All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Andrey Albershteyn via Linux-f2fs-devel"
	<linux-f2fs-devel@lists.sourceforge.net>
Cc: linux-ext4@vger.kernel.org, dsterba@suse.cz, tytso@mit.edu
Subject: Re: [f2fs-dev] [PATCH v17 15/21] xfs: add fs-verity support
Date: Sat, 03 Oct 2026 01:34:22 +0000	[thread overview]
Message-ID: <20261003013422.708321F00893@smtp.kernel.org> (raw)
In-Reply-To: <20261002223705.2175542-16-aalbersh@kernel.org>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] xfs: AB-BA lock inversion deadlock in xfs_fsverity_delete_metadata
- [High] xfs: inconsistent on-disk state after fs-verity enablement optimization failure
- [Medium] xfs: resource leak when fs-verity enablement is aborted
--

commit e2140f5468115bfa6cf4b74f36f51ee2780f1c23
Author: Andrey Albershteyn via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>

xfs: add fs-verity support

This commit adds integration with fs-verity for XFS. It introduces reading
and writing the Merkle tree through the iomap interface and stores the
verity descriptor in the inode data fork past EOF.

> diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c
> index 976e05257bf90..8cffcafc19aa0 100644
> --- a/fs/xfs/xfs_fsverity.c
> +++ b/fs/xfs/xfs_fsverity.c

[ ... ]

> +static int
> +xfs_fsverity_delete_metadata(
> +	struct xfs_inode	*ip)
> +{
> +	struct xfs_trans	*tp;
> +	struct xfs_mount	*mp = ip->i_mount;
> +	int			error;
> +
> +	xfs_ilock(ip, XFS_MMAPLOCK_EXCL);
> +	error = xfs_trans_alloc(mp, &M_RES(mp)->tr_itruncate, 0, 0, 0, &tp);
> +	if (error) {
> +		xfs_iunlock(ip, XFS_MMAPLOCK_EXCL);
> +		return error;
> +	}
> +
> +	truncate_inode_pages(VFS_I(ip)->i_mapping, XFS_ISIZE(ip));

[Severity: High]
Could this lock ordering lead to an AB-BA deadlock?

In XFS, folio locks must generally be acquired before transaction allocation
to prevent deadlocks with memory reclaim or writeback threads that may hold
the folio lock while waiting for transaction log space.

Here, xfs_trans_alloc() is called before truncate_inode_pages(), which
acquires the folio locks.

[ ... ]

> +static int
> +xfs_fsverity_end_enable(
> +	struct file		*file,
> +	const void		*desc,
> +	size_t			desc_size,
> +	u64			merkle_tree_size)
> +{
> +	struct inode		*inode = file_inode(file);
> +	struct xfs_inode	*ip = XFS_I(inode);
> +	struct xfs_mount	*mp = ip->i_mount;
> +	struct xfs_trans	*tp;
> +	int			error = 0;
> +	loff_t			range_start = xfs_fsverity_metadata_offset(ip);
> +
> +	xfs_assert_ilocked(ip, XFS_IOLOCK_EXCL);
> +
> +	/* fs-verity failed, just cleanup */
> +	if (desc == NULL)
> +		goto out;

[Severity: Medium]
Does this abort path leak blocks allocated for the Merkle tree past EOF?

When the core calls xfs_fsverity_end_enable() with desc == NULL to signal
an abort, this code jumps to the out label.

Because error is initialized to 0 and not updated here, the cleanup block
at the end of the function (which checks if error is non-zero) is skipped.

[ ... ]

> +	/*
> +	 * Ensure that we've persisted the verity information before we enable
> +	 * it on the inode and tell the caller we have sealed the inode.
> +	 */
> +	ip->i_diflags2 |= XFS_DIFLAG2_VERITY;
> +
> +	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
> +	xfs_trans_set_sync(tp);
> +
> +	error = xfs_trans_commit(tp);
> +	xfs_iunlock(ip, XFS_ILOCK_EXCL);
> +	if (error)
> +		goto out;
> +
> +	inode_set_flags(inode, S_VERITY, S_VERITY);
> +
> +	/*
> +	 * Proactively remove unwritten extents left by COW preallocations and
> +	 * write preallocation in the merkle tree holes and past descriptor,
> +	 * and any delayed preallocations
> +	 */
> +	error = xfs_free_eofblocks(ip);
> +out:
> +	if (error) {
> +		int	error2;
> +
> +		error2 = xfs_fsverity_reset_inode(ip);

[Severity: High]
Can this sequence result in an inconsistent on-disk state?

If xfs_free_eofblocks() fails, the XFS_DIFLAG2_VERITY flag has already
been committed to disk in the previous transaction. The code then calls
xfs_fsverity_reset_inode() to revert the enablement in a new transaction.

If a system crash occurs between the two transactions, or if allocating
the second transaction fails, the file could be left permanently sealed
on disk, but unsealed in memory.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002223705.2175542-1-aalbersh@kernel.org?part=15

WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot--- via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>
To: "Andrey Albershteyn via Linux-f2fs-devel"
	<linux-f2fs-devel@lists.sourceforge.net>
Cc: sashiko-bot@kernel.org, linux-ext4@vger.kernel.org,
	tytso@mit.edu, dsterba@suse.cz
Subject: Re: [f2fs-dev] [PATCH v17 15/21] xfs: add fs-verity support
Date: Sat, 03 Oct 2026 01:34:22 +0000	[thread overview]
Message-ID: <20261003013422.708321F00893@smtp.kernel.org> (raw)
In-Reply-To: <20261002223705.2175542-16-aalbersh@kernel.org>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] xfs: AB-BA lock inversion deadlock in xfs_fsverity_delete_metadata
- [High] xfs: inconsistent on-disk state after fs-verity enablement optimization failure
- [Medium] xfs: resource leak when fs-verity enablement is aborted
--

commit e2140f5468115bfa6cf4b74f36f51ee2780f1c23
Author: Andrey Albershteyn via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>

xfs: add fs-verity support

This commit adds integration with fs-verity for XFS. It introduces reading
and writing the Merkle tree through the iomap interface and stores the
verity descriptor in the inode data fork past EOF.

> diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c
> index 976e05257bf90..8cffcafc19aa0 100644
> --- a/fs/xfs/xfs_fsverity.c
> +++ b/fs/xfs/xfs_fsverity.c

[ ... ]

> +static int
> +xfs_fsverity_delete_metadata(
> +	struct xfs_inode	*ip)
> +{
> +	struct xfs_trans	*tp;
> +	struct xfs_mount	*mp = ip->i_mount;
> +	int			error;
> +
> +	xfs_ilock(ip, XFS_MMAPLOCK_EXCL);
> +	error = xfs_trans_alloc(mp, &M_RES(mp)->tr_itruncate, 0, 0, 0, &tp);
> +	if (error) {
> +		xfs_iunlock(ip, XFS_MMAPLOCK_EXCL);
> +		return error;
> +	}
> +
> +	truncate_inode_pages(VFS_I(ip)->i_mapping, XFS_ISIZE(ip));

[Severity: High]
Could this lock ordering lead to an AB-BA deadlock?

In XFS, folio locks must generally be acquired before transaction allocation
to prevent deadlocks with memory reclaim or writeback threads that may hold
the folio lock while waiting for transaction log space.

Here, xfs_trans_alloc() is called before truncate_inode_pages(), which
acquires the folio locks.

[ ... ]

> +static int
> +xfs_fsverity_end_enable(
> +	struct file		*file,
> +	const void		*desc,
> +	size_t			desc_size,
> +	u64			merkle_tree_size)
> +{
> +	struct inode		*inode = file_inode(file);
> +	struct xfs_inode	*ip = XFS_I(inode);
> +	struct xfs_mount	*mp = ip->i_mount;
> +	struct xfs_trans	*tp;
> +	int			error = 0;
> +	loff_t			range_start = xfs_fsverity_metadata_offset(ip);
> +
> +	xfs_assert_ilocked(ip, XFS_IOLOCK_EXCL);
> +
> +	/* fs-verity failed, just cleanup */
> +	if (desc == NULL)
> +		goto out;

[Severity: Medium]
Does this abort path leak blocks allocated for the Merkle tree past EOF?

When the core calls xfs_fsverity_end_enable() with desc == NULL to signal
an abort, this code jumps to the out label.

Because error is initialized to 0 and not updated here, the cleanup block
at the end of the function (which checks if error is non-zero) is skipped.

[ ... ]

> +	/*
> +	 * Ensure that we've persisted the verity information before we enable
> +	 * it on the inode and tell the caller we have sealed the inode.
> +	 */
> +	ip->i_diflags2 |= XFS_DIFLAG2_VERITY;
> +
> +	xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE);
> +	xfs_trans_set_sync(tp);
> +
> +	error = xfs_trans_commit(tp);
> +	xfs_iunlock(ip, XFS_ILOCK_EXCL);
> +	if (error)
> +		goto out;
> +
> +	inode_set_flags(inode, S_VERITY, S_VERITY);
> +
> +	/*
> +	 * Proactively remove unwritten extents left by COW preallocations and
> +	 * write preallocation in the merkle tree holes and past descriptor,
> +	 * and any delayed preallocations
> +	 */
> +	error = xfs_free_eofblocks(ip);
> +out:
> +	if (error) {
> +		int	error2;
> +
> +		error2 = xfs_fsverity_reset_inode(ip);

[Severity: High]
Can this sequence result in an inconsistent on-disk state?

If xfs_free_eofblocks() fails, the XFS_DIFLAG2_VERITY flag has already
been committed to disk in the previous transaction. The code then calls
xfs_fsverity_reset_inode() to revert the enablement in a new transaction.

If a system crash occurs between the two transactions, or if allocating
the second transaction fails, the file could be left permanently sealed
on disk, but unsealed in memory.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002223705.2175542-1-aalbersh@kernel.org?part=15


_______________________________________________
Linux-f2fs-devel mailing list
Linux-f2fs-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel

  reply	other threads:[~2026-10-03  1:34 UTC|newest]

Thread overview: 96+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 22:36 [PATCH v17 00/21] fs-verity support for XFS with post EOF merkle tree Andrey Albershteyn
2026-10-02 22:36 ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 01/21] fsverity: report validation errors through fserror to fsnotify Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 02/21] fsverity: expose ensure_fsverity_info() Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 03/21] fsverity: pass digest size and hash of the all-zeroes block to ->write Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 04/21] fsverity: hoist pagecache_read from f2fs/ext4 to fsverity Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 05/21] fsverity: don't allow setting DAX file attribute on fsverity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 06/21] fsverity: hoist statx reporting of fs-verity flag Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 07/21] xfs: introduce fsverity on-disk changes Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 08/21] xfs: don't allow to enable DAX on fs-verity sealed inode Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 09/21] xfs: disable direct read path for fs-verity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 10/21] xfs: don't report dio_mem_align and dio_offset_align for fsverity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 11/21] xfs: handle fsverity I/O in write/read path Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 12/21] xfs: use read ioend for fsverity data verification Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 13/21] xfs: add XFS_BMAPI_UNWRITTEN to unmap unwritten extents in __xfs_bunmapi() Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 14/21] xfs: don't remove written extents past EOF on fsverity inodes Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 15/21] xfs: add fs-verity support Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot [this message]
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-05 17:18   ` Andrey Albershteyn
2026-10-05 17:18     ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-05 21:12     ` Darrick J. Wong
2026-10-05 21:12       ` [f2fs-dev] " Darrick J. Wong via Linux-f2fs-devel
2026-10-06  9:03       ` Andrey Albershteyn
2026-10-06  9:03         ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 16/21] xfs: initialize fs-verity on file open Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 17/21] xfs: add fs-verity ioctls Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 18/21] xfs: advertise fs-verity being available on filesystem Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 19/21] xfs: check and repair the verity inode flag state Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 20/21] xfs: introduce health state for corrupted fsverity metadata Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 21/21] xfs: enable ro-compat fs-verity flag Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 23:25 ` [PATCH v17 00/21] fs-verity support for XFS with post EOF merkle tree Eric Biggers
2026-10-02 23:25   ` [f2fs-dev] " Eric Biggers via Linux-f2fs-devel
2026-10-03 12:07   ` Carlos Maiolino
2026-10-03 12:07     ` [f2fs-dev] " Carlos Maiolino via Linux-f2fs-devel
2026-10-05 11:26     ` Andrey Albershteyn
2026-10-05 11:26       ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-05 13:30       ` Eric Biggers
2026-10-05 13:30         ` [f2fs-dev] " Eric Biggers via Linux-f2fs-devel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003013422.708321F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dsterba@suse.cz \
    --cc=linux-ext4@vger.kernel.org \
    --cc=linux-f2fs-devel@lists.sourceforge.net \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tytso@mit.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.