Re: [PATCH net] net/smc: serialize sndbuf descriptor release with diagnostic dumps
From: Mahanta Jambigi
Date: Mon Sep 28 2026 - 01:57:29 EST
On 27/09/26 1:02 pm, Chengfeng Ye wrote:
> An SMC-D connection can remain in the socket hash while smc_conn_kill()
> tears it down. For devices supporting DMB nocopy, smcd_buf_detach() frees
> the send buffer descriptor without taking the hash lock held by the
> diagnostic reader.
>
> __smc_diag_dump() can load a non-NULL conn->sndbuf_desc, then a concurrent
> smc_conn_kill() can clear the pointer and free the descriptor before the
> dump reads its len field. The socket lock held by the teardown path does
> not exclude the dump, and clearing the pointer before freeing it does
> not protect a reader that has already loaded it.
Agreed. This is addressed in v6[1] by unhashing the socket at the top of
smc_conn_kill(), before smcd_buf_detach() runs, so no hashed socket can
have its sndbuf_desc freed under a concurrent diag reader.
[1]
https://lore.kernel.org/netdev/20260926065023.1629497-1-mjambigi@xxxxxxxxxxxxx/