Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit da6e1a32 authored by Neil Brown's avatar Neil Brown Committed by Linus Torvalds
Browse files

[PATCH] md: avoid possible BUG_ON in md bitmap handling



md/bitmap tracks how many active write requests are pending on blocks
associated with each bit in the bitmap, so that it knows when it can clear
the bit (when count hits zero).

The counter has 14 bits of space, so if there are ever more than 16383, we
cannot cope.

Currently the code just calles BUG_ON as "all" drivers have request queue
limits much smaller than this.

However is seems that some don't.  Apparently some multipath configurations
can allow more than 16383 concurrent write requests.

So, in this unlikely situation, instead of calling BUG_ON we now wait
for the count to drop down a bit.  This requires a new wait_queue_head,
some waiting code, and a wakeup call.

Tested by limiting the counter to 20 instead of 16383 (writes go a lot slower
in that case...).

Signed-off-by: default avatarNeil Brown <neilb@suse.de>
Cc: <stable@kernel.org>
Signed-off-by: default avatarAndrew Morton <akpm@linux-foundation.org>
Signed-off-by: default avatarLinus Torvalds <torvalds@linux-foundation.org>
parent aaf68cfb
Loading
Loading
Loading
Loading
+21 −1
Original line number Original line Diff line number Diff line
@@ -1160,6 +1160,22 @@ int bitmap_startwrite(struct bitmap *bitmap, sector_t offset, unsigned long sect
			return 0;
			return 0;
		}
		}


		if (unlikely((*bmc & COUNTER_MAX) == COUNTER_MAX)) {
			DEFINE_WAIT(__wait);
			/* note that it is safe to do the prepare_to_wait
			 * after the test as long as we do it before dropping
			 * the spinlock.
			 */
			prepare_to_wait(&bitmap->overflow_wait, &__wait,
					TASK_UNINTERRUPTIBLE);
			spin_unlock_irq(&bitmap->lock);
			bitmap->mddev->queue
				->unplug_fn(bitmap->mddev->queue);
			schedule();
			finish_wait(&bitmap->overflow_wait, &__wait);
			continue;
		}

		switch(*bmc) {
		switch(*bmc) {
		case 0:
		case 0:
			bitmap_file_set_bit(bitmap, offset);
			bitmap_file_set_bit(bitmap, offset);
@@ -1169,7 +1185,7 @@ int bitmap_startwrite(struct bitmap *bitmap, sector_t offset, unsigned long sect
		case 1:
		case 1:
			*bmc = 2;
			*bmc = 2;
		}
		}
		BUG_ON((*bmc & COUNTER_MAX) == COUNTER_MAX);

		(*bmc)++;
		(*bmc)++;


		spin_unlock_irq(&bitmap->lock);
		spin_unlock_irq(&bitmap->lock);
@@ -1207,6 +1223,9 @@ void bitmap_endwrite(struct bitmap *bitmap, sector_t offset, unsigned long secto
		if (!success && ! (*bmc & NEEDED_MASK))
		if (!success && ! (*bmc & NEEDED_MASK))
			*bmc |= NEEDED_MASK;
			*bmc |= NEEDED_MASK;


		if ((*bmc & COUNTER_MAX) == COUNTER_MAX)
			wake_up(&bitmap->overflow_wait);

		(*bmc)--;
		(*bmc)--;
		if (*bmc <= 2) {
		if (*bmc <= 2) {
			set_page_attr(bitmap,
			set_page_attr(bitmap,
@@ -1431,6 +1450,7 @@ int bitmap_create(mddev_t *mddev)
	spin_lock_init(&bitmap->lock);
	spin_lock_init(&bitmap->lock);
	atomic_set(&bitmap->pending_writes, 0);
	atomic_set(&bitmap->pending_writes, 0);
	init_waitqueue_head(&bitmap->write_wait);
	init_waitqueue_head(&bitmap->write_wait);
	init_waitqueue_head(&bitmap->overflow_wait);


	bitmap->mddev = mddev;
	bitmap->mddev = mddev;


+1 −0
Original line number Original line Diff line number Diff line
@@ -247,6 +247,7 @@ struct bitmap {


	atomic_t pending_writes; /* pending writes to the bitmap file */
	atomic_t pending_writes; /* pending writes to the bitmap file */
	wait_queue_head_t write_wait;
	wait_queue_head_t write_wait;
	wait_queue_head_t overflow_wait;


};
};