1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3 * Copyright (C) Sistina Software, Inc. 1997-2003 All rights reserved.
4 * Copyright (C) 2004-2006 Red Hat, Inc. All rights reserved.
5 */
6
7 #include <linux/module.h>
8 #include <linux/slab.h>
9 #include <linux/spinlock.h>
10 #include <linux/completion.h>
11 #include <linux/buffer_head.h>
12 #include <linux/gfs2_ondisk.h>
13 #include <linux/crc32.h>
14 #include <linux/crc32c.h>
15 #include <linux/ktime.h>
16
17 #include "gfs2.h"
18 #include "incore.h"
19 #include "bmap.h"
20 #include "glock.h"
21 #include "glops.h"
22 #include "log.h"
23 #include "lops.h"
24 #include "meta_io.h"
25 #include "recovery.h"
26 #include "super.h"
27 #include "util.h"
28 #include "dir.h"
29
30 struct workqueue_struct *gfs2_recovery_wq;
31
gfs2_replay_read_block(struct gfs2_jdesc * jd,unsigned int blk,struct buffer_head ** bh)32 int gfs2_replay_read_block(struct gfs2_jdesc *jd, unsigned int blk,
33 struct buffer_head **bh)
34 {
35 struct gfs2_inode *ip = GFS2_I(jd->jd_inode);
36 struct gfs2_glock *gl = ip->i_gl;
37 u64 dblock;
38 u32 extlen;
39 int error;
40
41 extlen = 32;
42 error = gfs2_get_extent(&ip->i_inode, blk, &dblock, &extlen);
43 if (error)
44 return error;
45 if (!dblock) {
46 gfs2_consist_inode(ip);
47 return -EIO;
48 }
49
50 *bh = gfs2_meta_ra(gl, dblock, extlen);
51
52 return error;
53 }
54
gfs2_revoke_add(struct gfs2_jdesc * jd,u64 blkno,unsigned int where)55 int gfs2_revoke_add(struct gfs2_jdesc *jd, u64 blkno, unsigned int where)
56 {
57 struct list_head *head = &jd->jd_revoke_list;
58 struct gfs2_revoke_replay *rr = NULL, *iter;
59
60 list_for_each_entry(iter, head, rr_list) {
61 if (iter->rr_blkno == blkno) {
62 rr = iter;
63 break;
64 }
65 }
66
67 if (rr) {
68 rr->rr_where = where;
69 return 0;
70 }
71
72 rr = kmalloc_obj(struct gfs2_revoke_replay, GFP_NOFS);
73 if (!rr)
74 return -ENOMEM;
75
76 rr->rr_blkno = blkno;
77 rr->rr_where = where;
78 list_add(&rr->rr_list, head);
79
80 return 1;
81 }
82
gfs2_revoke_check(struct gfs2_jdesc * jd,u64 blkno,unsigned int where)83 int gfs2_revoke_check(struct gfs2_jdesc *jd, u64 blkno, unsigned int where)
84 {
85 struct gfs2_revoke_replay *rr = NULL, *iter;
86 int wrap, a, b, revoke;
87
88 list_for_each_entry(iter, &jd->jd_revoke_list, rr_list) {
89 if (iter->rr_blkno == blkno) {
90 rr = iter;
91 break;
92 }
93 }
94
95 if (!rr)
96 return 0;
97
98 wrap = (rr->rr_where < jd->jd_replay_tail);
99 a = (jd->jd_replay_tail < where);
100 b = (where < rr->rr_where);
101 revoke = (wrap) ? (a || b) : (a && b);
102
103 return revoke;
104 }
105
gfs2_revoke_clean(struct gfs2_jdesc * jd)106 void gfs2_revoke_clean(struct gfs2_jdesc *jd)
107 {
108 struct list_head *head = &jd->jd_revoke_list;
109 struct gfs2_revoke_replay *rr;
110
111 while (!list_empty(head)) {
112 rr = list_first_entry(head, struct gfs2_revoke_replay, rr_list);
113 list_del(&rr->rr_list);
114 kfree(rr);
115 }
116 }
117
__get_log_header(struct gfs2_sbd * sdp,const struct gfs2_log_header * lh,unsigned int blkno,struct gfs2_log_header_host * head)118 int __get_log_header(struct gfs2_sbd *sdp, const struct gfs2_log_header *lh,
119 unsigned int blkno, struct gfs2_log_header_host *head)
120 {
121 const u32 zero = 0;
122 u32 hash, crc;
123
124 if (lh->lh_header.mh_magic != cpu_to_be32(GFS2_MAGIC) ||
125 lh->lh_header.mh_type != cpu_to_be32(GFS2_METATYPE_LH) ||
126 (blkno && be32_to_cpu(lh->lh_blkno) != blkno))
127 return 1;
128
129 hash = crc32(~0, lh, LH_V1_SIZE - 4);
130 hash = ~crc32(hash, &zero, 4); /* assume lh_hash is zero */
131
132 if (be32_to_cpu(lh->lh_hash) != hash)
133 return 1;
134
135 crc = crc32c(~0, (void *)lh + LH_V1_SIZE + 4,
136 sdp->sd_sb.sb_bsize - LH_V1_SIZE - 4);
137
138 if ((lh->lh_crc != 0 && be32_to_cpu(lh->lh_crc) != crc))
139 return 1;
140
141 head->lh_sequence = be64_to_cpu(lh->lh_sequence);
142 head->lh_flags = be32_to_cpu(lh->lh_flags);
143 head->lh_tail = be32_to_cpu(lh->lh_tail);
144 head->lh_blkno = be32_to_cpu(lh->lh_blkno);
145
146 head->lh_local_total = be64_to_cpu(lh->lh_local_total);
147 head->lh_local_free = be64_to_cpu(lh->lh_local_free);
148 head->lh_local_dinodes = be64_to_cpu(lh->lh_local_dinodes);
149
150 return 0;
151 }
152 /**
153 * get_log_header - read the log header for a given segment
154 * @jd: the journal
155 * @blk: the block to look at
156 * @head: the log header to return
157 *
158 * Read the log header for a given segement in a given journal. Do a few
159 * sanity checks on it.
160 *
161 * Returns: 0 on success,
162 * 1 if the header was invalid or incomplete,
163 * errno on error
164 */
165
get_log_header(struct gfs2_jdesc * jd,unsigned int blk,struct gfs2_log_header_host * head)166 static int get_log_header(struct gfs2_jdesc *jd, unsigned int blk,
167 struct gfs2_log_header_host *head)
168 {
169 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
170 struct buffer_head *bh;
171 int error;
172
173 error = gfs2_replay_read_block(jd, blk, &bh);
174 if (error)
175 return error;
176
177 error = __get_log_header(sdp, (const struct gfs2_log_header *)bh->b_data,
178 blk, head);
179 brelse(bh);
180
181 return error;
182 }
183
184 /**
185 * foreach_descriptor - go through the active part of the log
186 * @jd: the journal
187 * @start: the first log header in the active region
188 * @end: the last log header (don't process the contents of this entry))
189 * @pass: iteration number (foreach_descriptor() is called in a for() loop)
190 *
191 * Call a given function once for every log descriptor in the active
192 * portion of the log.
193 *
194 * Returns: errno
195 */
196
foreach_descriptor(struct gfs2_jdesc * jd,u32 start,unsigned int end,int pass)197 static int foreach_descriptor(struct gfs2_jdesc *jd, u32 start,
198 unsigned int end, int pass)
199 {
200 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
201 struct buffer_head *bh;
202 struct gfs2_log_descriptor *ld;
203 int error = 0;
204 u32 length;
205 __be64 *ptr;
206 unsigned int offset = sizeof(struct gfs2_log_descriptor);
207 offset += sizeof(__be64) - 1;
208 offset &= ~(sizeof(__be64) - 1);
209
210 while (start != end) {
211 error = gfs2_replay_read_block(jd, start, &bh);
212 if (error)
213 return error;
214 if (gfs2_meta_check(sdp, bh)) {
215 brelse(bh);
216 return -EIO;
217 }
218 ld = (struct gfs2_log_descriptor *)bh->b_data;
219 length = be32_to_cpu(ld->ld_length);
220
221 if (be32_to_cpu(ld->ld_header.mh_type) == GFS2_METATYPE_LH) {
222 struct gfs2_log_header_host lh;
223 error = get_log_header(jd, start, &lh);
224 if (!error) {
225 gfs2_replay_incr_blk(jd, &start);
226 brelse(bh);
227 continue;
228 }
229 if (error == 1) {
230 gfs2_consist_inode(GFS2_I(jd->jd_inode));
231 error = -EIO;
232 }
233 brelse(bh);
234 return error;
235 } else if (gfs2_metatype_check(sdp, bh, GFS2_METATYPE_LD)) {
236 brelse(bh);
237 return -EIO;
238 }
239 ptr = (__be64 *)(bh->b_data + offset);
240 error = lops_scan_elements(jd, start, ld, ptr, pass);
241 if (error) {
242 brelse(bh);
243 return error;
244 }
245
246 while (length--)
247 gfs2_replay_incr_blk(jd, &start);
248
249 brelse(bh);
250 }
251
252 return 0;
253 }
254
255 /**
256 * clean_journal - mark a dirty journal as being clean
257 * @jd: the journal
258 * @head: the head journal to start from
259 *
260 * Returns: errno
261 */
262
clean_journal(struct gfs2_jdesc * jd,struct gfs2_log_header_host * head)263 static void clean_journal(struct gfs2_jdesc *jd,
264 struct gfs2_log_header_host *head)
265 {
266 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
267
268 gfs2_replay_incr_blk(jd, &head->lh_blkno);
269 head->lh_sequence++;
270 gfs2_write_log_header(sdp, jd, head->lh_sequence, 0, head->lh_blkno,
271 GFS2_LOG_HEAD_UNMOUNT | GFS2_LOG_HEAD_RECOVERY,
272 REQ_PREFLUSH | REQ_FUA | REQ_META | REQ_SYNC);
273 }
274
275
gfs2_recovery_done(struct gfs2_sbd * sdp,unsigned int jid,unsigned int message)276 static void gfs2_recovery_done(struct gfs2_sbd *sdp, unsigned int jid,
277 unsigned int message)
278 {
279 char env_jid[20];
280 char env_status[20];
281 char *envp[] = { env_jid, env_status, NULL };
282 struct lm_lockstruct *ls = &sdp->sd_lockstruct;
283
284 ls->ls_recover_jid_done = jid;
285 ls->ls_recover_jid_status = message;
286 sprintf(env_jid, "JID=%u", jid);
287 sprintf(env_status, "RECOVERY=%s",
288 message == LM_RD_SUCCESS ? "Done" : "Failed");
289 kobject_uevent_env(&sdp->sd_kobj, KOBJ_CHANGE, envp);
290
291 if (sdp->sd_lockstruct.ls_ops->lm_recovery_result)
292 sdp->sd_lockstruct.ls_ops->lm_recovery_result(sdp, jid, message);
293 }
294
295 /**
296 * update_statfs_inode - Update the master statfs inode or zero out the local
297 * statfs inode for a given journal.
298 * @jd: The journal
299 * @head: If NULL, @inode is the local statfs inode and we need to zero it out.
300 * Otherwise, it @head contains the statfs change info that needs to be
301 * synced to the master statfs inode (pointed to by @inode).
302 * @inode: statfs inode to update.
303 */
update_statfs_inode(struct gfs2_jdesc * jd,struct gfs2_log_header_host * head,struct inode * inode)304 static int update_statfs_inode(struct gfs2_jdesc *jd,
305 struct gfs2_log_header_host *head,
306 struct inode *inode)
307 {
308 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
309 struct gfs2_inode *ip;
310 struct buffer_head *bh;
311 struct gfs2_statfs_change_host sc;
312 int error = 0;
313
314 BUG_ON(!inode);
315 ip = GFS2_I(inode);
316
317 error = gfs2_meta_inode_buffer(ip, &bh);
318 if (error)
319 goto out;
320
321 spin_lock(&sdp->sd_statfs_spin);
322
323 if (head) { /* Update the master statfs inode */
324 gfs2_statfs_change_in(&sc, bh->b_data + sizeof(struct gfs2_dinode));
325 sc.sc_total += head->lh_local_total;
326 sc.sc_free += head->lh_local_free;
327 sc.sc_dinodes += head->lh_local_dinodes;
328 gfs2_statfs_change_out(&sc, bh->b_data + sizeof(struct gfs2_dinode));
329
330 fs_info(sdp, "jid=%u: Updated master statfs Total:%lld, "
331 "Free:%lld, Dinodes:%lld after change "
332 "[%+lld,%+lld,%+lld]\n", jd->jd_jid, sc.sc_total,
333 sc.sc_free, sc.sc_dinodes, head->lh_local_total,
334 head->lh_local_free, head->lh_local_dinodes);
335 } else { /* Zero out the local statfs inode */
336 memset(bh->b_data + sizeof(struct gfs2_dinode), 0,
337 sizeof(struct gfs2_statfs_change));
338 /* If it's our own journal, reset any in-memory changes too */
339 if (jd->jd_jid == sdp->sd_lockstruct.ls_jid) {
340 memset(&sdp->sd_statfs_local, 0,
341 sizeof(struct gfs2_statfs_change_host));
342 }
343 }
344 spin_unlock(&sdp->sd_statfs_spin);
345
346 mark_buffer_dirty(bh);
347 brelse(bh);
348 gfs2_inode_metasync(ip->i_gl);
349
350 out:
351 return error;
352 }
353
354 /**
355 * recover_local_statfs - Update the master and local statfs changes for this
356 * journal.
357 *
358 * Previously, statfs updates would be read in from the local statfs inode and
359 * synced to the master statfs inode during recovery.
360 *
361 * We now use the statfs updates in the journal head to update the master statfs
362 * inode instead of reading in from the local statfs inode. To preserve backward
363 * compatibility with kernels that can't do this, we still need to keep the
364 * local statfs inode up to date by writing changes to it. At some point in the
365 * future, we can do away with the local statfs inodes altogether and keep the
366 * statfs changes solely in the journal.
367 *
368 * @jd: the journal
369 * @head: the journal head
370 *
371 * Returns: errno
372 */
recover_local_statfs(struct gfs2_jdesc * jd,struct gfs2_log_header_host * head)373 static void recover_local_statfs(struct gfs2_jdesc *jd,
374 struct gfs2_log_header_host *head)
375 {
376 int error;
377 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
378
379 if (!head->lh_local_total && !head->lh_local_free
380 && !head->lh_local_dinodes) /* No change */
381 goto zero_local;
382
383 /* First update the master statfs inode with the changes we
384 * found in the journal. */
385 error = update_statfs_inode(jd, head, sdp->sd_statfs_inode);
386 if (error)
387 goto out;
388
389 zero_local:
390 /* Zero out the local statfs inode so any changes in there
391 * are not re-recovered. */
392 error = update_statfs_inode(jd, NULL,
393 find_local_statfs_inode(sdp, jd->jd_jid));
394 out:
395 return;
396 }
397
gfs2_recover_func(struct work_struct * work)398 void gfs2_recover_func(struct work_struct *work)
399 {
400 struct gfs2_jdesc *jd = container_of(work, struct gfs2_jdesc, jd_work);
401 struct gfs2_inode *ip = GFS2_I(jd->jd_inode);
402 struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
403 struct gfs2_log_header_host head;
404 struct gfs2_holder j_gh, ji_gh;
405 ktime_t t_start, t_jlck, t_jhd, t_tlck, t_rep;
406 int ro = 0;
407 unsigned int pass;
408 int error = 0;
409 int jlocked = 0;
410
411 if (gfs2_withdrawn(sdp)) {
412 fs_err(sdp, "jid=%u: Recovery not attempted due to withdraw.\n",
413 jd->jd_jid);
414 goto fail;
415 }
416 t_start = ktime_get();
417 if (sdp->sd_args.ar_spectator)
418 goto fail;
419 if (jd->jd_jid != sdp->sd_lockstruct.ls_jid) {
420 fs_info(sdp, "jid=%u: Trying to acquire journal glock...\n",
421 jd->jd_jid);
422 jlocked = 1;
423 /* Acquire the journal glock so we can do recovery */
424
425 error = gfs2_glock_nq_num(sdp, jd->jd_jid, &gfs2_journal_glops,
426 LM_ST_EXCLUSIVE,
427 LM_FLAG_RECOVER | LM_FLAG_TRY |
428 GL_NOCACHE,
429 &j_gh);
430 switch (error) {
431 case 0:
432 break;
433
434 case GLR_TRYFAILED:
435 fs_info(sdp, "jid=%u: Busy\n", jd->jd_jid);
436 error = 0;
437 goto fail;
438
439 default:
440 goto fail;
441 }
442
443 error = gfs2_glock_nq_init(ip->i_gl, LM_ST_SHARED,
444 LM_FLAG_RECOVER | GL_NOCACHE,
445 &ji_gh);
446 if (error)
447 goto fail_gunlock_j;
448 } else {
449 fs_info(sdp, "jid=%u, already locked for use\n", jd->jd_jid);
450 }
451
452 t_jlck = ktime_get();
453 fs_info(sdp, "jid=%u: Looking at journal...\n", jd->jd_jid);
454
455 error = gfs2_jdesc_check(jd);
456 if (error)
457 goto fail_gunlock_ji;
458
459 error = gfs2_find_jhead(jd, &head);
460 if (error)
461 goto fail_gunlock_ji;
462 t_jhd = ktime_get();
463 fs_info(sdp, "jid=%u: Journal head lookup took %lldms\n", jd->jd_jid,
464 ktime_ms_delta(t_jhd, t_jlck));
465
466 if (!(head.lh_flags & GFS2_LOG_HEAD_UNMOUNT)) {
467 mutex_lock(&sdp->sd_freeze_mutex);
468
469 if (test_bit(SDF_FROZEN, &sdp->sd_flags)) {
470 mutex_unlock(&sdp->sd_freeze_mutex);
471 fs_warn(sdp, "jid=%u: Can't replay: filesystem "
472 "is frozen\n", jd->jd_jid);
473 goto fail_gunlock_ji;
474 }
475
476 if (test_bit(SDF_RORECOVERY, &sdp->sd_flags)) {
477 ro = 1;
478 } else if (test_bit(SDF_JOURNAL_CHECKED, &sdp->sd_flags)) {
479 if (!test_bit(SDF_JOURNAL_LIVE, &sdp->sd_flags))
480 ro = 1;
481 } else {
482 if (sb_rdonly(sdp->sd_vfs)) {
483 /* check if device itself is read-only */
484 ro = bdev_read_only(sdp->sd_vfs->s_bdev);
485 if (!ro) {
486 fs_info(sdp, "recovery required on "
487 "read-only filesystem.\n");
488 fs_info(sdp, "write access will be "
489 "enabled during recovery.\n");
490 }
491 }
492 }
493
494 if (ro) {
495 fs_warn(sdp, "jid=%u: Can't replay: read-only block "
496 "device\n", jd->jd_jid);
497 error = -EROFS;
498 goto fail_gunlock_nofreeze;
499 }
500
501 t_tlck = ktime_get();
502 fs_info(sdp, "jid=%u: Replaying journal...0x%x to 0x%x\n",
503 jd->jd_jid, head.lh_tail, head.lh_blkno);
504
505 /* We take the sd_log_flush_lock here primarily to prevent log
506 * flushes and simultaneous journal replays from stomping on
507 * each other wrt jd_log_bio. */
508 down_read(&sdp->sd_log_flush_lock);
509 for (pass = 0; pass < 2; pass++) {
510 lops_before_scan(jd, &head, pass);
511 error = foreach_descriptor(jd, head.lh_tail,
512 head.lh_blkno, pass);
513 lops_after_scan(jd, error, pass);
514 if (error) {
515 up_read(&sdp->sd_log_flush_lock);
516 goto fail_gunlock_nofreeze;
517 }
518 }
519
520 recover_local_statfs(jd, &head);
521 clean_journal(jd, &head);
522 up_read(&sdp->sd_log_flush_lock);
523
524 mutex_unlock(&sdp->sd_freeze_mutex);
525 t_rep = ktime_get();
526 fs_info(sdp, "jid=%u: Journal replayed in %lldms [jlck:%lldms, "
527 "jhead:%lldms, tlck:%lldms, replay:%lldms]\n",
528 jd->jd_jid, ktime_ms_delta(t_rep, t_start),
529 ktime_ms_delta(t_jlck, t_start),
530 ktime_ms_delta(t_jhd, t_jlck),
531 ktime_ms_delta(t_tlck, t_jhd),
532 ktime_ms_delta(t_rep, t_tlck));
533 }
534
535 if (jd->jd_jid == sdp->sd_lockstruct.ls_jid)
536 gfs2_log_pointers_init(sdp, &head);
537
538 gfs2_recovery_done(sdp, jd->jd_jid, LM_RD_SUCCESS);
539
540 if (jlocked) {
541 gfs2_glock_dq_uninit(&ji_gh);
542 gfs2_glock_dq_uninit(&j_gh);
543 }
544
545 fs_info(sdp, "jid=%u: Done\n", jd->jd_jid);
546 goto done;
547
548 fail_gunlock_nofreeze:
549 mutex_unlock(&sdp->sd_freeze_mutex);
550 fail_gunlock_ji:
551 if (jlocked) {
552 gfs2_glock_dq_uninit(&ji_gh);
553 fail_gunlock_j:
554 gfs2_glock_dq_uninit(&j_gh);
555 }
556
557 fs_info(sdp, "jid=%u: %s\n", jd->jd_jid, (error) ? "Failed" : "Done");
558 fail:
559 jd->jd_recover_error = error;
560 gfs2_recovery_done(sdp, jd->jd_jid, LM_RD_GAVEUP);
561 done:
562 clear_bit(JDF_RECOVERY, &jd->jd_flags);
563 smp_mb__after_atomic();
564 wake_up_bit(&jd->jd_flags, JDF_RECOVERY);
565 }
566
gfs2_recover_journal(struct gfs2_jdesc * jd,bool wait)567 int gfs2_recover_journal(struct gfs2_jdesc *jd, bool wait)
568 {
569 int rv;
570
571 if (test_and_set_bit(JDF_RECOVERY, &jd->jd_flags))
572 return -EBUSY;
573
574 /* we have JDF_RECOVERY, queue should always succeed */
575 rv = queue_work(gfs2_recovery_wq, &jd->jd_work);
576 BUG_ON(!rv);
577
578 if (wait)
579 wait_on_bit(&jd->jd_flags, JDF_RECOVERY,
580 TASK_UNINTERRUPTIBLE);
581
582 return wait ? jd->jd_recover_error : 0;
583 }
584
gfs2_log_pointers_init(struct gfs2_sbd * sdp,struct gfs2_log_header_host * head)585 void gfs2_log_pointers_init(struct gfs2_sbd *sdp,
586 struct gfs2_log_header_host *head)
587 {
588 sdp->sd_log_sequence = head->lh_sequence + 1;
589 gfs2_replay_incr_blk(sdp->sd_jdesc, &head->lh_blkno);
590 sdp->sd_log_tail = head->lh_blkno;
591 sdp->sd_log_flush_head = head->lh_blkno;
592 sdp->sd_log_flush_tail = head->lh_blkno;
593 sdp->sd_log_head = head->lh_blkno;
594 }
595