From: Guixin Liu <kanie@linux.alibaba.com>
To: shinichiro.kawasaki@wdc.com, Keith Busch <kbusch@kernel.org>,
Jens Axboe <axboe@kernel.dk>, Christoph Hellwig <hch@lst.de>,
Sagi Grimberg <sagi@grimberg.me>, Hannes Reinecke <hare@suse.de>,
nilay@linux.ibm.com, Chaitanya Kulkarni <kch@nvidia.com>,
Kanchan Joshi <joshi.k@samsung.com>
Cc: linux-nvme@lists.infradead.org
Subject: [PATCH blktests] nvme/070: add a test for Identify CNS 07h NULL pointer dereference
Date: Fri, 31 Jul 2026 11:26:01 +0800 [thread overview]
Message-ID: <20260731032601.1100664-1-kanie@linux.alibaba.com> (raw)
nvmet_execute_identify_nslist() handles both the Active Namespace ID list
(CNS 02h) and the per-command-set variant (CNS 07h). For CNS 07h it
filtered the list on req->ns->csi, but this handler never resolves
req->ns, so it is always NULL. As soon as an enabled namespace with an
NSID above the requested value exists, the target dereferenced a NULL
pointer and oopsed.
This test connects a target with a single namespace and issues an
Identify with CNS 07h starting from NSID 0, which is exactly the
condition that triggered the crash. Without the kernel fix [0] the target
oopses; with it the command completes normally.
[0] https://lore.kernel.org/linux-nvme/20260730043105.3071328-2-kanie@linux.alibaba.com/
Suggested-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
---
tests/nvme/070 | 54 ++++++++++++++++++++++++++++++++++++++++++++++
tests/nvme/070.out | 2 ++
2 files changed, 56 insertions(+)
create mode 100755 tests/nvme/070
create mode 100644 tests/nvme/070.out
diff --git a/tests/nvme/070 b/tests/nvme/070
new file mode 100755
index 0000000..1f29a69
--- /dev/null
+++ b/tests/nvme/070
@@ -0,0 +1,54 @@
+#!/bin/bash
+# SPDX-License-Identifier: GPL-3.0+
+# Copyright (C) 2026 Guixin Liu
+#
+# Regression test for the NULL pointer dereference in
+# nvmet_execute_identify_nslist() when handling Identify CNS 07h (Active
+# Namespace ID List for the specified I/O Command Set). The CNS 07h handler
+# filtered the list on req->ns->csi, but this handler never resolves req->ns
+# so it is always NULL. As soon as an enabled namespace with an NSID above the
+# requested value exists, the target dereferenced a NULL pointer and oopsed.
+
+. tests/nvme/rc
+
+DESCRIPTION="issue Identify CNS 07h (per-command-set active NS list)"
+QUICK=1
+
+requires() {
+ _nvme_requires
+ _have_loop
+ _require_nvme_trtype_is_fabrics
+}
+
+set_conditions() {
+ _set_nvme_trtype "$@"
+}
+
+test() {
+ echo "Running ${TEST_NAME}"
+
+ _setup_nvmet
+
+ _nvmet_target_setup
+
+ _nvme_connect_subsys
+
+ local nvmedev
+ nvmedev=$(_find_nvme_dev "${def_subsysnqn}")
+
+ # CNS 07h == Active Namespace ID list for the specified I/O Command Set.
+ # CDW10 bits[7:0] hold the CNS; CDW11 bits[31:24] hold the CSI (0 == NVM).
+ # Request from NSID 0 so the enabled namespace (NSID 1) is listed, which
+ # is exactly the condition that used to dereference the NULL req->ns.
+ if ! nvme admin-passthru "/dev/${nvmedev}" --opcode=0x06 \
+ --namespace-id=0 --cdw10=0x07 --cdw11=0 --data-len=4096 -r \
+ >> "${FULL}" 2>&1; then
+ echo "Error: Identify CNS 07h failed"
+ fi
+
+ _nvme_disconnect_subsys
+
+ _nvmet_target_cleanup
+
+ echo "Test complete"
+}
diff --git a/tests/nvme/070.out b/tests/nvme/070.out
new file mode 100644
index 0000000..b765a28
--- /dev/null
+++ b/tests/nvme/070.out
@@ -0,0 +1,2 @@
+Running nvme/070
+Test complete
--
2.43.7
next reply other threads:[~2026-07-31 3:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 3:26 Guixin Liu [this message]
2026-08-01 14:01 ` [PATCH blktests] nvme/070: add a test for Identify CNS 07h NULL pointer dereference Nilay Shroff
2026-08-03 4:14 ` Shin'ichiro Kawasaki
2026-08-04 2:37 ` Guixin Liu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731032601.1100664-1-kanie@linux.alibaba.com \
--to=kanie@linux.alibaba.com \
--cc=axboe@kernel.dk \
--cc=hare@suse.de \
--cc=hch@lst.de \
--cc=joshi.k@samsung.com \
--cc=kbusch@kernel.org \
--cc=kch@nvidia.com \
--cc=linux-nvme@lists.infradead.org \
--cc=nilay@linux.ibm.com \
--cc=sagi@grimberg.me \
--cc=shinichiro.kawasaki@wdc.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.