From: sashiko-bot@kernel.org
To: "Miklos Szeredi" <mszeredi@redhat.com>
Cc: nvdimm@lists.linux.dev, linux-cxl@vger.kernel.org
Subject: Re: [PATCH v3 1/9] dax: replace exported dax_dev_get() with non-allocating dax_dev_find()
Date: Tue, 06 Oct 2026 18:10:55 +0000 [thread overview]
Message-ID: <sashiko-outbox-162320@kernel.org> (raw)
In-Reply-To: <20261006180115.1425232-2-mszeredi@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] dax: partially initialized dax_device returned by dax_dev_find() due to premature unlock_new_inode()
--
commit 9b2ac5a45a1d5eca0b23e84e793ce64303f44b4e
Author: John Groves <John@Groves.net>
dax: replace exported dax_dev_get() with non-allocating dax_dev_find()
dax_dev_get() uses iget5_locked() which creates a new inode if no
matching one exists, which is dangerous for external callers. This patch
introduces dax_dev_find() to provide lookup-only semantics without allocating
new inodes, and restricts dax_dev_get() to internal allocation use.
> diff --git a/drivers/dax/super.c b/drivers/dax/super.c
> index 45f84b0eb909a..824e1f6df3780 100644
> --- a/drivers/dax/super.c
> +++ b/drivers/dax/super.c
[ ... ]
> @@ -588,7 +588,41 @@ struct dax_device *dax_dev_get(dev_t devt)
>
> return dax_dev;
> }
> -EXPORT_SYMBOL_GPL(dax_dev_get);
> +
> +/**
> + * dax_dev_find - look up an existing dax_device by dev_t
> + * @devt: the device number to find
> + *
> + * Returns a dax_device with an elevated inode reference, or NULL if no
> + * device with the given dev_t exists. Unlike dax_dev_get(), this never
> + * allocates a new inode -- it is safe for external callers that are looking
> + * up devices from user-supplied or metadata-supplied dev_t values.
> + *
> + * Caller must put_dax() the returned device when done.
> + */
> +struct dax_device *dax_dev_find(dev_t devt)
> +{
> + struct dax_device *dax_dev;
> + struct inode *inode;
> + int id;
> +
> + inode = ilookup5(dax_superblock, hash_32(devt + DAXFS_MAGIC, 31),
> + dax_test, &devt);
> + if (!inode)
> + return NULL;
> +
> + dax_dev = to_dax_dev(inode);
> + id = dax_read_lock();
> + if (!dax_alive(dax_dev)) {
^^^^^^^^^^^^^^^^^^^^^^^
[Severity: High]
Does this introduce a regression where a concurrent external caller of
dax_dev_find() can obtain a partially initialized device?
When a thread calls alloc_dax(), it calls dax_dev_get() to allocate the inode.
Inside dax_dev_get(), the new inode is instantiated, DAXDEV_ALIVE is set, and
unlock_new_inode() is called:
drivers/dax/super.c:dax_dev_get() {
...
if (inode_state_read_once(inode) & I_NEW) {
set_bit(DAXDEV_ALIVE, &dax_dev->flags);
...
unlock_new_inode(inode);
}
return dax_dev;
}
This clears the I_NEW flag, making the inode fully accessible to concurrent
VFS lookups before dax_dev_get() returns.
If a concurrent thread calls dax_dev_find() at this moment, ilookup5() will
find the unlocked inode and return it. Since DAXDEV_ALIVE is already set,
dax_dev_find() will successfully return the device.
However, the allocating thread has not yet initialized the operations and
private data in alloc_dax():
drivers/dax/super.c:alloc_dax() {
...
dax_dev = dax_dev_get(devt);
if (!dax_dev)
goto err_dev;
dax_dev->ops = ops;
dax_dev->private = private;
return dax_dev;
}
Will this sequence allow an external caller to access a dax_device with
uninitialized ops and private pointers?
> + dax_read_unlock(id);
> + iput(inode);
> + return NULL;
> + }
> + dax_read_unlock(id);
> +
> + return dax_dev;
> +}
> +EXPORT_SYMBOL_GPL(dax_dev_find);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006180115.1425232-1-mszeredi@redhat.com?part=1
next prev parent reply other threads:[~2026-10-06 18:10 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 18:01 [PATCH v3 0/9] fuse: DAX device based extent maps (famfs) Miklos Szeredi
2026-10-06 18:01 ` [PATCH v3 1/9] dax: replace exported dax_dev_get() with non-allocating dax_dev_find() Miklos Szeredi
2026-10-06 18:10 ` sashiko-bot [this message]
2026-10-06 18:01 ` [PATCH v3 2/9] dax: use READ_ONCE() in dax_holder() Miklos Szeredi
2026-10-06 18:13 ` sashiko-bot
2026-10-08 1:02 ` Alison Schofield
2026-10-08 6:58 ` Miklos Szeredi
2026-10-06 18:01 ` [PATCH v3 3/9] fuse: add helpers for EIO return value with kernel message Miklos Szeredi
2026-10-06 21:03 ` Amir Goldstein
2026-10-06 18:01 ` [PATCH v3 4/9] fuse: support 64 bit, server allocated backing ID Miklos Szeredi
2026-10-06 18:20 ` sashiko-bot
2026-10-06 20:10 ` John Groves
2026-10-07 12:49 ` Miklos Szeredi
2026-10-06 22:08 ` Amir Goldstein
2026-10-07 12:54 ` Miklos Szeredi
2026-10-06 18:01 ` [PATCH v3 5/9] fuse: support opening 64 bit " Miklos Szeredi
2026-10-06 18:01 ` [PATCH v3 6/9] fuse: add support for opening dax device as backing Miklos Szeredi
2026-10-06 18:18 ` sashiko-bot
2026-10-06 18:01 ` [PATCH v3 7/9] fuse: add extent map data structure Miklos Szeredi
2026-10-06 18:17 ` sashiko-bot
2026-10-06 18:01 ` [PATCH v3 8/9] fuse: add extent map I/O support Miklos Szeredi
2026-10-06 18:22 ` sashiko-bot
2026-10-06 18:01 ` [PATCH v3 9/9] fuse: add support for striped backing Miklos Szeredi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-162320@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-cxl@vger.kernel.org \
--cc=mszeredi@redhat.com \
--cc=nvdimm@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox