]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
RDMA/irdma: Prevent rereg_mr for non-mem regions
authorJacob Moroni <jmoroni@google.com>
Wed, 17 Jun 2026 14:19:36 +0000 (14:19 +0000)
committerLeon Romanovsky <leon@kernel.org>
Thu, 2 Jul 2026 12:03:38 +0000 (08:03 -0400)
When a QP/CQ/SRQ is created, a two step process is used
where the buffer is allocated in userspace and explicitly
registered with the normal reg_mr mechanism prior to creating
the actual QP/CQ/SRQ object.

These special registrations are indicated via an ABI field
so the driver knows that they do not have a valid mkey and
to skip the actual CQP command submission.

Since these are real MR objects from the core's perspective,
it is possible for a user application to invoke rereg_mr on them
and cause a real CQP op to be emitted with the zero-initialized
mkey value of 0.

Fix this by preventing rereg_mr on these special regions.

Fixes: 5ac388db27c4 ("RDMA/irdma: Add support to re-register a memory region")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Reviewed-by: David Hu <xuehaohu@google.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
drivers/infiniband/hw/irdma/verbs.c

index cb54c7c8fcd8fc6b5e7d92f02d0a19bde94d482d..23ab8286dc12b0ee14b17cf3c52da52f7ccdcc99 100644 (file)
@@ -3791,6 +3791,9 @@ static struct ib_mr *irdma_rereg_user_mr(struct ib_mr *ib_mr, int flags,
        if (flags & ~(IB_MR_REREG_TRANS | IB_MR_REREG_PD | IB_MR_REREG_ACCESS))
                return ERR_PTR(-EOPNOTSUPP);
 
+       if (iwmr->type != IRDMA_MEMREG_TYPE_MEM)
+            return ERR_PTR(-EINVAL);
+
        ret = ib_umem_check_rereg(iwmr->region, flags, new_access);
        if (ret)
                return ERR_PTR(ret);