Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

xfs: disallow marking previously dirty buffers as ordered

Ordered buffers are used in situations where the buffer is not
physically logged but must pass through the transaction/logging
pipeline for a particular transaction. As a result, ordered buffers
are not unpinned and written back until the transaction commits to
the log. Ordered buffers have a strict requirement that the target
buffer must not be currently dirty and resident in the log pipeline
at the time it is marked ordered. If a dirty+ordered buffer is
committed, the buffer is reinserted to the AIL but not physically
relogged at the LSN of the associated checkpoint. The buffer log
item is assigned the LSN of the latest checkpoint and the AIL
effectively releases the previously logged buffer content from the
active log before the buffer has been written back. If the tail
pushes forward and a filesystem crash occurs while in this state, an
inconsistent filesystem could result.

It is currently the caller responsibility to ensure an ordered
buffer is not already dirty from a previous modification. This is
unclear and error prone when not used in situations where it is
guaranteed a buffer has not been previously modified (such as new
metadata allocations).

To facilitate general purpose use of ordered buffers, update
xfs_trans_ordered_buf() to conditionally order the buffer based on
state of the log item and return the status of the result. If the
bli is dirty, do not order the buffer and return false. The caller
must either physically log the buffer (having acquired the
appropriate log reservation) or push it from the AIL to clean it
before it can be marked ordered in the current transaction.

Note that ordered buffers are currently only used in two situations:
1.) inode chunk allocation where previously logged buffers are not
possible and 2.) extent swap which will be updated to handle ordered
buffer failures in a separate patch.

Signed-off-by: Brian Foster <bfoster@redhat.com>
Reviewed-by: Darrick J. Wong <darrick.wong@oracle.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Darrick J. Wong <darrick.wong@oracle.com>

authored by

Brian Foster and committed by
Darrick J. Wong
a5814bce 6fb10d6d

+6 -3
+1 -1
fs/xfs/xfs_trans.h
··· 212 212 void xfs_trans_binval(xfs_trans_t *, struct xfs_buf *); 213 213 void xfs_trans_inode_buf(xfs_trans_t *, struct xfs_buf *); 214 214 void xfs_trans_stale_inode_buf(xfs_trans_t *, struct xfs_buf *); 215 - void xfs_trans_ordered_buf(xfs_trans_t *, struct xfs_buf *); 215 + bool xfs_trans_ordered_buf(xfs_trans_t *, struct xfs_buf *); 216 216 void xfs_trans_dquot_buf(xfs_trans_t *, struct xfs_buf *, uint); 217 217 void xfs_trans_inode_alloc_buf(xfs_trans_t *, struct xfs_buf *); 218 218 void xfs_trans_ichgtime(struct xfs_trans *, struct xfs_inode *, int);
+5 -2
fs/xfs/xfs_trans_buf.c
··· 724 724 * transactions rather than the physical changes we make to the buffer without 725 725 * changing writeback ordering constraints of metadata buffers. 726 726 */ 727 - void 727 + bool 728 728 xfs_trans_ordered_buf( 729 729 struct xfs_trans *tp, 730 730 struct xfs_buf *bp) ··· 734 734 ASSERT(bp->b_transp == tp); 735 735 ASSERT(bip != NULL); 736 736 ASSERT(atomic_read(&bip->bli_refcount) > 0); 737 - ASSERT(!xfs_buf_item_dirty_format(bip)); 737 + 738 + if (xfs_buf_item_dirty_format(bip)) 739 + return false; 738 740 739 741 bip->bli_flags |= XFS_BLI_ORDERED; 740 742 trace_xfs_buf_item_ordered(bip); ··· 746 744 * to be marked dirty and that it has been logged. 747 745 */ 748 746 xfs_trans_dirty_buf(tp, bp); 747 + return true; 749 748 } 750 749 751 750 /*