io_uring: remove the need for relying on an io-wq fallback worker
[linux-2.6-microblaze.git] / fs / io-wq.c
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * Basic worker thread pool for io_uring
4  *
5  * Copyright (C) 2019 Jens Axboe
6  *
7  */
8 #include <linux/kernel.h>
9 #include <linux/init.h>
10 #include <linux/errno.h>
11 #include <linux/sched/signal.h>
12 #include <linux/mm.h>
13 #include <linux/sched/mm.h>
14 #include <linux/percpu.h>
15 #include <linux/slab.h>
16 #include <linux/kthread.h>
17 #include <linux/rculist_nulls.h>
18 #include <linux/fs_struct.h>
19 #include <linux/blk-cgroup.h>
20 #include <linux/audit.h>
21 #include <linux/cpu.h>
22
23 #include "../kernel/sched/sched.h"
24 #include "io-wq.h"
25
26 #define WORKER_IDLE_TIMEOUT     (5 * HZ)
27
28 enum {
29         IO_WORKER_F_UP          = 1,    /* up and active */
30         IO_WORKER_F_RUNNING     = 2,    /* account as running */
31         IO_WORKER_F_FREE        = 4,    /* worker on free list */
32         IO_WORKER_F_FIXED       = 8,    /* static idle worker */
33         IO_WORKER_F_BOUND       = 16,   /* is doing bounded work */
34 };
35
36 enum {
37         IO_WQ_BIT_EXIT          = 0,    /* wq exiting */
38         IO_WQ_BIT_ERROR         = 1,    /* error on setup */
39 };
40
41 enum {
42         IO_WQE_FLAG_STALLED     = 1,    /* stalled on hash */
43 };
44
45 /*
46  * One for each thread in a wqe pool
47  */
48 struct io_worker {
49         refcount_t ref;
50         unsigned flags;
51         struct hlist_nulls_node nulls_node;
52         struct list_head all_list;
53         struct task_struct *task;
54         struct io_wqe *wqe;
55
56         struct io_wq_work *cur_work;
57         spinlock_t lock;
58
59         struct rcu_head rcu;
60         struct mm_struct *mm;
61 #ifdef CONFIG_BLK_CGROUP
62         struct cgroup_subsys_state *blkcg_css;
63 #endif
64         const struct cred *cur_creds;
65         const struct cred *saved_creds;
66         struct nsproxy *restore_nsproxy;
67 };
68
69 #if BITS_PER_LONG == 64
70 #define IO_WQ_HASH_ORDER        6
71 #else
72 #define IO_WQ_HASH_ORDER        5
73 #endif
74
75 #define IO_WQ_NR_HASH_BUCKETS   (1u << IO_WQ_HASH_ORDER)
76
77 struct io_wqe_acct {
78         unsigned nr_workers;
79         unsigned max_workers;
80         atomic_t nr_running;
81 };
82
83 enum {
84         IO_WQ_ACCT_BOUND,
85         IO_WQ_ACCT_UNBOUND,
86 };
87
88 /*
89  * Per-node worker thread pool
90  */
91 struct io_wqe {
92         struct {
93                 raw_spinlock_t lock;
94                 struct io_wq_work_list work_list;
95                 unsigned long hash_map;
96                 unsigned flags;
97         } ____cacheline_aligned_in_smp;
98
99         int node;
100         struct io_wqe_acct acct[2];
101
102         struct hlist_nulls_head free_list;
103         struct list_head all_list;
104
105         struct io_wq *wq;
106         struct io_wq_work *hash_tail[IO_WQ_NR_HASH_BUCKETS];
107 };
108
109 /*
110  * Per io_wq state
111   */
112 struct io_wq {
113         struct io_wqe **wqes;
114         unsigned long state;
115
116         free_work_fn *free_work;
117         io_wq_work_fn *do_work;
118
119         struct task_struct *manager;
120         struct user_struct *user;
121         refcount_t refs;
122         struct completion done;
123
124         struct hlist_node cpuhp_node;
125
126         refcount_t use_refs;
127 };
128
129 static enum cpuhp_state io_wq_online;
130
131 static bool io_worker_get(struct io_worker *worker)
132 {
133         return refcount_inc_not_zero(&worker->ref);
134 }
135
136 static void io_worker_release(struct io_worker *worker)
137 {
138         if (refcount_dec_and_test(&worker->ref))
139                 wake_up_process(worker->task);
140 }
141
142 /*
143  * Note: drops the wqe->lock if returning true! The caller must re-acquire
144  * the lock in that case. Some callers need to restart handling if this
145  * happens, so we can't just re-acquire the lock on behalf of the caller.
146  */
147 static bool __io_worker_unuse(struct io_wqe *wqe, struct io_worker *worker)
148 {
149         bool dropped_lock = false;
150
151         if (worker->saved_creds) {
152                 revert_creds(worker->saved_creds);
153                 worker->cur_creds = worker->saved_creds = NULL;
154         }
155
156         if (current->files) {
157                 __acquire(&wqe->lock);
158                 raw_spin_unlock_irq(&wqe->lock);
159                 dropped_lock = true;
160
161                 task_lock(current);
162                 current->files = NULL;
163                 current->nsproxy = worker->restore_nsproxy;
164                 task_unlock(current);
165         }
166
167         if (current->fs)
168                 current->fs = NULL;
169
170         /*
171          * If we have an active mm, we need to drop the wq lock before unusing
172          * it. If we do, return true and let the caller retry the idle loop.
173          */
174         if (worker->mm) {
175                 if (!dropped_lock) {
176                         __acquire(&wqe->lock);
177                         raw_spin_unlock_irq(&wqe->lock);
178                         dropped_lock = true;
179                 }
180                 __set_current_state(TASK_RUNNING);
181                 kthread_unuse_mm(worker->mm);
182                 mmput(worker->mm);
183                 worker->mm = NULL;
184         }
185
186 #ifdef CONFIG_BLK_CGROUP
187         if (worker->blkcg_css) {
188                 kthread_associate_blkcg(NULL);
189                 worker->blkcg_css = NULL;
190         }
191 #endif
192         if (current->signal->rlim[RLIMIT_FSIZE].rlim_cur != RLIM_INFINITY)
193                 current->signal->rlim[RLIMIT_FSIZE].rlim_cur = RLIM_INFINITY;
194         return dropped_lock;
195 }
196
197 static inline struct io_wqe_acct *io_work_get_acct(struct io_wqe *wqe,
198                                                    struct io_wq_work *work)
199 {
200         if (work->flags & IO_WQ_WORK_UNBOUND)
201                 return &wqe->acct[IO_WQ_ACCT_UNBOUND];
202
203         return &wqe->acct[IO_WQ_ACCT_BOUND];
204 }
205
206 static inline struct io_wqe_acct *io_wqe_get_acct(struct io_wqe *wqe,
207                                                   struct io_worker *worker)
208 {
209         if (worker->flags & IO_WORKER_F_BOUND)
210                 return &wqe->acct[IO_WQ_ACCT_BOUND];
211
212         return &wqe->acct[IO_WQ_ACCT_UNBOUND];
213 }
214
215 static void io_worker_exit(struct io_worker *worker)
216 {
217         struct io_wqe *wqe = worker->wqe;
218         struct io_wqe_acct *acct = io_wqe_get_acct(wqe, worker);
219
220         /*
221          * If we're not at zero, someone else is holding a brief reference
222          * to the worker. Wait for that to go away.
223          */
224         set_current_state(TASK_INTERRUPTIBLE);
225         if (!refcount_dec_and_test(&worker->ref))
226                 schedule();
227         __set_current_state(TASK_RUNNING);
228
229         preempt_disable();
230         current->flags &= ~PF_IO_WORKER;
231         if (worker->flags & IO_WORKER_F_RUNNING)
232                 atomic_dec(&acct->nr_running);
233         if (!(worker->flags & IO_WORKER_F_BOUND))
234                 atomic_dec(&wqe->wq->user->processes);
235         worker->flags = 0;
236         preempt_enable();
237
238         raw_spin_lock_irq(&wqe->lock);
239         hlist_nulls_del_rcu(&worker->nulls_node);
240         list_del_rcu(&worker->all_list);
241         if (__io_worker_unuse(wqe, worker)) {
242                 __release(&wqe->lock);
243                 raw_spin_lock_irq(&wqe->lock);
244         }
245         acct->nr_workers--;
246         raw_spin_unlock_irq(&wqe->lock);
247
248         kfree_rcu(worker, rcu);
249         if (refcount_dec_and_test(&wqe->wq->refs))
250                 complete(&wqe->wq->done);
251 }
252
253 static inline bool io_wqe_run_queue(struct io_wqe *wqe)
254         __must_hold(wqe->lock)
255 {
256         if (!wq_list_empty(&wqe->work_list) &&
257             !(wqe->flags & IO_WQE_FLAG_STALLED))
258                 return true;
259         return false;
260 }
261
262 /*
263  * Check head of free list for an available worker. If one isn't available,
264  * caller must wake up the wq manager to create one.
265  */
266 static bool io_wqe_activate_free_worker(struct io_wqe *wqe)
267         __must_hold(RCU)
268 {
269         struct hlist_nulls_node *n;
270         struct io_worker *worker;
271
272         n = rcu_dereference(hlist_nulls_first_rcu(&wqe->free_list));
273         if (is_a_nulls(n))
274                 return false;
275
276         worker = hlist_nulls_entry(n, struct io_worker, nulls_node);
277         if (io_worker_get(worker)) {
278                 wake_up_process(worker->task);
279                 io_worker_release(worker);
280                 return true;
281         }
282
283         return false;
284 }
285
286 /*
287  * We need a worker. If we find a free one, we're good. If not, and we're
288  * below the max number of workers, wake up the manager to create one.
289  */
290 static void io_wqe_wake_worker(struct io_wqe *wqe, struct io_wqe_acct *acct)
291 {
292         bool ret;
293
294         /*
295          * Most likely an attempt to queue unbounded work on an io_wq that
296          * wasn't setup with any unbounded workers.
297          */
298         WARN_ON_ONCE(!acct->max_workers);
299
300         rcu_read_lock();
301         ret = io_wqe_activate_free_worker(wqe);
302         rcu_read_unlock();
303
304         if (!ret && acct->nr_workers < acct->max_workers)
305                 wake_up_process(wqe->wq->manager);
306 }
307
308 static void io_wqe_inc_running(struct io_wqe *wqe, struct io_worker *worker)
309 {
310         struct io_wqe_acct *acct = io_wqe_get_acct(wqe, worker);
311
312         atomic_inc(&acct->nr_running);
313 }
314
315 static void io_wqe_dec_running(struct io_wqe *wqe, struct io_worker *worker)
316         __must_hold(wqe->lock)
317 {
318         struct io_wqe_acct *acct = io_wqe_get_acct(wqe, worker);
319
320         if (atomic_dec_and_test(&acct->nr_running) && io_wqe_run_queue(wqe))
321                 io_wqe_wake_worker(wqe, acct);
322 }
323
324 static void io_worker_start(struct io_wqe *wqe, struct io_worker *worker)
325 {
326         allow_kernel_signal(SIGINT);
327
328         current->flags |= PF_IO_WORKER;
329         current->fs = NULL;
330         current->files = NULL;
331
332         worker->flags |= (IO_WORKER_F_UP | IO_WORKER_F_RUNNING);
333         worker->restore_nsproxy = current->nsproxy;
334         io_wqe_inc_running(wqe, worker);
335 }
336
337 /*
338  * Worker will start processing some work. Move it to the busy list, if
339  * it's currently on the freelist
340  */
341 static void __io_worker_busy(struct io_wqe *wqe, struct io_worker *worker,
342                              struct io_wq_work *work)
343         __must_hold(wqe->lock)
344 {
345         bool worker_bound, work_bound;
346
347         if (worker->flags & IO_WORKER_F_FREE) {
348                 worker->flags &= ~IO_WORKER_F_FREE;
349                 hlist_nulls_del_init_rcu(&worker->nulls_node);
350         }
351
352         /*
353          * If worker is moving from bound to unbound (or vice versa), then
354          * ensure we update the running accounting.
355          */
356         worker_bound = (worker->flags & IO_WORKER_F_BOUND) != 0;
357         work_bound = (work->flags & IO_WQ_WORK_UNBOUND) == 0;
358         if (worker_bound != work_bound) {
359                 io_wqe_dec_running(wqe, worker);
360                 if (work_bound) {
361                         worker->flags |= IO_WORKER_F_BOUND;
362                         wqe->acct[IO_WQ_ACCT_UNBOUND].nr_workers--;
363                         wqe->acct[IO_WQ_ACCT_BOUND].nr_workers++;
364                         atomic_dec(&wqe->wq->user->processes);
365                 } else {
366                         worker->flags &= ~IO_WORKER_F_BOUND;
367                         wqe->acct[IO_WQ_ACCT_UNBOUND].nr_workers++;
368                         wqe->acct[IO_WQ_ACCT_BOUND].nr_workers--;
369                         atomic_inc(&wqe->wq->user->processes);
370                 }
371                 io_wqe_inc_running(wqe, worker);
372          }
373 }
374
375 /*
376  * No work, worker going to sleep. Move to freelist, and unuse mm if we
377  * have one attached. Dropping the mm may potentially sleep, so we drop
378  * the lock in that case and return success. Since the caller has to
379  * retry the loop in that case (we changed task state), we don't regrab
380  * the lock if we return success.
381  */
382 static bool __io_worker_idle(struct io_wqe *wqe, struct io_worker *worker)
383         __must_hold(wqe->lock)
384 {
385         if (!(worker->flags & IO_WORKER_F_FREE)) {
386                 worker->flags |= IO_WORKER_F_FREE;
387                 hlist_nulls_add_head_rcu(&worker->nulls_node, &wqe->free_list);
388         }
389
390         return __io_worker_unuse(wqe, worker);
391 }
392
393 static inline unsigned int io_get_work_hash(struct io_wq_work *work)
394 {
395         return work->flags >> IO_WQ_HASH_SHIFT;
396 }
397
398 static struct io_wq_work *io_get_next_work(struct io_wqe *wqe)
399         __must_hold(wqe->lock)
400 {
401         struct io_wq_work_node *node, *prev;
402         struct io_wq_work *work, *tail;
403         unsigned int hash;
404
405         wq_list_for_each(node, prev, &wqe->work_list) {
406                 work = container_of(node, struct io_wq_work, list);
407
408                 /* not hashed, can run anytime */
409                 if (!io_wq_is_hashed(work)) {
410                         wq_list_del(&wqe->work_list, node, prev);
411                         return work;
412                 }
413
414                 /* hashed, can run if not already running */
415                 hash = io_get_work_hash(work);
416                 if (!(wqe->hash_map & BIT(hash))) {
417                         wqe->hash_map |= BIT(hash);
418                         /* all items with this hash lie in [work, tail] */
419                         tail = wqe->hash_tail[hash];
420                         wqe->hash_tail[hash] = NULL;
421                         wq_list_cut(&wqe->work_list, &tail->list, prev);
422                         return work;
423                 }
424         }
425
426         return NULL;
427 }
428
429 static void io_wq_switch_mm(struct io_worker *worker, struct io_wq_work *work)
430 {
431         if (worker->mm) {
432                 kthread_unuse_mm(worker->mm);
433                 mmput(worker->mm);
434                 worker->mm = NULL;
435         }
436
437         if (mmget_not_zero(work->identity->mm)) {
438                 kthread_use_mm(work->identity->mm);
439                 worker->mm = work->identity->mm;
440                 return;
441         }
442
443         /* failed grabbing mm, ensure work gets cancelled */
444         work->flags |= IO_WQ_WORK_CANCEL;
445 }
446
447 static inline void io_wq_switch_blkcg(struct io_worker *worker,
448                                       struct io_wq_work *work)
449 {
450 #ifdef CONFIG_BLK_CGROUP
451         if (!(work->flags & IO_WQ_WORK_BLKCG))
452                 return;
453         if (work->identity->blkcg_css != worker->blkcg_css) {
454                 kthread_associate_blkcg(work->identity->blkcg_css);
455                 worker->blkcg_css = work->identity->blkcg_css;
456         }
457 #endif
458 }
459
460 static void io_wq_switch_creds(struct io_worker *worker,
461                                struct io_wq_work *work)
462 {
463         const struct cred *old_creds = override_creds(work->identity->creds);
464
465         worker->cur_creds = work->identity->creds;
466         if (worker->saved_creds)
467                 put_cred(old_creds); /* creds set by previous switch */
468         else
469                 worker->saved_creds = old_creds;
470 }
471
472 static void io_impersonate_work(struct io_worker *worker,
473                                 struct io_wq_work *work)
474 {
475         if ((work->flags & IO_WQ_WORK_FILES) &&
476             current->files != work->identity->files) {
477                 task_lock(current);
478                 current->files = work->identity->files;
479                 current->nsproxy = work->identity->nsproxy;
480                 task_unlock(current);
481                 if (!work->identity->files) {
482                         /* failed grabbing files, ensure work gets cancelled */
483                         work->flags |= IO_WQ_WORK_CANCEL;
484                 }
485         }
486         if ((work->flags & IO_WQ_WORK_FS) && current->fs != work->identity->fs)
487                 current->fs = work->identity->fs;
488         if ((work->flags & IO_WQ_WORK_MM) && work->identity->mm != worker->mm)
489                 io_wq_switch_mm(worker, work);
490         if ((work->flags & IO_WQ_WORK_CREDS) &&
491             worker->cur_creds != work->identity->creds)
492                 io_wq_switch_creds(worker, work);
493         if (work->flags & IO_WQ_WORK_FSIZE)
494                 current->signal->rlim[RLIMIT_FSIZE].rlim_cur = work->identity->fsize;
495         else if (current->signal->rlim[RLIMIT_FSIZE].rlim_cur != RLIM_INFINITY)
496                 current->signal->rlim[RLIMIT_FSIZE].rlim_cur = RLIM_INFINITY;
497         io_wq_switch_blkcg(worker, work);
498 #ifdef CONFIG_AUDIT
499         current->loginuid = work->identity->loginuid;
500         current->sessionid = work->identity->sessionid;
501 #endif
502 }
503
504 static void io_assign_current_work(struct io_worker *worker,
505                                    struct io_wq_work *work)
506 {
507         if (work) {
508                 /* flush pending signals before assigning new work */
509                 if (signal_pending(current))
510                         flush_signals(current);
511                 cond_resched();
512         }
513
514 #ifdef CONFIG_AUDIT
515         current->loginuid = KUIDT_INIT(AUDIT_UID_UNSET);
516         current->sessionid = AUDIT_SID_UNSET;
517 #endif
518
519         spin_lock_irq(&worker->lock);
520         worker->cur_work = work;
521         spin_unlock_irq(&worker->lock);
522 }
523
524 static void io_wqe_enqueue(struct io_wqe *wqe, struct io_wq_work *work);
525
526 static void io_worker_handle_work(struct io_worker *worker)
527         __releases(wqe->lock)
528 {
529         struct io_wqe *wqe = worker->wqe;
530         struct io_wq *wq = wqe->wq;
531
532         do {
533                 struct io_wq_work *work;
534 get_next:
535                 /*
536                  * If we got some work, mark us as busy. If we didn't, but
537                  * the list isn't empty, it means we stalled on hashed work.
538                  * Mark us stalled so we don't keep looking for work when we
539                  * can't make progress, any work completion or insertion will
540                  * clear the stalled flag.
541                  */
542                 work = io_get_next_work(wqe);
543                 if (work)
544                         __io_worker_busy(wqe, worker, work);
545                 else if (!wq_list_empty(&wqe->work_list))
546                         wqe->flags |= IO_WQE_FLAG_STALLED;
547
548                 raw_spin_unlock_irq(&wqe->lock);
549                 if (!work)
550                         break;
551                 io_assign_current_work(worker, work);
552
553                 /* handle a whole dependent link */
554                 do {
555                         struct io_wq_work *next_hashed, *linked;
556                         unsigned int hash = io_get_work_hash(work);
557
558                         next_hashed = wq_next_work(work);
559                         io_impersonate_work(worker, work);
560                         wq->do_work(work);
561                         io_assign_current_work(worker, NULL);
562
563                         linked = wq->free_work(work);
564                         work = next_hashed;
565                         if (!work && linked && !io_wq_is_hashed(linked)) {
566                                 work = linked;
567                                 linked = NULL;
568                         }
569                         io_assign_current_work(worker, work);
570                         if (linked)
571                                 io_wqe_enqueue(wqe, linked);
572
573                         if (hash != -1U && !next_hashed) {
574                                 raw_spin_lock_irq(&wqe->lock);
575                                 wqe->hash_map &= ~BIT_ULL(hash);
576                                 wqe->flags &= ~IO_WQE_FLAG_STALLED;
577                                 /* skip unnecessary unlock-lock wqe->lock */
578                                 if (!work)
579                                         goto get_next;
580                                 raw_spin_unlock_irq(&wqe->lock);
581                         }
582                 } while (work);
583
584                 raw_spin_lock_irq(&wqe->lock);
585         } while (1);
586 }
587
588 static int io_wqe_worker(void *data)
589 {
590         struct io_worker *worker = data;
591         struct io_wqe *wqe = worker->wqe;
592         struct io_wq *wq = wqe->wq;
593
594         io_worker_start(wqe, worker);
595
596         while (!test_bit(IO_WQ_BIT_EXIT, &wq->state)) {
597                 set_current_state(TASK_INTERRUPTIBLE);
598 loop:
599                 raw_spin_lock_irq(&wqe->lock);
600                 if (io_wqe_run_queue(wqe)) {
601                         __set_current_state(TASK_RUNNING);
602                         io_worker_handle_work(worker);
603                         goto loop;
604                 }
605                 /* drops the lock on success, retry */
606                 if (__io_worker_idle(wqe, worker)) {
607                         __release(&wqe->lock);
608                         goto loop;
609                 }
610                 raw_spin_unlock_irq(&wqe->lock);
611                 if (signal_pending(current))
612                         flush_signals(current);
613                 if (schedule_timeout(WORKER_IDLE_TIMEOUT))
614                         continue;
615                 /* timed out, exit unless we're the fixed worker */
616                 if (test_bit(IO_WQ_BIT_EXIT, &wq->state) ||
617                     !(worker->flags & IO_WORKER_F_FIXED))
618                         break;
619         }
620
621         if (test_bit(IO_WQ_BIT_EXIT, &wq->state)) {
622                 raw_spin_lock_irq(&wqe->lock);
623                 if (!wq_list_empty(&wqe->work_list))
624                         io_worker_handle_work(worker);
625                 else
626                         raw_spin_unlock_irq(&wqe->lock);
627         }
628
629         io_worker_exit(worker);
630         return 0;
631 }
632
633 /*
634  * Called when a worker is scheduled in. Mark us as currently running.
635  */
636 void io_wq_worker_running(struct task_struct *tsk)
637 {
638         struct io_worker *worker = kthread_data(tsk);
639         struct io_wqe *wqe = worker->wqe;
640
641         if (!(worker->flags & IO_WORKER_F_UP))
642                 return;
643         if (worker->flags & IO_WORKER_F_RUNNING)
644                 return;
645         worker->flags |= IO_WORKER_F_RUNNING;
646         io_wqe_inc_running(wqe, worker);
647 }
648
649 /*
650  * Called when worker is going to sleep. If there are no workers currently
651  * running and we have work pending, wake up a free one or have the manager
652  * set one up.
653  */
654 void io_wq_worker_sleeping(struct task_struct *tsk)
655 {
656         struct io_worker *worker = kthread_data(tsk);
657         struct io_wqe *wqe = worker->wqe;
658
659         if (!(worker->flags & IO_WORKER_F_UP))
660                 return;
661         if (!(worker->flags & IO_WORKER_F_RUNNING))
662                 return;
663
664         worker->flags &= ~IO_WORKER_F_RUNNING;
665
666         raw_spin_lock_irq(&wqe->lock);
667         io_wqe_dec_running(wqe, worker);
668         raw_spin_unlock_irq(&wqe->lock);
669 }
670
671 static bool create_io_worker(struct io_wq *wq, struct io_wqe *wqe, int index)
672 {
673         struct io_wqe_acct *acct = &wqe->acct[index];
674         struct io_worker *worker;
675
676         worker = kzalloc_node(sizeof(*worker), GFP_KERNEL, wqe->node);
677         if (!worker)
678                 return false;
679
680         refcount_set(&worker->ref, 1);
681         worker->nulls_node.pprev = NULL;
682         worker->wqe = wqe;
683         spin_lock_init(&worker->lock);
684
685         worker->task = kthread_create_on_node(io_wqe_worker, worker, wqe->node,
686                                 "io_wqe_worker-%d/%d", index, wqe->node);
687         if (IS_ERR(worker->task)) {
688                 kfree(worker);
689                 return false;
690         }
691         kthread_bind_mask(worker->task, cpumask_of_node(wqe->node));
692
693         raw_spin_lock_irq(&wqe->lock);
694         hlist_nulls_add_head_rcu(&worker->nulls_node, &wqe->free_list);
695         list_add_tail_rcu(&worker->all_list, &wqe->all_list);
696         worker->flags |= IO_WORKER_F_FREE;
697         if (index == IO_WQ_ACCT_BOUND)
698                 worker->flags |= IO_WORKER_F_BOUND;
699         if (!acct->nr_workers && (worker->flags & IO_WORKER_F_BOUND))
700                 worker->flags |= IO_WORKER_F_FIXED;
701         acct->nr_workers++;
702         raw_spin_unlock_irq(&wqe->lock);
703
704         if (index == IO_WQ_ACCT_UNBOUND)
705                 atomic_inc(&wq->user->processes);
706
707         refcount_inc(&wq->refs);
708         wake_up_process(worker->task);
709         return true;
710 }
711
712 static inline bool io_wqe_need_worker(struct io_wqe *wqe, int index)
713         __must_hold(wqe->lock)
714 {
715         struct io_wqe_acct *acct = &wqe->acct[index];
716
717         /* if we have available workers or no work, no need */
718         if (!hlist_nulls_empty(&wqe->free_list) || !io_wqe_run_queue(wqe))
719                 return false;
720         return acct->nr_workers < acct->max_workers;
721 }
722
723 /*
724  * Iterate the passed in list and call the specific function for each
725  * worker that isn't exiting
726  */
727 static bool io_wq_for_each_worker(struct io_wqe *wqe,
728                                   bool (*func)(struct io_worker *, void *),
729                                   void *data)
730 {
731         struct io_worker *worker;
732         bool ret = false;
733
734         list_for_each_entry_rcu(worker, &wqe->all_list, all_list) {
735                 if (io_worker_get(worker)) {
736                         /* no task if node is/was offline */
737                         if (worker->task)
738                                 ret = func(worker, data);
739                         io_worker_release(worker);
740                         if (ret)
741                                 break;
742                 }
743         }
744
745         return ret;
746 }
747
748 static bool io_wq_worker_wake(struct io_worker *worker, void *data)
749 {
750         wake_up_process(worker->task);
751         return false;
752 }
753
754 /*
755  * Manager thread. Tasked with creating new workers, if we need them.
756  */
757 static int io_wq_manager(void *data)
758 {
759         struct io_wq *wq = data;
760         int node;
761
762         /* create fixed workers */
763         refcount_set(&wq->refs, 1);
764         for_each_node(node) {
765                 if (!node_online(node))
766                         continue;
767                 if (create_io_worker(wq, wq->wqes[node], IO_WQ_ACCT_BOUND))
768                         continue;
769                 set_bit(IO_WQ_BIT_ERROR, &wq->state);
770                 set_bit(IO_WQ_BIT_EXIT, &wq->state);
771                 goto out;
772         }
773
774         complete(&wq->done);
775
776         while (!kthread_should_stop()) {
777                 for_each_node(node) {
778                         struct io_wqe *wqe = wq->wqes[node];
779                         bool fork_worker[2] = { false, false };
780
781                         if (!node_online(node))
782                                 continue;
783
784                         raw_spin_lock_irq(&wqe->lock);
785                         if (io_wqe_need_worker(wqe, IO_WQ_ACCT_BOUND))
786                                 fork_worker[IO_WQ_ACCT_BOUND] = true;
787                         if (io_wqe_need_worker(wqe, IO_WQ_ACCT_UNBOUND))
788                                 fork_worker[IO_WQ_ACCT_UNBOUND] = true;
789                         raw_spin_unlock_irq(&wqe->lock);
790                         if (fork_worker[IO_WQ_ACCT_BOUND])
791                                 create_io_worker(wq, wqe, IO_WQ_ACCT_BOUND);
792                         if (fork_worker[IO_WQ_ACCT_UNBOUND])
793                                 create_io_worker(wq, wqe, IO_WQ_ACCT_UNBOUND);
794                 }
795                 set_current_state(TASK_INTERRUPTIBLE);
796                 schedule_timeout(HZ);
797         }
798
799 out:
800         if (refcount_dec_and_test(&wq->refs)) {
801                 complete(&wq->done);
802                 return 0;
803         }
804         /* if ERROR is set and we get here, we have workers to wake */
805         if (test_bit(IO_WQ_BIT_ERROR, &wq->state)) {
806                 rcu_read_lock();
807                 for_each_node(node)
808                         io_wq_for_each_worker(wq->wqes[node], io_wq_worker_wake, NULL);
809                 rcu_read_unlock();
810         }
811         return 0;
812 }
813
814 static bool io_wq_can_queue(struct io_wqe *wqe, struct io_wqe_acct *acct,
815                             struct io_wq_work *work)
816 {
817         bool free_worker;
818
819         if (!(work->flags & IO_WQ_WORK_UNBOUND))
820                 return true;
821         if (atomic_read(&acct->nr_running))
822                 return true;
823
824         rcu_read_lock();
825         free_worker = !hlist_nulls_empty(&wqe->free_list);
826         rcu_read_unlock();
827         if (free_worker)
828                 return true;
829
830         if (atomic_read(&wqe->wq->user->processes) >= acct->max_workers &&
831             !(capable(CAP_SYS_RESOURCE) || capable(CAP_SYS_ADMIN)))
832                 return false;
833
834         return true;
835 }
836
837 static void io_run_cancel(struct io_wq_work *work, struct io_wqe *wqe)
838 {
839         struct io_wq *wq = wqe->wq;
840
841         do {
842                 work->flags |= IO_WQ_WORK_CANCEL;
843                 wq->do_work(work);
844                 work = wq->free_work(work);
845         } while (work);
846 }
847
848 static void io_wqe_insert_work(struct io_wqe *wqe, struct io_wq_work *work)
849 {
850         unsigned int hash;
851         struct io_wq_work *tail;
852
853         if (!io_wq_is_hashed(work)) {
854 append:
855                 wq_list_add_tail(&work->list, &wqe->work_list);
856                 return;
857         }
858
859         hash = io_get_work_hash(work);
860         tail = wqe->hash_tail[hash];
861         wqe->hash_tail[hash] = work;
862         if (!tail)
863                 goto append;
864
865         wq_list_add_after(&work->list, &tail->list, &wqe->work_list);
866 }
867
868 static void io_wqe_enqueue(struct io_wqe *wqe, struct io_wq_work *work)
869 {
870         struct io_wqe_acct *acct = io_work_get_acct(wqe, work);
871         int work_flags;
872         unsigned long flags;
873
874         /*
875          * Do early check to see if we need a new unbound worker, and if we do,
876          * if we're allowed to do so. This isn't 100% accurate as there's a
877          * gap between this check and incrementing the value, but that's OK.
878          * It's close enough to not be an issue, fork() has the same delay.
879          */
880         if (unlikely(!io_wq_can_queue(wqe, acct, work))) {
881                 io_run_cancel(work, wqe);
882                 return;
883         }
884
885         work_flags = work->flags;
886         raw_spin_lock_irqsave(&wqe->lock, flags);
887         io_wqe_insert_work(wqe, work);
888         wqe->flags &= ~IO_WQE_FLAG_STALLED;
889         raw_spin_unlock_irqrestore(&wqe->lock, flags);
890
891         if ((work_flags & IO_WQ_WORK_CONCURRENT) ||
892             !atomic_read(&acct->nr_running))
893                 io_wqe_wake_worker(wqe, acct);
894 }
895
896 void io_wq_enqueue(struct io_wq *wq, struct io_wq_work *work)
897 {
898         struct io_wqe *wqe = wq->wqes[numa_node_id()];
899
900         io_wqe_enqueue(wqe, work);
901 }
902
903 /*
904  * Work items that hash to the same value will not be done in parallel.
905  * Used to limit concurrent writes, generally hashed by inode.
906  */
907 void io_wq_hash_work(struct io_wq_work *work, void *val)
908 {
909         unsigned int bit;
910
911         bit = hash_ptr(val, IO_WQ_HASH_ORDER);
912         work->flags |= (IO_WQ_WORK_HASHED | (bit << IO_WQ_HASH_SHIFT));
913 }
914
915 struct io_cb_cancel_data {
916         work_cancel_fn *fn;
917         void *data;
918         int nr_running;
919         int nr_pending;
920         bool cancel_all;
921 };
922
923 static bool io_wq_worker_cancel(struct io_worker *worker, void *data)
924 {
925         struct io_cb_cancel_data *match = data;
926         unsigned long flags;
927
928         /*
929          * Hold the lock to avoid ->cur_work going out of scope, caller
930          * may dereference the passed in work.
931          */
932         spin_lock_irqsave(&worker->lock, flags);
933         if (worker->cur_work &&
934             match->fn(worker->cur_work, match->data)) {
935                 send_sig(SIGINT, worker->task, 1);
936                 match->nr_running++;
937         }
938         spin_unlock_irqrestore(&worker->lock, flags);
939
940         return match->nr_running && !match->cancel_all;
941 }
942
943 static inline void io_wqe_remove_pending(struct io_wqe *wqe,
944                                          struct io_wq_work *work,
945                                          struct io_wq_work_node *prev)
946 {
947         unsigned int hash = io_get_work_hash(work);
948         struct io_wq_work *prev_work = NULL;
949
950         if (io_wq_is_hashed(work) && work == wqe->hash_tail[hash]) {
951                 if (prev)
952                         prev_work = container_of(prev, struct io_wq_work, list);
953                 if (prev_work && io_get_work_hash(prev_work) == hash)
954                         wqe->hash_tail[hash] = prev_work;
955                 else
956                         wqe->hash_tail[hash] = NULL;
957         }
958         wq_list_del(&wqe->work_list, &work->list, prev);
959 }
960
961 static void io_wqe_cancel_pending_work(struct io_wqe *wqe,
962                                        struct io_cb_cancel_data *match)
963 {
964         struct io_wq_work_node *node, *prev;
965         struct io_wq_work *work;
966         unsigned long flags;
967
968 retry:
969         raw_spin_lock_irqsave(&wqe->lock, flags);
970         wq_list_for_each(node, prev, &wqe->work_list) {
971                 work = container_of(node, struct io_wq_work, list);
972                 if (!match->fn(work, match->data))
973                         continue;
974                 io_wqe_remove_pending(wqe, work, prev);
975                 raw_spin_unlock_irqrestore(&wqe->lock, flags);
976                 io_run_cancel(work, wqe);
977                 match->nr_pending++;
978                 if (!match->cancel_all)
979                         return;
980
981                 /* not safe to continue after unlock */
982                 goto retry;
983         }
984         raw_spin_unlock_irqrestore(&wqe->lock, flags);
985 }
986
987 static void io_wqe_cancel_running_work(struct io_wqe *wqe,
988                                        struct io_cb_cancel_data *match)
989 {
990         rcu_read_lock();
991         io_wq_for_each_worker(wqe, io_wq_worker_cancel, match);
992         rcu_read_unlock();
993 }
994
995 enum io_wq_cancel io_wq_cancel_cb(struct io_wq *wq, work_cancel_fn *cancel,
996                                   void *data, bool cancel_all)
997 {
998         struct io_cb_cancel_data match = {
999                 .fn             = cancel,
1000                 .data           = data,
1001                 .cancel_all     = cancel_all,
1002         };
1003         int node;
1004
1005         /*
1006          * First check pending list, if we're lucky we can just remove it
1007          * from there. CANCEL_OK means that the work is returned as-new,
1008          * no completion will be posted for it.
1009          */
1010         for_each_node(node) {
1011                 struct io_wqe *wqe = wq->wqes[node];
1012
1013                 io_wqe_cancel_pending_work(wqe, &match);
1014                 if (match.nr_pending && !match.cancel_all)
1015                         return IO_WQ_CANCEL_OK;
1016         }
1017
1018         /*
1019          * Now check if a free (going busy) or busy worker has the work
1020          * currently running. If we find it there, we'll return CANCEL_RUNNING
1021          * as an indication that we attempt to signal cancellation. The
1022          * completion will run normally in this case.
1023          */
1024         for_each_node(node) {
1025                 struct io_wqe *wqe = wq->wqes[node];
1026
1027                 io_wqe_cancel_running_work(wqe, &match);
1028                 if (match.nr_running && !match.cancel_all)
1029                         return IO_WQ_CANCEL_RUNNING;
1030         }
1031
1032         if (match.nr_running)
1033                 return IO_WQ_CANCEL_RUNNING;
1034         if (match.nr_pending)
1035                 return IO_WQ_CANCEL_OK;
1036         return IO_WQ_CANCEL_NOTFOUND;
1037 }
1038
1039 struct io_wq *io_wq_create(unsigned bounded, struct io_wq_data *data)
1040 {
1041         int ret = -ENOMEM, node;
1042         struct io_wq *wq;
1043
1044         if (WARN_ON_ONCE(!data->free_work || !data->do_work))
1045                 return ERR_PTR(-EINVAL);
1046
1047         wq = kzalloc(sizeof(*wq), GFP_KERNEL);
1048         if (!wq)
1049                 return ERR_PTR(-ENOMEM);
1050
1051         wq->wqes = kcalloc(nr_node_ids, sizeof(struct io_wqe *), GFP_KERNEL);
1052         if (!wq->wqes)
1053                 goto err_wq;
1054
1055         ret = cpuhp_state_add_instance_nocalls(io_wq_online, &wq->cpuhp_node);
1056         if (ret)
1057                 goto err_wqes;
1058
1059         wq->free_work = data->free_work;
1060         wq->do_work = data->do_work;
1061
1062         /* caller must already hold a reference to this */
1063         wq->user = data->user;
1064
1065         ret = -ENOMEM;
1066         for_each_node(node) {
1067                 struct io_wqe *wqe;
1068                 int alloc_node = node;
1069
1070                 if (!node_online(alloc_node))
1071                         alloc_node = NUMA_NO_NODE;
1072                 wqe = kzalloc_node(sizeof(struct io_wqe), GFP_KERNEL, alloc_node);
1073                 if (!wqe)
1074                         goto err;
1075                 wq->wqes[node] = wqe;
1076                 wqe->node = alloc_node;
1077                 wqe->acct[IO_WQ_ACCT_BOUND].max_workers = bounded;
1078                 atomic_set(&wqe->acct[IO_WQ_ACCT_BOUND].nr_running, 0);
1079                 if (wq->user) {
1080                         wqe->acct[IO_WQ_ACCT_UNBOUND].max_workers =
1081                                         task_rlimit(current, RLIMIT_NPROC);
1082                 }
1083                 atomic_set(&wqe->acct[IO_WQ_ACCT_UNBOUND].nr_running, 0);
1084                 wqe->wq = wq;
1085                 raw_spin_lock_init(&wqe->lock);
1086                 INIT_WQ_LIST(&wqe->work_list);
1087                 INIT_HLIST_NULLS_HEAD(&wqe->free_list, 0);
1088                 INIT_LIST_HEAD(&wqe->all_list);
1089         }
1090
1091         init_completion(&wq->done);
1092
1093         wq->manager = kthread_create(io_wq_manager, wq, "io_wq_manager");
1094         if (!IS_ERR(wq->manager)) {
1095                 wake_up_process(wq->manager);
1096                 wait_for_completion(&wq->done);
1097                 if (test_bit(IO_WQ_BIT_ERROR, &wq->state)) {
1098                         ret = -ENOMEM;
1099                         goto err;
1100                 }
1101                 refcount_set(&wq->use_refs, 1);
1102                 reinit_completion(&wq->done);
1103                 return wq;
1104         }
1105
1106         ret = PTR_ERR(wq->manager);
1107         complete(&wq->done);
1108 err:
1109         cpuhp_state_remove_instance_nocalls(io_wq_online, &wq->cpuhp_node);
1110         for_each_node(node)
1111                 kfree(wq->wqes[node]);
1112 err_wqes:
1113         kfree(wq->wqes);
1114 err_wq:
1115         kfree(wq);
1116         return ERR_PTR(ret);
1117 }
1118
1119 bool io_wq_get(struct io_wq *wq, struct io_wq_data *data)
1120 {
1121         if (data->free_work != wq->free_work || data->do_work != wq->do_work)
1122                 return false;
1123
1124         return refcount_inc_not_zero(&wq->use_refs);
1125 }
1126
1127 static void __io_wq_destroy(struct io_wq *wq)
1128 {
1129         int node;
1130
1131         cpuhp_state_remove_instance_nocalls(io_wq_online, &wq->cpuhp_node);
1132
1133         set_bit(IO_WQ_BIT_EXIT, &wq->state);
1134         if (wq->manager)
1135                 kthread_stop(wq->manager);
1136
1137         rcu_read_lock();
1138         for_each_node(node)
1139                 io_wq_for_each_worker(wq->wqes[node], io_wq_worker_wake, NULL);
1140         rcu_read_unlock();
1141
1142         wait_for_completion(&wq->done);
1143
1144         for_each_node(node)
1145                 kfree(wq->wqes[node]);
1146         kfree(wq->wqes);
1147         kfree(wq);
1148 }
1149
1150 void io_wq_destroy(struct io_wq *wq)
1151 {
1152         if (refcount_dec_and_test(&wq->use_refs))
1153                 __io_wq_destroy(wq);
1154 }
1155
1156 static bool io_wq_worker_affinity(struct io_worker *worker, void *data)
1157 {
1158         struct task_struct *task = worker->task;
1159         struct rq_flags rf;
1160         struct rq *rq;
1161
1162         rq = task_rq_lock(task, &rf);
1163         do_set_cpus_allowed(task, cpumask_of_node(worker->wqe->node));
1164         task->flags |= PF_NO_SETAFFINITY;
1165         task_rq_unlock(rq, task, &rf);
1166         return false;
1167 }
1168
1169 static int io_wq_cpu_online(unsigned int cpu, struct hlist_node *node)
1170 {
1171         struct io_wq *wq = hlist_entry_safe(node, struct io_wq, cpuhp_node);
1172         int i;
1173
1174         rcu_read_lock();
1175         for_each_node(i)
1176                 io_wq_for_each_worker(wq->wqes[i], io_wq_worker_affinity, NULL);
1177         rcu_read_unlock();
1178         return 0;
1179 }
1180
1181 static __init int io_wq_init(void)
1182 {
1183         int ret;
1184
1185         ret = cpuhp_setup_state_multi(CPUHP_AP_ONLINE_DYN, "io-wq/online",
1186                                         io_wq_cpu_online, NULL);
1187         if (ret < 0)
1188                 return ret;
1189         io_wq_online = ret;
1190         return 0;
1191 }
1192 subsys_initcall(io_wq_init);