From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v6 14/27] scsi-multipath: support iopolicy
Date: Wed, 29 Jul 2026 14:07:32 +0000 [thread overview]
Message-ID: <20260729140733.162A61F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260729105107.255712-15-john.g.garry@oracle.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] The struct mpath_head_template 'smpdt' is entirely empty, lacking implementations for logically required callbacks, leading to NULL pointer dereferences.
- [Low] Missing READ_ONCE() when reading the global `iopolicy` variable, leading to a data race.
--
--- Patch [14]: [PATCH v6 14/27] scsi-multipath: support iopolicy ---
commit f1795dc3e5eb8bb57ed7783aab4a6563ae5c3b62
Author: John Garry <john.g.garry@oracle.com>
scsi-multipath: support iopolicy
Add support to set the multipath iopolicy. The iopolicy member is per
scsi_mpath_head structure, and a module param is added so that the default
iopolicy may be set.
> diff --git a/drivers/scsi/scsi_multipath.c b/drivers/scsi/scsi_multipath.c
> index 1ec7bf1835de0..593f94aac70e9 100644
> --- a/drivers/scsi/scsi_multipath.c
> +++ b/drivers/scsi/scsi_multipath.c
> @@ -61,6 +61,23 @@ static const struct kernel_param_ops multipath_param_ops = {
> module_param_cb(multipath, &multipath_param_ops, &scsi_multipath, 0444);
> MODULE_PARM_DESC(multipath, "turn on native multipath support, options: on, off, always");
>
> +static enum mpath_iopolicy_e iopolicy = MPATH_IOPOLICY_NUMA;
> +
> +static int scsi_mpath_set_iopolicy_param(const char *val, const struct kernel_param *kp)
> +{
> + return mpath_set_iopolicy(val, &iopolicy);
> +}
> +
> +static int scsi_mpath_get_iopolicy_param(char *buf, const struct kernel_param *kp)
> +{
> + return mpath_get_iopolicy(buf, iopolicy);
[Severity: Low]
Is a READ_ONCE() missing here when reading the global iopolicy variable?
mpath_set_iopolicy() updates the variable using WRITE_ONCE(). Concurrent
reads here could lead to a data race and trigger KCSAN warnings.
> +}
> +
> +module_param_call(multipath_iopolicy, scsi_mpath_set_iopolicy_param,
> + scsi_mpath_get_iopolicy_param, &iopolicy, 0644);
> +MODULE_PARM_DESC(multipath_iopolicy,
> + "Default multipath I/O policy; 'numa' (default), 'round-robin' or 'queue-depth'");
> +
[ ... ]
> @@ -204,6 +254,8 @@ static struct scsi_mpath_head *scsi_mpath_alloc_head(char *vpd_id)
> if (mpath_head_init(&scsi_mpath_head->mpath_head))
> goto out_free;
> scsi_mpath_head->mpath_head.mpdt = &smpdt;
[Severity: Critical]
Since the scsi_mpath_head is initialized with smpdt here, and smpdt appears
to be an empty template, could this lead to NULL pointer dereferences in the
core multipath library?
drivers/scsi/scsi_multipath.c:
static struct mpath_head_template smpdt = {
};
The core code unconditionally dereferences these callbacks. For example, during
path validation:
lib/multipath.c:mpath_path_is_disabled() {
...
return mpath_head->mpdt->is_disabled(mpath_device);
}
> + scsi_mpath_head->iopolicy = iopolicy;
[Severity: Low]
Would it be better to also use READ_ONCE() here when reading the global
iopolicy variable during initialization?
> + scsi_mpath_head->mpath_head.iopolicy = &scsi_mpath_head->iopolicy;
>
> strscpy(scsi_mpath_head->vpd_id, vpd_id,
> SCSI_MPATH_DEVICE_ID_LEN);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260729105107.255712-1-john.g.garry@oracle.com?part=14
next prev parent reply other threads:[~2026-07-29 14:07 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-29 10:50 [PATCH v6 00/27] Native SCSI Multipath support John Garry
2026-07-29 10:50 ` [PATCH v6 01/27] libmultipath: Add initial framework John Garry
2026-07-29 10:50 ` [PATCH v6 02/27] libmultipath: Add basic gendisk support John Garry
2026-07-29 11:20 ` sashiko-bot
2026-07-29 11:36 ` John Garry
2026-07-29 10:50 ` [PATCH v6 03/27] libmultipath: Add path selection support John Garry
2026-07-29 11:33 ` sashiko-bot
2026-07-29 11:41 ` John Garry
2026-07-29 10:50 ` [PATCH v6 04/27] libmultipath: Add bio handling John Garry
2026-07-29 10:50 ` [PATCH v6 05/27] libmultipath: Add support for mpath_device management John Garry
2026-07-29 11:57 ` sashiko-bot
2026-07-29 12:11 ` John Garry
2026-07-29 10:50 ` [PATCH v6 06/27] libmultipath: Add delayed removal support John Garry
2026-07-29 12:08 ` sashiko-bot
2026-07-29 12:15 ` John Garry
2026-07-29 10:50 ` [PATCH v6 07/27] libmultipath: Add sysfs helpers John Garry
2026-07-29 12:28 ` sashiko-bot
2026-07-29 12:51 ` John Garry
2026-07-29 10:50 ` [PATCH v6 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-07-29 12:39 ` sashiko-bot
2026-07-29 12:53 ` John Garry
2026-07-29 10:50 ` [PATCH v6 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-29 10:50 ` [PATCH v6 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-29 10:50 ` [PATCH v6 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-29 10:50 ` [PATCH v6 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-29 13:46 ` sashiko-bot
2026-07-29 14:06 ` John Garry
2026-07-29 10:50 ` [PATCH v6 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-29 10:50 ` [PATCH v6 14/27] scsi-multipath: support iopolicy John Garry
2026-07-29 14:07 ` sashiko-bot [this message]
2026-07-29 14:11 ` John Garry
2026-07-29 10:50 ` [PATCH v6 15/27] scsi-multipath: clone each bio John Garry
2026-07-29 14:23 ` sashiko-bot
2026-07-29 14:25 ` John Garry
2026-07-29 10:50 ` [PATCH v6 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-07-29 14:42 ` sashiko-bot
2026-07-29 14:51 ` John Garry
2026-07-29 10:50 ` [PATCH v6 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-29 14:54 ` sashiko-bot
2026-07-29 15:27 ` John Garry
2026-07-29 10:50 ` [PATCH v6 18/27] scsi-multipath: failover handling John Garry
2026-07-29 15:14 ` sashiko-bot
2026-07-29 15:29 ` John Garry
2026-07-29 10:50 ` [PATCH v6 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-07-29 15:43 ` sashiko-bot
2026-07-29 16:54 ` John Garry
2026-07-29 10:51 ` [PATCH v6 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-29 16:12 ` sashiko-bot
2026-07-29 16:55 ` John Garry
2026-07-29 10:51 ` [PATCH v6 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-07-29 16:26 ` sashiko-bot
2026-07-29 16:56 ` John Garry
2026-07-29 10:51 ` [PATCH v6 22/27] scsi: sd: add multipath disk class John Garry
2026-07-29 16:33 ` sashiko-bot
2026-07-29 16:57 ` John Garry
2026-07-29 10:51 ` [PATCH v6 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-07-29 16:48 ` sashiko-bot
2026-07-29 17:05 ` John Garry
2026-07-29 10:51 ` [PATCH v6 24/27] scsi: sd: support multipath disk John Garry
2026-07-29 17:01 ` sashiko-bot
2026-07-29 17:24 ` John Garry
2026-07-29 10:51 ` [PATCH v6 25/27] scsi: sd: add mpath_dev file John Garry
2026-07-29 10:51 ` [PATCH v6 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-29 10:51 ` [PATCH v6 27/27] scsi: sd: add mpath_queue_depth " John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729140733.162A61F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.