From: netdev-bot+sashiko@kernel.org
To: dhowells@redhat.com
Cc: netdev@vger.kernel.org, marc.dionne@auristor.com,
kuba@kernel.org, davem@davemloft.net, edumazet@google.com,
pabeni@redhat.com, horms@kernel.org,
linux-afs@lists.infradead.org, linux-kernel@vger.kernel.org,
qotmddnjs@ajou.ac.kr, stable@vger.kernel.org
Subject: Re: [PATCH net v11 15/17] afs: Fix lack of setting call->server when doing FS.InlineBulkStatus
Date: Sun, 27 Sep 2026 14:59:56 +0000 [thread overview]
Message-ID: <179052119696.2160803.18135878260747693344@kernel.org> (raw)
In-Reply-To: <20260923133706.1496540-16-dhowells@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.
Critical: 0 · High: 0 · Medium: 1 · Low: 0
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [Medium] This patch adds `call->server = afs_use_server(op->server,
false, afs_server_trace_use_call)` in afs_make_op_call()…
--
afs: Fix lack of setting call->server when doing FS.InlineBulkStatus
This commit makes afs_make_op_call() take an active count on op->server
and store it in call->server. That stops afs_done_fs_inline_bulk_status()
from oopsing when the server doesn't support FS.InlineBulkStatus. The
function moves further down internal.h so it can use afs_use_server(), and
a new afs_server_trace_use_call trace value is added.
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260824091645.415423-1-dhowells%40redhat.com
> diff --git a/fs/afs/internal.h b/fs/afs/internal.h
> index 330654ed16ece..40dc85d9a5c95 100644
> --- a/fs/afs/internal.h
> +++ b/fs/afs/internal.h
[ ... ]
> @@ -1771,6 +1755,23 @@ static inline struct inode *AFS_VNODE_TO_I(struct afs_vnode *vnode)
> return &vnode->netfs.inode;
> }
>
> +static inline void afs_make_op_call(struct afs_operation *op, struct afs_call *call,
> + gfp_t gfp)
> +{
> + struct afs_addr_list *alist = op->estate->addresses;
> +
> + op->call = afs_get_call(call, afs_call_trace_get);
> + op->type = call->type;
> + call->op = op;
> + call->server = afs_use_server(op->server, false, afs_server_trace_use_call);
[Severity: Medium]
Can this leave a server record that is no longer used with no GC timer
armed?
With this change, every op call holds an active count on op->server.
afs_free_call() drops it with the _notime variant:
fs/afs/rxrpc.c:afs_free_call() {
...
afs_unuse_server_notime(call->net, call->server, afs_server_trace_unuse_call);
...
}
When active reaches zero on a server that hasn't expired, in a cell that is
still live, afs_unuse_server_notime() does nothing:
fs/afs/server.c:afs_unuse_server_notime() {
...
if (atomic_dec_and_test(&server->active)) {
if (test_bit(AFS_SERVER_FL_EXPIRED, &server->flags) ||
READ_ONCE(server->cell->state) >= AFS_CELL_REMOVING)
schedule_work(&server->destroyer);
}
...
}
Only afs_unuse_server() sets unuse_time and calls afs_set_server_timer()
when active reaches zero. Before this patch, op calls didn't pin the
server, so the last active count was always dropped by the server list's
afs_unuse_server().
In the async read path, the call can outlive the op's server list:
afs_fetch_data_async_rx()
afs_read_receive()
afs_put_call(call) <- drops the op's ref
afs_select_fileserver(op) <- may afs_put_serverlist() the old list
or
afs_end_read()->afs_put_operation()->afs_put_serverlist()
afs_put_call(call) <- work item's ref, reaches afs_free_call()
Suppose the volume's server list is replaced while the read is in flight,
for example after a VLDB update or a VMOVED abort, and server X is in no
other list. The old list's afs_unuse_server() takes active from 2 to 1,
which doesn't arm the timer. The call's afs_unuse_server_notime() then
takes it from 1 to 0, which does nothing.
Would server X then stay in cell->fs_servers and on the probe lists? It
would keep being probed and its callbacks would not be given up, until
afs_purge_servers() runs at cell removal or the server is looked up again.
The periodic afs_fs_get_capabilities() probes also unuse with the _notime
variant, so they wouldn't re-arm GC either.
Probe and CM calls already have the same _notime behaviour. This change
extends it to every FS operation call, including async calls that often
outlive their op.
Could op calls be released with afs_unuse_server() instead? Another option
is for afs_unuse_server_notime() to set unuse_time and arm the timer when
active reaches zero on a live server.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260923133706.1496540-1-dhowells%40redhat.com
next prev parent reply other threads:[~2026-09-27 14:59 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 13:36 [PATCH net v11 00/17] rxrpc: Miscellaneous fixes David Howells
2026-09-23 13:36 ` [PATCH net v11 01/17] rxrpc: Revert "rxrpc: rxperf: Fix missing decoding of terminal magic cookie" David Howells
2026-09-23 13:36 ` [PATCH net v11 02/17] rxrpc: Fix rxperf test rxgk key kvno to be 0 David Howells
2026-09-23 13:36 ` [PATCH net v11 03/17] rxrpc: Fix update of call->tx_pending without holding lock David Howells
2026-09-23 13:36 ` [PATCH net v11 04/17] rxrpc: Fix lack of short-send handling in rxrpc_kernel_send_data() David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:36 ` [PATCH net v11 05/17] afs: Fix afs to abort the rxrpc call on send error David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:36 ` [PATCH net v11 06/17] rxrpc: Fix aborting in rxperf test server David Howells
2026-09-23 13:36 ` [PATCH net v11 07/17] rxrpc: Fix sendmsg length David Howells
2026-09-23 13:36 ` [PATCH net v11 08/17] rxrpc: Fix error handling in rxrpc_send_data() David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:36 ` [PATCH net v11 09/17] rxrpc: Fix packet encryption error handling David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:36 ` [PATCH net v11 10/17] rxrpc: Fix return in rxrpc_recvmsg_data() for service calls David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:36 ` [PATCH net v11 11/17] rxrpc: Fix double IRQ enablement David Howells
2026-09-23 13:36 ` [PATCH net v11 12/17] rxrpc: Fix generation of notifications after call completion David Howells
2026-09-23 13:37 ` [PATCH net v11 13/17] rxrpc: Fix RxGK key parser to check enctype is supported David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-23 13:37 ` [PATCH net v11 14/17] afs: Fix creation of RxGK CM channel token to have right size David Howells
2026-09-23 13:37 ` [PATCH net v11 15/17] afs: Fix lack of setting call->server when doing FS.InlineBulkStatus David Howells
2026-09-27 14:59 ` netdev-bot+sashiko [this message]
2026-09-23 13:37 ` [PATCH net v11 16/17] afs: Fix uncleared op->call pointer David Howells
2026-09-23 13:37 ` [PATCH net v11 17/17] rxrpc: fix use-after-free in rxrpc_poke_conn() David Howells
2026-09-27 14:59 ` netdev-bot+sashiko
2026-09-24 8:45 ` [PATCH net v11 10/17] rxrpc: Fix return in rxrpc_recvmsg_data() for service calls David Howells
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179052119696.2160803.18135878260747693344@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=davem@davemloft.net \
--cc=dhowells@redhat.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-afs@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marc.dionne@auristor.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=qotmddnjs@ajou.ac.kr \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®