All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Stefan Haberland" <sth@linux.ibm.com>
Cc: "Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>,
	linux-s390@vger.kernel.org
Subject: Re: [PATCH v6 15/18] s390/dasd: Detect ESE volumes from the on-disk format label
Date: Sat, 01 Aug 2026 11:38:35 +0000	[thread overview]
Message-ID: <20260801113836.5BEA71F00AC4@smtp.kernel.org> (raw)
In-Reply-To: <20260801111008.3391031-16-sth@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [Medium] The in-memory ESE label cache (`private->ese_label_valid`) is not invalidated when track 0 is formatted without an ESE label, leaving the driver with a stale ESE state that no longer matches the physical disk.

Pre-existing issues:
- [High] Fatal NULL pointer dereference in `dasd_release_space()` for devices whose discipline lacks the `is_ese` method (e.g., FBA or DIAG devices).
--

--- Patch [15]: [PATCH v6 15/18] s390/dasd: Detect ESE volumes from the on-disk format label ---
commit d17ebb7bd94d36c62afdabb020d82a8a18a64bba
Author: Stefan Haberland <sth@linux.ibm.com>
Subject: s390/dasd: Detect ESE volumes from the on-disk format label

This commit updates the DASD driver to detect Extent Space Efficient (ESE)
volumes by reading the format label from track 0 during device bring-up. It
caches this label and derives the ESE status from it, allowing volumes copied
from ESE storage to maintain their thin-provisioned handling on different
hardware.

> diff --git a/drivers/s390/block/dasd_eckd.c b/drivers/s390/block/dasd_eckd.c
> index ebffb3364c33c..35a970e006fd0 100644
> --- a/drivers/s390/block/dasd_eckd.c
> +++ b/drivers/s390/block/dasd_eckd.c
[ ... ]
> @@ -3224,23 +3353,35 @@ static int dasd_eckd_format_device(struct dasd_device *base,
>  	struct dasd_eckd_private *private = base->private;
>  	int rc;
>  
>  	rc = dasd_eckd_format_process_data(base, fdata, enable_pav, 0, NULL,
>  					   0, NULL);
> +	if (fdata->start_unit != 0)
> +		return rc;
> +
> +	if (rc) {
> +		/*
> +		 * The format failed, so the label cached speculatively during
> +		 * CCW build may not match the disk; drop it so is_ese() falls
> +		 * back to the hardware field until the next successful format
> +		 * or bring-up.
> +		 */
> +		private->ese_label_valid = false;
> +		return rc;
> +	}

[Severity: Medium]
When track 0 is formatted, what happens if no ESE label is written?

If a user issues the BIODASDFMT ioctl with start_unit == 0 and a non-CDL
layout (e.g., intensity & 0x08 == 0), dasd_eckd_build_format() might not
write a new label. The physical label on track 0 is then zeroed or destroyed
by the format.

However, dasd_eckd_format_device() only clears private->ese_label_valid on
failure. Could this regression leave the driver using a stale ESE state that
no longer matches the physical disk after a successful format?

[ ... ]
> @@ -4241,6 +4382,14 @@ static int dasd_eckd_release_space_trks(struct dasd_device *device,
>  static int dasd_eckd_release_space(struct dasd_device *device,
>  				   struct format_data_t *rdata)
>  {
> +	/*
> +	 * Space release (and thus a quick format) requires real ESE hardware.
> +	 * is_ese() may be true from a copied label on non-ESE hardware, so gate
> +	 * on the hardware capability, not on is_ese().
> +	 */
> +	if (!dasd_eckd_ese_capable(device))
> +		return -EOPNOTSUPP;
> +

[Severity: High]
This isn't a bug introduced by this patch, but does the ioctl path for space
release have a NULL pointer dereference for devices without an is_ese method?

In drivers/s390/block/dasd_ioctl.c, dasd_release_space() contains this check:

    if (!device->discipline->is_ese && !device->discipline->is_ese(device))
        return -ENOTSUPP;

Since it uses a logical AND (&&) instead of OR (||), if the discipline (e.g.,
FBA or DIAG) lacks the is_ese method, the first operand evaluates to true.

Will this force the evaluation of the second operand, immediately
dereferencing the NULL function pointer when a user issues the BIODASDRAS
ioctl?

>  	if (rdata->intensity & DASD_FMT_INT_ESE_FULL)
>  		return dasd_eckd_release_space_full(device);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260801111008.3391031-1-sth@linux.ibm.com?part=15

  reply	other threads:[~2026-08-01 11:38 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-01 11:09 [PATCH v6 00/18] s390/dasd: ESE thin-provisioning performance improvements Stefan Haberland
2026-08-01 11:09 ` [PATCH v6 01/18] s390/dasd: Do not complete a failed ESE read as successful Stefan Haberland
2026-08-01 11:27   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 02/18] s390/dasd: Propagate partial completion length across ERP recovery Stefan Haberland
2026-08-01 11:21   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 03/18] s390/dasd: Guard sysfs discipline callbacks against unallocated private data Stefan Haberland
2026-08-01 11:40   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 04/18] s390/dasd: Optimize max blocks per request for track alignment Stefan Haberland
2026-08-01 11:20   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 05/18] s390/dasd: Use GFP_KERNEL in dasd_alloc_device() Stefan Haberland
2026-08-01 11:21   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 06/18] s390/dasd: Add defines for the Extended Address Volume track address Stefan Haberland
2026-08-01 11:13   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 07/18] s390/dasd: Add infrastructure for ESE full-track write Stefan Haberland
2026-08-01 11:32   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 08/18] s390/dasd: Add range-based format-track collision detection Stefan Haberland
2026-08-01 11:36   ` sashiko-bot
2026-08-01 11:09 ` [PATCH v6 09/18] s390/dasd: Extend prepare_itcw() to support WRITE_FULL_TRACK Stefan Haberland
2026-08-01 11:37   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 10/18] s390/dasd: Add dasd_eckd_build_cp_tpm_writefulltrack() Stefan Haberland
2026-08-01 11:29   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 11/18] s390/dasd: Use WRITE_FULL_TRACK in ESE format handler Stefan Haberland
2026-08-01 11:39   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 12/18] s390/dasd: Add full_track_bias to control fulltrack write mode Stefan Haberland
2026-08-01 11:27   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 13/18] s390/dasd: Derive adaptive ESE fulltrack heuristic from ft_bias Stefan Haberland
2026-08-01 11:46   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 14/18] s390/dasd: Stamp a format label into newly formatted volumes Stefan Haberland
2026-08-01 11:33   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 15/18] s390/dasd: Detect ESE volumes from the on-disk format label Stefan Haberland
2026-08-01 11:38   ` sashiko-bot [this message]
2026-08-01 11:10 ` [PATCH v6 16/18] s390/dasd: Report ESE capability and format mode at device online Stefan Haberland
2026-08-01 11:45   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 17/18] s390/dasd: Re-enable discard support for ESE volumes Stefan Haberland
2026-08-01 11:45   ` sashiko-bot
2026-08-01 11:10 ` [PATCH v6 18/18] s390/dasd: Read cached unit address and LSS in the CCW build path Stefan Haberland
2026-08-01 11:49   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260801113836.5BEA71F00AC4@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sth@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.