This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "Hurd".

The branch, master has been updated
       via  98bb6e4f0c67c9331bc3eebdcb89b91237d8e06c (commit)
       via  1c764c3bcf2aae62cef82ae6304f951da1fb4b1e (commit)
      from  5bcfdfc39f243b9fd53f8cca85171fbb86a554da (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
commit 98bb6e4f0c67c9331bc3eebdcb89b91237d8e06c
Author: Milos Nikic <[email protected]>
Date:   Wed Sep 30 15:14:23 2026 -0700

    libdiskfs, ext2fs: Open the journal handle before the node lock
    
    Adding start/stop journal transaction in a few places previously missed.
    
    The diskfs_journal_start_transaction may wait for a commit to drain the
    previous transaction.  That wait is safe only
    when the caller holds no lock a participant of the draining transaction
    could need.  RPC handlers already take their handle first and their node
    locks second.  A few paths reached a start with a lock already held:
    
      - diskfs_release_peropen, from the ports clean routine when a client
        closes its last port to a file.  It locks the node and calls
        diskfs_nput; for an unlinked file _diskfs_lastref then writes the
        node back under nodecache_lock, and diskfs_drop_node truncates and
        frees it under np->lock, each starting a transaction.  A participant
        blocked on nodecache_lock in diskfs_cached_lookup, or on np->lock
        after reacquiring the node through the hash, would wait on this
        thread while this thread waited on the drain.
    
      - diskfs_S_fsys_getfile, whose lookup locks the node and whose nput can
        drop it.
    
      - diskfs_S_io_read and diskfs_S_io_stat, which call diskfs_node_update
        under np->lock for the access time.
    
      - pager_unlock_page, whose block allocation dirties bitmaps, group
        descriptors and indirect blocks through several nested starts.  The
        pager thread never waits, but without one handle around the loop
        each allocation could land in a different transaction.
    Message-ID: <[email protected]>

commit 1c764c3bcf2aae62cef82ae6304f951da1fb4b1e
Author: Milos Nikic <[email protected]>
Date:   Wed Sep 30 15:14:22 2026 -0700

    ext2fs: Keep one RPC in one journal transaction
    
    This fixes a split-RPC bug introduced in 296bacec9 and the resulting shadow 
buffer corruptions. Previously, publishing the successor transaction too early 
allowed a single RPC to be split across multiple transactions. Furthermore, 
overlapping epochs invalidated the t_updates == 0 hydration invariant, as 
threads in the new transaction could edit the live cache while the old one was 
still copying.
    
    The fix reworks transaction handling to make the journal epoch a 
thread-local property for the duration of the RPC (similar to JBD2's 
current->journal_info).
    
    - Thread-Local Nesting: Outermost starts record the transaction in TLS. 
Nested starts return that same exact transaction and increment a depth counter 
without taking locks.
    
    - Active Threads: t_updates is renamed to t_active_threads to reflect that 
it now counts unique participant threads, not open handles.
    
    - Safe Draining: Successor publishing is pushed until after the previous 
transaction finishes draining. Outermost starts will now safely wait for the 
successor since they hold no node locks yet.
    
    - Pager Carveout: Because a pager thread waiting on the journal would cause 
a deadlock, it receives an explicit exemption. Pager callbacks mark their 
thread, allowing them to bypass the wait and join the draining transaction to 
safely complete their bounded operation.
    
    - Thread-Local Sync: Sync requests are now thread-local. This prevents one 
thread's synchronous commit from forcing all other RPCs sharing the transaction 
to block (which caused severe rm -rf slowdowns).
    
    - Shadow Copy Safety: The needs_copy flag is now cleared under the lock 
before the unlocked copy, preventing the sweep from clobbering a concurrent 
re-arm.
    Message-ID: <[email protected]>

-----------------------------------------------------------------------

Summary of changes:
 ext2fs/journal.c         | 252 +++++++++++++++++++++++++++++++++++++----------
 ext2fs/journal.h         |   9 ++
 ext2fs/pager.c           |  13 +++
 libdiskfs/fsys-getfile.c |  12 +++
 libdiskfs/io-read.c      |   7 ++
 libdiskfs/io-stat.c      |   7 ++
 libdiskfs/node-drop.c    |   6 ++
 libdiskfs/peropen-rele.c |  13 +++
 8 files changed, 268 insertions(+), 51 deletions(-)


hooks/post-receive
-- 
Hurd

Reply via email to