From: Hari Mishal <harimishal1@gmail.com>
To: Keith Busch <kbusch@kernel.org>, Jens Axboe <axboe@kernel.dk>,
Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>
Cc: Hannes Reinecke <hare@suse.de>,
Kanchan Joshi <joshi.k@samsung.com>,
Nitesh Shetty <nj.shetty@samsung.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org,
Hari Mishal <harimishal1@gmail.com>
Subject: [PATCH 0/2] nvme: fix racy access to FDP placement ID array
Date: Sat, 25 Jul 2026 15:51:09 +0200 [thread overview]
Message-ID: <20260725135111.14041-1-harimishal1@gmail.com> (raw)
nvme_ns_head can be shared across multiple nvme_ns paths (multipath,
or dual-port/multi-controller subsystems). nvme_query_fdp_info()
populates head->nr_plids/head->plids the first time a namespace's
FDP configuration is registered, but nothing protects that pair from
concurrent access - two paths scanning the same namespace at the
same time can race to populate it, and depending on how the writes
interleave a concurrent reader can hit a NULL dereference or an
out-of-bounds read.
Patch 1 adds a spinlock and closes the race.
Patch 2 is a small, unrelated cleanup on code sitting right next to
what patch 1 touches: it drops a WARN_ON_ONCE that turns out to be
unreachable through any current path, since the value it guards
against is already validated upstream in the block layer and F2FS
before a bio ever carries it. Happy to drop this one or send it
separately if you'd rather keep it out of this series.
Hari Mishal (2):
nvme: fix racy access to FDP placement ID array
nvme: drop WARN_ON_ONCE on write_stream bounds check
drivers/nvme/host/core.c | 63 ++++++++++++++++++++++++++--------------
drivers/nvme/host/nvme.h | 1 +
2 files changed, 43 insertions(+), 21 deletions(-)
--
2.43.0
next reply other threads:[~2026-07-25 13:51 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-25 13:51 Hari Mishal [this message]
2026-07-25 13:51 ` [PATCH 1/2] nvme: fix racy access to FDP placement ID array Hari Mishal
2026-07-27 13:31 ` Kanchan Joshi
2026-07-27 14:22 ` Kanchan Joshi
2026-07-25 13:51 ` [PATCH 2/2] nvme: drop WARN_ON_ONCE on write_stream bounds check Hari Mishal
2026-07-27 14:24 ` Keith Busch
2026-07-27 19:19 ` Greg Kroah-Hartman
2026-07-27 22:51 ` Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260725135111.14041-1-harimishal1@gmail.com \
--to=harimishal1@gmail.com \
--cc=axboe@kernel.dk \
--cc=gregkh@linuxfoundation.org \
--cc=hare@suse.de \
--cc=hch@lst.de \
--cc=joshi.k@samsung.com \
--cc=kbusch@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=nj.shetty@samsung.com \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.