From: Dongliang Qin <cccccccccccc777777@gmail.com>
To: Zhu Yanjun <zyjzyj2000@gmail.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Leon Romanovsky <leon@kernel.org>
Cc: Dongliang Qin <cccccccccccc777777@gmail.com>,
linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org,
Bob Pearson <rpearsonhpe@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH 0/4] RDMA/rxe: Fix MW/MR lifetime races
Date: Mon, 28 Sep 2026 23:53:47 +0800 [thread overview]
Message-ID: <20260928155351.3222978-1-cccccccccccc777777@gmail.com> (raw)
Soft-RoCE keeps MW-to-MR bindings and type-2 MW-to-QP references across
verbs operations and responder packets. Several paths currently assume
those references remain stable without taking the MW lock or reserving
the MR state. As a result, the responder can acquire a zero reference,
a bind can race with MR invalidation or deregistration, a type-2 MW can
outlive its QP, or the pool can force-free an object with outstanding
references. An unprivileged user with access to an RXe device can use these
races to corrupt kernel memory and escalate privileges.
This series fixes those races with four focused, individually
revertible changes:
1. Move MW lookup, validation, and MR reference acquisition under
mw->lock.
2. Use num_mw as an atomic state reservation while an MR changes state.
3. Invalidate type-2 MWs bound to a QP before destroying that QP.
4. Stop force-freeing sleepable pool objects after a timeout.
Patch 4 is hardening: it prevents pool cleanup from turning an outstanding
reference into a use-after-free, rather than fixing the reported bind and
deregistration race directly.
Before the fix, a concurrent MW bind and MR deregistration reproducer made
KASAN report a slab use-after-free in rxe_mr_copy() from rxe_receiver() on
the RXe responder workqueue. With this series, the same 120-second test no
longer triggers KASAN. MW READ, WRITE, partial READ, invalidate, and rebind
still pass.
Dongliang Qin (4):
RDMA/rxe: Take MR reference under MW lock
RDMA/rxe: Reserve MR state during MW binding
RDMA/rxe: Invalidate MWs on QP destroy
RDMA/rxe: Do not force cleanup on pool timeout
drivers/infiniband/sw/rxe/rxe_loc.h | 8 ++-
drivers/infiniband/sw/rxe/rxe_mr.c | 70 +++++++++++++++++--
drivers/infiniband/sw/rxe/rxe_mw.c | 99 +++++++++++++++++++--------
drivers/infiniband/sw/rxe/rxe_pool.c | 14 +---
drivers/infiniband/sw/rxe/rxe_resp.c | 38 +---------
drivers/infiniband/sw/rxe/rxe_verbs.c | 15 +++-
6 files changed, 159 insertions(+), 85 deletions(-)
base-commit: 93f51579e7df2
--
2.43.0
next reply other threads:[~2026-09-28 15:53 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 15:53 Dongliang Qin [this message]
2026-09-28 15:53 ` [PATCH 1/4] RDMA/rxe: Take MR reference under MW lock Dongliang Qin
2026-09-28 15:53 ` [PATCH 2/4] RDMA/rxe: Reserve MR state during MW binding Dongliang Qin
2026-09-28 15:53 ` [PATCH 3/4] RDMA/rxe: Invalidate MWs on QP destroy Dongliang Qin
2026-09-28 15:53 ` [PATCH 4/4] RDMA/rxe: Do not force cleanup on pool timeout Dongliang Qin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928155351.3222978-1-cccccccccccc777777@gmail.com \
--to=cccccccccccc777777@gmail.com \
--cc=jgg@ziepe.ca \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=rpearsonhpe@gmail.com \
--cc=stable@vger.kernel.org \
--cc=zyjzyj2000@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®