forked from Minki/linux
3c3751f2da
When target side trace in turned on and flush command is issued from the host it results in the following Oops. [ 856.789724] BUG: kernel NULL pointer dereference, address: 0000000000000068 [ 856.790686] #PF: supervisor read access in kernel mode [ 856.791262] #PF: error_code(0x0000) - not-present page [ 856.791863] PGD 6d7110067 P4D 6d7110067 PUD 66f0ad067 PMD 0 [ 856.792527] Oops: 0000 [#1] SMP NOPTI [ 856.792950] CPU: 15 PID: 7034 Comm: nvme Tainted: G OE 5.9.0nvme-5.9+ #71 [ 856.793790] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.0-59-gc9ba5276e3214 [ 856.794956] RIP: 0010:trace_event_raw_event_nvmet_req_init+0x13e/0x170 [nvmet] [ 856.795734] Code: 41 5c 41 5d c3 31 d2 31 f6 e8 4e 9b b8 e0 e9 0e ff ff ff 49 8b 55 00 48 8b 38 8b 0 [ 856.797740] RSP: 0018:ffffc90001be3a60 EFLAGS: 00010246 [ 856.798375] RAX: 0000000000000000 RBX: ffff8887e7d2c01c RCX: 0000000000000000 [ 856.799234] RDX: 0000000000000020 RSI: 0000000057e70ea2 RDI: ffff8887e7d2c034 [ 856.800088] RBP: ffff88869f710578 R08: ffff888807500d40 R09: 00000000fffffffe [ 856.800951] R10: 0000000064c66670 R11: 00000000ef955201 R12: ffff8887e7d2c034 [ 856.801807] R13: ffff88869f7105c8 R14: 0000000000000040 R15: ffff88869f710440 [ 856.802667] FS: 00007f6a22bd8780(0000) GS:ffff888813a00000(0000) knlGS:0000000000000000 [ 856.803635] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 856.804367] CR2: 0000000000000068 CR3: 00000006d73e0000 CR4: 00000000003506e0 [ 856.805283] Call Trace: [ 856.805613] nvmet_req_init+0x27c/0x480 [nvmet] [ 856.806200] nvme_loop_queue_rq+0xcb/0x1d0 [nvme_loop] [ 856.806862] blk_mq_dispatch_rq_list+0x123/0x7b0 [ 856.807459] ? kvm_sched_clock_read+0x14/0x30 [ 856.808025] __blk_mq_sched_dispatch_requests+0xc7/0x170 [ 856.808708] blk_mq_sched_dispatch_requests+0x30/0x60 [ 856.809372] __blk_mq_run_hw_queue+0x70/0x100 [ 856.809935] __blk_mq_delay_run_hw_queue+0x156/0x170 [ 856.810574] blk_mq_run_hw_queue+0x86/0xe0 [ 856.811104] blk_mq_sched_insert_request+0xef/0x160 [ 856.811733] blk_execute_rq+0x69/0xc0 [ 856.812212] ? blk_mq_rq_ctx_init+0xd0/0x230 [ 856.812784] nvme_execute_passthru_rq+0x57/0x130 [nvme_core] [ 856.813461] nvme_submit_user_cmd+0xeb/0x300 [nvme_core] [ 856.814099] nvme_user_cmd.isra.82+0x11e/0x1a0 [nvme_core] [ 856.814752] blkdev_ioctl+0x1dc/0x2c0 [ 856.815197] block_ioctl+0x3f/0x50 [ 856.815606] __x64_sys_ioctl+0x84/0xc0 [ 856.816074] do_syscall_64+0x33/0x40 [ 856.816533] entry_SYSCALL_64_after_hwframe+0x44/0xa9 [ 856.817168] RIP: 0033:0x7f6a222ed107 [ 856.817617] Code: 44 00 00 48 8b 05 81 cd 2c 00 64 c7 00 26 00 00 00 48 c7 c0 ff ff ff ff c3 66 2e 8 [ 856.819901] RSP: 002b:00007ffca848f058 EFLAGS: 00000202 ORIG_RAX: 0000000000000010 [ 856.820846] RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007f6a222ed107 [ 856.821726] RDX: 00007ffca848f060 RSI: 00000000c0484e43 RDI: 0000000000000003 [ 856.822603] RBP: 0000000000000003 R08: 000000000000003f R09: 0000000000000005 [ 856.823478] R10: 00007ffca848ece0 R11: 0000000000000202 R12: 00007ffca84912d3 [ 856.824359] R13: 00007ffca848f4d0 R14: 0000000000000002 R15: 000000000067e900 [ 856.825236] Modules linked in: nvme_loop(OE) nvmet(OE) nvme_fabrics(OE) null_blk nvme(OE) nvme_corel Move the nvmet_req_init() tracepoint after we parse the command in nvmet_req_init() so that we can get rid of the duplicate nvmet_find_namespace() call. Rename __assign_disk_name() -> __assign_req_name(). Now that we call tracepoint after parsing the command simplify the newly added __assign_req_name() which fixes this bug. Signed-off-by: Chaitanya Kulkarni <chaitanya.kulkarni@wdc.com> Signed-off-by: Christoph Hellwig <hch@lst.de>
163 lines
4.5 KiB
C
163 lines
4.5 KiB
C
/* SPDX-License-Identifier: GPL-2.0 */
|
|
/*
|
|
* NVM Express target device driver tracepoints
|
|
* Copyright (c) 2018 Johannes Thumshirn, SUSE Linux GmbH
|
|
*
|
|
* This is entirely based on drivers/nvme/host/trace.h
|
|
*/
|
|
|
|
#undef TRACE_SYSTEM
|
|
#define TRACE_SYSTEM nvmet
|
|
|
|
#if !defined(_TRACE_NVMET_H) || defined(TRACE_HEADER_MULTI_READ)
|
|
#define _TRACE_NVMET_H
|
|
|
|
#include <linux/nvme.h>
|
|
#include <linux/tracepoint.h>
|
|
#include <linux/trace_seq.h>
|
|
|
|
#include "nvmet.h"
|
|
|
|
const char *nvmet_trace_parse_admin_cmd(struct trace_seq *p, u8 opcode,
|
|
u8 *cdw10);
|
|
const char *nvmet_trace_parse_nvm_cmd(struct trace_seq *p, u8 opcode,
|
|
u8 *cdw10);
|
|
const char *nvmet_trace_parse_fabrics_cmd(struct trace_seq *p, u8 fctype,
|
|
u8 *spc);
|
|
|
|
#define parse_nvme_cmd(qid, opcode, fctype, cdw10) \
|
|
((opcode) == nvme_fabrics_command ? \
|
|
nvmet_trace_parse_fabrics_cmd(p, fctype, cdw10) : \
|
|
(qid ? \
|
|
nvmet_trace_parse_nvm_cmd(p, opcode, cdw10) : \
|
|
nvmet_trace_parse_admin_cmd(p, opcode, cdw10)))
|
|
|
|
const char *nvmet_trace_ctrl_name(struct trace_seq *p, struct nvmet_ctrl *ctrl);
|
|
#define __print_ctrl_name(ctrl) \
|
|
nvmet_trace_ctrl_name(p, ctrl)
|
|
|
|
const char *nvmet_trace_disk_name(struct trace_seq *p, char *name);
|
|
#define __print_disk_name(name) \
|
|
nvmet_trace_disk_name(p, name)
|
|
|
|
#ifndef TRACE_HEADER_MULTI_READ
|
|
static inline struct nvmet_ctrl *nvmet_req_to_ctrl(struct nvmet_req *req)
|
|
{
|
|
return req->sq->ctrl;
|
|
}
|
|
|
|
static inline void __assign_req_name(char *name, struct nvmet_req *req)
|
|
{
|
|
if (req->ns)
|
|
strncpy(name, req->ns->device_path, DISK_NAME_LEN);
|
|
else
|
|
memset(name, 0, DISK_NAME_LEN);
|
|
}
|
|
#endif
|
|
|
|
TRACE_EVENT(nvmet_req_init,
|
|
TP_PROTO(struct nvmet_req *req, struct nvme_command *cmd),
|
|
TP_ARGS(req, cmd),
|
|
TP_STRUCT__entry(
|
|
__field(struct nvme_command *, cmd)
|
|
__field(struct nvmet_ctrl *, ctrl)
|
|
__array(char, disk, DISK_NAME_LEN)
|
|
__field(int, qid)
|
|
__field(u16, cid)
|
|
__field(u8, opcode)
|
|
__field(u8, fctype)
|
|
__field(u8, flags)
|
|
__field(u32, nsid)
|
|
__field(u64, metadata)
|
|
__array(u8, cdw10, 24)
|
|
),
|
|
TP_fast_assign(
|
|
__entry->cmd = cmd;
|
|
__entry->ctrl = nvmet_req_to_ctrl(req);
|
|
__assign_req_name(__entry->disk, req);
|
|
__entry->qid = req->sq->qid;
|
|
__entry->cid = cmd->common.command_id;
|
|
__entry->opcode = cmd->common.opcode;
|
|
__entry->fctype = cmd->fabrics.fctype;
|
|
__entry->flags = cmd->common.flags;
|
|
__entry->nsid = le32_to_cpu(cmd->common.nsid);
|
|
__entry->metadata = le64_to_cpu(cmd->common.metadata);
|
|
memcpy(__entry->cdw10, &cmd->common.cdw10,
|
|
sizeof(__entry->cdw10));
|
|
),
|
|
TP_printk("nvmet%s: %sqid=%d, cmdid=%u, nsid=%u, flags=%#x, "
|
|
"meta=%#llx, cmd=(%s, %s)",
|
|
__print_ctrl_name(__entry->ctrl),
|
|
__print_disk_name(__entry->disk),
|
|
__entry->qid, __entry->cid, __entry->nsid,
|
|
__entry->flags, __entry->metadata,
|
|
show_opcode_name(__entry->qid, __entry->opcode,
|
|
__entry->fctype),
|
|
parse_nvme_cmd(__entry->qid, __entry->opcode,
|
|
__entry->fctype, __entry->cdw10))
|
|
);
|
|
|
|
TRACE_EVENT(nvmet_req_complete,
|
|
TP_PROTO(struct nvmet_req *req),
|
|
TP_ARGS(req),
|
|
TP_STRUCT__entry(
|
|
__field(struct nvmet_ctrl *, ctrl)
|
|
__array(char, disk, DISK_NAME_LEN)
|
|
__field(int, qid)
|
|
__field(int, cid)
|
|
__field(u64, result)
|
|
__field(u16, status)
|
|
),
|
|
TP_fast_assign(
|
|
__entry->ctrl = nvmet_req_to_ctrl(req);
|
|
__entry->qid = req->cq->qid;
|
|
__entry->cid = req->cqe->command_id;
|
|
__entry->result = le64_to_cpu(req->cqe->result.u64);
|
|
__entry->status = le16_to_cpu(req->cqe->status) >> 1;
|
|
__assign_req_name(__entry->disk, req);
|
|
),
|
|
TP_printk("nvmet%s: %sqid=%d, cmdid=%u, res=%#llx, status=%#x",
|
|
__print_ctrl_name(__entry->ctrl),
|
|
__print_disk_name(__entry->disk),
|
|
__entry->qid, __entry->cid, __entry->result, __entry->status)
|
|
|
|
);
|
|
|
|
#define aer_name(aer) { aer, #aer }
|
|
|
|
TRACE_EVENT(nvmet_async_event,
|
|
TP_PROTO(struct nvmet_ctrl *ctrl, __le32 result),
|
|
TP_ARGS(ctrl, result),
|
|
TP_STRUCT__entry(
|
|
__field(int, ctrl_id)
|
|
__field(u32, result)
|
|
),
|
|
TP_fast_assign(
|
|
__entry->ctrl_id = ctrl->cntlid;
|
|
__entry->result = (le32_to_cpu(result) & 0xff00) >> 8;
|
|
),
|
|
TP_printk("nvmet%d: NVME_AEN=%#08x [%s]",
|
|
__entry->ctrl_id, __entry->result,
|
|
__print_symbolic(__entry->result,
|
|
aer_name(NVME_AER_NOTICE_NS_CHANGED),
|
|
aer_name(NVME_AER_NOTICE_ANA),
|
|
aer_name(NVME_AER_NOTICE_FW_ACT_STARTING),
|
|
aer_name(NVME_AER_NOTICE_DISC_CHANGED),
|
|
aer_name(NVME_AER_ERROR),
|
|
aer_name(NVME_AER_SMART),
|
|
aer_name(NVME_AER_CSS),
|
|
aer_name(NVME_AER_VS))
|
|
)
|
|
);
|
|
#undef aer_name
|
|
|
|
#endif /* _TRACE_NVMET_H */
|
|
|
|
#undef TRACE_INCLUDE_PATH
|
|
#define TRACE_INCLUDE_PATH .
|
|
#undef TRACE_INCLUDE_FILE
|
|
#define TRACE_INCLUDE_FILE trace
|
|
|
|
/* This part must be outside protection */
|
|
#include <trace/define_trace.h>
|