From: Allison Henderson <achender@kernel.org>
To: netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
pabeni@redhat.com, edumazet@google.com, kuba@kernel.org,
horms@kernel.org
Cc: achender@kernel.org, jhubbard@nvidia.com, leon@kernel.org
Subject: [PATCH net v4 0/4] net/rds: Bug fix ports
Date: Wed, 29 Jul 2026 21:16:25 -0700 [thread overview]
Message-ID: <20260730041629.3512480-1-achender@kernel.org> (raw)
Hi all,
This is a small set of net/rds bug fixes and ports from uek to upstream
rds. I've been working on extending the rds selftest case, but need to
stabilize a few more bugs and the first few fall into net with Fixes
tags. I decided to leverage fable for this set and I thought the ports we
clean and well explained.
This series fixes a sleeping-in-softirq bug in the RDS message free
path, a use-after-free of the RDS socket through long-lived MR
references, a message leak in the rds_send_xmit() drop path, and - new
in v4 - a pinned-page leak in the IB transport's MR teardown.
The first three patches are ports of fixes carried in the Oracle UEK
kernel, reworked where the UEK approach no longer applies upstream.
[PATCH net 1/3] net/rds: don't use unpin_user_pages_dirty_lock() from atomic context
Originally a port of ueks 4d4a5551a1d2 ("net/rds: Avoid
unpin_user_pages_dirty_lock() in tasklets"), but reworked to defer
the user-page unpin to a work item. The rest of the message purge
(including the MR and socket reference drops) stay in the caller's
context. The deferred work touches only core mm and the rds modules
own memory, so it cannot race with transport module unload, and the
flush_workqueue() calls previously added to rds_ib_exit() are gone
along with the concerns raised against them.
[PATCH net 2/3] net/rds: hold the socket while an rds_mr references it
Port: commit c4d69e511f3b ("rds: Add proper refcnt when an RDS MR references an RDS Socket")
https://github.com/oracle/linux-uek/commit/94549e4732d8
[PATCH net-next 3/3] net/rds: fix rds_message leak in the rds_send_xmit() drop path
Port: commit 94549e4732d8 ("net/rds: fix rds_message memleak in rds_send_xmit")
https://github.com/oracle/linux-uek/commit/94549e4732d8
[PATCH net v4 4/4] net/rds: unpin MR pages with unpin_user_pages_dirty_lock()
Fix page leak in __rds_ib_teardown_mr() by releasing
pin_user_pages_fast()-pinned pages with unpin_user_pages_dirty_lock()
instead of leaving them pinned with put_page()
These were carved out of a larger porting effort, but I'll follow up with a few more
targeted for net-net after these land in net.
Question and comments appreciated!
Thanks,
Allison
Change log
v1: https://lore.kernel.org/all/20260711025118.2449428-1-achender@kernel.org/
v2: https://lore.kernel.org/netdev/20260725082939.2546624-1-achender@kernel.org/
- Patch 1/3: re-written to delay page ditying via queued work items
- Patch 3/3: fixed check patch nits
v3: https://lore.kernel.org/netdev/20260726230449.2880446-1-achender@kernel.org/
- Patch 3/3: Added extra flush for possible purge work item queued
after the first flush
v4:
- Patch 1/4: reworked to delay only user-page unpin
- Patch 2/4: ODP path now takes the socket ref next to kref_init()
and unwinds its get_mr() error path through __rds_put_mr_final(),
so both MR allocation sites follow the same ownership rule.
- Patch 3/4: commit message corrected to name the code paths that
actually clear RDS_MSG_ON_CONN.
- Patch 4/4: new
Allison Henderson (2):
net/rds: don't use unpin_user_pages_dirty_lock() from atomic context
net/rds: unpin MR pages with unpin_user_pages_dirty_lock()
Håkon Bugge (1):
net/rds: hold the socket while an rds_mr references it
Sharath Srinivasan (1):
net/rds: fix rds_message leak in the rds_send_xmit() drop path
net/rds/ib_rdma.c | 4 +--
net/rds/message.c | 26 +++++++++++++++++++
net/rds/rdma.c | 63 ++++++++++++++++++++++++++++++++++++++---------
net/rds/rds.h | 15 ++++++++++-
net/rds/send.c | 18 +++++++++++---
5 files changed, 107 insertions(+), 19 deletions(-)
base-commit: 89d8006259b81dd25c962f6cc8d7ab268d6ea426
--
2.25.1
next reply other threads:[~2026-07-30 4:16 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 4:16 Allison Henderson [this message]
2026-07-30 4:16 ` [PATCH net v4 1/4] net/rds: don't use unpin_user_pages_dirty_lock() from atomic context Allison Henderson
2026-07-30 4:16 ` [PATCH net v4 2/4] net/rds: hold the socket while an rds_mr references it Allison Henderson
2026-07-30 4:16 ` [PATCH net v4 3/4] net/rds: fix rds_message leak in the rds_send_xmit() drop path Allison Henderson
2026-07-30 4:16 ` [PATCH net v4 4/4] net/rds: unpin MR pages with unpin_user_pages_dirty_lock() Allison Henderson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730041629.3512480-1-achender@kernel.org \
--to=achender@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jhubbard@nvidia.com \
--cc=kuba@kernel.org \
--cc=leon@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox