]> git.proxmox.com Git - mirror_zfs.git/blob - include/sys/zil_impl.h
OpenZFS 8909 - 8585 can cause a use-after-free kernel panic
[mirror_zfs.git] / include / sys / zil_impl.h
1 /*
2 * CDDL HEADER START
3 *
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
7 *
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
12 *
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 *
19 * CDDL HEADER END
20 */
21 /*
22 * Copyright (c) 2005, 2010, Oracle and/or its affiliates. All rights reserved.
23 * Copyright (c) 2012, 2017 by Delphix. All rights reserved.
24 */
25
26 /* Portions Copyright 2010 Robert Milkowski */
27
28 #ifndef _SYS_ZIL_IMPL_H
29 #define _SYS_ZIL_IMPL_H
30
31 #include <sys/zil.h>
32 #include <sys/dmu_objset.h>
33
34 #ifdef __cplusplus
35 extern "C" {
36 #endif
37
38 /*
39 * Possible states for a given lwb structure.
40 *
41 * An lwb will start out in the "closed" state, and then transition to
42 * the "opened" state via a call to zil_lwb_write_open(). When
43 * transitioning from "closed" to "opened" the zilog's "zl_issuer_lock"
44 * must be held.
45 *
46 * After the lwb is "opened", it can transition into the "issued" state
47 * via zil_lwb_write_issue(). Again, the zilog's "zl_issuer_lock" must
48 * be held when making this transition.
49 *
50 * After the lwb's zio completes, and the vdev's are flushed, the lwb
51 * will transition into the "done" state via zil_lwb_write_done(). When
52 * transitioning from "issued" to "done", the zilog's "zl_lock" must be
53 * held, *not* the "zl_issuer_lock".
54 *
55 * The zilog's "zl_issuer_lock" can become heavily contended in certain
56 * workloads, so we specifically avoid acquiring that lock when
57 * transitioning an lwb from "issued" to "done". This allows us to avoid
58 * having to acquire the "zl_issuer_lock" for each lwb ZIO completion,
59 * which would have added more lock contention on an already heavily
60 * contended lock.
61 *
62 * Additionally, correctness when reading an lwb's state is often
63 * achieved by exploiting the fact that these state transitions occur in
64 * this specific order; i.e. "closed" to "opened" to "issued" to "done".
65 *
66 * Thus, if an lwb is in the "closed" or "opened" state, holding the
67 * "zl_issuer_lock" will prevent a concurrent thread from transitioning
68 * that lwb to the "issued" state. Likewise, if an lwb is already in the
69 * "issued" state, holding the "zl_lock" will prevent a concurrent
70 * thread from transitioning that lwb to the "done" state.
71 */
72 typedef enum {
73 LWB_STATE_CLOSED,
74 LWB_STATE_OPENED,
75 LWB_STATE_ISSUED,
76 LWB_STATE_DONE,
77 LWB_NUM_STATES
78 } lwb_state_t;
79
80 /*
81 * Log write block (lwb)
82 *
83 * Prior to an lwb being issued to disk via zil_lwb_write_issue(), it
84 * will be protected by the zilog's "zl_issuer_lock". Basically, prior
85 * to it being issued, it will only be accessed by the thread that's
86 * holding the "zl_issuer_lock". After the lwb is issued, the zilog's
87 * "zl_lock" is used to protect the lwb against concurrent access.
88 */
89 typedef struct lwb {
90 zilog_t *lwb_zilog; /* back pointer to log struct */
91 blkptr_t lwb_blk; /* on disk address of this log blk */
92 boolean_t lwb_fastwrite; /* is blk marked for fastwrite? */
93 boolean_t lwb_slog; /* lwb_blk is on SLOG device */
94 int lwb_nused; /* # used bytes in buffer */
95 int lwb_sz; /* size of block and buffer */
96 lwb_state_t lwb_state; /* the state of this lwb */
97 char *lwb_buf; /* log write buffer */
98 zio_t *lwb_write_zio; /* zio for the lwb buffer */
99 zio_t *lwb_root_zio; /* root zio for lwb write and flushes */
100 dmu_tx_t *lwb_tx; /* tx for log block allocation */
101 uint64_t lwb_max_txg; /* highest txg in this lwb */
102 list_node_t lwb_node; /* zilog->zl_lwb_list linkage */
103 list_t lwb_itxs; /* list of itx's */
104 list_t lwb_waiters; /* list of zil_commit_waiter's */
105 avl_tree_t lwb_vdev_tree; /* vdevs to flush after lwb write */
106 kmutex_t lwb_vdev_lock; /* protects lwb_vdev_tree */
107 hrtime_t lwb_issued_timestamp; /* when was the lwb issued? */
108 } lwb_t;
109
110 /*
111 * ZIL commit waiter.
112 *
113 * This structure is allocated each time zil_commit() is called, and is
114 * used by zil_commit() to communicate with other parts of the ZIL, such
115 * that zil_commit() can know when it safe for it return. For more
116 * details, see the comment above zil_commit().
117 *
118 * The "zcw_lock" field is used to protect the commit waiter against
119 * concurrent access. This lock is often acquired while already holding
120 * the zilog's "zl_issuer_lock" or "zl_lock"; see the functions
121 * zil_process_commit_list() and zil_lwb_flush_vdevs_done() as examples
122 * of this. Thus, one must be careful not to acquire the
123 * "zl_issuer_lock" or "zl_lock" when already holding the "zcw_lock";
124 * e.g. see the zil_commit_waiter_timeout() function.
125 */
126 typedef struct zil_commit_waiter {
127 kcondvar_t zcw_cv; /* signalled when "done" */
128 kmutex_t zcw_lock; /* protects fields of this struct */
129 list_node_t zcw_node; /* linkage in lwb_t:lwb_waiter list */
130 lwb_t *zcw_lwb; /* back pointer to lwb when linked */
131 boolean_t zcw_done; /* B_TRUE when "done", else B_FALSE */
132 int zcw_zio_error; /* contains the zio io_error value */
133 } zil_commit_waiter_t;
134
135 /*
136 * Intent log transaction lists
137 */
138 typedef struct itxs {
139 list_t i_sync_list; /* list of synchronous itxs */
140 avl_tree_t i_async_tree; /* tree of foids for async itxs */
141 } itxs_t;
142
143 typedef struct itxg {
144 kmutex_t itxg_lock; /* lock for this structure */
145 uint64_t itxg_txg; /* txg for this chain */
146 itxs_t *itxg_itxs; /* sync and async itxs */
147 } itxg_t;
148
149 /* for async nodes we build up an AVL tree of lists of async itxs per file */
150 typedef struct itx_async_node {
151 uint64_t ia_foid; /* file object id */
152 list_t ia_list; /* list of async itxs for this foid */
153 avl_node_t ia_node; /* AVL tree linkage */
154 } itx_async_node_t;
155
156 /*
157 * Vdev flushing: during a zil_commit(), we build up an AVL tree of the vdevs
158 * we've touched so we know which ones need a write cache flush at the end.
159 */
160 typedef struct zil_vdev_node {
161 uint64_t zv_vdev; /* vdev to be flushed */
162 avl_node_t zv_node; /* AVL tree linkage */
163 } zil_vdev_node_t;
164
165 #define ZIL_PREV_BLKS 16
166
167 /*
168 * Stable storage intent log management structure. One per dataset.
169 */
170 struct zilog {
171 kmutex_t zl_lock; /* protects most zilog_t fields */
172 struct dsl_pool *zl_dmu_pool; /* DSL pool */
173 spa_t *zl_spa; /* handle for read/write log */
174 const zil_header_t *zl_header; /* log header buffer */
175 objset_t *zl_os; /* object set we're logging */
176 zil_get_data_t *zl_get_data; /* callback to get object content */
177 lwb_t *zl_last_lwb_opened; /* most recent lwb opened */
178 hrtime_t zl_last_lwb_latency; /* zio latency of last lwb done */
179 uint64_t zl_lr_seq; /* on-disk log record sequence number */
180 uint64_t zl_commit_lr_seq; /* last committed on-disk lr seq */
181 uint64_t zl_destroy_txg; /* txg of last zil_destroy() */
182 uint64_t zl_replayed_seq[TXG_SIZE]; /* last replayed rec seq */
183 uint64_t zl_replaying_seq; /* current replay seq number */
184 uint32_t zl_suspend; /* log suspend count */
185 kcondvar_t zl_cv_suspend; /* log suspend completion */
186 uint8_t zl_suspending; /* log is currently suspending */
187 uint8_t zl_keep_first; /* keep first log block in destroy */
188 uint8_t zl_replay; /* replaying records while set */
189 uint8_t zl_stop_sync; /* for debugging */
190 kmutex_t zl_issuer_lock; /* single writer, per ZIL, at a time */
191 uint8_t zl_logbias; /* latency or throughput */
192 uint8_t zl_sync; /* synchronous or asynchronous */
193 int zl_parse_error; /* last zil_parse() error */
194 uint64_t zl_parse_blk_seq; /* highest blk seq on last parse */
195 uint64_t zl_parse_lr_seq; /* highest lr seq on last parse */
196 uint64_t zl_parse_blk_count; /* number of blocks parsed */
197 uint64_t zl_parse_lr_count; /* number of log records parsed */
198 itxg_t zl_itxg[TXG_SIZE]; /* intent log txg chains */
199 list_t zl_itx_commit_list; /* itx list to be committed */
200 uint64_t zl_cur_used; /* current commit log size used */
201 list_t zl_lwb_list; /* in-flight log write list */
202 avl_tree_t zl_bp_tree; /* track bps during log parse */
203 clock_t zl_replay_time; /* lbolt of when replay started */
204 uint64_t zl_replay_blks; /* number of log blocks replayed */
205 zil_header_t zl_old_header; /* debugging aid */
206 uint_t zl_prev_blks[ZIL_PREV_BLKS]; /* size - sector rounded */
207 uint_t zl_prev_rotor; /* rotor for zl_prev[] */
208 txg_node_t zl_dirty_link; /* protected by dp_dirty_zilogs list */
209 uint64_t zl_dirty_max_txg; /* highest txg used to dirty zilog */
210 };
211
212 typedef struct zil_bp_node {
213 dva_t zn_dva;
214 avl_node_t zn_node;
215 } zil_bp_node_t;
216
217 /*
218 * Maximum amount of write data that can be put into single log block.
219 */
220 #define ZIL_MAX_LOG_DATA (SPA_OLD_MAXBLOCKSIZE - sizeof (zil_chain_t) - \
221 sizeof (lr_write_t))
222
223 /*
224 * Maximum amount of log space we agree to waste to reduce number of
225 * WR_NEED_COPY chunks to reduce zl_get_data() overhead (~12%).
226 */
227 #define ZIL_MAX_WASTE_SPACE (ZIL_MAX_LOG_DATA / 8)
228
229 /*
230 * Maximum amount of write data for WR_COPIED. Fall back to WR_NEED_COPY
231 * as more space efficient if we can't fit at least two log records into
232 * maximum sized log block.
233 */
234 #define ZIL_MAX_COPIED_DATA ((SPA_OLD_MAXBLOCKSIZE - \
235 sizeof (zil_chain_t)) / 2 - sizeof (lr_write_t))
236
237 #ifdef __cplusplus
238 }
239 #endif
240
241 #endif /* _SYS_ZIL_IMPL_H */