diff options
author | Chao Leng <lengchao@huawei.com> | 2021-01-14 17:09:25 +0800 |
---|---|---|
committer | Christoph Hellwig <hch@lst.de> | 2021-01-18 18:58:18 +0100 |
commit | 7674073b2ed35ac951a49c425dec6b39d5a57140 (patch) | |
tree | 2b0bef7ebfe424595f1f0c96e41be19c3343d1d2 /.get_maintainer.ignore | |
parent | 4d6b1c95b974761c01cbad92321b82232b66d2a2 (diff) |
nvme-rdma: avoid request double completion for concurrent nvme_rdma_timeout
A crash happens when inject completing request long time(nearly 30s).
Each name space has a request queue, when inject completing request long
time, multi request queues may have time out requests at the same time,
nvme_rdma_timeout will execute concurrently. Multi requests in different
request queues may be queued in the same rdma queue, multi
nvme_rdma_timeout may call nvme_rdma_stop_queue at the same time.
The first nvme_rdma_timeout will clear NVME_RDMA_Q_LIVE and continue
stopping the rdma queue(drain qp), but the others check NVME_RDMA_Q_LIVE
is already cleared, and then directly complete the requests, complete
request before the qp is fully drained may lead to a use-after-free
condition.
Add a multex lock to serialize nvme_rdma_stop_queue.
Signed-off-by: Chao Leng <lengchao@huawei.com>
Tested-by: Israel Rukshin <israelr@nvidia.com>
Reviewed-by: Israel Rukshin <israelr@nvidia.com>
Signed-off-by: Christoph Hellwig <hch@lst.de>
Diffstat (limited to '.get_maintainer.ignore')
0 files changed, 0 insertions, 0 deletions