All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Denis V. Lunev" <den@virtuozzo.com>
To: Markus Armbruster <armbru@redhat.com>
Cc: "Denis V. Lunev" <den@openvz.org>,
	qemu-devel@nongnu.org, qemu-block@nongnu.org,
	Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>,
	Kevin Wolf <kwolf@redhat.com>, Hanna Reitz <hreitz@redhat.com>,
	Eric Blake <eblake@redhat.com>,
	qemu-stable@nongnu.org
Subject: Re: [PATCH v4 5/5] qcow2: repair a dirty image when it becomes writable
Date: Tue, 1 Sep 2026 00:03:57 +0200	[thread overview]
Message-ID: <7ad0843e-63d2-401a-8ce3-fbdfe317826d@virtuozzo.com> (raw)
In-Reply-To: <8691b460-faa3-4562-9820-c63823041878@virtuozzo.com>

On 8/31/26 21:01, Denis V. Lunev wrote:
> On 8/31/26 14:31, Markus Armbruster wrote:
>> "Denis V. Lunev" <den@virtuozzo.com> writes:
>>
>>> On 8/27/26 11:15, Markus Armbruster wrote:
>> [...]
>>
>>>> We must not (re)open a dirty image read/write without cleaning it,
>>>> because writing to risks corruption, i.e. data loss.
>>>>
>>>> When we open a dirty image read/write, we can clean it without
>>>> inconveniencing the guest, because the guest cannot access it until
>>>> after open completes and we connect the newly open image.  Correct?
>>> correct.
>>>
>>>> When we reopen a read/only dirty image read/write, cleaning it *can*
>>>> affect the guest, as discussed above.
>>>>
>>>> As far as I can tell, all the trouble discussed above ultimately comes
>>>> from letting the guest work with read-only dirty images.  Why is that
>>>> useful?
>>>>
>>>> What are the use cases for opening dirty images read-only?
>>> Read only images usually comes in image chains (snapshots, backing
>>> stores). How RO image becomes dirty is very good question. May
>>> be this was due to QEMU stop/node crash during running commit.
>>>
>>> Why this is needed? VM should continue to start with dirty
>>> RO image. Doing maintenance at start? That is also problematic.
>>> At this moment we can face shared lock on base image (so called
>>> golden image scenario).
>> We can "do maintenance" during initial open proactively, or during
>> reopen read/write as needed.
>>
>> In both cases, we risk delays that can make the guest hang.
>>
>> Cleaning as needed might avoid some delays.  It can also shift delays
>> from QEMU startup (sometimes bad) to guest operation (commonly worse).
>>
>> Cleaning as needed in its current state appears to violate
>> blockdev-reopen's contract: it breaks the transaction.  This feels like
>> a regression.
>>
>> I think cleaning as needed poses challenges to management applications.
>> I figure sophisticated ones can make a reasonable choice between "clean
>> offline before you pass to QEMU" and "don't, and manage the delay on
>> reopen".  For less sophisticated ones, and also human users, all this
>> feels like a trap.
>>
>> Have we considered dirty image open to require an "I'm sophisticated"
>> flag?
>>
>> Anyway, this is how far I can take this.  Now the block layer
>> maintainers need to chime in.
>>
>> [...]
> The problem is that we are opening RO and could not change the
> image. That is the worst part and not just by the fact that
> we opening RO (we can try to reopen RW) but by the fact that
> another QEMU has already opened that image and we could not
> take the lock. Reopen here may not happen ever.
>
> Both ways are weird, the question is what is worse? :-)
>
> Den
There are 2 additional note, which I would like to share.

1. Denying start of VM with dirty RO image is no-go for
any migration of such VM over shared storage. Nothing
could be done with such a VM once node would need to be
upgraded and thus to be moved. That would be real hell
for any operation.

2. Though this could be mitigated with an addition of
forced image check through QMP and that makes a lot of
sense. Fixing image integrity for alive VM even with
several seconds pause could be a real life saver. This
functionality smells useful.

Thus we could
* make a check of RO images on start and deny if the fix
could not be made for whatever reason
* and add qmp-image-check as a command for specific node
as command

This could be correct API wise.

Thanks,
    Den


  reply	other threads:[~2026-08-31 22:04 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-24 13:37 [PATCH v4 0/5] qcow2: silent corruption when a dirty image becomes writable Denis V. Lunev
2026-08-24 13:37 ` [PATCH v4 1/5] qcow2: do not clear the dirty bit when reopening a read-only node Denis V. Lunev
2026-10-06 10:01   ` Kevin Wolf
2026-08-24 13:37 ` [PATCH v4 2/5] block: reject a reopen of an unusable node instead of crashing Denis V. Lunev
2026-10-06 10:02   ` Kevin Wolf
2026-08-24 13:37 ` [PATCH v4 3/5] block: let bdrv_reopen_commit_post() report a failure Denis V. Lunev
2026-10-06 12:12   ` Kevin Wolf
2026-08-24 13:37 ` [PATCH v4 4/5] block: remember the flags a reopen starts from Denis V. Lunev
2026-08-24 13:37 ` [PATCH v4 5/5] qcow2: repair a dirty image when it becomes writable Denis V. Lunev
2026-08-25  9:37   ` Markus Armbruster
2026-08-26 13:49     ` Denis V. Lunev
2026-08-26 15:24       ` Markus Armbruster
2026-08-26 16:37         ` Denis V. Lunev
2026-08-27  9:15           ` Markus Armbruster
2026-08-27 16:06             ` Denis V. Lunev
2026-08-31 12:31               ` Markus Armbruster
2026-08-31 19:01                 ` Denis V. Lunev
2026-08-31 22:03                   ` Denis V. Lunev [this message]
2026-10-06 10:30             ` Kevin Wolf
2026-09-21 19:40 ` [PATCH v4 0/5] qcow2: silent corruption when a dirty image " Denis V. Lunev
2026-10-05  8:57 ` Denis V. Lunev

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7ad0843e-63d2-401a-8ce3-fbdfe317826d@virtuozzo.com \
    --to=den@virtuozzo.com \
    --cc=andrey.drobyshev@virtuozzo.com \
    --cc=armbru@redhat.com \
    --cc=den@openvz.org \
    --cc=eblake@redhat.com \
    --cc=hreitz@redhat.com \
    --cc=kwolf@redhat.com \
    --cc=qemu-block@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-stable@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.