Skip to content

Commit 07175cb

Browse files
YuKuai-huaweiaxboe
authored andcommitted
nbd: make sure request completion won't concurrent
commit cddce01 ("nbd: Aovid double completion of a request") try to fix that nbd_clear_que() and recv_work() can complete a request concurrently. However, the problem still exists: t1 t2 t3 nbd_disconnect_and_put flush_workqueue recv_work blk_mq_complete_request blk_mq_complete_request_remote -> this is true WRITE_ONCE(rq->state, MQ_RQ_COMPLETE) blk_mq_raise_softirq blk_done_softirq blk_complete_reqs nbd_complete_rq blk_mq_end_request blk_mq_free_request WRITE_ONCE(rq->state, MQ_RQ_IDLE) nbd_clear_que blk_mq_tagset_busy_iter nbd_clear_req __blk_mq_free_request blk_mq_put_tag blk_mq_complete_request -> complete again There are three places where request can be completed in nbd: recv_work(), nbd_clear_que() and nbd_xmit_timeout(). Since they all hold cmd->lock before completing the request, it's easy to avoid the problem by setting and checking a cmd flag. Signed-off-by: Yu Kuai <yukuai3@huawei.com> Reviewed-by: Ming Lei <ming.lei@redhat.com> Reviewed-by: Josef Bacik <josef@toxicpanda.com> Link: https://lore.kernel.org/r/20210916093350.1410403-3-yukuai3@huawei.com Signed-off-by: Jens Axboe <axboe@kernel.dk>
1 parent 4e6eef5 commit 07175cb

File tree

1 file changed

+9
-2
lines changed

1 file changed

+9
-2
lines changed

drivers/block/nbd.c

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -411,7 +411,11 @@ static enum blk_eh_timer_return nbd_xmit_timeout(struct request *req,
411411
if (!mutex_trylock(&cmd->lock))
412412
return BLK_EH_RESET_TIMER;
413413

414-
__clear_bit(NBD_CMD_INFLIGHT, &cmd->flags);
414+
if (!__test_and_clear_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
415+
mutex_unlock(&cmd->lock);
416+
return BLK_EH_DONE;
417+
}
418+
415419
if (!refcount_inc_not_zero(&nbd->config_refs)) {
416420
cmd->status = BLK_STS_TIMEOUT;
417421
mutex_unlock(&cmd->lock);
@@ -846,7 +850,10 @@ static bool nbd_clear_req(struct request *req, void *data, bool reserved)
846850
return true;
847851

848852
mutex_lock(&cmd->lock);
849-
__clear_bit(NBD_CMD_INFLIGHT, &cmd->flags);
853+
if (!__test_and_clear_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
854+
mutex_unlock(&cmd->lock);
855+
return true;
856+
}
850857
cmd->status = BLK_STS_IOERR;
851858
mutex_unlock(&cmd->lock);
852859

0 commit comments

Comments
 (0)