* [PATCH 1/1] RDMA/cma: Fix WARNING in res_to_rt
@ 2026-08-10 1:53 Zhu Yanjun
2026-08-10 18:37 ` Jason Gunthorpe
0 siblings, 1 reply; 2+ messages in thread
From: Zhu Yanjun @ 2026-08-10 1:53 UTC (permalink / raw)
To: jgg, leon, linux-rdma, yanjun.zhu; +Cc: syzbot+72eddfbadda3e3928e72
syzbot reported a WARN_ON(!res->dev) in res_to_rt() triggered via
addr_handler() during asynchronous address resolution:
"
WARNING: drivers/infiniband/core/restrack.c:138 at res_to_rt+0x1c4/0x230
CPU#1: kworker/u8:4/59
Modules linked in:
CPU: 1 UID: 0 PID: 59 Comm: kworker/u8:4 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Compute Engine, BIOS Google 07/24/2026
Workqueue: ib_addr process_one_req
RIP: 0010:res_to_rt+0x1c4/0x230 drivers/infiniband/core/restrack.c:138
RSP: 0018:ffffc9000201f850 EFLAGS: 00010293
RAX: ffffffff88d00ce5 RBX: ffff88807f0fd4f8 RCX: ffff88801e6e0000
RDX: 0000000000000000 RSI: ffffffff8fd996f0 RDI: 0000000000000003
RBP: 0000000000000000 R08: ffff88801e6e0000 R09: 000000000000000a
R10: 0000000000000009 R11: 0000000000000000 R12: dffffc0000000000
R13: 1ffff1100fe1fa9f R14: 0000000000000000 R15: 0000000000000003
FS: 0000000000000000(0000) GS:ffff888125012000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00001d559c3d2000 CR3: 0000000077c4c000 CR4: 00000000003526f0
Call Trace:
<TASK>
rdma_restrack_add+0x5a/0x8a0 drivers/infiniband/core/restrack.c:236
addr_handler+0x41a/0x5a0 drivers/infiniband/core/cma.c:3534
process_one_req+0x2eb/0x540 drivers/infiniband/core/addr.c:624
process_one_work kernel/workqueue.c:3375 [inline]
process_scheduled_works+0xc4e/0x1630 kernel/workqueue.c:3458
worker_thread+0xa47/0xfb0 kernel/workqueue.c:3539
kthread+0x388/0x470 kernel/kthread.c:436
ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245
</TASK>
"
The function addr_handler is invoked to process the resolved destination.
If address resolution fails or encounters a state race before an RDMA
device binding is established (that is, id_priv->id.device remains NULL),
id_priv->res.dev is not initialized.
addr_handler() previously called rdma_restrack_add(&id_priv->res)
unconditionally upon handling the resolution step. Passing an uninitialized
restrack resource with a NULL dev pointer causes res_to_rt() to hit the
WARN_ON(!res->dev) assertion.
Fix this by adding a check for id_priv->id.device in addr_handler() before
registering the CMA ID with restrack.
Reported-by: syzbot+72eddfbadda3e3928e72@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=72eddfbadda3e3928e72
Tested-by: syzbot+72eddfbadda3e3928e72@syzkaller.appspotmail.com
Fixes: cb5cd0ea4eb3 ("RDMA/core: Add CM to restrack after successful attachment to a device")
Signed-off-by: Zhu Yanjun <yanjun.zhu@linux.dev>
---
drivers/infiniband/core/cma.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/cma.c b/drivers/infiniband/core/cma.c
index cc24fddf9aaa..35e463a20ade 100644
--- a/drivers/infiniband/core/cma.c
+++ b/drivers/infiniband/core/cma.c
@@ -3531,7 +3531,8 @@ static void addr_handler(int status, struct sockaddr *src_addr,
if (status)
pr_debug_ratelimited("RDMA CM: ADDR_ERROR: failed to acquire device. status %d\n",
status);
- rdma_restrack_add(&id_priv->res);
+ if (id_priv->id.device)
+ rdma_restrack_add(&id_priv->res);
} else if (status) {
pr_debug_ratelimited("RDMA CM: ADDR_ERROR: failed to resolve IP. status %d\n", status);
}
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH 1/1] RDMA/cma: Fix WARNING in res_to_rt
2026-08-10 1:53 [PATCH 1/1] RDMA/cma: Fix WARNING in res_to_rt Zhu Yanjun
@ 2026-08-10 18:37 ` Jason Gunthorpe
0 siblings, 0 replies; 2+ messages in thread
From: Jason Gunthorpe @ 2026-08-10 18:37 UTC (permalink / raw)
To: Zhu Yanjun; +Cc: leon, linux-rdma, syzbot+72eddfbadda3e3928e72
On Mon, Aug 10, 2026 at 03:53:57AM +0200, Zhu Yanjun wrote:
> @@ -3531,7 +3531,8 @@ static void addr_handler(int status, struct sockaddr *src_addr,
> if (status)
> pr_debug_ratelimited("RDMA CM: ADDR_ERROR: failed to acquire device. status %d\n",
> status);
> - rdma_restrack_add(&id_priv->res);
> + if (id_priv->id.device)
> + rdma_restrack_add(&id_priv->res);
> } else if (status) {
> pr_debug_ratelimited("RDMA CM: ADDR_ERROR: failed to resolve IP. status %d\n", status);
> }
The full text is:
if (!status && !id_priv->cma_dev) {
status = cma_acquire_dev_by_src_ip(id_priv);
if (status)
pr_debug_ratelimited("RDMA CM: ADDR_ERROR: failed to acquire device. status %d\n",
status);
rdma_restrack_add(&id_priv->res);
What it is trying to do is fill in cma_dev/id.device (they are
linked).
'if (status)' means the resolution failed and the cm_id is not
populated, so it should just be if/else instead of trying to check
id.device
But this does seem to be the bug syzkaller is pointing at, but the
commit message seems really strange.
If status is !0 then we know id.device is NULL and we cannot add this
to restrack. Otherwise it must be !NULL and it must be safe to add it
or we have a locking problem.
Jason
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-10 18:37 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-10 1:53 [PATCH 1/1] RDMA/cma: Fix WARNING in res_to_rt Zhu Yanjun
2026-08-10 18:37 ` Jason Gunthorpe
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox