* [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations
@ 2026-10-09 0:35 Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 1/4] scsi: target: rd: Fix oversized sg table array allocation Sanan Hasanov
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Sanan Hasanov @ 2026-10-09 0:35 UTC (permalink / raw)
To: Martin K. Petersen
Cc: Sanan Hasanov, linux-scsi, target-devel, linux-kernel,
syzbot+fa495e1497c48a6ed885
From: Sanan Hasanov <sanan.hasanov@ucf.edu>
A ramdisk page count set through configfs (rd_pages=) has no upper bound.
syzbot found that a large value makes rd_build_device_space() attempt a
single sg table array allocation above the page allocator's maximum
order, which triggers a WARNING. Patch 1 rejects page counts that
exceed system RAM and allocates the array with kvzalloc so that valid
large ramdisks also work.
A page count close to system RAM still passes that check, and the
backing pages are allocated with GFP_KERNEL, which invokes the OOM
killer instead of failing. On a 1 GiB VM, rd_pages=250000 panics the
system with "System is deadlocked on memory". Patch 3 allocates the
backing pages with __GFP_RETRY_MAYFAIL so that enabling such a device
fails with -ENOMEM instead.
That makes the failure path in rd_build_prot_space() reachable, and it
leaks the partially allocated protection space when pi_prot_type is
written again. Patch 2 fixes that first, so that patch 3 does not
introduce a leak.
Patch 4 fixes an older bug in the same function: the protection space
size is computed in 32 bits and wraps for ramdisks of 2 TiB and larger,
which leaves the protection sg tables too small.
Tested on an arm64 QEMU VM with 1 GiB RAM, with the syzbot reproducer,
normal and NULLIO ramdisks, DIF protection space, device removal, and
rd_pages=250000. The leak was checked with kmemleak by making
pi_prot_type=1 fail under memory pressure and then writing it again:
two unreferenced objects from rd_init_prot() are reported without
patch 2, none with it. I could not test the 2 TiB case of patch 4.
pi_prot_type_store() does not serialize concurrent writes, so two
writers can still race in rd_build_prot_space() and
rd_release_prot_space(). That was already the case before this series
and is not addressed here.
Changes in v4:
- Patch 2: build the protection space in local variables and store it
in rd_dev only on success, so that the error path cannot free an
array installed by a concurrent pi_prot_type write (Sashiko AI
review).
- New patch 4 to compute the protection space size in 64 bits
(Sashiko AI review).
Changes in v3:
- New patch 2 to release the protection space when its allocation
fails (Sashiko AI review).
Changes in v2:
- Allocate the sg table arrays with kvzalloc_objs() so that ramdisks
larger than 512 GiB do not hit the same WARNING (Sashiko AI review).
- New patch to avoid the OOM killer when the backing pages cannot be
allocated (Sashiko AI review).
v3: https://lore.kernel.org/all/20261008235411.56641-1-sanan.hasanou@gmail.com/
v2: https://lore.kernel.org/all/20261008223712.49827-1-sanan.hasanou@gmail.com/
v1: https://lore.kernel.org/all/20261008215709.46014-1-sanan.hasanou@gmail.com/
Sanan Hasanov (4):
scsi: target: rd: Fix oversized sg table array allocation
scsi: target: rd: Release protection space on allocation failure
scsi: target: rd: Don't invoke the OOM killer for ramdisk pages
scsi: target: rd: Avoid 32-bit overflow in protection space size
drivers/target/target_core_rd.c | 29 ++++++++++++++++++++---------
1 file changed, 20 insertions(+), 9 deletions(-)
base-commit: 6c377d19d4a5116d9bec5203aa3c6c11523e7898
--
2.48.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 1/4] scsi: target: rd: Fix oversized sg table array allocation
2026-10-09 0:35 [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations Sanan Hasanov
@ 2026-10-09 0:35 ` Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 2/4] scsi: target: rd: Release protection space on allocation failure Sanan Hasanov
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Sanan Hasanov @ 2026-10-09 0:35 UTC (permalink / raw)
To: Martin K. Petersen
Cc: Sanan Hasanov, linux-scsi, target-devel, linux-kernel,
syzbot+fa495e1497c48a6ed885
From: Sanan Hasanov <sanan.hasanov@ucf.edu>
The rd_pages= device parameter is taken from configfs without an upper
bound. rd_build_device_space() uses it to size the sg table array, so a
large value such as INT_MAX makes it attempt a kzalloc() of roughly
64 MiB, which is above the page allocator's maximum order and triggers:
WARNING: mm/page_alloc.c:5340 at __alloc_frozen_pages_noprof+0x294/0x874
Call trace:
__alloc_frozen_pages_noprof+0x294/0x874 (P)
___kmalloc_large_node+0x64/0xd0
__kmalloc_noprof+0x24/0x54
rd_configure_device+0x74/0xdc
target_configure_device+0xa0/0x1c4
target_dev_enable_store+0x4c/0x5c
configfs_write_iter+0xec/0x124
A ramdisk is backed page-by-page by system memory, so a page count
larger than totalram_pages() can never be satisfied. Reject it with
-EINVAL before allocating anything. NULLIO devices allocate no backing
pages and are not affected.
The array needs 64 bytes per 2048 pages, so even a valid page count
exceeds the 4 MiB maximum order once the ramdisk is larger than 512 GiB.
Allocate the sg table arrays with kvzalloc_objs() so that large arrays
fall back to vmalloc.
Fixes: c66ac9db8d4a ("[SCSI] target: Add LIO target core v4.0.0-rc6")
Reported-by: syzbot+fa495e1497c48a6ed885@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=fa495e1497c48a6ed885
Signed-off-by: Sanan Hasanov <sanan.hasanov@ucf.edu>
---
drivers/target/target_core_rd.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/target/target_core_rd.c b/drivers/target/target_core_rd.c
index 092d9fe0d..97c63b122 100644
--- a/drivers/target/target_core_rd.c
+++ b/drivers/target/target_core_rd.c
@@ -14,6 +14,7 @@
#include <linux/string.h>
#include <linux/parser.h>
#include <linux/highmem.h>
+#include <linux/mm.h>
#include <linux/timer.h>
#include <linux/scatterlist.h>
#include <linux/slab.h>
@@ -81,7 +82,7 @@ static u32 rd_release_sgl_table(struct rd_dev *rd_dev, struct rd_dev_sg_table *s
kfree(sg);
}
- kfree(sg_table);
+ kvfree(sg_table);
return page_count;
}
@@ -188,10 +189,16 @@ static int rd_build_device_space(struct rd_dev *rd_dev)
if (rd_dev->rd_flags & RDF_NULLIO)
return 0;
+ if (rd_dev->rd_page_count > totalram_pages()) {
+ pr_err("Page count: %u exceeds total RAM pages: %lu for Ramdisk device\n",
+ rd_dev->rd_page_count, totalram_pages());
+ return -EINVAL;
+ }
+
total_sg_needed = rd_dev->rd_page_count;
sg_tables = (total_sg_needed / max_sg_per_table) + 1;
- sg_table = kzalloc_objs(*sg_table, sg_tables);
+ sg_table = kvzalloc_objs(*sg_table, sg_tables);
if (!sg_table)
return -ENOMEM;
@@ -248,7 +255,7 @@ static int rd_build_prot_space(struct rd_dev *rd_dev, int prot_length, int block
total_sg_needed = (rd_dev->rd_page_count * prot_length / block_size) + 1;
sg_tables = (total_sg_needed / max_sg_per_table) + 1;
- sg_table = kzalloc_objs(*sg_table, sg_tables);
+ sg_table = kvzalloc_objs(*sg_table, sg_tables);
if (!sg_table)
return -ENOMEM;
--
2.48.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 2/4] scsi: target: rd: Release protection space on allocation failure
2026-10-09 0:35 [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 1/4] scsi: target: rd: Fix oversized sg table array allocation Sanan Hasanov
@ 2026-10-09 0:35 ` Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 3/4] scsi: target: rd: Don't invoke the OOM killer for ramdisk pages Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 4/4] scsi: target: rd: Avoid 32-bit overflow in protection space size Sanan Hasanov
3 siblings, 0 replies; 5+ messages in thread
From: Sanan Hasanov @ 2026-10-09 0:35 UTC (permalink / raw)
To: Martin K. Petersen
Cc: Sanan Hasanov, linux-scsi, target-devel, linux-kernel,
syzbot+fa495e1497c48a6ed885
From: Sanan Hasanov <sanan.hasanov@ucf.edu>
When rd_allocate_sgl_table() fails, rd_build_prot_space() returns the
error but leaves the partially populated sg_prot_array in place.
pi_prot_type_store() then restores the previous protection type without
calling ->free_prot(), so the pages and scatterlists allocated so far
stay attached to the device. If the user writes pi_prot_type again,
rd_build_prot_space() overwrites sg_prot_array and the earlier
allocation is leaked.
Build the protection space in local variables, free them if the
allocation fails, and only store them in rd_dev on success. The error
path then only touches memory that this call allocated.
Fixes: d7e8eb5d9216 ("target/rd: Add support for protection SGL setup + release")
Signed-off-by: Sanan Hasanov <sanan.hasanov@ucf.edu>
---
drivers/target/target_core_rd.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/target/target_core_rd.c b/drivers/target/target_core_rd.c
index 97c63b122..b52d703d2 100644
--- a/drivers/target/target_core_rd.c
+++ b/drivers/target/target_core_rd.c
@@ -259,12 +259,14 @@ static int rd_build_prot_space(struct rd_dev *rd_dev, int prot_length, int block
if (!sg_table)
return -ENOMEM;
- rd_dev->sg_prot_array = sg_table;
- rd_dev->sg_prot_count = sg_tables;
-
rc = rd_allocate_sgl_table(rd_dev, sg_table, total_sg_needed, 0xff);
- if (rc)
+ if (rc) {
+ rd_release_sgl_table(rd_dev, sg_table, sg_tables);
return rc;
+ }
+
+ rd_dev->sg_prot_array = sg_table;
+ rd_dev->sg_prot_count = sg_tables;
pr_debug("CORE_RD[%u] - Built Ramdisk Device ID: %u prot space of"
" %u pages in %u tables\n", rd_dev->rd_host->rd_host_id,
--
2.48.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 3/4] scsi: target: rd: Don't invoke the OOM killer for ramdisk pages
2026-10-09 0:35 [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 1/4] scsi: target: rd: Fix oversized sg table array allocation Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 2/4] scsi: target: rd: Release protection space on allocation failure Sanan Hasanov
@ 2026-10-09 0:35 ` Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 4/4] scsi: target: rd: Avoid 32-bit overflow in protection space size Sanan Hasanov
3 siblings, 0 replies; 5+ messages in thread
From: Sanan Hasanov @ 2026-10-09 0:35 UTC (permalink / raw)
To: Martin K. Petersen
Cc: Sanan Hasanov, linux-scsi, target-devel, linux-kernel,
syzbot+fa495e1497c48a6ed885
From: Sanan Hasanov <sanan.hasanov@ucf.edu>
rd_allocate_sgl_table() allocates the ramdisk's backing memory one page
at a time with GFP_KERNEL. When the requested ramdisk is larger than the
memory that can be freed, these allocations do not fail but invoke the
OOM killer instead. The pages are not charged to any task, so the OOM
killer keeps killing unrelated processes, and may panic the system once
nothing is left to kill, while the configfs write continues allocating.
Use __GFP_RETRY_MAYFAIL so that the allocation fails once reclaim can
make no more progress. rd_allocate_sgl_table() already handles failure
by returning -ENOMEM, and the caller then releases the pages allocated
so far. Add __GFP_NOWARN since the driver logs its own error.
Signed-off-by: Sanan Hasanov <sanan.hasanov@ucf.edu>
---
drivers/target/target_core_rd.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/target/target_core_rd.c b/drivers/target/target_core_rd.c
index b52d703d2..2613342be 100644
--- a/drivers/target/target_core_rd.c
+++ b/drivers/target/target_core_rd.c
@@ -150,7 +150,8 @@ static int rd_allocate_sgl_table(struct rd_dev *rd_dev, struct rd_dev_sg_table *
- 1;
for (j = 0; j < sg_per_table; j++) {
- pg = alloc_pages(GFP_KERNEL, 0);
+ pg = alloc_pages(GFP_KERNEL | __GFP_RETRY_MAYFAIL |
+ __GFP_NOWARN, 0);
if (!pg) {
pr_err("Unable to allocate scatterlist"
" pages for struct rd_dev_sg_table\n");
--
2.48.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v4 4/4] scsi: target: rd: Avoid 32-bit overflow in protection space size
2026-10-09 0:35 [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations Sanan Hasanov
` (2 preceding siblings ...)
2026-10-09 0:35 ` [PATCH v4 3/4] scsi: target: rd: Don't invoke the OOM killer for ramdisk pages Sanan Hasanov
@ 2026-10-09 0:35 ` Sanan Hasanov
3 siblings, 0 replies; 5+ messages in thread
From: Sanan Hasanov @ 2026-10-09 0:35 UTC (permalink / raw)
To: Martin K. Petersen
Cc: Sanan Hasanov, linux-scsi, target-devel, linux-kernel,
syzbot+fa495e1497c48a6ed885
From: Sanan Hasanov <sanan.hasanov@ucf.edu>
rd_build_prot_space() computes the number of protection pages as
rd_page_count * prot_length / block_size. rd_page_count is a u32 and
prot_length an int, so the multiplication is done in 32 bits and wraps
once rd_page_count reaches 2^29 with 8-byte protection information,
that is for a 2 TiB ramdisk. The protection sg tables are then
allocated much smaller than the device needs. A command whose
protection data starts inside the allocated range but extends past its
end makes sbc_dif_copy_prot() walk off the last scatterlist and
dereference the NULL returned by sg_next().
Do the multiplication in 64 bits. The quotient still fits in a u32
because prot_length is smaller than block_size.
Fixes: d7e8eb5d9216 ("target/rd: Add support for protection SGL setup + release")
Signed-off-by: Sanan Hasanov <sanan.hasanov@ucf.edu>
---
drivers/target/target_core_rd.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/target/target_core_rd.c b/drivers/target/target_core_rd.c
index 2613342be..d7752fd34 100644
--- a/drivers/target/target_core_rd.c
+++ b/drivers/target/target_core_rd.c
@@ -253,7 +253,8 @@ static int rd_build_prot_space(struct rd_dev *rd_dev, int prot_length, int block
* (prot_length/block_size) + pad
* PGSZ canceled each other.
*/
- total_sg_needed = (rd_dev->rd_page_count * prot_length / block_size) + 1;
+ total_sg_needed = div_u64((u64)rd_dev->rd_page_count * prot_length,
+ block_size) + 1;
sg_tables = (total_sg_needed / max_sg_per_table) + 1;
sg_table = kvzalloc_objs(*sg_table, sg_tables);
--
2.48.1
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-10-09 0:35 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09 0:35 [PATCH v4 0/4] scsi: target: rd: Fix oversized ramdisk allocations Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 1/4] scsi: target: rd: Fix oversized sg table array allocation Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 2/4] scsi: target: rd: Release protection space on allocation failure Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 3/4] scsi: target: rd: Don't invoke the OOM killer for ramdisk pages Sanan Hasanov
2026-10-09 0:35 ` [PATCH v4 4/4] scsi: target: rd: Avoid 32-bit overflow in protection space size Sanan Hasanov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®