static loff_t
 dax_iomap_actor(struct inode *inode, loff_t pos, loff_t length, void *data,
-               struct iomap *iomap)
+               struct iomap *iomap, struct iomap *srcmap)
 {
        struct block_device *bdev = iomap->bdev;
        struct dax_device *dax_dev = iomap->dax_dev;
        struct inode *inode = mapping->host;
        unsigned long vaddr = vmf->address;
        loff_t pos = (loff_t)vmf->pgoff << PAGE_SHIFT;
-       struct iomap iomap = { 0 };
+       struct iomap iomap = { .type = IOMAP_HOLE };
+       struct iomap srcmap = { .type = IOMAP_HOLE };
        unsigned flags = IOMAP_FAULT;
        int error, major = 0;
        bool write = vmf->flags & FAULT_FLAG_WRITE;
         * the file system block size to be equal the page size, which means
         * that we never have to deal with more than a single extent here.
         */
-       error = ops->iomap_begin(inode, pos, PAGE_SIZE, flags, &iomap);
+       error = ops->iomap_begin(inode, pos, PAGE_SIZE, flags, &iomap, &srcmap);
        if (iomap_errp)
                *iomap_errp = error;
        if (error) {
        unsigned int iomap_flags = (write ? IOMAP_WRITE : 0) | IOMAP_FAULT;
        struct inode *inode = mapping->host;
        vm_fault_t result = VM_FAULT_FALLBACK;
-       struct iomap iomap = { 0 };
+       struct iomap iomap = { .type = IOMAP_HOLE };
+       struct iomap srcmap = { .type = IOMAP_HOLE };
        pgoff_t max_pgoff;
        void *entry;
        loff_t pos;
         * to look up our filesystem block.
         */
        pos = (loff_t)xas.xa_index << PAGE_SHIFT;
-       error = ops->iomap_begin(inode, pos, PMD_SIZE, iomap_flags, &iomap);
+       error = ops->iomap_begin(inode, pos, PMD_SIZE, iomap_flags, &iomap,
+                       &srcmap);
        if (error)
                goto unlock_entry;
 
 
 iomap_apply(struct inode *inode, loff_t pos, loff_t length, unsigned flags,
                const struct iomap_ops *ops, void *data, iomap_actor_t actor)
 {
-       struct iomap iomap = { 0 };
+       struct iomap iomap = { .type = IOMAP_HOLE };
+       struct iomap srcmap = { .type = IOMAP_HOLE };
        loff_t written = 0, ret;
+       u64 end;
 
        /*
         * Need to map a range from start position for length bytes. This can
         * expose transient stale data. If the reserve fails, we can safely
         * back out at this point as there is nothing to undo.
         */
-       ret = ops->iomap_begin(inode, pos, length, flags, &iomap);
+       ret = ops->iomap_begin(inode, pos, length, flags, &iomap, &srcmap);
        if (ret)
                return ret;
        if (WARN_ON(iomap.offset > pos))
         * Cut down the length to the one actually provided by the filesystem,
         * as it might not be able to give us the whole size that we requested.
         */
-       if (iomap.offset + iomap.length < pos + length)
-               length = iomap.offset + iomap.length - pos;
+       end = iomap.offset + iomap.length;
+       if (srcmap.type != IOMAP_HOLE)
+               end = min(end, srcmap.offset + srcmap.length);
+       if (pos + length > end)
+               length = end - pos;
 
        /*
-        * Now that we have guaranteed that the space allocation will succeed.
+        * Now that we have guaranteed that the space allocation will succeed,
         * we can do the copy-in page by page without having to worry about
         * failures exposing transient data.
+        *
+        * To support COW operations, we read in data for partially blocks from
+        * the srcmap if the file system filled it in.  In that case we the
+        * length needs to be limited to the earlier of the ends of the iomaps.
+        * If the file system did not provide a srcmap we pass in the normal
+        * iomap into the actors so that they don't need to have special
+        * handling for the two cases.
         */
-       written = actor(inode, pos, length, data, &iomap);
+       written = actor(inode, pos, length, data, &iomap,
+                       srcmap.type != IOMAP_HOLE ? &srcmap : &iomap);
 
        /*
         * Now the data has been copied, commit the range we've copied.  This
 
 
 static loff_t
 iomap_readpage_actor(struct inode *inode, loff_t pos, loff_t length, void *data,
-               struct iomap *iomap)
+               struct iomap *iomap, struct iomap *srcmap)
 {
        struct iomap_readpage_ctx *ctx = data;
        struct page *page = ctx->cur_page;
 
 static loff_t
 iomap_readpages_actor(struct inode *inode, loff_t pos, loff_t length,
-               void *data, struct iomap *iomap)
+               void *data, struct iomap *iomap, struct iomap *srcmap)
 {
        struct iomap_readpage_ctx *ctx = data;
        loff_t done, ret;
                        ctx->cur_page_in_bio = false;
                }
                ret = iomap_readpage_actor(inode, pos + done, length - done,
-                               ctx, iomap);
+                               ctx, iomap, srcmap);
        }
 
        return done;
 
 static int
 __iomap_write_begin(struct inode *inode, loff_t pos, unsigned len, int flags,
-               struct page *page, struct iomap *iomap)
+               struct page *page, struct iomap *srcmap)
 {
        struct iomap_page *iop = iomap_page_create(inode, page);
        loff_t block_size = i_blocksize(inode);
                    (to <= poff || to >= poff + plen))
                        continue;
 
-               if (iomap_block_needs_zeroing(inode, iomap, block_start)) {
+               if (iomap_block_needs_zeroing(inode, srcmap, block_start)) {
                        if (WARN_ON_ONCE(flags & IOMAP_WRITE_F_UNSHARE))
                                return -EIO;
                        zero_user_segments(page, poff, from, to, poff + plen);
                }
 
                status = iomap_read_page_sync(block_start, page, poff, plen,
-                               iomap);
+                               srcmap);
                if (status)
                        return status;
        } while ((block_start += plen) < block_end);
 
 static int
 iomap_write_begin(struct inode *inode, loff_t pos, unsigned len, unsigned flags,
-               struct page **pagep, struct iomap *iomap)
+               struct page **pagep, struct iomap *iomap, struct iomap *srcmap)
 {
        const struct iomap_page_ops *page_ops = iomap->page_ops;
        struct page *page;
        int status = 0;
 
        BUG_ON(pos + len > iomap->offset + iomap->length);
+       if (srcmap != iomap)
+               BUG_ON(pos + len > srcmap->offset + srcmap->length);
 
        if (fatal_signal_pending(current))
                return -EINTR;
                goto out_no_page;
        }
 
-       if (iomap->type == IOMAP_INLINE)
-               iomap_read_inline_data(inode, page, iomap);
+       if (srcmap->type == IOMAP_INLINE)
+               iomap_read_inline_data(inode, page, srcmap);
        else if (iomap->flags & IOMAP_F_BUFFER_HEAD)
-               status = __block_write_begin_int(page, pos, len, NULL, iomap);
+               status = __block_write_begin_int(page, pos, len, NULL, srcmap);
        else
                status = __iomap_write_begin(inode, pos, len, flags, page,
-                               iomap);
+                               srcmap);
 
        if (unlikely(status))
                goto out_unlock;
 }
 
 static int
-iomap_write_end(struct inode *inode, loff_t pos, unsigned len,
-               unsigned copied, struct page *page, struct iomap *iomap)
+iomap_write_end(struct inode *inode, loff_t pos, unsigned len, unsigned copied,
+               struct page *page, struct iomap *iomap, struct iomap *srcmap)
 {
        const struct iomap_page_ops *page_ops = iomap->page_ops;
        loff_t old_size = inode->i_size;
        int ret;
 
-       if (iomap->type == IOMAP_INLINE) {
+       if (srcmap->type == IOMAP_INLINE) {
                ret = iomap_write_end_inline(inode, page, iomap, pos, copied);
-       } else if (iomap->flags & IOMAP_F_BUFFER_HEAD) {
+       } else if (srcmap->flags & IOMAP_F_BUFFER_HEAD) {
                ret = block_write_end(NULL, inode->i_mapping, pos, len, copied,
                                page, NULL);
        } else {
 
 static loff_t
 iomap_write_actor(struct inode *inode, loff_t pos, loff_t length, void *data,
-               struct iomap *iomap)
+               struct iomap *iomap, struct iomap *srcmap)
 {
        struct iov_iter *i = data;
        long status = 0;
                        break;
                }
 
-               status = iomap_write_begin(inode, pos, bytes, 0, &page, iomap);
+               status = iomap_write_begin(inode, pos, bytes, 0, &page, iomap,
+                               srcmap);
                if (unlikely(status))
                        break;
 
 
                flush_dcache_page(page);
 
-               status = iomap_write_end(inode, pos, bytes, copied, page,
-                               iomap);
+               status = iomap_write_end(inode, pos, bytes, copied, page, iomap,
+                               srcmap);
                if (unlikely(status < 0))
                        break;
                copied = status;
 
 static loff_t
 iomap_unshare_actor(struct inode *inode, loff_t pos, loff_t length, void *data,
-               struct iomap *iomap)
+               struct iomap *iomap, struct iomap *srcmap)
 {
        long status = 0;
        ssize_t written = 0;
        if (!(iomap->flags & IOMAP_F_SHARED))
                return length;
        /* don't bother with holes or unwritten extents */
-       if (iomap->type == IOMAP_HOLE || iomap->type == IOMAP_UNWRITTEN)
+       if (srcmap->type == IOMAP_HOLE || srcmap->type == IOMAP_UNWRITTEN)
                return length;
 
        do {
                struct page *page;
 
                status = iomap_write_begin(inode, pos, bytes,
-                               IOMAP_WRITE_F_UNSHARE, &page, iomap);
+                               IOMAP_WRITE_F_UNSHARE, &page, iomap, srcmap);
                if (unlikely(status))
                        return status;
 
-               status = iomap_write_end(inode, pos, bytes, bytes, page, iomap);
+               status = iomap_write_end(inode, pos, bytes, bytes, page, iomap,
+                               srcmap);
                if (unlikely(status <= 0)) {
                        if (WARN_ON_ONCE(status == 0))
                                return -EIO;
 EXPORT_SYMBOL_GPL(iomap_file_unshare);
 
 static int iomap_zero(struct inode *inode, loff_t pos, unsigned offset,
-               unsigned bytes, struct iomap *iomap)
+               unsigned bytes, struct iomap *iomap, struct iomap *srcmap)
 {
        struct page *page;
        int status;
 
-       status = iomap_write_begin(inode, pos, bytes, 0, &page, iomap);
+       status = iomap_write_begin(inode, pos, bytes, 0, &page, iomap, srcmap);
        if (status)
                return status;
 
        zero_user(page, offset, bytes);
        mark_page_accessed(page);
 
-       return iomap_write_end(inode, pos, bytes, bytes, page, iomap);
+       return iomap_write_end(inode, pos, bytes, bytes, page, iomap, srcmap);
 }
 
 static int iomap_dax_zero(loff_t pos, unsigned offset, unsigned bytes,
 
 static loff_t
 iomap_zero_range_actor(struct inode *inode, loff_t pos, loff_t count,
-               void *data, struct iomap *iomap)
+               void *data, struct iomap *iomap, struct iomap *srcmap)
 {
        bool *did_zero = data;
        loff_t written = 0;
        int status;
 
        /* already zeroed?  we're done. */
-       if (iomap->type == IOMAP_HOLE || iomap->type == IOMAP_UNWRITTEN)
+       if (srcmap->type == IOMAP_HOLE || srcmap->type == IOMAP_UNWRITTEN)
                return count;
 
        do {
                if (IS_DAX(inode))
                        status = iomap_dax_zero(pos, offset, bytes, iomap);
                else
-                       status = iomap_zero(inode, pos, offset, bytes, iomap);
+                       status = iomap_zero(inode, pos, offset, bytes, iomap,
+                                       srcmap);
                if (status < 0)
                        return status;
 
 
 static loff_t
 iomap_page_mkwrite_actor(struct inode *inode, loff_t pos, loff_t length,
-               void *data, struct iomap *iomap)
+               void *data, struct iomap *iomap, struct iomap *srcmap)
 {
        struct page *page = data;
        int ret;