From: netdev-bot+sashiko@kernel.org
To: achender@kernel.org
Cc: netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
pabeni@redhat.com, edumazet@google.com, kuba@kernel.org,
horms@kernel.org
Subject: Re: [PATCH net-next v7 08/12] net/rds: hold a connection reference from struct rds_incoming
Date: Thu, 01 Oct 2026 06:16:12 +0000 [thread overview]
Message-ID: <179083537208.434549.10956746980107541963@kernel.org> (raw)
In-Reply-To: <20260927061448.167862-9-achender@kernel.org>
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] The commit fixes a use-after-free that users can hit and that was
reported with a KASAN trace and a panic trace (Reported-by/Closes tags…
--
net/rds: hold a connection reference from struct rds_incoming
This commit makes every holder of rds_incoming->i_conn take a reference
on the connection. It covers rds_inc_init(), rds_inc_path_init(),
rds_recv_incoming(), rds_send_queue_rm(), rds_send_probe() and the
congestion map path of rds_send_xmit(). The references are dropped from
rds_inc_put() and from a new rds_message_free() helper, which fixes a
use-after-free of the connection seen from rds6_inc_info_copy() and from
rds_ib_inc_free() after the connection has been destroyed.
Closes: https://lore.kernel.org/netdev/20260720184955.3008978-1-nicoyip.dev@gmail.com/
> This is not a stable candidate: reaching the use-after-free requires
> freeing a connection out from under a live socket, which needs
> CAP_SYS_MODULE, and the fix
> depends on the connection reference counting introduced earlier in this
> series.
[ ... ]
> Reported-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> Closes: https://lore.kernel.org/netdev/20260720184955.3008978-1-nicoyip.dev@gmail.com/
[Severity: Low]
This isn't a bug, but should the commit carry a Fixes: tag?
It fixes a use-after-free that has been reported, with a KASAN trace in
rds6_inc_info_copy() and a panic in rds_ib_recv_cache_put(), and it has
Reported-by and Closes trailers. The unreferenced i_conn pointer appears
to date back to the original RDS code.
Leaving the tag out looks deliberate. The quoted paragraph says the patch
depends on the connection reference counting added earlier in this series,
and a Fixes: tag could lead stable tooling to pick it up without those
prerequisites.
Would it help to add a Fixes: tag pointing at the commit that introduced
i_conn, maybe together with a note or a Cc: stable line that names the
prerequisite patches? That way the origin of the bug is recorded without
inviting a partial backport.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260927061448.167862-1-achender%40kernel.org
next prev parent reply other threads:[~2026-10-01 6:16 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 6:14 [PATCH net-next v7 00/12] net/rds: make connection lifetime reference-counted Allison Henderson
2026-09-27 6:14 ` [PATCH net-next v7 01/12] net/rds: ib: don't enable interrupts in rds_ib_conn_free() Allison Henderson
2026-09-28 6:14 ` sashiko-bot
2026-09-27 6:14 ` [PATCH net-next v7 02/12] net/rds: undo conn_alloc() the same way on every __rds_conn_create() exit Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-09-27 6:14 ` [PATCH net-next v7 03/12] net/rds: guard every work-requeueing site with rds_destroy_pending() Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 04/12] net/rds: make rds_destroy_pending() report a connection's own destroy Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 05/12] net/rds: split connection destroy into quiesce and kref-governed free Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 06/12] net/rds: wait for connections to be freed on transport unload Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 07/12] net/rds: unlink transport nodes before a possibly deferred connection free Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 08/12] net/rds: hold a connection reference from struct rds_incoming Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko [this message]
2026-09-27 6:14 ` [PATCH net-next v7 09/12] net/rds: take cp_lock to purge cp_send_queue in the quiesce Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 10/12] net/rds: hold connection references in lookup, sockets and c_passive Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 11/12] net/rds: pin the connection across RDMA-CM event handling Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-09-27 6:14 ` [PATCH net-next v7 12/12] net/rds: drop rds_conn_count in favor of t_conn_count Allison Henderson
2026-09-28 6:15 ` sashiko-bot
2026-10-01 6:16 ` netdev-bot+sashiko
2026-10-02 19:37 ` [PATCH net-next v7 00/12] net/rds: make connection lifetime reference-counted Jakub Kicinski
2026-10-02 21:26 ` Allison Henderson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179083537208.434549.10956746980107541963@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=achender@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox