Thread (5 messages) 5 messages, 4 authors, 4d ago

Re: [PATCH net v5] net/smc: fix lgr/lnk lifetime vs diag reader race

From: Dust Li <dust.li@linux.alibaba.com>
Date: 2026-09-24 07:08:23
Also in: linux-rdma, linux-s390, stable

On 2026-09-23 08:17:16, Mahanta Jambigi wrote:
The diag dump walks the socket hash table under a read_lock and dereferences
conn->lgr and conn->lnk. Two terminal teardown paths drop those references via
smc_conn_free() while the socket is still hashed:

 - smc_conn_kill() -> smc_close_active_abort() -> smc_conn_free()
 - smc_close_passive_work() -> smc_conn_free()

This allows the diag reader to dereference a freed lgr or lnk.

Fix it by unhashing the socket before smc_conn_free() is called at the two
terminal teardown sites in smc_close.c.

Additionally, smc_conn_abort() calls smc_conn_free() during early handshake
aborts while the socket remains hashed in SMC_INIT state. The
smc_listen_out_err() path leaves the socket hashed in SMC_CLOSED state after
smc_conn_abort() returns. Guard the conn/lgr/lnk inspection blocks in
__smc_diag_dump() by skipping them when the socket is in SMC_INIT or SMC_CLOSED
state.

Fixes: f16a7dd5cf27 ("smc: netlink interface for SMC sockets")
Fixes: 9dbe086c69b8 ("net/smc: fix invalid link access in dumping SMC-R connections")
Signed-off-by: Mahanta Jambigi <mjambigi@linux.ibm.com>

Reviewed-by: Dust Li <dust.li@linux.alibaba.com>

Best regards,
Dust
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help