From nobody Sat Jul 25 17:34:23 2026 Received: from mail-wr1-f45.google.com (mail-wr1-f45.google.com [209.85.221.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 31060326924 for ; Wed, 15 Jul 2026 13:57:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.45 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784123825; cv=none; b=m4z/qtTgZKGnai1pAfLc3z3JSIKgoKaJg1C9FiHgr134U0LpuzXHD2/1aEQ1C/1iL4pbD3vLqUoVWXhI5Eb7Bzq/lgT41A56ns5Mdbdma63N3VvyPt11dZes1YYd2M5j6BaGFgMESaGwfQwaPApICTX+0NQrEjHHeQDJWhMb6YU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784123825; c=relaxed/simple; bh=fHfXfwEc0ghsiYFZBHpO96ExH/GyzOS5wPECh/RgVIY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=PtZjS5qCcFs0LZRQK0qm5GPx40S6XS91DJdJWDUCnKtImp3AgoFHBe2Uf4ZpJP5auI8NiTPufiIoiWH16BN2TeFUczIqK8Sfw73LjE2rBLv4btH7CrFP5usFH6x2bz72MMWFlTnS3STE1GnZA+OIQMimGZbRvJGqZJ2BsoGU7Dk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com; spf=pass smtp.mailfrom=ionos.com; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b=Ff9BqWfU; arc=none smtp.client-ip=209.85.221.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ionos.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b="Ff9BqWfU" Received: by mail-wr1-f45.google.com with SMTP id ffacd0b85a97d-4728c12ba97so2556721f8f.0 for ; Wed, 15 Jul 2026 06:57:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ionos.com; s=google; t=1784123820; x=1784728620; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=13DZ1ti/XUipAhOOzOx37nwrN3CtQ4Vj0oi6u43J5uE=; b=Ff9BqWfUyD94xR221QC1OnFimmefE2CEkatAt5z2SQy2Eg/eFgNNxBOs1b43b+vSdE ikm7pQFTOJGkHv27wEXtpu/IoGsiGeQjM7L541KN6LeV4+YGYh/aG/bmro1Q9QXuZPP3 Tn5GOJYDuGQzL8xdkzrWfyxKQM1+fFlwxKws0tEP8WLVXlXYJKfDBhFhuTTR5KNXCCUb UDQ2i9D/RklmMh9l3suvLnJ3nw/sdfxaR2sIfntTLMi9OjKOby9hS9WOHP9jlngzzmIq cJr25HhRHu4JKpSeDCEMj3UYiSOZ32w2aUwrUPA6TLuH8x219YrM/FPu9/lQqQRKoAqt oBZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784123820; x=1784728620; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=13DZ1ti/XUipAhOOzOx37nwrN3CtQ4Vj0oi6u43J5uE=; b=NQmIk7xc8mFXxyZN/jyvdhAA7mGtWJ7QcaqBSnuynJYuQhfFyKpUhTdbcTd+hUQbmm gxi9PIS2JfADYc+9z2iQeEYyxh7+IfmogclCUBU1Z9cB7c3auxahxtLL7Tw8nlbHxr6T 7vnMizWozAQ9Wm5sYHPMinv0AtGMhbphqzZNcoCfDlCPHxN3coYm8WR0nC3OUBj/vGNi HC/MeVK3yPxujwhTtgD2mqiSB0inCIFq8FmTAB4pMaAvJmgZdkSRP6INYJtGJjPDK0KJ 7fnKweccd2iirGRNsC6x7QJJ9tE+E8jTnTZbEwTUACylHEqM9V3uHAzR3xa1XfjmVwG2 rP1A== X-Forwarded-Encrypted: i=1; AHgh+RrnknRM4sbdtBL9IjJ5+mADC22547tkJmpc+2DEMnNYBqBUnknjSB2rYzxSHgBr4QFHDChG7mBot/AfEVw=@vger.kernel.org X-Gm-Message-State: AOJu0Ywl8J3Ycq2WfvI+WvzBUOY1Pa+b0ba9K4kzLVJbHylc8Pdlry6k lzJPTDQ+li0d+2XzggMd+5oFZdGkFTBnLDpzizD10lUu4uGpL25qUa6rFqCoTXOfKkA= X-Gm-Gg: AfdE7cm3XxePWO/Lhzhbkd6o8YhWNjhxNemqyvFRh9TwZsw3DJcBAOIEcu10MULkPcq GtA2aVCgQj78WO58FNujmYawbYCjKJErUOkMoncpl4wWGguQql2gRQ0OG7zznDwpF+Ool7ocn8u 1vd9DyBBIlaiSSDhAaQorjYIxiUSvM/nbvn61iuXfcB/uc6MfDo8hgv5dM+F7HRxwvuKBUpcNAa s1KTEZPGS4u0b9RNmxkCw7iuxv84xkOTkPAm6/eRQz9Q1naVH74HPpwAcy3XHpMXUaYiTX1wQFl d9/T7Ayvli2bQxs+hNKvYvJgwGMxDS4yoseyJgKFZAtmmLY+qEqU54wgBOFro8CoPz+hQtfGZx9 m9I6cpbVkuW2azRLpfdiXq0VaWyyZGgcUdWthSxap4hPAHQNhGyc7nYhqksa8QJgrCLN+r/Fovo aK0sAF0It8KtAz8Ol6JNHThtvRcy1Ryd05Qkw9O3TmR3gqkO615XYlZhGt80ljSrvtsPd0OHKiX Klvv8NkAstw0e4BFYdweyWlwdhUReg6lmw= X-Received: by 2002:a05:6000:2911:b0:47e:5c6c:bdd5 with SMTP id ffacd0b85a97d-47f4fc998a1mr3336281f8f.6.1784123820192; Wed, 15 Jul 2026 06:57:00 -0700 (PDT) Received: from lb03189.fkb.profitbricks.net ([212.227.34.98]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f4635a935sm16404864f8f.11.2026.07.15.06.56.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 15 Jul 2026 06:56:59 -0700 (PDT) From: Md Haris Iqbal To: Sathya Prakash , Sreekanth Reddy , Suganath Prabu Subramani , Ranjan Kumar Cc: MPT-FusionLinux.pdl@broadcom.com, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, Md Haris Iqbal Subject: [PATCH] scsi: mpt3sas: don't post task management replies to io_uring poll queues Date: Wed, 15 Jul 2026 15:56:42 +0200 Message-ID: <20260715135642.456578-1-haris.iqbal@ionos.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" mpt3sas_scsih_issue_tm() posts a task management (TM) request to the reply queue given by @msix_task. For ABORT_TASK and the broadcast primitive QUERY_TASK/ABORT_TASK paths, @msix_task is the msix_io of the command being managed; for an io_uring polled (RWF_HIPRI) command that is an io_uring poll reply queue (index >=3D ioc->iopoll_q_start_index). io_uring poll queues have no MSI-X interrupt registered and are drained only by mpt3sas_blk_mq_poll(), which the block layer calls to complete polled block I/O. A task management request is not a block layer request, so nothing polls on its behalf: the reply is posted to a queue that is never serviced during the wait, tm_cmds.done is never completed, and the TM times out even though the controller is healthy. The abort then escalates to a controller reset that was not needed. Post TM replies to reply queue 0 whenever the selected reply queue is an io_uring poll queue; reply queue 0 is always interrupt-serviced. When poll queues are disabled, iopoll_q_start_index equals reply_queue_count, so the check is a no-op and behaviour is unchanged. Reachable only when the driver is loaded with poll_queues > 0 and an io_uring polled workload issues I/O that later times out and is aborted. Fixes: 432bc7caef4e ("scsi: mpt3sas: Add io_uring iopoll support") Signed-off-by: Md Haris Iqbal --- Found by code inspection while auditing the task-management reply path. Posting for review of the analysis. drivers/scsi/mpt3sas/mpt3sas_scsih.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/scsi/mpt3sas/mpt3sas_scsih.c b/drivers/scsi/mpt3sas/mp= t3sas_scsih.c index 12caffeed3a0..572ec1787e10 100644 --- a/drivers/scsi/mpt3sas/mpt3sas_scsih.c +++ b/drivers/scsi/mpt3sas/mpt3sas_scsih.c @@ -3186,6 +3186,16 @@ mpt3sas_scsih_issue_tm(struct MPT3SAS_ADAPTER *ioc, = u16 handle, uint channel, int_to_scsilun(lun, (struct scsi_lun *)mpi_request->LUN); mpt3sas_scsih_set_tm_flag(ioc, handle); init_completion(&ioc->tm_cmds.done); + /* + * A task management reply must be posted to an interrupt-serviced + * reply queue. If the associated command was submitted on an io_uring + * poll queue, that queue has no MSI-X interrupt and is drained only by + * mpt3sas_blk_mq_poll(); a task management request is not a block layer + * request, so nothing would process its reply and the command would + * time out. Fall back to reply queue 0 in that case. + */ + if (msix_task >=3D ioc->iopoll_q_start_index) + msix_task =3D 0; ioc->put_smid_hi_priority(ioc, smid, msix_task); wait_for_completion_timeout(&ioc->tm_cmds.done, timeout*HZ); if (!(ioc->tm_cmds.status & MPT3_CMD_COMPLETE)) { --=20 2.43.0