From: Allison Henderson <achender@kernel.org>
To: netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
pabeni@redhat.com, edumazet@google.com, kuba@kernel.org,
horms@kernel.org
Cc: achender@kernel.org, ljp1205831794@gmail.com, henrymei@tencent.com
Subject: [PATCH net v4 0/2] net/rds: RDMA-CM event handler fixes for non-IB devices
Date: Sat, 3 Oct 2026 09:34:06 -0700 [thread overview]
Message-ID: <20261003163408.250568-1-achender@kernel.org> (raw)
Hi all,
This is v4 of Aohan Mei's fix for the uninitialized transport pointer
in the RDMA-CM event handler (v1 at [1], v2 at [2], v3 at [3]), now a
two-patch set.
Patch 1 is the fix itself. v3 only rejected a connect request
arriving on a non-IB device; the active side can bind an id to one
as well, and resolving a route on an iWARP id leaves
cm_id->route.path_rec unset, which the ROUTE_RESOLVED case
dereferences. Such a connection is now dropped at ADDR_RESOLVED
instead of resolving a route.
Patch 2 fixes a neighbouring problem in the same case: a synchronous
rdma_resolve_route() failure was handed back to the rdma_cm, which
then destroyed an id RDS still owns as ic->i_cm_id and would later
disconnect and destroy again from the connection's shutdown.
On net-next the rdma_cm ids RDS creates are restricted to IB devices
(commit c7fca8aae6fe), which makes the non-IB cases impossible there;
these are the fixes stable kernels without that API need.
Changes since v3 [3]:
- Patch 1 also drops a connection whose address resolved to a non-IB
device, before a route is resolved on it (review of v3).
- New patch 2 for the rdma_resolve_route() failure return.
- Rebased onto current net.
Changes since v2 [2]:
- Carried forward; the rejection is limited to
RDMA_CM_EVENT_CONNECT_REQUEST so that rdma_cm does not destroy
connection ids RDS still owns.
[1] https://lore.kernel.org/netdev/20260824111701.2979194-1-ljp1205831794@gmail.com/
[2] https://lore.kernel.org/netdev/20260825021223.3483044-1-ljp1205831794@gmail.com/
[3] https://lore.kernel.org/netdev/20260928044507.335883-1-achender@kernel.org/
Thank you,
Allison
Allison Henderson (1):
net/rds: don't let the rdma_cm destroy an id RDS still owns on route
failure
Aohan Mei (1):
net: rds: fix uninitialized trans dereference in CM event handler
net/rds/rdma_transport.c | 38 +++++++++++++++++++++++++++++++++-----
1 file changed, 33 insertions(+), 5 deletions(-)
--
2.25.1
next reply other threads:[~2026-10-03 16:34 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-03 16:34 Allison Henderson [this message]
2026-10-03 16:34 ` [PATCH net v4 1/2] net: rds: fix uninitialized trans dereference in CM event handler Allison Henderson
2026-10-03 17:56 ` sashiko-bot
2026-10-03 16:34 ` [PATCH net v4 2/2] net/rds: don't let the rdma_cm destroy an id RDS still owns on route failure Allison Henderson
2026-10-03 17:56 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003163408.250568-1-achender@kernel.org \
--to=achender@kernel.org \
--cc=edumazet@google.com \
--cc=henrymei@tencent.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=ljp1205831794@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox