mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Denis Efremov (Oracle)" <efremov@linux.com>
To: Jens Axboe <axboe@kernel.dk>
Cc: Karl Mehltretter <kmehltretter@gmail.com>,
	linux-block@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [GIT PULL] Floppy fixes for 7.4
Date: Mon, 5 Oct 2026 19:21:25 +0400	[thread overview]
Message-ID: <348194a3-e542-45df-8be9-eaed588c07a7@linux.com> (raw)

Hi Jens,

Floppy fixes for the 7.4 merge window, based on your for-7.4/block
branch.

Please pull

The following changes since commit 9690943353cec1690a715e000ba6a74e5139f530:

  block: amiflop: synchronize flush timer before track flush (2026-10-01 08:37:58 -0600)

are available in the Git repository at:

  https://github.com/evdenis/linux-floppy.git tags/floppy-for-7.4

for you to fetch changes up to bb38473f1bcb287567f2fa7980e483a778092504:

  floppy: return the drive state flags from the 32-bit FDGETDRVSTAT (2026-10-05 18:59:41 +0400)

----------------------------------------------------------------
Floppy fixes for 7.4

Six fixes for long-standing floppy bugs, most of them found by syzbot
or by race detectors:

- Flush pending work before releasing the IRQ and DMA when no FDC is
  found, from Karl Mehltretter. The work queued by the probe could run
  after the IRQ and DMA were already freed ("work still pending").

- Unregister the platform device when add_disk() fails, from Guangshuo
  Li. The failing drive's device stayed registered after the module
  was unloaded, and reading its sysfs attributes oopsed on freed module
  memory.

- Return early from reset_interrupt() when cont is already NULL, from
  Yang Xiuwei. This fixes the syzbot GPF in reset_interrupt(). I decided
  to take v1 as a partial solution; the full fix will require
  additional rework.

- Replace volatile on command_status with READ_ONCE()/WRITE_ONCE() and
  annotate floppy_work_fn and current_type[], from Cen Zhang. No
  functional change.

- Don't keep a pointer to a stack buffer in timeout_message.
  show_floppy() printed it from the interrupt handler after
  request_done() had returned (syzbot KASAN report).

- Copy the drive state flags in the 32-bit FDGETDRVSTAT and
  FDPOLLDRVSTAT. Since 4.13 the compat path returned flags == 0, so
  32-bit fdutils saw every disk as write-protected and never saw a
  disk change.

Tested in QEMU with a floppy test suite (including the compat ioctls
from 32-bit userspace, and fdutils/mtools/dosfstools workflows) on
KASAN and KCSAN kernels, with no new warnings.

Signed-off-by: Denis Efremov (Oracle) <efremov@linux.com>

----------------------------------------------------------------
Cen Zhang (1):
      floppy: annotate data-races around command_status and floppy_work_fn

Denis Efremov (Oracle) (2):
      floppy: don't store a stack buffer in timeout_message
      floppy: return the drive state flags from the 32-bit FDGETDRVSTAT

Guangshuo Li (1):
      floppy: unregister platform device on add_disk failure

Karl Mehltretter (1):
      floppy: flush pending work before releasing resources on init failure

Yang Xiuwei (1):
      floppy: avoid NULL deref in reset_interrupt when cont is cleared

 drivers/block/floppy.c | 56 ++++++++++++++++++++++++++++++--------------------
 1 file changed, 34 insertions(+), 22 deletions(-)

             reply	other threads:[~2026-10-05 15:21 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 15:21 Denis Efremov (Oracle) [this message]
2026-10-05 16:00 ` Jens Axboe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=348194a3-e542-45df-8be9-eaed588c07a7@linux.com \
    --to=efremov@linux.com \
    --cc=axboe@kernel.dk \
    --cc=kmehltretter@gmail.com \
    --cc=linux-block@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®