From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pdx-out-002.esa.us-west-2.outbound.mail-perimeter.amazon.com (pdx-out-002.esa.us-west-2.outbound.mail-perimeter.amazon.com [44.246.1.125]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A9A7440E8D3 for ; Wed, 1 Jul 2026 10:34:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=44.246.1.125 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782902103; cv=none; b=MQQ0eSwoXzD6u43vBAxL7Rpfz2aPhUyZicbM80fIUMGYQfpJUxdU16wo/bILqR9Qz7eLPkdocFE3Bz4gix1VZl84PCRa2QG364G1/YFAo2cBloRN0SNYXGGP2gO75d4/RPt61RVmINha4p7ThXiBrPMp4Ql/ox4UhudDriBeyNc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782902103; c=relaxed/simple; bh=tZa6YQLUwVeKwWAI/ZeuMyQfheGMGmUBEbdTHL6iE4g=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=hh1xfvd3YGBNSbvCzOBRPqkvHCvsHtpQCay+tuEZqm1A/w1zVr+zWGbyBKCJqn/5mBP1VoZr31MMPgu3SO65JfOPc9oQJSJF4U2/FdTXgWOb1zxmqhzDffXOrUFrqQ2R4FNBnNwxPWwxXkLkq0Mn1+uGmAPSD7MixvOl97m1pXc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amazon.com; spf=pass smtp.mailfrom=amazon.com; dkim=pass (2048-bit key) header.d=amazon.com header.i=@amazon.com header.b=n+otddaA; arc=none smtp.client-ip=44.246.1.125 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amazon.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=amazon.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=amazon.com header.i=@amazon.com header.b="n+otddaA" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazoncorp2; t=1782902098; x=1814438098; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Ps7AvSN4kZOrHTRYsD2yP1/NiSkDU/bL77yp118ks+Y=; b=n+otddaAv/PrBWRI8G0U6v5Qcyfx43Ca7a31w+0Gb085wcgPD5TrdivS w3YApY3rPVzmC2+DwWscOo0Ngi1OMaoLVrgpEW6J6n5oSi28b80joqROp nVVcz7nzSaT048H59Gw/Vm9whteg9/nfVIOjbYnlVgrOa6GxD8bVg2qgF O3et5BlSmfHqRv5ZN+o4CW0TqJK6vnhKApnaEuhnUN8Ncj/SqMLOnxXWq J8zn/AtRHNVO0IFM1QlbN8+g8c7mAYjK5HyHy0jvLWM310Uju8sBSmT7+ MfVNngpLJcozHzbpCL+mVy8h/AcjcIf9QP8p3LepYJLUAcrnoWWkZ5DMZ Q==; X-CSE-ConnectionGUID: sqGBLIv0SK2DRrxEGr0N/A== X-CSE-MsgGUID: kToIvQ7QSv+rQBMXWzp6XQ== X-IronPort-AV: E=Sophos;i="6.25,141,1779148800"; d="scan'208";a="22851256" Received: from ip-10-5-6-203.us-west-2.compute.internal (HELO smtpout.naws.us-west-2.prod.farcaster.email.amazon.dev) ([10.5.6.203]) by internal-pdx-out-002.esa.us-west-2.outbound.mail-perimeter.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 01 Jul 2026 10:34:54 +0000 Received: from EX19MTAUWA002.ant.amazon.com [205.251.233.234:20132] by smtpin.naws.us-west-2.prod.farcaster.email.amazon.dev [10.0.31.226:2525] with esmtp (Farcaster) id f347b116-d733-4f2a-a614-175e4b0d2698; Wed, 1 Jul 2026 10:34:54 +0000 (UTC) X-Farcaster-Flow-ID: f347b116-d733-4f2a-a614-175e4b0d2698 Received: from EX19D001UWA001.ant.amazon.com (10.13.138.214) by EX19MTAUWA002.ant.amazon.com (10.250.64.202) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.43; Wed, 1 Jul 2026 10:34:54 +0000 Received: from dev-dsk-mrgolin-1c-b2091117.eu-west-1.amazon.com (10.253.103.172) by EX19D001UWA001.ant.amazon.com (10.13.138.214) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.2562.43; Wed, 1 Jul 2026 10:34:53 +0000 From: Michael Margolin To: , , CC: , , , "Yonatan Nachum" Subject: [PATCH for-next v7 2/5] RDMA/core: Prevent destroying in-use completion counters Date: Wed, 1 Jul 2026 10:34:45 +0000 Message-ID: <20260701103448.17895-3-mrgolin@amazon.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260701103448.17895-1-mrgolin@amazon.com> References: <20260701103448.17895-1-mrgolin@amazon.com> Precedence: bulk X-Mailing-List: linux-rdma@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: EX19D032UWA002.ant.amazon.com (10.13.139.81) To EX19D001UWA001.ant.amazon.com (10.13.138.214) Reject comp_cntr destroy while it is attached to any QP. Track attachments using an xarray in ib_qp keyed by the attach op_mask. Use op bitmask to reject overlapping attaches early. Reviewed-by: Yonatan Nachum Signed-off-by: Michael Margolin --- .../core/uverbs_std_types_comp_cntr.c | 3 +++ drivers/infiniband/core/uverbs_std_types_qp.c | 18 +++++++++++++++++- drivers/infiniband/core/verbs.c | 8 ++++++++ include/rdma/ib_verbs.h | 3 +++ 4 files changed, 31 insertions(+), 1 deletion(-) diff --git a/drivers/infiniband/core/uverbs_std_types_comp_cntr.c b/drivers/infiniband/core/uverbs_std_types_comp_cntr.c index 91ad54b270cf..967f05f76bbe 100644 --- a/drivers/infiniband/core/uverbs_std_types_comp_cntr.c +++ b/drivers/infiniband/core/uverbs_std_types_comp_cntr.c @@ -13,6 +13,9 @@ static int uverbs_free_comp_cntr(struct ib_uobject *uobject, enum rdma_remove_re struct ib_comp_cntr *cc = uobject->object; int ret; + if (atomic_read(&cc->usecnt)) + return -EBUSY; + ret = cc->device->ops.destroy_comp_cntr(cc); if (ret) return ret; diff --git a/drivers/infiniband/core/uverbs_std_types_qp.c b/drivers/infiniband/core/uverbs_std_types_qp.c index 6ef5ea2bd7a7..f6e9c33f23e3 100644 --- a/drivers/infiniband/core/uverbs_std_types_qp.c +++ b/drivers/infiniband/core/uverbs_std_types_qp.c @@ -400,7 +400,23 @@ static int UVERBS_HANDLER(UVERBS_METHOD_QP_ATTACH_COMP_CNTR)( if (!attr.op_mask) return -EINVAL; - return qp->device->ops.qp_attach_comp_cntr(qp, cc, &attr); + if (attr.op_mask & qp->comp_cntr_op_mask) + return -EBUSY; + + ret = xa_err(xa_store(&qp->comp_cntrs, attr.op_mask, cc, GFP_KERNEL)); + if (ret) + return ret; + + ret = qp->device->ops.qp_attach_comp_cntr(qp, cc, &attr); + if (ret) { + xa_erase(&qp->comp_cntrs, attr.op_mask); + return ret; + } + + atomic_inc(&cc->usecnt); + qp->comp_cntr_op_mask |= attr.op_mask; + + return 0; } DECLARE_UVERBS_NAMED_METHOD( diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c index 3b613b57e269..e30e250640c8 100644 --- a/drivers/infiniband/core/verbs.c +++ b/drivers/infiniband/core/verbs.c @@ -1293,6 +1293,7 @@ static struct ib_qp *create_qp(struct ib_device *dev, struct ib_pd *pd, qp->qp_context = attr->qp_context; spin_lock_init(&qp->mr_lock); + xa_init(&qp->comp_cntrs); INIT_LIST_HEAD(&qp->rdma_mrs); INIT_LIST_HEAD(&qp->sig_mrs); init_completion(&qp->srq_completion); @@ -1327,6 +1328,7 @@ static struct ib_qp *create_qp(struct ib_device *dev, struct ib_pd *pd, qp, uattrs ? uverbs_get_cleared_udata(uattrs) : NULL); err_create: rdma_restrack_put(&qp->res); + xa_destroy(&qp->comp_cntrs); kfree(qp); return ERR_PTR(ret); @@ -2144,6 +2146,8 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata) const struct ib_gid_attr *alt_path_sgid_attr = qp->alt_path_sgid_attr; const struct ib_gid_attr *av_sgid_attr = qp->av_sgid_attr; struct ib_qp_security *sec; + struct ib_comp_cntr *cc; + unsigned long index; int ret; WARN_ON_ONCE(qp->mrs_used > 0); @@ -2174,6 +2178,10 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata) if (av_sgid_attr) rdma_put_gid_attr(av_sgid_attr); + xa_for_each(&qp->comp_cntrs, index, cc) + atomic_dec(&cc->usecnt); + xa_destroy(&qp->comp_cntrs); + ib_qp_usecnt_dec(qp); if (sec) ib_destroy_qp_security_end(sec); diff --git a/include/rdma/ib_verbs.h b/include/rdma/ib_verbs.h index 8ad9584ba0cc..723bf368c41f 100644 --- a/include/rdma/ib_verbs.h +++ b/include/rdma/ib_verbs.h @@ -1752,6 +1752,7 @@ struct ib_comp_cntr { struct ib_uobject *uobject; u64 comp_count_max_value; u64 err_count_max_value; + atomic_t usecnt; }; enum ib_comp_cntr_entry { @@ -1947,6 +1948,8 @@ struct ib_qp { struct completion srq_completion; struct ib_xrcd *xrcd; /* XRC TGT QPs only */ struct list_head xrcd_list; + struct xarray comp_cntrs; /* op_mask -> comp_cntr */ + u32 comp_cntr_op_mask; /* count times opened, mcast attaches, flow attaches */ atomic_t usecnt; -- 2.47.3