blob: 36ece095ff172500d9830dfed41a74147afa6d51 [file] [log] [blame]
Akinobu Mitade1ba092006-12-08 02:39:42 -08001Fault injection capabilities infrastructure
2===========================================
3
4See also drivers/md/faulty.c and "every_nth" module option for scsi_debug.
5
6
7Available fault injection capabilities
8--------------------------------------
9
10o failslab
11
12 injects slab allocation failures. (kmalloc(), kmem_cache_alloc(), ...)
13
14o fail_page_alloc
15
16 injects page allocation failures. (alloc_pages(), get_free_pages(), ...)
17
18o fail_make_request
19
Don Mullis5d0ffa22006-12-08 02:39:50 -080020 injects disk IO errors on devices permitted by setting
Akinobu Mitade1ba092006-12-08 02:39:42 -080021 /sys/block/<device>/make-it-fail or
22 /sys/block/<device>/<partition>/make-it-fail. (generic_make_request())
23
24Configure fault-injection capabilities behavior
25-----------------------------------------------
26
27o debugfs entries
28
29fault-inject-debugfs kernel module provides some debugfs entries for runtime
30configuration of fault-injection capabilities.
31
Don Mullis5d0ffa22006-12-08 02:39:50 -080032- /debug/fail*/probability:
Akinobu Mitade1ba092006-12-08 02:39:42 -080033
34 likelihood of failure injection, in percent.
35 Format: <percent>
36
Don Mullis5d0ffa22006-12-08 02:39:50 -080037 Note that one-failure-per-hundred is a very high error rate
38 for some testcases. Consider setting probability=100 and configure
39 /debug/fail*/interval for such testcases.
Akinobu Mitade1ba092006-12-08 02:39:42 -080040
Don Mullis5d0ffa22006-12-08 02:39:50 -080041- /debug/fail*/interval:
Akinobu Mitade1ba092006-12-08 02:39:42 -080042
43 specifies the interval between failures, for calls to
44 should_fail() that pass all the other tests.
45
46 Note that if you enable this, by setting interval>1, you will
47 probably want to set probability=100.
48
Don Mullis5d0ffa22006-12-08 02:39:50 -080049- /debug/fail*/times:
Akinobu Mitade1ba092006-12-08 02:39:42 -080050
51 specifies how many times failures may happen at most.
52 A value of -1 means "no limit".
53
Don Mullis5d0ffa22006-12-08 02:39:50 -080054- /debug/fail*/space:
Akinobu Mitade1ba092006-12-08 02:39:42 -080055
56 specifies an initial resource "budget", decremented by "size"
57 on each call to should_fail(,size). Failure injection is
58 suppressed until "space" reaches zero.
59
Don Mullis5d0ffa22006-12-08 02:39:50 -080060- /debug/fail*/verbose
Akinobu Mitade1ba092006-12-08 02:39:42 -080061
62 Format: { 0 | 1 | 2 }
Don Mullis5d0ffa22006-12-08 02:39:50 -080063 specifies the verbosity of the messages when failure is
64 injected. '0' means no messages; '1' will print only a single
65 log line per failure; '2' will print a call trace too -- useful
66 to debug the problems revealed by fault injection.
Akinobu Mitade1ba092006-12-08 02:39:42 -080067
Don Mullis5d0ffa22006-12-08 02:39:50 -080068- /debug/fail*/task-filter:
Akinobu Mitade1ba092006-12-08 02:39:42 -080069
Don Mullis5d0ffa22006-12-08 02:39:50 -080070 Format: { 'Y' | 'N' }
71 A value of 'N' disables filtering by process (default).
Akinobu Mitade1ba092006-12-08 02:39:42 -080072 Any positive value limits failures to only processes indicated by
73 /proc/<pid>/make-it-fail==1.
74
Don Mullis5d0ffa22006-12-08 02:39:50 -080075- /debug/fail*/require-start:
76- /debug/fail*/require-end:
77- /debug/fail*/reject-start:
78- /debug/fail*/reject-end:
Akinobu Mitade1ba092006-12-08 02:39:42 -080079
80 specifies the range of virtual addresses tested during
81 stacktrace walking. Failure is injected only if some caller
Akinobu Mita329409a2006-12-08 02:39:48 -080082 in the walked stacktrace lies within the required range, and
83 none lies within the rejected range.
84 Default required range is [0,ULONG_MAX) (whole of virtual address space).
85 Default rejected range is [0,0).
Akinobu Mitade1ba092006-12-08 02:39:42 -080086
Don Mullis5d0ffa22006-12-08 02:39:50 -080087- /debug/fail*/stacktrace-depth:
Akinobu Mitade1ba092006-12-08 02:39:42 -080088
89 specifies the maximum stacktrace depth walked during search
Don Mullis5d0ffa22006-12-08 02:39:50 -080090 for a caller within [require-start,require-end) OR
91 [reject-start,reject-end).
Akinobu Mitade1ba092006-12-08 02:39:42 -080092
Akinobu Mitade1ba092006-12-08 02:39:42 -080093- /debug/fail_page_alloc/ignore-gfp-highmem:
94
Don Mullis5d0ffa22006-12-08 02:39:50 -080095 Format: { 'Y' | 'N' }
96 default is 'N', setting it to 'Y' won't inject failures into
Akinobu Mitade1ba092006-12-08 02:39:42 -080097 highmem/user allocations.
98
99- /debug/failslab/ignore-gfp-wait:
100- /debug/fail_page_alloc/ignore-gfp-wait:
101
Don Mullis5d0ffa22006-12-08 02:39:50 -0800102 Format: { 'Y' | 'N' }
103 default is 'N', setting it to 'Y' will inject failures
Akinobu Mitade1ba092006-12-08 02:39:42 -0800104 only into non-sleep allocations (GFP_ATOMIC allocations).
105
Akinobu Mita54114992007-07-15 23:40:23 -0700106- /debug/fail_page_alloc/min-order:
107
108 specifies the minimum page allocation order to be injected
109 failures.
110
Akinobu Mitade1ba092006-12-08 02:39:42 -0800111o Boot option
112
113In order to inject faults while debugfs is not available (early boot time),
114use the boot option:
115
116 failslab=
117 fail_page_alloc=
118 fail_make_request=<interval>,<probability>,<space>,<times>
119
120How to add new fault injection capability
121-----------------------------------------
122
123o #include <linux/fault-inject.h>
124
125o define the fault attributes
126
127 DECLARE_FAULT_INJECTION(name);
128
129 Please see the definition of struct fault_attr in fault-inject.h
130 for details.
131
Don Mullis5d0ffa22006-12-08 02:39:50 -0800132o provide a way to configure fault attributes
Akinobu Mitade1ba092006-12-08 02:39:42 -0800133
134- boot option
135
136 If you need to enable the fault injection capability from boot time, you can
Don Mullis5d0ffa22006-12-08 02:39:50 -0800137 provide boot option to configure it. There is a helper function for it:
Akinobu Mitade1ba092006-12-08 02:39:42 -0800138
Don Mullis5d0ffa22006-12-08 02:39:50 -0800139 setup_fault_attr(attr, str);
Akinobu Mitade1ba092006-12-08 02:39:42 -0800140
141- debugfs entries
142
143 failslab, fail_page_alloc, and fail_make_request use this way.
Don Mullis5d0ffa22006-12-08 02:39:50 -0800144 Helper functions:
Akinobu Mitade1ba092006-12-08 02:39:42 -0800145
Don Mullis5d0ffa22006-12-08 02:39:50 -0800146 init_fault_attr_entries(entries, attr, name);
147 void cleanup_fault_attr_entries(entries);
Akinobu Mitade1ba092006-12-08 02:39:42 -0800148
149- module parameters
150
151 If the scope of the fault injection capability is limited to a
152 single kernel module, it is better to provide module parameters to
153 configure the fault attributes.
154
155o add a hook to insert failures
156
Don Mullis5d0ffa22006-12-08 02:39:50 -0800157 Upon should_fail() returning true, client code should inject a failure.
Akinobu Mitade1ba092006-12-08 02:39:42 -0800158
Don Mullis5d0ffa22006-12-08 02:39:50 -0800159 should_fail(attr, size);
Akinobu Mitade1ba092006-12-08 02:39:42 -0800160
161Application Examples
162--------------------
163
164o inject slab allocation failures into module init/cleanup code
165
166------------------------------------------------------------------------------
167#!/bin/bash
168
169FAILCMD=Documentation/fault-injection/failcmd.sh
170BLACKLIST="root_plug evbug"
171
172FAILNAME=failslab
173echo Y > /debug/$FAILNAME/task-filter
174echo 10 > /debug/$FAILNAME/probability
175echo 100 > /debug/$FAILNAME/interval
176echo -1 > /debug/$FAILNAME/times
177echo 2 > /debug/$FAILNAME/verbose
Akinobu Mitade1ba092006-12-08 02:39:42 -0800178echo 1 > /debug/$FAILNAME/ignore-gfp-wait
179
180blacklist()
181{
182 echo $BLACKLIST | grep $1 > /dev/null 2>&1
183}
184
185oops()
186{
187 dmesg | grep BUG > /dev/null 2>&1
188}
189
190find /lib/modules/`uname -r` -name '*.ko' -exec basename {} .ko \; |
191 while read i
192 do
193 oops && exit 1
194
195 if ! blacklist $i
196 then
197 echo inserting $i...
198 bash $FAILCMD modprobe $i
199 fi
200 done
201
202lsmod | awk '{ if ($3 == 0) { print $1 } }' |
203 while read i
204 do
205 oops && exit 1
206
207 if ! blacklist $i
208 then
209 echo removing $i...
210 bash $FAILCMD modprobe -r $i
211 fi
212 done
213
214------------------------------------------------------------------------------
215
216o inject slab allocation failures only for a specific module
217
218------------------------------------------------------------------------------
219#!/bin/bash
220
221FAILMOD=Documentation/fault-injection/failmodule.sh
222
223echo injecting errors into the module $1...
224
225modprobe $1
226bash $FAILMOD failslab $1 10
227echo 25 > /debug/failslab/probability
228
229------------------------------------------------------------------------------
230