* [PATCH] RDMA/mlx5: Unbind data direct device on IB device unregister
@ 2026-09-23 8:14 lirongqing
2026-09-23 8:31 ` sashiko-bot
0 siblings, 1 reply; 2+ messages in thread
From: lirongqing @ 2026-09-23 8:14 UTC (permalink / raw)
To: Leon Romanovsky, Jason Gunthorpe, Yishai Hadas, linux-rdma,
linux-kernel
Cc: Li RongQing
From: Li RongQing <lirongqing@baidu.com>
mlx5_data_direct_ib_unreg() removes and frees the registration entry
but, unlike mlx5_data_direct_dev_unreg(), does not call
mlx5_ib_data_direct_unbind().
As a result, when an IB device is unregistered while its affiliated
data-direct device is still registered, its data_direct_dev pointer
is left set and its data-direct MRs are not revoked.
Call mlx5_ib_data_direct_unbind() before removing the registration so
that the data-direct MRs are revoked and data_direct_dev is cleared
during IB device teardown as well.
Fixes: 6910e3660d86 ("RDMA/mlx5: Introduce the 'data direct' driver")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
---
drivers/infiniband/hw/mlx5/data_direct.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/hw/mlx5/data_direct.c b/drivers/infiniband/hw/mlx5/data_direct.c
index d574842..54c07ac 100644
--- a/drivers/infiniband/hw/mlx5/data_direct.c
+++ b/drivers/infiniband/hw/mlx5/data_direct.c
@@ -113,6 +113,7 @@ void mlx5_data_direct_ib_unreg(struct mlx5_ib_dev *ibdev)
mutex_lock(&mlx5_data_direct_mutex);
list_for_each_entry(reg, &mlx5_data_direct_reg_list, list) {
if (reg->ibdev == ibdev) {
+ mlx5_ib_data_direct_unbind(reg->ibdev);
list_del(®->list);
kfree(reg);
goto end;
--
2.9.4
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH] RDMA/mlx5: Unbind data direct device on IB device unregister
2026-09-23 8:14 [PATCH] RDMA/mlx5: Unbind data direct device on IB device unregister lirongqing
@ 2026-09-23 8:31 ` sashiko-bot
0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-23 8:31 UTC (permalink / raw)
To: lirongqing; +Cc: linux-rdma
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] RDMA/mlx5: Use-After-Free in mlx5r_umr_post_send due to teardown phase inversion
--
commit a526f3c890d0ead88aa1cec9b7e04bfef90a8d6b
Author: Li RongQing <lirongqing@baidu.com>
RDMA/mlx5: Unbind data direct device on IB device unregister
This commit adds a call to mlx5_ib_data_direct_unbind() during IB device
unregister to revoke data-direct MRs and clear the data_direct_dev pointer.
> diff --git a/drivers/infiniband/hw/mlx5/data_direct.c b/drivers/infiniband/hw/mlx5/data_direct.c
> index 93a56ee2c4ef4..66852e83c38d0 100644
> --- a/drivers/infiniband/hw/mlx5/data_direct.c
> +++ b/drivers/infiniband/hw/mlx5/data_direct.c
[ ... ]
> @@ -109,6 +109,7 @@ void mlx5_data_direct_ib_unreg(struct mlx5_ib_dev *ibdev)
> mutex_lock(&mlx5_data_direct_mutex);
> list_for_each_entry(reg, &mlx5_data_direct_reg_list, list) {
> if (reg->ibdev == ibdev) {
> + mlx5_ib_data_direct_unbind(reg->ibdev);
[Severity: High]
Does this introduce a use-after-free during device teardown?
Looking at the teardown sequence in __mlx5_ib_remove(), device stages are
cleaned up in reverse order. The MLX5_IB_STAGE_PRE_IB_REG_UMR stage is torn
down before MLX5_IB_STAGE_INIT.
During MLX5_IB_STAGE_PRE_IB_REG_UMR cleanup, mlx5r_umr_resource_cleanup()
frees the UMR queue pair:
mlx5r_umr_resource_cleanup() {
...
ib_destroy_qp(dev->umrc.qp);
...
}
Later, during MLX5_IB_STAGE_INIT cleanup, mlx5_ib_stage_init_cleanup() calls
mlx5_data_direct_ib_unreg(), which now triggers mlx5_ib_data_direct_unbind().
If there are remaining MRs to revoke, the call chain is:
mlx5_ib_data_direct_unbind()
mlx5_ib_revoke_data_direct_mrs()
mlx5r_umr_revoke_mr()
mlx5r_umr_post_send_wait()
At this point, mlx5r_umr_post_send_wait() will attempt to post a work request
using the already-freed dev->umrc.qp, causing a use-after-free if any
data-direct MRs failed to deregister cleanly.
> list_del(®->list);
> kfree(reg);
> goto end;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923081442.2520-1-lirongqing@baidu.com?part=1
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-23 8:31 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23 8:14 [PATCH] RDMA/mlx5: Unbind data direct device on IB device unregister lirongqing
2026-09-23 8:31 ` sashiko-bot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox