Re: [PATCH v3 0/2] scsi: ufs: core: Fix unsafe MMIO reads and redundant CQ sweeps in MCQ reset
From: Martin K. Petersen (Oracle)
Date: Mon Oct 05 2026 - 22:45:21 EST
On Mon, 28 Sep 2026 11:58:14 +0800, Stanley Jhu wrote:
> During Multi-Circular Queue (MCQ) error recovery and host reset,
> ufshcd_mcq_compl_pending_transfer() sweeps or polls completion queues to
> reap pending transfers. Two bugs exist in this path:
>
> 1. Unsafe MMIO read and spurious errors while HCE = 0 (Patch 1/2):
> ufshcd_host_reset_and_restore() stops the controller (HCE = 0) before
> calling ufshcd_mcq_compl_all_cqes_lock(). Calling
> ufshcd_mcq_update_cq_tail_slot() at the end of the sweep reads CQTPy
> over MMIO while HCE = 0, directly contradicting the function's own
> documented contract that reading host controller registers may not be
> safe when the controller is disabled. In addition, passing expected
> empty slots during a full-ring sweep into ufshcd_mcq_process_cqe()
> prints spurious "Abnormal CQ entry!" errors.
>
> [...]
Applied to 7.3/scsi-fixes, thanks!
[1/2] scsi: ufs: core: Avoid unsafe MMIO reads in ufshcd_mcq_compl_all_cqes_lock()
https://git.kernel.org/mkp/scsi/c/375f3a5691dd
[2/2] scsi: ufs: core: Decouple CQ sweep from request iterator in MCQ
https://git.kernel.org/mkp/scsi/c/469fa055664b
--
Martin K. Petersen