Darrick J. Wong
e3b7b58b0a
BACKPORT: fuse: fix livelock in synchronous file put from fuseblk workers
...
[ Upstream commit 26e5c67deb2e1f42a951f022fdf5b9f7eb747b01 ]
I observed a hang when running generic/323 against a fuseblk server.
This test opens a file, initiates a lot of AIO writes to that file
descriptor, and closes the file descriptor before the writes complete.
Unsurprisingly, the AIO exerciser threads are mostly stuck waiting for
responses from the fuseblk server:
[<0>] request_wait_answer+0x1fe/0x2a0 [fuse]
[<0>] __fuse_simple_request+0xd3/0x2b0 [fuse]
[<0>] fuse_do_getattr+0xfc/0x1f0 [fuse]
[<0>] fuse_file_read_iter+0xbe/0x1c0 [fuse]
[<0>] aio_read+0x130/0x1e0
[<0>] io_submit_one+0x542/0x860
[<0>] __x64_sys_io_submit+0x98/0x1a0
[<0>] do_syscall_64+0x37/0xf0
[<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53
But the /weird/ part is that the fuseblk server threads are waiting for
responses from itself:
[<0>] request_wait_answer+0x1fe/0x2a0 [fuse]
[<0>] __fuse_simple_request+0xd3/0x2b0 [fuse]
[<0>] fuse_file_put+0x9a/0xd0 [fuse]
[<0>] fuse_release+0x36/0x50 [fuse]
[<0>] __fput+0xec/0x2b0
[<0>] task_work_run+0x55/0x90
[<0>] syscall_exit_to_user_mode+0xe9/0x100
[<0>] do_syscall_64+0x43/0xf0
[<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53
The fuseblk server is fuse2fs so there's nothing all that exciting in
the server itself. So why is the fuse server calling fuse_file_put?
The commit message for the fstest sheds some light on that:
"By closing the file descriptor before calling io_destroy, you pretty
much guarantee that the last put on the ioctx will be done in interrupt
context (during I/O completion).
Aha. AIO fgets a new struct file from the fd when it queues the ioctx.
The completion of the FUSE_WRITE command from userspace causes the fuse
server to call the AIO completion function. The completion puts the
struct file, queuing a delayed fput to the fuse server task. When the
fuse server task returns to userspace, it has to run the delayed fput,
which in the case of a fuseblk server, it does synchronously.
Sending the FUSE_RELEASE command sychronously from fuse server threads
is a bad idea because a client program can initiate enough simultaneous
AIOs such that all the fuse server threads end up in delayed_fput, and
now there aren't any threads left to handle the queued fuse commands.
Fix this by only using asynchronous fputs when closing files, and leave
a comment explaining why.
Change-Id: I78be67f615f1318447e2fdad9ebfb34e60857b95
Cc: stable@vger.kernel.org # v2.6.38
Fixes: 5a18ec176c ("fuse: fix hang of single threaded fuseblk filesystem")
Signed-off-by: Darrick J. Wong <djwong@kernel.org>
Signed-off-by: Miklos Szeredi <mszeredi@redhat.com>
[ added isdir parameter to fuse_file_put() call ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-05-08 21:46:20 +02:00
..
9p
UPSTREAM: new helper: inode_wrong_type()
2026-05-08 21:46:14 +02:00
adfs
affs
affs: don't write overlarge OFS data block size fields
2025-04-10 14:29:42 +02:00
afs
BACKPORT: bdi: initialize ->ra_pages and ->io_pages in bdi_init
2026-05-08 21:46:13 +02:00
autofs
befs
bfs
btrfs
BACKPORT: compat_ioctl: move more drivers to compat_ptr_ioctl
2026-05-08 21:46:20 +02:00
cachefiles
cachefiles: fix memory leak in cachefiles_add_cache()
2024-03-06 14:36:10 +00:00
ceph
This is the 5.4.302 stable release
2025-12-03 14:36:44 +00:00
cifs
UPSTREAM: new helper: inode_wrong_type()
2026-05-08 21:46:14 +02:00
coda
configfs
configfs: Do not override creating attribute file failure in populate_attrs()
2025-06-27 11:02:50 +01:00
cramfs
cramfs: Verify inode mode when loading from disk
2025-10-29 13:59:55 +01:00
crypto
debugfs
devpts
dlm
dlm: check for defined force value in dlm_lockspace_release
2025-10-29 13:59:58 +01:00
ecryptfs
This is the 5.4.278 stable release
2024-06-18 14:18:49 +00:00
efivarfs
efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
2025-09-04 14:05:55 +02:00
efs
erofs
Merge tag 'ASB-2025-02-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-02-06 22:53:05 +02:00
exfat
Merge branch 'for-kernel-version-from-4.1.0' of https://github.com/namjaejeon/linux-exfat-oot into android13-5.4-lahaina
2024-04-16 00:03:08 +03:00
exportfs
ext2
ext4
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
f2fs
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:17:54 +03:00
fat
fat: fix uninitialized variable
2024-11-08 16:20:47 +01:00
freevxfs
fscache
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
fuse
BACKPORT: fuse: fix livelock in synchronous file put from fuseblk workers
2026-05-08 21:46:20 +02:00
gfs2
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
hfs
This is the 5.4.301 stable release
2025-10-30 07:52:10 +00:00
hfsplus
This is the 5.4.301 stable release
2025-10-30 07:52:10 +00:00
hostfs
hpfs
fs/hpfs: Fix error code for new_inode() failure in mkdir/create/mknod/symlink
2025-12-03 12:45:14 +01:00
hugetlbfs
mm/hugetlb: fix folio is still mapped when deleted
2025-10-02 13:34:35 +02:00
incfs
iomap
This is the 5.4.270 stable release
2024-03-05 14:53:04 +00:00
isofs
isofs: Verify inode mode when loading from disk
2025-08-28 16:21:15 +02:00
jbd2
jbd2: ensure that all ongoing I/O complete before freeing blocks
2025-10-29 14:00:01 +01:00
jffs2
This is the 5.4.295 stable release
2025-06-30 08:05:33 +00:00
jfs
This is the 5.4.302 stable release
2025-12-03 14:36:44 +00:00
kernfs
UPSTREAM: kernfs: Add option to enable user xattrs
2026-01-14 18:13:12 -08:00
lockd
minix
minixfs: Verify inode mode when loading from disk
2025-10-29 13:59:55 +01:00
nfs
UPSTREAM: new helper: inode_wrong_type()
2026-05-08 21:46:14 +02:00
nfs_common
nfsd
UPSTREAM: new helper: inode_wrong_type()
2026-05-08 21:46:14 +02:00
nilfs2
nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/*
2025-10-02 13:34:31 +02:00
nls
notify
BACKPORT: compat_ioctl: move more drivers to compat_ptr_ioctl
2026-05-08 21:46:20 +02:00
ntfs
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
ocfs2
This is the 5.4.301 stable release
2025-10-30 07:52:10 +00:00
omfs
openpromfs
openpromfs: finish conversion to the new mount API
2024-06-16 13:28:32 +02:00
orangefs
This is the 5.4.302 stable release
2025-12-03 14:36:44 +00:00
overlayfs
UPSTREAM: new helper: inode_wrong_type()
2026-05-08 21:46:14 +02:00
proc
FROMGIT: procfs: prevent unpriveleged processes accessing fdinfo dir
2026-05-07 10:19:32 -04:00
pstore
Merge tag 'ASB-2024-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-06-22 17:58:09 +03:00
qnx4
qnx6
quota
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
ramfs
reiserfs
romfs
squashfs
This is the 5.4.301 stable release
2025-10-30 07:52:10 +00:00
sysfs
This is the 5.4.275 stable release
2024-05-15 16:00:38 +00:00
sysv
sysv: don't call sb_bread() with pointers_lock held
2024-04-13 12:51:38 +02:00
tracefs
ubifs
BACKPORT: bdi: initialize ->ra_pages and ->io_pages in bdi_init
2026-05-08 21:46:13 +02:00
udf
fs: udf: fix OOB read in lengthAllocDescs handling
2025-10-29 13:59:54 +01:00
ufs
unicode
Revert "unicode: Don't special case ignorable code points"
2024-12-14 19:44:55 +01:00
verity
xfs
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
aio.c
BACKPORT: FROMLIST: Revert "mremap: don't allow MREMAP_DONTUNMAP on special_mappings and aio"
2025-05-18 08:08:42 +00:00
anon_inodes.c
UPSTREAM: fs: anon_inodes: rephrase to appropriate kernel-doc
2025-02-20 04:17:46 +02:00
attr.c
bad_inode.c
binfmt_aout.c
binfmt_elf.c
binfmt_elf_fdpic.c
fs: binfmt_elf_efpic: don't use missing interpreter's properties
2024-09-04 13:14:54 +02:00
binfmt_em86.c
binfmt_flat.c
binfmt_flat: Fix integer overflow bug on 32 bit systems
2025-03-13 12:43:07 +01:00
binfmt_misc.c
binfmt_misc: cleanup on filesystem umount
2024-09-04 13:14:53 +02:00
binfmt_script.c
block_dev.c
block: Don't invalidate pagecache for invalid falloc modes
2024-01-08 11:29:48 +01:00
buffer.c
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:17:54 +03:00
char_dev.c
compat.c
compat_binfmt_elf.c
compat_ioctl.c
lsm: new security_file_ioctl_compat() hook
2024-02-23 08:25:15 +01:00
coredump.c
Revert "coredump: hand a pidfd to the usermode coredump helper"
2025-06-05 07:57:32 +00:00
d_path.c
dax.c
dcache.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
dcookies.c
direct-io.c
drop_caches.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
eventfd.c
eventpoll.c
UPSTREAM: epoll: add syscall epoll_pwait2
2025-12-22 04:28:19 +02:00
exec.c
This is the 5.4.301 stable release
2025-10-30 07:52:10 +00:00
fcntl.c
fs: Fix file_set_fowner LSM hook inconsistencies
2024-11-08 16:20:34 +01:00
fhandle.c
do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak
2024-03-26 18:22:13 -04:00
file.c
UPSTREAM: fs: prevent out-of-bounds array speculation when closing a file descriptor
2026-01-18 00:27:36 -08:00
file_table.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
filesystems.c
fs/filesystems: Fix potential unsigned integer underflow in fs_name()
2025-06-27 11:02:50 +01:00
fs-writeback.c
fs/fs-writeback.c: adjust dirtytime_interval_handler definition to match prototype
2026-02-01 20:38:24 -08:00
fs_context.c
fs_parser.c
fs_pin.c
fs_struct.c
fs_types.c
fsopen.c
inode.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
internal.h
io_uring.c
This is the 5.4.278 stable release
2024-06-18 14:18:49 +00:00
ioctl.c
Kconfig
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-06-30 10:49:17 +03:00
Kconfig.binfmt
libfs.c
UPSTREAM: fs: add LSM-supporting anon-inode interface
2025-02-20 04:17:45 +02:00
locks.c
filelock: Correct the filelock owner in fcntl_setlk/fcntl_setlk64
2024-09-04 13:15:02 +02:00
Makefile
mbcache.c
mount.h
mpage.c
namei.c
This is the 5.4.292 stable release
2025-04-11 08:16:05 +00:00
namespace.c
UPSTREAM: fuse: reject options on reconfigure via fsconfig(2)
2026-05-08 21:46:11 +02:00
no-block.c
nsfs.c
UPSTREAM: fs/nsfs.c: Added ns_match
2025-12-23 13:36:04 -08:00
open.c
UPSTREAM: close_range: add CLOSE_RANGE_UNSHARE
2025-12-22 03:48:31 +02:00
OWNERS
pipe.c
pnode.c
pnode.h
posix_acl.c
proc_namespace.c
read_write.c
BACKPORT: vfs: add vfs_iocb_iter_[read|write] helper functions
2026-05-08 21:46:16 +02:00
readdir.c
select.c
fs/select: rework stack allocation hack for clang
2024-03-26 18:22:13 -04:00
seq_file.c
signalfd.c
splice.c
stack.c
stat.c
statfs.c
super.c
fs: explicitly unregister per-superblock BDIs
2024-11-08 16:20:26 +01:00
sync.c
This is the 5.4.263 stable release
2023-12-11 12:08:17 +00:00
timerfd.c
userfaultfd.c
BACKPORT: compat_ioctl: move more drivers to compat_ptr_ioctl
2026-05-08 21:46:20 +02:00
utimes.c
xattr.c
UPSTREAM: kernfs: Add removed_size out param for simple_xattr_set
2026-01-14 18:13:12 -08:00