* [PATCH] ublk: snapshot batch commands before preparing I/O
@ 2026-06-30 21:18 Yousef Alhouseen
2026-07-02 11:53 ` Ming Lei
2026-07-02 12:28 ` Jens Axboe
0 siblings, 2 replies; 3+ messages in thread
From: Yousef Alhouseen @ 2026-06-30 21:18 UTC (permalink / raw)
To: Ming Lei, Jens Axboe
Cc: Caleb Sander Mateos, linux-block, linux-kernel,
syzbot+1a67ee1aa79484801ec6, Yousef Alhouseen
The batch prepare path rereads its userspace element array when rolling
back a partially prepared batch. Userspace can change an already
processed tag before the second read, causing rollback to reject the
replacement tag and leave earlier I/O slots prepared. The
WARN_ON_ONCE() in the rollback path then fires.
Copy the bounded batch into kernel memory before changing any I/O state
and use the same snapshot for preparation and rollback. Commit and fetch
batches retain the existing chunked userspace walk.
Fixes: b256795b3606 ("ublk: handle UBLK_U_IO_PREP_IO_CMDS")
Reported-by: syzbot+1a67ee1aa79484801ec6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a67ee1aa79484801ec6
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
---
drivers/block/ublk_drv.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
index 4f6d9e652187..c2c11f2a01e7 100644
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -3584,6 +3584,7 @@ ublk_batch_auto_buf_reg(const struct ublk_batch_io *uc,
#define UBLK_CMD_BATCH_TMP_BUF_SZ (48 * 10)
struct ublk_batch_io_iter {
void __user *uaddr;
+ const u8 *kaddr;
unsigned done, total;
unsigned char elem_bytes;
/* copy to this buffer from user space */
@@ -3632,7 +3633,10 @@ static int ublk_walk_cmd_buf(struct ublk_batch_io_iter *iter,
while (iter->done < iter->total) {
unsigned int len = min(sizeof(iter->buf), iter->total - iter->done);
- if (copy_from_user(iter->buf, iter->uaddr + iter->done, len)) {
+ if (iter->kaddr) {
+ memcpy(iter->buf, iter->kaddr + iter->done, len);
+ } else if (copy_from_user(iter->buf, iter->uaddr + iter->done,
+ len)) {
pr_warn("ublk%d: read batch cmd buffer failed\n",
data->ub->dev_info.dev_id);
return -EFAULT;
@@ -3723,14 +3727,21 @@ static int ublk_handle_batch_prep_cmd(const struct ublk_batch_io_data *data)
.total = uc->nr_elem * uc->elem_bytes,
.elem_bytes = uc->elem_bytes,
};
+ void *cmd_buf;
int ret;
+ cmd_buf = vmemdup_user(iter.uaddr, iter.total);
+ if (IS_ERR(cmd_buf))
+ return PTR_ERR(cmd_buf);
+ iter.kaddr = cmd_buf;
+
mutex_lock(&data->ub->mutex);
ret = ublk_walk_cmd_buf(&iter, data, ublk_batch_prep_io);
if (ret && iter.done)
ublk_batch_revert_prep_cmd(&iter, data);
mutex_unlock(&data->ub->mutex);
+ kvfree(cmd_buf);
return ret;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] ublk: snapshot batch commands before preparing I/O
2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
@ 2026-07-02 11:53 ` Ming Lei
2026-07-02 12:28 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Ming Lei @ 2026-07-02 11:53 UTC (permalink / raw)
To: Yousef Alhouseen
Cc: Jens Axboe, Caleb Sander Mateos, linux-block, linux-kernel,
syzbot+1a67ee1aa79484801ec6
On Tue, Jun 30, 2026 at 4:18 PM Yousef Alhouseen
<alhouseenyousef@gmail.com> wrote:
>
> The batch prepare path rereads its userspace element array when rolling
> back a partially prepared batch. Userspace can change an already
> processed tag before the second read, causing rollback to reject the
> replacement tag and leave earlier I/O slots prepared. The
> WARN_ON_ONCE() in the rollback path then fires.
>
> Copy the bounded batch into kernel memory before changing any I/O state
> and use the same snapshot for preparation and rollback. Commit and fetch
> batches retain the existing chunked userspace walk.
>
> Fixes: b256795b3606 ("ublk: handle UBLK_U_IO_PREP_IO_CMDS")
> Reported-by: syzbot+1a67ee1aa79484801ec6@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=1a67ee1aa79484801ec6
> Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
The fix looks fine, given the copy is only added in prep stage, which
isn't part of fast io path:
Reviewed-by: Ming Lei <tom.leiming@gmail.com>
Thanks,
Ming Lei
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] ublk: snapshot batch commands before preparing I/O
2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
2026-07-02 11:53 ` Ming Lei
@ 2026-07-02 12:28 ` Jens Axboe
1 sibling, 0 replies; 3+ messages in thread
From: Jens Axboe @ 2026-07-02 12:28 UTC (permalink / raw)
To: Ming Lei, Yousef Alhouseen
Cc: Caleb Sander Mateos, linux-block, linux-kernel,
syzbot+1a67ee1aa79484801ec6
On Tue, 30 Jun 2026 23:18:27 +0200, Yousef Alhouseen wrote:
> The batch prepare path rereads its userspace element array when rolling
> back a partially prepared batch. Userspace can change an already
> processed tag before the second read, causing rollback to reject the
> replacement tag and leave earlier I/O slots prepared. The
> WARN_ON_ONCE() in the rollback path then fires.
>
> Copy the bounded batch into kernel memory before changing any I/O state
> and use the same snapshot for preparation and rollback. Commit and fetch
> batches retain the existing chunked userspace walk.
>
> [...]
Applied, thanks!
[1/1] ublk: snapshot batch commands before preparing I/O
commit: f01f5275feb77bac9fefbbf7cc584fe0b3850a92
Best regards,
--
Jens Axboe
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-02 12:28 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
2026-07-02 11:53 ` Ming Lei
2026-07-02 12:28 ` Jens Axboe
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox