scsi: lpfc: Fix NVME Target crash in defer rcv logic
authorJames Smart <jsmart2021@gmail.com>
Tue, 26 Jun 2018 15:24:28 +0000 (08:24 -0700)
committerMartin K. Petersen <martin.petersen@oracle.com>
Wed, 11 Jul 2018 02:15:09 +0000 (22:15 -0400)
Kernel occasionally crashed with the following
ops on NVME Target:
  BUG: unable to handle kernel NULL pointer dereference at 0000000000000058
  IP: [<ffffffffa042ee50>] lpfc_nvmet_defer_rcv+0x50/0x70 [lpfc]

Callback routine was called for deferred rcv when it should be treated as a
normal rcv.

Added code in callback routine to detect this condition and log a message,
then bail.

Signed-off-by: Dick Kennedy <dick.kennedy@broadcom.com>
Signed-off-by: James Smart <james.smart@broadcom.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
drivers/scsi/lpfc/lpfc_nvmet.c

index ccb35efef1e191aa9a8fa2e292f8338ddf0a2bca..ff994712f58a596c763f6da0eda1467112ef09fe 100644 (file)
@@ -402,6 +402,7 @@ lpfc_nvmet_ctxbuf_post(struct lpfc_hba *phba, struct lpfc_nvmet_ctxbuf *ctx_buf)
 
                /* Process FCP command */
                if (rc == 0) {
+                       ctxp->rqb_buffer = NULL;
                        atomic_inc(&tgtp->rcv_fcp_cmd_out);
                        nvmebuf->hrq->rqbp->rqb_free_buffer(phba, nvmebuf);
                        return;
@@ -1116,8 +1117,17 @@ lpfc_nvmet_defer_rcv(struct nvmet_fc_target_port *tgtport,
        lpfc_nvmeio_data(phba, "NVMET DEFERRCV: xri x%x sz %d CPU %02x\n",
                         ctxp->oxid, ctxp->size, smp_processor_id());
 
+       if (!nvmebuf) {
+               lpfc_printf_log(phba, KERN_INFO, LOG_NVME_IOERR,
+                               "6425 Defer rcv: no buffer xri x%x: "
+                               "flg %x ste %x\n",
+                               ctxp->oxid, ctxp->flag, ctxp->state);
+               return;
+       }
+
        tgtp = phba->targetport->private;
-       atomic_inc(&tgtp->rcv_fcp_cmd_defer);
+       if (tgtp)
+               atomic_inc(&tgtp->rcv_fcp_cmd_defer);
 
        /* Free the nvmebuf since a new buffer already replaced it */
        nvmebuf->hrq->rqbp->rqb_free_buffer(phba, nvmebuf);