From: Nilay Shroff <nilay@linux.ibm.com>
To: Bart Van Assche <bvanassche@acm.org>, Jens Axboe <axboe@kernel.dk>
Cc: linux-block@vger.kernel.org, Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH 07/13] loop: Fix race conditions in loop_validate_file()
Date: Mon, 24 Aug 2026 23:36:21 +0530 [thread overview]
Message-ID: <2e6d7e6d-d6e2-4675-abc3-51f21e407ff4@linux.ibm.com> (raw)
In-Reply-To: <d998a691-4c43-4feb-ac5c-d174208c01db@acm.org>
On 8/24/26 9:45 PM, Bart Van Assche wrote:
> On 8/23/26 11:12 PM, Nilay Shroff wrote:
>> I see that with the refactoring and the changes in this patch, where
>> we now take an explicit reference to each backing file while
>> traversing the loop-device chain and hold the corresponding lo_mutex
>> while checking lo_state and acquiring that reference,
>> loop_validate_mutex may no longer be necessary.
>>
>> In particular, loop_get_backing_file() now atomically checks that
>> the loop device is in Lo_bound state and takes a reference to
>> lo_backing_file while holding lo_mutex. Therefore, if loop_clr_fd()
>> or loop_change_fd() concurrently replaces or clears the backing
>> file, the validator still holds its own reference. It also appears
>> that loop_change_fd() and loop_clr_fd() for the same loop device are already serialized by lo_mutex.
>>
>> So I am wondering whether loop_validate_mutex now be redundant? If
>> so, it may be worth consider removing it as part of this series.
>> That would simplify the locking and make the context annotations
>> considerably cleaner as well.
>
> Hi Nilay,
>
> That's an interesting question. I think we still need
> loop_validate_mutex. Without that mutex the hierarchy could be
> changed from linear into recursive after loop_validate_file()
> has verified the hierarchy and before the loop fd is changed.
> Removing loop_validate_mutex might introduce other race conditions
> than the one mentioned above.
>
Okay, that makes sense. So it looks like we can't easily get rid
of loop_validate_mutex. In that case, would it make sense to always
acquire loop_validate_mutex rather than acquiring it conditionally
only when the new backing file is a loop device?
I think loop_configure() and loop_change_fd() are control-plane
operations and are relatively infrequent, so taking
loop_validate_mutex should not add any noticeable overhead.
In return, we would have a single locking hierarchy and
the locking-context annotations would be much simpler and easier
to reason about.
What do you think?
Thanks,
--Nilay
next prev parent reply other threads:[~2026-08-24 18:06 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-20 19:57 [PATCH 00/13] Improve the loop driver Bart Van Assche
2026-08-20 19:57 ` [PATCH 01/13] loop: Fix the code for recursion detection Bart Van Assche
2026-08-20 19:57 ` [PATCH 02/13] loop: Reorder checks in loop_validate_file() Bart Van Assche
2026-08-20 19:57 ` [PATCH 03/13] loop: Enable context analysis Bart Van Assche
2026-08-20 19:57 ` [PATCH 04/13] loop: Assign a unique lockdep key to each lo_mutex instance Bart Van Assche
2026-08-20 19:57 ` [PATCH 05/13] loop: Add more __must_hold() annotations Bart Van Assche
2026-08-20 19:57 ` [PATCH 06/13] loop: Protect all lo_backing_file accesses with lo->lo_mutex Bart Van Assche
2026-08-20 19:57 ` [PATCH 07/13] loop: Fix race conditions in loop_validate_file() Bart Van Assche
2026-08-24 6:12 ` Nilay Shroff
2026-08-24 16:15 ` Bart Van Assche
2026-08-24 18:06 ` Nilay Shroff [this message]
2026-08-24 20:23 ` Bart Van Assche
2026-08-20 19:57 ` [PATCH 08/13] loop: Remove memory barriers Bart Van Assche
2026-08-20 19:57 ` [PATCH 09/13] loop: Split loop_change_fd() Bart Van Assche
2026-08-20 19:57 ` [PATCH 10/13] loop: Split loop_configure() Bart Van Assche
2026-08-20 19:57 ` [PATCH 11/13] loop: Remove the "bool global" function argument Bart Van Assche
2026-08-20 19:57 ` [PATCH 12/13] loop: Modify the loop_process_work() calling convention Bart Van Assche
2026-08-20 19:57 ` [PATCH 13/13] loop: Add __guarded_by() annotations Bart Van Assche
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2e6d7e6d-d6e2-4675-abc3-51f21e407ff4@linux.ibm.com \
--to=nilay@linux.ibm.com \
--cc=axboe@kernel.dk \
--cc=bvanassche@acm.org \
--cc=hch@lst.de \
--cc=linux-block@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.