From: sashiko-bot@kernel.org
To: "Tariq Toukan" <tariqt@nvidia.com>
Cc: linux-rdma@vger.kernel.org
Subject: Re: [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct
Date: Fri, 18 Sep 2026 11:16:31 +0000 [thread overview]
Message-ID: <20260918111632.4415C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917111422.4054862-8-tariqt@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] core: missing smp_store_release() in lockless pointer publication
--
commit 70f41e46e61426ca24948348bb11ea96b2dc863f
Author: Dragos Tatulea <dtatulea@nvidia.com>
RDMA/mlx5: Extract IB specific lock out of data direct
The data_direct_lock from struct mlx5_ib_dev is an IB specific lock.
It protects from unbind while mlx5_data_direct_dev is being accessed.
So move data_direct_lock out of the generic bind/unbind functions
and into the IB specific notifier callback.
> diff --git a/drivers/infiniband/hw/mlx5/data_direct.c b/drivers/infiniband/hw/mlx5/data_direct.c
> index f871e3ce9f73d..16afacdd36018 100644
> --- a/drivers/infiniband/hw/mlx5/data_direct.c
> +++ b/drivers/infiniband/hw/mlx5/data_direct.c
> @@ -197,9 +197,7 @@ mlx5_data_direct_get_reg(struct mlx5_ib_dev *ibdev)
> static void mlx5_data_direct_bind(struct mlx5_ib_dev *ibdev,
> struct mlx5_data_direct_dev *dev)
> {
> - mutex_lock(&ibdev->data_direct_lock);
> - ibdev->data_direct_dev = dev;
> - mutex_unlock(&ibdev->data_direct_lock);
> + WRITE_ONCE(ibdev->data_direct_dev, dev);
[Severity: High]
Is a release barrier needed here?
By removing the shared lock, this becomes a lockless publication.
mutex_lock() only provides ACQUIRE semantics, so the writer lacks a RELEASE
barrier like smp_store_release().
Could weakly-ordered CPUs reorder the initialization of dev to become
visible after the pointer publication? This might allow a concurrent
lockless reader to observe the newly assigned pointer but read uninitialized
structure fields (e.g., dev->pdev being NULL), leading to a kernel panic
when dereferenced.
[ ... ]
> diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
> index e6b74955d95dc..1fc61a680f8af 100644
> --- a/drivers/infiniband/hw/mlx5/mr.c
> +++ b/drivers/infiniband/hw/mlx5/mr.c
> @@ -997,7 +997,7 @@ reg_user_mr_dmabuf_by_data_direct(struct ib_pd *pd, u64 offset,
> return ERR_PTR(-EOPNOTSUPP);
>
> mutex_lock(&dev->data_direct_lock);
> - data_direct_dev = dev->data_direct_dev;
> + data_direct_dev = READ_ONCE(dev->data_direct_dev);
[Severity: High]
Is an acquire barrier like smp_load_acquire() needed here instead of
READ_ONCE()?
Since the reader in reg_user_mr_dmabuf_by_data_direct() takes a different
lock (dev->data_direct_lock) than the writer (which takes
mlx5_data_direct_mutex), it loads the pointer locklessly with respect to the
writer.
Could an unprivileged userspace issuing an RDMA memory registration
concurrently with a data direct device hotplug or bind observe uninitialized
memory fields because of this missing barrier?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917111422.4054862-1-tariqt@nvidia.com?part=7
next prev parent reply other threads:[~2026-09-18 11:16 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 11:14 [PATCH mlx5-next 00/10] mlx5: Move data direct infrastructure to mlx5_core Tariq Toukan
2026-09-17 11:14 ` [PATCH mlx5-next 01/10] RDMA/mlx5: Notify data direct users via a notifier chain on unbind Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 02/10] RDMA/mlx5: Add mlx5_data_direct_supported() helper Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 03/10] RDMA/mlx5: Make the data direct VUID query self-contained Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 04/10] RDMA/mlx5: Give the data direct PCI driver a proper name Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 05/10] RDMA/mlx5: Move and rename data direct resource functions Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 06/10] RDMA/mlx5: Add new registration stage for data direct users Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct Tariq Toukan
2026-09-18 11:16 ` sashiko-bot [this message]
2026-09-28 11:39 ` Leon Romanovsky
2026-09-17 11:14 ` [PATCH mlx5-next 08/10] RDMA/mlx5: Consolidate data direct state into one object Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 09/10] RDMA/mlx5: Pull data_direct resource creation in init phase Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 10/10] mlx5: Move data direct implementation to mlx5_core Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-28 11:34 ` Leon Romanovsky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918111632.4415C1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox