From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f43.google.com (mail-yx1-f43.google.com [74.125.224.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 76650346A18 for ; Mon, 10 Aug 2026 22:03:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786399382; cv=none; b=YrrtNw1d1qbxaeO+NaEre/EXrSWyvPZRd6qwnvOe2mhg8eEvnX28bsLJK+eSx3+neco6fupEzejKF+wkRKMYd1OtCKqQhcVVSVfKyl9N/xP0MCU10S/I3KMef7vJCBCGrwm1ceVII+V8sHa0p/bJIm9/AOiu9RbwFXn977jfNPo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786399382; c=relaxed/simple; bh=GCHcjtITmV+WOW8kqs5tkCV/zdKQg7jiv76Swgyag58=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=FquTnkw1qOI6xho1NUXukI0Zv6nOlu7/45cqhemLKAsEszN+VeKCN6AEefEwrsNopWSnDhpTNrMjB2ooYe6teHCTzykwcuKbfAN9sYsm6b4kJt+vmhvF1HWYseVEYBFLwMgDaH1m3xTXFSmOJ/t0wOOvWEWcOpWZaYyCl9wSN6w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fzc+nsnl; arc=none smtp.client-ip=74.125.224.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fzc+nsnl" Received: by mail-yx1-f43.google.com with SMTP id 956f58d0204a3-66843304cbaso3405955d50.2 for ; Mon, 10 Aug 2026 15:03:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786399380; x=1787004180; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=L4HJis6zMvRkqVAWz+E140YbLNtXuGOK2SxG+4zvx4c=; b=fzc+nsnlkdp0AprAn6MXN2qhp02J8jWZ0FSO5ZN0jC3dI6gG0W3//qpwYVXRGHs2tm gKnjE+zYIGGQQI4sOhVLEC0sLqj50wTKYXemqXqFj5W/wRklR/9aBVPegQxXS+BDTKYu aths9YfgZ6gJe4hkhUfgMhXTTcKjgc4B3qsOh+QnuXfdqqg6z8XLYK5imGxU2AgKLVAe +shU+LcP5r4Of+1bp2FQAPJWF3g65CNVRj0mOMc+/EVgT+UNBZKdaqK6LjYk9/Jfwkv3 RVS4lhJvfy3cxct5jc0yZjzHqDUl1ebb4HeL6IYYKbAxenaskQ96rNV7KAyIom/84YSE 11+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786399380; x=1787004180; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=L4HJis6zMvRkqVAWz+E140YbLNtXuGOK2SxG+4zvx4c=; b=WBxpnBOkbeNEyS51JXwVtDKZdzdTMk+9uFn44oBlcurPtRXuxw/m/x7yOGXW3FlZYw ompmSRBff5Lt8/O9FJFyEkn79qJTDvXkmLKPtUdc/QCoUML7okSj6YIYQThu5/mTVT4+ DpWkRsagQk/4cNFlwX/ahp+Y17xF9oRaIQx4jxm1/IegBRjWi65CAtRSrriuAP8Oueq0 aShyDJili1hmhBhR4Q4aANJEWjh19TMt71EFLvANFm11fmOcEkfyLobHAKk9+mi3ZC3r iPM1C6YRiuYzd5YHO+ztnQ+usNDG6Vd/BbrOebQgZEizbDXe+3dom8lY0LeGlqO5Q/jQ K3Nw== X-Gm-Message-State: AOJu0YwBwjiBYRV89nnXPiXz5+vJgf4DPZHMDjFGLyZq98EBw9+zzNsV +GxAr0PPHTsYy9lNEw7sTQRIen7OMiMYEXoNIrpZuY8T8syatLqxRz4L41rVDmpG X-Gm-Gg: AR+sD10JLmnOmxpXCEl54M0VFyXe2R0PfgUXUUp6cYAMZMDD20Enr/ypQP2tPLpPeuT Tjua2rcBUUz1+r90t7QHDfOwvfY8gbNgycWWqgXRsMtf3P5JbAUwDqe24T0PXAnQdB/kDbwn0N2 H2s257WGSJC97kzvzVvixpNlaaFh8W97FXEq7YKGVp3B1ModEV0OglA7VpVOfN/Jv/Vfo1wuwI1 68Qnuh27t+pt9hZWMXmBAIvtUB3d9uWPFGTnosCa5lL91zrG0kisYK1HhbElmKK3Kocz+SMWGx7 lnDcYUo4TabzHlgDsUAvm+YY1wxTl0TUufqP6fID1CrDb1xF1RySoMTU94uTIDQhB7Zg6bX0Nxc aoaNA4jAaS4PPcCs9gIXuIEhlMrPx1lncXsx9QAlSW97qp6f28KURIaT+lXKk1/hlj+92OxRxAU tF944ODQz397oZL8OpFw4NQ4K+Nvj/jrxVS4J/LRcdLVerzlMM64Vvk6BE98OsSvaYcfJUpdcoQ 38nWMc= X-Received: by 2002:a05:690e:d43:b0:664:7d5d:4390 with SMTP id 956f58d0204a3-66b122944damr2929855d50.1.1786399380140; Mon, 10 Aug 2026 15:03:00 -0700 (PDT) Received: from syssplab.cs.fiu.edu (nat1.cs.fiu.edu. [131.94.134.89]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-66acae62283sm7139966d50.13.2026.08.10.15.02.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 15:02:59 -0700 (PDT) From: Chao Shi To: Keith Busch , Jens Axboe , Christoph Hellwig , Sagi Grimberg , linux-nvme@lists.infradead.org Cc: linux-kernel@vger.kernel.org Subject: [PATCH] nvme: ratelimit the completion-path messages driven by device data Date: Mon, 10 Aug 2026 18:02:58 -0400 Message-ID: <20260810220258.1960208-1-coshi036@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit nvme_find_rq() and nvme_handle_cqe() print an unratelimited message for every completion queue entry whose command id does not resolve to an in-flight request. Both are reached from the completion interrupt path (nvme_irq() -> nvme_poll_cq() -> nvme_handle_cqe()) and the decision to print is made entirely from device-supplied data, so a controller that posts a stream of bogus command ids drives unbounded printk from hard interrupt context. This is not hypothetical. A single boot under an emulated controller that posts invalid completions produced 846 "could not locate request for tag 0x0", 846 "invalid id 0 completed on queue 2" and 123 "genctr mismatch" lines. Once the tag set has been torn down every subsequent completion resolves to nothing, so the print rate is bounded only by how fast the device can post entries. Ratelimit the three messages. The information they carry is diagnostic and repeats, so the suppression count printed by the ratelimit helpers is enough to tell that the condition persists. This matches how the other device-driven error prints in the driver are already handled, for example the status messages in nvme_log_error() and nvme_log_err_passthru(). nvme_find_rq() lives in nvme.h and is shared by pci, tcp, rdma, apple and target-loop, so all transports are covered. Found by FuzzNvme. Signed-off-by: Chao Shi --- drivers/nvme/host/nvme.h | 11 ++++++----- drivers/nvme/host/pci.c | 6 +++--- 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/drivers/nvme/host/nvme.h b/drivers/nvme/host/nvme.h index ccd5e05dac98..31e771e1b721 100644 --- a/drivers/nvme/host/nvme.h +++ b/drivers/nvme/host/nvme.h @@ -666,14 +666,15 @@ static inline struct request *nvme_find_rq(struct blk_mq_tags *tags, rq = blk_mq_tag_to_rq(tags, tag); if (unlikely(!rq)) { - pr_err("could not locate request for tag %#x\n", - tag); + pr_err_ratelimited("could not locate request for tag %#x\n", + tag); return NULL; } if (unlikely(nvme_genctr_mask(nvme_req(rq)->genctr) != genctr)) { - dev_err(nvme_req(rq)->ctrl->device, - "request %#x genctr mismatch (got %#x expected %#x)\n", - tag, genctr, nvme_genctr_mask(nvme_req(rq)->genctr)); + dev_err_ratelimited(nvme_req(rq)->ctrl->device, + "request %#x genctr mismatch (got %#x expected %#x)\n", + tag, genctr, + nvme_genctr_mask(nvme_req(rq)->genctr)); return NULL; } return rq; diff --git a/drivers/nvme/host/pci.c b/drivers/nvme/host/pci.c index db5fc9bf6627..93c0cb47bcaf 100644 --- a/drivers/nvme/host/pci.c +++ b/drivers/nvme/host/pci.c @@ -1549,9 +1549,9 @@ static inline void nvme_handle_cqe(struct nvme_queue *nvmeq, req = nvme_find_rq(nvme_queue_tagset(nvmeq), command_id); if (unlikely(!req)) { - dev_warn(nvmeq->dev->ctrl.device, - "invalid id %d completed on queue %d\n", - command_id, le16_to_cpu(cqe->sq_id)); + dev_warn_ratelimited(nvmeq->dev->ctrl.device, + "invalid id %d completed on queue %d\n", + command_id, le16_to_cpu(cqe->sq_id)); return; } base-commit: 8541d8f725c673db3bd741947f27974358b2e163 -- 2.43.0