Linux CXL
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Gregory Price" <gourry@gourry.net>
Cc: nvdimm@lists.linux.dev, linux-cxl@vger.kernel.org
Subject: Re: [PATCH v5 8/9] dax/kmem: add sysfs interface for atomic whole-device hotplug
Date: Wed, 24 Jun 2026 15:11:21 +0000	[thread overview]
Message-ID: <20260624151122.AFE551F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260624145744.3532049-9-gourry@gourry.net>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The protection against deadlocks during driver unbind can be completely bypassed if the underlying memory blocks are manually onlined via the core memory sysfs, causing state desynchronization.
- [Medium] any_hotremove_failed is irrevocably set on recoverable sysfs hotremove failures, leading to a permanent leak of kmem_name.
--

commit fa89899811083ada324ea3db8204b1c135005af5
Author: Gregory Price <gourry@gourry.net>
Subject: dax/kmem: add sysfs interface for atomic whole-device hotplug

This patch adds a new 'state' sysfs attribute for dax_kmem devices to enable
atomic whole-device hotplug operations. It also updates the unbind logic to
prevent deadlocks by omitting memory removal if the memory blocks are
currently online.

> diff --git a/drivers/dax/kmem.c b/drivers/dax/kmem.c
> index a45e50def5371..340486586d82c 100644
> --- a/drivers/dax/kmem.c
> +++ b/drivers/dax/kmem.c

[ ... ]

> +static int dax_kmem_do_hotremove(struct dev_dax *dev_dax,
> +				 struct dax_kmem_data *data)
> +{

[ ... ]

> +	rc = offline_and_remove_memory_ranges(ranges, nr_ranges);
> +	kfree(ranges);
> +	if (rc) {
> +		any_hotremove_failed = true;
> +		dev_err(dev, "hotremove failed, device left online: %d\n", rc);
> +		return rc;
> +	}

[Severity: Medium]
Does this permanently leak kmem_name on recoverable sysfs failures?

If a user attempts to unplug a device via sysfs and the hotremove fails
transiently (e.g., due to memory being in use), any_hotremove_failed is set
to true. Even if the user retries and the unplug later succeeds, this global
flag is never cleared, which will prevent freeing kmem_name during module
unload.

[ ... ]

> @@ -348,20 +490,26 @@ static int dev_dax_kmem_probe(struct dev_dax *dev_dax)
>  #ifdef CONFIG_MEMORY_HOTREMOVE
>  static void dev_dax_kmem_remove(struct dev_dax *dev_dax)
>  {

[ ... ]

> +	if (dax_kmem_state_is_online(data->state)) {
> +		dev_warn(dev, "Hotplug regions stuck online until reboot\n");
> +		any_hotremove_failed = true;
> +		return;
> +	} else if (data->state == MMOP_OFFLINE &&
> +	    dax_kmem_do_hotremove(dev_dax, data)) {
> +		dev_warn(dev, "Unplug failed, resources leaked until reboot\n");
>  		return;
>  	}

[Severity: High]
Can this deadlock during unbind if the memory state is desynchronized?

If the device is configured with auto_online_blocks=offline, data->state is
initially MMOP_OFFLINE. If a user manually onlines the underlying memory
blocks via the generic /sys/devices/system/memory/memoryX/state sysfs
interface, data->state remains MMOP_OFFLINE.

During unbind, dev_dax_kmem_remove() will evaluate
dax_kmem_state_is_online(data->state) as false and proceed to call
dax_kmem_do_hotremove() instead of safely aborting. This attempts to offline
the blocks while holding the device unbind lock, bypassing the intended
deadlock protection.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260624145744.3532049-1-gourry@gourry.net?part=8

  reply	other threads:[~2026-06-24 15:11 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-24 14:57 [PATCH v5 0/9] dax/kmem: atomic whole-device hotplug via sysfs Gregory Price
2026-06-24 14:57 ` [PATCH v5 1/9] mm/memory: add memory_block_aligned_range() helper Gregory Price
2026-06-24 15:08   ` sashiko-bot
2026-06-24 14:57 ` [PATCH v5 2/9] mm/memory_hotplug: pass online_type to online_memory_block() via arg Gregory Price
2026-06-24 16:28   ` Gupta, Pankaj
2026-06-24 14:57 ` [PATCH v5 3/9] mm/memory_hotplug: export mhp_get_default_online_type Gregory Price
2026-06-24 14:57 ` [PATCH v5 4/9] mm/memory_hotplug: add __add_memory_driver_managed() with online_type arg Gregory Price
2026-06-24 16:41   ` Gupta, Pankaj
2026-06-24 14:57 ` [PATCH v5 5/9] mm/memory_hotplug: offline_and_remove_memory_ranges() Gregory Price
2026-06-24 15:11   ` sashiko-bot
2026-06-24 14:57 ` [PATCH v5 6/9] dax: plumb hotplug online_type through dax Gregory Price
2026-06-24 15:12   ` sashiko-bot
2026-06-24 14:57 ` [PATCH v5 7/9] dax/kmem: extract hotplug/hotremove helper functions Gregory Price
2026-06-24 15:09   ` sashiko-bot
2026-06-24 14:57 ` [PATCH v5 8/9] dax/kmem: add sysfs interface for atomic whole-device hotplug Gregory Price
2026-06-24 15:11   ` sashiko-bot [this message]
2026-06-24 14:57 ` [PATCH v5 9/9] selftests/dax: add dax/kmem hotplug sysfs regression test Gregory Price
2026-06-24 15:12   ` sashiko-bot
2026-06-24 18:59 ` [PATCH v5 0/9] dax/kmem: atomic whole-device hotplug via sysfs Gregory Price

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260624151122.AFE551F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=gourry@gourry.net \
    --cc=linux-cxl@vger.kernel.org \
    --cc=nvdimm@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox