[PATCH blktests] nvme/071: add a test for fcloop LS request use-after-free

Shin'ichiro Kawasaki shinichiro.kawasaki at wdc.com
Wed Sep 23 01:33:26 PDT 2026


On Sep 21, 2026 / 21:56, Nguyen Ngoc Thang wrote:
> Delete the fcloop remote port and then the target port while an
> association is being deleted. The Disconnect Association LS is completed
> from a work item that can run after nvmet_fc_unregister_targetport() freed
> the pending request, which KASAN reports as a use-after-free in
> fcloop_tport_lsrqst_work().

It is the better to note which kernel side fix is related to this test case.
I suggest to note the commit title of the kernel fix here.

  If its git hash could be noted, it would be the best, but the fix is not
  yet applied, so we can not do that yet.


When I tried to run this test case, I often observed the test run hanged.
The hang was observed with v7.3-rc4 kernel. It was observed even with the
v2 fix patch [*]. Do you observe hangs on your test systems?

[*] https://lore.kernel.org/linux-nvme/20260921145651.17131-1-ngocthang2710.1999@gmail.com/

Also, please find my comments in line. Thanks!

> 
> Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999 at gmail.com>
> ---
>  tests/nvme/071     | 70 ++++++++++++++++++++++++++++++++++++++++++++++
>  tests/nvme/071.out |  2 ++
>  2 files changed, 72 insertions(+)
>  create mode 100755 tests/nvme/071
>  create mode 100644 tests/nvme/071.out
> 
> diff --git a/tests/nvme/071 b/tests/nvme/071
> new file mode 100755
> index 0000000..d17ef18
> --- /dev/null
> +++ b/tests/nvme/071
> @@ -0,0 +1,70 @@
> +#!/bin/bash
> +# SPDX-License-Identifier: GPL-3.0+
> +# Copyright (C) 2026 Nguyen Ngoc Thang
> +#
> +# Regression test for a use-after-free in fcloop when the target port is
> +# deleted right after the remote port. Deleting the association sends a
> +# Disconnect Association LS whose completion is queued while
> +# nvmet_fc_unregister_targetport() is flushing nvmet_wq. The pending LS request
> +# was freed before that completion ran.

I suggest to the note the kernel side fix commit here too.

> +
> +. tests/nvme/rc
> +
> +DESCRIPTION="delete fcloop target port right after remote port"
> +QUICK=1
> +
> +requires() {
> +	_nvme_requires
> +	_have_loop
> +	_require_nvme_trtype fc
> +}
> +
> +set_conditions() {
> +	_set_nvme_trtype "$@"
> +}
> +
> +test() {
> +	echo "Running ${TEST_NAME}"
> +
> +	_setup_nvmet
> +
> +	local i ports port host_port

Nit: ports is an array, so I suggest to seprarte it from other variables and
declare it as an array:

        local -a ports

> +
> +	_nvmet_target_setup
> +
> +	_get_nvmet_ports "${def_subsysnqn}" ports
> +	port="${ports[0]}"
> +	host_port="${ports_to_hosts[${port}]}"

common/nvme provides _get_fc_host_port(). Let's use it to avoid the
reference to the global variable.

> +
> +	for ((i = 0; i < 20; i++)); do
> +		_nvme_connect_subsys
> +		sleep 0.05
> +
> +		# Deleting the association sends a Disconnect Association LS.
> +		_remove_nvmet_subsystem_from_port "${port}" "${def_subsysnqn}"
> +		sleep "0.00$(printf "%02d" "${i}")"

Is there any reason to variate the sleep time here?

I tried to recreate the KASAN use-after-free using v7.3-rc4 kernel, but I was
not able to do it on my test node. I modified the above line to "sleep 0", then
I was able to recreate the failure. I guess the sleep lengths f
r KASAN recreation could be test system dependent.



More information about the Linux-nvme mailing list