* [PATCH 0/3] CONFIG_VFS_DEBUG at last
@ 2025-02-05 18:38 Mateusz Guzik
2025-02-05 18:38 ` [PATCH 1/3] vfs: add initial support for CONFIG_VFS_DEBUG Mateusz Guzik
` (3 more replies)
0 siblings, 4 replies; 6+ messages in thread
From: Mateusz Guzik @ 2025-02-05 18:38 UTC (permalink / raw)
To: brauner; +Cc: viro, jack, linux-kernel, linux-fsdevel, Mateusz Guzik
This adds a super basic version just to get the mechanism going and
adds sample usage.
The macro set is incomplete (e.g., lack of locking macros) and
dump_inode routine fails to dump any state yet, to be implemented(tm).
I think despite the primitive state this is complete enough to start
sprinkling warns as necessary.
Mateusz Guzik (3):
vfs: add initial support for CONFIG_VFS_DEBUG
vfs: catch invalid modes in may_open
vfs: use the new debug macros in inode_set_cached_link()
fs/namei.c | 2 ++
include/linux/fs.h | 16 +++----------
include/linux/vfsdebug.h | 50 ++++++++++++++++++++++++++++++++++++++++
lib/Kconfig.debug | 9 ++++++++
4 files changed, 64 insertions(+), 13 deletions(-)
create mode 100644 include/linux/vfsdebug.h
--
2.43.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH 1/3] vfs: add initial support for CONFIG_VFS_DEBUG
2025-02-05 18:38 [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
@ 2025-02-05 18:38 ` Mateusz Guzik
2025-02-05 18:38 ` [PATCH 2/3] vfs: catch invalid modes in may_open Mateusz Guzik
` (2 subsequent siblings)
3 siblings, 0 replies; 6+ messages in thread
From: Mateusz Guzik @ 2025-02-05 18:38 UTC (permalink / raw)
To: brauner; +Cc: viro, jack, linux-kernel, linux-fsdevel, Mateusz Guzik
Small collection of macros taken from mmdebug.h
Signed-off-by: Mateusz Guzik <mjguzik@gmail.com>
---
include/linux/fs.h | 1 +
include/linux/vfsdebug.h | 50 ++++++++++++++++++++++++++++++++++++++++
lib/Kconfig.debug | 9 ++++++++
3 files changed, 60 insertions(+)
create mode 100644 include/linux/vfsdebug.h
diff --git a/include/linux/fs.h b/include/linux/fs.h
index 1437a3323731..034745af9702 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -2,6 +2,7 @@
#ifndef _LINUX_FS_H
#define _LINUX_FS_H
+#include <linux/vfsdebug.h>
#include <linux/linkage.h>
#include <linux/wait_bit.h>
#include <linux/kdev_t.h>
diff --git a/include/linux/vfsdebug.h b/include/linux/vfsdebug.h
new file mode 100644
index 000000000000..b1a2c776992a
--- /dev/null
+++ b/include/linux/vfsdebug.h
@@ -0,0 +1,50 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#ifndef LINUX_VFS_DEBUG_H
+#define LINUX_VFS_DEBUG_H 1
+
+#include <linux/bug.h>
+#include <linux/stringify.h>
+
+struct inode;
+
+#ifdef CONFIG_DEBUG_VFS
+/*
+ * TODO: add a proper inode dumping routine, this is a stub to get debug off the ground
+ */
+static inline void dump_inode(struct inode *inode, const char *reason) {
+ pr_crit("%s failed for inode %px", reason, inode);
+}
+#define VFS_BUG_ON(cond) BUG_ON(cond)
+#define VFS_WARN_ON(cond) (void)WARN_ON(cond)
+#define VFS_WARN_ON_ONCE(cond) (void)WARN_ON_ONCE(cond)
+#define VFS_WARN_ONCE(cond, format...) (void)WARN_ONCE(cond, format)
+#define VFS_WARN(cond, format...) (void)WARN(cond, format)
+
+#define VFS_BUG_ON_INODE(cond, inode) ({ \
+ if (unlikely(!!(cond))) { \
+ dump_inode(inode, "VFS_BUG_ON_INODE(" __stringify(cond)")");\
+ BUG_ON(1); \
+ } \
+})
+
+#define VFS_WARN_ON_INODE(cond, inode) ({ \
+ int __ret_warn = !!(cond); \
+ \
+ if (unlikely(__ret_warn)) { \
+ dump_inode(inode, "VFS_WARN_ON_INODE(" __stringify(cond)")");\
+ WARN_ON(1); \
+ } \
+ unlikely(__ret_warn); \
+})
+#else
+#define VFS_BUG_ON(cond) BUILD_BUG_ON_INVALID(cond)
+#define VFS_WARN_ON(cond) BUILD_BUG_ON_INVALID(cond)
+#define VFS_WARN_ON_ONCE(cond) BUILD_BUG_ON_INVALID(cond)
+#define VFS_WARN_ONCE(cond, format...) BUILD_BUG_ON_INVALID(cond)
+#define VFS_WARN(cond, format...) BUILD_BUG_ON_INVALID(cond)
+
+#define VFS_BUG_ON_INODE(cond, inode) VFS_BUG_ON(cond)
+#define VFS_WARN_ON_INODE(cond, inode) BUILD_BUG_ON_INVALID(cond)
+#endif /* CONFIG_DEBUG_VFS */
+
+#endif
diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
index 1af972a92d06..c08ce985c482 100644
--- a/lib/Kconfig.debug
+++ b/lib/Kconfig.debug
@@ -808,6 +808,15 @@ config ARCH_HAS_DEBUG_VM_PGTABLE
An architecture should select this when it can successfully
build and run DEBUG_VM_PGTABLE.
+config DEBUG_VFS
+ bool "Debug VFS"
+ depends on DEBUG_KERNEL
+ help
+ Enable this to turn on extended checks in the VFS layer that may impact
+ performance.
+
+ If unsure, say N.
+
config DEBUG_VM_IRQSOFF
def_bool DEBUG_VM && !PREEMPT_RT
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/3] vfs: catch invalid modes in may_open
2025-02-05 18:38 [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
2025-02-05 18:38 ` [PATCH 1/3] vfs: add initial support for CONFIG_VFS_DEBUG Mateusz Guzik
@ 2025-02-05 18:38 ` Mateusz Guzik
2025-02-05 18:38 ` [PATCH 3/3] vfs: use the new debug macros in inode_set_cached_link() Mateusz Guzik
2025-02-05 18:57 ` [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
3 siblings, 0 replies; 6+ messages in thread
From: Mateusz Guzik @ 2025-02-05 18:38 UTC (permalink / raw)
To: brauner; +Cc: viro, jack, linux-kernel, linux-fsdevel, Mateusz Guzik
Signed-off-by: Mateusz Guzik <mjguzik@gmail.com>
---
fs/namei.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/namei.c b/fs/namei.c
index 3ab9440c5b93..c2822fd94a8a 100644
--- a/fs/namei.c
+++ b/fs/namei.c
@@ -3415,6 +3415,8 @@ static int may_open(struct mnt_idmap *idmap, const struct path *path,
if ((acc_mode & MAY_EXEC) && path_noexec(path))
return -EACCES;
break;
+ default:
+ VFS_BUG_ON_INODE(0, inode);
}
error = inode_permission(idmap, inode, MAY_OPEN | acc_mode);
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 3/3] vfs: use the new debug macros in inode_set_cached_link()
2025-02-05 18:38 [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
2025-02-05 18:38 ` [PATCH 1/3] vfs: add initial support for CONFIG_VFS_DEBUG Mateusz Guzik
2025-02-05 18:38 ` [PATCH 2/3] vfs: catch invalid modes in may_open Mateusz Guzik
@ 2025-02-05 18:38 ` Mateusz Guzik
2025-02-05 18:57 ` [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
3 siblings, 0 replies; 6+ messages in thread
From: Mateusz Guzik @ 2025-02-05 18:38 UTC (permalink / raw)
To: brauner; +Cc: viro, jack, linux-kernel, linux-fsdevel, Mateusz Guzik
Signed-off-by: Mateusz Guzik <mjguzik@gmail.com>
---
include/linux/fs.h | 15 ++-------------
1 file changed, 2 insertions(+), 13 deletions(-)
diff --git a/include/linux/fs.h b/include/linux/fs.h
index 034745af9702..e71d58c7f59c 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -792,19 +792,8 @@ struct inode {
static inline void inode_set_cached_link(struct inode *inode, char *link, int linklen)
{
- int testlen;
-
- /*
- * TODO: patch it into a debug-only check if relevant macros show up.
- * In the meantime, since we are suffering strlen even on production kernels
- * to find the right length, do a fixup if the wrong value got passed.
- */
- testlen = strlen(link);
- if (testlen != linklen) {
- WARN_ONCE(1, "bad length passed for symlink [%s] (got %d, expected %d)",
- link, linklen, testlen);
- linklen = testlen;
- }
+ VFS_WARN_ON_INODE(strlen(link) != linklen, inode);
+ VFS_WARN_ON_INODE(inode->i_opflags & IOP_CACHED_LINK, inode);
inode->i_link = link;
inode->i_linklen = linklen;
inode->i_opflags |= IOP_CACHED_LINK;
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 0/3] CONFIG_VFS_DEBUG at last
2025-02-05 18:38 [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
` (2 preceding siblings ...)
2025-02-05 18:38 ` [PATCH 3/3] vfs: use the new debug macros in inode_set_cached_link() Mateusz Guzik
@ 2025-02-05 18:57 ` Mateusz Guzik
2025-02-06 9:46 ` Christian Brauner
3 siblings, 1 reply; 6+ messages in thread
From: Mateusz Guzik @ 2025-02-05 18:57 UTC (permalink / raw)
To: brauner; +Cc: viro, jack, linux-kernel, linux-fsdevel
On Wed, Feb 5, 2025 at 7:38 PM Mateusz Guzik <mjguzik@gmail.com> wrote:
>
> This adds a super basic version just to get the mechanism going and
> adds sample usage.
>
> The macro set is incomplete (e.g., lack of locking macros) and
> dump_inode routine fails to dump any state yet, to be implemented(tm).
>
> I think despite the primitive state this is complete enough to start
> sprinkling warns as necessary.
>
> Mateusz Guzik (3):
> vfs: add initial support for CONFIG_VFS_DEBUG
> vfs: catch invalid modes in may_open
> vfs: use the new debug macros in inode_set_cached_link()
>
> fs/namei.c | 2 ++
> include/linux/fs.h | 16 +++----------
> include/linux/vfsdebug.h | 50 ++++++++++++++++++++++++++++++++++++++++
> lib/Kconfig.debug | 9 ++++++++
> 4 files changed, 64 insertions(+), 13 deletions(-)
> create mode 100644 include/linux/vfsdebug.h
>
> --
> 2.43.0
>
The produced warn is ugly as sin:\, for example for that bad size:
[ 51.433206] VFS_WARN_ON_INODE(__builtin_choose_expr((sizeof(int) ==
sizeof(*(8 ? ((void *)((long)(__builtin_strlen(link)) * 0l)) : (int
*)8))), __builtin_strlen(link), __fortify_strlen(link)) != linklen)
failed for inode ff32f7c350c8aec8
maybe there is a way to work it around, the code is literally lifted
out of mmdebug.h so they presumably have the same problem
apart from that the assert in may_open is backwards, the code normally
is not reached.
anyhow I expect to send a v2, but will wait for feedback before I do
--
Mateusz Guzik <mjguzik gmail.com>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH 0/3] CONFIG_VFS_DEBUG at last
2025-02-05 18:57 ` [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
@ 2025-02-06 9:46 ` Christian Brauner
0 siblings, 0 replies; 6+ messages in thread
From: Christian Brauner @ 2025-02-06 9:46 UTC (permalink / raw)
To: Mateusz Guzik; +Cc: viro, jack, linux-kernel, linux-fsdevel
On Wed, Feb 05, 2025 at 07:57:07PM +0100, Mateusz Guzik wrote:
> On Wed, Feb 5, 2025 at 7:38 PM Mateusz Guzik <mjguzik@gmail.com> wrote:
> >
> > This adds a super basic version just to get the mechanism going and
> > adds sample usage.
> >
> > The macro set is incomplete (e.g., lack of locking macros) and
> > dump_inode routine fails to dump any state yet, to be implemented(tm).
> >
> > I think despite the primitive state this is complete enough to start
> > sprinkling warns as necessary.
> >
> > Mateusz Guzik (3):
> > vfs: add initial support for CONFIG_VFS_DEBUG
> > vfs: catch invalid modes in may_open
> > vfs: use the new debug macros in inode_set_cached_link()
> >
> > fs/namei.c | 2 ++
> > include/linux/fs.h | 16 +++----------
> > include/linux/vfsdebug.h | 50 ++++++++++++++++++++++++++++++++++++++++
> > lib/Kconfig.debug | 9 ++++++++
> > 4 files changed, 64 insertions(+), 13 deletions(-)
> > create mode 100644 include/linux/vfsdebug.h
> >
> > --
> > 2.43.0
> >
>
> The produced warn is ugly as sin:\, for example for that bad size:
> [ 51.433206] VFS_WARN_ON_INODE(__builtin_choose_expr((sizeof(int) ==
> sizeof(*(8 ? ((void *)((long)(__builtin_strlen(link)) * 0l)) : (int
> *)8))), __builtin_strlen(link), __fortify_strlen(link)) != linklen)
> failed for inode ff32f7c350c8aec8
>
> maybe there is a way to work it around, the code is literally lifted
> out of mmdebug.h so they presumably have the same problem
>
> apart from that the assert in may_open is backwards, the code normally
> is not reached.
>
> anyhow I expect to send a v2, but will wait for feedback before I do
I think it is overdue that we do something like this. Being able to be
more liberal with _meaningful_ asserts can help us in the long run.
So I'm supportive.
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2025-02-06 9:46 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-02-05 18:38 [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
2025-02-05 18:38 ` [PATCH 1/3] vfs: add initial support for CONFIG_VFS_DEBUG Mateusz Guzik
2025-02-05 18:38 ` [PATCH 2/3] vfs: catch invalid modes in may_open Mateusz Guzik
2025-02-05 18:38 ` [PATCH 3/3] vfs: use the new debug macros in inode_set_cached_link() Mateusz Guzik
2025-02-05 18:57 ` [PATCH 0/3] CONFIG_VFS_DEBUG at last Mateusz Guzik
2025-02-06 9:46 ` Christian Brauner
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox