Linux block layer
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: Christoph Hellwig <hch@lst.de>
Cc: Jens Axboe <axboe@kernel.dk>,
	Christian Brauner <brauner@kernel.org>,
	Carlos Maiolino <cem@kernel.org>,
	Tal Zussman <tz2294@columbia.edu>,
	Anuj Gupta <anuj20.g@samsung.com>,
	linux-block@vger.kernel.org, linux-xfs@vger.kernel.org,
	linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH 19/22] iomap,xfs: move integrity verification to the file system
Date: Thu, 23 Jul 2026 14:02:16 -0700	[thread overview]
Message-ID: <20260723210216.GI2901224@frogsfrogsfrogs> (raw)
In-Reply-To: <20260723145000.116419-20-hch@lst.de>

On Thu, Jul 23, 2026 at 04:49:44PM +0200, Christoph Hellwig wrote:
> Integrity support in file systems already requires file system-specific
> completion handling because it must be run in process context.
> 
> Move the actual verification to the file system so that it can better
> handle errors in file system specific ways, and to support lazy bounce
> buffering.
> 
> Signed-off-by: Christoph Hellwig <hch@lst.de>

Sounds good to me.  I gather the idea here is that direct reads go
straight into the user's buffer, and if they're evil and mess with the
buffer contents during the read to make the PI verification fail, we can
then retry the read with a bounce buffer out of spite for userspace?

If so, then
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>

--D

> ---
>  fs/iomap/ioend.c      | 8 ++------
>  fs/xfs/xfs_ioend.c    | 3 +++
>  include/linux/iomap.h | 1 +
>  3 files changed, 6 insertions(+), 6 deletions(-)
> 
> diff --git a/fs/iomap/ioend.c b/fs/iomap/ioend.c
> index 438be92e131b..b1078f7c08c6 100644
> --- a/fs/iomap/ioend.c
> +++ b/fs/iomap/ioend.c
> @@ -308,12 +308,13 @@ ssize_t iomap_add_to_ioend(struct iomap_writepage_ctx *wpc, struct folio *folio,
>  }
>  EXPORT_SYMBOL_GPL(iomap_add_to_ioend);
>  
> -static int iomap_ioend_integrity_verify(struct iomap_ioend *ioend)
> +int iomap_ioend_integrity_verify(struct iomap_ioend *ioend)
>  {
>  	struct bvec_iter data_iter = BVEC_ITER_IOEND(ioend);
>  
>  	return fs_bio_integrity_verify(&ioend->io_bio, &data_iter);
>  }
> +EXPORT_SYMBOL_GPL(iomap_ioend_integrity_verify);
>  
>  static u32 iomap_finish_ioend(struct iomap_ioend *ioend, int error)
>  {
> @@ -330,11 +331,6 @@ static u32 iomap_finish_ioend(struct iomap_ioend *ioend, int error)
>  	if (!atomic_dec_and_test(&ioend->io_remaining))
>  		return 0;
>  
> -	if (!ioend->io_error &&
> -	    bio_integrity(&ioend->io_bio) &&
> -	    bio_op(&ioend->io_bio) == REQ_OP_READ)
> -		ioend->io_error = iomap_ioend_integrity_verify(ioend);
> -
>  	if (ioend->io_flags & IOMAP_IOEND_DIRECT)
>  		return iomap_finish_ioend_direct(ioend);
>  	if (bio_op(&ioend->io_bio) == REQ_OP_READ)
> diff --git a/fs/xfs/xfs_ioend.c b/fs/xfs/xfs_ioend.c
> index 37a3ae8066e9..a095cf217863 100644
> --- a/fs/xfs/xfs_ioend.c
> +++ b/fs/xfs/xfs_ioend.c
> @@ -25,6 +25,9 @@ xfs_end_io_read(
>  	struct iomap_ioend	*ioend = iomap_ioend_from_bio(bio);
>  	int			error = blk_status_to_errno(bio->bi_status);
>  
> +	if (!error && (ioend->io_flags & IOMAP_IOEND_INTEGRITY))
> +		error = iomap_ioend_integrity_verify(ioend);
> +
>  	iomap_finish_ioends(ioend, error);
>  }
>  
> diff --git a/include/linux/iomap.h b/include/linux/iomap.h
> index 1916a4f28002..f9e2fce21be0 100644
> --- a/include/linux/iomap.h
> +++ b/include/linux/iomap.h
> @@ -518,6 +518,7 @@ void iomap_finish_ioends(struct iomap_ioend *ioend, int error);
>  void iomap_ioend_try_merge(struct iomap_ioend *ioend,
>  		struct list_head *more_ioends);
>  void iomap_sort_ioends(struct list_head *ioend_list);
> +int iomap_ioend_integrity_verify(struct iomap_ioend *ioend);
>  ssize_t iomap_add_to_ioend(struct iomap_writepage_ctx *wpc, struct folio *folio,
>  		loff_t pos, loff_t end_pos, unsigned int dirty_len);
>  int iomap_ioend_writeback_submit(struct iomap_writepage_ctx *wpc, int error);
> -- 
> 2.53.0
> 
> 

  reply	other threads:[~2026-07-23 21:02 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 14:49 lazy bounce buffering for checksummed reads Christoph Hellwig
2026-07-23 14:49 ` [PATCH 01/22] iomap: add a separate bio_set for iomap_split_ioend Christoph Hellwig
2026-07-23 16:49   ` Darrick J. Wong
2026-07-24  6:22     ` Christoph Hellwig
2026-07-23 14:49 ` [PATCH 02/22] block: remove bip_should_check Christoph Hellwig
2026-07-23 14:49 ` [PATCH 03/22] block: lift BIP_CHECK_FLAGS to include/linux/bio-integrity.h Christoph Hellwig
2026-07-23 14:49 ` [PATCH 04/22] block: handle nogenerate/noverify properly in fs-integrity Christoph Hellwig
2026-07-23 17:05   ` Anuj gupta
2026-07-23 14:49 ` [PATCH 05/22] iomap: don't free integrity payload that doesn't exist Christoph Hellwig
2026-07-23 16:55   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 06/22] block,iomap: fix protection information verification with initial bvec offset Christoph Hellwig
2026-07-23 14:49 ` [PATCH 07/22] block: add task-context bio completion infrastructure Christoph Hellwig
2026-07-23 14:49 ` [PATCH 08/22] block: don't delay bio task completions Christoph Hellwig
2026-07-23 14:49 ` [PATCH 09/22] block: split bio_iov_iter_bounce_write Christoph Hellwig
2026-07-23 14:49 ` [PATCH 10/22] block: export fs_bio_integrity_{alloc,free} Christoph Hellwig
2026-07-23 14:49 ` [PATCH 11/22] block: don't include blk-integrity.h in bdev.c Christoph Hellwig
2026-07-23 14:49 ` [PATCH 12/22] iomap: better read bounce buffering support Christoph Hellwig
2026-07-23 21:10   ` Darrick J. Wong
2026-07-24  6:26     ` Christoph Hellwig
2026-07-23 14:49 ` [PATCH 13/22] iomap: add a iomap_ioend_flags helper Christoph Hellwig
2026-07-23 20:52   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 14/22] iomap: add a IOMAP_IOEND_INTEGRITY flag Christoph Hellwig
2026-07-23 20:53   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 15/22] iomap,xfs: move T10 PI handling for direct I/O into ->submit_io Christoph Hellwig
2026-07-23 20:55   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 16/22] xfs: move PI generation into xfs_zone_alloc_and_submit Christoph Hellwig
2026-07-23 20:55   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 17/22] xfs: split ioend handling into a separate source file Christoph Hellwig
2026-07-23 20:55   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 18/22] xfs: use BIO_COMPLETE_IN_TASK for bounce buffered read I/Os Christoph Hellwig
2026-07-23 15:58   ` Andrey Albershteyn
2026-07-24  6:21     ` Christoph Hellwig
2026-07-23 20:58   ` Darrick J. Wong
2026-07-24  6:21     ` Christoph Hellwig
2026-07-23 14:49 ` [PATCH 19/22] iomap,xfs: move integrity verification to the file system Christoph Hellwig
2026-07-23 21:02   ` Darrick J. Wong [this message]
2026-07-24  6:23     ` Christoph Hellwig
2026-07-23 14:49 ` [PATCH 20/22] xfs: add support for lazy direct read bounce buffering Christoph Hellwig
2026-07-23 21:05   ` Darrick J. Wong
2026-07-24  6:24     ` Christoph Hellwig
2026-07-24  6:33       ` Christoph Hellwig
2026-07-23 14:49 ` [PATCH 21/22] xfs: add error injection for lazy " Christoph Hellwig
2026-07-23 21:06   ` Darrick J. Wong
2026-07-23 14:49 ` [PATCH 22/22] xfs: log a message at mount time when using integrity protection Christoph Hellwig
2026-07-23 21:07   ` Darrick J. Wong
2026-07-24  6:25     ` Christoph Hellwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723210216.GI2901224@frogsfrogsfrogs \
    --to=djwong@kernel.org \
    --cc=anuj20.g@samsung.com \
    --cc=axboe@kernel.dk \
    --cc=brauner@kernel.org \
    --cc=cem@kernel.org \
    --cc=hch@lst.de \
    --cc=linux-block@vger.kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    --cc=tz2294@columbia.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox