]> git.sesse.net Git - bcachefs-tools-debian/blob - libbcachefs/super-io.c
Update bcachefs sources to f9d2e809a8 bcachefs: Turn encoded_extent_max into a regula...
[bcachefs-tools-debian] / libbcachefs / super-io.c
1 // SPDX-License-Identifier: GPL-2.0
2
3 #include "bcachefs.h"
4 #include "btree_update_interior.h"
5 #include "buckets.h"
6 #include "checksum.h"
7 #include "disk_groups.h"
8 #include "ec.h"
9 #include "error.h"
10 #include "io.h"
11 #include "journal.h"
12 #include "journal_io.h"
13 #include "journal_seq_blacklist.h"
14 #include "replicas.h"
15 #include "quota.h"
16 #include "super-io.h"
17 #include "super.h"
18 #include "vstructs.h"
19
20 #include <linux/backing-dev.h>
21 #include <linux/sort.h>
22
23 const char * const bch2_sb_fields[] = {
24 #define x(name, nr)     #name,
25         BCH_SB_FIELDS()
26 #undef x
27         NULL
28 };
29
30 static const char *bch2_sb_field_validate(struct bch_sb *,
31                                           struct bch_sb_field *);
32
33 struct bch_sb_field *bch2_sb_field_get(struct bch_sb *sb,
34                                       enum bch_sb_field_type type)
35 {
36         struct bch_sb_field *f;
37
38         /* XXX: need locking around superblock to access optional fields */
39
40         vstruct_for_each(sb, f)
41                 if (le32_to_cpu(f->type) == type)
42                         return f;
43         return NULL;
44 }
45
46 static struct bch_sb_field *__bch2_sb_field_resize(struct bch_sb_handle *sb,
47                                                    struct bch_sb_field *f,
48                                                    unsigned u64s)
49 {
50         unsigned old_u64s = f ? le32_to_cpu(f->u64s) : 0;
51         unsigned sb_u64s = le32_to_cpu(sb->sb->u64s) + u64s - old_u64s;
52
53         BUG_ON(__vstruct_bytes(struct bch_sb, sb_u64s) > sb->buffer_size);
54
55         if (!f && !u64s) {
56                 /* nothing to do: */
57         } else if (!f) {
58                 f = vstruct_last(sb->sb);
59                 memset(f, 0, sizeof(u64) * u64s);
60                 f->u64s = cpu_to_le32(u64s);
61                 f->type = 0;
62         } else {
63                 void *src, *dst;
64
65                 src = vstruct_end(f);
66
67                 if (u64s) {
68                         f->u64s = cpu_to_le32(u64s);
69                         dst = vstruct_end(f);
70                 } else {
71                         dst = f;
72                 }
73
74                 memmove(dst, src, vstruct_end(sb->sb) - src);
75
76                 if (dst > src)
77                         memset(src, 0, dst - src);
78         }
79
80         sb->sb->u64s = cpu_to_le32(sb_u64s);
81
82         return u64s ? f : NULL;
83 }
84
85 void bch2_sb_field_delete(struct bch_sb_handle *sb,
86                           enum bch_sb_field_type type)
87 {
88         struct bch_sb_field *f = bch2_sb_field_get(sb->sb, type);
89
90         if (f)
91                 __bch2_sb_field_resize(sb, f, 0);
92 }
93
94 /* Superblock realloc/free: */
95
96 void bch2_free_super(struct bch_sb_handle *sb)
97 {
98         if (sb->bio)
99                 bio_put(sb->bio);
100         if (!IS_ERR_OR_NULL(sb->bdev))
101                 blkdev_put(sb->bdev, sb->mode);
102
103         kfree(sb->sb);
104         memset(sb, 0, sizeof(*sb));
105 }
106
107 int bch2_sb_realloc(struct bch_sb_handle *sb, unsigned u64s)
108 {
109         size_t new_bytes = __vstruct_bytes(struct bch_sb, u64s);
110         size_t new_buffer_size;
111         struct bch_sb *new_sb;
112         struct bio *bio;
113
114         if (sb->bdev)
115                 new_bytes = max_t(size_t, new_bytes, bdev_logical_block_size(sb->bdev));
116
117         new_buffer_size = roundup_pow_of_two(new_bytes);
118
119         if (sb->sb && sb->buffer_size >= new_buffer_size)
120                 return 0;
121
122         if (sb->have_layout) {
123                 u64 max_bytes = 512 << sb->sb->layout.sb_max_size_bits;
124
125                 if (new_bytes > max_bytes) {
126                         char buf[BDEVNAME_SIZE];
127
128                         pr_err("%s: superblock too big: want %zu but have %llu",
129                                bdevname(sb->bdev, buf), new_bytes, max_bytes);
130                         return -ENOSPC;
131                 }
132         }
133
134         if (sb->buffer_size >= new_buffer_size && sb->sb)
135                 return 0;
136
137         if (dynamic_fault("bcachefs:add:super_realloc"))
138                 return -ENOMEM;
139
140         if (sb->have_bio) {
141                 bio = bio_kmalloc(GFP_KERNEL,
142                         DIV_ROUND_UP(new_buffer_size, PAGE_SIZE));
143                 if (!bio)
144                         return -ENOMEM;
145
146                 if (sb->bio)
147                         bio_put(sb->bio);
148                 sb->bio = bio;
149         }
150
151         new_sb = krealloc(sb->sb, new_buffer_size, GFP_NOFS|__GFP_ZERO);
152         if (!new_sb)
153                 return -ENOMEM;
154
155         sb->sb = new_sb;
156         sb->buffer_size = new_buffer_size;
157
158         return 0;
159 }
160
161 struct bch_sb_field *bch2_sb_field_resize(struct bch_sb_handle *sb,
162                                           enum bch_sb_field_type type,
163                                           unsigned u64s)
164 {
165         struct bch_sb_field *f = bch2_sb_field_get(sb->sb, type);
166         ssize_t old_u64s = f ? le32_to_cpu(f->u64s) : 0;
167         ssize_t d = -old_u64s + u64s;
168
169         if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d))
170                 return NULL;
171
172         if (sb->fs_sb) {
173                 struct bch_fs *c = container_of(sb, struct bch_fs, disk_sb);
174                 struct bch_dev *ca;
175                 unsigned i;
176
177                 lockdep_assert_held(&c->sb_lock);
178
179                 /* XXX: we're not checking that offline device have enough space */
180
181                 for_each_online_member(ca, c, i) {
182                         struct bch_sb_handle *sb = &ca->disk_sb;
183
184                         if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d)) {
185                                 percpu_ref_put(&ca->ref);
186                                 return NULL;
187                         }
188                 }
189         }
190
191         f = bch2_sb_field_get(sb->sb, type);
192         f = __bch2_sb_field_resize(sb, f, u64s);
193         if (f)
194                 f->type = cpu_to_le32(type);
195         return f;
196 }
197
198 /* Superblock validate: */
199
200 static inline void __bch2_sb_layout_size_assert(void)
201 {
202         BUILD_BUG_ON(sizeof(struct bch_sb_layout) != 512);
203 }
204
205 static const char *validate_sb_layout(struct bch_sb_layout *layout)
206 {
207         u64 offset, prev_offset, max_sectors;
208         unsigned i;
209
210         if (uuid_le_cmp(layout->magic, BCACHE_MAGIC))
211                 return "Not a bcachefs superblock layout";
212
213         if (layout->layout_type != 0)
214                 return "Invalid superblock layout type";
215
216         if (!layout->nr_superblocks)
217                 return "Invalid superblock layout: no superblocks";
218
219         if (layout->nr_superblocks > ARRAY_SIZE(layout->sb_offset))
220                 return "Invalid superblock layout: too many superblocks";
221
222         max_sectors = 1 << layout->sb_max_size_bits;
223
224         prev_offset = le64_to_cpu(layout->sb_offset[0]);
225
226         for (i = 1; i < layout->nr_superblocks; i++) {
227                 offset = le64_to_cpu(layout->sb_offset[i]);
228
229                 if (offset < prev_offset + max_sectors)
230                         return "Invalid superblock layout: superblocks overlap";
231                 prev_offset = offset;
232         }
233
234         return NULL;
235 }
236
237 const char *bch2_sb_validate(struct bch_sb_handle *disk_sb)
238 {
239         struct bch_sb *sb = disk_sb->sb;
240         struct bch_sb_field *f;
241         struct bch_sb_field_members *mi;
242         const char *err;
243         u32 version, version_min;
244         u16 block_size;
245
246         version         = le16_to_cpu(sb->version);
247         version_min     = version >= bcachefs_metadata_version_new_versioning
248                 ? le16_to_cpu(sb->version_min)
249                 : version;
250
251         if (version    >= bcachefs_metadata_version_max ||
252             version_min < bcachefs_metadata_version_min)
253                 return "Unsupported superblock version";
254
255         if (version_min > version)
256                 return "Bad minimum version";
257
258         if (sb->features[1] ||
259             (le64_to_cpu(sb->features[0]) & (~0ULL << BCH_FEATURE_NR)))
260                 return "Filesystem has incompatible features";
261
262         block_size = le16_to_cpu(sb->block_size);
263
264         if (block_size > PAGE_SECTORS)
265                 return "Bad block size";
266
267         if (bch2_is_zero(sb->user_uuid.b, sizeof(uuid_le)))
268                 return "Bad user UUID";
269
270         if (bch2_is_zero(sb->uuid.b, sizeof(uuid_le)))
271                 return "Bad internal UUID";
272
273         if (!sb->nr_devices ||
274             sb->nr_devices <= sb->dev_idx ||
275             sb->nr_devices > BCH_SB_MEMBERS_MAX)
276                 return "Bad number of member devices";
277
278         if (!BCH_SB_META_REPLICAS_WANT(sb) ||
279             BCH_SB_META_REPLICAS_WANT(sb) > BCH_REPLICAS_MAX)
280                 return "Invalid number of metadata replicas";
281
282         if (!BCH_SB_META_REPLICAS_REQ(sb) ||
283             BCH_SB_META_REPLICAS_REQ(sb) > BCH_REPLICAS_MAX)
284                 return "Invalid number of metadata replicas";
285
286         if (!BCH_SB_DATA_REPLICAS_WANT(sb) ||
287             BCH_SB_DATA_REPLICAS_WANT(sb) > BCH_REPLICAS_MAX)
288                 return "Invalid number of data replicas";
289
290         if (!BCH_SB_DATA_REPLICAS_REQ(sb) ||
291             BCH_SB_DATA_REPLICAS_REQ(sb) > BCH_REPLICAS_MAX)
292                 return "Invalid number of data replicas";
293
294         if (BCH_SB_META_CSUM_TYPE(sb) >= BCH_CSUM_OPT_NR)
295                 return "Invalid metadata checksum type";
296
297         if (BCH_SB_DATA_CSUM_TYPE(sb) >= BCH_CSUM_OPT_NR)
298                 return "Invalid metadata checksum type";
299
300         if (BCH_SB_COMPRESSION_TYPE(sb) >= BCH_COMPRESSION_OPT_NR)
301                 return "Invalid compression type";
302
303         if (!BCH_SB_BTREE_NODE_SIZE(sb))
304                 return "Btree node size not set";
305
306         if (BCH_SB_GC_RESERVE(sb) < 5)
307                 return "gc reserve percentage too small";
308
309         if (!sb->time_precision ||
310             le32_to_cpu(sb->time_precision) > NSEC_PER_SEC)
311                 return "invalid time precision";
312
313         /* validate layout */
314         err = validate_sb_layout(&sb->layout);
315         if (err)
316                 return err;
317
318         vstruct_for_each(sb, f) {
319                 if (!f->u64s)
320                         return "Invalid superblock: invalid optional field";
321
322                 if (vstruct_next(f) > vstruct_last(sb))
323                         return "Invalid superblock: invalid optional field";
324         }
325
326         /* members must be validated first: */
327         mi = bch2_sb_get_members(sb);
328         if (!mi)
329                 return "Invalid superblock: member info area missing";
330
331         err = bch2_sb_field_validate(sb, &mi->field);
332         if (err)
333                 return err;
334
335         vstruct_for_each(sb, f) {
336                 if (le32_to_cpu(f->type) == BCH_SB_FIELD_members)
337                         continue;
338
339                 err = bch2_sb_field_validate(sb, f);
340                 if (err)
341                         return err;
342         }
343
344         return NULL;
345 }
346
347 /* device open: */
348
349 static void bch2_sb_update(struct bch_fs *c)
350 {
351         struct bch_sb *src = c->disk_sb.sb;
352         struct bch_sb_field_members *mi = bch2_sb_get_members(src);
353         struct bch_dev *ca;
354         unsigned i;
355
356         lockdep_assert_held(&c->sb_lock);
357
358         c->sb.uuid              = src->uuid;
359         c->sb.user_uuid         = src->user_uuid;
360         c->sb.version           = le16_to_cpu(src->version);
361         c->sb.version_min       = le16_to_cpu(src->version_min);
362         c->sb.nr_devices        = src->nr_devices;
363         c->sb.clean             = BCH_SB_CLEAN(src);
364         c->sb.encryption_type   = BCH_SB_ENCRYPTION_TYPE(src);
365
366         c->sb.nsec_per_time_unit = le32_to_cpu(src->time_precision);
367         c->sb.time_units_per_sec = NSEC_PER_SEC / c->sb.nsec_per_time_unit;
368
369         /* XXX this is wrong, we need a 96 or 128 bit integer type */
370         c->sb.time_base_lo      = div_u64(le64_to_cpu(src->time_base_lo),
371                                           c->sb.nsec_per_time_unit);
372         c->sb.time_base_hi      = le32_to_cpu(src->time_base_hi);
373
374         c->sb.features          = le64_to_cpu(src->features[0]);
375         c->sb.compat            = le64_to_cpu(src->compat[0]);
376
377         for_each_member_device(ca, c, i)
378                 ca->mi = bch2_mi_to_cpu(mi->members + i);
379 }
380
381 static void __copy_super(struct bch_sb_handle *dst_handle, struct bch_sb *src)
382 {
383         struct bch_sb_field *src_f, *dst_f;
384         struct bch_sb *dst = dst_handle->sb;
385         unsigned i;
386
387         dst->version            = src->version;
388         dst->version_min        = src->version_min;
389         dst->seq                = src->seq;
390         dst->uuid               = src->uuid;
391         dst->user_uuid          = src->user_uuid;
392         memcpy(dst->label,      src->label, sizeof(dst->label));
393
394         dst->block_size         = src->block_size;
395         dst->nr_devices         = src->nr_devices;
396
397         dst->time_base_lo       = src->time_base_lo;
398         dst->time_base_hi       = src->time_base_hi;
399         dst->time_precision     = src->time_precision;
400
401         memcpy(dst->flags,      src->flags,     sizeof(dst->flags));
402         memcpy(dst->features,   src->features,  sizeof(dst->features));
403         memcpy(dst->compat,     src->compat,    sizeof(dst->compat));
404
405         for (i = 0; i < BCH_SB_FIELD_NR; i++) {
406                 if (i == BCH_SB_FIELD_journal)
407                         continue;
408
409                 src_f = bch2_sb_field_get(src, i);
410                 dst_f = bch2_sb_field_get(dst, i);
411                 dst_f = __bch2_sb_field_resize(dst_handle, dst_f,
412                                 src_f ? le32_to_cpu(src_f->u64s) : 0);
413
414                 if (src_f)
415                         memcpy(dst_f, src_f, vstruct_bytes(src_f));
416         }
417 }
418
419 int bch2_sb_to_fs(struct bch_fs *c, struct bch_sb *src)
420 {
421         struct bch_sb_field_journal *journal_buckets =
422                 bch2_sb_get_journal(src);
423         unsigned journal_u64s = journal_buckets
424                 ? le32_to_cpu(journal_buckets->field.u64s)
425                 : 0;
426         int ret;
427
428         lockdep_assert_held(&c->sb_lock);
429
430         ret = bch2_sb_realloc(&c->disk_sb,
431                               le32_to_cpu(src->u64s) - journal_u64s);
432         if (ret)
433                 return ret;
434
435         __copy_super(&c->disk_sb, src);
436
437         if (BCH_SB_INITIALIZED(c->disk_sb.sb))
438                 set_bit(BCH_FS_INITIALIZED, &c->flags);
439
440         ret = bch2_sb_replicas_to_cpu_replicas(c);
441         if (ret)
442                 return ret;
443
444         ret = bch2_sb_disk_groups_to_cpu(c);
445         if (ret)
446                 return ret;
447
448         bch2_sb_update(c);
449         return 0;
450 }
451
452 int bch2_sb_from_fs(struct bch_fs *c, struct bch_dev *ca)
453 {
454         struct bch_sb *src = c->disk_sb.sb, *dst = ca->disk_sb.sb;
455         struct bch_sb_field_journal *journal_buckets =
456                 bch2_sb_get_journal(dst);
457         unsigned journal_u64s = journal_buckets
458                 ? le32_to_cpu(journal_buckets->field.u64s)
459                 : 0;
460         unsigned u64s = le32_to_cpu(src->u64s) + journal_u64s;
461         int ret;
462
463         ret = bch2_sb_realloc(&ca->disk_sb, u64s);
464         if (ret)
465                 return ret;
466
467         __copy_super(&ca->disk_sb, src);
468         return 0;
469 }
470
471 /* read superblock: */
472
473 static const char *read_one_super(struct bch_sb_handle *sb, u64 offset)
474 {
475         struct bch_csum csum;
476         size_t bytes;
477 reread:
478         bio_reset(sb->bio);
479         bio_set_dev(sb->bio, sb->bdev);
480         sb->bio->bi_iter.bi_sector = offset;
481         bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
482         bch2_bio_map(sb->bio, sb->sb, sb->buffer_size);
483
484         if (submit_bio_wait(sb->bio))
485                 return "IO error";
486
487         if (uuid_le_cmp(sb->sb->magic, BCACHE_MAGIC))
488                 return "Not a bcachefs superblock";
489
490         if (le16_to_cpu(sb->sb->version) <  bcachefs_metadata_version_min ||
491             le16_to_cpu(sb->sb->version) >= bcachefs_metadata_version_max)
492                 return "Unsupported superblock version";
493
494         bytes = vstruct_bytes(sb->sb);
495
496         if (bytes > 512 << sb->sb->layout.sb_max_size_bits)
497                 return "Bad superblock: too big";
498
499         if (bytes > sb->buffer_size) {
500                 if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s)))
501                         return "cannot allocate memory";
502                 goto reread;
503         }
504
505         if (BCH_SB_CSUM_TYPE(sb->sb) >= BCH_CSUM_NR)
506                 return "unknown csum type";
507
508         /* XXX: verify MACs */
509         csum = csum_vstruct(NULL, BCH_SB_CSUM_TYPE(sb->sb),
510                             null_nonce(), sb->sb);
511
512         if (bch2_crc_cmp(csum, sb->sb->csum))
513                 return "bad checksum reading superblock";
514
515         sb->seq = le64_to_cpu(sb->sb->seq);
516
517         return NULL;
518 }
519
520 int bch2_read_super(const char *path, struct bch_opts *opts,
521                     struct bch_sb_handle *sb)
522 {
523         u64 offset = opt_get(*opts, sb);
524         struct bch_sb_layout layout;
525         const char *err;
526         __le64 *i;
527         int ret;
528
529         pr_verbose_init(*opts, "");
530
531         memset(sb, 0, sizeof(*sb));
532         sb->mode        = FMODE_READ;
533         sb->have_bio    = true;
534
535         if (!opt_get(*opts, noexcl))
536                 sb->mode |= FMODE_EXCL;
537
538         if (!opt_get(*opts, nochanges))
539                 sb->mode |= FMODE_WRITE;
540
541         sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
542         if (IS_ERR(sb->bdev) &&
543             PTR_ERR(sb->bdev) == -EACCES &&
544             opt_get(*opts, read_only)) {
545                 sb->mode &= ~FMODE_WRITE;
546
547                 sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
548                 if (!IS_ERR(sb->bdev))
549                         opt_set(*opts, nochanges, true);
550         }
551
552         if (IS_ERR(sb->bdev)) {
553                 ret = PTR_ERR(sb->bdev);
554                 goto out;
555         }
556
557         err = "cannot allocate memory";
558         ret = bch2_sb_realloc(sb, 0);
559         if (ret)
560                 goto err;
561
562         ret = -EFAULT;
563         err = "dynamic fault";
564         if (bch2_fs_init_fault("read_super"))
565                 goto err;
566
567         ret = -EINVAL;
568         err = read_one_super(sb, offset);
569         if (!err)
570                 goto got_super;
571
572         if (opt_defined(*opts, sb))
573                 goto err;
574
575         pr_err("error reading default superblock: %s", err);
576
577         /*
578          * Error reading primary superblock - read location of backup
579          * superblocks:
580          */
581         bio_reset(sb->bio);
582         bio_set_dev(sb->bio, sb->bdev);
583         sb->bio->bi_iter.bi_sector = BCH_SB_LAYOUT_SECTOR;
584         bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
585         /*
586          * use sb buffer to read layout, since sb buffer is page aligned but
587          * layout won't be:
588          */
589         bch2_bio_map(sb->bio, sb->sb, sizeof(struct bch_sb_layout));
590
591         err = "IO error";
592         if (submit_bio_wait(sb->bio))
593                 goto err;
594
595         memcpy(&layout, sb->sb, sizeof(layout));
596         err = validate_sb_layout(&layout);
597         if (err)
598                 goto err;
599
600         for (i = layout.sb_offset;
601              i < layout.sb_offset + layout.nr_superblocks; i++) {
602                 offset = le64_to_cpu(*i);
603
604                 if (offset == opt_get(*opts, sb))
605                         continue;
606
607                 err = read_one_super(sb, offset);
608                 if (!err)
609                         goto got_super;
610         }
611
612         ret = -EINVAL;
613         goto err;
614
615 got_super:
616         err = "Superblock block size smaller than device block size";
617         ret = -EINVAL;
618         if (le16_to_cpu(sb->sb->block_size) << 9 <
619             bdev_logical_block_size(sb->bdev)) {
620                 pr_err("error reading superblock: Superblock block size (%u) smaller than device block size (%u)",
621                        le16_to_cpu(sb->sb->block_size) << 9,
622                        bdev_logical_block_size(sb->bdev));
623                 goto err_no_print;
624         }
625
626         ret = 0;
627         sb->have_layout = true;
628 out:
629         pr_verbose_init(*opts, "ret %i", ret);
630         return ret;
631 err:
632         pr_err("error reading superblock: %s", err);
633 err_no_print:
634         bch2_free_super(sb);
635         goto out;
636 }
637
638 /* write superblock: */
639
640 static void write_super_endio(struct bio *bio)
641 {
642         struct bch_dev *ca = bio->bi_private;
643
644         /* XXX: return errors directly */
645
646         if (bch2_dev_io_err_on(bio->bi_status, ca, "superblock write error: %s",
647                                bch2_blk_status_to_str(bio->bi_status)))
648                 ca->sb_write_error = 1;
649
650         closure_put(&ca->fs->sb_write);
651         percpu_ref_put(&ca->io_ref);
652 }
653
654 static void read_back_super(struct bch_fs *c, struct bch_dev *ca)
655 {
656         struct bch_sb *sb = ca->disk_sb.sb;
657         struct bio *bio = ca->disk_sb.bio;
658
659         bio_reset(bio);
660         bio_set_dev(bio, ca->disk_sb.bdev);
661         bio->bi_iter.bi_sector  = le64_to_cpu(sb->layout.sb_offset[0]);
662         bio->bi_end_io          = write_super_endio;
663         bio->bi_private         = ca;
664         bio_set_op_attrs(bio, REQ_OP_READ, REQ_SYNC|REQ_META);
665         bch2_bio_map(bio, ca->sb_read_scratch, PAGE_SIZE);
666
667         this_cpu_add(ca->io_done->sectors[READ][BCH_DATA_sb],
668                      bio_sectors(bio));
669
670         percpu_ref_get(&ca->io_ref);
671         closure_bio_submit(bio, &c->sb_write);
672 }
673
674 static void write_one_super(struct bch_fs *c, struct bch_dev *ca, unsigned idx)
675 {
676         struct bch_sb *sb = ca->disk_sb.sb;
677         struct bio *bio = ca->disk_sb.bio;
678
679         sb->offset = sb->layout.sb_offset[idx];
680
681         SET_BCH_SB_CSUM_TYPE(sb, bch2_csum_opt_to_type(c->opts.metadata_checksum, false));
682         sb->csum = csum_vstruct(c, BCH_SB_CSUM_TYPE(sb),
683                                 null_nonce(), sb);
684
685         bio_reset(bio);
686         bio_set_dev(bio, ca->disk_sb.bdev);
687         bio->bi_iter.bi_sector  = le64_to_cpu(sb->offset);
688         bio->bi_end_io          = write_super_endio;
689         bio->bi_private         = ca;
690         bio_set_op_attrs(bio, REQ_OP_WRITE, REQ_SYNC|REQ_META);
691         bch2_bio_map(bio, sb,
692                      roundup((size_t) vstruct_bytes(sb),
693                              bdev_logical_block_size(ca->disk_sb.bdev)));
694
695         this_cpu_add(ca->io_done->sectors[WRITE][BCH_DATA_sb],
696                      bio_sectors(bio));
697
698         percpu_ref_get(&ca->io_ref);
699         closure_bio_submit(bio, &c->sb_write);
700 }
701
702 int bch2_write_super(struct bch_fs *c)
703 {
704         struct closure *cl = &c->sb_write;
705         struct bch_dev *ca;
706         unsigned i, sb = 0, nr_wrote;
707         const char *err;
708         struct bch_devs_mask sb_written;
709         bool wrote, can_mount_without_written, can_mount_with_written;
710         unsigned degraded_flags = BCH_FORCE_IF_DEGRADED;
711         int ret = 0;
712
713         if (c->opts.very_degraded)
714                 degraded_flags |= BCH_FORCE_IF_LOST;
715
716         lockdep_assert_held(&c->sb_lock);
717
718         closure_init_stack(cl);
719         memset(&sb_written, 0, sizeof(sb_written));
720
721         le64_add_cpu(&c->disk_sb.sb->seq, 1);
722
723         if (test_bit(BCH_FS_ERROR, &c->flags))
724                 SET_BCH_SB_HAS_ERRORS(c->disk_sb.sb, 1);
725         if (test_bit(BCH_FS_TOPOLOGY_ERROR, &c->flags))
726                 SET_BCH_SB_HAS_TOPOLOGY_ERRORS(c->disk_sb.sb, 1);
727
728         SET_BCH_SB_BIG_ENDIAN(c->disk_sb.sb, CPU_BIG_ENDIAN);
729
730         for_each_online_member(ca, c, i)
731                 bch2_sb_from_fs(c, ca);
732
733         for_each_online_member(ca, c, i) {
734                 err = bch2_sb_validate(&ca->disk_sb);
735                 if (err) {
736                         bch2_fs_inconsistent(c, "sb invalid before write: %s", err);
737                         ret = -1;
738                         goto out;
739                 }
740         }
741
742         if (c->opts.nochanges)
743                 goto out;
744
745         for_each_online_member(ca, c, i) {
746                 __set_bit(ca->dev_idx, sb_written.d);
747                 ca->sb_write_error = 0;
748         }
749
750         for_each_online_member(ca, c, i)
751                 read_back_super(c, ca);
752         closure_sync(cl);
753
754         for_each_online_member(ca, c, i) {
755                 if (!ca->sb_write_error &&
756                     ca->disk_sb.seq !=
757                     le64_to_cpu(ca->sb_read_scratch->seq)) {
758                         bch2_fs_fatal_error(c,
759                                 "Superblock modified by another process");
760                         percpu_ref_put(&ca->io_ref);
761                         ret = -EROFS;
762                         goto out;
763                 }
764         }
765
766         do {
767                 wrote = false;
768                 for_each_online_member(ca, c, i)
769                         if (!ca->sb_write_error &&
770                             sb < ca->disk_sb.sb->layout.nr_superblocks) {
771                                 write_one_super(c, ca, sb);
772                                 wrote = true;
773                         }
774                 closure_sync(cl);
775                 sb++;
776         } while (wrote);
777
778         for_each_online_member(ca, c, i) {
779                 if (ca->sb_write_error)
780                         __clear_bit(ca->dev_idx, sb_written.d);
781                 else
782                         ca->disk_sb.seq = le64_to_cpu(ca->disk_sb.sb->seq);
783         }
784
785         nr_wrote = dev_mask_nr(&sb_written);
786
787         can_mount_with_written =
788                 bch2_have_enough_devs(c, sb_written, degraded_flags, false);
789
790         for (i = 0; i < ARRAY_SIZE(sb_written.d); i++)
791                 sb_written.d[i] = ~sb_written.d[i];
792
793         can_mount_without_written =
794                 bch2_have_enough_devs(c, sb_written, degraded_flags, false);
795
796         /*
797          * If we would be able to mount _without_ the devices we successfully
798          * wrote superblocks to, we weren't able to write to enough devices:
799          *
800          * Exception: if we can mount without the successes because we haven't
801          * written anything (new filesystem), we continue if we'd be able to
802          * mount with the devices we did successfully write to:
803          */
804         if (bch2_fs_fatal_err_on(!nr_wrote ||
805                                  !can_mount_with_written ||
806                                  (can_mount_without_written &&
807                                   !can_mount_with_written), c,
808                 "Unable to write superblock to sufficient devices (from %ps)",
809                 (void *) _RET_IP_))
810                 ret = -1;
811 out:
812         /* Make new options visible after they're persistent: */
813         bch2_sb_update(c);
814         return ret;
815 }
816
817 void __bch2_check_set_feature(struct bch_fs *c, unsigned feat)
818 {
819         mutex_lock(&c->sb_lock);
820         if (!(c->sb.features & (1ULL << feat))) {
821                 c->disk_sb.sb->features[0] |= cpu_to_le64(1ULL << feat);
822
823                 bch2_write_super(c);
824         }
825         mutex_unlock(&c->sb_lock);
826 }
827
828 /* BCH_SB_FIELD_journal: */
829
830 static int u64_cmp(const void *_l, const void *_r)
831 {
832         u64 l = *((const u64 *) _l), r = *((const u64 *) _r);
833
834         return l < r ? -1 : l > r ? 1 : 0;
835 }
836
837 static const char *bch2_sb_validate_journal(struct bch_sb *sb,
838                                             struct bch_sb_field *f)
839 {
840         struct bch_sb_field_journal *journal = field_to_type(f, journal);
841         struct bch_member *m = bch2_sb_get_members(sb)->members + sb->dev_idx;
842         const char *err;
843         unsigned nr;
844         unsigned i;
845         u64 *b;
846
847         journal = bch2_sb_get_journal(sb);
848         if (!journal)
849                 return NULL;
850
851         nr = bch2_nr_journal_buckets(journal);
852         if (!nr)
853                 return NULL;
854
855         b = kmalloc_array(sizeof(u64), nr, GFP_KERNEL);
856         if (!b)
857                 return "cannot allocate memory";
858
859         for (i = 0; i < nr; i++)
860                 b[i] = le64_to_cpu(journal->buckets[i]);
861
862         sort(b, nr, sizeof(u64), u64_cmp, NULL);
863
864         err = "journal bucket at sector 0";
865         if (!b[0])
866                 goto err;
867
868         err = "journal bucket before first bucket";
869         if (m && b[0] < le16_to_cpu(m->first_bucket))
870                 goto err;
871
872         err = "journal bucket past end of device";
873         if (m && b[nr - 1] >= le64_to_cpu(m->nbuckets))
874                 goto err;
875
876         err = "duplicate journal buckets";
877         for (i = 0; i + 1 < nr; i++)
878                 if (b[i] == b[i + 1])
879                         goto err;
880
881         err = NULL;
882 err:
883         kfree(b);
884         return err;
885 }
886
887 static const struct bch_sb_field_ops bch_sb_field_ops_journal = {
888         .validate       = bch2_sb_validate_journal,
889 };
890
891 /* BCH_SB_FIELD_members: */
892
893 static const char *bch2_sb_validate_members(struct bch_sb *sb,
894                                             struct bch_sb_field *f)
895 {
896         struct bch_sb_field_members *mi = field_to_type(f, members);
897         struct bch_member *m;
898
899         if ((void *) (mi->members + sb->nr_devices) >
900             vstruct_end(&mi->field))
901                 return "Invalid superblock: bad member info";
902
903         for (m = mi->members;
904              m < mi->members + sb->nr_devices;
905              m++) {
906                 if (!bch2_member_exists(m))
907                         continue;
908
909                 if (le64_to_cpu(m->nbuckets) > LONG_MAX)
910                         return "Too many buckets";
911
912                 if (le64_to_cpu(m->nbuckets) -
913                     le16_to_cpu(m->first_bucket) < BCH_MIN_NR_NBUCKETS)
914                         return "Not enough buckets";
915
916                 if (le16_to_cpu(m->bucket_size) <
917                     le16_to_cpu(sb->block_size))
918                         return "bucket size smaller than block size";
919
920                 if (le16_to_cpu(m->bucket_size) <
921                     BCH_SB_BTREE_NODE_SIZE(sb))
922                         return "bucket size smaller than btree node size";
923         }
924
925         return NULL;
926 }
927
928 static const struct bch_sb_field_ops bch_sb_field_ops_members = {
929         .validate       = bch2_sb_validate_members,
930 };
931
932 /* BCH_SB_FIELD_crypt: */
933
934 static const char *bch2_sb_validate_crypt(struct bch_sb *sb,
935                                           struct bch_sb_field *f)
936 {
937         struct bch_sb_field_crypt *crypt = field_to_type(f, crypt);
938
939         if (vstruct_bytes(&crypt->field) != sizeof(*crypt))
940                 return "invalid field crypt: wrong size";
941
942         if (BCH_CRYPT_KDF_TYPE(crypt))
943                 return "invalid field crypt: bad kdf type";
944
945         return NULL;
946 }
947
948 static const struct bch_sb_field_ops bch_sb_field_ops_crypt = {
949         .validate       = bch2_sb_validate_crypt,
950 };
951
952 /* BCH_SB_FIELD_clean: */
953
954 int bch2_sb_clean_validate(struct bch_fs *c, struct bch_sb_field_clean *clean, int write)
955 {
956         struct jset_entry *entry;
957         int ret;
958
959         for (entry = clean->start;
960              entry < (struct jset_entry *) vstruct_end(&clean->field);
961              entry = vstruct_next(entry)) {
962                 ret = bch2_journal_entry_validate(c, "superblock", entry,
963                                                   le16_to_cpu(c->disk_sb.sb->version),
964                                                   BCH_SB_BIG_ENDIAN(c->disk_sb.sb),
965                                                   write);
966                 if (ret)
967                         return ret;
968         }
969
970         return 0;
971 }
972
973 int bch2_fs_mark_dirty(struct bch_fs *c)
974 {
975         int ret;
976
977         /*
978          * Unconditionally write superblock, to verify it hasn't changed before
979          * we go rw:
980          */
981
982         mutex_lock(&c->sb_lock);
983         SET_BCH_SB_CLEAN(c->disk_sb.sb, false);
984         c->disk_sb.sb->features[0] |= cpu_to_le64(BCH_SB_FEATURES_ALWAYS);
985         c->disk_sb.sb->compat[0] &= cpu_to_le64((1ULL << BCH_COMPAT_NR) - 1);
986         ret = bch2_write_super(c);
987         mutex_unlock(&c->sb_lock);
988
989         return ret;
990 }
991
992 static struct jset_entry *jset_entry_init(struct jset_entry **end, size_t size)
993 {
994         struct jset_entry *entry = *end;
995         unsigned u64s = DIV_ROUND_UP(size, sizeof(u64));
996
997         memset(entry, 0, u64s * sizeof(u64));
998         /*
999          * The u64s field counts from the start of data, ignoring the shared
1000          * fields.
1001          */
1002         entry->u64s = cpu_to_le16(u64s - 1);
1003
1004         *end = vstruct_next(*end);
1005         return entry;
1006 }
1007
1008 void bch2_journal_super_entries_add_common(struct bch_fs *c,
1009                                            struct jset_entry **end,
1010                                            u64 journal_seq)
1011 {
1012         struct bch_dev *ca;
1013         unsigned i, dev;
1014
1015         percpu_down_read(&c->mark_lock);
1016
1017         if (!journal_seq) {
1018                 for (i = 0; i < ARRAY_SIZE(c->usage); i++)
1019                         bch2_fs_usage_acc_to_base(c, i);
1020         } else {
1021                 bch2_fs_usage_acc_to_base(c, journal_seq & JOURNAL_BUF_MASK);
1022         }
1023
1024         {
1025                 struct jset_entry_usage *u =
1026                         container_of(jset_entry_init(end, sizeof(*u)),
1027                                      struct jset_entry_usage, entry);
1028
1029                 u->entry.type   = BCH_JSET_ENTRY_usage;
1030                 u->entry.btree_id = FS_USAGE_INODES;
1031                 u->v            = cpu_to_le64(c->usage_base->nr_inodes);
1032         }
1033
1034         {
1035                 struct jset_entry_usage *u =
1036                         container_of(jset_entry_init(end, sizeof(*u)),
1037                                      struct jset_entry_usage, entry);
1038
1039                 u->entry.type   = BCH_JSET_ENTRY_usage;
1040                 u->entry.btree_id = FS_USAGE_KEY_VERSION;
1041                 u->v            = cpu_to_le64(atomic64_read(&c->key_version));
1042         }
1043
1044         for (i = 0; i < BCH_REPLICAS_MAX; i++) {
1045                 struct jset_entry_usage *u =
1046                         container_of(jset_entry_init(end, sizeof(*u)),
1047                                      struct jset_entry_usage, entry);
1048
1049                 u->entry.type   = BCH_JSET_ENTRY_usage;
1050                 u->entry.btree_id = FS_USAGE_RESERVED;
1051                 u->entry.level  = i;
1052                 u->v            = cpu_to_le64(c->usage_base->persistent_reserved[i]);
1053         }
1054
1055         for (i = 0; i < c->replicas.nr; i++) {
1056                 struct bch_replicas_entry *e =
1057                         cpu_replicas_entry(&c->replicas, i);
1058                 struct jset_entry_data_usage *u =
1059                         container_of(jset_entry_init(end, sizeof(*u) + e->nr_devs),
1060                                      struct jset_entry_data_usage, entry);
1061
1062                 u->entry.type   = BCH_JSET_ENTRY_data_usage;
1063                 u->v            = cpu_to_le64(c->usage_base->replicas[i]);
1064                 memcpy(&u->r, e, replicas_entry_bytes(e));
1065         }
1066
1067         for_each_member_device(ca, c, dev) {
1068                 unsigned b = sizeof(struct jset_entry_dev_usage) +
1069                         sizeof(struct jset_entry_dev_usage_type) * BCH_DATA_NR;
1070                 struct jset_entry_dev_usage *u =
1071                         container_of(jset_entry_init(end, b),
1072                                      struct jset_entry_dev_usage, entry);
1073
1074                 u->entry.type = BCH_JSET_ENTRY_dev_usage;
1075                 u->dev = cpu_to_le32(dev);
1076                 u->buckets_ec           = cpu_to_le64(ca->usage_base->buckets_ec);
1077                 u->buckets_unavailable  = cpu_to_le64(ca->usage_base->buckets_unavailable);
1078
1079                 for (i = 0; i < BCH_DATA_NR; i++) {
1080                         u->d[i].buckets = cpu_to_le64(ca->usage_base->d[i].buckets);
1081                         u->d[i].sectors = cpu_to_le64(ca->usage_base->d[i].sectors);
1082                         u->d[i].fragmented = cpu_to_le64(ca->usage_base->d[i].fragmented);
1083                 }
1084         }
1085
1086         percpu_up_read(&c->mark_lock);
1087
1088         for (i = 0; i < 2; i++) {
1089                 struct jset_entry_clock *clock =
1090                         container_of(jset_entry_init(end, sizeof(*clock)),
1091                                      struct jset_entry_clock, entry);
1092
1093                 clock->entry.type = BCH_JSET_ENTRY_clock;
1094                 clock->rw       = i;
1095                 clock->time     = cpu_to_le64(atomic64_read(&c->io_clock[i].now));
1096         }
1097 }
1098
1099 void bch2_fs_mark_clean(struct bch_fs *c)
1100 {
1101         struct bch_sb_field_clean *sb_clean;
1102         struct jset_entry *entry;
1103         unsigned u64s;
1104         int ret;
1105
1106         mutex_lock(&c->sb_lock);
1107         if (BCH_SB_CLEAN(c->disk_sb.sb))
1108                 goto out;
1109
1110         SET_BCH_SB_CLEAN(c->disk_sb.sb, true);
1111
1112         c->disk_sb.sb->compat[0] |= cpu_to_le64(1ULL << BCH_COMPAT_alloc_info);
1113         c->disk_sb.sb->compat[0] |= cpu_to_le64(1ULL << BCH_COMPAT_alloc_metadata);
1114         c->disk_sb.sb->features[0] &= cpu_to_le64(~(1ULL << BCH_FEATURE_extents_above_btree_updates));
1115         c->disk_sb.sb->features[0] &= cpu_to_le64(~(1ULL << BCH_FEATURE_btree_updates_journalled));
1116
1117         u64s = sizeof(*sb_clean) / sizeof(u64) + c->journal.entry_u64s_reserved;
1118
1119         sb_clean = bch2_sb_resize_clean(&c->disk_sb, u64s);
1120         if (!sb_clean) {
1121                 bch_err(c, "error resizing superblock while setting filesystem clean");
1122                 goto out;
1123         }
1124
1125         sb_clean->flags         = 0;
1126         sb_clean->journal_seq   = cpu_to_le64(journal_cur_seq(&c->journal) - 1);
1127
1128         /* Trying to catch outstanding bug: */
1129         BUG_ON(le64_to_cpu(sb_clean->journal_seq) > S64_MAX);
1130
1131         entry = sb_clean->start;
1132         bch2_journal_super_entries_add_common(c, &entry, 0);
1133         entry = bch2_btree_roots_to_journal_entries(c, entry, entry);
1134         BUG_ON((void *) entry > vstruct_end(&sb_clean->field));
1135
1136         memset(entry, 0,
1137                vstruct_end(&sb_clean->field) - (void *) entry);
1138
1139         /*
1140          * this should be in the write path, and we should be validating every
1141          * superblock section:
1142          */
1143         ret = bch2_sb_clean_validate(c, sb_clean, WRITE);
1144         if (ret) {
1145                 bch_err(c, "error writing marking filesystem clean: validate error");
1146                 goto out;
1147         }
1148
1149         bch2_write_super(c);
1150 out:
1151         mutex_unlock(&c->sb_lock);
1152 }
1153
1154 static const char *bch2_sb_validate_clean(struct bch_sb *sb,
1155                                           struct bch_sb_field *f)
1156 {
1157         struct bch_sb_field_clean *clean = field_to_type(f, clean);
1158
1159         if (vstruct_bytes(&clean->field) < sizeof(*clean))
1160                 return "invalid field crypt: wrong size";
1161
1162         return NULL;
1163 }
1164
1165 static const struct bch_sb_field_ops bch_sb_field_ops_clean = {
1166         .validate       = bch2_sb_validate_clean,
1167 };
1168
1169 static const struct bch_sb_field_ops *bch2_sb_field_ops[] = {
1170 #define x(f, nr)                                        \
1171         [BCH_SB_FIELD_##f] = &bch_sb_field_ops_##f,
1172         BCH_SB_FIELDS()
1173 #undef x
1174 };
1175
1176 static const char *bch2_sb_field_validate(struct bch_sb *sb,
1177                                           struct bch_sb_field *f)
1178 {
1179         unsigned type = le32_to_cpu(f->type);
1180
1181         return type < BCH_SB_FIELD_NR
1182                 ? bch2_sb_field_ops[type]->validate(sb, f)
1183                 : NULL;
1184 }
1185
1186 void bch2_sb_field_to_text(struct printbuf *out, struct bch_sb *sb,
1187                            struct bch_sb_field *f)
1188 {
1189         unsigned type = le32_to_cpu(f->type);
1190         const struct bch_sb_field_ops *ops = type < BCH_SB_FIELD_NR
1191                 ? bch2_sb_field_ops[type] : NULL;
1192
1193         if (ops)
1194                 pr_buf(out, "%s", bch2_sb_fields[type]);
1195         else
1196                 pr_buf(out, "(unknown field %u)", type);
1197
1198         pr_buf(out, " (size %llu):", vstruct_bytes(f));
1199
1200         if (ops && ops->to_text)
1201                 bch2_sb_field_ops[type]->to_text(out, sb, f);
1202 }