RDMA/rxe: Fix incorrect rxe_put in error path
authorBob Pearson <rpearsonhpe@gmail.com>
Fri, 29 Mar 2024 14:55:12 +0000 (09:55 -0500)
committerJason Gunthorpe <jgg@nvidia.com>
Mon, 22 Apr 2024 19:54:33 +0000 (16:54 -0300)
In rxe_send() a ref is taken on the qp to keep it alive until the
kfree_skb() has a chance to call the skb destructor rxe_skb_tx_dtor()
which drops the reference. If the packet has an incorrect protocol the
error path just calls kfree_skb() which will call the destructor which
will drop the ref. Currently the driver also calls rxe_put() which is
incorrect. Additionally since the packets sent to rxe_send() are under the
control of the driver and it only ever produces IPV4 or IPV6 packets the
simplest fix is to remove all the code in this block.

Link: https://lore.kernel.org/r/20240329145513.35381-12-rpearsonhpe@gmail.com
Signed-off-by: Bob Pearson <rpearsonhpe@gmail.com>
Fixes: 9eb7f8e44d13 ("IB/rxe: Move refcounting earlier in rxe_send()")
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
drivers/infiniband/sw/rxe/rxe_net.c

index a2fc118e7ec1fa1fb2a227773e4dc8b76b160ec7..d81440038f916ffc86b384d1272052dde4fbb3fa 100644 (file)
@@ -366,18 +366,10 @@ static int rxe_send(struct sk_buff *skb, struct rxe_pkt_info *pkt)
        rxe_get(pkt->qp);
        atomic_inc(&pkt->qp->skb_out);
 
-       if (skb->protocol == htons(ETH_P_IP)) {
+       if (skb->protocol == htons(ETH_P_IP))
                err = ip_local_out(dev_net(skb_dst(skb)->dev), skb->sk, skb);
-       } else if (skb->protocol == htons(ETH_P_IPV6)) {
+       else
                err = ip6_local_out(dev_net(skb_dst(skb)->dev), skb->sk, skb);
-       } else {
-               rxe_dbg_qp(pkt->qp, "Unknown layer 3 protocol: %d\n",
-                               skb->protocol);
-               atomic_dec(&pkt->qp->skb_out);
-               rxe_put(pkt->qp);
-               kfree_skb(skb);
-               return -EINVAL;
-       }
 
        if (unlikely(net_xmit_eval(err))) {
                rxe_dbg_qp(pkt->qp, "error sending packet: %d\n", err);