FS/XFS testing framework
 help / color / mirror / Atom feed
From: Jeff Layton <jlayton@kernel.org>
To: Zorro Lang <zlang@kernel.org>, Anand Jain <asj@kernel.org>,
	 Filipe Manana <fdmanana@suse.com>
Cc: linux-btrfs@vger.kernel.org, fstests@vger.kernel.org,
	 Jeff Layton <jlayton@kernel.org>
Subject: [PATCH fstests v3] btrfs: test graceful ENOMEM handling in synchronous dirops
Date: Tue, 22 Sep 2026 14:46:22 -0400	[thread overview]
Message-ID: <20260922-btrfs-enomem-v3-1-1be91fc173fc@kernel.org> (raw)

Recently, we added some patches to allow btrfs to handle -ENOMEM errors
in dir-morphing codepaths [1]. As part of that, we added fault injection
knobs to a few functions so we could test that error handling.

Add a test case that uses the fail_function facility to inject -ENOMEM
into btrfs_prealloc_delayed_dir_index() and confirms that a
dir-modifying operation returns ENOMEM to userspace without aborting the
filesystem:

- mkdir fails with ENOMEM (not EROFS),
- a subsequent create succeeds (fs is not read-only/aborted),
- a mount cycle runs orphan cleanup and the automatic fsck confirms
  consistency.

The injection is global, so any other btrfs dir-entry creation can
consume it first -- including the test's own $tmp redirection when /tmp
is itself on btrfs. Pre-create that file and retry until the mkdir takes
the error.

Add generic _require_function_error_injection / _inject_function_error /
_uninject_function_error helpers to common/inject for driving the kernel
fail_function interface.

[1]: https://lore.kernel.org/linux-btrfs/20260825-btrfs-enomem-v4-0-b9363fa8714a@kernel.org/

Assisted-by: LLM
Reviewed-by: Zorro Lang <zlang@kernel.org>
Reviewed-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: Jeff Layton <jlayton@kernel.org>
---
Changes in v3:
- Call _require_debugfs in _require_function_error_injection
- Add the test to the "dir" group
- Uninject the error in _cleanup, so an interrupted test can't leak it
- Use _exit 0 instead of setting status directly
- Link to v2: https://lore.kernel.org/r/20260917-btrfs-enomem-v2-1-0ccc4271ad64@kernel.org

Changes in v2:
- Add _fixed_by_kernel_commit line
- Clean up changelog
- Link to v1: https://lore.kernel.org/r/20260915-btrfs-enomem-v1-1-ca07610ebcad@kernel.org
---
 common/inject       | 51 +++++++++++++++++++++++++++++
 tests/btrfs/354     | 92 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 tests/btrfs/354.out |  2 ++
 3 files changed, 145 insertions(+)

diff --git a/common/inject b/common/inject
index 6b590804d1ea..fc63d3a32c8a 100644
--- a/common/inject
+++ b/common/inject
@@ -111,3 +111,54 @@ _scratch_inject_error()
 		_fail "Cannot inject error ${type} value ${value}."
 	fi
 }
+
+# Requires the kernel fail_function facility (CONFIG_FUNCTION_ERROR_INJECTION
+# and CONFIG_FAIL_FUNCTION) and, if a function name is given, that the function
+# is annotated with ALLOW_ERROR_INJECTION().
+_require_function_error_injection()
+{
+	local func="$1"
+
+	_require_debugfs
+	test -d "$DEBUGFS_MNT/fail_function" || \
+		_notrun "$DEBUGFS_MNT/fail_function not found; CONFIG_FAIL_FUNCTION not enabled"
+
+	if [ -n "$func" ]; then
+		grep -qw "$func" "$DEBUGFS_MNT/error_injection/list" 2>/dev/null || \
+			_notrun "$func is not registered for error injection"
+	fi
+}
+
+# Inject a fixed return value into a kernel function via fail_function.
+#   $1 - function name (must be ALLOW_ERROR_INJECTION annotated)
+#   $2 - return value to inject (e.g. -12 for -ENOMEM)
+#   $3 - number of times to fail (default 1)
+_inject_function_error()
+{
+	local func="$1"
+	local retval="$2"
+	local times="${3:-1}"
+
+	# Writing the function name to "inject" creates its per-function dir.
+	echo "$func" > "$DEBUGFS_MNT/fail_function/inject"
+	# The retval file is an unsigned hex attribute (DEFINE_DEBUGFS_ATTRIBUTE
+	# "%llx"), so a negative errno like -12 must be written as its unsigned
+	# 64-bit (two's-complement) hex form; a bare "-12" is rejected with EINVAL.
+	printf '%#x\n' "$retval" > "$DEBUGFS_MNT/fail_function/$func/retval"
+	echo 100 > "$DEBUGFS_MNT/fail_function/probability"
+	echo 0 > "$DEBUGFS_MNT/fail_function/interval"
+	echo 0 > "$DEBUGFS_MNT/fail_function/space"
+	echo 0 > "$DEBUGFS_MNT/fail_function/verbose"
+	echo "$times" > "$DEBUGFS_MNT/fail_function/times"
+}
+
+# Stop injecting errors into a kernel function set up by
+# _inject_function_error().
+_uninject_function_error()
+{
+	local func="$1"
+
+	echo 0 > "$DEBUGFS_MNT/fail_function/times" 2>/dev/null
+	echo 0 > "$DEBUGFS_MNT/fail_function/probability" 2>/dev/null
+	echo "!$func" > "$DEBUGFS_MNT/fail_function/inject" 2>/dev/null
+}
diff --git a/tests/btrfs/354 b/tests/btrfs/354
new file mode 100755
index 000000000000..a4d8fec41091
--- /dev/null
+++ b/tests/btrfs/354
@@ -0,0 +1,92 @@
+#! /bin/bash
+# SPDX-License-Identifier: GPL-2.0
+# Copyright (c) 2026 Jeff Layton.  All Rights Reserved.
+#
+# FS QA Test No. 354
+#
+# Verify that an -ENOMEM in the synchronous directory entry insertion path is
+# returned to userspace without aborting the filesystem.
+#
+# btrfs pre-allocates the delayed dir index before modifying the btree, so a
+# failure in btrfs_prealloc_delayed_dir_index() must surface as -ENOMEM from
+# mkdir()/create()/etc. rather than a transaction abort. Use the fail_function
+# facility to force that allocation to fail and confirm the fs survives.
+#
+. ./common/preamble
+_begin_fstest auto quick dir
+
+_cleanup()
+{
+	[ -n "$func" ] && _uninject_function_error $func
+	cd /
+	rm -r -f $tmp.*
+}
+
+. ./common/inject
+. ./common/filter
+
+_fixed_by_kernel_commit xxxxxxxxxxxx \
+	"btrfs: handle ENOMEM from btrfs_insert_dir_item() without aborting"
+
+_require_scratch
+# For the automatic fsck at unmount, which confirms the orphaned inode left by
+# the failed operation is cleaned up and the fs is consistent.
+_require_check_dmesg
+_require_function_error_injection btrfs_prealloc_delayed_dir_index
+
+func=btrfs_prealloc_delayed_dir_index
+
+_scratch_mkfs >> $seqres.full 2>&1
+_scratch_mount
+
+# Pre-create the stderr file. fail_function has no usable task filter, so the
+# injection is global, and $tmp may well live on a btrfs filesystem itself. If
+# the shell had to create this file it would insert a dir entry and swallow the
+# injected failure before mkdir() ever ran.
+touch $tmp.err
+
+# For the same reason any other btrfs dir-entry creation on the system can
+# consume the one-shot failure, so retry until our mkdir is the operation that
+# takes it.
+err=""
+for i in $(seq 1 20); do
+	rm -rf "$SCRATCH_MNT/dir"
+
+	# Force a single -ENOMEM (-12) into the prealloc path.
+	_inject_function_error $func -12 1
+	mkdir "$SCRATCH_MNT/dir" 2>$tmp.err
+	res=$?
+	_uninject_function_error $func
+
+	# mkdir succeeded, so something else consumed the injected failure.
+	# Note we must not leave the directory behind, or the next attempt
+	# would fail with EEXIST rather than the injected error.
+	if [ $res -eq 0 ]; then
+		continue
+	fi
+
+	err=$(cat $tmp.err)
+	break
+done
+
+if [ -z "$err" ]; then
+	_notrun "injected error did not reach mkdir"
+fi
+
+# The error returned to userspace must be ENOMEM, not EROFS (which would mean
+# the transaction was aborted and the fs went read-only).
+echo "$err" | grep -qi "cannot allocate memory" || \
+	{ echo "unexpected error from mkdir:"; echo "$err" | _filter_scratch; }
+
+# The filesystem must still be usable: a create with injection disabled must
+# succeed. On an aborted (read-only) fs this would fail with EROFS.
+mkdir "$SCRATCH_MNT/dir2" || _fail "filesystem unusable after injected ENOMEM"
+
+# Cycle the mount to run orphan cleanup for the inode left behind by the failed
+# mkdir, then keep using the fs to be sure it is healthy.
+_scratch_cycle_mount
+touch "$SCRATCH_MNT/dir2/file"
+
+echo "silence is golden"
+
+_exit 0
diff --git a/tests/btrfs/354.out b/tests/btrfs/354.out
new file mode 100644
index 000000000000..afe30ed36fea
--- /dev/null
+++ b/tests/btrfs/354.out
@@ -0,0 +1,2 @@
+QA output created by 354
+silence is golden

---
base-commit: a370dcbed43563f0462801e889e0eceb93c7cfad
change-id: 20260915-btrfs-enomem-e70077862117

Best regards,
-- 
Jeff Layton <jlayton@kernel.org>


                 reply	other threads:[~2026-09-22 18:46 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922-btrfs-enomem-v3-1-1be91fc173fc@kernel.org \
    --to=jlayton@kernel.org \
    --cc=asj@kernel.org \
    --cc=fdmanana@suse.com \
    --cc=fstests@vger.kernel.org \
    --cc=linux-btrfs@vger.kernel.org \
    --cc=zlang@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox