mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 0/4] RDMA/rxe: Fix MW/MR lifetime races
@ 2026-09-28 17:17 Dongliang Qin
  2026-09-28 17:17 ` [PATCH v2 1/4] RDMA/rxe: Take MR reference under MW lock Dongliang Qin
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Dongliang Qin @ 2026-09-28 17:17 UTC (permalink / raw)
  To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky
  Cc: Dongliang Qin, linux-rdma, linux-kernel, Bob Pearson, stable

Soft-RoCE keeps MW-to-MR bindings and type-2 MW-to-QP references across
verbs operations and responder packets. Several paths currently assume
those references remain stable without taking the MW lock or reserving
the MR state. As a result, the responder can acquire a zero reference,
a bind can race with MR invalidation or deregistration, a type-2 MW can
outlive its QP, or the pool can force-free an object with outstanding
references. An unprivileged user with access to an RXe device can use
these races to corrupt kernel memory and escalate privileges.

This series fixes those races with four focused, individually revertible
changes:

1. Move MW lookup, validation, and MR reference acquisition under
   mw->lock.
2. Use num_mw as an atomic state reservation while an MR changes state.
3. Track and invalidate type-2 MWs bound to a QP before destroying that
   QP.
4. Stop force-freeing sleepable pool objects after a timeout.

Patch 4 is hardening: it prevents pool cleanup from turning an
outstanding reference into a use-after-free, rather than fixing the
reported bind and deregistration race directly.

Before the fix, a concurrent MW bind and MR deregistration reproducer
made KASAN report a slab use-after-free in rxe_mr_copy() from
rxe_receiver() on the RXe responder workqueue. With this series, the
same 120-second test no longer triggers KASAN. MW READ, WRITE, partial
READ, invalidate, and rebind still pass.

Changes in v2:

- Patch 3 now tracks type-2 MWs on a per-QP list instead of scanning the
  global MW pool. This fixes the pool-element type mismatch, avoids a
  concurrent MW deallocation race, and eliminates the unbounded global
  scan.
- Patch 3 clears qp->valid and stops the send task before invalidating
  MWs so a late bind cannot attach an MW after invalidation.
- Patch 3 yields between MW invalidations.
- Patches 1, 2, and 4 are unchanged.

v1: https://lore.kernel.org/linux-rdma/20260928155351.3222978-1-cccccccccccc777777@gmail.com/

Dongliang Qin (4):
  RDMA/rxe: Take MR reference under MW lock
  RDMA/rxe: Reserve MR state during MW binding
  RDMA/rxe: Invalidate MWs on QP destroy
  RDMA/rxe: Do not force cleanup on pool timeout

 drivers/infiniband/sw/rxe/rxe_loc.h   |   8 +-
 drivers/infiniband/sw/rxe/rxe_mr.c    |  70 +++++++++++++--
 drivers/infiniband/sw/rxe/rxe_mw.c    | 122 +++++++++++++++++++-------
 drivers/infiniband/sw/rxe/rxe_pool.c  |  14 +--
 drivers/infiniband/sw/rxe/rxe_qp.c    |   2 +
 drivers/infiniband/sw/rxe/rxe_resp.c  |  38 +-------
 drivers/infiniband/sw/rxe/rxe_verbs.c |  21 ++++-
 drivers/infiniband/sw/rxe/rxe_verbs.h |   3 +
 8 files changed, 190 insertions(+), 88 deletions(-)

-- 
2.43.0

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-28 17:18 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 17:17 [PATCH v2 0/4] RDMA/rxe: Fix MW/MR lifetime races Dongliang Qin
2026-09-28 17:17 ` [PATCH v2 1/4] RDMA/rxe: Take MR reference under MW lock Dongliang Qin
2026-09-28 17:17 ` [PATCH v2 2/4] RDMA/rxe: Reserve MR state during MW binding Dongliang Qin
2026-09-28 17:17 ` [PATCH v2 3/4] RDMA/rxe: Invalidate MWs on QP destroy Dongliang Qin
2026-09-28 17:17 ` [PATCH v2 4/4] RDMA/rxe: Do not force cleanup on pool timeout Dongliang Qin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®