Linux block layer
 help / color / mirror / Atom feed
From: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
To: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
Cc: linux-block@vger.kernel.org, Daniel Wagner <dwagner@suse.de>,
	 Hannes Reinecke <hare@suse.de>,
	linux-nvme@lists.infradead.org
Subject: Re: [PATCH blktests] nvme/071: add a test for fcloop LS request use-after-free
Date: Wed, 23 Sep 2026 17:33:26 +0900	[thread overview]
Message-ID: <arOLaz8NSnz6bqL2@shinmob> (raw)
In-Reply-To: <20260921145659.17151-1-ngocthang2710.1999@gmail.com>

On Sep 21, 2026 / 21:56, Nguyen Ngoc Thang wrote:
> Delete the fcloop remote port and then the target port while an
> association is being deleted. The Disconnect Association LS is completed
> from a work item that can run after nvmet_fc_unregister_targetport() freed
> the pending request, which KASAN reports as a use-after-free in
> fcloop_tport_lsrqst_work().

It is the better to note which kernel side fix is related to this test case.
I suggest to note the commit title of the kernel fix here.

  If its git hash could be noted, it would be the best, but the fix is not
  yet applied, so we can not do that yet.


When I tried to run this test case, I often observed the test run hanged.
The hang was observed with v7.3-rc4 kernel. It was observed even with the
v2 fix patch [*]. Do you observe hangs on your test systems?

[*] https://lore.kernel.org/linux-nvme/20260921145651.17131-1-ngocthang2710.1999@gmail.com/

Also, please find my comments in line. Thanks!

> 
> Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@gmail.com>
> ---
>  tests/nvme/071     | 70 ++++++++++++++++++++++++++++++++++++++++++++++
>  tests/nvme/071.out |  2 ++
>  2 files changed, 72 insertions(+)
>  create mode 100755 tests/nvme/071
>  create mode 100644 tests/nvme/071.out
> 
> diff --git a/tests/nvme/071 b/tests/nvme/071
> new file mode 100755
> index 0000000..d17ef18
> --- /dev/null
> +++ b/tests/nvme/071
> @@ -0,0 +1,70 @@
> +#!/bin/bash
> +# SPDX-License-Identifier: GPL-3.0+
> +# Copyright (C) 2026 Nguyen Ngoc Thang
> +#
> +# Regression test for a use-after-free in fcloop when the target port is
> +# deleted right after the remote port. Deleting the association sends a
> +# Disconnect Association LS whose completion is queued while
> +# nvmet_fc_unregister_targetport() is flushing nvmet_wq. The pending LS request
> +# was freed before that completion ran.

I suggest to the note the kernel side fix commit here too.

> +
> +. tests/nvme/rc
> +
> +DESCRIPTION="delete fcloop target port right after remote port"
> +QUICK=1
> +
> +requires() {
> +	_nvme_requires
> +	_have_loop
> +	_require_nvme_trtype fc
> +}
> +
> +set_conditions() {
> +	_set_nvme_trtype "$@"
> +}
> +
> +test() {
> +	echo "Running ${TEST_NAME}"
> +
> +	_setup_nvmet
> +
> +	local i ports port host_port

Nit: ports is an array, so I suggest to seprarte it from other variables and
declare it as an array:

        local -a ports

> +
> +	_nvmet_target_setup
> +
> +	_get_nvmet_ports "${def_subsysnqn}" ports
> +	port="${ports[0]}"
> +	host_port="${ports_to_hosts[${port}]}"

common/nvme provides _get_fc_host_port(). Let's use it to avoid the
reference to the global variable.

> +
> +	for ((i = 0; i < 20; i++)); do
> +		_nvme_connect_subsys
> +		sleep 0.05
> +
> +		# Deleting the association sends a Disconnect Association LS.
> +		_remove_nvmet_subsystem_from_port "${port}" "${def_subsysnqn}"
> +		sleep "0.00$(printf "%02d" "${i}")"

Is there any reason to variate the sleep time here?

I tried to recreate the KASAN use-after-free using v7.3-rc4 kernel, but I was
not able to do it on my test node. I modified the above line to "sleep 0", then
I was able to recreate the failure. I guess the sleep lengths f
r KASAN recreation could be test system dependent.

  reply	other threads:[~2026-09-23  8:33 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 14:56 [PATCH blktests] nvme/071: add a test for fcloop LS request use-after-free Nguyen Ngoc Thang
2026-09-23  8:33 ` Shin'ichiro Kawasaki [this message]
2026-09-23 13:53   ` Nguyen Ngoc Thang
2026-09-23 13:49 ` [PATCH blktests v2] " Nguyen Ngoc Thang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=arOLaz8NSnz6bqL2@shinmob \
    --to=shinichiro.kawasaki@wdc.com \
    --cc=dwagner@suse.de \
    --cc=hare@suse.de \
    --cc=linux-block@vger.kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=ngocthang2710.1999@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox