The current devfreq downdifferential threshold of 5% causes overly
aggressive frequency downscaling, leading to performance degradation
sometimes during sequential read workloads.
Update the UFS devfreq downdifferential threshold to 65. This widens
the hysteresis window and prevents overly aggressive downscaling,
ensuring that frequency is maintained for loads above 5% and scaling
down occurs only when utilization falls below this level, while scale-up
still triggers above the 70% threshold.
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Nitin Rawat <nitin.rawat@oss.qualcomm.com>
Link: https://patch.msgid.link/20260825145203.265579-3-nitin.rawat@oss.qualcomm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The link startup mode (HS LSS - high-speed link startup, or LS LSS -
low-speed link startup) is decided in the boot stage based on the
bootconfig GPIO. This selection is carried forward through the secondary
stage bootloaders and finally to HLOS via the spare configuration
register (REG_UFS_DEBUG_SPARE_CFG).
On Qualcomm UFS controller v6.2 and later, bit 31 in the spare
configuration register indicates the high-speed link startup mode
selection, as per the Hardware Programming Guide (HPG).
The spare register value is read during host driver initialization but
gets cleared after UFS reset. Preserve the spare register value during
initialization and restore it during link startup to maintain the
bootloader-configured link startup mode.
Signed-off-by: Nitin Rawat <nitin.rawat@oss.qualcomm.com>
Tested-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://patch.msgid.link/20260825145203.265579-2-nitin.rawat@oss.qualcomm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Commit 249313b3f7 ("scsi: ibmvfc: allocate targets based on protocol")
added a protocol parameter to ibmvfc_alloc_target() but did not describe
it in the function's kernel-doc comment, so a W=1 build warns:
drivers/scsi/ibmvscsi/ibmvfc-core.c:4996: warning: Function parameter
or struct member 'protocol' not described in 'ibmvfc_alloc_target'
Add the missing parameter description.
Fixes: 249313b3f7 ("scsi: ibmvfc: allocate targets based on protocol")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608270829.lHI1FAdO-lkp@intel.com/
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
Reviewed-by: Dave Marquardt <davemarq@linux.ibm.com>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/b073968ae020b6ae0240e91341a92f428587ebd9.1787828961.git.falakreyaz@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Commit e0fca728a8 ("scsi: ibmvfc: delete NVMe/FC targets as well as
SCSI") renamed ibmvfc_relogin() to ibmvfc_scsi_relogin() but left the
kernel-doc comment referring to the old name, so a W=1 build warns:
drivers/scsi/ibmvscsi/ibmvfc-core.c:1901: warning: expecting prototype
for ibmvfc_relogin(). Prototype was for ibmvfc_scsi_relogin() instead
Update the kernel-doc comment to use the current function name.
Fixes: e0fca728a8 ("scsi: ibmvfc: delete NVMe/FC targets as well as SCSI")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608271026.iMLmrwz4-lkp@intel.com/
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
Reviewed-by: Dave Marquardt <davemarq@linux.ibm.com>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/dd866cf2321381694af027fbd726bcbd63ac3751.1787828961.git.falakreyaz@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
pm8001_request_msix() unwinds previously registered handlers with
free_irq() when request_irq() fails. The rollback loop uses the failing
index i for every iteration instead of the already registered vector
index j.
That passes the wrong IRQ/dev_id pair to free_irq() and leaves the
earlier handlers installed. Use j for both pci_irq_vector() and the
matching irq_vector entry in the rollback loop.
Fixes: a76037ff34 ("scsi: pm8001: switch to pci_irq_alloc_vectors")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Link: https://patch.msgid.link/20260824113618.2239100-1-runyu.xiao@seu.edu.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
nvfnic_add_lport() declares struct nvme_fc_port_info on the stack and
fills in four of its five members, leaving dev_loss_tmo holding whatever
the stack happened to contain before the call. The structure is then
handed to nvme_fc_register_localport().
nvfnic_add_tport(), which registers the remote port a few lines further
down, memsets its own struct nvme_fc_port_info first, so only the local
port path passes uninitialized data across the transport interface.
The NVMe/FC transport documents dev_loss_tmo as "Used only on a
remoteport" and does not read it in nvme_fc_register_localport(), so
there is no behavioural change today. Initialize the structure anyway:
the driver must not depend on which members the transport happens to
consume, and any member added to struct nvme_fc_port_info later would
silently start out as stack garbage.
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260819114242.3598034-2-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In snic_add_host(), if scsi_add_host() succeeds but
alloc_ordered_workqueue() fails, the function returns -ENOMEM with
shost->work_q left as NULL. The caller's error path then calls
snic_del_host(), which returns early when !shost->work_q without calling
scsi_remove_host(). The Scsi_Host remains registered in sysfs as a zombie
device even after the probe has failed. This causes:
- The leaked host remains visible in /sys/class/scsi_host/ after probe
failure, with state "running".
- Subsequent SCSI host numbering is permanently shifted (the leaked host
ID from ida_alloc() is never reclaimed).
- Memory leak: the Scsi_Host allocation can never be freed because
device_add() took a reference that can only be released by device_del()
inside scsi_remove_host().
Fix by adding scsi_remove_host() in the workqueue allocation failure path
inside snic_add_host(), undoing the successful scsi_add_host() before
returning the error. This is cleaner than modifying snic_del_host() because
snic_del_host() is called from a shared error label that also serves paths
where snic_add_host() was never invoked.
Reproducer (requires no real SNIC hardware):
- Build CONFIG_SCSI_SNIC=y (built-in)
- Add snic.test_mode=1 snic.inject_wq_fail=1 to kernel cmdline
- Boot with a PCI device matching the snic driver (e.g. QEMU edu device,
PCI ID 0x1234:0x11e8, temporarily added to the driver's PCI ID table)
Before the fix:
# /sys/class/scsi_host/ contains a zombie host0:
$ cat /sys/class/scsi_host/host0/proc_name
snic_scsi
$ cat /sys/class/scsi_host/host0/state
running
# ata_piix gets host1, host2 (host0 stuck):
scsi host1: ata_piix
scsi host2: ata_piix
After the fix:
# host0 is properly freed and reused by ata_piix:
scsi host0: ata_piix
scsi host1: ata_piix
# No zombie host in /sys/class/scsi_host/
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Acked-by: Narsimhulu Musini <nmusini@cisco.com>
Link: https://patch.msgid.link/20260727073438.209673-1-chenchangcheng@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The NCR5380 entry in MAINTAINERS includes drivers/scsi/arm/cumana_1.c and
drivers/scsi/arm/oak.c. However, those two files are also covered by the
drivers/scsi/arm/ pathname in the ARM/RISCPC entry.
The latter entry is more effective than the former because, AIUI, neither
Michael nor I have access to the necessary hardware. IMHO, such access is a
pre-requisite for the 'maintainer' role for device drivers.
To work on these particular drivers would require an old GCC compiler,
having support for -march=armv3m, which is a problem for contributors.
Cc: Michael Schmitz <schmitzmic@gmail.com>
Cc: Russell King <linux@armlinux.org.uk>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Finn Thain <fthain@linux-m68k.org>
Acked-by: Michael Schmitz <schmitzmic@gmail.com>
Link: https://patch.msgid.link/935b08c0fb292888c06c2233570331f2ccadcd53.1787014824.git.fthain@linux-m68k.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Replace the earlier LeapRAID ncq_cmd_prio_enable attribute with the
standard sas_ncq_prio_supported and sas_ncq_prio_enable names documented in
Documentation/ABI/testing/sysfs-block-device, and rename the per-device NCQ
priority state to match.
The earlier ncq_cmd_prio_enable name has not yet been established as part
of a released userspace ABI, so no compatibility alias is needed.
For LeapRAID, sas_ncq_prio_enable is backed by the driver's per-device NCQ
priority state and controls whether RT-class I/O requests are issued with
command priority on supported SATA devices.
Update leapraid.rst to describe the standard attribute names and paths, and
clean up the surrounding RST text for consistency with kernel documentation
style.
Also switch the capability check from open-coded VPD page 0x89 parsing to
sas_ata_ncq_prio_supported(), use kstrtobool() for the enable path, and
expose the NCQ priority attributes only for SATA devices using LeapRAID's
target-private SAS device state.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260814090526.395704-1-doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
leapraid_fw_log_exit() waits for mmap_refcnt to reach zero before it frees
the firmware log buffer. leapraid_fw_mmap() checks host_removing, but it
does not increment mmap_refcnt until after dma_mmap_coherent() succeeds and
the VMA open callback runs.
Removal can set host_removing and observe a zero mmap_refcnt between the
check and the VMA open. It can then free the coherent buffer while the
mmap path is still establishing a userspace mapping of it.
Claim a temporary mmap reference while looking up the adapter under
leapraid_adapter_lock. Removal deletes the adapter from the same locked
list after setting host_removing, so a mapping is either rejected or
included in the count that removal waits for. Drop the temporary reference
on the common exit path, after a successful VMA open has acquired the
reference covering the VMA lifetime.
Fixes: 5597088c9e ("scsi: leapraid: Add new SCSI driver")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/20260814033845.2971706-3-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
leapraid_fw_mmap() keeps the Scsi_Host reference obtained while looking up
the adapter for the lifetime of the initial VMA. The VMA close callback
drops that reference.
The open callback is also invoked when a VMA is duplicated or split, but it
only increments mmap_refcnt. Since every corresponding close callback
drops a host reference, cloning the mapping can release the host while
another VMA still refers to the adapter.
Take a host device reference for every VMA open and release the lookup
reference once the initial mapping has acquired its own reference. Use
get_device() because a VMA can be cloned after the host enters SHOST_DEL;
an existing VMA still pins the host at that point and open cannot fail.
Fixes: 5597088c9e ("scsi: leapraid: Add new SCSI driver")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/20260814033845.2971706-2-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The "evt_dat" variale is non-NULL at this point so there is no need to
check. Delete the check and pull the code in a tab.
Signed-off-by: Dan Carpenter <error27@gmail.com>
Reviewed-by: Paul Ely <paul.ely@broadcom.com>
Link: https://patch.msgid.link/an1trOAUeQmYEus_@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
This loop timeout with "retries" set to -1, not 0. Fix the test for
failure.
Fixes: 7ec0effd30 ("[SCSI] qla2xxx: Add support for ISP8044.")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/an1twcxTYSFkkUTA@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Negative -EIO was intended instead of positive EIO. The caller, doesn't
care so this doesn't affect runtime. It's just a cleanup.
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/an1taxANE_4_vzJT@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
After commit 696d1cc2aa ("scsi: ibmvfc: process NVMe/FC rports in work
thread"), clang warns (or errors with CONFIG_WERROR=y / W=e):
drivers/scsi/ibmvscsi/ibmvfc-core.c:6154:15: error: variable 'rport' is uninitialized when used here [-Werror,-Wuninitialized]
6154 | } else if (rport && tgt->action == IBMVFC_TGT_ACTION_DEL_AND_LOGOUT_RPORT) {
| ^~~~~
The check for rport is unnecessary in this block, it was accidentally
included from copying and pasting. Remove it to clear up the warning.
Fixes: 696d1cc2aa ("scsi: ibmvfc: process NVMe/FC rports in work thread")
Suggested-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://lore.kernel.org/6ccbe8c5-beb6-483f-bfa4-c2d3819ad5f2@linux.ibm.com/
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/20260817-ibmvscsi-rport-wuninitialized-v1-1-0fdfb27a5f01@kernel.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Enable compiler-based context analysis for drivers/scsi/hosts.c by setting
CONTEXT_ANALYSIS_hosts.o := y in drivers/scsi/Makefile.
The SCSI host management code in hosts.c now has the necessary lock context
annotations (such as __must_hold(shost->host_lock) on scsi_host_set_state)
and conforms to compile-time lock checking rules. It builds cleanly without
triggering any context analysis warnings.
Enable context analysis for hosts.o so that lock correctness and context
safety invariants for SCSI host operations are verified at compile time
when CONFIG_WARN_CONTEXT_ANALYSIS is enabled.
Fixes: fb0fc67db9 ("scsi: core: Enable context analysis")
Reported-by: John Garry <john.g.garry@oracle.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/3e1c3c0ca9307e2581cf4b96cf3fcdae35202255.1786724393.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Ian Bridges <icb@fastmail.org> says:
In preparation for removing the strlcat() API[1], this series replaces
its 81 remaining call sites in the lpfc driver. The sites live in nine
string building functions across five files, and each patch converts
one source file.
Functions that accumulate a variable number of fragments move to
seq_buf. The three sysfs show functions move to sysfs_emit_at(), the
designated helper for sysfs output. lpfc_vport_symbolic_node_name()
builds five fixed fragments and becomes a single scnprintf() call.
The intermediate tmp buffers and the per fragment overflow checks
become unnecessary in every scheme. Each loop that appends keeps one
overflow exit, so a full buffer stops the iteration.
One cross-cutting behavior change applies to several patches. The old
code formatted each fragment into a fixed size tmp buffer before
appending it, so a fragment longer than that buffer was silently
truncated even when the destination had room for it. The replacements
format each fragment directly into the destination. Truncation is
still bounded by the destination size. The per patch changelogs call
out the affected functions.
The patch series was tested as follows. No hardware testing was
done. Testing on real adapters is welcome.
- W=1 builds of the whole driver directory, zero warnings.
- A userspace differential harness. The old and new function bodies
are extracted verbatim from the two trees and compiled side by side
against the real lib/seq_buf.c. 472000 randomized cases across all
nine functions, including oversized inputs, undersized buffers and
prefilled destinations, compared byte for byte under ASan and
UBSan. All outputs are identical except two behavior changes.
Those are the format string interpretation removed in patch 1 and
the fragment cap removal in patch 2. The harness classifies every
observed difference as exactly one of those two.
- A KUnit corpus. The nine functions run as compiled kernel code in a
QEMU guest with KASAN, UBSAN and FORTIFY_SOURCE enabled, against
fabricated adapter state covering both branches of every converted
conditional that is compiled in. The LPFC_MXP_STAT debug block is
disabled at compile time and was build tested with the macro
defined. The same 40 test cases run on the unpatched base and
on this series. The base run matches the old expected outputs, and
the patched run is byte identical everywhere except the two
documented changes.
[1] https://github.com/KSPP/linux/issues/370
Link: https://patch.msgid.link/20260729144617.1388646-1-icb@fastmail.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_cmf_info_show(), lpfc_nvme_info_show() and lpfc_scsi_stat_show().
The three functions build sysfs attribute output, and sysfs_emit_at() is
the designated helper for that. The single write paths become
sysfs_emit(), the offset zero form of the same helper. Each intermediate
tmp buffer and its per fragment overflow check become unnecessary. Once
the page is full, sysfs_emit_at() writes nothing more, so dropping the
early exits does not change the produced bytes. Each loop that appends
keeps one exit, so a full page stops the iteration. In
lpfc_nvme_info_show() the exit also releases the fc_nodes_list_lock as
it did before. The unlock_buf_done label loses its last user and is
removed.
The old code capped every fragment at LPFC_MAX_INFO_TMP_LEN or
LPFC_MAX_SCSI_INFO_TMP_LEN bytes before appending it. The replacement
formats each fragment directly into the page, so a fragment longer than
its old tmp buffer is no longer truncated when the page has room for
it. Both macros lose their last user and are removed.
The running length that sysfs_emit_at() maintains equals the length that
the removed strnlen() calls computed, so the "Could be more info"
overflow markers keep their trigger condition.
Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-6-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_debugfs_multixripools_data(), lpfc_debugfs_scsistat_data() and
lpfc_debugfs_hdwqstat_data().
Each helper accumulates a variable number of lines into the debugfs
buffer, which is what seq_buf is for. The intermediate tmp buffers and
the per fragment overflow checks become unnecessary. Once a seq_buf
overflows, later writes to it do nothing, so dropping the early exits
does not change the produced bytes. Each loop that appends keeps one
seq_buf_has_overflowed() exit, so a full buffer stops the iteration.
lpfc_debugfs_multixripools_data() and lpfc_debugfs_hdwqstat_data()
append to whatever the buffer already holds, so their seq_buf is
anchored at the current end of the string. All three helpers keep
returning strnlen() because seq_buf_used() reports the full buffer size
after an overflow.
Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-5-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In preparation for removing the strlcat() API[1], replace its use in
lpfc_rx_monitor_report().
The function accumulates one line per ring entry, which is what seq_buf
is for. seq_buf tracks the write position, so the per entry strlen()
rescans of the destination are gone. Each record is still formatted into
the tmp buffer. seq_buf_puts() appends it only when it fits whole, so
the output keeps ending at the last complete record. The loop still
stops on overflow without consuming the current entry, and the returned
count and the ring head keep their old meaning. The produced bytes are
unchanged.
Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-4-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_vport_symbolic_node_name().
The function builds five unconditional fragments, so one scnprintf()
call composes the whole string. The intermediate tmp buffer and the per
fragment overflow checks become unnecessary. scnprintf() truncates at
the buffer size and returns the number of bytes it wrote, which equals
the length that the removed strnlen() call computed.
The old code capped every fragment at MAXHOSTNAMELEN bytes before
appending it, independently of the room left in the destination. The
replacement formats each fragment directly into the destination, so a
fragment longer than MAXHOSTNAMELEN is no longer truncated when the
destination has room for it.
Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-3-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_info().
The function accumulates a variable number of optional fragments, which
is what seq_buf is for. The intermediate tmp buffer and the per fragment
overflow checks become unnecessary. seq_buf is memory safe by
construction and silently truncates in the same way as the replaced
pattern.
The old code passed phba->ModelDesc as the format string of the first
scnprintf() call. The model description comes from adapter VPD data.
seq_buf_printf() takes a format string, so the replacement prints it
through "%s". A model description containing conversion specifiers is no
longer interpreted.
Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-2-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Bart Van Assche <bvanassche@acm.org> says:
Hi Martin,
This patch series enables context analysis for the SCSI core and the UFS
driver. The advantages are as follows:
- The compiler (only Clang) verifies whether the lock and unlock calls match
what has been declared via __must_hold(), __acquires() or __releases().
This is useful for catching locking bugs in error paths.
- Support for __guarded_by() is enabled. If a member variable is annotated
with __guarded_by(lock), the compiler will issue a warning if that member
variable is accessed without holding 'lock'.
Additionally, a patch is included that suppresses KCSAN complaints about SCSI
host state changes.
More information about lock context analysis is available in the cover letter of
[PATCH v5 00/36] Compiler-Based Context- and Locking-Analysis
(https://lore.kernel.org/lkml/20251219154418.3592607-1-elver@google.com/).
Please consider this patch series for the next merge window.
Thanks,
Bart.
Link: https://patch.msgid.link/cover.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
In the functions scsi_probe_and_add_lun(), scsi_sequential_lun_scan(),
scsi_report_lun_scan() and __scsi_scan_target() the SCSI host pointer is
derived from the SCSI target pointer. Pass the SCSI host pointer
directly.
This patch prepares for enabling context analysis. With this patch applied,
context annotations can refer to the SCSI host pointer directly, e.g.
__must_hold(&shost->scan_mutex). Without this patch, the following
annotation would have to be used:
__must_hold(&dev_to_shost(starget->dev.parent)->scan_mutex)
Additionally, in code that locks shost->scan_mutex, the following would
have to be added to help the compiler understand that shost ==
dev_to_shost(starget->dev.parent):
__assume_ctx_lock(&dev_to_shost(starget->dev.parent)->scan_mutex);
__assume_ctx_lock() statements should be avoided if there is a good
alternative. Hence this patch. No functionality has been changed.
Reviewed-by: John Garry <john.g.garry@oracle.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/49d2fc5fae5cb5dca2536818155581c73f39c883.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Annotate functions that modify the state of a synchronization object.
Remove the struct semaphore annotations because lock context annotations
are not supported for semaphores.
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/3c975386a5bcb939f8a2a0d47fd621f234321a9e.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Set the task state to TASK_UNINTERRUPTIBLE before calling
io_schedule_timeout() in ufshcd_wait_for_pending_cmds(). Without
setting the task state, io_schedule_timeout() returns immediately
because the task state remains TASK_RUNNING. This results in a busy loop
that wastes CPU cycles.
Fixes: 2000bc3097 ("scsi: ufs: core: Reduce the clock scaling latency")
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/8fe4526ce272811b28e99048b42358dd8f7c48af.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Introduce sas_dev_is_flutter() and sas_rediscover_ex_phy() to improve
flutter and device replace detection during rediscovery.
sas_dev_is_flutter() calls sas_ex_phy_discover() before looking up the
child device via sas_ex_phy_to_dev(), ensuring the PHY state is always
updated and avoiding use-after-free since the child device pointer is
obtained after the sleeping SMP request completes.
Add validation for linkrate and sas_addr changes. When the SAS address
changes, phy->attached_sas_addr is restored to the original address
before returning false, so sas_unregister_devs_sas_addr() can properly
match and unregister the old device. The sas_addr check is ordered
before the linkrate check to avoid skipping the restoration when both
change simultaneously.
sas_rediscover_ex_phy() uses the async discovery pattern
(sas_discover_event) instead of the synchronous sas_discover_new() to
ensure proper ordering between device unregistration and rediscovery,
avoiding sysfs_warn_dup() errors.
Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Suggested-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260811040334.4184911-3-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Add sas_ex_phy_to_dev() to return any device type attached to an
expander phy, and refactor sas_ex_to_ata() to use it.
No functional changes intended.
Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260811040334.4184911-2-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
_base_release_memory_pools() unconditionally frees every
ioc->pcie_sg_lookup[] entry, including ones the setup loop never
allocated after a partial failure, causing a "bad dma" warning on debug
kernels or a NULL pointer dereference otherwise.
Fixes: dbec4c9040 ("scsi: mpt3sas: lockless command submission")
Reported-by: Laurence Oberman <loberman@redhat.com>
Signed-off-by: Chandrakanth Patil <chandrakanth.patil@broadcom.com>
Link: https://patch.msgid.link/20260808151010.185603-1-chandrakanth.patil@broadcom.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
After commit c3930ec119 ("scsi: qla2xxx: Add FC operational firmware
load for 29xx"), there is a warning due to an incorrect format specifier
for a 'size_t' variable when building for 32-bit platforms, for which
'size_t' is 'unsigned int':
drivers/scsi/qla2xxx/qla_init.c: In function 'qla29xx_process_rd_image':
drivers/scsi/qla2xxx/qla_init.c:9272:74: error: format '%lx' expects argument of type 'long unsigned int', but argument 6 has type 'size_t' {aka 'unsigned int'} [-Werror=format=]
9272 | "TIM section too large (0x%x bytes, ring 0x%lx bytes).\n",
| ~~^
| |
| long unsigned int
| %x
9273 | section_size,
9274 | req->length * qla_req_entry_size(ha));
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| |
| size_t {aka unsigned int}
cc1: all warnings being treated as errors
Use '%zx', the proper 'size_t' format specifier, to clear up the
warning.
Fixes: c3930ec119 ("scsi: qla2xxx: Add FC operational firmware load for 29xx")
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260811-scsi-qla2xxxx-qla_init-wformat-v1-1-50760021914f@kernel.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The fnic NVMe/FC code is guarded with IS_ENABLED(CONFIG_NVME_FC). That
also evaluates true when NVME_FC is built as a module.
When fnic is built into vmlinux and NVME_FC=m, fnic_nvme.o still
references the NVMe/FC transport helpers even though those helpers are
not reachable from built-in code. The final vmlinux link then fails with
undefined nvme_fc_* symbols.
Use IS_REACHABLE(CONFIG_NVME_FC) for the fnic NVMe/FC implementation and
prototypes so built-in fnic uses the disabled stubs unless the NVMe/FC
transport is reachable.
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608092246.XZe7Hlrt-lkp@intel.com/
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260810110627.4521-1-kartilak@cisco.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The current comparison err != ERR_ECMDUNKNOWN is useless because err < 0
and ERR_ECMDUNKNOWN == 5. The logic is that if the CMD_CAPABILITY
command was executed, there is no need to respond to unknown errors.
Therefore, the sign of the number in the comparison must be changed.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260807091852.13151-1-roman.demidov.nn@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
During fuzz testing, the following issue was discovered:
BUG: KMSAN: uninit-value in __dma_map_sg_attrs+0x217/0x310
__dma_map_sg_attrs+0x217/0x310
dma_map_sg_attrs+0x4a/0x70
ata_qc_issue+0x9f8/0x1420
__ata_scsi_queuecmd+0x1657/0x1740
ata_scsi_queuecmd+0x79a/0x920
scsi_queue_rq+0x4472/0x4f40
blk_mq_dispatch_rq_list+0x1cca/0x3ee0
__blk_mq_sched_dispatch_requests+0x458/0x630
blk_mq_sched_dispatch_requests+0x15b/0x340
__blk_mq_run_hw_queue+0xe5/0x250
__blk_mq_delay_run_hw_queue+0x138/0x780
blk_mq_run_hw_queue+0x4bb/0x7e0
blk_mq_sched_insert_request+0x2a7/0x4c0
blk_execute_rq+0x497/0x8a0
sg_io+0xbe0/0xe20
scsi_ioctl+0x2b36/0x3c60
sr_block_ioctl+0x319/0x440
blkdev_ioctl+0x80f/0xd70
__se_sys_ioctl+0x219/0x420
__x64_sys_ioctl+0x93/0xe0
x64_sys_call+0x1d6c/0x3ad0
do_syscall_64+0x4c/0xa0
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Uninit was created at:
__alloc_pages+0x5c0/0xc80
alloc_pages+0xe0e/0x1050
blk_rq_map_user_iov+0x2b77/0x6100
blk_rq_map_user_io+0x2fa/0x4d0
sg_io+0xad6/0xe20
scsi_ioctl+0x2b36/0x3c60
sr_block_ioctl+0x319/0x440
blkdev_ioctl+0x80f/0xd70
__se_sys_ioctl+0x219/0x420
__x64_sys_ioctl+0x93/0xe0
x64_sys_call+0x1d6c/0x3ad0
do_syscall_64+0x4c/0xa0
entry_SYSCALL_64_after_hwframe+0x6e/0xd8
Bytes 14-15 of 16 are uninitialized
Memory access of size 16 starts at ffff88800cbdb000
When processing the last unaligned element of the scatterlist, it is
supplemented with missing bytes in the amount of pad_len. These bytes
remain uninitialized, which leads to a problem.
Extend last_sg->length by pad_len first, then use sg_zero_buffer() to
zero those pad_len bytes. sg_zero_buffer() uses sg_miter internally,
which correctly handles sg entries spanning multiple pages and padding
that crosses a page boundary.
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Fixes: 40b01b9bbd ("block: update bio according to DMA alignment padding")
Cc: stable@vger.kernel.org
Signed-off-by: Petr Vaganov <p.vaganov@ideco.ru>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260628185229.37957-1-p.vaganov@ideco.ru
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Heiko Carstens <hca@linux.ibm.com> says:
Enable CONTEXT_ANALYSYS for the zfcp driver.
Static code checking for acquiring and releasing locks used to be done
with sparse. That was removed with [1] and replaced with a clang based
approach [2]. The new approach requires that each subsystem needs to
be explicitly enabled for checking.
Do that for drivers/s390/scsi. Add a __must_hold() attribute to
zfcp_qdio_sbal_get() to address the only valid warning. Then enable
CONTEXT_ANALYSIS, similar to other patches for drivers/s390 I'm
currently working on.
Link: https://patch.msgid.link/20260806134759.2122369-1-hca@linux.ibm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Add __must_hold() attribute to zfcp_qdio_sbal_get() in order to let
clang's context analysis know that qdio->req_q_wq must be held on
function entry. This is also documented above the function. Without this
annotation this leads to a valid warning when context analysis is
enabled:
drivers/s390/scsi/zfcp_qdio.c:287:8: warning:
expecting spinlock '->req_q_lock' to be held at start of each loop [-Wthread-safety-analysis]
287 | ret = wait_event_interruptible_lock_irq_timeout(qdio->req_q_wq,
| ^
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Link: https://patch.msgid.link/20260806134759.2122369-2-hca@linux.ibm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with
kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via
spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this
atomic context and can trigger a sleeping-from-invalid-context warning
or deadlock.
Pass GFP_ATOMIC so the allocation is safe under the IRQ-safe spinlock.
Fixes: 098585aa8a ("scsi: fnic: Add and integrate support for FIP")
Cc: stable@vger.kernel.org
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260731073820.16449-1-gonglinkai@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The Fibre Channel transport topology created by storvsc exposes only one
dummy remote port per SCSI host. Its scsi_target_id is always zero.
As a result, the FC transport user-scan path looks up the remote port
using target ID 0. It cannot initiate a scan for Target 1 or higher. No
SCSI command is therefore sent to Hyper-V when userspace explicitly
requests a scan of one of these targets.
storvsc itself supports up to STORVSC_FC_MAX_TARGETS and already passes
scmnd->device->id to Hyper-V as vm_srb->target_id. Devices on Target 1
and higher work when initially discovered. They can also be rediscovered
by a full host scan, such as the scan triggered after an FC port bounce.
Provide a storvsc-specific user_scan callback that uses the exported
scsi_scan_target() interface. Iterate over the requested channel and
target ranges so that wildcard and explicitly addressed scans retain the
expected SCSI sysfs scan semantics.
This bypasses the single-rport lookup in fc_user_scan() and allows
userspace to explicitly scan any target supported by storvsc without
requiring one synthetic fc_rport for every Hyper-V target.
Signed-off-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260723163743.1274830-1-loberman@redhat.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Only enter the sense_key switch when the command returned CHECK
CONDITION with valid, non-deferred sense. The old condition let deferred
or invalid sense fall through and mis-handle the I/O.
Fixes: 03aba2f795 ("[SCSI] sd/scsi_lib simplify sd_rw_intr and scsi_io_completion")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260707030333.22245-4-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
sd_set_special_bvec() allocates a special payload page for UNMAP and
WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in
sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI
midlayer does not call uninit_command() because RQF_DONTPREP is not set
yet, leaking the page.
Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after
freeing the page.
Fixes: 81d926e8b5 ("sd: split sd_setup_discard_cmnd")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260707030333.22245-3-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
After device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create()
failure must unregister disk_dev and let scsi_disk_release() free
sdkp. Going through out_free_index kfree()s an already registered device
and leaks the sysfs entry.
Fixes: 7179e626b7 ("scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260707030333.22245-2-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Dongdong Hao <doubled@leap-io-kernel.com> says:
This series adds the LeapRAID driver and its documentation.
This version addresses issues reported by Sashiko and the kernel test
robot, as well as issues identified through internal testing. Because
[PATCH v4 1/2] exceeded the line-count limit of the public Sashiko
service, it was not analyzed. We therefore deployed Sashiko locally
with an increased line-count limit to complete the analysis and have
fixed all identified issues.
Link: https://patch.msgid.link/cover.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
This patch adds the necessary documentation for the LeapRAID SCSI driver
to the kernel's documentation tree.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/6dc9239844dc00cd053ea0649cc9fe05cad1d98a.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
The LeapRAID driver provides support for LeapRAID PCIe RAID controllers,
enabling communication between the host operating system, firmware, and
hardware for efficient storage management.
The driver is organized into several logical modules, each with a clear
responsibility:
leapraid_os.c: Integrates with the Linux SCSI subsystem, handling host
template callbacks, PCIe device probing, and initialization.
leapraid_func.c: Contains low-level routines for firmware/hardware
interaction, interrupt handling, and reset logic.
leapraid_app.c: Provides the ioctl interface for user-space tools.
leapraid_transport.c: Manages interactions with the SCSI transport
layer for SAS PHYs and ports.
leapraid_func.h: Contains internal definitions shared among driver
modules.
leapraid.h: Contains low-level hardware definitions for
driver/firmware interaction.
The leapraid_probe() function orchestrates the setup: it allocates the
adapter structure and SCSI host, configures hardware interfaces, and
registers it with the SCSI mid-layer. Following registration,
scsi_scan_host() is invoked to initiate device discovery, with firmware
reporting devices via interrupt-driven events.
This initial commit provides the necessary infrastructure for
subsequent development of full I/O path handling, error recovery,
and advanced management features.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/0cbc6245aabdc6e8c90587675e76ba316c5b549e.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>