From: Guixin Liu <kanie@linux.alibaba.com>
To: Keith Busch <kbusch@kernel.org>, Jens Axboe <axboe@kernel.dk>,
Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>,
Nilay Shroff <nilay@linux.ibm.com>,
Daniel Wagner <dwagner@suse.de>,
John Garry <john.g.garry@oracle.com>,
Hannes Reinecke <hare@suse.de>
Cc: linux-nvme@lists.infradead.org
Subject: [PATCH] nvme-multipath: set BLK_FEAT_ZONED only after the zone info is known
Date: Mon, 14 Sep 2026 18:57:13 +0800 [thread overview]
Message-ID: <20260914105713.155704-1-kanie@linux.alibaba.com> (raw)
The namespace head is marked zoned at allocation time based only on
the command set identifier, before any zone information has been
queried. If the zone info query fails on the first scan, the path
namespace is registered without zoned limits while the head still
advertises the zoned capability with a zone size of zero. Reporting
zones or writing to the head then shifts by ilog2(0), triggering the
UBSAN shift-out-of-bounds report in the report-zones and write paths.
Drop the zoned feature from the head allocation and inherit it from
the path namespace: the head limits refresh already stacks the zoned
feature, the zone size and the zone resource limits from the path
queue, so the head matches the path namespace and becomes zoned once a
revalidation succeeds. This also stops marking the head zoned when
CONFIG_BLK_DEV_ZONED is off, which used to fail the head allocation
with a WARN.
Found by code inspection while reviewing the nvme-7.3 branch.
Tested with a null_blk zoned namespace exported over two nvmet-tcp
ports, with the target patched to fail the command set specific
identify: the head no longer comes up zoned with zone size 0, the
UBSAN report is gone, and an ns-rescan once the identify succeeds again
transitions the head to zoned with the correct zone size.
Fixes: 28982ad73d6a ("nvme: set BLK_FEAT_ZONED for ZNS multipath disks")
Fixes: 3838e80fcfb3 ("nvme: skip the zoned limits update if the zone info query failed")
Cc: stable@vger.kernel.org
Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
---
drivers/nvme/host/multipath.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/nvme/host/multipath.c b/drivers/nvme/host/multipath.c
index 75dbb58286a3..cdfaa04c25f8 100644
--- a/drivers/nvme/host/multipath.c
+++ b/drivers/nvme/host/multipath.c
@@ -763,8 +763,6 @@ int nvme_mpath_alloc_disk(struct nvme_ctrl *ctrl, struct nvme_ns_head *head)
lim.dma_alignment = 3;
lim.features |= BLK_FEAT_IO_STAT | BLK_FEAT_NOWAIT |
BLK_FEAT_POLL | BLK_FEAT_ATOMIC_WRITES | BLK_FEAT_PCI_P2PDMA;
- if (head->ids.csi == NVME_CSI_ZNS)
- lim.features |= BLK_FEAT_ZONED;
head->disk = blk_alloc_disk(&lim, ctrl->numa_node);
if (IS_ERR(head->disk))
--
2.43.7
next reply other threads:[~2026-09-14 10:57 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 10:57 Guixin Liu [this message]
2026-09-15 6:36 ` [PATCH] nvme-multipath: set BLK_FEAT_ZONED only after the zone info is known Christoph Hellwig
2026-09-15 8:51 ` Guixin Liu
2026-09-22 8:17 ` Guixin Liu
2026-09-22 15:13 ` Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914105713.155704-1-kanie@linux.alibaba.com \
--to=kanie@linux.alibaba.com \
--cc=axboe@kernel.dk \
--cc=dwagner@suse.de \
--cc=hare@suse.de \
--cc=hch@lst.de \
--cc=john.g.garry@oracle.com \
--cc=kbusch@kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=nilay@linux.ibm.com \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox