[PATCH] RDMA/rtrs-clt: Reject invalid queue_depth from the peer

From: Quanye Yang via B4 Relay

Date: Wed Sep 23 2026 - 00:10:09 EST


From: Quanye Yang <quanyeyang@xxxxxxxxx>

queue_depth is taken from the server's CM private_data and later
used as a session invariant. A peer can send 0, which the client
stores and then trips WARN_ON() in create_con_cq_qp() when the
next connection is set up.

Reject a zero queue_depth on ESTABLISHED, same as a bad
magic or version, and fail the handshake with -ECONNRESET.

Fixes: 6a98d71daea1 ("RDMA/rtrs: client: main functionality")
Reported-by: Farhad Alemi <farhad.alemi@xxxxxxxxxxxx>
Link: https://lore.kernel.org/linux-rdma/CA+0ovCg_sG8gaZXXj9zmOrpxRt=8+-x9wvycVNUKwWmMbr6-Yg@xxxxxxxxxxxxxx
Signed-off-by: Quanye Yang <quanyeyang@xxxxxxxxx>
---
drivers/infiniband/ulp/rtrs/rtrs-clt.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/drivers/infiniband/ulp/rtrs/rtrs-clt.c b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
index eac38b57b00d..7fbbb9a53607 100644
--- a/drivers/infiniband/ulp/rtrs/rtrs-clt.c
+++ b/drivers/infiniband/ulp/rtrs/rtrs-clt.c
@@ -1853,6 +1853,10 @@ static int rtrs_rdma_conn_established(struct rtrs_clt_con *con,
}
if (con->c.cid == 0) {
queue_depth = le16_to_cpu(msg->queue_depth);
+ if (!queue_depth) {
+ rtrs_err(clt, "Invalid queue depth %u\n", queue_depth);
+ return -ECONNRESET;
+ }

if (clt_path->queue_depth > 0 && queue_depth != clt_path->queue_depth) {
rtrs_err(clt, "Error: queue depth changed\n");

---
base-commit: 93f51579e7df248780214094418f205253383cc5
change-id: 20260922-rtrs-fix-warning-rtrs-clt-rdma-cm-handler-2160ee358b4e

Best regards,
--
Quanye Yang <quanyeyang@xxxxxxxxx>