All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v5 24/27] scsi: sd: support multipath disk
Date: Mon, 27 Jul 2026 15:20:33 +0000	[thread overview]
Message-ID: <20260727152033.A7E5B1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727144234.3802948-25-john.g.garry@oracle.com>

Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:

New issues:
- [High] Concurrent path removal and addition causes a TOCTOU race that overwrites and frees the shared `mpath_head->disk`.
- [High] Uncancelled `remove_work` triggers a Use-After-Free if a re-attached multipath disk fails probing.
- [Medium] Missing `put_device()` on the `sd_mpath_add_disk()` error path permanently leaks `struct scsi_disk`.

Pre-existing issues:
- [High] Direct `kfree(sdkp)` in the `sd_large_pool_create()` error path causes a use-after-free because the device is already registered in sysfs.
--

--- Patch [24]: [PATCH v5 24/27] scsi: sd: support multipath disk ---
commit 6b75fe218921318a27f170eca853c70058afe60d
Author: John Garry <john.garry@linux.dev>
Subject: scsi: sd: support multipath disk

Add support to attach a multipath disk.

We still allocate the gendisk per path, and this is required for the
per-path submission. However, those gendisks are marked as hidden. Those
disks are named sdX:Y, where X is the multipath disk index and Y is the
per-path index.

> diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
> index 36c745cbb2619..f044b2dfaa9fd 100644
> --- a/drivers/scsi/sd.c
> +++ b/drivers/scsi/sd.c

[ ... ]

> @@ -4035,13 +4138,259 @@ static const struct attribute_group sd_mpath_disk_attr_group = {
> +static int sd_mpath_probe(struct scsi_disk *sdkp)
> +{
[ ... ]
> +	mpath_head->parent = &sd_mpath_disk->dev;
> +	mpath_head->drv_module = THIS_MODULE;
> +	mpath_head->disk_groups = sd_mpath_disk_attr_groups;
> +	error = mpath_alloc_head_disk(mpath_head, &lim,
> +				dev_to_node(dma_dev));
> +	if (error)
> +		goto out_free_disk;
> +	disk = mpath_head->disk;

[ ... ]

> +static void sd_mpath_remove(struct scsi_disk *sdkp)
> +{
[ ... ]
> +	mutex_lock(&sd_mpath_disks_lock);
> +	sd_mpath_disk->disk_count--;
> +	if (!sd_mpath_disk->disk_count && mpath_can_remove_head(mpath_head)) {
> +		list_del_init(&sd_mpath_disk->entry);
> +		remove = true;
> +	}
> +	mutex_unlock(&sd_mpath_disks_lock);
> +	mpath_remove_sysfs_link(mpath_device);
> +	mpath_device->disk = NULL;
> +
> +	if (remove) {
> +		device_del(&sd_mpath_disk->dev);
> +		mpath_remove_disk(mpath_head);

[Severity: High]
Does this create a TOCTOU race that overwrites and frees the shared
mpath_head->disk?

If sd_mpath_remove() and sd_mpath_probe() run concurrently for the same
scsi_mpath_head (e.g., during hotplug/hot-unplug events):

The removal path drops the sd_mpath_disks_lock before tearing down
mpath_head->disk here. A concurrent probe can then allocate and assign a new
disk to mpath_head->disk in sd_mpath_probe().

When the removal thread resumes, it deletes and frees the new disk while the
probe thread proceeds to use it, causing a use-after-free.

> +	}
> +	sd_mpath_put_disk(sd_mpath_disk);
> +}

[ ... ]

> +static void sd_mpath_fail_probe(struct scsi_disk *sdkp)
> +{
[ ... ]
> +	mutex_lock(&sd_mpath_disks_lock);
> +	sd_mpath_disk->disk_count--;
> +	if (!sd_mpath_disk->disk_count) {
> +		list_del_init(&sd_mpath_disk->entry);
> +		remove = true;
> +	}
> +	mutex_unlock(&sd_mpath_disks_lock);
> +	mpath_device->disk = NULL;
> +
> +	if (remove) {
> +		device_del(&sd_mpath_disk->dev);
> +		mpath_remove_disk(mpath_head);
> +	}
> +	sd_mpath_put_disk(sd_mpath_disk);

[Severity: High]
Can an uncancelled remove_work trigger a use-after-free here if a re-attached
multipath disk fails probing?

A delayed removal is scheduled when the last path is removed. A new path is
then rapidly probed, incrementing the disk count, but fails midway through
sd_probe().

This cleanup function decrements the count back to 0 and frees sd_mpath_disk
and scsi_mpath_head, but it does NOT cancel the pending remove_work (which
would normally be cancelled later in sd_mpath_add_disk()). The scheduled work
will subsequently execute on freed memory.

> +}

[ ... ]

> @@ -4158,11 +4515,18 @@ static int sd_probe(struct scsi_device *sdp)
>  	sd_revalidate_disk(gd);
>  	if (sdp->sector_size > PAGE_SIZE) {
>  		if (sd_large_pool_create()) {
> +			sd_mpath_fail_probe(sdkp);
>  			error = -ENOMEM;
>  			goto out_free_index;

[Severity: High]
This isn't a bug introduced by this patch, but does the direct kfree(sdkp) in
the sd_large_pool_create() error path cause a use-after-free because the
device is already registered in sysfs?

After device_add(&sdkp->disk_dev) succeeds earlier in sd_probe(), the device
is exposed to sysfs. If sd_large_pool_create() fails, the code branches to
out_free_index which directly calls kfree(sdkp) without unregistering the
sysfs device, leaving dangling pointers in the sysfs tree.

>  		}
>  	}

[ ... ]

> @@ -4184,6 +4549,19 @@ static int sd_probe(struct scsi_device *sdp)
>  		goto out;
>  	}
>  
> +	if (sdp->scsi_mpath_dev) {
> +		error = sd_mpath_add_disk(sdkp);
> +		if (error) {
> +			sd_mpath_fail_probe(sdkp);
> +			device_del(&sdkp->disk_dev);
> +			del_gendisk(sdkp->disk);
> +
> +			put_disk(sdkp->disk);
> +			if (sdp->sector_size > PAGE_SIZE)
> +				sd_large_pool_destroy();
> +			goto out;

[Severity: Medium]
Will this error path leak the struct scsi_disk?

A failure in sd_mpath_add_disk() triggers the error handling path which calls
device_del() but misses the corresponding put_device().

Because the kobject reference is never dropped, scsi_disk_release() is never
invoked, permanently leaking the memory.

> +		}
> +	}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260727144234.3802948-1-john.g.garry@oracle.com?part=24

  reply	other threads:[~2026-07-27 15:20 UTC|newest]

Thread overview: 71+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 14:42 [PATCH v5 00/27] Native SCSI Multipath support John Garry
2026-07-27 14:42 ` [PATCH v5 01/27] libmultipath: Add initial framework John Garry
2026-07-27 15:05   ` sashiko-bot
2026-07-27 15:12     ` John Garry
2026-07-27 14:42 ` [PATCH v5 02/27] libmultipath: Add basic gendisk support John Garry
2026-07-27 15:04   ` sashiko-bot
2026-07-27 15:15     ` John Garry
2026-07-27 14:42 ` [PATCH v5 03/27] libmultipath: Add path selection support John Garry
2026-07-27 15:03   ` sashiko-bot
2026-07-27 15:20     ` John Garry
2026-07-27 14:42 ` [PATCH v5 04/27] libmultipath: Add bio handling John Garry
2026-07-27 14:42 ` [PATCH v5 05/27] libmultipath: Add support for mpath_device management John Garry
2026-07-27 15:03   ` sashiko-bot
2026-07-27 15:23     ` John Garry
2026-07-27 14:42 ` [PATCH v5 06/27] libmultipath: Add delayed removal support John Garry
2026-07-27 15:00   ` sashiko-bot
2026-07-27 15:25     ` John Garry
2026-07-27 14:42 ` [PATCH v5 07/27] libmultipath: Add sysfs helpers John Garry
2026-07-27 15:03   ` sashiko-bot
2026-07-27 15:33     ` John Garry
2026-07-27 14:42 ` [PATCH v5 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-07-27 15:08   ` sashiko-bot
2026-07-27 15:31     ` John Garry
2026-07-27 14:42 ` [PATCH v5 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-27 14:42 ` [PATCH v5 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-27 14:42 ` [PATCH v5 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-27 18:59   ` sashiko-bot
2026-07-27 14:42 ` [PATCH v5 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-27 15:15   ` sashiko-bot
2026-07-27 15:37     ` John Garry
2026-07-27 14:42 ` [PATCH v5 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-27 15:07   ` sashiko-bot
2026-07-27 16:21     ` John Garry
2026-07-27 14:42 ` [PATCH v5 14/27] scsi-multipath: support iopolicy John Garry
2026-07-27 15:06   ` sashiko-bot
2026-07-27 15:39     ` John Garry
2026-07-27 14:42 ` [PATCH v5 15/27] scsi-multipath: clone each bio John Garry
2026-07-27 15:21   ` sashiko-bot
2026-07-27 15:40     ` John Garry
2026-07-27 14:42 ` [PATCH v5 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-07-27 15:14   ` sashiko-bot
2026-07-27 15:44     ` John Garry
2026-07-27 14:42 ` [PATCH v5 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-27 15:17   ` sashiko-bot
2026-07-27 16:05     ` John Garry
2026-07-27 14:42 ` [PATCH v5 18/27] scsi-multipath: failover handling John Garry
2026-07-27 14:42 ` [PATCH v5 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-07-27 15:24   ` sashiko-bot
2026-07-27 16:07     ` John Garry
2026-07-27 14:42 ` [PATCH v5 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-27 15:25   ` sashiko-bot
2026-07-27 16:18     ` John Garry
2026-07-27 14:42 ` [PATCH v5 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-07-27 15:23   ` sashiko-bot
2026-07-27 16:20     ` John Garry
2026-07-27 14:42 ` [PATCH v5 22/27] scsi: sd: add multipath disk class John Garry
2026-07-27 15:14   ` sashiko-bot
2026-07-27 16:21     ` John Garry
2026-07-27 14:42 ` [PATCH v5 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-07-27 15:20   ` sashiko-bot
2026-07-27 16:22     ` John Garry
2026-07-27 14:42 ` [PATCH v5 24/27] scsi: sd: support multipath disk John Garry
2026-07-27 15:20   ` sashiko-bot [this message]
2026-07-27 16:33     ` John Garry
2026-07-27 14:42 ` [PATCH v5 25/27] scsi: sd: add mpath_dev file John Garry
2026-07-27 15:33   ` sashiko-bot
2026-07-27 16:24     ` John Garry
2026-07-27 14:42 ` [PATCH v5 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-27 14:42 ` [PATCH v5 27/27] scsi: sd: add mpath_queue_depth " John Garry
2026-07-27 15:28   ` sashiko-bot
2026-07-27 15:29     ` John Garry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727152033.A7E5B1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.