]> git.sesse.net Git - bcachefs-tools-debian/blob - libbcachefs/super-io.c
Update bcachefs sources to ffe09df106 bcachefs: Verify fs hasn't been modified before...
[bcachefs-tools-debian] / libbcachefs / super-io.c
1
2 #include "bcachefs.h"
3 #include "checksum.h"
4 #include "disk_groups.h"
5 #include "ec.h"
6 #include "error.h"
7 #include "io.h"
8 #include "journal.h"
9 #include "replicas.h"
10 #include "quota.h"
11 #include "super-io.h"
12 #include "super.h"
13 #include "vstructs.h"
14
15 #include <linux/backing-dev.h>
16 #include <linux/sort.h>
17
18 const char * const bch2_sb_fields[] = {
19 #define x(name, nr)     #name,
20         BCH_SB_FIELDS()
21 #undef x
22         NULL
23 };
24
25 static const char *bch2_sb_field_validate(struct bch_sb *,
26                                           struct bch_sb_field *);
27
28 struct bch_sb_field *bch2_sb_field_get(struct bch_sb *sb,
29                                       enum bch_sb_field_type type)
30 {
31         struct bch_sb_field *f;
32
33         /* XXX: need locking around superblock to access optional fields */
34
35         vstruct_for_each(sb, f)
36                 if (le32_to_cpu(f->type) == type)
37                         return f;
38         return NULL;
39 }
40
41 static struct bch_sb_field *__bch2_sb_field_resize(struct bch_sb_handle *sb,
42                                                    struct bch_sb_field *f,
43                                                    unsigned u64s)
44 {
45         unsigned old_u64s = f ? le32_to_cpu(f->u64s) : 0;
46         unsigned sb_u64s = le32_to_cpu(sb->sb->u64s) + u64s - old_u64s;
47
48         BUG_ON(get_order(__vstruct_bytes(struct bch_sb, sb_u64s)) >
49                sb->page_order);
50
51         if (!f) {
52                 f = vstruct_last(sb->sb);
53                 memset(f, 0, sizeof(u64) * u64s);
54                 f->u64s = cpu_to_le32(u64s);
55                 f->type = 0;
56         } else {
57                 void *src, *dst;
58
59                 src = vstruct_end(f);
60
61                 if (u64s) {
62                         f->u64s = cpu_to_le32(u64s);
63                         dst = vstruct_end(f);
64                 } else {
65                         dst = f;
66                 }
67
68                 memmove(dst, src, vstruct_end(sb->sb) - src);
69
70                 if (dst > src)
71                         memset(src, 0, dst - src);
72         }
73
74         sb->sb->u64s = cpu_to_le32(sb_u64s);
75
76         return u64s ? f : NULL;
77 }
78
79 void bch2_sb_field_delete(struct bch_sb_handle *sb,
80                           enum bch_sb_field_type type)
81 {
82         struct bch_sb_field *f = bch2_sb_field_get(sb->sb, type);
83
84         if (f)
85                 __bch2_sb_field_resize(sb, f, 0);
86 }
87
88 /* Superblock realloc/free: */
89
90 void bch2_free_super(struct bch_sb_handle *sb)
91 {
92         if (sb->bio)
93                 bio_put(sb->bio);
94         if (!IS_ERR_OR_NULL(sb->bdev))
95                 blkdev_put(sb->bdev, sb->mode);
96
97         free_pages((unsigned long) sb->sb, sb->page_order);
98         memset(sb, 0, sizeof(*sb));
99 }
100
101 int bch2_sb_realloc(struct bch_sb_handle *sb, unsigned u64s)
102 {
103         size_t new_bytes = __vstruct_bytes(struct bch_sb, u64s);
104         unsigned order = get_order(new_bytes);
105         struct bch_sb *new_sb;
106         struct bio *bio;
107
108         if (sb->sb && sb->page_order >= order)
109                 return 0;
110
111         if (sb->have_layout) {
112                 u64 max_bytes = 512 << sb->sb->layout.sb_max_size_bits;
113
114                 if (new_bytes > max_bytes) {
115                         char buf[BDEVNAME_SIZE];
116
117                         pr_err("%s: superblock too big: want %zu but have %llu",
118                                bdevname(sb->bdev, buf), new_bytes, max_bytes);
119                         return -ENOSPC;
120                 }
121         }
122
123         if (sb->page_order >= order && sb->sb)
124                 return 0;
125
126         if (dynamic_fault("bcachefs:add:super_realloc"))
127                 return -ENOMEM;
128
129         if (sb->have_bio) {
130                 bio = bio_kmalloc(GFP_KERNEL, 1 << order);
131                 if (!bio)
132                         return -ENOMEM;
133
134                 if (sb->bio)
135                         bio_put(sb->bio);
136                 sb->bio = bio;
137         }
138
139         new_sb = (void *) __get_free_pages(GFP_NOFS|__GFP_ZERO, order);
140         if (!new_sb)
141                 return -ENOMEM;
142
143         if (sb->sb)
144                 memcpy(new_sb, sb->sb, PAGE_SIZE << sb->page_order);
145
146         free_pages((unsigned long) sb->sb, sb->page_order);
147         sb->sb = new_sb;
148
149         sb->page_order = order;
150
151         return 0;
152 }
153
154 struct bch_sb_field *bch2_sb_field_resize(struct bch_sb_handle *sb,
155                                           enum bch_sb_field_type type,
156                                           unsigned u64s)
157 {
158         struct bch_sb_field *f = bch2_sb_field_get(sb->sb, type);
159         ssize_t old_u64s = f ? le32_to_cpu(f->u64s) : 0;
160         ssize_t d = -old_u64s + u64s;
161
162         if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d))
163                 return NULL;
164
165         if (sb->fs_sb) {
166                 struct bch_fs *c = container_of(sb, struct bch_fs, disk_sb);
167                 struct bch_dev *ca;
168                 unsigned i;
169
170                 lockdep_assert_held(&c->sb_lock);
171
172                 /* XXX: we're not checking that offline device have enough space */
173
174                 for_each_online_member(ca, c, i) {
175                         struct bch_sb_handle *sb = &ca->disk_sb;
176
177                         if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d)) {
178                                 percpu_ref_put(&ca->ref);
179                                 return NULL;
180                         }
181                 }
182         }
183
184         f = bch2_sb_field_get(sb->sb, type);
185         f = __bch2_sb_field_resize(sb, f, u64s);
186         if (f)
187                 f->type = cpu_to_le32(type);
188         return f;
189 }
190
191 /* Superblock validate: */
192
193 static inline void __bch2_sb_layout_size_assert(void)
194 {
195         BUILD_BUG_ON(sizeof(struct bch_sb_layout) != 512);
196 }
197
198 static const char *validate_sb_layout(struct bch_sb_layout *layout)
199 {
200         u64 offset, prev_offset, max_sectors;
201         unsigned i;
202
203         if (uuid_le_cmp(layout->magic, BCACHE_MAGIC))
204                 return "Not a bcachefs superblock layout";
205
206         if (layout->layout_type != 0)
207                 return "Invalid superblock layout type";
208
209         if (!layout->nr_superblocks)
210                 return "Invalid superblock layout: no superblocks";
211
212         if (layout->nr_superblocks > ARRAY_SIZE(layout->sb_offset))
213                 return "Invalid superblock layout: too many superblocks";
214
215         max_sectors = 1 << layout->sb_max_size_bits;
216
217         prev_offset = le64_to_cpu(layout->sb_offset[0]);
218
219         for (i = 1; i < layout->nr_superblocks; i++) {
220                 offset = le64_to_cpu(layout->sb_offset[i]);
221
222                 if (offset < prev_offset + max_sectors)
223                         return "Invalid superblock layout: superblocks overlap";
224                 prev_offset = offset;
225         }
226
227         return NULL;
228 }
229
230 const char *bch2_sb_validate(struct bch_sb_handle *disk_sb)
231 {
232         struct bch_sb *sb = disk_sb->sb;
233         struct bch_sb_field *f;
234         struct bch_sb_field_members *mi;
235         const char *err;
236         u32 version, version_min;
237         u16 block_size;
238
239         version         = le16_to_cpu(sb->version);
240         version_min     = version >= bcachefs_metadata_version_new_versioning
241                 ? le16_to_cpu(sb->version_min)
242                 : version;
243
244         if (version    >= bcachefs_metadata_version_max ||
245             version_min < bcachefs_metadata_version_min)
246                 return "Unsupported superblock version";
247
248         if (version_min > version)
249                 return "Bad minimum version";
250
251         if (sb->features[1] ||
252             (le64_to_cpu(sb->features[0]) & (~0ULL << BCH_FEATURE_NR)))
253                 return "Filesystem has incompatible features";
254
255         block_size = le16_to_cpu(sb->block_size);
256
257         if (!is_power_of_2(block_size) ||
258             block_size > PAGE_SECTORS)
259                 return "Bad block size";
260
261         if (bch2_is_zero(sb->user_uuid.b, sizeof(uuid_le)))
262                 return "Bad user UUID";
263
264         if (bch2_is_zero(sb->uuid.b, sizeof(uuid_le)))
265                 return "Bad internal UUID";
266
267         if (!sb->nr_devices ||
268             sb->nr_devices <= sb->dev_idx ||
269             sb->nr_devices > BCH_SB_MEMBERS_MAX)
270                 return "Bad number of member devices";
271
272         if (!BCH_SB_META_REPLICAS_WANT(sb) ||
273             BCH_SB_META_REPLICAS_WANT(sb) >= BCH_REPLICAS_MAX)
274                 return "Invalid number of metadata replicas";
275
276         if (!BCH_SB_META_REPLICAS_REQ(sb) ||
277             BCH_SB_META_REPLICAS_REQ(sb) >= BCH_REPLICAS_MAX)
278                 return "Invalid number of metadata replicas";
279
280         if (!BCH_SB_DATA_REPLICAS_WANT(sb) ||
281             BCH_SB_DATA_REPLICAS_WANT(sb) >= BCH_REPLICAS_MAX)
282                 return "Invalid number of data replicas";
283
284         if (!BCH_SB_DATA_REPLICAS_REQ(sb) ||
285             BCH_SB_DATA_REPLICAS_REQ(sb) >= BCH_REPLICAS_MAX)
286                 return "Invalid number of data replicas";
287
288         if (BCH_SB_META_CSUM_TYPE(sb) >= BCH_CSUM_OPT_NR)
289                 return "Invalid metadata checksum type";
290
291         if (BCH_SB_DATA_CSUM_TYPE(sb) >= BCH_CSUM_OPT_NR)
292                 return "Invalid metadata checksum type";
293
294         if (BCH_SB_COMPRESSION_TYPE(sb) >= BCH_COMPRESSION_OPT_NR)
295                 return "Invalid compression type";
296
297         if (!BCH_SB_BTREE_NODE_SIZE(sb))
298                 return "Btree node size not set";
299
300         if (!is_power_of_2(BCH_SB_BTREE_NODE_SIZE(sb)))
301                 return "Btree node size not a power of two";
302
303         if (BCH_SB_GC_RESERVE(sb) < 5)
304                 return "gc reserve percentage too small";
305
306         if (!sb->time_precision ||
307             le32_to_cpu(sb->time_precision) > NSEC_PER_SEC)
308                 return "invalid time precision";
309
310         /* validate layout */
311         err = validate_sb_layout(&sb->layout);
312         if (err)
313                 return err;
314
315         vstruct_for_each(sb, f) {
316                 if (!f->u64s)
317                         return "Invalid superblock: invalid optional field";
318
319                 if (vstruct_next(f) > vstruct_last(sb))
320                         return "Invalid superblock: invalid optional field";
321         }
322
323         /* members must be validated first: */
324         mi = bch2_sb_get_members(sb);
325         if (!mi)
326                 return "Invalid superblock: member info area missing";
327
328         err = bch2_sb_field_validate(sb, &mi->field);
329         if (err)
330                 return err;
331
332         vstruct_for_each(sb, f) {
333                 if (le32_to_cpu(f->type) == BCH_SB_FIELD_members)
334                         continue;
335
336                 err = bch2_sb_field_validate(sb, f);
337                 if (err)
338                         return err;
339         }
340
341         return NULL;
342 }
343
344 /* device open: */
345
346 static void bch2_sb_update(struct bch_fs *c)
347 {
348         struct bch_sb *src = c->disk_sb.sb;
349         struct bch_sb_field_members *mi = bch2_sb_get_members(src);
350         struct bch_dev *ca;
351         unsigned i;
352
353         lockdep_assert_held(&c->sb_lock);
354
355         c->sb.uuid              = src->uuid;
356         c->sb.user_uuid         = src->user_uuid;
357         c->sb.version           = le16_to_cpu(src->version);
358         c->sb.nr_devices        = src->nr_devices;
359         c->sb.clean             = BCH_SB_CLEAN(src);
360         c->sb.encryption_type   = BCH_SB_ENCRYPTION_TYPE(src);
361         c->sb.encoded_extent_max= 1 << BCH_SB_ENCODED_EXTENT_MAX_BITS(src);
362         c->sb.time_base_lo      = le64_to_cpu(src->time_base_lo);
363         c->sb.time_base_hi      = le32_to_cpu(src->time_base_hi);
364         c->sb.time_precision    = le32_to_cpu(src->time_precision);
365         c->sb.features          = le64_to_cpu(src->features[0]);
366         c->sb.compat            = le64_to_cpu(src->compat[0]);
367
368         for_each_member_device(ca, c, i)
369                 ca->mi = bch2_mi_to_cpu(mi->members + i);
370 }
371
372 /* doesn't copy member info */
373 static void __copy_super(struct bch_sb_handle *dst_handle, struct bch_sb *src)
374 {
375         struct bch_sb_field *src_f, *dst_f;
376         struct bch_sb *dst = dst_handle->sb;
377         unsigned i;
378
379         dst->version            = src->version;
380         dst->version_min        = src->version_min;
381         dst->seq                = src->seq;
382         dst->uuid               = src->uuid;
383         dst->user_uuid          = src->user_uuid;
384         memcpy(dst->label,      src->label, sizeof(dst->label));
385
386         dst->block_size         = src->block_size;
387         dst->nr_devices         = src->nr_devices;
388
389         dst->time_base_lo       = src->time_base_lo;
390         dst->time_base_hi       = src->time_base_hi;
391         dst->time_precision     = src->time_precision;
392
393         memcpy(dst->flags,      src->flags,     sizeof(dst->flags));
394         memcpy(dst->features,   src->features,  sizeof(dst->features));
395         memcpy(dst->compat,     src->compat,    sizeof(dst->compat));
396
397         for (i = 0; i < BCH_SB_FIELD_NR; i++) {
398                 if (i == BCH_SB_FIELD_journal)
399                         continue;
400
401                 src_f = bch2_sb_field_get(src, i);
402                 dst_f = bch2_sb_field_get(dst, i);
403                 dst_f = __bch2_sb_field_resize(dst_handle, dst_f,
404                                 src_f ? le32_to_cpu(src_f->u64s) : 0);
405
406                 if (src_f)
407                         memcpy(dst_f, src_f, vstruct_bytes(src_f));
408         }
409 }
410
411 int bch2_sb_to_fs(struct bch_fs *c, struct bch_sb *src)
412 {
413         struct bch_sb_field_journal *journal_buckets =
414                 bch2_sb_get_journal(src);
415         unsigned journal_u64s = journal_buckets
416                 ? le32_to_cpu(journal_buckets->field.u64s)
417                 : 0;
418         int ret;
419
420         lockdep_assert_held(&c->sb_lock);
421
422         ret = bch2_sb_realloc(&c->disk_sb,
423                               le32_to_cpu(src->u64s) - journal_u64s);
424         if (ret)
425                 return ret;
426
427         __copy_super(&c->disk_sb, src);
428
429         ret = bch2_sb_replicas_to_cpu_replicas(c);
430         if (ret)
431                 return ret;
432
433         ret = bch2_sb_disk_groups_to_cpu(c);
434         if (ret)
435                 return ret;
436
437         bch2_sb_update(c);
438         return 0;
439 }
440
441 int bch2_sb_from_fs(struct bch_fs *c, struct bch_dev *ca)
442 {
443         struct bch_sb *src = c->disk_sb.sb, *dst = ca->disk_sb.sb;
444         struct bch_sb_field_journal *journal_buckets =
445                 bch2_sb_get_journal(dst);
446         unsigned journal_u64s = journal_buckets
447                 ? le32_to_cpu(journal_buckets->field.u64s)
448                 : 0;
449         unsigned u64s = le32_to_cpu(src->u64s) + journal_u64s;
450         int ret;
451
452         ret = bch2_sb_realloc(&ca->disk_sb, u64s);
453         if (ret)
454                 return ret;
455
456         __copy_super(&ca->disk_sb, src);
457         return 0;
458 }
459
460 /* read superblock: */
461
462 static const char *read_one_super(struct bch_sb_handle *sb, u64 offset)
463 {
464         struct bch_csum csum;
465         size_t bytes;
466 reread:
467         bio_reset(sb->bio);
468         bio_set_dev(sb->bio, sb->bdev);
469         sb->bio->bi_iter.bi_sector = offset;
470         sb->bio->bi_iter.bi_size = PAGE_SIZE << sb->page_order;
471         bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
472         bch2_bio_map(sb->bio, sb->sb);
473
474         if (submit_bio_wait(sb->bio))
475                 return "IO error";
476
477         if (uuid_le_cmp(sb->sb->magic, BCACHE_MAGIC))
478                 return "Not a bcachefs superblock";
479
480         if (le16_to_cpu(sb->sb->version) <  bcachefs_metadata_version_min ||
481             le16_to_cpu(sb->sb->version) >= bcachefs_metadata_version_max)
482                 return "Unsupported superblock version";
483
484         bytes = vstruct_bytes(sb->sb);
485
486         if (bytes > 512 << sb->sb->layout.sb_max_size_bits)
487                 return "Bad superblock: too big";
488
489         if (get_order(bytes) > sb->page_order) {
490                 if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s)))
491                         return "cannot allocate memory";
492                 goto reread;
493         }
494
495         if (BCH_SB_CSUM_TYPE(sb->sb) >= BCH_CSUM_NR)
496                 return "unknown csum type";
497
498         /* XXX: verify MACs */
499         csum = csum_vstruct(NULL, BCH_SB_CSUM_TYPE(sb->sb),
500                             null_nonce(), sb->sb);
501
502         if (bch2_crc_cmp(csum, sb->sb->csum))
503                 return "bad checksum reading superblock";
504
505         sb->seq = le64_to_cpu(sb->sb->seq);
506
507         return NULL;
508 }
509
510 int bch2_read_super(const char *path, struct bch_opts *opts,
511                     struct bch_sb_handle *sb)
512 {
513         u64 offset = opt_get(*opts, sb);
514         struct bch_sb_layout layout;
515         const char *err;
516         __le64 *i;
517         int ret;
518
519         pr_verbose_init(*opts, "");
520
521         memset(sb, 0, sizeof(*sb));
522         sb->mode        = FMODE_READ;
523         sb->have_bio    = true;
524
525         if (!opt_get(*opts, noexcl))
526                 sb->mode |= FMODE_EXCL;
527
528         if (!opt_get(*opts, nochanges))
529                 sb->mode |= FMODE_WRITE;
530
531         sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
532         if (IS_ERR(sb->bdev) &&
533             PTR_ERR(sb->bdev) == -EACCES &&
534             opt_get(*opts, read_only)) {
535                 sb->mode &= ~FMODE_WRITE;
536
537                 sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
538                 if (!IS_ERR(sb->bdev))
539                         opt_set(*opts, nochanges, true);
540         }
541
542         if (IS_ERR(sb->bdev)) {
543                 ret = PTR_ERR(sb->bdev);
544                 goto out;
545         }
546
547         err = "cannot allocate memory";
548         ret = bch2_sb_realloc(sb, 0);
549         if (ret)
550                 goto err;
551
552         ret = -EFAULT;
553         err = "dynamic fault";
554         if (bch2_fs_init_fault("read_super"))
555                 goto err;
556
557         ret = -EINVAL;
558         err = read_one_super(sb, offset);
559         if (!err)
560                 goto got_super;
561
562         if (opt_defined(*opts, sb))
563                 goto err;
564
565         pr_err("error reading default superblock: %s", err);
566
567         /*
568          * Error reading primary superblock - read location of backup
569          * superblocks:
570          */
571         bio_reset(sb->bio);
572         bio_set_dev(sb->bio, sb->bdev);
573         sb->bio->bi_iter.bi_sector = BCH_SB_LAYOUT_SECTOR;
574         sb->bio->bi_iter.bi_size = sizeof(struct bch_sb_layout);
575         bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
576         /*
577          * use sb buffer to read layout, since sb buffer is page aligned but
578          * layout won't be:
579          */
580         bch2_bio_map(sb->bio, sb->sb);
581
582         err = "IO error";
583         if (submit_bio_wait(sb->bio))
584                 goto err;
585
586         memcpy(&layout, sb->sb, sizeof(layout));
587         err = validate_sb_layout(&layout);
588         if (err)
589                 goto err;
590
591         for (i = layout.sb_offset;
592              i < layout.sb_offset + layout.nr_superblocks; i++) {
593                 offset = le64_to_cpu(*i);
594
595                 if (offset == opt_get(*opts, sb))
596                         continue;
597
598                 err = read_one_super(sb, offset);
599                 if (!err)
600                         goto got_super;
601         }
602
603         ret = -EINVAL;
604         goto err;
605
606 got_super:
607         err = "Superblock block size smaller than device block size";
608         ret = -EINVAL;
609         if (le16_to_cpu(sb->sb->block_size) << 9 <
610             bdev_logical_block_size(sb->bdev))
611                 goto err;
612
613         if (sb->mode & FMODE_WRITE)
614                 bdev_get_queue(sb->bdev)->backing_dev_info->capabilities
615                         |= BDI_CAP_STABLE_WRITES;
616         ret = 0;
617         sb->have_layout = true;
618 out:
619         pr_verbose_init(*opts, "ret %i", ret);
620         return ret;
621 err:
622         bch2_free_super(sb);
623         pr_err("error reading superblock: %s", err);
624         goto out;
625 }
626
627 /* write superblock: */
628
629 static void write_super_endio(struct bio *bio)
630 {
631         struct bch_dev *ca = bio->bi_private;
632
633         /* XXX: return errors directly */
634
635         if (bch2_dev_io_err_on(bio->bi_status, ca, "superblock write"))
636                 ca->sb_write_error = 1;
637
638         closure_put(&ca->fs->sb_write);
639         percpu_ref_put(&ca->io_ref);
640 }
641
642 static void read_back_super(struct bch_fs *c, struct bch_dev *ca)
643 {
644         struct bch_sb *sb = ca->disk_sb.sb;
645         struct bio *bio = ca->disk_sb.bio;
646
647         bio_reset(bio);
648         bio_set_dev(bio, ca->disk_sb.bdev);
649         bio->bi_iter.bi_sector  = le64_to_cpu(sb->layout.sb_offset[0]);
650         bio->bi_iter.bi_size    = 4096;
651         bio->bi_end_io          = write_super_endio;
652         bio->bi_private         = ca;
653         bio_set_op_attrs(bio, REQ_OP_READ, REQ_SYNC|REQ_META);
654         bch2_bio_map(bio, ca->sb_read_scratch);
655
656         this_cpu_add(ca->io_done->sectors[READ][BCH_DATA_SB],
657                      bio_sectors(bio));
658
659         percpu_ref_get(&ca->io_ref);
660         closure_bio_submit(bio, &c->sb_write);
661 }
662
663 static void write_one_super(struct bch_fs *c, struct bch_dev *ca, unsigned idx)
664 {
665         struct bch_sb *sb = ca->disk_sb.sb;
666         struct bio *bio = ca->disk_sb.bio;
667
668         sb->offset = sb->layout.sb_offset[idx];
669
670         SET_BCH_SB_CSUM_TYPE(sb, c->opts.metadata_checksum);
671         sb->csum = csum_vstruct(c, BCH_SB_CSUM_TYPE(sb),
672                                 null_nonce(), sb);
673
674         bio_reset(bio);
675         bio_set_dev(bio, ca->disk_sb.bdev);
676         bio->bi_iter.bi_sector  = le64_to_cpu(sb->offset);
677         bio->bi_iter.bi_size    =
678                 roundup((size_t) vstruct_bytes(sb),
679                         bdev_logical_block_size(ca->disk_sb.bdev));
680         bio->bi_end_io          = write_super_endio;
681         bio->bi_private         = ca;
682         bio_set_op_attrs(bio, REQ_OP_WRITE, REQ_SYNC|REQ_META);
683         bch2_bio_map(bio, sb);
684
685         this_cpu_add(ca->io_done->sectors[WRITE][BCH_DATA_SB],
686                      bio_sectors(bio));
687
688         percpu_ref_get(&ca->io_ref);
689         closure_bio_submit(bio, &c->sb_write);
690 }
691
692 int bch2_write_super(struct bch_fs *c)
693 {
694         struct closure *cl = &c->sb_write;
695         struct bch_dev *ca;
696         unsigned i, sb = 0, nr_wrote;
697         const char *err;
698         struct bch_devs_mask sb_written;
699         bool wrote, can_mount_without_written, can_mount_with_written;
700         int ret = 0;
701
702         lockdep_assert_held(&c->sb_lock);
703
704         closure_init_stack(cl);
705         memset(&sb_written, 0, sizeof(sb_written));
706
707         le64_add_cpu(&c->disk_sb.sb->seq, 1);
708
709         for_each_online_member(ca, c, i)
710                 bch2_sb_from_fs(c, ca);
711
712         for_each_online_member(ca, c, i) {
713                 err = bch2_sb_validate(&ca->disk_sb);
714                 if (err) {
715                         bch2_fs_inconsistent(c, "sb invalid before write: %s", err);
716                         ret = -1;
717                         goto out;
718                 }
719         }
720
721         if (c->opts.nochanges ||
722             test_bit(BCH_FS_ERROR, &c->flags))
723                 goto out;
724
725         for_each_online_member(ca, c, i) {
726                 __set_bit(ca->dev_idx, sb_written.d);
727                 ca->sb_write_error = 0;
728         }
729
730         for_each_online_member(ca, c, i)
731                 read_back_super(c, ca);
732         closure_sync(cl);
733
734         for_each_online_member(ca, c, i) {
735                 if (!ca->sb_write_error &&
736                     ca->disk_sb.seq !=
737                     le64_to_cpu(ca->sb_read_scratch->seq)) {
738                         bch2_fs_fatal_error(c,
739                                 "Superblock modified by another process");
740                         percpu_ref_put(&ca->io_ref);
741                         ret = -EROFS;
742                         goto out;
743                 }
744         }
745
746         do {
747                 wrote = false;
748                 for_each_online_member(ca, c, i)
749                         if (!ca->sb_write_error &&
750                             sb < ca->disk_sb.sb->layout.nr_superblocks) {
751                                 write_one_super(c, ca, sb);
752                                 wrote = true;
753                         }
754                 closure_sync(cl);
755                 sb++;
756         } while (wrote);
757
758         for_each_online_member(ca, c, i) {
759                 if (ca->sb_write_error)
760                         __clear_bit(ca->dev_idx, sb_written.d);
761                 else
762                         ca->disk_sb.seq = le64_to_cpu(ca->disk_sb.sb->seq);
763         }
764
765         nr_wrote = dev_mask_nr(&sb_written);
766
767         can_mount_with_written =
768                 bch2_have_enough_devs(__bch2_replicas_status(c, sb_written),
769                                       BCH_FORCE_IF_DEGRADED);
770
771         for (i = 0; i < ARRAY_SIZE(sb_written.d); i++)
772                 sb_written.d[i] = ~sb_written.d[i];
773
774         can_mount_without_written =
775                 bch2_have_enough_devs(__bch2_replicas_status(c, sb_written),
776                                       BCH_FORCE_IF_DEGRADED);
777
778         /*
779          * If we would be able to mount _without_ the devices we successfully
780          * wrote superblocks to, we weren't able to write to enough devices:
781          *
782          * Exception: if we can mount without the successes because we haven't
783          * written anything (new filesystem), we continue if we'd be able to
784          * mount with the devices we did successfully write to:
785          */
786         if (bch2_fs_fatal_err_on(!nr_wrote ||
787                                  (can_mount_without_written &&
788                                   !can_mount_with_written), c,
789                 "Unable to write superblock to sufficient devices"))
790                 ret = -1;
791 out:
792         /* Make new options visible after they're persistent: */
793         bch2_sb_update(c);
794         return ret;
795 }
796
797 /* BCH_SB_FIELD_journal: */
798
799 static int u64_cmp(const void *_l, const void *_r)
800 {
801         u64 l = *((const u64 *) _l), r = *((const u64 *) _r);
802
803         return l < r ? -1 : l > r ? 1 : 0;
804 }
805
806 static const char *bch2_sb_validate_journal(struct bch_sb *sb,
807                                             struct bch_sb_field *f)
808 {
809         struct bch_sb_field_journal *journal = field_to_type(f, journal);
810         struct bch_member *m = bch2_sb_get_members(sb)->members + sb->dev_idx;
811         const char *err;
812         unsigned nr;
813         unsigned i;
814         u64 *b;
815
816         journal = bch2_sb_get_journal(sb);
817         if (!journal)
818                 return NULL;
819
820         nr = bch2_nr_journal_buckets(journal);
821         if (!nr)
822                 return NULL;
823
824         b = kmalloc_array(sizeof(u64), nr, GFP_KERNEL);
825         if (!b)
826                 return "cannot allocate memory";
827
828         for (i = 0; i < nr; i++)
829                 b[i] = le64_to_cpu(journal->buckets[i]);
830
831         sort(b, nr, sizeof(u64), u64_cmp, NULL);
832
833         err = "journal bucket at sector 0";
834         if (!b[0])
835                 goto err;
836
837         err = "journal bucket before first bucket";
838         if (m && b[0] < le16_to_cpu(m->first_bucket))
839                 goto err;
840
841         err = "journal bucket past end of device";
842         if (m && b[nr - 1] >= le64_to_cpu(m->nbuckets))
843                 goto err;
844
845         err = "duplicate journal buckets";
846         for (i = 0; i + 1 < nr; i++)
847                 if (b[i] == b[i + 1])
848                         goto err;
849
850         err = NULL;
851 err:
852         kfree(b);
853         return err;
854 }
855
856 static const struct bch_sb_field_ops bch_sb_field_ops_journal = {
857         .validate       = bch2_sb_validate_journal,
858 };
859
860 /* BCH_SB_FIELD_members: */
861
862 static const char *bch2_sb_validate_members(struct bch_sb *sb,
863                                             struct bch_sb_field *f)
864 {
865         struct bch_sb_field_members *mi = field_to_type(f, members);
866         struct bch_member *m;
867
868         if ((void *) (mi->members + sb->nr_devices) >
869             vstruct_end(&mi->field))
870                 return "Invalid superblock: bad member info";
871
872         for (m = mi->members;
873              m < mi->members + sb->nr_devices;
874              m++) {
875                 if (!bch2_member_exists(m))
876                         continue;
877
878                 if (le64_to_cpu(m->nbuckets) > LONG_MAX)
879                         return "Too many buckets";
880
881                 if (le64_to_cpu(m->nbuckets) -
882                     le16_to_cpu(m->first_bucket) < BCH_MIN_NR_NBUCKETS)
883                         return "Not enough buckets";
884
885                 if (le16_to_cpu(m->bucket_size) <
886                     le16_to_cpu(sb->block_size))
887                         return "bucket size smaller than block size";
888
889                 if (le16_to_cpu(m->bucket_size) <
890                     BCH_SB_BTREE_NODE_SIZE(sb))
891                         return "bucket size smaller than btree node size";
892         }
893
894         return NULL;
895 }
896
897 static const struct bch_sb_field_ops bch_sb_field_ops_members = {
898         .validate       = bch2_sb_validate_members,
899 };
900
901 /* BCH_SB_FIELD_crypt: */
902
903 static const char *bch2_sb_validate_crypt(struct bch_sb *sb,
904                                           struct bch_sb_field *f)
905 {
906         struct bch_sb_field_crypt *crypt = field_to_type(f, crypt);
907
908         if (vstruct_bytes(&crypt->field) != sizeof(*crypt))
909                 return "invalid field crypt: wrong size";
910
911         if (BCH_CRYPT_KDF_TYPE(crypt))
912                 return "invalid field crypt: bad kdf type";
913
914         return NULL;
915 }
916
917 static const struct bch_sb_field_ops bch_sb_field_ops_crypt = {
918         .validate       = bch2_sb_validate_crypt,
919 };
920
921 /* BCH_SB_FIELD_clean: */
922
923 void bch2_sb_clean_renumber(struct bch_sb_field_clean *clean, int write)
924 {
925         struct jset_entry *entry;
926
927         for (entry = clean->start;
928              entry < (struct jset_entry *) vstruct_end(&clean->field);
929              entry = vstruct_next(entry))
930                 bch2_bkey_renumber(BKEY_TYPE_BTREE, bkey_to_packed(entry->start), write);
931 }
932
933 int bch2_fs_mark_dirty(struct bch_fs *c)
934 {
935         int ret;
936
937         /*
938          * Unconditionally write superblock, to verify it hasn't changed before
939          * we go rw:
940          */
941
942         mutex_lock(&c->sb_lock);
943         SET_BCH_SB_CLEAN(c->disk_sb.sb, false);
944         c->disk_sb.sb->compat[0] &= ~(1ULL << BCH_COMPAT_FEAT_ALLOC_INFO);
945         ret = bch2_write_super(c);
946         mutex_unlock(&c->sb_lock);
947
948         return ret;
949 }
950
951 struct jset_entry *
952 bch2_journal_super_entries_add_common(struct bch_fs *c,
953                                       struct jset_entry *entry)
954 {
955         struct btree_root *r;
956         unsigned i;
957
958         mutex_lock(&c->btree_root_lock);
959
960         for (r = c->btree_roots;
961              r < c->btree_roots + BTREE_ID_NR;
962              r++)
963                 if (r->alive) {
964                         entry->u64s     = r->key.u64s;
965                         entry->btree_id = r - c->btree_roots;
966                         entry->level    = r->level;
967                         entry->type     = BCH_JSET_ENTRY_btree_root;
968                         bkey_copy(&entry->start[0], &r->key);
969
970                         entry = vstruct_next(entry);
971                 }
972         c->btree_roots_dirty = false;
973
974         mutex_unlock(&c->btree_root_lock);
975
976         percpu_down_read_preempt_disable(&c->mark_lock);
977
978         {
979                 u64 nr_inodes = percpu_u64_get(&c->usage[0]->nr_inodes);
980                 struct jset_entry_usage *u =
981                         container_of(entry, struct jset_entry_usage, entry);
982
983                 memset(u, 0, sizeof(*u));
984                 u->entry.u64s   = DIV_ROUND_UP(sizeof(*u), sizeof(u64)) - 1;
985                 u->entry.type   = BCH_JSET_ENTRY_usage;
986                 u->entry.btree_id = FS_USAGE_INODES;
987                 u->v            = cpu_to_le64(nr_inodes);
988
989                 entry = vstruct_next(entry);
990         }
991
992         {
993                 struct jset_entry_usage *u =
994                         container_of(entry, struct jset_entry_usage, entry);
995
996                 memset(u, 0, sizeof(*u));
997                 u->entry.u64s   = DIV_ROUND_UP(sizeof(*u), sizeof(u64)) - 1;
998                 u->entry.type   = BCH_JSET_ENTRY_usage;
999                 u->entry.btree_id = FS_USAGE_KEY_VERSION;
1000                 u->v            = cpu_to_le64(atomic64_read(&c->key_version));
1001
1002                 entry = vstruct_next(entry);
1003         }
1004
1005         for (i = 0; i < BCH_REPLICAS_MAX; i++) {
1006                 struct jset_entry_usage *u =
1007                         container_of(entry, struct jset_entry_usage, entry);
1008                 u64 sectors = percpu_u64_get(&c->usage[0]->persistent_reserved[i]);
1009
1010                 if (!sectors)
1011                         continue;
1012
1013                 memset(u, 0, sizeof(*u));
1014                 u->entry.u64s   = DIV_ROUND_UP(sizeof(*u), sizeof(u64)) - 1;
1015                 u->entry.type   = BCH_JSET_ENTRY_usage;
1016                 u->entry.btree_id = FS_USAGE_RESERVED;
1017                 u->entry.level  = i;
1018                 u->v            = sectors;
1019
1020                 entry = vstruct_next(entry);
1021         }
1022
1023         for (i = 0; i < c->replicas.nr; i++) {
1024                 struct bch_replicas_entry *e =
1025                         cpu_replicas_entry(&c->replicas, i);
1026                 u64 sectors = percpu_u64_get(&c->usage[0]->replicas[i]);
1027                 struct jset_entry_data_usage *u =
1028                         container_of(entry, struct jset_entry_data_usage, entry);
1029
1030                 memset(u, 0, sizeof(*u));
1031                 u->entry.u64s   = DIV_ROUND_UP(sizeof(*u) + e->nr_devs,
1032                                                sizeof(u64)) - 1;
1033                 u->entry.type   = BCH_JSET_ENTRY_data_usage;
1034                 u->v            = cpu_to_le64(sectors);
1035                 memcpy(&u->r, e, replicas_entry_bytes(e));
1036
1037                 entry = vstruct_next(entry);
1038         }
1039
1040         percpu_up_read_preempt_enable(&c->mark_lock);
1041
1042         return entry;
1043 }
1044
1045 void bch2_fs_mark_clean(struct bch_fs *c)
1046 {
1047         struct bch_sb_field_clean *sb_clean;
1048         struct jset_entry *entry;
1049         unsigned u64s;
1050
1051         mutex_lock(&c->sb_lock);
1052         if (BCH_SB_CLEAN(c->disk_sb.sb))
1053                 goto out;
1054
1055         SET_BCH_SB_CLEAN(c->disk_sb.sb, true);
1056
1057         c->disk_sb.sb->compat[0] |= 1ULL << BCH_COMPAT_FEAT_ALLOC_INFO;
1058
1059         u64s = sizeof(*sb_clean) / sizeof(u64) + c->journal.entry_u64s_reserved;
1060
1061         sb_clean = bch2_sb_resize_clean(&c->disk_sb, u64s);
1062         if (!sb_clean) {
1063                 bch_err(c, "error resizing superblock while setting filesystem clean");
1064                 goto out;
1065         }
1066
1067         sb_clean->flags         = 0;
1068         sb_clean->read_clock    = cpu_to_le16(c->bucket_clock[READ].hand);
1069         sb_clean->write_clock   = cpu_to_le16(c->bucket_clock[WRITE].hand);
1070         sb_clean->journal_seq   = cpu_to_le64(journal_cur_seq(&c->journal) - 1);
1071
1072         /* Trying to catch outstanding bug: */
1073         BUG_ON(le64_to_cpu(sb_clean->journal_seq) > S64_MAX);
1074
1075         entry = sb_clean->start;
1076         entry = bch2_journal_super_entries_add_common(c, entry);
1077         BUG_ON((void *) entry > vstruct_end(&sb_clean->field));
1078
1079         memset(entry, 0,
1080                vstruct_end(&sb_clean->field) - (void *) entry);
1081
1082         if (le16_to_cpu(c->disk_sb.sb->version) <
1083             bcachefs_metadata_version_bkey_renumber)
1084                 bch2_sb_clean_renumber(sb_clean, WRITE);
1085
1086         bch2_write_super(c);
1087 out:
1088         mutex_unlock(&c->sb_lock);
1089 }
1090
1091 static const char *bch2_sb_validate_clean(struct bch_sb *sb,
1092                                           struct bch_sb_field *f)
1093 {
1094         struct bch_sb_field_clean *clean = field_to_type(f, clean);
1095
1096         if (vstruct_bytes(&clean->field) < sizeof(*clean))
1097                 return "invalid field crypt: wrong size";
1098
1099         return NULL;
1100 }
1101
1102 static const struct bch_sb_field_ops bch_sb_field_ops_clean = {
1103         .validate       = bch2_sb_validate_clean,
1104 };
1105
1106 static const struct bch_sb_field_ops *bch2_sb_field_ops[] = {
1107 #define x(f, nr)                                        \
1108         [BCH_SB_FIELD_##f] = &bch_sb_field_ops_##f,
1109         BCH_SB_FIELDS()
1110 #undef x
1111 };
1112
1113 static const char *bch2_sb_field_validate(struct bch_sb *sb,
1114                                           struct bch_sb_field *f)
1115 {
1116         unsigned type = le32_to_cpu(f->type);
1117
1118         return type < BCH_SB_FIELD_NR
1119                 ? bch2_sb_field_ops[type]->validate(sb, f)
1120                 : NULL;
1121 }
1122
1123 void bch2_sb_field_to_text(struct printbuf *out, struct bch_sb *sb,
1124                            struct bch_sb_field *f)
1125 {
1126         unsigned type = le32_to_cpu(f->type);
1127         const struct bch_sb_field_ops *ops = type < BCH_SB_FIELD_NR
1128                 ? bch2_sb_field_ops[type] : NULL;
1129
1130         if (ops)
1131                 pr_buf(out, "%s", bch2_sb_fields[type]);
1132         else
1133                 pr_buf(out, "(unknown field %u)", type);
1134
1135         pr_buf(out, " (size %llu):", vstruct_bytes(f));
1136
1137         if (ops && ops->to_text)
1138                 bch2_sb_field_ops[type]->to_text(out, sb, f);
1139 }