2 * Copyright (c) 2000-2006 Silicon Graphics, Inc.
5 * This program is free software; you can redistribute it and/or
6 * modify it under the terms of the GNU General Public License as
7 * published by the Free Software Foundation.
9 * This program is distributed in the hope that it would be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write the Free Software Foundation,
16 * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
20 #include "xfs_types.h"
24 #include "xfs_trans.h"
28 #include "xfs_dmapi.h"
29 #include "xfs_mount.h"
30 #include "xfs_bmap_btree.h"
31 #include "xfs_alloc_btree.h"
32 #include "xfs_ialloc_btree.h"
33 #include "xfs_dir2_sf.h"
34 #include "xfs_attr_sf.h"
35 #include "xfs_dinode.h"
36 #include "xfs_inode.h"
37 #include "xfs_inode_item.h"
39 #include "xfs_btree.h"
40 #include "xfs_ialloc.h"
41 #include "xfs_itable.h"
42 #include "xfs_dfrag.h"
43 #include "xfs_error.h"
45 #include "xfs_vnodeops.h"
46 #include "xfs_trace.h"
49 static int xfs_swap_extents(
50 xfs_inode_t
*ip
, /* target inode */
51 xfs_inode_t
*tip
, /* tmp inode */
55 * ioctl interface for swapext
61 xfs_inode_t
*ip
, *tip
;
62 struct file
*file
, *tmp_file
;
65 /* Pull information for the target fd */
66 file
= fget((int)sxp
->sx_fdtarget
);
68 error
= XFS_ERROR(EINVAL
);
72 if (!(file
->f_mode
& FMODE_WRITE
) ||
73 !(file
->f_mode
& FMODE_READ
) ||
74 (file
->f_flags
& O_APPEND
)) {
75 error
= XFS_ERROR(EBADF
);
79 tmp_file
= fget((int)sxp
->sx_fdtmp
);
81 error
= XFS_ERROR(EINVAL
);
85 if (!(tmp_file
->f_mode
& FMODE_WRITE
) ||
86 !(tmp_file
->f_mode
& FMODE_READ
) ||
87 (tmp_file
->f_flags
& O_APPEND
)) {
88 error
= XFS_ERROR(EBADF
);
89 goto out_put_tmp_file
;
92 if (IS_SWAPFILE(file
->f_path
.dentry
->d_inode
) ||
93 IS_SWAPFILE(tmp_file
->f_path
.dentry
->d_inode
)) {
94 error
= XFS_ERROR(EINVAL
);
95 goto out_put_tmp_file
;
98 ip
= XFS_I(file
->f_path
.dentry
->d_inode
);
99 tip
= XFS_I(tmp_file
->f_path
.dentry
->d_inode
);
101 if (ip
->i_mount
!= tip
->i_mount
) {
102 error
= XFS_ERROR(EINVAL
);
103 goto out_put_tmp_file
;
106 if (ip
->i_ino
== tip
->i_ino
) {
107 error
= XFS_ERROR(EINVAL
);
108 goto out_put_tmp_file
;
111 if (XFS_FORCED_SHUTDOWN(ip
->i_mount
)) {
112 error
= XFS_ERROR(EIO
);
113 goto out_put_tmp_file
;
116 error
= xfs_swap_extents(ip
, tip
, sxp
);
127 * We need to check that the format of the data fork in the temporary inode is
128 * valid for the target inode before doing the swap. This is not a problem with
129 * attr1 because of the fixed fork offset, but attr2 has a dynamically sized
130 * data fork depending on the space the attribute fork is taking so we can get
131 * invalid formats on the target inode.
133 * E.g. target has space for 7 extents in extent format, temp inode only has
134 * space for 6. If we defragment down to 7 extents, then the tmp format is a
135 * btree, but when swapped it needs to be in extent format. Hence we can't just
136 * blindly swap data forks on attr2 filesystems.
138 * Note that we check the swap in both directions so that we don't end up with
139 * a corrupt temporary inode, either.
141 * Note that fixing the way xfs_fsr sets up the attribute fork in the source
142 * inode will prevent this situation from occurring, so all we do here is
143 * reject and log the attempt. basically we are putting the responsibility on
144 * userspace to get this right.
147 xfs_swap_extents_check_format(
148 xfs_inode_t
*ip
, /* target inode */
149 xfs_inode_t
*tip
) /* tmp inode */
152 /* Should never get a local format */
153 if (ip
->i_d
.di_format
== XFS_DINODE_FMT_LOCAL
||
154 tip
->i_d
.di_format
== XFS_DINODE_FMT_LOCAL
)
158 * if the target inode has less extents that then temporary inode then
159 * why did userspace call us?
161 if (ip
->i_d
.di_nextents
< tip
->i_d
.di_nextents
)
165 * if the target inode is in extent form and the temp inode is in btree
166 * form then we will end up with the target inode in the wrong format
167 * as we already know there are less extents in the temp inode.
169 if (ip
->i_d
.di_format
== XFS_DINODE_FMT_EXTENTS
&&
170 tip
->i_d
.di_format
== XFS_DINODE_FMT_BTREE
)
173 /* Check temp in extent form to max in target */
174 if (tip
->i_d
.di_format
== XFS_DINODE_FMT_EXTENTS
&&
175 XFS_IFORK_NEXTENTS(tip
, XFS_DATA_FORK
) > ip
->i_df
.if_ext_max
)
178 /* Check target in extent form to max in temp */
179 if (ip
->i_d
.di_format
== XFS_DINODE_FMT_EXTENTS
&&
180 XFS_IFORK_NEXTENTS(ip
, XFS_DATA_FORK
) > tip
->i_df
.if_ext_max
)
184 * If we are in a btree format, check that the temp root block will fit
185 * in the target and that it has enough extents to be in btree format
188 * Note that we have to be careful to allow btree->extent conversions
189 * (a common defrag case) which will occur when the temp inode is in
192 if (tip
->i_d
.di_format
== XFS_DINODE_FMT_BTREE
&&
193 ((XFS_IFORK_BOFF(ip
) &&
194 tip
->i_df
.if_broot_bytes
> XFS_IFORK_BOFF(ip
)) ||
195 XFS_IFORK_NEXTENTS(tip
, XFS_DATA_FORK
) <= ip
->i_df
.if_ext_max
))
198 /* Reciprocal target->temp btree format checks */
199 if (ip
->i_d
.di_format
== XFS_DINODE_FMT_BTREE
&&
200 ((XFS_IFORK_BOFF(tip
) &&
201 ip
->i_df
.if_broot_bytes
> XFS_IFORK_BOFF(tip
)) ||
202 XFS_IFORK_NEXTENTS(ip
, XFS_DATA_FORK
) <= tip
->i_df
.if_ext_max
))
210 xfs_inode_t
*ip
, /* target inode */
211 xfs_inode_t
*tip
, /* tmp inode */
216 xfs_bstat_t
*sbp
= &sxp
->sx_stat
;
217 xfs_ifork_t
*tempifp
, *ifp
, *tifp
;
218 int ilf_fields
, tilf_fields
;
226 tempifp
= kmem_alloc(sizeof(xfs_ifork_t
), KM_MAYFAIL
);
228 error
= XFS_ERROR(ENOMEM
);
235 * we have to do two separate lock calls here to keep lockdep
236 * happy. If we try to get all the locks in one call, lock will
237 * report false positives when we drop the ILOCK and regain them
240 xfs_lock_two_inodes(ip
, tip
, XFS_IOLOCK_EXCL
);
241 xfs_lock_two_inodes(ip
, tip
, XFS_ILOCK_EXCL
);
243 /* Verify that both files have the same format */
244 if ((ip
->i_d
.di_mode
& S_IFMT
) != (tip
->i_d
.di_mode
& S_IFMT
)) {
245 error
= XFS_ERROR(EINVAL
);
249 /* Verify both files are either real-time or non-realtime */
250 if (XFS_IS_REALTIME_INODE(ip
) != XFS_IS_REALTIME_INODE(tip
)) {
251 error
= XFS_ERROR(EINVAL
);
255 if (VN_CACHED(VFS_I(tip
)) != 0) {
256 error
= xfs_flushinval_pages(tip
, 0, -1,
262 /* Verify O_DIRECT for ftmp */
263 if (VN_CACHED(VFS_I(tip
)) != 0) {
264 error
= XFS_ERROR(EINVAL
);
268 /* Verify all data are being swapped */
269 if (sxp
->sx_offset
!= 0 ||
270 sxp
->sx_length
!= ip
->i_d
.di_size
||
271 sxp
->sx_length
!= tip
->i_d
.di_size
) {
272 error
= XFS_ERROR(EFAULT
);
276 trace_xfs_swap_extent_before(ip
, 0);
277 trace_xfs_swap_extent_before(tip
, 1);
279 /* check inode formats now that data is flushed */
280 error
= xfs_swap_extents_check_format(ip
, tip
);
282 xfs_fs_cmn_err(CE_NOTE
, mp
,
283 "%s: inode 0x%llx format is incompatible for exchanging.",
284 __FILE__
, ip
->i_ino
);
289 * Compare the current change & modify times with that
290 * passed in. If they differ, we abort this swap.
291 * This is the mechanism used to ensure the calling
292 * process that the file was not changed out from
295 if ((sbp
->bs_ctime
.tv_sec
!= VFS_I(ip
)->i_ctime
.tv_sec
) ||
296 (sbp
->bs_ctime
.tv_nsec
!= VFS_I(ip
)->i_ctime
.tv_nsec
) ||
297 (sbp
->bs_mtime
.tv_sec
!= VFS_I(ip
)->i_mtime
.tv_sec
) ||
298 (sbp
->bs_mtime
.tv_nsec
!= VFS_I(ip
)->i_mtime
.tv_nsec
)) {
299 error
= XFS_ERROR(EBUSY
);
303 /* We need to fail if the file is memory mapped. Once we have tossed
304 * all existing pages, the page fault will have no option
305 * but to go to the filesystem for pages. By making the page fault call
306 * vop_read (or write in the case of autogrow) they block on the iolock
307 * until we have switched the extents.
309 if (VN_MAPPED(VFS_I(ip
))) {
310 error
= XFS_ERROR(EBUSY
);
314 xfs_iunlock(ip
, XFS_ILOCK_EXCL
);
315 xfs_iunlock(tip
, XFS_ILOCK_EXCL
);
318 * There is a race condition here since we gave up the
319 * ilock. However, the data fork will not change since
320 * we have the iolock (locked for truncation too) so we
321 * are safe. We don't really care if non-io related
325 xfs_tosspages(ip
, 0, -1, FI_REMAPF
);
327 tp
= xfs_trans_alloc(mp
, XFS_TRANS_SWAPEXT
);
328 if ((error
= xfs_trans_reserve(tp
, 0,
329 XFS_ICHANGE_LOG_RES(mp
), 0,
331 xfs_iunlock(ip
, XFS_IOLOCK_EXCL
);
332 xfs_iunlock(tip
, XFS_IOLOCK_EXCL
);
333 xfs_trans_cancel(tp
, 0);
336 xfs_lock_two_inodes(ip
, tip
, XFS_ILOCK_EXCL
);
339 * Count the number of extended attribute blocks
341 if ( ((XFS_IFORK_Q(ip
) != 0) && (ip
->i_d
.di_anextents
> 0)) &&
342 (ip
->i_d
.di_aformat
!= XFS_DINODE_FMT_LOCAL
)) {
343 error
= xfs_bmap_count_blocks(tp
, ip
, XFS_ATTR_FORK
, &aforkblks
);
345 goto out_trans_cancel
;
347 if ( ((XFS_IFORK_Q(tip
) != 0) && (tip
->i_d
.di_anextents
> 0)) &&
348 (tip
->i_d
.di_aformat
!= XFS_DINODE_FMT_LOCAL
)) {
349 error
= xfs_bmap_count_blocks(tp
, tip
, XFS_ATTR_FORK
,
352 goto out_trans_cancel
;
356 * Swap the data forks of the inodes
360 *tempifp
= *ifp
; /* struct copy */
361 *ifp
= *tifp
; /* struct copy */
362 *tifp
= *tempifp
; /* struct copy */
365 * Fix the in-memory data fork values that are dependent on the fork
366 * offset in the inode. We can't assume they remain the same as attr2
367 * has dynamic fork offsets.
369 ifp
->if_ext_max
= XFS_IFORK_SIZE(ip
, XFS_DATA_FORK
) /
370 (uint
)sizeof(xfs_bmbt_rec_t
);
371 tifp
->if_ext_max
= XFS_IFORK_SIZE(tip
, XFS_DATA_FORK
) /
372 (uint
)sizeof(xfs_bmbt_rec_t
);
375 * Fix the on-disk inode values
377 tmp
= (__uint64_t
)ip
->i_d
.di_nblocks
;
378 ip
->i_d
.di_nblocks
= tip
->i_d
.di_nblocks
- taforkblks
+ aforkblks
;
379 tip
->i_d
.di_nblocks
= tmp
+ taforkblks
- aforkblks
;
381 tmp
= (__uint64_t
) ip
->i_d
.di_nextents
;
382 ip
->i_d
.di_nextents
= tip
->i_d
.di_nextents
;
383 tip
->i_d
.di_nextents
= tmp
;
385 tmp
= (__uint64_t
) ip
->i_d
.di_format
;
386 ip
->i_d
.di_format
= tip
->i_d
.di_format
;
387 tip
->i_d
.di_format
= tmp
;
389 ilf_fields
= XFS_ILOG_CORE
;
391 switch(ip
->i_d
.di_format
) {
392 case XFS_DINODE_FMT_EXTENTS
:
393 /* If the extents fit in the inode, fix the
394 * pointer. Otherwise it's already NULL or
395 * pointing to the extent.
397 if (ip
->i_d
.di_nextents
<= XFS_INLINE_EXTS
) {
398 ifp
->if_u1
.if_extents
=
399 ifp
->if_u2
.if_inline_ext
;
401 ilf_fields
|= XFS_ILOG_DEXT
;
403 case XFS_DINODE_FMT_BTREE
:
404 ilf_fields
|= XFS_ILOG_DBROOT
;
408 tilf_fields
= XFS_ILOG_CORE
;
410 switch(tip
->i_d
.di_format
) {
411 case XFS_DINODE_FMT_EXTENTS
:
412 /* If the extents fit in the inode, fix the
413 * pointer. Otherwise it's already NULL or
414 * pointing to the extent.
416 if (tip
->i_d
.di_nextents
<= XFS_INLINE_EXTS
) {
417 tifp
->if_u1
.if_extents
=
418 tifp
->if_u2
.if_inline_ext
;
420 tilf_fields
|= XFS_ILOG_DEXT
;
422 case XFS_DINODE_FMT_BTREE
:
423 tilf_fields
|= XFS_ILOG_DBROOT
;
429 xfs_trans_ijoin(tp
, ip
, XFS_ILOCK_EXCL
| XFS_IOLOCK_EXCL
);
432 xfs_trans_ijoin(tp
, tip
, XFS_ILOCK_EXCL
| XFS_IOLOCK_EXCL
);
434 xfs_trans_log_inode(tp
, ip
, ilf_fields
);
435 xfs_trans_log_inode(tp
, tip
, tilf_fields
);
438 * If this is a synchronous mount, make sure that the
439 * transaction goes to disk before returning to the user.
441 if (mp
->m_flags
& XFS_MOUNT_WSYNC
)
442 xfs_trans_set_sync(tp
);
444 error
= xfs_trans_commit(tp
, XFS_TRANS_SWAPEXT
);
446 trace_xfs_swap_extent_after(ip
, 0);
447 trace_xfs_swap_extent_after(tip
, 1);
453 xfs_iunlock(ip
, XFS_ILOCK_EXCL
| XFS_IOLOCK_EXCL
);
454 xfs_iunlock(tip
, XFS_ILOCK_EXCL
| XFS_IOLOCK_EXCL
);
458 xfs_trans_cancel(tp
, 0);