Linux-NVME Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] nvmet: passthru cleanup and fixup I/O hotpath
@ 2026-09-25 11:21 Nilay Shroff
  2026-09-25 11:21 ` [PATCH 1/2] nvmet: introduce struct nvmet_passthru Nilay Shroff
  2026-09-25 11:21 ` [PATCH 2/2] nvmet: fix use-after-free error in passthru I/O hotpath Nilay Shroff
  0 siblings, 2 replies; 5+ messages in thread
From: Nilay Shroff @ 2026-09-25 11:21 UTC (permalink / raw)
  To: linux-nvme; +Cc: hch, kbusch, sagi, gjoyce, chaitanyak, Nilay Shroff

Hi,

This series addresses a race in the passthru I/O hotpath where
concurrently disabling the passthru controller while I/Os are in flight
can result in a use-after-free bug.

We were able to reproduce this bug with NVMe/TCP configured and by
injecting an additional delay into the target-side I/O processing code.
If the passthru controller is disabled while an I/O is still in flight,
it results in the following kernel crash:

BUG: Kernel NULL pointer dereference on read at 0x00000030
[...]
CPU: 9 UID: 0 PID: 4143 Comm: kworker/9:5H Kdump: loaded Not tainted 7.3.0-rc3+ #14 PREEMPT 
Hardware name: IBM,9080-HEX Power11 (architected) 0x820200 0xf000007 of:IBM,FW1110.00 (NH1110_031) hv:phyp pSeries
Workqueue: nvmet_tcp_wq nvmet_tcp_io_work [nvmet_tcp]
[...]
NIP [c0080000156d8fe0] nvmet_passthru_execute_cmd+0x58/0x45c [nvmet]
LR [c0080000156d8fc4] nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet]
Call Trace:
 nvmet_passthru_execute_cmd+0x3c/0x45c [nvmet] (unreliable)
 nvmet_tcp_done_recv_pdu+0x2d0/0x718 [nvmet_tcp]
 nvmet_tcp_try_recv_pdu+0x29c/0x348 [nvmet_tcp]
 nvmet_tcp_io_work+0xe8/0x838 [nvmet_tcp]
 process_one_work+0x224/0x5ec
 worker_thread+0x1f8/0x3e8
 kthread+0x178/0x1ac
 start_kernel_thread+0x14/0x18

There are two patches in this series. The first patch groups all
passthru-related fields into a separate struct nvmet_passthru, which
makes the code easier to maintain and reason about. The second patch
fixes the kernel bug described above.

As usual, code review comments and feedback are most welcome!

Thanks!

Nilay Shroff (2):
  nvmet: introduce struct nvmet_passthru
  nvmet: fix use-after-free error in passthru I/O hotpath

 drivers/nvme/target/configfs.c | 45 +++++++++--------
 drivers/nvme/target/core.c     |  6 ++-
 drivers/nvme/target/nvmet.h    | 41 +++++++++++++---
 drivers/nvme/target/passthru.c | 88 +++++++++++++++++++++++++---------
 4 files changed, 130 insertions(+), 50 deletions(-)

-- 
2.53.0



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-28  6:35 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 11:21 [PATCH 0/2] nvmet: passthru cleanup and fixup I/O hotpath Nilay Shroff
2026-09-25 11:21 ` [PATCH 1/2] nvmet: introduce struct nvmet_passthru Nilay Shroff
2026-09-28  5:10   ` Christoph Hellwig
2026-09-28  6:35     ` Nilay Shroff
2026-09-25 11:21 ` [PATCH 2/2] nvmet: fix use-after-free error in passthru I/O hotpath Nilay Shroff

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox