From: Allison Henderson <achender@kernel.org>
To: Ren Wei <n05ec@lzu.edu.cn>,
netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
rds-devel@oss.oracle.com
Cc: davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, horms@kernel.org,
santosh.shilimkar@oracle.com, sowmini.varadhan@oracle.com,
willemb@google.com, yuantan098@gmail.com, yifanwucs@gmail.com,
tomapufckgml@gmail.com, bird@lzu.edu.cn, lx24@stu.ynu.edu.cn,
tonanli66@gmail.com
Subject: Re: [PATCH net 1/1] net/rds: handle zerocopy send cleanup before the message is queued
Date: Fri, 01 May 2026 12:40:26 -0700 [thread overview]
Message-ID: <87f79bc7483aa1a7b3a44718b62a5cd5bd016f8c.camel@kernel.org> (raw)
In-Reply-To: <d2ea98a6313d5467bac00f7c9fef8c7acddb9258.1777550074.git.tonanli66@gmail.com>
On Fri, 2026-05-01 at 09:08 +0800, Ren Wei wrote:
> From: Nan Li <tonanli66@gmail.com>
>
> A zerocopy send can fail after user pages have been pinned but before
> the message is attached to the sending socket.
>
> The purge path currently infers zerocopy state from rm->m_rs, so an
> unqueued message can be cleaned up as if it owned normal payload pages.
> However, zerocopy ownership is really determined by the presence of
> op_mmp_znotifier, regardless of whether the message has reached the
> socket queue.
>
> Capture op_mmp_znotifier up front in rds_message_purge() and use it as
> the cleanup discriminator. If the message is already associated with a
> socket, keep the existing completion path. Otherwise, drop the pinned
> page accounting directly and release the notifier before putting the
> payload pages.
>
> This keeps early send failure cleanup consistent with the zerocopy
> lifetime rules without changing the normal queued completion path.
>
> Fixes: 0cebaccef3ac ("rds: zerocopy Tx support.")
> Cc: stable@kernel.org
> Reported-by: Yuan Tan <yuantan098@gmail.com>
> Reported-by: Yifan Wu <yifanwucs@gmail.com>
> Reported-by: Juefei Pu <tomapufckgml@gmail.com>
> Reported-by: Xin Liu <bird@lzu.edu.cn>
> Co-developed-by: Xiao Liu <lx24@stu.ynu.edu.cn>
> Signed-off-by: Xiao Liu <lx24@stu.ynu.edu.cn>
> Signed-off-by: Nan Li <tonanli66@gmail.com>
> Signed-off-by: Ren Wei <n05ec@lzu.edu.cn>
This fix looks fine to me. Thanks Ren Wei!
Reviewed-by: Allison Henderson <achender@kernel.org>
Allison
> ---
> net/rds/message.c | 20 +++++++++++++++-----
> 1 file changed, 15 insertions(+), 5 deletions(-)
>
> diff --git a/net/rds/message.c b/net/rds/message.c
> index eaa6f22601a4..25fedcb3cd00 100644
> --- a/net/rds/message.c
> +++ b/net/rds/message.c
> @@ -131,24 +131,34 @@ static void rds_rm_zerocopy_callback(struct rds_sock *rs,
> */
> static void rds_message_purge(struct rds_message *rm)
> {
> + struct rds_znotifier *znotifier;
> unsigned long i, flags;
> - bool zcopy = false;
> + bool zcopy;
>
> if (unlikely(test_bit(RDS_MSG_PAGEVEC, &rm->m_flags)))
> return;
>
> spin_lock_irqsave(&rm->m_rs_lock, flags);
> + znotifier = rm->data.op_mmp_znotifier;
> + rm->data.op_mmp_znotifier = NULL;
> + zcopy = !!znotifier;
> +
> if (rm->m_rs) {
> struct rds_sock *rs = rm->m_rs;
>
> - if (rm->data.op_mmp_znotifier) {
> - zcopy = true;
> - rds_rm_zerocopy_callback(rs, rm->data.op_mmp_znotifier);
> + if (znotifier) {
> + rds_rm_zerocopy_callback(rs, znotifier);
> rds_wake_sk_sleep(rs);
> - rm->data.op_mmp_znotifier = NULL;
> }
> sock_put(rds_rs_to_sk(rs));
> rm->m_rs = NULL;
> + } else if (znotifier) {
> + /*
> + * Zerocopy can fail before the message is queued on the
> + * socket, so there is no rs to carry the notification.
> + */
> + mm_unaccount_pinned_pages(&znotifier->z_mmp);
> + kfree(rds_info_from_znotifier(znotifier));
> }
> spin_unlock_irqrestore(&rm->m_rs_lock, flags);
>
next prev parent reply other threads:[~2026-05-01 19:40 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <cover.1777550074.git.tonanli66@gmail.com>
2026-05-01 1:08 ` [PATCH net 1/1] net/rds: handle zerocopy send cleanup before the message is queued Ren Wei
2026-05-01 19:40 ` Allison Henderson [this message]
2026-05-05 13:32 ` Paolo Abeni
2026-05-05 18:04 ` Allison Henderson
2026-05-05 13:40 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87f79bc7483aa1a7b3a44718b62a5cd5bd016f8c.camel@kernel.org \
--to=achender@kernel.org \
--cc=bird@lzu.edu.cn \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=lx24@stu.ynu.edu.cn \
--cc=n05ec@lzu.edu.cn \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rds-devel@oss.oracle.com \
--cc=santosh.shilimkar@oracle.com \
--cc=sowmini.varadhan@oracle.com \
--cc=tomapufckgml@gmail.com \
--cc=tonanli66@gmail.com \
--cc=willemb@google.com \
--cc=yifanwucs@gmail.com \
--cc=yuantan098@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox