2008-12-16 20:17:18

by scameron

[permalink] [raw]
Subject: [patch] cciss: Fix problem that deleting multiple logical drives could cause a panic


Fix problem that deleting multiple logical drives could cause a panic.

Signed-off-by: Stephen M. Cameron <[email protected]>
---

drivers/block/cciss.c | 5 +++++
1 file changed, 5 insertions(+)

diff -puN drivers/block/cciss.c~fix_rebuild_lun_table_bug drivers/block/cciss.c
--- linux-2.6.28-rc8/drivers/block/cciss.c~fix_rebuild_lun_table_bug 2008-12-16 14:00:52.000000000 -0600
+++ linux-2.6.28-rc8-root/drivers/block/cciss.c 2008-12-16 14:00:52.000000000 -0600
@@ -1693,6 +1693,11 @@ static int rebuild_lun_table(ctlr_info_t
for (i = 0; i <= h->highest_lun; i++) {
int j;
drv_found = 0;
+
+ /* skip holes in the array from already deleted drives */
+ if (h->drv[i].raid_level == -1)
+ continue;
+
for (j = 0; j < num_luns; j++) {
memcpy(&lunid, &ld_buff->LUN[j][0], 4);
lunid = le32_to_cpu(lunid);
_


2008-12-16 20:28:24

by Jens Axboe

[permalink] [raw]
Subject: Re: [patch] cciss: Fix problem that deleting multiple logical drives could cause a panic

On Tue, Dec 16 2008, [email protected] wrote:
>
> Fix problem that deleting multiple logical drives could cause a panic.

This looks like a 2.6.28 candidate, correct?

>
> Signed-off-by: Stephen M. Cameron <[email protected]>
> ---
>
> drivers/block/cciss.c | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff -puN drivers/block/cciss.c~fix_rebuild_lun_table_bug drivers/block/cciss.c
> --- linux-2.6.28-rc8/drivers/block/cciss.c~fix_rebuild_lun_table_bug 2008-12-16 14:00:52.000000000 -0600
> +++ linux-2.6.28-rc8-root/drivers/block/cciss.c 2008-12-16 14:00:52.000000000 -0600
> @@ -1693,6 +1693,11 @@ static int rebuild_lun_table(ctlr_info_t
> for (i = 0; i <= h->highest_lun; i++) {
> int j;
> drv_found = 0;
> +
> + /* skip holes in the array from already deleted drives */
> + if (h->drv[i].raid_level == -1)
> + continue;
> +
> for (j = 0; j < num_luns; j++) {
> memcpy(&lunid, &ld_buff->LUN[j][0], 4);
> lunid = le32_to_cpu(lunid);
> _

--
Jens Axboe

2008-12-16 20:49:55

by scameron

[permalink] [raw]
Subject: Re: [patch] cciss: Fix problem that deleting multiple logical drives could cause a panic

On Tue, Dec 16, 2008 at 09:27:30PM +0100, Jens Axboe wrote:
> On Tue, Dec 16 2008, [email protected] wrote:
> >
> > Fix problem that deleting multiple logical drives could cause a panic.
>
> This looks like a 2.6.28 candidate, correct?

Yes, and we would like to get it in anywhere else it needs to go
(backport to 2.6.27.x? if that makes sense.)

It fixes a panic which can be easily reproduced in the following
way: Just create several "arrays," each with multiple logical
drives via hpacucli, then delete the first array, and it will blow
up in deregister_disk(), in the call to get_host() when it tries to
dig the hba pointer out of a NULL queue pointer.

The problem has been present since my code to make
rebuild_lun_table behave better went in.

-- steve

>
> >
> > Signed-off-by: Stephen M. Cameron <[email protected]>
> > ---
> >
> > drivers/block/cciss.c | 5 +++++
> > 1 file changed, 5 insertions(+)
> >
> > diff -puN drivers/block/cciss.c~fix_rebuild_lun_table_bug drivers/block/cciss.c
> > --- linux-2.6.28-rc8/drivers/block/cciss.c~fix_rebuild_lun_table_bug 2008-12-16 14:00:52.000000000 -0600
> > +++ linux-2.6.28-rc8-root/drivers/block/cciss.c 2008-12-16 14:00:52.000000000 -0600
> > @@ -1693,6 +1693,11 @@ static int rebuild_lun_table(ctlr_info_t
> > for (i = 0; i <= h->highest_lun; i++) {
> > int j;
> > drv_found = 0;
> > +
> > + /* skip holes in the array from already deleted drives */
> > + if (h->drv[i].raid_level == -1)
> > + continue;
> > +
> > for (j = 0; j < num_luns; j++) {
> > memcpy(&lunid, &ld_buff->LUN[j][0], 4);
> > lunid = le32_to_cpu(lunid);
> > _
>
> --
> Jens Axboe
>

2008-12-18 13:58:05

by Jens Axboe

[permalink] [raw]
Subject: Re: [patch] cciss: Fix problem that deleting multiple logical drives could cause a panic

On Tue, Dec 16 2008, [email protected] wrote:
> On Tue, Dec 16, 2008 at 09:27:30PM +0100, Jens Axboe wrote:
> > On Tue, Dec 16 2008, [email protected] wrote:
> > >
> > > Fix problem that deleting multiple logical drives could cause a panic.
> >
> > This looks like a 2.6.28 candidate, correct?
>
> Yes, and we would like to get it in anywhere else it needs to go
> (backport to 2.6.27.x? if that makes sense.)
>
> It fixes a panic which can be easily reproduced in the following
> way: Just create several "arrays," each with multiple logical
> drives via hpacucli, then delete the first array, and it will blow
> up in deregister_disk(), in the call to get_host() when it tries to
> dig the hba pointer out of a NULL queue pointer.
>
> The problem has been present since my code to make
> rebuild_lun_table behave better went in.

OK, I'll make sure it goes upstream for 2.6.28. I've merged your other
cciss patch for 2.6.29.

--
Jens Axboe