blk-mq: fix blk_mq_hw_ctx active request accounting

The nr_active counter continues to increase over time which causes the
blk_mq_get_tag to hang until the thread is rescheduled to a different
core despite there are still tags available.

kernel-stack

INFO: task inboundIOReacto:3014879 blocked for more than 2 seconds
Not tainted 6.1.15-amd64 #1 Debian 6.1.15~debian11
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
task:inboundIOReacto state:D stack:0 pid:3014879 ppid:4557 flags:0x00000000
Call Trace:
<TASK>
__schedule+0x351/0xa20
scheduler+0x5d/0xe0
io_schedule+0x42/0x70
blk_mq_get_tag+0x11a/0x2a0
? dequeue_task_stop+0x70/0x70
__blk_mq_alloc_requests+0x191/0x2e0

kprobe output showing RQF_MQ_INFLIGHT bit is not cleared before
__blk_mq_free_request being called.

320 320 kworker/29:1H __blk_mq_free_request rq_flags 0x220c0 in-flight 1
b'__blk_mq_free_request+0x1 [kernel]'
b'bt_iter+0x50 [kernel]'
b'blk_mq_queue_tag_busy_iter+0x318 [kernel]'
b'blk_mq_timeout_work+0x7c [kernel]'
b'process_one_work+0x1c4 [kernel]'
b'worker_thread+0x4d [kernel]'
b'kthread+0xe6 [kernel]'
b'ret_from_fork+0x1f [kernel]'

Signed-off-by: Tian Lan <tian.lan@twosigma.com>
Fixes: 2e315dc07df0 ("blk-mq: grab rq->refcount before calling ->fn in blk_mq_tagset_busy_iter")
Reviewed-by: Ming Lei <ming.lei@redhat.com>
Link: https://lore.kernel.org/r/20230513221227.497327-1-tilan7663@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>

authored by Tian Lan and committed by Jens Axboe ddad5933 2e45a495

+4 -4
+4 -4
block/blk-mq.c
··· 683 683 blk_crypto_free_request(rq); 684 684 blk_pm_mark_last_busy(rq); 685 685 rq->mq_hctx = NULL; 686 + 687 + if (rq->rq_flags & RQF_MQ_INFLIGHT) 688 + __blk_mq_dec_active_requests(hctx); 689 + 686 690 if (rq->tag != BLK_MQ_NO_TAG) 687 691 blk_mq_put_tag(hctx->tags, ctx, rq->tag); 688 692 if (sched_tag != BLK_MQ_NO_TAG) ··· 698 694 void blk_mq_free_request(struct request *rq) 699 695 { 700 696 struct request_queue *q = rq->q; 701 - struct blk_mq_hw_ctx *hctx = rq->mq_hctx; 702 697 703 698 if ((rq->rq_flags & RQF_ELVPRIV) && 704 699 q->elevator->type->ops.finish_request) 705 700 q->elevator->type->ops.finish_request(rq); 706 - 707 - if (rq->rq_flags & RQF_MQ_INFLIGHT) 708 - __blk_mq_dec_active_requests(hctx); 709 701 710 702 if (unlikely(laptop_mode && !blk_rq_is_passthrough(rq))) 711 703 laptop_io_completion(q->disk->bdi);