From: Chuck Lever <cel@kernel.org>
To: NeilBrown <neil@brown.name>, Jeff Layton <jlayton@kernel.org>,
Olga Kornievskaia <okorniev@redhat.com>,
Dai Ngo <dai.ngo@oracle.com>, Tom Talpey <tom@talpey.com>
Cc: <linux-nfs@vger.kernel.org>, <linux-rdma@vger.kernel.org>
Subject: [PATCH v1 3/5] svcrdma: fix a page leak in backchannel sends
Date: Mon, 21 Sep 2026 21:51:26 -0400 [thread overview]
Message-ID: <20260922015128.240977-3-cel@kernel.org> (raw)
In-Reply-To: <20260922015128.240977-1-cel@kernel.org>
svc_rdma_bc_sendto() takes an extra reference on the page that
holds the backchannel Call message, so that the page is not
returned to the allocator while the Send that reads it is still
posted. Send completion once dropped that reference, back when the
page sat in the send context's page array. Commit 99722fe4d5a6
("svcrdma: Persistently allocate and DMA-map Send buffers")
switched the backchannel to svc_rdma_map_reply_msg(), which
DMA-maps the buffer and records no pages. Send completion no
longer touches the page, but the get_page() stayed.
xprt_rdma_bc_free() drops the allocation reference and nothing
drops the extra one, so every backchannel Call sent over RPC/RDMA
leaks its send buffer page.
The extra reference is still needed. A Call at or above
RPCRDMA_PULLUP_THRESH is DMA-mapped in place. The RPC client frees
rq_buffer when the callback task times out or is killed, whether
or not the Send has completed. Record the page in the send
context's page array so that svc_rdma_send_ctxt_release() drops
the reference after Send completion.
Fixes: 99722fe4d5a6 ("svcrdma: Persistently allocate and DMA-map Send buffers")
Signed-off-by: Chuck Lever <cel@kernel.org>
---
net/sunrpc/xprtrdma/svc_rdma_backchannel.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/net/sunrpc/xprtrdma/svc_rdma_backchannel.c b/net/sunrpc/xprtrdma/svc_rdma_backchannel.c
index e5a78b761012..e0768d1ee556 100644
--- a/net/sunrpc/xprtrdma/svc_rdma_backchannel.c
+++ b/net/sunrpc/xprtrdma/svc_rdma_backchannel.c
@@ -85,10 +85,14 @@ static int svc_rdma_bc_sendto(struct svcxprt_rdma *rdma,
if (ret < 0)
return -EIO;
- /* Bump page refcnt so Send completion doesn't release
- * the rq_buffer before all retransmits are complete.
+ /* The RPC client frees rq_buffer when the callback task ends,
+ * whether or not the Send has completed. Hold the page until the
+ * send context is released after Send completion.
*/
- get_page(virt_to_page(rqst->rq_buffer));
+ sctxt->sc_pages[0] = virt_to_page(rqst->rq_buffer);
+ get_page(sctxt->sc_pages[0]);
+ sctxt->sc_page_count = 1;
+
sctxt->sc_send_wr.opcode = IB_WR_SEND;
return svc_rdma_post_send(rdma, sctxt);
}
--
2.55.0
next prev parent reply other threads:[~2026-09-22 1:51 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 1:51 [PATCH v1 1/5] SUNRPC: fire svc_xprt_free tracepoint before dropping the netns Chuck Lever
2026-09-22 1:51 ` [PATCH v1 2/5] SUNRPC: fire svc_defer_queue tracepoint before publishing the request Chuck Lever
2026-09-22 1:57 ` sashiko-bot
2026-09-22 1:51 ` Chuck Lever [this message]
2026-09-22 1:58 ` [PATCH v1 3/5] svcrdma: fix a page leak in backchannel sends sashiko-bot
2026-09-22 1:51 ` [PATCH v1 4/5] svcrdma: release a send context stranded by a partial post Chuck Lever
2026-09-22 1:59 ` sashiko-bot
2026-09-22 1:51 ` [PATCH v1 5/5] svcrdma: release a receive context stranded by a partial Read post Chuck Lever
2026-09-22 1:57 ` sashiko-bot
2026-09-22 1:57 ` [PATCH v1 1/5] SUNRPC: fire svc_xprt_free tracepoint before dropping the netns sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922015128.240977-3-cel@kernel.org \
--to=cel@kernel.org \
--cc=dai.ngo@oracle.com \
--cc=jlayton@kernel.org \
--cc=linux-nfs@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=neil@brown.name \
--cc=okorniev@redhat.com \
--cc=tom@talpey.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox