mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps
@ 2026-09-27  7:32 Chengfeng Ye
  2026-09-28  5:56 ` Mahanta Jambigi
  0 siblings, 1 reply; 3+ messages in thread
From: Chengfeng Ye @ 2026-09-27  7:32 UTC (permalink / raw)
  To: D. Wythe, Dust Li, Sidraya Jayagond, Mahanta Jambigi, Tony Lu,
	Wen Gu, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Wenjia Zhang
  Cc: linux-rdma, linux-s390, netdev, linux-kernel, Chengfeng Ye, stable

An SMC-D connection can remain in the socket hash while smc_conn_kill()
tears it down. For devices supporting DMB nocopy, smcd_buf_detach() frees
the send buffer descriptor without taking the hash lock held by the
diagnostic reader.

__smc_diag_dump() can load a non-NULL conn->sndbuf_desc, then a concurrent
smc_conn_kill() can clear the pointer and free the descriptor before the
dump reads its len field. The socket lock held by the teardown path does
not exclude the dump, and clearing the pointer before freeing it does
not protect a reader that has already loaded it.

KASAN reported:

  BUG: KASAN: slab-use-after-free in __smc_diag_dump.constprop.0+0x2477/0x2b10
  Call Trace:
   __smc_diag_dump.constprop.0+0x2477/0x2b10
   smc_diag_dump_proto+0x266/0x390
   smc_diag_dump+0x20/0x70
   netlink_dump+0x489/0x1140
  Allocated by task 70:
   smcd_buf_attach+0x11b/0x310
   smc_listen_work+0x2a62/0x4cf0
  Freed by task 98:
   kfree+0x131/0x3c0
   smcd_buf_detach+0x120/0x280
   smc_conn_kill+0x487/0x720
   __smc_lgr_terminate.part.0+0x231/0x430
   smc_smcd_terminate_all+0x2cf/0x610

Take the hash write lock when removing the descriptor from the
connection. This waits for dumps holding the old pointer and prevents
new dumps from seeing it. Free the descriptor after dropping the lock.

Fixes: ae2be35cbed2 ("net/smc: {at|de}tach sndbuf to peer DMB if supported")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
 net/smc/smc_core.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/net/smc/smc_core.c b/net/smc/smc_core.c
index 9974149659c2..f32fc1bd5bc8 100644
--- a/net/smc/smc_core.c
+++ b/net/smc/smc_core.c
@@ -1207,6 +1207,8 @@ static void smcr_buf_unuse(struct smc_buf_desc *buf_desc, bool is_rmb,
 
 static void smcd_buf_detach(struct smc_connection *conn)
 {
+	struct smc_sock *smc = container_of(conn, struct smc_sock, conn);
+	struct smc_hashinfo *h = smc->sk.sk_prot->h.smc_hash;
 	struct smcd_dev *smcd = conn->lgr->smcd;
 	u64 peer_token = conn->peer_token;
 	struct smc_buf_desc *buf_desc;
@@ -1216,8 +1218,10 @@ static void smcd_buf_detach(struct smc_connection *conn)
 
 	smc_ism_detach_dmb(smcd, peer_token);
 
+	write_lock_bh(&h->lock);
 	buf_desc = conn->sndbuf_desc;
 	conn->sndbuf_desc = NULL;
+	write_unlock_bh(&h->lock);
 	kfree(buf_desc);
 }
 
-- 
2.43.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps
  2026-09-27  7:32 [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps Chengfeng Ye
@ 2026-09-28  5:56 ` Mahanta Jambigi
  2026-09-28  6:16   ` Chengfeng Ye
  0 siblings, 1 reply; 3+ messages in thread
From: Mahanta Jambigi @ 2026-09-28  5:56 UTC (permalink / raw)
  To: Chengfeng Ye, D. Wythe, Dust Li, Sidraya Jayagond, Tony Lu,
	Wen Gu, David S. Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Wenjia Zhang
  Cc: linux-rdma, linux-s390, netdev, linux-kernel, stable



On 27/09/26 1:02 pm, Chengfeng Ye wrote:
> An SMC-D connection can remain in the socket hash while smc_conn_kill()
> tears it down. For devices supporting DMB nocopy, smcd_buf_detach() frees
> the send buffer descriptor without taking the hash lock held by the
> diagnostic reader.
> 
> __smc_diag_dump() can load a non-NULL conn->sndbuf_desc, then a concurrent
> smc_conn_kill() can clear the pointer and free the descriptor before the
> dump reads its len field. The socket lock held by the teardown path does
> not exclude the dump, and clearing the pointer before freeing it does
> not protect a reader that has already loaded it.

Agreed. This is addressed in v6[1] by unhashing the socket at the top of
smc_conn_kill(), before smcd_buf_detach() runs, so no hashed socket can
have its sndbuf_desc freed under a concurrent diag reader.

[1]
https://lore.kernel.org/netdev/20260926065023.1629497-1-mjambigi@linux.ibm.com/



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps
  2026-09-28  5:56 ` Mahanta Jambigi
@ 2026-09-28  6:16   ` Chengfeng Ye
  0 siblings, 0 replies; 3+ messages in thread
From: Chengfeng Ye @ 2026-09-28  6:16 UTC (permalink / raw)
  To: Mahanta Jambigi
  Cc: D. Wythe, Dust Li, Sidraya Jayagond, Tony Lu, Wen Gu,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, Wenjia Zhang, linux-rdma, linux-s390, netdev,
	linux-kernel, stable

On Mon, Sep 28, 2026 at 1:57 PM Mahanta Jambigi <mjambigi@linux.ibm.com> wrote:
>
> Agreed. This is addressed in v6[1] by unhashing the socket at the top of
> smc_conn_kill(), before smcd_buf_detach() runs, so no hashed socket can
> have its sndbuf_desc freed under a concurrent diag reader.
>
> [1]
> https://lore.kernel.org/netdev/20260926065023.1629497-1-mjambigi@linux.ibm.com/
>

Hi Mahanta,

Thanks for pointing this out, I didn't notice there was a patch
working on the same problem. Please drop my patch in favour of yours.

Best Regards,
Chengfeng

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28  6:16 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-27  7:32 [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps Chengfeng Ye
2026-09-28  5:56 ` Mahanta Jambigi
2026-09-28  6:16   ` Chengfeng Ye

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®