From patchwork Wed May 20 12:36:59 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241198 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=MqZX9nsE; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=i/um=dr=vger.kernel.org=linux-ext4+bounces-16592-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB002c7Bz1xxD for ; Wed, 20 May 2026 22:37:51 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gL9zz3gnJz59HM for ; Wed, 20 May 2026 22:37:51 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gL9zz3Mrpz59HL; Wed, 20 May 2026 22:37:51 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.232.135.74 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280671; cv=pass; b=YRPrTZP0lZo/SXVmgBIzgljQK9Cmyw2tXHGsM/dQwmI/+AoXN35ZvYrx5yrumgxXK3EUwyIgP/RGthzy9c6z0yFWwDWMVV7meNPDcVunXTs0BttiEiMCyZPC1XsJLPdQaES75xZROt07opoh6qobywGahuH9picXK7TmXF1kHG+Xz+tX3Jal86znkBJZW5lJepXczQd5iCLFr00s+RnxgzWduiAt5JhSj/BTtggz5FxcSMX9qQp3/5QwaKRxXbvK2noPr0pq6PvoYVJLE+VK/ZzvV9h0gTr7hxjo7xS2r9/HxKY+9XA0XAsdXno0Hd4LD0UsT80myJ+aoSyEjvbGJQ== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280671; c=relaxed/relaxed; bh=Q24umAnIhjJWMMv84GCWO2VASOQlpvqwGDh+ApTBnaM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eBthXAlJu8QkqtDmsgIAEW7Bws9ib6JeCLuoQasPSM7ohohO+yXZt/HROn9dyRxhyvwHF1mgO5R3C4JXwZhEqCk9UJyJgfkTdVjttXEF6bjc4gw/3PciudL+N9yRL5fkZyuz50UbdQn6GL7lqJkFOPDox11an7Qd1CICAIEYZd9gWW5AaQA/QNE+XS+Qj4HiXAORML67dlzhG8rhyMjAyQuEGRz/CLWmc6SbKFLvgoSdxPnsFv41lRUKEvQhXqDdJZJlFy8+p7CJgblvTcuESFx9fscXbO5k0RK+zk95UP4b3bwF38+av2mxdCKeAkC4yjet0r3Ho+bVDaAQwqC1iw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=MqZX9nsE; dkim-atps=neutral; spf=pass (client-ip=172.232.135.74; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16592-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=MqZX9nsE; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.232.135.74; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16592-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [172.232.135.74]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gL9zw0zt4z59HM for ; Wed, 20 May 2026 22:37:48 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 1B595300F751 for ; Wed, 20 May 2026 12:37:37 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 7D8AA3E0C46; Wed, 20 May 2026 12:37:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="MqZX9nsE" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2B9123E00B6; Wed, 20 May 2026 12:37:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280652; cv=none; b=jGHXjpLzbwKhmCEvk/YJUGPpc5lhBlogmwx29BktXWSvMgCtAOV0aXx5CiV1IV3BWsEaiW/FKzDtRi1NK/Mk2QkyMf3MgDQb2YHM0mkt5I5ubUAUYs/Ij4dWkIw1HOLf/CZf79uwvJkxCQqCa7I3dnri/gqLilnRsvnGH0s2G7A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280652; c=relaxed/simple; bh=xdJuXteL2kuBB7E/JnTWxaOughFhLnHqfW8AFjBOmQ0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nvC0l2h/7WRTSdE+y8aJXdM19t2tZaMH8MlnASELxC+F5dh9LKmlbx0i1dusy1k6b9EWcOBgmQ7mr6NeY6ng/h+O9i2Xkv9CiKU8DYfOmCAosJmFVbdVeyHePYgITtiM7aByva9u4rnCT4xW6OHGqDW5TDoZxHipxdrtQIYMrfg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=MqZX9nsE; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id D7B481F00894; Wed, 20 May 2026 12:37:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280650; bh=Q24umAnIhjJWMMv84GCWO2VASOQlpvqwGDh+ApTBnaM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=MqZX9nsE8QFNLXuhluue/cW4JgOHY2OtHyA5kgBjSDYIE5nUSDoTviEarvXRjvasL om8I8YRDVTAntoEST6h/tUqAJYIEVbqfZicYvfU+jIGsMvXMzjZlhJhj67Ng5Wzu0r 5cSxBlerB1F6e7DR0jAQicjnNrvuvqTzPL+WUuSIvGLBKxmvdPBXVDZyIv4KK55uRU sXi78jEf29W4JUO/ylFRmqIcTXig74tdF/NCJZMecJLWFXpPxyM1VN4sMfz+baQLmB /tOhc3UPIDQGZb9RDiU3333CZ2RGQk4q835ARjQPh+Hmgi6+Mw+umyula3/eVResjN 4h0gGg7jXowpA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 01/22] fsverity: report validation errors through fserror to fsnotify Date: Wed, 20 May 2026 14:36:59 +0200 Message-ID: <20260520123722.405752-2-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Reported verification errors to fsnotify through recently added fserror interface. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Acked-by: Eric Biggers Signed-off-by: Andrey Albershteyn --- fs/verity/verify.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/fs/verity/verify.c b/fs/verity/verify.c index 4004a1d42875..db8c350234bb 100644 --- a/fs/verity/verify.c +++ b/fs/verity/verify.c @@ -9,6 +9,7 @@ #include #include +#include #define FS_VERITY_MAX_PENDING_BLOCKS 2 @@ -205,6 +206,8 @@ static bool verify_data_block(struct fsverity_info *vi, if (memchr_inv(dblock->data, 0, params->block_size)) { fsverity_err(inode, "FILE CORRUPTED! Data past EOF is not zeroed"); + fserror_report_data_lost(inode, data_pos, + params->block_size, GFP_NOFS); return false; } return true; @@ -312,6 +315,7 @@ static bool verify_data_block(struct fsverity_info *vi, data_pos, level - 1, params->hash_alg->name, hsize, want_hash, params->hash_alg->name, hsize, level == 0 ? dblock->real_hash : real_hash); + fserror_report_data_lost(inode, data_pos, params->block_size, GFP_NOFS); error: for (; level > 0; level--) { kunmap_local(hblocks[level - 1].addr); From patchwork Wed May 20 12:37:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241199 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VuTLUh8s; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=if9x=dr=vger.kernel.org=linux-ext4+bounces-16593-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB0C4FSlz1xxD for ; Wed, 20 May 2026 22:38:03 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB0C3kX2z59HM for ; Wed, 20 May 2026 22:38:03 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB0C3gQqz59HL; Wed, 20 May 2026 22:38:03 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c09:e001:a7::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280683; cv=pass; b=xClLbRcdoiSGhpvr60C10yR1pxOxoA7E2cAQMp/2Agopb3adBHLzKX9tQnHC7sJya4hVwXdEZRBSSKNwJDnXtnl3eMEydzAVqnFg9JdJcqTe3JfI34EkNCuK/dMK0OD7HVJAGLsEpZxI/OzCFF+f4tcP1AtBslCb780YyjwsNkdGSW81xGaQmuclAS59zhpnOv+MdNGuI72MD8GprtvKq8icYAmX9AuAQ/yAEEB6fuK7dtFGg0VvjyvdkaSHo57GTkb2G22rKUJRld+CcGO/J1IewiUpocFYQFjVhxZq+LpYbZc8uhIrwCJNmp7LTEnFJcg+ZryYVaiq1UA+LSNuBQ== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280683; c=relaxed/relaxed; bh=aPukUD+NtePBNeO+9pQXROMWpzJAwBfMA+GAmXDsmOw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=J1t+5HDcD9rtD9/3YywGeK0Kbzu7MUpYarVh7O3tWVJ2hGeTFucLQ3TKuZdV51RKbPTRNQA8ufXYk+oqpUBkEHO/vQaejLe5YwXXifaABHBICSCdcxklzDn0Ek7Y3O+YcxXtVUFsm4gKQNmp8MZcfvhrH7L6IhzXYh3PzzpgM/SY65cZ+AVDffwnKCbFc+AFnYHa4EpzOtqPEtF1ZXksFHhODODPlSWXztoXdgdhuHO687Uhn3wDvMSC/OnxxQZEVyJvOKc2vyA8i7rrleTLgDDqaBUYwpZIhu/I9CDtDPn4c3ZDvRxN+o0L/r6Cbul5RKRcc++OmLpSQm4zUnTvlA== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VuTLUh8s; dkim-atps=neutral; spf=pass (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16593-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VuTLUh8s; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16593-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [IPv6:2600:3c09:e001:a7::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB0813CJz59HM for ; Wed, 20 May 2026 22:38:00 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 0B81D300C33D for ; Wed, 20 May 2026 12:37:42 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 04A6C3E1232; Wed, 20 May 2026 12:37:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VuTLUh8s" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA9093DD518; Wed, 20 May 2026 12:37:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280654; cv=none; b=Qn5kqNa1C4W1ytksNBgGqD5cYy6iSB5Q4tFkIZLMD6+hRi7bLa+DwKuoxIkQM9CuUulCk4yyBRwKVmx7j9dccPk8VrfeXnE98SoFAsKX35xqkoV/J5PZJvqrnvZfFgPJ0ZskSC5pmHD9bhLNoKlfhoGOga4LWZ7aUMJ4HKHBG6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280654; c=relaxed/simple; bh=WUbmJ09ApFlE5dv+q3/j1K9Rxwfb6sksHU6Kmj2I7n4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=WB6TJkBpwTHXGgLUD3oiSer+IwSioKViX0XwxmNmlNYCtVUAf4z15MY4RC7gwfDbSxvu7n03u/PRVfkgOMROsQ4K4bhj/9u02rCa5UyPJcTr/uS6WqPVOeuRFv0hNr3op+7YEo7ldPt5/eKVikbviWgzS9F/09vK9BvFKWPxiaE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VuTLUh8s; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 509381F000E9; Wed, 20 May 2026 12:37:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280653; bh=aPukUD+NtePBNeO+9pQXROMWpzJAwBfMA+GAmXDsmOw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VuTLUh8sfDD/phf8ZbFnKsnOI/dDSd7+fjq92/uCsC+kcCtyPN4tZLc2/9BVY6Kaz qho6eKhVZExcvQd5I3/fDLEg1v6h0YWxj5s0h4MZVIlECyFcKesvfFC1wFRb2po3PQ lvKDBu6xD84QDVS6kIpMVD3jt7NBB+/DrmXBq8V+7rmc5SV7pWP8rEVcZL1ISL/rxn WPgn9JPu3e6a3lmHtpMPdKIkv1XPKJksf6wrEc0XqJXuianYWq3ukTr7qFZzmt2PQF FWipOqDD1Ji/xxnqeBwbXFUaQuvPCgpmP8JOq8ppUR0ZcJIlBWEcvSVaibaip2NXlf l1JCroTm2qvOg== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 02/22] fsverity: expose ensure_fsverity_info() Date: Wed, 20 May 2026 14:37:00 +0200 Message-ID: <20260520123722.405752-3-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org This function will be used by XFS's scrub to force fsverity activation, therefore, to read fsverity context. Reviewed-by: Darrick J. Wong Acked-by: Eric Biggers Signed-off-by: Andrey Albershteyn Reviewed-by: Christoph Hellwig --- fs/verity/open.c | 22 ++++++++++++++++++++-- include/linux/fsverity.h | 2 ++ 2 files changed, 22 insertions(+), 2 deletions(-) diff --git a/fs/verity/open.c b/fs/verity/open.c index dfa0d1afe0fe..d32d0899df25 100644 --- a/fs/verity/open.c +++ b/fs/verity/open.c @@ -344,7 +344,24 @@ int fsverity_get_descriptor(struct inode *inode, return 0; } -static int ensure_verity_info(struct inode *inode) +/** + * fsverity_ensure_verity_info() - cache verity info if it's not already cached + * @inode: the inode for which verity info should be cached + * + * Ensure this inode has verity info attached to it, it's assumed the inode + * already has fsverity enabled. Read fsverity descriptor and creates verity + * based on that. + * + * This needs to be called at least once before any of the inode's data + * can be verified (and thus read at all) or the inode's fsverity digest + * retrieved. fsverity_file_open() calls this already, which handles + * normal file accesses. If a filesystem does any internal (i.e. not + * associated with a file descriptor) reads of the file's data or + * fsverity digest, it must call this explicitly before doing so. + * + * Return: 0 on success, -errno on failure + */ +int fsverity_ensure_verity_info(struct inode *inode) { struct fsverity_info *vi = fsverity_get_info(inode), *found; struct fsverity_descriptor *desc; @@ -380,12 +397,13 @@ static int ensure_verity_info(struct inode *inode) kfree(desc); return err; } +EXPORT_SYMBOL_GPL(fsverity_ensure_verity_info); int __fsverity_file_open(struct inode *inode, struct file *filp) { if (filp->f_mode & FMODE_WRITE) return -EPERM; - return ensure_verity_info(inode); + return fsverity_ensure_verity_info(inode); } EXPORT_SYMBOL_GPL(__fsverity_file_open); diff --git a/include/linux/fsverity.h b/include/linux/fsverity.h index a8f9aa75b792..5562271bd628 100644 --- a/include/linux/fsverity.h +++ b/include/linux/fsverity.h @@ -309,6 +309,8 @@ static inline int fsverity_file_open(struct inode *inode, struct file *filp) return 0; } +int fsverity_ensure_verity_info(struct inode *inode); + void fsverity_cleanup_inode(struct inode *inode); struct page *generic_read_merkle_tree_page(struct inode *inode, pgoff_t index); From patchwork Wed May 20 12:37:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241203 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=bz1mjG/i; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=150.107.74.76; helo=mail.ozlabs.org; envelope-from=srs0=wcci=dr=vger.kernel.org=linux-ext4+bounces-16594-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB2t6sZ2z1xx8 for ; Wed, 20 May 2026 22:40:22 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB2t6NrBz59HN for ; Wed, 20 May 2026 22:40:22 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB2t6K7gz59Gh; Wed, 20 May 2026 22:40:22 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280822; cv=pass; b=xsHA8o9qlm+ZzT91J9sc/Brqzl65whPNz4SGYPsFaGhF10EjP0zF3aQPjnc1VBamV2d/8VAw8W4zzyOIoDr7XIVGaF3FSjwKFArjt8+UxBMfXkXh46xE7LQptY4eetp2lvCulhLMuxlemP6hIl0+Z1BYBlbRzsmb1g5ndHVZ77PPecjDK+eSN74tIQfcPVYLrmqVaWCtut+ng9JcU9jlynFXvovRSJLR4oyR4i1on8oe6M3JSdGC2Sj9N8llW/6Ks1n+ZW20yhHFzi5X2/6/qbUB7TYk4Bb7KuQxlWR4e/q2HbAHNQwk21dqgW4j7aBhCbatt/NonoCU5EW3SoPc6A== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280822; c=relaxed/relaxed; bh=S6DVheQpRL47ADeu0p23U/KgTF/b8n3o4ctQu4PeRXA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=aATPCkEgqnIfGkYnYyOiKu+uRlHT0lDulfZThNhpXbsYrrNaN3h8b1GNiVfdY/hABWvWKUeEI5FW0TKfLMAWlK/rhU/iTFKemEi7F9ncpKwFlZ+qj3d3Cu7YrUU5AtqCPEStXxLdKxZyWcUaf612T5IsyHbSw0Z/U/dAWULdjSdrumloO1OqgaHiEmUhTEtEY624WQjfBySVxGPYD3oNcUNcOAPR2u40erwkC6u1Ao5CFsv5ggNC9nc+O2nYinHguoHp7FH5W4AIPRWu46O+106QfhDzbVL9ayjqJWCx+LseNFHF5u2VKYu+iujlAJGvvETsCSmmR2k2+8Yo0cG4Kw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=bz1mjG/i; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16594-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=bz1mjG/i; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16594-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB2q4xxCz59HN for ; Wed, 20 May 2026 22:40:19 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id C5F9C309EFE1 for ; Wed, 20 May 2026 12:37:50 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 8EBC53DF002; Wed, 20 May 2026 12:37:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="bz1mjG/i" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 53A423DD518; Wed, 20 May 2026 12:37:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280657; cv=none; b=a40jFzJpLdFw9EHJlrsaDcN60qKvmJ5Bi959hnvUwFcks1HxEqhz9FSxgf5w8XlCv/di2JVMO84PhbYDEC1QUyuWkTH1ytfWOkXhtEYCwNffNaG6aH/54ooDTFjNbk/6ZXonkaiK5n1iZxU/LNXlzMYtq6rPMGtIbn9qvJmaWeA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280657; c=relaxed/simple; bh=aQ949vdqN+2VaRoZc//9SuDMmlCcOxHdwGdimTwSIGA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=CTAoo1AQ/+t4MEdd82Szyks6v/9zkOsdGNqXyiZHlTD636f+c5de2n2U3JL7opO0mHdN7pcPfdVcseVS9mWmpXyi9wYwnOT86rARJQa8eGgDfSm4pGigS/06thbAyqRyCZIlhRXRrz7o46LgYq/yEPWw9P/SJR28uua5PD6KT7Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=bz1mjG/i; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id B98E21F00893; Wed, 20 May 2026 12:37:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280655; bh=S6DVheQpRL47ADeu0p23U/KgTF/b8n3o4ctQu4PeRXA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=bz1mjG/igVr51QMf/GX/vNogqKcrJsXkQsKiEc99VZY6J2rrwZ6r3ZTbJo0LxzBfp Wlls8sWGix1E+yEsVg3oFeYVDMBe7iENfCopFYq/BPqeBL8KGAQQB7QkmrMdNKDR2U lnTvzFuLeF3AAKPT0trN9C2lz0REmoKiIMRD+n+kH5R01CpW9B0Ih/FUEMy0gtjYMo uVzSGkapGiUfQwPiuLTQ7P4N7xCDCof8Kai1n/SKcSQCOBfX2PNFflCw2Oekjzcpaa 3MLnlE2qiGHaVcWDSsDIFxYyR0n+rQp4rDFDKEOGEroEg9EqLPOjxhhZUhp9eOMbAY ovRmwD0AoY94g== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org, Amir Goldstein Subject: [PATCH v10 03/22] ovl: use core fsverity ensure info interface Date: Wed, 20 May 2026 14:37:01 +0200 Message-ID: <20260520123722.405752-4-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org fsverity now exposes fsverity_ensure_verity_info() which could be used instead of opening file to ensure that fsverity info is loaded and attached to inode. Signed-off-by: Andrey Albershteyn Acked-by: Amir Goldstein Reviewed-by: Amir Goldstein Reviewed-by: Eric Biggers --- fs/overlayfs/util.c | 14 +++----------- 1 file changed, 3 insertions(+), 11 deletions(-) diff --git a/fs/overlayfs/util.c b/fs/overlayfs/util.c index b41f4788e4f0..1e783cab4fbf 100644 --- a/fs/overlayfs/util.c +++ b/fs/overlayfs/util.c @@ -16,6 +16,7 @@ #include #include #include +#include #include "overlayfs.h" /* Get write access to upper mnt - may fail if upper sb was remounted ro */ @@ -1352,18 +1353,9 @@ char *ovl_get_redirect_xattr(struct ovl_fs *ofs, const struct path *path, int pa int ovl_ensure_verity_loaded(const struct path *datapath) { struct inode *inode = d_inode(datapath->dentry); - struct file *filp; - if (IS_VERITY(inode) && fsverity_get_info(inode) == NULL) { - /* - * If this inode was not yet opened, the verity info hasn't been - * loaded yet, so we need to do that here to force it into memory. - */ - filp = kernel_file_open(datapath, O_RDONLY, current_cred()); - if (IS_ERR(filp)) - return PTR_ERR(filp); - fput(filp); - } + if (fsverity_active(inode)) + return fsverity_ensure_verity_info(inode); return 0; } From patchwork Wed May 20 12:37:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241205 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Y49jq1xD; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=iyl8=dr=vger.kernel.org=linux-ext4+bounces-16595-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB3N1Q7hz1xxH for ; Wed, 20 May 2026 22:40:48 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB3N0xD8z59HN for ; Wed, 20 May 2026 22:40:48 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB3N0rptz59Gh; Wed, 20 May 2026 22:40:48 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280848; cv=pass; b=RwdoSbo43XTyctVFT9UT3CHXye0BpF6iiQulLxSA8ON/5ifK3b52iAcR8bTZ5i2Em/E24trPqionkJlpHvixggKc7aDUHFuu+lLfMbAghyhE13WBo1LZq9IH9DNzZ6632ykHVIgaLrYWX6AC/zAdCdVZgv763V9cz53P52+IgTdLFOG9i3yjxIkVbAjoJDjDbs1TePBIg7o8msJLavb58UlO4FKMZtBc6hsrhOoIzylgs8UGr8qX2FR5cnWqxXOnqhSa+Pf694wMywY8j+sNJryz91yN+j7xNR7v6pYxdL6lPohfUzPlrlfXJfbRl/fMXtRI5se1xdgZsLI6hwPlvw== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280848; c=relaxed/relaxed; bh=2W/huMs5akZB5W5rF4xsjMB8NN0kUDnKQc173nD7tcM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Ni6b1ugXW688FkJNYv+C6bdPWGjVOMw3uFCYgxCwKA91Ns3WnNNxj+pBSNy4UYyasZscrjqoTA/QjvlxC8MTbiv/y3/lXysLnrEliaYxzBCYAdLSujcd/A9S+Yyi5uj0sx198YFtjwUyThrabH3GKjmi8uHHhkQjeH72uDMSNCyfujbxu/3SKoxOxb94nn/qckQnt+6YswxRw1qspoPy47R5CjGMLcfhVJ29ruAcayLRLdZauMduuUB2tQGgHXXm6oC9kRmyZf5zlYqDnPt7MFfSPlAiNeiq6O2UmmMO5TN3WV8Ngb2XUqC56xGBKJ+rPo99HGtT1XEhUPkMsZvL/w== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Y49jq1xD; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16595-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Y49jq1xD; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16595-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB3J6mBzz59HN for ; Wed, 20 May 2026 22:40:44 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id B9E3330B2FA2 for ; Wed, 20 May 2026 12:37:55 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 11B1A3E1CFB; Wed, 20 May 2026 12:37:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Y49jq1xD" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9E48A3DD518; Wed, 20 May 2026 12:37:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280659; cv=none; b=pzRtnaPDOdkPd/dZwJehi3VFoIj/AwhupklKoyt8eX33htQyAUS8PUp8yv0b+E0LdJuWBUe6PE9tNG2jQe1777n3ptPhHqB4nKWax0EdwEEMdzZiHxPCsjlzE4jjmlrHxTP9PM8FfWCVS7AKG1mNkwTrQjZ+58i2ewYbQYFZaHU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280659; c=relaxed/simple; bh=nUhG1extIwuU0/MW8Rh2m8eKBR8Qhj6c/9kAlQIdHFo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=olQ/O51AIPsxQADR0EVmliw3/KWvuMPoAI37/k/o/PPeo8AJ+aYfldC6AUgSd8ZJlvG5bR7a/CZN53VJy+BvJOoCQacRHbe0mLgs2irqRB7/Y43orusDUEYVSFUuFn5Zsv/FsGTOQ2HzsXKQVB+kFxHWiQN3511YB882fwQcS9s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Y49jq1xD; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 546551F000E9; Wed, 20 May 2026 12:37:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280658; bh=2W/huMs5akZB5W5rF4xsjMB8NN0kUDnKQc173nD7tcM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Y49jq1xDXpkx5lth7cEu6Rnyxy1WAsb6OpI4S+ps/ssxvZvOAZEjHOLGJl/T0yv2j xFJF++hXx0WHof0IZJR0LCxGNDa9J3L7rpwMl/2L+vSUkzBBnuOEg5KCAqYtmVToWi 8gVF44DEgxQ6fE3RZntO/sUmd4OUGCb9B9U3/uZEf4VdlJyad+O0bC4239T9RIumWA g1PBEwe1Wt21uA1539p2TxgHSGdVyrp+sgEcY3kxf3u105Kjy4FHTlYFpv1QDfsFmI 7vNMPoWuVkBH1UkK354nry7Tvwdy28FNOH6cjlicjebm6fJWrljXG2EBRviEO/AhOx ctUAWKAObQH5g== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 04/22] fsverity: generate and store zero-block hash Date: Wed, 20 May 2026 14:37:02 +0200 Message-ID: <20260520123722.405752-5-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Compute the hash of one filesystem block's worth of zeros. A filesystem implementation can decide to elide merkle tree blocks containing only this hash and synthesize the contents at read time. Let's pretend that there's a file containing 131 data block and whose merkle tree looks roughly like this: root +--leaf0 | +--data0 | +--data1 | +--... | `--data128 `--leaf1 +--data129 +--data130 `--data131 If data[0-128] are sparse holes, then leaf0 will contain a repeating sequence of @zero_digest. Therefore, leaf0 need not be written to disk because its contents can be synthesized. A subsequent xfs patch will use this to reduce the size of the merkle tree when dealing with sparse gold master disk images and the like. Note that this works only on the first-level (data holes). fsverity doesn't store/generate zero_digest for any higher levels. Add a helper to pre-fill folio with hashes of empty blocks. This will be used by iomap to synthesize blocks full of zero hashes on the fly. Signed-off-by: Darrick J. Wong Acked-by: Eric Biggers Signed-off-by: Andrey Albershteyn --- fs/verity/fsverity_private.h | 3 +++ fs/verity/measure.c | 4 ++-- fs/verity/open.c | 3 +++ fs/verity/pagecache.c | 22 ++++++++++++++++++++++ include/linux/fsverity.h | 8 ++++++++ 5 files changed, 38 insertions(+), 2 deletions(-) diff --git a/fs/verity/fsverity_private.h b/fs/verity/fsverity_private.h index 6e6854c19078..881d46f25e08 100644 --- a/fs/verity/fsverity_private.h +++ b/fs/verity/fsverity_private.h @@ -53,6 +53,9 @@ struct merkle_tree_params { u64 tree_size; /* Merkle tree size in bytes */ unsigned long tree_pages; /* Merkle tree size in pages */ + /* the hash of an all-zeroes block */ + u8 zero_digest[FS_VERITY_MAX_DIGEST_SIZE]; + /* * Starting block index for each tree level, ordered from leaf level (0) * to root level ('num_levels - 1') diff --git a/fs/verity/measure.c b/fs/verity/measure.c index 6a35623ebdf0..818083507885 100644 --- a/fs/verity/measure.c +++ b/fs/verity/measure.c @@ -68,8 +68,8 @@ EXPORT_SYMBOL_GPL(fsverity_ioctl_measure); * @alg: (out) the digest's algorithm, as a FS_VERITY_HASH_ALG_* value * @halg: (out) the digest's algorithm, as a HASH_ALGO_* value * - * Retrieves the fsverity digest of the given file. The file must have been - * opened at least once since the inode was last loaded into the inode cache; + * Retrieves the fsverity digest of the given file. The + * fsverity_ensure_verity_info() must be called on the inode beforehand; * otherwise this function will not recognize when fsverity is enabled. * * The file's fsverity digest consists of @raw_digest in combination with either diff --git a/fs/verity/open.c b/fs/verity/open.c index d32d0899df25..875e8850ccba 100644 --- a/fs/verity/open.c +++ b/fs/verity/open.c @@ -153,6 +153,9 @@ int fsverity_init_merkle_tree_params(struct merkle_tree_params *params, goto out_err; } + fsverity_hash_block(params, page_address(ZERO_PAGE(0)), + params->zero_digest); + params->tree_size = offset << log_blocksize; params->tree_pages = PAGE_ALIGN(params->tree_size) >> PAGE_SHIFT; return 0; diff --git a/fs/verity/pagecache.c b/fs/verity/pagecache.c index 1819314ecaa3..99f5f53eea98 100644 --- a/fs/verity/pagecache.c +++ b/fs/verity/pagecache.c @@ -2,6 +2,7 @@ /* * Copyright 2019 Google LLC */ +#include "fsverity_private.h" #include #include @@ -56,3 +57,24 @@ void generic_readahead_merkle_tree(struct inode *inode, pgoff_t index, folio_put(folio); } EXPORT_SYMBOL_GPL(generic_readahead_merkle_tree); + +/** + * fsverity_fill_zerohash() - fill folio with hashes of zero data block + * @folio: folio to fill + * @offset: offset in the folio to start + * @len: length of the range to fill with hashes + * @vi: fsverity info + */ +void fsverity_fill_zerohash(struct folio *folio, size_t offset, size_t len, + struct fsverity_info *vi) +{ + size_t off = offset; + + WARN_ON_ONCE(!IS_ALIGNED(offset, vi->tree_params.digest_size)); + WARN_ON_ONCE(!IS_ALIGNED(len, vi->tree_params.digest_size)); + + for (; off < (offset + len); off += vi->tree_params.digest_size) + memcpy_to_folio(folio, off, vi->tree_params.zero_digest, + vi->tree_params.digest_size); +} +EXPORT_SYMBOL_GPL(fsverity_fill_zerohash); diff --git a/include/linux/fsverity.h b/include/linux/fsverity.h index 5562271bd628..3c3250f6f272 100644 --- a/include/linux/fsverity.h +++ b/include/linux/fsverity.h @@ -201,6 +201,8 @@ bool fsverity_verify_blocks(struct fsverity_info *vi, struct folio *folio, size_t len, size_t offset); void fsverity_verify_bio(struct fsverity_info *vi, struct bio *bio); void fsverity_enqueue_verify_work(struct work_struct *work); +void fsverity_fill_zerohash(struct folio *folio, size_t offset, size_t len, + struct fsverity_info *vi); #else /* !CONFIG_FS_VERITY */ @@ -281,6 +283,12 @@ static inline void fsverity_enqueue_verify_work(struct work_struct *work) WARN_ON_ONCE(1); } +static inline void fsverity_fill_zerohash(struct folio *folio, size_t offset, + size_t len, struct fsverity_info *vi) +{ + WARN_ON_ONCE(1); +} + #endif /* !CONFIG_FS_VERITY */ static inline bool fsverity_verify_folio(struct fsverity_info *vi, From patchwork Wed May 20 12:37:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241209 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Wabb3xiV; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=xpsh=dr=vger.kernel.org=linux-ext4+bounces-16596-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB5z6lpsz1xx8 for ; Wed, 20 May 2026 22:43:03 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB5z6JStz59HC for ; Wed, 20 May 2026 22:43:03 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB5z6Dsvz59HN; Wed, 20 May 2026 22:43:03 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c0a:e001:db::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280983; cv=pass; b=TXXSrDlAJ/4jCJf/4TLT7vvsq1yurr1n4y46419HXrL2ESrfTaWJqJoiVFjtB194SfOHnVAHRFMM5U3ztviz1HrmUiuR78pfTqba3MYcRU8A0NyTVb6j4qciR0ZeYpdoMYQtS+LjXOrQGdoCpGg3KZUh6qQf3hoMxgOsj4NH5EEazFIPwodRMTfvn8r+o4wm/TJ18x9RBeVDXWvFkmJgydPZMl3qJenslcTayVW5krfBq0AA+bNcMvtPK4FXdeRb0TbRgw7FdiKhoTkMcNINY9/XlEi6oRkjiYkRzGOFUwBzuRkRQdVsv0oew6n6oYOCoB9TbhPWdvV3xVNRO6b+oA== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280983; c=relaxed/relaxed; bh=bE8p1397UMHMZu2/AK9ljMJak3Vf/v+sTTscAk6wHps=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UmCMeLMNjSGl7p1YN9hYww2BOj+uc3pkC/6cbSHBZxDwXZ0vETkwoBz/C2XAkcfvkU0SE7jPZ07A1wLXFDzTP/Zt0v1Vc7/47URMhWExsmT4zPi5IsY1yS95/7OF+p6V6mkcSzMXuPOjPn8bqZ6OGyUXs21V8JVWUYSpdD/XMoCrPmGhviQsa34Fos+0AOyYOZ9D34GE3TNIELRTGs/zwjnolXmPglPuhXLA1SNUlWq+/GFncj3XTG+cZ948bg5VUabIoBb4CIkfu1WumxKV1kZ/z5ycrtaPowkZXQKrHC8wnus1/wdBIsPacpfB87nIQPtFfz7PMvdgWFAdr9oAtQ== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Wabb3xiV; dkim-atps=neutral; spf=pass (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16596-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Wabb3xiV; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16596-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [IPv6:2600:3c0a:e001:db::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB5w4XVkz59HC for ; Wed, 20 May 2026 22:43:00 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 609C230BE77E for ; Wed, 20 May 2026 12:38:01 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A5ABA3E275F; Wed, 20 May 2026 12:37:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Wabb3xiV" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D63793DD518; Wed, 20 May 2026 12:37:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280662; cv=none; b=sw3GKcB4TOiQ1QLb2mZ4lVT9puD72eb0UbBs0up+PfOilMWl/1kqk3VvHkI1ELv3Oc8umD2XEo8E1nn0Uqj/VJQGH2EMPiyRnU5FZpcR5rvz1I0JazXkUe/vWPURui2AqBWYHpHo0Qcmnlz2BjfuGrtaDhJ9wEPVq/wCewfkeTg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280662; c=relaxed/simple; bh=7Fpta3DiwBpUIOOjCNREW+R79tP+jAnYKhabwJ2dGuE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Y1KDTTGF3WFmT3PVM2TUXo2St9bcXWVEASuFHplMLFu97F5/VzPeDYDDHU39xaQI4LobmNG9TeFr/6wwgEH2BqcdSpzn4f+uWDsN9UbsJNeoOFQWZGiPb7nXEVzF++p7xCpw+x7DbsRVyNi72OC0IDyQBo2Z8D2oOm/ALScKg34= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Wabb3xiV; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id B949A1F00893; Wed, 20 May 2026 12:37:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280660; bh=bE8p1397UMHMZu2/AK9ljMJak3Vf/v+sTTscAk6wHps=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Wabb3xiVBTvAjY6O6/AG4iCtybK9opWo5Df5CWefc3wetFZ0rMSlvR0UjHLKa8y9g vctH26tq7t9YGZaSgrwLlzUKMOp7UROHV/dYX1U8v4jAbQYtM6VB75SlWz4ASBYKpk oslX64E/cB/cppaMdks1CX+0yEboCZYCm5s/WyPOgtBdOPdjSIFJuOUGu3cBpeN5A/ AL9VtTGxKFRqSHDZcfU6e/CrZr15JkqmteEX74OtLf/D1LQoVrgGYKVNIzWMd1l4mg 9i/x5QZlyO4ki94OPGJGP959Pzgcwla+RpyfPYcr745kWC7MPSuG63ZUvDEGlpzMVn MAy/gDZs9xiWA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 05/22] fsverity: pass digest size and hash of the all-zeroes block to ->write Date: Wed, 20 May 2026 14:37:03 +0200 Message-ID: <20260520123722.405752-6-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Let filesystem iterate over hashes in the block and check if these are hashes of zeroed data blocks. XFS will use this to decide if it want to store tree block full of these hashes. Signed-off-by: Andrey Albershteyn Reviewed-by: "Darrick J. Wong" Acked-by: Eric Biggers --- fs/btrfs/verity.c | 6 +++++- fs/ext4/verity.c | 4 +++- fs/f2fs/verity.c | 4 +++- fs/verity/enable.c | 4 +++- include/linux/fsverity.h | 6 +++++- 5 files changed, 19 insertions(+), 5 deletions(-) diff --git a/fs/btrfs/verity.c b/fs/btrfs/verity.c index 0062b3a55781..fd3696d3f4ce 100644 --- a/fs/btrfs/verity.c +++ b/fs/btrfs/verity.c @@ -773,11 +773,15 @@ static struct page *btrfs_read_merkle_tree_page(struct inode *inode, * @buf: Merkle tree block to write * @pos: the position of the block in the Merkle tree (in bytes) * @size: the Merkle tree block size (in bytes) + * @zero_digest: the hash of the all-zeroes block + * @digest_size: size of zero_digest, in bytes * * Returns 0 on success or negative error code on failure */ static int btrfs_write_merkle_tree_block(struct file *file, const void *buf, - u64 pos, unsigned int size) + u64 pos, unsigned int size, + const u8 *zero_digest, + unsigned int digest_size) { struct inode *inode = file_inode(file); loff_t merkle_pos = merkle_file_pos(inode); diff --git a/fs/ext4/verity.c b/fs/ext4/verity.c index ca61da53f313..347945ac23a4 100644 --- a/fs/ext4/verity.c +++ b/fs/ext4/verity.c @@ -374,7 +374,9 @@ static void ext4_readahead_merkle_tree(struct inode *inode, pgoff_t index, } static int ext4_write_merkle_tree_block(struct file *file, const void *buf, - u64 pos, unsigned int size) + u64 pos, unsigned int size, + const u8 *zero_digest, + unsigned int digest_size) { pos += ext4_verity_metadata_pos(file_inode(file)); diff --git a/fs/f2fs/verity.c b/fs/f2fs/verity.c index 92ebcc19cab0..b3b3e71604ac 100644 --- a/fs/f2fs/verity.c +++ b/fs/f2fs/verity.c @@ -270,7 +270,9 @@ static void f2fs_readahead_merkle_tree(struct inode *inode, pgoff_t index, } static int f2fs_write_merkle_tree_block(struct file *file, const void *buf, - u64 pos, unsigned int size) + u64 pos, unsigned int size, + const u8 *zero_digest, + unsigned int digest_size) { pos += f2fs_verity_metadata_pos(file_inode(file)); diff --git a/fs/verity/enable.c b/fs/verity/enable.c index 42dfed1ce0ce..ad4ff71d7dd9 100644 --- a/fs/verity/enable.c +++ b/fs/verity/enable.c @@ -50,7 +50,9 @@ static int write_merkle_tree_block(struct file *file, const u8 *buf, int err; err = inode->i_sb->s_vop->write_merkle_tree_block(file, buf, pos, - params->block_size); + params->block_size, + params->zero_digest, + params->digest_size); if (err) fsverity_err(inode, "Error %d writing Merkle tree block %lu", err, index); diff --git a/include/linux/fsverity.h b/include/linux/fsverity.h index 3c3250f6f272..9e7d946676b9 100644 --- a/include/linux/fsverity.h +++ b/include/linux/fsverity.h @@ -124,6 +124,8 @@ struct fsverity_operations { * @buf: the Merkle tree block to write * @pos: the position of the block in the Merkle tree (in bytes) * @size: the Merkle tree block size (in bytes) + * @zero_digest: the hash of the all-zeroes block + * @digest_size: size of zero_digest, in bytes * * This is only called between ->begin_enable_verity() and * ->end_enable_verity(). @@ -131,7 +133,9 @@ struct fsverity_operations { * Return: 0 on success, -errno on failure */ int (*write_merkle_tree_block)(struct file *file, const void *buf, - u64 pos, unsigned int size); + u64 pos, unsigned int size, + const u8 *zero_digest, + unsigned int digest_size); }; #ifdef CONFIG_FS_VERITY From patchwork Wed May 20 12:37:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241206 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VNdrrnMI; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=eogj=dr=vger.kernel.org=linux-ext4+bounces-16597-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB4P6mtNz1xx8 for ; Wed, 20 May 2026 22:41:41 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB4P6D11z596y for ; Wed, 20 May 2026 22:41:41 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB4P65r8z597M; Wed, 20 May 2026 22:41:41 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280901; cv=pass; b=u9ewdvF2Td02yZFiJa7GUQAahhHLSRbDXO+AqsaUKuvih/Qzag3fFFGTzCPF5g7a1xkjKP8IC8gyH3+aBKSyW/E3pxnxbVnw25c9DqwCU6fWYqgA+agW/iRorcwzvetdEwG7XSEeY9abZXXf368tfm+nklbst3OCdijPWcsRKo4Xms9h8BXfhp8yijtPGeKMwx23sfqC/iU9mQ8Lk315XigQHRRGZxEkZWptqVN+AtHby0cuaaJQ7A8evNJMcj5t3tz2gBvJkUK5viCft7PeKztOXSG7h6FR/d6EiATW/qSYPJolaCCkXyDvrMp2AVCbtcTcNKLLh5w/79ML5aCuIQ== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280901; c=relaxed/relaxed; bh=sVTGGPE/qLWPG7zNwh5xf7mxjHPGfB8oH+pkWcFtnJk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nsuAXUJQuFMEWNtgGLhYl9HKqtUmtwx7joe8ZoD5P7B+o7YH4eSkulK+b1QTAaF0SfBTmLFxt8czwcJQ+oI8YQjt0pVzc/uZyitqqrGHNz304VjQUHUr2mC3NG0ne5hVlu1EHr1pZ5sDjx4apjuu0lgSXRvcV7/ARlmHtuA1oTnHwXstjyGiXuvgRK8OO2viraFl1yetJ1R3wE4PxB0/c8/vuL9FUWNUjrrT3aRLmlzi8aPJ6zl/PR1BxYbVkLJ0OI1U+9ULlrdb13xOVz6gH4xmAtahIYlVQBdIxh4B7rWdVgnaVNhbYdwl4E0h76eoALPrRvG/jjzy+6POTqQpxA== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VNdrrnMI; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16597-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VNdrrnMI; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16597-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB4L3vC8z596y for ; Wed, 20 May 2026 22:41:38 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 7A6FD3005162 for ; Wed, 20 May 2026 12:38:10 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 179433E0C71; Wed, 20 May 2026 12:37:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VNdrrnMI" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0C5A53E1689; Wed, 20 May 2026 12:37:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280666; cv=none; b=emJEPMWX7+/VGT2dnthwCP1i2/yB/P2Yyf4SuPCoF2VLrVNogaa6YvZyCC9cC6RJ/6nVInnR6Wy8L4cL8ce31xEgVxSrWyfwMR6U6Q7Ps7w1bBHUF7ldDvuxsC3+QbHI9VgE/C7nSsl1KKfHvOx+Mb550RArpbh8J7ILKvxF9ks= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280666; c=relaxed/simple; bh=vZWYj+Ga6j52sqD6hIaXvS0sskvDwDhFJnZNiPmdFsM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UAVabWQxAc7INWs6XEndSBzUyWEEdAYEYbIp+lWi7oS7LG+Jx+9OdTIf4CzwiQZ2JfCQa3NaIQUIWQXhlGkYbnyB8AEoLZrBJtqq1X4w+gm9ayZL2lvKqNQfkvjnc63orX2TeuLOETDp/StVwqVhixh3UI1PIz8vB4k0ZnzxorU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VNdrrnMI; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2CA101F000E9; Wed, 20 May 2026 12:37:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280663; bh=sVTGGPE/qLWPG7zNwh5xf7mxjHPGfB8oH+pkWcFtnJk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VNdrrnMI3QGrKsC6xCans4vZw+6UW20seaIUCO1pNlUeRfV9Oks5TiUEPtn/jdJXP Ibft1w5C+ptBIk2yGfbtJlp3R6sFXaX+NmJ4jHZBFQ+xN2lZjW5moHqU11Hd+JroUS aiMd3fpKYnto9qi9LkLnedd0pxvXUWvPcVqxNdqY97PxVws0ePWwGYiEnsnbRv/DYG is4vc900/0RGyB3lrh9IAHCxh6w6vzN+4zlnP7ca83HDPlmlBAxVT0xf6MJlYtnp4K VqKp/kO3UJW6PNp+1HGopotW6Ib717bSVXx/hP8zis1t+B/SJShJq8l8fE+I3JTHok jDmMR9teV49dw== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 06/22] fsverity: hoist pagecache_read from f2fs/ext4 to fsverity Date: Wed, 20 May 2026 14:37:04 +0200 Message-ID: <20260520123722.405752-7-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org This is the same function to read from pageache. XFS will also need this, so move this to core fsverity. Note that f2fs and ext4 functions diverged a bit, as ext4 operated over folios and f2fs operated over pages. The common one will operate over folios. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Acked-by: Eric Biggers Signed-off-by: Andrey Albershteyn --- fs/ext4/verity.c | 32 +++----------------------------- fs/f2fs/verity.c | 30 +----------------------------- fs/verity/pagecache.c | 33 +++++++++++++++++++++++++++++++++ include/linux/fsverity.h | 2 ++ 4 files changed, 39 insertions(+), 58 deletions(-) diff --git a/fs/ext4/verity.c b/fs/ext4/verity.c index 347945ac23a4..ac5c133f5529 100644 --- a/fs/ext4/verity.c +++ b/fs/ext4/verity.c @@ -34,32 +34,6 @@ static inline loff_t ext4_verity_metadata_pos(const struct inode *inode) return round_up(inode->i_size, 65536); } -/* - * Read some verity metadata from the inode. __vfs_read() can't be used because - * we need to read beyond i_size. - */ -static int pagecache_read(struct inode *inode, void *buf, size_t count, - loff_t pos) -{ - while (count) { - struct folio *folio; - size_t n; - - folio = read_mapping_folio(inode->i_mapping, pos >> PAGE_SHIFT, - NULL); - if (IS_ERR(folio)) - return PTR_ERR(folio); - - n = memcpy_from_file_folio(buf, folio, pos, count); - folio_put(folio); - - buf += n; - pos += n; - count -= n; - } - return 0; -} - /* * Write some verity metadata to the inode for FS_IOC_ENABLE_VERITY. * kernel_write() can't be used because the file descriptor is readonly. @@ -311,8 +285,8 @@ static int ext4_get_verity_descriptor_location(struct inode *inode, goto bad; desc_size_pos -= sizeof(desc_size_disk); - err = pagecache_read(inode, &desc_size_disk, sizeof(desc_size_disk), - desc_size_pos); + err = fsverity_pagecache_read(inode, &desc_size_disk, + sizeof(desc_size_disk), desc_size_pos); if (err) return err; desc_size = le32_to_cpu(desc_size_disk); @@ -352,7 +326,7 @@ static int ext4_get_verity_descriptor(struct inode *inode, void *buf, if (buf_size) { if (desc_size > buf_size) return -ERANGE; - err = pagecache_read(inode, buf, desc_size, desc_pos); + err = fsverity_pagecache_read(inode, buf, desc_size, desc_pos); if (err) return err; } diff --git a/fs/f2fs/verity.c b/fs/f2fs/verity.c index b3b3e71604ac..5ea0a9b40443 100644 --- a/fs/f2fs/verity.c +++ b/fs/f2fs/verity.c @@ -36,34 +36,6 @@ static inline loff_t f2fs_verity_metadata_pos(const struct inode *inode) return round_up(inode->i_size, 65536); } -/* - * Read some verity metadata from the inode. __vfs_read() can't be used because - * we need to read beyond i_size. - */ -static int pagecache_read(struct inode *inode, void *buf, size_t count, - loff_t pos) -{ - while (count) { - size_t n = min_t(size_t, count, - PAGE_SIZE - offset_in_page(pos)); - struct page *page; - - page = read_mapping_page(inode->i_mapping, pos >> PAGE_SHIFT, - NULL); - if (IS_ERR(page)) - return PTR_ERR(page); - - memcpy_from_page(buf, page, offset_in_page(pos), n); - - put_page(page); - - buf += n; - pos += n; - count -= n; - } - return 0; -} - /* * Write some verity metadata to the inode for FS_IOC_ENABLE_VERITY. * kernel_write() can't be used because the file descriptor is readonly. @@ -248,7 +220,7 @@ static int f2fs_get_verity_descriptor(struct inode *inode, void *buf, if (buf_size) { if (size > buf_size) return -ERANGE; - res = pagecache_read(inode, buf, size, pos); + res = fsverity_pagecache_read(inode, buf, size, pos); if (res) return res; } diff --git a/fs/verity/pagecache.c b/fs/verity/pagecache.c index 99f5f53eea98..9d82e6b74ba1 100644 --- a/fs/verity/pagecache.c +++ b/fs/verity/pagecache.c @@ -78,3 +78,36 @@ void fsverity_fill_zerohash(struct folio *folio, size_t offset, size_t len, vi->tree_params.digest_size); } EXPORT_SYMBOL_GPL(fsverity_fill_zerohash); + +/** + * fsverity_pagecache_read() - read page and copy data to buffer + * @inode: copy from this inode's address space + * @buf: buffer to copy to + * @count: number of bytes to copy + * @pos: position of the folio to copy from + * + * Read some verity metadata from the inode. __vfs_read() can't be used because + * we need to read beyond i_size. + */ +int fsverity_pagecache_read(struct inode *inode, void *buf, size_t count, + loff_t pos) +{ + while (count) { + struct folio *folio; + size_t n; + + folio = read_mapping_folio(inode->i_mapping, pos >> PAGE_SHIFT, + NULL); + if (IS_ERR(folio)) + return PTR_ERR(folio); + + n = memcpy_from_file_folio(buf, folio, pos, count); + folio_put(folio); + + buf += n; + pos += n; + count -= n; + } + return 0; +} +EXPORT_SYMBOL_GPL(fsverity_pagecache_read); diff --git a/include/linux/fsverity.h b/include/linux/fsverity.h index 9e7d946676b9..f9433332c274 100644 --- a/include/linux/fsverity.h +++ b/include/linux/fsverity.h @@ -328,5 +328,7 @@ void fsverity_cleanup_inode(struct inode *inode); struct page *generic_read_merkle_tree_page(struct inode *inode, pgoff_t index); void generic_readahead_merkle_tree(struct inode *inode, pgoff_t index, unsigned long nr_pages); +int fsverity_pagecache_read(struct inode *inode, void *buf, size_t count, + loff_t pos); #endif /* _LINUX_FSVERITY_H */ From patchwork Wed May 20 12:37:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241212 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=d5KfCmdn; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=nq3m=dr=vger.kernel.org=linux-ext4+bounces-16598-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB7Q5QCVz1xx8 for ; Wed, 20 May 2026 22:44:18 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB7Q4w4vz59HC for ; Wed, 20 May 2026 22:44:18 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB7Q4r1Wz59HN; Wed, 20 May 2026 22:44:18 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c0a:e001:db::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281058; cv=pass; b=eG1mnZ6c0ms7Xpn6gbldAgunQj1Y67CGoxsIoXF5+UWaIYsuFX4bupeVsm/5pNi1SUZJjRreFD/7bikiI8PRVdxXcpx1jW74z2xcz/WxCklV9T0zSq1746tt2RBQUcs6+dZF9gy+/o0YTuTHx65tTJs3ObviZ7XoRFReQ75RotLRL2mNImDoQWcaSKIbyITXeG3ag44rXjJl+4pjpas2U34ycSH9j90d+k+rc7s3dWxa2IXAo5RcBMqgkuEfFodZJazTnmCHgcfg3nhwgfohQXCNUKvob6Uj++VX+wa4DnP2pufwTnp13Mlqi+/dlL5HwASDEIk2sK1dItgZDK8C3Q== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281058; c=relaxed/relaxed; bh=uqGYC+Xo07Bo0DJjsb5FX+IUzhDkmJjiRFqdavyiqa4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ZJvGq/OQIbjxBcQIOYzibk4rXrvRads02q6AMq18C0fbi0FyoayaLleBZe5+kKs31bsutS+YofagDLjwt8zqlScZ1LD8a592BoJk30gyVKE+QN+/+1/DotcWn4i7acrFVI4mhZZiN5iENq1vs8uiZsPVy1weeuGGLoJMhQw2f+VszCuyE0cph9OnEJjausQy4HLYtYi9BfmR1nDxHl89xJWZry5YzTcF4wyWt0JCjsqfAG5iRNyIaVp7U2qzCP8Ebk7VdvaMxQPYtcfs4ZfKgU2MNEZE67mPs8NhxD/eMKWlkMZhSiu50YxUoDIMstKLAbEJ9/yRVqkwXKXWQMI75g== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=d5KfCmdn; dkim-atps=neutral; spf=pass (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16598-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=d5KfCmdn; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16598-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [IPv6:2600:3c0a:e001:db::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB7M3CqZz59HC for ; Wed, 20 May 2026 22:44:15 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 0612730C1ABF for ; Wed, 20 May 2026 12:38:20 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 5F9B63DF002; Wed, 20 May 2026 12:37:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="d5KfCmdn" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 321083E314D; Wed, 20 May 2026 12:37:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280671; cv=none; b=Nsv3cYlVt1tacweeZedbQAwhmXujzZoelxEVnX0ZPyeS08dj+qLfmL7V3e3Le2WT+sdfqK2VuyGxFym/2x7K/gx3PWu7XZ1SQGCWNMIi67glpGC8ls8evDtwdn1u9DNzwqjSHF/2bepDegK9anVFR2ax4u8zqPGa78uqCgCX+84= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280671; c=relaxed/simple; bh=hmdOLaItS0sgTBX3BOx+azLS5uxrUqYyX9EAI3HLov0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qo+LOWIrDJbckbvMDWHmb/1Sg0d6LtzT7cfYI8dOFTn29KF+G1tc5evLDJMp+9whQTD9/I7vrjohDrYzDXZxrEOqdFxDhgEmd6Q0W8QPcsRIFyxnZRPix24jtqZ5J0iXtztxWa/i7nOHKj67DUOYJkLZHcbmQxfOblbJL3cUhRg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=d5KfCmdn; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9DC061F00893; Wed, 20 May 2026 12:37:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280665; bh=uqGYC+Xo07Bo0DJjsb5FX+IUzhDkmJjiRFqdavyiqa4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=d5KfCmdnueXDSjLY2n7tnUTZ5GkpTt4I5+5loqKbKcpUIwvZrydEXbFZZ1EJcua04 F0tIOmir1Hp+8Ejv08xw8HDIAyk2eKKz5DtDSrYzdLMMT6FoE6eu7gO8YvX3MYLo06 ks2DK5LhhUYTVoTTf7PIJID7IFGn1VI8O7zZcvKiLb/altk3coTBw4II+fRSWtCRqc hWYAjRdJsqq2tsQBftskCZ6+ISRUnGAkpl6ehYhBMLHaCG5bqTR2fweLnl2PA3xgz2 DIThsVxfmwRLcKvSS1EOHt9OxbxW2NVwbXRVGbZqACS7poXiIuL+nOQrihCJcVCT0y NsLfKK5aZP4pA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 07/22] iomap: introduce IOMAP_F_FSVERITY and teach writeback to handle fsverity Date: Wed, 20 May 2026 14:37:05 +0200 Message-ID: <20260520123722.405752-8-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org This flag indicates that I/O is for fsverity metadata. In the write path skip i_size check and i_size updates as metadata is past EOF. In writeback don't update i_size and continue writeback if even folio is beyond EOF. In read path don't zero fsverity folios, again they are past EOF. The iomap_block_needs_zeroing() is also called from write path. For folios of larger order we don't want to zero out pages in the folio as these could contain other merkle tree blocks. For fsverity, filesystem will request to read PAGE_SIZE memory regions. For data folios, iomap will zero the rest of the folio for anything which is beyond EOF. We don't want this for fsverity folios. Signed-off-by: Andrey Albershteyn Reviewed-by: "Darrick J. Wong" Reviewed-by: Christoph Hellwig --- fs/iomap/buffered-io.c | 43 +++++++++++++++++++++++++++++++++--------- fs/iomap/trace.h | 3 ++- include/linux/iomap.h | 8 ++++++++ 3 files changed, 44 insertions(+), 10 deletions(-) diff --git a/fs/iomap/buffered-io.c b/fs/iomap/buffered-io.c index d7b648421a70..3e0976bdb3ef 100644 --- a/fs/iomap/buffered-io.c +++ b/fs/iomap/buffered-io.c @@ -353,9 +353,26 @@ static inline bool iomap_block_needs_zeroing(const struct iomap_iter *iter, { const struct iomap *srcmap = iomap_iter_srcmap(iter); - return srcmap->type != IOMAP_MAPPED || - (srcmap->flags & IOMAP_F_NEW) || - pos >= i_size_read(iter->inode); + /* + * If this block has not been written, there's nothing to read + */ + if (srcmap->type != IOMAP_MAPPED) + return true; + + /* + * Newly allocated blocks have not been written + */ + if (srcmap->flags & IOMAP_F_NEW) + return true; + + /* + * fsverity metadata is stored past i_size, we need to read it instead + * of zeroing + */ + if (srcmap->flags & IOMAP_F_FSVERITY) + return false; + + return pos >= i_size_read(iter->inode); } /** @@ -1167,13 +1184,14 @@ static int iomap_write_iter(struct iomap_iter *iter, struct iov_iter *i, * unlock and release the folio. */ old_size = iter->inode->i_size; - if (pos + written > old_size) { + if (pos + written > old_size && + !(iter->iomap.flags & IOMAP_F_FSVERITY)) { i_size_write(iter->inode, pos + written); iter->iomap.flags |= IOMAP_F_SIZE_CHANGED; } __iomap_put_folio(iter, write_ops, written, folio); - if (old_size < pos) + if (old_size < pos && !(iter->iomap.flags & IOMAP_F_FSVERITY)) pagecache_isize_extended(iter->inode, old_size, pos); cond_resched(); @@ -1797,13 +1815,20 @@ static int iomap_writeback_range(struct iomap_writepage_ctx *wpc, * Check interaction of the folio with the file end. * * If the folio is entirely beyond i_size, return false. If it straddles - * i_size, adjust end_pos and zero all data beyond i_size. + * i_size, adjust end_pos and zero all data beyond i_size. Don't skip fsverity + * folios as those are beyond i_size. */ -static bool iomap_writeback_handle_eof(struct folio *folio, struct inode *inode, - u64 *end_pos) +static bool iomap_writeback_handle_eof(struct folio *folio, + struct iomap_writepage_ctx *wpc, u64 *end_pos) { + struct inode *inode = wpc->inode; u64 isize = i_size_read(inode); + if (wpc->iomap.flags & IOMAP_F_FSVERITY) { + WARN_ON_ONCE(folio_pos(folio) < isize); + return true; + } + if (*end_pos > isize) { size_t poff = offset_in_folio(folio, isize); pgoff_t end_index = isize >> PAGE_SHIFT; @@ -1869,7 +1894,7 @@ int iomap_writeback_folio(struct iomap_writepage_ctx *wpc, struct folio *folio) trace_iomap_writeback_folio(inode, pos, folio_size(folio)); - if (!iomap_writeback_handle_eof(folio, inode, &end_pos)) + if (!iomap_writeback_handle_eof(folio, wpc, &end_pos)) return 0; WARN_ON_ONCE(end_pos <= pos); diff --git a/fs/iomap/trace.h b/fs/iomap/trace.h index 097773c6db80..e4dd25b27656 100644 --- a/fs/iomap/trace.h +++ b/fs/iomap/trace.h @@ -118,7 +118,8 @@ DEFINE_RANGE_EVENT(iomap_zero_iter); { IOMAP_F_ATOMIC_BIO, "ATOMIC_BIO" }, \ { IOMAP_F_PRIVATE, "PRIVATE" }, \ { IOMAP_F_SIZE_CHANGED, "SIZE_CHANGED" }, \ - { IOMAP_F_STALE, "STALE" } + { IOMAP_F_STALE, "STALE" }, \ + { IOMAP_F_FSVERITY, "FSVERITY" } #define IOMAP_DIO_STRINGS \ diff --git a/include/linux/iomap.h b/include/linux/iomap.h index 2c5685adf3a9..ad1e39cde5e0 100644 --- a/include/linux/iomap.h +++ b/include/linux/iomap.h @@ -87,6 +87,14 @@ struct vm_fault; #define IOMAP_F_INTEGRITY 0 #endif /* CONFIG_BLK_DEV_INTEGRITY */ +/* + * Indicates reads and writes of fsverity metadata. + * + * Fsverity metadata is stored after the regular file data and thus beyond + * i_size. + */ +#define IOMAP_F_FSVERITY (1U << 10) + /* * Flag reserved for file system specific usage */ From patchwork Wed May 20 12:37:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241213 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Cbz1F8g3; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=kbl4=dr=vger.kernel.org=linux-ext4+bounces-16599-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB7X1SLgz1xx8 for ; Wed, 20 May 2026 22:44:24 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB7X12V7z59HN for ; Wed, 20 May 2026 22:44:24 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB7X0xgzz59HC; Wed, 20 May 2026 22:44:24 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c0a:e001:db::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281064; cv=pass; b=UOiSl9eZewDHWjVCR3RLM53xfNCWUSD5TDjfX9Pe+rmMK8FHFa6IOyIwyQlrndpRXl4ywch7/59P0MRVbOU6Qx3zDyl2rrQzb2oqnvpe31ZmEBa85FYpZ2pbRRGB4F4tL0FBYx1yTCwFuVa2yEUCAOOjgkbuQDZScR6f13qu2s1c1fKONhPUhJBM73nXKigTIcOGMeM/B4Hn7mnjc2djH2Zp59JWXwQcoqima9oTuN5sT1odjsDSL4YZSJbkRlBWDEGFxFFqpt/Edfcj8ATo3vBSnCvicOtdKG69TQsz7SerCJTZTfBptDL667l7ulLbYrVgdwRDshplOxYmXfQJ1w== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281064; c=relaxed/relaxed; bh=p1vQC2ub1UA9ygBk2EcKtqp5ZHh1Jmwwvx64Z+1Yosw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ATFOTIXx9HD/2x3MYGvGJAeOOdrlxDWQf196fgJqijeDCQmh8DojmNp6VxfgGwYQkjTmWYbrJYdDb2PmQbZRe+xghJvrJ+I2nya1qDTLY/j0LkwbG5htQQPaeBqt8BKsCo0BHPc65/WsBlJLKnkl/wjSJPn8NXlzC/T9wsv1tUZpan3aKqmYNMheRIiMLZmuQ+MsKsjcPYe1H9rhV/nuWR1eoI0vpvZtrBmKYhPEALNuMB19jugHHYOQZ8XyqYq2bXq0/b8l+IvYq7jDILlTx5MIroci7lMQ9JFtAAA3Z0A/DHPKoJ8fYSNN2DCnRLYjC6Si/5vJcnRDO6AEU72yYg== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Cbz1F8g3; dkim-atps=neutral; spf=pass (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16599-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=Cbz1F8g3; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16599-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [IPv6:2600:3c0a:e001:db::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB7S6Gcbz59HN for ; Wed, 20 May 2026 22:44:20 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id DE77D30D2E1E for ; Wed, 20 May 2026 12:38:26 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A55423E4C90; Wed, 20 May 2026 12:37:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Cbz1F8g3" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BEE173A2E3F; Wed, 20 May 2026 12:37:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280671; cv=none; b=DWmvted1iE4RM8cGN8fxJ3CQcv4heAPGeWPyQmC0CfSBBkBnK1FiklP03d19H9bna/gMTbcPf9OujPJd3bK+f0Mm7ZSPHCo92X2sS0DrcOPPhLbmg3DedQ0bKi5HaVd4sW+G272on49lfxtsZDAaN42aA6aZT62WxGJW8Q6qXqw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280671; c=relaxed/simple; bh=zstVptgKM2D/tEW7lhqy5Iv8bF+kKWCKyre6uXYSM8g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=a92vdsoC1D6WaDBslksdeF3WjCvVUN2ySXEhwHdVnWwpQYxWfTdQw7B25GLZ9IcAOG2WtMXAxwpzLUv7+RK7exRaYNm91J+e57Tymht4RJ68abe6zHxGaV80a4jouyGubb6RM2jyRrMvH331rQ/N26ng6OclJuZB6mgCn43MDRM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Cbz1F8g3; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 171471F00894; Wed, 20 May 2026 12:37:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280668; bh=p1vQC2ub1UA9ygBk2EcKtqp5ZHh1Jmwwvx64Z+1Yosw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Cbz1F8g3j9sMytZ6bpGR+ayY4TDv7h+Dm44W6dcZDXKk7ErsAD03rZQ56pMtT7d73 6FNcLiFDL6zRFaiPC/bCcyQpOLAVdJGz4gzkg3lzSCKL9n2WVNN+PaxXwKJxTxcqJJ r+NdYezlEJXsxKVGPbTFbclxcZ0kmGTuXlG3t1LARoDy9KVpk0x1QaAEtHZx3jrMDt Xkr1gYoXJKShEs39xluw7JVjuKUoAg+itYWIvfoLjoBXlALiF5VRzqi88U+vw11VuR Z/6hPX+NFKSdeKzbIyfteayY5acBf+J9vVZ/5UMVKNYqq5Mc52OPuY0EH/wPhC4E7V 8Crd+wizdsQXA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 08/22] iomap: teach iomap to read files with fsverity Date: Wed, 20 May 2026 14:37:06 +0200 Message-ID: <20260520123722.405752-9-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Obtain fsverity info for folios with file data and fsverity metadata. Filesystem can pass vi down to ioend and then to fsverity for verification. This is different from other filesystems ext4, f2fs, btrfs supporting fsverity, these filesystems don't need fsverity_info for reading fsverity metadata. While reading merkle tree iomap requires fsverity info to synthesize hashes for zeroed data block. fsverity metadata has two kinds of holes - ones in merkle tree and one after fsverity descriptor. Merkle tree holes are blocks full of hashes of zeroed data blocks. These are not stored on the disk but synthesized on the fly. This saves a bit of space for sparse files. Due to this iomap also need to lookup fsverity_info for folios with fsverity metadata. ->vi has a hash of the zeroed data block which will be used to fill the merkle tree block. The hole past descriptor is interpreted as end of metadata region. As we don't have EOF here we use this hole as an indication that rest of the folio is empty. This patch marks rest of the folio beyond fsverity descriptor as uptodate. For file data, fsverity needs to verify consistency of the whole file against the root hash, hashes of holes are included in the merkle tree. Verify them too. Issue reading of fsverity merkle tree on the fsverity inodes. This way metadata will be available at I/O completion time. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/iomap/buffered-io.c | 41 +++++++++++++++++++++++++++++++++++++++-- fs/iomap/ioend.c | 1 + include/linux/iomap.h | 2 ++ 3 files changed, 42 insertions(+), 2 deletions(-) diff --git a/fs/iomap/buffered-io.c b/fs/iomap/buffered-io.c index 3e0976bdb3ef..1c66a1c362a7 100644 --- a/fs/iomap/buffered-io.c +++ b/fs/iomap/buffered-io.c @@ -9,6 +9,7 @@ #include #include #include +#include #include "internal.h" #include "trace.h" @@ -561,9 +562,27 @@ static int iomap_read_folio_iter(struct iomap_iter *iter, if (plen == 0) return 0; - /* zero post-eof blocks as the page may be mapped */ - if (iomap_block_needs_zeroing(iter, pos)) { + /* + * Handling of fsverity "holes". We hit this for two case: + * 1. No need to go further, the hole after fsverity + * descriptor is the end of the fsverity metadata. + * + * 2. This folio contains merkle tree blocks which need to be + * synthesized. If we already have fsverity info (ctx->vi) + * synthesize these blocks. + */ + if ((iomap->flags & IOMAP_F_FSVERITY) && + iomap->type == IOMAP_HOLE) { + if (ctx->vi) + fsverity_fill_zerohash(folio, poff, plen, + ctx->vi); + iomap_set_range_uptodate(folio, poff, plen); + } else if (iomap_block_needs_zeroing(iter, pos)) { + /* zero post-eof blocks as the page may be mapped */ folio_zero_range(folio, poff, plen); + if (ctx->vi && + !fsverity_verify_blocks(ctx->vi, folio, plen, poff)) + return -EIO; iomap_set_range_uptodate(folio, poff, plen); } else { if (!*bytes_submitted) @@ -614,6 +633,15 @@ void iomap_read_folio(const struct iomap_ops *ops, trace_iomap_readpage(iter.inode, 1); + /* + * Fetch fsverity_info for both data and fsverity metadata, as iomap + * needs zeroed hash for merkle tree block synthesis + */ + ctx->vi = fsverity_get_info(iter.inode); + if (ctx->vi && iter.pos < i_size_read(iter.inode)) + fsverity_readahead(ctx->vi, folio->index, + folio_nr_pages(folio)); + while ((ret = iomap_iter(&iter, ops)) > 0) iter.status = iomap_read_folio_iter(&iter, ctx, &bytes_submitted); @@ -681,6 +709,15 @@ void iomap_readahead(const struct iomap_ops *ops, trace_iomap_readahead(rac->mapping->host, readahead_count(rac)); + /* + * Fetch fsverity_info for both data and fsverity metadata, as iomap + * needs zeroed hash for merkle tree block synthesis + */ + ctx->vi = fsverity_get_info(iter.inode); + if (ctx->vi && iter.pos < i_size_read(iter.inode)) + fsverity_readahead(ctx->vi, readahead_index(rac), + readahead_count(rac)); + while (iomap_iter(&iter, ops) > 0) iter.status = iomap_readahead_iter(&iter, ctx, &cur_bytes_submitted); diff --git a/fs/iomap/ioend.c b/fs/iomap/ioend.c index acf3cf98b23a..f7c3e0c70fd7 100644 --- a/fs/iomap/ioend.c +++ b/fs/iomap/ioend.c @@ -28,6 +28,7 @@ struct iomap_ioend *iomap_init_ioend(struct inode *inode, ioend->io_offset = file_offset; ioend->io_size = bio->bi_iter.bi_size; ioend->io_sector = bio->bi_iter.bi_sector; + ioend->io_vi = NULL; ioend->io_private = NULL; return ioend; } diff --git a/include/linux/iomap.h b/include/linux/iomap.h index ad1e39cde5e0..94afe4e170d0 100644 --- a/include/linux/iomap.h +++ b/include/linux/iomap.h @@ -435,6 +435,7 @@ struct iomap_ioend { loff_t io_offset; /* offset in the file */ sector_t io_sector; /* start sector of ioend */ void *io_private; /* file system private data */ + struct fsverity_info *io_vi; /* fsverity info */ struct bio io_bio; /* MUST BE LAST! */ }; @@ -509,6 +510,7 @@ struct iomap_read_folio_ctx { struct readahead_control *rac; void *read_ctx; loff_t read_ctx_file_offset; + struct fsverity_info *vi; }; struct iomap_read_ops { From patchwork Wed May 20 12:37:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241210 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=YZW53TEQ; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=150.107.74.76; helo=mail.ozlabs.org; envelope-from=srs0=lir1=dr=vger.kernel.org=linux-ext4+bounces-16600-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB6C6lQHz1xx8 for ; Wed, 20 May 2026 22:43:15 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB6C6Dmtz59HC for ; Wed, 20 May 2026 22:43:15 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB6C6BN8z59HR; Wed, 20 May 2026 22:43:15 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c04:e001:36c::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280995; cv=pass; b=sDZu/3541uTWbOw+J8s/6SXS4j9zjepxC7R+pOQ+l/SE9VlCagWU6urh2eNGvMTB/7yaFJjtW846KBxrW3XPPh495ky7ynQxp+5HMT+dZEeM9oXcU26MdSWKuBHyY6LhDSo1Ex1yQeJ3dZHcozWKcYsQY4/JAoe15xixTDM1niwcEAESFnahSpfbQ6OniWGyXwgqrY3W5lRbE5D+YXbxUDBrf/vWwFVZ5GfbzTp9tbSXxynCLXgh5XatOEInXpi1t4BocRzNT5GUL8YiV2xosj7dmcMXXfHtBtMhOFuvLakoHbPZMgw0Yqghf3ZOxhjp0ZRDs1O50z7VoLom2F8Qxw== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280995; c=relaxed/relaxed; bh=HzdcyfQPNerVORYm1bBgmiQ6yYyGFk9EgoKl05CxMyA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MfMAqoDfBTRosG1POQmRAV662oo+FS17ZxNYq4MvOVGMPm1bZaBTkLSecJ6Ok4r8RgPfJI0f3vDwy/aVI1WNSaKOT05OL1MpoQR1o4U4uV8jSLN6HG6Eh4IsxqTNZawV9ONUiV7Om0obITARsxLZTXwAJDP82hsPqFsTCJUdQGo8AbAwy3LGoj6Dh5TfBncXdXzptq3AHjVRn8d/Ga9sKsQ7Lp+gUk9E7cdjv7rUVoBgIgx3Is/5nsAEQ4wmAZGuj5/Jcwzl0NNhy2Uoos+FCICUOpAQKg5Yar9lVzBg8+4/hrvZjfZe5mu/ShYK/ydmt/AkzU8KbMFyDKsn+8djMg== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=YZW53TEQ; dkim-atps=neutral; spf=pass (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16600-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=YZW53TEQ; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16600-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB684nQFz59HC for ; Wed, 20 May 2026 22:43:12 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 77BF730F4A27 for ; Wed, 20 May 2026 12:38:37 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id C59CF3E5EE7; Wed, 20 May 2026 12:37:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YZW53TEQ" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 400583E1689; Wed, 20 May 2026 12:37:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280672; cv=none; b=qJIWoPVTMzTq7u92AsmFkjH07hHNBn8JcgTBsf9UQ8KKW0Vd04JcKxWyE5cECBbSLkrQhs12fVGioJawuuKtgOuAtkHYVMqhzuvNDm/eN/f/bQnURtt2P38UDY4QWXSyHV2PYlSOTKjipg2YZV7+brF5HmUE2fQiuoiZRaES1xE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280672; c=relaxed/simple; bh=1YGKwRWSwDpwL0zPksrmqnNVlgXD5DrMzp6PtbmNMqs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PaZ9WPnlE1UMiSzJewrdWSbWCA2iQPT0kO38qzxRJv0eLAlPMJE52R4LppkK51xNhuGYdoXNVFguwlbo9UyqVc/3YniF7/PyOL2rI1sOU2Pqjjccw7k+jkfs7oMYBYWoMF5SGEmJ7WibuVfdNWHpwaeXtetD6hpmcncrGTPgchc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YZW53TEQ; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 84C1E1F000E9; Wed, 20 May 2026 12:37:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280670; bh=HzdcyfQPNerVORYm1bBgmiQ6yYyGFk9EgoKl05CxMyA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YZW53TEQcamrcSJeuP8xVdiBhGLi/o/4IHVdtbH4S3GGk9uYKEMn8PGxsZ8JDjwgn svt/50otd+fBBnsYluQwsOVExQjhfwh87goTxxAAIkX3jFm7jyy5fuqFHerrTbrGlJ RRNtIc14qmEs0C/H8JZjiko2Z5mnS+6ZBSrJT6ys7OwgLMBYsl+dwMasPZwaLkepzf lV8nVOeYm+2T5j86bI6ml2JFF4erDNAlgcHbGGoTGOY4zwE824nJoh+C1NxOfwbNVf WxOYYe0PWHaun2sK0+sWPfC4GxtN52NCxGFf3+XMmlUhLPwmXlQ9oAv/CNVWvXV/td 50H+T+3xztDpA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 09/22] iomap: introduce iomap_fsverity_write() for writing fsverity metadata Date: Wed, 20 May 2026 14:37:07 +0200 Message-ID: <20260520123722.405752-10-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org This is just a wrapper around iomap_file_buffered_write() to create necessary iterator over metadata. Reviewed-by: Christoph Hellwig Reviewed-by: Darrick J. Wong Signed-off-by: Andrey Albershteyn --- fs/iomap/buffered-io.c | 25 +++++++++++++++++++++++++ include/linux/iomap.h | 3 +++ 2 files changed, 28 insertions(+) diff --git a/fs/iomap/buffered-io.c b/fs/iomap/buffered-io.c index 1c66a1c362a7..eed646d7eb48 100644 --- a/fs/iomap/buffered-io.c +++ b/fs/iomap/buffered-io.c @@ -1287,6 +1287,31 @@ iomap_file_buffered_write(struct kiocb *iocb, struct iov_iter *i, } EXPORT_SYMBOL_GPL(iomap_file_buffered_write); +int iomap_fsverity_write(struct file *file, loff_t pos, size_t length, + const void *buf, const struct iomap_ops *ops, + const struct iomap_write_ops *write_ops) +{ + int ret; + struct iov_iter iiter; + struct kvec kvec = { + .iov_base = (void *)buf, + .iov_len = length, + }; + struct kiocb iocb = { + .ki_filp = file, + .ki_ioprio = get_current_ioprio(), + .ki_pos = pos, + }; + + iov_iter_kvec(&iiter, WRITE, &kvec, 1, length); + + ret = iomap_file_buffered_write(&iocb, &iiter, ops, write_ops, NULL); + if (ret < 0) + return ret; + return ret == length ? 0 : -EIO; +} +EXPORT_SYMBOL_GPL(iomap_fsverity_write); + static void iomap_write_delalloc_ifs_punch(struct inode *inode, struct folio *folio, loff_t start_byte, loff_t end_byte, struct iomap *iomap, iomap_punch_t punch) diff --git a/include/linux/iomap.h b/include/linux/iomap.h index 94afe4e170d0..5517bd9622ca 100644 --- a/include/linux/iomap.h +++ b/include/linux/iomap.h @@ -359,6 +359,9 @@ static inline bool iomap_want_unshare_iter(const struct iomap_iter *iter) ssize_t iomap_file_buffered_write(struct kiocb *iocb, struct iov_iter *from, const struct iomap_ops *ops, const struct iomap_write_ops *write_ops, void *private); +int iomap_fsverity_write(struct file *file, loff_t pos, size_t length, + const void *buf, const struct iomap_ops *ops, + const struct iomap_write_ops *write_ops); void iomap_read_folio(const struct iomap_ops *ops, struct iomap_read_folio_ctx *ctx, void *private); void iomap_readahead(const struct iomap_ops *ops, From patchwork Wed May 20 12:37:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241202 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SM2CLHjl; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=150.107.74.76; helo=mail.ozlabs.org; envelope-from=srs0=6pvw=dr=vger.kernel.org=linux-ext4+bounces-16601-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB2r3L11z1xx8 for ; Wed, 20 May 2026 22:40:20 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB2r2vqgz59HS for ; Wed, 20 May 2026 22:40:20 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB2r2r7Dz59HQ; Wed, 20 May 2026 22:40:20 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c09:e001:a7::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280820; cv=pass; b=LnLHSFlsanrE5R0S+dbQH+AMTIZDfEnufimKoIAYcxyZ8LTU3ZIwBMS/h+AmoCpsfFPtwCrKLgmmxdZt7M7F3CXarYI0zb7xUnqEa0zXkXt7EA1aHY6senyW1W4gTrKBvIq8OvmWmWMbzOa/r/fm83qro1AAJQkut7M9GBrqvVwcCHbikVmMXXRH7sPdl4II7V90ZDgMfsrO+0k4VAaKwtJxAn8GkjVEYw1iqSYdlT49fkRxYI1MhsGCMJz17KTx7n7GMq2kz7572CXs/B+GUgi79m6ynhciteDdCE13rj+gR3XZvydxJGHyUVe0jPpHm+SlnDF7a3kSOimyoyHXeg== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280820; c=relaxed/relaxed; bh=gg4rCyFYhv5l6Q+vqxuwS2I+3QnGOKPEeHuiVn6kbnY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=cY+WT46SGhvqraEDr6HTGWoILOOHyexztCUT/lImKDX0j69X9nS6eY4pCDs30ZQ1N+I/d9dh9v+IRDP71ClxzQNCQ3H6l9McRlGlAWT3gtHDpKaukfjW6dDCj6Gb4DUHB8+Xr8/SypyPpiQs8PfCWcjJq6+0k1nTARlAn9LmBaR0OH/4yYFEw5lBI6Qi0EVrUeoDHhOFZ18E1I/hDqiOxFoZ996Waw/WdunNF+CFa6843lZ/Cy5HOb+QD7IXHAyobYnI31dtNUgse+Pt81md3An6bss6ajEoCy+5ebmmgU8Jn0vQjDvjaSfRzO1C29tAOTurQ6qIcJKd3yemA2hIGw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SM2CLHjl; dkim-atps=neutral; spf=pass (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16601-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SM2CLHjl; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16601-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [IPv6:2600:3c09:e001:a7::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB2m4xQKz59HV for ; Wed, 20 May 2026 22:40:16 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 77E8A300C33A for ; Wed, 20 May 2026 12:38:44 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id E036A3E715E; Wed, 20 May 2026 12:37:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="SM2CLHjl" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 676863E63AC; Wed, 20 May 2026 12:37:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280674; cv=none; b=qp9OjFkiNMNlqKaq5ws16ZmdIEuDUxw11Nbq2L0v/bCIw33TlZUE8zQ8EIqGsRsvQ9MlDVrc9oHmeczIM3QvlrwMm/VdPeDCLUi8/TXmAvjCw1M0cgP9SAo8YDpkuItCTQ/c5royyRSVf7+nwMo/Pc4gLBCqy3kS9mwNElx+Gd0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280674; c=relaxed/simple; bh=DI+HyN52G+Fqr5k9YmqNkZiBe7FPPoDXQWOhI2idPwU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=qGc/io0HVquKTnt43To+73IIqV5qwl8uUS6eiFx0sHMInpkwjVUD72cCdizOQ/4tkD4enagwJTD8cFVgxhOoOIKw7inV04jfPiBNg8L3kBN0HXNh83e33zdo19aEGBICv6oDiDoNvVNqnDI+3hRLc1rrMkgmifrxRui/wABH0Xk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=SM2CLHjl; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id F3B021F00896; Wed, 20 May 2026 12:37:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280673; bh=gg4rCyFYhv5l6Q+vqxuwS2I+3QnGOKPEeHuiVn6kbnY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SM2CLHjla0ZOYmC7wAXU33ttnandNjccSaeryM2ZkTpztoQtvSL1HpBSvD8Vt9Lpg r3vVfW/7gaMRxvbX7T0RBpfItX0QGD+QoDR2TCVBdmaCj2uSfYKFBHwgDSKonhHWuc k+xcnuesU/28qglhxpGXEJdRS/lI4I+hw1L3x8DXwD1ikJh+vBqP9MmX0Ko0H/wDxu 2Yje+1CSfTNCb07p4BwBMTEHKqhfuy99EiGO6la4M7KRHqFx897wyRA8hXRJzHSQrP xYO5eh9YGEcF0YJngj4sm5+Igd4ov1s7/j7OR9O1w9nUY9B3kuH1ORhn6lbDUBGCmi s0oNe5alCDWjQ== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 10/22] xfs: introduce fsverity on-disk changes Date: Wed, 20 May 2026 14:37:08 +0200 Message-ID: <20260520123722.405752-11-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Introduce XFS_DIFLAG2_VERITY for inodes with fsverity. This flag indicates that inode has fs-verity enabled (i.e. descriptor exist, tree is built and file is read-only). Introduce XFS_SB_FEAT_RO_COMPAT_VERITY for filesystems having fsverity inodes. As on-disk changes applies to fsverity inodes only, let older kernels read-only access. This will be enabled in the further patch after full fsverity support. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/libxfs/xfs_format.h | 30 +++++++++++++++++++++++++++++- fs/xfs/libxfs/xfs_inode_buf.c | 8 ++++++++ fs/xfs/libxfs/xfs_inode_util.c | 2 ++ fs/xfs/libxfs/xfs_sb.c | 2 ++ fs/xfs/xfs_iops.c | 2 ++ fs/xfs/xfs_mount.h | 2 ++ 6 files changed, 45 insertions(+), 1 deletion(-) diff --git a/fs/xfs/libxfs/xfs_format.h b/fs/xfs/libxfs/xfs_format.h index 779dac59b1f3..4dff29659e40 100644 --- a/fs/xfs/libxfs/xfs_format.h +++ b/fs/xfs/libxfs/xfs_format.h @@ -374,6 +374,7 @@ xfs_sb_has_compat_feature( #define XFS_SB_FEAT_RO_COMPAT_RMAPBT (1 << 1) /* reverse map btree */ #define XFS_SB_FEAT_RO_COMPAT_REFLINK (1 << 2) /* reflinked files */ #define XFS_SB_FEAT_RO_COMPAT_INOBTCNT (1 << 3) /* inobt block counts */ +#define XFS_SB_FEAT_RO_COMPAT_VERITY (1 << 4) /* fs-verity */ #define XFS_SB_FEAT_RO_COMPAT_ALL \ (XFS_SB_FEAT_RO_COMPAT_FINOBT | \ XFS_SB_FEAT_RO_COMPAT_RMAPBT | \ @@ -1230,16 +1231,21 @@ static inline void xfs_dinode_put_rdev(struct xfs_dinode *dip, xfs_dev_t rdev) */ #define XFS_DIFLAG2_METADATA_BIT 5 +/* inodes sealed with fs-verity */ +#define XFS_DIFLAG2_VERITY_BIT 6 + #define XFS_DIFLAG2_DAX (1ULL << XFS_DIFLAG2_DAX_BIT) #define XFS_DIFLAG2_REFLINK (1ULL << XFS_DIFLAG2_REFLINK_BIT) #define XFS_DIFLAG2_COWEXTSIZE (1ULL << XFS_DIFLAG2_COWEXTSIZE_BIT) #define XFS_DIFLAG2_BIGTIME (1ULL << XFS_DIFLAG2_BIGTIME_BIT) #define XFS_DIFLAG2_NREXT64 (1ULL << XFS_DIFLAG2_NREXT64_BIT) #define XFS_DIFLAG2_METADATA (1ULL << XFS_DIFLAG2_METADATA_BIT) +#define XFS_DIFLAG2_VERITY (1ULL << XFS_DIFLAG2_VERITY_BIT) #define XFS_DIFLAG2_ANY \ (XFS_DIFLAG2_DAX | XFS_DIFLAG2_REFLINK | XFS_DIFLAG2_COWEXTSIZE | \ - XFS_DIFLAG2_BIGTIME | XFS_DIFLAG2_NREXT64 | XFS_DIFLAG2_METADATA) + XFS_DIFLAG2_BIGTIME | XFS_DIFLAG2_NREXT64 | XFS_DIFLAG2_METADATA | \ + XFS_DIFLAG2_VERITY) static inline bool xfs_dinode_has_bigtime(const struct xfs_dinode *dip) { @@ -2021,4 +2027,26 @@ struct xfs_acl { #define SGI_ACL_FILE_SIZE (sizeof(SGI_ACL_FILE)-1) #define SGI_ACL_DEFAULT_SIZE (sizeof(SGI_ACL_DEFAULT)-1) +/* + * At maximum of 8 levels with 128 hashes per block (32 bytes SHA-256) maximum + * tree size is ((128^8 − 1)/(128 − 1)) = 567*10^12 blocks. This should fit in + * 53 bits address space. + * + * At this Merkle tree size we can cover 295EB large file. This is much larger + * than the currently supported file size. + * + * For sha512 the largest file we can cover ends at 1 << 50 offset, this is also + * good. + */ +#define XFS_FSVERITY_LARGEST_FILE ((loff_t)1ULL << 53) + +/* + * Alignment of the fsverity metadata placement. This is largest supported PAGE + * SIZE for fsverity. This is used to space out data and metadata in page cache. + * The spacing is necessary for non-exposure of metadata to userspace and + * correct merkle tree synethesis in the iomap. + */ +#define XFS_FSVERITY_START_ALIGN (65536) + + #endif /* __XFS_FORMAT_H__ */ diff --git a/fs/xfs/libxfs/xfs_inode_buf.c b/fs/xfs/libxfs/xfs_inode_buf.c index 3794e5412eba..f2181c1bed54 100644 --- a/fs/xfs/libxfs/xfs_inode_buf.c +++ b/fs/xfs/libxfs/xfs_inode_buf.c @@ -760,6 +760,14 @@ xfs_dinode_verify( !xfs_has_rtreflink(mp)) return __this_address; + /* only regular files can have fsverity */ + if (flags2 & XFS_DIFLAG2_VERITY) { + if (!xfs_has_verity(mp)) + return __this_address; + if (!S_ISREG(mode)) + return __this_address; + } + if (xfs_has_zoned(mp) && dip->di_metatype == cpu_to_be16(XFS_METAFILE_RTRMAP)) { if (be32_to_cpu(dip->di_used_blocks) > mp->m_sb.sb_rgextents) diff --git a/fs/xfs/libxfs/xfs_inode_util.c b/fs/xfs/libxfs/xfs_inode_util.c index 551fa51befb6..6b1e20a4bb9b 100644 --- a/fs/xfs/libxfs/xfs_inode_util.c +++ b/fs/xfs/libxfs/xfs_inode_util.c @@ -126,6 +126,8 @@ xfs_ip2xflags( flags |= FS_XFLAG_DAX; if (ip->i_diflags2 & XFS_DIFLAG2_COWEXTSIZE) flags |= FS_XFLAG_COWEXTSIZE; + if (ip->i_diflags2 & XFS_DIFLAG2_VERITY) + flags |= FS_XFLAG_VERITY; } if (xfs_inode_has_attr_fork(ip)) diff --git a/fs/xfs/libxfs/xfs_sb.c b/fs/xfs/libxfs/xfs_sb.c index 47322adb7690..a15510ebd2f1 100644 --- a/fs/xfs/libxfs/xfs_sb.c +++ b/fs/xfs/libxfs/xfs_sb.c @@ -165,6 +165,8 @@ xfs_sb_version_to_features( features |= XFS_FEAT_REFLINK; if (sbp->sb_features_ro_compat & XFS_SB_FEAT_RO_COMPAT_INOBTCNT) features |= XFS_FEAT_INOBTCNT; + if (sbp->sb_features_ro_compat & XFS_SB_FEAT_RO_COMPAT_VERITY) + features |= XFS_FEAT_VERITY; if (sbp->sb_features_incompat & XFS_SB_FEAT_INCOMPAT_FTYPE) features |= XFS_FEAT_FTYPE; if (sbp->sb_features_incompat & XFS_SB_FEAT_INCOMPAT_SPINODES) diff --git a/fs/xfs/xfs_iops.c b/fs/xfs/xfs_iops.c index 325c2200c501..25c6e1d08cdc 100644 --- a/fs/xfs/xfs_iops.c +++ b/fs/xfs/xfs_iops.c @@ -1398,6 +1398,8 @@ xfs_diflags_to_iflags( flags |= S_NOATIME; if (init && xfs_inode_should_enable_dax(ip)) flags |= S_DAX; + if (xflags & FS_XFLAG_VERITY) + flags |= S_VERITY; /* * S_DAX can only be set during inode initialization and is never set by diff --git a/fs/xfs/xfs_mount.h b/fs/xfs/xfs_mount.h index d964bae096ef..2c06778a404a 100644 --- a/fs/xfs/xfs_mount.h +++ b/fs/xfs/xfs_mount.h @@ -388,6 +388,7 @@ typedef struct xfs_mount { #define XFS_FEAT_EXCHANGE_RANGE (1ULL << 27) /* exchange range */ #define XFS_FEAT_METADIR (1ULL << 28) /* metadata directory tree */ #define XFS_FEAT_ZONED (1ULL << 29) /* zoned RT device */ +#define XFS_FEAT_VERITY (1ULL << 30) /* fs-verity */ /* Mount features */ #define XFS_FEAT_NOLIFETIME (1ULL << 47) /* disable lifetime hints */ @@ -445,6 +446,7 @@ __XFS_HAS_FEAT(exchange_range, EXCHANGE_RANGE) __XFS_HAS_FEAT(metadir, METADIR) __XFS_HAS_FEAT(zoned, ZONED) __XFS_HAS_FEAT(nolifetime, NOLIFETIME) +__XFS_HAS_FEAT(verity, VERITY) static inline bool xfs_has_rtgroups(const struct xfs_mount *mp) { From patchwork Wed May 20 12:37:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241220 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=kpYxJYjR; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=v06l=dr=vger.kernel.org=linux-ext4+bounces-16602-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLBBd6BKTz1xx5 for ; Wed, 20 May 2026 22:47:05 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLBBd5kYNz58xk for ; Wed, 20 May 2026 22:47:05 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLBBd5gGhz58xl; Wed, 20 May 2026 22:47:05 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c0a:e001:db::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281225; cv=pass; b=HQDWkDsK0rKu1buLx7q1PKgQfrmCOJwSebQL3FwgxU0lh763vSt8BBQquS3hhw8SAbwUioUyWULwdVCQrEaOqD3Nvypq4yFjVaaY4Y4O3S9bG/O+aKtBoYMFcHn1rVAy1tS4UXlCYzJPOFvP81M0W1DW8G7ZZS/W9+nd5MIKvncuSIP9YzU8hryN3s6PTmUdcj6URc1zrXfCSWuFLJ0LvuY+Dn6Z5YOy22KNxfuYPewzo/7cjl/rt6k+N8kXb/+fwj4zVwCq4pxAkhjXV7pvvmup0w89aIucM7fWFZH1AgxbL2EYjng+YKKPtHiM8GJwCMLpeR+T6wByX0/bZTKsIQ== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281225; c=relaxed/relaxed; bh=Gmm/Ji1RHhaSPceVQfaTAAUkaYHkDKfuhVH2to82VPM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bZ1vjIAncTOUP/bgovCbI/uuhUAS65DuPHnSZriNqYZPzVVako5kMEzHKdlMdQ7A6InqPov2RMbZfTAtHcWAgaFjMqWYh2XVI+ShHfTTWt6bOjF16gFPAhCI1ZhGcTumJvSOBNkrObGfgmU4u/DnOM3Jt81AJp+QMu9/5S8z1qdKHvfYTPRN6uV+e2BvaVtitRf8a3P8aAuZ87JQ8DNJQ26NVe+69nQqfd6UE+Qyn4SBVPwZwuoSA1ojVngRUXV1o2wiPFY9qGvV5p8W+xg7KM3k4lniHKoxq3/clccjRvy98xwFe1gTgo5SDDB0fzJs+waoj5kCGM2V5+hWzSa3Ag== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=kpYxJYjR; dkim-atps=neutral; spf=pass (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16602-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=kpYxJYjR; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16602-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [IPv6:2600:3c0a:e001:db::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLBBZ3fPBz58xk for ; Wed, 20 May 2026 22:47:02 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id BAA173108186 for ; Wed, 20 May 2026 12:38:48 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 073AA3E7BDB; Wed, 20 May 2026 12:37:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="kpYxJYjR" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B4E343E63AC; Wed, 20 May 2026 12:37:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280676; cv=none; b=Fl0+y+QKBc+0Fi8cEg8ngm5kH9HH/1C9SRyCVMELxpwYRv1I/lGVsbHeElqwnZCibn5w0/W+nouNeYZvYr1Mfzdugok0N1lflkUwW9W0pXuQ3ll2w/Hqr3BUDT7AzgxbD/R5WpcPEqcWfRth9aHXCPjOy8yPTRwp21E40yFKU10= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280676; c=relaxed/simple; bh=Xwc/mSUOzY/SmBUARJA9roLn2GRyO6d/A0YYUkM7h/M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iHOmutB5AIGs+d8HHwhGqTfOIl1NaEN0bJcAXH3+7Pn7JlNihIvAA5V4UWCinlEH/rWT4W/ifngh+pMXhvPQBVAuTguvgxo+7xlHKMF3kk8Y/1eW/Wb/B2O5JqmrbprSXNpBhVMeK2yFEjc9njs3EyPstiCwwSA+oTOKW2lD/6Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=kpYxJYjR; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6C4341F000E9; Wed, 20 May 2026 12:37:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280675; bh=Gmm/Ji1RHhaSPceVQfaTAAUkaYHkDKfuhVH2to82VPM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kpYxJYjRk5/+MEaUS8enTXHARxLnY/AfiiHQ0jcV+X0auH56ze47nTKqVDX3eGBzl xHtK0JcZ1xuoC66vJWHOLfiZYk9DZNw4KdQXi6LfBSeg4mg4HEZ8lZ2ykZ4pv6292J 61ibHMo72HTxhQFOe4cLkqJpDNAhBWgPPDxz/Q3H2oRW2X4vALBflKXqBOfLpFfxnS cKOVIT3XrRcyZfAPsVa6coZY9mCDt9u1GmxCQGRNuojQn8khA617kseH2NtQoVLBvM bLUW9cruvYFz71WJ6PDtuJNIlivk1nApGr1a7tr4P3q1IMu7Lye46MFdr+XiOErIuy jKGc+8vuceQ0Q== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 11/22] xfs: initialize fs-verity on file open Date: Wed, 20 May 2026 14:37:09 +0200 Message-ID: <20260520123722.405752-12-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org fs-verity will read and attach metadata (not the tree itself) from a disk for those inodes which already have fs-verity enabled. Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_file.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/fs/xfs/xfs_file.c b/fs/xfs/xfs_file.c index 845a97c9b063..e3f4353b3b78 100644 --- a/fs/xfs/xfs_file.c +++ b/fs/xfs/xfs_file.c @@ -37,6 +37,7 @@ #include #include #include +#include static const struct vm_operations_struct xfs_file_vm_ops; @@ -1700,11 +1701,18 @@ xfs_file_open( struct inode *inode, struct file *file) { + int error; + if (xfs_is_shutdown(XFS_M(inode->i_sb))) return -EIO; file->f_mode |= FMODE_NOWAIT | FMODE_CAN_ODIRECT; if (xfs_get_atomic_write_min(XFS_I(inode)) > 0) file->f_mode |= FMODE_CAN_ATOMIC_WRITE; + + error = fsverity_file_open(inode, file); + if (error) + return error; + return generic_file_open(inode, file); } From patchwork Wed May 20 12:37:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241214 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=LRKXai55; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=8em3=dr=vger.kernel.org=linux-ext4+bounces-16603-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB7z1WB8z1xx8 for ; Wed, 20 May 2026 22:44:47 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB7z0zpGz59HC for ; Wed, 20 May 2026 22:44:47 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB7z0vS3z59HN; Wed, 20 May 2026 22:44:47 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c04:e001:36c::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281087; cv=pass; b=UK/FDGTxKgDNyT0jAG/v1vetvYFr6i0F9Ce4ODmdu4fyw4UKBU8nGBrq3RN9m2hyXJUfJbi8lFK9l0iuBQ3KXoAjyccSZl5PAhqyA9QtDLpNWFQBImYg4uUFZbxdwuG6HoF3xCNypNk6pihWXlp0ugEdK6mZFNqa1c8INaGsdj74EkB8p2qVlVE+NOibRKdwYZ21X1Bdyce6pU0QDs/3MuoXlB3BbmN8scE120xglzWjpXDTGPSAcpxbXBT9LXOM37B/viMnS1D5qnALpj3i0E31FG8nQnJsltlaqNEXQQ64O0af2ofHYVirmG7/D0Hu5UVQqZCViRcj5FS6U07vUA== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281087; c=relaxed/relaxed; bh=1DHHkbgWsldiFzDBohMOCibrE/jcCaw8Lz0td95bxyE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IlGeGB+tghQTiDw/LTdF+x2tiYDzO3ZZwLecDpWAiQKur63NXwcCkbwa+oTZBodRa+zMwUdaInnoM7phAvF1ZWvJZzJmacaJS5cT/XUGIk0tzTZiVCs6u5+/2MoFDXiETF3T9EJCVQXeu/KE5Dry14/iySiUMDbYnUfez9DhMD/VY+MONrjw1JN7ci6+orjsO1C0yFVpHSf9saMD/xKfYMTmIOhFaxgRI/wvnUmH+QYjMmg2xs+HF7a6Ahi98GaID8urZqijhDZAb4m2yZfN9HCiaGC19VV0IuZl9s8TS33qvm1wqhH/JhsboAGPLvT9n6xPvcTyFUJjBvKe+uHlzA== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=LRKXai55; dkim-atps=neutral; spf=pass (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16603-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=LRKXai55; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16603-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB7v5tYQz59HC for ; Wed, 20 May 2026 22:44:43 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 64B1B310B869 for ; Wed, 20 May 2026 12:38:53 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 6F6623E835E; Wed, 20 May 2026 12:38:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LRKXai55" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 308363E1D19; Wed, 20 May 2026 12:37:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280681; cv=none; b=FwwfMFw/ItAXxqDRlaQ5uo6sXmYMYPjeraPI1/2+SG5ozwbg4FOuVMqyO0IKh0sDod6WF/saD2v4WuQ7YccjxejJKblJP47GBempeXvtrSx1oUhg25O7ogDVeoFYjQFWxg76wGShQgJWTRQei4x9ZlF5edYhdj7xWA56vnnxnh8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280681; c=relaxed/simple; bh=hznJ9z3moGo3PQExhNYjGzN6OfHHvMeRYu21TBhj7yU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=cXX4vV4BKEvL4hLtir6QCueYDkVmITLiORHo07ChRziFuS+BxQZr0th+Qpfsh5/OOvE+neoznvRi+UP7htzWzluQtToSQAeg/IrK5oVcv674EljyK75TINIj4SeZ/JySGfijpxLwHnaVVr4v6NzL8NiMLHuS/FtSgJIZ2qUitvQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LRKXai55; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id D634E1F00893; Wed, 20 May 2026 12:37:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280677; bh=1DHHkbgWsldiFzDBohMOCibrE/jcCaw8Lz0td95bxyE=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=LRKXai55KPHdXoSF1SgA7EMzJPc1BMAysLhGwQrlta1BIkj+sNr0V/T7d8AHLsrOS bd1v9iOaxht824zX6/RpRumfLOXEWsWGhF5Zq9unP9PYgQ/J8AFrACzTsjsHcAT+9U vJz/s/N07ayoVpXlNL5B74+euEWv2XVNwU/kzV6ZX9ziPpevXA63WhOPYn+WctfBVV hNixN3HydHu+UjAfzFshayfr6qyDhJwhaFeq4JxukRFp+aE/fZ6xL1a6Wp+I9k7Ppc 2EVa2Js2BHy7/ofpIiFUM4m/LFoi+mvYitEGGJRDqljR4jLsvLjylsEm9TJLb3bc4z ANmdEb3mw8kvA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 12/22] xfs: don't allow to enable DAX on fs-verity sealed inode Date: Wed, 20 May 2026 14:37:10 +0200 Message-ID: <20260520123722.405752-13-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org fs-verity doesn't support DAX. Forbid filesystem to enable DAX on inodes which already have fs-verity enabled. The opposite is checked when fs-verity is enabled, it won't be enabled if DAX is. Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_iops.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/fs/xfs/xfs_iops.c b/fs/xfs/xfs_iops.c index 25c6e1d08cdc..99ce8bc12840 100644 --- a/fs/xfs/xfs_iops.c +++ b/fs/xfs/xfs_iops.c @@ -1370,6 +1370,8 @@ xfs_inode_should_enable_dax( return false; if (!xfs_inode_supports_dax(ip)) return false; + if (ip->i_diflags2 & XFS_DIFLAG2_VERITY) + return false; if (xfs_has_dax_always(ip->i_mount)) return true; if (ip->i_diflags2 & XFS_DIFLAG2_DAX) From patchwork Wed May 20 12:37:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241216 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SUkVW4Tz; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=fjid=dr=vger.kernel.org=linux-ext4+bounces-16604-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB8G4FMHz1xx8 for ; Wed, 20 May 2026 22:45:02 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB8G3lN1z59HC for ; Wed, 20 May 2026 22:45:02 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB8G3fftz59HN; Wed, 20 May 2026 22:45:02 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281102; cv=pass; b=ITIcz/6xaeki6gERTrBP20JqKKkal85tku1Y7OFPC4yooqnnmE7lwMYulgUL19V+iwR0o6EU8oOpKQOLppghmi1TUTlRK06mBYaUlZrsLvb5zm/EYtMwEVBr0kOwWGLeXoRtqUxcJ6LeppAZ6C/MRX1I1SKwAccz+APj4FxgMeG3KChVtQnDDXLM/qTP+HfEYAFTEo47AoUApWB+vci/+X6lHkMxgE1rHdUDGWXeYyKPURfk8J6Fpr5kDALG/0Bcqn7sXgzafhXIC2Gq4dvZno2gyAB1fo+AJexQ6C6l5qljxW4QVluPhKvCra7JllGvKjscvbp8X0feD/JDA7cdHw== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281102; c=relaxed/relaxed; bh=VpHBl5t/VGkWUCdWGO0BSnsIrLjhVZANk3wAFYMTAUk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lvP525hlYmmQml/0IZiHDNtnSEqfi25vbqbsoz+oSuImLUfo3sMmAtQ+1wcnzK5IZeyR2IBoRPYA54VN9Hgng0vuA0Lo3cMCxsiWpghtg4YnLIuHFWhLjlEiJtcCeCBWMA2TYEWCSEIvubqSgKuNlA4QETbNEoQzcxJWUolx6n1Ke51VkiSIOiToHREpZMYkyLO8lHgCdcuDzfcPoaW+G8rs4B/P0a4HhLLnT+7LqeZau/Of/xrR8/hmjeF3Lg4cwdeercouhw5fqeIvLPeTWGD1kOaVcVk9w999CoDSTJf9mXKa9myorJK/Wmk7wdgkwY0K/RD3eP3POF6/pxccxQ== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SUkVW4Tz; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16604-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=SUkVW4Tz; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16604-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB8C2TWHz59HC for ; Wed, 20 May 2026 22:44:59 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 10F19310EFB8 for ; Wed, 20 May 2026 12:38:56 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 1B2723E8C65; Wed, 20 May 2026 12:38:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="SUkVW4Tz" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA82A3E122D; Wed, 20 May 2026 12:38:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280682; cv=none; b=UHIzOngCox4Gtn6MVMIlWtbIK+agUUyGwO4m593G9nl6le4q6/NuA0ox20AvhBUmsiBP1nWIIq+uMoKWDxMlxsdsFsJdGT/N6oNAbehvitX/+jBmGWUab+M0BJqAaDf3wO1EsrRqHpIXTrO4JLRBBm+t9LjMfzKcVOt/UYvlMB4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280682; c=relaxed/simple; bh=J/crzavrYHIn1d+gW2ScGAtX27fA6aHmmfZp3AwtM2s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=u1rV6Ie+X/cVTTpGvdecXTIDVttUxuZX9LfLX8rRQ0HlWhjX4QeVC5S4onLmLbx99iSHBrwcZurV1BmGbbL+kl5NS5l+9hgG5Nxt9ysmcWkok4BCOx9p8piXIYTwx3Evg3KShrA2IW7Hph4SGgSKW+yhMMaFCgr06nmuldXEqDk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=SUkVW4Tz; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4F9231F000E9; Wed, 20 May 2026 12:37:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280680; bh=VpHBl5t/VGkWUCdWGO0BSnsIrLjhVZANk3wAFYMTAUk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=SUkVW4TzrSEHkRKhjpwkCgR9+l7/kyskC1KL6846qbfM5dI1NpUKyXYjjZjcqsQVD 8wyQdH5upJ/CZv4xWRgb2OcF67ZOEKLKY6IKYd9xGdEz/cu938mc3Qw0iK17zwVqzU f+7uNr/AoOAhj/w6se+oX1k8znWlL68hh7RqDE3fMadk/dIjA/IDqxNa+fF/34ynnr zau2L6KrFmv9PXq3pa2ylVDzBQiFetIWoXypeH98AZ0b1ck5THLICjCgQck5mv+Adf LbSd8kikdQ38sKIAYaQpCEAzL7BYISOaN6BPNRZfwu3F3NEbrjYPhG7cViKtKDpVU8 tsfB2JnRy2JTg== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 13/22] xfs: disable direct read path for fs-verity files Date: Wed, 20 May 2026 14:37:11 +0200 Message-ID: <20260520123722.405752-14-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org The direct path is not supported on verity files. Attempts to use direct I/O path on such files should fall back to buffered I/O path. Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_file.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/fs/xfs/xfs_file.c b/fs/xfs/xfs_file.c index e3f4353b3b78..2ef946e3f46f 100644 --- a/fs/xfs/xfs_file.c +++ b/fs/xfs/xfs_file.c @@ -282,7 +282,8 @@ xfs_file_dax_read( struct kiocb *iocb, struct iov_iter *to) { - struct xfs_inode *ip = XFS_I(iocb->ki_filp->f_mapping->host); + struct inode *inode = iocb->ki_filp->f_mapping->host; + struct xfs_inode *ip = XFS_I(inode); ssize_t ret = 0; trace_xfs_file_dax_read(iocb, to); @@ -333,6 +334,14 @@ xfs_file_read_iter( if (xfs_is_shutdown(mp)) return -EIO; + /* + * In case fs-verity is enabled, we also fallback to the buffered read + * from the direct read path. Therefore, IOCB_DIRECT is set and need to + * be cleared (see generic_file_read_iter()) + */ + if (fsverity_active(inode)) + iocb->ki_flags &= ~IOCB_DIRECT; + if (IS_DAX(inode)) ret = xfs_file_dax_read(iocb, to); else if (iocb->ki_flags & IOCB_DIRECT) From patchwork Wed May 20 12:37:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241215 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=ogzDGkZ1; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=bal8=dr=vger.kernel.org=linux-ext4+bounces-16605-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB8970Jrz1xx8 for ; Wed, 20 May 2026 22:44:57 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB896R5Wz59HC for ; Wed, 20 May 2026 22:44:57 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB896MTWz59HN; Wed, 20 May 2026 22:44:57 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.234.253.10 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281097; cv=pass; b=GW7b0gtGbaFeulqBVDd+RI2x8roVjiz80avf8KKJjtAfoKGcJQf73qcLdv3dEUW2s/Y3pQUdhC7qg8hz821mtgBs8Jy/imefdUoiFRV0KwS+tA7LObZWVo6SGZyrSJf/X9NOU0hPu7o7H/BVe/GRhydLsZ3yTNU73DOdyXcNO2wPJgLjThCZ+oaURab3IsdWthuIHaXrQ3W7Ydn8WkvqPjWw7ZAdOaNXhWY0iPoXQZl2kDGv5Ke2zwCVFJHFuD32UJiKltF2WxwaFEMa8RIRvrgcbr0AJ3GBhseJGYK1xDIpromoF9ovp2k7GyEtPsszd036scNH4Hul10SO3JavgQ== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281097; c=relaxed/relaxed; bh=Q/8QKW6zbsRwWhwGEi9ElfQBNCcTTA5pNjJ71ec5bYA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Q+dwammeWv9qnxqco4LfcXmaAdouBZWT4zZ08IL+/JRbyAPj8VZZn3JhO9em8GDCYOF3deV3rBFWjrv0CQQJg9szD/0NoOA6hozjkABUN5BtUPDPXm3igbzHBAtK1uWZ1qkEQaUPCHjYzukw6HVCAUiy0cHZWxVZYxtJy4MOV23NwWgesxgj2PdTKxqCmQePwTo3A7W4OyJpsgxZgL+iZXNxP/O0vIbH8MRK2O8kE2i/+o8kQTNz9HbvDcqIDYOcE6qqaJn5mSp6UE1qCf8jjSYOZoqMH9J8yi7hW7A21pcL+KwjPPfU5Sy2Kp4b0BqpqvnEtmwNHLEuaDWU+I60mw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=ogzDGkZ1; dkim-atps=neutral; spf=pass (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16605-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=ogzDGkZ1; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16605-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB865RZwz59HC for ; Wed, 20 May 2026 22:44:54 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 74549311D0B8 for ; Wed, 20 May 2026 12:39:01 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 155A33E9584; Wed, 20 May 2026 12:38:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ogzDGkZ1" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C08963E9299; Wed, 20 May 2026 12:38:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280686; cv=none; b=fGSYN/4QH2dow2QMkKQcE8xcOZz0y2tFJKbR99O+248+9LSYPKTALc7OeBEKCqBdipxqsM2+JYCBMGFliPnYOTiNf11L34QsTqCkP5CP9KtsArBeDkeyeP00VlzGLhPtVWrze63ZFN6KQDmcu1QgBIdAJRN4OFfE/c58s8JXPw0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280686; c=relaxed/simple; bh=zAqS1f07EiIaQcCO0AZp7/t41XaPwR0USrgvgTZdPno=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EWSq0D3FxyXp5EB9SXnX/8bDzBq9fvUHkVjw8MVU626VaqyMXQW3fWd1qtUV9RYIEj0Bz8uCJOsxd9U6dGgwm2QSFnPWKbhX7iD9Ohw1Q9jBnWkA2PpB2UGUTfjDWKg1bvaRSwPeLx74YSV9IkGToRf/Ekl2GW2JwdvGV3eq5tE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ogzDGkZ1; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id BEA291F00894; Wed, 20 May 2026 12:38:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280682; bh=Q/8QKW6zbsRwWhwGEi9ElfQBNCcTTA5pNjJ71ec5bYA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ogzDGkZ1Qw/3a25UIh/Kxuvj2HoazOwG5fJKaTewVNJXZw8EWDY19v7DuMBhZ4AAa BNEK+TLpLtDGj1+v5d/hK2ASeQnzAnUF9BGhLCCzZCgmExXUZzOihgWLdaQ/vN2f6p m0MZ71Dll2PPKf+vaH2ugcsI5yO+mZHi4Bmz2hcWkwpW6DCDa3UGapb3gApamk/c7V nSP+P7bbyps+SBziaiW/nq6sloaR1lbL5wntH/IaecxudHtQiqXloJ/Q5Z+UIrL1Hu UBh2wbgA1vu60c8/M5vZH28u7l0sGnFW3KUCHCAiM/5APQ8C28A2x6pXH3d2I1im0n V/d/tmNvXqlfQ== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 14/22] xfs: handle fsverity I/O in write/read path Date: Wed, 20 May 2026 14:37:12 +0200 Message-ID: <20260520123722.405752-15-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org For write/writeback set IOMAP_F_FSVERITY flag telling iomap to not update inode size and to not skip folios beyond EOF. Initiate fsverity writeback with IOMAP_F_FSVERITY set to tell iomap should not skip folio that is dirty beyond EOF. In read path let iomap know that we are reading fsverity metadata. So, treat holes in the tree as request to synthesize tree blocks and hole after descriptor as end of the fsverity region. Introduce a new inode flag meaning that merkle tree is being build on the inode. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/Makefile | 1 + fs/xfs/libxfs/xfs_bmap.c | 7 +++++++ fs/xfs/xfs_aops.c | 16 +++++++++++++++- fs/xfs/xfs_fsverity.c | 21 +++++++++++++++++++++ fs/xfs/xfs_fsverity.h | 20 ++++++++++++++++++++ fs/xfs/xfs_inode.h | 6 ++++++ fs/xfs/xfs_iomap.c | 15 +++++++++++++-- 7 files changed, 83 insertions(+), 3 deletions(-) create mode 100644 fs/xfs/xfs_fsverity.c create mode 100644 fs/xfs/xfs_fsverity.h diff --git a/fs/xfs/Makefile b/fs/xfs/Makefile index 9f7133e02576..38b7f51e5d84 100644 --- a/fs/xfs/Makefile +++ b/fs/xfs/Makefile @@ -149,6 +149,7 @@ xfs-$(CONFIG_XFS_POSIX_ACL) += xfs_acl.o xfs-$(CONFIG_SYSCTL) += xfs_sysctl.o xfs-$(CONFIG_COMPAT) += xfs_ioctl32.o xfs-$(CONFIG_EXPORTFS_BLOCK_OPS) += xfs_pnfs.o +xfs-$(CONFIG_FS_VERITY) += xfs_fsverity.o # notify failure ifeq ($(CONFIG_MEMORY_FAILURE),y) diff --git a/fs/xfs/libxfs/xfs_bmap.c b/fs/xfs/libxfs/xfs_bmap.c index 7a4c8f1aa76c..931d02678d19 100644 --- a/fs/xfs/libxfs/xfs_bmap.c +++ b/fs/xfs/libxfs/xfs_bmap.c @@ -41,6 +41,8 @@ #include "xfs_inode_util.h" #include "xfs_rtgroup.h" #include "xfs_zone_alloc.h" +#include "xfs_fsverity.h" +#include struct kmem_cache *xfs_bmap_intent_cache; @@ -4451,6 +4453,11 @@ xfs_bmapi_convert_one_delalloc( XFS_STATS_ADD(mp, xs_xstrat_bytes, XFS_FSB_TO_B(mp, bma.length)); XFS_STATS_INC(mp, xs_xstrat_quick); + if (xfs_iflags_test(ip, XFS_VERITY_CONSTRUCTION) && + XFS_FSB_TO_B(mp, bma.got.br_startoff) >= + xfs_fsverity_metadata_offset(ip)) + flags |= IOMAP_F_FSVERITY; + ASSERT(!isnullstartblock(bma.got.br_startblock)); xfs_bmbt_to_iomap(ip, iomap, &bma.got, 0, flags, xfs_iomap_inode_sequence(ip, flags)); diff --git a/fs/xfs/xfs_aops.c b/fs/xfs/xfs_aops.c index f279055fcea0..9503252a0fa4 100644 --- a/fs/xfs/xfs_aops.c +++ b/fs/xfs/xfs_aops.c @@ -22,6 +22,7 @@ #include "xfs_icache.h" #include "xfs_zone_alloc.h" #include "xfs_rtgroup.h" +#include "xfs_fsverity.h" #include struct xfs_writepage_ctx { @@ -339,12 +340,16 @@ xfs_map_blocks( int retries = 0; int error = 0; unsigned int *seq; + unsigned int iomap_flags = 0; if (xfs_is_shutdown(mp)) return -EIO; XFS_ERRORTAG_DELAY(mp, XFS_ERRTAG_WB_DELAY_MS); + if (xfs_iflags_test(ip, XFS_VERITY_CONSTRUCTION)) + iomap_flags |= IOMAP_F_FSVERITY; + /* * COW fork blocks can overlap data fork blocks even if the blocks * aren't shared. COW I/O always takes precedent, so we must always @@ -432,7 +437,8 @@ xfs_map_blocks( isnullstartblock(imap.br_startblock)) goto allocate_blocks; - xfs_bmbt_to_iomap(ip, &wpc->iomap, &imap, 0, 0, XFS_WPC(wpc)->data_seq); + xfs_bmbt_to_iomap(ip, &wpc->iomap, &imap, 0, iomap_flags, + XFS_WPC(wpc)->data_seq); trace_xfs_map_blocks_found(ip, offset, count, whichfork, &imap); return 0; allocate_blocks: @@ -705,6 +711,14 @@ xfs_vm_writepages( }, }; + /* + * Writeback does not work for folios past EOF, let it know that + * I/O happens for fsverity metadata and this restriction need + * to be skipped + */ + if (xfs_iflags_test(ip, XFS_VERITY_CONSTRUCTION)) + wpc.ctx.iomap.flags |= IOMAP_F_FSVERITY; + return iomap_writepages(&wpc.ctx); } } diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c new file mode 100644 index 000000000000..6e6a8636a577 --- /dev/null +++ b/fs/xfs/xfs_fsverity.c @@ -0,0 +1,21 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +/* + * Copyright (C) 2026 Red Hat, Inc. + */ +#include "xfs_platform.h" +#include "xfs_format.h" +#include "xfs_inode.h" +#include "xfs_shared.h" +#include "xfs_trans_resv.h" +#include "xfs_mount.h" +#include "xfs_fsverity.h" +#include "xfs_fsverity.h" +#include +#include + +loff_t +xfs_fsverity_metadata_offset( + const struct xfs_inode *ip) +{ + return round_up(i_size_read(VFS_IC(ip)), XFS_FSVERITY_START_ALIGN); +} diff --git a/fs/xfs/xfs_fsverity.h b/fs/xfs/xfs_fsverity.h new file mode 100644 index 000000000000..5771db2cd797 --- /dev/null +++ b/fs/xfs/xfs_fsverity.h @@ -0,0 +1,20 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +/* + * Copyright (C) 2026 Red Hat, Inc. + */ +#ifndef __XFS_FSVERITY_H__ +#define __XFS_FSVERITY_H__ + +#include "xfs_platform.h" + +#ifdef CONFIG_FS_VERITY +loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip); +#else +static inline loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip) +{ + WARN_ON_ONCE(1); + return ULLONG_MAX; +} +#endif /* CONFIG_FS_VERITY */ + +#endif /* __XFS_FSVERITY_H__ */ diff --git a/fs/xfs/xfs_inode.h b/fs/xfs/xfs_inode.h index bd6d33557194..6df48d68a919 100644 --- a/fs/xfs/xfs_inode.h +++ b/fs/xfs/xfs_inode.h @@ -415,6 +415,12 @@ static inline bool xfs_inode_can_sw_atomic_write(const struct xfs_inode *ip) */ #define XFS_IREMAPPING (1U << 15) +/* + * fs-verity's Merkle tree is under construction. The file is read-only, the + * only writes happening are for the fsverity metadata. + */ +#define XFS_VERITY_CONSTRUCTION (1U << 16) + /* All inode state flags related to inode reclaim. */ #define XFS_ALL_IRECLAIM_FLAGS (XFS_IRECLAIMABLE | \ XFS_IRECLAIM | \ diff --git a/fs/xfs/xfs_iomap.c b/fs/xfs/xfs_iomap.c index f20a02f49ed9..2af2bc47b9b3 100644 --- a/fs/xfs/xfs_iomap.c +++ b/fs/xfs/xfs_iomap.c @@ -32,6 +32,8 @@ #include "xfs_rtbitmap.h" #include "xfs_icache.h" #include "xfs_zone_alloc.h" +#include "xfs_fsverity.h" +#include #define XFS_ALLOC_ALIGN(mp, off) \ (((off) >> mp->m_allocsize_log) << mp->m_allocsize_log) @@ -1812,6 +1814,9 @@ xfs_buffered_write_iomap_begin( return xfs_direct_write_iomap_begin(inode, offset, count, flags, iomap, srcmap); + if (xfs_iflags_test(ip, XFS_VERITY_CONSTRUCTION)) + iomap_flags |= IOMAP_F_FSVERITY; + error = xfs_qm_dqattach(ip); if (error) return error; @@ -2191,12 +2196,17 @@ xfs_read_iomap_begin( bool shared = false; unsigned int lockmode = XFS_ILOCK_SHARED; u64 seq; + unsigned int iomap_flags = 0; ASSERT(!(flags & (IOMAP_WRITE | IOMAP_ZERO))); if (xfs_is_shutdown(mp)) return -EIO; + if (fsverity_active(inode) && + (offset >= xfs_fsverity_metadata_offset(ip))) + iomap_flags |= IOMAP_F_FSVERITY; + error = xfs_ilock_for_iomap(ip, flags, &lockmode); if (error) return error; @@ -2210,8 +2220,9 @@ xfs_read_iomap_begin( if (error) return error; trace_xfs_iomap_found(ip, offset, length, XFS_DATA_FORK, &imap); - return xfs_bmbt_to_iomap(ip, iomap, &imap, flags, - shared ? IOMAP_F_SHARED : 0, seq); + iomap_flags |= shared ? IOMAP_F_SHARED : 0; + + return xfs_bmbt_to_iomap(ip, iomap, &imap, flags, iomap_flags, seq); } const struct iomap_ops xfs_read_iomap_ops = { From patchwork Wed May 20 12:37:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241219 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=GOO5CU6Z; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=p23m=dr=vger.kernel.org=linux-ext4+bounces-16606-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB9S25Ctz1xx5 for ; Wed, 20 May 2026 22:46:04 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB9S1dkYz59HP for ; Wed, 20 May 2026 22:46:04 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB9S1YfQz59HR; Wed, 20 May 2026 22:46:04 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c04:e001:36c::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281164; cv=pass; b=FYmqX4rA5jA31uYxj0K1NfBtXTRKNTpK+4WuPUk/FsD8/v/yyWDRECU8FhsGwkNsAVGqbbHxnNN3VVjC2vqaCGKtA6Xu1buLTQz5nWKJDNWwqWTbcP75DmFfGpDBiWiZnM3nu0+ztP8l6B5JCTlLm5/CNskvSH/FX29hr8NHP31V3i77Iv3HQwKsr+7EaeHCsEoeXEJsUJLgmLmRD6CK2H/RRqblLtqIp34qFBGgIeLKOXlAPRpz/ntv7zJkm2JGdzqmjG3gAzwD1N3/Ststf+Y4VPYLNqRTp+zqRCmgKPHj5CzTpXNbZidA1dzvpqb5tHVthAW5Ina8hRR9RD/KRA== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281164; c=relaxed/relaxed; bh=lWM0vfhRoQN3XUnUh/hfhcB8qeHDbNjCnEWLhHQ7Rno=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fGxPK8Doo0IXXhUbzwhbcJTDCC04sNbrvd5fSfkXDqDzaw5TqQRtgRsxdIEBQdw8PzAY/ixVdEIIZGgDNi/ll2SHLoynmO8AqZ8dhz9Ll929IenFDl8HIwZbOyp2RcCldmKfI8KHL9FwPOGU8Knxu22nh7QFJV/W9/TQQ3WNC28ro736yY7zUiSjaHWgmBxqzpZk77kXLKVoAjPOqdVpshXysCP1iNasjSnIqNOpdZVk16s8ifufZINFBUa/ZMq5sMZ7bORkjA0OlL0iWVNnlEz8Mnp7+mT1z+GJTeysXhkz4zn7DTdDqYKwWQs23d76l2Pd4LA+Mbwf6DLio88Gpg== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=GOO5CU6Z; dkim-atps=neutral; spf=pass (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16606-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=GOO5CU6Z; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c04:e001:36c::12fc:5321; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16606-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [IPv6:2600:3c04:e001:36c::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB9P03j1z59HP for ; Wed, 20 May 2026 22:46:00 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id C64A9311E8B4 for ; Wed, 20 May 2026 12:39:06 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 3B1B43E9C0D; Wed, 20 May 2026 12:38:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="GOO5CU6Z" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0CCF43DB996; Wed, 20 May 2026 12:38:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280688; cv=none; b=K8ozxm8d19CH4w6du5rfeaboylrIRCAoj6oiI3deHqkl1c8O4cQ26Rg7gWu/o/Y5/KFNYvSae8x1bq7AVWWra20VOUmM9JlwDBvV8h3ERJbSH9oj3jpnhO1UXpUOamfUjdrU+pdxqVaAZigI/GX6X/GFW3hGKPsyfXXCvk79J2M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280688; c=relaxed/simple; bh=+IPCnfTbYJgst2p5FA7yf8LN40/02HKXVjwkca7X0i4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tFVLPs75luntueXOwkAYbl6OEmtrITM2fTeTOd7flS0DSZLmtucOq3eiKdc75YEo0DGyjZ5NA8/qIqxBzM4CEMrhQD4S4HwcTYJO5Q7E48ikfdZGy+pamk4Pb0DlJqb8Hb+LRbh7ZefrvJZKaWpjCg6NHglZQdS4RwIr/15+t3E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=GOO5CU6Z; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3551C1F000E9; Wed, 20 May 2026 12:38:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280685; bh=lWM0vfhRoQN3XUnUh/hfhcB8qeHDbNjCnEWLhHQ7Rno=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GOO5CU6ZZYsrx3o+aIx6YU5bNx/DFo6UipebOopXUMaUod+t8y2vPzojIbu6CZq9D DruozvEeG5AayVwkmruK6ov9jZnp51gHNphrsz5lO1wWU3qOsn+fF5FI7dA48WlmkG diYZTuRsBjstrjdK+DctozXCXEhfjm71NeNc9/bGoGPDJM8jm0oMpyI9PfeOgxtMsv bpIiWyVu99ZT8RDzvdtPnTMlSzbV7cU845Jf9nTLkikiansR71AabeS6qSvfG+7ncZ 2M/mSmMwDSxe4tfUECzIylSJYuPWo0iaN42jwO3LuYfcjPTJd+3c+3lt3SHwYtYb/e UCXmG9lG/OpdA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 15/22] xfs: use read ioend for fsverity data verification Date: Wed, 20 May 2026 14:37:13 +0200 Message-ID: <20260520123722.405752-16-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Use read ioends for fsverity verification. Do not issues fsverity metadata I/O through the same workqueue due to risk of a deadlock by a filled workqueue. Pass fsverity_info from iomap context down to the ioend as hashtable lookups are expensive. Add a simple helper to check that this is not fsverity metadata but file data that needs verification. Reviewed-by: Christoph Hellwig Reviewed-by: Darrick J. Wong Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_aops.c | 46 ++++++++++++++++++++++++++++++++++--------- fs/xfs/xfs_fsverity.c | 9 +++++++++ fs/xfs/xfs_fsverity.h | 6 ++++++ 3 files changed, 52 insertions(+), 9 deletions(-) diff --git a/fs/xfs/xfs_aops.c b/fs/xfs/xfs_aops.c index 9503252a0fa4..ecb07f250956 100644 --- a/fs/xfs/xfs_aops.c +++ b/fs/xfs/xfs_aops.c @@ -24,6 +24,7 @@ #include "xfs_rtgroup.h" #include "xfs_fsverity.h" #include +#include struct xfs_writepage_ctx { struct iomap_writepage_ctx ctx; @@ -171,6 +172,23 @@ xfs_end_ioend_write( memalloc_nofs_restore(nofs_flag); } +/* + * IO read completion. + */ +static void +xfs_end_ioend_read( + struct iomap_ioend *ioend) +{ + struct xfs_inode *ip = XFS_I(ioend->io_inode); + + if (!ioend->io_bio.bi_status && + xfs_fsverity_is_file_data(ip, ioend->io_offset)) + fsverity_verify_bio(ioend->io_vi, + &ioend->io_bio); + iomap_finish_ioends(ioend, + blk_status_to_errno(ioend->io_bio.bi_status)); +} + /* * Finish all pending IO completions that require transactional modifications. * @@ -205,8 +223,7 @@ xfs_end_io( list_del_init(&ioend->io_list); iomap_ioend_try_merge(ioend, &tmp); if (bio_op(&ioend->io_bio) == REQ_OP_READ) - iomap_finish_ioends(ioend, - blk_status_to_errno(ioend->io_bio.bi_status)); + xfs_end_ioend_read(ioend); else xfs_end_ioend_write(ioend); cond_resched(); @@ -232,9 +249,14 @@ xfs_end_bio( } spin_lock_irqsave(&ip->i_ioend_lock, flags); - if (list_empty(&ip->i_ioend_list)) - WARN_ON_ONCE(!queue_work(mp->m_unwritten_workqueue, + if (list_empty(&ip->i_ioend_list)) { + if (IS_ENABLED(CONFIG_FS_VERITY) && ioend->io_vi && + ioend->io_offset < xfs_fsverity_metadata_offset(ip)) + fsverity_enqueue_verify_work(&ip->i_ioend_work); + else + WARN_ON_ONCE(!queue_work(mp->m_unwritten_workqueue, &ip->i_ioend_work)); + } list_add_tail(&ioend->io_list, &ip->i_ioend_list); spin_unlock_irqrestore(&ip->i_ioend_lock, flags); } @@ -764,9 +786,13 @@ xfs_bio_submit_read( struct iomap_read_folio_ctx *ctx) { struct bio *bio = ctx->read_ctx; + struct iomap_ioend *ioend; /* defer read completions to the ioend workqueue */ - iomap_init_ioend(iter->inode, bio, ctx->read_ctx_file_offset, 0); + ioend = iomap_init_ioend(iter->inode, bio, ctx->read_ctx_file_offset, + 0); + ioend->io_vi = ctx->vi; + bio->bi_end_io = xfs_end_bio; submit_bio(bio); } @@ -779,11 +805,13 @@ static const struct iomap_read_ops xfs_iomap_read_ops = { static inline const struct iomap_read_ops * xfs_get_iomap_read_ops( - const struct address_space *mapping) + const struct address_space *mapping, + loff_t position) { struct xfs_inode *ip = XFS_I(mapping->host); - if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev)) + if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev) || + xfs_fsverity_is_file_data(ip, position)) return &xfs_iomap_read_ops; return &iomap_bio_read_ops; } @@ -795,7 +823,7 @@ xfs_vm_read_folio( { struct iomap_read_folio_ctx ctx = { .cur_folio = folio }; - ctx.ops = xfs_get_iomap_read_ops(folio->mapping); + ctx.ops = xfs_get_iomap_read_ops(folio->mapping, folio_pos(folio)); iomap_read_folio(&xfs_read_iomap_ops, &ctx, NULL); return 0; } @@ -806,7 +834,7 @@ xfs_vm_readahead( { struct iomap_read_folio_ctx ctx = { .rac = rac }; - ctx.ops = xfs_get_iomap_read_ops(rac->mapping), + ctx.ops = xfs_get_iomap_read_ops(rac->mapping, readahead_pos(rac)); iomap_readahead(&xfs_read_iomap_ops, &ctx, NULL); } diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c index 6e6a8636a577..b983e20bb5e1 100644 --- a/fs/xfs/xfs_fsverity.c +++ b/fs/xfs/xfs_fsverity.c @@ -19,3 +19,12 @@ xfs_fsverity_metadata_offset( { return round_up(i_size_read(VFS_IC(ip)), XFS_FSVERITY_START_ALIGN); } + +bool +xfs_fsverity_is_file_data( + const struct xfs_inode *ip, + loff_t offset) +{ + return fsverity_active(VFS_IC(ip)) && + offset < xfs_fsverity_metadata_offset(ip); +} diff --git a/fs/xfs/xfs_fsverity.h b/fs/xfs/xfs_fsverity.h index 5771db2cd797..ec77ba571106 100644 --- a/fs/xfs/xfs_fsverity.h +++ b/fs/xfs/xfs_fsverity.h @@ -9,12 +9,18 @@ #ifdef CONFIG_FS_VERITY loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip); +bool xfs_fsverity_is_file_data(const struct xfs_inode *ip, loff_t offset); #else static inline loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip) { WARN_ON_ONCE(1); return ULLONG_MAX; } +static inline bool xfs_fsverity_is_file_data(const struct xfs_inode *ip, + loff_t offset) +{ + return false; +} #endif /* CONFIG_FS_VERITY */ #endif /* __XFS_FSVERITY_H__ */ From patchwork Wed May 20 12:37:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241207 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=gyyO+5hO; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=nj6z=dr=vger.kernel.org=linux-ext4+bounces-16607-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB4S61Kbz1xx8 for ; Wed, 20 May 2026 22:41:44 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB4S5Y60z5977 for ; Wed, 20 May 2026 22:41:44 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB4S5RHvz59HC; Wed, 20 May 2026 22:41:44 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c09:e001:a7::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280904; cv=pass; b=ulWun4OOOXvpROfkBdmBU/CSmmNPduVb/J7il/wBV8AV2bax24qZc5vRggBCguupWBr2O6dyMZKNguk5fNjTx76va9W0ClbgM0MUiYQaYS5o5QwAfRAZFTMK4ub7YXKipRtfExPw/PT2ejX333tV9Ifb70dVyDRLPptuYY1GT643a6P51yhQNNscVfbQFk6smT4Mg589zHalYp1oEi52cTjXliTWM4RDCMWYQCSAL4ilDxBaKgDzqE/g6/pAEmpTY87YaXgy0GMt2zP283UkOni6qieGobzf8Y9TPx8RsVwzE3kH0+sYdTqwmObuyq0doKH7EG82eHvvMR9b/1O4eg== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280904; c=relaxed/relaxed; bh=Cu7KD3OaNV8WAOc9SGCZOWDkwM/cVKIApCYrNi+Lwtc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qz81KCwcyqzpbHTLKqqE/Xkg/vFRRAHrevhZCiF1HTdS0gfGbEpE5bbdbCIejG7Cs+dxOu0IFJRoh0noRFNM7r/6Eh+XkmQz/uYBHxO8SFBDjO/sJW0ZRbWfwYvRI1e1hPJjvLAxYWYVqa9MyBkmlXKN83doHdGspTxOVNYlDbXAG5BRafWops2E6bCWrZrpT+niQTGF86CEWwNpvqcpCsOH+qdGvvKnMJDDuKr4VPZcxKpL+nC4STf89o5+IHs1Mq8tcXeAbAuwdyRjUm9wyxyGVhsEJaCDOCU5pbFROMczLJ81Yxa0xXQgbOheQU2rIoNoMCNnAmEsCpUkhbZaEA== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=gyyO+5hO; dkim-atps=neutral; spf=pass (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16607-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=gyyO+5hO; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16607-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [IPv6:2600:3c09:e001:a7::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB4P2nZzz5977 for ; Wed, 20 May 2026 22:41:41 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 819D530623DA for ; Wed, 20 May 2026 12:39:13 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 84BF13E9C31; Wed, 20 May 2026 12:38:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="gyyO+5hO" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AE5D93E274B; Wed, 20 May 2026 12:38:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280691; cv=none; b=Ekj732qDqhEyC4/adKpzmXyEfwVZuaD2esQWOx/rHoi6OIJ+j8Mg519YrLzWICjZchsXyfB/3KbxHld/i6r9cL7RywltpqaQdMUSTKLmw+1aKHT/GnE2EhEZdL7eGj2UsB3lT7BmwBi907jOP3/s/yncLtSwjAM9khJK3zF9Pp8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280691; c=relaxed/simple; bh=0ar10N6epoobI9/LzOpX/nG/Lb0UGwvgN0Q4WGsujw4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VBeCAo/yZJTe6wLJ+/7+zvpxQdqyNNRzExJaHXUDMF/D5EiEbS/OTvEuv3Lk0qIgtcFh1qpOq7g6TcHjdUVCnahCpYiw8zq922YCiudv/akDrASvpudBGOHnaE6Xym9xLxBXc2NjVgZeR0kiOcjxNHoiWZ6dZ/r5Jm6E5D4oy70= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=gyyO+5hO; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id A08AA1F00893; Wed, 20 May 2026 12:38:05 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280687; bh=Cu7KD3OaNV8WAOc9SGCZOWDkwM/cVKIApCYrNi+Lwtc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=gyyO+5hOCw8CCM35leNzlE8MmzCkTOFO4abU+veC5jVYUrZV9IwmtRzRLt8cMHdlR i6TnbdvCrwfAKJ+/L5bgX8XJ6PPrK8bur8wsy+38oa1tVNfW6WFiJvEXXMNjaRDG0o ITmK4J//vi2cG8otzhJUnv2VXxVsRXQTWOAwIxSZ1avXLKGfRQGkalG3C0arfqLwSp ZyRsEuAvSXCPFwlebRYiJHJ6aFx4HJ7Lsyk9YAoH7707S3k0i0Q6ZCGvkLLcdph+n7 NvBd8p6dI0jqoJ6r/pIInS71gOuqZNWlc6qtPB42nIcAMlnzdJilnAoCM/hNF66P5H JzWLKWg4ngqSQ== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 16/22] xfs: add fs-verity support Date: Wed, 20 May 2026 14:37:14 +0200 Message-ID: <20260520123722.405752-17-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Add integration with fs-verity. XFS stores fs-verity descriptor and Merkle tree in the inode data fork at first block aligned to 64k past EOF. The Merkle tree reading/writing is done through iomap interface. The data itself is read to the inode's page cache. When XFS reads from this region iomap doesn't call into fsverity to verify it against Merkle tree. For data, verification is done at ioend completion in a workqueue. When fs-verity is enabled on an inode, the XFS_IVERITY_CONSTRUCTION flag is set meaning that the Merkle tree is being build. The initialization ends with storing of verity descriptor and setting inode on-disk flag (XFS_DIFLAG2_VERITY). Lastly, the XFS_IVERITY_CONSTRUCTION is dropped and I_VERITY is set on inode. The descriptor is stored in a new block aligned to 64k after the last Merkle tree block. The size of the descriptor is stored at the end of the last descriptor block (descriptor can be multiple blocks). Reviewed-by: Christoph Hellwig Reviewed-by: Darrick J. Wong Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_bmap_util.c | 8 + fs/xfs/xfs_fsverity.c | 353 ++++++++++++++++++++++++++++++++++++++++- fs/xfs/xfs_fsverity.h | 2 + fs/xfs/xfs_message.c | 4 + fs/xfs/xfs_message.h | 1 + fs/xfs/xfs_mount.h | 2 + fs/xfs/xfs_super.c | 7 + 7 files changed, 376 insertions(+), 1 deletion(-) diff --git a/fs/xfs/xfs_bmap_util.c b/fs/xfs/xfs_bmap_util.c index 0ab00615f1ad..18348f4fd2aa 100644 --- a/fs/xfs/xfs_bmap_util.c +++ b/fs/xfs/xfs_bmap_util.c @@ -31,6 +31,7 @@ #include "xfs_rtbitmap.h" #include "xfs_rtgroup.h" #include "xfs_zone_alloc.h" +#include /* Kernel only BMAP related definitions and functions */ @@ -553,6 +554,13 @@ xfs_can_free_eofblocks( if (last_fsb <= end_fsb) return false; + /* + * Nothing to clean on fsverity inodes as they don't use prealloc and + * there no delalloc as only written data is fsverity metadata + */ + if (IS_VERITY(VFS_I(ip))) + return false; + /* * Check if there is an post-EOF extent to free. If there are any * delalloc blocks attached to the inode (data fork delalloc diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c index b983e20bb5e1..a06885291412 100644 --- a/fs/xfs/xfs_fsverity.c +++ b/fs/xfs/xfs_fsverity.c @@ -4,14 +4,26 @@ */ #include "xfs_platform.h" #include "xfs_format.h" -#include "xfs_inode.h" #include "xfs_shared.h" #include "xfs_trans_resv.h" #include "xfs_mount.h" #include "xfs_fsverity.h" +#include "xfs_da_format.h" +#include "xfs_da_btree.h" +#include "xfs_inode.h" +#include "xfs_log_format.h" +#include "xfs_bmap_util.h" +#include "xfs_log_format.h" +#include "xfs_trans.h" +#include "xfs_trace.h" +#include "xfs_quota.h" #include "xfs_fsverity.h" +#include "xfs_iomap.h" +#include "xfs_error.h" +#include "xfs_health.h" #include #include +#include loff_t xfs_fsverity_metadata_offset( @@ -28,3 +40,342 @@ xfs_fsverity_is_file_data( return fsverity_active(VFS_IC(ip)) && offset < xfs_fsverity_metadata_offset(ip); } + +/* + * Retrieve the verity descriptor. + */ +static int +xfs_fsverity_get_descriptor( + struct inode *inode, + void *buf, + size_t buf_size) +{ + struct xfs_inode *ip = XFS_I(inode); + struct xfs_mount *mp = ip->i_mount; + __be32 d_desc_size; + u32 desc_size; + u64 desc_size_pos; + int error; + u64 desc_pos; + struct xfs_bmbt_irec rec; + int is_empty; + uint32_t blocksize = i_blocksize(VFS_I(ip)); + xfs_fileoff_t last_block_offset; + + ASSERT(inode->i_flags & S_VERITY); + error = xfs_bmap_last_extent(NULL, ip, XFS_DATA_FORK, &rec, &is_empty); + if (error) + return error; + + if (is_empty) + return -ENODATA; + + last_block_offset = + XFS_FSB_TO_B(mp, rec.br_startoff + rec.br_blockcount); + if (last_block_offset < xfs_fsverity_metadata_offset(ip)) + return -ENODATA; + + desc_size_pos = last_block_offset - sizeof(__be32); + error = fsverity_pagecache_read(inode, (char *)&d_desc_size, + sizeof(d_desc_size), desc_size_pos); + if (error) + return error; + + desc_size = be32_to_cpu(d_desc_size); + if (XFS_IS_CORRUPT(mp, desc_size > FS_VERITY_MAX_DESCRIPTOR_SIZE)) + return -ERANGE; + if (XFS_IS_CORRUPT(mp, desc_size > desc_size_pos)) + return -ERANGE; + + if (!buf_size) + return desc_size; + + if (XFS_IS_CORRUPT(mp, desc_size > buf_size)) + return -ERANGE; + + desc_pos = round_down(desc_size_pos - desc_size, blocksize); + error = fsverity_pagecache_read(inode, buf, desc_size, desc_pos); + if (error) + return error; + + return desc_size; +} + +static int +xfs_fsverity_write_descriptor( + struct file *file, + const void *desc, + u32 desc_size, + u64 merkle_tree_size) +{ + int error; + struct inode *inode = file_inode(file); + struct xfs_inode *ip = XFS_I(inode); + unsigned int blksize = ip->i_mount->m_sb.sb_blocksize; + u64 tree_last_block = + xfs_fsverity_metadata_offset(ip) + merkle_tree_size; + u64 desc_pos = + round_up(tree_last_block, XFS_FSVERITY_START_ALIGN); + u64 desc_end = desc_pos + desc_size; + __be32 desc_size_disk = cpu_to_be32(desc_size); + u64 desc_size_pos = + round_up(desc_end + sizeof(desc_size_disk), blksize) - + sizeof(desc_size_disk); + + error = iomap_fsverity_write(file, desc_size_pos, sizeof(__be32), + (const void *)&desc_size_disk, + &xfs_buffered_write_iomap_ops, + &xfs_iomap_write_ops); + if (error) + return error; + + return iomap_fsverity_write(file, desc_pos, desc_size, desc, + &xfs_buffered_write_iomap_ops, + &xfs_iomap_write_ops); +} + +/* + * Try to remove all the fsverity metadata after a failed enablement. + */ +static int +xfs_fsverity_delete_metadata( + struct xfs_inode *ip) +{ + struct xfs_trans *tp; + struct xfs_mount *mp = ip->i_mount; + int error; + + error = xfs_trans_alloc(mp, &M_RES(mp)->tr_itruncate, 0, 0, 0, &tp); + if (error) + return error; + + xfs_ilock(ip, XFS_ILOCK_EXCL); + xfs_trans_ijoin(tp, ip, 0); + + /* + * We removing post EOF data, no need to update i_size as fsverity + * didn't move i_size in the first place + */ + error = xfs_itruncate_extents(&tp, ip, XFS_DATA_FORK, XFS_ISIZE(ip)); + if (error) + goto err_cancel; + + error = xfs_trans_commit(tp); + xfs_iunlock(ip, XFS_ILOCK_EXCL); + + return error; + +err_cancel: + xfs_iunlock(ip, XFS_ILOCK_EXCL); + xfs_trans_cancel(tp); + return error; +} + + +/* + * Prepare to enable fsverity by clearing old metadata. + */ +static int +xfs_fsverity_begin_enable( + struct file *filp) +{ + struct inode *inode = file_inode(filp); + struct xfs_inode *ip = XFS_I(inode); + int error; + + xfs_assert_ilocked(ip, XFS_IOLOCK_EXCL); + + if (IS_DAX(inode)) + return -EINVAL; + + if (inode->i_size > XFS_FSVERITY_LARGEST_FILE) + return -EFBIG; + + /* + * Flush pagecache before building Merkle tree. Inode is locked and no + * further writes will happen to the file except fsverity metadata + */ + error = filemap_write_and_wait(inode->i_mapping); + if (error) + return error; + + if (xfs_iflags_test_and_set(ip, XFS_VERITY_CONSTRUCTION)) + return -EBUSY; + + error = xfs_qm_dqattach(ip); + if (error) + return error; + + return xfs_fsverity_delete_metadata(ip); +} + +/* + * Complete (or fail) the process of enabling fsverity. + */ +static int +xfs_fsverity_end_enable( + struct file *file, + const void *desc, + size_t desc_size, + u64 merkle_tree_size) +{ + struct inode *inode = file_inode(file); + struct xfs_inode *ip = XFS_I(inode); + struct xfs_mount *mp = ip->i_mount; + struct xfs_trans *tp; + int error = 0; + loff_t range_start = xfs_fsverity_metadata_offset(ip); + + xfs_assert_ilocked(ip, XFS_IOLOCK_EXCL); + + /* fs-verity failed, just cleanup */ + if (desc == NULL) { + error = xfs_fsverity_delete_metadata(ip); + goto out; + } + + error = xfs_fsverity_write_descriptor(file, desc, desc_size, + merkle_tree_size); + if (error) + goto out; + + /* + * Wait for Merkle tree get written to disk before setting on-disk inode + * flag and clearing XFS_VERITY_CONSTRUCTION + */ + error = filemap_write_and_wait_range(inode->i_mapping, range_start, + LLONG_MAX); + if (error) + goto out; + + /* + * Proactively drop any delayed allocations in COW fork, the fsverity + * files are read-only + */ + if (xfs_is_cow_inode(ip)) + xfs_bmap_punch_delalloc_range(ip, XFS_COW_FORK, 0, LLONG_MAX, + NULL); + + /* + * Set fsverity inode flag + */ + error = xfs_trans_alloc_inode(ip, &M_RES(mp)->tr_ichange, + 0, 0, false, &tp); + if (error) + goto out; + + /* + * Ensure that we've persisted the verity information before we enable + * it on the inode and tell the caller we have sealed the inode. + */ + ip->i_diflags2 |= XFS_DIFLAG2_VERITY; + + xfs_trans_log_inode(tp, ip, XFS_ILOG_CORE); + xfs_trans_set_sync(tp); + + error = xfs_trans_commit(tp); + xfs_iunlock(ip, XFS_ILOCK_EXCL); + + if (!error) + inode->i_flags |= S_VERITY; + +out: + if (error) { + int error2; + + error2 = xfs_fsverity_delete_metadata(ip); + if (error2) + xfs_alert(ip->i_mount, +"ino 0x%llx failed to clean up new fsverity metadata, err %d", + ip->i_ino, error2); + } + + xfs_iflags_clear(ip, XFS_VERITY_CONSTRUCTION); + return error; +} + +/* + * Retrieve a merkle tree block. + */ +static struct page * +xfs_fsverity_read_merkle( + struct inode *inode, + pgoff_t index) +{ + index += xfs_fsverity_metadata_offset(XFS_I(inode)) >> PAGE_SHIFT; + + return generic_read_merkle_tree_page(inode, index); +} + +/* + * Retrieve a merkle tree block. + */ +static void +xfs_fsverity_readahead_merkle_tree( + struct inode *inode, + pgoff_t index, + unsigned long nr_pages) +{ + index += xfs_fsverity_metadata_offset(XFS_I(inode)) >> PAGE_SHIFT; + + generic_readahead_merkle_tree(inode, index, nr_pages); +} + +/* + * Write a merkle tree block. + */ +static int +xfs_fsverity_write_merkle( + struct file *file, + const void *buf, + u64 pos, + unsigned int size, + const u8 *zero_digest, + unsigned int digest_size) +{ + struct inode *inode = file_inode(file); + struct xfs_inode *ip = XFS_I(inode); + loff_t position = pos + + xfs_fsverity_metadata_offset(ip); + + if (position + size > inode->i_sb->s_maxbytes) + return -EFBIG; + + /* + * If this is a block full of hashes of zeroed blocks, don't bother + * storing the block. We can synthesize them later. + * + * However, do this only in case Merkle tree block == fs block size. + * Iomap synthesizes these blocks based on holes in the merkle tree. We + * won't be able to tell if something need to be synthesizes for the + * range in the fs block. For example, for 4k filesystem block + * + * [ 1k | zero hashes | zero hashes | 1k ] + * + * Iomap won't know about these empty blocks. + */ + if (size == ip->i_mount->m_sb.sb_blocksize && + /* + * First digest is zero_digest + */ + memcmp(buf, zero_digest, digest_size) == 0 && + /* + * Every digest is same as previous, thus all are + * zero_digest + */ + memcmp(buf + digest_size, buf, size - digest_size) == 0) + return 0; + + return iomap_fsverity_write(file, position, size, buf, + &xfs_buffered_write_iomap_ops, + &xfs_iomap_write_ops); +} + +const struct fsverity_operations xfs_fsverity_ops = { + .begin_enable_verity = xfs_fsverity_begin_enable, + .end_enable_verity = xfs_fsverity_end_enable, + .get_verity_descriptor = xfs_fsverity_get_descriptor, + .read_merkle_tree_page = xfs_fsverity_read_merkle, + .readahead_merkle_tree = xfs_fsverity_readahead_merkle_tree, + .write_merkle_tree_block = xfs_fsverity_write_merkle, +}; diff --git a/fs/xfs/xfs_fsverity.h b/fs/xfs/xfs_fsverity.h index ec77ba571106..6a981e20a75b 100644 --- a/fs/xfs/xfs_fsverity.h +++ b/fs/xfs/xfs_fsverity.h @@ -6,8 +6,10 @@ #define __XFS_FSVERITY_H__ #include "xfs_platform.h" +#include #ifdef CONFIG_FS_VERITY +extern const struct fsverity_operations xfs_fsverity_ops; loff_t xfs_fsverity_metadata_offset(const struct xfs_inode *ip); bool xfs_fsverity_is_file_data(const struct xfs_inode *ip, loff_t offset); #else diff --git a/fs/xfs/xfs_message.c b/fs/xfs/xfs_message.c index fd297082aeb8..9818d8f8f239 100644 --- a/fs/xfs/xfs_message.c +++ b/fs/xfs/xfs_message.c @@ -153,6 +153,10 @@ xfs_warn_experimental( .opstate = XFS_OPSTATE_WARNED_ZONED, .name = "zoned RT device", }, + [XFS_EXPERIMENTAL_FSVERITY] = { + .opstate = XFS_OPSTATE_WARNED_FSVERITY, + .name = "fsverity", + }, }; ASSERT(feat >= 0 && feat < XFS_EXPERIMENTAL_MAX); BUILD_BUG_ON(ARRAY_SIZE(features) != XFS_EXPERIMENTAL_MAX); diff --git a/fs/xfs/xfs_message.h b/fs/xfs/xfs_message.h index 49b0ef40d299..083403944f11 100644 --- a/fs/xfs/xfs_message.h +++ b/fs/xfs/xfs_message.h @@ -94,6 +94,7 @@ enum xfs_experimental_feat { XFS_EXPERIMENTAL_SHRINK, XFS_EXPERIMENTAL_LARP, XFS_EXPERIMENTAL_ZONED, + XFS_EXPERIMENTAL_FSVERITY, XFS_EXPERIMENTAL_MAX, }; diff --git a/fs/xfs/xfs_mount.h b/fs/xfs/xfs_mount.h index 2c06778a404a..aef5bffb832f 100644 --- a/fs/xfs/xfs_mount.h +++ b/fs/xfs/xfs_mount.h @@ -586,6 +586,8 @@ __XFS_HAS_FEAT(nouuid, NOUUID) #define XFS_OPSTATE_WARNED_ZONED 19 /* (Zoned) GC is in progress */ #define XFS_OPSTATE_ZONEGC_RUNNING 20 +/* Kernel has logged a warning about fsverity support */ +#define XFS_OPSTATE_WARNED_FSVERITY 21 #define __XFS_IS_OPSTATE(name, NAME) \ static inline bool xfs_is_ ## name (struct xfs_mount *mp) \ diff --git a/fs/xfs/xfs_super.c b/fs/xfs/xfs_super.c index f8de44443e81..d9d442009610 100644 --- a/fs/xfs/xfs_super.c +++ b/fs/xfs/xfs_super.c @@ -30,6 +30,7 @@ #include "xfs_filestream.h" #include "xfs_quota.h" #include "xfs_sysfs.h" +#include "xfs_fsverity.h" #include "xfs_ondisk.h" #include "xfs_rmap_item.h" #include "xfs_refcount_item.h" @@ -1686,6 +1687,9 @@ xfs_fs_fill_super( sb->s_quota_types = QTYPE_MASK_USR | QTYPE_MASK_GRP | QTYPE_MASK_PRJ; #endif sb->s_op = &xfs_super_operations; +#ifdef CONFIG_FS_VERITY + sb->s_vop = &xfs_fsverity_ops; +#endif /* * Delay mount work if the debug hook is set. This is debug @@ -1939,6 +1943,9 @@ xfs_fs_fill_super( if (error) goto out_filestream_unmount; + if (xfs_has_verity(mp)) + xfs_warn_experimental(mp, XFS_EXPERIMENTAL_FSVERITY); + root = igrab(VFS_I(mp->m_rootip)); if (!root) { error = -ENOENT; From patchwork Wed May 20 12:37:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241217 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=S5jZ1m7A; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=yedc=dr=vger.kernel.org=linux-ext4+bounces-16608-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB8R6NhTz1xx5 for ; Wed, 20 May 2026 22:45:11 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB8R5kzZz59HN for ; Wed, 20 May 2026 22:45:11 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB8R5brwz59HP; Wed, 20 May 2026 22:45:11 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.234.253.10 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281111; cv=pass; b=g1b89TX2X61zsgc3xyAhVevvz/9W1KIpF3v+NxsnTJO4pEFy0r14SFRi9/4KCFMyHhMWp5E6odKei9otXu1w1rXyeXEuByQx6a/Cgsm72YbyTE+dIAyWIcgOtXiNZJvdolepQMH5HVj3pFm0MpYdcs6cLQoF9adMuHmERq20Uu/2gLMlzOoSzkZTtiuy03fFDyl2pUUDgcBJMu6OWY6fWEpooxXw6JtVYqf1ut8zkuE2g4VExIN08h2ybr6PPsCc6jYptuNjq4hC5Y5Wl2EuoV3YC7Nuj6q+2uVKT4gPfbZ2YjEBdxZ9UOOLodQYY9qq9oarH5B2KsbL54f5Q1Co/w== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281111; c=relaxed/relaxed; bh=qCCHYwxJZa/5SOjD2WmE7I8ycEVOggZ75oMnnZ58Shk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=glZK1DE/EGWFIHEcK5zFzk7kfVpb7uyvauA6juf1CS6JGGyQvj6UyanIHrsdkLPIN05jXKlP8xAGD7SP/tT7/qgXxRgUtV64BFtUqbVp3pbld0GCS+fi74OU3PEBp8o7rwbPsDKL8aGKkwYaTRQBdrXbjl7V2a1bO3win2OVyfl32yFmIqy32d+h+NS+2zdy4QiBe5mW4rm/J15osBheB9XJO1SHQF0aJNLN93nIKKFFG9f67hA8WX0ybSNvbSXjofHljcofY0pqDdRgDBpJ0Zb1bd/DLArKqlEk1jvmpnazuCaA6rS9qrv/0lcLGmvwZr4VyIrI1lkjfwDr4hQFpg== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=S5jZ1m7A; dkim-atps=neutral; spf=pass (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16608-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=S5jZ1m7A; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16608-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB8N41rhz59HN for ; Wed, 20 May 2026 22:45:08 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id CC3523035D60 for ; Wed, 20 May 2026 12:39:19 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id B64FF3E9F8B; Wed, 20 May 2026 12:38:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="S5jZ1m7A" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 39F9B3DD518; Wed, 20 May 2026 12:38:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280693; cv=none; b=Ztpp9aS1iD5By4qDMJt3jQ/vh6jf5y8DHbps/8J7dXsNvrpfDAlp0CfkSI5Z4kJ6P0st9S0s0YGsnfH11T9lHbsAXBK6lo0F/oc7CEzbiK7cGnN1M3TjIBKFEyMNWT0XoAIaL9lP9/ASm4QknYIpVd0HShtADL3xMdkCPCSAVRs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280693; c=relaxed/simple; bh=nvo+/jQmBzOVT1hZLKQjDFN1ozBMwJTC50yAygolAgM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ona9euA98weDzO8M1/DbU0v+6Uh8FEa0njEnFpwc2+O+d7pJWcP1Ntv+Is9T9dyng2ah9VNHPRhRjMU6Ud6Ihx4bTPb4EFE08yEPc6IYTp+SEMwlWMq/RI8u9nhVUyt3jCdDKHiuNI82oz2dRFvcldY1DlocoMBpxl2L53vk+hY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=S5jZ1m7A; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1A0EE1F00894; Wed, 20 May 2026 12:38:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280690; bh=qCCHYwxJZa/5SOjD2WmE7I8ycEVOggZ75oMnnZ58Shk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=S5jZ1m7AluCpwY1SkZ2skQlpneuIK+O/lzRac9DyBHEcoZXLl8F7fUE9bx5P0yJ6N npf0XdVLX0tAcKnSh5vX6LPyhDS3VAIxIvEmKJqmvRYEqKHamRI0dVNRL50uvG9vBQ IqdEDY1rLF2lIgVEspWBRWWcL/6IVstYXuse+QBPxmxgFxMGc0tffeuUpWsgDcp2VL ek9vvRqPaksSlRWHtYpUz+Pc+KPx6qbicQB8Eb7vrV0lDszzKBXzNps1HFSaOrzXjc o04U5AEU5cnHGHwo2g1NzHH6go3y52npR3tGJz3qKcwIM6/Lvosa88dzI1uo4z5AU/ /pAfhi/aq4H0A== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 17/22] xfs: remove unwritten extents after preallocations in fsverity metadata Date: Wed, 20 May 2026 14:37:15 +0200 Message-ID: <20260520123722.405752-18-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org XFS preallocates spaces during writes. In normal I/O this space, if unused, is removed by truncate. For files with fsverity XFS does not use truncate as fsverity metadata is stored past EOF. After we're done with writing fsverity metadata iterate over extents in that region and remove any unwritten ones. These would be left overs in the holes in the merkle tree and past fsverity descriptor. Reviewed-by: Christoph Hellwig Reviewed-by: Darrick J. Wong Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_fsverity.c | 69 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c index a06885291412..298d712b5ba2 100644 --- a/fs/xfs/xfs_fsverity.c +++ b/fs/xfs/xfs_fsverity.c @@ -21,6 +21,8 @@ #include "xfs_iomap.h" #include "xfs_error.h" #include "xfs_health.h" +#include "xfs_bmap.h" +#include "xfs_bmap_util.h" #include #include #include @@ -171,6 +173,65 @@ xfs_fsverity_delete_metadata( return error; } +static int +xfs_fsverity_cancel_unwritten( + struct xfs_inode *ip, + loff_t start, + loff_t end) +{ + struct xfs_mount *mp = ip->i_mount; + struct xfs_trans *tp; + xfs_fileoff_t offset_fsb = XFS_B_TO_FSB(mp, start); + xfs_fileoff_t end_fsb = XFS_B_TO_FSB(mp, end); + struct xfs_bmbt_irec imap; + int nimaps; + int error = 0; + int done; + + + while (offset_fsb < end_fsb) { + nimaps = 1; + + error = xfs_trans_alloc(mp, &M_RES(mp)->tr_write, 0, 0, + 0, &tp); + if (error) + return error; + + xfs_ilock(ip, XFS_ILOCK_EXCL); + error = xfs_bmapi_read(ip, offset_fsb, end_fsb - offset_fsb, + &imap, &nimaps, 0); + if (error) + goto out_cancel; + + if (nimaps == 0) + goto out_cancel; + + if (imap.br_state == XFS_EXT_UNWRITTEN) { + xfs_trans_ijoin(tp, ip, 0); + + error = xfs_bunmapi(tp, ip, imap.br_startoff, + imap.br_blockcount, 0, 1, &done); + if (error) + goto out_cancel; + + error = xfs_trans_commit(tp); + if (error) + return error; + } else { + xfs_trans_cancel(tp); + } + xfs_iunlock(ip, XFS_ILOCK_EXCL); + + offset_fsb = imap.br_startoff + imap.br_blockcount; + } + + return error; +out_cancel: + xfs_trans_cancel(tp); + xfs_iunlock(ip, XFS_ILOCK_EXCL); + return error; +} + /* * Prepare to enable fsverity by clearing old metadata. @@ -248,6 +309,14 @@ xfs_fsverity_end_enable( if (error) goto out; + /* + * Remove unwritten extents left by COW preallocations and write + * preallocation in the merkle tree holes and past descriptor + */ + error = xfs_fsverity_cancel_unwritten(ip, range_start, LLONG_MAX); + if (error) + goto out; + /* * Proactively drop any delayed allocations in COW fork, the fsverity * files are read-only From patchwork Wed May 20 12:37:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241221 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VaxDcVuz; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=zkp+=dr=vger.kernel.org=linux-ext4+bounces-16609-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLBCM077wz1xx5 for ; Wed, 20 May 2026 22:47:43 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLBCL6kHfz58xl for ; Wed, 20 May 2026 22:47:42 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLBCL6dpTz58xk; Wed, 20 May 2026 22:47:42 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281262; cv=pass; b=tqKNnZ5j+PtC5N2I9Og/C+Ik5upB5WurAJB9SVIxmR3Znh0cXWKYkRMBJYhX95Z9gGVEfrADDz+57fckBjP8IE8FRXQ2j2O0eLEc2rHZIBvenC/m06Yu3bqSY6Y5i9PrxZ5YZcTeJs+4qXNNXD4MR43fN+stO4ahMDCU6tIDVqCJUeZU/mUvuVIX9FiIaLT6tcRrjeltAVrOJuD8Mo1cCu7VgfvFdyj+R8BLCO9dzc82UU34KdcwB0J6kLuncvv14ysCY1RBPv7vX3/uoDY9YkJXbJWQ1mQLlg7O4E9Hk4QqqXG/zkfrMPGaQYUHiLMFEneFAmZetFiBXjFx85cbBw== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281262; c=relaxed/relaxed; bh=XyaTEum6ayosvS4JuNWMJtSuDVSnOoX0XTEMccL3PFY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=nj+nNeVeJ0Yfl//CUE5+PtKJlLYG7wrWrA6tR2IhiwF3arFpvKrIEp2GzeJQPL1Lup3D9ickt/HQk9yiunkzMFjTNTmKj4DvNqvXS1twyQ7oVJVPhiqDif8fCR5VxBkz2GxLxIJck5r74kYe6g0ILFrtJ7PGcgfdhye+doi5VrFlW2c8qVAgjKCLIH0D7dv/serPMoGN2YtN3b+OT4iWjMwG8QA1897EfSRmGe1CrKpcTPw1M0Ed/qJKUvHCyFuO6qKOLx/aZWJMOo+5wizgSuFnCHl/EVMGtF8gszC+7aHiYPqudaewL4FUllyfKVE3X/guDfQC5PcPf/5By5mdUw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VaxDcVuz; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16609-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VaxDcVuz; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16609-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLBCH57Hzz58xl for ; Wed, 20 May 2026 22:47:39 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id BEF5230692BE for ; Wed, 20 May 2026 12:39:24 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 411B43EA959; Wed, 20 May 2026 12:38:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VaxDcVuz" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A81BA3E3158; Wed, 20 May 2026 12:38:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280694; cv=none; b=sdwg461B7vkpok4WqSy5TZwUzigCqAymPr69BflnkDZOqNDYICTsnwn3HZ2F4iOxAV2/QSFP3HCOmXoeXWfOj4izSy6S8dRH3aZqpUZAhBmdyMNAigE43WmECND1lrGnkZizlEwmHiELx9njVMHbHdDXeCTPgGWrccKnTKDKwCk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280694; c=relaxed/simple; bh=OXHDc6p2KY2Ob2ruRnf+AlLCT69XEhND7ctSrARe+30=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rpxgRrRVgZgx8FCrxGls2Vy9tUJBppyu/+aEIUOCRpy82GP1bChS8BxE9o6zHwmLgcmWAYytpbzdEch69h5EvziVlnR2aTBHR2wRtpVUCeHies4VNykQQ2u38auIclZE8FxYAg+ORz5n9KdRe1SlxGuAt4cJXxtHc4K/mUqkO5s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VaxDcVuz; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 871CD1F00896; Wed, 20 May 2026 12:38:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280692; bh=XyaTEum6ayosvS4JuNWMJtSuDVSnOoX0XTEMccL3PFY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VaxDcVuzdIy6fM8JDky8Y42v0bXFL0F2l+Tu8XfW+w87gG8SF+Z4bk1EoSQLqexiq 6fXL/9VQPhRl74HMSB4Djzxvhz1Y9C4eITK2ogwh7vhd/OJt2zjDH3s5A9+Nvm175l swNQG9TdnF4uOuvi9KgiUSYnoqe5FjlsHbh425OjTtvBrUic2pK3mqUumibdbGpRo+ 7HoG2WxTjLjNEpaTwDq1sQqpXFUhSunj0c4+iQxxN+3uhDYtzRkU6Jcgyiw1dzrLM1 itD7L2f+9PPMT61FtL/eECmJAgjQo3VmcM084xzznJztGRhSDi+6DZVc5hkOJhjDFg rMYgkDrjvjKTg== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 18/22] xfs: add fs-verity ioctls Date: Wed, 20 May 2026 14:37:16 +0200 Message-ID: <20260520123722.405752-19-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Add fs-verity ioctls to enable, dump metadata (descriptor and Merkle tree pages) and obtain file's digest. [djwong: remove unnecessary casting] Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/xfs_ioctl.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/fs/xfs/xfs_ioctl.c b/fs/xfs/xfs_ioctl.c index 46e234863644..e7cc64b2b56b 100644 --- a/fs/xfs/xfs_ioctl.c +++ b/fs/xfs/xfs_ioctl.c @@ -49,6 +49,7 @@ #include #include +#include /* Return 0 on success or positive error */ int @@ -1445,6 +1446,19 @@ xfs_file_ioctl( case XFS_IOC_VERIFY_MEDIA: return xfs_ioc_verify_media(filp, arg); + case FS_IOC_ENABLE_VERITY: + if (!xfs_has_verity(mp)) + return -EOPNOTSUPP; + return fsverity_ioctl_enable(filp, arg); + case FS_IOC_MEASURE_VERITY: + if (!xfs_has_verity(mp)) + return -EOPNOTSUPP; + return fsverity_ioctl_measure(filp, arg); + case FS_IOC_READ_VERITY_METADATA: + if (!xfs_has_verity(mp)) + return -EOPNOTSUPP; + return fsverity_ioctl_read_metadata(filp, arg); + default: return -ENOTTY; } From patchwork Wed May 20 12:37:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241222 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=A21DPI5Y; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=1i9o=dr=vger.kernel.org=linux-ext4+bounces-16610-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLBCV75ZQz1xx5 for ; Wed, 20 May 2026 22:47:50 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLBCV6dWvz58xl for ; Wed, 20 May 2026 22:47:50 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLBCV6Yhrz58xn; Wed, 20 May 2026 22:47:50 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.105.105.114 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281270; cv=pass; b=NHp9TNWIYz4iMn4VJODujaC5MB+HQ8SAHK7wcOuA2BttEVA5p/I6XlJr3dow04eJqfeqbyW/gpfNLE4saFGKR8juoM+AUFvjIjna4ebtu+C91JXT6riHc9HcBI25iWvWdK0K/3jm1J+es33t93YAXQ3I+5wFsLQs0tgPCWyNAMspGiBV8ckuW8S99mB0hQCJs/cjYTa5qmzAihmbdyrx94cnMa1sxrziE8YSMW8gtsWJypqmJe3WOpDZyezlcTqKaT/ob/p1dn/zsPi3K4OdEiWSnFPLcuBmMtHr13/Zk7DvHLDM2CQz5xod8+cf8wNZgZprau1/J6i5EjnDkRdd4g== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281270; c=relaxed/relaxed; bh=mfyAjF/CmUTJWYFj5Klp/BtXlNLH5opRVJLFuVtT+eY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=p5wcdTWdzpnRIDSmGbUKFVUghTmMFnBeNPm2F6XZ5bLJ3iOF9/O/oFgnnWslBlRK8IGwTWJ2VIEvKn9M+2v2c4N/VnkWRQ4nR5jtxe+uGH2d8GCWg7GAq7U5/Qf/tLVPP4/1dM1lJegu1wiO28cUu7yMU+v5ClPVTlh3MmrWWjo0twa2qgPPUKmC67KOm/2hcif/tyf+HgXjxq0FVZABoRFufEDdE+mTz02L4zp/h46j8qm7SISVwUZShnILq2bQGbu9LiREC72oFgIAEp2ZtmtUa/2u8nCMdECE0KMRljoOXrkYya3/nGiDM7lG9cbU46EeWNKDcodxbKwyTTu1xQ== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=A21DPI5Y; dkim-atps=neutral; spf=pass (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16610-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=A21DPI5Y; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.105.105.114; helo=tor.lore.kernel.org; envelope-from=linux-ext4+bounces-16610-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from tor.lore.kernel.org (tor.lore.kernel.org [172.105.105.114]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLBCR56TFz58xl for ; Wed, 20 May 2026 22:47:47 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by tor.lore.kernel.org (Postfix) with ESMTP id 57B273125C35 for ; Wed, 20 May 2026 12:39:33 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 5F8983EAC74; Wed, 20 May 2026 12:38:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="A21DPI5Y" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 44FF13E3170; Wed, 20 May 2026 12:38:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280696; cv=none; b=uMIHnQfqWGyDtbk/Fzs2P+oRY062JYXFASazszj5T/fZNnqT/mMYhNxFmS1AmgUhnrYk6WPxecO39I52mZDswi2WZMvZIfKSMx6AVJsXq/BsdXNM58LCsnYsZGAG+Ufo5/AmDvZj9PuAsN4n13Gmi/g6VMCzJz139rI2SnsNVRU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280696; c=relaxed/simple; bh=RpmGdpK19RQWoIgTFdViqQtD9XKbSGy/qb0W7trms+Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mk9EwUakCCta3KxkOvf+dPHY5Awy+kHgQkMz/gxr8J360WNAE3935lYAfpAD+bOFQ0nytD1Yp2/IxY/THCWvVKD1U7oMJULe16wF59ooa75yoPELd7GPOX0daRW7CsF5LhZR9dTvTVmKlOLXj7+IglhxMNuqYHDaIcOxfbu07xA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=A21DPI5Y; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 013EF1F000E9; Wed, 20 May 2026 12:38:12 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280695; bh=mfyAjF/CmUTJWYFj5Klp/BtXlNLH5opRVJLFuVtT+eY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=A21DPI5YQPBuVhDAVnIzMTuK4VVJioBQZQbdzkFplNnvjXl1IdzDB+o9R1PPQlBNz 7g8/lFEIBkRh1a6xvzMb5IGIOhi+khVCZ3ybEow1bA5QnNjV6dUJqO3Q/mBdFM82oh ApC90tVdO/St9SPZTWxaAfaOilZG958BjvdOYD68Z+reXkNRx0IjE62B2Gu4FZpZhb RdWUPdO8jU/f5ispiHdf1hRYzHsBYDv1zw/wlHtCxzwbQYag/XZbnYFpwKGWdT7Srg UKTJ8gnR9Y2C+kK4uhPNWounxXavpMnYDhityc3XFreEujy7pnyGcY4OaWx7wSuBFc TM7pIboETB3eg== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: "Darrick J. Wong" , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, Andrey Albershteyn , Andrey Albershteyn Subject: [PATCH v10 19/22] xfs: advertise fs-verity being available on filesystem Date: Wed, 20 May 2026 14:37:17 +0200 Message-ID: <20260520123722.405752-20-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org From: "Darrick J. Wong" Advertise that this filesystem supports fsverity. Signed-off-by: Darrick J. Wong Reviewed-by: Andrey Albershteyn Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/libxfs/xfs_fs.h | 1 + fs/xfs/libxfs/xfs_sb.c | 2 ++ 2 files changed, 3 insertions(+) diff --git a/fs/xfs/libxfs/xfs_fs.h b/fs/xfs/libxfs/xfs_fs.h index 185f09f327c0..c80133784419 100644 --- a/fs/xfs/libxfs/xfs_fs.h +++ b/fs/xfs/libxfs/xfs_fs.h @@ -250,6 +250,7 @@ typedef struct xfs_fsop_resblks { #define XFS_FSOP_GEOM_FLAGS_PARENT (1 << 25) /* linux parent pointers */ #define XFS_FSOP_GEOM_FLAGS_METADIR (1 << 26) /* metadata directories */ #define XFS_FSOP_GEOM_FLAGS_ZONED (1 << 27) /* zoned rt device */ +#define XFS_FSOP_GEOM_FLAGS_VERITY (1 << 28) /* fs-verity */ /* * Minimum and maximum sizes need for growth checks. diff --git a/fs/xfs/libxfs/xfs_sb.c b/fs/xfs/libxfs/xfs_sb.c index a15510ebd2f1..222bbe5559df 100644 --- a/fs/xfs/libxfs/xfs_sb.c +++ b/fs/xfs/libxfs/xfs_sb.c @@ -1590,6 +1590,8 @@ xfs_fs_geometry( geo->flags |= XFS_FSOP_GEOM_FLAGS_METADIR; if (xfs_has_zoned(mp)) geo->flags |= XFS_FSOP_GEOM_FLAGS_ZONED; + if (xfs_has_verity(mp)) + geo->flags |= XFS_FSOP_GEOM_FLAGS_VERITY; geo->rtsectsize = sbp->sb_blocksize; geo->dirblocksize = xfs_dir2_dirblock_bytes(sbp); From patchwork Wed May 20 12:37:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241223 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VIC6BLCF; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=2404:9400:2221:ea00::3; helo=mail.ozlabs.org; envelope-from=srs0=cahj=dr=vger.kernel.org=linux-ext4+bounces-16611-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLBCj0QH5z1xx5 for ; Wed, 20 May 2026 22:48:01 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLBCh73qgz58xk for ; Wed, 20 May 2026 22:48:00 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLBCh6yPMz58xn; Wed, 20 May 2026 22:48:00 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip=172.234.253.10 arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281280; cv=pass; b=y0rKeOOyuwla48+YSilNoShhxnHM7oDXiDU4iPmM/jIgs4x2rAmF0CLeK4aqYM44HLCs6yUwZEAP2PYVLMJXDHAyZzIG9dnoay9uxodQ7iESc+kpU44++Ikcu8c/OyMmi89E6EeUn58rxvjSEPAYwhCtD7tKFsvmR1ffrj+oo3UDE5vnkVjSG3/Se8HY8CLG0rG3rblVos7NMQmph0hkPa5HKk6lVl1FsLjMkYECe2BD4WlQu3EBBOBWim2U4rRVl2DSiuW10FpGFtH1tQTiOMQaeyBhlR1plJcFysPOUn+xgdve5xEBe8qV/ltNECDmO6wl7j0HkDrgofAjnnJqEw== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281280; c=relaxed/relaxed; bh=BGFET5v8J3XUK0lwUrHuswyYjriSddyK9gOxmEyWsyA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Y0EAdDNvUosG1dM6e9nf9RVmG8LLTkTS0FEv/2HDYrCIYHnUu8fevsWsaQ1PpZDDGWh/qMY7kfNKCC8F7nH7z5g3o1F1YX6ZznmWnfgj9Obq5u5ktYUZcSqeqU43MQ8+pg8csmJeHjaRQM3v21sBW4ok923bJV+216K8QUxOOl6xwhmm9q7gKldhFcOGdFegUKudrCfwYc3jHEa2Q4Kg6mgok6pEpdvUXMgQprvOZ8eJKjjekJANg6/wmrA/sqzU7w+B9//P4uSgVBeS2iQPWtAU2vusLcpbdL48CYpHDVpFXChEdVXbW+VcTburawumFFqQaxNR9F411m+r2+EcUw== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VIC6BLCF; dkim-atps=neutral; spf=pass (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16611-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=VIC6BLCF; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=172.234.253.10; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16611-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [172.234.253.10]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLBCd5xm3z58xk for ; Wed, 20 May 2026 22:47:57 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 75A6A312E0DC for ; Wed, 20 May 2026 12:39:40 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 936BC3EA97B; Wed, 20 May 2026 12:38:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VIC6BLCF" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D92C43E1695; Wed, 20 May 2026 12:38:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280701; cv=none; b=BKViGkr1xOqOdg1WO9ZjrClvzy6Ea+RFiOMHmsKsxPtLnCKOAjBywBvJPpzrVAutF9q38U+859AernMarUYpKA5cGI/d4SN7vSDpyDxF+brBN+B9e3inZjGoe6pr9j5PpeSVs1QMcz2B/raV1H6eL+0dgi+yxsxNw9TH8Ux5/Gg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280701; c=relaxed/simple; bh=6DyjuXv0mND6GBGborc5IMtd1Jq8Mc6iPaxy70tYdeU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=e8mQLAjYTt/fShHHZwiQfJ8wG6lnttGI6YBEBZjjeIvUdh06CXFJwCBnFX81pUA3Sc9b8FWJSRqLJAmJFG5G5OSpoByrd0Es516CTm00XeeD87+a/kouLGJNqrVo/DYhqM+fktUL7ndHlRCyhuQPHjji0vPa00x2HBwsipm/0oE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VIC6BLCF; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8F03F1F00893; Wed, 20 May 2026 12:38:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280697; bh=BGFET5v8J3XUK0lwUrHuswyYjriSddyK9gOxmEyWsyA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VIC6BLCFLbuBtWROmmjjPlVJB/FMdvb46De6hEqKxCN3DzAgzH1E3210N49XWr6xt XGHIgq4u55hYSq8xonklx0+wPEquLgtLeFSoTL5V68354HbkBAmBZJrUBj97yOp/HB VJ/Pk1NqADqI++geLRzZkexjJ6J8wEjk6AicLAMKKXxjIs1U++KON/t+Dzpsk+gfwv jA5ieBXniIqGfy2itRK2dF4SJvyuokrZmwoK2WLMjFnNX1JfjbujjGRQuF7xH5fvE/ EUcMXkNzOh9RtPNBsPtTjsSjOr5eHrmAll0Pxjgi3LSWzRJGkDDCOpnGQ2NVPpUYww nFT0Yezi0rUTQ== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: "Darrick J. Wong" , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, Andrey Albershteyn Subject: [PATCH v10 20/22] xfs: check and repair the verity inode flag state Date: Wed, 20 May 2026 14:37:18 +0200 Message-ID: <20260520123722.405752-21-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org From: "Darrick J. Wong" If an inode has the incore verity iflag set, make sure that we can actually activate fsverity on that inode. If activation fails due to a fsverity metadata validation error, clear the flag. The usage model for fsverity requires that any program that cares about verity state is required to call statx/getflags to check that the flag is set after opening the file, so clearing the flag will not compromise that model. Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/scrub/attr.c | 7 +++++ fs/xfs/scrub/common.c | 53 +++++++++++++++++++++++++++++++++++++ fs/xfs/scrub/common.h | 2 ++ fs/xfs/scrub/inode.c | 7 +++++ fs/xfs/scrub/inode_repair.c | 36 +++++++++++++++++++++++++ 5 files changed, 105 insertions(+) diff --git a/fs/xfs/scrub/attr.c b/fs/xfs/scrub/attr.c index 390ac2e11ee0..daf7962c2374 100644 --- a/fs/xfs/scrub/attr.c +++ b/fs/xfs/scrub/attr.c @@ -649,6 +649,13 @@ xchk_xattr( if (!xfs_inode_hasattr(sc->ip)) return -ENOENT; + /* + * If this is a verity file that won't activate, we cannot check the + * merkle tree geometry. + */ + if (xchk_inode_verity_broken(sc->ip)) + xchk_set_incomplete(sc); + /* Allocate memory for xattr checking. */ error = xchk_setup_xattr_buf(sc, 0); if (error == -ENOMEM) diff --git a/fs/xfs/scrub/common.c b/fs/xfs/scrub/common.c index 3d40cb0b2496..706a2777d7e6 100644 --- a/fs/xfs/scrub/common.c +++ b/fs/xfs/scrub/common.c @@ -45,6 +45,8 @@ #include "scrub/health.h" #include "scrub/tempfile.h" +#include + /* Common code for the metadata scrubbers. */ /* @@ -1754,3 +1756,54 @@ xchk_inode_count_blocks( return xfs_bmap_count_blocks(sc->tp, sc->ip, whichfork, nextents, count); } + +/* + * If this inode has S_VERITY set on it, read the verity info. If the reading + * fails with anything other than ENOMEM, the file is corrupt, which we can + * detect later with fsverity_active. + * + * Callers must hold the IOLOCK and must not hold the ILOCK of sc->ip because + * activation reads inode data. + */ +int +xchk_inode_setup_verity( + struct xfs_scrub *sc) +{ + int error; + + if (!fsverity_active(VFS_I(sc->ip))) + return 0; + + error = fsverity_ensure_verity_info(VFS_I(sc->ip)); + switch (error) { + case 0: + /* fsverity is active */ + break; + case -ENODATA: + case -EMSGSIZE: + case -EINVAL: + case -EFSCORRUPTED: + case -EFBIG: + /* + * The nonzero errno codes above are the error codes that can + * be returned from fsverity on metadata validation errors. + */ + return 0; + default: + /* runtime errors */ + return error; + } + + return 0; +} + +/* + * Is this a verity file that failed to activate? Callers must have tried to + * activate fsverity via xchk_inode_setup_verity. + */ +bool +xchk_inode_verity_broken( + struct xfs_inode *ip) +{ + return fsverity_active(VFS_I(ip)) && !fsverity_get_info(VFS_I(ip)); +} diff --git a/fs/xfs/scrub/common.h b/fs/xfs/scrub/common.h index b494d747c008..ff51bbe62e9f 100644 --- a/fs/xfs/scrub/common.h +++ b/fs/xfs/scrub/common.h @@ -266,6 +266,8 @@ int xchk_inode_is_allocated(struct xfs_scrub *sc, xfs_agino_t agino, bool *inuse); int xchk_inode_count_blocks(struct xfs_scrub *sc, int whichfork, xfs_extnum_t *nextents, xfs_filblks_t *count); +int xchk_inode_setup_verity(struct xfs_scrub *sc); +bool xchk_inode_verity_broken(struct xfs_inode *ip); bool xchk_inode_is_dirtree_root(const struct xfs_inode *ip); bool xchk_inode_is_sb_rooted(const struct xfs_inode *ip); diff --git a/fs/xfs/scrub/inode.c b/fs/xfs/scrub/inode.c index 948d04dcba2a..8ce6917e22b4 100644 --- a/fs/xfs/scrub/inode.c +++ b/fs/xfs/scrub/inode.c @@ -36,6 +36,10 @@ xchk_prepare_iscrub( xchk_ilock(sc, XFS_IOLOCK_EXCL); + error = xchk_inode_setup_verity(sc); + if (error) + return error; + error = xchk_trans_alloc(sc, 0); if (error) return error; @@ -833,6 +837,9 @@ xchk_inode( if (S_ISREG(VFS_I(sc->ip)->i_mode)) xchk_inode_check_reflink_iflag(sc, sc->ip->i_ino); + if (xchk_inode_verity_broken(sc->ip)) + xchk_ino_set_corrupt(sc, sc->sm->sm_ino); + xchk_inode_check_unlinked(sc); xchk_inode_xref(sc, sc->ip->i_ino, &di); diff --git a/fs/xfs/scrub/inode_repair.c b/fs/xfs/scrub/inode_repair.c index 9738b9ce3f2d..3761e3922466 100644 --- a/fs/xfs/scrub/inode_repair.c +++ b/fs/xfs/scrub/inode_repair.c @@ -573,6 +573,8 @@ xrep_dinode_flags( dip->di_nrext64_pad = 0; else if (dip->di_version >= 3) dip->di_v3_pad = 0; + if (!xfs_has_verity(mp) || !S_ISREG(mode)) + flags2 &= ~XFS_DIFLAG2_VERITY; if (flags2 & XFS_DIFLAG2_METADATA) { xfs_failaddr_t fa; @@ -1613,6 +1615,10 @@ xrep_dinode_core( if (iget_error) return iget_error; + error = xchk_inode_setup_verity(sc); + if (error) + return error; + error = xchk_trans_alloc(sc, 0); if (error) return error; @@ -2032,6 +2038,27 @@ xrep_inode_unlinked( return 0; } +/* + * If this file is a fsverity file, xchk_prepare_iscrub or xrep_dinode_core + * should have activated it. If it's still not active, then there's something + * wrong with the verity descriptor and we should turn it off. + */ +STATIC int +xrep_inode_verity( + struct xfs_scrub *sc) +{ + struct inode *inode = VFS_I(sc->ip); + + if (xchk_inode_verity_broken(sc->ip)) { + sc->ip->i_diflags2 &= ~XFS_DIFLAG2_VERITY; + inode->i_flags &= ~S_VERITY; + + xfs_trans_log_inode(sc->tp, sc->ip, XFS_ILOG_CORE); + } + + return 0; +} + /* Repair an inode's fields. */ int xrep_inode( @@ -2081,6 +2108,15 @@ xrep_inode( return error; } + /* + * Disable fsverity if it cannot be activated. Activation failure + * prohibits the file from being opened, so there cannot be another + * program with an open fd to what it thinks is a verity file. + */ + error = xrep_inode_verity(sc); + if (error) + return error; + /* Reconnect incore unlinked list */ error = xrep_inode_unlinked(sc); if (error) From patchwork Wed May 20 12:37:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241211 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=obSrY2ZO; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=150.107.74.76; helo=mail.ozlabs.org; envelope-from=srs0=xq1b=dr=vger.kernel.org=linux-ext4+bounces-16612-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB6G335Mz1xx8 for ; Wed, 20 May 2026 22:43:18 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB6G2Zrkz59HN for ; Wed, 20 May 2026 22:43:18 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB6G2V0cz59HC; Wed, 20 May 2026 22:43:18 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c09:e001:a7::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280998; cv=pass; b=J10Y+GXnqmxREC4RzgZ/oT4G2MjLAejsI3kYgUtlEQpXJxEIP4hleHFjwRFGNGYVPHJ6DGjkoIbI3yaOrWOYvvLpNRvfK4x5DT9FjDxiU2vs4iZBEc3RZkD2VbPfQ6+RpK7tXb+JXbjKFbMpKNEqBKbAm311QWDiS09jzmTNctYGryeNu9Un8ZRpq9KupIqap48uECvxwhF/G+ii5v5Nc/ZrcJ/KIxhX/+MwA5dEtSQeREpW6+JRsrX/g7qrcLP5xdFn9dZaH5NqqMYWaYQ3WEdbCV2oOEzxdQdSRQ1vNXM4Nz8fyEjWrTNDuwOwx4IfaxwdsbwMwiuRVFl5/UheBg== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779280998; c=relaxed/relaxed; bh=wwCsJAbnyXtcckT/N5X3iHRQJj6H6toVwoc9J6vCOQk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dLgMJSNLKilVi8lYO+UHxeoX8P02iq7TeWqCke44G0bnN3Fo0CfjWpBjLE4nWdxgTQXT3ziveyfyZsGPwKp48gyBdwOPxIF4fo09sJ3nz19AM44e7fkkq8xLij8SgaWd2k2vhM+7vq1oTj/RFiW1/Q4CxM8GdkSejt5ekwvK50zv7ebUHhzkmU485khxlBz8i7qWV4Am1LpF9D+SpaPNodBuqGL3mipecQPUD+W8NBPqnx4wW7nlXWKweUaARyOKjCMb/cd1zsji3Fmrrqen/YMnu8847I0Ot09xJBQByC91+UHDlb6B0m/ddHV3mlnoeflJAm8q4RwgTwLVP/ZO6Q== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=obSrY2ZO; dkim-atps=neutral; spf=pass (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16612-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=obSrY2ZO; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c09:e001:a7::12fc:5321; helo=sto.lore.kernel.org; envelope-from=linux-ext4+bounces-16612-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sto.lore.kernel.org (sto.lore.kernel.org [IPv6:2600:3c09:e001:a7::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB6B6wlrz59HN for ; Wed, 20 May 2026 22:43:14 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sto.lore.kernel.org (Postfix) with ESMTP id 7EFD93041845 for ; Wed, 20 May 2026 12:39:47 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 0B0863EBF0C; Wed, 20 May 2026 12:38:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="obSrY2ZO" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C895B3DF002; Wed, 20 May 2026 12:38:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280703; cv=none; b=D8W+3Tpja4N4P5kAXKaeSE/bCOy2QPlRHHqf7wls+vAw6tlsYk4qBtbxziUsERbpaszClq+hKdFLIUjQGpkIKIz+U7I0hzsPztgeUy42VeVmjbE6S+eMg8PTbOaqJgNfML2LoZRp/CpvY19nPuIdOWp/XZzOoSycHcat0WXj8sw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280703; c=relaxed/simple; bh=LcsvudtBvCEVOKizeNawa6YpvmKVeIw8YTpKJAMV5Oc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=K/4NYP7oiQFeb33D09RBF4qrMNtEYmpw4qD8ZbfOTCyDKk0tAhz5IDGecvnkkexgq+eWufPdDlEXOlPo8JLOS8hP2bSxVT8l92bQFp/EoRlEaL5fV0UI0Dsl91wCRkw0PKnaeqmzE2JsC4/id0HdIVSQWRjEXDCeLUKlcPZVu0Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=obSrY2ZO; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0D16D1F00894; Wed, 20 May 2026 12:38:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280700; bh=wwCsJAbnyXtcckT/N5X3iHRQJj6H6toVwoc9J6vCOQk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=obSrY2ZOxwnXf383pybE7QW7/WPCGKknCqDVD5IgrYqN618Vke9xDgIXS+RIzHOIp dJ8oKcgBHU+1xlMvhGiWnFvf0MxoJQb60/7koo+R4TQJlyWWq9x0I1FiR474WfACKA u7CGGDzBO17oTcIJCc0G1EBWVh9xnwwzKH/CQsX2zObBIhN9/yfHtkA6fKxDoMbZtm BU9kMCEYlTfuysUPREzgECp5lQaCCmPsMmUS6nggUn3hHa2GobXubgyh6zgif8nnDx I27H4itD3Nfn6lfNFXkHl8dvxanw2cr6KPBkWWxaFOKHA0NsWgo8hfGU+7cqldOiL0 7ykCSscA42q0A== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 21/22] xfs: introduce health state for corrupted fsverity metadata Date: Wed, 20 May 2026 14:37:19 +0200 Message-ID: <20260520123722.405752-22-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Report corrupted fsverity descriptor through health system. Reviewed-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/libxfs/xfs_fs.h | 1 + fs/xfs/libxfs/xfs_health.h | 4 +++- fs/xfs/xfs_fsverity.c | 13 ++++++++++--- fs/xfs/xfs_health.c | 1 + 4 files changed, 15 insertions(+), 4 deletions(-) diff --git a/fs/xfs/libxfs/xfs_fs.h b/fs/xfs/libxfs/xfs_fs.h index c80133784419..84d62b7506a9 100644 --- a/fs/xfs/libxfs/xfs_fs.h +++ b/fs/xfs/libxfs/xfs_fs.h @@ -422,6 +422,7 @@ struct xfs_bulkstat { #define XFS_BS_SICK_SYMLINK (1 << 6) /* symbolic link remote target */ #define XFS_BS_SICK_PARENT (1 << 7) /* parent pointers */ #define XFS_BS_SICK_DIRTREE (1 << 8) /* directory tree structure */ +#define XFS_BS_SICK_FSVERITY (1 << 9) /* fsverity metadata */ /* * Project quota id helpers (previously projid was 16bit only diff --git a/fs/xfs/libxfs/xfs_health.h b/fs/xfs/libxfs/xfs_health.h index 1d45cf5789e8..932b447190da 100644 --- a/fs/xfs/libxfs/xfs_health.h +++ b/fs/xfs/libxfs/xfs_health.h @@ -104,6 +104,7 @@ struct xfs_rtgroup; /* Don't propagate sick status to ag health summary during inactivation */ #define XFS_SICK_INO_FORGET (1 << 12) #define XFS_SICK_INO_DIRTREE (1 << 13) /* directory tree structure */ +#define XFS_SICK_INO_FSVERITY (1 << 14) /* fsverity metadata */ /* Primary evidence of health problems in a given group. */ #define XFS_SICK_FS_PRIMARY (XFS_SICK_FS_COUNTERS | \ @@ -140,7 +141,8 @@ struct xfs_rtgroup; XFS_SICK_INO_XATTR | \ XFS_SICK_INO_SYMLINK | \ XFS_SICK_INO_PARENT | \ - XFS_SICK_INO_DIRTREE) + XFS_SICK_INO_DIRTREE | \ + XFS_SICK_INO_FSVERITY) #define XFS_SICK_INO_ZAPPED (XFS_SICK_INO_BMBTD_ZAPPED | \ XFS_SICK_INO_BMBTA_ZAPPED | \ diff --git a/fs/xfs/xfs_fsverity.c b/fs/xfs/xfs_fsverity.c index 298d712b5ba2..82f5ca542c97 100644 --- a/fs/xfs/xfs_fsverity.c +++ b/fs/xfs/xfs_fsverity.c @@ -84,16 +84,23 @@ xfs_fsverity_get_descriptor( return error; desc_size = be32_to_cpu(d_desc_size); - if (XFS_IS_CORRUPT(mp, desc_size > FS_VERITY_MAX_DESCRIPTOR_SIZE)) + if (XFS_IS_CORRUPT(mp, desc_size > FS_VERITY_MAX_DESCRIPTOR_SIZE)) { + xfs_inode_mark_sick(XFS_I(inode), XFS_SICK_INO_FSVERITY); return -ERANGE; - if (XFS_IS_CORRUPT(mp, desc_size > desc_size_pos)) + } + + if (XFS_IS_CORRUPT(mp, desc_size > desc_size_pos)) { + xfs_inode_mark_sick(XFS_I(inode), XFS_SICK_INO_FSVERITY); return -ERANGE; + } if (!buf_size) return desc_size; - if (XFS_IS_CORRUPT(mp, desc_size > buf_size)) + if (XFS_IS_CORRUPT(mp, desc_size > buf_size)) { + xfs_inode_mark_sick(XFS_I(inode), XFS_SICK_INO_FSVERITY); return -ERANGE; + } desc_pos = round_down(desc_size_pos - desc_size, blocksize); error = fsverity_pagecache_read(inode, buf, desc_size, desc_pos); diff --git a/fs/xfs/xfs_health.c b/fs/xfs/xfs_health.c index 239b843e83d4..be66760fb120 100644 --- a/fs/xfs/xfs_health.c +++ b/fs/xfs/xfs_health.c @@ -625,6 +625,7 @@ static const struct ioctl_sick_map ino_map[] = { { XFS_SICK_INO_DIR_ZAPPED, XFS_BS_SICK_DIR }, { XFS_SICK_INO_SYMLINK_ZAPPED, XFS_BS_SICK_SYMLINK }, { XFS_SICK_INO_DIRTREE, XFS_BS_SICK_DIRTREE }, + { XFS_SICK_INO_FSVERITY, XFS_BS_SICK_FSVERITY }, }; /* Fill out bulkstat health info. */ From patchwork Wed May 20 12:37:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andrey Albershteyn X-Patchwork-Id: 2241218 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@legolas.ozlabs.org Authentication-Results: legolas.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=o1Y54qAh; dkim-atps=neutral Authentication-Results: legolas.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=ozlabs.org (client-ip=150.107.74.76; helo=mail.ozlabs.org; envelope-from=srs0=sigv=dr=vger.kernel.org=linux-ext4+bounces-16613-patchwork-incoming=ozlabs.org@ozlabs.org; receiver=patchwork.ozlabs.org) Received: from mail.ozlabs.org (gandalf.ozlabs.org [150.107.74.76]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (No client certificate requested) by legolas.ozlabs.org (Postfix) with ESMTPS id 4gLB992TSjz1xx5 for ; Wed, 20 May 2026 22:45:49 +1000 (AEST) Received: from mail.ozlabs.org (mail.ozlabs.org [IPv6:2404:9400:2221:ea00::3]) by gandalf.ozlabs.org (Postfix) with ESMTP id 4gLB991xxRz59HP for ; Wed, 20 May 2026 22:45:49 +1000 (AEST) Received: by gandalf.ozlabs.org (Postfix) id 4gLB991rNzz59HQ; Wed, 20 May 2026 22:45:49 +1000 (AEST) Delivered-To: patchwork-incoming@ozlabs.org Authentication-Results: gandalf.ozlabs.org; arc=pass smtp.remote-ip="2600:3c0a:e001:db::12fc:5321" arc.chain=subspace.kernel.org ARC-Seal: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281149; cv=pass; b=tEsGuNWIovoA7SJ7ozSTH9bD22Sj8C02P3WsVtXdIm0i2zkscEErCz1mmuwVQLennKf7JB+RHeH+qLYd1nJtBFTpJrWk5mPve+5ehsob1V0wmvHUTefbF2PE7OC+jL5lZF18YUF72zGegHflJszRTBYfurTFpngXreTIP8D6MvoI34tXYdYNlqrvKnmhbPp5YZuwCX+Y3hc08KYw+5HHGLz5rRnRg4dMjduaDWGazgHgq04BSIahuKH36u82vUb0ZHN5s89WAogOp8D2f/WpqlPPqrcoG5S72SDoOW8y1MBGEdqrSvMlAHYWPDzJ8WAmzWU3tM4k/kzq1hPm1wOnVg== ARC-Message-Signature: i=2; a=rsa-sha256; d=ozlabs.org; s=201707; t=1779281149; c=relaxed/relaxed; bh=Xui3Yd2dYz+96SItktvVLM/CAryyTbeJqWzBMfavRug=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=xGzd7F6xCmu0sj9CfjF6Wz7XRgz/AjUKose8SqfZvk/mOsmwaRecXuddTLnb1X/kNLDmxO5n69zj70ScdvMABIQ0Kmb+DiqMmbcM22UnlifDImIDDp4aF6gbVVvg7gwYYiyEUwmJNSPOibPUr5YzEVGabVf3KL74YT/6BzXkdTsElvOE3kaAY3toZMVyVnudE1h54wpdCS0v+hUqAtCPPSbT1hd/ZyYi9Ehqxl5RD5ANVaKE1p3kC8DOCASQyPiPRf26jC7/ZQ8rPTrk0+/FUlfbH/yeieBZipV/PwhGqfwd0CFGH0zqYp/RHsl8vL/0CYTSdmVH0DIafx2ThQd/aQ== ARC-Authentication-Results: i=2; gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=o1Y54qAh; dkim-atps=neutral; spf=pass (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16613-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) smtp.mailfrom=vger.kernel.org Authentication-Results: gandalf.ozlabs.org; dmarc=pass (p=quarantine dis=none) header.from=kernel.org Authentication-Results: gandalf.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=kernel.org header.i=@kernel.org header.a=rsa-sha256 header.s=k20260515 header.b=o1Y54qAh; dkim-atps=neutral Authentication-Results: gandalf.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org (client-ip=2600:3c0a:e001:db::12fc:5321; helo=sea.lore.kernel.org; envelope-from=linux-ext4+bounces-16613-patchwork-incoming=ozlabs.org@vger.kernel.org; receiver=ozlabs.org) Received: from sea.lore.kernel.org (sea.lore.kernel.org [IPv6:2600:3c0a:e001:db::12fc:5321]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by gandalf.ozlabs.org (Postfix) with ESMTPS id 4gLB9572PXz59HP for ; Wed, 20 May 2026 22:45:45 +1000 (AEST) Received: from smtp.subspace.kernel.org (conduit.subspace.kernel.org [100.90.174.1]) by sea.lore.kernel.org (Postfix) with ESMTP id 738DF31341B8 for ; Wed, 20 May 2026 12:39:54 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 2412C3EC2E3; Wed, 20 May 2026 12:38:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="o1Y54qAh" X-Original-To: linux-ext4@vger.kernel.org Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5985A3E2764; Wed, 20 May 2026 12:38:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280706; cv=none; b=J3wFwYwJkf16tyCkL2kRn2s2jONtvCekm9wBPn86XNsT88Evf5abWni26CPKWv8yRjf7oqKLpMQ4Un9hrDHqG84JpTYhLil4RHetRBIT4AhAyxm0T/nfj9dkkR1iPQZxl8xRt4gtzXu38ceR7PwOE+I5NM44+ODA4CIfGTAJFxY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779280706; c=relaxed/simple; bh=ED63hkK8etbxautcxx1u5AO9FSZT6ssFdgXiGIlo5Yc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=c7aeP1WeQgm9gfM++yuS40r2LULtyV8UuTuVXKPYD1pXElbcMb72Qz4W1VaBpLS+E/WCfTHDPs+7qfn61KlvaZrk6XF8YkkPL987oQiyY+eWHpuRlbvXEmAFGgXRIPgHQ32adQQt/sk6tMp9nY0uBNsEs8xfwFv3Pdf+YG0pt98= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=o1Y54qAh; arc=none smtp.client-ip=100.103.45.18 Received: by smtp.kernel.org (Postfix) with ESMTPSA id 760041F000E9; Wed, 20 May 2026 12:38:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1779280702; bh=Xui3Yd2dYz+96SItktvVLM/CAryyTbeJqWzBMfavRug=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=o1Y54qAhJ+MlxLZEm34rOkFWoYDs6EpF5rRGiQxtOf/dkT3d6pKYzBvHIfo8NO3H1 9XvV6r7oJ8xiZjhbsYdW6kJhgMxOAiifi00n1VMJu4p6ePfib2S8A9Sw3IX4/xToBg 8iToT+Z8XG/HCgQDyRsi7c4MDkeL+n0cwWXE5afFOyr1hZstn35FMbCCm6NI7pJjVk 2fVy378BOftYgRAEbKqz1Ycnwdf1ZlFAAzKfvSBTy5zKIDSTgxUxC1bt8pbO1uTaNW RN+Y/MiV7LxUyIBEK12JrxZwv+jqOUBRy0ZQUJNKL1chTTuEBlqUaN8EZCTd2g2WdH dq7/puFX3RRfA== From: Andrey Albershteyn To: linux-xfs@vger.kernel.org, fsverity@lists.linux.dev, linux-fsdevel@vger.kernel.org, ebiggers@kernel.org Cc: Andrey Albershteyn , hch@lst.de, linux-ext4@vger.kernel.org, linux-f2fs-devel@lists.sourceforge.net, linux-btrfs@vger.kernel.org, linux-unionfs@vger.kernel.org, djwong@kernel.org Subject: [PATCH v10 22/22] xfs: enable ro-compat fs-verity flag Date: Wed, 20 May 2026 14:37:20 +0200 Message-ID: <20260520123722.405752-23-aalbersh@kernel.org> X-Mailer: git-send-email 2.51.2 In-Reply-To: <20260520123722.405752-1-aalbersh@kernel.org> References: <20260520123722.405752-1-aalbersh@kernel.org> Precedence: bulk X-Mailing-List: linux-ext4@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Spam-Status: No, score=-1.5 required=5.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DMARC_PASS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS autolearn=disabled version=4.0.1 X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-25) on gandalf.ozlabs.org Finalize fs-verity integration in XFS by making kernel fs-verity aware with ro-compat flag. Reviewed-by: Darrick J. Wong [djwong: add spaces] Signed-off-by: Darrick J. Wong Reviewed-by: Christoph Hellwig Signed-off-by: Andrey Albershteyn --- fs/xfs/libxfs/xfs_format.h | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/fs/xfs/libxfs/xfs_format.h b/fs/xfs/libxfs/xfs_format.h index 4dff29659e40..0ce46c234b9c 100644 --- a/fs/xfs/libxfs/xfs_format.h +++ b/fs/xfs/libxfs/xfs_format.h @@ -378,8 +378,9 @@ xfs_sb_has_compat_feature( #define XFS_SB_FEAT_RO_COMPAT_ALL \ (XFS_SB_FEAT_RO_COMPAT_FINOBT | \ XFS_SB_FEAT_RO_COMPAT_RMAPBT | \ - XFS_SB_FEAT_RO_COMPAT_REFLINK| \ - XFS_SB_FEAT_RO_COMPAT_INOBTCNT) + XFS_SB_FEAT_RO_COMPAT_REFLINK | \ + XFS_SB_FEAT_RO_COMPAT_INOBTCNT | \ + XFS_SB_FEAT_RO_COMPAT_VERITY) #define XFS_SB_FEAT_RO_COMPAT_UNKNOWN ~XFS_SB_FEAT_RO_COMPAT_ALL static inline bool xfs_sb_has_ro_compat_feature(