All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jens Axboe <axboe@suse.de>
To: Badari Pulavarty <badari@us.ibm.com>
Cc: merlin hughes <merlin@merlin.org>, linux-scsi@vger.kernel.org
Subject: Re: possible use-after-free in 2.5.44 scsi changes
Date: Thu, 31 Oct 2002 16:12:12 +0100	[thread overview]
Message-ID: <20021031151212.GG6549@suse.de> (raw)
In-Reply-To: <20021031150408.GF6549@suse.de>

On Thu, Oct 31 2002, Jens Axboe wrote:
> On Wed, Oct 30 2002, Badari Pulavarty wrote:
> > > >- Badari
> > > 
> > > Hi; if it's of any use, the patch doesn't seem to solve the scsi
> > > problem for me (2.5.44-bk3-badari). I get the usual 'Incorrect number
> > > of segments...' and random kernel death during the boot process.
> > > 
> > > Merlin
> > 
> > Hi Merlin,
> > 
> > I am looking at the output  of your problem ..
> > 
> > 
> > Oct 28 12:36:09 badb kernel: Incorrect number of segments after building list 
> > Oct 28 12:36:09 badb kernel: counted 2, received 1 
> > Oct 28 12:36:09 badb kernel: req nr_sec 8, cur_nr_sec 8 
> > Oct 28 12:36:09 badb kernel: end_request: I/O error, dev 08:40, sector 6784528 
> > Oct 28 12:36:09 badb kernel: raid5: Disk failure on scsi/host0/bus0/target4/lun0/part7, disabling device. Operation continuing on 4 devices 
> > 
> > Huh !! Your IO size is only 4K. You are using 2 sg entries ?
> 
> Even weirder, nr_sec == cur_nr_sec so there can only be one segment or
> something is corrupted...

Ah wait, I think I may know at least what is happening in this case.
I've seen numerous reports of software raid problems botching bio's, and
this above one could easily be explained with one of the bio's having
!bi_size. In fact, it's about the only explanation, otherwise there's
just no way we can have nr_sec == cur_nr_sec unless only _one_ bio is
attached to the request.

Merlin, please also add a

	blk_dump_rq_flags(req, "scsi_init_io");

to drivers/scsi/scsi_lib.c:scsi_init_io() before it calls
scsi_end_request() and kills the request (right after the incorrect
segment complaining).

Badari, I'm not so sure that Merlin's and your bug are the same. Is
yours solved by the patch I sent out earlier? AFAICT, that should fix
the segment miscounting.

-- 
Jens Axboe


  reply	other threads:[~2002-10-31 15:12 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-25  1:39 possible use-after-free in 2.5.44 scsi changes Andrew Morton
2002-10-25  4:06 ` Doug Ledford
2002-10-25  4:40   ` Andrew Morton
2002-10-25 14:21     ` James Bottomley
2002-10-25  4:07 ` Patrick Mansfield
2002-10-25 14:16 ` James Bottomley
2002-10-25 18:34   ` James Bottomley
2002-10-25 18:49     ` Mike Anderson
2002-10-25 19:08     ` Patrick Mansfield
2002-10-25 19:41       ` Mike Anderson
2002-10-25 19:47         ` Jens Axboe
2002-10-25 22:14           ` James Bottomley
2002-10-25 22:18             ` Andrew Morton
2002-10-25 22:23     ` Badari Pulavarty
2002-10-26  0:13       ` James Bottomley
2002-10-26  0:18         ` Mike Anderson
2002-10-26  9:29         ` Jens Axboe
2002-10-27  0:50           ` James Bottomley
2002-10-27 21:20             ` Jens Axboe
2002-10-27 21:37               ` James Bottomley
2002-10-27 21:54                 ` Jens Axboe
2002-10-30 17:39                   ` Badari Pulavarty
2002-10-30 18:16                     ` Jens Axboe
2002-10-30 19:31                       ` Badari Pulavarty
2002-10-30 21:36                         ` merlin hughes
2002-10-30 22:19                           ` Badari Pulavarty
2002-10-31  2:17                             ` merlin
2002-10-31 13:18                               ` Jens Axboe
2002-10-31 14:41                                 ` merlin
2002-10-31 14:46                                   ` Jens Axboe
2002-10-31 15:04                             ` Jens Axboe
2002-10-31 15:12                               ` Jens Axboe [this message]
2002-10-31 17:41                                 ` merlin
2002-10-30 20:35                       ` David S. Miller
2002-10-30 22:03                         ` Badari Pulavarty
  -- strict thread matches above, loose matches on Subject: below --
2002-10-31 17:57 Badari Pulavarty
2002-10-31 18:46 ` Jens Axboe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20021031151212.GG6549@suse.de \
    --to=axboe@suse.de \
    --cc=badari@us.ibm.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=merlin@merlin.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.