Linux SCSI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v4 22/28] scsi-multipath: add delayed disk removal support
Date: Thu, 23 Jul 2026 10:39:55 +0000	[thread overview]
Message-ID: <20260723103956.480A31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723093627.2327456-23-john.g.garry@oracle.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Broadcasting `scsi_mpath_head` to all SCSI drivers without halting iteration causes a Use-After-Free and Type Confusion risk if the callback drops the final reference and frees the structure.
- [High] Missing module reference pinning allows `scsi_mod` to be unloaded while delayed removal work is pending, leading to code-execution UAF.
--

--- Patch [22]: [PATCH v4 22/28] scsi-multipath: add delayed disk removal support ---
commit e75160848c3c93c7fdb328d5ebd94850baa881c8
Author: John Garry <john.g.garry@oracle.com>

scsi-multipath: add delayed disk removal support

This commit adds delayed disk removal support to the SCSI multipath core. 
It introduces a new mpath_remove_head callback in the scsi_driver structure 
and implements scsi_mpath_remove_head_work to execute this callback by 
iterating over available SCSI drivers.

> diff --git a/drivers/scsi/scsi_multipath.c b/drivers/scsi/scsi_multipath.c
> index 6c50fdde70d65..056b9c35d1144 100644
> --- a/drivers/scsi/scsi_multipath.c
> +++ b/drivers/scsi/scsi_multipath.c
[ ... ]
> @@ -362,7 +362,25 @@ static bool scsi_mpath_available_path(struct mpath_device *mpath_device)
>  	return false;
>  }
>  
> +static int scsi_mpath_remove_head_drv(struct device_driver *drv, void *data)
> +{
> +	struct scsi_mpath_head *scsi_mpath_head = data;
> +	struct scsi_driver *scsi_driver = to_scsi_driver(drv);
> +
> +	if (scsi_driver->mpath_remove_head)
> +		scsi_driver->mpath_remove_head(scsi_mpath_head);
> +
> +	return 0;
> +}
> +
> +static void scsi_mpath_remove_head_work(struct mpath_head *mpath_head)
> +{
> +	bus_for_each_drv(&scsi_bus_type, NULL, to_scsi_mpath_head(mpath_head),
> +		scsi_mpath_remove_head_drv);
> +}

[Severity: High]
Does this code risk a use-after-free and type confusion regression during bus
iteration?

Looking at scsi_mpath_remove_head_work() in drivers/scsi/scsi_multipath.c, it
unconditionally iterates over all SCSI drivers via bus_for_each_drv(). If the
target driver implements mpath_remove_head and drops the final reference to
scsi_mpath_head freeing the structure, scsi_mpath_remove_head_drv() still
returns 0.

Could the iteration continue and pass the freed scsi_mpath_head pointer to
subsequent drivers on the bus, causing other drivers that implement
mpath_remove_head to dereference a dangling pointer? 

Should the iteration halt by returning a non-zero value once the callback has
been successfully executed?

>  static struct mpath_head_template smpdt = {
> +	.remove_head = scsi_mpath_remove_head_work,

[Severity: High]
Does this delayed work introduction expose a use-after-free regression due to
a missing module reference?

When delayed removal is queued, it relies on mpath_head->drv_module being set
to pin the module. However, looking at scsi_mpath_alloc_head() where smpdt is
assigned:

drivers/scsi/scsi_multipath.c:scsi_mpath_alloc_head() {
    ...
	scsi_mpath_head = kzalloc(sizeof(*scsi_mpath_head), GFP_KERNEL);
	if (!scsi_mpath_head)
		return NULL;
    ...
	if (mpath_head_init(&scsi_mpath_head->mpath_head))
		goto out_free;
	scsi_mpath_head->mpath_head.mpdt = &smpdt;
    ...
}

Since mpath_head->drv_module is never initialized to THIS_MODULE,
try_module_get(mpath_head->drv_module) will return true without taking a
reference. 

Could scsi_mod be unloaded while the delayed remove_work is still pending in
the workqueue, causing the remove_head callback execution to jump to unmapped
memory?

>  	.is_disabled = scsi_mpath_is_disabled,
>  	.is_optimized = scsi_mpath_is_optimized,
[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260723093627.2327456-1-john.g.garry@oracle.com?part=22

  reply	other threads:[~2026-07-23 10:39 UTC|newest]

Thread overview: 74+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23  9:35 [PATCH v4 00/28] Native SCSI Multipath support John Garry
2026-07-23  9:35 ` [PATCH v4 01/28] libmultipath: Add initial framework John Garry
2026-07-23  9:50   ` sashiko-bot
2026-07-23 10:19     ` John Garry
2026-07-23  9:36 ` [PATCH v4 02/28] libmultipath: Add basic gendisk support John Garry
2026-07-23  9:57   ` sashiko-bot
2026-07-23 10:34     ` John Garry
2026-07-23  9:36 ` [PATCH v4 03/28] libmultipath: Add path selection support John Garry
2026-07-23  9:55   ` sashiko-bot
2026-07-23 10:28     ` John Garry
2026-07-23  9:36 ` [PATCH v4 04/28] libmultipath: Add bio handling John Garry
2026-07-23  9:36 ` [PATCH v4 05/28] libmultipath: Add support for mpath_device management John Garry
2026-07-23  9:58   ` sashiko-bot
2026-07-23 10:36     ` John Garry
2026-07-23  9:36 ` [PATCH v4 06/28] libmultipath: Add delayed removal support John Garry
2026-07-23  9:57   ` sashiko-bot
2026-07-23 10:33     ` John Garry
2026-07-23  9:36 ` [PATCH v4 07/28] libmultipath: Add sysfs helpers John Garry
2026-07-23 10:05   ` sashiko-bot
2026-07-23 10:37     ` John Garry
2026-07-23  9:36 ` [PATCH v4 08/28] libmultipath: Add mpath_bdev_report_zones() John Garry
2026-07-23 10:15   ` sashiko-bot
2026-07-23 10:39     ` John Garry
2026-07-23  9:36 ` [PATCH v4 09/28] libmultipath: Add support for block device IOCTL John Garry
2026-07-23 10:09   ` sashiko-bot
2026-07-23 10:38     ` John Garry
2026-07-23  9:36 ` [PATCH v4 10/28] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-23  9:36 ` [PATCH v4 11/28] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-23  9:36 ` [PATCH v4 12/28] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-23 10:14   ` sashiko-bot
2026-07-23  9:36 ` [PATCH v4 13/28] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-23 10:16   ` sashiko-bot
2026-07-23 10:47     ` John Garry
2026-07-23  9:36 ` [PATCH v4 14/28] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-23  9:36 ` [PATCH v4 15/28] scsi-multipath: support iopolicy John Garry
2026-07-23 10:20   ` sashiko-bot
2026-07-23 10:51     ` John Garry
2026-07-23  9:36 ` [PATCH v4 16/28] scsi-multipath: clone each bio John Garry
2026-07-23 10:27   ` sashiko-bot
2026-07-23 10:55     ` John Garry
2026-07-23  9:36 ` [PATCH v4 17/28] scsi-multipath: clear path when device is blocked John Garry
2026-07-23 10:33   ` sashiko-bot
2026-07-23 11:01     ` John Garry
2026-07-23  9:36 ` [PATCH v4 18/28] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-23 10:39   ` sashiko-bot
2026-07-23 11:15     ` John Garry
2026-07-23  9:36 ` [PATCH v4 19/28] scsi-multipath: failover handling John Garry
2026-07-23 10:36   ` sashiko-bot
2026-07-23 11:03     ` John Garry
2026-07-23  9:36 ` [PATCH v4 20/28] scsi-multipath: provide callbacks for path state John Garry
2026-07-23 10:36   ` sashiko-bot
2026-07-23 11:05     ` John Garry
2026-07-23  9:36 ` [PATCH v4 21/28] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-23 10:32   ` sashiko-bot
2026-07-23 10:57     ` John Garry
2026-07-23  9:36 ` [PATCH v4 22/28] scsi-multipath: add delayed disk removal support John Garry
2026-07-23 10:39   ` sashiko-bot [this message]
2026-07-23 11:21     ` John Garry
2026-07-23  9:36 ` [PATCH v4 23/28] scsi: sd: add multipath disk class John Garry
2026-07-23 10:39   ` sashiko-bot
2026-07-23 11:21     ` John Garry
2026-07-23  9:36 ` [PATCH v4 24/28] scsi: sd: add multipath disk attr groups John Garry
2026-07-23 10:47   ` sashiko-bot
2026-07-23 11:22     ` John Garry
2026-07-23  9:36 ` [PATCH v4 25/28] scsi: sd: support multipath disk John Garry
2026-07-23 10:47   ` sashiko-bot
2026-07-23 11:27     ` John Garry
2026-07-23  9:36 ` [PATCH v4 26/28] scsi: sd: add mpath_dev file John Garry
2026-07-23 11:07   ` sashiko-bot
2026-07-23 11:30     ` John Garry
2026-07-23  9:36 ` [PATCH v4 27/28] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-23 10:52   ` sashiko-bot
2026-07-23 11:30     ` John Garry
2026-07-23  9:36 ` [PATCH v4 28/28] scsi: sd: add mpath_queue_depth " John Garry

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723103956.480A31F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=john.g.garry@oracle.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox