Received: by 2002:a05:7208:c250:b0:86:f851:443 with SMTP id w16csp948246rbd; Thu, 13 Jun 2024 02:08:28 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCVo5Hqd2tNGbuV+qyYTUj8ZL6SdQiOuSydcZv/woHy2AjvSzFZyT0JnRE4UDOOmoQbYB5KIFupUBPMzYfxZx7MdV8M0J+d4sgP9l/yWyQ== X-Google-Smtp-Source: AGHT+IEeVOwkldFpqZZfZGNe1r9PkSMrPJQjMPszS4zB99eWVO3FROm9p6dS2878DZbL8v7On/fi X-Received: by 2002:a05:6512:3b9c:b0:52b:bdbd:2c54 with SMTP id 2adb3069b0e04-52c9a3e3c62mr4339875e87.34.1718269708236; Thu, 13 Jun 2024 02:08:28 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1718269708; cv=pass; d=google.com; s=arc-20160816; b=aX2F6WVTyM7tTyGFVNcFUBjikmLceQsxWIR+uOxuf3uSYTRexsxAhRhX3Wv6GnrWtf zi1udSiEVCKS2tQNjz//YW9mkWwqHl73B+6gmqTsy4NFDW12KA08RuUKIhdYAYogae16 6vGEqvcInM+vrE26VYUqUr9GeNb7lQ2fNrv6khtyaXtF4u+oQirR05tb3qY/7wufxbVo EScPmUr2c72aUQPSIiMb2IQ3TSx9H95Rw0GDXTvBEU5lflEktj/eWJ2OXyE59OMt6Hkw EfV1unhyslkJM8gCn7p4g8AWnZbl+72SGxN8HYvxEAtg1g+4Z1jCxnu7+K4+FQNCjLpk mTgQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:message-id:date:subject:cc:to :from; bh=nhpwv9Rud8tBOT7lCIVDJHI5/tEvC8cHsm2QcZP18vs=; fh=FmG7DF7uo3pnVoAtry0cqJ348XVgt1uALjdDXZ1F5tQ=; b=nJ2NR9/yflC5mDyIquXyl2WAOfI+f2RW8OeLxhA7rBo6S+noPfqp2g9kslWCXH1Wco l8fhGC/9IN9fvlFDkeFuhXr6De5oHcPp9ksR/3FI66GyjdPmbCWKBmal3ihGv+Lqmgi3 geBtfGk/+vt9+/22xVizIxW7bz3W5cRiUHnZx4M9Baei/Uaj75oARj/TvMMnTs5ZtjfJ Ei0t8+OoqYit0+varaFX1FXvccfKDYsdkwN2LLoRRKAdjGwwkFd8uuAwGXrEMVQfNlui zJL/CXpQ5rNqFuqapg63VdB11ddK2u2FJKRcNbavUTeNNnF+Y4p1RxtbwuAZvafL5qw9 f06g==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; arc=pass (i=1 spf=pass spfdomain=huaweicloud.com); spf=pass (google.com: domain of linux-kernel+bounces-212899-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-212899-linux.lists.archive=gmail.com@vger.kernel.org" Return-Path: Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [2604:1380:4601:e00::3]) by mx.google.com with ESMTPS id a640c23a62f3a-a6f56dd6edesi48135366b.485.2024.06.13.02.08.28 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Jun 2024 02:08:28 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-212899-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) client-ip=2604:1380:4601:e00::3; Authentication-Results: mx.google.com; arc=pass (i=1 spf=pass spfdomain=huaweicloud.com); spf=pass (google.com: domain of linux-kernel+bounces-212899-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:4601:e00::3 as permitted sender) smtp.mailfrom="linux-kernel+bounces-212899-linux.lists.archive=gmail.com@vger.kernel.org" Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 72A3D1F26F59 for ; Thu, 13 Jun 2024 09:01:25 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id ACB1013D893; Thu, 13 Jun 2024 09:01:12 +0000 (UTC) Received: from dggsgout12.his.huawei.com (unknown [45.249.212.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0EA3B84D03; Thu, 13 Jun 2024 09:01:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=45.249.212.56 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718269272; cv=none; b=KBiVh27tb5VHsiXBI9TYI8kbqIdMTqsKfIFffzSM/AkahjVWMV7WM7+NbMJkCM9xE5XwkF0GPpwnTzh42yl8kDPlaLDJc7j9W5CHN/hKbDM80D5yezpEgQplutScKyoQDdOBYWue/APqwaNYt6a9DDjB+3teTfudEk4QmdKSj78= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718269272; c=relaxed/simple; bh=smK+jc7dSgvkAp6lPonVm1WD+q8MJwaXm8XGmu7+Ecg=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=KvpbdzLteBuMI9HSNMYmNZT13NjesQHzqzvQy8/vXDHFJS5YPRw4kNhzDMcnFjCoJY/wGUdgeYseK3O5TRmvfBOXalgwF4WAWIbKniqY0eWmITVou4PGA9wsh8HcTwMnMYlLV0HiNNRXml53/n7NA0yyUXPvhp4jxp+aqf5FAXw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com; spf=pass smtp.mailfrom=huaweicloud.com; arc=none smtp.client-ip=45.249.212.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huaweicloud.com Received: from mail.maildlp.com (unknown [172.19.93.142]) by dggsgout12.his.huawei.com (SkyGuard) with ESMTP id 4W0GbX3Vm2z4f3jMS; Thu, 13 Jun 2024 17:00:56 +0800 (CST) Received: from mail02.huawei.com (unknown [10.116.40.112]) by mail.maildlp.com (Postfix) with ESMTP id 8C8E61A0181; Thu, 13 Jun 2024 17:01:06 +0800 (CST) Received: from huaweicloud.com (unknown [10.175.104.67]) by APP1 (Coremail) with SMTP id cCh0CgBXKBFOtWpmHK1uPQ--.16895S4; Thu, 13 Jun 2024 17:01:04 +0800 (CST) From: Zhang Yi To: linux-xfs@vger.kernel.org, linux-fsdevel@vger.kernel.org Cc: linux-kernel@vger.kernel.org, djwong@kernel.org, hch@infradead.org, brauner@kernel.org, david@fromorbit.com, chandanbabu@kernel.org, jack@suse.cz, yi.zhang@huawei.com, yi.zhang@huaweicloud.com, chengzhihao1@huawei.com, yukuai3@huawei.com Subject: [PATCH -next v5 0/8] iomap/xfs: fix stale data exposure when truncating realtime inodes Date: Thu, 13 Jun 2024 17:00:25 +0800 Message-Id: <20240613090033.2246907-1-yi.zhang@huaweicloud.com> X-Mailer: git-send-email 2.39.2 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CM-TRANSID:cCh0CgBXKBFOtWpmHK1uPQ--.16895S4 X-Coremail-Antispam: 1UD129KBjvJXoWxGw1xWrW5AFW7Cr1kXr47urg_yoWrXw4kpF ZxKay5Cr4kJ34furyxZa4DXw45u3Z7CFWjkFy7GrsxC3W5Xr1Ivr1vqF4F93yjkrs7uFs0 vrsYyFWxur1qyFJanT9S1TB71UUUUUUqnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUvY14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26F1j6w1UM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4U JVWxJr1l84ACjcxK6I8E87Iv67AKxVW0oVCq3wA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_Gc CE3s1le2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E 2Ix0cI8IcVAFwI0_JrI_JrylYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJV W8JwACjcxG0xvY0x0EwIxGrwACjI8F5VA0II8E6IAqYI8I648v4I1lFIxGxcIEc7CjxVA2 Y2ka0xkIwI1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4 xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWwC2zVAF1VAY17CE14v26r1q6r43 MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I 0E14v26r4j6F4UMIIF0xvE42xK8VAvwI8IcIk0rVWrZr1j6s0DMIIF0xvEx4A2jsIE14v2 6r1j6r4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr0_Gr1UYxBIdaVFxhVjvjDU0xZFpf9x0J UZa9-UUUUU= X-CM-SenderInfo: d1lo6xhdqjqx5xdzvxpfor3voofrz/ From: Zhang Yi Changes since v4: - Drop the first patch in v4 "iomap: zeroing needs to be pagecache aware" since this series is not strongly depends on it, that patch still needs furtuer analyse and also should add to handle the case of a pending COW extent that extends over a data fork hole. This is a big job, so let's fix the exposure stale data issue and brings back the changes in iomap_write_end() first, don't block the ext4 buffered iomap conversion. - In patch 1, drop the 'ifndef rem_u64'. - In patch 4, factor out a helper xfs_setattr_truncate_data() to handle the zero out, update i_size, write back and drop pagecache on truncate. - In patch 5, switch to use xfs_inode_alloc_unitsize() in xfs_itruncate_extents_flags(). - In patch 6, changes to reserve blocks for rtextsize > 1 realtime inodes on truncate down. - In patch 7, drop the unwritten convert threshold, always convert tail blocks to unwritten on truncate down realtime inodes. - Add patch 8 to bring back 'commit 943bc0882ceb ("iomap: don't increase i_size if it's not a write operation")'. Changes since v3: - Factor out a new helper to get the remainder in math64.h as Darrick suggested. - Adjust the truncating order to prevent too much redundant blocking writes as Dave suggested. - Improve to convert the tail extent to unwritten when truncating down an inode with large rtextsize as Darrick and Dave suggested. Since 'commit 943bc0882ceb ("iomap: don't increase i_size if it's not a write operation")' merged, Chandan reported a stale data exposure issue when running fstests generic/561 on xfs with realtime device [1]. This issue has been fix on 6.10 by revert this commit through commit '0841ea4a3b41 ("iomap: keep on increasing i_size in iomap_write_end()")', but the real problem is xfs_setattr_size() doesn't zero out enough range when truncate down a realtime inode. So this series fix this problem by zeroing out allocation unitsize and convert the tail blocks to unwritten when truncate down realtime inodes, finally we could bring commit 943bc0882ceb back. Patch 1-3 modify iomap_truncate_page() and dax_truncate_page() to pass filesystem identified blocksize, and drop the assumption of i_blocksize() as Dave suggested. Patch 4-5 refactor and adjust the truncating down processing order to first zero out the tail aligned blocks, then write back and update i_size, finally drop cache beyond aligned EOF. Fix the data exposure issue by zeroing out the entire EOF extent. Patch 6-7 improves truncate down performace on realtime inodes with big rtextsize(>1 fsblock) by converting the tail unaligned extent to unwritten. Patch 8 reverts commit 0841ea4a3b41 and brings commit 943bc0882ceb back, don't increase i_size on IOMAP_ZERO and IOMAP_UNSHARE. I've tested this series on fstests (1) with reflink=0, (2) with reflink=1, (3) with 28K RT device and (4) with dax, no new failures detected, and it passed generic/561 on RT device over 1000+ rounds, please let me know if it needs other tests. [1] https://lore.kernel.org/linux-xfs/87ttj8ircu.fsf@debian-BULLSEYE-live-builder-AMD64/ Thanks, Yi. Zhang Yi (8): math64: add rem_u64() to just return the remainder iomap: pass blocksize to iomap_truncate_page() fsdax: pass blocksize to dax_truncate_page() xfs: refactor the truncating order xfs: correct the truncate blocksize of realtime inode xfs: reserve blocks for truncating large realtime inode xfs: speed up truncating down a big realtime inode iomap: don't increase i_size in iomap_write_end() fs/dax.c | 8 +- fs/ext2/inode.c | 4 +- fs/iomap/buffered-io.c | 61 +++++++------- fs/xfs/xfs_inode.c | 9 ++- fs/xfs/xfs_iomap.c | 5 +- fs/xfs/xfs_iomap.h | 3 +- fs/xfs/xfs_iops.c | 180 ++++++++++++++++++++++++++++------------- include/linux/dax.h | 4 +- include/linux/iomap.h | 4 +- include/linux/math64.h | 22 +++++ 10 files changed, 204 insertions(+), 96 deletions(-) -- 2.39.2