* [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot
@ 2026-10-07 6:30 Sung Byeongchan
2026-10-07 6:46 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: Sung Byeongchan @ 2026-10-07 6:30 UTC (permalink / raw)
To: Zhu Yanjun, Jason Gunthorpe, Leon Romanovsky; +Cc: linux-rdma
Receive WQEs are held in queues which are writable by userspace. The
responder bounds num_sge before copying a WQE to its private snapshot, but
does not validate cur_sge. A non-empty SEND can therefore make copy_data()
select SGE metadata outside the populated receive SGE array.
Validate the immutable snapshot before installing it in the responder.
Require the copied num_sge to match the value used to size the copy and
require cur_sge to name a populated SGE whenever residual data remains.
Apply the same checks to per-QP and shared receive queues.
This was found by source review with AI assistance. An unprivileged
RXE queue owner reproduced a kernel fault twice with num_sge set to 1,
resid set to 8, and cur_sge set to UINT_MAX. The fixed kernel rejected
that WQE, while an ordinary eight-byte receive completed successfully.
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Sung Byeongchan <tjdqudcks0424@naver.com>
---
drivers/infiniband/sw/rxe/rxe_resp.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 02b16e2b49b8f..f059434eead13 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -288,8 +288,15 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
}
size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
memcpy(&qp->resp.srq_wqe, wqe, size);
+ wqe = &qp->resp.srq_wqe.wqe;
+ if (unlikely(wqe->dma.num_sge != num_sge ||
+ (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
+ spin_unlock_irqrestore(&srq->rq.consumer_lock, flags);
+ rxe_dbg_qp(qp, "invalid num_sge/cur_sge in SRQ entry\n");
+ return RESPST_ERR_MALFORMED_WQE;
+ }
- qp->resp.wqe = &qp->resp.srq_wqe.wqe;
+ qp->resp.wqe = wqe;
queue_advance_consumer(q, QUEUE_TYPE_FROM_CLIENT);
count = queue_count(q, QUEUE_TYPE_FROM_CLIENT);
@@ -328,8 +335,14 @@ static enum resp_states rxe_get_recv_wqe(struct rxe_qp *qp)
}
size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
memcpy(&qp->resp.srq_wqe, wqe, size);
+ wqe = &qp->resp.srq_wqe.wqe;
+ if (unlikely(wqe->dma.num_sge != num_sge ||
+ (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
+ rxe_dbg_qp(qp, "invalid num_sge/cur_sge in recv WQE\n");
+ return RESPST_ERR_MALFORMED_WQE;
+ }
- qp->resp.wqe = &qp->resp.srq_wqe.wqe;
+ qp->resp.wqe = wqe;
return RESPST_CHK_LENGTH;
}
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot
2026-10-07 6:30 [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot Sung Byeongchan
@ 2026-10-07 6:46 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-10-07 6:46 UTC (permalink / raw)
To: Sung Byeongchan; +Cc: linux-rdma
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] rdma/rxe: malformed WQE check wedges SRQ and drops error CQE
- [High] rxe: Missing READ_ONCE() on user-mapped num_sge allows double-fetch
--
commit 9a901f2aad88cef9dab9b3e49e87d7bb3dc7cd00
Author: Sung Byeongchan <tjdqudcks0424@naver.com>
RDMA/rxe: validate receive WQE cursor after snapshot
This commit adds validation for the receive WQE cursor before installing the
snapshot in the responder. It ensures that the copied num_sge matches the
size used for the copy and requires cur_sge to be within bounds. The checks
are applied to both per-QP and shared receive queues.
> diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
> index 02b16e2b49b8f..f059434eead13 100644
> --- a/drivers/infiniband/sw/rxe/rxe_resp.c
> +++ b/drivers/infiniband/sw/rxe/rxe_resp.c
> @@ -288,8 +288,15 @@ static enum resp_states get_srq_wqe(struct rxe_qp *qp)
> }
> size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
[Severity: High]
Since num_sge is read from user-mapped memory in wqe->dma.num_sge earlier in
the function without READ_ONCE(), can the compiler re-fetch the value for this
size calculation or the snapshot validation check below?
If the compiler re-fetches the value after a malicious user modifies it, could
it lead to a heap buffer overflow in memcpy(), or bypass the
wqe->dma.num_sge != num_sge equality check?
> memcpy(&qp->resp.srq_wqe, wqe, size);
> + wqe = &qp->resp.srq_wqe.wqe;
> + if (unlikely(wqe->dma.num_sge != num_sge ||
> + (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
> + spin_unlock_irqrestore(&srq->rq.consumer_lock, flags);
> + rxe_dbg_qp(qp, "invalid num_sge/cur_sge in SRQ entry\n");
> + return RESPST_ERR_MALFORMED_WQE;
> + }
[Severity: High]
If we return early here, we skip calling queue_advance_consumer(). Will this
permanently wedge the shared receive queue because the malformed WQE is never
consumed, potentially causing a denial of service to all other connections
sharing this queue?
Additionally, because qp->resp.wqe is never set, when do_complete() is called
later:
drivers/infiniband/sw/rxe/rxe_resp.c:do_complete() {
...
if (!wqe)
goto finish;
...
}
Will this incorrectly skip generating the mandatory error CQE for the
malformed WQE, violating the IB specification (Section 10.8.3.1)?
>
> - qp->resp.wqe = &qp->resp.srq_wqe.wqe;
> + qp->resp.wqe = wqe;
> queue_advance_consumer(q, QUEUE_TYPE_FROM_CLIENT);
> count = queue_count(q, QUEUE_TYPE_FROM_CLIENT);
[ ... ]
> @@ -328,8 +335,14 @@ static enum resp_states rxe_get_recv_wqe(struct rxe_qp *qp)
> }
> size = sizeof(*wqe) + num_sge * sizeof(struct rxe_sge);
> memcpy(&qp->resp.srq_wqe, wqe, size);
> + wqe = &qp->resp.srq_wqe.wqe;
> + if (unlikely(wqe->dma.num_sge != num_sge ||
> + (wqe->dma.resid && wqe->dma.cur_sge >= num_sge))) {
> + rxe_dbg_qp(qp, "invalid num_sge/cur_sge in recv WQE\n");
> + return RESPST_ERR_MALFORMED_WQE;
> + }
[Severity: High]
Similarly to get_srq_wqe(), does returning here without setting qp->resp.wqe
cause do_complete() to skip generating the proper error CQE?
While the WQE is eventually consumed by flush_recv_queue() for normal QPs,
does skipping do_complete() here result in an incorrect generic flush error
CQE instead of the required local QP operation error CQE?
>
> - qp->resp.wqe = &qp->resp.srq_wqe.wqe;
> + qp->resp.wqe = wqe;
> return RESPST_CHK_LENGTH;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261007063029.26073-1-tjdqudcks0424@naver.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 6:46 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 6:30 [PATCH] RDMA/rxe: validate receive WQE cursor after snapshot Sung Byeongchan
2026-10-07 6:46 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox