Received: by 2002:a05:6a10:a0d1:0:0:0:0 with SMTP id j17csp2031866pxa; Mon, 3 Aug 2020 05:53:42 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxhGumnYllG943fVodv2ZUYWKzxM1xGvSVRBQQ0qN9zftNhfhwrJ+k3hBehzoBkxTHZUa6L X-Received: by 2002:a05:6402:1a46:: with SMTP id bf6mr15410786edb.284.1596459222377; Mon, 03 Aug 2020 05:53:42 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1596459222; cv=none; d=google.com; s=arc-20160816; b=PLr+xPA5vKphvS1qQp/ZayWTSDZgXFdng4ije+FNfRf97CkCF5GQDTa3sH/a/0n49j ylqnNYdURrPmlFErj0mB7dzPRjWRgOlYwMax4EhaUfIw5XdR0sCSj/oQ0kEOcBJAQKM4 DHf0uMnHlZ5Zj0IiWtfGIFoAxp4x04XiA2rcMnAKMgTt5hya3f5JTGy0wA+tR5TEJ1Ci +HnqITSLYlwCmRfYgQF2ShmPAVh03SGdXy8simY0OhRVvLCHNzN+oScCp+mMvWO9qo5d 8ZLUiqZ9x0e6h2SaXVZTiZrUFym2o6UFfBQpFLHBD+rR1jlbpl8WUX8jQcrF5pF+cDA4 mDRQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:message-id:references :in-reply-to:subject:cc:to:from:date:content-transfer-encoding :mime-version:dkim-signature; bh=jepPBJzpwNuriMTj33dYfuOkzUu353rrYsvD7FzsN1c=; b=jIXDd0If0ZJI6NAhoXo/GAHpnmMk/f9oAZ3fV0AC0wGbrpe8iGVKm1y0MwENBM1WbN EFFGKoD8hRjxc/ttBKrsjNPh7UXvxXIHy26ufJwH9rPIA0LzN/QNBXs3vf9Fbtwjb6JU 9vdMqWkmDAzWAD3Gd0pFTQApDg3QedPXN/QwWoLWP705Ruff6TplA7IfuUW5k4b/nX6U DXvZNyy1MH+nEU+tF6HbSPjW4vDp59Hyt+iE++iaw75r2WpctrZ9wrfIDZD5ZQK3WlCG 8wv/JsJHlG9dUw3n/cpSAHhhds52q9VKBLtcyNrwB2sj4quE4w/IDyBTHq7i+NfyUuUw /JmA== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@mg.codeaurora.org header.s=smtp header.b="onefh8/J"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id v13si10051126edr.516.2020.08.03.05.53.20; Mon, 03 Aug 2020 05:53:42 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=fail header.i=@mg.codeaurora.org header.s=smtp header.b="onefh8/J"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728640AbgHCMv5 (ORCPT + 99 others); Mon, 3 Aug 2020 08:51:57 -0400 Received: from mail29.static.mailgun.info ([104.130.122.29]:36355 "EHLO mail29.static.mailgun.info" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1729542AbgHCMv0 (ORCPT ); Mon, 3 Aug 2020 08:51:26 -0400 DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=mg.codeaurora.org; q=dns/txt; s=smtp; t=1596459077; h=Message-ID: References: In-Reply-To: Subject: Cc: To: From: Date: Content-Transfer-Encoding: Content-Type: MIME-Version: Sender; bh=jepPBJzpwNuriMTj33dYfuOkzUu353rrYsvD7FzsN1c=; b=onefh8/J05V1Fr7p1QxbPn+0PxBz6lLF2aQLcNuTM7CRNU0zlgNXHUtDDNcc7cB2MbjdLAfh eTVCdYeDFiWgOOHw0Cwa86G0jUQr5M7H3tYmO1JmBLfUSAYKxZ0w8mq/sfJi5cs++CZhEhWp ApKUKpe3jbVmBvcjLD9jGdyn8xQ= X-Mailgun-Sending-Ip: 104.130.122.29 X-Mailgun-Sid: WyI0MWYwYSIsICJsaW51eC1rZXJuZWxAdmdlci5rZXJuZWwub3JnIiwgImJlOWU0YSJd Received: from smtp.codeaurora.org (ec2-35-166-182-171.us-west-2.compute.amazonaws.com [35.166.182.171]) by smtp-out-n12.prod.us-west-2.postgun.com with SMTP id 5f28083a849144fbcbb7ff4d (version=TLS1.2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256); Mon, 03 Aug 2020 12:51:06 GMT Received: by smtp.codeaurora.org (Postfix, from userid 1001) id 4DF52C433A1; Mon, 3 Aug 2020 12:51:05 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-caf-mail-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.0 required=2.0 tests=ALL_TRUSTED autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.codeaurora.org (localhost.localdomain [127.0.0.1]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: cang) by smtp.codeaurora.org (Postfix) with ESMTPSA id F0205C433C6; Mon, 3 Aug 2020 12:51:03 +0000 (UTC) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit Date: Mon, 03 Aug 2020 20:51:03 +0800 From: Can Guo To: Stanley Chu Cc: linux-scsi@vger.kernel.org, martin.petersen@oracle.com, avri.altman@wdc.com, alim.akhtar@samsung.com, jejb@linux.ibm.com, bvanassche@acm.org, beanhuo@micron.com, asutoshd@codeaurora.org, matthias.bgg@gmail.com, linux-mediatek@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, kuohong.wang@mediatek.com, peter.wang@mediatek.com, chun-hung.wu@mediatek.com, andy.teng@mediatek.com, chaotian.jing@mediatek.com, cc.chou@mediatek.com, jiajie.hao@mediatek.com Subject: Re: [PATCH v7] scsi: ufs: Quiesce all scsi devices before shutdown In-Reply-To: <20200803100448.2738-1-stanley.chu@mediatek.com> References: <20200803100448.2738-1-stanley.chu@mediatek.com> Message-ID: <70222bbb82a8b167475189110cf69317@codeaurora.org> X-Sender: cang@codeaurora.org User-Agent: Roundcube Webmail/1.3.9 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi Stanley, Sorry for the noises, please ignore my previous 2 mails and let's focus on this one. On 2020-08-03 18:04, Stanley Chu wrote: > Currently I/O request could be still submitted to UFS device while > UFS is working on shutdown flow. This may lead to racing as below > scenarios and finally system may crash due to unclocked register > accesses. > > To fix this kind of issues, in ufshcd_shutdown(), > > 1. Use pm_runtime_get_sync() instead of resuming UFS device by > ufshcd_runtime_resume() "internally" to let runtime PM framework > manage and prevent concurrent runtime operations by incoming I/O > requests. > > 2. Specifically quiesce all SCSI devices to block all I/O requests > after device is resumed. > > Example of racing scenario: While UFS device is runtime-suspended > > Thread #1: Executing UFS shutdown flow, e.g., > ufshcd_suspend(UFS_SHUTDOWN_PM) > > Thread #2: Executing runtime resume flow triggered by I/O request, > e.g., ufshcd_resume(UFS_RUNTIME_PM) > > This breaks the assumption that UFS PM flows can not be running > concurrently and some unexpected racing behavior may happen. > > Signed-off-by: Stanley Chu > --- > Changes: > - Since v6: > - Do quiesce to all SCSI devices. > - Since v4: > - Use pm_runtime_get_sync() instead of resuming UFS device by > ufshcd_runtime_resume() "internally". > --- > drivers/scsi/ufs/ufshcd.c | 27 ++++++++++++++++++++++----- > 1 file changed, 22 insertions(+), 5 deletions(-) > > diff --git a/drivers/scsi/ufs/ufshcd.c b/drivers/scsi/ufs/ufshcd.c > index 307622284239..7cb220b3fde0 100644 > --- a/drivers/scsi/ufs/ufshcd.c > +++ b/drivers/scsi/ufs/ufshcd.c > @@ -8640,6 +8640,7 @@ EXPORT_SYMBOL(ufshcd_runtime_idle); > int ufshcd_shutdown(struct ufs_hba *hba) > { > int ret = 0; > + struct scsi_target *starget; > > if (!hba->is_powered) > goto out; > @@ -8647,11 +8648,27 @@ int ufshcd_shutdown(struct ufs_hba *hba) > if (ufshcd_is_ufs_dev_poweroff(hba) && ufshcd_is_link_off(hba)) > goto out; > > - if (pm_runtime_suspended(hba->dev)) { > - ret = ufshcd_runtime_resume(hba); > - if (ret) > - goto out; > - } > + /* > + * Let runtime PM framework manage and prevent concurrent runtime > + * operations with shutdown flow. > + */ > + pm_runtime_get_sync(hba->dev); > + > + /* > + * Quiesce all SCSI devices to prevent any non-PM requests sending > + * from block layer during and after shutdown. > + * > + * Here we can not use blk_cleanup_queue() since PM requests > + * (with BLK_MQ_REQ_PREEMPT flag) are still required to be sent > + * through block layer. Therefore SCSI command queued after the > + * scsi_target_quiesce() call returned will block until > + * blk_cleanup_queue() is called. > + * > + * Besides, scsi_target_"un"quiesce (e.g., scsi_target_resume) can > + * be ignored since shutdown is one-way flow. > + */ > + list_for_each_entry(starget, &hba->host->__targets, siblings) > + scsi_target_quiesce(starget); > Sorry for misleading you to scsi_target_quiesce(), maybe below is better. shost_for_each_device(sdev, hba->host) scsi_device_quiesce(sdev); We may need to discuss more about this quiesce part since I missed something. After we quiesce the scsi devices, only PM requests are allowed, but it is still not safe - PM requests can still pass through. How about only quiescing the UFS device well known scsi device but using freeze_queue to the other scsi devices? blk_mq_freeze_queue can eliminate the risk. shost_for_each_device(sdev, hba->host) { if (sdev == hba->sdev_ufs_device) scsi_device_quiesce(sdev); else blk_mq_freeze_queue(sdev->request_queue); } IF blk_mq_freeze_queue is not allowed to be used by LLD (I think we can use it as I recalled Bart used to use it in one of his changes to UFS scaling), we can use scsi_remove_device instead, it changes scsi device's state to SDEV_DEL and calls blk_cleanup_queue. We can also use scsi_autopm_get_device like below. It is to make sure no more PM requests sent to scsi devices (since PM requests are only sent during PM ops). shost_for_each_device(sdev, hba->host) { scsi_autopm_get_device(sdev); scsi_device_quiesce(sdev); } Please let me know which one do you prefer or if you have better ideas, thanks! Regards, Can Guo. > ret = ufshcd_suspend(hba, UFS_SHUTDOWN_PM); > out: