From: John Allen <hidden> Date: 2018-07-17 19:40:56
Stress testing has uncovered issues with handling continuously queued PRRN
events. Running PRRN events in this way can seriously load the system given
the sheer volume of dlpar being handled. This patchset ensures that PRRN
events are handled more synchronously, only allowing the PRRN handler to
queue a single dlpar event at any given time. Additionally, it ensures
that rtas polling continues normally when multiple PRRN events are queued
simultaneously.
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
John Allen (2):
powerpc/pseries: Avoid blocking rtas polling handling multiple PRRN
events
powerpc/pseries: Wait for completion of hotplug events during PRRN
handling
arch/powerpc/kernel/rtasd.c | 10 +++++++---
arch/powerpc/platforms/pseries/mobility.c | 5 ++++-
2 files changed, 11 insertions(+), 4 deletions(-)
--
2.17.1
From: John Allen <hidden> Date: 2018-07-17 19:40:57
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
Signed-off-by: John Allen <redacted>
---
arch/powerpc/platforms/pseries/mobility.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
From: John Allen <hidden> Date: 2018-07-17 19:40:58
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
Reviewed-by: Nathan Fontenot <redacted>
quoted hunk
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
Signed-off-by: John Allen <redacted>
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2018-07-23 13:27:58
Hi John,
I'm a bit puzzled by this one.
John Allen [off-list ref] writes:
quoted hunk
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
This seems like it's actually the core of the change. Previously we were
basically blocking on the flush before continuing.
- prrn_update_scope = scope;
I don't really understand the scope. With the old code we always ran the
work function once for call, now we potentially throw away the scope
value (if the try lock fails).
Ignoring the scope, the addition of the mutex should not actually make
any difference. If you see the doco for schedule_work() it says:
* This puts a job in the kernel-global workqueue if it was not already
* queued and leaves it in the same position on the kernel-global
* workqueue otherwise.
So the mutex basically implements that existing behaviour. But maybe the
scope is the issue? Like I said I don't really understand the scope
value.
So I guess I'm wondering if we just need to drop the flush_work() and
the rest is not required?
cheers
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2018-07-23 13:41:25
John Allen [off-list ref] writes:
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
So do we need the hotplug work queue at all? Can we just call
handle_dlpar_errorlog() directly?
Or are we using the work queue to serialise things? And if so would a
mutex be better?
It looks like prrn_update_node() is called via at least, prrn_work_fn()
and post_mobility_fixup().
The latter is called from migration_store(), which seems like it would
be harmless. But also from pseries_suspend_enable_irqs() which I'm less
clear on.
cheers
From: John Allen <hidden> Date: 2018-07-23 15:06:58
On Mon, Jul 23, 2018 at 11:27:56PM +1000, Michael Ellerman wrote:
Hi John,
I'm a bit puzzled by this one.
John Allen [off-list ref] writes:
quoted
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
This seems like it's actually the core of the change. Previously we were
basically blocking on the flush before continuing.
The idea here is to replace the blocking flush_work with a non-blocking
mutex. So rather than waiting on the running PRRN event to complete, we
bail out since a PRRN event is already running. The situation this is
meant to address is flooding the workqueue with PRRN events, which like
the situation in patch 2/2, these can be queued up faster than they can
actually be handled.
quoted
- prrn_update_scope = scope;
I don't really understand the scope. With the old code we always ran the
work function once for call, now we potentially throw away the scope
value (if the try lock fails).
So anytime we actually want to run with the scope (in the event the
trylock succeeds), we schedule the work with the scope value set
accordingly as seen in the code below. In the case that we actually
don't want to run a PRRN event (if one is already running) we do throw
away the scope and ignore the request entirely.
Ignoring the scope, the addition of the mutex should not actually make
any difference. If you see the doco for schedule_work() it says:
* This puts a job in the kernel-global workqueue if it was not already
* queued and leaves it in the same position on the kernel-global
* workqueue otherwise.
So the mutex basically implements that existing behaviour. But maybe the
scope is the issue? Like I said I don't really understand the scope
value.
So I guess I'm wondering if we just need to drop the flush_work() and
the rest is not required?
To sum up the above, the behavior without the mutex is not the same as
with the mutex. Without the mutex, that means that anytime we get a PRRN
event, it will get queued on the workqueue which can get flooded if PRRN
events are queued continuously. With the mutex, only one PRRN event can
be queued for handling at once.
Hope that clears things up!
-John
From: John Allen <hidden> Date: 2018-07-23 15:23:41
On Mon, Jul 23, 2018 at 11:41:24PM +1000, Michael Ellerman wrote:
John Allen [off-list ref] writes:
quoted
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
So do we need the hotplug work queue at all? Can we just call
handle_dlpar_errorlog() directly?
Or are we using the work queue to serialise things? And if so would a
mutex be better?
Right, the workqueue is meant to serialize all hotplug events and it
gets used for more than just PRRN events. I believe the motivation for
using the workqueue over a mutex is that KVM guests initiate hotplug
events through the hotplug interrupt and can queue fairly large requests
meaning that in this scenario, waiting for a lock would block interrupts
for a while. Using the workqueue allows us to serialize hotplug events
from different sources in the same way without worrying about the
context in which the event is generated.
It looks like prrn_update_node() is called via at least, prrn_work_fn()
and post_mobility_fixup().
The latter is called from migration_store(), which seems like it would
be harmless. But also from pseries_suspend_enable_irqs() which I'm less
clear on.
Yeah, that doesn't seem to make sense based on the function name. Odd
that prrn_update_node is being called from anywhere outside of handling
PRRN events. Perhaps if other code paths are using the function, it
needs a more generic name.
-John
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2018-08-01 13:03:06
Hi John,
I'm still not sure about this one.
John Allen [off-list ref] writes:
On Mon, Jul 23, 2018 at 11:27:56PM +1000, Michael Ellerman wrote:
quoted
Hi John,
I'm a bit puzzled by this one.
John Allen [off-list ref] writes:
quoted
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
This seems like it's actually the core of the change. Previously we were
basically blocking on the flush before continuing.
The idea here is to replace the blocking flush_work with a non-blocking
mutex. So rather than waiting on the running PRRN event to complete, we
bail out since a PRRN event is already running.
OK, but why is it OK to bail out?
The firmware sent you an error log asking you to do something, with a
scope value that has some meaning, and now you're just going to drop
that on the floor?
Maybe it is OK to just drop these events? Or maybe you're saying that
because the system is crashing under the load of too many events it's OK
to drop the events in this case.
The situation this is
meant to address is flooding the workqueue with PRRN events, which like
the situation in patch 2/2, these can be queued up faster than they can
actually be handled.
I'm not really sure why this is a problem though.
The current code synchronously processes the events, so there should
only ever be one in flight.
I guess the issue is that each one can queue multiple events on the
hotplug work queue?
But still, we have terabytes of RAM, we should be able to queue a lot
of events before it becomes a problem.
So what exactly is getting flooded, what's the symptom?
If the queuing of the hotplug events is the problem, then why don't we
stop doing that? We could just process them synchronously from the PRRN
update, that would naturally throttle them.
cheers
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2018-08-01 13:16:24
John Allen [off-list ref] writes:
On Mon, Jul 23, 2018 at 11:41:24PM +1000, Michael Ellerman wrote:
quoted
John Allen [off-list ref] writes:
quoted
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
Have you tested this patch in isolation, ie. not with patch 1?
quoted
So do we need the hotplug work queue at all? Can we just call
handle_dlpar_errorlog() directly?
Or are we using the work queue to serialise things? And if so would a
mutex be better?
Right, the workqueue is meant to serialize all hotplug events and it
gets used for more than just PRRN events. I believe the motivation for
using the workqueue over a mutex is that KVM guests initiate hotplug
events through the hotplug interrupt and can queue fairly large requests
meaning that in this scenario, waiting for a lock would block interrupts
for a while.
OK, but that just means that path needs to schedule work to run later.
Using the workqueue allows us to serialize hotplug events
from different sources in the same way without worrying about the
context in which the event is generated.
A lock would be so much simpler.
It looks like we have three callers of queue_hotplug_event(), the dlpar
code, the mobility code and the ras interrupt.
The dlpar code already waits synchronously:
init_completion(&hotplug_done);
queue_hotplug_event(hp_elog, &hotplug_done, &rc);
wait_for_completion(&hotplug_done);
You're changing mobility to do the same (this patch), leaving only the
ras interrupt that actually queues work and returns.
So it really seems like a mutex would do the trick, and the ras
interrupt would be the only case that needs to schedule work for later.
cheers
From: John Allen <hidden> Date: 2018-08-06 19:09:25
On Wed, Aug 01, 2018 at 11:02:59PM +1000, Michael Ellerman wrote:
Hi John,
I'm still not sure about this one.
John Allen [off-list ref] writes:
quoted
On Mon, Jul 23, 2018 at 11:27:56PM +1000, Michael Ellerman wrote:
quoted
Hi John,
I'm a bit puzzled by this one.
John Allen [off-list ref] writes:
quoted
When a PRRN event is being handled and another PRRN event comes in, the
second event will block rtas polling waiting on the first to complete,
preventing any further rtas events from being handled. This can be
especially problematic in case that PRRN events are continuously being
queued in which case rtas polling gets indefinitely blocked completely.
This patch introduces a mutex that prevents any subsequent PRRN events from
running while there is a prrn event being handled, allowing rtas polling to
continue normally.
Signed-off-by: John Allen <redacted>
---
v2:
-Unlock prrn_lock when PRRN operations are complete, not after handler is
scheduled.
-Remove call to flush_work, the previous broken method of serializing
PRRN events.
---
arch/powerpc/kernel/rtasd.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
This seems like it's actually the core of the change. Previously we were
basically blocking on the flush before continuing.
The idea here is to replace the blocking flush_work with a non-blocking
mutex. So rather than waiting on the running PRRN event to complete, we
bail out since a PRRN event is already running.
OK, but why is it OK to bail out?
The firmware sent you an error log asking you to do something, with a
scope value that has some meaning, and now you're just going to drop
that on the floor?
Maybe it is OK to just drop these events? Or maybe you're saying that
because the system is crashing under the load of too many events it's OK
to drop the events in this case.
I think I see your point. If a PRRN event comes in while another is
currently running, the new one may contain a different list of LMBs/CPUs
and the old list becomes outdated. With the mutex, the only event that
gets handled is the oldest and we will lose any additional changes
beyond the initial event. Therefore, as you mentioned in your previous
message, the behavior of the global workqueue should work just fine once
we remove the call to flush_work. While a prrn event is running, only
one will remain on the workqueue, then when the first one completes, the
newly scheduled work function should grab the latest PRRN list.
I will send a new version of the patch with just the call to flush_work
removed.
-John
quoted
The situation this is
meant to address is flooding the workqueue with PRRN events, which like
the situation in patch 2/2, these can be queued up faster than they can
actually be handled.
I'm not really sure why this is a problem though.
The current code synchronously processes the events, so there should
only ever be one in flight.
I guess the issue is that each one can queue multiple events on the
hotplug work queue?
But still, we have terabytes of RAM, we should be able to queue a lot
of events before it becomes a problem.
So what exactly is getting flooded, what's the symptom?
If the queuing of the hotplug events is the problem, then why don't we
stop doing that? We could just process them synchronously from the PRRN
update, that would naturally throttle them.
cheers
From: John Allen <hidden> Date: 2018-08-07 19:26:35
On Wed, Aug 01, 2018 at 11:16:22PM +1000, Michael Ellerman wrote:
John Allen [off-list ref] writes:
quoted
On Mon, Jul 23, 2018 at 11:41:24PM +1000, Michael Ellerman wrote:
quoted
John Allen [off-list ref] writes:
quoted
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
Have you tested this patch in isolation, ie. not with patch 1?
While I was away on vacation, I believe a build was tested with just
this patch and not the first and it has been running with no problems.
However, I think they've had problems recreating the problem in general
so it may just be that the environment is not setup properly to recreate
the issue.
quoted
quoted
So do we need the hotplug work queue at all? Can we just call
handle_dlpar_errorlog() directly?
Or are we using the work queue to serialise things? And if so would a
mutex be better?
Right, the workqueue is meant to serialize all hotplug events and it
gets used for more than just PRRN events. I believe the motivation for
using the workqueue over a mutex is that KVM guests initiate hotplug
events through the hotplug interrupt and can queue fairly large requests
meaning that in this scenario, waiting for a lock would block interrupts
for a while.
OK, but that just means that path needs to schedule work to run later.
quoted
Using the workqueue allows us to serialize hotplug events
from different sources in the same way without worrying about the
context in which the event is generated.
A lock would be so much simpler.
It looks like we have three callers of queue_hotplug_event(), the dlpar
code, the mobility code and the ras interrupt.
The dlpar code already waits synchronously:
init_completion(&hotplug_done);
queue_hotplug_event(hp_elog, &hotplug_done, &rc);
wait_for_completion(&hotplug_done);
You're changing mobility to do the same (this patch), leaving only the
ras interrupt that actually queues work and returns.
So it really seems like a mutex would do the trick, and the ras
interrupt would be the only case that needs to schedule work for later.
I think you may be right, but I would need some feedback from Nathan
Fontenot before I redesign the queue. He's been thinking about that
design for longer than I have and may know something that I don't
regarding the reason we're using a workqueue rather than a mutex.
Given that the bug this is meant to address is pretty high priority,
would you consider the wait_for_completion an acceptable stopgap while a
more substantial redesign of this code is discussed?
-John
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2018-08-08 13:38:53
John Allen [off-list ref] writes:
On Wed, Aug 01, 2018 at 11:16:22PM +1000, Michael Ellerman wrote:
quoted
John Allen [off-list ref] writes:
quoted
On Mon, Jul 23, 2018 at 11:41:24PM +1000, Michael Ellerman wrote:
quoted
John Allen [off-list ref] writes:
quoted
While handling PRRN events, the time to handle the actual hotplug events
dwarfs the time it takes to perform the device tree updates and queue the
hotplug events. In the case that PRRN events are being queued continuously,
hotplug events have been observed to be queued faster than the kernel can
actually handle them. This patch avoids the problem by waiting for a
hotplug request to complete before queueing more hotplug events.
Have you tested this patch in isolation, ie. not with patch 1?
While I was away on vacation, I believe a build was tested with just
this patch and not the first and it has been running with no problems.
However, I think they've had problems recreating the problem in general
so it may just be that the environment is not setup properly to recreate
the issue.
Yes I asked Haren to test it :)
From memory there were some warnings still about the work queue being
blocked for long periods, but they weren't fatal.
quoted
quoted
quoted
So do we need the hotplug work queue at all? Can we just call
handle_dlpar_errorlog() directly?
Or are we using the work queue to serialise things? And if so would a
mutex be better?
Right, the workqueue is meant to serialize all hotplug events and it
gets used for more than just PRRN events. I believe the motivation for
using the workqueue over a mutex is that KVM guests initiate hotplug
events through the hotplug interrupt and can queue fairly large requests
meaning that in this scenario, waiting for a lock would block interrupts
for a while.
OK, but that just means that path needs to schedule work to run later.
quoted
Using the workqueue allows us to serialize hotplug events
from different sources in the same way without worrying about the
context in which the event is generated.
A lock would be so much simpler.
It looks like we have three callers of queue_hotplug_event(), the dlpar
code, the mobility code and the ras interrupt.
The dlpar code already waits synchronously:
init_completion(&hotplug_done);
queue_hotplug_event(hp_elog, &hotplug_done, &rc);
wait_for_completion(&hotplug_done);
You're changing mobility to do the same (this patch), leaving only the
ras interrupt that actually queues work and returns.
So it really seems like a mutex would do the trick, and the ras
interrupt would be the only case that needs to schedule work for later.
I think you may be right, but I would need some feedback from Nathan
Fontenot before I redesign the queue. He's been thinking about that
design for longer than I have and may know something that I don't
regarding the reason we're using a workqueue rather than a mutex.
Given that the bug this is meant to address is pretty high priority,
would you consider the wait_for_completion an acceptable stopgap while a
more substantial redesign of this code is discussed?