All of lore.kernel.org
 help / color / mirror / Atom feed
From: Krystian Kaniewski <krystianmkaniewski@gmail.com>
To: syzbot <syzbot@kernel.org>,
	syzkaller-upstream-moderation@googlegroups.com
Cc: syzbot@lists.linux.dev
Subject: Re: [PATCH RFC v4] nbd: skip queue limits update for size-only reconfigure
Date: Tue, 28 Jul 2026 12:21:57 +0200	[thread overview]
Message-ID: <12eb7cfa-43df-4a09-bc51-00aaadef7309@gmail.com> (raw)
In-Reply-To: <91ae453b-d78d-443c-9f19-4588fa65447a@mail.kernel.org>

#syz upstream

On 7/23/2026 11:49 PM, syzbot wrote:
> Commit 242a49e5c878 ("nbd: freeze the queue for queue limits updates")
> correctly added queue freezing for live updates of real queue limits.
> However, nbd_set_size() is also used for capacity-only generic netlink
> updates, so the freeze is unnecessarily broad for the reported request.
>
> When an NBD server becomes unresponsive, it leaves I/O in flight. An
> unnecessary queue freeze during a size-only reconfigure will wait forever
> for these in-flight I/Os to complete while the global genl_mutex is held,
> leading to a global generic netlink stall.
>
> A size-only reconfigure can update config->bytesize and disk capacity
> directly because the effective block size and all other queue limits stay
> unchanged.
>
> This patch introduces nbd_size_set() to handle size-only updates directly
> without freezing the queue or committing queue limits. Capacity-only
> generic netlink reconfiguration no longer freezes the queue, while startup
> and real block-size changes continue to use the existing frozen limits
> update via nbd_set_size().
>
> Fixes: 242a49e5c878 ("nbd: freeze the queue for queue limits updates")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: syzbot <syzbot+f272bbfbf8498ddadea5@syzkaller.appspotmail.com>
> Closes: https://syzkaller.appspot.com/bug?extid=f272bbfbf8498ddadea5
> Link: https://syzkaller.appspot.com/ai_job?id=786b3bd0-fdad-4252-9e86-7a6a35c3b756
> To: "Jens Axboe" <axboe@kernel.dk>
> To: "Josef Bacik" <josef@toxicpanda.com>
> To: <linux-block@vger.kernel.org>
> To: <nbd@other.debian.org>
> To: "Christoph Hellwig" <hch@lst.de>
> Cc: <linux-kernel@vger.kernel.org>
>
> ---
> v4:
> - Removed stack traces from the commit message.
> - Replaced "system-wide deadlock" with "global generic netlink stall" in the commit message.
>
> v3:
> - Removed the unrelated decrement of nbd_total_devices in nbd_dev_remove().
> - Corrected the referenced commit title of 242a49e5c878 in the description.
> - Clarified that capacity-only generic netlink reconfiguration no longer freezes the queue, while startup and real block-size changes continue to do so.
> https://lore.kernel.org/all/130f544a-70fd-4ca0-91e8-08824170c91b@mail.kernel.org/T/
>
> v2:
> - Replaced the approach of using parallel netlink ops and custom timeouts with skipping queue limits updates for size-only reconfigurations.
> - Introduced nbd_size_set() and nbd_size_update() to update device capacity directly without freezing the queue when the block size does not change.
> - Retained queue freezing only for actual block-size changes.
> - Added decrement of nbd_total_devices in nbd_dev_remove().
> https://lore.kernel.org/all/514764a5-5acd-4e5d-a8eb-f40c403e7514@mail.kernel.org/T/
>
> v1:
> https://lore.kernel.org/all/69ff9a21-60be-4e97-bc8f-a59e739fd982@mail.kernel.org/T/
> ---
> diff --git a/drivers/block/nbd.c b/drivers/block/nbd.c
> index fe63f3c55..567b031ec 100644
> --- a/drivers/block/nbd.c
> +++ b/drivers/block/nbd.c
> @@ -331,6 +331,27 @@ static void nbd_mark_nsock_dead(struct nbd_device *nbd, struct nbd_sock *nsock,
>   	nsock->sent = 0;
>   }
>   
> +static void nbd_size_update(struct nbd_device *nbd)
> +{
> +	struct nbd_config *config = nbd->config;
> +
> +	if (max_part)
> +		set_bit(GD_NEED_PART_SCAN, &nbd->disk->state);
> +	if (!set_capacity_and_notify(nbd->disk, config->bytesize >> 9))
> +		kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE);
> +}
> +
> +static int nbd_size_set(struct nbd_device *nbd, loff_t bytesize)
> +{
> +	if (bytesize < 0)
> +		return -EINVAL;
> +
> +	nbd->config->bytesize = bytesize;
> +	if (nbd->pid)
> +		nbd_size_update(nbd);
> +	return 0;
> +}
> +
>   static int nbd_set_size(struct nbd_device *nbd, loff_t bytesize, loff_t blksize)
>   {
>   	struct queue_limits lim;
> @@ -375,10 +396,7 @@ static int nbd_set_size(struct nbd_device *nbd, loff_t bytesize, loff_t blksize)
>   	if (error)
>   		return error;
>   
> -	if (max_part)
> -		set_bit(GD_NEED_PART_SCAN, &nbd->disk->state);
> -	if (!set_capacity_and_notify(nbd->disk, bytesize >> 9))
> -		kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE);
> +	nbd_size_update(nbd);
>   	return 0;
>   }
>   
> @@ -2062,11 +2080,19 @@ static int nbd_genl_size_set(struct genl_info *info, struct nbd_device *nbd)
>   	if (info->attrs[NBD_ATTR_SIZE_BYTES])
>   		bytes = nla_get_u64(info->attrs[NBD_ATTR_SIZE_BYTES]);
>   
> -	if (info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES])
> +	if (info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]) {
>   		bsize = nla_get_u64(info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]);
> +		if (!bsize)
> +			bsize = 1u << NBD_DEF_BLKSIZE_BITS;
> +		if (blk_validate_block_size(bsize))
> +			return -EINVAL;
> +	}
>   
> -	if (bytes != config->bytesize || bsize != nbd_blksize(config))
> -		return nbd_set_size(nbd, bytes, bsize);
> +	if (bytes != config->bytesize || bsize != nbd_blksize(config)) {
> +		if (bsize != nbd_blksize(config))
> +			return nbd_set_size(nbd, bytes, bsize);
> +		return nbd_size_set(nbd, bytes);
> +	}
>   	return 0;
>   }
>   
>
>
> base-commit: 8cd9520d35a6c38db6567e97dd93b1f11f185dc6

      reply	other threads:[~2026-07-28 10:22 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 21:49 [PATCH RFC v4] nbd: skip queue limits update for size-only reconfigure syzbot
2026-07-28 10:21 ` Krystian Kaniewski [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=12eb7cfa-43df-4a09-bc51-00aaadef7309@gmail.com \
    --to=krystianmkaniewski@gmail.com \
    --cc=syzbot@kernel.org \
    --cc=syzbot@lists.linux.dev \
    --cc=syzkaller-upstream-moderation@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.