summaryrefslogtreecommitdiff
path: root/security/landlock
diff options
context:
space:
mode:
authorChuck Lever <chuck.lever@oracle.com>2025-09-03 11:53:35 -0400
committerChuck Lever <chuck.lever@oracle.com>2025-11-16 18:20:11 -0500
commitbf94dea7fd4e6708d1a784be23db65eff84d82f1 (patch)
tree6767b75234807c22368795f5c4861f3365cd86cd /security/landlock
parent6a23ae0a96a600d1d12557add110e0bb6e32730c (diff)
svcrdma: Release transport resources synchronously
NFSD has always supported added network listeners. The new netlink protocol now enables the removal of listeners. Olga noticed that if an RDMA listener is removed and immediately re-added, the deferred __svc_rdma_free() function might not have run yet, so some or all of the old listener's RDMA resources linger, which prevents a new listener on the same address from being created. Also, svc_xprt_free() does a module_put() just after calling ->xpo_free(). That means if there is deferred work going on, the module could be unloaded before that work is even started, resulting in a UAF. Neil asks: > What particular part of __svc_rdma_free() needs to run in order for a > subsequent registration to succeed? > Can that bit be run directory from svc_rdma_free() rather than be > delayed? > (I know almost nothing about rdma so forgive me if the answers to these > questions seems obvious) The reasons I can recall are: - Some of the transport tear-down work can sleep - Releasing a cm_id is tricky and can deadlock We might be able to mitigate the second issue with judicious application of transport reference counting. Reported-by: Olga Kornievskaia <okorniev@redhat.com> Closes: https://lore.kernel.org/linux-nfs/20250821204328.89218-1-okorniev@redhat.com/ Suggested-by: NeilBrown <neil@brown.name> Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Diffstat (limited to 'security/landlock')
0 files changed, 0 insertions, 0 deletions
86f0cd9690357b9bb67af00d386a7e819f'>ice: cleanup capabilities evaluationDave Ertman 2025-07-24libie: add adminq helper for converting err to strMichal Swiatkowski 2025-07-24i40e: use libie adminq descriptorsMichal Swiatkowski 2025-07-24ixgbe: use libie adminq descriptorsMichal Swiatkowski 2025-07-24ice, libie: move generic adminq descriptors to libMichal Swiatkowski 2025-07-17Merge branch 'for-next' of git://git.kernel.org/pub/scm/linux/kernel/git/tngu...Paolo Abeni 2025-07-14idpf: implement get LAN MMIO memory regionsJoshua Hay 2025-07-14idpf: implement RDMA vport auxiliary dev create, init, and destroyJoshua Hay 2025-07-14idpf: implement core RDMA auxiliary dev create, init, and destroyJoshua Hay 2025-06-09net: intel: move RSS packet classifier types to libieJacob Keller 2025-05-09iidc/ice/irdma: Update IDC to support multiple consumersDave Ertman 2025-04-30ice: Replace ice specific DSCP mapping num with a kernel defineTatyana Nikolova 2025-04-30iidc/ice/irdma: Break iidc.h into two headersDave Ertman 2025-04-30iidc/ice/irdma: Rename to iidc_* conventionDave Ertman 2025-04-30iidc/ice/irdma: Rename IDC header fileDave Ertman 2025-02-05ice, irdma: move interrupts code to irdmaMichal Swiatkowski 2024-04-24iavf: switch to Page PoolAlexander Lobakin 2024-04-24net: intel: introduce {, Intel} Ethernet common libraryAlexander Lobakin 2023-11-30i40e: Annotate struct i40e_qvlist_info with __counted_byKees Cook 2022-02-08Merge branch 'iwl-next' of git://git.kernel.org/pub/scm/linux/kernel/git/tngu...Jakub Kicinski 2022-02-03ice: add support for DSCP QoS for IDCDave Ertman 2022-02-03i40e: remove enum i40e_client_stateJakub Kicinski 2021-11-22net/ice: Add support for enable_iwarp and enable_roce devlink paramShiraz Saleem 2021-06-02RDMA/irdma: Add irdma Kconfig/Makefile and remove i40iwShiraz Saleem 2021-05-28i40e: Prep i40e header for aux bus conversionShiraz Saleem 2021-05-28iidc: Introduce iidc.hDave Ertman 2021-05-26i40e: Replace one-element array with flexible-array memberGustavo A. R. Silva 2020-06-25i40e: remove unused definesJesse Brandeburg 2020-06-25i40e: Move client header locationShiraz Saleem