Line data Source code
1 : // SPDX-License-Identifier: GPL-2.0-or-later
2 : /*
3 : * Copyright (C) 2020-2023 Oracle. All Rights Reserved.
4 : * Author: Darrick J. Wong <djwong@kernel.org>
5 : */
6 : #include "xfs.h"
7 : #include "xfs_fs.h"
8 : #include "xfs_shared.h"
9 : #include "xfs_format.h"
10 : #include "xfs_trans_resv.h"
11 : #include "xfs_mount.h"
12 : #include "xfs_defer.h"
13 : #include "xfs_bit.h"
14 : #include "xfs_log_format.h"
15 : #include "xfs_trans.h"
16 : #include "xfs_sb.h"
17 : #include "xfs_inode.h"
18 : #include "xfs_icache.h"
19 : #include "xfs_da_format.h"
20 : #include "xfs_da_btree.h"
21 : #include "xfs_dir2.h"
22 : #include "xfs_bmap_btree.h"
23 : #include "xfs_dir2_priv.h"
24 : #include "xfs_trans_space.h"
25 : #include "xfs_health.h"
26 : #include "xfs_swapext.h"
27 : #include "xfs_parent.h"
28 : #include "scrub/xfs_scrub.h"
29 : #include "scrub/scrub.h"
30 : #include "scrub/common.h"
31 : #include "scrub/trace.h"
32 : #include "scrub/repair.h"
33 : #include "scrub/iscan.h"
34 : #include "scrub/findparent.h"
35 : #include "scrub/readdir.h"
36 : #include "scrub/tempfile.h"
37 : #include "scrub/listxattr.h"
38 :
39 : /*
40 : * Finding the Parent of a Directory
41 : * =================================
42 : *
43 : * Directories have parent pointers, in the sense that each directory contains
44 : * a dotdot entry that points to the single allowed parent. The brute force
45 : * way to find the parent of a given directory is to scan every directory in
46 : * the filesystem looking for a child dirent that references this directory.
47 : *
48 : * This module wraps the process of scanning the directory tree. It requires
49 : * that @sc->ip is the directory whose parent we want to find, and that the
50 : * caller hold only the IOLOCK on that directory. The scan itself needs to
51 : * take the ILOCK of each directory visited.
52 : *
53 : * Because we cannot hold @sc->ip's ILOCK during a scan of the whole fs, it is
54 : * necessary to use dirent hooks to update the parent scan results. Callers
55 : * must not read the scan results without re-taking @sc->ip's ILOCK.
56 : *
57 : * There are a few shortcuts that we can take to avoid scanning the entire
58 : * filesystem, such as noticing directory tree roots and querying the dentry
59 : * cache for parent information.
60 : */
61 :
62 : struct xrep_findparent_info {
63 : /* The directory currently being scanned. */
64 : struct xfs_inode *dp;
65 :
66 : /*
67 : * Scrub context. We're looking for a @dp containing a directory
68 : * entry pointing to sc->ip->i_ino.
69 : */
70 : struct xfs_scrub *sc;
71 :
72 : /* Optional scan information for a xrep_findparent_scan call. */
73 : struct xrep_parent_scan_info *parent_scan;
74 :
75 : /*
76 : * Parent that we've found for sc->ip. If we're scanning the entire
77 : * directory tree, we need this to ensure that we only find /one/
78 : * parent directory.
79 : */
80 : xfs_ino_t found_parent;
81 :
82 : /*
83 : * This is set to true if @found_parent was not observed directly from
84 : * the directory scan but by noticing a change in dotdot entries after
85 : * cycling the sc->ip IOLOCK.
86 : */
87 : bool parent_tentative;
88 : };
89 :
90 : /*
91 : * If this directory entry points to the scrub target inode, then the directory
92 : * we're scanning is the parent of the scrub target inode.
93 : */
94 : STATIC int
95 0 : xrep_findparent_dirent(
96 : struct xfs_scrub *sc,
97 : struct xfs_inode *dp,
98 : xfs_dir2_dataptr_t dapos,
99 : const struct xfs_name *name,
100 : xfs_ino_t ino,
101 : void *priv)
102 : {
103 0 : struct xrep_findparent_info *fpi = priv;
104 0 : int error = 0;
105 :
106 0 : if (xchk_should_terminate(fpi->sc, &error))
107 0 : return error;
108 :
109 0 : if (ino != fpi->sc->ip->i_ino)
110 : return 0;
111 :
112 : /* Ignore garbage directory entry names. */
113 0 : if (name->len == 0 || !xfs_dir2_namecheck(name->name, name->len))
114 0 : return -EFSCORRUPTED;
115 :
116 : /*
117 : * Ignore dotdot and dot entries -- we're looking for parent -> child
118 : * links only.
119 : */
120 0 : if (name->name[0] == '.' && (name->len == 1 ||
121 0 : (name->len == 2 && name->name[1] == '.')))
122 : return 0;
123 :
124 : /* Uhoh, more than one parent for a dir? */
125 0 : if (fpi->found_parent != NULLFSINO &&
126 0 : !(fpi->parent_tentative && fpi->found_parent == fpi->dp->i_ino)) {
127 0 : trace_xrep_findparent_dirent(fpi->sc->ip, 0);
128 0 : return -EFSCORRUPTED;
129 : }
130 :
131 : /* We found a potential parent; remember this. */
132 0 : trace_xrep_findparent_dirent(fpi->sc->ip, fpi->dp->i_ino);
133 0 : fpi->found_parent = fpi->dp->i_ino;
134 0 : fpi->parent_tentative = false;
135 :
136 0 : if (fpi->parent_scan)
137 0 : xrep_findparent_scan_found(fpi->parent_scan, fpi->dp->i_ino);
138 :
139 : return 0;
140 : }
141 :
142 : /*
143 : * If this is a directory, walk the dirents looking for any that point to the
144 : * scrub target inode.
145 : */
146 : STATIC int
147 0 : xrep_findparent_walk_directory(
148 : struct xrep_findparent_info *fpi)
149 : {
150 0 : struct xfs_scrub *sc = fpi->sc;
151 0 : struct xfs_inode *dp = fpi->dp;
152 0 : unsigned int lock_mode;
153 0 : int error = 0;
154 :
155 : /*
156 : * The inode being scanned cannot be its own parent, nor can any
157 : * temporary directory we created to stage this repair.
158 : */
159 0 : if (dp == sc->ip || dp == sc->tempip)
160 : return 0;
161 :
162 : /*
163 : * Similarly, temporary files created to stage a repair cannot be the
164 : * parent of this inode.
165 : */
166 0 : if (xrep_is_tempfile(dp))
167 : return 0;
168 :
169 : /*
170 : * Scan the directory to see if there it contains an entry pointing to
171 : * the directory that we are repairing.
172 : */
173 0 : lock_mode = xfs_ilock_data_map_shared(dp);
174 :
175 : /*
176 : * If this directory is known to be sick, we cannot scan it reliably
177 : * and must abort.
178 : */
179 0 : if (xfs_inode_has_sickness(dp, XFS_SICK_INO_CORE |
180 : XFS_SICK_INO_BMBTD |
181 : XFS_SICK_INO_DIR)) {
182 0 : error = -EFSCORRUPTED;
183 0 : goto out_unlock;
184 : }
185 :
186 : /*
187 : * We cannot complete our parent pointer scan if a directory looks as
188 : * though it has been zapped by the inode record repair code.
189 : */
190 0 : if (xchk_dir_looks_zapped(dp)) {
191 0 : error = -EFSCORRUPTED;
192 0 : goto out_unlock;
193 : }
194 :
195 0 : error = xchk_dir_walk(sc, dp, xrep_findparent_dirent, fpi);
196 0 : if (error)
197 0 : goto out_unlock;
198 :
199 0 : out_unlock:
200 0 : xfs_iunlock(dp, lock_mode);
201 0 : return error;
202 : }
203 :
204 : /*
205 : * Update this directory's dotdot pointer based on ongoing dirent updates.
206 : */
207 : STATIC int
208 0 : xrep_findparent_live_update(
209 : struct notifier_block *nb,
210 : unsigned long action,
211 : void *data)
212 : {
213 0 : struct xfs_dir_update_params *p = data;
214 0 : struct xrep_parent_scan_info *pscan;
215 0 : struct xfs_scrub *sc;
216 :
217 0 : pscan = container_of(nb, struct xrep_parent_scan_info,
218 : hooks.dirent_hook.nb);
219 0 : sc = pscan->sc;
220 :
221 : /*
222 : * If @p->ip is the subdirectory that we're interested in and we've
223 : * already scanned @p->dp, update the dotdot target inumber to the
224 : * parent inode.
225 : */
226 0 : if (p->ip->i_ino == sc->ip->i_ino &&
227 0 : xchk_iscan_want_live_update(&pscan->iscan, p->dp->i_ino)) {
228 0 : if (p->delta > 0) {
229 0 : xrep_findparent_scan_found(pscan, p->dp->i_ino);
230 : } else {
231 0 : xrep_findparent_scan_found(pscan, NULLFSINO);
232 : }
233 : }
234 :
235 0 : return NOTIFY_DONE;
236 : }
237 :
238 : /*
239 : * Set up a scan to find the parent of a directory. The provided dirent hook
240 : * will be called when there is a dotdot update for the inode being repaired.
241 : */
242 : int
243 90443 : __xrep_findparent_scan_start(
244 : struct xfs_scrub *sc,
245 : struct xrep_parent_scan_info *pscan,
246 : notifier_fn_t custom_fn)
247 : {
248 90443 : int error;
249 :
250 90443 : if (!(sc->flags & XCHK_FSGATES_DIRENTS)) {
251 0 : ASSERT(sc->flags & XCHK_FSGATES_DIRENTS);
252 0 : return -EINVAL;
253 : }
254 :
255 90443 : pscan->sc = sc;
256 90443 : pscan->parent_ino = NULLFSINO;
257 :
258 90443 : mutex_init(&pscan->lock);
259 :
260 90443 : xchk_iscan_start(sc, 30000, 100, &pscan->iscan);
261 :
262 : /*
263 : * Hook into the dirent update code. The hook only operates on inodes
264 : * that were already scanned, and the scanner thread takes each inode's
265 : * ILOCK, which means that any in-progress inode updates will finish
266 : * before we can scan the inode.
267 : */
268 90442 : xfs_hook_setup(&pscan->hooks.dirent_hook,
269 : custom_fn ? custom_fn : xrep_findparent_live_update);
270 90442 : error = xfs_dir_hook_add(sc->mp, &pscan->hooks);
271 90443 : if (error)
272 0 : goto out_iscan;
273 :
274 : return 0;
275 : out_iscan:
276 0 : xchk_iscan_teardown(&pscan->iscan);
277 0 : mutex_destroy(&pscan->lock);
278 0 : return error;
279 : }
280 :
281 : /*
282 : * Scan the entire filesystem looking for a parent inode for the inode being
283 : * scrubbed. @sc->ip must not be the root of a directory tree. Callers must
284 : * not hold a dirty transaction or any lock that would interfere with taking
285 : * an ILOCK.
286 : *
287 : * Returns 0 with @pscan->parent_ino set to the parent that we found.
288 : * Returns 0 with @pscan->parent_ino set to NULLFSINO if we found no parents.
289 : * Returns the usual negative errno if something else happened.
290 : */
291 : int
292 0 : xrep_findparent_scan(
293 : struct xrep_parent_scan_info *pscan)
294 : {
295 0 : struct xrep_findparent_info fpi = {
296 0 : .sc = pscan->sc,
297 : .found_parent = NULLFSINO,
298 : .parent_scan = pscan,
299 : };
300 0 : struct xfs_scrub *sc = pscan->sc;
301 0 : int ret;
302 :
303 0 : ASSERT(S_ISDIR(VFS_IC(sc->ip)->i_mode));
304 :
305 0 : while ((ret = xchk_iscan_iter(&pscan->iscan, &fpi.dp)) == 1) {
306 0 : if (S_ISDIR(VFS_I(fpi.dp)->i_mode))
307 0 : ret = xrep_findparent_walk_directory(&fpi);
308 : else
309 0 : ret = 0;
310 0 : xchk_iscan_mark_visited(&pscan->iscan, fpi.dp);
311 0 : xchk_irele(sc, fpi.dp);
312 0 : if (ret)
313 : break;
314 :
315 0 : if (xchk_should_terminate(sc, &ret))
316 : break;
317 : }
318 0 : xchk_iscan_iter_finish(&pscan->iscan);
319 :
320 0 : return ret;
321 : }
322 :
323 : /* Tear down a parent scan. */
324 : void
325 90424 : xrep_findparent_scan_teardown(
326 : struct xrep_parent_scan_info *pscan)
327 : {
328 90424 : xfs_dir_hook_del(pscan->sc->mp, &pscan->hooks);
329 90443 : xchk_iscan_teardown(&pscan->iscan);
330 90441 : mutex_destroy(&pscan->lock);
331 90433 : }
332 :
333 : /* Finish a parent scan early. */
334 : void
335 0 : xrep_findparent_scan_finish_early(
336 : struct xrep_parent_scan_info *pscan,
337 : xfs_ino_t ino)
338 : {
339 0 : xrep_findparent_scan_found(pscan, ino);
340 0 : xchk_iscan_finish_early(&pscan->iscan);
341 0 : }
342 :
343 : /*
344 : * Confirm that the directory @parent_ino actually contains a directory entry
345 : * pointing to the child @sc->ip->ino. This function returns one of several
346 : * ways:
347 : *
348 : * Returns 0 with @parent_ino unchanged if the parent was confirmed.
349 : * Returns 0 with @parent_ino set to NULLFSINO if the parent was not valid.
350 : * Returns the usual negative errno if something else happened.
351 : */
352 : int
353 0 : xrep_findparent_confirm(
354 : struct xfs_scrub *sc,
355 : xfs_ino_t *parent_ino)
356 : {
357 0 : struct xrep_findparent_info fpi = {
358 : .sc = sc,
359 : .found_parent = NULLFSINO,
360 : };
361 0 : int error;
362 :
363 : /*
364 : * The root directory always points to itself. Unlinked dirs can point
365 : * anywhere, so we point them at the root dir too.
366 : */
367 0 : if (sc->ip == sc->mp->m_rootip || VFS_I(sc->ip)->i_nlink == 0) {
368 0 : *parent_ino = sc->mp->m_sb.sb_rootino;
369 0 : return 0;
370 : }
371 :
372 : /* Reject garbage parent inode numbers and self-referential parents. */
373 0 : if (*parent_ino == NULLFSINO)
374 : return 0;
375 0 : if (!xfs_verify_dir_ino(sc->mp, *parent_ino) ||
376 0 : *parent_ino == sc->ip->i_ino) {
377 0 : *parent_ino = NULLFSINO;
378 0 : return 0;
379 : }
380 :
381 0 : error = xchk_iget(sc, *parent_ino, &fpi.dp);
382 0 : if (error)
383 : return error;
384 :
385 0 : if (!S_ISDIR(VFS_I(fpi.dp)->i_mode)) {
386 0 : *parent_ino = NULLFSINO;
387 0 : goto out_rele;
388 : }
389 :
390 0 : error = xrep_findparent_walk_directory(&fpi);
391 0 : if (error)
392 0 : goto out_rele;
393 :
394 0 : *parent_ino = fpi.found_parent;
395 0 : out_rele:
396 0 : xchk_irele(sc, fpi.dp);
397 0 : return error;
398 : }
399 :
400 : /*
401 : * If we're the root of a directory tree, we are our own parent. If we're an
402 : * unlinked directory, the parent /won't/ have a link to us. Set the parent
403 : * directory to the root for both cases. Returns NULLFSINO if we don't know
404 : * what to do.
405 : */
406 : xfs_ino_t
407 0 : xrep_findparent_self_reference(
408 : struct xfs_scrub *sc)
409 : {
410 0 : if (sc->ip->i_ino == sc->mp->m_sb.sb_rootino)
411 : return sc->mp->m_sb.sb_rootino;
412 :
413 0 : if (VFS_I(sc->ip)->i_nlink == 0)
414 0 : return sc->mp->m_sb.sb_rootino;
415 :
416 : return NULLFSINO;
417 : }
418 :
419 : /* Check the dentry cache to see if knows of a parent for the scrub target. */
420 : xfs_ino_t
421 0 : xrep_findparent_from_dcache(
422 : struct xfs_scrub *sc)
423 : {
424 0 : struct inode *pip = NULL;
425 0 : struct dentry *dentry, *parent;
426 0 : xfs_ino_t ret = NULLFSINO;
427 :
428 0 : dentry = d_find_alias(VFS_I(sc->ip));
429 0 : if (!dentry)
430 0 : goto out;
431 :
432 0 : parent = dget_parent(dentry);
433 0 : if (!parent)
434 0 : goto out_dput;
435 :
436 0 : if (parent->d_sb != sc->ip->i_mount->m_super) {
437 0 : dput(parent);
438 0 : goto out_dput;
439 : }
440 :
441 0 : pip = igrab(d_inode(parent));
442 0 : dput(parent);
443 :
444 0 : if (S_ISDIR(pip->i_mode)) {
445 0 : trace_xrep_findparent_from_dcache(sc->ip, XFS_I(pip)->i_ino);
446 0 : ret = XFS_I(pip)->i_ino;
447 : }
448 :
449 0 : xchk_irele(sc, XFS_I(pip));
450 :
451 0 : out_dput:
452 0 : dput(dentry);
453 0 : out:
454 0 : return ret;
455 : }
456 :
457 : /* Pass back the parent inumber if this a parent pointer */
458 : STATIC int
459 76704 : xrep_findparent_from_pptr(
460 : struct xfs_scrub *sc,
461 : struct xfs_inode *ip,
462 : const struct xfs_parent_name_irec *pptr,
463 : void *priv)
464 : {
465 76704 : xfs_ino_t *inop = priv;
466 :
467 76704 : *inop = pptr->p_ino;
468 76704 : return -ECANCELED;
469 : }
470 :
471 : /*
472 : * Find the first parent of the inode being scrubbed by walking parent
473 : * pointers. Caller must hold sc->ip's ILOCK.
474 : */
475 : int
476 76698 : xrep_findparent_from_pptrs(
477 : struct xfs_scrub *sc,
478 : xfs_ino_t *inop)
479 : {
480 76698 : struct xfs_parent_name_irec pptr;
481 76698 : int error;
482 :
483 76698 : *inop = NULLFSINO;
484 :
485 76698 : error = xchk_pptr_walk(sc, sc->ip, xrep_findparent_from_pptr, &pptr,
486 : inop);
487 76689 : if (error && error != -ECANCELED)
488 0 : return error;
489 : return 0;
490 : }
|