2 * Linux io_uring support.
4 * Copyright (C) 2009 IBM, Corp.
5 * Copyright (C) 2009 Red Hat, Inc.
6 * Copyright (C) 2019 Aarushi Mehta
8 * This work is licensed under the terms of the GNU GPL, version 2 or later.
9 * See the COPYING file in the top-level directory.
11 #include "qemu/osdep.h"
13 #include "block/aio.h"
14 #include "qemu/error-report.h"
15 #include "qemu/queue.h"
16 #include "block/block.h"
17 #include "block/raw-aio.h"
18 #include "qemu/coroutine.h"
19 #include "qapi/error.h"
23 /* io_uring ring size */
24 #define MAX_ENTRIES 128
26 typedef struct LuringAIOCB
{
28 struct io_uring_sqe sqeq
;
32 QSIMPLEQ_ENTRY(LuringAIOCB
) next
;
35 * Buffered reads may require resubmission, see
36 * luring_resubmit_short_read().
39 QEMUIOVector resubmit_qiov
;
42 typedef struct LuringQueue
{
44 unsigned int in_queue
;
45 unsigned int in_flight
;
47 QSIMPLEQ_HEAD(, LuringAIOCB
) submit_queue
;
50 typedef struct LuringState
{
51 AioContext
*aio_context
;
55 /* io queue for submit at batch. Protected by AioContext lock. */
58 /* I/O completion processing. Only runs in I/O thread. */
59 QEMUBH
*completion_bh
;
65 * Resubmit a request by appending it to submit_queue. The caller must ensure
66 * that ioq_submit() is called later so that submit_queue requests are started.
68 static void luring_resubmit(LuringState
*s
, LuringAIOCB
*luringcb
)
70 QSIMPLEQ_INSERT_TAIL(&s
->io_q
.submit_queue
, luringcb
, next
);
75 * luring_resubmit_short_read:
77 * Short reads are rare but may occur. The remaining read request needs to be
80 static void luring_resubmit_short_read(LuringState
*s
, LuringAIOCB
*luringcb
,
83 QEMUIOVector
*resubmit_qiov
;
86 trace_luring_resubmit_short_read(s
, luringcb
, nread
);
88 /* Update read position */
89 luringcb
->total_read
+= nread
;
90 remaining
= luringcb
->qiov
->size
- luringcb
->total_read
;
93 resubmit_qiov
= &luringcb
->resubmit_qiov
;
94 if (resubmit_qiov
->iov
== NULL
) {
95 qemu_iovec_init(resubmit_qiov
, luringcb
->qiov
->niov
);
97 qemu_iovec_reset(resubmit_qiov
);
99 qemu_iovec_concat(resubmit_qiov
, luringcb
->qiov
, luringcb
->total_read
,
103 luringcb
->sqeq
.off
+= nread
;
104 luringcb
->sqeq
.addr
= (__u64
)(uintptr_t)luringcb
->resubmit_qiov
.iov
;
105 luringcb
->sqeq
.len
= luringcb
->resubmit_qiov
.niov
;
107 luring_resubmit(s
, luringcb
);
111 * luring_process_completions:
114 * Fetches completed I/O requests, consumes cqes and invokes their callbacks
115 * The function is somewhat tricky because it supports nested event loops, for
116 * example when a request callback invokes aio_poll().
118 * Function schedules BH completion so it can be called again in a nested
119 * event loop. When there are no events left to complete the BH is being
123 static void luring_process_completions(LuringState
*s
)
125 struct io_uring_cqe
*cqes
;
128 * Request completion callbacks can run the nested event loop.
129 * Schedule ourselves so the nested event loop will "see" remaining
130 * completed requests and process them. Without this, completion
131 * callbacks that wait for other requests using a nested event loop
132 * would hang forever.
134 * This workaround is needed because io_uring uses poll_wait, which
135 * is woken up when new events are added to the uring, thus polling on
136 * the same uring fd will block unless more events are received.
138 * Other leaf block drivers (drivers that access the data themselves)
139 * are networking based, so they poll sockets for data and run the
142 qemu_bh_schedule(s
->completion_bh
);
144 while (io_uring_peek_cqe(&s
->ring
, &cqes
) == 0) {
145 LuringAIOCB
*luringcb
;
152 luringcb
= io_uring_cqe_get_data(cqes
);
154 io_uring_cqe_seen(&s
->ring
, cqes
);
157 /* Change counters one-by-one because we can be nested. */
159 trace_luring_process_completion(s
, luringcb
, ret
);
161 /* total_read is non-zero only for resubmitted read requests */
162 total_bytes
= ret
+ luringcb
->total_read
;
166 * Only writev/readv/fsync requests on regular files or host block
167 * devices are submitted. Therefore -EAGAIN is not expected but it's
168 * known to happen sometimes with Linux SCSI. Submit again and hope
169 * the request completes successfully.
171 * For more information, see:
172 * https://lore.kernel.org/io-uring/20210727165811.284510-3-axboe@kernel.dk/T/#u
174 * If the code is changed to submit other types of requests in the
175 * future, then this workaround may need to be extended to deal with
176 * genuine -EAGAIN results that should not be resubmitted
179 if (ret
== -EINTR
|| ret
== -EAGAIN
) {
180 luring_resubmit(s
, luringcb
);
183 } else if (!luringcb
->qiov
) {
185 } else if (total_bytes
== luringcb
->qiov
->size
) {
187 /* Only read/write */
189 /* Short Read/Write */
190 if (luringcb
->is_read
) {
192 luring_resubmit_short_read(s
, luringcb
, ret
);
195 /* Pad with zeroes */
196 qemu_iovec_memset(luringcb
->qiov
, total_bytes
, 0,
197 luringcb
->qiov
->size
- total_bytes
);
206 qemu_iovec_destroy(&luringcb
->resubmit_qiov
);
209 * If the coroutine is already entered it must be in ioq_submit()
210 * and will notice luringcb->ret has been filled in when it
211 * eventually runs later. Coroutines cannot be entered recursively
212 * so avoid doing that!
214 if (!qemu_coroutine_entered(luringcb
->co
)) {
215 aio_co_wake(luringcb
->co
);
218 qemu_bh_cancel(s
->completion_bh
);
221 static int ioq_submit(LuringState
*s
)
224 LuringAIOCB
*luringcb
, *luringcb_next
;
226 while (s
->io_q
.in_queue
> 0) {
228 * Try to fetch sqes from the ring for requests waiting in
231 QSIMPLEQ_FOREACH_SAFE(luringcb
, &s
->io_q
.submit_queue
, next
,
233 struct io_uring_sqe
*sqes
= io_uring_get_sqe(&s
->ring
);
237 /* Prep sqe for submission */
238 *sqes
= luringcb
->sqeq
;
239 QSIMPLEQ_REMOVE_HEAD(&s
->io_q
.submit_queue
, next
);
241 ret
= io_uring_submit(&s
->ring
);
242 trace_luring_io_uring_submit(s
, ret
);
243 /* Prevent infinite loop if submission is refused */
245 if (ret
== -EAGAIN
|| ret
== -EINTR
) {
250 s
->io_q
.in_flight
+= ret
;
251 s
->io_q
.in_queue
-= ret
;
253 s
->io_q
.blocked
= (s
->io_q
.in_queue
> 0);
255 if (s
->io_q
.in_flight
) {
257 * We can try to complete something just right away if there are
258 * still requests in-flight.
260 luring_process_completions(s
);
265 static void luring_process_completions_and_submit(LuringState
*s
)
267 aio_context_acquire(s
->aio_context
);
268 luring_process_completions(s
);
270 if (!s
->io_q
.plugged
&& s
->io_q
.in_queue
> 0) {
273 aio_context_release(s
->aio_context
);
276 static void qemu_luring_completion_bh(void *opaque
)
278 LuringState
*s
= opaque
;
279 luring_process_completions_and_submit(s
);
282 static void qemu_luring_completion_cb(void *opaque
)
284 LuringState
*s
= opaque
;
285 luring_process_completions_and_submit(s
);
288 static bool qemu_luring_poll_cb(void *opaque
)
290 LuringState
*s
= opaque
;
292 return io_uring_cq_ready(&s
->ring
);
295 static void qemu_luring_poll_ready(void *opaque
)
297 LuringState
*s
= opaque
;
299 luring_process_completions_and_submit(s
);
302 static void ioq_init(LuringQueue
*io_q
)
304 QSIMPLEQ_INIT(&io_q
->submit_queue
);
308 io_q
->blocked
= false;
311 void luring_io_plug(BlockDriverState
*bs
, LuringState
*s
)
313 trace_luring_io_plug(s
);
317 void luring_io_unplug(BlockDriverState
*bs
, LuringState
*s
)
319 assert(s
->io_q
.plugged
);
320 trace_luring_io_unplug(s
, s
->io_q
.blocked
, s
->io_q
.plugged
,
321 s
->io_q
.in_queue
, s
->io_q
.in_flight
);
322 if (--s
->io_q
.plugged
== 0 &&
323 !s
->io_q
.blocked
&& s
->io_q
.in_queue
> 0) {
330 * @fd: file descriptor for I/O
331 * @luringcb: AIO control block
333 * @offset: offset for request
334 * @type: type of request
336 * Fetches sqes from ring, adds to pending queue and preps them
339 static int luring_do_submit(int fd
, LuringAIOCB
*luringcb
, LuringState
*s
,
340 uint64_t offset
, int type
)
343 struct io_uring_sqe
*sqes
= &luringcb
->sqeq
;
347 io_uring_prep_writev(sqes
, fd
, luringcb
->qiov
->iov
,
348 luringcb
->qiov
->niov
, offset
);
351 io_uring_prep_readv(sqes
, fd
, luringcb
->qiov
->iov
,
352 luringcb
->qiov
->niov
, offset
);
355 io_uring_prep_fsync(sqes
, fd
, IORING_FSYNC_DATASYNC
);
358 fprintf(stderr
, "%s: invalid AIO request type, aborting 0x%x.\n",
362 io_uring_sqe_set_data(sqes
, luringcb
);
364 QSIMPLEQ_INSERT_TAIL(&s
->io_q
.submit_queue
, luringcb
, next
);
366 trace_luring_do_submit(s
, s
->io_q
.blocked
, s
->io_q
.plugged
,
367 s
->io_q
.in_queue
, s
->io_q
.in_flight
);
368 if (!s
->io_q
.blocked
&&
370 s
->io_q
.in_flight
+ s
->io_q
.in_queue
>= MAX_ENTRIES
)) {
372 trace_luring_do_submit_done(s
, ret
);
378 int coroutine_fn
luring_co_submit(BlockDriverState
*bs
, LuringState
*s
, int fd
,
379 uint64_t offset
, QEMUIOVector
*qiov
, int type
)
382 LuringAIOCB luringcb
= {
383 .co
= qemu_coroutine_self(),
386 .is_read
= (type
== QEMU_AIO_READ
),
388 trace_luring_co_submit(bs
, s
, &luringcb
, fd
, offset
, qiov
? qiov
->size
: 0,
390 ret
= luring_do_submit(fd
, &luringcb
, s
, offset
, type
);
396 if (luringcb
.ret
== -EINPROGRESS
) {
397 qemu_coroutine_yield();
402 void luring_detach_aio_context(LuringState
*s
, AioContext
*old_context
)
404 aio_set_fd_handler(old_context
, s
->ring
.ring_fd
, false,
405 NULL
, NULL
, NULL
, NULL
, s
);
406 qemu_bh_delete(s
->completion_bh
);
407 s
->aio_context
= NULL
;
410 void luring_attach_aio_context(LuringState
*s
, AioContext
*new_context
)
412 s
->aio_context
= new_context
;
413 s
->completion_bh
= aio_bh_new(new_context
, qemu_luring_completion_bh
, s
);
414 aio_set_fd_handler(s
->aio_context
, s
->ring
.ring_fd
, false,
415 qemu_luring_completion_cb
, NULL
,
416 qemu_luring_poll_cb
, qemu_luring_poll_ready
, s
);
419 LuringState
*luring_init(Error
**errp
)
422 LuringState
*s
= g_new0(LuringState
, 1);
423 struct io_uring
*ring
= &s
->ring
;
425 trace_luring_init_state(s
, sizeof(*s
));
427 rc
= io_uring_queue_init(MAX_ENTRIES
, ring
, 0);
429 error_setg_errno(errp
, errno
, "failed to init linux io_uring ring");
435 #ifdef CONFIG_LIBURING_REGISTER_RING_FD
436 if (io_uring_register_ring_fd(&s
->ring
) < 0) {
438 * Only warn about this error: we will fallback to the non-optimized
439 * io_uring operations.
441 warn_report("failed to register linux io_uring ring file descriptor");
448 void luring_cleanup(LuringState
*s
)
450 io_uring_queue_exit(&s
->ring
);
451 trace_luring_cleanup_state(s
);