Re: dm: don't reuse bio for flushes
From: Mike Snitzer <hidden>
Date: 2018-12-19 16:13:52
On Wed, Dec 19 2018 at 11:11am -0500, Mike Snitzer [off-list ref] wrote:
On Wed, Dec 19 2018 at 10:50am -0500, Jens Axboe [off-list ref] wrote:quoted
DM currently has a statically allocated bio that it uses to issue empty flushes. It doesn't submit this bio, it just uses it for maintaining state while setting up clones. Multiple users can access this bio at the same time. This wasn't previously an issue, even if it was a bit iffy, but with the blkg associations it can become one. We setup the blkg association, then clone bio's and submit, then remove the blkg assocation again. But since we can have multiple tasks doing this at the same time, against multiple blkg's, then we can either lose references to a blkg, or put it twice. The latter causes complaints on the percpu ref being <= 0 when released, and can cause use-after-free as well. Ming reports that xfstest generic/475 triggers this: ------------[ cut here ]------------ percpu ref (blkg_release) <= 0 (0) after switching to atomic WARNING: CPU: 13 PID: 0 at lib/percpu-refcount.c:155 percpu_ref_switch_to_atomic_rcu+0x2c9/0x4a0 Switch to just using an on-stack bio for this, and get rid of the embedded bio. Fixes: 5cdf2e3fea5e ("blkcg: associate blkg when associating a device") Reported-by: Ming Lei <redacted> Signed-off-by: Jens Axboe <axboe@kernel.dk>Thanks for sorting this one out, definitely wasn't happy with how exposed DM was left with the recent blkg changes. This is clearly better. Acked-by: Mike Snitzer <redacted>
Please upgrade this to: Reviewed-by: Mike Snitzer <redacted>