2020-08-27 09:54:40 -05:00
|
|
|
/* SPDX-License-Identifier: GPL-2.0 OR Linux-OpenIB */
|
2016-06-16 16:45:23 +03:00
|
|
|
/*
|
|
|
|
* Copyright (c) 2016 Mellanox Technologies Ltd. All rights reserved.
|
|
|
|
* Copyright (c) 2015 System Fabric Works, Inc. All rights reserved.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef RXE_H
|
|
|
|
#define RXE_H
|
|
|
|
|
2016-09-28 20:26:26 +00:00
|
|
|
#ifdef pr_fmt
|
|
|
|
#undef pr_fmt
|
|
|
|
#endif
|
|
|
|
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
|
|
|
|
|
2016-06-16 16:45:23 +03:00
|
|
|
#include <linux/skbuff.h>
|
|
|
|
|
|
|
|
#include <rdma/ib_verbs.h>
|
|
|
|
#include <rdma/ib_user_verbs.h>
|
|
|
|
#include <rdma/ib_pack.h>
|
|
|
|
#include <rdma/ib_smi.h>
|
|
|
|
#include <rdma/ib_umem.h>
|
|
|
|
#include <rdma/ib_cache.h>
|
|
|
|
#include <rdma/ib_addr.h>
|
|
|
|
|
|
|
|
#include "rxe_net.h"
|
|
|
|
#include "rxe_opcode.h"
|
|
|
|
#include "rxe_hdr.h"
|
|
|
|
#include "rxe_param.h"
|
|
|
|
#include "rxe_verbs.h"
|
2018-01-01 13:07:11 +02:00
|
|
|
#include "rxe_loc.h"
|
2016-06-16 16:45:23 +03:00
|
|
|
|
2018-03-20 14:19:50 -06:00
|
|
|
/*
|
|
|
|
* Version 1 and Version 2 are identical on 64 bit machines, but on 32 bit
|
|
|
|
* machines Version 2 has a different struct layout.
|
|
|
|
*/
|
|
|
|
#define RXE_UVERBS_ABI_VERSION 2
|
2016-06-16 16:45:23 +03:00
|
|
|
|
|
|
|
#define RXE_ROCE_V2_SPORT (0xc000)
|
|
|
|
|
2024-01-09 16:32:52 +08:00
|
|
|
#define rxe_dbg(fmt, ...) pr_debug("%s: " fmt, __func__, ##__VA_ARGS__)
|
2023-03-03 16:16:22 -06:00
|
|
|
#define rxe_dbg_dev(rxe, fmt, ...) ibdev_dbg(&(rxe)->ib_dev, \
|
2022-11-03 12:09:59 -05:00
|
|
|
"%s: " fmt, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_uc(uc, fmt, ...) ibdev_dbg((uc)->ibuc.device, \
|
|
|
|
"uc#%d %s: " fmt, (uc)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_pd(pd, fmt, ...) ibdev_dbg((pd)->ibpd.device, \
|
|
|
|
"pd#%d %s: " fmt, (pd)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_ah(ah, fmt, ...) ibdev_dbg((ah)->ibah.device, \
|
|
|
|
"ah#%d %s: " fmt, (ah)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_srq(srq, fmt, ...) ibdev_dbg((srq)->ibsrq.device, \
|
|
|
|
"srq#%d %s: " fmt, (srq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_qp(qp, fmt, ...) ibdev_dbg((qp)->ibqp.device, \
|
|
|
|
"qp#%d %s: " fmt, (qp)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_cq(cq, fmt, ...) ibdev_dbg((cq)->ibcq.device, \
|
|
|
|
"cq#%d %s: " fmt, (cq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_mr(mr, fmt, ...) ibdev_dbg((mr)->ibmr.device, \
|
|
|
|
"mr#%d %s: " fmt, (mr)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_dbg_mw(mw, fmt, ...) ibdev_dbg((mw)->ibmw.device, \
|
|
|
|
"mw#%d %s: " fmt, (mw)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
|
2024-01-09 16:32:52 +08:00
|
|
|
#define rxe_err(fmt, ...) pr_err_ratelimited("%s: " fmt, __func__, \
|
2023-03-03 16:16:23 -06:00
|
|
|
##__VA_ARGS__)
|
|
|
|
#define rxe_err_dev(rxe, fmt, ...) ibdev_err_ratelimited(&(rxe)->ib_dev, \
|
|
|
|
"%s: " fmt, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_uc(uc, fmt, ...) ibdev_err_ratelimited((uc)->ibuc.device, \
|
|
|
|
"uc#%d %s: " fmt, (uc)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_pd(pd, fmt, ...) ibdev_err_ratelimited((pd)->ibpd.device, \
|
|
|
|
"pd#%d %s: " fmt, (pd)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_ah(ah, fmt, ...) ibdev_err_ratelimited((ah)->ibah.device, \
|
|
|
|
"ah#%d %s: " fmt, (ah)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_srq(srq, fmt, ...) ibdev_err_ratelimited((srq)->ibsrq.device, \
|
|
|
|
"srq#%d %s: " fmt, (srq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_qp(qp, fmt, ...) ibdev_err_ratelimited((qp)->ibqp.device, \
|
|
|
|
"qp#%d %s: " fmt, (qp)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_cq(cq, fmt, ...) ibdev_err_ratelimited((cq)->ibcq.device, \
|
|
|
|
"cq#%d %s: " fmt, (cq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_mr(mr, fmt, ...) ibdev_err_ratelimited((mr)->ibmr.device, \
|
|
|
|
"mr#%d %s: " fmt, (mr)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_err_mw(mw, fmt, ...) ibdev_err_ratelimited((mw)->ibmw.device, \
|
|
|
|
"mw#%d %s: " fmt, (mw)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
|
2024-01-09 16:32:52 +08:00
|
|
|
#define rxe_info(fmt, ...) pr_info_ratelimited("%s: " fmt, __func__, \
|
2023-03-03 16:16:23 -06:00
|
|
|
##__VA_ARGS__)
|
|
|
|
#define rxe_info_dev(rxe, fmt, ...) ibdev_info_ratelimited(&(rxe)->ib_dev, \
|
|
|
|
"%s: " fmt, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_uc(uc, fmt, ...) ibdev_info_ratelimited((uc)->ibuc.device, \
|
|
|
|
"uc#%d %s: " fmt, (uc)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_pd(pd, fmt, ...) ibdev_info_ratelimited((pd)->ibpd.device, \
|
|
|
|
"pd#%d %s: " fmt, (pd)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_ah(ah, fmt, ...) ibdev_info_ratelimited((ah)->ibah.device, \
|
|
|
|
"ah#%d %s: " fmt, (ah)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_srq(srq, fmt, ...) ibdev_info_ratelimited((srq)->ibsrq.device, \
|
|
|
|
"srq#%d %s: " fmt, (srq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_qp(qp, fmt, ...) ibdev_info_ratelimited((qp)->ibqp.device, \
|
|
|
|
"qp#%d %s: " fmt, (qp)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_cq(cq, fmt, ...) ibdev_info_ratelimited((cq)->ibcq.device, \
|
|
|
|
"cq#%d %s: " fmt, (cq)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_mr(mr, fmt, ...) ibdev_info_ratelimited((mr)->ibmr.device, \
|
|
|
|
"mr#%d %s: " fmt, (mr)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
#define rxe_info_mw(mw, fmt, ...) ibdev_info_ratelimited((mw)->ibmw.device, \
|
|
|
|
"mw#%d %s: " fmt, (mw)->elem.index, __func__, ##__VA_ARGS__)
|
|
|
|
|
2018-04-20 10:30:54 -04:00
|
|
|
void rxe_set_mtu(struct rxe_dev *rxe, unsigned int dev_mtu);
|
2016-06-16 16:45:23 +03:00
|
|
|
|
RDMA/rxe: Remove the direct link to net_device
The similar patch in siw is in the link:
https://git.kernel.org/rdma/rdma/c/16b87037b48889
This problem also occurred in RXE. The following analyze this problem.
In the following Call Traces:
"
BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0 net/core/dev.c:8782
Read of size 4 at addr ffff8880554640b0 by task kworker/1:4/5295
CPU: 1 UID: 0 PID: 5295 Comm: kworker/1:4 Not tainted
6.12.0-rc3-syzkaller-00399-g9197b73fd7bb #0
Hardware name: Google Compute Engine/Google Compute Engine,
BIOS Google 09/13/2024
Workqueue: infiniband ib_cache_event_task
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:377 [inline]
print_report+0x169/0x550 mm/kasan/report.c:488
kasan_report+0x143/0x180 mm/kasan/report.c:601
dev_get_flags+0x188/0x1d0 net/core/dev.c:8782
rxe_query_port+0x12d/0x260 drivers/infiniband/sw/rxe/rxe_verbs.c:60
__ib_query_port drivers/infiniband/core/device.c:2111 [inline]
ib_query_port+0x168/0x7d0 drivers/infiniband/core/device.c:2143
ib_cache_update+0x1a9/0xb80 drivers/infiniband/core/cache.c:1494
ib_cache_event_task+0xf3/0x1e0 drivers/infiniband/core/cache.c:1568
process_one_work kernel/workqueue.c:3229 [inline]
process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310
worker_thread+0x870/0xd30 kernel/workqueue.c:3391
kthread+0x2f2/0x390 kernel/kthread.c:389
ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244
</TASK>
"
1). In the link [1],
"
infiniband syz2: set down
"
This means that on 839.350575, the event ib_cache_event_task was sent andi
queued in ib_wq.
2). In the link [1],
"
team0 (unregistering): Port device team_slave_0 removed
"
It indicates that before 843.251853, the net device should be freed.
3). In the link [1],
"
BUG: KASAN: slab-use-after-free in dev_get_flags+0x188/0x1d0
"
This means that on 850.559070, this slab-use-after-free problem occurred.
In all, on 839.350575, the event ib_cache_event_task was sent and queued
in ib_wq,
before 843.251853, the net device veth was freed.
on 850.559070, this event was executed, and the mentioned freed net device
was called. Thus, the above call trace occurred.
[1] https://syzkaller.appspot.com/x/log.txt?x=12e7025f980000
Reported-by: syzbot+4b87489410b4efd181bf@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=4b87489410b4efd181bf
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Signed-off-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Link: https://patch.msgid.link/20241220222325.2487767-1-yanjun.zhu@linux.dev
Signed-off-by: Leon Romanovsky <leon@kernel.org>
2024-12-20 23:23:25 +01:00
|
|
|
int rxe_add(struct rxe_dev *rxe, unsigned int mtu, const char *ibdev_name,
|
|
|
|
struct net_device *ndev);
|
2016-06-16 16:45:23 +03:00
|
|
|
|
2018-04-20 17:05:03 +03:00
|
|
|
void rxe_rcv(struct sk_buff *skb);
|
2016-06-16 16:45:23 +03:00
|
|
|
|
2019-02-12 21:12:52 -07:00
|
|
|
/* The caller must do a matching ib_device_put(&dev->ib_dev) */
|
|
|
|
static inline struct rxe_dev *rxe_get_dev_from_net(struct net_device *ndev)
|
|
|
|
{
|
|
|
|
struct ib_device *ibdev =
|
|
|
|
ib_device_get_by_netdev(ndev, RDMA_DRIVER_RXE);
|
|
|
|
|
|
|
|
if (!ibdev)
|
|
|
|
return NULL;
|
|
|
|
return container_of(ibdev, struct rxe_dev, ib_dev);
|
|
|
|
}
|
|
|
|
|
2016-06-16 16:45:23 +03:00
|
|
|
void rxe_port_up(struct rxe_dev *rxe);
|
|
|
|
void rxe_port_down(struct rxe_dev *rxe);
|
2018-12-14 08:05:49 -08:00
|
|
|
void rxe_set_port_state(struct rxe_dev *rxe);
|
2016-06-16 16:45:23 +03:00
|
|
|
|
|
|
|
#endif /* RXE_H */
|