* [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
@ 2026-08-17 22:13 Ivy Lopez
2026-08-17 22:30 ` sashiko-bot
` (3 more replies)
0 siblings, 4 replies; 8+ messages in thread
From: Ivy Lopez @ 2026-08-17 22:13 UTC (permalink / raw)
To: Sathya Prakash
Cc: Sreekanth Reddy, Suganath Prabu Subramani, Ranjan Kumar,
James E . J . Bottomley, Martin K . Petersen, MPT-FusionLinux.pdl,
linux-scsi, linux-kernel, Ivy Lopez
dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
topology information for the PCI device, such as single-socket
boards that don't expose device-to-node affinity. Passing -1
directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
an out-of-bounds array read caught by UBSAN:
UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
index -1 is out of range for type 'cpumask *[1024]'
Fall back to cpu_online_mask when no NUMA node is available, rather
than assuming dev_to_node() always returns a valid node index.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
---
drivers/scsi/mpt3sas/mpt3sas_base.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
index 79052f2accbd..eaad6fb7f3cf 100644
--- a/drivers/scsi/mpt3sas/mpt3sas_base.c
+++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
@@ -3238,7 +3238,9 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
* corresponding to high iops queues.
*/
if (ioc->high_iops_queues) {
- mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
+ int node = (dev_to_node(&ioc->pdev->dev));
+
+ mask = (node == NUMA_NO_NODE) ? cpu_online_mask : cpumask_of_node(node);
for (index = 0; index < ioc->high_iops_queues;
index++) {
irq = pci_irq_vector(ioc->pdev, index);
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-17 22:13 [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Ivy Lopez
@ 2026-08-17 22:30 ` sashiko-bot
2026-08-18 12:46 ` Johannes Thumshirn
` (2 subsequent siblings)
3 siblings, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-08-17 22:30 UTC (permalink / raw)
To: Ivy Lopez; +Cc: linux-scsi
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Incorrect calculation of remaining MSI-X queues causes a Division by Zero kernel panic or severe IO imbalance.
--
--- Patch [1]: [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() ---
commit 2577a38cb04664cd3aa266df2234da5f8d4aff10
Author: Ivy Lopez <skunkolee@gmail.com>
scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
Fixes an out-of-bounds array read in cpumask_of_node() by checking if
dev_to_node() returns NUMA_NO_NODE. If so, it falls back to cpu_online_mask
instead of using the invalid NUMA node index.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
> diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
> index fed7aeffec58d..b354cbcd12741 100644
> --- a/drivers/scsi/mpt3sas/mpt3sas_base.c
> +++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
> @@ -3238,7 +3238,9 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
> * corresponding to high iops queues.
> */
> if (ioc->high_iops_queues) {
> - mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
> + int node = (dev_to_node(&ioc->pdev->dev));
> +
> + mask = (node == NUMA_NO_NODE) ? cpu_online_mask : cpumask_of_node(node);
> for (index = 0; index < ioc->high_iops_queues;
> index++) {
> irq = pci_irq_vector(ioc->pdev, index);
[ ... ]
[Severity: High]
This is a pre-existing issue, but I noticed a potential division by zero
later in drivers/scsi/mpt3sas/mpt3sas_base.c:_base_assign_reply_queues():
fall_back:
cpu = cpumask_first(cpu_online_mask);
nr_msix -= (ioc->high_iops_queues - iopoll_q_count);
index = 0;
list_for_each_entry(reply_q, &ioc->reply_queue_list, list) {
unsigned int i, group = nr_cpus / nr_msix;
Can this result in a division by zero panic?
If iopoll_q_count == 0 and all available vectors are assigned to
high_iops_queues, nr_msix becomes 0. The list loop unconditionally computes
group = nr_cpus / nr_msix before checking if the queue is a default queue,
triggering a division by zero.
Additionally, does the fallback logic incorrectly add the poll queues instead
of subtracting them when iopoll_q_count > 0? This would shrink the CPU group
size and could cause unassigned CPUs to fall back to a single queue.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260817221300.43286-1-skunkolee@gmail.com?part=1
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-17 22:13 [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Ivy Lopez
2026-08-17 22:30 ` sashiko-bot
@ 2026-08-18 12:46 ` Johannes Thumshirn
2026-08-18 15:09 ` John Garry
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
3 siblings, 0 replies; 8+ messages in thread
From: Johannes Thumshirn @ 2026-08-18 12:46 UTC (permalink / raw)
To: Ivy Lopez
Cc: Sathya Prakash, Sreekanth Reddy, Suganath Prabu Subramani,
Ranjan Kumar, James E . J . Bottomley, Martin K . Petersen,
MPT-FusionLinux.pdl, linux-scsi, linux-kernel
On Mon, Aug 17, 2026 at 04:13:00PM -0600, Ivy Lopez wrote:
> dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
> topology information for the PCI device, such as single-socket
> boards that don't expose device-to-node affinity. Passing -1
> directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
> an out-of-bounds array read caught by UBSAN:
>
> UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
> index -1 is out of range for type 'cpumask *[1024]'
>
> Fall back to cpu_online_mask when no NUMA node is available, rather
> than assuming dev_to_node() always returns a valid node index.
>
> Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
> Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
> ---
> drivers/scsi/mpt3sas/mpt3sas_base.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
> index 79052f2accbd..eaad6fb7f3cf 100644
> --- a/drivers/scsi/mpt3sas/mpt3sas_base.c
> +++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
> @@ -3238,7 +3238,9 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
> * corresponding to high iops queues.
> */
> if (ioc->high_iops_queues) {
> - mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
> + int node = (dev_to_node(&ioc->pdev->dev));
Why the superfluous parenthesis?
> +
> + mask = (node == NUMA_NO_NODE) ? cpu_online_mask : cpumask_of_node(node);
Overly long line here.
> for (index = 0; index < ioc->high_iops_queues;
> index++) {
> irq = pci_irq_vector(ioc->pdev, index);
> --
> 2.55.0
>
>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-17 22:13 [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Ivy Lopez
2026-08-17 22:30 ` sashiko-bot
2026-08-18 12:46 ` Johannes Thumshirn
@ 2026-08-18 15:09 ` John Garry
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
3 siblings, 0 replies; 8+ messages in thread
From: John Garry @ 2026-08-18 15:09 UTC (permalink / raw)
To: Ivy Lopez, Sathya Prakash
Cc: Sreekanth Reddy, Suganath Prabu Subramani, Ranjan Kumar,
James E . J . Bottomley, Martin K . Petersen, MPT-FusionLinux.pdl,
linux-scsi, linux-kernel
On 17/08/2026 23:13, Ivy Lopez wrote:
> dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
> topology information for the PCI device, such as single-socket
> boards that don't expose device-to-node affinity.
I think that this problem would have appeared by now for this driver (if
it were really a problem).
However, for CONFIG_NUMA=n dev_to_node() always returns NUMA_NO_NODE.
> Passing -1
> directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
> an out-of-bounds array read caught by UBSAN:
>
> UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
> index -1 is out of range for type 'cpumask *[1024]'
x86 seems to be only arch which has this problem now.
I have tried unsuccessfully to fix it:
https://lore.kernel.org/lkml/20260107094007.966496-5-john.g.garry@oracle.com/
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH v2] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-17 22:13 [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Ivy Lopez
` (2 preceding siblings ...)
2026-08-18 15:09 ` John Garry
@ 2026-08-25 19:03 ` Ivy Lopez
2026-08-25 19:17 ` sashiko-bot
` (2 more replies)
3 siblings, 3 replies; 8+ messages in thread
From: Ivy Lopez @ 2026-08-25 19:03 UTC (permalink / raw)
To: sathya.prakash, sreekanth.reddy, suganath-prabu.subramani,
ranjan.kumar
Cc: James.Bottomley, martin.petersen, MPT-FusionLinux.pdl, linux-scsi,
linux-kernel, johannes.thumshirn, john.g.garry, Ivy Lopez
dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
topology information for the PCI device, such as single-socket
boards that don't expose device-to-node affinity. Passing -1
directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
an out-of-bounds array read caught by UBSAN:
UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
index -1 is out of range for type 'cpumask *[1024]'
Fall back to cpu_online_mask when no NUMA node is available, rather
than assuming dev_to_node() always returns a valid node index.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
Suggested-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Fixes: 728bbc6cbff7 ("scsi: mpt3sas: Affinity high iops queues IRQs to local node")
Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
---
Changes in v2:
- Drop superfluous parentheses around dev_to_node() call.
- Split overly long ternary assignment line.
- Add Fixes: tag per checkpatch --strict suggestion.
- Link to v1: https://lore.kernel.org/r/20260817221300.43286-1-skunkolee@gmail.com
drivers/scsi/mpt3sas/mpt3sas_base.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
index 79052f2accbd..ce5a5882acc8 100644
--- a/drivers/scsi/mpt3sas/mpt3sas_base.c
+++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
@@ -3238,7 +3238,10 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
* corresponding to high iops queues.
*/
if (ioc->high_iops_queues) {
- mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
+ int node = dev_to_node(&ioc->pdev->dev);
+
+ mask = (node == NUMA_NO_NODE) ?
+ cpu_online_mask : cpumask_of_node(node);
for (index = 0; index < ioc->high_iops_queues;
index++) {
irq = pci_irq_vector(ioc->pdev, index);
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH v2] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
@ 2026-08-25 19:17 ` sashiko-bot
2026-09-01 10:21 ` John Garry
2026-09-03 3:10 ` Martin K. Petersen (Oracle)
2 siblings, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-08-25 19:17 UTC (permalink / raw)
To: Ivy Lopez; +Cc: linux-scsi
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but incorrect subtraction in the fall_back path causes unassigned CPUs in the msix table and a potential divide by zero if nr_msix evaluates to zero.
--
commit 9e90c3b985462523aebc40d2af67de713d3be849
Author: Ivy Lopez <skunkolee@gmail.com>
scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
topology information for the PCI device, such as single-socket
boards that don't expose device-to-node affinity. Fall back to
cpu_online_mask when no NUMA node is available, rather than assuming
dev_to_node() always returns a valid node index.
Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
> diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
> index fed7aeffec58d..1af25a22611a1 100644
> --- a/drivers/scsi/mpt3sas/mpt3sas_base.c
> +++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
> @@ -3238,7 +3238,10 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
> * corresponding to high iops queues.
> */
> if (ioc->high_iops_queues) {
> - mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
> + int node = dev_to_node(&ioc->pdev->dev);
> +
> + mask = (node == NUMA_NO_NODE) ?
> + cpu_online_mask : cpumask_of_node(node);
> for (index = 0; index < ioc->high_iops_queues;
> index++) {
> irq = pci_irq_vector(ioc->pdev, index);
[Severity: High]
This isn't a bug introduced by this patch, but incorrect subtraction in the
fall_back path causes unassigned CPUs in the msix table and a potential
divide by zero.
In _base_assign_reply_queues(), the calculation evaluates incorrectly:
drivers/scsi/mpt3sas/mpt3sas_base.c:_base_assign_reply_queues() {
...
fall_back:
cpu = cpumask_first(cpu_online_mask);
nr_msix -= (ioc->high_iops_queues - iopoll_q_count);
index = 0;
list_for_each_entry(reply_q, &ioc->reply_queue_list, list) {
unsigned int i, group = nr_cpus / nr_msix;
...
}
If iopoll_q_count > 0, the calculation nr_msix -= (ioc->high_iops_queues -
iopoll_q_count) evaluates to nr_msix - high_iops_queues + iopoll_q_count.
This mathematically adds iopoll_q_count instead of subtracting it, inflating
nr_msix. This causes group = nr_cpus / nr_msix to calculate a smaller group
size, leaving trailing CPUs mapped to vector 0.
Furthermore, if PCI MSI-X allocation limits nr_msix to exactly
high_iops_queues (e.g. system interrupt limits), nr_msix evaluates to 0.
This would trigger a hardware divide-by-zero exception when evaluating
nr_cpus / nr_msix.
Is it possible to rewrite this subtraction to avoid inflating nr_msix and
prevent a potential divide-by-zero?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260825190313.24013-1-skunkolee@gmail.com?part=1
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH v2] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
2026-08-25 19:17 ` sashiko-bot
@ 2026-09-01 10:21 ` John Garry
2026-09-03 3:10 ` Martin K. Petersen (Oracle)
2 siblings, 0 replies; 8+ messages in thread
From: John Garry @ 2026-09-01 10:21 UTC (permalink / raw)
To: Ivy Lopez, sathya.prakash, sreekanth.reddy,
suganath-prabu.subramani, ranjan.kumar
Cc: James.Bottomley, martin.petersen, MPT-FusionLinux.pdl, linux-scsi,
linux-kernel, johannes.thumshirn
Reviewed-by: John Garry <john.g.garry@oracle.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH v2] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
2026-08-25 19:17 ` sashiko-bot
2026-09-01 10:21 ` John Garry
@ 2026-09-03 3:10 ` Martin K. Petersen (Oracle)
2 siblings, 0 replies; 8+ messages in thread
From: Martin K. Petersen (Oracle) @ 2026-09-03 3:10 UTC (permalink / raw)
To: sathya.prakash, sreekanth.reddy, suganath-prabu.subramani,
ranjan.kumar, Ivy Lopez
Cc: Martin K . Petersen, James.Bottomley, MPT-FusionLinux.pdl,
linux-scsi, linux-kernel, johannes.thumshirn, john.g.garry
On Tue, 25 Aug 2026 13:03:13 -0600, Ivy Lopez wrote:
> dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
> topology information for the PCI device, such as single-socket
> boards that don't expose device-to-node affinity. Passing -1
> directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
> an out-of-bounds array read caught by UBSAN:
>
> UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
> index -1 is out of range for type 'cpumask *[1024]'
>
> [...]
Applied to 7.3/scsi-fixes, thanks!
[1/1] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()
https://git.kernel.org/mkp/scsi/c/e0d26fe176a8
--
Martin K. Petersen
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-03 3:10 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-17 22:13 [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues() Ivy Lopez
2026-08-17 22:30 ` sashiko-bot
2026-08-18 12:46 ` Johannes Thumshirn
2026-08-18 15:09 ` John Garry
2026-08-25 19:03 ` [PATCH v2] " Ivy Lopez
2026-08-25 19:17 ` sashiko-bot
2026-09-01 10:21 ` John Garry
2026-09-03 3:10 ` Martin K. Petersen (Oracle)
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.