From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v4 05/28] libmultipath: Add support for mpath_device management
Date: Thu, 23 Jul 2026 09:58:32 +0000 [thread overview]
Message-ID: <20260723095834.326961F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723093627.2327456-6-john.g.garry@oracle.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] mpath_delete_device fails to clear the device from the current_path array before calling mpath_synchronize, guaranteeing an RCU Use-After-Free.
- [Low] Duplicate function declaration of `mpath_synchronize`.
--
--- Patch [5]: [PATCH v4 05/28] libmultipath: Add support for mpath_device management ---
commit 729c9713b67dacb1c3c3c943a84db42ae105702d
Author: John Garry <john.g.garry@oracle.com>
libmultipath: Add support for mpath_device management
Add support to add or remove a mpath_device as a path. This implements
functionality similar to NVMe equivalents for path management.
> diff --git a/include/linux/multipath.h b/include/linux/multipath.h
> index 57d13eb1450cd..6915c2a979642 100644
> --- a/include/linux/multipath.h
> +++ b/include/linux/multipath.h
[ ... ]
> @@ -89,6 +92,17 @@ static inline enum mpath_iopolicy_e mpath_read_iopolicy(
> void mpath_synchronize(struct mpath_head *mpath_head);
> int mpath_set_iopolicy(const char *str, enum mpath_iopolicy_e *iopolicy);
> int mpath_get_iopolicy(char *buf, int iopolicy);
> +bool mpath_clear_current_path(struct mpath_device *mpath_device);
> +void mpath_synchronize(struct mpath_head *mpath_head);
[Severity: Low]
This isn't a bug, but should we remove this duplicate declaration of
mpath_synchronize() since it is already declared just a few lines above?
> +int mpath_add_device(struct mpath_device *mpath_device,
[ ... ]
> diff --git a/lib/multipath.c b/lib/multipath.c
> index 448d879abb354..20c633ad7e1df 100644
> --- a/lib/multipath.c
> +++ b/lib/multipath.c
[ ... ]
> @@ -50,6 +50,87 @@ void mpath_synchronize(struct mpath_head *mpath_head)
[ ... ]
> +bool mpath_delete_device(struct mpath_device *mpath_device)
> +{
> + bool empty;
> +
> + mutex_lock(&mpath_device->mpath_head->lock);
> + list_del_rcu(&mpath_device->siblings);
> + empty = list_empty(&mpath_device->mpath_head->dev_list);
> + mutex_unlock(&mpath_device->mpath_head->lock);
> +
> + mpath_synchronize(mpath_device->mpath_head);
[Severity: High]
Does this leave a dangling pointer in the current_path array that could
lead to a use-after-free?
Since the deleted device isn't cleared from mpath_head->current_path[],
new I/O submissions starting after mpath_synchronize() returns could still
read the device from current_path and use it after it's been freed.
If a caller tries to avoid this by calling mpath_clear_current_path()
before mpath_delete_device(), concurrent I/O could potentially re-select
the device from dev_list and place it back into current_path before the
deletion acquires the list lock.
Should mpath_clear_current_path() be called here, exactly between
list_del_rcu() and mpath_synchronize()?
> +
> + return empty;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260723093627.2327456-1-john.g.garry@oracle.com?part=5
next prev parent reply other threads:[~2026-07-23 9:58 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 9:35 [PATCH v4 00/28] Native SCSI Multipath support John Garry
2026-07-23 9:35 ` [PATCH v4 01/28] libmultipath: Add initial framework John Garry
2026-07-23 9:50 ` sashiko-bot
2026-07-23 10:19 ` John Garry
2026-07-23 9:36 ` [PATCH v4 02/28] libmultipath: Add basic gendisk support John Garry
2026-07-23 9:57 ` sashiko-bot
2026-07-23 10:34 ` John Garry
2026-07-23 9:36 ` [PATCH v4 03/28] libmultipath: Add path selection support John Garry
2026-07-23 9:55 ` sashiko-bot
2026-07-23 10:28 ` John Garry
2026-07-23 9:36 ` [PATCH v4 04/28] libmultipath: Add bio handling John Garry
2026-07-23 9:36 ` [PATCH v4 05/28] libmultipath: Add support for mpath_device management John Garry
2026-07-23 9:58 ` sashiko-bot [this message]
2026-07-23 10:36 ` John Garry
2026-07-23 9:36 ` [PATCH v4 06/28] libmultipath: Add delayed removal support John Garry
2026-07-23 9:57 ` sashiko-bot
2026-07-23 10:33 ` John Garry
2026-07-23 9:36 ` [PATCH v4 07/28] libmultipath: Add sysfs helpers John Garry
2026-07-23 10:05 ` sashiko-bot
2026-07-23 10:37 ` John Garry
2026-07-23 9:36 ` [PATCH v4 08/28] libmultipath: Add mpath_bdev_report_zones() John Garry
2026-07-23 10:15 ` sashiko-bot
2026-07-23 10:39 ` John Garry
2026-07-23 9:36 ` [PATCH v4 09/28] libmultipath: Add support for block device IOCTL John Garry
2026-07-23 10:09 ` sashiko-bot
2026-07-23 10:38 ` John Garry
2026-07-23 9:36 ` [PATCH v4 10/28] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-23 9:36 ` [PATCH v4 11/28] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-23 9:36 ` [PATCH v4 12/28] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-23 10:14 ` sashiko-bot
2026-07-23 9:36 ` [PATCH v4 13/28] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-23 10:16 ` sashiko-bot
2026-07-23 10:47 ` John Garry
2026-07-23 9:36 ` [PATCH v4 14/28] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-23 9:36 ` [PATCH v4 15/28] scsi-multipath: support iopolicy John Garry
2026-07-23 10:20 ` sashiko-bot
2026-07-23 10:51 ` John Garry
2026-07-23 9:36 ` [PATCH v4 16/28] scsi-multipath: clone each bio John Garry
2026-07-23 10:27 ` sashiko-bot
2026-07-23 10:55 ` John Garry
2026-07-23 9:36 ` [PATCH v4 17/28] scsi-multipath: clear path when device is blocked John Garry
2026-07-23 10:33 ` sashiko-bot
2026-07-23 11:01 ` John Garry
2026-07-23 9:36 ` [PATCH v4 18/28] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-23 10:39 ` sashiko-bot
2026-07-23 11:15 ` John Garry
2026-07-23 9:36 ` [PATCH v4 19/28] scsi-multipath: failover handling John Garry
2026-07-23 10:36 ` sashiko-bot
2026-07-23 11:03 ` John Garry
2026-07-23 9:36 ` [PATCH v4 20/28] scsi-multipath: provide callbacks for path state John Garry
2026-07-23 10:36 ` sashiko-bot
2026-07-23 11:05 ` John Garry
2026-07-23 9:36 ` [PATCH v4 21/28] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-23 10:32 ` sashiko-bot
2026-07-23 10:57 ` John Garry
2026-07-23 9:36 ` [PATCH v4 22/28] scsi-multipath: add delayed disk removal support John Garry
2026-07-23 10:39 ` sashiko-bot
2026-07-23 11:21 ` John Garry
2026-07-23 9:36 ` [PATCH v4 23/28] scsi: sd: add multipath disk class John Garry
2026-07-23 10:39 ` sashiko-bot
2026-07-23 11:21 ` John Garry
2026-07-23 9:36 ` [PATCH v4 24/28] scsi: sd: add multipath disk attr groups John Garry
2026-07-23 10:47 ` sashiko-bot
2026-07-23 11:22 ` John Garry
2026-07-23 9:36 ` [PATCH v4 25/28] scsi: sd: support multipath disk John Garry
2026-07-23 10:47 ` sashiko-bot
2026-07-23 11:27 ` John Garry
2026-07-23 16:52 ` John Garry
2026-07-23 9:36 ` [PATCH v4 26/28] scsi: sd: add mpath_dev file John Garry
2026-07-23 11:07 ` sashiko-bot
2026-07-23 11:30 ` John Garry
2026-07-23 9:36 ` [PATCH v4 27/28] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-23 10:52 ` sashiko-bot
2026-07-23 11:30 ` John Garry
2026-07-23 9:36 ` [PATCH v4 28/28] scsi: sd: add mpath_queue_depth " John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260723095834.326961F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.