From: John Garry <john.garry@linux.dev>
To: Bart Van Assche <bvanassche@acm.org>,
"Martin K . Petersen" <martin.petersen@oracle.com>
Cc: linux-scsi@vger.kernel.org, John Garry <john.g.garry@oracle.com>,
Christoph Hellwig <hch@lst.de>
Subject: Re: [PATCH v2 1/7] scsi: scsi_debug: Fix a locking bug in resp_write_same()
Date: Fri, 25 Sep 2026 09:43:12 +0100 [thread overview]
Message-ID: <b6ba9c00-e3c5-4534-be92-dd2d5ceb9cf4@linux.dev> (raw)
In-Reply-To: <f3cedcaf09495936f46898a4242cd83da9145989.1790290090.git.bvanassche@acm.org>
On 9/24/26 23:54, Bart Van Assche wrote:
> If fetch_to_dev_buffer() fails in resp_write_same(), the function jumps
> to 'out' without releasing the data write lock acquired earlier via
> sdeb_data_write_lock(). Jump to 'unlock' instead so that
> sdeb_data_write_unlock() is called on the error path. This bug has been
> discovered by building the scsi_debug driver with Clang and modified
> lock context annotations. The modified lock context annotations are
> available in patch "scsi: scsi_debug: Improve lock context annotations".
>
> Fixes: 84f3a3c01d70 ("scsi: scsi_debug: Atomic write support")
> Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: John Garry <john.garry@linux.dev>
> ---
> drivers/scsi/scsi_debug.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
> index 6941809dfdb7..ed8d69f305f8 100644
> --- a/drivers/scsi/scsi_debug.c
> +++ b/drivers/scsi/scsi_debug.c
> @@ -5402,7 +5402,7 @@ static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
>
> if (-1 == ret) {
> ret = DID_ERROR << 16;
> - goto out;
> + goto unlock;
> } else if (sdebug_verbose && !ndob && (ret < lb_size))
> sdev_printk(KERN_INFO, scp->device,
> "%s: %s: lb size=%u, IO sent=%d bytes\n",
> @@ -5419,8 +5419,9 @@ static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
> /* If ZBC zone then bump its write pointer */
> if (sdebug_dev_is_zoned(devip))
> zbc_inc_wp(devip, lba, num);
> - sdeb_data_write_unlock(sip);
> ret = 0;
> +unlock:
> + sdeb_data_write_unlock(sip);
> out:
> if (meta_data_locked)
> sdeb_meta_write_unlock(sip);
next prev parent reply other threads:[~2026-09-25 8:43 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 22:54 [PATCH v2 0/7] scsi_debug: Enable lock context analysis Bart Van Assche
2026-09-24 22:54 ` [PATCH v2 1/7] scsi: scsi_debug: Fix a locking bug in resp_write_same() Bart Van Assche
2026-09-25 7:06 ` Christoph Hellwig
2026-09-25 8:43 ` John Garry [this message]
2026-09-24 22:54 ` [PATCH v2 2/7] scsi: scsi_debug: Split resp_write_same() Bart Van Assche
2026-09-25 7:08 ` Christoph Hellwig
2026-09-25 8:50 ` John Garry
2026-09-24 22:54 ` [PATCH v2 3/7] scsi: scsi_debug: Split corrupt_lbas() Bart Van Assche
2026-09-25 7:09 ` Christoph Hellwig
2026-09-25 8:55 ` John Garry
2026-09-24 22:54 ` [PATCH v2 4/7] scsi: scsi_debug: Split resp_read_dt0() Bart Van Assche
2026-09-25 7:10 ` Christoph Hellwig
2026-09-25 9:06 ` John Garry
2026-09-24 22:54 ` [PATCH v2 5/7] scsi: scsi_debug: Split resp_write_dt0() Bart Van Assche
2026-09-25 7:12 ` Christoph Hellwig
2026-09-24 22:54 ` [PATCH v2 6/7] scsi: scsi_debug: Improve lock context annotations Bart Van Assche
2026-09-25 9:15 ` John Garry
2026-09-25 15:55 ` Bart Van Assche
2026-09-24 22:54 ` [PATCH v2 7/7] scsi: core: Enable lock context analysis for the scsi_debug driver Bart Van Assche
2026-09-25 7:13 ` Christoph Hellwig
2026-09-25 9:16 ` John Garry
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b6ba9c00-e3c5-4534-be92-dd2d5ceb9cf4@linux.dev \
--to=john.garry@linux.dev \
--cc=bvanassche@acm.org \
--cc=hch@lst.de \
--cc=john.g.garry@oracle.com \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox