Commit Graph

1461968 Commits

Author SHA1 Message Date
Nitin Rawat
b2ededcb27 scsi: ufs: ufs-qcom: Fix sequential read variance
The current devfreq downdifferential threshold of 5% causes overly
aggressive frequency downscaling, leading to performance degradation
sometimes during sequential read workloads.

Update the UFS devfreq downdifferential threshold to 65.  This widens
the hysteresis window and prevents overly aggressive downscaling,
ensuring that frequency is maintained for loads above 5% and scaling
down occurs only when utilization falls below this level, while scale-up
still triggers above the 70% threshold.

Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Nitin Rawat <nitin.rawat@oss.qualcomm.com>
Link: https://patch.msgid.link/20260825145203.265579-3-nitin.rawat@oss.qualcomm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:55:10 -04:00
Nitin Rawat
a3756f53ba scsi: ufs: ufs-qcom: Restore HS/LS link startup mode for Qualcomm UFS controller v6.2+
The link startup mode (HS LSS - high-speed link startup, or LS LSS -
low-speed link startup) is decided in the boot stage based on the
bootconfig GPIO. This selection is carried forward through the secondary
stage bootloaders and finally to HLOS via the spare configuration
register (REG_UFS_DEBUG_SPARE_CFG).

On Qualcomm UFS controller v6.2 and later, bit 31 in the spare
configuration register indicates the high-speed link startup mode
selection, as per the Hardware Programming Guide (HPG).

The spare register value is read during host driver initialization but
gets cleared after UFS reset. Preserve the spare register value during
initialization and restore it during link startup to maintain the
bootloader-configured link startup mode.

Signed-off-by: Nitin Rawat <nitin.rawat@oss.qualcomm.com>
Tested-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://patch.msgid.link/20260825145203.265579-2-nitin.rawat@oss.qualcomm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:55:10 -04:00
Muhammad Falak R Wani
9a69cc5f19 scsi: ibmvfc: Document protocol parameter of ibmvfc_alloc_target()
Commit 249313b3f7 ("scsi: ibmvfc: allocate targets based on protocol")
added a protocol parameter to ibmvfc_alloc_target() but did not describe
it in the function's kernel-doc comment, so a W=1 build warns:

  drivers/scsi/ibmvscsi/ibmvfc-core.c:4996: warning: Function parameter
  or struct member 'protocol' not described in 'ibmvfc_alloc_target'

Add the missing parameter description.

Fixes: 249313b3f7 ("scsi: ibmvfc: allocate targets based on protocol")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608270829.lHI1FAdO-lkp@intel.com/
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
Reviewed-by: Dave Marquardt <davemarq@linux.ibm.com>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/b073968ae020b6ae0240e91341a92f428587ebd9.1787828961.git.falakreyaz@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:38:26 -04:00
Muhammad Falak R Wani
9a0716348d scsi: ibmvfc: Fix kernel-doc name for ibmvfc_scsi_relogin()
Commit e0fca728a8 ("scsi: ibmvfc: delete NVMe/FC targets as well as
SCSI") renamed ibmvfc_relogin() to ibmvfc_scsi_relogin() but left the
kernel-doc comment referring to the old name, so a W=1 build warns:

  drivers/scsi/ibmvscsi/ibmvfc-core.c:1901: warning: expecting prototype
  for ibmvfc_relogin(). Prototype was for ibmvfc_scsi_relogin() instead

Update the kernel-doc comment to use the current function name.

Fixes: e0fca728a8 ("scsi: ibmvfc: delete NVMe/FC targets as well as SCSI")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608271026.iMLmrwz4-lkp@intel.com/
Signed-off-by: Muhammad Falak R Wani <falakreyaz@gmail.com>
Reviewed-by: Dave Marquardt <davemarq@linux.ibm.com>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/dd866cf2321381694af027fbd726bcbd63ac3751.1787828961.git.falakreyaz@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:38:26 -04:00
Runyu Xiao
3f92a64545 scsi: pm8001: Use rollback index when freeing MSI-X vectors
pm8001_request_msix() unwinds previously registered handlers with
free_irq() when request_irq() fails. The rollback loop uses the failing
index i for every iteration instead of the already registered vector
index j.

That passes the wrong IRQ/dev_id pair to free_irq() and leaves the
earlier handlers installed. Use j for both pci_irq_vector() and the
matching irq_vector entry in the rollback loop.

Fixes: a76037ff34 ("scsi: pm8001: switch to pci_irq_alloc_vectors")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Link: https://patch.msgid.link/20260824113618.2239100-1-runyu.xiao@seu.edu.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:36:18 -04:00
Linmao Li
98f0a1422e scsi: fnic: Initialize the NVMe local port info before registering
nvfnic_add_lport() declares struct nvme_fc_port_info on the stack and
fills in four of its five members, leaving dev_loss_tmo holding whatever
the stack happened to contain before the call.  The structure is then
handed to nvme_fc_register_localport().

nvfnic_add_tport(), which registers the remote port a few lines further
down, memsets its own struct nvme_fc_port_info first, so only the local
port path passes uninitialized data across the transport interface.

The NVMe/FC transport documents dev_loss_tmo as "Used only on a
remoteport" and does not read it in nvme_fc_register_localport(), so
there is no behavioural change today.  Initialize the structure anyway:
the driver must not depend on which members the transport happens to
consume, and any member added to struct nvme_fc_port_info later would
silently start out as stack garbage.

Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Tested-by: Karan Tilak Kumar <kartilak@cisco.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260819114242.3598034-2-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-28 21:33:03 -04:00
Chen Changcheng
12e67eb89e scsi: snic: Fix SCSI host leak on workqueue allocation failure
In snic_add_host(), if scsi_add_host() succeeds but
alloc_ordered_workqueue() fails, the function returns -ENOMEM with
shost->work_q left as NULL. The caller's error path then calls
snic_del_host(), which returns early when !shost->work_q without calling
scsi_remove_host(). The Scsi_Host remains registered in sysfs as a zombie
device even after the probe has failed. This causes:

 - The leaked host remains visible in /sys/class/scsi_host/ after probe
   failure, with state "running".

 - Subsequent SCSI host numbering is permanently shifted (the leaked host
   ID from ida_alloc() is never reclaimed).

 - Memory leak: the Scsi_Host allocation can never be freed because
   device_add() took a reference that can only be released by device_del()
   inside scsi_remove_host().

Fix by adding scsi_remove_host() in the workqueue allocation failure path
inside snic_add_host(), undoing the successful scsi_add_host() before
returning the error. This is cleaner than modifying snic_del_host() because
snic_del_host() is called from a shared error label that also serves paths
where snic_add_host() was never invoked.

Reproducer (requires no real SNIC hardware):

 - Build CONFIG_SCSI_SNIC=y (built-in)

 - Add snic.test_mode=1 snic.inject_wq_fail=1 to kernel cmdline

 - Boot with a PCI device matching the snic driver (e.g. QEMU edu device,
   PCI ID 0x1234:0x11e8, temporarily added to the driver's PCI ID table)

Before the fix:

  # /sys/class/scsi_host/ contains a zombie host0:
  $ cat /sys/class/scsi_host/host0/proc_name
  snic_scsi
  $ cat /sys/class/scsi_host/host0/state
  running
  # ata_piix gets host1, host2 (host0 stuck):
  scsi host1: ata_piix
  scsi host2: ata_piix

After the fix:

  # host0 is properly freed and reused by ata_piix:
  scsi host0: ata_piix
  scsi host1: ata_piix
  # No zombie host in /sys/class/scsi_host/

Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Acked-by: Narsimhulu Musini <nmusini@cisco.com>
Link: https://patch.msgid.link/20260727073438.209673-1-chenchangcheng@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 22:34:58 -04:00
Martin K. Petersen (Oracle)
df125bd162 scsi: MAINTAINERS: Update my email address
Use my kernel.org address for Linux development.

Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 22:32:39 -04:00
Finn Thain
764587d7d7 scsi: MAINTAINERS: Leave the cumana_1 and oak drivers to the RISCPC maintainers
The NCR5380 entry in MAINTAINERS includes drivers/scsi/arm/cumana_1.c and
drivers/scsi/arm/oak.c. However, those two files are also covered by the
drivers/scsi/arm/ pathname in the ARM/RISCPC entry.

The latter entry is more effective than the former because, AIUI, neither
Michael nor I have access to the necessary hardware. IMHO, such access is a
pre-requisite for the 'maintainer' role for device drivers.

To work on these particular drivers would require an old GCC compiler,
having support for -march=armv3m, which is a problem for contributors.

Cc: Michael Schmitz <schmitzmic@gmail.com>
Cc: Russell King <linux@armlinux.org.uk>
Cc: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Finn Thain <fthain@linux-m68k.org>
Acked-by: Michael Schmitz <schmitzmic@gmail.com>
Link: https://patch.msgid.link/935b08c0fb292888c06c2233570331f2ccadcd53.1787014824.git.fthain@linux-m68k.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 22:07:17 -04:00
Dongdong Hao
46f861d300 scsi: leapraid: Standardize NCQ priority sysfs attributes
Replace the earlier LeapRAID ncq_cmd_prio_enable attribute with the
standard sas_ncq_prio_supported and sas_ncq_prio_enable names documented in
Documentation/ABI/testing/sysfs-block-device, and rename the per-device NCQ
priority state to match.

The earlier ncq_cmd_prio_enable name has not yet been established as part
of a released userspace ABI, so no compatibility alias is needed.

For LeapRAID, sas_ncq_prio_enable is backed by the driver's per-device NCQ
priority state and controls whether RT-class I/O requests are issued with
command priority on supported SATA devices.

Update leapraid.rst to describe the standard attribute names and paths, and
clean up the surrounding RST text for consistency with kernel documentation
style.

Also switch the capability check from open-coded VPD page 0x89 parsing to
sas_ata_ncq_prio_supported(), use kstrtobool() for the enable path, and
expose the NCQ priority attributes only for SATA devices using LeapRAID's
target-private SAS device state.

Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260814090526.395704-1-doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:57:41 -04:00
Linmao Li
00b7c8d4ce scsi: leapraid: Serialize firmware log mmap with teardown
leapraid_fw_log_exit() waits for mmap_refcnt to reach zero before it frees
the firmware log buffer.  leapraid_fw_mmap() checks host_removing, but it
does not increment mmap_refcnt until after dma_mmap_coherent() succeeds and
the VMA open callback runs.

Removal can set host_removing and observe a zero mmap_refcnt between the
check and the VMA open.  It can then free the coherent buffer while the
mmap path is still establishing a userspace mapping of it.

Claim a temporary mmap reference while looking up the adapter under
leapraid_adapter_lock.  Removal deletes the adapter from the same locked
list after setting host_removing, so a mapping is either rejected or
included in the count that removal waits for.  Drop the temporary reference
on the common exit path, after a successful VMA open has acquired the
reference covering the VMA lifetime.

Fixes: 5597088c9e ("scsi: leapraid: Add new SCSI driver")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/20260814033845.2971706-3-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:51:43 -04:00
Linmao Li
970f69b6bf scsi: leapraid: Balance host references for firmware log VMAs
leapraid_fw_mmap() keeps the Scsi_Host reference obtained while looking up
the adapter for the lifetime of the initial VMA.  The VMA close callback
drops that reference.

The open callback is also invoked when a VMA is duplicated or split, but it
only increments mmap_refcnt.  Since every corresponding close callback
drops a host reference, cloning the mapping can release the host while
another VMA still refers to the adapter.

Take a host device reference for every VMA open and release the lookup
reference once the initial mapping has acquired its own reference.  Use
get_device() because a VMA can be cloned after the host enters SHOST_DEL;
an existing VMA still pins the host at that point and open cannot fail.

Fixes: 5597088c9e ("scsi: leapraid: Add new SCSI driver")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/20260814033845.2971706-2-lilinmao@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:51:43 -04:00
Dan Carpenter
0ec418204f scsi: lpfc: Remove unnnecessary NULL check
The "evt_dat" variale is non-NULL at this point so there is no need to
check.  Delete the check and pull the code in a tab.

Signed-off-by: Dan Carpenter <error27@gmail.com>
Reviewed-by: Paul Ely <paul.ely@broadcom.com>
Link: https://patch.msgid.link/an1trOAUeQmYEus_@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:48:53 -04:00
Dan Carpenter
11e48f5201 scsi: qla2xxx: Fix an loop timeout test
This loop timeout with "retries" set to -1, not 0.  Fix the test for
failure.

Fixes: 7ec0effd30 ("[SCSI] qla2xxx: Add support for ISP8044.")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/an1twcxTYSFkkUTA@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:48:03 -04:00
Dan Carpenter
ff9365a4c9 scsi: qla2xxx: Fix an error code in qla_get_tmf()
Negative -EIO was intended instead of positive EIO.  The caller, doesn't
care so this doesn't affect runtime.  It's just a cleanup.

Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/an1taxANE_4_vzJT@stanley.mountain
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:45:44 -04:00
Nathan Chancellor
b79b88b655 scsi: ibmvfc: Fix use of uninitialized rport in ibmvfc_do_work()
After commit 696d1cc2aa ("scsi: ibmvfc: process NVMe/FC rports in work
thread"), clang warns (or errors with CONFIG_WERROR=y / W=e):

  drivers/scsi/ibmvscsi/ibmvfc-core.c:6154:15: error: variable 'rport' is uninitialized when used here [-Werror,-Wuninitialized]
   6154 |                         } else if (rport && tgt->action == IBMVFC_TGT_ACTION_DEL_AND_LOGOUT_RPORT) {
        |                                    ^~~~~

The check for rport is unnecessary in this block, it was accidentally
included from copying and pasting. Remove it to clear up the warning.

Fixes: 696d1cc2aa ("scsi: ibmvfc: process NVMe/FC rports in work thread")
Suggested-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://lore.kernel.org/6ccbe8c5-beb6-483f-bfa4-c2d3819ad5f2@linux.ibm.com/
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Tyrel Datwyler <tyreld@linux.ibm.com>
Link: https://patch.msgid.link/20260817-ibmvscsi-rport-wuninitialized-v1-1-0fdfb27a5f01@kernel.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:37:21 -04:00
Bart Van Assche
d34a88f53a scsi: core: Enable context analysis for hosts.o
Enable compiler-based context analysis for drivers/scsi/hosts.c by setting
CONTEXT_ANALYSIS_hosts.o := y in drivers/scsi/Makefile.

The SCSI host management code in hosts.c now has the necessary lock context
annotations (such as __must_hold(shost->host_lock) on scsi_host_set_state)
and conforms to compile-time lock checking rules. It builds cleanly without
triggering any context analysis warnings.

Enable context analysis for hosts.o so that lock correctness and context
safety invariants for SCSI host operations are verified at compile time
when CONFIG_WARN_CONTEXT_ANALYSIS is enabled.

Fixes: fb0fc67db9 ("scsi: core: Enable context analysis")
Reported-by: John Garry <john.g.garry@oracle.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/3e1c3c0ca9307e2581cf4b96cf3fcdae35202255.1786724393.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-23 21:32:17 -04:00
Martin K. Petersen (Oracle)
30733f28c0 Merge patch series "scsi: lpfc: Remove all strlcat() uses"
Ian Bridges <icb@fastmail.org> says:

In preparation for removing the strlcat() API[1], this series replaces
its 81 remaining call sites in the lpfc driver. The sites live in nine
string building functions across five files, and each patch converts
one source file.

Functions that accumulate a variable number of fragments move to
seq_buf. The three sysfs show functions move to sysfs_emit_at(), the
designated helper for sysfs output. lpfc_vport_symbolic_node_name()
builds five fixed fragments and becomes a single scnprintf() call.
The intermediate tmp buffers and the per fragment overflow checks
become unnecessary in every scheme. Each loop that appends keeps one
overflow exit, so a full buffer stops the iteration.

One cross-cutting behavior change applies to several patches. The old
code formatted each fragment into a fixed size tmp buffer before
appending it, so a fragment longer than that buffer was silently
truncated even when the destination had room for it. The replacements
format each fragment directly into the destination. Truncation is
still bounded by the destination size. The per patch changelogs call
out the affected functions.

The patch series was tested as follows. No hardware testing was
done. Testing on real adapters is welcome.

- W=1 builds of the whole driver directory, zero warnings.
- A userspace differential harness. The old and new function bodies
  are extracted verbatim from the two trees and compiled side by side
  against the real lib/seq_buf.c. 472000 randomized cases across all
  nine functions, including oversized inputs, undersized buffers and
  prefilled destinations, compared byte for byte under ASan and
  UBSan. All outputs are identical except two behavior changes.
  Those are the format string interpretation removed in patch 1 and
  the fragment cap removal in patch 2. The harness classifies every
  observed difference as exactly one of those two.
- A KUnit corpus. The nine functions run as compiled kernel code in a
  QEMU guest with KASAN, UBSAN and FORTIFY_SOURCE enabled, against
  fabricated adapter state covering both branches of every converted
  conditional that is compiled in. The LPFC_MXP_STAT debug block is
  disabled at compile time and was build tested with the macro
  defined. The same 40 test cases run on the unpatched base and
  on this series. The base run matches the old expected outputs, and
  the patched run is byte identical everywhere except the two
  documented changes.

[1] https://github.com/KSPP/linux/issues/370

Link: https://patch.msgid.link/20260729144617.1388646-1-icb@fastmail.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:16:26 -04:00
Ian Bridges
36b6dcb2b7 scsi: lpfc: Replace strlcat() with sysfs_emit_at() in the sysfs show functions
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_cmf_info_show(), lpfc_nvme_info_show() and lpfc_scsi_stat_show().

The three functions build sysfs attribute output, and sysfs_emit_at() is
the designated helper for that. The single write paths become
sysfs_emit(), the offset zero form of the same helper. Each intermediate
tmp buffer and its per fragment overflow check become unnecessary. Once
the page is full, sysfs_emit_at() writes nothing more, so dropping the
early exits does not change the produced bytes. Each loop that appends
keeps one exit, so a full page stops the iteration. In
lpfc_nvme_info_show() the exit also releases the fc_nodes_list_lock as
it did before. The unlock_buf_done label loses its last user and is
removed.

The old code capped every fragment at LPFC_MAX_INFO_TMP_LEN or
LPFC_MAX_SCSI_INFO_TMP_LEN bytes before appending it. The replacement
formats each fragment directly into the page, so a fragment longer than
its old tmp buffer is no longer truncated when the page has room for
it. Both macros lose their last user and are removed.

The running length that sysfs_emit_at() maintains equals the length that
the removed strnlen() calls computed, so the "Could be more info"
overflow markers keep their trigger condition.

Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-6-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:15:22 -04:00
Ian Bridges
4832a60e0a scsi: lpfc: Replace strlcat() with seq_buf in the debugfs dump helpers
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_debugfs_multixripools_data(), lpfc_debugfs_scsistat_data() and
lpfc_debugfs_hdwqstat_data().

Each helper accumulates a variable number of lines into the debugfs
buffer, which is what seq_buf is for. The intermediate tmp buffers and
the per fragment overflow checks become unnecessary. Once a seq_buf
overflows, later writes to it do nothing, so dropping the early exits
does not change the produced bytes. Each loop that appends keeps one
seq_buf_has_overflowed() exit, so a full buffer stops the iteration.

lpfc_debugfs_multixripools_data() and lpfc_debugfs_hdwqstat_data()
append to whatever the buffer already holds, so their seq_buf is
anchored at the current end of the string. All three helpers keep
returning strnlen() because seq_buf_used() reports the full buffer size
after an overflow.

Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-5-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:15:22 -04:00
Ian Bridges
22d4cbf6f7 scsi: lpfc: Replace strlcat() with seq_buf in lpfc_rx_monitor_report()
In preparation for removing the strlcat() API[1], replace its use in
lpfc_rx_monitor_report().

The function accumulates one line per ring entry, which is what seq_buf
is for. seq_buf tracks the write position, so the per entry strlen()
rescans of the destination are gone. Each record is still formatted into
the tmp buffer. seq_buf_puts() appends it only when it fits whole, so
the output keeps ending at the last complete record. The loop still
stops on overflow without consuming the current entry, and the returned
count and the ring head keep their old meaning. The produced bytes are
unchanged.

Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-4-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:15:22 -04:00
Ian Bridges
07f46a9f89 scsi: lpfc: Replace strlcat() with scnprintf() in lpfc_vport_symbolic_node_name()
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_vport_symbolic_node_name().

The function builds five unconditional fragments, so one scnprintf()
call composes the whole string. The intermediate tmp buffer and the per
fragment overflow checks become unnecessary. scnprintf() truncates at
the buffer size and returns the number of bytes it wrote, which equals
the length that the removed strnlen() call computed.

The old code capped every fragment at MAXHOSTNAMELEN bytes before
appending it, independently of the room left in the destination. The
replacement formats each fragment directly into the destination, so a
fragment longer than MAXHOSTNAMELEN is no longer truncated when the
destination has room for it.

Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-3-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:15:22 -04:00
Ian Bridges
5a03dbfd67 scsi: lpfc: Replace strlcat() with seq_buf in lpfc_info()
In preparation for removing the strlcat() API[1], replace its uses in
lpfc_info().

The function accumulates a variable number of optional fragments, which
is what seq_buf is for. The intermediate tmp buffer and the per fragment
overflow checks become unnecessary. seq_buf is memory safe by
construction and silently truncates in the same way as the replaced
pattern.

The old code passed phba->ModelDesc as the format string of the first
scnprintf() call. The model description comes from adapter VPD data.
seq_buf_printf() takes a format string, so the replacement prints it
through "%s". A model description containing conversion specifiers is no
longer interpreted.

Link: https://github.com/KSPP/linux/issues/370 [1]
Signed-off-by: Ian Bridges <icb@fastmail.org>
Link: https://patch.msgid.link/20260729144617.1388646-2-icb@fastmail.org
Reviewed-by: Nigel Kirkland <nigel.kirkland@broadcom.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:15:22 -04:00
Martin K. Petersen (Oracle)
99d1623c08 Merge patch series "Enable context analysis in the SCSI core and UFS driver"
Bart Van Assche <bvanassche@acm.org> says:

Hi Martin,

This patch series enables context analysis for the SCSI core and the UFS
driver. The advantages are as follows:
 - The compiler (only Clang) verifies whether the lock and unlock calls match
   what has been declared via __must_hold(), __acquires() or __releases().
   This is useful for catching locking bugs in error paths.
 - Support for __guarded_by() is enabled. If a member variable is annotated
   with __guarded_by(lock), the compiler will issue a warning if that member
   variable is accessed without holding 'lock'.

Additionally, a patch is included that suppresses KCSAN complaints about SCSI
host state changes.

More information about lock context analysis is available in the cover letter of
[PATCH v5 00/36] Compiler-Based Context- and Locking-Analysis
(https://lore.kernel.org/lkml/20251219154418.3592607-1-elver@google.com/).

Please consider this patch series for the next merge window.

Thanks,

Bart.

Link: https://patch.msgid.link/cover.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:10:33 -04:00
Bart Van Assche
fb0fc67db9 scsi: core: Enable context analysis
Enable context analysis for those SCSI core files that build without
triggering any context analysis warnings.

Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/2576d2f7e3530b721b5050ac6d25c413037d7e7e.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:50 -04:00
Bart Van Assche
4c461ee2b2 scsi: core: Protect host state changes with the host lock
Some but not all SCSI host state changes are protected with the SCSI
host lock. Annotate the SCSI host state with __guarded_by(host_lock) and
protect all SCSI host state changes with the SCSI host lock. This patch
prevents that KCSAN complains about data races when accessing the SCSI
host state.

Reported-by: Jianzhou Zhao <luckd0g@163.com>
Closes: https://lore.kernel.org/all/36d59d0e.6db0.19cdbeee01b.Coremail.luckd0g@163.com/
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/681e4a5260c182feb5fc1d96f0d43c62c21dc6c9.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:50 -04:00
Bart Van Assche
09982efcc0 scsi: core: Add lock context annotations
Document which functions expect that shost->scan_mutex is held.

Reviewed-by: John Garry <john.g.garry@oracle.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/ad5ca37acf8c933a12830c0811c293af54c87573.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:50 -04:00
Bart Van Assche
e70647b25a scsi: core: Pass the SCSI host pointer directly to scanning functions
In the functions scsi_probe_and_add_lun(), scsi_sequential_lun_scan(),
scsi_report_lun_scan() and __scsi_scan_target() the SCSI host pointer is
derived from the SCSI target pointer. Pass the SCSI host pointer
directly.

This patch prepares for enabling context analysis. With this patch applied,
context annotations can refer to the SCSI host pointer directly, e.g.
__must_hold(&shost->scan_mutex). Without this patch, the following
annotation would have to be used:
	__must_hold(&dev_to_shost(starget->dev.parent)->scan_mutex)
Additionally, in code that locks shost->scan_mutex, the following would
have to be added to help the compiler understand that shost ==
dev_to_shost(starget->dev.parent):
	__assume_ctx_lock(&dev_to_shost(starget->dev.parent)->scan_mutex);
__assume_ctx_lock() statements should be avoided if there is a good
alternative. Hence this patch. No functionality has been changed.

Reviewed-by: John Garry <john.g.garry@oracle.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/49d2fc5fae5cb5dca2536818155581c73f39c883.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:49 -04:00
Bart Van Assche
ff5d552022 scsi: ufs: core: Enable context analysis
Annotate functions that modify the state of a synchronization object.
Remove the struct semaphore annotations because lock context annotations
are not supported for semaphores.

Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/3c975386a5bcb939f8a2a0d47fd621f234321a9e.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:49 -04:00
Bart Van Assche
720d8b2f24 scsi: ufs: core: Set task state before io_schedule_timeout()
Set the task state to TASK_UNINTERRUPTIBLE before calling
io_schedule_timeout() in ufshcd_wait_for_pending_cmds().  Without
setting the task state, io_schedule_timeout() returns immediately
because the task state remains TASK_RUNNING. This results in a busy loop
that wastes CPU cycles.

Fixes: 2000bc3097 ("scsi: ufs: core: Reduce the clock scaling latency")
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/8fe4526ce272811b28e99048b42358dd8f7c48af.1786142946.git.bvanassche@acm.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 22:04:49 -04:00
Martin K. Petersen (Oracle)
dc1b802f8e Merge patch series "libsas: rediscover improvements for linkrate/sas_addr"
Xingui Yang <yangxingui@huawei.com> says:

When a device attached to an expander phy experiences a linkrate change
(e.g., due to cable reconnection or negotiation), the current code in
sas_rediscover_dev() treats it as "broadcast flutter" and takes no action
if the SAS address and device type remain unchanged.

This series is based on John Garry's suggestion [1] to check the linkrate
and mark the device as gone and rediscover when flutter occurs, replacing
the previous v2 patch series that used lldd callbacks.

The previous v2 approach added lldd_dev_info_update callback which John
commented as "seem fragile and too specialized" [2]. This series adopts
a simpler approach that directly checks linkrate/sas_addr changes in
sas_rediscover_dev() and triggers rediscovery using libsas's standard
async discovery pattern.

This aligns with Jason Yan's earlier work [3] which was verified to
solve the linkrate change issue.

Additionally, per the discussion in v3 [4], the existing replace code
path also suffers from the same sysfs duplication issue:
sas_unregister_devs_sas_addr() only marks the device as gone, but the
actual sysfs cleanup happens later in sas_destruct_devices(). Calling
sas_discover_new() immediately after unregister causes sysfs_warn_dup()
errors. This series also optimizes the replace path to use the async
pattern, ensuring proper ordering for both flutter and replace cases.

[1] https://lore.kernel.org/linux-scsi/c4e4c99f-a13c-4e28-8650-48be1f96d7cf@oracle.com/
[2] https://lore.kernel.org/linux-scsi/28bd9d5b-f597-0aae-5340-bd951b2083aa@huawei.com/
[3] https://lore.kernel.org/linux-scsi/20190130082412.9357-6-yanaijie@huawei.com/
[4] https://lore.kernel.org/linux-scsi/b99cd59f-b986-432e-aaf1-3b757e1c4c34@oracle.com/
[5] https://lore.kernel.org/linux-scsi/11581a25-caa6-4ea3-9aa0-2a4dacb7f34e@oracle.com/
[6] https://lore.kernel.org/linux-scsi/20260624063230.3264029-1-yangxingui@huawei.com/

Link: https://patch.msgid.link/20260811040334.4184911-1-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 21:55:24 -04:00
Xingui Yang
db441dcb8c scsi: libsas: Add linkrate and sas_addr change detection in rediscover
Introduce sas_dev_is_flutter() and sas_rediscover_ex_phy() to improve
flutter and device replace detection during rediscovery.

sas_dev_is_flutter() calls sas_ex_phy_discover() before looking up the
child device via sas_ex_phy_to_dev(), ensuring the PHY state is always
updated and avoiding use-after-free since the child device pointer is
obtained after the sleeping SMP request completes.

Add validation for linkrate and sas_addr changes. When the SAS address
changes, phy->attached_sas_addr is restored to the original address
before returning false, so sas_unregister_devs_sas_addr() can properly
match and unregister the old device. The sas_addr check is ordered
before the linkrate check to avoid skipping the restoration when both
change simultaneously.

sas_rediscover_ex_phy() uses the async discovery pattern
(sas_discover_event) instead of the synchronous sas_discover_new() to
ensure proper ordering between device unregistration and rediscovery,
avoiding sysfs_warn_dup() errors.

Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Suggested-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260811040334.4184911-3-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 21:53:50 -04:00
Xingui Yang
4c2128c1a3 scsi: libsas: Add sas_ex_phy_to_dev() helper
Add sas_ex_phy_to_dev() to return any device type attached to an
expander phy, and refactor sas_ex_to_ata() to use it.

No functional changes intended.

Signed-off-by: Xingui Yang <yangxingui@huawei.com>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260811040334.4184911-2-yangxingui@huawei.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 21:53:50 -04:00
Chandrakanth Patil
b9f679dfe6 scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
_base_release_memory_pools() unconditionally frees every
ioc->pcie_sg_lookup[] entry, including ones the setup loop never
allocated after a partial failure, causing a "bad dma" warning on debug
kernels or a NULL pointer dereference otherwise.

Fixes: dbec4c9040 ("scsi: mpt3sas: lockless command submission")
Reported-by: Laurence Oberman <loberman@redhat.com>
Signed-off-by: Chandrakanth Patil <chandrakanth.patil@broadcom.com>
Link: https://patch.msgid.link/20260808151010.185603-1-chandrakanth.patil@broadcom.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 21:45:38 -04:00
Nathan Chancellor
431e735e9b scsi: qla2xxx: Fix size_t format specifier in qla29xx_process_rd_image()
After commit c3930ec119 ("scsi: qla2xxx: Add FC operational firmware
load for 29xx"), there is a warning due to an incorrect format specifier
for a 'size_t' variable when building for 32-bit platforms, for which
'size_t' is 'unsigned int':

  drivers/scsi/qla2xxx/qla_init.c: In function 'qla29xx_process_rd_image':
  drivers/scsi/qla2xxx/qla_init.c:9272:74: error: format '%lx' expects argument of type 'long unsigned int', but argument 6 has type 'size_t' {aka 'unsigned int'} [-Werror=format=]
   9272 |                             "TIM section too large (0x%x bytes, ring 0x%lx bytes).\n",
        |                                                                        ~~^
        |                                                                          |
        |                                                                          long unsigned int
        |                                                                        %x
   9273 |                             section_size,
   9274 |                             req->length * qla_req_entry_size(ha));
        |                             ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        |                                         |
        |                                         size_t {aka unsigned int}
  cc1: all warnings being treated as errors

Use '%zx', the proper 'size_t' format specifier, to clear up the
warning.

Fixes: c3930ec119 ("scsi: qla2xxx: Add FC operational firmware load for 29xx")
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260811-scsi-qla2xxxx-qla_init-wformat-v1-1-50760021914f@kernel.org
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-13 21:42:06 -04:00
Karan Tilak Kumar
376a3960e5 scsi: fnic: Fix built-in NVMe/FC build
The fnic NVMe/FC code is guarded with IS_ENABLED(CONFIG_NVME_FC).  That
also evaluates true when NVME_FC is built as a module.

When fnic is built into vmlinux and NVME_FC=m, fnic_nvme.o still
references the NVMe/FC transport helpers even though those helpers are
not reachable from built-in code. The final vmlinux link then fails with
undefined nvme_fc_* symbols.

Use IS_REACHABLE(CONFIG_NVME_FC) for the fnic NVMe/FC implementation and
prototypes so built-in fnic uses the disabled stubs unless the NVMe/FC
transport is reachable.

Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202608092246.XZe7Hlrt-lkp@intel.com/
Reviewed-by: Sesidhar Baddela <sebaddel@cisco.com>
Reviewed-by: Arulprabhu Ponnusamy <arulponn@cisco.com>
Reviewed-by: Gian Carlo Boffa <gcboffa@cisco.com>
Reviewed-by: Arun Easi <aeasi@cisco.com>
Signed-off-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260810110627.4521-1-kartilak@cisco.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-10 21:24:01 -04:00
Roman Demidov
15b7fe6db6 scsi: fnic: Fix invalid comparison for error
The current comparison err != ERR_ECMDUNKNOWN is useless because err < 0
and ERR_ECMDUNKNOWN == 5. The logic is that if the CMD_CAPABILITY
command was executed, there is no need to respond to unknown errors.
Therefore, the sign of the number in the comparison must be changed.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260807091852.13151-1-roman.demidov.nn@gmail.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 14:09:34 -04:00
Petr Vaganov
626147717b scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables()
During fuzz testing, the following issue was discovered:

BUG: KMSAN: uninit-value in __dma_map_sg_attrs+0x217/0x310
 __dma_map_sg_attrs+0x217/0x310
 dma_map_sg_attrs+0x4a/0x70
 ata_qc_issue+0x9f8/0x1420
 __ata_scsi_queuecmd+0x1657/0x1740
 ata_scsi_queuecmd+0x79a/0x920
 scsi_queue_rq+0x4472/0x4f40
 blk_mq_dispatch_rq_list+0x1cca/0x3ee0
 __blk_mq_sched_dispatch_requests+0x458/0x630
 blk_mq_sched_dispatch_requests+0x15b/0x340
 __blk_mq_run_hw_queue+0xe5/0x250
 __blk_mq_delay_run_hw_queue+0x138/0x780
 blk_mq_run_hw_queue+0x4bb/0x7e0
 blk_mq_sched_insert_request+0x2a7/0x4c0
 blk_execute_rq+0x497/0x8a0
 sg_io+0xbe0/0xe20
 scsi_ioctl+0x2b36/0x3c60
 sr_block_ioctl+0x319/0x440
 blkdev_ioctl+0x80f/0xd70
 __se_sys_ioctl+0x219/0x420
 __x64_sys_ioctl+0x93/0xe0
 x64_sys_call+0x1d6c/0x3ad0
 do_syscall_64+0x4c/0xa0
 entry_SYSCALL_64_after_hwframe+0x6e/0xd8

Uninit was created at:
 __alloc_pages+0x5c0/0xc80
 alloc_pages+0xe0e/0x1050
 blk_rq_map_user_iov+0x2b77/0x6100
 blk_rq_map_user_io+0x2fa/0x4d0
 sg_io+0xad6/0xe20
 scsi_ioctl+0x2b36/0x3c60
 sr_block_ioctl+0x319/0x440
 blkdev_ioctl+0x80f/0xd70
 __se_sys_ioctl+0x219/0x420
 __x64_sys_ioctl+0x93/0xe0
 x64_sys_call+0x1d6c/0x3ad0
 do_syscall_64+0x4c/0xa0
 entry_SYSCALL_64_after_hwframe+0x6e/0xd8

Bytes 14-15 of 16 are uninitialized
Memory access of size 16 starts at ffff88800cbdb000

When processing the last unaligned element of the scatterlist, it is
supplemented with missing bytes in the amount of pad_len.  These bytes
remain uninitialized, which leads to a problem.

Extend last_sg->length by pad_len first, then use sg_zero_buffer() to
zero those pad_len bytes.  sg_zero_buffer() uses sg_miter internally,
which correctly handles sg entries spanning multiple pages and padding
that crosses a page boundary.

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Fixes: 40b01b9bbd ("block: update bio according to DMA alignment padding")
Cc: stable@vger.kernel.org
Signed-off-by: Petr Vaganov <p.vaganov@ideco.ru>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260628185229.37957-1-p.vaganov@ideco.ru
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:50:42 -04:00
Martin K. Petersen (Oracle)
3ad1010413 Merge patch series "scsi: zfcp: Enable CONTEXT_ANALYSIS"
Heiko Carstens <hca@linux.ibm.com> says:

Enable CONTEXT_ANALYSYS for the zfcp driver.

Static code checking for acquiring and releasing locks used to be done
with sparse. That was removed with [1] and replaced with a clang based
approach [2]. The new approach requires that each subsystem needs to
be explicitly enabled for checking.

Do that for drivers/s390/scsi. Add a __must_hold() attribute to
zfcp_qdio_sbal_get() to address the only valid warning. Then enable
CONTEXT_ANALYSIS, similar to other patches for drivers/s390 I'm
currently working on.

Link: https://patch.msgid.link/20260806134759.2122369-1-hca@linux.ibm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:45:47 -04:00
Heiko Carstens
32d9a4e296 scsi: zfcp: Enable CONTEXT_ANALYSIS
The zfcp driver passes clang's compile time context analysis.  Therefore
enable CONTEXT_ANALYSIS.

Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Link: https://patch.msgid.link/20260806134759.2122369-3-hca@linux.ibm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:44:39 -04:00
Heiko Carstens
ea598cfa56 scsi: zfcp: Add __must_hold() attribute to zfcp_qdio_sbal_get()
Add __must_hold() attribute to zfcp_qdio_sbal_get() in order to let
clang's context analysis know that qdio->req_q_wq must be held on
function entry. This is also documented above the function. Without this
annotation this leads to a valid warning when context analysis is
enabled:

drivers/s390/scsi/zfcp_qdio.c:287:8: warning:
  expecting spinlock '->req_q_lock' to be held at start of each loop [-Wthread-safety-analysis]
  287 |         ret = wait_event_interruptible_lock_irq_timeout(qdio->req_q_wq,
      |               ^

Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Link: https://patch.msgid.link/20260806134759.2122369-2-hca@linux.ibm.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:44:39 -04:00
Linkai Gong
9639c63245 scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock
fnic_fcoe_process_vlan_resp() allocates a VLAN descriptor with
kzalloc_obj() (default GFP_KERNEL) while holding vlans_lock via
spin_lock_irqsave(). GFP_KERNEL may sleep, which is not allowed in this
atomic context and can trigger a sleeping-from-invalid-context warning
or deadlock.

Pass GFP_ATOMIC so the allocation is safe under the IRQ-safe spinlock.

Fixes: 098585aa8a ("scsi: fnic: Add and integrate support for FIP")
Cc: stable@vger.kernel.org
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Reviewed-by: Karan Tilak Kumar <kartilak@cisco.com>
Link: https://patch.msgid.link/20260731073820.16449-1-gonglinkai@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:32:53 -04:00
Laurence Oberman
4c84c2e08a scsi: storvsc: Support manual scans for all Hyper-V targets
The Fibre Channel transport topology created by storvsc exposes only one
dummy remote port per SCSI host. Its scsi_target_id is always zero.

As a result, the FC transport user-scan path looks up the remote port
using target ID 0. It cannot initiate a scan for Target 1 or higher. No
SCSI command is therefore sent to Hyper-V when userspace explicitly
requests a scan of one of these targets.

storvsc itself supports up to STORVSC_FC_MAX_TARGETS and already passes
scmnd->device->id to Hyper-V as vm_srb->target_id. Devices on Target 1
and higher work when initially discovered. They can also be rediscovered
by a full host scan, such as the scan triggered after an FC port bounce.

Provide a storvsc-specific user_scan callback that uses the exported
scsi_scan_target() interface. Iterate over the requested channel and
target ranges so that wildcard and explicitly addressed scans retain the
expected SCSI sysfs scan semantics.

This bypasses the single-rport lookup in fc_user_scan() and allows
userspace to explicitly scan any target supported by storvsc without
requiring one synthetic fc_rport for every Hyper-V target.

Signed-off-by: Laurence Oberman <loberman@redhat.com>
Link: https://patch.msgid.link/20260723163743.1274830-1-loberman@redhat.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:25:48 -04:00
Martin K. Petersen (Oracle)
8368367590 Merge patch series "scsi: sd: fix probe error cleanup, special_vec leak and sd_done() sense gate"
Yang Xiuwei <yangxiuwei@kylinos.cn> says:

This series fixes three resource-handling bugs in drivers/scsi/sd.c:
sd_probe() error cleanup, special_vec mempool leak on prep failure,
and sd_done() sense handling.

v1: https://lore.kernel.org/all/20260623100159.4018066-1-yangxiuwei@kylinos.cn/

Link: https://patch.msgid.link/20260707030333.22245-1-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:14:49 -04:00
Yang Xiuwei
a640d4546b scsi: sd: Fix sd_done() sense handling condition
Only enter the sense_key switch when the command returned CHECK
CONDITION with valid, non-deferred sense. The old condition let deferred
or invalid sense fall through and mis-handle the I/O.

Fixes: 03aba2f795 ("[SCSI] sd/scsi_lib simplify sd_rw_intr and scsi_io_completion")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260707030333.22245-4-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:13:17 -04:00
Yang Xiuwei
bb31844d88 scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
sd_set_special_bvec() allocates a special payload page for UNMAP and
WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in
sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI
midlayer does not call uninit_command() because RQF_DONTPREP is not set
yet, leaking the page.

Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after
freeing the page.

Fixes: 81d926e8b5 ("sd: split sd_setup_discard_cmnd")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260707030333.22245-3-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:13:17 -04:00
Yang Xiuwei
e3cc6ea1a7 scsi: sd: Fix error handling in sd_probe() after large pool creation failure
After device_add(&sdkp->disk_dev) succeeds, sd_large_pool_create()
failure must unregister disk_dev and let scsi_disk_release() free
sdkp. Going through out_free_index kfree()s an already registered device
and leaks the sysfs entry.

Fixes: 7179e626b7 ("scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260707030333.22245-2-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 13:13:17 -04:00
Martin K. Petersen (Oracle)
3b6ee713a8 Merge patch series "scsi: Add LeapRAID driver support"
Dongdong Hao <doubled@leap-io-kernel.com> says:

This series adds the LeapRAID driver and its documentation.

This version addresses issues reported by Sashiko and the kernel test
robot, as well as issues identified through internal testing. Because
[PATCH v4 1/2] exceeded the line-count limit of the public Sashiko
service, it was not analyzed. We therefore deployed Sashiko locally
with an increased line-count limit to complete the analysis and have
fixed all identified issues.

Link: https://patch.msgid.link/cover.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 11:59:18 -04:00
Dongdong Hao
ca76824a3a scsi: leapraid: Add driver documentation
This patch adds the necessary documentation for the LeapRAID SCSI driver
to the kernel's documentation tree.

Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/6dc9239844dc00cd053ea0649cc9fe05cad1d98a.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 11:56:30 -04:00
Dongdong Hao
5597088c9e scsi: leapraid: Add new SCSI driver
The LeapRAID driver provides support for LeapRAID PCIe RAID controllers,
enabling communication between the host operating system, firmware, and
hardware for efficient storage management.

The driver is organized into several logical modules, each with a clear
responsibility:

leapraid_os.c: Integrates with the Linux SCSI subsystem, handling host
template callbacks, PCIe device probing, and initialization.

leapraid_func.c: Contains low-level routines for firmware/hardware
interaction, interrupt handling, and reset logic.

leapraid_app.c: Provides the ioctl interface for user-space tools.

leapraid_transport.c: Manages interactions with the SCSI transport
layer for SAS PHYs and ports.

leapraid_func.h: Contains internal definitions shared among driver
modules.

leapraid.h: Contains low-level hardware definitions for
driver/firmware interaction.

The leapraid_probe() function orchestrates the setup: it allocates the
adapter structure and SCSI host, configures hardware interfaces, and
registers it with the SCSI mid-layer. Following registration,
scsi_scan_host() is invoked to initiate device discovery, with firmware
reporting devices via interrupt-driven events.

This initial commit provides the necessary infrastructure for
subsequent development of full I/O path handling, error recovery,
and advanced management features.

Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Dongdong Hao <doubled@leap-io-kernel.com>
Link: https://patch.msgid.link/0cbc6245aabdc6e8c90587675e76ba316c5b549e.1785823793.git.doubled@leap-io-kernel.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
2026-08-07 11:56:30 -04:00