All of lore.kernel.org
 help / color / mirror / Atom feed
From: Alex Markuze <amarkuze@redhat.com>
To: ceph-devel@vger.kernel.org
Cc: idryomov@gmail.com, xiubo.li@clyso.com
Subject: [PATCH v7 00/14] ceph: add binary logging (BLOG) for CephFS
Date: Thu, 24 Sep 2026 15:30:30 +0000	[thread overview]
Message-ID: <20260924153045.994784-1-amarkuze@redhat.com> (raw)

This series adds a per-mount binary flight recorder for CephFS debug
messages. It stores typed arguments in per-task page-fragment buffers
and reconstructs text through debugfs. Runtime enablement is per mount
and defaults to off; CONFIG_DEBUG_FS remains the build gate.

Thanks to Xiubo for the detailed v6 testing and reproducer. This revision
addresses the two xattr logging hazards and the empty-magazine growth
reported in that review. Further code reviews and a 32-bit build also
found issues in cache lookup, counted-name logging, debugfs controls,
dump completion, record timestamps and stack usage, fixed here. The
complete 14-patch series is based on testing tip 6a8449a3f814.

Changes since v6:

  - In __ceph_destroy_xattrs(), log the node pointers without reading
    xattr->name. Snapshot encoding can free the blob backing the old
    index before its destruction; a bounded string read is still unsafe.
  - In __copy_xattr_names(), log the NUL-terminated destination and xattr
    pointer. The borrowed source name is length-delimited and cannot be
    passed to an unbounded %s.
  - Return exhausted allocation magazines directly to log_batch's empty
    list, where blog_batch_put() can refill them. Do this for both task
    context allocation and atomic buffer rotation. Detach the per-CPU
    magazine before publishing it under the destination empty-list lock.
    Both batches use the same magazine slab cache.
  - Load the per-CPU cached context once and check that same pointer.
    A remote migration or retirement can clear the slot between the old
    check and reload, causing a NULL dereference despite local preemption
    being disabled.
  - On a long encrypted snapshot-name lookup failure, log the existing
    terminated copy, restoring the leading underscore in the format.
    The original input is length-delimited.
  - Bound binary capture of the base64-encoded ciphertext name with
    BLOG_STR(p, elen). base64_encode() does not append a terminator;
    %.*s alone only bounds the text path.
  - Make the BLOG read files root-readable (0400), matching the other
    Ceph debugfs data files. Recorded names and xattr values must not be
    exposed when the debugfs root is traversable by other users.
  - Check the mount's enabled flag during context lookup. Disabling one
    mount must stop subsequent capture even if another enabled mount
    keeps the global static key active.
  - Bound an entries dump by a maximum context ID, preserving that bound
    across seq_file overflow retries. Stop formatting on overflow so
    sustained rotation cannot keep a reader chasing new contexts.
  - Store record base times as u64 from get_jiffies_64(), including the
    delta calculation. Protect published base updates with the pagefrag
    lock used by readers. This preserves the epoch on 32-bit kernels,
    whose low jiffies word first wraps about five minutes after boot.
    Use one clock sample for the overflow check and stored delta, so a
    tick between them cannot wrap an exactly U32_MAX delta to zero.
  - Prepare each argument directly in its existing TLS scratch slot.
    Returning a temporary struct for every argument pushed the GCC i386
    __ceph_setattr() frame over its 1280-byte build limit. Direct filling
    brings reported stack usage to 300 bytes without changing evaluation
    order, string bounds or the recursive arity macros.
  - Rebase onto testing with the subsequent CephFS fixes already applied.
    Fold the fixes into patches 01, 04, 06, 07, 10 and 14; retain 14 patches.

Local validation:

  - GCC 11.4 and Clang 18.1 builds of fs/ceph/ceph.o and
    net/ceph/libceph.o with DEBUG_FS=y and DYNAMIC_DEBUG=y; GCC also
    builds both objects with DEBUG_FS=n. A GCC i386 build of both objects
    also passes with the default 1280-byte frame limit.
  - ASan/UBSan host tests using the actual xattr functions, BLOG argument
    serializer and kernel string-reading loop reproduce the v6 UAF and
    over-read. The v7 cases pass with BLOG and dynamic debug off/on.
  - Host tests using the actual magazine get/put/cleanup and rebalance
    code check both allocation call sites, sustained churn, reuse with
    new magazine allocations disabled, and 64,000 cycles on eight
    pthread workers. v6 exposes the growth; v7 reuses the magazines and
    releases all remaining objects at cleanup.
  - Additional ASan/UBSan host checks inject a remote cache clear and use
    exact-sized, unterminated encrypted names. They reproduce all three
    additional faults in the earlier v7 draft and pass with these fixes.
    The decoder passes 200,000 randomized malformed-payload cases with
    exact-sized input and output allocations under ASan/UBSan.
  - Before/after reader tests cover continuous context-ID churn and a
    stable bound across overflow retries. A cache test covers disabling
    a mount with an active context. Native freestanding i386 checks of
    the actual timestamp expressions cover crossing the first wrap,
    creating a context after it, detecting an expired u32 delta, and a
    clock tick at the exact U32_MAX boundary.
  - GCC/Clang serializer, request-context and initialization-failure
    host tests pass. The review-fix diff has no strict checkpatch errors,
    warnings or checks.

These are composite-object builds and host regression checks. Kernel
primitives are substituted in the host harnesses; they do not establish
kernel scheduling, interrupt, KASAN or lockdep behavior. A v7 booted
kernel and Ceph-cluster rerun remains for Xiubo; KASAN is not available
in the local setup. Xiubo's reported cluster results were against v6
with the destructor logging fix.

Known follow-up: existing %ptSp arguments still decode as pointer values
on the binary path. Timestamp-by-value serialization and further style
cleanup remain deferred as in v6.

AI assistance was used for the v7 fixes, code review, regression harnesses
and this cover letter. The changed implementation commits carry
Assisted-by attribution.

Alex Markuze (14):
  ceph: add BLOG private headers
  ceph: add BLOG deserialization support
  ceph: add BLOG page-fragment allocator
  ceph: add BLOG magazine batch allocator
  ceph: add BLOG logger core
  ceph: add BLOG per-module context management
  ceph: add Ceph BLOG scaffolding
  ceph: add boutc wrappers for BLOG
  ceph: switch MDS request plumbing to struct ceph_journal_info
  ceph: add BLOG debugfs interface
  ceph: convert VFS inode and directory paths to BLOG logging
  ceph: convert VFS data I/O paths to BLOG logging
  ceph: convert capability and snapshot paths to BLOG logging
  ceph: convert remaining helper paths to BLOG logging

 fs/ceph/Makefile                |    3 +
 fs/ceph/addr.c                  |  202 ++++---
 fs/ceph/blog.h                  |  216 +++++++
 fs/ceph/blog_batch.c            |  267 ++++++++
 fs/ceph/blog_batch.h            |   44 ++
 fs/ceph/blog_client.c           |  644 ++++++++++++++++++++
 fs/ceph/blog_core.c             |  297 +++++++++
 fs/ceph/blog_debugfs.c          |  702 +++++++++++++++++++++
 fs/ceph/blog_des.c              |  335 +++++++++++
 fs/ceph/blog_des.h              |   16 +
 fs/ceph/blog_module.c           | 1003 +++++++++++++++++++++++++++++++
 fs/ceph/blog_module.h           |   42 ++
 fs/ceph/blog_pagefrag.c         |   62 ++
 fs/ceph/blog_pagefrag.h         |   27 +
 fs/ceph/blog_ser.h              |  404 +++++++++++++
 fs/ceph/caps.c                  |  116 ++--
 fs/ceph/crypto.c                |   19 +-
 fs/ceph/debugfs.c               |   11 +-
 fs/ceph/dir.c                   |  329 +++++++---
 fs/ceph/export.c                |   83 ++-
 fs/ceph/file.c                  |  287 ++++++---
 fs/ceph/inode.c                 |  256 ++++----
 fs/ceph/locks.c                 |   66 +-
 fs/ceph/mds_client.c            |  369 +++++++-----
 fs/ceph/snap.c                  |   17 +-
 fs/ceph/super.c                 |   61 +-
 fs/ceph/super.h                 |    7 +
 fs/ceph/xattr.c                 |  101 ++--
 include/linux/ceph/ceph_blog.h  |  292 +++++++++
 include/linux/ceph/ceph_debug.h |   81 ++-
 include/linux/ceph/libceph.h    |    2 +
 31 files changed, 5705 insertions(+), 656 deletions(-)
 create mode 100644 fs/ceph/blog.h
 create mode 100644 fs/ceph/blog_batch.c
 create mode 100644 fs/ceph/blog_batch.h
 create mode 100644 fs/ceph/blog_client.c
 create mode 100644 fs/ceph/blog_core.c
 create mode 100644 fs/ceph/blog_debugfs.c
 create mode 100644 fs/ceph/blog_des.c
 create mode 100644 fs/ceph/blog_des.h
 create mode 100644 fs/ceph/blog_module.c
 create mode 100644 fs/ceph/blog_module.h
 create mode 100644 fs/ceph/blog_pagefrag.c
 create mode 100644 fs/ceph/blog_pagefrag.h
 create mode 100644 fs/ceph/blog_ser.h
 create mode 100644 include/linux/ceph/ceph_blog.h


base-commit: 6a8449a3f81444b6a25adc41cfd2c0ac33f8f96a
-- 
2.34.1


             reply	other threads:[~2026-09-24 15:30 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 15:30 Alex Markuze [this message]
2026-09-24 15:30 ` [PATCH v7 01/14] ceph: add BLOG private headers Alex Markuze
2026-09-24 15:30 ` [PATCH v7 02/14] ceph: add BLOG deserialization support Alex Markuze
2026-09-24 15:30 ` [PATCH v7 03/14] ceph: add BLOG page-fragment allocator Alex Markuze
2026-09-24 15:30 ` [PATCH v7 04/14] ceph: add BLOG magazine batch allocator Alex Markuze
2026-09-24 15:30 ` [PATCH v7 05/14] ceph: add BLOG logger core Alex Markuze
2026-09-24 15:30 ` [PATCH v7 06/14] ceph: add BLOG per-module context management Alex Markuze
2026-09-24 15:30 ` [PATCH v7 07/14] ceph: add Ceph BLOG scaffolding Alex Markuze
2026-09-24 15:30 ` [PATCH v7 08/14] ceph: add boutc wrappers for BLOG Alex Markuze
2026-09-24 15:30 ` [PATCH v7 09/14] ceph: switch MDS request plumbing to struct ceph_journal_info Alex Markuze
2026-09-24 15:30 ` [PATCH v7 10/14] ceph: add BLOG debugfs interface Alex Markuze
2026-09-24 15:30 ` [PATCH v7 11/14] ceph: convert VFS inode and directory paths to BLOG logging Alex Markuze
2026-09-24 15:30 ` [PATCH v7 12/14] ceph: convert VFS data I/O " Alex Markuze
2026-09-24 15:30 ` [PATCH v7 13/14] ceph: convert capability and snapshot " Alex Markuze
2026-09-24 15:30 ` [PATCH v7 14/14] ceph: convert remaining helper " Alex Markuze
2026-10-01 13:25 ` [PATCH v7 00/14] ceph: add binary logging (BLOG) for CephFS Xiubo Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924153045.994784-1-amarkuze@redhat.com \
    --to=amarkuze@redhat.com \
    --cc=ceph-devel@vger.kernel.org \
    --cc=idryomov@gmail.com \
    --cc=xiubo.li@clyso.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.