[PATCH blktests] nvme/070: add a test for Identify CNS 07h NULL pointer dereference
Guixin Liu <[email protected]> Fri, 31 Jul 2026 11:26:01 +0800
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <[email protected]> |
nvmet_execute_identify_nslist() handles both the Active Namespace ID list (CNS 02h) and the per-command-set variant (CNS 07h). For CNS 07h it filtered the list on req->ns->csi, but this handler never resolves req->ns, so it is always NULL. As soon as an enabled namespace with an NSID above the requested value exists, the target dereferenced a NULL pointer and oopsed. This test connects a target with a single namespace and issues an Identify with CNS 07h starting from NSID 0, which is exactly the condition that triggered the crash. Without the kernel fix [0] the target oopses; with it the command completes normally. [0] https://lore.kernel.org/linux-nvme/[email protected]/ Suggested-by: Christoph Hellwig <[email protected]> Signed-off-by: Guixin Liu <[email protected]> --- tests/nvme/070 | 54 ++++++++++++++++++++++++++++++++++++++++++++++ tests/nvme/070.out | 2 ++ 2 files changed, 56 insertions(+) create mode 100755 tests/nvme/070 create mode 100644 tests/nvme/070.out diff --git a/tests/nvme/070 b/tests/nvme/070 new file mode 100755 index 0000000..1f29a69 --- /dev/null +++ b/tests/nvme/070 @@ -0,0 +1,54 @@ +#!/bin/bash +# SPDX-License-Identifier: GPL-3.0+ +# Copyright (C) 2026 Guixin Liu +# +# Regression test for the NULL pointer dereference in +# nvmet_execute_identify_nslist() when handling Identify CNS 07h (Active +# Namespace ID List for the specified I/O Command Set). The CNS 07h handler +# filtered the list on req->ns->csi, but this handler never resolves req->ns +# so it is always NULL. As soon as an enabled namespace with an NSID above the +# requested value exists, the target dereferenced a NULL pointer and oopsed. + +. tests/nvme/rc + +DESCRIPTION="issue Identify CNS 07h (per-command-set active NS list)" +QUICK=1 + +requires() { + _nvme_requires + _have_loop + _require_nvme_trtype_is_fabrics +} + +set_conditions() { + _set_nvme_trtype "$@" +} + +test() { + echo "Running ${TEST_NAME}" + + _setup_nvmet + + _nvmet_target_setup + + _nvme_connect_subsys + + local nvmedev + nvmedev=$(_find_nvme_dev "${def_subsysnqn}") + + # CNS 07h == Active Namespace ID list for the specified I/O Command Set. + # CDW10 bits[7:0] hold the CNS; CDW11 bits[31:24] hold the CSI (0 == NVM). + # Request from NSID 0 so the enabled namespace (NSID 1) is listed, which + # is exactly the condition that used to dereference the NULL req->ns. + if ! nvme admin-passthru "/dev/${nvmedev}" --opcode=0x06 \ + --namespace-id=0 --cdw10=0x07 --cdw11=0 --data-len=4096 -r \ + >> "${FULL}" 2>&1; then + echo "Error: Identify CNS 07h failed" + fi + + _nvme_disconnect_subsys + + _nvmet_target_cleanup + + echo "Test complete" +} diff --git a/tests/nvme/070.out b/tests/nvme/070.out new file mode 100644 index 0000000..b765a28 --- /dev/null +++ b/tests/nvme/070.out @@ -0,0 +1,2 @@ +Running nvme/070 +Test complete -- 2.43.7