Re: [PATCH] vhost-scsi: Prevent OOM from invalid protection SGL count
Mike Christie <[email protected]>
| Newsgroups | dev.linux.lists.virtualization,org.kernel.vger.kvm,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
cc'ing Linfeng.
Linfeng also reported this bug and provided a patch that has your check
and an extra check to avoid calling into the function in the first
place. It's been stuck in some other list.
I think it might be best for Linfeng to re-submit their patch now so it
can get merged. For that patch, I think there was one outstanding
question left where Michael had asked if the issue was found with AI so
the proper tag could be added. I don't think that question was responded to.
On 7/17/26 9:22 AM, Jia Jia wrote:
> The protection SGL path passes the result of vhost_scsi_calc_sgls()
> directly to sg_alloc_table_chained(). The helper returns a negative
> errno when the iterator is invalid or the request exceeds the segment
> limit. The negative errno is then treated as a very large unsigned count
> and sends the request into the SGL allocation path with an invalid size.
>
> Repeated malformed T10-PI submissions from a host-side application caused
> memory usage to rise sharply. MemAvailable fell to about 200 MB, and PSI
> full avg10 reached about 1.46. The OOM killer terminated several userspace
> processes before the endpoint cleanup completed. The kernel log included:
>
> [17036.451028] Out of memory: Killed process 2345 (systemd)
> [17036.493325] Out of memory: Killed process 2349 (sd-pam)
> [17078.265127] Out of memory: Killed process 1793 (networkd-dispat)
>
> Return the calculation error before setting up the protection SGL. This
> keeps the protection path consistent with the data SGL path and prevents
> the invalid count from entering the allocation path.
>
> Fixes: bca939d5bcd0 ("vhost-scsi: Dynamically allocate scatterlists")
> Cc: [email protected]
> Signed-off-by: Jia Jia <[email protected]>
> ---
> drivers/vhost/scsi.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/vhost/scsi.c b/drivers/vhost/scsi.c
> index 9a1253b9d..8486652fd 100644
> --- a/drivers/vhost/scsi.c
> +++ b/drivers/vhost/scsi.c
> @@ -972,6 +972,9 @@ vhost_scsi_mapal(struct vhost_scsi *vs, struct vhost_scsi_cmd *cmd,
> if (prot_bytes) {
> sgl_count = vhost_scsi_calc_sgls(prot_iter, prot_bytes,
> VHOST_SCSI_PREALLOC_PROT_SGLS);
> + if (sgl_count < 0)
> + return sgl_count;
> +
> cmd->prot_table.sgl = cmd->prot_sgl;
> ret = sg_alloc_table_chained(&cmd->prot_table, sgl_count,
> cmd->prot_table.sgl,
> --
> 2.43.0
>