Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Allison Henderson" <achender@kernel.org>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH net-next v9 12/13] net/rds: pin the connection across RDMA-CM event handling
Date: Thu, 08 Oct 2026 03:32:20 +0000	[thread overview]
Message-ID: <sashiko-outbox-163552@kernel.org> (raw)
In-Reply-To: <20261008031333.1142174-13-achender@kernel.org>

> rds_rdma_cm_event_handler_cmn() picks the connection up from
> cm_id->context, which carries no reference, and holds c_cm_lock - a
> mutex that lives in the connection's path array - across the transport
> callbacks.  Before this series that was already a use-after-free
> whenever a callback destroyed the connection, since rds_conn_destroy()
> freed it synchronously and the handler's mutex_unlock() ran on freed
> memory; the one such callback, rds_ib_cm_connect_complete() on a
> protocol version below 3.1, has meanwhile been switched to
> rds_conn_drop() by commit f97d8c7bab78 ("rds: ib: use rds_conn_drop()
> on protocol version mismatch"), which also removed the deadlock that
> destroy took on c_cm_lock.
> 
> Now that a connection is freed by its last reference, none of the
> callbacks the handler dispatches drops a reference on the connection
> it was handed: the version-mismatch path only drops the connection,
> [ ... ]
> rds_ib_add_conn() refusing a device that rds_ib_dev_shutdown() has
> marked.
> 
> Assisted-by: Claude-Code:claude-fable-5
> Signed-off-by: Allison Henderson <achender@kernel.org>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008031333.1142174-1-achender@kernel.org?part=12


  reply	other threads:[~2026-10-08  3:32 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08  3:13 [PATCH net-next v9 00/13] net/rds: make connection lifetime reference-counted Allison Henderson
2026-10-08  3:13 ` [PATCH net-next v9 01/13] net/rds: ib: don't enable interrupts in rds_ib_conn_free() Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 02/13] net/rds: undo conn_alloc() the same way on every __rds_conn_create() exit Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 03/13] net/rds: ib: refuse to attach a connection to a device being removed Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 04/13] net/rds: guard every work-requeueing site with rds_destroy_pending() Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 05/13] net/rds: make rds_destroy_pending() report a connection's own destroy Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 06/13] net/rds: split connection destroy into quiesce and kref-governed free Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 07/13] net/rds: unlink transport nodes before a possibly deferred connection free Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 08/13] net/rds: wait for connections to be freed on transport unload Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 09/13] net/rds: hold a connection reference from struct rds_incoming Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 10/13] net/rds: take cp_lock to purge cp_send_queue in the quiesce Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 11/13] net/rds: hold connection references in lookup, sockets and c_passive Allison Henderson
2026-10-08  3:32   ` sashiko-bot
2026-10-08  3:13 ` [PATCH net-next v9 12/13] net/rds: pin the connection across RDMA-CM event handling Allison Henderson
2026-10-08  3:32   ` sashiko-bot [this message]
2026-10-08  3:13 ` [PATCH net-next v9 13/13] net/rds: drop rds_conn_count in favor of t_conn_count Allison Henderson
2026-10-08  3:32   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-163552@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=achender@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox