All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ranjan Kumar <ranjan.kumar@broadcom.com>
To: linux-scsi@vger.kernel.org, martin.petersen@oracle.com
Cc: sathya.prakash@broadcom.com, chandrakanth.patil@broadcom.com,
	vishakhavc@google.com, ipylypiv@google.com,
	Ranjan Kumar <ranjan.kumar@broadcom.com>
Subject: [PATCH v3 00/10] mpi3mr: Few Enhancements and minor fixes
Date: Fri, 24 Jul 2026 15:54:55 +0530	[thread overview]
Message-ID: <20260724102505.115136-1-ranjan.kumar@broadcom.com> (raw)

Few Enhancements and minor fixes of mpi3mr driver.

Changes since v2:
- Patch 1: Added missing endianness conversions (le16_to_cpu()) for
  buffer size fields in mpi3mr_alloc_diag_bufs() to prevent large memory
  allocations on big-endian architectures.
- Patch 5: Hardened reply queue processing by adding bounds checking for
  request_queue_id, fixed a TOCTOU race with a double-check pattern
  (using dma_rmb and atomic_add_unless), and replaced a direct panic()
  with a safe ioc_err() log for malformed DMA reply addresses.
- Patch 6: Fixed potential NULL pointer dereferences and Use-After-Free
  during spurious interrupts by properly clearing intr_info[*].op_reply_q
  when reply queue segments are freed.
- Patch 7: Resolved multiple concurrency issues around firmware event
  cleanup: fixed TOCTOU races by safely handling current_event under the
  fwevt_lock, fixed a Use-After-Free by delaying the release of event
  references until after cancellation, and prevented deadlocks during module
  unload.
- Patch 8: Removed an explicit sas_rphy_free() to fix a double-free
  vulnerability on the sas_rphy_add() error path, as sas_port_delete()
  implicitly handles the cleanup.

Changes since v1:
- Fixed test robot build warning.
- Patch 1: Added le32_to_cpu() conversion for driver_pg1.flags to prevent
  incorrect logic on big-endian architectures.
- Patch 4: Added bounds checking for firmware-provided NVMe page size to
  prevent undefined shift behavior and potential divide-by-zero panics.
- Patch 5: Added missing dma_rmb() memory barriers in reply queue
  processing loops to prevent weakly ordered architectures from
  processing stale data.
- Patch 6: Hardened operational queue error handling to prevent
  NULL pointer dereferences and deferred kernel panics
  during driver cleanup.
- Patch 7: Fixed a TOCTOU Use-After-Free race condition and reference leak
  during firmware event cleanup by safely acquiring the event reference
  under a spinlock.
- Patch 8: Added missing NULL pointer checks for rphy allocations and
  handled sas_rphy_add() failures to prevent NULL pointer dereferences
  and resource leaks.
- Patch 9: Added return value check for mpi3mr_add_host_phy() to prevent
  a NULL pointer dereference during device addition events.

Ranjan Kumar (10):
  mpi3mr: Skip device shutdown during unload per controller
    configuration
  mpi3mr: Update MPI Headers to revision 41
  mpi3mr: Add early timestamp synchronization after driver load
  mpi3mr: Fix NVMe page size caching for non-operational devices
  mpi3mr: Fix performance regression caused by extended IRQ poll sleep
  mpi3mr: Fix memory leak on operational queue creation failure
  mpi3mr: Fix firmware event reference leak during cleanup
  mpi3mr: Fix SAS port allocation and registration error handling
  mpi3mr: Fix SAS PHY cleanup in host addition error paths
  mpi3mr: Driver version update to 8.18.0.8.50

 drivers/scsi/mpi3mr/mpi/mpi30_cnfg.h      |  77 +++++++++++-
 drivers/scsi/mpi3mr/mpi/mpi30_image.h     |   7 +-
 drivers/scsi/mpi3mr/mpi/mpi30_ioc.h       |  15 ++-
 drivers/scsi/mpi3mr/mpi/mpi30_transport.h |   2 +-
 drivers/scsi/mpi3mr/mpi3mr.h              |  12 +-
 drivers/scsi/mpi3mr/mpi3mr_app.c          |  24 ++--
 drivers/scsi/mpi3mr/mpi3mr_fw.c           | 142 ++++++++++++++++++----
 drivers/scsi/mpi3mr/mpi3mr_os.c           |  99 ++++++++-------
 drivers/scsi/mpi3mr/mpi3mr_transport.c    |  56 +++++++--
 9 files changed, 332 insertions(+), 102 deletions(-)

-- 
2.47.3


             reply	other threads:[~2026-07-24 10:32 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-24 10:24 Ranjan Kumar [this message]
2026-07-24 10:24 ` [PATCH v3 01/10] mpi3mr: Skip device shutdown during unload per controller configuration Ranjan Kumar
2026-07-24 10:59   ` sashiko-bot
2026-07-24 10:24 ` [PATCH v3 02/10] mpi3mr: Update MPI Headers to revision 41 Ranjan Kumar
2026-07-24 10:24 ` [PATCH v3 03/10] mpi3mr: Add early timestamp synchronization after driver load Ranjan Kumar
2026-07-24 10:24 ` [PATCH v3 04/10] mpi3mr: Fix NVMe page size caching for non-operational devices Ranjan Kumar
2026-07-24 10:44   ` sashiko-bot
2026-07-24 10:25 ` [PATCH v3 05/10] mpi3mr: Fix performance regression caused by extended IRQ poll sleep Ranjan Kumar
2026-07-24 10:50   ` sashiko-bot
2026-07-24 10:25 ` [PATCH v3 06/10] mpi3mr: Fix memory leak on operational queue creation failure Ranjan Kumar
2026-07-24 10:51   ` sashiko-bot
2026-07-24 10:25 ` [PATCH v3 07/10] mpi3mr: Fix firmware event reference leak during cleanup Ranjan Kumar
2026-07-24 11:02   ` sashiko-bot
2026-07-24 10:25 ` [PATCH v3 08/10] mpi3mr: Fix SAS port allocation and registration error handling Ranjan Kumar
2026-07-24 10:58   ` sashiko-bot
2026-07-24 10:25 ` [PATCH v3 09/10] mpi3mr: Fix SAS PHY cleanup in host addition error paths Ranjan Kumar
2026-07-24 10:25 ` [PATCH v3 10/10] mpi3mr: Driver version update to 8.18.0.8.50 Ranjan Kumar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260724102505.115136-1-ranjan.kumar@broadcom.com \
    --to=ranjan.kumar@broadcom.com \
    --cc=chandrakanth.patil@broadcom.com \
    --cc=ipylypiv@google.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    --cc=sathya.prakash@broadcom.com \
    --cc=vishakhavc@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.