From: Stanley Jhu <stanleyjhu@google.com>
To: Jeuk Kim <jeuk20.kim@samsung.com>, qemu-devel@nongnu.org
Cc: Brian Kao <powenkao@google.com>, Stanley Jhu <stanleyjhu@google.com>
Subject: [PATCH v2 1/3] hw/ufs: Track SCSIRequest and cancel pending requests in ufs_clear_req
Date: Wed, 9 Sep 2026 11:11:44 +0800 [thread overview]
Message-ID: <20260909031146.1646684-2-stanleyjhu@google.com> (raw)
In-Reply-To: <20260909031146.1646684-1-stanleyjhu@google.com>
In the UFS emulator, outstanding SCSI requests are dispatched asynchronously
to the block layer via scsi_req_enqueue(). When requests are cleared or
aborted (e.g. during HCE reset or TMR aborts), ufs_clear_req() releases the
scatter-gather list without cancelling the pending SCSIRequest. If an
asynchronous AIO callback completes afterwards, ufs_scsi_command_complete()
dereferences stale or freed request state, resulting in use-after-free
hazards.
Track the active SCSIRequest in UfsRequest and explicitly cancel any in-flight
requests in ufs_clear_req() before freeing request resources. To prevent
dangling references during cancellation cascades, decouple and clear req->sreq
in completion and cancellation handlers.
Signed-off-by: Stanley Jhu <stanleyjhu@google.com>
---
hw/ufs/lu.c | 12 ++++++++++++
hw/ufs/ufs.c | 6 ++++++
hw/ufs/ufs.h | 1 +
3 files changed, 19 insertions(+)
diff --git a/hw/ufs/lu.c b/hw/ufs/lu.c
index bdb1650851..a62ebb51fd 100644
--- a/hw/ufs/lu.c
+++ b/hw/ufs/lu.c
@@ -173,6 +173,12 @@ static void ufs_scsi_command_complete(SCSIRequest *scsi_req, size_t resid)
int16_t status = scsi_req->status;
uint32_t transfered_len = scsi_req->cmd.xfer - resid;
+ if (!req) {
+ return;
+ }
+
+ req->sreq = NULL;
+
/* WB / HID accounting should only happen for successful commands */
if (status == GOOD) {
ufs_wb_process_write_req(req, transfered_len);
@@ -190,6 +196,11 @@ static void ufs_scsi_command_complete(SCSIRequest *scsi_req, size_t resid)
static void ufs_scsi_command_cancelled(SCSIRequest *scsi_req)
{
+ UfsRequest *req = scsi_req->hba_private;
+
+ if (req) {
+ req->sreq = NULL;
+ }
scsi_req->hba_private = NULL;
scsi_req_unref(scsi_req);
}
@@ -389,6 +400,7 @@ static UfsReqResult ufs_process_scsi_cmd(UfsLu *lu, UfsRequest *req)
SCSIRequest *scsi_req =
scsi_req_new(lu->scsi_dev, task_tag, lu->lun, req->req_upiu.sc.cdb,
UFS_CDB_SIZE, req);
+ req->sreq = scsi_req;
uint32_t len = scsi_req_enqueue(scsi_req);
if (len) {
diff --git a/hw/ufs/ufs.c b/hw/ufs/ufs.c
index 3c4d7424da..adae6639e1 100644
--- a/hw/ufs/ufs.c
+++ b/hw/ufs/ufs.c
@@ -2221,6 +2221,12 @@ void ufs_complete_req(UfsRequest *req, UfsReqResult req_result)
static void ufs_clear_req(UfsRequest *req)
{
+ if (req->sreq != NULL) {
+ SCSIRequest *sreq = req->sreq;
+ req->sreq = NULL;
+ scsi_req_cancel(sreq);
+ }
+
if (req->sg != NULL) {
qemu_sglist_destroy(req->sg);
g_free(req->sg);
diff --git a/hw/ufs/ufs.h b/hw/ufs/ufs.h
index 6f2693b7ca..265a43faaa 100644
--- a/hw/ufs/ufs.h
+++ b/hw/ufs/ufs.h
@@ -60,6 +60,7 @@ typedef struct UfsRequest {
UtpUpiuRsp rsp_upiu;
/* for scsi command */
+ SCSIRequest *sreq;
QEMUSGList *sg;
uint32_t data_len;
--
2.55.0.1007.g17ff1f9808-goog
next prev parent reply other threads:[~2026-09-09 3:12 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 3:11 [PATCH v2 0/3] hw/ufs: Support Task Management Request (TMR) and MCQ status registers Stanley Jhu
2026-09-09 3:11 ` Stanley Jhu [this message]
2026-09-23 2:03 ` [PATCH v2 1/3] hw/ufs: Track SCSIRequest and cancel pending requests in ufs_clear_req Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
2026-09-09 3:11 ` [PATCH v2 2/3] hw/ufs: Support MCQ runtime interrupt and queue status registers Stanley Jhu
2026-09-23 2:03 ` Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
2026-09-09 3:11 ` [PATCH v2 3/3] hw/ufs: Implement Task Management Request (TMR) handling Stanley Jhu
2026-09-23 2:03 ` Jeuk Kim
2026-09-23 14:45 ` Stanley Jhu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909031146.1646684-2-stanleyjhu@google.com \
--to=stanleyjhu@google.com \
--cc=jeuk20.kim@samsung.com \
--cc=powenkao@google.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.