xref: /linux/fs/xfs/xfs_trans_ail.c (revision 3577cfd738e29b3d54cdb10c45a56730346dfe8b)
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * Copyright (c) 2000-2002,2005 Silicon Graphics, Inc.
4  * Copyright (c) 2008 Dave Chinner
5  * All Rights Reserved.
6  */
7 #include "xfs_platform.h"
8 #include "xfs_fs.h"
9 #include "xfs_shared.h"
10 #include "xfs_format.h"
11 #include "xfs_log_format.h"
12 #include "xfs_trans_resv.h"
13 #include "xfs_mount.h"
14 #include "xfs_trans.h"
15 #include "xfs_trans_priv.h"
16 #include "xfs_trace.h"
17 #include "xfs_errortag.h"
18 #include "xfs_error.h"
19 #include "xfs_log.h"
20 #include "xfs_log_priv.h"
21 
22 #ifdef DEBUG
23 /*
24  * Check that the list is sorted as it should be.
25  *
26  * Called with the ail lock held, but we don't want to assert fail with it
27  * held otherwise we'll lock everything up and won't be able to debug the
28  * cause. Hence we sample and check the state under the AIL lock and return if
29  * everything is fine, otherwise we drop the lock and run the ASSERT checks.
30  * Asserts may not be fatal, so pick the lock back up and continue onwards.
31  */
32 STATIC void
xfs_ail_check(struct xfs_ail * ailp,struct xfs_log_item * lip)33 xfs_ail_check(
34 	struct xfs_ail		*ailp,
35 	struct xfs_log_item	*lip)
36 	__must_hold(&ailp->ail_lock)
37 {
38 	struct xfs_log_item	*prev_lip;
39 	struct xfs_log_item	*next_lip;
40 	xfs_lsn_t		prev_lsn = NULLCOMMITLSN;
41 	xfs_lsn_t		next_lsn = NULLCOMMITLSN;
42 	xfs_lsn_t		lsn;
43 	bool			in_ail;
44 
45 
46 	if (list_empty(&ailp->ail_head))
47 		return;
48 
49 	/*
50 	 * Sample then check the next and previous entries are valid.
51 	 */
52 	in_ail = test_bit(XFS_LI_IN_AIL, &lip->li_flags);
53 	prev_lip = list_entry(lip->li_ail.prev, struct xfs_log_item, li_ail);
54 	if (&prev_lip->li_ail != &ailp->ail_head)
55 		prev_lsn = prev_lip->li_lsn;
56 	next_lip = list_entry(lip->li_ail.next, struct xfs_log_item, li_ail);
57 	if (&next_lip->li_ail != &ailp->ail_head)
58 		next_lsn = next_lip->li_lsn;
59 	lsn = lip->li_lsn;
60 
61 	if (in_ail &&
62 	    (prev_lsn == NULLCOMMITLSN || XFS_LSN_CMP(prev_lsn, lsn) <= 0) &&
63 	    (next_lsn == NULLCOMMITLSN || XFS_LSN_CMP(next_lsn, lsn) >= 0))
64 		return;
65 
66 	spin_unlock(&ailp->ail_lock);
67 	ASSERT(in_ail);
68 	ASSERT(prev_lsn == NULLCOMMITLSN || XFS_LSN_CMP(prev_lsn, lsn) <= 0);
69 	ASSERT(next_lsn == NULLCOMMITLSN || XFS_LSN_CMP(next_lsn, lsn) >= 0);
70 	spin_lock(&ailp->ail_lock);
71 }
72 #else /* !DEBUG */
73 #define	xfs_ail_check(a,l)
74 #endif /* DEBUG */
75 
76 /*
77  * Return a pointer to the last item in the AIL.  If the AIL is empty, then
78  * return NULL.
79  */
80 static struct xfs_log_item *
xfs_ail_max(struct xfs_ail * ailp)81 xfs_ail_max(
82 	struct xfs_ail  *ailp)
83 {
84 	if (list_empty(&ailp->ail_head))
85 		return NULL;
86 
87 	return list_entry(ailp->ail_head.prev, struct xfs_log_item, li_ail);
88 }
89 
90 /*
91  * Return a pointer to the item which follows the given item in the AIL.  If
92  * the given item is the last item in the list, then return NULL.
93  */
94 static struct xfs_log_item *
xfs_ail_next(struct xfs_ail * ailp,struct xfs_log_item * lip)95 xfs_ail_next(
96 	struct xfs_ail		*ailp,
97 	struct xfs_log_item	*lip)
98 {
99 	if (lip->li_ail.next == &ailp->ail_head)
100 		return NULL;
101 
102 	return list_first_entry(&lip->li_ail, struct xfs_log_item, li_ail);
103 }
104 
105 /*
106  * This is called by the log manager code to determine the LSN of the tail of
107  * the log.  This is exactly the LSN of the first item in the AIL.  If the AIL
108  * is empty, then this function returns 0.
109  *
110  * We need the AIL lock in order to get a coherent read of the lsn of the last
111  * item in the AIL.
112  */
113 static xfs_lsn_t
__xfs_ail_min_lsn(struct xfs_ail * ailp)114 __xfs_ail_min_lsn(
115 	struct xfs_ail		*ailp)
116 {
117 	struct xfs_log_item	*lip = xfs_ail_min(ailp);
118 
119 	if (lip)
120 		return lip->li_lsn;
121 	return 0;
122 }
123 
124 xfs_lsn_t
xfs_ail_min_lsn(struct xfs_ail * ailp)125 xfs_ail_min_lsn(
126 	struct xfs_ail		*ailp)
127 {
128 	xfs_lsn_t		lsn;
129 
130 	spin_lock(&ailp->ail_lock);
131 	lsn = __xfs_ail_min_lsn(ailp);
132 	spin_unlock(&ailp->ail_lock);
133 
134 	return lsn;
135 }
136 
137 /*
138  * The cursor keeps track of where our current traversal is up to by tracking
139  * the next item in the list for us. However, for this to be safe, removing an
140  * object from the AIL needs to invalidate any cursor that points to it. hence
141  * the traversal cursor needs to be linked to the struct xfs_ail so that
142  * deletion can search all the active cursors for invalidation.
143  */
144 STATIC void
xfs_trans_ail_cursor_init(struct xfs_ail * ailp,struct xfs_ail_cursor * cur)145 xfs_trans_ail_cursor_init(
146 	struct xfs_ail		*ailp,
147 	struct xfs_ail_cursor	*cur)
148 {
149 	cur->item = NULL;
150 	list_add_tail(&cur->list, &ailp->ail_cursors);
151 }
152 
153 /*
154  * Get the next item in the traversal and advance the cursor.  If the cursor
155  * was invalidated (indicated by a lip of 1), restart the traversal.
156  */
157 struct xfs_log_item *
xfs_trans_ail_cursor_next(struct xfs_ail * ailp,struct xfs_ail_cursor * cur)158 xfs_trans_ail_cursor_next(
159 	struct xfs_ail		*ailp,
160 	struct xfs_ail_cursor	*cur)
161 {
162 	struct xfs_log_item	*lip = cur->item;
163 
164 	if ((uintptr_t)lip & 1)
165 		lip = xfs_ail_min(ailp);
166 	if (lip)
167 		cur->item = xfs_ail_next(ailp, lip);
168 	return lip;
169 }
170 
171 /*
172  * When the traversal is complete, we need to remove the cursor from the list
173  * of traversing cursors.
174  */
175 void
xfs_trans_ail_cursor_done(struct xfs_ail_cursor * cur)176 xfs_trans_ail_cursor_done(
177 	struct xfs_ail_cursor	*cur)
178 {
179 	cur->item = NULL;
180 	list_del_init(&cur->list);
181 }
182 
183 /*
184  * Invalidate any cursor that is pointing to this item. This is called when an
185  * item is removed from the AIL. Any cursor pointing to this object is now
186  * invalid and the traversal needs to be terminated so it doesn't reference a
187  * freed object. We set the low bit of the cursor item pointer so we can
188  * distinguish between an invalidation and the end of the list when getting the
189  * next item from the cursor.
190  */
191 STATIC void
xfs_trans_ail_cursor_clear(struct xfs_ail * ailp,struct xfs_log_item * lip)192 xfs_trans_ail_cursor_clear(
193 	struct xfs_ail		*ailp,
194 	struct xfs_log_item	*lip)
195 {
196 	struct xfs_ail_cursor	*cur;
197 
198 	list_for_each_entry(cur, &ailp->ail_cursors, list) {
199 		if (cur->item == lip)
200 			cur->item = (struct xfs_log_item *)
201 					((uintptr_t)cur->item | 1);
202 	}
203 }
204 
205 /*
206  * Find the first item in the AIL with the given @lsn by searching in ascending
207  * LSN order and initialise the cursor to point to the next item for a
208  * ascending traversal.  Pass a @lsn of zero to initialise the cursor to the
209  * first item in the AIL. Returns NULL if the list is empty.
210  */
211 struct xfs_log_item *
xfs_trans_ail_cursor_first(struct xfs_ail * ailp,struct xfs_ail_cursor * cur,xfs_lsn_t lsn)212 xfs_trans_ail_cursor_first(
213 	struct xfs_ail		*ailp,
214 	struct xfs_ail_cursor	*cur,
215 	xfs_lsn_t		lsn)
216 {
217 	struct xfs_log_item	*lip;
218 
219 	xfs_trans_ail_cursor_init(ailp, cur);
220 
221 	if (lsn == 0) {
222 		lip = xfs_ail_min(ailp);
223 		goto out;
224 	}
225 
226 	list_for_each_entry(lip, &ailp->ail_head, li_ail) {
227 		if (XFS_LSN_CMP(lip->li_lsn, lsn) >= 0)
228 			goto out;
229 	}
230 	return NULL;
231 
232 out:
233 	if (lip)
234 		cur->item = xfs_ail_next(ailp, lip);
235 	return lip;
236 }
237 
238 static struct xfs_log_item *
__xfs_trans_ail_cursor_last(struct xfs_ail * ailp,xfs_lsn_t lsn)239 __xfs_trans_ail_cursor_last(
240 	struct xfs_ail		*ailp,
241 	xfs_lsn_t		lsn)
242 {
243 	struct xfs_log_item	*lip;
244 
245 	list_for_each_entry_reverse(lip, &ailp->ail_head, li_ail) {
246 		if (XFS_LSN_CMP(lip->li_lsn, lsn) <= 0)
247 			return lip;
248 	}
249 	return NULL;
250 }
251 
252 /*
253  * Find the last item in the AIL with the given @lsn by searching in descending
254  * LSN order and initialise the cursor to point to that item.  If there is no
255  * item with the value of @lsn, then it sets the cursor to the last item with an
256  * LSN lower than @lsn.  Returns NULL if the list is empty.
257  */
258 struct xfs_log_item *
xfs_trans_ail_cursor_last(struct xfs_ail * ailp,struct xfs_ail_cursor * cur,xfs_lsn_t lsn)259 xfs_trans_ail_cursor_last(
260 	struct xfs_ail		*ailp,
261 	struct xfs_ail_cursor	*cur,
262 	xfs_lsn_t		lsn)
263 {
264 	xfs_trans_ail_cursor_init(ailp, cur);
265 	cur->item = __xfs_trans_ail_cursor_last(ailp, lsn);
266 	return cur->item;
267 }
268 
269 /*
270  * Splice the log item list into the AIL at the given LSN. We splice to the
271  * tail of the given LSN to maintain insert order for push traversals. The
272  * cursor is optional, allowing repeated updates to the same LSN to avoid
273  * repeated traversals.  This should not be called with an empty list.
274  */
275 static void
xfs_ail_splice(struct xfs_ail * ailp,struct xfs_ail_cursor * cur,struct list_head * list,xfs_lsn_t lsn)276 xfs_ail_splice(
277 	struct xfs_ail		*ailp,
278 	struct xfs_ail_cursor	*cur,
279 	struct list_head	*list,
280 	xfs_lsn_t		lsn)
281 {
282 	struct xfs_log_item	*lip;
283 
284 	ASSERT(!list_empty(list));
285 
286 	/*
287 	 * Use the cursor to determine the insertion point if one is
288 	 * provided.  If not, or if the one we got is not valid,
289 	 * find the place in the AIL where the items belong.
290 	 */
291 	lip = cur ? cur->item : NULL;
292 	if (!lip || (uintptr_t)lip & 1)
293 		lip = __xfs_trans_ail_cursor_last(ailp, lsn);
294 
295 	/*
296 	 * If a cursor is provided, we know we're processing the AIL
297 	 * in lsn order, and future items to be spliced in will
298 	 * follow the last one being inserted now.  Update the
299 	 * cursor to point to that last item, now while we have a
300 	 * reliable pointer to it.
301 	 */
302 	if (cur)
303 		cur->item = list_entry(list->prev, struct xfs_log_item, li_ail);
304 
305 	/*
306 	 * Finally perform the splice.  Unless the AIL was empty,
307 	 * lip points to the item in the AIL _after_ which the new
308 	 * items should go.  If lip is null the AIL was empty, so
309 	 * the new items go at the head of the AIL.
310 	 */
311 	if (lip)
312 		list_splice(list, &lip->li_ail);
313 	else
314 		list_splice(list, &ailp->ail_head);
315 }
316 
317 /*
318  * Delete the given item from the AIL.
319  */
320 static void
xfs_ail_delete(struct xfs_ail * ailp,struct xfs_log_item * lip)321 xfs_ail_delete(
322 	struct xfs_ail		*ailp,
323 	struct xfs_log_item	*lip)
324 {
325 	xfs_ail_check(ailp, lip);
326 	list_del(&lip->li_ail);
327 	xfs_trans_ail_cursor_clear(ailp, lip);
328 }
329 
330 /*
331  * Requeue a failed buffer for writeback.
332  *
333  * We clear the log item failed state here as well, but we have to be careful
334  * about reference counts because the only active reference counts on the buffer
335  * may be the failed log items. Hence if we clear the log item failed state
336  * before queuing the buffer for IO we can release all active references to
337  * the buffer and free it, leading to use after free problems in
338  * xfs_buf_delwri_queue. It makes no difference to the buffer or log items which
339  * order we process them in - the buffer is locked, and we own the buffer list
340  * so nothing on them is going to change while we are performing this action.
341  *
342  * Hence we can safely queue the buffer for IO before we clear the failed log
343  * item state, therefore  always having an active reference to the buffer and
344  * avoiding the transient zero-reference state that leads to use-after-free.
345  */
346 static inline int
xfsaild_resubmit_item(struct xfs_log_item * lip,struct list_head * buffer_list)347 xfsaild_resubmit_item(
348 	struct xfs_log_item	*lip,
349 	struct list_head	*buffer_list)
350 {
351 	struct xfs_buf		*bp = lip->li_buf;
352 
353 	if (!xfs_buf_trylock(bp))
354 		return XFS_ITEM_LOCKED;
355 
356 	if (!xfs_buf_delwri_queue(bp, buffer_list)) {
357 		xfs_buf_unlock(bp);
358 		return XFS_ITEM_FLUSHING;
359 	}
360 
361 	/* protected by ail_lock */
362 	list_for_each_entry(lip, &bp->b_li_list, li_bio_list)
363 		clear_bit(XFS_LI_FAILED, &lip->li_flags);
364 	xfs_buf_unlock(bp);
365 	return XFS_ITEM_SUCCESS;
366 }
367 
368 /*
369  * Push a single log item from the AIL.
370  *
371  * @lip may have been released and freed by the time this function returns,
372  * so callers must not dereference the log item afterwards.
373  */
374 static inline uint
xfsaild_push_item(struct xfs_ail * ailp,struct xfs_log_item * lip)375 xfsaild_push_item(
376 	struct xfs_ail		*ailp,
377 	struct xfs_log_item	*lip)
378 {
379 	/*
380 	 * If log item pinning is enabled, skip the push and track the item as
381 	 * pinned. This can help induce head-behind-tail conditions.
382 	 */
383 	if (XFS_TEST_ERROR(ailp->ail_log->l_mp, XFS_ERRTAG_LOG_ITEM_PIN))
384 		return XFS_ITEM_PINNED;
385 
386 	/*
387 	 * Consider the item pinned if a push callback is not defined so the
388 	 * caller will force the log. This should only happen for intent items
389 	 * as they are unpinned once the associated done item is committed to
390 	 * the on-disk log.
391 	 */
392 	if (!lip->li_ops->iop_push)
393 		return XFS_ITEM_PINNED;
394 	if (test_bit(XFS_LI_FAILED, &lip->li_flags))
395 		return xfsaild_resubmit_item(lip, &ailp->ail_buf_list);
396 	return lip->li_ops->iop_push(lip, &ailp->ail_buf_list);
397 }
398 
399 /*
400  * Compute the LSN that we'd need to push the log tail towards in order to have
401  * at least 25% of the log space free.  If the log free space already meets this
402  * threshold, this function returns the lowest LSN in the AIL to slowly keep
403  * writeback ticking over and the tail of the log moving forward.
404  */
405 static xfs_lsn_t
xfs_ail_calc_push_target(struct xfs_ail * ailp)406 xfs_ail_calc_push_target(
407 	struct xfs_ail		*ailp)
408 {
409 	struct xlog		*log = ailp->ail_log;
410 	struct xfs_log_item	*lip;
411 	xfs_lsn_t		target_lsn;
412 	xfs_lsn_t		max_lsn;
413 	xfs_lsn_t		min_lsn;
414 	int32_t			free_bytes;
415 	uint32_t		target_block;
416 	uint32_t		target_cycle;
417 
418 	lockdep_assert_held(&ailp->ail_lock);
419 
420 	lip = xfs_ail_max(ailp);
421 	if (!lip)
422 		return NULLCOMMITLSN;
423 
424 	max_lsn = lip->li_lsn;
425 	min_lsn = __xfs_ail_min_lsn(ailp);
426 
427 	/*
428 	 * If we are supposed to push all the items in the AIL, we want to push
429 	 * to the current head. We then clear the push flag so that we don't
430 	 * keep pushing newly queued items beyond where the push all command was
431 	 * run. If the push waiter wants to empty the ail, it should queue
432 	 * itself on the ail_empty wait queue.
433 	 */
434 	if (test_and_clear_bit(XFS_AIL_OPSTATE_PUSH_ALL, &ailp->ail_opstate))
435 		return max_lsn;
436 
437 	/* If someone wants the AIL empty, keep pushing everything we have. */
438 	if (waitqueue_active(&ailp->ail_empty))
439 		return max_lsn;
440 
441 	/*
442 	 * Background pushing - attempt to keep 25% of the log free and if we
443 	 * have that much free retain the existing target.
444 	 */
445 	free_bytes = log->l_logsize - xlog_lsn_sub(log, max_lsn, min_lsn);
446 	if (free_bytes >= log->l_logsize >> 2)
447 		return ailp->ail_target;
448 
449 	target_cycle = CYCLE_LSN(min_lsn);
450 	target_block = BLOCK_LSN(min_lsn) + (log->l_logBBsize >> 2);
451 	if (target_block >= log->l_logBBsize) {
452 		target_block -= log->l_logBBsize;
453 		target_cycle += 1;
454 	}
455 	target_lsn = xlog_assign_lsn(target_cycle, target_block);
456 
457 	/* Cap the target to the highest LSN known to be in the AIL. */
458 	if (XFS_LSN_CMP(target_lsn, max_lsn) > 0)
459 		return max_lsn;
460 
461 	/* If the existing target is higher than the new target, keep it. */
462 	if (XFS_LSN_CMP(ailp->ail_target, target_lsn) >= 0)
463 		return ailp->ail_target;
464 	return target_lsn;
465 }
466 
467 static void
xfsaild_process_logitem(struct xfs_ail * ailp,struct xfs_log_item * lip,int * stuck,int * flushing)468 xfsaild_process_logitem(
469 	struct xfs_ail		*ailp,
470 	struct xfs_log_item	*lip,
471 	int			*stuck,
472 	int			*flushing)
473 {
474 	struct xfs_mount	*mp = ailp->ail_log->l_mp;
475 	uint			type = lip->li_type;
476 	unsigned long		flags = lip->li_flags;
477 	xfs_lsn_t		item_lsn = lip->li_lsn;
478 	int			lock_result;
479 
480 	/*
481 	 * Note that iop_push may unlock and reacquire the AIL lock. We
482 	 * rely on the AIL cursor implementation to be able to deal with
483 	 * the dropped lock.
484 	 *
485 	 * The log item may have been freed by the push, so it must not
486 	 * be accessed or dereferenced below this line.
487 	 */
488 	lock_result = xfsaild_push_item(ailp, lip);
489 	switch (lock_result) {
490 	case XFS_ITEM_SUCCESS:
491 		XFS_STATS_INC(mp, xs_push_ail_success);
492 		trace_xfs_ail_push(ailp, type, flags, item_lsn);
493 
494 		ailp->ail_last_pushed_lsn = item_lsn;
495 		break;
496 
497 	case XFS_ITEM_FLUSHING:
498 		/*
499 		 * The item or its backing buffer is already being
500 		 * flushed.  The typical reason for that is that an
501 		 * inode buffer is locked because we already pushed the
502 		 * updates to it as part of inode clustering.
503 		 *
504 		 * We do not want to stop flushing just because lots
505 		 * of items are already being flushed, but we need to
506 		 * re-try the flushing relatively soon if most of the
507 		 * AIL is being flushed.
508 		 */
509 		XFS_STATS_INC(mp, xs_push_ail_flushing);
510 		trace_xfs_ail_flushing(ailp, type, flags, item_lsn);
511 
512 		(*flushing)++;
513 		ailp->ail_last_pushed_lsn = item_lsn;
514 		break;
515 
516 	case XFS_ITEM_PINNED:
517 		XFS_STATS_INC(mp, xs_push_ail_pinned);
518 		trace_xfs_ail_pinned(ailp, type, flags, item_lsn);
519 
520 		(*stuck)++;
521 		ailp->ail_log_flush++;
522 		break;
523 	case XFS_ITEM_LOCKED:
524 		XFS_STATS_INC(mp, xs_push_ail_locked);
525 		trace_xfs_ail_locked(ailp, type, flags, item_lsn);
526 
527 		(*stuck)++;
528 		break;
529 	default:
530 		ASSERT(0);
531 		break;
532 	}
533 }
534 
535 static long
xfsaild_push(struct xfs_ail * ailp)536 xfsaild_push(
537 	struct xfs_ail		*ailp)
538 {
539 	struct xfs_mount	*mp = ailp->ail_log->l_mp;
540 	struct xfs_ail_cursor	cur;
541 	struct xfs_log_item	*lip;
542 	xfs_lsn_t		lsn;
543 	long			tout;
544 	int			stuck = 0;
545 	int			flushing = 0;
546 	int			count = 0;
547 
548 	/*
549 	 * If we encountered pinned items or did not finish writing out all
550 	 * buffers the last time we ran, force a background CIL push to get the
551 	 * items unpinned in the near future. We do not wait on the CIL push as
552 	 * that could stall us for seconds if there is enough background IO
553 	 * load. Stalling for that long when the tail of the log is pinned and
554 	 * needs flushing will hard stop the transaction subsystem when log
555 	 * space runs out.
556 	 */
557 	if (ailp->ail_log_flush && ailp->ail_last_pushed_lsn == 0 &&
558 	    (!list_empty_careful(&ailp->ail_buf_list) ||
559 	     xfs_ail_min_lsn(ailp))) {
560 		ailp->ail_log_flush = 0;
561 
562 		XFS_STATS_INC(mp, xs_push_ail_flush);
563 		xlog_cil_flush(ailp->ail_log);
564 	}
565 
566 	spin_lock(&ailp->ail_lock);
567 	WRITE_ONCE(ailp->ail_target, xfs_ail_calc_push_target(ailp));
568 	if (ailp->ail_target == NULLCOMMITLSN)
569 		goto out_done;
570 
571 	/* we're done if the AIL is empty or our push has reached the end */
572 	lip = xfs_trans_ail_cursor_first(ailp, &cur, ailp->ail_last_pushed_lsn);
573 	if (!lip)
574 		goto out_done_cursor;
575 
576 	XFS_STATS_INC(mp, xs_push_ail);
577 
578 	ASSERT(ailp->ail_target != NULLCOMMITLSN);
579 
580 	lsn = lip->li_lsn;
581 	while ((XFS_LSN_CMP(lip->li_lsn, ailp->ail_target) <= 0)) {
582 
583 		if (test_bit(XFS_LI_FLUSHING, &lip->li_flags))
584 			goto next_item;
585 
586 		xfsaild_process_logitem(ailp, lip, &stuck, &flushing);
587 		count++;
588 
589 		/*
590 		 * Are there too many items we can't do anything with?
591 		 *
592 		 * If we are skipping too many items because we can't flush
593 		 * them or they are already being flushed, we back off and
594 		 * given them time to complete whatever operation is being
595 		 * done. i.e. remove pressure from the AIL while we can't make
596 		 * progress so traversals don't slow down further inserts and
597 		 * removals to/from the AIL.
598 		 *
599 		 * The value of 100 is an arbitrary magic number based on
600 		 * observation.
601 		 */
602 		if (stuck > 100)
603 			break;
604 
605 next_item:
606 		lip = xfs_trans_ail_cursor_next(ailp, &cur);
607 		if (lip == NULL)
608 			break;
609 		if (lip->li_lsn != lsn && count > 1000)
610 			break;
611 		lsn = lip->li_lsn;
612 	}
613 
614 out_done_cursor:
615 	xfs_trans_ail_cursor_done(&cur);
616 out_done:
617 	spin_unlock(&ailp->ail_lock);
618 
619 	if (xfs_buf_delwri_submit_nowait(&ailp->ail_buf_list))
620 		ailp->ail_log_flush++;
621 
622 	if (!count || XFS_LSN_CMP(lsn, ailp->ail_target) >= 0) {
623 		/*
624 		 * We reached the target or the AIL is empty, so wait a bit
625 		 * longer for I/O to complete and remove pushed items from the
626 		 * AIL before we start the next scan from the start of the AIL.
627 		 */
628 		tout = 50;
629 		ailp->ail_last_pushed_lsn = 0;
630 	} else if (((stuck + flushing) * 100) / count > 90) {
631 		/*
632 		 * Either there is a lot of contention on the AIL or we are
633 		 * stuck due to operations in progress. "Stuck" in this case
634 		 * is defined as >90% of the items we tried to push were stuck.
635 		 *
636 		 * Backoff a bit more to allow some I/O to complete before
637 		 * restarting from the start of the AIL. This prevents us from
638 		 * spinning on the same items, and if they are pinned will all
639 		 * the restart to issue a log force to unpin the stuck items.
640 		 */
641 		tout = 20;
642 		ailp->ail_last_pushed_lsn = 0;
643 	} else {
644 		/*
645 		 * Assume we have more work to do in a short while.
646 		 */
647 		tout = 0;
648 	}
649 
650 	return tout;
651 }
652 
653 static int
xfsaild(void * data)654 xfsaild(
655 	void		*data)
656 {
657 	struct xfs_ail	*ailp = data;
658 	long		tout = 0;	/* milliseconds */
659 	unsigned int	noreclaim_flag;
660 
661 	noreclaim_flag = memalloc_noreclaim_save();
662 	set_freezable();
663 
664 	while (1) {
665 		/*
666 		 * Long waits of 50ms or more occur when we've run out of items
667 		 * to push, so we only want uninterruptible state if we're
668 		 * actually blocked on something.
669 		 */
670 		if (tout && tout <= 20)
671 			set_current_state(TASK_KILLABLE|TASK_FREEZABLE);
672 		else
673 			set_current_state(TASK_INTERRUPTIBLE|TASK_FREEZABLE);
674 
675 		/*
676 		 * Check kthread_should_stop() after we set the task state to
677 		 * guarantee that we either see the stop bit and exit or the
678 		 * task state is reset to runnable such that it's not scheduled
679 		 * out indefinitely and detects the stop bit at next iteration.
680 		 * A memory barrier is included in above task state set to
681 		 * serialize again kthread_stop().
682 		 */
683 		if (kthread_should_stop()) {
684 			__set_current_state(TASK_RUNNING);
685 
686 			/*
687 			 * The caller forces out the AIL before stopping the
688 			 * thread in the common case, which means the delwri
689 			 * queue is drained. In the shutdown case, the queue may
690 			 * still hold relogged buffers that haven't been
691 			 * submitted because they were pinned since added to the
692 			 * queue.
693 			 *
694 			 * Log I/O error processing stales the underlying buffer
695 			 * and clears the delwri state, expecting the buf to be
696 			 * removed on the next submission attempt. That won't
697 			 * happen if we're shutting down, so this is the last
698 			 * opportunity to release such buffers from the queue.
699 			 */
700 			ASSERT(list_empty(&ailp->ail_buf_list) ||
701 			       xlog_is_shutdown(ailp->ail_log));
702 			xfs_buf_delwri_cancel(&ailp->ail_buf_list);
703 			break;
704 		}
705 
706 		/* Idle if the AIL is empty. */
707 		spin_lock(&ailp->ail_lock);
708 		if (!xfs_ail_min(ailp) && list_empty(&ailp->ail_buf_list)) {
709 			spin_unlock(&ailp->ail_lock);
710 			schedule();
711 			tout = 0;
712 			continue;
713 		}
714 		spin_unlock(&ailp->ail_lock);
715 
716 		if (tout)
717 			schedule_timeout(msecs_to_jiffies(tout));
718 
719 		__set_current_state(TASK_RUNNING);
720 
721 		try_to_freeze();
722 
723 		tout = xfsaild_push(ailp);
724 	}
725 
726 	memalloc_noreclaim_restore(noreclaim_flag);
727 	return 0;
728 }
729 
730 /*
731  * Push out all items in the AIL immediately and wait until the AIL is empty.
732  */
733 void
xfs_ail_push_all_sync(struct xfs_ail * ailp)734 xfs_ail_push_all_sync(
735 	struct xfs_ail  *ailp)
736 {
737 	DEFINE_WAIT(wait);
738 
739 	spin_lock(&ailp->ail_lock);
740 	while (xfs_ail_max(ailp) != NULL) {
741 		prepare_to_wait(&ailp->ail_empty, &wait, TASK_UNINTERRUPTIBLE);
742 		wake_up_process(ailp->ail_task);
743 		spin_unlock(&ailp->ail_lock);
744 		schedule();
745 		spin_lock(&ailp->ail_lock);
746 	}
747 	spin_unlock(&ailp->ail_lock);
748 
749 	finish_wait(&ailp->ail_empty, &wait);
750 }
751 
752 void
__xfs_ail_assign_tail_lsn(struct xfs_ail * ailp)753 __xfs_ail_assign_tail_lsn(
754 	struct xfs_ail		*ailp)
755 {
756 	struct xlog		*log = ailp->ail_log;
757 	xfs_lsn_t		tail_lsn;
758 
759 	assert_spin_locked(&ailp->ail_lock);
760 
761 	if (xlog_is_shutdown(log))
762 		return;
763 
764 	tail_lsn = __xfs_ail_min_lsn(ailp);
765 	if (!tail_lsn)
766 		tail_lsn = ailp->ail_head_lsn;
767 
768 	WRITE_ONCE(log->l_tail_space,
769 			xlog_lsn_sub(log, ailp->ail_head_lsn, tail_lsn));
770 	trace_xfs_log_assign_tail_lsn(log, tail_lsn);
771 	atomic64_set(&log->l_tail_lsn, tail_lsn);
772 }
773 
774 /*
775  * Callers should pass the original tail lsn so that we can detect if the tail
776  * has moved as a result of the operation that was performed. If the caller
777  * needs to force a tail space update, it should pass NULLCOMMITLSN to bypass
778  * the "did the tail LSN change?" checks. If the caller wants to avoid a tail
779  * update (e.g. it knows the tail did not change) it should pass an @old_lsn of
780  * 0.
781  */
782 void
xfs_ail_update_finish(struct xfs_ail * ailp,xfs_lsn_t old_lsn)783 xfs_ail_update_finish(
784 	struct xfs_ail		*ailp,
785 	xfs_lsn_t		old_lsn) __releases(ailp->ail_lock)
786 {
787 	struct xlog		*log = ailp->ail_log;
788 
789 	/* If the tail lsn hasn't changed, don't do updates or wakeups. */
790 	if (!old_lsn || old_lsn == __xfs_ail_min_lsn(ailp)) {
791 		spin_unlock(&ailp->ail_lock);
792 		return;
793 	}
794 
795 	__xfs_ail_assign_tail_lsn(ailp);
796 	if (list_empty(&ailp->ail_head))
797 		wake_up_all(&ailp->ail_empty);
798 	spin_unlock(&ailp->ail_lock);
799 	xfs_log_space_wake(log->l_mp);
800 }
801 
802 /*
803  * xfs_trans_ail_update_bulk - bulk AIL insertion operation.
804  *
805  * @xfs_trans_ail_update_bulk takes an array of log items that all need to be
806  * positioned at the same LSN in the AIL. If an item is not in the AIL, it will
807  * be added. Otherwise, it will be repositioned by removing it and re-adding
808  * it to the AIL.
809  *
810  * If we move the first item in the AIL, update the log tail to match the new
811  * minimum LSN in the AIL.
812  *
813  * This function should be called with the AIL lock held.
814  *
815  * To optimise the insert operation, we add all items to a temporary list, then
816  * splice this list into the correct position in the AIL.
817  *
818  * Items that are already in the AIL are first deleted from their current
819  * location before being added to the temporary list.
820  *
821  * This avoids needing to do an insert operation on every item.
822  *
823  * The AIL lock is dropped by xfs_ail_update_finish() before returning to
824  * the caller.
825  */
826 void
xfs_trans_ail_update_bulk(struct xfs_ail * ailp,struct xfs_ail_cursor * cur,struct xfs_log_item ** log_items,int nr_items,xfs_lsn_t lsn)827 xfs_trans_ail_update_bulk(
828 	struct xfs_ail		*ailp,
829 	struct xfs_ail_cursor	*cur,
830 	struct xfs_log_item	**log_items,
831 	int			nr_items,
832 	xfs_lsn_t		lsn) __releases(ailp->ail_lock)
833 {
834 	struct xfs_log_item	*mlip;
835 	xfs_lsn_t		tail_lsn = 0;
836 	int			i;
837 	LIST_HEAD(tmp);
838 
839 	ASSERT(nr_items > 0);		/* Not required, but true. */
840 	mlip = xfs_ail_min(ailp);
841 
842 	for (i = 0; i < nr_items; i++) {
843 		struct xfs_log_item *lip = log_items[i];
844 		if (test_and_set_bit(XFS_LI_IN_AIL, &lip->li_flags)) {
845 			/* check if we really need to move the item */
846 			if (XFS_LSN_CMP(lsn, lip->li_lsn) <= 0)
847 				continue;
848 
849 			trace_xfs_ail_move(lip, lip->li_lsn, lsn);
850 			if (mlip == lip && !tail_lsn)
851 				tail_lsn = lip->li_lsn;
852 
853 			xfs_ail_delete(ailp, lip);
854 		} else {
855 			trace_xfs_ail_insert(lip, 0, lsn);
856 		}
857 		lip->li_lsn = lsn;
858 		list_add_tail(&lip->li_ail, &tmp);
859 	}
860 
861 	if (!list_empty(&tmp))
862 		xfs_ail_splice(ailp, cur, &tmp, lsn);
863 
864 	/*
865 	 * If this is the first insert, wake up the push daemon so it can
866 	 * actively scan for items to push. We also need to do a log tail
867 	 * LSN update to ensure that it is correctly tracked by the log, so
868 	 * set the tail_lsn to NULLCOMMITLSN so that xfs_ail_update_finish()
869 	 * will see that the tail lsn has changed and will update the tail
870 	 * appropriately.
871 	 */
872 	if (!mlip) {
873 		wake_up_process(ailp->ail_task);
874 		tail_lsn = NULLCOMMITLSN;
875 	}
876 
877 	xfs_ail_update_finish(ailp, tail_lsn);
878 }
879 
880 /* Insert a log item into the AIL. */
881 void
xfs_trans_ail_insert(struct xfs_ail * ailp,struct xfs_log_item * lip,xfs_lsn_t lsn)882 xfs_trans_ail_insert(
883 	struct xfs_ail		*ailp,
884 	struct xfs_log_item	*lip,
885 	xfs_lsn_t		lsn)
886 {
887 	spin_lock(&ailp->ail_lock);
888 	xfs_trans_ail_update_bulk(ailp, NULL, &lip, 1, lsn);
889 }
890 
891 /*
892  * Delete one log item from the AIL.
893  *
894  * If this item was at the tail of the AIL, return the LSN of the log item so
895  * that we can use it to check if the LSN of the tail of the log has moved
896  * when finishing up the AIL delete process in xfs_ail_update_finish().
897  */
898 xfs_lsn_t
xfs_ail_delete_one(struct xfs_ail * ailp,struct xfs_log_item * lip)899 xfs_ail_delete_one(
900 	struct xfs_ail		*ailp,
901 	struct xfs_log_item	*lip)
902 {
903 	struct xfs_log_item	*mlip = xfs_ail_min(ailp);
904 	xfs_lsn_t		lsn = lip->li_lsn;
905 
906 	trace_xfs_ail_delete(lip, mlip->li_lsn, lip->li_lsn);
907 	xfs_ail_delete(ailp, lip);
908 	clear_bit(XFS_LI_IN_AIL, &lip->li_flags);
909 	lip->li_lsn = 0;
910 
911 	if (mlip == lip)
912 		return lsn;
913 	return 0;
914 }
915 
916 void
xfs_trans_ail_delete(struct xfs_log_item * lip,int shutdown_type)917 xfs_trans_ail_delete(
918 	struct xfs_log_item	*lip,
919 	int			shutdown_type)
920 {
921 	struct xfs_ail		*ailp = lip->li_ailp;
922 	struct xlog		*log = ailp->ail_log;
923 	xfs_lsn_t		tail_lsn;
924 
925 	spin_lock(&ailp->ail_lock);
926 	if (!test_bit(XFS_LI_IN_AIL, &lip->li_flags)) {
927 		spin_unlock(&ailp->ail_lock);
928 		if (shutdown_type && !xlog_is_shutdown(log)) {
929 			xfs_alert_tag(log->l_mp, XFS_PTAG_AILDELETE,
930 	"%s: attempting to delete a log item that is not in the AIL",
931 					__func__);
932 			xlog_force_shutdown(log, shutdown_type);
933 		}
934 		return;
935 	}
936 
937 	clear_bit(XFS_LI_FAILED, &lip->li_flags);
938 	tail_lsn = xfs_ail_delete_one(ailp, lip);
939 	xfs_ail_update_finish(ailp, tail_lsn);	/* drops the AIL lock */
940 }
941 
942 int
xfs_trans_ail_init(xfs_mount_t * mp)943 xfs_trans_ail_init(
944 	xfs_mount_t	*mp)
945 {
946 	struct xfs_ail	*ailp;
947 
948 	ailp = kzalloc_obj(struct xfs_ail, GFP_KERNEL | __GFP_RETRY_MAYFAIL);
949 	if (!ailp)
950 		return -ENOMEM;
951 
952 	ailp->ail_log = mp->m_log;
953 	INIT_LIST_HEAD(&ailp->ail_head);
954 	INIT_LIST_HEAD(&ailp->ail_cursors);
955 	spin_lock_init(&ailp->ail_lock);
956 	INIT_LIST_HEAD(&ailp->ail_buf_list);
957 	init_waitqueue_head(&ailp->ail_empty);
958 
959 	ailp->ail_task = kthread_run(xfsaild, ailp, "xfsaild/%s",
960 				mp->m_super->s_id);
961 	if (IS_ERR(ailp->ail_task))
962 		goto out_free_ailp;
963 
964 	mp->m_ail = ailp;
965 	return 0;
966 
967 out_free_ailp:
968 	kfree(ailp);
969 	return -ENOMEM;
970 }
971 
972 void
xfs_trans_ail_destroy(xfs_mount_t * mp)973 xfs_trans_ail_destroy(
974 	xfs_mount_t	*mp)
975 {
976 	struct xfs_ail	*ailp = mp->m_ail;
977 
978 	kthread_stop(ailp->ail_task);
979 	kfree(ailp);
980 }
981