* [PATCH v2 1/2] nvmet: introduce struct nvmet_passthru
2026-09-29 11:26 [PATCH v2 0/2] nvmet: passthru cleanup and fixup I/O hotpath Nilay Shroff
@ 2026-09-29 11:26 ` Nilay Shroff
2026-09-29 11:26 ` [PATCH v2 2/2] nvmet: fix use-after-free in passthru I/O hotpath Nilay Shroff
1 sibling, 0 replies; 3+ messages in thread
From: Nilay Shroff @ 2026-09-29 11:26 UTC (permalink / raw)
To: linux-nvme; +Cc: hch, kbusch, sagi, gjoyce, chaitanyak, Nilay Shroff
Currently, passthru parameters are grouped under struct nvmet_subsys.
Since passthru can be configured through configfs and all passthru
parameters are exposed under a separate configfs subdirectory, group
these parameters under a new struct nvmet_passthru.
Grouping passthru-specific parameters in a separate structure makes
the code easier to maintain and reason about.
This also allows the passthru structure to be allocated on demand,
avoiding the memory overhead for subsystems that do not use passthru.
The structure is allocated when passthru configuration is needed and
its configfs attributes are accessed under subsys->lock. The passthru
configfs group is still created when the subsystem is allocated.
There are no functional changes intended.
Signed-off-by: Nilay Shroff <nilay@linux.ibm.com>
---
drivers/nvme/target/configfs.c | 90 +++++++++++++++++++++++++++++-----
drivers/nvme/target/core.c | 12 ++++-
drivers/nvme/target/nvmet.h | 34 ++++++++++---
drivers/nvme/target/passthru.c | 52 ++++++++++++--------
4 files changed, 148 insertions(+), 40 deletions(-)
diff --git a/drivers/nvme/target/configfs.c b/drivers/nvme/target/configfs.c
index b03b5d1c2dc3..6bac66c48bff 100644
--- a/drivers/nvme/target/configfs.c
+++ b/drivers/nvme/target/configfs.c
@@ -905,21 +905,34 @@ static ssize_t nvmet_passthru_device_path_show(struct config_item *item,
char *page)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ ssize_t ret;
- return snprintf(page, PAGE_SIZE, "%s\n", subsys->passthru_ctrl_path);
+ mutex_lock(&subsys->lock);
+ ret = snprintf(page, PAGE_SIZE, "%s\n",
+ subsys->passthru && subsys->passthru->ctrl_path ?
+ subsys->passthru->ctrl_path : "");
+ mutex_unlock(&subsys->lock);
+ return ret;
}
static ssize_t nvmet_passthru_device_path_store(struct config_item *item,
const char *page, size_t count)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ struct nvmet_passthru *passthru;
size_t len;
int ret;
mutex_lock(&subsys->lock);
+ passthru = nvmet_subsys_passthru(subsys);
+ if (!passthru) {
+ ret = -ENOMEM;
+ goto out_unlock;
+ }
+
ret = -EBUSY;
- if (subsys->passthru_ctrl)
+ if (passthru->ctrl)
goto out_unlock;
ret = -EINVAL;
@@ -927,10 +940,10 @@ static ssize_t nvmet_passthru_device_path_store(struct config_item *item,
if (!len)
goto out_unlock;
- kfree(subsys->passthru_ctrl_path);
+ kfree(passthru->ctrl_path);
ret = -ENOMEM;
- subsys->passthru_ctrl_path = kstrndup(page, len, GFP_KERNEL);
- if (!subsys->passthru_ctrl_path)
+ passthru->ctrl_path = kstrndup(page, len, GFP_KERNEL);
+ if (!passthru->ctrl_path)
goto out_unlock;
mutex_unlock(&subsys->lock);
@@ -946,8 +959,13 @@ static ssize_t nvmet_passthru_enable_show(struct config_item *item,
char *page)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ ssize_t ret;
- return sprintf(page, "%d\n", subsys->passthru_ctrl ? 1 : 0);
+ mutex_lock(&subsys->lock);
+ ret = sprintf(page, "%d\n",
+ subsys->passthru && subsys->passthru->ctrl ? 1 : 0);
+ mutex_unlock(&subsys->lock);
+ return ret;
}
static ssize_t nvmet_passthru_enable_store(struct config_item *item,
@@ -972,18 +990,34 @@ CONFIGFS_ATTR(nvmet_passthru_, enable);
static ssize_t nvmet_passthru_admin_timeout_show(struct config_item *item,
char *page)
{
- return sprintf(page, "%u\n", to_subsys(item->ci_parent)->admin_timeout);
+ struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ ssize_t ret;
+
+ mutex_lock(&subsys->lock);
+ ret = sprintf(page, "%u\n", subsys->passthru ?
+ subsys->passthru->admin_timeout : 0);
+ mutex_unlock(&subsys->lock);
+ return ret;
}
static ssize_t nvmet_passthru_admin_timeout_store(struct config_item *item,
const char *page, size_t count)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ struct nvmet_passthru *passthru;
unsigned int timeout;
if (kstrtouint(page, 0, &timeout))
return -EINVAL;
- subsys->admin_timeout = timeout;
+
+ mutex_lock(&subsys->lock);
+ passthru = nvmet_subsys_passthru(subsys);
+ if (!passthru) {
+ mutex_unlock(&subsys->lock);
+ return -ENOMEM;
+ }
+ passthru->admin_timeout = timeout;
+ mutex_unlock(&subsys->lock);
return count;
}
CONFIGFS_ATTR(nvmet_passthru_, admin_timeout);
@@ -991,18 +1025,34 @@ CONFIGFS_ATTR(nvmet_passthru_, admin_timeout);
static ssize_t nvmet_passthru_io_timeout_show(struct config_item *item,
char *page)
{
- return sprintf(page, "%u\n", to_subsys(item->ci_parent)->io_timeout);
+ struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ ssize_t ret;
+
+ mutex_lock(&subsys->lock);
+ ret = sprintf(page, "%u\n",
+ subsys->passthru ? subsys->passthru->io_timeout : 0);
+ mutex_unlock(&subsys->lock);
+ return ret;
}
static ssize_t nvmet_passthru_io_timeout_store(struct config_item *item,
const char *page, size_t count)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ struct nvmet_passthru *passthru;
unsigned int timeout;
if (kstrtouint(page, 0, &timeout))
return -EINVAL;
- subsys->io_timeout = timeout;
+
+ mutex_lock(&subsys->lock);
+ passthru = nvmet_subsys_passthru(subsys);
+ if (!passthru) {
+ mutex_unlock(&subsys->lock);
+ return -ENOMEM;
+ }
+ passthru->io_timeout = timeout;
+ mutex_unlock(&subsys->lock);
return count;
}
CONFIGFS_ATTR(nvmet_passthru_, io_timeout);
@@ -1010,18 +1060,34 @@ CONFIGFS_ATTR(nvmet_passthru_, io_timeout);
static ssize_t nvmet_passthru_clear_ids_show(struct config_item *item,
char *page)
{
- return sprintf(page, "%u\n", to_subsys(item->ci_parent)->clear_ids);
+ struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ ssize_t ret;
+
+ mutex_lock(&subsys->lock);
+ ret = sprintf(page, "%u\n",
+ subsys->passthru ? subsys->passthru->clear_ids : 0);
+ mutex_unlock(&subsys->lock);
+ return ret;
}
static ssize_t nvmet_passthru_clear_ids_store(struct config_item *item,
const char *page, size_t count)
{
struct nvmet_subsys *subsys = to_subsys(item->ci_parent);
+ struct nvmet_passthru *passthru;
unsigned int clear_ids;
if (kstrtouint(page, 0, &clear_ids))
return -EINVAL;
- subsys->clear_ids = clear_ids;
+
+ mutex_lock(&subsys->lock);
+ passthru = nvmet_subsys_passthru(subsys);
+ if (!passthru) {
+ mutex_unlock(&subsys->lock);
+ return -ENOMEM;
+ }
+ passthru->clear_ids = clear_ids;
+ mutex_unlock(&subsys->lock);
return count;
}
CONFIGFS_ATTR(nvmet_passthru_, clear_ids);
diff --git a/drivers/nvme/target/core.c b/drivers/nvme/target/core.c
index 8eea0a504308..b09681cb4a1f 100644
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -1645,8 +1645,16 @@ struct nvmet_ctrl *nvmet_alloc_ctrl(struct nvmet_alloc_ctrl_args *args)
#ifdef CONFIG_NVME_TARGET_PASSTHRU
/* By default, set loop targets to clear IDS by default */
- if (ctrl->port->disc_addr.trtype == NVMF_TRTYPE_LOOP)
- subsys->clear_ids = 1;
+ if (ctrl->port->disc_addr.trtype == NVMF_TRTYPE_LOOP) {
+ mutex_lock(&subsys->lock);
+ subsys->passthru = nvmet_subsys_passthru(subsys);
+ if (!subsys->passthru) {
+ mutex_unlock(&subsys->lock);
+ goto out_free_ctrl;
+ }
+ subsys->passthru->clear_ids = 1;
+ mutex_unlock(&subsys->lock);
+ }
#endif
INIT_WORK(&ctrl->async_event_work, nvmet_async_event_work);
diff --git a/drivers/nvme/target/nvmet.h b/drivers/nvme/target/nvmet.h
index 162e2fdd848e..eb0f965b1a7e 100644
--- a/drivers/nvme/target/nvmet.h
+++ b/drivers/nvme/target/nvmet.h
@@ -319,6 +319,14 @@ struct nvmet_ctrl {
struct nvmet_pr_log_mgr pr_log_mgr;
};
+struct nvmet_passthru {
+ struct nvme_ctrl *ctrl;
+ char *ctrl_path;
+ unsigned int admin_timeout;
+ unsigned int io_timeout;
+ unsigned int clear_ids;
+};
+
struct nvmet_subsys {
enum nvme_subsys_type type;
@@ -358,12 +366,8 @@ struct nvmet_subsys {
char *firmware_rev;
#ifdef CONFIG_NVME_TARGET_PASSTHRU
- struct nvme_ctrl *passthru_ctrl;
- char *passthru_ctrl_path;
+ struct nvmet_passthru *passthru;
struct config_group passthru_group;
- unsigned int admin_timeout;
- unsigned int io_timeout;
- unsigned int clear_ids;
#endif /* CONFIG_NVME_TARGET_PASSTHRU */
#ifdef CONFIG_BLK_DEV_ZONED
@@ -793,7 +797,20 @@ u16 nvmet_parse_passthru_admin_cmd(struct nvmet_req *req);
u16 nvmet_parse_passthru_io_cmd(struct nvmet_req *req);
static inline bool nvmet_is_passthru_subsys(struct nvmet_subsys *subsys)
{
- return subsys->passthru_ctrl;
+ return subsys->passthru && subsys->passthru->ctrl;
+}
+
+static inline struct nvmet_passthru *nvmet_subsys_passthru(
+ struct nvmet_subsys *subsys)
+{
+ lockdep_assert_held(&subsys->lock);
+
+ if (!subsys->passthru) {
+ subsys->passthru = kzalloc_obj(*subsys->passthru);
+ if (!subsys->passthru)
+ return NULL;
+ }
+ return subsys->passthru;
}
#else /* CONFIG_NVME_TARGET_PASSTHRU */
static inline void nvmet_passthru_subsys_free(struct nvmet_subsys *subsys)
@@ -814,6 +831,11 @@ static inline bool nvmet_is_passthru_subsys(struct nvmet_subsys *subsys)
{
return NULL;
}
+static inline struct nvmet_passthru *nvmet_subsys_passthru(
+ struct nvmet_subsys *subsys)
+{
+ return NULL;
+}
#endif /* CONFIG_NVME_TARGET_PASSTHRU */
static inline bool nvmet_is_passthru_req(struct nvmet_req *req)
diff --git a/drivers/nvme/target/passthru.c b/drivers/nvme/target/passthru.c
index fa6527c537e2..16cd3fdf98ec 100644
--- a/drivers/nvme/target/passthru.c
+++ b/drivers/nvme/target/passthru.c
@@ -26,7 +26,7 @@ void nvmet_passthrough_override_cap(struct nvmet_ctrl *ctrl)
* Multiple command set support can only be declared if the underlying
* controller actually supports it.
*/
- if (!nvme_multi_css(ctrl->subsys->passthru_ctrl))
+ if (!nvme_multi_css(ctrl->subsys->passthru->ctrl))
ctrl->cap &= ~(1ULL << 43);
}
@@ -39,7 +39,7 @@ static u16 nvmet_passthru_override_id_descs(struct nvmet_req *req)
void *data;
u8 csi;
- if (!ctrl->subsys->clear_ids)
+ if (!ctrl->subsys->passthru->clear_ids)
return status;
data = kzalloc(NVME_IDENTIFY_DATA_SIZE, GFP_KERNEL);
@@ -89,7 +89,7 @@ static u16 nvmet_passthru_override_id_descs(struct nvmet_req *req)
static u16 nvmet_passthru_override_id_ctrl(struct nvmet_req *req)
{
struct nvmet_ctrl *ctrl = req->sq->ctrl;
- struct nvme_ctrl *pctrl = ctrl->subsys->passthru_ctrl;
+ struct nvme_ctrl *pctrl = ctrl->subsys->passthru->ctrl;
u16 status = NVME_SC_SUCCESS;
struct nvme_id_ctrl *id;
unsigned int max_hw_sectors;
@@ -208,7 +208,7 @@ static u16 nvmet_passthru_override_id_ns(struct nvmet_req *req)
*/
id->mc = 0;
- if (req->sq->ctrl->subsys->clear_ids) {
+ if (req->sq->ctrl->subsys->passthru->clear_ids) {
memset(id->nguid, 0, NVME_NIDT_NGUID_LEN);
memset(id->eui64, 0, NVME_NIDT_EUI64_LEN);
}
@@ -305,7 +305,8 @@ static int nvmet_passthru_map_sg(struct nvmet_req *req, struct request *rq)
static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
{
- struct nvme_ctrl *ctrl = nvmet_req_subsys(req)->passthru_ctrl;
+ struct nvmet_passthru *passthru = nvmet_req_subsys(req)->passthru;
+ struct nvme_ctrl *ctrl = passthru->ctrl;
struct request_queue *q = ctrl->admin_q;
struct nvme_ns *ns = NULL;
struct request *rq = NULL;
@@ -325,9 +326,9 @@ static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
}
q = ns->queue;
- timeout = nvmet_req_subsys(req)->io_timeout;
+ timeout = passthru->io_timeout;
} else {
- timeout = nvmet_req_subsys(req)->admin_timeout;
+ timeout = passthru->admin_timeout;
}
rq = blk_mq_alloc_request(q, nvme_req_op(req->cmd), 0);
@@ -386,7 +387,7 @@ static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
*/
static void nvmet_passthru_set_host_behaviour(struct nvmet_req *req)
{
- struct nvme_ctrl *ctrl = nvmet_req_subsys(req)->passthru_ctrl;
+ struct nvme_ctrl *ctrl = nvmet_req_subsys(req)->passthru->ctrl;
struct nvme_feat_host_behavior *host;
u16 status = NVME_SC_INTERNAL;
int ret;
@@ -586,15 +587,17 @@ u16 nvmet_parse_passthru_admin_cmd(struct nvmet_req *req)
int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
{
+ struct nvmet_passthru *passthru;
struct nvme_ctrl *ctrl;
struct file *file;
int ret = -EINVAL;
void *old;
mutex_lock(&subsys->lock);
- if (!subsys->passthru_ctrl_path)
+ passthru = subsys->passthru;
+ if (!passthru || !passthru->ctrl_path)
goto out_unlock;
- if (subsys->passthru_ctrl)
+ if (passthru->ctrl)
goto out_unlock;
if (subsys->nr_namespaces) {
@@ -602,7 +605,7 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
goto out_unlock;
}
- file = filp_open(subsys->passthru_ctrl_path, O_RDWR, 0);
+ file = filp_open(passthru->ctrl_path, O_RDWR, 0);
if (IS_ERR(file)) {
ret = PTR_ERR(file);
goto out_unlock;
@@ -611,7 +614,7 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
ctrl = nvme_ctrl_from_file(file);
if (!ctrl) {
pr_err("failed to open nvme controller %s\n",
- subsys->passthru_ctrl_path);
+ passthru->ctrl_path);
goto out_put_file;
}
@@ -626,7 +629,7 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
if (old)
goto out_put_file;
- subsys->passthru_ctrl = ctrl;
+ passthru->ctrl = ctrl;
subsys->ver = ctrl->vs;
if (subsys->ver < NVME_VS(1, 2, 1)) {
@@ -636,7 +639,7 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
subsys->ver = NVME_VS(1, 2, 1);
}
nvme_get_ctrl(ctrl);
- __module_get(subsys->passthru_ctrl->ops->module);
+ __module_get(passthru->ctrl->ops->module);
ret = 0;
out_put_file:
@@ -648,12 +651,17 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
static void __nvmet_passthru_ctrl_disable(struct nvmet_subsys *subsys)
{
- if (subsys->passthru_ctrl) {
- xa_erase(&passthru_subsystems, subsys->passthru_ctrl->instance);
- module_put(subsys->passthru_ctrl->ops->module);
- nvme_put_ctrl(subsys->passthru_ctrl);
+ struct nvmet_passthru *passthru = subsys->passthru;
+
+ if (!passthru)
+ return;
+
+ if (passthru->ctrl) {
+ xa_erase(&passthru_subsystems, passthru->ctrl->instance);
+ module_put(passthru->ctrl->ops->module);
+ nvme_put_ctrl(passthru->ctrl);
}
- subsys->passthru_ctrl = NULL;
+ passthru->ctrl = NULL;
subsys->ver = NVMET_DEFAULT_VS;
}
@@ -668,6 +676,10 @@ void nvmet_passthru_subsys_free(struct nvmet_subsys *subsys)
{
mutex_lock(&subsys->lock);
__nvmet_passthru_ctrl_disable(subsys);
+ if (subsys->passthru) {
+ kfree(subsys->passthru->ctrl_path);
+ kfree(subsys->passthru);
+ subsys->passthru = NULL;
+ }
mutex_unlock(&subsys->lock);
- kfree(subsys->passthru_ctrl_path);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH v2 2/2] nvmet: fix use-after-free in passthru I/O hotpath
2026-09-29 11:26 [PATCH v2 0/2] nvmet: passthru cleanup and fixup I/O hotpath Nilay Shroff
2026-09-29 11:26 ` [PATCH v2 1/2] nvmet: introduce struct nvmet_passthru Nilay Shroff
@ 2026-09-29 11:26 ` Nilay Shroff
1 sibling, 0 replies; 3+ messages in thread
From: Nilay Shroff @ 2026-09-29 11:26 UTC (permalink / raw)
To: linux-nvme; +Cc: hch, kbusch, sagi, gjoyce, chaitanyak, Nilay Shroff
Concurrently disabling a passthru controller while passthru I/Os are
in flight can potentially result in a use-after-free. Introduce a
percpu refcount, an atomic flag, and an nvmet request flag to protect
the passthru controller lifetime.
When enabling the passthru controller, initialize the percpu refcount
and set the enabled flag. Each passthru I/O acquires a reference before
entering the passthru hotpath and sets an nvmet request flag to record
that the reference is held. The reference is released when the I/O
completes.
When disabling the passthru controller, clear the enabled flag, kill
the percpu refcount, and wait for all in-flight I/Os to release their
references before releasing the passthru controller.
Disable operations are serialized by subsys->lock. The enabled flag
ensures that only the first disable operation proceeds and subsequent
attempts observe the flag as cleared and return.
Once disabling starts, new I/Os either fail to be routed to the
passthru path or fail to acquire a live reference, and therefore cannot
dereference the passthru controller and thus avoid use-after-free.
Signed-off-by: Nilay Shroff <nilay@linux.ibm.com>
---
drivers/nvme/target/core.c | 3 ++
drivers/nvme/target/nvmet.h | 34 +++++++++++++++++-
drivers/nvme/target/passthru.c | 65 +++++++++++++++++++++++++++++-----
3 files changed, 92 insertions(+), 10 deletions(-)
diff --git a/drivers/nvme/target/core.c b/drivers/nvme/target/core.c
index b09681cb4a1f..fa1420065e30 100644
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -819,6 +819,8 @@ static void __nvmet_req_complete(struct nvmet_req *req, u16 status)
nvmet_pr_put_ns_pc_ref(pc_ref);
if (ns)
nvmet_put_namespace(ns);
+
+ nvmet_put_passthru_ref(req);
}
void nvmet_req_complete(struct nvmet_req *req, u16 status)
@@ -1195,6 +1197,7 @@ bool nvmet_req_init(struct nvmet_req *req, struct nvmet_sq *sq,
req->error_loc = NVMET_NO_ERROR_LOC;
req->error_slba = 0;
req->pc_ref = NULL;
+ req->p.ref_held = false;
/* no support for fused commands yet */
if (unlikely(flags & (NVME_CMD_FUSE_FIRST | NVME_CMD_FUSE_SECOND))) {
diff --git a/drivers/nvme/target/nvmet.h b/drivers/nvme/target/nvmet.h
index eb0f965b1a7e..04dc33004cb7 100644
--- a/drivers/nvme/target/nvmet.h
+++ b/drivers/nvme/target/nvmet.h
@@ -320,6 +320,11 @@ struct nvmet_ctrl {
};
struct nvmet_passthru {
+ struct percpu_ref ref;
+ struct completion disable_done;
+#define NVMET_PASSTHRU_ENABLED 0
+ unsigned long flags;
+
struct nvme_ctrl *ctrl;
char *ctrl_path;
unsigned int admin_timeout;
@@ -478,6 +483,7 @@ struct nvmet_req {
struct request *rq;
struct work_struct work;
bool use_workqueue;
+ bool ref_held;
} p;
#ifdef CONFIG_BLK_DEV_ZONED
struct {
@@ -797,7 +803,8 @@ u16 nvmet_parse_passthru_admin_cmd(struct nvmet_req *req);
u16 nvmet_parse_passthru_io_cmd(struct nvmet_req *req);
static inline bool nvmet_is_passthru_subsys(struct nvmet_subsys *subsys)
{
- return subsys->passthru && subsys->passthru->ctrl;
+ return subsys->passthru &&
+ test_bit(NVMET_PASSTHRU_ENABLED, &subsys->passthru->flags);
}
static inline struct nvmet_passthru *nvmet_subsys_passthru(
@@ -812,6 +819,24 @@ static inline struct nvmet_passthru *nvmet_subsys_passthru(
}
return subsys->passthru;
}
+
+static inline bool nvmet_get_passthru_ref(struct nvmet_req *req)
+{
+ if (!percpu_ref_tryget_live(&nvmet_req_subsys(req)->passthru->ref))
+ return false;
+
+ req->p.ref_held = true;
+ return true;
+}
+
+static inline void nvmet_put_passthru_ref(struct nvmet_req *req)
+{
+ if (!req->p.ref_held)
+ return;
+
+ req->p.ref_held = false;
+ percpu_ref_put(&nvmet_req_subsys(req)->passthru->ref);
+}
#else /* CONFIG_NVME_TARGET_PASSTHRU */
static inline void nvmet_passthru_subsys_free(struct nvmet_subsys *subsys)
{
@@ -836,6 +861,13 @@ static inline struct nvmet_passthru *nvmet_subsys_passthru(
{
return NULL;
}
+static inline bool nvmet_get_passthru_ref(struct nvmet_req *req)
+{
+ return false;
+}
+static inline void nvmet_put_passthru_ref(struct nvmet_req *req)
+{
+}
#endif /* CONFIG_NVME_TARGET_PASSTHRU */
static inline bool nvmet_is_passthru_req(struct nvmet_req *req)
diff --git a/drivers/nvme/target/passthru.c b/drivers/nvme/target/passthru.c
index 16cd3fdf98ec..6b67880c7bb2 100644
--- a/drivers/nvme/target/passthru.c
+++ b/drivers/nvme/target/passthru.c
@@ -305,9 +305,9 @@ static int nvmet_passthru_map_sg(struct nvmet_req *req, struct request *rq)
static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
{
- struct nvmet_passthru *passthru = nvmet_req_subsys(req)->passthru;
- struct nvme_ctrl *ctrl = passthru->ctrl;
- struct request_queue *q = ctrl->admin_q;
+ struct nvmet_passthru *passthru;
+ struct nvme_ctrl *ctrl;
+ struct request_queue *q;
struct nvme_ns *ns = NULL;
struct request *rq = NULL;
unsigned int timeout;
@@ -315,6 +315,15 @@ static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
u16 status;
int ret;
+ if (!nvmet_get_passthru_ref(req)) {
+ status = NVME_SC_INTERNAL | NVME_STATUS_DNR;
+ goto out;
+ }
+
+ passthru = nvmet_req_subsys(req)->passthru;
+ ctrl = passthru->ctrl;
+ q = ctrl->admin_q;
+
if (likely(req->sq->qid != 0)) {
u32 nsid = le32_to_cpu(req->cmd->common.nsid);
@@ -387,11 +396,17 @@ static void nvmet_passthru_execute_cmd(struct nvmet_req *req)
*/
static void nvmet_passthru_set_host_behaviour(struct nvmet_req *req)
{
- struct nvme_ctrl *ctrl = nvmet_req_subsys(req)->passthru->ctrl;
+ struct nvme_ctrl *ctrl;
struct nvme_feat_host_behavior *host;
u16 status = NVME_SC_INTERNAL;
int ret;
+ if (!nvmet_get_passthru_ref(req)) {
+ status |= NVME_STATUS_DNR;
+ goto out_complete_req;
+ }
+ ctrl = nvmet_req_subsys(req)->passthru->ctrl;
+
host = kzalloc(sizeof(*host) * 2, GFP_KERNEL);
if (!host)
goto out_complete_req;
@@ -585,6 +600,14 @@ u16 nvmet_parse_passthru_admin_cmd(struct nvmet_req *req)
}
}
+static void nvmet_release_passthru_ctrl(struct percpu_ref *ref)
+{
+ struct nvmet_passthru *passthru = container_of(ref,
+ struct nvmet_passthru, ref);
+
+ complete(&passthru->disable_done);
+}
+
int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
{
struct nvmet_passthru *passthru;
@@ -629,6 +652,13 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
if (old)
goto out_put_file;
+ ret = percpu_ref_init(&passthru->ref, nvmet_release_passthru_ctrl,
+ 0, GFP_KERNEL);
+ if (ret) {
+ xa_erase(&passthru_subsystems, ctrl->instance);
+ goto out_put_file;
+ }
+ init_completion(&passthru->disable_done);
passthru->ctrl = ctrl;
subsys->ver = ctrl->vs;
@@ -640,6 +670,7 @@ int nvmet_passthru_ctrl_enable(struct nvmet_subsys *subsys)
}
nvme_get_ctrl(ctrl);
__module_get(passthru->ctrl->ops->module);
+ set_bit(NVMET_PASSTHRU_ENABLED, &passthru->flags);
ret = 0;
out_put_file:
@@ -653,14 +684,30 @@ static void __nvmet_passthru_ctrl_disable(struct nvmet_subsys *subsys)
{
struct nvmet_passthru *passthru = subsys->passthru;
+ lockdep_assert_held(&subsys->lock);
+
if (!passthru)
return;
- if (passthru->ctrl) {
- xa_erase(&passthru_subsystems, passthru->ctrl->instance);
- module_put(passthru->ctrl->ops->module);
- nvme_put_ctrl(passthru->ctrl);
- }
+ if (!test_and_clear_bit(NVMET_PASSTHRU_ENABLED, &passthru->flags))
+ return;
+
+ mutex_unlock(&subsys->lock);
+ /*
+ * Now new I/Os should not enter passthru hotpath as we cleared the
+ * enabled flag. Kill percpu reference and wait for in-flight I/Os
+ * to drain.
+ */
+ percpu_ref_kill(&passthru->ref);
+ wait_for_completion(&passthru->disable_done);
+ percpu_ref_exit(&passthru->ref);
+
+ mutex_lock(&subsys->lock);
+
+ xa_erase(&passthru_subsystems, passthru->ctrl->instance);
+ module_put(passthru->ctrl->ops->module);
+ nvme_put_ctrl(passthru->ctrl);
+
passthru->ctrl = NULL;
subsys->ver = NVMET_DEFAULT_VS;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread