From: sashiko-bot@kernel.org
To: "Stefan Haberland" <sth@linux.ibm.com>
Cc: "Alexander Gordeev" <agordeev@linux.ibm.com>,
linux-s390@vger.kernel.org, "Vasily Gorbik" <gor@linux.ibm.com>,
"Heiko Carstens" <hca@linux.ibm.com>
Subject: Re: [PATCH 12/19] s390/dasd: Use WRITE_FULL_TRACK in ESE format handler
Date: Wed, 05 Aug 2026 16:21:17 +0000 [thread overview]
Message-ID: <20260805162118.1CE841F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260805111612.1285190-13-sth@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] Full-track format requests bypass `test_and_set_format_track()` locking, leading to TOCTOU data corruption from concurrent partial-track writes.
- [High] Setting cqr->callback = NULL for aborted requests during teardown overwrites the flush queue wakeup callback, causing an indefinite deadlock during device offline.
--
--- Patch [12]: [PATCH 12/19] s390/dasd: Use WRITE_FULL_TRACK in ESE format handler ---
commit c79b7434acd3a79782b3c648eaa1de078edf01da
Author: Stefan Haberland <sth@linux.ibm.com>
s390/dasd: Use WRITE_FULL_TRACK in ESE format handler
Wire dasd_eckd_build_cp_tpm_writefulltrack() into the ESE unformated
track handler.
> diff --git a/drivers/s390/block/dasd_eckd.c b/drivers/s390/block/dasd_eckd.c
> index 8379c8a40382f..da488c0775fcd 100644
> --- a/drivers/s390/block/dasd_eckd.c
> +++ b/drivers/s390/block/dasd_eckd.c
> @@ -3253,50 +3241,94 @@ dasd_eckd_ese_format(struct dasd_device *startdev, struct dasd_ccw_req *cqr,
> [ ... ]
> + if (first_trk != last_trk && last_offs + 1 < recs_per_trk) {
> + diff = last_offs + 1;
> + last_rec = last_rec - diff;
> + last_trk = last_rec;
> + last_offs = sector_div(last_trk, recs_per_trk);
> + proc_bytes = (last_rec - first_rec + 1) * blksize;
> + }
> + if (first_offs > 0 || last_offs + 1 < recs_per_trk) {
> + /* test if tracks are already in formatting by another thread */
> + if (test_and_set_format_track(first_trk, last_trk, cqr,
> + cqr->block, cqr->startdev, &format)) {
[Severity: Critical]
Does bypassing test_and_set_format_track() for full-track requests allow
concurrent partial-track writes to the same track to proceed without
detecting a conflict?
If a partial-track format CCW chain executes after the full-track write, its
zero-padding could silently overwrite the valid data just written by the
full-track write.
> + /* this is no real error so do not count down retries */
> + cqr->retries++;
> + goto out_retry;
> + }
> + }
> +
> [ ... ]
> @@ -3304,10 +3336,44 @@ dasd_eckd_ese_format(struct dasd_device *startdev, struct dasd_ccw_req *cqr,
> [ ... ]
> + /*
> + * stage under ese_lock; dasd_block_tasklet splices it into ccw_queue.
> + * Direct enqueue here would invert queue_lock / ccwdev_lock.
> + */
> + spin_lock(&block->ese_lock);
> + list_add(&fcqr->blocklist, &block->ese_staging);
> + spin_unlock(&block->ese_lock);
> + /* mark origin CQR as aborted; ccwdev_lock is held by the IRQ handler */
> + cqr->status = DASD_CQR_ABORT;
[Severity: High]
If a device is taken offline while an I/O request is being aborted by an ESE
format operation, _dasd_requests_to_flushqueue() sets
cqr->callback = _dasd_wake_block_flush_cb.
Will marking the status as DASD_CQR_ABORT here trigger a path in
__dasd_process_cqr() that unconditionally clears cqr->callback = NULL?
This would strip the wakeup callback installed by the offline process,
causing the offline process to sleep forever since wake_up(&dasd_flush_wq)
is never called.
> + goto out;
> +
> +out_retry:
> + /*
> + * If we can't format now, let the request go
> + * one extra round. Maybe we can format later.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260805111612.1285190-1-sth@linux.ibm.com?part=12
next prev parent reply other threads:[~2026-08-05 16:21 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 11:15 [PATCH 00/19] s390/dasd: ESE Performance improvements Stefan Haberland
2026-08-05 11:15 ` [PATCH 01/19] s390/dasd: Do not complete a failed ESE read as successful Stefan Haberland
2026-08-05 11:48 ` sashiko-bot
2026-08-05 11:15 ` [PATCH 02/19] s390/dasd: Propagate partial completion length across ERP recovery Stefan Haberland
2026-08-05 12:17 ` sashiko-bot
2026-08-05 11:15 ` [PATCH 03/19] s390/dasd: Guard sysfs discipline callbacks against unallocated private data Stefan Haberland
2026-08-05 12:44 ` sashiko-bot
2026-08-05 11:15 ` [PATCH 04/19] s390/dasd: Snapshot intrc before freeing the request block Stefan Haberland
2026-08-05 13:06 ` sashiko-bot
2026-08-05 11:15 ` [PATCH 05/19] s390/dasd: Optimize max blocks per request for track alignment Stefan Haberland
2026-08-05 13:10 ` sashiko-bot
2026-08-05 11:15 ` [PATCH 06/19] s390/dasd: Use GFP_KERNEL in dasd_alloc_device() Stefan Haberland
2026-08-05 13:17 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 07/19] s390/dasd: Add defines for the Extended Address Volume track address Stefan Haberland
2026-08-05 13:19 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 08/19] s390/dasd: Add infrastructure for ESE full-track write Stefan Haberland
2026-08-05 14:02 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 09/19] s390/dasd: Add range-based format-track collision detection Stefan Haberland
2026-08-05 15:11 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 10/19] s390/dasd: Extend prepare_itcw() to support WRITE_FULL_TRACK Stefan Haberland
2026-08-05 15:39 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 11/19] s390/dasd: Add dasd_eckd_build_cp_tpm_writefulltrack() Stefan Haberland
2026-08-05 15:53 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 12/19] s390/dasd: Use WRITE_FULL_TRACK in ESE format handler Stefan Haberland
2026-08-05 16:21 ` sashiko-bot [this message]
2026-08-05 11:16 ` [PATCH 13/19] s390/dasd: Add full_track_bias to control fulltrack write mode Stefan Haberland
2026-08-05 16:41 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 14/19] s390/dasd: Derive adaptive ESE fulltrack heuristic from ft_bias Stefan Haberland
2026-08-05 16:48 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 15/19] s390/dasd: Stamp a format label into newly formatted volumes Stefan Haberland
2026-08-05 17:14 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 16/19] s390/dasd: Detect ESE volumes from the on-disk format label Stefan Haberland
2026-08-05 19:34 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 17/19] s390/dasd: Report ESE capability and format mode at device online Stefan Haberland
2026-08-05 19:44 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 18/19] s390/dasd: Re-enable discard support for ESE volumes Stefan Haberland
2026-08-05 20:04 ` sashiko-bot
2026-08-05 11:16 ` [PATCH 19/19] s390/dasd: Read cached unit address and LSS in the CCW build path Stefan Haberland
2026-08-05 20:31 ` sashiko-bot
2026-08-05 12:32 ` [PATCH 00/19] s390/dasd: ESE Performance improvements Jens Axboe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805162118.1CE841F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sth@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.