From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org,
"Dave Carroll" <david.carroll@microsemi.com>,
"Wen Xiong" <wenxiong@linux.vnet.ibm.com>,
"Martin K. Petersen" <martin.petersen@oracle.com>,
"Brian King" <brking@linux.vnet.ibm.com>
Subject: [PATCH 3.2 27/61] scsi: aacraid: Fix command send race condition
Date: Wed, 22 Nov 2017 02:11:06 +0000 [thread overview]
Message-ID: <lsq.1511316666.935182798@decadent.org.uk> (raw)
In-Reply-To: <lsq.1511316665.221837797@decadent.org.uk>
3.2.96-rc1 review patch. If anyone has any objections, please let me know.
------------------
From: Brian King <brking@linux.vnet.ibm.com>
commit 1ae948fa4f00f3a2823e7cb19a3049ef27dd6947 upstream.
This fixes a potential race condition observed on Power systems.
Several places throughout the aacraid driver call aac_fib_send or
similar to send a command to the aacraid adapter, then check the return
code to determine if the command was actually sent to the adapter, then
update the phase field in the scsi command scratch pad area to track
that the firmware now owns this command. However, there is nothing that
ensures that by the time the aac_fib_send function returns and we go to
write to the scsi command, that the command hasn't already completed and
the scsi command has been freed. This was causing random crashes in the
TCP stack which was tracked down to be caused by memory that had been a
struct request + scsi_cmnd being now used for an skbuff. Memory
poisoning was enabled in the kernel to debug this which showed that the
last owner of the memory that had been freed was aacraid and that it was
a struct request. The memory that was corrupted was the exact data
pattern of AAC_OWNER_FIRMWARE and it was at the same offset that aacraid
writes, which is scsicmd->SCp.phase. The patch below resolves this
issue.
Signed-off-by: Brian King <brking@linux.vnet.ibm.com>
Tested-by: Wen Xiong <wenxiong@linux.vnet.ibm.com>
Reviewed-by: Dave Carroll <david.carroll@microsemi.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
[bwh: Backported to 3.2:
- Drop changes to aac_send_hba_fib()
- Adjust context]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/drivers/scsi/aacraid/aachba.c
+++ b/drivers/scsi/aacraid/aachba.c
@@ -468,6 +468,7 @@ static int aac_get_container_name(struct
aac_fib_init(cmd_fibcontext);
dinfo = (struct aac_get_name *) fib_data(cmd_fibcontext);
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
dinfo->command = cpu_to_le32(VM_ContainerConfig);
dinfo->type = cpu_to_le32(CT_READ_NAME);
@@ -485,10 +486,8 @@ static int aac_get_container_name(struct
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING "aac_get_container_name: aac_fib_send failed with status: %d.\n", status);
aac_fib_complete(cmd_fibcontext);
@@ -577,6 +576,7 @@ static void _aac_probe_container1(void *
dinfo->command = cpu_to_le32(VM_NameServe64);
dinfo->count = cpu_to_le32(scmd_id(scsicmd));
dinfo->type = cpu_to_le32(FT_FILESYS);
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_fib_send(ContainerCommand,
fibptr,
@@ -588,9 +588,7 @@ static void _aac_probe_container1(void *
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS)
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
- else if (status < 0) {
+ if (status < 0 && status != -EINPROGRESS) {
/* Inherit results from VM_NameServe, if any */
dresp->status = cpu_to_le32(ST_OK);
_aac_probe_container2(context, fibptr);
@@ -613,6 +611,7 @@ static int _aac_probe_container(struct s
dinfo->count = cpu_to_le32(scmd_id(scsicmd));
dinfo->type = cpu_to_le32(FT_FILESYS);
scsicmd->SCp.ptr = (char *)callback;
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_fib_send(ContainerCommand,
fibptr,
@@ -624,10 +623,9 @@ static int _aac_probe_container(struct s
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
+
if (status < 0) {
scsicmd->SCp.ptr = NULL;
aac_fib_complete(fibptr);
@@ -861,6 +859,7 @@ static int aac_get_container_serial(stru
dinfo->command = cpu_to_le32(VM_ContainerConfig);
dinfo->type = cpu_to_le32(CT_CID_TO_32BITS_UID);
dinfo->cid = cpu_to_le32(scmd_id(scsicmd));
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_fib_send(ContainerCommand,
cmd_fibcontext,
@@ -873,10 +872,8 @@ static int aac_get_container_serial(stru
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING "aac_get_container_serial: aac_fib_send failed with status: %d.\n", status);
aac_fib_complete(cmd_fibcontext);
@@ -1689,16 +1686,14 @@ static int aac_read(struct scsi_cmnd * s
printk(KERN_WARNING "aac_read: fib allocation failed\n");
return -1;
}
-
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_adapter_read(cmd_fibcontext, scsicmd, lba, count);
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING "aac_read: aac_fib_send failed with status: %d.\n", status);
/*
@@ -1792,16 +1787,14 @@ static int aac_write(struct scsi_cmnd *
printk(KERN_WARNING "aac_write: fib allocation failed\n");
return -1;
}
-
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_adapter_write(cmd_fibcontext, scsicmd, lba, count, fua);
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING "aac_write: aac_fib_send failed with status: %d\n", status);
/*
@@ -1951,6 +1944,7 @@ static int aac_synchronize(struct scsi_c
synchronizecmd->cid = cpu_to_le32(scmd_id(scsicmd));
synchronizecmd->count =
cpu_to_le32(sizeof(((struct aac_synchronize_reply *)NULL)->data));
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
/*
* Now send the Fib to the adapter
@@ -1966,10 +1960,8 @@ static int aac_synchronize(struct scsi_c
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING
"aac_synchronize: aac_fib_send failed with status: %d.\n", status);
@@ -2031,6 +2023,7 @@ static int aac_start_stop(struct scsi_cm
pmcmd->cid = cpu_to_le32(sdev_id(sdev));
pmcmd->parm = (scsicmd->cmnd[1] & 1) ?
cpu_to_le32(CT_PM_UNIT_IMMEDIATE) : 0;
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
/*
* Now send the Fib to the adapter
@@ -2046,10 +2039,8 @@ static int aac_start_stop(struct scsi_cm
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
aac_fib_complete(cmd_fibcontext);
aac_fib_free(cmd_fibcontext);
@@ -2798,15 +2789,14 @@ static int aac_send_srb_fib(struct scsi_
if (!(cmd_fibcontext = aac_fib_alloc(dev))) {
return -1;
}
+ scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
status = aac_adapter_scsi(cmd_fibcontext, scsicmd);
/*
* Check that the command queued to the controller
*/
- if (status == -EINPROGRESS) {
- scsicmd->SCp.phase = AAC_OWNER_FIRMWARE;
+ if (status == -EINPROGRESS)
return 0;
- }
printk(KERN_WARNING "aac_srb: aac_fib_send failed with status: %d\n", status);
aac_fib_complete(cmd_fibcontext);
next prev parent reply other threads:[~2017-11-22 3:01 UTC|newest]
Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-11-22 2:11 [PATCH 3.2 00/61] 3.2.96-rc1 review Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 07/61] x86/fsgsbase/64: Report FSBASE and GSBASE correctly in core dumps Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 03/61] fcntl: Don't use ambiguous SIG_POLL si_codes Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 08/61] scsi: zfcp: fix queuecommand for scsi_eh commands when DIX enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 06/61] dlm: avoid double-free on error path in dlm_device_{register,unregister} Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 01/61] IB/core: Fix the validations of a multicast LID in attach or detach operations Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 05/61] PCI: shpchp: Enable bridge bus mastering if MSI is enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 04/61] powerpc/mm: Fix check of multiple 16G pages from device tree Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 02/61] signal: move the "sig < SIGRTMIN" check into siginmask(sig) Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 13/61] scsi: zfcp: fix payload with full FCP_RSP IU in SCSI trace records Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 54/61] sctp: do not peel off an assoc from one netns to another one Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 12/61] scsi: zfcp: fix missing trace records for early returns in TMF eh handlers Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 19/61] media: uvcvideo: Prevent heap overflow when accessing mapped controls Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 39/61] MIPS: BCM63XX: allow NULL clock for clk_get_rate Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 58/61] Input: gtco - fix potential out-of-bound access Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 44/61] Input: xpad - add a few new VID/PID combinations Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 47/61] Input: xpad - validate USB endpoint type during probe Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 17/61] drm/ttm: Fix accounting error when fail to get pages for pool Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 14/61] scsi: zfcp: trace HBA FSF response by default on dismiss or timedout late response Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 31/61] powerpc/44x: Fix mask and shift to zero bug Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 25/61] IB/{qib, hfi1}: Avoid flow control testing for RDMA write operation Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 09/61] scsi: zfcp: add handling for FCP_RESID_OVER to the fcp ingress path Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 45/61] Input: xpad - add support for Xbox One controllers Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 42/61] ipv6: fix memory leak with multiple tables during netns destruction Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 33/61] driver core: bus: Fix a potential double free Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 18/61] block: Relax a check in blk_start_queue() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 46/61] Input: xpad - don't depend on endpoint order Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 35/61] xfs: fix incorrect log_flushed on fsync Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 59/61] net: cdc_ether: fix divide by 0 on bad descriptors Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 52/61] ext4: validate s_first_meta_bg at mount time Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 49/61] KVM: SVM: Add a missing 'break' statement Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 41/61] genirq: Make sparse_irq_lock protect what it should protect Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 38/61] MIPS: AR7: allow NULL clock for clk_get_rate Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 40/61] mm/vmstat.c: fix wrong comment Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 34/61] ftrace: Fix selftest goto location on error Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 22/61] USB: core: Avoid race of async_completed() w/ usbdev_release() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 37/61] l2tp: pass tunnel pointer to ->session_create() Ben Hutchings
2017-11-22 2:11 ` Ben Hutchings [this message]
2017-11-22 2:11 ` [PATCH 3.2 57/61] media: imon: Fix null-ptr-deref in imon_probe Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 30/61] scsi: qla2xxx: Fix an integer overflow in sysfs code Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 26/61] net/mlx4_core: Make explicit conversion to 64bit value Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 28/61] [SCSI] qla2xxx: Corrections to returned sysfs error codes Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 32/61] powerpc: Correct instruction code for xxlor instruction Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 43/61] ipv6: fix typo in fib6_net_exit() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 55/61] USB: serial: console: fix use-after-free after failed setup Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 24/61] usb: Add device quirk for Logitech HD Pro Webcam C920-C Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 36/61] l2tp: prevent creation of sessions on terminated tunnels Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 50/61] KVM: async_pf: Fix #DF due to inject "Page not Present" and "Page Ready" exceptions simultaneously Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 10/61] scsi: zfcp: fix capping of unsuccessful GPN_FT SAN response trace records Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 56/61] [media] cx231xx-cards: fix NULL-deref on missing association descriptor Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 60/61] mac80211: don't compare TKIP TX MIC key in reinstall prevention Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 53/61] ext4: fix fencepost in s_first_meta_bg validation Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 11/61] scsi: zfcp: fix passing fsf_req to SCSI trace on TMF to correlate with HBA Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 48/61] smsc95xx: Configure pause time to 0xffff when tx flow control enabled Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 61/61] mac80211: Fix null dereference in ieee80211_key_link() Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 15/61] scsi: mac_esp: Fix PIO transfers for MESSAGE IN phase Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 23/61] usb: quirks: add delay init quirk for Corsair Strafe RGB keyboard Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 16/61] cs5536: add support for IDE controller variant Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 29/61] [SCSI] qla2xxx: Add mutex around optrom calls to serialize accesses Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 20/61] media: lirc_zilog: driver only sends LIRCCODE Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 21/61] media: em28xx: calculate left volume level correctly Ben Hutchings
2017-11-22 2:11 ` [PATCH 3.2 51/61] Input: i8042 - add Gigabyte P57 to the keyboard reset table Ben Hutchings
2017-11-22 14:59 ` [PATCH 3.2 00/61] 3.2.96-rc1 review Guenter Roeck
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=lsq.1511316666.935182798@decadent.org.uk \
--to=ben@decadent.org.uk \
--cc=akpm@linux-foundation.org \
--cc=brking@linux.vnet.ibm.com \
--cc=david.carroll@microsemi.com \
--cc=linux-kernel@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=stable@vger.kernel.org \
--cc=wenxiong@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®