Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH v4 0/2] RDMA/rxe: fix TOCTOU races in send WQE processing
@ 2026-10-07 22:32 Tristan Madani
  2026-10-07 22:32 ` [PATCH v4 1/2] RDMA/rxe: copy send WQE to kernel buffer before processing Tristan Madani
                   ` (3 more replies)
  0 siblings, 4 replies; 13+ messages in thread
From: Tristan Madani @ 2026-10-07 22:32 UTC (permalink / raw)
  To: linux-rdma; +Cc: jgg, leon, zyjzyj2000, bob.pearson, Tristan Madani

From: Tristan Madani <tristan@talencesecurity.com>

The SoftRoCE driver maps its send work queue into userspace for direct
posting. The kernel reads WQE fields directly from this shared mapping,
which allows a concurrent userspace thread to modify fields between
kernel reads -- classic TOCTOU.

This series copies each send WQE to a kernel-private buffer before
processing, in both the requester (patch 1) and completer (patch 2)
paths.

Changes since v3:
  - Copy the full queue element (max_sge SGEs) instead of computing a
    per-WQE copy size from num_sge. This ensures inline data (which
    shares the flex array with SGEs) is always captured, and eliminates
    a TOCTOU on the copy size itself.
  - Clamp dma.num_sge against qp->sq.max_sge after copy (patch 2)
    instead of against the global RXE_MAX_SGE constant.
  - Invalidate the cached copy on QP reset (rxe_qp_reset), on the
    ERR flush path, and on the RESET state check in the requester.
    This prevents stale-cache reuse after state transitions.
  - Each patch now also touches rxe_qp.c for the reset invalidation.

Changes since v2:
  - Addressed review comments on naming and ordering.
  - Writeback status using WRITE_ONCE() instead of plain store.
  - Added smp_store_release() in requester for state transitions.

Changes since v1:
  - Split into per-path patches (requester, completer).
  - Cache the local copy across retransmits and multi-packet operations.
  - Added writeback of completion status and rd_atomic state.

Tristan Madani (2):
  RDMA/rxe: copy send WQE to kernel buffer before processing
  RDMA/rxe: copy send WQE to kernel buffer in completer path

 drivers/infiniband/sw/rxe/rxe_comp.c  | 53 +++++++++++++++++++++++++-
 drivers/infiniband/sw/rxe/rxe_qp.c    |  2 +
 drivers/infiniband/sw/rxe/rxe_req.c   | 55 +++++++++++++++++++++++++--
 drivers/infiniband/sw/rxe/rxe_verbs.h | 12 ++++++
 4 files changed, 116 insertions(+), 6 deletions(-)

-- 
2.47.3

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-10-08 19:34 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 22:32 [PATCH v4 0/2] RDMA/rxe: fix TOCTOU races in send WQE processing Tristan Madani
2026-10-07 22:32 ` [PATCH v4 1/2] RDMA/rxe: copy send WQE to kernel buffer before processing Tristan Madani
2026-10-07 22:47   ` sashiko-bot
2026-10-07 22:32 ` [PATCH v4 2/2] RDMA/rxe: copy send WQE to kernel buffer in completer path Tristan Madani
2026-10-07 22:48   ` sashiko-bot
2026-10-08  5:11 ` [PATCH v4 0/2] RDMA/rxe: fix TOCTOU races in send WQE processing Zhu Yanjun
2026-10-08 12:01   ` Tristan Madani
2026-10-08 19:34     ` Zhu Yanjun
2026-10-08  9:37 ` [PATCH v5 0/2] RDMA/rxe: fix send-path TOCTOU races on shared WQEs Tristan Madani
2026-10-08  9:37   ` [PATCH v5 1/2] RDMA/rxe: copy send WQE to kernel buffer before processing Tristan Madani
2026-10-08  9:54     ` sashiko-bot
2026-10-08  9:37   ` [PATCH v5 2/2] RDMA/rxe: copy send WQE to kernel buffer in completer path Tristan Madani
2026-10-08  9:55     ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox