On Wed, Aug 31, 2022 at 11:43:49AM +0200, Jan Kara wrote: > So after looking into that a bit more, I think a clean approach would be to > provide iov_iter_pin_pages2() and iov_iter_pages_alloc2(), under the hood > in __iov_iter_get_pages_alloc() make sure we use pin_user_page() instead of > get_page() in all the cases (using this in pipe_get_pages() and > iter_xarray_get_pages() is easy) and then make all bio handling use the > pinning variants for iters. I think at least iov_iter_is_pipe() case needs > to be handled as well because as I wrote above, pipe pages can enter direct > IO code e.g. for splice(2). > > Also I think that all iov_iter_get_pages2() (or the _alloc2 variant) users > actually do want the "pin page" semantics in the end (they are accessing > page contents) so eventually we should convert them all to > iov_iter_pin_pages2() and remove iov_iter_get_pages2() altogether. But this > will take some more conversion work with networking etc. so I'd start with > converting bios only. Not sure, TBH... FWIW, quite a few of the callers of iov_iter_get_pages2() do *NOT* need to grab any references for BVEC/XARRAY/PIPE cases. What's more, it would be bloody useful to have a variant that doesn't grab references for !iter->user_backed case - that could be usable for KVEC as well, simplifying several callers. Requirements: * recepients of those struct page * should have a way to make dropping the page refs conditional (obviously); bio machinery can be told to do so. * callers should *NOT* do something like "set an ITER_BVEC iter, with page references grabbed and stashed in bio_vec array, call async read_iter() and drop the references in array - the refs we grab in dio will serve" Note that for sync IO that pattern is fine whether we grab/drop anything inside read_iter(); for async we could take depopulating the bio_vec array to the IO completion or downstream of that. * the code dealing with the references returned by iov_iter_..._pages should *NOT* play silly buggers with refcounts - something like "I'll grab a reference, start DMA and report success; page will stay around until I get around to dropping the ref and callers don't need to wait for that" deep in the bowels of infinibad stack (or something equally tasteful) is seriously asking for trouble. Future plans from the last cycle included iov_iter_find_pages{,_alloc}() that would *not* grab references on anything other than IOVEC and UBUF (would advance the iterator, same as iov_iter_get_pages2(), though). Then iov_iter_get_...() would become a wrapper for that. After that - look into switching the users of ..._get_... to ..._find_.... Hadn't done much in that direction yet, though - need to redo the analysis first. That primitive might very well do FOLL_PIN instead of FOLL_GET for IOVEC and UBUF...