From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Quinn Tran <qutran@marvell.com>,
Himanshu Madhani <himanshu.madhani@oracle.com>,
Nilesh Javali <njavali@marvell.com>,
"Martin K . Petersen" <martin.petersen@oracle.com>,
Sasha Levin <sashal@kernel.org>,
linux-scsi@vger.kernel.org
Subject: [PATCH AUTOSEL 5.4 30/38] scsi: qla2xxx: Fix null pointer access during disconnect from subsystem
Date: Mon, 24 Aug 2020 12:37:42 -0400 [thread overview]
Message-ID: <20200824163751.606577-30-sashal@kernel.org> (raw)
In-Reply-To: <20200824163751.606577-1-sashal@kernel.org>
From: Quinn Tran <qutran@marvell.com>
[ Upstream commit 83949613fac61e8e37eadf8275bf072342302f4e ]
NVMEAsync command is being submitted to QLA while the same NVMe controller
is in the middle of reset. The reset path has deleted the association and
freed aen_op->fcp_req.private. Add a check for this private pointer before
issuing the command.
...
6 [ffffb656ca11fce0] page_fault at ffffffff8c00114e
[exception RIP: qla_nvme_post_cmd+394]
RIP: ffffffffc0d012ba RSP: ffffb656ca11fd98 RFLAGS: 00010206
RAX: ffff8fb039eda228 RBX: ffff8fb039eda200 RCX: 00000000000da161
RDX: ffffffffc0d4d0f0 RSI: ffffffffc0d26c9b RDI: ffff8fb039eda220
RBP: 0000000000000013 R8: ffff8fb47ff6aa80 R9: 0000000000000002
R10: 0000000000000000 R11: ffffb656ca11fdc8 R12: ffff8fb27d04a3b0
R13: ffff8fc46dd98a58 R14: 0000000000000000 R15: ffff8fc4540f0000
ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018
7 [ffffb656ca11fe08] nvme_fc_start_fcp_op at ffffffffc0241568 [nvme_fc]
8 [ffffb656ca11fe50] nvme_fc_submit_async_event at ffffffffc0241901 [nvme_fc]
9 [ffffb656ca11fe68] nvme_async_event_work at ffffffffc014543d [nvme_core]
10 [ffffb656ca11fe98] process_one_work at ffffffff8b6cd437
11 [ffffb656ca11fed8] worker_thread at ffffffff8b6cdcef
12 [ffffb656ca11ff10] kthread at ffffffff8b6d3402
13 [ffffb656ca11ff50] ret_from_fork at ffffffff8c000255
--
PID: 37824 TASK: ffff8fb033063d80 CPU: 20 COMMAND: "kworker/u97:451"
0 [ffffb656ce1abc28] __schedule at ffffffff8be629e3
1 [ffffb656ce1abcc8] schedule at ffffffff8be62fe8
2 [ffffb656ce1abcd0] schedule_timeout at ffffffff8be671ed
3 [ffffb656ce1abd70] wait_for_completion at ffffffff8be639cf
4 [ffffb656ce1abdd0] flush_work at ffffffff8b6ce2d5
5 [ffffb656ce1abe70] nvme_stop_ctrl at ffffffffc0144900 [nvme_core]
6 [ffffb656ce1abe80] nvme_fc_reset_ctrl_work at ffffffffc0243445 [nvme_fc]
7 [ffffb656ce1abe98] process_one_work at ffffffff8b6cd437
8 [ffffb656ce1abed8] worker_thread at ffffffff8b6cdb50
9 [ffffb656ce1abf10] kthread at ffffffff8b6d3402
10 [ffffb656ce1abf50] ret_from_fork at ffffffff8c000255
Link: https://lore.kernel.org/r/20200806111014.28434-10-njavali@marvell.com
Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com>
Signed-off-by: Quinn Tran <qutran@marvell.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_nvme.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/scsi/qla2xxx/qla_nvme.c b/drivers/scsi/qla2xxx/qla_nvme.c
index 941aa53363f56..f4815a4084d8c 100644
--- a/drivers/scsi/qla2xxx/qla_nvme.c
+++ b/drivers/scsi/qla2xxx/qla_nvme.c
@@ -535,6 +535,11 @@ static int qla_nvme_post_cmd(struct nvme_fc_local_port *lport,
struct nvme_private *priv = fd->private;
struct qla_nvme_rport *qla_rport = rport->private;
+ if (!priv) {
+ /* nvme association has been torn down */
+ return rval;
+ }
+
fcport = qla_rport->fcport;
if (!qpair || !fcport || (qpair && !qpair->fw_started) ||
--
2.25.1
next prev parent reply other threads:[~2020-08-24 17:02 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-08-24 16:37 [PATCH AUTOSEL 5.4 01/38] spi: stm32: clear only asserted irq flags on interrupt Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 02/38] jbd2: make sure jh have b_transaction set in refile/unfile_buffer Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 03/38] ext4: don't BUG on inconsistent journal feature Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 04/38] ext4: handle read only external journal device Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 05/38] jbd2: abort journal if free a async write error metadata buffer Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 06/38] ext4: handle option set by mount flags correctly Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 07/38] ext4: handle error of ext4_setup_system_zone() on remount Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 08/38] ext4: correctly restore system zone info when remount fails Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 09/38] fs: prevent BUG_ON in submit_bh_wbc() Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 10/38] spi: stm32h7: fix race condition at end of transfer Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 11/38] spi: stm32: fix fifo threshold level in case of short transfer Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 12/38] spi: stm32: fix stm32_spi_prepare_mbr in case of odd clk_rate Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 13/38] spi: stm32: always perform registers configuration prior to transfer Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 14/38] drm/amd/powerplay: correct Vega20 cached smu feature state Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 15/38] drm/amd/powerplay: correct UVD/VCE PG state on custom pptable uploading Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 16/38] drm/amd/display: Switch to immediate mode for updating infopackets Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 17/38] libbpf: Handle GCC built-in types for Arm NEON Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 18/38] netfilter: avoid ipv6 -> nf_defrag_ipv6 module dependency Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 19/38] can: j1939: transport: j1939_xtp_rx_dat_one(): compare own packets to detect corruptions Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 20/38] ALSA: hda/realtek: Add model alc298-samsung-headphone Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 21/38] s390/cio: add cond_resched() in the slow_eval_known_fn() loop Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 22/38] ASoC: wm8994: Avoid attempts to read unreadable registers Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 23/38] selftests: disable rp_filter for icmp_redirect.sh Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 24/38] scsi: fcoe: Fix I/O path allocation Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 25/38] scsi: ufs: Fix possible infinite loop in ufshcd_hold Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 26/38] scsi: ufs: Improve interrupt handling for shared interrupts Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 27/38] scsi: ufs: Clean up completed request without interrupt notification Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 28/38] scsi: qla2xxx: Fix login timeout Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 29/38] scsi: qla2xxx: Check if FW supports MQ before enabling Sasha Levin
2020-08-24 16:37 ` Sasha Levin [this message]
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 31/38] Revert "scsi: qla2xxx: Fix crash on qla2x00_mailbox_command" Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 32/38] macvlan: validate setting of multiple remote source MAC addresses Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 33/38] net: gianfar: Add of_node_put() before goto statement Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 34/38] drm/amdgpu: disable gfxoff for navy_flounder Sasha Levin
2020-08-24 18:25 ` Alex Deucher
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 35/38] Revert "drm/amdgpu: disable gfxoff for navy_flounder" Sasha Levin
2020-08-24 18:25 ` Alex Deucher
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 36/38] powerpc/perf: Fix soft lockups due to missed interrupt accounting Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 37/38] arm64: Move handling of erratum 1418040 into C code Sasha Levin
2020-08-24 16:37 ` [PATCH AUTOSEL 5.4 38/38] arm64: Allow booting of late CPUs affected by erratum 1418040 Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200824163751.606577-30-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=himanshu.madhani@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=njavali@marvell.com \
--cc=qutran@marvell.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome