mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Chao Yu <chao@kernel.org>
To: Daeho Jeong <daeho43@gmail.com>,
	linux-kernel@vger.kernel.org,
	linux-f2fs-devel@lists.sourceforge.net, kernel-team@android.com
Cc: chao@kernel.org, Daeho Jeong <daehojeong@google.com>
Subject: Re: [f2fs-dev] [PATCH] f2fs: cache: count the temporary pins apart from the regular references
Date: Fri, 9 Oct 2026 15:23:25 +0800	[thread overview]
Message-ID: <b55e3d43-589f-4d04-a7d3-4cc52aa66fc9@kernel.org> (raw)
In-Reply-To: <20261005192114.1511660-1-daeho43@gmail.com>

On 10/6/26 03:21, Daeho Jeong wrote:
> From: Daeho Jeong <daehojeong@google.com>
> 
> f2fs_unlock_cache() and f2fs_end_cache_writeback() take a temporary
> reference on the entry around clear_and_wake_up_bit(), so that the entry
> is not freed before wake_up_bit() returns. f2fs_destroy_cache() waits
> for the LOCKED and WRITEBACK bits and then expects the refcount to be 1,
> but the bit waits can return as soon as the bit is cleared, before the
> I/O completion drops the temporary reference. When the completion runs
> in process context and is preempted there (e.g. dm-flakey in
> generic/311), umount hits:
> 
>   kernel BUG at fs/f2fs/cache.c:567!
>   f2fs_destroy_cache+0x260/0x268
>   f2fs_put_super+0x1fc/0x428
> 
> Count the temporary references in units of F2FS_CACHE_PIN_BIAS, like
> GUP_PIN_COUNTING_BIAS for folios, and check only the regular references
> in f2fs_destroy_cache(). A leaked regular reference is still caught
> there, without waiting for the completion.
> 
> The pinned entry is freed by whichever of f2fs_cache_put() and
> f2fs_cache_unpin() drops the refcount to zero, as before. The shrinker
> still skips an entry while it is pinned, since the refcount is then
> neither 1 nor below 3.
> 
> Fixes: 6e392158cf54 ("f2fs: cache: pin cached block in f2fs_end_cache_writeback()")
> Fixes: 61ba87b33e87 ("f2fs: cache: pin cached block in f2fs_unlock_cache()")
> Signed-off-by: Daeho Jeong <daehojeong@google.com>
Reviewed-by: Chao Yu <chao@kernel.org>

Thanks,

      reply	other threads:[~2026-10-09  7:23 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 19:21 Daeho Jeong
2026-10-09  7:23 ` Chao Yu [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b55e3d43-589f-4d04-a7d3-4cc52aa66fc9@kernel.org \
    --to=chao@kernel.org \
    --cc=daeho43@gmail.com \
    --cc=daehojeong@google.com \
    --cc=kernel-team@android.com \
    --cc=linux-f2fs-devel@lists.sourceforge.net \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®