xref: /linux/fs/xfs/xfs_icache.c (revision cf3a01684f323dd905d83230b7cb705fabdbcb7b)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * Copyright (c) 2000-2005 Silicon Graphics, Inc.
4  * All Rights Reserved.
5  */
6 #include "xfs_platform.h"
7 #include "xfs_fs.h"
8 #include "xfs_shared.h"
9 #include "xfs_format.h"
10 #include "xfs_log_format.h"
11 #include "xfs_trans_resv.h"
12 #include "xfs_mount.h"
13 #include "xfs_inode.h"
14 #include "xfs_trans.h"
15 #include "xfs_trans_priv.h"
16 #include "xfs_inode_item.h"
17 #include "xfs_quota.h"
18 #include "xfs_trace.h"
19 #include "xfs_icache.h"
20 #include "xfs_bmap_util.h"
21 #include "xfs_dquot_item.h"
22 #include "xfs_dquot.h"
23 #include "xfs_reflink.h"
24 #include "xfs_ialloc.h"
25 #include "xfs_ag.h"
26 #include "xfs_log_priv.h"
27 #include "xfs_health.h"
28 #include "xfs_da_format.h"
29 #include "xfs_dir2.h"
30 #include "xfs_metafile.h"
31 
32 #include <linux/iversion.h>
33 
34 /* Radix tree tags for incore inode tree. */
35 
36 /* inode is to be reclaimed */
37 #define XFS_ICI_RECLAIM_TAG	0
38 /* Inode has speculative preallocations (posteof or cow) to clean. */
39 #define XFS_ICI_BLOCKGC_TAG	1
40 
41 /*
42  * The goal for walking incore inodes.  These can correspond with incore inode
43  * radix tree tags when convenient.  Avoid existing XFS_IWALK namespace.
44  */
45 enum xfs_icwalk_goal {
46 	/* Goals directly associated with tagged inodes. */
47 	XFS_ICWALK_BLOCKGC	= XFS_ICI_BLOCKGC_TAG,
48 	XFS_ICWALK_RECLAIM	= XFS_ICI_RECLAIM_TAG,
49 };
50 
51 static int xfs_icwalk(struct xfs_mount *mp,
52 		enum xfs_icwalk_goal goal, struct xfs_icwalk *icw);
53 static int xfs_icwalk_ag(struct xfs_perag *pag,
54 		enum xfs_icwalk_goal goal, struct xfs_icwalk *icw);
55 
56 /*
57  * Private inode cache walk flags for struct xfs_icwalk.  Must not
58  * coincide with XFS_ICWALK_FLAGS_VALID.
59  */
60 
61 /* Stop scanning after icw_scan_limit inodes. */
62 #define XFS_ICWALK_FLAG_SCAN_LIMIT	(1U << 28)
63 
64 #define XFS_ICWALK_FLAG_RECLAIM_SICK	(1U << 27)
65 #define XFS_ICWALK_FLAG_UNION		(1U << 26) /* union filter algorithm */
66 
67 #define XFS_ICWALK_PRIVATE_FLAGS	(XFS_ICWALK_FLAG_SCAN_LIMIT | \
68 					 XFS_ICWALK_FLAG_RECLAIM_SICK | \
69 					 XFS_ICWALK_FLAG_UNION)
70 
71 /* Marks for the perag xarray */
72 #define XFS_PERAG_RECLAIM_MARK	XA_MARK_0
73 #define XFS_PERAG_BLOCKGC_MARK	XA_MARK_1
74 
75 static inline xa_mark_t ici_tag_to_mark(unsigned int tag)
76 {
77 	if (tag == XFS_ICI_RECLAIM_TAG)
78 		return XFS_PERAG_RECLAIM_MARK;
79 	ASSERT(tag == XFS_ICI_BLOCKGC_TAG);
80 	return XFS_PERAG_BLOCKGC_MARK;
81 }
82 
83 /*
84  * Allocate and initialise an xfs_inode.
85  *
86  * This can happen in context of already dirtied transactions, so the memory
87  * allocations must not fail.
88  */
89 struct xfs_inode *
90 xfs_inode_alloc(
91 	struct xfs_mount	*mp,
92 	xfs_ino_t		ino)
93 {
94 	gfp_t			gfp = GFP_KERNEL | __GFP_NOFAIL;
95 	struct xfs_inode	*ip;
96 
97 	ip = alloc_inode_sb(mp->m_super, xfs_inode_cache, gfp);
98 	inode_init_always_gfp(mp->m_super, VFS_I(ip), gfp);
99 
100 	VFS_I(ip)->i_ino = ino;
101 	/* VFS doesn't initialise i_mode! */
102 	VFS_I(ip)->i_mode = 0;
103 	mapping_set_folio_min_order(VFS_I(ip)->i_mapping,
104 				    M_IGEO(mp)->min_folio_order);
105 
106 	XFS_STATS_INC(mp, xs_inodes_active);
107 	ASSERT(atomic_read(&ip->i_pincount) == 0);
108 
109 	/* initialise the xfs inode */
110 	ip->i_mount = mp;
111 	memset(&ip->i_imap, 0, sizeof(struct xfs_imap));
112 	ip->i_cowfp = NULL;
113 	memset(&ip->i_af, 0, sizeof(ip->i_af));
114 	ip->i_af.if_format = XFS_DINODE_FMT_EXTENTS;
115 	memset(&ip->i_df, 0, sizeof(ip->i_df));
116 	ip->i_flags = 0;
117 	ip->i_delayed_blks = 0;
118 	ip->i_diflags2 = mp->m_ino_geo.new_diflags2;
119 	ip->i_nblocks = 0;
120 	ip->i_forkoff = 0;
121 	ip->i_sick = 0;
122 	ip->i_checked = 0;
123 	INIT_WORK(&ip->i_ioend_work, xfs_end_io);
124 	INIT_LIST_HEAD(&ip->i_ioend_list);
125 	spin_lock_init(&ip->i_ioend_lock);
126 	ip->i_next_unlinked = NULLAGINO;
127 	ip->i_prev_unlinked = 0;
128 
129 	return ip;
130 }
131 
132 STATIC void
133 xfs_inode_free_callback(
134 	struct rcu_head		*head)
135 {
136 	struct inode		*inode = container_of(head, struct inode, i_rcu);
137 	struct xfs_inode	*ip = XFS_I(inode);
138 
139 	switch (VFS_I(ip)->i_mode & S_IFMT) {
140 	case S_IFREG:
141 	case S_IFDIR:
142 	case S_IFLNK:
143 		xfs_idestroy_fork(&ip->i_df);
144 		break;
145 	}
146 
147 	xfs_ifork_zap_attr(ip);
148 
149 	if (ip->i_cowfp) {
150 		xfs_idestroy_fork(ip->i_cowfp);
151 		kmem_cache_free(xfs_ifork_cache, ip->i_cowfp);
152 	}
153 	if (ip->i_itemp) {
154 		ASSERT(!test_bit(XFS_LI_IN_AIL,
155 				 &ip->i_itemp->ili_item.li_flags));
156 		xfs_inode_item_destroy(ip);
157 	}
158 
159 	kmem_cache_free(xfs_inode_cache, ip);
160 }
161 
162 static void
163 __xfs_inode_free(
164 	struct xfs_inode	*ip)
165 {
166 	/* asserts to verify all state is correct here */
167 	ASSERT(atomic_read(&ip->i_pincount) == 0);
168 	ASSERT(!ip->i_itemp || list_empty(&ip->i_itemp->ili_item.li_bio_list));
169 	if (xfs_is_metadir_inode(ip))
170 		XFS_STATS_DEC(ip->i_mount, xs_inodes_meta);
171 	else
172 		XFS_STATS_DEC(ip->i_mount, xs_inodes_active);
173 
174 	call_rcu(&VFS_I(ip)->i_rcu, xfs_inode_free_callback);
175 }
176 
177 void
178 xfs_inode_free(
179 	struct xfs_inode	*ip)
180 {
181 	ASSERT(!xfs_iflags_test(ip, XFS_IFLUSHING));
182 
183 	/*
184 	 * Because we use RCU freeing we need to ensure the inode always
185 	 * appears to be reclaimed with an invalid inode number when in the
186 	 * free state. The ip->i_flags_lock provides the barrier against lookup
187 	 * races.
188 	 */
189 	spin_lock(&ip->i_flags_lock);
190 	ip->i_flags = XFS_IRECLAIM;
191 	VFS_I(ip)->i_ino = 0;
192 	spin_unlock(&ip->i_flags_lock);
193 
194 	__xfs_inode_free(ip);
195 }
196 
197 /*
198  * Queue background inode reclaim work if there are reclaimable inodes and there
199  * isn't reclaim work already scheduled or in progress.
200  */
201 static void
202 xfs_reclaim_work_queue(
203 	struct xfs_mount        *mp)
204 {
205 
206 	rcu_read_lock();
207 	if (xfs_group_marked(mp, XG_TYPE_AG, XFS_PERAG_RECLAIM_MARK)) {
208 		queue_delayed_work(mp->m_reclaim_workqueue, &mp->m_reclaim_work,
209 			msecs_to_jiffies(xfs_syncd_centisecs / 6 * 10));
210 	}
211 	rcu_read_unlock();
212 }
213 
214 /*
215  * Background scanning to trim preallocated space. This is queued based on the
216  * 'speculative_prealloc_lifetime' tunable (5m by default).
217  */
218 static inline void
219 xfs_blockgc_queue(
220 	struct xfs_perag	*pag)
221 {
222 	struct xfs_mount	*mp = pag_mount(pag);
223 
224 	if (!xfs_is_blockgc_enabled(mp))
225 		return;
226 
227 	rcu_read_lock();
228 	if (radix_tree_tagged(&pag->pag_ici_root, XFS_ICI_BLOCKGC_TAG))
229 		queue_delayed_work(mp->m_blockgc_wq, &pag->pag_blockgc_work,
230 				   secs_to_jiffies(xfs_blockgc_secs));
231 	rcu_read_unlock();
232 }
233 
234 /* Set a tag on both the AG incore inode tree and the AG radix tree. */
235 static void
236 xfs_perag_set_inode_tag(
237 	struct xfs_perag	*pag,
238 	xfs_agino_t		agino,
239 	unsigned int		tag)
240 {
241 	bool			was_tagged;
242 
243 	lockdep_assert_held(&pag->pag_ici_lock);
244 
245 	was_tagged = radix_tree_tagged(&pag->pag_ici_root, tag);
246 	radix_tree_tag_set(&pag->pag_ici_root, agino, tag);
247 
248 	if (tag == XFS_ICI_RECLAIM_TAG)
249 		pag->pag_ici_reclaimable++;
250 
251 	if (was_tagged)
252 		return;
253 
254 	/* propagate the tag up into the pag xarray tree */
255 	xfs_group_set_mark(pag_group(pag), ici_tag_to_mark(tag));
256 
257 	/* start background work */
258 	switch (tag) {
259 	case XFS_ICI_RECLAIM_TAG:
260 		xfs_reclaim_work_queue(pag_mount(pag));
261 		break;
262 	case XFS_ICI_BLOCKGC_TAG:
263 		xfs_blockgc_queue(pag);
264 		break;
265 	}
266 
267 	trace_xfs_perag_set_inode_tag(pag, _RET_IP_);
268 }
269 
270 /* Clear a tag on both the AG incore inode tree and the AG radix tree. */
271 static void
272 xfs_perag_clear_inode_tag(
273 	struct xfs_perag	*pag,
274 	xfs_agino_t		agino,
275 	unsigned int		tag)
276 {
277 	lockdep_assert_held(&pag->pag_ici_lock);
278 
279 	/*
280 	 * Reclaim can signal (with a null agino) that it cleared its own tag
281 	 * by removing the inode from the radix tree.
282 	 */
283 	if (agino != NULLAGINO)
284 		radix_tree_tag_clear(&pag->pag_ici_root, agino, tag);
285 	else
286 		ASSERT(tag == XFS_ICI_RECLAIM_TAG);
287 
288 	if (tag == XFS_ICI_RECLAIM_TAG)
289 		pag->pag_ici_reclaimable--;
290 
291 	if (radix_tree_tagged(&pag->pag_ici_root, tag))
292 		return;
293 
294 	/* clear the tag from the pag xarray */
295 	xfs_group_clear_mark(pag_group(pag), ici_tag_to_mark(tag));
296 	trace_xfs_perag_clear_inode_tag(pag, _RET_IP_);
297 }
298 
299 /*
300  * Find the next AG after @pag, or the first AG if @pag is NULL.
301  */
302 static struct xfs_perag *
303 xfs_perag_grab_next_tag(
304 	struct xfs_mount	*mp,
305 	struct xfs_perag	*pag,
306 	int			tag)
307 {
308 	return to_perag(xfs_group_grab_next_mark(mp,
309 			pag ? pag_group(pag) : NULL,
310 			ici_tag_to_mark(tag), XG_TYPE_AG));
311 }
312 
313 /*
314  * When we recycle a reclaimable inode, we need to re-initialise the VFS inode
315  * part of the structure. This is made more complex by the fact we store
316  * information about the on-disk values in the VFS inode and so we can't just
317  * overwrite the values unconditionally. Hence we save the parameters we
318  * need to retain across reinitialisation, and rewrite them into the VFS inode
319  * after reinitialisation even if it fails.
320  */
321 static int
322 xfs_reinit_inode(
323 	struct xfs_mount	*mp,
324 	struct inode		*inode)
325 {
326 	int			error;
327 	u64			ino = inode->i_ino;
328 	uint32_t		nlink = inode->i_nlink;
329 	uint32_t		generation = inode->i_generation;
330 	uint64_t		version = inode_peek_iversion(inode);
331 	umode_t			mode = inode->i_mode;
332 	dev_t			dev = inode->i_rdev;
333 	kuid_t			uid = inode->i_uid;
334 	kgid_t			gid = inode->i_gid;
335 	unsigned long		state = inode_state_read_once(inode);
336 
337 	error = inode_init_always(mp->m_super, inode);
338 
339 	inode->i_ino = ino;
340 	set_nlink(inode, nlink);
341 	inode->i_generation = generation;
342 	inode_set_iversion_queried(inode, version);
343 	inode->i_mode = mode;
344 	inode->i_rdev = dev;
345 	inode->i_uid = uid;
346 	inode->i_gid = gid;
347 	inode_state_assign_raw(inode, state);
348 	mapping_set_folio_min_order(inode->i_mapping,
349 				    M_IGEO(mp)->min_folio_order);
350 	return error;
351 }
352 
353 /*
354  * Carefully nudge an inode whose VFS state has been torn down back into a
355  * usable state.  Drops the i_flags_lock and the rcu read lock.
356  */
357 static int
358 xfs_iget_recycle(
359 	struct xfs_perag	*pag,
360 	struct xfs_inode	*ip)
361 {
362 	struct xfs_mount	*mp = ip->i_mount;
363 	struct inode		*inode = VFS_I(ip);
364 	int			error;
365 
366 	trace_xfs_iget_recycle(ip);
367 
368 	ASSERT(!rwsem_is_locked(&inode->i_rwsem));
369 	error = xfs_reinit_inode(mp, inode);
370 	xfs_iunlock(ip, XFS_ILOCK_EXCL);
371 	if (error) {
372 		/*
373 		 * Re-initializing the inode failed, and we are in deep
374 		 * trouble.  Try to re-add it to the reclaim list.
375 		 */
376 		rcu_read_lock();
377 		spin_lock(&ip->i_flags_lock);
378 		ip->i_flags &= ~(XFS_INEW | XFS_IRECLAIM);
379 		ASSERT(ip->i_flags & XFS_IRECLAIMABLE);
380 		spin_unlock(&ip->i_flags_lock);
381 		rcu_read_unlock();
382 
383 		trace_xfs_iget_recycle_fail(ip);
384 		return error;
385 	}
386 
387 	spin_lock(&pag->pag_ici_lock);
388 	spin_lock(&ip->i_flags_lock);
389 
390 	/*
391 	 * Clear the per-lifetime state in the inode as we are now effectively
392 	 * a new inode and need to return to the initial state before reuse
393 	 * occurs.
394 	 */
395 	ip->i_flags &= ~XFS_IRECLAIM_RESET_FLAGS;
396 	ip->i_flags |= XFS_INEW;
397 	xfs_perag_clear_inode_tag(pag, XFS_INODE_TO_AGINO(ip),
398 			XFS_ICI_RECLAIM_TAG);
399 	inode_state_assign_raw(inode, I_NEW);
400 	spin_unlock(&ip->i_flags_lock);
401 	spin_unlock(&pag->pag_ici_lock);
402 
403 	return 0;
404 }
405 
406 /*
407  * If we are allocating a new inode, then check what was returned is
408  * actually a free, empty inode. If we are not allocating an inode,
409  * then check we didn't find a free inode.
410  *
411  * Returns:
412  *	0		if the inode free state matches the lookup context
413  *	-ENOENT		if the inode is free and we are not allocating
414  *	-EFSCORRUPTED	if there is any state mismatch at all
415  */
416 static int
417 xfs_iget_check_free_state(
418 	struct xfs_inode	*ip,
419 	int			flags)
420 {
421 	if (flags & XFS_IGET_CREATE) {
422 		/* should be a free inode */
423 		if (VFS_I(ip)->i_mode != 0) {
424 			xfs_warn(ip->i_mount,
425 "Corruption detected! Free inode 0x%llx not marked free! (mode 0x%x)",
426 				I_INO(ip), VFS_I(ip)->i_mode);
427 			xfs_agno_mark_sick(ip->i_mount, XFS_INODE_TO_AGNO(ip),
428 					XFS_SICK_AG_INOBT);
429 			return -EFSCORRUPTED;
430 		}
431 
432 		if (ip->i_nblocks != 0) {
433 			xfs_warn(ip->i_mount,
434 "Corruption detected! Free inode 0x%llx has blocks allocated!",
435 				I_INO(ip));
436 			xfs_agno_mark_sick(ip->i_mount, XFS_INODE_TO_AGNO(ip),
437 					XFS_SICK_AG_INOBT);
438 			return -EFSCORRUPTED;
439 		}
440 		return 0;
441 	}
442 
443 	/* should be an allocated inode */
444 	if (VFS_I(ip)->i_mode == 0)
445 		return -ENOENT;
446 
447 	return 0;
448 }
449 
450 /* Make all pending inactivation work start immediately. */
451 static bool
452 xfs_inodegc_queue_all(
453 	struct xfs_mount	*mp)
454 {
455 	struct xfs_inodegc	*gc;
456 	int			cpu;
457 	bool			ret = false;
458 
459 	for_each_cpu(cpu, &mp->m_inodegc_cpumask) {
460 		gc = per_cpu_ptr(mp->m_inodegc, cpu);
461 		if (!llist_empty(&gc->list)) {
462 			mod_delayed_work_on(cpu, mp->m_inodegc_wq, &gc->work, 0);
463 			ret = true;
464 		}
465 	}
466 
467 	return ret;
468 }
469 
470 /* Wait for all queued work and collect errors */
471 static int
472 xfs_inodegc_wait_all(
473 	struct xfs_mount	*mp)
474 {
475 	int			cpu;
476 	int			error = 0;
477 
478 	flush_workqueue(mp->m_inodegc_wq);
479 	for_each_cpu(cpu, &mp->m_inodegc_cpumask) {
480 		struct xfs_inodegc	*gc;
481 
482 		gc = per_cpu_ptr(mp->m_inodegc, cpu);
483 		if (gc->error && !error)
484 			error = gc->error;
485 		gc->error = 0;
486 	}
487 
488 	return error;
489 }
490 
491 /*
492  * Check the validity of the inode we just found it the cache
493  */
494 static int
495 xfs_iget_cache_hit(
496 	struct xfs_perag	*pag,
497 	struct xfs_inode	*ip,
498 	xfs_ino_t		ino,
499 	int			flags,
500 	int			lock_flags)
501 		__releases_shared(RCU)
502 {
503 	struct inode		*inode = VFS_I(ip);
504 	struct xfs_mount	*mp = ip->i_mount;
505 	int			error;
506 
507 	/*
508 	 * check for re-use of an inode within an RCU grace period due to the
509 	 * radix tree nodes not being updated yet. We monitor for this by
510 	 * setting the inode number to zero before freeing the inode structure.
511 	 * If the inode has been reallocated and set up, then the inode number
512 	 * will not match, so check for that, too.
513 	 */
514 	spin_lock(&ip->i_flags_lock);
515 	if (I_INO(ip) != ino)
516 		goto out_skip;
517 
518 	/*
519 	 * If we are racing with another cache hit that is currently
520 	 * instantiating this inode or currently recycling it out of
521 	 * reclaimable state, wait for the initialisation to complete
522 	 * before continuing.
523 	 *
524 	 * If we're racing with the inactivation worker we also want to wait.
525 	 * If we're creating a new file, it's possible that the worker
526 	 * previously marked the inode as free on disk but hasn't finished
527 	 * updating the incore state yet.  The AGI buffer will be dirty and
528 	 * locked to the icreate transaction, so a synchronous push of the
529 	 * inodegc workers would result in deadlock.  For a regular iget, the
530 	 * worker is running already, so we might as well wait.
531 	 *
532 	 * XXX(hch): eventually we should do something equivalent to
533 	 *	     wait_on_inode to wait for these flags to be cleared
534 	 *	     instead of polling for it.
535 	 */
536 	if (ip->i_flags & (XFS_INEW | XFS_IRECLAIM | XFS_INACTIVATING))
537 		goto out_skip;
538 
539 	if (ip->i_flags & XFS_NEED_INACTIVE) {
540 		/* Unlinked inodes cannot be re-grabbed. */
541 		if (VFS_I(ip)->i_nlink == 0) {
542 			error = -ENOENT;
543 			goto out_error;
544 		}
545 		goto out_inodegc_flush;
546 	}
547 
548 	/*
549 	 * Check the inode free state is valid. This also detects lookup
550 	 * racing with unlinks.
551 	 */
552 	error = xfs_iget_check_free_state(ip, flags);
553 	if (error)
554 		goto out_error;
555 
556 	/* Skip inodes that have no vfs state. */
557 	if ((flags & XFS_IGET_INCORE) &&
558 	    (ip->i_flags & XFS_IRECLAIMABLE))
559 		goto out_skip;
560 
561 	/* The inode fits the selection criteria; process it. */
562 	if (ip->i_flags & XFS_IRECLAIMABLE) {
563 		/*
564 		 * We need to make it look like the inode is being reclaimed to
565 		 * prevent the actual reclaim workers from stomping over us
566 		 * while we recycle the inode.  We can't clear the radix tree
567 		 * tag yet as it requires pag_ici_lock to be held exclusive.
568 		 */
569 		if (!xfs_ilock_nowait(ip, XFS_ILOCK_EXCL))
570 			goto out_skip;
571 		ip->i_flags |= XFS_IRECLAIM;
572 		spin_unlock(&ip->i_flags_lock);
573 		rcu_read_unlock();
574 
575 		error = xfs_iget_recycle(pag, ip);
576 		if (error)
577 			return error;
578 	} else {
579 		/* If the VFS inode is being torn down, pause and try again. */
580 		if (!igrab(inode))
581 			goto out_skip;
582 
583 		/* We've got a live one. */
584 		spin_unlock(&ip->i_flags_lock);
585 		rcu_read_unlock();
586 		trace_xfs_iget_hit(ip);
587 	}
588 
589 	if (lock_flags != 0)
590 		xfs_ilock(ip, lock_flags);
591 
592 	if (!(flags & XFS_IGET_INCORE))
593 		xfs_iflags_clear(ip, XFS_ISTALE);
594 	XFS_STATS_INC(mp, xs_ig_found);
595 
596 	return 0;
597 
598 out_skip:
599 	trace_xfs_iget_skip(ip);
600 	XFS_STATS_INC(mp, xs_ig_frecycle);
601 	error = -EAGAIN;
602 out_error:
603 	spin_unlock(&ip->i_flags_lock);
604 	rcu_read_unlock();
605 	return error;
606 
607 out_inodegc_flush:
608 	spin_unlock(&ip->i_flags_lock);
609 	rcu_read_unlock();
610 	/*
611 	 * Do not wait for the workers, because the caller could hold an AGI
612 	 * buffer lock.  We're just going to sleep in a loop anyway.
613 	 */
614 	if (xfs_is_inodegc_enabled(mp))
615 		xfs_inodegc_queue_all(mp);
616 	return -EAGAIN;
617 }
618 
619 static int
620 xfs_iget_cache_miss(
621 	struct xfs_mount	*mp,
622 	struct xfs_perag	*pag,
623 	xfs_trans_t		*tp,
624 	xfs_ino_t		ino,
625 	struct xfs_inode	**ipp,
626 	int			flags,
627 	int			lock_flags)
628 {
629 	struct xfs_inode	*ip;
630 	int			error;
631 	xfs_agino_t		agino = XFS_INO_TO_AGINO(mp, ino);
632 
633 	ip = xfs_inode_alloc(mp, ino);
634 	if (!ip)
635 		return -ENOMEM;
636 
637 	/*
638 	 * Set XFS_INEW as early as possible so that the health code won't pass
639 	 * the inode to the fserror code if the ondisk inode cannot be loaded.
640 	 * We're going to free the xfs_inode immediately if that happens, which
641 	 * would lead to UAF problems.
642 	 */
643 	xfs_iflags_set(ip, XFS_INEW);
644 
645 	error = xfs_imap(pag, tp, I_INO(ip), &ip->i_imap, flags);
646 	if (error)
647 		goto out_destroy;
648 
649 	/*
650 	 * For version 5 superblocks, if we are initialising a new inode, we
651 	 * simply build the new inode core with a random generation number.
652 	 *
653 	 * For version 4 (and older) superblocks, log recovery is dependent on
654 	 * the i_flushiter field being initialised from the current on-disk
655 	 * value and hence we must also read the inode off disk even when
656 	 * initializing new inodes.
657 	 */
658 	if (xfs_has_v3inodes(mp) && (flags & XFS_IGET_CREATE)) {
659 		VFS_I(ip)->i_generation = get_random_u32();
660 	} else {
661 		struct xfs_buf		*bp;
662 
663 		error = xfs_read_icluster(pag, tp, ip->i_imap.im_agbno, &bp);
664 		if (error)
665 			goto out_destroy;
666 
667 		error = xfs_inode_from_disk(ip,
668 				xfs_buf_offset(bp, ip->i_imap.im_boffset));
669 		if (!error)
670 			xfs_buf_set_ref(bp, XFS_INO_REF);
671 		else
672 			xfs_inode_mark_sick(ip, XFS_SICK_INO_CORE);
673 		xfs_trans_brelse(tp, bp);
674 
675 		if (error)
676 			goto out_destroy;
677 	}
678 
679 	trace_xfs_iget_miss(ip);
680 
681 	/*
682 	 * Check the inode free state is valid. This also detects lookup
683 	 * racing with unlinks.
684 	 */
685 	error = xfs_iget_check_free_state(ip, flags);
686 	if (error)
687 		goto out_destroy;
688 
689 	/*
690 	 * Preload the radix tree so we can insert safely under the
691 	 * write spinlock. Note that we cannot sleep inside the preload
692 	 * region.
693 	 */
694 	if (radix_tree_preload(GFP_KERNEL | __GFP_NOLOCKDEP)) {
695 		error = -EAGAIN;
696 		goto out_destroy;
697 	}
698 
699 	/*
700 	 * Because the inode hasn't been added to the radix-tree yet it can't
701 	 * be found by another thread, so we can do the non-sleeping lock here.
702 	 */
703 	if (lock_flags) {
704 		if (!xfs_ilock_nowait(ip, lock_flags))
705 			BUG();
706 	}
707 
708 	/*
709 	 * These values must be set before inserting the inode into the radix
710 	 * tree as the moment it is inserted a concurrent lookup (allowed by the
711 	 * RCU locking mechanism) can find it and that lookup must see that this
712 	 * is an inode currently under construction (i.e. that XFS_INEW is set).
713 	 * The ip->i_flags_lock that protects the XFS_INEW flag forms the
714 	 * memory barrier that ensures this detection works correctly at lookup
715 	 * time.
716 	 */
717 	if (flags & XFS_IGET_DONTCACHE)
718 		d_mark_dontcache(VFS_I(ip));
719 	ip->i_udquot = NULL;
720 	ip->i_gdquot = NULL;
721 	ip->i_pdquot = NULL;
722 
723 	/* insert the new inode */
724 	spin_lock(&pag->pag_ici_lock);
725 	error = radix_tree_insert(&pag->pag_ici_root, agino, ip);
726 	if (unlikely(error)) {
727 		WARN_ON(error != -EEXIST);
728 		XFS_STATS_INC(mp, xs_ig_dup);
729 		error = -EAGAIN;
730 		goto out_preload_end;
731 	}
732 	spin_unlock(&pag->pag_ici_lock);
733 	radix_tree_preload_end();
734 
735 	*ipp = ip;
736 	return 0;
737 
738 out_preload_end:
739 	spin_unlock(&pag->pag_ici_lock);
740 	radix_tree_preload_end();
741 	if (lock_flags)
742 		xfs_iunlock(ip, lock_flags);
743 out_destroy:
744 	__destroy_inode(VFS_I(ip));
745 	xfs_inode_free(ip);
746 	return error;
747 }
748 
749 /*
750  * Look up an inode by number in the given file system.  The inode is looked up
751  * in the cache held in each AG.  If the inode is found in the cache, initialise
752  * the vfs inode if necessary.
753  *
754  * If it is not in core, read it in from the file system's device, add it to the
755  * cache and initialise the vfs inode.
756  *
757  * The inode is locked according to the value of the lock_flags parameter.
758  * Inode lookup is only done during metadata operations and not as part of the
759  * data IO path. Hence we only allow locking of the XFS_ILOCK during lookup.
760  */
761 int
762 xfs_iget(
763 	struct xfs_mount	*mp,
764 	struct xfs_trans	*tp,
765 	xfs_ino_t		ino,
766 	uint			flags,
767 	uint			lock_flags,
768 	struct xfs_inode	**ipp)
769 {
770 	struct xfs_inode	*ip;
771 	struct xfs_perag	*pag;
772 	xfs_agino_t		agino;
773 	int			error;
774 
775 	ASSERT((lock_flags & (XFS_IOLOCK_EXCL | XFS_IOLOCK_SHARED)) == 0);
776 
777 	/* reject inode numbers outside existing AGs */
778 	if (!xfs_verify_ino(mp, ino))
779 		return -EINVAL;
780 
781 	XFS_STATS_INC(mp, xs_ig_attempts);
782 
783 	/* get the perag structure and ensure that it's inode capable */
784 	pag = xfs_perag_get(mp, XFS_INO_TO_AGNO(mp, ino));
785 	agino = XFS_INO_TO_AGINO(mp, ino);
786 
787 again:
788 	error = 0;
789 	rcu_read_lock();
790 	ip = radix_tree_lookup(&pag->pag_ici_root, agino);
791 
792 	if (ip) {
793 		error = xfs_iget_cache_hit(pag, ip, ino, flags, lock_flags);
794 		if (error)
795 			goto out_error_or_again;
796 	} else {
797 		rcu_read_unlock();
798 		if (flags & XFS_IGET_INCORE) {
799 			error = -ENODATA;
800 			goto out_error_or_again;
801 		}
802 		XFS_STATS_INC(mp, xs_ig_missed);
803 
804 		error = xfs_iget_cache_miss(mp, pag, tp, ino, &ip,
805 							flags, lock_flags);
806 		if (error)
807 			goto out_error_or_again;
808 	}
809 	xfs_perag_put(pag);
810 
811 	*ipp = ip;
812 
813 	/*
814 	 * If we have a real type for an on-disk inode, we can setup the inode
815 	 * now.	 If it's a new inode being created, xfs_init_new_inode will
816 	 * handle it.
817 	 */
818 	if (xfs_iflags_test(ip, XFS_INEW) && VFS_I(ip)->i_mode != 0) {
819 		xfs_setup_inode(ip);
820 		xfs_setup_iops(ip);
821 		xfs_finish_inode_setup(ip);
822 	}
823 	return 0;
824 
825 out_error_or_again:
826 	if (!(flags & (XFS_IGET_INCORE | XFS_IGET_NORETRY)) &&
827 	    error == -EAGAIN) {
828 		delay(1);
829 		goto again;
830 	}
831 	xfs_perag_put(pag);
832 	return error;
833 }
834 
835 /*
836  * Get a metadata inode.
837  *
838  * The metafile type must match the file mode exactly, and for files in the
839  * metadata directory tree, it must match the inode's metatype exactly.
840  */
841 int
842 xfs_trans_metafile_iget(
843 	struct xfs_trans	*tp,
844 	xfs_ino_t		ino,
845 	enum xfs_metafile_type	metafile_type,
846 	struct xfs_inode	**ipp)
847 {
848 	struct xfs_mount	*mp = tp->t_mountp;
849 	struct xfs_inode	*ip;
850 	umode_t			mode;
851 	int			error;
852 
853 	error = xfs_iget(mp, tp, ino, 0, 0, &ip);
854 	if (error == -EFSCORRUPTED || error == -EINVAL)
855 		goto whine;
856 	if (error)
857 		return error;
858 
859 	if (VFS_I(ip)->i_nlink == 0)
860 		goto bad_rele;
861 
862 	if (metafile_type == XFS_METAFILE_DIR)
863 		mode = S_IFDIR;
864 	else
865 		mode = S_IFREG;
866 	if (inode_wrong_type(VFS_I(ip), mode))
867 		goto bad_rele;
868 	if (xfs_has_metadir(mp)) {
869 		if (!xfs_is_metadir_inode(ip))
870 			goto bad_rele;
871 		if (metafile_type != ip->i_metatype)
872 			goto bad_rele;
873 	}
874 
875 	*ipp = ip;
876 	return 0;
877 bad_rele:
878 	xfs_irele(ip);
879 whine:
880 	xfs_err(mp, "metadata inode 0x%llx type %u is corrupt", ino,
881 			metafile_type);
882 	xfs_fs_mark_sick(mp, XFS_SICK_FS_METADIR);
883 	return -EFSCORRUPTED;
884 }
885 
886 /* Grab a metadata file if the caller doesn't already have a transaction. */
887 int
888 xfs_metafile_iget(
889 	struct xfs_mount	*mp,
890 	xfs_ino_t		ino,
891 	enum xfs_metafile_type	metafile_type,
892 	struct xfs_inode	**ipp)
893 {
894 	struct xfs_trans	*tp;
895 	int			error;
896 
897 	tp = xfs_trans_alloc_empty(mp);
898 	error = xfs_trans_metafile_iget(tp, ino, metafile_type, ipp);
899 	xfs_trans_cancel(tp);
900 	return error;
901 }
902 
903 /*
904  * Grab the inode for reclaim exclusively.
905  *
906  * We have found this inode via a lookup under RCU, so the inode may have
907  * already been freed, or it may be in the process of being recycled by
908  * xfs_iget(). In both cases, the inode will have XFS_IRECLAIM set. If the inode
909  * has been fully recycled by the time we get the i_flags_lock, XFS_IRECLAIMABLE
910  * will not be set. Hence we need to check for both these flag conditions to
911  * avoid inodes that are no longer reclaim candidates.
912  *
913  * Note: checking for other state flags here, under the i_flags_lock or not, is
914  * racy and should be avoided. Those races should be resolved only after we have
915  * ensured that we are able to reclaim this inode and the world can see that we
916  * are going to reclaim it.
917  *
918  * Return true if we grabbed it, false otherwise.
919  */
920 static bool
921 xfs_reclaim_igrab(
922 	struct xfs_inode	*ip,
923 	struct xfs_icwalk	*icw)
924 {
925 	ASSERT(rcu_read_lock_held());
926 
927 	spin_lock(&ip->i_flags_lock);
928 	if (!__xfs_iflags_test(ip, XFS_IRECLAIMABLE) ||
929 	    __xfs_iflags_test(ip, XFS_IRECLAIM)) {
930 		/* not a reclaim candidate. */
931 		spin_unlock(&ip->i_flags_lock);
932 		return false;
933 	}
934 
935 	/* Don't reclaim a sick inode unless the caller asked for it. */
936 	if (ip->i_sick &&
937 	    (!icw || !(icw->icw_flags & XFS_ICWALK_FLAG_RECLAIM_SICK))) {
938 		spin_unlock(&ip->i_flags_lock);
939 		return false;
940 	}
941 
942 	__xfs_iflags_set(ip, XFS_IRECLAIM);
943 	spin_unlock(&ip->i_flags_lock);
944 	return true;
945 }
946 
947 /*
948  * Inode reclaim is non-blocking, so the default action if progress cannot be
949  * made is to "requeue" the inode for reclaim by unlocking it and clearing the
950  * XFS_IRECLAIM flag.  If we are in a shutdown state, we don't care about
951  * blocking anymore and hence we can wait for the inode to be able to reclaim
952  * it.
953  *
954  * We do no IO here - if callers require inodes to be cleaned they must push the
955  * AIL first to trigger writeback of dirty inodes.  This enables writeback to be
956  * done in the background in a non-blocking manner, and enables memory reclaim
957  * to make progress without blocking.
958  */
959 static void
960 xfs_reclaim_inode(
961 	struct xfs_inode	*ip,
962 	struct xfs_perag	*pag)
963 {
964 	xfs_ino_t		ino = I_INO(ip); /* for radix_tree_delete */
965 
966 	if (!xfs_ilock_nowait(ip, XFS_ILOCK_EXCL))
967 		goto out;
968 	if (xfs_iflags_test_and_set(ip, XFS_IFLUSHING))
969 		goto out_iunlock;
970 
971 	/*
972 	 * Check for log shutdown because aborting the inode can move the log
973 	 * tail and corrupt in memory state. This is fine if the log is shut
974 	 * down, but if the log is still active and only the mount is shut down
975 	 * then the in-memory log tail movement caused by the abort can be
976 	 * incorrectly propagated to disk.
977 	 */
978 	if (xlog_is_shutdown(ip->i_mount->m_log)) {
979 		xfs_iunpin_wait(ip);
980 		/*
981 		 * Avoid a ABBA deadlock on the inode cluster buffer vs
982 		 * concurrent xfs_ifree_cluster() trying to mark the inode
983 		 * stale. We don't need the inode locked to run the flush abort
984 		 * code, but the flush abort needs to lock the cluster buffer.
985 		 */
986 		xfs_iunlock(ip, XFS_ILOCK_EXCL);
987 		xfs_iflush_shutdown_abort(ip);
988 		xfs_ilock(ip, XFS_ILOCK_EXCL);
989 		goto reclaim;
990 	}
991 	if (xfs_ipincount(ip))
992 		goto out_clear_flush;
993 	if (!xfs_inode_clean(ip))
994 		goto out_clear_flush;
995 
996 	xfs_iflags_clear(ip, XFS_IFLUSHING);
997 reclaim:
998 	trace_xfs_inode_reclaiming(ip);
999 
1000 	/*
1001 	 * Because we use RCU freeing we need to ensure the inode always appears
1002 	 * to be reclaimed with an invalid inode number when in the free state.
1003 	 * We do this as early as possible under the ILOCK so that
1004 	 * xfs_iflush_cluster() and xfs_ifree_cluster() can be guaranteed to
1005 	 * detect races with us here. By doing this, we guarantee that once
1006 	 * xfs_iflush_cluster() or xfs_ifree_cluster() has locked XFS_ILOCK that
1007 	 * it will see either a valid inode that will serialise correctly, or it
1008 	 * will see an invalid inode that it can skip.
1009 	 */
1010 	spin_lock(&ip->i_flags_lock);
1011 	ip->i_flags = XFS_IRECLAIM;
1012 	VFS_I(ip)->i_ino = 0;
1013 	ip->i_sick = 0;
1014 	ip->i_checked = 0;
1015 	spin_unlock(&ip->i_flags_lock);
1016 
1017 	ASSERT(!ip->i_itemp || ip->i_itemp->ili_item.li_buf == NULL);
1018 	xfs_iunlock(ip, XFS_ILOCK_EXCL);
1019 
1020 	XFS_STATS_INC(ip->i_mount, xs_ig_reclaims);
1021 	/*
1022 	 * Remove the inode from the per-AG radix tree.
1023 	 *
1024 	 * Because radix_tree_delete won't complain even if the item was never
1025 	 * added to the tree assert that it's been there before to catch
1026 	 * problems with the inode life time early on.
1027 	 */
1028 	spin_lock(&pag->pag_ici_lock);
1029 	if (!radix_tree_delete(&pag->pag_ici_root,
1030 				XFS_INO_TO_AGINO(ip->i_mount, ino)))
1031 		ASSERT(0);
1032 	xfs_perag_clear_inode_tag(pag, NULLAGINO, XFS_ICI_RECLAIM_TAG);
1033 	spin_unlock(&pag->pag_ici_lock);
1034 
1035 	/*
1036 	 * Here we do an (almost) spurious inode lock in order to coordinate
1037 	 * with inode cache radix tree lookups.  This is because the lookup
1038 	 * can reference the inodes in the cache without taking references.
1039 	 *
1040 	 * We make that OK here by ensuring that we wait until the inode is
1041 	 * unlocked after the lookup before we go ahead and free it.
1042 	 */
1043 	xfs_ilock(ip, XFS_ILOCK_EXCL);
1044 	ASSERT(!ip->i_udquot && !ip->i_gdquot && !ip->i_pdquot);
1045 	xfs_iunlock(ip, XFS_ILOCK_EXCL);
1046 	ASSERT(xfs_inode_clean(ip));
1047 
1048 	__xfs_inode_free(ip);
1049 	return;
1050 
1051 out_clear_flush:
1052 	xfs_iflags_clear(ip, XFS_IFLUSHING);
1053 out_iunlock:
1054 	xfs_iunlock(ip, XFS_ILOCK_EXCL);
1055 out:
1056 	xfs_iflags_clear(ip, XFS_IRECLAIM);
1057 }
1058 
1059 /* Reclaim sick inodes if we're unmounting or the fs went down. */
1060 static inline bool
1061 xfs_want_reclaim_sick(
1062 	struct xfs_mount	*mp)
1063 {
1064 	return xfs_is_unmounting(mp) || xfs_has_norecovery(mp) ||
1065 	       xfs_is_shutdown(mp);
1066 }
1067 
1068 void
1069 xfs_reclaim_inodes(
1070 	struct xfs_mount	*mp)
1071 {
1072 	struct xfs_icwalk	icw = {
1073 		.icw_flags	= 0,
1074 	};
1075 
1076 	if (xfs_want_reclaim_sick(mp))
1077 		icw.icw_flags |= XFS_ICWALK_FLAG_RECLAIM_SICK;
1078 
1079 	while (xfs_group_marked(mp, XG_TYPE_AG, XFS_PERAG_RECLAIM_MARK)) {
1080 		xfs_ail_push_all_sync(mp->m_ail);
1081 		xfs_icwalk(mp, XFS_ICWALK_RECLAIM, &icw);
1082 	}
1083 }
1084 
1085 /*
1086  * The shrinker infrastructure determines how many inodes we should scan for
1087  * reclaim. We want as many clean inodes ready to reclaim as possible, so we
1088  * push the AIL here. We also want to proactively free up memory if we can to
1089  * minimise the amount of work memory reclaim has to do so we kick the
1090  * background reclaim if it isn't already scheduled.
1091  */
1092 long
1093 xfs_reclaim_inodes_nr(
1094 	struct xfs_mount	*mp,
1095 	unsigned long		nr_to_scan)
1096 {
1097 	struct xfs_icwalk	icw = {
1098 		.icw_flags	= XFS_ICWALK_FLAG_SCAN_LIMIT,
1099 		.icw_scan_limit	= min_t(unsigned long, LONG_MAX, nr_to_scan),
1100 	};
1101 
1102 	if (xfs_want_reclaim_sick(mp))
1103 		icw.icw_flags |= XFS_ICWALK_FLAG_RECLAIM_SICK;
1104 
1105 	/* kick background reclaimer and push the AIL */
1106 	xfs_reclaim_work_queue(mp);
1107 	xfs_ail_push_all(mp->m_ail);
1108 
1109 	xfs_icwalk(mp, XFS_ICWALK_RECLAIM, &icw);
1110 	return 0;
1111 }
1112 
1113 /*
1114  * Return the number of reclaimable inodes in the filesystem for
1115  * the shrinker to determine how much to reclaim.
1116  */
1117 long
1118 xfs_reclaim_inodes_count(
1119 	struct xfs_mount	*mp)
1120 {
1121 	XA_STATE		(xas, &mp->m_groups[XG_TYPE_AG].xa, 0);
1122 	long			reclaimable = 0;
1123 	struct xfs_perag	*pag;
1124 
1125 	rcu_read_lock();
1126 	xas_for_each_marked(&xas, pag, ULONG_MAX, XFS_PERAG_RECLAIM_MARK) {
1127 		trace_xfs_reclaim_inodes_count(pag, _THIS_IP_);
1128 		reclaimable += pag->pag_ici_reclaimable;
1129 	}
1130 	rcu_read_unlock();
1131 
1132 	return reclaimable;
1133 }
1134 
1135 STATIC bool
1136 xfs_icwalk_match_id(
1137 	struct xfs_inode	*ip,
1138 	struct xfs_icwalk	*icw)
1139 {
1140 	if ((icw->icw_flags & XFS_ICWALK_FLAG_UID) &&
1141 	    !uid_eq(VFS_I(ip)->i_uid, icw->icw_uid))
1142 		return false;
1143 
1144 	if ((icw->icw_flags & XFS_ICWALK_FLAG_GID) &&
1145 	    !gid_eq(VFS_I(ip)->i_gid, icw->icw_gid))
1146 		return false;
1147 
1148 	if ((icw->icw_flags & XFS_ICWALK_FLAG_PRID) &&
1149 	    ip->i_projid != icw->icw_prid)
1150 		return false;
1151 
1152 	return true;
1153 }
1154 
1155 /*
1156  * A union-based inode filtering algorithm. Process the inode if any of the
1157  * criteria match. This is for global/internal scans only.
1158  */
1159 STATIC bool
1160 xfs_icwalk_match_id_union(
1161 	struct xfs_inode	*ip,
1162 	struct xfs_icwalk	*icw)
1163 {
1164 	if ((icw->icw_flags & XFS_ICWALK_FLAG_UID) &&
1165 	    uid_eq(VFS_I(ip)->i_uid, icw->icw_uid))
1166 		return true;
1167 
1168 	if ((icw->icw_flags & XFS_ICWALK_FLAG_GID) &&
1169 	    gid_eq(VFS_I(ip)->i_gid, icw->icw_gid))
1170 		return true;
1171 
1172 	if ((icw->icw_flags & XFS_ICWALK_FLAG_PRID) &&
1173 	    ip->i_projid == icw->icw_prid)
1174 		return true;
1175 
1176 	return false;
1177 }
1178 
1179 /*
1180  * Is this inode @ip eligible for eof/cow block reclamation, given some
1181  * filtering parameters @icw?  The inode is eligible if @icw is null or
1182  * if the predicate functions match.
1183  */
1184 static bool
1185 xfs_icwalk_match(
1186 	struct xfs_inode	*ip,
1187 	struct xfs_icwalk	*icw)
1188 {
1189 	bool			match;
1190 
1191 	if (!icw)
1192 		return true;
1193 
1194 	if (icw->icw_flags & XFS_ICWALK_FLAG_UNION)
1195 		match = xfs_icwalk_match_id_union(ip, icw);
1196 	else
1197 		match = xfs_icwalk_match_id(ip, icw);
1198 	if (!match)
1199 		return false;
1200 
1201 	/* skip the inode if the file size is too small */
1202 	if ((icw->icw_flags & XFS_ICWALK_FLAG_MINFILESIZE) &&
1203 	    XFS_ISIZE(ip) < icw->icw_min_file_size)
1204 		return false;
1205 
1206 	return true;
1207 }
1208 
1209 /*
1210  * This is a fast pass over the inode cache to try to get reclaim moving on as
1211  * many inodes as possible in a short period of time. It kicks itself every few
1212  * seconds, as well as being kicked by the inode cache shrinker when memory
1213  * goes low.
1214  */
1215 void
1216 xfs_reclaim_worker(
1217 	struct work_struct *work)
1218 {
1219 	struct xfs_mount *mp = container_of(to_delayed_work(work),
1220 					struct xfs_mount, m_reclaim_work);
1221 
1222 	xfs_icwalk(mp, XFS_ICWALK_RECLAIM, NULL);
1223 	xfs_reclaim_work_queue(mp);
1224 }
1225 
1226 STATIC int
1227 xfs_inode_free_eofblocks(
1228 	struct xfs_inode	*ip,
1229 	struct xfs_icwalk	*icw,
1230 	unsigned int		*lockflags)
1231 {
1232 	bool			wait;
1233 
1234 	wait = icw && (icw->icw_flags & XFS_ICWALK_FLAG_SYNC);
1235 
1236 	if (!xfs_iflags_test(ip, XFS_IEOFBLOCKS))
1237 		return 0;
1238 
1239 	/*
1240 	 * If the mapping is dirty the operation can block and wait for some
1241 	 * time. Unless we are waiting, skip it.
1242 	 */
1243 	if (!wait && mapping_tagged(VFS_I(ip)->i_mapping, PAGECACHE_TAG_DIRTY))
1244 		return 0;
1245 
1246 	if (!xfs_icwalk_match(ip, icw))
1247 		return 0;
1248 
1249 	/*
1250 	 * If the caller is waiting, return -EAGAIN to keep the background
1251 	 * scanner moving and revisit the inode in a subsequent pass.
1252 	 */
1253 	if (!xfs_ilock_nowait(ip, XFS_IOLOCK_EXCL)) {
1254 		if (wait)
1255 			return -EAGAIN;
1256 		return 0;
1257 	}
1258 	*lockflags |= XFS_IOLOCK_EXCL;
1259 
1260 	if (xfs_can_free_eofblocks(ip))
1261 		return xfs_free_eofblocks(ip);
1262 
1263 	/* inode could be preallocated */
1264 	trace_xfs_inode_free_eofblocks_invalid(ip);
1265 	xfs_inode_clear_eofblocks_tag(ip);
1266 	return 0;
1267 }
1268 
1269 static void
1270 xfs_blockgc_set_iflag(
1271 	struct xfs_inode	*ip,
1272 	unsigned long		iflag)
1273 {
1274 	struct xfs_mount	*mp = ip->i_mount;
1275 	struct xfs_perag	*pag;
1276 
1277 	ASSERT((iflag & ~(XFS_IEOFBLOCKS | XFS_ICOWBLOCKS)) == 0);
1278 
1279 	/*
1280 	 * Don't bother locking the AG and looking up in the radix trees
1281 	 * if we already know that we have the tag set.
1282 	 */
1283 	if (ip->i_flags & iflag)
1284 		return;
1285 	spin_lock(&ip->i_flags_lock);
1286 	ip->i_flags |= iflag;
1287 	spin_unlock(&ip->i_flags_lock);
1288 
1289 	pag = xfs_perag_get(mp, XFS_INODE_TO_AGNO(ip));
1290 	spin_lock(&pag->pag_ici_lock);
1291 
1292 	xfs_perag_set_inode_tag(pag, XFS_INODE_TO_AGINO(ip),
1293 			XFS_ICI_BLOCKGC_TAG);
1294 
1295 	spin_unlock(&pag->pag_ici_lock);
1296 	xfs_perag_put(pag);
1297 }
1298 
1299 void
1300 xfs_inode_set_eofblocks_tag(
1301 	xfs_inode_t	*ip)
1302 {
1303 	trace_xfs_inode_set_eofblocks_tag(ip);
1304 	return xfs_blockgc_set_iflag(ip, XFS_IEOFBLOCKS);
1305 }
1306 
1307 static void
1308 xfs_blockgc_clear_iflag(
1309 	struct xfs_inode	*ip,
1310 	unsigned long		iflag)
1311 {
1312 	struct xfs_mount	*mp = ip->i_mount;
1313 	struct xfs_perag	*pag;
1314 	bool			clear_tag;
1315 
1316 	ASSERT((iflag & ~(XFS_IEOFBLOCKS | XFS_ICOWBLOCKS)) == 0);
1317 
1318 	spin_lock(&ip->i_flags_lock);
1319 	ip->i_flags &= ~iflag;
1320 	clear_tag = (ip->i_flags & (XFS_IEOFBLOCKS | XFS_ICOWBLOCKS)) == 0;
1321 	spin_unlock(&ip->i_flags_lock);
1322 
1323 	if (!clear_tag)
1324 		return;
1325 
1326 	pag = xfs_perag_get(mp, XFS_INODE_TO_AGNO(ip));
1327 	spin_lock(&pag->pag_ici_lock);
1328 
1329 	xfs_perag_clear_inode_tag(pag, XFS_INODE_TO_AGINO(ip),
1330 			XFS_ICI_BLOCKGC_TAG);
1331 
1332 	spin_unlock(&pag->pag_ici_lock);
1333 	xfs_perag_put(pag);
1334 }
1335 
1336 void
1337 xfs_inode_clear_eofblocks_tag(
1338 	xfs_inode_t	*ip)
1339 {
1340 	trace_xfs_inode_clear_eofblocks_tag(ip);
1341 	return xfs_blockgc_clear_iflag(ip, XFS_IEOFBLOCKS);
1342 }
1343 
1344 /*
1345  * Prepare to free COW fork blocks from an inode.
1346  */
1347 static bool
1348 xfs_prep_free_cowblocks(
1349 	struct xfs_inode	*ip,
1350 	struct xfs_icwalk	*icw)
1351 {
1352 	bool			sync;
1353 
1354 	sync = icw && (icw->icw_flags & XFS_ICWALK_FLAG_SYNC);
1355 
1356 	/*
1357 	 * Just clear the tag if we have an empty cow fork or none at all. It's
1358 	 * possible the inode was fully unshared since it was originally tagged.
1359 	 */
1360 	if (!xfs_inode_has_cow_data(ip)) {
1361 		trace_xfs_inode_free_cowblocks_invalid(ip);
1362 		xfs_inode_clear_cowblocks_tag(ip);
1363 		return false;
1364 	}
1365 
1366 	/*
1367 	 * A cowblocks trim of an inode can have a significant effect on
1368 	 * fragmentation even when a reasonable COW extent size hint is set.
1369 	 * Therefore, we prefer to not process cowblocks unless they are clean
1370 	 * and idle. We can never process a cowblocks inode that is dirty or has
1371 	 * in-flight I/O under any circumstances, because outstanding writeback
1372 	 * or dio expects targeted COW fork blocks exist through write
1373 	 * completion where they can be remapped into the data fork.
1374 	 *
1375 	 * Therefore, the heuristic used here is to never process inodes
1376 	 * currently opened for write from background (i.e. non-sync) scans. For
1377 	 * sync scans, use the pagecache/dio state of the inode to ensure we
1378 	 * never free COW fork blocks out from under pending I/O.
1379 	 */
1380 	if (!sync && inode_is_open_for_write(VFS_I(ip)))
1381 		return false;
1382 	return xfs_can_free_cowblocks(ip);
1383 }
1384 
1385 /*
1386  * Automatic CoW Reservation Freeing
1387  *
1388  * These functions automatically garbage collect leftover CoW reservations
1389  * that were made on behalf of a cowextsize hint when we start to run out
1390  * of quota or when the reservations sit around for too long.  If the file
1391  * has dirty pages or is undergoing writeback, its CoW reservations will
1392  * be retained.
1393  *
1394  * The actual garbage collection piggybacks off the same code that runs
1395  * the speculative EOF preallocation garbage collector.
1396  */
1397 STATIC int
1398 xfs_inode_free_cowblocks(
1399 	struct xfs_inode	*ip,
1400 	struct xfs_icwalk	*icw,
1401 	unsigned int		*lockflags)
1402 {
1403 	bool			wait;
1404 	int			ret = 0;
1405 
1406 	wait = icw && (icw->icw_flags & XFS_ICWALK_FLAG_SYNC);
1407 
1408 	if (!xfs_iflags_test(ip, XFS_ICOWBLOCKS))
1409 		return 0;
1410 
1411 	if (!xfs_prep_free_cowblocks(ip, icw))
1412 		return 0;
1413 
1414 	if (!xfs_icwalk_match(ip, icw))
1415 		return 0;
1416 
1417 	/*
1418 	 * If the caller is waiting, return -EAGAIN to keep the background
1419 	 * scanner moving and revisit the inode in a subsequent pass.
1420 	 */
1421 	if (!(*lockflags & XFS_IOLOCK_EXCL) &&
1422 	    !xfs_ilock_nowait(ip, XFS_IOLOCK_EXCL)) {
1423 		if (wait)
1424 			return -EAGAIN;
1425 		return 0;
1426 	}
1427 	*lockflags |= XFS_IOLOCK_EXCL;
1428 
1429 	if (!xfs_ilock_nowait(ip, XFS_MMAPLOCK_EXCL)) {
1430 		if (wait)
1431 			return -EAGAIN;
1432 		return 0;
1433 	}
1434 	*lockflags |= XFS_MMAPLOCK_EXCL;
1435 
1436 	/*
1437 	 * Check again, nobody else should be able to dirty blocks or change
1438 	 * the reflink iflag now that we have the first two locks held.
1439 	 */
1440 	if (xfs_prep_free_cowblocks(ip, icw))
1441 		ret = xfs_reflink_cancel_cow_range(ip, 0, NULLFILEOFF, false);
1442 	return ret;
1443 }
1444 
1445 void
1446 xfs_inode_set_cowblocks_tag(
1447 	xfs_inode_t	*ip)
1448 {
1449 	trace_xfs_inode_set_cowblocks_tag(ip);
1450 	return xfs_blockgc_set_iflag(ip, XFS_ICOWBLOCKS);
1451 }
1452 
1453 void
1454 xfs_inode_clear_cowblocks_tag(
1455 	xfs_inode_t	*ip)
1456 {
1457 	trace_xfs_inode_clear_cowblocks_tag(ip);
1458 	return xfs_blockgc_clear_iflag(ip, XFS_ICOWBLOCKS);
1459 }
1460 
1461 /* Disable post-EOF and CoW block auto-reclamation. */
1462 void
1463 xfs_blockgc_stop(
1464 	struct xfs_mount	*mp)
1465 {
1466 	struct xfs_perag	*pag = NULL;
1467 
1468 	if (!xfs_clear_blockgc_enabled(mp))
1469 		return;
1470 
1471 	while ((pag = xfs_perag_next(mp, pag)))
1472 		cancel_delayed_work_sync(&pag->pag_blockgc_work);
1473 	trace_xfs_blockgc_stop(mp, __return_address);
1474 }
1475 
1476 /* Enable post-EOF and CoW block auto-reclamation. */
1477 void
1478 xfs_blockgc_start(
1479 	struct xfs_mount	*mp)
1480 {
1481 	struct xfs_perag	*pag = NULL;
1482 
1483 	if (xfs_set_blockgc_enabled(mp))
1484 		return;
1485 
1486 	trace_xfs_blockgc_start(mp, __return_address);
1487 	while ((pag = xfs_perag_grab_next_tag(mp, pag, XFS_ICI_BLOCKGC_TAG)))
1488 		xfs_blockgc_queue(pag);
1489 }
1490 
1491 /* Don't try to run block gc on an inode that's in any of these states. */
1492 #define XFS_BLOCKGC_NOGRAB_IFLAGS	(XFS_INEW | \
1493 					 XFS_NEED_INACTIVE | \
1494 					 XFS_INACTIVATING | \
1495 					 XFS_IRECLAIMABLE | \
1496 					 XFS_IRECLAIM)
1497 /*
1498  * Decide if the given @ip is eligible for garbage collection of speculative
1499  * preallocations, and grab it if so.  Returns true if it's ready to go or
1500  * false if we should just ignore it.
1501  */
1502 static bool
1503 xfs_blockgc_igrab(
1504 	struct xfs_inode	*ip)
1505 {
1506 	struct inode		*inode = VFS_I(ip);
1507 
1508 	ASSERT(rcu_read_lock_held());
1509 
1510 	/* Check for stale RCU freed inode */
1511 	spin_lock(&ip->i_flags_lock);
1512 	if (!I_INO(ip))
1513 		goto out_unlock_noent;
1514 
1515 	if (ip->i_flags & XFS_BLOCKGC_NOGRAB_IFLAGS)
1516 		goto out_unlock_noent;
1517 	spin_unlock(&ip->i_flags_lock);
1518 
1519 	/* nothing to sync during shutdown */
1520 	if (xfs_is_shutdown(ip->i_mount))
1521 		return false;
1522 
1523 	/* If we can't grab the inode, it must on it's way to reclaim. */
1524 	if (!igrab(inode))
1525 		return false;
1526 
1527 	/* inode is valid */
1528 	return true;
1529 
1530 out_unlock_noent:
1531 	spin_unlock(&ip->i_flags_lock);
1532 	return false;
1533 }
1534 
1535 /* Scan one incore inode for block preallocations that we can remove. */
1536 static int
1537 xfs_blockgc_scan_inode(
1538 	struct xfs_inode	*ip,
1539 	struct xfs_icwalk	*icw)
1540 {
1541 	unsigned int		lockflags = 0;
1542 	int			error;
1543 
1544 	error = xfs_inode_free_eofblocks(ip, icw, &lockflags);
1545 	if (error)
1546 		goto unlock;
1547 
1548 	error = xfs_inode_free_cowblocks(ip, icw, &lockflags);
1549 unlock:
1550 	if (lockflags)
1551 		xfs_iunlock(ip, lockflags);
1552 	xfs_irele(ip);
1553 	return error;
1554 }
1555 
1556 /* Background worker that trims preallocated space. */
1557 void
1558 xfs_blockgc_worker(
1559 	struct work_struct	*work)
1560 {
1561 	struct xfs_perag	*pag = container_of(to_delayed_work(work),
1562 					struct xfs_perag, pag_blockgc_work);
1563 	struct xfs_mount	*mp = pag_mount(pag);
1564 	int			error;
1565 
1566 	trace_xfs_blockgc_worker(mp, __return_address);
1567 
1568 	error = xfs_icwalk_ag(pag, XFS_ICWALK_BLOCKGC, NULL);
1569 	if (error)
1570 		xfs_info(mp, "AG %u preallocation gc worker failed, err=%d",
1571 				pag_agno(pag), error);
1572 	xfs_blockgc_queue(pag);
1573 }
1574 
1575 /*
1576  * Try to free space in the filesystem by purging inactive inodes, eofblocks
1577  * and cowblocks.
1578  */
1579 int
1580 xfs_blockgc_free_space(
1581 	struct xfs_mount	*mp,
1582 	struct xfs_icwalk	*icw)
1583 {
1584 	int			error;
1585 
1586 	trace_xfs_blockgc_free_space(mp, icw, _RET_IP_);
1587 
1588 	error = xfs_icwalk(mp, XFS_ICWALK_BLOCKGC, icw);
1589 	if (error)
1590 		return error;
1591 
1592 	return xfs_inodegc_flush(mp);
1593 }
1594 
1595 /*
1596  * Reclaim all the free space that we can by scheduling the background blockgc
1597  * and inodegc workers immediately and waiting for them all to clear.
1598  */
1599 int
1600 xfs_blockgc_flush_all(
1601 	struct xfs_mount	*mp)
1602 {
1603 	struct xfs_perag	*pag = NULL;
1604 
1605 	trace_xfs_blockgc_flush_all(mp, __return_address);
1606 
1607 	/*
1608 	 * For each blockgc worker, move its queue time up to now.  If it wasn't
1609 	 * queued, it will not be requeued.  Then flush whatever is left.
1610 	 */
1611 	while ((pag = xfs_perag_grab_next_tag(mp, pag, XFS_ICI_BLOCKGC_TAG)))
1612 		mod_delayed_work(mp->m_blockgc_wq, &pag->pag_blockgc_work, 0);
1613 
1614 	while ((pag = xfs_perag_grab_next_tag(mp, pag, XFS_ICI_BLOCKGC_TAG)))
1615 		flush_delayed_work(&pag->pag_blockgc_work);
1616 
1617 	return xfs_inodegc_flush(mp);
1618 }
1619 
1620 /*
1621  * Run cow/eofblocks scans on the supplied dquots.  We don't know exactly which
1622  * quota caused an allocation failure, so we make a best effort by including
1623  * each quota under low free space conditions (less than 1% free space) in the
1624  * scan.
1625  *
1626  * Callers must not hold any inode's ILOCK.  If requesting a synchronous scan
1627  * (XFS_ICWALK_FLAG_SYNC), the caller also must not hold any inode's IOLOCK or
1628  * MMAPLOCK.
1629  */
1630 int
1631 xfs_blockgc_free_dquots(
1632 	struct xfs_mount	*mp,
1633 	struct xfs_dquot	*udqp,
1634 	struct xfs_dquot	*gdqp,
1635 	struct xfs_dquot	*pdqp,
1636 	unsigned int		iwalk_flags)
1637 {
1638 	struct xfs_icwalk	icw = {0};
1639 	bool			do_work = false;
1640 
1641 	if (!udqp && !gdqp && !pdqp)
1642 		return 0;
1643 
1644 	/*
1645 	 * Run a scan to free blocks using the union filter to cover all
1646 	 * applicable quotas in a single scan.
1647 	 */
1648 	icw.icw_flags = XFS_ICWALK_FLAG_UNION | iwalk_flags;
1649 
1650 	if (XFS_IS_UQUOTA_ENFORCED(mp) && udqp && xfs_dquot_lowsp(udqp)) {
1651 		icw.icw_uid = make_kuid(mp->m_super->s_user_ns, udqp->q_id);
1652 		icw.icw_flags |= XFS_ICWALK_FLAG_UID;
1653 		do_work = true;
1654 	}
1655 
1656 	if (XFS_IS_UQUOTA_ENFORCED(mp) && gdqp && xfs_dquot_lowsp(gdqp)) {
1657 		icw.icw_gid = make_kgid(mp->m_super->s_user_ns, gdqp->q_id);
1658 		icw.icw_flags |= XFS_ICWALK_FLAG_GID;
1659 		do_work = true;
1660 	}
1661 
1662 	if (XFS_IS_PQUOTA_ENFORCED(mp) && pdqp && xfs_dquot_lowsp(pdqp)) {
1663 		icw.icw_prid = pdqp->q_id;
1664 		icw.icw_flags |= XFS_ICWALK_FLAG_PRID;
1665 		do_work = true;
1666 	}
1667 
1668 	if (!do_work)
1669 		return 0;
1670 
1671 	return xfs_blockgc_free_space(mp, &icw);
1672 }
1673 
1674 /* Run cow/eofblocks scans on the quotas attached to the inode. */
1675 int
1676 xfs_blockgc_free_quota(
1677 	struct xfs_inode	*ip,
1678 	unsigned int		iwalk_flags)
1679 {
1680 	return xfs_blockgc_free_dquots(ip->i_mount,
1681 			xfs_inode_dquot(ip, XFS_DQTYPE_USER),
1682 			xfs_inode_dquot(ip, XFS_DQTYPE_GROUP),
1683 			xfs_inode_dquot(ip, XFS_DQTYPE_PROJ), iwalk_flags);
1684 }
1685 
1686 /* XFS Inode Cache Walking Code */
1687 
1688 /*
1689  * The inode lookup is done in batches to keep the amount of lock traffic and
1690  * radix tree lookups to a minimum. The batch size is a trade off between
1691  * lookup reduction and stack usage. This is in the reclaim path, so we can't
1692  * be too greedy.
1693  */
1694 #define XFS_LOOKUP_BATCH	32
1695 
1696 
1697 /*
1698  * Decide if we want to grab this inode in anticipation of doing work towards
1699  * the goal.
1700  */
1701 static inline bool
1702 xfs_icwalk_igrab(
1703 	enum xfs_icwalk_goal	goal,
1704 	struct xfs_inode	*ip,
1705 	struct xfs_icwalk	*icw)
1706 {
1707 	switch (goal) {
1708 	case XFS_ICWALK_BLOCKGC:
1709 		return xfs_blockgc_igrab(ip);
1710 	case XFS_ICWALK_RECLAIM:
1711 		return xfs_reclaim_igrab(ip, icw);
1712 	default:
1713 		return false;
1714 	}
1715 }
1716 
1717 /*
1718  * Process an inode.  Each processing function must handle any state changes
1719  * made by the icwalk igrab function.  Return -EAGAIN to skip an inode.
1720  */
1721 static inline int
1722 xfs_icwalk_process_inode(
1723 	enum xfs_icwalk_goal	goal,
1724 	struct xfs_inode	*ip,
1725 	struct xfs_perag	*pag,
1726 	struct xfs_icwalk	*icw)
1727 {
1728 	int			error = 0;
1729 
1730 	switch (goal) {
1731 	case XFS_ICWALK_BLOCKGC:
1732 		error = xfs_blockgc_scan_inode(ip, icw);
1733 		break;
1734 	case XFS_ICWALK_RECLAIM:
1735 		xfs_reclaim_inode(ip, pag);
1736 		break;
1737 	}
1738 	return error;
1739 }
1740 
1741 /*
1742  * For a given per-AG structure @pag and a goal, grab qualifying inodes and
1743  * process them in some manner.
1744  */
1745 static int
1746 xfs_icwalk_ag(
1747 	struct xfs_perag	*pag,
1748 	enum xfs_icwalk_goal	goal,
1749 	struct xfs_icwalk	*icw)
1750 {
1751 	struct xfs_mount	*mp = pag_mount(pag);
1752 	uint32_t		first_index;
1753 	int			last_error = 0;
1754 	int			skipped;
1755 	bool			done;
1756 	int			nr_found;
1757 
1758 restart:
1759 	done = false;
1760 	skipped = 0;
1761 	if (goal == XFS_ICWALK_RECLAIM)
1762 		first_index = READ_ONCE(pag->pag_ici_reclaim_cursor);
1763 	else
1764 		first_index = 0;
1765 	nr_found = 0;
1766 	do {
1767 		struct xfs_inode *batch[XFS_LOOKUP_BATCH];
1768 		int		error = 0;
1769 		int		i;
1770 
1771 		rcu_read_lock();
1772 
1773 		nr_found = radix_tree_gang_lookup_tag(&pag->pag_ici_root,
1774 				(void **) batch, first_index,
1775 				XFS_LOOKUP_BATCH, goal);
1776 		if (!nr_found) {
1777 			done = true;
1778 			rcu_read_unlock();
1779 			break;
1780 		}
1781 
1782 		/*
1783 		 * Grab the inodes before we drop the lock. if we found
1784 		 * nothing, nr == 0 and the loop will be skipped.
1785 		 */
1786 		for (i = 0; i < nr_found; i++) {
1787 			struct xfs_inode *ip = batch[i];
1788 
1789 			if (done || !xfs_icwalk_igrab(goal, ip, icw))
1790 				batch[i] = NULL;
1791 
1792 			/*
1793 			 * Update the index for the next lookup. Catch
1794 			 * overflows into the next AG range which can occur if
1795 			 * we have inodes in the last block of the AG and we
1796 			 * are currently pointing to the last inode.
1797 			 *
1798 			 * Because we may see inodes that are from the wrong AG
1799 			 * due to RCU freeing and reallocation, only update the
1800 			 * index if it lies in this AG. It was a race that lead
1801 			 * us to see this inode, so another lookup from the
1802 			 * same index will not find it again.
1803 			 */
1804 			if (XFS_INODE_TO_AGNO(ip) != pag_agno(pag))
1805 				continue;
1806 			first_index = XFS_INO_TO_AGINO(mp, I_INO(ip) + 1);
1807 			if (first_index < XFS_INODE_TO_AGINO(ip))
1808 				done = true;
1809 		}
1810 
1811 		/* unlock now we've grabbed the inodes. */
1812 		rcu_read_unlock();
1813 
1814 		for (i = 0; i < nr_found; i++) {
1815 			if (!batch[i])
1816 				continue;
1817 			error = xfs_icwalk_process_inode(goal, batch[i], pag,
1818 					icw);
1819 			if (error == -EAGAIN) {
1820 				skipped++;
1821 				continue;
1822 			}
1823 			if (error && last_error != -EFSCORRUPTED)
1824 				last_error = error;
1825 		}
1826 
1827 		/* bail out if the filesystem is corrupted.  */
1828 		if (error == -EFSCORRUPTED)
1829 			break;
1830 
1831 		cond_resched();
1832 
1833 		if (icw && (icw->icw_flags & XFS_ICWALK_FLAG_SCAN_LIMIT)) {
1834 			icw->icw_scan_limit -= XFS_LOOKUP_BATCH;
1835 			if (icw->icw_scan_limit <= 0)
1836 				break;
1837 		}
1838 	} while (nr_found && !done);
1839 
1840 	if (goal == XFS_ICWALK_RECLAIM) {
1841 		if (done)
1842 			first_index = 0;
1843 		WRITE_ONCE(pag->pag_ici_reclaim_cursor, first_index);
1844 	}
1845 
1846 	if (skipped) {
1847 		delay(1);
1848 		goto restart;
1849 	}
1850 	return last_error;
1851 }
1852 
1853 /* Walk all incore inodes to achieve a given goal. */
1854 static int
1855 xfs_icwalk(
1856 	struct xfs_mount	*mp,
1857 	enum xfs_icwalk_goal	goal,
1858 	struct xfs_icwalk	*icw)
1859 {
1860 	struct xfs_perag	*pag = NULL;
1861 	int			error = 0;
1862 	int			last_error = 0;
1863 
1864 	while ((pag = xfs_perag_grab_next_tag(mp, pag, goal))) {
1865 		error = xfs_icwalk_ag(pag, goal, icw);
1866 		if (error) {
1867 			last_error = error;
1868 			if (error == -EFSCORRUPTED) {
1869 				xfs_perag_rele(pag);
1870 				break;
1871 			}
1872 		}
1873 	}
1874 	return last_error;
1875 	BUILD_BUG_ON(XFS_ICWALK_PRIVATE_FLAGS & XFS_ICWALK_FLAGS_VALID);
1876 }
1877 
1878 #ifdef DEBUG
1879 static void
1880 xfs_check_delalloc(
1881 	struct xfs_inode	*ip,
1882 	int			whichfork)
1883 {
1884 	struct xfs_ifork	*ifp = xfs_ifork_ptr(ip, whichfork);
1885 	struct xfs_bmbt_irec	got;
1886 	struct xfs_iext_cursor	icur;
1887 
1888 	if (!ifp || !xfs_iext_lookup_extent(ip, ifp, 0, &icur, &got))
1889 		return;
1890 	do {
1891 		if (isnullstartblock(got.br_startblock)) {
1892 			xfs_warn(ip->i_mount,
1893 	"ino %llx %s fork has delalloc extent at [0x%llx:0x%llx]",
1894 				I_INO(ip),
1895 				whichfork == XFS_DATA_FORK ? "data" : "cow",
1896 				got.br_startoff, got.br_blockcount);
1897 		}
1898 	} while (xfs_iext_next_extent(ifp, &icur, &got));
1899 }
1900 #else
1901 #define xfs_check_delalloc(ip, whichfork)	do { } while (0)
1902 #endif
1903 
1904 /* Schedule the inode for reclaim. */
1905 static void
1906 xfs_inodegc_set_reclaimable(
1907 	struct xfs_inode	*ip)
1908 {
1909 	struct xfs_mount	*mp = ip->i_mount;
1910 	struct xfs_perag	*pag;
1911 
1912 	if (!xfs_is_shutdown(mp) && ip->i_delayed_blks) {
1913 		xfs_check_delalloc(ip, XFS_DATA_FORK);
1914 		xfs_check_delalloc(ip, XFS_COW_FORK);
1915 		ASSERT(0);
1916 	}
1917 
1918 	pag = xfs_perag_get(mp, XFS_INODE_TO_AGNO(ip));
1919 	spin_lock(&pag->pag_ici_lock);
1920 	spin_lock(&ip->i_flags_lock);
1921 
1922 	trace_xfs_inode_set_reclaimable(ip);
1923 	ip->i_flags &= ~(XFS_NEED_INACTIVE | XFS_INACTIVATING);
1924 	ip->i_flags |= XFS_IRECLAIMABLE;
1925 	xfs_perag_set_inode_tag(pag, XFS_INODE_TO_AGINO(ip),
1926 			XFS_ICI_RECLAIM_TAG);
1927 
1928 	spin_unlock(&ip->i_flags_lock);
1929 	spin_unlock(&pag->pag_ici_lock);
1930 	xfs_perag_put(pag);
1931 }
1932 
1933 /*
1934  * Free all speculative preallocations and possibly even the inode itself.
1935  * This is the last chance to make changes to an otherwise unreferenced file
1936  * before incore reclamation happens.
1937  */
1938 static int
1939 xfs_inodegc_inactivate(
1940 	struct xfs_inode	*ip)
1941 {
1942 	int			error;
1943 
1944 	trace_xfs_inode_inactivating(ip);
1945 	error = xfs_inactive(ip);
1946 	xfs_inodegc_set_reclaimable(ip);
1947 	return error;
1948 
1949 }
1950 
1951 void
1952 xfs_inodegc_worker(
1953 	struct work_struct	*work)
1954 {
1955 	struct xfs_inodegc	*gc = container_of(to_delayed_work(work),
1956 						struct xfs_inodegc, work);
1957 	struct llist_node	*node = llist_del_all(&gc->list);
1958 	struct xfs_inode	*ip, *n;
1959 	struct xfs_mount	*mp = gc->mp;
1960 	unsigned int		nofs_flag;
1961 
1962 	/*
1963 	 * Clear the cpu mask bit and ensure that we have seen the latest
1964 	 * update of the gc structure associated with this CPU. This matches
1965 	 * with the release semantics used when setting the cpumask bit in
1966 	 * xfs_inodegc_queue.
1967 	 */
1968 	cpumask_clear_cpu(gc->cpu, &mp->m_inodegc_cpumask);
1969 	smp_mb__after_atomic();
1970 
1971 	WRITE_ONCE(gc->items, 0);
1972 
1973 	if (!node)
1974 		return;
1975 
1976 	/*
1977 	 * We can allocate memory here while doing writeback on behalf of
1978 	 * memory reclaim.  To avoid memory allocation deadlocks set the
1979 	 * task-wide nofs context for the following operations.
1980 	 */
1981 	nofs_flag = memalloc_nofs_save();
1982 
1983 	ip = llist_entry(node, struct xfs_inode, i_gclist);
1984 	trace_xfs_inodegc_worker(mp, READ_ONCE(gc->shrinker_hits));
1985 
1986 	WRITE_ONCE(gc->shrinker_hits, 0);
1987 	llist_for_each_entry_safe(ip, n, node, i_gclist) {
1988 		int	error;
1989 
1990 		xfs_iflags_set(ip, XFS_INACTIVATING);
1991 		error = xfs_inodegc_inactivate(ip);
1992 		if (error && !gc->error)
1993 			gc->error = error;
1994 	}
1995 
1996 	memalloc_nofs_restore(nofs_flag);
1997 }
1998 
1999 /*
2000  * Expedite all pending inodegc work to run immediately. This does not wait for
2001  * completion of the work.
2002  */
2003 void
2004 xfs_inodegc_push(
2005 	struct xfs_mount	*mp)
2006 {
2007 	if (!xfs_is_inodegc_enabled(mp))
2008 		return;
2009 	trace_xfs_inodegc_push(mp, __return_address);
2010 	xfs_inodegc_queue_all(mp);
2011 }
2012 
2013 /*
2014  * Force all currently queued inode inactivation work to run immediately and
2015  * wait for the work to finish.
2016  */
2017 int
2018 xfs_inodegc_flush(
2019 	struct xfs_mount	*mp)
2020 {
2021 	xfs_inodegc_push(mp);
2022 	trace_xfs_inodegc_flush(mp, __return_address);
2023 	return xfs_inodegc_wait_all(mp);
2024 }
2025 
2026 /*
2027  * Flush all the pending work and then disable the inode inactivation background
2028  * workers and wait for them to stop.  Caller must hold sb->s_umount to
2029  * coordinate changes in the inodegc_enabled state.
2030  */
2031 void
2032 xfs_inodegc_stop(
2033 	struct xfs_mount	*mp)
2034 {
2035 	bool			rerun;
2036 
2037 	if (!xfs_clear_inodegc_enabled(mp))
2038 		return;
2039 
2040 	/*
2041 	 * Drain all pending inodegc work, including inodes that could be
2042 	 * queued by racing xfs_inodegc_queue or xfs_inodegc_shrinker_scan
2043 	 * threads that sample the inodegc state just prior to us clearing it.
2044 	 * The inodegc flag state prevents new threads from queuing more
2045 	 * inodes, so we queue pending work items and flush the workqueue until
2046 	 * all inodegc lists are empty.  IOWs, we cannot use drain_workqueue
2047 	 * here because it does not allow other unserialized mechanisms to
2048 	 * reschedule inodegc work while this draining is in progress.
2049 	 */
2050 	xfs_inodegc_queue_all(mp);
2051 	do {
2052 		flush_workqueue(mp->m_inodegc_wq);
2053 		rerun = xfs_inodegc_queue_all(mp);
2054 	} while (rerun);
2055 
2056 	trace_xfs_inodegc_stop(mp, __return_address);
2057 }
2058 
2059 /*
2060  * Enable the inode inactivation background workers and schedule deferred inode
2061  * inactivation work if there is any.  Caller must hold sb->s_umount to
2062  * coordinate changes in the inodegc_enabled state.
2063  */
2064 void
2065 xfs_inodegc_start(
2066 	struct xfs_mount	*mp)
2067 {
2068 	if (xfs_set_inodegc_enabled(mp))
2069 		return;
2070 
2071 	trace_xfs_inodegc_start(mp, __return_address);
2072 	xfs_inodegc_queue_all(mp);
2073 }
2074 
2075 #ifdef CONFIG_XFS_RT
2076 static inline bool
2077 xfs_inodegc_want_queue_rt_file(
2078 	struct xfs_inode	*ip)
2079 {
2080 	struct xfs_mount	*mp = ip->i_mount;
2081 
2082 	if (!XFS_IS_REALTIME_INODE(ip) || xfs_has_zoned(mp))
2083 		return false;
2084 
2085 	if (xfs_compare_freecounter(mp, XC_FREE_RTEXTENTS,
2086 				mp->m_low_rtexts[XFS_LOWSP_5_PCNT],
2087 				XFS_FDBLOCKS_BATCH) < 0)
2088 		return true;
2089 
2090 	return false;
2091 }
2092 #else
2093 # define xfs_inodegc_want_queue_rt_file(ip)	(false)
2094 #endif /* CONFIG_XFS_RT */
2095 
2096 /*
2097  * Schedule the inactivation worker when:
2098  *
2099  *  - We've accumulated more than one inode cluster buffer's worth of inodes.
2100  *  - There is less than 5% free space left.
2101  *  - Any of the quotas for this inode are near an enforcement limit.
2102  */
2103 static inline bool
2104 xfs_inodegc_want_queue_work(
2105 	struct xfs_inode	*ip,
2106 	unsigned int		items)
2107 {
2108 	struct xfs_mount	*mp = ip->i_mount;
2109 
2110 	if (items > mp->m_ino_geo.inodes_per_cluster)
2111 		return true;
2112 
2113 	if (xfs_compare_freecounter(mp, XC_FREE_BLOCKS,
2114 				mp->m_low_space[XFS_LOWSP_5_PCNT],
2115 				XFS_FDBLOCKS_BATCH) < 0)
2116 		return true;
2117 
2118 	if (xfs_inodegc_want_queue_rt_file(ip))
2119 		return true;
2120 
2121 	if (xfs_inode_near_dquot_enforcement(ip, XFS_DQTYPE_USER))
2122 		return true;
2123 
2124 	if (xfs_inode_near_dquot_enforcement(ip, XFS_DQTYPE_GROUP))
2125 		return true;
2126 
2127 	if (xfs_inode_near_dquot_enforcement(ip, XFS_DQTYPE_PROJ))
2128 		return true;
2129 
2130 	return false;
2131 }
2132 
2133 /*
2134  * Upper bound on the number of inodes in each AG that can be queued for
2135  * inactivation at any given time, to avoid monopolizing the workqueue.
2136  */
2137 #define XFS_INODEGC_MAX_BACKLOG		(4 * XFS_INODES_PER_CHUNK)
2138 
2139 /*
2140  * Make the frontend wait for inactivations when:
2141  *
2142  *  - Memory shrinkers queued the inactivation worker and it hasn't finished.
2143  *  - The queue depth exceeds the maximum allowable percpu backlog.
2144  *
2145  * Note: If we are in a NOFS context here (e.g. current thread is running a
2146  * transaction) the we don't want to block here as inodegc progress may require
2147  * filesystem resources we hold to make progress and that could result in a
2148  * deadlock. Hence we skip out of here if we are in a scoped NOFS context.
2149  */
2150 static inline bool
2151 xfs_inodegc_want_flush_work(
2152 	struct xfs_inode	*ip,
2153 	unsigned int		items,
2154 	unsigned int		shrinker_hits)
2155 {
2156 	if (current->flags & PF_MEMALLOC_NOFS)
2157 		return false;
2158 
2159 	if (shrinker_hits > 0)
2160 		return true;
2161 
2162 	if (items > XFS_INODEGC_MAX_BACKLOG)
2163 		return true;
2164 
2165 	return false;
2166 }
2167 
2168 /*
2169  * Queue a background inactivation worker if there are inodes that need to be
2170  * inactivated and higher level xfs code hasn't disabled the background
2171  * workers.
2172  */
2173 static void
2174 xfs_inodegc_queue(
2175 	struct xfs_inode	*ip)
2176 {
2177 	struct xfs_mount	*mp = ip->i_mount;
2178 	struct xfs_inodegc	*gc;
2179 	int			items;
2180 	unsigned int		shrinker_hits;
2181 	unsigned int		cpu_nr;
2182 	unsigned long		queue_delay = 1;
2183 
2184 	trace_xfs_inode_set_need_inactive(ip);
2185 	spin_lock(&ip->i_flags_lock);
2186 	ip->i_flags |= XFS_NEED_INACTIVE;
2187 	spin_unlock(&ip->i_flags_lock);
2188 
2189 	cpu_nr = get_cpu();
2190 	gc = this_cpu_ptr(mp->m_inodegc);
2191 	llist_add(&ip->i_gclist, &gc->list);
2192 	items = READ_ONCE(gc->items);
2193 	WRITE_ONCE(gc->items, items + 1);
2194 	shrinker_hits = READ_ONCE(gc->shrinker_hits);
2195 
2196 	/*
2197 	 * Ensure the list add is always seen by anyone who finds the cpumask
2198 	 * bit set. This effectively gives the cpumask bit set operation
2199 	 * release ordering semantics.
2200 	 */
2201 	smp_mb__before_atomic();
2202 	if (!cpumask_test_cpu(cpu_nr, &mp->m_inodegc_cpumask))
2203 		cpumask_test_and_set_cpu(cpu_nr, &mp->m_inodegc_cpumask);
2204 
2205 	/*
2206 	 * We queue the work while holding the current CPU so that the work
2207 	 * is scheduled to run on this CPU.
2208 	 */
2209 	if (!xfs_is_inodegc_enabled(mp)) {
2210 		put_cpu();
2211 		return;
2212 	}
2213 
2214 	if (xfs_inodegc_want_queue_work(ip, items))
2215 		queue_delay = 0;
2216 
2217 	trace_xfs_inodegc_queue(mp, __return_address);
2218 	mod_delayed_work_on(current_cpu(), mp->m_inodegc_wq, &gc->work,
2219 			queue_delay);
2220 	put_cpu();
2221 
2222 	if (xfs_inodegc_want_flush_work(ip, items, shrinker_hits)) {
2223 		trace_xfs_inodegc_throttle(mp, __return_address);
2224 		flush_delayed_work(&gc->work);
2225 	}
2226 }
2227 
2228 /*
2229  * We set the inode flag atomically with the radix tree tag.  Once we get tag
2230  * lookups on the radix tree, this inode flag can go away.
2231  *
2232  * We always use background reclaim here because even if the inode is clean, it
2233  * still may be under IO and hence we have wait for IO completion to occur
2234  * before we can reclaim the inode. The background reclaim path handles this
2235  * more efficiently than we can here, so simply let background reclaim tear down
2236  * all inodes.
2237  */
2238 void
2239 xfs_inode_mark_reclaimable(
2240 	struct xfs_inode	*ip)
2241 {
2242 	struct xfs_mount	*mp = ip->i_mount;
2243 	bool			need_inactive;
2244 
2245 	XFS_STATS_INC(mp, xs_inode_mark_reclaimable);
2246 
2247 	/*
2248 	 * We should never get here with any of the reclaim flags already set.
2249 	 */
2250 	ASSERT_ALWAYS(!xfs_iflags_test(ip, XFS_ALL_IRECLAIM_FLAGS));
2251 
2252 	need_inactive = xfs_inode_needs_inactive(ip);
2253 	if (need_inactive) {
2254 		xfs_inodegc_queue(ip);
2255 		return;
2256 	}
2257 
2258 	/* Going straight to reclaim, so drop the dquots. */
2259 	xfs_qm_dqdetach(ip);
2260 	xfs_inodegc_set_reclaimable(ip);
2261 }
2262 
2263 /*
2264  * Register a phony shrinker so that we can run background inodegc sooner when
2265  * there's memory pressure.  Inactivation does not itself free any memory but
2266  * it does make inodes reclaimable, which eventually frees memory.
2267  *
2268  * The count function, seek value, and batch value are crafted to trigger the
2269  * scan function during the second round of scanning.  Hopefully this means
2270  * that we reclaimed enough memory that initiating metadata transactions won't
2271  * make things worse.
2272  */
2273 #define XFS_INODEGC_SHRINKER_COUNT	(1UL << DEF_PRIORITY)
2274 #define XFS_INODEGC_SHRINKER_BATCH	((XFS_INODEGC_SHRINKER_COUNT / 2) + 1)
2275 
2276 static unsigned long
2277 xfs_inodegc_shrinker_count(
2278 	struct shrinker		*shrink,
2279 	struct shrink_control	*sc)
2280 {
2281 	struct xfs_mount	*mp = shrink->private_data;
2282 	struct xfs_inodegc	*gc;
2283 	int			cpu;
2284 
2285 	if (!xfs_is_inodegc_enabled(mp))
2286 		return 0;
2287 
2288 	for_each_cpu(cpu, &mp->m_inodegc_cpumask) {
2289 		gc = per_cpu_ptr(mp->m_inodegc, cpu);
2290 		if (!llist_empty(&gc->list))
2291 			return XFS_INODEGC_SHRINKER_COUNT;
2292 	}
2293 
2294 	return 0;
2295 }
2296 
2297 static unsigned long
2298 xfs_inodegc_shrinker_scan(
2299 	struct shrinker		*shrink,
2300 	struct shrink_control	*sc)
2301 {
2302 	struct xfs_mount	*mp = shrink->private_data;
2303 	struct xfs_inodegc	*gc;
2304 	int			cpu;
2305 	bool			no_items = true;
2306 
2307 	if (!xfs_is_inodegc_enabled(mp))
2308 		return SHRINK_STOP;
2309 
2310 	trace_xfs_inodegc_shrinker_scan(mp, sc, __return_address);
2311 
2312 	for_each_cpu(cpu, &mp->m_inodegc_cpumask) {
2313 		gc = per_cpu_ptr(mp->m_inodegc, cpu);
2314 		if (!llist_empty(&gc->list)) {
2315 			unsigned int	h = READ_ONCE(gc->shrinker_hits);
2316 
2317 			WRITE_ONCE(gc->shrinker_hits, h + 1);
2318 			mod_delayed_work_on(cpu, mp->m_inodegc_wq, &gc->work, 0);
2319 			no_items = false;
2320 		}
2321 	}
2322 
2323 	/*
2324 	 * If there are no inodes to inactivate, we don't want the shrinker
2325 	 * to think there's deferred work to call us back about.
2326 	 */
2327 	if (no_items)
2328 		return LONG_MAX;
2329 
2330 	return SHRINK_STOP;
2331 }
2332 
2333 /* Register a shrinker so we can accelerate inodegc and throttle queuing. */
2334 int
2335 xfs_inodegc_register_shrinker(
2336 	struct xfs_mount	*mp)
2337 {
2338 	mp->m_inodegc_shrinker = shrinker_alloc(SHRINKER_NONSLAB,
2339 						"xfs-inodegc:%s",
2340 						mp->m_super->s_id);
2341 	if (!mp->m_inodegc_shrinker)
2342 		return -ENOMEM;
2343 
2344 	mp->m_inodegc_shrinker->count_objects = xfs_inodegc_shrinker_count;
2345 	mp->m_inodegc_shrinker->scan_objects = xfs_inodegc_shrinker_scan;
2346 	mp->m_inodegc_shrinker->seeks = 0;
2347 	mp->m_inodegc_shrinker->batch = XFS_INODEGC_SHRINKER_BATCH;
2348 	mp->m_inodegc_shrinker->private_data = mp;
2349 
2350 	shrinker_register(mp->m_inodegc_shrinker);
2351 
2352 	return 0;
2353 }
2354