From: Michael Margolin <mrgolin@amazon.com>
To: <jgg@nvidia.com>, <leon@kernel.org>, <linux-rdma@vger.kernel.org>
Cc: <sleybo@amazon.com>, <matua@amazon.com>, <gal.pressman@linux.dev>,
"Yonatan Nachum" <ynachum@amazon.com>
Subject: [PATCH for-next v9 2/6] RDMA/core: Prevent destroying in-use completion counters
Date: Mon, 20 Jul 2026 07:58:02 +0000 [thread overview]
Message-ID: <20260720075806.12334-1-mrgolin@amazon.com> (raw)
Reject comp_cntr destroy while it is attached to any QP. Track
attachments using an xarray in ib_qp keyed by the attach op_mask.
Use op bitmask to reject overlapping attaches early.
Reviewed-by: Yonatan Nachum <ynachum@amazon.com>
Signed-off-by: Michael Margolin <mrgolin@amazon.com>
---
.../core/uverbs_std_types_comp_cntr.c | 3 +++
drivers/infiniband/core/uverbs_std_types_qp.c | 18 +++++++++++++++++-
drivers/infiniband/core/verbs.c | 8 ++++++++
include/rdma/ib_verbs.h | 3 +++
4 files changed, 31 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/uverbs_std_types_comp_cntr.c b/drivers/infiniband/core/uverbs_std_types_comp_cntr.c
index 7db3feace2a9..e12aececbb09 100644
--- a/drivers/infiniband/core/uverbs_std_types_comp_cntr.c
+++ b/drivers/infiniband/core/uverbs_std_types_comp_cntr.c
@@ -13,6 +13,9 @@ static int uverbs_free_comp_cntr(struct ib_uobject *uobject, enum rdma_remove_re
struct ib_comp_cntr *cc = uobject->object;
int ret;
+ if (atomic_read(&cc->usecnt))
+ return -EBUSY;
+
ret = cc->device->ops.destroy_comp_cntr(cc);
if (ret)
return ret;
diff --git a/drivers/infiniband/core/uverbs_std_types_qp.c b/drivers/infiniband/core/uverbs_std_types_qp.c
index 1a32a902bdba..30fc20fb251f 100644
--- a/drivers/infiniband/core/uverbs_std_types_qp.c
+++ b/drivers/infiniband/core/uverbs_std_types_qp.c
@@ -403,7 +403,23 @@ static int UVERBS_HANDLER(UVERBS_METHOD_QP_ATTACH_COMP_CNTR)(
if (!attr.op_mask)
return -EINVAL;
- return qp->device->ops.qp_attach_comp_cntr(qp, cc, &attr);
+ if (attr.op_mask & qp->comp_cntr_op_mask)
+ return -EBUSY;
+
+ ret = xa_err(xa_store(&qp->comp_cntrs, attr.op_mask, cc, GFP_KERNEL));
+ if (ret)
+ return ret;
+
+ ret = qp->device->ops.qp_attach_comp_cntr(qp, cc, &attr);
+ if (ret) {
+ xa_erase(&qp->comp_cntrs, attr.op_mask);
+ return ret;
+ }
+
+ atomic_inc(&cc->usecnt);
+ qp->comp_cntr_op_mask |= attr.op_mask;
+
+ return 0;
}
DECLARE_UVERBS_NAMED_METHOD(
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 3b613b57e269..e30e250640c8 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -1293,6 +1293,7 @@ static struct ib_qp *create_qp(struct ib_device *dev, struct ib_pd *pd,
qp->qp_context = attr->qp_context;
spin_lock_init(&qp->mr_lock);
+ xa_init(&qp->comp_cntrs);
INIT_LIST_HEAD(&qp->rdma_mrs);
INIT_LIST_HEAD(&qp->sig_mrs);
init_completion(&qp->srq_completion);
@@ -1327,6 +1328,7 @@ static struct ib_qp *create_qp(struct ib_device *dev, struct ib_pd *pd,
qp, uattrs ? uverbs_get_cleared_udata(uattrs) : NULL);
err_create:
rdma_restrack_put(&qp->res);
+ xa_destroy(&qp->comp_cntrs);
kfree(qp);
return ERR_PTR(ret);
@@ -2144,6 +2146,8 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata)
const struct ib_gid_attr *alt_path_sgid_attr = qp->alt_path_sgid_attr;
const struct ib_gid_attr *av_sgid_attr = qp->av_sgid_attr;
struct ib_qp_security *sec;
+ struct ib_comp_cntr *cc;
+ unsigned long index;
int ret;
WARN_ON_ONCE(qp->mrs_used > 0);
@@ -2174,6 +2178,10 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata)
if (av_sgid_attr)
rdma_put_gid_attr(av_sgid_attr);
+ xa_for_each(&qp->comp_cntrs, index, cc)
+ atomic_dec(&cc->usecnt);
+ xa_destroy(&qp->comp_cntrs);
+
ib_qp_usecnt_dec(qp);
if (sec)
ib_destroy_qp_security_end(sec);
diff --git a/include/rdma/ib_verbs.h b/include/rdma/ib_verbs.h
index 9a952750f068..84a8904fbad4 100644
--- a/include/rdma/ib_verbs.h
+++ b/include/rdma/ib_verbs.h
@@ -1758,6 +1758,7 @@ enum ib_qp_attach_comp_cntr_op {
struct ib_comp_cntr {
struct ib_device *device;
struct ib_uobject *uobject;
+ atomic_t usecnt;
};
enum ib_comp_cntr_entry {
@@ -1944,6 +1945,8 @@ struct ib_qp {
struct completion srq_completion;
struct ib_xrcd *xrcd; /* XRC TGT QPs only */
struct list_head xrcd_list;
+ struct xarray comp_cntrs; /* op_mask -> comp_cntr */
+ u32 comp_cntr_op_mask;
/* count times opened, mcast attaches, flow attaches */
atomic_t usecnt;
--
2.47.3
next reply other threads:[~2026-07-20 7:58 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 7:58 Michael Margolin [this message]
2026-07-20 7:58 ` [PATCH for-next v9 3/6] RDMA/core: Expose Completion Counter capabilities to userspace Michael Margolin
2026-07-20 7:58 ` [PATCH for-next v9 4/6] RDMA/core: Add Completion Counters to resource tracking Michael Margolin
2026-07-20 7:58 ` [PATCH for-next v9 5/6] RDMA/efa: Update device interface Michael Margolin
2026-07-20 7:58 ` [PATCH for-next v9 6/6] RDMA/efa: Add Completion Counters support Michael Margolin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720075806.12334-1-mrgolin@amazon.com \
--to=mrgolin@amazon.com \
--cc=gal.pressman@linux.dev \
--cc=jgg@nvidia.com \
--cc=leon@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=matua@amazon.com \
--cc=sleybo@amazon.com \
--cc=ynachum@amazon.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.