From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5387ACA5FFF for ; Wed, 7 Oct 2026 07:24:59 +0000 (UTC) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 77829402D2; Wed, 7 Oct 2026 09:24:46 +0200 (CEST) Received: from inva021.nxp.com (inva021.nxp.com [92.121.34.21]) by mails.dpdk.org (Postfix) with ESMTP id 526584027B; Wed, 7 Oct 2026 09:24:43 +0200 (CEST) Received: from inva021.nxp.com (localhost [127.0.0.1]) by inva021.eu-rdc02.nxp.com (Postfix) with ESMTP id 309E720000E; Wed, 7 Oct 2026 09:24:43 +0200 (CEST) Received: from aprdc01srsp001v.ap-rdc01.nxp.com (aprdc01srsp001v.ap-rdc01.nxp.com [165.114.16.16]) by inva021.eu-rdc02.nxp.com (Postfix) with ESMTP id 05684200004; Wed, 7 Oct 2026 09:24:43 +0200 (CEST) Received: from lsv03583.swis.in-blr01.nxp.com (lsv03583.swis.in-blr01.nxp.com [92.120.146.12]) by aprdc01srsp001v.ap-rdc01.nxp.com (Postfix) with ESMTP id 17B861800240; Wed, 7 Oct 2026 15:24:42 +0800 (+08) From: Hemant Agrawal To: stephen@networkplumber.org, thomas@monjalon.net, dev@dpdk.org Cc: stable@dpdk.org Subject: [PATCH v22 01/27] net/dpaa: fix double close and null deref on remove Date: Wed, 7 Oct 2026 12:54:13 +0530 Message-Id: <20261007072439.3135351-2-hemant.agrawal@nxp.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20261007072439.3135351-1-hemant.agrawal@nxp.com> References: <20261006092703.2138929-1-hemant.agrawal@nxp.com> <20261007072439.3135351-1-hemant.agrawal@nxp.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Virus-Scanned: ClamAV using ClamSMTP X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org rte_dpaa_remove() closed the port twice: ret = dpaa_eth_dev_close(eth_dev); if (eth_dev->state != RTE_ETH_DEV_UNUSED) { dpaa_eth_dev_close(eth_dev); The first call ran unconditionally, the second ran again on a port that had just been torn down. The unconditional call also dereferenced eth_dev without checking that rte_eth_dev_allocated() found anything, so removing a device that was never probed crashed. Close the port once, only when it is still in use, and log the close result before releasing the port. The release status is returned, since the port must be released regardless of how close ended. Fixes: 78ea4b4fcb52 ("bus/dpaa: improve cleanup") Cc: stable@dpdk.org Signed-off-by: Hemant Agrawal --- drivers/net/dpaa/dpaa_ethdev.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/net/dpaa/dpaa_ethdev.c b/drivers/net/dpaa/dpaa_ethdev.c index 1aaf97f175..a5b02cc9a8 100644 --- a/drivers/net/dpaa/dpaa_ethdev.c +++ b/drivers/net/dpaa/dpaa_ethdev.c @@ -2679,11 +2679,14 @@ rte_dpaa_remove(struct rte_dpaa_device *dpaa_dev) PMD_INIT_FUNC_TRACE(); eth_dev = rte_eth_dev_allocated(dpaa_dev->device.name); - ret = dpaa_eth_dev_close(eth_dev); - if (eth_dev->state != RTE_ETH_DEV_UNUSED) { - dpaa_eth_dev_close(eth_dev); + if (eth_dev != NULL && eth_dev->state != RTE_ETH_DEV_UNUSED) { + ret = dpaa_eth_dev_close(eth_dev); + if (ret != 0) + DPAA_PMD_WARN("%s: close failed(%d), releasing port", + dpaa_dev->device.name, ret); ret = rte_eth_dev_release_port(eth_dev); } + dpaa_valid_dev--; if (!dpaa_valid_dev) rte_mempool_free(dpaa_tx_sg_pool); -- 2.25.1