Skip to content

Commit 2a62b62

Browse files
zhuyjjgunthorpe
authored andcommitted
RDMA/rxe: Fix the use-before-initialization error of resp_pkts
In the following: Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 assign_lock_key kernel/locking/lockdep.c:982 [inline] register_lock_class+0xdb6/0x1120 kernel/locking/lockdep.c:1295 __lock_acquire+0x10a/0x5df0 kernel/locking/lockdep.c:4951 lock_acquire kernel/locking/lockdep.c:5691 [inline] lock_acquire+0x1b1/0x520 kernel/locking/lockdep.c:5656 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0x3d/0x60 kernel/locking/spinlock.c:162 skb_dequeue+0x20/0x180 net/core/skbuff.c:3639 drain_resp_pkts drivers/infiniband/sw/rxe/rxe_comp.c:555 [inline] rxe_completer+0x250d/0x3cc0 drivers/infiniband/sw/rxe/rxe_comp.c:652 rxe_qp_do_cleanup+0x1be/0x820 drivers/infiniband/sw/rxe/rxe_qp.c:761 execute_in_process_context+0x3b/0x150 kernel/workqueue.c:3473 __rxe_cleanup+0x21e/0x370 drivers/infiniband/sw/rxe/rxe_pool.c:233 rxe_create_qp+0x3f6/0x5f0 drivers/infiniband/sw/rxe/rxe_verbs.c:583 This is a use-before-initialization problem. It happens because rxe_qp_do_cleanup is called during error unwind before the struct has been fully initialized. Move the initialization of the skb earlier. Fixes: 8700e3e ("Soft RoCE driver") Link: https://lore.kernel.org/r/20230602035408.741534-1-yanjun.zhu@intel.com Reported-by: syzbot+eba589d8f49c73d356da@syzkaller.appspotmail.com Signed-off-by: Zhu Yanjun <yanjun.zhu@linux.dev> Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
1 parent 18e7e3e commit 2a62b62

1 file changed

Lines changed: 3 additions & 4 deletions

File tree

drivers/infiniband/sw/rxe/rxe_qp.c

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -176,6 +176,9 @@ static void rxe_qp_init_misc(struct rxe_dev *rxe, struct rxe_qp *qp,
176176
spin_lock_init(&qp->rq.producer_lock);
177177
spin_lock_init(&qp->rq.consumer_lock);
178178

179+
skb_queue_head_init(&qp->req_pkts);
180+
skb_queue_head_init(&qp->resp_pkts);
181+
179182
atomic_set(&qp->ssn, 0);
180183
atomic_set(&qp->skb_out, 0);
181184
}
@@ -234,8 +237,6 @@ static int rxe_qp_init_req(struct rxe_dev *rxe, struct rxe_qp *qp,
234237
qp->req.opcode = -1;
235238
qp->comp.opcode = -1;
236239

237-
skb_queue_head_init(&qp->req_pkts);
238-
239240
rxe_init_task(&qp->req.task, qp, rxe_requester);
240241
rxe_init_task(&qp->comp.task, qp, rxe_completer);
241242

@@ -279,8 +280,6 @@ static int rxe_qp_init_resp(struct rxe_dev *rxe, struct rxe_qp *qp,
279280
}
280281
}
281282

282-
skb_queue_head_init(&qp->resp_pkts);
283-
284283
rxe_init_task(&qp->resp.task, qp, rxe_responder);
285284

286285
qp->resp.opcode = OPCODE_NONE;

0 commit comments

Comments
 (0)