* [PATCH] scsi: target: reject configfs db_root for ALUA metadata
@ 2026-08-18 4:27 Runyu Xiao
2026-08-18 5:14 ` [PATCH v2] scsi: target: pin db_root for metadata writes Runyu Xiao
0 siblings, 1 reply; 4+ messages in thread
From: Runyu Xiao @ 2026-08-18 4:27 UTC (permalink / raw)
To: Martin K . Petersen
Cc: Nicholas Bellinger, Lee Duncan, linux-scsi, target-devel,
linux-kernel, stable, Runyu Xiao, Jianhao Xu
The db_root configfs attribute only validates that the supplied path
resolves to a directory. Later ALUA metadata writes build file names
under db_root and open them with filp_open().
If db_root itself points at a configfs mount, an ALUA transition that
updates metadata can re-enter configfs through that filp_open() path
while configfs is still servicing the original store. That makes the
metadata path recurse back into the same frag_sem.
Reject configfs-backed db_root values in target_core_item_dbroot_store()
so later metadata users keep running on a normal filesystem instead of
re-entering configfs.
Fixes: a96e9783e058 ("target: make target db location configurable")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
---
drivers/target/target_core_configfs.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/target/target_core_configfs.c b/drivers/target/target_core_configfs.c
index a2bd2e8..5ee6f9c 100644
--- a/drivers/target/target_core_configfs.c
+++ b/drivers/target/target_core_configfs.c
@@ -138,8 +138,16 @@ static ssize_t target_core_item_dbroot_store(struct config_item *item,
pr_err("db_root: not a directory: %s\n", db_root_stage);
goto unlock;
}
+ if (!strcmp(path.dentry->d_sb->s_type->name, "configfs")) {
+ pr_err("db_root: configfs is not a valid target database root: %s\n",
+ db_root_stage);
+ r = -EINVAL;
+ }
path_put(&path);
+ if (r)
+ goto unlock;
+
strscpy(db_root, db_root_stage);
pr_debug("Target_Core_ConfigFS: db_root set to %s\n", db_root);
--
2.34.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH v2] scsi: target: pin db_root for metadata writes
2026-08-18 4:27 [PATCH] scsi: target: reject configfs db_root for ALUA metadata Runyu Xiao
@ 2026-08-18 5:14 ` Runyu Xiao
2026-08-21 12:20 ` kernel test robot
2026-08-23 11:43 ` lkp
0 siblings, 2 replies; 4+ messages in thread
From: Runyu Xiao @ 2026-08-18 5:14 UTC (permalink / raw)
To: Martin K . Petersen
Cc: Nicholas Bellinger, Lee Duncan, linux-scsi, target-devel,
linux-kernel, stable, Runyu Xiao, Jianhao Xu
db_root is configured from configfs as a pathname string. ALUA and
APTPL later build metadata filenames under that string and open them
with filp_open().
Validating db_root once in target_core_item_dbroot_store() is not
enough. A later symlink retarget can bypass a one-time check, and doing
path resolution under target_devices_lock keeps the VFS lock-order
concern in the configfs store path.
Resolve db_root to a directory path once, keep a pinned struct path
reference, and open metadata files relative to that fixed root with
file_open_root(). Also reject configfs-backed roots before publishing
them and move the path walk out from under target_devices_lock.
This closes the ALUA recursive configfs re-entry path without leaving a
string-based TOCTOU gap, and keeps the same fixed-root semantics for
APTPL metadata writes.
Fixes: a96e9783e058 ("target: make target db location configurable")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
---
v2:
- replace one-time store-path validation with a pinned db_root path
- move db_root path resolution out from under target_devices_lock
- open ALUA and APTPL metadata files relative to the pinned root
- close the string-based TOCTOU gap raised in review
drivers/target/target_core_alua.c | 40 ++++++++-----
drivers/target/target_core_configfs.c | 83 ++++++++++++++++++---------
drivers/target/target_core_internal.h | 3 +
drivers/target/target_core_pr.c | 19 ++++--
4 files changed, 96 insertions(+), 49 deletions(-)
diff --git a/drivers/target/target_core_alua.c b/drivers/target/target_core_alua.c
index 10250aca5a81..cfe4c30e534a 100644
--- a/drivers/target/target_core_alua.c
+++ b/drivers/target/target_core_alua.c
@@ -856,17 +856,27 @@ static int core_alua_write_tpg_metadata(
unsigned char *md_buf,
u32 md_buf_len)
{
- struct file *file = filp_open(path, O_RDWR | O_CREAT | O_TRUNC, 0600);
+ struct file *file;
loff_t pos = 0;
int ret;
+ if (!db_root_path.dentry) {
+ pr_err("db_root is not initialized for ALUA metadata path: %s/%s\n",
+ db_root, path);
+ return -ENODEV;
+ }
+
+ file = file_open_root(&db_root_path, path, O_RDWR | O_CREAT | O_TRUNC,
+ 0600);
if (IS_ERR(file)) {
- pr_err("filp_open(%s) for ALUA metadata failed\n", path);
+ pr_err("file_open_root(%s/%s) for ALUA metadata failed\n",
+ db_root, path);
return -ENODEV;
}
ret = kernel_write(file, md_buf, md_buf_len, &pos);
if (ret < 0)
- pr_err("Error writing ALUA metadata file: %s\n", path);
+ pr_err("Error writing ALUA metadata file: %s/%s\n", db_root,
+ path);
fput(file);
return (ret < 0) ? -EIO : 0;
}
@@ -896,9 +906,9 @@ static int core_alua_update_tpg_primary_metadata(
tg_pt_gp->tg_pt_gp_alua_access_status);
rc = -ENOMEM;
- path = kasprintf(GFP_KERNEL, "%s/alua/tpgs_%s/%s", db_root,
- &wwn->unit_serial[0],
- config_item_name(&tg_pt_gp->tg_pt_gp_group.cg_item));
+ path = kasprintf(GFP_KERNEL, "alua/tpgs_%s/%s",
+ &wwn->unit_serial[0],
+ config_item_name(&tg_pt_gp->tg_pt_gp_group.cg_item));
if (path) {
rc = core_alua_write_tpg_metadata(path, md_buf, len);
kfree(path);
@@ -1187,16 +1197,16 @@ static int core_alua_update_tpg_secondary_metadata(struct se_lun *lun)
lun->lun_tg_pt_secondary_stat);
if (se_tpg->se_tpg_tfo->tpg_get_tag != NULL) {
- path = kasprintf(GFP_KERNEL, "%s/alua/%s/%s+%hu/lun_%llu",
- db_root, se_tpg->se_tpg_tfo->fabric_name,
- se_tpg->se_tpg_tfo->tpg_get_wwn(se_tpg),
- se_tpg->se_tpg_tfo->tpg_get_tag(se_tpg),
- lun->unpacked_lun);
+ path = kasprintf(GFP_KERNEL, "alua/%s/%s+%hu/lun_%llu",
+ se_tpg->se_tpg_tfo->fabric_name,
+ se_tpg->se_tpg_tfo->tpg_get_wwn(se_tpg),
+ se_tpg->se_tpg_tfo->tpg_get_tag(se_tpg),
+ lun->unpacked_lun);
} else {
- path = kasprintf(GFP_KERNEL, "%s/alua/%s/%s/lun_%llu",
- db_root, se_tpg->se_tpg_tfo->fabric_name,
- se_tpg->se_tpg_tfo->tpg_get_wwn(se_tpg),
- lun->unpacked_lun);
+ path = kasprintf(GFP_KERNEL, "alua/%s/%s/lun_%llu",
+ se_tpg->se_tpg_tfo->fabric_name,
+ se_tpg->se_tpg_tfo->tpg_get_wwn(se_tpg),
+ lun->unpacked_lun);
}
if (!path) {
rc = -ENOMEM;
diff --git a/drivers/target/target_core_configfs.c b/drivers/target/target_core_configfs.c
index a2bd2e81d2c6..7788db0c64eb 100644
--- a/drivers/target/target_core_configfs.c
+++ b/drivers/target/target_core_configfs.c
@@ -96,8 +96,31 @@ static ssize_t target_core_item_version_show(struct config_item *item,
CONFIGFS_ATTR_RO(target_core_item_, version);
char db_root[DB_ROOT_LEN] = DB_ROOT_DEFAULT;
+struct path db_root_path;
static char db_root_stage[DB_ROOT_LEN];
+static int target_validate_db_root(const char *path_str, struct path *path)
+{
+ int ret;
+
+ ret = kern_path(path_str, LOOKUP_FOLLOW | LOOKUP_DIRECTORY, path);
+ if (ret) {
+ pr_err("db_root: cannot open: %s\n", path_str);
+ if (ret == -ENOTDIR)
+ pr_err("db_root: not a directory: %s\n", path_str);
+ return ret;
+ }
+
+ if (!strcmp(path->dentry->d_sb->s_type->name, "configfs")) {
+ pr_err("db_root: configfs is not a valid target database root: %s\n",
+ path_str);
+ path_put(path);
+ return -EINVAL;
+ }
+
+ return 0;
+}
+
static ssize_t target_core_item_dbroot_show(struct config_item *item,
char *page)
{
@@ -110,43 +133,49 @@ static ssize_t target_core_item_dbroot_store(struct config_item *item,
ssize_t read_bytes;
ssize_t r = -EINVAL;
struct path path = {};
-
- mutex_lock(&target_devices_lock);
- if (target_devices) {
- pr_err("db_root: cannot be changed because it's in use\n");
- goto unlock;
- }
+ struct path old_path = {};
+ bool have_old_path = false;
if (count > (DB_ROOT_LEN - 1)) {
pr_err("db_root: count %d exceeds DB_ROOT_LEN-1: %u\n",
(int)count, DB_ROOT_LEN - 1);
- goto unlock;
+ return r;
}
read_bytes = scnprintf(db_root_stage, DB_ROOT_LEN, "%s", page);
if (!read_bytes)
- goto unlock;
+ return r;
if (db_root_stage[read_bytes - 1] == '\n')
db_root_stage[read_bytes - 1] = '\0';
/* validate new db root before accepting it */
- r = kern_path(db_root_stage, LOOKUP_FOLLOW | LOOKUP_DIRECTORY, &path);
- if (r) {
- pr_err("db_root: cannot open: %s\n", db_root_stage);
- if (r == -ENOTDIR)
- pr_err("db_root: not a directory: %s\n", db_root_stage);
- goto unlock;
+ r = target_validate_db_root(db_root_stage, &path);
+ if (r)
+ return r;
+
+ mutex_lock(&target_devices_lock);
+ if (target_devices) {
+ pr_err("db_root: cannot be changed because it's in use\n");
+ goto unlock_put;
}
- path_put(&path);
+ have_old_path = db_root_path.dentry;
+ if (have_old_path)
+ old_path = db_root_path;
+ db_root_path = path;
+ path = (struct path){};
strscpy(db_root, db_root_stage);
pr_debug("Target_Core_ConfigFS: db_root set to %s\n", db_root);
r = read_bytes;
-unlock:
+unlock_put:
mutex_unlock(&target_devices_lock);
+ if (path.dentry)
+ path_put(&path);
+ if (have_old_path)
+ path_put(&old_path);
return r;
}
@@ -3643,21 +3672,19 @@ void target_setup_backend_cits(struct target_backend *tb)
static void target_init_dbroot(void)
{
- struct file *fp;
+ struct path path = {};
+ int ret;
- snprintf(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
- fp = filp_open(db_root_stage, O_RDONLY, 0);
- if (IS_ERR(fp)) {
- pr_err("db_root: cannot open: %s\n", db_root_stage);
- return;
- }
- if (!S_ISDIR(file_inode(fp)->i_mode)) {
- filp_close(fp, NULL);
- pr_err("db_root: not a valid directory: %s\n", db_root_stage);
- return;
+ strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
+ ret = target_validate_db_root(db_root_stage, &path);
+ if (ret) {
+ strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
+ ret = target_validate_db_root(db_root_stage, &path);
+ if (ret)
+ return;
}
- filp_close(fp, NULL);
+ db_root_path = path;
strscpy(db_root, db_root_stage);
pr_debug("Target_Core_ConfigFS: db_root set to %s\n", db_root);
}
diff --git a/drivers/target/target_core_internal.h b/drivers/target/target_core_internal.h
index 20aab1f50565..4cbc6218d4de 100644
--- a/drivers/target/target_core_internal.h
+++ b/drivers/target/target_core_internal.h
@@ -169,6 +169,9 @@ extern struct se_portal_group xcopy_pt_tpg;
#define DB_ROOT_DEFAULT "/var/target"
#define DB_ROOT_PREFERRED "/etc/target"
+struct path;
+
extern char db_root[];
+extern struct path db_root_path;
#endif /* TARGET_CORE_INTERNAL_H */
diff --git a/drivers/target/target_core_pr.c b/drivers/target/target_core_pr.c
index 83e172c92238..35ec38c6f528 100644
--- a/drivers/target/target_core_pr.c
+++ b/drivers/target/target_core_pr.c
@@ -1965,15 +1965,21 @@ static int __core_scsi3_write_aptpl_to_file(
int ret;
loff_t pos = 0;
- path = kasprintf(GFP_KERNEL, "%s/pr/aptpl_%s", db_root,
- &wwn->unit_serial[0]);
+ path = kasprintf(GFP_KERNEL, "pr/aptpl_%s", &wwn->unit_serial[0]);
if (!path)
return -ENOMEM;
- file = filp_open(path, flags, 0600);
+ if (!db_root_path.dentry) {
+ pr_err("db_root is not initialized for APTPL metadata path: %s/%s\n",
+ db_root, path);
+ kfree(path);
+ return -ENODEV;
+ }
+
+ file = file_open_root(&db_root_path, path, flags, 0600);
if (IS_ERR(file)) {
- pr_err("filp_open(%s) for APTPL metadata"
- " failed\n", path);
+ pr_err("file_open_root(%s/%s) for APTPL metadata failed\n",
+ db_root, path);
kfree(path);
return PTR_ERR(file);
}
@@ -1983,7 +1989,8 @@ static int __core_scsi3_write_aptpl_to_file(
ret = kernel_write(file, buf, pr_aptpl_buf_len, &pos);
if (ret < 0)
- pr_debug("Error writing APTPL metadata file: %s\n", path);
+ pr_debug("Error writing APTPL metadata file: %s/%s\n", db_root,
+ path);
fput(file);
kfree(path);
--
2.34.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH v2] scsi: target: pin db_root for metadata writes
2026-08-18 5:14 ` [PATCH v2] scsi: target: pin db_root for metadata writes Runyu Xiao
@ 2026-08-21 12:20 ` kernel test robot
2026-08-23 11:43 ` lkp
1 sibling, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-08-21 12:20 UTC (permalink / raw)
To: Runyu Xiao, Martin K . Petersen
Cc: llvm, oe-kbuild-all, Nicholas Bellinger, Lee Duncan, linux-scsi,
target-devel, linux-kernel, stable, Runyu Xiao, Jianhao Xu
Hi Runyu,
kernel test robot noticed the following build errors:
[auto build test ERROR on mkp-scsi/for-next]
[also build test ERROR on v7.2]
[cannot apply to linus/master next-20260820]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Runyu-Xiao/scsi-target-pin-db_root-for-metadata-writes/20260818-131442
base: https://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi.git for-next
patch link: https://lore.kernel.org/r/20260818051442.1523210-1-runyu.xiao%40seu.edu.cn
patch subject: [PATCH v2] scsi: target: pin db_root for metadata writes
config: loongarch-defconfig (https://download.01.org/0day-ci/archive/20260821/202608212004.Xyev8OzS-lkp@intel.com/config)
compiler: clang version 24.0.0git (https://github.com/llvm/llvm-project 935bfc708590c60147a79c7df145bb6e68b1d388)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260821/202608212004.Xyev8OzS-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608212004.Xyev8OzS-lkp@intel.com/
All error/warnings (new ones prefixed by >>):
>> drivers/target/target_core_configfs.c:3757:2: warning: adding 'int' to a string does not append to the string [-Wstring-plus-int]
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/string.h:111:2: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/args.h:26:27: note: expanded from macro 'CONCATENATE'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^
include/linux/args.h:25:24: note: expanded from macro '__CONCAT'
25 | #define __CONCAT(a, b) a ## b
| ^
<scratch space>:29:1: note: expanded from here
29 | __strscpy1
| ^
include/linux/string.h:80:31: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ~~~~~^~~~~~~~~~~~~~~~~~~~~
drivers/target/target_core_configfs.c:3757:2: note: use array indexing to silence this warning
include/linux/string.h:111:2: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^
include/linux/args.h:26:27: note: expanded from macro 'CONCATENATE'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^
include/linux/args.h:25:24: note: expanded from macro '__CONCAT'
25 | #define __CONCAT(a, b) a ## b
| ^
<scratch space>:29:1: note: expanded from here
29 | __strscpy1
| ^
include/linux/string.h:80:31: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^
>> drivers/target/target_core_configfs.c:3757:25: error: incompatible integer to pointer conversion passing 'int' to parameter of type 'const char *' [-Wint-conversion]
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~~~~~
drivers/target/target_core_internal.h:169:22: note: expanded from macro 'DB_ROOT_LEN'
169 | #define DB_ROOT_LEN 4096
| ^~~~
include/linux/string.h:70:43: note: passing argument to parameter here
70 | ssize_t sized_strscpy(char *, const char *, size_t);
| ^
>> drivers/target/target_core_configfs.c:3757:38: error: incompatible pointer to integer conversion passing 'char *' to parameter of type 'size_t' (aka 'unsigned long') [-Wint-conversion]
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~
drivers/target/target_core_internal.h:171:27: note: expanded from macro 'DB_ROOT_PREFERRED'
171 | #define DB_ROOT_PREFERRED "/etc/target"
| ^
include/linux/string.h:111:60: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~
include/linux/string.h:80:26: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/string.h:70:51: note: passing argument to parameter here
70 | ssize_t sized_strscpy(char *, const char *, size_t);
| ^
drivers/target/target_core_configfs.c:3760:3: warning: adding 'int' to a string does not append to the string [-Wstring-plus-int]
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/string.h:111:2: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/args.h:26:27: note: expanded from macro 'CONCATENATE'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^
include/linux/args.h:25:24: note: expanded from macro '__CONCAT'
25 | #define __CONCAT(a, b) a ## b
| ^
<scratch space>:30:1: note: expanded from here
30 | __strscpy1
| ^
include/linux/string.h:80:31: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ~~~~~^~~~~~~~~~~~~~~~~~~~~
drivers/target/target_core_configfs.c:3760:3: note: use array indexing to silence this warning
include/linux/string.h:111:2: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^
include/linux/args.h:26:27: note: expanded from macro 'CONCATENATE'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^
include/linux/args.h:25:24: note: expanded from macro '__CONCAT'
25 | #define __CONCAT(a, b) a ## b
| ^
<scratch space>:30:1: note: expanded from here
30 | __strscpy1
| ^
include/linux/string.h:80:31: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^
drivers/target/target_core_configfs.c:3760:26: error: incompatible integer to pointer conversion passing 'int' to parameter of type 'const char *' [-Wint-conversion]
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~~~~~
drivers/target/target_core_internal.h:169:22: note: expanded from macro 'DB_ROOT_LEN'
169 | #define DB_ROOT_LEN 4096
| ^~~~
include/linux/string.h:70:43: note: passing argument to parameter here
70 | ssize_t sized_strscpy(char *, const char *, size_t);
| ^
drivers/target/target_core_configfs.c:3760:39: error: incompatible pointer to integer conversion passing 'char *' to parameter of type 'size_t' (aka 'unsigned long') [-Wint-conversion]
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~
drivers/target/target_core_internal.h:170:26: note: expanded from macro 'DB_ROOT_DEFAULT'
170 | #define DB_ROOT_DEFAULT "/var/target"
| ^
include/linux/string.h:111:60: note: expanded from macro 'strscpy'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~
include/linux/string.h:80:26: note: expanded from macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
include/linux/string.h:70:51: note: passing argument to parameter here
70 | ssize_t sized_strscpy(char *, const char *, size_t);
| ^
2 warnings and 4 errors generated.
vim +3757 drivers/target/target_core_configfs.c
3751
3752 static void target_init_dbroot(void)
3753 {
3754 struct path path = {};
3755 int ret;
3756
> 3757 strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
3758 ret = target_validate_db_root(db_root_stage, &path);
3759 if (ret) {
3760 strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
3761 ret = target_validate_db_root(db_root_stage, &path);
3762 if (ret)
3763 return;
3764 }
3765
3766 db_root_path = path;
3767 strscpy(db_root, db_root_stage);
3768 pr_debug("Target_Core_ConfigFS: db_root set to %s\n", db_root);
3769 }
3770
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v2] scsi: target: pin db_root for metadata writes
2026-08-18 5:14 ` [PATCH v2] scsi: target: pin db_root for metadata writes Runyu Xiao
2026-08-21 12:20 ` kernel test robot
@ 2026-08-23 11:43 ` lkp
1 sibling, 0 replies; 4+ messages in thread
From: lkp @ 2026-08-23 11:43 UTC (permalink / raw)
To: Runyu Xiao, Martin K . Petersen
Cc: oe-kbuild-all, Nicholas Bellinger, Lee Duncan, linux-scsi,
target-devel, linux-kernel, stable, Runyu Xiao, Jianhao Xu
Hi Runyu,
kernel test robot noticed the following build errors:
[auto build test ERROR on mkp-scsi/for-next]
[also build test ERROR on v7.2]
[cannot apply to linus/master next-20260821]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Runyu-Xiao/scsi-target-pin-db_root-for-metadata-writes/20260818-131442
base: https://git.kernel.org/pub/scm/linux/kernel/git/mkp/scsi.git for-next
patch link: https://lore.kernel.org/r/20260818051442.1523210-1-runyu.xiao%40seu.edu.cn
patch subject: [PATCH v2] scsi: target: pin db_root for metadata writes
config: powerpc-allmodconfig (https://download.01.org/0day-ci/archive/20260823/202608231112.vQxAhOxi-lkp@intel.com/config)
compiler: powerpc64-linux-gcc (GCC) 16.1.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260823/202608231112.vQxAhOxi-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608231112.vQxAhOxi-lkp@intel.com/
All errors (new ones prefixed by >>):
In file included from arch/powerpc/include/asm/paca.h:16,
from arch/powerpc/include/asm/current.h:13,
from include/linux/thread_info.h:23,
from include/asm-generic/preempt.h:5,
from arch/powerpc/include/asm/preempt.h:5,
from include/linux/preempt.h:79,
from include/linux/spinlock.h:56,
from include/linux/mmzone.h:8,
from include/linux/gfp.h:7,
from include/linux/umh.h:4,
from include/linux/kmod.h:9,
from include/linux/module.h:18,
from drivers/target/target_core_configfs.c:16:
drivers/target/target_core_configfs.c: In function 'target_init_dbroot':
>> drivers/target/target_core_internal.h:169:33: error: passing argument 2 of 'sized_strscpy' makes pointer from integer without a cast [-Wint-conversion]
169 | #define DB_ROOT_LEN 4096
| ^~~~
| |
| int
include/linux/string.h:80:28: note: in definition of macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~
drivers/target/target_core_configfs.c:3757:9: note: in expansion of macro 'strscpy'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~
drivers/target/target_core_configfs.c:3757:32: note: in expansion of macro 'DB_ROOT_LEN'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~~~~~
In file included from include/linux/string.h:383:
include/linux/fortify-string.h:227:83: note: expected 'const char *' but argument is of type 'int'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~~~~~~~~~~~~~~~~~^
>> include/linux/string.h:80:60: error: passing argument 3 of 'sized_strscpy' makes integer from pointer without a cast [-Wint-conversion]
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
include/linux/args.h:25:24: note: in expansion of macro '__strscpy1'
25 | #define __CONCAT(a, b) a ## b
| ^
include/linux/args.h:26:27: note: in expansion of macro '__CONCAT'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^~~~~~~~
include/linux/string.h:111:9: note: in expansion of macro 'CONCATENATE'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~
drivers/target/target_core_configfs.c:3757:9: note: in expansion of macro 'strscpy'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~
include/linux/fortify-string.h:227:93: note: expected 'long unsigned int' but argument is of type 'char *'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~^~~~
>> drivers/target/target_core_internal.h:169:33: error: passing argument 2 of 'sized_strscpy' makes pointer from integer without a cast [-Wint-conversion]
169 | #define DB_ROOT_LEN 4096
| ^~~~
| |
| int
include/linux/string.h:80:28: note: in definition of macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~
drivers/target/target_core_configfs.c:3760:17: note: in expansion of macro 'strscpy'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~
drivers/target/target_core_configfs.c:3760:40: note: in expansion of macro 'DB_ROOT_LEN'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~~~~~
include/linux/fortify-string.h:227:83: note: expected 'const char *' but argument is of type 'int'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~~~~~~~~~~~~~~~~~^
>> include/linux/string.h:80:60: error: passing argument 3 of 'sized_strscpy' makes integer from pointer without a cast [-Wint-conversion]
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
include/linux/args.h:25:24: note: in expansion of macro '__strscpy1'
25 | #define __CONCAT(a, b) a ## b
| ^
include/linux/args.h:26:27: note: in expansion of macro '__CONCAT'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^~~~~~~~
include/linux/string.h:111:9: note: in expansion of macro 'CONCATENATE'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~
drivers/target/target_core_configfs.c:3760:17: note: in expansion of macro 'strscpy'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~
include/linux/fortify-string.h:227:93: note: expected 'long unsigned int' but argument is of type 'char *'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~^~~~
--
In file included from arch/powerpc/include/asm/paca.h:16,
from arch/powerpc/include/asm/current.h:13,
from include/linux/thread_info.h:23,
from include/asm-generic/preempt.h:5,
from arch/powerpc/include/asm/preempt.h:5,
from include/linux/preempt.h:79,
from include/linux/spinlock.h:56,
from include/linux/mmzone.h:8,
from include/linux/gfp.h:7,
from include/linux/umh.h:4,
from include/linux/kmod.h:9,
from include/linux/module.h:18,
from target/target_core_configfs.c:16:
target/target_core_configfs.c: In function 'target_init_dbroot':
target/target_core_internal.h:169:33: error: passing argument 2 of 'sized_strscpy' makes pointer from integer without a cast [-Wint-conversion]
169 | #define DB_ROOT_LEN 4096
| ^~~~
| |
| int
include/linux/string.h:80:28: note: in definition of macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~
target/target_core_configfs.c:3757:9: note: in expansion of macro 'strscpy'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~
target/target_core_configfs.c:3757:32: note: in expansion of macro 'DB_ROOT_LEN'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~~~~~
In file included from include/linux/string.h:383:
include/linux/fortify-string.h:227:83: note: expected 'const char *' but argument is of type 'int'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~~~~~~~~~~~~~~~~~^
>> include/linux/string.h:80:60: error: passing argument 3 of 'sized_strscpy' makes integer from pointer without a cast [-Wint-conversion]
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
include/linux/args.h:25:24: note: in expansion of macro '__strscpy1'
25 | #define __CONCAT(a, b) a ## b
| ^
include/linux/args.h:26:27: note: in expansion of macro '__CONCAT'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^~~~~~~~
include/linux/string.h:111:9: note: in expansion of macro 'CONCATENATE'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~
target/target_core_configfs.c:3757:9: note: in expansion of macro 'strscpy'
3757 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_PREFERRED);
| ^~~~~~~
include/linux/fortify-string.h:227:93: note: expected 'long unsigned int' but argument is of type 'char *'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~^~~~
target/target_core_internal.h:169:33: error: passing argument 2 of 'sized_strscpy' makes pointer from integer without a cast [-Wint-conversion]
169 | #define DB_ROOT_LEN 4096
| ^~~~
| |
| int
include/linux/string.h:80:28: note: in definition of macro '__strscpy1'
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
| ^~~
target/target_core_configfs.c:3760:17: note: in expansion of macro 'strscpy'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~
target/target_core_configfs.c:3760:40: note: in expansion of macro 'DB_ROOT_LEN'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~~~~~
include/linux/fortify-string.h:227:83: note: expected 'const char *' but argument is of type 'int'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~~~~~~~~~~~~~~~~~^
>> include/linux/string.h:80:60: error: passing argument 3 of 'sized_strscpy' makes integer from pointer without a cast [-Wint-conversion]
80 | sized_strscpy(dst, src, size + __must_be_cstr(dst) + __must_be_cstr(src))
include/linux/args.h:25:24: note: in expansion of macro '__strscpy1'
25 | #define __CONCAT(a, b) a ## b
| ^
include/linux/args.h:26:27: note: in expansion of macro '__CONCAT'
26 | #define CONCATENATE(a, b) __CONCAT(a, b)
| ^~~~~~~~
include/linux/string.h:111:9: note: in expansion of macro 'CONCATENATE'
111 | CONCATENATE(__strscpy, COUNT_ARGS(__VA_ARGS__))(dst, src, __VA_ARGS__)
| ^~~~~~~~~~~
target/target_core_configfs.c:3760:17: note: in expansion of macro 'strscpy'
3760 | strscpy(db_root_stage, DB_ROOT_LEN, DB_ROOT_DEFAULT);
| ^~~~~~~
include/linux/fortify-string.h:227:93: note: expected 'long unsigned int' but argument is of type 'char *'
227 | __FORTIFY_INLINE ssize_t sized_strscpy(char * const POS p, const char * const POS q, size_t size)
| ~~~~~~~^~~~
vim +/sized_strscpy +169 drivers/target/target_core_internal.h
adf653f92f38e8 Christoph Hellwig 2015-05-25 167
a96e9783e05851 Lee Duncan 2016-04-14 168 /* target_core_configfs.c */
a96e9783e05851 Lee Duncan 2016-04-14 @169 #define DB_ROOT_LEN 4096
a96e9783e05851 Lee Duncan 2016-04-14 170 #define DB_ROOT_DEFAULT "/var/target"
78a6295c71cb27 Lee Duncan 2018-04-06 171 #define DB_ROOT_PREFERRED "/etc/target"
a96e9783e05851 Lee Duncan 2016-04-14 172
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-23 11:43 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-18 4:27 [PATCH] scsi: target: reject configfs db_root for ALUA metadata Runyu Xiao
2026-08-18 5:14 ` [PATCH v2] scsi: target: pin db_root for metadata writes Runyu Xiao
2026-08-21 12:20 ` kernel test robot
2026-08-23 11:43 ` lkp
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox