[PATCH v5 0/2] RDMA/rxe: fix send-path TOCTOU races on shared WQEs

From: Tristan Madani

Date: Thu Oct 08 2026 - 05:43:51 EST


From: Tristan Madani <tristan@xxxxxxxxxxxxxxxxxxx>

The rxe driver maps send queues into userspace. Both the requester and
completer read Work Queue Entries (WQEs) directly from this shared
buffer. Userspace can modify WQE fields between kernel reads, causing
inconsistent state in copy_data() and related paths.

This series copies the send WQE to kernel-private buffers, mirroring
the receive-path fixes (commits 22b8fbded65b8 and d6ab440240a04).

Changes v4 -> v5:
- Use qp->sq.max_inline instead of qp->sq.max_sge * sizeof(rxe_sge)
for the copy size, avoiding integer division truncation when
max_inline_data is not a multiple of sizeof(struct ib_sge)

Changes v3 -> v4:
- Use full queue element size (max_sge SGEs) for the copy instead of
per-WQE num_sge. Eliminates inline data gap, sizeof mismatch, and
simplifies both patches
- Invalidate requester copy on ERR flush path before writing status
to shared memory (prevents writeback from clobbering error state)
- Invalidate both caches on QP reset (rxe_qp.c changes added)

Changes v2 -> v3:
- Add completer-path copy (patch 2/2) to close the remaining TOCTOU
window. The completer was still reading directly from shared memory
- Add smp_load_acquire()/smp_store_release() for state transitions
between requester and completer

Changes v1 -> v2:
- Added writeback mechanism using WRITE_ONCE() and smp_store_release()
- Reuse kernel copy across multi-packet sends to preserve DMA state
- Invalidate on retry, QP reset, and error paths

Tristan Madani (2):
RDMA/rxe: copy send WQE to kernel buffer before processing
RDMA/rxe: copy send WQE to kernel buffer in completer path

drivers/infiniband/sw/rxe/rxe_comp.c | 53 ++++++++++++++++++++++++++++--
drivers/infiniband/sw/rxe/rxe_qp.c | 2 ++
drivers/infiniband/sw/rxe/rxe_req.c | 55 ++++++++++++++++++++++++++++++---
drivers/infiniband/sw/rxe/rxe_verbs.h | 12 ++++++++
4 files changed, 116 insertions(+), 6 deletions(-)

--
2.39.5