From: Tejun Heo <tj@kernel.org>
To: Liz Fong-Jones <lizf@honeycomb.io>
Cc: Christian Brauner <brauner@kernel.org>, Jan Kara <jack@suse.cz>,
Alexander Viro <viro@zeniv.linux.org.uk>,
Jens Axboe <axboe@kernel.dk>,
Andrew Morton <akpm@linux-foundation.org>,
Johannes Weiner <hannes@cmpxchg.org>,
Roman Gushchin <roman.gushchin@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Xin Yin <yinxin.x@bytedance.com>,
linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
cgroups@vger.kernel.org, linux-kernel@vger.kernel.org,
ian@honeycomb.io
Subject: Re: [PATCH v3 1/2] writeback: let foreign flushes reach dying cgwbs
Date: Tue, 29 Sep 2026 07:58:56 -1000 [thread overview]
Message-ID: <d594ecb783f0f6838a52099fdba3de8e@kernel.org> (raw)
In-Reply-To: <20260928-wb-dying-cgwb-flush-v3-1-e35374884667@honeycomb.io>
Hello, Liz.
On Tue, Sep 29, 2026 at 01:40:49AM +0000, Liz Fong-Jones wrote:
> if (test_bit(WB_registered, &bdi->wb.state) &&
> blkcg_cgwb_list->next && memcg_cgwb_list->next) {
> - /* we might have raced another instance of this function */
> - ret = radix_tree_insert(&bdi->cgwb_tree, memcg_css->id, wb);
> + /*
> + * We might have raced another instance of this function. A
> + * dying wb keeps its slot until released; take it over.
> + */
> + slot = radix_tree_lookup_slot(&bdi->cgwb_tree, memcg_css->id);
> + if (!slot) {
> + ret = radix_tree_insert(&bdi->cgwb_tree, memcg_css->id, wb);
> + } else {
> + old_wb = radix_tree_deref_slot_protected(slot, &cgwb_lock);
> + if (wb_dying(old_wb)) {
> + radix_tree_replace_slot(&bdi->cgwb_tree, slot, wb);
This can also replace the wb of a removed memcg:
1. A cgroup with io enabled is removed. Killing its io css makes
cgroup_get_e_css() return the parent's right away, but
memcg_cgwb_list->next stays set until wb_memcg_offline().
2. In between, wb_get_create() for the memcg, e.g. from
__inode_attach_wb() or inode_switch_wbs(), kills the dirty wb on
blkcg mismatch and a new wb takes over its slot.
3. wb_memcg_offline() kills the new wb. Foreign flushes for the memcg
now find the new wb while the dirty inodes stay on the old one, as
css_is_dying() keeps wbc_attach_and_unlock_inode() from switching
them, so the stall comes back.
Can you also fail the link when the memcg is dying?
if (test_bit(WB_registered, &bdi->wb.state) &&
blkcg_cgwb_list->next && memcg_cgwb_list->next &&
!css_is_dying(memcg_css)) {
CSS_DYING is set before the io css is killed. Testing it here, after
the blkcg lookup and under cgwb_lock, catches every removal that could
have made the old wb replaceable.
Thanks.
--
tejun
next prev parent reply other threads:[~2026-09-29 17:58 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 1:40 [PATCH v3 0/2] " Liz Fong-Jones
2026-09-29 1:40 ` [PATCH v3 1/2] " Liz Fong-Jones
2026-09-29 17:58 ` Tejun Heo [this message]
2026-09-29 1:40 ` [PATCH v3 2/2] writeback: kick writeback on a cgwb replaced in cgwb_create() Liz Fong-Jones
2026-09-29 19:32 ` [PATCH v3 0/2] writeback: let foreign flushes reach dying cgwbs Tejun Heo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d594ecb783f0f6838a52099fdba3de8e@kernel.org \
--to=tj@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=axboe@kernel.dk \
--cc=brauner@kernel.org \
--cc=cgroups@vger.kernel.org \
--cc=hannes@cmpxchg.org \
--cc=ian@honeycomb.io \
--cc=jack@suse.cz \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=lizf@honeycomb.io \
--cc=roman.gushchin@linux.dev \
--cc=shakeel.butt@linux.dev \
--cc=viro@zeniv.linux.org.uk \
--cc=yinxin.x@bytedance.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®