Skip to content
Commit d4398b08 authored by Jason Gunthorpe's avatar Jason Gunthorpe Committed by bgman111111
Browse files

RDMA/ucma: Put a lock around every call to the rdma_cm layer

commit 7c11910783a1ea17e88777552ef146cace607b3c upstream.

The rdma_cm must be used single threaded.

This appears to be a bug in the design, as it does have lots of locking
that seems like it should allow concurrency. However, when it is all said
and done every single place that uses the cma_exch() scheme is broken, and
all the unlocked reads from the ucma of the cm_id data are wrong too.

syzkaller has been finding endless bugs related to this.

Fixing this in any elegant way is some enormous amount of work. Take a
very big hammer and put a mutex around everything to do with the
ucma_context at the top of every syscall.

Fixes: 75216638 ("RDMA/cma: Export rdma cm interface to userspace")
Link: https://lore.kernel.org/r/20200218210432.GA31966@ziepe.ca


Reported-by: default avatar <syzbot+adb15cf8c2798e4e0db4@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+e5579222b6a3edd96522@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+4b628fcc748474003457@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+29ee8f76017ce6cf03da@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+6956235342b7317ec564@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+b358909d8d01556b790b@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+6b46b135602a3f3ac99e@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+8458d13b13562abf6b77@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+bd034f3fdc0402e942ed@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+c92378b32760a4eef756@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+68b44a1597636e0b342c@syzkaller.appspotmail.com>
Signed-off-by: default avatarJason Gunthorpe <jgg@mellanox.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent fbe8b306
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment