From: Leon Romanovsky <leon-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>
To: Jason Gunthorpe
<jgunthorpe-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
Cc: Doug Ledford <dledford-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>,
Yishai Hadas
<yishaih-LDSdmyG8hGV8YrgS2mwiifqBs+8SCbDb@public.gmane.org>,
linux-rdma-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: Re: [PATCH rdma-core] verbs: Do not copy uninitialized data in ibv_cmd_modify_qp
Date: Sun, 25 Dec 2016 09:42:43 +0200 [thread overview]
Message-ID: <20161225074243.GA14356@mtr-leonro.local> (raw)
In-Reply-To: <20161222221334.GA15907-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
[-- Attachment #1: Type: text/plain, Size: 8492 bytes --]
On Thu, Dec 22, 2016 at 03:13:34PM -0700, Jason Gunthorpe wrote:
> Valgrind reports:
>
> ==1196== Syscall param write(buf) points to uninitialised byte(s)
> ==1196== at 0x506250D: ??? (syscall-template.S:84)
> ==1196== by 0x527756F: ibv_cmd_modify_qp (cmd.c:1291)
> ==1196== by 0x8008D74: mlx4_modify_qp (verbs.c:820)
> ==1196== by 0x527E4F4: ibv_modify_qp@@IBVERBS_1.1 (verbs.c:561)
> ==1196== by 0x4E3FAB3: ucma_modify_qp_err.isra.6 (cma.c:1115)
> ==1196== by 0x4E41D56: rdma_get_cm_event.part.15 (cma.c:2180)
> ==1196== by 0x402CF0: cm_thread (rping.c:576)
> ==1196== by 0x5059709: start_thread (pthread_create.c:333)
> ==1196== by 0x558A82C: clone (clone.S:109)
> ==1196== Address 0x9847980 is on thread 2's stack
> ==1196== in frame #2, created by mlx4_modify_qp (verbs.c:775)
>
> This is because of code like this:
>
> struct ibv_qp_attr qp_attr;
> qp_attr.qp_state = IBV_QPS_ERR;
> return rdma_seterrno(ibv_modify_qp(id->qp, &qp_attr, IBV_QP_STATE));
>
> Always pass 0 into the kernel for for attributes that are not requested
> to be modified.
>
> Signed-off-by: Jason Gunthorpe <jgunthorpe-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
> ---
> libibverbs/cmd.c | 170 +++++++++++++++++++++++++++++++++++++++----------------
> 1 file changed, 121 insertions(+), 49 deletions(-)
>
> Shown with rping
>
> Please double check my if's.. I followed the man page
>
> I think there will be other cases where we do this wrong as well :\
>
> diff --git a/libibverbs/cmd.c b/libibverbs/cmd.c
> index 38061892da0de0..a702d67b05f2a3 100644
> --- a/libibverbs/cmd.c
> +++ b/libibverbs/cmd.c
> @@ -1221,55 +1221,127 @@ int ibv_cmd_modify_qp(struct ibv_qp *qp, struct ibv_qp_attr *attr,
> {
> IBV_INIT_CMD(cmd, cmd_size, MODIFY_QP);
I didn't check all ibv_* commands but for ibv_cmd_modify_qp callers, there are no callers
which change cmd before this call. It looks like it is safe to replace all cmd->* = 0 with
one global memset(). Maybe it is safe to put this memset in IBV_INIT_CMD too.
>
> - cmd->qp_handle = qp->handle;
> - cmd->attr_mask = attr_mask;
> - cmd->qkey = attr->qkey;
> - cmd->rq_psn = attr->rq_psn;
> - cmd->sq_psn = attr->sq_psn;
> - cmd->dest_qp_num = attr->dest_qp_num;
> - cmd->qp_access_flags = attr->qp_access_flags;
> - cmd->pkey_index = attr->pkey_index;
> - cmd->alt_pkey_index = attr->alt_pkey_index;
> - cmd->qp_state = attr->qp_state;
> - cmd->cur_qp_state = attr->cur_qp_state;
> - cmd->path_mtu = attr->path_mtu;
> - cmd->path_mig_state = attr->path_mig_state;
> - cmd->en_sqd_async_notify = attr->en_sqd_async_notify;
> - cmd->max_rd_atomic = attr->max_rd_atomic;
> - cmd->max_dest_rd_atomic = attr->max_dest_rd_atomic;
> - cmd->min_rnr_timer = attr->min_rnr_timer;
> - cmd->port_num = attr->port_num;
> - cmd->timeout = attr->timeout;
> - cmd->retry_cnt = attr->retry_cnt;
> - cmd->rnr_retry = attr->rnr_retry;
> - cmd->alt_port_num = attr->alt_port_num;
> - cmd->alt_timeout = attr->alt_timeout;
> -
> - memcpy(cmd->dest.dgid, attr->ah_attr.grh.dgid.raw, 16);
> - cmd->dest.flow_label = attr->ah_attr.grh.flow_label;
> - cmd->dest.dlid = attr->ah_attr.dlid;
> - cmd->dest.reserved = 0;
> - cmd->dest.sgid_index = attr->ah_attr.grh.sgid_index;
> - cmd->dest.hop_limit = attr->ah_attr.grh.hop_limit;
> - cmd->dest.traffic_class = attr->ah_attr.grh.traffic_class;
> - cmd->dest.sl = attr->ah_attr.sl;
> - cmd->dest.src_path_bits = attr->ah_attr.src_path_bits;
> - cmd->dest.static_rate = attr->ah_attr.static_rate;
> - cmd->dest.is_global = attr->ah_attr.is_global;
> - cmd->dest.port_num = attr->ah_attr.port_num;
> -
> - memcpy(cmd->alt_dest.dgid, attr->alt_ah_attr.grh.dgid.raw, 16);
> - cmd->alt_dest.flow_label = attr->alt_ah_attr.grh.flow_label;
> - cmd->alt_dest.dlid = attr->alt_ah_attr.dlid;
> - cmd->alt_dest.reserved = 0;
> - cmd->alt_dest.sgid_index = attr->alt_ah_attr.grh.sgid_index;
> - cmd->alt_dest.hop_limit = attr->alt_ah_attr.grh.hop_limit;
> - cmd->alt_dest.traffic_class = attr->alt_ah_attr.grh.traffic_class;
> - cmd->alt_dest.sl = attr->alt_ah_attr.sl;
> - cmd->alt_dest.src_path_bits = attr->alt_ah_attr.src_path_bits;
> - cmd->alt_dest.static_rate = attr->alt_ah_attr.static_rate;
> - cmd->alt_dest.is_global = attr->alt_ah_attr.is_global;
> - cmd->alt_dest.port_num = attr->alt_ah_attr.port_num;
> + cmd->qp_handle = qp->handle;
> + cmd->attr_mask = attr_mask;
> +
> + if (attr_mask & IBV_QP_STATE)
> + cmd->qp_state = attr->qp_state;
> + else
> + cmd->qp_state = 0;
> +
> + if (attr_mask & IBV_QP_CUR_STATE)
> + cmd->cur_qp_state = attr->cur_qp_state;
> + else
> + cmd->cur_qp_state = 0;
> +
> + if (attr_mask & IBV_QP_EN_SQD_ASYNC_NOTIFY)
> + cmd->en_sqd_async_notify = attr->en_sqd_async_notify;
> + else
> + cmd->en_sqd_async_notify = 0;
> +
> + if (attr_mask & IBV_QP_ACCESS_FLAGS)
> + cmd->qp_access_flags = attr->qp_access_flags;
> + else
> + cmd->qp_access_flags = 0;
> + if (attr_mask & IBV_QP_PKEY_INDEX)
> + cmd->pkey_index = attr->pkey_index;
> + else
> + cmd->pkey_index = 0;
> + if (attr_mask & IBV_QP_PORT)
> + cmd->port_num = attr->port_num;
> + else
> + cmd->port_num = 0;
> + if (attr_mask & IBV_QP_QKEY)
> + cmd->qkey = attr->qkey;
> + else
> + cmd->qkey = 0;
> +
> + if (attr_mask & IBV_QP_AV) {
> + memcpy(cmd->dest.dgid, attr->ah_attr.grh.dgid.raw, 16);
> + cmd->dest.flow_label = attr->ah_attr.grh.flow_label;
> + cmd->dest.dlid = attr->ah_attr.dlid;
> + cmd->dest.reserved = 0;
> + cmd->dest.sgid_index = attr->ah_attr.grh.sgid_index;
> + cmd->dest.hop_limit = attr->ah_attr.grh.hop_limit;
> + cmd->dest.traffic_class = attr->ah_attr.grh.traffic_class;
> + cmd->dest.sl = attr->ah_attr.sl;
> + cmd->dest.src_path_bits = attr->ah_attr.src_path_bits;
> + cmd->dest.static_rate = attr->ah_attr.static_rate;
> + cmd->dest.is_global = attr->ah_attr.is_global;
> + cmd->dest.port_num = attr->ah_attr.port_num;
> + } else
> + memset(&cmd->dest, 0, sizeof(cmd->dest));
> +
> + if (attr_mask & IBV_QP_PATH_MTU)
> + cmd->path_mtu = attr->path_mtu;
> + else
> + cmd->path_mtu = 0;
> + if (attr_mask & IBV_QP_TIMEOUT)
> + cmd->timeout = attr->timeout;
> + else
> + cmd->timeout = 0;
> + if (attr_mask & IBV_QP_RETRY_CNT)
> + cmd->retry_cnt = attr->retry_cnt;
> + else
> + cmd->retry_cnt = 0;
> + if (attr_mask & IBV_QP_RNR_RETRY)
> + cmd->rnr_retry = attr->rnr_retry;
> + else
> + cmd->rnr_retry = 0;
> + if (attr_mask & IBV_QP_RQ_PSN)
> + cmd->rq_psn = attr->rq_psn;
> + else
> + cmd->rq_psn = 0;
> + if (attr_mask & IBV_QP_MAX_QP_RD_ATOMIC)
> + cmd->max_rd_atomic = attr->max_rd_atomic;
> + else
> + cmd->max_rd_atomic = 0;
> +
> + if (attr_mask & IBV_QP_ALT_PATH) {
> + cmd->alt_pkey_index = attr->alt_pkey_index;
> + cmd->alt_port_num = attr->alt_port_num;
> + cmd->alt_timeout = attr->alt_timeout;
> +
> + memcpy(cmd->alt_dest.dgid, attr->alt_ah_attr.grh.dgid.raw, 16);
> + cmd->alt_dest.flow_label = attr->alt_ah_attr.grh.flow_label;
> + cmd->alt_dest.dlid = attr->alt_ah_attr.dlid;
> + cmd->alt_dest.reserved = 0;
> + cmd->alt_dest.sgid_index = attr->alt_ah_attr.grh.sgid_index;
> + cmd->alt_dest.hop_limit = attr->alt_ah_attr.grh.hop_limit;
> + cmd->alt_dest.traffic_class =
> + attr->alt_ah_attr.grh.traffic_class;
> + cmd->alt_dest.sl = attr->alt_ah_attr.sl;
> + cmd->alt_dest.src_path_bits = attr->alt_ah_attr.src_path_bits;
> + cmd->alt_dest.static_rate = attr->alt_ah_attr.static_rate;
> + cmd->alt_dest.is_global = attr->alt_ah_attr.is_global;
> + cmd->alt_dest.port_num = attr->alt_ah_attr.port_num;
> + } else {
> + cmd->alt_pkey_index = 0;
> + cmd->alt_port_num = 0;
> + cmd->alt_timeout = 0;
> + memset(&cmd->alt_dest, 0, sizeof(cmd->alt_dest));
> + }
> +
> + if (attr_mask & IBV_QP_MIN_RNR_TIMER)
> + cmd->min_rnr_timer = attr->min_rnr_timer;
> + else
> + cmd->min_rnr_timer = 0;
> + if (attr_mask & IBV_QP_SQ_PSN)
> + cmd->sq_psn = attr->sq_psn;
> + else
> + cmd->sq_psn = 0;
> + if (attr_mask & IBV_QP_MAX_DEST_RD_ATOMIC)
> + cmd->max_dest_rd_atomic = attr->max_dest_rd_atomic;
> + else
> + cmd->max_dest_rd_atomic = 0;
> + if (attr_mask & IBV_QP_PATH_MIG_STATE)
> + cmd->path_mig_state = attr->path_mig_state;
> + else
> + cmd->path_mig_state = 0;
> + if (attr_mask & IBV_QP_DEST_QPN)
> + cmd->dest_qp_num = attr->dest_qp_num;
> + else
> + cmd->dest_qp_num = 0;
>
> cmd->reserved[0] = cmd->reserved[1] = 0;
>
> --
> 2.7.4
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
next prev parent reply other threads:[~2016-12-25 7:42 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2016-12-22 22:13 [PATCH rdma-core] verbs: Do not copy uninitialized data in ibv_cmd_modify_qp Jason Gunthorpe
[not found] ` <20161222221334.GA15907-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
2016-12-23 12:11 ` Doug Ledford
2016-12-25 7:42 ` Leon Romanovsky [this message]
2017-01-02 8:02 ` Bart Van Assche
[not found] ` <1483344105.3592.1.camel-XdAiOPVOjttBDgjK7y7TUQ@public.gmane.org>
2017-01-02 21:14 ` Jason Gunthorpe
[not found] ` <20170102211430.GC5544-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org>
2017-01-03 8:36 ` Bart Van Assche
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20161225074243.GA14356@mtr-leonro.local \
--to=leon-dgejt+ai2ygdnm+yrofe0a@public.gmane.org \
--cc=dledford-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
--cc=jgunthorpe-ePGOBjL8dl3ta4EC/59zMFaTQe2KTcn/@public.gmane.org \
--cc=linux-rdma-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=yishaih-LDSdmyG8hGV8YrgS2mwiifqBs+8SCbDb@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.