Commit 12f8e18a authored by Ye Bin's avatar Ye Bin Committed by Baokun Li
Browse files

jbd2: avoid mount failed when commit block is partial submitted

mainline inclusion
from mainline-v6.11-rc1
commit 0bab8db4152c4a2185a1367db09cc402bdc62d5e
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/IAJ5DD
CVE: NA

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0bab8db4152c4a2185a1367db09cc402bdc62d5e



--------------------------------

We encountered a problem that the file system could not be mounted in
the power-off scenario. The analysis of the file system mirror shows that
only part of the data is written to the last commit block.
The valid data of the commit block is concentrated in the first sector.
However, the data of the entire block is involved in the checksum calculation.
For different hardware, the minimum atomic unit may be different.
If the checksum of a committed block is incorrect, clear the data except the
'commit_header' and then calculate the checksum. If the checkusm is correct,
it is considered that the block is partially committed, Then continue to replay
journal.

Signed-off-by: default avatarYe Bin <yebin10@huawei.com>
Reviewed-by: default avatarJan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20240620072405.3533701-1-yebin@huaweicloud.com


Signed-off-by: default avatarTheodore Ts'o <tytso@mit.edu>

Conflicts:
	fs/jbd2/recovery.c
[There is a context conflict because commit a20d1ceb ("jbd2: fix
portability problems caused by unaligned accesses") is not merged.]
Signed-off-by: default avatarBaokun Li <libaokun1@huawei.com>
parent f40e2e86
Loading
Loading
Loading
Loading
+32 −1
Original line number Diff line number Diff line
@@ -401,6 +401,27 @@ static int jbd2_commit_block_csum_verify(journal_t *j, void *buf)
	return provided == cpu_to_be32(calculated);
}

static bool jbd2_commit_block_csum_verify_partial(journal_t *j, void *buf)
{
	struct commit_header *h;
	__be32 provided;
	__u32 calculated;
	void *tmpbuf;

	tmpbuf = kzalloc(j->j_blocksize, GFP_KERNEL);
	if (!tmpbuf)
		return false;

	memcpy(tmpbuf, buf, sizeof(struct commit_header));
	h = tmpbuf;
	provided = h->h_chksum[0];
	h->h_chksum[0] = 0;
	calculated = jbd2_chksum(j, j->j_csum_seed, tmpbuf, j->j_blocksize);
	kfree(tmpbuf);

	return provided == cpu_to_be32(calculated);
}

static int jbd2_block_tag_csum_verify(journal_t *j, journal_block_tag_t *tag,
				      void *buf, __u32 sequence)
{
@@ -768,6 +789,13 @@ static int do_one_pass(journal_t *journal,
			if (pass == PASS_SCAN &&
			    !jbd2_commit_block_csum_verify(journal,
							   bh->b_data)) {
				if (jbd2_commit_block_csum_verify_partial(
								  journal,
								  bh->b_data)) {
					pr_notice("JBD2: Find incomplete commit block in transaction %u block %lu\n",
						  next_commit_ID, next_log_block);
					goto chksum_ok;
				}
			chksum_error:
				if (commit_time < last_trans_commit_time)
					goto ignore_crc_mismatch;
@@ -780,8 +808,10 @@ static int do_one_pass(journal_t *journal,
					break;
				}
			}
			if (pass == PASS_SCAN)
			if (pass == PASS_SCAN) {
			chksum_ok:
				last_trans_commit_time = commit_time;
			}
			brelse(bh);
			next_commit_ID++;
			continue;
@@ -798,6 +828,7 @@ static int do_one_pass(journal_t *journal,
					  next_log_block);
				need_check_commit_time = true;
			}

			/* If we aren't in the REVOKE pass, then we can
			 * just skip over this block. */
			if (pass != PASS_REVOKE) {