From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f170.google.com (mail-qt1-f170.google.com [209.85.160.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D9F9F3DE450 for ; Tue, 26 May 2026 12:23:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779798213; cv=none; b=TtfNZJ9kS9pvbHcniCEp8T/w5X0dWJ6QTOUb6VtVcYPgXmwy/9VmtpEe385l3AH2O83HmARzpqgAa0xaGdgHsqlPiYljtQ3+HcizdhQhYODlL5z/2+JNEF7bDVpPlAka/aCWd1DGLbjrNSHnTeeorTC72aMNV7kIVophH1bqoiM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779798213; c=relaxed/simple; bh=qHzTBhBuiiRVcIIH5BT2JepEYDzlIvlJbPiwlXdsMHQ=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=j85u1eL0VwK3GkXc9fgJ2aKpG/WRw6XF0/Xz+OvpbHYMvRkUA7O61RBTvRb276wybwllkhN/xQJfginloCbb6zl6nJuaBAwwAZL0OHHPG0SZ3QchyabyBsL8dWKui668U0neEAqzufQntWGn07csA3oZgGCcdya1agpTnYhuapM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=N2jPbej0; arc=none smtp.client-ip=209.85.160.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="N2jPbej0" Received: by mail-qt1-f170.google.com with SMTP id d75a77b69052e-50e63771eb0so105059611cf.3 for ; Tue, 26 May 2026 05:23:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1779798211; x=1780403011; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=nOvLEHi8YfJgqS+zaJD3Y3WESLiMuTb2mTPvxBI5ndM=; b=N2jPbej0cSo/qsyh+xPJV6N0GTN6oqcwYe7cIDtGIhPUNxSSK/WL8FHOMFfqp3JLF9 061P3ItFMCJ8A5LqDG5P9SP/Wyjbd+HsEGX1ya4qWwJQj4Uuotwt/yqiAXA09ul5zQT4 5rgdJqqO43TlZt+ARKRvaRgi3jMesWETV1Y9P269H3rsJYTC69QgKu9yD2vLVjo5hMeX CIv43bPCe5BYUxbY5G569SFaCyYRmTBUISJN+XR9GRvBrH+DTU5W7fyej5Uraaej+qN2 pH4lW7gpr18BkUUjppyVRom4qfL4psTnwmou8Bw6Zhub8q1Xd8Wbn8VkcEi2qRsdPXBJ tWIw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779798211; x=1780403011; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nOvLEHi8YfJgqS+zaJD3Y3WESLiMuTb2mTPvxBI5ndM=; b=PfqBKGI4lxbza9y3mXasRiNoxPLeNqaCO7z3kyLZumY10iDTKy7AAAxlKlYtAHmDAl oFzx+eCxQB4qQp42ASdYmMK/O32Efzzb7rFE2F/RnfPNkzNeQzoB1FbzeW1gG6IMofWD Y8nx65N7uw8R4cdN4+Qkb9c/pbX7qQXd2WBusmsrNCg3uZ2ZaJYqvJv5+HK1jddD1cRM 0nyFinMlKs9zHBgKJe8c7m44tHQ071CyfzI7vAMcrfUuiy+b//dUWBnTjud2YdmSlcP+ WwbIkctX9ir9hBsb8dLPSCqdfP/G1ysBMwWdML5+DebwXeUWr1ym4tAJmC93xj/7Qye3 65pQ== X-Forwarded-Encrypted: i=1; AFNElJ/M++JLiINGFBPkTAwQHRBt4GSjFHje2I+4p56p5OyI82RgJz48ADLu/2WxtGq/pfO+ssaiYJZCBDosLXo=@vger.kernel.org X-Gm-Message-State: AOJu0YzHo25qLgtDXw3BSAU3xVhrcEiwvMI79FJ/w5VUGW2AuiYO89EV roZFf0MquPtrgAkQk+rTT0a1qYzwzMLTZxBeywc7qZH4Iigb0XFv9pDsNwetrpz9st8= X-Gm-Gg: Acq92OHZ+goj8X02qDbBg2w4miAObGmnmxTMoNujb+8bDrgvuKSsXQ31UYHBTLnrThv QiXZcvBM4sIJ+aw9K6t4IzVHVPlAi6519cn+IL+wt202CSlYtp40+ASqUy1a06QnMuiAGhc8aiP pr9ew6gkk510Pl6bwQlpmTxYV6EtR/JBEiCfVxwOydbOBnPIgAbXKuMqS09ItN/HRm5puPRCEVj xitxJRnnWHLoR0jT5ZL44AlYglWzlwS5GbH3JnuZLjeOQVCxaqH5Z5EIX2SpB/AUWUr8xp4wjVz 7gSrQ+vK7tMyBnFJsF49nsGZHUQZiywhwV9XQGqyS1Lhyn63UsQwUKQEfwvxhUGssLmRz7GtyXD I1iV9b8seELLeUbeYTg9+KeevpYDHpDxb9AVwrsAp2RgJM17hs692450INY1qci0nRBhiujvzms OhEukVWnmsVFLE+9drFaQCRudN0ZGTvMhz8kBAI6aNInyzM6a+y3yrW1L/7FwWQNUiz/ztM8tt+ F2ipPnj3wrMk9+u X-Received: by 2002:a05:620a:298f:b0:911:fba0:6d0f with SMTP id af79cd13be357-914b49ddae1mr1408362285a.41.1779798210531; Tue, 26 May 2026 05:23:30 -0700 (PDT) Received: from ziepe.ca (crbknf0213w-47-54-130-67.pppoe-dynamic.high-speed.nl.bellaliant.net. [47.54.130.67]) by smtp.gmail.com with ESMTPSA id af79cd13be357-914f87cda12sm190384885a.31.2026.05.26.05.23.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 26 May 2026 05:23:30 -0700 (PDT) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1wRqoj-0000000DOAT-1tj1; Tue, 26 May 2026 09:23:29 -0300 Date: Tue, 26 May 2026 09:23:29 -0300 From: Jason Gunthorpe To: luoqing Cc: Leon Romanovsky , Kees Cook , Mark Zhang , luoqing , linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] rdma: infiniband: Added __alloc_cq request value Return value non-zero value determination Message-ID: <20260526122329.GC2487554@ziepe.ca> References: <20260526091816.1873077-1-l1138897701@163.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260526091816.1873077-1-l1138897701@163.com> On Tue, May 26, 2026 at 05:18:16PM +0800, luoqing wrote: > From: luoqing > > Currently, when __alloc_cq allocates memory for an InfiniBand Completion Queue (ib_cq) object, > it uses memory allocation functions that may not guarantee zero-initialization under certain error paths or memory pressure conditions. > If the allocated ib_cq object contains non-zero garbage data due to incomplete initialization, > the function may return a non-NULL pointer even though the object is not in a valid state. This can lead to undefined behavior, > memory corruption, and potential kernel crashes when the driver subsequently accesses uninitialized fields. > > This patch adds explicit validation to ensure that the allocated ib_cq object is properly zeroed before being considered valid. > If the object fails the zero-check (i.e., contains non-zero bytes beyond expected initialized fields), > the function returns an error code (e.g., -ENOMEM or -EINVAL), logs a warning message, and prevents further usage of the corrupted CQ. > > Signed-off-by: luoqing > --- > drivers/infiniband/core/cq.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/infiniband/core/cq.c b/drivers/infiniband/core/cq.c > index 3d7b6cddd131..756bc33c850d 100644 > --- a/drivers/infiniband/core/cq.c > +++ b/drivers/infiniband/core/cq.c > @@ -224,7 +224,7 @@ struct ib_cq *__ib_alloc_cq(struct ib_device *dev, void *private, int nr_cqe, > return ERR_PTR(-EINVAL); > > cq = rdma_zalloc_drv_obj(dev, ib_cq); > - if (!cq) > + if (unlikely(ZERO_OR_NULL_PTR(cq))) > return ERR_PTR(ret); Wow, this entire report is unintelligible. ZERO_OR_NULL_PTR() has nothing to do with the memory contents. Jason