Bug 2497058 - librxe: wr_set_sge_list() mis-computes WR length
Summary: librxe: wr_set_sge_list() mis-computes WR length
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: rdma-core
Version: 44
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Michal Schmidt
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-04 15:45 UTC by Ming Lei
Modified: 2026-09-11 01:01 UTC (History)
3 users (show)

Fixed In Version: rdma-core-61.1^20260812git975bdaf-1.fc44
Clone Of:
Environment:
Last Closed: 2026-09-11 01:01:24 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ming Lei 2026-07-04 15:45:20 UTC
# Fedora 44 bug report: rdma-core / librxe

**Component:** rdma-core
**Version:** 61.0-2.fc44 (Fedora 44)
**Severity:** high (data-path corruption / connection loss on the rxe provider)

**Summary:** librxe: wr_set_sge_list() mis-computes WR length (num_sge × sg_list[0].length) — multi-SGE work requests via the ibv_qp_ex API are corrupted; fixed upstream, needs backport

## Description

`providers/rxe/rxe.c:wr_set_sge_list()` sums the scatter/gather list without ever
advancing the list pointer:

```c
while (num_sge--)
        tot_length += sg_list->length;
```

so `wqe->dma.length` / `wqe->dma.resid` end up as `num_sge * sg_list[0].length`
instead of the true sum. Every work request posted through the extended QP
work-request API (`ibv_wr_start()` / `ibv_wr_set_sge_list()` /
`ibv_wr_complete()`) with **more than one SGE** on the rxe (soft-RoCE) provider
carries a corrupted total length. The per-SGE entries themselves are correct
(populated by the preceding `memcpy()`), so single-SGE WRs are accidentally
unaffected — which is why the bug is easy to miss.

Consequences, depending on opcode:

- **RDMA READ:** the inflated length goes on the wire in the RETH header; the
  responder rejects it against the (correctly sized) remote MR —
  `iova/length out of range` in kernel rxe — and returns NAK Remote Access
  Error. The requester's SQ completes with `IBV_WC_REM_ACCESS_ERR` (status 10)
  and the QP transitions to error.
- **SEND / RDMA WRITE:** the kernel rxe driver requires
  `dma.length == sum(sge[i].length)`; `copy_data()` runs off the end of the
  SGE list and the WR completes with `IB_WC_LOC_PROT_ERR`.

## How reproduced

A userspace NVMe-oF RDMA target on rxe, driven by the in-kernel nvme-rdma
initiator running xfstests `generic/113` (aio-stress). Any fragmented buffer
produced a multi-SGE RDMA READ, whose inflated wire length killed the QP
within seconds (e.g. a 96 KiB transfer with `num_sge = 3`,
`sg_list[0].length = 64 KiB` went out as a 192 KiB read against a 96 KiB MR).
The NVMe host controller then entered error recovery. A one-line fix to the
summing loop makes the same workload pass.

How reproducible: always, within seconds, with any multi-SGE extended-API WR
on rxe.

## Introduced by

Upstream `1a894ca10105` ("Providers/rxe: Implement ibv_create_qp_ex verb") —
i.e. present since the extended-WR API was added to librxe.

## Fixed upstream

- master: `406cd2ad` ("rxe: Fix dma.length computation in wr_set_sge_list",
  Jared Holzman, 2026-05-25)
  https://github.com/linux-rdma/rdma-core/commit/406cd2ad
- backported to `stable-v61` as `3bb6a9b0`
  https://github.com/linux-rdma/rdma-core/commit/3bb6a9b0
  (also `stable-v62`: `262570e4`, `stable-v63`: `51fd1fde`)

No released tarball contains the fix yet (v61.0–v63.0 all predate it), so all
current Fedora rdma-core builds are affected.

## Requested action

Apply the `stable-v61` backport `3bb6a9b0` as a patch to Fedora 44's
rdma-core 61.0 (it's a two-line change), or rebase to v61.1 once it is
released.

Reproducible: Always

Comment 2 Fedora Update System 2026-09-08 15:32:21 UTC
FEDORA-2026-7995e71bdd (rdma-core-61.1^20260812git975bdaf-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7995e71bdd

Comment 3 Fedora Update System 2026-09-09 05:05:29 UTC
FEDORA-2026-7995e71bdd has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-7995e71bdd`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-7995e71bdd

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 4 Fedora Update System 2026-09-11 01:01:24 UTC
FEDORA-2026-7995e71bdd (rdma-core-61.1^20260812git975bdaf-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.