This is a note to let you know that I've just added the patch titled dm: fix potential for q->make_request_fn NULL pointer to the 5.4-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: dm-fix-potential-for-q-make_request_fn-null-pointer.patch and it can be found in the queue-5.4 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From 47ace7e012b9f7ad71d43ac9063d335ea3d6820b Mon Sep 17 00:00:00 2001 From: Mike Snitzer <snitzer@xxxxxxxxxx> Date: Mon, 27 Jan 2020 14:07:23 -0500 Subject: dm: fix potential for q->make_request_fn NULL pointer From: Mike Snitzer <snitzer@xxxxxxxxxx> commit 47ace7e012b9f7ad71d43ac9063d335ea3d6820b upstream. Move blk_queue_make_request() to dm.c:alloc_dev() so that q->make_request_fn is never NULL during the lifetime of a DM device (even one that is created without a DM table). Otherwise generic_make_request() will crash simply by doing: dmsetup create -n test mount /dev/dm-N /mnt While at it, move ->congested_data initialization out of dm.c:alloc_dev() and into the bio-based specific init method. Reported-by: Stefan Bader <stefan.bader@xxxxxxxxxxxxx> BugLink: https://bugs.launchpad.net/bugs/1860231 Fixes: ff36ab34583a ("dm: remove request-based logic from make_request_fn wrapper") Depends-on: c12c9a3c3860c ("dm: various cleanups to md->queue initialization code") Cc: stable@xxxxxxxxxxxxxxx Signed-off-by: Mike Snitzer <snitzer@xxxxxxxxxx> Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- drivers/md/dm.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) --- a/drivers/md/dm.c +++ b/drivers/md/dm.c @@ -1880,6 +1880,7 @@ static void dm_init_normal_md_queue(stru /* * Initialize aspects of queue that aren't relevant for blk-mq */ + md->queue->backing_dev_info->congested_data = md; md->queue->backing_dev_info->congested_fn = dm_any_congested; } @@ -1970,7 +1971,12 @@ static struct mapped_device *alloc_dev(i if (!md->queue) goto bad; md->queue->queuedata = md; - md->queue->backing_dev_info->congested_data = md; + /* + * default to bio-based required ->make_request_fn until DM + * table is loaded and md->type established. If request-based + * table is loaded: blk-mq will override accordingly. + */ + blk_queue_make_request(md->queue, dm_make_request); md->disk = alloc_disk_node(1, md->numa_node_id); if (!md->disk) @@ -2285,7 +2291,6 @@ int dm_setup_md_queue(struct mapped_devi case DM_TYPE_DAX_BIO_BASED: case DM_TYPE_NVME_BIO_BASED: dm_init_normal_md_queue(md); - blk_queue_make_request(md->queue, dm_make_request); break; case DM_TYPE_NONE: WARN_ON_ONCE(true); Patches currently in stable-queue which might be from snitzer@xxxxxxxxxx are queue-5.4/dm-crypt-fix-benbi-iv-constructor-crash-if-used-in-authenticated-mode.patch queue-5.4/dm-fix-potential-for-q-make_request_fn-null-pointer.patch queue-5.4/dm-crypt-fix-gfp-flags-passed-to-skcipher_request_alloc.patch queue-5.4/dm-writecache-fix-incorrect-flush-sequence-when-doing-ssd-mode-commit.patch queue-5.4/dm-thin-metadata-use-pool-locking-at-end-of-dm_pool_metadata_close.patch queue-5.4/dm-zoned-support-zone-sizes-smaller-than-128mib.patch queue-5.4/dm-space-map-common-fix-to-ensure-new-block-isn-t-already-in-use.patch