From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v5 12/27] scsi-multipath: introduce scsi_device head structure
Date: Mon, 27 Jul 2026 15:15:47 +0000 [thread overview]
Message-ID: <20260727151547.AF75D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727144234.3802948-13-john.g.garry@oracle.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] The `smpdt` (mpath_head_template) is defined without implementing logically required callbacks, which will lead to a NULL pointer dereference.
- [High] scsi_mpath_unique_lun_id treats a 0-length Unique LUN ID as success, leading to unintended grouping of devices with empty IDs.
- [Low] The function `scsi_multipath_sysfs_group_visible` and the macro invocation `DEFINE_SIMPLE_SYSFS_GROUP_VISIBLE(scsi_multipath_sysfs)` are defined but never used.
--
--- Patch [12]: [PATCH v5 12/27] scsi-multipath: introduce scsi_device head structure ---
commit 0296ab446bccfc5a00926fcca72b8b18f69d4e30
Author: John Garry <john.garry@linux.dev>
Subject: scsi-multipath: introduce scsi_device head structure
Introduce a scsi_device head structure - scsi_mpath_head - to manage
multipathing for a scsi_device. This is similar to nvme_ns_head structure.
A list of scsi_mpath_head structures is managed to lookup for matching
multipathed scsi_device's.
> diff --git a/drivers/scsi/scsi_multipath.c b/drivers/scsi/scsi_multipath.c
> index 947f3e2103e6b..5d19ab6a89eb5 100644
> --- a/drivers/scsi/scsi_multipath.c
> +++ b/drivers/scsi/scsi_multipath.c
> @@ -70,6 +74,55 @@ static int scsi_mpath_unique_lun_id(struct scsi_device *sdev)
[Severity: High]
Does this function mistakenly treat a 0-length Unique LUN ID as success?
Looking at scsi_mpath_unique_lun_id() in drivers/scsi/scsi_multipath.c:
ret = scsi_vpd_lun_id(sdev, scsi_mpath_dev->device_id_str,
SCSI_MPATH_DEVICE_ID_LEN);
if (ret < 0)
return ret;
If a SCSI device responds with a valid VPD page 0x83 but a 0-length SCSI name
string, scsi_vpd_lun_id() returns 0. Since this code only checks if (ret < 0),
it will accept 0 as success.
This could cause the multipath subsystem to incorrectly group distinct devices
with empty IDs together, as strncmp("", "", 256) will match, routing I/O
intended for one disk to another entirely separate disk.
> return 0;
> }
>
> +static void scsi_mpath_head_release(struct device *dev)
[ ... ]
> +static bool scsi_multipath_sysfs_group_visible(struct kobject *kobj)
> +{
> + return true;
> +}
> +DEFINE_SIMPLE_SYSFS_GROUP_VISIBLE(scsi_multipath_sysfs)
[Severity: Low]
Are this function and macro invocation needed?
They appear to be defined but never used to gate an attribute group in this
patch.
> +
> +static const struct attribute_group *scsi_mpath_device_groups[] = {
[ ... ]
> @@ -89,6 +142,74 @@ static int scsi_multipath_sdev_init(struct scsi_device *sdev)
> return 0;
> }
>
> +static struct mpath_head_template smpdt = {
> +};
[Severity: High]
Can this empty template cause a NULL pointer dereference?
Because smpdt is defined as an empty struct, all its function pointers are
NULL. The multipath core unconditionally invokes template callbacks (such as
is_disabled and is_optimized) without checking for NULL.
When a multipath SCSI device is configured and processed, invoking these
callbacks could trigger a kernel panic.
> +
> +static struct scsi_mpath_head *scsi_mpath_alloc_head(char *vpd_id)
> +{
> + struct scsi_mpath_head *scsi_mpath_head;
[ ... ]
> + if (mpath_head_init(&scsi_mpath_head->mpath_head))
> + goto out_free;
> + scsi_mpath_head->mpath_head.mpdt = &smpdt;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727144234.3802948-1-john.g.garry@oracle.com?part=12
next prev parent reply other threads:[~2026-07-27 15:15 UTC|newest]
Thread overview: 71+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 14:42 [PATCH v5 00/27] Native SCSI Multipath support John Garry
2026-07-27 14:42 ` [PATCH v5 01/27] libmultipath: Add initial framework John Garry
2026-07-27 15:05 ` sashiko-bot
2026-07-27 15:12 ` John Garry
2026-07-27 14:42 ` [PATCH v5 02/27] libmultipath: Add basic gendisk support John Garry
2026-07-27 15:04 ` sashiko-bot
2026-07-27 15:15 ` John Garry
2026-07-27 14:42 ` [PATCH v5 03/27] libmultipath: Add path selection support John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:20 ` John Garry
2026-07-27 14:42 ` [PATCH v5 04/27] libmultipath: Add bio handling John Garry
2026-07-27 14:42 ` [PATCH v5 05/27] libmultipath: Add support for mpath_device management John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:23 ` John Garry
2026-07-27 14:42 ` [PATCH v5 06/27] libmultipath: Add delayed removal support John Garry
2026-07-27 15:00 ` sashiko-bot
2026-07-27 15:25 ` John Garry
2026-07-27 14:42 ` [PATCH v5 07/27] libmultipath: Add sysfs helpers John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:33 ` John Garry
2026-07-27 14:42 ` [PATCH v5 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-07-27 15:08 ` sashiko-bot
2026-07-27 15:31 ` John Garry
2026-07-27 14:42 ` [PATCH v5 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-27 14:42 ` [PATCH v5 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-27 14:42 ` [PATCH v5 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-27 18:59 ` sashiko-bot
2026-07-27 14:42 ` [PATCH v5 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-27 15:15 ` sashiko-bot [this message]
2026-07-27 15:37 ` John Garry
2026-07-27 14:42 ` [PATCH v5 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-27 15:07 ` sashiko-bot
2026-07-27 16:21 ` John Garry
2026-07-27 14:42 ` [PATCH v5 14/27] scsi-multipath: support iopolicy John Garry
2026-07-27 15:06 ` sashiko-bot
2026-07-27 15:39 ` John Garry
2026-07-27 14:42 ` [PATCH v5 15/27] scsi-multipath: clone each bio John Garry
2026-07-27 15:21 ` sashiko-bot
2026-07-27 15:40 ` John Garry
2026-07-27 14:42 ` [PATCH v5 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-07-27 15:14 ` sashiko-bot
2026-07-27 15:44 ` John Garry
2026-07-27 14:42 ` [PATCH v5 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-27 15:17 ` sashiko-bot
2026-07-27 16:05 ` John Garry
2026-07-27 14:42 ` [PATCH v5 18/27] scsi-multipath: failover handling John Garry
2026-07-27 14:42 ` [PATCH v5 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-07-27 15:24 ` sashiko-bot
2026-07-27 16:07 ` John Garry
2026-07-27 14:42 ` [PATCH v5 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-27 15:25 ` sashiko-bot
2026-07-27 16:18 ` John Garry
2026-07-27 14:42 ` [PATCH v5 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-07-27 15:23 ` sashiko-bot
2026-07-27 16:20 ` John Garry
2026-07-27 14:42 ` [PATCH v5 22/27] scsi: sd: add multipath disk class John Garry
2026-07-27 15:14 ` sashiko-bot
2026-07-27 16:21 ` John Garry
2026-07-27 14:42 ` [PATCH v5 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-07-27 15:20 ` sashiko-bot
2026-07-27 16:22 ` John Garry
2026-07-27 14:42 ` [PATCH v5 24/27] scsi: sd: support multipath disk John Garry
2026-07-27 15:20 ` sashiko-bot
2026-07-27 16:33 ` John Garry
2026-07-27 14:42 ` [PATCH v5 25/27] scsi: sd: add mpath_dev file John Garry
2026-07-27 15:33 ` sashiko-bot
2026-07-27 16:24 ` John Garry
2026-07-27 14:42 ` [PATCH v5 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-27 14:42 ` [PATCH v5 27/27] scsi: sd: add mpath_queue_depth " John Garry
2026-07-27 15:28 ` sashiko-bot
2026-07-27 15:29 ` John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727151547.AF75D1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.