From: Klaus Jensen <its@irrelevant.dk>
To: qemu-devel@nongnu.org
Cc: Peter Maydell <peter.maydell@linaro.org>,
Minwoo Im <minwoo.im.dev@gmail.com>,
qemu-stable@nongnu.org, Minwoo Im <minwoo.im@samsung.com>,
Klaus Jensen <k.jensen@samsung.com>,
Keith Busch <kbusch@kernel.org>, Klaus Jensen <its@irrelevant.dk>,
Jesper Devantier <foss@defmacro.it>,
qemu-block@nongnu.org
Subject: [PULL 1/4] hw/nvme: drop AER requests without aiocb in nvme_del_sq()
Date: Mon, 3 Aug 2026 15:44:32 -0700 [thread overview]
Message-ID: <20260803224436.38768-2-its@irrelevant.dk> (raw)
In-Reply-To: <20260803224436.38768-1-its@irrelevant.dk>
From: Minwoo Im <minwoo.im.dev@gmail.com>
nvme_del_sq() asserted r->aiocb was always set when canceling a
queue's inflight requests. A pending Async Event Request has no
aiocb (nvme_aer() parks it without issuing any block I/O), so
deleting a queue with an outstanding AER trips the assert instead of
just dropping the request.
Cc: qemu-stable@nongnu.org
Signed-off-by: Minwoo Im <minwoo.im@samsung.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
---
hw/nvme/ctrl.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c
index bd6ad64b2000..e3eadf3d1dd0 100644
--- a/hw/nvme/ctrl.c
+++ b/hw/nvme/ctrl.c
@@ -4862,12 +4862,14 @@ static uint16_t nvme_del_sq(NvmeCtrl *n, NvmeRequest *req)
sq = n->sq[qid];
while (!QTAILQ_EMPTY(&sq->out_req_list)) {
r = QTAILQ_FIRST(&sq->out_req_list);
- assert(r->aiocb);
r->status = NVME_CMD_ABORT_SQ_DEL;
- blk_aio_cancel(r->aiocb);
- }
- assert(QTAILQ_EMPTY(&sq->out_req_list));
+ if (r->aiocb) {
+ blk_aio_cancel(r->aiocb);
+ } else {
+ QTAILQ_REMOVE(&sq->out_req_list, r, entry);
+ }
+ }
if (!nvme_check_cqid(n, sq->cqid)) {
cq = n->cq[sq->cqid];
--
2.53.0
next prev parent reply other threads:[~2026-08-03 22:45 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 22:44 [PULL 0/4] hw/nvme queue Klaus Jensen
2026-08-03 22:44 ` Klaus Jensen [this message]
2026-08-03 22:44 ` [PULL 2/4] hw/nvme: factor out nvme_sq_cancel_inflight() Klaus Jensen
2026-08-03 22:44 ` [PULL 3/4] hw/nvme: cancel inflight requests on controller reset Klaus Jensen
2026-08-03 22:44 ` [PULL 4/4] hw/nvme: fix leak on copy ranges Klaus Jensen
2026-08-05 0:54 ` [PULL 0/4] hw/nvme queue Stefan Hajnoczi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260803224436.38768-2-its@irrelevant.dk \
--to=its@irrelevant.dk \
--cc=foss@defmacro.it \
--cc=k.jensen@samsung.com \
--cc=kbusch@kernel.org \
--cc=minwoo.im.dev@gmail.com \
--cc=minwoo.im@samsung.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.