mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Nilay Shroff <nilay@linux.ibm.com>
To: linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org
Cc: shinichiro.kawasaki@wdc.com, hch@lst.de, kbusch@kernel.org,
	sagi@grimberg.me, gjoyce@linux.ibm.com, chaitanyak@nvidia.com,
	Nilay Shroff <nilay@linux.ibm.com>,
	stable@vger.kernel.org
Subject: [PATCH] nvmet: send namespace changed event after namespace is fully initialized
Date: Fri,  2 Oct 2026 12:31:43 +0530	[thread overview]
Message-ID: <20261002070249.338225-1-nilay@linux.ibm.com> (raw)

nvmet_ns_enable() queues the asynchronous namespace change event before
the namespace is enabled and the corresponding xarray entry is marked
with NVMET_NS_ENABLED. This may create a narrow race if the host
receives the namespace change event before the namespace is fully
initialized on the target. In that case, scanning the active namespace
list on the host may fail to find the namespace that is being enabled
on the target.

The blktests nvme/052 failure was reported[1] due to this race.

Fix the race by moving nvmet_ns_changed() in nvmet_ns_enable() after
the namespace is enabled, the xarray entry is marked with
NVMET_NS_ENABLED, and the NVMET_NS_IO_LIVE flag is set.

Cc: stable@vger.kernel.org
Fixes: 74d16965d7ac ("nvmet-loop: avoid using mutex in IO hotpath")
Reported-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
Closes: https://lore.kernel.org/all/ar30Q5H1fuyFtDwM@shinmob/ [1]
Tested-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
Signed-off-by: Nilay Shroff <nilay@linux.ibm.com>
---
 drivers/nvme/target/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/nvme/target/core.c b/drivers/nvme/target/core.c
index 8eea0a504308..da98e5cae7f6 100644
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -626,11 +626,11 @@ int nvmet_ns_enable(struct nvmet_ns *ns)
 	if (ret)
 		goto out_pr_exit;
 
-	nvmet_ns_changed(subsys, ns->nsid);
 	ns->enabled = true;
 	xa_set_mark(&subsys->namespaces, ns->nsid, NVMET_NS_ENABLED);
 	nvmet_debugfs_ns_setup(ns);
 	set_bit(NVMET_NS_IO_LIVE, &ns->flags);
+	nvmet_ns_changed(subsys, ns->nsid);
 	ret = 0;
 out_unlock:
 	mutex_unlock(&subsys->lock);
-- 
2.53.0


                 reply	other threads:[~2026-10-02  7:03 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002070249.338225-1-nilay@linux.ibm.com \
    --to=nilay@linux.ibm.com \
    --cc=chaitanyak@nvidia.com \
    --cc=gjoyce@linux.ibm.com \
    --cc=hch@lst.de \
    --cc=kbusch@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=sagi@grimberg.me \
    --cc=shinichiro.kawasaki@wdc.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®