Sashiko points out that the user can specify WQs sharing the same CQ as a
part of the uAPI and this will trigger the WARN_ON() then go on to corrupt
the kernel.

Just reject it outright and fail the QP creation.

Cc: [email protected]
Fixes: c15d7802a424 ("RDMA/mana_ib: Add CQ interrupt support for RAW QP")
Link: 
https://sashiko.dev/#/patchset/0-v2-1c49eeb88c48%2B91-rdma_udata_rep_jgg%40nvidia.com?part=1
Signed-off-by: Jason Gunthorpe <[email protected]>
---
 drivers/infiniband/hw/mana/cq.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/infiniband/hw/mana/cq.c b/drivers/infiniband/hw/mana/cq.c
index f4cbe21763bf11..2d682428ef202a 100644
--- a/drivers/infiniband/hw/mana/cq.c
+++ b/drivers/infiniband/hw/mana/cq.c
@@ -137,8 +137,9 @@ int mana_ib_install_cq_cb(struct mana_ib_dev *mdev, struct 
mana_ib_cq *cq)
 
        if (cq->queue.id >= gc->max_num_cqs)
                return -EINVAL;
-       /* Create CQ table entry */
-       WARN_ON(gc->cq_table[cq->queue.id]);
+       /* Create CQ table entry, sharing a CQ between WQs is not supported */
+       if (gc->cq_table[cq->queue.id])
+               return -EINVAL;
        if (cq->queue.kmem)
                gdma_cq = cq->queue.kmem;
        else
-- 
2.43.0


Reply via email to