On Thu, Oct 20, 2022 at 12:58:34PM -0400, Sweet Tea Dorminy wrote: > From: Omar Sandoval <osandov@xxxxxxxxxxx> > > Add in the necessary calls to encrypt and decrypt data to achieve > encryption of normal data. > > Since these are all page cache pages being encrypted, we can't encrypt > them in place and must encrypt/decrypt into a new page. fscrypt provides a pool > of pages for this purpose, which it calls bounce pages. For IO of > encrypted data, we use a bounce page for the actual IO, and > encrypt/decrypt from/to the actual page cache page on either side of the > IO. > > Signed-off-by: Omar Sandoval <osandov@xxxxxxxxxxx> > Signed-off-by: Sweet Tea Dorminy <sweettea-kernel@xxxxxxxxxx> > --- > fs/btrfs/extent_io.c | 56 ++++++++++++++++++++++++++++++++++++----- > fs/btrfs/file-item.c | 9 +++++-- > fs/btrfs/fscrypt.c | 32 ++++++++++++++++++++++- > fs/btrfs/tree-checker.c | 11 +++++--- > 4 files changed, 96 insertions(+), 12 deletions(-) > > diff --git a/fs/btrfs/extent_io.c b/fs/btrfs/extent_io.c > index 4e4f28387ace..94d0636aafd0 100644 > --- a/fs/btrfs/extent_io.c > +++ b/fs/btrfs/extent_io.c > @@ -113,6 +113,7 @@ static void submit_one_bio(struct btrfs_bio_ctrl *bio_ctrl) > { > struct bio *bio; > struct bio_vec *bv; > + struct page *first_page; > struct inode *inode; > int mirror_num; > > @@ -121,13 +122,17 @@ static void submit_one_bio(struct btrfs_bio_ctrl *bio_ctrl) > > bio = bio_ctrl->bio; > bv = bio_first_bvec_all(bio); > - inode = bv->bv_page->mapping->host; > + first_page = bio_first_page_all(bio); > + if (fscrypt_is_bounce_page(first_page)) > + inode = fscrypt_pagecache_page(first_page)->mapping->host; > + else > + inode = first_page->mapping->host; > mirror_num = bio_ctrl->mirror_num; > > /* Caller should ensure the bio has at least some range added */ > ASSERT(bio->bi_iter.bi_size); > > - btrfs_bio(bio)->file_offset = page_offset(bv->bv_page) + bv->bv_offset; > + btrfs_bio(bio)->file_offset = page_offset(first_page) + bv->bv_offset; > > if (!is_data_inode(inode)) > btrfs_submit_metadata_bio(inode, bio, mirror_num); > @@ -1014,9 +1019,19 @@ static void end_bio_extent_writepage(struct btrfs_bio *bbio) > ASSERT(!bio_flagged(bio, BIO_CLONED)); > bio_for_each_segment_all(bvec, bio, iter_all) { > struct page *page = bvec->bv_page; > - struct inode *inode = page->mapping->host; > - struct btrfs_fs_info *fs_info = btrfs_sb(inode->i_sb); > - const u32 sectorsize = fs_info->sectorsize; > + struct inode *inode; > + struct btrfs_fs_info *fs_info; > + u32 sectorsize; > + struct page *bounce_page = NULL; > + > + if (fscrypt_is_bounce_page(page)) { > + bounce_page = page; > + page = fscrypt_pagecache_page(bounce_page); > + } > + > + inode = page->mapping->host; > + fs_info = btrfs_sb(inode->i_sb); > + sectorsize = fs_info->sectorsize; > > /* Our read/write should always be sector aligned. */ > if (!IS_ALIGNED(bvec->bv_offset, sectorsize)) > @@ -1037,7 +1052,7 @@ static void end_bio_extent_writepage(struct btrfs_bio *bbio) > } > > end_extent_writepage(page, error, start, end); > - > + fscrypt_free_bounce_page(bounce_page); > btrfs_page_clear_writeback(fs_info, page, start, bvec->bv_len); > } > > @@ -1229,6 +1244,17 @@ static void end_bio_extent_readpage(struct btrfs_bio *bbio) > } > } > > + if (likely(uptodate)) { > + if (fscrypt_inode_uses_fs_layer_crypto(inode)) { > + int ret = fscrypt_decrypt_pagecache_blocks(page, > + bvec->bv_len, > + bvec->bv_offset); > + if (ret) { > + error_bitmap = (unsigned int) -1; > + uptodate = false; > + } Messed up indenting. > + } > + } > if (likely(uptodate)) { > loff_t i_size = i_size_read(inode); > pgoff_t end_index = i_size >> PAGE_SHIFT; > @@ -1563,11 +1589,29 @@ static int submit_extent_page(blk_opf_t opf, > bool force_bio_submit) > { > int ret = 0; > + struct page *bounce_page = NULL; > struct btrfs_inode *inode = BTRFS_I(page->mapping->host); > unsigned int cur = pg_offset; > > ASSERT(bio_ctrl); > > + if ((opf & REQ_OP_MASK) == REQ_OP_WRITE && > + fscrypt_inode_uses_fs_layer_crypto(&inode->vfs_inode)) { > + gfp_t gfp_flags = GFP_NOFS; > + > + if (bio_ctrl->bio) > + gfp_flags = GFP_NOWAIT | __GFP_NOWARN; > + else > + gfp_flags = GFP_NOFS; > + bounce_page = fscrypt_encrypt_pagecache_blocks(page, size, > + pg_offset, > + gfp_flags); > + if (IS_ERR(bounce_page)) > + return PTR_ERR(bounce_page); > + page = bounce_page; > + pg_offset = 0; > + } > + > ASSERT(pg_offset < PAGE_SIZE && size <= PAGE_SIZE && > pg_offset + size <= PAGE_SIZE); > > diff --git a/fs/btrfs/file-item.c b/fs/btrfs/file-item.c > index 598dff14078f..e4ec6a97a85c 100644 > --- a/fs/btrfs/file-item.c > +++ b/fs/btrfs/file-item.c > @@ -676,8 +676,13 @@ blk_status_t btrfs_csum_one_bio(struct btrfs_inode *inode, struct bio *bio, > shash->tfm = fs_info->csum_shash; > > bio_for_each_segment(bvec, bio, iter) { > - if (use_page_offsets) > - offset = page_offset(bvec.bv_page) + bvec.bv_offset; > + if (use_page_offsets) { > + struct page *page = bvec.bv_page; > + > + if (fscrypt_is_bounce_page(page)) > + page = fscrypt_pagecache_page(page); > + offset = page_offset(page) + bvec.bv_offset; > + } > > if (!ordered) { > ordered = btrfs_lookup_ordered_extent(inode, offset); > diff --git a/fs/btrfs/fscrypt.c b/fs/btrfs/fscrypt.c > index 717a9c244306..324436cba989 100644 > --- a/fs/btrfs/fscrypt.c > +++ b/fs/btrfs/fscrypt.c > @@ -175,7 +175,37 @@ static int btrfs_fscrypt_get_extent_context(const struct inode *inode, > size_t *extent_offset, > size_t *extent_length) > { > - return len; > + u64 offset = lblk_num << inode->i_blkbits; > + struct extent_map *em; > + > + /* Since IO must be in progress on this extent, this must succeed */ > + em = btrfs_get_extent(BTRFS_I(inode), NULL, 0, offset, PAGE_SIZE); If the bulk of the code is in the normal case, you need to invert the condition. So instead if (!em) return -EINVAL // the rest of hte code at a normal indentation. Thanks, Josef