xref: /linux/fs/gfs2/recovery.c (revision e47a324d6f07c9ef252cfce1f14cfa5110cbed99)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * Copyright (C) Sistina Software, Inc.  1997-2003 All rights reserved.
4  * Copyright (C) 2004-2006 Red Hat, Inc.  All rights reserved.
5  */
6 
7 #include <linux/module.h>
8 #include <linux/slab.h>
9 #include <linux/spinlock.h>
10 #include <linux/completion.h>
11 #include <linux/buffer_head.h>
12 #include <linux/gfs2_ondisk.h>
13 #include <linux/crc32.h>
14 #include <linux/crc32c.h>
15 #include <linux/ktime.h>
16 
17 #include "gfs2.h"
18 #include "incore.h"
19 #include "bmap.h"
20 #include "glock.h"
21 #include "glops.h"
22 #include "log.h"
23 #include "lops.h"
24 #include "meta_io.h"
25 #include "recovery.h"
26 #include "super.h"
27 #include "util.h"
28 #include "dir.h"
29 
30 struct workqueue_struct *gfs2_recovery_wq;
31 
32 int gfs2_replay_read_block(struct gfs2_jdesc *jd, unsigned int blk,
33 			   struct buffer_head **bh)
34 {
35 	struct gfs2_inode *ip = GFS2_I(jd->jd_inode);
36 	struct gfs2_glock *gl = ip->i_gl;
37 	u64 dblock;
38 	u32 extlen;
39 	int error;
40 
41 	extlen = 32;
42 	error = gfs2_get_extent(&ip->i_inode, blk, &dblock, &extlen);
43 	if (error)
44 		return error;
45 	if (!dblock) {
46 		gfs2_consist_inode(ip);
47 		return -EIO;
48 	}
49 
50 	*bh = gfs2_meta_ra(gl, dblock, extlen);
51 
52 	return error;
53 }
54 
55 int gfs2_revoke_add(struct gfs2_jdesc *jd, u64 blkno, unsigned int where)
56 {
57 	struct list_head *head = &jd->jd_revoke_list;
58 	struct gfs2_revoke_replay *rr = NULL, *iter;
59 
60 	list_for_each_entry(iter, head, rr_list) {
61 		if (iter->rr_blkno == blkno) {
62 			rr = iter;
63 			break;
64 		}
65 	}
66 
67 	if (rr) {
68 		rr->rr_where = where;
69 		return 0;
70 	}
71 
72 	rr = kmalloc(sizeof(struct gfs2_revoke_replay), GFP_NOFS);
73 	if (!rr)
74 		return -ENOMEM;
75 
76 	rr->rr_blkno = blkno;
77 	rr->rr_where = where;
78 	list_add(&rr->rr_list, head);
79 
80 	return 1;
81 }
82 
83 int gfs2_revoke_check(struct gfs2_jdesc *jd, u64 blkno, unsigned int where)
84 {
85 	struct gfs2_revoke_replay *rr = NULL, *iter;
86 	int wrap, a, b, revoke;
87 
88 	list_for_each_entry(iter, &jd->jd_revoke_list, rr_list) {
89 		if (iter->rr_blkno == blkno) {
90 			rr = iter;
91 			break;
92 		}
93 	}
94 
95 	if (!rr)
96 		return 0;
97 
98 	wrap = (rr->rr_where < jd->jd_replay_tail);
99 	a = (jd->jd_replay_tail < where);
100 	b = (where < rr->rr_where);
101 	revoke = (wrap) ? (a || b) : (a && b);
102 
103 	return revoke;
104 }
105 
106 void gfs2_revoke_clean(struct gfs2_jdesc *jd)
107 {
108 	struct list_head *head = &jd->jd_revoke_list;
109 	struct gfs2_revoke_replay *rr;
110 
111 	while (!list_empty(head)) {
112 		rr = list_first_entry(head, struct gfs2_revoke_replay, rr_list);
113 		list_del(&rr->rr_list);
114 		kfree(rr);
115 	}
116 }
117 
118 int __get_log_header(struct gfs2_sbd *sdp, const struct gfs2_log_header *lh,
119 		     unsigned int blkno, struct gfs2_log_header_host *head)
120 {
121 	const u32 zero = 0;
122 	u32 hash, crc;
123 
124 	if (lh->lh_header.mh_magic != cpu_to_be32(GFS2_MAGIC) ||
125 	    lh->lh_header.mh_type != cpu_to_be32(GFS2_METATYPE_LH) ||
126 	    (blkno && be32_to_cpu(lh->lh_blkno) != blkno))
127 		return 1;
128 
129 	hash = crc32(~0, lh, LH_V1_SIZE - 4);
130 	hash = ~crc32(hash, &zero, 4); /* assume lh_hash is zero */
131 
132 	if (be32_to_cpu(lh->lh_hash) != hash)
133 		return 1;
134 
135 	crc = crc32c(~0, (void *)lh + LH_V1_SIZE + 4,
136 		     sdp->sd_sb.sb_bsize - LH_V1_SIZE - 4);
137 
138 	if ((lh->lh_crc != 0 && be32_to_cpu(lh->lh_crc) != crc))
139 		return 1;
140 
141 	head->lh_sequence = be64_to_cpu(lh->lh_sequence);
142 	head->lh_flags = be32_to_cpu(lh->lh_flags);
143 	head->lh_tail = be32_to_cpu(lh->lh_tail);
144 	head->lh_blkno = be32_to_cpu(lh->lh_blkno);
145 
146 	head->lh_local_total = be64_to_cpu(lh->lh_local_total);
147 	head->lh_local_free = be64_to_cpu(lh->lh_local_free);
148 	head->lh_local_dinodes = be64_to_cpu(lh->lh_local_dinodes);
149 
150 	return 0;
151 }
152 /**
153  * get_log_header - read the log header for a given segment
154  * @jd: the journal
155  * @blk: the block to look at
156  * @head: the log header to return
157  *
158  * Read the log header for a given segement in a given journal.  Do a few
159  * sanity checks on it.
160  *
161  * Returns: 0 on success,
162  *          1 if the header was invalid or incomplete,
163  *          errno on error
164  */
165 
166 static int get_log_header(struct gfs2_jdesc *jd, unsigned int blk,
167 			  struct gfs2_log_header_host *head)
168 {
169 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
170 	struct buffer_head *bh;
171 	int error;
172 
173 	error = gfs2_replay_read_block(jd, blk, &bh);
174 	if (error)
175 		return error;
176 
177 	error = __get_log_header(sdp, (const struct gfs2_log_header *)bh->b_data,
178 				 blk, head);
179 	brelse(bh);
180 
181 	return error;
182 }
183 
184 /**
185  * foreach_descriptor - go through the active part of the log
186  * @jd: the journal
187  * @start: the first log header in the active region
188  * @end: the last log header (don't process the contents of this entry))
189  * @pass: iteration number (foreach_descriptor() is called in a for() loop)
190  *
191  * Call a given function once for every log descriptor in the active
192  * portion of the log.
193  *
194  * Returns: errno
195  */
196 
197 static int foreach_descriptor(struct gfs2_jdesc *jd, u32 start,
198 			      unsigned int end, int pass)
199 {
200 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
201 	struct buffer_head *bh;
202 	struct gfs2_log_descriptor *ld;
203 	int error = 0;
204 	u32 length;
205 	__be64 *ptr;
206 	unsigned int offset = sizeof(struct gfs2_log_descriptor);
207 	offset += sizeof(__be64) - 1;
208 	offset &= ~(sizeof(__be64) - 1);
209 
210 	while (start != end) {
211 		error = gfs2_replay_read_block(jd, start, &bh);
212 		if (error)
213 			return error;
214 		if (gfs2_meta_check(sdp, bh)) {
215 			brelse(bh);
216 			return -EIO;
217 		}
218 		ld = (struct gfs2_log_descriptor *)bh->b_data;
219 		length = be32_to_cpu(ld->ld_length);
220 
221 		if (be32_to_cpu(ld->ld_header.mh_type) == GFS2_METATYPE_LH) {
222 			struct gfs2_log_header_host lh;
223 			error = get_log_header(jd, start, &lh);
224 			if (!error) {
225 				gfs2_replay_incr_blk(jd, &start);
226 				brelse(bh);
227 				continue;
228 			}
229 			if (error == 1) {
230 				gfs2_consist_inode(GFS2_I(jd->jd_inode));
231 				error = -EIO;
232 			}
233 			brelse(bh);
234 			return error;
235 		} else if (gfs2_metatype_check(sdp, bh, GFS2_METATYPE_LD)) {
236 			brelse(bh);
237 			return -EIO;
238 		}
239 		ptr = (__be64 *)(bh->b_data + offset);
240 		error = lops_scan_elements(jd, start, ld, ptr, pass);
241 		if (error) {
242 			brelse(bh);
243 			return error;
244 		}
245 
246 		while (length--)
247 			gfs2_replay_incr_blk(jd, &start);
248 
249 		brelse(bh);
250 	}
251 
252 	return 0;
253 }
254 
255 /**
256  * clean_journal - mark a dirty journal as being clean
257  * @jd: the journal
258  * @head: the head journal to start from
259  *
260  * Returns: errno
261  */
262 
263 static void clean_journal(struct gfs2_jdesc *jd,
264 			  struct gfs2_log_header_host *head)
265 {
266 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
267 
268 	gfs2_replay_incr_blk(jd, &head->lh_blkno);
269 	head->lh_sequence++;
270 	gfs2_write_log_header(sdp, jd, head->lh_sequence, 0, head->lh_blkno,
271 			      GFS2_LOG_HEAD_UNMOUNT | GFS2_LOG_HEAD_RECOVERY,
272 			      REQ_PREFLUSH | REQ_FUA | REQ_META | REQ_SYNC);
273 }
274 
275 
276 static void gfs2_recovery_done(struct gfs2_sbd *sdp, unsigned int jid,
277                                unsigned int message)
278 {
279 	char env_jid[20];
280 	char env_status[20];
281 	char *envp[] = { env_jid, env_status, NULL };
282 	struct lm_lockstruct *ls = &sdp->sd_lockstruct;
283 
284         ls->ls_recover_jid_done = jid;
285         ls->ls_recover_jid_status = message;
286 	sprintf(env_jid, "JID=%u", jid);
287 	sprintf(env_status, "RECOVERY=%s",
288 		message == LM_RD_SUCCESS ? "Done" : "Failed");
289         kobject_uevent_env(&sdp->sd_kobj, KOBJ_CHANGE, envp);
290 
291 	if (sdp->sd_lockstruct.ls_ops->lm_recovery_result)
292 		sdp->sd_lockstruct.ls_ops->lm_recovery_result(sdp, jid, message);
293 }
294 
295 /**
296  * update_statfs_inode - Update the master statfs inode or zero out the local
297  *			 statfs inode for a given journal.
298  * @jd: The journal
299  * @head: If NULL, @inode is the local statfs inode and we need to zero it out.
300  *	  Otherwise, it @head contains the statfs change info that needs to be
301  *	  synced to the master statfs inode (pointed to by @inode).
302  * @inode: statfs inode to update.
303  */
304 static int update_statfs_inode(struct gfs2_jdesc *jd,
305 			       struct gfs2_log_header_host *head,
306 			       struct inode *inode)
307 {
308 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
309 	struct gfs2_inode *ip;
310 	struct buffer_head *bh;
311 	struct gfs2_statfs_change_host sc;
312 	int error = 0;
313 
314 	BUG_ON(!inode);
315 	ip = GFS2_I(inode);
316 
317 	error = gfs2_meta_inode_buffer(ip, &bh);
318 	if (error)
319 		goto out;
320 
321 	spin_lock(&sdp->sd_statfs_spin);
322 
323 	if (head) { /* Update the master statfs inode */
324 		gfs2_statfs_change_in(&sc, bh->b_data + sizeof(struct gfs2_dinode));
325 		sc.sc_total += head->lh_local_total;
326 		sc.sc_free += head->lh_local_free;
327 		sc.sc_dinodes += head->lh_local_dinodes;
328 		gfs2_statfs_change_out(&sc, bh->b_data + sizeof(struct gfs2_dinode));
329 
330 		fs_info(sdp, "jid=%u: Updated master statfs Total:%lld, "
331 			"Free:%lld, Dinodes:%lld after change "
332 			"[%+lld,%+lld,%+lld]\n", jd->jd_jid, sc.sc_total,
333 			sc.sc_free, sc.sc_dinodes, head->lh_local_total,
334 			head->lh_local_free, head->lh_local_dinodes);
335 	} else { /* Zero out the local statfs inode */
336 		memset(bh->b_data + sizeof(struct gfs2_dinode), 0,
337 		       sizeof(struct gfs2_statfs_change));
338 		/* If it's our own journal, reset any in-memory changes too */
339 		if (jd->jd_jid == sdp->sd_lockstruct.ls_jid) {
340 			memset(&sdp->sd_statfs_local, 0,
341 			       sizeof(struct gfs2_statfs_change_host));
342 		}
343 	}
344 	spin_unlock(&sdp->sd_statfs_spin);
345 
346 	mark_buffer_dirty(bh);
347 	brelse(bh);
348 	gfs2_inode_metasync(ip->i_gl);
349 
350 out:
351 	return error;
352 }
353 
354 /**
355  * recover_local_statfs - Update the master and local statfs changes for this
356  *			  journal.
357  *
358  * Previously, statfs updates would be read in from the local statfs inode and
359  * synced to the master statfs inode during recovery.
360  *
361  * We now use the statfs updates in the journal head to update the master statfs
362  * inode instead of reading in from the local statfs inode. To preserve backward
363  * compatibility with kernels that can't do this, we still need to keep the
364  * local statfs inode up to date by writing changes to it. At some point in the
365  * future, we can do away with the local statfs inodes altogether and keep the
366  * statfs changes solely in the journal.
367  *
368  * @jd: the journal
369  * @head: the journal head
370  *
371  * Returns: errno
372  */
373 static void recover_local_statfs(struct gfs2_jdesc *jd,
374 				 struct gfs2_log_header_host *head)
375 {
376 	int error;
377 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
378 
379 	if (!head->lh_local_total && !head->lh_local_free
380 	    && !head->lh_local_dinodes) /* No change */
381 		goto zero_local;
382 
383 	 /* First update the master statfs inode with the changes we
384 	  * found in the journal. */
385 	error = update_statfs_inode(jd, head, sdp->sd_statfs_inode);
386 	if (error)
387 		goto out;
388 
389 zero_local:
390 	/* Zero out the local statfs inode so any changes in there
391 	 * are not re-recovered. */
392 	error = update_statfs_inode(jd, NULL,
393 				    find_local_statfs_inode(sdp, jd->jd_jid));
394 out:
395 	return;
396 }
397 
398 void gfs2_recover_func(struct work_struct *work)
399 {
400 	struct gfs2_jdesc *jd = container_of(work, struct gfs2_jdesc, jd_work);
401 	struct gfs2_inode *ip = GFS2_I(jd->jd_inode);
402 	struct gfs2_sbd *sdp = GFS2_SB(jd->jd_inode);
403 	struct gfs2_log_header_host head;
404 	struct gfs2_holder j_gh, ji_gh;
405 	ktime_t t_start, t_jlck, t_jhd, t_tlck, t_rep;
406 	int ro = 0;
407 	unsigned int pass;
408 	int error = 0;
409 	int jlocked = 0;
410 
411 	if (gfs2_withdrawing_or_withdrawn(sdp)) {
412 		fs_err(sdp, "jid=%u: Recovery not attempted due to withdraw.\n",
413 		       jd->jd_jid);
414 		goto fail;
415 	}
416 	t_start = ktime_get();
417 	if (sdp->sd_args.ar_spectator)
418 		goto fail;
419 	if (jd->jd_jid != sdp->sd_lockstruct.ls_jid) {
420 		fs_info(sdp, "jid=%u: Trying to acquire journal glock...\n",
421 			jd->jd_jid);
422 		jlocked = 1;
423 		/* Acquire the journal glock so we can do recovery */
424 
425 		error = gfs2_glock_nq_num(sdp, jd->jd_jid, &gfs2_journal_glops,
426 					  LM_ST_EXCLUSIVE,
427 					  LM_FLAG_NOEXP | LM_FLAG_TRY | GL_NOCACHE,
428 					  &j_gh);
429 		switch (error) {
430 		case 0:
431 			break;
432 
433 		case GLR_TRYFAILED:
434 			fs_info(sdp, "jid=%u: Busy\n", jd->jd_jid);
435 			error = 0;
436 			goto fail;
437 
438 		default:
439 			goto fail;
440 		}
441 
442 		error = gfs2_glock_nq_init(ip->i_gl, LM_ST_SHARED,
443 					   LM_FLAG_NOEXP | GL_NOCACHE, &ji_gh);
444 		if (error)
445 			goto fail_gunlock_j;
446 	} else {
447 		fs_info(sdp, "jid=%u, already locked for use\n", jd->jd_jid);
448 	}
449 
450 	t_jlck = ktime_get();
451 	fs_info(sdp, "jid=%u: Looking at journal...\n", jd->jd_jid);
452 
453 	error = gfs2_jdesc_check(jd);
454 	if (error)
455 		goto fail_gunlock_ji;
456 
457 	error = gfs2_find_jhead(jd, &head);
458 	if (error)
459 		goto fail_gunlock_ji;
460 	t_jhd = ktime_get();
461 	fs_info(sdp, "jid=%u: Journal head lookup took %lldms\n", jd->jd_jid,
462 		ktime_ms_delta(t_jhd, t_jlck));
463 
464 	if (!(head.lh_flags & GFS2_LOG_HEAD_UNMOUNT)) {
465 		mutex_lock(&sdp->sd_freeze_mutex);
466 
467 		if (test_bit(SDF_FROZEN, &sdp->sd_flags)) {
468 			mutex_unlock(&sdp->sd_freeze_mutex);
469 			fs_warn(sdp, "jid=%u: Can't replay: filesystem "
470 				"is frozen\n", jd->jd_jid);
471 			goto fail_gunlock_ji;
472 		}
473 
474 		if (test_bit(SDF_RORECOVERY, &sdp->sd_flags)) {
475 			ro = 1;
476 		} else if (test_bit(SDF_JOURNAL_CHECKED, &sdp->sd_flags)) {
477 			if (!test_bit(SDF_JOURNAL_LIVE, &sdp->sd_flags))
478 				ro = 1;
479 		} else {
480 			if (sb_rdonly(sdp->sd_vfs)) {
481 				/* check if device itself is read-only */
482 				ro = bdev_read_only(sdp->sd_vfs->s_bdev);
483 				if (!ro) {
484 					fs_info(sdp, "recovery required on "
485 						"read-only filesystem.\n");
486 					fs_info(sdp, "write access will be "
487 						"enabled during recovery.\n");
488 				}
489 			}
490 		}
491 
492 		if (ro) {
493 			fs_warn(sdp, "jid=%u: Can't replay: read-only block "
494 				"device\n", jd->jd_jid);
495 			error = -EROFS;
496 			goto fail_gunlock_nofreeze;
497 		}
498 
499 		t_tlck = ktime_get();
500 		fs_info(sdp, "jid=%u: Replaying journal...0x%x to 0x%x\n",
501 			jd->jd_jid, head.lh_tail, head.lh_blkno);
502 
503 		/* We take the sd_log_flush_lock here primarily to prevent log
504 		 * flushes and simultaneous journal replays from stomping on
505 		 * each other wrt jd_log_bio. */
506 		down_read(&sdp->sd_log_flush_lock);
507 		for (pass = 0; pass < 2; pass++) {
508 			lops_before_scan(jd, &head, pass);
509 			error = foreach_descriptor(jd, head.lh_tail,
510 						   head.lh_blkno, pass);
511 			lops_after_scan(jd, error, pass);
512 			if (error) {
513 				up_read(&sdp->sd_log_flush_lock);
514 				goto fail_gunlock_nofreeze;
515 			}
516 		}
517 
518 		recover_local_statfs(jd, &head);
519 		clean_journal(jd, &head);
520 		up_read(&sdp->sd_log_flush_lock);
521 
522 		mutex_unlock(&sdp->sd_freeze_mutex);
523 		t_rep = ktime_get();
524 		fs_info(sdp, "jid=%u: Journal replayed in %lldms [jlck:%lldms, "
525 			"jhead:%lldms, tlck:%lldms, replay:%lldms]\n",
526 			jd->jd_jid, ktime_ms_delta(t_rep, t_start),
527 			ktime_ms_delta(t_jlck, t_start),
528 			ktime_ms_delta(t_jhd, t_jlck),
529 			ktime_ms_delta(t_tlck, t_jhd),
530 			ktime_ms_delta(t_rep, t_tlck));
531 	}
532 
533 	if (jd->jd_jid == sdp->sd_lockstruct.ls_jid)
534 		gfs2_log_pointers_init(sdp, &head);
535 
536 	gfs2_recovery_done(sdp, jd->jd_jid, LM_RD_SUCCESS);
537 
538 	if (jlocked) {
539 		gfs2_glock_dq_uninit(&ji_gh);
540 		gfs2_glock_dq_uninit(&j_gh);
541 	}
542 
543 	fs_info(sdp, "jid=%u: Done\n", jd->jd_jid);
544 	goto done;
545 
546 fail_gunlock_nofreeze:
547 	mutex_unlock(&sdp->sd_freeze_mutex);
548 fail_gunlock_ji:
549 	if (jlocked) {
550 		gfs2_glock_dq_uninit(&ji_gh);
551 fail_gunlock_j:
552 		gfs2_glock_dq_uninit(&j_gh);
553 	}
554 
555 	fs_info(sdp, "jid=%u: %s\n", jd->jd_jid, (error) ? "Failed" : "Done");
556 fail:
557 	jd->jd_recover_error = error;
558 	gfs2_recovery_done(sdp, jd->jd_jid, LM_RD_GAVEUP);
559 done:
560 	clear_bit(JDF_RECOVERY, &jd->jd_flags);
561 	smp_mb__after_atomic();
562 	wake_up_bit(&jd->jd_flags, JDF_RECOVERY);
563 }
564 
565 int gfs2_recover_journal(struct gfs2_jdesc *jd, bool wait)
566 {
567 	int rv;
568 
569 	if (test_and_set_bit(JDF_RECOVERY, &jd->jd_flags))
570 		return -EBUSY;
571 
572 	/* we have JDF_RECOVERY, queue should always succeed */
573 	rv = queue_work(gfs2_recovery_wq, &jd->jd_work);
574 	BUG_ON(!rv);
575 
576 	if (wait)
577 		wait_on_bit(&jd->jd_flags, JDF_RECOVERY,
578 			    TASK_UNINTERRUPTIBLE);
579 
580 	return wait ? jd->jd_recover_error : 0;
581 }
582 
583 void gfs2_log_pointers_init(struct gfs2_sbd *sdp,
584 			    struct gfs2_log_header_host *head)
585 {
586 	sdp->sd_log_sequence = head->lh_sequence + 1;
587 	gfs2_replay_incr_blk(sdp->sd_jdesc, &head->lh_blkno);
588 	sdp->sd_log_tail = head->lh_blkno;
589 	sdp->sd_log_flush_head = head->lh_blkno;
590 	sdp->sd_log_flush_tail = head->lh_blkno;
591 	sdp->sd_log_head = head->lh_blkno;
592 }
593