Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Konstantin Taranov" <kotaranov@linux.microsoft.com>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH rdma-next 03/10] net/mana: Extend GDMA encoding for new RDMA WQEs
Date: Fri, 02 Oct 2026 09:13:04 +0000	[thread overview]
Message-ID: <20261002091305.2D76B1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261001182015.1757203-4-kotaranov@linux.microsoft.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rdma/mana: Missing fixed WQE size validation causes ring buffer overflow
--

commit 8f045a852a650adae362c74de90d65ccaf6541d9
Author: Konstantin Taranov <kotaranov@microsoft.com>

net/mana: Extend GDMA encoding for new RDMA WQEs

This commit extends mana_gd_post_work_request() to support extra-large OOB
data and fixed-size WQEs. It encodes WQE header fields based on WR flags
and uses num_pad_sge to specify padding size for fixed-size WQEs.

> diff --git a/drivers/net/ethernet/microsoft/mana/gdma_main.c b/drivers/net/ethernet/microsoft/mana/gdma_main.c
> index 05ba7055405da..444101dcbb647 100644
> --- a/drivers/net/ethernet/microsoft/mana/gdma_main.c
> +++ b/drivers/net/ethernet/microsoft/mana/gdma_main.c
> @@ -1699,8 +1699,27 @@ static u32 mana_gd_write_client_oob(const struct gdma_wqe_request *wqe_req,
>  	header->num_sge = wqe_req->num_sge;
>  	header->inline_oob_size_div4 = client_oob_size / sizeof(u32);
>  
> +	if (client_oob_size == INLINE_OOB_EXTRA_LARGE_SIZE) {
> +		/* Extra large oob is encoded as 7 */
> +		header->inline_oob_size_div4 = 7;
> +		/* Extra large oob has 8 byte padding  */
> +		client_oob_size += 8;
> +	}
> +
> +	if (wqe_req->wqe_size_in_bu) {
> +		header->num_sge = (wqe_req->wqe_size_in_bu * GDMA_WQE_BU_SIZE
> +			- sizeof(struct gdma_wqe) - client_oob_size) / sizeof(struct gdma_sge);
> +		header->num_pad_sge = header->num_sge - wqe_req->num_sge;

[Severity: High]
Does this calculation risk silently underflowing if the fixed WQE size is too
small?

If a caller provides an undersized fixed WQE size, this subtraction could
underflow, which might corrupt the hardware descriptor bitfields and lead to an
out-of-bounds write of SGEs.

> +	}
> +
> +	header->check_rsn = !!(wqe_req->flags & GDMA_WR_CHECK_RSN);

[ ... ]

> @@ -1792,15 +1814,26 @@ int mana_gd_post_work_request(struct gdma_queue *wq,
>  		max_wqe_size = GDMA_MAX_RQE_SIZE;
>  	} else {
>  		if (client_oob_size != INLINE_OOB_SMALL_SIZE &&
> -		    client_oob_size != INLINE_OOB_LARGE_SIZE)
> +		    client_oob_size != INLINE_OOB_LARGE_SIZE &&
> +		    client_oob_size != INLINE_OOB_EXTRA_LARGE_SIZE)
>  			return -EINVAL;
>  
>  		max_wqe_size = GDMA_MAX_SQE_SIZE;
>  	}
>  
>  	sgl_data_size = sizeof(struct gdma_sge) * wqe_req->num_sge;
> -	wqe_size = ALIGN(sizeof(struct gdma_wqe) + client_oob_size +
> -			 sgl_data_size, GDMA_WQE_BU_SIZE);
> +	if (wqe_req->wqe_size_in_bu)
> +		wqe_size = wqe_req->wqe_size_in_bu * GDMA_WQE_BU_SIZE;

[Severity: High]
Is it possible for the user-provided fixed WQE size to be accepted here
without verifying that it is actually large enough to contain the requested
SGEs and OOB payload?

If a caller creates a queue pair with a small max_send_sge (fixing the WQE
size) but posts a send work request with num_sge larger than max_send_sge,
could this bypass validation?

If this validation is missing, it appears it would cause the integer underflow
mentioned above in mana_gd_write_client_oob() and lead to an out-of-bounds
memory write during mana_gd_write_sgl().

> +	else
> +		wqe_size = ALIGN(sizeof(struct gdma_wqe) + client_oob_size +
> +				 sgl_data_size, GDMA_WQE_BU_SIZE);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261001182015.1757203-1-kotaranov@linux.microsoft.com?part=3

  reply	other threads:[~2026-10-02  9:13 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 18:20 [PATCH rdma-next 00/10] RDMA/mana_ib: Add kernel RC and fast registration support Konstantin Taranov
2026-10-01 18:20 ` [PATCH rdma-next 01/10] RDMA/mana_ib: Allocate and map fast-registration MRs Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 02/10] RDMA/mana: Create and destroy kernel RC QPs Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 03/10] net/mana: Extend GDMA encoding for new RDMA WQEs Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot [this message]
2026-10-01 18:20 ` [PATCH rdma-next 04/10] RDMA/mana_ib: Maintain kernel RC QP state Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 05/10] RDMA/mana_ib: Post receive WRs on kernel RC QPs Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 06/10] RDMA/mana_ib: Post send and memory-management WRs on " Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 07/10] RDMA/mana_ib: Poll RC completions using PSN and FSN progress Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 08/10] RDMA/mana_ib: Flush and notify CQs when kernel QPs enter ERR Konstantin Taranov
2026-10-02  9:12   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 09/10] RDMA/mana_ib: Handle error CQEs for RC QPs Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 10/10] RDMA/mana_ib: Drain kernel receive and send queues Konstantin Taranov
2026-10-02  9:13   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002091305.2D76B1F00899@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kotaranov@linux.microsoft.com \
    --cc=linux-rdma@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox