mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Hannes Reinecke <hare@suse.de>
To: Guangshuo Li <lgs201920130244@gmail.com>,
	"James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>,
	"Martin K. Petersen" <martin.petersen@oracle.com>,
	Robert Love <robert.w.love@intel.com>,
	James Bottomley <James.Bottomley@suse.de>,
	Joe Eykholt <jeykholt@cisco.com>,
	linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Subject: Re: [PATCH] scsi: libfc: fix directory server rport memory leak
Date: Mon, 21 Sep 2026 10:48:26 +0200	[thread overview]
Message-ID: <4ca4f5c5-5021-4a63-bb14-4b7d0502eef6@suse.de> (raw)
In-Reply-To: <20260919173405.3718408-1-lgs201920130244@gmail.com>

On 9/19/26 7:34 PM, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
> 
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
> 
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
> 
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
> 
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
> 
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
>   drivers/scsi/libfc/fc_rport.c | 7 ++++++-
>   1 file changed, 6 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c
> index c25979d96808..884b233c2f72 100644
> --- a/drivers/scsi/libfc/fc_rport.c
> +++ b/drivers/scsi/libfc/fc_rport.c
> @@ -1848,6 +1848,7 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
>   	struct fc_els_flogi *pl;
>   	struct fc_seq_els_data rjt_data;
>   	u32 sid;
> +	bool drop_rdata = false;
>   
>   	lockdep_assert_held(&lport->lp_mutex);
>   
> @@ -1940,8 +1941,10 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
>   	 * Send LS_ACC.	 If this fails, the originator should retry.
>   	 */
>   	fp = fc_frame_alloc(lport, sizeof(*pl));
> -	if (!fp)
> +	if (!fp) {
> +		drop_rdata = sid == FC_FID_DIR_SERV;
>   		goto out;
> +	}
>   
>   	fc_plogi_fill(lport, fp, ELS_LS_ACC);
>   	fc_fill_reply_hdr(fp, rx_fp, FC_RCTL_ELS_REP, 0);
> @@ -1949,6 +1952,8 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
>   	fc_rport_enter_prli(rdata);
>   out:
>   	mutex_unlock(&rdata->rp_mutex);
> +	if (drop_rdata)
> +		kref_put(&rdata->kref, fc_rport_destroy);
>   	fc_frame_free(rx_fp);
>   	return;
>   

Wouldn't it be better to always create an rport for the directory
server?
That would make the teardown path far easier.

Cheers,

Hannes
-- 
Dr. Hannes Reinecke                  Kernel Storage Architect
hare@suse.de                                +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich

  reply	other threads:[~2026-09-21  8:48 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-19 17:34 Guangshuo Li
2026-09-21  8:48 ` Hannes Reinecke [this message]
2026-09-21 15:04 ` krzk
2026-09-21 15:07 ` krzk
2026-09-21 15:15 ` krzk
2026-09-21 15:30   ` Krzysztof Kozlowski
2026-09-22  2:13     ` Guangshuo Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4ca4f5c5-5021-4a63-bb14-4b7d0502eef6@suse.de \
    --to=hare@suse.de \
    --cc=James.Bottomley@HansenPartnership.com \
    --cc=James.Bottomley@suse.de \
    --cc=jeykholt@cisco.com \
    --cc=lgs201920130244@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=martin.petersen@oracle.com \
    --cc=robert.w.love@intel.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®