From: Hannes Reinecke <hare@suse.de>
To: Guangshuo Li <lgs201920130244@gmail.com>,
"James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
"Martin K. Petersen" <martin.petersen@oracle.com>,
Robert Love <robert.w.love@intel.com>,
James Bottomley <James.Bottomley@suse.de>,
Joe Eykholt <jeykholt@cisco.com>,
linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Subject: Re: [PATCH] scsi: libfc: fix directory server rport memory leak
Date: Mon, 21 Sep 2026 10:48:26 +0200 [thread overview]
Message-ID: <4ca4f5c5-5021-4a63-bb14-4b7d0502eef6@suse.de> (raw)
In-Reply-To: <20260919173405.3718408-1-lgs201920130244@gmail.com>
On 9/19/26 7:34 PM, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
>
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
>
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
>
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c
> index c25979d96808..884b233c2f72 100644
> --- a/drivers/scsi/libfc/fc_rport.c
> +++ b/drivers/scsi/libfc/fc_rport.c
> @@ -1848,6 +1848,7 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> struct fc_els_flogi *pl;
> struct fc_seq_els_data rjt_data;
> u32 sid;
> + bool drop_rdata = false;
>
> lockdep_assert_held(&lport->lp_mutex);
>
> @@ -1940,8 +1941,10 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> * Send LS_ACC. If this fails, the originator should retry.
> */
> fp = fc_frame_alloc(lport, sizeof(*pl));
> - if (!fp)
> + if (!fp) {
> + drop_rdata = sid == FC_FID_DIR_SERV;
> goto out;
> + }
>
> fc_plogi_fill(lport, fp, ELS_LS_ACC);
> fc_fill_reply_hdr(fp, rx_fp, FC_RCTL_ELS_REP, 0);
> @@ -1949,6 +1952,8 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> fc_rport_enter_prli(rdata);
> out:
> mutex_unlock(&rdata->rp_mutex);
> + if (drop_rdata)
> + kref_put(&rdata->kref, fc_rport_destroy);
> fc_frame_free(rx_fp);
> return;
>
Wouldn't it be better to always create an rport for the directory
server?
That would make the teardown path far easier.
Cheers,
Hannes
--
Dr. Hannes Reinecke Kernel Storage Architect
hare@suse.de +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich
next prev parent reply other threads:[~2026-09-21 8:48 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-19 17:34 Guangshuo Li
2026-09-21 8:48 ` Hannes Reinecke [this message]
2026-09-21 15:04 ` krzk
2026-09-21 15:07 ` krzk
2026-09-21 15:15 ` krzk
2026-09-21 15:30 ` Krzysztof Kozlowski
2026-09-22 2:13 ` Guangshuo Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4ca4f5c5-5021-4a63-bb14-4b7d0502eef6@suse.de \
--to=hare@suse.de \
--cc=James.Bottomley@HansenPartnership.com \
--cc=James.Bottomley@suse.de \
--cc=jeykholt@cisco.com \
--cc=lgs201920130244@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=robert.w.love@intel.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®