[PATCH blktests] nvme/071: add a test for fcloop LS request use-after-free
Nguyen Ngoc Thang
ngocthang2710.1999 at gmail.com
Wed Sep 23 06:53:16 PDT 2026
Hi Shin'ichiro,
Thanks for testing and the review, v2 is sent:
[PATCH blktests v2] nvme/071: add a test for fcloop LS request use-after-free
Message-ID: <20260923134938.12673-1-ngocthang2710.1999 at gmail.com>
- Noted the kernel fix's commit title in the file header, since it's not
applied yet and has no hash.
- local -a ports, and use _get_fc_host_port() instead of reading
ports_to_hosts directly.
- On the hang: I couldn't reproduce a real hang, but I think I found the
cause. _nvme_connect_subsys() doesn't pass --ctrl-loss-tmo, so it
defaults to NVMF_DEF_CTRL_LOSS_TMO (600s). After we pull the remote
port the host has nothing to reconnect to, and the following
_nvme_disconnect_subsys() has to wait on that reconnect state before
it can remove the controller, up to 10 minutes if it lands there.
v2 connects with --ctrl-loss-tmo 0 so the host gives up on the first
failed reconnect instead. Let me know if you still see it hang with
this.
- On the swept delay: I tried a fixed "sleep 0" here too and got the
same KASAN UAF + list_debug BUG as with the sweep, so it wasn't
earning its complexity. Dropped it in v2.
Thanks,
Thang
More information about the Linux-nvme
mailing list