From: Andreas Dilger <adilger@clusterfs.com>
To: Eric Sandeen <sandeen@redhat.com>
Cc: ext4 development <linux-ext4@vger.kernel.org>
Subject: Re: [PATCH/RFC] - make ext3 more robust in the face of filesystem corruption
Date: Wed, 18 Oct 2006 16:24:49 -0600 [thread overview]
Message-ID: <20061018222449.GK3509@schatzie.adilger.int> (raw)
In-Reply-To: <4536A31F.5050604@redhat.com>
On Oct 18, 2006 16:56 -0500, Eric Sandeen wrote:
> Andreas Dilger wrote:
> > The directory leaf data is kept in
> > the page cache and there is a helper function ext2_check_page() to mark
> > the page "checked". That means the page only needs to be checked once
> > after being read from disk, instead of each time through readdir.
>
> ah, sure. Hm... well, this might be a bit of a performance hit if it's
> checking cached data... let me think on that.
Well, having something like "ext3_dir_bread()" that verifies the leaf block
once if (!uptodate()) would be almost the same as ext2 with fairly little
effort. It would help performance in several places, at the slight risk
of not handling in-memory corruption after the block is read...
> > I'm not sure whether this is a win or not. It means that if there is ever
> > a directory with a bad leaf block any entries beyond that block are not
> > accessible anymore.
>
> I'm amazed at how hard ext3 works to cope with bad blocks ;-)
It would fail all of your tests otherwise, right? That is one virtue of
ext2 having grown up in the days when bad blocks existed. Those days are
(sadly) coming back again, hence desire for fs-level checksums, etc.
> > The existing !bh case already marks the filesystem in
> > error. Maybe as a special case we can check in "if (!bh)" if i_size and
> > i_blocks make sense. Something like:
> >
> > if (!bh) {
> > :
> > :
> > + if (filp->f_pos > inode->i_blocks << 9) {
> > + break;
> > filp->f_pos += sb->s_blocksize - offset;
> > continue;
> > }
> >
> > This obviously won't help if the whole inode is bogus, but then nothing
> > will catch all errors.
>
> Yep, I'd thought maybe a size vs. blocks test might make sense; I think
> there can never legitimately be a sparse directory?
Not currently, though there was some desire to allow this during htree
development, to allow shrinking large-but-empty directories. Since this
already provokes an ext3_error() (which might be a panic()) to hit a hole
we can assume that this needs to be carefully implmemented.
> I guess if the intent is to soldier on in the face of adversity, it
> doesn't matter if it's an umappable offset or an IO error; ext3 wants to
> go ahead & try the next one block anyway. So the size test probably
> makes sense as a stopping point.
Well, it would also be possible to look into inode->i_blocks to see what
blocks exist past this offset, but that is complicated by the introduction
Cheers, Andreas
--
Andreas Dilger
Principal Software Engineer
Cluster File Systems, Inc.
next prev parent reply other threads:[~2006-10-18 22:24 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-10-18 21:11 [PATCH/RFC] - make ext3 more robust in the face of filesystem corruption Eric Sandeen
2006-10-18 21:40 ` Andreas Dilger
2006-10-18 21:56 ` Eric Sandeen
2006-10-18 22:24 ` Andreas Dilger [this message]
2006-10-19 0:26 ` Eric Sandeen
2006-10-19 7:35 ` Andreas Dilger
2006-10-19 16:04 ` Eric Sandeen
2006-10-19 22:43 ` Eric Sandeen
2006-10-20 3:50 ` Andreas Dilger
2006-10-20 4:00 ` Eric Sandeen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20061018222449.GK3509@schatzie.adilger.int \
--to=adilger@clusterfs.com \
--cc=linux-ext4@vger.kernel.org \
--cc=sandeen@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox