Linux s390 Architecture development
 help / color / mirror / Atom feed
From: Jiri Pirko <jiri@resnulli.us>
To: sashiko-reviews@lists.linux.dev
Cc: Vasily Gorbik <gor@linux.ibm.com>,
	tj@kernel.org,  Alexander Gordeev <agordeev@linux.ibm.com>,
	linux-s390@vger.kernel.org, hannes@cmpxchg.org,
	 Heiko Carstens <hca@linux.ibm.com>,
	mkoutny@suse.com
Subject: Re: [PATCH rdma-next v3 04/14] RDMA/nldev: Report net namespace move errors through extack
Date: Wed, 22 Jul 2026 13:17:42 +0200	[thread overview]
Message-ID: <amCmyqEQaMgJrtg5@FV6GYCPJ69> (raw)
In-Reply-To: <20260717132425.C9FBE1F00AC4@smtp.kernel.org>

Fri, Jul 17, 2026 at 03:24:25PM +0200, sashiko-bot@kernel.org wrote:
>Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>- [High] The newly added feature to support renaming an RDMA device while moving its network namespace is inaccessible from userspace due to a logic flaw in the netlink handler. Additionally, providing both attributes silently aborts the namespace move.
>--
>
>--- Patch [4]: [PATCH rdma-next v3 04/14] RDMA/nldev: Report net namespace move errors through extack ---
>commit dd68e4a951ab0b58504bc034673213514633a1a1
>Author: Jiri Pirko <jiri@resnulli.us>
>
>RDMA/nldev: Report net namespace move errors through extack
>
>Thread extack through the existing net namespace move helper and report the
>main failure reasons from the core path. Keep the existing move UAPI shape
>unchanged.
>
>> diff --git a/drivers/infiniband/core/nldev.c b/drivers/infiniband/core/nldev.c
>> index 77a7580801486..8648e95700bfa 100644
>> --- a/drivers/infiniband/core/nldev.c
>> +++ b/drivers/infiniband/core/nldev.c
>> @@ -1195,10 +1195,8 @@ static int nldev_set_doit(struct sk_buff *skb, struct nlmsghdr *nlh,
>>  		u32 ns_fd;
>>  
>>  		ns_fd = nla_get_u32(tb[RDMA_NLDEV_NET_NS_FD]);
>> -		err = ib_device_set_netns_put(skb, device, ns_fd, NULL);
>> -		if (err == -EEXIST)
>> -			NL_SET_ERR_MSG(extack,
>> -				       "Device name already exists in the target net namespace");
>> +		err = ib_device_set_netns_put(skb, device, ns_fd, NULL,
>> +					      extack);
>
>[Severity: High]
>Does this logic prioritize the device rename and exit early, preventing the
>namespace move from occurring if both attributes are present?
>
>Looking at nldev_set_doit(), if a user with CAP_NET_ADMIN provides both
>RDMA_NLDEV_ATTR_DEV_NAME and RDMA_NLDEV_NET_NS_FD in a single message:
>
>    if (tb[RDMA_NLDEV_ATTR_DEV_NAME]) {
>        /* ... */
>        err = ib_device_rename(device, name);
>        goto done;
>    }
>
>won't the handler process the rename and hit a goto done; silently skipping
>the namespace move? This could result in a success response while leaving the
>device in the old namespace.
>
>Additionally, it unconditionally passes NULL as the name to
>ib_device_set_netns_put() in the patched hunk above. Doesn't this render
>the rename-on-move functionality completely inaccessible from userspace?

Both concerns are resolved by the follow-up patch.

  reply	other threads:[~2026-07-22 11:17 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16 13:23 [PATCH rdma-next v3 00/14] RDMA: Make device names unique per net namespace Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 01/14] RDMA/core: Pass the net namespace to the device name lookups Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 02/14] RDMA/core: Handle device name conflicts when changing net namespace Jiri Pirko
2026-07-17 13:24   ` sashiko-bot
2026-07-17 14:06     ` Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 03/14] RDMA/core: Support renaming a device when changing its " Jiri Pirko
2026-07-17 13:24   ` sashiko-bot
2026-07-22 11:02     ` Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 04/14] RDMA/nldev: Report net namespace move errors through extack Jiri Pirko
2026-07-17 13:24   ` sashiko-bot
2026-07-22 11:17     ` Jiri Pirko [this message]
2026-07-16 13:23 ` [PATCH rdma-next v3 05/14] RDMA/nldev: Allow setting the device name while changing net namespace Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 06/14] net/smc: Look up the pnetid ib device within the " Jiri Pirko
2026-07-17 13:24   ` sashiko-bot
2026-07-17 14:08     ` Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 07/14] RDMA/srp: Make the SRP sysfs class net namespace aware Jiri Pirko
2026-07-30 18:34   ` Bart Van Assche
2026-07-16 13:23 ` [PATCH rdma-next v3 08/14] RDMA/cgroup: Disambiguate devices across net namespaces Jiri Pirko
2026-08-24 18:29   ` Michal Koutný
2026-07-16 13:23 ` [PATCH rdma-next v3 09/14] RDMA/cma: Document that CM configfs cannot be net namespace scoped Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 10/14] RDMA/core: Document the SELinux ibendport net namespace limitation Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 11/14] RDMA/core: Make device names unique per net namespace Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 12/14] RDMA/rxe: Allow queue VMAs to outlive ucontexts Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 13/14] RDMA/rxe: Implement disassociate_ucontext callback Jiri Pirko
2026-07-16 13:23 ` [PATCH rdma-next v3 14/14] RDMA/selftests: Add rxe_netns_names test Jiri Pirko
2026-07-17  4:22   ` Zhu Yanjun
2026-07-17 13:24   ` sashiko-bot
2026-07-17 14:09     ` Jiri Pirko
2026-07-22 11:19 ` [PATCH rdma-next v3 00/14] RDMA: Make device names unique per net namespace Jiri Pirko
2026-07-22 11:53   ` Leon Romanovsky
2026-07-22 13:01     ` Jiri Pirko
2026-07-26  7:32 ` Leon Romanovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amCmyqEQaMgJrtg5@FV6GYCPJ69 \
    --to=jiri@resnulli.us \
    --cc=agordeev@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hannes@cmpxchg.org \
    --cc=hca@linux.ibm.com \
    --cc=linux-s390@vger.kernel.org \
    --cc=mkoutny@suse.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tj@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox