Commit bbc050488525e1ab1194c27355f63c66814385b8

Authored by Nicholas Bellinger
1 parent a95d651130

iscsi-target: Fix ABORT_TASK + connection reset iscsi_queue_req memory leak

This patch fixes a iscsi_queue_req memory leak when ABORT_TASK response
has been queued by TFO->queue_tm_rsp() -> lio_queue_tm_rsp() after a
long standing I/O completes, but the connection has already reset and
waiting for cleanup to complete in iscsit_release_commands_from_conn()
-> transport_generic_free_cmd() -> transport_wait_for_tasks() code.

It moves iscsit_free_queue_reqs_for_conn() after the per-connection command
list has been released, so that the associated se_cmd tag can be completed +
released by target-core before freeing any remaining iscsi_queue_req memory
for the connection generated by lio_queue_tm_rsp().

Cc: Thomas Glanzmann <thomas@glanzmann.de>
Cc: Charalampos Pournaris <charpour@gmail.com>
Cc: stable@vger.kernel.org # 3.10+
Signed-off-by: Nicholas Bellinger <nab@linux-iscsi.org>

Showing 1 changed file with 1 additions and 2 deletions Side-by-side Diff

drivers/target/iscsi/iscsi_target.c
... ... @@ -4231,8 +4231,6 @@
4231 4231 if (conn->conn_transport->iscsit_wait_conn)
4232 4232 conn->conn_transport->iscsit_wait_conn(conn);
4233 4233  
4234   - iscsit_free_queue_reqs_for_conn(conn);
4235   -
4236 4234 /*
4237 4235 * During Connection recovery drop unacknowledged out of order
4238 4236 * commands for this connection, and prepare the other commands
... ... @@ -4249,6 +4247,7 @@
4249 4247 iscsit_clear_ooo_cmdsns_for_conn(conn);
4250 4248 iscsit_release_commands_from_conn(conn);
4251 4249 }
  4250 + iscsit_free_queue_reqs_for_conn(conn);
4252 4251  
4253 4252 /*
4254 4253 * Handle decrementing session or connection usage count if