Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
@ 2026-09-19 10:08 lirongqing
  2026-09-19 10:24 ` sashiko-bot
  2026-09-28 18:40 ` Leon Romanovsky
  0 siblings, 2 replies; 3+ messages in thread
From: lirongqing @ 2026-09-19 10:08 UTC (permalink / raw)
  To: Leon Romanovsky, Jason Gunthorpe, linux-rdma; +Cc: Li RongQing

From: Li RongQing <lirongqing@baidu.com>

In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
so set_pi_umr_wr can read it during this call. The pointer is never
restored, so after the function returns mr->pi_mr dangles at a freed stack
frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
remapping reads the stale pointer and dereferences it.

Save the original pi_mr (captured at function entry) and restore it on
the out path.

Fixes: 2563e2f30acb ("RDMA/mlx5: Use PA mapping for PI handover")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
---
 drivers/infiniband/hw/mlx5/wr.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/infiniband/hw/mlx5/wr.c b/drivers/infiniband/hw/mlx5/wr.c
index fca9e1d..bb2c603 100644
--- a/drivers/infiniband/hw/mlx5/wr.c
+++ b/drivers/infiniband/hw/mlx5/wr.c
@@ -927,6 +927,7 @@ static noinline_for_stack int handle_reg_mr_integrity(struct mlx5_ib_dev *dev,
 	qp->next_fence = MLX5_FENCE_MODE_INITIATOR_SMALL;
 
 out:
+	mr->pi_mr = pi_mr;
 	return err;
 }
 
-- 
2.9.4


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
  2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
@ 2026-09-19 10:24 ` sashiko-bot
  2026-09-28 18:40 ` Leon Romanovsky
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-19 10:24 UTC (permalink / raw)
  To: lirongqing; +Cc: linux-rdma

> From: Li RongQing <lirongqing@baidu.com>
> 
> In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
> optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
> so set_pi_umr_wr can read it during this call. The pointer is never
> restored, so after the function returns mr->pi_mr dangles at a freed stack
> frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
> remapping reads the stale pointer and dereferences it.
> 
> Save the original pi_mr (captured at function entry) and restore it on
> the out path.
> 
> Fixes: 2563e2f30acb ("RDMA/mlx5: Use PA mapping for PI handover")
> Signed-off-by: Li RongQing <lirongqing@baidu.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260919100848.2442-1-lirongqing@baidu.com?part=1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
  2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
  2026-09-19 10:24 ` sashiko-bot
@ 2026-09-28 18:40 ` Leon Romanovsky
  1 sibling, 0 replies; 3+ messages in thread
From: Leon Romanovsky @ 2026-09-28 18:40 UTC (permalink / raw)
  To: Jason Gunthorpe, linux-rdma, lirongqing


On Sat, 19 Sep 2026 18:08:48 +0800, lirongqing wrote:
> In handle_reg_mr_integrity, when mr->pi_mr is NULL (physical-address
> optimization path), the code points mr->pi_mr at a stack-local pa_pi_mr
> so set_pi_umr_wr can read it during this call. The pointer is never
> restored, so after the function returns mr->pi_mr dangles at a freed stack
> frame. A second IB_WR_REG_MR_INTEGRITY posted on the same MR without
> remapping reads the stale pointer and dereferences it.
> 
> [...]

Applied, thanks!

[1/1] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment
      https://git.kernel.org/rdma/rdma/c/9728effe43d8fc

Best regards,
-- 
Leon Romanovsky <leon@kernel.org>


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28 18:40 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19 10:08 [PATCH] RDMA/mlx5: Restore mr->pi_mr after temporary stack-local assignment lirongqing
2026-09-19 10:24 ` sashiko-bot
2026-09-28 18:40 ` Leon Romanovsky

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox