* [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
@ 2026-09-19 10:08 lirongqing
2026-09-19 10:24 ` sashiko-bot
2026-09-28 18:40 ` Leon Romanovsky
0 siblings, 2 replies; 3+ messages in thread
From: lirongqing @ 2026-09-19 10:08 UTC (permalink / raw)
To: Leon Romanovsky, Jason Gunthorpe, linux-rdma; +Cc: Li RongQing
From: Li RongQing <lirongqing@baidu.com>
In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
so set_pi_umr_wr can read it during this call. The pointer is never
restored, so after the function returns mr->pi_mr dangles at a freed stack
frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
remapping reads the stale pointer and dereferences it.
Save the original pi_mr (captured at function entry) and restore it on
the out path.
Fixes: 2563e2f30acb ("RDMA/mlx5: Use PA mapping for PI handover")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
---
drivers/infiniband/hw/mlx5/wr.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/hw/mlx5/wr.c b/drivers/infiniband/hw/mlx5/wr.c
index fca9e1d..bb2c603 100644
--- a/drivers/infiniband/hw/mlx5/wr.c
+++ b/drivers/infiniband/hw/mlx5/wr.c
@@ -927,6 +927,7 @@ static noinline_for_stack int handle_reg_mr_integrity(struct mlx5_ib_dev *dev,
qp->next_fence = MLX5_FENCE_MODE_INITIATOR_SMALL;
out:
+ mr->pi_mr = pi_mr;
return err;
}
--
2.9.4
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
@ 2026-09-19 10:24 ` sashiko-bot
2026-09-28 18:40 ` Leon Romanovsky
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-19 10:24 UTC (permalink / raw)
To: lirongqing; +Cc: linux-rdma
> From: Li RongQing <lirongqing@baidu.com>
>
> In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
> optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
> so set_pi_umr_wr can read it during this call. The pointer is never
> restored, so after the function returns mr->pi_mr dangles at a freed stack
> frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
> remapping reads the stale pointer and dereferences it.
>
> Save the original pi_mr (captured at function entry) and restore it on
> the out path.
>
> Fixes: 2563e2f30acb ("RDMA/mlx5: Use PA mapping for PI handover")
> Signed-off-by: Li RongQing <lirongqing@baidu.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260919100848.2442-1-lirongqing@baidu.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
2026-09-19 10:24 ` sashiko-bot
@ 2026-09-28 18:40 ` Leon Romanovsky
1 sibling, 0 replies; 3+ messages in thread
From: Leon Romanovsky @ 2026-09-28 18:40 UTC (permalink / raw)
To: Jason Gunthorpe, linux-rdma, lirongqing
On Sat, 19 Sep 2026 18:08:48 +0800, lirongqing wrote:
> In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
> optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
> so set_pi_umr_wr can read it during this call. The pointer is never
> restored, so after the function returns mr->pi_mr dangles at a freed stack
> frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
> remapping reads the stale pointer and dereferences it.
>
> [...]
Applied, thanks!
[1/1] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
https://git.kernel.org/rdma/rdma/c/9728effe43d8fc
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-28 18:40 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
2026-09-19 10:24 ` sashiko-bot
2026-09-28 18:40 ` Leon Romanovsky
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox