All of lore.kernel.org
 help / color / mirror / Atom feed
From: "syzbot" <syzbot@kernel.org>
To: syzkaller-upstream-moderation@googlegroups.com
Cc: syzbot@lists.linux.dev
Subject: [PATCH RFC] md: clear pending reshape parameters in __md_stop()
Date: Wed,  9 Sep 2026 21:45:11 +0000 (UTC)	[thread overview]
Message-ID: <0bbc5530-3021-49ec-a8cd-a006c2639d53@mail.kernel.org> (raw)

When reconfiguring an active MD array (for instance, updating the number of
disks via the raid_disks sysfs attribute), pending reshape parameters such
as delta_disks, new_level, new_layout, and new_chunk_sectors are stored in
struct mddev. At this stage, the reshape has not yet started running and
mddev->reshape_position remains set to MaxSector.

If userspace deactivates or stops the array before the reshape begins (such
as by writing "inactive" to array_state), do_md_stop() invokes __md_stop().
Unlike a full stop which invokes md_clean() to clear all configuration
fields, __md_stop() detaches the personality and frees private data but
leaves the pending reshape parameters in struct mddev. When the array is
later restarted (e.g. by writing "active" to array_state), md_run() calls
the personality's run method, raid5_run(). Because mddev->reshape_position
is still MaxSector, raid5_run() assumes no reshape is taking place and
expects no pending reshape parameters, causing BUG_ON(mddev->delta_disks !=
0) to trigger:

kernel BUG at drivers/md/raid5.c:8117!
Oops: invalid opcode: 0000 [#1] SMP
RIP: 0010:raid5_run+0x2550/0x2560 drivers/md/raid5.c:8117
Call Trace:
 <TASK>
 md_run+0xc3d/0x1cd0 drivers/md/md.c:6779
 do_md_run+0x35/0x720 drivers/md/md.c:6880
 array_state_store+0x958/0xe90 drivers/md/md.c:-1
 md_attr_store+0x3b7/0x640 drivers/md/md.c:6158
 kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
 vfs_write+0x612/0xba0 fs/read_write.c:687
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
 </TASK>

Fix this by clearing pending reshape parameters in __md_stop() if no
reshape is currently running (mddev->reshape_position == MaxSector).
Specifically, reset delta_disks and reshape_backwards to 0, and reset
new_level, new_layout, and new_chunk_sectors to level, layout, and
chunk_sectors, respectively. If a reshape is actively in progress
(mddev->reshape_position != MaxSector), the parameters are preserved so the
reshape can resume when the array is restarted.

Fixes: 91adb56473fe ("md/raid5: refactor raid5 "run"")
Assisted-by: Gemini:gemini-3.8-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+1f5a7de91d547763f4c8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1f5a7de91d547763f4c8
Link: https://syzkaller.appspot.com/ai_job?id=ebe142c5-4399-48c5-aad4-4ee23cb2055d
To: <linux-raid@vger.kernel.org>
To: "Song Liu" <song@kernel.org>
To: "Yu Kuai" <yukuai@fygo.io>
To: "NeilBrown" <neilb@suse.de>
Cc: <linux-kernel@vger.kernel.org>
Cc: "Li Nan" <magiclinan@didiglobal.com>
Cc: "Xiao Ni" <xiao@kernel.org>

---
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 680b34a63..38ab41bbc 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -7095,6 +7095,14 @@ static void __md_stop(struct mddev *mddev)
 	mddev->private = NULL;
 	put_pers(pers);
 	clear_bit(MD_RECOVERY_FROZEN, &mddev->recovery);
+
+	if (mddev->reshape_position == MaxSector) {
+		mddev->delta_disks = 0;
+		mddev->reshape_backwards = 0;
+		mddev->new_level = mddev->level;
+		mddev->new_layout = mddev->layout;
+		mddev->new_chunk_sectors = mddev->chunk_sectors;
+	}
 }
 
 void md_stop(struct mddev *mddev)


base-commit: df2908090cda368b01ff43709f51890076c56157
-- 
This is an AI-generated patch subject to moderation.
Reply with '#syz upstream' to Sign-off the patch as a human author
and send it to the upstream kernel mailing lists.
Reply with '#syz reject' to reject it ('#syz unreject' to undo).

See https://goo.gle/syzbot-ai-patches for information about AI-generated patches.
You can comment on the patch as usual, syzbot will try to address
the comments and send a new version of the patch if necessary.
syzbot engineers can be reached at syzkaller@googlegroups.com.

                 reply	other threads:[~2026-09-09 21:45 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0bbc5530-3021-49ec-a8cd-a006c2639d53@mail.kernel.org \
    --to=syzbot@kernel.org \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-upstream-moderation@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.