Linux SCSI subsystem development
 help / color / mirror / Atom feed
* [PATCH v2] scsi: libfc: fix directory server rport memory leak
@ 2026-09-24 13:34 Guangshuo Li
  2026-09-24 14:16 ` Greg KH
  0 siblings, 1 reply; 2+ messages in thread
From: Guangshuo Li @ 2026-09-24 13:34 UTC (permalink / raw)
  To: Hannes Reinecke, James E.J. Bottomley, Martin K. Petersen,
	James Bottomley, Joe Eykholt, Robert Love, linux-scsi,
	linux-kernel
  Cc: Guangshuo Li, stable

fc_rport_create() does not add FC_FID_DIR_SERV rports to
lport->disc.rports. If fc_frame_alloc() fails in
fc_rport_recv_plogi_req() after creating a directory server rport, its
initial reference is not released through the normal rport teardown
path.

Normal rports are added to lport->disc.rports and removed from the list
before their initial reference is dropped. The directory server rport
bypasses both operations.

Add directory server rports to lport->disc.rports and use the existing
list removal path when they are deleted. Keep the existing directory
server callback and retry behavior unchanged.

The issue was identified by a static analysis tool I developed and
confirmed by manual review.

Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
v2:
  - Add directory server rports to the discovery rport list and use the
    existing teardown path, as suggested by Hannes Reinecke.
  - Preserve the existing LLDD callback and retry behavior for directory
    server rports.

 drivers/scsi/libfc/fc_rport.c | 12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c
index c25979d96808..eac3fde1246a 100644
--- a/drivers/scsi/libfc/fc_rport.c
+++ b/drivers/scsi/libfc/fc_rport.c
@@ -160,10 +160,9 @@ struct fc_rport_priv *fc_rport_create(struct fc_lport *lport, u32 port_id)
 	rdata->maxframe_size = FC_MIN_MAX_PAYLOAD;
 	INIT_DELAYED_WORK(&rdata->retry_work, fc_rport_timeout);
 	INIT_WORK(&rdata->event_work, fc_rport_work);
-	if (port_id != FC_FID_DIR_SERV) {
+	if (port_id != FC_FID_DIR_SERV)
 		rdata->lld_event_callback = lport->tt.rport_event_callback;
-		list_add_rcu(&rdata->peers, &lport->disc.rports);
-	}
+	list_add_rcu(&rdata->peers, &lport->disc.rports);
 	return rdata;
 }
 EXPORT_SYMBOL(fc_rport_create);
@@ -363,11 +362,8 @@ static void fc_rport_work(struct work_struct *work)
 
 		mutex_lock(&rdata->rp_mutex);
 		if (rdata->rp_state == RPORT_ST_DELETE) {
-			if (port_id == FC_FID_DIR_SERV) {
-				rdata->event = RPORT_EV_NONE;
-				mutex_unlock(&rdata->rp_mutex);
-				kref_put(&rdata->kref, fc_rport_destroy);
-			} else if ((rdata->flags & FC_RP_STARTED) &&
+			if (port_id != FC_FID_DIR_SERV &&
+			    (rdata->flags & FC_RP_STARTED) &&
 				   rdata->major_retries <
 				   lport->max_rport_retry_count) {
 				rdata->major_retries++;
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] scsi: libfc: fix directory server rport memory leak
  2026-09-24 13:34 [PATCH v2] scsi: libfc: fix directory server rport memory leak Guangshuo Li
@ 2026-09-24 14:16 ` Greg KH
  0 siblings, 0 replies; 2+ messages in thread
From: Greg KH @ 2026-09-24 14:16 UTC (permalink / raw)
  To: Guangshuo Li
  Cc: Hannes Reinecke, James E.J. Bottomley, Martin K. Petersen,
	James Bottomley, Joe Eykholt, Robert Love, linux-scsi,
	linux-kernel, stable

On Thu, Sep 24, 2026 at 09:34:29PM +0800, Guangshuo Li wrote:
> fc_rport_create() does not add FC_FID_DIR_SERV rports to
> lport->disc.rports. If fc_frame_alloc() fails in
> fc_rport_recv_plogi_req() after creating a directory server rport, its
> initial reference is not released through the normal rport teardown
> path.
> 
> Normal rports are added to lport->disc.rports and removed from the list
> before their initial reference is dropped. The directory server rport
> bypasses both operations.
> 
> Add directory server rports to lport->disc.rports and use the existing
> list removal path when they are deleted. Keep the existing directory
> server callback and retry behavior unchanged.
> 
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.

Great, please document that as is asked for in the kernel documentation
in the changelog here please.

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-24 14:16 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 13:34 [PATCH v2] scsi: libfc: fix directory server rport memory leak Guangshuo Li
2026-09-24 14:16 ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox