Commit 622ecb59 authored by Yu Kuai's avatar Yu Kuai Committed by Yongqiang Liu
Browse files

nbd: don't clear 'NBD_CMD_INFLIGHT' flag if request is not completed

mainline inclusion
from mainline-v5.19-rc1
commit 2895f183
category: bugfix
bugzilla: 187081, https://gitee.com/src-openeuler/kernel/issues/I5H341


CVE: NA

--------------------------------

Otherwise io will hung because request will only be completed if the
cmd has the flag 'NBD_CMD_INFLIGHT'.

Fixes: 07175cb1 ("nbd: make sure request completion won't concurrent")
Signed-off-by: default avatarYu Kuai <yukuai3@huawei.com>
Link: https://lore.kernel.org/r/20220521073749.3146892-4-yukuai3@huawei.com


Signed-off-by: default avatarJens Axboe <axboe@kernel.dk>

Conflict: fake timeout is not supported yet, clear_bit() in
nbd_handle_reply() directly.
Signed-off-by: default avatarYu Kuai <yukuai3@huawei.com>
Reviewed-by: default avatarJason Yan <yanaijie@huawei.com>
Signed-off-by: default avatarYongqiang Liu <liuyongqiang13@huawei.com>
parent f4df027e
Loading
Loading
Loading
Loading
+6 −2
Original line number Diff line number Diff line
@@ -375,13 +375,14 @@ static enum blk_eh_timer_return nbd_xmit_timeout(struct request *req,
	if (!mutex_trylock(&cmd->lock))
		return BLK_EH_RESET_TIMER;

	if (!__test_and_clear_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
	if (!test_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
		mutex_unlock(&cmd->lock);
		return BLK_EH_DONE;
	}

	if (!refcount_inc_not_zero(&nbd->config_refs)) {
		cmd->status = BLK_STS_TIMEOUT;
		__clear_bit(NBD_CMD_INFLIGHT, &cmd->flags);
		mutex_unlock(&cmd->lock);
		goto done;
	}
@@ -422,6 +423,7 @@ static enum blk_eh_timer_return nbd_xmit_timeout(struct request *req,
	}
	set_bit(NBD_RT_TIMEDOUT, &config->runtime_flags);
	cmd->status = BLK_STS_IOERR;
	__clear_bit(NBD_CMD_INFLIGHT, &cmd->flags);
	mutex_unlock(&cmd->lock);
	sock_shutdown(nbd);
	nbd_config_put(nbd);
@@ -693,7 +695,7 @@ static struct nbd_cmd *nbd_handle_reply(struct nbd_device *nbd, int index,
	cmd = blk_mq_rq_to_pdu(req);

	mutex_lock(&cmd->lock);
	if (!__test_and_clear_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
	if (!test_bit(NBD_CMD_INFLIGHT, &cmd->flags)) {
		dev_err(disk_to_dev(nbd->disk), "Suspicious reply %d (status %u flags %lu)",
			tag, cmd->status, cmd->flags);
		ret = -ENOENT;
@@ -761,6 +763,8 @@ static struct nbd_cmd *nbd_handle_reply(struct nbd_device *nbd, int index,
		}
	}
out:
	if (!ret)
		__clear_bit(NBD_CMD_INFLIGHT, &cmd->flags);
	mutex_unlock(&cmd->lock);
	return ret ? ERR_PTR(ret) : cmd;
}