linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: James Bottomley <James.Bottomley@HansenPartnership.com>
To: Christoph Hellwig <hch@infradead.org>
Cc: jgross@suse.com, linux-scsi@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH] Save command pool address of Scsi_Host
Date: Sat, 02 Aug 2014 00:24:34 +0400	[thread overview]
Message-ID: <1406924674.2654.19.camel@jarvis> (raw)
In-Reply-To: <20140801120301.GA27198@infradead.org>

On Fri, 2014-08-01 at 05:03 -0700, Christoph Hellwig wrote:
> On Fri, Aug 01, 2014 at 08:27:05AM +0200, jgross@suse.com wrote:
> > From: Juergen Gross <jgross@suse.com>
> > 
> > If a scsi host driver specifies .cmd_len in it's scsi_host_template, a driver's
> > private command pool is needed. scsi_find_host_cmd_pool() will locate it, but
> > scsi_alloc_host_cmd_pool() isn't saving the pool address in the host template.
> > 
> > This will result in an access error when the host is removed.
> > 
> > Avoid the problem by saving the address of a new allocated command pool where
> > it is expected.
> > 
> > Signed-off-by: Juergen Gross <jgross@suse.com>
> 
> Looks good, but minor nitpick below:
> 
> > +	if (shost->hostt->cmd_size)
> > +		shost->hostt->cmd_pool = pool;
> > +
> 
> 
> We already have a local hostt variable for the host template in this
> function, please use it.

Wait, that's not right at all.  There looks to be a thinko in the
command pool handling code.  We have both a cmd_pool in the host
structure and in the host template structure, but there's confusion
about which one we're supposed to be using.

The origin of confusion seems to be the reference counting in the pool
itself ... you want the same pool for all hosts, since they can only
have one cmd_size, but you want it created on first host use and
destroyed again on the last one.

If you take this patch, a host that attached, detaches and then attaches
a host will panic because it will use a freed pool structure.

This whole mess is created by the attempt to refcount the pools.  What's
wrong with simply creating the pool at init time and deleting it again
at module removal ... that way no refcounting and no bogus problems like
this (and we can delete the cmd_pool from the host).  The restriction
this would give is that cmd_size can only be set in the template, but
that seems to be the only safe use anyway, since any driver trying to
vary this in its host add routines will get unexpected results.

James



  reply	other threads:[~2014-08-01 20:24 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-08-01  6:27 [PATCH] Save command pool address of Scsi_Host jgross
2014-08-01 12:03 ` Christoph Hellwig
2014-08-01 20:24   ` James Bottomley [this message]
2014-08-04  4:22     ` Juergen Gross
2014-08-04 11:03       ` Christoph Hellwig
2014-08-04 14:31         ` James Bottomley
2014-08-04 11:07     ` Christoph Hellwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1406924674.2654.19.camel@jarvis \
    --to=james.bottomley@hansenpartnership.com \
    --cc=hch@infradead.org \
    --cc=jgross@suse.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).