From nobody Sun Jul 26 01:45:23 2026 Received: from mail-qk1-f173.google.com (mail-qk1-f173.google.com [209.85.222.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 63D322D7DCF for ; Fri, 10 Jul 2026 02:30:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650626; cv=none; b=A3LeMOv7AyErkRoTLF9w++weEuqSpdpVZMGS+83LG6hYb9Ml7ZWOlGVT3AiI9Qh+QlWgd+uQSfO16lt4vGZQxzo1b/uiDuvQ4fLFTgSiOV0DMguCmCsZWA95V9sTxW5qqIKa2xj2kNB+jY+efC+nDMMDeynBLUKClgWphr+Co2o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650626; c=relaxed/simple; bh=C3alcSBjrUVozN+9IQM4PUHMmXGEWaomuPn0A1LETyU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JFkJbEcWhTfmSCmXqyI3iWPca7BzVsc5G7VhGR8sA9P1abiSxNE5kbcEYm+3SxYPHxzVnykjDwIFi2UrUmZiSP4pkeQIE+YMdtRlhiJc1Jyy0ZyQXMyiSJMEoHdOno3sMY6B6RZwkyMissQyAouWAKEn6sNoDo7VvXRQo8JwZd0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fMoUhj16; arc=none smtp.client-ip=209.85.222.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fMoUhj16" Received: by mail-qk1-f173.google.com with SMTP id af79cd13be357-920f33347f5so19863085a.3 for ; Thu, 09 Jul 2026 19:30:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783650624; x=1784255424; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gt0/g7zZyJ9oxGVfpXChoCA6Z2B5Mn4pHu0Aa2usY6s=; b=fMoUhj165Vjja3pGXSrZeDlegv7DY5SypxrQXUd27uyo4LDBQml3MuDGBt/PpVzn8J qVFJGbmSoxygsrir10hYefTTEKX9jaAUb7lcFO4Ssh0jl7zsEY1K7d7X0DZ3nSO7HrZN W6R6czx61nXod6AZ0jRxNot3aUHctRUxw53pWfej9cHC43jdsrVjvVqnlVa9BdXPTW+I kzuDnfvMSYX3mwIKyfVjeE8Y4cocIQlU5uK4nZVyI4Ya3fD6HNlbeT+bE/jT6RiQJISk Z5Ex75PFZovE4v0liTo5+Dr1uJeHLt0ZDOe31sBq0qBCVUayR/ZmGy2aUi5tlxctmH3Z 1/yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783650624; x=1784255424; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=gt0/g7zZyJ9oxGVfpXChoCA6Z2B5Mn4pHu0Aa2usY6s=; b=DgNq0SH396mWDkeIgxrAcT0Of0IuK1XVC62vp9RRm1QW4wdyC+/iIqVYIcg13UmZPq GgUYv/gCogAMtCie5qXMiYpzW7PUNZ0UY8FlkMf7nFC3dBJdhgO1NOYHk+vAuhuRxYYr ptGNrvQvHzNL8MKDm/Cms0yZwyiP7HtJgfws0QMlxNR8n9StOkZTJt/9Qdb75uKjKAp/ mrcZXP8S+8O/VAoj6LAcy3+J5r09SIQfG43ODY1TfGtO3ty0vH92FqgpfGB99YqWhYW4 v/UfPMUcxPKR1rFEnCbIkCg7cNhY3ibJOh0ZHXfKDTAx4atDOT18bHzA9SsUC1x4FGqF cbaw== X-Forwarded-Encrypted: i=1; AHgh+RoGNQ7KtR8RDqkVEslGJJWrOOMUJQn8g2DbC1JW1+03+Zpp8OTzrr8bqlks/ItIwIvBnQ7vXG8O/bpxmSw=@vger.kernel.org X-Gm-Message-State: AOJu0Yy01cnnIfz5xsysro/4ImzkKWXIVxCMyr10lRIYSPUhd6ZzIlVL OZIJqgGnpCCQvL2/hGKbV8vgVmNFEIj3/ukbgcHMisgWNbKS3F3ChHhz X-Gm-Gg: AfdE7cmZtBMI4LH0EqUdJe1ld1lPe2UOpL15H9WNme6KEHhtoTBkkPq//W31Vkx4N5s ViwxSg0U+jGZ4zvJeEszqKpU+eHoUscFUlVcv8qYlJ1c6CPVFtkK6I4kbQIOhFMTM6Yy6xXQO4R uVmvi4OzVqC1cu9xH8LjGur/iRhjg1H+FfM6Ib+blymKmuLE9s67rwcG87U3vZUNWl/KO36MB/M zYYOtpgNfUbChxjWEo5IaRWANjhyfV6obyZ7hTYzklgEBCtfY/5lrka80SjHyWNC4JXXR3lYXAp TUEzj5pTGZ7ShnP/d55WvACGxeyNuA74sj0VvgrAH+JWeRCfmJYswH7yE7qZHFcoASacHnlpIY1 5Xl0Rb6OJjjiuRMOY2hU8g9PgJsgBdbnKgdOwMPuTb3A0AKQOhjWJWBMYbMJ6OPqFQMs3ALO8O3 +PjHFqTJZrtN+vudqPHHWBXL/DwLampGj7VoI6QIfwCNmKQFZ06gUPVbhxV8tw/a0Oi2QK37Fhu rpmguuT7+sEBnh4woQgf2Y9Pzy1VLym X-Received: by 2002:a05:620a:4693:b0:92e:c116:bf10 with SMTP id af79cd13be357-92ecf95ea9emr984970385a.89.1783650624113; Thu, 09 Jul 2026 19:30:24 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-92ee5cf9d9bsm88854685a.28.2026.07.09.19.30.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 19:30:23 -0700 (PDT) From: Michael Bommarito To: Christoph Hellwig , Sagi Grimberg , Chaitanya Kulkarni Cc: kwilczynski@kernel.org, Damien Le Moal , Manivannan Sadhasivam , Keith Busch , linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 1/2] nvmet-pci: validate queue IDs against endpoint queues Date: Thu, 9 Jul 2026 22:30:14 -0400 Message-ID: <20260710023015.3744082-2-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260710023015.3744082-1-michael.bommarito@gmail.com> References: <20260710023015.3744082-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The NVMe PCI endpoint transport allocates SQ/CQ arrays using ctrl->nr_queues, which is capped by endpoint interrupt capacity. Common target admin validation only checks queue IDs against subsys->max_qid, so a root-complex host can submit Create/Delete SQ/CQ commands with qids that pass the common checks but index past the smaller endpoint transport arrays. Impact: A PCI root-complex host can crash an NVMe PCI endpoint target with malformed queue IDs. Reject queue IDs that are outside ctrl->nr_queues before indexing the endpoint SQ/CQ arrays. Fixes: 0faa0fe6f90e ("nvmet: New NVMe PCI endpoint function target driver") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5-5-xhigh Signed-off-by: Michael Bommarito Reviewed-by: Damien Le Moal --- I reproduced this with a same-translation-unit KUnit/KASAN test. The stock Create CQ path faults in nvmet_pci_epf_create_cq() after nvmet_check_io_cqid() accepts qid 2 with max_qid 8 and nr_queues 2. The patched checks reject malformed Create/Delete SQ/CQ cases while the benign control still passes. drivers/nvme/target/pci-epf.c | 31 ++++++++++++++++++++++++++----- 1 file changed, 26 insertions(+), 5 deletions(-) diff --git a/drivers/nvme/target/pci-epf.c b/drivers/nvme/target/pci-epf.c index 4e9db96ebfecd..5bddda09c0538 100644 --- a/drivers/nvme/target/pci-epf.c +++ b/drivers/nvme/target/pci-epf.c @@ -1267,10 +1267,15 @@ static u16 nvmet_pci_epf_create_cq(struct nvmet_ctr= l *tctrl, u16 cqid, u16 flags, u16 qsize, u64 pci_addr, u16 vector) { struct nvmet_pci_epf_ctrl *ctrl =3D tctrl->drvdata; - struct nvmet_pci_epf_queue *cq =3D &ctrl->cq[cqid]; + struct nvmet_pci_epf_queue *cq; u16 status; int ret; =20 + if (cqid >=3D ctrl->nr_queues) + return NVME_SC_QID_INVALID | NVME_STATUS_DNR; + + cq =3D &ctrl->cq[cqid]; + if (test_bit(NVMET_PCI_EPF_Q_LIVE, &cq->flags)) return NVME_SC_QID_INVALID | NVME_STATUS_DNR; =20 @@ -1348,7 +1353,12 @@ static u16 nvmet_pci_epf_create_cq(struct nvmet_ctrl= *tctrl, static u16 nvmet_pci_epf_delete_cq(struct nvmet_ctrl *tctrl, u16 cqid) { struct nvmet_pci_epf_ctrl *ctrl =3D tctrl->drvdata; - struct nvmet_pci_epf_queue *cq =3D &ctrl->cq[cqid]; + struct nvmet_pci_epf_queue *cq; + + if (cqid >=3D ctrl->nr_queues) + return NVME_SC_QID_INVALID | NVME_STATUS_DNR; + + cq =3D &ctrl->cq[cqid]; =20 if (!test_and_clear_bit(NVMET_PCI_EPF_Q_LIVE, &cq->flags)) return NVME_SC_QID_INVALID | NVME_STATUS_DNR; @@ -1367,10 +1377,16 @@ static u16 nvmet_pci_epf_create_sq(struct nvmet_ctr= l *tctrl, u16 sqid, u16 cqid, u16 flags, u16 qsize, u64 pci_addr) { struct nvmet_pci_epf_ctrl *ctrl =3D tctrl->drvdata; - struct nvmet_pci_epf_queue *sq =3D &ctrl->sq[sqid]; - struct nvmet_pci_epf_queue *cq =3D &ctrl->cq[cqid]; + struct nvmet_pci_epf_queue *sq; + struct nvmet_pci_epf_queue *cq; u16 status; =20 + if (sqid >=3D ctrl->nr_queues || cqid >=3D ctrl->nr_queues) + return NVME_SC_QID_INVALID | NVME_STATUS_DNR; + + sq =3D &ctrl->sq[sqid]; + cq =3D &ctrl->cq[cqid]; + if (test_bit(NVMET_PCI_EPF_Q_LIVE, &sq->flags)) return NVME_SC_QID_INVALID | NVME_STATUS_DNR; =20 @@ -1419,7 +1435,12 @@ static u16 nvmet_pci_epf_create_sq(struct nvmet_ctrl= *tctrl, static u16 nvmet_pci_epf_delete_sq(struct nvmet_ctrl *tctrl, u16 sqid) { struct nvmet_pci_epf_ctrl *ctrl =3D tctrl->drvdata; - struct nvmet_pci_epf_queue *sq =3D &ctrl->sq[sqid]; + struct nvmet_pci_epf_queue *sq; + + if (sqid >=3D ctrl->nr_queues) + return NVME_SC_QID_INVALID | NVME_STATUS_DNR; + + sq =3D &ctrl->sq[sqid]; =20 if (!test_and_clear_bit(NVMET_PCI_EPF_Q_LIVE, &sq->flags)) return NVME_SC_QID_INVALID | NVME_STATUS_DNR; --=20 2.53.0 From nobody Sun Jul 26 01:45:23 2026 Received: from mail-qk1-f178.google.com (mail-qk1-f178.google.com [209.85.222.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2C8452D23A4 for ; Fri, 10 Jul 2026 02:30:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650630; cv=none; b=hD0S2cZxlsmndXDLhV8iCRCBGtVeZTFrHJzzkoh8WNLk4P7PEpllewGLzq7bY/WaV6+DmDTEG8lHHHbZ0n+mr/mhsldqH1PvGGSpRs6oa4zCxEyC3I2+JiMG87y0teg4WgnkgbW0zJ+HqinzqRQdg0b7vnPB9NSjzvMjJBKdYFQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783650630; c=relaxed/simple; bh=6rcoTl5xiJEaGPQJTsD/mlHreqv+V88NduNqHg/I68c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XgtpH+6QB2diycCo8VQD4Kg9apx0ufGyb0hBMMI9WknUcCJATkSorGln4/3Nv9qgRbNTuQSUfk6KrHJtt1mzA4PLOtTmqSmELCa26czFf2J4x+dXj+vJTUB4wWSDYhvcFt+k4p/AmsE7zF0icGl1UMbRzfx15SlApv5f40ihuOg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=W3IXwVlr; arc=none smtp.client-ip=209.85.222.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="W3IXwVlr" Received: by mail-qk1-f178.google.com with SMTP id af79cd13be357-92e54f8c051so18550885a.3 for ; Thu, 09 Jul 2026 19:30:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783650626; x=1784255426; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Q1TRFmapyBVbWd7VNMC/WNlG0M10kUIkWE/yDLtryY8=; b=W3IXwVlrpdh/nw+w5EVAlyHj2b5V5rWxHpPSkVLTKjnitNDJchdV7u569SzrgX8p2A Geo43uJinvaV6oNpkfdsRU4w7llp+YNB0p7jnDiNBiYKjr8tw8jKbqS8PwBTHQOc33zq pPBpLGsTh+/BaLsLJt1NcTnpyZHkWp8OjQWaF0oH6UmYG8yCovju5ifJ/fxZKV0cruj/ bCp4/dReYn/3IeJwi0pndAE453lkculHadIDwsN4KM51qm+aBcmXFu+4QfmmhnG6IvCe 3BTrs2A6GA99+WwHwO7Z9QdkqeXP+3oFH1jnVMI/XDYjn33HBECcb063YH4PrP7AD2Dy IxMg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783650626; x=1784255426; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Q1TRFmapyBVbWd7VNMC/WNlG0M10kUIkWE/yDLtryY8=; b=eajZt6ofZT0qsTUN0EO/fwS9MwGrFaZmhPjw7S9bRR7kLCAwsjiEbXJeEDQIrtW/Dw fWeAtAXPRJDOlG4wgGhq0CeV0spLAujf89m+DA093c+Al/c7KnWgoiSEmwG2p5hWaX2o JQVjvbQ/W82C4avVEe6BHCMcLPTFcqu+oQEYRLcCEW5ehxU9WuXCj45ib6otpMVg3MQ0 5YtJVPhatYwkbxojN/OB5dWB48zuRI0Y9u1cab8icp/QNaaUYzrHIgKu3Gh54cTJoQ9V NLvUpLTVKzHWxPGEFjsR/qkaT8hxBMbyOCXN6DRBcKqh4zhhx07z4jQdZ+vXq/p4ClHJ eYjg== X-Forwarded-Encrypted: i=1; AHgh+RpNQDDrjzogsZT8ffcdYDsyuc7P0ti2faAAJ0/hZy4XpZ+E7ny0d0QtEmKxXBJqn4CxRy+iH+K2YKGhCMo=@vger.kernel.org X-Gm-Message-State: AOJu0Yyx/NZTgNgawppL2Fi0eJNA1DADEWjC6c8eQffTPcRhs3MApYfQ 0/a3Mju1fscUjF0bGl08brFeuTaRJi4b8U2ZK2Mj+B/tRxHrfRVHJXLe X-Gm-Gg: AfdE7cmjNL89Y6cBSkkwPj3eWD4CJp/mHN8F9EijH6PxcEvhdnhqNvQRGMyugE0cNhS o7HyA67O3AA5fFVwopbF5oPT/edLVaJ3C9b21S0J0f3dITgtNKUrPR9qgJMHd3bwG3S8jI/obFh kQtER89kDE4JPT4yCydty+phnMv+U5EOsWY6ZM+rsu8pJO+/7grKNcxlHHuoRGmSggMF8DO61pd zE+CKZWaVND5By7O7qVeYUDm7oRSnT21BzkwYoxZTed9ODxaF1Y7PJpFXnCLlPGUi7ccTRIMaVS tPhNyLi75Hm9o12jBKZgULXxCEFwnYQSyZvpgAhM1JDsFj9oY8JMKHBNX7iK7WNsx0WGCJLk5yZ +LHAFFyFWXFx1vbostLd0zFi1XGEVPpGO5qVvEEymNrPBKnebVLR/vLHr45fGRjRR96ZkCDDVe3 GkFv1Pb0GjdNOWflfRlJJGJu/ahgQCXE7MUmWDrphwvhGuthQ6elvk5MSWvOE5EtjM71AI02Qw/ qpY8w59U8B2emRcVUFQqPv5inzOUR9fd5tldQGhpvA= X-Received: by 2002:a05:620a:2842:b0:915:abc4:b580 with SMTP id af79cd13be357-92ecf5ddb30mr1039946985a.49.1783650625775; Thu, 09 Jul 2026 19:30:25 -0700 (PDT) Received: from server0.tail6e7dd.ts.net (c-68-48-65-54.hsd1.mi.comcast.net. [68.48.65.54]) by smtp.gmail.com with ESMTPSA id af79cd13be357-92ee5cf9d9bsm88854685a.28.2026.07.09.19.30.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Jul 2026 19:30:25 -0700 (PDT) From: Michael Bommarito To: Christoph Hellwig , Sagi Grimberg , Chaitanya Kulkarni Cc: kwilczynski@kernel.org, Damien Le Moal , Manivannan Sadhasivam , Keith Busch , linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/2] nvmet-pci: add KUnit coverage for endpoint queue IDs Date: Thu, 9 Jul 2026 22:30:15 -0400 Message-ID: <20260710023015.3744082-3-michael.bommarito@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260710023015.3744082-1-michael.bommarito@gmail.com> References: <20260710023015.3744082-1-michael.bommarito@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add KUnit coverage for the PCI endpoint target queue-id boundary. The tests model the case where target-core max_qid is larger than the endpoint transport's ctrl->nr_queues, confirm the common qid check accepts the malformed id, and verify the endpoint callbacks reject out-of-range Create/Delete SQ/CQ requests before indexing transport-private arrays. This covers the regression fixed by the preceding patch. Assisted-by: Codex:gpt-5-5-xhigh Signed-off-by: Michael Bommarito Reviewed-by: Damien Le Moal --- drivers/nvme/target/Kconfig | 11 ++++ drivers/nvme/target/pci-epf.c | 120 ++++++++++++++++++++++++++++++++++ 2 files changed, 131 insertions(+) diff --git a/drivers/nvme/target/Kconfig b/drivers/nvme/target/Kconfig index 4904097dfd490..ea64bbe9882c5 100644 --- a/drivers/nvme/target/Kconfig +++ b/drivers/nvme/target/Kconfig @@ -127,3 +127,14 @@ config NVME_TARGET_PCI_EPF capable PCI controller. =20 If unsure, say N. + +config NVMET_PCI_EPF_KUNIT_TEST + bool "NVMe PCI endpoint target KUnit tests" if !KUNIT_ALL_TESTS + depends on KUNIT + depends on NVME_TARGET_PCI_EPF=3Dy + default KUNIT_ALL_TESTS + help + KUnit tests for the NVMe PCI endpoint target transport. + These tests exercise transport-private queue ID checks for + Create/Delete SQ/CQ commands when target-core max_qid is larger than + the endpoint controller's available queue arrays. diff --git a/drivers/nvme/target/pci-epf.c b/drivers/nvme/target/pci-epf.c index 5bddda09c0538..e2eb96f32fab5 100644 --- a/drivers/nvme/target/pci-epf.c +++ b/drivers/nvme/target/pci-epf.c @@ -20,6 +20,9 @@ #include #include #include +#if IS_ENABLED(CONFIG_NVMET_PCI_EPF_KUNIT_TEST) +#include +#endif =20 #include "nvmet.h" =20 @@ -2667,3 +2670,120 @@ module_exit(nvmet_pci_epf_cleanup_module); MODULE_DESCRIPTION("NVMe PCI Endpoint Function target driver"); MODULE_AUTHOR("Damien Le Moal "); MODULE_LICENSE("GPL"); + +#if IS_ENABLED(CONFIG_NVMET_PCI_EPF_KUNIT_TEST) + +struct nvmet_pci_epf_kunit_ctx { + struct nvmet_ctrl tctrl; + struct nvmet_subsys subsys; + struct nvmet_pci_epf_ctrl ctrl; + struct nvmet_pci_epf nvme_epf; +}; + +static int nvmet_pci_epf_kunit_init(struct kunit *test) +{ + struct nvmet_pci_epf_kunit_ctx *ctx; + unsigned int qid; + + ctx =3D kunit_kzalloc(test, sizeof(*ctx), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, ctx); + + ctx->subsys.max_qid =3D 8; + ctx->tctrl.subsys =3D &ctx->subsys; + ctx->tctrl.drvdata =3D &ctx->ctrl; + ctx->tctrl.cqs =3D kunit_kcalloc(test, ctx->subsys.max_qid + 1, + sizeof(*ctx->tctrl.cqs), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, ctx->tctrl.cqs); + ctx->tctrl.sqs =3D kunit_kcalloc(test, ctx->subsys.max_qid + 1, + sizeof(*ctx->tctrl.sqs), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, ctx->tctrl.sqs); + + ctx->ctrl.nr_queues =3D 2; + ctx->ctrl.tctrl =3D &ctx->tctrl; + ctx->ctrl.nvme_epf =3D &ctx->nvme_epf; + ctx->ctrl.sq =3D kunit_kcalloc(test, ctx->ctrl.nr_queues, + sizeof(*ctx->ctrl.sq), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, ctx->ctrl.sq); + ctx->ctrl.cq =3D kunit_kcalloc(test, ctx->ctrl.nr_queues, + sizeof(*ctx->ctrl.cq), GFP_KERNEL); + KUNIT_ASSERT_NOT_NULL(test, ctx->ctrl.cq); + + for (qid =3D 0; qid < ctx->ctrl.nr_queues; qid++) { + nvmet_pci_epf_init_queue(&ctx->ctrl, qid, true); + nvmet_pci_epf_init_queue(&ctx->ctrl, qid, false); + } + + test->priv =3D ctx; + return 0; +} + +static void nvmet_pci_epf_qid_control_test(struct kunit *test) +{ + struct nvmet_pci_epf_kunit_ctx *ctx =3D test->priv; + u16 status; + + status =3D nvmet_check_io_cqid(&ctx->tctrl, 1, true); + KUNIT_EXPECT_EQ(test, status, (u16)NVME_SC_SUCCESS); + + status =3D nvmet_pci_epf_create_cq(&ctx->tctrl, 1, 0, 1, 0, 0); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_INVALID_QUEUE | NVME_STATUS_DNR)); +} + +static void nvmet_pci_epf_qid_oob_test(struct kunit *test) +{ + struct nvmet_pci_epf_kunit_ctx *ctx =3D test->priv; + u16 bad_qid =3D ctx->ctrl.nr_queues; + u16 status; + + status =3D nvmet_check_io_cqid(&ctx->tctrl, bad_qid, true); + KUNIT_EXPECT_EQ(test, status, (u16)NVME_SC_SUCCESS); + + status =3D nvmet_pci_epf_create_cq(&ctx->tctrl, bad_qid, 0, 1, 0, 0); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); +} + +static void nvmet_pci_epf_qid_reject_all_test(struct kunit *test) +{ + struct nvmet_pci_epf_kunit_ctx *ctx =3D test->priv; + u16 bad_qid =3D ctx->ctrl.nr_queues; + u16 status; + + status =3D nvmet_pci_epf_create_cq(&ctx->tctrl, bad_qid, 0, 1, 0, 0); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); + + status =3D nvmet_pci_epf_create_sq(&ctx->tctrl, bad_qid, 1, 0, 1, 0); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); + + status =3D nvmet_pci_epf_create_sq(&ctx->tctrl, 1, bad_qid, 0, 1, 0); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); + + status =3D nvmet_pci_epf_delete_cq(&ctx->tctrl, bad_qid); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); + + status =3D nvmet_pci_epf_delete_sq(&ctx->tctrl, bad_qid); + KUNIT_EXPECT_EQ(test, status, + (u16)(NVME_SC_QID_INVALID | NVME_STATUS_DNR)); +} + +static struct kunit_case nvmet_pci_epf_qid_test_cases[] =3D { + KUNIT_CASE(nvmet_pci_epf_qid_control_test), + KUNIT_CASE(nvmet_pci_epf_qid_oob_test), + KUNIT_CASE(nvmet_pci_epf_qid_reject_all_test), + {} +}; + +static struct kunit_suite nvmet_pci_epf_qid_test_suite =3D { + .name =3D "nvmet_pci_epf_qid", + .init =3D nvmet_pci_epf_kunit_init, + .test_cases =3D nvmet_pci_epf_qid_test_cases, +}; + +kunit_test_suite(nvmet_pci_epf_qid_test_suite); + +#endif --=20 2.53.0