Line data Source code
1 : // SPDX-License-Identifier: GPL-2.0-or-later
2 : /*
3 : * Copyright (C) 2020-2023 Oracle. All Rights Reserved.
4 : * Author: Darrick J. Wong <djwong@kernel.org>
5 : */
6 : #include "xfs.h"
7 : #include "xfs_fs.h"
8 : #include "xfs_shared.h"
9 : #include "xfs_format.h"
10 : #include "xfs_trans_resv.h"
11 : #include "xfs_mount.h"
12 : #include "xfs_defer.h"
13 : #include "xfs_bit.h"
14 : #include "xfs_log_format.h"
15 : #include "xfs_trans.h"
16 : #include "xfs_sb.h"
17 : #include "xfs_inode.h"
18 : #include "xfs_icache.h"
19 : #include "xfs_da_format.h"
20 : #include "xfs_da_btree.h"
21 : #include "xfs_dir2.h"
22 : #include "xfs_bmap_btree.h"
23 : #include "xfs_dir2_priv.h"
24 : #include "xfs_trans_space.h"
25 : #include "xfs_health.h"
26 : #include "xfs_swapext.h"
27 : #include "xfs_parent.h"
28 : #include "scrub/xfs_scrub.h"
29 : #include "scrub/scrub.h"
30 : #include "scrub/common.h"
31 : #include "scrub/trace.h"
32 : #include "scrub/repair.h"
33 : #include "scrub/iscan.h"
34 : #include "scrub/findparent.h"
35 : #include "scrub/readdir.h"
36 : #include "scrub/tempfile.h"
37 : #include "scrub/listxattr.h"
38 :
39 : /*
40 : * Finding the Parent of a Directory
41 : * =================================
42 : *
43 : * Directories have parent pointers, in the sense that each directory contains
44 : * a dotdot entry that points to the single allowed parent. The brute force
45 : * way to find the parent of a given directory is to scan every directory in
46 : * the filesystem looking for a child dirent that references this directory.
47 : *
48 : * This module wraps the process of scanning the directory tree. It requires
49 : * that @sc->ip is the directory whose parent we want to find, and that the
50 : * caller hold only the IOLOCK on that directory. The scan itself needs to
51 : * take the ILOCK of each directory visited.
52 : *
53 : * Because we cannot hold @sc->ip's ILOCK during a scan of the whole fs, it is
54 : * necessary to use dirent hooks to update the parent scan results. Callers
55 : * must not read the scan results without re-taking @sc->ip's ILOCK.
56 : *
57 : * There are a few shortcuts that we can take to avoid scanning the entire
58 : * filesystem, such as noticing directory tree roots and querying the dentry
59 : * cache for parent information.
60 : */
61 :
62 : struct xrep_findparent_info {
63 : /* The directory currently being scanned. */
64 : struct xfs_inode *dp;
65 :
66 : /*
67 : * Scrub context. We're looking for a @dp containing a directory
68 : * entry pointing to sc->ip->i_ino.
69 : */
70 : struct xfs_scrub *sc;
71 :
72 : /* Optional scan information for a xrep_findparent_scan call. */
73 : struct xrep_parent_scan_info *parent_scan;
74 :
75 : /*
76 : * Parent that we've found for sc->ip. If we're scanning the entire
77 : * directory tree, we need this to ensure that we only find /one/
78 : * parent directory.
79 : */
80 : xfs_ino_t found_parent;
81 :
82 : /*
83 : * This is set to true if @found_parent was not observed directly from
84 : * the directory scan but by noticing a change in dotdot entries after
85 : * cycling the sc->ip IOLOCK.
86 : */
87 : bool parent_tentative;
88 : };
89 :
90 : /*
91 : * If this directory entry points to the scrub target inode, then the directory
92 : * we're scanning is the parent of the scrub target inode.
93 : */
94 : STATIC int
95 2244553 : xrep_findparent_dirent(
96 : struct xfs_scrub *sc,
97 : struct xfs_inode *dp,
98 : xfs_dir2_dataptr_t dapos,
99 : const struct xfs_name *name,
100 : xfs_ino_t ino,
101 : void *priv)
102 : {
103 2244553 : struct xrep_findparent_info *fpi = priv;
104 2244553 : int error = 0;
105 :
106 2244553 : if (xchk_should_terminate(fpi->sc, &error))
107 0 : return error;
108 :
109 2244722 : if (ino != fpi->sc->ip->i_ino)
110 : return 0;
111 :
112 : /* Ignore garbage directory entry names. */
113 44667 : if (name->len == 0 || !xfs_dir2_namecheck(name->name, name->len))
114 0 : return -EFSCORRUPTED;
115 :
116 : /*
117 : * Ignore dotdot and dot entries -- we're looking for parent -> child
118 : * links only.
119 : */
120 44667 : if (name->name[0] == '.' && (name->len == 1 ||
121 573 : (name->len == 2 && name->name[1] == '.')))
122 : return 0;
123 :
124 : /* Uhoh, more than one parent for a dir? */
125 44094 : if (fpi->found_parent != NULLFSINO &&
126 0 : !(fpi->parent_tentative && fpi->found_parent == fpi->dp->i_ino)) {
127 0 : trace_xrep_findparent_dirent(fpi->sc->ip, 0);
128 0 : return -EFSCORRUPTED;
129 : }
130 :
131 : /* We found a potential parent; remember this. */
132 44094 : trace_xrep_findparent_dirent(fpi->sc->ip, fpi->dp->i_ino);
133 44092 : fpi->found_parent = fpi->dp->i_ino;
134 44092 : fpi->parent_tentative = false;
135 :
136 44092 : if (fpi->parent_scan)
137 575 : xrep_findparent_scan_found(fpi->parent_scan, fpi->dp->i_ino);
138 :
139 : return 0;
140 : }
141 :
142 : /*
143 : * If this is a directory, walk the dirents looking for any that point to the
144 : * scrub target inode.
145 : */
146 : STATIC int
147 303996 : xrep_findparent_walk_directory(
148 : struct xrep_findparent_info *fpi)
149 : {
150 303996 : struct xfs_scrub *sc = fpi->sc;
151 303996 : struct xfs_inode *dp = fpi->dp;
152 303996 : unsigned int lock_mode;
153 303996 : int error = 0;
154 :
155 : /*
156 : * The inode being scanned cannot be its own parent, nor can any
157 : * temporary directory we created to stage this repair.
158 : */
159 303996 : if (dp == sc->ip || dp == sc->tempip)
160 : return 0;
161 :
162 : /*
163 : * Similarly, temporary files created to stage a repair cannot be the
164 : * parent of this inode.
165 : */
166 303421 : if (xrep_is_tempfile(dp))
167 : return 0;
168 :
169 : /*
170 : * Scan the directory to see if there it contains an entry pointing to
171 : * the directory that we are repairing.
172 : */
173 303416 : lock_mode = xfs_ilock_data_map_shared(dp);
174 :
175 : /*
176 : * If this directory is known to be sick, we cannot scan it reliably
177 : * and must abort.
178 : */
179 303403 : if (xfs_inode_has_sickness(dp, XFS_SICK_INO_CORE |
180 : XFS_SICK_INO_BMBTD |
181 : XFS_SICK_INO_DIR)) {
182 0 : error = -EFSCORRUPTED;
183 0 : goto out_unlock;
184 : }
185 :
186 : /*
187 : * We cannot complete our parent pointer scan if a directory looks as
188 : * though it has been zapped by the inode record repair code.
189 : */
190 303417 : if (xchk_dir_looks_zapped(dp)) {
191 0 : error = -EFSCORRUPTED;
192 0 : goto out_unlock;
193 : }
194 :
195 303414 : error = xchk_dir_walk(sc, dp, xrep_findparent_dirent, fpi);
196 303418 : if (error)
197 0 : goto out_unlock;
198 :
199 303418 : out_unlock:
200 303418 : xfs_iunlock(dp, lock_mode);
201 303418 : return error;
202 : }
203 :
204 : /*
205 : * Update this directory's dotdot pointer based on ongoing dirent updates.
206 : */
207 : STATIC int
208 32269 : xrep_findparent_live_update(
209 : struct notifier_block *nb,
210 : unsigned long action,
211 : void *data)
212 : {
213 32269 : struct xfs_dir_update_params *p = data;
214 32269 : struct xrep_parent_scan_info *pscan;
215 32269 : struct xfs_scrub *sc;
216 :
217 32269 : pscan = container_of(nb, struct xrep_parent_scan_info,
218 : hooks.dirent_hook.nb);
219 32269 : sc = pscan->sc;
220 :
221 : /*
222 : * If @p->ip is the subdirectory that we're interested in and we've
223 : * already scanned @p->dp, update the dotdot target inumber to the
224 : * parent inode.
225 : */
226 32269 : if (p->ip->i_ino == sc->ip->i_ino &&
227 0 : xchk_iscan_want_live_update(&pscan->iscan, p->dp->i_ino)) {
228 0 : if (p->delta > 0) {
229 0 : xrep_findparent_scan_found(pscan, p->dp->i_ino);
230 : } else {
231 0 : xrep_findparent_scan_found(pscan, NULLFSINO);
232 : }
233 : }
234 :
235 32269 : return NOTIFY_DONE;
236 : }
237 :
238 : /*
239 : * Set up a scan to find the parent of a directory. The provided dirent hook
240 : * will be called when there is a dotdot update for the inode being repaired.
241 : */
242 : int
243 2382199 : __xrep_findparent_scan_start(
244 : struct xfs_scrub *sc,
245 : struct xrep_parent_scan_info *pscan,
246 : notifier_fn_t custom_fn)
247 : {
248 2382199 : int error;
249 :
250 2382199 : if (!(sc->flags & XCHK_FSGATES_DIRENTS)) {
251 0 : ASSERT(sc->flags & XCHK_FSGATES_DIRENTS);
252 0 : return -EINVAL;
253 : }
254 :
255 2382199 : pscan->sc = sc;
256 2382199 : pscan->parent_ino = NULLFSINO;
257 :
258 2382199 : mutex_init(&pscan->lock);
259 :
260 2382190 : xchk_iscan_start(sc, 30000, 100, &pscan->iscan);
261 :
262 : /*
263 : * Hook into the dirent update code. The hook only operates on inodes
264 : * that were already scanned, and the scanner thread takes each inode's
265 : * ILOCK, which means that any in-progress inode updates will finish
266 : * before we can scan the inode.
267 : */
268 2382192 : xfs_hook_setup(&pscan->hooks.dirent_hook,
269 : custom_fn ? custom_fn : xrep_findparent_live_update);
270 2382192 : error = xfs_dir_hook_add(sc->mp, &pscan->hooks);
271 2382208 : if (error)
272 0 : goto out_iscan;
273 :
274 : return 0;
275 : out_iscan:
276 0 : xchk_iscan_teardown(&pscan->iscan);
277 0 : mutex_destroy(&pscan->lock);
278 0 : return error;
279 : }
280 :
281 : /*
282 : * Scan the entire filesystem looking for a parent inode for the inode being
283 : * scrubbed. @sc->ip must not be the root of a directory tree. Callers must
284 : * not hold a dirty transaction or any lock that would interfere with taking
285 : * an ILOCK.
286 : *
287 : * Returns 0 with @pscan->parent_ino set to the parent that we found.
288 : * Returns 0 with @pscan->parent_ino set to NULLFSINO if we found no parents.
289 : * Returns the usual negative errno if something else happened.
290 : */
291 : int
292 575 : xrep_findparent_scan(
293 : struct xrep_parent_scan_info *pscan)
294 : {
295 575 : struct xrep_findparent_info fpi = {
296 575 : .sc = pscan->sc,
297 : .found_parent = NULLFSINO,
298 : .parent_scan = pscan,
299 : };
300 575 : struct xfs_scrub *sc = pscan->sc;
301 575 : int ret;
302 :
303 575 : ASSERT(S_ISDIR(VFS_IC(sc->ip)->i_mode));
304 :
305 1292934 : while ((ret = xchk_iscan_iter(&pscan->iscan, &fpi.dp)) == 1) {
306 1292512 : if (S_ISDIR(VFS_I(fpi.dp)->i_mode))
307 260479 : ret = xrep_findparent_walk_directory(&fpi);
308 : else
309 1032033 : ret = 0;
310 1292503 : xchk_iscan_mark_visited(&pscan->iscan, fpi.dp);
311 1292192 : xchk_irele(sc, fpi.dp);
312 1292539 : if (ret)
313 : break;
314 :
315 1292539 : if (xchk_should_terminate(sc, &ret))
316 : break;
317 : }
318 575 : xchk_iscan_iter_finish(&pscan->iscan);
319 :
320 575 : return ret;
321 : }
322 :
323 : /* Tear down a parent scan. */
324 : void
325 2380689 : xrep_findparent_scan_teardown(
326 : struct xrep_parent_scan_info *pscan)
327 : {
328 2380689 : xfs_dir_hook_del(pscan->sc->mp, &pscan->hooks);
329 2382208 : xchk_iscan_teardown(&pscan->iscan);
330 2381529 : mutex_destroy(&pscan->lock);
331 2381527 : }
332 :
333 : /* Finish a parent scan early. */
334 : void
335 43746 : xrep_findparent_scan_finish_early(
336 : struct xrep_parent_scan_info *pscan,
337 : xfs_ino_t ino)
338 : {
339 43746 : xrep_findparent_scan_found(pscan, ino);
340 43748 : xchk_iscan_finish_early(&pscan->iscan);
341 43747 : }
342 :
343 : /*
344 : * Confirm that the directory @parent_ino actually contains a directory entry
345 : * pointing to the child @sc->ip->ino. This function returns one of several
346 : * ways:
347 : *
348 : * Returns 0 with @parent_ino unchanged if the parent was confirmed.
349 : * Returns 0 with @parent_ino set to NULLFSINO if the parent was not valid.
350 : * Returns the usual negative errno if something else happened.
351 : */
352 : int
353 43517 : xrep_findparent_confirm(
354 : struct xfs_scrub *sc,
355 : xfs_ino_t *parent_ino)
356 : {
357 43517 : struct xrep_findparent_info fpi = {
358 : .sc = sc,
359 : .found_parent = NULLFSINO,
360 : };
361 43517 : int error;
362 :
363 : /*
364 : * The root directory always points to itself. Unlinked dirs can point
365 : * anywhere, so we point them at the root dir too.
366 : */
367 43517 : if (sc->ip == sc->mp->m_rootip || VFS_I(sc->ip)->i_nlink == 0) {
368 0 : *parent_ino = sc->mp->m_sb.sb_rootino;
369 0 : return 0;
370 : }
371 :
372 : /* Reject garbage parent inode numbers and self-referential parents. */
373 43517 : if (*parent_ino == NULLFSINO)
374 : return 0;
375 43517 : if (!xfs_verify_dir_ino(sc->mp, *parent_ino) ||
376 43519 : *parent_ino == sc->ip->i_ino) {
377 0 : *parent_ino = NULLFSINO;
378 0 : return 0;
379 : }
380 :
381 43519 : error = xchk_iget(sc, *parent_ino, &fpi.dp);
382 43519 : if (error)
383 : return error;
384 :
385 43519 : if (!S_ISDIR(VFS_I(fpi.dp)->i_mode)) {
386 0 : *parent_ino = NULLFSINO;
387 0 : goto out_rele;
388 : }
389 :
390 43519 : error = xrep_findparent_walk_directory(&fpi);
391 43519 : if (error)
392 0 : goto out_rele;
393 :
394 43519 : *parent_ino = fpi.found_parent;
395 43519 : out_rele:
396 43519 : xchk_irele(sc, fpi.dp);
397 43519 : return error;
398 : }
399 :
400 : /*
401 : * If we're the root of a directory tree, we are our own parent. If we're an
402 : * unlinked directory, the parent /won't/ have a link to us. Set the parent
403 : * directory to the root for both cases. Returns NULLFSINO if we don't know
404 : * what to do.
405 : */
406 : xfs_ino_t
407 44323 : xrep_findparent_self_reference(
408 : struct xfs_scrub *sc)
409 : {
410 44323 : if (sc->ip->i_ino == sc->mp->m_sb.sb_rootino)
411 : return sc->mp->m_sb.sb_rootino;
412 :
413 44094 : if (VFS_I(sc->ip)->i_nlink == 0)
414 0 : return sc->mp->m_sb.sb_rootino;
415 :
416 : return NULLFSINO;
417 : }
418 :
419 : /* Check the dentry cache to see if knows of a parent for the scrub target. */
420 : xfs_ino_t
421 44093 : xrep_findparent_from_dcache(
422 : struct xfs_scrub *sc)
423 : {
424 44093 : struct inode *pip = NULL;
425 44093 : struct dentry *dentry, *parent;
426 44093 : xfs_ino_t ret = NULLFSINO;
427 :
428 44093 : dentry = d_find_alias(VFS_I(sc->ip));
429 44094 : if (!dentry)
430 575 : goto out;
431 :
432 43519 : parent = dget_parent(dentry);
433 43519 : if (!parent)
434 0 : goto out_dput;
435 :
436 43519 : if (parent->d_sb != sc->ip->i_mount->m_super) {
437 0 : dput(parent);
438 0 : goto out_dput;
439 : }
440 :
441 43519 : pip = igrab(d_inode(parent));
442 43519 : dput(parent);
443 :
444 43519 : if (S_ISDIR(pip->i_mode)) {
445 43519 : trace_xrep_findparent_from_dcache(sc->ip, XFS_I(pip)->i_ino);
446 43517 : ret = XFS_I(pip)->i_ino;
447 : }
448 :
449 43517 : xchk_irele(sc, XFS_I(pip));
450 :
451 43519 : out_dput:
452 43519 : dput(dentry);
453 44093 : out:
454 44093 : return ret;
455 : }
456 :
457 : /* Pass back the parent inumber if this a parent pointer */
458 : STATIC int
459 2141030 : xrep_findparent_from_pptr(
460 : struct xfs_scrub *sc,
461 : struct xfs_inode *ip,
462 : const struct xfs_parent_name_irec *pptr,
463 : void *priv)
464 : {
465 2141030 : xfs_ino_t *inop = priv;
466 :
467 2141030 : *inop = pptr->p_ino;
468 2141030 : return -ECANCELED;
469 : }
470 :
471 : /*
472 : * Find the first parent of the inode being scrubbed by walking parent
473 : * pointers. Caller must hold sc->ip's ILOCK.
474 : */
475 : int
476 2142557 : xrep_findparent_from_pptrs(
477 : struct xfs_scrub *sc,
478 : xfs_ino_t *inop)
479 : {
480 2142557 : struct xfs_parent_name_irec pptr;
481 2142557 : int error;
482 :
483 2142557 : *inop = NULLFSINO;
484 :
485 2142557 : error = xchk_pptr_walk(sc, sc->ip, xrep_findparent_from_pptr, &pptr,
486 : inop);
487 2140101 : if (error && error != -ECANCELED)
488 0 : return error;
489 : return 0;
490 : }
|