Linux SCSI subsystem development
 help / color / mirror / Atom feed
From: John Garry <john.garry@linux.dev>
To: Niklas Cassel <cassel@kernel.org>,
	"James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
	"Martin K. Petersen" <mkp@kernel.org>
Cc: linux-scsi@vger.kernel.org, Damien Le Moal <dlemoal@kernel.org>
Subject: Re: [PATCH v5 04/10] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once
Date: Mon, 21 Sep 2026 16:53:33 +0100	[thread overview]
Message-ID: <d460d0ef-d182-44ca-82d3-dd29afbce565@linux.dev> (raw)
In-Reply-To: <20260921154015.2971990-16-cassel@kernel.org>

On 9/21/26 16:40, Niklas Cassel wrote:
> corrupt_lbas(), resp_write_dt0() and resp_write_same() call
> scsi_debug_lbp() to decide whether to take the zone metadata lock, and
> then call it again to decide whether to read or write the provisioning
> map that the lock protects.
> 
> The result is not a constant. scsi_debug_lbp() is false while the
> fake_rw module parameter is set, and fake_rw can be written at any time,
> both as a module parameter and through its driver attribute in sysfs.
> The two calls can therefore disagree, and the later one can decide to
> touch the provisioning map after the earlier one decided not to take the
> lock that protects it.
> 
> Call it once and use the result throughout.
> 
> Assisted-by: LLM
> Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
> Signed-off-by: Niklas Cassel <cassel@kernel.org>

Reviewed-by: John Garry <john.garry@linux.dev>

> ---
> Tested with:
> 
>    modprobe scsi_debug sector_size=512 dev_size_mb=128 lbpu=1 lbpws=1
> 
> A WRITE(16) completes and GET LBA STATUS then reports the region as
> mapped, which covers resp_write_dt0(). A WRITE SAME and a WRITE SAME
> with the UNMAP bit set complete, and GET LBA STATUS reports the first
> region as mapped and the second as deallocated, which covers all three
> uses of the result in resp_write_same().
> 
> corrupt_lbas() is not covered. It is reached by writing to the corrupt
> file in debugfs, and that interface rejected the requests that were
> tried, for a reason that has nothing to do with this patch.
> 
> The window that the change closes was not reproduced. It needs fake_rw
> to be written between two calls, and was found by review.
> ---
>   drivers/scsi/scsi_debug.c | 17 ++++++++++-------
>   1 file changed, 10 insertions(+), 7 deletions(-)
> 
> diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
> index 18aefe83b7b6..c68dba6dbbdd 100644
> --- a/drivers/scsi/scsi_debug.c
> +++ b/drivers/scsi/scsi_debug.c
> @@ -4953,12 +4953,13 @@ static int corrupt_lbas(struct sdebug_dev_info *devip, u64 lba, u32 num,
>   {
>   	struct sdeb_store_info *sip = devip2sip(devip, false);
>   	bool meta_data_locked = false;
> +	bool lbp = scsi_debug_lbp();
>   	u32 block, num_mapped, b, i;
>   	int error = 0;
>   
>   	if (sdebug_dev_is_zoned(devip) ||
>   	    sdebug_dix ||
> -	    scsi_debug_lbp())  {
> +	    lbp)  {
>   		sdeb_meta_write_lock(sip);
>   		meta_data_locked = true;
>   	}
> @@ -4975,7 +4976,7 @@ static int corrupt_lbas(struct sdebug_dev_info *devip, u64 lba, u32 num,
>   		goto out_unlock;
>   	}
>   
> -	if (scsi_debug_lbp() &&
> +	if (lbp &&
>   	    (!map_state(sip, lba, &num_mapped) || num > num_mapped)) {

combine lines? Please consider elsewhere in this patch. However I think 
that we still like to enforce the 80 character line limit... well, some do.

Thanks

>   		pr_err("can't modify unmapped logical blocks: %llu:%u",
>   			lba, num);
> @@ -5035,6 +5036,7 @@ static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
>   	struct sdeb_store_info *sip = devip2sip(devip, true);
>   	u8 *cmd = scp->cmnd;
>   	bool meta_data_locked = false;
> +	bool lbp = scsi_debug_lbp();
>   
>   	if (unlikely(sdebug_opts & SDEBUG_OPT_UNALIGNED_WRITE &&
>   		     atomic_read(&sdeb_inject_pending))) {
> @@ -5102,7 +5104,7 @@ static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
>   
>   	if (sdebug_dev_is_zoned(devip) ||
>   	    (sdebug_dix && scsi_prot_sg_count(scp)) ||
> -	    scsi_debug_lbp())  {
> +	    lbp)  {
>   		sdeb_meta_write_lock(sip);
>   		meta_data_locked = true;
>   	}
> @@ -5147,7 +5149,7 @@ static int resp_write_dt0(struct scsi_cmnd *scp, struct sdebug_dev_info *devip)
>   	}
>   
>   	ret = do_device_access(sip, scp, 0, lba, num, group, true, false);
> -	if (unlikely(scsi_debug_lbp()))
> +	if (unlikely(lbp))
>   		map_region(sip, lba, num);
>   
>   	/* If ZBC zone then bump its write pointer */
> @@ -5374,8 +5376,9 @@ static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
>   	u8 *fs1p;
>   	u8 *fsp;
>   	bool meta_data_locked = false;
> +	bool lbp = scsi_debug_lbp();
>   
> -	if (sdebug_dev_is_zoned(devip) || scsi_debug_lbp()) {
> +	if (sdebug_dev_is_zoned(devip) || lbp) {
>   		sdeb_meta_write_lock(sip);
>   		meta_data_locked = true;
>   	}
> @@ -5384,7 +5387,7 @@ static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
>   	if (ret)
>   		goto out;
>   
> -	if (unmap && scsi_debug_lbp()) {
> +	if (unmap && lbp) {
>   		unmap_region(sip, lba, num);
>   		goto out;
>   	}
> @@ -5414,7 +5417,7 @@ static int resp_write_same(struct scsi_cmnd *scp, u64 lba, u32 num,
>   		block = do_div(lbaa, sdebug_store_sectors);
>   		memmove(fsp + (block * lb_size), fs1p, lb_size);
>   	}
> -	if (scsi_debug_lbp())
> +	if (lbp)
>   		map_region(sip, lba, num);
>   	/* If ZBC zone then bump its write pointer */
>   	if (sdebug_dev_is_zoned(devip))


  reply	other threads:[~2026-09-21 15:53 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 15:40 [PATCH v5 00/10] scsi: scsi_debug: fix zoned write validation Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 01/10] scsi: scsi_debug: Refuse a zoned device with a non-zero lowest aligned LBA Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 02/10] scsi: scsi_debug: Make atomic writes and ZBC emulation mutually exclusive Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 03/10] scsi: scsi_debug: Take the zone metadata lock before the data lock Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 04/10] scsi: scsi_debug: Evaluate scsi_debug_lbp() only once Niklas Cassel
2026-09-21 15:53   ` John Garry [this message]
2026-09-23  9:54   ` Johannes Thumshirn
2026-09-21 15:40 ` [PATCH v5 05/10] scsi: scsi_debug: Report the residual of a write Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 06/10] scsi: scsi_debug: Enforce physical block alignment of zoned writes Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 07/10] scsi: scsi_debug: Do not write a partial physical block to a zoned device Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 08/10] scsi: scsi_debug: Advance the write pointer over the data written Niklas Cassel
2026-09-21 15:40 ` [PATCH v5 09/10] scsi: scsi_debug: Map the region written by WRITE ATOMIC (16) Niklas Cassel
2026-09-21 15:50   ` John Garry
2026-09-24 11:10     ` Niklas Cassel
2026-09-25  9:32       ` John Garry
2026-09-21 15:40 ` [PATCH v5 10/10] scsi: scsi_debug: Validate the access parameters of " Niklas Cassel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d460d0ef-d182-44ca-82d3-dd29afbce565@linux.dev \
    --to=john.garry@linux.dev \
    --cc=James.Bottomley@HansenPartnership.com \
    --cc=cassel@kernel.org \
    --cc=dlemoal@kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=mkp@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox