mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: torvalds@linux-foundation.org, akpm@linux-foundation.org,
	alan@lxorguk.ukuu.org.uk,
	Sebastian Andrzej Siewior <bigeasy@linutronix.de>,
	Christoph Hellwig <hch@lst.de>,
	Nicholas Bellinger <nab@linux-iscsi.org>
Subject: [26/53] target/file: walk properly over sg list
Date: Fri, 16 Dec 2011 11:45:23 -0800	[thread overview]
Message-ID: <20111216194558.238199484@clark.kroah.org> (raw)
In-Reply-To: <20111216194613.GA18395@kroah.com>

3.1-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>

commit 9649fa1b8764f64c8cc4293e197e14cd46fe7205 upstream.

This patch changes fileio to use for_each_sg() when walking se_task->task_sg
memory passed into from loopback LLD struct scsi_cmnd scatterlist memory.

This addresses an issue where FILEIO backends with loopback where hitting the
following OOPs with mkfs.ext2:

|kernel BUG at include/linux/scatterlist.h:97!
|invalid opcode: 0000 [#1] PREEMPT SMP
|Modules linked in: sd_mod tcm_loop target_core_stgt scsi_tgt target_core_pscsi target_core_file target_core_iblock target_core_mod configfs scsi_mod
|
|Pid: 671, comm: LIO_fileio Not tainted 3.1.0-rc10+ #139 Bochs Bochs
|EIP: 0060:[<e0afd746>] EFLAGS: 00010202 CPU: 0
|EIP is at fd_do_task+0x396/0x420 [target_core_file]
| [<e0aa7884>] __transport_execute_tasks+0xd4/0x190 [target_core_mod]
| [<e0aa797c>] transport_execute_tasks+0x3c/0xf0 [target_core_mod]
|EIP: [<e0afd746>] fd_do_task+0x396/0x420 [target_core_file] SS:ESP 0068:dea47e90

Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Christoph Hellwig <hch@lst.de>
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 drivers/target/target_core_file.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/drivers/target/target_core_file.c
+++ b/drivers/target/target_core_file.c
@@ -288,9 +288,9 @@ static int fd_do_readv(struct se_task *t
 		return -ENOMEM;
 	}
 
-	for (i = 0; i < task->task_sg_nents; i++) {
-		iov[i].iov_len = sg[i].length;
-		iov[i].iov_base = sg_virt(&sg[i]);
+	for_each_sg(task->task_sg, sg, task->task_sg_nents, i) {
+		iov[i].iov_len = sg->length;
+		iov[i].iov_base = sg_virt(sg);
 	}
 
 	old_fs = get_fs();
@@ -340,9 +340,9 @@ static int fd_do_writev(struct se_task *
 		return -ENOMEM;
 	}
 
-	for (i = 0; i < task->task_sg_nents; i++) {
-		iov[i].iov_len = sg[i].length;
-		iov[i].iov_base = sg_virt(&sg[i]);
+	for_each_sg(task->task_sg, sg, task->task_sg_nents, i) {
+		iov[i].iov_len = sg->length;
+		iov[i].iov_base = sg_virt(sg);
 	}
 
 	old_fs = get_fs();



  parent reply	other threads:[~2011-12-16 20:07 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-12-16 19:46 [00/53] 3.1.6-stable review Greg KH
2011-12-16 19:44 ` [01/53] ALSA: sis7019 - give slow codecs more time to reset Greg KH
2011-12-16 19:44 ` [02/53] ALSA: hda/realtek - Fix Oops in alc_mux_select() Greg KH
2011-12-16 19:45 ` [03/53] ALSA: hda - Fix GPIO LED setup for IDT 92HD75 codecs Greg KH
2011-12-16 19:45 ` [04/53] alarmtimers: Fix time comparison Greg KH
2011-12-16 19:45 ` [05/53] ARM: davinci: da850 evm: change audio edma event queue to EVENTQ_0 Greg KH
2011-12-16 19:45 ` [06/53] arm: mx23: recognise stmp378x as mx23 Greg KH
2011-12-16 19:45 ` [07/53] ARM: at91: fix clock conid for atmel_tcb.1 on 9260/9g20 Greg KH
2011-12-16 19:45 ` [08/53] ARM: at91: Fix USB AT91 gadget registration Greg KH
2011-12-16 19:45 ` [09/53] ARM: davinci: dm646x evm: wrong register used in setup_vpif_input_channel_mode Greg KH
2011-12-16 19:45 ` [10/53] ASoC: Provide a more complete DMA driver stub Greg KH
2011-12-16 19:45 ` [11/53] drivers/rtc/rtc-s3c.c: fix driver clock enable/disable balance issues Greg KH
2011-12-16 19:45 ` [12/53] fs/proc/meminfo.c: fix compilation error Greg KH
2011-12-16 19:45 ` [13/53] thp: add compound tail page _mapcount when mapped Greg KH
2011-12-16 19:45 ` [14/53] thp: set compound tail page _count to zero Greg KH
2011-12-16 19:45 ` [15/53] lockdep, kmemcheck: Annotate ->lock in lockdep_init_map() Greg KH
2011-12-16 19:45 ` [16/53] ptp: Fix clock_getres() implementation Greg KH
2011-12-16 19:45 ` [17/53] mm: Ensure that pfn_valid() is called once per pageblock when reserving pageblocks Greg KH
2011-12-16 19:45 ` [18/53] mm: vmalloc: check for page allocation failure before vmlist insertion Greg KH
2011-12-16 19:45 ` [19/53] fix apparmor dereferencing potentially freed dentry, sanitize __d_path() API Greg KH
2011-12-16 19:45 ` [20/53] TOMOYO: Fix pathname handling of disconnected paths Greg KH
2011-12-16 19:45 ` [21/53] target: Reject SCSI data overflow for fabrics using transport_generic_map_mem_to_cmd Greg KH
2011-12-16 19:45 ` [22/53] iscsi-target: Fix residual count hanlding + remove iscsi_cmd->residual_count Greg KH
2011-12-16 19:45 ` [23/53] target: Handle 0 correctly in transport_get_sectors_6() Greg KH
2011-12-16 19:45 ` [24/53] target: Fix page length in emulated INQUIRY VPD page 86h Greg KH
2011-12-16 19:45 ` [25/53] iscsi-target: Add missing F_BIT for iscsi_tm_rsp Greg KH
2011-12-16 19:45 ` Greg KH [this message]
2011-12-16 19:45 ` [27/53] percpu: fix chunk range calculation Greg KH
2011-12-16 19:45 ` [28/53] cifs: check for NULL last_entry before calling cifs_save_resume_key Greg KH
2011-12-16 19:45 ` [29/53] linux/log2.h: Fix rounddown_pow_of_two(1) Greg KH
2011-12-16 19:45 ` [30/53] hwmon: (jz4740) fix signedness bug Greg KH
2011-12-16 19:45 ` [31/53] ARM: 7204/1: arch/arm/kernel/setup.c: initialize arm_dma_zone_size earlier Greg KH
2011-12-16 19:45 ` [32/53] mmc: mxcmmc: fix falling back to PIO Greg KH
2011-12-16 19:45 ` [33/53] xen/pm_idle: Make pm_idle be default_idle under Xen Greg KH
2011-12-16 19:45 ` [34/53] x86, hpet: Immediately disable HPET timer 1 if rtc irq is masked Greg KH
2011-12-16 19:45 ` [35/53] jbd/jbd2: validate sb->s_first in journal_get_superblock() Greg KH
2011-12-16 19:45 ` [36/53] hfs: fix hfs_find_init() sb->ext_tree NULL ptr oops Greg KH
2011-12-16 19:45 ` [37/53] drm/radeon/kms: cleanup atombios_adjust_pll() Greg KH
2011-12-16 19:45 ` [38/53] drm/radeon/kms: rework DP bridge checks Greg KH
2011-12-16 19:45 ` [39/53] drm/radeon/kms: fix DP setup on TRAVIS bridges Greg KH
2011-12-16 19:45 ` [40/53] xen: only limit memory map to maximum reservation for domain 0 Greg KH
2011-12-16 19:45 ` [41/53] ext4: fix ext4_end_io_dio() racing against fsync() Greg KH
2011-12-16 19:45 ` [42/53] ext4: display the correct mount option in /proc/mounts for [no]init_itable Greg KH
2011-12-16 19:45 ` [43/53] ext4: avoid hangs in ext4_da_should_update_i_disksize() Greg KH
2011-12-16 19:45 ` [44/53] ext4: avoid potential hang in mpage_submit_io() when blocksize < pagesize Greg KH
2011-12-16 19:45 ` [45/53] ext4: handle EOF correctly in ext4_bio_write_page() Greg KH
2011-12-16 19:45 ` [46/53] fuse: fix fuse_retrieve Greg KH
2011-12-16 19:45 ` [47/53] fuse: fix llseek bug Greg KH
2011-12-16 19:45 ` [48/53] staging: r8712u: Add new USB ID Greg KH
2011-12-16 19:45 ` [49/53] drm/radeon/kms: add some new pci ids Greg KH
2011-12-16 19:45 ` [50/53] ibft: Fix finding IBFT ACPI table on UEFI Greg KH
2011-12-16 19:45 ` [51/53] USB: cdc-acm: add IDs for Motorola H24 HSPA USB module Greg KH
2011-12-16 19:45 ` [52/53] usb: option: Add Huawei E398 controlling interfaces Greg KH
2011-12-16 19:45 ` [53/53] USB: option: Removing one bogus and adding some new Huawei combinations Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20111216194558.238199484@clark.kroah.org \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=bigeasy@linutronix.de \
    --cc=hch@lst.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nab@linux-iscsi.org \
    --cc=stable@vger.kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®