]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
nvme-tcp: send only permitted commands for secure concat
authorMartin George <martinus.gpy@gmail.com>
Tue, 9 Sep 2025 10:35:09 +0000 (16:05 +0530)
committerKeith Busch <kbusch@kernel.org>
Mon, 15 Sep 2025 16:25:05 +0000 (09:25 -0700)
commitdf4666a4908a6d883f628f93a3e6c80981332035
treeb698fd075d36f026ef131142f9551570c64b6598
parent891cdbb162ccdb079cd5228ae43bdeebce8597ad
nvme-tcp: send only permitted commands for secure concat

In addition to sending permitted commands such as connect/auth
over the initial unencrypted admin connection as part of secure
channel concatenation, the host also sends commands such as
Property Get and Identify on the same. This is a spec violation
leading to secure concat failures. Fix this by ensuring these
additional commands are avoided on this connection.

Fixes: 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation")
Signed-off-by: Martin George <marting@netapp.com>
Reviewed-by: Hannes Reinecke <hare@suse.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
drivers/nvme/host/tcp.c