[PATCH v2 0/2] RDMA/srp: fix use-after-free of a request in srp_destroy_qp()

Yehyeong Lee posted 2 patches 1 month, 1 week ago
drivers/infiniband/ulp/srp/ib_srp.c | 30 +++++++++++++++++------------
drivers/infiniband/ulp/srp/ib_srp.h |  8 +++++++-
2 files changed, 25 insertions(+), 13 deletions(-)
[PATCH v2 0/2] RDMA/srp: fix use-after-free of a request in srp_destroy_qp()
Posted by Yehyeong Lee 1 month, 1 week ago
Bart asked whether reordering srp_remove_target() also fixes the crash.
It does.  Against the same test target, the report appears in 5 of 5
runs without his patch and in 0 of 5 with it.  The drain still finds
the same two completions; the request pool now outlives it.  A
conforming target was unchanged over 5 runs each way.  Both patches
applied together behave the same way.  I never reached the SCSI error
handler.

Each patch stops the crash on its own, so this series carries both.
Patch 1 takes the shared ib_cqe out of the request; it is tagged for
stable.  Patch 2 is Bart's, carried as posted.  Whether it should go to
stable too is his call.

Two notes on patch 2, from source only.  srp_stop_rport_timers() is
documented as "Must be called after srp_remove_host() and
scsi_remove_host()" (scsi_transport_srp.c:789); patch 2 calls it before
both.  And the host now stays SHOST_RUNNING until the end, so a device
added by a late scan would miss the cache sync.  Its commands fail with
DID_NO_CONNECT, so that is a lost sync, not a crash.

v1: https://lore.kernel.org/linux-rdma/20260812190418.200337-1-yhlee@isslab.korea.ac.kr/

Bart Van Assche (1):
  RDMA/srp: Fix srp_remove_target()

Yehyeong Lee (1):
  RDMA/srp: fix use-after-free of a request in srp_destroy_qp()

 drivers/infiniband/ulp/srp/ib_srp.c | 30 +++++++++++++++++------------
 drivers/infiniband/ulp/srp/ib_srp.h |  8 +++++++-
 2 files changed, 25 insertions(+), 13 deletions(-)

-- 
2.43.0
Re: (subset) [PATCH v2 0/2] RDMA/srp: fix use-after-free of a request in srp_destroy_qp()
Posted by Leon Romanovsky 3 weeks, 5 days ago
On Tue, 18 Aug 2026 12:52:27 +0900, Yehyeong Lee wrote:
> Bart asked whether reordering srp_remove_target() also fixes the crash.
> It does.  Against the same test target, the report appears in 5 of 5
> runs without his patch and in 0 of 5 with it.  The drain still finds
> the same two completions; the request pool now outlives it.  A
> conforming target was unchanged over 5 runs each way.  Both patches
> applied together behave the same way.  I never reached the SCSI error
> handler.
> 
> [...]

Applied, thanks!

[2/2] RDMA/srp: Fix srp_remove_target()
      https://git.kernel.org/rdma/rdma/c/9cdfad5dd5529e

Best regards,
-- 
Leon Romanovsky <leon@kernel.org>
Re: (subset) [PATCH v2 0/2] RDMA/srp: fix use-after-free of a request in srp_destroy_qp()
Posted by Bart Van Assche 3 weeks, 3 days ago
On 9/2/26 5:59 AM, Leon Romanovsky wrote:
> Applied, thanks!
> 
> [2/2] RDMA/srp: Fix srp_remove_target()
>        https://git.kernel.org/rdma/rdma/c/9cdfad5dd5529e

Thanks Leon!

Bart.