From: Eli Cohen Date: Wed, 22 Feb 2017 21:55:10 +0000 (-0600) Subject: net/mlx4_core: Disallow creation of RAW QPs on a VF X-Git-Tag: v4.1.12-98.0.20170517_2143~38^2 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=64453f042519;p=users%2Fjedix%2Flinux-maple.git net/mlx4_core: Disallow creation of RAW QPs on a VF This is considered a security breach since RAW QPs, implemented using MLX transport QPs, can send any message they wish to. Orabug: 257846022 Tested-by: Pierre Orzechowski Reviewed-by: Santosh Shilimkar Signed-off-by: Eli Cohen Signed-off-by: Mukesh Kacker Signed-off-by: Brian Maly --- diff --git a/drivers/net/ethernet/mellanox/mlx4/resource_tracker.c b/drivers/net/ethernet/mellanox/mlx4/resource_tracker.c index b25e12a1d417..441d062d468d 100644 --- a/drivers/net/ethernet/mellanox/mlx4/resource_tracker.c +++ b/drivers/net/ethernet/mellanox/mlx4/resource_tracker.c @@ -2705,6 +2705,11 @@ static u32 qp_get_srqn(struct mlx4_qp_context *qpc) return be32_to_cpu(qpc->srqn) & 0x1ffffff; } +static u32 qp_get_st(struct mlx4_qp_context *qpc) +{ + return (be32_to_cpu(qpc->flags) >> 16) & 0xff; +} + static void adjust_proxy_tun_qkey(struct mlx4_dev *dev, struct mlx4_vhcr *vhcr, struct mlx4_qp_context *context) { @@ -2739,6 +2744,10 @@ int mlx4_RST2INIT_QP_wrapper(struct mlx4_dev *dev, int slave, int use_srq = (qp_get_srqn(qpc) >> 24) & 1; struct res_srq *srq; int local_qpn = be32_to_cpu(qpc->local_qpn) & 0xffffff; + int st = qp_get_st(qpc); + + if ((slave != mlx4_master_func_num(dev)) && (st == MLX4_QP_ST_MLX)) + return -EPERM; err = qp_res_start_move_to(dev, slave, qpn, RES_QP_HW, &qp, 0); if (err)