* [PATCH v3] md: do not _put wrong device in md_seq_next
@ 2023-09-14 15:24 Mariusz Tkaczyk
2023-09-14 17:57 ` Song Liu
0 siblings, 1 reply; 2+ messages in thread
From: Mariusz Tkaczyk @ 2023-09-14 15:24 UTC (permalink / raw)
To: song; +Cc: linux-raid, Mariusz Tkaczyk, Yu Kuai, AceLan Kao
If there are multiple arrays in system and one mddevice is marked
with MD_DELETED and md_seq_next() is called in the middle of removal
then it _get()s proper device but it may _put() deleted one. As a result,
active counter may never be zeroed for mddevice and it cannot
be removed.
Put the device which has been _get with previous md_seq_next() call.
Cc: Yu Kuai <yukuai3@huawei.com>
Fixes: 12a6caf27324 ("md: only delete entries from all_mddevs when the disk is freed")
Reported-by: AceLan Kao <acelan@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=217798
Signed-off-by: Mariusz Tkaczyk <mariusz.tkaczyk@linux.intel.com>
---
drivers/md/md.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 0fe7ab6e8ab9..b8f232840f7c 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -8256,7 +8256,7 @@ static void *md_seq_next(struct seq_file *seq, void *v, loff_t *pos)
spin_unlock(&all_mddevs_lock);
if (to_put)
- mddev_put(mddev);
+ mddev_put(to_put);
return next_mddev;
}
--
2.26.2
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v3] md: do not _put wrong device in md_seq_next
2023-09-14 15:24 [PATCH v3] md: do not _put wrong device in md_seq_next Mariusz Tkaczyk
@ 2023-09-14 17:57 ` Song Liu
0 siblings, 0 replies; 2+ messages in thread
From: Song Liu @ 2023-09-14 17:57 UTC (permalink / raw)
To: Mariusz Tkaczyk; +Cc: linux-raid, Yu Kuai, AceLan Kao
On Thu, Sep 14, 2023 at 8:24 AM Mariusz Tkaczyk
<mariusz.tkaczyk@linux.intel.com> wrote:
>
> If there are multiple arrays in system and one mddevice is marked
> with MD_DELETED and md_seq_next() is called in the middle of removal
> then it _get()s proper device but it may _put() deleted one. As a result,
> active counter may never be zeroed for mddevice and it cannot
> be removed.
>
> Put the device which has been _get with previous md_seq_next() call.
>
> Cc: Yu Kuai <yukuai3@huawei.com>
> Fixes: 12a6caf27324 ("md: only delete entries from all_mddevs when the disk is freed")
> Reported-by: AceLan Kao <acelan@gmail.com>
> Closes: https://bugzilla.kernel.org/show_bug.cgi?id=217798
>
> Signed-off-by: Mariusz Tkaczyk <mariusz.tkaczyk@linux.intel.com>
Applied to md-fixes, with minor changes in the commit log.
Thanks,
Song
> ---
> drivers/md/md.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/md/md.c b/drivers/md/md.c
> index 0fe7ab6e8ab9..b8f232840f7c 100644
> --- a/drivers/md/md.c
> +++ b/drivers/md/md.c
> @@ -8256,7 +8256,7 @@ static void *md_seq_next(struct seq_file *seq, void *v, loff_t *pos)
> spin_unlock(&all_mddevs_lock);
>
> if (to_put)
> - mddev_put(mddev);
> + mddev_put(to_put);
> return next_mddev;
>
> }
> --
> 2.26.2
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-09-14 17:58 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-09-14 15:24 [PATCH v3] md: do not _put wrong device in md_seq_next Mariusz Tkaczyk
2023-09-14 17:57 ` Song Liu
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox