From: Bart Van Assche <bvanassche@acm.org>
To: Kashyap Desai <kashyap.desai@broadcom.com>,
linux-block <linux-block@vger.kernel.org>,
Jens Axboe <axboe@kernel.dk>, Ming Lei <ming.lei@redhat.com>,
linux-scsi <linux-scsi@vger.kernel.org>
Cc: Suganath Prabu Subramani <suganath-prabu.subramani@broadcom.com>,
Sreekanth Reddy <sreekanth.reddy@broadcom.com>,
Sathya Prakash Veerichetty <sathya.prakash@broadcom.com>
Subject: Re: [PATCH] blk-mq: Set request mapping to NULL in blk_mq_put_driver_tag
Date: Tue, 04 Dec 2018 09:14:34 -0800 [thread overview]
Message-ID: <1543943674.185366.194.camel@acm.org> (raw)
In-Reply-To: <d56ddf2b485c13445fff5f9c36dd3c87@mail.gmail.com>
On Tue, 2018-12-04 at 22:17 +0530, Kashyap Desai wrote:
> + Linux-scsi
>
> > > diff --git a/block/blk-mq.h b/block/blk-mq.h
> > > index 9497b47..57432be 100644
> > > --- a/block/blk-mq.h
> > > +++ b/block/blk-mq.h
> > > @@ -175,6 +175,7 @@ static inline bool
> > > blk_mq_get_dispatch_budget(struct blk_mq_hw_ctx *hctx)
> > > static inline void __blk_mq_put_driver_tag(struct blk_mq_hw_ctx *hctx,
> > > struct request *rq)
> > > {
> > > + hctx->tags->rqs[rq->tag] = NULL;
> > > blk_mq_put_tag(hctx, hctx->tags, rq->mq_ctx, rq->tag);
> > > rq->tag = -1;
> >
> > No SCSI driver should call scsi_host_find_tag() after a request has
> > finished. The above patch introduces yet another race and hence can't be
> > a proper fix.
>
> Bart, many scsi drivers use scsi_host_find_tag() to traverse max tag_id to
> find out pending IO in firmware.
> One of the use case is - HBA firmware recovery. In case of firmware
> recovery, driver may require to traverse the list and return back pending
> scsi command to SML for retry.
> I quickly grep the scsi code and found that snic_scsi, qla4xxx, fnic,
> mpt3sas are using API scsi_host_find_tag for the same purpose.
>
> Without this patch, we hit very basic kernel panic due to page fault. This
> is not an issue in non-mq code path. Non-mq path use
> blk_map_queue_find_tag() and that particular API does not provide stale
> requests.
As I wrote before, your patch doesn't fix the race you described but only
makes the race window smaller. If you want an example of how to use
scsi_host_find_tag() properly, have a look at the SRP initiator driver
(drivers/infiniband/ulp/srp). That driver uses scsi_host_find_tag() without
triggering any NULL pointer dereferences. The approach used in that driver
also works when having to support HBA firmware recovery.
Bart.
next prev parent reply other threads:[~2018-12-04 17:14 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-12-04 10:00 [PATCH] blk-mq: Set request mapping to NULL in blk_mq_put_driver_tag Kashyap Desai
2018-12-04 11:35 ` Ming Lei
2018-12-04 16:51 ` Kashyap Desai
2018-12-04 14:48 ` Bart Van Assche
2018-12-04 16:47 ` Kashyap Desai
2018-12-04 17:14 ` Bart Van Assche [this message]
2018-12-04 18:18 ` +AFs-PATCH+AF0- blk-mq: Set request mapping to NULL in blk+AF8-mq+AF8-put+AF8-driver+AF8-tag Kashyap Desai
2018-12-04 19:35 ` Bart Van Assche
2018-12-06 0:33 ` Ming Lei
2018-12-06 5:45 ` Kashyap Desai
2018-12-06 15:22 ` Jens Axboe
2018-12-07 7:16 ` Kashyap Desai
2018-12-07 10:20 ` Ming Lei
2018-12-07 10:34 ` Kashyap Desai
2018-12-11 15:06 ` Kashyap Desai
2018-12-14 6:22 ` Kashyap Desai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1543943674.185366.194.camel@acm.org \
--to=bvanassche@acm.org \
--cc=axboe@kernel.dk \
--cc=kashyap.desai@broadcom.com \
--cc=linux-block@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=ming.lei@redhat.com \
--cc=sathya.prakash@broadcom.com \
--cc=sreekanth.reddy@broadcom.com \
--cc=suganath-prabu.subramani@broadcom.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.