mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id
@ 2026-09-23 10:52 Quanye Yang via B4 Relay
  2026-09-29  3:53 ` Jinpu Wang
  2026-09-29 22:59 ` Jason Gunthorpe
  0 siblings, 2 replies; 3+ messages in thread
From: Quanye Yang via B4 Relay @ 2026-09-23 10:52 UTC (permalink / raw)
  To: Md. Haris Iqbal, Jack Wang, Jason Gunthorpe, Leon Romanovsky,
	Danil Kipnis
  Cc: Jack Wang, linux-rdma, linux-kernel, Farhad Alemi

From: Quanye Yang <quanyeyang@proton.me>

process_io_rsp() indexes clt_path->reqs[] with the 19-bit msg_id
taken from a WRITE_WITH_IMM immediate. That value is chosen by the
peer. The only check was WARN_ON(msg_id >= queue_depth), which still
lets a completion run after free_path_reqs() has set reqs to NULL,
or against a slot whose FRWR is already gone. Either path
dereferences req->mr and can GPF; KASAN reports a null-ptr-deref at
offsetof(struct rtrs_clt_io_req, mr).

Treat a missing reqs array, an out-of-range msg_id, or a req
without an MR as a protocol error and recover the connection.

Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Link: https://lore.kernel.org/r/CA+0ovCiJZz6O8LzsS9Dq1-JE1OE1L_OTA6Mr-WratpUE6jczHw@mail.gmail.com
Fixes: 6a98d71daea1 ("RDMA/rtrs: client: main functionality")
Signed-off-by: Quanye Yang <quanyeyang@proton.me>
---
 drivers/infiniband/ulp/rtrs/rtrs-clt.c | 21 ++++++++++++++++-----
 1 file changed, 16 insertions(+), 5 deletions(-)

diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index eac38b57b00d..f8d3c6f37e3e 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -489,18 +489,22 @@ static int rtrs_post_send_rdma(struct rtrs_clt_con *con,
 					    imm, flags, wr, NULL);
 }
 
-static void process_io_rsp(struct rtrs_clt_path *clt_path, u32 msg_id,
+static bool process_io_rsp(struct rtrs_clt_path *clt_path, u32 msg_id,
 			   s16 errno, bool w_inval)
 {
 	struct rtrs_clt_io_req *req;
 
-	if (WARN_ON(msg_id >= clt_path->queue_depth))
-		return;
+	if (!clt_path->reqs || msg_id >= clt_path->queue_depth)
+		return false;
 
 	req = &clt_path->reqs[msg_id];
+	if (!req->mr)
+		return false;
+
 	/* Drop need_inv if server responded with send with invalidation */
 	req->mr->need_inval &= !w_inval;
 	complete_rdma_req(req, errno, true, false);
+	return true;
 }
 
 static void rtrs_clt_recv_done(struct rtrs_clt_con *con, struct ib_wc *wc)
@@ -562,7 +566,8 @@ static void rtrs_clt_rkey_rsp_done(struct rtrs_clt_con *con, struct ib_wc *wc)
 		if (WARN_ON(buf_id != msg_id))
 			goto out;
 		clt_path->rbufs[buf_id].rkey = le32_to_cpu(msg->rkey);
-		process_io_rsp(clt_path, msg_id, err, w_inval);
+		if (!process_io_rsp(clt_path, msg_id, err, w_inval))
+			goto out;
 	}
 	ib_dma_sync_single_for_device(clt_path->s.dev->ib_dev, iu->dma_addr,
 				      iu->size, DMA_FROM_DEVICE);
@@ -634,7 +639,13 @@ static void rtrs_clt_rdma_done(struct ib_cq *cq, struct ib_wc *wc)
 			w_inval = (imm_type == RTRS_IO_RSP_W_INV_IMM);
 			rtrs_from_io_rsp_imm(imm_payload, &msg_id, &err);
 
-			process_io_rsp(clt_path, msg_id, err, w_inval);
+			if (!process_io_rsp(clt_path, msg_id, err, w_inval)) {
+				rtrs_err(clt_path->clt,
+					 "Invalid IO rsp: msg_id %u queue_depth %zu\n",
+					 msg_id, clt_path->queue_depth);
+				rtrs_rdma_error_recovery(con);
+				return;
+			}
 		} else if (imm_type == RTRS_HB_MSG_IMM) {
 			WARN_ON(con->c.cid);
 			rtrs_send_hb_ack(&clt_path->s);

---
base-commit: 93f51579e7df248780214094418f205253383cc5
change-id: 20260923-rtrs-warning-inrtrs-clt-rdma-done-3a72d73550b1

Best regards,
--  
Quanye Yang <quanyeyang@proton.me>



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id
  2026-09-23 10:52 [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id Quanye Yang via B4 Relay
@ 2026-09-29  3:53 ` Jinpu Wang
  2026-09-29 22:59 ` Jason Gunthorpe
  1 sibling, 0 replies; 3+ messages in thread
From: Jinpu Wang @ 2026-09-29  3:53 UTC (permalink / raw)
  To: quanyeyang
  Cc: Md. Haris Iqbal, Jason Gunthorpe, Leon Romanovsky, Danil Kipnis,
	linux-rdma, linux-kernel, Farhad Alemi

On Wed, Sep 23, 2026 at 12:52 PM Quanye Yang via B4 Relay
<devnull+quanyeyang.proton.me@kernel.org> wrote:
>
> From: Quanye Yang <quanyeyang@proton.me>
>
> process_io_rsp() indexes clt_path->reqs[] with the 19-bit msg_id
> taken from a WRITE_WITH_IMM immediate. That value is chosen by the
> peer. The only check was WARN_ON(msg_id >= queue_depth), which still
> lets a completion run after free_path_reqs() has set reqs to NULL,
> or against a slot whose FRWR is already gone. Either path
> dereferences req->mr and can GPF; KASAN reports a null-ptr-deref at
> offsetof(struct rtrs_clt_io_req, mr).
>
> Treat a missing reqs array, an out-of-range msg_id, or a req
> without an MR as a protocol error and recover the connection.
>
> Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
> Link: https://lore.kernel.org/r/CA+0ovCiJZz6O8LzsS9Dq1-JE1OE1L_OTA6Mr-WratpUE6jczHw@mail.gmail.com
> Fixes: 6a98d71daea1 ("RDMA/rtrs: client: main functionality")
> Signed-off-by: Quanye Yang <quanyeyang@proton.me>
lgtm, thx!
Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
> ---
>  drivers/infiniband/ulp/rtrs/rtrs-clt.c | 21 ++++++++++++++++-----
>  1 file changed, 16 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
> index eac38b57b00d..f8d3c6f37e3e 100644
> --- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
> +++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
> @@ -489,18 +489,22 @@ static int rtrs_post_send_rdma(struct rtrs_clt_con *con,
>                                             imm, flags, wr, NULL);
>  }
>
> -static void process_io_rsp(struct rtrs_clt_path *clt_path, u32 msg_id,
> +static bool process_io_rsp(struct rtrs_clt_path *clt_path, u32 msg_id,
>                            s16 errno, bool w_inval)
>  {
>         struct rtrs_clt_io_req *req;
>
> -       if (WARN_ON(msg_id >= clt_path->queue_depth))
> -               return;
> +       if (!clt_path->reqs || msg_id >= clt_path->queue_depth)
> +               return false;
>
>         req = &clt_path->reqs[msg_id];
> +       if (!req->mr)
> +               return false;
> +
>         /* Drop need_inv if server responded with send with invalidation */
>         req->mr->need_inval &= !w_inval;
>         complete_rdma_req(req, errno, true, false);
> +       return true;
>  }
>
>  static void rtrs_clt_recv_done(struct rtrs_clt_con *con, struct ib_wc *wc)
> @@ -562,7 +566,8 @@ static void rtrs_clt_rkey_rsp_done(struct rtrs_clt_con *con, struct ib_wc *wc)
>                 if (WARN_ON(buf_id != msg_id))
>                         goto out;
>                 clt_path->rbufs[buf_id].rkey = le32_to_cpu(msg->rkey);
> -               process_io_rsp(clt_path, msg_id, err, w_inval);
> +               if (!process_io_rsp(clt_path, msg_id, err, w_inval))
> +                       goto out;
>         }
>         ib_dma_sync_single_for_device(clt_path->s.dev->ib_dev, iu->dma_addr,
>                                       iu->size, DMA_FROM_DEVICE);
> @@ -634,7 +639,13 @@ static void rtrs_clt_rdma_done(struct ib_cq *cq, struct ib_wc *wc)
>                         w_inval = (imm_type == RTRS_IO_RSP_W_INV_IMM);
>                         rtrs_from_io_rsp_imm(imm_payload, &msg_id, &err);
>
> -                       process_io_rsp(clt_path, msg_id, err, w_inval);
> +                       if (!process_io_rsp(clt_path, msg_id, err, w_inval)) {
> +                               rtrs_err(clt_path->clt,
> +                                        "Invalid IO rsp: msg_id %u queue_depth %zu\n",
> +                                        msg_id, clt_path->queue_depth);
> +                               rtrs_rdma_error_recovery(con);
> +                               return;
> +                       }
>                 } else if (imm_type == RTRS_HB_MSG_IMM) {
>                         WARN_ON(con->c.cid);
>                         rtrs_send_hb_ack(&clt_path->s);
>
> ---
> base-commit: 93f51579e7df248780214094418f205253383cc5
> change-id: 20260923-rtrs-warning-inrtrs-clt-rdma-done-3a72d73550b1
>
> Best regards,
> --
> Quanye Yang <quanyeyang@proton.me>
>
>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id
  2026-09-23 10:52 [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id Quanye Yang via B4 Relay
  2026-09-29  3:53 ` Jinpu Wang
@ 2026-09-29 22:59 ` Jason Gunthorpe
  1 sibling, 0 replies; 3+ messages in thread
From: Jason Gunthorpe @ 2026-09-29 22:59 UTC (permalink / raw)
  To: Quanye Yang
  Cc: Md. Haris Iqbal, Jack Wang, Leon Romanovsky, Danil Kipnis,
	Jack Wang, linux-rdma, linux-kernel, Farhad Alemi

On Wed, Sep 23, 2026 at 03:52:11AM -0700, Quanye Yang wrote:
> From: Quanye Yang <quanyeyang@proton.me>
> 
> process_io_rsp() indexes clt_path->reqs[] with the 19-bit msg_id
> taken from a WRITE_WITH_IMM immediate. That value is chosen by the
> peer. The only check was WARN_ON(msg_id >= queue_depth), which still
> lets a completion run after free_path_reqs() has set reqs to NULL,
> or against a slot whose FRWR is already gone. Either path
> dereferences req->mr and can GPF; KASAN reports a null-ptr-deref at
> offsetof(struct rtrs_clt_io_req, mr).
> 
> Treat a missing reqs array, an out-of-range msg_id, or a req
> without an MR as a protocol error and recover the connection.
> 
> Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
> Link: https://lore.kernel.org/r/CA+0ovCiJZz6O8LzsS9Dq1-JE1OE1L_OTA6Mr-WratpUE6jczHw@mail.gmail.com
> Fixes: 6a98d71daea1 ("RDMA/rtrs: client: main functionality")
> Signed-off-by: Quanye Yang <quanyeyang@proton.me>
> Reviewed-by: Jack Wang <jinpu.wang@cloud.ionos.com>
> ---
>  drivers/infiniband/ulp/rtrs/rtrs-clt.c | 21 ++++++++++++++++-----
>  1 file changed, 16 insertions(+), 5 deletions(-)

Applied to for-next, thanks

Jason

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-29 22:59 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23 10:52 [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id Quanye Yang via B4 Relay
2026-09-29  3:53 ` Jinpu Wang
2026-09-29 22:59 ` Jason Gunthorpe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®