[PATCH 6.18.y] nvme-pci: DMA unmap the correct regions in nvme_free_sgls
Nicolai Buchwitz <[email protected]>
| Newsgroups | org.infradead.lists.linux-nvme,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Roger Pau Monne <[email protected]> commit a54afbc8a2138f8c2490510cf26cde188d480c43 upstream. The call to nvme_free_sgls() in nvme_unmap_data() has the sg_list and sge parameters swapped. This wasn't noticed by the compiler because both share the same type. On a Xen PV hardware domain, and possibly any other architectures that takes that path, this leads to corruption of the NVMe contents. Fixes: f0887e2a52d4 ("nvme-pci: create common sgl unmapping helper") Reviewed-by: Christoph Hellwig <[email protected]> Signed-off-by: Roger Pau Monné <[email protected]> Signed-off-by: Keith Busch <[email protected]> [nb: drop the attrs parameter added in 6.19 by commit 61d43b1731e0 ("nvme-pci: migrate to dma_map_phys instead of map_page"), which is not in 6.18.y] Signed-off-by: Nicolai Buchwitz <[email protected]> --- This hits 6.18 too: besides the known Xen PV issue, the missing fix leads to corrupted data on NVMe disks with SGL support on BCM2712 (Raspberry Pi 5). Reported and diagnosed in https://github.com/raspberrypi/linux/issues/7496 Backported by Phil Elwell in https://github.com/raspberrypi/linux/pull/7500 drivers/nvme/host/pci.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/nvme/host/pci.c b/drivers/nvme/host/pci.c index 5e36a5926fe0..8c66fd23a143 100644 --- a/drivers/nvme/host/pci.c +++ b/drivers/nvme/host/pci.c @@ -761,8 +761,8 @@ static void nvme_unmap_data(struct request *req) if (!blk_rq_dma_unmap(req, dma_dev, &iod->dma_state, iod->total_len)) { if (nvme_pci_cmd_use_sgl(&iod->cmd)) - nvme_free_sgls(req, iod->descriptors[0], - &iod->cmd.common.dptr.sgl); + nvme_free_sgls(req, &iod->cmd.common.dptr.sgl, + iod->descriptors[0]); else nvme_free_prps(req); } -- 2.53.0