Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
From: Leon Romanovsky <leon@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: Tariq Toukan <tariqt@nvidia.com>, linux-rdma@vger.kernel.org
Subject: Re: [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct
Date: Mon, 28 Sep 2026 14:39:40 +0300	[thread overview]
Message-ID: <20260928113940.GV563127@unreal> (raw)
In-Reply-To: <20260918111632.4415C1F000FF@smtp.kernel.org>

On Fri, Sep 18, 2026 at 11:16:31AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] core: missing smp_store_release() in lockless pointer publication
> --
> 
> commit 70f41e46e61426ca24948348bb11ea96b2dc863f
> Author: Dragos Tatulea <dtatulea@nvidia.com>
> 
> RDMA/mlx5: Extract IB specific lock out of data direct
> 
> The data_direct_lock from struct mlx5_ib_dev is an IB specific lock.
> It protects from unbind while mlx5_data_direct_dev is being accessed.
> So move data_direct_lock out of the generic bind/unbind functions
> and into the IB specific notifier callback.
> 
> > diff --git a/drivers/infiniband/hw/mlx5/data_direct.c b/drivers/infiniband/hw/mlx5/data_direct.c
> > index f871e3ce9f73d..16afacdd36018 100644
> > --- a/drivers/infiniband/hw/mlx5/data_direct.c
> > +++ b/drivers/infiniband/hw/mlx5/data_direct.c
> > @@ -197,9 +197,7 @@ mlx5_data_direct_get_reg(struct mlx5_ib_dev *ibdev)
> >  static void mlx5_data_direct_bind(struct mlx5_ib_dev *ibdev,
> >  				  struct mlx5_data_direct_dev *dev)
> >  {
> > -	mutex_lock(&ibdev->data_direct_lock);
> > -	ibdev->data_direct_dev = dev;
> > -	mutex_unlock(&ibdev->data_direct_lock);
> > +	WRITE_ONCE(ibdev->data_direct_dev, dev);
> 
> [Severity: High]
> Is a release barrier needed here?
> 
> By removing the shared lock, this becomes a lockless publication.
> mutex_lock() only provides ACQUIRE semantics, so the writer lacks a RELEASE
> barrier like smp_store_release().
> 
> Could weakly-ordered CPUs reorder the initialization of dev to become
> visible after the pointer publication?  This might allow a concurrent
> lockless reader to observe the newly assigned pointer but read uninitialized
> structure fields (e.g., dev->pdev being NULL), leading to a kernel panic
> when dereferenced.
> 
> [ ... ]
> > diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
> > index e6b74955d95dc..1fc61a680f8af 100644
> > --- a/drivers/infiniband/hw/mlx5/mr.c
> > +++ b/drivers/infiniband/hw/mlx5/mr.c
> > @@ -997,7 +997,7 @@ reg_user_mr_dmabuf_by_data_direct(struct ib_pd *pd, u64 offset,
> >  		return ERR_PTR(-EOPNOTSUPP);
> >  
> >  	mutex_lock(&dev->data_direct_lock);
> > -	data_direct_dev = dev->data_direct_dev;
> > +	data_direct_dev = READ_ONCE(dev->data_direct_dev);
> 
> [Severity: High]
> Is an acquire barrier like smp_load_acquire() needed here instead of
> READ_ONCE()?
> 
> Since the reader in reg_user_mr_dmabuf_by_data_direct() takes a different
> lock (dev->data_direct_lock) than the writer (which takes
> mlx5_data_direct_mutex), it loads the pointer locklessly with respect to the
> writer.
> 
> Could an unprivileged userspace issuing an RDMA memory registration
> concurrently with a data direct device hotplug or bind observe uninitialized
> memory fields because of this missing barrier?

At least for bind, no. The ibdev device shouldn't be operable at that
stage yet.

Thanks

> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20260917111422.4054862-1-tariqt@nvidia.com?part=7
> 

  reply	other threads:[~2026-09-28 11:39 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 11:14 [PATCH mlx5-next 00/10] mlx5: Move data direct infrastructure to mlx5_core Tariq Toukan
2026-09-17 11:14 ` [PATCH mlx5-next 01/10] RDMA/mlx5: Notify data direct users via a notifier chain on unbind Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 02/10] RDMA/mlx5: Add mlx5_data_direct_supported() helper Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 03/10] RDMA/mlx5: Make the data direct VUID query self-contained Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 04/10] RDMA/mlx5: Give the data direct PCI driver a proper name Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 05/10] RDMA/mlx5: Move and rename data direct resource functions Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 06/10] RDMA/mlx5: Add new registration stage for data direct users Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-28 11:39     ` Leon Romanovsky [this message]
2026-09-17 11:14 ` [PATCH mlx5-next 08/10] RDMA/mlx5: Consolidate data direct state into one object Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 09/10] RDMA/mlx5: Pull data_direct resource creation in init phase Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 10/10] mlx5: Move data direct implementation to mlx5_core Tariq Toukan
2026-09-18 11:16   ` sashiko-bot
2026-09-28 11:34     ` Leon Romanovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928113940.GV563127@unreal \
    --to=leon@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox