2018-06-05 19:42:14 -07:00
|
|
|
// SPDX-License-Identifier: GPL-2.0
|
2005-04-16 15:20:36 -07:00
|
|
|
/*
|
2006-06-09 15:29:58 +10:00
|
|
|
* Copyright (c) 2000-2006 Silicon Graphics, Inc.
|
2005-11-02 14:59:41 +11:00
|
|
|
* All Rights Reserved.
|
2005-04-16 15:20:36 -07:00
|
|
|
*/
|
|
|
|
#include "xfs.h"
|
|
|
|
#include "xfs_fs.h"
|
2019-06-28 19:25:35 -07:00
|
|
|
#include "xfs_shared.h"
|
2013-08-12 20:49:26 +10:00
|
|
|
#include "xfs_format.h"
|
2013-10-23 10:50:10 +11:00
|
|
|
#include "xfs_log_format.h"
|
|
|
|
#include "xfs_trans_resv.h"
|
2024-02-22 12:30:55 -08:00
|
|
|
#include "xfs_mount.h"
|
2005-04-16 15:20:36 -07:00
|
|
|
#include "xfs_quota.h"
|
|
|
|
#include "xfs_inode.h"
|
2013-10-23 10:50:10 +11:00
|
|
|
#include "xfs_trans.h"
|
2005-04-16 15:20:36 -07:00
|
|
|
#include "xfs_qm.h"
|
|
|
|
|
|
|
|
|
2007-08-30 17:19:57 +10:00
|
|
|
STATIC void
|
|
|
|
xfs_fill_statvfs_from_dquot(
|
2008-11-28 14:23:36 +11:00
|
|
|
struct kstatfs *statp,
|
2024-11-03 20:19:40 -08:00
|
|
|
struct xfs_inode *ip,
|
2012-02-20 02:28:17 +00:00
|
|
|
struct xfs_dquot *dqp)
|
2006-06-09 15:29:58 +10:00
|
|
|
{
|
2024-11-03 20:19:40 -08:00
|
|
|
struct xfs_dquot_res *blkres = &dqp->q_blk;
|
2017-06-16 11:00:05 -07:00
|
|
|
uint64_t limit;
|
2006-06-09 15:29:58 +10:00
|
|
|
|
2024-11-03 20:19:40 -08:00
|
|
|
if (XFS_IS_REALTIME_MOUNT(ip->i_mount) &&
|
|
|
|
(ip->i_diflags & (XFS_DIFLAG_RTINHERIT | XFS_DIFLAG_REALTIME)))
|
|
|
|
blkres = &dqp->q_rtb;
|
|
|
|
|
|
|
|
limit = blkres->softlimit ?
|
|
|
|
blkres->softlimit :
|
|
|
|
blkres->hardlimit;
|
2024-12-12 14:37:56 -08:00
|
|
|
if (limit) {
|
|
|
|
uint64_t remaining = 0;
|
|
|
|
|
|
|
|
if (limit > blkres->reserved)
|
|
|
|
remaining = limit - blkres->reserved;
|
|
|
|
|
|
|
|
statp->f_blocks = min(statp->f_blocks, limit);
|
|
|
|
statp->f_bfree = min(statp->f_bfree, remaining);
|
2006-06-09 15:29:58 +10:00
|
|
|
}
|
2006-07-28 17:04:26 +10:00
|
|
|
|
2020-07-14 10:37:31 -07:00
|
|
|
limit = dqp->q_ino.softlimit ?
|
|
|
|
dqp->q_ino.softlimit :
|
|
|
|
dqp->q_ino.hardlimit;
|
2024-12-12 14:37:56 -08:00
|
|
|
if (limit) {
|
|
|
|
uint64_t remaining = 0;
|
|
|
|
|
|
|
|
if (limit > dqp->q_ino.reserved)
|
|
|
|
remaining = limit - dqp->q_ino.reserved;
|
|
|
|
|
|
|
|
statp->f_files = min(statp->f_files, limit);
|
|
|
|
statp->f_ffree = min(statp->f_ffree, remaining);
|
2006-06-09 15:29:58 +10:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2007-08-30 17:19:57 +10:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Directory tree accounting is implemented using project quotas, where
|
|
|
|
* the project identifier is inherited from parent directories.
|
|
|
|
* A statvfs (df, etc.) of a directory that is using project quota should
|
|
|
|
* return a statvfs of the project, not the entire filesystem.
|
|
|
|
* This makes such trees appear as if they are filesystems in themselves.
|
|
|
|
*/
|
2009-06-08 15:33:32 +02:00
|
|
|
void
|
2007-08-30 17:19:57 +10:00
|
|
|
xfs_qm_statvfs(
|
2019-11-12 17:04:02 -08:00
|
|
|
struct xfs_inode *ip,
|
2008-11-28 14:23:36 +11:00
|
|
|
struct kstatfs *statp)
|
2005-04-16 15:20:36 -07:00
|
|
|
{
|
2019-11-12 17:04:02 -08:00
|
|
|
struct xfs_mount *mp = ip->i_mount;
|
|
|
|
struct xfs_dquot *dqp;
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2021-03-29 11:11:39 -07:00
|
|
|
if (!xfs_qm_dqget(mp, ip->i_projid, XFS_DQTYPE_PROJ, false, &dqp)) {
|
2024-11-03 20:19:40 -08:00
|
|
|
xfs_fill_statvfs_from_dquot(statp, ip, dqp);
|
2007-08-30 17:19:57 +10:00
|
|
|
xfs_qm_dqput(dqp);
|
2005-04-16 15:20:36 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
xfs: Do not allow norecovery mount with quotacheck
Mounting a filesystem that requires quota state changing will generate a
transaction.
We already check for a read-only device; we should do that for
norecovery too.
A quotacheck on a norecovery mount, and with the right log size, will cause
the mount process to hang on:
[<0>] xlog_grant_head_wait+0x5d/0x2a0 [xfs]
[<0>] xlog_grant_head_check+0x112/0x180 [xfs]
[<0>] xfs_log_reserve+0xe3/0x260 [xfs]
[<0>] xfs_trans_reserve+0x179/0x250 [xfs]
[<0>] xfs_trans_alloc+0x101/0x260 [xfs]
[<0>] xfs_sync_sb+0x3f/0x80 [xfs]
[<0>] xfs_qm_mount_quotas+0xe3/0x2f0 [xfs]
[<0>] xfs_mountfs+0x7ad/0xc20 [xfs]
[<0>] xfs_fs_fill_super+0x762/0xa50 [xfs]
[<0>] get_tree_bdev_flags+0x131/0x1d0
[<0>] vfs_get_tree+0x26/0xd0
[<0>] vfs_cmd_create+0x59/0xe0
[<0>] __do_sys_fsconfig+0x4e3/0x6b0
[<0>] do_syscall_64+0x82/0x160
[<0>] entry_SYSCALL_64_after_hwframe+0x76/0x7e
This is caused by a transaction running with bogus initialized head/tail
I initially hit this while running generic/050, with random log
sizes, but I managed to reproduce it reliably here with the steps
below:
mkfs.xfs -f -lsize=1025M -f -b size=4096 -m crc=1,reflink=1,rmapbt=1, -i
sparse=1 /dev/vdb2 > /dev/null
mount -o usrquota,grpquota,prjquota /dev/vdb2 /mnt
xfs_io -x -c 'shutdown -f' /mnt
umount /mnt
mount -o ro,norecovery,usrquota,grpquota,prjquota /dev/vdb2 /mnt
Last mount hangs up
As we add yet another validation if quota state is changing, this also
add a new helper named xfs_qm_validate_state_change(), factoring the
quota state changes out of xfs_qm_newmount() to reduce cluttering
within it.
Signed-off-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
2025-02-03 14:04:57 +01:00
|
|
|
STATIC int
|
|
|
|
xfs_qm_validate_state_change(
|
|
|
|
struct xfs_mount *mp,
|
|
|
|
uint uqd,
|
|
|
|
uint gqd,
|
|
|
|
uint pqd)
|
|
|
|
{
|
|
|
|
int state;
|
|
|
|
|
|
|
|
/* Is quota state changing? */
|
|
|
|
state = ((uqd && !XFS_IS_UQUOTA_ON(mp)) ||
|
|
|
|
(!uqd && XFS_IS_UQUOTA_ON(mp)) ||
|
|
|
|
(gqd && !XFS_IS_GQUOTA_ON(mp)) ||
|
|
|
|
(!gqd && XFS_IS_GQUOTA_ON(mp)) ||
|
|
|
|
(pqd && !XFS_IS_PQUOTA_ON(mp)) ||
|
|
|
|
(!pqd && XFS_IS_PQUOTA_ON(mp)));
|
|
|
|
|
|
|
|
return state &&
|
|
|
|
(xfs_dev_is_read_only(mp, "changing quota state") ||
|
|
|
|
xfs_has_norecovery(mp));
|
|
|
|
}
|
|
|
|
|
2009-06-08 15:33:32 +02:00
|
|
|
int
|
2005-04-16 15:20:36 -07:00
|
|
|
xfs_qm_newmount(
|
|
|
|
xfs_mount_t *mp,
|
|
|
|
uint *needquotamount,
|
|
|
|
uint *quotaflags)
|
|
|
|
{
|
|
|
|
uint quotaondisk;
|
2005-06-21 15:38:48 +10:00
|
|
|
uint uquotaondisk = 0, gquotaondisk = 0, pquotaondisk = 0;
|
2005-04-16 15:20:36 -07:00
|
|
|
|
2021-08-18 18:46:37 -07:00
|
|
|
quotaondisk = xfs_has_quota(mp) &&
|
2005-06-21 15:38:48 +10:00
|
|
|
(mp->m_sb.sb_qflags & XFS_ALL_QUOTA_ACCT);
|
2005-04-16 15:20:36 -07:00
|
|
|
|
|
|
|
if (quotaondisk) {
|
|
|
|
uquotaondisk = mp->m_sb.sb_qflags & XFS_UQUOTA_ACCT;
|
2005-06-21 15:38:48 +10:00
|
|
|
pquotaondisk = mp->m_sb.sb_qflags & XFS_PQUOTA_ACCT;
|
2005-04-16 15:20:36 -07:00
|
|
|
gquotaondisk = mp->m_sb.sb_qflags & XFS_GQUOTA_ACCT;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
xfs: Do not allow norecovery mount with quotacheck
Mounting a filesystem that requires quota state changing will generate a
transaction.
We already check for a read-only device; we should do that for
norecovery too.
A quotacheck on a norecovery mount, and with the right log size, will cause
the mount process to hang on:
[<0>] xlog_grant_head_wait+0x5d/0x2a0 [xfs]
[<0>] xlog_grant_head_check+0x112/0x180 [xfs]
[<0>] xfs_log_reserve+0xe3/0x260 [xfs]
[<0>] xfs_trans_reserve+0x179/0x250 [xfs]
[<0>] xfs_trans_alloc+0x101/0x260 [xfs]
[<0>] xfs_sync_sb+0x3f/0x80 [xfs]
[<0>] xfs_qm_mount_quotas+0xe3/0x2f0 [xfs]
[<0>] xfs_mountfs+0x7ad/0xc20 [xfs]
[<0>] xfs_fs_fill_super+0x762/0xa50 [xfs]
[<0>] get_tree_bdev_flags+0x131/0x1d0
[<0>] vfs_get_tree+0x26/0xd0
[<0>] vfs_cmd_create+0x59/0xe0
[<0>] __do_sys_fsconfig+0x4e3/0x6b0
[<0>] do_syscall_64+0x82/0x160
[<0>] entry_SYSCALL_64_after_hwframe+0x76/0x7e
This is caused by a transaction running with bogus initialized head/tail
I initially hit this while running generic/050, with random log
sizes, but I managed to reproduce it reliably here with the steps
below:
mkfs.xfs -f -lsize=1025M -f -b size=4096 -m crc=1,reflink=1,rmapbt=1, -i
sparse=1 /dev/vdb2 > /dev/null
mount -o usrquota,grpquota,prjquota /dev/vdb2 /mnt
xfs_io -x -c 'shutdown -f' /mnt
umount /mnt
mount -o ro,norecovery,usrquota,grpquota,prjquota /dev/vdb2 /mnt
Last mount hangs up
As we add yet another validation if quota state is changing, this also
add a new helper named xfs_qm_validate_state_change(), factoring the
quota state changes out of xfs_qm_newmount() to reduce cluttering
within it.
Signed-off-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
2025-02-03 14:04:57 +01:00
|
|
|
* If the device itself is read-only and/or in norecovery
|
|
|
|
* mode, we can't allow the user to change the state of
|
|
|
|
* quota on the mount - this would generate a transaction
|
|
|
|
* on the ro device, which would lead to an I/O error and
|
|
|
|
* shutdown.
|
2005-04-16 15:20:36 -07:00
|
|
|
*/
|
|
|
|
|
xfs: Do not allow norecovery mount with quotacheck
Mounting a filesystem that requires quota state changing will generate a
transaction.
We already check for a read-only device; we should do that for
norecovery too.
A quotacheck on a norecovery mount, and with the right log size, will cause
the mount process to hang on:
[<0>] xlog_grant_head_wait+0x5d/0x2a0 [xfs]
[<0>] xlog_grant_head_check+0x112/0x180 [xfs]
[<0>] xfs_log_reserve+0xe3/0x260 [xfs]
[<0>] xfs_trans_reserve+0x179/0x250 [xfs]
[<0>] xfs_trans_alloc+0x101/0x260 [xfs]
[<0>] xfs_sync_sb+0x3f/0x80 [xfs]
[<0>] xfs_qm_mount_quotas+0xe3/0x2f0 [xfs]
[<0>] xfs_mountfs+0x7ad/0xc20 [xfs]
[<0>] xfs_fs_fill_super+0x762/0xa50 [xfs]
[<0>] get_tree_bdev_flags+0x131/0x1d0
[<0>] vfs_get_tree+0x26/0xd0
[<0>] vfs_cmd_create+0x59/0xe0
[<0>] __do_sys_fsconfig+0x4e3/0x6b0
[<0>] do_syscall_64+0x82/0x160
[<0>] entry_SYSCALL_64_after_hwframe+0x76/0x7e
This is caused by a transaction running with bogus initialized head/tail
I initially hit this while running generic/050, with random log
sizes, but I managed to reproduce it reliably here with the steps
below:
mkfs.xfs -f -lsize=1025M -f -b size=4096 -m crc=1,reflink=1,rmapbt=1, -i
sparse=1 /dev/vdb2 > /dev/null
mount -o usrquota,grpquota,prjquota /dev/vdb2 /mnt
xfs_io -x -c 'shutdown -f' /mnt
umount /mnt
mount -o ro,norecovery,usrquota,grpquota,prjquota /dev/vdb2 /mnt
Last mount hangs up
As we add yet another validation if quota state is changing, this also
add a new helper named xfs_qm_validate_state_change(), factoring the
quota state changes out of xfs_qm_newmount() to reduce cluttering
within it.
Signed-off-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
2025-02-03 14:04:57 +01:00
|
|
|
if (xfs_qm_validate_state_change(mp, uquotaondisk,
|
|
|
|
gquotaondisk, pquotaondisk)) {
|
|
|
|
|
|
|
|
if (xfs_has_metadir(mp))
|
|
|
|
xfs_warn(mp,
|
|
|
|
"metadir enabled, please mount without any quota mount options");
|
|
|
|
else
|
|
|
|
xfs_warn(mp, "please mount with%s%s%s%s.",
|
|
|
|
(!quotaondisk ? "out quota" : ""),
|
|
|
|
(uquotaondisk ? " usrquota" : ""),
|
|
|
|
(gquotaondisk ? " grpquota" : ""),
|
|
|
|
(pquotaondisk ? " prjquota" : ""));
|
2014-06-25 14:58:08 +10:00
|
|
|
return -EPERM;
|
2005-04-16 15:20:36 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
if (XFS_IS_QUOTA_ON(mp) || quotaondisk) {
|
|
|
|
/*
|
|
|
|
* Call mount_quotas at this point only if we won't have to do
|
|
|
|
* a quotacheck.
|
|
|
|
*/
|
|
|
|
if (quotaondisk && !XFS_QM_NEED_QUOTACHECK(mp)) {
|
|
|
|
/*
|
2011-03-30 22:57:33 -03:00
|
|
|
* If an error occurred, qm_mount_quotas code
|
2005-04-16 15:20:36 -07:00
|
|
|
* has already disabled quotas. So, just finish
|
|
|
|
* mounting, and get on with the boring life
|
|
|
|
* without disk quotas.
|
|
|
|
*/
|
2008-08-13 16:49:32 +10:00
|
|
|
xfs_qm_mount_quotas(mp);
|
2005-04-16 15:20:36 -07:00
|
|
|
} else {
|
|
|
|
/*
|
|
|
|
* Clear the quota flags, but remember them. This
|
|
|
|
* is so that the quota code doesn't get invoked
|
|
|
|
* before we're ready. This can happen when an
|
|
|
|
* inode goes inactive and wants to free blocks,
|
|
|
|
* or via xfs_log_mount_finish.
|
|
|
|
*/
|
2012-11-12 21:32:59 -02:00
|
|
|
*needquotamount = true;
|
2005-04-16 15:20:36 -07:00
|
|
|
*quotaflags = mp->m_qflags;
|
|
|
|
mp->m_qflags = 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
2024-11-03 20:19:39 -08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* If the sysadmin didn't provide any quota mount options, restore the quota
|
|
|
|
* accounting and enforcement state from the ondisk superblock. Only do this
|
|
|
|
* for metadir filesystems because this is a behavior change.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
xfs_qm_resume_quotaon(
|
|
|
|
struct xfs_mount *mp)
|
|
|
|
{
|
|
|
|
if (!xfs_has_metadir(mp))
|
|
|
|
return;
|
|
|
|
if (xfs_has_norecovery(mp))
|
|
|
|
return;
|
|
|
|
|
|
|
|
mp->m_qflags = mp->m_sb.sb_qflags & (XFS_ALL_QUOTA_ACCT |
|
|
|
|
XFS_ALL_QUOTA_ENFD);
|
|
|
|
}
|