Fedora Account System
Red Hat Associate
Red Hat Customer
# Fedora 44 bug report: rdma-core / librxe **Component:** rdma-core **Version:** 61.0-2.fc44 (Fedora 44) **Severity:** high (data-path corruption / connection loss on the rxe provider) **Summary:** librxe: wr_set_sge_list() mis-computes WR length (num_sge × sg_list[0].length) — multi-SGE work requests via the ibv_qp_ex API are corrupted; fixed upstream, needs backport ## Description `providers/rxe/rxe.c:wr_set_sge_list()` sums the scatter/gather list without ever advancing the list pointer: ```c while (num_sge--) tot_length += sg_list->length; ``` so `wqe->dma.length` / `wqe->dma.resid` end up as `num_sge * sg_list[0].length` instead of the true sum. Every work request posted through the extended QP work-request API (`ibv_wr_start()` / `ibv_wr_set_sge_list()` / `ibv_wr_complete()`) with **more than one SGE** on the rxe (soft-RoCE) provider carries a corrupted total length. The per-SGE entries themselves are correct (populated by the preceding `memcpy()`), so single-SGE WRs are accidentally unaffected — which is why the bug is easy to miss. Consequences, depending on opcode: - **RDMA READ:** the inflated length goes on the wire in the RETH header; the responder rejects it against the (correctly sized) remote MR — `iova/length out of range` in kernel rxe — and returns NAK Remote Access Error. The requester's SQ completes with `IBV_WC_REM_ACCESS_ERR` (status 10) and the QP transitions to error. - **SEND / RDMA WRITE:** the kernel rxe driver requires `dma.length == sum(sge[i].length)`; `copy_data()` runs off the end of the SGE list and the WR completes with `IB_WC_LOC_PROT_ERR`. ## How reproduced A userspace NVMe-oF RDMA target on rxe, driven by the in-kernel nvme-rdma initiator running xfstests `generic/113` (aio-stress). Any fragmented buffer produced a multi-SGE RDMA READ, whose inflated wire length killed the QP within seconds (e.g. a 96 KiB transfer with `num_sge = 3`, `sg_list[0].length = 64 KiB` went out as a 192 KiB read against a 96 KiB MR). The NVMe host controller then entered error recovery. A one-line fix to the summing loop makes the same workload pass. How reproducible: always, within seconds, with any multi-SGE extended-API WR on rxe. ## Introduced by Upstream `1a894ca10105` ("Providers/rxe: Implement ibv_create_qp_ex verb") — i.e. present since the extended-WR API was added to librxe. ## Fixed upstream - master: `406cd2ad` ("rxe: Fix dma.length computation in wr_set_sge_list", Jared Holzman, 2026-05-25) https://github.com/linux-rdma/rdma-core/commit/406cd2ad - backported to `stable-v61` as `3bb6a9b0` https://github.com/linux-rdma/rdma-core/commit/3bb6a9b0 (also `stable-v62`: `262570e4`, `stable-v63`: `51fd1fde`) No released tarball contains the fix yet (v61.0–v63.0 all predate it), so all current Fedora rdma-core builds are affected. ## Requested action Apply the `stable-v61` backport `3bb6a9b0` as a patch to Fedora 44's rdma-core 61.0 (it's a two-line change), or rebase to v61.1 once it is released. Reproducible: Always
https://src.fedoraproject.org/rpms/rdma-core/pull-request/40
FEDORA-2026-7995e71bdd (rdma-core-61.1^20260812git975bdaf-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-7995e71bdd
FEDORA-2026-7995e71bdd has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-7995e71bdd` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-7995e71bdd See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-7995e71bdd (rdma-core-61.1^20260812git975bdaf-1.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.