From: Tristan Madani <tristmd@gmail.com>
To: Zhu Yanjun <zyjzyj2000@gmail.com>, Jason Gunthorpe <jgg@ziepe.ca>,
Leon Romanovsky <leon@kernel.org>
Cc: linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org,
stable@vger.kernel.org,
Tristan Madani <tristan@talencesecurity.com>
Subject: [PATCH v5 0/2] RDMA/rxe: fix send-path TOCTOU races on shared WQEs
Date: Thu, 8 Oct 2026 09:37:38 +0000 [thread overview]
Message-ID: <20261008093740.3034881-1-tristmd@gmail.com> (raw)
In-Reply-To: <20261007223222.2342804-1-tristmd@gmail.com>
From: Tristan Madani <tristan@talencesecurity.com>
The rxe driver maps send queues into userspace. Both the requester and
completer read Work Queue Entries (WQEs) directly from this shared
buffer. Userspace can modify WQE fields between kernel reads, causing
inconsistent state in copy_data() and related paths.
This series copies the send WQE to kernel-private buffers, mirroring
the receive-path fixes (commits 22b8fbded65b8 and d6ab440240a04).
Changes v4 -> v5:
- Use qp->sq.max_inline instead of qp->sq.max_sge * sizeof(rxe_sge)
for the copy size, avoiding integer division truncation when
max_inline_data is not a multiple of sizeof(struct ib_sge)
Changes v3 -> v4:
- Use full queue element size (max_sge SGEs) for the copy instead of
per-WQE num_sge. Eliminates inline data gap, sizeof mismatch, and
simplifies both patches
- Invalidate requester copy on ERR flush path before writing status
to shared memory (prevents writeback from clobbering error state)
- Invalidate both caches on QP reset (rxe_qp.c changes added)
Changes v2 -> v3:
- Add completer-path copy (patch 2/2) to close the remaining TOCTOU
window. The completer was still reading directly from shared memory
- Add smp_load_acquire()/smp_store_release() for state transitions
between requester and completer
Changes v1 -> v2:
- Added writeback mechanism using WRITE_ONCE() and smp_store_release()
- Reuse kernel copy across multi-packet sends to preserve DMA state
- Invalidate on retry, QP reset, and error paths
Tristan Madani (2):
RDMA/rxe: copy send WQE to kernel buffer before processing
RDMA/rxe: copy send WQE to kernel buffer in completer path
drivers/infiniband/sw/rxe/rxe_comp.c | 53 ++++++++++++++++++++++++++++--
drivers/infiniband/sw/rxe/rxe_qp.c | 2 ++
drivers/infiniband/sw/rxe/rxe_req.c | 55 ++++++++++++++++++++++++++++++---
drivers/infiniband/sw/rxe/rxe_verbs.h | 12 ++++++++
4 files changed, 116 insertions(+), 6 deletions(-)
--
2.39.5
next prev parent reply other threads:[~2026-10-08 9:37 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 22:32 [PATCH v4 0/2] RDMA/rxe: fix TOCTOU races in send WQE processing Tristan Madani
2026-10-07 22:32 ` [PATCH v4 1/2] RDMA/rxe: copy send WQE to kernel buffer before processing Tristan Madani
2026-10-07 22:47 ` sashiko-bot
2026-10-07 22:32 ` [PATCH v4 2/2] RDMA/rxe: copy send WQE to kernel buffer in completer path Tristan Madani
2026-10-07 22:48 ` sashiko-bot
2026-10-08 5:11 ` [PATCH v4 0/2] RDMA/rxe: fix TOCTOU races in send WQE processing Zhu Yanjun
2026-10-08 12:01 ` Tristan Madani
2026-10-08 19:34 ` Zhu Yanjun
2026-10-08 9:37 ` Tristan Madani [this message]
2026-10-08 9:37 ` [PATCH v5 1/2] RDMA/rxe: copy send WQE to kernel buffer before processing Tristan Madani
2026-10-08 9:54 ` sashiko-bot
2026-10-08 9:37 ` [PATCH v5 2/2] RDMA/rxe: copy send WQE to kernel buffer in completer path Tristan Madani
2026-10-08 9:55 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008093740.3034881-1-tristmd@gmail.com \
--to=tristmd@gmail.com \
--cc=jgg@ziepe.ca \
--cc=leon@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=tristan@talencesecurity.com \
--cc=zyjzyj2000@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox