linux-nfs.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Jeff Layton <jlayton@kernel.org>
To: "Steve Dickson" <steved@redhat.com>,
	"Mantas Mikulėnas" <grawity@gmail.com>
Cc: Chuck Lever <cel@kernel.org>,
	linux-nfs@vger.kernel.org,  Jeff Layton <jlayton@kernel.org>
Subject: [PATCH nfs-utils v3 10/11] mountd: bound the retry queues
Date: Mon, 14 Sep 2026 09:14:19 -0400	[thread overview]
Message-ID: <20260914-nl-crossmnt-v3-10-a984a6c94829@kernel.org> (raw)
In-Reply-To: <20260914-nl-crossmnt-v3-0-a984a6c94829@kernel.org>

A request is deferred when we cannot yet say whether its path or fsid is
exportable.  lookup_fsid() defers on "!found && dev_missing", and
dev_missing counts any export whose "mountpoint" is not mounted, whatever
fsid was asked for.  The fsid comes out of the filehandle the client sent,
so on a server with one unmounted mountpoint= export - the case this retry
logic exists for - every fsid a client invents gets a queue entry.

None of the three queues has a limit.  The pre-existing "delayed" queue
nfsd_fh() feeds is the worst: it strndup()s the whole upcall message and
does not deduplicate at all, so even a repeated fsid allocates again.
delayed_export and delayed_expkey dedup, but still grow without end, and
the dedup walk makes each insertion O(n).

Cap all three at MAX_DELAYED and drop the new request once full.  Queuing
is only an optimisation: the kernel repeats the upcall when the client
retries, so a dropped deferral costs latency, not correctness - the same
trade the existing allocation-failure paths already make.

The cap applies only where a record is created.  nfsd_retry_fh(),
nl_retry_export() and nl_retry_expkey() re-queue a record they already
dequeued and own, and must not be refused.

nfsd_fh() had no dedup walk, so it gets a counting one; it ends at the tail
the append needs anyway.

Signed-off-by: Jeff Layton <jlayton@kernel.org>
Assisted-by: LLM
---
 support/export/cache.c | 57 +++++++++++++++++++++++++++++++++++++++++++++-----
 1 file changed, 52 insertions(+), 5 deletions(-)

diff --git a/support/export/cache.c b/support/export/cache.c
index 6c887cd50327..d1fef23a6c0f 100644
--- a/support/export/cache.c
+++ b/support/export/cache.c
@@ -777,6 +777,38 @@ static struct addrinfo *lookup_client_addr(char *dom)
 }
 
 #define RETRY_SEC 120
+
+/*
+ * Cap on each retry queue.  A request is deferred when we cannot yet say
+ * whether its path or fsid is exportable, and the client picks the fsid out of
+ * the filehandle it sends, so the queues are reachable from the network: any
+ * export with an unmounted "mountpoint" makes lookup_fsid() defer every fsid it
+ * cannot match, invented ones included.  Queuing is only an optimisation - the
+ * kernel repeats the upcall when the client retries - so refusing to grow past
+ * this costs latency, not correctness.
+ */
+#define MAX_DELAYED 1024
+
+/*
+ * Has the queue holding @count entries hit the cap?  Warns once when it fills,
+ * and arms the warning again only once it has properly drained, so a queue
+ * sitting at the limit does not turn into a stream of log messages.
+ */
+static bool delayed_is_full(unsigned int count, bool *warned, const char *what)
+{
+	if (count < MAX_DELAYED / 2)
+		*warned = false;
+	if (count < MAX_DELAYED)
+		return false;
+
+	if (!*warned) {
+		*warned = true;
+		xlog(L_WARNING, "%s retry queue is full (%u), dropping requests;"
+		     " the kernel will ask again", what, MAX_DELAYED);
+	}
+	return true;
+}
+
 struct delayed {
 	char *message;
 	time_t last_attempt;
@@ -1008,8 +1040,10 @@ out:
 
 static void nfsd_fh(int f)
 {
+	static bool queue_full_warned;
 	struct delayed *d, **dp;
 	char inbuf[RPC_CHAN_BUF_SIZE];
+	unsigned int count = 0;
 	int blen;
 
 	blen = cache_read(f, inbuf, sizeof(inbuf));
@@ -1029,6 +1063,11 @@ static void nfsd_fh(int f)
 	 * We cannot tell the kernel to retry, so we have to
 	 * retry ourselves.
 	 */
+	for (dp = &delayed; *dp; dp = &(*dp)->next)
+		count++;
+	if (delayed_is_full(count, &queue_full_warned, "filehandle"))
+		return;
+
 	d = malloc(sizeof(*d));
 
 	if (!d)
@@ -1041,9 +1080,7 @@ static void nfsd_fh(int f)
 	d->f = f;
 	d->last_attempt = time(NULL);
 	d->next = NULL;
-	dp = &delayed;
-	while (*dp)
-		dp = &(*dp)->next;
+	/* the count above left dp at the tail */
 	*dp = d;
 }
 
@@ -2072,12 +2109,17 @@ static void delayed_export_remove(char *dom, char *path)
 
 static void nl_delay_export(char *dom, char *path)
 {
+	static bool queue_full_warned;
+	unsigned int count = 0;
 	struct delayed_export *d;
 
-	for (d = delayed_export; d; d = d->next)
+	for (d = delayed_export; d; d = d->next, count++)
 		if (!strcmp(d->client, dom) && !strcmp(d->path, path))
 			return;
 
+	if (delayed_is_full(count, &queue_full_warned, "export"))
+		return;
+
 	d = calloc(1, sizeof(*d));
 	if (!d)
 		return;
@@ -2428,12 +2470,17 @@ static void delayed_expkey_remove(struct expkey_req *req)
 
 static void nl_delay_expkey(struct expkey_req *req)
 {
+	static bool queue_full_warned;
+	unsigned int count = 0;
 	struct delayed_expkey *d;
 
-	for (d = delayed_expkey; d; d = d->next)
+	for (d = delayed_expkey; d; d = d->next, count++)
 		if (delayed_expkey_matches(d, req))
 			return;
 
+	if (delayed_is_full(count, &queue_full_warned, "fsid"))
+		return;
+
 	d = calloc(1, sizeof(*d));
 	if (!d)
 		return;

-- 
2.55.0


  parent reply	other threads:[~2026-09-14 13:14 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-14 13:14 [PATCH nfs-utils v3 00/11] mountd: bugfixes for up/downcall interfaces Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 01/11] mountd: factor out the per-path export attribute computation Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 02/11] mountd: handle unmountable paths and junctions in the netlink downcall Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 03/11] mountd: answer requests the kernel rejects on " Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 04/11] mountd: don't leak the parent export's fsid onto crossmnt submounts Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 05/11] mountd: retry unresolvable fsid lookups on the netlink downcall Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 06/11] mountd: bound the junction path before copying it into e_path Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 07/11] mountd: give each worker its own netlink command socket Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 08/11] mountd: retry export attributes that fail to resolve for a passing reason Jeff Layton
2026-09-14 13:14 ` [PATCH nfs-utils v3 09/11] mountd: drop a deferred fsid lookup once it has been answered Jeff Layton
2026-09-14 13:14 ` Jeff Layton [this message]
2026-09-14 13:14 ` [PATCH nfs-utils v3 11/11] mountd: don't warn about pipefs submounts nobody asked to export Jeff Layton
2026-09-15  9:24 ` [PATCH nfs-utils v3 00/11] mountd: bugfixes for up/downcall interfaces Mantas Mikulėnas
2026-09-17  7:21 ` Steve Dickson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260914-nl-crossmnt-v3-10-a984a6c94829@kernel.org \
    --to=jlayton@kernel.org \
    --cc=cel@kernel.org \
    --cc=grawity@gmail.com \
    --cc=linux-nfs@vger.kernel.org \
    --cc=steved@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).