Linux-HyperV List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Wei Hu" <weh@linux.microsoft.com>
Cc: linux-hyperv@vger.kernel.org, linux-rdma@vger.kernel.org
Subject: Re: [PATCH net-next v6 1/4] net: mana: prepare HWC ownership for safe reinitialization
Date: Thu, 08 Oct 2026 12:54:01 +0000	[thread overview]
Message-ID: <sashiko-outbox-164177@kernel.org> (raw)
In-Reply-To: <901e5237127da4fbd8e14ff07fa32dec8a20fd84.1790670523.git.weh@linux.microsoft.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] net: mana: Use-After-Free of CQ during queue teardown due to missing RCU grace period
--

commit 50d2c3c4bc7f5e569d234a68a7842e4c466d0022
Author: Long Li <longli@microsoft.com>

net: mana: prepare HWC ownership for safe reinitialization

Dynamic HWC queue sizing tears down the bootstrap queues and establishes a
second channel before publishing it. Prepare the existing HWC ownership and
teardown paths so that sequence cannot free or reuse state still reachable
by either the PF or an EQ handler.

Link: https://lore.kernel.org/r/20260908035201.402424-2-longli@microsoft.com
Link: https://lore.kernel.org/r/20260908035201.402424-5-longli@microsoft.com
Link: https://lore.kernel.org/r/178910960115.219967.13830871915506436112@kernel.org

> diff --git a/drivers/net/ethernet/microsoft/mana/gdma_main.c b/drivers/net/ethernet/microsoft/mana/gdma_main.c
> index 8e9bfc1d6a2ae..f63e236d4d190 100644
> --- a/drivers/net/ethernet/microsoft/mana/gdma_main.c
> +++ b/drivers/net/ethernet/microsoft/mana/gdma_main.c
[ ... ]
> @@ -922,11 +923,16 @@ static void mana_gd_process_eqe(struct gdma_queue *eq)
>  	switch (type) {
>  	case GDMA_EQE_COMPLETION:
>  		cq_id = eqe->details[0] & 0xFFFFFF;
> -		if (WARN_ON_ONCE(cq_id >= gc->max_num_cqs))
> +		/* The IRQ handler's RCU read-side section protects the table
> +		 * until HWC teardown has fenced its EQ and waited for readers.
> +		 */
> +		cq_table = smp_load_acquire(&gc->cq_table);
> +		if (!cq_table || cq_id >= READ_ONCE(gc->max_num_cqs))
>  			break;
>  
> -		cq = gc->cq_table[cq_id];
> -		if (WARN_ON_ONCE(!cq || cq->type != GDMA_CQ || cq->id != cq_id))
> +		cq = READ_ONCE(cq_table[cq_id]);
> +		if (!cq || WARN_ON_ONCE(cq->type != GDMA_CQ ||
> +					cq->id != cq_id))

[Severity: High]
Can this dereference of cq race with mana_gd_destroy_queue() and cause a
use-after-free?

When the network device is detached (e.g., driver unload or suspend),
mana_dealloc_queues() destroys Ethernet CQs via mana_destroy_rxqs() and
mana_destroy_txq() before destroying the Ethernet EQs via mana_destroy_eq().

Because the Ethernet EQ handler is still active, its IRQ handler
(mana_gd_process_eqe()) can run concurrently.  Inside the RCU read-side
critical section, mana_gd_process_eqe() reads the CQ pointer from cq_table.

If the pointer is read just before it is unpublished, the subsequent cq->type
dereference will access memory that is immediately freed by
mana_gd_destroy_queue():

drivers/net/ethernet/microsoft/mana/gdma_main.c:mana_gd_destroy_queue() {
    ...
    mana_gd_free_memory(gmi);
    kfree(queue);
}

The kfree(queue) here doesn't wait for an RCU grace period (via
synchronize_rcu() or kfree_rcu()), allowing the active EQ handler to access
freed memory.

>  			break;
>  
>  		if (cq->cq.callback)

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1790665894.git.weh@linux.microsoft.com?part=1

  reply	other threads:[~2026-10-08 12:54 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 12:53 [PATCH net-next v6 0/4] net: mana: concurrent HWC requests and dynamic queue depth Wei Hu
2026-10-07 12:53 ` [PATCH net-next v6 1/4] net: mana: prepare HWC ownership for safe reinitialization Wei Hu
2026-10-08 12:54   ` sashiko-bot [this message]
2026-10-09 11:20     ` Wei Hu
2026-10-07 12:53 ` [PATCH net-next v6 2/4] net: mana: give each HWC message slot its own completion state Wei Hu
2026-10-08 12:54   ` sashiko-bot
2026-10-07 12:53 ` [PATCH net-next v6 3/4] net: mana: support concurrent HWC requests Wei Hu
2026-10-08 12:54   ` sashiko-bot
2026-10-07 12:53 ` [PATCH net-next v6 4/4] net: mana: add dynamic HWC queue depth with reinit path Wei Hu
2026-10-08 12:54   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-164177@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-hyperv@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=weh@linux.microsoft.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox