Thread (4 messages) read the whole thread 4 messages, 3 authors, 2021-05-10

Re: [PATCH rdma-rc] RDMA/siw: Properly check send and receive CQ pointers

From: Bernard Metzler <hidden>
Date: 2021-05-10 09:33:48
Also in: lkml

-----"Leon Romanovsky" [off-list ref] wrote: -----
quoted hunk ↗ jump to hunk
To: "Doug Ledford" <redacted>, "Jason Gunthorpe"
[off-list ref]
From: "Leon Romanovsky" <leon@kernel.org>
Date: 05/09/2021 01:39PM
Cc: "Leon Romanovsky" <leonro@nvidia.com>, "Bernard Metzler"
[off-list ref], linux-kernel@vger.kernel.org,
linux-rdma@vger.kernel.org
Subject: [EXTERNAL] [PATCH rdma-rc] RDMA/siw: Properly check send and
receive CQ pointers

From: Leon Romanovsky <leonro@nvidia.com>

The check for the NULL of pointer received from container_of is
incorrect by definition as it points to some random memory.

Change such check with proper NULL check of SIW QP attributes.

Fixes: 303ae1cdfdf7 ("rdma/siw: application interface")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
---
drivers/infiniband/sw/siw/siw_verbs.c | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/sw/siw/siw_verbs.c
b/drivers/infiniband/sw/siw/siw_verbs.c
index d2313efb26db..917c8a919f38 100644
--- a/drivers/infiniband/sw/siw/siw_verbs.c
+++ b/drivers/infiniband/sw/siw/siw_verbs.c
@@ -300,7 +300,6 @@ struct ib_qp *siw_create_qp(struct ib_pd *pd,
	struct siw_ucontext *uctx =
		rdma_udata_to_drv_context(udata, struct siw_ucontext,
					  base_ucontext);
-	struct siw_cq *scq = NULL, *rcq = NULL;
	unsigned long flags;
	int num_sqe, num_rqe, rv = 0;
	size_t length;
@@ -343,10 +342,8 @@ struct ib_qp *siw_create_qp(struct ib_pd *pd,
		rv = -EINVAL;
		goto err_out;
	}
-	scq = to_siw_cq(attrs->send_cq);
-	rcq = to_siw_cq(attrs->recv_cq);

-	if (!scq || (!rcq && !attrs->srq)) {
+	if (!attrs->send_cq || (!attrs->recv_cq && !attrs->srq)) {
		siw_dbg(base_dev, "send CQ or receive CQ invalid\n");
		rv = -EINVAL;
		goto err_out;
@@ -401,8 +398,8 @@ struct ib_qp *siw_create_qp(struct ib_pd *pd,
		}
	}
	qp->pd = pd;
-	qp->scq = scq;
-	qp->rcq = rcq;
+	qp->scq = to_siw_cq(attrs->send_cq);
+	qp->rcq = to_siw_cq(attrs->recv_cq);

	if (attrs->srq) {
		/*
-- 
2.31.1
Thanks Leon!

Reviewed-by: Bernard Metzler <redacted>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help