From: sashiko-bot@kernel.org
To: "Yehyeong Lee" <yhlee@isslab.korea.ac.kr>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH] RDMA/rxe: check the PD when invalidating an MR or MW
Date: Tue, 29 Sep 2026 03:29:32 +0000 [thread overview]
Message-ID: <20260929032932.70BEB1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929031811.1550334-1-yhlee@isslab.korea.ac.kr>
> rxe_invalidate_mr() and rxe_invalidate_mw() look the object up by index in
> the device-wide pool and then only compare the key, so a QP can invalidate
> an MR or MW that belongs to a different protection domain on the same rxe
> device. Both entry points are affected: IB_WR_LOCAL_INV from the requester
> and SEND_WITH_INVALIDATE from the responder, where the rkey comes off the
> wire.
>
> Everything else that resolves one of these objects already refuses a
> foreign PD. lookup_mr() rejects mr_pd(mr) != pd, rxe_reg_fast_mr() rejects
> qp->ibqp.pd != mr->ibmr.pd, and rxe_check_bind_mw() was given the same
> check in commit fbbe1d5cd7d4 ("RDMA/rxe: Check PDs for memory window
> binds"). Remote access is therefore scoped to a PD while remote
> invalidation is not.
>
> A peer on one connection can invalidate a kernel ULP's fast-reg MR on
> another, which ends that ULP's I/O. Reject a foreign PD in both
> functions; -EINVAL turns into RESPST_ERR_INVALIDATE_RKEY for the
> responder and a failed work request for the requester.
>
> The MR side has behaved this way since the driver was merged, where
> do_complete() freed the MR it found by index; rxe_invalidate_mw() arrived
> later carrying the same omission.
>
> Fixes: 8700e3e7c485 ("Soft RoCE driver")
> Cc: stable@vger.kernel.org
> Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929031811.1550334-1-yhlee@isslab.korea.ac.kr?part=1
prev parent reply other threads:[~2026-09-29 3:29 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 3:18 [PATCH] RDMA/rxe: check the PD when invalidating an MR or MW Yehyeong Lee
2026-09-29 3:29 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929032932.70BEB1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yhlee@isslab.korea.ac.kr \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox