Linux XFS filesystem development
 help / color / mirror / Atom feed
From: "Darrick J. Wong" <djwong@kernel.org>
To: Christoph Hellwig <hch@lst.de>
Cc: Carlos Maiolino <cem@kernel.org>, Jens Axboe <axboe@kernel.dk>,
	Christian Brauner <brauner@kernel.org>,
	linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org
Subject: Re: [PATCH 18/21] xfs: don't try to verify checksums on empty zones
Date: Mon, 28 Sep 2026 18:25:55 -0700	[thread overview]
Message-ID: <20260929012555.GZ2705364@frogsfrogsfrogs> (raw)
In-Reply-To: <20260924100032.2733101-19-hch@lst.de>

On Thu, Sep 24, 2026 at 11:59:50AM +0200, Christoph Hellwig wrote:
> xfs_scrub can sometimes send XFS_IOC_VERIFY_MEDIA ioctls for ranges
> that have never been written since the last zone reset, which will
> lead to checksum verification failures.

...and pointless work. :)

> Protect against this by checking that the range is valid.  If the report
> flag is set, a verification failure could lead to health reports and
> the file system being marked corrupt, so lock out zone racing reset
> completions for this case as well.
> 
> Signed-off-by: Christoph Hellwig <hch@lst.de>
> ---
>  fs/xfs/xfs_verify_media.c | 44 ++++++++++++++++++++++++++++++++++++---
>  1 file changed, 41 insertions(+), 3 deletions(-)
> 
> diff --git a/fs/xfs/xfs_verify_media.c b/fs/xfs/xfs_verify_media.c
> index 46a19405c9e5..fc739f7ffa4e 100644
> --- a/fs/xfs/xfs_verify_media.c
> +++ b/fs/xfs/xfs_verify_media.c
> @@ -25,6 +25,8 @@
>  #include "xfs_rtcsum.h"
>  #include "xfs_trace.h"
>  #include "xfs_verify_media.h"
> +#include "xfs_zone_alloc.h"
> +#include "xfs_zone_priv.h"
>  
>  #include <linux/fserror.h>
>  
> @@ -288,6 +290,43 @@ xfs_submit_verify_bio(
>  	return 0;
>  }
>  
> +static int
> +xfs_csum_verify_metafile(
> +	struct xfs_mount	*mp,
> +	struct bio		*bio,
> +	struct bvec_iter	*saved_iter,
> +	void			*csum_buf,
> +	xfs_fsblock_t		bno)
> +{
> +	struct xfs_rtgroup	*rtg;
> +	int			error = 0;
> +
> +	rtg = xfs_rtgroup_get(mp, xfs_rtb_to_rgno(mp, bno));
> +	if (!rtg)
> +		return -EFSCORRUPTED;
> +
> +	/*
> +	 * Only validate the checksums for valid data, as data never written
> +	 * will not have valid checksums.  We need to hold the ilock on the rmap
> +	 * inode to prevent freeing of blocks and thus a zone reset to happen
> +	 * underneath us.
> +	 *
> +	 * Note that this still relies on cooperating userspace, as there also
> +	 * can be blocks that were written but never recorded after an unclean
> +	 * shutdown, which this check does not catch.  It purely tries to deal
> +	 * with races vs the previous FSMAP output used by xfs_scrub.

Just a general note -- if the csum update never makes it to disk, then
the remap cannot have been written to disk either.  Therefore, fsmap
will report that as unowned space, and xfs_scrub won't try to
read-verify it, given the xfs_scrub patch you post later to only read rt
blocks for which there are rmap records.

So I think this is only a theoretical concern, right?

The code looks fine to me, so
Reviewed-by: "Darrick J. Wong" <djwong@kernel.org>

--D

> +	 */
> +	xfs_ilock(rtg_rmap(rtg), XFS_ILOCK_SHARED);
> +	if (!xa_get_mark(&mp->m_groups[XG_TYPE_RTG].xa, rtg_rgno(rtg),
> +			XFS_RTG_FREE)) {
> +		error = xfs_csum_verify(mp, bio, saved_iter, csum_buf, bno,
> +				false);
> +	}
> +	xfs_iunlock(rtg_rmap(rtg), XFS_ILOCK_SHARED);
> +	xfs_rtgroup_put(rtg);
> +	return error;
> +}
> +
>  static int
>  xfs_submit_verify_bio_csum(
>  	struct xfs_mount	*mp,
> @@ -332,9 +371,8 @@ xfs_submit_verify_bio_csum(
>  	if (error)
>  		goto out_buf_rele;
>  
> -	error = xfs_csum_verify(mp, &bio, &saved_iter,
> -			csum_bp->b_addr + xfs_rtb_to_rtcsumoff(mp, bno), bno,
> -			false);
> +	error = xfs_csum_verify_metafile(mp, &bio, &saved_iter,
> +			csum_bp->b_addr + xfs_rtb_to_rtcsumoff(mp, bno), bno);
>  	if (error)
>  		goto out_media_error;
>  
> -- 
> 2.53.0
> 
> 

  reply	other threads:[~2026-09-29  1:25 UTC|newest]

Thread overview: 69+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  9:59 support for RT data checksums Christoph Hellwig
2026-09-24  9:59 ` [PATCH 01/21] block: export fs_bio_integrity_verify Christoph Hellwig
2026-09-24 20:29   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 02/21] iomap: add support for data checksumming Christoph Hellwig
2026-09-24 21:39   ` Darrick J. Wong
2026-09-25  5:53     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 03/21] xfs: add a xfs_buf_read_async buffer cache API Christoph Hellwig
2026-09-24 21:43   ` Darrick J. Wong
2026-09-25  5:54     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 04/21] xfs: add xfs_daddr_to_rgno and xfs_daddr_to_rgbno helpers Christoph Hellwig
2026-09-24 21:44   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 05/21] xfs: introduce XFS_BLI_PREALLOC Christoph Hellwig
2026-09-24 21:49   ` Darrick J. Wong
2026-09-25  5:57     ` Christoph Hellwig
2026-10-08 11:46   ` Anuj gupta
2026-09-24  9:59 ` [PATCH 06/21] xfs: prepare xfs_rtfile_initialize_blocks for larger than FSB blocks Christoph Hellwig
2026-09-24 22:03   ` Darrick J. Wong
2026-09-25  5:58     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 07/21] xfs: relase zi_open_zones_lock over xfs_open_zone_put on unmount Christoph Hellwig
2026-09-24  9:59 ` [PATCH 08/21] xfs: define the RT data checksum on-disk format Christoph Hellwig
2026-09-24 22:13   ` Darrick J. Wong
2026-09-25  0:04     ` Eric Biggers
2026-09-25  6:01     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 09/21] xfs: add support for per-RTG csum files Christoph Hellwig
2026-09-24 22:24   ` Darrick J. Wong
2026-09-25  6:10     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 10/21] xfs: calculate the log reservation for logging data checksum buffers Christoph Hellwig
2026-09-24 22:30   ` Darrick J. Wong
2026-09-25  6:12     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 11/21] xfs: core RT data checksum support Christoph Hellwig
2026-09-25 23:20   ` Darrick J. Wong
2026-09-26  6:13     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 12/21] xfs: data checksums require stable writes Christoph Hellwig
2026-09-25 23:21   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 13/21] xfs: require file system block size alignment when using data checksums Christoph Hellwig
2026-09-25 23:24   ` Darrick J. Wong
2026-09-26  6:15     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 14/21] xfs: add support for reading with " Christoph Hellwig
2026-09-29  0:42   ` Darrick J. Wong
2026-10-05 12:59     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 15/21] xfs: add support for writing " Christoph Hellwig
2026-09-29  1:01   ` Darrick J. Wong
2026-10-05 13:00     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 16/21] xfs: add data checksum support to zoned garbage collection Christoph Hellwig
2026-09-29  1:06   ` Darrick J. Wong
2026-10-05 13:11     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 17/21] xfs: verify data checksums during media verification Christoph Hellwig
2026-09-29  1:19   ` Darrick J. Wong
2026-10-05 13:13     ` Christoph Hellwig
2026-09-24  9:59 ` [PATCH 18/21] xfs: don't try to verify checksums on empty zones Christoph Hellwig
2026-09-29  1:25   ` Darrick J. Wong [this message]
2026-10-05 13:14     ` Christoph Hellwig
2026-10-08 11:43   ` Anuj gupta
2026-09-24  9:59 ` [PATCH 19/21] xfs: report RT data checksum information via XFS_FSOP_GEOM Christoph Hellwig
2026-09-29  1:26   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 20/21] xfs: add an experimental feature warning for RT data checksums Christoph Hellwig
2026-09-29  1:27   ` Darrick J. Wong
2026-09-24  9:59 ` [PATCH 21/21] xfs: enable " Christoph Hellwig
2026-09-29  1:27   ` Darrick J. Wong
2026-10-05 13:16     ` Christoph Hellwig
2026-09-24 22:52 ` support for " Dave Chinner
2026-09-25  6:27   ` Christoph Hellwig
2026-09-27 22:59     ` Dave Chinner
2026-09-28  5:24       ` Christoph Hellwig
2026-09-29 14:11         ` Dave Chinner
2026-09-30  7:11           ` Dave Chinner
2026-10-05 13:53             ` Christoph Hellwig
2026-10-06  5:31               ` Dave Chinner
2026-10-07 13:46                 ` Christoph Hellwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929012555.GZ2705364@frogsfrogsfrogs \
    --to=djwong@kernel.org \
    --cc=axboe@kernel.dk \
    --cc=brauner@kernel.org \
    --cc=cem@kernel.org \
    --cc=hch@lst.de \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-xfs@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox