[PATCH] nvme-multipath: set BLK_FEAT_ZONED only after the zone info is known

Guixin Liu kanie at linux.alibaba.com
Mon Sep 14 03:57:13 PDT 2026


The namespace head is marked zoned at allocation time based only on
the command set identifier, before any zone information has been
queried.  If the zone info query fails on the first scan, the path
namespace is registered without zoned limits while the head still
advertises the zoned capability with a zone size of zero.  Reporting
zones or writing to the head then shifts by ilog2(0), triggering the
UBSAN shift-out-of-bounds report in the report-zones and write paths.

Drop the zoned feature from the head allocation and inherit it from
the path namespace: the head limits refresh already stacks the zoned
feature, the zone size and the zone resource limits from the path
queue, so the head matches the path namespace and becomes zoned once a
revalidation succeeds.  This also stops marking the head zoned when
CONFIG_BLK_DEV_ZONED is off, which used to fail the head allocation
with a WARN.

Found by code inspection while reviewing the nvme-7.3 branch.

Tested with a null_blk zoned namespace exported over two nvmet-tcp
ports, with the target patched to fail the command set specific
identify: the head no longer comes up zoned with zone size 0, the
UBSAN report is gone, and an ns-rescan once the identify succeeds again
transitions the head to zoned with the correct zone size.

Fixes: 28982ad73d6a ("nvme: set BLK_FEAT_ZONED for ZNS multipath disks")
Fixes: 3838e80fcfb3 ("nvme: skip the zoned limits update if the zone info query failed")
Cc: stable at vger.kernel.org
Signed-off-by: Guixin Liu <kanie at linux.alibaba.com>
---
 drivers/nvme/host/multipath.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/nvme/host/multipath.c b/drivers/nvme/host/multipath.c
index 75dbb58286a3..cdfaa04c25f8 100644
--- a/drivers/nvme/host/multipath.c
+++ b/drivers/nvme/host/multipath.c
@@ -763,8 +763,6 @@ int nvme_mpath_alloc_disk(struct nvme_ctrl *ctrl, struct nvme_ns_head *head)
 	lim.dma_alignment = 3;
 	lim.features |= BLK_FEAT_IO_STAT | BLK_FEAT_NOWAIT |
 		BLK_FEAT_POLL | BLK_FEAT_ATOMIC_WRITES | BLK_FEAT_PCI_P2PDMA;
-	if (head->ids.csi == NVME_CSI_ZNS)
-		lim.features |= BLK_FEAT_ZONED;
 
 	head->disk = blk_alloc_disk(&lim, ctrl->numa_node);
 	if (IS_ERR(head->disk))
-- 
2.43.7




More information about the Linux-nvme mailing list