[PATCH] nvmet: send namespace changed event after namespace is fully initialized
From: Nilay Shroff
Date: Fri Oct 02 2026 - 03:05:54 EST
nvmet_ns_enable() queues the asynchronous namespace change event before
the namespace is enabled and the corresponding xarray entry is marked
with NVMET_NS_ENABLED. This may create a narrow race if the host
receives the namespace change event before the namespace is fully
initialized on the target. In that case, scanning the active namespace
list on the host may fail to find the namespace that is being enabled
on the target.
The blktests nvme/052 failure was reported[1] due to this race.
Fix the race by moving nvmet_ns_changed() in nvmet_ns_enable() after
the namespace is enabled, the xarray entry is marked with
NVMET_NS_ENABLED, and the NVMET_NS_IO_LIVE flag is set.
Cc: stable@xxxxxxxxxxxxxxx
Fixes: 74d16965d7ac ("nvmet-loop: avoid using mutex in IO hotpath")
Reported-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@xxxxxxx>
Closes: https://lore.kernel.org/all/ar30Q5H1fuyFtDwM@shinmob/ [1]
Tested-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@xxxxxxx>
Signed-off-by: Nilay Shroff <nilay@xxxxxxxxxxxxx>
---
drivers/nvme/target/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/nvme/target/core.c b/drivers/nvme/target/core.c
index 8eea0a504308..da98e5cae7f6 100644
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -626,11 +626,11 @@ int nvmet_ns_enable(struct nvmet_ns *ns)
if (ret)
goto out_pr_exit;
- nvmet_ns_changed(subsys, ns->nsid);
ns->enabled = true;
xa_set_mark(&subsys->namespaces, ns->nsid, NVMET_NS_ENABLED);
nvmet_debugfs_ns_setup(ns);
set_bit(NVMET_NS_IO_LIVE, &ns->flags);
+ nvmet_ns_changed(subsys, ns->nsid);
ret = 0;
out_unlock:
mutex_unlock(&subsys->lock);
--
2.53.0