All of lore.kernel.org
 help / color / mirror / Atom feed
From: bugzilla@dpdk.org
To: dev@dpdk.org
Subject: [DPDK/ethdev Bug 2032] bus/dpaa: crash when removing ethdev callbacks from a non-EAL thread
Date: Wed, 09 Sep 2026 02:55:38 +0000	[thread overview]
Message-ID: <bug-2032-3@https.bugs.dpdk.org/> (raw)

https://bugs.dpdk.org/show_bug.cgi?id=2032

            Bug ID: 2032
           Summary: bus/dpaa: crash when removing ethdev callbacks from a
                    non-EAL thread
           Product: DPDK
           Version: 24.11
          Hardware: ARM
                OS: Linux
            Status: UNCONFIRMED
          Severity: normal
          Priority: Normal
         Component: ethdev
          Assignee: dev@dpdk.org
          Reporter: gu.jiawei@e-quantum.com.cn
  Target Milestone: ---

DPDK version: 24.11.7

Environment:
- NXP LS1043A (aarch64)
- DPAA1 Ethernet device
- Two PMD threads
- Linux ANP 6.1.55-ASG1200-H #28 SMP PREEMPT Sun Sep 29 10:01:56 CST 2024
aarch64 GNU/Linux
- Packet capture implemented with ethdev RX/TX callbacks
- Callback registration and removal are performed by a non-PMD, non-EAL thread

Description:
The application crashes when a non-EAL thread removes ethdev RX/TX callbacks
that were registered for packet capture.

The capture thread registers callbacks with:
  rte_eth_add_rx_callback(...);
  rte_eth_add_tx_callback(...);

After the capture interval expires, the same non-EAL thread removes them with:
  rte_eth_remove_rx_callback(...);
  rte_eth_remove_tx_callback(...);

The crash occurs in dpaa_portal_finish() at:
  dpaa_portals[rte_lcore_id()] = NULL;

Because the callback removal is executed from a non-EAL thread, rte_lcore_id()
returns LCORE_ID_ANY. This value is used as an index into dpaa_portals[],
causing an out-of-bounds access and a segmentation fault.

Steps to reproduce:
1. Start an application using a DPAA1 Ethernet device on LS1043A with two PMD
threads.
2. Start packet forwarding or packet processing.
3. From a non-EAL thread, register RX and TX callbacks for packet capture using
rte_eth_add_rx_callback() and rte_eth_add_tx_callback().
4. After a capture interval, remove the callbacks from the same thread using
rte_eth_remove_rx_callback() and rte_eth_remove_tx_callback().
5. Observe the application crash.

Actual result:
The application terminates with SIGSEGV in dpaa_portal_finish() because
LCORE_ID_ANY is used as an array index.

Expected result:
Removing ethdev callbacks from a non-EAL thread must not cause an out-of-bounds
array access or application crash.

Backtrace:
Program terminated with signal SIGSEGV, Segmentation fault.
#0  dpaa_portal_finish (arg=0x2184242e80)
    at ../drivers/bus/dpaa/dpaa_bus.c:453
#1  0x0000ffff9283ed84 in ?? () from /lib64/libc.so.6
#2  0x0000ffff92841740 in ?? () from /lib64/libc.so.6
#3  0x0000ffff928976dc in ?? () from /lib64/libc.so.6

-- 
You are receiving this mail because:
You are the assignee for the bug.

                 reply	other threads:[~2026-09-09  2:55 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bug-2032-3@https.bugs.dpdk.org/ \
    --to=bugzilla@dpdk.org \
    --cc=dev@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.