From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BECB13596F8 for ; Fri, 12 Jun 2026 09:40:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781257233; cv=none; b=ZF92z84zYHJyr1FPzX5ak0tdyhN2c+Sb8eTt1WNOE+hR9A00kGpndapRSjRjwnoPMRkhKvMSantbUA7LWE5GDdlEYCsOEuGrjin/y8ocBdJCkGyuFRGXpkAOmEE+nINsflaswal0qTDdCbNAWg9VgaKn9KXGnLYkCqo/e50hs4Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781257233; c=relaxed/simple; bh=dvvJGP8seoXJbEB71BwDcA4pq9Th3sDnGpORJL37W/Y=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=FiwGehMfp8ixxvHWZoTMX/tBesQ33IilLOIZkqlHLqxOuIibjTi1RdSpCGlFGiPJDDstee+303j/psFNuRWVDleWRWW92kRLg0r/6mhqBDKvL2oP+UgJZUPCpp3MQB74ysgdQ+tlXswQp/N7Vi5KkWl4aD80yIjd1mL4/paPKRw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ULqaJ8fU; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ULqaJ8fU" Received: by smtp.kernel.org (Postfix) with ESMTPS id 188C9C2BCB4; Fri, 12 Jun 2026 09:40:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1781257233; bh=dvvJGP8seoXJbEB71BwDcA4pq9Th3sDnGpORJL37W/Y=; h=From:Date:Subject:To:Cc:From; b=ULqaJ8fUzhj4HVRdD64HPGpbmXE0K/UXbeWVe1pOqxBnR3CjEyNuplpV3rZyYsXiu MsNCYN4Ep2YttrN9u2hj0+ZTkgoAuiNrI70/bixFJ33agDhDbPZ3fGsZm3sSlDlUyI xTttBtY6bOJDEz/dbbWHDdB9kNOh+pEfBvwA9U/2ENNguzuKq5YDAiWGLJ1lqUk9xg B3UL3X3gNO575Izv7Vq2kJl/JvBt+yVMc75qjWGZC0kS9zw6+hxwtIO8loa4v21F3E csc3HXuDsAyP84pohNJkmkDYzyB0UFpHohVS4FINi9OfNHQ8Jy7Q0LMEnrq/t27iwE g3lKUIqoiz/YA== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 00085CD98CE; Fri, 12 Jun 2026 09:40:32 +0000 (UTC) From: Joel Granados Date: Fri, 12 Jun 2026 11:40:23 +0200 Subject: [PATCH] nvme: unmap the data buffer when metadata mapping fails Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260612-jag-fixes-v1-1-24423dc8afdb@kernel.org> X-B4-Tracking: v=1; b=H4sIAAbUK2oC/6tWKk4tykwtVrJSqFYqSi3LLM7MzwNyDHUUlJIzE vPSU3UzU4B8JSMDIzMDM0Mj3azEdN20zIrUYl2zJBNTy9REQ7MUU2MloPqColSwBFB5dGxtLQA lPQ6SWwAAAA== X-Change-ID: 20260612-jag-fixes-6b459ea16d53 To: Keith Busch , Jens Axboe , Christoph Hellwig , Sagi Grimberg Cc: Daniel Gomez , linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org, Joel Granados X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1844; i=joel.granados@kernel.org; h=from:subject:message-id; bh=dvvJGP8seoXJbEB71BwDcA4pq9Th3sDnGpORJL37W/Y=; b=owJ4nAHtARL+kA0DAAoBupfNUreWQU8ByyZiAGor1A9zkZhR0quHNS7DbnQa0qQrZeirRUPDJ WfxBHF28lrPUokBswQAAQoAHRYhBK5HCVcl5jElzssnkLqXzVK3lkFPBQJqK9QPAAoJELqXzVK3 lkFP0ocMAIDSLx7nSaxQ7ggaIDFrId2MZPWz9f1Rw6YK1Vj1JiUN264k04uTf2mRv21tas1tQtX 9+CXnCc4F8USqxZyfeZ32om1CDVOpzr5vuDtIiE/bPl+uhxTvysgMpzOVEAl9Z+JzmvpSClrOct StKUznKNkQOKPFoWh7Cx0/ZdI68xILH9k6k1SE7XkaP0Z7MAqxhRXjyfcKE79z7Se8LTNqNfNgf L6LJp9FnTBcfC9Pnjjuwfr19lXKNNi7ynWQlzF9lsbqEpqk+r5rXbvBAhXB6YfrczfiuaGoaRSO n52pY3PYFWIJtKNIzN+VJixbHJ8gAy+aKa7XiwMaSch37xE1kOSHO7S3+om9bxceXBHnah8pJCE KIUJ0zXwweFDIrtJ+u7Ym86EZ6JmO9J207BKWr+etachqxg7x38WxLU8lfSAMSCHyjbzFNV41Y+ wNBlR+pALmcjIwQmHpwYlNvOaBw6aV8Mt1wh/t+CQCijwfrKuqbUkS/RNeTvHskzKBhGME+DvC5 +Q= X-Developer-Key: i=joel.granados@kernel.org; a=openpgp; fpr=F1F8E46D30F0F6C4A45FF4465895FAAC338C6E77 X-Endpoint-Received: by B4 Relay for joel.granados@kernel.org/default with auth_id=239 Commit d0d1d522316e ("blk-map: provide the bdev to bio if one exists") dropped the "bio = req->bio" assignment in nvme_map_user_request(), but left the local bio variable initialized to NULL and still used it in the out_unmap error path. The "if (bio)" test is therefore always false, so a failure of blk_rq_integrity_map_user() no longer unmaps the already mapped data buffer. The callers only call blk_mq_free_request(), which does not unmap user pages, leaking the bio and its pinned user pages. Use req->bio directly to unmap the data buffer on the error path, and drop the now unused local variable. Fixes: d0d1d522316e ("blk-map: provide the bdev to bio if one exists") Signed-off-by: Joel Granados --- Did we forget to unmap? --- drivers/nvme/host/ioctl.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/drivers/nvme/host/ioctl.c b/drivers/nvme/host/ioctl.c index 9597a87cf05dc32a7eb0373485f575502c32a105..9ae3c0aadfb8f35790c8e57619d1af69ca41af0c 100644 --- a/drivers/nvme/host/ioctl.c +++ b/drivers/nvme/host/ioctl.c @@ -122,7 +122,6 @@ static int nvme_map_user_request(struct request *req, u64 ubuffer, bool supports_metadata = bdev && blk_get_integrity(bdev->bd_disk); struct nvme_ctrl *ctrl = nvme_req(req)->ctrl; bool has_metadata = meta_buffer && meta_len; - struct bio *bio = NULL; int ret; if (!nvme_ctrl_sgl_supported(ctrl)) @@ -154,8 +153,8 @@ static int nvme_map_user_request(struct request *req, u64 ubuffer, return ret; out_unmap: - if (bio) - blk_rq_unmap_user(bio); + if (req->bio) + blk_rq_unmap_user(req->bio); return ret; } --- base-commit: adeac771f4901bb66267eaddb9fcc538925f92a4 change-id: 20260612-jag-fixes-6b459ea16d53 Best regards, -- Joel Granados