1 // SPDX-License-Identifier: GPL-2.0+
3 * Copyright (C) 2007 Zach Brown
5 * Test race in read cache invalidation
7 #define _XOPEN_SOURCE 500 /* pwrite */
12 #include <sys/types.h>
18 #include <sys/types.h>
22 * DIO invalidates the read cache after it writes. At one point it tried to
23 * return EIO if this failed. When called from AIO, though, this EIO return
24 * would clobber EIOCBQUEUED and cause fs/aio.c and fs/direct-io.c to complete
25 * an iocb twice. This typically references freed memory from an interrupt
28 * This test hits the race after at most two minutes on a single spindle. It
29 * spins performing large dio writes. It also spins racing buffered writes.
30 * It assumes it's on ext3 using ordered writes. The ordered write bhs can be
31 * pinned by jbd as a transaction commits. If invalidate_inode_pages2_range()
32 * hits pages backed by those buffers ->releasepage will fail and it'll try to
36 #define O_DIRECT 040000 /* direct disk access hint */
39 #define GINORMOUS (32 * 1024 * 1024)
42 /* This test never survived to 180 seconds on a single spindle */
45 static unsigned char buf[GINORMOUS] __attribute((aligned (4096)));
47 #define fail(fmt , args...) do {\
48 printf(fmt , ##args); \
56 struct iocb *iocbs[1] = { &iocb };
57 struct io_event event;
60 io_prep_pwrite(&iocb, fd, buf, GINORMOUS, 0);
62 ret = io_queue_init(1, &ctx);
64 fail("io_queue_init returned %d", ret);
67 ret = io_submit(ctx, 1, iocbs);
69 fail("io_submit returned %d instead of 1", ret);
71 ret = io_getevents(ctx, 1, 1, &event, NULL);
73 fail("io_getevents returned %d instead of 1", ret);
75 if (event.res == -EIO) {
76 printf("invalidation returned -EIO, OK\n");
80 if (event.res != GINORMOUS)
81 fail("event res %ld\n", event.res);
85 void spin_buffered(int fd)
90 ret = pwrite(fd, buf, GINORMOUS, 0);
92 fail("buffered write returned %d", ret);
96 static void alarm_handler(int signum)
100 int main(int argc, char **argv)
111 fail("only arg should be file name");
113 fd = open(argv[1], O_DIRECT|O_CREAT|O_RDWR, 0644);
115 fail("open dio failed: %d\n", errno);
117 fd2 = open(argv[1], O_RDWR, 0644);
119 fail("open failed: %d\n", errno);
121 buffered_pid = fork();
122 if (buffered_pid < 0)
123 fail("fork failed: %d\n", errno);
125 if (buffered_pid == 0) {
132 kill(buffered_pid, SIGKILL);
133 waitpid(buffered_pid, NULL, 0);
134 fail("fork failed: %d\n", errno);
142 memset(&sa, 0, sizeof(sa));
143 sa.sa_handler = alarm_handler;
144 sigemptyset(&sa.sa_mask);
145 if (sigaction(SIGALRM, &sa, NULL) == -1)
146 fail("sigaction: %d\n", errno);
151 if (pid < 0 && errno == EINTR) {
152 /* if we timed out then we're done */
153 kill(buffered_pid, SIGKILL);
154 kill(dio_pid, SIGKILL);
156 waitpid(buffered_pid, NULL, 0);
157 waitpid(dio_pid, NULL, 0);
159 printf("ran for %d seconds without error, passing\n", SECONDS);
163 if (pid == dio_pid) {
164 kill(buffered_pid, SIGKILL);
165 waitpid(buffered_pid, NULL, 0);
167 kill(dio_pid, SIGKILL);
168 waitpid(dio_pid, NULL, 0);
172 * pass on the child's pass/fail return code or fail if the child
173 * didn't exit cleanly.
175 exit(WIFEXITED(status) ? WEXITSTATUS(status) : 1);