From nobody Mon Sep 28 04:08:03 2026 Received: from mta0.migadu.com (out-168.mta0.migadu.com [91.218.175.168]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 290331DED5C for ; Thu, 27 Aug 2026 00:01:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.168 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788893; cv=none; b=Ihwz0G85zd/B4ZfejWgoDDRDHovnovQy0YDgpXxLT610mmyetYtqUE61LbEBzn6ef5kQBnqWAhuOYCzr6EzzFmb3ozgG9PHv1Zsz3L2ZGiBGYrvVueX8U1hCHMbb5nyRuRd+3Z1/xeI7DIsRAw7Bpygs0pPdOTb8aQDMa1lubZ0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788893; c=relaxed/simple; bh=nb9Tbop7u7Gyn6AIVPCudlCvO4vbRR92MCmqSU5eK6o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EnNf1lSVAaLJZKJ8l7m8XyZdKV2GbTZMqm8Bxa3GQcuWWz+B1ibv5HLfGyr1AjxNP01gFOoovt7mD3rFxPwI617K9iQbrwKnQ5rtZ3wZrsbEj63f+YMfZeIHYbdCdBJy/NEl4DQ9Eemdmbrz6UebfIzlDbZzOXsN9ZX9N4GdXGk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=loXMeo9B; arc=none smtp.client-ip=91.218.175.168 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="loXMeo9B" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=nb9Tbop7u7Gyn6AIVPCudlCvO4vbRR92MCmqSU5eK6o=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787788890; v=1; x=1788393690; b=loXMeo9BstjECdMDaMth5QJn2dnQi8K/mye9n5hyfcL5oM9ZWegT7Pfkh+SKnAINpRb2W202 LbMj3qRUeDGT1u9r7OgbC1HMu/FxlbudV7ySN0bxKEUQhAJOSt6+SN1wpUF6loLCqTlDvnKP1dF 4talIPCWTtPzQcSdBGL2hjmY= X-Envelope-To: linux-kernel@vger.kernel.org Received: from dragon-master.speedport.ip (2003:fc:df23:7abd:c598:7cec:94a0:927b) by smtp.migadu.com with ESMTPS id a6df62b32feb26dc; Thu, 27 Aug 2026 00:01:30 +0000 X-Mizu-Trace-ID: a6df62b32feb26dc X-Migadu-Flow: FLOW_OUT From: Md Haris Iqbal To: Jens Axboe Cc: linux-block@vger.kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Corbet , Md Haris Iqbal , Christoph Hellwig Subject: [RFC for-next 1/3] block: reject unknown status tags in error injection rules Date: Thu, 27 Aug 2026 02:01:13 +0200 Message-ID: <20260827000115.128093-2-haris.iqbal@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260827000115.128093-1-haris.iqbal@linux.dev> References: <20260827000115.128093-1-haris.iqbal@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" An unknown status tag leaves *status at BLK_STS_OK, which error_inject_add() then rejects. Fail in match_status() instead, so that rejecting a bad tag does not rely on BLK_STS_OK being invalid for a rule. For a single status=3D this does not change behaviour: an unknown tag still fails the write with -EINVAL. A repeated status=3D where an invalid tag comes first is now rejected instead of being overridden by the later one. Cc: Christoph Hellwig Signed-off-by: Md Haris Iqbal --- block/error-injection.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/block/error-injection.c b/block/error-injection.c index e14bc4b723ef..47cdd8973adc 100644 --- a/block/error-injection.c +++ b/block/error-injection.c @@ -171,15 +171,18 @@ static int match_op(substring_t *args, enum req_op *o= p) static int match_status(substring_t *args, blk_status_t *status) { const char *tag; + int ret =3D 0; =20 tag =3D match_strdup(args); if (!tag) return -ENOMEM; *status =3D tag_to_blk_status(tag); - if (!*status) + if (!*status) { pr_warn("invalid status '%s'\n", tag); + ret =3D -EINVAL; + } kfree(tag); - return 0; + return ret; } =20 static ssize_t blk_error_injection_parse_options(struct gendisk *disk, --=20 2.53.0 From nobody Mon Sep 28 04:08:03 2026 Received: from mta1.migadu.com (out-165.mta1.migadu.com [95.215.58.165]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 443842AEE1 for ; Thu, 27 Aug 2026 00:01:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.165 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788895; cv=none; b=VMxNmdb5oqXoazVU7DvEvIAqiZ9uUE9fpLelSo/ROqR+KbRfSn7Bh1QEZLhDdJklG0uQVVdwA/cewMb3r7G/bFEAYO5elup2WXzmrn4zfANu5K46HIZUkTup9z3M02cHbsJ0zHcNB4Tw7cn5Q7g8DwsfB/SxssYF16LJKBs3b+Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788895; c=relaxed/simple; bh=TvqWBTb479dLnNj7XyocETAhU2b6NUuFp6SZAzpJMuQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Mmzz4NVCl9xvPgRa1FOso3CRNVyZVBG3mTkrWP2S2f7DDEecSl/oZvnam4MO/DkWCiUNP7z3N/qnaGnF6yUR8vj88Cy+yUAHm/tIpq7mppWzLZhrRklSocrs7XSj8CrQlcJi2fOOSnW1YC192HMcXuMb+VtHkydbcm2ChZWVroI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=nfwScI9x; arc=none smtp.client-ip=95.215.58.165 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="nfwScI9x" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=TvqWBTb479dLnNj7XyocETAhU2b6NUuFp6SZAzpJMuQ=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787788891; v=1; x=1788393691; b=nfwScI9xTcsU9uL+MqNEbZDDK3Mx+1ycMdr9kC2gRPEfVHXHYE3YQhZOZLicEN2LIMnrVyY7 pyrVJLDxy1rozlNb/3cgr8pQdMgMByft9Yj52LIN65kbxPT+BOUgAK1pq19GMOFOz9tTJY6HSxP zLQ/8XPRxXX5WLkgDI/V4Oc0= X-Envelope-To: linux-kernel@vger.kernel.org Received: from dragon-master.speedport.ip (2003:fc:df23:7abd:c598:7cec:94a0:927b) by smtp.migadu.com with ESMTPS id 98be105a5da1ca64; Thu, 27 Aug 2026 00:01:31 +0000 X-Mizu-Trace-ID: 98be105a5da1ca64 X-Migadu-Flow: FLOW_OUT From: Md Haris Iqbal To: Jens Axboe Cc: linux-block@vger.kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Corbet , Md Haris Iqbal , Christoph Hellwig Subject: [RFC for-next 2/3] block: allow error injection rules to delay bios Date: Thu, 27 Aug 2026 02:01:14 +0200 Message-ID: <20260827000115.128093-3-haris.iqbal@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260827000115.128093-1-haris.iqbal@linux.dev> References: <20260827000115.128093-1-haris.iqbal@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Error injection can only fail a bio today. Add a delay_us option so that a rule can hold a bio back first, to model a slow device. If a matching rule has delay_us set, the bio is held for that long. It is then failed if the rule also has a status, or resubmitted below the injection hook so that the rules are not applied to it again. The bio is submitted from a workqueue rather than from the timer, because submitting a bio can sleep. Bios with REQ_NOWAIT are never delayed, and values above 600 seconds are rejected. Cc: Christoph Hellwig Signed-off-by: Md Haris Iqbal --- block/blk-core.c | 13 ++-- block/blk.h | 1 + block/error-injection.c | 147 ++++++++++++++++++++++++++++++++++++---- 3 files changed, 142 insertions(+), 19 deletions(-) diff --git a/block/blk-core.c b/block/blk-core.c index 196bccf27f58..f28ccc4633d4 100644 --- a/block/blk-core.c +++ b/block/blk-core.c @@ -759,11 +759,8 @@ static void __submit_bio_noacct_mq(struct bio *bio) current->bio_list =3D NULL; } =20 -void submit_bio_noacct_nocheck(struct bio *bio, bool split) +void __submit_bio_noacct_nocheck(struct bio *bio, bool split) { - if (unlikely(blk_error_inject(bio))) - return; - blk_cgroup_bio_start(bio); =20 if (!bio_flagged(bio, BIO_TRACE_COMPLETION)) { @@ -793,6 +790,14 @@ void submit_bio_noacct_nocheck(struct bio *bio, bool s= plit) } } =20 +void submit_bio_noacct_nocheck(struct bio *bio, bool split) +{ + if (unlikely(blk_error_inject(bio))) + return; + + __submit_bio_noacct_nocheck(bio, split); +} + static blk_status_t blk_validate_atomic_write_op_size(struct request_queue= *q, struct bio *bio) { diff --git a/block/blk.h b/block/blk.h index 50abfd932886..cdf6d8964da6 100644 --- a/block/blk.h +++ b/block/blk.h @@ -61,6 +61,7 @@ bool __blk_freeze_queue_start(struct request_queue *q, struct task_struct *owner); int __bio_queue_enter(struct request_queue *q, struct bio *bio); void submit_bio_noacct_nocheck(struct bio *bio, bool split); +void __submit_bio_noacct_nocheck(struct bio *bio, bool split); int bio_submit_or_kill(struct bio *bio, unsigned int flags); =20 static inline bool blk_try_enter_queue(struct request_queue *q, bool pm) diff --git a/block/error-injection.c b/block/error-injection.c index 47cdd8973adc..9b823edf3f8a 100644 --- a/block/error-injection.c +++ b/block/error-injection.c @@ -6,9 +6,17 @@ #include #include #include +#include #include "blk.h" #include "error-injection.h" =20 +/* + * Cap the delay so that a typo can't wedge a device for good. This is st= ill + * well beyond the default hung task timeout, which is one of the things a + * delay is useful for triggering. + */ +#define BLK_ERROR_INJECT_MAX_DELAY_US (600 * USEC_PER_SEC) + struct blk_error_inject { struct list_head entry; sector_t start; @@ -18,14 +26,91 @@ struct blk_error_inject { =20 /* only inject every 1 / chance times */ unsigned int chance; + + /* hold the bio for this long before submitting or failing it */ + unsigned int delay_us; }; =20 +/* + * A bio held by a delay rule. This is self-contained on purpose: it does= not + * point back at the rule, so rules can be removed while delayed bios are + * outstanding, and it does not point at the gendisk, so nothing has to be + * cleaned up when the disk goes away. A delayed bio holds no queue usage + * counter reference either, so one that outlives its disk is failed by the + * GD_DEAD check in __bio_queue_enter() once it is finally submitted. + */ +struct blk_error_inject_delay { + struct delayed_work dwork; + struct bio *bio; + blk_status_t status; +}; + +static struct workqueue_struct *blk_error_inject_wq; + DEFINE_STATIC_KEY_FALSE(blk_error_injection_enabled); =20 +static void blk_error_inject_delay_work(struct work_struct *work) +{ + struct blk_error_inject_delay *d =3D container_of(to_delayed_work(work), + struct blk_error_inject_delay, dwork); + struct bio *bio =3D d->bio; + blk_status_t status =3D d->status; + + kfree(d); + + if (status !=3D BLK_STS_OK) { + bio->bi_status =3D status; + bio_endio(bio); + } else { + /* + * Submit below the injection hook. Re-entering it would match + * the same rule again and the bio would never be issued, so a + * bio that was delayed once skips error injection entirely + * from here on, including any other rule that covers it. + */ + __submit_bio_noacct_nocheck(bio, false); + } +} + +/* + * Hand the bio to a workqueue that submits or fails it once the delay has + * expired. Both blk_mq_submit_bio() and ->submit_bio can sleep, so this = can't + * be completed from the timer itself. + * + * Returns false if the bio can't be delayed, in which case the caller han= dles + * it immediately instead. + */ +static bool blk_error_inject_delay(struct gendisk *disk, struct bio *bio, + blk_status_t status, unsigned int delay_us) +{ + struct blk_error_inject_delay *d; + + /* never block a bio that asked not to be blocked */ + if (bio->bi_opf & REQ_NOWAIT) + return false; + + d =3D kmalloc_obj(*d, GFP_NOIO); + if (!d) + return false; + + pr_info_ratelimited("%pg: delaying %s at sector %llu:%u by %uus\n", + disk->part0, blk_op_str(bio_op(bio)), + bio->bi_iter.bi_sector, bio_sectors(bio), delay_us); + + d->bio =3D bio; + d->status =3D status; + INIT_DELAYED_WORK(&d->dwork, blk_error_inject_delay_work); + queue_delayed_work(blk_error_inject_wq, &d->dwork, + usecs_to_jiffies(delay_us)); + return true; +} + bool __blk_error_inject(struct bio *bio) { struct gendisk *disk =3D bio->bi_bdev->bd_disk; struct blk_error_inject *inj; + blk_status_t status =3D BLK_STS_OK; + unsigned int delay_us =3D 0; =20 rcu_read_lock(); list_for_each_entry_rcu(inj, &disk->error_injection_list, entry) { @@ -45,29 +130,38 @@ bool __blk_error_inject(struct bio *bio) if (inj->chance > 1 && (get_random_u32() % inj->chance) !=3D 0) continue; =20 - pr_info_ratelimited("%pg: injecting %s error for %s at sector %llu:%u\n", - disk->part0, blk_status_to_str(inj->status), - blk_op_str(inj->op), bio->bi_iter.bi_sector, - bio_sectors(bio)); - bio->bi_status =3D inj->status; - rcu_read_unlock(); - bio_endio(bio); - return true; + status =3D inj->status; + delay_us =3D inj->delay_us; + break; } rcu_read_unlock(); - return false; + + if (delay_us && blk_error_inject_delay(disk, bio, status, delay_us)) + return true; + if (status =3D=3D BLK_STS_OK) + return false; + + pr_info_ratelimited("%pg: injecting %s error for %s at sector %llu:%u\n", + disk->part0, blk_status_to_str(status), + blk_op_str(bio_op(bio)), bio->bi_iter.bi_sector, + bio_sectors(bio)); + bio->bi_status =3D status; + bio_endio(bio); + return true; } =20 static int error_inject_add(struct gendisk *disk, enum req_op op, sector_t start, u64 nr_sectors, blk_status_t status, - unsigned int chance) + unsigned int chance, unsigned int delay_us) { struct blk_error_inject *inj; int error =3D -EINVAL; =20 if (op =3D=3D REQ_OP_LAST) return -EINVAL; - if (status =3D=3D BLK_STS_OK) + if (status =3D=3D BLK_STS_OK && !delay_us) + return -EINVAL; + if (delay_us > BLK_ERROR_INJECT_MAX_DELAY_US) return -EINVAL; =20 inj =3D kzalloc_obj(*inj); @@ -86,6 +180,7 @@ static int error_inject_add(struct gendisk *disk, enum r= eq_op op, inj->start =3D start; inj->status =3D status; inj->chance =3D chance; + inj->delay_us =3D delay_us; =20 pr_debug_ratelimited("%pg: adding %s injection for %s at sector %llu:%llu= \n", disk->part0, blk_status_to_str(status), @@ -139,6 +234,7 @@ enum options { Opt_nr_sectors =3D (1u << 18), Opt_status =3D (1u << 19), Opt_chance =3D (1u << 20), + Opt_delay_us =3D (1u << 21), =20 Opt_invalid, }; @@ -151,6 +247,7 @@ static const match_table_t opt_tokens =3D { { Opt_nr_sectors, "nr_sectors=3D%u" }, { Opt_status, "status=3D%s" }, { Opt_chance, "chance=3D%u" }, + { Opt_delay_us, "delay_us=3D%u" }, { Opt_invalid, NULL, }, }; =20 @@ -189,7 +286,7 @@ static ssize_t blk_error_injection_parse_options(struct= gendisk *disk, char *options) { enum { Unset, Add, Removeall } action =3D Unset; - unsigned int option_mask =3D 0, chance =3D 1; + unsigned int option_mask =3D 0, chance =3D 1, delay_us =3D 0; enum req_op op =3D REQ_OP_LAST; u64 start =3D 0, nr_sectors =3D 0; blk_status_t status =3D BLK_STS_OK; @@ -232,6 +329,9 @@ static ssize_t blk_error_injection_parse_options(struct= gendisk *disk, if (!error && chance =3D=3D 0) error =3D -EINVAL; break; + case Opt_delay_us: + error =3D match_uint(args, &delay_us); + break; default: pr_warn("unknown parameter or missing value '%s'\n", p); error =3D -EINVAL; @@ -243,7 +343,7 @@ static ssize_t blk_error_injection_parse_options(struct= gendisk *disk, switch (action) { case Add: return error_inject_add(disk, op, start, nr_sectors, status, - chance); + chance, delay_us); case Removeall: if (option_mask & ~Opt_removeall) return -EINVAL; @@ -279,10 +379,11 @@ static int blk_error_injection_show(struct seq_file *= s, void *private) =20 rcu_read_lock(); list_for_each_entry_rcu(inj, &disk->error_injection_list, entry) { - seq_printf(s, "%llu:%llu op=3D%s,status=3D%s,chance=3D%u", + seq_printf(s, "%llu:%llu op=3D%s,status=3D%s,chance=3D%u,delay_us=3D%u", inj->start, inj->end, blk_op_str(inj->op), - blk_status_to_tag(inj->status), inj->chance); + blk_status_to_tag(inj->status), inj->chance, + inj->delay_us); seq_putc(s, '\n'); } rcu_read_unlock(); @@ -317,3 +418,19 @@ void blk_error_injection_exit(struct gendisk *disk) { error_inject_removeall(disk); } + +static int __init blk_error_injection_init_wq(void) +{ + /* + * WQ_MEM_RECLAIM so that a delayed bio on the reclaim path can still + * find a worker under memory pressure. Note that this only guarantees + * a worker exists, not that it is free: submitting a bio can block on + * a queue freeze or on tag allocation, so a delayed bio can still be + * held up behind another one. + */ + blk_error_inject_wq =3D alloc_workqueue("blk_error_inject", WQ_MEM_RECLAI= M | WQ_UNBOUND, 0); + if (!blk_error_inject_wq) + panic("Failed to create blk_error_inject wq\n"); + return 0; +} +subsys_initcall(blk_error_injection_init_wq); --=20 2.53.0 From nobody Mon Sep 28 04:08:03 2026 Received: from mta1.migadu.com (out-168.mta1.migadu.com [95.215.58.168]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3AF2925CC74 for ; Thu, 27 Aug 2026 00:01:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.168 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788896; cv=none; b=glF5CcKu4lG2qH6GjkVczb2WRG50NWyQTaMonVsty9nKn9qxK2uoK7jnV+mRPLdxFKlk29gfwVG8jqIyQmEO0nIl3d+UrVh5RSaoYTMSbUlCIWnq2lOl41GYCPiuK7+uY9RAM6Mpju07pcOPn9pZO2ONLcb4ajjKzs+p+MbiuqA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787788896; c=relaxed/simple; bh=pG+zyDcr41wPY5rZsh7Dk2WwsFc7q1ojUQ0WexYU4FI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gQRy/SS+daH36mzNF49ZslBioZsc7qfV+OkRVIWXfCUyu8kvGTgAyXg9aJ1tfBOaI2znhbtuFgjJ2MYSSFVP/Duye02RgctDrmRgRswHlJQywWhLmsGKtTkH2AIhP39h022UFwvG03IcB8cHT35QWtH45uyiinuKxNXeMzFSP5w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=OnrMH8UT; arc=none smtp.client-ip=95.215.58.168 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="OnrMH8UT" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=pG+zyDcr41wPY5rZsh7Dk2WwsFc7q1ojUQ0WexYU4FI=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1787788892; v=1; x=1788393692; b=OnrMH8UTvZ3WmdgAwHDvgF8PqoHHp5t1ozf8FXWTKiOmyTdKTQHB/LujXxdoxp0fO87KNz91 bbQzpZ4vAS0xH68ZejMQ6NTiRvK79N/nM0j54e7D4NJUjXq/r/9+8gILDWfsyjmx8stm8KG5RW+ X5kkFJ+d8z9Mr9/DcdMaGjaA= X-Envelope-To: linux-kernel@vger.kernel.org Received: from dragon-master.speedport.ip (2003:fc:df23:7abd:c598:7cec:94a0:927b) by smtp.migadu.com with ESMTPS id 2c6467ffe6f12a37; Thu, 27 Aug 2026 00:01:32 +0000 X-Mizu-Trace-ID: 2c6467ffe6f12a37 X-Migadu-Flow: FLOW_OUT From: Md Haris Iqbal To: Jens Axboe Cc: linux-block@vger.kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, Jonathan Corbet , Md Haris Iqbal , Christoph Hellwig Subject: [RFC for-next 3/3] Documentation: block: document error injection delays Date: Thu, 27 Aug 2026 02:01:15 +0200 Message-ID: <20260827000115.128093-4-haris.iqbal@linux.dev> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260827000115.128093-1-haris.iqbal@linux.dev> References: <20260827000115.128093-1-haris.iqbal@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Document the delay_us option: the delay happens above the driver, a delayed bio is not run through the rules again, and holding a bio back reorders it against bios submitted later. Cc: Christoph Hellwig Signed-off-by: Md Haris Iqbal --- Documentation/block/error-injection.rst | 56 ++++++++++++++++++++++++- 1 file changed, 54 insertions(+), 2 deletions(-) diff --git a/Documentation/block/error-injection.rst b/Documentation/block/= error-injection.rst index 81f31af82e65..54490c23cde7 100644 --- a/Documentation/block/error-injection.rst +++ b/Documentation/block/error-injection.rst @@ -9,7 +9,8 @@ Overview =20 Configurable error injection allows injecting specific block layer status = codes for sector ranges of a block device. Errors can be injected unconditional= ly, or -with a given probability. +with a given probability. Instead of, or before, failing a bio it can als= o be +held back for a while to model a slow device. =20 To use configurable error injection, CONFIG_BLK_ERROR_INJECTION must be en= abled. =20 @@ -34,15 +35,58 @@ op=3D block layer operation this rule applies = to. This uses the XYZ for each REQ_OP_XYZ operation, e.g. READ, WRITE or DISCARD. Mandatory. status=3D Status to return. This uses XYZ for each BLK_STS_XYZ - code, e.g. IOERR or MEDIUM. Mandatory. + code, e.g. IOERR or MEDIUM. Mandatory unless delay_us + is given. start=3D First block layer sector the rule applies to. Optional, defaults to 0. nr_sectors=3D Number of sectors this rule applies. Optional, defaults to the remainder of the device. chance=3D Only return a failure with a likelihood of 1/chance. Optional, defaults to 1 (always). +delay_us=3D Hold the bio back for this many microseconds. Without + status the bio is then submitted to the device as + usual, with status it is failed once the delay has + expired. Optional, defaults to 0 (no delay). + Values above 600 seconds are rejected. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =20 +Delays +------ + +A delayed bio is held before it is submitted, so the device itself never s= ees a +slow I/O: the delay is not visible to the driver, to the I/O statistics, o= r to +anything else below submission such as writeback throttling. Throttling by +blk-throttle happens before a bio can be delayed, so it is not affected ei= ther. +What it does exercise is everything waiting above the block layer, for ins= tance +io_uring cancellation, hung task detection, and filesystem or userspace +timeouts. Because the low level driver is not involved, a delay does not = reach +the blk-mq timeout handler or SCSI error handling. + +Once its delay expires a bio is submitted below the injection hook, so no = rule +is evaluated for it a second time. A bio that matched a delay rule theref= ore +never gets an error from another rule, even one covering the same sectors.= Put +the delay and the status in a single rule to fail a bio after holding it b= ack. + +A delayed bio is issued after bios submitted while it was held, which reor= ders +the I/O stream. On zoned devices this breaks sequential write ordering: z= one +write plugging happens below the injection hook, so the writes issued whil= e a +write is held reach the zone out of order and are failed as misaligned. O= nly +delay reads there. For the same reason, delaying one half of a split bio +issues it out of order with the other half. + +Bios that must not block are never delayed. A bio with REQ_NOWAIT set is +submitted, or failed with the rule's status, immediately. + +The delay is a lower bound for anything longer than a timer tick, and the = timer +wheel adds further slack as the delay grows. Values shorter than a tick a= re of +little use: they expire on the next tick, which is anywhere between now an= d one +tick away. + +Removing rules does not release bios that are already being delayed by the= m; +those run out on their own. A delayed bio whose disk is removed in the me= antime +is not submitted until its delay expires, by which point the queue no long= er +accepts I/O, so it fails with EIO. + Example ------- =20 @@ -54,6 +98,14 @@ Return BLK_STS_MEDIUM for every write to /dev/nvme0n1: =20 $ echo 'add,op=3DWRITE,start=3D0,status=3DMEDIUM' > /sys/kernel/debug/blo= ck/nvme0n1/error_injection =20 +Delay every read of /dev/nvme0n1 by 10 milliseconds, then issue it normall= y: + + $ echo 'add,op=3DREAD,delay_us=3D10000' > /sys/kernel/debug/block/nvme0n1= /error_injection + +Fail one in 100 writes with BLK_STS_TIMEOUT, but only after 30 seconds: + + $ echo 'add,op=3DWRITE,status=3DTIMEOUT,chance=3D100,delay_us=3D30000000'= > /sys/kernel/debug/block/nvme0n1/error_injection + Remove all rules for /dev/nvme0n1: =20 $ echo 'removeall' > /sys/kernel/debug/block/nvme0n1/error_injection --=20 2.53.0