Re: [PATCH] nvmet: pci-epf: put CQ ref on create_cq mapping failure
Keith Busch <[email protected]>
| Newsgroups | org.kernel.vger.linux-kernel,org.infradead.lists.linux-nvme,org.kernel.vger.stable |
|---|---|
| Message-ID | <anoN25Z3HHIpijuL@kbusch-mbp> |
On Tue, Aug 04, 2026 at 09:36:25PM +0000, Yifei Gao wrote: > nvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a > reference on the controller and installs the completion queue. If the > subsequent PCI address-space mapping fails or returns a too-small partial > mapping, the function jumps to err_internal / err_unmap_queue without > calling nvmet_cq_put(). The matching put in nvmet_pci_epf_delete_cq() is > gated on NVMET_PCI_EPF_Q_LIVE, which is only set after the mapping > succeeds, so teardown never releases these references. A remote PCI host > that drives Create IO CQ commands with a failing PRP1/pci_addr therefore > leaks the CQ and a controller reference on each attempt. > > Drop the CQ reference on the mapping-failure paths. The err_internal and > err_unmap_queue labels are only reachable after nvmet_cq_create() has > succeeded, so this pairs the create/put correctly. Thanks, applied to nvme-7.3.