All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v7 17/27] scsi-multipath: revalidate paths upon device unblock
Date: Tue, 01 Sep 2026 11:12:57 +0000	[thread overview]
Message-ID: <20260901111258.4F9381F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901104526.3850621-18-john.g.garry@oracle.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Unsynchronized access to `sdev->scsi_mpath_dev` in `scsi_internal_device_unblock()` races with device initialization, leading to a NULL pointer dereference or Use-After-Free.
--

commit 9827c5b37e1215c845ce584c07c0fadae92e797b
Author: John Garry <john.garry@linux.dev>

scsi-multipath: revalidate paths upon device unblock

This commit revalidates paths when a scsi_device is unblocked. It clears
any paths and requeues queued bios as part of the revalidation process.

> diff --git a/drivers/scsi/scsi_lib.c b/drivers/scsi/scsi_lib.c
> index f02b3a50e20cd..189263ce56624 100644
> --- a/drivers/scsi/scsi_lib.c
> +++ b/drivers/scsi/scsi_lib.c
> @@ -3093,6 +3093,8 @@ static int scsi_internal_device_unblock(struct scsi_device *sdev,
>  	mutex_lock(&sdev->state_mutex);
>  	ret = scsi_internal_device_unblock_nowait(sdev, new_state);
>  	mutex_unlock(&sdev->state_mutex);
> +	if ((ret == 0) && sdev->scsi_mpath_dev)
> +		scsi_mpath_revalidate_paths(sdev->scsi_mpath_dev);

[Severity: High]
Does this lockless access to sdev->scsi_mpath_dev race with device
initialization?

If a transport unblock event occurs concurrently with hardware discovery,
scsi_internal_device_unblock() might read sdev->scsi_mpath_dev while it is
being initialized.

For instance, scsi_multipath_sdev_init() publishes the pointer before
initialization is fully complete:

drivers/scsi/scsi_multipath.c:scsi_multipath_sdev_init() {
    ...
    scsi_mpath_dev->sdev = sdev;
    sdev->scsi_mpath_dev = scsi_mpath_dev;
    ...
}

Could calling scsi_mpath_revalidate_paths() here lead to a NULL pointer
dereference when it attempts to access an uninitialized scsi_mpath_head?

Additionally, if initialization fails and the structure is freed in the error
path, could this result in a use-after-free?

>  
>  	return ret;
>  }

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260901104526.3850621-1-john.g.garry@oracle.com?part=17

  reply	other threads:[~2026-09-01 11:12 UTC|newest]

Thread overview: 50+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01 10:44 [PATCH v7 00/27] Native SCSI Multipath support John Garry
2026-09-01 10:45 ` [PATCH v7 01/27] libmultipath: Add initial framework John Garry
2026-09-01 11:03   ` sashiko-bot
2026-09-04  8:36     ` John Garry
2026-09-01 10:45 ` [PATCH v7 02/27] libmultipath: Add basic gendisk support John Garry
2026-09-01 10:45 ` [PATCH v7 03/27] libmultipath: Add path selection support John Garry
2026-09-01 11:04   ` sashiko-bot
2026-09-04  8:41     ` John Garry
2026-09-01 10:45 ` [PATCH v7 04/27] libmultipath: Add bio handling John Garry
2026-09-01 10:45 ` [PATCH v7 05/27] libmultipath: Add support for mpath_device management John Garry
2026-09-01 10:45 ` [PATCH v7 06/27] libmultipath: Add delayed removal support John Garry
2026-09-01 11:05   ` sashiko-bot
2026-09-04  9:10     ` John Garry
2026-09-01 10:45 ` [PATCH v7 07/27] libmultipath: Add sysfs helpers John Garry
2026-09-01 10:45 ` [PATCH v7 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-09-01 11:04   ` sashiko-bot
2026-09-04  9:19     ` John Garry
2026-09-01 10:45 ` [PATCH v7 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-09-01 10:45 ` [PATCH v7 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-09-01 10:45 ` [PATCH v7 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-09-01 10:45 ` [PATCH v7 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-09-01 10:45 ` [PATCH v7 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-09-01 10:45 ` [PATCH v7 14/27] scsi-multipath: support iopolicy John Garry
2026-09-01 11:11   ` sashiko-bot
2026-09-04 10:17     ` John Garry
2026-09-01 10:45 ` [PATCH v7 15/27] scsi-multipath: clone each bio John Garry
2026-09-01 10:45 ` [PATCH v7 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-09-01 11:02   ` sashiko-bot
2026-09-04 13:41     ` John Garry
2026-09-01 10:45 ` [PATCH v7 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-09-01 11:12   ` sashiko-bot [this message]
2026-09-04 10:28     ` John Garry
2026-09-01 10:45 ` [PATCH v7 18/27] scsi-multipath: failover handling John Garry
2026-09-01 11:09   ` sashiko-bot
2026-09-04 10:42     ` John Garry
2026-09-01 10:45 ` [PATCH v7 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-09-01 11:13   ` sashiko-bot
2026-09-04 10:44     ` John Garry
2026-09-01 10:45 ` [PATCH v7 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-09-01 11:25   ` sashiko-bot
2026-09-04 10:46     ` John Garry
2026-09-01 10:45 ` [PATCH v7 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-09-01 10:45 ` [PATCH v7 22/27] scsi: sd: add multipath disk class John Garry
2026-09-01 10:45 ` [PATCH v7 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-09-01 10:45 ` [PATCH v7 24/27] scsi: sd: support multipath disk John Garry
2026-09-01 11:19   ` sashiko-bot
2026-09-04 12:05     ` John Garry
2026-09-01 10:45 ` [PATCH v7 25/27] scsi: sd: add mpath_dev file John Garry
2026-09-01 10:45 ` [PATCH v7 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-09-01 10:45 ` [PATCH v7 27/27] scsi: sd: add mpath_queue_depth " John Garry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260901111258.4F9381F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.