2009-05-04 15:23:58 +00:00
|
|
|
/*-
|
|
|
|
* Copyright (c) 1989, 1993
|
|
|
|
* The Regents of the University of California. All rights reserved.
|
|
|
|
*
|
|
|
|
* This code is derived from software contributed to Berkeley by
|
|
|
|
* Rick Macklem at The University of Guelph.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
2017-02-28 23:42:47 +00:00
|
|
|
* 3. Neither the name of the University nor the names of its contributors
|
2009-05-04 15:23:58 +00:00
|
|
|
* may be used to endorse or promote products derived from this software
|
|
|
|
* without specific prior written permission.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
|
|
|
|
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
|
|
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
|
|
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
|
|
|
|
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
|
|
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
|
|
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
|
|
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
|
|
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
|
|
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
|
|
* SUCH DAMAGE.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <sys/cdefs.h>
|
|
|
|
__FBSDID("$FreeBSD$");
|
|
|
|
|
|
|
|
#include "opt_kgssapi.h"
|
|
|
|
|
|
|
|
#include <fs/nfs/nfsport.h>
|
|
|
|
|
|
|
|
#include <rpc/rpc.h>
|
|
|
|
#include <rpc/rpcsec_gss.h>
|
|
|
|
#include <rpc/replay.h>
|
|
|
|
|
|
|
|
|
|
|
|
NFSDLOCKMUTEX;
|
|
|
|
|
2012-12-08 22:52:39 +00:00
|
|
|
extern SVCPOOL *nfscbd_pool;
|
2009-05-04 15:23:58 +00:00
|
|
|
|
|
|
|
static int nfs_cbproc(struct nfsrv_descript *, u_int32_t);
|
|
|
|
|
|
|
|
extern u_long sb_max_adj;
|
|
|
|
extern int nfs_numnfscbd;
|
2012-12-08 22:52:39 +00:00
|
|
|
extern int nfscl_debuglevel;
|
2009-05-04 15:23:58 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* NFS client system calls for handling callbacks.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Handles server to client callbacks.
|
|
|
|
*/
|
|
|
|
static void
|
|
|
|
nfscb_program(struct svc_req *rqst, SVCXPRT *xprt)
|
|
|
|
{
|
|
|
|
struct nfsrv_descript nd;
|
2009-05-14 21:39:08 +00:00
|
|
|
int cacherep, credflavor;
|
2009-05-04 15:23:58 +00:00
|
|
|
|
|
|
|
memset(&nd, 0, sizeof(nd));
|
|
|
|
if (rqst->rq_proc != NFSPROC_NULL &&
|
|
|
|
rqst->rq_proc != NFSV4PROC_CBCOMPOUND) {
|
|
|
|
svcerr_noproc(rqst);
|
|
|
|
svc_freereq(rqst);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
nd.nd_procnum = rqst->rq_proc;
|
|
|
|
nd.nd_flag = (ND_NFSCB | ND_NFSV4);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Note: we want rq_addr, not svc_getrpccaller for nd_nam2 -
|
|
|
|
* NFS_SRVMAXDATA uses a NULL value for nd_nam2 to detect TCP
|
|
|
|
* mounts.
|
|
|
|
*/
|
|
|
|
nd.nd_mrep = rqst->rq_args;
|
|
|
|
rqst->rq_args = NULL;
|
Revamp the old NFS server's File Handle Affinity (FHA) code so that
it will work with either the old or new server.
The FHA code keeps a cache of currently active file handles for
NFSv2 and v3 requests, so that read and write requests for the same
file are directed to the same group of threads (reads) or thread
(writes). It does not currently work for NFSv4 requests. They are
more complex, and will take more work to support.
This improves read-ahead performance, especially with ZFS, if the
FHA tuning parameters are configured appropriately. Without the
FHA code, concurrent reads that are part of a sequential read from
a file will be directed to separate NFS threads. This has the
effect of confusing the ZFS zfetch (prefetch) code and makes
sequential reads significantly slower with clients like Linux that
do a lot of prefetching.
The FHA code has also been updated to direct write requests to nearby
file offsets to the same thread in the same way it batches reads,
and the FHA code will now also send writes to multiple threads when
needed.
This improves sequential write performance in ZFS, because writes
to a file are now more ordered. Since NFS writes (generally
less than 64K) are smaller than the typical ZFS record size
(usually 128K), out of order NFS writes to the same block can
trigger a read in ZFS. Sending them down the same thread increases
the odds of their being in order.
In order for multiple write threads per file in the FHA code to be
useful, writes in the NFS server have been changed to use a LK_SHARED
vnode lock, and upgrade that to LK_EXCLUSIVE if the filesystem
doesn't allow multiple writers to a file at once. ZFS is currently
the only filesystem that allows multiple writers to a file, because
it has internal file range locking. This change does not affect the
NFSv4 code.
This improves random write performance to a single file in ZFS, since
we can now have multiple writers inside ZFS at one time.
I have changed the default tuning parameters to a 22 bit (4MB)
window size (from 256K) and unlimited commands per thread as a
result of my benchmarking with ZFS.
The FHA code has been updated to allow configuring the tuning
parameters from loader tunable variables in addition to sysctl
variables. The read offset window calculation has been slightly
modified as well. Instead of having separate bins, each file
handle has a rolling window of bin_shift size. This minimizes
glitches in throughput when shifting from one bin to another.
sys/conf/files:
Add nfs_fha_new.c and nfs_fha_old.c. Compile nfs_fha.c
when either the old or the new NFS server is built.
sys/fs/nfs/nfsport.h,
sys/fs/nfs/nfs_commonport.c:
Bring in changes from Rick Macklem to newnfs_realign that
allow it to operate in blocking (M_WAITOK) or non-blocking
(M_NOWAIT) mode.
sys/fs/nfs/nfs_commonsubs.c,
sys/fs/nfs/nfs_var.h:
Bring in a change from Rick Macklem to allow telling
nfsm_dissect() whether or not to wait for mallocs.
sys/fs/nfs/nfsm_subs.h:
Bring in changes from Rick Macklem to create a new
nfsm_dissect_nonblock() inline function and
NFSM_DISSECT_NONBLOCK() macro.
sys/fs/nfs/nfs_commonkrpc.c,
sys/fs/nfsclient/nfs_clkrpc.c:
Add the malloc wait flag to a newnfs_realign() call.
sys/fs/nfsserver/nfs_nfsdkrpc.c:
Setup the new NFS server's RPC thread pool so that it will
call the FHA code.
Add the malloc flag argument to newnfs_realign().
Unstaticize newnfs_nfsv3_procid[] so that we can use it in
the FHA code.
sys/fs/nfsserver/nfs_nfsdsocket.c:
In nfsrvd_dorpc(), add NFSPROC_WRITE to the list of RPC types
that use the LK_SHARED lock type.
sys/fs/nfsserver/nfs_nfsdport.c:
In nfsd_fhtovp(), if we're starting a write, check to see
whether the underlying filesystem supports shared writes.
If not, upgrade the lock type from LK_SHARED to LK_EXCLUSIVE.
sys/nfsserver/nfs_fha.c:
Remove all code that is specific to the NFS server
implementation. Anything that is server-specific is now
accessed through a callback supplied by that server's FHA
shim in the new softc.
There are now separate sysctls and tunables for the FHA
implementations for the old and new NFS servers. The new
NFS server has its tunables under vfs.nfsd.fha, the old
NFS server's tunables are under vfs.nfsrv.fha as before.
In fha_extract_info(), use callouts for all server-specific
code. Getting file handles and offsets is now done in the
individual server's shim module.
In fha_hash_entry_choose_thread(), change the way we decide
whether two reads are in proximity to each other.
Previously, the calculation was a simple shift operation to
see whether the offsets were in the same power of 2 bucket.
The issue was that there would be a bucket (and therefore
thread) transition, even if the reads were in close
proximity. When there is a thread transition, reads wind
up going somewhat out of order, and ZFS gets confused.
The new calculation simply tries to see whether the offsets
are within 1 << bin_shift of each other. If they are, the
reads will be sent to the same thread.
The effect of this change is that for sequential reads, if
the client doesn't exceed the max_reqs_per_nfsd parameter
and the bin_shift is set to a reasonable value (22, or
4MB works well in my tests), the reads in any sequential
stream will largely be confined to a single thread.
Change fha_assign() so that it takes a softc argument. It
is now called from the individual server's shim code, which
will pass in the softc.
Change fhe_stats_sysctl() so that it takes a softc
parameter. It is now called from the individual server's
shim code. Add the current offset to the list of things
printed out about each active thread.
Change the num_reads and num_writes counters in the
fha_hash_entry structure to 32-bit values, and rename them
num_rw and num_exclusive, respectively, to reflect their
changed usage.
Add an enable sysctl and tunable that allows the user to
disable the FHA code (when vfs.XXX.fha.enable = 0). This
is useful for before/after performance comparisons.
nfs_fha.h:
Move most structure definitions out of nfs_fha.c and into
the header file, so that the individual server shims can
see them.
Change the default bin_shift to 22 (4MB) instead of 18
(256K). Allow unlimited commands per thread.
sys/nfsserver/nfs_fha_old.c,
sys/nfsserver/nfs_fha_old.h,
sys/fs/nfsserver/nfs_fha_new.c,
sys/fs/nfsserver/nfs_fha_new.h:
Add shims for the old and new NFS servers to interface with
the FHA code, and callbacks for the
The shims contain all of the code and definitions that are
specific to the NFS servers.
They setup the server-specific callbacks and set the server
name for the sysctl and loader tunable variables.
sys/nfsserver/nfs_srvkrpc.c:
Configure the RPC code to call fhaold_assign() instead of
fha_assign().
sys/modules/nfsd/Makefile:
Add nfs_fha.c and nfs_fha_new.c.
sys/modules/nfsserver/Makefile:
Add nfs_fha_old.c.
Reviewed by: rmacklem
Sponsored by: Spectra Logic
MFC after: 2 weeks
2013-04-17 21:00:22 +00:00
|
|
|
newnfs_realign(&nd.nd_mrep, M_WAITOK);
|
2009-05-04 15:23:58 +00:00
|
|
|
nd.nd_md = nd.nd_mrep;
|
|
|
|
nd.nd_dpos = mtod(nd.nd_md, caddr_t);
|
|
|
|
nd.nd_nam = svc_getrpccaller(rqst);
|
|
|
|
nd.nd_nam2 = rqst->rq_addr;
|
|
|
|
nd.nd_mreq = NULL;
|
|
|
|
nd.nd_cred = NULL;
|
|
|
|
|
2012-12-08 22:52:39 +00:00
|
|
|
NFSCL_DEBUG(1, "cbproc=%d\n",nd.nd_procnum);
|
2009-05-04 15:23:58 +00:00
|
|
|
if (nd.nd_procnum != NFSPROC_NULL) {
|
2009-05-14 21:39:08 +00:00
|
|
|
if (!svc_getcred(rqst, &nd.nd_cred, &credflavor)) {
|
2009-05-04 15:23:58 +00:00
|
|
|
svcerr_weakauth(rqst);
|
|
|
|
svc_freereq(rqst);
|
|
|
|
m_freem(nd.nd_mrep);
|
|
|
|
return;
|
|
|
|
}
|
2009-05-14 21:39:08 +00:00
|
|
|
|
|
|
|
/* For now, I don't care what credential flavor was used. */
|
2009-05-04 15:23:58 +00:00
|
|
|
#ifdef notyet
|
|
|
|
#ifdef MAC
|
|
|
|
mac_cred_associate_nfsd(nd.nd_cred);
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
cacherep = nfs_cbproc(&nd, rqst->rq_xid);
|
|
|
|
} else {
|
|
|
|
NFSMGET(nd.nd_mreq);
|
|
|
|
nd.nd_mreq->m_len = 0;
|
|
|
|
cacherep = RC_REPLY;
|
|
|
|
}
|
|
|
|
if (nd.nd_mrep != NULL)
|
|
|
|
m_freem(nd.nd_mrep);
|
|
|
|
|
|
|
|
if (nd.nd_cred != NULL)
|
|
|
|
crfree(nd.nd_cred);
|
|
|
|
|
|
|
|
if (cacherep == RC_DROPIT) {
|
|
|
|
if (nd.nd_mreq != NULL)
|
|
|
|
m_freem(nd.nd_mreq);
|
|
|
|
svc_freereq(rqst);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (nd.nd_mreq == NULL) {
|
|
|
|
svcerr_decode(rqst);
|
|
|
|
svc_freereq(rqst);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (nd.nd_repstat & NFSERR_AUTHERR) {
|
|
|
|
svcerr_auth(rqst, nd.nd_repstat & ~NFSERR_AUTHERR);
|
|
|
|
if (nd.nd_mreq != NULL)
|
|
|
|
m_freem(nd.nd_mreq);
|
2012-12-08 22:52:39 +00:00
|
|
|
} else if (!svc_sendreply_mbuf(rqst, nd.nd_mreq))
|
2009-05-04 15:23:58 +00:00
|
|
|
svcerr_systemerr(rqst);
|
2012-12-08 22:52:39 +00:00
|
|
|
else
|
|
|
|
NFSCL_DEBUG(1, "cbrep sent\n");
|
2009-05-04 15:23:58 +00:00
|
|
|
svc_freereq(rqst);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Check the cache and, optionally, do the RPC.
|
|
|
|
* Return the appropriate cache response.
|
|
|
|
*/
|
|
|
|
static int
|
|
|
|
nfs_cbproc(struct nfsrv_descript *nd, u_int32_t xid)
|
|
|
|
{
|
|
|
|
struct thread *td = curthread;
|
|
|
|
int cacherep;
|
|
|
|
|
|
|
|
if (nd->nd_nam2 == NULL)
|
|
|
|
nd->nd_flag |= ND_STREAMSOCK;
|
|
|
|
|
|
|
|
nfscl_docb(nd, td);
|
|
|
|
if (nd->nd_repstat == NFSERR_DONTREPLY)
|
|
|
|
cacherep = RC_DROPIT;
|
|
|
|
else
|
|
|
|
cacherep = RC_REPLY;
|
|
|
|
return (cacherep);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Adds a socket to the list for servicing by nfscbds.
|
|
|
|
*/
|
|
|
|
int
|
|
|
|
nfscbd_addsock(struct file *fp)
|
|
|
|
{
|
|
|
|
int siz;
|
|
|
|
struct socket *so;
|
|
|
|
int error;
|
|
|
|
SVCXPRT *xprt;
|
|
|
|
|
|
|
|
so = fp->f_data;
|
|
|
|
|
|
|
|
siz = sb_max_adj;
|
|
|
|
error = soreserve(so, siz, siz);
|
|
|
|
if (error)
|
|
|
|
return (error);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Steal the socket from userland so that it doesn't close
|
|
|
|
* unexpectedly.
|
|
|
|
*/
|
|
|
|
if (so->so_type == SOCK_DGRAM)
|
|
|
|
xprt = svc_dg_create(nfscbd_pool, so, 0, 0);
|
|
|
|
else
|
|
|
|
xprt = svc_vc_create(nfscbd_pool, so, 0, 0);
|
|
|
|
if (xprt) {
|
|
|
|
fp->f_ops = &badfileops;
|
|
|
|
fp->f_data = NULL;
|
|
|
|
svc_reg(xprt, NFS_CALLBCKPROG, NFSV4_CBVERS, nfscb_program,
|
|
|
|
NULL);
|
2009-06-17 22:55:59 +00:00
|
|
|
SVC_RELEASE(xprt);
|
2009-05-04 15:23:58 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Called by nfssvc() for nfscbds. Just loops around servicing rpc requests
|
|
|
|
* until it is killed by a signal.
|
|
|
|
*
|
|
|
|
* For now, only support callbacks via RPCSEC_GSS if there is a KerberosV
|
|
|
|
* keytab entry with a host based entry in it on the client. (I'm not even
|
|
|
|
* sure that getting Acceptor credentials for a user principal with a
|
|
|
|
* credentials cache is possible, but even if it is, major changes to the
|
|
|
|
* kgssapi would be required.)
|
|
|
|
* I don't believe that this is a serious limitation since, as of 2009, most
|
|
|
|
* NFSv4 servers supporting callbacks are using AUTH_SYS for callbacks even
|
|
|
|
* when the client is using RPCSEC_GSS. (This BSD server uses AUTH_SYS
|
|
|
|
* for callbacks unless nfsrv_gsscallbackson is set non-zero.)
|
|
|
|
*/
|
|
|
|
int
|
|
|
|
nfscbd_nfsd(struct thread *td, struct nfsd_nfscbd_args *args)
|
|
|
|
{
|
|
|
|
char principal[128];
|
|
|
|
int error;
|
|
|
|
|
|
|
|
if (args != NULL) {
|
|
|
|
error = copyinstr(args->principal, principal,
|
|
|
|
sizeof(principal), NULL);
|
|
|
|
if (error)
|
|
|
|
return (error);
|
|
|
|
} else {
|
|
|
|
principal[0] = '\0';
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Only the first nfsd actually does any work. The RPC code
|
|
|
|
* adds threads to it as needed. Any extra processes offered
|
|
|
|
* by nfsd just exit. If nfsd is new enough, it will call us
|
|
|
|
* once with a structure that specifies how many threads to
|
|
|
|
* use.
|
|
|
|
*/
|
|
|
|
NFSD_LOCK();
|
|
|
|
if (nfs_numnfscbd == 0) {
|
|
|
|
nfs_numnfscbd++;
|
|
|
|
|
|
|
|
NFSD_UNLOCK();
|
|
|
|
|
|
|
|
if (principal[0] != '\0')
|
2011-06-19 22:08:55 +00:00
|
|
|
rpc_gss_set_svc_name_call(principal, "kerberosv5",
|
2009-05-04 15:23:58 +00:00
|
|
|
GSS_C_INDEFINITE, NFS_CALLBCKPROG, NFSV4_CBVERS);
|
|
|
|
|
|
|
|
nfscbd_pool->sp_minthreads = 4;
|
|
|
|
nfscbd_pool->sp_maxthreads = 4;
|
|
|
|
|
|
|
|
svc_run(nfscbd_pool);
|
|
|
|
|
2011-06-19 22:08:55 +00:00
|
|
|
rpc_gss_clear_svc_name_call(NFS_CALLBCKPROG, NFSV4_CBVERS);
|
2009-05-04 15:23:58 +00:00
|
|
|
|
|
|
|
NFSD_LOCK();
|
|
|
|
nfs_numnfscbd--;
|
|
|
|
nfsrvd_cbinit(1);
|
|
|
|
}
|
|
|
|
NFSD_UNLOCK();
|
|
|
|
|
|
|
|
return (0);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Initialize the data structures for the server.
|
|
|
|
* Handshake with any new nfsds starting up to avoid any chance of
|
|
|
|
* corruption.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
nfsrvd_cbinit(int terminating)
|
|
|
|
{
|
|
|
|
|
|
|
|
NFSD_LOCK_ASSERT();
|
|
|
|
|
|
|
|
if (terminating) {
|
2012-12-08 22:52:39 +00:00
|
|
|
/* Wait for any xprt registrations to complete. */
|
|
|
|
while (nfs_numnfscbd > 0)
|
|
|
|
msleep(&nfs_numnfscbd, NFSDLOCKMUTEXPTR, PZERO,
|
|
|
|
"nfscbdt", 0);
|
2017-04-13 20:16:29 +00:00
|
|
|
if (nfscbd_pool != NULL) {
|
|
|
|
NFSD_UNLOCK();
|
|
|
|
svcpool_close(nfscbd_pool);
|
|
|
|
NFSD_LOCK();
|
|
|
|
}
|
2013-09-04 22:47:56 +00:00
|
|
|
}
|
2009-05-04 15:23:58 +00:00
|
|
|
|
2013-09-04 22:47:56 +00:00
|
|
|
if (nfscbd_pool == NULL) {
|
|
|
|
NFSD_UNLOCK();
|
|
|
|
nfscbd_pool = svcpool_create("nfscbd", NULL);
|
|
|
|
nfscbd_pool->sp_rcache = NULL;
|
|
|
|
nfscbd_pool->sp_assign = NULL;
|
|
|
|
nfscbd_pool->sp_done = NULL;
|
|
|
|
NFSD_LOCK();
|
|
|
|
}
|
2009-05-04 15:23:58 +00:00
|
|
|
}
|
|
|
|
|