ffs_wapbl.c revision 1.44.4.1       1 /*	$NetBSD: ffs_wapbl.c,v 1.44.4.1 2025/01/07 16:16:50 martin Exp $	*/
      2 
      3 /*-
      4  * Copyright (c) 2003,2006,2008 The NetBSD Foundation, Inc.
      5  * All rights reserved.
      6  *
      7  * This code is derived from software contributed to The NetBSD Foundation
      8  * by Wasabi Systems, Inc.
      9  *
     10  * Redistribution and use in source and binary forms, with or without
     11  * modification, are permitted provided that the following conditions
     12  * are met:
     13  * 1. Redistributions of source code must retain the above copyright
     14  *    notice, this list of conditions and the following disclaimer.
     15  * 2. Redistributions in binary form must reproduce the above copyright
     16  *    notice, this list of conditions and the following disclaimer in the
     17  *    documentation and/or other materials provided with the distribution.
     18  *
     19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29  * POSSIBILITY OF SUCH DAMAGE.
     30  */
     31 
     32 #include <sys/cdefs.h>
     33 __KERNEL_RCSID(0, "$NetBSD: ffs_wapbl.c,v 1.44.4.1 2025/01/07 16:16:50 martin Exp $");
     34 
     35 #define WAPBL_INTERNAL
     36 
     37 #if defined(_KERNEL_OPT)
     38 #include "opt_ffs.h"
     39 #endif
     40 
     41 #include <sys/param.h>
     42 #include <sys/systm.h>
     43 #include <sys/kernel.h>
     44 #include <sys/vnode.h>
     45 #include <sys/mount.h>
     46 #include <sys/file.h>
     47 #include <sys/disk.h>
     48 #include <sys/ioctl.h>
     49 #include <sys/errno.h>
     50 #include <sys/kauth.h>
     51 #include <sys/wapbl.h>
     52 
     53 #include <ufs/ufs/inode.h>
     54 #include <ufs/ufs/quota.h>
     55 #include <ufs/ufs/ufsmount.h>
     56 #include <ufs/ufs/ufs_bswap.h>
     57 #include <ufs/ufs/ufs_extern.h>
     58 #include <ufs/ufs/ufs_wapbl.h>
     59 
     60 #include <ufs/ffs/fs.h>
     61 #include <ufs/ffs/ffs_extern.h>
     62 
     63 #undef	WAPBL_DEBUG
     64 #ifdef WAPBL_DEBUG
     65 int ffs_wapbl_debug = 1;
     66 #define DPRINTF(fmt, args...)						\
     67 do {									\
     68 	if (ffs_wapbl_debug)						\
     69 		printf("%s:%d "fmt, __func__ , __LINE__, ##args);	\
     70 } while (/* CONSTCOND */0)
     71 #else
     72 #define	DPRINTF(fmt, args...)						\
     73 do {									\
     74 	/* nothing */							\
     75 } while (/* CONSTCOND */0)
     76 #endif
     77 
     78 static int ffs_superblock_layout(struct fs *);
     79 static int wapbl_log_position(struct mount *, struct fs *, struct vnode *,
     80     daddr_t *, size_t *, size_t *, uint64_t *);
     81 static int wapbl_create_infs_log(struct mount *, struct fs *, struct vnode *,
     82     daddr_t *, size_t *, uint64_t *);
     83 static void wapbl_find_log_start(struct mount *, struct vnode *, off_t,
     84     daddr_t *, daddr_t *, size_t *);
     85 static int wapbl_remove_log(struct mount *);
     86 static int wapbl_allocate_log_file(struct mount *, struct vnode *,
     87     daddr_t *, size_t *, uint64_t *);
     88 
     89 /*
     90  * Return the super block layout format - UFS1 or UFS2.
     91  * WAPBL only works with UFS2 layout (which is still available
     92  * with FFSv1).
     93  *
     94  * XXX Should this be in ufs/ffs/fs.h?  Same style of check is
     95  * also used in ffs_alloc.c in a few places.
     96  */
     97 static int
     98 ffs_superblock_layout(struct fs *fs)
     99 {
    100 	if ((fs->fs_magic == FS_UFS1_MAGIC) &&
    101 	    ((fs->fs_old_flags & FS_FLAGS_UPDATED) == 0))
    102 		return 1;
    103 	else
    104 		return 2;
    105 }
    106 
    107 /*
    108  * This function is invoked after a log is replayed to
    109  * disk to perform logical cleanup actions as described by
    110  * the log
    111  */
    112 void
    113 ffs_wapbl_replay_finish(struct mount *mp)
    114 {
    115 	struct wapbl_replay *wr = mp->mnt_wapbl_replay;
    116 	int i;
    117 	int error;
    118 
    119 	if (!wr)
    120 		return;
    121 
    122 	KDASSERT((mp->mnt_flag & MNT_RDONLY) == 0);
    123 
    124 	for (i = 0; i < wr->wr_inodescnt; i++) {
    125 		struct vnode *vp;
    126 		struct inode *ip;
    127 		error = VFS_VGET(mp, wr->wr_inodes[i].wr_inumber, &vp);
    128 		if (error) {
    129 			printf("%s: %s: unable to cleanup inode %" PRIu32 "\n",
    130 			    __func__, VFSTOUFS(mp)->um_fs->fs_fsmnt,
    131 			    wr->wr_inodes[i].wr_inumber);
    132 			continue;
    133 		}
    134 		ip = VTOI(vp);
    135 		KDASSERT(wr->wr_inodes[i].wr_inumber == ip->i_number);
    136 #ifdef WAPBL_DEBUG
    137 		printf("%s%s: %s: cleaning inode %" PRIu64 " size=%" PRIu64
    138 		    " mode=%o nlink=%d\n",
    139 		    __func__, VFSTOUFS(mp)->um_fs->fs_fsmnt,
    140 		    ip->i_number, ip->i_size, ip->i_mode, ip->i_nlink);
    141 #endif
    142 		KASSERT(ip->i_nlink == 0);
    143 
    144 		/*
    145 		 * The journal may have left partially allocated inodes in mode
    146 		 * zero.  This may occur if a crash occurs betweeen the node
    147 		 * allocation in ffs_nodeallocg and when the node is properly
    148 		 * initialized in ufs_makeinode.  If so, just dallocate them.
    149 		 */
    150 		if (ip->i_mode == 0) {
    151 			error = UFS_WAPBL_BEGIN(mp);
    152 			if (error) {
    153 				printf("%s: %s: "
    154 				    "unable to cleanup inode %" PRIu32 "\n",
    155 				    __func__, VFSTOUFS(mp)->um_fs->fs_fsmnt,
    156 				    wr->wr_inodes[i].wr_inumber);
    157 			} else {
    158 				ffs_vfree(vp, ip->i_number,
    159 				    wr->wr_inodes[i].wr_imode);
    160 				UFS_WAPBL_END(mp);
    161 			}
    162 		}
    163 		vput(vp);
    164 	}
    165 	wapbl_replay_stop(wr);
    166 	wapbl_replay_free(wr);
    167 	mp->mnt_wapbl_replay = NULL;
    168 }
    169 
    170 /* Callback for wapbl */
    171 void
    172 ffs_wapbl_sync_metadata(struct mount *mp, struct wapbl_dealloc *fdealloc)
    173 {
    174 	struct ufsmount *ump = VFSTOUFS(mp);
    175 	struct fs *fs = ump->um_fs;
    176 	int error __diagused;
    177 	struct wapbl_dealloc *wd;
    178 
    179 	UFS_WAPBL_JLOCK_ASSERT(ump->um_mountp);
    180 
    181 #ifdef WAPBL_DEBUG_INODES
    182 	ufs_wapbl_verify_inodes(mp, __func__);
    183 #endif
    184 
    185 	for (wd = fdealloc; wd != NULL; wd = TAILQ_NEXT(wd, wd_entries)) {
    186 		/*
    187 		 * blkfree errors are unreported, might silently fail
    188 		 * if it cannot read the cylinder group block
    189 		 */
    190 		ffs_blkfree(fs, ump->um_devvp,
    191 		    FFS_DBTOFSB(fs, wd->wd_blkno), wd->wd_len, -1);
    192 	}
    193 
    194 	mutex_enter(&ump->um_lock);
    195 	if (fs->fs_fmod != 0) {
    196 		fs->fs_fmod = 0;
    197 		fs->fs_time = time_second;
    198 		mutex_exit(&ump->um_lock);
    199 		error = ffs_cgupdate(ump, 0);
    200 		KASSERT(error == 0);
    201 	} else {
    202 		mutex_exit(&ump->um_lock);
    203 	}
    204 }
    205 
    206 void
    207 ffs_wapbl_abort_sync_metadata(struct mount *mp, struct wapbl_dealloc *fdealloc)
    208 {
    209 	struct ufsmount *ump = VFSTOUFS(mp);
    210 	struct fs *fs = ump->um_fs;
    211 	struct wapbl_dealloc *wd;
    212 
    213 	for (wd = fdealloc; wd != NULL; wd = TAILQ_NEXT(wd, wd_entries)) {
    214 		/*
    215 		 * Since the above blkfree may have failed, this blkalloc might
    216 		 * fail as well, so don't check its error.  Note that if the
    217 		 * blkfree succeeded above, then this shouldn't fail because
    218 		 * the buffer will be locked in the current transaction.
    219 		 */
    220 		ffs_blkalloc_ump(ump, FFS_DBTOFSB(fs, wd->wd_blkno),
    221 		    wd->wd_len);
    222 	}
    223 }
    224 
    225 static int
    226 wapbl_remove_log(struct mount *mp)
    227 {
    228 	struct ufsmount *ump = VFSTOUFS(mp);
    229 	struct fs *fs = ump->um_fs;
    230 	struct vnode *vp;
    231 	struct inode *ip;
    232 	ino_t log_ino;
    233 	int error;
    234 
    235 	/* If super block layout is too old to support WAPBL, return */
    236 	if (ffs_superblock_layout(fs) < 2)
    237 		return 0;
    238 
    239 	/* If all the log locators are 0, just clean up */
    240 	if (fs->fs_journallocs[0] == 0 &&
    241 	    fs->fs_journallocs[1] == 0 &&
    242 	    fs->fs_journallocs[2] == 0 &&
    243 	    fs->fs_journallocs[3] == 0) {
    244 		DPRINTF("empty locators, just clear\n");
    245 		goto done;
    246 	}
    247 
    248 	switch (fs->fs_journal_location) {
    249 	case UFS_WAPBL_JOURNALLOC_NONE:
    250 		/* nothing! */
    251 		DPRINTF("no log\n");
    252 		break;
    253 
    254 	case UFS_WAPBL_JOURNALLOC_IN_FILESYSTEM:
    255 		log_ino = fs->fs_journallocs[UFS_WAPBL_INFS_INO];
    256 		DPRINTF("in-fs log, ino = %" PRId64 "\n",log_ino);
    257 
    258 		/* if no existing log inode, just clear all fields and bail */
    259 		if (log_ino == 0)
    260 			goto done;
    261 		error = VFS_VGET(mp, log_ino, &vp);
    262 		if (error != 0) {
    263 			printf("%s: %s: vget failed %d\n", __func__,
    264 			    fs->fs_fsmnt, error);
    265 			/* clear out log info on error */
    266 			goto done;
    267 		}
    268 		ip = VTOI(vp);
    269 		KASSERT(log_ino == ip->i_number);
    270 		if ((ip->i_flags & SF_LOG) == 0) {
    271 			printf("%s: %s: try to clear non-log inode "
    272 			    "%" PRId64 "\n", __func__, fs->fs_fsmnt, log_ino);
    273 			vput(vp);
    274 			/* clear out log info on error */
    275 			goto done;
    276 		}
    277 
    278 		/*
    279 		 * remove the log inode by setting its link count back
    280 		 * to zero and bail.
    281 		 */
    282 		ip->i_nlink = 0;
    283 		DIP_ASSIGN(ip, nlink, 0);
    284 		vput(vp);
    285 		break;
    286 
    287 	case UFS_WAPBL_JOURNALLOC_END_PARTITION:
    288 		DPRINTF("end-of-partition log\n");
    289 		/* no extra work required */
    290 		break;
    291 
    292 	default:
    293 		printf("%s: %s: unknown journal type %d\n", __func__,
    294 		    fs->fs_fsmnt, fs->fs_journal_location);
    295 		break;
    296 	}
    297 
    298 
    299 done:
    300 	/* Clear out all previous knowledge of journal */
    301 	fs->fs_journal_version = 0;
    302 	fs->fs_journal_location = 0;
    303 	fs->fs_journal_flags = 0;
    304 	fs->fs_journallocs[0] = 0;
    305 	fs->fs_journallocs[1] = 0;
    306 	fs->fs_journallocs[2] = 0;
    307 	fs->fs_journallocs[3] = 0;
    308 	(void) ffs_sbupdate(ump, MNT_WAIT);
    309 
    310 	return 0;
    311 }
    312 
    313 int
    314 ffs_wapbl_start(struct mount *mp)
    315 {
    316 	struct ufsmount *ump = VFSTOUFS(mp);
    317 	struct fs *fs = ump->um_fs;
    318 	struct vnode *devvp = ump->um_devvp;
    319 	daddr_t off;
    320 	size_t count;
    321 	size_t blksize;
    322 	uint64_t extradata;
    323 	int error;
    324 
    325 	if (mp->mnt_wapbl == NULL) {
    326 		if (fs->fs_journal_flags & UFS_WAPBL_FLAGS_CLEAR_LOG) {
    327 			/* Clear out any existing journal file */
    328 			error = wapbl_remove_log(mp);
    329 			if (error != 0)
    330 				return error;
    331 		}
    332 
    333 		if (mp->mnt_flag & MNT_LOG) {
    334 			KDASSERT(fs->fs_ronly == 0);
    335 
    336 			/* WAPBL needs UFS2 format super block */
    337 			if (ffs_superblock_layout(fs) < 2) {
    338 				printf("%s: %s: fs superblock in old format, "
    339 				   "not journaling\n", __func__,
    340 				   VFSTOUFS(mp)->um_fs->fs_fsmnt);
    341 				mp->mnt_flag &= ~MNT_LOG;
    342 				return EINVAL;
    343 			}
    344 
    345 			error = wapbl_log_position(mp, fs, devvp, &off,
    346 			    &count, &blksize, &extradata);
    347 			if (error)
    348 				return error;
    349 
    350 			/*
    351 			 * Make sure we don't carry over any delayed write
    352 			 * buffers when updating to log. Need to turn off
    353 			 * async termporarily, to prevent ffs_sync() writes
    354 			 * themselves being turned into delayed writes.
    355 			 */
    356 			if (mp->mnt_flag & MNT_UPDATE) {
    357 				int saveflag = mp->mnt_flag & MNT_ASYNC;
    358 				mp->mnt_flag &= ~MNT_ASYNC;
    359 				ffs_sync(mp, MNT_WAIT, FSCRED);
    360 				mp->mnt_flag |= saveflag;
    361 			}
    362 
    363 			error = wapbl_start(&mp->mnt_wapbl, mp, devvp, off,
    364 			    count, blksize, mp->mnt_wapbl_replay,
    365 			    ffs_wapbl_sync_metadata,
    366 			    ffs_wapbl_abort_sync_metadata);
    367 			if (error)
    368 				return error;
    369 
    370 			mp->mnt_wapbl_op = &wapbl_ops;
    371 
    372 #ifdef WAPBL_DEBUG
    373 			printf("%s: %s: enabling logging\n", __func__,
    374 			    fs->fs_fsmnt);
    375 #endif
    376 
    377 			if ((fs->fs_flags & FS_DOWAPBL) == 0) {
    378 				fs->fs_flags |= FS_DOWAPBL;
    379 				if ((error = UFS_WAPBL_BEGIN(mp)) != 0)
    380 					goto out;
    381 				error = ffs_sbupdate(ump, MNT_WAIT);
    382 				if (error) {
    383 					UFS_WAPBL_END(mp);
    384 					goto out;
    385 				}
    386 				UFS_WAPBL_END(mp);
    387 				error = wapbl_flush(mp->mnt_wapbl, 1);
    388 				if (error)
    389 					goto out;
    390 			}
    391 
    392 			/*
    393 			 * XXX discard interferes with block deallocation
    394 			 * registration and hence log consistency
    395 			 */
    396 			if (mp->mnt_flag & MNT_DISCARD) {
    397 				CLR(mp->mnt_flag, MNT_DISCARD);
    398 				printf("%s: %s: disabling discard to preserve log consistency\n", __func__,
    399 				    fs->fs_fsmnt);
    400 
    401 				if (ump->um_discarddata != NULL) {
    402 		                	ffs_discard_finish(ump->um_discarddata,
    403 					    0);
    404 	                		ump->um_discarddata = NULL;
    405 				}
    406 			}
    407 
    408 		} else if (fs->fs_flags & FS_DOWAPBL) {
    409 			fs->fs_fmod = 1;
    410 			fs->fs_flags &= ~FS_DOWAPBL;
    411 		}
    412 	}
    413 
    414 	/*
    415 	 * It is recommended that you finish replay with logging enabled.
    416 	 * However, even if logging is not enabled, the remaining log
    417 	 * replay should be safely recoverable with an fsck, so perform
    418 	 * it anyway.
    419 	 */
    420 	if ((fs->fs_ronly == 0) && mp->mnt_wapbl_replay) {
    421 		int saveflag = mp->mnt_flag & MNT_RDONLY;
    422 		/*
    423 		 * Make sure MNT_RDONLY is not set so that the inode
    424 		 * cleanup in ufs_inactive will actually do its work.
    425 		 */
    426 		mp->mnt_flag &= ~MNT_RDONLY;
    427 		ffs_wapbl_replay_finish(mp);
    428 		mp->mnt_flag |= saveflag;
    429 		KASSERT(fs->fs_ronly == 0);
    430 	}
    431 
    432 	return 0;
    433 out:
    434 	ffs_wapbl_stop(mp, MNT_FORCE);
    435 	return error;
    436 }
    437 
    438 int
    439 ffs_wapbl_stop(struct mount *mp, int force)
    440 {
    441 	struct ufsmount *ump = VFSTOUFS(mp);
    442 	struct fs *fs = ump->um_fs;
    443 	int error;
    444 
    445 	if (mp->mnt_wapbl) {
    446 		KDASSERT(fs->fs_ronly == 0);
    447 
    448 		/*
    449 		 * Make sure turning off FS_DOWAPBL is only removed
    450 		 * as the only change in the final flush since otherwise
    451 		 * a transaction may reorder writes.
    452 		 */
    453 		error = wapbl_flush(mp->mnt_wapbl, 1);
    454 		if (error && !force)
    455 			return error;
    456 		if (error && force)
    457 			goto forceout;
    458 		error = UFS_WAPBL_BEGIN(mp);
    459 		if (error && !force)
    460 			return error;
    461 		if (error && force)
    462 			goto forceout;
    463 		KASSERT(fs->fs_flags & FS_DOWAPBL);
    464 
    465 		fs->fs_flags &= ~FS_DOWAPBL;
    466 		error = ffs_sbupdate(ump, MNT_WAIT);
    467 		KASSERT(error == 0);	/* XXX a bit drastic! */
    468 		UFS_WAPBL_END(mp);
    469 	forceout:
    470 		error = wapbl_stop(mp->mnt_wapbl, force);
    471 		if (error) {
    472 			KASSERT(!force);
    473 			fs->fs_flags |= FS_DOWAPBL;
    474 			return error;
    475 		}
    476 		fs->fs_flags &= ~FS_DOWAPBL; /* Repeat in case of forced error */
    477 		mp->mnt_wapbl = NULL;
    478 
    479 #ifdef WAPBL_DEBUG
    480 		printf("%s: %s: disabled logging\n", __func__, fs->fs_fsmnt);
    481 #endif
    482 	}
    483 
    484 	return 0;
    485 }
    486 
    487 int
    488 ffs_wapbl_replay_start(struct mount *mp, struct fs *fs, struct vnode *devvp)
    489 {
    490 	int error;
    491 	daddr_t off;
    492 	size_t count;
    493 	size_t blksize;
    494 	uint64_t extradata;
    495 
    496 	/*
    497 	 * WAPBL needs UFS2 format super block, if we got here with a
    498 	 * UFS1 format super block something is amiss...
    499 	 */
    500 	if (ffs_superblock_layout(fs) < 2)
    501 		return EINVAL;
    502 
    503 	error = wapbl_log_position(mp, fs, devvp, &off, &count, &blksize,
    504 	    &extradata);
    505 
    506 	if (error)
    507 		return error;
    508 
    509 	error = wapbl_replay_start(&mp->mnt_wapbl_replay, devvp, off,
    510 		count, blksize);
    511 	if (error)
    512 		return error;
    513 
    514 	mp->mnt_wapbl_op = &wapbl_ops;
    515 
    516 	return 0;
    517 }
    518 
    519 /*
    520  * If the superblock doesn't already have a recorded journal location
    521  * then we allocate the journal in one of two positions:
    522  *
    523  *  - At the end of the partition after the filesystem if there's
    524  *    enough space.  "Enough space" is defined as >= 1MB of journal
    525  *    per 1GB of filesystem or 64MB, whichever is smaller.
    526  *
    527  *  - Inside the filesystem.  We try to allocate a contiguous journal
    528  *    based on the total filesystem size - the target is 1MB of journal
    529  *    per 1GB of filesystem, up to a maximum journal size of 64MB.  As
    530  *    a worst case allowing for fragmentation, we'll allocate a journal
    531  *    1/4 of the desired size but never smaller than 1MB.
    532  *
    533  *    XXX In the future if we allow for non-contiguous journal files we
    534  *    can tighten the above restrictions.
    535  *
    536  * XXX
    537  * These seems like a lot of duplication both here and in some of
    538  * the userland tools (fsck_ffs, dumpfs, tunefs) with similar
    539  * "switch (fs_journal_location)" constructs.  Can we centralise
    540  * this sort of code somehow/somewhere?
    541  */
    542 static int
    543 wapbl_log_position(struct mount *mp, struct fs *fs, struct vnode *devvp,
    544     daddr_t *startp, size_t *countp, size_t *blksizep, uint64_t *extradatap)
    545 {
    546 	struct ufsmount *ump = VFSTOUFS(mp);
    547 	daddr_t logstart, logend, desired_logsize;
    548 	uint64_t numsecs;
    549 	unsigned secsize;
    550 	int error, location;
    551 
    552 	if (fs->fs_journal_version == UFS_WAPBL_VERSION) {
    553 		switch (fs->fs_journal_location) {
    554 		case UFS_WAPBL_JOURNALLOC_END_PARTITION:
    555 			DPRINTF("found existing end-of-partition log\n");
    556 			*startp = fs->fs_journallocs[UFS_WAPBL_EPART_ADDR];
    557 			*countp = fs->fs_journallocs[UFS_WAPBL_EPART_COUNT];
    558 			*blksizep = fs->fs_journallocs[UFS_WAPBL_EPART_BLKSZ];
    559 			DPRINTF(" start = %" PRId64 ", size = %zu, "
    560 			    "blksize = %zu\n", *startp, *countp, *blksizep);
    561 			return 0;
    562 
    563 		case UFS_WAPBL_JOURNALLOC_IN_FILESYSTEM:
    564 			DPRINTF("found existing in-filesystem log\n");
    565 			*startp = fs->fs_journallocs[UFS_WAPBL_INFS_ADDR];
    566 			*countp = fs->fs_journallocs[UFS_WAPBL_INFS_COUNT];
    567 			*blksizep = fs->fs_journallocs[UFS_WAPBL_INFS_BLKSZ];
    568 			DPRINTF(" start = %" PRId64 ", size = %zu, "
    569 			    "blksize = %zu\n", *startp, *countp, *blksizep);
    570 			return 0;
    571 
    572 		default:
    573 			printf("%s: %s: unknown journal type %d\n", __func__,
    574 			    fs->fs_fsmnt, fs->fs_journal_location);
    575 			return EINVAL;
    576 		}
    577 	}
    578 
    579 	desired_logsize =
    580 	    ffs_lfragtosize(fs, fs->fs_size) / UFS_WAPBL_JOURNAL_SCALE;
    581 	DPRINTF("desired log size = %" PRId64 " kB\n", desired_logsize / 1024);
    582 	desired_logsize = uimax(desired_logsize, UFS_WAPBL_MIN_JOURNAL_SIZE);
    583 	desired_logsize = uimin(desired_logsize, UFS_WAPBL_MAX_JOURNAL_SIZE);
    584 	DPRINTF("adjusted desired log size = %" PRId64 " kB\n",
    585 	    desired_logsize / 1024);
    586 
    587 	/* Is there space after after filesystem on partition for log? */
    588 	logstart = FFS_FSBTODB(fs, fs->fs_size);
    589 	error = getdisksize(devvp, &numsecs, &secsize);
    590 	if (error)
    591 		return error;
    592 	KDASSERT(secsize != 0);
    593 	logend = btodb(numsecs * secsize);
    594 
    595 	if (dbtob(logend - logstart) >= desired_logsize) {
    596 		DPRINTF("enough space, use end-of-partition log\n");
    597 
    598 		location = UFS_WAPBL_JOURNALLOC_END_PARTITION;
    599 		*blksizep = secsize;
    600 
    601 		*startp = logstart;
    602 		*countp = (logend - logstart);
    603 		*extradatap = 0;
    604 
    605 		/* convert to physical block numbers */
    606 		*startp = dbtob(*startp) / secsize;
    607 		*countp = dbtob(*countp) / secsize;
    608 
    609 		fs->fs_journallocs[UFS_WAPBL_EPART_ADDR] = *startp;
    610 		fs->fs_journallocs[UFS_WAPBL_EPART_COUNT] = *countp;
    611 		fs->fs_journallocs[UFS_WAPBL_EPART_BLKSZ] = *blksizep;
    612 		fs->fs_journallocs[UFS_WAPBL_EPART_UNUSED] = *extradatap;
    613 	} else {
    614 		DPRINTF("end-of-partition has only %" PRId64 " free\n",
    615 		    logend - logstart);
    616 
    617 		location = UFS_WAPBL_JOURNALLOC_IN_FILESYSTEM;
    618 		*blksizep = secsize;
    619 
    620 		error = wapbl_create_infs_log(mp, fs, devvp,
    621 		                  startp, countp, extradatap);
    622 		ffs_sync(mp, MNT_WAIT, FSCRED);
    623 
    624 		/* convert to physical block numbers */
    625 		*startp = dbtob(*startp) / secsize;
    626 		*countp = dbtob(*countp) / secsize;
    627 
    628 		fs->fs_journallocs[UFS_WAPBL_INFS_ADDR] = *startp;
    629 		fs->fs_journallocs[UFS_WAPBL_INFS_COUNT] = *countp;
    630 		fs->fs_journallocs[UFS_WAPBL_INFS_BLKSZ] = *blksizep;
    631 		fs->fs_journallocs[UFS_WAPBL_INFS_INO] = *extradatap;
    632 	}
    633 
    634 	if (error == 0) {
    635 		/* update superblock with log location */
    636 		fs->fs_journal_version = UFS_WAPBL_VERSION;
    637 		fs->fs_journal_location = location;
    638 		fs->fs_journal_flags = 0;
    639 
    640 		error = ffs_sbupdate(ump, MNT_WAIT);
    641 	}
    642 
    643 	return error;
    644 }
    645 
    646 /*
    647  * Try to create a journal log inside the filesystem.
    648  */
    649 static int
    650 wapbl_create_infs_log(struct mount *mp, struct fs *fs, struct vnode *devvp,
    651     daddr_t *startp, size_t *countp, uint64_t *extradatap)
    652 {
    653 	struct vnode *vp, *rvp;
    654 	struct vattr va;
    655 	struct inode *ip;
    656 	int error;
    657 
    658 	if ((error = VFS_ROOT(mp, &rvp)) != 0)
    659 		return error;
    660 
    661 	vattr_null(&va);
    662 	va.va_type = VREG;
    663 	va.va_mode = 0;
    664 
    665 	error = vcache_new(mp, rvp, &va, NOCRED, NULL, &vp);
    666 	vput(rvp);
    667 	if (error)
    668 		return error;
    669 
    670 	error = vn_lock(vp, LK_EXCLUSIVE);
    671 	if (error) {
    672 		vrele(vp);
    673 		return error;
    674 	}
    675 
    676 	ip = VTOI(vp);
    677 	ip->i_flags = SF_LOG;
    678 	DIP_ASSIGN(ip, flags, ip->i_flags);
    679 	ip->i_nlink = 1;
    680 	DIP_ASSIGN(ip, nlink, 1);
    681 	ip->i_flag |= IN_ACCESS | IN_CHANGE | IN_UPDATE;
    682 	ffs_update(vp, NULL, NULL, UPDATE_WAIT);
    683 
    684 	if ((error = wapbl_allocate_log_file(mp, vp,
    685 	                 startp, countp, extradatap)) != 0) {
    686 		/*
    687 		 * If we couldn't allocate the space for the log file,
    688 		 * remove the inode by setting its link count back to
    689 		 * zero and bail.
    690 		 */
    691 		ip->i_nlink = 0;
    692 		DIP_ASSIGN(ip, nlink, 0);
    693 		vput(vp);
    694 
    695 		return error;
    696 	}
    697 
    698 	/*
    699 	 * Now that we have the place-holder inode for the journal,
    700 	 * we don't need the vnode ever again.
    701 	 */
    702 	vput(vp);
    703 
    704 	return 0;
    705 }
    706 
    707 int
    708 wapbl_allocate_log_file(struct mount *mp, struct vnode *vp,
    709     daddr_t *startp, size_t *countp, uint64_t *extradatap)
    710 {
    711 	struct ufsmount *ump = VFSTOUFS(mp);
    712 	struct fs *fs = ump->um_fs;
    713 	daddr_t addr, indir_addr;
    714 	off_t logsize;
    715 	size_t size;
    716 	int error;
    717 
    718 	logsize = 0;
    719 	/* check if there's a suggested log size */
    720 	if (fs->fs_journal_flags & UFS_WAPBL_FLAGS_CREATE_LOG &&
    721 	    fs->fs_journal_location == UFS_WAPBL_JOURNALLOC_IN_FILESYSTEM)
    722 		logsize = fs->fs_journallocs[UFS_WAPBL_INFS_COUNT];
    723 
    724 	if (vp->v_size > 0) {
    725 		printf("%s: %s: file size (%" PRId64 ") non zero\n", __func__,
    726 		    fs->fs_fsmnt, vp->v_size);
    727 		return EEXIST;
    728 	}
    729 	wapbl_find_log_start(mp, vp, logsize, &addr, &indir_addr, &size);
    730 	if (addr == 0) {
    731 		printf("%s: %s: log not allocated, largest extent is "
    732 		    "%" PRId64 "MB\n", __func__, fs->fs_fsmnt,
    733 		    ffs_lblktosize(fs, size) / (1024 * 1024));
    734 		return ENOSPC;
    735 	}
    736 
    737 	logsize = ffs_lblktosize(fs, size);	/* final log size */
    738 
    739 	VTOI(vp)->i_ffs_first_data_blk = addr;
    740 	VTOI(vp)->i_ffs_first_indir_blk = indir_addr;
    741 
    742 	error = GOP_ALLOC(vp, 0, logsize, B_CONTIG, FSCRED);
    743 	if (error) {
    744 		printf("%s: %s: GOP_ALLOC error %d\n", __func__, fs->fs_fsmnt,
    745 		    error);
    746 		return error;
    747 	}
    748 
    749 	*startp     = FFS_FSBTODB(fs, addr);
    750 	*countp     = btodb(logsize);
    751 	*extradatap = VTOI(vp)->i_number;
    752 
    753 	return 0;
    754 }
    755 
    756 /*
    757  * Find a suitable location for the journal in the filesystem.
    758  *
    759  * Our strategy here is to look for a contiguous block of free space
    760  * at least "logfile" MB in size (plus room for any indirect blocks).
    761  * We start at the middle of the filesystem and check each cylinder
    762  * group working outwards.  If "logfile" MB is not available as a
    763  * single contigous chunk, then return the address and size of the
    764  * largest chunk found.
    765  *
    766  * XXX
    767  * At what stage does the search fail?  Is if the largest space we could
    768  * find is less than a quarter the requested space reasonable?  If the
    769  * search fails entirely, return a block address if "0" it indicate this.
    770  */
    771 static void
    772 wapbl_find_log_start(struct mount *mp, struct vnode *vp, off_t logsize,
    773     daddr_t *addr, daddr_t *indir_addr, size_t *size)
    774 {
    775 	struct ufsmount *ump = VFSTOUFS(mp);
    776 	struct fs *fs = ump->um_fs;
    777 	struct vnode *devvp = ump->um_devvp;
    778 	struct cg *cgp;
    779 	struct buf *bp;
    780 	uint8_t *blksfree;
    781 	daddr_t blkno, best_addr, start_addr;
    782 	daddr_t desired_blks, min_desired_blks;
    783 	daddr_t freeblks, best_blks;
    784 	int bpcg, cg, error, fixedsize, indir_blks, n, s;
    785 	const int needswap = UFS_FSNEEDSWAP(fs);
    786 
    787 	if (logsize == 0) {
    788 		fixedsize = 0;	/* We can adjust the size if tight */
    789 		logsize = ffs_lfragtosize(fs, fs->fs_dsize) /
    790 		    UFS_WAPBL_JOURNAL_SCALE;
    791 		DPRINTF("suggested log size = %" PRId64 "\n", logsize);
    792 		logsize = uimax(logsize, UFS_WAPBL_MIN_JOURNAL_SIZE);
    793 		logsize = uimin(logsize, UFS_WAPBL_MAX_JOURNAL_SIZE);
    794 		DPRINTF("adjusted log size = %" PRId64 "\n", logsize);
    795 	} else {
    796 		fixedsize = 1;
    797 		DPRINTF("fixed log size = %" PRId64 "\n", logsize);
    798 	}
    799 
    800 	desired_blks = logsize / fs->fs_bsize;
    801 	DPRINTF("desired blocks = %" PRId64 "\n", desired_blks);
    802 
    803 	/* add in number of indirect blocks needed */
    804 	indir_blks = 0;
    805 	if (desired_blks >= UFS_NDADDR) {
    806 		struct indir indirs[UFS_NIADDR + 2];
    807 		int num;
    808 
    809 		error = ufs_getlbns(vp, desired_blks, indirs, &num);
    810 		if (error) {
    811 			printf("%s: %s:  ufs_getlbns failed, error %d!\n",
    812 			    __func__, fs->fs_fsmnt, error);
    813 			goto bad;
    814 		}
    815 
    816 		switch (num) {
    817 		case 2:
    818 			indir_blks = 1;		/* 1st level indirect */
    819 			break;
    820 		case 3:
    821 			indir_blks = 1 +	/* 1st level indirect */
    822 			    1 +			/* 2nd level indirect */
    823 			    indirs[1].in_off + 1; /* extra 1st level indirect */
    824 			break;
    825 		default:
    826 			printf("%s: %s: unexpected numlevels %d from "
    827 			    "ufs_getlbns\n", __func__, fs->fs_fsmnt, num);
    828 			*size = 0;
    829 			goto bad;
    830 		}
    831 		desired_blks += indir_blks;
    832 	}
    833 	DPRINTF("desired blocks = %" PRId64 " (including indirect)\n",
    834 	    desired_blks);
    835 
    836 	/*
    837 	 * If a specific size wasn't requested, allow for a smaller log
    838 	 * if we're really tight for space...
    839 	 */
    840 	min_desired_blks = desired_blks;
    841 	if (!fixedsize)
    842 		min_desired_blks = desired_blks / 4;
    843 
    844 	/* Look at number of blocks per CG.  If it's too small, bail early. */
    845 	bpcg = ffs_fragstoblks(fs, fs->fs_fpg);
    846 	if (min_desired_blks > bpcg) {
    847 		printf("%s: %s: cylinder group size of %" PRId64 " MB "
    848 		    " is not big enough for journal\n", __func__, fs->fs_fsmnt,
    849 		    ffs_lblktosize(fs, bpcg) / (1024 * 1024));
    850 		goto bad;
    851 	}
    852 
    853 	/*
    854 	 * Start with the middle cylinder group, and search outwards in
    855 	 * both directions until we either find the requested log size
    856 	 * or reach the start/end of the file system.  If we reach the
    857 	 * start/end without finding enough space for the full requested
    858 	 * log size, use the largest extent found if it is large enough
    859 	 * to satisfy the our minimum size.
    860 	 *
    861 	 * XXX
    862 	 * Can we just use the cluster contigsum stuff (esp on UFS2)
    863 	 * here to simplify this search code?
    864 	 */
    865 	best_addr = 0;
    866 	best_blks = 0;
    867 	for (cg = fs->fs_ncg / 2, s = 0, n = 1;
    868 	    best_blks < desired_blks && cg >= 0 && cg < fs->fs_ncg;
    869 	    s++, n = -n, cg += n * s) {
    870 		DPRINTF("check cg %d of %d\n", cg, fs->fs_ncg);
    871 		error = bread(devvp, FFS_FSBTODB(fs, cgtod(fs, cg)),
    872 		    fs->fs_cgsize, 0, &bp);
    873 		if (error) {
    874 			continue;
    875 		}
    876 		cgp = (struct cg *)bp->b_data;
    877 		if (!cg_chkmagic(cgp, UFS_FSNEEDSWAP(fs))) {
    878 			brelse(bp, 0);
    879 			continue;
    880 		}
    881 
    882 		blksfree = cg_blksfree(cgp, needswap);
    883 
    884 		for (blkno = 0; blkno < bpcg;) {
    885 			/* look for next free block */
    886 			/* XXX use scanc() and fragtbl[] here? */
    887 			for (; blkno < bpcg - min_desired_blks; blkno++)
    888 				if (ffs_isblock(fs, blksfree, blkno))
    889 					break;
    890 
    891 			/* past end of search space in this CG? */
    892 			if (blkno >= bpcg - min_desired_blks)
    893 				break;
    894 
    895 			/* count how many free blocks in this extent */
    896 			start_addr = blkno;
    897 			for (freeblks = 0; blkno < bpcg; blkno++, freeblks++)
    898 				if (!ffs_isblock(fs, blksfree, blkno))
    899 					break;
    900 
    901 			if (freeblks > best_blks) {
    902 				best_blks = freeblks;
    903 				best_addr = ffs_blkstofrags(fs, start_addr) +
    904 				    cgbase(fs, cg);
    905 
    906 				if (freeblks >= desired_blks) {
    907 					DPRINTF("found len %" PRId64
    908 					    " at offset %" PRId64 " in gc\n",
    909 					    freeblks, start_addr);
    910 					break;
    911 				}
    912 			}
    913 		}
    914 		brelse(bp, 0);
    915 	}
    916 	DPRINTF("best found len = %" PRId64 ", wanted %" PRId64
    917 	    " at addr %" PRId64 "\n", best_blks, desired_blks, best_addr);
    918 
    919 	if (best_blks < min_desired_blks) {
    920 		*addr = 0;
    921 		*indir_addr = 0;
    922 	} else {
    923 		/* put indirect blocks at start, and data blocks after */
    924 		*addr = best_addr + ffs_blkstofrags(fs, indir_blks);
    925 		*indir_addr = best_addr;
    926 	}
    927 	*size = uimin(desired_blks, best_blks) - indir_blks;
    928 	return;
    929 
    930 bad:
    931 	*addr = 0;
    932 	*indir_addr = 0;
    933 	*size = 0;
    934 	return;
    935 }
    936