From nobody Mon Sep 28 21:53:55 2026 Received: from canpmsgout02.his.huawei.com (canpmsgout02.his.huawei.com [113.46.200.217]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 822123112B2; Mon, 17 Aug 2026 03:39:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.217 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786937993; cv=none; b=mfZAgKtjQNjywE0MmPsaVOc8ThLnfjUGgrjtKyOOcnuV8sGWir736ipgQNTUAdaInjCxWtEbSV8pyvm0GJKQIhz+9NdpPswKI0YqNQp7SWzeOQCz/5EPeTG2nmcQudrWitCeFy+kJBrq3PUmbFw9J/lll/+CTwsF5uKInr9qAYk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786937993; c=relaxed/simple; bh=Yf18fPn/EFoNmAu1Ovv86K/pAYUmLkYZFlGm1b3I3ho=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=hRUVeWb0oL2vFhPvB8WE4/ZnafwwpIqp6qqHXj6HbB4kCHorVeQQjxcmSYF44LMi+gT5tlGseK6dMkd64k2vRX1biQkRtkWngbkhs4f/hc/yrsNLPoUFXhwwYQZkMDDoBNsAMWQU92F4/O9UJ9LgywQzMIAglRvXM/mICSLOCwk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=qf6j7aV9; arc=none smtp.client-ip=113.46.200.217 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="qf6j7aV9" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=sFQix3HaAxxhtqyNdoSbUtgSIFhJraZV6JC9JomQCdQ=; b=qf6j7aV9SC9qaWkpe+gHaIke5UULdn129HnMkp+GZLADgy8Kl6SMeQToWgqa7vxEQtWn76UPW /jy3ZAzLVQIZdEyu0SfXlRtS36IZ2O88ngnwB3h7qQkKUlBtLcfqRaTKdSjexHY2m0J86rY4/uA rQX/I7079jGqIcNZB+VlML8= Received: from mail.maildlp.com (unknown [172.19.162.140]) by canpmsgout02.his.huawei.com (SkyGuard) with ESMTPS id 4hNdc95Tn3zcbMk; Mon, 17 Aug 2026 11:29:29 +0800 (CST) Received: from kwepemf100017.china.huawei.com (unknown [7.202.181.16]) by mail.maildlp.com (Postfix) with ESMTPS id A8E84202E6; Mon, 17 Aug 2026 11:39:45 +0800 (CST) Received: from localhost.localdomain (10.50.85.155) by kwepemf100017.china.huawei.com (7.202.181.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.36; Mon, 17 Aug 2026 11:39:45 +0800 From: Zizhi Wo To: , , , , CC: , , , Subject: [PATCH V2 1/2] md/raid10: annotate lockless access to array_freeze_pending Date: Mon, 17 Aug 2026 11:33:39 +0800 Message-ID: <20260817033340.418119-2-wozizhi@huawei.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260817033340.418119-1-wozizhi@huawei.com> References: <20260817033340.418119-1-wozizhi@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To kwepemf100017.china.huawei.com (7.202.181.16) Content-Type: text/plain; charset="utf-8" conf->array_freeze_pending is updated under conf->resync_lock in freeze_array(), but read locklessly in allow_barrier(). Annotate these accesses with READ_ONCE()/WRITE_ONCE() to document the intentional lockless access and to prevent load/store tearing or fusing by the compiler. No functional change. Signed-off-by: Zizhi Wo --- drivers/md/raid10.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c index 0a3cfdd3f5df..dc40110a6736 100644 --- a/drivers/md/raid10.c +++ b/drivers/md/raid10.c @@ -1031,11 +1031,11 @@ static bool wait_barrier(struct r10conf *conf, bool= nowait) } =20 static void allow_barrier(struct r10conf *conf) { if ((atomic_dec_and_test(&conf->nr_pending)) || - (conf->array_freeze_pending)) + READ_ONCE(conf->array_freeze_pending)) wake_up_barrier(conf); } =20 static void freeze_array(struct r10conf *conf, int extra) { @@ -1050,16 +1050,16 @@ static void freeze_array(struct r10conf *conf, int = extra) * Thus the number queued (nr_queued) plus this request (extra) * must match the number of pending IOs (nr_pending) before * we continue. */ write_seqlock_irq(&conf->resync_lock); - conf->array_freeze_pending++; + WRITE_ONCE(conf->array_freeze_pending, conf->array_freeze_pending + 1); WRITE_ONCE(conf->barrier, conf->barrier + 1); conf->nr_waiting++; wait_event_barrier_cmd(conf, atomic_read(&conf->nr_pending) =3D=3D conf->nr_queued + extra, flush_pending_writes(conf)); - conf->array_freeze_pending--; + WRITE_ONCE(conf->array_freeze_pending, conf->array_freeze_pending - 1); write_sequnlock_irq(&conf->resync_lock); } =20 static void unfreeze_array(struct r10conf *conf) { --=20 2.52.0 From nobody Mon Sep 28 21:53:55 2026 Received: from canpmsgout06.his.huawei.com (canpmsgout06.his.huawei.com [113.46.200.221]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B6E6C12F585; Mon, 17 Aug 2026 03:39:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=113.46.200.221 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786937993; cv=none; b=Rtx69pF93KATAPtRDWj2S1ROfYQpr6DW2rGz3f4v4BNFo5qs3tlop8hAvH9hzz2jDZOdfPGWegmbAXgQil/22bmO2m2HyjfbX94t+jiVRDw096VEU2+ubH7xfahPa2oRDz0RG87PDgnTG/M+b1aZea0tNXH5sh0Ha0/lq1umGt4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786937993; c=relaxed/simple; bh=IwVjahjJn+ZdvHfTf+caZIi2uaS64c7NgcNAx/8Sdd4=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=jukhS9V1op3nAYQdX6HtRtPy/5N6uYFpdfMOxwdc/eH/+cgk+mbu01zggHcB/bgTpWRAvrpHmaNcEmuIutZgIVo2PzwXhMXlVshvkPQ+wFXUAmGRam/afvcJIH2wYXd/XveUnLS9pXA9rjCv5LwykEks4ut/UQ9Qcb8fZRLK7p8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com; spf=pass smtp.mailfrom=huawei.com; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b=Nt+eXoSX; arc=none smtp.client-ip=113.46.200.221 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=huawei.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huawei.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=huawei.com header.i=@huawei.com header.b="Nt+eXoSX" dkim-signature: v=1; a=rsa-sha256; d=huawei.com; s=dkim; c=relaxed/relaxed; q=dns/txt; h=From; bh=yAjtlREqtUzi3zeRO7aDhDF+AxGZlDKRCOfVsKUr7J4=; b=Nt+eXoSXmVd9Cew4LGZTwt8d4oPdOGzFwOeHS6rFoqTwBlfheGguPSVViZXivB9ZTktQfNb2q DlJYoY8k6TAiygIZxMxdAtguk1j57GTq8hM55pangmOf+fy0+3GZ7CDZ4EPmcsozTHw7ROd05ml A7mx9pYqkowUzVISdguvjU8= Received: from mail.maildlp.com (unknown [172.19.162.223]) by canpmsgout06.his.huawei.com (SkyGuard) with ESMTPS id 4hNdbl6nLPzRhQt; Mon, 17 Aug 2026 11:29:07 +0800 (CST) Received: from kwepemf100017.china.huawei.com (unknown [7.202.181.16]) by mail.maildlp.com (Postfix) with ESMTPS id 111EE40561; Mon, 17 Aug 2026 11:39:46 +0800 (CST) Received: from localhost.localdomain (10.50.85.155) by kwepemf100017.china.huawei.com (7.202.181.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.36; Mon, 17 Aug 2026 11:39:45 +0800 From: Zizhi Wo To: , , , , CC: , , , Subject: [PATCH V2 2/2] md/raid10: fix missing wakeup in wait_barrier_nolock Date: Mon, 17 Aug 2026 11:33:40 +0800 Message-ID: <20260817033340.418119-3-wozizhi@huawei.com> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260817033340.418119-1-wozizhi@huawei.com> References: <20260817033340.418119-1-wozizhi@huawei.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: kwepems500002.china.huawei.com (7.221.188.17) To kwepemf100017.china.huawei.com (7.202.181.16) Content-Type: text/plain; charset="utf-8" [BUG] Recently, our fuzz testing triggered a hungtask issue in RAID10: INFO: task md0_raid10:1273 blocked for more than 120 seconds. Not tainted 7.2.0-rc6+ #94 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:md0_raid10 state:D stack:0 pid:1273 tgid:1273 ppid:2 Call Trace: __schedule+0xdf9/0x5c90 ? _raw_spin_unlock_irqrestore+0xe/0x40 schedule+0x74/0x1f0 raid10d.cold+0x7db/0x1992 md_thread+0x1ce/0x3e0 kthread+0x327/0x410 ...... [CAUSE] The root cause of the issue is as follows: [read process1] [read process2] [raid10d] raid10_make_request ... // nr_pending =3D=3D 1 atomic_inc(&conf->nr_pending) ... raid10_end_read_request reschedule_retry md_wakeup_thread(mddev->thread) raid10_read_request regular_request_wait wait_barrier wait_barrier_nolock seq =3D read_seqbegin(&conf->resync_lock) // nr_pending =3D=3D 2 atomic_inc(&conf->nr_pending) raid10d handle_read_error freeze_array write_seqlock_irq(&conf->resync_lock) conf->array_freeze_pending++ WRITE_ONCE(conf->barrier, conf->barrier + 1) conf->nr_waiting++ // nr_pending =3D=3D 2, nr_queued =3D=3D 0 wait_event_barrier_cmd write_sequnlock_irq(&(conf)->resync_lock) schedule // hungtask!! read_seqretry(&conf->resync_lock, seq) // not wakeup because conf->nr_pending =3D=3D 1 atomic_dec_and_test(&conf->nr_pending) /* Hungtask will also occur here: since the barrier is non-zero, * this I/O can never complete, so it can't call allow_barrier() * to wake up the pending freeze_array(). */ wait_event_barrier(conf, stop_waiting_barrier(conf)) wait_barrier_nolock() speculatively increments nr_pending and, on a seqlock retry, rolls it back with atomic_dec_and_test(). The wake fires only when nr_pending reaches 0. This causes the freeze_array() in the aforementioned raid10d flow to never be woken up. [FIX] Referring to allow_barrier(), this issue can be fixed by adding a wake-up condition for "conf->array_freeze_pending" in wait_barrier_nolock(). Fixes: b9b083f9044a ("md/raid10: convert resync_lock to use seqlock") Signed-off-by: Zizhi Wo Reviewed-by: Abd-Alrhman Masalkhi --- drivers/md/raid10.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c index dc40110a6736..8dadf13c2b4d 100644 --- a/drivers/md/raid10.c +++ b/drivers/md/raid10.c @@ -994,11 +994,12 @@ static bool wait_barrier_nolock(struct r10conf *conf) =20 atomic_inc(&conf->nr_pending); if (!read_seqretry(&conf->resync_lock, seq)) return true; =20 - if (atomic_dec_and_test(&conf->nr_pending)) + if (atomic_dec_and_test(&conf->nr_pending) || + READ_ONCE(conf->array_freeze_pending)) wake_up_barrier(conf); =20 return false; } =20 --=20 2.52.0