]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
RDMA/rxe: Prevent access to wr->next ptr afrer wr is posted to send queue
authorMikhail Malygin <m.malygin@yadro.com>
Thu, 16 Jul 2020 19:03:41 +0000 (22:03 +0300)
committerJason Gunthorpe <jgg@nvidia.com>
Thu, 16 Jul 2020 19:12:07 +0000 (16:12 -0300)
rxe_post_send_kernel() iterates over linked list of wr's, until the
wr->next ptr is NULL.  However if we've got an interrupt after last wr is
posted, control may be returned to the code after send completion callback
is executed and wr memory is freed.

As a result, wr->next pointer may contain incorrect value leading to
panic. Store the wr->next on the stack before posting it.

Fixes: 8700e3e7c485 ("Soft RoCE driver")
Link: https://lore.kernel.org/r/20200716190340.23453-1-m.malygin@yadro.com
Signed-off-by: Mikhail Malygin <m.malygin@yadro.com>
Signed-off-by: Sergey Kojushev <s.kojushev@yadro.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/infiniband/sw/rxe/rxe_verbs.c

index 74f071003690a653c467c1fa0b750a3bdaf7fb91..c1649aec8c23d0a9dc4a36e9bdd9eadb9e4b8d2c 100644 (file)
@@ -682,6 +682,7 @@ static int rxe_post_send_kernel(struct rxe_qp *qp, const struct ib_send_wr *wr,
        unsigned int mask;
        unsigned int length = 0;
        int i;
+       struct ib_send_wr *next;
 
        while (wr) {
                mask = wr_opcode_mask(wr->opcode, qp);
@@ -698,6 +699,8 @@ static int rxe_post_send_kernel(struct rxe_qp *qp, const struct ib_send_wr *wr,
                        break;
                }
 
+               next = wr->next;
+
                length = 0;
                for (i = 0; i < wr->num_sge; i++)
                        length += wr->sg_list[i].length;
@@ -708,7 +711,7 @@ static int rxe_post_send_kernel(struct rxe_qp *qp, const struct ib_send_wr *wr,
                        *bad_wr = wr;
                        break;
                }
-               wr = wr->next;
+               wr = next;
        }
 
        rxe_run_task(&qp->req.task, 1);