From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E6C1140F8D8 for ; Wed, 4 Feb 2026 14:04:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770213890; cv=none; b=c40qbe0gzKG0tB3vGhTu/ke6P16ArFF3k/tJaTuzHPxNY7tlHYGccNSDlQ5jOQjEBpY9AgoQWBzVvqhJpB0Aj/Zb36ABmR2g2K1CjiOhbiBCS79SebJwiRtMe3BfdwvkrKGgqUx3JrCglVV1f0Prply07pq1yZ3JBeR/1C2h5hc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770213890; c=relaxed/simple; bh=RLBNkLX00/DVFN+jbfXa24RWsw0z6IhmuksSlVBTxqk=; h=Message-ID:Date:MIME-Version:Subject:From:To:Cc:References: In-Reply-To:Content-Type; b=kQ34u/Wu+XfRFp1iENgS88Y7LxTJ8PAg8P/uyM0evuiHTvVoV554H1HcXvdZ49DINABzbogxfArAoHRTMgh/niOnDSzTI0HCa6D02ZMzVtWw8alU/EV/9PbVAyyMLeNVmGZVm0INOYA+dQD5Vcg6kfIuviGnsxVoV2yejqjiOWk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=pR28mkPE; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=hcI1xhVM; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="pR28mkPE"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="hcI1xhVM" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 614CIUDt096183 for ; Wed, 4 Feb 2026 14:04:48 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= g8tqW5Hq/w4yBZGsIGjLboSs0fMRtytJGNyqGY+7pxA=; b=pR28mkPE79srk/r0 tc+k6GtbMrLxlIlRm2yZU+MYOLtltcGdlGgs95wbtyRwq93lvppI1oCF39Z+Z/jo A+TBXTguc/QlUyHHrZkvdfuwxcaUlFwADeica30sLwKEUeIvhwITtioLAtSL/Mrn AAqGwC65mhxoFIl9VvrrjxRsEgAQCyn/wFHeVJbnKqK82Qfr6kG0Ox/sCYLr8rpJ Eu856/1h364OIn/TsmbYDu+nACPGTmtyQmNEa4FtYMYRVIRCeakzFY43GV7Ta1oD vgnCS2XInV2Eb15Ww+yzeKlIo0UdAzhWeP+yId3Q7mQuZ7AMZgpQ7yJI86YuDXWL +aYrxQ== Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4c44kbghtx-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 04 Feb 2026 14:04:48 +0000 (GMT) Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-3545dbb7ee6so3113700a91.3 for ; Wed, 04 Feb 2026 06:04:48 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1770213888; x=1770818688; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:references :cc:to:from:subject:user-agent:mime-version:date:message-id:from:to :cc:subject:date:message-id:reply-to; bh=g8tqW5Hq/w4yBZGsIGjLboSs0fMRtytJGNyqGY+7pxA=; b=hcI1xhVMqHyvn1k51aQQiBlZ71EqzQ29XVPXp9nzMBxmXgrPjYEzvg7eRkdhJtnHZf yavVmjsjJiKiCnk9Bn1h9NGSkHOVnVHengq+eI7tReEe3/PzSxmgv4F7bNAOePt0hVUP 35RQZ2IrqLk7MjZMr6hNwawKq+PJrLTwKer3+OJmcT6umd99MQXzO30VYMJ6qR3hHcF/ Jr+7+h8bWVx/PsYH75bL2urcoho6t3Kp9fZyS9bz0FZMKHKWiDsN2WCiSSfC98BmdXJN R8oGxstpJacZWxPjOIemOTjZvkNYEtaErEl71mKLesT9G2pCJJFdfzGyrMbp/6yne/L8 7xUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770213888; x=1770818688; h=content-transfer-encoding:in-reply-to:content-language:references :cc:to:from:subject:user-agent:mime-version:date:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=g8tqW5Hq/w4yBZGsIGjLboSs0fMRtytJGNyqGY+7pxA=; b=SYCNdrPP7/hej+3E2G6yFrxzePwo0XPzhqIlqcqDdM+H7YHz3Ed/+s2DrjcsA2bnpi t0An3G9RoZKfWmDd9C5BxBfMFHXHDD/W6vhv3RipB3Jcekp3MSx3UhoPieDkb9gHCmmL VblR3YecV7C5/PI6rJ/rtyv6jWO2lhyYEz4ZH++rix/GadRPnLCmRYk8xfX+ponwfUtk 1jQqLl197VCIDUC0vynd5U92UzYp3ArtdMoAagoizvigeQChtIhdZ4NAc7DjLegRYpIf 2FQppj/81CD+EbiHW8clBxDR/4r2FY6OJsKDS62PR13vBzhmWh1MvCu6YUgCiRg/DKSe dLag== X-Forwarded-Encrypted: i=1; AJvYcCXmUWxt9dFQZ4nqdwcR0tvldpl46O+yNDAeZUw48imLfCUG7nY9yCYp9LXnQvxe6LTO6y8gMSjbvKTEKh0=@vger.kernel.org X-Gm-Message-State: AOJu0Yycv/gdFwb5R9C/b/UnTKhhU1XKlNVkbu1/dNkgRae/Ai3iN6eT d/1z3DSELvO2FrtZSD7uP81GEEizH2mUye2nNwTEqKfZGfBAU0qXC/vg6e1s+mH1Nx1k8aJIhVM BX+8tTKVsX3/7R9wKcs+f88YwSmlambNVNEQnplgROUm3iVuY4t0LPdLHMKx+2PMirv4= X-Gm-Gg: AZuq6aKHowblbLjl9b+HZw8VXbzHj1c3AZLGEdsVbGscUTWMCADTpyApF9tANFF2/pz IX7SDiB8Bw46u7lX4GPNep6JikzujUe1RcDcFWc88tCYMpuNy1my2s5gkMyVcnKSNw7/FeQf7lp EpR1N56kv19VGElQbht6y1KZzVb24tHKenawuCS2JCLez6nwFEGeCsk5BRq4QWxIfqmgZ/iTf65 KjQNJx7i8ObzrlXA0sXvrpJA/tjZzHVorui8H+gy0F5IwjUA6TO9Gh1VCQ+8K9ipQNiW/c/1VQ3 YUOVXc/8JnUZQLshpybdZEqXeGYb2dC2oidp28wI2elAPsAw410bc/UgErL4ZXVTFDC/LriGMN5 oPH0dBIdp7DcCsvROb5IN1uPWnbBXRgFs4FEir90BFHDIjtLy6vM= X-Received: by 2002:a17:90b:2e10:b0:343:87b1:285 with SMTP id 98e67ed59e1d1-354871a9119mr2601663a91.18.1770213887900; Wed, 04 Feb 2026 06:04:47 -0800 (PST) X-Received: by 2002:a17:90b:2e10:b0:343:87b1:285 with SMTP id 98e67ed59e1d1-354871a9119mr2601622a91.18.1770213887347; Wed, 04 Feb 2026 06:04:47 -0800 (PST) Received: from [10.217.216.105] ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8241d1b71cesm2524594b3a.19.2026.02.04.06.04.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 04 Feb 2026 06:04:46 -0800 (PST) Message-ID: <563080fc-e5b3-4ff3-9c27-74a167246544@oss.qualcomm.com> Date: Wed, 4 Feb 2026 19:34:42 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH V1] nvme-pci: Fix NULL pointer dereference in nvme_pci_prp_iter_next From: Pradeep Pragallapati To: Christoph Hellwig , Keith Busch Cc: Robin Murphy , axboe@kernel.dk, sagi@grimberg.me, linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org, nitin.rawat@oss.qualcomm.com, Leon Romanovsky , Marek Szyprowski , iommu@lists.linux.dev References: <20260202143548.GA19313@lst.de> <20260202173624.GA32713@lst.de> <20260203052756.GA15839@lst.de> <79034c4c-ba06-4961-b41b-a43e5f5946af@oss.qualcomm.com> Content-Language: en-US In-Reply-To: <79034c4c-ba06-4961-b41b-a43e5f5946af@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Proofpoint-ORIG-GUID: MHFQDV_S5JQjY2cQJdZmSf2DiMcKOlDH X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMjA0MDEwNiBTYWx0ZWRfX9LWgNcIkNRVU ayBUT3oglnDdJmq+Eo8lj/rx8e8eHRscTByD0wQdCDAt2+kx7lH9602w3tiyWV8sLzPB+nf3Jog CyztVzIB4Znk1m3waRXO6jn+MRcvgIKDViTE+/cp4vho94ueX2/EvSzBnBNd5Dt3VU0JsNZx7Ot GU1sbiLYJwThPz++Xn1Z+Lz8BlaEqxdL/nZkwihQLV+8XeSoT5QiVVvMa3eRgtJC7MON3S03NGW iduIh5ljnuBkshcMAHIkqIlHzPooGZv60oyYcquFgT8lK12FZ8XhgTHiuO3CRAtvNyCrsjZ2+cY sYiY5SNQd7QeW7pQKxd7z1WX8FBtABk7wHMHE2DiT3JGCjLq4/FWdMagVOS1SQdKrDTryGWnDZL TOz0dC7SyoIkjfTOfgXnbf4dz1ygTAMjjgQLKN5XkXxXkROsjvnxqY1ql/LhcEdYMLpbkDv4c44 YxfRr5DTSNsaQb1/EOA== X-Proofpoint-GUID: MHFQDV_S5JQjY2cQJdZmSf2DiMcKOlDH X-Authority-Analysis: v=2.4 cv=HN7O14tv c=1 sm=1 tr=0 ts=69835200 cx=c_pps a=RP+M6JBNLl+fLTcSJhASfg==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=HzLeVaNsDn8A:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=Gc0GUWPnaK2Fg8JTCy4A:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=iS9zxrgQBfv6-_F4QbHw:22 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-02-04_04,2026-02-04_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 suspectscore=0 phishscore=0 clxscore=1015 bulkscore=0 spamscore=0 adultscore=0 malwarescore=0 priorityscore=1501 lowpriorityscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2601150000 definitions=main-2602040106 On 2/3/2026 7:35 PM, Pradeep Pragallapati wrote: > > > On 2/3/2026 10:57 AM, Christoph Hellwig wrote: >> On Mon, Feb 02, 2026 at 11:59:04AM -0700, Keith Busch wrote: >>> In the case where this iteration caused dma_need_unmap() to toggle to >>> true, this is the iteration that allocates the dma_vecs, and it >>> initializes the first entry to this iter. But the next lines proceed to >>> the save this iter in the next index, so it's doubly accounted for and >>> will get unmapped twice in the completion. >> >> Yeah. >> >>> Also, if the allocation fails, we should set iter->status to >>> BLK_STS_RESOURCE so the callers know why the iteration can't continue. >>> Otherwise, the caller will think the request is badly formed if you >>> return false from here without setting iter->status. >>> >>> Here's my quick take. Boot tested with swiotlb enabled, but haven't >>> tried to test the changing dma_need_unmap() scenario. >> >> Looks much better.  Cosmetic nits below. >> >> Pradeep, can you test this with your setup? > Sure, testing has started, and I will share the findings soon. > Also, I did not pick up the initialization of dma_vecs during testing. I ran testing for over 20 hours and did not observe the issue on my setup. It appears to be helping. > >> >>> +    if (!dma_use_iova(&iod->dma_state) && dma_need_unmap(dma_dev)) >>> +        return nvme_pci_prp_save_mapping(iter, req); >> >>> +    if (!dma_use_iova(&iod->dma_state) && dma_need_unmap(nvmeq->dev- >>> >dev)) >>> +        if (!nvme_pci_prp_save_mapping(iter, req)) >>> +            return iter->status; >> >> I'd move the dma_use_iova / dma_need_unmap checks into >> nvme_pci_prp_save_mapping to simplify this a bit more. >> >>>       /* >>>        * PRP1 always points to the start of the DMA transfers. >>> @@ -1218,6 +1231,8 @@ static blk_status_t nvme_prep_rq(struct request >>> *req) >>>       iod->nr_descriptors = 0; >>>       iod->total_len = 0; >>>       iod->meta_total_len = 0; >>> +    iod->nr_dma_vecs = 0; >>> +    iod->dma_vecs = NULL; >> >> I don't think we need the dma_vecs initialization here, as everything >> is keyed off nr_dma_vecs. >