Netdev List
 help / color / mirror / Atom feed
* [PATCH net v4 0/4] net/rds: Bug fix ports
@ 2026-07-30  4:16 Allison Henderson
  2026-07-30  4:16 ` [PATCH net v4 1/4] net/rds: don't use unpin_user_pages_dirty_lock() from atomic context Allison Henderson
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Allison Henderson @ 2026-07-30  4:16 UTC (permalink / raw)
  To: netdev, linux-rdma, pabeni, edumazet, kuba, horms
  Cc: achender, jhubbard, leon

Hi all,

This is a small set of net/rds bug fixes and ports from uek to upstream
rds.  I've been working on extending the rds selftest case, but need to
stabilize a few more bugs and the first few fall into net with Fixes
tags. I decided to leverage fable for this set and I thought the ports we
clean and well explained.

This series fixes a sleeping-in-softirq bug in the RDS message free
path, a use-after-free of the RDS socket through long-lived MR
references, a message leak in the rds_send_xmit() drop path, and - new
in v4 - a pinned-page leak in the IB transport's MR teardown.

The first three patches are ports of fixes carried in the Oracle UEK
kernel, reworked where the UEK approach no longer applies upstream.

[PATCH net 1/3] net/rds: don't use unpin_user_pages_dirty_lock() from atomic context
   Originally a port of ueks 4d4a5551a1d2 ("net/rds: Avoid
   unpin_user_pages_dirty_lock() in tasklets"), but reworked to defer
   the user-page unpin to a work item.  The rest of the message purge
   (including the MR and socket reference drops) stay in the caller's
   context.  The deferred work touches only core mm and the rds modules
   own memory, so it cannot race with transport module unload, and the
   flush_workqueue() calls previously added to rds_ib_exit() are gone
   along with the concerns raised against them.

[PATCH net 2/3] net/rds: hold the socket while an rds_mr references it
   Port: commit c4d69e511f3b ("rds: Add proper refcnt when an RDS MR references an RDS Socket")
   https://github.com/oracle/linux-uek/commit/94549e4732d8

[PATCH net-next 3/3] net/rds: fix rds_message leak in the rds_send_xmit() drop path
  Port: commit 94549e4732d8 ("net/rds: fix rds_message memleak in rds_send_xmit")
  https://github.com/oracle/linux-uek/commit/94549e4732d8

[PATCH net v4 4/4] net/rds: unpin MR pages with unpin_user_pages_dirty_lock()
  Fix page leak in __rds_ib_teardown_mr() by releasing
  pin_user_pages_fast()-pinned pages with unpin_user_pages_dirty_lock()
  instead of leaving them pinned with put_page()

These were carved out of a larger porting effort, but I'll follow up with a few more
targeted for net-net after these land in net.

Question and comments appreciated!

Thanks,
Allison

Change log
v1: https://lore.kernel.org/all/20260711025118.2449428-1-achender@kernel.org/

v2: https://lore.kernel.org/netdev/20260725082939.2546624-1-achender@kernel.org/
  - Patch 1/3: re-written to delay page ditying via queued work items
  - Patch 3/3: fixed check patch nits

v3: https://lore.kernel.org/netdev/20260726230449.2880446-1-achender@kernel.org/
  - Patch 3/3: Added extra flush for possible purge work item queued
               after the first flush
v4:
  - Patch 1/4: reworked to delay only user-page unpin
  - Patch 2/4: ODP path now takes the socket ref next to kref_init()
    and unwinds its get_mr() error path through __rds_put_mr_final(),
    so both MR allocation sites follow the same ownership rule.
  - Patch 3/4: commit message corrected to name the code paths that
    actually clear RDS_MSG_ON_CONN.
  - Patch 4/4: new

Allison Henderson (2):
  net/rds: don't use unpin_user_pages_dirty_lock() from atomic context
  net/rds: unpin MR pages with unpin_user_pages_dirty_lock()

Håkon Bugge (1):
  net/rds: hold the socket while an rds_mr references it

Sharath Srinivasan (1):
  net/rds: fix rds_message leak in the rds_send_xmit() drop path

 net/rds/ib_rdma.c |  4 +--
 net/rds/message.c | 26 +++++++++++++++++++
 net/rds/rdma.c    | 63 ++++++++++++++++++++++++++++++++++++++---------
 net/rds/rds.h     | 15 ++++++++++-
 net/rds/send.c    | 18 +++++++++++---
 5 files changed, 107 insertions(+), 19 deletions(-)


base-commit: 89d8006259b81dd25c962f6cc8d7ab268d6ea426
-- 
2.25.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-07-30  4:16 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-30  4:16 [PATCH net v4 0/4] net/rds: Bug fix ports Allison Henderson
2026-07-30  4:16 ` [PATCH net v4 1/4] net/rds: don't use unpin_user_pages_dirty_lock() from atomic context Allison Henderson
2026-07-30  4:16 ` [PATCH net v4 2/4] net/rds: hold the socket while an rds_mr references it Allison Henderson
2026-07-30  4:16 ` [PATCH net v4 3/4] net/rds: fix rds_message leak in the rds_send_xmit() drop path Allison Henderson
2026-07-30  4:16 ` [PATCH net v4 4/4] net/rds: unpin MR pages with unpin_user_pages_dirty_lock() Allison Henderson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox