Path: csiph.com!aioe.org!bofh.it!news.nic.it!robomod From: Andrea Righi Newsgroups: linux.kernel Subject: Re: [PATCH] ib_isert: prevent NULL pointer dereference in isert_login_recv_done() Date: Thu, 29 Jun 2017 10:30:01 +0200 Message-ID: References: X-Original-To: Sagi Grimberg Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=BzF0g/Moq0mDF0QvbyaeUGWCJByODlrSQRecc/ztwIo=; b=dIDKbNJ5XHvWRw16YHQ5Qxf2GK0jvEGnqH64f2qvfo7wQdCogA7xcy9p0FHhr99a5Q jc8H0QlNkE9A4zjB5rmwW55xTKvCKcUALS0N9KrBsd62/pyn7NHnIIafPhHXbPThW5B2 qIBMQQdXQgkEkGHDEizBYxFl+lQ7nRUTaL5jnsutbPWDIHAmyfnHMwiZ7+fIS/cR0xT3 G3jAMd0LJ1xuHBHEOIjV5ZM6CYZFRwVfWast/5xyD1yjEKK8s7OVMZvZS8LYUORiPHb7 surV3aSz0jTqvB9sg/i+ijF6vTaC6jUN+YnDZRufEND8qPPTV+WTe2VAMlZ6uwd4NueU E2KQ== X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=BzF0g/Moq0mDF0QvbyaeUGWCJByODlrSQRecc/ztwIo=; b=sarjrAUf1WRLPenN2tUSaqgTWqIJzsIGaMwW8Fus9jnEjWkOO40WfraqPk86a9LDtj 2wc85SRTW6wtFm8yCUvELYXNIeZhWwxXMr8db504whdvOqDLhMedM7kwy9dU9nE5oLHk sITiRpQqa4E3aRx7rWg1kRtDh19g8LVoatB6hLCly/jrrvNTd2oCVsq1mnUPzY+gRc/w r7PkMhffjY7rkAwly1f5ROjfjSV92Rf9QBqhebRWf/Y9uCCVhNgeyfCbW1hD/pfyiYwu rU0i6fYK+NzmJjHXj7JgLQRq77XeA8amxCmwxVnKAJUdUv3tJDq2rfVYxBIk6YMq4n6+ k22w== X-Gm-Message-State: AIVw113TQijFTJyYMOmAreyVJD+tTLdeTV9mUbfIJPuiMeH6y8WCZExV /OVWyfys6GNsIQ== X-Received: by 10.28.148.18 with SMTP id w18mr845580wmd.56.1498724460107; Thu, 29 Jun 2017 01:21:00 -0700 (PDT) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.24 (2015-08-30) Sender: robomod@news.nic.it List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Approved: robomod@news.nic.it Lines: 26 Organization: linux.* mail to news gateway X-Original-Cc: "Nicholas A. Bellinger" , Robert LeBlanc , Sean Jenkins , Doug Ledford , Sean Hefty , Hal Rosenstock , linux-rdma , target-devel , lkml , Christoph Hellwig X-Original-Date: Thu, 29 Jun 2017 10:20:57 +0200 X-Original-Message-ID: <20170629082057.GA2037@Dell> X-Original-References: <20170622223757.GC28955@Dell> <1498435084.26123.66.camel@haakon3.risingtidesystems.com> <20170628175354.GB1769@Dell> X-Original-Sender: linux-kernel-owner@vger.kernel.org Xref: csiph.com linux.kernel:1677514 On Thu, Jun 29, 2017 at 08:36:51AM +0300, Sagi Grimberg wrote: > > >Just tested this patch, I wasn't able to reproduce the NULL pointer > >dereference or any other bugs, so this fix seems safe enough to me. > > > >Tested-by: Andrea Righi > > Can you test just the one liner fix below? > > >>@@ -1452,7 +1452,7 @@ > >> isert_login_recv_done(struct ib_cq *cq, struct ib_wc *wc) > >> { > >> struct isert_conn *isert_conn = wc->qp->qp_context; > >>- struct ib_device *ib_dev = isert_conn->cm_id->device; > >>+ struct ib_device *ib_dev = isert_conn->device->ib_device; > >> if (unlikely(wc->status != IB_WC_SUCCESS)) { > >> isert_print_wc(wc, "login recv"); I'll test also this one-liner fix as soon as I can. But I can say that I'm pretty sure it will work as well, because all the previous NULL pointer dereferences that we've got in the past happened all 100% in isert_login_recv_done(). The other cases are probably a safe precaution, but they can't really happen. -Andrea