From: Leon Romanovsky <leon@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: Tariq Toukan <tariqt@nvidia.com>, linux-rdma@vger.kernel.org
Subject: Re: [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct
Date: Mon, 28 Sep 2026 14:39:40 +0300 [thread overview]
Message-ID: <20260928113940.GV563127@unreal> (raw)
In-Reply-To: <20260918111632.4415C1F000FF@smtp.kernel.org>
On Fri, Sep 18, 2026 at 11:16:31AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] core: missing smp_store_release() in lockless pointer publication
> --
>
> commit 70f41e46e61426ca24948348bb11ea96b2dc863f
> Author: Dragos Tatulea <dtatulea@nvidia.com>
>
> RDMA/mlx5: Extract IB specific lock out of data direct
>
> The data_direct_lock from struct mlx5_ib_dev is an IB specific lock.
> It protects from unbind while mlx5_data_direct_dev is being accessed.
> So move data_direct_lock out of the generic bind/unbind functions
> and into the IB specific notifier callback.
>
> > diff --git a/drivers/infiniband/hw/mlx5/data_direct.c b/drivers/infiniband/hw/mlx5/data_direct.c
> > index f871e3ce9f73d..16afacdd36018 100644
> > --- a/drivers/infiniband/hw/mlx5/data_direct.c
> > +++ b/drivers/infiniband/hw/mlx5/data_direct.c
> > @@ -197,9 +197,7 @@ mlx5_data_direct_get_reg(struct mlx5_ib_dev *ibdev)
> > static void mlx5_data_direct_bind(struct mlx5_ib_dev *ibdev,
> > struct mlx5_data_direct_dev *dev)
> > {
> > - mutex_lock(&ibdev->data_direct_lock);
> > - ibdev->data_direct_dev = dev;
> > - mutex_unlock(&ibdev->data_direct_lock);
> > + WRITE_ONCE(ibdev->data_direct_dev, dev);
>
> [Severity: High]
> Is a release barrier needed here?
>
> By removing the shared lock, this becomes a lockless publication.
> mutex_lock() only provides ACQUIRE semantics, so the writer lacks a RELEASE
> barrier like smp_store_release().
>
> Could weakly-ordered CPUs reorder the initialization of dev to become
> visible after the pointer publication? This might allow a concurrent
> lockless reader to observe the newly assigned pointer but read uninitialized
> structure fields (e.g., dev->pdev being NULL), leading to a kernel panic
> when dereferenced.
>
> [ ... ]
> > diff --git a/drivers/infiniband/hw/mlx5/mr.c b/drivers/infiniband/hw/mlx5/mr.c
> > index e6b74955d95dc..1fc61a680f8af 100644
> > --- a/drivers/infiniband/hw/mlx5/mr.c
> > +++ b/drivers/infiniband/hw/mlx5/mr.c
> > @@ -997,7 +997,7 @@ reg_user_mr_dmabuf_by_data_direct(struct ib_pd *pd, u64 offset,
> > return ERR_PTR(-EOPNOTSUPP);
> >
> > mutex_lock(&dev->data_direct_lock);
> > - data_direct_dev = dev->data_direct_dev;
> > + data_direct_dev = READ_ONCE(dev->data_direct_dev);
>
> [Severity: High]
> Is an acquire barrier like smp_load_acquire() needed here instead of
> READ_ONCE()?
>
> Since the reader in reg_user_mr_dmabuf_by_data_direct() takes a different
> lock (dev->data_direct_lock) than the writer (which takes
> mlx5_data_direct_mutex), it loads the pointer locklessly with respect to the
> writer.
>
> Could an unprivileged userspace issuing an RDMA memory registration
> concurrently with a data direct device hotplug or bind observe uninitialized
> memory fields because of this missing barrier?
At least for bind, no. The ibdev device shouldn't be operable at that
stage yet.
Thanks
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260917111422.4054862-1-tariqt@nvidia.com?part=7
>
next prev parent reply other threads:[~2026-09-28 11:39 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 11:14 [PATCH mlx5-next 00/10] mlx5: Move data direct infrastructure to mlx5_core Tariq Toukan
2026-09-17 11:14 ` [PATCH mlx5-next 01/10] RDMA/mlx5: Notify data direct users via a notifier chain on unbind Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 02/10] RDMA/mlx5: Add mlx5_data_direct_supported() helper Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 03/10] RDMA/mlx5: Make the data direct VUID query self-contained Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 04/10] RDMA/mlx5: Give the data direct PCI driver a proper name Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 05/10] RDMA/mlx5: Move and rename data direct resource functions Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 06/10] RDMA/mlx5: Add new registration stage for data direct users Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 07/10] RDMA/mlx5: Extract IB specific lock out of data direct Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-28 11:39 ` Leon Romanovsky [this message]
2026-09-17 11:14 ` [PATCH mlx5-next 08/10] RDMA/mlx5: Consolidate data direct state into one object Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 09/10] RDMA/mlx5: Pull data_direct resource creation in init phase Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-17 11:14 ` [PATCH mlx5-next 10/10] mlx5: Move data direct implementation to mlx5_core Tariq Toukan
2026-09-18 11:16 ` sashiko-bot
2026-09-28 11:34 ` Leon Romanovsky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928113940.GV563127@unreal \
--to=leon@kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox