Saurav Kashyap
b5eb54c4a9
scsi: qla2xxx: Sync queue idx with queue_pair_map idx
commit c8fadf019964d0eb1da410ba8b629494d3339db9 upstream.
The first invocation of function find_first_zero_bit will return 0 and
queue_id gets set to 0.
An index of queue_pair_map also gets set to 0.
qpair_id = find_first_zero_bit(ha->qpair_qid_map, ha->max_qpairs);
set_bit(qpair_id, ha->qpair_qid_map);
ha->queue_pair_map[qpair_id] = qpair;
In the alloc_queue callback driver checks the map, if queue is already
allocated:
ha->queue_pair_map[qidx]
This works fine as long as max_qpairs is greater than nvme_max_hw_queues(8)
since the size of the queue_pair_map is equal to max_qpair. In case nr_cpus
is less than 8, max_qpairs is less than 8. This creates wrong value
returned as qpair.
[ 1572.353669] qla2xxx [0000:24:00.3]-2121:6: Returning existing qpair of 4e00000000000000 for idx=2
[ 1572.354458] general protection fault: 0000 [#1] SMP PTI
[ 1572.354461] CPU: 1 PID: 44 Comm: kworker/1:1H Kdump: loaded Tainted: G IOE --------- - - 4.18.0-304.el8.x86_64 #1
[ 1572.354462] Hardware name: HP ProLiant DL380p Gen8, BIOS P70 03/01/2013
[ 1572.354467] Workqueue: kblockd blk_mq_run_work_fn
[ 1572.354485] RIP: 0010:qla_nvme_post_cmd+0x92/0x760 [qla2xxx]
[ 1572.354486] Code: 84 24 5c 01 00 00 00 00 b8 0a 74 1e 66 83 79 48 00 0f 85 a8 03 00 00 48 8b 44 24 08 48 89 ee 4c 89 e7 8b 50 24 e8 5e 8e 00 00 <f0> 41 ff 47 04 0f ae f0 41 f6 47 24 04 74 19 f0 41 ff 4f 04 b8 f0
[ 1572.354487] RSP: 0018:ffff9c81c645fc90 EFLAGS: 00010246
[ 1572.354489] RAX: 0000000000000001 RBX: ffff8ea3e5070138 RCX: 0000000000000001
[ 1572.354490] RDX: 0000000000000001 RSI: 0000000000000001 RDI: ffff8ea4c866b800
[ 1572.354491] RBP: ffff8ea4c866b800 R08: 0000000000005010 R09: ffff8ea4c866b800
[ 1572.354492] R10: 0000000000000001 R11: 000000069d1ca3ff R12: ffff8ea4bc460000
[ 1572.354493] R13: ffff8ea3e50702b0 R14: ffff8ea4c4c16a58 R15: 4e00000000000000
[ 1572.354494] FS: 0000000000000000(0000) GS:ffff8ea4dfd00000(0000) knlGS:0000000000000000
[ 1572.354495] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1572.354496] CR2: 000055884504fa58 CR3: 00000005a1410001 CR4: 00000000000606e0
[ 1572.354497] Call Trace:
[ 1572.354503] ? check_preempt_curr+0x62/0x90
[ 1572.354506] ? dma_direct_map_sg+0x72/0x1f0
[ 1572.354509] ? nvme_fc_start_fcp_op.part.32+0x175/0x460 [nvme_fc]
[ 1572.354511] ? blk_mq_dispatch_rq_list+0x11c/0x730
[ 1572.354515] ? __switch_to_asm+0x35/0x70
[ 1572.354516] ? __switch_to_asm+0x41/0x70
[ 1572.354518] ? __switch_to_asm+0x35/0x70
[ 1572.354519] ? __switch_to_asm+0x41/0x70
[ 1572.354521] ? __switch_to_asm+0x35/0x70
[ 1572.354522] ? __switch_to_asm+0x41/0x70
[ 1572.354523] ? __switch_to_asm+0x35/0x70
[ 1572.354525] ? entry_SYSCALL_64_after_hwframe+0xb9/0xca
[ 1572.354527] ? __switch_to_asm+0x41/0x70
[ 1572.354529] ? __blk_mq_sched_dispatch_requests+0xc6/0x170
[ 1572.354531] ? blk_mq_sched_dispatch_requests+0x30/0x60
[ 1572.354532] ? __blk_mq_run_hw_queue+0x51/0xd0
[ 1572.354535] ? process_one_work+0x1a7/0x360
[ 1572.354537] ? create_worker+0x1a0/0x1a0
[ 1572.354538] ? worker_thread+0x30/0x390
[ 1572.354540] ? create_worker+0x1a0/0x1a0
[ 1572.354541] ? kthread+0x116/0x130
[ 1572.354543] ? kthread_flush_work_fn+0x10/0x10
[ 1572.354545] ? ret_from_fork+0x35/0x40
Fix is to use index 0 for admin and first IO queue.
Link: https://lore.kernel.org/r/20210810043720.1137-14-njavali@marvell.com
Fixes: e84067d743 ("scsi: qla2xxx: Add FC-NVMe F/W initialization and transport registration")
Cc: stable@vger.kernel.org
Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com>
Signed-off-by: Saurav Kashyap <skashyap@marvell.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
|
2021-09-22 12:26:37 +02:00 |
| .. |
|
aacraid
|
scsi: aacraid: Fix error handling paths in aac_probe_one()
|
2020-10-01 13:17:56 +02:00 |
|
aic7xxx
|
scsi: aic7xxx: Fix unintentional sign extension issue on left shift of u8
|
2021-07-25 14:35:12 +02:00 |
|
aic94xx
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
arcmsr
|
|
|
|
arm
|
scsi: eesox: Fix different dev_id between request_irq() and free_irq()
|
2020-08-19 08:16:09 +02:00 |
|
be2iscsi
|
scsi: be2iscsi: Fix an error handling path in beiscsi_dev_probe()
|
2021-07-20 16:10:53 +02:00 |
|
bfa
|
scsi: bfa: Fix error return in bfad_pci_init()
|
2020-10-29 09:57:57 +01:00 |
|
bnx2fc
|
scsi: bnx2fc: Return failure if io_req is already in ABTS processing
|
2021-06-16 11:59:35 +02:00 |
|
bnx2i
|
scsi: iscsi: Fix shost->max_id use
|
2021-07-20 16:10:43 +02:00 |
|
csiostor
|
scsi: csiostor: Fix wrong return value in csio_hw_prep_fw()
|
2020-10-29 09:57:37 +01:00 |
|
cxgbi
|
scsi: iscsi: Fix shost->max_id use
|
2021-07-20 16:10:43 +02:00 |
|
cxlflash
|
scsi: cxlflash: Fix error return code in cxlflash_probe()
|
2020-10-01 13:18:02 +02:00 |
|
device_handler
|
scsi: scsi_dh_rdac: Avoid crash during rdac_bus_attach()
|
2021-08-26 08:36:14 -04:00 |
|
dpt
|
|
|
|
esas2r
|
scsi: esas2r: unlock on error in esas2r_nvram_read_direct()
|
2020-01-23 08:22:58 +01:00 |
|
fcoe
|
scsi: fcoe: Memory leak fix in fcoe_sysfs_fcf_del()
|
2020-09-03 11:26:47 +02:00 |
|
fnic
|
scsi: fnic: Fix memleak in vnic_dev_init_devcmd2
|
2021-02-07 15:35:48 +01:00 |
|
hisi_sas
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
ibmvscsi
|
scsi: ibmvfc: Fix invalid state machine BUG_ON()
|
2021-05-14 09:44:25 +02:00 |
|
ibmvscsi_tgt
|
|
|
|
isci
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
libfc
|
scsi: libfc: Fix array index out of bound exception
|
2021-07-25 14:35:13 +02:00 |
|
libsas
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
lpfc
|
scsi: lpfc: Fix crash when lpfc_sli4_hba_setup() fails to initialize the SGLs
|
2021-07-20 16:10:42 +02:00 |
|
megaraid
|
scsi: megaraid_mm: Fix end of loop tests for list_for_each_entry()
|
2021-08-26 08:36:14 -04:00 |
|
mpt3sas
|
scsi: mpt3sas: Fix error return value in _scsih_expander_add()
|
2021-07-14 16:53:45 +02:00 |
|
mvsas
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
pcmcia
|
scsi: fdomain: Fix error return code in fdomain_probe()
|
2021-09-22 12:26:24 +02:00 |
|
pm8001
|
scsi: libsas: Add LUN number check in .slave_alloc callback
|
2021-07-25 14:35:13 +02:00 |
|
qedf
|
scsi: qedf: Fix error codes in qedf_alloc_global_queues()
|
2021-09-22 12:26:24 +02:00 |
|
qedi
|
scsi: qedi: Fix error codes in qedi_alloc_global_queues()
|
2021-09-22 12:26:24 +02:00 |
|
qla2xxx
|
scsi: qla2xxx: Sync queue idx with queue_pair_map idx
|
2021-09-22 12:26:37 +02:00 |
|
qla4xxx
|
scsi: qla4xxx: Fix an error handling path in 'qla4xxx_get_host_stats()'
|
2020-10-29 09:57:36 +01:00 |
|
smartpqi
|
scsi: smartpqi: Fix an error code in pqi_get_raid_map()
|
2021-09-22 12:26:24 +02:00 |
|
snic
|
|
|
|
sym53c8xx_2
|
|
|
|
ufs
|
scsi: ufs: handle cleanup correctly on devm_reset_control_get error
|
2021-05-26 12:05:20 +02:00 |
|
.gitignore
|
|
|
|
3w-9xxx.c
|
|
|
|
3w-9xxx.h
|
|
|
|
3w-sas.c
|
|
|
|
3w-sas.h
|
|
|
|
3w-xxxx.c
|
|
|
|
3w-xxxx.h
|
|
|
|
53c700.c
|
|
|
|
53c700.h
|
|
|
|
53c700.scr
|
|
|
|
53c700_d.h_shipped
|
|
|
|
a100u2w.c
|
|
|
|
a100u2w.h
|
|
|
|
a2091.c
|
|
|
|
a2091.h
|
|
|
|
a3000.c
|
|
|
|
a3000.h
|
|
|
|
a4000t.c
|
|
|
|
advansys.c
|
|
|
|
aha152x.c
|
|
|
|
aha152x.h
|
|
|
|
aha1542.c
|
|
|
|
aha1542.h
|
|
|
|
aha1740.c
|
|
|
|
aha1740.h
|
|
|
|
am53c974.c
|
|
|
|
atari_scsi.c
|
scsi: atari_scsi: sun3_scsi: Set sg_tablesize to 1 instead of SG_NONE
|
2020-01-04 19:18:10 +01:00 |
|
atp870u.c
|
|
|
|
atp870u.h
|
|
|
|
BusLogic.c
|
scsi: BusLogic: Fix missing pr_cont() use
|
2021-09-22 12:26:37 +02:00 |
|
BusLogic.h
|
scsi: BusLogic: Fix 64-bit system enumeration error for Buslogic
|
2021-06-03 08:59:11 +02:00 |
|
bvme6000_scsi.c
|
|
|
|
ch.c
|
scsi: ch: Make it possible to open a ch device multiple times again
|
2019-10-09 23:39:35 -04:00 |
|
constants.c
|
|
|
|
dc395x.c
|
|
|
|
dc395x.h
|
|
|
|
dmx3191d.c
|
|
|
|
dpt_i2o.c
|
|
|
|
dpti.h
|
|
|
|
esp_scsi.c
|
|
|
|
esp_scsi.h
|
|
|
|
fdomain.c
|
|
|
|
fdomain.h
|
|
|
|
fdomain_isa.c
|
|
|
|
fdomain_pci.c
|
|
|
|
FlashPoint.c
|
scsi: FlashPoint: Rename si_flags field
|
2021-07-14 16:53:41 +02:00 |
|
g_NCR5380.c
|
|
|
|
gdth.c
|
|
|
|
gdth.h
|
|
|
|
gdth_ioctl.h
|
|
|
|
gdth_proc.c
|
|
|
|
gdth_proc.h
|
|
|
|
gvp11.c
|
|
|
|
gvp11.h
|
|
|
|
hosts.c
|
scsi: core: Cap scsi_host cmd_per_lun at can_queue
|
2021-07-20 16:10:42 +02:00 |
|
hpsa.c
|
scsi: hpsa: Fix memory leak in hpsa_init_one()
|
2020-11-18 19:20:22 +01:00 |
|
hpsa.h
|
|
|
|
hpsa_cmd.h
|
|
|
|
hptiop.c
|
|
|
|
hptiop.h
|
|
|
|
imm.c
|
|
|
|
imm.h
|
|
|
|
initio.c
|
|
|
|
initio.h
|
|
|
|
ipr.c
|
scsi: ipr: Fix softlockup when rescanning devices in petitboot
|
2020-04-01 11:01:54 +02:00 |
|
ipr.h
|
scsi: ipr: Fix softlockup when rescanning devices in petitboot
|
2020-04-01 11:01:54 +02:00 |
|
ips.c
|
|
|
|
ips.h
|
|
|
|
iscsi_boot_sysfs.c
|
scsi: iscsi: Fix reference count leak in iscsi_boot_create_kobj
|
2020-06-24 17:50:37 +02:00 |
|
iscsi_tcp.c
|
scsi: iscsi: Don't destroy session if there are outstanding connections
|
2020-02-24 08:36:50 +01:00 |
|
iscsi_tcp.h
|
|
|
|
jazz_esp.c
|
scsi: jazz_esp: Add IRQ check
|
2021-05-14 09:44:25 +02:00 |
|
Kconfig
|
scsi: sr: remove references to BLK_DEV_SR_VENDOR, leave it enabled
|
2020-07-22 09:32:57 +02:00 |
|
lasi700.c
|
|
|
|
libiscsi.c
|
scsi: iscsi: Fix conn use after free during resets
|
2021-07-20 16:10:43 +02:00 |
|
libiscsi_tcp.c
|
|
|
|
mac53c94.c
|
|
|
|
mac53c94.h
|
|
|
|
mac_esp.c
|
|
|
|
mac_scsi.c
|
scsi: atari_scsi: sun3_scsi: Set sg_tablesize to 1 instead of SG_NONE
|
2020-01-04 19:18:10 +01:00 |
|
Makefile
|
|
|
|
megaraid.c
|
scsi: megaraid: disable device when probe failed after enabled device
|
2019-09-23 23:09:42 -04:00 |
|
megaraid.h
|
|
|
|
mesh.c
|
scsi: mesh: Fix panic after host or bus reset
|
2020-08-19 08:16:15 +02:00 |
|
mesh.h
|
|
|
|
mvme16x_scsi.c
|
|
|
|
mvme147.c
|
|
|
|
mvme147.h
|
|
|
|
mvumi.c
|
scsi: mvumi: Fix error return in mvumi_io_attach()
|
2020-10-29 09:58:04 +01:00 |
|
mvumi.h
|
|
|
|
myrb.c
|
|
|
|
myrb.h
|
|
|
|
myrs.c
|
scsi: myrs: Fix a double free in myrs_cleanup()
|
2021-03-24 11:26:40 +01:00 |
|
myrs.h
|
|
|
|
ncr53c8xx.c
|
|
|
|
ncr53c8xx.h
|
|
|
|
NCR5380.c
|
scsi: NCR5380: Add disconnect_mask module parameter
|
2020-01-04 19:18:16 +01:00 |
|
NCR5380.h
|
|
|
|
nsp32.c
|
|
|
|
nsp32.h
|
|
|
|
nsp32_debug.c
|
|
|
|
nsp32_io.h
|
|
|
|
pmcraid.c
|
|
|
|
pmcraid.h
|
|
|
|
ppa.c
|
|
|
|
ppa.h
|
|
|
|
ps3rom.c
|
|
|
|
qla1280.c
|
|
|
|
qla1280.h
|
|
|
|
qlogicfas.c
|
|
|
|
qlogicfas408.c
|
|
|
|
qlogicfas408.h
|
|
|
|
qlogicpti.c
|
|
|
|
qlogicpti.h
|
|
|
|
raid_class.c
|
|
|
|
script_asm.pl
|
|
|
|
scsi.c
|
|
|
|
scsi.h
|
|
|
|
scsi_common.c
|
|
|
|
scsi_debug.c
|
scsi: scsi_debug: Add check for sdebug_max_queue during module init
|
2020-08-19 08:16:11 +02:00 |
|
scsi_debugfs.c
|
|
|
|
scsi_debugfs.h
|
|
|
|
scsi_devinfo.c
|
scsi: scsi_devinfo: Add blacklist entry for HPE OPEN-V
|
2021-06-18 09:58:59 +02:00 |
|
scsi_dh.c
|
scsi: dh: Add Fujitsu device to devinfo and dh lists
|
2020-07-29 10:18:27 +02:00 |
|
scsi_error.c
|
scsi: core: save/restore command resid for error handling
|
2019-10-03 21:43:04 -04:00 |
|
scsi_ioctl.c
|
|
|
|
scsi_lib.c
|
scsi: core: Retry I/O for Notify (Enable Spinup) Required error
|
2021-07-14 16:53:48 +02:00 |
|
scsi_lib_dma.c
|
|
|
|
scsi_logging.c
|
|
|
|
scsi_logging.h
|
|
|
|
scsi_netlink.c
|
|
|
|
scsi_pm.c
|
scsi: pm: Balance pm_only counter of request queue during system resume
|
2020-06-07 13:18:50 +02:00 |
|
scsi_priv.h
|
|
|
|
scsi_proc.c
|
|
|
|
scsi_sas_internal.h
|
|
|
|
scsi_scan.c
|
scsi: core: Avoid printing an error if target_alloc() returns -ENXIO
|
2021-08-26 08:36:14 -04:00 |
|
scsi_sysctl.c
|
|
|
|
scsi_sysfs.c
|
scsi: core: Fix hang of freezing queue between blocking and running device
|
2021-09-03 10:08:13 +02:00 |
|
scsi_trace.c
|
scsi: core: scsi_trace: Use get_unaligned_be*()
|
2020-01-23 08:22:59 +01:00 |
|
scsi_transport_api.h
|
|
|
|
scsi_transport_fc.c
|
|
|
|
scsi_transport_iscsi.c
|
scsi: iscsi: Fix iface sysfs attr detection
|
2021-07-28 13:30:56 +02:00 |
|
scsi_transport_sas.c
|
scsi: scsi_transport_sas: Fix memory leak when removing devices
|
2020-01-23 08:22:58 +01:00 |
|
scsi_transport_spi.c
|
scsi: scsi_transport_spi: Set RQF_PM for domain validation commands
|
2021-01-12 20:16:09 +01:00 |
|
scsi_transport_srp.c
|
scsi: scsi_transport_srp: Don't block target in SRP_PORT_LOST state
|
2021-04-21 12:56:14 +02:00 |
|
scsicam.c
|
|
|
|
sd.c
|
scsi: sd: Suppress spurious errors when WRITE SAME is being disabled
|
2021-01-27 11:47:43 +01:00 |
|
sd.h
|
|
|
|
sd_dif.c
|
|
|
|
sd_zbc.c
|
scsi: sd_zbc: Fix sd_zbc_complete()
|
2019-11-05 23:17:53 -05:00 |
|
sense_codes.h
|
|
|
|
ses.c
|
|
|
|
sg.c
|
scsi: sg: add sg_remove_request in sg_write
|
2020-05-20 08:20:07 +02:00 |
|
sgiwd93.c
|
|
|
|
sim710.c
|
|
|
|
sni_53c710.c
|
scsi: sni_53c710: Add IRQ check
|
2021-05-14 09:44:25 +02:00 |
|
sr.c
|
scsi: sr: Return correct event when media event code is 3
|
2021-08-12 13:20:56 +02:00 |
|
sr.h
|
|
|
|
sr_ioctl.c
|
|
|
|
sr_vendor.c
|
scsi: sr: remove references to BLK_DEV_SR_VENDOR, leave it enabled
|
2020-07-22 09:32:57 +02:00 |
|
st.c
|
scsi: st: Fix a use after free in st_open()
|
2021-04-07 14:47:39 +02:00 |
|
st.h
|
|
|
|
st_options.h
|
|
|
|
stex.c
|
|
|
|
storvsc_drv.c
|
scsi: storvsc: Correctly set number of hardware queues for IDE disk
|
2020-01-23 08:22:38 +01:00 |
|
sun3_scsi.c
|
scsi: atari_scsi: sun3_scsi: Set sg_tablesize to 1 instead of SG_NONE
|
2020-01-04 19:18:10 +01:00 |
|
sun3_scsi_vme.c
|
|
|
|
sun3x_esp.c
|
scsi: sun3x_esp: Add IRQ check
|
2021-05-14 09:44:25 +02:00 |
|
sun_esp.c
|
|
|
|
virtio_scsi.c
|
scsi: virtio_scsi: unplug LUNs when events missed
|
2019-09-10 22:10:17 -04:00 |
|
vmw_pvscsi.c
|
scsi: vmw_pvscsi: Set correct residual data length
|
2021-06-16 11:59:35 +02:00 |
|
vmw_pvscsi.h
|
|
|
|
wd33c93.c
|
|
|
|
wd33c93.h
|
|
|
|
wd719x.c
|
|
|
|
wd719x.h
|
|
|
|
xen-scsifront.c
|
|
|
|
zalon.c
|
|
|
|
zorro7xx.c
|
|
|
|
zorro_esp.c
|
scsi: zorro_esp: Limit DMA transfers to 65536 bytes (except on Fastlane)
|
2020-01-04 19:17:37 +01:00 |