1. 21 Feb, 2024 8 commits
  2. 20 Feb, 2024 2 commits
  3. 19 Feb, 2024 4 commits
  4. 17 Feb, 2024 3 commits
    • Long Li's avatar
      xfs: ensure submit buffers on LSN boundaries in error handlers · e4c3b72a
      Long Li authored
      While performing the IO fault injection test, I caught the following data
      corruption report:
      
       XFS (dm-0): Internal error ltbno + ltlen > bno at line 1957 of file fs/xfs/libxfs/xfs_alloc.c.  Caller xfs_free_ag_extent+0x79c/0x1130
       CPU: 3 PID: 33 Comm: kworker/3:0 Not tainted 6.5.0-rc7-next-20230825-00001-g7f8666926889 #214
       Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ?-20190727_073836-buildvm-ppc64le-16.ppc.fedoraproject.org-3.fc31 04/01/2014
       Workqueue: xfs-inodegc/dm-0 xfs_inodegc_worker
       Call Trace:
        <TASK>
        dump_stack_lvl+0x50/0x70
        xfs_corruption_error+0x134/0x150
        xfs_free_ag_extent+0x7d3/0x1130
        __xfs_free_extent+0x201/0x3c0
        xfs_trans_free_extent+0x29b/0xa10
        xfs_extent_free_finish_item+0x2a/0xb0
        xfs_defer_finish_noroll+0x8d1/0x1b40
        xfs_defer_finish+0x21/0x200
        xfs_itruncate_extents_flags+0x1cb/0x650
        xfs_free_eofblocks+0x18f/0x250
        xfs_inactive+0x485/0x570
        xfs_inodegc_worker+0x207/0x530
        process_scheduled_works+0x24a/0xe10
        worker_thread+0x5ac/0xc60
        kthread+0x2cd/0x3c0
        ret_from_fork+0x4a/0x80
        ret_from_fork_asm+0x11/0x20
        </TASK>
       XFS (dm-0): Corruption detected. Unmount and run xfs_repair
      
      After analyzing the disk image, it was found that the corruption was
      triggered by the fact that extent was recorded in both inode datafork
      and AGF btree blocks. After a long time of reproduction and analysis,
      we found that the reason of free sapce btree corruption was that the
      AGF btree was not recovered correctly.
      
      Consider the following situation, Checkpoint A and Checkpoint B are in
      the same record and share the same start LSN1, buf items of same object
      (AGF btree block) is included in both Checkpoint A and Checkpoint B. If
      the buf item in Checkpoint A has been recovered and updates metadata LSN
      permanently, then the buf item in Checkpoint B cannot be recovered,
      because log recovery skips items with a metadata LSN >= the current LSN
      of the recovery item. If there is still an inode item in Checkpoint B
      that records the Extent X, the Extent X will be recorded in both inode
      datafork and AGF btree block after Checkpoint B is recovered. Such
      transaction can be seen when allocing enxtent for inode bmap, it record
      both the addition of extent to the inode extent list and the removing
      extent from the AGF.
      
        |------------Record (LSN1)------------------|---Record (LSN2)---|
        |-------Checkpoint A----------|----------Checkpoint B-----------|
        |     Buf Item(Extent X)      | Buf Item / Inode item(Extent X) |
        |     Extent X is freed       |     Extent X is allocated       |
      
      After commit 12818d24 ("xfs: rework log recovery to submit buffers
      on LSN boundaries") was introduced, we submit buffers on lsn boundaries
      during log recovery. The above problem can be avoided under normal paths,
      but it's not guaranteed under abnormal paths. Consider the following
      process, if an error was encountered after recover buf item in Checkpoint
      A and before recover buf item in Checkpoint B, buffers that have been
      added to the buffer_list will still be submitted, this violates the
      submits rule on lsn boundaries. So buf item in Checkpoint B cannot be
      recovered on the next mount due to current lsn of transaction equal to
      metadata lsn on disk. The detailed process of the problem is as follows.
      
      First Mount:
      
        xlog_do_recovery_pass
          error = xlog_recover_process
            xlog_recover_process_data
              xlog_recover_process_ophdr
                xlog_recovery_process_trans
                  ...
                    /* recover buf item in Checkpoint A */
                    xlog_recover_buf_commit_pass2
                      xlog_recover_do_reg_buffer
                      /* add buffer of agf btree block to buffer_list */
                      xfs_buf_delwri_queue(bp, buffer_list)
                  ...
                  ==> Encounter read IO error and return
          /* submit buffers regardless of error */
          if (!list_empty(&buffer_list))
            xfs_buf_delwri_submit(&buffer_list);
      
          <buf items of agf btree block in Checkpoint A recovery success>
      
      Second Mount:
      
        xlog_do_recovery_pass
          error = xlog_recover_process
            xlog_recover_process_data
              xlog_recover_process_ophdr
                xlog_recovery_process_trans
                  ...
                    /* recover buf item in Checkpoint B */
                    xlog_recover_buf_commit_pass2
                      /* buffer of agf btree block wouldn't added to
                         buffer_list due to lsn equal to current_lsn */
                      if (XFS_LSN_CMP(lsn, current_lsn) >= 0)
                        goto out_release
      
          <buf items of agf btree block in Checkpoint B wouldn't recovery>
      
      In order to make sure that submits buffers on lsn boundaries in the
      abnormal paths, we need to check error status before submit buffers that
      have been added from the last record processed. If error status exist,
      buffers in the bufffer_list should not be writen to disk.
      
      Canceling the buffers in the buffer_list directly isn't correct, unlike
      any other place where write list was canceled, these buffers has been
      initialized by xfs_buf_item_init() during recovery and held by buf item,
      buf items will not be released in xfs_buf_delwri_cancel(), it's not easy
      to solve.
      
      If the filesystem has been shut down, then delwri list submission will
      error out all buffers on the list via IO submission/completion and do
      all the correct cleanup automatically. So shutting down the filesystem
      could prevents buffers in the bufffer_list from being written to disk.
      
      Fixes: 50d5c8d8 ("xfs: check LSN ordering for v5 superblocks during recovery")
      Signed-off-by: default avatarLong Li <leo.lilong@huawei.com>
      Reviewed-by: default avatar"Darrick J. Wong" <djwong@kernel.org>
      Signed-off-by: default avatarChandan Babu R <chandanbabu@kernel.org>
      e4c3b72a
    • Shrikanth Hegde's avatar
      xfs: remove duplicate ifdefs · 0164defd
      Shrikanth Hegde authored
      when a ifdef is used in the below manner, second one could be considered as
      duplicate.
      
      ifdef DEFINE_A
      ...code block...
      ifdef DEFINE_A
      ...code block...
      endif
      ...code block...
      endif
      
      In the xfs code two such patterns were seen. Hence removing these ifdefs.
      No functional change is intended here. It only aims to improve code
      readability.
      Reviewed-by: default avatar"Darrick J. Wong" <djwong@kernel.org>
      Signed-off-by: default avatarShrikanth Hegde <sshegde@linux.ibm.com>
      Signed-off-by: default avatarChandan Babu R <chandanbabu@kernel.org>
      0164defd
    • Darrick J. Wong's avatar
      xfs: disable sparse inode chunk alignment check when there is no alignment · 1149314a
      Darrick J. Wong authored
      While testing a 64k-blocksize filesystem, I noticed that xfs/709 fails
      to rebuild the inode btree with a bunch of "Corruption remains"
      messages.  It turns out that when the inode chunk size is smaller than a
      single filesystem block, no block alignments constraints are necessary
      for inode chunk allocations, and sb_spino_align is zero.  Hence we can
      skip the check.
      
      Fixes: dbfbf3bd ("xfs: repair inode btrees")
      Signed-off-by: default avatar"Darrick J. Wong" <djwong@kernel.org>
      Reviewed-by: default avatarDave Chinner <dchinner@redhat.com>
      Reviewed-by: default avatarChristoph Hellwig <hch@lst.de>
      Signed-off-by: default avatarChandan Babu R <chandanbabu@kernel.org>
      1149314a
  5. 13 Feb, 2024 12 commits
  6. 11 Feb, 2024 3 commits
  7. 10 Feb, 2024 8 commits
    • Linus Torvalds's avatar
      Merge tag 'mm-hotfixes-stable-2024-02-10-11-16' of... · 7521f258
      Linus Torvalds authored
      Merge tag 'mm-hotfixes-stable-2024-02-10-11-16' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
      
      Pull misc fixes from Andrew Morton:
       "21 hotfixes. 12 are cc:stable and the remainder pertain to post-6.7
        issues or aren't considered to be needed in earlier kernel versions"
      
      * tag 'mm-hotfixes-stable-2024-02-10-11-16' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm: (21 commits)
        nilfs2: fix potential bug in end_buffer_async_write
        mm/damon/sysfs-schemes: fix wrong DAMOS tried regions update timeout setup
        nilfs2: fix hang in nilfs_lookup_dirty_data_buffers()
        MAINTAINERS: Leo Yan has moved
        mm/zswap: don't return LRU_SKIP if we have dropped lru lock
        fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super
        mailmap: switch email address for John Moon
        mm: zswap: fix objcg use-after-free in entry destruction
        mm/madvise: don't forget to leave lazy MMU mode in madvise_cold_or_pageout_pte_range()
        arch/arm/mm: fix major fault accounting when retrying under per-VMA lock
        selftests: core: include linux/close_range.h for CLOSE_RANGE_* macros
        mm/memory-failure: fix crash in split_huge_page_to_list from soft_offline_page
        mm: memcg: optimize parent iteration in memcg_rstat_updated()
        nilfs2: fix data corruption in dsync block recovery for small block sizes
        mm/userfaultfd: UFFDIO_MOVE implementation should use ptep_get()
        exit: wait_task_zombie: kill the no longer necessary spin_lock_irq(siglock)
        fs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats
        fs/proc: do_task_stat: move thread_group_cputime_adjusted() outside of lock_task_sighand()
        getrusage: use sig->stats_lock rather than lock_task_sighand()
        getrusage: move thread_group_cputime_adjusted() outside of lock_task_sighand()
        ...
      7521f258
    • Linus Torvalds's avatar
      Merge tag 'block-6.8-2024-02-10' of git://git.kernel.dk/linux · a5b6244c
      Linus Torvalds authored
      Pull block fixes from Jens Axboe:
      
       - NVMe pull request via Keith:
           - Update a potentially stale firmware attribute (Maurizio)
           - Fixes for the recent verbose error logging (Keith, Chaitanya)
           - Protection information payload size fix for passthrough (Francis)
      
       - Fix for a queue freezing issue in virtblk (Yi)
      
       - blk-iocost underflow fix (Tejun)
      
       - blk-wbt task detection fix (Jan)
      
      * tag 'block-6.8-2024-02-10' of git://git.kernel.dk/linux:
        virtio-blk: Ensure no requests in virtqueues before deleting vqs.
        blk-iocost: Fix an UBSAN shift-out-of-bounds warning
        nvme: use ns->head->pi_size instead of t10_pi_tuple structure size
        nvme-core: fix comment to reflect right functions
        nvme: move passthrough logging attribute to head
        blk-wbt: Fix detection of dirty-throttled tasks
        nvme-host: fix the updating of the firmware version
      a5b6244c
    • Linus Torvalds's avatar
      Merge tag 'firewire-fixes-6.8-rc4' of... · a38ff5bb
      Linus Torvalds authored
      Merge tag 'firewire-fixes-6.8-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394
      
      Pull firewire fix from Takashi Sakamoto:
       "A change to accelerate the device detection step in some cases.
      
        In the self-identification step after bus-reset, all nodes in the same
        bus broadcast selfID packet including the value of gap count. The
        value is related to the cable hops between nodes, and used to
        calculate the subaction gap and the arbitration reset gap.
      
        When each node has the different value of the gap count, the
        asynchronous communication between them is unreliable, since an
        asynchronous transaction could be interrupted by another asynchronous
        transaction before completion. The gap count inconsistency can be
        resolved by several ways; e.g. the transfer of PHY configuration
        packet and generation of bus-reset.
      
        The current implementation of firewire stack can correctly detect the
        gap count inconsistency, however the recovery action from the
        inconsistency tends to be delayed after reading configuration ROM of
        root node. This results in the long time to probe devices in some
        combinations of hardware.
      
        Here the stack is changed to schedule the action as soon as possible"
      
      * tag 'firewire-fixes-6.8-rc4' of git://git.kernel.org/pub/scm/linux/kernel/git/ieee1394/linux1394:
        firewire: core: send bus reset promptly on gap count error
      a38ff5bb
    • Linus Torvalds's avatar
      Merge tag '6.8-rc3-ksmbd-server-fixes' of git://git.samba.org/ksmbd · 5a7ec870
      Linus Torvalds authored
      Pull smb server fixes from Steve French:
       "Two ksmbd server fixes:
      
         - memory leak fix
      
         - a minor kernel-doc fix"
      
      * tag '6.8-rc3-ksmbd-server-fixes' of git://git.samba.org/ksmbd:
        ksmbd: free aux buffer if ksmbd_iov_pin_rsp_read fails
        ksmbd: Add kernel-doc for ksmbd_extract_sharename() function
      5a7ec870
    • Linus Torvalds's avatar
      Merge tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi · 4a7bbe75
      Linus Torvalds authored
      Pull SCSI fixes from James Bottomley:
       "Three small driver fixes and one core fix.
      
        The core fix being a fixup to the one in the last pull request which
        didn't entirely move checking of scsi_host_busy() out from under the
        host lock"
      
      * tag 'scsi-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/jejb/scsi:
        scsi: ufs: core: Remove the ufshcd_release() in ufshcd_err_handling_prepare()
        scsi: ufs: core: Fix shift issue in ufshcd_clear_cmd()
        scsi: lpfc: Use unsigned type for num_sge
        scsi: core: Move scsi_host_busy() out of host lock if it is for per-command
      4a7bbe75
    • Linus Torvalds's avatar
      Merge tag '6.8-rc3-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6 · ca00c700
      Linus Torvalds authored
      Pull smb client fixes from Steve French:
      
       - reconnect fix
      
       - multichannel channel selection fix
      
       - minor mount warning fix
      
       - reparse point fix
      
       - null pointer check improvement
      
      * tag '6.8-rc3-smb3-client-fixes' of git://git.samba.org/sfrench/cifs-2.6:
        smb3: clarify mount warning
        cifs: handle cases where multiple sessions share connection
        cifs: change tcon status when need_reconnect is set on it
        smb: client: set correct d_type for reparse points under DFS mounts
        smb3: add missing null server pointer check
      ca00c700
    • Linus Torvalds's avatar
      Merge tag 'ceph-for-6.8-rc4' of https://github.com/ceph/ceph-client · e1e3f530
      Linus Torvalds authored
      Pull ceph fixes from Ilya Dryomov:
       "Some fscrypt-related fixups (sparse reads are used only for encrypted
        files) and two cap handling fixes from Xiubo and Rishabh"
      
      * tag 'ceph-for-6.8-rc4' of https://github.com/ceph/ceph-client:
        ceph: always check dir caps asynchronously
        ceph: prevent use-after-free in encode_cap_msg()
        ceph: always set initial i_blkbits to CEPH_FSCRYPT_BLOCK_SHIFT
        libceph: just wait for more data to be available on the socket
        libceph: rename read_sparse_msg_*() to read_partial_sparse_msg_*()
        libceph: fail sparse-read if the data length doesn't match
      e1e3f530
    • Linus Torvalds's avatar
      Merge tag 'ntfs3_for_6.8' of https://github.com/Paragon-Software-Group/linux-ntfs3 · a2343df3
      Linus Torvalds authored
      Pull ntfs3 fixes from Konstantin Komarov:
       "Fixed:
         - size update for compressed file
         - some logic errors, overflows
         - memory leak
         - some code was refactored
      
        Added:
         - implement super_operations::shutdown
      
        Improved:
         - alternative boot processing
         - reduced stack usage"
      
      * tag 'ntfs3_for_6.8' of https://github.com/Paragon-Software-Group/linux-ntfs3: (28 commits)
        fs/ntfs3: Slightly simplify ntfs_inode_printk()
        fs/ntfs3: Add ioctl operation for directories (FITRIM)
        fs/ntfs3: Fix oob in ntfs_listxattr
        fs/ntfs3: Fix an NULL dereference bug
        fs/ntfs3: Update inode->i_size after success write into compressed file
        fs/ntfs3: Fixed overflow check in mi_enum_attr()
        fs/ntfs3: Correct function is_rst_area_valid
        fs/ntfs3: Use i_size_read and i_size_write
        fs/ntfs3: Prevent generic message "attempt to access beyond end of device"
        fs/ntfs3: use non-movable memory for ntfs3 MFT buffer cache
        fs/ntfs3: Use kvfree to free memory allocated by kvmalloc
        fs/ntfs3: Disable ATTR_LIST_ENTRY size check
        fs/ntfs3: Fix c/mtime typo
        fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame()
        fs/ntfs3: Add and fix comments
        fs/ntfs3: ntfs3_forced_shutdown use int instead of bool
        fs/ntfs3: Implement super_operations::shutdown
        fs/ntfs3: Drop suid and sgid bits as a part of fpunch
        fs/ntfs3: Add file_modified
        fs/ntfs3: Correct use bh_read
        ...
      a2343df3