Re: [PATCH v2] md: suspend array while updating raid_disks via sysfs
"Yu Kuai" <[email protected]>
| Newsgroups | gmane.linux.raid,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
在 2025/12/26 18:18, dannyshih 写道: > From: FengWei Shih<[email protected]> > > In raid1_reshape(), freeze_array() is called before modifying the r1bio > memory pool (conf->r1bio_pool) and conf->raid_disks, and > unfreeze_array() is called after the update is completed. > > However, freeze_array() only waits until nr_sync_pending and > (nr_pending - nr_queued) of all buckets reaches zero. When an I/O error > occurs, nr_queued is increased and the corresponding r1bio is queued to > either retry_list or bio_end_io_list. As a result, freeze_array() may > unblock before these r1bios are released. > > This can lead to a situation where conf->raid_disks and the mempool have > already been updated while queued r1bios, allocated with the old > raid_disks value, are later released. Consequently, free_r1bio() may > access memory out of bounds in put_all_bios() and release r1bios of the > wrong size to the new mempool, potentially causing issues with the > mempool as well. > > Since only normal I/O might increase nr_queued while an I/O error occurs, > suspending the array avoids this issue. > > Note: Updating raid_disks via ioctl SET_ARRAY_INFO already suspends > the array. Therefore, we suspend the array when updating raid_disks > via sysfs to avoid this issue too. > > Signed-off-by: FengWei Shih<[email protected]> > --- > v2: > * Suspend array unconditionally when updating raid_disks > * Refine commit message to describe the issue more concretely > --- > drivers/md/md.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) Applied to md-6.19 -- Thansk, Kuai