The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
@ 2026-06-28  8:33 WenTao Liang
  2026-06-29  4:37 ` Greg KH
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: WenTao Liang @ 2026-06-28  8:33 UTC (permalink / raw)
  To: ntb
  Cc: jdmason, dave.jiang, allenbh, linux-kernel, stable, WenTao Liang,
	Greg KH

When dmaengine_submit fails after dma_set_unmap has been called, the
error path err_set_unmap only calls dmaengine_unmap_put once, but the
unmap object has two references (one from dmaengine_get_unmap_data and
one from dma_set_unmap held by the tx descriptor). The tx descriptor
itself is never freed, so its reference to unmap is never released,
causing a kref leak and a dangling pointer in the freed descriptor.

Replace dmaengine_unmap_put with dmaengine_desc_put(txd) in the
err_set_unmap path to properly release the tx descriptor, which will also
drop the unmap reference it holds.

Suggested-by: Greg KH <gregkh@linuxfoundation.org>
Fixes: 282a2feeb9bf ("NTB: Use DMA Engine to Transmit and Receive")
Cc: stable@vger.kernel.org
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>

Changes in v2:
- Fix patch format based on reviewer feedback
- Resend to ntb@lists.linux.dev (remove invalid googlegroups address)
---
 drivers/ntb/ntb_transport.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
index 7cabc82305d6..28091ec5a74e 100644
--- a/drivers/ntb/ntb_transport.c
+++ b/drivers/ntb/ntb_transport.c
@@ -1572,7 +1572,7 @@ static int ntb_async_rx_submit(struct ntb_queue_entry *entry, void *offset)
 	return 0;
 
 err_set_unmap:
-	dmaengine_unmap_put(unmap);
+	dmaengine_desc_put(txd);
 err_get_unmap:
 	dmaengine_unmap_put(unmap);
 err:
@@ -1896,7 +1896,7 @@ static int ntb_async_tx_submit(struct ntb_transport_qp *qp,
 
 	return 0;
 err_set_unmap:
-	dmaengine_unmap_put(unmap);
+	dmaengine_desc_put(txd);
 err_get_unmap:
 	dmaengine_unmap_put(unmap);
 err:
-- 
2.39.5 (Apple Git-154)


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
  2026-06-28  8:33 [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure WenTao Liang
@ 2026-06-29  4:37 ` Greg KH
  2026-08-15  2:05 ` kernel test robot
  2026-08-16  3:01 ` kernel test robot
  2 siblings, 0 replies; 4+ messages in thread
From: Greg KH @ 2026-06-29  4:37 UTC (permalink / raw)
  To: WenTao Liang; +Cc: ntb, jdmason, dave.jiang, allenbh, linux-kernel, stable

On Sun, Jun 28, 2026 at 04:33:01PM +0800, WenTao Liang wrote:
> When dmaengine_submit fails after dma_set_unmap has been called, the
> error path err_set_unmap only calls dmaengine_unmap_put once, but the
> unmap object has two references (one from dmaengine_get_unmap_data and
> one from dma_set_unmap held by the tx descriptor). The tx descriptor
> itself is never freed, so its reference to unmap is never released,
> causing a kref leak and a dangling pointer in the freed descriptor.
> 
> Replace dmaengine_unmap_put with dmaengine_desc_put(txd) in the
> err_set_unmap path to properly release the tx descriptor, which will also
> drop the unmap reference it holds.
> 
> Suggested-by: Greg KH <gregkh@linuxfoundation.org>

No, I didn't suggest ANY of these patches.

Also you did not use Assisted-by:, why?

Please start small with just 1 patch that you can do properly, before
flooding us with lots.

Please go and reply to all of these where you incorrectly added my
suggested-by and ask for them to be dropped.

greg k-h

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
  2026-06-28  8:33 [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure WenTao Liang
  2026-06-29  4:37 ` Greg KH
@ 2026-08-15  2:05 ` kernel test robot
  2026-08-16  3:01 ` kernel test robot
  2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-08-15  2:05 UTC (permalink / raw)
  To: WenTao Liang, ntb
  Cc: oe-kbuild-all, jdmason, dave.jiang, allenbh, linux-kernel, stable,
	WenTao Liang, Greg KH

Hi WenTao,

kernel test robot noticed the following build errors:

[auto build test ERROR on jonmason-ntb/ntb-next]
[also build test ERROR on linus/master v7.2-rc7 next-20260813]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]

url:    https://github.com/intel-lab-lkp/linux/commits/WenTao-Liang/ntb-fix-tx-descriptor-leak-on-dmaengine_submit-failure/20260815-061001
base:   https://github.com/jonmason/ntb ntb-next
patch link:    https://lore.kernel.org/r/20260628083301.9781-1-vulab%40iscas.ac.cn
patch subject: [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
config: alpha-allmodconfig (https://download.01.org/0day-ci/archive/20260815/202608150920.Q3iV5WrW-lkp@intel.com/config)
compiler: alpha-linux-gcc (GCC) 16.1.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260815/202608150920.Q3iV5WrW-lkp@intel.com/reproduce)

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608150920.Q3iV5WrW-lkp@intel.com/

All errors (new ones prefixed by >>):

   drivers/ntb/ntb_transport.c: In function 'ntb_async_rx_submit':
>> drivers/ntb/ntb_transport.c:1577:9: error: implicit declaration of function 'dmaengine_desc_put'; did you mean 'dmaengine_desc_free'? [-Wimplicit-function-declaration]
    1577 |         dmaengine_desc_put(txd);
         |         ^~~~~~~~~~~~~~~~~~
         |         dmaengine_desc_free


vim +1577 drivers/ntb/ntb_transport.c

  1515	
  1516	static int ntb_async_rx_submit(struct ntb_queue_entry *entry, void *offset)
  1517	{
  1518		struct dma_async_tx_descriptor *txd;
  1519		struct ntb_transport_qp *qp = entry->qp;
  1520		struct dma_chan *chan = qp->rx_dma_chan;
  1521		struct dma_device *device;
  1522		size_t pay_off, buff_off, len;
  1523		struct dmaengine_unmap_data *unmap;
  1524		dma_cookie_t cookie;
  1525		void *buf = entry->buf;
  1526	
  1527		len = entry->len;
  1528		device = chan->device;
  1529		pay_off = (size_t)offset & ~PAGE_MASK;
  1530		buff_off = (size_t)buf & ~PAGE_MASK;
  1531	
  1532		if (!is_dma_copy_aligned(device, pay_off, buff_off, len))
  1533			goto err;
  1534	
  1535		unmap = dmaengine_get_unmap_data(device->dev, 2, GFP_NOWAIT);
  1536		if (!unmap)
  1537			goto err;
  1538	
  1539		unmap->len = len;
  1540		unmap->addr[0] = dma_map_phys(device->dev, virt_to_phys(offset),
  1541					      len, DMA_TO_DEVICE, 0);
  1542		if (dma_mapping_error(device->dev, unmap->addr[0]))
  1543			goto err_get_unmap;
  1544	
  1545		unmap->to_cnt = 1;
  1546	
  1547		unmap->addr[1] = dma_map_phys(device->dev, virt_to_phys(buf),
  1548					      len, DMA_FROM_DEVICE, 0);
  1549		if (dma_mapping_error(device->dev, unmap->addr[1]))
  1550			goto err_get_unmap;
  1551	
  1552		unmap->from_cnt = 1;
  1553	
  1554		txd = device->device_prep_dma_memcpy(chan, unmap->addr[1],
  1555						     unmap->addr[0], len,
  1556						     DMA_PREP_INTERRUPT);
  1557		if (!txd)
  1558			goto err_get_unmap;
  1559	
  1560		txd->callback_result = ntb_rx_copy_callback;
  1561		txd->callback_param = entry;
  1562		dma_set_unmap(txd, unmap);
  1563	
  1564		cookie = dmaengine_submit(txd);
  1565		if (dma_submit_error(cookie))
  1566			goto err_set_unmap;
  1567	
  1568		dmaengine_unmap_put(unmap);
  1569	
  1570		qp->last_cookie = cookie;
  1571	
  1572		qp->rx_async++;
  1573	
  1574		return 0;
  1575	
  1576	err_set_unmap:
> 1577		dmaengine_desc_put(txd);
  1578	err_get_unmap:
  1579		dmaengine_unmap_put(unmap);
  1580	err:
  1581		return -ENXIO;
  1582	}
  1583	

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
  2026-06-28  8:33 [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure WenTao Liang
  2026-06-29  4:37 ` Greg KH
  2026-08-15  2:05 ` kernel test robot
@ 2026-08-16  3:01 ` kernel test robot
  2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-08-16  3:01 UTC (permalink / raw)
  To: WenTao Liang, ntb
  Cc: llvm, oe-kbuild-all, jdmason, dave.jiang, allenbh, linux-kernel,
	stable, WenTao Liang, Greg KH

Hi WenTao,

kernel test robot noticed the following build errors:

[auto build test ERROR on jonmason-ntb/ntb-next]
[also build test ERROR on linus/master v7.2-rc7 next-20260814]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]

url:    https://github.com/intel-lab-lkp/linux/commits/WenTao-Liang/ntb-fix-tx-descriptor-leak-on-dmaengine_submit-failure/20260815-061001
base:   https://github.com/jonmason/ntb ntb-next
patch link:    https://lore.kernel.org/r/20260628083301.9781-1-vulab%40iscas.ac.cn
patch subject: [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure
config: loongarch-defconfig (https://download.01.org/0day-ci/archive/20260816/202608161033.NUWmez14-lkp@intel.com/config)
compiler: clang version 24.0.0git (https://github.com/llvm/llvm-project 844a18e753e822736c9805ab779144b647a2c186)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260816/202608161033.NUWmez14-lkp@intel.com/reproduce)

If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202608161033.NUWmez14-lkp@intel.com/

All errors (new ones prefixed by >>):

>> drivers/ntb/ntb_transport.c:1577:2: error: call to undeclared function 'dmaengine_desc_put'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration]
    1577 |         dmaengine_desc_put(txd);
         |         ^
   drivers/ntb/ntb_transport.c:1577:2: note: did you mean 'dmaengine_desc_free'?
   include/linux/dmaengine.h:1607:19: note: 'dmaengine_desc_free' declared here
    1607 | static inline int dmaengine_desc_free(struct dma_async_tx_descriptor *desc)
         |                   ^
   drivers/ntb/ntb_transport.c:1901:2: error: call to undeclared function 'dmaengine_desc_put'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration]
    1901 |         dmaengine_desc_put(txd);
         |         ^
   2 errors generated.


vim +/dmaengine_desc_put +1577 drivers/ntb/ntb_transport.c

  1515	
  1516	static int ntb_async_rx_submit(struct ntb_queue_entry *entry, void *offset)
  1517	{
  1518		struct dma_async_tx_descriptor *txd;
  1519		struct ntb_transport_qp *qp = entry->qp;
  1520		struct dma_chan *chan = qp->rx_dma_chan;
  1521		struct dma_device *device;
  1522		size_t pay_off, buff_off, len;
  1523		struct dmaengine_unmap_data *unmap;
  1524		dma_cookie_t cookie;
  1525		void *buf = entry->buf;
  1526	
  1527		len = entry->len;
  1528		device = chan->device;
  1529		pay_off = (size_t)offset & ~PAGE_MASK;
  1530		buff_off = (size_t)buf & ~PAGE_MASK;
  1531	
  1532		if (!is_dma_copy_aligned(device, pay_off, buff_off, len))
  1533			goto err;
  1534	
  1535		unmap = dmaengine_get_unmap_data(device->dev, 2, GFP_NOWAIT);
  1536		if (!unmap)
  1537			goto err;
  1538	
  1539		unmap->len = len;
  1540		unmap->addr[0] = dma_map_phys(device->dev, virt_to_phys(offset),
  1541					      len, DMA_TO_DEVICE, 0);
  1542		if (dma_mapping_error(device->dev, unmap->addr[0]))
  1543			goto err_get_unmap;
  1544	
  1545		unmap->to_cnt = 1;
  1546	
  1547		unmap->addr[1] = dma_map_phys(device->dev, virt_to_phys(buf),
  1548					      len, DMA_FROM_DEVICE, 0);
  1549		if (dma_mapping_error(device->dev, unmap->addr[1]))
  1550			goto err_get_unmap;
  1551	
  1552		unmap->from_cnt = 1;
  1553	
  1554		txd = device->device_prep_dma_memcpy(chan, unmap->addr[1],
  1555						     unmap->addr[0], len,
  1556						     DMA_PREP_INTERRUPT);
  1557		if (!txd)
  1558			goto err_get_unmap;
  1559	
  1560		txd->callback_result = ntb_rx_copy_callback;
  1561		txd->callback_param = entry;
  1562		dma_set_unmap(txd, unmap);
  1563	
  1564		cookie = dmaengine_submit(txd);
  1565		if (dma_submit_error(cookie))
  1566			goto err_set_unmap;
  1567	
  1568		dmaengine_unmap_put(unmap);
  1569	
  1570		qp->last_cookie = cookie;
  1571	
  1572		qp->rx_async++;
  1573	
  1574		return 0;
  1575	
  1576	err_set_unmap:
> 1577		dmaengine_desc_put(txd);
  1578	err_get_unmap:
  1579		dmaengine_unmap_put(unmap);
  1580	err:
  1581		return -ENXIO;
  1582	}
  1583	

--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-16  3:01 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-28  8:33 [PATCH v2] ntb: fix tx descriptor leak on dmaengine_submit failure WenTao Liang
2026-06-29  4:37 ` Greg KH
2026-08-15  2:05 ` kernel test robot
2026-08-16  3:01 ` kernel test robot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox