From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1C28BCA5FED for ; Tue, 6 Oct 2026 09:27:16 +0000 (UTC) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 0006E40A7F; Tue, 6 Oct 2026 11:27:09 +0200 (CEST) Received: from inva021.nxp.com (inva021.nxp.com [92.121.34.21]) by mails.dpdk.org (Postfix) with ESMTP id CF1164025F; Tue, 6 Oct 2026 11:27:07 +0200 (CEST) Received: from inva021.nxp.com (localhost [127.0.0.1]) by inva021.eu-rdc02.nxp.com (Postfix) with ESMTP id A6F06200185; Tue, 6 Oct 2026 11:27:07 +0200 (CEST) Received: from aprdc01srsp001v.ap-rdc01.nxp.com (aprdc01srsp001v.ap-rdc01.nxp.com [165.114.16.16]) by inva021.eu-rdc02.nxp.com (Postfix) with ESMTP id 707CF200236; Tue, 6 Oct 2026 11:27:07 +0200 (CEST) Received: from lsv03583.swis.in-blr01.nxp.com (lsv03583.swis.in-blr01.nxp.com [92.120.146.12]) by aprdc01srsp001v.ap-rdc01.nxp.com (Postfix) with ESMTP id E6F0E180022C; Tue, 6 Oct 2026 17:27:06 +0800 (+08) From: Hemant Agrawal To: stephen@networkplumber.org, thomas@monjalon.net, dev@dpdk.org Cc: stable@dpdk.org Subject: [PATCH v21 01/27] net/dpaa: fix double close and null deref on remove Date: Tue, 6 Oct 2026 14:56:37 +0530 Message-Id: <20261006092703.2138929-2-hemant.agrawal@nxp.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20261006092703.2138929-1-hemant.agrawal@nxp.com> References: <20261005085337.1069213-1-hemant.agrawal@nxp.com> <20261006092703.2138929-1-hemant.agrawal@nxp.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Virus-Scanned: ClamAV using ClamSMTP X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org rte_dpaa_remove() called dpaa_eth_dev_close() and then rte_eth_dev_release_port(), which calls the close op again through rte_eth_dev_destroy(). The second close ran on an already torn down port. It also dereferenced eth_dev without checking that rte_eth_dev_allocated() found anything. Close the port once, only when it is still in use, and log the close result before releasing the port. The release status is returned, since the port must be released regardless of how close ended. Fixes: 78ea4b4fcb52 ("bus/dpaa: improve cleanup") Cc: stable@dpdk.org Signed-off-by: Hemant Agrawal --- drivers/net/dpaa/dpaa_ethdev.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/net/dpaa/dpaa_ethdev.c b/drivers/net/dpaa/dpaa_ethdev.c index 1aaf97f175..a5b02cc9a8 100644 --- a/drivers/net/dpaa/dpaa_ethdev.c +++ b/drivers/net/dpaa/dpaa_ethdev.c @@ -2679,11 +2679,14 @@ rte_dpaa_remove(struct rte_dpaa_device *dpaa_dev) PMD_INIT_FUNC_TRACE(); eth_dev = rte_eth_dev_allocated(dpaa_dev->device.name); - ret = dpaa_eth_dev_close(eth_dev); - if (eth_dev->state != RTE_ETH_DEV_UNUSED) { - dpaa_eth_dev_close(eth_dev); + if (eth_dev != NULL && eth_dev->state != RTE_ETH_DEV_UNUSED) { + ret = dpaa_eth_dev_close(eth_dev); + if (ret != 0) + DPAA_PMD_WARN("%s: close failed(%d), releasing port", + dpaa_dev->device.name, ret); ret = rte_eth_dev_release_port(eth_dev); } + dpaa_valid_dev--; if (!dpaa_valid_dev) rte_mempool_free(dpaa_tx_sg_pool); -- 2.25.1