linux-scsi.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Bart Van Assche <bvanassche@acm.org>
To: FUJITA Tomonori <fujita.tomonori@lab.ntt.co.jp>
Cc: linux-scsi@vger.kernel.org, brking@linux.vnet.ibm.com
Subject: Re: [PATCH 3/3] tcm ibmvscsis driver
Date: Tue, 15 Feb 2011 20:20:53 +0100	[thread overview]
Message-ID: <AANLkTimPyjgoSnZrSXT2asV1Ly5D3NFUM3cn0-Jmp3Zm@mail.gmail.com> (raw)
In-Reply-To: <20110215124208B.fujita.tomonori@lab.ntt.co.jp>

On Tue, Feb 15, 2011 at 4:42 AM, FUJITA Tomonori
<fujita.tomonori@lab.ntt.co.jp> wrote:
> On Mon, 14 Feb 2011 12:50:40 +0100
> Bart Van Assche <bvanassche@acm.org> wrote:
>
>> - send_rsp() sends back an SRP response with req_lim_delta = 1 before
>> srp_iu_put() is invoked. I think this is a race condition: it can
>> happen that the SRP initiator has received an SRP_RSP and sends a new
>> SRP_CMD before srp_iu_put() was invoked. On a heavily loaded system
>> that can trigger a queue overflow in the target.
>
> Yeah, we had better to handle such case better.
>
> But I don't think that we hit a critical event such as crash, memory
> corruption, etc, with the current code.
>
> In such case, srp_iu_get return NULL, so the target ignores the
> request, then eventually the initiator recovers.

Sorry but I do not agree that hitting this race is harmless. If this
race gets triggered the credit associated with the lost SRP
information unit will never be returned to the initiator. If this
happens frequently enough (INITIAL_SRP_LIMIT times), the initiator
will run out of credits and will lock up forever.

> Probably, we should set the queue size to INITIAL_SRP_LIMIT + 1.

With the current implementation of the SCSI storage target core that's
probably sufficient. But if that core is ever modified such that
multiple SCSI commands can be processed concurrently, that limit
wouldn't be sufficient anymore because then the described race
condition could be triggered in multiple threads simultaneously - at
least in theory.

An alternative solution is to modify send_iu() such that srp_iu_put()
is invoked after all relevant data has been copied via h_copy_rdma()
and to the CRQ and before h_send_crq() is invoked. That approach has
e.g. been implemented in this patch:
http://www.spinics.net/lists/linux-scsi/msg49105.html.

Bart.

  reply	other threads:[~2011-02-15 19:21 UTC|newest]

Thread overview: 81+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-02-10 12:21 [PATCH 0/3] ibmvscsis driver rewrite FUJITA Tomonori
2011-02-10 12:21 ` [PATCH 1/3] libsrp: add srp_data_length helper function FUJITA Tomonori
2011-02-10 12:21 ` [PATCH 2/3] libsrp: fix dma_unmap_sg FUJITA Tomonori
2011-02-10 12:21 ` [PATCH 3/3] tcm ibmvscsis driver FUJITA Tomonori
2011-02-10 19:03   ` Nicholas A. Bellinger
2011-02-14  1:36     ` FUJITA Tomonori
2011-02-14  3:26     ` FUJITA Tomonori
2011-02-14  9:01       ` Nicholas A. Bellinger
2011-02-14  9:29         ` FUJITA Tomonori
2011-02-14  9:27           ` Nicholas A. Bellinger
2011-02-14  9:46             ` FUJITA Tomonori
2011-02-14  9:51               ` Nicholas A. Bellinger
2011-02-10 19:15   ` Brian King
2011-02-10 19:38     ` Nicholas A. Bellinger
2011-02-11 21:13       ` Brian King
2011-02-12 20:27         ` James Bottomley
2011-03-07  4:41           ` FUJITA Tomonori
2011-03-07  6:17             ` Nicholas A. Bellinger
2011-03-07  6:24               ` FUJITA Tomonori
2011-03-07  6:55                 ` Nicholas A. Bellinger
2011-03-07 14:40             ` James Bottomley
2011-03-18 16:57               ` James Bottomley
2011-03-18 20:58               ` Brian King
2011-03-18 22:09                 ` Nicholas A. Bellinger
2011-03-19 14:32                 ` James Bottomley
2011-03-21  1:09                 ` FUJITA Tomonori
2011-03-21 12:56                   ` Brian King
2011-03-21 21:01                   ` Brian King
2011-03-21 21:01                     ` Nicholas A. Bellinger
2011-03-21 21:24                       ` Brian King
2011-03-21 22:29                         ` Nicholas A. Bellinger
2011-03-21 23:20                         ` FUJITA Tomonori
2011-03-21 23:50                           ` Nicholas A. Bellinger
2011-03-21 23:55                             ` FUJITA Tomonori
2011-03-22  0:26                               ` Nicholas A. Bellinger
2011-03-22  0:32                                 ` FUJITA Tomonori
2011-03-22  2:28                                   ` Nicholas A. Bellinger
2011-03-22  3:26                                     ` FUJITA Tomonori
2011-03-21 21:05                     ` James Bottomley
2011-03-21 22:37                       ` Brian King
2011-03-21 22:22                   ` Brian King
2011-03-21 22:31                     ` Brian King
2011-03-21 22:48                       ` Nicholas A. Bellinger
2011-03-22 12:53                         ` Brian King
2011-03-22 22:06                           ` Nicholas A. Bellinger
2011-03-22 22:49                             ` FUJITA Tomonori
2011-03-23  1:35                               ` Nicholas A. Bellinger
2011-03-23  5:12                                 ` FUJITA Tomonori
2011-03-23  8:26                                   ` Nicholas A. Bellinger
2011-03-23  8:48                                     ` FUJITA Tomonori
2011-03-23 10:00                                       ` Nicholas A. Bellinger
2011-03-23 12:04                                         ` FUJITA Tomonori
2011-03-23 21:17                                           ` Nicholas A. Bellinger
2011-03-24  1:54                                             ` FUJITA Tomonori
2011-03-24  7:29                                               ` Nicholas A. Bellinger
2011-03-23 15:19                             ` Brian King
2011-03-23 20:34                               ` Nicholas A. Bellinger
2011-03-25 14:33                                 ` Brian King
2011-03-25 20:13                                   ` Nicholas A. Bellinger
2011-03-21 22:34                     ` Nicholas A. Bellinger
2011-03-21 23:06                       ` FUJITA Tomonori
2011-03-21 23:13                         ` Nicholas A. Bellinger
2011-03-21 23:22                           ` FUJITA Tomonori
2011-03-22  0:03                             ` Nicholas A. Bellinger
2011-03-21 23:30                     ` FUJITA Tomonori
2011-02-14  1:42       ` FUJITA Tomonori
2011-02-14  1:42     ` FUJITA Tomonori
2011-02-14  7:16   ` Bart Van Assche
2011-02-14  9:11     ` FUJITA Tomonori
2011-02-14  9:18       ` Nicholas A. Bellinger
2011-02-14  9:19         ` Nicholas A. Bellinger
2011-02-14  9:31           ` FUJITA Tomonori
2011-02-14  9:29             ` Nicholas A. Bellinger
2011-02-14 11:50       ` Bart Van Assche
2011-02-15  3:42         ` FUJITA Tomonori
2011-02-15 19:20           ` Bart Van Assche [this message]
2011-02-15 23:21             ` FUJITA Tomonori
2011-02-10 18:34 ` [PATCH 0/3] ibmvscsis driver rewrite Nicholas A. Bellinger
2011-02-14  1:36   ` FUJITA Tomonori
2011-02-14  8:48     ` Nicholas A. Bellinger
     [not found] ` <4D53DE96.2020502@suse.de>
     [not found]   ` <1297363312.18212.153.camel@haakon2.linux-iscsi.org>
2011-02-10 21:22     ` Bart Van Assche

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=AANLkTimPyjgoSnZrSXT2asV1Ly5D3NFUM3cn0-Jmp3Zm@mail.gmail.com \
    --to=bvanassche@acm.org \
    --cc=brking@linux.vnet.ibm.com \
    --cc=fujita.tomonori@lab.ntt.co.jp \
    --cc=linux-scsi@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).