From: Nilay Shroff <nilay@linux.ibm.com>
To: linux-nvme@lists.infradead.org
Cc: hch@lst.de, kbusch@kernel.org, sagi@grimberg.me,
gjoyce@linux.ibm.com, chaitanyak@nvidia.com,
Nilay Shroff <nilay@linux.ibm.com>
Subject: [PATCH 0/2] nvmet: passthru cleanup and fixup I/O hotpath
Date: Fri, 25 Sep 2026 16:51:08 +0530 [thread overview]
Message-ID: <20260925112120.790530-1-nilay@linux.ibm.com> (raw)
Hi,
This series addresses a race in the passthru I/O hotpath where
concurrently disabling the passthru controller while I/Os are in flight
can result in a use-after-free bug.
We were able to reproduce this bug with NVMe/TCP configured and by
injecting an additional delay into the target-side I/O processing code.
If the passthru controller is disabled while an I/O is still in flight,
it results in the following kernel crash:
BUG: Kernel NULL pointer dereference on read at 0x00000030
[...]
CPU: 9 UID: 0 PID: 4143 Comm: kworker/9:5H Kdump: loaded Not tainted 7.3.0-rc3+ #14 PREEMPT
Hardware name: IBM,9080-HEX Power11 (architected) 0x820200 0xf000007 of:IBM,FW1110.00 (NH1110_031) hv:phyp pSeries
Workqueue: nvmet_tcp_wq nvmet_tcp_io_work [nvmet_tcp]
[...]
NIP [c0080000156d8fe0] nvmet_passthru_execute_cmd+0x58/0x45c [nvmet]
LR [c0080000156d8fc4] nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet]
Call Trace:
nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet] (unreliable)
nvmet_tcp_done_recv_pdu+0x2d0/0x718 [nvmet_tcp]
nvmet_tcp_try_recv_pdu+0x29c/0x348 [nvmet_tcp]
nvmet_tcp_io_work+0xe8/0x838 [nvmet_tcp]
process_one_work+0x224/0x5ec
worker_thread+0x1f8/0x3e8
kthread+0x178/0x1ac
start_kernel_thread+0x14/0x18
There are two patches in this series. The first patch groups all
passthru-related fields into a separate struct nvmet_passthru, which
makes the code easier to maintain and reason about. The second patch
fixes the kernel bug described above.
As usual, code review comments and feedback are most welcome!
Thanks!
Nilay Shroff (2):
nvmet: introduce struct nvmet_passthru
nvmet: fix use-after-free error in passthru I/O hotpath
drivers/nvme/target/configfs.c | 45 +++++++++--------
drivers/nvme/target/core.c | 6 ++-
drivers/nvme/target/nvmet.h | 41 +++++++++++++---
drivers/nvme/target/passthru.c | 88 +++++++++++++++++++++++++---------
4 files changed, 130 insertions(+), 50 deletions(-)
--
2.53.0
next reply other threads:[~2026-09-25 11:21 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 11:21 Nilay Shroff [this message]
2026-09-25 11:21 ` [PATCH 1/2] nvmet: introduce struct nvmet_passthru Nilay Shroff
2026-09-28 5:10 ` Christoph Hellwig
2026-09-28 6:35 ` Nilay Shroff
2026-09-25 11:21 ` [PATCH 2/2] nvmet: fix use-after-free error in passthru I/O hotpath Nilay Shroff
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925112120.790530-1-nilay@linux.ibm.com \
--to=nilay@linux.ibm.com \
--cc=chaitanyak@nvidia.com \
--cc=gjoyce@linux.ibm.com \
--cc=hch@lst.de \
--cc=kbusch@kernel.org \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox