NFS: Fix use after free in write error path
[linux-block.git] / fs / nfs / write.c
1 /*
2  * linux/fs/nfs/write.c
3  *
4  * Write file data over NFS.
5  *
6  * Copyright (C) 1996, 1997, Olaf Kirch <okir@monad.swb.de>
7  */
8
9 #include <linux/types.h>
10 #include <linux/slab.h>
11 #include <linux/mm.h>
12 #include <linux/pagemap.h>
13 #include <linux/file.h>
14 #include <linux/writeback.h>
15 #include <linux/swap.h>
16 #include <linux/migrate.h>
17
18 #include <linux/sunrpc/clnt.h>
19 #include <linux/nfs_fs.h>
20 #include <linux/nfs_mount.h>
21 #include <linux/nfs_page.h>
22 #include <linux/backing-dev.h>
23 #include <linux/export.h>
24 #include <linux/freezer.h>
25 #include <linux/wait.h>
26
27 #include <linux/uaccess.h>
28
29 #include "delegation.h"
30 #include "internal.h"
31 #include "iostat.h"
32 #include "nfs4_fs.h"
33 #include "fscache.h"
34 #include "pnfs.h"
35
36 #include "nfstrace.h"
37
38 #define NFSDBG_FACILITY         NFSDBG_PAGECACHE
39
40 #define MIN_POOL_WRITE          (32)
41 #define MIN_POOL_COMMIT         (4)
42
43 /*
44  * Local function declarations
45  */
46 static void nfs_redirty_request(struct nfs_page *req);
47 static const struct rpc_call_ops nfs_commit_ops;
48 static const struct nfs_pgio_completion_ops nfs_async_write_completion_ops;
49 static const struct nfs_commit_completion_ops nfs_commit_completion_ops;
50 static const struct nfs_rw_ops nfs_rw_write_ops;
51 static void nfs_clear_request_commit(struct nfs_page *req);
52 static void nfs_init_cinfo_from_inode(struct nfs_commit_info *cinfo,
53                                       struct inode *inode);
54 static struct nfs_page *
55 nfs_page_search_commits_for_head_request_locked(struct nfs_inode *nfsi,
56                                                 struct page *page);
57
58 static struct kmem_cache *nfs_wdata_cachep;
59 static mempool_t *nfs_wdata_mempool;
60 static struct kmem_cache *nfs_cdata_cachep;
61 static mempool_t *nfs_commit_mempool;
62
63 struct nfs_commit_data *nfs_commitdata_alloc(bool never_fail)
64 {
65         struct nfs_commit_data *p;
66
67         if (never_fail)
68                 p = mempool_alloc(nfs_commit_mempool, GFP_NOIO);
69         else {
70                 /* It is OK to do some reclaim, not no safe to wait
71                  * for anything to be returned to the pool.
72                  * mempool_alloc() cannot handle that particular combination,
73                  * so we need two separate attempts.
74                  */
75                 p = mempool_alloc(nfs_commit_mempool, GFP_NOWAIT);
76                 if (!p)
77                         p = kmem_cache_alloc(nfs_cdata_cachep, GFP_NOIO |
78                                              __GFP_NOWARN | __GFP_NORETRY);
79                 if (!p)
80                         return NULL;
81         }
82
83         memset(p, 0, sizeof(*p));
84         INIT_LIST_HEAD(&p->pages);
85         return p;
86 }
87 EXPORT_SYMBOL_GPL(nfs_commitdata_alloc);
88
89 void nfs_commit_free(struct nfs_commit_data *p)
90 {
91         mempool_free(p, nfs_commit_mempool);
92 }
93 EXPORT_SYMBOL_GPL(nfs_commit_free);
94
95 static struct nfs_pgio_header *nfs_writehdr_alloc(void)
96 {
97         struct nfs_pgio_header *p = mempool_alloc(nfs_wdata_mempool, GFP_NOIO);
98
99         memset(p, 0, sizeof(*p));
100         return p;
101 }
102
103 static void nfs_writehdr_free(struct nfs_pgio_header *hdr)
104 {
105         mempool_free(hdr, nfs_wdata_mempool);
106 }
107
108 static void nfs_context_set_write_error(struct nfs_open_context *ctx, int error)
109 {
110         ctx->error = error;
111         smp_wmb();
112         set_bit(NFS_CONTEXT_ERROR_WRITE, &ctx->flags);
113 }
114
115 /*
116  * nfs_page_find_head_request_locked - find head request associated with @page
117  *
118  * must be called while holding the inode lock.
119  *
120  * returns matching head request with reference held, or NULL if not found.
121  */
122 static struct nfs_page *
123 nfs_page_find_head_request_locked(struct nfs_inode *nfsi, struct page *page)
124 {
125         struct nfs_page *req = NULL;
126
127         if (PagePrivate(page))
128                 req = (struct nfs_page *)page_private(page);
129         else if (unlikely(PageSwapCache(page)))
130                 req = nfs_page_search_commits_for_head_request_locked(nfsi,
131                         page);
132
133         if (req) {
134                 WARN_ON_ONCE(req->wb_head != req);
135                 kref_get(&req->wb_kref);
136         }
137
138         return req;
139 }
140
141 /*
142  * nfs_page_find_head_request - find head request associated with @page
143  *
144  * returns matching head request with reference held, or NULL if not found.
145  */
146 static struct nfs_page *nfs_page_find_head_request(struct page *page)
147 {
148         struct inode *inode = page_file_mapping(page)->host;
149         struct nfs_page *req = NULL;
150
151         spin_lock(&inode->i_lock);
152         req = nfs_page_find_head_request_locked(NFS_I(inode), page);
153         spin_unlock(&inode->i_lock);
154         return req;
155 }
156
157 /* Adjust the file length if we're writing beyond the end */
158 static void nfs_grow_file(struct page *page, unsigned int offset, unsigned int count)
159 {
160         struct inode *inode = page_file_mapping(page)->host;
161         loff_t end, i_size;
162         pgoff_t end_index;
163
164         spin_lock(&inode->i_lock);
165         i_size = i_size_read(inode);
166         end_index = (i_size - 1) >> PAGE_SHIFT;
167         if (i_size > 0 && page_index(page) < end_index)
168                 goto out;
169         end = page_file_offset(page) + ((loff_t)offset+count);
170         if (i_size >= end)
171                 goto out;
172         i_size_write(inode, end);
173         nfs_inc_stats(inode, NFSIOS_EXTENDWRITE);
174 out:
175         spin_unlock(&inode->i_lock);
176 }
177
178 /* A writeback failed: mark the page as bad, and invalidate the page cache */
179 static void nfs_set_pageerror(struct page *page)
180 {
181         nfs_zap_mapping(page_file_mapping(page)->host, page_file_mapping(page));
182 }
183
184 /*
185  * nfs_page_group_search_locked
186  * @head - head request of page group
187  * @page_offset - offset into page
188  *
189  * Search page group with head @head to find a request that contains the
190  * page offset @page_offset.
191  *
192  * Returns a pointer to the first matching nfs request, or NULL if no
193  * match is found.
194  *
195  * Must be called with the page group lock held
196  */
197 static struct nfs_page *
198 nfs_page_group_search_locked(struct nfs_page *head, unsigned int page_offset)
199 {
200         struct nfs_page *req;
201
202         WARN_ON_ONCE(head != head->wb_head);
203         WARN_ON_ONCE(!test_bit(PG_HEADLOCK, &head->wb_head->wb_flags));
204
205         req = head;
206         do {
207                 if (page_offset >= req->wb_pgbase &&
208                     page_offset < (req->wb_pgbase + req->wb_bytes))
209                         return req;
210
211                 req = req->wb_this_page;
212         } while (req != head);
213
214         return NULL;
215 }
216
217 /*
218  * nfs_page_group_covers_page
219  * @head - head request of page group
220  *
221  * Return true if the page group with head @head covers the whole page,
222  * returns false otherwise
223  */
224 static bool nfs_page_group_covers_page(struct nfs_page *req)
225 {
226         struct nfs_page *tmp;
227         unsigned int pos = 0;
228         unsigned int len = nfs_page_length(req->wb_page);
229
230         nfs_page_group_lock(req, false);
231
232         do {
233                 tmp = nfs_page_group_search_locked(req->wb_head, pos);
234                 if (tmp) {
235                         /* no way this should happen */
236                         WARN_ON_ONCE(tmp->wb_pgbase != pos);
237                         pos += tmp->wb_bytes - (pos - tmp->wb_pgbase);
238                 }
239         } while (tmp && pos < len);
240
241         nfs_page_group_unlock(req);
242         WARN_ON_ONCE(pos > len);
243         return pos == len;
244 }
245
246 /* We can set the PG_uptodate flag if we see that a write request
247  * covers the full page.
248  */
249 static void nfs_mark_uptodate(struct nfs_page *req)
250 {
251         if (PageUptodate(req->wb_page))
252                 return;
253         if (!nfs_page_group_covers_page(req))
254                 return;
255         SetPageUptodate(req->wb_page);
256 }
257
258 static int wb_priority(struct writeback_control *wbc)
259 {
260         int ret = 0;
261
262         if (wbc->sync_mode == WB_SYNC_ALL)
263                 ret = FLUSH_COND_STABLE;
264         return ret;
265 }
266
267 /*
268  * NFS congestion control
269  */
270
271 int nfs_congestion_kb;
272
273 #define NFS_CONGESTION_ON_THRESH        (nfs_congestion_kb >> (PAGE_SHIFT-10))
274 #define NFS_CONGESTION_OFF_THRESH       \
275         (NFS_CONGESTION_ON_THRESH - (NFS_CONGESTION_ON_THRESH >> 2))
276
277 static void nfs_set_page_writeback(struct page *page)
278 {
279         struct nfs_server *nfss = NFS_SERVER(page_file_mapping(page)->host);
280         int ret = test_set_page_writeback(page);
281
282         WARN_ON_ONCE(ret != 0);
283
284         if (atomic_long_inc_return(&nfss->writeback) >
285                         NFS_CONGESTION_ON_THRESH) {
286                 set_bdi_congested(&nfss->backing_dev_info,
287                                         BLK_RW_ASYNC);
288         }
289 }
290
291 static void nfs_end_page_writeback(struct nfs_page *req)
292 {
293         struct inode *inode = page_file_mapping(req->wb_page)->host;
294         struct nfs_server *nfss = NFS_SERVER(inode);
295
296         if (!nfs_page_group_sync_on_bit(req, PG_WB_END))
297                 return;
298
299         end_page_writeback(req->wb_page);
300         if (atomic_long_dec_return(&nfss->writeback) < NFS_CONGESTION_OFF_THRESH)
301                 clear_bdi_congested(&nfss->backing_dev_info, BLK_RW_ASYNC);
302 }
303
304
305 /* nfs_page_group_clear_bits
306  *   @req - an nfs request
307  * clears all page group related bits from @req
308  */
309 static void
310 nfs_page_group_clear_bits(struct nfs_page *req)
311 {
312         clear_bit(PG_TEARDOWN, &req->wb_flags);
313         clear_bit(PG_UNLOCKPAGE, &req->wb_flags);
314         clear_bit(PG_UPTODATE, &req->wb_flags);
315         clear_bit(PG_WB_END, &req->wb_flags);
316         clear_bit(PG_REMOVE, &req->wb_flags);
317 }
318
319
320 /*
321  * nfs_unroll_locks_and_wait -  unlock all newly locked reqs and wait on @req
322  *
323  * this is a helper function for nfs_lock_and_join_requests
324  *
325  * @inode - inode associated with request page group, must be holding inode lock
326  * @head  - head request of page group, must be holding head lock
327  * @req   - request that couldn't lock and needs to wait on the req bit lock
328  * @nonblock - if true, don't actually wait
329  *
330  * NOTE: this must be called holding page_group bit lock and inode spin lock
331  *       and BOTH will be released before returning.
332  *
333  * returns 0 on success, < 0 on error.
334  */
335 static int
336 nfs_unroll_locks_and_wait(struct inode *inode, struct nfs_page *head,
337                           struct nfs_page *req, bool nonblock)
338         __releases(&inode->i_lock)
339 {
340         struct nfs_page *tmp;
341         int ret;
342
343         /* relinquish all the locks successfully grabbed this run */
344         for (tmp = head ; tmp != req; tmp = tmp->wb_this_page)
345                 nfs_unlock_request(tmp);
346
347         WARN_ON_ONCE(test_bit(PG_TEARDOWN, &req->wb_flags));
348
349         /* grab a ref on the request that will be waited on */
350         kref_get(&req->wb_kref);
351
352         nfs_page_group_unlock(head);
353         spin_unlock(&inode->i_lock);
354
355         /* release ref from nfs_page_find_head_request_locked */
356         nfs_release_request(head);
357
358         if (!nonblock)
359                 ret = nfs_wait_on_request(req);
360         else
361                 ret = -EAGAIN;
362         nfs_release_request(req);
363
364         return ret;
365 }
366
367 /*
368  * nfs_destroy_unlinked_subrequests - destroy recently unlinked subrequests
369  *
370  * @destroy_list - request list (using wb_this_page) terminated by @old_head
371  * @old_head - the old head of the list
372  *
373  * All subrequests must be locked and removed from all lists, so at this point
374  * they are only "active" in this function, and possibly in nfs_wait_on_request
375  * with a reference held by some other context.
376  */
377 static void
378 nfs_destroy_unlinked_subrequests(struct nfs_page *destroy_list,
379                                  struct nfs_page *old_head)
380 {
381         while (destroy_list) {
382                 struct nfs_page *subreq = destroy_list;
383
384                 destroy_list = (subreq->wb_this_page == old_head) ?
385                                    NULL : subreq->wb_this_page;
386
387                 WARN_ON_ONCE(old_head != subreq->wb_head);
388
389                 /* make sure old group is not used */
390                 subreq->wb_head = subreq;
391                 subreq->wb_this_page = subreq;
392
393                 /* subreq is now totally disconnected from page group or any
394                  * write / commit lists. last chance to wake any waiters */
395                 nfs_unlock_request(subreq);
396
397                 if (!test_bit(PG_TEARDOWN, &subreq->wb_flags)) {
398                         /* release ref on old head request */
399                         nfs_release_request(old_head);
400
401                         nfs_page_group_clear_bits(subreq);
402
403                         /* release the PG_INODE_REF reference */
404                         if (test_and_clear_bit(PG_INODE_REF, &subreq->wb_flags))
405                                 nfs_release_request(subreq);
406                         else
407                                 WARN_ON_ONCE(1);
408                 } else {
409                         WARN_ON_ONCE(test_bit(PG_CLEAN, &subreq->wb_flags));
410                         /* zombie requests have already released the last
411                          * reference and were waiting on the rest of the
412                          * group to complete. Since it's no longer part of a
413                          * group, simply free the request */
414                         nfs_page_group_clear_bits(subreq);
415                         nfs_free_request(subreq);
416                 }
417         }
418 }
419
420 /*
421  * nfs_lock_and_join_requests - join all subreqs to the head req and return
422  *                              a locked reference, cancelling any pending
423  *                              operations for this page.
424  *
425  * @page - the page used to lookup the "page group" of nfs_page structures
426  * @nonblock - if true, don't block waiting for request locks
427  *
428  * This function joins all sub requests to the head request by first
429  * locking all requests in the group, cancelling any pending operations
430  * and finally updating the head request to cover the whole range covered by
431  * the (former) group.  All subrequests are removed from any write or commit
432  * lists, unlinked from the group and destroyed.
433  *
434  * Returns a locked, referenced pointer to the head request - which after
435  * this call is guaranteed to be the only request associated with the page.
436  * Returns NULL if no requests are found for @page, or a ERR_PTR if an
437  * error was encountered.
438  */
439 static struct nfs_page *
440 nfs_lock_and_join_requests(struct page *page, bool nonblock)
441 {
442         struct inode *inode = page_file_mapping(page)->host;
443         struct nfs_page *head, *subreq;
444         struct nfs_page *destroy_list = NULL;
445         unsigned int total_bytes;
446         int ret;
447
448 try_again:
449         total_bytes = 0;
450
451         WARN_ON_ONCE(destroy_list);
452
453         spin_lock(&inode->i_lock);
454
455         /*
456          * A reference is taken only on the head request which acts as a
457          * reference to the whole page group - the group will not be destroyed
458          * until the head reference is released.
459          */
460         head = nfs_page_find_head_request_locked(NFS_I(inode), page);
461
462         if (!head) {
463                 spin_unlock(&inode->i_lock);
464                 return NULL;
465         }
466
467         /* holding inode lock, so always make a non-blocking call to try the
468          * page group lock */
469         ret = nfs_page_group_lock(head, true);
470         if (ret < 0) {
471                 spin_unlock(&inode->i_lock);
472
473                 if (!nonblock && ret == -EAGAIN) {
474                         nfs_page_group_lock_wait(head);
475                         nfs_release_request(head);
476                         goto try_again;
477                 }
478
479                 nfs_release_request(head);
480                 return ERR_PTR(ret);
481         }
482
483         /* lock each request in the page group */
484         subreq = head;
485         do {
486                 /*
487                  * Subrequests are always contiguous, non overlapping
488                  * and in order - but may be repeated (mirrored writes).
489                  */
490                 if (subreq->wb_offset == (head->wb_offset + total_bytes)) {
491                         /* keep track of how many bytes this group covers */
492                         total_bytes += subreq->wb_bytes;
493                 } else if (WARN_ON_ONCE(subreq->wb_offset < head->wb_offset ||
494                             ((subreq->wb_offset + subreq->wb_bytes) >
495                              (head->wb_offset + total_bytes)))) {
496                         nfs_page_group_unlock(head);
497                         spin_unlock(&inode->i_lock);
498                         return ERR_PTR(-EIO);
499                 }
500
501                 if (!nfs_lock_request(subreq)) {
502                         /* releases page group bit lock and
503                          * inode spin lock and all references */
504                         ret = nfs_unroll_locks_and_wait(inode, head,
505                                 subreq, nonblock);
506
507                         if (ret == 0)
508                                 goto try_again;
509
510                         return ERR_PTR(ret);
511                 }
512
513                 subreq = subreq->wb_this_page;
514         } while (subreq != head);
515
516         /* Now that all requests are locked, make sure they aren't on any list.
517          * Commit list removal accounting is done after locks are dropped */
518         subreq = head;
519         do {
520                 nfs_clear_request_commit(subreq);
521                 subreq = subreq->wb_this_page;
522         } while (subreq != head);
523
524         /* unlink subrequests from head, destroy them later */
525         if (head->wb_this_page != head) {
526                 /* destroy list will be terminated by head */
527                 destroy_list = head->wb_this_page;
528                 head->wb_this_page = head;
529
530                 /* change head request to cover whole range that
531                  * the former page group covered */
532                 head->wb_bytes = total_bytes;
533         }
534
535         /*
536          * prepare head request to be added to new pgio descriptor
537          */
538         nfs_page_group_clear_bits(head);
539
540         /*
541          * some part of the group was still on the inode list - otherwise
542          * the group wouldn't be involved in async write.
543          * grab a reference for the head request, iff it needs one.
544          */
545         if (!test_and_set_bit(PG_INODE_REF, &head->wb_flags))
546                 kref_get(&head->wb_kref);
547
548         nfs_page_group_unlock(head);
549
550         /* drop lock to clean uprequests on destroy list */
551         spin_unlock(&inode->i_lock);
552
553         nfs_destroy_unlinked_subrequests(destroy_list, head);
554
555         /* still holds ref on head from nfs_page_find_head_request_locked
556          * and still has lock on head from lock loop */
557         return head;
558 }
559
560 static void nfs_write_error_remove_page(struct nfs_page *req)
561 {
562         nfs_unlock_request(req);
563         nfs_end_page_writeback(req);
564         generic_error_remove_page(page_file_mapping(req->wb_page),
565                                   req->wb_page);
566         nfs_release_request(req);
567 }
568
569 /*
570  * Find an associated nfs write request, and prepare to flush it out
571  * May return an error if the user signalled nfs_wait_on_request().
572  */
573 static int nfs_page_async_flush(struct nfs_pageio_descriptor *pgio,
574                                 struct page *page, bool nonblock,
575                                 bool launder)
576 {
577         struct nfs_page *req;
578         int ret = 0;
579
580         req = nfs_lock_and_join_requests(page, nonblock);
581         if (!req)
582                 goto out;
583         ret = PTR_ERR(req);
584         if (IS_ERR(req))
585                 goto out;
586
587         nfs_set_page_writeback(page);
588         WARN_ON_ONCE(test_bit(PG_CLEAN, &req->wb_flags));
589
590         ret = 0;
591         if (!nfs_pageio_add_request(pgio, req)) {
592                 ret = pgio->pg_error;
593                 /*
594                  * Remove the problematic req upon fatal errors
595                  * in launder case, while other dirty pages can
596                  * still be around until they get flushed.
597                  */
598                 if (nfs_error_is_fatal(ret)) {
599                         nfs_context_set_write_error(req->wb_context, ret);
600                         if (launder) {
601                                 nfs_write_error_remove_page(req);
602                                 goto out;
603                         }
604                 }
605                 nfs_redirty_request(req);
606                 ret = -EAGAIN;
607         } else
608                 nfs_add_stats(page_file_mapping(page)->host,
609                                 NFSIOS_WRITEPAGES, 1);
610 out:
611         return ret;
612 }
613
614 static int nfs_do_writepage(struct page *page, struct writeback_control *wbc,
615                             struct nfs_pageio_descriptor *pgio, bool launder)
616 {
617         int ret;
618
619         nfs_pageio_cond_complete(pgio, page_index(page));
620         ret = nfs_page_async_flush(pgio, page, wbc->sync_mode == WB_SYNC_NONE,
621                                    launder);
622         if (ret == -EAGAIN) {
623                 redirty_page_for_writepage(wbc, page);
624                 ret = 0;
625         }
626         return ret;
627 }
628
629 /*
630  * Write an mmapped page to the server.
631  */
632 static int nfs_writepage_locked(struct page *page,
633                                 struct writeback_control *wbc,
634                                 bool launder)
635 {
636         struct nfs_pageio_descriptor pgio;
637         struct inode *inode = page_file_mapping(page)->host;
638         int err;
639
640         nfs_inc_stats(inode, NFSIOS_VFSWRITEPAGE);
641         nfs_pageio_init_write(&pgio, inode, 0,
642                                 false, &nfs_async_write_completion_ops);
643         err = nfs_do_writepage(page, wbc, &pgio, launder);
644         nfs_pageio_complete(&pgio);
645         if (err < 0)
646                 return err;
647         if (pgio.pg_error < 0)
648                 return pgio.pg_error;
649         return 0;
650 }
651
652 int nfs_writepage(struct page *page, struct writeback_control *wbc)
653 {
654         int ret;
655
656         ret = nfs_writepage_locked(page, wbc, false);
657         unlock_page(page);
658         return ret;
659 }
660
661 static int nfs_writepages_callback(struct page *page, struct writeback_control *wbc, void *data)
662 {
663         int ret;
664
665         ret = nfs_do_writepage(page, wbc, data, false);
666         unlock_page(page);
667         return ret;
668 }
669
670 int nfs_writepages(struct address_space *mapping, struct writeback_control *wbc)
671 {
672         struct inode *inode = mapping->host;
673         struct nfs_pageio_descriptor pgio;
674         int err;
675
676         nfs_inc_stats(inode, NFSIOS_VFSWRITEPAGES);
677
678         nfs_pageio_init_write(&pgio, inode, wb_priority(wbc), false,
679                                 &nfs_async_write_completion_ops);
680         err = write_cache_pages(mapping, wbc, nfs_writepages_callback, &pgio);
681         nfs_pageio_complete(&pgio);
682
683         if (err < 0)
684                 goto out_err;
685         err = pgio.pg_error;
686         if (err < 0)
687                 goto out_err;
688         return 0;
689 out_err:
690         return err;
691 }
692
693 /*
694  * Insert a write request into an inode
695  */
696 static void nfs_inode_add_request(struct inode *inode, struct nfs_page *req)
697 {
698         struct nfs_inode *nfsi = NFS_I(inode);
699
700         WARN_ON_ONCE(req->wb_this_page != req);
701
702         /* Lock the request! */
703         nfs_lock_request(req);
704
705         spin_lock(&inode->i_lock);
706         if (!nfsi->nrequests &&
707             NFS_PROTO(inode)->have_delegation(inode, FMODE_WRITE))
708                 inode->i_version++;
709         /*
710          * Swap-space should not get truncated. Hence no need to plug the race
711          * with invalidate/truncate.
712          */
713         if (likely(!PageSwapCache(req->wb_page))) {
714                 set_bit(PG_MAPPED, &req->wb_flags);
715                 SetPagePrivate(req->wb_page);
716                 set_page_private(req->wb_page, (unsigned long)req);
717         }
718         nfsi->nrequests++;
719         /* this a head request for a page group - mark it as having an
720          * extra reference so sub groups can follow suit.
721          * This flag also informs pgio layer when to bump nrequests when
722          * adding subrequests. */
723         WARN_ON(test_and_set_bit(PG_INODE_REF, &req->wb_flags));
724         kref_get(&req->wb_kref);
725         spin_unlock(&inode->i_lock);
726 }
727
728 /*
729  * Remove a write request from an inode
730  */
731 static void nfs_inode_remove_request(struct nfs_page *req)
732 {
733         struct inode *inode = d_inode(req->wb_context->dentry);
734         struct nfs_inode *nfsi = NFS_I(inode);
735         struct nfs_page *head;
736
737         if (nfs_page_group_sync_on_bit(req, PG_REMOVE)) {
738                 head = req->wb_head;
739
740                 spin_lock(&inode->i_lock);
741                 if (likely(head->wb_page && !PageSwapCache(head->wb_page))) {
742                         set_page_private(head->wb_page, 0);
743                         ClearPagePrivate(head->wb_page);
744                         clear_bit(PG_MAPPED, &head->wb_flags);
745                 }
746                 nfsi->nrequests--;
747                 spin_unlock(&inode->i_lock);
748         } else {
749                 spin_lock(&inode->i_lock);
750                 nfsi->nrequests--;
751                 spin_unlock(&inode->i_lock);
752         }
753
754         if (test_and_clear_bit(PG_INODE_REF, &req->wb_flags))
755                 nfs_release_request(req);
756 }
757
758 static void
759 nfs_mark_request_dirty(struct nfs_page *req)
760 {
761         if (req->wb_page)
762                 __set_page_dirty_nobuffers(req->wb_page);
763 }
764
765 /*
766  * nfs_page_search_commits_for_head_request_locked
767  *
768  * Search through commit lists on @inode for the head request for @page.
769  * Must be called while holding the inode (which is cinfo) lock.
770  *
771  * Returns the head request if found, or NULL if not found.
772  */
773 static struct nfs_page *
774 nfs_page_search_commits_for_head_request_locked(struct nfs_inode *nfsi,
775                                                 struct page *page)
776 {
777         struct nfs_page *freq, *t;
778         struct nfs_commit_info cinfo;
779         struct inode *inode = &nfsi->vfs_inode;
780
781         nfs_init_cinfo_from_inode(&cinfo, inode);
782
783         /* search through pnfs commit lists */
784         freq = pnfs_search_commit_reqs(inode, &cinfo, page);
785         if (freq)
786                 return freq->wb_head;
787
788         /* Linearly search the commit list for the correct request */
789         list_for_each_entry_safe(freq, t, &cinfo.mds->list, wb_list) {
790                 if (freq->wb_page == page)
791                         return freq->wb_head;
792         }
793
794         return NULL;
795 }
796
797 /**
798  * nfs_request_add_commit_list_locked - add request to a commit list
799  * @req: pointer to a struct nfs_page
800  * @dst: commit list head
801  * @cinfo: holds list lock and accounting info
802  *
803  * This sets the PG_CLEAN bit, updates the cinfo count of
804  * number of outstanding requests requiring a commit as well as
805  * the MM page stats.
806  *
807  * The caller must hold cinfo->inode->i_lock, and the nfs_page lock.
808  */
809 void
810 nfs_request_add_commit_list_locked(struct nfs_page *req, struct list_head *dst,
811                             struct nfs_commit_info *cinfo)
812 {
813         set_bit(PG_CLEAN, &req->wb_flags);
814         nfs_list_add_request(req, dst);
815         cinfo->mds->ncommit++;
816 }
817 EXPORT_SYMBOL_GPL(nfs_request_add_commit_list_locked);
818
819 /**
820  * nfs_request_add_commit_list - add request to a commit list
821  * @req: pointer to a struct nfs_page
822  * @dst: commit list head
823  * @cinfo: holds list lock and accounting info
824  *
825  * This sets the PG_CLEAN bit, updates the cinfo count of
826  * number of outstanding requests requiring a commit as well as
827  * the MM page stats.
828  *
829  * The caller must _not_ hold the cinfo->lock, but must be
830  * holding the nfs_page lock.
831  */
832 void
833 nfs_request_add_commit_list(struct nfs_page *req, struct nfs_commit_info *cinfo)
834 {
835         spin_lock(&cinfo->inode->i_lock);
836         nfs_request_add_commit_list_locked(req, &cinfo->mds->list, cinfo);
837         spin_unlock(&cinfo->inode->i_lock);
838         if (req->wb_page)
839                 nfs_mark_page_unstable(req->wb_page, cinfo);
840 }
841 EXPORT_SYMBOL_GPL(nfs_request_add_commit_list);
842
843 /**
844  * nfs_request_remove_commit_list - Remove request from a commit list
845  * @req: pointer to a nfs_page
846  * @cinfo: holds list lock and accounting info
847  *
848  * This clears the PG_CLEAN bit, and updates the cinfo's count of
849  * number of outstanding requests requiring a commit
850  * It does not update the MM page stats.
851  *
852  * The caller _must_ hold the cinfo->lock and the nfs_page lock.
853  */
854 void
855 nfs_request_remove_commit_list(struct nfs_page *req,
856                                struct nfs_commit_info *cinfo)
857 {
858         if (!test_and_clear_bit(PG_CLEAN, &(req)->wb_flags))
859                 return;
860         nfs_list_remove_request(req);
861         cinfo->mds->ncommit--;
862 }
863 EXPORT_SYMBOL_GPL(nfs_request_remove_commit_list);
864
865 static void nfs_init_cinfo_from_inode(struct nfs_commit_info *cinfo,
866                                       struct inode *inode)
867 {
868         cinfo->inode = inode;
869         cinfo->mds = &NFS_I(inode)->commit_info;
870         cinfo->ds = pnfs_get_ds_info(inode);
871         cinfo->dreq = NULL;
872         cinfo->completion_ops = &nfs_commit_completion_ops;
873 }
874
875 void nfs_init_cinfo(struct nfs_commit_info *cinfo,
876                     struct inode *inode,
877                     struct nfs_direct_req *dreq)
878 {
879         if (dreq)
880                 nfs_init_cinfo_from_dreq(cinfo, dreq);
881         else
882                 nfs_init_cinfo_from_inode(cinfo, inode);
883 }
884 EXPORT_SYMBOL_GPL(nfs_init_cinfo);
885
886 /*
887  * Add a request to the inode's commit list.
888  */
889 void
890 nfs_mark_request_commit(struct nfs_page *req, struct pnfs_layout_segment *lseg,
891                         struct nfs_commit_info *cinfo, u32 ds_commit_idx)
892 {
893         if (pnfs_mark_request_commit(req, lseg, cinfo, ds_commit_idx))
894                 return;
895         nfs_request_add_commit_list(req, cinfo);
896 }
897
898 static void
899 nfs_clear_page_commit(struct page *page)
900 {
901         dec_node_page_state(page, NR_UNSTABLE_NFS);
902         dec_wb_stat(&inode_to_bdi(page_file_mapping(page)->host)->wb,
903                     WB_RECLAIMABLE);
904 }
905
906 /* Called holding inode (/cinfo) lock */
907 static void
908 nfs_clear_request_commit(struct nfs_page *req)
909 {
910         if (test_bit(PG_CLEAN, &req->wb_flags)) {
911                 struct inode *inode = d_inode(req->wb_context->dentry);
912                 struct nfs_commit_info cinfo;
913
914                 nfs_init_cinfo_from_inode(&cinfo, inode);
915                 if (!pnfs_clear_request_commit(req, &cinfo)) {
916                         nfs_request_remove_commit_list(req, &cinfo);
917                 }
918                 nfs_clear_page_commit(req->wb_page);
919         }
920 }
921
922 int nfs_write_need_commit(struct nfs_pgio_header *hdr)
923 {
924         if (hdr->verf.committed == NFS_DATA_SYNC)
925                 return hdr->lseg == NULL;
926         return hdr->verf.committed != NFS_FILE_SYNC;
927 }
928
929 static void nfs_write_completion(struct nfs_pgio_header *hdr)
930 {
931         struct nfs_commit_info cinfo;
932         unsigned long bytes = 0;
933
934         if (test_bit(NFS_IOHDR_REDO, &hdr->flags))
935                 goto out;
936         nfs_init_cinfo_from_inode(&cinfo, hdr->inode);
937         while (!list_empty(&hdr->pages)) {
938                 struct nfs_page *req = nfs_list_entry(hdr->pages.next);
939
940                 bytes += req->wb_bytes;
941                 nfs_list_remove_request(req);
942                 if (test_bit(NFS_IOHDR_ERROR, &hdr->flags) &&
943                     (hdr->good_bytes < bytes)) {
944                         nfs_set_pageerror(req->wb_page);
945                         nfs_context_set_write_error(req->wb_context, hdr->error);
946                         goto remove_req;
947                 }
948                 if (nfs_write_need_commit(hdr)) {
949                         memcpy(&req->wb_verf, &hdr->verf.verifier, sizeof(req->wb_verf));
950                         nfs_mark_request_commit(req, hdr->lseg, &cinfo,
951                                 hdr->pgio_mirror_idx);
952                         goto next;
953                 }
954 remove_req:
955                 nfs_inode_remove_request(req);
956 next:
957                 nfs_unlock_request(req);
958                 nfs_end_page_writeback(req);
959                 nfs_release_request(req);
960         }
961 out:
962         hdr->release(hdr);
963 }
964
965 unsigned long
966 nfs_reqs_to_commit(struct nfs_commit_info *cinfo)
967 {
968         return cinfo->mds->ncommit;
969 }
970
971 /* cinfo->inode->i_lock held by caller */
972 int
973 nfs_scan_commit_list(struct list_head *src, struct list_head *dst,
974                      struct nfs_commit_info *cinfo, int max)
975 {
976         struct nfs_page *req, *tmp;
977         int ret = 0;
978
979         list_for_each_entry_safe(req, tmp, src, wb_list) {
980                 if (!nfs_lock_request(req))
981                         continue;
982                 kref_get(&req->wb_kref);
983                 if (cond_resched_lock(&cinfo->inode->i_lock))
984                         list_safe_reset_next(req, tmp, wb_list);
985                 nfs_request_remove_commit_list(req, cinfo);
986                 nfs_list_add_request(req, dst);
987                 ret++;
988                 if ((ret == max) && !cinfo->dreq)
989                         break;
990         }
991         return ret;
992 }
993
994 /*
995  * nfs_scan_commit - Scan an inode for commit requests
996  * @inode: NFS inode to scan
997  * @dst: mds destination list
998  * @cinfo: mds and ds lists of reqs ready to commit
999  *
1000  * Moves requests from the inode's 'commit' request list.
1001  * The requests are *not* checked to ensure that they form a contiguous set.
1002  */
1003 int
1004 nfs_scan_commit(struct inode *inode, struct list_head *dst,
1005                 struct nfs_commit_info *cinfo)
1006 {
1007         int ret = 0;
1008
1009         spin_lock(&cinfo->inode->i_lock);
1010         if (cinfo->mds->ncommit > 0) {
1011                 const int max = INT_MAX;
1012
1013                 ret = nfs_scan_commit_list(&cinfo->mds->list, dst,
1014                                            cinfo, max);
1015                 ret += pnfs_scan_commit_lists(inode, cinfo, max - ret);
1016         }
1017         spin_unlock(&cinfo->inode->i_lock);
1018         return ret;
1019 }
1020
1021 /*
1022  * Search for an existing write request, and attempt to update
1023  * it to reflect a new dirty region on a given page.
1024  *
1025  * If the attempt fails, then the existing request is flushed out
1026  * to disk.
1027  */
1028 static struct nfs_page *nfs_try_to_update_request(struct inode *inode,
1029                 struct page *page,
1030                 unsigned int offset,
1031                 unsigned int bytes)
1032 {
1033         struct nfs_page *req;
1034         unsigned int rqend;
1035         unsigned int end;
1036         int error;
1037
1038         if (!PagePrivate(page))
1039                 return NULL;
1040
1041         end = offset + bytes;
1042         spin_lock(&inode->i_lock);
1043
1044         for (;;) {
1045                 req = nfs_page_find_head_request_locked(NFS_I(inode), page);
1046                 if (req == NULL)
1047                         goto out_unlock;
1048
1049                 /* should be handled by nfs_flush_incompatible */
1050                 WARN_ON_ONCE(req->wb_head != req);
1051                 WARN_ON_ONCE(req->wb_this_page != req);
1052
1053                 rqend = req->wb_offset + req->wb_bytes;
1054                 /*
1055                  * Tell the caller to flush out the request if
1056                  * the offsets are non-contiguous.
1057                  * Note: nfs_flush_incompatible() will already
1058                  * have flushed out requests having wrong owners.
1059                  */
1060                 if (offset > rqend
1061                     || end < req->wb_offset)
1062                         goto out_flushme;
1063
1064                 if (nfs_lock_request(req))
1065                         break;
1066
1067                 /* The request is locked, so wait and then retry */
1068                 spin_unlock(&inode->i_lock);
1069                 error = nfs_wait_on_request(req);
1070                 nfs_release_request(req);
1071                 if (error != 0)
1072                         goto out_err;
1073                 spin_lock(&inode->i_lock);
1074         }
1075
1076         /* Okay, the request matches. Update the region */
1077         if (offset < req->wb_offset) {
1078                 req->wb_offset = offset;
1079                 req->wb_pgbase = offset;
1080         }
1081         if (end > rqend)
1082                 req->wb_bytes = end - req->wb_offset;
1083         else
1084                 req->wb_bytes = rqend - req->wb_offset;
1085 out_unlock:
1086         if (req)
1087                 nfs_clear_request_commit(req);
1088         spin_unlock(&inode->i_lock);
1089         return req;
1090 out_flushme:
1091         spin_unlock(&inode->i_lock);
1092         nfs_release_request(req);
1093         error = nfs_wb_page(inode, page);
1094 out_err:
1095         return ERR_PTR(error);
1096 }
1097
1098 /*
1099  * Try to update an existing write request, or create one if there is none.
1100  *
1101  * Note: Should always be called with the Page Lock held to prevent races
1102  * if we have to add a new request. Also assumes that the caller has
1103  * already called nfs_flush_incompatible() if necessary.
1104  */
1105 static struct nfs_page * nfs_setup_write_request(struct nfs_open_context* ctx,
1106                 struct page *page, unsigned int offset, unsigned int bytes)
1107 {
1108         struct inode *inode = page_file_mapping(page)->host;
1109         struct nfs_page *req;
1110
1111         req = nfs_try_to_update_request(inode, page, offset, bytes);
1112         if (req != NULL)
1113                 goto out;
1114         req = nfs_create_request(ctx, page, NULL, offset, bytes);
1115         if (IS_ERR(req))
1116                 goto out;
1117         nfs_inode_add_request(inode, req);
1118 out:
1119         return req;
1120 }
1121
1122 static int nfs_writepage_setup(struct nfs_open_context *ctx, struct page *page,
1123                 unsigned int offset, unsigned int count)
1124 {
1125         struct nfs_page *req;
1126
1127         req = nfs_setup_write_request(ctx, page, offset, count);
1128         if (IS_ERR(req))
1129                 return PTR_ERR(req);
1130         /* Update file length */
1131         nfs_grow_file(page, offset, count);
1132         nfs_mark_uptodate(req);
1133         nfs_mark_request_dirty(req);
1134         nfs_unlock_and_release_request(req);
1135         return 0;
1136 }
1137
1138 int nfs_flush_incompatible(struct file *file, struct page *page)
1139 {
1140         struct nfs_open_context *ctx = nfs_file_open_context(file);
1141         struct nfs_lock_context *l_ctx;
1142         struct file_lock_context *flctx = file_inode(file)->i_flctx;
1143         struct nfs_page *req;
1144         int do_flush, status;
1145         /*
1146          * Look for a request corresponding to this page. If there
1147          * is one, and it belongs to another file, we flush it out
1148          * before we try to copy anything into the page. Do this
1149          * due to the lack of an ACCESS-type call in NFSv2.
1150          * Also do the same if we find a request from an existing
1151          * dropped page.
1152          */
1153         do {
1154                 req = nfs_page_find_head_request(page);
1155                 if (req == NULL)
1156                         return 0;
1157                 l_ctx = req->wb_lock_context;
1158                 do_flush = req->wb_page != page ||
1159                         !nfs_match_open_context(req->wb_context, ctx);
1160                 /* for now, flush if more than 1 request in page_group */
1161                 do_flush |= req->wb_this_page != req;
1162                 if (l_ctx && flctx &&
1163                     !(list_empty_careful(&flctx->flc_posix) &&
1164                       list_empty_careful(&flctx->flc_flock))) {
1165                         do_flush |= l_ctx->lockowner != current->files;
1166                 }
1167                 nfs_release_request(req);
1168                 if (!do_flush)
1169                         return 0;
1170                 status = nfs_wb_page(page_file_mapping(page)->host, page);
1171         } while (status == 0);
1172         return status;
1173 }
1174
1175 /*
1176  * Avoid buffered writes when a open context credential's key would
1177  * expire soon.
1178  *
1179  * Returns -EACCES if the key will expire within RPC_KEY_EXPIRE_FAIL.
1180  *
1181  * Return 0 and set a credential flag which triggers the inode to flush
1182  * and performs  NFS_FILE_SYNC writes if the key will expired within
1183  * RPC_KEY_EXPIRE_TIMEO.
1184  */
1185 int
1186 nfs_key_timeout_notify(struct file *filp, struct inode *inode)
1187 {
1188         struct nfs_open_context *ctx = nfs_file_open_context(filp);
1189         struct rpc_auth *auth = NFS_SERVER(inode)->client->cl_auth;
1190
1191         return rpcauth_key_timeout_notify(auth, ctx->cred);
1192 }
1193
1194 /*
1195  * Test if the open context credential key is marked to expire soon.
1196  */
1197 bool nfs_ctx_key_to_expire(struct nfs_open_context *ctx, struct inode *inode)
1198 {
1199         struct rpc_auth *auth = NFS_SERVER(inode)->client->cl_auth;
1200
1201         return rpcauth_cred_key_to_expire(auth, ctx->cred);
1202 }
1203
1204 /*
1205  * If the page cache is marked as unsafe or invalid, then we can't rely on
1206  * the PageUptodate() flag. In this case, we will need to turn off
1207  * write optimisations that depend on the page contents being correct.
1208  */
1209 static bool nfs_write_pageuptodate(struct page *page, struct inode *inode)
1210 {
1211         struct nfs_inode *nfsi = NFS_I(inode);
1212
1213         if (nfs_have_delegated_attributes(inode))
1214                 goto out;
1215         if (nfsi->cache_validity & NFS_INO_REVAL_PAGECACHE)
1216                 return false;
1217         smp_rmb();
1218         if (test_bit(NFS_INO_INVALIDATING, &nfsi->flags))
1219                 return false;
1220 out:
1221         if (nfsi->cache_validity & NFS_INO_INVALID_DATA)
1222                 return false;
1223         return PageUptodate(page) != 0;
1224 }
1225
1226 static bool
1227 is_whole_file_wrlock(struct file_lock *fl)
1228 {
1229         return fl->fl_start == 0 && fl->fl_end == OFFSET_MAX &&
1230                         fl->fl_type == F_WRLCK;
1231 }
1232
1233 /* If we know the page is up to date, and we're not using byte range locks (or
1234  * if we have the whole file locked for writing), it may be more efficient to
1235  * extend the write to cover the entire page in order to avoid fragmentation
1236  * inefficiencies.
1237  *
1238  * If the file is opened for synchronous writes then we can just skip the rest
1239  * of the checks.
1240  */
1241 static int nfs_can_extend_write(struct file *file, struct page *page, struct inode *inode)
1242 {
1243         int ret;
1244         struct file_lock_context *flctx = inode->i_flctx;
1245         struct file_lock *fl;
1246
1247         if (file->f_flags & O_DSYNC)
1248                 return 0;
1249         if (!nfs_write_pageuptodate(page, inode))
1250                 return 0;
1251         if (NFS_PROTO(inode)->have_delegation(inode, FMODE_WRITE))
1252                 return 1;
1253         if (!flctx || (list_empty_careful(&flctx->flc_flock) &&
1254                        list_empty_careful(&flctx->flc_posix)))
1255                 return 1;
1256
1257         /* Check to see if there are whole file write locks */
1258         ret = 0;
1259         spin_lock(&flctx->flc_lock);
1260         if (!list_empty(&flctx->flc_posix)) {
1261                 fl = list_first_entry(&flctx->flc_posix, struct file_lock,
1262                                         fl_list);
1263                 if (is_whole_file_wrlock(fl))
1264                         ret = 1;
1265         } else if (!list_empty(&flctx->flc_flock)) {
1266                 fl = list_first_entry(&flctx->flc_flock, struct file_lock,
1267                                         fl_list);
1268                 if (fl->fl_type == F_WRLCK)
1269                         ret = 1;
1270         }
1271         spin_unlock(&flctx->flc_lock);
1272         return ret;
1273 }
1274
1275 /*
1276  * Update and possibly write a cached page of an NFS file.
1277  *
1278  * XXX: Keep an eye on generic_file_read to make sure it doesn't do bad
1279  * things with a page scheduled for an RPC call (e.g. invalidate it).
1280  */
1281 int nfs_updatepage(struct file *file, struct page *page,
1282                 unsigned int offset, unsigned int count)
1283 {
1284         struct nfs_open_context *ctx = nfs_file_open_context(file);
1285         struct inode    *inode = page_file_mapping(page)->host;
1286         int             status = 0;
1287
1288         nfs_inc_stats(inode, NFSIOS_VFSUPDATEPAGE);
1289
1290         dprintk("NFS:       nfs_updatepage(%pD2 %d@%lld)\n",
1291                 file, count, (long long)(page_file_offset(page) + offset));
1292
1293         if (!count)
1294                 goto out;
1295
1296         if (nfs_can_extend_write(file, page, inode)) {
1297                 count = max(count + offset, nfs_page_length(page));
1298                 offset = 0;
1299         }
1300
1301         status = nfs_writepage_setup(ctx, page, offset, count);
1302         if (status < 0)
1303                 nfs_set_pageerror(page);
1304         else
1305                 __set_page_dirty_nobuffers(page);
1306 out:
1307         dprintk("NFS:       nfs_updatepage returns %d (isize %lld)\n",
1308                         status, (long long)i_size_read(inode));
1309         return status;
1310 }
1311
1312 static int flush_task_priority(int how)
1313 {
1314         switch (how & (FLUSH_HIGHPRI|FLUSH_LOWPRI)) {
1315                 case FLUSH_HIGHPRI:
1316                         return RPC_PRIORITY_HIGH;
1317                 case FLUSH_LOWPRI:
1318                         return RPC_PRIORITY_LOW;
1319         }
1320         return RPC_PRIORITY_NORMAL;
1321 }
1322
1323 static void nfs_initiate_write(struct nfs_pgio_header *hdr,
1324                                struct rpc_message *msg,
1325                                const struct nfs_rpc_ops *rpc_ops,
1326                                struct rpc_task_setup *task_setup_data, int how)
1327 {
1328         int priority = flush_task_priority(how);
1329
1330         task_setup_data->priority = priority;
1331         rpc_ops->write_setup(hdr, msg);
1332
1333         nfs4_state_protect_write(NFS_SERVER(hdr->inode)->nfs_client,
1334                                  &task_setup_data->rpc_client, msg, hdr);
1335 }
1336
1337 /* If a nfs_flush_* function fails, it should remove reqs from @head and
1338  * call this on each, which will prepare them to be retried on next
1339  * writeback using standard nfs.
1340  */
1341 static void nfs_redirty_request(struct nfs_page *req)
1342 {
1343         nfs_mark_request_dirty(req);
1344         set_bit(NFS_CONTEXT_RESEND_WRITES, &req->wb_context->flags);
1345         nfs_unlock_request(req);
1346         nfs_end_page_writeback(req);
1347         nfs_release_request(req);
1348 }
1349
1350 static void nfs_async_write_error(struct list_head *head)
1351 {
1352         struct nfs_page *req;
1353
1354         while (!list_empty(head)) {
1355                 req = nfs_list_entry(head->next);
1356                 nfs_list_remove_request(req);
1357                 nfs_redirty_request(req);
1358         }
1359 }
1360
1361 static void nfs_async_write_reschedule_io(struct nfs_pgio_header *hdr)
1362 {
1363         nfs_async_write_error(&hdr->pages);
1364 }
1365
1366 static const struct nfs_pgio_completion_ops nfs_async_write_completion_ops = {
1367         .error_cleanup = nfs_async_write_error,
1368         .completion = nfs_write_completion,
1369         .reschedule_io = nfs_async_write_reschedule_io,
1370 };
1371
1372 void nfs_pageio_init_write(struct nfs_pageio_descriptor *pgio,
1373                                struct inode *inode, int ioflags, bool force_mds,
1374                                const struct nfs_pgio_completion_ops *compl_ops)
1375 {
1376         struct nfs_server *server = NFS_SERVER(inode);
1377         const struct nfs_pageio_ops *pg_ops = &nfs_pgio_rw_ops;
1378
1379 #ifdef CONFIG_NFS_V4_1
1380         if (server->pnfs_curr_ld && !force_mds)
1381                 pg_ops = server->pnfs_curr_ld->pg_write_ops;
1382 #endif
1383         nfs_pageio_init(pgio, inode, pg_ops, compl_ops, &nfs_rw_write_ops,
1384                         server->wsize, ioflags);
1385 }
1386 EXPORT_SYMBOL_GPL(nfs_pageio_init_write);
1387
1388 void nfs_pageio_reset_write_mds(struct nfs_pageio_descriptor *pgio)
1389 {
1390         struct nfs_pgio_mirror *mirror;
1391
1392         if (pgio->pg_ops && pgio->pg_ops->pg_cleanup)
1393                 pgio->pg_ops->pg_cleanup(pgio);
1394
1395         pgio->pg_ops = &nfs_pgio_rw_ops;
1396
1397         nfs_pageio_stop_mirroring(pgio);
1398
1399         mirror = &pgio->pg_mirrors[0];
1400         mirror->pg_bsize = NFS_SERVER(pgio->pg_inode)->wsize;
1401 }
1402 EXPORT_SYMBOL_GPL(nfs_pageio_reset_write_mds);
1403
1404
1405 void nfs_commit_prepare(struct rpc_task *task, void *calldata)
1406 {
1407         struct nfs_commit_data *data = calldata;
1408
1409         NFS_PROTO(data->inode)->commit_rpc_prepare(task, data);
1410 }
1411
1412 /*
1413  * Special version of should_remove_suid() that ignores capabilities.
1414  */
1415 static int nfs_should_remove_suid(const struct inode *inode)
1416 {
1417         umode_t mode = inode->i_mode;
1418         int kill = 0;
1419
1420         /* suid always must be killed */
1421         if (unlikely(mode & S_ISUID))
1422                 kill = ATTR_KILL_SUID;
1423
1424         /*
1425          * sgid without any exec bits is just a mandatory locking mark; leave
1426          * it alone.  If some exec bits are set, it's a real sgid; kill it.
1427          */
1428         if (unlikely((mode & S_ISGID) && (mode & S_IXGRP)))
1429                 kill |= ATTR_KILL_SGID;
1430
1431         if (unlikely(kill && S_ISREG(mode)))
1432                 return kill;
1433
1434         return 0;
1435 }
1436
1437 static void nfs_writeback_check_extend(struct nfs_pgio_header *hdr,
1438                 struct nfs_fattr *fattr)
1439 {
1440         struct nfs_pgio_args *argp = &hdr->args;
1441         struct nfs_pgio_res *resp = &hdr->res;
1442         u64 size = argp->offset + resp->count;
1443
1444         if (!(fattr->valid & NFS_ATTR_FATTR_SIZE))
1445                 fattr->size = size;
1446         if (nfs_size_to_loff_t(fattr->size) < i_size_read(hdr->inode)) {
1447                 fattr->valid &= ~NFS_ATTR_FATTR_SIZE;
1448                 return;
1449         }
1450         if (size != fattr->size)
1451                 return;
1452         /* Set attribute barrier */
1453         nfs_fattr_set_barrier(fattr);
1454         /* ...and update size */
1455         fattr->valid |= NFS_ATTR_FATTR_SIZE;
1456 }
1457
1458 void nfs_writeback_update_inode(struct nfs_pgio_header *hdr)
1459 {
1460         struct nfs_fattr *fattr = &hdr->fattr;
1461         struct inode *inode = hdr->inode;
1462
1463         spin_lock(&inode->i_lock);
1464         nfs_writeback_check_extend(hdr, fattr);
1465         nfs_post_op_update_inode_force_wcc_locked(inode, fattr);
1466         spin_unlock(&inode->i_lock);
1467 }
1468 EXPORT_SYMBOL_GPL(nfs_writeback_update_inode);
1469
1470 /*
1471  * This function is called when the WRITE call is complete.
1472  */
1473 static int nfs_writeback_done(struct rpc_task *task,
1474                               struct nfs_pgio_header *hdr,
1475                               struct inode *inode)
1476 {
1477         int status;
1478
1479         /*
1480          * ->write_done will attempt to use post-op attributes to detect
1481          * conflicting writes by other clients.  A strict interpretation
1482          * of close-to-open would allow us to continue caching even if
1483          * another writer had changed the file, but some applications
1484          * depend on tighter cache coherency when writing.
1485          */
1486         status = NFS_PROTO(inode)->write_done(task, hdr);
1487         if (status != 0)
1488                 return status;
1489         nfs_add_stats(inode, NFSIOS_SERVERWRITTENBYTES, hdr->res.count);
1490
1491         if (hdr->res.verf->committed < hdr->args.stable &&
1492             task->tk_status >= 0) {
1493                 /* We tried a write call, but the server did not
1494                  * commit data to stable storage even though we
1495                  * requested it.
1496                  * Note: There is a known bug in Tru64 < 5.0 in which
1497                  *       the server reports NFS_DATA_SYNC, but performs
1498                  *       NFS_FILE_SYNC. We therefore implement this checking
1499                  *       as a dprintk() in order to avoid filling syslog.
1500                  */
1501                 static unsigned long    complain;
1502
1503                 /* Note this will print the MDS for a DS write */
1504                 if (time_before(complain, jiffies)) {
1505                         dprintk("NFS:       faulty NFS server %s:"
1506                                 " (committed = %d) != (stable = %d)\n",
1507                                 NFS_SERVER(inode)->nfs_client->cl_hostname,
1508                                 hdr->res.verf->committed, hdr->args.stable);
1509                         complain = jiffies + 300 * HZ;
1510                 }
1511         }
1512
1513         /* Deal with the suid/sgid bit corner case */
1514         if (nfs_should_remove_suid(inode))
1515                 nfs_mark_for_revalidate(inode);
1516         return 0;
1517 }
1518
1519 /*
1520  * This function is called when the WRITE call is complete.
1521  */
1522 static void nfs_writeback_result(struct rpc_task *task,
1523                                  struct nfs_pgio_header *hdr)
1524 {
1525         struct nfs_pgio_args    *argp = &hdr->args;
1526         struct nfs_pgio_res     *resp = &hdr->res;
1527
1528         if (resp->count < argp->count) {
1529                 static unsigned long    complain;
1530
1531                 /* This a short write! */
1532                 nfs_inc_stats(hdr->inode, NFSIOS_SHORTWRITE);
1533
1534                 /* Has the server at least made some progress? */
1535                 if (resp->count == 0) {
1536                         if (time_before(complain, jiffies)) {
1537                                 printk(KERN_WARNING
1538                                        "NFS: Server wrote zero bytes, expected %u.\n",
1539                                        argp->count);
1540                                 complain = jiffies + 300 * HZ;
1541                         }
1542                         nfs_set_pgio_error(hdr, -EIO, argp->offset);
1543                         task->tk_status = -EIO;
1544                         return;
1545                 }
1546
1547                 /* For non rpc-based layout drivers, retry-through-MDS */
1548                 if (!task->tk_ops) {
1549                         hdr->pnfs_error = -EAGAIN;
1550                         return;
1551                 }
1552
1553                 /* Was this an NFSv2 write or an NFSv3 stable write? */
1554                 if (resp->verf->committed != NFS_UNSTABLE) {
1555                         /* Resend from where the server left off */
1556                         hdr->mds_offset += resp->count;
1557                         argp->offset += resp->count;
1558                         argp->pgbase += resp->count;
1559                         argp->count -= resp->count;
1560                 } else {
1561                         /* Resend as a stable write in order to avoid
1562                          * headaches in the case of a server crash.
1563                          */
1564                         argp->stable = NFS_FILE_SYNC;
1565                 }
1566                 rpc_restart_call_prepare(task);
1567         }
1568 }
1569
1570 static int wait_on_commit(struct nfs_mds_commit_info *cinfo)
1571 {
1572         return wait_on_atomic_t(&cinfo->rpcs_out,
1573                         nfs_wait_atomic_killable, TASK_KILLABLE);
1574 }
1575
1576 static void nfs_commit_begin(struct nfs_mds_commit_info *cinfo)
1577 {
1578         atomic_inc(&cinfo->rpcs_out);
1579 }
1580
1581 static void nfs_commit_end(struct nfs_mds_commit_info *cinfo)
1582 {
1583         if (atomic_dec_and_test(&cinfo->rpcs_out))
1584                 wake_up_atomic_t(&cinfo->rpcs_out);
1585 }
1586
1587 void nfs_commitdata_release(struct nfs_commit_data *data)
1588 {
1589         put_nfs_open_context(data->context);
1590         nfs_commit_free(data);
1591 }
1592 EXPORT_SYMBOL_GPL(nfs_commitdata_release);
1593
1594 int nfs_initiate_commit(struct rpc_clnt *clnt, struct nfs_commit_data *data,
1595                         const struct nfs_rpc_ops *nfs_ops,
1596                         const struct rpc_call_ops *call_ops,
1597                         int how, int flags)
1598 {
1599         struct rpc_task *task;
1600         int priority = flush_task_priority(how);
1601         struct rpc_message msg = {
1602                 .rpc_argp = &data->args,
1603                 .rpc_resp = &data->res,
1604                 .rpc_cred = data->cred,
1605         };
1606         struct rpc_task_setup task_setup_data = {
1607                 .task = &data->task,
1608                 .rpc_client = clnt,
1609                 .rpc_message = &msg,
1610                 .callback_ops = call_ops,
1611                 .callback_data = data,
1612                 .workqueue = nfsiod_workqueue,
1613                 .flags = RPC_TASK_ASYNC | flags,
1614                 .priority = priority,
1615         };
1616         /* Set up the initial task struct.  */
1617         nfs_ops->commit_setup(data, &msg);
1618
1619         dprintk("NFS: initiated commit call\n");
1620
1621         nfs4_state_protect(NFS_SERVER(data->inode)->nfs_client,
1622                 NFS_SP4_MACH_CRED_COMMIT, &task_setup_data.rpc_client, &msg);
1623
1624         task = rpc_run_task(&task_setup_data);
1625         if (IS_ERR(task))
1626                 return PTR_ERR(task);
1627         if (how & FLUSH_SYNC)
1628                 rpc_wait_for_completion_task(task);
1629         rpc_put_task(task);
1630         return 0;
1631 }
1632 EXPORT_SYMBOL_GPL(nfs_initiate_commit);
1633
1634 static loff_t nfs_get_lwb(struct list_head *head)
1635 {
1636         loff_t lwb = 0;
1637         struct nfs_page *req;
1638
1639         list_for_each_entry(req, head, wb_list)
1640                 if (lwb < (req_offset(req) + req->wb_bytes))
1641                         lwb = req_offset(req) + req->wb_bytes;
1642
1643         return lwb;
1644 }
1645
1646 /*
1647  * Set up the argument/result storage required for the RPC call.
1648  */
1649 void nfs_init_commit(struct nfs_commit_data *data,
1650                      struct list_head *head,
1651                      struct pnfs_layout_segment *lseg,
1652                      struct nfs_commit_info *cinfo)
1653 {
1654         struct nfs_page *first = nfs_list_entry(head->next);
1655         struct inode *inode = d_inode(first->wb_context->dentry);
1656
1657         /* Set up the RPC argument and reply structs
1658          * NB: take care not to mess about with data->commit et al. */
1659
1660         list_splice_init(head, &data->pages);
1661
1662         data->inode       = inode;
1663         data->cred        = first->wb_context->cred;
1664         data->lseg        = lseg; /* reference transferred */
1665         /* only set lwb for pnfs commit */
1666         if (lseg)
1667                 data->lwb = nfs_get_lwb(&data->pages);
1668         data->mds_ops     = &nfs_commit_ops;
1669         data->completion_ops = cinfo->completion_ops;
1670         data->dreq        = cinfo->dreq;
1671
1672         data->args.fh     = NFS_FH(data->inode);
1673         /* Note: we always request a commit of the entire inode */
1674         data->args.offset = 0;
1675         data->args.count  = 0;
1676         data->context     = get_nfs_open_context(first->wb_context);
1677         data->res.fattr   = &data->fattr;
1678         data->res.verf    = &data->verf;
1679         nfs_fattr_init(&data->fattr);
1680 }
1681 EXPORT_SYMBOL_GPL(nfs_init_commit);
1682
1683 void nfs_retry_commit(struct list_head *page_list,
1684                       struct pnfs_layout_segment *lseg,
1685                       struct nfs_commit_info *cinfo,
1686                       u32 ds_commit_idx)
1687 {
1688         struct nfs_page *req;
1689
1690         while (!list_empty(page_list)) {
1691                 req = nfs_list_entry(page_list->next);
1692                 nfs_list_remove_request(req);
1693                 nfs_mark_request_commit(req, lseg, cinfo, ds_commit_idx);
1694                 if (!cinfo->dreq)
1695                         nfs_clear_page_commit(req->wb_page);
1696                 nfs_unlock_and_release_request(req);
1697         }
1698 }
1699 EXPORT_SYMBOL_GPL(nfs_retry_commit);
1700
1701 static void
1702 nfs_commit_resched_write(struct nfs_commit_info *cinfo,
1703                 struct nfs_page *req)
1704 {
1705         __set_page_dirty_nobuffers(req->wb_page);
1706 }
1707
1708 /*
1709  * Commit dirty pages
1710  */
1711 static int
1712 nfs_commit_list(struct inode *inode, struct list_head *head, int how,
1713                 struct nfs_commit_info *cinfo)
1714 {
1715         struct nfs_commit_data  *data;
1716
1717         /* another commit raced with us */
1718         if (list_empty(head))
1719                 return 0;
1720
1721         data = nfs_commitdata_alloc(true);
1722
1723         /* Set up the argument struct */
1724         nfs_init_commit(data, head, NULL, cinfo);
1725         atomic_inc(&cinfo->mds->rpcs_out);
1726         return nfs_initiate_commit(NFS_CLIENT(inode), data, NFS_PROTO(inode),
1727                                    data->mds_ops, how, 0);
1728 }
1729
1730 int nfs_commit_file(struct file *file, struct nfs_write_verifier *verf)
1731 {
1732         struct inode *inode = file_inode(file);
1733         struct nfs_open_context *open;
1734         struct nfs_commit_info cinfo;
1735         struct nfs_page *req;
1736         int ret;
1737
1738         open = get_nfs_open_context(nfs_file_open_context(file));
1739         req  = nfs_create_request(open, NULL, NULL, 0, i_size_read(inode));
1740         if (IS_ERR(req)) {
1741                 ret = PTR_ERR(req);
1742                 goto out_put;
1743         }
1744
1745         nfs_init_cinfo_from_inode(&cinfo, inode);
1746
1747         memcpy(&req->wb_verf, verf, sizeof(struct nfs_write_verifier));
1748         nfs_request_add_commit_list(req, &cinfo);
1749         ret = nfs_commit_inode(inode, FLUSH_SYNC);
1750         if (ret > 0)
1751                 ret = 0;
1752
1753         nfs_free_request(req);
1754 out_put:
1755         put_nfs_open_context(open);
1756         return ret;
1757 }
1758 EXPORT_SYMBOL_GPL(nfs_commit_file);
1759
1760 /*
1761  * COMMIT call returned
1762  */
1763 static void nfs_commit_done(struct rpc_task *task, void *calldata)
1764 {
1765         struct nfs_commit_data  *data = calldata;
1766
1767         dprintk("NFS: %5u nfs_commit_done (status %d)\n",
1768                                 task->tk_pid, task->tk_status);
1769
1770         /* Call the NFS version-specific code */
1771         NFS_PROTO(data->inode)->commit_done(task, data);
1772 }
1773
1774 static void nfs_commit_release_pages(struct nfs_commit_data *data)
1775 {
1776         struct nfs_page *req;
1777         int status = data->task.tk_status;
1778         struct nfs_commit_info cinfo;
1779         struct nfs_server *nfss;
1780
1781         while (!list_empty(&data->pages)) {
1782                 req = nfs_list_entry(data->pages.next);
1783                 nfs_list_remove_request(req);
1784                 if (req->wb_page)
1785                         nfs_clear_page_commit(req->wb_page);
1786
1787                 dprintk("NFS:       commit (%s/%llu %d@%lld)",
1788                         req->wb_context->dentry->d_sb->s_id,
1789                         (unsigned long long)NFS_FILEID(d_inode(req->wb_context->dentry)),
1790                         req->wb_bytes,
1791                         (long long)req_offset(req));
1792                 if (status < 0) {
1793                         nfs_context_set_write_error(req->wb_context, status);
1794                         if (req->wb_page)
1795                                 nfs_inode_remove_request(req);
1796                         dprintk_cont(", error = %d\n", status);
1797                         goto next;
1798                 }
1799
1800                 /* Okay, COMMIT succeeded, apparently. Check the verifier
1801                  * returned by the server against all stored verfs. */
1802                 if (!nfs_write_verifier_cmp(&req->wb_verf, &data->verf.verifier)) {
1803                         /* We have a match */
1804                         if (req->wb_page)
1805                                 nfs_inode_remove_request(req);
1806                         dprintk_cont(" OK\n");
1807                         goto next;
1808                 }
1809                 /* We have a mismatch. Write the page again */
1810                 dprintk_cont(" mismatch\n");
1811                 nfs_mark_request_dirty(req);
1812                 set_bit(NFS_CONTEXT_RESEND_WRITES, &req->wb_context->flags);
1813         next:
1814                 nfs_unlock_and_release_request(req);
1815         }
1816         nfss = NFS_SERVER(data->inode);
1817         if (atomic_long_read(&nfss->writeback) < NFS_CONGESTION_OFF_THRESH)
1818                 clear_bdi_congested(&nfss->backing_dev_info, BLK_RW_ASYNC);
1819
1820         nfs_init_cinfo(&cinfo, data->inode, data->dreq);
1821         nfs_commit_end(cinfo.mds);
1822 }
1823
1824 static void nfs_commit_release(void *calldata)
1825 {
1826         struct nfs_commit_data *data = calldata;
1827
1828         data->completion_ops->completion(data);
1829         nfs_commitdata_release(calldata);
1830 }
1831
1832 static const struct rpc_call_ops nfs_commit_ops = {
1833         .rpc_call_prepare = nfs_commit_prepare,
1834         .rpc_call_done = nfs_commit_done,
1835         .rpc_release = nfs_commit_release,
1836 };
1837
1838 static const struct nfs_commit_completion_ops nfs_commit_completion_ops = {
1839         .completion = nfs_commit_release_pages,
1840         .resched_write = nfs_commit_resched_write,
1841 };
1842
1843 int nfs_generic_commit_list(struct inode *inode, struct list_head *head,
1844                             int how, struct nfs_commit_info *cinfo)
1845 {
1846         int status;
1847
1848         status = pnfs_commit_list(inode, head, how, cinfo);
1849         if (status == PNFS_NOT_ATTEMPTED)
1850                 status = nfs_commit_list(inode, head, how, cinfo);
1851         return status;
1852 }
1853
1854 int nfs_commit_inode(struct inode *inode, int how)
1855 {
1856         LIST_HEAD(head);
1857         struct nfs_commit_info cinfo;
1858         int may_wait = how & FLUSH_SYNC;
1859         int error = 0;
1860         int res;
1861
1862         nfs_init_cinfo_from_inode(&cinfo, inode);
1863         nfs_commit_begin(cinfo.mds);
1864         res = nfs_scan_commit(inode, &head, &cinfo);
1865         if (res)
1866                 error = nfs_generic_commit_list(inode, &head, how, &cinfo);
1867         nfs_commit_end(cinfo.mds);
1868         if (error < 0)
1869                 goto out_error;
1870         if (!may_wait)
1871                 goto out_mark_dirty;
1872         error = wait_on_commit(cinfo.mds);
1873         if (error < 0)
1874                 return error;
1875         return res;
1876 out_error:
1877         res = error;
1878         /* Note: If we exit without ensuring that the commit is complete,
1879          * we must mark the inode as dirty. Otherwise, future calls to
1880          * sync_inode() with the WB_SYNC_ALL flag set will fail to ensure
1881          * that the data is on the disk.
1882          */
1883 out_mark_dirty:
1884         __mark_inode_dirty(inode, I_DIRTY_DATASYNC);
1885         return res;
1886 }
1887 EXPORT_SYMBOL_GPL(nfs_commit_inode);
1888
1889 int nfs_write_inode(struct inode *inode, struct writeback_control *wbc)
1890 {
1891         struct nfs_inode *nfsi = NFS_I(inode);
1892         int flags = FLUSH_SYNC;
1893         int ret = 0;
1894
1895         /* no commits means nothing needs to be done */
1896         if (!nfsi->commit_info.ncommit)
1897                 return ret;
1898
1899         if (wbc->sync_mode == WB_SYNC_NONE) {
1900                 /* Don't commit yet if this is a non-blocking flush and there
1901                  * are a lot of outstanding writes for this mapping.
1902                  */
1903                 if (nfsi->commit_info.ncommit <= (nfsi->nrequests >> 1))
1904                         goto out_mark_dirty;
1905
1906                 /* don't wait for the COMMIT response */
1907                 flags = 0;
1908         }
1909
1910         ret = nfs_commit_inode(inode, flags);
1911         if (ret >= 0) {
1912                 if (wbc->sync_mode == WB_SYNC_NONE) {
1913                         if (ret < wbc->nr_to_write)
1914                                 wbc->nr_to_write -= ret;
1915                         else
1916                                 wbc->nr_to_write = 0;
1917                 }
1918                 return 0;
1919         }
1920 out_mark_dirty:
1921         __mark_inode_dirty(inode, I_DIRTY_DATASYNC);
1922         return ret;
1923 }
1924 EXPORT_SYMBOL_GPL(nfs_write_inode);
1925
1926 /*
1927  * Wrapper for filemap_write_and_wait_range()
1928  *
1929  * Needed for pNFS in order to ensure data becomes visible to the
1930  * client.
1931  */
1932 int nfs_filemap_write_and_wait_range(struct address_space *mapping,
1933                 loff_t lstart, loff_t lend)
1934 {
1935         int ret;
1936
1937         ret = filemap_write_and_wait_range(mapping, lstart, lend);
1938         if (ret == 0)
1939                 ret = pnfs_sync_inode(mapping->host, true);
1940         return ret;
1941 }
1942 EXPORT_SYMBOL_GPL(nfs_filemap_write_and_wait_range);
1943
1944 /*
1945  * flush the inode to disk.
1946  */
1947 int nfs_wb_all(struct inode *inode)
1948 {
1949         int ret;
1950
1951         trace_nfs_writeback_inode_enter(inode);
1952
1953         ret = filemap_write_and_wait(inode->i_mapping);
1954         if (ret)
1955                 goto out;
1956         ret = nfs_commit_inode(inode, FLUSH_SYNC);
1957         if (ret < 0)
1958                 goto out;
1959         pnfs_sync_inode(inode, true);
1960         ret = 0;
1961
1962 out:
1963         trace_nfs_writeback_inode_exit(inode, ret);
1964         return ret;
1965 }
1966 EXPORT_SYMBOL_GPL(nfs_wb_all);
1967
1968 int nfs_wb_page_cancel(struct inode *inode, struct page *page)
1969 {
1970         struct nfs_page *req;
1971         int ret = 0;
1972
1973         wait_on_page_writeback(page);
1974
1975         /* blocking call to cancel all requests and join to a single (head)
1976          * request */
1977         req = nfs_lock_and_join_requests(page, false);
1978
1979         if (IS_ERR(req)) {
1980                 ret = PTR_ERR(req);
1981         } else if (req) {
1982                 /* all requests from this page have been cancelled by
1983                  * nfs_lock_and_join_requests, so just remove the head
1984                  * request from the inode / page_private pointer and
1985                  * release it */
1986                 nfs_inode_remove_request(req);
1987                 nfs_unlock_and_release_request(req);
1988         }
1989
1990         return ret;
1991 }
1992
1993 /*
1994  * Write back all requests on one page - we do this before reading it.
1995  */
1996 int nfs_wb_single_page(struct inode *inode, struct page *page, bool launder)
1997 {
1998         loff_t range_start = page_file_offset(page);
1999         loff_t range_end = range_start + (loff_t)(PAGE_SIZE - 1);
2000         struct writeback_control wbc = {
2001                 .sync_mode = WB_SYNC_ALL,
2002                 .nr_to_write = 0,
2003                 .range_start = range_start,
2004                 .range_end = range_end,
2005         };
2006         int ret;
2007
2008         trace_nfs_writeback_page_enter(inode);
2009
2010         for (;;) {
2011                 wait_on_page_writeback(page);
2012                 if (clear_page_dirty_for_io(page)) {
2013                         ret = nfs_writepage_locked(page, &wbc, launder);
2014                         if (ret < 0)
2015                                 goto out_error;
2016                         continue;
2017                 }
2018                 ret = 0;
2019                 if (!PagePrivate(page))
2020                         break;
2021                 ret = nfs_commit_inode(inode, FLUSH_SYNC);
2022                 if (ret < 0)
2023                         goto out_error;
2024         }
2025 out_error:
2026         trace_nfs_writeback_page_exit(inode, ret);
2027         return ret;
2028 }
2029
2030 #ifdef CONFIG_MIGRATION
2031 int nfs_migrate_page(struct address_space *mapping, struct page *newpage,
2032                 struct page *page, enum migrate_mode mode)
2033 {
2034         /*
2035          * If PagePrivate is set, then the page is currently associated with
2036          * an in-progress read or write request. Don't try to migrate it.
2037          *
2038          * FIXME: we could do this in principle, but we'll need a way to ensure
2039          *        that we can safely release the inode reference while holding
2040          *        the page lock.
2041          */
2042         if (PagePrivate(page))
2043                 return -EBUSY;
2044
2045         if (!nfs_fscache_release_page(page, GFP_KERNEL))
2046                 return -EBUSY;
2047
2048         return migrate_page(mapping, newpage, page, mode);
2049 }
2050 #endif
2051
2052 int __init nfs_init_writepagecache(void)
2053 {
2054         nfs_wdata_cachep = kmem_cache_create("nfs_write_data",
2055                                              sizeof(struct nfs_pgio_header),
2056                                              0, SLAB_HWCACHE_ALIGN,
2057                                              NULL);
2058         if (nfs_wdata_cachep == NULL)
2059                 return -ENOMEM;
2060
2061         nfs_wdata_mempool = mempool_create_slab_pool(MIN_POOL_WRITE,
2062                                                      nfs_wdata_cachep);
2063         if (nfs_wdata_mempool == NULL)
2064                 goto out_destroy_write_cache;
2065
2066         nfs_cdata_cachep = kmem_cache_create("nfs_commit_data",
2067                                              sizeof(struct nfs_commit_data),
2068                                              0, SLAB_HWCACHE_ALIGN,
2069                                              NULL);
2070         if (nfs_cdata_cachep == NULL)
2071                 goto out_destroy_write_mempool;
2072
2073         nfs_commit_mempool = mempool_create_slab_pool(MIN_POOL_COMMIT,
2074                                                       nfs_cdata_cachep);
2075         if (nfs_commit_mempool == NULL)
2076                 goto out_destroy_commit_cache;
2077
2078         /*
2079          * NFS congestion size, scale with available memory.
2080          *
2081          *  64MB:    8192k
2082          * 128MB:   11585k
2083          * 256MB:   16384k
2084          * 512MB:   23170k
2085          *   1GB:   32768k
2086          *   2GB:   46340k
2087          *   4GB:   65536k
2088          *   8GB:   92681k
2089          *  16GB:  131072k
2090          *
2091          * This allows larger machines to have larger/more transfers.
2092          * Limit the default to 256M
2093          */
2094         nfs_congestion_kb = (16*int_sqrt(totalram_pages)) << (PAGE_SHIFT-10);
2095         if (nfs_congestion_kb > 256*1024)
2096                 nfs_congestion_kb = 256*1024;
2097
2098         return 0;
2099
2100 out_destroy_commit_cache:
2101         kmem_cache_destroy(nfs_cdata_cachep);
2102 out_destroy_write_mempool:
2103         mempool_destroy(nfs_wdata_mempool);
2104 out_destroy_write_cache:
2105         kmem_cache_destroy(nfs_wdata_cachep);
2106         return -ENOMEM;
2107 }
2108
2109 void nfs_destroy_writepagecache(void)
2110 {
2111         mempool_destroy(nfs_commit_mempool);
2112         kmem_cache_destroy(nfs_cdata_cachep);
2113         mempool_destroy(nfs_wdata_mempool);
2114         kmem_cache_destroy(nfs_wdata_cachep);
2115 }
2116
2117 static const struct nfs_rw_ops nfs_rw_write_ops = {
2118         .rw_mode                = FMODE_WRITE,
2119         .rw_alloc_header        = nfs_writehdr_alloc,
2120         .rw_free_header         = nfs_writehdr_free,
2121         .rw_done                = nfs_writeback_done,
2122         .rw_result              = nfs_writeback_result,
2123         .rw_initiate            = nfs_initiate_write,
2124 };