All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v6 08/27] libmultipath: Add support for block device IOCTL
Date: Wed, 29 Jul 2026 12:39:51 +0000	[thread overview]
Message-ID: <20260729123951.D95981F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260729105107.255712-9-john.g.garry@oracle.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Deadlock in `mpath_bdev_ioctl` due to holding `srcu_read_lock` while forwarding ioctls that can trigger synchronous path removal.
- [High] Bypass of underlying partition-specific IOCTL security policies because `mpath_bdev_ioctl` unconditionally passes `part0`.
--

--- Patch [8]: [PATCH v6 08/27] libmultipath: Add support for block device IOCTL ---
commit d2e45114ccfb93fccdccc60ed75e05084f9b9173
Author: John Garry <john.garry@linux.dev>

libmultipath: Add support for block device IOCTL

Add mpath_bdev_ioctl() as a multipath block device IOCTL handler. This
handler calls into the mpath_device bdev fops handler.

> diff --git a/lib/multipath.c b/lib/multipath.c
> index 58eb9be5bebbe..f1758d1e60a60 100644
> --- a/lib/multipath.c
> +++ b/lib/multipath.c
> @@ -454,11 +454,53 @@ static void mpath_bdev_release(struct gendisk *disk)
>  	mpath_put_head(mpath_head);
>  }
>  
> +static int mpath_bdev_ioctl(struct block_device *bdev, blk_mode_t mode,
> +		    unsigned int cmd, unsigned long arg)
> +{
> +	struct gendisk *disk = bdev->bd_disk;
> +	struct mpath_head *mpath_head = mpath_gendisk_to_head(disk);
> +	struct mpath_device *mpath_device;
> +	int srcu_idx, err;
> +
> +	/*
> +	 * This check is duplicated from sd_ioctl() as we don't pass the
> +	 * partition bdev to fops->ioctl. That is not yet possible as the
> +	 * per-path disk is hidden and, as such, does not have partitions
> +	 * scanned.
> +	 */
> +	if (bdev_is_partition(bdev) && !capable(CAP_SYS_RAWIO))
> +		return -ENOIOCTLCMD;
> +
> +	srcu_idx = srcu_read_lock(&mpath_head->srcu);
> +	mpath_device = mpath_find_path(mpath_head);
> +	if (!mpath_device) {
> +		err = -EWOULDBLOCK;
> +		goto out_unlock;
> +	}
> +
> +	if (!mpath_device->disk->fops->ioctl) {
> +		err = -ENOTTY;
> +		goto out_unlock;
> +	}
> +
> +	err = mpath_device->disk->fops->ioctl(
> +			mpath_device->disk->part0, mode, cmd, arg);

[Severity: High]
Does unconditionally passing part0 bypass partition-specific IOCTL security
policies in the underlying driver?

By passing the whole-disk block device (mpath_device->disk->part0),
bdev_is_partition() will evaluate to false in the underlying driver. For
drivers like NVMe, this strips the partition context and could bypass
requirements like CAP_SYS_ADMIN for passthrough commands on partitions,
allowing a user with only CAP_SYS_RAWIO to execute whole-disk commands.

[Severity: High]
Can holding the SRCU read lock across the underlying ioctl cause a deadlock?

If the underlying ioctl triggers a controller reset or device removal, the
teardown path could eventually wait on synchronize_srcu() for this exact
srcu instance. Since the ioctl is waiting for the operation to complete
while holding srcu_read_lock(), synchronize_srcu() would block forever.

> +out_unlock:
> +	srcu_read_unlock(&mpath_head->srcu, srcu_idx);
> +	return err;
> +}

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260729105107.255712-1-john.g.garry@oracle.com?part=8

  reply	other threads:[~2026-07-29 12:39 UTC|newest]

Thread overview: 64+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29 10:50 [PATCH v6 00/27] Native SCSI Multipath support John Garry
2026-07-29 10:50 ` [PATCH v6 01/27] libmultipath: Add initial framework John Garry
2026-07-29 10:50 ` [PATCH v6 02/27] libmultipath: Add basic gendisk support John Garry
2026-07-29 11:20   ` sashiko-bot
2026-07-29 11:36     ` John Garry
2026-07-29 10:50 ` [PATCH v6 03/27] libmultipath: Add path selection support John Garry
2026-07-29 11:33   ` sashiko-bot
2026-07-29 11:41     ` John Garry
2026-07-29 10:50 ` [PATCH v6 04/27] libmultipath: Add bio handling John Garry
2026-07-29 10:50 ` [PATCH v6 05/27] libmultipath: Add support for mpath_device management John Garry
2026-07-29 11:57   ` sashiko-bot
2026-07-29 12:11     ` John Garry
2026-07-29 10:50 ` [PATCH v6 06/27] libmultipath: Add delayed removal support John Garry
2026-07-29 12:08   ` sashiko-bot
2026-07-29 12:15     ` John Garry
2026-07-29 10:50 ` [PATCH v6 07/27] libmultipath: Add sysfs helpers John Garry
2026-07-29 12:28   ` sashiko-bot
2026-07-29 12:51     ` John Garry
2026-07-29 10:50 ` [PATCH v6 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-07-29 12:39   ` sashiko-bot [this message]
2026-07-29 12:53     ` John Garry
2026-07-29 10:50 ` [PATCH v6 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-29 10:50 ` [PATCH v6 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-29 10:50 ` [PATCH v6 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-29 10:50 ` [PATCH v6 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-29 13:46   ` sashiko-bot
2026-07-29 14:06     ` John Garry
2026-07-29 10:50 ` [PATCH v6 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-29 10:50 ` [PATCH v6 14/27] scsi-multipath: support iopolicy John Garry
2026-07-29 14:07   ` sashiko-bot
2026-07-29 14:11     ` John Garry
2026-07-29 10:50 ` [PATCH v6 15/27] scsi-multipath: clone each bio John Garry
2026-07-29 14:23   ` sashiko-bot
2026-07-29 14:25     ` John Garry
2026-07-29 10:50 ` [PATCH v6 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-07-29 14:42   ` sashiko-bot
2026-07-29 14:51     ` John Garry
2026-07-29 10:50 ` [PATCH v6 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-29 14:54   ` sashiko-bot
2026-07-29 15:27     ` John Garry
2026-07-29 10:50 ` [PATCH v6 18/27] scsi-multipath: failover handling John Garry
2026-07-29 15:14   ` sashiko-bot
2026-07-29 15:29     ` John Garry
2026-07-29 10:50 ` [PATCH v6 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-07-29 15:43   ` sashiko-bot
2026-07-29 16:54     ` John Garry
2026-07-29 10:51 ` [PATCH v6 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-29 16:12   ` sashiko-bot
2026-07-29 16:55     ` John Garry
2026-07-29 10:51 ` [PATCH v6 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-07-29 16:26   ` sashiko-bot
2026-07-29 16:56     ` John Garry
2026-07-29 10:51 ` [PATCH v6 22/27] scsi: sd: add multipath disk class John Garry
2026-07-29 16:33   ` sashiko-bot
2026-07-29 16:57     ` John Garry
2026-07-29 10:51 ` [PATCH v6 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-07-29 16:48   ` sashiko-bot
2026-07-29 17:05     ` John Garry
2026-07-29 10:51 ` [PATCH v6 24/27] scsi: sd: support multipath disk John Garry
2026-07-29 17:01   ` sashiko-bot
2026-07-29 17:24     ` John Garry
2026-07-29 10:51 ` [PATCH v6 25/27] scsi: sd: add mpath_dev file John Garry
2026-07-29 10:51 ` [PATCH v6 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-29 10:51 ` [PATCH v6 27/27] scsi: sd: add mpath_queue_depth " John Garry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260729123951.D95981F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.