Linux block layer
 help / color / mirror / Atom feed
* [PATCH] ublk: snapshot batch commands before preparing I/O
@ 2026-06-30 21:18 Yousef Alhouseen
  2026-07-02 11:53 ` Ming Lei
  2026-07-02 12:28 ` Jens Axboe
  0 siblings, 2 replies; 3+ messages in thread
From: Yousef Alhouseen @ 2026-06-30 21:18 UTC (permalink / raw)
  To: Ming Lei, Jens Axboe
  Cc: Caleb Sander Mateos, linux-block, linux-kernel,
	syzbot+1a67ee1aa79484801ec6, Yousef Alhouseen

The batch prepare path rereads its userspace element array when rolling
back a partially prepared batch. Userspace can change an already
processed tag before the second read, causing rollback to reject the
replacement tag and leave earlier I/O slots prepared. The
WARN_ON_ONCE() in the rollback path then fires.

Copy the bounded batch into kernel memory before changing any I/O state
and use the same snapshot for preparation and rollback. Commit and fetch
batches retain the existing chunked userspace walk.

Fixes: b256795b3606 ("ublk: handle UBLK_U_IO_PREP_IO_CMDS")
Reported-by: syzbot+1a67ee1aa79484801ec6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1a67ee1aa79484801ec6
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
---
 drivers/block/ublk_drv.c | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
index 4f6d9e652187..c2c11f2a01e7 100644
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -3584,6 +3584,7 @@ ublk_batch_auto_buf_reg(const struct ublk_batch_io *uc,
 #define UBLK_CMD_BATCH_TMP_BUF_SZ  (48 * 10)
 struct ublk_batch_io_iter {
 	void __user *uaddr;
+	const u8 *kaddr;
 	unsigned done, total;
 	unsigned char elem_bytes;
 	/* copy to this buffer from user space */
@@ -3632,7 +3633,10 @@ static int ublk_walk_cmd_buf(struct ublk_batch_io_iter *iter,
 	while (iter->done < iter->total) {
 		unsigned int len = min(sizeof(iter->buf), iter->total - iter->done);
 
-		if (copy_from_user(iter->buf, iter->uaddr + iter->done, len)) {
+		if (iter->kaddr) {
+			memcpy(iter->buf, iter->kaddr + iter->done, len);
+		} else if (copy_from_user(iter->buf, iter->uaddr + iter->done,
+				  len)) {
 			pr_warn("ublk%d: read batch cmd buffer failed\n",
 					data->ub->dev_info.dev_id);
 			return -EFAULT;
@@ -3723,14 +3727,21 @@ static int ublk_handle_batch_prep_cmd(const struct ublk_batch_io_data *data)
 		.total = uc->nr_elem * uc->elem_bytes,
 		.elem_bytes = uc->elem_bytes,
 	};
+	void *cmd_buf;
 	int ret;
 
+	cmd_buf = vmemdup_user(iter.uaddr, iter.total);
+	if (IS_ERR(cmd_buf))
+		return PTR_ERR(cmd_buf);
+	iter.kaddr = cmd_buf;
+
 	mutex_lock(&data->ub->mutex);
 	ret = ublk_walk_cmd_buf(&iter, data, ublk_batch_prep_io);
 
 	if (ret && iter.done)
 		ublk_batch_revert_prep_cmd(&iter, data);
 	mutex_unlock(&data->ub->mutex);
+	kvfree(cmd_buf);
 	return ret;
 }
 
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] ublk: snapshot batch commands before preparing I/O
  2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
@ 2026-07-02 11:53 ` Ming Lei
  2026-07-02 12:28 ` Jens Axboe
  1 sibling, 0 replies; 3+ messages in thread
From: Ming Lei @ 2026-07-02 11:53 UTC (permalink / raw)
  To: Yousef Alhouseen
  Cc: Jens Axboe, Caleb Sander Mateos, linux-block, linux-kernel,
	syzbot+1a67ee1aa79484801ec6

On Tue, Jun 30, 2026 at 4:18 PM Yousef Alhouseen
<alhouseenyousef@gmail.com> wrote:
>
> The batch prepare path rereads its userspace element array when rolling
> back a partially prepared batch. Userspace can change an already
> processed tag before the second read, causing rollback to reject the
> replacement tag and leave earlier I/O slots prepared. The
> WARN_ON_ONCE() in the rollback path then fires.
>
> Copy the bounded batch into kernel memory before changing any I/O state
> and use the same snapshot for preparation and rollback. Commit and fetch
> batches retain the existing chunked userspace walk.
>
> Fixes: b256795b3606 ("ublk: handle UBLK_U_IO_PREP_IO_CMDS")
> Reported-by: syzbot+1a67ee1aa79484801ec6@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=1a67ee1aa79484801ec6
> Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>

The fix looks fine, given the copy is only added in prep stage, which
isn't part of fast io path:

Reviewed-by: Ming Lei <tom.leiming@gmail.com>



Thanks,
Ming Lei

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] ublk: snapshot batch commands before preparing I/O
  2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
  2026-07-02 11:53 ` Ming Lei
@ 2026-07-02 12:28 ` Jens Axboe
  1 sibling, 0 replies; 3+ messages in thread
From: Jens Axboe @ 2026-07-02 12:28 UTC (permalink / raw)
  To: Ming Lei, Yousef Alhouseen
  Cc: Caleb Sander Mateos, linux-block, linux-kernel,
	syzbot+1a67ee1aa79484801ec6


On Tue, 30 Jun 2026 23:18:27 +0200, Yousef Alhouseen wrote:
> The batch prepare path rereads its userspace element array when rolling
> back a partially prepared batch. Userspace can change an already
> processed tag before the second read, causing rollback to reject the
> replacement tag and leave earlier I/O slots prepared. The
> WARN_ON_ONCE() in the rollback path then fires.
> 
> Copy the bounded batch into kernel memory before changing any I/O state
> and use the same snapshot for preparation and rollback. Commit and fetch
> batches retain the existing chunked userspace walk.
> 
> [...]

Applied, thanks!

[1/1] ublk: snapshot batch commands before preparing I/O
      commit: f01f5275feb77bac9fefbbf7cc584fe0b3850a92

Best regards,
-- 
Jens Axboe




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-07-02 12:28 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-30 21:18 [PATCH] ublk: snapshot batch commands before preparing I/O Yousef Alhouseen
2026-07-02 11:53 ` Ming Lei
2026-07-02 12:28 ` Jens Axboe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox