All of lore.kernel.org
 help / color / mirror / Atom feed
From: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
To: Simon Horman <horms@kernel.org>
Cc: <anthony.l.nguyen@intel.com>, <davem@davemloft.net>,
	<kuba@kernel.org>, <pabeni@redhat.com>, <edumazet@google.com>,
	<andrew+netdev@lunn.ch>, <netdev@vger.kernel.org>,
	<larysa.zaremba@intel.com>, <przemyslaw.kitszel@intel.com>,
	<aleksander.lobakin@intel.com>, <sridhar.samudrala@intel.com>,
	<michal.swiatkowski@linux.intel.com>, <emil.s.tantilov@intel.com>,
	<madhu.chittim@intel.com>, <joshua.a.hay@intel.com>,
	<jacob.e.keller@intel.com>, <jayaprakash.shanmugam@intel.com>,
	<jiri@resnulli.us>, <corbet@lwn.net>, <richardcochran@gmail.com>,
	<skhan@linuxfoundation.org>, <linux-doc@vger.kernel.org>,
	<Bharath.r@intel.com>
Subject: Re: [PATCH net-next v5 14/15] ixd: add the core initialization
Date: Thu, 23 Jul 2026 12:28:00 +0200	[thread overview]
Message-ID: <amHssLjVOoOz7FbB@boxer> (raw)
In-Reply-To: <20260722161836.544694-1-horms@kernel.org>

On Wed, Jul 22, 2026 at 05:18:36PM +0100, Simon Horman wrote:

Simon,

Larysa already responded to Sashiko comments. Did you miss this?
Do you have a bot configured for that AI output forwarding?

> This is an AI-generated review of your patch. The human sending this
> email has considered the AI review valid, or at least plausible.
> https://sashiko.dev/#/patchset/20260715180042.1972010-2-anthony.l.nguyen@intel.com?part=14
> ---
> --- Patch [14]: [PATCH net-next v5 14/15] ixd: add the core initialization ---
> commit 43763d63c75ee5bcdd9189c20cf8b272997bdfec
> Author: Larysa Zaremba <larysa.zaremba@intel.com>
> 
> ixd: add the core initialization
> 
> This patch initializes the core when the mailbox is set up. The driver
> confirms the virtchnl version, requests necessary capabilities, and sets up
> the message handling framework.
> 
> > diff --git a/drivers/net/ethernet/intel/ixd/ixd_ctlq.c b/drivers/net/ethernet/intel/ixd/ixd_ctlq.c
> > index 0000000000000..6d658be0695d4
> > --- /dev/null
> > +++ b/drivers/net/ethernet/intel/ixd/ixd_ctlq.c
> 
> [ ... ]
> 
> > @@ -0,0 +1,146 @@
> 
> [ ... ]
> 
> > +void ixd_ctlq_rx_task(struct work_struct *work)
> > +{
> > +	struct ixd_adapter *adapter;
> > +
> > +	adapter = container_of(work, struct ixd_adapter, mbx_task.work);
> > +
> > +	queue_delayed_work(system_unbound_wq, &adapter->mbx_task,
> > +			   msecs_to_jiffies(300));
> > +
> > +	ixd_ctlq_recv_mb_msg(adapter);
> > +}
> 
> [Severity: High]
> Does queueing the delayed work before executing the main logic create a race
> condition? If cancel_delayed_work_sync() is called (for example, during
> teardown in ixd_deinit_dflt_mbx()), try_to_grab_pending() could successfully
> delete the newly queued timer and return immediately, assuming the work is
> fully cancelled.
> 
> This would bypass flush_work() and allow the teardown path to free
> adapter->xnm and set adapter->arq to NULL while ixd_ctlq_recv_mb_msg() is
> still running, potentially causing a use-after-free or NULL pointer
> dereference. Should the re-arming be moved to the end of the task?
> 
> > diff --git a/drivers/net/ethernet/intel/ixd/ixd_lib.c b/drivers/net/ethernet/intel/ixd/ixd_lib.c
> > index afc413d3650fb..ce870aba143d4 100644
> > --- a/drivers/net/ethernet/intel/ixd/ixd_lib.c
> > +++ b/drivers/net/ethernet/intel/ixd/ixd_lib.c
> 
> [ ... ]
> 
> > @@ -136,8 +145,27 @@ void ixd_init_task(struct work_struct *work)
> 
> [ ... ]
> 
> > +	libie_ctlq_xn_shutdown(adapter->xnm);
> > +	ixd_trigger_reset(adapter);
> > +	ixd_deinit_dflt_mbx(adapter);
> 
> [Severity: High]
> Is it safe to trigger a hardware reset before cancelling the mailbox polling
> task? ixd_deinit_dflt_mbx() is responsible for cancelling the mbx_task, but
> calling ixd_trigger_reset() first means the polling task could run while the
> hardware is resetting.
> 
> During reset, MMIO reads or DMA ring memory might temporarily contain invalid
> states, and the still-running mbx_task might process corrupted descriptors.
> Should the polling task be cancelled before asserting the hardware reset here,
> as well as in ixd_remove() in ixd_main.c?

  reply	other threads:[~2026-07-23 10:29 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15 18:00 [PATCH net-next v5 00/15][pull request] Introduce iXD driver Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 01/15] virtchnl: move virtchnl and virtchnl2 headers to 'include/linux/net/intel' Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 02/15] libie: add PCI device initialization helpers to libie Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 03/15] libeth: allow to create fill queues without NAPI Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 04/15] libie: add control queue support Tony Nguyen
2026-07-20 16:17   ` Larysa Zaremba
2026-07-22 15:54   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 05/15] libie: add bookkeeping support for control queue messages Tony Nguyen
2026-07-20 16:07   ` Larysa Zaremba
2026-07-22 15:55   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 06/15] idpf: remove 'vport_params_reqd' field Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 07/15] idpf: remove unused code for getting RSS info from device Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs Tony Nguyen
2026-07-20 16:09   ` Larysa Zaremba
2026-07-22 16:13   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 09/15] idpf: refactor idpf to use libie control queues Tony Nguyen
2026-07-20 16:11   ` Larysa Zaremba
2026-07-22 16:16   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 10/15] idpf: make mbx_task queueing and cancelling more consistent Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 11/15] idpf: print a debug message and bail in case of non-event ctlq message Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 12/15] ixd: add basic driver framework for Intel(R) Control Plane Function Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 13/15] ixd: add reset checks and initialize the mailbox Tony Nguyen
2026-07-22 16:17   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 14/15] ixd: add the core initialization Tony Nguyen
2026-07-20 16:14   ` Larysa Zaremba
2026-07-22 16:18   ` Simon Horman
2026-07-23 10:28     ` Maciej Fijalkowski [this message]
2026-07-23 12:51       ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 15/15] ixd: add devlink support Tony Nguyen
2026-07-20 16:24 ` [PATCH net-next v5 00/15][pull request] Introduce iXD driver Larysa Zaremba
2026-07-23 13:15   ` Jakub Kicinski
2026-07-27  8:33     ` Larysa Zaremba
2026-07-27 14:47       ` Simon Horman
2026-07-27 15:10         ` Larysa Zaremba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amHssLjVOoOz7FbB@boxer \
    --to=maciej.fijalkowski@intel.com \
    --cc=Bharath.r@intel.com \
    --cc=aleksander.lobakin@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=corbet@lwn.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=emil.s.tantilov@intel.com \
    --cc=horms@kernel.org \
    --cc=jacob.e.keller@intel.com \
    --cc=jayaprakash.shanmugam@intel.com \
    --cc=jiri@resnulli.us \
    --cc=joshua.a.hay@intel.com \
    --cc=kuba@kernel.org \
    --cc=larysa.zaremba@intel.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=madhu.chittim@intel.com \
    --cc=michal.swiatkowski@linux.intel.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=richardcochran@gmail.com \
    --cc=skhan@linuxfoundation.org \
    --cc=sridhar.samudrala@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.