All of lore.kernel.org
 help / color / mirror / Atom feed
From: Niklas Cassel <cassel@kernel.org>
To: Damien Le Moal <dlemoal@kernel.org>
Cc: Stefan Hajnoczi <stefanha@redhat.com>,
	Kevin Wolf <kwolf@redhat.com>, Hanna Reitz <hreitz@redhat.com>,
	Fam Zheng <fam@euphon.net>, Sam Li <faithilikerun@gmail.com>,
	qemu-block@nongnu.org, qemu-devel@nongnu.org
Subject: Re: [PATCH v3 12/12] file-posix: reject a zone append to a full or conventional zone
Date: Mon, 7 Sep 2026 12:47:42 +0200	[thread overview]
Message-ID: <ap6WTkOuuXVqNEEw@ryzen> (raw)
In-Reply-To: <08401f4f-1bb6-4445-b157-9135458d32ea@kernel.org>

On Sat, Sep 05, 2026 at 09:38:08AM +0900, Damien Le Moal wrote:
> On 9/5/26 01:18, Niklas Cassel wrote:
> > raw_co_prw() replaces the offset of a zone append with the write pointer
> > of the addressed zone, which assumes that the stored value names a
> > position inside that zone. It does not in two cases.
> > 
> > A full zone has its write pointer recorded at the end of the zone, since
> > get_zones_wp() stores start + len for BLK_ZONE_COND_FULL. That is the
> > first sector of the following zone, so the append is submitted there. The
> > kernel accepts it whenever that zone is empty, because it is a legal
> > write at its write pointer, and the completion path advances the wrong
> > zone because it recomputes the zone index from the replaced offset. The
> > data is written to a zone that was never addressed and success is
> > returned:
> > 
> >   zone 2 finished, then a 4 KiB append to zone 2:
> >   After zap done, the append sector is 0x180000     <- zone 3
> >   zone 2: wptr 0x180000, zcond:14 (full)
> >   zone 3: wptr 0x180008                             <- advanced
> > 
> > A conventional zone has no write pointer at all, and its array entry
> > carries only the type marker in the top bit, so the offset becomes
> > negative and the write fails with EINVAL. That is harmless but it reports
> > nothing about the actual mistake.
> > 
> > Reject both while the write pointer lock is held, since the state has to
> > be read and acted on atomically. check_zoned_request() in virtio-blk
> > refuses an append to a conventional zone, so that case needs a caller
> > that goes to the driver directly, but nothing there examines whether a
> > zone is full, so a guest can reach the misdirected write.
> > 
> > Fixes: 4751d09adcc3 ("block: introduce zone append write for zoned devices")
> > Signed-off-by: Niklas Cassel <cassel@kernel.org>
> 
> Looks good, modulo the comment below that needs to be addressed.
> With that fixed, feel free to add:
> 
> Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
> 
> > diff --git a/block/io.c b/block/io.c
> > index b59c7fdf3e..452254bc63 100644
> > --- a/block/io.c
> > +++ b/block/io.c
> > @@ -3378,6 +3378,15 @@ uint32_t bdrv_zone_index(BlockDriverState *bs, uint64_t offset)
> >      return offset >> ctz64(bs->bl.zone_size);
> >  }
> >  
> > +bool bdrv_zone_is_full(BlockDriverState *bs, uint32_t index)
> > +{
> > +    uint64_t zone_end = MIN((uint64_t)(index + 1) * bs->bl.zone_size,
> 
> I think this should look at zone capacity, not size. For cases where we have
> zone cap < zone size, zone full condition is reached when the write pointer is
> at the zone capacity.

There is no concept of zone capacity in QEMU upstream yet.

It is added in Sam Li's QCOW2 zoned patch series.

But yes, I already have a patch that modifies bdrv_zone_is_full() to use
zone capacity rather than zone size, once it is introduced.


Kind regards,
Niklas


  reply	other threads:[~2026-09-07 10:48 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04 16:17 [PATCH v3 00/12] block: fix the zone write granularity and the zone append limit Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 01/12] block: widen BlockLimits.zone_size to uint64_t Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 02/12] virtio-blk: do not merge requests across a zone boundary Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 03/12] block: add a helper for the index of the zone an offset falls in Niklas Cassel
2026-09-05  0:32   ` Damien Le Moal
2026-09-04 16:17 ` [PATCH v3 04/12] virtio-blk: report the effective zone write granularity Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 05/12] virtio-blk: check the write granularity of writes to sequential zones Niklas Cassel
2026-09-05  0:33   ` Damien Le Moal
2026-09-04 16:17 ` [PATCH v3 06/12] hw/block: reject a zoned device whose write pointers are unaddressable Niklas Cassel
2026-09-05  0:34   ` Damien Le Moal
2026-09-04 16:17 ` [PATCH v3 07/12] block: reject zone appends that are not a multiple of the sector size Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 08/12] file-posix: remove the zone append write granularity check Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 09/12] file-posix: base the zone append limit on the transfer limit Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 10/12] virtio-blk: derive the maximum zone append size Niklas Cassel
2026-09-04 16:17 ` [PATCH v3 11/12] file-posix: reject a zone append past the device capacity Niklas Cassel
2026-09-04 16:18 ` [PATCH v3 12/12] file-posix: reject a zone append to a full or conventional zone Niklas Cassel
2026-09-05  0:38   ` Damien Le Moal
2026-09-07 10:47     ` Niklas Cassel [this message]
2026-09-08  0:18       ` Damien Le Moal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ap6WTkOuuXVqNEEw@ryzen \
    --to=cassel@kernel.org \
    --cc=dlemoal@kernel.org \
    --cc=faithilikerun@gmail.com \
    --cc=fam@euphon.net \
    --cc=hreitz@redhat.com \
    --cc=kwolf@redhat.com \
    --cc=qemu-block@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=stefanha@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.