From: Hari Mishal <harimishal1@gmail.com>
To: Keith Busch <kbusch@kernel.org>, Jens Axboe <axboe@kernel.dk>,
Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>
Cc: Hannes Reinecke <hare@suse.de>,
Kanchan Joshi <joshi.k@samsung.com>,
Nitesh Shetty <nj.shetty@samsung.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org,
Hari Mishal <harimishal1@gmail.com>
Subject: [PATCH 0/2] nvme: fix racy access to FDP placement ID array
Date: Sat, 25 Jul 2026 15:51:09 +0200 [thread overview]
Message-ID: <20260725135111.14041-1-harimishal1@gmail.com> (raw)
nvme_ns_head can be shared across multiple nvme_ns paths (multipath,
or dual-port/multi-controller subsystems). nvme_query_fdp_info()
populates head->nr_plids/head->plids the first time a namespace's
FDP configuration is registered, but nothing protects that pair from
concurrent access - two paths scanning the same namespace at the
same time can race to populate it, and depending on how the writes
interleave a concurrent reader can hit a NULL dereference or an
out-of-bounds read.
Patch 1 adds a spinlock and closes the race.
Patch 2 is a small, unrelated cleanup on code sitting right next to
what patch 1 touches: it drops a WARN_ON_ONCE that turns out to be
unreachable through any current path, since the value it guards
against is already validated upstream in the block layer and F2FS
before a bio ever carries it. Happy to drop this one or send it
separately if you'd rather keep it out of this series.
Hari Mishal (2):
nvme: fix racy access to FDP placement ID array
nvme: drop WARN_ON_ONCE on write_stream bounds check
drivers/nvme/host/core.c | 63 ++++++++++++++++++++++++++--------------
drivers/nvme/host/nvme.h | 1 +
2 files changed, 43 insertions(+), 21 deletions(-)
--
2.43.0
next reply other threads:[~2026-07-25 13:51 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-25 13:51 Hari Mishal [this message]
2026-07-25 13:51 ` [PATCH 1/2] nvme: fix racy access to FDP placement ID array Hari Mishal
2026-07-27 13:31 ` Kanchan Joshi
2026-07-27 14:22 ` Kanchan Joshi
2026-07-25 13:51 ` [PATCH 2/2] nvme: drop WARN_ON_ONCE on write_stream bounds check Hari Mishal
2026-07-27 14:24 ` Keith Busch
2026-07-27 19:19 ` Greg Kroah-Hartman
2026-07-27 22:51 ` Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260725135111.14041-1-harimishal1@gmail.com \
--to=harimishal1@gmail.com \
--cc=axboe@kernel.dk \
--cc=gregkh@linuxfoundation.org \
--cc=hare@suse.de \
--cc=hch@lst.de \
--cc=joshi.k@samsung.com \
--cc=kbusch@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=nj.shetty@samsung.com \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox