* [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices
@ 2026-09-27 6:30 Allison Henderson
2026-09-27 6:30 ` [PATCH net-next v4 1/2] " Allison Henderson
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Allison Henderson @ 2026-09-27 6:30 UTC (permalink / raw)
To: netdev, linux-rdma, pabeni, edumazet, kuba, horms; +Cc: achender
Hi all,
This is v4 of the rdma_cm id restriction (v1 at [1], v2 at [2], v3 at
[3]). Patch 1 is the restriction itself; patch 2 is a small follow-on
the v3 review turned up in the function patch 1 touches.
Patch 1 restricts the listener, the per-connection id and the probe
id to RDMA_NODE_IB_CA with rdma_restrict_node_type(), so the rdma_cm
never installs the RDS listener on, or binds an RDS id to, a device
RDS has no transport for.
Patch 2 has rds_rdma_listen_init_common() print the port it actually
bound: the IPv6 listener sits on RDS_CM_PORT, not RDS_PORT.
Changes since v3 [3]:
- Fixes: dcdede0406d3 ("RDS: Drop stale iWARP RDMA transport") added,
with a note that stable trees without rdma_restrict_node_type() need
the separate handler fix rather than a backport of this one, and
that the two patches are independent.
- New patch 2 for the listener debug line.
- Rebased onto current net-next.
- The v3 notes linked the wrong message id for v2; corrected below.
Changes since v2 [2]:
- The changelog no longer claims a handler-side rejection exists in
this tree; it names the separate net fix for the handler and the
a760e80e90f5 prerequisite. The node_type half of the
rds_ib_laddr_check_cm() test, dead once the id is restricted, is
removed rather than described.
[1] https://lore.kernel.org/netdev/20260917074108.174262-1-achender@kernel.org/
[2] https://lore.kernel.org/netdev/20260919061042.250462-1-achender@kernel.org/
[3] https://lore.kernel.org/netdev/20260922084837.390414-1-achender@kernel.org/
Thank you,
Allison
Allison Henderson (2):
net/rds: restrict the rdma_cm ids to IB devices
net/rds: log the port a listener actually bound
net/rds/ib.c | 14 ++++++--------
net/rds/ib_cm.c | 12 ++++++++++++
net/rds/rdma_transport.c | 13 ++++++++++++-
3 files changed, 30 insertions(+), 9 deletions(-)
--
2.25.1
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net-next v4 1/2] net/rds: restrict the rdma_cm ids to IB devices
2026-09-27 6:30 [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices Allison Henderson
@ 2026-09-27 6:30 ` Allison Henderson
2026-10-01 12:32 ` Simon Horman
2026-09-27 6:30 ` [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound Allison Henderson
2026-10-02 0:20 ` [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Allison Henderson @ 2026-09-27 6:30 UTC (permalink / raw)
To: netdev, linux-rdma, pabeni, edumazet, kuba, horms; +Cc: achender
RDS only has an IB transport, but it never tells the rdma_cm so. The
listener created in rds_rdma_listen_init() is therefore installed on
every RDMA device in the system, including iWARP RNICs, and the id an
outgoing connection resolves through in rds_ib_conn_path_connect()
may be bound to whichever device the address resolution picks:
rds_ib_laddr_check() only vouched for the local address being served
by one of RDS's IB devices, while cma_acquire_dev_by_src_ip() walks
every RDMA device for the same address, so a software iWARP device
attached to the same netdev can win. The event handler then runs
the IB transport's callbacks against a device that is not one.
The rdma_cm has an API for exactly this since commit a760e80e90f5
("RDMA/core: introduce rdma_restrict_node_type()"). Restrict all
three ids RDS creates - the listener, the per-connection id and the
probe id in rds_ib_laddr_check_cm() - to RDMA_NODE_IB_CA before they
are bound, so that the listener is only installed on IB devices, an
outgoing connection can only bind one, and the address check's bind
fails outright on anything else - which makes its explicit node_type
test dead, so it goes; the check that the bind produced a device at
all stays.
With that, no rdma_cm event reaches RDS's handler from a device it
has no transport for. The handler itself still assumes IB: it assigns
its transport pointer only for RDMA_NODE_IB_CA and dereferences it
regardless, which is the crash that first surfaced this. The fix for
that is a separate net patch, Aohan Mei's "net: rds: fix uninitialized
trans dereference in CM event handler", and is what stable kernels
without rdma_restrict_node_type() - which arrived in commit
a760e80e90f5 ("RDMA/core: introduce rdma_restrict_node_type()") - have
to take: this patch depends on that API, so stable trees need that
separate, minimal fix rather than a backport of this one. The two
patches are independent and apply in either order. The
listener has been on every RDMA device since the iWARP transport was
removed and left the ids unrestricted, hence the Fixes tag.
Fixes: dcdede0406d3 ("RDS: Drop stale iWARP RDMA transport")
Assisted-by: Claude-Code:claude-fable-5
Signed-off-by: Allison Henderson <achender@kernel.org>
---
net/rds/ib.c | 14 ++++++--------
net/rds/ib_cm.c | 12 ++++++++++++
net/rds/rdma_transport.c | 8 ++++++++
3 files changed, 26 insertions(+), 8 deletions(-)
diff --git a/net/rds/ib.c b/net/rds/ib.c
index 786f39169bc1..4ea9838d090c 100644
--- a/net/rds/ib.c
+++ b/net/rds/ib.c
@@ -414,13 +414,14 @@ static int rds_ib_laddr_check_cm(struct net *net, const struct in6_addr *addr,
bool isv4;
isv4 = ipv6_addr_v4mapped(addr);
- /* Create a CMA ID and try to bind it. This catches both
- * IB and iWARP capable NICs.
- */
+ /* Create a CMA ID restricted to IB devices and try to bind it. */
cm_id = rdma_create_id(&init_net, rds_rdma_cm_event_handler,
NULL, RDMA_PS_TCP, IB_QPT_RC);
if (IS_ERR(cm_id))
return PTR_ERR(cm_id);
+ ret = rdma_restrict_node_type(cm_id, RDMA_NODE_IB_CA);
+ if (ret)
+ goto out;
if (isv4) {
memset(&sin, 0, sizeof(sin));
@@ -473,12 +474,9 @@ static int rds_ib_laddr_check_cm(struct net *net, const struct in6_addr *addr,
#endif
}
- /* rdma_bind_addr will only succeed for IB & iWARP devices */
+ /* the restriction above means this only succeeds for IB devices */
ret = rdma_bind_addr(cm_id, sa);
- /* due to this, we will claim to support iWARP devices unless we
- check node_type. */
- if (ret || !cm_id->device ||
- cm_id->device->node_type != RDMA_NODE_IB_CA)
+ if (ret || !cm_id->device)
ret = -EADDRNOTAVAIL;
rdsdebug("addr %pI6c%%%u ret %d node type %d\n",
diff --git a/net/rds/ib_cm.c b/net/rds/ib_cm.c
index 3ebe13d00953..3ed03ad32812 100644
--- a/net/rds/ib_cm.c
+++ b/net/rds/ib_cm.c
@@ -999,6 +999,18 @@ int rds_ib_conn_path_connect(struct rds_conn_path *cp)
goto out;
}
+ /* rds_ib_laddr_check() only vouched for the local address being
+ * on an IB device; the address resolution below picks the device
+ * on its own, so restrict it to the same kind.
+ */
+ ret = rdma_restrict_node_type(ic->i_cm_id, RDMA_NODE_IB_CA);
+ if (ret) {
+ rdsdebug("rdma_restrict_node_type() failed: %d\n", ret);
+ rdma_destroy_id(ic->i_cm_id);
+ ic->i_cm_id = NULL;
+ goto out;
+ }
+
rdsdebug("created cm id %p for conn %p\n", ic->i_cm_id, conn);
if (ipv6_addr_v4mapped(&conn->c_faddr)) {
diff --git a/net/rds/rdma_transport.c b/net/rds/rdma_transport.c
index b15cf316b23a..91ff1dde26af 100644
--- a/net/rds/rdma_transport.c
+++ b/net/rds/rdma_transport.c
@@ -210,6 +210,14 @@ static int rds_rdma_listen_init_common(rdma_cm_event_handler handler,
return ret;
}
+ /* Only the IB transport is left, so only listen on IB devices */
+ ret = rdma_restrict_node_type(cm_id, RDMA_NODE_IB_CA);
+ if (ret) {
+ pr_err("RDS/RDMA: failed to setup listener, rdma_restrict_node_type() returned %d\n",
+ ret);
+ goto out;
+ }
+
/*
* XXX I bet this binds the cm_id to a device. If we want to support
* fail-over we'll have to take this into consideration.
--
2.25.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound
2026-09-27 6:30 [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices Allison Henderson
2026-09-27 6:30 ` [PATCH net-next v4 1/2] " Allison Henderson
@ 2026-09-27 6:30 ` Allison Henderson
2026-10-01 12:32 ` Simon Horman
2026-10-02 0:20 ` [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Allison Henderson @ 2026-09-27 6:30 UTC (permalink / raw)
To: netdev, linux-rdma, pabeni, edumazet, kuba, horms; +Cc: achender
rds_rdma_listen_init_common() reports every listener as being on
RDS_PORT, but only the IPv4 caller binds that port; the IPv6 listener
is bound to RDS_CM_PORT, as rds_rdma_listen_init() explains, and its
debug line has claimed 18634 instead of 16385 since it was added.
Print the port from the address the helper just bound.
Assisted-by: Claude-Code:claude-fable-5
Signed-off-by: Allison Henderson <achender@kernel.org>
---
net/rds/rdma_transport.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/net/rds/rdma_transport.c b/net/rds/rdma_transport.c
index 91ff1dde26af..3f853004c490 100644
--- a/net/rds/rdma_transport.c
+++ b/net/rds/rdma_transport.c
@@ -236,7 +236,10 @@ static int rds_rdma_listen_init_common(rdma_cm_event_handler handler,
goto out;
}
- rdsdebug("cm %p listening on port %u\n", cm_id, RDS_PORT);
+ rdsdebug("cm %p listening on port %u\n", cm_id,
+ ntohs(sa->sa_family == AF_INET6 ?
+ ((struct sockaddr_in6 *)sa)->sin6_port :
+ ((struct sockaddr_in *)sa)->sin_port));
*ret_cm_id = cm_id;
cm_id = NULL;
--
2.25.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH net-next v4 1/2] net/rds: restrict the rdma_cm ids to IB devices
2026-09-27 6:30 ` [PATCH net-next v4 1/2] " Allison Henderson
@ 2026-10-01 12:32 ` Simon Horman
0 siblings, 0 replies; 6+ messages in thread
From: Simon Horman @ 2026-10-01 12:32 UTC (permalink / raw)
To: Allison Henderson; +Cc: netdev, linux-rdma, pabeni, edumazet, kuba
On Sat, Sep 26, 2026 at 11:30:57PM -0700, Allison Henderson wrote:
> RDS only has an IB transport, but it never tells the rdma_cm so. The
> listener created in rds_rdma_listen_init() is therefore installed on
> every RDMA device in the system, including iWARP RNICs, and the id an
> outgoing connection resolves through in rds_ib_conn_path_connect()
> may be bound to whichever device the address resolution picks:
> rds_ib_laddr_check() only vouched for the local address being served
> by one of RDS's IB devices, while cma_acquire_dev_by_src_ip() walks
> every RDMA device for the same address, so a software iWARP device
> attached to the same netdev can win. The event handler then runs
> the IB transport's callbacks against a device that is not one.
>
> The rdma_cm has an API for exactly this since commit a760e80e90f5
> ("RDMA/core: introduce rdma_restrict_node_type()"). Restrict all
> three ids RDS creates - the listener, the per-connection id and the
> probe id in rds_ib_laddr_check_cm() - to RDMA_NODE_IB_CA before they
> are bound, so that the listener is only installed on IB devices, an
> outgoing connection can only bind one, and the address check's bind
> fails outright on anything else - which makes its explicit node_type
> test dead, so it goes; the check that the bind produced a device at
> all stays.
>
> With that, no rdma_cm event reaches RDS's handler from a device it
> has no transport for. The handler itself still assumes IB: it assigns
> its transport pointer only for RDMA_NODE_IB_CA and dereferences it
> regardless, which is the crash that first surfaced this. The fix for
> that is a separate net patch, Aohan Mei's "net: rds: fix uninitialized
> trans dereference in CM event handler", and is what stable kernels
> without rdma_restrict_node_type() - which arrived in commit
> a760e80e90f5 ("RDMA/core: introduce rdma_restrict_node_type()") - have
> to take: this patch depends on that API, so stable trees need that
> separate, minimal fix rather than a backport of this one. The two
> patches are independent and apply in either order. The
> listener has been on every RDMA device since the iWARP transport was
> removed and left the ids unrestricted, hence the Fixes tag.
>
> Fixes: dcdede0406d3 ("RDS: Drop stale iWARP RDMA transport")
> Assisted-by: Claude-Code:claude-fable-5
> Signed-off-by: Allison Henderson <achender@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound
2026-09-27 6:30 ` [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound Allison Henderson
@ 2026-10-01 12:32 ` Simon Horman
0 siblings, 0 replies; 6+ messages in thread
From: Simon Horman @ 2026-10-01 12:32 UTC (permalink / raw)
To: Allison Henderson; +Cc: netdev, linux-rdma, pabeni, edumazet, kuba
On Sat, Sep 26, 2026 at 11:30:58PM -0700, Allison Henderson wrote:
> rds_rdma_listen_init_common() reports every listener as being on
> RDS_PORT, but only the IPv4 caller binds that port; the IPv6 listener
> is bound to RDS_CM_PORT, as rds_rdma_listen_init() explains, and its
> debug line has claimed 18634 instead of 16385 since it was added.
>
> Print the port from the address the helper just bound.
>
> Assisted-by: Claude-Code:claude-fable-5
> Signed-off-by: Allison Henderson <achender@kernel.org>
Reviewed-by: Simon Horman <horms@kernel.org>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices
2026-09-27 6:30 [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices Allison Henderson
2026-09-27 6:30 ` [PATCH net-next v4 1/2] " Allison Henderson
2026-09-27 6:30 ` [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound Allison Henderson
@ 2026-10-02 0:20 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-02 0:20 UTC (permalink / raw)
To: Allison Henderson; +Cc: netdev, linux-rdma, pabeni, edumazet, kuba, horms
Hello:
This series was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Sat, 26 Sep 2026 23:30:56 -0700 you wrote:
> Hi all,
>
> This is v4 of the rdma_cm id restriction (v1 at [1], v2 at [2], v3 at
> [3]). Patch 1 is the restriction itself; patch 2 is a small follow-on
> the v3 review turned up in the function patch 1 touches.
>
> Patch 1 restricts the listener, the per-connection id and the probe
> id to RDMA_NODE_IB_CA with rdma_restrict_node_type(), so the rdma_cm
> never installs the RDS listener on, or binds an RDS id to, a device
> RDS has no transport for.
>
> [...]
Here is the summary with links:
- [net-next,v4,1/2] net/rds: restrict the rdma_cm ids to IB devices
https://git.kernel.org/netdev/net-next/c/c7fca8aae6fe
- [net-next,v4,2/2] net/rds: log the port a listener actually bound
https://git.kernel.org/netdev/net-next/c/00d77b181866
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-02 0:20 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 6:30 [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices Allison Henderson
2026-09-27 6:30 ` [PATCH net-next v4 1/2] " Allison Henderson
2026-10-01 12:32 ` Simon Horman
2026-09-27 6:30 ` [PATCH net-next v4 2/2] net/rds: log the port a listener actually bound Allison Henderson
2026-10-01 12:32 ` Simon Horman
2026-10-02 0:20 ` [PATCH net-next v4 0/2] net/rds: restrict the rdma_cm ids to IB devices patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox