linux/drivers/nvme/target
Sagi Grimberg c758b77d4a nvmet: fix a possible leak when destroy a ctrl during qp establishment
In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we
know that a ctrl was allocated (in the admin connect request handler)
and we need to release pending AERs, clear ctrl->sqs and sq->ctrl
(for nvme-loop primarily), and drop the final reference on the ctrl.

However, a small window is possible where nvmet_sq_destroy starts (as
a result of the client giving up and disconnecting) concurrently with
the nvme admin connect cmd (which may be in an early stage). But *before*
kill_and_confirm of sq->ref (i.e. the admin connect managed to get an sq
live reference). In this case, sq->ctrl was allocated however after it was
captured in a local variable in nvmet_sq_destroy.
This prevented the final reference drop on the ctrl.

Solve this by re-capturing the sq->ctrl after all inflight request has
completed, where for sure sq->ctrl reference is final, and move forward
based on that.

This issue was observed in an environment with many hosts connecting
multiple ctrls simoutanuosly, creating a delay in allocating a ctrl
leading up to this race window.

Reported-by: Alex Turin <alex@vastdata.com>
Signed-off-by: Sagi Grimberg <sagi@grimberg.me>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
History 2024-05-28 10:01:52 -07:00
..
admin-cmd.c nvmet: set maxcmd to be per controller 2024-03-02 15:18:08 -08:00
auth.c nvme updates for Linux 6.10 2024-05-14 09:14:49 -06:00
configfs.c nvmet: fix ns enable/disable possible hang 2024-05-23 13:44:42 -07:00
core.c nvmet: fix a possible leak when destroy a ctrl during qp establishment 2024-05-28 10:01:52 -07:00
discovery.c nvmet: set maxcmd to be per controller 2024-03-02 15:18:08 -08:00
fabrics-cmd-auth.c nvmet: return DHCHAP status codes from nvmet_setup_auth() 2024-05-01 03:07:20 -07:00
fabrics-cmd.c nvmet: return DHCHAP status codes from nvmet_setup_auth() 2024-05-01 03:07:20 -07:00
fc.c nvmet-fc: move RCU read lock to nvmet_fc_assoc_exists 2024-04-04 08:47:56 -07:00
fcloop.c nvme: fcloop: make fcloop_class constant 2024-03-05 07:56:21 -08:00
io-cmd-bdev.c nvme: port block device access to file 2024-02-25 12:05:24 +01:00
io-cmd-file.c nvmet: use bvec_set_page to initialize bvecs 2023-02-03 08:20:55 -07:00
Kconfig nvme: improve NVME_HOST_AUTH and NVME_TARGET_AUTH config descriptions 2023-12-04 08:39:03 -08:00
loop.c nvme: use ctrl state accessor 2024-01-29 07:02:50 -08:00
Makefile nvmet: implement basic In-Band Authentication 2022-08-02 17:14:49 -06:00
nvmet.h nvme updates for Linux 6.10 2024-05-14 09:14:49 -06:00
passthru.c nvmet: set maxcmd to be per controller 2024-03-02 15:18:08 -08:00
rdma.c nvme updates for Linux 6.10 2024-05-14 09:14:49 -06:00
tcp.c nvmet-tcp: fix possible memory leak when tearing down a controller 2024-05-01 02:58:42 -07:00
trace.c nvmet: add tracing of zns commands 2024-03-08 06:58:20 -08:00
trace.h nvme: trace: avoid memcpy overflow warning 2024-01-05 13:16:18 -08:00
zns.c nvmet: zns: Do not reference the gendisk conv_zones_bitmap 2024-04-17 08:44:03 -06:00