All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nilay Shroff <nilay@linux.ibm.com>
To: Bart Van Assche <bvanassche@acm.org>, Jens Axboe <axboe@kernel.dk>
Cc: linux-block@vger.kernel.org, Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH 07/13] loop: Fix race conditions in loop_validate_file()
Date: Mon, 24 Aug 2026 11:42:46 +0530	[thread overview]
Message-ID: <b7f88eff-7886-4a85-9c97-7c88ba856780@linux.ibm.com> (raw)
In-Reply-To: <2b6da8a843526abf58d0d591ce487533bbce805e.1787255652.git.bvanassche@acm.org>

On 8/21/26 1:27 AM, Bart Van Assche wrote:
> Fix race conditions in loop_validate_file() by adding reference counting
> to the file chain traversal.
> 
> Ensure the file reference is kept alive during all dereferences by
> calling get_file() before the loop and deferring fput() until after we
> have locked the target device's lo_mutex and confirmed it is in the
> Lo_bound state.
> 
> Signed-off-by: Bart Van Assche <bvanassche@acm.org>
> ---
>   drivers/block/loop.c | 10 ++++++++--
>   1 file changed, 8 insertions(+), 2 deletions(-)
> 
> diff --git a/drivers/block/loop.c b/drivers/block/loop.c
> index c5f026520836..8b633ea6e72f 100644
> --- a/drivers/block/loop.c
> +++ b/drivers/block/loop.c
> @@ -520,7 +520,7 @@ static struct file *loop_get_backing_file(struct loop_device *lo)
>   	 * loop_configure().
>   	 */
>   	rmb();
> -	return lo->lo_backing_file;
> +	return get_file(lo->lo_backing_file);
>   }
>   
>   /* Returns 0 if and only if @file is not backed by loop device @bdev. */
> @@ -534,21 +534,27 @@ static int loop_validate_file(struct loop_device *lo, struct file *file,
>   	if (!S_ISREG(inode->i_mode) && !S_ISBLK(inode->i_mode))
>   		return -EINVAL;
>   
> +	get_file(f);
>   	/* Avoid recursion */
>   	while (is_loop_device(f)) {
>   		struct loop_device *l;
> +		struct file *prev_f = f;
>   		struct block_device *f_bdev = loop_get_bdev(f);
>   
>   		lockdep_assert_held(&loop_validate_mutex);
> -		if (f_bdev->bd_disk == bdev->bd_disk)
> +		if (f_bdev->bd_disk == bdev->bd_disk) {
> +			fput(f);
>   			return -EBADF;
> +		}
>   
>   		l = f_bdev->bd_disk->private_data;
>   		scoped_guard(mutex, &l->lo_mutex)
>   			f = loop_get_backing_file(l);
> +		fput(prev_f);
>   		if (!f)
>   			return -EINVAL;
>   	}
> +	fput(f);
>   	return 0;
>   }
>   
I see that with the refactoring and the changes in this patch, where we now
take an explicit reference to each backing file while traversing the loop-device
chain and hold the corresponding lo_mutex while checking lo_state and acquiring
that reference, loop_validate_mutex may no longer be necessary.

In particular, loop_get_backing_file() now atomically checks that the loop device
is in Lo_bound state and takes a reference to lo_backing_file while holding
lo_mutex. Therefore, if loop_clr_fd() or loop_change_fd() concurrently replaces
or clears the backing file, the validator still holds its own reference. It also
appears that loop_change_fd() and loop_clr_fd() for the same loop device are
already serialized by lo_mutex.

So I am wondering whether loop_validate_mutex now be redundant? If so, it may
be worth consider removing it as part of this series. That would simplify the
locking and make the context annotations considerably cleaner as well.

Thanks,
--Nilay


  reply	other threads:[~2026-08-24  6:12 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-20 19:57 [PATCH 00/13] Improve the loop driver Bart Van Assche
2026-08-20 19:57 ` [PATCH 01/13] loop: Fix the code for recursion detection Bart Van Assche
2026-08-20 19:57 ` [PATCH 02/13] loop: Reorder checks in loop_validate_file() Bart Van Assche
2026-08-20 19:57 ` [PATCH 03/13] loop: Enable context analysis Bart Van Assche
2026-08-20 19:57 ` [PATCH 04/13] loop: Assign a unique lockdep key to each lo_mutex instance Bart Van Assche
2026-08-20 19:57 ` [PATCH 05/13] loop: Add more __must_hold() annotations Bart Van Assche
2026-08-20 19:57 ` [PATCH 06/13] loop: Protect all lo_backing_file accesses with lo->lo_mutex Bart Van Assche
2026-08-20 19:57 ` [PATCH 07/13] loop: Fix race conditions in loop_validate_file() Bart Van Assche
2026-08-24  6:12   ` Nilay Shroff [this message]
2026-08-24 16:15     ` Bart Van Assche
2026-08-24 18:06       ` Nilay Shroff
2026-08-24 20:23         ` Bart Van Assche
2026-08-20 19:57 ` [PATCH 08/13] loop: Remove memory barriers Bart Van Assche
2026-08-20 19:57 ` [PATCH 09/13] loop: Split loop_change_fd() Bart Van Assche
2026-08-20 19:57 ` [PATCH 10/13] loop: Split loop_configure() Bart Van Assche
2026-08-20 19:57 ` [PATCH 11/13] loop: Remove the "bool global" function argument Bart Van Assche
2026-08-20 19:57 ` [PATCH 12/13] loop: Modify the loop_process_work() calling convention Bart Van Assche
2026-08-20 19:57 ` [PATCH 13/13] loop: Add __guarded_by() annotations Bart Van Assche

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b7f88eff-7886-4a85-9c97-7c88ba856780@linux.ibm.com \
    --to=nilay@linux.ibm.com \
    --cc=axboe@kernel.dk \
    --cc=bvanassche@acm.org \
    --cc=hch@lst.de \
    --cc=linux-block@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.