From nobody Sun Feb 8 09:32:16 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 61FF11B3937; Mon, 28 Apr 2025 20:24:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1745871882; cv=none; b=SEboNuGSeTcUJ+6oSymfy/a5mCz6IT7US8oxM5Wwm5OfcpBp4KsluL51Ve5NPwrzDjlJxu/ty2MkFQLF7W0SWeM/xrAx7mqGPTbGx/zbFqWgW4I19wbNZe+2kLPeQD81pu0UNll+TYlE3Me76FYgse7Oemfye2rIkrh+hIQK1AI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1745871882; c=relaxed/simple; bh=xptNENGGtclKBVRuB92L5LlI26MH8Q/AAe6oNcqgf3E=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=VsO+GHL/EHyUlEO3RK5yZ+n+y9GwFEk9c7uLDh1FuOs8Za9lzq5P3RXlI6LVAnxmyeKOqEgljfCugLwknxLcN+0HsZQXzKWwtyqadDlO1nTW3cpenww2/wMlKDFtUgIwnCTpha94XWx6F1K6XfNCeX19sm6vBpWSsOVGYeDABmI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=IveTORDH; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="IveTORDH" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B44BBC4CEEE; Mon, 28 Apr 2025 20:24:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1745871881; bh=xptNENGGtclKBVRuB92L5LlI26MH8Q/AAe6oNcqgf3E=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=IveTORDHv/soZjIb7NsUu1IJ1AarcVDSPlFJnLlmJuXqL5NqCc5LlszMhktDslPsh 32WtKYRGJO8b1KKQ7kKsXbGRl57GtdIzaem9FW7af3mpu0RlfpM+av1i5Bu+0zmF1r t/MZeTxOmcO2WeICpdjnVhlfxCnXPjtfsEoYj5EtXLmbLyqMsIYRDwnBjLud+M9GfL ChxjA4MRamcoi+PxoQikM6+WFlq1b9zXav3CVP17Vt32yWJ3xkXxu3QIE2Fl9XR7cT yEiQGzR41vmwX2c3VI9hPSOxHfVUnKFQHbFcE4SHPTgu/dH5sjHChPLhPm/Jvi2UZ3 kAe6GIHjOOKcg== From: Jeff Layton Date: Mon, 28 Apr 2025 13:24:38 -0700 Subject: [PATCH RFC 1/2] nfs: free leftover lsegs before freeing a layout in pnfs_put_layout_hdr Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20250428-nfs-6-16-v1-1-2d45b80facef@kernel.org> References: <20250428-nfs-6-16-v1-0-2d45b80facef@kernel.org> In-Reply-To: <20250428-nfs-6-16-v1-0-2d45b80facef@kernel.org> To: Trond Myklebust , Anna Schumaker Cc: Omar Sandoval , Chris Mason , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jeff Layton X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1884; i=jlayton@kernel.org; h=from:subject:message-id; bh=xptNENGGtclKBVRuB92L5LlI26MH8Q/AAe6oNcqgf3E=; b=owEBbQKS/ZANAwAIAQAOaEEZVoIVAcsmYgBoD+QII4ZFNWmKKwPdRPKRSZZXHX7yILZQOXAHB tGVvTTBi/2JAjMEAAEIAB0WIQRLwNeyRHGyoYTq9dMADmhBGVaCFQUCaA/kCAAKCRAADmhBGVaC FfysEACjaNN2BHkxxsIgTT4ioaEHV5Vdcyldc8toITSF+zJVNGq54s/tgiZfBgMIKNRiUiCUxlp P9IAdoG8UZ0hba7Y4sYoWVNF2zFfE3nIB1P9x234NCpZnx7OB0wtm79ONVp436q5/ZWON4p07J9 R2f3cy8a9I+g/FtElBWOstKld4uuR0te/L3HZQs7fsbNA3zI/q8kGKVFGfVXDHLYJMGdS7boJdo atyd2nvsS3Wg35Dv9/MmtF28xFKLeIiywsey+HiosqO2bpSQLdcLIdg9p5Glysx1UdpkjyxFpFi MRKgJ/BdaR2KXStPBW59T2TIXmWoK9Ccs7dxeiASxFCNDMY10/6tqUtlZuYeinUE9RvkdmDd6VT aF5Il3aPyuqePs9hhJdhq6ADCsxZ9maczt/+muE6QVBWnWpN4Jkn7rTrCwTMkHw8m/FVI60Bou6 q8on2YReYiyV8u9rl0214ssSErL/s8Fylpw1PGd4s3b2RrpS3GD3GG5dAnhsrq0MxrM+S7SBkEP XIBZVFm8AbbpypVuOW0Rq//bYTI0z7ohG6y4yokth7RNal+gzwk+BuU97FhkQUTrjFCepmf6c8b 55ZPNDTa2UGpFbekx3gHPFeiI4igW1uc2xGtl6kVDu1qhj1ZWKu3Pk0U2y+I5UfExRH7skVc2hI 5oFR6yYS3/B0pkg== X-Developer-Key: i=jlayton@kernel.org; a=openpgp; fpr=4BC0D7B24471B2A184EAF5D3000E684119568215 Entries on the plh_return_segs list have already had their refcount go to zero, and are only hanging around so that a LAYOUTRETURN can be issued. If there are still leftover lsegs on the plh_return_segs list when the last pnfs_layout_hdr reference is put, then that means that the layoutreturn just before the final refcount_dec_and_lock() has failed, or that new lsegs have somehow raced onto plh_return_segs. In either case, nothing else will be aware of the entries on that list, since there are no more outstanding references. On the last pnfs_layout_put(), do a final call to pnfs_mark_layout_stateid_invalid() to shuffle any leftover segments to a tmp_list. Then free that list after dropping the i_lock. Reported-by: Omar Sandoval Closes: https://lore.kernel.org/linux-nfs/Z_ArpQC_vREh_hEA@telecaster/ Signed-off-by: Jeff Layton --- fs/nfs/pnfs.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c index 5f582713bf05eb72eb34b2e2c06d1edcd3c258d3..0bcb5a4bd420c157069ee634575= 18b206223b7cb 100644 --- a/fs/nfs/pnfs.c +++ b/fs/nfs/pnfs.c @@ -307,6 +307,7 @@ pnfs_put_layout_hdr(struct pnfs_layout_hdr *lo) { struct inode *inode; unsigned long i_state; + LIST_HEAD(tmp_list); =20 if (!lo) return; @@ -316,9 +317,11 @@ pnfs_put_layout_hdr(struct pnfs_layout_hdr *lo) if (refcount_dec_and_lock(&lo->plh_refcount, &inode->i_lock)) { if (!list_empty(&lo->plh_segs)) WARN_ONCE(1, "NFS: BUG unfreed layout segments.\n"); + pnfs_mark_layout_stateid_invalid(lo, &tmp_list); pnfs_detach_layout_hdr(lo); i_state =3D inode->i_state; spin_unlock(&inode->i_lock); + pnfs_free_lseg_list(&tmp_list); pnfs_free_layout_hdr(lo); /* Notify pnfs_destroy_layout_final() that we're done */ if (i_state & (I_FREEING | I_CLEAR)) --=20 2.49.0 From nobody Sun Feb 8 09:32:16 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B250C1E766F; Mon, 28 Apr 2025 20:24:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1745871883; cv=none; b=L6A5j2aix4faz+BRQfm3BDUGmZJmXde+GX9cwrZsNdtrsEZCOt4Jin8f34VRE4HT6TokDDwhx4zfD/V2Suyh7TQuJ/rm1t91nvl8mfZQ3qJFOWMkaJ8+Y1hw5UX0ynJ0l8JbSzasVC5SweTEzXeMiqiuurD2H0vAzeeRyI3FhmU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1745871883; c=relaxed/simple; bh=nrYGlGVsPoTdqvS0ZHQ1tsED3Zl2BbfyUm21SX8CPSU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=m2+PsmPgiiIEoZjYOcrHCb0ktBfJ9HM1NFGYTwiYdX24jvedmDExpaNkaimi1HByteb392yqqLkDGXRDzsRwpZWUS2sMcxkowrJyedsQyuvpcDsdBycHIyuqU1RcN4bL60HOClsIFTNsVJ7m/1MQIDKlZfH5bYEtvcErSePa+uA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=pV0fPsOY; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="pV0fPsOY" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1467BC4CEF0; Mon, 28 Apr 2025 20:24:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1745871882; bh=nrYGlGVsPoTdqvS0ZHQ1tsED3Zl2BbfyUm21SX8CPSU=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=pV0fPsOYXeYqIYNe0I7apUlE95oxFB2UX/OVJLAC0WFY5z9LOV45PJqVJDhDS4jUW j6fIioRsCm5XLinfYpV7rSYiX9Aaw9aVRVmq0+vq8JGU0QEshR/aEPTzS3xBqlmdaU NLkYzjl8w9upgtrrDQJ+q1CYFkZncxxv5ptWrWhCFDUF66hxmAwcBhu2v6+h3NKo3o IjOok4w6kC7N0Sq/PI1DELVm+pboLnl6HTSlKHTfiF36pcsQnxWIdMadI6V3S0CFPU +Qpx9M4svj/vHyB+miPO8Q+flMJR2BIKynOJa857lBGSgs3XueeApHn1XtCC4yiRFh PFveQhqcHDyqQ== From: Jeff Layton Date: Mon, 28 Apr 2025 13:24:39 -0700 Subject: [PATCH RFC 2/2] nfs: pr_warn if plh_segs or plh_return_segs are non-empty when freeing Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20250428-nfs-6-16-v1-2-2d45b80facef@kernel.org> References: <20250428-nfs-6-16-v1-0-2d45b80facef@kernel.org> In-Reply-To: <20250428-nfs-6-16-v1-0-2d45b80facef@kernel.org> To: Trond Myklebust , Anna Schumaker Cc: Omar Sandoval , Chris Mason , linux-nfs@vger.kernel.org, linux-kernel@vger.kernel.org, Jeff Layton X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1809; i=jlayton@kernel.org; h=from:subject:message-id; bh=nrYGlGVsPoTdqvS0ZHQ1tsED3Zl2BbfyUm21SX8CPSU=; b=owEBbQKS/ZANAwAIAQAOaEEZVoIVAcsmYgBoD+QJCa339MvenqGc/ElCSaEpQPLffxmha44WM SLPDByQRj6JAjMEAAEIAB0WIQRLwNeyRHGyoYTq9dMADmhBGVaCFQUCaA/kCQAKCRAADmhBGVaC FSsaEACsvcOJbOOhszZeQBXglSszGnbtXpq1r1wsYzyFcYD55hIULaaxQvqjs2IYwMREReSp+YH dVxwEgkKc4LY036jvgOuoYny4q97um3aNh10ixrXJI5sN3/1OH4y80Q9wSRxt+m82uNX1QQVvea 4xo9Lh8Hy0CIMJg+/Mj64zuy4JGnWNR7a24DrVZ3Ln+GDsQkjX4KUP/k1jQzBsHA3jvEtkQs/ls e3v3fRXHUM9yvukm3JjWaNvMawnHRgUxxfslTad62ZhSI3tdWEwa4UypVffaaSzaPW6QmTF/9rp Iagw4N+pdrOLaF5s7YUR3Yh9frpk+abLM8p6xiZdMXjDzvzbBqFEuyyozQmso0nuX+b3RhzY4bj 1b+IyCntcAyLEtmZaVeEsPlEiEPYusOWmnpnOhC7QVhiB2tYMNbcCVDEvRIswuEYRXzzRVdK2A1 eF2DE0jZIcSWpp3RfPmX96rFjHNY4T8V7+/To1+gqU8dteUtAsZbtoaRZkK3e/fdv1/rSYTRnLb xm1d9tfQgYB9lyvNlFgs9kLKG2hxAP0S2sKerccmi+A9SscKnrfUqvroLR785B1VlX0hUiQ63Uo N8ufH7XdbME65hBvd7nsIyjDSmo5ThvUiwjfAj45/K+LYXebdcnNMDuT0Vmigl1h+JGivkYnOX0 OWhjRqglHymu9sw== X-Developer-Key: i=jlayton@kernel.org; a=openpgp; fpr=4BC0D7B24471B2A184EAF5D3000E684119568215 pnfs_layoutreturn_before_put_layout_hdr() currently throws a WARN if plh_segs still has entries when the layout_hdr is freed. Add a new routine that prints info about leftover segments when this occurs, before dumping the stack. Call that for both plh_segs and plh_return_segs lists. Suggested-by: Omar Sandoval Signed-off-by: Jeff Layton --- fs/nfs/pnfs.c | 20 ++++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/fs/nfs/pnfs.c b/fs/nfs/pnfs.c index 0bcb5a4bd420c157069ee63457518b206223b7cb..4387b1f77a3140b88a0644db1a5= 65a4b71ab64bf 100644 --- a/fs/nfs/pnfs.c +++ b/fs/nfs/pnfs.c @@ -302,6 +302,22 @@ pnfs_detach_layout_hdr(struct pnfs_layout_hdr *lo) nfsi->read_io =3D 0; } =20 +static void +pnfs_warn_dangling_lsegs(struct list_head *list, const char *name) +{ + struct pnfs_layout_segment *lseg; + + if (list_empty(list)) + return; + + pr_warn("NFS: BUG unfreed layout segments on %s\n", name); + list_for_each_entry(lseg, list, pls_list) + pr_warn("%p: refs=3D%d flags=3D0x%lx seq=3D%u\n", lseg, + refcount_read(&lseg->pls_refcount), lseg->pls_flags, + lseg->pls_seq); + dump_stack(); +} + void pnfs_put_layout_hdr(struct pnfs_layout_hdr *lo) { @@ -315,8 +331,8 @@ pnfs_put_layout_hdr(struct pnfs_layout_hdr *lo) pnfs_layoutreturn_before_put_layout_hdr(lo); =20 if (refcount_dec_and_lock(&lo->plh_refcount, &inode->i_lock)) { - if (!list_empty(&lo->plh_segs)) - WARN_ONCE(1, "NFS: BUG unfreed layout segments.\n"); + pnfs_warn_dangling_lsegs(&lo->plh_segs, "plh_segs"); + pnfs_warn_dangling_lsegs(&lo->plh_return_segs, "plh_return_segs"); pnfs_mark_layout_stateid_invalid(lo, &tmp_list); pnfs_detach_layout_hdr(lo); i_state =3D inode->i_state; --=20 2.49.0