Re: [PATCH 0/9] ublk: fix dispatch to canceled io commands

From: Ming Lei

Date: Tue Sep 29 2026 - 10:49:36 EST


Hi Josef,

On Mon, Sep 28, 2026 at 04:00:36PM +0000, Josef Bacik wrote:
> ublk can dispatch a block request to an io command which is completed
> already, and the kernel oopses in ublk_queue_rq() on a NULL io->cmd.
> Before commit f7700a4415af ("ublk: fix use-after-free in
> ublk_cancel_cmd()") it is a freed io_uring request instead. Commit
> 1133b93fc7f6 ("ublk: set canceling flag even when disk is not
> allocated") fixed the io_uring exit route before the first start.
> These are the routes next to it:
>
> 1. STOP_DEV on a device which is ready but not started, then
> START_DEV. ublk_stop_dev() cancels the fetched commands after
> dropping ub->mutex, without marking the queues as canceling.

It looks two races: STOP_DEV vs. START_DEV, STOP_DEV vs. FETCH.

Looks fast io path shouldn't be touched for fixing the races.

> 2. A partial FETCH round whose task exits, once another task
> completes the round.
> 3. During recovery, the task of a queue which is ready already
> exiting before the last queue is ready.

2 and 3 could be solved in single simpler patch by making use of the
ub->canceling flag, and it is easier for backport.