common.c 21.4 KB
Newer Older
D
Dave Chinner 已提交
1
// SPDX-License-Identifier: GPL-2.0+
D
Darrick J. Wong 已提交
2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * Copyright (C) 2017 Oracle.  All Rights Reserved.
 * Author: Darrick J. Wong <darrick.wong@oracle.com>
 */
#include "xfs.h"
#include "xfs_fs.h"
#include "xfs_shared.h"
#include "xfs_format.h"
#include "xfs_trans_resv.h"
#include "xfs_mount.h"
#include "xfs_defer.h"
#include "xfs_btree.h"
#include "xfs_bit.h"
#include "xfs_log_format.h"
#include "xfs_trans.h"
#include "xfs_sb.h"
#include "xfs_inode.h"
D
Darrick J. Wong 已提交
19 20
#include "xfs_icache.h"
#include "xfs_itable.h"
D
Darrick J. Wong 已提交
21 22 23 24 25 26 27 28 29 30
#include "xfs_alloc.h"
#include "xfs_alloc_btree.h"
#include "xfs_bmap.h"
#include "xfs_bmap_btree.h"
#include "xfs_ialloc.h"
#include "xfs_ialloc_btree.h"
#include "xfs_refcount.h"
#include "xfs_refcount_btree.h"
#include "xfs_rmap.h"
#include "xfs_rmap_btree.h"
D
Darrick J. Wong 已提交
31 32
#include "xfs_log.h"
#include "xfs_trans_priv.h"
33 34
#include "xfs_attr.h"
#include "xfs_reflink.h"
D
Darrick J. Wong 已提交
35 36 37 38
#include "scrub/xfs_scrub.h"
#include "scrub/scrub.h"
#include "scrub/common.h"
#include "scrub/trace.h"
39
#include "scrub/btree.h"
40
#include "scrub/repair.h"
41
#include "scrub/health.h"
D
Darrick J. Wong 已提交
42 43 44

/* Common code for the metadata scrubbers. */

45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70
/*
 * Handling operational errors.
 *
 * The *_process_error() family of functions are used to process error return
 * codes from functions called as part of a scrub operation.
 *
 * If there's no error, we return true to tell the caller that it's ok
 * to move on to the next check in its list.
 *
 * For non-verifier errors (e.g. ENOMEM) we return false to tell the
 * caller that something bad happened, and we preserve *error so that
 * the caller can return the *error up the stack to userspace.
 *
 * Verifier errors (EFSBADCRC/EFSCORRUPTED) are recorded by setting
 * OFLAG_CORRUPT in sm_flags and the *error is cleared.  In other words,
 * we track verifier errors (and failed scrub checks) via OFLAG_CORRUPT,
 * not via return codes.  We return false to tell the caller that
 * something bad happened.  Since the error has been cleared, the caller
 * will (presumably) return that zero and scrubbing will move on to
 * whatever's next.
 *
 * ftrace can be used to record the precise metadata location and the
 * approximate code location of the failed operation.
 */

/* Check for operational errors. */
71
static bool
D
Darrick J. Wong 已提交
72
__xchk_process_error(
73
	struct xfs_scrub	*sc,
74 75 76 77 78
	xfs_agnumber_t		agno,
	xfs_agblock_t		bno,
	int			*error,
	__u32			errflag,
	void			*ret_ip)
79 80 81 82 83 84
{
	switch (*error) {
	case 0:
		return true;
	case -EDEADLOCK:
		/* Used to restart an op with deadlock avoidance. */
D
Darrick J. Wong 已提交
85
		trace_xchk_deadlock_retry(sc->ip, sc->sm, *error);
86 87 88 89
		break;
	case -EFSBADCRC:
	case -EFSCORRUPTED:
		/* Note the badness but don't abort. */
90
		sc->sm->sm_flags |= errflag;
91 92 93
		*error = 0;
		/* fall through */
	default:
D
Darrick J. Wong 已提交
94
		trace_xchk_op_error(sc, agno, bno, *error,
95
				ret_ip);
96 97 98 99 100 101
		break;
	}
	return false;
}

bool
D
Darrick J. Wong 已提交
102
xchk_process_error(
103
	struct xfs_scrub	*sc,
104 105 106
	xfs_agnumber_t		agno,
	xfs_agblock_t		bno,
	int			*error)
107
{
D
Darrick J. Wong 已提交
108
	return __xchk_process_error(sc, agno, bno, error,
109 110 111 112
			XFS_SCRUB_OFLAG_CORRUPT, __return_address);
}

bool
D
Darrick J. Wong 已提交
113
xchk_xref_process_error(
114
	struct xfs_scrub	*sc,
115 116 117
	xfs_agnumber_t		agno,
	xfs_agblock_t		bno,
	int			*error)
118
{
D
Darrick J. Wong 已提交
119
	return __xchk_process_error(sc, agno, bno, error,
120 121 122 123 124
			XFS_SCRUB_OFLAG_XFAIL, __return_address);
}

/* Check for operational errors for a file offset. */
static bool
D
Darrick J. Wong 已提交
125
__xchk_fblock_process_error(
126
	struct xfs_scrub	*sc,
127 128 129 130 131
	int			whichfork,
	xfs_fileoff_t		offset,
	int			*error,
	__u32			errflag,
	void			*ret_ip)
132 133 134 135 136 137
{
	switch (*error) {
	case 0:
		return true;
	case -EDEADLOCK:
		/* Used to restart an op with deadlock avoidance. */
D
Darrick J. Wong 已提交
138
		trace_xchk_deadlock_retry(sc->ip, sc->sm, *error);
139 140 141 142
		break;
	case -EFSBADCRC:
	case -EFSCORRUPTED:
		/* Note the badness but don't abort. */
143
		sc->sm->sm_flags |= errflag;
144 145 146
		*error = 0;
		/* fall through */
	default:
D
Darrick J. Wong 已提交
147
		trace_xchk_file_op_error(sc, whichfork, offset, *error,
148
				ret_ip);
149 150 151 152 153
		break;
	}
	return false;
}

154
bool
D
Darrick J. Wong 已提交
155
xchk_fblock_process_error(
156
	struct xfs_scrub	*sc,
157 158 159
	int			whichfork,
	xfs_fileoff_t		offset,
	int			*error)
160
{
D
Darrick J. Wong 已提交
161
	return __xchk_fblock_process_error(sc, whichfork, offset, error,
162 163 164 165
			XFS_SCRUB_OFLAG_CORRUPT, __return_address);
}

bool
D
Darrick J. Wong 已提交
166
xchk_fblock_xref_process_error(
167
	struct xfs_scrub	*sc,
168 169 170
	int			whichfork,
	xfs_fileoff_t		offset,
	int			*error)
171
{
D
Darrick J. Wong 已提交
172
	return __xchk_fblock_process_error(sc, whichfork, offset, error,
173 174 175
			XFS_SCRUB_OFLAG_XFAIL, __return_address);
}

176 177 178 179 180 181 182 183 184 185 186 187 188 189
/*
 * Handling scrub corruption/optimization/warning checks.
 *
 * The *_set_{corrupt,preen,warning}() family of functions are used to
 * record the presence of metadata that is incorrect (corrupt), could be
 * optimized somehow (preen), or should be flagged for administrative
 * review but is not incorrect (warn).
 *
 * ftrace can be used to record the precise metadata location and
 * approximate code location of the failed check.
 */

/* Record a block which could be optimized. */
void
D
Darrick J. Wong 已提交
190
xchk_block_set_preen(
191
	struct xfs_scrub	*sc,
192
	struct xfs_buf		*bp)
193 194
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_PREEN;
D
Darrick J. Wong 已提交
195
	trace_xchk_block_preen(sc, bp->b_bn, __return_address);
196 197 198 199 200 201 202 203
}

/*
 * Record an inode which could be optimized.  The trace data will
 * include the block given by bp if bp is given; otherwise it will use
 * the block location of the inode record itself.
 */
void
D
Darrick J. Wong 已提交
204
xchk_ino_set_preen(
205
	struct xfs_scrub	*sc,
206
	xfs_ino_t		ino)
207 208
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_PREEN;
D
Darrick J. Wong 已提交
209
	trace_xchk_ino_preen(sc, ino, __return_address);
210 211 212 213
}

/* Record a corrupt block. */
void
D
Darrick J. Wong 已提交
214
xchk_block_set_corrupt(
215
	struct xfs_scrub	*sc,
216
	struct xfs_buf		*bp)
217 218
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_CORRUPT;
D
Darrick J. Wong 已提交
219
	trace_xchk_block_error(sc, bp->b_bn, __return_address);
220 221
}

222 223
/* Record a corruption while cross-referencing. */
void
D
Darrick J. Wong 已提交
224
xchk_block_xref_set_corrupt(
225
	struct xfs_scrub	*sc,
226
	struct xfs_buf		*bp)
227 228
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_XCORRUPT;
D
Darrick J. Wong 已提交
229
	trace_xchk_block_error(sc, bp->b_bn, __return_address);
230 231
}

232 233 234 235 236 237
/*
 * Record a corrupt inode.  The trace data will include the block given
 * by bp if bp is given; otherwise it will use the block location of the
 * inode record itself.
 */
void
D
Darrick J. Wong 已提交
238
xchk_ino_set_corrupt(
239
	struct xfs_scrub	*sc,
240
	xfs_ino_t		ino)
241 242
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_CORRUPT;
D
Darrick J. Wong 已提交
243
	trace_xchk_ino_error(sc, ino, __return_address);
244 245
}

246 247
/* Record a corruption while cross-referencing with an inode. */
void
D
Darrick J. Wong 已提交
248
xchk_ino_xref_set_corrupt(
249
	struct xfs_scrub	*sc,
250
	xfs_ino_t		ino)
251 252
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_XCORRUPT;
D
Darrick J. Wong 已提交
253
	trace_xchk_ino_error(sc, ino, __return_address);
254 255
}

256 257
/* Record corruption in a block indexed by a file fork. */
void
D
Darrick J. Wong 已提交
258
xchk_fblock_set_corrupt(
259
	struct xfs_scrub	*sc,
260 261
	int			whichfork,
	xfs_fileoff_t		offset)
262 263
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_CORRUPT;
D
Darrick J. Wong 已提交
264
	trace_xchk_fblock_error(sc, whichfork, offset, __return_address);
265 266
}

267 268
/* Record a corruption while cross-referencing a fork block. */
void
D
Darrick J. Wong 已提交
269
xchk_fblock_xref_set_corrupt(
270
	struct xfs_scrub	*sc,
271 272
	int			whichfork,
	xfs_fileoff_t		offset)
273 274
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_XCORRUPT;
D
Darrick J. Wong 已提交
275
	trace_xchk_fblock_error(sc, whichfork, offset, __return_address);
276 277
}

278 279 280 281 282
/*
 * Warn about inodes that need administrative review but is not
 * incorrect.
 */
void
D
Darrick J. Wong 已提交
283
xchk_ino_set_warning(
284
	struct xfs_scrub	*sc,
285
	xfs_ino_t		ino)
286 287
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_WARNING;
D
Darrick J. Wong 已提交
288
	trace_xchk_ino_warning(sc, ino, __return_address);
289 290 291 292
}

/* Warn about a block indexed by a file fork that needs review. */
void
D
Darrick J. Wong 已提交
293
xchk_fblock_set_warning(
294
	struct xfs_scrub	*sc,
295 296
	int			whichfork,
	xfs_fileoff_t		offset)
297 298
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_WARNING;
D
Darrick J. Wong 已提交
299
	trace_xchk_fblock_warning(sc, whichfork, offset, __return_address);
300 301 302 303
}

/* Signal an incomplete scrub. */
void
D
Darrick J. Wong 已提交
304
xchk_set_incomplete(
305
	struct xfs_scrub	*sc)
306 307
{
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_INCOMPLETE;
D
Darrick J. Wong 已提交
308
	trace_xchk_incomplete(sc, __return_address);
309 310
}

311 312 313 314 315
/*
 * rmap scrubbing -- compute the number of blocks with a given owner,
 * at least according to the reverse mapping data.
 */

D
Darrick J. Wong 已提交
316
struct xchk_rmap_ownedby_info {
317 318
	const struct xfs_owner_info	*oinfo;
	xfs_filblks_t			*blocks;
319 320 321
};

STATIC int
D
Darrick J. Wong 已提交
322
xchk_count_rmap_ownedby_irec(
323 324 325
	struct xfs_btree_cur		*cur,
	struct xfs_rmap_irec		*rec,
	void				*priv)
326
{
327 328 329
	struct xchk_rmap_ownedby_info	*sroi = priv;
	bool				irec_attr;
	bool				oinfo_attr;
330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347

	irec_attr = rec->rm_flags & XFS_RMAP_ATTR_FORK;
	oinfo_attr = sroi->oinfo->oi_flags & XFS_OWNER_INFO_ATTR_FORK;

	if (rec->rm_owner != sroi->oinfo->oi_owner)
		return 0;

	if (XFS_RMAP_NON_INODE_OWNER(rec->rm_owner) || irec_attr == oinfo_attr)
		(*sroi->blocks) += rec->rm_blockcount;

	return 0;
}

/*
 * Calculate the number of blocks the rmap thinks are owned by something.
 * The caller should pass us an rmapbt cursor.
 */
int
D
Darrick J. Wong 已提交
348
xchk_count_rmap_ownedby_ag(
349
	struct xfs_scrub		*sc,
350
	struct xfs_btree_cur		*cur,
351
	const struct xfs_owner_info	*oinfo,
352
	xfs_filblks_t			*blocks)
353
{
354 355 356 357
	struct xchk_rmap_ownedby_info	sroi = {
		.oinfo			= oinfo,
		.blocks			= blocks,
	};
358 359

	*blocks = 0;
D
Darrick J. Wong 已提交
360
	return xfs_rmap_query_all(cur, xchk_count_rmap_ownedby_irec,
361 362 363
			&sroi);
}

364 365 366 367 368 369 370 371
/*
 * AG scrubbing
 *
 * These helpers facilitate locking an allocation group's header
 * buffers, setting up cursors for all btrees that are present, and
 * cleaning everything up once we're through.
 */

D
Darrick J. Wong 已提交
372 373 374
/* Decide if we want to return an AG header read failure. */
static inline bool
want_ag_read_header_failure(
375
	struct xfs_scrub	*sc,
376
	unsigned int		type)
D
Darrick J. Wong 已提交
377 378 379
{
	/* Return all AG header read failures when scanning btrees. */
	if (sc->sm->sm_type != XFS_SCRUB_TYPE_AGF &&
D
Darrick J. Wong 已提交
380 381
	    sc->sm->sm_type != XFS_SCRUB_TYPE_AGFL &&
	    sc->sm->sm_type != XFS_SCRUB_TYPE_AGI)
D
Darrick J. Wong 已提交
382 383 384 385 386 387 388 389 390 391 392
		return true;
	/*
	 * If we're scanning a given type of AG header, we only want to
	 * see read failures from that specific header.  We'd like the
	 * other headers to cross-check them, but this isn't required.
	 */
	if (sc->sm->sm_type == type)
		return true;
	return false;
}

393 394 395
/*
 * Grab all the headers for an AG.
 *
D
Darrick J. Wong 已提交
396
 * The headers should be released by xchk_ag_free, but as a fail
397 398 399 400
 * safe we attach all the buffers we grab to the scrub transaction so
 * they'll all be freed when we cancel it.
 */
int
D
Darrick J. Wong 已提交
401
xchk_ag_read_headers(
402
	struct xfs_scrub	*sc,
403 404 405 406
	xfs_agnumber_t		agno,
	struct xfs_buf		**agi,
	struct xfs_buf		**agf,
	struct xfs_buf		**agfl)
407
{
408 409
	struct xfs_mount	*mp = sc->mp;
	int			error;
410 411

	error = xfs_ialloc_read_agi(mp, sc->tp, agno, agi);
D
Darrick J. Wong 已提交
412
	if (error && want_ag_read_header_failure(sc, XFS_SCRUB_TYPE_AGI))
413 414 415
		goto out;

	error = xfs_alloc_read_agf(mp, sc->tp, agno, 0, agf);
D
Darrick J. Wong 已提交
416
	if (error && want_ag_read_header_failure(sc, XFS_SCRUB_TYPE_AGF))
417 418 419
		goto out;

	error = xfs_alloc_read_agfl(mp, sc->tp, agno, agfl);
D
Darrick J. Wong 已提交
420
	if (error && want_ag_read_header_failure(sc, XFS_SCRUB_TYPE_AGFL))
421
		goto out;
422
	error = 0;
423 424 425 426 427 428
out:
	return error;
}

/* Release all the AG btree cursors. */
void
D
Darrick J. Wong 已提交
429 430
xchk_ag_btcur_free(
	struct xchk_ag		*sa)
431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454
{
	if (sa->refc_cur)
		xfs_btree_del_cursor(sa->refc_cur, XFS_BTREE_ERROR);
	if (sa->rmap_cur)
		xfs_btree_del_cursor(sa->rmap_cur, XFS_BTREE_ERROR);
	if (sa->fino_cur)
		xfs_btree_del_cursor(sa->fino_cur, XFS_BTREE_ERROR);
	if (sa->ino_cur)
		xfs_btree_del_cursor(sa->ino_cur, XFS_BTREE_ERROR);
	if (sa->cnt_cur)
		xfs_btree_del_cursor(sa->cnt_cur, XFS_BTREE_ERROR);
	if (sa->bno_cur)
		xfs_btree_del_cursor(sa->bno_cur, XFS_BTREE_ERROR);

	sa->refc_cur = NULL;
	sa->rmap_cur = NULL;
	sa->fino_cur = NULL;
	sa->ino_cur = NULL;
	sa->bno_cur = NULL;
	sa->cnt_cur = NULL;
}

/* Initialize all the btree cursors for an AG. */
int
D
Darrick J. Wong 已提交
455
xchk_ag_btcur_init(
456
	struct xfs_scrub	*sc,
D
Darrick J. Wong 已提交
457
	struct xchk_ag		*sa)
458
{
459 460
	struct xfs_mount	*mp = sc->mp;
	xfs_agnumber_t		agno = sa->agno;
461

462 463 464
	xchk_perag_get(sc->mp, sa);
	if (sa->agf_bp &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_BNO)) {
465 466 467 468 469
		/* Set up a bnobt cursor for cross-referencing. */
		sa->bno_cur = xfs_allocbt_init_cursor(mp, sc->tp, sa->agf_bp,
				agno, XFS_BTNUM_BNO);
		if (!sa->bno_cur)
			goto err;
470
	}
471

472 473
	if (sa->agf_bp &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_CNT)) {
474 475 476 477 478 479 480 481
		/* Set up a cntbt cursor for cross-referencing. */
		sa->cnt_cur = xfs_allocbt_init_cursor(mp, sc->tp, sa->agf_bp,
				agno, XFS_BTNUM_CNT);
		if (!sa->cnt_cur)
			goto err;
	}

	/* Set up a inobt cursor for cross-referencing. */
482 483
	if (sa->agi_bp &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_INO)) {
484 485 486 487 488 489 490
		sa->ino_cur = xfs_inobt_init_cursor(mp, sc->tp, sa->agi_bp,
					agno, XFS_BTNUM_INO);
		if (!sa->ino_cur)
			goto err;
	}

	/* Set up a finobt cursor for cross-referencing. */
491 492
	if (sa->agi_bp && xfs_sb_version_hasfinobt(&mp->m_sb) &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_FINO)) {
493 494 495 496 497 498 499
		sa->fino_cur = xfs_inobt_init_cursor(mp, sc->tp, sa->agi_bp,
				agno, XFS_BTNUM_FINO);
		if (!sa->fino_cur)
			goto err;
	}

	/* Set up a rmapbt cursor for cross-referencing. */
500 501
	if (sa->agf_bp && xfs_sb_version_hasrmapbt(&mp->m_sb) &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_RMAP)) {
502 503 504 505 506 507 508
		sa->rmap_cur = xfs_rmapbt_init_cursor(mp, sc->tp, sa->agf_bp,
				agno);
		if (!sa->rmap_cur)
			goto err;
	}

	/* Set up a refcountbt cursor for cross-referencing. */
509 510
	if (sa->agf_bp && xfs_sb_version_hasreflink(&mp->m_sb) &&
	    xchk_ag_btree_healthy_enough(sc, sa->pag, XFS_BTNUM_REFC)) {
511
		sa->refc_cur = xfs_refcountbt_init_cursor(mp, sc->tp,
512
				sa->agf_bp, agno);
513 514 515 516 517 518 519 520 521 522 523
		if (!sa->refc_cur)
			goto err;
	}

	return 0;
err:
	return -ENOMEM;
}

/* Release the AG header context and btree cursors. */
void
D
Darrick J. Wong 已提交
524
xchk_ag_free(
525
	struct xfs_scrub	*sc,
D
Darrick J. Wong 已提交
526
	struct xchk_ag		*sa)
527
{
D
Darrick J. Wong 已提交
528
	xchk_ag_btcur_free(sa);
529 530 531 532 533 534 535 536 537 538 539 540
	if (sa->agfl_bp) {
		xfs_trans_brelse(sc->tp, sa->agfl_bp);
		sa->agfl_bp = NULL;
	}
	if (sa->agf_bp) {
		xfs_trans_brelse(sc->tp, sa->agf_bp);
		sa->agf_bp = NULL;
	}
	if (sa->agi_bp) {
		xfs_trans_brelse(sc->tp, sa->agi_bp);
		sa->agi_bp = NULL;
	}
541 542 543 544
	if (sa->pag) {
		xfs_perag_put(sa->pag);
		sa->pag = NULL;
	}
545 546 547 548 549 550 551 552 553 554 555
	sa->agno = NULLAGNUMBER;
}

/*
 * For scrub, grab the AGI and the AGF headers, in that order.  Locking
 * order requires us to get the AGI before the AGF.  We use the
 * transaction to avoid deadlocking on crosslinked metadata buffers;
 * either the caller passes one in (bmap scrub) or we have to create a
 * transaction ourselves.
 */
int
D
Darrick J. Wong 已提交
556
xchk_ag_init(
557
	struct xfs_scrub	*sc,
558
	xfs_agnumber_t		agno,
D
Darrick J. Wong 已提交
559
	struct xchk_ag		*sa)
560
{
561
	int			error;
562 563

	sa->agno = agno;
D
Darrick J. Wong 已提交
564
	error = xchk_ag_read_headers(sc, agno, &sa->agi_bp,
565 566 567 568
			&sa->agf_bp, &sa->agfl_bp);
	if (error)
		return error;

D
Darrick J. Wong 已提交
569
	return xchk_ag_btcur_init(sc, sa);
570 571
}

572 573
/*
 * Grab the per-ag structure if we haven't already gotten it.  Teardown of the
D
Darrick J. Wong 已提交
574
 * xchk_ag will release it for us.
575 576
 */
void
D
Darrick J. Wong 已提交
577
xchk_perag_get(
578
	struct xfs_mount	*mp,
579
	struct xchk_ag		*sa)
580 581 582 583 584
{
	if (!sa->pag)
		sa->pag = xfs_perag_get(mp, sa->agno);
}

D
Darrick J. Wong 已提交
585 586
/* Per-scrubber setup functions */

587 588 589
/*
 * Grab an empty transaction so that we can re-grab locked buffers if
 * one of our btrees turns out to be cyclic.
590 591 592 593 594 595
 *
 * If we're going to repair something, we need to ask for the largest possible
 * log reservation so that we can handle the worst case scenario for metadata
 * updates while rebuilding a metadata item.  We also need to reserve as many
 * blocks in the head transaction as we think we're going to need to rebuild
 * the metadata object.
596 597
 */
int
D
Darrick J. Wong 已提交
598
xchk_trans_alloc(
599
	struct xfs_scrub	*sc,
600
	uint			resblks)
601
{
602 603 604 605
	if (sc->sm->sm_flags & XFS_SCRUB_IFLAG_REPAIR)
		return xfs_trans_alloc(sc->mp, &M_RES(sc->mp)->tr_itruncate,
				resblks, 0, 0, &sc->tp);

606 607 608
	return xfs_trans_alloc_empty(sc->mp, &sc->tp);
}

D
Darrick J. Wong 已提交
609 610
/* Set us up with a transaction and an empty context. */
int
D
Darrick J. Wong 已提交
611
xchk_setup_fs(
612
	struct xfs_scrub	*sc,
613
	struct xfs_inode	*ip)
D
Darrick J. Wong 已提交
614
{
615
	uint			resblks;
616

617
	resblks = xrep_calc_ag_resblks(sc);
D
Darrick J. Wong 已提交
618
	return xchk_trans_alloc(sc, resblks);
D
Darrick J. Wong 已提交
619
}
D
Darrick J. Wong 已提交
620 621 622

/* Set us up with AG headers and btree cursors. */
int
D
Darrick J. Wong 已提交
623
xchk_setup_ag_btree(
624
	struct xfs_scrub	*sc,
625 626
	struct xfs_inode	*ip,
	bool			force_log)
D
Darrick J. Wong 已提交
627
{
628 629
	struct xfs_mount	*mp = sc->mp;
	int			error;
D
Darrick J. Wong 已提交
630

D
Darrick J. Wong 已提交
631 632 633 634 635 636 637
	/*
	 * If the caller asks us to checkpont the log, do so.  This
	 * expensive operation should be performed infrequently and only
	 * as a last resort.  Any caller that sets force_log should
	 * document why they need to do so.
	 */
	if (force_log) {
D
Darrick J. Wong 已提交
638
		error = xchk_checkpoint_log(mp);
D
Darrick J. Wong 已提交
639 640 641 642
		if (error)
			return error;
	}

D
Darrick J. Wong 已提交
643
	error = xchk_setup_fs(sc, ip);
D
Darrick J. Wong 已提交
644 645 646
	if (error)
		return error;

D
Darrick J. Wong 已提交
647
	return xchk_ag_init(sc, sc->sm->sm_agno, &sc->sa);
D
Darrick J. Wong 已提交
648
}
D
Darrick J. Wong 已提交
649 650 651

/* Push everything out of the log onto disk. */
int
D
Darrick J. Wong 已提交
652
xchk_checkpoint_log(
D
Darrick J. Wong 已提交
653 654 655 656
	struct xfs_mount	*mp)
{
	int			error;

657
	error = xfs_log_force(mp, XFS_LOG_SYNC);
D
Darrick J. Wong 已提交
658 659 660 661 662
	if (error)
		return error;
	xfs_ail_push_all_sync(mp->m_ail);
	return 0;
}
D
Darrick J. Wong 已提交
663 664 665 666 667 668 669

/*
 * Given an inode and the scrub control structure, grab either the
 * inode referenced in the control structure or the inode passed in.
 * The inode is not locked.
 */
int
D
Darrick J. Wong 已提交
670
xchk_get_inode(
671
	struct xfs_scrub	*sc,
672
	struct xfs_inode	*ip_in)
D
Darrick J. Wong 已提交
673
{
674 675 676 677
	struct xfs_imap		imap;
	struct xfs_mount	*mp = sc->mp;
	struct xfs_inode	*ip = NULL;
	int			error;
D
Darrick J. Wong 已提交
678 679 680 681 682 683 684 685 686 687 688 689

	/* We want to scan the inode we already had opened. */
	if (sc->sm->sm_ino == 0 || sc->sm->sm_ino == ip_in->i_ino) {
		sc->ip = ip_in;
		return 0;
	}

	/* Look up the inode, see if the generation number matches. */
	if (xfs_internal_inum(mp, sc->sm->sm_ino))
		return -ENOENT;
	error = xfs_iget(mp, NULL, sc->sm->sm_ino,
			XFS_IGET_UNTRUSTED | XFS_IGET_DONTCACHE, 0, &ip);
690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716
	switch (error) {
	case -ENOENT:
		/* Inode doesn't exist, just bail out. */
		return error;
	case 0:
		/* Got an inode, continue. */
		break;
	case -EINVAL:
		/*
		 * -EINVAL with IGET_UNTRUSTED could mean one of several
		 * things: userspace gave us an inode number that doesn't
		 * correspond to fs space, or doesn't have an inobt entry;
		 * or it could simply mean that the inode buffer failed the
		 * read verifiers.
		 *
		 * Try just the inode mapping lookup -- if it succeeds, then
		 * the inode buffer verifier failed and something needs fixing.
		 * Otherwise, we really couldn't find it so tell userspace
		 * that it no longer exists.
		 */
		error = xfs_imap(sc->mp, sc->tp, sc->sm->sm_ino, &imap,
				XFS_IGET_UNTRUSTED | XFS_IGET_DONTCACHE);
		if (error)
			return -ENOENT;
		error = -EFSCORRUPTED;
		/* fall through */
	default:
D
Darrick J. Wong 已提交
717
		trace_xchk_op_error(sc,
D
Darrick J. Wong 已提交
718 719 720 721 722 723
				XFS_INO_TO_AGNO(mp, sc->sm->sm_ino),
				XFS_INO_TO_AGBNO(mp, sc->sm->sm_ino),
				error, __return_address);
		return error;
	}
	if (VFS_I(ip)->i_generation != sc->sm->sm_gen) {
724
		xfs_irele(ip);
D
Darrick J. Wong 已提交
725 726 727 728 729 730
		return -ENOENT;
	}

	sc->ip = ip;
	return 0;
}
D
Darrick J. Wong 已提交
731 732 733

/* Set us up to scrub a file's contents. */
int
D
Darrick J. Wong 已提交
734
xchk_setup_inode_contents(
735
	struct xfs_scrub	*sc,
736 737
	struct xfs_inode	*ip,
	unsigned int		resblks)
D
Darrick J. Wong 已提交
738
{
739
	int			error;
D
Darrick J. Wong 已提交
740

D
Darrick J. Wong 已提交
741
	error = xchk_get_inode(sc, ip);
D
Darrick J. Wong 已提交
742 743 744 745 746 747
	if (error)
		return error;

	/* Got the inode, lock it and we're ready to go. */
	sc->ilock_flags = XFS_IOLOCK_EXCL | XFS_MMAPLOCK_EXCL;
	xfs_ilock(sc->ip, sc->ilock_flags);
D
Darrick J. Wong 已提交
748
	error = xchk_trans_alloc(sc, resblks);
D
Darrick J. Wong 已提交
749 750 751 752 753 754 755 756 757
	if (error)
		goto out;
	sc->ilock_flags |= XFS_ILOCK_EXCL;
	xfs_ilock(sc->ip, XFS_ILOCK_EXCL);

out:
	/* scrub teardown will unlock and release the inode for us */
	return error;
}
758 759 760 761 762 763 764

/*
 * Predicate that decides if we need to evaluate the cross-reference check.
 * If there was an error accessing the cross-reference btree, just delete
 * the cursor and skip the check.
 */
bool
D
Darrick J. Wong 已提交
765
xchk_should_check_xref(
766
	struct xfs_scrub	*sc,
767 768
	int			*error,
	struct xfs_btree_cur	**curpp)
769
{
770
	/* No point in xref if we already know we're corrupt. */
D
Darrick J. Wong 已提交
771
	if (xchk_skip_xref(sc->sm))
772 773
		return false;

774 775 776 777 778 779 780 781 782 783 784 785 786 787
	if (*error == 0)
		return true;

	if (curpp) {
		/* If we've already given up on xref, just bail out. */
		if (!*curpp)
			return false;

		/* xref error, delete cursor and bail out. */
		xfs_btree_del_cursor(*curpp, XFS_BTREE_ERROR);
		*curpp = NULL;
	}

	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_XFAIL;
D
Darrick J. Wong 已提交
788
	trace_xchk_xref_error(sc, *error, __return_address);
789 790 791 792 793 794 795 796

	/*
	 * Errors encountered during cross-referencing with another
	 * data structure should not cause this scrubber to abort.
	 */
	*error = 0;
	return false;
}
D
Darrick J. Wong 已提交
797 798 799

/* Run the structure verifiers on in-memory buffers to detect bad memory. */
void
D
Darrick J. Wong 已提交
800
xchk_buffer_recheck(
801
	struct xfs_scrub	*sc,
802
	struct xfs_buf		*bp)
D
Darrick J. Wong 已提交
803
{
804
	xfs_failaddr_t		fa;
D
Darrick J. Wong 已提交
805 806

	if (bp->b_ops == NULL) {
D
Darrick J. Wong 已提交
807
		xchk_block_set_corrupt(sc, bp);
D
Darrick J. Wong 已提交
808 809 810
		return;
	}
	if (bp->b_ops->verify_struct == NULL) {
D
Darrick J. Wong 已提交
811
		xchk_set_incomplete(sc);
D
Darrick J. Wong 已提交
812 813 814 815 816 817
		return;
	}
	fa = bp->b_ops->verify_struct(bp);
	if (!fa)
		return;
	sc->sm->sm_flags |= XFS_SCRUB_OFLAG_CORRUPT;
D
Darrick J. Wong 已提交
818
	trace_xchk_block_error(sc, bp->b_bn, fa);
D
Darrick J. Wong 已提交
819
}
820 821 822 823 824 825

/*
 * Scrub the attr/data forks of a metadata inode.  The metadata inode must be
 * pointed to by sc->ip and the ILOCK must be held.
 */
int
D
Darrick J. Wong 已提交
826
xchk_metadata_inode_forks(
827
	struct xfs_scrub	*sc)
828
{
829 830 831
	__u32			smtype;
	bool			shared;
	int			error;
832 833 834 835 836 837

	if (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT)
		return 0;

	/* Metadata inodes don't live on the rt device. */
	if (sc->ip->i_d.di_flags & XFS_DIFLAG_REALTIME) {
D
Darrick J. Wong 已提交
838
		xchk_ino_set_corrupt(sc, sc->ip->i_ino);
839 840 841 842 843
		return 0;
	}

	/* They should never participate in reflink. */
	if (xfs_is_reflink_inode(sc->ip)) {
D
Darrick J. Wong 已提交
844
		xchk_ino_set_corrupt(sc, sc->ip->i_ino);
845 846 847 848 849
		return 0;
	}

	/* They also should never have extended attributes. */
	if (xfs_inode_hasattr(sc->ip)) {
D
Darrick J. Wong 已提交
850
		xchk_ino_set_corrupt(sc, sc->ip->i_ino);
851 852 853 854 855 856
		return 0;
	}

	/* Invoke the data fork scrubber. */
	smtype = sc->sm->sm_type;
	sc->sm->sm_type = XFS_SCRUB_TYPE_BMBTD;
D
Darrick J. Wong 已提交
857
	error = xchk_bmap_data(sc);
858 859 860 861 862 863 864 865
	sc->sm->sm_type = smtype;
	if (error || (sc->sm->sm_flags & XFS_SCRUB_OFLAG_CORRUPT))
		return error;

	/* Look for incorrect shared blocks. */
	if (xfs_sb_version_hasreflink(&sc->mp->m_sb)) {
		error = xfs_reflink_inode_has_shared_extents(sc->tp, sc->ip,
				&shared);
D
Darrick J. Wong 已提交
866
		if (!xchk_fblock_process_error(sc, XFS_DATA_FORK, 0,
867 868 869
				&error))
			return error;
		if (shared)
D
Darrick J. Wong 已提交
870
			xchk_ino_set_corrupt(sc, sc->ip->i_ino);
871 872 873 874
	}

	return error;
}
875 876 877 878 879 880 881 882 883

/*
 * Try to lock an inode in violation of the usual locking order rules.  For
 * example, trying to get the IOLOCK while in transaction context, or just
 * plain breaking AG-order or inode-order inode locking rules.  Either way,
 * the only way to avoid an ABBA deadlock is to use trylock and back off if
 * we can't.
 */
int
D
Darrick J. Wong 已提交
884
xchk_ilock_inverted(
885 886 887 888 889 890 891 892 893 894 895 896
	struct xfs_inode	*ip,
	uint			lock_mode)
{
	int			i;

	for (i = 0; i < 20; i++) {
		if (xfs_ilock_nowait(ip, lock_mode))
			return 0;
		delay(1);
	}
	return -EDEADLOCK;
}