From: Ming Lei <ming.lei@redhat.com>
To: Jens Axboe <axboe@kernel.dk>
Cc: linux-block@vger.kernel.org, Hannes Reinecke <hare@suse.com>,
Keith Busch <keith.busch@intel.com>,
linux-nvme@lists.infradead.org, Sagi Grimberg <sagi@grimberg.me>,
James Smart <james.smart@broadcom.com>,
Ming Lei <ming.lei@redhat.com>,
Dongli Zhang <dongli.zhang@oracle.com>,
Bart Van Assche <bart.vanassche@wdc.com>,
linux-scsi@vger.kernel.org,
"Martin K . Petersen" <martin.petersen@oracle.com>,
Christoph Hellwig <hch@lst.de>,
"James E . J . Bottomley" <jejb@linux.vnet.ibm.com>
Subject: [PATCH V7 0/9] blk-mq: fix races related with freeing queue
Date: Wed, 24 Apr 2019 19:02:12 +0800 [thread overview]
Message-ID: <20190424110221.17435-1-ming.lei@redhat.com> (raw)
Hi,
Since 45a9c9d909b2 ("blk-mq: Fix a use-after-free"), run queue isn't
allowed during cleanup queue even though queue refcount is held.
This change has caused lots of kernel oops triggered in run queue path,
turns out it isn't easy to fix them all.
So move freeing of hw queue resources into hctx's release handler, then
the above issue is fixed. Meantime, this way is safe given freeing hw
queue resource doesn't require tags.
V3 covers more races.
V7:
- add reviewed-by and tested-by tag
- rename "dead_hctx" as "unused_hctx"
- check if there are live hctx in queue's release handler
- only patch 6 is modified
V6:
- remove previous SCSI patch which will be routed via SCSI tree
- add reviewed-by tag
- fix one related NVMe scan vs reset race
V5:
- refactor blk_mq_alloc_and_init_hctx()
- fix race related updating nr_hw_queues by always freeing hctx
after request queue is released
V4:
- add patch for fixing potential use-after-free in blk_mq_update_nr_hw_queues
- fix comment in the last patch
V3:
- cancel q->requeue_work in queue's release handler
- cancel hctx->run_work in hctx's release handler
- add patch 1 for fixing race in plug code path
- the last patch is added for avoiding to grab SCSI's refcont
in IO path
V2:
- moving freeing hw queue resources into hctx's release handler
Ming Lei (9):
blk-mq: grab .q_usage_counter when queuing request from plug code path
blk-mq: move cancel of requeue_work into blk_mq_release
blk-mq: free hw queue's resource in hctx's release handler
blk-mq: move all hctx alloction & initialization into
__blk_mq_alloc_and_init_hctx
blk-mq: split blk_mq_alloc_and_init_hctx into two parts
blk-mq: always free hctx after request queue is freed
blk-mq: move cancel of hctx->run_work into blk_mq_hw_sysfs_release
block: don't drain in-progress dispatch in blk_cleanup_queue()
nvme: hold request queue's refcount in ns's whole lifetime
block/blk-core.c | 23 +-----
block/blk-mq-sysfs.c | 8 ++
block/blk-mq.c | 199 ++++++++++++++++++++++++++++-------------------
block/blk-mq.h | 2 +-
drivers/nvme/host/core.c | 10 ++-
include/linux/blk-mq.h | 2 +
include/linux/blkdev.h | 7 ++
7 files changed, 148 insertions(+), 103 deletions(-)
Cc: Dongli Zhang <dongli.zhang@oracle.com>
Cc: James Smart <james.smart@broadcom.com>
Cc: Bart Van Assche <bart.vanassche@wdc.com>
Cc: linux-scsi@vger.kernel.org,
Cc: Martin K . Petersen <martin.petersen@oracle.com>,
Cc: Christoph Hellwig <hch@lst.de>,
Cc: James E . J . Bottomley <jejb@linux.vnet.ibm.com>,
--
2.9.5
next reply other threads:[~2019-04-24 11:02 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-04-24 11:02 Ming Lei [this message]
2019-04-24 11:02 ` [PATCH V7 1/9] blk-mq: grab .q_usage_counter when queuing request from plug code path Ming Lei
2019-04-24 16:18 ` Christoph Hellwig
2019-04-25 0:53 ` Ming Lei
2019-04-25 5:32 ` Christoph Hellwig
2019-04-25 7:35 ` Ming Lei
2019-04-24 11:02 ` [PATCH V7 2/9] blk-mq: move cancel of requeue_work into blk_mq_release Ming Lei
2019-04-24 16:18 ` Christoph Hellwig
2019-04-24 11:02 ` [PATCH V7 3/9] blk-mq: free hw queue's resource in hctx's release handler Ming Lei
2019-04-24 16:19 ` Christoph Hellwig
2019-04-24 11:02 ` [PATCH V7 4/9] blk-mq: move all hctx alloction & initialization into __blk_mq_alloc_and_init_hctx Ming Lei
2019-04-24 16:22 ` Christoph Hellwig
2019-04-25 0:55 ` Ming Lei
2019-04-26 15:09 ` Christoph Hellwig
2019-04-25 1:02 ` Ming Lei
2019-04-24 11:02 ` [PATCH V7 5/9] blk-mq: split blk_mq_alloc_and_init_hctx into two parts Ming Lei
2019-04-24 11:02 ` [PATCH V7 6/9] blk-mq: always free hctx after request queue is freed Ming Lei
2019-04-24 11:15 ` Hannes Reinecke
2019-04-24 11:02 ` [PATCH V7 7/9] blk-mq: move cancel of hctx->run_work into blk_mq_hw_sysfs_release Ming Lei
2019-04-24 11:02 ` [PATCH V7 8/9] block: don't drain in-progress dispatch in blk_cleanup_queue() Ming Lei
2019-04-24 11:02 ` [PATCH V7 9/9] nvme: hold request queue's refcount in ns's whole lifetime Ming Lei
2019-04-24 16:27 ` Christoph Hellwig
2019-04-25 1:00 ` Ming Lei
2019-04-26 15:11 ` Christoph Hellwig
2019-04-26 17:04 ` Bart Van Assche
2019-04-26 22:49 ` Ming Lei
2019-04-26 22:45 ` Ming Lei
2019-04-27 5:54 ` Christoph Hellwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190424110221.17435-1-ming.lei@redhat.com \
--to=ming.lei@redhat.com \
--cc=axboe@kernel.dk \
--cc=bart.vanassche@wdc.com \
--cc=dongli.zhang@oracle.com \
--cc=hare@suse.com \
--cc=hch@lst.de \
--cc=james.smart@broadcom.com \
--cc=jejb@linux.vnet.ibm.com \
--cc=keith.busch@intel.com \
--cc=linux-block@vger.kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).