From: Hannes Reinecke <hare@suse.de>
To: Daniel Wagner <wagi@kernel.org>,
James Smart <james.smart@broadcom.com>,
Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>,
Chaitanya Kulkarni <kch@nvidia.com>
Cc: Keith Busch <kbusch@kernel.org>,
linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v5 01/14] nvmet-fcloop: track ref counts for nports
Date: Thu, 24 Apr 2025 12:08:33 +0200 [thread overview]
Message-ID: <002aee76-9114-4029-85b3-aa04e8ef76ed@suse.de> (raw)
In-Reply-To: <20250423-nvmet-fcloop-v5-1-3d7f968728a5@kernel.org>
On 4/23/25 15:21, Daniel Wagner wrote:
> A nport object is always used in association with targerport,
> remoteport, tport and rport objects. Add explicit references for any of
> the associated object. This ensures that nport is not removed too early
> on shutdown sequences.
>
> Signed-off-by: Daniel Wagner <wagi@kernel.org>
> ---
> drivers/nvme/target/fcloop.c | 133 +++++++++++++++++++++++++++++--------------
> 1 file changed, 90 insertions(+), 43 deletions(-)
>
> diff --git a/drivers/nvme/target/fcloop.c b/drivers/nvme/target/fcloop.c
> index 641201e62c1bafa13986642c6c4067b35f784edd..2b23e43ef4403fa4d70c66263f7750165d2ddc72 100644
> --- a/drivers/nvme/target/fcloop.c
> +++ b/drivers/nvme/target/fcloop.c
> @@ -1047,8 +1047,14 @@ static void
> fcloop_remoteport_delete(struct nvme_fc_remote_port *remoteport)
> {
> struct fcloop_rport *rport = remoteport->private;
> + unsigned long flags;
>
> flush_work(&rport->ls_work);
> +
> + spin_lock_irqsave(&fcloop_lock, flags);
> + rport->nport->rport = NULL;
> + spin_unlock_irqrestore(&fcloop_lock, flags);
> +
> fcloop_nport_put(rport->nport);
> }
>
> @@ -1056,8 +1062,14 @@ static void
> fcloop_targetport_delete(struct nvmet_fc_target_port *targetport)
> {
> struct fcloop_tport *tport = targetport->private;
> + unsigned long flags;
>
> flush_work(&tport->ls_work);
> +
> + spin_lock_irqsave(&fcloop_lock, flags);
> + tport->nport->tport = NULL;
> + spin_unlock_irqrestore(&fcloop_lock, flags);
> +
> fcloop_nport_put(tport->nport);
> }
>
> @@ -1184,6 +1196,37 @@ __wait_localport_unreg(struct fcloop_lport *lport)
> return ret;
> }
>
> +static struct fcloop_nport *
> +__fcloop_nport_lookup(u64 node_name, u64 port_name)
> +{
> + struct fcloop_nport *nport;
> +
> + list_for_each_entry(nport, &fcloop_nports, nport_list) {
> + if (nport->node_name != node_name ||
> + nport->port_name != port_name)
> + continue;
> +
> + if (fcloop_nport_get(nport))
> + return nport;
> +
> + break;
> + }
> +
> + return NULL;
> +}
> +
> +static struct fcloop_nport *
> +fcloop_nport_lookup(u64 node_name, u64 port_name)
> +{
> + struct fcloop_nport *nport;
> + unsigned long flags;
> +
> + spin_lock_irqsave(&fcloop_lock, flags);
> + nport = __fcloop_nport_lookup(node_name, port_name);
> + spin_unlock_irqrestore(&fcloop_lock, flags);
> +
> + return nport;
> +}
>
> static ssize_t
> fcloop_delete_local_port(struct device *dev, struct device_attribute *attr,
> @@ -1365,6 +1408,8 @@ __unlink_remote_port(struct fcloop_nport *nport)
> {
> struct fcloop_rport *rport = nport->rport;
>
> + lockdep_assert_held(&fcloop_lock);
> +
> if (rport && nport->tport)
> nport->tport->remoteport = NULL;
> nport->rport = NULL;
> @@ -1377,9 +1422,6 @@ __unlink_remote_port(struct fcloop_nport *nport)
> static int
> __remoteport_unreg(struct fcloop_nport *nport, struct fcloop_rport *rport)
> {
> - if (!rport)
> - return -EALREADY;
> -
> return nvme_fc_unregister_remoteport(rport->remoteport);
> }
>
> @@ -1387,8 +1429,8 @@ static ssize_t
> fcloop_delete_remote_port(struct device *dev, struct device_attribute *attr,
> const char *buf, size_t count)
> {
> - struct fcloop_nport *nport = NULL, *tmpport;
> - static struct fcloop_rport *rport;
> + struct fcloop_nport *nport;
> + struct fcloop_rport *rport;
> u64 nodename, portname;
> unsigned long flags;
> int ret;
> @@ -1397,24 +1439,24 @@ fcloop_delete_remote_port(struct device *dev, struct device_attribute *attr,
> if (ret)
> return ret;
>
> - spin_lock_irqsave(&fcloop_lock, flags);
> -
> - list_for_each_entry(tmpport, &fcloop_nports, nport_list) {
> - if (tmpport->node_name == nodename &&
> - tmpport->port_name == portname && tmpport->rport) {
> - nport = tmpport;
> - rport = __unlink_remote_port(nport);
> - break;
> - }
> - }
> + nport = fcloop_nport_lookup(nodename, portname);
> + if (!nport)
> + return -ENOENT;
>
> + spin_lock_irqsave(&fcloop_lock, flags);
> + rport = __unlink_remote_port(nport);
> spin_unlock_irqrestore(&fcloop_lock, flags);
>
> - if (!nport)
> - return -ENOENT;
> + if (!rport) {
> + ret = -ENOENT;
> + goto out_nport_put;
> + }
>
> ret = __remoteport_unreg(nport, rport);
>
> +out_nport_put:
> + fcloop_nport_put(nport);
> +
> return ret ? ret : count;
> }
>
> @@ -1465,6 +1507,8 @@ __unlink_target_port(struct fcloop_nport *nport)
> {
> struct fcloop_tport *tport = nport->tport;
>
> + lockdep_assert_held(&fcloop_lock);
> +
> if (tport && nport->rport)
> nport->rport->targetport = NULL;
> nport->tport = NULL;
> @@ -1475,9 +1519,6 @@ __unlink_target_port(struct fcloop_nport *nport)
> static int
> __targetport_unreg(struct fcloop_nport *nport, struct fcloop_tport *tport)
> {
> - if (!tport)
> - return -EALREADY;
> -
> return nvmet_fc_unregister_targetport(tport->targetport);
> }
>
> @@ -1485,8 +1526,8 @@ static ssize_t
> fcloop_delete_target_port(struct device *dev, struct device_attribute *attr,
> const char *buf, size_t count)
> {
> - struct fcloop_nport *nport = NULL, *tmpport;
> - struct fcloop_tport *tport = NULL;
> + struct fcloop_nport *nport;
> + struct fcloop_tport *tport;
> u64 nodename, portname;
> unsigned long flags;
> int ret;
> @@ -1495,24 +1536,24 @@ fcloop_delete_target_port(struct device *dev, struct device_attribute *attr,
> if (ret)
> return ret;
>
> - spin_lock_irqsave(&fcloop_lock, flags);
> -
> - list_for_each_entry(tmpport, &fcloop_nports, nport_list) {
> - if (tmpport->node_name == nodename &&
> - tmpport->port_name == portname && tmpport->tport) {
> - nport = tmpport;
> - tport = __unlink_target_port(nport);
> - break;
> - }
> - }
> + nport = fcloop_nport_lookup(nodename, portname);
> + if (!nport)
> + return -ENOENT;
>
> + spin_lock_irqsave(&fcloop_lock, flags);
> + tport = __unlink_target_port(nport);
> spin_unlock_irqrestore(&fcloop_lock, flags);
>
Hmm. This now has a race condition; we're taking the lock
during lokup, drop the lock, take the lock again, and unlink
the port.
Please do a __fcloop_nport_lookup() function which doesn't
take a lock and avoid this race.
> - if (!nport)
> - return -ENOENT;
> + if (!tport) {
> + ret = -ENOENT;
> + goto out_nport_put;
> + }
>
> ret = __targetport_unreg(nport, tport);
>
> +out_nport_put:
> + fcloop_nport_put(nport);
> +
> return ret ? ret : count;
> }
>
> @@ -1609,8 +1650,8 @@ static int __init fcloop_init(void)
>
> static void __exit fcloop_exit(void)
> {
> - struct fcloop_lport *lport = NULL;
> - struct fcloop_nport *nport = NULL;
> + struct fcloop_lport *lport;
> + struct fcloop_nport *nport;
> struct fcloop_tport *tport;
> struct fcloop_rport *rport;
> unsigned long flags;
> @@ -1621,7 +1662,7 @@ static void __exit fcloop_exit(void)
> for (;;) {
> nport = list_first_entry_or_null(&fcloop_nports,
> typeof(*nport), nport_list);
> - if (!nport)
> + if (!nport || !fcloop_nport_get(nport))
> break;
>
> tport = __unlink_target_port(nport);
> @@ -1629,13 +1670,19 @@ static void __exit fcloop_exit(void)
>
> spin_unlock_irqrestore(&fcloop_lock, flags);
>
> - ret = __targetport_unreg(nport, tport);
> - if (ret)
> - pr_warn("%s: Failed deleting target port\n", __func__);
> + if (tport) {
> + ret = __targetport_unreg(nport, tport);
> + if (ret)
> + pr_warn("%s: Failed deleting target port\n", __func__);
> + }
>
And same here; don't drop the lock after lookup.
> - ret = __remoteport_unreg(nport, rport);
> - if (ret)
> - pr_warn("%s: Failed deleting remote port\n", __func__);
> + if (rport) {
> + ret = __remoteport_unreg(nport, rport);
> + if (ret)
> + pr_warn("%s: Failed deleting remote port\n", __func__);
> + }
> +
> + fcloop_nport_put(nport);
>
> spin_lock_irqsave(&fcloop_lock, flags);
> }
>
Cheers,
Hannes
--
Dr. Hannes Reinecke Kernel Storage Architect
hare@suse.de +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich
next prev parent reply other threads:[~2025-04-24 10:08 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-23 13:21 [PATCH v5 00/14] nvmet-fcloop: track resources via reference counting Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 01/14] nvmet-fcloop: track ref counts for nports Daniel Wagner
2025-04-24 10:08 ` Hannes Reinecke [this message]
2025-04-24 11:13 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 02/14] nvmet-fcloop: remove nport from list on last user Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 03/14] nvmet-fcloop: refactor fcloop_nport_alloc and track lport Daniel Wagner
2025-04-24 10:09 ` Hannes Reinecke
2025-04-23 13:21 ` [PATCH v5 04/14] nvmet-fcloop: refactor fcloop_delete_local_port Daniel Wagner
2025-04-24 10:10 ` Hannes Reinecke
2025-04-24 11:16 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 05/14] nvmet-fcloop: update refs on tfcp_req Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 06/14] nvmet-fcloop: add missing fcloop_callback_host_done Daniel Wagner
2025-04-24 10:13 ` Hannes Reinecke
2025-04-24 11:26 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 07/14] nvmet-fcloop: access fcpreq only when holding reqlock Daniel Wagner
2025-04-24 10:15 ` Hannes Reinecke
2025-04-24 11:31 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 08/14] nvmet-fcloop: prevent double port deletion Daniel Wagner
2025-04-24 10:17 ` Hannes Reinecke
2025-04-24 11:32 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 09/14] nvmet-fcloop: allocate/free fcloop_lsreq directly Daniel Wagner
2025-04-24 10:18 ` Hannes Reinecke
2025-05-07 10:48 ` kernel test robot
2025-04-23 13:21 ` [PATCH v5 10/14] nvmet-fcloop: don't wait for lport cleanup Daniel Wagner
2025-04-24 10:21 ` Hannes Reinecke
2025-04-24 11:48 ` Daniel Wagner
2025-04-24 12:10 ` Hannes Reinecke
2025-04-24 12:58 ` Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 11/14] nvmet-fcloop: drop response if targetport is gone Daniel Wagner
2025-04-24 10:21 ` Hannes Reinecke
2025-04-23 13:21 ` [PATCH v5 12/14] nvmet-fc: free pending reqs on tgtport unregister Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 13/14] nvmet-fc: take tgtport refs for portentry Daniel Wagner
2025-04-23 13:21 ` [PATCH v5 14/14] nvme-fc: do not reference lsrsp after failure Daniel Wagner
2025-05-06 16:36 ` [PATCH v5 00/14] nvmet-fcloop: track resources via reference counting Daniel Wagner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=002aee76-9114-4029-85b3-aa04e8ef76ed@suse.de \
--to=hare@suse.de \
--cc=hch@lst.de \
--cc=james.smart@broadcom.com \
--cc=kbusch@kernel.org \
--cc=kch@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
--cc=wagi@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox