2 * Linux io_uring support.
4 * Copyright (C) 2009 IBM, Corp.
5 * Copyright (C) 2009 Red Hat, Inc.
6 * Copyright (C) 2019 Aarushi Mehta
8 * This work is licensed under the terms of the GNU GPL, version 2 or later.
9 * See the COPYING file in the top-level directory.
11 #include "qemu/osdep.h"
13 #include "qemu-common.h"
14 #include "block/aio.h"
15 #include "qemu/queue.h"
16 #include "block/block.h"
17 #include "block/raw-aio.h"
18 #include "qemu/coroutine.h"
19 #include "qapi/error.h"
21 /* io_uring ring size */
22 #define MAX_ENTRIES 128
24 typedef struct LuringAIOCB {
26 struct io_uring_sqe sqeq;
30 QSIMPLEQ_ENTRY(LuringAIOCB) next;
33 * Buffered reads may require resubmission, see
34 * luring_resubmit_short_read().
37 QEMUIOVector resubmit_qiov;
40 typedef struct LuringQueue {
42 unsigned int in_queue;
43 unsigned int in_flight;
45 QSIMPLEQ_HEAD(, LuringAIOCB) submit_queue;
48 typedef struct LuringState {
49 AioContext *aio_context;
53 /* io queue for submit at batch. Protected by AioContext lock. */
56 /* I/O completion processing. Only runs in I/O thread. */
57 QEMUBH *completion_bh;
63 * Resubmit a request by appending it to submit_queue. The caller must ensure
64 * that ioq_submit() is called later so that submit_queue requests are started.
66 static void luring_resubmit(LuringState *s, LuringAIOCB *luringcb)
68 QSIMPLEQ_INSERT_TAIL(&s->io_q.submit_queue, luringcb, next);
73 * luring_resubmit_short_read:
75 * Before Linux commit 9d93a3f5a0c ("io_uring: punt short reads to async
76 * context") a buffered I/O request with the start of the file range in the
77 * page cache could result in a short read. Applications need to resubmit the
78 * remaining read request.
80 * This is a slow path but recent kernels never take it.
82 static void luring_resubmit_short_read(LuringState *s, LuringAIOCB *luringcb,
85 QEMUIOVector *resubmit_qiov;
88 /* Update read position */
89 luringcb->total_read = nread;
90 remaining = luringcb->qiov->size - luringcb->total_read;
93 resubmit_qiov = &luringcb->resubmit_qiov;
94 if (resubmit_qiov->iov == NULL) {
95 qemu_iovec_init(resubmit_qiov, luringcb->qiov->niov);
97 qemu_iovec_reset(resubmit_qiov);
99 qemu_iovec_concat(resubmit_qiov, luringcb->qiov, luringcb->total_read,
103 luringcb->sqeq.off = nread;
104 luringcb->sqeq.addr = (__u64)(uintptr_t)luringcb->resubmit_qiov.iov;
105 luringcb->sqeq.len = luringcb->resubmit_qiov.niov;
107 luring_resubmit(s, luringcb);
111 * luring_process_completions:
114 * Fetches completed I/O requests, consumes cqes and invokes their callbacks
115 * The function is somewhat tricky because it supports nested event loops, for
116 * example when a request callback invokes aio_poll().
118 * Function schedules BH completion so it can be called again in a nested
119 * event loop. When there are no events left to complete the BH is being
123 static void luring_process_completions(LuringState *s)
125 struct io_uring_cqe *cqes;
128 * Request completion callbacks can run the nested event loop.
129 * Schedule ourselves so the nested event loop will "see" remaining
130 * completed requests and process them. Without this, completion
131 * callbacks that wait for other requests using a nested event loop
132 * would hang forever.
134 * This workaround is needed because io_uring uses poll_wait, which
135 * is woken up when new events are added to the uring, thus polling on
136 * the same uring fd will block unless more events are received.
138 * Other leaf block drivers (drivers that access the data themselves)
139 * are networking based, so they poll sockets for data and run the
142 qemu_bh_schedule(s->completion_bh);
144 while (io_uring_peek_cqe(&s->ring, &cqes) == 0) {
145 LuringAIOCB *luringcb;
152 luringcb = io_uring_cqe_get_data(cqes);
154 io_uring_cqe_seen(&s->ring, cqes);
157 /* Change counters one-by-one because we can be nested. */
160 /* total_read is non-zero only for resubmitted read requests */
161 total_bytes = ret + luringcb->total_read;
165 luring_resubmit(s, luringcb);
168 } else if (!luringcb->qiov) {
170 } else if (total_bytes == luringcb->qiov->size) {
172 /* Only read/write */
174 /* Short Read/Write */
175 if (luringcb->is_read) {
177 luring_resubmit_short_read(s, luringcb, ret);
180 /* Pad with zeroes */
181 qemu_iovec_memset(luringcb->qiov, total_bytes, 0,
182 luringcb->qiov->size - total_bytes);
191 qemu_iovec_destroy(&luringcb->resubmit_qiov);
194 * If the coroutine is already entered it must be in ioq_submit()
195 * and will notice luringcb->ret has been filled in when it
196 * eventually runs later. Coroutines cannot be entered recursively
197 * so avoid doing that!
199 if (!qemu_coroutine_entered(luringcb->co)) {
200 aio_co_wake(luringcb->co);
203 qemu_bh_cancel(s->completion_bh);
206 static int ioq_submit(LuringState *s)
209 LuringAIOCB *luringcb, *luringcb_next;
211 while (s->io_q.in_queue > 0) {
213 * Try to fetch sqes from the ring for requests waiting in
216 QSIMPLEQ_FOREACH_SAFE(luringcb, &s->io_q.submit_queue, next,
218 struct io_uring_sqe *sqes = io_uring_get_sqe(&s->ring);
222 /* Prep sqe for submission */
223 *sqes = luringcb->sqeq;
224 QSIMPLEQ_REMOVE_HEAD(&s->io_q.submit_queue, next);
226 ret = io_uring_submit(&s->ring);
227 /* Prevent infinite loop if submission is refused */
229 if (ret == -EAGAIN) {
234 s->io_q.in_flight += ret;
235 s->io_q.in_queue -= ret;
237 s->io_q.blocked = (s->io_q.in_queue > 0);
239 if (s->io_q.in_flight) {
241 * We can try to complete something just right away if there are
242 * still requests in-flight.
244 luring_process_completions(s);
249 static void luring_process_completions_and_submit(LuringState *s)
251 aio_context_acquire(s->aio_context);
252 luring_process_completions(s);
254 if (!s->io_q.plugged && s->io_q.in_queue > 0) {
257 aio_context_release(s->aio_context);
260 static void qemu_luring_completion_bh(void *opaque)
262 LuringState *s = opaque;
263 luring_process_completions_and_submit(s);
266 static void qemu_luring_completion_cb(void *opaque)
268 LuringState *s = opaque;
269 luring_process_completions_and_submit(s);
272 static void ioq_init(LuringQueue *io_q)
274 QSIMPLEQ_INIT(&io_q->submit_queue);
278 io_q->blocked = false;
281 void luring_io_plug(BlockDriverState *bs, LuringState *s)
286 void luring_io_unplug(BlockDriverState *bs, LuringState *s)
288 assert(s->io_q.plugged);
289 if (--s->io_q.plugged == 0 &&
290 !s->io_q.blocked && s->io_q.in_queue > 0) {
297 * @fd: file descriptor for I/O
298 * @luringcb: AIO control block
300 * @offset: offset for request
301 * @type: type of request
303 * Fetches sqes from ring, adds to pending queue and preps them
306 static int luring_do_submit(int fd, LuringAIOCB *luringcb, LuringState *s,
307 uint64_t offset, int type)
309 struct io_uring_sqe *sqes = &luringcb->sqeq;
313 io_uring_prep_writev(sqes, fd, luringcb->qiov->iov,
314 luringcb->qiov->niov, offset);
317 io_uring_prep_readv(sqes, fd, luringcb->qiov->iov,
318 luringcb->qiov->niov, offset);
321 io_uring_prep_fsync(sqes, fd, IORING_FSYNC_DATASYNC);
324 fprintf(stderr, "%s: invalid AIO request type, aborting 0x%x.\n",
328 io_uring_sqe_set_data(sqes, luringcb);
330 QSIMPLEQ_INSERT_TAIL(&s->io_q.submit_queue, luringcb, next);
333 if (!s->io_q.blocked &&
335 s->io_q.in_flight + s->io_q.in_queue >= MAX_ENTRIES)) {
336 return ioq_submit(s);
341 int coroutine_fn luring_co_submit(BlockDriverState *bs, LuringState *s, int fd,
342 uint64_t offset, QEMUIOVector *qiov, int type)
345 LuringAIOCB luringcb = {
346 .co = qemu_coroutine_self(),
349 .is_read = (type == QEMU_AIO_READ),
352 ret = luring_do_submit(fd, &luringcb, s, offset, type);
357 if (luringcb.ret == -EINPROGRESS) {
358 qemu_coroutine_yield();
363 void luring_detach_aio_context(LuringState *s, AioContext *old_context)
365 aio_set_fd_handler(old_context, s->ring.ring_fd, false, NULL, NULL, NULL,
367 qemu_bh_delete(s->completion_bh);
368 s->aio_context = NULL;
371 void luring_attach_aio_context(LuringState *s, AioContext *new_context)
373 s->aio_context = new_context;
374 s->completion_bh = aio_bh_new(new_context, qemu_luring_completion_bh, s);
375 aio_set_fd_handler(s->aio_context, s->ring.ring_fd, false,
376 qemu_luring_completion_cb, NULL, NULL, s);
379 LuringState *luring_init(Error **errp)
382 LuringState *s = g_new0(LuringState, 1);
383 struct io_uring *ring = &s->ring;
385 rc = io_uring_queue_init(MAX_ENTRIES, ring, 0);
387 error_setg_errno(errp, errno, "failed to init linux io_uring ring");
397 void luring_cleanup(LuringState *s)
399 io_uring_queue_exit(&s->ring);