Linux XFS filesystem development
 help / color / mirror / Atom feed
From: Christoph Hellwig <hch@lst.de>
To: Carlos Maiolino <cem@kernel.org>
Cc: "Darrick J . Wong" <djwong@kernel.org>,
	Jens Axboe <axboe@kernel.dk>,
	Christian Brauner <brauner@kernel.org>,
	linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org
Subject: support for RT data checksums
Date: Thu, 24 Sep 2026 11:59:32 +0200	[thread overview]
Message-ID: <20260924100032.2733101-1-hch@lst.de> (raw)

Hi all,

data checksums provide an additional safeguard against silent data loss.

In classic XFS they were hard to support because they need to be
atomically updated with the written data.  The zoned allocator solves
that problem because it always writes out of place, and the checksums
can be committed at the same as the metadata linking the newly written
file data into place.  In theory, a conventional allocator could be used
in combination with the always_cow option, but there are few upsides of
this compared to using the zoned allocator.

Data checksums are stored in per-realtime group files in the metadir,
similar to other modern RT metadata.  Unlike the checksum design in btrfs
or some other file system, the checksums are associated with the
physical blocks, and not with logical data in files.  This reduces the
mapping overhead, and significantly reduces the write amplification,
and also avoids duplicate checksums for reflinked files (although those
are not yet supported with the zoned allocator anyway).

The initial version provides two checksums algorithms: crc32c and crc64.
Both of those are cyclic redundancy check algorithms which provide known
good detection of bit flips that is better than general purpose hash
functions.  Both are not cryptographic hashes and thus do not provide any
kind of protection against intentional tampering with the data.
The crc32c parameters exactly match those use for xfs metadata checksums,
and also those used by the default btrfs checksum, and the NVMe PI
formats using crc32c.  The crc64 parameters exactly match those using
the NVMe PI formats using crc64.  crc32c provides reasonable assurance
for today's hardware, but might prove limiting for extremely large data
sets, crc64 fills that void, but probably warrants using > 4k file system
block sizes to amortize the overhead.

In this series the checksums are only used to check data integrity
and report issues with it.  That on it's own is a bit of a lame story,
but it is important as a building block for two additional features
under development:

 - exposing the checksum to userspace through io_uring with
   IORING_RW_ATTR_FLAG_PI.  A prototype of this exists, but it needs
   a bit more rework of common code than I'd like for the initial
   review.  As a side effect this support will also support salvaging
   data with bad checksums for analysis in userspace.
 - retrying reads through a different replica from RAID devices that
   provide it.  This has been proposed before and requires some
   hairy block layer infrastructure.  I have a prototype for MD-based
   mirrors that can be extended to other use cases.  The same mechanism
   can also be used to retry reads for the already checksum protected
   XFS metadata.

The performance drop when using data checksums is between not measurable
to about 2% for most workloads on HDD and SSD.  On fast enough SSDs
single threaded large reads can see up to 10% slow down as the
checksum validation runs on a strict per-cpu workqueue through the block
layer in-task bio completion.  If needed, different completion methods
that distribute the I/O completions could be added.

This series is based on the lazy bounce series queued up in a special
block branch, the prep series just send out and fixes queue up in
different maintainer tree, so it is best to use the git branch:

    git://git.infradead.org/users/hch/xfs.git xfs-crc

Gitweb:

    https://git.infradead.org/?p=users/hch/xfs.git;a=shortlog;h=refs/heads/xfs-crc

Note that the series will need a rebase on top of the fsverity work,
but the code points have been chosen to hopefully not conflict.

Diffstat:
 block/bio-integrity-fs.c       |    1 
 fs/iomap/bio.c                 |    3 
 fs/iomap/direct-io.c           |    2 
 fs/iomap/internal.h            |   21 ++
 fs/iomap/ioend.c               |   77 +++++++++
 fs/xfs/Kconfig                 |    1 
 fs/xfs/Makefile                |    2 
 fs/xfs/libxfs/xfs_cksum.h      |    7 
 fs/xfs/libxfs/xfs_format.h     |   46 +++++
 fs/xfs/libxfs/xfs_fs.h         |    6 
 fs/xfs/libxfs/xfs_health.h     |    4 
 fs/xfs/libxfs/xfs_log_format.h |    1 
 fs/xfs/libxfs/xfs_ondisk.h     |    4 
 fs/xfs/libxfs/xfs_rtbitmap.c   |   54 ++++--
 fs/xfs/libxfs/xfs_rtbitmap.h   |    3 
 fs/xfs/libxfs/xfs_rtcsumfile.c |   94 ++++++++++++
 fs/xfs/libxfs/xfs_rtcsumfile.h |  150 +++++++++++++++++++
 fs/xfs/libxfs/xfs_rtgroup.c    |   10 +
 fs/xfs/libxfs/xfs_rtgroup.h    |   26 +++
 fs/xfs/libxfs/xfs_sb.c         |   80 ++++++++++
 fs/xfs/libxfs/xfs_sb.h         |    1 
 fs/xfs/libxfs/xfs_shared.h     |    1 
 fs/xfs/libxfs/xfs_trans_resv.c |   23 ++
 fs/xfs/libxfs/xfs_trans_resv.h |    5 
 fs/xfs/scrub/agheader.c        |    5 
 fs/xfs/xfs_aops.c              |    4 
 fs/xfs/xfs_buf.c               |  130 +++++++++++++---
 fs/xfs/xfs_buf.h               |    4 
 fs/xfs/xfs_buf_item.c          |   10 +
 fs/xfs/xfs_buf_item.h          |    4 
 fs/xfs/xfs_buf_item_recover.c  |    7 
 fs/xfs/xfs_file.c              |   21 ++
 fs/xfs/xfs_inode.h             |    8 -
 fs/xfs/xfs_ioend.c             |  159 ++++++++++++++++++--
 fs/xfs/xfs_ioend.h             |    2 
 fs/xfs/xfs_iomap.c             |   72 ++++++++-
 fs/xfs/xfs_iomap.h             |    4 
 fs/xfs/xfs_iops.c              |   10 +
 fs/xfs/xfs_message.c           |    4 
 fs/xfs/xfs_message.h           |    1 
 fs/xfs/xfs_mount.h             |    9 +
 fs/xfs/xfs_platform.h          |    1 
 fs/xfs/xfs_reflink.c           |    2 
 fs/xfs/xfs_rtalloc.c           |   11 +
 fs/xfs/xfs_rtcsum.c            |  317 +++++++++++++++++++++++++++++++++++++++++
 fs/xfs/xfs_rtcsum.h            |   23 ++
 fs/xfs/xfs_super.c             |   14 +
 fs/xfs/xfs_sysfs.c             |    2 
 fs/xfs/xfs_trace.h             |    3 
 fs/xfs/xfs_verify_media.c      |  169 ++++++++++++++++++---
 fs/xfs/xfs_zone_alloc.c        |   40 ++++-
 fs/xfs/xfs_zone_gc.c           |   65 ++++++--
 fs/xfs/xfs_zone_priv.h         |    8 +
 include/linux/iomap.h          |   31 +++-
 54 files changed, 1619 insertions(+), 143 deletions(-)

             reply	other threads:[~2026-09-24 10:00 UTC|newest]

Thread overview: 69+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  9:59 Christoph Hellwig [this message]
2026-09-24  9:59 ` [PATCH 01/21] block: export fs_bio_integrity_verify Christoph Hellwig
2026-09-24 20:29   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 02/21] iomap: add support for data checksumming Christoph Hellwig
2026-09-24 21:39   ` Darrick J. Wong
2026-09-25  5:53     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 03/21] xfs: add a xfs_buf_read_async buffer cache API Christoph Hellwig
2026-09-24 21:43   ` Darrick J. Wong
2026-09-25  5:54     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 04/21] xfs: add xfs_daddr_to_rgno and xfs_daddr_to_rgbno helpers Christoph Hellwig
2026-09-24 21:44   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 05/21] xfs: introduce XFS_BLI_PREALLOC Christoph Hellwig
2026-09-24 21:49   ` Darrick J. Wong
2026-09-25  5:57     ` Christoph Hellwig
2026-10-08 11:46   ` Anuj gupta
2026-09-24  9:59 ` [PATCH 06/21] xfs: prepare xfs_rtfile_initialize_blocks for larger than FSB blocks Christoph Hellwig
2026-09-24 22:03   ` Darrick J. Wong
2026-09-25  5:58     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 07/21] xfs: relase zi_open_zones_lock over xfs_open_zone_put on unmount Christoph Hellwig
2026-09-24  9:59 ` [PATCH 08/21] xfs: define the RT data checksum on-disk format Christoph Hellwig
2026-09-24 22:13   ` Darrick J. Wong
2026-09-25  0:04     ` Eric Biggers
2026-09-25  6:01     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 09/21] xfs: add support for per-RTG csum files Christoph Hellwig
2026-09-24 22:24   ` Darrick J. Wong
2026-09-25  6:10     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 10/21] xfs: calculate the log reservation for logging data checksum buffers Christoph Hellwig
2026-09-24 22:30   ` Darrick J. Wong
2026-09-25  6:12     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 11/21] xfs: core RT data checksum support Christoph Hellwig
2026-09-25 23:20   ` Darrick J. Wong
2026-09-26  6:13     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 12/21] xfs: data checksums require stable writes Christoph Hellwig
2026-09-25 23:21   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 13/21] xfs: require file system block size alignment when using data checksums Christoph Hellwig
2026-09-25 23:24   ` Darrick J. Wong
2026-09-26  6:15     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 14/21] xfs: add support for reading with " Christoph Hellwig
2026-09-29  0:42   ` Darrick J. Wong
2026-10-05 12:59     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 15/21] xfs: add support for writing " Christoph Hellwig
2026-09-29  1:01   ` Darrick J. Wong
2026-10-05 13:00     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 16/21] xfs: add data checksum support to zoned garbage collection Christoph Hellwig
2026-09-29  1:06   ` Darrick J. Wong
2026-10-05 13:11     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 17/21] xfs: verify data checksums during media verification Christoph Hellwig
2026-09-29  1:19   ` Darrick J. Wong
2026-10-05 13:13     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 18/21] xfs: don't try to verify checksums on empty zones Christoph Hellwig
2026-09-29  1:25   ` Darrick J. Wong
2026-10-05 13:14     ` Christoph Hellwig
2026-10-08 11:43   ` Anuj gupta
2026-09-24  9:59 ` [PATCH 19/21] xfs: report RT data checksum information via XFS_FSOP_GEOM Christoph Hellwig
2026-09-29  1:26   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 20/21] xfs: add an experimental feature warning for RT data checksums Christoph Hellwig
2026-09-29  1:27   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 21/21] xfs: enable " Christoph Hellwig
2026-09-29  1:27   ` Darrick J. Wong
2026-10-05 13:16     ` Christoph Hellwig
2026-09-24 22:52 ` support for " Dave Chinner
2026-09-25  6:27   ` Christoph Hellwig
2026-09-27 22:59     ` Dave Chinner
2026-09-28  5:24       ` Christoph Hellwig
2026-09-29 14:11         ` Dave Chinner
2026-09-30  7:11           ` Dave Chinner
2026-10-05 13:53             ` Christoph Hellwig
2026-10-06  5:31               ` Dave Chinner
2026-10-07 13:46                 ` Christoph Hellwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924100032.2733101-1-hch@lst.de \
    --to=hch@lst.de \
    --cc=axboe@kernel.dk \
    --cc=brauner@kernel.org \
    --cc=cem@kernel.org \
    --cc=djwong@kernel.org \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox