xfs_mount.c 36.4 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0
L
Linus Torvalds 已提交
2
/*
3 4
 * Copyright (c) 2000-2005 Silicon Graphics, Inc.
 * All Rights Reserved.
L
Linus Torvalds 已提交
5 6
 */
#include "xfs.h"
7
#include "xfs_fs.h"
8
#include "xfs_shared.h"
9 10 11
#include "xfs_format.h"
#include "xfs_log_format.h"
#include "xfs_trans_resv.h"
12
#include "xfs_bit.h"
L
Linus Torvalds 已提交
13 14 15
#include "xfs_sb.h"
#include "xfs_mount.h"
#include "xfs_inode.h"
16
#include "xfs_dir2.h"
17
#include "xfs_ialloc.h"
L
Linus Torvalds 已提交
18 19 20
#include "xfs_alloc.h"
#include "xfs_rtalloc.h"
#include "xfs_bmap.h"
21 22 23
#include "xfs_trans.h"
#include "xfs_trans_priv.h"
#include "xfs_log.h"
L
Linus Torvalds 已提交
24 25 26
#include "xfs_error.h"
#include "xfs_quota.h"
#include "xfs_fsops.h"
27
#include "xfs_icache.h"
B
Brian Foster 已提交
28
#include "xfs_sysfs.h"
29
#include "xfs_rmap_btree.h"
30
#include "xfs_refcount_btree.h"
31
#include "xfs_reflink.h"
32
#include "xfs_extent_busy.h"
33
#include "xfs_health.h"
34
#include "xfs_trace.h"
35
#include "xfs_ag.h"
L
Linus Torvalds 已提交
36

C
Christoph Hellwig 已提交
37 38 39 40
static DEFINE_MUTEX(xfs_uuid_table_mutex);
static int xfs_uuid_table_size;
static uuid_t *xfs_uuid_table;

41 42 43 44 45 46 47 48 49 50
void
xfs_uuid_table_free(void)
{
	if (xfs_uuid_table_size == 0)
		return;
	kmem_free(xfs_uuid_table);
	xfs_uuid_table = NULL;
	xfs_uuid_table_size = 0;
}

C
Christoph Hellwig 已提交
51 52 53 54 55 56 57 58 59 60 61
/*
 * See if the UUID is unique among mounted XFS filesystems.
 * Mount fails if UUID is nil or a FS with the same UUID is already mounted.
 */
STATIC int
xfs_uuid_mount(
	struct xfs_mount	*mp)
{
	uuid_t			*uuid = &mp->m_sb.sb_uuid;
	int			hole, i;

62
	/* Publish UUID in struct super_block */
63
	uuid_copy(&mp->m_super->s_uuid, uuid);
64

C
Christoph Hellwig 已提交
65 66 67
	if (mp->m_flags & XFS_MOUNT_NOUUID)
		return 0;

68 69
	if (uuid_is_null(uuid)) {
		xfs_warn(mp, "Filesystem has null UUID - can't mount");
D
Dave Chinner 已提交
70
		return -EINVAL;
C
Christoph Hellwig 已提交
71 72 73 74
	}

	mutex_lock(&xfs_uuid_table_mutex);
	for (i = 0, hole = -1; i < xfs_uuid_table_size; i++) {
75
		if (uuid_is_null(&xfs_uuid_table[i])) {
C
Christoph Hellwig 已提交
76 77 78 79 80 81 82 83
			hole = i;
			continue;
		}
		if (uuid_equal(uuid, &xfs_uuid_table[i]))
			goto out_duplicate;
	}

	if (hole < 0) {
C
Carlos Maiolino 已提交
84
		xfs_uuid_table = krealloc(xfs_uuid_table,
C
Christoph Hellwig 已提交
85
			(xfs_uuid_table_size + 1) * sizeof(*xfs_uuid_table),
C
Carlos Maiolino 已提交
86
			GFP_KERNEL | __GFP_NOFAIL);
C
Christoph Hellwig 已提交
87 88 89 90 91 92 93 94 95
		hole = xfs_uuid_table_size++;
	}
	xfs_uuid_table[hole] = *uuid;
	mutex_unlock(&xfs_uuid_table_mutex);

	return 0;

 out_duplicate:
	mutex_unlock(&xfs_uuid_table_mutex);
96
	xfs_warn(mp, "Filesystem has duplicate UUID %pU - can't mount", uuid);
D
Dave Chinner 已提交
97
	return -EINVAL;
C
Christoph Hellwig 已提交
98 99 100 101 102 103 104 105 106 107 108 109 110 111
}

STATIC void
xfs_uuid_unmount(
	struct xfs_mount	*mp)
{
	uuid_t			*uuid = &mp->m_sb.sb_uuid;
	int			i;

	if (mp->m_flags & XFS_MOUNT_NOUUID)
		return;

	mutex_lock(&xfs_uuid_table_mutex);
	for (i = 0; i < xfs_uuid_table_size; i++) {
112
		if (uuid_is_null(&xfs_uuid_table[i]))
C
Christoph Hellwig 已提交
113 114 115 116 117 118 119 120 121 122
			continue;
		if (!uuid_equal(uuid, &xfs_uuid_table[i]))
			continue;
		memset(&xfs_uuid_table[i], 0, sizeof(uuid_t));
		break;
	}
	ASSERT(i < xfs_uuid_table_size);
	mutex_unlock(&xfs_uuid_table_mutex);
}

123 124 125 126 127 128 129
/*
 * Check size of device based on the (data/realtime) block count.
 * Note: this check is used by the growfs code as well as mount.
 */
int
xfs_sb_validate_fsb_count(
	xfs_sb_t	*sbp,
130
	uint64_t	nblocks)
131 132 133 134
{
	ASSERT(PAGE_SHIFT >= sbp->sb_blocklog);
	ASSERT(sbp->sb_blocklog >= BBSHIFT);

C
Christoph Hellwig 已提交
135
	/* Limited by ULONG_MAX of page cache index */
136
	if (nblocks >> (PAGE_SHIFT - sbp->sb_blocklog) > ULONG_MAX)
D
Dave Chinner 已提交
137
		return -EFBIG;
138 139
	return 0;
}
L
Linus Torvalds 已提交
140 141 142 143 144 145 146

/*
 * xfs_readsb
 *
 * Does the initial read of the superblock.
 */
int
147 148 149
xfs_readsb(
	struct xfs_mount *mp,
	int		flags)
L
Linus Torvalds 已提交
150 151
{
	unsigned int	sector_size;
152 153
	struct xfs_buf	*bp;
	struct xfs_sb	*sbp = &mp->m_sb;
L
Linus Torvalds 已提交
154
	int		error;
155
	int		loud = !(flags & XFS_MFSI_QUIET);
156
	const struct xfs_buf_ops *buf_ops;
L
Linus Torvalds 已提交
157 158 159 160

	ASSERT(mp->m_sb_bp == NULL);
	ASSERT(mp->m_ddev_targp != NULL);

161 162 163 164 165 166 167 168 169 170
	/*
	 * For the initial read, we must guess at the sector
	 * size based on the block device.  It's enough to
	 * get the sb_sectsize out of the superblock and
	 * then reread with the proper length.
	 * We don't verify it yet, because it may not be complete.
	 */
	sector_size = xfs_getsize_buftarg(mp->m_ddev_targp);
	buf_ops = NULL;

L
Linus Torvalds 已提交
171
	/*
172 173 174 175
	 * Allocate a (locked) buffer to hold the superblock. This will be kept
	 * around at all times to optimize access to the superblock. Therefore,
	 * set XBF_NO_IOACCT to make sure it doesn't hold the buftarg count
	 * elevated.
L
Linus Torvalds 已提交
176
	 */
D
Dave Chinner 已提交
177
reread:
178
	error = xfs_buf_read_uncached(mp->m_ddev_targp, XFS_SB_DADDR,
179 180
				      BTOBB(sector_size), XBF_NO_IOACCT, &bp,
				      buf_ops);
181
	if (error) {
182
		if (loud)
183
			xfs_warn(mp, "SB validate failed with error %d.", error);
184
		/* bad CRC means corrupted metadata */
D
Dave Chinner 已提交
185 186
		if (error == -EFSBADCRC)
			error = -EFSCORRUPTED;
187
		return error;
188
	}
L
Linus Torvalds 已提交
189 190 191 192

	/*
	 * Initialize the mount structure from the superblock.
	 */
C
Christoph Hellwig 已提交
193
	xfs_sb_from_disk(sbp, bp->b_addr);
194 195 196 197 198 199 200 201

	/*
	 * If we haven't validated the superblock, do so now before we try
	 * to check the sector size and reread the superblock appropriately.
	 */
	if (sbp->sb_magicnum != XFS_SB_MAGIC) {
		if (loud)
			xfs_warn(mp, "Invalid superblock magic number");
D
Dave Chinner 已提交
202
		error = -EINVAL;
203 204
		goto release_buf;
	}
205

L
Linus Torvalds 已提交
206 207 208
	/*
	 * We must be able to do sector-sized and sector-aligned IO.
	 */
209
	if (sector_size > sbp->sb_sectsize) {
210 211
		if (loud)
			xfs_warn(mp, "device supports %u byte sectors (not %u)",
212
				sector_size, sbp->sb_sectsize);
D
Dave Chinner 已提交
213
		error = -ENOSYS;
D
Dave Chinner 已提交
214
		goto release_buf;
L
Linus Torvalds 已提交
215 216
	}

217
	if (buf_ops == NULL) {
218 219 220 221
		/*
		 * Re-read the superblock so the buffer is correctly sized,
		 * and properly verified.
		 */
L
Linus Torvalds 已提交
222
		xfs_buf_relse(bp);
223
		sector_size = sbp->sb_sectsize;
224
		buf_ops = loud ? &xfs_sb_buf_ops : &xfs_sb_quiet_buf_ops;
D
Dave Chinner 已提交
225
		goto reread;
L
Linus Torvalds 已提交
226 227
	}

228
	mp->m_features |= xfs_sb_version_to_features(sbp);
D
Dave Chinner 已提交
229
	xfs_reinit_percpu_counters(mp);
230

231 232 233
	/* no need to be quiet anymore, so reset the buf ops */
	bp->b_ops = &xfs_sb_buf_ops;

L
Linus Torvalds 已提交
234
	mp->m_sb_bp = bp;
D
Dave Chinner 已提交
235
	xfs_buf_unlock(bp);
L
Linus Torvalds 已提交
236 237
	return 0;

D
Dave Chinner 已提交
238 239
release_buf:
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
240 241 242
	return error;
}

243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278
/*
 * If the sunit/swidth change would move the precomputed root inode value, we
 * must reject the ondisk change because repair will stumble over that.
 * However, we allow the mount to proceed because we never rejected this
 * combination before.  Returns true to update the sb, false otherwise.
 */
static inline int
xfs_check_new_dalign(
	struct xfs_mount	*mp,
	int			new_dalign,
	bool			*update_sb)
{
	struct xfs_sb		*sbp = &mp->m_sb;
	xfs_ino_t		calc_ino;

	calc_ino = xfs_ialloc_calc_rootino(mp, new_dalign);
	trace_xfs_check_new_dalign(mp, new_dalign, calc_ino);

	if (sbp->sb_rootino == calc_ino) {
		*update_sb = true;
		return 0;
	}

	xfs_warn(mp,
"Cannot change stripe alignment; would require moving root inode.");

	/*
	 * XXX: Next time we add a new incompat feature, this should start
	 * returning -EINVAL to fail the mount.  Until then, spit out a warning
	 * that we're ignoring the administrator's instructions.
	 */
	xfs_warn(mp, "Skipping superblock stripe alignment update.");
	*update_sb = false;
	return 0;
}

L
Linus Torvalds 已提交
279
/*
280 281 282 283
 * If we were provided with new sunit/swidth values as mount options, make sure
 * that they pass basic alignment and superblock feature checks, and convert
 * them into the same units (FSB) that everything else expects.  This step
 * /must/ be done before computing the inode geometry.
L
Linus Torvalds 已提交
284
 */
E
Eric Sandeen 已提交
285
STATIC int
286 287
xfs_validate_new_dalign(
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
288
{
289 290
	if (mp->m_dalign == 0)
		return 0;
L
Linus Torvalds 已提交
291

292 293 294 295 296 297 298 299 300 301 302
	/*
	 * If stripe unit and stripe width are not multiples
	 * of the fs blocksize turn off alignment.
	 */
	if ((BBTOB(mp->m_dalign) & mp->m_blockmask) ||
	    (BBTOB(mp->m_swidth) & mp->m_blockmask)) {
		xfs_warn(mp,
	"alignment check failed: sunit/swidth vs. blocksize(%d)",
			mp->m_sb.sb_blocksize);
		return -EINVAL;
	} else {
L
Linus Torvalds 已提交
303
		/*
304
		 * Convert the stripe unit and width to FSBs.
L
Linus Torvalds 已提交
305
		 */
306 307
		mp->m_dalign = XFS_BB_TO_FSBT(mp, mp->m_dalign);
		if (mp->m_dalign && (mp->m_sb.sb_agblocks % mp->m_dalign)) {
J
Jie Liu 已提交
308
			xfs_warn(mp,
309 310
		"alignment check failed: sunit/swidth vs. agsize(%d)",
				 mp->m_sb.sb_agblocks);
D
Dave Chinner 已提交
311
			return -EINVAL;
312 313
		} else if (mp->m_dalign) {
			mp->m_swidth = XFS_BB_TO_FSBT(mp, mp->m_swidth);
314 315
		} else {
			xfs_warn(mp,
316 317
		"alignment check failed: sunit(%d) less than bsize(%d)",
				 mp->m_dalign, mp->m_sb.sb_blocksize);
D
Dave Chinner 已提交
318
			return -EINVAL;
L
Linus Torvalds 已提交
319
		}
320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338
	}

	if (!xfs_sb_version_hasdalign(&mp->m_sb)) {
		xfs_warn(mp,
"cannot change alignment: superblock does not support data alignment");
		return -EINVAL;
	}

	return 0;
}

/* Update alignment values based on mount options and sb values. */
STATIC int
xfs_update_alignment(
	struct xfs_mount	*mp)
{
	struct xfs_sb		*sbp = &mp->m_sb;

	if (mp->m_dalign) {
339 340 341
		bool		update_sb;
		int		error;

342 343 344 345
		if (sbp->sb_unit == mp->m_dalign &&
		    sbp->sb_width == mp->m_swidth)
			return 0;

346 347 348 349
		error = xfs_check_new_dalign(mp, mp->m_dalign, &update_sb);
		if (error || !update_sb)
			return error;

350 351 352
		sbp->sb_unit = mp->m_dalign;
		sbp->sb_width = mp->m_swidth;
		mp->m_update_sb = true;
L
Linus Torvalds 已提交
353
	} else if ((mp->m_flags & XFS_MOUNT_NOALIGN) != XFS_MOUNT_NOALIGN &&
354
		    xfs_sb_version_hasdalign(&mp->m_sb)) {
355 356
		mp->m_dalign = sbp->sb_unit;
		mp->m_swidth = sbp->sb_width;
L
Linus Torvalds 已提交
357 358
	}

E
Eric Sandeen 已提交
359 360
	return 0;
}
L
Linus Torvalds 已提交
361

362 363 364 365 366 367 368
/*
 * precalculate the low space thresholds for dynamic speculative preallocation.
 */
void
xfs_set_low_space_thresholds(
	struct xfs_mount	*mp)
{
369 370 371
	uint64_t		dblocks = mp->m_sb.sb_dblocks;
	uint64_t		rtexts = mp->m_sb.sb_rextents;
	int			i;
372

373 374
	do_div(dblocks, 100);
	do_div(rtexts, 100);
375

376 377 378
	for (i = 0; i < XFS_LOWSP_MAX; i++) {
		mp->m_low_space[i] = dblocks * (i + 1);
		mp->m_low_rtexts[i] = rtexts * (i + 1);
379 380 381
	}
}

E
Eric Sandeen 已提交
382
/*
383
 * Check that the data (and log if separate) is an ok size.
E
Eric Sandeen 已提交
384 385
 */
STATIC int
386 387
xfs_check_sizes(
	struct xfs_mount *mp)
E
Eric Sandeen 已提交
388
{
389
	struct xfs_buf	*bp;
E
Eric Sandeen 已提交
390
	xfs_daddr_t	d;
391
	int		error;
E
Eric Sandeen 已提交
392

L
Linus Torvalds 已提交
393 394
	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_dblocks);
	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_dblocks) {
395
		xfs_warn(mp, "filesystem size mismatch detected");
D
Dave Chinner 已提交
396
		return -EFBIG;
L
Linus Torvalds 已提交
397
	}
398
	error = xfs_buf_read_uncached(mp->m_ddev_targp,
399
					d - XFS_FSS_TO_BB(mp, 1),
400 401
					XFS_FSS_TO_BB(mp, 1), 0, &bp, NULL);
	if (error) {
402
		xfs_warn(mp, "last sector read failed");
403
		return error;
L
Linus Torvalds 已提交
404
	}
405
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
406

407 408 409 410 411 412 413 414 415
	if (mp->m_logdev_targp == mp->m_ddev_targp)
		return 0;

	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_logblocks);
	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_logblocks) {
		xfs_warn(mp, "log size mismatch detected");
		return -EFBIG;
	}
	error = xfs_buf_read_uncached(mp->m_logdev_targp,
416
					d - XFS_FSB_TO_BB(mp, 1),
417 418 419 420
					XFS_FSB_TO_BB(mp, 1), 0, &bp, NULL);
	if (error) {
		xfs_warn(mp, "log device read failed");
		return error;
E
Eric Sandeen 已提交
421
	}
422
	xfs_buf_relse(bp);
E
Eric Sandeen 已提交
423 424 425
	return 0;
}

C
Christoph Hellwig 已提交
426 427 428 429 430 431 432 433 434
/*
 * Clear the quotaflags in memory and in the superblock.
 */
int
xfs_mount_reset_sbqflags(
	struct xfs_mount	*mp)
{
	mp->m_qflags = 0;

435
	/* It is OK to look at sb_qflags in the mount path without m_sb_lock. */
C
Christoph Hellwig 已提交
436 437 438 439 440 441
	if (mp->m_sb.sb_qflags == 0)
		return 0;
	spin_lock(&mp->m_sb_lock);
	mp->m_sb.sb_qflags = 0;
	spin_unlock(&mp->m_sb_lock);

442
	if (!xfs_fs_writable(mp, SB_FREEZE_WRITE))
C
Christoph Hellwig 已提交
443 444
		return 0;

445
	return xfs_sync_sb(mp, false);
C
Christoph Hellwig 已提交
446 447
}

448
uint64_t
E
Eric Sandeen 已提交
449 450
xfs_default_resblks(xfs_mount_t *mp)
{
451
	uint64_t resblks;
E
Eric Sandeen 已提交
452 453

	/*
454 455 456 457 458
	 * We default to 5% or 8192 fsbs of space reserved, whichever is
	 * smaller.  This is intended to cover concurrent allocation
	 * transactions when we initially hit enospc. These each require a 4
	 * block reservation. Hence by default we cover roughly 2000 concurrent
	 * allocation reservations.
E
Eric Sandeen 已提交
459 460 461
	 */
	resblks = mp->m_sb.sb_dblocks;
	do_div(resblks, 20);
462
	resblks = min_t(uint64_t, resblks, 8192);
E
Eric Sandeen 已提交
463 464 465
	return resblks;
}

466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493
/* Ensure the summary counts are correct. */
STATIC int
xfs_check_summary_counts(
	struct xfs_mount	*mp)
{
	/*
	 * The AG0 superblock verifier rejects in-progress filesystems,
	 * so we should never see the flag set this far into mounting.
	 */
	if (mp->m_sb.sb_inprogress) {
		xfs_err(mp, "sb_inprogress set after log recovery??");
		WARN_ON(1);
		return -EFSCORRUPTED;
	}

	/*
	 * Now the log is mounted, we know if it was an unclean shutdown or
	 * not. If it was, with the first phase of recovery has completed, we
	 * have consistent AG blocks on disk. We have not recovered EFIs yet,
	 * but they are recovered transactionally in the second recovery phase
	 * later.
	 *
	 * If the log was clean when we mounted, we can check the summary
	 * counters.  If any of them are obviously incorrect, we can recompute
	 * them from the AGF headers in the next step.
	 */
	if (XFS_LAST_UNMOUNT_WAS_CLEAN(mp) &&
	    (mp->m_sb.sb_fdblocks > mp->m_sb.sb_dblocks ||
494
	     !xfs_verify_icount(mp, mp->m_sb.sb_icount) ||
495
	     mp->m_sb.sb_ifree > mp->m_sb.sb_icount))
496
		xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
497 498 499 500 501 502 503 504 505 506 507 508 509 510

	/*
	 * We can safely re-initialise incore superblock counters from the
	 * per-ag data. These may not be correct if the filesystem was not
	 * cleanly unmounted, so we waited for recovery to finish before doing
	 * this.
	 *
	 * If the filesystem was cleanly unmounted or the previous check did
	 * not flag anything weird, then we can trust the values in the
	 * superblock to be correct and we don't need to do anything here.
	 * Otherwise, recalculate the summary counters.
	 */
	if ((!xfs_sb_version_haslazysbcount(&mp->m_sb) ||
	     XFS_LAST_UNMOUNT_WAS_CLEAN(mp)) &&
511
	    !xfs_fs_has_sickness(mp, XFS_SICK_FS_COUNTERS))
512 513 514 515 516
		return 0;

	return xfs_initialize_perag_data(mp, mp->m_sb.sb_agcount);
}

517 518 519 520
/*
 * Flush and reclaim dirty inodes in preparation for unmount. Inodes and
 * internal inode structures can be sitting in the CIL and AIL at this point,
 * so we need to unpin them, write them back and/or reclaim them before unmount
521 522
 * can proceed.  In other words, callers are required to have inactivated all
 * inodes.
523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553
 *
 * An inode cluster that has been freed can have its buffer still pinned in
 * memory because the transaction is still sitting in a iclog. The stale inodes
 * on that buffer will be pinned to the buffer until the transaction hits the
 * disk and the callbacks run. Pushing the AIL will skip the stale inodes and
 * may never see the pinned buffer, so nothing will push out the iclog and
 * unpin the buffer.
 *
 * Hence we need to force the log to unpin everything first. However, log
 * forces don't wait for the discards they issue to complete, so we have to
 * explicitly wait for them to complete here as well.
 *
 * Then we can tell the world we are unmounting so that error handling knows
 * that the filesystem is going away and we should error out anything that we
 * have been retrying in the background.  This will prevent never-ending
 * retries in AIL pushing from hanging the unmount.
 *
 * Finally, we can push the AIL to clean all the remaining dirty objects, then
 * reclaim the remaining inodes that are still in memory at this point in time.
 */
static void
xfs_unmount_flush_inodes(
	struct xfs_mount	*mp)
{
	xfs_log_force(mp, XFS_LOG_SYNC);
	xfs_extent_busy_wait_all(mp);
	flush_workqueue(xfs_discard_wq);

	mp->m_flags |= XFS_MOUNT_UNMOUNTING;

	xfs_ail_push_all_sync(mp->m_ail);
554
	xfs_inodegc_stop(mp);
555 556 557 558 559
	cancel_delayed_work_sync(&mp->m_reclaim_work);
	xfs_reclaim_inodes(mp);
	xfs_health_unmount(mp);
}

560 561 562 563 564 565 566 567 568 569 570 571
static void
xfs_mount_setup_inode_geom(
	struct xfs_mount	*mp)
{
	struct xfs_ino_geometry *igeo = M_IGEO(mp);

	igeo->attr_fork_offset = xfs_bmap_compute_attr_offset(mp);
	ASSERT(igeo->attr_fork_offset < XFS_LITINO(mp));

	xfs_ialloc_setup_geometry(mp);
}

E
Eric Sandeen 已提交
572 573 574 575 576 577 578 579 580 581 582 583
/*
 * This function does the following on an initial mount of a file system:
 *	- reads the superblock from disk and init the mount struct
 *	- if we're a 32-bit kernel, do a size check on the superblock
 *		so we don't mount terabyte filesystems
 *	- init mount struct realtime fields
 *	- allocate inode hash table for fs
 *	- init directory manager
 *	- perform recovery and init the log manager
 */
int
xfs_mountfs(
584
	struct xfs_mount	*mp)
E
Eric Sandeen 已提交
585
{
586 587
	struct xfs_sb		*sbp = &(mp->m_sb);
	struct xfs_inode	*rip;
D
Darrick J. Wong 已提交
588
	struct xfs_ino_geometry	*igeo = M_IGEO(mp);
589
	uint64_t		resblks;
590 591 592
	uint			quotamount = 0;
	uint			quotaflags = 0;
	int			error = 0;
E
Eric Sandeen 已提交
593

594
	xfs_sb_mount_common(mp, sbp);
E
Eric Sandeen 已提交
595

596
	/*
597 598 599 600 601
	 * Check for a mismatched features2 values.  Older kernels read & wrote
	 * into the wrong sb offset for sb_features2 on some platforms due to
	 * xfs_sb_t not being 64bit size aligned when sb_features2 was added,
	 * which made older superblock reading/writing routines swap it as a
	 * 64-bit value.
602
	 *
603 604
	 * For backwards compatibility, we make both slots equal.
	 *
605 606 607 608 609 610
	 * If we detect a mismatched field, we OR the set bits into the existing
	 * features2 field in case it has already been modified; we don't want
	 * to lose any features.  We then update the bad location with the ORed
	 * value so that older kernels will see any features2 flags. The
	 * superblock writeback code ensures the new sb_features2 is copied to
	 * sb_bad_features2 before it is logged or written to disk.
611
	 */
612
	if (xfs_sb_has_mismatched_features2(sbp)) {
613
		xfs_warn(mp, "correcting sb_features alignment problem");
614
		sbp->sb_features2 |= sbp->sb_bad_features2;
615
		mp->m_update_sb = true;
616 617
	}

618

619 620 621
	/* always use v2 inodes by default now */
	if (!(mp->m_sb.sb_versionnum & XFS_SB_VERSION_NLINKBIT)) {
		mp->m_sb.sb_versionnum |= XFS_SB_VERSION_NLINKBIT;
622
		mp->m_update_sb = true;
623 624
	}

E
Eric Sandeen 已提交
625
	/*
626 627 628 629
	 * If we were given new sunit/swidth options, do some basic validation
	 * checks and convert the incore dalign and swidth values to the
	 * same units (FSB) that everything else uses.  This /must/ happen
	 * before computing the inode geometry.
E
Eric Sandeen 已提交
630
	 */
631
	error = xfs_validate_new_dalign(mp);
E
Eric Sandeen 已提交
632
	if (error)
633
		goto out;
E
Eric Sandeen 已提交
634 635 636 637

	xfs_alloc_compute_maxlevels(mp);
	xfs_bmap_compute_maxlevels(mp, XFS_DATA_FORK);
	xfs_bmap_compute_maxlevels(mp, XFS_ATTR_FORK);
638
	xfs_mount_setup_inode_geom(mp);
639
	xfs_rmapbt_compute_maxlevels(mp);
640
	xfs_refcountbt_compute_maxlevels(mp);
E
Eric Sandeen 已提交
641

642 643 644 645 646 647 648 649 650 651 652
	/*
	 * Check if sb_agblocks is aligned at stripe boundary.  If sb_agblocks
	 * is NOT aligned turn off m_dalign since allocator alignment is within
	 * an ag, therefore ag has to be aligned at stripe boundary.  Note that
	 * we must compute the free space and rmap btree geometry before doing
	 * this.
	 */
	error = xfs_update_alignment(mp);
	if (error)
		goto out;

653
	/* enable fail_at_unmount as default */
654
	mp->m_fail_unmount = true;
655

656 657
	error = xfs_sysfs_init(&mp->m_kobj, &xfs_mp_ktype,
			       NULL, mp->m_super->s_id);
C
Christoph Hellwig 已提交
658 659
	if (error)
		goto out;
L
Linus Torvalds 已提交
660

661 662
	error = xfs_sysfs_init(&mp->m_stats.xs_kobj, &xfs_stats_ktype,
			       &mp->m_kobj, "stats");
B
Brian Foster 已提交
663 664 665
	if (error)
		goto out_remove_sysfs;

666
	error = xfs_error_sysfs_init(mp);
667 668 669
	if (error)
		goto out_del_stats;

670 671 672
	error = xfs_errortag_init(mp);
	if (error)
		goto out_remove_error_sysfs;
673 674 675

	error = xfs_uuid_mount(mp);
	if (error)
676
		goto out_remove_errortag;
677

E
Eric Sandeen 已提交
678
	/*
679 680
	 * Update the preferred write size based on the information from the
	 * on-disk superblock.
E
Eric Sandeen 已提交
681
	 */
682 683 684
	mp->m_allocsize_log =
		max_t(uint32_t, sbp->sb_blocklog, mp->m_allocsize_log);
	mp->m_allocsize_blocks = 1U << (mp->m_allocsize_log - sbp->sb_blocklog);
E
Eric Sandeen 已提交
685

686 687 688
	/* set the low space thresholds for dynamic preallocation */
	xfs_set_low_space_thresholds(mp);

689 690 691 692 693 694 695
	/*
	 * If enabled, sparse inode chunk alignment is expected to match the
	 * cluster size. Full inode chunk alignment must match the chunk size,
	 * but that is checked on sb read verification...
	 */
	if (xfs_sb_version_hassparseinodes(&mp->m_sb) &&
	    mp->m_sb.sb_spino_align !=
696
			XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw)) {
697 698 699
		xfs_warn(mp,
	"Sparse inode block alignment (%u) must match cluster size (%llu).",
			 mp->m_sb.sb_spino_align,
700
			 XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw));
701 702 703 704
		error = -EINVAL;
		goto out_remove_uuid;
	}

E
Eric Sandeen 已提交
705
	/*
706
	 * Check that the data (and log if separate) is an ok size.
E
Eric Sandeen 已提交
707
	 */
C
Christoph Hellwig 已提交
708
	error = xfs_check_sizes(mp);
E
Eric Sandeen 已提交
709
	if (error)
710
		goto out_remove_uuid;
E
Eric Sandeen 已提交
711

L
Linus Torvalds 已提交
712 713 714
	/*
	 * Initialize realtime fields in the mount structure
	 */
E
Eric Sandeen 已提交
715 716
	error = xfs_rtmount_init(mp);
	if (error) {
717
		xfs_warn(mp, "RT mount failed");
718
		goto out_remove_uuid;
L
Linus Torvalds 已提交
719 720 721 722 723 724
	}

	/*
	 *  Copies the low order bits of the timestamp and the randomly
	 *  set "sequence" number out of a UUID.
	 */
725 726 727 728
	mp->m_fixedfsid[0] =
		(get_unaligned_be16(&sbp->sb_uuid.b[8]) << 16) |
		 get_unaligned_be16(&sbp->sb_uuid.b[4]);
	mp->m_fixedfsid[1] = get_unaligned_be32(&sbp->sb_uuid.b[0]);
L
Linus Torvalds 已提交
729

730 731 732 733 734
	error = xfs_da_mount(mp);
	if (error) {
		xfs_warn(mp, "Failed dir/attr init: %d", error);
		goto out_remove_uuid;
	}
L
Linus Torvalds 已提交
735 736 737 738 739 740 741 742 743

	/*
	 * Initialize the precomputed transaction reservations values.
	 */
	xfs_trans_init(mp);

	/*
	 * Allocate and initialize the per-ag data.
	 */
744 745
	error = xfs_initialize_perag(mp, sbp->sb_agcount, &mp->m_maxagi);
	if (error) {
746
		xfs_warn(mp, "Failed per-ag init: %d", error);
747
		goto out_free_dir;
748
	}
L
Linus Torvalds 已提交
749

750
	if (XFS_IS_CORRUPT(mp, !sbp->sb_logblocks)) {
751
		xfs_warn(mp, "no log defined");
D
Dave Chinner 已提交
752
		error = -EFSCORRUPTED;
753 754 755
		goto out_free_perag;
	}

756 757 758 759
	error = xfs_inodegc_register_shrinker(mp);
	if (error)
		goto out_fail_wait;

L
Linus Torvalds 已提交
760
	/*
761 762 763
	 * Log's mount-time initialization. The first part of recovery can place
	 * some items on the AIL, to be handled when recovery is finished or
	 * cancelled.
L
Linus Torvalds 已提交
764
	 */
765 766 767 768
	error = xfs_log_mount(mp, mp->m_logdev_targp,
			      XFS_FSB_TO_DADDR(mp, sbp->sb_logstart),
			      XFS_FSB_TO_BB(mp, sbp->sb_logblocks));
	if (error) {
769
		xfs_warn(mp, "log mount failed");
770
		goto out_inodegc_shrinker;
L
Linus Torvalds 已提交
771 772
	}

773 774 775 776
	/* Make sure the summary counts are ok. */
	error = xfs_check_summary_counts(mp);
	if (error)
		goto out_log_dealloc;
777

778 779
	/* Enable background inode inactivation workers. */
	xfs_inodegc_start(mp);
780
	xfs_blockgc_start(mp);
781

782 783 784 785 786 787 788 789 790 791
	/*
	 * Now that we've recovered any pending superblock feature bit
	 * additions, we can finish setting up the attr2 behaviour for the
	 * mount. If no attr2 mount options were specified, the we use the
	 * behaviour specified by the superblock feature bit.
	 */
	if (!(mp->m_flags & (XFS_MOUNT_ATTR2|XFS_MOUNT_NOATTR2)) &&
	    xfs_sb_version_hasattr2(&mp->m_sb))
		mp->m_flags |= XFS_MOUNT_ATTR2;

L
Linus Torvalds 已提交
792 793 794 795
	/*
	 * Get and sanity-check the root inode.
	 * Save the pointer to it in the mount structure.
	 */
796 797
	error = xfs_iget(mp, NULL, sbp->sb_rootino, XFS_IGET_UNTRUSTED,
			 XFS_ILOCK_EXCL, &rip);
L
Linus Torvalds 已提交
798
	if (error) {
799 800 801
		xfs_warn(mp,
			"Failed to read root inode 0x%llx, error %d",
			sbp->sb_rootino, -error);
802
		goto out_log_dealloc;
L
Linus Torvalds 已提交
803 804 805 806
	}

	ASSERT(rip != NULL);

807
	if (XFS_IS_CORRUPT(mp, !S_ISDIR(VFS_I(rip)->i_mode))) {
808
		xfs_warn(mp, "corrupted root inode %llu: not a directory",
809
			(unsigned long long)rip->i_ino);
L
Linus Torvalds 已提交
810
		xfs_iunlock(rip, XFS_ILOCK_EXCL);
D
Dave Chinner 已提交
811
		error = -EFSCORRUPTED;
812
		goto out_rele_rip;
L
Linus Torvalds 已提交
813 814 815 816 817 818 819 820
	}
	mp->m_rootip = rip;	/* save it */

	xfs_iunlock(rip, XFS_ILOCK_EXCL);

	/*
	 * Initialize realtime inode pointers in the mount structure
	 */
E
Eric Sandeen 已提交
821 822
	error = xfs_rtmount_inodes(mp);
	if (error) {
L
Linus Torvalds 已提交
823 824 825
		/*
		 * Free up the root inode.
		 */
826
		xfs_warn(mp, "failed to read RT inodes");
827
		goto out_rele_rip;
L
Linus Torvalds 已提交
828 829 830
	}

	/*
831 832 833
	 * If this is a read-only mount defer the superblock updates until
	 * the next remount into writeable mode.  Otherwise we would never
	 * perform the update e.g. for the root filesystem.
L
Linus Torvalds 已提交
834
	 */
835 836
	if (mp->m_update_sb && !(mp->m_flags & XFS_MOUNT_RDONLY)) {
		error = xfs_sync_sb(mp, false);
837
		if (error) {
838
			xfs_warn(mp, "failed to write sb changes");
839
			goto out_rtunmount;
840 841
		}
	}
L
Linus Torvalds 已提交
842 843 844 845

	/*
	 * Initialise the XFS quota management subsystem for this mount
	 */
846
	if (XFS_IS_QUOTA_ON(mp)) {
C
Christoph Hellwig 已提交
847 848 849 850 851 852 853 854 855 856
		error = xfs_qm_newmount(mp, &quotamount, &quotaflags);
		if (error)
			goto out_rtunmount;
	} else {
		/*
		 * If a file system had quotas running earlier, but decided to
		 * mount without -o uquota/pquota/gquota options, revoke the
		 * quotachecked license.
		 */
		if (mp->m_sb.sb_qflags & XFS_ALL_QUOTA_ACCT) {
857
			xfs_notice(mp, "resetting quota flags");
C
Christoph Hellwig 已提交
858 859
			error = xfs_mount_reset_sbqflags(mp);
			if (error)
860
				goto out_rtunmount;
C
Christoph Hellwig 已提交
861 862
		}
	}
L
Linus Torvalds 已提交
863 864

	/*
865 866
	 * Finish recovering the file system.  This part needed to be delayed
	 * until after the root and real-time bitmap inodes were consistently
867 868 869 870
	 * read in.  Temporarily create per-AG space reservations for metadata
	 * btree shape changes because space freeing transactions (for inode
	 * inactivation) require the per-AG reservation in lieu of reserving
	 * blocks.
L
Linus Torvalds 已提交
871
	 */
872 873 874 875
	error = xfs_fs_reserve_ag_blocks(mp);
	if (error && error == -ENOSPC)
		xfs_warn(mp,
	"ENOSPC reserving per-AG metadata pool, log recovery may fail.");
C
Christoph Hellwig 已提交
876
	error = xfs_log_mount_finish(mp);
877
	xfs_fs_unreserve_ag_blocks(mp);
L
Linus Torvalds 已提交
878
	if (error) {
879
		xfs_warn(mp, "log mount finish failed");
880
		goto out_rtunmount;
L
Linus Torvalds 已提交
881 882
	}

883 884 885 886 887 888 889 890 891 892 893
	/*
	 * Now the log is fully replayed, we can transition to full read-only
	 * mode for read-only mounts. This will sync all the metadata and clean
	 * the log so that the recovery we just performed does not have to be
	 * replayed again on the next mount.
	 *
	 * We use the same quiesce mechanism as the rw->ro remount, as they are
	 * semantically identical operations.
	 */
	if ((mp->m_flags & (XFS_MOUNT_RDONLY|XFS_MOUNT_NORECOVERY)) ==
							XFS_MOUNT_RDONLY) {
B
Brian Foster 已提交
894
		xfs_log_clean(mp);
895 896
	}

L
Linus Torvalds 已提交
897 898 899
	/*
	 * Complete the quota initialisation, post-log-replay component.
	 */
C
Christoph Hellwig 已提交
900 901 902 903 904 905 906
	if (quotamount) {
		ASSERT(mp->m_qflags == 0);
		mp->m_qflags = quotaflags;

		xfs_qm_mount_quotas(mp);
	}

907 908 909 910 911 912 913
	/*
	 * Now we are mounted, reserve a small amount of unused space for
	 * privileged transactions. This is needed so that transaction
	 * space required for critical operations can dip into this pool
	 * when at ENOSPC. This is needed for operations like create with
	 * attr, unwritten extent conversion at ENOSPC, etc. Data allocations
	 * are not allowed to use this reserved space.
914 915 916
	 *
	 * This may drive us straight to ENOSPC on mount, but that implies
	 * we were already there on the last unmount. Warn if this occurs.
917
	 */
E
Eric Sandeen 已提交
918 919 920 921
	if (!(mp->m_flags & XFS_MOUNT_RDONLY)) {
		resblks = xfs_default_resblks(mp);
		error = xfs_reserve_blocks(mp, &resblks, NULL);
		if (error)
922 923
			xfs_warn(mp,
	"Unable to allocate reserve blocks. Continuing without reserve pool.");
924 925 926 927 928 929 930 931 932

		/* Recover any CoW blocks that never got remapped. */
		error = xfs_reflink_recover_cow(mp);
		if (error) {
			xfs_err(mp,
	"Error %d recovering leftover CoW allocations.", error);
			xfs_force_shutdown(mp, SHUTDOWN_CORRUPT_INCORE);
			goto out_quota;
		}
933 934 935 936 937

		/* Reserve AG blocks for future btree expansion. */
		error = xfs_fs_reserve_ag_blocks(mp);
		if (error && error != -ENOSPC)
			goto out_agresv;
E
Eric Sandeen 已提交
938
	}
939

L
Linus Torvalds 已提交
940 941
	return 0;

942 943
 out_agresv:
	xfs_fs_unreserve_ag_blocks(mp);
944 945
 out_quota:
	xfs_qm_unmount_quotas(mp);
946 947
 out_rtunmount:
	xfs_rtunmount_inodes(mp);
948
 out_rele_rip:
949
	xfs_irele(rip);
950 951
	/* Clean out dquots that might be in memory after quotacheck. */
	xfs_qm_unmount(mp);
952 953 954 955 956 957 958 959 960

	/*
	 * Inactivate all inodes that might still be in memory after a log
	 * intent recovery failure so that reclaim can free them.  Metadata
	 * inodes and the root directory shouldn't need inactivation, but the
	 * mount failed for some reason, so pull down all the state and flee.
	 */
	xfs_inodegc_flush(mp);

961
	/*
962
	 * Flush all inode reclamation work and flush the log.
963 964 965 966 967 968 969 970 971
	 * We have to do this /after/ rtunmount and qm_unmount because those
	 * two will have scheduled delayed reclaim for the rt/quota inodes.
	 *
	 * This is slightly different from the unmountfs call sequence
	 * because we could be tearing down a partially set up mount.  In
	 * particular, if log_mount_finish fails we bail out without calling
	 * qm_unmount_quotas and therefore rely on qm_unmount to release the
	 * quota inodes.
	 */
972
	xfs_unmount_flush_inodes(mp);
973
 out_log_dealloc:
974
	xfs_log_mount_cancel(mp);
975 976
 out_inodegc_shrinker:
	unregister_shrinker(&mp->m_inodegc_shrinker);
977 978
 out_fail_wait:
	if (mp->m_logdev_targp && mp->m_logdev_targp != mp->m_ddev_targp)
979 980
		xfs_buftarg_drain(mp->m_logdev_targp);
	xfs_buftarg_drain(mp->m_ddev_targp);
981
 out_free_perag:
982
	xfs_free_perag(mp);
983 984
 out_free_dir:
	xfs_da_unmount(mp);
985
 out_remove_uuid:
C
Christoph Hellwig 已提交
986
	xfs_uuid_unmount(mp);
987 988
 out_remove_errortag:
	xfs_errortag_del(mp);
989 990
 out_remove_error_sysfs:
	xfs_error_sysfs_del(mp);
991 992
 out_del_stats:
	xfs_sysfs_del(&mp->m_stats.xs_kobj);
B
Brian Foster 已提交
993 994
 out_remove_sysfs:
	xfs_sysfs_del(&mp->m_kobj);
995
 out:
L
Linus Torvalds 已提交
996 997 998 999 1000 1001 1002
	return error;
}

/*
 * This flushes out the inodes,dquots and the superblock, unmounts the
 * log and makes sure that incore structures are freed.
 */
1003 1004 1005
void
xfs_unmountfs(
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
1006
{
1007
	uint64_t		resblks;
1008
	int			error;
L
Linus Torvalds 已提交
1009

1010 1011 1012 1013 1014 1015 1016 1017 1018 1019
	/*
	 * Perform all on-disk metadata updates required to inactivate inodes
	 * that the VFS evicted earlier in the unmount process.  Freeing inodes
	 * and discarding CoW fork preallocations can cause shape changes to
	 * the free inode and refcount btrees, respectively, so we must finish
	 * this before we discard the metadata space reservations.  Metadata
	 * inodes and the root directory do not require inactivation.
	 */
	xfs_inodegc_flush(mp);

1020
	xfs_blockgc_stop(mp);
1021
	xfs_fs_unreserve_ag_blocks(mp);
C
Christoph Hellwig 已提交
1022
	xfs_qm_unmount_quotas(mp);
1023
	xfs_rtunmount_inodes(mp);
1024
	xfs_irele(mp->m_rootip);
1025

1026
	xfs_unmount_flush_inodes(mp);
L
Linus Torvalds 已提交
1027

C
Christoph Hellwig 已提交
1028
	xfs_qm_unmount(mp);
1029

1030 1031 1032 1033
	/*
	 * Unreserve any blocks we have so that when we unmount we don't account
	 * the reserved free space as used. This is really only necessary for
	 * lazy superblock counting because it trusts the incore superblock
M
Malcolm Parsons 已提交
1034
	 * counters to be absolutely correct on clean unmount.
1035 1036 1037 1038 1039 1040 1041 1042 1043 1044
	 *
	 * We don't bother correcting this elsewhere for lazy superblock
	 * counting because on mount of an unclean filesystem we reconstruct the
	 * correct counter value and this is irrelevant.
	 *
	 * For non-lazy counter filesystems, this doesn't matter at all because
	 * we only every apply deltas to the superblock and hence the incore
	 * value does not matter....
	 */
	resblks = 0;
1045 1046
	error = xfs_reserve_blocks(mp, &resblks, NULL);
	if (error)
1047
		xfs_warn(mp, "Unable to free reserved block pool. "
1048 1049
				"Freespace may not be correct on next mount.");

1050
	xfs_log_unmount(mp);
1051
	xfs_da_unmount(mp);
C
Christoph Hellwig 已提交
1052
	xfs_uuid_unmount(mp);
L
Linus Torvalds 已提交
1053

C
Christoph Hellwig 已提交
1054
#if defined(DEBUG)
1055
	xfs_errortag_clearall(mp);
L
Linus Torvalds 已提交
1056
#endif
1057
	unregister_shrinker(&mp->m_inodegc_shrinker);
1058
	xfs_free_perag(mp);
B
Brian Foster 已提交
1059

1060
	xfs_errortag_del(mp);
1061
	xfs_error_sysfs_del(mp);
1062
	xfs_sysfs_del(&mp->m_stats.xs_kobj);
B
Brian Foster 已提交
1063
	xfs_sysfs_del(&mp->m_kobj);
L
Linus Torvalds 已提交
1064 1065
}

1066 1067 1068 1069 1070 1071 1072 1073 1074 1075
/*
 * Determine whether modifications can proceed. The caller specifies the minimum
 * freeze level for which modifications should not be allowed. This allows
 * certain operations to proceed while the freeze sequence is in progress, if
 * necessary.
 */
bool
xfs_fs_writable(
	struct xfs_mount	*mp,
	int			level)
D
David Chinner 已提交
1076
{
1077 1078 1079 1080 1081 1082
	ASSERT(level > SB_UNFROZEN);
	if ((mp->m_super->s_writers.frozen >= level) ||
	    XFS_FORCED_SHUTDOWN(mp) || (mp->m_flags & XFS_MOUNT_RDONLY))
		return false;

	return true;
D
David Chinner 已提交
1083 1084
}

1085 1086 1087 1088 1089 1090 1091 1092 1093
int
xfs_mod_fdblocks(
	struct xfs_mount	*mp,
	int64_t			delta,
	bool			rsvd)
{
	int64_t			lcounter;
	long long		res_used;
	s32			batch;
1094
	uint64_t		set_aside;
1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127

	if (delta > 0) {
		/*
		 * If the reserve pool is depleted, put blocks back into it
		 * first. Most of the time the pool is full.
		 */
		if (likely(mp->m_resblks == mp->m_resblks_avail)) {
			percpu_counter_add(&mp->m_fdblocks, delta);
			return 0;
		}

		spin_lock(&mp->m_sb_lock);
		res_used = (long long)(mp->m_resblks - mp->m_resblks_avail);

		if (res_used > delta) {
			mp->m_resblks_avail += delta;
		} else {
			delta -= res_used;
			mp->m_resblks_avail = mp->m_resblks;
			percpu_counter_add(&mp->m_fdblocks, delta);
		}
		spin_unlock(&mp->m_sb_lock);
		return 0;
	}

	/*
	 * Taking blocks away, need to be more accurate the closer we
	 * are to zero.
	 *
	 * If the counter has a value of less than 2 * max batch size,
	 * then make everything serialise as we are real close to
	 * ENOSPC.
	 */
1128 1129
	if (__percpu_counter_compare(&mp->m_fdblocks, 2 * XFS_FDBLOCKS_BATCH,
				     XFS_FDBLOCKS_BATCH) < 0)
1130 1131
		batch = 1;
	else
1132
		batch = XFS_FDBLOCKS_BATCH;
1133

1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145
	/*
	 * Set aside allocbt blocks because these blocks are tracked as free
	 * space but not available for allocation. Technically this means that a
	 * single reservation cannot consume all remaining free space, but the
	 * ratio of allocbt blocks to usable free blocks should be rather small.
	 * The tradeoff without this is that filesystems that maintain high
	 * perag block reservations can over reserve physical block availability
	 * and fail physical allocation, which leads to much more serious
	 * problems (i.e. transaction abort, pagecache discards, etc.) than
	 * slightly premature -ENOSPC.
	 */
	set_aside = mp->m_alloc_set_aside + atomic64_read(&mp->m_allocbt_blks);
1146
	percpu_counter_add_batch(&mp->m_fdblocks, delta, batch);
1147
	if (__percpu_counter_compare(&mp->m_fdblocks, set_aside,
1148
				     XFS_FDBLOCKS_BATCH) >= 0) {
1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167
		/* we had space! */
		return 0;
	}

	/*
	 * lock up the sb for dipping into reserves before releasing the space
	 * that took us to ENOSPC.
	 */
	spin_lock(&mp->m_sb_lock);
	percpu_counter_add(&mp->m_fdblocks, -delta);
	if (!rsvd)
		goto fdblocks_enospc;

	lcounter = (long long)mp->m_resblks_avail + delta;
	if (lcounter >= 0) {
		mp->m_resblks_avail = lcounter;
		spin_unlock(&mp->m_sb_lock);
		return 0;
	}
1168 1169 1170
	xfs_warn_once(mp,
"Reserve blocks depleted! Consider increasing reserve pool size.");

1171 1172 1173 1174 1175
fdblocks_enospc:
	spin_unlock(&mp->m_sb_lock);
	return -ENOSPC;
}

D
Dave Chinner 已提交
1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193
int
xfs_mod_frextents(
	struct xfs_mount	*mp,
	int64_t			delta)
{
	int64_t			lcounter;
	int			ret = 0;

	spin_lock(&mp->m_sb_lock);
	lcounter = mp->m_sb.sb_frextents + delta;
	if (lcounter < 0)
		ret = -ENOSPC;
	else
		mp->m_sb.sb_frextents = lcounter;
	spin_unlock(&mp->m_sb_lock);
	return ret;
}

L
Linus Torvalds 已提交
1194 1195 1196 1197 1198
/*
 * Used to free the superblock along various error paths.
 */
void
xfs_freesb(
D
Dave Chinner 已提交
1199
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
1200
{
D
Dave Chinner 已提交
1201
	struct xfs_buf		*bp = mp->m_sb_bp;
L
Linus Torvalds 已提交
1202

D
Dave Chinner 已提交
1203
	xfs_buf_lock(bp);
L
Linus Torvalds 已提交
1204
	mp->m_sb_bp = NULL;
D
Dave Chinner 已提交
1205
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
1206 1207
}

1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219
/*
 * If the underlying (data/log/rt) device is readonly, there are some
 * operations that cannot proceed.
 */
int
xfs_dev_is_read_only(
	struct xfs_mount	*mp,
	char			*message)
{
	if (xfs_readonly_buftarg(mp->m_ddev_targp) ||
	    xfs_readonly_buftarg(mp->m_logdev_targp) ||
	    (mp->m_rtdev_targp && xfs_readonly_buftarg(mp->m_rtdev_targp))) {
1220 1221
		xfs_notice(mp, "%s required on read-only device.", message);
		xfs_notice(mp, "write access unavailable, cannot proceed.");
D
Dave Chinner 已提交
1222
		return -EROFS;
1223 1224 1225
	}
	return 0;
}
1226 1227 1228 1229 1230 1231 1232 1233 1234

/* Force the summary counters to be recalculated at next mount. */
void
xfs_force_summary_recalc(
	struct xfs_mount	*mp)
{
	if (!xfs_sb_version_haslazysbcount(&mp->m_sb))
		return;

1235
	xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
1236
}
1237

1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347
/*
 * Enable a log incompat feature flag in the primary superblock.  The caller
 * cannot have any other transactions in progress.
 */
int
xfs_add_incompat_log_feature(
	struct xfs_mount	*mp,
	uint32_t		feature)
{
	struct xfs_dsb		*dsb;
	int			error;

	ASSERT(hweight32(feature) == 1);
	ASSERT(!(feature & XFS_SB_FEAT_INCOMPAT_LOG_UNKNOWN));

	/*
	 * Force the log to disk and kick the background AIL thread to reduce
	 * the chances that the bwrite will stall waiting for the AIL to unpin
	 * the primary superblock buffer.  This isn't a data integrity
	 * operation, so we don't need a synchronous push.
	 */
	error = xfs_log_force(mp, XFS_LOG_SYNC);
	if (error)
		return error;
	xfs_ail_push_all(mp->m_ail);

	/*
	 * Lock the primary superblock buffer to serialize all callers that
	 * are trying to set feature bits.
	 */
	xfs_buf_lock(mp->m_sb_bp);
	xfs_buf_hold(mp->m_sb_bp);

	if (XFS_FORCED_SHUTDOWN(mp)) {
		error = -EIO;
		goto rele;
	}

	if (xfs_sb_has_incompat_log_feature(&mp->m_sb, feature))
		goto rele;

	/*
	 * Write the primary superblock to disk immediately, because we need
	 * the log_incompat bit to be set in the primary super now to protect
	 * the log items that we're going to commit later.
	 */
	dsb = mp->m_sb_bp->b_addr;
	xfs_sb_to_disk(dsb, &mp->m_sb);
	dsb->sb_features_log_incompat |= cpu_to_be32(feature);
	error = xfs_bwrite(mp->m_sb_bp);
	if (error)
		goto shutdown;

	/*
	 * Add the feature bits to the incore superblock before we unlock the
	 * buffer.
	 */
	xfs_sb_add_incompat_log_features(&mp->m_sb, feature);
	xfs_buf_relse(mp->m_sb_bp);

	/* Log the superblock to disk. */
	return xfs_sync_sb(mp, false);
shutdown:
	xfs_force_shutdown(mp, SHUTDOWN_META_IO_ERROR);
rele:
	xfs_buf_relse(mp->m_sb_bp);
	return error;
}

/*
 * Clear all the log incompat flags from the superblock.
 *
 * The caller cannot be in a transaction, must ensure that the log does not
 * contain any log items protected by any log incompat bit, and must ensure
 * that there are no other threads that depend on the state of the log incompat
 * feature flags in the primary super.
 *
 * Returns true if the superblock is dirty.
 */
bool
xfs_clear_incompat_log_features(
	struct xfs_mount	*mp)
{
	bool			ret = false;

	if (!xfs_sb_version_hascrc(&mp->m_sb) ||
	    !xfs_sb_has_incompat_log_feature(&mp->m_sb,
				XFS_SB_FEAT_INCOMPAT_LOG_ALL) ||
	    XFS_FORCED_SHUTDOWN(mp))
		return false;

	/*
	 * Update the incore superblock.  We synchronize on the primary super
	 * buffer lock to be consistent with the add function, though at least
	 * in theory this shouldn't be necessary.
	 */
	xfs_buf_lock(mp->m_sb_bp);
	xfs_buf_hold(mp->m_sb_bp);

	if (xfs_sb_has_incompat_log_feature(&mp->m_sb,
				XFS_SB_FEAT_INCOMPAT_LOG_ALL)) {
		xfs_info(mp, "Clearing log incompat feature flags.");
		xfs_sb_remove_incompat_log_features(&mp->m_sb);
		ret = true;
	}

	xfs_buf_relse(mp->m_sb_bp);
	return ret;
}

1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367
/*
 * Update the in-core delayed block counter.
 *
 * We prefer to update the counter without having to take a spinlock for every
 * counter update (i.e. batching).  Each change to delayed allocation
 * reservations can change can easily exceed the default percpu counter
 * batching, so we use a larger batch factor here.
 *
 * Note that we don't currently have any callers requiring fast summation
 * (e.g. percpu_counter_read) so we can use a big batch value here.
 */
#define XFS_DELALLOC_BATCH	(4096)
void
xfs_mod_delalloc(
	struct xfs_mount	*mp,
	int64_t			delta)
{
	percpu_counter_add_batch(&mp->m_delalloc_blks, delta,
			XFS_DELALLOC_BATCH);
}