From nobody Fri Oct 2 08:29:30 2026 Received: from mail-qk1-f176.google.com (mail-qk1-f176.google.com [209.85.222.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7E132D23A6 for ; Mon, 3 Aug 2026 14:12:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785766343; cv=none; b=T6Zq+Gkod3dJoaA+bTnhyK+iW0b3oS0E66WUUAdVVjIq1EioEOl59uURdJ9cSsVlcEnanM1Ywbej9j4OdP+SItG4kkW59SxHvHCkGFEpixWQpmv4QMng5t5gcVWVW31HrcKbUzwM/i7oNolr7EaJNcwZW296Ehz1HWIAKs8eR8Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785766343; c=relaxed/simple; bh=BbpslXywfD0iTpZteroQReQ4uidHwvn2ta6HC9rpZn4=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=ndFdXC4lLxmbspJW1rBHlVdbvLt5vxGHlEDokyVtoEn7AjngKQuNITj6vneppm04opD0nqyDPd24VEotir0n/nmjo8y2ICj6AJPoYNynDvEXMWsi5wpH8ypPMDGvpe8zZ2AFt4YIRMQPQG6nKwei9sdaWZNn32WQWP2pvVxpNFE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=KxzsSz6K; arc=none smtp.client-ip=209.85.222.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="KxzsSz6K" Received: by mail-qk1-f176.google.com with SMTP id af79cd13be357-92e7632b193so210619185a.2 for ; Mon, 03 Aug 2026 07:12:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785766341; x=1786371141; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=qAleDQ8MfrNQGQUDixmHN9nrOWbjKoQY0SCnYduBErY=; b=KxzsSz6K6lqtbhpsr6VPq4y0FhDwY/brVKVdgLRH991R1Ll7L0V7mk046r1GwsDYBC 9CBgKdyd/Tln/Vy9JVwasF8jClXyrRdY2Zkt8XRibdLVNm/ok9K268AdTO2VmGPeB87S UYkxUtqYMikiUIC6bpm0TKgtbF0t5lYnkX4tisnFNNDNpcySRe9LNT9cV28/XZQibGcK hAZeyN6WBHZiRx7z+HeL3ORhxM+Tkc1QgXahqxKULngATuvoHQaPVwljz3T1pM66Xaif BzlpE79l+Q8+lovow4RBpn7akSc5uzBJezfiMyaBkbyHeLrJNv208lEoKVsbuMpSvJZ/ qzEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785766341; x=1786371141; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qAleDQ8MfrNQGQUDixmHN9nrOWbjKoQY0SCnYduBErY=; b=Fr+KCrjEFKaNd03QOhsWZGUjBWYZxwC3Hx11GU0j048wHfLxP/n2an5L7bjJ1NS/74 m+PdIIb5P6HaZA6wQMzIGRMzEBe0vCanaHST47lSpA0ClbNcsB4qAkSmGhiXAPQWFXEQ ZbqECzVDyt8Bt2u8oA6kSg3DjnrAadyF9/bR/8Y5VfhcR2C0LJkArp4fxhy8jPfQ6I7L nephGnWCBHYPROBblc+XAPLweFG1ZbtNl6ZvZG+SczWQGZ1YAfsPRMqMP/RPNU0iChpv f0itumdUHKesaK3roGKGU2nfukWec2E4asYFIqegZ5YnPz8g0qx8L9AnIpi57f/3A/zU 1URw== X-Forwarded-Encrypted: i=1; AHgh+RoI4ivpz2AlSYabP86OQ988wJJ+SBwBLcaOqchYCEaGQYbnySPw+qYh6DPo8PTS5ALLBJP5wMCKIzce4eA=@vger.kernel.org X-Gm-Message-State: AOJu0YyRtMJR/rp6gPahR7S4eoklbRjVrOTLO+HtB9jAYTmtyGXH4DQD 2Xfq8WDK5YzfgIJIXBYPEFW3L5Q1OnygYrsWdx2O+cvUaPce7W5C/hrZeiuAdtrnFC0= X-Gm-Gg: AR+sD12SSfd8bXpGay9XZM2EhSsOAVn2ZG3yuxQvEvqqVaPjxpUiNHud8ZwZ0VFuNHW tAURpLRfWUSn5TpBbPh+is3s9xcpOes6W2nL6pFK3ggW3hserAfLRZTrH7TgArdoMOncxW5ATNr BzbyVttyaJnP7oA5ucIraFwm3kGQOkZa0WTfakmpCYDGq1u4uvg99fJPho2+xWBGqlgEtjEJVQw iF2iBla7cU46mErwYKonDE8Tbky7Ofmaq7Z7x6wQgs4txO86gxVEwPMsGszN+FlQ1Kpgc4jpvag c9/zQnLlQkjmfJ6Sd1KwzjW6wBJ7KF+eC0klVNQaJVHTHg2mxIjqyxZyfx108TV9udPn17Peaqn xwhto0PqDJYUA+eGRz45bx0opYVfzHhhX1EZHIXqrHRW7EZwwBB3x7Tf/oxIx4+kjeAk4gYnkkT KdGUtvfw/NwCpGp6xYJ1crKzjTSKeQlVzCUR9eoN3UqrNm/eC04Yd6/HM7/06TEviD X-Received: by 2002:a05:620a:2988:b0:92f:199:b035 with SMTP id af79cd13be357-934a06d57f7mr1631563185a.3.1785766340716; Mon, 03 Aug 2026 07:12:20 -0700 (PDT) Received: from localhost ([161.35.96.86]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-9349c19f881sm677024385a.29.2026.08.03.07.12.19 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 03 Aug 2026 07:12:19 -0700 (PDT) From: Samuel Moelius To: Alasdair Kergon Cc: Samuel Moelius , Mike Snitzer , Mikulas Patocka , Benjamin Marzinski , dm-devel@lists.linux.dev (open list:DEVICE-MAPPER (LVM)), linux-kernel@vger.kernel.org (open list) Subject: [PATCH v2] dm dust: make badblock messages target-relative Date: Mon, 3 Aug 2026 14:09:13 +0000 Message-ID: <20260803140905.383600.be823861719c.dm-dust-badblock-coordinate-mismatch@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" dm-dust currently treats addbadblock, removebadblock and queryblock arguments as block numbers on the underlying device. That is surprising for a device-mapper target: a dm-dust table with a non-zero backing offset can add bad blocks that are outside the mapped target, and a badblock added for logical block 0 is missed because the I/O path checks the remapped backing-device block instead. Interpret badblock message arguments as blocks relative to the start of the dm-dust target instead. Bound the arguments by the target length and perform badblock lookup using target-relative sectors before remapping the bio to the underlying device. This intentionally changes the non-zero backing-offset behavior to make the badblock control interface match the mapped dm-dust device, rather than the underlying device. Assisted-by: Codex:gpt-5.5-cyber-preview Signed-off-by: Samuel Moelius Reviewed-by: Benjamin Marzinski Tested-by: Bryan Gurney --- Changes in v2: - Revise commit message - Remove call to sector_div() in __dust_map_write() drivers/md/dm-dust.c | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/drivers/md/dm-dust.c b/drivers/md/dm-dust.c index c7e3077fb1f5..954f4ec5a51c 100644 --- a/drivers/md/dm-dust.c +++ b/drivers/md/dm-dust.c @@ -196,7 +196,6 @@ static int __dust_map_write(struct dust_device *dd, sec= tor_t thisblock) dd->badblock_count--; kfree(bblk); if (!dd->quiet_mode) { - sector_div(thisblock, dd->sect_per_block); DMINFO("block %llu removed from badblocklist by write", (unsigned long long)thisblock); } @@ -224,15 +223,16 @@ static int dust_map_write(struct dust_device *dd, sec= tor_t thisblock, static int dust_map(struct dm_target *ti, struct bio *bio) { struct dust_device *dd =3D ti->private; + sector_t dust_sector =3D dm_target_offset(ti, bio->bi_iter.bi_sector); int r; =20 bio_set_dev(bio, dd->dev->bdev); - bio->bi_iter.bi_sector =3D dd->start + dm_target_offset(ti, bio->bi_iter.= bi_sector); + bio->bi_iter.bi_sector =3D dd->start + dust_sector; =20 if (bio_data_dir(bio) =3D=3D READ) - r =3D dust_map_read(dd, bio->bi_iter.bi_sector, dd->fail_read_on_bb); + r =3D dust_map_read(dd, dust_sector, dd->fail_read_on_bb); else - r =3D dust_map_write(dd, bio->bi_iter.bi_sector, dd->fail_read_on_bb); + r =3D dust_map_write(dd, dust_sector, dd->fail_read_on_bb); =20 return r; } @@ -415,7 +415,7 @@ static int dust_message(struct dm_target *ti, unsigned = int argc, char **argv, char *result, unsigned int maxlen) { struct dust_device *dd =3D ti->private; - sector_t size =3D bdev_nr_sectors(dd->dev->bdev); + sector_t size =3D dm_sector_div_up(ti->len, dd->sect_per_block); bool invalid_msg =3D false; int r =3D -EINVAL; unsigned long long tmp, block; @@ -462,8 +462,7 @@ static int dust_message(struct dm_target *ti, unsigned = int argc, char **argv, return r; =20 block =3D tmp; - sector_div(size, dd->sect_per_block); - if (block > size) { + if (block >=3D size) { DMERR("selected block value out of range"); return r; } @@ -490,8 +489,7 @@ static int dust_message(struct dm_target *ti, unsigned = int argc, char **argv, return r; } wr_fail_cnt =3D tmp_ui; - sector_div(size, dd->sect_per_block); - if (block > size) { + if (block >=3D size) { DMERR("selected block value out of range"); return r; } --=20 2.43.0