* [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
@ 2026-10-05 0:25 Haitam Lazaar
2026-10-05 0:35 ` sashiko-bot
2026-10-05 11:31 ` Bernard Metzler
0 siblings, 2 replies; 6+ messages in thread
From: Haitam Lazaar @ 2026-10-05 0:25 UTC (permalink / raw)
To: Bernard Metzler; +Cc: Jason Gunthorpe, Leon Romanovsky, linux-rdma, stable
When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
siw_check_sgl_tx() unconditionally passes 0 as the required permission
mask:
/* Reference memory to be tx'd w/o checking access for LOCAL_READ */
rv = siw_check_sgl_tx(qp->pd, wqe, 0);
Because perms is 0, siw_check_mem()'s authorization test:
if ((mem->perms & perms) < perms)
evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
an untrusted remote peer can issue an RDMA Read targeting any valid
STag in the Protection Domain, even if the memory was registered strictly
as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
perms = 0 for standard local sends.
Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
Cc: stable@vger.kernel.org
Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
---
drivers/infiniband/sw/siw/siw_qp_tx.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_tx.c b/drivers/infiniband/sw/siw/siw_qp_tx.c
index f7dd32c6e5ba..9e652585f904 100644
--- a/drivers/infiniband/sw/siw/siw_qp_tx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_tx.c
@@ -810,12 +810,17 @@ static int siw_qp_sq_proc_tx(struct siw_qp *qp, struct siw_wqe *wqe)
if (tx_type(wqe) != SIW_OP_READ &&
tx_type(wqe) != SIW_OP_READ_LOCAL_INV) {
+ enum ib_access_flags perms = 0;
+
/*
- * Reference memory to be tx'd w/o checking
- * access for LOCAL_READ permission, since
- * not defined in RDMA core.
+ * Local READ permission doesn't exist in RDMA core.
+ * A READ RESPONSE source is read by the remote peer,
+ * so it must be checked for REMOTE_READ permission.
*/
- rv = siw_check_sgl_tx(qp->pd, wqe, 0);
+ if (tx_type(wqe) == SIW_OP_READ_RESPONSE)
+ perms = IB_ACCESS_REMOTE_READ;
+
+ rv = siw_check_sgl_tx(qp->pd, wqe, perms);
if (rv < 0) {
if (tx_type(wqe) ==
SIW_OP_READ_RESPONSE)
--
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
2026-10-05 0:25 [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses Haitam Lazaar
@ 2026-10-05 0:35 ` sashiko-bot
2026-10-05 11:31 ` Bernard Metzler
1 sibling, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-10-05 0:35 UTC (permalink / raw)
To: Haitam Lazaar; +Cc: linux-rdma
> When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
> siw_check_sgl_tx() unconditionally passes 0 as the required permission
> mask:
>
> /* Reference memory to be tx'd w/o checking access for LOCAL_READ */
> rv = siw_check_sgl_tx(qp->pd, wqe, 0);
>
> Because perms is 0, siw_check_mem()'s authorization test:
> if ((mem->perms & perms) < perms)
> evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
> an untrusted remote peer can issue an RDMA Read targeting any valid
> STag in the Protection Domain, even if the memory was registered strictly
> as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
>
> Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
> when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
> perms = 0 for standard local sends.
>
> Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
> Cc: stable@vger.kernel.org
> Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/1a10973a2a8.17e04b672219.8760522594078806286@lazaarsec.com?part=1
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
2026-10-05 0:25 [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses Haitam Lazaar
2026-10-05 0:35 ` sashiko-bot
@ 2026-10-05 11:31 ` Bernard Metzler
2026-10-05 15:18 ` [PATCH v2 " Haitam Lazaar
1 sibling, 1 reply; 6+ messages in thread
From: Bernard Metzler @ 2026-10-05 11:31 UTC (permalink / raw)
To: Haitam Lazaar; +Cc: Jason Gunthorpe, Leon Romanovsky, linux-rdma, stable
On 05.10.2026 02:25, Haitam Lazaar wrote:
> When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
> siw_check_sgl_tx() unconditionally passes 0 as the required permission
> mask:
>
> /* Reference memory to be tx'd w/o checking access for LOCAL_READ */
> rv = siw_check_sgl_tx(qp->pd, wqe, 0);
>
> Because perms is 0, siw_check_mem()'s authorization test:
> if ((mem->perms & perms) < perms)
> evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
> an untrusted remote peer can issue an RDMA Read targeting any valid
> STag in the Protection Domain, even if the memory was registered strictly
> as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
>
> Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
> when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
> perms = 0 for standard local sends.
>
> Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
> Cc: stable@vger.kernel.org
> Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
> ---
> drivers/infiniband/sw/siw/siw_qp_tx.c | 13 +++++++++----
> 1 file changed, 9 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/infiniband/sw/siw/siw_qp_tx.c b/drivers/infiniband/sw/siw/siw_qp_tx.c
> index f7dd32c6e5ba..9e652585f904 100644
> --- a/drivers/infiniband/sw/siw/siw_qp_tx.c
> +++ b/drivers/infiniband/sw/siw/siw_qp_tx.c
> @@ -810,12 +810,17 @@ static int siw_qp_sq_proc_tx(struct siw_qp *qp, struct siw_wqe *wqe)
>
> if (tx_type(wqe) != SIW_OP_READ &&
> tx_type(wqe) != SIW_OP_READ_LOCAL_INV) {
> + enum ib_access_flags perms = 0;
> +
> /*
> - * Reference memory to be tx'd w/o checking
> - * access for LOCAL_READ permission, since
> - * not defined in RDMA core.
> + * Local READ permission doesn't exist in RDMA core.
> + * A READ RESPONSE source is read by the remote peer,
> + * so it must be checked for REMOTE_READ permission.
> */
> - rv = siw_check_sgl_tx(qp->pd, wqe, 0);
> + if (tx_type(wqe) == SIW_OP_READ_RESPONSE)
> + perms = IB_ACCESS_REMOTE_READ;
> +
> + rv = siw_check_sgl_tx(qp->pd, wqe, perms);
> if (rv < 0) {
> if (tx_type(wqe) ==
> SIW_OP_READ_RESPONSE)
Excellent finding! You may further compact the code by
moving the test and set...
if (tx_type(wqe) == SIW_OP_READ_RESPONSE)
wqe->sqe.num_sge = 1;
.. from a few lines above and merge it with the new 'perms'
assignmnet like:
if (tx_type(wqe) == SIW_OP_READ_RESPONSE) {
perms = IB_ACCESS_REMOTE_READ;
wqe->sqe.num_sge = 1;
}
Thanks,
Bernard.
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH v2 for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
2026-10-05 11:31 ` Bernard Metzler
@ 2026-10-05 15:18 ` Haitam Lazaar
2026-10-05 15:28 ` sashiko-bot
2026-10-06 12:36 ` Bernard Metzler
0 siblings, 2 replies; 6+ messages in thread
From: Haitam Lazaar @ 2026-10-05 15:18 UTC (permalink / raw)
To: Bernard Metzler; +Cc: Jason Gunthorpe, Leon Romanovsky, linux-rdma, stable
When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
siw_check_sgl_tx() unconditionally passes 0 as the required permission
mask:
/* Reference memory to be tx'd w/o checking access for LOCAL_READ */
rv = siw_check_sgl_tx(qp->pd, wqe, 0);
Because perms is 0, siw_check_mem()'s authorization test:
if ((mem->perms & perms) < perms)
evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
an untrusted remote peer can issue an RDMA Read targeting any valid
STag in the Protection Domain, even if the memory was registered strictly
as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
perms = 0 for standard local sends.
Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
Cc: stable@vger.kernel.org
Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
---
v1 -> v2:
- Compact READ_RESPONSE handling by combining num_sge and perms assignment
as suggested by Bernard Metzler.
drivers/infiniband/sw/siw/siw_qp_tx.c | 18 +++++++++++-------
1 file changed, 11 insertions(+), 7 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_qp_tx.c b/drivers/infiniband/sw/siw/siw_qp_tx.c
index f7dd32c6e5ba..7dac144cc903 100644
--- a/drivers/infiniband/sw/siw/siw_qp_tx.c
+++ b/drivers/infiniband/sw/siw/siw_qp_tx.c
@@ -805,17 +805,21 @@ static int siw_qp_sq_proc_tx(struct siw_qp *qp, struct siw_wqe *wqe)
if (wqe->wr_status == SIW_WR_QUEUED) {
if (!(wqe->sqe.flags & SIW_WQE_INLINE)) {
- if (tx_type(wqe) == SIW_OP_READ_RESPONSE)
- wqe->sqe.num_sge = 1;
-
if (tx_type(wqe) != SIW_OP_READ &&
tx_type(wqe) != SIW_OP_READ_LOCAL_INV) {
+ enum ib_access_flags perms = 0;
+
/*
- * Reference memory to be tx'd w/o checking
- * access for LOCAL_READ permission, since
- * not defined in RDMA core.
+ * Local READ permission doesn't exist in RDMA core.
+ * A READ RESPONSE source is read by the remote peer,
+ * so it must be checked for REMOTE_READ permission.
*/
- rv = siw_check_sgl_tx(qp->pd, wqe, 0);
+ if (tx_type(wqe) == SIW_OP_READ_RESPONSE) {
+ perms = IB_ACCESS_REMOTE_READ;
+ wqe->sqe.num_sge = 1;
+ }
+
+ rv = siw_check_sgl_tx(qp->pd, wqe, perms);
if (rv < 0) {
if (tx_type(wqe) ==
SIW_OP_READ_RESPONSE)
--
2.43.0
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH v2 for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
2026-10-05 15:18 ` [PATCH v2 " Haitam Lazaar
@ 2026-10-05 15:28 ` sashiko-bot
2026-10-06 12:36 ` Bernard Metzler
1 sibling, 0 replies; 6+ messages in thread
From: sashiko-bot @ 2026-10-05 15:28 UTC (permalink / raw)
To: Haitam Lazaar; +Cc: linux-rdma
> When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
> siw_check_sgl_tx() unconditionally passes 0 as the required permission
> mask:
>
> /* Reference memory to be tx'd w/o checking access for LOCAL_READ */
> rv = siw_check_sgl_tx(qp->pd, wqe, 0);
>
> Because perms is 0, siw_check_mem()'s authorization test:
> if ((mem->perms & perms) < perms)
> evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
> an untrusted remote peer can issue an RDMA Read targeting any valid
> STag in the Protection Domain, even if the memory was registered strictly
> as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
>
> Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
> when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
> perms = 0 for standard local sends.
>
> Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
> Cc: stable@vger.kernel.org
> Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/1a10ca50b82.4c79b9977088.8671544618706545172@lazaarsec.com?part=1
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH v2 for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses
2026-10-05 15:18 ` [PATCH v2 " Haitam Lazaar
2026-10-05 15:28 ` sashiko-bot
@ 2026-10-06 12:36 ` Bernard Metzler
1 sibling, 0 replies; 6+ messages in thread
From: Bernard Metzler @ 2026-10-06 12:36 UTC (permalink / raw)
To: Haitam Lazaar; +Cc: Jason Gunthorpe, Leon Romanovsky, linux-rdma, stable
On 05.10.2026 17:18, Haitam Lazaar wrote:
> When generating an RDMA READ response (SIW_OP_READ_RESPONSE),
> siw_check_sgl_tx() unconditionally passes 0 as the required permission
> mask:
>
> /* Reference memory to be tx'd w/o checking access for LOCAL_READ */
> rv = siw_check_sgl_tx(qp->pd, wqe, 0);
>
> Because perms is 0, siw_check_mem()'s authorization test:
> if ((mem->perms & perms) < perms)
> evaluates to (mem->perms & 0) < 0, which is always false. Consequently,
> an untrusted remote peer can issue an RDMA Read targeting any valid
> STag in the Protection Domain, even if the memory was registered strictly
> as write-only (IB_ACCESS_REMOTE_WRITE) without IB_ACCESS_REMOTE_READ.
>
> Enforce that the target memory region was granted IB_ACCESS_REMOTE_READ
> when answering SIW_OP_READ_RESPONSE work queue entries, while preserving
> perms = 0 for standard local sends.
>
> Fixes: b9be6f18cf9e ("rdma/siw: transmit path")
> Cc: stable@vger.kernel.org
> Signed-off-by: Haitam Lazaar <haitam@lazaarsec.com>
> ---
> v1 -> v2:
> - Compact READ_RESPONSE handling by combining num_sge and perms assignment
> as suggested by Bernard Metzler.
>
> drivers/infiniband/sw/siw/siw_qp_tx.c | 18 +++++++++++-------
> 1 file changed, 11 insertions(+), 7 deletions(-)
>
> diff --git a/drivers/infiniband/sw/siw/siw_qp_tx.c b/drivers/infiniband/sw/siw/siw_qp_tx.c
> index f7dd32c6e5ba..7dac144cc903 100644
> --- a/drivers/infiniband/sw/siw/siw_qp_tx.c
> +++ b/drivers/infiniband/sw/siw/siw_qp_tx.c
> @@ -805,17 +805,21 @@ static int siw_qp_sq_proc_tx(struct siw_qp *qp, struct siw_wqe *wqe)
>
> if (wqe->wr_status == SIW_WR_QUEUED) {
> if (!(wqe->sqe.flags & SIW_WQE_INLINE)) {
> - if (tx_type(wqe) == SIW_OP_READ_RESPONSE)
> - wqe->sqe.num_sge = 1;
> -
> if (tx_type(wqe) != SIW_OP_READ &&
> tx_type(wqe) != SIW_OP_READ_LOCAL_INV) {
> + enum ib_access_flags perms = 0;
> +
> /*
> - * Reference memory to be tx'd w/o checking
> - * access for LOCAL_READ permission, since
> - * not defined in RDMA core.
> + * Local READ permission doesn't exist in RDMA core.
> + * A READ RESPONSE source is read by the remote peer,
> + * so it must be checked for REMOTE_READ permission.
> */
> - rv = siw_check_sgl_tx(qp->pd, wqe, 0);
> + if (tx_type(wqe) == SIW_OP_READ_RESPONSE) {
> + perms = IB_ACCESS_REMOTE_READ;
> + wqe->sqe.num_sge = 1;
> + }
> +
> + rv = siw_check_sgl_tx(qp->pd, wqe, perms);
> if (rv < 0) {
> if (tx_type(wqe) ==
> SIW_OP_READ_RESPONSE)
Great, thanks!
Acked-by: Bernard Metzler <bernard.metzler@linux.dev>
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-06 12:36 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 0:25 [PATCH for-rc] RDMA/siw: Enforce IB_ACCESS_REMOTE_READ for read responses Haitam Lazaar
2026-10-05 0:35 ` sashiko-bot
2026-10-05 11:31 ` Bernard Metzler
2026-10-05 15:18 ` [PATCH v2 " Haitam Lazaar
2026-10-05 15:28 ` sashiko-bot
2026-10-06 12:36 ` Bernard Metzler
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox