All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tyrel Datwyler" <tyreld@linux.ibm.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH v2 28/33] ibmvfc: implement LLDD callbacks for mapping nvme-fc queues
Date: Thu, 23 Jul 2026 00:58:42 +0000	[thread overview]
Message-ID: <20260723005843.713591F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723000149.969416-29-tyreld@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
- [High] Missing `nvme_fc_unregister_localport` during adapter teardown causes Use-After-Free.
- [High] TOCTOU race in `ibmvfc_nvme_create_queue` leading to divide-by-zero and NULL pointer dereference.
- [High] Stub implementations of `ls_req` and `fcp_io` return 0 without invoking completion callbacks, causing uninterruptible kernel hangs.
--

--- Patch [28]: [PATCH v2 28/33] ibmvfc: implement LLDD callbacks for mapping nvme-fc queues ---
commit 186f72e380294760659d725fac77194c4e72d82e
Author: Tyrel Datwyler <tyreld@linux.ibm.com>

ibmvfc: implement LLDD callbacks for mapping nvme-fc queues

Implement the NVMe-FC queue create and delete callbacks and map NVMe
controller queues onto ibmvfc hardware queues. Use qidx of NVMe controller
queue to map onto a ibmvfc_queue channel. Add a new ibmvfc_nvme_qhandle
struct that will be used as the opaque queue handle by the NVMe-FC layer
when issuing fcp IO.

> diff --git a/drivers/scsi/ibmvscsi/ibmvfc-nvme.c b/drivers/scsi/ibmvscsi/ibmvfc-nvme.c
> index 637d7d7015cf5..ecf9f4c0549c2 100644
> --- a/drivers/scsi/ibmvscsi/ibmvfc-nvme.c
> +++ b/drivers/scsi/ibmvscsi/ibmvfc-nvme.c

[ ... ]

> +static int ibmvfc_nvme_create_queue(struct nvme_fc_local_port *lport, unsigned int qidx,
> +				    u16 qsize, void **handle)
> +{
> +	struct ibmvfc_host *vhost = lport->private;
> +	struct ibmvfc_nvme_qhandle *qhandle;
> +
> +	if (!vhost->nvme_scrqs.active_queues)
> +		return -ENODEV;
> +
> +	qhandle = kzalloc_obj(struct ibmvfc_nvme_qhandle);
> +	if (!qhandle)
> +		return -ENOMEM;
> +
> +	qhandle->cpu_id = raw_smp_processor_id();
> +	qhandle->qidx = qidx;
> +
> +	/* Admin and first IO queue are both mapped to index 0 */
> +	if (qidx)
> +		qhandle->index = (qidx - 1) % vhost->nvme_scrqs.active_queues;

[Severity: High]
Could this result in a divide-by-zero or NULL pointer dereference?

The vhost->nvme_scrqs.active_queues value is read locklessly at the start of
the function. Since kzalloc_obj() can sleep, if a concurrent teardown or reset
(such as ibmvfc_release_channels()) executes during this window, it could set
active_queues to 0 and scrqs to NULL.

When the thread resumes, it would divide by zero here.

> +	else
> +		qhandle->index = qidx;
> +
> +	qhandle->queue = &vhost->nvme_scrqs.scrqs[qhandle->index];

[Severity: High]
Will this lead to a use-after-free during adapter teardown?

When unloading the driver or hot-removing the adapter, ibmvfc_remove() frees
the memory backing vhost->nvme_scrqs.scrqs via ibmvfc_release_sub_crqs().

However, it appears nvme_fc_unregister_localport() is never called during this
teardown path. Without notifying the NVMe-FC transport layer, it retains active
references to the local port and its queues. Any subsequent background transport
operations could dereference the freed queues.

[ ... ]

> @@ -59,8 +93,8 @@ static void ibmvfc_nvme_fcp_abort(struct nvme_fc_local_port *lport,
>  static struct nvme_fc_port_template ibmvfc_nvme_fc_transport = {
>  	.localport_delete	= ibmvfc_nvme_localport_delete,
>  	.remoteport_delete	= ibmvfc_nvme_remoteport_delete,
> -	.create_queue		= NULL,
> -	.delete_queue		= NULL,
> +	.create_queue		= ibmvfc_nvme_create_queue,
> +	.delete_queue		= ibmvfc_nvme_delete_queue,
>  	.ls_req			= ibmvfc_nvme_ls_req,
>  	.ls_abort		= ibmvfc_nvme_ls_abort,
>  	.fcp_io			= ibmvfc_nvme_fcp_io,

[Severity: High]
Does returning 0 from the stub implementations of ibmvfc_nvme_ls_req() and
ibmvfc_nvme_fcp_io() cause uninterruptible kernel hangs?

The NVMe-FC transport layer calls the LLDD's ls_req and fcp_io functions.
Returning 0 signals that the request was successfully dispatched and the
LLDD will asynchronously invoke the req->done() callback.

For example, __nvme_fc_send_ls_req() issues a synchronous wait_for_completion()
with no timeout. Because the stub functions simply return 0 and never call
done(), the caller would block forever, leaving block layer I/Os permanently
outstanding.

If these are meant to be stubs, should they return an error code like
-EOPNOTSUPP or -EIO instead?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260723000149.969416-1-tyreld@linux.ibm.com?part=28

  reply	other threads:[~2026-07-23  0:58 UTC|newest]

Thread overview: 62+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23  0:01 [PATCH v2 00/33] ibmvfc: NVMe/FC support over IBM Virtual FC Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 01/33] ibmvfc: don't call locked done variant for MADs on send failure Tyrel Datwyler
2026-07-23  0:42   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 02/33] ibmvfc: flush rport_add_work_q during driver teardown Tyrel Datwyler
2026-07-23  0:35   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 03/33] ibmvfc: check for NULL evt in implicit LOGO and target delete path Tyrel Datwyler
2026-07-23  0:30   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 04/33] ibmvfc: free ibmvfc_target allocations with mempool_free Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 05/33] ibmvfc: move target list from host to protocol specific channel groups Tyrel Datwyler
2026-07-23  0:34   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 06/33] ibmvfc: add NVMe/FC protocol interface definitions Tyrel Datwyler
2026-07-23  0:28   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 07/33] ibmvfc: split NVMe support into separate source file and add transport stubs Tyrel Datwyler
2026-07-23  0:22   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 08/33] ibmvfc: initialize NVMe channel configuration during driver probe Tyrel Datwyler
2026-07-23  0:21   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 09/33] ibmvfc: alloc/dealloc sub-queues for nvme channels Tyrel Datwyler
2026-07-23  0:33   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 10/33] ibmvfc: add logic for protocol specific fabric logins Tyrel Datwyler
2026-07-23  0:28   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 11/33] ibmvfc: add wrapper to get vhost associated with a channel struct Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 12/33] ibmvfc: add helper for creating protocol specific discovery event Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 13/33] ibmvfc: add helper to check NVMe/FC support with active channels Tyrel Datwyler
2026-07-23  0:17   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 14/33] ibmvfc: allocate and free NVMe channel group discover buffer Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 15/33] ibmvfc: send NVMe target discovery MAD Tyrel Datwyler
2026-07-23  0:31   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 16/33] ibmvfc: add NVMe/FC Implicit Logout and Move Login support Tyrel Datwyler
2026-07-23  0:36   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 17/33] ibmvfc: add NVMe/FC Port " Tyrel Datwyler
2026-07-23  0:38   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 18/33] ibmvfc: add NVMe/FC Process " Tyrel Datwyler
2026-07-23  0:39   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 19/33] ibmvfc: add NVMe/FC Query Target support Tyrel Datwyler
2026-07-23  0:50   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 20/33] ibmvfc: allocate targets based on protocol Tyrel Datwyler
2026-07-23  0:43   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 21/33] ibmvfc: delete NVMe/FC targets as well as SCSI Tyrel Datwyler
2026-07-23  0:52   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 22/33] ibmvfc: update state machine to process NVMe/FC targets Tyrel Datwyler
2026-07-23  0:53   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 23/33] ibmvfc: implement NVMe/FC stubs for local/remote port registration Tyrel Datwyler
2026-07-23  0:54   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 24/33] ibmvfc: register local nvme fc port after fabric login Tyrel Datwyler
2026-07-23  0:53   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 25/33] ibmvfc: process NVMe/FC rports in work thread Tyrel Datwyler
2026-07-23  0:50   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 26/33] ibmvfc: extend ibmvfc_debug visibility to ibmvfc-nvme.h Tyrel Datwyler
2026-07-23  0:42   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 27/33] ibmvfc: declare global function definitions Tyrel Datwyler
2026-07-23  0:01 ` [PATCH v2 28/33] ibmvfc: implement LLDD callbacks for mapping nvme-fc queues Tyrel Datwyler
2026-07-23  0:58   ` sashiko-bot [this message]
2026-07-23  0:01 ` [PATCH v2 29/33] ibmvfc: implement nvme-fc LS submission transport callback Tyrel Datwyler
2026-07-23  1:00   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 30/33] ibmvfc: implement nvme-fc IO command submission callback Tyrel Datwyler
2026-07-23  1:08   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 31/33] ibmvfc: implement nvme-fc LS abort handling callback Tyrel Datwyler
2026-07-23  1:05   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 32/33] ibmvfc: implement nvme-fc FCP abort callback Tyrel Datwyler
2026-07-23  1:05   ` sashiko-bot
2026-07-23  0:01 ` [PATCH v2 33/33] ibmvfc: fail nvme-fc fcp-io and ls requests during transport reset Tyrel Datwyler
2026-07-23  0:58   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723005843.713591F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tyreld@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.