From: "Darrick J. Wong" <djwong@kernel.org>
To: Andrey Albershteyn <aalbersh@kernel.org>
Cc: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev,
linux-fsdevel@vger.kernel.org, ebiggers@kernel.org, hch@lst.de,
linux-ext4@vger.kernel.org,
linux-f2fs-devel@lists.sourceforge.net,
linux-btrfs@vger.kernel.org
Subject: Re: [PATCH v6 14/22] xfs: use read ioend for fsverity data verification
Date: Tue, 31 Mar 2026 16:34:13 -0700 [thread overview]
Message-ID: <20260331233413.GH6223@frogsfrogsfrogs> (raw)
In-Reply-To: <20260331212827.2631020-15-aalbersh@kernel.org>
On Tue, Mar 31, 2026 at 11:28:15PM +0200, Andrey Albershteyn wrote:
> Use read ioends for fsverity verification. Do not issues fsverity
> metadata I/O through the same workqueue due to risk of a deadlock by a
> filled workqueue.
>
> Pass fsverity_info from iomap context down to the ioend as hashtable
> lookups are expensive.
>
> Add a simple helper to check that this is not fsverity metadata but file
> data that needs verification.
>
> Reviewed-by: Christoph Hellwig <hch@lst.de>
> Signed-off-by: Andrey Albershteyn <aalbersh@kernel.org>
Looks fine to me still,
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>
--D
> ---
> fs/xfs/xfs_aops.c | 46 ++++++++++++++++++++++++++++++++++---------
> fs/xfs/xfs_fsverity.c | 9 +++++++++
> fs/xfs/xfs_fsverity.h | 6 ++++++
> 3 files changed, 52 insertions(+), 9 deletions(-)
>
> diff --git a/fs/xfs/xfs_aops.c b/fs/xfs/xfs_aops.c
> index 9503252a0fa4..ecb07f250956 100644
> --- a/fs/xfs/xfs_aops.c
> +++ b/fs/xfs/xfs_aops.c
> @@ -24,6 +24,7 @@
> #include "xfs_rtgroup.h"
> #include "xfs_fsverity.h"
> #include <linux/bio-integrity.h>
> +#include <linux/fsverity.h>
>
> struct xfs_writepage_ctx {
> struct iomap_writepage_ctx ctx;
> @@ -171,6 +172,23 @@ xfs_end_ioend_write(
> memalloc_nofs_restore(nofs_flag);
> }
>
> +/*
> + * IO read completion.
> + */
> +static void
> +xfs_end_ioend_read(
> + struct iomap_ioend *ioend)
> +{
> + struct xfs_inode *ip = XFS_I(ioend->io_inode);
> +
> + if (!ioend->io_bio.bi_status &&
> + xfs_fsverity_is_file_data(ip, ioend->io_offset))
> + fsverity_verify_bio(ioend->io_vi,
> + &ioend->io_bio);
> + iomap_finish_ioends(ioend,
> + blk_status_to_errno(ioend->io_bio.bi_status));
> +}
> +
> /*
> * Finish all pending IO completions that require transactional modifications.
> *
> @@ -205,8 +223,7 @@ xfs_end_io(
> list_del_init(&ioend->io_list);
> iomap_ioend_try_merge(ioend, &tmp);
> if (bio_op(&ioend->io_bio) == REQ_OP_READ)
> - iomap_finish_ioends(ioend,
> - blk_status_to_errno(ioend->io_bio.bi_status));
> + xfs_end_ioend_read(ioend);
> else
> xfs_end_ioend_write(ioend);
> cond_resched();
> @@ -232,9 +249,14 @@ xfs_end_bio(
> }
>
> spin_lock_irqsave(&ip->i_ioend_lock, flags);
> - if (list_empty(&ip->i_ioend_list))
> - WARN_ON_ONCE(!queue_work(mp->m_unwritten_workqueue,
> + if (list_empty(&ip->i_ioend_list)) {
> + if (IS_ENABLED(CONFIG_FS_VERITY) && ioend->io_vi &&
> + ioend->io_offset < xfs_fsverity_metadata_offset(ip))
> + fsverity_enqueue_verify_work(&ip->i_ioend_work);
> + else
> + WARN_ON_ONCE(!queue_work(mp->m_unwritten_workqueue,
> &ip->i_ioend_work));
> + }
> list_add_tail(&ioend->io_list, &ip->i_ioend_list);
> spin_unlock_irqrestore(&ip->i_ioend_lock, flags);
> }
> @@ -764,9 +786,13 @@ xfs_bio_submit_read(
> struct iomap_read_folio_ctx *ctx)
> {
> struct bio *bio = ctx->read_ctx;
> + struct iomap_ioend *ioend;
>
> /* defer read completions to the ioend workqueue */
> - iomap_init_ioend(iter->inode, bio, ctx->read_ctx_file_offset, 0);
> + ioend = iomap_init_ioend(iter->inode, bio, ctx->read_ctx_file_offset,
> + 0);
> + ioend->io_vi = ctx->vi;
> +
> bio->bi_end_io = xfs_end_bio;
> submit_bio(bio);
> }
> @@ -779,11 +805,13 @@ static const struct iomap_read_ops xfs_iomap_read_ops = {
>
> static inline const struct iomap_read_ops *
> xfs_get_iomap_read_ops(
> - const struct address_space *mapping)
> + const struct address_space *mapping,
> + loff_t position)
> {
> struct xfs_inode *ip = XFS_I(mapping->host);
>
> - if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev))
> + if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev) ||
> + xfs_fsverity_is_file_data(ip, position))
> return &xfs_iomap_read_ops;
> return &iomap_bio_read_ops;
> }
> @@ -795,7 +823,7 @@ xfs_vm_read_folio(
> {
> struct iomap_read_folio_ctx ctx = { .cur_folio = folio };
>
> - ctx.ops = xfs_get_iomap_read_ops(folio->mapping);
> + ctx.ops = xfs_get_iomap_read_ops(folio->mapping, folio_pos(folio));
> iomap_read_folio(&xfs_read_iomap_ops, &ctx, NULL);
> return 0;
> }
> @@ -806,7 +834,7 @@ xfs_vm_readahead(
> {
> struct iomap_read_folio_ctx ctx = { .rac = rac };
>
> - ctx.ops = xfs_get_iomap_read_ops(rac->mapping),
> + ctx.ops = xfs_get_iomap_read_ops(rac->mapping, readahead_pos(rac));
> iomap_readahead(&xfs_read_iomap_ops, &ctx, NULL);
> }
>
> diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c
> index 6e6a8636a577..b983e20bb5e1 100644
> --- a/fs/xfs/xfs_fsverity.c
> +++ b/fs/xfs/xfs_fsverity.c
> @@ -19,3 +19,12 @@ xfs_fsverity_metadata_offset(
> {
> return round_up(i_size_read(VFS_IC(ip)), XFS_FSVERITY_START_ALIGN);
> }
> +
> +bool
> +xfs_fsverity_is_file_data(
> + const struct xfs_inode *ip,
> + loff_t offset)
> +{
> + return fsverity_active(VFS_IC(ip)) &&
> + offset < xfs_fsverity_metadata_offset(ip);
> +}
> diff --git a/fs/xfs/xfs_fsverity.h b/fs/xfs/xfs_fsverity.h
> index 5771db2cd797..ec77ba571106 100644
> --- a/fs/xfs/xfs_fsverity.h
> +++ b/fs/xfs/xfs_fsverity.h
> @@ -9,12 +9,18 @@
>
> #ifdef CONFIG_FS_VERITY
> loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip);
> +bool xfs_fsverity_is_file_data(const struct xfs_inode *ip, loff_t offset);
> #else
> static inline loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip)
> {
> WARN_ON_ONCE(1);
> return ULLONG_MAX;
> }
> +static inline bool xfs_fsverity_is_file_data(const struct xfs_inode *ip,
> + loff_t offset)
> +{
> + return false;
> +}
> #endif /* CONFIG_FS_VERITY */
>
> #endif /* __XFS_FSVERITY_H__ */
> --
> 2.51.2
>
>
next prev parent reply other threads:[~2026-03-31 23:34 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-31 21:28 [PATCH v6 00/22] fs-verity support for XFS with post EOF merkle tree Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 01/22] fsverity: report validation errors through fserror to fsnotify Andrey Albershteyn
2026-04-01 21:19 ` Eric Biggers
2026-03-31 21:28 ` [PATCH v6 02/22] fsverity: expose ensure_fsverity_info() Andrey Albershteyn
2026-04-01 6:27 ` Christoph Hellwig
2026-04-01 22:02 ` Eric Biggers
2026-04-02 14:02 ` Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 03/22] fsverity: generate and store zero-block hash Andrey Albershteyn
2026-04-01 22:27 ` Eric Biggers
2026-04-02 14:47 ` Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 04/22] fsverity: pass digest size and hash of the empty block to ->write Andrey Albershteyn
2026-04-01 23:36 ` Eric Biggers
2026-03-31 21:28 ` [PATCH v6 05/22] fsverity: hoist pagecache_read from f2fs/ext4 to fsverity Andrey Albershteyn
2026-04-01 23:44 ` Eric Biggers
2026-03-31 21:28 ` [PATCH v6 06/22] iomap: introduce IOMAP_F_FSVERITY and teach writeback to handle fsverity Andrey Albershteyn
2026-04-01 6:28 ` Christoph Hellwig
2026-03-31 21:28 ` [PATCH v6 07/22] iomap: teach iomap to read files with fsverity Andrey Albershteyn
2026-03-31 23:30 ` Darrick J. Wong
2026-04-01 6:30 ` Christoph Hellwig
2026-03-31 21:28 ` [PATCH v6 08/22] iomap: introduce iomap_fsverity_write() for writing fsverity metadata Andrey Albershteyn
2026-03-31 23:32 ` Darrick J. Wong
2026-03-31 21:28 ` [PATCH v6 09/22] xfs: introduce fsverity on-disk changes Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 10/22] xfs: initialize fs-verity on file open Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 11/22] xfs: don't allow to enable DAX on fs-verity sealed inode Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 12/22] xfs: disable direct read path for fs-verity files Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 13/22] xfs: handle fsverity I/O in write/read path Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 14/22] xfs: use read ioend for fsverity data verification Andrey Albershteyn
2026-03-31 23:34 ` Darrick J. Wong [this message]
2026-03-31 21:28 ` [PATCH v6 15/22] xfs: add fs-verity support Andrey Albershteyn
2026-03-31 23:35 ` Darrick J. Wong
2026-04-01 23:57 ` Eric Biggers
2026-03-31 21:28 ` [PATCH v6 16/22] xfs: remove unwritten extents after preallocations in fsverity metadata Andrey Albershteyn
2026-03-31 23:36 ` Darrick J. Wong
2026-03-31 21:28 ` [PATCH v6 17/22] xfs: add fs-verity ioctls Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 18/22] xfs: advertise fs-verity being available on filesystem Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 19/22] xfs: check and repair the verity inode flag state Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 20/22] xfs: introduce health state for corrupted fsverity metadata Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 21/22] xfs: add fsverity traces Andrey Albershteyn
2026-04-01 6:31 ` Christoph Hellwig
2026-04-01 13:19 ` Andrey Albershteyn
2026-03-31 21:28 ` [PATCH v6 22/22] xfs: enable ro-compat fs-verity flag Andrey Albershteyn
2026-04-01 6:32 ` Christoph Hellwig
2026-04-01 6:32 ` [PATCH v6 00/22] fs-verity support for XFS with post EOF merkle tree Christoph Hellwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260331233413.GH6223@frogsfrogsfrogs \
--to=djwong@kernel.org \
--cc=aalbersh@kernel.org \
--cc=ebiggers@kernel.org \
--cc=fsverity@lists.linux.dev \
--cc=hch@lst.de \
--cc=linux-btrfs@vger.kernel.org \
--cc=linux-ext4@vger.kernel.org \
--cc=linux-f2fs-devel@lists.sourceforge.net \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-xfs@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox