cachepc-linux

Fork of AMDESE/linux with modifications for CachePC side-channel attack
git clone https://git.sinitax.com/sinitax/cachepc-linux
Log | Files | Refs | README | LICENSE | sfeed.txt

addr.c (55900B)


      1// SPDX-License-Identifier: GPL-2.0
      2#include <linux/ceph/ceph_debug.h>
      3
      4#include <linux/backing-dev.h>
      5#include <linux/fs.h>
      6#include <linux/mm.h>
      7#include <linux/swap.h>
      8#include <linux/pagemap.h>
      9#include <linux/slab.h>
     10#include <linux/pagevec.h>
     11#include <linux/task_io_accounting_ops.h>
     12#include <linux/signal.h>
     13#include <linux/iversion.h>
     14#include <linux/ktime.h>
     15#include <linux/netfs.h>
     16
     17#include "super.h"
     18#include "mds_client.h"
     19#include "cache.h"
     20#include "metric.h"
     21#include <linux/ceph/osd_client.h>
     22#include <linux/ceph/striper.h>
     23
     24/*
     25 * Ceph address space ops.
     26 *
     27 * There are a few funny things going on here.
     28 *
     29 * The page->private field is used to reference a struct
     30 * ceph_snap_context for _every_ dirty page.  This indicates which
     31 * snapshot the page was logically dirtied in, and thus which snap
     32 * context needs to be associated with the osd write during writeback.
     33 *
     34 * Similarly, struct ceph_inode_info maintains a set of counters to
     35 * count dirty pages on the inode.  In the absence of snapshots,
     36 * i_wrbuffer_ref == i_wrbuffer_ref_head == the dirty page count.
     37 *
     38 * When a snapshot is taken (that is, when the client receives
     39 * notification that a snapshot was taken), each inode with caps and
     40 * with dirty pages (dirty pages implies there is a cap) gets a new
     41 * ceph_cap_snap in the i_cap_snaps list (which is sorted in ascending
     42 * order, new snaps go to the tail).  The i_wrbuffer_ref_head count is
     43 * moved to capsnap->dirty. (Unless a sync write is currently in
     44 * progress.  In that case, the capsnap is said to be "pending", new
     45 * writes cannot start, and the capsnap isn't "finalized" until the
     46 * write completes (or fails) and a final size/mtime for the inode for
     47 * that snap can be settled upon.)  i_wrbuffer_ref_head is reset to 0.
     48 *
     49 * On writeback, we must submit writes to the osd IN SNAP ORDER.  So,
     50 * we look for the first capsnap in i_cap_snaps and write out pages in
     51 * that snap context _only_.  Then we move on to the next capsnap,
     52 * eventually reaching the "live" or "head" context (i.e., pages that
     53 * are not yet snapped) and are writing the most recently dirtied
     54 * pages.
     55 *
     56 * Invalidate and so forth must take care to ensure the dirty page
     57 * accounting is preserved.
     58 */
     59
     60#define CONGESTION_ON_THRESH(congestion_kb) (congestion_kb >> (PAGE_SHIFT-10))
     61#define CONGESTION_OFF_THRESH(congestion_kb)				\
     62	(CONGESTION_ON_THRESH(congestion_kb) -				\
     63	 (CONGESTION_ON_THRESH(congestion_kb) >> 2))
     64
     65static int ceph_netfs_check_write_begin(struct file *file, loff_t pos, unsigned int len,
     66					struct folio *folio, void **_fsdata);
     67
     68static inline struct ceph_snap_context *page_snap_context(struct page *page)
     69{
     70	if (PagePrivate(page))
     71		return (void *)page->private;
     72	return NULL;
     73}
     74
     75/*
     76 * Dirty a page.  Optimistically adjust accounting, on the assumption
     77 * that we won't race with invalidate.  If we do, readjust.
     78 */
     79static bool ceph_dirty_folio(struct address_space *mapping, struct folio *folio)
     80{
     81	struct inode *inode;
     82	struct ceph_inode_info *ci;
     83	struct ceph_snap_context *snapc;
     84
     85	if (folio_test_dirty(folio)) {
     86		dout("%p dirty_folio %p idx %lu -- already dirty\n",
     87		     mapping->host, folio, folio->index);
     88		VM_BUG_ON_FOLIO(!folio_test_private(folio), folio);
     89		return false;
     90	}
     91
     92	inode = mapping->host;
     93	ci = ceph_inode(inode);
     94
     95	/* dirty the head */
     96	spin_lock(&ci->i_ceph_lock);
     97	BUG_ON(ci->i_wr_ref == 0); // caller should hold Fw reference
     98	if (__ceph_have_pending_cap_snap(ci)) {
     99		struct ceph_cap_snap *capsnap =
    100				list_last_entry(&ci->i_cap_snaps,
    101						struct ceph_cap_snap,
    102						ci_item);
    103		snapc = ceph_get_snap_context(capsnap->context);
    104		capsnap->dirty_pages++;
    105	} else {
    106		BUG_ON(!ci->i_head_snapc);
    107		snapc = ceph_get_snap_context(ci->i_head_snapc);
    108		++ci->i_wrbuffer_ref_head;
    109	}
    110	if (ci->i_wrbuffer_ref == 0)
    111		ihold(inode);
    112	++ci->i_wrbuffer_ref;
    113	dout("%p dirty_folio %p idx %lu head %d/%d -> %d/%d "
    114	     "snapc %p seq %lld (%d snaps)\n",
    115	     mapping->host, folio, folio->index,
    116	     ci->i_wrbuffer_ref-1, ci->i_wrbuffer_ref_head-1,
    117	     ci->i_wrbuffer_ref, ci->i_wrbuffer_ref_head,
    118	     snapc, snapc->seq, snapc->num_snaps);
    119	spin_unlock(&ci->i_ceph_lock);
    120
    121	/*
    122	 * Reference snap context in folio->private.  Also set
    123	 * PagePrivate so that we get invalidate_folio callback.
    124	 */
    125	VM_BUG_ON_FOLIO(folio_test_private(folio), folio);
    126	folio_attach_private(folio, snapc);
    127
    128	return ceph_fscache_dirty_folio(mapping, folio);
    129}
    130
    131/*
    132 * If we are truncating the full folio (i.e. offset == 0), adjust the
    133 * dirty folio counters appropriately.  Only called if there is private
    134 * data on the folio.
    135 */
    136static void ceph_invalidate_folio(struct folio *folio, size_t offset,
    137				size_t length)
    138{
    139	struct inode *inode;
    140	struct ceph_inode_info *ci;
    141	struct ceph_snap_context *snapc;
    142
    143	inode = folio->mapping->host;
    144	ci = ceph_inode(inode);
    145
    146	if (offset != 0 || length != folio_size(folio)) {
    147		dout("%p invalidate_folio idx %lu partial dirty page %zu~%zu\n",
    148		     inode, folio->index, offset, length);
    149		return;
    150	}
    151
    152	WARN_ON(!folio_test_locked(folio));
    153	if (folio_test_private(folio)) {
    154		dout("%p invalidate_folio idx %lu full dirty page\n",
    155		     inode, folio->index);
    156
    157		snapc = folio_detach_private(folio);
    158		ceph_put_wrbuffer_cap_refs(ci, 1, snapc);
    159		ceph_put_snap_context(snapc);
    160	}
    161
    162	folio_wait_fscache(folio);
    163}
    164
    165static bool ceph_release_folio(struct folio *folio, gfp_t gfp)
    166{
    167	struct inode *inode = folio->mapping->host;
    168
    169	dout("%llx:%llx release_folio idx %lu (%sdirty)\n",
    170	     ceph_vinop(inode),
    171	     folio->index, folio_test_dirty(folio) ? "" : "not ");
    172
    173	if (folio_test_private(folio))
    174		return false;
    175
    176	if (folio_test_fscache(folio)) {
    177		if (current_is_kswapd() || !(gfp & __GFP_FS))
    178			return false;
    179		folio_wait_fscache(folio);
    180	}
    181	ceph_fscache_note_page_release(inode);
    182	return true;
    183}
    184
    185static void ceph_netfs_expand_readahead(struct netfs_io_request *rreq)
    186{
    187	struct inode *inode = rreq->inode;
    188	struct ceph_inode_info *ci = ceph_inode(inode);
    189	struct ceph_file_layout *lo = &ci->i_layout;
    190	u32 blockoff;
    191	u64 blockno;
    192
    193	/* Expand the start downward */
    194	blockno = div_u64_rem(rreq->start, lo->stripe_unit, &blockoff);
    195	rreq->start = blockno * lo->stripe_unit;
    196	rreq->len += blockoff;
    197
    198	/* Now, round up the length to the next block */
    199	rreq->len = roundup(rreq->len, lo->stripe_unit);
    200}
    201
    202static bool ceph_netfs_clamp_length(struct netfs_io_subrequest *subreq)
    203{
    204	struct inode *inode = subreq->rreq->inode;
    205	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
    206	struct ceph_inode_info *ci = ceph_inode(inode);
    207	u64 objno, objoff;
    208	u32 xlen;
    209
    210	/* Truncate the extent at the end of the current block */
    211	ceph_calc_file_object_mapping(&ci->i_layout, subreq->start, subreq->len,
    212				      &objno, &objoff, &xlen);
    213	subreq->len = min(xlen, fsc->mount_options->rsize);
    214	return true;
    215}
    216
    217static void finish_netfs_read(struct ceph_osd_request *req)
    218{
    219	struct ceph_fs_client *fsc = ceph_inode_to_client(req->r_inode);
    220	struct ceph_osd_data *osd_data = osd_req_op_extent_osd_data(req, 0);
    221	struct netfs_io_subrequest *subreq = req->r_priv;
    222	int num_pages;
    223	int err = req->r_result;
    224
    225	ceph_update_read_metrics(&fsc->mdsc->metric, req->r_start_latency,
    226				 req->r_end_latency, osd_data->length, err);
    227
    228	dout("%s: result %d subreq->len=%zu i_size=%lld\n", __func__, req->r_result,
    229	     subreq->len, i_size_read(req->r_inode));
    230
    231	/* no object means success but no data */
    232	if (err == -ENOENT)
    233		err = 0;
    234	else if (err == -EBLOCKLISTED)
    235		fsc->blocklisted = true;
    236
    237	if (err >= 0 && err < subreq->len)
    238		__set_bit(NETFS_SREQ_CLEAR_TAIL, &subreq->flags);
    239
    240	netfs_subreq_terminated(subreq, err, true);
    241
    242	num_pages = calc_pages_for(osd_data->alignment, osd_data->length);
    243	ceph_put_page_vector(osd_data->pages, num_pages, false);
    244	iput(req->r_inode);
    245}
    246
    247static bool ceph_netfs_issue_op_inline(struct netfs_io_subrequest *subreq)
    248{
    249	struct netfs_io_request *rreq = subreq->rreq;
    250	struct inode *inode = rreq->inode;
    251	struct ceph_mds_reply_info_parsed *rinfo;
    252	struct ceph_mds_reply_info_in *iinfo;
    253	struct ceph_mds_request *req;
    254	struct ceph_mds_client *mdsc = ceph_sb_to_mdsc(inode->i_sb);
    255	struct ceph_inode_info *ci = ceph_inode(inode);
    256	struct iov_iter iter;
    257	ssize_t err = 0;
    258	size_t len;
    259	int mode;
    260
    261	__set_bit(NETFS_SREQ_CLEAR_TAIL, &subreq->flags);
    262	__clear_bit(NETFS_SREQ_COPY_TO_CACHE, &subreq->flags);
    263
    264	if (subreq->start >= inode->i_size)
    265		goto out;
    266
    267	/* We need to fetch the inline data. */
    268	mode = ceph_try_to_choose_auth_mds(inode, CEPH_STAT_CAP_INLINE_DATA);
    269	req = ceph_mdsc_create_request(mdsc, CEPH_MDS_OP_GETATTR, mode);
    270	if (IS_ERR(req)) {
    271		err = PTR_ERR(req);
    272		goto out;
    273	}
    274	req->r_ino1 = ci->i_vino;
    275	req->r_args.getattr.mask = cpu_to_le32(CEPH_STAT_CAP_INLINE_DATA);
    276	req->r_num_caps = 2;
    277
    278	err = ceph_mdsc_do_request(mdsc, NULL, req);
    279	if (err < 0)
    280		goto out;
    281
    282	rinfo = &req->r_reply_info;
    283	iinfo = &rinfo->targeti;
    284	if (iinfo->inline_version == CEPH_INLINE_NONE) {
    285		/* The data got uninlined */
    286		ceph_mdsc_put_request(req);
    287		return false;
    288	}
    289
    290	len = min_t(size_t, iinfo->inline_len - subreq->start, subreq->len);
    291	iov_iter_xarray(&iter, READ, &rreq->mapping->i_pages, subreq->start, len);
    292	err = copy_to_iter(iinfo->inline_data + subreq->start, len, &iter);
    293	if (err == 0)
    294		err = -EFAULT;
    295
    296	ceph_mdsc_put_request(req);
    297out:
    298	netfs_subreq_terminated(subreq, err, false);
    299	return true;
    300}
    301
    302static void ceph_netfs_issue_read(struct netfs_io_subrequest *subreq)
    303{
    304	struct netfs_io_request *rreq = subreq->rreq;
    305	struct inode *inode = rreq->inode;
    306	struct ceph_inode_info *ci = ceph_inode(inode);
    307	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
    308	struct ceph_osd_request *req;
    309	struct ceph_vino vino = ceph_vino(inode);
    310	struct iov_iter iter;
    311	struct page **pages;
    312	size_t page_off;
    313	int err = 0;
    314	u64 len = subreq->len;
    315
    316	if (ci->i_inline_version != CEPH_INLINE_NONE &&
    317	    ceph_netfs_issue_op_inline(subreq))
    318		return;
    319
    320	req = ceph_osdc_new_request(&fsc->client->osdc, &ci->i_layout, vino, subreq->start, &len,
    321			0, 1, CEPH_OSD_OP_READ,
    322			CEPH_OSD_FLAG_READ | fsc->client->osdc.client->options->read_from_replica,
    323			NULL, ci->i_truncate_seq, ci->i_truncate_size, false);
    324	if (IS_ERR(req)) {
    325		err = PTR_ERR(req);
    326		req = NULL;
    327		goto out;
    328	}
    329
    330	dout("%s: pos=%llu orig_len=%zu len=%llu\n", __func__, subreq->start, subreq->len, len);
    331	iov_iter_xarray(&iter, READ, &rreq->mapping->i_pages, subreq->start, len);
    332	err = iov_iter_get_pages_alloc(&iter, &pages, len, &page_off);
    333	if (err < 0) {
    334		dout("%s: iov_ter_get_pages_alloc returned %d\n", __func__, err);
    335		goto out;
    336	}
    337
    338	/* should always give us a page-aligned read */
    339	WARN_ON_ONCE(page_off);
    340	len = err;
    341
    342	osd_req_op_extent_osd_data_pages(req, 0, pages, len, 0, false, false);
    343	req->r_callback = finish_netfs_read;
    344	req->r_priv = subreq;
    345	req->r_inode = inode;
    346	ihold(inode);
    347
    348	err = ceph_osdc_start_request(req->r_osdc, req, false);
    349	if (err)
    350		iput(inode);
    351out:
    352	ceph_osdc_put_request(req);
    353	if (err)
    354		netfs_subreq_terminated(subreq, err, false);
    355	dout("%s: result %d\n", __func__, err);
    356}
    357
    358static int ceph_init_request(struct netfs_io_request *rreq, struct file *file)
    359{
    360	struct inode *inode = rreq->inode;
    361	int got = 0, want = CEPH_CAP_FILE_CACHE;
    362	int ret = 0;
    363
    364	if (rreq->origin != NETFS_READAHEAD)
    365		return 0;
    366
    367	if (file) {
    368		struct ceph_rw_context *rw_ctx;
    369		struct ceph_file_info *fi = file->private_data;
    370
    371		rw_ctx = ceph_find_rw_context(fi);
    372		if (rw_ctx)
    373			return 0;
    374	}
    375
    376	/*
    377	 * readahead callers do not necessarily hold Fcb caps
    378	 * (e.g. fadvise, madvise).
    379	 */
    380	ret = ceph_try_get_caps(inode, CEPH_CAP_FILE_RD, want, true, &got);
    381	if (ret < 0) {
    382		dout("start_read %p, error getting cap\n", inode);
    383		return ret;
    384	}
    385
    386	if (!(got & want)) {
    387		dout("start_read %p, no cache cap\n", inode);
    388		return -EACCES;
    389	}
    390	if (ret == 0)
    391		return -EACCES;
    392
    393	rreq->netfs_priv = (void *)(uintptr_t)got;
    394	return 0;
    395}
    396
    397static void ceph_netfs_free_request(struct netfs_io_request *rreq)
    398{
    399	struct ceph_inode_info *ci = ceph_inode(rreq->inode);
    400	int got = (uintptr_t)rreq->netfs_priv;
    401
    402	if (got)
    403		ceph_put_cap_refs(ci, got);
    404}
    405
    406const struct netfs_request_ops ceph_netfs_ops = {
    407	.init_request		= ceph_init_request,
    408	.free_request		= ceph_netfs_free_request,
    409	.begin_cache_operation	= ceph_begin_cache_operation,
    410	.issue_read		= ceph_netfs_issue_read,
    411	.expand_readahead	= ceph_netfs_expand_readahead,
    412	.clamp_length		= ceph_netfs_clamp_length,
    413	.check_write_begin	= ceph_netfs_check_write_begin,
    414};
    415
    416#ifdef CONFIG_CEPH_FSCACHE
    417static void ceph_set_page_fscache(struct page *page)
    418{
    419	set_page_fscache(page);
    420}
    421
    422static void ceph_fscache_write_terminated(void *priv, ssize_t error, bool was_async)
    423{
    424	struct inode *inode = priv;
    425
    426	if (IS_ERR_VALUE(error) && error != -ENOBUFS)
    427		ceph_fscache_invalidate(inode, false);
    428}
    429
    430static void ceph_fscache_write_to_cache(struct inode *inode, u64 off, u64 len, bool caching)
    431{
    432	struct ceph_inode_info *ci = ceph_inode(inode);
    433	struct fscache_cookie *cookie = ceph_fscache_cookie(ci);
    434
    435	fscache_write_to_cache(cookie, inode->i_mapping, off, len, i_size_read(inode),
    436			       ceph_fscache_write_terminated, inode, caching);
    437}
    438#else
    439static inline void ceph_set_page_fscache(struct page *page)
    440{
    441}
    442
    443static inline void ceph_fscache_write_to_cache(struct inode *inode, u64 off, u64 len, bool caching)
    444{
    445}
    446#endif /* CONFIG_CEPH_FSCACHE */
    447
    448struct ceph_writeback_ctl
    449{
    450	loff_t i_size;
    451	u64 truncate_size;
    452	u32 truncate_seq;
    453	bool size_stable;
    454	bool head_snapc;
    455};
    456
    457/*
    458 * Get ref for the oldest snapc for an inode with dirty data... that is, the
    459 * only snap context we are allowed to write back.
    460 */
    461static struct ceph_snap_context *
    462get_oldest_context(struct inode *inode, struct ceph_writeback_ctl *ctl,
    463		   struct ceph_snap_context *page_snapc)
    464{
    465	struct ceph_inode_info *ci = ceph_inode(inode);
    466	struct ceph_snap_context *snapc = NULL;
    467	struct ceph_cap_snap *capsnap = NULL;
    468
    469	spin_lock(&ci->i_ceph_lock);
    470	list_for_each_entry(capsnap, &ci->i_cap_snaps, ci_item) {
    471		dout(" cap_snap %p snapc %p has %d dirty pages\n", capsnap,
    472		     capsnap->context, capsnap->dirty_pages);
    473		if (!capsnap->dirty_pages)
    474			continue;
    475
    476		/* get i_size, truncate_{seq,size} for page_snapc? */
    477		if (snapc && capsnap->context != page_snapc)
    478			continue;
    479
    480		if (ctl) {
    481			if (capsnap->writing) {
    482				ctl->i_size = i_size_read(inode);
    483				ctl->size_stable = false;
    484			} else {
    485				ctl->i_size = capsnap->size;
    486				ctl->size_stable = true;
    487			}
    488			ctl->truncate_size = capsnap->truncate_size;
    489			ctl->truncate_seq = capsnap->truncate_seq;
    490			ctl->head_snapc = false;
    491		}
    492
    493		if (snapc)
    494			break;
    495
    496		snapc = ceph_get_snap_context(capsnap->context);
    497		if (!page_snapc ||
    498		    page_snapc == snapc ||
    499		    page_snapc->seq > snapc->seq)
    500			break;
    501	}
    502	if (!snapc && ci->i_wrbuffer_ref_head) {
    503		snapc = ceph_get_snap_context(ci->i_head_snapc);
    504		dout(" head snapc %p has %d dirty pages\n",
    505		     snapc, ci->i_wrbuffer_ref_head);
    506		if (ctl) {
    507			ctl->i_size = i_size_read(inode);
    508			ctl->truncate_size = ci->i_truncate_size;
    509			ctl->truncate_seq = ci->i_truncate_seq;
    510			ctl->size_stable = false;
    511			ctl->head_snapc = true;
    512		}
    513	}
    514	spin_unlock(&ci->i_ceph_lock);
    515	return snapc;
    516}
    517
    518static u64 get_writepages_data_length(struct inode *inode,
    519				      struct page *page, u64 start)
    520{
    521	struct ceph_inode_info *ci = ceph_inode(inode);
    522	struct ceph_snap_context *snapc = page_snap_context(page);
    523	struct ceph_cap_snap *capsnap = NULL;
    524	u64 end = i_size_read(inode);
    525
    526	if (snapc != ci->i_head_snapc) {
    527		bool found = false;
    528		spin_lock(&ci->i_ceph_lock);
    529		list_for_each_entry(capsnap, &ci->i_cap_snaps, ci_item) {
    530			if (capsnap->context == snapc) {
    531				if (!capsnap->writing)
    532					end = capsnap->size;
    533				found = true;
    534				break;
    535			}
    536		}
    537		spin_unlock(&ci->i_ceph_lock);
    538		WARN_ON(!found);
    539	}
    540	if (end > page_offset(page) + thp_size(page))
    541		end = page_offset(page) + thp_size(page);
    542	return end > start ? end - start : 0;
    543}
    544
    545/*
    546 * Write a single page, but leave the page locked.
    547 *
    548 * If we get a write error, mark the mapping for error, but still adjust the
    549 * dirty page accounting (i.e., page is no longer dirty).
    550 */
    551static int writepage_nounlock(struct page *page, struct writeback_control *wbc)
    552{
    553	struct folio *folio = page_folio(page);
    554	struct inode *inode = page->mapping->host;
    555	struct ceph_inode_info *ci = ceph_inode(inode);
    556	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
    557	struct ceph_snap_context *snapc, *oldest;
    558	loff_t page_off = page_offset(page);
    559	int err;
    560	loff_t len = thp_size(page);
    561	struct ceph_writeback_ctl ceph_wbc;
    562	struct ceph_osd_client *osdc = &fsc->client->osdc;
    563	struct ceph_osd_request *req;
    564	bool caching = ceph_is_cache_enabled(inode);
    565
    566	dout("writepage %p idx %lu\n", page, page->index);
    567
    568	/* verify this is a writeable snap context */
    569	snapc = page_snap_context(page);
    570	if (!snapc) {
    571		dout("writepage %p page %p not dirty?\n", inode, page);
    572		return 0;
    573	}
    574	oldest = get_oldest_context(inode, &ceph_wbc, snapc);
    575	if (snapc->seq > oldest->seq) {
    576		dout("writepage %p page %p snapc %p not writeable - noop\n",
    577		     inode, page, snapc);
    578		/* we should only noop if called by kswapd */
    579		WARN_ON(!(current->flags & PF_MEMALLOC));
    580		ceph_put_snap_context(oldest);
    581		redirty_page_for_writepage(wbc, page);
    582		return 0;
    583	}
    584	ceph_put_snap_context(oldest);
    585
    586	/* is this a partial page at end of file? */
    587	if (page_off >= ceph_wbc.i_size) {
    588		dout("folio at %lu beyond eof %llu\n", folio->index,
    589				ceph_wbc.i_size);
    590		folio_invalidate(folio, 0, folio_size(folio));
    591		return 0;
    592	}
    593
    594	if (ceph_wbc.i_size < page_off + len)
    595		len = ceph_wbc.i_size - page_off;
    596
    597	dout("writepage %p page %p index %lu on %llu~%llu snapc %p seq %lld\n",
    598	     inode, page, page->index, page_off, len, snapc, snapc->seq);
    599
    600	if (atomic_long_inc_return(&fsc->writeback_count) >
    601	    CONGESTION_ON_THRESH(fsc->mount_options->congestion_kb))
    602		fsc->write_congested = true;
    603
    604	req = ceph_osdc_new_request(osdc, &ci->i_layout, ceph_vino(inode), page_off, &len, 0, 1,
    605				    CEPH_OSD_OP_WRITE, CEPH_OSD_FLAG_WRITE, snapc,
    606				    ceph_wbc.truncate_seq, ceph_wbc.truncate_size,
    607				    true);
    608	if (IS_ERR(req)) {
    609		redirty_page_for_writepage(wbc, page);
    610		return PTR_ERR(req);
    611	}
    612
    613	set_page_writeback(page);
    614	if (caching)
    615		ceph_set_page_fscache(page);
    616	ceph_fscache_write_to_cache(inode, page_off, len, caching);
    617
    618	/* it may be a short write due to an object boundary */
    619	WARN_ON_ONCE(len > thp_size(page));
    620	osd_req_op_extent_osd_data_pages(req, 0, &page, len, 0, false, false);
    621	dout("writepage %llu~%llu (%llu bytes)\n", page_off, len, len);
    622
    623	req->r_mtime = inode->i_mtime;
    624	err = ceph_osdc_start_request(osdc, req, true);
    625	if (!err)
    626		err = ceph_osdc_wait_request(osdc, req);
    627
    628	ceph_update_write_metrics(&fsc->mdsc->metric, req->r_start_latency,
    629				  req->r_end_latency, len, err);
    630
    631	ceph_osdc_put_request(req);
    632	if (err == 0)
    633		err = len;
    634
    635	if (err < 0) {
    636		struct writeback_control tmp_wbc;
    637		if (!wbc)
    638			wbc = &tmp_wbc;
    639		if (err == -ERESTARTSYS) {
    640			/* killed by SIGKILL */
    641			dout("writepage interrupted page %p\n", page);
    642			redirty_page_for_writepage(wbc, page);
    643			end_page_writeback(page);
    644			return err;
    645		}
    646		if (err == -EBLOCKLISTED)
    647			fsc->blocklisted = true;
    648		dout("writepage setting page/mapping error %d %p\n",
    649		     err, page);
    650		mapping_set_error(&inode->i_data, err);
    651		wbc->pages_skipped++;
    652	} else {
    653		dout("writepage cleaned page %p\n", page);
    654		err = 0;  /* vfs expects us to return 0 */
    655	}
    656	oldest = detach_page_private(page);
    657	WARN_ON_ONCE(oldest != snapc);
    658	end_page_writeback(page);
    659	ceph_put_wrbuffer_cap_refs(ci, 1, snapc);
    660	ceph_put_snap_context(snapc);  /* page's reference */
    661
    662	if (atomic_long_dec_return(&fsc->writeback_count) <
    663	    CONGESTION_OFF_THRESH(fsc->mount_options->congestion_kb))
    664		fsc->write_congested = false;
    665
    666	return err;
    667}
    668
    669static int ceph_writepage(struct page *page, struct writeback_control *wbc)
    670{
    671	int err;
    672	struct inode *inode = page->mapping->host;
    673	BUG_ON(!inode);
    674	ihold(inode);
    675
    676	if (wbc->sync_mode == WB_SYNC_NONE &&
    677	    ceph_inode_to_client(inode)->write_congested)
    678		return AOP_WRITEPAGE_ACTIVATE;
    679
    680	wait_on_page_fscache(page);
    681
    682	err = writepage_nounlock(page, wbc);
    683	if (err == -ERESTARTSYS) {
    684		/* direct memory reclaimer was killed by SIGKILL. return 0
    685		 * to prevent caller from setting mapping/page error */
    686		err = 0;
    687	}
    688	unlock_page(page);
    689	iput(inode);
    690	return err;
    691}
    692
    693/*
    694 * async writeback completion handler.
    695 *
    696 * If we get an error, set the mapping error bit, but not the individual
    697 * page error bits.
    698 */
    699static void writepages_finish(struct ceph_osd_request *req)
    700{
    701	struct inode *inode = req->r_inode;
    702	struct ceph_inode_info *ci = ceph_inode(inode);
    703	struct ceph_osd_data *osd_data;
    704	struct page *page;
    705	int num_pages, total_pages = 0;
    706	int i, j;
    707	int rc = req->r_result;
    708	struct ceph_snap_context *snapc = req->r_snapc;
    709	struct address_space *mapping = inode->i_mapping;
    710	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
    711	unsigned int len = 0;
    712	bool remove_page;
    713
    714	dout("writepages_finish %p rc %d\n", inode, rc);
    715	if (rc < 0) {
    716		mapping_set_error(mapping, rc);
    717		ceph_set_error_write(ci);
    718		if (rc == -EBLOCKLISTED)
    719			fsc->blocklisted = true;
    720	} else {
    721		ceph_clear_error_write(ci);
    722	}
    723
    724	/*
    725	 * We lost the cache cap, need to truncate the page before
    726	 * it is unlocked, otherwise we'd truncate it later in the
    727	 * page truncation thread, possibly losing some data that
    728	 * raced its way in
    729	 */
    730	remove_page = !(ceph_caps_issued(ci) &
    731			(CEPH_CAP_FILE_CACHE|CEPH_CAP_FILE_LAZYIO));
    732
    733	/* clean all pages */
    734	for (i = 0; i < req->r_num_ops; i++) {
    735		if (req->r_ops[i].op != CEPH_OSD_OP_WRITE) {
    736			pr_warn("%s incorrect op %d req %p index %d tid %llu\n",
    737				__func__, req->r_ops[i].op, req, i, req->r_tid);
    738			break;
    739		}
    740
    741		osd_data = osd_req_op_extent_osd_data(req, i);
    742		BUG_ON(osd_data->type != CEPH_OSD_DATA_TYPE_PAGES);
    743		len += osd_data->length;
    744		num_pages = calc_pages_for((u64)osd_data->alignment,
    745					   (u64)osd_data->length);
    746		total_pages += num_pages;
    747		for (j = 0; j < num_pages; j++) {
    748			page = osd_data->pages[j];
    749			BUG_ON(!page);
    750			WARN_ON(!PageUptodate(page));
    751
    752			if (atomic_long_dec_return(&fsc->writeback_count) <
    753			     CONGESTION_OFF_THRESH(
    754					fsc->mount_options->congestion_kb))
    755				fsc->write_congested = false;
    756
    757			ceph_put_snap_context(detach_page_private(page));
    758			end_page_writeback(page);
    759			dout("unlocking %p\n", page);
    760
    761			if (remove_page)
    762				generic_error_remove_page(inode->i_mapping,
    763							  page);
    764
    765			unlock_page(page);
    766		}
    767		dout("writepages_finish %p wrote %llu bytes cleaned %d pages\n",
    768		     inode, osd_data->length, rc >= 0 ? num_pages : 0);
    769
    770		release_pages(osd_data->pages, num_pages);
    771	}
    772
    773	ceph_update_write_metrics(&fsc->mdsc->metric, req->r_start_latency,
    774				  req->r_end_latency, len, rc);
    775
    776	ceph_put_wrbuffer_cap_refs(ci, total_pages, snapc);
    777
    778	osd_data = osd_req_op_extent_osd_data(req, 0);
    779	if (osd_data->pages_from_pool)
    780		mempool_free(osd_data->pages, ceph_wb_pagevec_pool);
    781	else
    782		kfree(osd_data->pages);
    783	ceph_osdc_put_request(req);
    784}
    785
    786/*
    787 * initiate async writeback
    788 */
    789static int ceph_writepages_start(struct address_space *mapping,
    790				 struct writeback_control *wbc)
    791{
    792	struct inode *inode = mapping->host;
    793	struct ceph_inode_info *ci = ceph_inode(inode);
    794	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
    795	struct ceph_vino vino = ceph_vino(inode);
    796	pgoff_t index, start_index, end = -1;
    797	struct ceph_snap_context *snapc = NULL, *last_snapc = NULL, *pgsnapc;
    798	struct pagevec pvec;
    799	int rc = 0;
    800	unsigned int wsize = i_blocksize(inode);
    801	struct ceph_osd_request *req = NULL;
    802	struct ceph_writeback_ctl ceph_wbc;
    803	bool should_loop, range_whole = false;
    804	bool done = false;
    805	bool caching = ceph_is_cache_enabled(inode);
    806
    807	if (wbc->sync_mode == WB_SYNC_NONE &&
    808	    fsc->write_congested)
    809		return 0;
    810
    811	dout("writepages_start %p (mode=%s)\n", inode,
    812	     wbc->sync_mode == WB_SYNC_NONE ? "NONE" :
    813	     (wbc->sync_mode == WB_SYNC_ALL ? "ALL" : "HOLD"));
    814
    815	if (ceph_inode_is_shutdown(inode)) {
    816		if (ci->i_wrbuffer_ref > 0) {
    817			pr_warn_ratelimited(
    818				"writepage_start %p %lld forced umount\n",
    819				inode, ceph_ino(inode));
    820		}
    821		mapping_set_error(mapping, -EIO);
    822		return -EIO; /* we're in a forced umount, don't write! */
    823	}
    824	if (fsc->mount_options->wsize < wsize)
    825		wsize = fsc->mount_options->wsize;
    826
    827	pagevec_init(&pvec);
    828
    829	start_index = wbc->range_cyclic ? mapping->writeback_index : 0;
    830	index = start_index;
    831
    832retry:
    833	/* find oldest snap context with dirty data */
    834	snapc = get_oldest_context(inode, &ceph_wbc, NULL);
    835	if (!snapc) {
    836		/* hmm, why does writepages get called when there
    837		   is no dirty data? */
    838		dout(" no snap context with dirty data?\n");
    839		goto out;
    840	}
    841	dout(" oldest snapc is %p seq %lld (%d snaps)\n",
    842	     snapc, snapc->seq, snapc->num_snaps);
    843
    844	should_loop = false;
    845	if (ceph_wbc.head_snapc && snapc != last_snapc) {
    846		/* where to start/end? */
    847		if (wbc->range_cyclic) {
    848			index = start_index;
    849			end = -1;
    850			if (index > 0)
    851				should_loop = true;
    852			dout(" cyclic, start at %lu\n", index);
    853		} else {
    854			index = wbc->range_start >> PAGE_SHIFT;
    855			end = wbc->range_end >> PAGE_SHIFT;
    856			if (wbc->range_start == 0 && wbc->range_end == LLONG_MAX)
    857				range_whole = true;
    858			dout(" not cyclic, %lu to %lu\n", index, end);
    859		}
    860	} else if (!ceph_wbc.head_snapc) {
    861		/* Do not respect wbc->range_{start,end}. Dirty pages
    862		 * in that range can be associated with newer snapc.
    863		 * They are not writeable until we write all dirty pages
    864		 * associated with 'snapc' get written */
    865		if (index > 0)
    866			should_loop = true;
    867		dout(" non-head snapc, range whole\n");
    868	}
    869
    870	ceph_put_snap_context(last_snapc);
    871	last_snapc = snapc;
    872
    873	while (!done && index <= end) {
    874		int num_ops = 0, op_idx;
    875		unsigned i, pvec_pages, max_pages, locked_pages = 0;
    876		struct page **pages = NULL, **data_pages;
    877		struct page *page;
    878		pgoff_t strip_unit_end = 0;
    879		u64 offset = 0, len = 0;
    880		bool from_pool = false;
    881
    882		max_pages = wsize >> PAGE_SHIFT;
    883
    884get_more_pages:
    885		pvec_pages = pagevec_lookup_range_tag(&pvec, mapping, &index,
    886						end, PAGECACHE_TAG_DIRTY);
    887		dout("pagevec_lookup_range_tag got %d\n", pvec_pages);
    888		if (!pvec_pages && !locked_pages)
    889			break;
    890		for (i = 0; i < pvec_pages && locked_pages < max_pages; i++) {
    891			page = pvec.pages[i];
    892			dout("? %p idx %lu\n", page, page->index);
    893			if (locked_pages == 0)
    894				lock_page(page);  /* first page */
    895			else if (!trylock_page(page))
    896				break;
    897
    898			/* only dirty pages, or our accounting breaks */
    899			if (unlikely(!PageDirty(page)) ||
    900			    unlikely(page->mapping != mapping)) {
    901				dout("!dirty or !mapping %p\n", page);
    902				unlock_page(page);
    903				continue;
    904			}
    905			/* only if matching snap context */
    906			pgsnapc = page_snap_context(page);
    907			if (pgsnapc != snapc) {
    908				dout("page snapc %p %lld != oldest %p %lld\n",
    909				     pgsnapc, pgsnapc->seq, snapc, snapc->seq);
    910				if (!should_loop &&
    911				    !ceph_wbc.head_snapc &&
    912				    wbc->sync_mode != WB_SYNC_NONE)
    913					should_loop = true;
    914				unlock_page(page);
    915				continue;
    916			}
    917			if (page_offset(page) >= ceph_wbc.i_size) {
    918				struct folio *folio = page_folio(page);
    919
    920				dout("folio at %lu beyond eof %llu\n",
    921				     folio->index, ceph_wbc.i_size);
    922				if ((ceph_wbc.size_stable ||
    923				    folio_pos(folio) >= i_size_read(inode)) &&
    924				    folio_clear_dirty_for_io(folio))
    925					folio_invalidate(folio, 0,
    926							folio_size(folio));
    927				folio_unlock(folio);
    928				continue;
    929			}
    930			if (strip_unit_end && (page->index > strip_unit_end)) {
    931				dout("end of strip unit %p\n", page);
    932				unlock_page(page);
    933				break;
    934			}
    935			if (PageWriteback(page) || PageFsCache(page)) {
    936				if (wbc->sync_mode == WB_SYNC_NONE) {
    937					dout("%p under writeback\n", page);
    938					unlock_page(page);
    939					continue;
    940				}
    941				dout("waiting on writeback %p\n", page);
    942				wait_on_page_writeback(page);
    943				wait_on_page_fscache(page);
    944			}
    945
    946			if (!clear_page_dirty_for_io(page)) {
    947				dout("%p !clear_page_dirty_for_io\n", page);
    948				unlock_page(page);
    949				continue;
    950			}
    951
    952			/*
    953			 * We have something to write.  If this is
    954			 * the first locked page this time through,
    955			 * calculate max possinle write size and
    956			 * allocate a page array
    957			 */
    958			if (locked_pages == 0) {
    959				u64 objnum;
    960				u64 objoff;
    961				u32 xlen;
    962
    963				/* prepare async write request */
    964				offset = (u64)page_offset(page);
    965				ceph_calc_file_object_mapping(&ci->i_layout,
    966							      offset, wsize,
    967							      &objnum, &objoff,
    968							      &xlen);
    969				len = xlen;
    970
    971				num_ops = 1;
    972				strip_unit_end = page->index +
    973					((len - 1) >> PAGE_SHIFT);
    974
    975				BUG_ON(pages);
    976				max_pages = calc_pages_for(0, (u64)len);
    977				pages = kmalloc_array(max_pages,
    978						      sizeof(*pages),
    979						      GFP_NOFS);
    980				if (!pages) {
    981					from_pool = true;
    982					pages = mempool_alloc(ceph_wb_pagevec_pool, GFP_NOFS);
    983					BUG_ON(!pages);
    984				}
    985
    986				len = 0;
    987			} else if (page->index !=
    988				   (offset + len) >> PAGE_SHIFT) {
    989				if (num_ops >= (from_pool ?  CEPH_OSD_SLAB_OPS :
    990							     CEPH_OSD_MAX_OPS)) {
    991					redirty_page_for_writepage(wbc, page);
    992					unlock_page(page);
    993					break;
    994				}
    995
    996				num_ops++;
    997				offset = (u64)page_offset(page);
    998				len = 0;
    999			}
   1000
   1001			/* note position of first page in pvec */
   1002			dout("%p will write page %p idx %lu\n",
   1003			     inode, page, page->index);
   1004
   1005			if (atomic_long_inc_return(&fsc->writeback_count) >
   1006			    CONGESTION_ON_THRESH(
   1007				    fsc->mount_options->congestion_kb))
   1008				fsc->write_congested = true;
   1009
   1010			pages[locked_pages++] = page;
   1011			pvec.pages[i] = NULL;
   1012
   1013			len += thp_size(page);
   1014		}
   1015
   1016		/* did we get anything? */
   1017		if (!locked_pages)
   1018			goto release_pvec_pages;
   1019		if (i) {
   1020			unsigned j, n = 0;
   1021			/* shift unused page to beginning of pvec */
   1022			for (j = 0; j < pvec_pages; j++) {
   1023				if (!pvec.pages[j])
   1024					continue;
   1025				if (n < j)
   1026					pvec.pages[n] = pvec.pages[j];
   1027				n++;
   1028			}
   1029			pvec.nr = n;
   1030
   1031			if (pvec_pages && i == pvec_pages &&
   1032			    locked_pages < max_pages) {
   1033				dout("reached end pvec, trying for more\n");
   1034				pagevec_release(&pvec);
   1035				goto get_more_pages;
   1036			}
   1037		}
   1038
   1039new_request:
   1040		offset = page_offset(pages[0]);
   1041		len = wsize;
   1042
   1043		req = ceph_osdc_new_request(&fsc->client->osdc,
   1044					&ci->i_layout, vino,
   1045					offset, &len, 0, num_ops,
   1046					CEPH_OSD_OP_WRITE, CEPH_OSD_FLAG_WRITE,
   1047					snapc, ceph_wbc.truncate_seq,
   1048					ceph_wbc.truncate_size, false);
   1049		if (IS_ERR(req)) {
   1050			req = ceph_osdc_new_request(&fsc->client->osdc,
   1051						&ci->i_layout, vino,
   1052						offset, &len, 0,
   1053						min(num_ops,
   1054						    CEPH_OSD_SLAB_OPS),
   1055						CEPH_OSD_OP_WRITE,
   1056						CEPH_OSD_FLAG_WRITE,
   1057						snapc, ceph_wbc.truncate_seq,
   1058						ceph_wbc.truncate_size, true);
   1059			BUG_ON(IS_ERR(req));
   1060		}
   1061		BUG_ON(len < page_offset(pages[locked_pages - 1]) +
   1062			     thp_size(page) - offset);
   1063
   1064		req->r_callback = writepages_finish;
   1065		req->r_inode = inode;
   1066
   1067		/* Format the osd request message and submit the write */
   1068		len = 0;
   1069		data_pages = pages;
   1070		op_idx = 0;
   1071		for (i = 0; i < locked_pages; i++) {
   1072			u64 cur_offset = page_offset(pages[i]);
   1073			/*
   1074			 * Discontinuity in page range? Ceph can handle that by just passing
   1075			 * multiple extents in the write op.
   1076			 */
   1077			if (offset + len != cur_offset) {
   1078				/* If it's full, stop here */
   1079				if (op_idx + 1 == req->r_num_ops)
   1080					break;
   1081
   1082				/* Kick off an fscache write with what we have so far. */
   1083				ceph_fscache_write_to_cache(inode, offset, len, caching);
   1084
   1085				/* Start a new extent */
   1086				osd_req_op_extent_dup_last(req, op_idx,
   1087							   cur_offset - offset);
   1088				dout("writepages got pages at %llu~%llu\n",
   1089				     offset, len);
   1090				osd_req_op_extent_osd_data_pages(req, op_idx,
   1091							data_pages, len, 0,
   1092							from_pool, false);
   1093				osd_req_op_extent_update(req, op_idx, len);
   1094
   1095				len = 0;
   1096				offset = cur_offset;
   1097				data_pages = pages + i;
   1098				op_idx++;
   1099			}
   1100
   1101			set_page_writeback(pages[i]);
   1102			if (caching)
   1103				ceph_set_page_fscache(pages[i]);
   1104			len += thp_size(page);
   1105		}
   1106		ceph_fscache_write_to_cache(inode, offset, len, caching);
   1107
   1108		if (ceph_wbc.size_stable) {
   1109			len = min(len, ceph_wbc.i_size - offset);
   1110		} else if (i == locked_pages) {
   1111			/* writepages_finish() clears writeback pages
   1112			 * according to the data length, so make sure
   1113			 * data length covers all locked pages */
   1114			u64 min_len = len + 1 - thp_size(page);
   1115			len = get_writepages_data_length(inode, pages[i - 1],
   1116							 offset);
   1117			len = max(len, min_len);
   1118		}
   1119		dout("writepages got pages at %llu~%llu\n", offset, len);
   1120
   1121		osd_req_op_extent_osd_data_pages(req, op_idx, data_pages, len,
   1122						 0, from_pool, false);
   1123		osd_req_op_extent_update(req, op_idx, len);
   1124
   1125		BUG_ON(op_idx + 1 != req->r_num_ops);
   1126
   1127		from_pool = false;
   1128		if (i < locked_pages) {
   1129			BUG_ON(num_ops <= req->r_num_ops);
   1130			num_ops -= req->r_num_ops;
   1131			locked_pages -= i;
   1132
   1133			/* allocate new pages array for next request */
   1134			data_pages = pages;
   1135			pages = kmalloc_array(locked_pages, sizeof(*pages),
   1136					      GFP_NOFS);
   1137			if (!pages) {
   1138				from_pool = true;
   1139				pages = mempool_alloc(ceph_wb_pagevec_pool, GFP_NOFS);
   1140				BUG_ON(!pages);
   1141			}
   1142			memcpy(pages, data_pages + i,
   1143			       locked_pages * sizeof(*pages));
   1144			memset(data_pages + i, 0,
   1145			       locked_pages * sizeof(*pages));
   1146		} else {
   1147			BUG_ON(num_ops != req->r_num_ops);
   1148			index = pages[i - 1]->index + 1;
   1149			/* request message now owns the pages array */
   1150			pages = NULL;
   1151		}
   1152
   1153		req->r_mtime = inode->i_mtime;
   1154		rc = ceph_osdc_start_request(&fsc->client->osdc, req, true);
   1155		BUG_ON(rc);
   1156		req = NULL;
   1157
   1158		wbc->nr_to_write -= i;
   1159		if (pages)
   1160			goto new_request;
   1161
   1162		/*
   1163		 * We stop writing back only if we are not doing
   1164		 * integrity sync. In case of integrity sync we have to
   1165		 * keep going until we have written all the pages
   1166		 * we tagged for writeback prior to entering this loop.
   1167		 */
   1168		if (wbc->nr_to_write <= 0 && wbc->sync_mode == WB_SYNC_NONE)
   1169			done = true;
   1170
   1171release_pvec_pages:
   1172		dout("pagevec_release on %d pages (%p)\n", (int)pvec.nr,
   1173		     pvec.nr ? pvec.pages[0] : NULL);
   1174		pagevec_release(&pvec);
   1175	}
   1176
   1177	if (should_loop && !done) {
   1178		/* more to do; loop back to beginning of file */
   1179		dout("writepages looping back to beginning of file\n");
   1180		end = start_index - 1; /* OK even when start_index == 0 */
   1181
   1182		/* to write dirty pages associated with next snapc,
   1183		 * we need to wait until current writes complete */
   1184		if (wbc->sync_mode != WB_SYNC_NONE &&
   1185		    start_index == 0 && /* all dirty pages were checked */
   1186		    !ceph_wbc.head_snapc) {
   1187			struct page *page;
   1188			unsigned i, nr;
   1189			index = 0;
   1190			while ((index <= end) &&
   1191			       (nr = pagevec_lookup_tag(&pvec, mapping, &index,
   1192						PAGECACHE_TAG_WRITEBACK))) {
   1193				for (i = 0; i < nr; i++) {
   1194					page = pvec.pages[i];
   1195					if (page_snap_context(page) != snapc)
   1196						continue;
   1197					wait_on_page_writeback(page);
   1198				}
   1199				pagevec_release(&pvec);
   1200				cond_resched();
   1201			}
   1202		}
   1203
   1204		start_index = 0;
   1205		index = 0;
   1206		goto retry;
   1207	}
   1208
   1209	if (wbc->range_cyclic || (range_whole && wbc->nr_to_write > 0))
   1210		mapping->writeback_index = index;
   1211
   1212out:
   1213	ceph_osdc_put_request(req);
   1214	ceph_put_snap_context(last_snapc);
   1215	dout("writepages dend - startone, rc = %d\n", rc);
   1216	return rc;
   1217}
   1218
   1219
   1220
   1221/*
   1222 * See if a given @snapc is either writeable, or already written.
   1223 */
   1224static int context_is_writeable_or_written(struct inode *inode,
   1225					   struct ceph_snap_context *snapc)
   1226{
   1227	struct ceph_snap_context *oldest = get_oldest_context(inode, NULL, NULL);
   1228	int ret = !oldest || snapc->seq <= oldest->seq;
   1229
   1230	ceph_put_snap_context(oldest);
   1231	return ret;
   1232}
   1233
   1234/**
   1235 * ceph_find_incompatible - find an incompatible context and return it
   1236 * @page: page being dirtied
   1237 *
   1238 * We are only allowed to write into/dirty a page if the page is
   1239 * clean, or already dirty within the same snap context. Returns a
   1240 * conflicting context if there is one, NULL if there isn't, or a
   1241 * negative error code on other errors.
   1242 *
   1243 * Must be called with page lock held.
   1244 */
   1245static struct ceph_snap_context *
   1246ceph_find_incompatible(struct page *page)
   1247{
   1248	struct inode *inode = page->mapping->host;
   1249	struct ceph_inode_info *ci = ceph_inode(inode);
   1250
   1251	if (ceph_inode_is_shutdown(inode)) {
   1252		dout(" page %p %llx:%llx is shutdown\n", page,
   1253		     ceph_vinop(inode));
   1254		return ERR_PTR(-ESTALE);
   1255	}
   1256
   1257	for (;;) {
   1258		struct ceph_snap_context *snapc, *oldest;
   1259
   1260		wait_on_page_writeback(page);
   1261
   1262		snapc = page_snap_context(page);
   1263		if (!snapc || snapc == ci->i_head_snapc)
   1264			break;
   1265
   1266		/*
   1267		 * this page is already dirty in another (older) snap
   1268		 * context!  is it writeable now?
   1269		 */
   1270		oldest = get_oldest_context(inode, NULL, NULL);
   1271		if (snapc->seq > oldest->seq) {
   1272			/* not writeable -- return it for the caller to deal with */
   1273			ceph_put_snap_context(oldest);
   1274			dout(" page %p snapc %p not current or oldest\n", page, snapc);
   1275			return ceph_get_snap_context(snapc);
   1276		}
   1277		ceph_put_snap_context(oldest);
   1278
   1279		/* yay, writeable, do it now (without dropping page lock) */
   1280		dout(" page %p snapc %p not current, but oldest\n", page, snapc);
   1281		if (clear_page_dirty_for_io(page)) {
   1282			int r = writepage_nounlock(page, NULL);
   1283			if (r < 0)
   1284				return ERR_PTR(r);
   1285		}
   1286	}
   1287	return NULL;
   1288}
   1289
   1290static int ceph_netfs_check_write_begin(struct file *file, loff_t pos, unsigned int len,
   1291					struct folio *folio, void **_fsdata)
   1292{
   1293	struct inode *inode = file_inode(file);
   1294	struct ceph_inode_info *ci = ceph_inode(inode);
   1295	struct ceph_snap_context *snapc;
   1296
   1297	snapc = ceph_find_incompatible(folio_page(folio, 0));
   1298	if (snapc) {
   1299		int r;
   1300
   1301		folio_unlock(folio);
   1302		folio_put(folio);
   1303		if (IS_ERR(snapc))
   1304			return PTR_ERR(snapc);
   1305
   1306		ceph_queue_writeback(inode);
   1307		r = wait_event_killable(ci->i_cap_wq,
   1308					context_is_writeable_or_written(inode, snapc));
   1309		ceph_put_snap_context(snapc);
   1310		return r == 0 ? -EAGAIN : r;
   1311	}
   1312	return 0;
   1313}
   1314
   1315/*
   1316 * We are only allowed to write into/dirty the page if the page is
   1317 * clean, or already dirty within the same snap context.
   1318 */
   1319static int ceph_write_begin(struct file *file, struct address_space *mapping,
   1320			    loff_t pos, unsigned len,
   1321			    struct page **pagep, void **fsdata)
   1322{
   1323	struct inode *inode = file_inode(file);
   1324	struct ceph_inode_info *ci = ceph_inode(inode);
   1325	struct folio *folio = NULL;
   1326	int r;
   1327
   1328	r = netfs_write_begin(&ci->netfs, file, inode->i_mapping, pos, len, &folio, NULL);
   1329	if (r == 0)
   1330		folio_wait_fscache(folio);
   1331	if (r < 0) {
   1332		if (folio)
   1333			folio_put(folio);
   1334	} else {
   1335		WARN_ON_ONCE(!folio_test_locked(folio));
   1336		*pagep = &folio->page;
   1337	}
   1338	return r;
   1339}
   1340
   1341/*
   1342 * we don't do anything in here that simple_write_end doesn't do
   1343 * except adjust dirty page accounting
   1344 */
   1345static int ceph_write_end(struct file *file, struct address_space *mapping,
   1346			  loff_t pos, unsigned len, unsigned copied,
   1347			  struct page *subpage, void *fsdata)
   1348{
   1349	struct folio *folio = page_folio(subpage);
   1350	struct inode *inode = file_inode(file);
   1351	bool check_cap = false;
   1352
   1353	dout("write_end file %p inode %p folio %p %d~%d (%d)\n", file,
   1354	     inode, folio, (int)pos, (int)copied, (int)len);
   1355
   1356	if (!folio_test_uptodate(folio)) {
   1357		/* just return that nothing was copied on a short copy */
   1358		if (copied < len) {
   1359			copied = 0;
   1360			goto out;
   1361		}
   1362		folio_mark_uptodate(folio);
   1363	}
   1364
   1365	/* did file size increase? */
   1366	if (pos+copied > i_size_read(inode))
   1367		check_cap = ceph_inode_set_size(inode, pos+copied);
   1368
   1369	folio_mark_dirty(folio);
   1370
   1371out:
   1372	folio_unlock(folio);
   1373	folio_put(folio);
   1374
   1375	if (check_cap)
   1376		ceph_check_caps(ceph_inode(inode), CHECK_CAPS_AUTHONLY, NULL);
   1377
   1378	return copied;
   1379}
   1380
   1381const struct address_space_operations ceph_aops = {
   1382	.read_folio = netfs_read_folio,
   1383	.readahead = netfs_readahead,
   1384	.writepage = ceph_writepage,
   1385	.writepages = ceph_writepages_start,
   1386	.write_begin = ceph_write_begin,
   1387	.write_end = ceph_write_end,
   1388	.dirty_folio = ceph_dirty_folio,
   1389	.invalidate_folio = ceph_invalidate_folio,
   1390	.release_folio = ceph_release_folio,
   1391	.direct_IO = noop_direct_IO,
   1392};
   1393
   1394static void ceph_block_sigs(sigset_t *oldset)
   1395{
   1396	sigset_t mask;
   1397	siginitsetinv(&mask, sigmask(SIGKILL));
   1398	sigprocmask(SIG_BLOCK, &mask, oldset);
   1399}
   1400
   1401static void ceph_restore_sigs(sigset_t *oldset)
   1402{
   1403	sigprocmask(SIG_SETMASK, oldset, NULL);
   1404}
   1405
   1406/*
   1407 * vm ops
   1408 */
   1409static vm_fault_t ceph_filemap_fault(struct vm_fault *vmf)
   1410{
   1411	struct vm_area_struct *vma = vmf->vma;
   1412	struct inode *inode = file_inode(vma->vm_file);
   1413	struct ceph_inode_info *ci = ceph_inode(inode);
   1414	struct ceph_file_info *fi = vma->vm_file->private_data;
   1415	loff_t off = (loff_t)vmf->pgoff << PAGE_SHIFT;
   1416	int want, got, err;
   1417	sigset_t oldset;
   1418	vm_fault_t ret = VM_FAULT_SIGBUS;
   1419
   1420	if (ceph_inode_is_shutdown(inode))
   1421		return ret;
   1422
   1423	ceph_block_sigs(&oldset);
   1424
   1425	dout("filemap_fault %p %llx.%llx %llu trying to get caps\n",
   1426	     inode, ceph_vinop(inode), off);
   1427	if (fi->fmode & CEPH_FILE_MODE_LAZY)
   1428		want = CEPH_CAP_FILE_CACHE | CEPH_CAP_FILE_LAZYIO;
   1429	else
   1430		want = CEPH_CAP_FILE_CACHE;
   1431
   1432	got = 0;
   1433	err = ceph_get_caps(vma->vm_file, CEPH_CAP_FILE_RD, want, -1, &got);
   1434	if (err < 0)
   1435		goto out_restore;
   1436
   1437	dout("filemap_fault %p %llu got cap refs on %s\n",
   1438	     inode, off, ceph_cap_string(got));
   1439
   1440	if ((got & (CEPH_CAP_FILE_CACHE | CEPH_CAP_FILE_LAZYIO)) ||
   1441	    ci->i_inline_version == CEPH_INLINE_NONE) {
   1442		CEPH_DEFINE_RW_CONTEXT(rw_ctx, got);
   1443		ceph_add_rw_context(fi, &rw_ctx);
   1444		ret = filemap_fault(vmf);
   1445		ceph_del_rw_context(fi, &rw_ctx);
   1446		dout("filemap_fault %p %llu drop cap refs %s ret %x\n",
   1447		     inode, off, ceph_cap_string(got), ret);
   1448	} else
   1449		err = -EAGAIN;
   1450
   1451	ceph_put_cap_refs(ci, got);
   1452
   1453	if (err != -EAGAIN)
   1454		goto out_restore;
   1455
   1456	/* read inline data */
   1457	if (off >= PAGE_SIZE) {
   1458		/* does not support inline data > PAGE_SIZE */
   1459		ret = VM_FAULT_SIGBUS;
   1460	} else {
   1461		struct address_space *mapping = inode->i_mapping;
   1462		struct page *page;
   1463
   1464		filemap_invalidate_lock_shared(mapping);
   1465		page = find_or_create_page(mapping, 0,
   1466				mapping_gfp_constraint(mapping, ~__GFP_FS));
   1467		if (!page) {
   1468			ret = VM_FAULT_OOM;
   1469			goto out_inline;
   1470		}
   1471		err = __ceph_do_getattr(inode, page,
   1472					 CEPH_STAT_CAP_INLINE_DATA, true);
   1473		if (err < 0 || off >= i_size_read(inode)) {
   1474			unlock_page(page);
   1475			put_page(page);
   1476			ret = vmf_error(err);
   1477			goto out_inline;
   1478		}
   1479		if (err < PAGE_SIZE)
   1480			zero_user_segment(page, err, PAGE_SIZE);
   1481		else
   1482			flush_dcache_page(page);
   1483		SetPageUptodate(page);
   1484		vmf->page = page;
   1485		ret = VM_FAULT_MAJOR | VM_FAULT_LOCKED;
   1486out_inline:
   1487		filemap_invalidate_unlock_shared(mapping);
   1488		dout("filemap_fault %p %llu read inline data ret %x\n",
   1489		     inode, off, ret);
   1490	}
   1491out_restore:
   1492	ceph_restore_sigs(&oldset);
   1493	if (err < 0)
   1494		ret = vmf_error(err);
   1495
   1496	return ret;
   1497}
   1498
   1499static vm_fault_t ceph_page_mkwrite(struct vm_fault *vmf)
   1500{
   1501	struct vm_area_struct *vma = vmf->vma;
   1502	struct inode *inode = file_inode(vma->vm_file);
   1503	struct ceph_inode_info *ci = ceph_inode(inode);
   1504	struct ceph_file_info *fi = vma->vm_file->private_data;
   1505	struct ceph_cap_flush *prealloc_cf;
   1506	struct page *page = vmf->page;
   1507	loff_t off = page_offset(page);
   1508	loff_t size = i_size_read(inode);
   1509	size_t len;
   1510	int want, got, err;
   1511	sigset_t oldset;
   1512	vm_fault_t ret = VM_FAULT_SIGBUS;
   1513
   1514	if (ceph_inode_is_shutdown(inode))
   1515		return ret;
   1516
   1517	prealloc_cf = ceph_alloc_cap_flush();
   1518	if (!prealloc_cf)
   1519		return VM_FAULT_OOM;
   1520
   1521	sb_start_pagefault(inode->i_sb);
   1522	ceph_block_sigs(&oldset);
   1523
   1524	if (off + thp_size(page) <= size)
   1525		len = thp_size(page);
   1526	else
   1527		len = offset_in_thp(page, size);
   1528
   1529	dout("page_mkwrite %p %llx.%llx %llu~%zd getting caps i_size %llu\n",
   1530	     inode, ceph_vinop(inode), off, len, size);
   1531	if (fi->fmode & CEPH_FILE_MODE_LAZY)
   1532		want = CEPH_CAP_FILE_BUFFER | CEPH_CAP_FILE_LAZYIO;
   1533	else
   1534		want = CEPH_CAP_FILE_BUFFER;
   1535
   1536	got = 0;
   1537	err = ceph_get_caps(vma->vm_file, CEPH_CAP_FILE_WR, want, off + len, &got);
   1538	if (err < 0)
   1539		goto out_free;
   1540
   1541	dout("page_mkwrite %p %llu~%zd got cap refs on %s\n",
   1542	     inode, off, len, ceph_cap_string(got));
   1543
   1544	/* Update time before taking page lock */
   1545	file_update_time(vma->vm_file);
   1546	inode_inc_iversion_raw(inode);
   1547
   1548	do {
   1549		struct ceph_snap_context *snapc;
   1550
   1551		lock_page(page);
   1552
   1553		if (page_mkwrite_check_truncate(page, inode) < 0) {
   1554			unlock_page(page);
   1555			ret = VM_FAULT_NOPAGE;
   1556			break;
   1557		}
   1558
   1559		snapc = ceph_find_incompatible(page);
   1560		if (!snapc) {
   1561			/* success.  we'll keep the page locked. */
   1562			set_page_dirty(page);
   1563			ret = VM_FAULT_LOCKED;
   1564			break;
   1565		}
   1566
   1567		unlock_page(page);
   1568
   1569		if (IS_ERR(snapc)) {
   1570			ret = VM_FAULT_SIGBUS;
   1571			break;
   1572		}
   1573
   1574		ceph_queue_writeback(inode);
   1575		err = wait_event_killable(ci->i_cap_wq,
   1576				context_is_writeable_or_written(inode, snapc));
   1577		ceph_put_snap_context(snapc);
   1578	} while (err == 0);
   1579
   1580	if (ret == VM_FAULT_LOCKED) {
   1581		int dirty;
   1582		spin_lock(&ci->i_ceph_lock);
   1583		dirty = __ceph_mark_dirty_caps(ci, CEPH_CAP_FILE_WR,
   1584					       &prealloc_cf);
   1585		spin_unlock(&ci->i_ceph_lock);
   1586		if (dirty)
   1587			__mark_inode_dirty(inode, dirty);
   1588	}
   1589
   1590	dout("page_mkwrite %p %llu~%zd dropping cap refs on %s ret %x\n",
   1591	     inode, off, len, ceph_cap_string(got), ret);
   1592	ceph_put_cap_refs_async(ci, got);
   1593out_free:
   1594	ceph_restore_sigs(&oldset);
   1595	sb_end_pagefault(inode->i_sb);
   1596	ceph_free_cap_flush(prealloc_cf);
   1597	if (err < 0)
   1598		ret = vmf_error(err);
   1599	return ret;
   1600}
   1601
   1602void ceph_fill_inline_data(struct inode *inode, struct page *locked_page,
   1603			   char	*data, size_t len)
   1604{
   1605	struct address_space *mapping = inode->i_mapping;
   1606	struct page *page;
   1607
   1608	if (locked_page) {
   1609		page = locked_page;
   1610	} else {
   1611		if (i_size_read(inode) == 0)
   1612			return;
   1613		page = find_or_create_page(mapping, 0,
   1614					   mapping_gfp_constraint(mapping,
   1615					   ~__GFP_FS));
   1616		if (!page)
   1617			return;
   1618		if (PageUptodate(page)) {
   1619			unlock_page(page);
   1620			put_page(page);
   1621			return;
   1622		}
   1623	}
   1624
   1625	dout("fill_inline_data %p %llx.%llx len %zu locked_page %p\n",
   1626	     inode, ceph_vinop(inode), len, locked_page);
   1627
   1628	if (len > 0) {
   1629		void *kaddr = kmap_atomic(page);
   1630		memcpy(kaddr, data, len);
   1631		kunmap_atomic(kaddr);
   1632	}
   1633
   1634	if (page != locked_page) {
   1635		if (len < PAGE_SIZE)
   1636			zero_user_segment(page, len, PAGE_SIZE);
   1637		else
   1638			flush_dcache_page(page);
   1639
   1640		SetPageUptodate(page);
   1641		unlock_page(page);
   1642		put_page(page);
   1643	}
   1644}
   1645
   1646int ceph_uninline_data(struct file *file)
   1647{
   1648	struct inode *inode = file_inode(file);
   1649	struct ceph_inode_info *ci = ceph_inode(inode);
   1650	struct ceph_fs_client *fsc = ceph_inode_to_client(inode);
   1651	struct ceph_osd_request *req = NULL;
   1652	struct ceph_cap_flush *prealloc_cf;
   1653	struct folio *folio = NULL;
   1654	u64 inline_version = CEPH_INLINE_NONE;
   1655	struct page *pages[1];
   1656	int err = 0;
   1657	u64 len;
   1658
   1659	spin_lock(&ci->i_ceph_lock);
   1660	inline_version = ci->i_inline_version;
   1661	spin_unlock(&ci->i_ceph_lock);
   1662
   1663	dout("uninline_data %p %llx.%llx inline_version %llu\n",
   1664	     inode, ceph_vinop(inode), inline_version);
   1665
   1666	if (inline_version == CEPH_INLINE_NONE)
   1667		return 0;
   1668
   1669	prealloc_cf = ceph_alloc_cap_flush();
   1670	if (!prealloc_cf)
   1671		return -ENOMEM;
   1672
   1673	if (inline_version == 1) /* initial version, no data */
   1674		goto out_uninline;
   1675
   1676	folio = read_mapping_folio(inode->i_mapping, 0, file);
   1677	if (IS_ERR(folio)) {
   1678		err = PTR_ERR(folio);
   1679		goto out;
   1680	}
   1681
   1682	folio_lock(folio);
   1683
   1684	len = i_size_read(inode);
   1685	if (len > folio_size(folio))
   1686		len = folio_size(folio);
   1687
   1688	req = ceph_osdc_new_request(&fsc->client->osdc, &ci->i_layout,
   1689				    ceph_vino(inode), 0, &len, 0, 1,
   1690				    CEPH_OSD_OP_CREATE, CEPH_OSD_FLAG_WRITE,
   1691				    NULL, 0, 0, false);
   1692	if (IS_ERR(req)) {
   1693		err = PTR_ERR(req);
   1694		goto out_unlock;
   1695	}
   1696
   1697	req->r_mtime = inode->i_mtime;
   1698	err = ceph_osdc_start_request(&fsc->client->osdc, req, false);
   1699	if (!err)
   1700		err = ceph_osdc_wait_request(&fsc->client->osdc, req);
   1701	ceph_osdc_put_request(req);
   1702	if (err < 0)
   1703		goto out_unlock;
   1704
   1705	req = ceph_osdc_new_request(&fsc->client->osdc, &ci->i_layout,
   1706				    ceph_vino(inode), 0, &len, 1, 3,
   1707				    CEPH_OSD_OP_WRITE, CEPH_OSD_FLAG_WRITE,
   1708				    NULL, ci->i_truncate_seq,
   1709				    ci->i_truncate_size, false);
   1710	if (IS_ERR(req)) {
   1711		err = PTR_ERR(req);
   1712		goto out_unlock;
   1713	}
   1714
   1715	pages[0] = folio_page(folio, 0);
   1716	osd_req_op_extent_osd_data_pages(req, 1, pages, len, 0, false, false);
   1717
   1718	{
   1719		__le64 xattr_buf = cpu_to_le64(inline_version);
   1720		err = osd_req_op_xattr_init(req, 0, CEPH_OSD_OP_CMPXATTR,
   1721					    "inline_version", &xattr_buf,
   1722					    sizeof(xattr_buf),
   1723					    CEPH_OSD_CMPXATTR_OP_GT,
   1724					    CEPH_OSD_CMPXATTR_MODE_U64);
   1725		if (err)
   1726			goto out_put_req;
   1727	}
   1728
   1729	{
   1730		char xattr_buf[32];
   1731		int xattr_len = snprintf(xattr_buf, sizeof(xattr_buf),
   1732					 "%llu", inline_version);
   1733		err = osd_req_op_xattr_init(req, 2, CEPH_OSD_OP_SETXATTR,
   1734					    "inline_version",
   1735					    xattr_buf, xattr_len, 0, 0);
   1736		if (err)
   1737			goto out_put_req;
   1738	}
   1739
   1740	req->r_mtime = inode->i_mtime;
   1741	err = ceph_osdc_start_request(&fsc->client->osdc, req, false);
   1742	if (!err)
   1743		err = ceph_osdc_wait_request(&fsc->client->osdc, req);
   1744
   1745	ceph_update_write_metrics(&fsc->mdsc->metric, req->r_start_latency,
   1746				  req->r_end_latency, len, err);
   1747
   1748out_uninline:
   1749	if (!err) {
   1750		int dirty;
   1751
   1752		/* Set to CAP_INLINE_NONE and dirty the caps */
   1753		down_read(&fsc->mdsc->snap_rwsem);
   1754		spin_lock(&ci->i_ceph_lock);
   1755		ci->i_inline_version = CEPH_INLINE_NONE;
   1756		dirty = __ceph_mark_dirty_caps(ci, CEPH_CAP_FILE_WR, &prealloc_cf);
   1757		spin_unlock(&ci->i_ceph_lock);
   1758		up_read(&fsc->mdsc->snap_rwsem);
   1759		if (dirty)
   1760			__mark_inode_dirty(inode, dirty);
   1761	}
   1762out_put_req:
   1763	ceph_osdc_put_request(req);
   1764	if (err == -ECANCELED)
   1765		err = 0;
   1766out_unlock:
   1767	if (folio) {
   1768		folio_unlock(folio);
   1769		folio_put(folio);
   1770	}
   1771out:
   1772	ceph_free_cap_flush(prealloc_cf);
   1773	dout("uninline_data %p %llx.%llx inline_version %llu = %d\n",
   1774	     inode, ceph_vinop(inode), inline_version, err);
   1775	return err;
   1776}
   1777
   1778static const struct vm_operations_struct ceph_vmops = {
   1779	.fault		= ceph_filemap_fault,
   1780	.page_mkwrite	= ceph_page_mkwrite,
   1781};
   1782
   1783int ceph_mmap(struct file *file, struct vm_area_struct *vma)
   1784{
   1785	struct address_space *mapping = file->f_mapping;
   1786
   1787	if (!mapping->a_ops->read_folio)
   1788		return -ENOEXEC;
   1789	vma->vm_ops = &ceph_vmops;
   1790	return 0;
   1791}
   1792
   1793enum {
   1794	POOL_READ	= 1,
   1795	POOL_WRITE	= 2,
   1796};
   1797
   1798static int __ceph_pool_perm_get(struct ceph_inode_info *ci,
   1799				s64 pool, struct ceph_string *pool_ns)
   1800{
   1801	struct ceph_fs_client *fsc = ceph_inode_to_client(&ci->netfs.inode);
   1802	struct ceph_mds_client *mdsc = fsc->mdsc;
   1803	struct ceph_osd_request *rd_req = NULL, *wr_req = NULL;
   1804	struct rb_node **p, *parent;
   1805	struct ceph_pool_perm *perm;
   1806	struct page **pages;
   1807	size_t pool_ns_len;
   1808	int err = 0, err2 = 0, have = 0;
   1809
   1810	down_read(&mdsc->pool_perm_rwsem);
   1811	p = &mdsc->pool_perm_tree.rb_node;
   1812	while (*p) {
   1813		perm = rb_entry(*p, struct ceph_pool_perm, node);
   1814		if (pool < perm->pool)
   1815			p = &(*p)->rb_left;
   1816		else if (pool > perm->pool)
   1817			p = &(*p)->rb_right;
   1818		else {
   1819			int ret = ceph_compare_string(pool_ns,
   1820						perm->pool_ns,
   1821						perm->pool_ns_len);
   1822			if (ret < 0)
   1823				p = &(*p)->rb_left;
   1824			else if (ret > 0)
   1825				p = &(*p)->rb_right;
   1826			else {
   1827				have = perm->perm;
   1828				break;
   1829			}
   1830		}
   1831	}
   1832	up_read(&mdsc->pool_perm_rwsem);
   1833	if (*p)
   1834		goto out;
   1835
   1836	if (pool_ns)
   1837		dout("__ceph_pool_perm_get pool %lld ns %.*s no perm cached\n",
   1838		     pool, (int)pool_ns->len, pool_ns->str);
   1839	else
   1840		dout("__ceph_pool_perm_get pool %lld no perm cached\n", pool);
   1841
   1842	down_write(&mdsc->pool_perm_rwsem);
   1843	p = &mdsc->pool_perm_tree.rb_node;
   1844	parent = NULL;
   1845	while (*p) {
   1846		parent = *p;
   1847		perm = rb_entry(parent, struct ceph_pool_perm, node);
   1848		if (pool < perm->pool)
   1849			p = &(*p)->rb_left;
   1850		else if (pool > perm->pool)
   1851			p = &(*p)->rb_right;
   1852		else {
   1853			int ret = ceph_compare_string(pool_ns,
   1854						perm->pool_ns,
   1855						perm->pool_ns_len);
   1856			if (ret < 0)
   1857				p = &(*p)->rb_left;
   1858			else if (ret > 0)
   1859				p = &(*p)->rb_right;
   1860			else {
   1861				have = perm->perm;
   1862				break;
   1863			}
   1864		}
   1865	}
   1866	if (*p) {
   1867		up_write(&mdsc->pool_perm_rwsem);
   1868		goto out;
   1869	}
   1870
   1871	rd_req = ceph_osdc_alloc_request(&fsc->client->osdc, NULL,
   1872					 1, false, GFP_NOFS);
   1873	if (!rd_req) {
   1874		err = -ENOMEM;
   1875		goto out_unlock;
   1876	}
   1877
   1878	rd_req->r_flags = CEPH_OSD_FLAG_READ;
   1879	osd_req_op_init(rd_req, 0, CEPH_OSD_OP_STAT, 0);
   1880	rd_req->r_base_oloc.pool = pool;
   1881	if (pool_ns)
   1882		rd_req->r_base_oloc.pool_ns = ceph_get_string(pool_ns);
   1883	ceph_oid_printf(&rd_req->r_base_oid, "%llx.00000000", ci->i_vino.ino);
   1884
   1885	err = ceph_osdc_alloc_messages(rd_req, GFP_NOFS);
   1886	if (err)
   1887		goto out_unlock;
   1888
   1889	wr_req = ceph_osdc_alloc_request(&fsc->client->osdc, NULL,
   1890					 1, false, GFP_NOFS);
   1891	if (!wr_req) {
   1892		err = -ENOMEM;
   1893		goto out_unlock;
   1894	}
   1895
   1896	wr_req->r_flags = CEPH_OSD_FLAG_WRITE;
   1897	osd_req_op_init(wr_req, 0, CEPH_OSD_OP_CREATE, CEPH_OSD_OP_FLAG_EXCL);
   1898	ceph_oloc_copy(&wr_req->r_base_oloc, &rd_req->r_base_oloc);
   1899	ceph_oid_copy(&wr_req->r_base_oid, &rd_req->r_base_oid);
   1900
   1901	err = ceph_osdc_alloc_messages(wr_req, GFP_NOFS);
   1902	if (err)
   1903		goto out_unlock;
   1904
   1905	/* one page should be large enough for STAT data */
   1906	pages = ceph_alloc_page_vector(1, GFP_KERNEL);
   1907	if (IS_ERR(pages)) {
   1908		err = PTR_ERR(pages);
   1909		goto out_unlock;
   1910	}
   1911
   1912	osd_req_op_raw_data_in_pages(rd_req, 0, pages, PAGE_SIZE,
   1913				     0, false, true);
   1914	err = ceph_osdc_start_request(&fsc->client->osdc, rd_req, false);
   1915
   1916	wr_req->r_mtime = ci->netfs.inode.i_mtime;
   1917	err2 = ceph_osdc_start_request(&fsc->client->osdc, wr_req, false);
   1918
   1919	if (!err)
   1920		err = ceph_osdc_wait_request(&fsc->client->osdc, rd_req);
   1921	if (!err2)
   1922		err2 = ceph_osdc_wait_request(&fsc->client->osdc, wr_req);
   1923
   1924	if (err >= 0 || err == -ENOENT)
   1925		have |= POOL_READ;
   1926	else if (err != -EPERM) {
   1927		if (err == -EBLOCKLISTED)
   1928			fsc->blocklisted = true;
   1929		goto out_unlock;
   1930	}
   1931
   1932	if (err2 == 0 || err2 == -EEXIST)
   1933		have |= POOL_WRITE;
   1934	else if (err2 != -EPERM) {
   1935		if (err2 == -EBLOCKLISTED)
   1936			fsc->blocklisted = true;
   1937		err = err2;
   1938		goto out_unlock;
   1939	}
   1940
   1941	pool_ns_len = pool_ns ? pool_ns->len : 0;
   1942	perm = kmalloc(sizeof(*perm) + pool_ns_len + 1, GFP_NOFS);
   1943	if (!perm) {
   1944		err = -ENOMEM;
   1945		goto out_unlock;
   1946	}
   1947
   1948	perm->pool = pool;
   1949	perm->perm = have;
   1950	perm->pool_ns_len = pool_ns_len;
   1951	if (pool_ns_len > 0)
   1952		memcpy(perm->pool_ns, pool_ns->str, pool_ns_len);
   1953	perm->pool_ns[pool_ns_len] = 0;
   1954
   1955	rb_link_node(&perm->node, parent, p);
   1956	rb_insert_color(&perm->node, &mdsc->pool_perm_tree);
   1957	err = 0;
   1958out_unlock:
   1959	up_write(&mdsc->pool_perm_rwsem);
   1960
   1961	ceph_osdc_put_request(rd_req);
   1962	ceph_osdc_put_request(wr_req);
   1963out:
   1964	if (!err)
   1965		err = have;
   1966	if (pool_ns)
   1967		dout("__ceph_pool_perm_get pool %lld ns %.*s result = %d\n",
   1968		     pool, (int)pool_ns->len, pool_ns->str, err);
   1969	else
   1970		dout("__ceph_pool_perm_get pool %lld result = %d\n", pool, err);
   1971	return err;
   1972}
   1973
   1974int ceph_pool_perm_check(struct inode *inode, int need)
   1975{
   1976	struct ceph_inode_info *ci = ceph_inode(inode);
   1977	struct ceph_string *pool_ns;
   1978	s64 pool;
   1979	int ret, flags;
   1980
   1981	/* Only need to do this for regular files */
   1982	if (!S_ISREG(inode->i_mode))
   1983		return 0;
   1984
   1985	if (ci->i_vino.snap != CEPH_NOSNAP) {
   1986		/*
   1987		 * Pool permission check needs to write to the first object.
   1988		 * But for snapshot, head of the first object may have alread
   1989		 * been deleted. Skip check to avoid creating orphan object.
   1990		 */
   1991		return 0;
   1992	}
   1993
   1994	if (ceph_test_mount_opt(ceph_inode_to_client(inode),
   1995				NOPOOLPERM))
   1996		return 0;
   1997
   1998	spin_lock(&ci->i_ceph_lock);
   1999	flags = ci->i_ceph_flags;
   2000	pool = ci->i_layout.pool_id;
   2001	spin_unlock(&ci->i_ceph_lock);
   2002check:
   2003	if (flags & CEPH_I_POOL_PERM) {
   2004		if ((need & CEPH_CAP_FILE_RD) && !(flags & CEPH_I_POOL_RD)) {
   2005			dout("ceph_pool_perm_check pool %lld no read perm\n",
   2006			     pool);
   2007			return -EPERM;
   2008		}
   2009		if ((need & CEPH_CAP_FILE_WR) && !(flags & CEPH_I_POOL_WR)) {
   2010			dout("ceph_pool_perm_check pool %lld no write perm\n",
   2011			     pool);
   2012			return -EPERM;
   2013		}
   2014		return 0;
   2015	}
   2016
   2017	pool_ns = ceph_try_get_string(ci->i_layout.pool_ns);
   2018	ret = __ceph_pool_perm_get(ci, pool, pool_ns);
   2019	ceph_put_string(pool_ns);
   2020	if (ret < 0)
   2021		return ret;
   2022
   2023	flags = CEPH_I_POOL_PERM;
   2024	if (ret & POOL_READ)
   2025		flags |= CEPH_I_POOL_RD;
   2026	if (ret & POOL_WRITE)
   2027		flags |= CEPH_I_POOL_WR;
   2028
   2029	spin_lock(&ci->i_ceph_lock);
   2030	if (pool == ci->i_layout.pool_id &&
   2031	    pool_ns == rcu_dereference_raw(ci->i_layout.pool_ns)) {
   2032		ci->i_ceph_flags |= flags;
   2033        } else {
   2034		pool = ci->i_layout.pool_id;
   2035		flags = ci->i_ceph_flags;
   2036	}
   2037	spin_unlock(&ci->i_ceph_lock);
   2038	goto check;
   2039}
   2040
   2041void ceph_pool_perm_destroy(struct ceph_mds_client *mdsc)
   2042{
   2043	struct ceph_pool_perm *perm;
   2044	struct rb_node *n;
   2045
   2046	while (!RB_EMPTY_ROOT(&mdsc->pool_perm_tree)) {
   2047		n = rb_first(&mdsc->pool_perm_tree);
   2048		perm = rb_entry(n, struct ceph_pool_perm, node);
   2049		rb_erase(n, &mdsc->pool_perm_tree);
   2050		kfree(perm);
   2051	}
   2052}