Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit d444edc6 authored by Nicholas Bellinger's avatar Nicholas Bellinger
Browse files

iscsi-target: Fix ERL=2 ASYNC_EVENT connection pointer bug



This patch fixes a long-standing bug in iscsit_build_conn_drop_async_message()
where during ERL=2 connection recovery, a bogus conn_p pointer could
end up being used to send the ISCSI_OP_ASYNC_EVENT + DROPPING_CONNECTION
notifying the initiator that cmd->logout_cid has failed.

The bug was manifesting itself as an OOPs in iscsit_allocate_cmd() with
a bogus conn_p pointer in iscsit_build_conn_drop_async_message().

Reported-by: default avatarArshad Hussain <arshad.hussain@calsoftinc.com>
Reported-by: default avatarsantosh kulkarni <santosh.kulkarni@calsoftinc.com>
Cc: <stable@vger.kernel.org> #3.1+
Signed-off-by: default avatarNicholas Bellinger <nab@linux-iscsi.org>
parent f2252258
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -2491,6 +2491,7 @@ static void iscsit_build_conn_drop_async_message(struct iscsi_conn *conn)
{
	struct iscsi_cmd *cmd;
	struct iscsi_conn *conn_p;
	bool found = false;

	/*
	 * Only send a Asynchronous Message on connections whos network
@@ -2499,11 +2500,12 @@ static void iscsit_build_conn_drop_async_message(struct iscsi_conn *conn)
	list_for_each_entry(conn_p, &conn->sess->sess_conn_list, conn_list) {
		if (conn_p->conn_state == TARG_CONN_STATE_LOGGED_IN) {
			iscsit_inc_conn_usage_count(conn_p);
			found = true;
			break;
		}
	}

	if (!conn_p)
	if (!found)
		return;

	cmd = iscsit_allocate_cmd(conn_p, TASK_RUNNING);