From: Keith Busch <kbusch@meta.com>
To: <linux-block@vger.kernel.org>, <axboe@kernel.dk>
Cc: Keith Busch <kbusch@kernel.org>,
<syzbot+ac00e7bf7ac8c91af921@syzkaller.appspotmail.com>
Subject: [PATCH] loop, zloop: fix dma_alignment for large or unreported limits
Date: Mon, 10 Aug 2026 09:42:17 -0700 [thread overview]
Message-ID: <20260810164218.3721636-1-kbusch@meta.com> (raw)
From: Keith Busch <kbusch@kernel.org>
A file system sets STATX_DIOALIGN with zeroed alignments when the file
can't be used for direct I/O. The zero underflowed to UINT_MAX and
triggered a queue limits validation warning. Fall back to the block
device's limits when dio_mem_align isn't reported.
A file system with a block size larger than PAGE_SIZE may also report a
memory alignment that can't be expressed as a queue limit. File systems
fall back to buffered I/O for requests that don't meet their alignment,
so cap the reported limit to the largest possible value.
Fixes: 6c8dec275ccc ("loop: set dma_alignment from the backing file for direct I/O")
Fixes: c5059c1af2bd ("zloop: set dma_alignment from the backing files for direct I/O")
Reported-by: syzbot+ac00e7bf7ac8c91af921@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=ac00e7bf7ac8c91af921
Signed-off-by: Keith Busch <kbusch@kernel.org>
---
drivers/block/loop.c | 8 +++++---
drivers/block/zloop.c | 8 +++++---
2 files changed, 10 insertions(+), 6 deletions(-)
diff --git a/drivers/block/loop.c b/drivers/block/loop.c
index 8639fa34b8470..cbf1e2ce27126 100644
--- a/drivers/block/loop.c
+++ b/drivers/block/loop.c
@@ -458,12 +458,14 @@ static void loop_update_dio_alignment(struct loop_device *lo)
* Use the dio alignment of the file system if provided. The incomoing
* request's bio_vec is forwarded to the backing file unchanged, so its
* required memory alignment becomes the device's dma_alignment when
- * used for direct-io.
+ * used for direct-io. The file system reports zeroed alignments if the
+ * file can't be used for direct-io at all, so fall back to the block
+ * device limits in that case.
*/
if (!vfs_getattr(&file->f_path, &st, STATX_DIOALIGN, 0) &&
- (st.result_mask & STATX_DIOALIGN)) {
+ (st.result_mask & STATX_DIOALIGN) && st.dio_mem_align) {
lo->lo_min_dio_size = st.dio_offset_align;
- lo->lo_dio_mem_align = st.dio_mem_align - 1;
+ lo->lo_dio_mem_align = min(st.dio_mem_align - 1, PAGE_SIZE - 1);
return;
}
diff --git a/drivers/block/zloop.c b/drivers/block/zloop.c
index 4323ac108cae8..f0ca221524db6 100644
--- a/drivers/block/zloop.c
+++ b/drivers/block/zloop.c
@@ -1042,12 +1042,14 @@ static int zloop_get_block_size(struct zloop_device *zlo,
* Use the dio alignment of the file system if provided. The incoming
* request's bio_vec is forwarded to the backing file unchanged, so its
* required memory alignment becomes the device's dma_alignment when
- * used for direct-io.
+ * used for direct-io. The file system reports zeroed alignments if the
+ * file can't be used for direct-io at all, so fall back to the block
+ * device limits in that case.
*/
if (!vfs_getattr(&zone->file->f_path, &st, STATX_DIOALIGN, 0) &&
- (st.result_mask & STATX_DIOALIGN)) {
+ (st.result_mask & STATX_DIOALIGN) && st.dio_mem_align) {
zlo->block_size = st.dio_offset_align;
- zlo->dio_mem_align = st.dio_mem_align - 1;
+ zlo->dio_mem_align = min(st.dio_mem_align - 1, PAGE_SIZE - 1);
} else if (sb_bdev) {
zlo->block_size = bdev_physical_block_size(sb_bdev);
zlo->dio_mem_align = bdev_dma_alignment(sb_bdev);
--
2.53.0-Meta
next reply other threads:[~2026-08-10 16:42 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 16:42 Keith Busch [this message]
2026-08-10 17:30 ` [PATCH] loop, zloop: fix dma_alignment for large or unreported limits Christoph Hellwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810164218.3721636-1-kbusch@meta.com \
--to=kbusch@meta.com \
--cc=axboe@kernel.dk \
--cc=kbusch@kernel.org \
--cc=linux-block@vger.kernel.org \
--cc=syzbot+ac00e7bf7ac8c91af921@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.