netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Allison Henderson <achender@kernel.org>
To: netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
	pabeni@redhat.com, edumazet@google.com, kuba@kernel.org,
	horms@kernel.org
Cc: achender@kernel.org, ljp1205831794@gmail.com, henrymei@tencent.com
Subject: [PATCH net v4 0/2] net/rds: RDMA-CM event handler fixes for non-IB devices
Date: Sat,  3 Oct 2026 09:34:06 -0700	[thread overview]
Message-ID: <20261003163408.250568-1-achender@kernel.org> (raw)

Hi all,

This is v4 of Aohan Mei's fix for the uninitialized transport pointer
in the RDMA-CM event handler (v1 at [1], v2 at [2], v3 at [3]), now a
two-patch set.

  Patch 1 is the fix itself.  v3 only rejected a connect request
  arriving on a non-IB device; the active side can bind an id to one
  as well, and resolving a route on an iWARP id leaves
  cm_id->route.path_rec unset, which the ROUTE_RESOLVED case
  dereferences.  Such a connection is now dropped at ADDR_RESOLVED
  instead of resolving a route.

  Patch 2 fixes a neighbouring problem in the same case: a synchronous
  rdma_resolve_route() failure was handed back to the rdma_cm, which
  then destroyed an id RDS still owns as ic->i_cm_id and would later
  disconnect and destroy again from the connection's shutdown.

On net-next the rdma_cm ids RDS creates are restricted to IB devices
(commit c7fca8aae6fe), which makes the non-IB cases impossible there;
these are the fixes stable kernels without that API need.

Changes since v3 [3]:
 - Patch 1 also drops a connection whose address resolved to a non-IB
   device, before a route is resolved on it (review of v3).
 - New patch 2 for the rdma_resolve_route() failure return.
 - Rebased onto current net.

Changes since v2 [2]:
 - Carried forward; the rejection is limited to
   RDMA_CM_EVENT_CONNECT_REQUEST so that rdma_cm does not destroy
   connection ids RDS still owns.

[1] https://lore.kernel.org/netdev/20260824111701.2979194-1-ljp1205831794@gmail.com/
[2] https://lore.kernel.org/netdev/20260825021223.3483044-1-ljp1205831794@gmail.com/
[3] https://lore.kernel.org/netdev/20260928044507.335883-1-achender@kernel.org/

Thank you,
Allison


Allison Henderson (1):
  net/rds: don't let the rdma_cm destroy an id RDS still owns on route
    failure

Aohan Mei (1):
  net: rds: fix uninitialized trans dereference in CM event handler

 net/rds/rdma_transport.c | 38 +++++++++++++++++++++++++++++++++-----
 1 file changed, 33 insertions(+), 5 deletions(-)

-- 
2.25.1


             reply	other threads:[~2026-10-03 16:34 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-03 16:34 Allison Henderson [this message]
2026-10-03 16:34 ` [PATCH net v4 1/2] net: rds: fix uninitialized trans dereference in CM event handler Allison Henderson
2026-10-03 16:34 ` [PATCH net v4 2/2] net/rds: don't let the rdma_cm destroy an id RDS still owns on route failure Allison Henderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003163408.250568-1-achender@kernel.org \
    --to=achender@kernel.org \
    --cc=edumazet@google.com \
    --cc=henrymei@tencent.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=ljp1205831794@gmail.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).