]> git.sesse.net Git - bcachefs-tools-debian/blobdiff - libbcachefs/super-io.c
Update bcachefs sources to bdf6d7c135 fixup! bcachefs: Kill journal buf bloom filter
[bcachefs-tools-debian] / libbcachefs / super-io.c
index 1e4eafb2fa1011d259ff1bcfe38d954a910256b7..a2b789b4ac68a344dde31b82ffe1687373f0eecc 100644 (file)
@@ -1,23 +1,38 @@
+// SPDX-License-Identifier: GPL-2.0
 
 #include "bcachefs.h"
+#include "btree_update_interior.h"
+#include "buckets.h"
 #include "checksum.h"
+#include "disk_groups.h"
+#include "ec.h"
 #include "error.h"
 #include "io.h"
 #include "journal.h"
+#include "journal_io.h"
+#include "journal_sb.h"
+#include "journal_seq_blacklist.h"
+#include "replicas.h"
+#include "quota.h"
 #include "super-io.h"
 #include "super.h"
 #include "vstructs.h"
+#include "counters.h"
 
 #include <linux/backing-dev.h>
 #include <linux/sort.h>
 
-static int bch2_sb_replicas_to_cpu_replicas(struct bch_fs *);
-static const char *bch2_sb_validate_replicas(struct bch_sb *);
+#include <trace/events/bcachefs.h>
 
-static inline void __bch2_sb_layout_size_assert(void)
-{
-       BUILD_BUG_ON(sizeof(struct bch_sb_layout) != 512);
-}
+const char * const bch2_sb_fields[] = {
+#define x(name, nr)    #name,
+       BCH_SB_FIELDS()
+#undef x
+       NULL
+};
+
+static int bch2_sb_field_validate(struct bch_sb *, struct bch_sb_field *,
+                                 struct printbuf *);
 
 struct bch_sb_field *bch2_sb_field_get(struct bch_sb *sb,
                                      enum bch_sb_field_type type)
@@ -32,117 +47,119 @@ struct bch_sb_field *bch2_sb_field_get(struct bch_sb *sb,
        return NULL;
 }
 
-void bch2_free_super(struct bch_sb_handle *sb)
-{
-       if (sb->bio)
-               bio_put(sb->bio);
-       if (!IS_ERR_OR_NULL(sb->bdev))
-               blkdev_put(sb->bdev, sb->mode);
-
-       free_pages((unsigned long) sb->sb, sb->page_order);
-       memset(sb, 0, sizeof(*sb));
-}
-
-static int __bch2_super_realloc(struct bch_sb_handle *sb, unsigned order)
+static struct bch_sb_field *__bch2_sb_field_resize(struct bch_sb_handle *sb,
+                                                  struct bch_sb_field *f,
+                                                  unsigned u64s)
 {
-       struct bch_sb *new_sb;
-       struct bio *bio;
-
-       if (sb->page_order >= order && sb->sb)
-               return 0;
+       unsigned old_u64s = f ? le32_to_cpu(f->u64s) : 0;
+       unsigned sb_u64s = le32_to_cpu(sb->sb->u64s) + u64s - old_u64s;
 
-       if (dynamic_fault("bcachefs:add:super_realloc"))
-               return -ENOMEM;
+       BUG_ON(__vstruct_bytes(struct bch_sb, sb_u64s) > sb->buffer_size);
 
-       bio = bio_kmalloc(GFP_KERNEL, 1 << order);
-       if (!bio)
-               return -ENOMEM;
+       if (!f && !u64s) {
+               /* nothing to do: */
+       } else if (!f) {
+               f = vstruct_last(sb->sb);
+               memset(f, 0, sizeof(u64) * u64s);
+               f->u64s = cpu_to_le32(u64s);
+               f->type = 0;
+       } else {
+               void *src, *dst;
 
-       if (sb->bio)
-               bio_put(sb->bio);
-       sb->bio = bio;
+               src = vstruct_end(f);
 
-       new_sb = (void *) __get_free_pages(GFP_KERNEL, order);
-       if (!new_sb)
-               return -ENOMEM;
+               if (u64s) {
+                       f->u64s = cpu_to_le32(u64s);
+                       dst = vstruct_end(f);
+               } else {
+                       dst = f;
+               }
 
-       if (sb->sb)
-               memcpy(new_sb, sb->sb, PAGE_SIZE << sb->page_order);
+               memmove(dst, src, vstruct_end(sb->sb) - src);
 
-       free_pages((unsigned long) sb->sb, sb->page_order);
-       sb->sb = new_sb;
+               if (dst > src)
+                       memset(src, 0, dst - src);
+       }
 
-       sb->page_order = order;
+       sb->sb->u64s = cpu_to_le32(sb_u64s);
 
-       return 0;
+       return u64s ? f : NULL;
 }
 
-static int bch2_sb_realloc(struct bch_sb_handle *sb, unsigned u64s)
+void bch2_sb_field_delete(struct bch_sb_handle *sb,
+                         enum bch_sb_field_type type)
 {
-       u64 new_bytes = __vstruct_bytes(struct bch_sb, u64s);
-       u64 max_bytes = 512 << sb->sb->layout.sb_max_size_bits;
+       struct bch_sb_field *f = bch2_sb_field_get(sb->sb, type);
 
-       if (new_bytes > max_bytes) {
-               char buf[BDEVNAME_SIZE];
+       if (f)
+               __bch2_sb_field_resize(sb, f, 0);
+}
 
-               pr_err("%s: superblock too big: want %llu but have %llu",
-                      bdevname(sb->bdev, buf), new_bytes, max_bytes);
-               return -ENOSPC;
-       }
+/* Superblock realloc/free: */
 
-       return __bch2_super_realloc(sb, get_order(new_bytes));
+void bch2_free_super(struct bch_sb_handle *sb)
+{
+       if (sb->bio)
+               bio_put(sb->bio);
+       if (!IS_ERR_OR_NULL(sb->bdev))
+               blkdev_put(sb->bdev, sb->mode);
+
+       kfree(sb->sb);
+       memset(sb, 0, sizeof(*sb));
 }
 
-static int bch2_fs_sb_realloc(struct bch_fs *c, unsigned u64s)
+int bch2_sb_realloc(struct bch_sb_handle *sb, unsigned u64s)
 {
-       u64 bytes = __vstruct_bytes(struct bch_sb, u64s);
-       struct bch_sb *sb;
-       unsigned order = get_order(bytes);
+       size_t new_bytes = __vstruct_bytes(struct bch_sb, u64s);
+       size_t new_buffer_size;
+       struct bch_sb *new_sb;
+       struct bio *bio;
 
-       if (c->disk_sb && order <= c->disk_sb_order)
-               return 0;
+       if (sb->bdev)
+               new_bytes = max_t(size_t, new_bytes, bdev_logical_block_size(sb->bdev));
 
-       sb = (void *) __get_free_pages(GFP_KERNEL|__GFP_ZERO, order);
-       if (!sb)
-               return -ENOMEM;
+       new_buffer_size = roundup_pow_of_two(new_bytes);
 
-       if (c->disk_sb)
-               memcpy(sb, c->disk_sb, PAGE_SIZE << c->disk_sb_order);
+       if (sb->sb && sb->buffer_size >= new_buffer_size)
+               return 0;
 
-       free_pages((unsigned long) c->disk_sb, c->disk_sb_order);
+       if (sb->have_layout) {
+               u64 max_bytes = 512 << sb->sb->layout.sb_max_size_bits;
 
-       c->disk_sb = sb;
-       c->disk_sb_order = order;
-       return 0;
-}
+               if (new_bytes > max_bytes) {
+                       char buf[BDEVNAME_SIZE];
 
-static struct bch_sb_field *__bch2_sb_field_resize(struct bch_sb *sb,
-                                                 struct bch_sb_field *f,
-                                                 unsigned u64s)
-{
-       unsigned old_u64s = f ? le32_to_cpu(f->u64s) : 0;
+                       pr_err("%s: superblock too big: want %zu but have %llu",
+                              bdevname(sb->bdev, buf), new_bytes, max_bytes);
+                       return -ENOSPC;
+               }
+       }
 
-       if (!f) {
-               f = vstruct_last(sb);
-               memset(f, 0, sizeof(u64) * u64s);
-               f->u64s = cpu_to_le32(u64s);
-               f->type = 0;
-       } else {
-               void *src, *dst;
+       if (sb->buffer_size >= new_buffer_size && sb->sb)
+               return 0;
 
-               src = vstruct_end(f);
-               f->u64s = cpu_to_le32(u64s);
-               dst = vstruct_end(f);
+       if (dynamic_fault("bcachefs:add:super_realloc"))
+               return -ENOMEM;
 
-               memmove(dst, src, vstruct_end(sb) - src);
+       if (sb->have_bio) {
+               bio = bio_kmalloc(GFP_KERNEL,
+                       DIV_ROUND_UP(new_buffer_size, PAGE_SIZE));
+               if (!bio)
+                       return -ENOMEM;
 
-               if (dst > src)
-                       memset(src, 0, dst - src);
+               if (sb->bio)
+                       bio_put(sb->bio);
+               sb->bio = bio;
        }
 
-       le32_add_cpu(&sb->u64s, u64s - old_u64s);
+       new_sb = krealloc(sb->sb, new_buffer_size, GFP_NOFS|__GFP_ZERO);
+       if (!new_sb)
+               return -ENOMEM;
 
-       return f;
+       sb->sb = new_sb;
+       sb->buffer_size = new_buffer_size;
+
+       return 0;
 }
 
 struct bch_sb_field *bch2_sb_field_resize(struct bch_sb_handle *sb,
@@ -156,58 +173,64 @@ struct bch_sb_field *bch2_sb_field_resize(struct bch_sb_handle *sb,
        if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d))
                return NULL;
 
-       f = __bch2_sb_field_resize(sb->sb, f, u64s);
-       f->type = type;
-       return f;
-}
-
-struct bch_sb_field *bch2_fs_sb_field_resize(struct bch_fs *c,
-                                           enum bch_sb_field_type type,
-                                           unsigned u64s)
-{
-       struct bch_sb_field *f = bch2_sb_field_get(c->disk_sb, type);
-       ssize_t old_u64s = f ? le32_to_cpu(f->u64s) : 0;
-       ssize_t d = -old_u64s + u64s;
-       struct bch_dev *ca;
-       unsigned i;
-
-       lockdep_assert_held(&c->sb_lock);
+       if (sb->fs_sb) {
+               struct bch_fs *c = container_of(sb, struct bch_fs, disk_sb);
+               struct bch_dev *ca;
+               unsigned i;
 
-       if (bch2_fs_sb_realloc(c, le32_to_cpu(c->disk_sb->u64s) + d))
-               return NULL;
+               lockdep_assert_held(&c->sb_lock);
 
-       /* XXX: we're not checking that offline device have enough space */
+               /* XXX: we're not checking that offline device have enough space */
 
-       for_each_online_member(ca, c, i) {
-               struct bch_sb_handle *sb = &ca->disk_sb;
+               for_each_online_member(ca, c, i) {
+                       struct bch_sb_handle *sb = &ca->disk_sb;
 
-               if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d)) {
-                       percpu_ref_put(&ca->ref);
-                       return NULL;
+                       if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s) + d)) {
+                               percpu_ref_put(&ca->ref);
+                               return NULL;
+                       }
                }
        }
 
-       f = __bch2_sb_field_resize(c->disk_sb, f, u64s);
-       f->type = type;
+       f = bch2_sb_field_get(sb->sb, type);
+       f = __bch2_sb_field_resize(sb, f, u64s);
+       if (f)
+               f->type = cpu_to_le32(type);
        return f;
 }
 
-static const char *validate_sb_layout(struct bch_sb_layout *layout)
+/* Superblock validate: */
+
+static inline void __bch2_sb_layout_size_assert(void)
+{
+       BUILD_BUG_ON(sizeof(struct bch_sb_layout) != 512);
+}
+
+static int validate_sb_layout(struct bch_sb_layout *layout, struct printbuf *out)
 {
        u64 offset, prev_offset, max_sectors;
        unsigned i;
 
-       if (uuid_le_cmp(layout->magic, BCACHE_MAGIC))
-               return "Not a bcachefs superblock layout";
+       if (uuid_le_cmp(layout->magic, BCACHE_MAGIC)) {
+               pr_buf(out, "Not a bcachefs superblock layout");
+               return -EINVAL;
+       }
 
-       if (layout->layout_type != 0)
-               return "Invalid superblock layout type";
+       if (layout->layout_type != 0) {
+               pr_buf(out, "Invalid superblock layout type %u",
+                      layout->layout_type);
+               return -EINVAL;
+       }
 
-       if (!layout->nr_superblocks)
-               return "Invalid superblock layout: no superblocks";
+       if (!layout->nr_superblocks) {
+               pr_buf(out, "Invalid superblock layout: no superblocks");
+               return -EINVAL;
+       }
 
-       if (layout->nr_superblocks > ARRAY_SIZE(layout->sb_offset))
-               return "Invalid superblock layout: too many superblocks";
+       if (layout->nr_superblocks > ARRAY_SIZE(layout->sb_offset)) {
+               pr_buf(out, "Invalid superblock layout: too many superblocks");
+               return -EINVAL;
+       }
 
        max_sectors = 1 << layout->sb_max_size_bits;
 
@@ -216,246 +239,170 @@ static const char *validate_sb_layout(struct bch_sb_layout *layout)
        for (i = 1; i < layout->nr_superblocks; i++) {
                offset = le64_to_cpu(layout->sb_offset[i]);
 
-               if (offset < prev_offset + max_sectors)
-                       return "Invalid superblock layout: superblocks overlap";
+               if (offset < prev_offset + max_sectors) {
+                       pr_buf(out, "Invalid superblock layout: superblocks overlap\n"
+                              "  (sb %u ends at %llu next starts at %llu",
+                              i - 1, prev_offset + max_sectors, offset);
+                       return -EINVAL;
+               }
                prev_offset = offset;
        }
 
-       return NULL;
-}
-
-static int u64_cmp(const void *_l, const void *_r)
-{
-       u64 l = *((const u64 *) _l), r = *((const u64 *) _r);
-
-       return l < r ? -1 : l > r ? 1 : 0;
-}
-
-const char *bch2_sb_validate_journal(struct bch_sb *sb,
-                                    struct bch_member_cpu mi)
-{
-       struct bch_sb_field_journal *journal;
-       const char *err;
-       unsigned nr;
-       unsigned i;
-       u64 *b;
-
-       journal = bch2_sb_get_journal(sb);
-       if (!journal)
-               return NULL;
-
-       nr = bch2_nr_journal_buckets(journal);
-       if (!nr)
-               return NULL;
-
-       b = kmalloc_array(sizeof(u64), nr, GFP_KERNEL);
-       if (!b)
-               return "cannot allocate memory";
-
-       for (i = 0; i < nr; i++)
-               b[i] = le64_to_cpu(journal->buckets[i]);
-
-       sort(b, nr, sizeof(u64), u64_cmp, NULL);
-
-       err = "journal bucket at sector 0";
-       if (!b[0])
-               goto err;
-
-       err = "journal bucket before first bucket";
-       if (b[0] < mi.first_bucket)
-               goto err;
-
-       err = "journal bucket past end of device";
-       if (b[nr - 1] >= mi.nbuckets)
-               goto err;
-
-       err = "duplicate journal buckets";
-       for (i = 0; i + 1 < nr; i++)
-               if (b[i] == b[i + 1])
-                       goto err;
-
-       err = NULL;
-err:
-       kfree(b);
-       return err;
+       return 0;
 }
 
-static const char *bch2_sb_validate_members(struct bch_sb *sb)
+static int bch2_sb_validate(struct bch_sb_handle *disk_sb, struct printbuf *out,
+                           int rw)
 {
+       struct bch_sb *sb = disk_sb->sb;
+       struct bch_sb_field *f;
        struct bch_sb_field_members *mi;
-       unsigned i;
-
-       mi = bch2_sb_get_members(sb);
-       if (!mi)
-               return "Invalid superblock: member info area missing";
-
-       if ((void *) (mi->members + sb->nr_devices) >
-           vstruct_end(&mi->field))
-               return "Invalid superblock: bad member info";
+       enum bch_opt_id opt_id;
+       u32 version, version_min;
+       u16 block_size;
+       int ret;
 
-       for (i = 0; i < sb->nr_devices; i++) {
-               if (!bch2_dev_exists(sb, mi, i))
-                       continue;
+       version         = le16_to_cpu(sb->version);
+       version_min     = version >= bcachefs_metadata_version_bkey_renumber
+               ? le16_to_cpu(sb->version_min)
+               : version;
 
-               if (le16_to_cpu(mi->members[i].bucket_size) <
-                   BCH_SB_BTREE_NODE_SIZE(sb))
-                       return "bucket size smaller than btree node size";
+       if (version    >= bcachefs_metadata_version_max) {
+               pr_buf(out, "Unsupported superblock version %u (min %u, max %u)",
+                      version, bcachefs_metadata_version_min, bcachefs_metadata_version_max);
+               return -EINVAL;
        }
 
-       return NULL;
-}
-
-const char *bch2_sb_validate(struct bch_sb_handle *disk_sb)
-{
-       struct bch_sb *sb = disk_sb->sb;
-       struct bch_sb_field *f;
-       struct bch_sb_field_members *sb_mi;
-       struct bch_member_cpu mi;
-       const char *err;
-       u16 block_size;
+       if (version_min < bcachefs_metadata_version_min) {
+               pr_buf(out, "Unsupported superblock version %u (min %u, max %u)",
+                      version_min, bcachefs_metadata_version_min, bcachefs_metadata_version_max);
+               return -EINVAL;
+       }
 
-       if (le64_to_cpu(sb->version) < BCH_SB_VERSION_MIN ||
-           le64_to_cpu(sb->version) > BCH_SB_VERSION_MAX)
-               return"Unsupported superblock version";
+       if (version_min > version) {
+               pr_buf(out, "Bad minimum version %u, greater than version field %u",
+                      version_min, version);
+               return -EINVAL;
+       }
 
-       if (le64_to_cpu(sb->version) < BCH_SB_VERSION_EXTENT_MAX) {
-               SET_BCH_SB_ENCODED_EXTENT_MAX_BITS(sb, 7);
-               SET_BCH_SB_POSIX_ACL(sb, 1);
+       if (sb->features[1] ||
+           (le64_to_cpu(sb->features[0]) & (~0ULL << BCH_FEATURE_NR))) {
+               pr_buf(out, "Filesystem has incompatible features");
+               return -EINVAL;
        }
 
        block_size = le16_to_cpu(sb->block_size);
 
-       if (!is_power_of_2(block_size) ||
-           block_size > PAGE_SECTORS)
-               return "Bad block size";
+       if (block_size > PAGE_SECTORS) {
+               pr_buf(out, "Block size too big (got %u, max %u)",
+                      block_size, PAGE_SECTORS);
+               return -EINVAL;
+       }
 
-       if (bch2_is_zero(sb->user_uuid.b, sizeof(uuid_le)))
-               return "Bad user UUID";
+       if (bch2_is_zero(sb->user_uuid.b, sizeof(uuid_le))) {
+               pr_buf(out, "Bad user UUID (got zeroes)");
+               return -EINVAL;
+       }
 
-       if (bch2_is_zero(sb->uuid.b, sizeof(uuid_le)))
-               return "Bad internal UUID";
+       if (bch2_is_zero(sb->uuid.b, sizeof(uuid_le))) {
+               pr_buf(out, "Bad intenal UUID (got zeroes)");
+               return -EINVAL;
+       }
 
        if (!sb->nr_devices ||
-           sb->nr_devices <= sb->dev_idx ||
-           sb->nr_devices > BCH_SB_MEMBERS_MAX)
-               return "Bad cache device number in set";
-
-       if (!BCH_SB_META_REPLICAS_WANT(sb) ||
-           BCH_SB_META_REPLICAS_WANT(sb) >= BCH_REPLICAS_MAX)
-               return "Invalid number of metadata replicas";
-
-       if (!BCH_SB_META_REPLICAS_REQ(sb) ||
-           BCH_SB_META_REPLICAS_REQ(sb) >= BCH_REPLICAS_MAX)
-               return "Invalid number of metadata replicas";
+           sb->nr_devices > BCH_SB_MEMBERS_MAX) {
+               pr_buf(out, "Bad number of member devices %u (max %u)",
+                      sb->nr_devices, BCH_SB_MEMBERS_MAX);
+               return -EINVAL;
+       }
 
-       if (!BCH_SB_DATA_REPLICAS_WANT(sb) ||
-           BCH_SB_DATA_REPLICAS_WANT(sb) >= BCH_REPLICAS_MAX)
-               return "Invalid number of data replicas";
+       if (sb->dev_idx >= sb->nr_devices) {
+               pr_buf(out, "Bad dev_idx (got %u, nr_devices %u)",
+                      sb->dev_idx, sb->nr_devices);
+               return -EINVAL;
+       }
 
-       if (!BCH_SB_DATA_REPLICAS_REQ(sb) ||
-           BCH_SB_DATA_REPLICAS_REQ(sb) >= BCH_REPLICAS_MAX)
-               return "Invalid number of metadata replicas";
+       if (!sb->time_precision ||
+           le32_to_cpu(sb->time_precision) > NSEC_PER_SEC) {
+               pr_buf(out, "Invalid time precision: %u (min 1, max %lu)",
+                      le32_to_cpu(sb->time_precision), NSEC_PER_SEC);
+               return -EINVAL;
+       }
 
-       if (!BCH_SB_BTREE_NODE_SIZE(sb))
-               return "Btree node size not set";
+       if (rw == READ) {
+               /*
+                * Been seeing a bug where these are getting inexplicably
+                * zeroed, so we'r now validating them, but we have to be
+                * careful not to preven people's filesystems from mounting:
+                */
+               if (!BCH_SB_JOURNAL_FLUSH_DELAY(sb))
+                       SET_BCH_SB_JOURNAL_FLUSH_DELAY(sb, 1000);
+               if (!BCH_SB_JOURNAL_RECLAIM_DELAY(sb))
+                       SET_BCH_SB_JOURNAL_RECLAIM_DELAY(sb, 1000);
+       }
 
-       if (!is_power_of_2(BCH_SB_BTREE_NODE_SIZE(sb)))
-               return "Btree node size not a power of two";
+       for (opt_id = 0; opt_id < bch2_opts_nr; opt_id++) {
+               const struct bch_option *opt = bch2_opt_table + opt_id;
 
-       if (BCH_SB_BTREE_NODE_SIZE(sb) > BTREE_NODE_SIZE_MAX)
-               return "Btree node size too large";
+               if (opt->get_sb != BCH2_NO_SB_OPT) {
+                       u64 v = bch2_opt_from_sb(sb, opt_id);
 
-       if (BCH_SB_GC_RESERVE(sb) < 5)
-               return "gc reserve percentage too small";
+                       pr_buf(out, "Invalid option ");
+                       ret = bch2_opt_validate(opt, v, out);
+                       if (ret)
+                               return ret;
 
-       if (!sb->time_precision ||
-           le32_to_cpu(sb->time_precision) > NSEC_PER_SEC)
-               return "invalid time precision";
+                       printbuf_reset(out);
+               }
+       }
 
        /* validate layout */
-       err = validate_sb_layout(&sb->layout);
-       if (err)
-               return err;
+       ret = validate_sb_layout(&sb->layout, out);
+       if (ret)
+               return ret;
 
        vstruct_for_each(sb, f) {
-               if (!f->u64s)
-                       return "Invalid superblock: invalid optional field";
-
-               if (vstruct_next(f) > vstruct_last(sb))
-                       return "Invalid superblock: invalid optional field";
+               if (!f->u64s) {
+                       pr_buf(out, "Invalid superblock: optional with size 0 (type %u)",
+                              le32_to_cpu(f->type));
+                       return -EINVAL;
+               }
 
-               if (le32_to_cpu(f->type) >= BCH_SB_FIELD_NR)
-                       return "Invalid superblock: unknown optional field type";
+               if (vstruct_next(f) > vstruct_last(sb)) {
+                       pr_buf(out, "Invalid superblock: optional field extends past end of superblock (type %u)",
+                              le32_to_cpu(f->type));
+                       return -EINVAL;
+               }
        }
 
-       err = bch2_sb_validate_members(sb);
-       if (err)
-               return err;
-
-       sb_mi = bch2_sb_get_members(sb);
-       mi = bch2_mi_to_cpu(sb_mi->members + sb->dev_idx);
-
-       if (le64_to_cpu(sb->version) < BCH_SB_VERSION_EXTENT_MAX) {
-               struct bch_member *m;
-
-               for (m = sb_mi->members;
-                    m < sb_mi->members + sb->nr_devices;
-                    m++)
-                       SET_BCH_MEMBER_DATA_ALLOWED(m, ~0);
+       /* members must be validated first: */
+       mi = bch2_sb_get_members(sb);
+       if (!mi) {
+               pr_buf(out, "Invalid superblock: member info area missing");
+               return -EINVAL;
        }
 
-       if (mi.nbuckets > LONG_MAX)
-               return "Too many buckets";
-
-       if (mi.nbuckets - mi.first_bucket < 1 << 10)
-               return "Not enough buckets";
-
-       if (mi.bucket_size < block_size)
-               return "Bad bucket size";
-
-       if (get_capacity(disk_sb->bdev->bd_disk) <
-           mi.bucket_size * mi.nbuckets)
-               return "Invalid superblock: device too small";
-
-       err = bch2_sb_validate_journal(sb, mi);
-       if (err)
-               return err;
+       ret = bch2_sb_field_validate(sb, &mi->field, out);
+       if (ret)
+               return ret;
 
-       err = bch2_sb_validate_replicas(sb);
-       if (err)
-               return err;
+       vstruct_for_each(sb, f) {
+               if (le32_to_cpu(f->type) == BCH_SB_FIELD_members)
+                       continue;
 
-       sb->version = cpu_to_le64(BCH_SB_VERSION_MAX);
+               ret = bch2_sb_field_validate(sb, f, out);
+               if (ret)
+                       return ret;
+       }
 
-       return NULL;
+       return 0;
 }
 
 /* device open: */
 
-static const char *bch2_blkdev_open(const char *path, fmode_t mode,
-                                  void *holder, struct block_device **ret)
-{
-       struct block_device *bdev;
-
-       *ret = NULL;
-       bdev = blkdev_get_by_path(path, mode, holder);
-       if (bdev == ERR_PTR(-EBUSY))
-               return "device busy";
-
-       if (IS_ERR(bdev))
-               return "failed to open device";
-
-       if (mode & FMODE_WRITE)
-               bdev_get_queue(bdev)->backing_dev_info->capabilities
-                       |= BDI_CAP_STABLE_WRITES;
-
-       *ret = bdev;
-       return NULL;
-}
-
 static void bch2_sb_update(struct bch_fs *c)
 {
-       struct bch_sb *src = c->disk_sb;
+       struct bch_sb *src = c->disk_sb.sb;
        struct bch_sb_field_members *mi = bch2_sb_get_members(src);
        struct bch_dev *ca;
        unsigned i;
@@ -464,24 +411,35 @@ static void bch2_sb_update(struct bch_fs *c)
 
        c->sb.uuid              = src->uuid;
        c->sb.user_uuid         = src->user_uuid;
+       c->sb.version           = le16_to_cpu(src->version);
+       c->sb.version_min       = le16_to_cpu(src->version_min);
        c->sb.nr_devices        = src->nr_devices;
        c->sb.clean             = BCH_SB_CLEAN(src);
        c->sb.encryption_type   = BCH_SB_ENCRYPTION_TYPE(src);
-       c->sb.encoded_extent_max= 1 << BCH_SB_ENCODED_EXTENT_MAX_BITS(src);
-       c->sb.time_base_lo      = le64_to_cpu(src->time_base_lo);
+
+       c->sb.nsec_per_time_unit = le32_to_cpu(src->time_precision);
+       c->sb.time_units_per_sec = NSEC_PER_SEC / c->sb.nsec_per_time_unit;
+
+       /* XXX this is wrong, we need a 96 or 128 bit integer type */
+       c->sb.time_base_lo      = div_u64(le64_to_cpu(src->time_base_lo),
+                                         c->sb.nsec_per_time_unit);
        c->sb.time_base_hi      = le32_to_cpu(src->time_base_hi);
-       c->sb.time_precision    = le32_to_cpu(src->time_precision);
+
+       c->sb.features          = le64_to_cpu(src->features[0]);
+       c->sb.compat            = le64_to_cpu(src->compat[0]);
 
        for_each_member_device(ca, c, i)
                ca->mi = bch2_mi_to_cpu(mi->members + i);
 }
 
-/* doesn't copy member info */
-static void __copy_super(struct bch_sb *dst, struct bch_sb *src)
+static void __copy_super(struct bch_sb_handle *dst_handle, struct bch_sb *src)
 {
        struct bch_sb_field *src_f, *dst_f;
+       struct bch_sb *dst = dst_handle->sb;
+       unsigned i;
 
        dst->version            = src->version;
+       dst->version_min        = src->version_min;
        dst->seq                = src->seq;
        dst->uuid               = src->uuid;
        dst->user_uuid          = src->user_uuid;
@@ -498,15 +456,17 @@ static void __copy_super(struct bch_sb *dst, struct bch_sb *src)
        memcpy(dst->features,   src->features,  sizeof(dst->features));
        memcpy(dst->compat,     src->compat,    sizeof(dst->compat));
 
-       vstruct_for_each(src, src_f) {
-               if (src_f->type == BCH_SB_FIELD_journal)
+       for (i = 0; i < BCH_SB_FIELD_NR; i++) {
+               if ((1U << i) & BCH_SINGLE_DEVICE_SB_FIELDS)
                        continue;
 
-               dst_f = bch2_sb_field_get(dst, src_f->type);
-               dst_f = __bch2_sb_field_resize(dst, dst_f,
-                               le32_to_cpu(src_f->u64s));
+               src_f = bch2_sb_field_get(src, i);
+               dst_f = bch2_sb_field_get(dst, i);
+               dst_f = __bch2_sb_field_resize(dst_handle, dst_f,
+                               src_f ? le32_to_cpu(src_f->u64s) : 0);
 
-               memcpy(dst_f, src_f, vstruct_bytes(src_f));
+               if (src_f)
+                       memcpy(dst_f, src_f, vstruct_bytes(src_f));
        }
 }
 
@@ -521,22 +481,28 @@ int bch2_sb_to_fs(struct bch_fs *c, struct bch_sb *src)
 
        lockdep_assert_held(&c->sb_lock);
 
-       if (bch2_fs_sb_realloc(c, le32_to_cpu(src->u64s) - journal_u64s))
-               return -ENOMEM;
+       ret = bch2_sb_realloc(&c->disk_sb,
+                             le32_to_cpu(src->u64s) - journal_u64s);
+       if (ret)
+               return ret;
 
-       __copy_super(c->disk_sb, src);
+       __copy_super(&c->disk_sb, src);
 
        ret = bch2_sb_replicas_to_cpu_replicas(c);
        if (ret)
                return ret;
 
+       ret = bch2_sb_disk_groups_to_cpu(c);
+       if (ret)
+               return ret;
+
        bch2_sb_update(c);
        return 0;
 }
 
 int bch2_sb_from_fs(struct bch_fs *c, struct bch_dev *ca)
 {
-       struct bch_sb *src = c->disk_sb, *dst = ca->disk_sb.sb;
+       struct bch_sb *src = c->disk_sb.sb, *dst = ca->disk_sb.sb;
        struct bch_sb_field_journal *journal_buckets =
                bch2_sb_get_journal(dst);
        unsigned journal_u64s = journal_buckets
@@ -549,153 +515,214 @@ int bch2_sb_from_fs(struct bch_fs *c, struct bch_dev *ca)
        if (ret)
                return ret;
 
-       __copy_super(dst, src);
-
+       __copy_super(&ca->disk_sb, src);
        return 0;
 }
 
 /* read superblock: */
 
-static const char *read_one_super(struct bch_sb_handle *sb, u64 offset)
+static int read_one_super(struct bch_sb_handle *sb, u64 offset, struct printbuf *err)
 {
        struct bch_csum csum;
+       u32 version, version_min;
        size_t bytes;
-       unsigned order;
+       int ret;
 reread:
        bio_reset(sb->bio);
-       sb->bio->bi_bdev = sb->bdev;
+       bio_set_dev(sb->bio, sb->bdev);
        sb->bio->bi_iter.bi_sector = offset;
-       sb->bio->bi_iter.bi_size = PAGE_SIZE << sb->page_order;
        bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
-       bch2_bio_map(sb->bio, sb->sb);
+       bch2_bio_map(sb->bio, sb->sb, sb->buffer_size);
+
+       ret = submit_bio_wait(sb->bio);
+       if (ret) {
+               pr_buf(err, "IO error: %i", ret);
+               return ret;
+       }
 
-       if (submit_bio_wait(sb->bio))
-               return "IO error";
+       if (uuid_le_cmp(sb->sb->magic, BCACHE_MAGIC)) {
+               pr_buf(err, "Not a bcachefs superblock");
+               return -EINVAL;
+       }
 
-       if (uuid_le_cmp(sb->sb->magic, BCACHE_MAGIC))
-               return "Not a bcachefs superblock";
+       version         = le16_to_cpu(sb->sb->version);
+       version_min     = version >= bcachefs_metadata_version_bkey_renumber
+               ? le16_to_cpu(sb->sb->version_min)
+               : version;
 
-       if (le64_to_cpu(sb->sb->version) < BCH_SB_VERSION_MIN ||
-           le64_to_cpu(sb->sb->version) > BCH_SB_VERSION_MAX)
-               return"Unsupported superblock version";
+       if (version    >= bcachefs_metadata_version_max) {
+               pr_buf(err, "Unsupported superblock version %u (min %u, max %u)",
+                      version, bcachefs_metadata_version_min, bcachefs_metadata_version_max);
+               return -EINVAL;
+       }
+
+       if (version_min < bcachefs_metadata_version_min) {
+               pr_buf(err, "Unsupported superblock version %u (min %u, max %u)",
+                      version_min, bcachefs_metadata_version_min, bcachefs_metadata_version_max);
+               return -EINVAL;
+       }
 
        bytes = vstruct_bytes(sb->sb);
 
-       if (bytes > 512 << sb->sb->layout.sb_max_size_bits)
-               return "Bad superblock: too big";
+       if (bytes > 512 << sb->sb->layout.sb_max_size_bits) {
+               pr_buf(err, "Invalid superblock: too big (got %zu bytes, layout max %lu)",
+                      bytes, 512UL << sb->sb->layout.sb_max_size_bits);
+               return -EINVAL;
+       }
 
-       order = get_order(bytes);
-       if (order > sb->page_order) {
-               if (__bch2_super_realloc(sb, order))
-                       return "cannot allocate memory";
+       if (bytes > sb->buffer_size) {
+               if (bch2_sb_realloc(sb, le32_to_cpu(sb->sb->u64s)))
+                       return -ENOMEM;
                goto reread;
        }
 
-       if (BCH_SB_CSUM_TYPE(sb->sb) >= BCH_CSUM_NR)
-               return "unknown csum type";
+       if (BCH_SB_CSUM_TYPE(sb->sb) >= BCH_CSUM_NR) {
+               pr_buf(err, "unknown checksum type %llu", BCH_SB_CSUM_TYPE(sb->sb));
+               return -EINVAL;
+       }
 
        /* XXX: verify MACs */
        csum = csum_vstruct(NULL, BCH_SB_CSUM_TYPE(sb->sb),
-                           (struct nonce) { 0 }, sb->sb);
+                           null_nonce(), sb->sb);
 
-       if (bch2_crc_cmp(csum, sb->sb->csum))
-               return "bad checksum reading superblock";
+       if (bch2_crc_cmp(csum, sb->sb->csum)) {
+               pr_buf(err, "bad checksum");
+               return -EINVAL;
+       }
 
-       return NULL;
+       sb->seq = le64_to_cpu(sb->sb->seq);
+
+       return 0;
 }
 
-const char *bch2_read_super(const char *path,
-                           struct bch_opts opts,
-                           struct bch_sb_handle *ret)
+int bch2_read_super(const char *path, struct bch_opts *opts,
+                   struct bch_sb_handle *sb)
 {
-       u64 offset = opt_get(opts, sb);
+       u64 offset = opt_get(*opts, sb);
        struct bch_sb_layout layout;
-       const char *err;
-       unsigned i;
+       struct printbuf err = PRINTBUF;
+       __le64 *i;
+       int ret;
+
+       pr_verbose_init(*opts, "");
+
+       memset(sb, 0, sizeof(*sb));
+       sb->mode        = FMODE_READ;
+       sb->have_bio    = true;
+
+       if (!opt_get(*opts, noexcl))
+               sb->mode |= FMODE_EXCL;
 
-       memset(ret, 0, sizeof(*ret));
-       ret->mode = FMODE_READ;
+       if (!opt_get(*opts, nochanges))
+               sb->mode |= FMODE_WRITE;
 
-       if (!opt_get(opts, noexcl))
-               ret->mode |= FMODE_EXCL;
+       sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
+       if (IS_ERR(sb->bdev) &&
+           PTR_ERR(sb->bdev) == -EACCES &&
+           opt_get(*opts, read_only)) {
+               sb->mode &= ~FMODE_WRITE;
 
-       if (!opt_get(opts, nochanges))
-               ret->mode |= FMODE_WRITE;
+               sb->bdev = blkdev_get_by_path(path, sb->mode, sb);
+               if (!IS_ERR(sb->bdev))
+                       opt_set(*opts, nochanges, true);
+       }
 
-       err = bch2_blkdev_open(path, ret->mode, ret, &ret->bdev);
-       if (err)
-               return err;
+       if (IS_ERR(sb->bdev)) {
+               ret = PTR_ERR(sb->bdev);
+               goto out;
+       }
 
-       err = "cannot allocate memory";
-       if (__bch2_super_realloc(ret, 0))
+       ret = bch2_sb_realloc(sb, 0);
+       if (ret) {
+               pr_buf(&err, "error allocating memory for superblock");
                goto err;
+       }
 
-       err = "dynamic fault";
-       if (bch2_fs_init_fault("read_super"))
+       if (bch2_fs_init_fault("read_super")) {
+               pr_buf(&err, "dynamic fault");
+               ret = -EFAULT;
                goto err;
+       }
 
-       err = read_one_super(ret, offset);
-       if (!err)
+       ret = read_one_super(sb, offset, &err);
+       if (!ret)
                goto got_super;
 
-       if (offset != BCH_SB_SECTOR) {
-               pr_err("error reading superblock: %s", err);
+       if (opt_defined(*opts, sb))
                goto err;
-       }
 
-       pr_err("error reading default superblock: %s", err);
+       printk(KERN_ERR "bcachefs (%s): error reading default superblock: %s",
+              path, err.buf);
+       printbuf_reset(&err);
 
        /*
         * Error reading primary superblock - read location of backup
         * superblocks:
         */
-       bio_reset(ret->bio);
-       ret->bio->bi_bdev = ret->bdev;
-       ret->bio->bi_iter.bi_sector = BCH_SB_LAYOUT_SECTOR;
-       ret->bio->bi_iter.bi_size = sizeof(struct bch_sb_layout);
-       bio_set_op_attrs(ret->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
+       bio_reset(sb->bio);
+       bio_set_dev(sb->bio, sb->bdev);
+       sb->bio->bi_iter.bi_sector = BCH_SB_LAYOUT_SECTOR;
+       bio_set_op_attrs(sb->bio, REQ_OP_READ, REQ_SYNC|REQ_META);
        /*
         * use sb buffer to read layout, since sb buffer is page aligned but
         * layout won't be:
         */
-       bch2_bio_map(ret->bio, ret->sb);
+       bch2_bio_map(sb->bio, sb->sb, sizeof(struct bch_sb_layout));
 
-       err = "IO error";
-       if (submit_bio_wait(ret->bio))
+       ret = submit_bio_wait(sb->bio);
+       if (ret) {
+               pr_buf(&err, "IO error: %i", ret);
                goto err;
+       }
 
-       memcpy(&layout, ret->sb, sizeof(layout));
-       err = validate_sb_layout(&layout);
-       if (err)
+       memcpy(&layout, sb->sb, sizeof(layout));
+       ret = validate_sb_layout(&layout, &err);
+       if (ret)
                goto err;
 
-       for (i = 0; i < layout.nr_superblocks; i++) {
-               u64 offset = le64_to_cpu(layout.sb_offset[i]);
+       for (i = layout.sb_offset;
+            i < layout.sb_offset + layout.nr_superblocks; i++) {
+               offset = le64_to_cpu(*i);
 
-               if (offset == BCH_SB_SECTOR)
+               if (offset == opt_get(*opts, sb))
                        continue;
 
-               err = read_one_super(ret, offset);
-               if (!err)
+               ret = read_one_super(sb, offset, &err);
+               if (!ret)
                        goto got_super;
        }
+
        goto err;
+
 got_super:
-       pr_debug("read sb version %llu, flags %llu, seq %llu, journal size %u",
-                le64_to_cpu(ret->sb->version),
-                le64_to_cpu(ret->sb->flags),
-                le64_to_cpu(ret->sb->seq),
-                le16_to_cpu(ret->sb->u64s));
-
-       err = "Superblock block size smaller than device block size";
-       if (le16_to_cpu(ret->sb->block_size) << 9 <
-           bdev_logical_block_size(ret->bdev))
+       if (le16_to_cpu(sb->sb->block_size) << 9 <
+           bdev_logical_block_size(sb->bdev)) {
+               pr_buf(&err, "block size (%u) smaller than device block size (%u)",
+                      le16_to_cpu(sb->sb->block_size) << 9,
+                      bdev_logical_block_size(sb->bdev));
+               ret = -EINVAL;
                goto err;
+       }
 
-       return NULL;
+       ret = 0;
+       sb->have_layout = true;
+
+       ret = bch2_sb_validate(sb, &err, READ);
+       if (ret) {
+               printk(KERN_ERR "bcachefs (%s): error validating superblock: %s",
+                      path, err.buf);
+               goto err_no_print;
+       }
+out:
+       pr_verbose_init(*opts, "ret %i", ret);
+       printbuf_exit(&err);
+       return ret;
 err:
-       bch2_free_super(ret);
-       return err;
+       printk(KERN_ERR "bcachefs (%s): error reading superblock: %s",
+              path, err.buf);
+err_no_print:
+       bch2_free_super(sb);
+       goto out;
 }
 
 /* write superblock: */
@@ -706,13 +733,34 @@ static void write_super_endio(struct bio *bio)
 
        /* XXX: return errors directly */
 
-       if (bch2_dev_io_err_on(bio->bi_error, ca, "superblock write"))
+       if (bch2_dev_io_err_on(bio->bi_status, ca, "superblock write error: %s",
+                              bch2_blk_status_to_str(bio->bi_status)))
                ca->sb_write_error = 1;
 
        closure_put(&ca->fs->sb_write);
        percpu_ref_put(&ca->io_ref);
 }
 
+static void read_back_super(struct bch_fs *c, struct bch_dev *ca)
+{
+       struct bch_sb *sb = ca->disk_sb.sb;
+       struct bio *bio = ca->disk_sb.bio;
+
+       bio_reset(bio);
+       bio_set_dev(bio, ca->disk_sb.bdev);
+       bio->bi_iter.bi_sector  = le64_to_cpu(sb->layout.sb_offset[0]);
+       bio->bi_end_io          = write_super_endio;
+       bio->bi_private         = ca;
+       bio_set_op_attrs(bio, REQ_OP_READ, REQ_SYNC|REQ_META);
+       bch2_bio_map(bio, ca->sb_read_scratch, PAGE_SIZE);
+
+       this_cpu_add(ca->io_done->sectors[READ][BCH_DATA_sb],
+                    bio_sectors(bio));
+
+       percpu_ref_get(&ca->io_ref);
+       closure_bio_submit(bio, &c->sb_write);
+}
+
 static void write_one_super(struct bch_fs *c, struct bch_dev *ca, unsigned idx)
 {
        struct bch_sb *sb = ca->disk_sb.sb;
@@ -720,57 +768,81 @@ static void write_one_super(struct bch_fs *c, struct bch_dev *ca, unsigned idx)
 
        sb->offset = sb->layout.sb_offset[idx];
 
-       SET_BCH_SB_CSUM_TYPE(sb, c->opts.metadata_checksum);
+       SET_BCH_SB_CSUM_TYPE(sb, bch2_csum_opt_to_type(c->opts.metadata_checksum, false));
        sb->csum = csum_vstruct(c, BCH_SB_CSUM_TYPE(sb),
-                               (struct nonce) { 0 }, sb);
+                               null_nonce(), sb);
 
        bio_reset(bio);
-       bio->bi_bdev            = ca->disk_sb.bdev;
+       bio_set_dev(bio, ca->disk_sb.bdev);
        bio->bi_iter.bi_sector  = le64_to_cpu(sb->offset);
-       bio->bi_iter.bi_size    =
-               roundup(vstruct_bytes(sb),
-                       bdev_logical_block_size(ca->disk_sb.bdev));
        bio->bi_end_io          = write_super_endio;
        bio->bi_private         = ca;
        bio_set_op_attrs(bio, REQ_OP_WRITE, REQ_SYNC|REQ_META);
-       bch2_bio_map(bio, sb);
+       bch2_bio_map(bio, sb,
+                    roundup((size_t) vstruct_bytes(sb),
+                            bdev_logical_block_size(ca->disk_sb.bdev)));
 
-       this_cpu_add(ca->io_done->sectors[WRITE][BCH_DATA_SB],
+       this_cpu_add(ca->io_done->sectors[WRITE][BCH_DATA_sb],
                     bio_sectors(bio));
 
        percpu_ref_get(&ca->io_ref);
        closure_bio_submit(bio, &c->sb_write);
 }
 
-void bch2_write_super(struct bch_fs *c)
+int bch2_write_super(struct bch_fs *c)
 {
        struct closure *cl = &c->sb_write;
        struct bch_dev *ca;
+       struct printbuf err = PRINTBUF;
        unsigned i, sb = 0, nr_wrote;
-       const char *err;
        struct bch_devs_mask sb_written;
        bool wrote, can_mount_without_written, can_mount_with_written;
+       unsigned degraded_flags = BCH_FORCE_IF_DEGRADED;
+       int ret = 0;
+
+       trace_write_super(c, _RET_IP_);
+
+       if (c->opts.very_degraded)
+               degraded_flags |= BCH_FORCE_IF_LOST;
 
        lockdep_assert_held(&c->sb_lock);
 
        closure_init_stack(cl);
        memset(&sb_written, 0, sizeof(sb_written));
 
-       le64_add_cpu(&c->disk_sb->seq, 1);
+       le64_add_cpu(&c->disk_sb.sb->seq, 1);
+
+       if (test_bit(BCH_FS_ERROR, &c->flags))
+               SET_BCH_SB_HAS_ERRORS(c->disk_sb.sb, 1);
+       if (test_bit(BCH_FS_TOPOLOGY_ERROR, &c->flags))
+               SET_BCH_SB_HAS_TOPOLOGY_ERRORS(c->disk_sb.sb, 1);
+
+       SET_BCH_SB_BIG_ENDIAN(c->disk_sb.sb, CPU_BIG_ENDIAN);
+
+       bch2_sb_counters_from_cpu(c);
 
        for_each_online_member(ca, c, i)
                bch2_sb_from_fs(c, ca);
 
        for_each_online_member(ca, c, i) {
-               err = bch2_sb_validate(&ca->disk_sb);
-               if (err) {
-                       bch2_fs_inconsistent(c, "sb invalid before write: %s", err);
+               printbuf_reset(&err);
+
+               ret = bch2_sb_validate(&ca->disk_sb, &err, WRITE);
+               if (ret) {
+                       bch2_fs_inconsistent(c, "sb invalid before write: %s", err.buf);
+                       percpu_ref_put(&ca->io_ref);
                        goto out;
                }
        }
 
-       if (c->opts.nochanges ||
-           test_bit(BCH_FS_ERROR, &c->flags))
+       if (c->opts.nochanges)
+               goto out;
+
+       /*
+        * Defer writing the superblock until filesystem initialization is
+        * complete - don't write out a partly initialized superblock:
+        */
+       if (!BCH_SB_INITIALIZED(c->disk_sb.sb))
                goto out;
 
        for_each_online_member(ca, c, i) {
@@ -778,10 +850,40 @@ void bch2_write_super(struct bch_fs *c)
                ca->sb_write_error = 0;
        }
 
+       for_each_online_member(ca, c, i)
+               read_back_super(c, ca);
+       closure_sync(cl);
+
+       for_each_online_member(ca, c, i) {
+               if (ca->sb_write_error)
+                       continue;
+
+               if (le64_to_cpu(ca->sb_read_scratch->seq) < ca->disk_sb.seq) {
+                       bch2_fs_fatal_error(c,
+                               "Superblock write was silently dropped! (seq %llu expected %llu)",
+                               le64_to_cpu(ca->sb_read_scratch->seq),
+                               ca->disk_sb.seq);
+                       percpu_ref_put(&ca->io_ref);
+                       ret = -EROFS;
+                       goto out;
+               }
+
+               if (le64_to_cpu(ca->sb_read_scratch->seq) > ca->disk_sb.seq) {
+                       bch2_fs_fatal_error(c,
+                               "Superblock modified by another process (seq %llu expected %llu)",
+                               le64_to_cpu(ca->sb_read_scratch->seq),
+                               ca->disk_sb.seq);
+                       percpu_ref_put(&ca->io_ref);
+                       ret = -EROFS;
+                       goto out;
+               }
+       }
+
        do {
                wrote = false;
                for_each_online_member(ca, c, i)
-                       if (sb < ca->disk_sb.sb->layout.nr_superblocks) {
+                       if (!ca->sb_write_error &&
+                           sb < ca->disk_sb.sb->layout.nr_superblocks) {
                                write_one_super(c, ca, sb);
                                wrote = true;
                        }
@@ -789,24 +891,23 @@ void bch2_write_super(struct bch_fs *c)
                sb++;
        } while (wrote);
 
-       for_each_online_member(ca, c, i)
+       for_each_online_member(ca, c, i) {
                if (ca->sb_write_error)
                        __clear_bit(ca->dev_idx, sb_written.d);
+               else
+                       ca->disk_sb.seq = le64_to_cpu(ca->disk_sb.sb->seq);
+       }
 
        nr_wrote = dev_mask_nr(&sb_written);
 
        can_mount_with_written =
-               bch2_have_enough_devs(c,
-                       __bch2_replicas_status(c, sb_written),
-                       BCH_FORCE_IF_DEGRADED);
+               bch2_have_enough_devs(c, sb_written, degraded_flags, false);
 
        for (i = 0; i < ARRAY_SIZE(sb_written.d); i++)
                sb_written.d[i] = ~sb_written.d[i];
 
        can_mount_without_written =
-               bch2_have_enough_devs(c,
-                       __bch2_replicas_status(c, sb_written),
-                       BCH_FORCE_IF_DEGRADED);
+               bch2_have_enough_devs(c, sb_written, degraded_flags, false);
 
        /*
         * If we would be able to mount _without_ the devices we successfully
@@ -816,594 +917,698 @@ void bch2_write_super(struct bch_fs *c)
         * written anything (new filesystem), we continue if we'd be able to
         * mount with the devices we did successfully write to:
         */
-       bch2_fs_fatal_err_on(!nr_wrote ||
-                            (can_mount_without_written &&
-                             !can_mount_with_written), c,
-               "Unable to write superblock to sufficient devices");
+       if (bch2_fs_fatal_err_on(!nr_wrote ||
+                                !can_mount_with_written ||
+                                (can_mount_without_written &&
+                                 !can_mount_with_written), c,
+               "Unable to write superblock to sufficient devices (from %ps)",
+               (void *) _RET_IP_))
+               ret = -1;
 out:
        /* Make new options visible after they're persistent: */
        bch2_sb_update(c);
+       printbuf_exit(&err);
+       return ret;
 }
 
-/* replica information: */
-
-static inline struct bch_replicas_cpu_entry *
-cpu_replicas_entry(struct bch_replicas_cpu *r, unsigned i)
-{
-       return (void *) r->entries + r->entry_size * i;
-}
-
-static inline bool replicas_test_dev(struct bch_replicas_cpu_entry *e,
-                                    unsigned dev)
+void __bch2_check_set_feature(struct bch_fs *c, unsigned feat)
 {
-       return (e->devs[dev >> 3] & (1 << (dev & 7))) != 0;
-}
+       mutex_lock(&c->sb_lock);
+       if (!(c->sb.features & (1ULL << feat))) {
+               c->disk_sb.sb->features[0] |= cpu_to_le64(1ULL << feat);
 
-static inline void replicas_set_dev(struct bch_replicas_cpu_entry *e,
-                                   unsigned dev)
-{
-       e->devs[dev >> 3] |= 1 << (dev & 7);
+               bch2_write_super(c);
+       }
+       mutex_unlock(&c->sb_lock);
 }
 
-static inline unsigned replicas_dev_slots(struct bch_replicas_cpu *r)
-{
-       return (r->entry_size -
-               offsetof(struct bch_replicas_cpu_entry, devs)) * 8;
-}
+/* BCH_SB_FIELD_members: */
 
-static void bch2_sb_replicas_nr_entries(struct bch_sb_field_replicas *r,
-                                       unsigned *nr,
-                                       unsigned *bytes,
-                                       unsigned *max_dev)
+static int bch2_sb_members_validate(struct bch_sb *sb,
+                                   struct bch_sb_field *f,
+                                   struct printbuf *err)
 {
-       struct bch_replicas_entry *i;
-       unsigned j;
-
-       *nr     = 0;
-       *bytes  = sizeof(*r);
-       *max_dev = 0;
-
-       if (!r)
-               return;
+       struct bch_sb_field_members *mi = field_to_type(f, members);
+       unsigned i;
 
-       for_each_replicas_entry(r, i) {
-               for (j = 0; j < i->nr; j++)
-                       *max_dev = max_t(unsigned, *max_dev, i->devs[j]);
-               (*nr)++;
+       if ((void *) (mi->members + sb->nr_devices) >
+           vstruct_end(&mi->field)) {
+               pr_buf(err, "too many devices for section size");
+               return -EINVAL;
        }
 
-       *bytes = (void *) i - (void *) r;
-}
-
-static struct bch_replicas_cpu *
-__bch2_sb_replicas_to_cpu_replicas(struct bch_sb_field_replicas *sb_r)
-{
-       struct bch_replicas_cpu *cpu_r;
-       unsigned i, nr, bytes, max_dev, entry_size;
-
-       bch2_sb_replicas_nr_entries(sb_r, &nr, &bytes, &max_dev);
-
-       entry_size = offsetof(struct bch_replicas_cpu_entry, devs) +
-               DIV_ROUND_UP(max_dev + 1, 8);
+       for (i = 0; i < sb->nr_devices; i++) {
+               struct bch_member *m = mi->members + i;
 
-       cpu_r = kzalloc(sizeof(struct bch_replicas_cpu) +
-                       nr * entry_size, GFP_NOIO);
-       if (!cpu_r)
-               return NULL;
+               if (!bch2_member_exists(m))
+                       continue;
 
-       cpu_r->nr               = nr;
-       cpu_r->entry_size       = entry_size;
+               if (le64_to_cpu(m->nbuckets) > LONG_MAX) {
+                       pr_buf(err, "device %u: too many buckets (got %llu, max %lu)",
+                              i, le64_to_cpu(m->nbuckets), LONG_MAX);
+                       return -EINVAL;
+               }
 
-       if (nr) {
-               struct bch_replicas_cpu_entry *dst =
-                       cpu_replicas_entry(cpu_r, 0);
-               struct bch_replicas_entry *src = sb_r->entries;
+               if (le64_to_cpu(m->nbuckets) -
+                   le16_to_cpu(m->first_bucket) < BCH_MIN_NR_NBUCKETS) {
+                       pr_buf(err, "device %u: not enough buckets (got %llu, max %u)",
+                              i, le64_to_cpu(m->nbuckets), BCH_MIN_NR_NBUCKETS);
+                       return -EINVAL;
+               }
 
-               while (dst < cpu_replicas_entry(cpu_r, nr)) {
-                       dst->data_type = src->data_type;
-                       for (i = 0; i < src->nr; i++)
-                               replicas_set_dev(dst, src->devs[i]);
+               if (le16_to_cpu(m->bucket_size) <
+                   le16_to_cpu(sb->block_size)) {
+                       pr_buf(err, "device %u: bucket size %u smaller than block size %u",
+                              i, le16_to_cpu(m->bucket_size), le16_to_cpu(sb->block_size));
+                       return -EINVAL;
+               }
 
-                       src     = replicas_entry_next(src);
-                       dst     = (void *) dst + entry_size;
+               if (le16_to_cpu(m->bucket_size) <
+                   BCH_SB_BTREE_NODE_SIZE(sb)) {
+                       pr_buf(err, "device %u: bucket size %u smaller than btree node size %llu",
+                              i, le16_to_cpu(m->bucket_size), BCH_SB_BTREE_NODE_SIZE(sb));
+                       return -EINVAL;
                }
        }
 
-       eytzinger0_sort(cpu_r->entries,
-                       cpu_r->nr,
-                       cpu_r->entry_size,
-                       memcmp, NULL);
-       return cpu_r;
+       return 0;
 }
 
-static int bch2_sb_replicas_to_cpu_replicas(struct bch_fs *c)
+static void bch2_sb_members_to_text(struct printbuf *out, struct bch_sb *sb,
+                                   struct bch_sb_field *f)
 {
-       struct bch_sb_field_replicas *sb_r;
-       struct bch_replicas_cpu *cpu_r, *old_r;
-
-       lockdep_assert_held(&c->sb_lock);
+       struct bch_sb_field_members *mi = field_to_type(f, members);
+       struct bch_sb_field_disk_groups *gi = bch2_sb_get_disk_groups(sb);
+       unsigned i;
 
-       sb_r    = bch2_sb_get_replicas(c->disk_sb);
-       cpu_r   = __bch2_sb_replicas_to_cpu_replicas(sb_r);
-       if (!cpu_r)
-               return -ENOMEM;
+       for (i = 0; i < sb->nr_devices; i++) {
+               struct bch_member *m = mi->members + i;
+               unsigned data_have = bch2_sb_dev_has_data(sb, i);
+               u64 bucket_size = le16_to_cpu(m->bucket_size);
+               u64 device_size = le64_to_cpu(m->nbuckets) * bucket_size;
 
-       old_r = c->replicas;
-       rcu_assign_pointer(c->replicas, cpu_r);
-       if (old_r)
-               kfree_rcu(old_r, rcu);
+               if (!bch2_member_exists(m))
+                       continue;
 
-       return 0;
+               pr_buf(out, "Device:");
+               pr_tab(out);
+               pr_buf(out, "%u", i);
+               pr_newline(out);
+
+               pr_indent_push(out, 2);
+
+               pr_buf(out, "UUID:");
+               pr_tab(out);
+               pr_uuid(out, m->uuid.b);
+               pr_newline(out);
+
+               pr_buf(out, "Size:");
+               pr_tab(out);
+               pr_units(out, device_size, device_size << 9);
+               pr_newline(out);
+
+               pr_buf(out, "Bucket size:");
+               pr_tab(out);
+               pr_units(out, bucket_size, bucket_size << 9);
+               pr_newline(out);
+
+               pr_buf(out, "First bucket:");
+               pr_tab(out);
+               pr_buf(out, "%u", le16_to_cpu(m->first_bucket));
+               pr_newline(out);
+
+               pr_buf(out, "Buckets:");
+               pr_tab(out);
+               pr_buf(out, "%llu", le64_to_cpu(m->nbuckets));
+               pr_newline(out);
+
+               pr_buf(out, "Last mount:");
+               pr_tab(out);
+               if (m->last_mount)
+                       pr_time(out, le64_to_cpu(m->last_mount));
+               else
+                       pr_buf(out, "(never)");
+               pr_newline(out);
+
+               pr_buf(out, "State:");
+               pr_tab(out);
+               pr_buf(out, "%s",
+                      BCH_MEMBER_STATE(m) < BCH_MEMBER_STATE_NR
+                      ? bch2_member_states[BCH_MEMBER_STATE(m)]
+                      : "unknown");
+               pr_newline(out);
+
+               pr_buf(out, "Group:");
+               pr_tab(out);
+               if (BCH_MEMBER_GROUP(m)) {
+                       unsigned idx = BCH_MEMBER_GROUP(m) - 1;
+
+                       if (idx < disk_groups_nr(gi))
+                               pr_buf(out, "%s (%u)",
+                                      gi->entries[idx].label, idx);
+                       else
+                               pr_buf(out, "(bad disk labels section)");
+               } else {
+                       pr_buf(out, "(none)");
+               }
+               pr_newline(out);
+
+               pr_buf(out, "Data allowed:");
+               pr_tab(out);
+               if (BCH_MEMBER_DATA_ALLOWED(m))
+                       bch2_flags_to_text(out, bch2_data_types,
+                                          BCH_MEMBER_DATA_ALLOWED(m));
+               else
+                       pr_buf(out, "(none)");
+               pr_newline(out);
+
+               pr_buf(out, "Has data:");
+               pr_tab(out);
+               if (data_have)
+                       bch2_flags_to_text(out, bch2_data_types, data_have);
+               else
+                       pr_buf(out, "(none)");
+               pr_newline(out);
+
+               pr_buf(out, "Discard:");
+               pr_tab(out);
+               pr_buf(out, "%llu", BCH_MEMBER_DISCARD(m));
+               pr_newline(out);
+
+               pr_buf(out, "Freespace initialized:");
+               pr_tab(out);
+               pr_buf(out, "%llu", BCH_MEMBER_FREESPACE_INITIALIZED(m));
+               pr_newline(out);
+
+               pr_indent_pop(out, 2);
+       }
 }
 
-static void bkey_to_replicas(struct bkey_s_c_extent e,
-                            enum bch_data_type data_type,
-                            struct bch_replicas_cpu_entry *r,
-                            unsigned *max_dev)
-{
-       const struct bch_extent_ptr *ptr;
+static const struct bch_sb_field_ops bch_sb_field_ops_members = {
+       .validate       = bch2_sb_members_validate,
+       .to_text        = bch2_sb_members_to_text,
+};
 
-       BUG_ON(!data_type ||
-              data_type == BCH_DATA_SB ||
-              data_type >= BCH_DATA_NR);
+/* BCH_SB_FIELD_crypt: */
 
-       memset(r, 0, sizeof(*r));
-       r->data_type = data_type;
+static int bch2_sb_crypt_validate(struct bch_sb *sb,
+                                 struct bch_sb_field *f,
+                                 struct printbuf *err)
+{
+       struct bch_sb_field_crypt *crypt = field_to_type(f, crypt);
 
-       *max_dev = 0;
+       if (vstruct_bytes(&crypt->field) < sizeof(*crypt)) {
+               pr_buf(err, "wrong size (got %zu should be %zu)",
+                      vstruct_bytes(&crypt->field), sizeof(*crypt));
+               return -EINVAL;
+       }
 
-       extent_for_each_ptr(e, ptr)
-               if (!ptr->cached) {
-                       *max_dev = max_t(unsigned, *max_dev, ptr->dev);
-                       replicas_set_dev(r, ptr->dev);
-               }
+       if (BCH_CRYPT_KDF_TYPE(crypt)) {
+               pr_buf(err, "bad kdf type %llu", BCH_CRYPT_KDF_TYPE(crypt));
+               return -EINVAL;
+       }
+
+       return 0;
 }
 
-/*
- * for when gc of replica information is in progress:
- */
-static int bch2_update_gc_replicas(struct bch_fs *c,
-                                  struct bch_replicas_cpu *gc_r,
-                                  struct bkey_s_c_extent e,
-                                  enum bch_data_type data_type)
+static void bch2_sb_crypt_to_text(struct printbuf *out, struct bch_sb *sb,
+                                 struct bch_sb_field *f)
 {
-       struct bch_replicas_cpu_entry new_e;
-       struct bch_replicas_cpu *new;
-       unsigned i, nr, entry_size, max_dev;
-
-       bkey_to_replicas(e, data_type, &new_e, &max_dev);
-
-       entry_size = offsetof(struct bch_replicas_cpu_entry, devs) +
-               DIV_ROUND_UP(max_dev + 1, 8);
-       entry_size = max(entry_size, gc_r->entry_size);
-       nr = gc_r->nr + 1;
-
-       new = kzalloc(sizeof(struct bch_replicas_cpu) +
-                     nr * entry_size, GFP_NOIO);
-       if (!new)
-               return -ENOMEM;
+       struct bch_sb_field_crypt *crypt = field_to_type(f, crypt);
+
+       pr_buf(out, "KFD:               %llu", BCH_CRYPT_KDF_TYPE(crypt));
+       pr_newline(out);
+       pr_buf(out, "scrypt n:          %llu", BCH_KDF_SCRYPT_N(crypt));
+       pr_newline(out);
+       pr_buf(out, "scrypt r:          %llu", BCH_KDF_SCRYPT_R(crypt));
+       pr_newline(out);
+       pr_buf(out, "scrypt p:          %llu", BCH_KDF_SCRYPT_P(crypt));
+       pr_newline(out);
+}
 
-       new->nr         = nr;
-       new->entry_size = entry_size;
+static const struct bch_sb_field_ops bch_sb_field_ops_crypt = {
+       .validate       = bch2_sb_crypt_validate,
+       .to_text        = bch2_sb_crypt_to_text,
+};
 
-       for (i = 0; i < gc_r->nr; i++)
-               memcpy(cpu_replicas_entry(new, i),
-                      cpu_replicas_entry(gc_r, i),
-                      gc_r->entry_size);
+/* BCH_SB_FIELD_clean: */
 
-       memcpy(cpu_replicas_entry(new, nr - 1),
-              &new_e,
-              new->entry_size);
+int bch2_sb_clean_validate_late(struct bch_fs *c, struct bch_sb_field_clean *clean, int write)
+{
+       struct jset_entry *entry;
+       int ret;
 
-       eytzinger0_sort(new->entries,
-                       new->nr,
-                       new->entry_size,
-                       memcmp, NULL);
+       for (entry = clean->start;
+            entry < (struct jset_entry *) vstruct_end(&clean->field);
+            entry = vstruct_next(entry)) {
+               ret = bch2_journal_entry_validate(c, "superblock", entry,
+                                                 le16_to_cpu(c->disk_sb.sb->version),
+                                                 BCH_SB_BIG_ENDIAN(c->disk_sb.sb),
+                                                 write);
+               if (ret)
+                       return ret;
+       }
 
-       rcu_assign_pointer(c->replicas_gc, new);
-       kfree_rcu(gc_r, rcu);
        return 0;
 }
 
-static bool replicas_has_extent(struct bch_replicas_cpu *r,
-                               struct bkey_s_c_extent e,
-                               enum bch_data_type data_type)
+int bch2_fs_mark_dirty(struct bch_fs *c)
 {
-       struct bch_replicas_cpu_entry search;
-       unsigned max_dev;
+       int ret;
 
-       bkey_to_replicas(e, data_type, &search, &max_dev);
+       /*
+        * Unconditionally write superblock, to verify it hasn't changed before
+        * we go rw:
+        */
 
-       return max_dev < replicas_dev_slots(r) &&
-               eytzinger0_find(r->entries, r->nr,
-                               r->entry_size,
-                               memcmp, &search) < r->nr;
+       mutex_lock(&c->sb_lock);
+       SET_BCH_SB_CLEAN(c->disk_sb.sb, false);
+       c->disk_sb.sb->features[0] |= cpu_to_le64(BCH_SB_FEATURES_ALWAYS);
+       c->disk_sb.sb->compat[0] &= cpu_to_le64((1ULL << BCH_COMPAT_NR) - 1);
+       ret = bch2_write_super(c);
+       mutex_unlock(&c->sb_lock);
+
+       return ret;
 }
 
-bool bch2_sb_has_replicas(struct bch_fs *c, struct bkey_s_c_extent e,
-                         enum bch_data_type data_type)
+static struct jset_entry *jset_entry_init(struct jset_entry **end, size_t size)
 {
-       bool ret;
+       struct jset_entry *entry = *end;
+       unsigned u64s = DIV_ROUND_UP(size, sizeof(u64));
 
-       rcu_read_lock();
-       ret = replicas_has_extent(rcu_dereference(c->replicas),
-                                 e, data_type);
-       rcu_read_unlock();
+       memset(entry, 0, u64s * sizeof(u64));
+       /*
+        * The u64s field counts from the start of data, ignoring the shared
+        * fields.
+        */
+       entry->u64s = cpu_to_le16(u64s - 1);
 
-       return ret;
+       *end = vstruct_next(*end);
+       return entry;
 }
 
-noinline
-static int bch2_check_mark_super_slowpath(struct bch_fs *c,
-                                         struct bkey_s_c_extent e,
-                                         enum bch_data_type data_type)
+void bch2_journal_super_entries_add_common(struct bch_fs *c,
+                                          struct jset_entry **end,
+                                          u64 journal_seq)
 {
-       struct bch_replicas_cpu *gc_r;
-       const struct bch_extent_ptr *ptr;
-       struct bch_sb_field_replicas *sb_r;
-       struct bch_replicas_entry *new_entry;
-       unsigned new_entry_bytes, new_u64s, nr, bytes, max_dev;
-       int ret = 0;
+       struct bch_dev *ca;
+       unsigned i, dev;
 
-       mutex_lock(&c->sb_lock);
+       percpu_down_read(&c->mark_lock);
 
-       gc_r = rcu_dereference_protected(c->replicas_gc,
-                                        lockdep_is_held(&c->sb_lock));
-       if (gc_r &&
-           !replicas_has_extent(gc_r, e, data_type)) {
-               ret = bch2_update_gc_replicas(c, gc_r, e, data_type);
-               if (ret)
-                       goto err;
+       if (!journal_seq) {
+               for (i = 0; i < ARRAY_SIZE(c->usage); i++)
+                       bch2_fs_usage_acc_to_base(c, i);
+       } else {
+               bch2_fs_usage_acc_to_base(c, journal_seq & JOURNAL_BUF_MASK);
        }
 
-       /* recheck, might have raced */
-       if (bch2_sb_has_replicas(c, e, data_type)) {
-               mutex_unlock(&c->sb_lock);
-               return 0;
-       }
+       {
+               struct jset_entry_usage *u =
+                       container_of(jset_entry_init(end, sizeof(*u)),
+                                    struct jset_entry_usage, entry);
 
-       new_entry_bytes = sizeof(struct bch_replicas_entry) +
-               bch2_extent_nr_dirty_ptrs(e.s_c);
+               u->entry.type   = BCH_JSET_ENTRY_usage;
+               u->entry.btree_id = BCH_FS_USAGE_inodes;
+               u->v            = cpu_to_le64(c->usage_base->nr_inodes);
+       }
 
-       sb_r = bch2_sb_get_replicas(c->disk_sb);
+       {
+               struct jset_entry_usage *u =
+                       container_of(jset_entry_init(end, sizeof(*u)),
+                                    struct jset_entry_usage, entry);
 
-       bch2_sb_replicas_nr_entries(sb_r, &nr, &bytes, &max_dev);
+               u->entry.type   = BCH_JSET_ENTRY_usage;
+               u->entry.btree_id = BCH_FS_USAGE_key_version;
+               u->v            = cpu_to_le64(atomic64_read(&c->key_version));
+       }
 
-       new_u64s = DIV_ROUND_UP(bytes + new_entry_bytes, sizeof(u64));
+       for (i = 0; i < BCH_REPLICAS_MAX; i++) {
+               struct jset_entry_usage *u =
+                       container_of(jset_entry_init(end, sizeof(*u)),
+                                    struct jset_entry_usage, entry);
 
-       sb_r = bch2_fs_sb_resize_replicas(c,
-                       DIV_ROUND_UP(sizeof(*sb_r) + bytes + new_entry_bytes,
-                                    sizeof(u64)));
-       if (!sb_r) {
-               ret = -ENOSPC;
-               goto err;
+               u->entry.type   = BCH_JSET_ENTRY_usage;
+               u->entry.btree_id = BCH_FS_USAGE_reserved;
+               u->entry.level  = i;
+               u->v            = cpu_to_le64(c->usage_base->persistent_reserved[i]);
        }
 
-       new_entry = (void *) sb_r + bytes;
-       new_entry->data_type = data_type;
-       new_entry->nr = 0;
-
-       extent_for_each_ptr(e, ptr)
-               if (!ptr->cached)
-                       new_entry->devs[new_entry->nr++] = ptr->dev;
+       for (i = 0; i < c->replicas.nr; i++) {
+               struct bch_replicas_entry *e =
+                       cpu_replicas_entry(&c->replicas, i);
+               struct jset_entry_data_usage *u =
+                       container_of(jset_entry_init(end, sizeof(*u) + e->nr_devs),
+                                    struct jset_entry_data_usage, entry);
 
-       ret = bch2_sb_replicas_to_cpu_replicas(c);
-       if (ret) {
-               memset(new_entry, 0,
-                      vstruct_end(&sb_r->field) - (void *) new_entry);
-               goto err;
+               u->entry.type   = BCH_JSET_ENTRY_data_usage;
+               u->v            = cpu_to_le64(c->usage_base->replicas[i]);
+               memcpy(&u->r, e, replicas_entry_bytes(e));
        }
 
-       bch2_write_super(c);
-err:
-       mutex_unlock(&c->sb_lock);
-       return ret;
-}
-
-int bch2_check_mark_super(struct bch_fs *c, struct bkey_s_c_extent e,
-                         enum bch_data_type data_type)
-{
-       struct bch_replicas_cpu *gc_r;
-       bool marked;
+       for_each_member_device(ca, c, dev) {
+               unsigned b = sizeof(struct jset_entry_dev_usage) +
+                       sizeof(struct jset_entry_dev_usage_type) * BCH_DATA_NR;
+               struct jset_entry_dev_usage *u =
+                       container_of(jset_entry_init(end, b),
+                                    struct jset_entry_dev_usage, entry);
+
+               u->entry.type = BCH_JSET_ENTRY_dev_usage;
+               u->dev = cpu_to_le32(dev);
+               u->buckets_ec           = cpu_to_le64(ca->usage_base->buckets_ec);
+
+               for (i = 0; i < BCH_DATA_NR; i++) {
+                       u->d[i].buckets = cpu_to_le64(ca->usage_base->d[i].buckets);
+                       u->d[i].sectors = cpu_to_le64(ca->usage_base->d[i].sectors);
+                       u->d[i].fragmented = cpu_to_le64(ca->usage_base->d[i].fragmented);
+               }
+       }
 
-       rcu_read_lock();
-       marked = replicas_has_extent(rcu_dereference(c->replicas),
-                                    e, data_type) &&
-               (!(gc_r = rcu_dereference(c->replicas_gc)) ||
-                replicas_has_extent(gc_r, e, data_type));
-       rcu_read_unlock();
+       percpu_up_read(&c->mark_lock);
 
-       if (marked)
-               return 0;
+       for (i = 0; i < 2; i++) {
+               struct jset_entry_clock *clock =
+                       container_of(jset_entry_init(end, sizeof(*clock)),
+                                    struct jset_entry_clock, entry);
 
-       return bch2_check_mark_super_slowpath(c, e, data_type);
+               clock->entry.type = BCH_JSET_ENTRY_clock;
+               clock->rw       = i;
+               clock->time     = cpu_to_le64(atomic64_read(&c->io_clock[i].now));
+       }
 }
 
-struct replicas_status __bch2_replicas_status(struct bch_fs *c,
-                                       struct bch_devs_mask online_devs)
+void bch2_fs_mark_clean(struct bch_fs *c)
 {
-       struct bch_replicas_cpu_entry *e;
-       struct bch_replicas_cpu *r;
-       unsigned i, dev, dev_slots, nr_online, nr_offline;
-       struct replicas_status ret;
+       struct bch_sb_field_clean *sb_clean;
+       struct jset_entry *entry;
+       unsigned u64s;
+       int ret;
 
-       memset(&ret, 0, sizeof(ret));
+       mutex_lock(&c->sb_lock);
+       if (BCH_SB_CLEAN(c->disk_sb.sb))
+               goto out;
 
-       for (i = 0; i < ARRAY_SIZE(ret.replicas); i++)
-               ret.replicas[i].nr_online = UINT_MAX;
+       SET_BCH_SB_CLEAN(c->disk_sb.sb, true);
 
-       rcu_read_lock();
-       r = rcu_dereference(c->replicas);
-       dev_slots = min_t(unsigned, replicas_dev_slots(r), c->sb.nr_devices);
+       c->disk_sb.sb->compat[0] |= cpu_to_le64(1ULL << BCH_COMPAT_alloc_info);
+       c->disk_sb.sb->compat[0] |= cpu_to_le64(1ULL << BCH_COMPAT_alloc_metadata);
+       c->disk_sb.sb->features[0] &= cpu_to_le64(~(1ULL << BCH_FEATURE_extents_above_btree_updates));
+       c->disk_sb.sb->features[0] &= cpu_to_le64(~(1ULL << BCH_FEATURE_btree_updates_journalled));
 
-       for (i = 0; i < r->nr; i++) {
-               e = cpu_replicas_entry(r, i);
+       u64s = sizeof(*sb_clean) / sizeof(u64) + c->journal.entry_u64s_reserved;
 
-               BUG_ON(e->data_type >= ARRAY_SIZE(ret.replicas));
+       sb_clean = bch2_sb_resize_clean(&c->disk_sb, u64s);
+       if (!sb_clean) {
+               bch_err(c, "error resizing superblock while setting filesystem clean");
+               goto out;
+       }
 
-               nr_online = nr_offline = 0;
+       sb_clean->flags         = 0;
+       sb_clean->journal_seq   = cpu_to_le64(atomic64_read(&c->journal.seq));
 
-               for (dev = 0; dev < dev_slots; dev++) {
-                       if (!replicas_test_dev(e, dev))
-                               continue;
+       /* Trying to catch outstanding bug: */
+       BUG_ON(le64_to_cpu(sb_clean->journal_seq) > S64_MAX);
 
-                       if (test_bit(dev, online_devs.d))
-                               nr_online++;
-                       else
-                               nr_offline++;
-               }
+       entry = sb_clean->start;
+       bch2_journal_super_entries_add_common(c, &entry, 0);
+       entry = bch2_btree_roots_to_journal_entries(c, entry, entry);
+       BUG_ON((void *) entry > vstruct_end(&sb_clean->field));
 
-               ret.replicas[e->data_type].nr_online =
-                       min(ret.replicas[e->data_type].nr_online,
-                           nr_online);
+       memset(entry, 0,
+              vstruct_end(&sb_clean->field) - (void *) entry);
 
-               ret.replicas[e->data_type].nr_offline =
-                       max(ret.replicas[e->data_type].nr_offline,
-                           nr_offline);
+       /*
+        * this should be in the write path, and we should be validating every
+        * superblock section:
+        */
+       ret = bch2_sb_clean_validate_late(c, sb_clean, WRITE);
+       if (ret) {
+               bch_err(c, "error writing marking filesystem clean: validate error");
+               goto out;
        }
 
-       rcu_read_unlock();
-
-       return ret;
-}
-
-struct replicas_status bch2_replicas_status(struct bch_fs *c)
-{
-       return __bch2_replicas_status(c, bch2_online_devs(c));
+       bch2_write_super(c);
+out:
+       mutex_unlock(&c->sb_lock);
 }
 
-bool bch2_have_enough_devs(struct bch_fs *c,
-                          struct replicas_status s,
-                          unsigned flags)
+static int bch2_sb_clean_validate(struct bch_sb *sb,
+                                 struct bch_sb_field *f,
+                                 struct printbuf *err)
 {
-       if ((s.replicas[BCH_DATA_JOURNAL].nr_offline ||
-            s.replicas[BCH_DATA_BTREE].nr_offline) &&
-           !(flags & BCH_FORCE_IF_METADATA_DEGRADED))
-               return false;
-
-       if ((!s.replicas[BCH_DATA_JOURNAL].nr_online ||
-            !s.replicas[BCH_DATA_BTREE].nr_online) &&
-           !(flags & BCH_FORCE_IF_METADATA_LOST))
-               return false;
+       struct bch_sb_field_clean *clean = field_to_type(f, clean);
 
-       if (s.replicas[BCH_DATA_USER].nr_offline &&
-           !(flags & BCH_FORCE_IF_DATA_DEGRADED))
-               return false;
-
-       if (!s.replicas[BCH_DATA_USER].nr_online &&
-           !(flags & BCH_FORCE_IF_DATA_LOST))
-               return false;
+       if (vstruct_bytes(&clean->field) < sizeof(*clean)) {
+               pr_buf(err, "wrong size (got %zu should be %zu)",
+                      vstruct_bytes(&clean->field), sizeof(*clean));
+               return -EINVAL;
+       }
 
-       return true;
+       return 0;
 }
 
-unsigned bch2_replicas_online(struct bch_fs *c, bool meta)
+static void bch2_sb_clean_to_text(struct printbuf *out, struct bch_sb *sb,
+                                 struct bch_sb_field *f)
 {
-       struct replicas_status s = bch2_replicas_status(c);
+       struct bch_sb_field_clean *clean = field_to_type(f, clean);
+       struct jset_entry *entry;
+
+       pr_buf(out, "flags:          %x",       le32_to_cpu(clean->flags));
+       pr_newline(out);
+       pr_buf(out, "journal_seq:    %llu",     le64_to_cpu(clean->journal_seq));
+       pr_newline(out);
+
+       for (entry = clean->start;
+            entry != vstruct_end(&clean->field);
+            entry = vstruct_next(entry)) {
+               if (entry->type == BCH_JSET_ENTRY_btree_keys &&
+                   !entry->u64s)
+                       continue;
 
-       return meta
-               ? min(s.replicas[BCH_DATA_JOURNAL].nr_online,
-                     s.replicas[BCH_DATA_BTREE].nr_online)
-               : s.replicas[BCH_DATA_USER].nr_online;
+               bch2_journal_entry_to_text(out, NULL, entry);
+               pr_newline(out);
+       }
 }
 
-unsigned bch2_dev_has_data(struct bch_fs *c, struct bch_dev *ca)
-{
-       struct bch_replicas_cpu_entry *e;
-       struct bch_replicas_cpu *r;
-       unsigned i, ret = 0;
+static const struct bch_sb_field_ops bch_sb_field_ops_clean = {
+       .validate       = bch2_sb_clean_validate,
+       .to_text        = bch2_sb_clean_to_text,
+};
 
-       rcu_read_lock();
-       r = rcu_dereference(c->replicas);
+static const struct bch_sb_field_ops *bch2_sb_field_ops[] = {
+#define x(f, nr)                                       \
+       [BCH_SB_FIELD_##f] = &bch_sb_field_ops_##f,
+       BCH_SB_FIELDS()
+#undef x
+};
 
-       if (ca->dev_idx >= replicas_dev_slots(r))
-               goto out;
+static int bch2_sb_field_validate(struct bch_sb *sb, struct bch_sb_field *f,
+                                 struct printbuf *err)
+{
+       unsigned type = le32_to_cpu(f->type);
+       struct printbuf field_err = PRINTBUF;
+       int ret;
 
-       for (i = 0; i < r->nr; i++) {
-               e = cpu_replicas_entry(r, i);
+       if (type >= BCH_SB_FIELD_NR)
+               return 0;
 
-               if (replicas_test_dev(e, ca->dev_idx)) {
-                       ret |= 1 << e->data_type;
-                       break;
-               }
+       ret = bch2_sb_field_ops[type]->validate(sb, f, &field_err);
+       if (ret) {
+               pr_buf(err, "Invalid superblock section %s: %s",
+                      bch2_sb_fields[type],
+                      field_err.buf);
+               pr_newline(err);
+               bch2_sb_field_to_text(err, sb, f);
        }
-out:
-       rcu_read_unlock();
 
+       printbuf_exit(&field_err);
        return ret;
 }
 
-static const char *bch2_sb_validate_replicas(struct bch_sb *sb)
+void bch2_sb_field_to_text(struct printbuf *out, struct bch_sb *sb,
+                          struct bch_sb_field *f)
 {
-       struct bch_sb_field_members *mi;
-       struct bch_sb_field_replicas *sb_r;
-       struct bch_replicas_cpu *cpu_r = NULL;
-       struct bch_replicas_entry *e;
-       const char *err;
-       unsigned i;
+       unsigned type = le32_to_cpu(f->type);
+       const struct bch_sb_field_ops *ops = type < BCH_SB_FIELD_NR
+               ? bch2_sb_field_ops[type] : NULL;
 
-       mi      = bch2_sb_get_members(sb);
-       sb_r    = bch2_sb_get_replicas(sb);
-       if (!sb_r)
-               return NULL;
+       if (!out->tabstops[0])
+               out->tabstops[0] = 32;
 
-       for_each_replicas_entry(sb_r, e) {
-               err = "invalid replicas entry: invalid data type";
-               if (e->data_type >= BCH_DATA_NR)
-                       goto err;
+       if (ops)
+               pr_buf(out, "%s", bch2_sb_fields[type]);
+       else
+               pr_buf(out, "(unknown field %u)", type);
 
-               err = "invalid replicas entry: too many devices";
-               if (e->nr >= BCH_REPLICAS_MAX)
-                       goto err;
+       pr_buf(out, " (size %zu):", vstruct_bytes(f));
+       pr_newline(out);
 
-               err = "invalid replicas entry: invalid device";
-               for (i = 0; i < e->nr; i++)
-                       if (!bch2_dev_exists(sb, mi, e->devs[i]))
-                               goto err;
+       if (ops && ops->to_text) {
+               pr_indent_push(out, 2);
+               bch2_sb_field_ops[type]->to_text(out, sb, f);
+               pr_indent_pop(out, 2);
        }
-
-       err = "cannot allocate memory";
-       cpu_r = __bch2_sb_replicas_to_cpu_replicas(sb_r);
-       if (!cpu_r)
-               goto err;
-
-       sort_cmp_size(cpu_r->entries,
-                     cpu_r->nr,
-                     cpu_r->entry_size,
-                     memcmp, NULL);
-
-       for (i = 0; i + 1 < cpu_r->nr; i++) {
-               struct bch_replicas_cpu_entry *l =
-                       cpu_replicas_entry(cpu_r, i);
-               struct bch_replicas_cpu_entry *r =
-                       cpu_replicas_entry(cpu_r, i + 1);
-
-               BUG_ON(memcmp(l, r, cpu_r->entry_size) > 0);
-
-               err = "duplicate replicas entry";
-               if (!memcmp(l, r, cpu_r->entry_size))
-                       goto err;
-       }
-
-       err = NULL;
-err:
-       kfree(cpu_r);
-       return err;
 }
 
-int bch2_replicas_gc_end(struct bch_fs *c, int err)
+void bch2_sb_layout_to_text(struct printbuf *out, struct bch_sb_layout *l)
 {
-       struct bch_sb_field_replicas *sb_r;
-       struct bch_replicas_cpu *r, *old_r;
-       struct bch_replicas_entry *dst_e;
-       size_t i, j, bytes, dev_slots;
-       int ret = 0;
-
-       lockdep_assert_held(&c->replicas_gc_lock);
-
-       mutex_lock(&c->sb_lock);
-
-       r = rcu_dereference_protected(c->replicas_gc,
-                                     lockdep_is_held(&c->sb_lock));
-
-       if (err) {
-               rcu_assign_pointer(c->replicas_gc, NULL);
-               kfree_rcu(r, rcu);
-               goto err;
-       }
-
-       dev_slots = replicas_dev_slots(r);
-
-       bytes = sizeof(struct bch_sb_field_replicas);
-
-       for (i = 0; i < r->nr; i++) {
-               struct bch_replicas_cpu_entry *e =
-                       cpu_replicas_entry(r, i);
-
-               bytes += sizeof(struct bch_replicas_entry);
-               for (j = 0; j < r->entry_size - 1; j++)
-                       bytes += hweight8(e->devs[j]);
-       }
-
-       sb_r = bch2_fs_sb_resize_replicas(c,
-                       DIV_ROUND_UP(sizeof(*sb_r) + bytes, sizeof(u64)));
-       if (!sb_r) {
-               ret = -ENOSPC;
-               goto err;
-       }
-
-       memset(&sb_r->entries, 0,
-              vstruct_end(&sb_r->field) -
-              (void *) &sb_r->entries);
+       unsigned i;
 
-       dst_e = sb_r->entries;
-       for (i = 0; i < r->nr; i++) {
-               struct bch_replicas_cpu_entry *src_e =
-                       cpu_replicas_entry(r, i);
+       pr_buf(out, "Type:                    %u", l->layout_type);
+       pr_newline(out);
 
-               dst_e->data_type = src_e->data_type;
+       pr_buf(out, "Superblock max size:     ");
+       pr_units(out,
+                1 << l->sb_max_size_bits,
+                512 << l->sb_max_size_bits);
+       pr_newline(out);
 
-               for (j = 0; j < dev_slots; j++)
-                       if (replicas_test_dev(src_e, j))
-                               dst_e->devs[dst_e->nr++] = j;
+       pr_buf(out, "Nr superblocks:          %u", l->nr_superblocks);
+       pr_newline(out);
 
-               dst_e = replicas_entry_next(dst_e);
+       pr_buf(out, "Offsets:                 ");
+       for (i = 0; i < l->nr_superblocks; i++) {
+               if (i)
+                       pr_buf(out, ", ");
+               pr_buf(out, "%llu", le64_to_cpu(l->sb_offset[i]));
        }
-
-       old_r = rcu_dereference_protected(c->replicas,
-                                         lockdep_is_held(&c->sb_lock));
-       rcu_assign_pointer(c->replicas, r);
-       rcu_assign_pointer(c->replicas_gc, NULL);
-       kfree_rcu(old_r, rcu);
-
-       bch2_write_super(c);
-err:
-       mutex_unlock(&c->sb_lock);
-       return ret;
+       pr_newline(out);
 }
 
-int bch2_replicas_gc_start(struct bch_fs *c, unsigned typemask)
+void bch2_sb_to_text(struct printbuf *out, struct bch_sb *sb,
+                    bool print_layout, unsigned fields)
 {
-       struct bch_replicas_cpu *r, *src;
-       unsigned i;
-
-       lockdep_assert_held(&c->replicas_gc_lock);
+       struct bch_sb_field_members *mi;
+       struct bch_sb_field *f;
+       u64 fields_have = 0;
+       unsigned nr_devices = 0;
 
-       mutex_lock(&c->sb_lock);
-       BUG_ON(c->replicas_gc);
+       if (!out->tabstops[0])
+               out->tabstops[0] = 32;
 
-       src = rcu_dereference_protected(c->replicas,
-                                       lockdep_is_held(&c->sb_lock));
+       mi = bch2_sb_get_members(sb);
+       if (mi) {
+               struct bch_member *m;
 
-       r = kzalloc(sizeof(struct bch_replicas_cpu) +
-                   src->nr * src->entry_size, GFP_NOIO);
-       if (!r) {
-               mutex_unlock(&c->sb_lock);
-               return -ENOMEM;
+               for (m = mi->members;
+                    m < mi->members + sb->nr_devices;
+                    m++)
+                       nr_devices += bch2_member_exists(m);
        }
 
-       r->entry_size = src->entry_size;
-       r->nr = 0;
-
-       for (i = 0; i < src->nr; i++) {
-               struct bch_replicas_cpu_entry *dst_e =
-                       cpu_replicas_entry(r, r->nr);
-               struct bch_replicas_cpu_entry *src_e =
-                       cpu_replicas_entry(src, i);
-
-               if (!(src_e->data_type & typemask)) {
-                       memcpy(dst_e, src_e, r->entry_size);
-                       r->nr++;
+       pr_buf(out, "External UUID:");
+       pr_tab(out);
+       pr_uuid(out, sb->user_uuid.b);
+       pr_newline(out);
+
+       pr_buf(out, "Internal UUID:");
+       pr_tab(out);
+       pr_uuid(out, sb->uuid.b);
+       pr_newline(out);
+
+       pr_buf(out, "Device index:");
+       pr_tab(out);
+       pr_buf(out, "%u", sb->dev_idx);
+       pr_newline(out);
+
+       pr_buf(out, "Label:");
+       pr_tab(out);
+       pr_buf(out, "%.*s", (int) sizeof(sb->label), sb->label);
+       pr_newline(out);
+
+       pr_buf(out, "Version:");
+       pr_tab(out);
+       pr_buf(out, "%s", bch2_metadata_versions[le16_to_cpu(sb->version)]);
+       pr_newline(out);
+
+       pr_buf(out, "Oldest version on disk:");
+       pr_tab(out);
+       pr_buf(out, "%s", bch2_metadata_versions[le16_to_cpu(sb->version_min)]);
+       pr_newline(out);
+
+       pr_buf(out, "Created:");
+       pr_tab(out);
+       if (sb->time_base_lo)
+               pr_time(out, div_u64(le64_to_cpu(sb->time_base_lo), NSEC_PER_SEC));
+       else
+               pr_buf(out, "(not set)");
+       pr_newline(out);
+
+       pr_buf(out, "Sequence number:");
+       pr_tab(out);
+       pr_buf(out, "%llu", le64_to_cpu(sb->seq));
+       pr_newline(out);
+
+       pr_buf(out, "Superblock size:");
+       pr_tab(out);
+       pr_buf(out, "%zu", vstruct_bytes(sb));
+       pr_newline(out);
+
+       pr_buf(out, "Clean:");
+       pr_tab(out);
+       pr_buf(out, "%llu", BCH_SB_CLEAN(sb));
+       pr_newline(out);
+
+       pr_buf(out, "Devices:");
+       pr_tab(out);
+       pr_buf(out, "%u", nr_devices);
+       pr_newline(out);
+
+       pr_buf(out, "Sections:");
+       vstruct_for_each(sb, f)
+               fields_have |= 1 << le32_to_cpu(f->type);
+       pr_tab(out);
+       bch2_flags_to_text(out, bch2_sb_fields, fields_have);
+       pr_newline(out);
+
+       pr_buf(out, "Features:");
+       pr_tab(out);
+       bch2_flags_to_text(out, bch2_sb_features,
+                          le64_to_cpu(sb->features[0]));
+       pr_newline(out);
+
+       pr_buf(out, "Compat features:");
+       pr_tab(out);
+       bch2_flags_to_text(out, bch2_sb_compat,
+                          le64_to_cpu(sb->compat[0]));
+       pr_newline(out);
+
+       pr_newline(out);
+       pr_buf(out, "Options:");
+       pr_newline(out);
+       pr_indent_push(out, 2);
+       {
+               enum bch_opt_id id;
+
+               for (id = 0; id < bch2_opts_nr; id++) {
+                       const struct bch_option *opt = bch2_opt_table + id;
+
+                       if (opt->get_sb != BCH2_NO_SB_OPT) {
+                               u64 v = bch2_opt_from_sb(sb, id);
+
+                               pr_buf(out, "%s:", opt->attr.name);
+                               pr_tab(out);
+                               bch2_opt_to_text(out, NULL, sb, opt, v,
+                                                OPT_HUMAN_READABLE|OPT_SHOW_FULL_LIST);
+                               pr_newline(out);
+                       }
                }
        }
 
-       eytzinger0_sort(r->entries,
-                       r->nr,
-                       r->entry_size,
-                       memcmp, NULL);
+       pr_indent_pop(out, 2);
 
-       rcu_assign_pointer(c->replicas_gc, r);
-       mutex_unlock(&c->sb_lock);
+       if (print_layout) {
+               pr_newline(out);
+               pr_buf(out, "layout:");
+               pr_newline(out);
+               pr_indent_push(out, 2);
+               bch2_sb_layout_to_text(out, &sb->layout);
+               pr_indent_pop(out, 2);
+       }
 
-       return 0;
+       vstruct_for_each(sb, f)
+               if (fields & (1 << le32_to_cpu(f->type))) {
+                       pr_newline(out);
+                       bch2_sb_field_to_text(out, sb, f);
+               }
 }