summaryrefslogtreecommitdiff
path: root/include/linux/usb/audio.h
diff options
context:
space:
mode:
authorChuck Lever <chuck.lever@oracle.com>2025-09-03 11:53:35 -0400
committerChuck Lever <chuck.lever@oracle.com>2025-11-16 18:20:11 -0500
commitbf94dea7fd4e6708d1a784be23db65eff84d82f1 (patch)
tree6767b75234807c22368795f5c4861f3365cd86cd /include/linux/usb/audio.h
parent6a23ae0a96a600d1d12557add110e0bb6e32730c (diff)
downloadkernel-bf94dea7fd4e6708d1a784be23db65eff84d82f1.tar.gz
svcrdma: Release transport resources synchronously
NFSD has always supported added network listeners. The new netlink protocol now enables the removal of listeners. Olga noticed that if an RDMA listener is removed and immediately re-added, the deferred __svc_rdma_free() function might not have run yet, so some or all of the old listener's RDMA resources linger, which prevents a new listener on the same address from being created. Also, svc_xprt_free() does a module_put() just after calling ->xpo_free(). That means if there is deferred work going on, the module could be unloaded before that work is even started, resulting in a UAF. Neil asks: > What particular part of __svc_rdma_free() needs to run in order for a > subsequent registration to succeed? > Can that bit be run directory from svc_rdma_free() rather than be > delayed? > (I know almost nothing about rdma so forgive me if the answers to these > questions seems obvious) The reasons I can recall are: - Some of the transport tear-down work can sleep - Releasing a cm_id is tricky and can deadlock We might be able to mitigate the second issue with judicious application of transport reference counting. Reported-by: Olga Kornievskaia <okorniev@redhat.com> Closes: https://lore.kernel.org/linux-nfs/20250821204328.89218-1-okorniev@redhat.com/ Suggested-by: NeilBrown <neil@brown.name> Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Diffstat (limited to 'include/linux/usb/audio.h')
0 files changed, 0 insertions, 0 deletions
pan>bpf, devmap: Move drop error path to devmap for XDP_REDIRECTLorenzo Bianconi 2021-01-08net, xdp: Introduce xdp_prepare_buff utility routineLorenzo Bianconi 2021-01-08net, xdp: Introduce xdp_init_buff utility routineLorenzo Bianconi 2020-08-23treewide: Use fallthrough pseudo-keywordGustavo A. R. Silva 2020-07-25bpf, xdp: Remove XDP_QUERY_PROG and XDP_QUERY_PROG_HW XDP commandsAndrii Nakryiko 2020-05-14bnxt: Add XDP frame size to driverJesper Dangaard Brouer 2019-07-08bnxt_en: add page_pool supportAndy Gospodarek 2019-07-08bnxt_en: optimized XDP_REDIRECT supportAndy Gospodarek 2019-07-08bnxt_en: Refactor __bnxt_xmit_xdp().Michael Chan 2019-07-08bnxt_en: rename some xdp functionsAndy Gospodarek 2018-12-17bnxt_en: get rid of num_stat_ctxs variableVasundhara Volam 2018-10-15bnxt_en: Re-structure doorbells.Michael Chan 2018-07-13xdp: don't make drivers report attachment modeJakub Kicinski 2018-04-18bpf: make bnxt compatible w/ bpf_xdp_adjust_tailNikita V. Shirokov 2018-01-05bnxt_en: setup xdp_rxq_infoJesper Dangaard Brouer 2017-11-05net: bpf: rename ndo_xdp to ndo_bpfJakub Kicinski 2017-09-26bpf: add meta pointer for direct accessDaniel Borkmann 2017-08-28bnxt_en: Improve tx ring reservation logic.Michael Chan 2017-07-11bnxt_en: Fix bug in ethtool -L.Michael Chan 2017-06-16bpf: bnxt: Report bpf_prog ID during XDP_QUERY_PROGMartin KaFai Lau 2017-05-30bnxt_en: Optimize doorbell write operations for newer chips.Michael Chan 2017-04-05bnxt_en: Use short TX BDs for the XDP TX ring.Michael Chan 2017-04-05bnxt_en: Add ethtool mac loopback self test.Michael Chan 2017-02-07bnxt_en: Add support for XDP_TX action.Michael Chan 2017-02-07bnxt_en: Add basic XDP support.Michael Chan