Thread (16 messages) 16 messages, 2 authors, 2021-09-22
STALE1764d LANDED

[PATCH 01/14] lpfc: Fix list_add corruption in lpfc_drain_txq

From: James Smart <hidden>
Date: 2021-09-10 23:32:10
Subsystem: emulex/broadcom lpfc fc/fcoe scsi driver, scsi subsystem, the rest · Maintainers: Justin Tee, Paul Ely, "James E.J. Bottomley", "Martin K. Petersen", Linus Torvalds

When parsing the txq list in lpfc_drain_txq, the driver attempts to
pass the requests to the adapter. If such an attempt fails, a local
"fail_msg" string is set and a log message output.  The job is then
added to a completions list for cancellation.

Processing of any further jobs from the txq list continues, but since
"fail_msg" remains set, jobs are added to the completions list
regardless of whether a wqe was passed to the adapter.  If successfully
added to txcmplq, jobs are added to both lists resulting in list
corruption.

Fix by clearing the fail_msg string after adding a job to the
completions list. This stops the subsequent jobs from being
added to the completions list unless they had an appropriate failure.

Co-developed-by: Justin Tee <justin.tee@broadcom.com>
Signed-off-by: Justin Tee <justin.tee@broadcom.com>
Signed-off-by: James Smart <redacted>
---
 drivers/scsi/lpfc/lpfc_sli.c | 1 +
 1 file changed, 1 insertion(+)
diff --git a/drivers/scsi/lpfc/lpfc_sli.c b/drivers/scsi/lpfc/lpfc_sli.c
index ffd8a140638c..546c851938bc 100644
--- a/drivers/scsi/lpfc/lpfc_sli.c
+++ b/drivers/scsi/lpfc/lpfc_sli.c
@@ -21104,6 +21104,7 @@ lpfc_drain_txq(struct lpfc_hba *phba)
 					fail_msg,
 					piocbq->iotag, piocbq->sli4_xritag);
 			list_add_tail(&piocbq->list, &completions);
+			fail_msg = NULL;
 		}
 		spin_unlock_irqrestore(&pring->ring_lock, iflags);
 	}
-- 
2.26.2
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help