]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
scsi: target: iscsi: Fix timeout on deleted connection
authorDmitry Bogdanov <d.bogdanov@yadro.com>
Tue, 24 Dec 2024 10:17:57 +0000 (13:17 +0300)
committerMartin K. Petersen <martin.petersen@oracle.com>
Sat, 12 Apr 2025 02:13:00 +0000 (22:13 -0400)
NOPIN response timer may expire on a deleted connection and crash with
such logs:

Did not receive response to NOPIN on CID: 0, failing connection for I_T Nexus (null),i,0x00023d000125,iqn.2017-01.com.iscsi.target,t,0x3d

BUG: Kernel NULL pointer dereference on read at 0x00000000
NIP  strlcpy+0x8/0xb0
LR iscsit_fill_cxn_timeout_err_stats+0x5c/0xc0 [iscsi_target_mod]
Call Trace:
 iscsit_handle_nopin_response_timeout+0xfc/0x120 [iscsi_target_mod]
 call_timer_fn+0x58/0x1f0
 run_timer_softirq+0x740/0x860
 __do_softirq+0x16c/0x420
 irq_exit+0x188/0x1c0
 timer_interrupt+0x184/0x410

That is because nopin response timer may be re-started on nopin timer
expiration.

Stop nopin timer before stopping the nopin response timer to be sure
that no one of them will be re-started.

Signed-off-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
Link: https://lore.kernel.org/r/20241224101757.32300-1-d.bogdanov@yadro.com
Reviewed-by: Maurizio Lombardi <mlombard@redhat.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
drivers/target/iscsi/iscsi_target.c

index 1244ef3aa86c1d3ba38e84f1ede005b818d0c249..620ba6e0ab075686024315e9c5d5ea43e1f6269d 100644 (file)
@@ -4263,8 +4263,8 @@ int iscsit_close_connection(
        spin_unlock(&iscsit_global->ts_bitmap_lock);
 
        iscsit_stop_timers_for_cmds(conn);
-       iscsit_stop_nopin_response_timer(conn);
        iscsit_stop_nopin_timer(conn);
+       iscsit_stop_nopin_response_timer(conn);
 
        if (conn->conn_transport->iscsit_wait_conn)
                conn->conn_transport->iscsit_wait_conn(conn);