xref: /linux-6.15/fs/bcachefs/super.c (revision dfd76010)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * bcachefs setup/teardown code, and some metadata io - read a superblock and
4  * figure out what to do with it.
5  *
6  * Copyright 2010, 2011 Kent Overstreet <[email protected]>
7  * Copyright 2012 Google, Inc.
8  */
9 
10 #include "bcachefs.h"
11 #include "alloc_background.h"
12 #include "alloc_foreground.h"
13 #include "bkey_sort.h"
14 #include "btree_cache.h"
15 #include "btree_gc.h"
16 #include "btree_journal_iter.h"
17 #include "btree_key_cache.h"
18 #include "btree_node_scan.h"
19 #include "btree_update_interior.h"
20 #include "btree_io.h"
21 #include "btree_write_buffer.h"
22 #include "buckets_waiting_for_journal.h"
23 #include "chardev.h"
24 #include "checksum.h"
25 #include "clock.h"
26 #include "compress.h"
27 #include "debug.h"
28 #include "disk_accounting.h"
29 #include "disk_groups.h"
30 #include "ec.h"
31 #include "errcode.h"
32 #include "error.h"
33 #include "fs.h"
34 #include "fs-io.h"
35 #include "fs-io-buffered.h"
36 #include "fs-io-direct.h"
37 #include "fsck.h"
38 #include "inode.h"
39 #include "io_read.h"
40 #include "io_write.h"
41 #include "journal.h"
42 #include "journal_reclaim.h"
43 #include "journal_seq_blacklist.h"
44 #include "move.h"
45 #include "migrate.h"
46 #include "movinggc.h"
47 #include "nocow_locking.h"
48 #include "quota.h"
49 #include "rebalance.h"
50 #include "recovery.h"
51 #include "replicas.h"
52 #include "sb-clean.h"
53 #include "sb-counters.h"
54 #include "sb-errors.h"
55 #include "sb-members.h"
56 #include "snapshot.h"
57 #include "subvolume.h"
58 #include "super.h"
59 #include "super-io.h"
60 #include "sysfs.h"
61 #include "thread_with_file.h"
62 #include "trace.h"
63 
64 #include <linux/backing-dev.h>
65 #include <linux/blkdev.h>
66 #include <linux/debugfs.h>
67 #include <linux/device.h>
68 #include <linux/idr.h>
69 #include <linux/module.h>
70 #include <linux/percpu.h>
71 #include <linux/random.h>
72 #include <linux/sysfs.h>
73 
74 MODULE_LICENSE("GPL");
75 MODULE_AUTHOR("Kent Overstreet <[email protected]>");
76 MODULE_DESCRIPTION("bcachefs filesystem");
77 
78 const char * const bch2_fs_flag_strs[] = {
79 #define x(n)		#n,
80 	BCH_FS_FLAGS()
81 #undef x
82 	NULL
83 };
84 
85 void bch2_print_str(struct bch_fs *c, const char *str)
86 {
87 #ifdef __KERNEL__
88 	struct stdio_redirect *stdio = bch2_fs_stdio_redirect(c);
89 
90 	if (unlikely(stdio)) {
91 		bch2_stdio_redirect_printf(stdio, true, "%s", str);
92 		return;
93 	}
94 #endif
95 	bch2_print_string_as_lines(KERN_ERR, str);
96 }
97 
98 __printf(2, 0)
99 static void bch2_print_maybe_redirect(struct stdio_redirect *stdio, const char *fmt, va_list args)
100 {
101 #ifdef __KERNEL__
102 	if (unlikely(stdio)) {
103 		if (fmt[0] == KERN_SOH[0])
104 			fmt += 2;
105 
106 		bch2_stdio_redirect_vprintf(stdio, true, fmt, args);
107 		return;
108 	}
109 #endif
110 	vprintk(fmt, args);
111 }
112 
113 void bch2_print_opts(struct bch_opts *opts, const char *fmt, ...)
114 {
115 	struct stdio_redirect *stdio = (void *)(unsigned long)opts->stdio;
116 
117 	va_list args;
118 	va_start(args, fmt);
119 	bch2_print_maybe_redirect(stdio, fmt, args);
120 	va_end(args);
121 }
122 
123 void __bch2_print(struct bch_fs *c, const char *fmt, ...)
124 {
125 	struct stdio_redirect *stdio = bch2_fs_stdio_redirect(c);
126 
127 	va_list args;
128 	va_start(args, fmt);
129 	bch2_print_maybe_redirect(stdio, fmt, args);
130 	va_end(args);
131 }
132 
133 #define KTYPE(type)							\
134 static const struct attribute_group type ## _group = {			\
135 	.attrs = type ## _files						\
136 };									\
137 									\
138 static const struct attribute_group *type ## _groups[] = {		\
139 	&type ## _group,						\
140 	NULL								\
141 };									\
142 									\
143 static const struct kobj_type type ## _ktype = {			\
144 	.release	= type ## _release,				\
145 	.sysfs_ops	= &type ## _sysfs_ops,				\
146 	.default_groups = type ## _groups				\
147 }
148 
149 static void bch2_fs_release(struct kobject *);
150 static void bch2_dev_release(struct kobject *);
151 static void bch2_fs_counters_release(struct kobject *k)
152 {
153 }
154 
155 static void bch2_fs_internal_release(struct kobject *k)
156 {
157 }
158 
159 static void bch2_fs_opts_dir_release(struct kobject *k)
160 {
161 }
162 
163 static void bch2_fs_time_stats_release(struct kobject *k)
164 {
165 }
166 
167 KTYPE(bch2_fs);
168 KTYPE(bch2_fs_counters);
169 KTYPE(bch2_fs_internal);
170 KTYPE(bch2_fs_opts_dir);
171 KTYPE(bch2_fs_time_stats);
172 KTYPE(bch2_dev);
173 
174 static struct kset *bcachefs_kset;
175 static LIST_HEAD(bch_fs_list);
176 static DEFINE_MUTEX(bch_fs_list_lock);
177 
178 DECLARE_WAIT_QUEUE_HEAD(bch2_read_only_wait);
179 
180 static void bch2_dev_unlink(struct bch_dev *);
181 static void bch2_dev_free(struct bch_dev *);
182 static int bch2_dev_alloc(struct bch_fs *, unsigned);
183 static int bch2_dev_sysfs_online(struct bch_fs *, struct bch_dev *);
184 static void bch2_dev_io_ref_stop(struct bch_dev *, int);
185 static void __bch2_dev_read_only(struct bch_fs *, struct bch_dev *);
186 
187 struct bch_fs *bch2_dev_to_fs(dev_t dev)
188 {
189 	struct bch_fs *c;
190 
191 	mutex_lock(&bch_fs_list_lock);
192 	rcu_read_lock();
193 
194 	list_for_each_entry(c, &bch_fs_list, list)
195 		for_each_member_device_rcu(c, ca, NULL)
196 			if (ca->disk_sb.bdev && ca->disk_sb.bdev->bd_dev == dev) {
197 				closure_get(&c->cl);
198 				goto found;
199 			}
200 	c = NULL;
201 found:
202 	rcu_read_unlock();
203 	mutex_unlock(&bch_fs_list_lock);
204 
205 	return c;
206 }
207 
208 static struct bch_fs *__bch2_uuid_to_fs(__uuid_t uuid)
209 {
210 	struct bch_fs *c;
211 
212 	lockdep_assert_held(&bch_fs_list_lock);
213 
214 	list_for_each_entry(c, &bch_fs_list, list)
215 		if (!memcmp(&c->disk_sb.sb->uuid, &uuid, sizeof(uuid)))
216 			return c;
217 
218 	return NULL;
219 }
220 
221 struct bch_fs *bch2_uuid_to_fs(__uuid_t uuid)
222 {
223 	struct bch_fs *c;
224 
225 	mutex_lock(&bch_fs_list_lock);
226 	c = __bch2_uuid_to_fs(uuid);
227 	if (c)
228 		closure_get(&c->cl);
229 	mutex_unlock(&bch_fs_list_lock);
230 
231 	return c;
232 }
233 
234 /* Filesystem RO/RW: */
235 
236 /*
237  * For startup/shutdown of RW stuff, the dependencies are:
238  *
239  * - foreground writes depend on copygc and rebalance (to free up space)
240  *
241  * - copygc and rebalance depend on mark and sweep gc (they actually probably
242  *   don't because they either reserve ahead of time or don't block if
243  *   allocations fail, but allocations can require mark and sweep gc to run
244  *   because of generation number wraparound)
245  *
246  * - all of the above depends on the allocator threads
247  *
248  * - allocator depends on the journal (when it rewrites prios and gens)
249  */
250 
251 static void __bch2_fs_read_only(struct bch_fs *c)
252 {
253 	unsigned clean_passes = 0;
254 	u64 seq = 0;
255 
256 	bch2_fs_ec_stop(c);
257 	bch2_open_buckets_stop(c, NULL, true);
258 	bch2_rebalance_stop(c);
259 	bch2_copygc_stop(c);
260 	bch2_fs_ec_flush(c);
261 
262 	bch_verbose(c, "flushing journal and stopping allocators, journal seq %llu",
263 		    journal_cur_seq(&c->journal));
264 
265 	do {
266 		clean_passes++;
267 
268 		if (bch2_btree_interior_updates_flush(c) ||
269 		    bch2_btree_write_buffer_flush_going_ro(c) ||
270 		    bch2_journal_flush_all_pins(&c->journal) ||
271 		    bch2_btree_flush_all_writes(c) ||
272 		    seq != atomic64_read(&c->journal.seq)) {
273 			seq = atomic64_read(&c->journal.seq);
274 			clean_passes = 0;
275 		}
276 	} while (clean_passes < 2);
277 
278 	bch_verbose(c, "flushing journal and stopping allocators complete, journal seq %llu",
279 		    journal_cur_seq(&c->journal));
280 
281 	if (test_bit(JOURNAL_replay_done, &c->journal.flags) &&
282 	    !test_bit(BCH_FS_emergency_ro, &c->flags))
283 		set_bit(BCH_FS_clean_shutdown, &c->flags);
284 
285 	bch2_fs_journal_stop(&c->journal);
286 
287 	bch_info(c, "%sclean shutdown complete, journal seq %llu",
288 		 test_bit(BCH_FS_clean_shutdown, &c->flags) ? "" : "un",
289 		 c->journal.seq_ondisk);
290 
291 	/*
292 	 * After stopping journal:
293 	 */
294 	for_each_member_device(c, ca) {
295 		bch2_dev_io_ref_stop(ca, WRITE);
296 		bch2_dev_allocator_remove(c, ca);
297 	}
298 }
299 
300 #ifndef BCH_WRITE_REF_DEBUG
301 static void bch2_writes_disabled(struct percpu_ref *writes)
302 {
303 	struct bch_fs *c = container_of(writes, struct bch_fs, writes);
304 
305 	set_bit(BCH_FS_write_disable_complete, &c->flags);
306 	wake_up(&bch2_read_only_wait);
307 }
308 #endif
309 
310 void bch2_fs_read_only(struct bch_fs *c)
311 {
312 	if (!test_bit(BCH_FS_rw, &c->flags)) {
313 		bch2_journal_reclaim_stop(&c->journal);
314 		return;
315 	}
316 
317 	BUG_ON(test_bit(BCH_FS_write_disable_complete, &c->flags));
318 
319 	bch_verbose(c, "going read-only");
320 
321 	/*
322 	 * Block new foreground-end write operations from starting - any new
323 	 * writes will return -EROFS:
324 	 */
325 	set_bit(BCH_FS_going_ro, &c->flags);
326 #ifndef BCH_WRITE_REF_DEBUG
327 	percpu_ref_kill(&c->writes);
328 #else
329 	for (unsigned i = 0; i < BCH_WRITE_REF_NR; i++)
330 		bch2_write_ref_put(c, i);
331 #endif
332 
333 	/*
334 	 * If we're not doing an emergency shutdown, we want to wait on
335 	 * outstanding writes to complete so they don't see spurious errors due
336 	 * to shutting down the allocator:
337 	 *
338 	 * If we are doing an emergency shutdown outstanding writes may
339 	 * hang until we shutdown the allocator so we don't want to wait
340 	 * on outstanding writes before shutting everything down - but
341 	 * we do need to wait on them before returning and signalling
342 	 * that going RO is complete:
343 	 */
344 	wait_event(bch2_read_only_wait,
345 		   test_bit(BCH_FS_write_disable_complete, &c->flags) ||
346 		   test_bit(BCH_FS_emergency_ro, &c->flags));
347 
348 	bool writes_disabled = test_bit(BCH_FS_write_disable_complete, &c->flags);
349 	if (writes_disabled)
350 		bch_verbose(c, "finished waiting for writes to stop");
351 
352 	__bch2_fs_read_only(c);
353 
354 	wait_event(bch2_read_only_wait,
355 		   test_bit(BCH_FS_write_disable_complete, &c->flags));
356 
357 	if (!writes_disabled)
358 		bch_verbose(c, "finished waiting for writes to stop");
359 
360 	clear_bit(BCH_FS_write_disable_complete, &c->flags);
361 	clear_bit(BCH_FS_going_ro, &c->flags);
362 	clear_bit(BCH_FS_rw, &c->flags);
363 
364 	if (!bch2_journal_error(&c->journal) &&
365 	    !test_bit(BCH_FS_error, &c->flags) &&
366 	    !test_bit(BCH_FS_emergency_ro, &c->flags) &&
367 	    test_bit(BCH_FS_started, &c->flags) &&
368 	    test_bit(BCH_FS_clean_shutdown, &c->flags) &&
369 	    c->recovery_pass_done >= BCH_RECOVERY_PASS_journal_replay) {
370 		BUG_ON(c->journal.last_empty_seq != journal_cur_seq(&c->journal));
371 		BUG_ON(atomic_long_read(&c->btree_cache.nr_dirty));
372 		BUG_ON(atomic_long_read(&c->btree_key_cache.nr_dirty));
373 		BUG_ON(c->btree_write_buffer.inc.keys.nr);
374 		BUG_ON(c->btree_write_buffer.flushing.keys.nr);
375 		bch2_verify_accounting_clean(c);
376 
377 		bch_verbose(c, "marking filesystem clean");
378 		bch2_fs_mark_clean(c);
379 	} else {
380 		bch_verbose(c, "done going read-only, filesystem not clean");
381 	}
382 }
383 
384 static void bch2_fs_read_only_work(struct work_struct *work)
385 {
386 	struct bch_fs *c =
387 		container_of(work, struct bch_fs, read_only_work);
388 
389 	down_write(&c->state_lock);
390 	bch2_fs_read_only(c);
391 	up_write(&c->state_lock);
392 }
393 
394 static void bch2_fs_read_only_async(struct bch_fs *c)
395 {
396 	queue_work(system_long_wq, &c->read_only_work);
397 }
398 
399 bool bch2_fs_emergency_read_only(struct bch_fs *c)
400 {
401 	bool ret = !test_and_set_bit(BCH_FS_emergency_ro, &c->flags);
402 
403 	bch2_journal_halt(&c->journal);
404 	bch2_fs_read_only_async(c);
405 
406 	wake_up(&bch2_read_only_wait);
407 	return ret;
408 }
409 
410 bool bch2_fs_emergency_read_only_locked(struct bch_fs *c)
411 {
412 	bool ret = !test_and_set_bit(BCH_FS_emergency_ro, &c->flags);
413 
414 	bch2_journal_halt_locked(&c->journal);
415 	bch2_fs_read_only_async(c);
416 
417 	wake_up(&bch2_read_only_wait);
418 	return ret;
419 }
420 
421 static int bch2_fs_read_write_late(struct bch_fs *c)
422 {
423 	int ret;
424 
425 	/*
426 	 * Data move operations can't run until after check_snapshots has
427 	 * completed, and bch2_snapshot_is_ancestor() is available.
428 	 *
429 	 * Ideally we'd start copygc/rebalance earlier instead of waiting for
430 	 * all of recovery/fsck to complete:
431 	 */
432 	ret = bch2_copygc_start(c);
433 	if (ret) {
434 		bch_err(c, "error starting copygc thread");
435 		return ret;
436 	}
437 
438 	ret = bch2_rebalance_start(c);
439 	if (ret) {
440 		bch_err(c, "error starting rebalance thread");
441 		return ret;
442 	}
443 
444 	return 0;
445 }
446 
447 static int __bch2_fs_read_write(struct bch_fs *c, bool early)
448 {
449 	int ret;
450 
451 	BUG_ON(!test_bit(BCH_FS_may_go_rw, &c->flags));
452 
453 	if (test_bit(BCH_FS_initial_gc_unfixed, &c->flags)) {
454 		bch_err(c, "cannot go rw, unfixed btree errors");
455 		return -BCH_ERR_erofs_unfixed_errors;
456 	}
457 
458 	if (test_bit(BCH_FS_rw, &c->flags))
459 		return 0;
460 
461 	bch_info(c, "going read-write");
462 
463 	ret = bch2_sb_members_v2_init(c);
464 	if (ret)
465 		goto err;
466 
467 	clear_bit(BCH_FS_clean_shutdown, &c->flags);
468 
469 	/*
470 	 * First journal write must be a flush write: after a clean shutdown we
471 	 * don't read the journal, so the first journal write may end up
472 	 * overwriting whatever was there previously, and there must always be
473 	 * at least one non-flush write in the journal or recovery will fail:
474 	 */
475 	set_bit(JOURNAL_need_flush_write, &c->journal.flags);
476 	set_bit(JOURNAL_running, &c->journal.flags);
477 
478 	__for_each_online_member(c, ca, BIT(BCH_MEMBER_STATE_rw), READ) {
479 		bch2_dev_allocator_add(c, ca);
480 		percpu_ref_reinit(&ca->io_ref[WRITE]);
481 	}
482 	bch2_recalc_capacity(c);
483 
484 	ret = bch2_fs_mark_dirty(c);
485 	if (ret)
486 		goto err;
487 
488 	spin_lock(&c->journal.lock);
489 	bch2_journal_space_available(&c->journal);
490 	spin_unlock(&c->journal.lock);
491 
492 	ret = bch2_journal_reclaim_start(&c->journal);
493 	if (ret)
494 		goto err;
495 
496 	set_bit(BCH_FS_rw, &c->flags);
497 	set_bit(BCH_FS_was_rw, &c->flags);
498 
499 #ifndef BCH_WRITE_REF_DEBUG
500 	percpu_ref_reinit(&c->writes);
501 #else
502 	for (unsigned i = 0; i < BCH_WRITE_REF_NR; i++) {
503 		BUG_ON(atomic_long_read(&c->writes[i]));
504 		atomic_long_inc(&c->writes[i]);
505 	}
506 #endif
507 	if (!early) {
508 		ret = bch2_fs_read_write_late(c);
509 		if (ret)
510 			goto err;
511 	}
512 
513 	bch2_do_discards(c);
514 	bch2_do_invalidates(c);
515 	bch2_do_stripe_deletes(c);
516 	bch2_do_pending_node_rewrites(c);
517 	return 0;
518 err:
519 	if (test_bit(BCH_FS_rw, &c->flags))
520 		bch2_fs_read_only(c);
521 	else
522 		__bch2_fs_read_only(c);
523 	return ret;
524 }
525 
526 int bch2_fs_read_write(struct bch_fs *c)
527 {
528 	if (c->opts.recovery_pass_last &&
529 	    c->opts.recovery_pass_last < BCH_RECOVERY_PASS_journal_replay)
530 		return -BCH_ERR_erofs_norecovery;
531 
532 	if (c->opts.nochanges)
533 		return -BCH_ERR_erofs_nochanges;
534 
535 	return __bch2_fs_read_write(c, false);
536 }
537 
538 int bch2_fs_read_write_early(struct bch_fs *c)
539 {
540 	down_write(&c->state_lock);
541 	int ret = __bch2_fs_read_write(c, true);
542 	up_write(&c->state_lock);
543 
544 	return ret;
545 }
546 
547 /* Filesystem startup/shutdown: */
548 
549 static void __bch2_fs_free(struct bch_fs *c)
550 {
551 	for (unsigned i = 0; i < BCH_TIME_STAT_NR; i++)
552 		bch2_time_stats_exit(&c->times[i]);
553 
554 	bch2_find_btree_nodes_exit(&c->found_btree_nodes);
555 	bch2_free_pending_node_rewrites(c);
556 	bch2_fs_accounting_exit(c);
557 	bch2_fs_sb_errors_exit(c);
558 	bch2_fs_counters_exit(c);
559 	bch2_fs_snapshots_exit(c);
560 	bch2_fs_quota_exit(c);
561 	bch2_fs_fs_io_direct_exit(c);
562 	bch2_fs_fs_io_buffered_exit(c);
563 	bch2_fs_fsio_exit(c);
564 	bch2_fs_vfs_exit(c);
565 	bch2_fs_ec_exit(c);
566 	bch2_fs_encryption_exit(c);
567 	bch2_fs_nocow_locking_exit(c);
568 	bch2_fs_io_write_exit(c);
569 	bch2_fs_io_read_exit(c);
570 	bch2_fs_buckets_waiting_for_journal_exit(c);
571 	bch2_fs_btree_interior_update_exit(c);
572 	bch2_fs_btree_key_cache_exit(&c->btree_key_cache);
573 	bch2_fs_btree_cache_exit(c);
574 	bch2_fs_btree_iter_exit(c);
575 	bch2_fs_replicas_exit(c);
576 	bch2_fs_journal_exit(&c->journal);
577 	bch2_io_clock_exit(&c->io_clock[WRITE]);
578 	bch2_io_clock_exit(&c->io_clock[READ]);
579 	bch2_fs_compress_exit(c);
580 	bch2_fs_btree_gc_exit(c);
581 	bch2_journal_keys_put_initial(c);
582 	bch2_find_btree_nodes_exit(&c->found_btree_nodes);
583 	BUG_ON(atomic_read(&c->journal_keys.ref));
584 	bch2_fs_btree_write_buffer_exit(c);
585 	percpu_free_rwsem(&c->mark_lock);
586 	if (c->online_reserved) {
587 		u64 v = percpu_u64_get(c->online_reserved);
588 		WARN(v, "online_reserved not 0 at shutdown: %lli", v);
589 		free_percpu(c->online_reserved);
590 	}
591 
592 	darray_exit(&c->incompat_versions_requested);
593 	darray_exit(&c->btree_roots_extra);
594 	free_percpu(c->pcpu);
595 	free_percpu(c->usage);
596 	mempool_exit(&c->large_bkey_pool);
597 	mempool_exit(&c->btree_bounce_pool);
598 	bioset_exit(&c->btree_bio);
599 	mempool_exit(&c->fill_iter);
600 #ifndef BCH_WRITE_REF_DEBUG
601 	percpu_ref_exit(&c->writes);
602 #endif
603 	kfree(rcu_dereference_protected(c->disk_groups, 1));
604 	kfree(c->journal_seq_blacklist_table);
605 
606 	if (c->write_ref_wq)
607 		destroy_workqueue(c->write_ref_wq);
608 	if (c->btree_write_submit_wq)
609 		destroy_workqueue(c->btree_write_submit_wq);
610 	if (c->btree_read_complete_wq)
611 		destroy_workqueue(c->btree_read_complete_wq);
612 	if (c->copygc_wq)
613 		destroy_workqueue(c->copygc_wq);
614 	if (c->btree_io_complete_wq)
615 		destroy_workqueue(c->btree_io_complete_wq);
616 	if (c->btree_update_wq)
617 		destroy_workqueue(c->btree_update_wq);
618 
619 	bch2_free_super(&c->disk_sb);
620 	kvfree(c);
621 	module_put(THIS_MODULE);
622 }
623 
624 static void bch2_fs_release(struct kobject *kobj)
625 {
626 	struct bch_fs *c = container_of(kobj, struct bch_fs, kobj);
627 
628 	__bch2_fs_free(c);
629 }
630 
631 void __bch2_fs_stop(struct bch_fs *c)
632 {
633 	bch_verbose(c, "shutting down");
634 
635 	set_bit(BCH_FS_stopping, &c->flags);
636 
637 	down_write(&c->state_lock);
638 	bch2_fs_read_only(c);
639 	up_write(&c->state_lock);
640 
641 	for_each_member_device(c, ca)
642 		bch2_dev_unlink(ca);
643 
644 	if (c->kobj.state_in_sysfs)
645 		kobject_del(&c->kobj);
646 
647 	bch2_fs_debug_exit(c);
648 	bch2_fs_chardev_exit(c);
649 
650 	bch2_ro_ref_put(c);
651 	wait_event(c->ro_ref_wait, !refcount_read(&c->ro_ref));
652 
653 	kobject_put(&c->counters_kobj);
654 	kobject_put(&c->time_stats);
655 	kobject_put(&c->opts_dir);
656 	kobject_put(&c->internal);
657 
658 	/* btree prefetch might have kicked off reads in the background: */
659 	bch2_btree_flush_all_reads(c);
660 
661 	for_each_member_device(c, ca)
662 		cancel_work_sync(&ca->io_error_work);
663 
664 	cancel_work_sync(&c->read_only_work);
665 }
666 
667 void bch2_fs_free(struct bch_fs *c)
668 {
669 	unsigned i;
670 
671 	mutex_lock(&bch_fs_list_lock);
672 	list_del(&c->list);
673 	mutex_unlock(&bch_fs_list_lock);
674 
675 	closure_sync(&c->cl);
676 	closure_debug_destroy(&c->cl);
677 
678 	for (i = 0; i < c->sb.nr_devices; i++) {
679 		struct bch_dev *ca = rcu_dereference_protected(c->devs[i], true);
680 
681 		if (ca) {
682 			EBUG_ON(atomic_long_read(&ca->ref) != 1);
683 			bch2_dev_io_ref_stop(ca, READ);
684 			bch2_free_super(&ca->disk_sb);
685 			bch2_dev_free(ca);
686 		}
687 	}
688 
689 	bch_verbose(c, "shutdown complete");
690 
691 	kobject_put(&c->kobj);
692 }
693 
694 void bch2_fs_stop(struct bch_fs *c)
695 {
696 	__bch2_fs_stop(c);
697 	bch2_fs_free(c);
698 }
699 
700 static int bch2_fs_online(struct bch_fs *c)
701 {
702 	int ret = 0;
703 
704 	lockdep_assert_held(&bch_fs_list_lock);
705 
706 	if (__bch2_uuid_to_fs(c->sb.uuid)) {
707 		bch_err(c, "filesystem UUID already open");
708 		return -EINVAL;
709 	}
710 
711 	ret = bch2_fs_chardev_init(c);
712 	if (ret) {
713 		bch_err(c, "error creating character device");
714 		return ret;
715 	}
716 
717 	bch2_fs_debug_init(c);
718 
719 	ret = kobject_add(&c->kobj, NULL, "%pU", c->sb.user_uuid.b) ?:
720 	    kobject_add(&c->internal, &c->kobj, "internal") ?:
721 	    kobject_add(&c->opts_dir, &c->kobj, "options") ?:
722 #ifndef CONFIG_BCACHEFS_NO_LATENCY_ACCT
723 	    kobject_add(&c->time_stats, &c->kobj, "time_stats") ?:
724 #endif
725 	    kobject_add(&c->counters_kobj, &c->kobj, "counters") ?:
726 	    bch2_opts_create_sysfs_files(&c->opts_dir, OPT_FS);
727 	if (ret) {
728 		bch_err(c, "error creating sysfs objects");
729 		return ret;
730 	}
731 
732 	down_write(&c->state_lock);
733 
734 	for_each_member_device(c, ca) {
735 		ret = bch2_dev_sysfs_online(c, ca);
736 		if (ret) {
737 			bch_err(c, "error creating sysfs objects");
738 			bch2_dev_put(ca);
739 			goto err;
740 		}
741 	}
742 
743 	BUG_ON(!list_empty(&c->list));
744 	list_add(&c->list, &bch_fs_list);
745 err:
746 	up_write(&c->state_lock);
747 	return ret;
748 }
749 
750 static struct bch_fs *bch2_fs_alloc(struct bch_sb *sb, struct bch_opts opts)
751 {
752 	struct bch_fs *c;
753 	struct printbuf name = PRINTBUF;
754 	unsigned i, iter_size;
755 	int ret = 0;
756 
757 	c = kvmalloc(sizeof(struct bch_fs), GFP_KERNEL|__GFP_ZERO);
758 	if (!c) {
759 		c = ERR_PTR(-BCH_ERR_ENOMEM_fs_alloc);
760 		goto out;
761 	}
762 
763 	c->stdio = (void *)(unsigned long) opts.stdio;
764 
765 	__module_get(THIS_MODULE);
766 
767 	closure_init(&c->cl, NULL);
768 
769 	c->kobj.kset = bcachefs_kset;
770 	kobject_init(&c->kobj, &bch2_fs_ktype);
771 	kobject_init(&c->internal, &bch2_fs_internal_ktype);
772 	kobject_init(&c->opts_dir, &bch2_fs_opts_dir_ktype);
773 	kobject_init(&c->time_stats, &bch2_fs_time_stats_ktype);
774 	kobject_init(&c->counters_kobj, &bch2_fs_counters_ktype);
775 
776 	c->minor		= -1;
777 	c->disk_sb.fs_sb	= true;
778 
779 	init_rwsem(&c->state_lock);
780 	mutex_init(&c->sb_lock);
781 	mutex_init(&c->replicas_gc_lock);
782 	mutex_init(&c->btree_root_lock);
783 	INIT_WORK(&c->read_only_work, bch2_fs_read_only_work);
784 
785 	refcount_set(&c->ro_ref, 1);
786 	init_waitqueue_head(&c->ro_ref_wait);
787 	spin_lock_init(&c->recovery_pass_lock);
788 	sema_init(&c->online_fsck_mutex, 1);
789 
790 	for (i = 0; i < BCH_TIME_STAT_NR; i++)
791 		bch2_time_stats_init(&c->times[i]);
792 
793 	bch2_fs_copygc_init(c);
794 	bch2_fs_btree_key_cache_init_early(&c->btree_key_cache);
795 	bch2_fs_btree_iter_init_early(c);
796 	bch2_fs_btree_interior_update_init_early(c);
797 	bch2_fs_journal_keys_init(c);
798 	bch2_fs_allocator_background_init(c);
799 	bch2_fs_allocator_foreground_init(c);
800 	bch2_fs_rebalance_init(c);
801 	bch2_fs_quota_init(c);
802 	bch2_fs_ec_init_early(c);
803 	bch2_fs_move_init(c);
804 	bch2_fs_sb_errors_init_early(c);
805 
806 	INIT_LIST_HEAD(&c->list);
807 
808 	mutex_init(&c->bio_bounce_pages_lock);
809 	mutex_init(&c->snapshot_table_lock);
810 	init_rwsem(&c->snapshot_create_lock);
811 
812 	spin_lock_init(&c->btree_write_error_lock);
813 
814 	INIT_LIST_HEAD(&c->journal_iters);
815 
816 	INIT_LIST_HEAD(&c->fsck_error_msgs);
817 	mutex_init(&c->fsck_error_msgs_lock);
818 
819 	seqcount_init(&c->usage_lock);
820 
821 	sema_init(&c->io_in_flight, 128);
822 
823 	INIT_LIST_HEAD(&c->vfs_inodes_list);
824 	mutex_init(&c->vfs_inodes_lock);
825 
826 	c->journal.flush_write_time	= &c->times[BCH_TIME_journal_flush_write];
827 	c->journal.noflush_write_time	= &c->times[BCH_TIME_journal_noflush_write];
828 	c->journal.flush_seq_time	= &c->times[BCH_TIME_journal_flush_seq];
829 
830 	bch2_fs_btree_cache_init_early(&c->btree_cache);
831 
832 	mutex_init(&c->sectors_available_lock);
833 
834 	ret = percpu_init_rwsem(&c->mark_lock);
835 	if (ret)
836 		goto err;
837 
838 	mutex_lock(&c->sb_lock);
839 	ret = bch2_sb_to_fs(c, sb);
840 	mutex_unlock(&c->sb_lock);
841 
842 	if (ret)
843 		goto err;
844 
845 #ifdef CONFIG_UNICODE
846 	/* Default encoding until we can potentially have more as an option. */
847 	c->cf_encoding = utf8_load(BCH_FS_DEFAULT_UTF8_ENCODING);
848 	if (IS_ERR(c->cf_encoding)) {
849 		printk(KERN_ERR "Cannot load UTF-8 encoding for filesystem. Version: %u.%u.%u",
850 			unicode_major(BCH_FS_DEFAULT_UTF8_ENCODING),
851 			unicode_minor(BCH_FS_DEFAULT_UTF8_ENCODING),
852 			unicode_rev(BCH_FS_DEFAULT_UTF8_ENCODING));
853 		ret = -EINVAL;
854 		goto err;
855 	}
856 #else
857 	if (c->sb.features & BIT_ULL(BCH_FEATURE_casefolding)) {
858 		printk(KERN_ERR "Cannot mount a filesystem with casefolding on a kernel without CONFIG_UNICODE\n");
859 		ret = -EINVAL;
860 		goto err;
861 	}
862 #endif
863 
864 	pr_uuid(&name, c->sb.user_uuid.b);
865 	ret = name.allocation_failure ? -BCH_ERR_ENOMEM_fs_name_alloc : 0;
866 	if (ret)
867 		goto err;
868 
869 	strscpy(c->name, name.buf, sizeof(c->name));
870 	printbuf_exit(&name);
871 
872 	/* Compat: */
873 	if (le16_to_cpu(sb->version) <= bcachefs_metadata_version_inode_v2 &&
874 	    !BCH_SB_JOURNAL_FLUSH_DELAY(sb))
875 		SET_BCH_SB_JOURNAL_FLUSH_DELAY(sb, 1000);
876 
877 	if (le16_to_cpu(sb->version) <= bcachefs_metadata_version_inode_v2 &&
878 	    !BCH_SB_JOURNAL_RECLAIM_DELAY(sb))
879 		SET_BCH_SB_JOURNAL_RECLAIM_DELAY(sb, 100);
880 
881 	c->opts = bch2_opts_default;
882 	ret = bch2_opts_from_sb(&c->opts, sb);
883 	if (ret)
884 		goto err;
885 
886 	bch2_opts_apply(&c->opts, opts);
887 
888 	c->btree_key_cache_btrees |= 1U << BTREE_ID_alloc;
889 	if (c->opts.inodes_use_key_cache)
890 		c->btree_key_cache_btrees |= 1U << BTREE_ID_inodes;
891 	c->btree_key_cache_btrees |= 1U << BTREE_ID_logged_ops;
892 
893 	c->block_bits		= ilog2(block_sectors(c));
894 	c->btree_foreground_merge_threshold = BTREE_FOREGROUND_MERGE_THRESHOLD(c);
895 
896 	if (bch2_fs_init_fault("fs_alloc")) {
897 		bch_err(c, "fs_alloc fault injected");
898 		ret = -EFAULT;
899 		goto err;
900 	}
901 
902 	iter_size = sizeof(struct sort_iter) +
903 		(btree_blocks(c) + 1) * 2 *
904 		sizeof(struct sort_iter_set);
905 
906 	if (!(c->btree_update_wq = alloc_workqueue("bcachefs",
907 				WQ_HIGHPRI|WQ_FREEZABLE|WQ_MEM_RECLAIM|WQ_UNBOUND, 512)) ||
908 	    !(c->btree_io_complete_wq = alloc_workqueue("bcachefs_btree_io",
909 				WQ_HIGHPRI|WQ_FREEZABLE|WQ_MEM_RECLAIM, 1)) ||
910 	    !(c->copygc_wq = alloc_workqueue("bcachefs_copygc",
911 				WQ_HIGHPRI|WQ_FREEZABLE|WQ_MEM_RECLAIM|WQ_CPU_INTENSIVE, 1)) ||
912 	    !(c->btree_read_complete_wq = alloc_workqueue("bcachefs_btree_read_complete",
913 				WQ_HIGHPRI|WQ_FREEZABLE|WQ_MEM_RECLAIM, 512)) ||
914 	    !(c->btree_write_submit_wq = alloc_workqueue("bcachefs_btree_write_sumit",
915 				WQ_HIGHPRI|WQ_FREEZABLE|WQ_MEM_RECLAIM, 1)) ||
916 	    !(c->write_ref_wq = alloc_workqueue("bcachefs_write_ref",
917 				WQ_FREEZABLE, 0)) ||
918 #ifndef BCH_WRITE_REF_DEBUG
919 	    percpu_ref_init(&c->writes, bch2_writes_disabled,
920 			    PERCPU_REF_INIT_DEAD, GFP_KERNEL) ||
921 #endif
922 	    mempool_init_kmalloc_pool(&c->fill_iter, 1, iter_size) ||
923 	    bioset_init(&c->btree_bio, 1,
924 			max(offsetof(struct btree_read_bio, bio),
925 			    offsetof(struct btree_write_bio, wbio.bio)),
926 			BIOSET_NEED_BVECS) ||
927 	    !(c->pcpu = alloc_percpu(struct bch_fs_pcpu)) ||
928 	    !(c->usage = alloc_percpu(struct bch_fs_usage_base)) ||
929 	    !(c->online_reserved = alloc_percpu(u64)) ||
930 	    mempool_init_kvmalloc_pool(&c->btree_bounce_pool, 1,
931 				       c->opts.btree_node_size) ||
932 	    mempool_init_kmalloc_pool(&c->large_bkey_pool, 1, 2048)) {
933 		ret = -BCH_ERR_ENOMEM_fs_other_alloc;
934 		goto err;
935 	}
936 
937 	ret = bch2_fs_counters_init(c) ?:
938 	    bch2_fs_sb_errors_init(c) ?:
939 	    bch2_io_clock_init(&c->io_clock[READ]) ?:
940 	    bch2_io_clock_init(&c->io_clock[WRITE]) ?:
941 	    bch2_fs_journal_init(&c->journal) ?:
942 	    bch2_fs_btree_iter_init(c) ?:
943 	    bch2_fs_btree_cache_init(c) ?:
944 	    bch2_fs_btree_key_cache_init(&c->btree_key_cache) ?:
945 	    bch2_fs_btree_interior_update_init(c) ?:
946 	    bch2_fs_btree_gc_init(c) ?:
947 	    bch2_fs_buckets_waiting_for_journal_init(c) ?:
948 	    bch2_fs_btree_write_buffer_init(c) ?:
949 	    bch2_fs_subvolumes_init(c) ?:
950 	    bch2_fs_io_read_init(c) ?:
951 	    bch2_fs_io_write_init(c) ?:
952 	    bch2_fs_nocow_locking_init(c) ?:
953 	    bch2_fs_encryption_init(c) ?:
954 	    bch2_fs_compress_init(c) ?:
955 	    bch2_fs_ec_init(c) ?:
956 	    bch2_fs_vfs_init(c) ?:
957 	    bch2_fs_fsio_init(c) ?:
958 	    bch2_fs_fs_io_buffered_init(c) ?:
959 	    bch2_fs_fs_io_direct_init(c);
960 	if (ret)
961 		goto err;
962 
963 	for (i = 0; i < c->sb.nr_devices; i++) {
964 		if (!bch2_member_exists(c->disk_sb.sb, i))
965 			continue;
966 		ret = bch2_dev_alloc(c, i);
967 		if (ret)
968 			goto err;
969 	}
970 
971 	bch2_journal_entry_res_resize(&c->journal,
972 			&c->btree_root_journal_res,
973 			BTREE_ID_NR * (JSET_KEYS_U64s + BKEY_BTREE_PTR_U64s_MAX));
974 	bch2_journal_entry_res_resize(&c->journal,
975 			&c->clock_journal_res,
976 			(sizeof(struct jset_entry_clock) / sizeof(u64)) * 2);
977 
978 	mutex_lock(&bch_fs_list_lock);
979 	ret = bch2_fs_online(c);
980 	mutex_unlock(&bch_fs_list_lock);
981 
982 	if (ret)
983 		goto err;
984 out:
985 	return c;
986 err:
987 	bch2_fs_free(c);
988 	c = ERR_PTR(ret);
989 	goto out;
990 }
991 
992 noinline_for_stack
993 static void print_mount_opts(struct bch_fs *c)
994 {
995 	enum bch_opt_id i;
996 	struct printbuf p = PRINTBUF;
997 	bool first = true;
998 
999 	prt_str(&p, "starting version ");
1000 	bch2_version_to_text(&p, c->sb.version);
1001 
1002 	for (i = 0; i < bch2_opts_nr; i++) {
1003 		const struct bch_option *opt = &bch2_opt_table[i];
1004 		u64 v = bch2_opt_get_by_id(&c->opts, i);
1005 
1006 		if (!(opt->flags & OPT_MOUNT))
1007 			continue;
1008 
1009 		if (v == bch2_opt_get_by_id(&bch2_opts_default, i))
1010 			continue;
1011 
1012 		prt_str(&p, first ? " opts=" : ",");
1013 		first = false;
1014 		bch2_opt_to_text(&p, c, c->disk_sb.sb, opt, v, OPT_SHOW_MOUNT_STYLE);
1015 	}
1016 
1017 	if (c->sb.version_incompat_allowed != c->sb.version) {
1018 		prt_printf(&p, "\n  allowing incompatible features above ");
1019 		bch2_version_to_text(&p, c->sb.version_incompat_allowed);
1020 	}
1021 
1022 	bch_info(c, "%s", p.buf);
1023 	printbuf_exit(&p);
1024 }
1025 
1026 int bch2_fs_start(struct bch_fs *c)
1027 {
1028 	time64_t now = ktime_get_real_seconds();
1029 	int ret = 0;
1030 
1031 	print_mount_opts(c);
1032 
1033 	down_write(&c->state_lock);
1034 	mutex_lock(&c->sb_lock);
1035 
1036 	BUG_ON(test_bit(BCH_FS_started, &c->flags));
1037 
1038 	if (!bch2_sb_field_get_minsize(&c->disk_sb, ext,
1039 			sizeof(struct bch_sb_field_ext) / sizeof(u64))) {
1040 		mutex_unlock(&c->sb_lock);
1041 		up_write(&c->state_lock);
1042 		ret = -BCH_ERR_ENOSPC_sb;
1043 		goto err;
1044 	}
1045 
1046 	ret = bch2_sb_members_v2_init(c);
1047 	if (ret) {
1048 		mutex_unlock(&c->sb_lock);
1049 		up_write(&c->state_lock);
1050 		goto err;
1051 	}
1052 
1053 	for_each_online_member(c, ca)
1054 		bch2_members_v2_get_mut(c->disk_sb.sb, ca->dev_idx)->last_mount = cpu_to_le64(now);
1055 
1056 	mutex_unlock(&c->sb_lock);
1057 
1058 	for_each_rw_member(c, ca)
1059 		bch2_dev_allocator_add(c, ca);
1060 	bch2_recalc_capacity(c);
1061 	up_write(&c->state_lock);
1062 
1063 	c->recovery_task = current;
1064 	ret = BCH_SB_INITIALIZED(c->disk_sb.sb)
1065 		? bch2_fs_recovery(c)
1066 		: bch2_fs_initialize(c);
1067 	c->recovery_task = NULL;
1068 
1069 	if (ret)
1070 		goto err;
1071 
1072 	ret = bch2_opts_check_may_set(c);
1073 	if (ret)
1074 		goto err;
1075 
1076 	if (bch2_fs_init_fault("fs_start")) {
1077 		ret = -BCH_ERR_injected_fs_start;
1078 		goto err;
1079 	}
1080 
1081 	set_bit(BCH_FS_started, &c->flags);
1082 	wake_up(&c->ro_ref_wait);
1083 
1084 	down_write(&c->state_lock);
1085 	if (c->opts.read_only) {
1086 		bch2_fs_read_only(c);
1087 	} else {
1088 		ret = !test_bit(BCH_FS_rw, &c->flags)
1089 			? bch2_fs_read_write(c)
1090 			: bch2_fs_read_write_late(c);
1091 	}
1092 	up_write(&c->state_lock);
1093 
1094 err:
1095 	if (ret)
1096 		bch_err_msg(c, ret, "starting filesystem");
1097 	else
1098 		bch_verbose(c, "done starting filesystem");
1099 	return ret;
1100 }
1101 
1102 static int bch2_dev_may_add(struct bch_sb *sb, struct bch_fs *c)
1103 {
1104 	struct bch_member m = bch2_sb_member_get(sb, sb->dev_idx);
1105 
1106 	if (le16_to_cpu(sb->block_size) != block_sectors(c))
1107 		return -BCH_ERR_mismatched_block_size;
1108 
1109 	if (le16_to_cpu(m.bucket_size) <
1110 	    BCH_SB_BTREE_NODE_SIZE(c->disk_sb.sb))
1111 		return -BCH_ERR_bucket_size_too_small;
1112 
1113 	return 0;
1114 }
1115 
1116 static int bch2_dev_in_fs(struct bch_sb_handle *fs,
1117 			  struct bch_sb_handle *sb,
1118 			  struct bch_opts *opts)
1119 {
1120 	if (fs == sb)
1121 		return 0;
1122 
1123 	if (!uuid_equal(&fs->sb->uuid, &sb->sb->uuid))
1124 		return -BCH_ERR_device_not_a_member_of_filesystem;
1125 
1126 	if (!bch2_member_exists(fs->sb, sb->sb->dev_idx))
1127 		return -BCH_ERR_device_has_been_removed;
1128 
1129 	if (fs->sb->block_size != sb->sb->block_size)
1130 		return -BCH_ERR_mismatched_block_size;
1131 
1132 	if (le16_to_cpu(fs->sb->version) < bcachefs_metadata_version_member_seq ||
1133 	    le16_to_cpu(sb->sb->version) < bcachefs_metadata_version_member_seq)
1134 		return 0;
1135 
1136 	if (fs->sb->seq == sb->sb->seq &&
1137 	    fs->sb->write_time != sb->sb->write_time) {
1138 		struct printbuf buf = PRINTBUF;
1139 
1140 		prt_str(&buf, "Split brain detected between ");
1141 		prt_bdevname(&buf, sb->bdev);
1142 		prt_str(&buf, " and ");
1143 		prt_bdevname(&buf, fs->bdev);
1144 		prt_char(&buf, ':');
1145 		prt_newline(&buf);
1146 		prt_printf(&buf, "seq=%llu but write_time different, got", le64_to_cpu(sb->sb->seq));
1147 		prt_newline(&buf);
1148 
1149 		prt_bdevname(&buf, fs->bdev);
1150 		prt_char(&buf, ' ');
1151 		bch2_prt_datetime(&buf, le64_to_cpu(fs->sb->write_time));
1152 		prt_newline(&buf);
1153 
1154 		prt_bdevname(&buf, sb->bdev);
1155 		prt_char(&buf, ' ');
1156 		bch2_prt_datetime(&buf, le64_to_cpu(sb->sb->write_time));
1157 		prt_newline(&buf);
1158 
1159 		if (!opts->no_splitbrain_check)
1160 			prt_printf(&buf, "Not using older sb");
1161 
1162 		pr_err("%s", buf.buf);
1163 		printbuf_exit(&buf);
1164 
1165 		if (!opts->no_splitbrain_check)
1166 			return -BCH_ERR_device_splitbrain;
1167 	}
1168 
1169 	struct bch_member m = bch2_sb_member_get(fs->sb, sb->sb->dev_idx);
1170 	u64 seq_from_fs		= le64_to_cpu(m.seq);
1171 	u64 seq_from_member	= le64_to_cpu(sb->sb->seq);
1172 
1173 	if (seq_from_fs && seq_from_fs < seq_from_member) {
1174 		struct printbuf buf = PRINTBUF;
1175 
1176 		prt_str(&buf, "Split brain detected between ");
1177 		prt_bdevname(&buf, sb->bdev);
1178 		prt_str(&buf, " and ");
1179 		prt_bdevname(&buf, fs->bdev);
1180 		prt_char(&buf, ':');
1181 		prt_newline(&buf);
1182 
1183 		prt_bdevname(&buf, fs->bdev);
1184 		prt_str(&buf, " believes seq of ");
1185 		prt_bdevname(&buf, sb->bdev);
1186 		prt_printf(&buf, " to be %llu, but ", seq_from_fs);
1187 		prt_bdevname(&buf, sb->bdev);
1188 		prt_printf(&buf, " has %llu\n", seq_from_member);
1189 
1190 		if (!opts->no_splitbrain_check) {
1191 			prt_str(&buf, "Not using ");
1192 			prt_bdevname(&buf, sb->bdev);
1193 		}
1194 
1195 		pr_err("%s", buf.buf);
1196 		printbuf_exit(&buf);
1197 
1198 		if (!opts->no_splitbrain_check)
1199 			return -BCH_ERR_device_splitbrain;
1200 	}
1201 
1202 	return 0;
1203 }
1204 
1205 /* Device startup/shutdown: */
1206 
1207 static void bch2_dev_io_ref_stop(struct bch_dev *ca, int rw)
1208 {
1209 	if (!percpu_ref_is_zero(&ca->io_ref[rw])) {
1210 		reinit_completion(&ca->io_ref_completion[rw]);
1211 		percpu_ref_kill(&ca->io_ref[rw]);
1212 		wait_for_completion(&ca->io_ref_completion[rw]);
1213 	}
1214 }
1215 
1216 static void bch2_dev_release(struct kobject *kobj)
1217 {
1218 	struct bch_dev *ca = container_of(kobj, struct bch_dev, kobj);
1219 
1220 	kfree(ca);
1221 }
1222 
1223 static void bch2_dev_free(struct bch_dev *ca)
1224 {
1225 	WARN_ON(!percpu_ref_is_zero(&ca->io_ref[WRITE]));
1226 	WARN_ON(!percpu_ref_is_zero(&ca->io_ref[READ]));
1227 
1228 	cancel_work_sync(&ca->io_error_work);
1229 
1230 	bch2_dev_unlink(ca);
1231 
1232 	if (ca->kobj.state_in_sysfs)
1233 		kobject_del(&ca->kobj);
1234 
1235 	bch2_free_super(&ca->disk_sb);
1236 	bch2_dev_allocator_background_exit(ca);
1237 	bch2_dev_journal_exit(ca);
1238 
1239 	free_percpu(ca->io_done);
1240 	bch2_dev_buckets_free(ca);
1241 	kfree(ca->sb_read_scratch);
1242 
1243 	bch2_time_stats_quantiles_exit(&ca->io_latency[WRITE]);
1244 	bch2_time_stats_quantiles_exit(&ca->io_latency[READ]);
1245 
1246 	percpu_ref_exit(&ca->io_ref[WRITE]);
1247 	percpu_ref_exit(&ca->io_ref[READ]);
1248 #ifndef CONFIG_BCACHEFS_DEBUG
1249 	percpu_ref_exit(&ca->ref);
1250 #endif
1251 	kobject_put(&ca->kobj);
1252 }
1253 
1254 static void __bch2_dev_offline(struct bch_fs *c, struct bch_dev *ca)
1255 {
1256 
1257 	lockdep_assert_held(&c->state_lock);
1258 
1259 	if (percpu_ref_is_zero(&ca->io_ref[READ]))
1260 		return;
1261 
1262 	__bch2_dev_read_only(c, ca);
1263 
1264 	bch2_dev_io_ref_stop(ca, READ);
1265 
1266 	bch2_dev_unlink(ca);
1267 
1268 	bch2_free_super(&ca->disk_sb);
1269 	bch2_dev_journal_exit(ca);
1270 }
1271 
1272 #ifndef CONFIG_BCACHEFS_DEBUG
1273 static void bch2_dev_ref_complete(struct percpu_ref *ref)
1274 {
1275 	struct bch_dev *ca = container_of(ref, struct bch_dev, ref);
1276 
1277 	complete(&ca->ref_completion);
1278 }
1279 #endif
1280 
1281 static void bch2_dev_io_ref_read_complete(struct percpu_ref *ref)
1282 {
1283 	struct bch_dev *ca = container_of(ref, struct bch_dev, io_ref[READ]);
1284 
1285 	complete(&ca->io_ref_completion[READ]);
1286 }
1287 
1288 static void bch2_dev_io_ref_write_complete(struct percpu_ref *ref)
1289 {
1290 	struct bch_dev *ca = container_of(ref, struct bch_dev, io_ref[WRITE]);
1291 
1292 	complete(&ca->io_ref_completion[WRITE]);
1293 }
1294 
1295 static void bch2_dev_unlink(struct bch_dev *ca)
1296 {
1297 	struct kobject *b;
1298 
1299 	/*
1300 	 * This is racy w.r.t. the underlying block device being hot-removed,
1301 	 * which removes it from sysfs.
1302 	 *
1303 	 * It'd be lovely if we had a way to handle this race, but the sysfs
1304 	 * code doesn't appear to provide a good method and block/holder.c is
1305 	 * susceptible as well:
1306 	 */
1307 	if (ca->kobj.state_in_sysfs &&
1308 	    ca->disk_sb.bdev &&
1309 	    (b = bdev_kobj(ca->disk_sb.bdev))->state_in_sysfs) {
1310 		sysfs_remove_link(b, "bcachefs");
1311 		sysfs_remove_link(&ca->kobj, "block");
1312 	}
1313 }
1314 
1315 static int bch2_dev_sysfs_online(struct bch_fs *c, struct bch_dev *ca)
1316 {
1317 	int ret;
1318 
1319 	if (!c->kobj.state_in_sysfs)
1320 		return 0;
1321 
1322 	if (!ca->kobj.state_in_sysfs) {
1323 		ret =   kobject_add(&ca->kobj, &c->kobj, "dev-%u", ca->dev_idx) ?:
1324 			bch2_opts_create_sysfs_files(&ca->kobj, OPT_DEVICE);
1325 		if (ret)
1326 			return ret;
1327 	}
1328 
1329 	if (ca->disk_sb.bdev) {
1330 		struct kobject *block = bdev_kobj(ca->disk_sb.bdev);
1331 
1332 		ret = sysfs_create_link(block, &ca->kobj, "bcachefs");
1333 		if (ret)
1334 			return ret;
1335 
1336 		ret = sysfs_create_link(&ca->kobj, block, "block");
1337 		if (ret)
1338 			return ret;
1339 	}
1340 
1341 	return 0;
1342 }
1343 
1344 static struct bch_dev *__bch2_dev_alloc(struct bch_fs *c,
1345 					struct bch_member *member)
1346 {
1347 	struct bch_dev *ca;
1348 	unsigned i;
1349 
1350 	ca = kzalloc(sizeof(*ca), GFP_KERNEL);
1351 	if (!ca)
1352 		return NULL;
1353 
1354 	kobject_init(&ca->kobj, &bch2_dev_ktype);
1355 	init_completion(&ca->ref_completion);
1356 	init_completion(&ca->io_ref_completion[READ]);
1357 	init_completion(&ca->io_ref_completion[WRITE]);
1358 
1359 	INIT_WORK(&ca->io_error_work, bch2_io_error_work);
1360 
1361 	bch2_time_stats_quantiles_init(&ca->io_latency[READ]);
1362 	bch2_time_stats_quantiles_init(&ca->io_latency[WRITE]);
1363 
1364 	ca->mi = bch2_mi_to_cpu(member);
1365 
1366 	for (i = 0; i < ARRAY_SIZE(member->errors); i++)
1367 		atomic64_set(&ca->errors[i], le64_to_cpu(member->errors[i]));
1368 
1369 	ca->uuid = member->uuid;
1370 
1371 	ca->nr_btree_reserve = DIV_ROUND_UP(BTREE_NODE_RESERVE,
1372 			     ca->mi.bucket_size / btree_sectors(c));
1373 
1374 #ifndef CONFIG_BCACHEFS_DEBUG
1375 	if (percpu_ref_init(&ca->ref, bch2_dev_ref_complete, 0, GFP_KERNEL))
1376 		goto err;
1377 #else
1378 	atomic_long_set(&ca->ref, 1);
1379 #endif
1380 
1381 	bch2_dev_allocator_background_init(ca);
1382 
1383 	if (percpu_ref_init(&ca->io_ref[READ], bch2_dev_io_ref_read_complete,
1384 			    PERCPU_REF_INIT_DEAD, GFP_KERNEL) ||
1385 	    percpu_ref_init(&ca->io_ref[WRITE], bch2_dev_io_ref_write_complete,
1386 			    PERCPU_REF_INIT_DEAD, GFP_KERNEL) ||
1387 	    !(ca->sb_read_scratch = kmalloc(BCH_SB_READ_SCRATCH_BUF_SIZE, GFP_KERNEL)) ||
1388 	    bch2_dev_buckets_alloc(c, ca) ||
1389 	    !(ca->io_done	= alloc_percpu(*ca->io_done)))
1390 		goto err;
1391 
1392 	return ca;
1393 err:
1394 	bch2_dev_free(ca);
1395 	return NULL;
1396 }
1397 
1398 static void bch2_dev_attach(struct bch_fs *c, struct bch_dev *ca,
1399 			    unsigned dev_idx)
1400 {
1401 	ca->dev_idx = dev_idx;
1402 	__set_bit(ca->dev_idx, ca->self.d);
1403 	scnprintf(ca->name, sizeof(ca->name), "dev-%u", dev_idx);
1404 
1405 	ca->fs = c;
1406 	rcu_assign_pointer(c->devs[ca->dev_idx], ca);
1407 
1408 	if (bch2_dev_sysfs_online(c, ca))
1409 		pr_warn("error creating sysfs objects");
1410 }
1411 
1412 static int bch2_dev_alloc(struct bch_fs *c, unsigned dev_idx)
1413 {
1414 	struct bch_member member = bch2_sb_member_get(c->disk_sb.sb, dev_idx);
1415 	struct bch_dev *ca = NULL;
1416 
1417 	if (bch2_fs_init_fault("dev_alloc"))
1418 		goto err;
1419 
1420 	ca = __bch2_dev_alloc(c, &member);
1421 	if (!ca)
1422 		goto err;
1423 
1424 	ca->fs = c;
1425 
1426 	bch2_dev_attach(c, ca, dev_idx);
1427 	return 0;
1428 err:
1429 	return -BCH_ERR_ENOMEM_dev_alloc;
1430 }
1431 
1432 static int __bch2_dev_attach_bdev(struct bch_dev *ca, struct bch_sb_handle *sb)
1433 {
1434 	unsigned ret;
1435 
1436 	if (bch2_dev_is_online(ca)) {
1437 		bch_err(ca, "already have device online in slot %u",
1438 			sb->sb->dev_idx);
1439 		return -BCH_ERR_device_already_online;
1440 	}
1441 
1442 	if (get_capacity(sb->bdev->bd_disk) <
1443 	    ca->mi.bucket_size * ca->mi.nbuckets) {
1444 		bch_err(ca, "cannot online: device too small");
1445 		return -BCH_ERR_device_size_too_small;
1446 	}
1447 
1448 	BUG_ON(!percpu_ref_is_zero(&ca->io_ref[READ]));
1449 	BUG_ON(!percpu_ref_is_zero(&ca->io_ref[WRITE]));
1450 
1451 	ret = bch2_dev_journal_init(ca, sb->sb);
1452 	if (ret)
1453 		return ret;
1454 
1455 	/* Commit: */
1456 	ca->disk_sb = *sb;
1457 	memset(sb, 0, sizeof(*sb));
1458 
1459 	/*
1460 	 * Stash pointer to the filesystem for blk_holder_ops - note that once
1461 	 * attached to a filesystem, we will always close the block device
1462 	 * before tearing down the filesystem object.
1463 	 */
1464 	ca->disk_sb.holder->c = ca->fs;
1465 
1466 	ca->dev = ca->disk_sb.bdev->bd_dev;
1467 
1468 	percpu_ref_reinit(&ca->io_ref[READ]);
1469 
1470 	return 0;
1471 }
1472 
1473 static int bch2_dev_attach_bdev(struct bch_fs *c, struct bch_sb_handle *sb)
1474 {
1475 	struct bch_dev *ca;
1476 	int ret;
1477 
1478 	lockdep_assert_held(&c->state_lock);
1479 
1480 	if (le64_to_cpu(sb->sb->seq) >
1481 	    le64_to_cpu(c->disk_sb.sb->seq))
1482 		bch2_sb_to_fs(c, sb->sb);
1483 
1484 	BUG_ON(!bch2_dev_exists(c, sb->sb->dev_idx));
1485 
1486 	ca = bch2_dev_locked(c, sb->sb->dev_idx);
1487 
1488 	ret = __bch2_dev_attach_bdev(ca, sb);
1489 	if (ret)
1490 		return ret;
1491 
1492 	bch2_dev_sysfs_online(c, ca);
1493 
1494 	struct printbuf name = PRINTBUF;
1495 	prt_bdevname(&name, ca->disk_sb.bdev);
1496 
1497 	if (c->sb.nr_devices == 1)
1498 		strscpy(c->name, name.buf, sizeof(c->name));
1499 	strscpy(ca->name, name.buf, sizeof(ca->name));
1500 
1501 	printbuf_exit(&name);
1502 
1503 	rebalance_wakeup(c);
1504 	return 0;
1505 }
1506 
1507 /* Device management: */
1508 
1509 /*
1510  * Note: this function is also used by the error paths - when a particular
1511  * device sees an error, we call it to determine whether we can just set the
1512  * device RO, or - if this function returns false - we'll set the whole
1513  * filesystem RO:
1514  *
1515  * XXX: maybe we should be more explicit about whether we're changing state
1516  * because we got an error or what have you?
1517  */
1518 bool bch2_dev_state_allowed(struct bch_fs *c, struct bch_dev *ca,
1519 			    enum bch_member_state new_state, int flags)
1520 {
1521 	struct bch_devs_mask new_online_devs;
1522 	int nr_rw = 0, required;
1523 
1524 	lockdep_assert_held(&c->state_lock);
1525 
1526 	switch (new_state) {
1527 	case BCH_MEMBER_STATE_rw:
1528 		return true;
1529 	case BCH_MEMBER_STATE_ro:
1530 		if (ca->mi.state != BCH_MEMBER_STATE_rw)
1531 			return true;
1532 
1533 		/* do we have enough devices to write to?  */
1534 		for_each_member_device(c, ca2)
1535 			if (ca2 != ca)
1536 				nr_rw += ca2->mi.state == BCH_MEMBER_STATE_rw;
1537 
1538 		required = max(!(flags & BCH_FORCE_IF_METADATA_DEGRADED)
1539 			       ? c->opts.metadata_replicas
1540 			       : metadata_replicas_required(c),
1541 			       !(flags & BCH_FORCE_IF_DATA_DEGRADED)
1542 			       ? c->opts.data_replicas
1543 			       : data_replicas_required(c));
1544 
1545 		return nr_rw >= required;
1546 	case BCH_MEMBER_STATE_failed:
1547 	case BCH_MEMBER_STATE_spare:
1548 		if (ca->mi.state != BCH_MEMBER_STATE_rw &&
1549 		    ca->mi.state != BCH_MEMBER_STATE_ro)
1550 			return true;
1551 
1552 		/* do we have enough devices to read from?  */
1553 		new_online_devs = bch2_online_devs(c);
1554 		__clear_bit(ca->dev_idx, new_online_devs.d);
1555 
1556 		return bch2_have_enough_devs(c, new_online_devs, flags, false);
1557 	default:
1558 		BUG();
1559 	}
1560 }
1561 
1562 static bool bch2_fs_may_start(struct bch_fs *c)
1563 {
1564 	struct bch_dev *ca;
1565 	unsigned i, flags = 0;
1566 
1567 	if (c->opts.very_degraded)
1568 		flags |= BCH_FORCE_IF_DEGRADED|BCH_FORCE_IF_LOST;
1569 
1570 	if (c->opts.degraded)
1571 		flags |= BCH_FORCE_IF_DEGRADED;
1572 
1573 	if (!c->opts.degraded &&
1574 	    !c->opts.very_degraded) {
1575 		mutex_lock(&c->sb_lock);
1576 
1577 		for (i = 0; i < c->disk_sb.sb->nr_devices; i++) {
1578 			if (!bch2_member_exists(c->disk_sb.sb, i))
1579 				continue;
1580 
1581 			ca = bch2_dev_locked(c, i);
1582 
1583 			if (!bch2_dev_is_online(ca) &&
1584 			    (ca->mi.state == BCH_MEMBER_STATE_rw ||
1585 			     ca->mi.state == BCH_MEMBER_STATE_ro)) {
1586 				mutex_unlock(&c->sb_lock);
1587 				return false;
1588 			}
1589 		}
1590 		mutex_unlock(&c->sb_lock);
1591 	}
1592 
1593 	return bch2_have_enough_devs(c, bch2_online_devs(c), flags, true);
1594 }
1595 
1596 static void __bch2_dev_read_only(struct bch_fs *c, struct bch_dev *ca)
1597 {
1598 	bch2_dev_io_ref_stop(ca, WRITE);
1599 
1600 	/*
1601 	 * The allocator thread itself allocates btree nodes, so stop it first:
1602 	 */
1603 	bch2_dev_allocator_remove(c, ca);
1604 	bch2_recalc_capacity(c);
1605 	bch2_dev_journal_stop(&c->journal, ca);
1606 }
1607 
1608 static void __bch2_dev_read_write(struct bch_fs *c, struct bch_dev *ca)
1609 {
1610 	lockdep_assert_held(&c->state_lock);
1611 
1612 	BUG_ON(ca->mi.state != BCH_MEMBER_STATE_rw);
1613 
1614 	bch2_dev_allocator_add(c, ca);
1615 	bch2_recalc_capacity(c);
1616 
1617 	if (percpu_ref_is_zero(&ca->io_ref[WRITE]))
1618 		percpu_ref_reinit(&ca->io_ref[WRITE]);
1619 
1620 	bch2_dev_do_discards(ca);
1621 }
1622 
1623 int __bch2_dev_set_state(struct bch_fs *c, struct bch_dev *ca,
1624 			 enum bch_member_state new_state, int flags)
1625 {
1626 	struct bch_member *m;
1627 	int ret = 0;
1628 
1629 	if (ca->mi.state == new_state)
1630 		return 0;
1631 
1632 	if (!bch2_dev_state_allowed(c, ca, new_state, flags))
1633 		return -BCH_ERR_device_state_not_allowed;
1634 
1635 	if (new_state != BCH_MEMBER_STATE_rw)
1636 		__bch2_dev_read_only(c, ca);
1637 
1638 	bch_notice(ca, "%s", bch2_member_states[new_state]);
1639 
1640 	mutex_lock(&c->sb_lock);
1641 	m = bch2_members_v2_get_mut(c->disk_sb.sb, ca->dev_idx);
1642 	SET_BCH_MEMBER_STATE(m, new_state);
1643 	bch2_write_super(c);
1644 	mutex_unlock(&c->sb_lock);
1645 
1646 	if (new_state == BCH_MEMBER_STATE_rw)
1647 		__bch2_dev_read_write(c, ca);
1648 
1649 	rebalance_wakeup(c);
1650 
1651 	return ret;
1652 }
1653 
1654 int bch2_dev_set_state(struct bch_fs *c, struct bch_dev *ca,
1655 		       enum bch_member_state new_state, int flags)
1656 {
1657 	int ret;
1658 
1659 	down_write(&c->state_lock);
1660 	ret = __bch2_dev_set_state(c, ca, new_state, flags);
1661 	up_write(&c->state_lock);
1662 
1663 	return ret;
1664 }
1665 
1666 /* Device add/removal: */
1667 
1668 int bch2_dev_remove(struct bch_fs *c, struct bch_dev *ca, int flags)
1669 {
1670 	struct bch_member *m;
1671 	unsigned dev_idx = ca->dev_idx, data;
1672 	int ret;
1673 
1674 	down_write(&c->state_lock);
1675 
1676 	/*
1677 	 * We consume a reference to ca->ref, regardless of whether we succeed
1678 	 * or fail:
1679 	 */
1680 	bch2_dev_put(ca);
1681 
1682 	if (!bch2_dev_state_allowed(c, ca, BCH_MEMBER_STATE_failed, flags)) {
1683 		bch_err(ca, "Cannot remove without losing data");
1684 		ret = -BCH_ERR_device_state_not_allowed;
1685 		goto err;
1686 	}
1687 
1688 	__bch2_dev_read_only(c, ca);
1689 
1690 	ret = bch2_dev_data_drop(c, ca->dev_idx, flags);
1691 	bch_err_msg(ca, ret, "bch2_dev_data_drop()");
1692 	if (ret)
1693 		goto err;
1694 
1695 	ret = bch2_dev_remove_alloc(c, ca);
1696 	bch_err_msg(ca, ret, "bch2_dev_remove_alloc()");
1697 	if (ret)
1698 		goto err;
1699 
1700 	/*
1701 	 * We need to flush the entire journal to get rid of keys that reference
1702 	 * the device being removed before removing the superblock entry
1703 	 */
1704 	bch2_journal_flush_all_pins(&c->journal);
1705 
1706 	/*
1707 	 * this is really just needed for the bch2_replicas_gc_(start|end)
1708 	 * calls, and could be cleaned up:
1709 	 */
1710 	ret = bch2_journal_flush_device_pins(&c->journal, ca->dev_idx);
1711 	bch_err_msg(ca, ret, "bch2_journal_flush_device_pins()");
1712 	if (ret)
1713 		goto err;
1714 
1715 	ret = bch2_journal_flush(&c->journal);
1716 	bch_err_msg(ca, ret, "bch2_journal_flush()");
1717 	if (ret)
1718 		goto err;
1719 
1720 	ret = bch2_replicas_gc2(c);
1721 	bch_err_msg(ca, ret, "bch2_replicas_gc2()");
1722 	if (ret)
1723 		goto err;
1724 
1725 	data = bch2_dev_has_data(c, ca);
1726 	if (data) {
1727 		struct printbuf data_has = PRINTBUF;
1728 
1729 		prt_bitflags(&data_has, __bch2_data_types, data);
1730 		bch_err(ca, "Remove failed, still has data (%s)", data_has.buf);
1731 		printbuf_exit(&data_has);
1732 		ret = -EBUSY;
1733 		goto err;
1734 	}
1735 
1736 	__bch2_dev_offline(c, ca);
1737 
1738 	mutex_lock(&c->sb_lock);
1739 	rcu_assign_pointer(c->devs[ca->dev_idx], NULL);
1740 	mutex_unlock(&c->sb_lock);
1741 
1742 #ifndef CONFIG_BCACHEFS_DEBUG
1743 	percpu_ref_kill(&ca->ref);
1744 #else
1745 	ca->dying = true;
1746 	bch2_dev_put(ca);
1747 #endif
1748 	wait_for_completion(&ca->ref_completion);
1749 
1750 	bch2_dev_free(ca);
1751 
1752 	/*
1753 	 * Free this device's slot in the bch_member array - all pointers to
1754 	 * this device must be gone:
1755 	 */
1756 	mutex_lock(&c->sb_lock);
1757 	m = bch2_members_v2_get_mut(c->disk_sb.sb, dev_idx);
1758 	memset(&m->uuid, 0, sizeof(m->uuid));
1759 
1760 	bch2_write_super(c);
1761 
1762 	mutex_unlock(&c->sb_lock);
1763 	up_write(&c->state_lock);
1764 	return 0;
1765 err:
1766 	if (test_bit(BCH_FS_rw, &c->flags) &&
1767 	    ca->mi.state == BCH_MEMBER_STATE_rw &&
1768 	    !percpu_ref_is_zero(&ca->io_ref[READ]))
1769 		__bch2_dev_read_write(c, ca);
1770 	up_write(&c->state_lock);
1771 	return ret;
1772 }
1773 
1774 /* Add new device to running filesystem: */
1775 int bch2_dev_add(struct bch_fs *c, const char *path)
1776 {
1777 	struct bch_opts opts = bch2_opts_empty();
1778 	struct bch_sb_handle sb;
1779 	struct bch_dev *ca = NULL;
1780 	struct printbuf errbuf = PRINTBUF;
1781 	struct printbuf label = PRINTBUF;
1782 	int ret;
1783 
1784 	ret = bch2_read_super(path, &opts, &sb);
1785 	bch_err_msg(c, ret, "reading super");
1786 	if (ret)
1787 		goto err;
1788 
1789 	struct bch_member dev_mi = bch2_sb_member_get(sb.sb, sb.sb->dev_idx);
1790 
1791 	if (BCH_MEMBER_GROUP(&dev_mi)) {
1792 		bch2_disk_path_to_text_sb(&label, sb.sb, BCH_MEMBER_GROUP(&dev_mi) - 1);
1793 		if (label.allocation_failure) {
1794 			ret = -ENOMEM;
1795 			goto err;
1796 		}
1797 	}
1798 
1799 	ret = bch2_dev_may_add(sb.sb, c);
1800 	if (ret)
1801 		goto err;
1802 
1803 	ca = __bch2_dev_alloc(c, &dev_mi);
1804 	if (!ca) {
1805 		ret = -ENOMEM;
1806 		goto err;
1807 	}
1808 
1809 	ret = __bch2_dev_attach_bdev(ca, &sb);
1810 	if (ret)
1811 		goto err;
1812 
1813 	down_write(&c->state_lock);
1814 	mutex_lock(&c->sb_lock);
1815 
1816 	ret = bch2_sb_from_fs(c, ca);
1817 	bch_err_msg(c, ret, "setting up new superblock");
1818 	if (ret)
1819 		goto err_unlock;
1820 
1821 	if (dynamic_fault("bcachefs:add:no_slot"))
1822 		goto err_unlock;
1823 
1824 	ret = bch2_sb_member_alloc(c);
1825 	if (ret < 0) {
1826 		bch_err_msg(c, ret, "setting up new superblock");
1827 		goto err_unlock;
1828 	}
1829 	unsigned dev_idx = ret;
1830 
1831 	/* success: */
1832 
1833 	dev_mi.last_mount = cpu_to_le64(ktime_get_real_seconds());
1834 	*bch2_members_v2_get_mut(c->disk_sb.sb, dev_idx) = dev_mi;
1835 
1836 	ca->disk_sb.sb->dev_idx	= dev_idx;
1837 	bch2_dev_attach(c, ca, dev_idx);
1838 
1839 	if (BCH_MEMBER_GROUP(&dev_mi)) {
1840 		ret = __bch2_dev_group_set(c, ca, label.buf);
1841 		bch_err_msg(c, ret, "creating new label");
1842 		if (ret)
1843 			goto err_unlock;
1844 	}
1845 
1846 	bch2_write_super(c);
1847 	mutex_unlock(&c->sb_lock);
1848 
1849 	ret = bch2_dev_usage_init(ca, false);
1850 	if (ret)
1851 		goto err_late;
1852 
1853 	ret = bch2_trans_mark_dev_sb(c, ca, BTREE_TRIGGER_transactional);
1854 	bch_err_msg(ca, ret, "marking new superblock");
1855 	if (ret)
1856 		goto err_late;
1857 
1858 	ret = bch2_fs_freespace_init(c);
1859 	bch_err_msg(ca, ret, "initializing free space");
1860 	if (ret)
1861 		goto err_late;
1862 
1863 	if (ca->mi.state == BCH_MEMBER_STATE_rw)
1864 		__bch2_dev_read_write(c, ca);
1865 
1866 	ret = bch2_dev_journal_alloc(ca, false);
1867 	bch_err_msg(c, ret, "allocating journal");
1868 	if (ret)
1869 		goto err_late;
1870 
1871 	up_write(&c->state_lock);
1872 out:
1873 	printbuf_exit(&label);
1874 	printbuf_exit(&errbuf);
1875 	bch_err_fn(c, ret);
1876 	return ret;
1877 
1878 err_unlock:
1879 	mutex_unlock(&c->sb_lock);
1880 	up_write(&c->state_lock);
1881 err:
1882 	if (ca)
1883 		bch2_dev_free(ca);
1884 	bch2_free_super(&sb);
1885 	goto out;
1886 err_late:
1887 	up_write(&c->state_lock);
1888 	ca = NULL;
1889 	goto err;
1890 }
1891 
1892 /* Hot add existing device to running filesystem: */
1893 int bch2_dev_online(struct bch_fs *c, const char *path)
1894 {
1895 	struct bch_opts opts = bch2_opts_empty();
1896 	struct bch_sb_handle sb = { NULL };
1897 	struct bch_dev *ca;
1898 	unsigned dev_idx;
1899 	int ret;
1900 
1901 	down_write(&c->state_lock);
1902 
1903 	ret = bch2_read_super(path, &opts, &sb);
1904 	if (ret) {
1905 		up_write(&c->state_lock);
1906 		return ret;
1907 	}
1908 
1909 	dev_idx = sb.sb->dev_idx;
1910 
1911 	ret = bch2_dev_in_fs(&c->disk_sb, &sb, &c->opts);
1912 	bch_err_msg(c, ret, "bringing %s online", path);
1913 	if (ret)
1914 		goto err;
1915 
1916 	ret = bch2_dev_attach_bdev(c, &sb);
1917 	if (ret)
1918 		goto err;
1919 
1920 	ca = bch2_dev_locked(c, dev_idx);
1921 
1922 	ret = bch2_trans_mark_dev_sb(c, ca, BTREE_TRIGGER_transactional);
1923 	bch_err_msg(c, ret, "bringing %s online: error from bch2_trans_mark_dev_sb", path);
1924 	if (ret)
1925 		goto err;
1926 
1927 	if (ca->mi.state == BCH_MEMBER_STATE_rw)
1928 		__bch2_dev_read_write(c, ca);
1929 
1930 	if (!ca->mi.freespace_initialized) {
1931 		ret = bch2_dev_freespace_init(c, ca, 0, ca->mi.nbuckets);
1932 		bch_err_msg(ca, ret, "initializing free space");
1933 		if (ret)
1934 			goto err;
1935 	}
1936 
1937 	if (!ca->journal.nr) {
1938 		ret = bch2_dev_journal_alloc(ca, false);
1939 		bch_err_msg(ca, ret, "allocating journal");
1940 		if (ret)
1941 			goto err;
1942 	}
1943 
1944 	mutex_lock(&c->sb_lock);
1945 	bch2_members_v2_get_mut(c->disk_sb.sb, ca->dev_idx)->last_mount =
1946 		cpu_to_le64(ktime_get_real_seconds());
1947 	bch2_write_super(c);
1948 	mutex_unlock(&c->sb_lock);
1949 
1950 	up_write(&c->state_lock);
1951 	return 0;
1952 err:
1953 	up_write(&c->state_lock);
1954 	bch2_free_super(&sb);
1955 	return ret;
1956 }
1957 
1958 int bch2_dev_offline(struct bch_fs *c, struct bch_dev *ca, int flags)
1959 {
1960 	down_write(&c->state_lock);
1961 
1962 	if (!bch2_dev_is_online(ca)) {
1963 		bch_err(ca, "Already offline");
1964 		up_write(&c->state_lock);
1965 		return 0;
1966 	}
1967 
1968 	if (!bch2_dev_state_allowed(c, ca, BCH_MEMBER_STATE_failed, flags)) {
1969 		bch_err(ca, "Cannot offline required disk");
1970 		up_write(&c->state_lock);
1971 		return -BCH_ERR_device_state_not_allowed;
1972 	}
1973 
1974 	__bch2_dev_offline(c, ca);
1975 
1976 	up_write(&c->state_lock);
1977 	return 0;
1978 }
1979 
1980 int bch2_dev_resize(struct bch_fs *c, struct bch_dev *ca, u64 nbuckets)
1981 {
1982 	struct bch_member *m;
1983 	u64 old_nbuckets;
1984 	int ret = 0;
1985 
1986 	down_write(&c->state_lock);
1987 	old_nbuckets = ca->mi.nbuckets;
1988 
1989 	if (nbuckets < ca->mi.nbuckets) {
1990 		bch_err(ca, "Cannot shrink yet");
1991 		ret = -EINVAL;
1992 		goto err;
1993 	}
1994 
1995 	if (nbuckets > BCH_MEMBER_NBUCKETS_MAX) {
1996 		bch_err(ca, "New device size too big (%llu greater than max %u)",
1997 			nbuckets, BCH_MEMBER_NBUCKETS_MAX);
1998 		ret = -BCH_ERR_device_size_too_big;
1999 		goto err;
2000 	}
2001 
2002 	if (bch2_dev_is_online(ca) &&
2003 	    get_capacity(ca->disk_sb.bdev->bd_disk) <
2004 	    ca->mi.bucket_size * nbuckets) {
2005 		bch_err(ca, "New size larger than device");
2006 		ret = -BCH_ERR_device_size_too_small;
2007 		goto err;
2008 	}
2009 
2010 	ret = bch2_dev_buckets_resize(c, ca, nbuckets);
2011 	bch_err_msg(ca, ret, "resizing buckets");
2012 	if (ret)
2013 		goto err;
2014 
2015 	ret = bch2_trans_mark_dev_sb(c, ca, BTREE_TRIGGER_transactional);
2016 	if (ret)
2017 		goto err;
2018 
2019 	mutex_lock(&c->sb_lock);
2020 	m = bch2_members_v2_get_mut(c->disk_sb.sb, ca->dev_idx);
2021 	m->nbuckets = cpu_to_le64(nbuckets);
2022 
2023 	bch2_write_super(c);
2024 	mutex_unlock(&c->sb_lock);
2025 
2026 	if (ca->mi.freespace_initialized) {
2027 		u64 v[3] = { nbuckets - old_nbuckets, 0, 0 };
2028 
2029 		ret   = bch2_trans_commit_do(ca->fs, NULL, NULL, 0,
2030 				bch2_disk_accounting_mod2(trans, false, v, dev_data_type,
2031 							  .dev = ca->dev_idx,
2032 							  .data_type = BCH_DATA_free)) ?:
2033 			bch2_dev_freespace_init(c, ca, old_nbuckets, nbuckets);
2034 		if (ret)
2035 			goto err;
2036 	}
2037 
2038 	bch2_recalc_capacity(c);
2039 err:
2040 	up_write(&c->state_lock);
2041 	return ret;
2042 }
2043 
2044 /* return with ref on ca->ref: */
2045 struct bch_dev *bch2_dev_lookup(struct bch_fs *c, const char *name)
2046 {
2047 	if (!strncmp(name, "/dev/", strlen("/dev/")))
2048 		name += strlen("/dev/");
2049 
2050 	for_each_member_device(c, ca)
2051 		if (!strcmp(name, ca->name))
2052 			return ca;
2053 	return ERR_PTR(-BCH_ERR_ENOENT_dev_not_found);
2054 }
2055 
2056 /* blk_holder_ops: */
2057 
2058 static struct bch_fs *bdev_get_fs(struct block_device *bdev)
2059 	__releases(&bdev->bd_holder_lock)
2060 {
2061 	struct bch_sb_handle_holder *holder = bdev->bd_holder;
2062 	struct bch_fs *c = holder->c;
2063 
2064 	if (c && !bch2_ro_ref_tryget(c))
2065 		c = NULL;
2066 
2067 	mutex_unlock(&bdev->bd_holder_lock);
2068 
2069 	if (c)
2070 		wait_event(c->ro_ref_wait, test_bit(BCH_FS_started, &c->flags));
2071 	return c;
2072 }
2073 
2074 /* returns with ref on ca->ref */
2075 static struct bch_dev *bdev_to_bch_dev(struct bch_fs *c, struct block_device *bdev)
2076 {
2077 	for_each_member_device(c, ca)
2078 		if (ca->disk_sb.bdev == bdev)
2079 			return ca;
2080 	return NULL;
2081 }
2082 
2083 static void bch2_fs_bdev_mark_dead(struct block_device *bdev, bool surprise)
2084 {
2085 	struct bch_fs *c = bdev_get_fs(bdev);
2086 	if (!c)
2087 		return;
2088 
2089 	struct super_block *sb = c->vfs_sb;
2090 	if (sb) {
2091 		/*
2092 		 * Not necessary, c->ro_ref guards against the filesystem being
2093 		 * unmounted - we only take this to avoid a warning in
2094 		 * sync_filesystem:
2095 		 */
2096 		down_read(&sb->s_umount);
2097 	}
2098 
2099 	down_write(&c->state_lock);
2100 	struct bch_dev *ca = bdev_to_bch_dev(c, bdev);
2101 	if (!ca)
2102 		goto unlock;
2103 
2104 	if (bch2_dev_state_allowed(c, ca, BCH_MEMBER_STATE_failed, BCH_FORCE_IF_DEGRADED)) {
2105 		__bch2_dev_offline(c, ca);
2106 	} else {
2107 		if (sb) {
2108 			if (!surprise)
2109 				sync_filesystem(sb);
2110 			shrink_dcache_sb(sb);
2111 			evict_inodes(sb);
2112 		}
2113 
2114 		bch2_journal_flush(&c->journal);
2115 		bch2_fs_emergency_read_only(c);
2116 	}
2117 
2118 	bch2_dev_put(ca);
2119 unlock:
2120 	if (sb)
2121 		up_read(&sb->s_umount);
2122 	up_write(&c->state_lock);
2123 	bch2_ro_ref_put(c);
2124 }
2125 
2126 static void bch2_fs_bdev_sync(struct block_device *bdev)
2127 {
2128 	struct bch_fs *c = bdev_get_fs(bdev);
2129 	if (!c)
2130 		return;
2131 
2132 	struct super_block *sb = c->vfs_sb;
2133 	if (sb) {
2134 		/*
2135 		 * Not necessary, c->ro_ref guards against the filesystem being
2136 		 * unmounted - we only take this to avoid a warning in
2137 		 * sync_filesystem:
2138 		 */
2139 		down_read(&sb->s_umount);
2140 		sync_filesystem(sb);
2141 		up_read(&sb->s_umount);
2142 	}
2143 
2144 	bch2_ro_ref_put(c);
2145 }
2146 
2147 const struct blk_holder_ops bch2_sb_handle_bdev_ops = {
2148 	.mark_dead		= bch2_fs_bdev_mark_dead,
2149 	.sync			= bch2_fs_bdev_sync,
2150 };
2151 
2152 /* Filesystem open: */
2153 
2154 static inline int sb_cmp(struct bch_sb *l, struct bch_sb *r)
2155 {
2156 	return  cmp_int(le64_to_cpu(l->seq), le64_to_cpu(r->seq)) ?:
2157 		cmp_int(le64_to_cpu(l->write_time), le64_to_cpu(r->write_time));
2158 }
2159 
2160 struct bch_fs *bch2_fs_open(char * const *devices, unsigned nr_devices,
2161 			    struct bch_opts opts)
2162 {
2163 	DARRAY(struct bch_sb_handle) sbs = { 0 };
2164 	struct bch_fs *c = NULL;
2165 	struct bch_sb_handle *best = NULL;
2166 	struct printbuf errbuf = PRINTBUF;
2167 	int ret = 0;
2168 
2169 	if (!try_module_get(THIS_MODULE))
2170 		return ERR_PTR(-ENODEV);
2171 
2172 	if (!nr_devices) {
2173 		ret = -EINVAL;
2174 		goto err;
2175 	}
2176 
2177 	ret = darray_make_room(&sbs, nr_devices);
2178 	if (ret)
2179 		goto err;
2180 
2181 	for (unsigned i = 0; i < nr_devices; i++) {
2182 		struct bch_sb_handle sb = { NULL };
2183 
2184 		ret = bch2_read_super(devices[i], &opts, &sb);
2185 		if (ret)
2186 			goto err;
2187 
2188 		BUG_ON(darray_push(&sbs, sb));
2189 	}
2190 
2191 	if (opts.nochanges && !opts.read_only) {
2192 		ret = -BCH_ERR_erofs_nochanges;
2193 		goto err_print;
2194 	}
2195 
2196 	darray_for_each(sbs, sb)
2197 		if (!best || sb_cmp(sb->sb, best->sb) > 0)
2198 			best = sb;
2199 
2200 	darray_for_each_reverse(sbs, sb) {
2201 		ret = bch2_dev_in_fs(best, sb, &opts);
2202 
2203 		if (ret == -BCH_ERR_device_has_been_removed ||
2204 		    ret == -BCH_ERR_device_splitbrain) {
2205 			bch2_free_super(sb);
2206 			darray_remove_item(&sbs, sb);
2207 			best -= best > sb;
2208 			ret = 0;
2209 			continue;
2210 		}
2211 
2212 		if (ret)
2213 			goto err_print;
2214 	}
2215 
2216 	c = bch2_fs_alloc(best->sb, opts);
2217 	ret = PTR_ERR_OR_ZERO(c);
2218 	if (ret)
2219 		goto err;
2220 
2221 	down_write(&c->state_lock);
2222 	darray_for_each(sbs, sb) {
2223 		ret = bch2_dev_attach_bdev(c, sb);
2224 		if (ret) {
2225 			up_write(&c->state_lock);
2226 			goto err;
2227 		}
2228 	}
2229 	up_write(&c->state_lock);
2230 
2231 	if (!bch2_fs_may_start(c)) {
2232 		ret = -BCH_ERR_insufficient_devices_to_start;
2233 		goto err_print;
2234 	}
2235 
2236 	if (!c->opts.nostart) {
2237 		ret = bch2_fs_start(c);
2238 		if (ret)
2239 			goto err;
2240 	}
2241 out:
2242 	darray_for_each(sbs, sb)
2243 		bch2_free_super(sb);
2244 	darray_exit(&sbs);
2245 	printbuf_exit(&errbuf);
2246 	module_put(THIS_MODULE);
2247 	return c;
2248 err_print:
2249 	pr_err("bch_fs_open err opening %s: %s",
2250 	       devices[0], bch2_err_str(ret));
2251 err:
2252 	if (!IS_ERR_OR_NULL(c))
2253 		bch2_fs_stop(c);
2254 	c = ERR_PTR(ret);
2255 	goto out;
2256 }
2257 
2258 /* Global interfaces/init */
2259 
2260 static void bcachefs_exit(void)
2261 {
2262 	bch2_debug_exit();
2263 	bch2_vfs_exit();
2264 	bch2_chardev_exit();
2265 	bch2_btree_key_cache_exit();
2266 	if (bcachefs_kset)
2267 		kset_unregister(bcachefs_kset);
2268 }
2269 
2270 static int __init bcachefs_init(void)
2271 {
2272 	bch2_bkey_pack_test();
2273 
2274 	if (!(bcachefs_kset = kset_create_and_add("bcachefs", NULL, fs_kobj)) ||
2275 	    bch2_btree_key_cache_init() ||
2276 	    bch2_chardev_init() ||
2277 	    bch2_vfs_init() ||
2278 	    bch2_debug_init())
2279 		goto err;
2280 
2281 	return 0;
2282 err:
2283 	bcachefs_exit();
2284 	return -ENOMEM;
2285 }
2286 
2287 #define BCH_DEBUG_PARAM(name, description)			\
2288 	bool bch2_##name;					\
2289 	module_param_named(name, bch2_##name, bool, 0644);	\
2290 	MODULE_PARM_DESC(name, description);
2291 BCH_DEBUG_PARAMS()
2292 #undef BCH_DEBUG_PARAM
2293 
2294 __maybe_unused
2295 static unsigned bch2_metadata_version = bcachefs_metadata_version_current;
2296 module_param_named(version, bch2_metadata_version, uint, 0444);
2297 
2298 module_exit(bcachefs_exit);
2299 module_init(bcachefs_init);
2300