All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dust Li <dust.li@linux.alibaba.com>
To: Mahanta Jambigi <mjambigi@linux.ibm.com>,
	andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
	kuba@kernel.org, pabeni@redhat.com, alibuda@linux.alibaba.com,
	sidraya@linux.ibm.com
Cc: pasic@linux.ibm.com, horms@kernel.org, tonylu@linux.alibaba.com,
	guwen@linux.alibaba.com, hidayath@linux.ibm.com,
	stable@vger.kernel.org, netdev@vger.kernel.org,
	linux-s390@vger.kernel.org, linux-rdma@vger.kernel.org
Subject: Re: [PATCH net v4] net/smc: fix lgr/lnk lifetime vs diag reader race
Date: Tue, 15 Sep 2026 23:13:57 +0800	[thread overview]
Message-ID: <aqlgtaEk3kNcg-Yp@linux.alibaba.com> (raw)
In-Reply-To: <20260911090906.1949163-1-mjambigi@linux.ibm.com>

On 2026-09-11 11:09:06, Mahanta Jambigi wrote:
>The diag dump walks the socket hash table under a read_lock and dereferences
>conn->lgr and conn->lnk.  Two terminal teardown paths drop those references via
>smc_conn_free() while the socket is still hashed:
>
>  - smc_conn_kill() -> smc_close_active_abort() -> smc_conn_free()
>  - smc_close_passive_work() -> smc_conn_free()
>
>This allows the diag reader to dereference a freed lgr or lnk.
>
>Fix it by unhashing the socket before smc_conn_free() is called at each of these
>two sites.  Any socket visible to the diag reader under the hash read_lock then
>has valid conn->lgr and conn->lnk pointers.
>
>Fixes: f16a7dd5cf27 ("smc: netlink interface for SMC sockets")
>Fixes: 9dbe086c69b8 ("net/smc: fix invalid link access in dumping SMC-R connections")
>Signed-off-by: Mahanta Jambigi <mjambigi@linux.ibm.com>
>---
>Changes in v4:
>- dropped smc_conn_unhash() wrapper, conn->unhashed flag, and all
>  changes to af_smc.c, smc.h, smc_core.c and smc_core.h; smc_unhash_sk()
>  is already idempotent via sk_hashed(), so direct calls at the two
>  teardown sites in smc_close.c are sufficient
>- dropped the __smc_release() hunk: it needs no change since the
>  subsequent unhash there is already a safe no-op
>- fixed premature-unhash issue present in v3: smc_conn_free() must not
>  unhash because smc_conn_abort() calls it before smc_switch_to_fallback()
>  in both smc_listen_decline() and smc_connect_rdma() error paths;
>  unhashing there would make live fallback sockets invisible to smcss
>- likewise, the ISM/RDMA retry loops (smc_find_ism_v2_device_serv(),
>  smc_find_rdma_v2_device_serv()) call smc_conn_abort() on a failed
>  attempt and then smc_conn_create() on the next device; unhashing in
>  smc_conn_free() would permanently hide the established connection from
>  smc_diag since smc_conn_create() does not re-hash the socket

Hi Mahanta,

This version looks clean. And you explained why we can't call unhash in
smc_conn_abort() well. But smc_conn_abort() still calls smc_conn_free(),
when the smc_sk is still hashed, is there still a race window with dump ?

Best regards,
Dust


  parent reply	other threads:[~2026-09-15 15:14 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11  9:09 [PATCH net v4] net/smc: fix lgr/lnk lifetime vs diag reader race Mahanta Jambigi
2026-09-11  9:30 ` sashiko-bot
2026-09-15 15:13 ` Dust Li [this message]
2026-09-16  8:34   ` Mahanta Jambigi
2026-09-16 15:24     ` Dust Li
2026-09-17  7:45       ` Mahanta Jambigi
2026-09-17 15:53         ` Dust Li
2026-09-18  7:27           ` Mahanta Jambigi
2026-09-21  9:56             ` Dust Li
2026-09-22 13:27               ` Mahanta Jambigi
2026-09-22 16:01                 ` Dust Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aqlgtaEk3kNcg-Yp@linux.alibaba.com \
    --to=dust.li@linux.alibaba.com \
    --cc=alibuda@linux.alibaba.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=guwen@linux.alibaba.com \
    --cc=hidayath@linux.ibm.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=mjambigi@linux.ibm.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=pasic@linux.ibm.com \
    --cc=sidraya@linux.ibm.com \
    --cc=stable@vger.kernel.org \
    --cc=tonylu@linux.alibaba.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.