Re: [PATCH v14 13/21] xfs: use read ioend for fsverity data verification

"Darrick J. Wong" <[email protected]>
Newsgroups dev.linux.lists.fsverity,net.sourceforge.lists.linux-f2fs-devel,org.kernel.vger.linux-btrfs,org.kernel.vger.linux-ext4,org.kernel.vger.linux-fsdevel,org.kernel.vger.linux-xfs
Message-ID <20260811162906.GC3556460@frogsfrogsfrogs>
On Tue, Aug 11, 2026 at 10:18:05AM +0200, Andrey Albershteyn wrote:
> > > > "If we have fsverity and block device integrity attached to this bio,
> > > > we need to run both validations from the separate fsverity workqueue
> > > > to avoid deadlocking due to fsverity issuing its own reads."
> > > > 
> > > > (Assuming I understand the fsverity && pi case correctly.)
> > > > 
> > > > One thing I'm not clear about -- why is it safe to do the fsverity
> > > > validation here if PI isn't enabled?  Can't that also issue IO to pull
> > > > in merkle tree blocks?
> > > 
> > > Without PI, fsverity metadata is read without XFS bio completion
> > > path, we don't get here for the descriptor/metadata reads
> > > (see xfs_get_iomap_read_ops()). So, we won't block the queue, as
> > > data ioends won't be mixed with metadata ioends.
> > > 
> > > With PI, all fsverity reads goes through this path. We could get a
> > > case that data ioend is waiting for metadata IO to be completed which
> > > in turn is pending for data ioend to be finished (due to batch
> > > processing of multiple BIOs in the bio_complete wq).
> > > 
> > > So, this will issue more IO, but this IO will not get onto this
> > > queue (it will go through iomap_bio_submit_read()).
> > 
> > Ah, ok.  Maybe add to that comment:
> > 
> > "If we have fsverity enabled but block device integrity is not enabled,
> > completion of the fsverity metadata reads does not require a workqueue
> > so there is no deadlock potential."
> > 
> > then?
> > 
> > (Just echoing you to make sure I understand completely.)
> > 
> 
> yes,
> 
> I've changed it to:
> 
> +       /*
> +        * If we have fsverity and block device integrity attached to this bio,
> +        * we need to run fsverity verification of data folios from a separate
> +        * fsverity workqueue. This is necessary to avoid deadlocking due to
> +        * fsverity issuing more reads of fsverity metadata which would be
> +        * processed by the same worker in the BIO completion workqueue.
> +        *
> +        * Without device integrity, fsverity metadata IO will not use ioends for

I would like to nitpick this to "Without block device integrity..." but
otherwise this comment looks good to me :)

With that fixed,
Reviewed-by: "Darrick J. Wong" <[email protected]>

--D

> +        * completion.
> +        */
> 
> 
> -- 
> - Andrey
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.