[PATCH v4 00/20] Support Clang context analysis for NVMe host drivers

Marco Elver elver at google.com
Mon Jul 20 06:22:49 PDT 2026


On Mon, 13 Jul 2026 at 13:55, Nilay Shroff <nilay at linux.ibm.com> wrote:
>
> Hi,
>
> This series adds support for Clang's context analysis to the NVMe host
> drivers.
>
> Recent work[1] by Marco Elver introduced infrastructure for lock context
> analysis in the kernel, allowing Clang to verify locking requirements at
> compile time through various annotations.
>
> This series build on top of that infrastructure by annotating the NVMe
> host drivers with the appropriate locking requirements and by addressing
> warnings reported by the analyzer.
>
> The series was built and tested with LLVM/Clang 23.x and enables the
> NVMe host drivers to build cleanly with CONFIG_CONTEXT_ANALYSIS enabled.
>
> Support for the NVMe target drivers will be addressed separately.
>
> As usual, comments/feedback/suggestions are most welcome!
>
> Thanks!
>
> [1] https://lore.kernel.org/lkml/20251219154418.3592607-1-elver@google.com/
>
> Changes from v3:
>
> - Moved the infrastructure patches to the front of the series; the first two
>   patches are now the infrastructure patches (hch).
>
> - Annotated initialization functions, which typically initialize objects
>   before they are published, with __context_unsafe instead of wrapping
>   individual initialization statements in context_unsafe(...).
>
> - Annotated nvme_next_ns() and nvme_available_path() with
>   __must_hold_shared(&head->srcu) since both APIs require the caller to
>   hold the SRCU read lock (Sashiko).
>
> - Split the removal of the redundant initialization of
>   nvme_ns_head::delayed_removal_secs into a separate patch (09/20)
>   (hch).
>
> - Split the removal of the redundant initialization of
>   nvme_ns_head::requeue_list into a separate patch (05/20)
>
> Link to v3: https://lore.kernel.org/all/20260706141452.3008233-1-nilay@linux.ibm.com/
>
> Changes from v2:
>
> - removed "Clang" from each commit subject line (hch)
>
> - for zero-initialized struct bio_list_init() is redundant and also to
>   suppress false-positive context analysis warning for a list variable
>   guarded by lock, remove bio_list_init(&head->requeue_list) from
>   nvme_mpath_alloc_disk() (hch)
>
> - get rid off wrapping rcu_access_pointer() using context_unsafe() as
>   the access to __rcu_guarded pointer using helper rcu_access_pointer()
>   should be implicitly safe (hch, Marco, Paul)
>
> - wrap INIT_LIST_HEAD() under context_unsafe(...) instead of interleaving
>   it under scoped_guard(...) to suppress context analysis warning while
>   initializing subsys->nsheads  (hch)
>
> - initializing head->delayed_removal_secs from nvme_mpath_alloc_disk() is
>   redudnamt as struct nvme_ns_head is zero allocated. This also helps
>   avoid false positive conext analysis warning (hch)
>
> - introduce LIST_HEAD_GUARDED(_name, _lock) and use it for guarding a
>   list (hch)
>
> - dropped context annotations for nvme_queue::cq_poll_lock as this
>   requires a annotation which could support guarding multiple
>   valid synchronization mechanisms for a single object, which is
>   ,as of today, not yet avalilable (hch)
>
> - new patch in the series from Marco Elver <elver at google.com>, which
>   annotates list_empty_careful() using __context_unsafe
>
> - context_unsafe() has a statement expression inside so group
>   multiple scope guarded variables before those are publsihed
>   under context_unsafe(...) where possible (Marco)
>
> Link to v2: https://lore.kernel.org/all/20260614131541.2017845-1-nilay@linux.ibm.com/
>
> Changes from v1:
>   - replace guard() with scoped_guard() for guarding request_list (Bart)
>   - annotate nvme_alloc_ns_head() using __must_hold(&ctrl->subsys->lock)
>     (Sashiko)
>   - guard nvme_queue::sq_cmds using nvme_queue::sq_lock
>   - annotate nvme_cqe_pending() using context_unsafe in nvme_poll()
>     (Keith)
>   - Split patch #13 and #14 to separate the context annotation change
>     from functionality change (Bart)
>
> Marco Elver (1):
>   list: Permit context-unguarded access with list_empty_careful()
>
> Nilay Shroff (19):
>   list: introduce LIST_HEAD_GUARDED
>   nvme: update nvme_passthru_end() signature
>   nvme: add context annotations for nvme_passthru_{start|stop}
>   nvme: add context annotations for nvme_ns_head::srcu
>   nvme: remove redundant initialization of nvme_ns_head::requeue_list
>   nvme: add context annotations for nvme_ns_head::requeue_list
>   nvme: add context annotations for nvme_ns_head::current_path
>   nvme: add context annotations for nvme_dev::shutdown_lock
>   nvme: remove redundant initialization of delayed_removal_secs
>   nvme: add context annotations for nvme_subsystem::lock
>   nvme: add context annotations for nvme_ctrl::ana_lock
>   nvme: add context annotations for nvme_subsystems_lock
>   nvme: add context annotations in fabric.c
>   nvme: add context annotations for nvme_queue::sq_lock
>   nvme: add context annotations in rdma.c
>   nvme: fix context analysis warning in rdma.c
>   nvme: add context annotations in tcp.c
>   nvme: fix context analysis warning in tcp.c
>   nvme: enable context analysis support for nvme host driver

Acked-by: Marco Elver <elver at google.com>

... from my end this looks reasonable.

Thanks!



More information about the Linux-nvme mailing list