Repository navigation
Update our CI runners to the newest FreeBSD 15.1 RELEASE - #18667
Merged
Merged
Conversation
Signed-off-by: Christos Longros
amotin
approved these changes
Jun 15, 2026
tonyhutter
approved these changes
Jun 15, 2026
4 of 13 tasks
lundman
pushed a commit
to openzfsonosx/openzfs-fork
that referenced
this pull request
Jul 30, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
lundman
pushed a commit
to openzfsonosx/openzfs-fork
that referenced
this pull request
Jul 30, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 12, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696
EchterAgo
pushed a commit
to EchterAgo/zfs
that referenced
this pull request
Aug 15, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
tonyhutter
pushed a commit
to tonyhutter/zfs
that referenced
this pull request
Aug 20, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696
tonyhutter
pushed a commit
that referenced
this pull request
Aug 21, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter
bugclerk
pushed a commit
to truenas/zfs
that referenced
this pull request
Aug 26, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter (cherry picked from commit 52be04b)
bugclerk
pushed a commit
to truenas/zfs
that referenced
this pull request
Aug 26, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696 (cherry picked from commit 8f04a5c)
bugclerk
pushed a commit
to truenas/zfs
that referenced
this pull request
Aug 26, 2026
Signed-off-by: Christos LongrosReviewed-by: Alexander Motin Reviewed-by: Tony Hutter (cherry picked from commit fa7e71e)
bugclerk
pushed a commit
to truenas/zfs
that referenced
this pull request
Aug 26, 2026
Our CI runners moved to FreeBSD 15.1 in 0a4b597 (openzfs#18667), but the README still lists 15.0. Update it to match the CI version. Reviewed-by: Brian BehlendorfReviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes openzfs#18696 (cherry picked from commit 5599bb7)
creatorcary
pushed a commit
to truenas/zfs
that referenced
this pull request
Aug 26, 2026
…431) * CI: FreeBSD 15.1 STABLE Update the freebsd15-1s builder to the released STABLE image. Reviewed-by: Alexander MotinSigned-off-by: Brian Behlendorf Closes #18524 * CI: Fix 99.99 META version We have an option in zfs-qemu-packages to test against a specific kernel version. However, qemu-3-deps.sh was incorrectly hard coded to look at $2 for a kernel version argument (which could come in $2 or $3 depending on if --poweroff was also passed). This caused the CI to incorrectly edit META with a max supported kernel version of 99.99 when we didn't want that. Fix this by looking at all the arguments for something that looks like a kernel version and set that as the kernel max in META. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18526 Closes #18531 * CI: Remove deprecated Fedora 42 Fedora 42 was deprecated on May 13 2026. Remove it from CI tests. Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18545 * CI: Allow testing with a newer GCC on ARM builder Add a text box to specify a custom GCC version (like '16') when running the zfs-arm builder. This allows you to test with a newer GCC than the Ubuntu default. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18540 * CI: remove FreeBSD 13.5 (EOL April 30, 2026) FreeBSD 13.5 and stable/13 reached End-of-Life on April 30, 2026 and no longer receive security support, so they fall outside README.md's stated support policy. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes #18553 * CI: Add Ubuntu 26.04 builder The Ubuntu 26.04 LTS, named "Resolute Raccoon, was released on April 23, 2026. Add to the supported releases in README.md and add a CI builder for it. Reviewed-by: Tino Reichardt Reviewed-by: George Melikov Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18547 * CI: Fix qemu-guest-agent systemd enable The qemu-guest-agent.service for Debian and Ubuntu does not contain an install section which prevents it from being enabled. Add a drop-in override file so it can be enabled and the service started on boot. Reviewed-by: Tino Reichardt Reviewed-by: George Melikov Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18547 * ZTS: zfs_unshare_006_pos.ksh enable usershares Ensure samba usershares are enabled in the CI test environment for the zfs_unshare_006_pos test case. By default they are disabled in the Ubuntu 26.04 LTS and must be enabled. Reviewed-by: Tino Reichardt Reviewed-by: George Melikov Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18547 * CI: Build custom branch from zfs-qemu-packages The zfs-qemu-packages workflow allows us to easily build RPMs for the current branch. However, there can be cases where we want to use the current CI environment to build older releases. This can happen when the VM or runner environment changes, and the older CI doesn't have the updates needed to run with it anymore. This commit adds in a text box to specify a specific branch/tag to build using the current CI environment. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18569 * CI: enable FreeBSD 15.0-RELEASE in matrix Add freebsd15-0r to the FreeBSD presets Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Christos Longros Closes #18561 * CI: skip full CI runs on push events Full CI runs for proposed changes always occur in the PR where the review is done and patch approved. Once merged the full CI is run again using the merged commit. This is somewhat overkill. In the interest of reducing the CI load only run the zloop and checkstyle workflows which are enough to verify the build on the master branch. Push events to forks will continue to trigger a full CI run. Reviewed-by: George Melikov Signed-off-by: Brian Behlendorf Closes #18571 * CI: run full CI when a workflow YAML changes FULL_RUN_REGEX in generate-ci-type.py covered .github/workflows/scripts/ but not the workflow YAML files, so a PR that only edited zfs-qemu.yml got "quick" CI and never tested its own matrix change. Add the YAML files to the list. Reviewed-by: George Melikov Reviewed-by: Brian Behlendorf Signed-off-by: Christos Longros Closes #18577 * .github: update workflows README Describe the current zfs-qemu pipeline, ci_type selection, supported guests, and the code-checking and other auxiliary workflows. Reviewed-by: Brian Behlendorf Signed-off-by: Christos Longros Closes #18590 * CI: Update checkstyle checkout action to v6 The checkstyle workflow was the only one still pinned to actions/checkout@v4; the other workflows already use v6. Bump it to match. Reviewed-by: Tony Hutter Reviewed-by: Brian Behlendorf Signed-off-by: Christos Longros Closes #18600 * CI: Lustre 6.16 kernel compatibility fix (#18602) Almalinux 9,10 kernels now include a backport of Linux commit v6.15-13744-g41cb08555c41 which renames the from_timer() function to timer_container_of(). Apply the upstream Lustre compatibility patch to our builds. This patch should be included in the next Lustre release and can be dropped then. ZFS-CI-Type: quick Signed-off-by: Brian Behlendorf Reviewed-by: Tony Hutter * CI: skip smatch, zloop, and zfs-arm for documentation-only changes Follow-up to #18518, which skipped the qemu matrix on doc-only PRs. zloop, zfs-arm, and smatch are irrelevant to doc-only changes. Reviewed-by: Brian Behlendorf Reviewed-by: Tony Hutter Signed-off-by: Christos Longros Closes #18601 * build: add ZFS_DEBUG Kconfig for copy-builtin ... so we can toggle ZFS debug assertions from the Linux kernel build without having to regenerate the ZFS patch. Update the qemu test script to also set this kernel config. Reviewed-by: Tony Hutter Reviewed-by: Brian Behlendorf Signed-off-by: Timothy Day Co-authored-by: Timothy Day Closes #18595 * CI: apt-get update before purging host packages The package removal ran against a stale package index and failed to fetch a package that had been removed from the repository. Refresh the index first. Reviewed-by: Brian Behlendorf Signed-off-by: Christos Longros Closes #18607 Closes #18609 * CI: add concurrency support to zfs-arm The zfs-arm workflow was the only build/test workflow without a concurrency block, so superseded runs were not cancelled. Reviewed-by: Brian Behlendorf Signed-off-by: Christos Longros Closes #18608 * nvpair: Check for un-terminated strings in packed nvlist Add additional checks to verify a packed string or string array nvpair is terminated. Or more specifically, verify doing a strlen() on the prospective string does not overrun the packed nvlist buffer. Also add additional checks in the libzfs_input_checks test case to verify un-terminated strings, and add in a nvlist ioctl payload fuzz test for good measure. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18604 * Fix the integer type in zfs_ioc_userspace_many() Fix the mismatched type in zfs_ioc_userspace_many() and limit the number of entries returned to 1000. When a size larger than this is requested the response is truncated, zfs_userspace() already correctly handles short responses. Historically, zfs_userspace() has requested 100 entries at a time, this cap allows for 10x larger batch sizes if needed in the future. Reported-by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, Reported-by: and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai Reviewed-by: Alexander Motin Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18615 * sharenfs: Check for invalid characters Check for invalid characters in sharenfs/sharesmb dataset props. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18613 * Fix uninitialized variable warning in vdev_prop_get() Update vdev_prop_get_objid() to set objid on error as the comment in vdev_prop_get() describes. "objid is set to 0 when absent and the few cases that call zap_lookup directly guard against this below." This resolves the following possible uninitialized variable warning. module/zfs/vdev.c: In function ‘vdev_prop_get’: module/zfs/vdev.c:6913:12: error: ‘objid’ may be used uninitialized in this function [-Werror=maybe-uninitialized] Reviewed-by: Alexander Motin Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18616 * Extend dataset zfs_ioc_set_prop() secpolicy When zc->zc_cookie is set this indicates to zfs_ioc_set_prop() that these are received properties and ZPROP_HAS_RECVD will be set on the dataset. This is only done as part of a `zfs receive` so additionally apply the zfs_secpolicy_recv() policy. Individual property checks continue to be handled by zfs_check_settable(). Reviewed-by: Tony Hutter Reviewed-by: Alexander Motin Signed-off-by: Brian Behlendorf Closes #18617 * pam: use open fd instead of path Instead of performing multiple operations on the path name in zfs_key_config_modify_session_counter() open the file once and perform the fchown, fchmod, and openat on the open file handle. Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18618 * Remove /etc/sudoers.d/zfs The smartctl exception in /etc/sudoers.d/zfs doesn't cover devices like NVMe or symlinked devices. Just get rid of it rather than keep maintaining it. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Tony Hutter Closes #18626 * CI: Re-enable CodeQL workflows on push This workflow was disabled 'on push' recently in commit 1916c2c5 to reduce redundant CI runs. However, this check is fairly quick and we want it run regularly against the branches. Enable it. Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18627 * CI: Update CodeQL actions to v4 CodeQL Action v3 has been deprecated and will be retired December 2026. Update codeql.yml to use CodeQL Action v4 and update the runner to ubuntu-24.04. Signed-off-by: Brian Behlendorf Closes #18629 * CI: Increase default RCU stall timeout on Linux When CONFIG_RCU_CPU_STALL_TIMEOUT is configured an RCU stall which exceeds the default timeout will trigger an NMI and panic the VM. Given the heavily virtualized nature of the CI environment we want to make sure to only trigger this due to a real deadlock and not due to over-subscription of the systems resources. This timeout normally defaults to 20-30 seconds and this change increases it to 120 seconds. Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18624 * CI: Add alternative URLs for CentOS stream Fallback to trying the "CentOS Strean Composes" repo for the qcow2 images if the regular URLs fail. The Composes repo contains the daily autobuilt Stream images. Reviewed-by: Brian Behlendorf Signed-off-by: Tony Hutter Closes #18628 * Add additional verification of size fields and strings (#18623) - Check for size fields that convert to smaller integers. - Explicitly terminate bootenv string. - Initialize variables that could be returned in an error case. Reviewed-by: Brian Behlendorf Reviewed-by: Chris Longros Reviewed-by: Alexander Motin Signed-off-by: Tony Hutter Closes #18623 * Fix uninitialized variable warning in zil_parse() This resolves the following possible uninitialized variable warning when building with --enable-code-coverage and gcc 8.5.0. module/zfs/zil.c: In function ‘zil_parse’: module/zfs/zil.c:549:47: warning: ‘end’ may be used uninitialized in this function [-Wmaybe-uninitialized] Reviewed-by: Alexander Motin Signed-off-by: Brian Behlendorf Closes #18633 * ZTS: relax zpool_import_parallel_pos.ksh timing Occasionally in the CI this test will fail because the parallel import took longer than half of the serial time (but still less than the full serial time). Increase the cutoff to 3/4 of the serial time to preserve the intent yet try and avoid these false positive failures. Reviewed-by: Chris Longros Signed-off-by: Brian Behlendorf Closes #18634 * linux: verify stale znodes in legacy fallocate The mode=0 and FALLOC_FL_KEEP_SIZE preallocation path can reach zfs_freesp() directly and call zfs_statvfs() before going through the normal zpl_enter_verify_zp() boundary. When zfs_rezget() tears down a failed SA reload, a stale inode may remain alive in the VFS with z_sa_hdl cleared. The unchecked fallocate path can then reach sa_lookup(zp->z_sa_hdl, ...) through zfs_statvfs() or zfs_freesp() and crash on a NULL SA handle. Use zfs_enter_verify_zp() in zfs_statvfs() so stale znodes are rejected under the teardown lock for both fallocate and statfs. Also wrap the direct zfs_freesp() call in zpl_enter_verify_zp()/zfs_exit() so this path follows the same validation rules as the other Linux ZPL file operations. Fixes: f734301d2267 ("linux: add basic fallocate(mode=0/2) compatibility") Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Co-authored-by: gality369 Closes #18458 * Linux: annotate nested xattr setattr znode locks zfs_setattr() updates both the target znode and its hidden xattr directory when ownership, mode, or project ID changes. The xattr directory uses the same z_acl_lock and z_lock classes as the parent znode, so lockdep reports recursive locking when the second znode's mutexes are acquired. This is a lockdep false positive rather than a real deadlock. attrzp is the target file's hidden xattr directory, and the code does not acquire these znode mutexes in the reverse order. Acquire the attrzp mutexes with mutex_enter_nested() so lockdep treats them as nested. Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Co-authored-by: gality369 Closes #18506 * Linux: avoid znode list lock inversion during resume Lockdep reports a circular locking dependency during mounted filesystem rollback. zfs_resume_fs() walks z_all_znodes under z_znodes_lock and calls zfs_rezget(), which takes the per-object znode hold lock via zfs_znode_hold_enter(). The normal zget path takes these locks in the opposite order. zfs_zget() takes the per-object hold lock before zfs_znode_alloc() inserts the znode on z_all_znodes under z_znodes_lock. Resume can therefore establish z_znodes_lock -> zh_lock while normal lookup creates zh_lock -> z_znodes_lock. Pin the current and next znodes with igrab() while holding the list lock, then drop the list lock before reloading the znode. Existing stale inode handling is preserved, and both the suspended reference and temporary walk reference are released asynchronously. Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Closes #18517 * linux/zpl_super: handle 'source' option directly vfs_parse_fs_param_source() didn't appear until 5.14, and was not backported to kernel.org LTS kernels. It's simple enough that it's easier to just handle it ourselves rather than use a configure check. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18529 * linux: suppress reclaim lockdep in zfs_inactive via rwlock wrappers kswapd can enter zfs_inactive() from inode reclaim while holding fs_reclaim. The z_teardown_inactive_lock still serializes teardown, but the reclaim-thread acquire/release pair can produce a lockdep cycle through zfs_zinactive() and zfs_rmnode(). Add Linux rwlock nolockdep wrappers alongside the existing rwlock macros and use them only for the reclaim-thread z_teardown_inactive_lock acquire/release in zfs_inactive(). Keep the real rwsem semantics unchanged and leave CONFIG_LOCKDEP handling in the platform rwlock layer. Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Closes #18505 * config: show progress output for kernel API checks Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18554 * linux/super: properly apply ro/rw mount option to superblock f5a9e3a622 changed how SB_RDONLY was applied to the new mount in a way that was too simplistic - it only sets readonly on the filesystem if the mount was 'ro', but it never clears it if the mount was 'rw'. This causes the 'rw' option to effectively be ignored, and so the readonly= property wins out. This fixes it by doing it the right way: checking the flags mask to see if it was actually provided as an option at all, and then setting or clearing it as appropriate. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18557 Closes #18563 * Linux 5.6 compat: fix fs_parse API mismatch Added m4 macro to check fs_parse API signature and wrappers. Before 5.6, fs_parse() took a struct fs_parameter_description which wraps the parameter specs with name and enum pointers. From 5.6, the description struct was removed and fs_parse() accepts the fs_parameter_spec directly. Reviewed-by: Rob Norris Reviewed-by: Brian Behlendorf Signed-off-by: tiehexue Closes #18585 * Fix aarch64 build failure by removing earlyclobber (#18532) The UVR macros used "+&w" (read-write + earlyclobber) as the constraint for NEON register operands that are declared as explicit hard-register variables via: register unsigned char wN asm("vN") __attribute__((vector_size(16))); The + modifier implicitly makes the operand also an input (reading the register before the asm runs). The & (earlyclobber) modifier says "this output may be written before all inputs are consumed." Having an earlyclobber output on the same hard-register that is simultaneously an input is a contradiction — GCC 16 now strictly diagnoses this. The fix removes the & from "+&w", yielding "+w". The earlyclobber was both incorrect (contradicts the implicit input) and unnecessary (the physical registers are already hard-bound, so the compiler has no freedom to assign conflicting registers anyway). Issue #18525 Signed-off-by: Brian Behlendorf Co-authored-by: Claude Sonnet 4.6 Reviewed-by: Tony Hutter * Fix "panic: cache_vop_rename: lingering negative entry" A FreeBSD ZFS filesystem with properties "utf8only=on" and "normalization=formD" consistently produces this panic when building the lang/perl-5.42.0 port. A ZFS file system with "utf8only=off" and "normalization=none" works fine. The cause of the panic seems to be incorrectly using the FreeBSD namecache when normalisation is present. This commit adds a predicate to prevent that. Reviewed-by: Brian Behlendorf Signed-off-by: Jan Martin Mikkelsen Closes #18430 * key lookup failure should always return EACCES spa_do_crypt_abd() already maps a missing key to EACCES. However spa_do_crypt_mac_abd(), spa_do_crypt_objset_mac_abd(), and spa_crypt_get_salt() still return the raw spa_keystore_lookup_key() error (ENOENT). This is inconsistent As we want to treat all “no key” failures as a permission failure. Standardize on EACCES for the unloaded-key case. Reviewed-by: Brian Behlendorf Signed-off-by: Alek Pinchuk Closes #18448 * Fix off-by-one in PREVIOUSLY_REDACTED handler that drops last block In send_reader_thread(), the PREVIOUSLY_REDACTED handler computed file_max as MIN(dn->dn_maxblkid, range->end_blkid). dn_maxblkid is an inclusive maximum block ID while range->end_blkid is exclusive (one past the last block). The resulting file_max was then used as an exclusive loop bound, causing the last block of any file (at index dn_maxblkid) to be silently skipped when a PREVIOUSLY_REDACTED range covered the end of the file. The block was never written to the send stream so the receiver kept zeros there. ZFS reported no error because the stream itself was valid; the data was simply absent. Fix: use dn_maxblkid + 1 so file_max is consistently exclusive. Add a regression test (redacted_max_blkid.ksh) that modifies only the last block of a file in one clone, creates a redaction bookmark from it, then sends an unmodified clone incrementally from that bookmark. The PREVIOUSLY_REDACTED path must fill in the last block; the test verifies it is not zeros and matches the original. Reviewed-by: Brian Behlendorf Reviewed-by: Paul Dagnelie Reviewed-by: Reviewed-by: Tony Hutter Signed-off-by: Manoj Joseph Closes #18477 * Avoid flushing unrelated NFS exports on snapshot unmount zfsctl_snapshot_unmount() called exportfs_flush() before every umount attempt to drop NFS export cache references that pin the snapshot mountpoint. The flush has global effect on the host's NFS exports and clients, so paying it on every snapshot unmount (including auto-expire rounds for snapshots that were never NFS-accessed) impacts unrelated snapshots and clients. ZFS cannot invalidate individual export cache entries because the relevant sunrpc cache APIs are exported GPL-only. Defer the global flush so it runs only when the umount has actually failed, then retry once. Snapshots that are not NFS-pinned succeed on the first attempt and never trigger the flush. Reviewed-by: Brian Behlendorf Reviewed-by: Youzhong Yang Signed-off-by: Ameer Hamza Closes #18476 * zfs: annotate nested dd_lock in reservation sync accounting When reservation sync updates a child's reserved space, it rolls the delta into ancestor space accounting while still holding the child's dd_lock. That locking order is intentional, but Linux lockdep sees the ancestor acquisition as recursive because it lacks a nested lock subclass annotation. Teach the reservation-sync space-accounting path to acquire ancestor dd_lock instances with a nested subclass. Keep the existing public interfaces and accounting behavior unchanged by routing only the ancestor rollup through local helpers. Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Signed-off-by: gality369 Closes #18497 * sa: fix sa_add_projid lock ordering sa_add_projid() currently acquires hdl->sa_lock before zp->z_lock. Several same-znode update paths take zp->z_lock and then call sa_update() or sa_bulk_update() on the same SA handle. On Linux, FS_IOC_FSSETXATTR reaches zfs_setattr() through zpl_ioctl_setxattr() without outer inode serialization. This makes the reversed lock order a real ABBA deadlock rather than a lockdep false positive when projid is added to an old-format inode while another thread updates the same znode. Acquire zp->z_lock before hdl->sa_lock in sa_add_projid() to match the existing znode update ordering. Reviewed-by: Brian Behlendorf Signed-off-by: ZhengYuan Huang Co-authored-by: gality369 Closes #18503 * zdb: detect BRT and DDT leaks during block traversal During -b traversal, track BRT and DDT reference counts and report blocks claimed more times than their reference tables account for if it causes claim errors, instead of just asserting it. Also report entries with references not fully consumed by the traversal. Add zdb leaks checks to cloning and dedup tests. This should make sure the pools are in a sane state after completing the functional tests. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18494 * zarcstat: detect attached L2ARC device with no data zarcstat and zarcsummary detected L2ARC presence using the l2_size kstat, which is data held in L2ARC, not whether a cache device is attached. When a cache device was attached but empty (freshly added, or fully evicted): - zarcstat rejected "-f l2*" with "Incompatible field specified!" - zarcsummary printed "L2ARC not detected, skipping section", hiding cumulative I/O history and health counters Expose the existing l2arc_ndev counter as a new kstat l2_dev_count. It is maintained by l2arc_add_vdev() and l2arc_remove_vdev(), so it tracks attachment in real time. Use it in both tools, falling back to l2_size for compatibility with older kernel modules. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Ameer Hamza Closes #18499 * Fix double free for blocks cloned after DDT prune Before this change, for blocks marked with D flag but absent in DDT (pruned from it), zio_ddt_free() fell back to ZIO_STAGE_DVA_FREE without trying ZIO_STAGE_BRT_FREE first. Same time such blocks might be present in BRT, and not handling that would result in double/multiple free. This change makes ZIO_DDT_FREE_PIPELINE include ZIO_FREE_PIPELINE, just adding required ZIO_STAGE_ISSUE_ASYNC and ZIO_STAGE_DDT_FREE, and moves DDT stages before BRT. This way, if the block is found in DDT by zio_ddt_free(), the pipeline is short-circuited to ZIO_INTERLOCK_PIPELINE, similar to what zio_brt_free() does. If not, then BRT is checked, and if also no match, the block is freed. Reviewed-by: Brian Behlendorf Reviewed-by: Rob Norris Signed-off-by: Alexander Motin Closes #18520 * arc: export additional required symbols External consumers of arc_read() need to be able to destroy the returned arc_buf_t. Add the arc_buf_destroy() interface as an exported symbol. Reviewed-by: Alexander Motin Signed-off-by: Brian Behlendorf Closes #18533 * zap_impl: use flex array field for mzap_phys_t.mz_chunks mz_phys_t is always a full-block allocation, with mz_chunks[] as an array over the rest of the block past the header. Recent Linux compiled with CONFIG_UBSAN will complain about this: UBSAN: array-index-out-of-bounds in module/zfs/zap.c:1236:28 index 2 is out of range for type 'mzap_ent_phys_t [1]' The fix is straightforward; simply convert this field to a flex member. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18550 * spl_kvmalloc: remove __GFP_COMP before calling vmalloc() In cb1833023 we stopped using it for KM_VMEM allocations, since its not a valid flag for vmalloc(). However, there's a fallback path for non-KM_VMEM allocations to use vmalloc(), and we need to remove __GFP_COMP there too to avoid a warning. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18558 * FreeBSD: Make it possible to build openzfs.ko with sanitizers Add make options which let one respectively compile the kernel modules with the address sanitizer, memory sanitizer, and undefined behaviour sanitizer enabled. This makes it much easier to run the ZTS with those sanitizers enabled. Reviewed-by: Brian Behlendorf Reviewed-by: Chris Longros Signed-off-by: Mark Johnston Closes #18596 * enforce exact decompressed length for lz4, gzip, and zstd Decompressors must expand a ZFS block to exactly the expected number of bytes. Treat decompression to an unexpected length as failure, so truncated or short output is not accepted as valid decompression. This makes our handling of decompress return values consistent with the decompression functions' APIs. Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Alek Pinchuk Closes #18599 * dsl_scan: close errorscrub cursor on pause If the cursor were ever to actively hold resources, not finalising it would mean leaking those resources whenever the scrub is paused. The cursor is already reinitialized from the stored serialized form if/when it is resumed, so there's nothing we need from the old one, just to release it. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Reviewed-by: Alexander Motin Signed-off-by: Rob Norris Closes #18603 * When reading a vdev label skip libzfs_core_init() There's no need to call libzfs_core_init() when `zdb -l` is used to read a vdev label. Reviewed-by: Brian Behlendorf Signed-off-by: tiehexue Closes #18606 * Simplify dnode_level_is_l2cacheable() We should not dereference through dn_handle->dnh_dnode once we already have a dnode pointer. The result will be the same. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18212 * Remove parent ZIO from dbuf_prefetch() I am not sure why it was added there 10 years ago, but it seems not needed now. According to my tests removing it improves sequential read performance with recordsize=4K by 5-10% by reducing the CPU overhead in prefetcher. Reviewed-by: Brian Behlendorf Reviewed-by: Rob Norris Reviewed-by: Ameer Hamza Reviewed-by: Akash B Signed-off-by: Alexander Motin Closes #18214 * Fix log vdev removal issues When we clear the log, we should clear all the fields, not only zh_log. Otherwise remaining ZIL_REPLAY_NEEDED will prevent the vdev removal. Handle it also from the other side, when zh_log is already cleared, while zh_flags is not. spa_vdev_remove_log() asserts that allocated space on removed log device is zero. While it should be so in perfect world, it might be not if space leaked at any point. Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18277 * ZVOL: Add encryption key check for block cloning Somehow during block cloning porting from file systems was missed the check for identical encryption keys. As result, blocks cloned between unrelated ZVOLs produced authentication errors on later reads. Having same or different encryption root does not matter. This patch copies dmu_objset_crypto_key_equal() call from FS side. Reviewed-by: Ameer Hamza Reviewed-by: Brian Behlendorf Signed-off-by: Alexander Motin Closes #18315 * abd: Fix stats asymmetry in case of Direct I/O abd_alloc_from_pages() does not call abd_update_scatter_stats(), since memory is not really allocated there. But abd_free_scatter() called by abd_free() does. It causes negative overflow of some ABD and possibly ARC counters. Reviewed-by: Brian Behlendorf Reviewed-by: Rob Norris Signed-off-by: Alexander Motin Closes #18390 * Tag zfs-2.4.3 META file and changelog updated. Signed-off-by: Tony Hutter * Constify some rrd_*() functions These don't modify the db, so just constify them while we're in the area. Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Reviewed-by: Chris Longros Signed-off-by: Kyle Evans * Add dbrrd_latest_time() to grab the latest timestamp in the db Returns 0 if the database is empty, otherwise it returns the highest value of the minutely db. dbrrd_add() will already enforce the property that these are monotonically increasing, so we won't try to second-guess it. Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Reviewed-by: Chris Longros Signed-off-by: Kyle Evans * freebsd: set mnt_time on the rootfs at mountroot time FreeBSD's vfs_mountroot() will collect `mnt_time` from every filesystem that we mounted and use the highest timestamp as a source for the system time if we didn't get anything from an attached RTC. Use the rrd mechanism added to gather up a notion of the latest time and set it on mnt_time. If the timestamp db is empty, we just fallback to the uberblock timestamp and hope that that is in the right ballpark. Relevant: FreeBSD PR254058[0] reporting the problem downstream [0] https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=254058 Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Reviewed-by: Chris Longros Signed-off-by: Kyle Evans * zio_ddt_write: compute have_dvas after taking dde_io_lock In zio_ddt_write(), have_dvas and is_ganged were computed before dde_io_lock was taken. A concurrent zio_ddt_child_write_done() error path calls ddt_phys_unextend() under dde_io_lock, which can zero DVA[0] while another thread is between computing have_dvas and taking dde_io_lock. That thread then uses the stale have_dvas=1 to call ddt_bp_fill(), copying the zeroed DVA into the BP. A zero DVA resolves as a hole, producing blocks that read back as zeros with no checksum error (silent data corruption). Fix by moving have_dvas and is_ganged computation to after dde_io_lock is taken, so they always reflect the current state of dde->dde_phys. Regression introduced by a41ef36858 ("DDT: Reduce global DDT lock scope during writes"). Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Co-authored-by: Saju Palayur Signed-off-by: Saju Palayur Closes #18366 Closes #18544 (cherry picked from commit 6fb72fda0f60d9efb591e320f83f78b19ec451cc) (cherry picked from commit 0a07efe3283df42db41a2060dc3ae0c455a7c056) * ZTS: Pass dec instead of hex to mknod On Ubuntu 26.04 the default mknod command returns an error when provided the major and minor numbers in hex. Switch to passing decimal values. Reviewed-by: Tino Reichardt Reviewed-by: George Melikov Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18547 * ZTS: statx_dioalign.ksh update to stride_dd The uutils 0.8.0 version of dd appears to diverge from GNU behavior and does not fail when an unaligned write O_DIRECT write is issued. Update the test case to use stride_dd which is provided by the ZTS so the expected syscall behavior can be verified. Reviewed-by: Tino Reichardt Reviewed-by: George Melikov Reviewed-by: Tony Hutter Signed-off-by: Brian Behlendorf Closes #18547 * ZTS: delegate: add test for send sub-permissions Regular send and raw send are actually separate operations with separate permissions. This adds a test to test the combinations properly using the existing permission test infrastructure. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18672 (cherry picked from commit 4d1d00f9fe0c87b2334613a0efaa758275f938b8) * ZTS: remove send_delegation tests These tests are doing the same tests as delegate/zfs_allow_send, and are hard to follow and maintain. There's no need for them now, so drop them. Sponsored-by: TrueNAS Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18672 (cherry picked from commit 562b96ced9f28b8517913e5e9f7eaf1686db7cd0) * ZTS: delegate: add encryption option for test fixture datasets The delegate test framework doesn't care about the encryption status of the dataset under test, so by adding an option to create with encryption the framework can be used to check encryption-related permissions without any further fanfare. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18673 (cherry picked from commit 8303a36488da79c13d0fcca4365d71d5180407c3) * ZTS: delegate: check send permissions on encrypted datasets Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18673 (cherry picked from commit bce9a8ef7d0b4c1b8e323ef2b045379177c20410) * ZTS: delegate: test send:encrypted Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18673 (cherry picked from commit 166a6672502c6398b3ef549d4a17f113f5cb2e8d) * zfs_secpolicy_send: lift checks to common function for both The permissions checks for send are a little involved because different permissions grant different abilities, and there's two ways to initiate a send. This lifts the common permissions checks into a single function, and ensures that we maintain a single dataset hold across all checks. This will become important in the next commit when we need to check a specific dataset property as part of the permission check. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18673 (cherry picked from commit f0d69e6b16d93ab49f1914a29e64d5df6e4f7bc2) * delegate: add 'send:encrypted' permission send:encrypted is like send:raw, but only permits encrypted datasets to be sent - raw send is not permitted for unencrypted datasets. This commit creates the permission, wires it up, and adds the check for it in zfs_secpolicy_send_impl(), if it is the last send permission standing, the dataset is checked for its encryption state. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #18673 (cherry picked from commit 97b9ba7a982e36d39a3cf7db271da2fab110769d) * zbookmark_compare: handle "marker" bookmarks with negative levels "Marker" bookmarks (those with zb_level == ZB_ROOT_LEVEL, ZB_ZIL_LEVEL or ZB_DNODE_LEVEL) represent valid blocks, but are associated with a dataset directly rather than with a specific object within it. They end up on bookmark lists during scan prefetch, and so need to be sorted ahead of any "true" object blocks. The problem is that for negative levels, BP_SPANB produces a negative shift, which is not legal C. Fortunately the results are used only for comparison, so the worst possible behaviour in a forgiving compilation environment is a mis-sort, which for the scan/traverse cases, means that we haven't prefetched certain metadata before we actually need it. But there _is_ UB in there, and UBSAN does rightly complain. Here we fix all this by handling these bookmarks directly - sorting them ahead of "true" object blocks, which is usually what scan/traverse will prefer. And we don't do any interesting math on these bookmarks, so we sidestep the whole UB thing. Sponsored-by: TrueNAS Reviewed-by: Alexander Motin Reviewed-by: Brian Behlendorf Signed-off-by: Rob Norris Closes #14777 Closes #18652 * arc: add a few invariant checks in release builds Convert a couple ASSERTs invariants to VERIFYs to enforce them in release builds to be able to root-case #18782 kernel panic, whenever it happens again. Reviewed-by: Brian Behlendorf Signed-off-by: Andriy Tkachuk Closes #18840 (cherry picked from commit 023d44b9ef68f1eff6b97d98c6a16cdb4b93cf76) * CI: Have zfs-build-packages workflow build tarballs on Alma (#18662) Previously, zfs-build-packages would only build source tarballs on Fedora due to problems with building them on RHEL 7. That's a relic of the past now, as we haven't supported RHEL 7 since it went EOL in 2024. With this change, we now build the tarballs on both Alma and Fedora. Signed-off-by: Tony Hutter Reviewed-by: Olaf Faaland Reviewed-by: Chris Longros * Update our CI runners to the newest FreeBSD 15.1 RELEASE (#18667) Signed-off-by: Christos Longros Reviewed-by: Alexander Motin Reviewed-by: Tony Hutter * Linux 7.1 compat: META (#18682) Update the META file to reflect compatibility with the 7.1 kernel. Signed-off-by: Tony Hutter Signed-off-by: Rob Norris Reviewed-by: Chris Longros * Fix handling of _PC_HAS_HIDDENSYSTEM for FreeBSD The hidden and system flags are only supported for ZFS pools if the z_use_fuids is true. Fix zfs_freebsd_pathconf() to check this. Reviewed-by: Alexander Motin Signed-off-by: Rick Macklem Closes #18688 * zfs_ioctl: fix EBUSY race between quota queries and mount zfsvfs_hold() fell back to zfsvfs_create() -> dmu_objset_own() (exclusive) for unmounted datasets. A concurrent zfs_domount() also calls dmu_objset_own(), causing EBUSY on the same dataset. Introduce zfsvfs_create_hold() using dmu_objset_hold() (shared hold) instead. Shared holds do not conflict with exclusive owns, eliminating the race. The release path (zfsvfs_rele, zfsvfs_create_impl error) uses dmu_objset_ds()->ds_owner to determine whether to disown or rele, avoiding the need for an extra flag in zfsvfs_t. Added tests userspace_005, groupspace_005, projectspace_006 (50 iter race test). Reviewed-by: Brian Behlendorf Reviewed-by: Tony Hutter Signed-off-by: HeonJe Lee Closes #18611 * CI: Re-allow workflow_dispatch on zfs-qemu Allow zfs-qemu to be invoked from a workflow_dispatch event (a.k.a, manually running a workflow). This may have been accidentally disabled in 1916c2c55. Reviewed-by: Chris Longros Reviewed-by: Brian Behlendorf
Motivation and Context
Point the CI runner to the new released FreeBSD 15.1-RELEASE.
Official release announcement: https://www.freebsd.org/releases/15.1R/announce/
Description
Replace the
freebsd15-0rrelease runner withfreebsd15-1rHow Has This Been Tested?
CI change only
Types of changes
Checklist:
make checkstyle.Signed-off-by.