From: Jeff Layton <jlayton@kernel.org>
To: "Steve Dickson" <steved@redhat.com>,
"Mantas Mikulėnas" <grawity@gmail.com>
Cc: Chuck Lever <cel@kernel.org>,
linux-nfs@vger.kernel.org, Jeff Layton <jlayton@kernel.org>
Subject: [PATCH nfs-utils v3 10/11] mountd: bound the retry queues
Date: Mon, 14 Sep 2026 09:14:19 -0400 [thread overview]
Message-ID: <20260914-nl-crossmnt-v3-10-a984a6c94829@kernel.org> (raw)
In-Reply-To: <20260914-nl-crossmnt-v3-0-a984a6c94829@kernel.org>
A request is deferred when we cannot yet say whether its path or fsid is
exportable. lookup_fsid() defers on "!found && dev_missing", and
dev_missing counts any export whose "mountpoint" is not mounted, whatever
fsid was asked for. The fsid comes out of the filehandle the client sent,
so on a server with one unmounted mountpoint= export - the case this retry
logic exists for - every fsid a client invents gets a queue entry.
None of the three queues has a limit. The pre-existing "delayed" queue
nfsd_fh() feeds is the worst: it strndup()s the whole upcall message and
does not deduplicate at all, so even a repeated fsid allocates again.
delayed_export and delayed_expkey dedup, but still grow without end, and
the dedup walk makes each insertion O(n).
Cap all three at MAX_DELAYED and drop the new request once full. Queuing
is only an optimisation: the kernel repeats the upcall when the client
retries, so a dropped deferral costs latency, not correctness - the same
trade the existing allocation-failure paths already make.
The cap applies only where a record is created. nfsd_retry_fh(),
nl_retry_export() and nl_retry_expkey() re-queue a record they already
dequeued and own, and must not be refused.
nfsd_fh() had no dedup walk, so it gets a counting one; it ends at the tail
the append needs anyway.
Signed-off-by: Jeff Layton <jlayton@kernel.org>
Assisted-by: LLM
---
support/export/cache.c | 57 +++++++++++++++++++++++++++++++++++++++++++++-----
1 file changed, 52 insertions(+), 5 deletions(-)
diff --git a/support/export/cache.c b/support/export/cache.c
index 6c887cd50327..d1fef23a6c0f 100644
--- a/support/export/cache.c
+++ b/support/export/cache.c
@@ -777,6 +777,38 @@ static struct addrinfo *lookup_client_addr(char *dom)
}
#define RETRY_SEC 120
+
+/*
+ * Cap on each retry queue. A request is deferred when we cannot yet say
+ * whether its path or fsid is exportable, and the client picks the fsid out of
+ * the filehandle it sends, so the queues are reachable from the network: any
+ * export with an unmounted "mountpoint" makes lookup_fsid() defer every fsid it
+ * cannot match, invented ones included. Queuing is only an optimisation - the
+ * kernel repeats the upcall when the client retries - so refusing to grow past
+ * this costs latency, not correctness.
+ */
+#define MAX_DELAYED 1024
+
+/*
+ * Has the queue holding @count entries hit the cap? Warns once when it fills,
+ * and arms the warning again only once it has properly drained, so a queue
+ * sitting at the limit does not turn into a stream of log messages.
+ */
+static bool delayed_is_full(unsigned int count, bool *warned, const char *what)
+{
+ if (count < MAX_DELAYED / 2)
+ *warned = false;
+ if (count < MAX_DELAYED)
+ return false;
+
+ if (!*warned) {
+ *warned = true;
+ xlog(L_WARNING, "%s retry queue is full (%u), dropping requests;"
+ " the kernel will ask again", what, MAX_DELAYED);
+ }
+ return true;
+}
+
struct delayed {
char *message;
time_t last_attempt;
@@ -1008,8 +1040,10 @@ out:
static void nfsd_fh(int f)
{
+ static bool queue_full_warned;
struct delayed *d, **dp;
char inbuf[RPC_CHAN_BUF_SIZE];
+ unsigned int count = 0;
int blen;
blen = cache_read(f, inbuf, sizeof(inbuf));
@@ -1029,6 +1063,11 @@ static void nfsd_fh(int f)
* We cannot tell the kernel to retry, so we have to
* retry ourselves.
*/
+ for (dp = &delayed; *dp; dp = &(*dp)->next)
+ count++;
+ if (delayed_is_full(count, &queue_full_warned, "filehandle"))
+ return;
+
d = malloc(sizeof(*d));
if (!d)
@@ -1041,9 +1080,7 @@ static void nfsd_fh(int f)
d->f = f;
d->last_attempt = time(NULL);
d->next = NULL;
- dp = &delayed;
- while (*dp)
- dp = &(*dp)->next;
+ /* the count above left dp at the tail */
*dp = d;
}
@@ -2072,12 +2109,17 @@ static void delayed_export_remove(char *dom, char *path)
static void nl_delay_export(char *dom, char *path)
{
+ static bool queue_full_warned;
+ unsigned int count = 0;
struct delayed_export *d;
- for (d = delayed_export; d; d = d->next)
+ for (d = delayed_export; d; d = d->next, count++)
if (!strcmp(d->client, dom) && !strcmp(d->path, path))
return;
+ if (delayed_is_full(count, &queue_full_warned, "export"))
+ return;
+
d = calloc(1, sizeof(*d));
if (!d)
return;
@@ -2428,12 +2470,17 @@ static void delayed_expkey_remove(struct expkey_req *req)
static void nl_delay_expkey(struct expkey_req *req)
{
+ static bool queue_full_warned;
+ unsigned int count = 0;
struct delayed_expkey *d;
- for (d = delayed_expkey; d; d = d->next)
+ for (d = delayed_expkey; d; d = d->next, count++)
if (delayed_expkey_matches(d, req))
return;
+ if (delayed_is_full(count, &queue_full_warned, "fsid"))
+ return;
+
d = calloc(1, sizeof(*d));
if (!d)
return;
--
2.55.0
next prev parent reply other threads:[~2026-09-14 13:14 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 13:14 [PATCH nfs-utils v3 00/11] mountd: bugfixes for up/downcall interfaces Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 01/11] mountd: factor out the per-path export attribute computation Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 02/11] mountd: handle unmountable paths and junctions in the netlink downcall Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 03/11] mountd: answer requests the kernel rejects on " Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 04/11] mountd: don't leak the parent export's fsid onto crossmnt submounts Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 05/11] mountd: retry unresolvable fsid lookups on the netlink downcall Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 06/11] mountd: bound the junction path before copying it into e_path Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 07/11] mountd: give each worker its own netlink command socket Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 08/11] mountd: retry export attributes that fail to resolve for a passing reason Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 09/11] mountd: drop a deferred fsid lookup once it has been answered Jeff Layton
2026-09-14 13:14 ` Jeff Layton [this message]
2026-09-14 13:14 ` [PATCH nfs-utils v3 11/11] mountd: don't warn about pipefs submounts nobody asked to export Jeff Layton
2026-09-15 9:24 ` [PATCH nfs-utils v3 00/11] mountd: bugfixes for up/downcall interfaces Mantas Mikulėnas
2026-09-17 7:21 ` Steve Dickson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914-nl-crossmnt-v3-10-a984a6c94829@kernel.org \
--to=jlayton@kernel.org \
--cc=cel@kernel.org \
--cc=grawity@gmail.com \
--cc=linux-nfs@vger.kernel.org \
--cc=steved@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).