Re: [PATCH v3 4/5] ceph: move mdsc->mutex into __do_request()

Xiubo Li <[email protected]>
Newsgroups org.kernel.vger.ceph-devel
Message-ID <CAOJNxRJkJoSi-8FfV-o69ccCxMP+s=+ZwA42W_LX696CUZAK5Q@mail.gmail.com>
Hi Alex,

Thanks for pointing this out. Yeah you are right. Let me fix it.

- Xiubo Li

On Tue, 11 Aug 2026 at 06:43, Alex Markuze <[email protected]> wrote:
>
> Hi Xiubo,
>
> Two issues with this patch:
>
> 1) kick_requests() list corruption
>
>    Requests are collected onto a local kick_list via r_wait, then
>    __do_request() is called for each entry. If __do_request() puts the
>    request back on waiting_for_map or s_waiting (no mdsmap, session not
>    open yet), it does list_add(&req->r_wait, ...) while r_wait is still
>    linked on kick_list. The subsequent list_del_init(&req->r_wait) in the
>    kick loop then removes from the wait list instead of kick_list,
>    corrupting the wait list and orphaning the request.
>
>    Moving the list_del_init(&req->r_wait) before the __do_request() call
>    should fix it.
>
> 2) Double dispatch window via r_attempts
>
>    __do_request() publishes r_session and drops the mutex before
>    __prepare_send_request() increments r_attempts (which happens inside
>    __send_request). A concurrent kick_requests() can see r_attempts == 0
>    during that window and collect the same request for a second dispatch.
>
>    Bumping r_attempts or setting a dispatch-in-progress flag under the
>    mutex before entering the unlocked send path would close this.
>
> --
> Alex Markuze
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.