mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v1 0/1] nvme: zns: cap zone report nr_zones by DMA buffer size
@ 2026-06-23  9:35 Xixin Liu
  2026-06-23  9:35 ` [PATCH v1 1/1] " Xixin Liu
  0 siblings, 1 reply; 3+ messages in thread
From: Xixin Liu @ 2026-06-23  9:35 UTC (permalink / raw)
  To: linux-nvme; +Cc: kbusch, axboe, hch, sagi, linux-kernel, liuxixin

Hi,

The ZNS host driver issues Zone Management Receive with Partial Report
(PR=1) fixed.  The Number of Zones (NZ) field in the report header must
reflect the zone descriptors actually transferred in the DMA buffer (ZNS
Command Set Specification Rev 1.2, section 3.4.2).

nvme_ns_report_zones() caps the parse loop by the device-reported NZ and
the caller's nr_zones limit, but not by the number of descriptors that fit
in buflen.  Cap nz with min3(device NZ, nr_zones - zone_idx, max_in_buf).

Thanks,
Xixin Liu

---

Xixin Liu (1):
  nvme: zns: cap zone report nr_zones by DMA buffer size

 drivers/nvme/host/zns.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v1 1/1] nvme: zns: cap zone report nr_zones by DMA buffer size
  2026-06-23  9:35 [PATCH v1 0/1] nvme: zns: cap zone report nr_zones by DMA buffer size Xixin Liu
@ 2026-06-23  9:35 ` Xixin Liu
  0 siblings, 0 replies; 3+ messages in thread
From: Xixin Liu @ 2026-06-23  9:35 UTC (permalink / raw)
  To: linux-nvme; +Cc: kbusch, axboe, hch, sagi, linux-kernel, liuxixin

With Partial Report (PR=1), the Number of Zones (NZ) field in the report
header must equal the number of zone descriptors fully transferred in the
DMA buffer (ZNS Command Set Specification Rev 1.2, section 3.4.2).

nvme_ns_report_zones() does not cap the parse loop by max_in_buf derived
from buflen.  Cap nz with min3() over the device-reported count, nr_zones -
zone_idx, and max_in_buf.

Signed-off-by: Xixin Liu <liuxixin@kylinos.cn>
---
 drivers/nvme/host/zns.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

diff --git a/drivers/nvme/host/zns.c b/drivers/nvme/host/zns.c
index 8ed1b6a33454..2a152e87bd76 100644
--- a/drivers/nvme/host/zns.c
+++ b/drivers/nvme/host/zns.c
@@ -155,7 +155,8 @@ static int nvme_zone_parse_entry(struct nvme_ns *ns,
 	struct blk_zone zone = { };
 
 	if ((entry->zt & 0xf) != NVME_ZONE_TYPE_SEQWRITE_REQ) {
-		dev_err(ns->ctrl->device, "invalid zone type %#x\n", entry->zt);
+		dev_err(ns->ctrl->device, "invalid zone type %#x at zone %u\n",
+			entry->zt, idx);
 		return -EINVAL;
 	}
 
@@ -178,7 +179,7 @@ int nvme_ns_report_zones(struct nvme_ns *ns, sector_t sector,
 	struct nvme_zone_report *report;
 	struct nvme_command c = { };
 	int ret, zone_idx = 0;
-	unsigned int nz, i;
+	unsigned int max_in_buf, nz, i;
 	size_t buflen;
 
 	if (ns->head->ids.csi != NVME_CSI_ZNS)
@@ -188,6 +189,9 @@ int nvme_ns_report_zones(struct nvme_ns *ns, sector_t sector,
 	if (!report)
 		return -ENOMEM;
 
+	max_in_buf = (buflen - sizeof(struct nvme_zone_report)) /
+		sizeof(struct nvme_zone_descriptor);
+
 	c.zmr.opcode = nvme_cmd_zone_mgmt_recv;
 	c.zmr.nsid = cpu_to_le32(ns->head->ns_id);
 	c.zmr.numd = cpu_to_le32(nvme_bytes_to_numd(buflen));
@@ -207,7 +211,8 @@ int nvme_ns_report_zones(struct nvme_ns *ns, sector_t sector,
 			goto out_free;
 		}
 
-		nz = min((unsigned int)le64_to_cpu(report->nr_zones), nr_zones);
+		nz = min3((unsigned int)le64_to_cpu(report->nr_zones),
+			  nr_zones - zone_idx, max_in_buf);
 		if (!nz)
 			break;
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v1 0/1] nvme: zns: cap zone report nr_zones by DMA buffer size
@ 2026-06-24  5:53 Xixin Liu
  0 siblings, 0 replies; 3+ messages in thread
From: Xixin Liu @ 2026-06-24  5:53 UTC (permalink / raw)
  To: linux-nvme; +Cc: kbusch, axboe, hch, sagi, linux-kernel, liuxixin

Hi,

The ZNS host driver issues Zone Management Receive with Partial Report
(PR=1) fixed.  The Number of Zones (NZ) field in the report header must
reflect the zone descriptors actually transferred in the DMA buffer (ZNS
Command Set Specification Rev 1.2, section 3.4.2).

nvme_ns_report_zones() caps the parse loop by the device-reported NZ and
the caller's nr_zones limit, but not by the number of descriptors that fit
in buflen.  Cap nz with min3(device NZ, nr_zones - zone_idx, max_in_buf).

Thanks,
Xixin Liu

---

Xixin Liu (1):
  nvme: zns: cap zone report nr_zones by DMA buffer size

 drivers/nvme/host/zns.c | 11 ++++++++---
 1 file changed, 8 insertions(+), 3 deletions(-)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-24  5:54 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-23  9:35 [PATCH v1 0/1] nvme: zns: cap zone report nr_zones by DMA buffer size Xixin Liu
2026-06-23  9:35 ` [PATCH v1 1/1] " Xixin Liu
2026-06-24  5:53 [PATCH v1 0/1] " Xixin Liu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®