All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] scsi: fnic: fix NVMe/FC local port setup and teardown
@ 2026-08-19 11:42 Linmao Li
  2026-08-19 11:42 ` [PATCH 1/2] scsi: fnic: initialize the NVMe local port info before registering Linmao Li
                   ` (2 more replies)
  0 siblings, 3 replies; 12+ messages in thread
From: Linmao Li @ 2026-08-19 11:42 UTC (permalink / raw)
  To: Satish Kharat, Sesidhar Baddela, Karan Tilak Kumar,
	Martin K . Petersen
  Cc: James E . J . Bottomley, Hannes Reinecke, Justin Tee,
	Naresh Gottumukkala, Paul Ely, linux-nvme, linux-scsi,
	linux-kernel, Linmao Li

Two small fixes to the NVMe/FC transport path added in commit 5efdd5cf9281
("scsi: fnic: Add the NVMe/FC transport path"), both found by reading the
code rather than by hitting them on hardware.  They apply to
scsi/for-next, since that code is not in mainline yet.

Patch 1 initializes struct nvme_fc_port_info in nvfnic_add_lport().
dev_loss_tmo is currently left uninitialized on the stack.  The transport
does not read it for a local port, so this is hygiene rather than a
behaviour fix, and it carries no Fixes tag; nvfnic_add_tport() right below
already memsets its own copy.

Patch 2 moves the kfree() of iport->nv_tmpl out of nvfnic_nvme_unload()
and into nvfnic_local_port_delete().  The template is what the transport
stores in lport->ops, and nvme_fc_unregister_localport() only calls
->localport_delete() inline when no active remote ports are left;
otherwise the call is deferred to nvme_fc_rport_inactive_on_lport(),
which dereferences lport->ops after the unregister has returned.  Today
the driver frees the template even when the removal wait times out, which
leaves the transport with a dangling ->ops.

Note that patch 2 only narrows that one use-after-free.  The rest of the
timeout path still tears the fnic down while the transport holds
lport->private == iport, so that path may deserve a wider look; I did not
want to fold that into a fix.

Patch 2's reasoning rests on the NVMe/FC transport's lifetime rules, so
linux-nvme and the FC transport maintainers are copied for a second
opinion on that argument.

Compile-tested only (allmodconfig, W=1, drivers/scsi/fnic/ clean).  I do
not have Cisco VIC hardware, so neither patch has been tested on a live
adapter.

Linmao Li (2):
  scsi: fnic: initialize the NVMe local port info before registering
  scsi: fnic: free the NVMe port template from the delete callback

 drivers/scsi/fnic/fnic_nvme.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)


base-commit: 30733f28c0347d237ffb5333fdfab7a9a2d4ed34
-- 
2.25.1


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-03  3:10 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19 11:42 [PATCH 0/2] scsi: fnic: fix NVMe/FC local port setup and teardown Linmao Li
2026-08-19 11:42 ` [PATCH 1/2] scsi: fnic: initialize the NVMe local port info before registering Linmao Li
2026-08-23  5:05   ` Karan Tilak Kumar (kartilak)
2026-08-23  5:10     ` Karan Tilak Kumar (kartilak)
2026-08-24  9:54       ` Karan Tilak Kumar (kartilak)
2026-08-29  1:33         ` Martin K. Petersen (Oracle)
2026-08-19 11:42 ` [PATCH 2/2] scsi: fnic: free the NVMe port template from the delete callback Linmao Li
2026-08-19 11:52   ` sashiko-bot
2026-08-19 12:47     ` Linmao Li
2026-08-20  7:30   ` Linmao Li
2026-08-23  5:02     ` Karan Tilak Kumar (kartilak)
2026-09-03  3:10 ` (subset) [PATCH 0/2] scsi: fnic: fix NVMe/FC local port setup and teardown Martin K. Petersen (Oracle)

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.