Skip to content

Commit

Permalink
IB/rxe: Wait for tasklets to finish before tearing down QP
Browse files Browse the repository at this point in the history
The system may crash when a malformed request is received and
the error is detected by the responder.

NodeA: $ ibv_rc_pingpong -g 0 -d rxe0 -i 1 -n 1 -s 50000
NodeB: $ ibv_rc_pingpong -g 0 -d rxe0 -i 1 -n 1 -s 1024 <NodeA_ip>

The responder generates a receive error on node B since the incoming
SEND is oversized. If the client tears down the QP before the responder
or the completer finish running, a page fault may occur.

The fix makes the destroy operation spin until the tasks complete, which
appears to be original intent of the design.

Signed-off-by: Andrew Boyer <andrew.boyer@dell.com>
Reviewed-by: Yuval Shaia <yuval.shaia@oracle.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
  • Loading branch information
Andrew Boyer authored and Doug Ledford committed Dec 12, 2016
1 parent 5407f53 commit 07bf962
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 0 deletions.
19 changes: 19 additions & 0 deletions drivers/infiniband/sw/rxe/rxe_task.c
Original file line number Diff line number Diff line change
Expand Up @@ -121,6 +121,7 @@ int rxe_init_task(void *obj, struct rxe_task *task,
task->arg = arg;
task->func = func;
snprintf(task->name, sizeof(task->name), "%s", name);
task->destroyed = false;

tasklet_init(&task->tasklet, rxe_do_task, (unsigned long)task);

Expand All @@ -132,11 +133,29 @@ int rxe_init_task(void *obj, struct rxe_task *task,

void rxe_cleanup_task(struct rxe_task *task)
{
unsigned long flags;
bool idle;

/*
* Mark the task, then wait for it to finish. It might be
* running in a non-tasklet (direct call) context.
*/
task->destroyed = true;

do {
spin_lock_irqsave(&task->state_lock, flags);
idle = (task->state == TASK_STATE_START);
spin_unlock_irqrestore(&task->state_lock, flags);
} while (!idle);

tasklet_kill(&task->tasklet);
}

void rxe_run_task(struct rxe_task *task, int sched)
{
if (task->destroyed)
return;

if (sched)
tasklet_schedule(&task->tasklet);
else
Expand Down
1 change: 1 addition & 0 deletions drivers/infiniband/sw/rxe/rxe_task.h
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,7 @@ struct rxe_task {
int (*func)(void *arg);
int ret;
char name[16];
bool destroyed;
};

/*
Expand Down

0 comments on commit 07bf962

Please sign in to comment.