From: Mark Lord <lkml@rtr.ca>
To: Andrew Morton <akpm@linux-foundation.org>
Cc: Stephen Tweedie <sct@redhat.com>, "Theodore Ts'o" <tytso@mit.edu>,
Linux Kernel <linux-kernel@vger.kernel.org>
Subject: Re: ext3fs: umount+sync not enough to guarantee metadata-on-disk
Date: Thu, 07 Jun 2007 12:01:43 -0400 [thread overview]
Message-ID: <46682BE7.6080802@rtr.ca> (raw)
In-Reply-To: <20070607084142.42583639.akpm@linux-foundation.org>
Andrew Morton wrote:
> On Thu, 07 Jun 2007 09:44:24 -0400 Mark Lord <lkml@rtr.ca> wrote:
..
>> 2. When I trigger the shutdown whilst this is happening, Myth gets
>> killed off, and so the unlinked file is automatically closed.
>> and the kernel (filesystem) code begins finishing the delete operation.
>>
>> 3. The shutdown scripts do their thing quickly, so the delete is
>> *still* underway when the umount commands are issued.
>> On this system, I use this sequence:
>>
>> ## /var/lib/mythtv is the recording's ext3fs, on /dev/md0 (RAID0):
>
> I assume the applikcaton has already been killed at this stage, and it is
> blocked in the kernel running the truncate?
Yes, I believe I saw that once.
>> mount /var/lib/mythtv -oremount,ro
>> sync
>> umount /var/lib/mythtv
>
> Did this succeed? If the application is still truncating that file, the
> umount should have failed.
Actually, what I expect to happen is for the remount,ro
to block until the file deletion completes. But it doesn't.
Once a f/s is read-only, there should be NO writing to it. Right?
I don't know if the umount worked or not, but the f/s ought to be
read-only at this point, so why is it still writing to the device?
I'll instrument the shutdown more for next time, to see if the remount
and umount really do succeed or not. Mmm.. do they log anything on failure?
>> sync
>> mount / -oremount,ro
>> sync
>> sleep 1
>> hdparm -W0 /dev/sda /dev/sdb
>> sync
>> sleep 2
>> halt -f -p
>>
>> 4. The hard drive light is on solid throughout, including at the point
>> when the power goes out.
>>
>> 5. On the next reboot, there is a LONG pause (20-30 seconds) at the
>> point where /var/lib/mythtv is remounted --> indicating unfinished business
>> from the journal file that needs to be replayed (eg. the file deletion).
>
> That opened-but-deleted file's inode is on the orphan list.
>
> See, the unlink-then-slowly-truncate trick is done in this fashion so that
> if the box crashes during the slow unlink, the orhpan list handling on the
> reboot will finish off the truncate for us.
Yes, absolutely.
>> So.. how can I guarantee a quiescent filesystem before doing "halt -f -p" ??
>> This looks pretty dangerous as-is.
>
> Wait for the killed-off applicaiton to actually exit, perhaps? But
> that unmount should have failed.
But some applications just "hang" regardless, and so this cannot wait forever.
There must be *some* way to know when a filesystem is really quiescent
and therefore safe to power off?
Cheers
next prev parent reply other threads:[~2007-06-07 16:02 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-06-07 13:44 ext3fs: umount+sync not enough to guarantee metadata-on-disk Mark Lord
2007-06-07 15:41 ` Andrew Morton
2007-06-07 16:01 ` Mark Lord [this message]
2007-06-07 17:09 ` Stephen C. Tweedie
2007-06-10 18:27 ` Pavel Machek
2007-06-12 15:15 ` Stephen C. Tweedie
2007-06-14 19:01 ` Phillip Susi
2007-06-07 16:11 ` Chuck Ebbert
2007-06-07 19:45 ` Andrew Morton
2007-06-07 21:38 ` Mark Lord
2007-06-07 22:04 ` Andrew Morton
2007-06-08 14:51 ` Mark Lord
2007-06-09 2:58 ` Mark Lord
2007-06-11 11:14 ` Jan Kara
2007-06-11 22:47 ` Mark Lord
2007-06-12 10:00 ` Jan Kara
2007-06-07 21:43 ` Mark Lord
2007-06-10 18:31 ` Pavel Machek
2007-06-11 11:05 ` Jan Kara
2007-06-11 22:46 ` Mark Lord
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=46682BE7.6080802@rtr.ca \
--to=lkml@rtr.ca \
--cc=akpm@linux-foundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sct@redhat.com \
--cc=tytso@mit.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox