[PATCH blktests] nvme/071: add a test for fcloop LS request use-after-free

Nguyen Ngoc Thang ngocthang2710.1999 at gmail.com
Wed Sep 23 06:53:16 PDT 2026


Hi Shin'ichiro,

Thanks for testing and the review, v2 is sent:

  [PATCH blktests v2] nvme/071: add a test for fcloop LS request use-after-free
  Message-ID: <20260923134938.12673-1-ngocthang2710.1999 at gmail.com>

- Noted the kernel fix's commit title in the file header, since it's not
  applied yet and has no hash.
- local -a ports, and use _get_fc_host_port() instead of reading
  ports_to_hosts directly.
- On the hang: I couldn't reproduce a real hang, but I think I found the
  cause. _nvme_connect_subsys() doesn't pass --ctrl-loss-tmo, so it
  defaults to NVMF_DEF_CTRL_LOSS_TMO (600s). After we pull the remote
  port the host has nothing to reconnect to, and the following
  _nvme_disconnect_subsys() has to wait on that reconnect state before
  it can remove the controller, up to 10 minutes if it lands there.
  v2 connects with --ctrl-loss-tmo 0 so the host gives up on the first
  failed reconnect instead. Let me know if you still see it hang with
  this.
- On the swept delay: I tried a fixed "sleep 0" here too and got the
  same KASAN UAF + list_debug BUG as with the sweep, so it wasn't
  earning its complexity. Dropped it in v2.

Thanks,
Thang



More information about the Linux-nvme mailing list