[PATCH] block, bfq: initialize active lists for all actuators
From: lirongqing
Date: Mon Oct 05 2026 - 06:49:05 EST
From: Li RongQing <lirongqing@xxxxxxxxx>
Commit 2d31c684a053 ("block, bfq: inject I/O to underutilized
actuators") extended bfqd->active_list from a single list_head to an
array indexed by actuator, but bfq_init_queue() still only initialized
the first two entries:
INIT_LIST_HEAD(&bfqd->active_list[0]);
INIT_LIST_HEAD(&bfqd->active_list[1]);
For devices with more than two independent access ranges, the remaining
list heads stay zeroed by kzalloc() and are never set up as empty lists.
When BFQ later adds a bfq_queue to one of those lists, list_add() writes
through head->next, which is NULL, corrupting the list or crashing the
kernel.
Initialize every actuator's active list using bfqd->num_actuators,
which is already set up earlier in bfq_init_queue().
Fixes: 2d31c684a053 ("block, bfq: inject I/O to underutilized actuators")
Signed-off-by: Li RongQing <lirongqing@xxxxxxxxx>
---
block/bfq-iosched.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/block/bfq-iosched.c b/block/bfq-iosched.c
index 0f75301..b21ddba 100644
--- a/block/bfq-iosched.c
+++ b/block/bfq-iosched.c
@@ -7273,8 +7273,8 @@ static int bfq_init_queue(struct request_queue *q, struct elevator_queue *eq)
bfqd->num_groups_with_pending_reqs = 0;
#endif
- INIT_LIST_HEAD(&bfqd->active_list[0]);
- INIT_LIST_HEAD(&bfqd->active_list[1]);
+ for (i = 0; i < bfqd->num_actuators; i++)
+ INIT_LIST_HEAD(&bfqd->active_list[i]);
INIT_LIST_HEAD(&bfqd->idle_list);
INIT_HLIST_HEAD(&bfqd->burst_list);
--
2.9.4