From: "Chen Cheng" <chencheng@fnnas.com>
To: <linux-raid@vger.kernel.org>, <yukuai@fygo.io>, <xiaoni@fygo.io>
Cc: <chencheng@fnnas.com>, <linux-kernel@vger.kernel.org>,
<syzbot+de94ddbfff0c9e6fe030@syzkaller.appspotmail.com>
Subject: [PATCH v2] md/raid5: reject raid4/5 arrays with too few disks
Date: Sat, 5 Sep 2026 18:43:23 +0800 [thread overview]
Message-ID: <20260905104323.2202902-1-chencheng@fnnas.com> (raw)
From: Chen Cheng <chencheng@fnnas.com>
raid4 requires at least two disks and raid5 requires at least three disks,
but setup_conf() only rejects raid6 arrays with fewer than four disks. As a
result, an invalid raid4 or raid5 array can be assembled with no data disks
and later reach raid5_set_limits().
Reject such arrays before the r5conf is created. This prevents the invalid
geometry from reaching queue limit setup, where roundup_pow_of_two() can be
called with a zero stripe size.
Reported-by: syzbot+de94ddbfff0c9e6fe030@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/r/6a778c82.01d0871a.3a0d52.006a.GAE@google.com/
Fixes: f63f17350e53 ("md/raid5: use the atomic queue limit update APIs")
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
---
v1->v2:
- Fix wrong tags
- Check raid-4 also
---
drivers/md/raid5.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index b91545ce090d..4d8bb0cf2605 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -7655,13 +7655,16 @@ static struct r5conf *setup_conf(struct mddev *mddev)
&& !algorithm_valid_raid6(mddev->new_layout))) {
pr_warn("md/raid:%s: layout %d not supported\n",
mdname(mddev), mddev->new_layout);
return ERR_PTR(-EIO);
}
- if (mddev->new_level == 6 && mddev->raid_disks < 4) {
- pr_warn("md/raid:%s: not enough configured devices (%d, minimum 4)\n",
- mdname(mddev), mddev->raid_disks);
+ if ((mddev->new_level == 4 && mddev->raid_disks < 2) ||
+ (mddev->new_level == 5 && mddev->raid_disks < 3) ||
+ (mddev->new_level == 6 && mddev->raid_disks < 4)) {
+ pr_warn("md/raid:%s: not enough configured devices (%d, minimum %d)\n",
+ mdname(mddev), mddev->raid_disks,
+ mddev->new_level - 2);
return ERR_PTR(-EINVAL);
}
if (!mddev->new_chunk_sectors ||
(mddev->new_chunk_sectors << 9) % PAGE_SIZE ||
--
2.55.0
next reply other threads:[~2026-09-05 10:44 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 10:43 Chen Cheng [this message]
2026-09-05 11:00 ` [PATCH v2] md/raid5: reject raid4/5 arrays with too few disks sashiko-bot
2026-09-07 6:35 ` yu kuai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905104323.2202902-1-chencheng@fnnas.com \
--to=chencheng@fnnas.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-raid@vger.kernel.org \
--cc=syzbot+de94ddbfff0c9e6fe030@syzkaller.appspotmail.com \
--cc=xiaoni@fygo.io \
--cc=yukuai@fygo.io \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.