* [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback
@ 2026-09-15 5:38 Daniel Linjama
2026-09-15 5:38 ` [PATCH 2/2] btrfs: test ENOSPC " Daniel Linjama
2026-09-15 5:50 ` [PATCH 1/2] btrfs: test qgroup limit " Qu Wenruo
0 siblings, 2 replies; 5+ messages in thread
From: Daniel Linjama @ 2026-09-15 5:38 UTC (permalink / raw)
To: fstests; +Cc: linux-btrfs, Qu Wenruo, Daniel Linjama
Test that the subvolume and the filesystem stay writable when an fsverity
enable and its rollback hit the qgroup limit, and that the subvolume is
still reachable after a remount with no verity or orphan items left behind.
This exercises a bug fixed by the kernel patch with subject:
"btrfs: handle lack of space when cleaning up verity items"
Assisted-by: LLM
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
---
tests/btrfs/354 | 131 ++++++++++++++++++++++++++++++++++++++++++++
tests/btrfs/354.out | 2 +
2 files changed, 133 insertions(+)
create mode 100755 tests/btrfs/354
create mode 100644 tests/btrfs/354.out
diff --git a/tests/btrfs/354 b/tests/btrfs/354
new file mode 100755
index 0000000..e3f6716
--- /dev/null
+++ b/tests/btrfs/354
@@ -0,0 +1,131 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 Daniel Linjama. All Rights Reserved.
+#
+# FS QA Test 354
+#
+# Test that a failed fsverity enable in a subvolume whose qgroup is at its
+# limit leaves the filesystem usable.
+#
+. ./common/preamble
+_begin_fstest auto quick qgroup limit verity
+
+# Override the default cleanup function.
+_cleanup()
+{
+ cd /
+ _restore_fsverity_signatures
+ rm -f $tmp.*
+}
+
+# Import common functions.
+. ./common/filter
+. ./common/verity
+
+# real QA test starts here
+
+_require_scratch_verity
+_require_btrfs_command inspect-internal dump-tree
+_require_btrfs_command quota
+_require_no_compress
+_require_scratch_size $((2 * 1024 * 1024))
+_disable_fsverity_signatures
+
+_fixed_by_kernel_commit xxxxxxxxxxxx \
+ "btrfs: handle lack of space when cleaning up verity items"
+
+subv=$SCRATCH_MNT/sub
+target=$subv/target
+
+prepare()
+{
+ _scratch_mkfs_verity &>> $seqres.full
+ _scratch_mount
+ $BTRFS_UTIL_PROG quota enable $SCRATCH_MNT >> $seqres.full 2>&1
+ _qgroup_rescan $SCRATCH_MNT >> $seqres.full 2>&1
+ _btrfs subvolume create $subv
+ subvolid=$(_btrfs_get_subvolid $SCRATCH_MNT sub)
+ $BTRFS_UTIL_PROG qgroup limit 200M 0/$subvolid $SCRATCH_MNT >> $seqres.full 2>&1
+}
+
+create_target()
+{
+ dd if=/dev/zero of=$target bs=1M count=128 status=none
+ sync
+}
+
+fill_qgroup()
+{
+ local i=0
+
+ while dd if=/dev/zero of=$subv/filler.$i bs=1M count=4 status=none 2>/dev/null; do
+ sync
+ i=$((i + 1))
+ [ $i -gt 200 ] && break
+ done
+ sync
+ echo "fillers written: $i" >> $seqres.full
+ $BTRFS_UTIL_PROG qgroup show -re $SCRATCH_MNT >> $seqres.full 2>&1
+}
+
+enable_fsverity()
+{
+ if _fsv_enable $target >> $seqres.full 2>&1; then
+ _notrun "could not exhaust the qgroup limit, verity enable succeeded"
+ fi
+}
+
+check_rollback()
+{
+ touch $SCRATCH_MNT/canary 2>> $seqres.full || \
+ echo "filesystem was forced read-only by the failed verity enable"
+ if $FSVERITY_PROG measure $target >> $seqres.full 2>&1; then
+ echo "verity is enabled on the target after a failed enable"
+ fi
+}
+
+check_remount()
+{
+ _scratch_unmount
+ _try_scratch_mount >> $seqres.full 2>&1 || \
+ _fail "cannot mount the filesystem after the failed verity enable"
+ ls $subv >/dev/null 2>> $seqres.full || \
+ echo "cannot read the subvolume after the failed verity enable"
+ dd if=$target of=/dev/null bs=1M count=1 status=none 2>> $seqres.full || \
+ echo "cannot read the target file after the failed verity enable"
+ _scratch_unmount
+}
+
+check_leftover_items()
+{
+ local dump=$($BTRFS_UTIL_PROG inspect-internal dump-tree -t $subvolid $SCRATCH_DEV)
+ local verity_items=$(echo "$dump" | grep -c 'VERITY_\(DESC\|MERKLE\)_ITEM')
+ local orphans=$(echo "$dump" | grep -c 'ORPHAN_ITEM')
+
+ echo "$dump" >> $seqres.full
+ [ "$verity_items" -eq 0 ] || \
+ echo "$verity_items verity items left behind by the failed enable"
+ [ "$orphans" -eq 0 ] || \
+ echo "$orphans orphan items left behind by the failed enable"
+}
+
+check_subvol_mount()
+{
+ _try_scratch_mount -o subvol=sub >> $seqres.full 2>&1 || \
+ _fail "cannot mount the quota limited subvolume on its own"
+}
+
+prepare
+create_target
+fill_qgroup
+enable_fsverity
+check_rollback
+check_remount
+check_leftover_items
+check_subvol_mount
+
+echo "Silence is golden"
+
+# success, all done
+status=0
+exit
diff --git a/tests/btrfs/354.out b/tests/btrfs/354.out
new file mode 100644
index 0000000..8bc7ecf
--- /dev/null
+++ b/tests/btrfs/354.out
@@ -0,0 +1,2 @@
+QA output created by 354
+Silence is golden
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 2/2] btrfs: test ENOSPC handling on fsverity rollback
2026-09-15 5:38 [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback Daniel Linjama
@ 2026-09-15 5:38 ` Daniel Linjama
2026-09-15 5:50 ` [PATCH 1/2] btrfs: test qgroup limit " Qu Wenruo
1 sibling, 0 replies; 5+ messages in thread
From: Daniel Linjama @ 2026-09-15 5:38 UTC (permalink / raw)
To: fstests; +Cc: linux-btrfs, Qu Wenruo, Daniel Linjama
Test that the filesystem stays writable when an fsverity enable and its
rollback run out of space on a small mixed block group filesystem, and
that it still mounts afterwards with no verity or orphan items left behind.
The -ENOSPC counterpart of btrfs/354.
This exercises a bug fixed by the kernel patch with subject:
"btrfs: handle lack of space when cleaning up verity items"
Assisted-by: LLM
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
---
tests/btrfs/355 | 119 ++++++++++++++++++++++++++++++++++++++++++++
tests/btrfs/355.out | 2 +
2 files changed, 121 insertions(+)
create mode 100755 tests/btrfs/355
create mode 100644 tests/btrfs/355.out
diff --git a/tests/btrfs/355 b/tests/btrfs/355
new file mode 100755
index 0000000..5f13c5b
--- /dev/null
+++ b/tests/btrfs/355
@@ -0,0 +1,119 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 Daniel Linjama. All Rights Reserved.
+#
+# FS QA Test 355
+#
+# Test that a failed fsverity enable on a full filesystem leaves the
+# filesystem usable. The -ENOSPC counterpart of btrfs/354.
+#
+. ./common/preamble
+_begin_fstest auto quick verity enospc
+
+# Override the default cleanup function.
+_cleanup()
+{
+ cd /
+ _restore_fsverity_signatures
+ rm -f $tmp.*
+}
+
+# Import common functions.
+. ./common/filter
+. ./common/verity
+
+# real QA test starts here
+
+_require_scratch_verity
+_require_btrfs_command inspect-internal dump-tree
+_require_xfs_io_command "falloc"
+_require_no_compress
+_require_scratch_size $((1024 * 1024))
+_disable_fsverity_signatures
+
+_fixed_by_kernel_commit xxxxxxxxxxxx \
+ "btrfs: handle lack of space when cleaning up verity items"
+
+target=$SCRATCH_MNT/target
+
+prepare()
+{
+ # Mixed block groups, so filling with data starves metadata too.
+ _scratch_mkfs --mixed -b 1G &>> $seqres.full || _fail "mkfs failed"
+ _scratch_mount
+}
+
+create_target()
+{
+ $XFS_IO_PROG -f -c "pwrite -S 0 -b 1m 0 512m" $target >> $seqres.full 2>&1
+ sync
+}
+
+fill_fs()
+{
+ local i=0
+
+ while $XFS_IO_PROG -f -c "falloc 0 2m" $SCRATCH_MNT/filler.$i &>/dev/null; do
+ i=$((i + 1))
+ [ $i -gt 1000 ] && break
+ done
+ echo "fillers written: $i" >> $seqres.full
+ # Room for the enable to start, not to finish.
+ rm -f $SCRATCH_MNT/filler.$((i - 1))
+ sync
+ $BTRFS_UTIL_PROG filesystem usage $SCRATCH_MNT >> $seqres.full 2>&1
+}
+
+enable_fsverity()
+{
+ if _fsv_enable $target >> $seqres.full 2>&1; then
+ _notrun "could not fill the filesystem, verity enable succeeded"
+ fi
+}
+
+check_rollback()
+{
+ # Deleting a filler needs no new space, it fails only if the fs went read-only.
+ rm -f $SCRATCH_MNT/filler.0 2>> $seqres.full || \
+ echo "filesystem was forced read-only by the failed verity enable"
+ if $FSVERITY_PROG measure $target >> $seqres.full 2>&1; then
+ echo "verity is enabled on the target after a failed enable"
+ fi
+}
+
+check_remount()
+{
+ _scratch_unmount
+ _try_scratch_mount >> $seqres.full 2>&1 || \
+ _fail "cannot mount the filesystem after the failed verity enable"
+ dd if=$target of=/dev/null bs=1M count=1 status=none 2>> $seqres.full || \
+ echo "cannot read the target file after the failed verity enable"
+ _scratch_unmount
+}
+
+check_leftover_items()
+{
+ local dump=$($BTRFS_UTIL_PROG inspect-internal dump-tree -t 5 $SCRATCH_DEV)
+ local verity_items=$(echo "$dump" | grep -c 'VERITY_\(DESC\|MERKLE\)_ITEM')
+ local orphans=$(echo "$dump" | grep -c 'ORPHAN_ITEM')
+
+ echo "$dump" >> $seqres.full
+ [ "$verity_items" -eq 0 ] || \
+ echo "$verity_items verity items left behind by the failed enable"
+ [ "$orphans" -eq 0 ] || \
+ echo "$orphans orphan items left behind by the failed enable"
+}
+
+prepare
+create_target
+fill_fs
+enable_fsverity
+check_rollback
+check_remount
+check_leftover_items
+
+echo "Silence is golden"
+
+# success, all done
+status=0
+exit
diff --git a/tests/btrfs/355.out b/tests/btrfs/355.out
new file mode 100644
index 0000000..4e4c5e9
--- /dev/null
+++ b/tests/btrfs/355.out
@@ -0,0 +1,2 @@
+QA output created by 355
+Silence is golden
--
2.55.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback
2026-09-15 5:38 [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback Daniel Linjama
2026-09-15 5:38 ` [PATCH 2/2] btrfs: test ENOSPC " Daniel Linjama
@ 2026-09-15 5:50 ` Qu Wenruo
2026-09-16 5:12 ` Daniel Linjama
1 sibling, 1 reply; 5+ messages in thread
From: Qu Wenruo @ 2026-09-15 5:50 UTC (permalink / raw)
To: Daniel Linjama, fstests; +Cc: linux-btrfs
在 2026/9/15 15:08, Daniel Linjama 写道:
> Test that the subvolume and the filesystem stay writable when an fsverity
> enable and its rollback hit the qgroup limit, and that the subvolume is
> still reachable after a remount with no verity or orphan items left behind.
>
> This exercises a bug fixed by the kernel patch with subject:
> "btrfs: handle lack of space when cleaning up verity items"
>
> Assisted-by: LLM
> Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
> ---
> tests/btrfs/354 | 131 ++++++++++++++++++++++++++++++++++++++++++++
> tests/btrfs/354.out | 2 +
> 2 files changed, 133 insertions(+)
> create mode 100755 tests/btrfs/354
> create mode 100644 tests/btrfs/354.out
>
> diff --git a/tests/btrfs/354 b/tests/btrfs/354
> new file mode 100755
> index 0000000..e3f6716
> --- /dev/null
> +++ b/tests/btrfs/354
> @@ -0,0 +1,131 @@
> +#! /bin/bash
> +# SPDX-License-Identifier: GPL-2.0
> +# Copyright (c) 2026 Daniel Linjama. All Rights Reserved.
> +#
> +# FS QA Test 354
> +#
> +# Test that a failed fsverity enable in a subvolume whose qgroup is at its
> +# limit leaves the filesystem usable.
> +#
> +. ./common/preamble
> +_begin_fstest auto quick qgroup limit verity
> +
> +# Override the default cleanup function.
> +_cleanup()
> +{
> + cd /
> + _restore_fsverity_signatures
> + rm -f $tmp.*
> +}
> +
> +# Import common functions.
> +. ./common/filter
> +. ./common/verity
> +
> +# real QA test starts here
> +
> +_require_scratch_verity
> +_require_btrfs_command inspect-internal dump-tree
> +_require_btrfs_command quota
_require_btrfs_command quota rescan -w
> +_require_no_compress
> +_require_scratch_size $((2 * 1024 * 1024))
> +_disable_fsverity_signatures
> +
> +_fixed_by_kernel_commit xxxxxxxxxxxx \
> + "btrfs: handle lack of space when cleaning up verity items"
> +
> +subv=$SCRATCH_MNT/sub
> +target=$subv/target
> +
> +prepare()
> +{
> + _scratch_mkfs_verity &>> $seqres.full
> + _scratch_mount
> + $BTRFS_UTIL_PROG quota enable $SCRATCH_MNT >> $seqres.full 2>&1
> + _qgroup_rescan $SCRATCH_MNT >> $seqres.full 2>&1
Use "-w" option, or the rescan may not finish in time before the workload.
> + _btrfs subvolume create $subv
> + subvolid=$(_btrfs_get_subvolid $SCRATCH_MNT sub)
> + $BTRFS_UTIL_PROG qgroup limit 200M 0/$subvolid $SCRATCH_MNT >> $seqres.full 2>&1
> +}
> +
> +create_target()
> +{
> + dd if=/dev/zero of=$target bs=1M count=128 status=none
> + sync
> +}
> +
> +fill_qgroup()
> +{
> + local i=0
> +
> + while dd if=/dev/zero of=$subv/filler.$i bs=1M count=4 status=none 2>/dev/null; do
> + sync
> + i=$((i + 1))
> + [ $i -gt 200 ] && break
This is so hard to read.
Why not just a regular for loop?
And what the point of doing 200 loops?
If you just want to make sure to hit the quota limit, you don't need so
many loops.
You can just do a 40MiB write (which should fail halfway), sync, retry
the write until the write failed to write any bytes.
> + done
> + sync
> + echo "fillers written: $i" >> $seqres.full
> + $BTRFS_UTIL_PROG qgroup show -re $SCRATCH_MNT >> $seqres.full 2>&1
> +}
> +
> +enable_fsverity()
> +{
> + if _fsv_enable $target >> $seqres.full 2>&1; then
> + _notrun "could not exhaust the qgroup limit, verity enable succeeded"
> + fi
> +}
> +
> +check_rollback()
> +{
> + touch $SCRATCH_MNT/canary 2>> $seqres.full || \
> + echo "filesystem was forced read-only by the failed verity enable"
> + if $FSVERITY_PROG measure $target >> $seqres.full 2>&1; then
> + echo "verity is enabled on the target after a failed enable"
> + fi
> +}
> +
> +check_remount()
> +{
> + _scratch_unmount
> + _try_scratch_mount >> $seqres.full 2>&1 || \
> + _fail "cannot mount the filesystem after the failed verity enable"
> + ls $subv >/dev/null 2>> $seqres.full || \
> + echo "cannot read the subvolume after the failed verity enable"
> + dd if=$target of=/dev/null bs=1M count=1 status=none 2>> $seqres.full || \
> + echo "cannot read the target file after the failed verity enable"
> + _scratch_unmount
> +}
> +
> +check_leftover_items()
> +{
> + local dump=$($BTRFS_UTIL_PROG inspect-internal dump-tree -t $subvolid $SCRATCH_DEV)
> + local verity_items=$(echo "$dump" | grep -c 'VERITY_\(DESC\|MERKLE\)_ITEM')
> + local orphans=$(echo "$dump" | grep -c 'ORPHAN_ITEM')
> +
> + echo "$dump" >> $seqres.full
> + [ "$verity_items" -eq 0 ] || \
> + echo "$verity_items verity items left behind by the failed enable"
> + [ "$orphans" -eq 0 ] || \
> + echo "$orphans orphan items left behind by the failed enable"
> +}
> +
> +check_subvol_mount()
> +{
> + _try_scratch_mount -o subvol=sub >> $seqres.full 2>&1 || \
> + _fail "cannot mount the quota limited subvolume on its own"
> +}
> +
> +prepare
> +create_target
> +fill_qgroup
> +enable_fsverity
> +check_rollback
> +check_remount
> +check_leftover_items
> +check_subvol_mount
> +
> +echo "Silence is golden"
> +
> +# success, all done
> +status=0
> +exit
> diff --git a/tests/btrfs/354.out b/tests/btrfs/354.out
> new file mode 100644
> index 0000000..8bc7ecf
> --- /dev/null
> +++ b/tests/btrfs/354.out
> @@ -0,0 +1,2 @@
> +QA output created by 354
> +Silence is golden
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback
2026-09-15 5:50 ` [PATCH 1/2] btrfs: test qgroup limit " Qu Wenruo
@ 2026-09-16 5:12 ` Daniel Linjama
2026-09-16 5:34 ` Qu Wenruo
0 siblings, 1 reply; 5+ messages in thread
From: Daniel Linjama @ 2026-09-16 5:12 UTC (permalink / raw)
To: Qu Wenruo; +Cc: fstests, linux-btrfs, Daniel Linjama
On 2026/9/15 15:20, Qu Wenruo wrote:
>> +_require_btrfs_command quota
>
> _require_btrfs_command quota rescan -w
Will do in v2.
>> + _qgroup_rescan $SCRATCH_MNT >> $seqres.full 2>&1
>
> Use "-w" option, or the rescan may not finish in time before the workload.
_qgroup_rescan already runs "btrfs quota rescan -w", so the test waits
for the rescan. I'll keep the helper.
>> + while dd if=/dev/zero of=$subv/filler.$i bs=1M count=4 status=none 2>/dev/null; do
> [...]
> You can just do a 40MiB write (which should fail halfway), sync, retry
> the write until the write failed to write any bytes.
Will do in v2, with xfs_io instead of dd as the other tests do. A single
write turned out to be enough: after it fails with -EDQUOT and a sync,
nothing more fits, so there is no retry loop.
Thanks,
Daniel
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback
2026-09-16 5:12 ` Daniel Linjama
@ 2026-09-16 5:34 ` Qu Wenruo
0 siblings, 0 replies; 5+ messages in thread
From: Qu Wenruo @ 2026-09-16 5:34 UTC (permalink / raw)
To: Daniel Linjama, Qu Wenruo; +Cc: fstests, linux-btrfs
在 2026/9/16 14:42, Daniel Linjama 写道:
> On 2026/9/15 15:20, Qu Wenruo wrote:
>>> +_require_btrfs_command quota
>>
>> _require_btrfs_command quota rescan -w
>
> Will do in v2.
The better solution is _require_qgroup_rescan(), which has the extra
checks for -W and -w options built-in.
>
>>> + _qgroup_rescan $SCRATCH_MNT >> $seqres.full 2>&1
>>
>> Use "-w" option, or the rescan may not finish in time before the workload.
>
> _qgroup_rescan already runs "btrfs quota rescan -w", so the test waits
> for the rescan. I'll keep the helper.
>
>>> + while dd if=/dev/zero of=$subv/filler.$i bs=1M count=4 status=none 2>/dev/null; do
>> [...]
>> You can just do a 40MiB write (which should fail halfway), sync, retry
>> the write until the write failed to write any bytes.
>
> Will do in v2, with xfs_io instead of dd as the other tests do. A single
> write turned out to be enough: after it fails with -EDQUOT and a sync,
> nothing more fits, so there is no retry loop.
>
> Thanks,
> Daniel
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-16 5:34 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15 5:38 [PATCH 1/2] btrfs: test qgroup limit handling on fsverity rollback Daniel Linjama
2026-09-15 5:38 ` [PATCH 2/2] btrfs: test ENOSPC " Daniel Linjama
2026-09-15 5:50 ` [PATCH 1/2] btrfs: test qgroup limit " Qu Wenruo
2026-09-16 5:12 ` Daniel Linjama
2026-09-16 5:34 ` Qu Wenruo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox