mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Damien Le Moal <dlemoal@kernel.org>
To: Palla Raghunath <raghunathpalla.0209@gmail.com>,
	Keith Busch <kbusch@kernel.org>, Jens Axboe <axboe@kernel.dk>,
	Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>,
	Yao Sang <sangyao@kylinos.cn>
Cc: Shuah Khan <shuah@kernel.org>,
	Brigham Campbell <me@brighamcampbell.com>,
	linux-kernel-mentees@lists.linux.dev,
	linux-kernel@vger.kernel.org,
	syzbot+b0910be96b7c31314822@syzkaller.appspotmail.com,
	syzbot+2e02ccadb3c5522a5c59@syzkaller.appspotmail.com,
	linux-nvme@lists.infradead.org
Subject: Re: [PATCH] nvme-multipath: revalidate head zones after unfreezing the head queue
Date: Wed, 30 Sep 2026 09:45:58 +0200	[thread overview]
Message-ID: <da512295-e265-43eb-b44a-74bc7647acfa@kernel.org> (raw)
In-Reply-To: <20260930062648.73871-1-raghunathpalla.0209@gmail.com>

On 2026/09/30 8:26, Palla Raghunath wrote:
> When a namespace on a multipath controller is updated,
> nvme_update_ns_info() freezes the head disk queue, commits the new
> limits, and then calls nvme_mpath_revalidate_zones() before it
> unfreezes the queue again.
> 
> That is the wrong way round for blk_revalidate_disk_zones(). It starts
> a limits update, which takes q->limits_lock, and it freezes the queue
> itself while updating the zone resources. The block layer takes
> limits_lock before freezing the queue, never the other way around, so
> calling it with the head queue already frozen reverses that order.
> 
> syzbot has hit this twice. One report goes through q->limits_lock. The
> other one is on linux-next, where blk_revalidate_disk_zones() also
> takes disk->zone_revalidate_mutex and holds it across alloc_workqueue()
> the first time a disk's zone resources are set up. Lockdep then sees:
> 
>   q_usage_counter(io) (frozen head queue, nvme_update_ns_info())
>   --> &disk->zone_revalidate_mutex
>   --> wq_pool_mutex --> fs_reclaim --> q_usage_counter(io)
> 
>   WARNING: possible circular locking dependency detected
>   kworker/u8:10/3352 is trying to acquire lock:
>   (&disk->zone_revalidate_mutex){+.+.}-{4:4}, at: blk_revalidate_disk_zones+0x1c5/0x1650
>   but task is already holding lock:
>   (&q->q_usage_counter(io)#75){++++}-{0:0}, at: nvme_update_ns_info+0x3ac/0x1200
>   ...
>    blk_revalidate_disk_zones+0x1c5/0x1650 block/blk-zoned.c:2560
>    nvme_mpath_revalidate_zones+0x106/0x1c0 drivers/nvme/host/multipath.c:301
>    nvme_update_ns_info+0x984/0x1200 drivers/nvme/host/core.c:2620
> 
> The rest of the driver already does this correctly:
> nvme_update_ns_info_block() unfreezes ns->disk->queue before calling
> blk_revalidate_disk_zones(), and nvme_mpath_set_live() revalidates the
> head zones without freezing the queue. Do the same here, and only
> revalidate the head zones once the queue is unfrozen and the limits
> update has succeeded.
> 
> Fixes: 224041412693 ("nvme-multipath: revalidate zones for namespace heads")
> Reported-by: syzbot+b0910be96b7c31314822@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=b0910be96b7c31314822
> Reported-by: syzbot+2e02ccadb3c5522a5c59@syzkaller.appspotmail.com
> Closes: https://syzkaller.appspot.com/bug?extid=2e02ccadb3c5522a5c59
> Link: https://lore.kernel.org/all/2bfc96f2-7d0d-47e0-936e-8810abb31a9f@acm.org/
> Cc: Shuah Khan <shuah@kernel.org>
> Cc: Brigham Campbell <me@brighamcampbell.com>
> Signed-off-by: Palla Raghunath <raghunathpalla.0209@gmail.com>

Reviewed-by: Damien Le Moal <dlemoal@kernel.org>

-- 
Damien Le Moal
Western Digital Research

  reply	other threads:[~2026-09-30  7:46 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  6:26 Palla Raghunath
2026-09-30  7:45 ` Damien Le Moal [this message]
2026-09-30  9:36 ` Yao Sang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=da512295-e265-43eb-b44a-74bc7647acfa@kernel.org \
    --to=dlemoal@kernel.org \
    --cc=axboe@kernel.dk \
    --cc=hch@lst.de \
    --cc=kbusch@kernel.org \
    --cc=linux-kernel-mentees@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=me@brighamcampbell.com \
    --cc=raghunathpalla.0209@gmail.com \
    --cc=sagi@grimberg.me \
    --cc=sangyao@kylinos.cn \
    --cc=shuah@kernel.org \
    --cc=syzbot+2e02ccadb3c5522a5c59@syzkaller.appspotmail.com \
    --cc=syzbot+b0910be96b7c31314822@syzkaller.appspotmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®