From: keith.busch@intel.com (Keith Busch)
Subject: [PATCHv2 1/3] nvme: Remove RCU namespace protection
Date: Tue, 28 Jun 2016 12:35:13 -0400 [thread overview]
Message-ID: <20160628163512.GB8607@localhost.localdomain> (raw)
In-Reply-To: <20160628083137.GA32618@infradead.org>
On Tue, Jun 28, 2016@01:31:37AM -0700, Christoph Hellwig wrote:
> > @@ -1656,10 +1662,8 @@ void nvme_remove_namespaces(struct nvme_ctrl *ctrl)
> > if (ctrl->state == NVME_CTRL_DEAD)
> > nvme_kill_queues(ctrl);
> >
> > - mutex_lock(&ctrl->namespaces_mutex);
> > list_for_each_entry_safe(ns, next, &ctrl->namespaces, list)
> > nvme_ns_remove(ns);
> > - mutex_unlock(&ctrl->namespaces_mutex);
>
> And this is the scary one - it does an unprotected
> list_for_each_entry_safe, and nvme_remove_namespaces isn't even called
> from the scan workqueue.
>
> I think this needs to be something like:
>
> mutex_lock(&ctrl->namespaces_mutex);
> list_splice_init(&ctrl->namespaces, &tmp);
> mutex_unlock(&ctrl->namespaces_mutex);
>
> list_for_each_entry_safe(ns, next, &tmp, list) {
> ..
>
> nvme_ns_remove(ns);
We actually can't do that. The namespace needs to be on ctrl->namespaces
during nvme_ns_remove because it does IO, and the controller can fail
during that IO. Every namespace needs to be on the ctrl's namespace
list until after del_gendisk completes so we can recover from potential
failures.
It does look concerning, but it's safe if the caller ensures no scan
work is or ever will be active. If that sounds okay or no alternative
exists, I can document this usage requirement in the code.
next prev parent reply other threads:[~2016-06-28 16:35 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-06-23 17:29 [PATCH 0/3] Namespace iteration fixes Keith Busch
2016-06-23 17:29 ` [PATCHv2 1/3] nvme: Remove RCU namespace protection Keith Busch
2016-06-28 8:31 ` Christoph Hellwig
2016-06-28 16:35 ` Keith Busch [this message]
2016-06-30 6:48 ` Christoph Hellwig
2016-06-30 14:57 ` Keith Busch
2016-06-30 22:59 ` Keith Busch
2016-06-23 17:29 ` [PATCH 2/3] nvme: Kill detached namespaces prior to removal Keith Busch
2016-06-28 8:32 ` Christoph Hellwig
2016-06-23 17:29 ` [PATCH 3/3] nvme: Put invalid namespaces on removal list Keith Busch
2016-06-28 8:32 ` Christoph Hellwig
2016-06-23 17:44 ` [PATCH 0/3] Namespace iteration fixes Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20160628163512.GB8607@localhost.localdomain \
--to=keith.busch@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox