Re: [PATCH v2] nvme/070: add a test for Identify CNS 07h NULL pointer dereference
Shin'ichiro Kawasaki <[email protected]>
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <ansFVrVVtnxfhi0Y@shinmob> |
On Aug 04, 2026 / 10:46, Guixin Liu wrote: > nvmet_execute_identify_nslist() handles both the Active Namespace ID list > (CNS 02h) and the per-command-set variant (CNS 07h). For CNS 07h it > filtered the list on req->ns->csi, but this handler never resolves > req->ns, so it is always NULL. As soon as an enabled namespace with an > NSID above the requested value exists, the target dereferenced a NULL > pointer and oopsed. > > This test connects a target with a single namespace and issues an > Identify with CNS 07h starting from NSID 0, which is exactly the > condition that triggered the crash. Without the kernel fix [0] the target > oopses; with it the command completes normally. > > [0] https://lore.kernel.org/linux-nvme/[email protected]/ > > Suggested-by: Christoph Hellwig <[email protected]> > Signed-off-by: Guixin Liu <[email protected]> > --- > v1 -> v2: > - Use "nvme list-ns --csi=0" instead of a raw admin-passthru to issue > Identify CNS 07h, as suggested by Nilay and Shinichiro; it drives the > same target code path via the existing nvme-cli subcommand. Thanks for this v2 patch. It looks good to me. I will wait for the kernel side fix get settled on Linus master branch before I apply this patch.