* [PATCH RFC] md: clear pending reshape parameters in __md_stop()
@ 2026-09-09 21:45 syzbot
0 siblings, 0 replies; only message in thread
From: syzbot @ 2026-09-09 21:45 UTC (permalink / raw)
To: syzkaller-upstream-moderation; +Cc: syzbot
When reconfiguring an active MD array (for instance, updating the number of
disks via the raid_disks sysfs attribute), pending reshape parameters such
as delta_disks, new_level, new_layout, and new_chunk_sectors are stored in
struct mddev. At this stage, the reshape has not yet started running and
mddev->reshape_position remains set to MaxSector.
If userspace deactivates or stops the array before the reshape begins (such
as by writing "inactive" to array_state), do_md_stop() invokes __md_stop().
Unlike a full stop which invokes md_clean() to clear all configuration
fields, __md_stop() detaches the personality and frees private data but
leaves the pending reshape parameters in struct mddev. When the array is
later restarted (e.g. by writing "active" to array_state), md_run() calls
the personality's run method, raid5_run(). Because mddev->reshape_position
is still MaxSector, raid5_run() assumes no reshape is taking place and
expects no pending reshape parameters, causing BUG_ON(mddev->delta_disks !=
0) to trigger:
kernel BUG at drivers/md/raid5.c:8117!
Oops: invalid opcode: 0000 [#1] SMP
RIP: 0010:raid5_run+0x2550/0x2560 drivers/md/raid5.c:8117
Call Trace:
<TASK>
md_run+0xc3d/0x1cd0 drivers/md/md.c:6779
do_md_run+0x35/0x720 drivers/md/md.c:6880
array_state_store+0x958/0xe90 drivers/md/md.c:-1
md_attr_store+0x3b7/0x640 drivers/md/md.c:6158
kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Fix this by clearing pending reshape parameters in __md_stop() if no
reshape is currently running (mddev->reshape_position == MaxSector).
Specifically, reset delta_disks and reshape_backwards to 0, and reset
new_level, new_layout, and new_chunk_sectors to level, layout, and
chunk_sectors, respectively. If a reshape is actively in progress
(mddev->reshape_position != MaxSector), the parameters are preserved so the
reshape can resume when the array is restarted.
Fixes: 91adb56473fe ("md/raid5: refactor raid5 "run"")
Assisted-by: Gemini:gemini-3.8-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+1f5a7de91d547763f4c8@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1f5a7de91d547763f4c8
Link: https://syzkaller.appspot.com/ai_job?id=ebe142c5-4399-48c5-aad4-4ee23cb2055d
To: <linux-raid@vger.kernel.org>
To: "Song Liu" <song@kernel.org>
To: "Yu Kuai" <yukuai@fygo.io>
To: "NeilBrown" <neilb@suse.de>
Cc: <linux-kernel@vger.kernel.org>
Cc: "Li Nan" <magiclinan@didiglobal.com>
Cc: "Xiao Ni" <xiao@kernel.org>
---
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 680b34a63..38ab41bbc 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -7095,6 +7095,14 @@ static void __md_stop(struct mddev *mddev)
mddev->private = NULL;
put_pers(pers);
clear_bit(MD_RECOVERY_FROZEN, &mddev->recovery);
+
+ if (mddev->reshape_position == MaxSector) {
+ mddev->delta_disks = 0;
+ mddev->reshape_backwards = 0;
+ mddev->new_level = mddev->level;
+ mddev->new_layout = mddev->layout;
+ mddev->new_chunk_sectors = mddev->chunk_sectors;
+ }
}
void md_stop(struct mddev *mddev)
base-commit: df2908090cda368b01ff43709f51890076c56157
--
This is an AI-generated patch subject to moderation.
Reply with '#syz upstream' to Sign-off the patch as a human author
and send it to the upstream kernel mailing lists.
Reply with '#syz reject' to reject it ('#syz unreject' to undo).
See https://goo.gle/syzbot-ai-patches for information about AI-generated patches.
You can comment on the patch as usual, syzbot will try to address
the comments and send a new version of the patch if necessary.
syzbot engineers can be reached at syzkaller@googlegroups.com.
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-09 21:45 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 21:45 [PATCH RFC] md: clear pending reshape parameters in __md_stop() syzbot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.