xfs_mount.c 36.4 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0
L
Linus Torvalds 已提交
2
/*
3 4
 * Copyright (c) 2000-2005 Silicon Graphics, Inc.
 * All Rights Reserved.
L
Linus Torvalds 已提交
5 6
 */
#include "xfs.h"
7
#include "xfs_fs.h"
8
#include "xfs_shared.h"
9 10 11
#include "xfs_format.h"
#include "xfs_log_format.h"
#include "xfs_trans_resv.h"
12
#include "xfs_bit.h"
L
Linus Torvalds 已提交
13 14 15
#include "xfs_sb.h"
#include "xfs_mount.h"
#include "xfs_inode.h"
16
#include "xfs_dir2.h"
17
#include "xfs_ialloc.h"
L
Linus Torvalds 已提交
18 19 20
#include "xfs_alloc.h"
#include "xfs_rtalloc.h"
#include "xfs_bmap.h"
21 22 23
#include "xfs_trans.h"
#include "xfs_trans_priv.h"
#include "xfs_log.h"
L
Linus Torvalds 已提交
24 25 26
#include "xfs_error.h"
#include "xfs_quota.h"
#include "xfs_fsops.h"
27
#include "xfs_icache.h"
B
Brian Foster 已提交
28
#include "xfs_sysfs.h"
29
#include "xfs_rmap_btree.h"
30
#include "xfs_refcount_btree.h"
31
#include "xfs_reflink.h"
32
#include "xfs_extent_busy.h"
33
#include "xfs_health.h"
34
#include "xfs_trace.h"
35
#include "xfs_ag.h"
L
Linus Torvalds 已提交
36

C
Christoph Hellwig 已提交
37 38 39 40
static DEFINE_MUTEX(xfs_uuid_table_mutex);
static int xfs_uuid_table_size;
static uuid_t *xfs_uuid_table;

41 42 43 44 45 46 47 48 49 50
void
xfs_uuid_table_free(void)
{
	if (xfs_uuid_table_size == 0)
		return;
	kmem_free(xfs_uuid_table);
	xfs_uuid_table = NULL;
	xfs_uuid_table_size = 0;
}

C
Christoph Hellwig 已提交
51 52 53 54 55 56 57 58 59 60 61
/*
 * See if the UUID is unique among mounted XFS filesystems.
 * Mount fails if UUID is nil or a FS with the same UUID is already mounted.
 */
STATIC int
xfs_uuid_mount(
	struct xfs_mount	*mp)
{
	uuid_t			*uuid = &mp->m_sb.sb_uuid;
	int			hole, i;

62
	/* Publish UUID in struct super_block */
63
	uuid_copy(&mp->m_super->s_uuid, uuid);
64

C
Christoph Hellwig 已提交
65 66 67
	if (mp->m_flags & XFS_MOUNT_NOUUID)
		return 0;

68 69
	if (uuid_is_null(uuid)) {
		xfs_warn(mp, "Filesystem has null UUID - can't mount");
D
Dave Chinner 已提交
70
		return -EINVAL;
C
Christoph Hellwig 已提交
71 72 73 74
	}

	mutex_lock(&xfs_uuid_table_mutex);
	for (i = 0, hole = -1; i < xfs_uuid_table_size; i++) {
75
		if (uuid_is_null(&xfs_uuid_table[i])) {
C
Christoph Hellwig 已提交
76 77 78 79 80 81 82 83
			hole = i;
			continue;
		}
		if (uuid_equal(uuid, &xfs_uuid_table[i]))
			goto out_duplicate;
	}

	if (hole < 0) {
C
Carlos Maiolino 已提交
84
		xfs_uuid_table = krealloc(xfs_uuid_table,
C
Christoph Hellwig 已提交
85
			(xfs_uuid_table_size + 1) * sizeof(*xfs_uuid_table),
C
Carlos Maiolino 已提交
86
			GFP_KERNEL | __GFP_NOFAIL);
C
Christoph Hellwig 已提交
87 88 89 90 91 92 93 94 95
		hole = xfs_uuid_table_size++;
	}
	xfs_uuid_table[hole] = *uuid;
	mutex_unlock(&xfs_uuid_table_mutex);

	return 0;

 out_duplicate:
	mutex_unlock(&xfs_uuid_table_mutex);
96
	xfs_warn(mp, "Filesystem has duplicate UUID %pU - can't mount", uuid);
D
Dave Chinner 已提交
97
	return -EINVAL;
C
Christoph Hellwig 已提交
98 99 100 101 102 103 104 105 106 107 108 109 110 111
}

STATIC void
xfs_uuid_unmount(
	struct xfs_mount	*mp)
{
	uuid_t			*uuid = &mp->m_sb.sb_uuid;
	int			i;

	if (mp->m_flags & XFS_MOUNT_NOUUID)
		return;

	mutex_lock(&xfs_uuid_table_mutex);
	for (i = 0; i < xfs_uuid_table_size; i++) {
112
		if (uuid_is_null(&xfs_uuid_table[i]))
C
Christoph Hellwig 已提交
113 114 115 116 117 118 119 120 121 122
			continue;
		if (!uuid_equal(uuid, &xfs_uuid_table[i]))
			continue;
		memset(&xfs_uuid_table[i], 0, sizeof(uuid_t));
		break;
	}
	ASSERT(i < xfs_uuid_table_size);
	mutex_unlock(&xfs_uuid_table_mutex);
}

123 124 125 126 127 128 129
/*
 * Check size of device based on the (data/realtime) block count.
 * Note: this check is used by the growfs code as well as mount.
 */
int
xfs_sb_validate_fsb_count(
	xfs_sb_t	*sbp,
130
	uint64_t	nblocks)
131 132 133 134
{
	ASSERT(PAGE_SHIFT >= sbp->sb_blocklog);
	ASSERT(sbp->sb_blocklog >= BBSHIFT);

C
Christoph Hellwig 已提交
135
	/* Limited by ULONG_MAX of page cache index */
136
	if (nblocks >> (PAGE_SHIFT - sbp->sb_blocklog) > ULONG_MAX)
D
Dave Chinner 已提交
137
		return -EFBIG;
138 139
	return 0;
}
L
Linus Torvalds 已提交
140 141 142 143 144 145 146

/*
 * xfs_readsb
 *
 * Does the initial read of the superblock.
 */
int
147 148 149
xfs_readsb(
	struct xfs_mount *mp,
	int		flags)
L
Linus Torvalds 已提交
150 151
{
	unsigned int	sector_size;
152 153
	struct xfs_buf	*bp;
	struct xfs_sb	*sbp = &mp->m_sb;
L
Linus Torvalds 已提交
154
	int		error;
155
	int		loud = !(flags & XFS_MFSI_QUIET);
156
	const struct xfs_buf_ops *buf_ops;
L
Linus Torvalds 已提交
157 158 159 160

	ASSERT(mp->m_sb_bp == NULL);
	ASSERT(mp->m_ddev_targp != NULL);

161 162 163 164 165 166 167 168 169 170
	/*
	 * For the initial read, we must guess at the sector
	 * size based on the block device.  It's enough to
	 * get the sb_sectsize out of the superblock and
	 * then reread with the proper length.
	 * We don't verify it yet, because it may not be complete.
	 */
	sector_size = xfs_getsize_buftarg(mp->m_ddev_targp);
	buf_ops = NULL;

L
Linus Torvalds 已提交
171
	/*
172 173 174 175
	 * Allocate a (locked) buffer to hold the superblock. This will be kept
	 * around at all times to optimize access to the superblock. Therefore,
	 * set XBF_NO_IOACCT to make sure it doesn't hold the buftarg count
	 * elevated.
L
Linus Torvalds 已提交
176
	 */
D
Dave Chinner 已提交
177
reread:
178
	error = xfs_buf_read_uncached(mp->m_ddev_targp, XFS_SB_DADDR,
179 180
				      BTOBB(sector_size), XBF_NO_IOACCT, &bp,
				      buf_ops);
181
	if (error) {
182
		if (loud)
183
			xfs_warn(mp, "SB validate failed with error %d.", error);
184
		/* bad CRC means corrupted metadata */
D
Dave Chinner 已提交
185 186
		if (error == -EFSBADCRC)
			error = -EFSCORRUPTED;
187
		return error;
188
	}
L
Linus Torvalds 已提交
189 190 191 192

	/*
	 * Initialize the mount structure from the superblock.
	 */
C
Christoph Hellwig 已提交
193
	xfs_sb_from_disk(sbp, bp->b_addr);
194 195 196 197 198 199 200 201

	/*
	 * If we haven't validated the superblock, do so now before we try
	 * to check the sector size and reread the superblock appropriately.
	 */
	if (sbp->sb_magicnum != XFS_SB_MAGIC) {
		if (loud)
			xfs_warn(mp, "Invalid superblock magic number");
D
Dave Chinner 已提交
202
		error = -EINVAL;
203 204
		goto release_buf;
	}
205

L
Linus Torvalds 已提交
206 207 208
	/*
	 * We must be able to do sector-sized and sector-aligned IO.
	 */
209
	if (sector_size > sbp->sb_sectsize) {
210 211
		if (loud)
			xfs_warn(mp, "device supports %u byte sectors (not %u)",
212
				sector_size, sbp->sb_sectsize);
D
Dave Chinner 已提交
213
		error = -ENOSYS;
D
Dave Chinner 已提交
214
		goto release_buf;
L
Linus Torvalds 已提交
215 216
	}

217
	if (buf_ops == NULL) {
218 219 220 221
		/*
		 * Re-read the superblock so the buffer is correctly sized,
		 * and properly verified.
		 */
L
Linus Torvalds 已提交
222
		xfs_buf_relse(bp);
223
		sector_size = sbp->sb_sectsize;
224
		buf_ops = loud ? &xfs_sb_buf_ops : &xfs_sb_quiet_buf_ops;
D
Dave Chinner 已提交
225
		goto reread;
L
Linus Torvalds 已提交
226 227
	}

D
Dave Chinner 已提交
228
	xfs_reinit_percpu_counters(mp);
229

230 231 232
	/* no need to be quiet anymore, so reset the buf ops */
	bp->b_ops = &xfs_sb_buf_ops;

L
Linus Torvalds 已提交
233
	mp->m_sb_bp = bp;
D
Dave Chinner 已提交
234
	xfs_buf_unlock(bp);
L
Linus Torvalds 已提交
235 236
	return 0;

D
Dave Chinner 已提交
237 238
release_buf:
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
239 240 241
	return error;
}

242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277
/*
 * If the sunit/swidth change would move the precomputed root inode value, we
 * must reject the ondisk change because repair will stumble over that.
 * However, we allow the mount to proceed because we never rejected this
 * combination before.  Returns true to update the sb, false otherwise.
 */
static inline int
xfs_check_new_dalign(
	struct xfs_mount	*mp,
	int			new_dalign,
	bool			*update_sb)
{
	struct xfs_sb		*sbp = &mp->m_sb;
	xfs_ino_t		calc_ino;

	calc_ino = xfs_ialloc_calc_rootino(mp, new_dalign);
	trace_xfs_check_new_dalign(mp, new_dalign, calc_ino);

	if (sbp->sb_rootino == calc_ino) {
		*update_sb = true;
		return 0;
	}

	xfs_warn(mp,
"Cannot change stripe alignment; would require moving root inode.");

	/*
	 * XXX: Next time we add a new incompat feature, this should start
	 * returning -EINVAL to fail the mount.  Until then, spit out a warning
	 * that we're ignoring the administrator's instructions.
	 */
	xfs_warn(mp, "Skipping superblock stripe alignment update.");
	*update_sb = false;
	return 0;
}

L
Linus Torvalds 已提交
278
/*
279 280 281 282
 * If we were provided with new sunit/swidth values as mount options, make sure
 * that they pass basic alignment and superblock feature checks, and convert
 * them into the same units (FSB) that everything else expects.  This step
 * /must/ be done before computing the inode geometry.
L
Linus Torvalds 已提交
283
 */
E
Eric Sandeen 已提交
284
STATIC int
285 286
xfs_validate_new_dalign(
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
287
{
288 289
	if (mp->m_dalign == 0)
		return 0;
L
Linus Torvalds 已提交
290

291 292 293 294 295 296 297 298 299 300 301
	/*
	 * If stripe unit and stripe width are not multiples
	 * of the fs blocksize turn off alignment.
	 */
	if ((BBTOB(mp->m_dalign) & mp->m_blockmask) ||
	    (BBTOB(mp->m_swidth) & mp->m_blockmask)) {
		xfs_warn(mp,
	"alignment check failed: sunit/swidth vs. blocksize(%d)",
			mp->m_sb.sb_blocksize);
		return -EINVAL;
	} else {
L
Linus Torvalds 已提交
302
		/*
303
		 * Convert the stripe unit and width to FSBs.
L
Linus Torvalds 已提交
304
		 */
305 306
		mp->m_dalign = XFS_BB_TO_FSBT(mp, mp->m_dalign);
		if (mp->m_dalign && (mp->m_sb.sb_agblocks % mp->m_dalign)) {
J
Jie Liu 已提交
307
			xfs_warn(mp,
308 309
		"alignment check failed: sunit/swidth vs. agsize(%d)",
				 mp->m_sb.sb_agblocks);
D
Dave Chinner 已提交
310
			return -EINVAL;
311 312
		} else if (mp->m_dalign) {
			mp->m_swidth = XFS_BB_TO_FSBT(mp, mp->m_swidth);
313 314
		} else {
			xfs_warn(mp,
315 316
		"alignment check failed: sunit(%d) less than bsize(%d)",
				 mp->m_dalign, mp->m_sb.sb_blocksize);
D
Dave Chinner 已提交
317
			return -EINVAL;
L
Linus Torvalds 已提交
318
		}
319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337
	}

	if (!xfs_sb_version_hasdalign(&mp->m_sb)) {
		xfs_warn(mp,
"cannot change alignment: superblock does not support data alignment");
		return -EINVAL;
	}

	return 0;
}

/* Update alignment values based on mount options and sb values. */
STATIC int
xfs_update_alignment(
	struct xfs_mount	*mp)
{
	struct xfs_sb		*sbp = &mp->m_sb;

	if (mp->m_dalign) {
338 339 340
		bool		update_sb;
		int		error;

341 342 343 344
		if (sbp->sb_unit == mp->m_dalign &&
		    sbp->sb_width == mp->m_swidth)
			return 0;

345 346 347 348
		error = xfs_check_new_dalign(mp, mp->m_dalign, &update_sb);
		if (error || !update_sb)
			return error;

349 350 351
		sbp->sb_unit = mp->m_dalign;
		sbp->sb_width = mp->m_swidth;
		mp->m_update_sb = true;
L
Linus Torvalds 已提交
352
	} else if ((mp->m_flags & XFS_MOUNT_NOALIGN) != XFS_MOUNT_NOALIGN &&
353
		    xfs_sb_version_hasdalign(&mp->m_sb)) {
354 355
		mp->m_dalign = sbp->sb_unit;
		mp->m_swidth = sbp->sb_width;
L
Linus Torvalds 已提交
356 357
	}

E
Eric Sandeen 已提交
358 359
	return 0;
}
L
Linus Torvalds 已提交
360

361 362 363 364 365 366 367
/*
 * precalculate the low space thresholds for dynamic speculative preallocation.
 */
void
xfs_set_low_space_thresholds(
	struct xfs_mount	*mp)
{
368 369 370
	uint64_t		dblocks = mp->m_sb.sb_dblocks;
	uint64_t		rtexts = mp->m_sb.sb_rextents;
	int			i;
371

372 373
	do_div(dblocks, 100);
	do_div(rtexts, 100);
374

375 376 377
	for (i = 0; i < XFS_LOWSP_MAX; i++) {
		mp->m_low_space[i] = dblocks * (i + 1);
		mp->m_low_rtexts[i] = rtexts * (i + 1);
378 379 380
	}
}

E
Eric Sandeen 已提交
381
/*
382
 * Check that the data (and log if separate) is an ok size.
E
Eric Sandeen 已提交
383 384
 */
STATIC int
385 386
xfs_check_sizes(
	struct xfs_mount *mp)
E
Eric Sandeen 已提交
387
{
388
	struct xfs_buf	*bp;
E
Eric Sandeen 已提交
389
	xfs_daddr_t	d;
390
	int		error;
E
Eric Sandeen 已提交
391

L
Linus Torvalds 已提交
392 393
	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_dblocks);
	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_dblocks) {
394
		xfs_warn(mp, "filesystem size mismatch detected");
D
Dave Chinner 已提交
395
		return -EFBIG;
L
Linus Torvalds 已提交
396
	}
397
	error = xfs_buf_read_uncached(mp->m_ddev_targp,
398
					d - XFS_FSS_TO_BB(mp, 1),
399 400
					XFS_FSS_TO_BB(mp, 1), 0, &bp, NULL);
	if (error) {
401
		xfs_warn(mp, "last sector read failed");
402
		return error;
L
Linus Torvalds 已提交
403
	}
404
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
405

406 407 408 409 410 411 412 413 414
	if (mp->m_logdev_targp == mp->m_ddev_targp)
		return 0;

	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_logblocks);
	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_logblocks) {
		xfs_warn(mp, "log size mismatch detected");
		return -EFBIG;
	}
	error = xfs_buf_read_uncached(mp->m_logdev_targp,
415
					d - XFS_FSB_TO_BB(mp, 1),
416 417 418 419
					XFS_FSB_TO_BB(mp, 1), 0, &bp, NULL);
	if (error) {
		xfs_warn(mp, "log device read failed");
		return error;
E
Eric Sandeen 已提交
420
	}
421
	xfs_buf_relse(bp);
E
Eric Sandeen 已提交
422 423 424
	return 0;
}

C
Christoph Hellwig 已提交
425 426 427 428 429 430 431 432 433
/*
 * Clear the quotaflags in memory and in the superblock.
 */
int
xfs_mount_reset_sbqflags(
	struct xfs_mount	*mp)
{
	mp->m_qflags = 0;

434
	/* It is OK to look at sb_qflags in the mount path without m_sb_lock. */
C
Christoph Hellwig 已提交
435 436 437 438 439 440
	if (mp->m_sb.sb_qflags == 0)
		return 0;
	spin_lock(&mp->m_sb_lock);
	mp->m_sb.sb_qflags = 0;
	spin_unlock(&mp->m_sb_lock);

441
	if (!xfs_fs_writable(mp, SB_FREEZE_WRITE))
C
Christoph Hellwig 已提交
442 443
		return 0;

444
	return xfs_sync_sb(mp, false);
C
Christoph Hellwig 已提交
445 446
}

447
uint64_t
E
Eric Sandeen 已提交
448 449
xfs_default_resblks(xfs_mount_t *mp)
{
450
	uint64_t resblks;
E
Eric Sandeen 已提交
451 452

	/*
453 454 455 456 457
	 * We default to 5% or 8192 fsbs of space reserved, whichever is
	 * smaller.  This is intended to cover concurrent allocation
	 * transactions when we initially hit enospc. These each require a 4
	 * block reservation. Hence by default we cover roughly 2000 concurrent
	 * allocation reservations.
E
Eric Sandeen 已提交
458 459 460
	 */
	resblks = mp->m_sb.sb_dblocks;
	do_div(resblks, 20);
461
	resblks = min_t(uint64_t, resblks, 8192);
E
Eric Sandeen 已提交
462 463 464
	return resblks;
}

465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492
/* Ensure the summary counts are correct. */
STATIC int
xfs_check_summary_counts(
	struct xfs_mount	*mp)
{
	/*
	 * The AG0 superblock verifier rejects in-progress filesystems,
	 * so we should never see the flag set this far into mounting.
	 */
	if (mp->m_sb.sb_inprogress) {
		xfs_err(mp, "sb_inprogress set after log recovery??");
		WARN_ON(1);
		return -EFSCORRUPTED;
	}

	/*
	 * Now the log is mounted, we know if it was an unclean shutdown or
	 * not. If it was, with the first phase of recovery has completed, we
	 * have consistent AG blocks on disk. We have not recovered EFIs yet,
	 * but they are recovered transactionally in the second recovery phase
	 * later.
	 *
	 * If the log was clean when we mounted, we can check the summary
	 * counters.  If any of them are obviously incorrect, we can recompute
	 * them from the AGF headers in the next step.
	 */
	if (XFS_LAST_UNMOUNT_WAS_CLEAN(mp) &&
	    (mp->m_sb.sb_fdblocks > mp->m_sb.sb_dblocks ||
493
	     !xfs_verify_icount(mp, mp->m_sb.sb_icount) ||
494
	     mp->m_sb.sb_ifree > mp->m_sb.sb_icount))
495
		xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
496 497 498 499 500 501 502 503 504 505 506 507 508 509

	/*
	 * We can safely re-initialise incore superblock counters from the
	 * per-ag data. These may not be correct if the filesystem was not
	 * cleanly unmounted, so we waited for recovery to finish before doing
	 * this.
	 *
	 * If the filesystem was cleanly unmounted or the previous check did
	 * not flag anything weird, then we can trust the values in the
	 * superblock to be correct and we don't need to do anything here.
	 * Otherwise, recalculate the summary counters.
	 */
	if ((!xfs_sb_version_haslazysbcount(&mp->m_sb) ||
	     XFS_LAST_UNMOUNT_WAS_CLEAN(mp)) &&
510
	    !xfs_fs_has_sickness(mp, XFS_SICK_FS_COUNTERS))
511 512 513 514 515
		return 0;

	return xfs_initialize_perag_data(mp, mp->m_sb.sb_agcount);
}

516 517 518 519
/*
 * Flush and reclaim dirty inodes in preparation for unmount. Inodes and
 * internal inode structures can be sitting in the CIL and AIL at this point,
 * so we need to unpin them, write them back and/or reclaim them before unmount
520 521
 * can proceed.  In other words, callers are required to have inactivated all
 * inodes.
522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552
 *
 * An inode cluster that has been freed can have its buffer still pinned in
 * memory because the transaction is still sitting in a iclog. The stale inodes
 * on that buffer will be pinned to the buffer until the transaction hits the
 * disk and the callbacks run. Pushing the AIL will skip the stale inodes and
 * may never see the pinned buffer, so nothing will push out the iclog and
 * unpin the buffer.
 *
 * Hence we need to force the log to unpin everything first. However, log
 * forces don't wait for the discards they issue to complete, so we have to
 * explicitly wait for them to complete here as well.
 *
 * Then we can tell the world we are unmounting so that error handling knows
 * that the filesystem is going away and we should error out anything that we
 * have been retrying in the background.  This will prevent never-ending
 * retries in AIL pushing from hanging the unmount.
 *
 * Finally, we can push the AIL to clean all the remaining dirty objects, then
 * reclaim the remaining inodes that are still in memory at this point in time.
 */
static void
xfs_unmount_flush_inodes(
	struct xfs_mount	*mp)
{
	xfs_log_force(mp, XFS_LOG_SYNC);
	xfs_extent_busy_wait_all(mp);
	flush_workqueue(xfs_discard_wq);

	mp->m_flags |= XFS_MOUNT_UNMOUNTING;

	xfs_ail_push_all_sync(mp->m_ail);
553
	xfs_inodegc_stop(mp);
554 555 556 557 558
	cancel_delayed_work_sync(&mp->m_reclaim_work);
	xfs_reclaim_inodes(mp);
	xfs_health_unmount(mp);
}

559 560 561 562 563 564 565 566 567 568 569 570
static void
xfs_mount_setup_inode_geom(
	struct xfs_mount	*mp)
{
	struct xfs_ino_geometry *igeo = M_IGEO(mp);

	igeo->attr_fork_offset = xfs_bmap_compute_attr_offset(mp);
	ASSERT(igeo->attr_fork_offset < XFS_LITINO(mp));

	xfs_ialloc_setup_geometry(mp);
}

E
Eric Sandeen 已提交
571 572 573 574 575 576 577 578 579 580 581 582
/*
 * This function does the following on an initial mount of a file system:
 *	- reads the superblock from disk and init the mount struct
 *	- if we're a 32-bit kernel, do a size check on the superblock
 *		so we don't mount terabyte filesystems
 *	- init mount struct realtime fields
 *	- allocate inode hash table for fs
 *	- init directory manager
 *	- perform recovery and init the log manager
 */
int
xfs_mountfs(
583
	struct xfs_mount	*mp)
E
Eric Sandeen 已提交
584
{
585 586
	struct xfs_sb		*sbp = &(mp->m_sb);
	struct xfs_inode	*rip;
D
Darrick J. Wong 已提交
587
	struct xfs_ino_geometry	*igeo = M_IGEO(mp);
588
	uint64_t		resblks;
589 590 591
	uint			quotamount = 0;
	uint			quotaflags = 0;
	int			error = 0;
E
Eric Sandeen 已提交
592

593
	xfs_sb_mount_common(mp, sbp);
E
Eric Sandeen 已提交
594

595
	/*
596 597 598 599 600
	 * Check for a mismatched features2 values.  Older kernels read & wrote
	 * into the wrong sb offset for sb_features2 on some platforms due to
	 * xfs_sb_t not being 64bit size aligned when sb_features2 was added,
	 * which made older superblock reading/writing routines swap it as a
	 * 64-bit value.
601
	 *
602 603
	 * For backwards compatibility, we make both slots equal.
	 *
604 605 606 607 608 609
	 * If we detect a mismatched field, we OR the set bits into the existing
	 * features2 field in case it has already been modified; we don't want
	 * to lose any features.  We then update the bad location with the ORed
	 * value so that older kernels will see any features2 flags. The
	 * superblock writeback code ensures the new sb_features2 is copied to
	 * sb_bad_features2 before it is logged or written to disk.
610
	 */
611
	if (xfs_sb_has_mismatched_features2(sbp)) {
612
		xfs_warn(mp, "correcting sb_features alignment problem");
613
		sbp->sb_features2 |= sbp->sb_bad_features2;
614
		mp->m_update_sb = true;
615 616
	}

617

618 619 620
	/* always use v2 inodes by default now */
	if (!(mp->m_sb.sb_versionnum & XFS_SB_VERSION_NLINKBIT)) {
		mp->m_sb.sb_versionnum |= XFS_SB_VERSION_NLINKBIT;
621
		mp->m_update_sb = true;
622 623
	}

E
Eric Sandeen 已提交
624
	/*
625 626 627 628
	 * If we were given new sunit/swidth options, do some basic validation
	 * checks and convert the incore dalign and swidth values to the
	 * same units (FSB) that everything else uses.  This /must/ happen
	 * before computing the inode geometry.
E
Eric Sandeen 已提交
629
	 */
630
	error = xfs_validate_new_dalign(mp);
E
Eric Sandeen 已提交
631
	if (error)
632
		goto out;
E
Eric Sandeen 已提交
633 634 635 636

	xfs_alloc_compute_maxlevels(mp);
	xfs_bmap_compute_maxlevels(mp, XFS_DATA_FORK);
	xfs_bmap_compute_maxlevels(mp, XFS_ATTR_FORK);
637
	xfs_mount_setup_inode_geom(mp);
638
	xfs_rmapbt_compute_maxlevels(mp);
639
	xfs_refcountbt_compute_maxlevels(mp);
E
Eric Sandeen 已提交
640

641 642 643 644 645 646 647 648 649 650 651
	/*
	 * Check if sb_agblocks is aligned at stripe boundary.  If sb_agblocks
	 * is NOT aligned turn off m_dalign since allocator alignment is within
	 * an ag, therefore ag has to be aligned at stripe boundary.  Note that
	 * we must compute the free space and rmap btree geometry before doing
	 * this.
	 */
	error = xfs_update_alignment(mp);
	if (error)
		goto out;

652
	/* enable fail_at_unmount as default */
653
	mp->m_fail_unmount = true;
654

655 656
	error = xfs_sysfs_init(&mp->m_kobj, &xfs_mp_ktype,
			       NULL, mp->m_super->s_id);
C
Christoph Hellwig 已提交
657 658
	if (error)
		goto out;
L
Linus Torvalds 已提交
659

660 661
	error = xfs_sysfs_init(&mp->m_stats.xs_kobj, &xfs_stats_ktype,
			       &mp->m_kobj, "stats");
B
Brian Foster 已提交
662 663 664
	if (error)
		goto out_remove_sysfs;

665
	error = xfs_error_sysfs_init(mp);
666 667 668
	if (error)
		goto out_del_stats;

669 670 671
	error = xfs_errortag_init(mp);
	if (error)
		goto out_remove_error_sysfs;
672 673 674

	error = xfs_uuid_mount(mp);
	if (error)
675
		goto out_remove_errortag;
676

E
Eric Sandeen 已提交
677
	/*
678 679
	 * Update the preferred write size based on the information from the
	 * on-disk superblock.
E
Eric Sandeen 已提交
680
	 */
681 682 683
	mp->m_allocsize_log =
		max_t(uint32_t, sbp->sb_blocklog, mp->m_allocsize_log);
	mp->m_allocsize_blocks = 1U << (mp->m_allocsize_log - sbp->sb_blocklog);
E
Eric Sandeen 已提交
684

685 686 687
	/* set the low space thresholds for dynamic preallocation */
	xfs_set_low_space_thresholds(mp);

688 689 690 691 692 693 694
	/*
	 * If enabled, sparse inode chunk alignment is expected to match the
	 * cluster size. Full inode chunk alignment must match the chunk size,
	 * but that is checked on sb read verification...
	 */
	if (xfs_sb_version_hassparseinodes(&mp->m_sb) &&
	    mp->m_sb.sb_spino_align !=
695
			XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw)) {
696 697 698
		xfs_warn(mp,
	"Sparse inode block alignment (%u) must match cluster size (%llu).",
			 mp->m_sb.sb_spino_align,
699
			 XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw));
700 701 702 703
		error = -EINVAL;
		goto out_remove_uuid;
	}

E
Eric Sandeen 已提交
704
	/*
705
	 * Check that the data (and log if separate) is an ok size.
E
Eric Sandeen 已提交
706
	 */
C
Christoph Hellwig 已提交
707
	error = xfs_check_sizes(mp);
E
Eric Sandeen 已提交
708
	if (error)
709
		goto out_remove_uuid;
E
Eric Sandeen 已提交
710

L
Linus Torvalds 已提交
711 712 713
	/*
	 * Initialize realtime fields in the mount structure
	 */
E
Eric Sandeen 已提交
714 715
	error = xfs_rtmount_init(mp);
	if (error) {
716
		xfs_warn(mp, "RT mount failed");
717
		goto out_remove_uuid;
L
Linus Torvalds 已提交
718 719 720 721 722 723
	}

	/*
	 *  Copies the low order bits of the timestamp and the randomly
	 *  set "sequence" number out of a UUID.
	 */
724 725 726 727
	mp->m_fixedfsid[0] =
		(get_unaligned_be16(&sbp->sb_uuid.b[8]) << 16) |
		 get_unaligned_be16(&sbp->sb_uuid.b[4]);
	mp->m_fixedfsid[1] = get_unaligned_be32(&sbp->sb_uuid.b[0]);
L
Linus Torvalds 已提交
728

729 730 731 732 733
	error = xfs_da_mount(mp);
	if (error) {
		xfs_warn(mp, "Failed dir/attr init: %d", error);
		goto out_remove_uuid;
	}
L
Linus Torvalds 已提交
734 735 736 737 738 739 740 741 742

	/*
	 * Initialize the precomputed transaction reservations values.
	 */
	xfs_trans_init(mp);

	/*
	 * Allocate and initialize the per-ag data.
	 */
743 744
	error = xfs_initialize_perag(mp, sbp->sb_agcount, &mp->m_maxagi);
	if (error) {
745
		xfs_warn(mp, "Failed per-ag init: %d", error);
746
		goto out_free_dir;
747
	}
L
Linus Torvalds 已提交
748

749
	if (XFS_IS_CORRUPT(mp, !sbp->sb_logblocks)) {
750
		xfs_warn(mp, "no log defined");
D
Dave Chinner 已提交
751
		error = -EFSCORRUPTED;
752 753 754
		goto out_free_perag;
	}

755 756 757 758
	error = xfs_inodegc_register_shrinker(mp);
	if (error)
		goto out_fail_wait;

L
Linus Torvalds 已提交
759
	/*
760 761 762
	 * Log's mount-time initialization. The first part of recovery can place
	 * some items on the AIL, to be handled when recovery is finished or
	 * cancelled.
L
Linus Torvalds 已提交
763
	 */
764 765 766 767
	error = xfs_log_mount(mp, mp->m_logdev_targp,
			      XFS_FSB_TO_DADDR(mp, sbp->sb_logstart),
			      XFS_FSB_TO_BB(mp, sbp->sb_logblocks));
	if (error) {
768
		xfs_warn(mp, "log mount failed");
769
		goto out_inodegc_shrinker;
L
Linus Torvalds 已提交
770 771
	}

772 773 774 775
	/* Make sure the summary counts are ok. */
	error = xfs_check_summary_counts(mp);
	if (error)
		goto out_log_dealloc;
776

777 778
	/* Enable background inode inactivation workers. */
	xfs_inodegc_start(mp);
779
	xfs_blockgc_start(mp);
780

781 782 783 784 785 786 787 788 789 790
	/*
	 * Now that we've recovered any pending superblock feature bit
	 * additions, we can finish setting up the attr2 behaviour for the
	 * mount. If no attr2 mount options were specified, the we use the
	 * behaviour specified by the superblock feature bit.
	 */
	if (!(mp->m_flags & (XFS_MOUNT_ATTR2|XFS_MOUNT_NOATTR2)) &&
	    xfs_sb_version_hasattr2(&mp->m_sb))
		mp->m_flags |= XFS_MOUNT_ATTR2;

L
Linus Torvalds 已提交
791 792 793 794
	/*
	 * Get and sanity-check the root inode.
	 * Save the pointer to it in the mount structure.
	 */
795 796
	error = xfs_iget(mp, NULL, sbp->sb_rootino, XFS_IGET_UNTRUSTED,
			 XFS_ILOCK_EXCL, &rip);
L
Linus Torvalds 已提交
797
	if (error) {
798 799 800
		xfs_warn(mp,
			"Failed to read root inode 0x%llx, error %d",
			sbp->sb_rootino, -error);
801
		goto out_log_dealloc;
L
Linus Torvalds 已提交
802 803 804 805
	}

	ASSERT(rip != NULL);

806
	if (XFS_IS_CORRUPT(mp, !S_ISDIR(VFS_I(rip)->i_mode))) {
807
		xfs_warn(mp, "corrupted root inode %llu: not a directory",
808
			(unsigned long long)rip->i_ino);
L
Linus Torvalds 已提交
809
		xfs_iunlock(rip, XFS_ILOCK_EXCL);
D
Dave Chinner 已提交
810
		error = -EFSCORRUPTED;
811
		goto out_rele_rip;
L
Linus Torvalds 已提交
812 813 814 815 816 817 818 819
	}
	mp->m_rootip = rip;	/* save it */

	xfs_iunlock(rip, XFS_ILOCK_EXCL);

	/*
	 * Initialize realtime inode pointers in the mount structure
	 */
E
Eric Sandeen 已提交
820 821
	error = xfs_rtmount_inodes(mp);
	if (error) {
L
Linus Torvalds 已提交
822 823 824
		/*
		 * Free up the root inode.
		 */
825
		xfs_warn(mp, "failed to read RT inodes");
826
		goto out_rele_rip;
L
Linus Torvalds 已提交
827 828 829
	}

	/*
830 831 832
	 * If this is a read-only mount defer the superblock updates until
	 * the next remount into writeable mode.  Otherwise we would never
	 * perform the update e.g. for the root filesystem.
L
Linus Torvalds 已提交
833
	 */
834 835
	if (mp->m_update_sb && !(mp->m_flags & XFS_MOUNT_RDONLY)) {
		error = xfs_sync_sb(mp, false);
836
		if (error) {
837
			xfs_warn(mp, "failed to write sb changes");
838
			goto out_rtunmount;
839 840
		}
	}
L
Linus Torvalds 已提交
841 842 843 844

	/*
	 * Initialise the XFS quota management subsystem for this mount
	 */
845
	if (XFS_IS_QUOTA_ON(mp)) {
C
Christoph Hellwig 已提交
846 847 848 849 850 851 852 853 854 855
		error = xfs_qm_newmount(mp, &quotamount, &quotaflags);
		if (error)
			goto out_rtunmount;
	} else {
		/*
		 * If a file system had quotas running earlier, but decided to
		 * mount without -o uquota/pquota/gquota options, revoke the
		 * quotachecked license.
		 */
		if (mp->m_sb.sb_qflags & XFS_ALL_QUOTA_ACCT) {
856
			xfs_notice(mp, "resetting quota flags");
C
Christoph Hellwig 已提交
857 858
			error = xfs_mount_reset_sbqflags(mp);
			if (error)
859
				goto out_rtunmount;
C
Christoph Hellwig 已提交
860 861
		}
	}
L
Linus Torvalds 已提交
862 863

	/*
864 865
	 * Finish recovering the file system.  This part needed to be delayed
	 * until after the root and real-time bitmap inodes were consistently
866 867 868 869
	 * read in.  Temporarily create per-AG space reservations for metadata
	 * btree shape changes because space freeing transactions (for inode
	 * inactivation) require the per-AG reservation in lieu of reserving
	 * blocks.
L
Linus Torvalds 已提交
870
	 */
871 872 873 874
	error = xfs_fs_reserve_ag_blocks(mp);
	if (error && error == -ENOSPC)
		xfs_warn(mp,
	"ENOSPC reserving per-AG metadata pool, log recovery may fail.");
C
Christoph Hellwig 已提交
875
	error = xfs_log_mount_finish(mp);
876
	xfs_fs_unreserve_ag_blocks(mp);
L
Linus Torvalds 已提交
877
	if (error) {
878
		xfs_warn(mp, "log mount finish failed");
879
		goto out_rtunmount;
L
Linus Torvalds 已提交
880 881
	}

882 883 884 885 886 887 888 889 890 891 892
	/*
	 * Now the log is fully replayed, we can transition to full read-only
	 * mode for read-only mounts. This will sync all the metadata and clean
	 * the log so that the recovery we just performed does not have to be
	 * replayed again on the next mount.
	 *
	 * We use the same quiesce mechanism as the rw->ro remount, as they are
	 * semantically identical operations.
	 */
	if ((mp->m_flags & (XFS_MOUNT_RDONLY|XFS_MOUNT_NORECOVERY)) ==
							XFS_MOUNT_RDONLY) {
B
Brian Foster 已提交
893
		xfs_log_clean(mp);
894 895
	}

L
Linus Torvalds 已提交
896 897 898
	/*
	 * Complete the quota initialisation, post-log-replay component.
	 */
C
Christoph Hellwig 已提交
899 900 901 902 903 904 905
	if (quotamount) {
		ASSERT(mp->m_qflags == 0);
		mp->m_qflags = quotaflags;

		xfs_qm_mount_quotas(mp);
	}

906 907 908 909 910 911 912
	/*
	 * Now we are mounted, reserve a small amount of unused space for
	 * privileged transactions. This is needed so that transaction
	 * space required for critical operations can dip into this pool
	 * when at ENOSPC. This is needed for operations like create with
	 * attr, unwritten extent conversion at ENOSPC, etc. Data allocations
	 * are not allowed to use this reserved space.
913 914 915
	 *
	 * This may drive us straight to ENOSPC on mount, but that implies
	 * we were already there on the last unmount. Warn if this occurs.
916
	 */
E
Eric Sandeen 已提交
917 918 919 920
	if (!(mp->m_flags & XFS_MOUNT_RDONLY)) {
		resblks = xfs_default_resblks(mp);
		error = xfs_reserve_blocks(mp, &resblks, NULL);
		if (error)
921 922
			xfs_warn(mp,
	"Unable to allocate reserve blocks. Continuing without reserve pool.");
923 924 925 926 927 928 929 930 931

		/* Recover any CoW blocks that never got remapped. */
		error = xfs_reflink_recover_cow(mp);
		if (error) {
			xfs_err(mp,
	"Error %d recovering leftover CoW allocations.", error);
			xfs_force_shutdown(mp, SHUTDOWN_CORRUPT_INCORE);
			goto out_quota;
		}
932 933 934 935 936

		/* Reserve AG blocks for future btree expansion. */
		error = xfs_fs_reserve_ag_blocks(mp);
		if (error && error != -ENOSPC)
			goto out_agresv;
E
Eric Sandeen 已提交
937
	}
938

L
Linus Torvalds 已提交
939 940
	return 0;

941 942
 out_agresv:
	xfs_fs_unreserve_ag_blocks(mp);
943 944
 out_quota:
	xfs_qm_unmount_quotas(mp);
945 946
 out_rtunmount:
	xfs_rtunmount_inodes(mp);
947
 out_rele_rip:
948
	xfs_irele(rip);
949 950
	/* Clean out dquots that might be in memory after quotacheck. */
	xfs_qm_unmount(mp);
951 952 953 954 955 956 957 958 959

	/*
	 * Inactivate all inodes that might still be in memory after a log
	 * intent recovery failure so that reclaim can free them.  Metadata
	 * inodes and the root directory shouldn't need inactivation, but the
	 * mount failed for some reason, so pull down all the state and flee.
	 */
	xfs_inodegc_flush(mp);

960
	/*
961
	 * Flush all inode reclamation work and flush the log.
962 963 964 965 966 967 968 969 970
	 * We have to do this /after/ rtunmount and qm_unmount because those
	 * two will have scheduled delayed reclaim for the rt/quota inodes.
	 *
	 * This is slightly different from the unmountfs call sequence
	 * because we could be tearing down a partially set up mount.  In
	 * particular, if log_mount_finish fails we bail out without calling
	 * qm_unmount_quotas and therefore rely on qm_unmount to release the
	 * quota inodes.
	 */
971
	xfs_unmount_flush_inodes(mp);
972
 out_log_dealloc:
973
	xfs_log_mount_cancel(mp);
974 975
 out_inodegc_shrinker:
	unregister_shrinker(&mp->m_inodegc_shrinker);
976 977
 out_fail_wait:
	if (mp->m_logdev_targp && mp->m_logdev_targp != mp->m_ddev_targp)
978 979
		xfs_buftarg_drain(mp->m_logdev_targp);
	xfs_buftarg_drain(mp->m_ddev_targp);
980
 out_free_perag:
981
	xfs_free_perag(mp);
982 983
 out_free_dir:
	xfs_da_unmount(mp);
984
 out_remove_uuid:
C
Christoph Hellwig 已提交
985
	xfs_uuid_unmount(mp);
986 987
 out_remove_errortag:
	xfs_errortag_del(mp);
988 989
 out_remove_error_sysfs:
	xfs_error_sysfs_del(mp);
990 991
 out_del_stats:
	xfs_sysfs_del(&mp->m_stats.xs_kobj);
B
Brian Foster 已提交
992 993
 out_remove_sysfs:
	xfs_sysfs_del(&mp->m_kobj);
994
 out:
L
Linus Torvalds 已提交
995 996 997 998 999 1000 1001
	return error;
}

/*
 * This flushes out the inodes,dquots and the superblock, unmounts the
 * log and makes sure that incore structures are freed.
 */
1002 1003 1004
void
xfs_unmountfs(
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
1005
{
1006
	uint64_t		resblks;
1007
	int			error;
L
Linus Torvalds 已提交
1008

1009 1010 1011 1012 1013 1014 1015 1016 1017 1018
	/*
	 * Perform all on-disk metadata updates required to inactivate inodes
	 * that the VFS evicted earlier in the unmount process.  Freeing inodes
	 * and discarding CoW fork preallocations can cause shape changes to
	 * the free inode and refcount btrees, respectively, so we must finish
	 * this before we discard the metadata space reservations.  Metadata
	 * inodes and the root directory do not require inactivation.
	 */
	xfs_inodegc_flush(mp);

1019
	xfs_blockgc_stop(mp);
1020
	xfs_fs_unreserve_ag_blocks(mp);
C
Christoph Hellwig 已提交
1021
	xfs_qm_unmount_quotas(mp);
1022
	xfs_rtunmount_inodes(mp);
1023
	xfs_irele(mp->m_rootip);
1024

1025
	xfs_unmount_flush_inodes(mp);
L
Linus Torvalds 已提交
1026

C
Christoph Hellwig 已提交
1027
	xfs_qm_unmount(mp);
1028

1029 1030 1031 1032
	/*
	 * Unreserve any blocks we have so that when we unmount we don't account
	 * the reserved free space as used. This is really only necessary for
	 * lazy superblock counting because it trusts the incore superblock
M
Malcolm Parsons 已提交
1033
	 * counters to be absolutely correct on clean unmount.
1034 1035 1036 1037 1038 1039 1040 1041 1042 1043
	 *
	 * We don't bother correcting this elsewhere for lazy superblock
	 * counting because on mount of an unclean filesystem we reconstruct the
	 * correct counter value and this is irrelevant.
	 *
	 * For non-lazy counter filesystems, this doesn't matter at all because
	 * we only every apply deltas to the superblock and hence the incore
	 * value does not matter....
	 */
	resblks = 0;
1044 1045
	error = xfs_reserve_blocks(mp, &resblks, NULL);
	if (error)
1046
		xfs_warn(mp, "Unable to free reserved block pool. "
1047 1048
				"Freespace may not be correct on next mount.");

1049
	xfs_log_unmount(mp);
1050
	xfs_da_unmount(mp);
C
Christoph Hellwig 已提交
1051
	xfs_uuid_unmount(mp);
L
Linus Torvalds 已提交
1052

C
Christoph Hellwig 已提交
1053
#if defined(DEBUG)
1054
	xfs_errortag_clearall(mp);
L
Linus Torvalds 已提交
1055
#endif
1056
	unregister_shrinker(&mp->m_inodegc_shrinker);
1057
	xfs_free_perag(mp);
B
Brian Foster 已提交
1058

1059
	xfs_errortag_del(mp);
1060
	xfs_error_sysfs_del(mp);
1061
	xfs_sysfs_del(&mp->m_stats.xs_kobj);
B
Brian Foster 已提交
1062
	xfs_sysfs_del(&mp->m_kobj);
L
Linus Torvalds 已提交
1063 1064
}

1065 1066 1067 1068 1069 1070 1071 1072 1073 1074
/*
 * Determine whether modifications can proceed. The caller specifies the minimum
 * freeze level for which modifications should not be allowed. This allows
 * certain operations to proceed while the freeze sequence is in progress, if
 * necessary.
 */
bool
xfs_fs_writable(
	struct xfs_mount	*mp,
	int			level)
D
David Chinner 已提交
1075
{
1076 1077 1078 1079 1080 1081
	ASSERT(level > SB_UNFROZEN);
	if ((mp->m_super->s_writers.frozen >= level) ||
	    XFS_FORCED_SHUTDOWN(mp) || (mp->m_flags & XFS_MOUNT_RDONLY))
		return false;

	return true;
D
David Chinner 已提交
1082 1083
}

1084 1085 1086 1087 1088 1089 1090 1091 1092
int
xfs_mod_fdblocks(
	struct xfs_mount	*mp,
	int64_t			delta,
	bool			rsvd)
{
	int64_t			lcounter;
	long long		res_used;
	s32			batch;
1093
	uint64_t		set_aside;
1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126

	if (delta > 0) {
		/*
		 * If the reserve pool is depleted, put blocks back into it
		 * first. Most of the time the pool is full.
		 */
		if (likely(mp->m_resblks == mp->m_resblks_avail)) {
			percpu_counter_add(&mp->m_fdblocks, delta);
			return 0;
		}

		spin_lock(&mp->m_sb_lock);
		res_used = (long long)(mp->m_resblks - mp->m_resblks_avail);

		if (res_used > delta) {
			mp->m_resblks_avail += delta;
		} else {
			delta -= res_used;
			mp->m_resblks_avail = mp->m_resblks;
			percpu_counter_add(&mp->m_fdblocks, delta);
		}
		spin_unlock(&mp->m_sb_lock);
		return 0;
	}

	/*
	 * Taking blocks away, need to be more accurate the closer we
	 * are to zero.
	 *
	 * If the counter has a value of less than 2 * max batch size,
	 * then make everything serialise as we are real close to
	 * ENOSPC.
	 */
1127 1128
	if (__percpu_counter_compare(&mp->m_fdblocks, 2 * XFS_FDBLOCKS_BATCH,
				     XFS_FDBLOCKS_BATCH) < 0)
1129 1130
		batch = 1;
	else
1131
		batch = XFS_FDBLOCKS_BATCH;
1132

1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144
	/*
	 * Set aside allocbt blocks because these blocks are tracked as free
	 * space but not available for allocation. Technically this means that a
	 * single reservation cannot consume all remaining free space, but the
	 * ratio of allocbt blocks to usable free blocks should be rather small.
	 * The tradeoff without this is that filesystems that maintain high
	 * perag block reservations can over reserve physical block availability
	 * and fail physical allocation, which leads to much more serious
	 * problems (i.e. transaction abort, pagecache discards, etc.) than
	 * slightly premature -ENOSPC.
	 */
	set_aside = mp->m_alloc_set_aside + atomic64_read(&mp->m_allocbt_blks);
1145
	percpu_counter_add_batch(&mp->m_fdblocks, delta, batch);
1146
	if (__percpu_counter_compare(&mp->m_fdblocks, set_aside,
1147
				     XFS_FDBLOCKS_BATCH) >= 0) {
1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166
		/* we had space! */
		return 0;
	}

	/*
	 * lock up the sb for dipping into reserves before releasing the space
	 * that took us to ENOSPC.
	 */
	spin_lock(&mp->m_sb_lock);
	percpu_counter_add(&mp->m_fdblocks, -delta);
	if (!rsvd)
		goto fdblocks_enospc;

	lcounter = (long long)mp->m_resblks_avail + delta;
	if (lcounter >= 0) {
		mp->m_resblks_avail = lcounter;
		spin_unlock(&mp->m_sb_lock);
		return 0;
	}
1167 1168 1169
	xfs_warn_once(mp,
"Reserve blocks depleted! Consider increasing reserve pool size.");

1170 1171 1172 1173 1174
fdblocks_enospc:
	spin_unlock(&mp->m_sb_lock);
	return -ENOSPC;
}

D
Dave Chinner 已提交
1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192
int
xfs_mod_frextents(
	struct xfs_mount	*mp,
	int64_t			delta)
{
	int64_t			lcounter;
	int			ret = 0;

	spin_lock(&mp->m_sb_lock);
	lcounter = mp->m_sb.sb_frextents + delta;
	if (lcounter < 0)
		ret = -ENOSPC;
	else
		mp->m_sb.sb_frextents = lcounter;
	spin_unlock(&mp->m_sb_lock);
	return ret;
}

L
Linus Torvalds 已提交
1193 1194 1195 1196 1197
/*
 * Used to free the superblock along various error paths.
 */
void
xfs_freesb(
D
Dave Chinner 已提交
1198
	struct xfs_mount	*mp)
L
Linus Torvalds 已提交
1199
{
D
Dave Chinner 已提交
1200
	struct xfs_buf		*bp = mp->m_sb_bp;
L
Linus Torvalds 已提交
1201

D
Dave Chinner 已提交
1202
	xfs_buf_lock(bp);
L
Linus Torvalds 已提交
1203
	mp->m_sb_bp = NULL;
D
Dave Chinner 已提交
1204
	xfs_buf_relse(bp);
L
Linus Torvalds 已提交
1205 1206
}

1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218
/*
 * If the underlying (data/log/rt) device is readonly, there are some
 * operations that cannot proceed.
 */
int
xfs_dev_is_read_only(
	struct xfs_mount	*mp,
	char			*message)
{
	if (xfs_readonly_buftarg(mp->m_ddev_targp) ||
	    xfs_readonly_buftarg(mp->m_logdev_targp) ||
	    (mp->m_rtdev_targp && xfs_readonly_buftarg(mp->m_rtdev_targp))) {
1219 1220
		xfs_notice(mp, "%s required on read-only device.", message);
		xfs_notice(mp, "write access unavailable, cannot proceed.");
D
Dave Chinner 已提交
1221
		return -EROFS;
1222 1223 1224
	}
	return 0;
}
1225 1226 1227 1228 1229 1230 1231 1232 1233

/* Force the summary counters to be recalculated at next mount. */
void
xfs_force_summary_recalc(
	struct xfs_mount	*mp)
{
	if (!xfs_sb_version_haslazysbcount(&mp->m_sb))
		return;

1234
	xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
1235
}
1236

1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346
/*
 * Enable a log incompat feature flag in the primary superblock.  The caller
 * cannot have any other transactions in progress.
 */
int
xfs_add_incompat_log_feature(
	struct xfs_mount	*mp,
	uint32_t		feature)
{
	struct xfs_dsb		*dsb;
	int			error;

	ASSERT(hweight32(feature) == 1);
	ASSERT(!(feature & XFS_SB_FEAT_INCOMPAT_LOG_UNKNOWN));

	/*
	 * Force the log to disk and kick the background AIL thread to reduce
	 * the chances that the bwrite will stall waiting for the AIL to unpin
	 * the primary superblock buffer.  This isn't a data integrity
	 * operation, so we don't need a synchronous push.
	 */
	error = xfs_log_force(mp, XFS_LOG_SYNC);
	if (error)
		return error;
	xfs_ail_push_all(mp->m_ail);

	/*
	 * Lock the primary superblock buffer to serialize all callers that
	 * are trying to set feature bits.
	 */
	xfs_buf_lock(mp->m_sb_bp);
	xfs_buf_hold(mp->m_sb_bp);

	if (XFS_FORCED_SHUTDOWN(mp)) {
		error = -EIO;
		goto rele;
	}

	if (xfs_sb_has_incompat_log_feature(&mp->m_sb, feature))
		goto rele;

	/*
	 * Write the primary superblock to disk immediately, because we need
	 * the log_incompat bit to be set in the primary super now to protect
	 * the log items that we're going to commit later.
	 */
	dsb = mp->m_sb_bp->b_addr;
	xfs_sb_to_disk(dsb, &mp->m_sb);
	dsb->sb_features_log_incompat |= cpu_to_be32(feature);
	error = xfs_bwrite(mp->m_sb_bp);
	if (error)
		goto shutdown;

	/*
	 * Add the feature bits to the incore superblock before we unlock the
	 * buffer.
	 */
	xfs_sb_add_incompat_log_features(&mp->m_sb, feature);
	xfs_buf_relse(mp->m_sb_bp);

	/* Log the superblock to disk. */
	return xfs_sync_sb(mp, false);
shutdown:
	xfs_force_shutdown(mp, SHUTDOWN_META_IO_ERROR);
rele:
	xfs_buf_relse(mp->m_sb_bp);
	return error;
}

/*
 * Clear all the log incompat flags from the superblock.
 *
 * The caller cannot be in a transaction, must ensure that the log does not
 * contain any log items protected by any log incompat bit, and must ensure
 * that there are no other threads that depend on the state of the log incompat
 * feature flags in the primary super.
 *
 * Returns true if the superblock is dirty.
 */
bool
xfs_clear_incompat_log_features(
	struct xfs_mount	*mp)
{
	bool			ret = false;

	if (!xfs_sb_version_hascrc(&mp->m_sb) ||
	    !xfs_sb_has_incompat_log_feature(&mp->m_sb,
				XFS_SB_FEAT_INCOMPAT_LOG_ALL) ||
	    XFS_FORCED_SHUTDOWN(mp))
		return false;

	/*
	 * Update the incore superblock.  We synchronize on the primary super
	 * buffer lock to be consistent with the add function, though at least
	 * in theory this shouldn't be necessary.
	 */
	xfs_buf_lock(mp->m_sb_bp);
	xfs_buf_hold(mp->m_sb_bp);

	if (xfs_sb_has_incompat_log_feature(&mp->m_sb,
				XFS_SB_FEAT_INCOMPAT_LOG_ALL)) {
		xfs_info(mp, "Clearing log incompat feature flags.");
		xfs_sb_remove_incompat_log_features(&mp->m_sb);
		ret = true;
	}

	xfs_buf_relse(mp->m_sb_bp);
	return ret;
}

1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366
/*
 * Update the in-core delayed block counter.
 *
 * We prefer to update the counter without having to take a spinlock for every
 * counter update (i.e. batching).  Each change to delayed allocation
 * reservations can change can easily exceed the default percpu counter
 * batching, so we use a larger batch factor here.
 *
 * Note that we don't currently have any callers requiring fast summation
 * (e.g. percpu_counter_read) so we can use a big batch value here.
 */
#define XFS_DELALLOC_BATCH	(4096)
void
xfs_mod_delalloc(
	struct xfs_mount	*mp,
	int64_t			delta)
{
	percpu_counter_add_batch(&mp->m_delalloc_blks, delta,
			XFS_DELALLOC_BATCH);
}