From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 84E2837B402 for ; Thu, 23 Jul 2026 21:49:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784843379; cv=none; b=TAu1ZbxBVRMBOnzwSo3LFagR69d8xIF31wxJ1nQsKUKnl6ik4FJRVRxvJB5DzBmfmtslBwzoEHhLb7xwZkNCStITQvFo7SwylgVKEyfMxL/DHAdjO4NSgCJS83Jc93T6VnZHDv7lywM+gXo6aTspShOf0FCgUbtY+0aBMO0QWEs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784843379; c=relaxed/simple; bh=b4LR0f+3CbYzZPifrL0npIjyqK6Ux/1GpvOHUqezZNo=; h=From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type:Date; b=jbIFLhZdRz556r0MglLICLYa3v+3hSHIZxCojnl2SUwFD28IL3hmDiLDQSqvGTrZG8KqXHHnbeExxNBqfzQSzHE9NQ3Txv2H4+C/TgsEiraVa/hVprrp7kTssWVm0gxNEIIvbX+/wcoyG7iB2rZbctZAgGSHStRyJv4GEvkkM4s= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=EEHwk+D5; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="EEHwk+D5" Received: by smtp.kernel.org (Postfix) with UTF8SMTPSA id 116C01F000E9; Thu, 23 Jul 2026 21:49:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1784843378; bh=QGuDTWervAYdEnq85Jd+LFh7HDeU1vRk7mENSeSgKYA=; h=From:To:Cc:Subject:Date; b=EEHwk+D5DR2Q6NqXRGs7u+Lb7xcXf1skqUQ1X54D/Urm1OSztDOHKElrX1UQPisf2 1NhrZozg7uAZJE9ccJWgZRrx9MLZN/En9nE4L8oK9Rm27DJekgL8teY6EOMD5/sXK8 /468hDkdepTWFwFOgfz/4Oc+neEUCtj8eQX6eV+3FcLJTs9HzFJBZennq9ogBc4GBe NBgMAbsKe5x8Qq4mH9SStPXNH6ACb3tTXGajvJYLrBE12PWFk63c1YEP/osyi8j4pf APofN4+6FwmopfUhlEtUgC4Bkt0o9O/iT/iWwlKtvU9Wak2QNigwsESQzWgytkNAaS O2kL/TQJqM5Bw== From: "syzbot" To: syzkaller-upstream-moderation@googlegroups.com Cc: krystianmkaniewski@gmail.com, syzbot@lists.linux.dev Subject: [PATCH RFC v4] nbd: skip queue limits update for size-only reconfigure Message-ID: <91ae453b-d78d-443c-9f19-4588fa65447a@mail.kernel.org> Precedence: bulk X-Mailing-List: syzbot@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Date: Thu, 23 Jul 2026 21:49:38 +0000 (UTC) Commit 242a49e5c878 ("nbd: freeze the queue for queue limits updates") correctly added queue freezing for live updates of real queue limits. However, nbd_set_size() is also used for capacity-only generic netlink updates, so the freeze is unnecessarily broad for the reported request. When an NBD server becomes unresponsive, it leaves I/O in flight. An unnecessary queue freeze during a size-only reconfigure will wait forever for these in-flight I/Os to complete while the global genl_mutex is held, leading to a global generic netlink stall. A size-only reconfigure can update config->bytesize and disk capacity directly because the effective block size and all other queue limits stay unchanged. This patch introduces nbd_size_set() to handle size-only updates directly without freezing the queue or committing queue limits. Capacity-only generic netlink reconfiguration no longer freezes the queue, while startup and real block-size changes continue to use the existing frozen limits update via nbd_set_size(). Fixes: 242a49e5c878 ("nbd: freeze the queue for queue limits updates") Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot Reported-by: syzbot Closes: https://syzkaller.appspot.com/bug?extid=f272bbfbf8498ddadea5 Link: https://syzkaller.appspot.com/ai_job?id=786b3bd0-fdad-4252-9e86-7a6a35c3b756 To: "Jens Axboe" To: "Josef Bacik" To: To: To: "Christoph Hellwig" Cc: --- v4: - Removed stack traces from the commit message. - Replaced "system-wide deadlock" with "global generic netlink stall" in the commit message. v3: - Removed the unrelated decrement of nbd_total_devices in nbd_dev_remove(). - Corrected the referenced commit title of 242a49e5c878 in the description. - Clarified that capacity-only generic netlink reconfiguration no longer freezes the queue, while startup and real block-size changes continue to do so. https://lore.kernel.org/all/130f544a-70fd-4ca0-91e8-08824170c91b@mail.kernel.org/T/ v2: - Replaced the approach of using parallel netlink ops and custom timeouts with skipping queue limits updates for size-only reconfigurations. - Introduced nbd_size_set() and nbd_size_update() to update device capacity directly without freezing the queue when the block size does not change. - Retained queue freezing only for actual block-size changes. - Added decrement of nbd_total_devices in nbd_dev_remove(). https://lore.kernel.org/all/514764a5-5acd-4e5d-a8eb-f40c403e7514@mail.kernel.org/T/ v1: https://lore.kernel.org/all/69ff9a21-60be-4e97-bc8f-a59e739fd982@mail.kernel.org/T/ --- diff --git a/drivers/block/nbd.c b/drivers/block/nbd.c index fe63f3c55..567b031ec 100644 --- a/drivers/block/nbd.c +++ b/drivers/block/nbd.c @@ -331,6 +331,27 @@ static void nbd_mark_nsock_dead(struct nbd_device *nbd, struct nbd_sock *nsock, nsock->sent = 0; } +static void nbd_size_update(struct nbd_device *nbd) +{ + struct nbd_config *config = nbd->config; + + if (max_part) + set_bit(GD_NEED_PART_SCAN, &nbd->disk->state); + if (!set_capacity_and_notify(nbd->disk, config->bytesize >> 9)) + kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE); +} + +static int nbd_size_set(struct nbd_device *nbd, loff_t bytesize) +{ + if (bytesize < 0) + return -EINVAL; + + nbd->config->bytesize = bytesize; + if (nbd->pid) + nbd_size_update(nbd); + return 0; +} + static int nbd_set_size(struct nbd_device *nbd, loff_t bytesize, loff_t blksize) { struct queue_limits lim; @@ -375,10 +396,7 @@ static int nbd_set_size(struct nbd_device *nbd, loff_t bytesize, loff_t blksize) if (error) return error; - if (max_part) - set_bit(GD_NEED_PART_SCAN, &nbd->disk->state); - if (!set_capacity_and_notify(nbd->disk, bytesize >> 9)) - kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE); + nbd_size_update(nbd); return 0; } @@ -2062,11 +2080,19 @@ static int nbd_genl_size_set(struct genl_info *info, struct nbd_device *nbd) if (info->attrs[NBD_ATTR_SIZE_BYTES]) bytes = nla_get_u64(info->attrs[NBD_ATTR_SIZE_BYTES]); - if (info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]) + if (info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]) { bsize = nla_get_u64(info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]); + if (!bsize) + bsize = 1u << NBD_DEF_BLKSIZE_BITS; + if (blk_validate_block_size(bsize)) + return -EINVAL; + } - if (bytes != config->bytesize || bsize != nbd_blksize(config)) - return nbd_set_size(nbd, bytes, bsize); + if (bytes != config->bytesize || bsize != nbd_blksize(config)) { + if (bsize != nbd_blksize(config)) + return nbd_set_size(nbd, bytes, bsize); + return nbd_size_set(nbd, bytes); + } return 0; } base-commit: 8cd9520d35a6c38db6567e97dd93b1f11f185dc6 -- This is an AI-generated patch subject to moderation. Reply with '#syz upstream' to Sign-off the patch as a human author and send it to the upstream kernel mailing lists. Reply with '#syz reject' to reject it ('#syz unreject' to undo). See https://goo.gle/syzbot-ai-patches for information about AI-generated patches. You can comment on the patch as usual, syzbot will try to address the comments and send a new version of the patch if necessary. syzbot engineers can be reached at syzkaller@googlegroups.com.