From nobody Thu Sep 24 21:48:42 2026 Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6DA2927603F for ; Sat, 19 Sep 2026 17:34:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789839292; cv=none; b=TdfSiIb5FEuVRQ5KmadJeNguGICDVAOnkKqLPfzA0+6tdqkO5tvaMIpWRM7Avjp/Gv1J9BKzVbtpoFT4gDKUpCXmxKdz8CH2Nq26kwHTAlK7JSMMoSpfcdPWpCTMFkW5VuCaDwV0TAFVKuzYpQLy4Fz9TPpKPqxLn3i3Bcve7HM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789839292; c=relaxed/simple; bh=tXPMv/Z528AzLwHoqZJSLZNkBxU0ltXfHPgB+kUGM0I=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=TKYBMJL6BSXFS7pg8YPGStFDpZAoxVJhyTDCMNno6naEqApJzqXWh5oGvWt7Iyuk/luqV9V0v2qSO0KDm8G5aYQpAArdrTqEIZ0ZTw+s35sQ3agTURAm/ZbWla8divv69a2NSon2GTXgZVkmWfOJK2Wzo2zwC4lPXb3g4/++KkM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aCoFo3lF; arc=none smtp.client-ip=74.125.227.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aCoFo3lF" Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-39b5b07ec78so1228145a91.3 for ; Sat, 19 Sep 2026 10:34:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789839291; x=1790444091; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=E3sjbzhb8LLlJu3Xq4nSK1HUp2gy9IN+rCu4DEVUfQU=; b=aCoFo3lFTKMrg7PIcA1ejGDI13I3vmHJBmZnC8El2K/sCTwSTghub9PQNrVm3hIzPH zE91qUQTHGt+8hP1wjX0wJ6p02E6neQ4IActu8nvkh50uU44QbP7FN3ApDSpIDUH5QgJ n8ReyfqBrdL0GMSrmXp4my3nW6LGdKXxuXC2ttTnT8VD9B1dCEHXj4cpGxW7XFZnfz/O kIMAr9bqHrz1WQ0sy0//sk/uumvk0YjDluST7jUh95HELb/m4lTa0UGAUrqG81uoVlHe BJtDY8BbuSBo9aL1o80wIQLCeEkVbUNc0MvIhuMmAGR467maNOrQk3JeFPL8osGhgGYw 08TA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789839291; x=1790444091; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=E3sjbzhb8LLlJu3Xq4nSK1HUp2gy9IN+rCu4DEVUfQU=; b=AjBrtq6qNaAS0YoocX1wW9OizlcgN03QC7Nki46Xaayw43j4N6cQX7IYIXefsrDKWt eMoPcR2+mx4V5mQpo351ot9yKdfHE2cvrLRhEE5J61++qly3PpjNCkTpHuE6qYvlgCDg PyGtAkd1tUIt8nms6hEpAp0YgyCxFByGIeLvjL/7WyDE8tbnAqGO9ImosljYRtIm6yDD Yeo+/ZVvvc8OOBW4cn8UZjmxynaO3otl6TpTDU4RIDY2laea4/m/K8FK6R3N1vfgPBFs V9jnw+He5sPYBv7V7cw6URh0qTmnxXGZyHzNY1sm0D5P6tWHDJ0gqIwdl6k1oS79higQ SEbA== X-Forwarded-Encrypted: i=1; AKwUvBxCeNZwVLxraKXPT1rd6EVMTQ/a0OhRW8NvpODa62T4nQIajmHANt6hmOkpLvYyJoyarNIedP6wN8Ffr0M=@vger.kernel.org X-Gm-Message-State: AFuF++lfnAGvltZfcxDC0B8udMz+fXJhrbW1fmphj2K5VcQbKDnsowel yKnppNhoDKYltNyOsdk7KHgTgbZ9Raa3F5cnu7jlM0Uav0We36rdR221 X-Gm-Gg: AYBFou0yEZHvgnRH/hZHtVwWM7S5Llh1WnDYxihoYKwcd4f4QqpewdvJ1S0Ff5TjVm8 kFa7MeB+f0UQlZJXMs/0E2zIHtUNB91OYNH79QI7PoKF7fKuTCW+EaNXf5LI9nhHL0auXIXhQlE DAjb+phmzmm+hMFazSQouhTV8Xzu/vyTABmPp2BbcpMkXvwWTad+FTZhlovFeW82WVlYPPjtOBn Ba/7POmsSuF+BP9J35U6+81esp1kTgrtxc5+ZNMPr/82q1Y+nLiCKFS/A3bswCU3x1v1lIyccVX L30d+NVSmzAFChVPkGJFbNy3Vx48YxgYEW7Tce5+UnJXgF4DiXswEsSZv7K68vSorkJxH9iQfEy a44YP2r2JHsCEVBGKkNnYsBkzfNnMdJc/grpk8FxImshuyGmhraZVTtbbbojYkDJvxAqmf8uuti suDVpMuVI6UUfvGVl5cj6Cu3u3DHxy2RYWMEZI8my35K8cgyVlxVo+rQ== X-Received: by 2002:a17:90b:1dce:b0:39e:6a80:dda3 with SMTP id 98e67ed59e1d1-39e6a810c76mr4792250a91.42.1789839290805; Sat, 19 Sep 2026 10:34:50 -0700 (PDT) Received: from lgs.. ([2001:250:5800:1002::de93]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a026898b76sm3234229a91.16.2026.09.19.10.34.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 19 Sep 2026 10:34:50 -0700 (PDT) From: Guangshuo Li To: Hannes Reinecke , "James E.J. Bottomley" , "Martin K. Petersen" , Robert Love , James Bottomley , Joe Eykholt , linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Guangshuo Li , stable@vger.kernel.org Subject: [PATCH] scsi: libfc: fix directory server rport memory leak Date: Sun, 20 Sep 2026 01:34:05 +0800 Message-ID: <20260919173405.3718408-1-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" fc_rport_recv_plogi_req() creates an rport before allocating the frame used for the PLOGI LS_ACC response. fc_rport_create() does not add FC_FID_DIR_SERV rports to the discovery rport list. If fc_frame_alloc() fails while handling a PLOGI from the directory server, the function returns without starting the rport state machine or dropping the initial rport reference. Since the directory server rport is not present in the discovery list, there is no later teardown path that can find the object and release that reference. The allocated fc_rport_priv is therefore leaked. Record when the failed frame allocation leaves an unlisted directory server rport behind and drop its initial reference after releasing the rport mutex. Keep the existing lifetime unchanged for ordinary rports, which remain owned by the discovery list. The issue was identified by a static analysis tool I developed and confirmed by manual review. Fixes: 3ac6f98f4113 ("[SCSI] libfc: correctly handle incoming PLOGI request= .") Cc: stable@vger.kernel.org Signed-off-by: Guangshuo Li --- drivers/scsi/libfc/fc_rport.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/scsi/libfc/fc_rport.c b/drivers/scsi/libfc/fc_rport.c index c25979d96808..884b233c2f72 100644 --- a/drivers/scsi/libfc/fc_rport.c +++ b/drivers/scsi/libfc/fc_rport.c @@ -1848,6 +1848,7 @@ static void fc_rport_recv_plogi_req(struct fc_lport *= lport, struct fc_els_flogi *pl; struct fc_seq_els_data rjt_data; u32 sid; + bool drop_rdata =3D false; =20 lockdep_assert_held(&lport->lp_mutex); =20 @@ -1940,8 +1941,10 @@ static void fc_rport_recv_plogi_req(struct fc_lport = *lport, * Send LS_ACC. If this fails, the originator should retry. */ fp =3D fc_frame_alloc(lport, sizeof(*pl)); - if (!fp) + if (!fp) { + drop_rdata =3D sid =3D=3D FC_FID_DIR_SERV; goto out; + } =20 fc_plogi_fill(lport, fp, ELS_LS_ACC); fc_fill_reply_hdr(fp, rx_fp, FC_RCTL_ELS_REP, 0); @@ -1949,6 +1952,8 @@ static void fc_rport_recv_plogi_req(struct fc_lport *= lport, fc_rport_enter_prli(rdata); out: mutex_unlock(&rdata->rp_mutex); + if (drop_rdata) + kref_put(&rdata->kref, fc_rport_destroy); fc_frame_free(rx_fp); return; =20 --=20 2.43.0