_agino(mp, agno, agino))
D
Darrick J. Wong 已提交
879
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
880 881 882

	agino = be32_to_cpu(agi->agi_dirino);
	if (agino != NULLAGINO && !xfs_verify_agino(mp, agno, agino))
D
Darrick J. Wong 已提交
883
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
884 885 886 887 888 889 890

	/* Check unlinked inode buckets */
	for (i = 0; i < XFS_AGI_UNLINKED_BUCKETS; i++) {
		agino = be32_to_cpu(agi->agi_unlinked[i]);
		if (agino == NULLAGINO)
			continue;
		if (!xfs_verify_agino(mp, agno, agino))
D
Darrick J. Wong 已提交
891
			xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
892 893 894
	}

	if (agi->agi_pad32 != cpu_to_be32(0))
D
Darrick J. Wong 已提交
895
		xchk_block_set_corrupt(sc, sc->sa.agi_bp);
D
Darrick J. Wong 已提交
896

D
Darrick J. Wong 已提交
897
	xchk_agi_xref(sc);
D
Darrick J. Wong 已提交
898 899 900
out:
	return error;
}