* [PATCH] scsi: libfc: fix directory server rport memory leak
@ 2026-09-19 17:34 Guangshuo Li
2026-09-21 8:48 ` Hannes Reinecke
` (3 more replies)
0 siblings, 4 replies; 7+ messages in thread
From: Guangshuo Li @ 2026-09-19 17:34 UTC (permalink / raw)
To: Hannes Reinecke, James E.J. Bottomley, Martin K. Petersen,
Robert Love, James Bottomley, Joe Eykholt, linux-scsi,
linux-kernel
Cc: Guangshuo Li, stable
fc_rport_recv_plogi_req() creates an rport before allocating the frame
used for the PLOGI LS_ACC response.
fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
rport list. If fc_frame_alloc() fails while handling a PLOGI from the
directory server, the function returns without starting the rport state
machine or dropping the initial rport reference.
Since the directory server rport is not present in the discovery list,
there is no later teardown path that can find the object and release
that reference. The allocated fc_rport_priv is therefore leaked.
Record when the failed frame allocation leaves an unlisted directory
server rport behind and drop its initial reference after releasing the
rport mutex. Keep the existing lifetime unchanged for ordinary rports,
which remain owned by the discovery list.
The issue was identified by a static analysis tool I developed and
confirmed by manual review.
Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
drivers/scsi/libfc/fc_rport.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c
index c25979d96808..884b233c2f72 100644
--- a/drivers/scsi/libfc/fc_rport.c
+++ b/drivers/scsi/libfc/fc_rport.c
@@ -1848,6 +1848,7 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
struct fc_els_flogi *pl;
struct fc_seq_els_data rjt_data;
u32 sid;
+ bool drop_rdata = false;
lockdep_assert_held(&lport->lp_mutex);
@@ -1940,8 +1941,10 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
* Send LS_ACC. If this fails, the originator should retry.
*/
fp = fc_frame_alloc(lport, sizeof(*pl));
- if (!fp)
+ if (!fp) {
+ drop_rdata = sid == FC_FID_DIR_SERV;
goto out;
+ }
fc_plogi_fill(lport, fp, ELS_LS_ACC);
fc_fill_reply_hdr(fp, rx_fp, FC_RCTL_ELS_REP, 0);
@@ -1949,6 +1952,8 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
fc_rport_enter_prli(rdata);
out:
mutex_unlock(&rdata->rp_mutex);
+ if (drop_rdata)
+ kref_put(&rdata->kref, fc_rport_destroy);
fc_frame_free(rx_fp);
return;
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-19 17:34 [PATCH] scsi: libfc: fix directory server rport memory leak Guangshuo Li
@ 2026-09-21 8:48 ` Hannes Reinecke
2026-09-21 15:04 ` krzk
` (2 subsequent siblings)
3 siblings, 0 replies; 7+ messages in thread
From: Hannes Reinecke @ 2026-09-21 8:48 UTC (permalink / raw)
To: Guangshuo Li, James E.J. Bottomley, Martin K. Petersen,
Robert Love, James Bottomley, Joe Eykholt, linux-scsi,
linux-kernel
Cc: stable
On 9/19/26 7:34 PM, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
>
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
>
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
>
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c
> index c25979d96808..884b233c2f72 100644
> --- a/drivers/scsi/libfc/fc_rport.c
> +++ b/drivers/scsi/libfc/fc_rport.c
> @@ -1848,6 +1848,7 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> struct fc_els_flogi *pl;
> struct fc_seq_els_data rjt_data;
> u32 sid;
> + bool drop_rdata = false;
>
> lockdep_assert_held(&lport->lp_mutex);
>
> @@ -1940,8 +1941,10 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> * Send LS_ACC. If this fails, the originator should retry.
> */
> fp = fc_frame_alloc(lport, sizeof(*pl));
> - if (!fp)
> + if (!fp) {
> + drop_rdata = sid == FC_FID_DIR_SERV;
> goto out;
> + }
>
> fc_plogi_fill(lport, fp, ELS_LS_ACC);
> fc_fill_reply_hdr(fp, rx_fp, FC_RCTL_ELS_REP, 0);
> @@ -1949,6 +1952,8 @@ static void fc_rport_recv_plogi_req(struct fc_lport *lport,
> fc_rport_enter_prli(rdata);
> out:
> mutex_unlock(&rdata->rp_mutex);
> + if (drop_rdata)
> + kref_put(&rdata->kref, fc_rport_destroy);
> fc_frame_free(rx_fp);
> return;
>
Wouldn't it be better to always create an rport for the directory
server?
That would make the teardown path far easier.
Cheers,
Hannes
--
Dr. Hannes Reinecke Kernel Storage Architect
hare@suse.de +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-19 17:34 [PATCH] scsi: libfc: fix directory server rport memory leak Guangshuo Li
2026-09-21 8:48 ` Hannes Reinecke
@ 2026-09-21 15:04 ` krzk
2026-09-21 15:07 ` krzk
2026-09-21 15:15 ` krzk
3 siblings, 0 replies; 7+ messages in thread
From: krzk @ 2026-09-21 15:04 UTC (permalink / raw)
To: Guangshuo Li
Cc: Martin K. Petersen, Hannes Reinecke, James E.J. Bottomley,
Robert Love, Joe Eykholt, linux-kernel, stable, James Bottomley,
linux-scsi
On Sun, 20 Sep 2026 01:34:05 +0800, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
>
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
>
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
>
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-19 17:34 [PATCH] scsi: libfc: fix directory server rport memory leak Guangshuo Li
2026-09-21 8:48 ` Hannes Reinecke
2026-09-21 15:04 ` krzk
@ 2026-09-21 15:07 ` krzk
2026-09-21 15:15 ` krzk
3 siblings, 0 replies; 7+ messages in thread
From: krzk @ 2026-09-21 15:07 UTC (permalink / raw)
To: Guangshuo Li
Cc: linux-kernel, Robert Love, linux-scsi, James E.J. Bottomley,
Martin K. Petersen, Joe Eykholt, Hannes Reinecke, stable,
James Bottomley
On Sun, 20 Sep 2026 01:34:05 +0800, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
>
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
>
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
>
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-19 17:34 [PATCH] scsi: libfc: fix directory server rport memory leak Guangshuo Li
` (2 preceding siblings ...)
2026-09-21 15:07 ` krzk
@ 2026-09-21 15:15 ` krzk
2026-09-21 15:30 ` Krzysztof Kozlowski
3 siblings, 1 reply; 7+ messages in thread
From: krzk @ 2026-09-21 15:15 UTC (permalink / raw)
To: Guangshuo Li
Cc: James E.J. Bottomley, Hannes Reinecke, Martin K. Petersen,
linux-scsi, Joe Eykholt, Robert Love, James Bottomley,
linux-kernel, stable
On Sun, 20 Sep 2026 01:34:05 +0800, Guangshuo Li wrote:
> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> used for the PLOGI LS_ACC response.
>
> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> directory server, the function returns without starting the rport state
> machine or dropping the initial rport reference.
>
> Since the directory server rport is not present in the discovery list,
> there is no later teardown path that can find the object and release
> that reference. The allocated fc_rport_priv is therefore leaked.
>
> Record when the failed frame allocation leaves an unlisted directory
> server rport behind and drop its initial reference after releasing the
> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> which remain owned by the discovery list.
>
> The issue was identified by a static analysis tool I developed and
> confirmed by manual review.
>
> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> Cc: stable@vger.kernel.org
> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> ---
> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
You sent multiple independent patches, to multiple independent
subsystems. The amount of these patches clearly suggest this was
AI generated and most likely not tested.
More importantly, you sent all this work without properly organizing
relevant patches into patchsets. This makes reviewing difficult
and might cause multiple reviewers to address the same issue.
Replying to the entire set is impossible and requires handling each
patch independently, instead of applying or discarding the set.
Maintainers also won't see the bigger picture of your work. Quite
worrying.
This is on the verge of hostile patch: bomb us with so many
contributions, we won't be able to handle them in efficient manner,
like responding ONCE to ask you to slow down. Considering all this
is untested and LLM generated, I have even more doubts whether this
should be considered for review.
Please read kernel documentation BEFORE posting more work. It will
explain you how to identify subsystems, how to organize your work per
subsystem, how to document usage of LLM and how what you should not
do if this was posted in a good faith.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-21 15:15 ` krzk
@ 2026-09-21 15:30 ` Krzysztof Kozlowski
2026-09-22 2:13 ` Guangshuo Li
0 siblings, 1 reply; 7+ messages in thread
From: Krzysztof Kozlowski @ 2026-09-21 15:30 UTC (permalink / raw)
To: Guangshuo Li
Cc: James E.J. Bottomley, Hannes Reinecke, Martin K. Petersen,
linux-scsi, Joe Eykholt, Robert Love, James Bottomley,
linux-kernel, stable
On 21/09/2026 17:15, krzk@kernel.org wrote:
>
> On Sun, 20 Sep 2026 01:34:05 +0800, Guangshuo Li wrote:
>> fc_rport_recv_plogi_req() creates an rport before allocating the frame
>> used for the PLOGI LS_ACC response.
>>
>> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
>> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
>> directory server, the function returns without starting the rport state
>> machine or dropping the initial rport reference.
>>
>> Since the directory server rport is not present in the discovery list,
>> there is no later teardown path that can find the object and release
>> that reference. The allocated fc_rport_priv is therefore leaked.
>>
>> Record when the failed frame allocation leaves an unlisted directory
>> server rport behind and drop its initial reference after releasing the
>> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
>> which remain owned by the discovery list.
>>
>> The issue was identified by a static analysis tool I developed and
>> confirmed by manual review.
>>
>> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
>> Cc: stable@vger.kernel.org
>> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
>> ---
>> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
>> 1 file changed, 6 insertions(+), 1 deletion(-)
>>
>
>
> You sent multiple independent patches, to multiple independent
> subsystems. The amount of these patches clearly suggest this was
> AI generated and most likely not tested.
>
> More importantly, you sent all this work without properly organizing
> relevant patches into patchsets. This makes reviewing difficult
> and might cause multiple reviewers to address the same issue.
> Replying to the entire set is impossible and requires handling each
> patch independently, instead of applying or discarding the set.
> Maintainers also won't see the bigger picture of your work. Quite
> worrying.
>
> This is on the verge of hostile patch: bomb us with so many
> contributions, we won't be able to handle them in efficient manner,
> like responding ONCE to ask you to slow down. Considering all this
> is untested and LLM generated, I have even more doubts whether this
> should be considered for review.
>
> Please read kernel documentation BEFORE posting more work. It will
> explain you how to identify subsystems, how to organize your work per
> subsystem, how to document usage of LLM and how what you should not
> do if this was posted in a good faith.
>
Apologies for spamming here. Fighting fire with fire :). No, just mutt
mistake on my side.
Best regards,
Krzysztof
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] scsi: libfc: fix directory server rport memory leak
2026-09-21 15:30 ` Krzysztof Kozlowski
@ 2026-09-22 2:13 ` Guangshuo Li
0 siblings, 0 replies; 7+ messages in thread
From: Guangshuo Li @ 2026-09-22 2:13 UTC (permalink / raw)
To: Krzysztof Kozlowski
Cc: James E.J. Bottomley, Hannes Reinecke, Martin K. Petersen,
linux-scsi, Joe Eykholt, Robert Love, James Bottomley,
linux-kernel, stable
Hi Krzysztof,
Thank you for your feedback.
On Mon, 21 Sept 2026 at 23:30, Krzysztof Kozlowski <krzk@kernel.org> wrote:
>
> On 21/09/2026 17:15, krzk@kernel.org wrote:
> >
> > On Sun, 20 Sep 2026 01:34:05 +0800, Guangshuo Li wrote:
> >> fc_rport_recv_plogi_req() creates an rport before allocating the frame
> >> used for the PLOGI LS_ACC response.
> >>
> >> fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery
> >> rport list. If fc_frame_alloc() fails while handling a PLOGI from the
> >> directory server, the function returns without starting the rport state
> >> machine or dropping the initial rport reference.
> >>
> >> Since the directory server rport is not present in the discovery list,
> >> there is no later teardown path that can find the object and release
> >> that reference. The allocated fc_rport_priv is therefore leaked.
> >>
> >> Record when the failed frame allocation leaves an unlisted directory
> >> server rport behind and drop its initial reference after releasing the
> >> rport mutex. Keep the existing lifetime unchanged for ordinary rports,
> >> which remain owned by the discovery list.
> >>
> >> The issue was identified by a static analysis tool I developed and
> >> confirmed by manual review.
> >>
> >> Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request.")
> >> Cc: stable@vger.kernel.org
> >> Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
> >> ---
> >> drivers/scsi/libfc/fc_rport.c | 7 ++++++-
> >> 1 file changed, 6 insertions(+), 1 deletion(-)
> >>
> >
> >
> > You sent multiple independent patches, to multiple independent
> > subsystems. The amount of these patches clearly suggest this was
> > AI generated and most likely not tested.
> >
> > More importantly, you sent all this work without properly organizing
> > relevant patches into patchsets. This makes reviewing difficult
> > and might cause multiple reviewers to address the same issue.
> > Replying to the entire set is impossible and requires handling each
> > patch independently, instead of applying or discarding the set.
> > Maintainers also won't see the bigger picture of your work. Quite
> > worrying.
> >
> > This is on the verge of hostile patch: bomb us with so many
> > contributions, we won't be able to handle them in efficient manner,
> > like responding ONCE to ask you to slow down. Considering all this
> > is untested and LLM generated, I have even more doubts whether this
> > should be considered for review.
> >
> > Please read kernel documentation BEFORE posting more work. It will
> > explain you how to identify subsystems, how to organize your work per
> > subsystem, how to document usage of LLM and how what you should not
> > do if this was posted in a good faith.
> >
>
> Apologies for spamming here. Fighting fire with fire :). No, just mutt
> mistake on my side.
>
> Best regards,
> Krzysztof
I would like to clarify that these patches were manually reviewed and
audited by us; they were not simply generated and submitted by an LLM.
However, I understand why the recent submission pattern may have given
that impression. We sent too many patches in a short period of time,
and we also failed to respond to some discussions in a timely manner,
which made the situation look worse.
Many of the recent patches, especially the v2 revisions, are
corrections and improvements based on previous review feedback rather
than completely new untested changes. That said, we recognize that the
way we submitted them increased the burden on maintainers and
reviewers.
We apologize for the pressure this caused to the community. We will be
more careful about organizing patches by subsystem, preparing proper
patchsets, and following the kernel contribution guidelines before
sending future work.
Thank you again for pointing this out.
Best regards,
Guangshuo
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-09-22 2:13 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 17:34 [PATCH] scsi: libfc: fix directory server rport memory leak Guangshuo Li
2026-09-21 8:48 ` Hannes Reinecke
2026-09-21 15:04 ` krzk
2026-09-21 15:07 ` krzk
2026-09-21 15:15 ` krzk
2026-09-21 15:30 ` Krzysztof Kozlowski
2026-09-22 2:13 ` Guangshuo Li
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®