Re: [RFC PATCH] nvme: refuse an unsolicited format change on a namespace that is in use

Keith Busch <[email protected]>
Newsgroups org.kernel.vger.linux-block,org.infradead.lists.linux-nvme,org.kernel.vger.linux-kernel
Message-ID <ant4bioGLl4B35n_@kbusch-mbp>
On Tue, Aug 11, 2026 at 03:21:11PM -0400, Chao Shi wrote:
> @@ -2436,6 +2454,28 @@ static int nvme_update_ns_info_block(struct nvme_ns *ns,
>  		goto out;
>  	}
>  
> +	/*
> +	 * Changing the LBA format or the metadata size reinterprets everything
> +	 * the host has already cached, queued or handed to the integrity code
> +	 * for this namespace, and freezing the queue does not cover any of it:
> +	 * page cache contents, bios batched on a plug and the deferred
> +	 * integrity verify work all outlive the freeze.  If such a change
> +	 * arrives unsolicited while the namespace is in use, refuse it and let
> +	 * the caller take the namespace offline rather than adopt a geometry
> +	 * that describes something else than what the host is holding.
> +	 */
> +	if (nvme_ns_openers(ns) &&
> +	    !test_bit(NVME_CTRL_SELF_RESCAN, &ns->ctrl->flags) &&
> +	    (ns->head->lba_shift != id->lbaf[lbaf].ds ||
> +	     ns->head->ms != le16_to_cpu(id->lbaf[lbaf].ms))) {
> +		dev_err(ns->ctrl->device,
> +			"unsolicited format change on in-use nsid %u (lba_shift %u -> %u, ms %u -> %u)\n",
> +			info->nsid, ns->head->lba_shift, id->lbaf[lbaf].ds,
> +			ns->head->ms, le16_to_cpu(id->lbaf[lbaf].ms));
> +		ret = NVME_SC_INVALID_NS | NVME_STATUS_DNR;
> +		goto out;
> +	}

Refusing to acknowledge the new format doesn't mean you get to continue
using the old format. You're going to corrupt memory and data this way.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.