[PATCH v4 00/10] mpi3mr: Few Enhancements and minor fixes
Ranjan Kumar <[email protected]> Wed, 5 Aug 2026 16:36:24 +0530
| Newsgroups | gmane.linux.scsi |
|---|---|
| Message-ID | <[email protected]> |
Few Enhancements and minor fixes of mpi3mr driver.
Changes since v3:
- Patch 1: Guarded the firmware buffer loop against a bad decrement size.
- Patch 4: Made reset_to/abort_to a single write, tightened pgsz bounds.
- Patch 5: Fixed a reply_dma leak, a double-decrement, and a stalled index.
- Patch 6: Added synchronize_irq() on queue teardown, fixed a segment leak.
- Patch 7: Closed an ABBA deadlock between the EH/reset thread and worker.
- Patch 8: Fixed a fatal device_del() bug and the same deadlock as patch 7.
Changes since v2:
- Patch 1: Added missing endianness conversions (le16_to_cpu()) for
buffer size fields in mpi3mr_alloc_diag_bufs() to prevent large memory
allocations on big-endian architectures.
- Patch 5: Hardened reply queue processing by adding bounds checking for
request_queue_id, fixed a TOCTOU race with a double-check pattern
(using dma_rmb and atomic_add_unless), and replaced a direct panic()
with a safe ioc_err() log for malformed DMA reply addresses.
- Patch 6: Fixed potential NULL pointer dereferences and Use-After-Free
during spurious interrupts by properly clearing intr_info[*].op_reply_q
when reply queue segments are freed.
- Patch 7: Resolved multiple concurrency issues around firmware event
cleanup: fixed TOCTOU races by safely handling current_event under the
fwevt_lock, fixed a Use-After-Free by delaying the release of event
references until after cancellation, and prevented deadlocks during
module unload.
- Patch 8: Removed an explicit sas_rphy_free() to fix a double-free
vulnerability on the sas_rphy_add() error path, as sas_port_delete()
implicitly handles the cleanup.
Changes since v1:
- Fixed test robot build warning.
- Patch 1: Added le32_to_cpu() conversion for driver_pg1.flags to prevent
incorrect logic on big-endian architectures.
- Patch 4: Added bounds checking for firmware-provided NVMe page size to
prevent undefined shift behavior and potential divide-by-zero panics.
- Patch 5: Added missing dma_rmb() memory barriers in reply queue
processing loops to prevent weakly ordered architectures from
processing stale data.
- Patch 6: Hardened operational queue error handling to prevent
NULL pointer dereferences and deferred kernel panics
during driver cleanup.
- Patch 7: Fixed a TOCTOU Use-After-Free race condition and reference leak
during firmware event cleanup by safely acquiring the event reference
under a spinlock.
- Patch 8: Added missing NULL pointer checks for rphy allocations and
handled sas_rphy_add() failures to prevent NULL pointer dereferences
and resource leaks.
- Patch 9: Added return value check for mpi3mr_add_host_phy() to prevent
a NULL pointer dereference during device addition events.
Ranjan Kumar (10):
mpi3mr: Skip device shutdown during unload per controller
configuration
mpi3mr: Update MPI Headers to revision 41
mpi3mr: Add early timestamp synchronization after driver load
mpi3mr: Fix NVMe page size caching for non-operational devices
mpi3mr: Fix performance regression caused by extended IRQ poll sleep
mpi3mr: Fix memory leak on operational queue creation failure
mpi3mr: Fix firmware event reference leak during cleanup
mpi3mr: Fix SAS port allocation and registration error handling
mpi3mr: Fix SAS PHY cleanup in host addition error paths
mpi3mr: Driver version update to 8.18.0.8.50
drivers/scsi/mpi3mr/mpi/mpi30_cnfg.h | 77 ++++++++-
drivers/scsi/mpi3mr/mpi/mpi30_image.h | 7 +-
drivers/scsi/mpi3mr/mpi/mpi30_ioc.h | 15 +-
drivers/scsi/mpi3mr/mpi/mpi30_transport.h | 2 +-
drivers/scsi/mpi3mr/mpi3mr.h | 13 +-
drivers/scsi/mpi3mr/mpi3mr_app.c | 44 +++--
drivers/scsi/mpi3mr/mpi3mr_fw.c | 193 +++++++++++++++++-----
drivers/scsi/mpi3mr/mpi3mr_os.c | 173 ++++++++++++-------
drivers/scsi/mpi3mr/mpi3mr_transport.c | 103 ++++++++++--
9 files changed, 479 insertions(+), 148 deletions(-)
--
2.47.3