Received: by 2002:a05:6358:45e:b0:b5:b6eb:e1f9 with SMTP id 30csp726806rwe; Wed, 31 Aug 2022 09:56:19 -0700 (PDT) X-Google-Smtp-Source: AA6agR5+tMljfxM+s9nmzk7fb9abbH1YCEHkqLGl95djpHNvv5V1PprNchioWnmpgLRdH0khKU9D X-Received: by 2002:a05:6402:d05:b0:425:b7ab:776e with SMTP id eb5-20020a0564020d0500b00425b7ab776emr26498292edb.142.1661964979116; Wed, 31 Aug 2022 09:56:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1661964979; cv=none; d=google.com; s=arc-20160816; b=FGcRSV/xSxYrWp7u0QZyxediwhtyfW3A7fFjcAMNHznINRj7h8tbGkKwvmL8d9R6Za iawe7WRiYkife1mEhXO2X9FGeCXtl6oeGsyRAWNM25epVj3BQ2AWwmdWek+NX9eGFe08 eeVCFApiSUNaPL0yAAOwlNWgwoY3LF6uXMWPkhVDndLhCEsHn/PlmqR4SKKdTDzOCUw3 Ok94HlWW5JN0pr0sRe8MfFsVTVf0xLOv+dXjZYXMAB+ZLUQSX9SaO6/Va4BVtqM7rL+i Ya73qYj2I9h1YJLVG88LNtSYsK25gt3XALPQEiw9UGGHhQ2d3W1iN7f20vkJ0Vf/qi3l pG3Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=A52U/PT4v++kcU8dd6hg/ZJ9qlo+0UfZAv87/XSSAw8=; b=cO5x8469QaFyQGydo3rNDOPUKMcHojNyJ/Co4zTGhj1eBKQEYmeeFVnYSzYz/MaIt+ 1Qs/A6FOKsJj4d2eVTPZxJzFFwUiIYMy+G7GFPCrq6UVTeuYl5SF3/HErnABmL6Hlxi2 xyzK1+QS4uXD8v23xssLdaqaW3WyFKACaRkkUdx3f9MJ61zLhAy84/Gxe8WxwnCq28ya iejdAbuITyQSFkWGlFO3oaveujs1KsxNj13qhg84Fe1mIRQ91Vrs1HURLnI30l0qLXXV xTiLcSSP0H20j0NdTZxQfh7IFGCT/guybfKtpIih3NCMcawMfk8s7DmFDGSJ28dD9b2N +ROw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=alibaba.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id gs36-20020a1709072d2400b0073da6628a3csi11362966ejc.805.2022.08.31.09.55.52; Wed, 31 Aug 2022 09:56:19 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=alibaba.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230310AbiHaPyK (ORCPT + 99 others); Wed, 31 Aug 2022 11:54:10 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:37172 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231249AbiHaPx4 (ORCPT ); Wed, 31 Aug 2022 11:53:56 -0400 Received: from out30-57.freemail.mail.aliyun.com (out30-57.freemail.mail.aliyun.com [115.124.30.57]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C818DAE231; Wed, 31 Aug 2022 08:53:54 -0700 (PDT) X-Alimail-AntiSpam: AC=PASS;BC=-1|-1;BR=01201311R181e4;CH=green;DM=||false|;DS=||;FP=0|-1|-1|-1|0|-1|-1|-1;HT=ay29a033018046059;MF=ziyangzhang@linux.alibaba.com;NM=1;PH=DS;RN=7;SR=0;TI=SMTPD_---0VNrdntv_1661961162; Received: from localhost.localdomain(mailfrom:ZiyangZhang@linux.alibaba.com fp:SMTPD_---0VNrdntv_1661961162) by smtp.aliyun-inc.com; Wed, 31 Aug 2022 23:53:49 +0800 From: ZiyangZhang To: ming.lei@redhat.com, axboe@kernel.dk Cc: xiaoguang.wang@linux.alibaba.com, linux-block@vger.kernel.org, linux-kernel@vger.kernel.org, joseph.qi@linux.alibaba.com, ZiyangZhang Subject: [RFC PATCH V2 2/6] ublk_drv: refactor ublk_cancel_queue() Date: Wed, 31 Aug 2022 23:51:32 +0800 Message-Id: <20220831155136.23434-3-ZiyangZhang@linux.alibaba.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20220831155136.23434-1-ZiyangZhang@linux.alibaba.com> References: <20220831155136.23434-1-ZiyangZhang@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-9.9 required=5.0 tests=BAYES_00, ENV_AND_HDR_SPF_MATCH,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE,UNPARSEABLE_RELAY,USER_IN_DEF_SPF_WL autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Assume only a few FETCH_REQ ioucmds are sent to ublk_drv, then the ubq_daemon exits, We have to call io_uring_cmd_done() for all ioucmds received so that io_uring ctx will not leak. ublk_cancel_queue() may be called before START_DEV or after STOP_DEV, we decrease ubq->nr_io_ready and clear UBLK_IO_FLAG_ACTIVE so that we won't call io_uring_cmd_done() twice for one ioucmd to avoid UAF. Also clearing UBLK_IO_FLAG_ACTIVE makes the code more reasonable. Signed-off-by: ZiyangZhang --- drivers/block/ublk_drv.c | 23 ++++++++++++++++++++--- 1 file changed, 20 insertions(+), 3 deletions(-) diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c index c39b67d7133d..0c6db0978ed0 100644 --- a/drivers/block/ublk_drv.c +++ b/drivers/block/ublk_drv.c @@ -963,22 +963,39 @@ static inline bool ublk_queue_ready(struct ublk_queue *ubq) return ubq->nr_io_ready == ubq->q_depth; } +/* If ublk_cancel_queue() is called before sending START_DEV(), ->mutex + * provides protection on above update. + * + * If ublk_cancel_queue() is called after sending START_DEV(), disk is + * deleted first, UBLK_IO_RES_ABORT is returned so that any new io + * command can't be issued to driver, so updating on io flags and + * nr_io_ready is safe here. + * + * Also ->nr_io_ready is guaranteed to become zero after ublk_cance_queue() + * returns since request queue is either frozen or not present in both two + * cases. + */ static void ublk_cancel_queue(struct ublk_queue *ubq) { int i; - if (!ublk_queue_ready(ubq)) + if (!ubq->nr_io_ready) return; for (i = 0; i < ubq->q_depth; i++) { struct ublk_io *io = &ubq->ios[i]; - if (io->flags & UBLK_IO_FLAG_ACTIVE) + if (io->flags & UBLK_IO_FLAG_ACTIVE) { + pr_devel("%s: done old cmd: qid %d tag %d\n", + __func__, ubq->q_id, i); io_uring_cmd_done(io->cmd, UBLK_IO_RES_ABORT, 0); + io->flags &= ~UBLK_IO_FLAG_ACTIVE; + ubq->nr_io_ready--; + } } /* all io commands are canceled */ - ubq->nr_io_ready = 0; + WARN_ON_ONCE(ubq->nr_io_ready); } /* Cancel all pending commands, must be called after del_gendisk() returns */ -- 2.27.0