From: sashiko-bot@kernel.org
To: "Konstantin Taranov" <kotaranov@linux.microsoft.com>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH rdma-next 03/10] net/mana: Extend GDMA encoding for new RDMA WQEs
Date: Fri, 02 Oct 2026 09:13:04 +0000 [thread overview]
Message-ID: <20261002091305.2D76B1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20261001182015.1757203-4-kotaranov@linux.microsoft.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rdma/mana: Missing fixed WQE size validation causes ring buffer overflow
--
commit 8f045a852a650adae362c74de90d65ccaf6541d9
Author: Konstantin Taranov <kotaranov@microsoft.com>
net/mana: Extend GDMA encoding for new RDMA WQEs
This commit extends mana_gd_post_work_request() to support extra-large OOB
data and fixed-size WQEs. It encodes WQE header fields based on WR flags
and uses num_pad_sge to specify padding size for fixed-size WQEs.
> diff --git a/drivers/net/ethernet/microsoft/mana/gdma_main.c b/drivers/net/ethernet/microsoft/mana/gdma_main.c
> index 05ba7055405da..444101dcbb647 100644
> --- a/drivers/net/ethernet/microsoft/mana/gdma_main.c
> +++ b/drivers/net/ethernet/microsoft/mana/gdma_main.c
> @@ -1699,8 +1699,27 @@ static u32 mana_gd_write_client_oob(const struct gdma_wqe_request *wqe_req,
> header->num_sge = wqe_req->num_sge;
> header->inline_oob_size_div4 = client_oob_size / sizeof(u32);
>
> + if (client_oob_size == INLINE_OOB_EXTRA_LARGE_SIZE) {
> + /* Extra large oob is encoded as 7 */
> + header->inline_oob_size_div4 = 7;
> + /* Extra large oob has 8 byte padding */
> + client_oob_size += 8;
> + }
> +
> + if (wqe_req->wqe_size_in_bu) {
> + header->num_sge = (wqe_req->wqe_size_in_bu * GDMA_WQE_BU_SIZE
> + - sizeof(struct gdma_wqe) - client_oob_size) / sizeof(struct gdma_sge);
> + header->num_pad_sge = header->num_sge - wqe_req->num_sge;
[Severity: High]
Does this calculation risk silently underflowing if the fixed WQE size is too
small?
If a caller provides an undersized fixed WQE size, this subtraction could
underflow, which might corrupt the hardware descriptor bitfields and lead to an
out-of-bounds write of SGEs.
> + }
> +
> + header->check_rsn = !!(wqe_req->flags & GDMA_WR_CHECK_RSN);
[ ... ]
> @@ -1792,15 +1814,26 @@ int mana_gd_post_work_request(struct gdma_queue *wq,
> max_wqe_size = GDMA_MAX_RQE_SIZE;
> } else {
> if (client_oob_size != INLINE_OOB_SMALL_SIZE &&
> - client_oob_size != INLINE_OOB_LARGE_SIZE)
> + client_oob_size != INLINE_OOB_LARGE_SIZE &&
> + client_oob_size != INLINE_OOB_EXTRA_LARGE_SIZE)
> return -EINVAL;
>
> max_wqe_size = GDMA_MAX_SQE_SIZE;
> }
>
> sgl_data_size = sizeof(struct gdma_sge) * wqe_req->num_sge;
> - wqe_size = ALIGN(sizeof(struct gdma_wqe) + client_oob_size +
> - sgl_data_size, GDMA_WQE_BU_SIZE);
> + if (wqe_req->wqe_size_in_bu)
> + wqe_size = wqe_req->wqe_size_in_bu * GDMA_WQE_BU_SIZE;
[Severity: High]
Is it possible for the user-provided fixed WQE size to be accepted here
without verifying that it is actually large enough to contain the requested
SGEs and OOB payload?
If a caller creates a queue pair with a small max_send_sge (fixing the WQE
size) but posts a send work request with num_sge larger than max_send_sge,
could this bypass validation?
If this validation is missing, it appears it would cause the integer underflow
mentioned above in mana_gd_write_client_oob() and lead to an out-of-bounds
memory write during mana_gd_write_sgl().
> + else
> + wqe_size = ALIGN(sizeof(struct gdma_wqe) + client_oob_size +
> + sgl_data_size, GDMA_WQE_BU_SIZE);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001182015.1757203-1-kotaranov@linux.microsoft.com?part=3
next prev parent reply other threads:[~2026-10-02 9:13 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 18:20 [PATCH rdma-next 00/10] RDMA/mana_ib: Add kernel RC and fast registration support Konstantin Taranov
2026-10-01 18:20 ` [PATCH rdma-next 01/10] RDMA/mana_ib: Allocate and map fast-registration MRs Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 02/10] RDMA/mana: Create and destroy kernel RC QPs Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 03/10] net/mana: Extend GDMA encoding for new RDMA WQEs Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot [this message]
2026-10-01 18:20 ` [PATCH rdma-next 04/10] RDMA/mana_ib: Maintain kernel RC QP state Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 05/10] RDMA/mana_ib: Post receive WRs on kernel RC QPs Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 06/10] RDMA/mana_ib: Post send and memory-management WRs on " Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 07/10] RDMA/mana_ib: Poll RC completions using PSN and FSN progress Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 08/10] RDMA/mana_ib: Flush and notify CQs when kernel QPs enter ERR Konstantin Taranov
2026-10-02 9:12 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 09/10] RDMA/mana_ib: Handle error CQEs for RC QPs Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
2026-10-01 18:20 ` [PATCH rdma-next 10/10] RDMA/mana_ib: Drain kernel receive and send queues Konstantin Taranov
2026-10-02 9:13 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002091305.2D76B1F00899@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kotaranov@linux.microsoft.com \
--cc=linux-rdma@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox