Commit 4a8f710
scsi: qla2xxx: Fix unmap of already freed sgl
The sgl is freed in the target stack in target_release_cmd_kref() before
calling qlt_free_cmd() but there is an unmap of sgl in qlt_free_cmd() that
causes a panic if sgl is not yet DMA unmapped:
NIP dma_direct_unmap_sg+0xdc/0x180
LR dma_direct_unmap_sg+0xc8/0x180
Call Trace:
ql_dbg_prefix+0x68/0xc0 [qla2xxx] (unreliable)
dma_unmap_sg_attrs+0x54/0xf0
qlt_unmap_sg.part.19+0x54/0x1c0 [qla2xxx]
qlt_free_cmd+0x124/0x1d0 [qla2xxx]
tcm_qla2xxx_release_cmd+0x4c/0xa0 [tcm_qla2xxx]
target_put_sess_cmd+0x198/0x370 [target_core_mod]
transport_generic_free_cmd+0x6c/0x1b0 [target_core_mod]
tcm_qla2xxx_complete_free+0x6c/0x90 [tcm_qla2xxx]
The sgl may be left unmapped in error cases of response sending. For
instance, qlt_rdy_to_xfer() maps sgl and exits when session is being
deleted keeping the sgl mapped.
This patch removes use-after-free of the sgl and ensures that the sgl is
unmapped for any command that was not sent to firmware.
Link: https://lore.kernel.org/r/[email protected]
Reviewed-by: Himanshu Madhani <[email protected]>
Signed-off-by: Dmitry Bogdanov <[email protected]>
Signed-off-by: Martin K. Petersen <[email protected]>1 parent 7fb223d commit 4a8f710
1 file changed
+5
-9
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3319 | 3319 | | |
3320 | 3320 | | |
3321 | 3321 | | |
3322 | | - | |
3323 | | - | |
| 3322 | + | |
3324 | 3323 | | |
3325 | 3324 | | |
3326 | 3325 | | |
| |||
3445 | 3444 | | |
3446 | 3445 | | |
3447 | 3446 | | |
3448 | | - | |
3449 | | - | |
3450 | | - | |
3451 | | - | |
3452 | 3447 | | |
3453 | 3448 | | |
3454 | 3449 | | |
| |||
3466 | 3461 | | |
3467 | 3462 | | |
3468 | 3463 | | |
| 3464 | + | |
| 3465 | + | |
| 3466 | + | |
| 3467 | + | |
3469 | 3468 | | |
3470 | 3469 | | |
3471 | 3470 | | |
| |||
3870 | 3869 | | |
3871 | 3870 | | |
3872 | 3871 | | |
3873 | | - | |
3874 | | - | |
3875 | | - | |
3876 | 3872 | | |
3877 | 3873 | | |
3878 | 3874 | | |
| |||
0 commit comments