Linux block layer
 help / color / mirror / Atom feed
From: Yang Erkun <yangerkun@huawei.com>
To: josef@toxicpanda.com, axboe@kernel.dk, hch@lst.de, yukuai@kernel.org
Cc: yi.zhang@huawei.com, chengzhihao1@huawei.com,
	echo.chenlin@huawei.com, leo.lilong@huaweicloud.com,
	wangkefeng.wang@huawei.com, huawei.libin@huawei.com,
	leijitang@huawei.com, linux-block@vger.kernel.org,
	nbd@other.debian.org
Subject: [PATCH v6 4/8] nbd: remove queue freeze in nbd_add_socket
Date: Tue,  4 Aug 2026 16:39:18 +0800	[thread overview]
Message-ID: <20260804083922.1927105-5-yangerkun@huawei.com> (raw)
In-Reply-To: <20260804083922.1927105-1-yangerkun@huawei.com>

nbd_add_socket() kreallocs config->socks, which a concurrent reader in
nbd_handle_cmd() could UAF; commit b98e762e3d71 ("nbd: freeze the queue
while we're adding connections")froze the queue to block that.  But the
freeze costs an RCU grace period on every socket added, and setup adds
them one by one.

After the previous patch, nbd_add_socket() is rejected once nbd->pid is
set, so it only runs during setup.  There the capacity is 0 and the
write cache is off (cleared on disconnect by the preceding patch, and
re-enabled only later in nbd_set_size), so submit_bio_noacct() rejects
every bio before it reaches the driver -- non-zero-sector ones via
bio_check_eod(), and flush-only ones via the !bdev_write_cache() branch.
No I/O is in flight, so the freeze is unnecessary.

Signed-off-by: Yang Erkun <yangerkun@huawei.com>
---
 drivers/block/nbd.c | 9 ---------
 1 file changed, 9 deletions(-)

diff --git a/drivers/block/nbd.c b/drivers/block/nbd.c
index 45e58191c5d7..8aeffc0eaaa1 100644
--- a/drivers/block/nbd.c
+++ b/drivers/block/nbd.c
@@ -1276,7 +1276,6 @@ static int nbd_add_socket(struct nbd_device *nbd, unsigned long arg,
 	struct socket *sock;
 	struct nbd_sock **socks;
 	struct nbd_sock *nsock;
-	unsigned int memflags;
 	int err;
 
 	/* Arg will be cast to int, check it to avoid overflow */
@@ -1294,12 +1293,6 @@ static int nbd_add_socket(struct nbd_device *nbd, unsigned long arg,
 		return err;
 	nbd_reclassify_socket(sock);
 
-	/*
-	 * We need to make sure we don't get any errant requests while we're
-	 * reallocating the ->socks array.
-	 */
-	memflags = blk_mq_freeze_queue(nbd->disk->queue);
-
 	if (!netlink && !nbd->task_setup &&
 	    !test_bit(NBD_RT_BOUND, &config->runtime_flags))
 		nbd->task_setup = current;
@@ -1339,12 +1332,10 @@ static int nbd_add_socket(struct nbd_device *nbd, unsigned long arg,
 	INIT_WORK(&nsock->work, nbd_pending_cmd_work);
 	socks[config->num_connections++] = nsock;
 	atomic_inc(&config->live_connections);
-	blk_mq_unfreeze_queue(nbd->disk->queue, memflags);
 
 	return 0;
 
 put_socket:
-	blk_mq_unfreeze_queue(nbd->disk->queue, memflags);
 	sockfd_put(sock);
 	return err;
 }
-- 
2.52.0


  parent reply	other threads:[~2026-08-04  8:48 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04  8:39 [PATCH v6 0/8] nbd: eliminate queue freeze/unfreeze overhead in connection setup Yang Erkun
2026-08-04  8:39 ` [PATCH v6 1/8] nbd: simplify find_fallback() by removing redundant logic Yang Erkun
2026-08-04  8:39 ` [PATCH v6 2/8] nbd: disallow NBD_SET_SOCK on an active device Yang Erkun
2026-08-04  8:39 ` [PATCH v6 3/8] nbd: clear queue limits on disconnect Yang Erkun
2026-08-05  6:27   ` yangerkun
2026-08-04  8:39 ` Yang Erkun [this message]
2026-08-04  8:39 ` [PATCH v6 5/8] nbd: skip queue freeze when setting size at device startup Yang Erkun
2026-08-04  8:39 ` [PATCH v6 6/8] nbd: factor out a nbd_genl_foreach_sock Yang Erkun
2026-08-04  8:39 ` [PATCH v6 7/8] nbd: remove queue freeze for newly created nbd from netlink path Yang Erkun
2026-08-04  8:39 ` [PATCH v6 8/8] nbd: add pre_defined_connections module parameter for pre-created devices Yang Erkun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260804083922.1927105-5-yangerkun@huawei.com \
    --to=yangerkun@huawei.com \
    --cc=axboe@kernel.dk \
    --cc=chengzhihao1@huawei.com \
    --cc=echo.chenlin@huawei.com \
    --cc=hch@lst.de \
    --cc=huawei.libin@huawei.com \
    --cc=josef@toxicpanda.com \
    --cc=leijitang@huawei.com \
    --cc=leo.lilong@huaweicloud.com \
    --cc=linux-block@vger.kernel.org \
    --cc=nbd@other.debian.org \
    --cc=wangkefeng.wang@huawei.com \
    --cc=yi.zhang@huawei.com \
    --cc=yukuai@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox