From: Jan Kara <jack@suse.cz>
To: Ross Zwisler <ross.zwisler@linux.intel.com>
Cc: Jan Kara <jack@suse.cz>, Dan Williams <dan.j.williams@intel.com>,
Dave Chinner <david@fromorbit.com>,
Matthew Wilcox <willy@linux.intel.com>,
Christoph Hellwig <hch@infradead.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Andrew Morton <akpm@linux-foundation.org>,
Jan Kara <jack@suse.com>,
linux-fsdevel <linux-fsdevel@vger.kernel.org>,
linux-nvdimm <linux-nvdimm@ml01.01.org>
Subject: Re: [PATCH 2/2] dax: fix bdev NULL pointer dereferences
Date: Thu, 4 Feb 2016 21:29:57 +0100 [thread overview]
Message-ID: <20160204202957.GB6895@quack.suse.cz> (raw)
In-Reply-To: <20160204195619.GA31860@linux.intel.com>
On Thu 04-02-16 12:56:19, Ross Zwisler wrote:
> On Wed, Feb 03, 2016 at 11:46:11AM +0100, Jan Kara wrote:
> > On Tue 02-02-16 10:34:56, Ross Zwisler wrote:
> > > On Tue, Feb 02, 2016 at 09:10:24AM -0800, Dan Williams wrote:
> > > > On Tue, Feb 2, 2016 at 8:46 AM, Jan Kara <jack@suse.cz> wrote:
> > > > > On Tue 02-02-16 08:33:56, Dan Williams wrote:
> > > > >> On Tue, Feb 2, 2016 at 3:17 AM, Jan Kara <jack@suse.cz> wrote:
> > > > >> [..]
> > > > >> > I see, thanks for explanation. So I'm OK with changing what is stored in
> > > > >> > the radix tree to accommodate this use case but my reservation that we IHMO
> > > > >> > have other more pressing things to fix remains...
> > > > >>
> > > > >> We don't need pfns in the radix to support XFS RT configurations.
> > > > >> Just call get_blocks() again and use the sector, or am I missing
> > > > >> something?
> > > > >
> > > > > You are correct. But if you decide to pay the cost of additional
> > > > > get_block() call, you only need the dirty tag in the radix tree and nothing
> > > > > else. So my understanding was that the whole point of games with radix tree
> > > > > is avoiding this extra get_block() calls for fsync().
> > > > >
> > > >
> > > > DAX-fsync() is already a potentially expensive operation to cover data
> > > > durability guarantees for DAX-unaware applications. A DAX-aware
> > > > application is going to skip fsync, and the get_blocks() cost, to do
> > > > cache management itself.
> > > >
> > > > Willy pointed out some other potential benefits, assuming a suitable
> > > > replacement for the protections afforded by the block-device
> > > > percpu_ref counter can be found. However, optimizing for the
> > > > DAX-unaware-application case seems the wrong motivation to me.
> > >
> > > Oh, no, the primary issue with calling get_block() in the fsync path isn't
> > > performance. It's that we don't have any idea what get_block() function to
> > > call.
> > >
> > > The fault handler calls all come from the filesystem directly, so they can
> > > easily give us an appropriate get_block() function pointer. But the
> > > dax_writeback_mapping_range() calls come from the generic code in
> > > mm/filemap.c, and don't know what get_block() to pass in.
> > >
> > > During one iteration I had the calls to dax_writeback_mapping_range()
> > > happening in the filesystem fsync code so that it could pass in get_block(),
> > > but Dave Chinner pointed out that this misses other paths in the filesystem
> > > that need to have things flushed via a call to filemap_write_and_wait_range().
> >
> > Let's clear this up a bit: The problem with using ->fsync() method is that
> > it doesn't get called for sync(2). We could use ->sync_fs() to flush caches
> > in case of sync(2) (that's what's happening for normal storage) but the
> > problem with PMEM is that "flush all cached data" operation effectively
> > means iterate through all modified pages and we didn't want to implement
> > this for DAX fsync code.
> >
> > So we have decided to do cache flushing for DAX at a different point - mark
> > inodes which may have writes cached as dirty and use writeback code for the
> > cache flushing. But looking at it now, we have actually chosen a wrong
> > place to do the flushing in the writeback path - note that sync(2) writes
> > data via __writeback_single_inode() -> do_writepages() and thus doesn't
> > even get to filemap_write_and_wait().
> >
> > So revisiting the decision I see two options:
> >
> > 1) Move the DAX flushing code from filemap_write_and_wait() into
> > ->writepages() fs callback. There the filesystem can provide all the
> > information it needs including bdev, get_block callback, or whatever.
> >
> > 2) Back out even further and implement own tracking and iteration of inodes
> > to write.
> >
> > So far I still think 2) is not worth the complexity (although it would
> > bring DAX code closer to how things behave with standard storage) so I
> > would go for 1).
>
> Jan, just to clarify, are you proposing this change for v4.5 in the remaining
> RCs as an alternative to the get_bdev() patch?
>
> https://lkml.org/lkml/2016/2/2/941
Yes, because I don't think anything like ->get_bdev() is needed at all.
Look: dax_do_io(), __dax_fault(), __dax_pmd_fault(), dax_zero_page_range()
don't really need bdev - we have agreed that get_block() fills that in just
fine.
dax_clear_blocks() has IMO just the wrong signature - it should take bdev
and not inode as an argument. Because combination inode + bdev sector
doesn't really make much sense.
dax_writeback_mapping_range() is the only remaining offender and it can
easily take bdev as an argument when called from ->writepages().
> Or can we move forward with get_bdev(), and try and figure out this new way of
> calling fsync/msync for v4.6? My main concern here is that changing how the
> DAX sync code gets called will affect all three filesystems as well as MM, and
> that it might be too much for RC inclusion...
I think changes aren't very intrusive so we can feed them in during RC
phase and frankly, you have to move to using ->writepages() anyway to make
sync(2) work reliably.
Honza
--
Jan Kara <jack@suse.com>
SUSE Labs, CR
next prev parent reply other threads:[~2016-02-04 20:29 UTC|newest]
Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-01-28 19:35 [PATCH 1/2] block: fix pfn_mkwrite() DAX fault handler Ross Zwisler
2016-01-28 19:35 ` [PATCH 2/2] dax: fix bdev NULL pointer dereferences Ross Zwisler
2016-01-28 20:21 ` Dan Williams
2016-01-28 21:38 ` Christoph Hellwig
2016-01-29 18:28 ` Ross Zwisler
2016-01-29 23:34 ` Ross Zwisler
2016-01-30 0:18 ` Dan Williams
2016-01-31 22:44 ` Dave Chinner
2016-01-30 5:28 ` Matthew Wilcox
2016-01-30 6:01 ` Dan Williams
2016-01-30 7:08 ` Jared Hulbert
2016-01-31 2:32 ` Matthew Wilcox
2016-01-31 6:12 ` Ross Zwisler
2016-01-31 10:55 ` Matthew Wilcox
2016-01-31 16:38 ` Dan Williams
2016-01-31 18:07 ` Matthew Wilcox
2016-01-31 18:18 ` Dan Williams
2016-01-31 18:27 ` Matthew Wilcox
2016-01-31 18:50 ` Dan Williams
2016-01-31 19:51 ` Dan Williams
2016-02-01 13:44 ` Matthew Wilcox
2016-02-01 14:51 ` Jan Kara
2016-02-01 20:49 ` Matthew Wilcox
2016-02-01 21:47 ` Dave Chinner
2016-02-02 6:06 ` Jared Hulbert
2016-02-02 6:46 ` Dan Williams
2016-02-02 8:05 ` Jared Hulbert
2016-02-02 16:51 ` Dan Williams
2016-02-02 21:46 ` Jared Hulbert
2016-02-03 0:34 ` Matthew Wilcox
2016-02-03 1:21 ` Jared Hulbert
2016-02-02 11:17 ` Jan Kara
2016-02-02 16:33 ` Dan Williams
2016-02-02 16:46 ` Jan Kara
2016-02-02 17:10 ` Dan Williams
2016-02-02 17:34 ` Ross Zwisler
2016-02-02 17:46 ` Dan Williams
2016-02-02 17:47 ` Dan Williams
2016-02-02 18:24 ` Ross Zwisler
2016-02-02 18:46 ` Matthew Wilcox
2016-02-02 18:59 ` Dan Williams
2016-02-02 20:14 ` Matthew Wilcox
2016-02-03 11:09 ` Jan Kara
2016-02-03 10:46 ` Jan Kara
2016-02-03 20:13 ` Ross Zwisler
2016-02-04 9:15 ` Jan Kara
2016-02-04 23:38 ` Ross Zwisler
2016-02-06 23:15 ` Dave Chinner
2016-02-07 5:27 ` Ross Zwisler
2016-02-04 19:56 ` Ross Zwisler
2016-02-04 20:29 ` Jan Kara [this message]
2016-02-04 22:19 ` Ross Zwisler
2016-02-05 22:25 ` Ross Zwisler
2016-02-06 23:40 ` Dave Chinner
2016-02-07 6:43 ` Ross Zwisler
2016-02-08 13:48 ` Jan Kara
2016-02-07 8:38 ` Christoph Hellwig
2016-02-08 15:55 ` Ross Zwisler
2016-02-02 18:41 ` Ross Zwisler
2016-02-02 18:53 ` Ross Zwisler
2016-02-02 0:02 ` Ross Zwisler
2016-02-02 7:10 ` Dave Chinner
2016-02-02 10:34 ` Jan Kara
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160204202957.GB6895@quack.suse.cz \
--to=jack@suse.cz \
--cc=akpm@linux-foundation.org \
--cc=dan.j.williams@intel.com \
--cc=david@fromorbit.com \
--cc=hch@infradead.org \
--cc=jack@suse.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nvdimm@ml01.01.org \
--cc=ross.zwisler@linux.intel.com \
--cc=viro@zeniv.linux.org.uk \
--cc=willy@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).