From: John Garry <john.garry@linux.dev>
To: sashiko-reviews@lists.linux.dev, John Garry <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v7 20/27] scsi-multipath: add scsi_mpath_{start,end}_request()
Date: Fri, 4 Sep 2026 11:46:30 +0100 [thread overview]
Message-ID: <f17d5e16-cc0e-4dd1-90c4-c7583cdf5ee9@linux.dev> (raw)
In-Reply-To: <20260901112533.2BC161F000E9@smtp.kernel.org>
On 9/1/26 12:25, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Bypassing `scsi_end_request()` on hard errors in `scsi_queue_rq()` permanently leaks multipath active counters and corrupts state for recycled blk-mq tags.
> --
>
> commit d6985f792a0819a7b56a04e827a71ff5a8dd2172
> Author: John Garry <john.garry@linux.dev>
>
> scsi-multipath: add scsi_mpath_{start,end}_request()
>
> This commit adds scsi_mpath_start_request() and scsi_mpath_end_request() to
> handle private multipath request data. It also introduces mpath_nr_active
> per SCSI host to track active requests for queue depth io-policies.
>
>> diff --git a/drivers/scsi/scsi_lib.c b/drivers/scsi/scsi_lib.c
>> index 189263ce56624..5916dead5422e 100644
>> --- a/drivers/scsi/scsi_lib.c
>> +++ b/drivers/scsi/scsi_lib.c
> [ ... ]
>> @@ -1918,6 +1921,9 @@ static blk_status_t scsi_queue_rq(struct blk_mq_hw_ctx *hctx,
>> memset(cmd->sense_buffer, 0, SCSI_SENSE_BUFFERSIZE);
>> cmd->submitter = SUBMITTED_BY_BLOCK_LAYER;
>>
>> + if (sdev->scsi_mpath_dev && is_mpath_request(req))
>> + scsi_mpath_start_request(req);
>> +
>> blk_mq_start_request(req);
>> if (blk_mq_is_reserved_rq(req)) {
>> reason = shost->hostt->queue_reserved_command(shost, cmd);
>
> [ ... ]
>
>> diff --git a/include/scsi/scsi_cmnd.h b/include/scsi/scsi_cmnd.h
>> index 8ecfb94049db5..52227e2cd9749 100644
>> --- a/include/scsi/scsi_cmnd.h
>> +++ b/include/scsi/scsi_cmnd.h
> [ ... ]
>> @@ -58,8 +58,11 @@ struct scsi_pointer {
>> */
>> #define SCMD_FORCE_EH_SUCCESS (1 << 3)
>> #define SCMD_FAIL_IF_RECOVERING (1 << 4)
>> +#define SCMD_MPATH_IO_STATS (1 << 5)
>> +#define SCMD_MPATH_CNT_ACTIVE (1 << 6)
>> /* flags preserved across unprep / reprep */
>> -#define SCMD_PRESERVED_FLAGS (SCMD_INITIALIZED | SCMD_FAIL_IF_RECOVERING)
>> +#define SCMD_PRESERVED_FLAGS (SCMD_INITIALIZED | SCMD_FAIL_IF_RECOVERING | \
>> + SCMD_MPATH_IO_STATS | SCMD_MPATH_CNT_ACTIVE)
>
> [Severity: High]
> Does preserving these multipath flags across requeue operations cause a leak
> of the mpath_nr_active counter and stale state for recycled tags?
>
> If a multipath request is dispatched, it calls scsi_mpath_start_request()
> which increments the host's mpath_nr_active counter and sets these flags.
>
> If this request is requeued (for example, if the host is busy) and then
> re-dispatched while the device is offline or entering recovery,
> scsi_device_state_check() in scsi_queue_rq() will fail early. This causes
> scsi_queue_rq() to return a hard error directly to the block layer.
>
> Because the block layer completes the request natively on hard dispatch
> errors, it bypasses scsi_end_request(), leaving scsi_mpath_end_request()
> uncalled. The mpath_nr_active counter is leaked.
This seems like something which needs to be fixed in scsi midlayer
>
> Furthermore, since SCMD_MPATH_IO_STATS and SCMD_MPATH_CNT_ACTIVE are
> preserved in SCMD_PRESERVED_FLAGS, any new request reusing this tag might
> inherit the stale flags, bypassing initialization in
> scsi_mpath_start_request().
>
> Could there be a mechanism to clear these flags and decrement the counter
> when a requeued request encounters a hard failure during re-dispatch?
>
next prev parent reply other threads:[~2026-09-04 10:46 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 10:44 [PATCH v7 00/27] Native SCSI Multipath support John Garry
2026-09-01 10:45 ` [PATCH v7 01/27] libmultipath: Add initial framework John Garry
2026-09-01 11:03 ` sashiko-bot
2026-09-04 8:36 ` John Garry
2026-09-01 10:45 ` [PATCH v7 02/27] libmultipath: Add basic gendisk support John Garry
2026-09-01 10:45 ` [PATCH v7 03/27] libmultipath: Add path selection support John Garry
2026-09-01 11:04 ` sashiko-bot
2026-09-04 8:41 ` John Garry
2026-09-01 10:45 ` [PATCH v7 04/27] libmultipath: Add bio handling John Garry
2026-09-01 10:45 ` [PATCH v7 05/27] libmultipath: Add support for mpath_device management John Garry
2026-09-01 10:45 ` [PATCH v7 06/27] libmultipath: Add delayed removal support John Garry
2026-09-01 11:05 ` sashiko-bot
2026-09-04 9:10 ` John Garry
2026-09-01 10:45 ` [PATCH v7 07/27] libmultipath: Add sysfs helpers John Garry
2026-09-01 10:45 ` [PATCH v7 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-09-01 11:04 ` sashiko-bot
2026-09-04 9:19 ` John Garry
2026-09-01 10:45 ` [PATCH v7 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-09-01 10:45 ` [PATCH v7 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-09-01 10:45 ` [PATCH v7 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-09-01 10:45 ` [PATCH v7 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-09-01 10:45 ` [PATCH v7 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-09-01 10:45 ` [PATCH v7 14/27] scsi-multipath: support iopolicy John Garry
2026-09-01 11:11 ` sashiko-bot
2026-09-04 10:17 ` John Garry
2026-09-01 10:45 ` [PATCH v7 15/27] scsi-multipath: clone each bio John Garry
2026-09-01 10:45 ` [PATCH v7 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-09-01 11:02 ` sashiko-bot
2026-09-04 13:41 ` John Garry
2026-09-01 10:45 ` [PATCH v7 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-09-01 11:12 ` sashiko-bot
2026-09-04 10:28 ` John Garry
2026-09-01 10:45 ` [PATCH v7 18/27] scsi-multipath: failover handling John Garry
2026-09-01 11:09 ` sashiko-bot
2026-09-04 10:42 ` John Garry
2026-09-01 10:45 ` [PATCH v7 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-09-01 11:13 ` sashiko-bot
2026-09-04 10:44 ` John Garry
2026-09-01 10:45 ` [PATCH v7 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-09-01 11:25 ` sashiko-bot
2026-09-04 10:46 ` John Garry [this message]
2026-09-01 10:45 ` [PATCH v7 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-09-01 10:45 ` [PATCH v7 22/27] scsi: sd: add multipath disk class John Garry
2026-09-01 10:45 ` [PATCH v7 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-09-01 10:45 ` [PATCH v7 24/27] scsi: sd: support multipath disk John Garry
2026-09-01 11:19 ` sashiko-bot
2026-09-04 12:05 ` John Garry
2026-09-01 10:45 ` [PATCH v7 25/27] scsi: sd: add mpath_dev file John Garry
2026-09-01 10:45 ` [PATCH v7 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-09-01 10:45 ` [PATCH v7 27/27] scsi: sd: add mpath_queue_depth " John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f17d5e16-cc0e-4dd1-90c4-c7583cdf5ee9@linux.dev \
--to=john.garry@linux.dev \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.