xref: /linux/fs/xfs/xfs_mount.c (revision 0560f31a09e523090d1ab2bfe21c69d028c2bdf2)
10b61f8a4SDave Chinner // SPDX-License-Identifier: GPL-2.0
21da177e4SLinus Torvalds /*
37b718769SNathan Scott  * Copyright (c) 2000-2005 Silicon Graphics, Inc.
47b718769SNathan Scott  * All Rights Reserved.
51da177e4SLinus Torvalds  */
61da177e4SLinus Torvalds #include "xfs.h"
7a844f451SNathan Scott #include "xfs_fs.h"
870a9883cSDave Chinner #include "xfs_shared.h"
9239880efSDave Chinner #include "xfs_format.h"
10239880efSDave Chinner #include "xfs_log_format.h"
11239880efSDave Chinner #include "xfs_trans_resv.h"
12a844f451SNathan Scott #include "xfs_bit.h"
131da177e4SLinus Torvalds #include "xfs_sb.h"
141da177e4SLinus Torvalds #include "xfs_mount.h"
151da177e4SLinus Torvalds #include "xfs_inode.h"
16a4fbe6abSDave Chinner #include "xfs_dir2.h"
17a844f451SNathan Scott #include "xfs_ialloc.h"
181da177e4SLinus Torvalds #include "xfs_alloc.h"
191da177e4SLinus Torvalds #include "xfs_rtalloc.h"
201da177e4SLinus Torvalds #include "xfs_bmap.h"
21a4fbe6abSDave Chinner #include "xfs_trans.h"
22a4fbe6abSDave Chinner #include "xfs_trans_priv.h"
23a4fbe6abSDave Chinner #include "xfs_log.h"
241da177e4SLinus Torvalds #include "xfs_error.h"
251da177e4SLinus Torvalds #include "xfs_quota.h"
261da177e4SLinus Torvalds #include "xfs_fsops.h"
276d8b79cfSDave Chinner #include "xfs_icache.h"
28a31b1d3dSBrian Foster #include "xfs_sysfs.h"
29035e00acSDarrick J. Wong #include "xfs_rmap_btree.h"
301946b91cSDarrick J. Wong #include "xfs_refcount_btree.h"
31174edb0eSDarrick J. Wong #include "xfs_reflink.h"
32ebf55872SChristoph Hellwig #include "xfs_extent_busy.h"
3339353ff6SDarrick J. Wong #include "xfs_health.h"
3413eaec4bSDarrick J. Wong #include "xfs_trace.h"
359bbafc71SDave Chinner #include "xfs_ag.h"
361da177e4SLinus Torvalds 
3727174203SChristoph Hellwig static DEFINE_MUTEX(xfs_uuid_table_mutex);
3827174203SChristoph Hellwig static int xfs_uuid_table_size;
3927174203SChristoph Hellwig static uuid_t *xfs_uuid_table;
4027174203SChristoph Hellwig 
41af3b6382SDarrick J. Wong void
42af3b6382SDarrick J. Wong xfs_uuid_table_free(void)
43af3b6382SDarrick J. Wong {
44af3b6382SDarrick J. Wong 	if (xfs_uuid_table_size == 0)
45af3b6382SDarrick J. Wong 		return;
46af3b6382SDarrick J. Wong 	kmem_free(xfs_uuid_table);
47af3b6382SDarrick J. Wong 	xfs_uuid_table = NULL;
48af3b6382SDarrick J. Wong 	xfs_uuid_table_size = 0;
49af3b6382SDarrick J. Wong }
50af3b6382SDarrick J. Wong 
5127174203SChristoph Hellwig /*
5227174203SChristoph Hellwig  * See if the UUID is unique among mounted XFS filesystems.
5327174203SChristoph Hellwig  * Mount fails if UUID is nil or a FS with the same UUID is already mounted.
5427174203SChristoph Hellwig  */
5527174203SChristoph Hellwig STATIC int
5627174203SChristoph Hellwig xfs_uuid_mount(
5727174203SChristoph Hellwig 	struct xfs_mount	*mp)
5827174203SChristoph Hellwig {
5927174203SChristoph Hellwig 	uuid_t			*uuid = &mp->m_sb.sb_uuid;
6027174203SChristoph Hellwig 	int			hole, i;
6127174203SChristoph Hellwig 
628f720d9fSAmir Goldstein 	/* Publish UUID in struct super_block */
6385787090SChristoph Hellwig 	uuid_copy(&mp->m_super->s_uuid, uuid);
648f720d9fSAmir Goldstein 
65*0560f31aSDave Chinner 	if (xfs_has_nouuid(mp))
6627174203SChristoph Hellwig 		return 0;
6727174203SChristoph Hellwig 
68d905fdaaSAmir Goldstein 	if (uuid_is_null(uuid)) {
69d905fdaaSAmir Goldstein 		xfs_warn(mp, "Filesystem has null UUID - can't mount");
702451337dSDave Chinner 		return -EINVAL;
7127174203SChristoph Hellwig 	}
7227174203SChristoph Hellwig 
7327174203SChristoph Hellwig 	mutex_lock(&xfs_uuid_table_mutex);
7427174203SChristoph Hellwig 	for (i = 0, hole = -1; i < xfs_uuid_table_size; i++) {
75d905fdaaSAmir Goldstein 		if (uuid_is_null(&xfs_uuid_table[i])) {
7627174203SChristoph Hellwig 			hole = i;
7727174203SChristoph Hellwig 			continue;
7827174203SChristoph Hellwig 		}
7927174203SChristoph Hellwig 		if (uuid_equal(uuid, &xfs_uuid_table[i]))
8027174203SChristoph Hellwig 			goto out_duplicate;
8127174203SChristoph Hellwig 	}
8227174203SChristoph Hellwig 
8327174203SChristoph Hellwig 	if (hole < 0) {
84771915c4SCarlos Maiolino 		xfs_uuid_table = krealloc(xfs_uuid_table,
8527174203SChristoph Hellwig 			(xfs_uuid_table_size + 1) * sizeof(*xfs_uuid_table),
86771915c4SCarlos Maiolino 			GFP_KERNEL | __GFP_NOFAIL);
8727174203SChristoph Hellwig 		hole = xfs_uuid_table_size++;
8827174203SChristoph Hellwig 	}
8927174203SChristoph Hellwig 	xfs_uuid_table[hole] = *uuid;
9027174203SChristoph Hellwig 	mutex_unlock(&xfs_uuid_table_mutex);
9127174203SChristoph Hellwig 
9227174203SChristoph Hellwig 	return 0;
9327174203SChristoph Hellwig 
9427174203SChristoph Hellwig  out_duplicate:
9527174203SChristoph Hellwig 	mutex_unlock(&xfs_uuid_table_mutex);
96021000e5SMitsuo Hayasaka 	xfs_warn(mp, "Filesystem has duplicate UUID %pU - can't mount", uuid);
972451337dSDave Chinner 	return -EINVAL;
9827174203SChristoph Hellwig }
9927174203SChristoph Hellwig 
10027174203SChristoph Hellwig STATIC void
10127174203SChristoph Hellwig xfs_uuid_unmount(
10227174203SChristoph Hellwig 	struct xfs_mount	*mp)
10327174203SChristoph Hellwig {
10427174203SChristoph Hellwig 	uuid_t			*uuid = &mp->m_sb.sb_uuid;
10527174203SChristoph Hellwig 	int			i;
10627174203SChristoph Hellwig 
107*0560f31aSDave Chinner 	if (xfs_has_nouuid(mp))
10827174203SChristoph Hellwig 		return;
10927174203SChristoph Hellwig 
11027174203SChristoph Hellwig 	mutex_lock(&xfs_uuid_table_mutex);
11127174203SChristoph Hellwig 	for (i = 0; i < xfs_uuid_table_size; i++) {
112d905fdaaSAmir Goldstein 		if (uuid_is_null(&xfs_uuid_table[i]))
11327174203SChristoph Hellwig 			continue;
11427174203SChristoph Hellwig 		if (!uuid_equal(uuid, &xfs_uuid_table[i]))
11527174203SChristoph Hellwig 			continue;
11627174203SChristoph Hellwig 		memset(&xfs_uuid_table[i], 0, sizeof(uuid_t));
11727174203SChristoph Hellwig 		break;
11827174203SChristoph Hellwig 	}
11927174203SChristoph Hellwig 	ASSERT(i < xfs_uuid_table_size);
12027174203SChristoph Hellwig 	mutex_unlock(&xfs_uuid_table_mutex);
12127174203SChristoph Hellwig }
12227174203SChristoph Hellwig 
1234cc929eeSNathan Scott /*
1244cc929eeSNathan Scott  * Check size of device based on the (data/realtime) block count.
1254cc929eeSNathan Scott  * Note: this check is used by the growfs code as well as mount.
1264cc929eeSNathan Scott  */
1274cc929eeSNathan Scott int
1284cc929eeSNathan Scott xfs_sb_validate_fsb_count(
1294cc929eeSNathan Scott 	xfs_sb_t	*sbp,
130c8ce540dSDarrick J. Wong 	uint64_t	nblocks)
1314cc929eeSNathan Scott {
1324cc929eeSNathan Scott 	ASSERT(PAGE_SHIFT >= sbp->sb_blocklog);
1334cc929eeSNathan Scott 	ASSERT(sbp->sb_blocklog >= BBSHIFT);
1344cc929eeSNathan Scott 
135d5cf09baSChristoph Hellwig 	/* Limited by ULONG_MAX of page cache index */
13609cbfeafSKirill A. Shutemov 	if (nblocks >> (PAGE_SHIFT - sbp->sb_blocklog) > ULONG_MAX)
1372451337dSDave Chinner 		return -EFBIG;
1384cc929eeSNathan Scott 	return 0;
1394cc929eeSNathan Scott }
1401da177e4SLinus Torvalds 
1411da177e4SLinus Torvalds /*
1421da177e4SLinus Torvalds  * xfs_readsb
1431da177e4SLinus Torvalds  *
1441da177e4SLinus Torvalds  * Does the initial read of the superblock.
1451da177e4SLinus Torvalds  */
1461da177e4SLinus Torvalds int
147ff55068cSDave Chinner xfs_readsb(
148ff55068cSDave Chinner 	struct xfs_mount *mp,
149ff55068cSDave Chinner 	int		flags)
1501da177e4SLinus Torvalds {
1511da177e4SLinus Torvalds 	unsigned int	sector_size;
15204a1e6c5SDave Chinner 	struct xfs_buf	*bp;
15304a1e6c5SDave Chinner 	struct xfs_sb	*sbp = &mp->m_sb;
1541da177e4SLinus Torvalds 	int		error;
155af34e09dSDave Chinner 	int		loud = !(flags & XFS_MFSI_QUIET);
156daba5427SEric Sandeen 	const struct xfs_buf_ops *buf_ops;
1571da177e4SLinus Torvalds 
1581da177e4SLinus Torvalds 	ASSERT(mp->m_sb_bp == NULL);
1591da177e4SLinus Torvalds 	ASSERT(mp->m_ddev_targp != NULL);
1601da177e4SLinus Torvalds 
1611da177e4SLinus Torvalds 	/*
162daba5427SEric Sandeen 	 * For the initial read, we must guess at the sector
163daba5427SEric Sandeen 	 * size based on the block device.  It's enough to
164daba5427SEric Sandeen 	 * get the sb_sectsize out of the superblock and
165daba5427SEric Sandeen 	 * then reread with the proper length.
166daba5427SEric Sandeen 	 * We don't verify it yet, because it may not be complete.
167daba5427SEric Sandeen 	 */
168daba5427SEric Sandeen 	sector_size = xfs_getsize_buftarg(mp->m_ddev_targp);
169daba5427SEric Sandeen 	buf_ops = NULL;
170daba5427SEric Sandeen 
171daba5427SEric Sandeen 	/*
172c891c30aSBrian Foster 	 * Allocate a (locked) buffer to hold the superblock. This will be kept
173c891c30aSBrian Foster 	 * around at all times to optimize access to the superblock. Therefore,
174c891c30aSBrian Foster 	 * set XBF_NO_IOACCT to make sure it doesn't hold the buftarg count
175c891c30aSBrian Foster 	 * elevated.
1761da177e4SLinus Torvalds 	 */
17726af6552SDave Chinner reread:
178ba372674SDave Chinner 	error = xfs_buf_read_uncached(mp->m_ddev_targp, XFS_SB_DADDR,
179c891c30aSBrian Foster 				      BTOBB(sector_size), XBF_NO_IOACCT, &bp,
180c891c30aSBrian Foster 				      buf_ops);
181ba372674SDave Chinner 	if (error) {
182eab4e633SDave Chinner 		if (loud)
183e721f504SDave Chinner 			xfs_warn(mp, "SB validate failed with error %d.", error);
184ac75a1f7SDave Chinner 		/* bad CRC means corrupted metadata */
1852451337dSDave Chinner 		if (error == -EFSBADCRC)
1862451337dSDave Chinner 			error = -EFSCORRUPTED;
187ba372674SDave Chinner 		return error;
188eab4e633SDave Chinner 	}
1891da177e4SLinus Torvalds 
1901da177e4SLinus Torvalds 	/*
1911da177e4SLinus Torvalds 	 * Initialize the mount structure from the superblock.
1921da177e4SLinus Torvalds 	 */
1933e6e8afdSChristoph Hellwig 	xfs_sb_from_disk(sbp, bp->b_addr);
194556b8883SDave Chinner 
195556b8883SDave Chinner 	/*
196556b8883SDave Chinner 	 * If we haven't validated the superblock, do so now before we try
197556b8883SDave Chinner 	 * to check the sector size and reread the superblock appropriately.
198556b8883SDave Chinner 	 */
199556b8883SDave Chinner 	if (sbp->sb_magicnum != XFS_SB_MAGIC) {
200556b8883SDave Chinner 		if (loud)
201556b8883SDave Chinner 			xfs_warn(mp, "Invalid superblock magic number");
2022451337dSDave Chinner 		error = -EINVAL;
203556b8883SDave Chinner 		goto release_buf;
204556b8883SDave Chinner 	}
205ff55068cSDave Chinner 
2061da177e4SLinus Torvalds 	/*
2071da177e4SLinus Torvalds 	 * We must be able to do sector-sized and sector-aligned IO.
2081da177e4SLinus Torvalds 	 */
20904a1e6c5SDave Chinner 	if (sector_size > sbp->sb_sectsize) {
210af34e09dSDave Chinner 		if (loud)
211af34e09dSDave Chinner 			xfs_warn(mp, "device supports %u byte sectors (not %u)",
21204a1e6c5SDave Chinner 				sector_size, sbp->sb_sectsize);
2132451337dSDave Chinner 		error = -ENOSYS;
21426af6552SDave Chinner 		goto release_buf;
2151da177e4SLinus Torvalds 	}
2161da177e4SLinus Torvalds 
217556b8883SDave Chinner 	if (buf_ops == NULL) {
2181da177e4SLinus Torvalds 		/*
219daba5427SEric Sandeen 		 * Re-read the superblock so the buffer is correctly sized,
220daba5427SEric Sandeen 		 * and properly verified.
2211da177e4SLinus Torvalds 		 */
2221da177e4SLinus Torvalds 		xfs_buf_relse(bp);
22304a1e6c5SDave Chinner 		sector_size = sbp->sb_sectsize;
224daba5427SEric Sandeen 		buf_ops = loud ? &xfs_sb_buf_ops : &xfs_sb_quiet_buf_ops;
22526af6552SDave Chinner 		goto reread;
2261da177e4SLinus Torvalds 	}
2271da177e4SLinus Torvalds 
228a1d86e8dSDave Chinner 	mp->m_features |= xfs_sb_version_to_features(sbp);
2295681ca40SDave Chinner 	xfs_reinit_percpu_counters(mp);
2308d280b98SDavid Chinner 
23104a1e6c5SDave Chinner 	/* no need to be quiet anymore, so reset the buf ops */
23204a1e6c5SDave Chinner 	bp->b_ops = &xfs_sb_buf_ops;
23304a1e6c5SDave Chinner 
2341da177e4SLinus Torvalds 	mp->m_sb_bp = bp;
23526af6552SDave Chinner 	xfs_buf_unlock(bp);
2361da177e4SLinus Torvalds 	return 0;
2371da177e4SLinus Torvalds 
23826af6552SDave Chinner release_buf:
2391da177e4SLinus Torvalds 	xfs_buf_relse(bp);
2401da177e4SLinus Torvalds 	return error;
2411da177e4SLinus Torvalds }
2421da177e4SLinus Torvalds 
2431da177e4SLinus Torvalds /*
24413eaec4bSDarrick J. Wong  * If the sunit/swidth change would move the precomputed root inode value, we
24513eaec4bSDarrick J. Wong  * must reject the ondisk change because repair will stumble over that.
24613eaec4bSDarrick J. Wong  * However, we allow the mount to proceed because we never rejected this
24713eaec4bSDarrick J. Wong  * combination before.  Returns true to update the sb, false otherwise.
24813eaec4bSDarrick J. Wong  */
24913eaec4bSDarrick J. Wong static inline int
25013eaec4bSDarrick J. Wong xfs_check_new_dalign(
25113eaec4bSDarrick J. Wong 	struct xfs_mount	*mp,
25213eaec4bSDarrick J. Wong 	int			new_dalign,
25313eaec4bSDarrick J. Wong 	bool			*update_sb)
25413eaec4bSDarrick J. Wong {
25513eaec4bSDarrick J. Wong 	struct xfs_sb		*sbp = &mp->m_sb;
25613eaec4bSDarrick J. Wong 	xfs_ino_t		calc_ino;
25713eaec4bSDarrick J. Wong 
25813eaec4bSDarrick J. Wong 	calc_ino = xfs_ialloc_calc_rootino(mp, new_dalign);
25913eaec4bSDarrick J. Wong 	trace_xfs_check_new_dalign(mp, new_dalign, calc_ino);
26013eaec4bSDarrick J. Wong 
26113eaec4bSDarrick J. Wong 	if (sbp->sb_rootino == calc_ino) {
26213eaec4bSDarrick J. Wong 		*update_sb = true;
26313eaec4bSDarrick J. Wong 		return 0;
26413eaec4bSDarrick J. Wong 	}
26513eaec4bSDarrick J. Wong 
26613eaec4bSDarrick J. Wong 	xfs_warn(mp,
26713eaec4bSDarrick J. Wong "Cannot change stripe alignment; would require moving root inode.");
26813eaec4bSDarrick J. Wong 
26913eaec4bSDarrick J. Wong 	/*
27013eaec4bSDarrick J. Wong 	 * XXX: Next time we add a new incompat feature, this should start
27113eaec4bSDarrick J. Wong 	 * returning -EINVAL to fail the mount.  Until then, spit out a warning
27213eaec4bSDarrick J. Wong 	 * that we're ignoring the administrator's instructions.
27313eaec4bSDarrick J. Wong 	 */
27413eaec4bSDarrick J. Wong 	xfs_warn(mp, "Skipping superblock stripe alignment update.");
27513eaec4bSDarrick J. Wong 	*update_sb = false;
27613eaec4bSDarrick J. Wong 	return 0;
27713eaec4bSDarrick J. Wong }
27813eaec4bSDarrick J. Wong 
27913eaec4bSDarrick J. Wong /*
2804f5b1b3aSDarrick J. Wong  * If we were provided with new sunit/swidth values as mount options, make sure
2814f5b1b3aSDarrick J. Wong  * that they pass basic alignment and superblock feature checks, and convert
2824f5b1b3aSDarrick J. Wong  * them into the same units (FSB) that everything else expects.  This step
2834f5b1b3aSDarrick J. Wong  * /must/ be done before computing the inode geometry.
2841da177e4SLinus Torvalds  */
2850771fb45SEric Sandeen STATIC int
2864f5b1b3aSDarrick J. Wong xfs_validate_new_dalign(
2874f5b1b3aSDarrick J. Wong 	struct xfs_mount	*mp)
2881da177e4SLinus Torvalds {
2894f5b1b3aSDarrick J. Wong 	if (mp->m_dalign == 0)
2904f5b1b3aSDarrick J. Wong 		return 0;
2911da177e4SLinus Torvalds 
2921da177e4SLinus Torvalds 	/*
2931da177e4SLinus Torvalds 	 * If stripe unit and stripe width are not multiples
2941da177e4SLinus Torvalds 	 * of the fs blocksize turn off alignment.
2951da177e4SLinus Torvalds 	 */
2961da177e4SLinus Torvalds 	if ((BBTOB(mp->m_dalign) & mp->m_blockmask) ||
2971da177e4SLinus Torvalds 	    (BBTOB(mp->m_swidth) & mp->m_blockmask)) {
29839a45d84SJie Liu 		xfs_warn(mp,
29939a45d84SJie Liu 	"alignment check failed: sunit/swidth vs. blocksize(%d)",
3004f5b1b3aSDarrick J. Wong 			mp->m_sb.sb_blocksize);
3012451337dSDave Chinner 		return -EINVAL;
3021da177e4SLinus Torvalds 	} else {
3031da177e4SLinus Torvalds 		/*
3041da177e4SLinus Torvalds 		 * Convert the stripe unit and width to FSBs.
3051da177e4SLinus Torvalds 		 */
3061da177e4SLinus Torvalds 		mp->m_dalign = XFS_BB_TO_FSBT(mp, mp->m_dalign);
3074f5b1b3aSDarrick J. Wong 		if (mp->m_dalign && (mp->m_sb.sb_agblocks % mp->m_dalign)) {
30853487786SDave Chinner 			xfs_warn(mp,
30939a45d84SJie Liu 		"alignment check failed: sunit/swidth vs. agsize(%d)",
3104f5b1b3aSDarrick J. Wong 				 mp->m_sb.sb_agblocks);
3112451337dSDave Chinner 			return -EINVAL;
3121da177e4SLinus Torvalds 		} else if (mp->m_dalign) {
3131da177e4SLinus Torvalds 			mp->m_swidth = XFS_BB_TO_FSBT(mp, mp->m_swidth);
3141da177e4SLinus Torvalds 		} else {
31539a45d84SJie Liu 			xfs_warn(mp,
31639a45d84SJie Liu 		"alignment check failed: sunit(%d) less than bsize(%d)",
3174f5b1b3aSDarrick J. Wong 				 mp->m_dalign, mp->m_sb.sb_blocksize);
3182451337dSDave Chinner 			return -EINVAL;
3191da177e4SLinus Torvalds 		}
3201da177e4SLinus Torvalds 	}
3211da177e4SLinus Torvalds 
32238c26bfdSDave Chinner 	if (!xfs_has_dalign(mp)) {
32334d7f603SJie Liu 		xfs_warn(mp,
32434d7f603SJie Liu "cannot change alignment: superblock does not support data alignment");
3252451337dSDave Chinner 		return -EINVAL;
3261da177e4SLinus Torvalds 	}
3274f5b1b3aSDarrick J. Wong 
3284f5b1b3aSDarrick J. Wong 	return 0;
3294f5b1b3aSDarrick J. Wong }
3304f5b1b3aSDarrick J. Wong 
3314f5b1b3aSDarrick J. Wong /* Update alignment values based on mount options and sb values. */
3324f5b1b3aSDarrick J. Wong STATIC int
3334f5b1b3aSDarrick J. Wong xfs_update_alignment(
3344f5b1b3aSDarrick J. Wong 	struct xfs_mount	*mp)
3354f5b1b3aSDarrick J. Wong {
3364f5b1b3aSDarrick J. Wong 	struct xfs_sb		*sbp = &mp->m_sb;
3374f5b1b3aSDarrick J. Wong 
3384f5b1b3aSDarrick J. Wong 	if (mp->m_dalign) {
33913eaec4bSDarrick J. Wong 		bool		update_sb;
34013eaec4bSDarrick J. Wong 		int		error;
34113eaec4bSDarrick J. Wong 
3424f5b1b3aSDarrick J. Wong 		if (sbp->sb_unit == mp->m_dalign &&
3434f5b1b3aSDarrick J. Wong 		    sbp->sb_width == mp->m_swidth)
3444f5b1b3aSDarrick J. Wong 			return 0;
3454f5b1b3aSDarrick J. Wong 
34613eaec4bSDarrick J. Wong 		error = xfs_check_new_dalign(mp, mp->m_dalign, &update_sb);
34713eaec4bSDarrick J. Wong 		if (error || !update_sb)
34813eaec4bSDarrick J. Wong 			return error;
34913eaec4bSDarrick J. Wong 
3504f5b1b3aSDarrick J. Wong 		sbp->sb_unit = mp->m_dalign;
3514f5b1b3aSDarrick J. Wong 		sbp->sb_width = mp->m_swidth;
3524f5b1b3aSDarrick J. Wong 		mp->m_update_sb = true;
353*0560f31aSDave Chinner 	} else if (!xfs_has_noalign(mp) && xfs_has_dalign(mp)) {
3541da177e4SLinus Torvalds 		mp->m_dalign = sbp->sb_unit;
3551da177e4SLinus Torvalds 		mp->m_swidth = sbp->sb_width;
3561da177e4SLinus Torvalds 	}
3571da177e4SLinus Torvalds 
3580771fb45SEric Sandeen 	return 0;
3590771fb45SEric Sandeen }
3601da177e4SLinus Torvalds 
3610771fb45SEric Sandeen /*
362055388a3SDave Chinner  * precalculate the low space thresholds for dynamic speculative preallocation.
363055388a3SDave Chinner  */
364055388a3SDave Chinner void
365055388a3SDave Chinner xfs_set_low_space_thresholds(
366055388a3SDave Chinner 	struct xfs_mount	*mp)
367055388a3SDave Chinner {
36865f03d86SDarrick J. Wong 	uint64_t		dblocks = mp->m_sb.sb_dblocks;
36965f03d86SDarrick J. Wong 	uint64_t		rtexts = mp->m_sb.sb_rextents;
370055388a3SDave Chinner 	int			i;
371055388a3SDave Chinner 
37265f03d86SDarrick J. Wong 	do_div(dblocks, 100);
37365f03d86SDarrick J. Wong 	do_div(rtexts, 100);
374055388a3SDave Chinner 
37565f03d86SDarrick J. Wong 	for (i = 0; i < XFS_LOWSP_MAX; i++) {
37665f03d86SDarrick J. Wong 		mp->m_low_space[i] = dblocks * (i + 1);
37765f03d86SDarrick J. Wong 		mp->m_low_rtexts[i] = rtexts * (i + 1);
378055388a3SDave Chinner 	}
379055388a3SDave Chinner }
380055388a3SDave Chinner 
3811da177e4SLinus Torvalds /*
3820471f62eSZhi Yong Wu  * Check that the data (and log if separate) is an ok size.
3831da177e4SLinus Torvalds  */
3840771fb45SEric Sandeen STATIC int
385ba372674SDave Chinner xfs_check_sizes(
386ba372674SDave Chinner 	struct xfs_mount *mp)
3870771fb45SEric Sandeen {
388ba372674SDave Chinner 	struct xfs_buf	*bp;
3890771fb45SEric Sandeen 	xfs_daddr_t	d;
390ba372674SDave Chinner 	int		error;
3910771fb45SEric Sandeen 
3921da177e4SLinus Torvalds 	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_dblocks);
3931da177e4SLinus Torvalds 	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_dblocks) {
3940b932cccSDave Chinner 		xfs_warn(mp, "filesystem size mismatch detected");
3952451337dSDave Chinner 		return -EFBIG;
3961da177e4SLinus Torvalds 	}
397ba372674SDave Chinner 	error = xfs_buf_read_uncached(mp->m_ddev_targp,
3981da177e4SLinus Torvalds 					d - XFS_FSS_TO_BB(mp, 1),
399ba372674SDave Chinner 					XFS_FSS_TO_BB(mp, 1), 0, &bp, NULL);
400ba372674SDave Chinner 	if (error) {
4010b932cccSDave Chinner 		xfs_warn(mp, "last sector read failed");
402ba372674SDave Chinner 		return error;
4031da177e4SLinus Torvalds 	}
4041922c949SDave Chinner 	xfs_buf_relse(bp);
4051da177e4SLinus Torvalds 
406ba372674SDave Chinner 	if (mp->m_logdev_targp == mp->m_ddev_targp)
407ba372674SDave Chinner 		return 0;
408ba372674SDave Chinner 
4091da177e4SLinus Torvalds 	d = (xfs_daddr_t)XFS_FSB_TO_BB(mp, mp->m_sb.sb_logblocks);
4101da177e4SLinus Torvalds 	if (XFS_BB_TO_FSB(mp, d) != mp->m_sb.sb_logblocks) {
4110b932cccSDave Chinner 		xfs_warn(mp, "log size mismatch detected");
4122451337dSDave Chinner 		return -EFBIG;
4131da177e4SLinus Torvalds 	}
414ba372674SDave Chinner 	error = xfs_buf_read_uncached(mp->m_logdev_targp,
4151da177e4SLinus Torvalds 					d - XFS_FSB_TO_BB(mp, 1),
416ba372674SDave Chinner 					XFS_FSB_TO_BB(mp, 1), 0, &bp, NULL);
417ba372674SDave Chinner 	if (error) {
4180b932cccSDave Chinner 		xfs_warn(mp, "log device read failed");
419ba372674SDave Chinner 		return error;
4201da177e4SLinus Torvalds 	}
4211922c949SDave Chinner 	xfs_buf_relse(bp);
4220771fb45SEric Sandeen 	return 0;
4230771fb45SEric Sandeen }
4240771fb45SEric Sandeen 
4250771fb45SEric Sandeen /*
4267d095257SChristoph Hellwig  * Clear the quotaflags in memory and in the superblock.
4277d095257SChristoph Hellwig  */
4287d095257SChristoph Hellwig int
4297d095257SChristoph Hellwig xfs_mount_reset_sbqflags(
4307d095257SChristoph Hellwig 	struct xfs_mount	*mp)
4317d095257SChristoph Hellwig {
4327d095257SChristoph Hellwig 	mp->m_qflags = 0;
4337d095257SChristoph Hellwig 
43461e63ecbSDave Chinner 	/* It is OK to look at sb_qflags in the mount path without m_sb_lock. */
4357d095257SChristoph Hellwig 	if (mp->m_sb.sb_qflags == 0)
4367d095257SChristoph Hellwig 		return 0;
4377d095257SChristoph Hellwig 	spin_lock(&mp->m_sb_lock);
4387d095257SChristoph Hellwig 	mp->m_sb.sb_qflags = 0;
4397d095257SChristoph Hellwig 	spin_unlock(&mp->m_sb_lock);
4407d095257SChristoph Hellwig 
44161e63ecbSDave Chinner 	if (!xfs_fs_writable(mp, SB_FREEZE_WRITE))
4427d095257SChristoph Hellwig 		return 0;
4437d095257SChristoph Hellwig 
44461e63ecbSDave Chinner 	return xfs_sync_sb(mp, false);
4457d095257SChristoph Hellwig }
4467d095257SChristoph Hellwig 
447c8ce540dSDarrick J. Wong uint64_t
448d5db0f97SEric Sandeen xfs_default_resblks(xfs_mount_t *mp)
449d5db0f97SEric Sandeen {
450c8ce540dSDarrick J. Wong 	uint64_t resblks;
451d5db0f97SEric Sandeen 
452d5db0f97SEric Sandeen 	/*
4538babd8a2SDave Chinner 	 * We default to 5% or 8192 fsbs of space reserved, whichever is
4548babd8a2SDave Chinner 	 * smaller.  This is intended to cover concurrent allocation
4558babd8a2SDave Chinner 	 * transactions when we initially hit enospc. These each require a 4
4568babd8a2SDave Chinner 	 * block reservation. Hence by default we cover roughly 2000 concurrent
4578babd8a2SDave Chinner 	 * allocation reservations.
458d5db0f97SEric Sandeen 	 */
459d5db0f97SEric Sandeen 	resblks = mp->m_sb.sb_dblocks;
460d5db0f97SEric Sandeen 	do_div(resblks, 20);
461c8ce540dSDarrick J. Wong 	resblks = min_t(uint64_t, resblks, 8192);
462d5db0f97SEric Sandeen 	return resblks;
463d5db0f97SEric Sandeen }
464d5db0f97SEric Sandeen 
4652e9e6481SDarrick J. Wong /* Ensure the summary counts are correct. */
4662e9e6481SDarrick J. Wong STATIC int
4672e9e6481SDarrick J. Wong xfs_check_summary_counts(
4682e9e6481SDarrick J. Wong 	struct xfs_mount	*mp)
4692e9e6481SDarrick J. Wong {
4702e9e6481SDarrick J. Wong 	/*
4712e9e6481SDarrick J. Wong 	 * The AG0 superblock verifier rejects in-progress filesystems,
4722e9e6481SDarrick J. Wong 	 * so we should never see the flag set this far into mounting.
4732e9e6481SDarrick J. Wong 	 */
4742e9e6481SDarrick J. Wong 	if (mp->m_sb.sb_inprogress) {
4752e9e6481SDarrick J. Wong 		xfs_err(mp, "sb_inprogress set after log recovery??");
4762e9e6481SDarrick J. Wong 		WARN_ON(1);
4772e9e6481SDarrick J. Wong 		return -EFSCORRUPTED;
4782e9e6481SDarrick J. Wong 	}
4792e9e6481SDarrick J. Wong 
4802e9e6481SDarrick J. Wong 	/*
4812e9e6481SDarrick J. Wong 	 * Now the log is mounted, we know if it was an unclean shutdown or
4822e9e6481SDarrick J. Wong 	 * not. If it was, with the first phase of recovery has completed, we
4832e9e6481SDarrick J. Wong 	 * have consistent AG blocks on disk. We have not recovered EFIs yet,
4842e9e6481SDarrick J. Wong 	 * but they are recovered transactionally in the second recovery phase
4852e9e6481SDarrick J. Wong 	 * later.
4862e9e6481SDarrick J. Wong 	 *
4872e9e6481SDarrick J. Wong 	 * If the log was clean when we mounted, we can check the summary
4882e9e6481SDarrick J. Wong 	 * counters.  If any of them are obviously incorrect, we can recompute
4892e9e6481SDarrick J. Wong 	 * them from the AGF headers in the next step.
4902e9e6481SDarrick J. Wong 	 */
4912e9e6481SDarrick J. Wong 	if (XFS_LAST_UNMOUNT_WAS_CLEAN(mp) &&
4922e9e6481SDarrick J. Wong 	    (mp->m_sb.sb_fdblocks > mp->m_sb.sb_dblocks ||
49300d22a1cSDarrick J. Wong 	     !xfs_verify_icount(mp, mp->m_sb.sb_icount) ||
4942e9e6481SDarrick J. Wong 	     mp->m_sb.sb_ifree > mp->m_sb.sb_icount))
49539353ff6SDarrick J. Wong 		xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
4962e9e6481SDarrick J. Wong 
4972e9e6481SDarrick J. Wong 	/*
4982e9e6481SDarrick J. Wong 	 * We can safely re-initialise incore superblock counters from the
4992e9e6481SDarrick J. Wong 	 * per-ag data. These may not be correct if the filesystem was not
5002e9e6481SDarrick J. Wong 	 * cleanly unmounted, so we waited for recovery to finish before doing
5012e9e6481SDarrick J. Wong 	 * this.
5022e9e6481SDarrick J. Wong 	 *
5032e9e6481SDarrick J. Wong 	 * If the filesystem was cleanly unmounted or the previous check did
5042e9e6481SDarrick J. Wong 	 * not flag anything weird, then we can trust the values in the
5052e9e6481SDarrick J. Wong 	 * superblock to be correct and we don't need to do anything here.
5062e9e6481SDarrick J. Wong 	 * Otherwise, recalculate the summary counters.
5072e9e6481SDarrick J. Wong 	 */
50838c26bfdSDave Chinner 	if ((!xfs_has_lazysbcount(mp) ||
5092e9e6481SDarrick J. Wong 	     XFS_LAST_UNMOUNT_WAS_CLEAN(mp)) &&
51039353ff6SDarrick J. Wong 	    !xfs_fs_has_sickness(mp, XFS_SICK_FS_COUNTERS))
5112e9e6481SDarrick J. Wong 		return 0;
5122e9e6481SDarrick J. Wong 
5132e9e6481SDarrick J. Wong 	return xfs_initialize_perag_data(mp, mp->m_sb.sb_agcount);
5142e9e6481SDarrick J. Wong }
5152e9e6481SDarrick J. Wong 
5167d095257SChristoph Hellwig /*
517d336f7ebSDarrick J. Wong  * Flush and reclaim dirty inodes in preparation for unmount. Inodes and
518d336f7ebSDarrick J. Wong  * internal inode structures can be sitting in the CIL and AIL at this point,
519d336f7ebSDarrick J. Wong  * so we need to unpin them, write them back and/or reclaim them before unmount
520ab23a776SDave Chinner  * can proceed.  In other words, callers are required to have inactivated all
521ab23a776SDave Chinner  * inodes.
522d336f7ebSDarrick J. Wong  *
523d336f7ebSDarrick J. Wong  * An inode cluster that has been freed can have its buffer still pinned in
524d336f7ebSDarrick J. Wong  * memory because the transaction is still sitting in a iclog. The stale inodes
525d336f7ebSDarrick J. Wong  * on that buffer will be pinned to the buffer until the transaction hits the
526d336f7ebSDarrick J. Wong  * disk and the callbacks run. Pushing the AIL will skip the stale inodes and
527d336f7ebSDarrick J. Wong  * may never see the pinned buffer, so nothing will push out the iclog and
528d336f7ebSDarrick J. Wong  * unpin the buffer.
529d336f7ebSDarrick J. Wong  *
530d336f7ebSDarrick J. Wong  * Hence we need to force the log to unpin everything first. However, log
531d336f7ebSDarrick J. Wong  * forces don't wait for the discards they issue to complete, so we have to
532d336f7ebSDarrick J. Wong  * explicitly wait for them to complete here as well.
533d336f7ebSDarrick J. Wong  *
534d336f7ebSDarrick J. Wong  * Then we can tell the world we are unmounting so that error handling knows
535d336f7ebSDarrick J. Wong  * that the filesystem is going away and we should error out anything that we
536d336f7ebSDarrick J. Wong  * have been retrying in the background.  This will prevent never-ending
537d336f7ebSDarrick J. Wong  * retries in AIL pushing from hanging the unmount.
538d336f7ebSDarrick J. Wong  *
539d336f7ebSDarrick J. Wong  * Finally, we can push the AIL to clean all the remaining dirty objects, then
540d336f7ebSDarrick J. Wong  * reclaim the remaining inodes that are still in memory at this point in time.
541d336f7ebSDarrick J. Wong  */
542d336f7ebSDarrick J. Wong static void
543d336f7ebSDarrick J. Wong xfs_unmount_flush_inodes(
544d336f7ebSDarrick J. Wong 	struct xfs_mount	*mp)
545d336f7ebSDarrick J. Wong {
546d336f7ebSDarrick J. Wong 	xfs_log_force(mp, XFS_LOG_SYNC);
547d336f7ebSDarrick J. Wong 	xfs_extent_busy_wait_all(mp);
548d336f7ebSDarrick J. Wong 	flush_workqueue(xfs_discard_wq);
549d336f7ebSDarrick J. Wong 
550d336f7ebSDarrick J. Wong 	mp->m_flags |= XFS_MOUNT_UNMOUNTING;
551d336f7ebSDarrick J. Wong 
552d336f7ebSDarrick J. Wong 	xfs_ail_push_all_sync(mp->m_ail);
553ab23a776SDave Chinner 	xfs_inodegc_stop(mp);
554d336f7ebSDarrick J. Wong 	cancel_delayed_work_sync(&mp->m_reclaim_work);
555d336f7ebSDarrick J. Wong 	xfs_reclaim_inodes(mp);
556d336f7ebSDarrick J. Wong 	xfs_health_unmount(mp);
557d336f7ebSDarrick J. Wong }
558d336f7ebSDarrick J. Wong 
559b2941046SDave Chinner static void
560b2941046SDave Chinner xfs_mount_setup_inode_geom(
561b2941046SDave Chinner 	struct xfs_mount	*mp)
562b2941046SDave Chinner {
563b2941046SDave Chinner 	struct xfs_ino_geometry *igeo = M_IGEO(mp);
564b2941046SDave Chinner 
565b2941046SDave Chinner 	igeo->attr_fork_offset = xfs_bmap_compute_attr_offset(mp);
566b2941046SDave Chinner 	ASSERT(igeo->attr_fork_offset < XFS_LITINO(mp));
567b2941046SDave Chinner 
568b2941046SDave Chinner 	xfs_ialloc_setup_geometry(mp);
569b2941046SDave Chinner }
570b2941046SDave Chinner 
571d336f7ebSDarrick J. Wong /*
5720771fb45SEric Sandeen  * This function does the following on an initial mount of a file system:
5730771fb45SEric Sandeen  *	- reads the superblock from disk and init the mount struct
5740771fb45SEric Sandeen  *	- if we're a 32-bit kernel, do a size check on the superblock
5750771fb45SEric Sandeen  *		so we don't mount terabyte filesystems
5760771fb45SEric Sandeen  *	- init mount struct realtime fields
5770771fb45SEric Sandeen  *	- allocate inode hash table for fs
5780771fb45SEric Sandeen  *	- init directory manager
5790771fb45SEric Sandeen  *	- perform recovery and init the log manager
5800771fb45SEric Sandeen  */
5810771fb45SEric Sandeen int
5820771fb45SEric Sandeen xfs_mountfs(
583f0b2efadSBrian Foster 	struct xfs_mount	*mp)
5840771fb45SEric Sandeen {
585f0b2efadSBrian Foster 	struct xfs_sb		*sbp = &(mp->m_sb);
586f0b2efadSBrian Foster 	struct xfs_inode	*rip;
587ef325959SDarrick J. Wong 	struct xfs_ino_geometry	*igeo = M_IGEO(mp);
588c8ce540dSDarrick J. Wong 	uint64_t		resblks;
5897d095257SChristoph Hellwig 	uint			quotamount = 0;
5907d095257SChristoph Hellwig 	uint			quotaflags = 0;
5910771fb45SEric Sandeen 	int			error = 0;
5920771fb45SEric Sandeen 
593ff55068cSDave Chinner 	xfs_sb_mount_common(mp, sbp);
5940771fb45SEric Sandeen 
5950771fb45SEric Sandeen 	/*
596074e427bSDave Chinner 	 * Check for a mismatched features2 values.  Older kernels read & wrote
597074e427bSDave Chinner 	 * into the wrong sb offset for sb_features2 on some platforms due to
598074e427bSDave Chinner 	 * xfs_sb_t not being 64bit size aligned when sb_features2 was added,
599074e427bSDave Chinner 	 * which made older superblock reading/writing routines swap it as a
600074e427bSDave Chinner 	 * 64-bit value.
601ee1c0908SDavid Chinner 	 *
602e6957ea4SEric Sandeen 	 * For backwards compatibility, we make both slots equal.
603e6957ea4SEric Sandeen 	 *
604074e427bSDave Chinner 	 * If we detect a mismatched field, we OR the set bits into the existing
605074e427bSDave Chinner 	 * features2 field in case it has already been modified; we don't want
606074e427bSDave Chinner 	 * to lose any features.  We then update the bad location with the ORed
607074e427bSDave Chinner 	 * value so that older kernels will see any features2 flags. The
608074e427bSDave Chinner 	 * superblock writeback code ensures the new sb_features2 is copied to
609074e427bSDave Chinner 	 * sb_bad_features2 before it is logged or written to disk.
610ee1c0908SDavid Chinner 	 */
611e6957ea4SEric Sandeen 	if (xfs_sb_has_mismatched_features2(sbp)) {
6120b932cccSDave Chinner 		xfs_warn(mp, "correcting sb_features alignment problem");
613ee1c0908SDavid Chinner 		sbp->sb_features2 |= sbp->sb_bad_features2;
61461e63ecbSDave Chinner 		mp->m_update_sb = true;
6157c12f296STim Shimmin 	}
616e6957ea4SEric Sandeen 
617ee1c0908SDavid Chinner 
618263997a6SDave Chinner 	/* always use v2 inodes by default now */
619263997a6SDave Chinner 	if (!(mp->m_sb.sb_versionnum & XFS_SB_VERSION_NLINKBIT)) {
620263997a6SDave Chinner 		mp->m_sb.sb_versionnum |= XFS_SB_VERSION_NLINKBIT;
62138c26bfdSDave Chinner 		mp->m_features |= XFS_FEAT_NLINK;
62261e63ecbSDave Chinner 		mp->m_update_sb = true;
623263997a6SDave Chinner 	}
624263997a6SDave Chinner 
625ee1c0908SDavid Chinner 	/*
6264f5b1b3aSDarrick J. Wong 	 * If we were given new sunit/swidth options, do some basic validation
6274f5b1b3aSDarrick J. Wong 	 * checks and convert the incore dalign and swidth values to the
6284f5b1b3aSDarrick J. Wong 	 * same units (FSB) that everything else uses.  This /must/ happen
6294f5b1b3aSDarrick J. Wong 	 * before computing the inode geometry.
6300771fb45SEric Sandeen 	 */
6314f5b1b3aSDarrick J. Wong 	error = xfs_validate_new_dalign(mp);
6320771fb45SEric Sandeen 	if (error)
633f9057e3dSChristoph Hellwig 		goto out;
6340771fb45SEric Sandeen 
6350771fb45SEric Sandeen 	xfs_alloc_compute_maxlevels(mp);
6360771fb45SEric Sandeen 	xfs_bmap_compute_maxlevels(mp, XFS_DATA_FORK);
6370771fb45SEric Sandeen 	xfs_bmap_compute_maxlevels(mp, XFS_ATTR_FORK);
638b2941046SDave Chinner 	xfs_mount_setup_inode_geom(mp);
639035e00acSDarrick J. Wong 	xfs_rmapbt_compute_maxlevels(mp);
6401946b91cSDarrick J. Wong 	xfs_refcountbt_compute_maxlevels(mp);
6410771fb45SEric Sandeen 
6424f5b1b3aSDarrick J. Wong 	/*
6434f5b1b3aSDarrick J. Wong 	 * Check if sb_agblocks is aligned at stripe boundary.  If sb_agblocks
6444f5b1b3aSDarrick J. Wong 	 * is NOT aligned turn off m_dalign since allocator alignment is within
6454f5b1b3aSDarrick J. Wong 	 * an ag, therefore ag has to be aligned at stripe boundary.  Note that
6464f5b1b3aSDarrick J. Wong 	 * we must compute the free space and rmap btree geometry before doing
6474f5b1b3aSDarrick J. Wong 	 * this.
6484f5b1b3aSDarrick J. Wong 	 */
6494f5b1b3aSDarrick J. Wong 	error = xfs_update_alignment(mp);
6504f5b1b3aSDarrick J. Wong 	if (error)
6514f5b1b3aSDarrick J. Wong 		goto out;
6524f5b1b3aSDarrick J. Wong 
653e6b3bb78SCarlos Maiolino 	/* enable fail_at_unmount as default */
654749f24f3SThomas Meyer 	mp->m_fail_unmount = true;
655e6b3bb78SCarlos Maiolino 
656e1d3d218SIan Kent 	error = xfs_sysfs_init(&mp->m_kobj, &xfs_mp_ktype,
657e1d3d218SIan Kent 			       NULL, mp->m_super->s_id);
65827174203SChristoph Hellwig 	if (error)
659f9057e3dSChristoph Hellwig 		goto out;
6601da177e4SLinus Torvalds 
661225e4635SBill O'Donnell 	error = xfs_sysfs_init(&mp->m_stats.xs_kobj, &xfs_stats_ktype,
662225e4635SBill O'Donnell 			       &mp->m_kobj, "stats");
663a31b1d3dSBrian Foster 	if (error)
664a31b1d3dSBrian Foster 		goto out_remove_sysfs;
665a31b1d3dSBrian Foster 
666192852beSCarlos Maiolino 	error = xfs_error_sysfs_init(mp);
667225e4635SBill O'Donnell 	if (error)
668225e4635SBill O'Donnell 		goto out_del_stats;
669225e4635SBill O'Donnell 
67031965ef3SDarrick J. Wong 	error = xfs_errortag_init(mp);
67131965ef3SDarrick J. Wong 	if (error)
67231965ef3SDarrick J. Wong 		goto out_remove_error_sysfs;
673192852beSCarlos Maiolino 
674192852beSCarlos Maiolino 	error = xfs_uuid_mount(mp);
675192852beSCarlos Maiolino 	if (error)
67631965ef3SDarrick J. Wong 		goto out_remove_errortag;
677192852beSCarlos Maiolino 
6781da177e4SLinus Torvalds 	/*
6792fcddee8SChristoph Hellwig 	 * Update the preferred write size based on the information from the
6802fcddee8SChristoph Hellwig 	 * on-disk superblock.
6810771fb45SEric Sandeen 	 */
6822fcddee8SChristoph Hellwig 	mp->m_allocsize_log =
6832fcddee8SChristoph Hellwig 		max_t(uint32_t, sbp->sb_blocklog, mp->m_allocsize_log);
6842fcddee8SChristoph Hellwig 	mp->m_allocsize_blocks = 1U << (mp->m_allocsize_log - sbp->sb_blocklog);
6850771fb45SEric Sandeen 
686055388a3SDave Chinner 	/* set the low space thresholds for dynamic preallocation */
687055388a3SDave Chinner 	xfs_set_low_space_thresholds(mp);
688055388a3SDave Chinner 
6890771fb45SEric Sandeen 	/*
690e5376fc1SBrian Foster 	 * If enabled, sparse inode chunk alignment is expected to match the
691e5376fc1SBrian Foster 	 * cluster size. Full inode chunk alignment must match the chunk size,
692e5376fc1SBrian Foster 	 * but that is checked on sb read verification...
693e5376fc1SBrian Foster 	 */
69438c26bfdSDave Chinner 	if (xfs_has_sparseinodes(mp) &&
695e5376fc1SBrian Foster 	    mp->m_sb.sb_spino_align !=
696490d451fSDarrick J. Wong 			XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw)) {
697e5376fc1SBrian Foster 		xfs_warn(mp,
698e5376fc1SBrian Foster 	"Sparse inode block alignment (%u) must match cluster size (%llu).",
699e5376fc1SBrian Foster 			 mp->m_sb.sb_spino_align,
700490d451fSDarrick J. Wong 			 XFS_B_TO_FSBT(mp, igeo->inode_cluster_size_raw));
701e5376fc1SBrian Foster 		error = -EINVAL;
702e5376fc1SBrian Foster 		goto out_remove_uuid;
703e5376fc1SBrian Foster 	}
704e5376fc1SBrian Foster 
705e5376fc1SBrian Foster 	/*
706c2bfbc9bSZhi Yong Wu 	 * Check that the data (and log if separate) is an ok size.
7070771fb45SEric Sandeen 	 */
7084249023aSChristoph Hellwig 	error = xfs_check_sizes(mp);
7090771fb45SEric Sandeen 	if (error)
710f9057e3dSChristoph Hellwig 		goto out_remove_uuid;
7110771fb45SEric Sandeen 
7120771fb45SEric Sandeen 	/*
7131da177e4SLinus Torvalds 	 * Initialize realtime fields in the mount structure
7141da177e4SLinus Torvalds 	 */
7150771fb45SEric Sandeen 	error = xfs_rtmount_init(mp);
7160771fb45SEric Sandeen 	if (error) {
7170b932cccSDave Chinner 		xfs_warn(mp, "RT mount failed");
718f9057e3dSChristoph Hellwig 		goto out_remove_uuid;
7191da177e4SLinus Torvalds 	}
7201da177e4SLinus Torvalds 
7211da177e4SLinus Torvalds 	/*
7221da177e4SLinus Torvalds 	 *  Copies the low order bits of the timestamp and the randomly
7231da177e4SLinus Torvalds 	 *  set "sequence" number out of a UUID.
7241da177e4SLinus Torvalds 	 */
725cb0ba6ccSChristoph Hellwig 	mp->m_fixedfsid[0] =
726cb0ba6ccSChristoph Hellwig 		(get_unaligned_be16(&sbp->sb_uuid.b[8]) << 16) |
727cb0ba6ccSChristoph Hellwig 		 get_unaligned_be16(&sbp->sb_uuid.b[4]);
728cb0ba6ccSChristoph Hellwig 	mp->m_fixedfsid[1] = get_unaligned_be32(&sbp->sb_uuid.b[0]);
7291da177e4SLinus Torvalds 
7300650b554SDave Chinner 	error = xfs_da_mount(mp);
7310650b554SDave Chinner 	if (error) {
7320650b554SDave Chinner 		xfs_warn(mp, "Failed dir/attr init: %d", error);
7330650b554SDave Chinner 		goto out_remove_uuid;
7340650b554SDave Chinner 	}
7351da177e4SLinus Torvalds 
7361da177e4SLinus Torvalds 	/*
7371da177e4SLinus Torvalds 	 * Initialize the precomputed transaction reservations values.
7381da177e4SLinus Torvalds 	 */
7391da177e4SLinus Torvalds 	xfs_trans_init(mp);
7401da177e4SLinus Torvalds 
7411da177e4SLinus Torvalds 	/*
7421da177e4SLinus Torvalds 	 * Allocate and initialize the per-ag data.
7431da177e4SLinus Torvalds 	 */
7441c1c6ebcSDave Chinner 	error = xfs_initialize_perag(mp, sbp->sb_agcount, &mp->m_maxagi);
7451c1c6ebcSDave Chinner 	if (error) {
7460b932cccSDave Chinner 		xfs_warn(mp, "Failed per-ag init: %d", error);
7470650b554SDave Chinner 		goto out_free_dir;
7481c1c6ebcSDave Chinner 	}
7491da177e4SLinus Torvalds 
750a71895c5SDarrick J. Wong 	if (XFS_IS_CORRUPT(mp, !sbp->sb_logblocks)) {
7510b932cccSDave Chinner 		xfs_warn(mp, "no log defined");
7522451337dSDave Chinner 		error = -EFSCORRUPTED;
753f9057e3dSChristoph Hellwig 		goto out_free_perag;
754f9057e3dSChristoph Hellwig 	}
755f9057e3dSChristoph Hellwig 
75640b1de00SDarrick J. Wong 	error = xfs_inodegc_register_shrinker(mp);
75740b1de00SDarrick J. Wong 	if (error)
75840b1de00SDarrick J. Wong 		goto out_fail_wait;
75940b1de00SDarrick J. Wong 
7601da177e4SLinus Torvalds 	/*
761f0b2efadSBrian Foster 	 * Log's mount-time initialization. The first part of recovery can place
762f0b2efadSBrian Foster 	 * some items on the AIL, to be handled when recovery is finished or
763f0b2efadSBrian Foster 	 * cancelled.
7641da177e4SLinus Torvalds 	 */
7651da177e4SLinus Torvalds 	error = xfs_log_mount(mp, mp->m_logdev_targp,
7661da177e4SLinus Torvalds 			      XFS_FSB_TO_DADDR(mp, sbp->sb_logstart),
7671da177e4SLinus Torvalds 			      XFS_FSB_TO_BB(mp, sbp->sb_logblocks));
7681da177e4SLinus Torvalds 	if (error) {
7690b932cccSDave Chinner 		xfs_warn(mp, "log mount failed");
77040b1de00SDarrick J. Wong 		goto out_inodegc_shrinker;
7711da177e4SLinus Torvalds 	}
7721da177e4SLinus Torvalds 
7732e9e6481SDarrick J. Wong 	/* Make sure the summary counts are ok. */
7742e9e6481SDarrick J. Wong 	error = xfs_check_summary_counts(mp);
775f9057e3dSChristoph Hellwig 	if (error)
7766eee8972Skbuild test robot 		goto out_log_dealloc;
777f9057e3dSChristoph Hellwig 
778ab23a776SDave Chinner 	/* Enable background inode inactivation workers. */
779ab23a776SDave Chinner 	xfs_inodegc_start(mp);
7806f649091SDarrick J. Wong 	xfs_blockgc_start(mp);
781ab23a776SDave Chinner 
78292821e2bSDavid Chinner 	/*
783e23b55d5SDave Chinner 	 * Now that we've recovered any pending superblock feature bit
784e23b55d5SDave Chinner 	 * additions, we can finish setting up the attr2 behaviour for the
785*0560f31aSDave Chinner 	 * mount. The noattr2 option overrides the superblock flag, so only
786*0560f31aSDave Chinner 	 * check the superblock feature flag if the mount option is not set.
787e23b55d5SDave Chinner 	 */
788*0560f31aSDave Chinner 	if (xfs_has_noattr2(mp)) {
789*0560f31aSDave Chinner 		mp->m_features &= ~XFS_FEAT_ATTR2;
790*0560f31aSDave Chinner 	} else if (!xfs_has_attr2(mp) &&
791*0560f31aSDave Chinner 		   (mp->m_sb.sb_features2 & XFS_SB_VERSION2_ATTR2BIT)) {
792*0560f31aSDave Chinner 		mp->m_features |= XFS_FEAT_ATTR2;
793*0560f31aSDave Chinner 	}
794e23b55d5SDave Chinner 
795e23b55d5SDave Chinner 	/*
7961da177e4SLinus Torvalds 	 * Get and sanity-check the root inode.
7971da177e4SLinus Torvalds 	 * Save the pointer to it in the mount structure.
7981da177e4SLinus Torvalds 	 */
799541b5accSDave Chinner 	error = xfs_iget(mp, NULL, sbp->sb_rootino, XFS_IGET_UNTRUSTED,
800541b5accSDave Chinner 			 XFS_ILOCK_EXCL, &rip);
8011da177e4SLinus Torvalds 	if (error) {
802541b5accSDave Chinner 		xfs_warn(mp,
803541b5accSDave Chinner 			"Failed to read root inode 0x%llx, error %d",
804541b5accSDave Chinner 			sbp->sb_rootino, -error);
805f9057e3dSChristoph Hellwig 		goto out_log_dealloc;
8061da177e4SLinus Torvalds 	}
8071da177e4SLinus Torvalds 
8081da177e4SLinus Torvalds 	ASSERT(rip != NULL);
8091da177e4SLinus Torvalds 
810a71895c5SDarrick J. Wong 	if (XFS_IS_CORRUPT(mp, !S_ISDIR(VFS_I(rip)->i_mode))) {
8110b932cccSDave Chinner 		xfs_warn(mp, "corrupted root inode %llu: not a directory",
812b6574520SNathan Scott 			(unsigned long long)rip->i_ino);
8131da177e4SLinus Torvalds 		xfs_iunlock(rip, XFS_ILOCK_EXCL);
8142451337dSDave Chinner 		error = -EFSCORRUPTED;
815f9057e3dSChristoph Hellwig 		goto out_rele_rip;
8161da177e4SLinus Torvalds 	}
8171da177e4SLinus Torvalds 	mp->m_rootip = rip;	/* save it */
8181da177e4SLinus Torvalds 
8191da177e4SLinus Torvalds 	xfs_iunlock(rip, XFS_ILOCK_EXCL);
8201da177e4SLinus Torvalds 
8211da177e4SLinus Torvalds 	/*
8221da177e4SLinus Torvalds 	 * Initialize realtime inode pointers in the mount structure
8231da177e4SLinus Torvalds 	 */
8240771fb45SEric Sandeen 	error = xfs_rtmount_inodes(mp);
8250771fb45SEric Sandeen 	if (error) {
8261da177e4SLinus Torvalds 		/*
8271da177e4SLinus Torvalds 		 * Free up the root inode.
8281da177e4SLinus Torvalds 		 */
8290b932cccSDave Chinner 		xfs_warn(mp, "failed to read RT inodes");
830f9057e3dSChristoph Hellwig 		goto out_rele_rip;
8311da177e4SLinus Torvalds 	}
8321da177e4SLinus Torvalds 
8331da177e4SLinus Torvalds 	/*
8347884bc86SChristoph Hellwig 	 * If this is a read-only mount defer the superblock updates until
8357884bc86SChristoph Hellwig 	 * the next remount into writeable mode.  Otherwise we would never
8367884bc86SChristoph Hellwig 	 * perform the update e.g. for the root filesystem.
8371da177e4SLinus Torvalds 	 */
83861e63ecbSDave Chinner 	if (mp->m_update_sb && !(mp->m_flags & XFS_MOUNT_RDONLY)) {
83961e63ecbSDave Chinner 		error = xfs_sync_sb(mp, false);
840e5720eecSDavid Chinner 		if (error) {
8410b932cccSDave Chinner 			xfs_warn(mp, "failed to write sb changes");
842b93b6e43SChristoph Hellwig 			goto out_rtunmount;
843e5720eecSDavid Chinner 		}
844e5720eecSDavid Chinner 	}
8451da177e4SLinus Torvalds 
8461da177e4SLinus Torvalds 	/*
8471da177e4SLinus Torvalds 	 * Initialise the XFS quota management subsystem for this mount
8481da177e4SLinus Torvalds 	 */
849149e53afSChristoph Hellwig 	if (XFS_IS_QUOTA_ON(mp)) {
8507d095257SChristoph Hellwig 		error = xfs_qm_newmount(mp, &quotamount, &quotaflags);
8510771fb45SEric Sandeen 		if (error)
852b93b6e43SChristoph Hellwig 			goto out_rtunmount;
8537d095257SChristoph Hellwig 	} else {
8547d095257SChristoph Hellwig 		/*
8557d095257SChristoph Hellwig 		 * If a file system had quotas running earlier, but decided to
8567d095257SChristoph Hellwig 		 * mount without -o uquota/pquota/gquota options, revoke the
8577d095257SChristoph Hellwig 		 * quotachecked license.
8587d095257SChristoph Hellwig 		 */
8597d095257SChristoph Hellwig 		if (mp->m_sb.sb_qflags & XFS_ALL_QUOTA_ACCT) {
8600b932cccSDave Chinner 			xfs_notice(mp, "resetting quota flags");
8617d095257SChristoph Hellwig 			error = xfs_mount_reset_sbqflags(mp);
8627d095257SChristoph Hellwig 			if (error)
863a70a4fa5SBrian Foster 				goto out_rtunmount;
8647d095257SChristoph Hellwig 		}
8657d095257SChristoph Hellwig 	}
8661da177e4SLinus Torvalds 
8671da177e4SLinus Torvalds 	/*
868f0b2efadSBrian Foster 	 * Finish recovering the file system.  This part needed to be delayed
869f0b2efadSBrian Foster 	 * until after the root and real-time bitmap inodes were consistently
87081ed9475SDarrick J. Wong 	 * read in.  Temporarily create per-AG space reservations for metadata
87181ed9475SDarrick J. Wong 	 * btree shape changes because space freeing transactions (for inode
87281ed9475SDarrick J. Wong 	 * inactivation) require the per-AG reservation in lieu of reserving
87381ed9475SDarrick J. Wong 	 * blocks.
8741da177e4SLinus Torvalds 	 */
87581ed9475SDarrick J. Wong 	error = xfs_fs_reserve_ag_blocks(mp);
87681ed9475SDarrick J. Wong 	if (error && error == -ENOSPC)
87781ed9475SDarrick J. Wong 		xfs_warn(mp,
87881ed9475SDarrick J. Wong 	"ENOSPC reserving per-AG metadata pool, log recovery may fail.");
8794249023aSChristoph Hellwig 	error = xfs_log_mount_finish(mp);
88081ed9475SDarrick J. Wong 	xfs_fs_unreserve_ag_blocks(mp);
8811da177e4SLinus Torvalds 	if (error) {
8820b932cccSDave Chinner 		xfs_warn(mp, "log mount finish failed");
883b93b6e43SChristoph Hellwig 		goto out_rtunmount;
8841da177e4SLinus Torvalds 	}
8851da177e4SLinus Torvalds 
8861da177e4SLinus Torvalds 	/*
887ddeb14f4SDave Chinner 	 * Now the log is fully replayed, we can transition to full read-only
888ddeb14f4SDave Chinner 	 * mode for read-only mounts. This will sync all the metadata and clean
889ddeb14f4SDave Chinner 	 * the log so that the recovery we just performed does not have to be
890ddeb14f4SDave Chinner 	 * replayed again on the next mount.
891ddeb14f4SDave Chinner 	 *
892ddeb14f4SDave Chinner 	 * We use the same quiesce mechanism as the rw->ro remount, as they are
893ddeb14f4SDave Chinner 	 * semantically identical operations.
894ddeb14f4SDave Chinner 	 */
895*0560f31aSDave Chinner 	if ((mp->m_flags & XFS_MOUNT_RDONLY) && !xfs_has_norecovery(mp))
896ea2064daSBrian Foster 		xfs_log_clean(mp);
897ddeb14f4SDave Chinner 
898ddeb14f4SDave Chinner 	/*
8991da177e4SLinus Torvalds 	 * Complete the quota initialisation, post-log-replay component.
9001da177e4SLinus Torvalds 	 */
9017d095257SChristoph Hellwig 	if (quotamount) {
9027d095257SChristoph Hellwig 		ASSERT(mp->m_qflags == 0);
9037d095257SChristoph Hellwig 		mp->m_qflags = quotaflags;
9047d095257SChristoph Hellwig 
9057d095257SChristoph Hellwig 		xfs_qm_mount_quotas(mp);
9067d095257SChristoph Hellwig 	}
9077d095257SChristoph Hellwig 
90884e1e99fSDavid Chinner 	/*
90984e1e99fSDavid Chinner 	 * Now we are mounted, reserve a small amount of unused space for
91084e1e99fSDavid Chinner 	 * privileged transactions. This is needed so that transaction
91184e1e99fSDavid Chinner 	 * space required for critical operations can dip into this pool
91284e1e99fSDavid Chinner 	 * when at ENOSPC. This is needed for operations like create with
91384e1e99fSDavid Chinner 	 * attr, unwritten extent conversion at ENOSPC, etc. Data allocations
91484e1e99fSDavid Chinner 	 * are not allowed to use this reserved space.
9158babd8a2SDave Chinner 	 *
9168babd8a2SDave Chinner 	 * This may drive us straight to ENOSPC on mount, but that implies
9178babd8a2SDave Chinner 	 * we were already there on the last unmount. Warn if this occurs.
91884e1e99fSDavid Chinner 	 */
919d5db0f97SEric Sandeen 	if (!(mp->m_flags & XFS_MOUNT_RDONLY)) {
920d5db0f97SEric Sandeen 		resblks = xfs_default_resblks(mp);
921714082bcSDavid Chinner 		error = xfs_reserve_blocks(mp, &resblks, NULL);
922714082bcSDavid Chinner 		if (error)
9230b932cccSDave Chinner 			xfs_warn(mp,
9240b932cccSDave Chinner 	"Unable to allocate reserve blocks. Continuing without reserve pool.");
925174edb0eSDarrick J. Wong 
926174edb0eSDarrick J. Wong 		/* Recover any CoW blocks that never got remapped. */
927174edb0eSDarrick J. Wong 		error = xfs_reflink_recover_cow(mp);
928174edb0eSDarrick J. Wong 		if (error) {
929174edb0eSDarrick J. Wong 			xfs_err(mp,
930174edb0eSDarrick J. Wong 	"Error %d recovering leftover CoW allocations.", error);
931174edb0eSDarrick J. Wong 			xfs_force_shutdown(mp, SHUTDOWN_CORRUPT_INCORE);
932174edb0eSDarrick J. Wong 			goto out_quota;
933174edb0eSDarrick J. Wong 		}
93484d69619SDarrick J. Wong 
93584d69619SDarrick J. Wong 		/* Reserve AG blocks for future btree expansion. */
93684d69619SDarrick J. Wong 		error = xfs_fs_reserve_ag_blocks(mp);
93784d69619SDarrick J. Wong 		if (error && error != -ENOSPC)
93884d69619SDarrick J. Wong 			goto out_agresv;
939d5db0f97SEric Sandeen 	}
94084e1e99fSDavid Chinner 
9411da177e4SLinus Torvalds 	return 0;
9421da177e4SLinus Torvalds 
94384d69619SDarrick J. Wong  out_agresv:
94484d69619SDarrick J. Wong 	xfs_fs_unreserve_ag_blocks(mp);
945174edb0eSDarrick J. Wong  out_quota:
946174edb0eSDarrick J. Wong 	xfs_qm_unmount_quotas(mp);
947b93b6e43SChristoph Hellwig  out_rtunmount:
948b93b6e43SChristoph Hellwig 	xfs_rtunmount_inodes(mp);
949f9057e3dSChristoph Hellwig  out_rele_rip:
95044a8736bSDarrick J. Wong 	xfs_irele(rip);
95177aff8c7SDarrick J. Wong 	/* Clean out dquots that might be in memory after quotacheck. */
95277aff8c7SDarrick J. Wong 	xfs_qm_unmount(mp);
953ab23a776SDave Chinner 
954ab23a776SDave Chinner 	/*
955ab23a776SDave Chinner 	 * Inactivate all inodes that might still be in memory after a log
956ab23a776SDave Chinner 	 * intent recovery failure so that reclaim can free them.  Metadata
957ab23a776SDave Chinner 	 * inodes and the root directory shouldn't need inactivation, but the
958ab23a776SDave Chinner 	 * mount failed for some reason, so pull down all the state and flee.
959ab23a776SDave Chinner 	 */
960ab23a776SDave Chinner 	xfs_inodegc_flush(mp);
961ab23a776SDave Chinner 
9622d1d1da3SDarrick J. Wong 	/*
963d336f7ebSDarrick J. Wong 	 * Flush all inode reclamation work and flush the log.
9642d1d1da3SDarrick J. Wong 	 * We have to do this /after/ rtunmount and qm_unmount because those
9652d1d1da3SDarrick J. Wong 	 * two will have scheduled delayed reclaim for the rt/quota inodes.
9662d1d1da3SDarrick J. Wong 	 *
9672d1d1da3SDarrick J. Wong 	 * This is slightly different from the unmountfs call sequence
9682d1d1da3SDarrick J. Wong 	 * because we could be tearing down a partially set up mount.  In
9692d1d1da3SDarrick J. Wong 	 * particular, if log_mount_finish fails we bail out without calling
9702d1d1da3SDarrick J. Wong 	 * qm_unmount_quotas and therefore rely on qm_unmount to release the
9712d1d1da3SDarrick J. Wong 	 * quota inodes.
9722d1d1da3SDarrick J. Wong 	 */
973d336f7ebSDarrick J. Wong 	xfs_unmount_flush_inodes(mp);
974f9057e3dSChristoph Hellwig  out_log_dealloc:
975f0b2efadSBrian Foster 	xfs_log_mount_cancel(mp);
97640b1de00SDarrick J. Wong  out_inodegc_shrinker:
97740b1de00SDarrick J. Wong 	unregister_shrinker(&mp->m_inodegc_shrinker);
978d4f3512bSDave Chinner  out_fail_wait:
979d4f3512bSDave Chinner 	if (mp->m_logdev_targp && mp->m_logdev_targp != mp->m_ddev_targp)
98010fb9ac1SBrian Foster 		xfs_buftarg_drain(mp->m_logdev_targp);
98110fb9ac1SBrian Foster 	xfs_buftarg_drain(mp->m_ddev_targp);
982f9057e3dSChristoph Hellwig  out_free_perag:
983ff4f038cSChristoph Hellwig 	xfs_free_perag(mp);
9840650b554SDave Chinner  out_free_dir:
9850650b554SDave Chinner 	xfs_da_unmount(mp);
986f9057e3dSChristoph Hellwig  out_remove_uuid:
98727174203SChristoph Hellwig 	xfs_uuid_unmount(mp);
98831965ef3SDarrick J. Wong  out_remove_errortag:
98931965ef3SDarrick J. Wong 	xfs_errortag_del(mp);
990192852beSCarlos Maiolino  out_remove_error_sysfs:
991192852beSCarlos Maiolino 	xfs_error_sysfs_del(mp);
992225e4635SBill O'Donnell  out_del_stats:
993225e4635SBill O'Donnell 	xfs_sysfs_del(&mp->m_stats.xs_kobj);
994a31b1d3dSBrian Foster  out_remove_sysfs:
995a31b1d3dSBrian Foster 	xfs_sysfs_del(&mp->m_kobj);
996f9057e3dSChristoph Hellwig  out:
9971da177e4SLinus Torvalds 	return error;
9981da177e4SLinus Torvalds }
9991da177e4SLinus Torvalds 
10001da177e4SLinus Torvalds /*
10011da177e4SLinus Torvalds  * This flushes out the inodes,dquots and the superblock, unmounts the
10021da177e4SLinus Torvalds  * log and makes sure that incore structures are freed.
10031da177e4SLinus Torvalds  */
100441b5c2e7SChristoph Hellwig void
100541b5c2e7SChristoph Hellwig xfs_unmountfs(
100641b5c2e7SChristoph Hellwig 	struct xfs_mount	*mp)
10071da177e4SLinus Torvalds {
1008c8ce540dSDarrick J. Wong 	uint64_t		resblks;
100941b5c2e7SChristoph Hellwig 	int			error;
10101da177e4SLinus Torvalds 
1011ab23a776SDave Chinner 	/*
1012ab23a776SDave Chinner 	 * Perform all on-disk metadata updates required to inactivate inodes
1013ab23a776SDave Chinner 	 * that the VFS evicted earlier in the unmount process.  Freeing inodes
1014ab23a776SDave Chinner 	 * and discarding CoW fork preallocations can cause shape changes to
1015ab23a776SDave Chinner 	 * the free inode and refcount btrees, respectively, so we must finish
1016ab23a776SDave Chinner 	 * this before we discard the metadata space reservations.  Metadata
1017ab23a776SDave Chinner 	 * inodes and the root directory do not require inactivation.
1018ab23a776SDave Chinner 	 */
1019ab23a776SDave Chinner 	xfs_inodegc_flush(mp);
1020ab23a776SDave Chinner 
1021c9a6526fSDarrick J. Wong 	xfs_blockgc_stop(mp);
102284d69619SDarrick J. Wong 	xfs_fs_unreserve_ag_blocks(mp);
10237d095257SChristoph Hellwig 	xfs_qm_unmount_quotas(mp);
1024b93b6e43SChristoph Hellwig 	xfs_rtunmount_inodes(mp);
102544a8736bSDarrick J. Wong 	xfs_irele(mp->m_rootip);
102677508ec8SChristoph Hellwig 
1027d336f7ebSDarrick J. Wong 	xfs_unmount_flush_inodes(mp);
10281da177e4SLinus Torvalds 
10297d095257SChristoph Hellwig 	xfs_qm_unmount(mp);
1030a357a121SLachlan McIlroy 
10311da177e4SLinus Torvalds 	/*
103284e1e99fSDavid Chinner 	 * Unreserve any blocks we have so that when we unmount we don't account
103384e1e99fSDavid Chinner 	 * the reserved free space as used. This is really only necessary for
103484e1e99fSDavid Chinner 	 * lazy superblock counting because it trusts the incore superblock
10359da096fdSMalcolm Parsons 	 * counters to be absolutely correct on clean unmount.
103684e1e99fSDavid Chinner 	 *
103784e1e99fSDavid Chinner 	 * We don't bother correcting this elsewhere for lazy superblock
103884e1e99fSDavid Chinner 	 * counting because on mount of an unclean filesystem we reconstruct the
103984e1e99fSDavid Chinner 	 * correct counter value and this is irrelevant.
104084e1e99fSDavid Chinner 	 *
104184e1e99fSDavid Chinner 	 * For non-lazy counter filesystems, this doesn't matter at all because
104284e1e99fSDavid Chinner 	 * we only every apply deltas to the superblock and hence the incore
104384e1e99fSDavid Chinner 	 * value does not matter....
104484e1e99fSDavid Chinner 	 */
104584e1e99fSDavid Chinner 	resblks = 0;
1046714082bcSDavid Chinner 	error = xfs_reserve_blocks(mp, &resblks, NULL);
1047714082bcSDavid Chinner 	if (error)
10480b932cccSDave Chinner 		xfs_warn(mp, "Unable to free reserved block pool. "
1049714082bcSDavid Chinner 				"Freespace may not be correct on next mount.");
1050714082bcSDavid Chinner 
105121b699c8SChristoph Hellwig 	xfs_log_unmount(mp);
10520650b554SDave Chinner 	xfs_da_unmount(mp);
105327174203SChristoph Hellwig 	xfs_uuid_unmount(mp);
10541da177e4SLinus Torvalds 
10551550d0b0SChristoph Hellwig #if defined(DEBUG)
105631965ef3SDarrick J. Wong 	xfs_errortag_clearall(mp);
10571da177e4SLinus Torvalds #endif
105840b1de00SDarrick J. Wong 	unregister_shrinker(&mp->m_inodegc_shrinker);
1059ff4f038cSChristoph Hellwig 	xfs_free_perag(mp);
1060a31b1d3dSBrian Foster 
106131965ef3SDarrick J. Wong 	xfs_errortag_del(mp);
1062192852beSCarlos Maiolino 	xfs_error_sysfs_del(mp);
1063225e4635SBill O'Donnell 	xfs_sysfs_del(&mp->m_stats.xs_kobj);
1064a31b1d3dSBrian Foster 	xfs_sysfs_del(&mp->m_kobj);
10651da177e4SLinus Torvalds }
10661da177e4SLinus Torvalds 
106791ee575fSBrian Foster /*
106891ee575fSBrian Foster  * Determine whether modifications can proceed. The caller specifies the minimum
106991ee575fSBrian Foster  * freeze level for which modifications should not be allowed. This allows
107091ee575fSBrian Foster  * certain operations to proceed while the freeze sequence is in progress, if
107191ee575fSBrian Foster  * necessary.
107291ee575fSBrian Foster  */
107391ee575fSBrian Foster bool
107491ee575fSBrian Foster xfs_fs_writable(
107591ee575fSBrian Foster 	struct xfs_mount	*mp,
107691ee575fSBrian Foster 	int			level)
107792821e2bSDavid Chinner {
107891ee575fSBrian Foster 	ASSERT(level > SB_UNFROZEN);
107991ee575fSBrian Foster 	if ((mp->m_super->s_writers.frozen >= level) ||
108091ee575fSBrian Foster 	    XFS_FORCED_SHUTDOWN(mp) || (mp->m_flags & XFS_MOUNT_RDONLY))
108191ee575fSBrian Foster 		return false;
108291ee575fSBrian Foster 
108391ee575fSBrian Foster 	return true;
108492821e2bSDavid Chinner }
108592821e2bSDavid Chinner 
10860d485adaSDave Chinner int
10870d485adaSDave Chinner xfs_mod_fdblocks(
10880d485adaSDave Chinner 	struct xfs_mount	*mp,
10890d485adaSDave Chinner 	int64_t			delta,
10900d485adaSDave Chinner 	bool			rsvd)
10910d485adaSDave Chinner {
10920d485adaSDave Chinner 	int64_t			lcounter;
10930d485adaSDave Chinner 	long long		res_used;
10940d485adaSDave Chinner 	s32			batch;
1095fd43cf60SBrian Foster 	uint64_t		set_aside;
10960d485adaSDave Chinner 
10970d485adaSDave Chinner 	if (delta > 0) {
10980d485adaSDave Chinner 		/*
10990d485adaSDave Chinner 		 * If the reserve pool is depleted, put blocks back into it
11000d485adaSDave Chinner 		 * first. Most of the time the pool is full.
11010d485adaSDave Chinner 		 */
11020d485adaSDave Chinner 		if (likely(mp->m_resblks == mp->m_resblks_avail)) {
11030d485adaSDave Chinner 			percpu_counter_add(&mp->m_fdblocks, delta);
11040d485adaSDave Chinner 			return 0;
11050d485adaSDave Chinner 		}
11060d485adaSDave Chinner 
11070d485adaSDave Chinner 		spin_lock(&mp->m_sb_lock);
11080d485adaSDave Chinner 		res_used = (long long)(mp->m_resblks - mp->m_resblks_avail);
11090d485adaSDave Chinner 
11100d485adaSDave Chinner 		if (res_used > delta) {
11110d485adaSDave Chinner 			mp->m_resblks_avail += delta;
11120d485adaSDave Chinner 		} else {
11130d485adaSDave Chinner 			delta -= res_used;
11140d485adaSDave Chinner 			mp->m_resblks_avail = mp->m_resblks;
11150d485adaSDave Chinner 			percpu_counter_add(&mp->m_fdblocks, delta);
11160d485adaSDave Chinner 		}
11170d485adaSDave Chinner 		spin_unlock(&mp->m_sb_lock);
11180d485adaSDave Chinner 		return 0;
11190d485adaSDave Chinner 	}
11200d485adaSDave Chinner 
11210d485adaSDave Chinner 	/*
11220d485adaSDave Chinner 	 * Taking blocks away, need to be more accurate the closer we
11230d485adaSDave Chinner 	 * are to zero.
11240d485adaSDave Chinner 	 *
11250d485adaSDave Chinner 	 * If the counter has a value of less than 2 * max batch size,
11260d485adaSDave Chinner 	 * then make everything serialise as we are real close to
11270d485adaSDave Chinner 	 * ENOSPC.
11280d485adaSDave Chinner 	 */
11298c1903d3SDave Chinner 	if (__percpu_counter_compare(&mp->m_fdblocks, 2 * XFS_FDBLOCKS_BATCH,
11308c1903d3SDave Chinner 				     XFS_FDBLOCKS_BATCH) < 0)
11310d485adaSDave Chinner 		batch = 1;
11320d485adaSDave Chinner 	else
11338c1903d3SDave Chinner 		batch = XFS_FDBLOCKS_BATCH;
11340d485adaSDave Chinner 
1135fd43cf60SBrian Foster 	/*
1136fd43cf60SBrian Foster 	 * Set aside allocbt blocks because these blocks are tracked as free
1137fd43cf60SBrian Foster 	 * space but not available for allocation. Technically this means that a
1138fd43cf60SBrian Foster 	 * single reservation cannot consume all remaining free space, but the
1139fd43cf60SBrian Foster 	 * ratio of allocbt blocks to usable free blocks should be rather small.
1140fd43cf60SBrian Foster 	 * The tradeoff without this is that filesystems that maintain high
1141fd43cf60SBrian Foster 	 * perag block reservations can over reserve physical block availability
1142fd43cf60SBrian Foster 	 * and fail physical allocation, which leads to much more serious
1143fd43cf60SBrian Foster 	 * problems (i.e. transaction abort, pagecache discards, etc.) than
1144fd43cf60SBrian Foster 	 * slightly premature -ENOSPC.
1145fd43cf60SBrian Foster 	 */
1146fd43cf60SBrian Foster 	set_aside = mp->m_alloc_set_aside + atomic64_read(&mp->m_allocbt_blks);
1147104b4e51SNikolay Borisov 	percpu_counter_add_batch(&mp->m_fdblocks, delta, batch);
1148fd43cf60SBrian Foster 	if (__percpu_counter_compare(&mp->m_fdblocks, set_aside,
11498c1903d3SDave Chinner 				     XFS_FDBLOCKS_BATCH) >= 0) {
11500d485adaSDave Chinner 		/* we had space! */
11510d485adaSDave Chinner 		return 0;
11520d485adaSDave Chinner 	}
11530d485adaSDave Chinner 
11540d485adaSDave Chinner 	/*
11550d485adaSDave Chinner 	 * lock up the sb for dipping into reserves before releasing the space
11560d485adaSDave Chinner 	 * that took us to ENOSPC.
11570d485adaSDave Chinner 	 */
11580d485adaSDave Chinner 	spin_lock(&mp->m_sb_lock);
11590d485adaSDave Chinner 	percpu_counter_add(&mp->m_fdblocks, -delta);
11600d485adaSDave Chinner 	if (!rsvd)
11610d485adaSDave Chinner 		goto fdblocks_enospc;
11620d485adaSDave Chinner 
11630d485adaSDave Chinner 	lcounter = (long long)mp->m_resblks_avail + delta;
11640d485adaSDave Chinner 	if (lcounter >= 0) {
11650d485adaSDave Chinner 		mp->m_resblks_avail = lcounter;
11660d485adaSDave Chinner 		spin_unlock(&mp->m_sb_lock);
11670d485adaSDave Chinner 		return 0;
11680d485adaSDave Chinner 	}
1169ec43f6daSEric Sandeen 	xfs_warn_once(mp,
1170ec43f6daSEric Sandeen "Reserve blocks depleted! Consider increasing reserve pool size.");
1171ec43f6daSEric Sandeen 
11720d485adaSDave Chinner fdblocks_enospc:
11730d485adaSDave Chinner 	spin_unlock(&mp->m_sb_lock);
11740d485adaSDave Chinner 	return -ENOSPC;
11750d485adaSDave Chinner }
11760d485adaSDave Chinner 
1177bab98bbeSDave Chinner int
1178bab98bbeSDave Chinner xfs_mod_frextents(
1179bab98bbeSDave Chinner 	struct xfs_mount	*mp,
1180bab98bbeSDave Chinner 	int64_t			delta)
1181bab98bbeSDave Chinner {
1182bab98bbeSDave Chinner 	int64_t			lcounter;
1183bab98bbeSDave Chinner 	int			ret = 0;
1184bab98bbeSDave Chinner 
1185bab98bbeSDave Chinner 	spin_lock(&mp->m_sb_lock);
1186bab98bbeSDave Chinner 	lcounter = mp->m_sb.sb_frextents + delta;
1187bab98bbeSDave Chinner 	if (lcounter < 0)
1188bab98bbeSDave Chinner 		ret = -ENOSPC;
1189bab98bbeSDave Chinner 	else
1190bab98bbeSDave Chinner 		mp->m_sb.sb_frextents = lcounter;
1191bab98bbeSDave Chinner 	spin_unlock(&mp->m_sb_lock);
1192bab98bbeSDave Chinner 	return ret;
1193bab98bbeSDave Chinner }
1194bab98bbeSDave Chinner 
11951da177e4SLinus Torvalds /*
11961da177e4SLinus Torvalds  * Used to free the superblock along various error paths.
11971da177e4SLinus Torvalds  */
11981da177e4SLinus Torvalds void
11991da177e4SLinus Torvalds xfs_freesb(
120026af6552SDave Chinner 	struct xfs_mount	*mp)
12011da177e4SLinus Torvalds {
120226af6552SDave Chinner 	struct xfs_buf		*bp = mp->m_sb_bp;
12031da177e4SLinus Torvalds 
120426af6552SDave Chinner 	xfs_buf_lock(bp);
12051da177e4SLinus Torvalds 	mp->m_sb_bp = NULL;
120626af6552SDave Chinner 	xfs_buf_relse(bp);
12071da177e4SLinus Torvalds }
12081da177e4SLinus Torvalds 
12091da177e4SLinus Torvalds /*
1210dda35b8fSChristoph Hellwig  * If the underlying (data/log/rt) device is readonly, there are some
1211dda35b8fSChristoph Hellwig  * operations that cannot proceed.
1212dda35b8fSChristoph Hellwig  */
1213dda35b8fSChristoph Hellwig int
1214dda35b8fSChristoph Hellwig xfs_dev_is_read_only(
1215dda35b8fSChristoph Hellwig 	struct xfs_mount	*mp,
1216dda35b8fSChristoph Hellwig 	char			*message)
1217dda35b8fSChristoph Hellwig {
1218dda35b8fSChristoph Hellwig 	if (xfs_readonly_buftarg(mp->m_ddev_targp) ||
1219dda35b8fSChristoph Hellwig 	    xfs_readonly_buftarg(mp->m_logdev_targp) ||
1220dda35b8fSChristoph Hellwig 	    (mp->m_rtdev_targp && xfs_readonly_buftarg(mp->m_rtdev_targp))) {
12210b932cccSDave Chinner 		xfs_notice(mp, "%s required on read-only device.", message);
12220b932cccSDave Chinner 		xfs_notice(mp, "write access unavailable, cannot proceed.");
12232451337dSDave Chinner 		return -EROFS;
1224dda35b8fSChristoph Hellwig 	}
1225dda35b8fSChristoph Hellwig 	return 0;
1226dda35b8fSChristoph Hellwig }
1227f467cad9SDarrick J. Wong 
1228f467cad9SDarrick J. Wong /* Force the summary counters to be recalculated at next mount. */
1229f467cad9SDarrick J. Wong void
1230f467cad9SDarrick J. Wong xfs_force_summary_recalc(
1231f467cad9SDarrick J. Wong 	struct xfs_mount	*mp)
1232f467cad9SDarrick J. Wong {
123338c26bfdSDave Chinner 	if (!xfs_has_lazysbcount(mp))
1234f467cad9SDarrick J. Wong 		return;
1235f467cad9SDarrick J. Wong 
123639353ff6SDarrick J. Wong 	xfs_fs_mark_sick(mp, XFS_SICK_FS_COUNTERS);
1237f467cad9SDarrick J. Wong }
12389fe82b8cSDarrick J. Wong 
12399fe82b8cSDarrick J. Wong /*
1240908ce71eSDarrick J. Wong  * Enable a log incompat feature flag in the primary superblock.  The caller
1241908ce71eSDarrick J. Wong  * cannot have any other transactions in progress.
1242908ce71eSDarrick J. Wong  */
1243908ce71eSDarrick J. Wong int
1244908ce71eSDarrick J. Wong xfs_add_incompat_log_feature(
1245908ce71eSDarrick J. Wong 	struct xfs_mount	*mp,
1246908ce71eSDarrick J. Wong 	uint32_t		feature)
1247908ce71eSDarrick J. Wong {
1248908ce71eSDarrick J. Wong 	struct xfs_dsb		*dsb;
1249908ce71eSDarrick J. Wong 	int			error;
1250908ce71eSDarrick J. Wong 
1251908ce71eSDarrick J. Wong 	ASSERT(hweight32(feature) == 1);
1252908ce71eSDarrick J. Wong 	ASSERT(!(feature & XFS_SB_FEAT_INCOMPAT_LOG_UNKNOWN));
1253908ce71eSDarrick J. Wong 
1254908ce71eSDarrick J. Wong 	/*
1255908ce71eSDarrick J. Wong 	 * Force the log to disk and kick the background AIL thread to reduce
1256908ce71eSDarrick J. Wong 	 * the chances that the bwrite will stall waiting for the AIL to unpin
1257908ce71eSDarrick J. Wong 	 * the primary superblock buffer.  This isn't a data integrity
1258908ce71eSDarrick J. Wong 	 * operation, so we don't need a synchronous push.
1259908ce71eSDarrick J. Wong 	 */
1260908ce71eSDarrick J. Wong 	error = xfs_log_force(mp, XFS_LOG_SYNC);
1261908ce71eSDarrick J. Wong 	if (error)
1262908ce71eSDarrick J. Wong 		return error;
1263908ce71eSDarrick J. Wong 	xfs_ail_push_all(mp->m_ail);
1264908ce71eSDarrick J. Wong 
1265908ce71eSDarrick J. Wong 	/*
1266908ce71eSDarrick J. Wong 	 * Lock the primary superblock buffer to serialize all callers that
1267908ce71eSDarrick J. Wong 	 * are trying to set feature bits.
1268908ce71eSDarrick J. Wong 	 */
1269908ce71eSDarrick J. Wong 	xfs_buf_lock(mp->m_sb_bp);
1270908ce71eSDarrick J. Wong 	xfs_buf_hold(mp->m_sb_bp);
1271908ce71eSDarrick J. Wong 
1272908ce71eSDarrick J. Wong 	if (XFS_FORCED_SHUTDOWN(mp)) {
1273908ce71eSDarrick J. Wong 		error = -EIO;
1274908ce71eSDarrick J. Wong 		goto rele;
1275908ce71eSDarrick J. Wong 	}
1276908ce71eSDarrick J. Wong 
1277908ce71eSDarrick J. Wong 	if (xfs_sb_has_incompat_log_feature(&mp->m_sb, feature))
1278908ce71eSDarrick J. Wong 		goto rele;
1279908ce71eSDarrick J. Wong 
1280908ce71eSDarrick J. Wong 	/*
1281908ce71eSDarrick J. Wong 	 * Write the primary superblock to disk immediately, because we need
1282908ce71eSDarrick J. Wong 	 * the log_incompat bit to be set in the primary super now to protect
1283908ce71eSDarrick J. Wong 	 * the log items that we're going to commit later.
1284908ce71eSDarrick J. Wong 	 */
1285908ce71eSDarrick J. Wong 	dsb = mp->m_sb_bp->b_addr;
1286908ce71eSDarrick J. Wong 	xfs_sb_to_disk(dsb, &mp->m_sb);
1287908ce71eSDarrick J. Wong 	dsb->sb_features_log_incompat |= cpu_to_be32(feature);
1288908ce71eSDarrick J. Wong 	error = xfs_bwrite(mp->m_sb_bp);
1289908ce71eSDarrick J. Wong 	if (error)
1290908ce71eSDarrick J. Wong 		goto shutdown;
1291908ce71eSDarrick J. Wong 
1292908ce71eSDarrick J. Wong 	/*
1293908ce71eSDarrick J. Wong 	 * Add the feature bits to the incore superblock before we unlock the
1294908ce71eSDarrick J. Wong 	 * buffer.
1295908ce71eSDarrick J. Wong 	 */
1296908ce71eSDarrick J. Wong 	xfs_sb_add_incompat_log_features(&mp->m_sb, feature);
1297908ce71eSDarrick J. Wong 	xfs_buf_relse(mp->m_sb_bp);
1298908ce71eSDarrick J. Wong 
1299908ce71eSDarrick J. Wong 	/* Log the superblock to disk. */
1300908ce71eSDarrick J. Wong 	return xfs_sync_sb(mp, false);
1301908ce71eSDarrick J. Wong shutdown:
1302908ce71eSDarrick J. Wong 	xfs_force_shutdown(mp, SHUTDOWN_META_IO_ERROR);
1303908ce71eSDarrick J. Wong rele:
1304908ce71eSDarrick J. Wong 	xfs_buf_relse(mp->m_sb_bp);
1305908ce71eSDarrick J. Wong 	return error;
1306908ce71eSDarrick J. Wong }
1307908ce71eSDarrick J. Wong 
1308908ce71eSDarrick J. Wong /*
1309908ce71eSDarrick J. Wong  * Clear all the log incompat flags from the superblock.
1310908ce71eSDarrick J. Wong  *
1311908ce71eSDarrick J. Wong  * The caller cannot be in a transaction, must ensure that the log does not
1312908ce71eSDarrick J. Wong  * contain any log items protected by any log incompat bit, and must ensure
1313908ce71eSDarrick J. Wong  * that there are no other threads that depend on the state of the log incompat
1314908ce71eSDarrick J. Wong  * feature flags in the primary super.
1315908ce71eSDarrick J. Wong  *
1316908ce71eSDarrick J. Wong  * Returns true if the superblock is dirty.
1317908ce71eSDarrick J. Wong  */
1318908ce71eSDarrick J. Wong bool
1319908ce71eSDarrick J. Wong xfs_clear_incompat_log_features(
1320908ce71eSDarrick J. Wong 	struct xfs_mount	*mp)
1321908ce71eSDarrick J. Wong {
1322908ce71eSDarrick J. Wong 	bool			ret = false;
1323908ce71eSDarrick J. Wong 
1324908ce71eSDarrick J. Wong 	if (!xfs_sb_version_hascrc(&mp->m_sb) ||
1325908ce71eSDarrick J. Wong 	    !xfs_sb_has_incompat_log_feature(&mp->m_sb,
1326908ce71eSDarrick J. Wong 				XFS_SB_FEAT_INCOMPAT_LOG_ALL) ||
1327908ce71eSDarrick J. Wong 	    XFS_FORCED_SHUTDOWN(mp))
1328908ce71eSDarrick J. Wong 		return false;
1329908ce71eSDarrick J. Wong 
1330908ce71eSDarrick J. Wong 	/*
1331908ce71eSDarrick J. Wong 	 * Update the incore superblock.  We synchronize on the primary super
1332908ce71eSDarrick J. Wong 	 * buffer lock to be consistent with the add function, though at least
1333908ce71eSDarrick J. Wong 	 * in theory this shouldn't be necessary.
1334908ce71eSDarrick J. Wong 	 */
1335908ce71eSDarrick J. Wong 	xfs_buf_lock(mp->m_sb_bp);
1336908ce71eSDarrick J. Wong 	xfs_buf_hold(mp->m_sb_bp);
1337908ce71eSDarrick J. Wong 
1338908ce71eSDarrick J. Wong 	if (xfs_sb_has_incompat_log_feature(&mp->m_sb,
1339908ce71eSDarrick J. Wong 				XFS_SB_FEAT_INCOMPAT_LOG_ALL)) {
1340908ce71eSDarrick J. Wong 		xfs_info(mp, "Clearing log incompat feature flags.");
1341908ce71eSDarrick J. Wong 		xfs_sb_remove_incompat_log_features(&mp->m_sb);
1342908ce71eSDarrick J. Wong 		ret = true;
1343908ce71eSDarrick J. Wong 	}
1344908ce71eSDarrick J. Wong 
1345908ce71eSDarrick J. Wong 	xfs_buf_relse(mp->m_sb_bp);
1346908ce71eSDarrick J. Wong 	return ret;
1347908ce71eSDarrick J. Wong }
1348908ce71eSDarrick J. Wong 
1349908ce71eSDarrick J. Wong /*
13509fe82b8cSDarrick J. Wong  * Update the in-core delayed block counter.
13519fe82b8cSDarrick J. Wong  *
13529fe82b8cSDarrick J. Wong  * We prefer to update the counter without having to take a spinlock for every
13539fe82b8cSDarrick J. Wong  * counter update (i.e. batching).  Each change to delayed allocation
13549fe82b8cSDarrick J. Wong  * reservations can change can easily exceed the default percpu counter
13559fe82b8cSDarrick J. Wong  * batching, so we use a larger batch factor here.
13569fe82b8cSDarrick J. Wong  *
13579fe82b8cSDarrick J. Wong  * Note that we don't currently have any callers requiring fast summation
13589fe82b8cSDarrick J. Wong  * (e.g. percpu_counter_read) so we can use a big batch value here.
13599fe82b8cSDarrick J. Wong  */
13609fe82b8cSDarrick J. Wong #define XFS_DELALLOC_BATCH	(4096)
13619fe82b8cSDarrick J. Wong void
13629fe82b8cSDarrick J. Wong xfs_mod_delalloc(
13639fe82b8cSDarrick J. Wong 	struct xfs_mount	*mp,
13649fe82b8cSDarrick J. Wong 	int64_t			delta)
13659fe82b8cSDarrick J. Wong {
13669fe82b8cSDarrick J. Wong 	percpu_counter_add_batch(&mp->m_delalloc_blks, delta,
13679fe82b8cSDarrick J. Wong 			XFS_DELALLOC_BATCH);
13689fe82b8cSDarrick J. Wong }
1369