* [PATCH v2 1/2] btrfs: test qgroup limit handling on fsverity rollback
@ 2026-09-16 6:23 Daniel Linjama
2026-09-16 6:23 ` [PATCH v2 2/2] btrfs: test ENOSPC " Daniel Linjama
0 siblings, 1 reply; 2+ messages in thread
From: Daniel Linjama @ 2026-09-16 6:23 UTC (permalink / raw)
To: fstests; +Cc: linux-btrfs, Qu Wenruo, Daniel Linjama
Test that the subvolume and the filesystem stay writable when an fsverity
enable and its rollback hit the qgroup limit, and that the subvolume is
still reachable after a remount with no verity or orphan items left behind.
This exercises a bug fixed by the kernel patch with subject:
"btrfs: handle lack of space when cleaning up verity items"
Assisted-by: LLM
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
---
Changes since v1:
- Use _require_qgroup_rescan(); the _qgroup_rescan helper already waits
with -w.
- Fill the qgroup with a single xfs_io write instead of a loop of dd
calls, xfs_io instead of dd elsewhere too.
- Both suggested by Qu Wenruo.
- Look for leftover items of the target inode only, like btrfs/058 does.
v1: https://lore.kernel.org/fstests/20260915053815.307674-1-daniel@dev.linjama.com/
tests/btrfs/354 | 126 ++++++++++++++++++++++++++++++++++++++++++++
tests/btrfs/354.out | 2 +
2 files changed, 128 insertions(+)
create mode 100755 tests/btrfs/354
create mode 100644 tests/btrfs/354.out
diff --git a/tests/btrfs/354 b/tests/btrfs/354
new file mode 100755
index 0000000..0ae6e7f
--- /dev/null
+++ b/tests/btrfs/354
@@ -0,0 +1,126 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 Daniel Linjama. All Rights Reserved.
+#
+# FS QA Test 354
+#
+# Test that a failed fsverity enable in a subvolume whose qgroup is at its
+# limit leaves the filesystem usable.
+#
+. ./common/preamble
+_begin_fstest auto quick qgroup limit verity
+
+# Override the default cleanup function.
+_cleanup()
+{
+ cd /
+ _restore_fsverity_signatures
+ rm -f $tmp.*
+}
+
+# Import common functions.
+. ./common/filter
+. ./common/verity
+
+# real QA test starts here
+
+_require_scratch_verity
+_require_btrfs_command inspect-internal dump-tree
+_require_qgroup_rescan
+_require_no_compress
+_require_scratch_size $((2 * 1024 * 1024))
+_disable_fsverity_signatures
+
+_fixed_by_kernel_commit xxxxxxxxxxxx \
+ "btrfs: handle lack of space when cleaning up verity items"
+
+subv=$SCRATCH_MNT/sub
+target=$subv/target
+
+prepare()
+{
+ _scratch_mkfs_verity &>> $seqres.full
+ _scratch_mount
+ _btrfs quota enable $SCRATCH_MNT
+ _qgroup_rescan $SCRATCH_MNT >> $seqres.full 2>&1
+ _btrfs subvolume create $subv
+ subvolid=$(_btrfs_get_subvolid $SCRATCH_MNT sub)
+ _btrfs qgroup limit 200M 0/$subvolid $SCRATCH_MNT
+}
+
+create_target()
+{
+ $XFS_IO_PROG -f -c "pwrite -q -b 1m 0 128m" $target
+ ino=$(stat -c %i $target)
+ sync
+}
+
+fill_qgroup()
+{
+ # Writes until the qgroup limit is hit.
+ $XFS_IO_PROG -f -c "pwrite -q -b 64k 0 256m" $subv/filler &>/dev/null
+ sync
+ $BTRFS_UTIL_PROG qgroup show -re $SCRATCH_MNT >> $seqres.full 2>&1
+}
+
+enable_fsverity()
+{
+ if _fsv_enable $target >> $seqres.full 2>&1; then
+ _notrun "could not exhaust the qgroup limit, verity enable succeeded"
+ fi
+}
+
+check_rollback()
+{
+ touch $SCRATCH_MNT/canary 2>> $seqres.full || \
+ echo "filesystem was forced read-only by the failed verity enable"
+ if $FSVERITY_PROG measure $target >> $seqres.full 2>&1; then
+ echo "verity is enabled on the target after a failed enable"
+ fi
+}
+
+check_remount()
+{
+ _scratch_unmount
+ _try_scratch_mount >> $seqres.full 2>&1 || \
+ _fail "cannot mount the filesystem after the failed verity enable"
+ ls $subv >/dev/null 2>> $seqres.full || \
+ echo "cannot read the subvolume after the failed verity enable"
+ $XFS_IO_PROG -c "pread -q 0 1m" $target >> $seqres.full 2>&1 || \
+ echo "cannot read the target file after the failed verity enable"
+ _scratch_unmount
+}
+
+check_leftover_items()
+{
+ local dump=$($BTRFS_UTIL_PROG inspect-internal dump-tree -t $subvolid $SCRATCH_DEV)
+ local verity_items=$(echo "$dump" | grep -c "($ino VERITY_\(DESC\|MERKLE\)_ITEM")
+ local orphans=$(echo "$dump" | grep -c "(ORPHAN ORPHAN_ITEM $ino)")
+
+ echo "$dump" >> $seqres.full
+ [ "$verity_items" -eq 0 ] || \
+ echo "$verity_items verity items left behind by the failed enable"
+ [ "$orphans" -eq 0 ] || \
+ echo "$orphans orphan items left behind by the failed enable"
+}
+
+check_subvol_mount()
+{
+ _try_scratch_mount -o subvol=sub >> $seqres.full 2>&1 || \
+ _fail "cannot mount the quota limited subvolume on its own"
+}
+
+prepare
+create_target
+fill_qgroup
+enable_fsverity
+check_rollback
+check_remount
+check_leftover_items
+check_subvol_mount
+
+echo "Silence is golden"
+
+# success, all done
+status=0
+exit
diff --git a/tests/btrfs/354.out b/tests/btrfs/354.out
new file mode 100644
index 0000000..8bc7ecf
--- /dev/null
+++ b/tests/btrfs/354.out
@@ -0,0 +1,2 @@
+QA output created by 354
+Silence is golden
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* [PATCH v2 2/2] btrfs: test ENOSPC handling on fsverity rollback
2026-09-16 6:23 [PATCH v2 1/2] btrfs: test qgroup limit handling on fsverity rollback Daniel Linjama
@ 2026-09-16 6:23 ` Daniel Linjama
0 siblings, 0 replies; 2+ messages in thread
From: Daniel Linjama @ 2026-09-16 6:23 UTC (permalink / raw)
To: fstests; +Cc: linux-btrfs, Qu Wenruo, Daniel Linjama
Test that the filesystem stays writable when an fsverity enable and its
rollback run out of space on a small mixed block group filesystem, and
that it still mounts afterwards with no verity or orphan items left behind.
The -ENOSPC counterpart of btrfs/354.
This exercises a bug fixed by the kernel patch with subject:
"btrfs: handle lack of space when cleaning up verity items"
Assisted-by: LLM
Signed-off-by: Daniel Linjama <daniel@dev.linjama.com>
---
Changes since v1:
- Fill the filesystem with a single xfs_io write, like btrfs/354 now
does. The room for the enable to start is made by deleting a small
file written beforehand, since a truncate fails on a full filesystem.
- Look for leftover items of the target inode only, like btrfs/058 does.
tests/btrfs/355 | 117 ++++++++++++++++++++++++++++++++++++++++++++
tests/btrfs/355.out | 2 +
2 files changed, 119 insertions(+)
create mode 100755 tests/btrfs/355
create mode 100644 tests/btrfs/355.out
diff --git a/tests/btrfs/355 b/tests/btrfs/355
new file mode 100755
index 0000000..8127d25
--- /dev/null
+++ b/tests/btrfs/355
@@ -0,0 +1,117 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 Daniel Linjama. All Rights Reserved.
+#
+# FS QA Test 355
+#
+# Test that a failed fsverity enable on a full filesystem leaves the
+# filesystem usable. The -ENOSPC counterpart of btrfs/354.
+#
+. ./common/preamble
+_begin_fstest auto quick verity enospc
+
+# Override the default cleanup function.
+_cleanup()
+{
+ cd /
+ _restore_fsverity_signatures
+ rm -f $tmp.*
+}
+
+# Import common functions.
+. ./common/filter
+. ./common/verity
+
+# real QA test starts here
+
+_require_scratch_verity
+_require_btrfs_command inspect-internal dump-tree
+_require_no_compress
+_require_scratch_size $((1024 * 1024))
+_disable_fsverity_signatures
+
+_fixed_by_kernel_commit xxxxxxxxxxxx \
+ "btrfs: handle lack of space when cleaning up verity items"
+
+target=$SCRATCH_MNT/target
+
+prepare()
+{
+ # Mixed block groups, so filling with data starves metadata too.
+ _scratch_mkfs --mixed -b 1G &>> $seqres.full || _fail "mkfs failed"
+ _scratch_mount
+}
+
+create_target()
+{
+ $XFS_IO_PROG -f -c "pwrite -q -b 1m 0 512m" $target
+ ino=$(stat -c %i $target)
+ sync
+}
+
+fill_fs()
+{
+ # Deleting this afterwards leaves room for the enable to start, not
+ # to finish.
+ $XFS_IO_PROG -f -c "pwrite -q 0 1m" $SCRATCH_MNT/margin
+ # Writes until the filesystem is full.
+ $XFS_IO_PROG -f -c "pwrite -q -b 64k 0 1g" $SCRATCH_MNT/filler &>/dev/null
+ sync
+ rm -f $SCRATCH_MNT/margin
+ sync
+ $BTRFS_UTIL_PROG filesystem usage $SCRATCH_MNT >> $seqres.full 2>&1
+}
+
+enable_fsverity()
+{
+ if _fsv_enable $target >> $seqres.full 2>&1; then
+ _notrun "could not fill the filesystem, verity enable succeeded"
+ fi
+}
+
+check_rollback()
+{
+ # Deleting a filler needs no new space, it fails only if the fs went read-only.
+ rm -f $SCRATCH_MNT/filler 2>> $seqres.full || \
+ echo "filesystem was forced read-only by the failed verity enable"
+ if $FSVERITY_PROG measure $target >> $seqres.full 2>&1; then
+ echo "verity is enabled on the target after a failed enable"
+ fi
+}
+
+check_remount()
+{
+ _scratch_unmount
+ _try_scratch_mount >> $seqres.full 2>&1 || \
+ _fail "cannot mount the filesystem after the failed verity enable"
+ $XFS_IO_PROG -c "pread -q 0 1m" $target >> $seqres.full 2>&1 || \
+ echo "cannot read the target file after the failed verity enable"
+ _scratch_unmount
+}
+
+check_leftover_items()
+{
+ local dump=$($BTRFS_UTIL_PROG inspect-internal dump-tree -t 5 $SCRATCH_DEV)
+ local verity_items=$(echo "$dump" | grep -c "($ino VERITY_\(DESC\|MERKLE\)_ITEM")
+ local orphans=$(echo "$dump" | grep -c "(ORPHAN ORPHAN_ITEM $ino)")
+
+ echo "$dump" >> $seqres.full
+ [ "$verity_items" -eq 0 ] || \
+ echo "$verity_items verity items left behind by the failed enable"
+ [ "$orphans" -eq 0 ] || \
+ echo "$orphans orphan items left behind by the failed enable"
+}
+
+prepare
+create_target
+fill_fs
+enable_fsverity
+check_rollback
+check_remount
+check_leftover_items
+
+echo "Silence is golden"
+
+# success, all done
+status=0
+exit
diff --git a/tests/btrfs/355.out b/tests/btrfs/355.out
new file mode 100644
index 0000000..4e4c5e9
--- /dev/null
+++ b/tests/btrfs/355.out
@@ -0,0 +1,2 @@
+QA output created by 355
+Silence is golden
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-16 6:24 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 6:23 [PATCH v2 1/2] btrfs: test qgroup limit handling on fsverity rollback Daniel Linjama
2026-09-16 6:23 ` [PATCH v2 2/2] btrfs: test ENOSPC " Daniel Linjama
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).