From: Eric Dumazet <edumazet@google.com>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Willem de Bruijn <willemb@google.com>,
netdev@vger.kernel.org, eric.dumazet@gmail.com,
Eric Dumazet <edumazet@google.com>,
stable@vger.kernel.org, Alexander Aring <aahringo@redhat.com>,
David Teigland <teigland@redhat.com>
Subject: [PATCH v2 net-next 1/9] dlm: fix send buffer backpressure handling
Date: Thu, 24 Sep 2026 13:47:21 +0000 [thread overview]
Message-ID: <20260924134729.2047213-2-edumazet@google.com> (raw)
In-Reply-To: <20260924134729.2047213-1-edumazet@google.com>
lowcomms.c tests and clears SOCKWQ_ASYNC_NOSPACE in con->sock->flags,
but this bit has not been stored there for ten years.
Commit 9cd3e072b0be ("net: rename SOCK_ASYNC_NOSPACE and
SOCK_ASYNC_WAITDATA") mechanically renamed the two dlm users, then
commit ceb5d58b2170 ("net: fix sock_wake_async() rcu protection") moved
the bit from socket->flags to the RCU protected socket_wq->flags, where
it is reachable only through sk_set_bit() and sk_clear_bit(), and is
only maintained for sockets having SOCK_FASYNC set. dlm uses kernel
sockets, which never have SOCK_FASYNC set, and never sets the bit
itself, so the test in send_to_sock() has been false ever since.
The consequence is that when sock_sendmsg() returns -EAGAIN because the
socket send buffer is full, dlm no longer sets CF_APP_LIMITED, does not
increment sk_write_pending, and does not return DLM_IO_END to wait for
lowcomms_write_space(). It returns DLM_IO_RESCHED instead, and
process_send_sockets() immediately requeues the send work. A connection
to a peer that is slow to drain thus keeps cycling through
sock_sendmsg() and -EAGAIN, burning CPU, instead of sleeping until TCP
reports that space is available again.
Test SOCK_NOSPACE instead. This is the bit that lives in socket->flags,
that TCP sets whenever sendmsg() returns -EAGAIN for lack of send buffer
space (tcp_sendmsg_locked() and sk_stream_wait_memory()), and that
lowcomms_write_space() already clears. This restores the semantics dlm
had before the bit moved.
Also remove the clear_bit() of SOCKWQ_ASYNC_NOSPACE from
lowcomms_write_space(), for the same reason.
SCTP connections are deliberately left as they are. SCTP does not set
SOCK_NOSPACE, and it never calls sk->sk_write_space(): sctp_wfree() ends
up in sctp_wake_up_waiters(), which calls sctp_write_space() directly.
lowcomms_write_space() is thus never invoked for an SCTP connection, and
the test added here stays false, so send_to_sock() keeps returning
DLM_IO_RESCHED as it does today. This is the only safe behavior, as
returning DLM_IO_END would wait for a callback that never comes.
Fixes: ceb5d58b2170 ("net: fix sock_wake_async() rcu protection")
Cc: stable@vger.kernel.org
Cc: Alexander Aring <aahringo@redhat.com>
Cc: David Teigland <teigland@redhat.com>
Acked-by: Alexander Aring <aahringo@redhat.com>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
fs/dlm/lowcomms.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/fs/dlm/lowcomms.c b/fs/dlm/lowcomms.c
index 2aff1c7c17de49c41f9fd02a1fae00bcc9e6af5b..abe9ae4c643fae061d2e168c03219a4f4e1bc007 100644
--- a/fs/dlm/lowcomms.c
+++ b/fs/dlm/lowcomms.c
@@ -522,10 +522,8 @@ static void lowcomms_write_space(struct sock *sk)
clear_bit(SOCK_NOSPACE, &con->sock->flags);
spin_lock_bh(&con->writequeue_lock);
- if (test_and_clear_bit(CF_APP_LIMITED, &con->flags)) {
+ if (test_and_clear_bit(CF_APP_LIMITED, &con->flags))
con->sock->sk->sk_write_pending--;
- clear_bit(SOCKWQ_ASYNC_NOSPACE, &con->sock->flags);
- }
lowcomms_queue_swork(con);
spin_unlock_bh(&con->writequeue_lock);
@@ -1391,7 +1389,7 @@ static int send_to_sock(struct connection *con)
if (ret == -EAGAIN || ret == 0) {
lock_sock(con->sock->sk);
spin_lock_bh(&con->writequeue_lock);
- if (test_bit(SOCKWQ_ASYNC_NOSPACE, &con->sock->flags) &&
+ if (test_bit(SOCK_NOSPACE, &con->sock->flags) &&
!test_and_set_bit(CF_APP_LIMITED, &con->flags)) {
/* Notify TCP that we're limited by the
* application window size.
--
2.56.0.rc1.310.g51773c2048-goog
next prev parent reply other threads:[~2026-09-24 13:47 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 13:47 [PATCH v2 net-next 0/9] tcp: avoid struct socket cache line miss in tcp_check_space() Eric Dumazet
2026-09-24 13:47 ` Eric Dumazet [this message]
2026-09-25 13:49 ` [PATCH v2 net-next 1/9] dlm: fix send buffer backpressure handling netdev-bot+sashiko
2026-09-24 13:47 ` [PATCH v2 net-next 2/9] net: add sk_set_nospace() and sk_clear_nospace() Eric Dumazet
2026-09-25 13:49 ` netdev-bot+sashiko
2026-09-24 13:47 ` [PATCH v2 net-next 3/9] sunrpc: use " Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 4/9] rds: use sk_set_nospace() Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 5/9] dlm: use sk_set_nospace() and sk_clear_nospace() Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 6/9] drbd: use sk_set_nospace() Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 7/9] nvme-tcp: use sk_clear_nospace() Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 8/9] libceph: " Eric Dumazet
2026-09-24 13:47 ` [PATCH v2 net-next 9/9] tcp: add tp->tcp_nospace Eric Dumazet
2026-09-29 1:18 ` [PATCH v2 net-next 0/9] tcp: avoid struct socket cache line miss in tcp_check_space() Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924134729.2047213-2-edumazet@google.com \
--to=edumazet@google.com \
--cc=aahringo@redhat.com \
--cc=davem@davemloft.net \
--cc=eric.dumazet@gmail.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
--cc=teigland@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox