mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Mohamed Khalfella <mkhalfella@purestorage.com>
To: Sagi Grimberg <sagi@grimberg.me>
Cc: Justin Tee <justin.tee@broadcom.com>,
	Naresh Gottumukkala <nareshgottumukkala83@gmail.com>,
	Paul Ely <paul.ely@broadcom.com>,
	Chaitanya Kulkarni <kch@nvidia.com>,
	Christoph Hellwig <hch@lst.de>, Jens Axboe <axboe@kernel.dk>,
	Keith Busch <kbusch@kernel.org>,
	James Smart <jsmart833426@gmail.com>,
	Hannes Reinecke <hare@suse.de>,
	Randy Jennings <randyj@purestorage.com>,
	Dhaval Giani <dgiani@purestorage.com>,
	Aaron Dailey <adailey@purestorage.com>,
	linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH v5 10/16] nvme-tcp: Use CCR to recover controller that hits an error
Date: Fri, 4 Sep 2026 19:09:47 -0700	[thread overview]
Message-ID: <20260905020947.GG5552-mkhalfella@purestorage.com> (raw)
In-Reply-To: <20260904225236.GB5552-mkhalfella@purestorage.com>

On Fri 2026-09-04 15:52:39 -0700, Mohamed Khalfella wrote:
> On Sun 2026-08-23 04:03:18 +0300, Sagi Grimberg wrote:
> > 
> > 
> > On 12/07/2026 5:23, Mohamed Khalfella wrote:
> > > An alive nvme controller that hits an error now will move to FENCING
> > > state instead of RESETTING state. ctrl->fencing_work attempts CCR to
> > > terminate inflight IOs. Regardless of the success or failure of CCR
> > > operation the controller is transitioned to RESETTING state to continue
> > > error recovery process.
> > >
> > > Signed-off-by: Mohamed Khalfella <mkhalfella@purestorage.com>
> > > ---
> > >   drivers/nvme/host/tcp.c | 30 +++++++++++++++++++++++++++++-
> > >   1 file changed, 29 insertions(+), 1 deletion(-)
> > >
> > > diff --git a/drivers/nvme/host/tcp.c b/drivers/nvme/host/tcp.c
> > > index ba5c7b3e2a7c..a1711dd1d3c2 100644
> > > --- a/drivers/nvme/host/tcp.c
> > > +++ b/drivers/nvme/host/tcp.c
> > > @@ -161,6 +161,7 @@ struct nvme_tcp_ctrl {
> > >   	struct sockaddr_storage src_addr;
> > >   	struct nvme_ctrl	ctrl;
> > >   
> > > +	struct work_struct	fencing_work;
> > >   	struct work_struct	err_work;
> > >   	struct delayed_work	connect_work;
> > >   	struct nvme_tcp_request async_req;
> > > @@ -605,6 +606,12 @@ static void nvme_tcp_init_recv_ctx(struct nvme_tcp_queue *queue)
> > >   
> > >   static void nvme_tcp_error_recovery(struct nvme_ctrl *ctrl)
> > >   {
> > > +	if (nvme_change_ctrl_state(ctrl, NVME_CTRL_FENCING)) {
> > > +		dev_warn(ctrl->device, "starting controller fencing\n");
> > > +		queue_work(nvme_wq, &to_tcp_ctrl(ctrl)->fencing_work);
> > > +		return;
> > > +	}
> > > +
> > >   	if (!nvme_change_ctrl_state(ctrl, NVME_CTRL_RESETTING))
> > >   		return;
> > >   
> > > @@ -2494,12 +2501,29 @@ static void nvme_tcp_reconnect_ctrl_work(struct work_struct *work)
> > >   	nvme_tcp_reconnect_or_remove(ctrl, ret);
> > >   }
> > >   
> > > +static void nvme_tcp_fencing_work(struct work_struct *work)
> > > +{
> > > +	struct nvme_tcp_ctrl *tcp_ctrl = container_of(work,
> > > +			struct nvme_tcp_ctrl, fencing_work);
> > > +	struct nvme_ctrl *ctrl = &tcp_ctrl->ctrl;
> > > +	unsigned long rem;
> > > +
> > > +	rem = nvme_fence_ctrl(ctrl);
> > > +	if (rem)
> > > +		dev_info(ctrl->device, "CCR failed, starting error recovery\n");
> > > +
> > > +	nvme_change_ctrl_state(ctrl, NVME_CTRL_FENCED);
> > > +	if (nvme_change_ctrl_state(ctrl, NVME_CTRL_RESETTING))
> > > +		queue_work(nvme_reset_wq, &tcp_ctrl->err_work);
> > > +}
> > > +
> > >   static void nvme_tcp_error_recovery_work(struct work_struct *work)
> > >   {
> > >   	struct nvme_tcp_ctrl *tcp_ctrl = container_of(work,
> > >   				struct nvme_tcp_ctrl, err_work);
> > >   	struct nvme_ctrl *ctrl = &tcp_ctrl->ctrl;
> > >   
> > > +	flush_work(&to_tcp_ctrl(ctrl)->fencing_work);
> > 
> > Agree we shouldn't be here with fencing work running.
> 
> Right, nvme_tcp_fencing_work() above queus tcp_ctrl->err_work. This
> flush makes aure that fencing is 100% done before we proceed with
> resetting.
> 
> > 
> > >   	if (nvme_tcp_key_revoke_needed(ctrl))
> > >   		nvme_auth_revoke_tls_key(ctrl);
> > >   	nvme_stop_keep_alive(ctrl);
> > > @@ -2542,6 +2566,7 @@ static void nvme_reset_ctrl_work(struct work_struct *work)
> > >   		container_of(work, struct nvme_ctrl, reset_work);
> > >   	int ret;
> > >   
> > > +	flush_work(&to_tcp_ctrl(ctrl)->fencing_work);
> > 
> > Isn't it being called in nvme_stop_ctrl? - perhaps it should be called 
> > in ->stop_ctrl() callback.
> > 
> > Other than that, this looks reasonable to me.
> 
> This flush_work() is needed in case nvme_tcp_fencing_work() loses the
> race of transitioning the controller from FENCED to RESETTING. The
> moment we move to FENCED anything can reset the controller. For example,
> userspace can do that. If we lose the race then tcp_ctrl->err_work will
> not be queued. That means reset work needs to flush fencing_work.

Now I am thinking about it again, what you suggested makes more sense
for both fencing and fenced work. Both should be flushed ->stop_ctrl().
I will do that.

  reply	other threads:[~2026-09-05  2:09 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-12  2:23 [PATCH v5 00/16] TP8028 Rapid Path Failure Recovery Mohamed Khalfella
2026-07-12  2:23 ` [PATCH v5 01/16] nvmet: Rapid Path Failure Recovery set controller identify fields Mohamed Khalfella
2026-08-23  0:49   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 02/16] nvmet/debugfs: Export controller CIU and CIRN via debugfs Mohamed Khalfella
2026-08-23  0:50   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 03/16] nvmet: Implement CCR nvme command Mohamed Khalfella
2026-08-23  0:53   ` Sagi Grimberg
2026-09-04 23:17     ` Mohamed Khalfella
2026-07-12  2:23 ` [PATCH v5 04/16] nvmet: Implement CCR logpage Mohamed Khalfella
2026-08-23  0:53   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 05/16] nvmet: Send an AEN on CCR completion Mohamed Khalfella
2026-08-23  0:54   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 06/16] nvme: Rapid Path Failure Recovery read controller identify fields Mohamed Khalfella
2026-08-23  0:55   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 07/16] nvme: Introduce FENCING and FENCED controller states Mohamed Khalfella
2026-08-23  0:55   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 08/16] nvme: Implement cross-controller reset recovery Mohamed Khalfella
2026-07-13  7:04   ` Hannes Reinecke
2026-09-04 23:04     ` Mohamed Khalfella
2026-08-23  0:59   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 09/16] nvme: Implement cross-controller reset completion Mohamed Khalfella
2026-07-13  7:11   ` Hannes Reinecke
2026-09-04 22:29     ` Mohamed Khalfella
2026-08-23  1:01   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 10/16] nvme-tcp: Use CCR to recover controller that hits an error Mohamed Khalfella
2026-07-13  7:17   ` Hannes Reinecke
2026-09-04 23:01     ` Mohamed Khalfella
2026-08-23  1:03   ` Sagi Grimberg
2026-09-04 22:52     ` Mohamed Khalfella
2026-09-05  2:09       ` Mohamed Khalfella [this message]
2026-07-12  2:23 ` [PATCH v5 11/16] nvme-rdma: " Mohamed Khalfella
2026-07-13  7:18   ` Hannes Reinecke
2026-07-12  2:23 ` [PATCH v5 12/16] nvme-fc: Refactor IO error recovery Mohamed Khalfella
2026-07-13  7:29   ` Hannes Reinecke
2026-09-04 23:19     ` Mohamed Khalfella
2026-07-12  2:23 ` [PATCH v5 13/16] nvme-fc: Use CCR to recover controller that hits an error Mohamed Khalfella
2026-07-12  2:23 ` [PATCH v5 14/16] nvme-fc: Hold inflight requests while in FENCING state Mohamed Khalfella
2026-07-12  2:23 ` [PATCH v5 15/16] nvmet: Add support for CQT to nvme target Mohamed Khalfella
2026-07-13  7:35   ` Hannes Reinecke
2026-08-23  1:04   ` Sagi Grimberg
2026-07-12  2:23 ` [PATCH v5 16/16] nvme: Add support for CQT to nvme host Mohamed Khalfella
2026-07-13  7:36   ` Hannes Reinecke
2026-08-23  1:07   ` Sagi Grimberg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905020947.GG5552-mkhalfella@purestorage.com \
    --to=mkhalfella@purestorage.com \
    --cc=adailey@purestorage.com \
    --cc=axboe@kernel.dk \
    --cc=dgiani@purestorage.com \
    --cc=hare@suse.de \
    --cc=hch@lst.de \
    --cc=jsmart833426@gmail.com \
    --cc=justin.tee@broadcom.com \
    --cc=kbusch@kernel.org \
    --cc=kch@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=nareshgottumukkala83@gmail.com \
    --cc=paul.ely@broadcom.com \
    --cc=randyj@purestorage.com \
    --cc=sagi@grimberg.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®