From nobody Mon Sep 28 19:23:38 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CC3C45DF5D; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; cv=none; b=YA3ZEcOFFHqwJALSXkkK6V/ZsJO57iPrbyvcVk3mGmcfWZt6GREV5iYn92XLSNKwNo11+gaiGPuVongzSOLoznMlpY2dCsOVAJm0kwgXpyBd2yQLDeWM+Zv8fdcdypsI1qIWMY3RTuJ1INUb7DNmElFYuLuBuoo1Tp4hWmepK58= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; c=relaxed/simple; bh=NRy+vc4hWJQrUiBYfp3itTG4myVbZh4BfWueZTePwcI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=E96p7c5txTdxt0XK9MkHX8pzUZGtEJnqWkjqfyEDijTEimG49c3Uyth3nwl/cC6i49sIvhGzrLmuStWSxgHCSG6hpE+DySBfTQeGATNCQKUGvjeyCdxrk+bAXwzaQgGDW2Jluvsk8JIFO/sT1j7TJB7zWAUzI+SrqJ53Xby2jOI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ge3Vc/Ug; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ge3Vc/Ug" Received: by smtp.kernel.org (Postfix) with ESMTPS id 3A887C2BCFA; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787050696; bh=NRy+vc4hWJQrUiBYfp3itTG4myVbZh4BfWueZTePwcI=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=ge3Vc/UgfLHrwshYnsaz5/jqdSWWz0e1px9OWBxa41Z8AZqYiKgKE5XDaKjEd55Zx /GtZK10q8JWuy9iIUB+kqJnl30MHpSpc+Nqx4K9k1FOa6QBXIiLX0uQiGOqESgNaJW 9XYBnLO+EyyRn2IELPHPcwdbvYzu8aEw3YXtG27aI9X/4f9wyFksGb0Awy2mjhoEQ4 WeIJPzfnOtHJGe8whcsdy8hGlXnwq65Oy7muhrWfFOwEVOAEZiYro3ozSXvT86QNfZ fC7Sq4u5yLkMLoLLUi+bKcAc7XjprmXFCL59MTAV5JCTgMTqgYqw3iYp0k3cfrVvHh 9g1radF83j2JQ== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1AEC3C5DF70; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) From: Xiubo Li via B4 Relay Date: Tue, 18 Aug 2026 03:58:08 -0700 Subject: [PATCH v5 1/5] ceph: use READ_ONCE/WRITE_ONCE for oldest_tid Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-ceph-mdsc-mutex-optimization-v5-1-7d335a3a1d0b@clyso.com> References: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> In-Reply-To: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> To: Ilya Dryomov , Alex Markuze , Viacheslav Dubeyko Cc: ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Xiubo Li X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787050693; l=3350; i=xiubo.li@clyso.com; s=20260625; h=from:subject:message-id; bh=exqvyxSW2xd5rzPWwAc/Vr8hxgWOg5BerR4rCyEJz+w=; b=iD5N9+N7NjyZYt3P0hgtQnmPesD8w/45v7DH9pOWBnc4yzVSEobm6aN3wTJPLsIIah3zY0pvQ 1KCouTplQ0rCrqdCDBZa34mA2cRwLDRuVIptdZQ+IpxDMyduK96x+N4 X-Developer-Key: i=xiubo.li@clyso.com; a=ed25519; pk=V3NGr0AgAopiUhaLY51ipBkLN5LlcLhjOEfLEq1RoZ8= X-Endpoint-Received: by B4 Relay for xiubo.li@clyso.com/20260625 with auth_id=840 X-Original-From: Xiubo Li Reply-To: xiubo.li@clyso.com From: Xiubo Li The oldest_client_tid sent in the MDS request header is advisory: a stale value is harmless --- at worst the MDS may resend a reply the client already has, or trim its completed-requests table slightly earlier or later than optimal, both of which the protocol handles correctly. The field is monotonic and does not need lock serialization to stay correct. Switch all accesses to READ_ONCE() and WRITE_ONCE() to prevent the compiler from tearing or inventing loads, documenting that these lockless accesses are intentional. This removes the last reason the MDS request-send path had to be serialized under mdsc->mutex. Signed-off-by: Xiubo Li --- fs/ceph/mds_client.c | 20 +++++++------------- 1 file changed, 7 insertions(+), 13 deletions(-) diff --git a/fs/ceph/mds_client.c b/fs/ceph/mds_client.c index f365e434e35d..2c51edd0e9cd 100644 --- a/fs/ceph/mds_client.c +++ b/fs/ceph/mds_client.c @@ -1240,8 +1240,8 @@ static void __register_request(struct ceph_mds_client= *mdsc, if (!req->r_mnt_idmap) req->r_mnt_idmap =3D &nop_mnt_idmap; =20 - if (mdsc->oldest_tid =3D=3D 0 && req->r_op !=3D CEPH_MDS_OP_SETFILELOCK) - mdsc->oldest_tid =3D req->r_tid; + if (READ_ONCE(mdsc->oldest_tid) =3D=3D 0 && req->r_op !=3D CEPH_MDS_OP_SE= TFILELOCK) + WRITE_ONCE(mdsc->oldest_tid, req->r_tid); =20 if (dir) { struct ceph_inode_info *ci =3D ceph_inode(dir); @@ -1262,14 +1262,14 @@ static void __unregister_request(struct ceph_mds_cl= ient *mdsc, /* Never leave an unregistered request on an unsafe list! */ list_del_init(&req->r_unsafe_item); =20 - if (req->r_tid =3D=3D mdsc->oldest_tid) { + if (req->r_tid =3D=3D READ_ONCE(mdsc->oldest_tid)) { struct rb_node *p =3D rb_next(&req->r_node); - mdsc->oldest_tid =3D 0; + WRITE_ONCE(mdsc->oldest_tid, 0); while (p) { struct ceph_mds_request *next_req =3D rb_entry(p, struct ceph_mds_request, r_node); if (next_req->r_op !=3D CEPH_MDS_OP_SETFILELOCK) { - mdsc->oldest_tid =3D next_req->r_tid; + WRITE_ONCE(mdsc->oldest_tid, next_req->r_tid); break; } p =3D rb_next(p); @@ -1698,7 +1698,7 @@ create_session_full_msg(struct ceph_mds_client *mdsc,= int op, u64 seq) ceph_encode_32(&p, 0); =20 /* version =3D=3D 7, oldest_client_tid */ - ceph_encode_64(&p, mdsc->oldest_tid); + ceph_encode_64(&p, READ_ONCE(mdsc->oldest_tid)); =20 msg->front.iov_len =3D p - msg->front.iov_base; msg->hdr.front_len =3D cpu_to_le32(msg->front.iov_len); @@ -2764,7 +2764,7 @@ static struct ceph_mds_request *__get_oldest_req(stru= ct ceph_mds_client *mdsc) =20 static inline u64 __get_oldest_tid(struct ceph_mds_client *mdsc) { - return mdsc->oldest_tid; + return READ_ONCE(mdsc->oldest_tid); } =20 #if IS_ENABLED(CONFIG_FS_ENCRYPTION) @@ -3443,9 +3443,6 @@ static void complete_request(struct ceph_mds_client *= mdsc, complete_all(&req->r_completion); } =20 -/* - * called under mdsc->mutex - */ static int __prepare_send_request(struct ceph_mds_session *session, struct ceph_mds_request *req, bool drop_cap_releases) @@ -3560,9 +3557,6 @@ static int __prepare_send_request(struct ceph_mds_ses= sion *session, return 0; } =20 -/* - * called under mdsc->mutex - */ static int __send_request(struct ceph_mds_session *session, struct ceph_mds_request *req, bool drop_cap_releases) --=20 2.53.0 From nobody Mon Sep 28 19:23:38 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CAE245D5DB; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; cv=none; b=U/fp0kCk79dlU5NBY1EQfMLxhEmSvOiokE7cpmeVc+RSKogzohkrMFpjKzSg3ClOyfmfLaNSHMLD4N9dcpOsU+Dzu9H3I7Fsv3XKYEy5ki3jy2ZsVyP9jSkEB0wKhehr5YHiUS1F1FnMpPyTmYdglnkzctEUK6WflCTzT1szihQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; c=relaxed/simple; bh=91+7/frEMLm5t4qfjeKHnincp9BQzBV2pqikrHqKSQo=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Gum0QWdYsYcUOeJJ5oXPIh7aVUWsAEKjfYJrQqTom9NkavIPQLH9LK0/vRcXQok4QxfOxrQ7w0drvc3jz09nMWzRWLhbplSpqWiEVHHK0ncdA6J0YhCJ/9E2De57SAYLSSRV1hKhAPdX3QmSDaQgn4rUfNse5wxaNSSTmMzDxd4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=YsqoN956; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="YsqoN956" Received: by smtp.kernel.org (Postfix) with ESMTPS id 47486C2BCFB; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787050696; bh=91+7/frEMLm5t4qfjeKHnincp9BQzBV2pqikrHqKSQo=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=YsqoN956vnDGMMsU9BMQEy3fmfxbsbB0r8VZnz5oj9602e0X85bOCW0ZdUY00llUN gXt4GHzuRUdEfZufCH4YTYe6RN67cVUi1Rqn37tw+2Fll7b3Qn1Yx+hjFk8Yay2PoF c0scVegDN2XeNhMUN6fApsCAlxEy0q3e9VTiDpjo7XvYGSt0s91lwWskCkwngprdrX TRSFN8wJ0YYz32dw4uMyQyKymb9fRA6imXcwxSVx9cluwbX9ApHb71nSmVPsTKHqw9 dcEpQKUl5Furf2TfGFYloPmZZL8/DHQMOThHxXZ6d4enDiKLXPfENvyCSv9dfROpsO TIkULeveWn3/w== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A8A0C5DF7E; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) From: Xiubo Li via B4 Relay Date: Tue, 18 Aug 2026 03:58:09 -0700 Subject: [PATCH v5 2/5] ceph: replace the request_tree rbtree with an xarray keyed by r_tid Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-ceph-mdsc-mutex-optimization-v5-2-7d335a3a1d0b@clyso.com> References: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> In-Reply-To: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> To: Ilya Dryomov , Alex Markuze , Viacheslav Dubeyko Cc: ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Xiubo Li X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787050693; l=11800; i=xiubo.li@clyso.com; s=20260625; h=from:subject:message-id; bh=ReChigIhMkeXtZj0pJ89gZHi/rbO4lqw10o8xu89Wsg=; b=5Us0+HoilaFPhsCgC0pDHobnlkHddjiiNRIPQVzyETF2j7L6aZw1e/suecpdUbq78UTcIEXy8 Qm/vdNh5vG/DhBt7oLcopGW1spjKft1kx1EuI1LFl1duz3LMcCLlK2b X-Developer-Key: i=xiubo.li@clyso.com; a=ed25519; pk=V3NGr0AgAopiUhaLY51ipBkLN5LlcLhjOEfLEq1RoZ8= X-Endpoint-Received: by B4 Relay for xiubo.li@clyso.com/20260625 with auth_id=840 X-Original-From: Xiubo Li Reply-To: xiubo.li@clyso.com From: Xiubo Li Replace the red-black tree that indexes pending MDS requests by transaction ID with an xarray. The xarray provides O(1) keyed lookups versus the rbtree's O(log N), and its internal RCU locking eliminates the need for an external mutex during lookups. Iteration is also simpler, with the xarray's native iterators replacing open-coded rb_first() / rb_next() walks. Because xarray indices are unsigned long, a u64 transaction ID would be truncated on 32-bit platforms. Restrict CEPH_FS to 64BIT since there are no 32-bit users. Validate the xarray insertion and clean up the structure at shutdown. Signed-off-by: Xiubo Li --- fs/ceph/Kconfig | 1 + fs/ceph/debugfs.c | 6 +-- fs/ceph/mds_client.c | 113 +++++++++++++++++++++++------------------------= ---- fs/ceph/mds_client.h | 3 +- 4 files changed, 56 insertions(+), 67 deletions(-) diff --git a/fs/ceph/Kconfig b/fs/ceph/Kconfig index 3d64a316ca31..1d95f9c7e271 100644 --- a/fs/ceph/Kconfig +++ b/fs/ceph/Kconfig @@ -2,6 +2,7 @@ config CEPH_FS tristate "Ceph distributed file system" depends on INET + depends on 64BIT select CEPH_LIB select NETFS_SUPPORT select FS_ENCRYPTION_ALGS if FS_ENCRYPTION diff --git a/fs/ceph/debugfs.c b/fs/ceph/debugfs.c index 18eb5da03411..491ead3fe1c6 100644 --- a/fs/ceph/debugfs.c +++ b/fs/ceph/debugfs.c @@ -87,12 +87,12 @@ static int mdsc_show(struct seq_file *s, void *p) struct ceph_fs_client *fsc =3D s->private; struct ceph_mds_client *mdsc =3D fsc->mdsc; struct ceph_mds_request *req; - struct rb_node *rp; + unsigned long idx; char *path; =20 mutex_lock(&mdsc->mutex); - for (rp =3D rb_first(&mdsc->request_tree); rp; rp =3D rb_next(rp)) { - req =3D rb_entry(rp, struct ceph_mds_request, r_node); + idx =3D 0; + xa_for_each(&mdsc->request_tree, idx, req) { =20 if (req->r_request && req->r_session) seq_printf(s, "%lld\tmds%d\t", req->r_tid, diff --git a/fs/ceph/mds_client.c b/fs/ceph/mds_client.c index 2c51edd0e9cd..c1df7e0ac051 100644 --- a/fs/ceph/mds_client.c +++ b/fs/ceph/mds_client.c @@ -1188,7 +1188,6 @@ void ceph_mdsc_release_request(struct kref *kref) kmem_cache_free(ceph_mds_request_cachep, req); } =20 -DEFINE_RB_FUNCS(request, struct ceph_mds_request, r_tid, r_node) =20 /* * lookup session, bump ref if found. @@ -1200,7 +1199,7 @@ lookup_get_request(struct ceph_mds_client *mdsc, u64 = tid) { struct ceph_mds_request *req; =20 - req =3D lookup_request(&mdsc->request_tree, tid); + req =3D xa_load(&mdsc->request_tree, tid); if (req) ceph_mdsc_get_request(req); =20 @@ -1234,7 +1233,14 @@ static void __register_request(struct ceph_mds_clien= t *mdsc, } doutc(cl, "%p tid %lld\n", req, req->r_tid); ceph_mdsc_get_request(req); - insert_request(&mdsc->request_tree, req); + if (xa_is_err(xa_store(&mdsc->request_tree, req->r_tid, req, + GFP_NOFS))) { + pr_err_client(cl, "%p tid %lld: xa_store failed\n", + req, req->r_tid); + ceph_mdsc_put_request(req); + req->r_err =3D -ENOMEM; + return; + } =20 req->r_cred =3D get_current_cred(); if (!req->r_mnt_idmap) @@ -1263,20 +1269,19 @@ static void __unregister_request(struct ceph_mds_cl= ient *mdsc, list_del_init(&req->r_unsafe_item); =20 if (req->r_tid =3D=3D READ_ONCE(mdsc->oldest_tid)) { - struct rb_node *p =3D rb_next(&req->r_node); + unsigned long tidx =3D req->r_tid + 1; + struct ceph_mds_request *next_req; + WRITE_ONCE(mdsc->oldest_tid, 0); - while (p) { - struct ceph_mds_request *next_req =3D - rb_entry(p, struct ceph_mds_request, r_node); + xa_for_each_start(&mdsc->request_tree, tidx, next_req, tidx) { if (next_req->r_op !=3D CEPH_MDS_OP_SETFILELOCK) { WRITE_ONCE(mdsc->oldest_tid, next_req->r_tid); break; } - p =3D rb_next(p); } } =20 - erase_request(&mdsc->request_tree, req); + xa_erase(&mdsc->request_tree, req->r_tid); =20 if (req->r_unsafe_dir) { struct ceph_inode_info *ci =3D ceph_inode(req->r_unsafe_dir); @@ -1833,7 +1838,7 @@ static void cleanup_session_requests(struct ceph_mds_= client *mdsc, { struct ceph_client *cl =3D mdsc->fsc->client; struct ceph_mds_request *req; - struct rb_node *p; + unsigned long idx; =20 doutc(cl, "mds%d\n", session->s_mds); mutex_lock(&mdsc->mutex); @@ -1849,10 +1854,8 @@ static void cleanup_session_requests(struct ceph_mds= _client *mdsc, __unregister_request(mdsc, req); } /* zero r_attempts, so kick_requests() will re-send requests */ - p =3D rb_first(&mdsc->request_tree); - while (p) { - req =3D rb_entry(p, struct ceph_mds_request, r_node); - p =3D rb_next(p); + idx =3D 0; + xa_for_each(&mdsc->request_tree, idx, req) { if (req->r_session && req->r_session->s_mds =3D=3D session->s_mds) req->r_attempts =3D 0; @@ -2736,7 +2739,6 @@ ceph_mdsc_create_request(struct ceph_mds_client *mdsc= , int op, int mode) req->r_fmode =3D -1; req->r_feature_needed =3D -1; kref_init(&req->r_kref); - RB_CLEAR_NODE(&req->r_node); INIT_LIST_HEAD(&req->r_wait); init_completion(&req->r_completion); init_completion(&req->r_safe_completion); @@ -2756,10 +2758,9 @@ ceph_mdsc_create_request(struct ceph_mds_client *mds= c, int op, int mode) */ static struct ceph_mds_request *__get_oldest_req(struct ceph_mds_client *m= dsc) { - if (RB_EMPTY_ROOT(&mdsc->request_tree)) - return NULL; - return rb_entry(rb_first(&mdsc->request_tree), - struct ceph_mds_request, r_node); + unsigned long idx =3D 0; + + return xa_find(&mdsc->request_tree, &idx, ULONG_MAX, XA_PRESENT); } =20 static inline u64 __get_oldest_tid(struct ceph_mds_client *mdsc) @@ -3820,12 +3821,11 @@ static void kick_requests(struct ceph_mds_client *m= dsc, int mds) { struct ceph_client *cl =3D mdsc->fsc->client; struct ceph_mds_request *req; - struct rb_node *p =3D rb_first(&mdsc->request_tree); + unsigned long idx; =20 doutc(cl, "kick_requests mds%d\n", mds); - while (p) { - req =3D rb_entry(p, struct ceph_mds_request, r_node); - p =3D rb_next(p); + idx =3D 0; + xa_for_each(&mdsc->request_tree, idx, req) { if (test_bit(CEPH_MDS_R_GOT_UNSAFE, &req->r_req_flags)) continue; if (req->r_attempts > 0) @@ -4668,7 +4668,7 @@ static void replay_unsafe_requests(struct ceph_mds_cl= ient *mdsc, struct ceph_mds_session *session) { struct ceph_mds_request *req, *nreq; - struct rb_node *p; + unsigned long idx; =20 doutc(mdsc->fsc->client, "mds%d\n", session->s_mds); =20 @@ -4680,10 +4680,8 @@ static void replay_unsafe_requests(struct ceph_mds_c= lient *mdsc, * also re-send old requests when MDS enters reconnect stage. So that MDS * can process completed request in clientreplay stage. */ - p =3D rb_first(&mdsc->request_tree); - while (p) { - req =3D rb_entry(p, struct ceph_mds_request, r_node); - p =3D rb_next(p); + idx =3D 0; + xa_for_each(&mdsc->request_tree, idx, req) { if (test_bit(CEPH_MDS_R_GOT_UNSAFE, &req->r_req_flags)) continue; if (req->r_attempts =3D=3D 0) @@ -5528,7 +5526,7 @@ static void ceph_mdsc_reset_workfn(struct work_struct= *work) */ { struct ceph_mds_request *req; - struct rb_node *rn; + unsigned long idx; u64 last_tid; =20 mutex_lock(&mdsc->mutex); @@ -5536,14 +5534,12 @@ static void ceph_mdsc_reset_workfn(struct work_stru= ct *work) mutex_unlock(&mdsc->mutex); =20 mutex_lock(&mdsc->mutex); - rn =3D rb_first(&mdsc->request_tree); - while (rn) { - req =3D rb_entry(rn, struct ceph_mds_request, r_node); - if (req->r_tid > last_tid) - break; + idx =3D 0; + while ((req =3D xa_find(&mdsc->request_tree, &idx, last_tid, + XA_PRESENT))) { if (req->r_op =3D=3D CEPH_MDS_OP_SETFILELOCK || !(req->r_op & CEPH_MDS_OP_WRITE)) { - rn =3D rb_next(rn); + idx++; continue; } ceph_mdsc_get_request(req); @@ -5556,7 +5552,7 @@ static void ceph_mdsc_reset_workfn(struct work_struct= *work) ceph_mdsc_put_request(req); if (time_after(jiffies, drain_deadline)) break; - rn =3D rb_first(&mdsc->request_tree); + idx =3D 0; /* restart: tree may have changed */ } mutex_unlock(&mdsc->mutex); =20 @@ -6282,7 +6278,7 @@ int ceph_mdsc_init(struct ceph_fs_client *fsc) mdsc->snap_realms =3D RB_ROOT; INIT_LIST_HEAD(&mdsc->snap_empty); spin_lock_init(&mdsc->snap_empty_lock); - mdsc->request_tree =3D RB_ROOT; + xa_init(&mdsc->request_tree); INIT_DELAYED_WORK(&mdsc->delayed_work, delayed_work); mdsc->last_renew_caps =3D jiffies; INIT_LIST_HEAD(&mdsc->cap_delay_list); @@ -6604,34 +6600,33 @@ static void flush_mdlog_and_wait_mdsc_unsafe_reques= ts(struct ceph_mds_client *md u64 want_tid) { struct ceph_client *cl =3D mdsc->fsc->client; - struct ceph_mds_request *req =3D NULL, *nextreq; + struct ceph_mds_request *req; struct ceph_mds_session *last_session =3D NULL; - struct rb_node *n; + unsigned long idx; =20 mutex_lock(&mdsc->mutex); doutc(cl, "want %lld\n", want_tid); -restart: - req =3D __get_oldest_req(mdsc); - while (req && req->r_tid <=3D want_tid) { - /* find next request */ - n =3D rb_next(&req->r_node); - if (n) - nextreq =3D rb_entry(n, struct ceph_mds_request, r_node); - else - nextreq =3D NULL; - if (req->r_op !=3D CEPH_MDS_OP_SETFILELOCK && - (req->r_op & CEPH_MDS_OP_WRITE)) { + idx =3D 0; + while ((req =3D xa_find(&mdsc->request_tree, &idx, want_tid, + XA_PRESENT))) { + u64 next_tid =3D req->r_tid + 1; + + if (req->r_op =3D=3D CEPH_MDS_OP_SETFILELOCK || + !(req->r_op & CEPH_MDS_OP_WRITE)) { + idx =3D next_tid; + continue; + } + + { struct ceph_mds_session *s =3D req->r_session; =20 if (!s) { - req =3D nextreq; + idx =3D next_tid; continue; } =20 /* write op */ ceph_mdsc_get_request(req); - if (nextreq) - ceph_mdsc_get_request(nextreq); s =3D ceph_get_mds_session(s); mutex_unlock(&mdsc->mutex); =20 @@ -6649,16 +6644,9 @@ static void flush_mdlog_and_wait_mdsc_unsafe_request= s(struct ceph_mds_client *md =20 mutex_lock(&mdsc->mutex); ceph_mdsc_put_request(req); - if (!nextreq) - break; /* next dne before, so we're done! */ - if (RB_EMPTY_NODE(&nextreq->r_node)) { - /* next request was removed from tree */ - ceph_mdsc_put_request(nextreq); - goto restart; - } - ceph_mdsc_put_request(nextreq); /* won't go away */ + /* restart from the next tid; tree may have changed */ + idx =3D next_tid; } - req =3D nextreq; } mutex_unlock(&mdsc->mutex); ceph_put_mds_session(last_session); @@ -6817,6 +6805,7 @@ static void ceph_mdsc_stop(struct ceph_mds_client *md= sc) if (mdsc->mdsmap) ceph_mdsmap_destroy(mdsc->mdsmap); kfree(mdsc->sessions); + xa_destroy(&mdsc->request_tree); ceph_caps_finalize(mdsc); =20 if (mdsc->s_cap_auths) { diff --git a/fs/ceph/mds_client.h b/fs/ceph/mds_client.h index 0ece4c9e3529..976dc9ffac17 100644 --- a/fs/ceph/mds_client.h +++ b/fs/ceph/mds_client.h @@ -330,7 +330,6 @@ typedef int (*ceph_mds_request_wait_callback_t) (struct= ceph_mds_client *mdsc, */ struct ceph_mds_request { u64 r_tid; /* transaction id */ - struct rb_node r_node; struct ceph_mds_client *r_mdsc; =20 struct kref r_kref; @@ -535,7 +534,7 @@ struct ceph_mds_client { u64 last_tid; /* most recent mds request */ u64 oldest_tid; /* oldest incomplete mds request, excluding setfilelock requests */ - struct rb_root request_tree; /* pending mds requests */ + struct xarray request_tree; /* pending mds requests */ struct delayed_work delayed_work; /* delayed work */ unsigned long last_renew_caps; /* last time we renewed our caps */ struct list_head cap_delay_list; /* caps with delayed release */ --=20 2.53.0 From nobody Mon Sep 28 19:23:38 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8C9B5451071; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; cv=none; b=ayTrn4nD4QtMNFfs0IeqUaL51nzZA6YTjTLPHiBJkjFM2i2jhzp05SDVCfCGCwqfF4nNt2W8yuQIwD4d2fatfqBKi/ZxftgXAHShjw9CB6G426m20JyHub4pNWkpMFeUVbCUavx9e+08JHmCRYt+wPDKwiizFvMgyPm7/Buvxlk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; c=relaxed/simple; bh=r5NSFB0GQRcWvJS2ZewGRoiQwc0nvL37T45wc6VBUn8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=HBRck6A9IPKnTQsrvk4WH5CWTQT0nex4IwoKthebvGyz8cph3Jbf/YmMvSGuokgzzvGpN/PCbzZmhvJ5OkOgUS9BRQ+R8z8cRKrmdVRKJxUcwXK5IRHa+ycBwhW6r8OC4ZNT3cGvHNP/kVGqppBIOcccob6ThvarSGIUVhdFCn0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=KJ1OeoLF; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="KJ1OeoLF" Received: by smtp.kernel.org (Postfix) with ESMTPS id 51733C19425; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787050696; bh=r5NSFB0GQRcWvJS2ZewGRoiQwc0nvL37T45wc6VBUn8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=KJ1OeoLFx2wSgQU1fwSuiIIoTRtdUPfEoRLP8fryB+EBay7inbBM4JdnTip5uChWq ZCelsd8mZ/5NNrHXuNu/AdHm0GFdLaA2Pq8r3A3o9W6jRwpXJ8ER1v1hjShXWaizWk Qcj7GqRB2O6KQIo/ZbD7JUlunhJXDwtcrO/z6QP9kma4NFVLW6JnqZKClsoDrKEYsY 0UF1e0L3Es5pvbOpAyMtAUAsnlzy+1i2mtJlLtL21GiFlVmeJWptNXgi1a7r7AleDl Uz1MjRvv39PVWdSXagZ+H1nTMaQAQqR9VaIshdWcnJyWX8IeBkHwIZsVvJVN3W2/cS x52M33A8sjApg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 39D90C5DF81; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) From: Xiubo Li via B4 Relay Date: Tue, 18 Aug 2026 03:58:10 -0700 Subject: [PATCH v5 3/5] ceph: add wait_list_lock for wait-list serialization Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-ceph-mdsc-mutex-optimization-v5-3-7d335a3a1d0b@clyso.com> References: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> In-Reply-To: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> To: Ilya Dryomov , Alex Markuze , Viacheslav Dubeyko Cc: ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Xiubo Li X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787050693; l=4398; i=xiubo.li@clyso.com; s=20260625; h=from:subject:message-id; bh=2KmjEKVQQSocgdYVXOQzPvN7CxFSrsQMZ0Mr/Vn+7cU=; b=cnuhx7/DDxgJUAnEOpAQBR/rfVP4XGtlmU/Ae+wu16+LYeuGLskG888HI7kdjVtc4ybz9ZlJE L90EOZn46qRA1yAz5/x6iyQlaETOWmWvpO8mYunV7hIZrbA++qmPzcu X-Developer-Key: i=xiubo.li@clyso.com; a=ed25519; pk=V3NGr0AgAopiUhaLY51ipBkLN5LlcLhjOEfLEq1RoZ8= X-Endpoint-Received: by B4 Relay for xiubo.li@clyso.com/20260625 with auth_id=840 X-Original-From: Xiubo Li Reply-To: xiubo.li@clyso.com From: Xiubo Li The per-MDS session wait list and the global waiting-for-map list are currently serialized by mdsc->mutex, even though the list operations themselves don't need the mutex's broader protection. Introduce a dedicated spinlock to guard these lists so that waking and kicking waiters can run outside the mutex. Reviewed-by: Viacheslav Dubeyko Signed-off-by: Xiubo Li --- fs/ceph/mds_client.c | 18 +++++++++++++++++- fs/ceph/mds_client.h | 3 +++ 2 files changed, 20 insertions(+), 1 deletion(-) diff --git a/fs/ceph/mds_client.c b/fs/ceph/mds_client.c index c1df7e0ac051..f35aa194795e 100644 --- a/fs/ceph/mds_client.c +++ b/fs/ceph/mds_client.c @@ -3619,7 +3619,9 @@ static void __do_request(struct ceph_mds_client *mdsc, doutc(cl, "no mdsmap, waiting for map\n"); trace_ceph_mdsc_suspend_request(mdsc, session, req, ceph_mdsc_suspend_reason_no_mdsmap); + spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &mdsc->waiting_for_map); + spin_unlock(&mdsc->wait_list_lock); return; } if (!(mdsc->fsc->mount_options->flags & @@ -3642,7 +3644,9 @@ static void __do_request(struct ceph_mds_client *mdsc, doutc(cl, "no mds or not active, waiting for map\n"); trace_ceph_mdsc_suspend_request(mdsc, session, req, ceph_mdsc_suspend_reason_no_active_mds); + spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &mdsc->waiting_for_map); + spin_unlock(&mdsc->wait_list_lock); return; } =20 @@ -3690,9 +3694,12 @@ static void __do_request(struct ceph_mds_client *mds= c, if (ceph_test_mount_opt(mdsc->fsc, CLEANRECOVER)) { trace_ceph_mdsc_suspend_request(mdsc, session, req, ceph_mdsc_suspend_reason_rejected); + spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &mdsc->waiting_for_map); - } else + spin_unlock(&mdsc->wait_list_lock); + } else { err =3D -EACCES; + } goto out_session; } =20 @@ -3707,7 +3714,9 @@ static void __do_request(struct ceph_mds_client *mdsc, } trace_ceph_mdsc_suspend_request(mdsc, session, req, ceph_mdsc_suspend_reason_session); + spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &session->s_waiting); + spin_unlock(&mdsc->wait_list_lock); goto out_session; } =20 @@ -3800,7 +3809,9 @@ static void __wake_requests(struct ceph_mds_client *m= dsc, struct ceph_mds_request *req; LIST_HEAD(tmp_list); =20 + spin_lock(&mdsc->wait_list_lock); list_splice_init(head, &tmp_list); + spin_unlock(&mdsc->wait_list_lock); =20 while (!list_empty(&tmp_list)) { req =3D list_entry(tmp_list.next, @@ -3833,7 +3844,9 @@ static void kick_requests(struct ceph_mds_client *mds= c, int mds) if (req->r_session && req->r_session->s_mds =3D=3D mds) { doutc(cl, " kicking tid %llu\n", req->r_tid); + spin_lock(&mdsc->wait_list_lock); list_del_init(&req->r_wait); + spin_unlock(&mdsc->wait_list_lock); trace_ceph_mdsc_resume_request(mdsc, req); __do_request(mdsc, req); } @@ -6278,6 +6291,7 @@ int ceph_mdsc_init(struct ceph_fs_client *fsc) mdsc->snap_realms =3D RB_ROOT; INIT_LIST_HEAD(&mdsc->snap_empty); spin_lock_init(&mdsc->snap_empty_lock); + spin_lock_init(&mdsc->wait_list_lock); xa_init(&mdsc->request_tree); INIT_DELAYED_WORK(&mdsc->delayed_work, delayed_work); mdsc->last_renew_caps =3D jiffies; @@ -6360,7 +6374,9 @@ static void wait_requests(struct ceph_mds_client *mds= c) mutex_lock(&mdsc->mutex); while ((req =3D __get_oldest_req(mdsc))) { doutc(cl, "timed out on tid %llu\n", req->r_tid); + spin_lock(&mdsc->wait_list_lock); list_del_init(&req->r_wait); + spin_unlock(&mdsc->wait_list_lock); __unregister_request(mdsc, req); } } diff --git a/fs/ceph/mds_client.h b/fs/ceph/mds_client.h index 976dc9ffac17..19d2eae9da5b 100644 --- a/fs/ceph/mds_client.h +++ b/fs/ceph/mds_client.h @@ -530,6 +530,9 @@ struct ceph_mds_client { struct list_head snap_empty; int num_snap_realms; spinlock_t snap_empty_lock; /* protect snap_empty */ + spinlock_t wait_list_lock; /* protect waiting_for_map + * and s_waiting lists + */ =20 u64 last_tid; /* most recent mds request */ u64 oldest_tid; /* oldest incomplete mds request, --=20 2.53.0 From nobody Mon Sep 28 19:23:38 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8CB9045D5E7; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; cv=none; b=t7Qd5REa8WzZbJJPzGMaPeMo8ZLdocfKhW0toOk5ByVITqHy9R6B/1xpNsh7a0t5/dwhVAoDFcskIufIeMREAt6UuXE18D9wY8SWe4krsF3RCS8CwxGcvdGK8Peejz+XkYwy9XDTwItoS5099aesJzJTlxi1rD58wxeEvZ72Dw8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; c=relaxed/simple; bh=EiyOTyFIQLFNGMlgwgxoaGOWVu7THjzlAb6j56h+s0Q=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=jxltZEYUL9/FWumyEPWk3rSE9uQVJ22T+TQE7mvnNrprKeizISJNoBHPKHI98Dq3k3Fkv1vy0f/3AIVC9y/T5yi/JB1DYX9X9yXWBBkXE4hpvTIVWAdCs+7V9CPqJXjQGVZgvqVGRJu3kU+6LeVqOgJd79TgnwJk6HvYrrjU0mE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=LwiKJ1U9; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="LwiKJ1U9" Received: by smtp.kernel.org (Postfix) with ESMTPS id 5D379C2BD00; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787050696; bh=EiyOTyFIQLFNGMlgwgxoaGOWVu7THjzlAb6j56h+s0Q=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=LwiKJ1U9jFO6fAhBuahQiMqjQE3FBfxgdqqr4R8D9U4q3MsOdm/iPyJ782YKkxVxH Aubg3A7WpRK+2cFhDEJavZuKkbePTscz+qOXMcdwfkdxEqPn6RL/CG3LA8rvStbxEA +o1HM1z5O6RoWOsv6dy8QLlGCg5UIoAQZ+/1JePwkuhy9QXU4YNvEJWGIiJeS5kPb7 OXHDkJp37iAXLQZjhN17hOiUXX5vEQ8H3OhUarRNK5OGsCPD4t3HHS3vb5RTaUrRvP FwZ6yhnLW2EBTqBYo2F3e7tSvzzG31YIju0euCHUe4n+HQTcyypmLqNiAlS4bB++VZ TV8DpH8TKUkEg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4973EC5DF80; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) From: Xiubo Li via B4 Relay Date: Tue, 18 Aug 2026 03:58:11 -0700 Subject: [PATCH v5 4/5] ceph: move mdsc->mutex into __do_request() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-ceph-mdsc-mutex-optimization-v5-4-7d335a3a1d0b@clyso.com> References: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> In-Reply-To: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> To: Ilya Dryomov , Alex Markuze , Viacheslav Dubeyko Cc: ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Xiubo Li X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787050693; l=14134; i=xiubo.li@clyso.com; s=20260625; h=from:subject:message-id; bh=R5iownZcbw5WkgdADYZGNONBbq6M0MX3T8goiqp70mc=; b=SCgdHeWrMDrGX2nSGhaEODUXZfoB0R5C+l8QVODs0MNyNpDszqts4l3vFvfH5/H8Ob4SxDEBp ACX/qhyh9fDAzViNWgk+/PT63ZXUUPGsLTOP5N4vsN1ZKtUnfmPOou8 X-Developer-Key: i=xiubo.li@clyso.com; a=ed25519; pk=V3NGr0AgAopiUhaLY51ipBkLN5LlcLhjOEfLEq1RoZ8= X-Endpoint-Received: by B4 Relay for xiubo.li@clyso.com/20260625 with auth_id=840 X-Original-From: Xiubo Li Reply-To: xiubo.li@clyso.com From: Xiubo Li Currently every caller must hold mdsc->mutex when invoking the request-send machinery. Move the mutex acquisition inside __do_request() so that callers can fire off a request without first serializing on the global lock. The mutex is released before the network send phase and re-acquired only for cleanup, so dentry traversal and message construction run concurrently across CPUs. This is the primary source of the observed 2x stat throughput improvement: the per-request send path shrinks from hundreds of microseconds to tens of microseconds once it no longer waits on the mutex. Wait-list draining, session-state wake-ups, and request kicking are reworked to either use the new wait-list spinlock or collect candidates under the mutex and process them outside it. Signed-off-by: Xiubo Li --- fs/ceph/mds_client.c | 118 +++++++++++++++++++++++++++++++++++------------= ---- fs/ceph/mds_client.h | 1 + 2 files changed, 83 insertions(+), 36 deletions(-) diff --git a/fs/ceph/mds_client.c b/fs/ceph/mds_client.c index f35aa194795e..c624f80aa5fd 100644 --- a/fs/ceph/mds_client.c +++ b/fs/ceph/mds_client.c @@ -2743,6 +2743,7 @@ ceph_mdsc_create_request(struct ceph_mds_client *mdsc= , int op, int mode) init_completion(&req->r_completion); init_completion(&req->r_safe_completion); INIT_LIST_HEAD(&req->r_unsafe_item); + INIT_LIST_HEAD(&req->r_aux_item); =20 ktime_get_coarse_real_ts64(&req->r_stamp); =20 @@ -3462,20 +3463,23 @@ static int __prepare_send_request(struct ceph_mds_s= ession *session, * Avoid infinite retrying after overflow. The client will * increase the retry count and if the MDS is old version, * so we limit to retry at most 256 times. + * + * r_attempts was already incremented under mdsc->mutex by the + * caller (__do_request or replay_unsafe_requests), so the + * actual retry count is r_attempts - 1 and we skip the check + * on the first dispatch (r_attempts =3D=3D 1). */ - if (req->r_attempts) { - old_max_retry =3D sizeof_field(struct ceph_mds_request_head, - num_retry); - old_max_retry =3D 1 << (old_max_retry * BITS_PER_BYTE); - if ((old_version && req->r_attempts >=3D old_max_retry) || - ((uint32_t)req->r_attempts >=3D U32_MAX)) { + if (req->r_attempts > 1) { + old_max_retry =3D sizeof_field(struct ceph_mds_request_head, + num_retry); + old_max_retry =3D 1 << (old_max_retry * BITS_PER_BYTE); + if ((old_version && (req->r_attempts - 1) >=3D old_max_retry) || + ((uint32_t)(req->r_attempts - 1) >=3D U32_MAX)) { pr_warn_ratelimited_client(cl, "request tid %llu seq overflow\n", req->r_tid); return -EMULTIHOP; - } + } } - - req->r_attempts++; if (req->r_inode) { struct ceph_cap *cap =3D ceph_get_cap_for_mds(ceph_inode(req->r_inode), mds); @@ -3587,9 +3591,36 @@ static void __do_request(struct ceph_mds_client *mds= c, int err =3D 0; bool random; =20 + mutex_lock(&mdsc->mutex); + + /* + * r_attempts is bumped under mdsc->mutex just before the mutex + * is dropped to send the request, and it is only ever written + * back to 0 by the forward handler or cleanup_session_requests() + * (both under the mutex) before re-dispatching through a new + * __do_request() call. Consequently, r_attempts > 0 at this + * point always means another __do_request() instance has already + * passed the point of no return for this request, i.e. a racing + * kick_requests() or __wake_requests() picked up the same + * request from the xarray or a wait list and is about to send + * it. Bail out to prevent a double dispatch. + * + * Note: kick_requests() also filters on r_attempts > 0 during + * its collection pass, but that is a one-time snapshot taken + * under the mutex. Between that snapshot and the actual + * __do_request() call the mutex is dropped and re-acquired, so + * the protection is not atomic =E2=80=94 this per-request gate closes + * the remaining window. + */ + if (req->r_attempts > 0) { + mutex_unlock(&mdsc->mutex); + return; + } + if (req->r_err || test_bit(CEPH_MDS_R_GOT_RESULT, &req->r_req_flags)) { if (test_bit(CEPH_MDS_R_ABORTED, &req->r_req_flags)) __unregister_request(mdsc, req); + mutex_unlock(&mdsc->mutex); return; } =20 @@ -3622,6 +3653,7 @@ static void __do_request(struct ceph_mds_client *mdsc, spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &mdsc->waiting_for_map); spin_unlock(&mdsc->wait_list_lock); + mutex_unlock(&mdsc->mutex); return; } if (!(mdsc->fsc->mount_options->flags & @@ -3647,6 +3679,7 @@ static void __do_request(struct ceph_mds_client *mdsc, spin_lock(&mdsc->wait_list_lock); list_add(&req->r_wait, &mdsc->waiting_for_map); spin_unlock(&mdsc->wait_list_lock); + mutex_unlock(&mdsc->mutex); return; } =20 @@ -3720,6 +3753,9 @@ static void __do_request(struct ceph_mds_client *mdsc, goto out_session; } =20 + req->r_attempts++; + mutex_unlock(&mdsc->mutex); + /* send request */ req->r_resend_mds =3D -1; /* forget any previous mds hint */ =20 @@ -3750,6 +3786,7 @@ static void __do_request(struct ceph_mds_client *mdsc, err =3D wait_on_bit(&di->flags, CEPH_DENTRY_ASYNC_CREATE_BIT, TASK_KILLABLE); if (err) { + mutex_lock(&mdsc->mutex); mutex_lock(&req->r_fill_mutex); set_bit(CEPH_MDS_R_ABORTED, &req->r_req_flags); mutex_unlock(&req->r_fill_mutex); @@ -3787,6 +3824,8 @@ static void __do_request(struct ceph_mds_client *mdsc, =20 err =3D __send_request(session, req, false); =20 + mutex_lock(&mdsc->mutex); + out_session: ceph_put_mds_session(session); finish: @@ -3796,12 +3835,10 @@ static void __do_request(struct ceph_mds_client *md= sc, complete_request(mdsc, req); __unregister_request(mdsc, req); } + mutex_unlock(&mdsc->mutex); return; } =20 -/* - * called under mdsc->mutex - */ static void __wake_requests(struct ceph_mds_client *mdsc, struct list_head *head) { @@ -3831,10 +3868,14 @@ static void __wake_requests(struct ceph_mds_client = *mdsc, static void kick_requests(struct ceph_mds_client *mdsc, int mds) { struct ceph_client *cl =3D mdsc->fsc->client; - struct ceph_mds_request *req; + struct ceph_mds_request *req, *nreq; unsigned long idx; + LIST_HEAD(kick_list); =20 doutc(cl, "kick_requests mds%d\n", mds); + + /* collect matching requests under the mutex */ + mutex_lock(&mdsc->mutex); idx =3D 0; xa_for_each(&mdsc->request_tree, idx, req) { if (test_bit(CEPH_MDS_R_GOT_UNSAFE, &req->r_req_flags)) @@ -3843,14 +3884,23 @@ static void kick_requests(struct ceph_mds_client *m= dsc, int mds) continue; /* only new requests */ if (req->r_session && req->r_session->s_mds =3D=3D mds) { - doutc(cl, " kicking tid %llu\n", req->r_tid); + ceph_mdsc_get_request(req); spin_lock(&mdsc->wait_list_lock); list_del_init(&req->r_wait); spin_unlock(&mdsc->wait_list_lock); - trace_ceph_mdsc_resume_request(mdsc, req); - __do_request(mdsc, req); + list_add_tail(&req->r_aux_item, &kick_list); } } + mutex_unlock(&mdsc->mutex); + + /* replay without the mutex */ + list_for_each_entry_safe(req, nreq, &kick_list, r_aux_item) { + doutc(cl, " kicking tid %llu\n", req->r_tid); + trace_ceph_mdsc_resume_request(mdsc, req); + list_del_init(&req->r_aux_item); + __do_request(mdsc, req); + ceph_mdsc_put_request(req); + } } =20 int ceph_mdsc_submit_request(struct ceph_mds_client *mdsc, struct inode *d= ir, @@ -3910,10 +3960,11 @@ int ceph_mdsc_submit_request(struct ceph_mds_client= *mdsc, struct inode *dir, doutc(cl, "submit_request on %p for inode %p\n", req, dir); mutex_lock(&mdsc->mutex); __register_request(mdsc, req, dir); + mutex_unlock(&mdsc->mutex); + trace_ceph_mdsc_submit_request(mdsc, req); __do_request(mdsc, req); err =3D req->r_err; - mutex_unlock(&mdsc->mutex); return err; } =20 @@ -4296,13 +4347,14 @@ static void handle_forward(struct ceph_mds_client *= mdsc, req->r_num_fwd =3D fwd_seq; req->r_resend_mds =3D next_mds; put_request_session(req); - __do_request(mdsc, req); } mutex_unlock(&mdsc->mutex); =20 /* kick calling process */ if (aborted) complete_request(mdsc, req); + else if (!test_bit(CEPH_MDS_R_ABORTED, &req->r_req_flags)) + __do_request(mdsc, req); ceph_mdsc_put_request(req); return; =20 @@ -4626,11 +4678,9 @@ static void handle_session(struct ceph_mds_session *= session, =20 mutex_unlock(&session->s_mutex); if (wake) { - mutex_lock(&mdsc->mutex); __wake_requests(mdsc, &session->s_waiting); if (wake =3D=3D 2) kick_requests(mdsc, mds); - mutex_unlock(&mdsc->mutex); } if (op =3D=3D CEPH_SESSION_CLOSE) ceph_put_mds_session(session); @@ -4687,6 +4737,7 @@ static void replay_unsafe_requests(struct ceph_mds_cl= ient *mdsc, =20 mutex_lock(&mdsc->mutex); list_for_each_entry_safe(req, nreq, &session->s_unsafe, r_unsafe_item) + req->r_attempts++; __send_request(session, req, true); =20 /* @@ -4706,6 +4757,7 @@ static void replay_unsafe_requests(struct ceph_mds_cl= ient *mdsc, =20 ceph_mdsc_release_dir_caps_async(req); =20 + req->r_attempts++; __send_request(session, req, true); } mutex_unlock(&mdsc->mutex); @@ -5265,9 +5317,7 @@ static int send_mds_reconnect(struct ceph_mds_client = *mdsc, =20 mutex_unlock(&session->s_mutex); =20 - mutex_lock(&mdsc->mutex); __wake_requests(mdsc, &session->s_waiting); - mutex_unlock(&mdsc->mutex); =20 up_read(&mdsc->snap_rwsem); ceph_pagelist_release(recon_state.pagelist); @@ -5692,8 +5742,8 @@ static void ceph_mdsc_reset_workfn(struct work_struct= *work) } sessions[i]->s_state =3D CEPH_MDS_SESSION_CLOSED; __unregister_session(mdsc, sessions[i]); - __wake_requests(mdsc, &sessions[i]->s_waiting); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &sessions[i]->s_waiting); =20 mutex_lock(&sessions[i]->s_mutex); cleanup_session_requests(mdsc, sessions[i]); @@ -5704,9 +5754,7 @@ static void ceph_mdsc_reset_workfn(struct work_struct= *work) =20 ceph_put_mds_session(sessions[i]); =20 - mutex_lock(&mdsc->mutex); kick_requests(mdsc, mds); - mutex_unlock(&mdsc->mutex); =20 torn_down++; pr_info_client(cl, "mds%d session reset complete\n", mds); @@ -5822,8 +5870,8 @@ static void check_new_map(struct ceph_mds_client *mds= c, /* force close session for stopped mds */ ceph_get_mds_session(s); __unregister_session(mdsc, s); - __wake_requests(mdsc, &s->s_waiting); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &s->s_waiting); =20 mutex_lock(&s->s_mutex); cleanup_session_requests(mdsc, s); @@ -5832,8 +5880,8 @@ static void check_new_map(struct ceph_mds_client *mds= c, =20 ceph_put_mds_session(s); =20 - mutex_lock(&mdsc->mutex); kick_requests(mdsc, i); + mutex_lock(&mdsc->mutex); continue; } =20 @@ -5877,8 +5925,8 @@ static void check_new_map(struct ceph_mds_client *mds= c, oldstate !=3D CEPH_MDS_STATE_STARTING) pr_info_client(cl, "mds%d recovery completed\n", s->s_mds); - kick_requests(mdsc, i); mutex_unlock(&mdsc->mutex); + kick_requests(mdsc, i); mutex_lock(&s->s_mutex); mutex_lock(&mdsc->mutex); ceph_kick_flushing_caps(mdsc, s); @@ -6786,8 +6834,8 @@ void ceph_mdsc_force_umount(struct ceph_mds_client *m= dsc) =20 if (session->s_state =3D=3D CEPH_MDS_SESSION_REJECTED) __unregister_session(mdsc, session); - __wake_requests(mdsc, &session->s_waiting); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &session->s_waiting); =20 mutex_lock(&session->s_mutex); __close_session(mdsc, session); @@ -6798,11 +6846,11 @@ void ceph_mdsc_force_umount(struct ceph_mds_client = *mdsc) mutex_unlock(&session->s_mutex); ceph_put_mds_session(session); =20 - mutex_lock(&mdsc->mutex); kick_requests(mdsc, mds); + mutex_lock(&mdsc->mutex); } - __wake_requests(mdsc, &mdsc->waiting_for_map); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &mdsc->waiting_for_map); } =20 static void ceph_mdsc_stop(struct ceph_mds_client *mdsc) @@ -6944,8 +6992,8 @@ void ceph_mdsc_handle_fsmap(struct ceph_mds_client *m= dsc, struct ceph_msg *msg) err_out: mutex_lock(&mdsc->mutex); mdsc->mdsmap_err =3D err; - __wake_requests(mdsc, &mdsc->waiting_for_map); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &mdsc->waiting_for_map); } =20 /* @@ -6996,11 +7044,11 @@ void ceph_mdsc_handle_mdsmap(struct ceph_mds_client= *mdsc, struct ceph_msg *msg) mdsc->fsc->max_file_size =3D min((loff_t)mdsc->mdsmap->m_max_file_size, MAX_LFS_FILESIZE); =20 + mutex_unlock(&mdsc->mutex); __wake_requests(mdsc, &mdsc->waiting_for_map); ceph_monc_got_map(&mdsc->fsc->client->monc, CEPH_SUB_MDSMAP, mdsc->mdsmap->m_epoch); =20 - mutex_unlock(&mdsc->mutex); schedule_delayed(mdsc, 0); return; =20 @@ -7098,8 +7146,8 @@ static void mds_peer_reset(struct ceph_connection *co= n) ceph_get_mds_session(s); s->s_state =3D CEPH_MDS_SESSION_CLOSED; __unregister_session(mdsc, s); - __wake_requests(mdsc, &s->s_waiting); mutex_unlock(&mdsc->mutex); + __wake_requests(mdsc, &s->s_waiting); =20 mutex_lock(&s->s_mutex); cleanup_session_requests(mdsc, s); @@ -7108,9 +7156,7 @@ static void mds_peer_reset(struct ceph_connection *co= n) =20 wake_up_all(&mdsc->session_close_wq); =20 - mutex_lock(&mdsc->mutex); kick_requests(mdsc, s->s_mds); - mutex_unlock(&mdsc->mutex); =20 ceph_put_mds_session(s); break; diff --git a/fs/ceph/mds_client.h b/fs/ceph/mds_client.h index 19d2eae9da5b..ee2e11f1c462 100644 --- a/fs/ceph/mds_client.h +++ b/fs/ceph/mds_client.h @@ -427,6 +427,7 @@ struct ceph_mds_request { struct completion r_safe_completion; ceph_mds_request_callback_t r_callback; struct list_head r_unsafe_item; /* per-session unsafe list item */ + struct list_head r_aux_item; /* auxiliary local list item */ =20 long long r_dir_release_cnt; long long r_dir_ordered_cnt; --=20 2.53.0 From nobody Mon Sep 28 19:23:38 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BEABD45FFA8; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; cv=none; b=bcTtyDew7GTlewMeIRsWBr/1Ga1hZUjo1RJUzqOnTK6L0gXjhIA3ZSrDLEoIVzZan4SsGMcdqNH4HicHOgPcGt+xmg7VfY7T+yo53M2QGC/2uTv2xZWHnNwnU3h6KQKebhiL3jT7pQ7DTqfAHSwskwQUkTNqFqb3oMmPYFFUiBA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787050696; c=relaxed/simple; bh=uxrr4D4UTD+yPK/coKgYzAaRfF5/Af5Jj+fyB0NqcNI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=DjMZXBb+nQu+B1oWhqC8IN8rGLxwGMusvdn7udK7TLorsVQojW3i58bndn0A1pAwxffkGurDdjYlKRuYJeNZdrdYR68vEV4iFKyfWdSoR1/aF0ubJt3rDTs6ERlwpzVY1QQn5WpQ2j27Pomc1oiizlTTZvM2fL3aoA1Ngy8DJz8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UUDdDpRm; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UUDdDpRm" Received: by smtp.kernel.org (Postfix) with ESMTPS id 6AA60C2BCFD; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1787050696; bh=uxrr4D4UTD+yPK/coKgYzAaRfF5/Af5Jj+fyB0NqcNI=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=UUDdDpRm6UXiqMRXoaP78Sf+uJ3z0qkPLcqtybomuRd4+bbCSyuRzJCWEXTOqu7KK REOCvEtWxM3KahIqOO/ymYGE+V0PwbO53yk7W6/ceH9UAr8mMrzLQ1zQUhDdLhdubM /lmOOGCndFD8wLrnlu9Kn5C0x2KRuSRQdQWUULTfU4mPvkISDnxfwyrY+qOqu0XRSx 8MHH4NAKdidcHy3niQEgtLT17AOkjZ7JOaQbPAFE4AtWdMpUZNFYcyQ2f2FvyPwb5E mf+mlrGLost/+g8dVkj2IDRrej9NcpHKDdw7PdAfGrFMxDIMKv6PJoNbDMHniVh23p X2Xa2NdwCIlHg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 57F55C5DF7D; Tue, 18 Aug 2026 10:58:16 +0000 (UTC) From: Xiubo Li via B4 Relay Date: Tue, 18 Aug 2026 03:58:12 -0700 Subject: [PATCH v5 5/5] ceph: narrow mdsc->mutex scope in replay_unsafe_requests Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-ceph-mdsc-mutex-optimization-v5-5-7d335a3a1d0b@clyso.com> References: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> In-Reply-To: <20260818-ceph-mdsc-mutex-optimization-v5-0-7d335a3a1d0b@clyso.com> To: Ilya Dryomov , Alex Markuze , Viacheslav Dubeyko Cc: ceph-devel@vger.kernel.org, linux-kernel@vger.kernel.org, Xiubo Li X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787050693; l=3299; i=xiubo.li@clyso.com; s=20260625; h=from:subject:message-id; bh=009BuODFeGOWGowR2RIFqNz08B1zIvCBUcUg2e3fczI=; b=AkP0sUdKpopnSZb06tylp8FhPUG8APSbnzUbaOI6jBqdKO0+qUZUcXXEagY5QcVq2cu/T+Ps4 ff5lUMYPfQ6AQ8wNRjfU3GPlUUsrS+Uau2v10a+OxuPTXOFvuAc/gFM X-Developer-Key: i=xiubo.li@clyso.com; a=ed25519; pk=V3NGr0AgAopiUhaLY51ipBkLN5LlcLhjOEfLEq1RoZ8= X-Endpoint-Received: by B4 Relay for xiubo.li@clyso.com/20260625 with auth_id=840 X-Original-From: Xiubo Li Reply-To: xiubo.li@clyso.com From: Xiubo Li Currently replay_unsafe_requests() holds mdsc->mutex across the entire function, including the __send_request() calls. Since __send_request() is lockless and the async cap-release helper schedules deferred work, neither needs the mutex. Collect the unsafe-list entries and the matching old xarray entries into local lists under mdsc->mutex, taking a reference on each, then replay them outside the mutex. Taking a reference ensures a concurrent reply handler can complete and unregister a request without invalidating the local list or the iterator. Unsafe requests remain on session->s_unsafe; r_aux_item serves only as a walk-list link. This keeps them tracked as unsafe until the MDS replies, so a later reconnect can replay them again and cleanup_session_requests() can still abort them on session teardown. Signed-off-by: Xiubo Li --- fs/ceph/mds_client.c | 42 +++++++++++++++++++++++++++++++++++++----- 1 file changed, 37 insertions(+), 5 deletions(-) diff --git a/fs/ceph/mds_client.c b/fs/ceph/mds_client.c index c624f80aa5fd..5310bb27b353 100644 --- a/fs/ceph/mds_client.c +++ b/fs/ceph/mds_client.c @@ -4732,13 +4732,30 @@ static void replay_unsafe_requests(struct ceph_mds_= client *mdsc, { struct ceph_mds_request *req, *nreq; unsigned long idx; + LIST_HEAD(unsafe_list); + LIST_HEAD(old_list); =20 doutc(mdsc->fsc->client, "mds%d\n", session->s_mds); =20 + /* + * Collect unsafe and old requests under mdsc->mutex, then + * replay them without it: __send_request() is lockless and + * ceph_mdsc_release_dir_caps_async() schedules work. + */ mutex_lock(&mdsc->mutex); - list_for_each_entry_safe(req, nreq, &session->s_unsafe, r_unsafe_item) + list_for_each_entry_safe(req, nreq, &session->s_unsafe, + r_unsafe_item) { + ceph_mdsc_get_request(req); req->r_attempts++; - __send_request(session, req, true); + /* + * Keep the request on s_unsafe: r_aux_item is only a + * walk list. The request must stay tracked as unsafe + * until the MDS replies, so that a later reconnect can + * replay it again and cleanup_session_requests() can + * still abort it on session teardown. + */ + list_add_tail(&req->r_aux_item, &unsafe_list); + } =20 /* * also re-send old requests when MDS enters reconnect stage. So that MDS @@ -4755,12 +4772,27 @@ static void replay_unsafe_requests(struct ceph_mds_= client *mdsc, if (req->r_session->s_mds !=3D session->s_mds) continue; =20 - ceph_mdsc_release_dir_caps_async(req); - + ceph_mdsc_get_request(req); req->r_attempts++; - __send_request(session, req, true); + list_add_tail(&req->r_aux_item, &old_list); } + mutex_unlock(&mdsc->mutex); + + /* replay unsafe requests */ + list_for_each_entry_safe(req, nreq, &unsafe_list, r_aux_item) { + list_del_init(&req->r_aux_item); + __send_request(session, req, true); + ceph_mdsc_put_request(req); + } + + /* replay old requests */ + list_for_each_entry_safe(req, nreq, &old_list, r_aux_item) { + list_del_init(&req->r_aux_item); + ceph_mdsc_release_dir_caps_async(req); + __send_request(session, req, true); + ceph_mdsc_put_request(req); + } } =20 static int send_reconnect_partial(struct ceph_reconnect_state *recon_state) --=20 2.53.0