Linux-NVME Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Nilay Shroff <nilay@linux.ibm.com>
To: linux-nvme@lists.infradead.org
Cc: hch@lst.de, kbusch@kernel.org, sagi@grimberg.me,
	gjoyce@linux.ibm.com, chaitanyak@nvidia.com,
	Nilay Shroff <nilay@linux.ibm.com>
Subject: [PATCH 0/2] nvmet: passthru cleanup and fixup I/O hotpath
Date: Fri, 25 Sep 2026 16:51:08 +0530	[thread overview]
Message-ID: <20260925112120.790530-1-nilay@linux.ibm.com> (raw)

Hi,

This series addresses a race in the passthru I/O hotpath where
concurrently disabling the passthru controller while I/Os are in flight
can result in a use-after-free bug.

We were able to reproduce this bug with NVMe/TCP configured and by
injecting an additional delay into the target-side I/O processing code.
If the passthru controller is disabled while an I/O is still in flight,
it results in the following kernel crash:

BUG: Kernel NULL pointer dereference on read at 0x00000030
[...]
CPU: 9 UID: 0 PID: 4143 Comm: kworker/9:5H Kdump: loaded Not tainted 7.3.0-rc3+ #14 PREEMPT 
Hardware name: IBM,9080-HEX Power11 (architected) 0x820200 0xf000007 of:IBM,FW1110.00 (NH1110_031) hv:phyp pSeries
Workqueue: nvmet_tcp_wq nvmet_tcp_io_work [nvmet_tcp]
[...]
NIP [c0080000156d8fe0] nvmet_passthru_execute_cmd+0x58/0x45c [nvmet]
LR [c0080000156d8fc4] nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet]
Call Trace:
 nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet] (unreliable)
 nvmet_tcp_done_recv_pdu+0x2d0/0x718 [nvmet_tcp]
 nvmet_tcp_try_recv_pdu+0x29c/0x348 [nvmet_tcp]
 nvmet_tcp_io_work+0xe8/0x838 [nvmet_tcp]
 process_one_work+0x224/0x5ec
 worker_thread+0x1f8/0x3e8
 kthread+0x178/0x1ac
 start_kernel_thread+0x14/0x18

There are two patches in this series. The first patch groups all
passthru-related fields into a separate struct nvmet_passthru, which
makes the code easier to maintain and reason about. The second patch
fixes the kernel bug described above.

As usual, code review comments and feedback are most welcome!

Thanks!

Nilay Shroff (2):
  nvmet: introduce struct nvmet_passthru
  nvmet: fix use-after-free error in passthru I/O hotpath

 drivers/nvme/target/configfs.c | 45 +++++++++--------
 drivers/nvme/target/core.c     |  6 ++-
 drivers/nvme/target/nvmet.h    | 41 +++++++++++++---
 drivers/nvme/target/passthru.c | 88 +++++++++++++++++++++++++---------
 4 files changed, 130 insertions(+), 50 deletions(-)

-- 
2.53.0



             reply	other threads:[~2026-09-25 11:21 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 11:21 Nilay Shroff [this message]
2026-09-25 11:21 ` [PATCH 1/2] nvmet: introduce struct nvmet_passthru Nilay Shroff
2026-09-28  5:10   ` Christoph Hellwig
2026-09-28  6:35     ` Nilay Shroff
2026-09-25 11:21 ` [PATCH 2/2] nvmet: fix use-after-free error in passthru I/O hotpath Nilay Shroff

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925112120.790530-1-nilay@linux.ibm.com \
    --to=nilay@linux.ibm.com \
    --cc=chaitanyak@nvidia.com \
    --cc=gjoyce@linux.ibm.com \
    --cc=hch@lst.de \
    --cc=kbusch@kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=sagi@grimberg.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox