From: sashiko-bot@kernel.org
To: "Koichiro Den" <den@valinux.co.jp>
Cc: ntb@lists.linux.dev
Subject: Re: [PATCH v2 12/14] NTB: ntb_transport: Clear QP pointers when freeing an MW
Date: Thu, 10 Sep 2026 04:32:32 +0000 [thread overview]
Message-ID: <20260910043233.57D091F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260910040836.3792333-13-den@valinux.co.jp>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] The patch addresses a serial Use-After-Free but leaves a concurrent TOCTOU (Time-Of-Check to Time-Of-Use) Use-After-Free unmitigated, as `WRITE_ONCE()` does not protect concurrent readers from accessing freed memory.
--
commit 83701cf77653ce575ecc537dc3582d73e7b2ebcf
Author: Koichiro Den <den@valinux.co.jp>
NTB: ntb_transport: Clear QP pointers when freeing an MW
This commit clears the rx_buff and remote_rx_info pointers for all QPs using
an MW when the MW is freed. This addresses a serial use-after-free where a
link-down event could cause ntb_qp_link_down_reset() to write to previously
freed MW memory.
> diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
> index b949f36a4f2d9..096be87e5ede9 100644
> --- a/drivers/ntb/ntb_transport.c
> +++ b/drivers/ntb/ntb_transport.c
> @@ -781,10 +781,17 @@ static void ntb_free_mw(struct ntb_transport_ctx *nt, int num_mw)
> {
> struct ntb_transport_mw *mw = &nt->mw_vec[num_mw];
> struct device *dma_dev = ntb_get_dma_dev(nt->ndev);
> + unsigned int i;
>
> if (!mw->virt_addr)
> return;
>
> + /* Drop references from every QP using this MW. */
> + for (i = num_mw; i < nt->qp_count; i += nt->mw_count) {
> + nt->qp_vec[i].rx_buff = NULL;
> + WRITE_ONCE(nt->qp_vec[i].remote_rx_info, NULL);
> + }
> +
[Severity: High]
This is a pre-existing issue, but does this clearing mechanism leave a
concurrent Time-Of-Check to Time-Of-Use (TOCTOU) regression unmitigated?
While this patch addresses a serial use-after-free, WRITE_ONCE() does not
protect concurrent readers from accessing freed memory. If a client drops the
link concurrently with a hardware link-down event triggering
ntb_transport_link_cleanup(), the client thread can fetch the remote_rx_info
pointer locklessly:
drivers/ntb/ntb_transport.c:ntb_qp_link_down_reset() {
...
remote_rx_info = READ_ONCE(qp->remote_rx_info);
if (remote_rx_info)
remote_rx_info->entry = qp->rx_max_entry - 1;
...
}
If the client thread is preempted after reading the pointer, and the cleanup
thread proceeds to free the memory in ntb_free_mw():
drivers/ntb/ntb_transport.c:ntb_free_mw() {
...
ntb_mw_clear_trans(nt->ndev, PIDX, num_mw);
dma_free_attrs(dma_dev, mw->alloc_size, mw->alloc_addr,
mw->original_dma_addr, DMA_ATTR_FORCE_CONTIGUOUS);
...
}
When the client thread resumes, wouldn't it write to the freed DMA memory?
This same lockless TOCTOU vulnerability appears to be reachable on the
transmit hot-path in ntb_transport_tx_free_entry() and via debugfs in
ntb_qp_debugfs_stats_show().
> ntb_mw_clear_trans(nt->ndev, PIDX, num_mw);
> dma_free_attrs(dma_dev, mw->alloc_size, mw->alloc_addr,
> mw->original_dma_addr, DMA_ATTR_FORCE_CONTIGUOUS);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260910040836.3792333-1-den@valinux.co.jp?part=12
next prev parent reply other threads:[~2026-09-10 4:32 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 4:08 [PATCH v2 00/14] NTB: ntb_transport: Miscellaneous fixes Koichiro Den
2026-09-10 4:08 ` [PATCH v2 01/14] NTB: ntb_transport: Remove the device debugfs directory Koichiro Den
2026-09-10 4:20 ` sashiko-bot
2026-09-10 18:41 ` Frank Li
2026-09-10 4:08 ` [PATCH v2 02/14] NTB: ntb_transport: Start TX offload thread after queue setup Koichiro Den
2026-09-11 16:13 ` Frank Li
2026-09-10 4:08 ` [PATCH v2 03/14] NTB: ntb_transport: Avoid deadlock when cancelling link work Koichiro Den
2026-09-10 4:23 ` sashiko-bot
2026-09-11 16:21 ` Frank Li
2026-09-11 17:41 ` Koichiro Den
2026-09-10 4:08 ` [PATCH v2 04/14] NTB: ntb_transport: Publish link state after QP setup Koichiro Den
2026-09-11 16:39 ` Frank Li
2026-09-10 4:08 ` [PATCH v2 05/14] NTB: ntb_transport: Avoid losing QP link-up requests Koichiro Den
2026-09-10 4:26 ` sashiko-bot
2026-09-11 16:53 ` Frank Li
2026-09-11 18:04 ` Koichiro Den
2026-09-11 18:21 ` Koichiro Den
2026-09-12 3:20 ` Frank Li
2026-09-12 14:52 ` Koichiro Den
2026-09-10 4:08 ` [PATCH v2 06/14] NTB: ntb_transport: Clear link state before QP cleanup Koichiro Den
2026-09-10 4:27 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 07/14] NTB: ntb_transport: Stop QP work before freeing a queue Koichiro Den
2026-09-10 4:23 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 08/14] NTB: ntb_transport: Stop RX tasklet scheduling " Koichiro Den
2026-09-10 4:08 ` [PATCH v2 09/14] NTB: ntb_transport: Drain RX tasklets during link cleanup Koichiro Den
2026-09-10 4:23 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 10/14] NTB: ntb_transport: Wait for RX completions before resetting a QP Koichiro Den
2026-09-10 4:24 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 11/14] NTB: ntb_transport: Prepare remote RX info accesses for MW teardown Koichiro Den
2026-09-10 4:31 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 12/14] NTB: ntb_transport: Clear QP pointers when freeing an MW Koichiro Den
2026-09-10 4:32 ` sashiko-bot [this message]
2026-09-10 4:08 ` [PATCH v2 13/14] NTB: ntb_transport: Abort link setup on QP MW allocation failure Koichiro Den
2026-09-10 4:40 ` sashiko-bot
2026-09-10 4:08 ` [PATCH v2 14/14] NTB: ntb_transport: Remove clients before freeing transport resources Koichiro Den
2026-09-10 4:36 ` sashiko-bot
2026-09-10 8:48 ` Koichiro Den
2026-09-11 15:49 ` Dave Jiang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910043233.57D091F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=den@valinux.co.jp \
--cc=ntb@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.