From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B163F43B4A3 for ; Thu, 27 Aug 2026 09:38:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823539; cv=none; b=I7SaHZap1urtCUmIm/Sl/AT7l+ACpzmC64KoH+x/Z9InD2jpppIEygNuB+q3FctLdNQCl2fYhDlY9CLgxmLFf5lQey66FS7tlAnhMzts796E07f1r1pNaQ2BjcxUH+2csHSqi6vFuktd/KXUNJhyBw/EV7T1td6Dbo1RXNF+yv8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823539; c=relaxed/simple; bh=gZJj56dXZ3m5mpuWg5Y32mLuivOuA0n2jQSSKK4Lf/g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jsg8REcMCORQ56p3TZUISCAq+SmBtqZhpJmaKpdTMx/4LLSmlZ5hA3FUbtVamVQJIX6CK9M7li9g9nHLJMNYSWpV9MqN8YkjfOsWJyu6dh3mZY5tW24Fmr4Z5sNDQlI0otwff3ZPipMoeDlrdVH1yNlqsBOci6E6u93UZb5CrDA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=QdsulrUK; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="QdsulrUK" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823534; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=b4i/vAlF7TVRLwxgQcCoqCNsYOQic8KZ0Txwd6Khtt8=; b=QdsulrUKS0MxYBHkz2OCEf5MTy2gZj93oUd/ipZcPZzzyLoU0e7FR3WmDw6QKTOMWTmMBZ hCnLCo4F8KosguNt9cR9G6zDKErbX04t+h05BDKJ3hilcGnW5Z0FPeBAbhKHelI2qtFRFh nh31CG/zxaqDTU9L9HNZfkqx+VC8eIc= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-99-29C6pAf6M6KyBp40UdNyVQ-1; Thu, 27 Aug 2026 05:38:49 -0400 X-MC-Unique: 29C6pAf6M6KyBp40UdNyVQ-1 X-Mimecast-MFC-AGG-ID: 29C6pAf6M6KyBp40UdNyVQ_1787823526 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1F6D2195423A; Thu, 27 Aug 2026 09:38:46 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3072E423; Thu, 27 Aug 2026 09:38:42 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Karl Mehltretter , stable@vger.kernel.org Subject: [PATCH v3 01/10] netfs: Fix uninitialized return value in netfs_unbuffered_write() Date: Thu, 27 Aug 2026 10:38:16 +0100 Message-ID: <20260827093828.1956211-2-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" From: Karl Mehltretter If preparation of the first subrequest fails, netfs_unbuffered_write() exits its loop before ret is initialized. The empty-iterator check can do the same. For synchronous writes, netfs_unbuffered_write_iter_locked() may then return an unrelated error instead of wreq->error. This is reachable through CIFS if cifs_prepare_write() fails to reopen the file or obtain credits. Initialize ret to 0 so the caller returns wreq->error if no data was written, or the number of bytes already written otherwise. Found with Clang's -Wconditional-uninitialized. Fixes: a0b4c7a49137e ("netfs: Fix unbuffered/DIO writes to dispatch subrequ= ests in strict sequence") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter Signed-off-by: David Howells --- fs/netfs/direct_write.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index c16fbad286a1..b04019097ab8 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -95,7 +95,7 @@ static int netfs_unbuffered_write(struct netfs_io_request= *wreq) { struct netfs_io_subrequest *subreq =3D NULL; struct netfs_io_stream *stream =3D &wreq->io_streams[0]; - int ret; + int ret =3D 0; =20 _enter("%llx", wreq->len); From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 18BA04399E2 for ; Thu, 27 Aug 2026 09:38:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823545; cv=none; b=WJ4JsVHZraSJmT1HCJn4yHoysFdKRmqftlNg7nh6JtOI5xmxPQ3mf6HiUoI1bxq9bKhmUxTiNh1ma8EU37ttocV7o7ktWjT/M1KTnJDTsR/au07n8yDredddud6PeWtOpiiJQ8fIoDYHCQmFcMlnfz4iOaXeGpiFdmT0XQ3WcJU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823545; c=relaxed/simple; bh=txJCVMXbXZvWlCXPrv6gBGpM1BgXhBKNdFGr0ZEG6w0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=M65tu/6Y6EnKaUU+JULycmFzV7HXj/6EwP3zF8LOKkglQR9fUtcPFdr5C1EGzWVxoMU8P7KM7SJtjhZ6DGhItfwif5zWkTg5oPNOFXmrC3tC4iL8zoT4xc9jEgN+xc1ZyKw50tb8iCbVzx9+IMa6ElyqHo66XSGioK3xgn5NlGs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=GNwyJiNr; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="GNwyJiNr" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823535; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0CGY+glbrnxXmLvEdK2C6tXXpmZuhxXjkwnlUGFD0SY=; b=GNwyJiNrvIpFwb/Za0p+OuOowgGvIUaswasoE+XASFAWBd9dLKSwye0liGgHgKrg+rutnP MqcvgZWE14mOpQ994m+dB/KoKDigPVsLU6zMut5tHDy5NUCaguuKpdPxeXjd6GeBEEUAiz dGQcu0WYaWIvUez1LTzFNJuDV8/z004= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-297-XCKAzDz8OzWc03-SyXxUDw-1; Thu, 27 Aug 2026 05:38:51 -0400 X-MC-Unique: XCKAzDz8OzWc03-SyXxUDw-1 X-Mimecast-MFC-AGG-ID: XCKAzDz8OzWc03-SyXxUDw_1787823530 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 399271956046; Thu, 27 Aug 2026 09:38:50 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 742DE434; Thu, 27 Aug 2026 09:38:47 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 02/10] netfs: Fix unbuffered/DIO write partial transfer error return Date: Thu, 27 Aug 2026 10:38:17 +0100 Message-ID: <20260827093828.1956211-3-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" Fix unbuffered/DIO write to return the amount of data transferred in preference to an error if a partial transfer has been achieved, and to prefer an error stashed in the request over the one returned by netfs_unbuffered_write() (likely -EINTR or -ERESTARTSYS). Fixes: a0b4c7a49137e ("netfs: Fix unbuffered/DIO writes to dispatch subrequ= ests in strict sequence") Link: https://sashiko.dev/#/patchset/20260824120224.504575-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/netfs/direct_write.c | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index b04019097ab8..544a4243fc59 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -139,13 +139,11 @@ static int netfs_unbuffered_write(struct netfs_io_req= uest *wreq) if (test_bit(NETFS_SREQ_NEED_RETRY, &subreq->flags)) { retry =3D true; } else if (test_bit(NETFS_SREQ_FAILED, &subreq->flags)) { - ret =3D subreq->error; - wreq->error =3D ret; + wreq->error =3D subreq->error; netfs_see_subrequest(subreq, netfs_sreq_trace_see_failed); subreq =3D NULL; break; } - ret =3D 0; =20 if (!retry) { netfs_unbuffered_write_collect(wreq, stream, subreq); @@ -288,11 +286,11 @@ ssize_t netfs_unbuffered_write_iter_locked(struct kio= cb *iocb, struct iov_iter * ret =3D -EIOCBQUEUED; } else { ret =3D netfs_unbuffered_write(wreq); - if (ret < 0) { - _debug("begin =3D %zd", ret); - } else { + if (wreq->transferred) { iocb->ki_pos +=3D wreq->transferred; - ret =3D wreq->transferred ?: wreq->error; + ret =3D wreq->transferred; + } else if (wreq->error) { + ret =3D wreq->error; } =20 netfs_put_request(wreq, netfs_rreq_trace_put_complete); From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EF9C43BDA4 for ; Thu, 27 Aug 2026 09:39:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823548; cv=none; b=L3J4EHEQZ4Dzw2tU2S6LRhCjclSRUubLEFtXWNFT8PiJhBAuap/FtG+bWZ6ItLz+2kgh29VOa1TZxJb54L+NZYv2ydBnI1wQlCMVKCWy6PA2gswT1mSrO+w/PioI7JeZI+WgZjCFPdPZ2xPNLs0zEyn4nP4V1a7GDpJvnAM232k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823548; c=relaxed/simple; bh=IizGxEfTjfhZJVkwhDscGC2P/a5HlqU4Kr8qrccX6z4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jzrMJomlF48zxYi8b/NM1uGUSAD9o+kyBn+9yt26OL3B8t9tL/0bUCi7sGkYgjbHWkb06ivDBCEdGI+jCD8lEbvkjcWEwICgpsdszFdc6dVSTJIRcYiNwH2TQv0jlioDl+He35azeP+Zd1jrhsk6j/UberVCDxz9ORcZyItKE3Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FbN9O306; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FbN9O306" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823538; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=bPPEzvtBLG/nC8I1Bmob/2jRQbbQ9nOnJ6K+0h7yLO8=; b=FbN9O306ewvEwBN2Hpwpm4z0LLh9k+z6KX02qgwW6xHZYe4bVhr9DECNjA1GirNBAzBzIk YFGxzrmXiQ0zJby9FusEsD18sRgkywpVcK+yHlkKusNjfNLSd+/FYxhwAphyG4LCclOX1j m4Y6aAjjlv4XoWsmC6T7DXHjAUvv2ic= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-277-lZ5oMDmuM-yPijVqlPdCLA-1; Thu, 27 Aug 2026 05:38:55 -0400 X-MC-Unique: lZ5oMDmuM-yPijVqlPdCLA-1 X-Mimecast-MFC-AGG-ID: lZ5oMDmuM-yPijVqlPdCLA_1787823533 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 63FB81954B1C; Thu, 27 Aug 2026 09:38:53 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 42CAB1800346; Thu, 27 Aug 2026 09:38:51 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 03/10] netfs: Fix error vs transferred passed to ->ki_complete() Date: Thu, 27 Aug 2026 10:38:18 +0100 Message-ID: <20260827093828.1956211-4-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Content-Type: text/plain; charset="utf-8" Fix netfs_unbuffered_write_done() to pass the amount written to ->ki_complete() rather than the error in the event of a partially complete transfer. Fixes: a0b4c7a49137e ("netfs: Fix unbuffered/DIO writes to dispatch subrequ= ests in strict sequence") Link: https://sashiko.dev/#/patchset/20260824120224.504575-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/netfs/direct_write.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index 544a4243fc59..f7d7e1b54653 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -51,7 +51,7 @@ static void netfs_unbuffered_write_done(struct netfs_io_r= equest *wreq) wreq->iocb->ki_pos +=3D written; if (wreq->iocb->ki_complete) { trace_netfs_rreq(wreq, netfs_rreq_trace_ki_complete); - wreq->iocb->ki_complete(wreq->iocb, wreq->error ?: written); + wreq->iocb->ki_complete(wreq->iocb, written ?: wreq->error); } wreq->iocb =3D VFS_PTR_POISON; } From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB7F23E49E4 for ; Thu, 27 Aug 2026 09:39:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823552; cv=none; b=sHPr+MhFnD7WCMwMp7Mde7OxX19S0kqqRM2fzzuvBXAr9qk0O9fN9HzzyLxUwRIrQRGEqYoTMy7I9ZV3Vv//B8F8VuIiUOFn+TmuyOlBLvqJmknwMxwYT5ZQlzApqR3rTNoHPhEoHJ7qh+/KqUUdWoCKzuuYe9R3hkjkmBCsuok= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823552; c=relaxed/simple; bh=TbyvXkUkP/iFkWLvIM6Uiy2D1Zai+6kwljmDrYii1Qs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=n6OPvIPfPBeoURoGRfsUxrJ1j7e0c91qQyGRdy5tS8zqFgvs171hlXqoC8NeQWKdhAkWUfrkgAXpdvLLGNC/IbpvyxGdRmpyNwYj4Qusbe4Jyfs5ujQCxwa3iy2CG806dArsoGrFBYv2426zMhZuoQKh7Ghw8+eiJxjFK8cyAbc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=JrBiojEv; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="JrBiojEv" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823543; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=r3vRJq2sMz9APK4rZhV/g2MBBVrXWqzKAsYSWHku/NM=; b=JrBiojEvPiEMtbiXqFInuHFmutm+nSQodRohDTxQUsznH47cYfONZmtUDx9Tp1l81ytPlS MnHLYHfKpGersc/Gg6+DczGRxZ38aaXkDFflfyqtQ5/SQJ8yC68bbTVYsSTKbYNll7GX7x Mcsu2lGmaXLlGXz6pxTUKe/LBM5dPaI= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-682-NSYaUZP2NiqDaqXLYIHHkg-1; Thu, 27 Aug 2026 05:38:59 -0400 X-MC-Unique: NSYaUZP2NiqDaqXLYIHHkg-1 X-Mimecast-MFC-AGG-ID: NSYaUZP2NiqDaqXLYIHHkg_1787823538 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4879718052CA; Thu, 27 Aug 2026 09:38:57 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BB0B71800346; Thu, 27 Aug 2026 09:38:54 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 04/10] netfs: Fix i_size update for partial transfer Date: Thu, 27 Aug 2026 10:38:19 +0100 Message-ID: <20260827093828.1956211-5-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Content-Type: text/plain; charset="utf-8" Fix netfs_unbuffered_write_done() to pass the amount written to netfs_update_i_size() in the event of a partial transfer that ends in an error. That said, it might be better for the filesystem to mark the inode data as invalid and recheck it in case something like a network error occurred that prevented the reply from the server from being received. Fixes: a0b4c7a49137e ("netfs: Fix unbuffered/DIO writes to dispatch subrequ= ests in strict sequence") Link: https://sashiko.dev/#/patchset/20260824120224.504575-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/netfs/direct_write.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index f7d7e1b54653..f33ccddaa826 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -21,7 +21,7 @@ static void netfs_unbuffered_write_done(struct netfs_io_r= equest *wreq) /* Okay, declare that all I/O is complete. */ trace_netfs_rreq(wreq, netfs_rreq_trace_write_done); =20 - if (!wreq->error) + if (wreq->transferred) netfs_update_i_size(ictx, &ictx->inode, wreq->start, wreq->transferred); =20 if (wreq->origin =3D=3D NETFS_DIO_WRITE && From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D59B143B4B3 for ; Thu, 27 Aug 2026 09:39:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823554; cv=none; b=tb8FpEMUe07x0+/XJn9AGQr714Lyiqk4GMD/sgWhhQuFrdftQao1aU3x+5/+37jcGUDCLwgJisWqh3+6Lkl5J08zIfDhZkTt6xQeeH+frRcEu59fKDbsgsvP6y6lh39K2QKlb/7Bu4M3tmRY3JQH74XEUUJytOpTLf12jyhkJkA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823554; c=relaxed/simple; bh=FzRo1GPNzAWelnrKwWW+888gA+zU/UXIf9GDxf2VjrM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Y8aL44wwQDaddMx8Sb1GVhwp4R26KfmioxfVUd9CBfs4ggopDYHXCde6AhYaOiZUcdQ+DuXsHsJLu0FU9c/EBiQUwKNjKT3pzlbK1NHXLlw9u70oBHWZaGu+5ltqV2xFSYk/sJ12TwqiVteGcbiZKN8trQvgEMuMb7RNYRfrpHg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Am6XyuWm; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Am6XyuWm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823547; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=M/Qxd7N6jCXPKHznu5KtiQXyFK2J5SiupV4se6oGxR0=; b=Am6XyuWmyeRSpq60ywISRV596ZnL3oxkKCtLTbjvfnpmI1PbWXPHK8aYAL+CDzGBzx8Jcq 9SP2pOggfdwh+juptxLnyZCIp+s5hjKFH0a7A/ZZn8WLcVLSwBssayz4B6DcI3Wmz9dDkJ +N0r3IDOVxYBojxSjs5O+vwzetQrrQc= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-382-MBf9HBZUO4i_8GBU_K4OYQ-1; Thu, 27 Aug 2026 05:39:03 -0400 X-MC-Unique: MBf9HBZUO4i_8GBU_K4OYQ-1 X-Mimecast-MFC-AGG-ID: MBf9HBZUO4i_8GBU_K4OYQ_1787823541 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DEF66195423E; Thu, 27 Aug 2026 09:39:00 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 590031955F04; Thu, 27 Aug 2026 09:38:58 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 05/10] netfs: Fix subreq ref leak Date: Thu, 27 Aug 2026 10:38:20 +0100 Message-ID: <20260827093828.1956211-6-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Content-Type: text/plain; charset="utf-8" Fix a subrequest ref leak in netfs_unbuffered_write() in the event that subreq->io_iter ends up zero length during preparation. Fixes: a0b4c7a49137e ("netfs: Fix unbuffered/DIO writes to dispatch subrequ= ests in strict sequence") Link: https://sashiko.dev/#/patchset/20260824120224.504575-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/netfs/direct_write.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index f33ccddaa826..fbcfadb232ee 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -121,8 +121,14 @@ static int netfs_unbuffered_write(struct netfs_io_requ= est *wreq) } =20 iov_iter_truncate(&subreq->io_iter, wreq->len - wreq->transferred); - if (!iov_iter_count(&subreq->io_iter)) + if (!iov_iter_count(&subreq->io_iter)) { + pr_warn("netfs: Unexpected zero-length iterator R=3D%08x\n", + wreq->debug_id); + __set_bit(NETFS_SREQ_FAILED, &subreq->flags); + netfs_write_subrequest_terminated(subreq, -EIO); + wreq->error =3D -EIO; break; + } =20 subreq->len =3D netfs_limit_iter(&subreq->io_iter, 0, stream->sreq_max_len, From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AFC0043D4E9 for ; Thu, 27 Aug 2026 09:39:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823560; cv=none; b=qSKh6OfAGnyEEXOyU8N7w4/K+VSmDGfB51RluIzNRZtofFxcdBxecbaduHy86p4ybhjZEbb1xuKNFZucsggF1DiyACuYwx0y4s9SNHzPr+GSIfcgtKrNOBxin9/VYbi06QsbYexOGWmrd6FPgAJ5dMLLu3Y2SGkrM5bkTY/I5V8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823560; c=relaxed/simple; bh=QrdzqNcCR9iFFgQpRU6lHGZ+NgG7PoA+HmJTAzSrA4Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=F5K+YuW2FIgwZALkay093U5bCU/+kcC5SZ73XGxe0VV8Rp19Ya9C0FF/J/jUSagcVNPyEN/ekzGmdoku4WLFYoEQqYk4Fwn/fTkbkB0dzqR30NTAU4IiV12BJhL3/Tn8aYYyDZheT7+JouxeBgstcE5BFW0P6nfTjc/feoH88oc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=BNSeU1x4; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="BNSeU1x4" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823551; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=P2pt6wnBqtVDYBV6sOHnn+X/jyNpYuj5XG1JqmENcwc=; b=BNSeU1x4aAS1DQFdUp2pVrvezZfiNhkuyObfcl1Pb3d/zsJspsl6lZBX5J5bL2LitG+H5l xJ4XkHBdlnYlwJNlT1i/kPOehem9zPkQ37cDfhYAhXVCFElsjJ7C/tKMmWDLBhAQr/q++S RSSwE5iBeFlZRP4QF9cBdFPpPSsSU8A= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-531-xH7X4unkNRGmDx4XinbiRA-1; Thu, 27 Aug 2026 05:39:06 -0400 X-MC-Unique: xH7X4unkNRGmDx4XinbiRA-1 X-Mimecast-MFC-AGG-ID: xH7X4unkNRGmDx4XinbiRA_1787823544 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 687961800C36; Thu, 27 Aug 2026 09:39:04 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0BE97180059E; Thu, 27 Aug 2026 09:39:01 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Edward Adam Davis , syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com Subject: [PATCH v3 06/10] netfs: break unbuffered write when netfs_alloc_subrequest() fails Date: Thu, 27 Aug 2026 10:38:21 +0100 Message-ID: <20260827093828.1956211-7-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Content-Type: text/plain; charset="utf-8" From: Edward Adam Davis syzbot reported a null-ptr-deref below [1] following a fault injection in netfs_alloc_subrequest(). [0] When netfs_alloc_subrequest() fails, subreq is NULL. Later, netfs_prepare_write() tries to initialize members of subreq(e.g., source), the issue in [1] is triggered. Let's handle the error of netfs_prepare_write() properly. [0] FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 0 Call Trace: netfs_alloc_subrequest+0x116/0x3f0 netfs_prepare_write+0x76/0x7b0 netfs_unbuffered_write+0x75c/0x2020 netfs_unbuffered_write_iter_locked+0x7d6/0xa80 netfs_unbuffered_write_iter+0x442/0x720 v9fs_file_write_iter+0xbf/0x100 vfs_write+0x6ac/0x1050 [1] KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af] RIP: 0010:netfs_prepare_write+0xbc/0x7b0 fs/netfs/write_issue.c:173 Call Trace: netfs_unbuffered_write+0x75c/0x2020 fs/netfs/direct_write.c:111 netfs_unbuffered_write_iter_locked+0x7d6/0xa80 fs/netfs/direct_write.c:290 netfs_unbuffered_write_iter+0x442/0x720 fs/netfs/direct_write.c:382 v9fs_file_write_iter+0xbf/0x100 fs/9p/vfs_file.c:409 new_sync_write fs/read_write.c:595 [inline] Fixes: 288ace2f57c9 ("netfs: New writeback implementation") Reported-by: syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D6a13fc77eb6f0802be2d Tested-by: syzbot+6a13fc77eb6f0802be2d@syzkaller.appspotmail.com Signed-off-by: Edward Adam Davis Signed-off-by: David Howells --- fs/netfs/direct_write.c | 5 +++++ fs/netfs/write_issue.c | 2 ++ 2 files changed, 7 insertions(+) diff --git a/fs/netfs/direct_write.c b/fs/netfs/direct_write.c index fbcfadb232ee..2361277416c7 100644 --- a/fs/netfs/direct_write.c +++ b/fs/netfs/direct_write.c @@ -110,6 +110,11 @@ static int netfs_unbuffered_write(struct netfs_io_requ= est *wreq) if (!subreq) { netfs_prepare_write(wreq, stream, wreq->start + wreq->transferred); subreq =3D stream->construct; + if (!subreq) { + wreq->error =3D -ENOMEM; + ret =3D -ENOMEM; + break; + } stream->construct =3D NULL; } =20 diff --git a/fs/netfs/write_issue.c b/fs/netfs/write_issue.c index 2d9cfcd43658..851f6f93ad45 100644 --- a/fs/netfs/write_issue.c +++ b/fs/netfs/write_issue.c @@ -170,6 +170,8 @@ void netfs_prepare_write(struct netfs_io_request *wreq, rolling_buffer_make_space(&wreq->buffer, wreq->gfp); =20 subreq =3D netfs_alloc_subrequest(wreq); + if (!subreq) + return; subreq->source =3D stream->source; subreq->start =3D start; subreq->stream_nr =3D stream->stream_nr; From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 049E543B3E6 for ; Thu, 27 Aug 2026 09:39:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823564; cv=none; b=Tr75kKUflv7/nHhNzISUrdkNIpBpCEK9y3bVB5iVw52DdU2v7Jqg1jjJ3nSX23uk5yjUbmk1kUxNp4Q8Es1GibcBvPztpENZggo7/FGFTP3FBtBOiiDO4Xnse2spUbXUowi3Kq2D4Eh3FbHpXwEDIOCDst3Q+toWpEMQRKD7A6E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823564; c=relaxed/simple; bh=BjURH8bwEAnSf7cBvL6SmtlelGQtfJbu6sYmimC4rdg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GFQj2LqOaMMZzGmZkFv/Em2QTq2aYqEdBmkgu/ke6B6piDGJ4KqXjl3B9ihBnrTTQPZeo9RlNEs7ziz1AphE+ZK76ybn542olht2C+5Wc9o/rHCXQnBtQgmGSEKDy/QFsQyr59vYKCnUJgVMffzK9T+mYAcOcsp/rD9mZGHXb6A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=d10GykNU; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="d10GykNU" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823554; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=r9iZolUQoXRsjj7Xv9NSqZ4No1AkzqqiBCElDUTpjbA=; b=d10GykNUZMG2+zHo4KePQSwbrULy6hrEXFq9v9pO2I6Pcepa9rjHPB+ncQjMssnJ1Nd7Zs s7DeUwzAfI1RjsEvnukJDTtEpgqIgeuCivohWRf2OvGqhmUlrGU0/UiRmCkxNvjKOFBr4U gIHxNe5Qgrd6bheNzDSl4CUoipCp678= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-522-gX0u3OrVOjWmMNSQCnOfxw-1; Thu, 27 Aug 2026 05:39:10 -0400 X-MC-Unique: gX0u3OrVOjWmMNSQCnOfxw-1 X-Mimecast-MFC-AGG-ID: gX0u3OrVOjWmMNSQCnOfxw_1787823548 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 94A9D1835ADB; Thu, 27 Aug 2026 09:39:08 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A81FE1800346; Thu, 27 Aug 2026 09:39:05 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Matthew Wilcox , linux-mm@kvack.org Subject: [PATCH v3 07/10] netfs: Fix readahead synchronisation issues by loading all folios upfront Date: Thu, 27 Aug 2026 10:38:22 +0100 Message-ID: <20260827093828.1956211-8-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Content-Type: text/plain; charset="utf-8" There are some synchronisation issues that derive from the app thread adding more folios to the rolling buffer whilst the collector thread is looking at them or trying to clear them, such as determining the setting of front_folio_order when the next folio hasn't been added yet, The reason for the rolling buffer approach is that loading the buffer upfront and then dropping all the refs just acquired is quite a slow operation, and loading progressively allows some of the cost to be deferred until after at least some of the I/O is started. Instead, a better way is to load all the folios into the rolling buffer upfront - and then drop the refs later, once the I/O is in progress. (Even better would be for the refs not to be there at all.) Fix this by changing the rolling buffer loader to load all the folios selected by the VM for readahead upfront into the folio queue. The folio queue is allocated a batch worth at a time as we don't know how many folios are involved (the readahead_control struct, alas, has a page count, not a folio count). The folio refs acquired from readahead are then dropped in bulk once the first subrequest is dispatched as it's quite a slow operation. The collector waits for NETFS_RREQ_NEED_PUT_RA_REFS to be cleared so that it doesn't unlock folios before the xarray has been scanned for them. This simplifies the buffer handling later and isn't noticeably slower as the xarray doesn't need to be modified and the folios are all already pre-locked. Fixes: ee4cdf7ba857 ("netfs: Speed up buffered reading") Link: https://sashiko.dev/#/patchset/20260824120224.504575-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara (Red Hat) cc: Matthew Wilcox cc: netfs@lists.linux.dev cc: linux-mm@kvack.org cc: linux-fsdevel@vger.kernel.org --- fs/netfs/buffered_read.c | 101 ++++++++++++++++++++------------- fs/netfs/internal.h | 1 + fs/netfs/misc.c | 19 +++++++ fs/netfs/read_collect.c | 7 +++ fs/netfs/read_retry.c | 7 +++ fs/netfs/rolling_buffer.c | 81 ++++++++++++++++---------- include/linux/netfs.h | 1 + include/linux/rolling_buffer.h | 6 +- include/trace/events/netfs.h | 3 + 9 files changed, 154 insertions(+), 72 deletions(-) diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c index 7fdfa4f27e34..303fdce54fba 100644 --- a/fs/netfs/buffered_read.c +++ b/fs/netfs/buffered_read.c @@ -54,6 +54,42 @@ static void netfs_rreq_expand(struct netfs_io_request *r= req, } } =20 +/* + * Drop the folio refs acquired from the readahead API. + */ +static void netfs_bulk_drop_ra_refs(struct netfs_io_request *rreq) +{ + struct folio_batch fbatch; + struct folio *folio; + pgoff_t nr_pages =3D DIV_ROUND_UP(rreq->len, PAGE_SIZE); + pgoff_t first =3D rreq->start / PAGE_SIZE; + XA_STATE(xas, &rreq->mapping->i_pages, first); + + folio_batch_init(&fbatch); + + rcu_read_lock(); + + xas_for_each(&xas, folio, first + nr_pages - 1) { + if (xas_retry(&xas, folio)) + continue; + + if (!folio_batch_add(&fbatch, folio)) + folio_batch_release(&fbatch); + } + + rcu_read_unlock(); + folio_batch_release(&fbatch); + trace_netfs_rreq(rreq, netfs_rreq_trace_ra_put_ref); + clear_bit_unlock(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags); + wake_up(&rreq->waitq); +} + +static void netfs_maybe_bulk_drop_ra_refs(struct netfs_io_request *rreq) +{ + if (test_bit(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags)) + netfs_bulk_drop_ra_refs(rreq); +} + /* * Begin an operation, and fetch the stored zero point value from the cook= ie if * available. @@ -74,12 +110,8 @@ static int netfs_begin_cache_read(struct netfs_io_reque= st *rreq, struct netfs_in * * Returns the limited size if successful and -ENOMEM if insufficient memo= ry * available. - * - * [!] NOTE: This must be run in the same thread as ->issue_read() was cal= led - * in as we access the readahead_control struct. */ -static ssize_t netfs_prepare_read_iterator(struct netfs_io_subrequest *sub= req, - struct readahead_control *ractl) +static ssize_t netfs_prepare_read_iterator(struct netfs_io_subrequest *sub= req) { struct netfs_io_request *rreq =3D subreq->rreq; size_t rsize =3D subreq->len; @@ -87,30 +119,6 @@ static ssize_t netfs_prepare_read_iterator(struct netfs= _io_subrequest *subreq, if (subreq->source =3D=3D NETFS_DOWNLOAD_FROM_SERVER) rsize =3D umin(rsize, rreq->io_streams[0].sreq_max_len); =20 - if (ractl) { - /* If we don't have sufficient folios in the rolling buffer, - * extract a folioq's worth from the readahead region at a time - * into the buffer. Note that this acquires a ref on each page - * that we will need to release later - but we don't want to do - * that until after we've started the I/O. - */ - struct folio_batch put_batch; - - folio_batch_init(&put_batch); - while (rreq->submitted < subreq->start + rsize) { - ssize_t added; - - added =3D rolling_buffer_load_from_ra(&rreq->buffer, ractl, - &put_batch); - if (added < 0) { - folio_batch_release(&put_batch); - return added; - } - rreq->submitted +=3D added; - } - folio_batch_release(&put_batch); - } - subreq->len =3D rsize; if (unlikely(rreq->io_streams[0].sreq_max_segs)) { size_t limit =3D netfs_limit_iter(&rreq->buffer.iter, 0, rsize, @@ -208,8 +216,7 @@ static void netfs_issue_read(struct netfs_io_request *r= req, * slicing up the region to be read according to available cache blocks and * network rsize. */ -static void netfs_read_to_pagecache(struct netfs_io_request *rreq, - struct readahead_control *ractl) +static void netfs_read_to_pagecache(struct netfs_io_request *rreq) { unsigned long long start =3D rreq->start; ssize_t size =3D rreq->len; @@ -288,7 +295,7 @@ static void netfs_read_to_pagecache(struct netfs_io_req= uest *rreq, break; =20 issue: - slice =3D netfs_prepare_read_iterator(subreq, ractl); + slice =3D netfs_prepare_read_iterator(subreq); if (slice < 0) { ret =3D slice; netfs_cancel_read(subreq, ret); @@ -302,6 +309,7 @@ static void netfs_read_to_pagecache(struct netfs_io_req= uest *rreq, } =20 netfs_issue_read(rreq, subreq); + netfs_maybe_bulk_drop_ra_refs(rreq); =20 if (test_bit(NETFS_RREQ_PAUSE, &rreq->flags)) netfs_wait_for_paused_read(rreq); @@ -339,7 +347,8 @@ void netfs_readahead(struct readahead_control *ractl) { struct netfs_io_request *rreq; struct netfs_inode *ictx =3D netfs_inode(ractl->mapping->host); - unsigned long long start =3D readahead_pos(ractl); + ssize_t added; + uoff_t start =3D readahead_pos(ractl); size_t size =3D readahead_length(ractl); int ret; =20 @@ -360,11 +369,23 @@ void netfs_readahead(struct readahead_control *ractl) =20 netfs_rreq_expand(rreq, ractl); =20 - rreq->submitted =3D rreq->start; - if (rolling_buffer_init(&rreq->buffer, rreq->debug_id, ITER_DEST, rreq->g= fp) < 0) + /* Load the folios to be read into a bvecq chain. Note that this + * acquires a ref on each folio that we will need to release later - + * but we don't want to do that until after we've started the I/O. + */ + added =3D rolling_buffer_bulk_load_from_ra(&rreq->buffer, ractl, + rreq->debug_id, rreq->gfp); + if (added < 0) { + ret =3D added; goto cleanup_free; - netfs_read_to_pagecache(rreq, ractl); + } + __set_bit(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags); + + rreq->submitted =3D rreq->start + added; + rreq->cleaned_to =3D rreq->start; =20 + netfs_read_to_pagecache(rreq); + netfs_maybe_bulk_drop_ra_refs(rreq); return netfs_put_request(rreq, netfs_rreq_trace_put_return); =20 cleanup_free: @@ -457,7 +478,7 @@ static int netfs_read_gaps(struct file *file, struct fo= lio *folio) iov_iter_bvec(&rreq->buffer.iter, ITER_DEST, bvec, i, rreq->len); rreq->submitted =3D rreq->start + flen; =20 - netfs_read_to_pagecache(rreq, NULL); + netfs_read_to_pagecache(rreq); =20 ret =3D netfs_wait_for_read(rreq); if (ret >=3D 0) { @@ -532,7 +553,7 @@ int netfs_read_folio(struct file *file, struct folio *f= olio) if (ret < 0) goto discard; =20 - netfs_read_to_pagecache(rreq, NULL); + netfs_read_to_pagecache(rreq); ret =3D netfs_wait_for_read(rreq); netfs_put_request(rreq, netfs_rreq_trace_put_return); return ret < 0 ? ret : 0; @@ -689,7 +710,7 @@ int netfs_write_begin(struct netfs_inode *ctx, if (ret < 0) goto error_put; =20 - netfs_read_to_pagecache(rreq, NULL); + netfs_read_to_pagecache(rreq); ret =3D netfs_wait_for_read(rreq); netfs_put_request(rreq, netfs_rreq_trace_put_return); if (ret < 0) @@ -754,7 +775,7 @@ int netfs_prefetch_for_write(struct file *file, struct = folio *folio, if (ret < 0) goto error_put; =20 - netfs_read_to_pagecache(rreq, NULL); + netfs_read_to_pagecache(rreq); ret =3D netfs_wait_for_read(rreq); netfs_put_request(rreq, netfs_rreq_trace_put_return); return ret < 0 ? ret : 0; diff --git a/fs/netfs/internal.h b/fs/netfs/internal.h index 420ee7b26580..bd8b2d633f96 100644 --- a/fs/netfs/internal.h +++ b/fs/netfs/internal.h @@ -79,6 +79,7 @@ ssize_t netfs_wait_for_read(struct netfs_io_request *rreq= ); ssize_t netfs_wait_for_write(struct netfs_io_request *rreq); void netfs_wait_for_paused_read(struct netfs_io_request *rreq); void netfs_wait_for_paused_write(struct netfs_io_request *rreq); +void netfs_wait_for_put_ra_refs(struct netfs_io_request *rreq); =20 /* * objects.c diff --git a/fs/netfs/misc.c b/fs/netfs/misc.c index 5d554512ed23..f5c1c463f4ff 100644 --- a/fs/netfs/misc.c +++ b/fs/netfs/misc.c @@ -563,3 +563,22 @@ void netfs_wait_for_paused_write(struct netfs_io_reque= st *rreq) { return netfs_wait_for_pause(rreq, netfs_write_collection); } + +/* + * Wait for the readahead-acquired refs to be put. + */ +void netfs_wait_for_put_ra_refs(struct netfs_io_request *rreq) +{ + DEFINE_WAIT(myself); + + for (;;) { + trace_netfs_rreq(rreq, netfs_rreq_trace_wait_put_ra_refs); + prepare_to_wait(&rreq->waitq, &myself, TASK_UNINTERRUPTIBLE); + if (!test_bit(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags)) + break; + schedule(); + } + + trace_netfs_rreq(rreq, netfs_rreq_trace_waited_put_ra_refs); + finish_wait(&rreq->waitq, &myself); +} diff --git a/fs/netfs/read_collect.c b/fs/netfs/read_collect.c index 23660a590124..edf7cea7e2f9 100644 --- a/fs/netfs/read_collect.c +++ b/fs/netfs/read_collect.c @@ -118,6 +118,13 @@ static void netfs_read_unlock_folios(struct netfs_io_r= equest *rreq, slot =3D 0; } =20 + /* We have to wait for readahead refs to have been released before we + * can unlock any folios as the ref-dropper walks i_pages and the only + * thing preventing these folios from being removed is the folio lock. + */ + if (test_bit(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags)) + netfs_wait_for_put_ra_refs(rreq); + for (;;) { struct folio *folio; unsigned long long fpos, fend; diff --git a/fs/netfs/read_retry.c b/fs/netfs/read_retry.c index 2b42758e01ec..dd463a485139 100644 --- a/fs/netfs/read_retry.c +++ b/fs/netfs/read_retry.c @@ -292,6 +292,13 @@ void netfs_unlock_abandoned_read_pages(struct netfs_io= _request *rreq) { struct folio_queue *p; =20 + /* We have to wait for readahead refs to have been released before we + * can unlock any folios as the ref-dropper walks i_pages and the only + * thing preventing these folios from being removed is the folio lock. + */ + if (test_bit(NETFS_RREQ_NEED_PUT_RA_REFS, &rreq->flags)) + netfs_wait_for_put_ra_refs(rreq); + for (p =3D rreq->buffer.tail; p; p =3D p->next) { for (int slot =3D 0; slot < folioq_count(p); slot++) { struct folio *folio =3D folioq_folio(p, slot); diff --git a/fs/netfs/rolling_buffer.c b/fs/netfs/rolling_buffer.c index 8c0026836f9c..424e77a9a109 100644 --- a/fs/netfs/rolling_buffer.c +++ b/fs/netfs/rolling_buffer.c @@ -115,42 +115,65 @@ int rolling_buffer_make_space(struct rolling_buffer *= roll, gfp_t gfp) } =20 /* - * Decant the list of folios to read into a rolling buffer. + * Decant the entire list of folios to read into a rolling buffer. */ -ssize_t rolling_buffer_load_from_ra(struct rolling_buffer *roll, - struct readahead_control *ractl, - struct folio_batch *put_batch) +ssize_t rolling_buffer_bulk_load_from_ra(struct rolling_buffer *roll, + struct readahead_control *ractl, + unsigned int rreq_id, gfp_t gfp) { struct folio_queue *fq; - struct page **vec; - int nr, ix, to; - ssize_t size =3D 0; + ssize_t loaded =3D 0; =20 - if (rolling_buffer_make_space(roll, GFP_KERNEL) < 0) - return -ENOMEM; + while (ractl->_nr_pages - ractl->_batch_count > 0) { + unsigned int nr; =20 - fq =3D roll->head; - vec =3D (struct page **)fq->vec.folios; - nr =3D __readahead_batch(ractl, vec + folio_batch_count(&fq->vec), - folio_batch_space(&fq->vec)); - ix =3D fq->vec.nr; - to =3D ix + nr; - fq->vec.nr =3D to; - for (; ix < to; ix++) { - struct folio *folio =3D folioq_folio(fq, ix); - unsigned int order =3D folio_order(folio); - - fq->orders[ix] =3D order; - size +=3D PAGE_SIZE << order; - trace_netfs_folio(folio, netfs_folio_trace_read); - if (!folio_batch_add(put_batch, folio)) - folio_batch_release(put_batch); + /* Allocate a folioq to put some folios into and attach it to + * the rolling buffer. + */ + fq =3D netfs_folioq_alloc(rreq_id, gfp, + netfs_trace_folioq_make_space); + if (!fq) + goto nomem_unlock; + fq->prev =3D roll->head; + if (!roll->tail) + roll->tail =3D fq; + else + roll->head->next =3D fq; + roll->head =3D fq; + + /* Get a batch of folios and note their orders. */ + nr =3D __readahead_batch(ractl, (struct page **)fq->vec.folios, + folioq_nr_slots(fq)); + if (WARN_ON_ONCE(!nr)) + break; + fq->vec.nr =3D nr; + + for (int slot =3D 0; slot < nr; slot++) { + struct folio *folio =3D folioq_folio(fq, slot); + unsigned int order; + + order =3D folio_order(folio); + fq->orders[slot] =3D order; + loaded +=3D PAGE_SIZE << order; + trace_netfs_folio(folio, netfs_folio_trace_read); + } } - WRITE_ONCE(roll->iter.count, roll->iter.count + size); =20 - /* Store the counter after setting the slot. */ - smp_store_release(&roll->next_head_slot, to); - return size; + WRITE_ONCE(roll->iter.count, loaded); + iov_iter_folio_queue(&roll->iter, ITER_DEST, roll->tail, 0, 0, loaded); + return loaded; + +nomem_unlock: + for (fq =3D roll->tail; fq; fq =3D fq->next) { + for (int slot =3D 0; slot < folioq_count(fq); slot++) { + folio_unlock(fq->vec.folios[slot]); + folioq_mark(fq, slot); + } + } + rolling_buffer_clear(roll); + roll->head =3D NULL; + roll->tail =3D NULL; + return -ENOMEM; } =20 /* diff --git a/include/linux/netfs.h b/include/linux/netfs.h index f837a501008c..5c538d0c5d79 100644 --- a/include/linux/netfs.h +++ b/include/linux/netfs.h @@ -278,6 +278,7 @@ struct netfs_io_request { #define NETFS_RREQ_FOLIO_COPY_TO_CACHE 10 /* Copy current folio to cache f= rom read */ #define NETFS_RREQ_UPLOAD_TO_SERVER 11 /* Need to write to the server */ #define NETFS_RREQ_USE_IO_ITER 12 /* Use ->io_iter rather than ->i_pages = */ +#define NETFS_RREQ_NEED_PUT_RA_REFS 17 /* Need to put the folio refs RA ga= ve us */ #define NETFS_RREQ_USE_PGPRIV2 31 /* [DEPRECATED] Use PG_private_2 to mark * write to cache on read */ const struct netfs_request_ops *netfs_ops; diff --git a/include/linux/rolling_buffer.h b/include/linux/rolling_buffer.h index 9e5dad29669c..a97f7cfaacaa 100644 --- a/include/linux/rolling_buffer.h +++ b/include/linux/rolling_buffer.h @@ -45,9 +45,9 @@ struct rolling_buffer_snapshot { int rolling_buffer_init(struct rolling_buffer *roll, unsigned int rreq_id, unsigned int direction, gfp_t gfp); int rolling_buffer_make_space(struct rolling_buffer *roll, gfp_t gfp); -ssize_t rolling_buffer_load_from_ra(struct rolling_buffer *roll, - struct readahead_control *ractl, - struct folio_batch *put_batch); +ssize_t rolling_buffer_bulk_load_from_ra(struct rolling_buffer *roll, + struct readahead_control *ractl, + unsigned int rreq_id, gfp_t gfp); ssize_t rolling_buffer_append(struct rolling_buffer *roll, struct folio *f= olio, unsigned int flags, gfp_t gfp); struct folio_queue *rolling_buffer_delete_spent(struct rolling_buffer *rol= l); diff --git a/include/trace/events/netfs.h b/include/trace/events/netfs.h index 082cb03c6131..9bda9302be90 100644 --- a/include/trace/events/netfs.h +++ b/include/trace/events/netfs.h @@ -59,6 +59,7 @@ EM(netfs_rreq_trace_free, "FREE ") \ EM(netfs_rreq_trace_intr, "INTR ") \ EM(netfs_rreq_trace_ki_complete, "KI-CMPL") \ + EM(netfs_rreq_trace_ra_put_ref, "RA-PUT ") \ EM(netfs_rreq_trace_recollect, "RECLLCT") \ EM(netfs_rreq_trace_redirty, "REDIRTY") \ EM(netfs_rreq_trace_resubmit, "RESUBMT") \ @@ -70,9 +71,11 @@ EM(netfs_rreq_trace_unpause, "UNPAUSE") \ EM(netfs_rreq_trace_wait_ip, "WAIT-IP") \ EM(netfs_rreq_trace_wait_pause, "--PAUSED--") \ + EM(netfs_rreq_trace_wait_put_ra_refs, "WAIT-P-RA") \ EM(netfs_rreq_trace_wait_quiesce, "WAIT-QUIESCE") \ EM(netfs_rreq_trace_waited_ip, "DONE-IP") \ EM(netfs_rreq_trace_waited_pause, "--UNPAUSED--") \ + EM(netfs_rreq_trace_waited_put_ra_refs, "DONE-P-RA") \ EM(netfs_rreq_trace_waited_quiesce, "DONE-QUIESCE") \ EM(netfs_rreq_trace_wake_ip, "WAKE-IP") \ EM(netfs_rreq_trace_wake_queue, "WAKE-Q ") \ From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6150A43C079 for ; Thu, 27 Aug 2026 09:39:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823569; cv=none; b=U6WNoJu9fta1UmioFf4JT5JNnG9sQ95HN2XNFkcbDMLeWQXktOu9YPgJJ64Z2QI3GZF18J/ryincTHcGvEbic7+jSvdBhE8IpYcYESpTZi0fla9WlmOd3M85KcmuDm/Carirm8+ChRCV+yNlA5HJw1a2acwmOM36EO5Sph9ji2A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823569; c=relaxed/simple; bh=enMiTh7ajQJDRkBDW3/xeNSf2AzA38c8MZQEyZKKMKA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qmVQH4jCVcW0uNJqlstu25Gsf24D+eaMITnOKWkIMjIWZEORu23GAdyG8RAA1+Oz6mtqjN5q2o+Deo96f/zDu3zo9gL+V2KMpUyANCmM7rzWzq38yWpv5iiN6T+mvisD6KLATFJldLTLQNaObOT7rUoybuWqqHD+q5UrMVwPzHI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=XPB6tJdr; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="XPB6tJdr" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823560; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=u3E4rlqJ8DWtsJPMhxO6MmP2nf33NlSqugS9DB0Zuf8=; b=XPB6tJdrwL1pJGZqSpA56mT06YTHObQ/BPvHiRJ977pN8oEAPJlZF/xi7bcYvLy61LaWLh 1RQBgt4V0MjJ3Fx5AYumHNtFR605zHrajgYa5vvB3TGxo7EDkmlNTae9lfHqCCoPqr7QW0 ROH+iYW89mswv18lI3VwWY1En/hdcu4= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-458-BRu3Mo4bN4K9PLAYtjhPdg-1; Thu, 27 Aug 2026 05:39:14 -0400 X-MC-Unique: BRu3Mo4bN4K9PLAYtjhPdg-1 X-Mimecast-MFC-AGG-ID: BRu3Mo4bN4K9PLAYtjhPdg_1787823553 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 97DEE18009C0; Thu, 27 Aug 2026 09:39:12 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D82343000223; Thu, 27 Aug 2026 09:39:09 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org, Matthew Wilcox , linux-mm@kvack.org Subject: [PATCH v3 08/10] netfs: Mark folios with COPY_TO_CACHE whilst issuing subreqs Date: Thu, 27 Aug 2026 10:38:23 +0100 Message-ID: <20260827093828.1956211-9-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" Mark folios with COPY_TO_CACHE whilst issuing subreqs rather than when collecting them. This means that the collector thread doesn't have to try and keep track of which subreqs contribute to which folios - and thus which folios will need to be copied to the cache because at least one byte wasn't in the cache. Instead, this is marked on the folios up front and the collector need only consider the folios. Signed-off-by: David Howells cc: Paulo Alcantara (Red Hat) cc: Matthew Wilcox cc: netfs@lists.linux.dev cc: linux-mm@kvack.org cc: linux-fsdevel@vger.kernel.org --- fs/netfs/buffered_read.c | 62 +++++++++++++++++++++++++++++++++++- fs/netfs/read_collect.c | 40 ++++++++++------------- fs/netfs/read_pgpriv2.c | 13 +++++--- include/linux/netfs.h | 2 +- include/trace/events/netfs.h | 6 ++-- 5 files changed, 90 insertions(+), 33 deletions(-) diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c index 303fdce54fba..20f358209730 100644 --- a/fs/netfs/buffered_read.c +++ b/fs/netfs/buffered_read.c @@ -211,6 +211,55 @@ static void netfs_issue_read(struct netfs_io_request *= rreq, } } =20 +/* + * Mark folios that we want to copy to the cache. For filesystems that use + * netfslib fully, we set folio->private to NETFS_FOLIO_COPY_TO_CACHE; + * otherwise we set the deprecated PG_private_2. + */ +static void netfs_mark_copy_to_cache(struct netfs_io_request *rreq, + struct folio_queue **fq, + unsigned int *offset, + int *slot, + size_t len, + bool copy) +{ + while (len > 0) { + struct folio *folio; + size_t fsize, overlap; + + if (!*fq) + break; + if (*slot >=3D folioq_count(*fq)) { + *fq =3D (*fq)->next; + *slot =3D 0; + *offset =3D 0; + continue; + } + + /* Determine how much the subreq overlaps the folio, if at all. */ + fsize =3D folioq_folio_size(*fq, *slot); + overlap =3D min(len, fsize - *offset); + + if (overlap > 0 && copy) { + folio =3D folioq_folio(*fq, *slot); + if (unlikely(test_bit(NETFS_RREQ_USE_PGPRIV2, &rreq->flags))) { + if (!folio_test_private_2(folio)) + folio_start_private_2(folio); + } else { + if (!folio_get_private(folio)) + folio_attach_private(folio, NETFS_FOLIO_COPY_TO_CACHE); + } + trace_netfs_folio(folio, netfs_folio_trace_mark_copy); + } + + *offset +=3D overlap; + if (*offset >=3D fsize) { + *slot +=3D 1; + *offset =3D 0; + } + } +} + /* * Perform a read to the pagecache from a series of sources of different t= ypes, * slicing up the region to be read according to available cache blocks and @@ -218,9 +267,11 @@ static void netfs_issue_read(struct netfs_io_request *= rreq, */ static void netfs_read_to_pagecache(struct netfs_io_request *rreq) { + struct folio_queue *fq =3D rreq->buffer.tail; unsigned long long start =3D rreq->start; + unsigned int offset; ssize_t size =3D rreq->len; - int ret =3D 0; + int ret =3D 0, slot =3D 0; =20 do { struct netfs_io_subrequest *subreq; @@ -308,6 +359,15 @@ static void netfs_read_to_pagecache(struct netfs_io_re= quest *rreq) set_bit(NETFS_RREQ_ALL_QUEUED, &rreq->flags); } =20 + if (fq) { + /* See if the cache indicated this should be cached. */ + bool copy =3D test_bit(NETFS_SREQ_COPY_TO_CACHE, &subreq->flags); + + if (copy) + set_bit(NETFS_RREQ_WRITE_TO_CACHE, &rreq->flags); + netfs_mark_copy_to_cache(rreq, &fq, &slot, &offset, slice, copy); + } + netfs_issue_read(rreq, subreq); netfs_maybe_bulk_drop_ra_refs(rreq); =20 diff --git a/fs/netfs/read_collect.c b/fs/netfs/read_collect.c index edf7cea7e2f9..4e298b690219 100644 --- a/fs/netfs/read_collect.c +++ b/fs/netfs/read_collect.c @@ -19,7 +19,6 @@ #define MADE_PROGRESS 0x04 /* Made progress cleaning up a stream or the fo= lio set */ #define BUFFERED 0x08 /* The pagecache needs cleaning up */ #define NEED_RETRY 0x10 /* A front op requests retrying */ -#define COPY_TO_CACHE 0x40 /* Need to copy subrequest to cache */ #define ABANDON_SREQ 0x80 /* Need to abandon untransferred part of subrequ= est */ =20 /* @@ -55,30 +54,31 @@ static void netfs_unlock_read_folio(struct netfs_io_req= uest *rreq, folio_mark_uptodate(folio); =20 if (!test_bit(NETFS_RREQ_USE_PGPRIV2, &rreq->flags)) { - finfo =3D netfs_folio_info(folio); - if (finfo) { - trace_netfs_folio(folio, netfs_folio_trace_filled_gaps); - if (finfo->netfs_group) - folio_change_private(folio, finfo->netfs_group); - else - folio_detach_private(folio); - kfree(finfo); - } - - if (test_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &rreq->flags)) { - if (!WARN_ON_ONCE(folio_get_private(folio) !=3D NULL)) { - trace_netfs_folio(folio, netfs_folio_trace_copy_to_cache); - folio_attach_private(folio, NETFS_FOLIO_COPY_TO_CACHE); + if (folio_get_private(folio) =3D=3D NETFS_FOLIO_COPY_TO_CACHE) { + if (test_bit(NETFS_RREQ_WRITE_TO_CACHE, &rreq->flags)) { + trace_netfs_folio(folio, netfs_folio_trace_sched_copy); folio_mark_dirty(folio); + } else { + trace_netfs_folio(folio, netfs_folio_trace_cancel_copy); + folio_detach_private(folio); } } else { + finfo =3D netfs_folio_info(folio); + if (finfo) { + trace_netfs_folio(folio, netfs_folio_trace_filled_gaps); + if (finfo->netfs_group) + folio_change_private(folio, finfo->netfs_group); + else + folio_detach_private(folio); + kfree(finfo); + } trace_netfs_folio(folio, netfs_folio_trace_read_done); } =20 folioq_clear(folioq, slot); } else { // TODO: Use of PG_private_2 is deprecated. - if (test_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &rreq->flags)) + if (test_bit(NETFS_RREQ_WRITE_TO_CACHE, &rreq->flags)) netfs_pgpriv2_copy_to_cache(rreq, folio); } =20 @@ -131,9 +131,6 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, unsigned int order; size_t fsize; =20 - if (*notes & COPY_TO_CACHE) - set_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &rreq->flags); - folio =3D folioq_folio(folioq, slot); if (WARN_ONCE(!folio_test_locked(folio), "R=3D%08x: folio %lx is not locked\n", @@ -156,8 +153,6 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, WRITE_ONCE(rreq->cleaned_to, fpos + fsize); *notes |=3D MADE_PROGRESS; =20 - clear_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &rreq->flags); - /* Clean up the head folioq. If we clear an entire folioq, then * we can get rid of it provided it's not also the tail folioq * being filled by the issuer. @@ -255,9 +250,6 @@ static void netfs_collect_read_results(struct netfs_io_= request *rreq) stream->collected_to =3D front->start + transferred; rreq->collected_to =3D stream->collected_to; =20 - if (test_bit(NETFS_SREQ_COPY_TO_CACHE, &front->flags)) - notes |=3D COPY_TO_CACHE; - if (test_bit(NETFS_SREQ_FAILED, &front->flags)) { rreq->abandon_to =3D front->start + front->len; front->transferred =3D front->len; diff --git a/fs/netfs/read_pgpriv2.c b/fs/netfs/read_pgpriv2.c index c31190993b76..fb57fc45b3fd 100644 --- a/fs/netfs/read_pgpriv2.c +++ b/fs/netfs/read_pgpriv2.c @@ -55,7 +55,7 @@ static void netfs_pgpriv2_copy_folio(struct netfs_io_requ= est *creq, struct folio /* Attach the folio to the rolling buffer. */ if (rolling_buffer_append(&creq->buffer, folio, 0, creq->gfp) < 0) { folio_end_private_2(folio); - clear_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &creq->flags); + clear_bit(NETFS_RREQ_WRITE_TO_CACHE, &creq->flags); return; } =20 @@ -122,7 +122,7 @@ static struct netfs_io_request *netfs_pgpriv2_begin_cop= y_to_cache( netfs_put_failed_request(creq); cancel: rreq->copy_to_cache =3D ERR_PTR(-ENOBUFS); - clear_bit(NETFS_RREQ_FOLIO_COPY_TO_CACHE, &rreq->flags); + clear_bit(NETFS_RREQ_WRITE_TO_CACHE, &rreq->flags); return ERR_PTR(-ENOBUFS); } =20 @@ -136,11 +136,14 @@ void netfs_pgpriv2_copy_to_cache(struct netfs_io_requ= est *rreq, struct folio *fo =20 if (!creq) creq =3D netfs_pgpriv2_begin_copy_to_cache(rreq, folio); - if (IS_ERR(creq)) + if (IS_ERR(creq)) { + clear_bit(NETFS_RREQ_WRITE_TO_CACHE, &rreq->flags); return; + } =20 - trace_netfs_folio(folio, netfs_folio_trace_copy_to_cache); - folio_start_private_2(folio); + trace_netfs_folio(folio, netfs_folio_trace_pgpriv2_copy); + if (WARN_ON_ONCE(!folio_test_private_2(folio))) + return; netfs_pgpriv2_copy_folio(creq, folio); } =20 diff --git a/include/linux/netfs.h b/include/linux/netfs.h index 5c538d0c5d79..49fea3a30611 100644 --- a/include/linux/netfs.h +++ b/include/linux/netfs.h @@ -275,7 +275,7 @@ struct netfs_io_request { #define NETFS_RREQ_SHORT_TRANSFER 5 /* Set if we have a short transfer */ #define NETFS_RREQ_OFFLOAD_COLLECTION 8 /* Offload collection to workqueue= */ #define NETFS_RREQ_NO_UNLOCK_FOLIO 9 /* Don't unlock no_unlock_folio on co= mpletion */ -#define NETFS_RREQ_FOLIO_COPY_TO_CACHE 10 /* Copy current folio to cache f= rom read */ +#define NETFS_RREQ_WRITE_TO_CACHE 10 /* Need to write to the cache */ #define NETFS_RREQ_UPLOAD_TO_SERVER 11 /* Need to write to the server */ #define NETFS_RREQ_USE_IO_ITER 12 /* Use ->io_iter rather than ->i_pages = */ #define NETFS_RREQ_NEED_PUT_RA_REFS 17 /* Need to put the folio refs RA ga= ve us */ diff --git a/include/trace/events/netfs.h b/include/trace/events/netfs.h index 9bda9302be90..a22084813cb5 100644 --- a/include/trace/events/netfs.h +++ b/include/trace/events/netfs.h @@ -198,7 +198,6 @@ EM(netfs_folio_trace_clear_cc, "clear-cc") \ EM(netfs_folio_trace_clear_g, "clear-g") \ EM(netfs_folio_trace_clear_s, "clear-s") \ - EM(netfs_folio_trace_copy_to_cache, "mark-copy") \ EM(netfs_folio_trace_end_copy, "end-copy") \ EM(netfs_folio_trace_filled_gaps, "filled-gaps") \ EM(netfs_folio_trace_invalidate_all, "inval-all") \ @@ -209,16 +208,19 @@ EM(netfs_folio_trace_kill_cc, "kill-cc") \ EM(netfs_folio_trace_kill_g, "kill-g") \ EM(netfs_folio_trace_kill_s, "kill-s") \ + EM(netfs_folio_trace_mark_copy, "mark-copy") \ EM(netfs_folio_trace_mkwrite, "mkwrite") \ EM(netfs_folio_trace_mkwrite_plus, "mkwrite+") \ - EM(netfs_folio_trace_not_under_wback, "!wback") \ EM(netfs_folio_trace_not_locked, "!locked") \ + EM(netfs_folio_trace_not_under_wback, "!wback") \ + EM(netfs_folio_trace_pgpriv2_copy, "pgpriv2-copy") \ EM(netfs_folio_trace_put, "put") \ EM(netfs_folio_trace_read, "read") \ EM(netfs_folio_trace_read_done, "read-done") \ EM(netfs_folio_trace_read_gaps, "read-gaps") \ EM(netfs_folio_trace_read_unlock, "read-unlock") \ EM(netfs_folio_trace_redirtied, "redirtied") \ + EM(netfs_folio_trace_sched_copy, "sched-copy") \ EM(netfs_folio_trace_store, "store") \ EM(netfs_folio_trace_store_copy, "store-copy") \ EM(netfs_folio_trace_store_plus, "store+") \ From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D702743B6EC for ; Thu, 27 Aug 2026 09:39:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823569; cv=none; b=DF+EigKaatGNYLIeX32SeP2MvSU0iUp/R3FI+JYoaQaZp12jjptvI4B4Fdijk4lo5W+jhGeT8wCDhUJzB9FRxDGCzioBT6qQ7aPvTW3RLGZlw37JY1XTR3INvaGxL1LzDTgZgBxNnlL/CZUXcjKRgwDtXfziTPKbHQh8cjCX3nM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823569; c=relaxed/simple; bh=bylhMG/xsSU1DkXbS6+3JW09TUtD1Fx+cKBW3g6t9Dw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HyTBCd3ezTmWwXn7Qmg+7kSfRMdkgeHQp7OapSmvD9nEho9+FLu4+rXgBYf+bJPA9n5xx2aapJjhuchpQ2qPqwyQMdP92Yqz6f6kT0F9P9BdBbJQTLj769L+S9PbZUjhdGcBkQqDgZpuug0/N+WpC2/ghO4W8o1oFol0q38xl0Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=G8ZNO9Fl; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="G8ZNO9Fl" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823559; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VU0W9uWkxCfILwS/Tq6pNCdVsczcmnOSDkZC96gvMGs=; b=G8ZNO9Fl0oczsSXYznbsFAqNOZoL6HhmWW3uRR13gLThctCjXlqbxhorOz0uNCu80tAZOa WhnceGsZHqJ456+q8yqxhKduTI4KfzS3VVFDr6MV157daptx3mKrGSU6vhbXuV58ZOTvjQ QRkMvuqpgAp4FWOsMXo5XFF1uJ3QlY4= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-510-Zy1ds6MwNleJUjpFzBzbPw-1; Thu, 27 Aug 2026 05:39:18 -0400 X-MC-Unique: Zy1ds6MwNleJUjpFzBzbPw-1 X-Mimecast-MFC-AGG-ID: Zy1ds6MwNleJUjpFzBzbPw_1787823556 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3D16D19560B4; Thu, 27 Aug 2026 09:39:16 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D216330001A2; Thu, 27 Aug 2026 09:39:13 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 09/10] netfs: Fix read progress reporting Date: Thu, 27 Aug 2026 10:38:24 +0100 Message-ID: <20260827093828.1956211-10-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" For really big read RPC ops that span multiple folios, netfslib allows the filesystem to give progress notifications to wake up the collector thread to do a collection of folios that have now been fetched, even if the RPC is still ongoing, thereby allowing the application to make progress. This works by taking the current rreq->cleaned_to value (which indicates which folios have been unlocked) and adding the stashed size of the next folio to it. cleaned_to, however, is subject to 64-bit tearing on a 32-bit arch. Fix this by stashing the next progress notification point as a size_t (which won't tear) to be added to rreq->start (which won't change), with the collector thread calculating that from cleaned_to plus the next folio size. Further, however, if the folios are small, the collector thread gets constantly woken up - which has a negative performance impact on the system. Fix that too by setting a minimum trigger of 256KiB or the size of the folio at the front of the queue, whichever is larger. Note that this has an issue that different subreqs have different need-to-be-cached properties; this is solved by a preceding patch that marks the property on the folios whilst issuing subreqs rather than when collecting them. Also, make sure rreq->cleaned_to is initialised up front, along with rreq->collected_to and stream->collected_to. Fixes: e2d46f2ec332 ("netfs: Change the read result collector to only use o= ne work item") Link: https://sashiko.dev/#/patchset/20260804100224.2748935-1-dhowells%40re= dhat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/netfs/buffered_read.c | 2 ++ fs/netfs/internal.h | 1 + fs/netfs/objects.c | 32 +++++++++++++-------- fs/netfs/read_collect.c | 56 +++++++++++++++++++++++++++--------- fs/netfs/read_single.c | 2 ++ include/linux/netfs.h | 2 +- include/trace/events/netfs.h | 21 ++++++++++++++ 7 files changed, 90 insertions(+), 26 deletions(-) diff --git a/fs/netfs/buffered_read.c b/fs/netfs/buffered_read.c index 20f358209730..252dbd9bc4fd 100644 --- a/fs/netfs/buffered_read.c +++ b/fs/netfs/buffered_read.c @@ -443,6 +443,7 @@ void netfs_readahead(struct readahead_control *ractl) =20 rreq->submitted =3D rreq->start + added; rreq->cleaned_to =3D rreq->start; + netfs_read_set_unlock_at(rreq); =20 netfs_read_to_pagecache(rreq); netfs_maybe_bulk_drop_ra_refs(rreq); @@ -468,6 +469,7 @@ static int netfs_create_singular_buffer(struct netfs_io= _request *rreq, struct fo if (added < 0) return added; rreq->submitted =3D rreq->start + added; + rreq->progress_at =3D added; return 0; } =20 diff --git a/fs/netfs/internal.h b/fs/netfs/internal.h index bd8b2d633f96..c734cad7063e 100644 --- a/fs/netfs/internal.h +++ b/fs/netfs/internal.h @@ -110,6 +110,7 @@ static inline void netfs_see_subrequest(struct netfs_io= _subrequest *subreq, /* * read_collect.c */ +void netfs_read_set_unlock_at(struct netfs_io_request *rreq); bool netfs_read_collection(struct netfs_io_request *rreq); void netfs_read_collection_worker(struct work_struct *work); void netfs_cancel_read(struct netfs_io_subrequest *subreq, int error); diff --git a/fs/netfs/objects.c b/fs/netfs/objects.c index 01461a74642d..7f6a3e912602 100644 --- a/fs/netfs/objects.c +++ b/fs/netfs/objects.c @@ -41,24 +41,32 @@ struct netfs_io_request *netfs_alloc_request(struct add= ress_space *mapping, =20 memset(rreq, 0, kmem_cache_size(cache)); INIT_WORK(&rreq->cleanup_work, netfs_free_request); - rreq->gfp =3D gfp; - rreq->start =3D start; - rreq->len =3D len; - rreq->origin =3D origin; - rreq->netfs_ops =3D ctx->ops; - rreq->mapping =3D mapping; - rreq->inode =3D inode; - rreq->i_size =3D i_size_read(inode); - rreq->debug_id =3D atomic_inc_return(&debug_ids); - rreq->wsize =3D INT_MAX; + rreq->gfp =3D gfp; + rreq->start =3D start; + rreq->collected_to =3D start; + rreq->cleaned_to =3D start; + rreq->len =3D len; + rreq->progress_at =3D 0; + rreq->origin =3D origin; + rreq->netfs_ops =3D ctx->ops; + rreq->mapping =3D mapping; + rreq->inode =3D inode; + rreq->i_size =3D i_size_read(inode); + rreq->debug_id =3D atomic_inc_return(&debug_ids); + rreq->wsize =3D INT_MAX; rreq->io_streams[0].sreq_max_len =3D ULONG_MAX; rreq->io_streams[0].sreq_max_segs =3D 0; spin_lock_init(&rreq->lock); - INIT_LIST_HEAD(&rreq->io_streams[0].subrequests); - INIT_LIST_HEAD(&rreq->io_streams[1].subrequests); init_waitqueue_head(&rreq->waitq); refcount_set(&rreq->ref, 2); =20 + for (int s =3D 0; s < NR_IO_STREAMS; s++) { + struct netfs_io_stream *stream =3D &rreq->io_streams[s]; + + INIT_LIST_HEAD(&stream->subrequests); + stream->collected_to =3D rreq->start; + } + if (origin =3D=3D NETFS_READAHEAD || origin =3D=3D NETFS_READPAGE || origin =3D=3D NETFS_READ_GAPS || diff --git a/fs/netfs/read_collect.c b/fs/netfs/read_collect.c index 4e298b690219..75a4aa4b949d 100644 --- a/fs/netfs/read_collect.c +++ b/fs/netfs/read_collect.c @@ -94,6 +94,35 @@ static void netfs_unlock_read_folio(struct netfs_io_requ= est *rreq, folioq_clear(folioq, slot); } =20 +/* + * Determine how much to gather before unlocking more folios. + */ +void netfs_read_set_unlock_at(struct netfs_io_request *rreq) +{ + struct folio_queue *folioq =3D rreq->buffer.tail; + unsigned int slot =3D rreq->buffer.first_tail_slot; + size_t cleaned_to =3D rreq->cleaned_to - rreq->start; + size_t progress_at =3D cleaned_to; + size_t minimum =3D 256 * 1024; + + while (progress_at < rreq->len) { + if (slot >=3D folioq_count(folioq)) { + folioq =3D folioq->next; + if (!folioq) + break; + slot =3D 0; + } + + progress_at +=3D folioq_folio_size(folioq, slot); + if (progress_at - cleaned_to >=3D minimum) + break; + slot++; + } + + WRITE_ONCE(rreq->progress_at, progress_at); + trace_netfs_read_progress_at(rreq); +} + /* * Unlock any folios we've finished with. */ @@ -112,7 +141,7 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, if (slot >=3D folioq_nr_slots(folioq)) { folioq =3D rolling_buffer_delete_spent(&rreq->buffer); if (!folioq) { - rreq->front_folio_order =3D 0; + WRITE_ONCE(rreq->progress_at, ULONG_MAX); return; } slot =3D 0; @@ -127,8 +156,7 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, =20 for (;;) { struct folio *folio; - unsigned long long fpos, fend; - unsigned int order; + unsigned long long fpos =3D rreq->cleaned_to, fend; size_t fsize; =20 folio =3D folioq_folio(folioq, slot); @@ -137,9 +165,7 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, rreq->debug_id, folio->index)) trace_netfs_folio(folio, netfs_folio_trace_not_locked); =20 - order =3D folioq_folio_order(folioq, slot); - rreq->front_folio_order =3D order; - fsize =3D PAGE_SIZE << order; + fsize =3D folioq_folio_size(folioq, slot); fpos =3D folio_pos(folio); fend =3D fpos + fsize; =20 @@ -174,6 +200,8 @@ static void netfs_read_unlock_folios(struct netfs_io_re= quest *rreq, rreq->buffer.tail =3D folioq; done: rreq->buffer.first_tail_slot =3D slot; + + netfs_read_set_unlock_at(rreq); } =20 /* @@ -234,7 +262,7 @@ static void netfs_collect_read_results(struct netfs_io_= request *rreq) * subreqs. */ if (notes & BUFFERED) { - size_t fsize =3D PAGE_SIZE << rreq->front_folio_order; + uoff_t unlock_at =3D rreq->start + rreq->progress_at; =20 /* Clear the tail of a short read. */ if (!(notes & HIT_PENDING) && @@ -256,7 +284,7 @@ static void netfs_collect_read_results(struct netfs_io_= request *rreq) transferred =3D front->len; trace_netfs_rreq(rreq, netfs_rreq_trace_set_abandon); } - if (front->start + transferred >=3D rreq->cleaned_to + fsize || + if (front->start + transferred >=3D unlock_at || test_bit(NETFS_SREQ_HIT_EOF, &front->flags)) netfs_read_unlock_folios(rreq, ¬es); } else { @@ -476,20 +504,22 @@ void netfs_read_collection_worker(struct work_struct = *work) void netfs_read_subreq_progress(struct netfs_io_subrequest *subreq) { struct netfs_io_request *rreq =3D subreq->rreq; - struct netfs_io_stream *stream =3D &rreq->io_streams[0]; - size_t fsize =3D PAGE_SIZE << rreq->front_folio_order; - - trace_netfs_sreq(subreq, netfs_sreq_trace_progress); + struct netfs_io_stream *stream =3D &rreq->io_streams[subreq->stream_nr]; + size_t progress_at =3D READ_ONCE(rreq->progress_at); + uoff_t update_at =3D rreq->start + progress_at; + uoff_t transferred_to =3D subreq->start + subreq->transferred; =20 /* If we are at the head of the queue, wake up the collector, * getting a ref to it if we were the ones to do so. */ - if (subreq->start + subreq->transferred > rreq->cleaned_to + fsize && + if (progress_at !=3D ULONG_MAX && + transferred_to >=3D update_at && (rreq->origin =3D=3D NETFS_READAHEAD || rreq->origin =3D=3D NETFS_READPAGE || rreq->origin =3D=3D NETFS_READ_FOR_WRITE) && list_is_first(&subreq->rreq_link, &stream->subrequests) ) { + trace_netfs_sreq(subreq, netfs_sreq_trace_progress); __set_bit(NETFS_SREQ_MADE_PROGRESS, &subreq->flags); netfs_wake_collector(rreq); } diff --git a/fs/netfs/read_single.c b/fs/netfs/read_single.c index 8833550d2eb6..de67ac41548d 100644 --- a/fs/netfs/read_single.c +++ b/fs/netfs/read_single.c @@ -170,6 +170,8 @@ ssize_t netfs_read_single(struct inode *inode, struct f= ile *file, struct iov_ite if (IS_ERR(rreq)) return PTR_ERR(rreq); =20 + rreq->progress_at =3D rreq->len; + ret =3D netfs_single_begin_cache_read(rreq, ictx); if (ret =3D=3D -ENOMEM || ret =3D=3D -EINTR || ret =3D=3D -ERESTARTSYS) goto cleanup_free; diff --git a/include/linux/netfs.h b/include/linux/netfs.h index 49fea3a30611..307c27721027 100644 --- a/include/linux/netfs.h +++ b/include/linux/netfs.h @@ -246,6 +246,7 @@ struct netfs_io_request { unsigned long long submitted; /* Amount submitted for I/O so far */ unsigned long long len; /* Length of the request */ size_t transferred; /* Amount to be indicated as transferred */ + size_t progress_at; /* Report read progress when hit this much read */ long error; /* 0 or error that occurred */ unsigned long long i_size; /* Size of the file */ unsigned long long start; /* Start position */ @@ -262,7 +263,6 @@ struct netfs_io_request { atomic_t subreq_counter; /* Next subreq->debug_index */ unsigned int nr_group_rel; /* Number of refs to release on ->group */ spinlock_t lock; /* Lock for queuing subreqs */ - unsigned char front_folio_order; /* Order (size) of front folio */ enum netfs_io_origin origin; /* Origin of the request */ bool direct_bv_unpin; /* T if direct_bv[] must be unpinned */ refcount_t ref; diff --git a/include/trace/events/netfs.h b/include/trace/events/netfs.h index a22084813cb5..3fec3e8f91c8 100644 --- a/include/trace/events/netfs.h +++ b/include/trace/events/netfs.h @@ -791,6 +791,27 @@ TRACE_EVENT(netfs_folioq, __print_symbolic(__entry->trace, netfs_folioq_traces)) ); =20 +TRACE_EVENT(netfs_read_progress_at, + TP_PROTO(const struct netfs_io_request *rreq), + + TP_ARGS(rreq), + + TP_STRUCT__entry( + __field(unsigned int, rreq) + __field(size_t, progress_at) + __field(size_t, cleaned_to) + ), + + TP_fast_assign( + __entry->rreq =3D rreq->debug_id; + __entry->cleaned_to =3D rreq->cleaned_to - rreq->start; + __entry->progress_at =3D rreq->progress_at; + ), + + TP_printk("R=3D%08x cln=3D%zx prg=3D%zx", + __entry->rreq, __entry->cleaned_to, __entry->progress_at) + ); + #undef EM #undef E_ #endif /* _TRACE_NETFS_H */ From nobody Mon Sep 28 03:41:44 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D12C3442374 for ; Thu, 27 Aug 2026 09:39:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823574; cv=none; b=rcWNthBaBybXsNWL5K6cxkj1Rmk2zZVXX0BFFNO8Ln9aV3tixLnTCoXIQAkh296r4mN9W4bKtaD9ByFIgmrPiCPyd4OR212qIrc1eJWyTeAa0W/6VhmrOKhytQqSkpFqj7XKAPvNaZuSBUXAkVz8xstlMpvtwPujeuCyTXSFuIw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787823574; c=relaxed/simple; bh=KZ6KryDoeo8J6srSXmaESOaWmDJlcHglaMBB60PNPQY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TDMSa8eEyuRS3mkAmQSSqmyZRfkKCxIcH6cs1r8/byrNQ4PKJMvdZDE9wJyPLV0qDrJ2XvAdyJMUWhj5AtdguQQDJILJ/2OzOJ4epOH+XX2/7Prc9yoMaTozO+kU0/YOSlgdtqI7RWr2oT1a+7eTaQq2JZYqmQpzABORLx0tzdU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=ddNkpHJl; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="ddNkpHJl" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787823567; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XdmER/0ot6k2e8DhxaTBmIQEr/pm9tQfzddtSKAfHwo=; b=ddNkpHJlMRvu6wxj0MERQI+5VMCuDZhiJng3ntSGX9zsKEKeI5ZbJoePCzXC2kpF6sy0Rh z0SAREbnRVc4kDv3cNp5lPjjkiWYKcn8UlfkyMiGFRtH30/lBf7DGdM77zZw9OZoFjLUY7 2Mi8C5gT/zyN4DwfpVU4APWzbQEurFI= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-444-Om0HkeuXMW-zuixSouzTbA-1; Thu, 27 Aug 2026 05:39:22 -0400 X-MC-Unique: Om0HkeuXMW-zuixSouzTbA-1 X-Mimecast-MFC-AGG-ID: Om0HkeuXMW-zuixSouzTbA_1787823559 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 741A11956063; Thu, 27 Aug 2026 09:39:19 +0000 (UTC) Received: from warthog.com (unknown [10.22.88.47]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 75E5130001A2; Thu, 27 Aug 2026 09:39:17 +0000 (UTC) From: David Howells To: Christian Brauner Cc: David Howells , Paulo Alcantara , netfs@lists.linux.dev, linux-afs@lists.infradead.org, linux-cifs@vger.kernel.org, ceph-devel@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v3 10/10] cachefiles: Fix potential UAF/KASAN warning Date: Thu, 27 Aug 2026 10:38:25 +0100 Message-ID: <20260827093828.1956211-11-dhowells@redhat.com> In-Reply-To: <20260827093828.1956211-1-dhowells@redhat.com> References: <20260827093828.1956211-1-dhowells@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" Currently, trace_cachefiles_coherency() is being passed a pointer to a __be64 lain over the coherency data in struct cachefiles_xattr so that it can display the first 8 bytes. However, the data is of variable length and could even be 0 bytes. This could lead to a UAF or KASAN warning. Fix this by making sure the buffer has room for at least 8 bytes and that those 8 bytes are pre-cleared. Further, those bytes are not 8-byte aligned, so fix the tracepoint to extract the data as four 2-byte words (they are 2-byte aligned) and reassemble the __be64. The compiler will convert this into a single 8-byte load where the CPU supports it. Fixes: 229105e5cfd9 ("cachefiles: Add auxiliary data trace") Link: https://sashiko.dev/#/patchset/20260810144746.574036-1-dhowells%40red= hat.com Signed-off-by: David Howells cc: Paulo Alcantara cc: netfs@lists.linux.dev cc: linux-fsdevel@vger.kernel.org --- fs/cachefiles/xattr.c | 16 ++++++++-------- include/trace/events/cachefiles.h | 19 +++++++++++++++++-- 2 files changed, 25 insertions(+), 10 deletions(-) diff --git a/fs/cachefiles/xattr.c b/fs/cachefiles/xattr.c index f8ae78b3f7b6..c70bf67e52b0 100644 --- a/fs/cachefiles/xattr.c +++ b/fs/cachefiles/xattr.c @@ -13,6 +13,7 @@ #include #include #include +#include #include "internal.h" =20 #define CACHEFILES_COOKIE_TYPE_DATA 1 @@ -50,7 +51,7 @@ int cachefiles_set_object_xattr(struct cachefiles_object = *object) =20 _enter("%x,#%d", object->debug_id, len); =20 - buf =3D kmalloc(sizeof(struct cachefiles_xattr) + len, GFP_KERNEL); + buf =3D kmalloc(sizeof(struct cachefiles_xattr) + max(len, sizeof(__be64)= ), GFP_KERNEL); if (!buf) return -ENOMEM; =20 @@ -60,6 +61,7 @@ int cachefiles_set_object_xattr(struct cachefiles_object = *object) buf->content =3D object->content_info; if (test_bit(FSCACHE_COOKIE_LOCAL_WRITE, &object->cookie->flags)) buf->content =3D CACHEFILES_CONTENT_DIRTY; + put_unaligned_be64(0, (__be64 *)buf->data); if (len > 0) memcpy(buf->data, fscache_get_aux(object->cookie), len); =20 @@ -77,8 +79,7 @@ int cachefiles_set_object_xattr(struct cachefiles_object = *object) trace_cachefiles_vfs_error(object, file_inode(file), ret, cachefiles_trace_setxattr_error); trace_cachefiles_coherency(object, file_inode(file)->i_ino, - be64_to_cpup((__be64 *)buf->data), - buf->content, + buf->data, buf->content, cachefiles_coherency_set_fail); if (ret !=3D -ENOMEM) cachefiles_io_error_obj( @@ -86,8 +87,7 @@ int cachefiles_set_object_xattr(struct cachefiles_object = *object) "Failed to set xattr with error %d", ret); } else { trace_cachefiles_coherency(object, file_inode(file)->i_ino, - be64_to_cpup((__be64 *)buf->data), - buf->content, + buf->data, buf->content, cachefiles_coherency_set_ok); } =20 @@ -110,9 +110,10 @@ int cachefiles_check_auxdata(struct cachefiles_object = *object, struct file *file int ret =3D -ESTALE; =20 tlen =3D sizeof(struct cachefiles_xattr) + len; - buf =3D kmalloc(tlen, GFP_KERNEL); + buf =3D kmalloc(sizeof(struct cachefiles_xattr) + max(len, sizeof(__be64)= ), GFP_KERNEL); if (!buf) return -ENOMEM; + put_unaligned_be64(0, (__be64 *)buf->data); =20 xlen =3D cachefiles_inject_read_error(); if (xlen =3D=3D 0) @@ -148,8 +149,7 @@ int cachefiles_check_auxdata(struct cachefiles_object *= object, struct file *file =20 out: trace_cachefiles_coherency(object, file_inode(file)->i_ino, - be64_to_cpup((__be64 *)buf->data), - buf->content, why); + buf->data, buf->content, why); kfree(buf); return ret; } diff --git a/include/trace/events/cachefiles.h b/include/trace/events/cache= files.h index 9259bc71049e..e3101410e8b2 100644 --- a/include/trace/events/cachefiles.h +++ b/include/trace/events/cachefiles.h @@ -372,7 +372,7 @@ TRACE_EVENT(cachefiles_rename, TRACE_EVENT(cachefiles_coherency, TP_PROTO(struct cachefiles_object *obj, ino_t ino, - u64 disk_aux, + const void *disk_aux, enum cachefiles_content content, enum cachefiles_coherency_trace why), =20 @@ -389,12 +389,27 @@ TRACE_EVENT(cachefiles_coherency, ), =20 TP_fast_assign( + union { + __be16 s[4]; + __be64 ll; + } x; + __entry->obj =3D obj->debug_id; __entry->why =3D why; __entry->content =3D content; __entry->ino =3D ino; __entry->aux =3D be64_to_cpup((__be64 *)obj->cookie->inline_aux); - __entry->disk_aux =3D disk_aux; + + /* cachefiles_xattr::data is 2-byte aligned but not 8-byte aligned. = */ + if (disk_aux) { + x.s[0] =3D ((__be16 *)disk_aux)[0]; + x.s[1] =3D ((__be16 *)disk_aux)[1]; + x.s[2] =3D ((__be16 *)disk_aux)[2]; + x.s[3] =3D ((__be16 *)disk_aux)[3]; + __entry->disk_aux =3D be64_to_cpu(x.ll); + } else { + __entry->disk_aux =3D 0; + } ), =20 TP_printk("o=3D%08x %s B=3D%llx c=3D%u aux=3D%llx dsk=3D%llx",