[openib-general][patch review] srp: fmr implementation,

Roland Dreier rdreier at cisco.com
Thu Apr 13 13:51:46 PDT 2006


Hmm, it's clearly a use-after-free bug.  Based on

    ip is at srp_reconnect_target+0x2b1/0x5c0 [ib_srp]

can you guess where it is in the SRP driver or what it's accessing?

Also this is happening because the connection is being reconnected,
because SCSI commands are timing out.  Do you have any idea why this
is happening?  What does the target see when this happens?

 - R.



More information about the general mailing list