From: sashiko-bot@kernel.org
To: "Stefan Haberland" <sth@linux.ibm.com>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>
Subject: Re: [PATCH v6 14/18] s390/dasd: Stamp a format label into newly formatted volumes
Date: Sat, 01 Aug 2026 11:33:25 +0000 [thread overview]
Message-ID: <20260801113326.46DDD1F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260801111008.3391031-15-sth@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Medium] Unsynchronized modification of the ese_format_quick state flag.
Pre-existing issues:
- [High] Heap buffer overflow in dasd_eckd_build_format when handling specialized format intensities.
--
--- Patch [14]: [PATCH v6 14/18] s390/dasd: Stamp a format label into newly formatted volumes ---
commit 1a0c863785cfe5455ad8a4386ef60684b5d42b93
Author: Stefan Haberland <sth@linux.ibm.com>
s390/dasd: Stamp a format label into newly formatted volumes
When a CDL volume is formatted, write a small on-disk label so the format
can later be recognised by the kernel. The label records a magic, a version,
whether the volume is ESE, and whether it was formatted quick (space released,
thin) or full.
> diff --git a/drivers/s390/block/dasd_eckd.c b/drivers/s390/block/dasd_eckd.c
> index 67c301e182c0f..ebffb3364c33c 100644
> --- a/drivers/s390/block/dasd_eckd.c
> +++ b/drivers/s390/block/dasd_eckd.c
[ ... ]
> @@ -2816,6 +2849,10 @@ dasd_eckd_build_format(struct dasd_device *base, struct dasd_device *startdev,
> return ERR_PTR(-EINVAL);
> }
>
> + /* room for the label data that R4 carries in addition to its count */
> + if (write_label)
> + datasize += fdata->blksize;
> +
[Severity: High]
This is a pre-existing issue, but can this code cause a heap buffer overflow?
When handling specialized format intensities (e.g., 0x01 or 0x09), the size
calculation in dasd_eckd_build_format() appears to under-calculate the
required allocation for multi-track requests by missing per-track R0
allocations:
dasd_eckd_build_format() {
...
case 0x01: /* Write record zero and format track. */
case 0x09: /* Write record zero and format track, use cdl. */
cplength = 2 + rpt * nr_tracks;
if (use_prefix)
datasize = sizeof(struct PFX_eckd_data) +
sizeof(struct LO_eckd_data) +
sizeof(struct eckd_count) +
rpt * nr_tracks * sizeof(struct eckd_count);
...
}
However, the subsequent loop unconditionally writes nr_tracks sets of CCWs and
eckd_count structures:
dasd_eckd_build_format() {
...
for (j = 0; j < nr_tracks; j++) {
...
if (intensity & 0x01) { /* write record zero */
ect = (struct eckd_count *) data;
data += sizeof(struct eckd_count);
...
ccw++;
...
}
Could this write past the allocated boundaries if a user with CAP_SYS_ADMIN
invokes the BIODASDFMT ioctl with a track range spanning multiple tracks?
> fcp = dasd_fmalloc_request(DASD_ECKD_MAGIC, cplength, datasize, startdev);
> if (IS_ERR(fcp))
> return fcp;
[ ... ]
> @@ -3177,8 +3231,18 @@ static int dasd_eckd_format_device(struct dasd_device *base,
> if (fdata->start_unit == 0)
> dasd_ft_bias_apply(base);
>
> - return dasd_eckd_format_process_data(base, fdata, enable_pav, 0, NULL,
> - 0, NULL);
> + rc = dasd_eckd_format_process_data(base, fdata, enable_pav, 0, NULL,
> + 0, NULL);
> +
> + /*
> + * The quick-format indicator was consumed by the label stamped into
> + * track 0; clear it so a later format that is not preceded by a full
> + * space release is recorded as a full format.
> + */
> + if (fdata->start_unit == 0)
> + private->ese_format_quick = 0;
[Severity: Medium]
Is it possible for this flag modification to race with concurrent updates?
If a concurrent BIODASDRAS ioctl is executing, dasd_eckd_release_space_full()
might update this state flag without locks:
dasd_eckd_release_space_full() {
...
private = device->private;
private->ese_format_quick = 1;
...
}
Because dasd_eckd_format_device() clears the flag unconditionally after an
unprotected blocking operation, could it overwrite the concurrent update?
This might cause the next disk format label to be incorrectly stamped as a
'full' format rather than a 'quick' format.
> +
> + return rc;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260801111008.3391031-1-sth@linux.ibm.com?part=14
next prev parent reply other threads:[~2026-08-01 11:33 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-01 11:09 [PATCH v6 00/18] s390/dasd: ESE thin-provisioning performance improvements Stefan Haberland
2026-08-01 11:09 ` [PATCH v6 01/18] s390/dasd: Do not complete a failed ESE read as successful Stefan Haberland
2026-08-01 11:27 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 02/18] s390/dasd: Propagate partial completion length across ERP recovery Stefan Haberland
2026-08-01 11:21 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 03/18] s390/dasd: Guard sysfs discipline callbacks against unallocated private data Stefan Haberland
2026-08-01 11:40 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 04/18] s390/dasd: Optimize max blocks per request for track alignment Stefan Haberland
2026-08-01 11:20 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 05/18] s390/dasd: Use GFP_KERNEL in dasd_alloc_device() Stefan Haberland
2026-08-01 11:21 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 06/18] s390/dasd: Add defines for the Extended Address Volume track address Stefan Haberland
2026-08-01 11:13 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 07/18] s390/dasd: Add infrastructure for ESE full-track write Stefan Haberland
2026-08-01 11:32 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 08/18] s390/dasd: Add range-based format-track collision detection Stefan Haberland
2026-08-01 11:36 ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 09/18] s390/dasd: Extend prepare_itcw() to support WRITE_FULL_TRACK Stefan Haberland
2026-08-01 11:37 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 10/18] s390/dasd: Add dasd_eckd_build_cp_tpm_writefulltrack() Stefan Haberland
2026-08-01 11:29 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 11/18] s390/dasd: Use WRITE_FULL_TRACK in ESE format handler Stefan Haberland
2026-08-01 11:39 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 12/18] s390/dasd: Add full_track_bias to control fulltrack write mode Stefan Haberland
2026-08-01 11:27 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 13/18] s390/dasd: Derive adaptive ESE fulltrack heuristic from ft_bias Stefan Haberland
2026-08-01 11:46 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 14/18] s390/dasd: Stamp a format label into newly formatted volumes Stefan Haberland
2026-08-01 11:33 ` sashiko-bot [this message]
2026-08-01 11:10 ` [PATCH v6 15/18] s390/dasd: Detect ESE volumes from the on-disk format label Stefan Haberland
2026-08-01 11:38 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 16/18] s390/dasd: Report ESE capability and format mode at device online Stefan Haberland
2026-08-01 11:45 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 17/18] s390/dasd: Re-enable discard support for ESE volumes Stefan Haberland
2026-08-01 11:45 ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 18/18] s390/dasd: Read cached unit address and LSS in the CCW build path Stefan Haberland
2026-08-01 11:49 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260801113326.46DDD1F00AC4@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sth@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.