mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: yangxingui <yangxingui@huawei.com>
To: Jason Yan <yanaijie@huawei.com>, <john.g.garry@oracle.com>,
	<jejb@linux.ibm.com>, <martin.petersen@oracle.com>
Cc: <linux-scsi@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
	<linuxarm@huawei.com>, <liyihang9@h-partners.com>,
	<liuyonglong@huawei.com>, <kangfenglong@huawei.com>
Subject: Re: [PATCH v8 2/2] scsi: libsas: Add linkrate and sas_addr change detection in rediscover
Date: Wed, 24 Jun 2026 14:16:14 +0800	[thread overview]
Message-ID: <f4c98a27-b9ae-e838-7320-9d307bacd23d@huawei.com> (raw)
In-Reply-To: <fabfd6ed-ccfa-4a2e-ad91-3598751615ca@huawei.com>

Hi Jason,

Thanks for the review.

On 2026/6/23 16:52, Jason Yan wrote:
> 在 2026/6/23 10:43, Xingui Yang 写道:
>> Introduce sas_dev_is_flutter() and sas_rediscover_ex_phy() to improve
>> flutter and device replace detection during rediscovery.
>>
>> sas_dev_is_flutter() adds validation for linkrate and sas_addr changes.
>> When the SAS address changes, it restores phy->attached_sas_addr back to
>> the original address before returning false, ensuring
>> sas_unregister_devs_sas_addr() can properly match and unregister the old
>> device via sas_phy_match_dev_addr().
>>
>> The sas_addr check is ordered before the linkrate check to ensure the
>> address restoration is not skipped when both change simultaneously.
>>
>> Hold a kref on child_dev across the sas_ex_phy_discover() call to
>> prevent use-after-free, since sas_ex_phy_discover() sends an SMP
>> request which can sleep, during which the device could be freed by
>> a concurrent removal path.
>>
>> sas_rediscover_ex_phy() uses the async discovery pattern
>> (sas_discover_event) instead of the synchronous sas_discover_new() to
>> ensure proper ordering between device unregistration and rediscovery,
>> avoiding sysfs_warn_dup() errors.
>>
>> Signed-off-by: Xingui Yang <yangxingui@huawei.com>
>> ---
>>   drivers/scsi/libsas/sas_expander.c | 89 +++++++++++++++++++++++++-----
>>   1 file changed, 75 insertions(+), 14 deletions(-)
>>
>> diff --git a/drivers/scsi/libsas/sas_expander.c 
>> b/drivers/scsi/libsas/sas_expander.c
>> index cb9d3b748222..63d033e78985 100644
>> --- a/drivers/scsi/libsas/sas_expander.c
>> +++ b/drivers/scsi/libsas/sas_expander.c
>> @@ -1966,6 +1966,78 @@ static bool dev_type_flutter(enum 
>> sas_device_type new, enum sas_device_type old)
>>       return false;
>>   }
>> +static void sas_rediscover_ex_phy(struct domain_device *dev, int phy_id,
>> +                  bool last)
>> +{
>> +    struct expander_device *ex = &dev->ex_dev;
>> +    struct ex_phy *phy = &ex->ex_phy[phy_id];
>> +
>> +    phy->phy_change_count = -1;
>> +    ex->ex_change_count = -1;
>> +    sas_unregister_devs_sas_addr(dev, phy_id, last);
>> +    sas_discover_event(dev->port, DISCE_REVALIDATE_DOMAIN);
>> +}
>> +
>> +static bool sas_dev_is_flutter(struct domain_device *dev, int phy_id,
>> +                   u8 *sas_addr, enum sas_device_type type)
>> +{
>> +    struct expander_device *ex = &dev->ex_dev;
>> +    struct ex_phy *phy = &ex->ex_phy[phy_id];
>> +    struct domain_device *child_dev = NULL;
>> +    char *action = "";
>> +    int res;
>> +
>> +    if (SAS_ADDR(sas_addr) != SAS_ADDR(phy->attached_sas_addr) ||
>> +        !dev_type_flutter(type, phy->attached_dev_type))
>> +        return false;
>> +
>> +    child_dev = sas_ex_to_dev(dev, phy_id);
>> +    if (!child_dev)
>> +        goto out;
>> +
>> +    kref_get(&child_dev->kref);
> 
> This is not necessary so I think you can remove it as domain device will 
> never release here sine we are in the discover workqueue process.
> It's ture that sas_find_dev_by_rphy() is not perfect. It shall get a 
> reference after lock ->dev_list_lock. But this will affect many existing 
> users. We can do that in another patchset.

Agreed. In v9 I have removed the kref_get/sas_put_device pattern
entirely. Instead, sas_ex_phy_discover() is now called before
sas_ex_to_dev(), so the child device pointer is obtained after the
sleeping SMP request completes. This eliminates the UAF concern
without needing a kref, since we are serialized by disco_mutex in
the discover workqueue.

The sas_find_dev_by_rphy() reference counting improvement is noted
as a separate patchset as you suggested.

Thanks,
Xingui

      reply	other threads:[~2026-06-24  6:16 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-23  2:43 [PATCH v8 0/2] libsas: rediscover improvements for linkrate/sas_addr changes Xingui Yang
2026-06-23  2:43 ` [PATCH v8 1/2] scsi: libsas: refactor sas_ex_to_ata() using new helper sas_ex_to_dev() Xingui Yang
2026-06-23  2:43 ` [PATCH v8 2/2] scsi: libsas: Add linkrate and sas_addr change detection in rediscover Xingui Yang
2026-06-23  8:52   ` Jason Yan
2026-06-24  6:16     ` yangxingui [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f4c98a27-b9ae-e838-7320-9d307bacd23d@huawei.com \
    --to=yangxingui@huawei.com \
    --cc=jejb@linux.ibm.com \
    --cc=john.g.garry@oracle.com \
    --cc=kangfenglong@huawei.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linuxarm@huawei.com \
    --cc=liuyonglong@huawei.com \
    --cc=liyihang9@h-partners.com \
    --cc=martin.petersen@oracle.com \
    --cc=yanaijie@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®