Re: [PATCH] RDMA/rtrs-clt: Validate peer-supplied IO completion msg_id
From: Jason Gunthorpe
Date: Tue Sep 29 2026 - 19:00:46 EST
On Wed, Sep 23, 2026 at 03:52:11AM -0700, Quanye Yang wrote:
> From: Quanye Yang <quanyeyang@xxxxxxxxx>
>
> process_io_rsp() indexes clt_path->reqs[] with the 19-bit msg_id
> taken from a WRITE_WITH_IMM immediate. That value is chosen by the
> peer. The only check was WARN_ON(msg_id >= queue_depth), which still
> lets a completion run after free_path_reqs() has set reqs to NULL,
> or against a slot whose FRWR is already gone. Either path
> dereferences req->mr and can GPF; KASAN reports a null-ptr-deref at
> offsetof(struct rtrs_clt_io_req, mr).
>
> Treat a missing reqs array, an out-of-range msg_id, or a req
> without an MR as a protocol error and recover the connection.
>
> Reported-by: Farhad Alemi <farhad.alemi@xxxxxxxxxxxx>
> Link: https://lore.kernel.org/r/CA+0ovCiJZz6O8LzsS9Dq1-JE1OE1L_OTA6Mr-WratpUE6jczHw@xxxxxxxxxxxxxx
> Fixes: 6a98d71daea1 ("RDMA/rtrs: client: main functionality")
> Signed-off-by: Quanye Yang <quanyeyang@xxxxxxxxx>
> Reviewed-by: Jack Wang <jinpu.wang@xxxxxxxxxxxxxxx>
> ---
> drivers/infiniband/ulp/rtrs/rtrs-clt.c | 21 ++++++++++++++++-----
> 1 file changed, 16 insertions(+), 5 deletions(-)
Applied to for-next, thanks
Jason