Skip to content
Commit 7c119107 authored by Jason Gunthorpe's avatar Jason Gunthorpe
Browse files

RDMA/ucma: Put a lock around every call to the rdma_cm layer

The rdma_cm must be used single threaded.

This appears to be a bug in the design, as it does have lots of locking
that seems like it should allow concurrency. However, when it is all said
and done every single place that uses the cma_exch() scheme is broken, and
all the unlocked reads from the ucma of the cm_id data are wrong too.

syzkaller has been finding endless bugs related to this.

Fixing this in any elegant way is some enormous amount of work. Take a
very big hammer and put a mutex around everything to do with the
ucma_context at the top of every syscall.

Fixes: 75216638 ("RDMA/cma: Export rdma cm interface to userspace")
Link: https://lore.kernel.org/r/20200218210432.GA31966@ziepe.ca


Reported-by: default avatar <syzbot+adb15cf8c2798e4e0db4@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+e5579222b6a3edd96522@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+4b628fcc748474003457@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+29ee8f76017ce6cf03da@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+6956235342b7317ec564@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+b358909d8d01556b790b@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+6b46b135602a3f3ac99e@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+8458d13b13562abf6b77@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+bd034f3fdc0402e942ed@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+c92378b32760a4eef756@syzkaller.appspotmail.com>
Reported-by: default avatar <syzbot+68b44a1597636e0b342c@syzkaller.appspotmail.com>
Signed-off-by: default avatarJason Gunthorpe <jgg@mellanox.com>
parent 25baba21
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment