Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yehyeong Lee" <yhlee@isslab.korea.ac.kr>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH] RDMA/rxe: check the PD when invalidating an MR or MW
Date: Tue, 29 Sep 2026 03:29:32 +0000	[thread overview]
Message-ID: <20260929032932.70BEB1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929031811.1550334-1-yhlee@isslab.korea.ac.kr>

> rxe_invalidate_mr() and rxe_invalidate_mw() look the object up by index in
> the device-wide pool and then only compare the key, so a QP can invalidate
> an MR or MW that belongs to a different protection domain on the same rxe
> device.  Both entry points are affected: IB_WR_LOCAL_INV from the requester
> and SEND_WITH_INVALIDATE from the responder, where the rkey comes off the
> wire.
> 
> Everything else that resolves one of these objects already refuses a
> foreign PD.  lookup_mr() rejects mr_pd(mr) != pd, rxe_reg_fast_mr() rejects
> qp->ibqp.pd != mr->ibmr.pd, and rxe_check_bind_mw() was given the same
> check in commit fbbe1d5cd7d4 ("RDMA/rxe: Check PDs for memory window
> binds").  Remote access is therefore scoped to a PD while remote
> invalidation is not.
> 
> A peer on one connection can invalidate a kernel ULP's fast-reg MR on
> another, which ends that ULP's I/O.  Reject a foreign PD in both
> functions; -EINVAL turns into RESPST_ERR_INVALIDATE_RKEY for the
> responder and a failed work request for the requester.
> 
> The MR side has behaved this way since the driver was merged, where
> do_complete() freed the MR it found by index; rxe_invalidate_mw() arrived
> later carrying the same omission.
> 
> Fixes: 8700e3e7c485 ("Soft RoCE driver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929031811.1550334-1-yhlee@isslab.korea.ac.kr?part=1


      reply	other threads:[~2026-09-29  3:29 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  3:18 [PATCH] RDMA/rxe: check the PD when invalidating an MR or MW Yehyeong Lee
2026-09-29  3:29 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929032932.70BEB1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yhlee@isslab.korea.ac.kr \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox