From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 34598531B11; Wed, 23 Sep 2026 14:49:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174944; cv=none; b=WwYfI+dGrbu8wnGHVxoB7Lev9LW9SPlBUeP5hp2+e0wGExIIA0buzixEmjmmn3F3whPMI2rISecQJMibcv5HYGtrE1bLavBc/gRVwjJ5cfEkvubfmIgroeE8JYPn4HrvUYArgMT+zuit4FM2KFoLKM5o9CQxtstW2Rdyl40D8ic= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174944; c=relaxed/simple; bh=DuwDJIlP/J59Nuqk0SzueQQp7ZfKj9Yar4RpMedlwpY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GoqvGGyzdLMSLlT3AyNU6lZoqmyAQnjoEnMtWfeJuIHtE0lXUx/OXp9dHXsCxGyc5L/UePnnVeASGD/W0D0cyVhocvybBYeAWfj2NxpywYXnogZ3CmEdZQuofrDaFxag5EUudql/wm8R5C93awqpLrQR1vSlEoFmPovae5pT/vg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=VnutnGf8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="VnutnGf8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B3EBF1F000FF; Wed, 23 Sep 2026 14:49:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790174943; bh=zMpRL/XiQdzI6C31i2PKhJrxLt8LhIdCOFeqQWON1bU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=VnutnGf8xLBbgLeGKDGU5DJ6EHSq/b2RfPElE0gldVJiVk31KQuEK0LQaHhCtKap6 INjyVuoDBx6ED5pnqPUddF+j/dPhfTluaTZQBWacSByFTqLx+JKaPIwDOFyl1uziiY foTbJfQ7Kt+KJVgoFjE0jW+p49YZ2fr/0oiPt9OA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Shuhei Takeshita , Leon Romanovsky Subject: [PATCH 6.18 272/398] IB/hfi1: Resolve the credit-return buffer through the send contexts node Date: Wed, 23 Sep 2026 16:05:46 +0200 Message-ID: <20260923140650.466776210@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Shuhei Takeshita commit 975396b9e5a4028e649f4b9a6a5ca5dfb76a824b upstream. hfi1_file_mmap()'s PIO_CRED case derives this context's credit-return page offset, and the DMA handle for it, from dd->cr_base[uctxt->numa_id]. uctxt->numa_id is the node of whichever CPU the process happened to be running on, but the entry itself lives in the credit-return allocation of the send context's own node: sc->hw_free = &sc->dd->cr_base[sc->node].va[gc].cr[index]; and user send contexts are allocated with sc_alloc(dd, SC_USER, ..., dd->node), the HFI-local node. On a multi-socket host with the process running off that node the two allocations differ, so the subtraction produces an offset into an unrelated buffer and the DMA handle belongs to the wrong allocation. Use the send context's own node for all three references. The continuation lines are reindented at the same time; they mixed spaces and tabs. Fixes: 7724105686e7 ("IB/hfi1: add driver files") Cc: stable@vger.kernel.org Signed-off-by: Shuhei Takeshita Link: https://patch.msgid.link/20260809032743.2671579-2-jyohuku.alterego@gmail.com Signed-off-by: Leon Romanovsky Signed-off-by: Greg Kroah-Hartman --- drivers/infiniband/hw/hfi1/file_ops.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) --- a/drivers/infiniband/hw/hfi1/file_ops.c +++ b/drivers/infiniband/hw/hfi1/file_ops.c @@ -382,10 +382,10 @@ static int hfi1_file_mmap(struct file *f * of enabled contexts > 64 and 128 respectively). */ cr_page_offset = ((u64)uctxt->sc->hw_free - - (u64)dd->cr_base[uctxt->numa_id].va) & - PAGE_MASK; - memvirt = dd->cr_base[uctxt->numa_id].va + cr_page_offset; - memdma = dd->cr_base[uctxt->numa_id].dma + cr_page_offset; + (u64)dd->cr_base[uctxt->sc->node].va) & + PAGE_MASK; + memvirt = dd->cr_base[uctxt->sc->node].va + cr_page_offset; + memdma = dd->cr_base[uctxt->sc->node].dma + cr_page_offset; memlen = PAGE_SIZE; flags &= ~VM_MAYWRITE; flags |= VM_DONTCOPY | VM_DONTEXPAND;