xprtrdma: Fix BUG after a device removal

"Linux Kernel Mailing List" <[email protected]>
Newsgroups gmane.linux.kernel.commits.head
Message-ID <[email protected]>
Web:        https://git.kernel.org/torvalds/c/e89e8d8fcdc6751e86ccad794b052fe67e6ad619
Commit:     e89e8d8fcdc6751e86ccad794b052fe67e6ad619
Parent:     1179e2c27efe21167ec9d882b14becefba2ee990
Refname:    refs/heads/master
Author:     Chuck Lever <[email protected]>
AuthorDate: Wed Jan 31 12:34:13 2018 -0500
Committer:  Anna Schumaker <[email protected]>
CommitDate: Fri Feb 2 13:31:04 2018 -0500

    xprtrdma: Fix BUG after a device removal
    
    Michal Kalderon reports a BUG that occurs just after device removal:
    
    [  169.112490] rpcrdma: removing device qedr0 for 192.168.110.146:20049
    [  169.143909] BUG: unable to handle kernel NULL pointer dereference at 0000000000000010
    [  169.181837] IP: rpcrdma_dma_unmap_regbuf+0xa/0x60 [rpcrdma]
    
    The RPC/RDMA client transport attempts to allocate some resources
    on demand. Registered buffers are one such resource. These are
    allocated (or re-allocated) by xprt_rdma_allocate to hold RPC Call
    and Reply messages. A hardware resource is associated with each of
    these buffers, as they can be used for a Send or Receive Work
    Request.
    
    If a device is removed from under an NFS/RDMA mount, the transport
    layer is responsible for releasing all hardware resources before
    the device can be finally unplugged. A BUG results when the NFS
    mount hasn't yet seen much activity: the transport tries to release
    resources that haven't yet been allocated.
    
    rpcrdma_free_regbuf() already checks for this case, so just move
    that check to cover the DEVICE_REMOVAL case as well.
    
    Reported-by: Michal Kalderon <[email protected]>
    Fixes: bebd031866ca ("xprtrdma: Support unplugging an HCA ...")
    Signed-off-by: Chuck Lever <[email protected]>
    Tested-by: Michal Kalderon <[email protected]>
    Cc: [email protected] # v4.12+
    Signed-off-by: Anna Schumaker <[email protected]>
---
 net/sunrpc/xprtrdma/verbs.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/net/sunrpc/xprtrdma/verbs.c b/net/sunrpc/xprtrdma/verbs.c
index bb56b9d849c4..e6f84a6434a0 100644
--- a/net/sunrpc/xprtrdma/verbs.c
+++ b/net/sunrpc/xprtrdma/verbs.c
@@ -1502,6 +1502,9 @@ __rpcrdma_dma_map_regbuf(struct rpcrdma_ia *ia, struct rpcrdma_regbuf *rb)
 static void
 rpcrdma_dma_unmap_regbuf(struct rpcrdma_regbuf *rb)
 {
+	if (!rb)
+		return;
+
 	if (!rpcrdma_regbuf_is_mapped(rb))
 		return;
 
@@ -1517,9 +1520,6 @@ rpcrdma_dma_unmap_regbuf(struct rpcrdma_regbuf *rb)
 void
 rpcrdma_free_regbuf(struct rpcrdma_regbuf *rb)
 {
-	if (!rb)
-		return;
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.