Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH net v4 0/2] net/rds: RDMA-CM event handler fixes for non-IB devices
@ 2026-10-03 16:34 Allison Henderson
  2026-10-03 16:34 ` [PATCH net v4 1/2] net: rds: fix uninitialized trans dereference in CM event handler Allison Henderson
  2026-10-03 16:34 ` [PATCH net v4 2/2] net/rds: don't let the rdma_cm destroy an id RDS still owns on route failure Allison Henderson
  0 siblings, 2 replies; 5+ messages in thread
From: Allison Henderson @ 2026-10-03 16:34 UTC (permalink / raw)
  To: netdev, linux-rdma, pabeni, edumazet, kuba, horms
  Cc: achender, ljp1205831794, henrymei

Hi all,

This is v4 of Aohan Mei's fix for the uninitialized transport pointer
in the RDMA-CM event handler (v1 at [1], v2 at [2], v3 at [3]), now a
two-patch set.

  Patch 1 is the fix itself.  v3 only rejected a connect request
  arriving on a non-IB device; the active side can bind an id to one
  as well, and resolving a route on an iWARP id leaves
  cm_id->route.path_rec unset, which the ROUTE_RESOLVED case
  dereferences.  Such a connection is now dropped at ADDR_RESOLVED
  instead of resolving a route.

  Patch 2 fixes a neighbouring problem in the same case: a synchronous
  rdma_resolve_route() failure was handed back to the rdma_cm, which
  then destroyed an id RDS still owns as ic->i_cm_id and would later
  disconnect and destroy again from the connection's shutdown.

On net-next the rdma_cm ids RDS creates are restricted to IB devices
(commit c7fca8aae6fe), which makes the non-IB cases impossible there;
these are the fixes stable kernels without that API need.

Changes since v3 [3]:
 - Patch 1 also drops a connection whose address resolved to a non-IB
   device, before a route is resolved on it (review of v3).
 - New patch 2 for the rdma_resolve_route() failure return.
 - Rebased onto current net.

Changes since v2 [2]:
 - Carried forward; the rejection is limited to
   RDMA_CM_EVENT_CONNECT_REQUEST so that rdma_cm does not destroy
   connection ids RDS still owns.

[1] https://lore.kernel.org/netdev/20260824111701.2979194-1-ljp1205831794@gmail.com/
[2] https://lore.kernel.org/netdev/20260825021223.3483044-1-ljp1205831794@gmail.com/
[3] https://lore.kernel.org/netdev/20260928044507.335883-1-achender@kernel.org/

Thank you,
Allison


Allison Henderson (1):
  net/rds: don't let the rdma_cm destroy an id RDS still owns on route
    failure

Aohan Mei (1):
  net: rds: fix uninitialized trans dereference in CM event handler

 net/rds/rdma_transport.c | 38 +++++++++++++++++++++++++++++++++-----
 1 file changed, 33 insertions(+), 5 deletions(-)

-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-10-03 17:56 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-03 16:34 [PATCH net v4 0/2] net/rds: RDMA-CM event handler fixes for non-IB devices Allison Henderson
2026-10-03 16:34 ` [PATCH net v4 1/2] net: rds: fix uninitialized trans dereference in CM event handler Allison Henderson
2026-10-03 17:56   ` sashiko-bot
2026-10-03 16:34 ` [PATCH net v4 2/2] net/rds: don't let the rdma_cm destroy an id RDS still owns on route failure Allison Henderson
2026-10-03 17:56   ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox