Linux NFS development
 help / color / mirror / Atom feed
* [PATCH v2 0/3] NFS: don't release an open context from writeback
@ 2026-09-28 18:57 Mike Snitzer
  2026-09-28 18:57 ` [PATCH v2 1/3] NFS: don't release the open context of a failed write " Mike Snitzer
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Mike Snitzer @ 2026-09-28 18:57 UTC (permalink / raw)
  To: Trond Myklebust, Anna Schumaker; +Cc: linux-nfs

v1 deferred the final deactivate_super() in nfs_sb_deactive() to nfsiod:
https://lore.kernel.org/linux-nfs/20260911184239.90154-1-snitzer@kernel.org/

Feedback on v1 was that it worked around the problem rather than fixing
it. That is fair: v1 made the last step of releasing an open context
safe to run from writeback, when the problem is that writeback releases
the open context at all. Testing bears that out, see below: with v1
applied the flusher still deadlocks, one step earlier, on I_SYNC.

Releasing an open context closes NFSv4 state and drops what may be the
last reference to the dentry, the inode and the superblock. The flusher
holds sb->s_umount and has set I_SYNC on the inode, so it can end up
waiting for itself on either. Writes normally avoid this because their
requests are released by the RPC release callback, on nfsiod. This
series fixes the three ways writeback does not:

Patch 1: a write that fails before it is sent is completed by
nfs_write_error() in the submitter. This is the deadlock that was hit
in the field, on a client whose server began returning AUTH_TOOWEAK.

Patch 2: nfs_initiate_pgio() and nfs_initiate_commit() drop their task
reference with rpc_put_task(), which runs the release callback in the
submitter if the task has already completed. This is the deadlock that
NeilBrown reported in 2014:
https://lore.kernel.org/linux-nfs/20140407135001.56ef9f36@notabene.brown/

Patch 3: the asynchronous LAYOUTCOMMIT that ->write_inode() sends has
the same problem as patch 2, with an inode and superblock reference of
its own in place of an open context, and no workqueue at all.

All three move the release to nfsiod, where every other write already
does it. None changes how or when a filesystem is shut down, and
nfs_sb_deactive() is left as it is.

Testing: NFSv3 over loopback, with a test-only knob that makes
nfs_do_writepage() see -EACCES in the pageio descriptor. Dirty a file
through a mapping after closing it, unmount, and let the periodic
flusher write it back. A plain umount is enough to leave the write
requests as the only thing keeping the superblock alive.

                  plain file           sillyrenamed file
  v1              shuts down, from     flusher hangs in evict(),
                  v1's work item       waiting for I_SYNC

  this series     shuts down, from     shuts down, from the release
                  the context's        of the sillyrename REMOVE
                  work item

Patches 2 and 3 close races and were not exercised by this test.

Changes since v1:
- Dropped "NFS: defer the final superblock deactivation".
- Fix the three places that release such references from writeback
  instead.
- Patch 1 carries a Fixes: tag; v1 had none.

Mike Snitzer (3):
  NFS: don't release the open context of a failed write from writeback
  NFS: don't run the release of a WRITE or COMMIT in the submitter
  NFSv4/pnfs: don't run the release of a LAYOUTCOMMIT in the submitter

 fs/nfs/inode.c         | 37 ++++++++++++++++++++++++++++++++++---
 fs/nfs/internal.h      |  1 +
 fs/nfs/nfs4proc.c      |  7 ++++++-
 fs/nfs/pagelist.c      |  3 ++-
 fs/nfs/write.c         |  8 +++++++-
 include/linux/nfs_fs.h |  2 ++
 6 files changed, 52 insertions(+), 6 deletions(-)


base-commit: 82e951e8628cdc0a5434c6f71ff1566b20e9912c
-- 
2.52.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-28 18:57 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 18:57 [PATCH v2 0/3] NFS: don't release an open context from writeback Mike Snitzer
2026-09-28 18:57 ` [PATCH v2 1/3] NFS: don't release the open context of a failed write " Mike Snitzer
2026-09-28 18:57 ` [PATCH v2 2/3] NFS: don't run the release of a WRITE or COMMIT in the submitter Mike Snitzer
2026-09-28 18:57 ` [PATCH v2 3/3] NFSv4/pnfs: don't run the release of a LAYOUTCOMMIT " Mike Snitzer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox