All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jesse Taube" <jtaubepe@redhat.com>
Cc: linux-scsi@vger.kernel.org
Subject: Re: [PATCH 10/13] scsi: qla2xxx: enable FPIN notification for NVMe
Date: Wed, 12 Aug 2026 18:34:46 +0000	[thread overview]
Message-ID: <20260812183447.69D111F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260812181300.3712426-11-jtaubepe@redhat.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Lockless access to `fcport->nvme_remote_port` in `qla2x00_set_rport_marginal()` introduces TOCTOU Use-After-Free and NULL pointer dereferences.
--

--- Patch [10]: [PATCH 10/13] scsi: qla2xxx: enable FPIN notification for NVMe ---
commit 1b0bf8a2abd4965d07b3b9fd652b0926356c721b
Author: Jesse Taube <jtaubepe@redhat.com>

scsi: qla2xxx: enable FPIN notification for NVMe

Implement set_rport_marginal callback using nvme_fc_set_remoteport_fpin()
to enable FPIN notifications for NVMe.

> diff --git a/drivers/scsi/qla2xxx/qla_attr.c b/drivers/scsi/qla2xxx/qla_attr.c
> index a4ca22024edeb..92db7d584eeb8 100644
> --- a/drivers/scsi/qla2xxx/qla_attr.c
> +++ b/drivers/scsi/qla2xxx/qla_attr.c
> @@ -2789,6 +2789,15 @@ qla2x00_set_rport_loss_tmo(struct fc_rport *rport, uint32_t timeout)
>  					       rport->dev_loss_tmo);
>  }
>  
> +static inline void
> +qla2x00_set_rport_marginal(struct fc_rport *rport, bool marginal)
> +{
> +	fc_port_t *fcport = *(fc_port_t **)rport->dd_data;
> +
> +	if (IS_ENABLED(CONFIG_NVME_FC) && fcport && fcport->nvme_remote_port)
> +		nvme_fc_set_remoteport_fpin(fcport->nvme_remote_port, marginal);

[Severity: High]
Does this code introduce a Time-Of-Check to Time-Of-Use (TOCTOU) race condition?

The nvme_remote_port pointer is read and dereferenced locklessly here. If a
device loss event triggers qla_nvme_remoteport_delete() concurrently, it sets
fcport->nvme_remote_port = NULL and allows the NVMe FC transport to free the
remote port memory.

If qla2x00_set_rport_marginal() checks that nvme_remote_port is non-NULL but
is preempted before calling nvme_fc_set_remoteport_fpin(), it will pass a stale
pointer to freed memory, causing a use-after-free.

Alternatively, because the pointer is fetched without READ_ONCE(), the compiler
could reload the now-NULL pointer from memory, leading to a NULL pointer
dereference inside nvme_fc_set_remoteport_fpin().

This pre-existing vulnerability is also present in qla2x00_set_rport_loss_tmo()
just above this new function.

> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260812181300.3712426-1-jtaubepe@redhat.com?part=10

  reply	other threads:[~2026-08-12 18:34 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12 18:12 [PATCH 00/13] nvme-fc: FPIN link integrity handling Jesse Taube
2026-08-12 18:12 ` [PATCH 01/13] fc_els: use 'union fc_tlv_desc' Jesse Taube
2026-08-12 18:26   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 02/13] nvme: add NVME_CTRL_MARGINAL flag Jesse Taube
2026-08-12 18:21   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 03/13] nvme-multipath: numa support for marginal paths Jesse Taube
2026-08-12 18:29   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 04/13] nvme-multipath: queue-depth " Jesse Taube
2026-08-12 18:12 ` [PATCH 05/13] nvme-multipath: round-robin " Jesse Taube
2026-08-12 18:26   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 06/13] nvme: sysfs: emit the marginal path state in show_state() Jesse Taube
2026-08-12 18:21   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 07/13] scsi: scsi_transport_fc: Add set_rport_marginal to fc_function_template Jesse Taube
2026-08-12 18:28   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 08/13] scsi: scsi_transport_fc: user support for clearing NVME_CTRL_MARGINAL Jesse Taube
2026-08-12 18:24   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 09/13] nvme-fc: add nvme_fc_set_remoteport_fpin() Jesse Taube
2026-08-12 18:27   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 10/13] scsi: qla2xxx: enable FPIN notification for NVMe Jesse Taube
2026-08-12 18:34   ` sashiko-bot [this message]
2026-08-12 19:38     ` Jesse Taube
2026-08-12 18:12 ` [PATCH 11/13] scsi: lpfc: " Jesse Taube
2026-08-12 18:35   ` sashiko-bot
2026-08-12 18:12 ` [PATCH 12/13] nvme: fcloop: Add set_rport_marginal to sysfs Jesse Taube
2026-08-12 18:31   ` sashiko-bot
2026-08-12 18:34   ` Jesse Taube
2026-08-12 18:13 ` [PATCH 13/13] docs: nvme-multipath: Add FC-NVMe marginal state Jesse Taube
2026-08-12 18:26   ` sashiko-bot
2026-08-12 18:46   ` Randy Dunlap
2026-08-12 18:50     ` Randy Dunlap

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260812183447.69D111F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=jtaubepe@redhat.com \
    --cc=linux-scsi@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.