Re: [PATCH v3 0/5] nvme: a few error-path and validation fixes
Keith Busch <[email protected]>
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <anon0VEOq8AApalr@kbusch-mbp> |
On Tue, Aug 04, 2026 at 10:18:56AM +0800, Guixin Liu wrote: > This series collects independent fixes found while auditing error and > command-processing paths in the NVMe host and target drivers. Each is > standalone; they only share the same subsystem. > > 1. nvmet: an Identify CNS 07h (active NS list for a command set) > dereferences req->ns, which is always NULL on that path -> NULL > pointer oops. Also fixes the filter to test the iterated ns->csi. > > 2. nvmet: nvmet_ns_enable() ignores the percpu_ref_init() return value > and reports success to userspace when it fails, leaving the ns dead. > > 3. nvme-pci: the per-NUMA-node descriptor DMA pools, created lazily on > admin tag set allocation, are only freed in nvme_remove(); a probe > failure after that point leaks them. > > 4. nvme: nvme_query_fdp_info() trusts the device-supplied nruhsd count > and can read past the fixed-size RUH status buffer (heap OOB read). > > 5. nvme: follow-up to #4, suggested by Kanchan -- the RUH status buffer > and the placement handle clamp used the odd S8_MAX - 1 value; raise > the cap to the meaningful U8_MAX (bio->bi_write_stream is u8) and > warn on overflow. #4 was handled by a earlier and different patch, so I dropped that one, and patch 5 had to accomodate. I've applied the result to nvme-7.3.