Skip to content

Volume destroy data race - #933

Merged
nnastonen merged 1 commit into
eBay:dev/v8.xfrom
nnastonen:SDSTOR-25815_volume_dstroy_data_race_bug
Oct 2, 2026
Merged

nnastonen merged 1 commit into
eBay:dev/v8.xfrom
nnastonen:SDSTOR-25815_volume_dstroy_data_race_bug

Conversation

@nnastonen

@nnastonen nnastonen commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

After volume destroy, the device is still in m_rd_map. A CP that fires in that window calls cp_flush on a device whose superblock is gone, and that null dereference causes the crash.

https://jirap.corp.ebay.com/browse/SDSTOR-25815

@nnastonen
nnastonen force-pushed the SDSTOR-25815_volume_dstroy_data_race_bug branch from 55cae52 to 8a7d977 Compare October 1, 2026 08:45
@nnastonen nnastonen changed the title Reorder instructions to eliminate data race Volume destroy data race Oct 1, 2026

@JacksonYao287 JacksonYao287 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM,nice catch

@JacksonYao287 JacksonYao287 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LG

@nnastonen
nnastonen merged commit 377a72e into eBay:dev/v8.x Oct 2, 2026
18 of 19 checks passed
@shosseinimotlagh

Copy link
Copy Markdown
Contributor

Good catch!

Approve. The race fix is correct and the mutex fence is sound. After destroy() freed m_rd_sb, a concurrent CP could still call cp_flush on the device (still visible in m_rd_map), hitting a null dereference. The fix erases from the map before destroy(). After the erase no future iterate_repl_devs() can find this device.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants