summaryrefslogtreecommitdiff
path: root/include/linux/ref_tracker.h
diff options
context:
space:
mode:
authorChuck Lever <chuck.lever@oracle.com>2025-09-03 11:53:35 -0400
committerChuck Lever <chuck.lever@oracle.com>2025-11-16 18:20:11 -0500
commitbf94dea7fd4e6708d1a784be23db65eff84d82f1 (patch)
tree6767b75234807c22368795f5c4861f3365cd86cd /include/linux/ref_tracker.h
parent6a23ae0a96a600d1d12557add110e0bb6e32730c (diff)
downloadkernel-bf94dea7fd4e6708d1a784be23db65eff84d82f1.tar.gz
svcrdma: Release transport resources synchronously
NFSD has always supported added network listeners. The new netlink protocol now enables the removal of listeners. Olga noticed that if an RDMA listener is removed and immediately re-added, the deferred __svc_rdma_free() function might not have run yet, so some or all of the old listener's RDMA resources linger, which prevents a new listener on the same address from being created. Also, svc_xprt_free() does a module_put() just after calling ->xpo_free(). That means if there is deferred work going on, the module could be unloaded before that work is even started, resulting in a UAF. Neil asks: > What particular part of __svc_rdma_free() needs to run in order for a > subsequent registration to succeed? > Can that bit be run directory from svc_rdma_free() rather than be > delayed? > (I know almost nothing about rdma so forgive me if the answers to these > questions seems obvious) The reasons I can recall are: - Some of the transport tear-down work can sleep - Releasing a cm_id is tricky and can deadlock We might be able to mitigate the second issue with judicious application of transport reference counting. Reported-by: Olga Kornievskaia <okorniev@redhat.com> Closes: https://lore.kernel.org/linux-nfs/20250821204328.89218-1-okorniev@redhat.com/ Suggested-by: NeilBrown <neil@brown.name> Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Diffstat (limited to 'include/linux/ref_tracker.h')
0 files changed, 0 insertions, 0 deletions
53:27 +0000'>2022-01-27hsr: remove get_prp_lan_id()Jakub Kicinski 2021-11-29net: Write lock dev_base_lock without disabling bottom halves.Sebastian Andrzej Siewior 2021-10-26net: hsr: Add support for redbox supervision framesAndreas Oetken 2021-10-24net: hsr: get ready for const netdev->dev_addrJakub Kicinski 2021-10-02net: use eth_hw_addr_set() instead of ether_addr_copy()Jakub Kicinski 2021-06-16net: hsr: don't check sequence number if tag removal is offloadedGeorge McCollister 2021-05-24net: hsr: fix mac_len checksGeorge McCollister 2021-05-03net: hsr: check skb can contain struct hsr_ethhdr in fill_frame_infoPhillip Potter 2021-04-09Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski 2021-04-07net: hsr: Reset MAC header for Tx pathKurt Kanzenbach 2021-03-18/net/hsr: fix misspellings using codespell toolXiong Zhenwu 2021-02-25net: hsr: add support for EntryForgetTimeMarco Wenzel 2021-02-11net: hsr: add offloading supportGeorge McCollister 2021-02-11net: hsr: generate supervision frame without HSR/PRP tagGeorge McCollister 2021-02-02net: hsr: align sup_multicast_addr in struct hsr_priv to u16 boundaryAndreas Oetken 2020-10-02genetlink: move to smaller ops wherever possibleJakub Kicinski 2020-09-22Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netDavid S. Miller 2020-09-17net: hsr: Convert to DEFINE_SHOW_ATTRIBUTEQinglang Miao 2020-09-09hsr: avoid newline at end of message in NL_SET_ERR_MSG_MODYe Bin