mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 20:54:03 +02:00
usb: gadget: f_tcm: keep port count until LUN teardown completes
tcm_usbg_drop_nexus() permits session removal once tpg_port_count
reaches zero. However, usbg_port_unlink() currently decrements that
count from the fabric_pre_unlink() callback, before core_dev_del_lun()
waits for active se_lun references to drain.
If removal of the last LUN races a nexus removal, the latter can observe
a zero port count and call target_remove_session(). This frees
sess_cmd_map while an in-flight struct usbg_cmd, including its work item,
can still be accessed.
Overlapping the last-LUN unlink with nexus removal reproduces this
lifetime violation as a DEBUG_OBJECTS "free active" warning for
usbg_cmd_work, followed by a target-core BUG/Oops.
The generic target-core unlink path has no callback after
core_dev_del_lun() completes. Add an optional fabric_post_unlink()
callback and use it for the f_tcm port count. The count now remains
nonzero until core_dev_del_lun() has finished draining active LUN
references, preventing nexus removal from freeing the session during
command completion.
Fixes: c52661d60f ("usb-gadget: Initial merge of target module for UASP + BOT")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260807060733.3186624-1-shuangpeng.kernel@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
00e2071f6d
commit
c39d0916da
|
|
@ -690,6 +690,14 @@ static void target_fabric_port_unlink(
|
|||
}
|
||||
|
||||
core_dev_del_lun(se_tpg, lun);
|
||||
|
||||
if (tf->tf_ops->fabric_post_unlink) {
|
||||
/*
|
||||
* Allow fabrics to release state that must remain valid until
|
||||
* core_dev_del_lun() has drained all active LUN references.
|
||||
*/
|
||||
tf->tf_ops->fabric_post_unlink(se_tpg, lun);
|
||||
}
|
||||
}
|
||||
|
||||
static void target_fabric_port_release(struct config_item *item)
|
||||
|
|
|
|||
|
|
@ -2027,7 +2027,7 @@ static const struct target_core_fabric_ops usbg_ops = {
|
|||
.fabric_enable_tpg = usbg_enable_tpg,
|
||||
.fabric_drop_tpg = usbg_drop_tpg,
|
||||
.fabric_post_link = usbg_port_link,
|
||||
.fabric_pre_unlink = usbg_port_unlink,
|
||||
.fabric_post_unlink = usbg_port_unlink,
|
||||
.fabric_init_nodeacl = usbg_init_nodeacl,
|
||||
|
||||
.tfc_wwn_attrs = usbg_wwn_attrs,
|
||||
|
|
|
|||
|
|
@ -95,6 +95,8 @@ struct target_core_fabric_ops {
|
|||
struct se_lun *);
|
||||
void (*fabric_pre_unlink)(struct se_portal_group *,
|
||||
struct se_lun *);
|
||||
void (*fabric_post_unlink)(struct se_portal_group *se_tpg,
|
||||
struct se_lun *lun);
|
||||
struct se_tpg_np *(*fabric_make_np)(struct se_portal_group *,
|
||||
struct config_group *, const char *);
|
||||
void (*fabric_drop_np)(struct se_tpg_np *);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user