提交 d09feb42 编写于 作者: R Rik van Riel 提交者: Caspar Zhang

xfs: fix missed wakeup on l_flush_wait

commit cdea5459ce263fbc963657a7736762ae897a8ae6 upstream.

The code in xlog_wait uses the spinlock to make adding the task to
the wait queue, and setting the task state to UNINTERRUPTIBLE atomic
with respect to the waker.

Doing the wakeup after releasing the spinlock opens up the following
race condition:

Task 1					task 2
add task to wait queue
					wake up task
set task state to UNINTERRUPTIBLE

This issue was found through code inspection as a result of kworkers
being observed stuck in UNINTERRUPTIBLE state with an empty
wait queue. It is rare and largely unreproducable.

Simply moving the spin_unlock to after the wake_up_all results
in the waker not being able to see a task on the waitqueue before
it has set its state to UNINTERRUPTIBLE.

This bug dates back to the conversion of this code to generic
waitqueue infrastructure from a counting semaphore back in 2008
which didn't place the wakeups consistently w.r.t. to the relevant
spin locks.

[dchinner: Also fix a similar issue in the shutdown path on
xc_commit_wait. Update commit log with more details of the issue.]

Fixes: d748c623 ("[XFS] Convert l_flushsema to a sv_t")
Reported-by: NChris Mason <clm@fb.com>
Signed-off-by: NRik van Riel <riel@surriel.com>
Signed-off-by: NDave Chinner <dchinner@redhat.com>
Reviewed-by: NDarrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: NDarrick J. Wong <darrick.wong@oracle.com>
Signed-off-by: NJoseph Qi <joseph.qi@linux.alibaba.com>
Reviewed-by: NXiaoguang Wang <xiaoguang.wang@linux.alibaba.com>
上级 d62252e6
...@@ -2707,7 +2707,6 @@ xlog_state_do_callback( ...@@ -2707,7 +2707,6 @@ xlog_state_do_callback(
int funcdidcallbacks; /* flag: function did callbacks */ int funcdidcallbacks; /* flag: function did callbacks */
int repeats; /* for issuing console warnings if int repeats; /* for issuing console warnings if
* looping too many times */ * looping too many times */
int wake = 0;
spin_lock(&log->l_icloglock); spin_lock(&log->l_icloglock);
first_iclog = iclog = log->l_iclog; first_iclog = iclog = log->l_iclog;
...@@ -2909,11 +2908,9 @@ xlog_state_do_callback( ...@@ -2909,11 +2908,9 @@ xlog_state_do_callback(
#endif #endif
if (log->l_iclog->ic_state & (XLOG_STATE_ACTIVE|XLOG_STATE_IOERROR)) if (log->l_iclog->ic_state & (XLOG_STATE_ACTIVE|XLOG_STATE_IOERROR))
wake = 1;
spin_unlock(&log->l_icloglock);
if (wake)
wake_up_all(&log->l_flush_wait); wake_up_all(&log->l_flush_wait);
spin_unlock(&log->l_icloglock);
} }
...@@ -4021,7 +4018,9 @@ xfs_log_force_umount( ...@@ -4021,7 +4018,9 @@ xfs_log_force_umount(
* item committed callback functions will do this again under lock to * item committed callback functions will do this again under lock to
* avoid races. * avoid races.
*/ */
spin_lock(&log->l_cilp->xc_push_lock);
wake_up_all(&log->l_cilp->xc_commit_wait); wake_up_all(&log->l_cilp->xc_commit_wait);
spin_unlock(&log->l_cilp->xc_push_lock);
xlog_state_do_callback(log, XFS_LI_ABORTED, NULL); xlog_state_do_callback(log, XFS_LI_ABORTED, NULL);
#ifdef XFSERRORDEBUG #ifdef XFSERRORDEBUG
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册