dev.dpdk.org archive mirror
 help / color / mirror / Atom feed
From: Rahul Bhansali <rbhansali@marvell.com>
To: <dev@dpdk.org>, Nithin Dabilpuram <ndabilpuram@marvell.com>,
	Kiran Kumar K <kirankumark@marvell.com>,
	Sunil Kumar Kori <skori@marvell.com>,
	Satha Rao <skoteshwar@marvell.com>,
	Harman Kalra <hkalra@marvell.com>,
	"Rakesh Kudurumalla" <rkudurumalla@marvell.com>
Cc: <jerinj@marvell.com>, Aarnav JP <ajp@marvell.com>, <stable@dpdk.org>
Subject: [PATCH 06/14] common/cnxk: fix null deref and irq ack in CPT CQ handler
Date: Thu, 17 Sep 2026 12:40:08 +0530	[thread overview]
Message-ID: <20260917071016.2366467-6-rbhansali@marvell.com> (raw)
In-Reply-To: <20260917071016.2366467-1-rbhansali@marvell.com>

From: Aarnav JP <ajp@marvell.com>

The CPT CQ interrupt handler (nix_inl_cpt_cq_cb) unconditionally
dereferences lf->dev->roc_nix to obtain roc_nix, nix, and port_id.
For inbound, the CPT LF belongs to the inline device which is not
an ethdev, so roc_nix is NULL and the dereference crashes.

Additionally, error paths returned without writing CPT_LF_DONE_ACK,
leaving CQ entries unacknowledged causing the completion queue to
fill up.

Fix by deferring roc_nix/nix/port_id derivation into the outbound
branch where roc_nix is valid, setting port_id to UINT32_MAX for
inbound, and routing all error paths through a common cq_ack label
that drains entries and writes CPT_LF_DONE_ACK.

Fixes: 3fdf3e53f3c4 ("common/cnxk: enable CPT CQ for inline IPsec inbound")
Cc: stable@dpdk.org

Signed-off-by: Aarnav JP <ajp@marvell.com>
---
 drivers/common/cnxk/roc_nix_inl_dev_irq.c | 48 ++++++++++++++++-------
 1 file changed, 33 insertions(+), 15 deletions(-)

diff --git a/drivers/common/cnxk/roc_nix_inl_dev_irq.c b/drivers/common/cnxk/roc_nix_inl_dev_irq.c
index afbf966f78..f99c32f30b 100644
--- a/drivers/common/cnxk/roc_nix_inl_dev_irq.c
+++ b/drivers/common/cnxk/roc_nix_inl_dev_irq.c
@@ -48,41 +48,57 @@ nix_inl_sso_work_cb(struct nix_inl_dev *inl_dev)
 static void
 nix_inl_cpt_cq_cb(struct roc_cpt_lf *lf)
 {
-	struct roc_nix *roc_nix = (struct roc_nix *)lf->dev->roc_nix;
-	struct nix *nix = roc_nix_to_nix_priv(roc_nix);
 	struct idev_cfg *idev = idev_get_cfg();
-	uint32_t port_id = roc_nix->port_id;
 	struct nix_inl_dev *inl_dev = NULL;
 	enum nix_inl_event_type cq_type;
 	union cpt_lf_cq_base cq_base;
 	union cpt_lf_cq_ptr cq_ptr;
+	struct roc_nix *roc_nix;
 	struct cpt_cq_s *cq_s;
 	uint8_t fmt_msk = 0x3;
 	uint32_t count, head;
+	uint32_t port_id = UINT32_MAX;
 	uint32_t nq_ptr;
+	struct nix *nix;
 	uint64_t i;
 	void *sa;
 
+	/* Read CQ state early so we can always acknowledge the interrupt */
+	head = lf->cq_head;
+	cq_base.u = plt_read64(lf->rbase + CPT_LF_CQ_BASE);
+	cq_ptr.u = plt_read64(lf->rbase + CPT_LF_CQ_PTR);
+	count = cq_ptr.s.count;
+	nq_ptr = cq_ptr.s.nq_ptr;
+
 	if (idev)
 		inl_dev = idev->nix_inl_dev;
 
 	if (!inl_dev) {
 		plt_nix_dbg("Inline Device could not be detected");
-		return;
+		goto cq_ack;
 	}
 
-	head = lf->cq_head;
-	cq_base.u = plt_read64(lf->rbase + CPT_LF_CQ_BASE);
-	cq_ptr.u = plt_read64(lf->rbase + CPT_LF_CQ_PTR);
-	count = cq_ptr.s.count;
-	nq_ptr = cq_ptr.s.nq_ptr;
-
-	if (lf->dev == &inl_dev->dev)
+	if (lf->dev == &inl_dev->dev) {
+		/* Inbound: CPT LF belongs to inline device.
+		 * roc_nix is NULL here as inline dev is not an ethdev.
+		 * port_id will be derived from SA in the PMD work callback.
+		 */
 		cq_type = NIX_INL_INB_CPT_CQ;
-	else if (lf->dev == &nix->dev)
+	} else {
+		/* Outbound: CPT LF belongs to an ethdev */
+		roc_nix = (struct roc_nix *)lf->dev->roc_nix;
+		if (!roc_nix) {
+			plt_nix_dbg("CPT LF dev has no roc_nix");
+			goto cq_ack;
+		}
+		nix = roc_nix_to_nix_priv(roc_nix);
+		if (lf->dev != &nix->dev) {
+			plt_nix_dbg("CPT LF dev mismatch with nix dev");
+			goto cq_ack;
+		}
 		cq_type = NIX_INL_OUTB_CPT_CQ;
-	else
-		return;
+		port_id = roc_nix->port_id;
+	}
 
 	for (i = 0; i < count; i++) {
 		cq_s = (struct cpt_cq_s *)(uintptr_t)(((cq_base.s.addr << 7)) + (head << 5));
@@ -106,11 +122,13 @@ nix_inl_cpt_cq_cb(struct roc_cpt_lf *lf)
 		head = (head + 1) % lf->cq_size;
 	}
 
+cq_ack:
+	/* Drain unprocessed entries and acknowledge the interrupt */
+	head = (lf->cq_head + count) % lf->cq_size;
 	lf->cq_head = head;
 	if (unlikely(nq_ptr != head))
 		plt_err("CPT LF[%d] CQ head %d != NQ ptr %d", lf->lf_id, head, nq_ptr);
 
-	/* Acknowledge the number of completed requests */
 	plt_write64(count, lf->rbase + CPT_LF_DONE_ACK);
 }
 
-- 
2.34.1


  parent reply	other threads:[~2026-09-17  7:14 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  7:10 [PATCH 01/14] net/cnxk: fix packet length handling Rahul Bhansali
2026-09-17  7:10 ` [PATCH 02/14] common/cnxk: disable CPT drop error in CQ Rahul Bhansali
2026-09-17 16:14   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 03/14] common/cnxk: fix NIX QINT count reset Rahul Bhansali
2026-09-17 16:14   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 04/14] common/cnxk: update channel mask for cn20k Rahul Bhansali
2026-09-17  7:10 ` [PATCH 05/14] common/cnxk: update macro " Rahul Bhansali
2026-09-17  7:10 ` Rahul Bhansali [this message]
2026-09-17 16:15   ` [PATCH 06/14] common/cnxk: fix null deref and irq ack in CPT CQ handler Stephen Hemminger
2026-09-17  7:10 ` [PATCH 07/14] common/cnxk: derive mbuf from CPT CQ in inline IRQ path Rahul Bhansali
2026-09-17 16:15   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 08/14] net/cnxk: resolve mbuf from CPT CQ format in SSO work cb Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 09/14] common/cnxk: update bpid config for cn20k Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 10/14] net/cnxk: add MSNS inb SA and CN20K CPT result struct Rahul Bhansali
2026-09-17 16:16   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 11/14] common/cnxk: fix CPT CQ base address calculation Rahul Bhansali
2026-09-17  7:10 ` [PATCH 12/14] common/cnxk: update mode param for link speed Rahul Bhansali
2026-09-17 16:17   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 13/14] common/cnxk: support for cn20k legacy msns mode Rahul Bhansali
2026-09-17 16:18   ` Stephen Hemminger
2026-09-17  7:10 ` [PATCH 14/14] net/cnxk: fix custom inbound SA condition check Rahul Bhansali
2026-09-17 16:12 ` [PATCH 01/14] net/cnxk: fix packet length handling Stephen Hemminger
2026-09-17 16:29 ` Stephen Hemminger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917071016.2366467-6-rbhansali@marvell.com \
    --to=rbhansali@marvell.com \
    --cc=ajp@marvell.com \
    --cc=dev@dpdk.org \
    --cc=hkalra@marvell.com \
    --cc=jerinj@marvell.com \
    --cc=kirankumark@marvell.com \
    --cc=ndabilpuram@marvell.com \
    --cc=rkudurumalla@marvell.com \
    --cc=skori@marvell.com \
    --cc=skoteshwar@marvell.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).