summaryrefslogtreecommitdiff
path: root/include/linux/ptp_clock_kernel.h
diff options
context:
space:
mode:
authorChuck Lever <chuck.lever@oracle.com>2025-09-03 11:53:35 -0400
committerChuck Lever <chuck.lever@oracle.com>2025-11-16 18:20:11 -0500
commitbf94dea7fd4e6708d1a784be23db65eff84d82f1 (patch)
tree6767b75234807c22368795f5c4861f3365cd86cd /include/linux/ptp_clock_kernel.h
parent6a23ae0a96a600d1d12557add110e0bb6e32730c (diff)
downloadkernel-bf94dea7fd4e6708d1a784be23db65eff84d82f1.tar.gz
svcrdma: Release transport resources synchronously
NFSD has always supported added network listeners. The new netlink protocol now enables the removal of listeners. Olga noticed that if an RDMA listener is removed and immediately re-added, the deferred __svc_rdma_free() function might not have run yet, so some or all of the old listener's RDMA resources linger, which prevents a new listener on the same address from being created. Also, svc_xprt_free() does a module_put() just after calling ->xpo_free(). That means if there is deferred work going on, the module could be unloaded before that work is even started, resulting in a UAF. Neil asks: > What particular part of __svc_rdma_free() needs to run in order for a > subsequent registration to succeed? > Can that bit be run directory from svc_rdma_free() rather than be > delayed? > (I know almost nothing about rdma so forgive me if the answers to these > questions seems obvious) The reasons I can recall are: - Some of the transport tear-down work can sleep - Releasing a cm_id is tricky and can deadlock We might be able to mitigate the second issue with judicious application of transport reference counting. Reported-by: Olga Kornievskaia <okorniev@redhat.com> Closes: https://lore.kernel.org/linux-nfs/20250821204328.89218-1-okorniev@redhat.com/ Suggested-by: NeilBrown <neil@brown.name> Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Diffstat (limited to 'include/linux/ptp_clock_kernel.h')
0 files changed, 0 insertions, 0 deletions
ro/kernel/commit/Documentation/scsi/index.rst?id=8dca37d259dff2371d414c51b72b5730e3c1ed01'>scsi: docs: convert ncr53c8xx.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert megaraid.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert lpfc.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert link_power_management_policy.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert libsas.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert hptiop.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert hpsa.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert g_NCR5380.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert FlashPoint.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert dpti.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert dc395x.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert cxgb3i.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert BusLogic.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert bnx2fc.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert bfa.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert aic7xxx.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert aic79xx.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert aha152x.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert advansys.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert aacraid.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: convert 53c700.txt to ReSTMauro Carvalho Chehab 2020-03-11scsi: docs: include SCSI Transport SRP diagram at the doc bodyMauro Carvalho Chehab 2020-03-11scsi: docs: Add an empty index file for SCSI documentsMauro Carvalho Chehab