From: Bart Van Assche <bvanassche@acm.org>
To: Kashyap Desai <kashyap.desai@broadcom.com>,
linux-block <linux-block@vger.kernel.org>,
Jens Axboe <axboe@kernel.dk>, Ming Lei <ming.lei@redhat.com>,
linux-scsi <linux-scsi@vger.kernel.org>
Cc: Suganath Prabu Subramani <suganath-prabu.subramani@broadcom.com>,
Sreekanth Reddy <sreekanth.reddy@broadcom.com>,
Sathya Prakash Veerichetty <sathya.prakash@broadcom.com>
Subject: Re: [PATCH] blk-mq: Set request mapping to NULL in blk_mq_put_driver_tag
Date: Tue, 04 Dec 2018 09:14:34 -0800 [thread overview]
Message-ID: <1543943674.185366.194.camel@acm.org> (raw)
In-Reply-To: <d56ddf2b485c13445fff5f9c36dd3c87@mail.gmail.com>
On Tue, 2018-12-04 at 22:17 +0530, Kashyap Desai wrote:
> + Linux-scsi
>
> > > diff --git a/block/blk-mq.h b/block/blk-mq.h
> > > index 9497b47..57432be 100644
> > > --- a/block/blk-mq.h
> > > +++ b/block/blk-mq.h
> > > @@ -175,6 +175,7 @@ static inline bool
> > > blk_mq_get_dispatch_budget(struct blk_mq_hw_ctx *hctx)
> > > static inline void __blk_mq_put_driver_tag(struct blk_mq_hw_ctx *hctx,
> > > struct request *rq)
> > > {
> > > + hctx->tags->rqs[rq->tag] = NULL;
> > > blk_mq_put_tag(hctx, hctx->tags, rq->mq_ctx, rq->tag);
> > > rq->tag = -1;
> >
> > No SCSI driver should call scsi_host_find_tag() after a request has
> > finished. The above patch introduces yet another race and hence can't be
> > a proper fix.
>
> Bart, many scsi drivers use scsi_host_find_tag() to traverse max tag_id to
> find out pending IO in firmware.
> One of the use case is - HBA firmware recovery. In case of firmware
> recovery, driver may require to traverse the list and return back pending
> scsi command to SML for retry.
> I quickly grep the scsi code and found that snic_scsi, qla4xxx, fnic,
> mpt3sas are using API scsi_host_find_tag for the same purpose.
>
> Without this patch, we hit very basic kernel panic due to page fault. This
> is not an issue in non-mq code path. Non-mq path use
> blk_map_queue_find_tag() and that particular API does not provide stale
> requests.
As I wrote before, your patch doesn't fix the race you described but only
makes the race window smaller. If you want an example of how to use
scsi_host_find_tag() properly, have a look at the SRP initiator driver
(drivers/infiniband/ulp/srp). That driver uses scsi_host_find_tag() without
triggering any NULL pointer dereferences. The approach used in that driver
also works when having to support HBA firmware recovery.
Bart.
next prev parent reply other threads:[~2018-12-04 17:14 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-12-04 10:00 [PATCH] blk-mq: Set request mapping to NULL in blk_mq_put_driver_tag Kashyap Desai
2018-12-04 11:35 ` Ming Lei
2018-12-04 16:51 ` Kashyap Desai
2018-12-04 14:48 ` Bart Van Assche
2018-12-04 16:47 ` Kashyap Desai
2018-12-04 17:14 ` Bart Van Assche [this message]
2018-12-04 18:18 ` +AFs-PATCH+AF0- blk-mq: Set request mapping to NULL in blk+AF8-mq+AF8-put+AF8-driver+AF8-tag Kashyap Desai
2018-12-04 19:35 ` Bart Van Assche
2018-12-06 0:33 ` Ming Lei
2018-12-06 5:45 ` Kashyap Desai
2018-12-06 15:22 ` Jens Axboe
2018-12-07 7:16 ` Kashyap Desai
2018-12-07 10:20 ` Ming Lei
2018-12-07 10:34 ` Kashyap Desai
2018-12-11 15:06 ` Kashyap Desai
2018-12-14 6:22 ` Kashyap Desai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1543943674.185366.194.camel@acm.org \
--to=bvanassche@acm.org \
--cc=axboe@kernel.dk \
--cc=kashyap.desai@broadcom.com \
--cc=linux-block@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=ming.lei@redhat.com \
--cc=sathya.prakash@broadcom.com \
--cc=sreekanth.reddy@broadcom.com \
--cc=suganath-prabu.subramani@broadcom.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).