2 * Helper functions for multiple mount protection (MMP).
4 * Copyright (C) 2011 Whamcloud, Inc.
7 * This file may be redistributed under the terms of the GNU Public
23 #include <sys/types.h>
27 #include "ext2fs/ext2_fs.h"
28 #include "ext2fs/ext2fs.h"
34 errcode_t ext2fs_mmp_read(ext2_filsys fs, blk64_t mmp_blk, void *buf)
36 struct mmp_struct *mmp_cmp;
39 if ((mmp_blk <= fs->super->s_first_data_block) ||
40 (mmp_blk >= fs->super->s_blocks_count))
41 return EXT2_ET_MMP_BAD_BLOCK;
43 /* ext2fs_open() reserves fd0,1,2 to avoid stdio collision, so checking
44 * mmp_fd <= 0 is OK to validate that the fd is valid. This opens its
45 * own fd to read the MMP block to ensure that it is using O_DIRECT,
46 * regardless of how the io_manager is doing reads, to avoid caching of
47 * the MMP block by the io_manager or the VM. It needs to be fresh. */
48 if (fs->mmp_fd <= 0) {
49 fs->mmp_fd = open(fs->device_name, O_RDWR | O_DIRECT);
51 retval = EXT2_ET_MMP_OPEN_DIRECT;
56 if (fs->mmp_cmp == NULL) {
57 int align = ext2fs_get_dio_alignment(fs->mmp_fd);
59 retval = ext2fs_get_memalign(fs->blocksize, align,
65 if (ext2fs_llseek(fs->mmp_fd, mmp_blk * fs->blocksize, SEEK_SET) !=
66 mmp_blk * fs->blocksize) {
67 retval = EXT2_ET_LLSEEK_FAILED;
71 if (read(fs->mmp_fd, fs->mmp_cmp, fs->blocksize) != fs->blocksize) {
72 retval = EXT2_ET_SHORT_READ;
76 mmp_cmp = fs->mmp_cmp;
77 #ifdef WORDS_BIGENDIAN
78 ext2fs_swap_mmp(mmp_cmp);
81 if (buf != NULL && buf != fs->mmp_cmp)
82 memcpy(buf, fs->mmp_cmp, fs->blocksize);
84 if (mmp_cmp->mmp_magic != EXT4_MMP_MAGIC) {
85 retval = EXT2_ET_MMP_MAGIC_INVALID;
93 errcode_t ext2fs_mmp_write(ext2_filsys fs, blk64_t mmp_blk, void *buf)
95 struct mmp_struct *mmp_s = buf;
100 mmp_s->mmp_time = tv.tv_sec;
101 fs->mmp_last_written = tv.tv_sec;
103 if (fs->super->s_mmp_block < fs->super->s_first_data_block ||
104 fs->super->s_mmp_block > ext2fs_blocks_count(fs->super))
105 return EXT2_ET_MMP_BAD_BLOCK;
107 #ifdef WORDS_BIGENDIAN
108 ext2fs_swap_mmp(mmp_s);
111 /* I was tempted to make this use O_DIRECT and the mmp_fd, but
112 * this caused no end of grief, while leaving it as-is works. */
113 retval = io_channel_write_blk64(fs->io, mmp_blk, -(int)sizeof(struct mmp_struct), buf);
115 #ifdef WORDS_BIGENDIAN
116 ext2fs_swap_mmp(mmp_s);
119 /* Make sure the block gets to disk quickly */
120 io_channel_flush(fs->io);
125 #define srand(x) srandom(x)
126 #define rand() random()
129 unsigned ext2fs_mmp_new_seq()
134 gettimeofday(&tv, 0);
135 srand((getpid() << 16) ^ getuid() ^ tv.tv_sec ^ tv.tv_usec);
137 gettimeofday(&tv, 0);
138 /* Crank the random number generator a few times */
139 for (new_seq = (tv.tv_sec ^ tv.tv_usec) & 0x1F; new_seq > 0; new_seq--)
144 } while (new_seq > EXT4_MMP_SEQ_MAX);
149 static errcode_t ext2fs_mmp_reset(ext2_filsys fs)
151 struct mmp_struct *mmp_s = NULL;
152 errcode_t retval = 0;
154 if (fs->mmp_buf == NULL) {
155 retval = ext2fs_get_mem(fs->blocksize, &fs->mmp_buf);
160 memset(fs->mmp_buf, 0, fs->blocksize);
163 mmp_s->mmp_magic = EXT4_MMP_MAGIC;
164 mmp_s->mmp_seq = EXT4_MMP_SEQ_CLEAN;
166 #if _BSD_SOURCE || _XOPEN_SOURCE >= 500
167 gethostname(mmp_s->mmp_nodename, sizeof(mmp_s->mmp_nodename));
169 mmp_s->mmp_nodename[0] = '\0';
171 strncpy(mmp_s->mmp_bdevname, fs->device_name,
172 sizeof(mmp_s->mmp_bdevname));
174 mmp_s->mmp_check_interval = fs->super->s_mmp_update_interval;
175 if (mmp_s->mmp_check_interval < EXT4_MMP_MIN_CHECK_INTERVAL)
176 mmp_s->mmp_check_interval = EXT4_MMP_MIN_CHECK_INTERVAL;
178 retval = ext2fs_mmp_write(fs, fs->super->s_mmp_block, fs->mmp_buf);
183 errcode_t ext2fs_mmp_clear(ext2_filsys fs)
185 errcode_t retval = 0;
187 if (!(fs->flags & EXT2_FLAG_RW))
188 return EXT2_ET_RO_FILSYS;
190 retval = ext2fs_mmp_reset(fs);
195 errcode_t ext2fs_mmp_init(ext2_filsys fs)
197 struct ext2_super_block *sb = fs->super;
201 if (sb->s_mmp_update_interval == 0)
202 sb->s_mmp_update_interval = EXT4_MMP_UPDATE_INTERVAL;
203 /* This is probably excessively large, but who knows? */
204 else if (sb->s_mmp_update_interval > EXT4_MMP_MAX_UPDATE_INTERVAL)
205 return EXT2_ET_INVALID_ARGUMENT;
207 if (fs->mmp_buf == NULL) {
208 retval = ext2fs_get_mem(fs->blocksize, &fs->mmp_buf);
213 retval = ext2fs_alloc_block2(fs, 0, fs->mmp_buf, &mmp_block);
217 sb->s_mmp_block = mmp_block;
219 retval = ext2fs_mmp_reset(fs);
228 * Make sure that the fs is not mounted or being fsck'ed while opening the fs.
230 errcode_t ext2fs_mmp_start(ext2_filsys fs)
232 struct mmp_struct *mmp_s;
234 unsigned int mmp_check_interval;
235 errcode_t retval = 0;
237 if (fs->mmp_buf == NULL) {
238 retval = ext2fs_get_mem(fs->blocksize, &fs->mmp_buf);
243 retval = ext2fs_mmp_read(fs, fs->super->s_mmp_block, fs->mmp_buf);
249 mmp_check_interval = fs->super->s_mmp_update_interval;
250 if (mmp_check_interval < EXT4_MMP_MIN_CHECK_INTERVAL)
251 mmp_check_interval = EXT4_MMP_MIN_CHECK_INTERVAL;
253 seq = mmp_s->mmp_seq;
254 if (seq == EXT4_MMP_SEQ_CLEAN)
256 if (seq == EXT4_MMP_SEQ_FSCK) {
257 retval = EXT2_ET_MMP_FSCK_ON;
261 if (seq > EXT4_MMP_SEQ_FSCK) {
262 retval = EXT2_ET_MMP_UNKNOWN_SEQ;
267 * If check_interval in MMP block is larger, use that instead of
268 * check_interval from the superblock.
270 if (mmp_s->mmp_check_interval > mmp_check_interval)
271 mmp_check_interval = mmp_s->mmp_check_interval;
273 sleep(2 * mmp_check_interval + 1);
275 retval = ext2fs_mmp_read(fs, fs->super->s_mmp_block, fs->mmp_buf);
279 if (seq != mmp_s->mmp_seq) {
280 retval = EXT2_ET_MMP_FAILED;
285 if (!(fs->flags & EXT2_FLAG_RW))
288 mmp_s->mmp_seq = seq = ext2fs_mmp_new_seq();
289 #if _BSD_SOURCE || _XOPEN_SOURCE >= 500
290 gethostname(mmp_s->mmp_nodename, sizeof(mmp_s->mmp_nodename));
292 strcpy(mmp_s->mmp_nodename, "unknown host");
294 strncpy(mmp_s->mmp_bdevname, fs->device_name,
295 sizeof(mmp_s->mmp_bdevname));
297 retval = ext2fs_mmp_write(fs, fs->super->s_mmp_block, fs->mmp_buf);
301 sleep(2 * mmp_check_interval + 1);
303 retval = ext2fs_mmp_read(fs, fs->super->s_mmp_block, fs->mmp_buf);
307 if (seq != mmp_s->mmp_seq) {
308 retval = EXT2_ET_MMP_FAILED;
312 mmp_s->mmp_seq = EXT4_MMP_SEQ_FSCK;
313 retval = ext2fs_mmp_write(fs, fs->super->s_mmp_block, fs->mmp_buf);
324 * Clear the MMP usage in the filesystem. If this function returns an
325 * error EXT2_ET_MMP_CHANGE_ABORT it means the filesystem was modified
326 * by some other process while in use, and changes should be dropped, or
327 * risk filesystem corruption.
329 errcode_t ext2fs_mmp_stop(ext2_filsys fs)
331 struct mmp_struct *mmp, *mmp_cmp;
332 errcode_t retval = 0;
334 if (!(fs->super->s_feature_incompat & EXT4_FEATURE_INCOMPAT_MMP) ||
335 !(fs->flags & EXT2_FLAG_RW) || (fs->flags & EXT2_FLAG_SKIP_MMP))
338 retval = ext2fs_mmp_read(fs, fs->super->s_mmp_block, fs->mmp_buf);
342 /* Check if the MMP block is not changed. */
344 mmp_cmp = fs->mmp_cmp;
345 if (memcmp(mmp, mmp_cmp, sizeof(*mmp_cmp))) {
346 retval = EXT2_ET_MMP_CHANGE_ABORT;
350 mmp_cmp->mmp_seq = EXT4_MMP_SEQ_CLEAN;
351 retval = ext2fs_mmp_write(fs, fs->super->s_mmp_block, fs->mmp_cmp);
354 if (fs->mmp_fd > 0) {
362 #define EXT2_MIN_MMP_UPDATE_INTERVAL 60
365 * Update the on-disk mmp buffer, after checking that it hasn't been changed.
367 errcode_t ext2fs_mmp_update(ext2_filsys fs)
369 struct mmp_struct *mmp, *mmp_cmp;
371 errcode_t retval = 0;
373 if (!(fs->super->s_feature_incompat & EXT4_FEATURE_INCOMPAT_MMP) ||
374 !(fs->flags & EXT2_FLAG_RW) || (fs->flags & EXT2_FLAG_SKIP_MMP))
377 gettimeofday(&tv, 0);
378 if (tv.tv_sec - fs->mmp_last_written < EXT2_MIN_MMP_UPDATE_INTERVAL)
381 retval = ext2fs_mmp_read(fs, fs->super->s_mmp_block, NULL);
386 mmp_cmp = fs->mmp_cmp;
388 if (memcmp(mmp, mmp_cmp, sizeof(*mmp_cmp)))
389 return EXT2_ET_MMP_CHANGE_ABORT;
391 mmp->mmp_time = tv.tv_sec;
392 mmp->mmp_seq = EXT4_MMP_SEQ_FSCK;
393 retval = ext2fs_mmp_write(fs, fs->super->s_mmp_block, fs->mmp_buf);