All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Andrey Albershteyn via Linux-f2fs-devel"
	<linux-f2fs-devel@lists.sourceforge.net>
Cc: linux-ext4@vger.kernel.org, tytso@mit.edu, dsterba@suse.cz
Subject: Re: [f2fs-dev] [PATCH v17 12/21] xfs: use read ioend for fsverity data verification
Date: Sat, 03 Oct 2026 01:34:22 +0000	[thread overview]
Message-ID: <20261003013423.33F4E1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261002223705.2175542-13-aalbersh@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] xfs: deadlock in per-CPU bio completion due to mempool_alloc() with GFP_NOFS
--

commit ea1a0b2023bf04b556e0f9d798eb8d673f0e72ca
Author: Andrey Albershteyn via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>

xfs: use read ioend for fsverity data verification

This commit uses read ioends for fsverity verification, moving fsverity
metadata I/O to a separate workqueue to avoid deadlocks. It passes
fsverity_info from the iomap context down to the ioend and adds a helper to
check for file data.

> diff --git a/fs/xfs/xfs_aops.c b/fs/xfs/xfs_aops.c
> index 19640e4e3ed12..a36f840884b49 100644
> --- a/fs/xfs/xfs_aops.c
> +++ b/fs/xfs/xfs_aops.c
[ ... ]
> @@ -623,11 +624,13 @@ static const struct iomap_read_ops xfs_iomap_read_ops = {
>  
>  static inline const struct iomap_read_ops *
>  xfs_get_iomap_read_ops(
> -	const struct address_space	*mapping)
> +	const struct address_space	*mapping,
> +	loff_t				pos)
>  {
>  	struct xfs_inode		*ip = XFS_I(mapping->host);
>  
> -	if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev))
> +	if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev) ||
> +	    xfs_fsverity_is_file_data(ip, pos))
>  		return &xfs_iomap_read_ops;

[Severity: High]
Does this logic route fsverity metadata reads through xfs_iomap_read_ops if
the block device has integrity checksums? 

Using xfs_iomap_read_ops causes xfs_bio_submit_read() to call
xfs_ioend_submit_read(), which sets BIO_COMPLETE_IN_TASK on the bio. This
means the completions for these metadata reads will be queued to the per-CPU
bio completion worker.

>  	return &iomap_bio_read_ops;
>  }

[ ... ]
> diff --git a/fs/xfs/xfs_ioend.c b/fs/xfs/xfs_ioend.c
> index e70be5b86f0b7..f4c1bbc03714f 100644
> --- a/fs/xfs/xfs_ioend.c
> +++ b/fs/xfs/xfs_ioend.c
[ ... ]
> @@ -117,6 +138,24 @@ xfs_end_io_read(
>  		}
>  	}
>  
> +	/*
> +	 * If we have fsverity on this bio, we need to run fsverity verification
> +	 * of data folios from a separate fsverity workqueue. This is necessary
> +	 * to avoid deadlocking due to fsverity issuing more reads of fsverity
> +	 * metadata which would be processed by the same worker in the BIO
> +	 * completion workqueue.
> +	 */
> +	if (IS_ENABLED(CONFIG_FS_VERITY) && !error && ioend->io_vi &&
> +			xfs_fsverity_is_file_data(ip, ioend->io_offset)) {
> +		fsv_ioend = mempool_alloc(&xfs_fsverity_ioend_pool,
> +				GFP_NOFS);

[Severity: High]
Can this result in an ABBA deadlock under memory pressure?

If the memory pool is empty, mempool_alloc() with GFP_NOFS will sleep and
block the per-CPU bio completion worker in xfs_end_io_read().

As noted in xfs_get_iomap_read_ops() above, if the block device has integrity
checksums enabled, fsverity metadata reads will use xfs_iomap_read_ops
and their completions will also be queued to this same per-CPU bio completion
worker.

Since this worker could be blocked in mempool_alloc() waiting for the
fsverity workqueue to finish verifying data, and the fsverity workqueue
could concurrently be waiting on a metadata read completion that is queued on
this blocked worker, can this cause a hang?

> +		fsv_ioend->ioend = ioend;
> +		INIT_WORK(&fsv_ioend->work, xfs_end_fsverity_io_read);
> +
> +		fsverity_enqueue_verify_work(&fsv_ioend->work);
> +		return;
> +	}
> +
>  	iomap_finish_ioends(ioend, error);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002223705.2175542-1-aalbersh@kernel.org?part=12

WARNING: multiple messages have this Message-ID (diff)
From: sashiko-bot--- via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>
To: "Andrey Albershteyn via Linux-f2fs-devel"
	<linux-f2fs-devel@lists.sourceforge.net>
Cc: sashiko-bot@kernel.org, linux-ext4@vger.kernel.org,
	tytso@mit.edu, dsterba@suse.cz
Subject: Re: [f2fs-dev] [PATCH v17 12/21] xfs: use read ioend for fsverity data verification
Date: Sat, 03 Oct 2026 01:34:22 +0000	[thread overview]
Message-ID: <20261003013423.33F4E1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261002223705.2175542-13-aalbersh@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] xfs: deadlock in per-CPU bio completion due to mempool_alloc() with GFP_NOFS
--

commit ea1a0b2023bf04b556e0f9d798eb8d673f0e72ca
Author: Andrey Albershteyn via Linux-f2fs-devel <linux-f2fs-devel@lists.sourceforge.net>

xfs: use read ioend for fsverity data verification

This commit uses read ioends for fsverity verification, moving fsverity
metadata I/O to a separate workqueue to avoid deadlocks. It passes
fsverity_info from the iomap context down to the ioend and adds a helper to
check for file data.

> diff --git a/fs/xfs/xfs_aops.c b/fs/xfs/xfs_aops.c
> index 19640e4e3ed12..a36f840884b49 100644
> --- a/fs/xfs/xfs_aops.c
> +++ b/fs/xfs/xfs_aops.c
[ ... ]
> @@ -623,11 +624,13 @@ static const struct iomap_read_ops xfs_iomap_read_ops = {
>  
>  static inline const struct iomap_read_ops *
>  xfs_get_iomap_read_ops(
> -	const struct address_space	*mapping)
> +	const struct address_space	*mapping,
> +	loff_t				pos)
>  {
>  	struct xfs_inode		*ip = XFS_I(mapping->host);
>  
> -	if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev))
> +	if (bdev_has_integrity_csum(xfs_inode_buftarg(ip)->bt_bdev) ||
> +	    xfs_fsverity_is_file_data(ip, pos))
>  		return &xfs_iomap_read_ops;

[Severity: High]
Does this logic route fsverity metadata reads through xfs_iomap_read_ops if
the block device has integrity checksums? 

Using xfs_iomap_read_ops causes xfs_bio_submit_read() to call
xfs_ioend_submit_read(), which sets BIO_COMPLETE_IN_TASK on the bio. This
means the completions for these metadata reads will be queued to the per-CPU
bio completion worker.

>  	return &iomap_bio_read_ops;
>  }

[ ... ]
> diff --git a/fs/xfs/xfs_ioend.c b/fs/xfs/xfs_ioend.c
> index e70be5b86f0b7..f4c1bbc03714f 100644
> --- a/fs/xfs/xfs_ioend.c
> +++ b/fs/xfs/xfs_ioend.c
[ ... ]
> @@ -117,6 +138,24 @@ xfs_end_io_read(
>  		}
>  	}
>  
> +	/*
> +	 * If we have fsverity on this bio, we need to run fsverity verification
> +	 * of data folios from a separate fsverity workqueue. This is necessary
> +	 * to avoid deadlocking due to fsverity issuing more reads of fsverity
> +	 * metadata which would be processed by the same worker in the BIO
> +	 * completion workqueue.
> +	 */
> +	if (IS_ENABLED(CONFIG_FS_VERITY) && !error && ioend->io_vi &&
> +			xfs_fsverity_is_file_data(ip, ioend->io_offset)) {
> +		fsv_ioend = mempool_alloc(&xfs_fsverity_ioend_pool,
> +				GFP_NOFS);

[Severity: High]
Can this result in an ABBA deadlock under memory pressure?

If the memory pool is empty, mempool_alloc() with GFP_NOFS will sleep and
block the per-CPU bio completion worker in xfs_end_io_read().

As noted in xfs_get_iomap_read_ops() above, if the block device has integrity
checksums enabled, fsverity metadata reads will use xfs_iomap_read_ops
and their completions will also be queued to this same per-CPU bio completion
worker.

Since this worker could be blocked in mempool_alloc() waiting for the
fsverity workqueue to finish verifying data, and the fsverity workqueue
could concurrently be waiting on a metadata read completion that is queued on
this blocked worker, can this cause a hang?

> +		fsv_ioend->ioend = ioend;
> +		INIT_WORK(&fsv_ioend->work, xfs_end_fsverity_io_read);
> +
> +		fsverity_enqueue_verify_work(&fsv_ioend->work);
> +		return;
> +	}
> +
>  	iomap_finish_ioends(ioend, error);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002223705.2175542-1-aalbersh@kernel.org?part=12


_______________________________________________
Linux-f2fs-devel mailing list
Linux-f2fs-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-f2fs-devel

  reply	other threads:[~2026-10-03  1:34 UTC|newest]

Thread overview: 96+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 22:36 [PATCH v17 00/21] fs-verity support for XFS with post EOF merkle tree Andrey Albershteyn
2026-10-02 22:36 ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 01/21] fsverity: report validation errors through fserror to fsnotify Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 02/21] fsverity: expose ensure_fsverity_info() Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 03/21] fsverity: pass digest size and hash of the all-zeroes block to ->write Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 04/21] fsverity: hoist pagecache_read from f2fs/ext4 to fsverity Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 05/21] fsverity: don't allow setting DAX file attribute on fsverity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 06/21] fsverity: hoist statx reporting of fs-verity flag Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 07/21] xfs: introduce fsverity on-disk changes Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 08/21] xfs: don't allow to enable DAX on fs-verity sealed inode Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-02 22:36 ` [PATCH v17 09/21] xfs: disable direct read path for fs-verity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 10/21] xfs: don't report dio_mem_align and dio_offset_align for fsverity files Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 11/21] xfs: handle fsverity I/O in write/read path Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 12/21] xfs: use read ioend for fsverity data verification Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot [this message]
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 13/21] xfs: add XFS_BMAPI_UNWRITTEN to unmap unwritten extents in __xfs_bunmapi() Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 14/21] xfs: don't remove written extents past EOF on fsverity inodes Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 15/21] xfs: add fs-verity support Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-05 17:18   ` Andrey Albershteyn
2026-10-05 17:18     ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-05 21:12     ` Darrick J. Wong
2026-10-05 21:12       ` [f2fs-dev] " Darrick J. Wong via Linux-f2fs-devel
2026-10-06  9:03       ` Andrey Albershteyn
2026-10-06  9:03         ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 16/21] xfs: initialize fs-verity on file open Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 17/21] xfs: add fs-verity ioctls Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:36 ` [PATCH v17 18/21] xfs: advertise fs-verity being available on filesystem Andrey Albershteyn
2026-10-02 22:36   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 19/21] xfs: check and repair the verity inode flag state Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 20/21] xfs: introduce health state for corrupted fsverity metadata Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 22:37 ` [PATCH v17 21/21] xfs: enable ro-compat fs-verity flag Andrey Albershteyn
2026-10-02 22:37   ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-03  1:34   ` sashiko-bot
2026-10-03  1:34     ` sashiko-bot--- via Linux-f2fs-devel
2026-10-02 23:25 ` [PATCH v17 00/21] fs-verity support for XFS with post EOF merkle tree Eric Biggers
2026-10-02 23:25   ` [f2fs-dev] " Eric Biggers via Linux-f2fs-devel
2026-10-03 12:07   ` Carlos Maiolino
2026-10-03 12:07     ` [f2fs-dev] " Carlos Maiolino via Linux-f2fs-devel
2026-10-05 11:26     ` Andrey Albershteyn
2026-10-05 11:26       ` [f2fs-dev] " Andrey Albershteyn via Linux-f2fs-devel
2026-10-05 13:30       ` Eric Biggers
2026-10-05 13:30         ` [f2fs-dev] " Eric Biggers via Linux-f2fs-devel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003013423.33F4E1F00899@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dsterba@suse.cz \
    --cc=linux-ext4@vger.kernel.org \
    --cc=linux-f2fs-devel@lists.sourceforge.net \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tytso@mit.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.