From: sashiko-bot@kernel.org
To: "John Garry" <john.g.garry@oracle.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v5 06/27] libmultipath: Add delayed removal support
Date: Mon, 27 Jul 2026 15:00:45 +0000 [thread overview]
Message-ID: <20260727150045.B19231F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260727144234.3802948-7-john.g.garry@oracle.com>
Thank you for your contribution! Sashiko AI review found 5 potential issue(s) to consider:
- [High] Missing synchronization between path addition and delayed removal causes Use-After-Free.
- [High] Missing cancellation of `remove_work` during head teardown causes Use-After-Free.
- [High] Disabling delayed removal via sysfs leaves queued I/Os stuck indefinitely.
- [Medium] Module reference leak in `mpath_can_remove_head()` when delayed work is already pending.
- [Medium] 32-bit integer overflow in delayed removal seconds calculation.
--
--- Patch [6]: [PATCH v5 06/27] libmultipath: Add delayed removal support ---
commit c3a14a8d55791e59aaf6def4186888f9333f0985
Author: John Garry <john.garry@linux.dev>
libmultipath: Add delayed removal support
This patch adds support for delayed removal of multipath devices, similar to
NVMe. It introduces a configurable delayed removal window to retain the disk
and cdev during transient path loss.
> diff --git a/lib/multipath.c b/lib/multipath.c
> index f70049b6cede9..ede06e5e901c8 100644
> --- a/lib/multipath.c
> +++ b/lib/multipath.c
> @@ -65,6 +65,9 @@ int mpath_add_device(struct mpath_device *mpath_device, struct gendisk *disk,
> list_add_tail_rcu(&mpath_device->siblings, &mpath_head->dev_list);
> mutex_unlock(&mpath_head->lock);
>
> + if (cancel_delayed_work(&mpath_head->remove_work))
> + module_put(mpath_head->drv_module);
> +
[Severity: High]
If mpath_remove_head_work() is already executing when we call
cancel_delayed_work(), the cancellation will fail and return false. By
dropping the lock before this check, is it possible for mpath_remove_head_work()
to unconditionally tear down the mpath_head without realizing a new path was
just added?
This might leave the newly added path with dangling pointers to the freed
multipath head. Should we hold the lock or verify the execution state of the
work item?
> return 0;
> }
[ ... ]
> @@ -480,6 +493,39 @@ static void mpath_requeue_work(struct work_struct *work)
> }
> }
>
> +bool mpath_can_remove_head(struct mpath_head *mpath_head)
> +{
> + bool remove = false;
> +
> + mutex_lock(&mpath_head->lock);
> + /*
> + * Ensure that no one could remove this module while the head
> + * remove work is pending.
> + */
> + if (mpath_head_queue_if_no_path(mpath_head) &&
> + try_module_get(mpath_head->drv_module)) {
[Severity: Medium]
If the delayed work is already pending from a previous path failure,
mod_delayed_work() will update the timer and return true, but it will not
queue a new execution of the work item.
Since try_module_get() unconditionally increments the reference count before
this, will subsequent calls to mpath_can_remove_head() leak module references
since mpath_remove_head_work() only executes once?
> + unsigned long delay = mpath_head->delayed_removal_secs * HZ;
[Severity: Medium]
Could this multiplication overflow on 32-bit systems? Both
mpath_head->delayed_removal_secs (unsigned int) and HZ are 32-bit types, so the
multiplication is evaluated in 32-bit arithmetic before being promoted to
unsigned long.
If a user writes a large value to the sysfs attribute, could this result in an
unintended short delay or immediate removal?
> +
> + mod_delayed_work(mpath_wq, &mpath_head->remove_work, delay);
> + } else {
> + remove = true;
> + }
> +
> + mutex_unlock(&mpath_head->lock);
> + return remove;
> +}
> +EXPORT_SYMBOL_GPL(mpath_can_remove_head);
[ ... ]
> @@ -525,6 +571,9 @@ int mpath_alloc_head_disk(struct mpath_head *mpath_head,
> mpath_head->disk->private_data = mpath_head;
> mpath_head->disk->fops = &mpath_ops;
>
> + INIT_DELAYED_WORK(&mpath_head->remove_work, mpath_remove_head_work);
[Severity: High]
Since this work is initialized here, do we need to ensure it is cancelled
during head teardown?
Looking at mpath_put_disk(), it flushes requeue_work and partition_scan_work
but does not appear to call cancel_delayed_work_sync() for remove_work. Could
this leave the delayed work active in the workqueue after mpath_head is freed?
> + mpath_head->delayed_removal_secs = 0;
> +
> set_bit(GD_SUPPRESS_PART_SCAN, &mpath_head->disk->state);
>
> return 0;
[ ... ]
> +ssize_t mpath_delayed_removal_secs_store(struct mpath_head *mpath_head,
> + const char *buf, size_t count)
> +{
> + unsigned int sec;
> + ssize_t ret;
> +
> + ret = kstrtouint(buf, 0, &sec);
> + if (ret < 0)
> + return ret;
> +
> + mutex_lock(&mpath_head->lock);
> + mpath_head->delayed_removal_secs = sec;
> + if (sec)
> + set_bit(MPATH_HEAD_QUEUE_IF_NO_PATH, &mpath_head->flags);
> + else
> + clear_bit(MPATH_HEAD_QUEUE_IF_NO_PATH, &mpath_head->flags);
> + mutex_unlock(&mpath_head->lock);
[Severity: High]
When delayed removal is disabled by writing 0, the MPATH_HEAD_QUEUE_IF_NO_PATH
flag is cleared. However, does this leave bios already queued in requeue_list
stuck indefinitely?
Should we call mpath_schedule_requeue_work() here to ensure previously queued
I/Os are flushed and failed?
> +
> + /*
> + * Ensure that update to MPATH_HEAD_QUEUE_IF_NO_PATH is seen
> + * by its reader.
> + */
> + mpath_synchronize(mpath_head);
> +
> + return count;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260727144234.3802948-1-john.g.garry@oracle.com?part=6
next prev parent reply other threads:[~2026-07-27 15:00 UTC|newest]
Thread overview: 71+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 14:42 [PATCH v5 00/27] Native SCSI Multipath support John Garry
2026-07-27 14:42 ` [PATCH v5 01/27] libmultipath: Add initial framework John Garry
2026-07-27 15:05 ` sashiko-bot
2026-07-27 15:12 ` John Garry
2026-07-27 14:42 ` [PATCH v5 02/27] libmultipath: Add basic gendisk support John Garry
2026-07-27 15:04 ` sashiko-bot
2026-07-27 15:15 ` John Garry
2026-07-27 14:42 ` [PATCH v5 03/27] libmultipath: Add path selection support John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:20 ` John Garry
2026-07-27 14:42 ` [PATCH v5 04/27] libmultipath: Add bio handling John Garry
2026-07-27 14:42 ` [PATCH v5 05/27] libmultipath: Add support for mpath_device management John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:23 ` John Garry
2026-07-27 14:42 ` [PATCH v5 06/27] libmultipath: Add delayed removal support John Garry
2026-07-27 15:00 ` sashiko-bot [this message]
2026-07-27 15:25 ` John Garry
2026-07-27 14:42 ` [PATCH v5 07/27] libmultipath: Add sysfs helpers John Garry
2026-07-27 15:03 ` sashiko-bot
2026-07-27 15:33 ` John Garry
2026-07-27 14:42 ` [PATCH v5 08/27] libmultipath: Add support for block device IOCTL John Garry
2026-07-27 15:08 ` sashiko-bot
2026-07-27 15:31 ` John Garry
2026-07-27 14:42 ` [PATCH v5 09/27] libmultipath: Add mpath_bdev_getgeo() John Garry
2026-07-27 14:42 ` [PATCH v5 10/27] libmultipath: Add mpath_bdev_get_unique_id() John Garry
2026-07-27 14:42 ` [PATCH v5 11/27] scsi-multipath: introduce basic SCSI device support John Garry
2026-07-27 18:59 ` sashiko-bot
2026-07-27 14:42 ` [PATCH v5 12/27] scsi-multipath: introduce scsi_device head structure John Garry
2026-07-27 15:15 ` sashiko-bot
2026-07-27 15:37 ` John Garry
2026-07-27 14:42 ` [PATCH v5 13/27] scsi-multipath: provide sysfs link from to scsi_device John Garry
2026-07-27 15:07 ` sashiko-bot
2026-07-27 16:21 ` John Garry
2026-07-27 14:42 ` [PATCH v5 14/27] scsi-multipath: support iopolicy John Garry
2026-07-27 15:06 ` sashiko-bot
2026-07-27 15:39 ` John Garry
2026-07-27 14:42 ` [PATCH v5 15/27] scsi-multipath: clone each bio John Garry
2026-07-27 15:21 ` sashiko-bot
2026-07-27 15:40 ` John Garry
2026-07-27 14:42 ` [PATCH v5 16/27] scsi-multipath: clear path when device is blocked John Garry
2026-07-27 15:14 ` sashiko-bot
2026-07-27 15:44 ` John Garry
2026-07-27 14:42 ` [PATCH v5 17/27] scsi-multipath: revalidate paths upon device unblock John Garry
2026-07-27 15:17 ` sashiko-bot
2026-07-27 16:05 ` John Garry
2026-07-27 14:42 ` [PATCH v5 18/27] scsi-multipath: failover handling John Garry
2026-07-27 14:42 ` [PATCH v5 19/27] scsi-multipath: provide callbacks for path state John Garry
2026-07-27 15:24 ` sashiko-bot
2026-07-27 16:07 ` John Garry
2026-07-27 14:42 ` [PATCH v5 20/27] scsi-multipath: add scsi_mpath_{start,end}_request() John Garry
2026-07-27 15:25 ` sashiko-bot
2026-07-27 16:18 ` John Garry
2026-07-27 14:42 ` [PATCH v5 21/27] scsi-multipath: add delayed disk removal support John Garry
2026-07-27 15:23 ` sashiko-bot
2026-07-27 16:20 ` John Garry
2026-07-27 14:42 ` [PATCH v5 22/27] scsi: sd: add multipath disk class John Garry
2026-07-27 15:14 ` sashiko-bot
2026-07-27 16:21 ` John Garry
2026-07-27 14:42 ` [PATCH v5 23/27] scsi: sd: add multipath disk attr groups John Garry
2026-07-27 15:20 ` sashiko-bot
2026-07-27 16:22 ` John Garry
2026-07-27 14:42 ` [PATCH v5 24/27] scsi: sd: support multipath disk John Garry
2026-07-27 15:20 ` sashiko-bot
2026-07-27 16:33 ` John Garry
2026-07-27 14:42 ` [PATCH v5 25/27] scsi: sd: add mpath_dev file John Garry
2026-07-27 15:33 ` sashiko-bot
2026-07-27 16:24 ` John Garry
2026-07-27 14:42 ` [PATCH v5 26/27] scsi: sd: add mpath_numa_nodes dev attribute John Garry
2026-07-27 14:42 ` [PATCH v5 27/27] scsi: sd: add mpath_queue_depth " John Garry
2026-07-27 15:28 ` sashiko-bot
2026-07-27 15:29 ` John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727150045.B19231F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox