Received: by 2002:a05:6358:45e:b0:b5:b6eb:e1f9 with SMTP id 30csp220005rwe; Tue, 23 Aug 2022 22:52:37 -0700 (PDT) X-Google-Smtp-Source: AA6agR49fcwjUyE2i28N/njdaEbwl30gDcoaHNKkrgyzGZFU2aFk5GplWVh60PT3ZiSb2sAfRAre X-Received: by 2002:a05:6402:3714:b0:445:d91b:b0aa with SMTP id ek20-20020a056402371400b00445d91bb0aamr6047110edb.313.1661320357182; Tue, 23 Aug 2022 22:52:37 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1661320357; cv=none; d=google.com; s=arc-20160816; b=qqkTxAknqGZU+ZbfIkdXzSW5jlpKnxzMYd9qpcu78bgrDm4xlx7rSJ53oOYuDVWBGo +uGme1Whou8zr2QIrUC+ysUGKvpyeIDtLsXoEbydPC+ZpzKQdvWZQMYSQIW/2xI38Pes bosbxtJwpnKkLCRDHk4CRTt4hU/IQE9vjwASQ950UaFZnd99qldNqndJzKprRxhDZwGS UVp3S/wA8oxP9ocbhBvIg2fUnuKO4SPxhXz4y+Go5KL9mIqLBzfdqOCjPGCFfy/eLng+ OB+Y/pcoEN1Jknf7AillwZfMLIsA7eAa3IzNMIVPM7RyjKSVIpn5KzWJKfVCLQ7bwqj9 XENw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=dOD9ApdxmctMdXhdkWAMhPoh4r96fGpusQaJclvr/pQ=; b=eV/XyF8ImLXd3b3K522mY8+tLotvp9MGjZ5gdpwvjHTGztyI77MA+xnKPT/V4aLDN5 ytPyU9Ul9SsxRjF1W5CJcg1j8lHy0gQxtW2RdCNkmDq1Tat7+Xpn6JmwYjQp5lEVNizJ 7IP8BV2LPP/acqWlqgZpGN64bPcKRMFTWhZNP5Sozijv99I94Q8O+2RZtZ/it6v3sq+i 1Q7JXST7LS87vNvNMgj/EWrHOE6Z+/z2yAlp7SloSQXi4JMEdaPhYn9Vf+9637REJRGn BPyywYRKzj3NW08+yJlVc1Sk6Q5HEmGrTKsMnqv6pSOn1E9FVIG0o9Mcf/frjxIf4oE9 pv6Q== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=alibaba.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id b7-20020a056402350700b0043c8f3fe2ebsi4123951edd.74.2022.08.23.22.52.11; Tue, 23 Aug 2022 22:52:37 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=alibaba.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234107AbiHXFtI (ORCPT + 99 others); Wed, 24 Aug 2022 01:49:08 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46570 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233451AbiHXFtE (ORCPT ); Wed, 24 Aug 2022 01:49:04 -0400 Received: from out30-54.freemail.mail.aliyun.com (out30-54.freemail.mail.aliyun.com [115.124.30.54]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id C39408001A; Tue, 23 Aug 2022 22:48:56 -0700 (PDT) X-Alimail-AntiSpam: AC=PASS;BC=-1|-1;BR=01201311R891e4;CH=green;DM=||false|;DS=||;FP=0|-1|-1|-1|0|-1|-1|-1;HT=ay29a033018046051;MF=ziyangzhang@linux.alibaba.com;NM=1;PH=DS;RN=7;SR=0;TI=SMTPD_---0VN5zTdx_1661320132; Received: from localhost.localdomain(mailfrom:ZiyangZhang@linux.alibaba.com fp:SMTPD_---0VN5zTdx_1661320132) by smtp.aliyun-inc.com; Wed, 24 Aug 2022 13:48:53 +0800 From: ZiyangZhang To: ming.lei@redhat.com, axboe@kernel.dk Cc: xiaoguang.wang@linux.alibaba.com, linux-block@vger.kernel.org, linux-kernel@vger.kernel.org, joseph.qi@linux.alibaba.com, ZiyangZhang Subject: [RFC PATCH 2/9] ublk_drv: refactor ublk_cancel_queue() Date: Wed, 24 Aug 2022 13:47:37 +0800 Message-Id: <20220824054744.77812-3-ZiyangZhang@linux.alibaba.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20220824054744.77812-1-ZiyangZhang@linux.alibaba.com> References: <20220824054744.77812-1-ZiyangZhang@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-9.9 required=5.0 tests=BAYES_00, ENV_AND_HDR_SPF_MATCH,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE,UNPARSEABLE_RELAY,USER_IN_DEF_SPF_WL autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Assume only a few FETCH_REQ ioucmds are sent to ublk_drv, then the ubq_daemon exits, We have to call io_uring_cmd_done() for all ioucmds received so that io_uring ctx will not leak. ublk_cancel_queue() may be called before START_DEV or after STOP_DEV, we decrease ubq->nr_io_ready and clear UBLK_IO_FLAG_ACTIVE so that we won't call io_uring_cmd_done() twice for one ioucmd to avoid UAF. Also clearing UBLK_IO_FLAG_ACTIVE makes the code more reasonable. Signed-off-by: ZiyangZhang --- drivers/block/ublk_drv.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c index c39b67d7133d..e08f636b0b9d 100644 --- a/drivers/block/ublk_drv.c +++ b/drivers/block/ublk_drv.c @@ -967,18 +967,23 @@ static void ublk_cancel_queue(struct ublk_queue *ubq) { int i; - if (!ublk_queue_ready(ubq)) + if (!ubq->nr_io_ready) return; for (i = 0; i < ubq->q_depth; i++) { struct ublk_io *io = &ubq->ios[i]; - if (io->flags & UBLK_IO_FLAG_ACTIVE) + if (io->flags & UBLK_IO_FLAG_ACTIVE) { + pr_devel("%s: done old cmd: qid %d tag %d\n", + __func__, ubq->q_id, i); io_uring_cmd_done(io->cmd, UBLK_IO_RES_ABORT, 0); + io->flags &= ~UBLK_IO_FLAG_ACTIVE; + ubq->nr_io_ready--; + } } /* all io commands are canceled */ - ubq->nr_io_ready = 0; + WARN_ON_ONCE(ubq->nr_io_ready); } /* Cancel all pending commands, must be called after del_gendisk() returns */ -- 2.27.0