[PATCH 6.18.y] nvme-pci: DMA unmap the correct regions in nvme_free_sgls

Nicolai Buchwitz <[email protected]>
Newsgroups org.infradead.lists.linux-nvme,org.kernel.vger.stable
Message-ID <[email protected]>
From: Roger Pau Monne <[email protected]>

commit a54afbc8a2138f8c2490510cf26cde188d480c43 upstream.

The call to nvme_free_sgls() in nvme_unmap_data() has the sg_list and sge
parameters swapped.  This wasn't noticed by the compiler because both share
the same type.  On a Xen PV hardware domain, and possibly any other
architectures that takes that path, this leads to corruption of the NVMe
contents.

Fixes: f0887e2a52d4 ("nvme-pci: create common sgl unmapping helper")
Reviewed-by: Christoph Hellwig <[email protected]>
Signed-off-by: Roger Pau Monné <[email protected]>
Signed-off-by: Keith Busch <[email protected]>
[nb: drop the attrs parameter added in 6.19 by commit 61d43b1731e0
 ("nvme-pci: migrate to dma_map_phys instead of map_page"), which is
 not in 6.18.y]
Signed-off-by: Nicolai Buchwitz <[email protected]>
---
This hits 6.18 too: besides the known Xen PV issue, the missing fix
leads to corrupted data on NVMe disks with SGL support on BCM2712
(Raspberry Pi 5).

Reported and diagnosed in https://github.com/raspberrypi/linux/issues/7496
Backported by Phil Elwell in https://github.com/raspberrypi/linux/pull/7500

 drivers/nvme/host/pci.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/nvme/host/pci.c b/drivers/nvme/host/pci.c
index 5e36a5926fe0..8c66fd23a143 100644
--- a/drivers/nvme/host/pci.c
+++ b/drivers/nvme/host/pci.c
@@ -761,8 +761,8 @@ static void nvme_unmap_data(struct request *req)
 
 	if (!blk_rq_dma_unmap(req, dma_dev, &iod->dma_state, iod->total_len)) {
 		if (nvme_pci_cmd_use_sgl(&iod->cmd))
-			nvme_free_sgls(req, iod->descriptors[0],
-				       &iod->cmd.common.dptr.sgl);
+			nvme_free_sgls(req, &iod->cmd.common.dptr.sgl,
+				       iod->descriptors[0]);
 		else
 			nvme_free_prps(req);
 	}
-- 
2.53.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.