Linux RAID subsystem development
 help / color / mirror / Atom feed
* [PATCH v3] md: do not _put wrong device in md_seq_next
@ 2023-09-14 15:24 Mariusz Tkaczyk
  2023-09-14 17:57 ` Song Liu
  0 siblings, 1 reply; 2+ messages in thread
From: Mariusz Tkaczyk @ 2023-09-14 15:24 UTC (permalink / raw)
  To: song; +Cc: linux-raid, Mariusz Tkaczyk, Yu Kuai, AceLan Kao

If there are multiple arrays in system and one mddevice is marked
with MD_DELETED and md_seq_next() is called in the middle of removal
then it _get()s proper device but it may _put() deleted one. As a result,
active counter may never be zeroed for mddevice and it cannot
be removed.

Put the device which has been _get with previous md_seq_next() call.

Cc: Yu Kuai <yukuai3@huawei.com>
Fixes: 12a6caf27324 ("md: only delete entries from all_mddevs when the disk is freed")
Reported-by: AceLan Kao <acelan@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=217798

Signed-off-by: Mariusz Tkaczyk <mariusz.tkaczyk@linux.intel.com>
---
 drivers/md/md.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/md/md.c b/drivers/md/md.c
index 0fe7ab6e8ab9..b8f232840f7c 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -8256,7 +8256,7 @@ static void *md_seq_next(struct seq_file *seq, void *v, loff_t *pos)
 	spin_unlock(&all_mddevs_lock);
 
 	if (to_put)
-		mddev_put(mddev);
+		mddev_put(to_put);
 	return next_mddev;
 
 }
-- 
2.26.2


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v3] md: do not _put wrong device in md_seq_next
  2023-09-14 15:24 [PATCH v3] md: do not _put wrong device in md_seq_next Mariusz Tkaczyk
@ 2023-09-14 17:57 ` Song Liu
  0 siblings, 0 replies; 2+ messages in thread
From: Song Liu @ 2023-09-14 17:57 UTC (permalink / raw)
  To: Mariusz Tkaczyk; +Cc: linux-raid, Yu Kuai, AceLan Kao

On Thu, Sep 14, 2023 at 8:24 AM Mariusz Tkaczyk
<mariusz.tkaczyk@linux.intel.com> wrote:
>
> If there are multiple arrays in system and one mddevice is marked
> with MD_DELETED and md_seq_next() is called in the middle of removal
> then it _get()s proper device but it may _put() deleted one. As a result,
> active counter may never be zeroed for mddevice and it cannot
> be removed.
>
> Put the device which has been _get with previous md_seq_next() call.
>
> Cc: Yu Kuai <yukuai3@huawei.com>
> Fixes: 12a6caf27324 ("md: only delete entries from all_mddevs when the disk is freed")
> Reported-by: AceLan Kao <acelan@gmail.com>
> Closes: https://bugzilla.kernel.org/show_bug.cgi?id=217798
>
> Signed-off-by: Mariusz Tkaczyk <mariusz.tkaczyk@linux.intel.com>

Applied to md-fixes, with minor changes in the commit log.

Thanks,
Song

> ---
>  drivers/md/md.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/md/md.c b/drivers/md/md.c
> index 0fe7ab6e8ab9..b8f232840f7c 100644
> --- a/drivers/md/md.c
> +++ b/drivers/md/md.c
> @@ -8256,7 +8256,7 @@ static void *md_seq_next(struct seq_file *seq, void *v, loff_t *pos)
>         spin_unlock(&all_mddevs_lock);
>
>         if (to_put)
> -               mddev_put(mddev);
> +               mddev_put(to_put);
>         return next_mddev;
>
>  }
> --
> 2.26.2
>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2023-09-14 17:58 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-09-14 15:24 [PATCH v3] md: do not _put wrong device in md_seq_next Mariusz Tkaczyk
2023-09-14 17:57 ` Song Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox