xref: /minix3/sys/ufs/lfs/lfs_rfw.c (revision 0a6a1f1d05b60e214de2f05a7310ddd1f0e590e7)
1*0a6a1f1dSLionel Sambuc /*	$NetBSD: lfs_rfw.c,v 1.32 2015/10/03 08:27:55 dholland Exp $	*/
2d65f6f70SBen Gras 
3d65f6f70SBen Gras /*-
4d65f6f70SBen Gras  * Copyright (c) 1999, 2000, 2001, 2002, 2003 The NetBSD Foundation, Inc.
5d65f6f70SBen Gras  * All rights reserved.
6d65f6f70SBen Gras  *
7d65f6f70SBen Gras  * This code is derived from software contributed to The NetBSD Foundation
8d65f6f70SBen Gras  * by Konrad E. Schroder <perseant@hhhh.org>.
9d65f6f70SBen Gras  *
10d65f6f70SBen Gras  * Redistribution and use in source and binary forms, with or without
11d65f6f70SBen Gras  * modification, are permitted provided that the following conditions
12d65f6f70SBen Gras  * are met:
13d65f6f70SBen Gras  * 1. Redistributions of source code must retain the above copyright
14d65f6f70SBen Gras  *    notice, this list of conditions and the following disclaimer.
15d65f6f70SBen Gras  * 2. Redistributions in binary form must reproduce the above copyright
16d65f6f70SBen Gras  *    notice, this list of conditions and the following disclaimer in the
17d65f6f70SBen Gras  *    documentation and/or other materials provided with the distribution.
18d65f6f70SBen Gras  *
19d65f6f70SBen Gras  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20d65f6f70SBen Gras  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21d65f6f70SBen Gras  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22d65f6f70SBen Gras  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23d65f6f70SBen Gras  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24d65f6f70SBen Gras  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25d65f6f70SBen Gras  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26d65f6f70SBen Gras  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27d65f6f70SBen Gras  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28d65f6f70SBen Gras  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29d65f6f70SBen Gras  * POSSIBILITY OF SUCH DAMAGE.
30d65f6f70SBen Gras  */
31d65f6f70SBen Gras 
32d65f6f70SBen Gras #include <sys/cdefs.h>
33*0a6a1f1dSLionel Sambuc __KERNEL_RCSID(0, "$NetBSD: lfs_rfw.c,v 1.32 2015/10/03 08:27:55 dholland Exp $");
34d65f6f70SBen Gras 
35d65f6f70SBen Gras #if defined(_KERNEL_OPT)
36d65f6f70SBen Gras #include "opt_quota.h"
37d65f6f70SBen Gras #endif
38d65f6f70SBen Gras 
39d65f6f70SBen Gras #include <sys/param.h>
40d65f6f70SBen Gras #include <sys/systm.h>
41d65f6f70SBen Gras #include <sys/namei.h>
42d65f6f70SBen Gras #include <sys/proc.h>
43d65f6f70SBen Gras #include <sys/kernel.h>
44d65f6f70SBen Gras #include <sys/vnode.h>
45d65f6f70SBen Gras #include <sys/mount.h>
46d65f6f70SBen Gras #include <sys/kthread.h>
47d65f6f70SBen Gras #include <sys/buf.h>
48d65f6f70SBen Gras #include <sys/device.h>
49d65f6f70SBen Gras #include <sys/mbuf.h>
50d65f6f70SBen Gras #include <sys/file.h>
51d65f6f70SBen Gras #include <sys/disklabel.h>
52d65f6f70SBen Gras #include <sys/ioctl.h>
53d65f6f70SBen Gras #include <sys/errno.h>
54d65f6f70SBen Gras #include <sys/malloc.h>
55d65f6f70SBen Gras #include <sys/pool.h>
56d65f6f70SBen Gras #include <sys/socket.h>
57d65f6f70SBen Gras #include <sys/syslog.h>
58d65f6f70SBen Gras #include <uvm/uvm_extern.h>
59d65f6f70SBen Gras #include <sys/sysctl.h>
60d65f6f70SBen Gras #include <sys/conf.h>
61d65f6f70SBen Gras #include <sys/kauth.h>
62d65f6f70SBen Gras 
63d65f6f70SBen Gras #include <miscfs/specfs/specdev.h>
64d65f6f70SBen Gras 
6584d9c625SLionel Sambuc #include <ufs/lfs/ulfs_quotacommon.h>
6684d9c625SLionel Sambuc #include <ufs/lfs/ulfs_inode.h>
6784d9c625SLionel Sambuc #include <ufs/lfs/ulfsmount.h>
6884d9c625SLionel Sambuc #include <ufs/lfs/ulfs_extern.h>
69d65f6f70SBen Gras 
70d65f6f70SBen Gras #include <uvm/uvm.h>
71d65f6f70SBen Gras #include <uvm/uvm_stat.h>
72d65f6f70SBen Gras #include <uvm/uvm_pager.h>
73d65f6f70SBen Gras #include <uvm/uvm_pdaemon.h>
74d65f6f70SBen Gras 
75d65f6f70SBen Gras #include <ufs/lfs/lfs.h>
76*0a6a1f1dSLionel Sambuc #include <ufs/lfs/lfs_accessors.h>
7784d9c625SLionel Sambuc #include <ufs/lfs/lfs_kernel.h>
78d65f6f70SBen Gras #include <ufs/lfs/lfs_extern.h>
79d65f6f70SBen Gras 
80d65f6f70SBen Gras #include <miscfs/genfs/genfs.h>
81d65f6f70SBen Gras #include <miscfs/genfs/genfs_node.h>
82d65f6f70SBen Gras 
83d65f6f70SBen Gras /*
84d65f6f70SBen Gras  * Roll-forward code.
85d65f6f70SBen Gras  */
86d65f6f70SBen Gras static daddr_t check_segsum(struct lfs *, daddr_t, u_int64_t,
87d65f6f70SBen Gras     kauth_cred_t, int, int *, struct lwp *);
88d65f6f70SBen Gras 
89d65f6f70SBen Gras extern int lfs_do_rfw;
90d65f6f70SBen Gras 
91d65f6f70SBen Gras /*
92d65f6f70SBen Gras  * Allocate a particular inode with a particular version number, freeing
93d65f6f70SBen Gras  * any previous versions of this inode that may have gone before.
94d65f6f70SBen Gras  * Used by the roll-forward code.
95d65f6f70SBen Gras  *
96d65f6f70SBen Gras  * XXX this function does not have appropriate locking to be used on a live fs;
97d65f6f70SBen Gras  * XXX but something similar could probably be used for an "undelete" call.
98d65f6f70SBen Gras  *
99d65f6f70SBen Gras  * Called with the Ifile inode locked.
100d65f6f70SBen Gras  */
101d65f6f70SBen Gras int
lfs_rf_valloc(struct lfs * fs,ino_t ino,int vers,struct lwp * l,struct vnode ** vpp)102d65f6f70SBen Gras lfs_rf_valloc(struct lfs *fs, ino_t ino, int vers, struct lwp *l,
103d65f6f70SBen Gras 	      struct vnode **vpp)
104d65f6f70SBen Gras {
105*0a6a1f1dSLionel Sambuc 	struct vattr va;
106d65f6f70SBen Gras 	struct vnode *vp;
107d65f6f70SBen Gras 	struct inode *ip;
108d65f6f70SBen Gras 	int error;
109d65f6f70SBen Gras 
110d65f6f70SBen Gras 	ASSERT_SEGLOCK(fs); /* XXX it doesn't, really */
111d65f6f70SBen Gras 
112d65f6f70SBen Gras 	/*
113d65f6f70SBen Gras 	 * First, just try a vget. If the version number is the one we want,
114d65f6f70SBen Gras 	 * we don't have to do anything else.  If the version number is wrong,
115d65f6f70SBen Gras 	 * take appropriate action.
116d65f6f70SBen Gras 	 */
117d65f6f70SBen Gras 	error = VFS_VGET(fs->lfs_ivnode->v_mount, ino, &vp);
118d65f6f70SBen Gras 	if (error == 0) {
119d65f6f70SBen Gras 		DLOG((DLOG_RF, "lfs_rf_valloc[1]: ino %d vp %p\n", ino, vp));
120d65f6f70SBen Gras 
121d65f6f70SBen Gras 		*vpp = vp;
122d65f6f70SBen Gras 		ip = VTOI(vp);
123d65f6f70SBen Gras 		if (ip->i_gen == vers)
124d65f6f70SBen Gras 			return 0;
125d65f6f70SBen Gras 		else if (ip->i_gen < vers) {
126d65f6f70SBen Gras 			lfs_truncate(vp, (off_t)0, 0, NOCRED);
127*0a6a1f1dSLionel Sambuc 			ip->i_gen = vers;
128*0a6a1f1dSLionel Sambuc 			lfs_dino_setgen(fs, ip->i_din, vers);
129d65f6f70SBen Gras 			LFS_SET_UINO(ip, IN_CHANGE | IN_UPDATE);
130d65f6f70SBen Gras 			return 0;
131d65f6f70SBen Gras 		} else {
132d65f6f70SBen Gras 			DLOG((DLOG_RF, "ino %d: sought version %d, got %d\n",
133*0a6a1f1dSLionel Sambuc 			       ino, vers, lfs_dino_getgen(fs, ip->i_din)));
134d65f6f70SBen Gras 			vput(vp);
135d65f6f70SBen Gras 			*vpp = NULLVP;
136d65f6f70SBen Gras 			return EEXIST;
137d65f6f70SBen Gras 		}
138d65f6f70SBen Gras 	}
139d65f6f70SBen Gras 
140*0a6a1f1dSLionel Sambuc 	/* Not found, create as regular file. */
141*0a6a1f1dSLionel Sambuc 	vattr_null(&va);
142*0a6a1f1dSLionel Sambuc 	va.va_type = VREG;
143*0a6a1f1dSLionel Sambuc 	va.va_mode = 0;
144*0a6a1f1dSLionel Sambuc 	va.va_fileid = ino;
145*0a6a1f1dSLionel Sambuc 	va.va_gen = vers;
146*0a6a1f1dSLionel Sambuc 	error = vcache_new(fs->lfs_ivnode->v_mount, NULL, &va, NOCRED, &vp);
147*0a6a1f1dSLionel Sambuc 	if (error)
148d65f6f70SBen Gras 		return error;
149*0a6a1f1dSLionel Sambuc 	error = vn_lock(vp, LK_EXCLUSIVE);
150*0a6a1f1dSLionel Sambuc 	if (error) {
151*0a6a1f1dSLionel Sambuc 		vrele(vp);
152*0a6a1f1dSLionel Sambuc 		*vpp = NULLVP;
153*0a6a1f1dSLionel Sambuc 		return error;
154*0a6a1f1dSLionel Sambuc 	}
155*0a6a1f1dSLionel Sambuc 	ip = VTOI(vp);
156*0a6a1f1dSLionel Sambuc 	ip->i_nlink = 1;
157*0a6a1f1dSLionel Sambuc 	lfs_dino_setnlink(fs, ip->i_din, 1);
158*0a6a1f1dSLionel Sambuc 	*vpp = vp;
159*0a6a1f1dSLionel Sambuc 	return 0;
160d65f6f70SBen Gras }
161d65f6f70SBen Gras 
162d65f6f70SBen Gras /*
163d65f6f70SBen Gras  * Load the appropriate indirect block, and change the appropriate pointer.
164d65f6f70SBen Gras  * Mark the block dirty.  Do segment and avail accounting.
165d65f6f70SBen Gras  */
166d65f6f70SBen Gras static int
update_meta(struct lfs * fs,ino_t ino,int vers,daddr_t lbn,daddr_t ndaddr,size_t size,struct lwp * l)167d65f6f70SBen Gras update_meta(struct lfs *fs, ino_t ino, int vers, daddr_t lbn,
168d65f6f70SBen Gras 	    daddr_t ndaddr, size_t size, struct lwp *l)
169d65f6f70SBen Gras {
170d65f6f70SBen Gras 	int error;
171d65f6f70SBen Gras 	struct vnode *vp;
172d65f6f70SBen Gras 	struct inode *ip;
173d65f6f70SBen Gras #ifdef DEBUG
174d65f6f70SBen Gras 	daddr_t odaddr;
17584d9c625SLionel Sambuc 	struct indir a[ULFS_NIADDR];
176d65f6f70SBen Gras 	int num;
177d65f6f70SBen Gras 	int i;
178d65f6f70SBen Gras #endif /* DEBUG */
179d65f6f70SBen Gras 	struct buf *bp;
180d65f6f70SBen Gras 	SEGUSE *sup;
181d65f6f70SBen Gras 
182d65f6f70SBen Gras 	KASSERT(lbn >= 0);	/* no indirect blocks */
183d65f6f70SBen Gras 
184d65f6f70SBen Gras 	if ((error = lfs_rf_valloc(fs, ino, vers, l, &vp)) != 0) {
185d65f6f70SBen Gras 		DLOG((DLOG_RF, "update_meta: ino %d: lfs_rf_valloc"
186d65f6f70SBen Gras 		      " returned %d\n", ino, error));
187d65f6f70SBen Gras 		return error;
188d65f6f70SBen Gras 	}
189d65f6f70SBen Gras 
190*0a6a1f1dSLionel Sambuc 	if ((error = lfs_balloc(vp, (lbn << lfs_sb_getbshift(fs)), size,
191d65f6f70SBen Gras 				NOCRED, 0, &bp)) != 0) {
192d65f6f70SBen Gras 		vput(vp);
193d65f6f70SBen Gras 		return (error);
194d65f6f70SBen Gras 	}
195d65f6f70SBen Gras 	/* No need to write, the block is already on disk */
196d65f6f70SBen Gras 	if (bp->b_oflags & BO_DELWRI) {
197d65f6f70SBen Gras 		LFS_UNLOCK_BUF(bp);
198*0a6a1f1dSLionel Sambuc 		lfs_sb_addavail(fs, lfs_btofsb(fs, bp->b_bcount));
199*0a6a1f1dSLionel Sambuc 		/* XXX should this wake up fs->lfs_availsleep? */
200d65f6f70SBen Gras 	}
201d65f6f70SBen Gras 	brelse(bp, BC_INVAL);
202d65f6f70SBen Gras 
203d65f6f70SBen Gras 	/*
204d65f6f70SBen Gras 	 * Extend the file, if it is not large enough already.
205d65f6f70SBen Gras 	 * XXX this is not exactly right, we don't know how much of the
206d65f6f70SBen Gras 	 * XXX last block is actually used.  We hope that an inode will
207d65f6f70SBen Gras 	 * XXX appear later to give the correct size.
208d65f6f70SBen Gras 	 */
209d65f6f70SBen Gras 	ip = VTOI(vp);
210*0a6a1f1dSLionel Sambuc 	if (ip->i_size <= (lbn << lfs_sb_getbshift(fs))) {
211d65f6f70SBen Gras 		u_int64_t newsize;
212d65f6f70SBen Gras 
213*0a6a1f1dSLionel Sambuc 		if (lbn < ULFS_NDADDR) {
214*0a6a1f1dSLionel Sambuc 			newsize = (lbn << lfs_sb_getbshift(fs)) +
215*0a6a1f1dSLionel Sambuc 				(size - lfs_sb_getfsize(fs)) + 1;
216*0a6a1f1dSLionel Sambuc 		} else {
217*0a6a1f1dSLionel Sambuc 			newsize = (lbn << lfs_sb_getbshift(fs)) + 1;
218*0a6a1f1dSLionel Sambuc 		}
219*0a6a1f1dSLionel Sambuc 		lfs_dino_setsize(fs, ip->i_din, newsize);
220d65f6f70SBen Gras 
221d65f6f70SBen Gras 		if (ip->i_size < newsize) {
222d65f6f70SBen Gras 			ip->i_size = newsize;
223d65f6f70SBen Gras 			/*
224d65f6f70SBen Gras 			 * tell vm our new size for the case the inode won't
225d65f6f70SBen Gras 			 * appear later.
226d65f6f70SBen Gras 			 */
227d65f6f70SBen Gras 			uvm_vnp_setsize(vp, newsize);
228d65f6f70SBen Gras 		}
229d65f6f70SBen Gras 	}
230d65f6f70SBen Gras 
231d65f6f70SBen Gras 	lfs_update_single(fs, NULL, vp, lbn, ndaddr, size);
232d65f6f70SBen Gras 
23384d9c625SLionel Sambuc 	LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, ndaddr), bp);
234d65f6f70SBen Gras 	sup->su_nbytes += size;
23584d9c625SLionel Sambuc 	LFS_WRITESEGENTRY(sup, fs, lfs_dtosn(fs, ndaddr), bp);
236d65f6f70SBen Gras 
237d65f6f70SBen Gras 	/* differences here should be due to UNWRITTEN indirect blocks. */
23884d9c625SLionel Sambuc 	KASSERT((lfs_lblkno(fs, ip->i_size) > ULFS_NDADDR &&
239*0a6a1f1dSLionel Sambuc 	    ip->i_lfs_effnblks == lfs_dino_getblocks(fs, ip->i_din)) ||
240*0a6a1f1dSLionel Sambuc 	    ip->i_lfs_effnblks >= lfs_dino_getblocks(fs, ip->i_din));
241d65f6f70SBen Gras 
242d65f6f70SBen Gras #ifdef DEBUG
243d65f6f70SBen Gras 	/* Now look again to make sure it worked */
24484d9c625SLionel Sambuc 	ulfs_bmaparray(vp, lbn, &odaddr, &a[0], &num, NULL, NULL);
245d65f6f70SBen Gras 	for (i = num; i > 0; i--) {
246d65f6f70SBen Gras 		if (!a[i].in_exists)
247d65f6f70SBen Gras 			panic("update_meta: absent %d lv indirect block", i);
248d65f6f70SBen Gras 	}
24984d9c625SLionel Sambuc 	if (LFS_DBTOFSB(fs, odaddr) != ndaddr)
250d65f6f70SBen Gras 		DLOG((DLOG_RF, "update_meta: failed setting ino %d lbn %"
251d65f6f70SBen Gras 		      PRId64 " to %" PRId64 "\n", ino, lbn, ndaddr));
252d65f6f70SBen Gras #endif /* DEBUG */
253d65f6f70SBen Gras 	vput(vp);
254d65f6f70SBen Gras 	return 0;
255d65f6f70SBen Gras }
256d65f6f70SBen Gras 
257*0a6a1f1dSLionel Sambuc /*
258*0a6a1f1dSLionel Sambuc  * Copy some the fields of the dinode as needed by update_inoblk().
259*0a6a1f1dSLionel Sambuc  */
260*0a6a1f1dSLionel Sambuc static void
update_inoblk_copy_dinode(struct lfs * fs,union lfs_dinode * dstu,const union lfs_dinode * srcu)261*0a6a1f1dSLionel Sambuc update_inoblk_copy_dinode(struct lfs *fs,
262*0a6a1f1dSLionel Sambuc     union lfs_dinode *dstu, const union lfs_dinode *srcu)
263*0a6a1f1dSLionel Sambuc {
264*0a6a1f1dSLionel Sambuc 	if (fs->lfs_is64) {
265*0a6a1f1dSLionel Sambuc 		struct lfs64_dinode *dst = &dstu->u_64;
266*0a6a1f1dSLionel Sambuc 		const struct lfs64_dinode *src = &srcu->u_64;
267*0a6a1f1dSLionel Sambuc 		unsigned i;
268*0a6a1f1dSLionel Sambuc 
269*0a6a1f1dSLionel Sambuc 		/*
270*0a6a1f1dSLionel Sambuc 		 * Copy everything but the block pointers and di_blocks.
271*0a6a1f1dSLionel Sambuc 		 * XXX what about di_extb?
272*0a6a1f1dSLionel Sambuc 		 */
273*0a6a1f1dSLionel Sambuc 		dst->di_mode = src->di_mode;
274*0a6a1f1dSLionel Sambuc 		dst->di_nlink = src->di_nlink;
275*0a6a1f1dSLionel Sambuc 		dst->di_uid = src->di_uid;
276*0a6a1f1dSLionel Sambuc 		dst->di_gid = src->di_gid;
277*0a6a1f1dSLionel Sambuc 		dst->di_blksize = src->di_blksize;
278*0a6a1f1dSLionel Sambuc 		dst->di_size = src->di_size;
279*0a6a1f1dSLionel Sambuc 		dst->di_atime = src->di_atime;
280*0a6a1f1dSLionel Sambuc 		dst->di_mtime = src->di_mtime;
281*0a6a1f1dSLionel Sambuc 		dst->di_ctime = src->di_ctime;
282*0a6a1f1dSLionel Sambuc 		dst->di_birthtime = src->di_birthtime;
283*0a6a1f1dSLionel Sambuc 		dst->di_mtimensec = src->di_mtimensec;
284*0a6a1f1dSLionel Sambuc 		dst->di_atimensec = src->di_atimensec;
285*0a6a1f1dSLionel Sambuc 		dst->di_ctimensec = src->di_ctimensec;
286*0a6a1f1dSLionel Sambuc 		dst->di_birthnsec = src->di_birthnsec;
287*0a6a1f1dSLionel Sambuc 		dst->di_gen = src->di_gen;
288*0a6a1f1dSLionel Sambuc 		dst->di_kernflags = src->di_kernflags;
289*0a6a1f1dSLionel Sambuc 		dst->di_flags = src->di_flags;
290*0a6a1f1dSLionel Sambuc 		dst->di_extsize = src->di_extsize;
291*0a6a1f1dSLionel Sambuc 		dst->di_modrev = src->di_modrev;
292*0a6a1f1dSLionel Sambuc 		dst->di_inumber = src->di_inumber;
293*0a6a1f1dSLionel Sambuc 		for (i = 0; i < __arraycount(src->di_spare); i++) {
294*0a6a1f1dSLionel Sambuc 			dst->di_spare[i] = src->di_spare[i];
295*0a6a1f1dSLionel Sambuc 		}
296*0a6a1f1dSLionel Sambuc 	} else {
297*0a6a1f1dSLionel Sambuc 		struct lfs32_dinode *dst = &dstu->u_32;
298*0a6a1f1dSLionel Sambuc 		const struct lfs32_dinode *src = &srcu->u_32;
299*0a6a1f1dSLionel Sambuc 
300*0a6a1f1dSLionel Sambuc 		/* Get mode, link count, size, and times */
301*0a6a1f1dSLionel Sambuc 		memcpy(dst, src, offsetof(struct lfs32_dinode, di_db[0]));
302*0a6a1f1dSLionel Sambuc 
303*0a6a1f1dSLionel Sambuc 		/* Then the rest, except di_blocks */
304*0a6a1f1dSLionel Sambuc 		dst->di_flags = src->di_flags;
305*0a6a1f1dSLionel Sambuc 		dst->di_gen = src->di_gen;
306*0a6a1f1dSLionel Sambuc 		dst->di_uid = src->di_uid;
307*0a6a1f1dSLionel Sambuc 		dst->di_gid = src->di_gid;
308*0a6a1f1dSLionel Sambuc 		dst->di_modrev = src->di_modrev;
309*0a6a1f1dSLionel Sambuc 	}
310*0a6a1f1dSLionel Sambuc }
311*0a6a1f1dSLionel Sambuc 
312d65f6f70SBen Gras static int
update_inoblk(struct lfs * fs,daddr_t offset,kauth_cred_t cred,struct lwp * l)313d65f6f70SBen Gras update_inoblk(struct lfs *fs, daddr_t offset, kauth_cred_t cred,
314d65f6f70SBen Gras 	      struct lwp *l)
315d65f6f70SBen Gras {
316d65f6f70SBen Gras 	struct vnode *devvp, *vp;
317d65f6f70SBen Gras 	struct inode *ip;
318*0a6a1f1dSLionel Sambuc 	union lfs_dinode *dip;
319d65f6f70SBen Gras 	struct buf *dbp, *ibp;
320d65f6f70SBen Gras 	int error;
321d65f6f70SBen Gras 	daddr_t daddr;
322d65f6f70SBen Gras 	IFILE *ifp;
323d65f6f70SBen Gras 	SEGUSE *sup;
324*0a6a1f1dSLionel Sambuc 	unsigned i, num;
325d65f6f70SBen Gras 
326d65f6f70SBen Gras 	devvp = VTOI(fs->lfs_ivnode)->i_devvp;
327d65f6f70SBen Gras 
328d65f6f70SBen Gras 	/*
329d65f6f70SBen Gras 	 * Get the inode, update times and perms.
330d65f6f70SBen Gras 	 * DO NOT update disk blocks, we do that separately.
331d65f6f70SBen Gras 	 */
332*0a6a1f1dSLionel Sambuc 	error = bread(devvp, LFS_FSBTODB(fs, offset), lfs_sb_getibsize(fs),
333*0a6a1f1dSLionel Sambuc 	    0, &dbp);
334d65f6f70SBen Gras 	if (error) {
335d65f6f70SBen Gras 		DLOG((DLOG_RF, "update_inoblk: bread returned %d\n", error));
336d65f6f70SBen Gras 		return error;
337d65f6f70SBen Gras 	}
338*0a6a1f1dSLionel Sambuc 	num = LFS_INOPB(fs);
339*0a6a1f1dSLionel Sambuc 	for (i = num; i-- > 0; ) {
340*0a6a1f1dSLionel Sambuc 		dip = DINO_IN_BLOCK(fs, dbp->b_data, i);
341*0a6a1f1dSLionel Sambuc 		if (lfs_dino_getinumber(fs, dip) > LFS_IFILE_INUM) {
342*0a6a1f1dSLionel Sambuc 			error = lfs_rf_valloc(fs, lfs_dino_getinumber(fs, dip),
343*0a6a1f1dSLionel Sambuc 					      lfs_dino_getgen(fs, dip),
344d65f6f70SBen Gras 					      l, &vp);
345d65f6f70SBen Gras 			if (error) {
346d65f6f70SBen Gras 				DLOG((DLOG_RF, "update_inoblk: lfs_rf_valloc"
347d65f6f70SBen Gras 				      " returned %d\n", error));
348d65f6f70SBen Gras 				continue;
349d65f6f70SBen Gras 			}
350d65f6f70SBen Gras 			ip = VTOI(vp);
351*0a6a1f1dSLionel Sambuc 			if (lfs_dino_getsize(fs, dip) != ip->i_size)
352*0a6a1f1dSLionel Sambuc 				lfs_truncate(vp, lfs_dino_getsize(fs, dip), 0,
353*0a6a1f1dSLionel Sambuc 					     NOCRED);
354*0a6a1f1dSLionel Sambuc 			update_inoblk_copy_dinode(fs, ip->i_din, dip);
355d65f6f70SBen Gras 
356*0a6a1f1dSLionel Sambuc 			ip->i_flags = lfs_dino_getflags(fs, dip);
357*0a6a1f1dSLionel Sambuc 			ip->i_gen = lfs_dino_getgen(fs, dip);
358*0a6a1f1dSLionel Sambuc 			ip->i_uid = lfs_dino_getuid(fs, dip);
359*0a6a1f1dSLionel Sambuc 			ip->i_gid = lfs_dino_getgid(fs, dip);
360d65f6f70SBen Gras 
361*0a6a1f1dSLionel Sambuc 			ip->i_mode = lfs_dino_getmode(fs, dip);
362*0a6a1f1dSLionel Sambuc 			ip->i_nlink = lfs_dino_getnlink(fs, dip);
363*0a6a1f1dSLionel Sambuc 			ip->i_size = lfs_dino_getsize(fs, dip);
364d65f6f70SBen Gras 
365d65f6f70SBen Gras 			LFS_SET_UINO(ip, IN_CHANGE | IN_UPDATE);
366d65f6f70SBen Gras 
367d65f6f70SBen Gras 			/* Re-initialize to get type right */
36884d9c625SLionel Sambuc 			ulfs_vinit(vp->v_mount, lfs_specop_p, lfs_fifoop_p,
369d65f6f70SBen Gras 				  &vp);
370d65f6f70SBen Gras 			vput(vp);
371d65f6f70SBen Gras 
372d65f6f70SBen Gras 			/* Record change in location */
373*0a6a1f1dSLionel Sambuc 			LFS_IENTRY(ifp, fs, lfs_dino_getinumber(fs, dip), ibp);
374*0a6a1f1dSLionel Sambuc 			daddr = lfs_if_getdaddr(fs, ifp);
375*0a6a1f1dSLionel Sambuc 			lfs_if_setdaddr(fs, ifp, LFS_DBTOFSB(fs, dbp->b_blkno));
376d65f6f70SBen Gras 			error = LFS_BWRITE_LOG(ibp); /* Ifile */
377d65f6f70SBen Gras 			/* And do segment accounting */
37884d9c625SLionel Sambuc 			if (lfs_dtosn(fs, daddr) != lfs_dtosn(fs, LFS_DBTOFSB(fs, dbp->b_blkno))) {
379d65f6f70SBen Gras 				if (daddr > 0) {
38084d9c625SLionel Sambuc 					LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, daddr),
381d65f6f70SBen Gras 						     ibp);
382*0a6a1f1dSLionel Sambuc 					sup->su_nbytes -= DINOSIZE(fs);
383d65f6f70SBen Gras 					LFS_WRITESEGENTRY(sup, fs,
38484d9c625SLionel Sambuc 							  lfs_dtosn(fs, daddr),
385d65f6f70SBen Gras 							  ibp);
386d65f6f70SBen Gras 				}
38784d9c625SLionel Sambuc 				LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, LFS_DBTOFSB(fs, dbp->b_blkno)),
388d65f6f70SBen Gras 					     ibp);
389*0a6a1f1dSLionel Sambuc 				sup->su_nbytes += DINOSIZE(fs);
390d65f6f70SBen Gras 				LFS_WRITESEGENTRY(sup, fs,
39184d9c625SLionel Sambuc 						  lfs_dtosn(fs, LFS_DBTOFSB(fs, dbp->b_blkno)),
392d65f6f70SBen Gras 						  ibp);
393d65f6f70SBen Gras 			}
394d65f6f70SBen Gras 		}
395d65f6f70SBen Gras 	}
396d65f6f70SBen Gras 	brelse(dbp, BC_AGE);
397d65f6f70SBen Gras 
398d65f6f70SBen Gras 	return 0;
399d65f6f70SBen Gras }
400d65f6f70SBen Gras 
401d65f6f70SBen Gras #define CHECK_CKSUM   0x0001  /* Check the checksum to make sure it's valid */
402d65f6f70SBen Gras #define CHECK_UPDATE  0x0002  /* Update Ifile for new data blocks / inodes */
403d65f6f70SBen Gras 
404d65f6f70SBen Gras static daddr_t
check_segsum(struct lfs * fs,daddr_t offset,u_int64_t nextserial,kauth_cred_t cred,int flags,int * pseg_flags,struct lwp * l)405d65f6f70SBen Gras check_segsum(struct lfs *fs, daddr_t offset, u_int64_t nextserial,
406d65f6f70SBen Gras 	     kauth_cred_t cred, int flags, int *pseg_flags, struct lwp *l)
407d65f6f70SBen Gras {
408d65f6f70SBen Gras 	struct vnode *devvp;
409d65f6f70SBen Gras 	struct buf *bp, *dbp;
410d65f6f70SBen Gras 	int error, nblocks = 0, ninos, i, j; /* XXX: gcc */
411d65f6f70SBen Gras 	SEGSUM *ssp;
412d65f6f70SBen Gras 	u_long *dp = NULL, *datap = NULL; /* XXX u_int32_t */
413d65f6f70SBen Gras 	daddr_t oldoffset;
414*0a6a1f1dSLionel Sambuc 	IINFO *iip;
415d65f6f70SBen Gras 	FINFO *fip;
416d65f6f70SBen Gras 	SEGUSE *sup;
417d65f6f70SBen Gras 	size_t size;
418*0a6a1f1dSLionel Sambuc 	uint32_t datasum, foundsum;
419d65f6f70SBen Gras 
420d65f6f70SBen Gras 	devvp = VTOI(fs->lfs_ivnode)->i_devvp;
421d65f6f70SBen Gras 	/*
422d65f6f70SBen Gras 	 * If the segment has a superblock and we're at the top
423d65f6f70SBen Gras 	 * of the segment, skip the superblock.
424d65f6f70SBen Gras 	 */
42584d9c625SLionel Sambuc 	if (lfs_sntod(fs, lfs_dtosn(fs, offset)) == offset) {
42684d9c625SLionel Sambuc 		LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, offset), bp);
427d65f6f70SBen Gras 		if (sup->su_flags & SEGUSE_SUPERBLOCK)
42884d9c625SLionel Sambuc 			offset += lfs_btofsb(fs, LFS_SBPAD);
429d65f6f70SBen Gras 		brelse(bp, 0);
430d65f6f70SBen Gras 	}
431d65f6f70SBen Gras 
432d65f6f70SBen Gras 	/* Read in the segment summary */
433*0a6a1f1dSLionel Sambuc 	error = bread(devvp, LFS_FSBTODB(fs, offset), lfs_sb_getsumsize(fs),
434*0a6a1f1dSLionel Sambuc 	    0, &bp);
435d65f6f70SBen Gras 	if (error)
436d65f6f70SBen Gras 		return -1;
437d65f6f70SBen Gras 
438d65f6f70SBen Gras 	/* Check summary checksum */
439d65f6f70SBen Gras 	ssp = (SEGSUM *)bp->b_data;
440d65f6f70SBen Gras 	if (flags & CHECK_CKSUM) {
441*0a6a1f1dSLionel Sambuc 		size_t sumstart;
442*0a6a1f1dSLionel Sambuc 
443*0a6a1f1dSLionel Sambuc 		sumstart = lfs_ss_getsumstart(fs);
444*0a6a1f1dSLionel Sambuc 		if (lfs_ss_getsumsum(fs, ssp) !=
445*0a6a1f1dSLionel Sambuc 		    cksum((char *)ssp + sumstart,
446*0a6a1f1dSLionel Sambuc 			  lfs_sb_getsumsize(fs) - sumstart)) {
447d65f6f70SBen Gras 			DLOG((DLOG_RF, "Sumsum error at 0x%" PRIx64 "\n", offset));
448d65f6f70SBen Gras 			offset = -1;
449d65f6f70SBen Gras 			goto err1;
450d65f6f70SBen Gras 		}
451*0a6a1f1dSLionel Sambuc 		if (lfs_ss_getnfinfo(fs, ssp) == 0 &&
452*0a6a1f1dSLionel Sambuc 		    lfs_ss_getninos(fs, ssp) == 0) {
453d65f6f70SBen Gras 			DLOG((DLOG_RF, "Empty pseg at 0x%" PRIx64 "\n", offset));
454d65f6f70SBen Gras 			offset = -1;
455d65f6f70SBen Gras 			goto err1;
456d65f6f70SBen Gras 		}
457*0a6a1f1dSLionel Sambuc 		if (lfs_ss_getcreate(fs, ssp) < lfs_sb_gettstamp(fs)) {
458d65f6f70SBen Gras 			DLOG((DLOG_RF, "Old data at 0x%" PRIx64 "\n", offset));
459d65f6f70SBen Gras 			offset = -1;
460d65f6f70SBen Gras 			goto err1;
461d65f6f70SBen Gras 		}
462d65f6f70SBen Gras 	}
463*0a6a1f1dSLionel Sambuc 	if (lfs_sb_getversion(fs) > 1) {
464*0a6a1f1dSLionel Sambuc 		if (lfs_ss_getserial(fs, ssp) != nextserial) {
465d65f6f70SBen Gras 			DLOG((DLOG_RF, "Unexpected serial number at 0x%" PRIx64
466d65f6f70SBen Gras 			      "\n", offset));
467d65f6f70SBen Gras 			offset = -1;
468d65f6f70SBen Gras 			goto err1;
469d65f6f70SBen Gras 		}
470*0a6a1f1dSLionel Sambuc 		if (lfs_ss_getident(fs, ssp) != lfs_sb_getident(fs)) {
471d65f6f70SBen Gras 			DLOG((DLOG_RF, "Incorrect fsid (0x%x vs 0x%x) at 0x%"
472*0a6a1f1dSLionel Sambuc 			      PRIx64 "\n", lfs_ss_getident(fs, ssp),
473*0a6a1f1dSLionel Sambuc 			      lfs_sb_getident(fs), offset));
474d65f6f70SBen Gras 			offset = -1;
475d65f6f70SBen Gras 			goto err1;
476d65f6f70SBen Gras 		}
477d65f6f70SBen Gras 	}
478d65f6f70SBen Gras 	if (pseg_flags)
479*0a6a1f1dSLionel Sambuc 		*pseg_flags = lfs_ss_getflags(fs, ssp);
480d65f6f70SBen Gras 	oldoffset = offset;
481*0a6a1f1dSLionel Sambuc 	offset += lfs_btofsb(fs, lfs_sb_getsumsize(fs));
482d65f6f70SBen Gras 
483*0a6a1f1dSLionel Sambuc 	ninos = howmany(lfs_ss_getninos(fs, ssp), LFS_INOPB(fs));
484*0a6a1f1dSLionel Sambuc 	iip = SEGSUM_IINFOSTART(fs, bp->b_data);
485d65f6f70SBen Gras 	if (flags & CHECK_CKSUM) {
486d65f6f70SBen Gras 		/* Count blocks */
487d65f6f70SBen Gras 		nblocks = 0;
488*0a6a1f1dSLionel Sambuc 		fip = SEGSUM_FINFOBASE(fs, (SEGSUM *)bp->b_data);
489*0a6a1f1dSLionel Sambuc 		for (i = 0; i < lfs_ss_getnfinfo(fs, ssp); ++i) {
490*0a6a1f1dSLionel Sambuc 			nblocks += lfs_fi_getnblocks(fs, fip);
491*0a6a1f1dSLionel Sambuc 			if (lfs_fi_getnblocks(fs, fip) <= 0)
492d65f6f70SBen Gras 				break;
493*0a6a1f1dSLionel Sambuc 			fip = NEXT_FINFO(fs, fip);
494d65f6f70SBen Gras 		}
495d65f6f70SBen Gras 		nblocks += ninos;
496d65f6f70SBen Gras 		/* Create the sum array */
497*0a6a1f1dSLionel Sambuc 		datap = dp = malloc(nblocks * sizeof(u_long),
498d65f6f70SBen Gras 				    M_SEGMENT, M_WAITOK);
499d65f6f70SBen Gras 	}
500d65f6f70SBen Gras 
501d65f6f70SBen Gras 	/* Handle individual blocks */
502*0a6a1f1dSLionel Sambuc 	fip = SEGSUM_FINFOBASE(fs, (SEGSUM *)bp->b_data);
503*0a6a1f1dSLionel Sambuc 	for (i = 0; i < lfs_ss_getnfinfo(fs, ssp) || ninos; ++i) {
504d65f6f70SBen Gras 		/* Inode block? */
505*0a6a1f1dSLionel Sambuc 		if (ninos && lfs_ii_getblock(fs, iip) == offset) {
506d65f6f70SBen Gras 			if (flags & CHECK_CKSUM) {
507d65f6f70SBen Gras 				/* Read in the head and add to the buffer */
508*0a6a1f1dSLionel Sambuc 				error = bread(devvp, LFS_FSBTODB(fs, offset), lfs_sb_getbsize(fs),
509*0a6a1f1dSLionel Sambuc 					      0, &dbp);
510d65f6f70SBen Gras 				if (error) {
511d65f6f70SBen Gras 					offset = -1;
512d65f6f70SBen Gras 					goto err2;
513d65f6f70SBen Gras 				}
514*0a6a1f1dSLionel Sambuc 				/* XXX this can't be right, on-disk u_long? */
515d65f6f70SBen Gras 				(*dp++) = ((u_long *)(dbp->b_data))[0];
516d65f6f70SBen Gras 				brelse(dbp, BC_AGE);
517d65f6f70SBen Gras 			}
518d65f6f70SBen Gras 			if (flags & CHECK_UPDATE) {
519d65f6f70SBen Gras 				if ((error = update_inoblk(fs, offset, cred, l))
520d65f6f70SBen Gras 				    != 0) {
521d65f6f70SBen Gras 					offset = -1;
522d65f6f70SBen Gras 					goto err2;
523d65f6f70SBen Gras 				}
524d65f6f70SBen Gras 			}
525*0a6a1f1dSLionel Sambuc 			offset += lfs_btofsb(fs, lfs_sb_getibsize(fs));
526*0a6a1f1dSLionel Sambuc 			iip = NEXTLOWER_IINFO(fs, iip);
527d65f6f70SBen Gras 			--ninos;
528*0a6a1f1dSLionel Sambuc 			--i; /* compensate for ++i in loop header */
529d65f6f70SBen Gras 			continue;
530d65f6f70SBen Gras 		}
531*0a6a1f1dSLionel Sambuc 		size = lfs_sb_getbsize(fs);
532*0a6a1f1dSLionel Sambuc 		for (j = 0; j < lfs_fi_getnblocks(fs, fip); ++j) {
533*0a6a1f1dSLionel Sambuc 			if (j == lfs_fi_getnblocks(fs, fip) - 1)
534*0a6a1f1dSLionel Sambuc 				size = lfs_fi_getlastlength(fs, fip);
535d65f6f70SBen Gras 			if (flags & CHECK_CKSUM) {
53684d9c625SLionel Sambuc 				error = bread(devvp, LFS_FSBTODB(fs, offset), size,
537*0a6a1f1dSLionel Sambuc 				    0, &dbp);
538d65f6f70SBen Gras 				if (error) {
539d65f6f70SBen Gras 					offset = -1;
540d65f6f70SBen Gras 					goto err2;
541d65f6f70SBen Gras 				}
542d65f6f70SBen Gras 				(*dp++) = ((u_long *)(dbp->b_data))[0];
543d65f6f70SBen Gras 				brelse(dbp, BC_AGE);
544d65f6f70SBen Gras 			}
545d65f6f70SBen Gras 			/* Account for and update any direct blocks */
546d65f6f70SBen Gras 			if ((flags & CHECK_UPDATE) &&
547*0a6a1f1dSLionel Sambuc 			   lfs_fi_getino(fs, fip) > LFS_IFILE_INUM &&
548*0a6a1f1dSLionel Sambuc 			   lfs_fi_getblock(fs, fip, j) >= 0) {
549*0a6a1f1dSLionel Sambuc 				update_meta(fs, lfs_fi_getino(fs, fip),
550*0a6a1f1dSLionel Sambuc 					    lfs_fi_getversion(fs, fip),
551*0a6a1f1dSLionel Sambuc 					    lfs_fi_getblock(fs, fip, j),
552*0a6a1f1dSLionel Sambuc 					    offset, size, l);
553d65f6f70SBen Gras 			}
55484d9c625SLionel Sambuc 			offset += lfs_btofsb(fs, size);
555d65f6f70SBen Gras 		}
556*0a6a1f1dSLionel Sambuc 		fip = NEXT_FINFO(fs, fip);
557d65f6f70SBen Gras 	}
558d65f6f70SBen Gras 	/* Checksum the array, compare */
559*0a6a1f1dSLionel Sambuc 	datasum = lfs_ss_getdatasum(fs, ssp);
560*0a6a1f1dSLionel Sambuc 	foundsum = cksum(datap, nblocks * sizeof(u_long));
561*0a6a1f1dSLionel Sambuc 	if ((flags & CHECK_CKSUM) && datasum != foundsum) {
562d65f6f70SBen Gras 		DLOG((DLOG_RF, "Datasum error at 0x%" PRIx64
563d65f6f70SBen Gras 		      " (wanted %x got %x)\n",
564*0a6a1f1dSLionel Sambuc 		      offset, datasum, foundsum));
565d65f6f70SBen Gras 		offset = -1;
566d65f6f70SBen Gras 		goto err2;
567d65f6f70SBen Gras 	}
568d65f6f70SBen Gras 
569d65f6f70SBen Gras 	/* If we're at the end of the segment, move to the next */
570*0a6a1f1dSLionel Sambuc 	if (lfs_dtosn(fs, offset + lfs_btofsb(fs, lfs_sb_getsumsize(fs) + lfs_sb_getbsize(fs))) !=
57184d9c625SLionel Sambuc 	   lfs_dtosn(fs, offset)) {
572*0a6a1f1dSLionel Sambuc 		if (lfs_dtosn(fs, offset) == lfs_dtosn(fs, lfs_ss_getnext(fs, ssp))) {
573d65f6f70SBen Gras 			offset = -1;
574d65f6f70SBen Gras 			goto err2;
575d65f6f70SBen Gras 		}
576*0a6a1f1dSLionel Sambuc 		offset = lfs_ss_getnext(fs, ssp);
577d65f6f70SBen Gras 		DLOG((DLOG_RF, "LFS roll forward: moving to offset 0x%" PRIx64
57884d9c625SLionel Sambuc 		       " -> segment %d\n", offset, lfs_dtosn(fs,offset)));
579d65f6f70SBen Gras 	}
580d65f6f70SBen Gras 
581d65f6f70SBen Gras 	if (flags & CHECK_UPDATE) {
582*0a6a1f1dSLionel Sambuc 		lfs_sb_subavail(fs, offset - oldoffset);
583d65f6f70SBen Gras 		/* Don't clog the buffer queue */
584d65f6f70SBen Gras 		mutex_enter(&lfs_lock);
585d65f6f70SBen Gras 		if (locked_queue_count > LFS_MAX_BUFS ||
586d65f6f70SBen Gras 		    locked_queue_bytes > LFS_MAX_BYTES) {
587d65f6f70SBen Gras 			lfs_flush(fs, SEGM_CKP, 0);
588d65f6f70SBen Gras 		}
589d65f6f70SBen Gras 		mutex_exit(&lfs_lock);
590d65f6f70SBen Gras 	}
591d65f6f70SBen Gras 
592d65f6f70SBen Gras     err2:
593d65f6f70SBen Gras 	if (flags & CHECK_CKSUM)
594d65f6f70SBen Gras 		free(datap, M_SEGMENT);
595d65f6f70SBen Gras     err1:
596d65f6f70SBen Gras 	brelse(bp, BC_AGE);
597d65f6f70SBen Gras 
598d65f6f70SBen Gras 	/* XXX should we update the serial number even for bad psegs? */
599*0a6a1f1dSLionel Sambuc 	if ((flags & CHECK_UPDATE) && offset > 0 && lfs_sb_getversion(fs) > 1)
600*0a6a1f1dSLionel Sambuc 		lfs_sb_setserial(fs, nextserial);
601d65f6f70SBen Gras 	return offset;
602d65f6f70SBen Gras }
603d65f6f70SBen Gras 
604d65f6f70SBen Gras void
lfs_roll_forward(struct lfs * fs,struct mount * mp,struct lwp * l)605d65f6f70SBen Gras lfs_roll_forward(struct lfs *fs, struct mount *mp, struct lwp *l)
606d65f6f70SBen Gras {
607d65f6f70SBen Gras 	int flags, dirty;
608d65f6f70SBen Gras 	daddr_t offset, oldoffset, lastgoodpseg;
609d65f6f70SBen Gras 	int sn, curseg, do_rollforward;
610d65f6f70SBen Gras 	struct proc *p;
611d65f6f70SBen Gras 	kauth_cred_t cred;
612d65f6f70SBen Gras 	SEGUSE *sup;
613d65f6f70SBen Gras 	struct buf *bp;
614d65f6f70SBen Gras 
615d65f6f70SBen Gras 	p = l ? l->l_proc : NULL;
616d65f6f70SBen Gras 	cred = p ? p->p_cred : NOCRED;
617d65f6f70SBen Gras 
618d65f6f70SBen Gras 	/*
619d65f6f70SBen Gras 	 * Roll forward.
620d65f6f70SBen Gras 	 *
621d65f6f70SBen Gras 	 * We don't roll forward for v1 filesystems, because
622d65f6f70SBen Gras 	 * of the danger that the clock was turned back between the last
623d65f6f70SBen Gras 	 * checkpoint and crash.  This would roll forward garbage.
624d65f6f70SBen Gras 	 *
625d65f6f70SBen Gras 	 * v2 filesystems don't have this problem because they use a
626d65f6f70SBen Gras 	 * monotonically increasing serial number instead of a timestamp.
627d65f6f70SBen Gras 	 */
628*0a6a1f1dSLionel Sambuc 	do_rollforward = (!(lfs_sb_getpflags(fs) & LFS_PF_CLEAN) &&
629*0a6a1f1dSLionel Sambuc 			  lfs_do_rfw && lfs_sb_getversion(fs) > 1 && p != NULL);
630d65f6f70SBen Gras 	if (do_rollforward) {
631d65f6f70SBen Gras 		u_int64_t nextserial;
632d65f6f70SBen Gras 		/*
633d65f6f70SBen Gras 		 * Phase I: Find the address of the last good partial
634d65f6f70SBen Gras 		 * segment that was written after the checkpoint.  Mark
635d65f6f70SBen Gras 		 * the segments in question dirty, so they won't be
636d65f6f70SBen Gras 		 * reallocated.
637d65f6f70SBen Gras 		 */
638*0a6a1f1dSLionel Sambuc 		lastgoodpseg = oldoffset = offset = lfs_sb_getoffset(fs);
639d65f6f70SBen Gras 		flags = 0x0;
640d65f6f70SBen Gras 		DLOG((DLOG_RF, "LFS roll forward phase 1: start at offset 0x%"
641d65f6f70SBen Gras 		      PRIx64 "\n", offset));
64284d9c625SLionel Sambuc 		LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, offset), bp);
643d65f6f70SBen Gras 		if (!(sup->su_flags & SEGUSE_DIRTY))
644*0a6a1f1dSLionel Sambuc 			lfs_sb_subnclean(fs, 1);
645d65f6f70SBen Gras 		sup->su_flags |= SEGUSE_DIRTY;
64684d9c625SLionel Sambuc 		LFS_WRITESEGENTRY(sup, fs, lfs_dtosn(fs, offset), bp);
647*0a6a1f1dSLionel Sambuc 		nextserial = lfs_sb_getserial(fs) + 1;
648d65f6f70SBen Gras 		while ((offset = check_segsum(fs, offset, nextserial,
649d65f6f70SBen Gras 		    cred, CHECK_CKSUM, &flags, l)) > 0) {
650d65f6f70SBen Gras 			nextserial++;
65184d9c625SLionel Sambuc 			if (lfs_sntod(fs, oldoffset) != lfs_sntod(fs, offset)) {
65284d9c625SLionel Sambuc 				LFS_SEGENTRY(sup, fs, lfs_dtosn(fs, oldoffset),
653d65f6f70SBen Gras 					     bp);
654d65f6f70SBen Gras 				if (!(sup->su_flags & SEGUSE_DIRTY))
655*0a6a1f1dSLionel Sambuc 					lfs_sb_subnclean(fs, 1);
656d65f6f70SBen Gras 				sup->su_flags |= SEGUSE_DIRTY;
65784d9c625SLionel Sambuc 				LFS_WRITESEGENTRY(sup, fs, lfs_dtosn(fs, oldoffset),
658d65f6f70SBen Gras 					     bp);
659d65f6f70SBen Gras 			}
660d65f6f70SBen Gras 
661d65f6f70SBen Gras 			DLOG((DLOG_RF, "LFS roll forward phase 1: offset=0x%"
662d65f6f70SBen Gras 			      PRIx64 "\n", offset));
663d65f6f70SBen Gras 			if (flags & SS_DIROP) {
664d65f6f70SBen Gras 				DLOG((DLOG_RF, "lfs_mountfs: dirops at 0x%"
665d65f6f70SBen Gras 				      PRIx64 "\n", oldoffset));
666d65f6f70SBen Gras 				if (!(flags & SS_CONT)) {
667d65f6f70SBen Gras 				     DLOG((DLOG_RF, "lfs_mountfs: dirops end "
668d65f6f70SBen Gras 					   "at 0x%" PRIx64 "\n", oldoffset));
669d65f6f70SBen Gras 				}
670d65f6f70SBen Gras 			}
671d65f6f70SBen Gras 			if (!(flags & SS_CONT))
672d65f6f70SBen Gras 				lastgoodpseg = offset;
673d65f6f70SBen Gras 			oldoffset = offset;
674d65f6f70SBen Gras 		}
675d65f6f70SBen Gras 		if (flags & SS_CONT) {
676d65f6f70SBen Gras 			DLOG((DLOG_RF, "LFS roll forward: warning: incomplete "
677d65f6f70SBen Gras 			      "dirops discarded\n"));
678d65f6f70SBen Gras 		}
679d65f6f70SBen Gras 		DLOG((DLOG_RF, "LFS roll forward phase 1: completed: "
680d65f6f70SBen Gras 		      "lastgoodpseg=0x%" PRIx64 "\n", lastgoodpseg));
681*0a6a1f1dSLionel Sambuc 		oldoffset = lfs_sb_getoffset(fs);
682*0a6a1f1dSLionel Sambuc 		if (lfs_sb_getoffset(fs) != lastgoodpseg) {
683d65f6f70SBen Gras 			/* Don't overwrite what we're trying to preserve */
684*0a6a1f1dSLionel Sambuc 			offset = lfs_sb_getoffset(fs);
685*0a6a1f1dSLionel Sambuc 			lfs_sb_setoffset(fs, lastgoodpseg);
686*0a6a1f1dSLionel Sambuc 			lfs_sb_setcurseg(fs, lfs_sntod(fs, lfs_dtosn(fs, lfs_sb_getoffset(fs))));
687*0a6a1f1dSLionel Sambuc 			for (sn = curseg = lfs_dtosn(fs, lfs_sb_getcurseg(fs));;) {
688*0a6a1f1dSLionel Sambuc 				sn = (sn + 1) % lfs_sb_getnseg(fs);
689d65f6f70SBen Gras 				if (sn == curseg)
690d65f6f70SBen Gras 					panic("lfs_mountfs: no clean segments");
691d65f6f70SBen Gras 				LFS_SEGENTRY(sup, fs, sn, bp);
692d65f6f70SBen Gras 				dirty = (sup->su_flags & SEGUSE_DIRTY);
693d65f6f70SBen Gras 				brelse(bp, 0);
694d65f6f70SBen Gras 				if (!dirty)
695d65f6f70SBen Gras 					break;
696d65f6f70SBen Gras 			}
697*0a6a1f1dSLionel Sambuc 			lfs_sb_setnextseg(fs, lfs_sntod(fs, sn));
698d65f6f70SBen Gras 
699d65f6f70SBen Gras 			/*
700d65f6f70SBen Gras 			 * Phase II: Roll forward from the first superblock.
701d65f6f70SBen Gras 			 */
702d65f6f70SBen Gras 			while (offset != lastgoodpseg) {
703d65f6f70SBen Gras 				DLOG((DLOG_RF, "LFS roll forward phase 2: 0x%"
704d65f6f70SBen Gras 				      PRIx64 "\n", offset));
705d65f6f70SBen Gras 				offset = check_segsum(fs, offset,
706*0a6a1f1dSLionel Sambuc 				    lfs_sb_getserial(fs) + 1, cred, CHECK_UPDATE,
707d65f6f70SBen Gras 				    NULL, l);
708d65f6f70SBen Gras 			}
709d65f6f70SBen Gras 
710d65f6f70SBen Gras 			/*
711d65f6f70SBen Gras 			 * Finish: flush our changes to disk.
712d65f6f70SBen Gras 			 */
713d65f6f70SBen Gras 			lfs_segwrite(mp, SEGM_CKP | SEGM_SYNC);
714d65f6f70SBen Gras 			DLOG((DLOG_RF, "lfs_mountfs: roll forward ",
715*0a6a1f1dSLionel Sambuc 			      "recovered %jd blocks\n",
716*0a6a1f1dSLionel Sambuc 			      (intmax_t)(lastgoodpseg - oldoffset)));
717d65f6f70SBen Gras 		}
718d65f6f70SBen Gras 		DLOG((DLOG_RF, "LFS roll forward complete\n"));
719d65f6f70SBen Gras 	}
720d65f6f70SBen Gras }
721