cbt: selfdeadlock in __blk_cbt_set()

Submitted by Vasily Averin on Oct. 11, 2018, 1:34 p.m.

Details

Message ID 79d4fc76-02d2-9d0f-93f7-d707903811fa@virtuozzo.com
State New
Series "cbt: selfdeadlock in __blk_cbt_set()"
Headers show

Commit Message

Vasily Averin Oct. 11, 2018, 1:34 p.m.
__blk_cbt_set() can be interrupted by IPI __cbt_flush_cpu_cache() 
that will be cycled forever in spin_lock_page()
because page was already locked by interrupted process.

 #5 [ffff880071e89f50] nmi at ffffffff81569781
    [exception RIP: __blk_cbt_set+133]
    RIP: ffffffff812b1a35  RSP: ffff880071e83ef8  RFLAGS: 00000087
    RAX: 0000000000000001  RBX: 00000000004a0020  RCX: 00000000ffffffff
    RDX: 0000000000000020  RSI: 00000000004a0020  RDI: ffffea007d13d9c0
    RBP: ffff880071e83f38   R8: 0000000000fa0001   R9: 00000000ffffffff
    R10: 0000000000000008  R11: 0000000000000044  R12: ffff880f0b08cbc0
    R13: 0000000000000001  R14: 0000000000000001  R15: 0000000000000094
    ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018
--- <NMI exception stack> ---
 #6 [ffff880071e83ef8] __blk_cbt_set at ffffffff812b1a35
 #7 [ffff880071e83f40] __cbt_flush_cpu_cache at ffffffff812b1c92
 #8 [ffff880071e83f60] generic_smp_call_function_interrupt at ffffffff810dab72
 #9 [ffff880071e83fa0] smp_call_function_interrupt at ffffffff8103950d
#10 [ffff880071e83fb0] call_function_interrupt at ffffffff81571423
--- <IRQ stack> ---
#11 [ffff88101045f678] call_function_interrupt at ffffffff81571423
    [exception RIP: __blk_cbt_set+297]
    RIP: ffffffff812b1ad9  RSP: ffff88101045f720  RFLAGS: 00000202
    RAX: 0000000000000002  RBX: ffff88101045f760  RCX: ffff881f44f67000
    RDX: 000000000000001f  RSI: 0000000000000021  RDI: ffffea007d13d9c0
    RBP: ffffffff8157141e   R8: 0000000000fa0001   R9: 00000000ffffffff
    R10: 0000000000000008  R11: 0000000000000044  R12: 0000000000000086
    R13: ffff8810697ac158  R14: ffff88101045f6b0  R15: 0000000100000001
    ORIG_RAX: ffffffffffffff03  CS: 0010  SS: 0018
#12 [ffff88101045f768] blk_cbt_bio_queue at ffffffff812b1d59
#13 [ffff88101045f778] generic_make_request at ffffffff8129412d
#14 [ffff88101045f838] submit_bio at ffffffff812944e1
#15 [ffff88101045f8a8] submit_bh at ffffffff81202f9d
...

Patch disables interrupts before access to spin_lock_page().

https://jira.sw.ru/browse/PSBM-89323
Signed-off-by: Vasily Averin <vvs@virtuozzo.com>

Patch hide | download patch | download mbox

diff --git a/block/blk-cbt.c b/block/blk-cbt.c
index 7a4303f720f..7a437356a24 100644
--- a/block/blk-cbt.c
+++ b/block/blk-cbt.c
@@ -98,9 +98,11 @@  static int __blk_cbt_set(struct cbt_info  *cbt, blkcnt_t block,
 
 		page = rcu_dereference(cbt->map[idx]);
 		if (page) {
+			local_irq_disable();
 			spin_lock_page(page);
 			set_bits(page_address(page), off, len, set);
 			unlock_page(page);
+			local_irq_enable();
 			count -= len;
 			block += len;
 			continue;