Re: [PATCH v2] nvme/070: add a test for Identify CNS 07h NULL pointer dereference
Nilay Shroff <[email protected]> Tue, 4 Aug 2026 10:18:35 +0530
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <[email protected]> |
On 8/4/26 8:16 AM, Guixin Liu wrote: > nvmet_execute_identify_nslist() handles both the Active Namespace ID list > (CNS 02h) and the per-command-set variant (CNS 07h). For CNS 07h it > filtered the list on req->ns->csi, but this handler never resolves > req->ns, so it is always NULL. As soon as an enabled namespace with an > NSID above the requested value exists, the target dereferenced a NULL > pointer and oopsed. > > This test connects a target with a single namespace and issues an > Identify with CNS 07h starting from NSID 0, which is exactly the > condition that triggered the crash. Without the kernel fix [0] the target > oopses; with it the command completes normally. > > [0] https://lore.kernel.org/linux-nvme/[email protected]/ > > Suggested-by: Christoph Hellwig <[email protected]> > Signed-off-by: Guixin Liu <[email protected]> > --- > v1 -> v2: > - Use "nvme list-ns --csi=0" instead of a raw admin-passthru to issue > Identify CNS 07h, as suggested by Nilay and Shinichiro; it drives the > same target code path via the existing nvme-cli subcommand. > > tests/nvme/070 | 52 ++++++++++++++++++++++++++++++++++++++++++++++ > tests/nvme/070.out | 2 ++ > 2 files changed, 54 insertions(+) > create mode 100755 tests/nvme/070 > create mode 100644 tests/nvme/070.out > > diff --git a/tests/nvme/070 b/tests/nvme/070 > new file mode 100755 > index 0000000..b7d8bc5 > --- /dev/null > +++ b/tests/nvme/070 > @@ -0,0 +1,52 @@ > +#!/bin/bash > +# SPDX-License-Identifier: GPL-3.0+ > +# Copyright (C) 2026 Guixin Liu > +# > +# Regression test for the NULL pointer dereference in > +# nvmet_execute_identify_nslist() when handling Identify CNS 07h (Active > +# Namespace ID List for the specified I/O Command Set). The CNS 07h handler > +# filtered the list on req->ns->csi, but this handler never resolves req->ns > +# so it is always NULL. As soon as an enabled namespace with an NSID above the > +# requested value exists, the target dereferenced a NULL pointer and oopsed. > + > +. tests/nvme/rc > + > +DESCRIPTION="issue Identify CNS 07h (per-command-set active NS list)" > +QUICK=1 > + > +requires() { > + _nvme_requires > + _have_loop > + _require_nvme_trtype_is_fabrics > +} > + > +set_conditions() { > + _set_nvme_trtype "$@" > +} > + > +test() { > + echo "Running ${TEST_NAME}" > + > + _setup_nvmet > + > + _nvmet_target_setup > + > + _nvme_connect_subsys > + > + local nvmedev > + nvmedev=$(_find_nvme_dev "${def_subsysnqn}") > + > + # "nvme list-ns --csi=0" issues Identify CNS 07h (Active Namespace ID > + # list for the specified I/O Command Set, here NVM), starting from NSID > + # 0 so the enabled namespace (NSID 1) is listed. That is exactly the > + # condition that used to dereference the NULL req->ns in the target. > + if ! nvme list-ns "/dev/${nvmedev}" --csi=0 >> "${FULL}" 2>&1; then > + echo "Error: Identify CNS 07h (list-ns --csi=0) failed" > + fi > + > + _nvme_disconnect_subsys > + > + _nvmet_target_cleanup > + > + echo "Test complete" > +} > diff --git a/tests/nvme/070.out b/tests/nvme/070.out > new file mode 100644 > index 0000000..b765a28 > --- /dev/null > +++ b/tests/nvme/070.out > @@ -0,0 +1,2 @@ > +Running nvme/070 > +Test complete Looks good to me. Reviewed-by: Nilay Shroff <[email protected]>