From: Li Lingfeng <lilingfeng3@huawei.com>
To: <ranjan.kumar@broadcom.com>
Cc: <linux-scsi@vger.kernel.org>, <jejb@linux.ibm.com>,
<martin.petersen@oracle.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
<rajsekhar.chundru@broadcom.com>, <sathya.prakash@broadcom.com>,
<sumit.saxena@broadcom.com>, <chandrakanth.patil@broadcom.com>,
<prayas.patel@broadcom.com>, yangerkun <yangerkun@huawei.com>,
"zhangyi (F)" <yi.zhang@huawei.com>, Hou Tao <houtao1@huawei.com>,
"chengzhihao1@huawei.com" <chengzhihao1@huawei.com>,
<jiangjianjun3@h-partners.com>, <yuancan@huawei.com>
Subject: [REGRESSION?] scsi: sas: wildcard user scan may iterate over huge max_id
Date: Sat, 28 Mar 2026 10:28:55 +0800 [thread overview]
Message-ID: <773ba972-433b-44b4-89d2-295bd9f5de38@huawei.com> (raw)
Hi,
I think commit 37c4e72b0651 ("scsi: Fix sas_user_scan() to handle wildcard
and multi-channel scans") may introduce a regression for wildcard scans on
some SAS hosts.
Userspace trigger:
echo "- - -" > /sys/class/scsi_host/host0/scan
results in:
channel = SCAN_WILD_CARD
id = SCAN_WILD_CARD
lun = SCAN_WILD_CARD
Before this commit, sas_user_scan() iterated sas_host->rphy_list and called
scsi_scan_target() for matching rphys. In effect, scanning was limited to
channel 0 and to target ids present in sas_host->rphy_list.
After this commit, sas_user_scan() does:
- scan channel 0 via scan_channel_zero()
- scan channels 1..shost->max_channel via scsi_scan_host_selected()
When id == SCAN_WILD_CARD, the latter path goes through
scsi_scan_channel(), which iterates ids from 0 to shost->max_id.
This looks problematic for drivers that use a very large max_id. For
example, smartpqi sets:
shost->max_id = ~0;
In that case, a wildcard scan may end up iterating from id 0 to ~0 in
scsi_scan_channel(). In my testing/analysis, this makes the scan take a
very long time, and the id-space walk itself does not seem meaningful for
this SAS transport scan path.
So while the commit fixes incomplete wildcard channel handling, it also
appears to expand the id scan range from:
sas_host->rphy_list target ids
to:
0..shost->max_id
for the additional channels.
It seems to me that wildcard SAS scans should probably remain bounded by
transport-discovered SAS targets, instead of falling back to a host-wide
id enumeration for the extra channels. One possible direction may be to
avoid calling scsi_scan_host_selected() with id == SCAN_WILD_CARD from
sas_user_scan(), or otherwise constrain the id range in a transport-aware
way.
Am I understanding this correctly? If so, what would be the preferred way
to address this? I would appreciate feedback on whether this is considered
a real regression, and on the best fix direction.
Thanks,
Lingfeng.
next reply other threads:[~2026-03-28 2:29 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-28 2:28 Li Lingfeng [this message]
2026-03-30 8:08 ` Li Lingfeng
2026-03-30 12:18 ` James Bottomley
2026-03-31 2:33 ` Li Lingfeng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=773ba972-433b-44b4-89d2-295bd9f5de38@huawei.com \
--to=lilingfeng3@huawei.com \
--cc=chandrakanth.patil@broadcom.com \
--cc=chengzhihao1@huawei.com \
--cc=houtao1@huawei.com \
--cc=jejb@linux.ibm.com \
--cc=jiangjianjun3@h-partners.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=prayas.patel@broadcom.com \
--cc=rajsekhar.chundru@broadcom.com \
--cc=ranjan.kumar@broadcom.com \
--cc=sathya.prakash@broadcom.com \
--cc=sumit.saxena@broadcom.com \
--cc=yangerkun@huawei.com \
--cc=yi.zhang@huawei.com \
--cc=yuancan@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®