mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ojaswin Mujoo <ojaswin@linux.ibm.com>
To: linux-ext4@vger.kernel.org, "Theodore Ts'o" <tytso@mit.edu>
Cc: John Garry <john.g.garry@oracle.com>,
	dchinner@redhat.com, "Darrick J . Wong" <djwong@kernel.org>,
	Ritesh Harjani <ritesh.list@gmail.com>,
	linux-kernel@vger.kernel.org
Subject: [RFC v3 11/11] ext4: disallow unaligned deallocations on forcealign inodes
Date: Mon, 24 Mar 2025 13:07:09 +0530	[thread overview]
Message-ID: <4fafc9c42962e1fdc8ce44b21fa977df5de0679e.1742800203.git.ojaswin@linux.ibm.com> (raw)
In-Reply-To: <cover.1742800203.git.ojaswin@linux.ibm.com>

When forcealign is set, an unaligned deallocation can disturb the
alignment of the mappings of the file by introducing unaligned holes/unwritten
extents to it. This could then lead to increased allocations failures on the
file in future.

To avoid this, disallow deallocations or extent shifting operations (like insert
range) unless they are aligned to extsize as well.

Note that this is a relatively strict approach which can be relaxed a bit more
in the future by using partial zeroing tricks etc.

Signed-off-by: Ojaswin Mujoo <ojaswin@linux.ibm.com>
---
 fs/ext4/extents.c | 36 ++++++++++++++++++++++++++++++++++++
 fs/ext4/inode.c   | 12 ++++++++++++
 2 files changed, 48 insertions(+)

diff --git a/fs/ext4/extents.c b/fs/ext4/extents.c
index 1835e18f0eef..1ac5bb8cbbde 100644
--- a/fs/ext4/extents.c
+++ b/fs/ext4/extents.c
@@ -4754,6 +4754,18 @@ static long ext4_zero_range(struct file *file, loff_t offset,
 			return ret;
 	}
 
+	if (ext4_should_use_forcealign(inode)) {
+		u32 extsize_bytes = ext4_inode_get_extsize(EXT4_I(inode))
+				    << inode->i_blkbits;
+
+		if (!IS_ALIGNED(offset | end, extsize_bytes)) {
+			ext4_warning(
+				inode->i_sb,
+				"tried unaligned operation on forcealign inode");
+			return -EINVAL;
+		}
+	}
+
 	flags = EXT4_GET_BLOCKS_CREATE_UNWRIT_EXT;
 	/* Preallocate the range including the unaligned edges */
 	if (!IS_ALIGNED(offset | end, blocksize)) {
@@ -5473,6 +5485,18 @@ static int ext4_collapse_range(struct file *file, loff_t offset, loff_t len)
 	if (end >= inode->i_size)
 		return -EINVAL;
 
+	if (ext4_should_use_forcealign(inode)) {
+		u32 extsize_bytes = ext4_inode_get_extsize(EXT4_I(inode))
+				    << inode->i_blkbits;
+
+		if (!IS_ALIGNED(offset | end, extsize_bytes)) {
+			ext4_warning(
+				inode->i_sb,
+				"tried unaligned operation on forcealign inode");
+			return -EINVAL;
+		}
+	}
+
 	/*
 	 * Write tail of the last page before removed range and data that
 	 * will be shifted since they will get removed from the page cache
@@ -5573,6 +5597,18 @@ static int ext4_insert_range(struct file *file, loff_t offset, loff_t len)
 	if (len > inode->i_sb->s_maxbytes - inode->i_size)
 		return -EFBIG;
 
+	if (ext4_should_use_forcealign(inode)) {
+		u32 extsize_bytes = ext4_inode_get_extsize(EXT4_I(inode))
+				    << inode->i_blkbits;
+
+		if (!IS_ALIGNED(offset | (offset + len), extsize_bytes)) {
+			ext4_warning(
+				sb,
+				"tried unaligned operation on forcealign inode");
+			return -EINVAL;
+		}
+	}
+
 	/*
 	 * Write out all dirty pages. Need to round down to align start offset
 	 * to page size boundary for page size > block size.
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index 5b36e62872d6..4c974e461061 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -4397,6 +4397,18 @@ int ext4_punch_hole(struct file *file, loff_t offset, loff_t length)
 		end = max_end;
 	length = end - offset;
 
+	if (ext4_should_use_forcealign(inode)) {
+		u32 extsize_bytes = ext4_inode_get_extsize(EXT4_I(inode))
+				    << inode->i_blkbits;
+
+		if (!IS_ALIGNED(offset | end, extsize_bytes)) {
+			ext4_warning(
+				sb,
+				"tried unaligned operation on forcealign inode");
+			return -EINVAL;
+		}
+	}
+
 	/*
 	 * Attach jinode to inode for jbd2 if we do any zeroing of partial
 	 * block.
-- 
2.48.1


      parent reply	other threads:[~2025-03-24  7:37 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-24  7:36 [RFC v3 00/11] ext4: Add extsize and forcealign support (groundwork for multi block atomic writes) Ojaswin Mujoo
2025-03-24  7:36 ` [RFC v3 01/11] ext4: add aligned allocation hint in mballoc Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 02/11] ext4: allow inode preallocation for aligned alloc Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 03/11] ext4: support for extsize hint using FS_IOC_FS(GET/SET)XATTR Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 04/11] ext4: pass lblk and len explicitly to ext4_split_extent*() Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 05/11] ext4: add extsize hint support Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 06/11] ext4: make extsize work with EOF allocations Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 07/11] ext4: add ext4_map_blocks_extsize() wrapper to handle overwrites Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 08/11] ext4: add forcealign support of mballoc Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 09/11] ext4: add forcealign support to ext4_map_blocks Ojaswin Mujoo
2025-03-24  7:37 ` [RFC v3 10/11] ext4: add support for adding focealign via SETXATTR ioctl Ojaswin Mujoo
2025-03-24  7:37 ` Ojaswin Mujoo [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4fafc9c42962e1fdc8ce44b21fa977df5de0679e.1742800203.git.ojaswin@linux.ibm.com \
    --to=ojaswin@linux.ibm.com \
    --cc=dchinner@redhat.com \
    --cc=djwong@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=linux-ext4@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ritesh.list@gmail.com \
    --cc=tytso@mit.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®