From: Niklas Cassel <cassel@kernel.org>
To: "James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
"Martin K. Petersen" <mkp@kernel.org>
Cc: linux-scsi@vger.kernel.org, Damien Le Moal <dlemoal@kernel.org>,
John Garry <john.garry@linux.dev>,
Niklas Cassel <cassel@kernel.org>
Subject: [PATCH v10 09/12] scsi: scsi_debug: Advance the write pointer over the data written
Date: Mon, 28 Sep 2026 09:21:12 +0200 [thread overview]
Message-ID: <20260928072102.725566-23-cassel@kernel.org> (raw)
In-Reply-To: <20260928072102.725566-14-cassel@kernel.org>
resp_write_dt0() and resp_write_scat() advance the write pointer of a
sequential write required zone by the transfer length of the command
without looking at what do_device_access() returned, which is -1 when
the data direction of the command does not match the operation, and a
short byte count when the data-out buffer is smaller than the transfer
length. An initiator can produce both with SG_IO.
The zone then describes more data than is on the medium, and a write at
the position where the data really ends is terminated with UNALIGNED
WRITE COMMAND, so the zone has to be reset before it can be written to
again.
Advance the write pointer over the data that was written instead. As
do_device_access() does not write a partial physical block to such a
zone, that leaves the write pointer where a write can end.
Assisted-by: LLM
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Fixes: f0d1cf9378bd ("scsi: scsi_debug: Add ZBC zone commands")
Signed-off-by: Niklas Cassel <cassel@kernel.org>
---
Tested with:
modprobe scsi_debug zbc=managed sector_size=512 physblk_exp=3 \
zone_size_mb=8 dev_size_mb=128 zone_nr_conv=2
issuing WRITE(16) through SG_IO with a data-out buffer shorter than the
transfer length of the command. A sixteen block write with a buffer of
twelve blocks leaves the write pointer of an empty sequential write
required zone eight blocks on, which is where the data it wrote ends,
and a following eight block write continues from there. An eight block
write with a buffer of one block writes nothing and leaves the write
pointer where it was.
Before this patch both advanced the write pointer by the full transfer
length, and a write at the end of the data that had actually been
written was then terminated with UNALIGNED WRITE COMMAND.
---
drivers/scsi/scsi_debug.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
index dd7132e92c27..f83440ab7966 100644
--- a/drivers/scsi/scsi_debug.c
+++ b/drivers/scsi/scsi_debug.c
@@ -5179,9 +5179,9 @@ static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
if (unlikely(lbp))
map_region(sip, lba, num);
- /* If ZBC zone then bump its write pointer */
- if (sdebug_dev_is_zoned(devip))
- zbc_inc_wp(devip, lba, num);
+ /* If ZBC zone then bump its write pointer over the data written */
+ if (sdebug_dev_is_zoned(devip) && ret > 0)
+ zbc_inc_wp(devip, lba, ret >> ilog2(sdebug_sector_size));
if (meta_data_locked)
sdeb_meta_write_unlock(sip);
@@ -5349,9 +5349,10 @@ static int resp_write_scat(struct scsi_cmnd *scp,
*/
ret = do_device_access(sip, scp, min_t(u64, sg_off, U32_MAX), lba,
num, group, true, true);
- /* If ZBC zone then bump its write pointer */
- if (sdebug_dev_is_zoned(devip))
- zbc_inc_wp(devip, lba, num);
+ /* If ZBC zone then bump its write pointer over the data written */
+ if (sdebug_dev_is_zoned(devip) && ret > 0)
+ zbc_inc_wp(devip, lba,
+ ret >> ilog2(sdebug_sector_size));
if (unlikely(scsi_debug_lbp()))
map_region(sip, lba, num);
if (unlikely(-1 == ret)) {
--
2.55.0
next prev parent reply other threads:[~2026-09-28 7:21 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 7:21 [PATCH v10 00/12] scsi: scsi_debug: fix zoned write validation Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 01/12] scsi: scsi_debug: Refuse a zoned device with a non-zero lowest aligned LBA Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 02/12] scsi: scsi_debug: Make atomic writes and ZBC emulation mutually exclusive Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 03/12] scsi: scsi_debug: Take the zone metadata lock before the data lock Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 04/12] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 05/12] scsi: scsi_debug: Avoid 32-bit overflow in WRITE SCATTERED offsets Niklas Cassel
2026-09-28 7:39 ` sashiko-bot
2026-09-28 7:21 ` [PATCH v10 06/12] scsi: scsi_debug: Report the residual of a write Niklas Cassel
2026-09-28 8:18 ` Damien Le Moal
2026-09-28 7:21 ` [PATCH v10 07/12] scsi: scsi_debug: Enforce physical block alignment of zoned writes Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 08/12] scsi: scsi_debug: Do not write a partial physical block to a zoned device Niklas Cassel
2026-09-28 7:21 ` Niklas Cassel [this message]
2026-09-28 7:21 ` [PATCH v10 10/12] scsi: scsi_debug: Refuse a short WRITE ATOMIC (16) before writing it Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 11/12] scsi: scsi_debug: Map the region written by WRITE ATOMIC (16) Niklas Cassel
2026-09-28 7:21 ` [PATCH v10 12/12] scsi: scsi_debug: Validate the access parameters of " Niklas Cassel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928072102.725566-23-cassel@kernel.org \
--to=cassel@kernel.org \
--cc=James.Bottomley@HansenPartnership.com \
--cc=dlemoal@kernel.org \
--cc=john.garry@linux.dev \
--cc=linux-scsi@vger.kernel.org \
--cc=mkp@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox