Netdev List
 help / color / mirror / Atom feed
From: manjunath.b.patil@oracle.com
To: netdev-bot+sinfo@kernel.org
Cc: saeedm@nvidia.com, leonro@nvidia.com, tariqt@nvidia.com,
	mbloch@nvidia.com, netdev@vger.kernel.org,
	linux-rdma@vger.kernel.org
Subject: Re: [PATCH net] net/mlx5: retain command mailboxes after timeout
Date: Fri, 2 Oct 2026 14:33:29 -0700	[thread overview]
Message-ID: <1517a795-a321-48c2-b896-f0f554fa066a@oracle.com> (raw)
In-Reply-To: <179097470162.1402591.16776600563260914451@kernel.org>


On 10/2/26 1:58 PM, netdev-bot+sinfo@kernel.org wrote:
> Hi!
> 
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
> 
>   - How the issue was discovered, e.g. hit in production, hit during
>     development, syzbot report, manual code inspection, LLM or static
>     analysis tool scan.
> 
>   - Whether the issue was actually triggered, or is only theoretical
>     (e.g. found by code inspection). If it was triggered please include
>     the symptoms, like the stack trace or error messages.
> 
>   - What hardware the change was tested on. For driver fixes please
>     mention the device (and if relevant firmware version) used for
>     testing, or say that the change was not tested on real hardware.
> 
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
> 
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.

Hi,

Thanks for the reminder. This was prompted by crashes on two production
systems with mlx5 command timeouts and device-health errors. One log
reported "Command completion arrived after timeout (entry idx = 2)"
shortly before an oops:

   BUG: kernel NULL pointer dereference, address: 0000000000000100
   RIP: dma_pool_alloc+0x3b/0x211
   mlx5_alloc_cmd_msg -> cmd_exec -> mlx5e_update_stats_work

The vmcores showed the mlx5_cmd DMA pool's next_block pointer at 0x100.
Manual inspection of the command timeout path then identified the early
mailbox free addressed by this patch. The production failure is real, 
but we have not proved that late firmware access caused that particular 
pool corruption, nor reproduced the original panic.

I tested the fix on an OL9 x86_64 VM with two passthrough ConnectX-7
SR-IOV VFs, both reporting firmware 28.34.4000. Test-only fault 
injection exercised normal, timeout-late, timeout-reset, timeout-lost, 
and timeout/completion-overlap paths on both VFs. In the overlap test, 
the blocking caller returned -ETIMEDOUT while completion was paused 
before its final mailbox access; the mailboxes and slot remained live 
until completion finished, then were released. There were no KASAN 
reports or kmemleak findings. The overlap uses a synthetic sleepable 
completion worker, not a physical firmware EQ interrupt.

Thanks,
Manjunath

  reply	other threads:[~2026-10-02 21:33 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 20:56 [PATCH net] net/mlx5: retain command mailboxes after timeout Manjunath Patil
2026-10-02 20:58 ` netdev-bot+sinfo
2026-10-02 21:33   ` manjunath.b.patil [this message]
2026-10-03 21:18 ` netdev-bot+sashiko
2026-10-05 17:23   ` manjunath.b.patil
2026-10-06 13:01 ` Moshe Shemesh
2026-10-06 19:42   ` manjunath.b.patil

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1517a795-a321-48c2-b896-f0f554fa066a@oracle.com \
    --to=manjunath.b.patil@oracle.com \
    --cc=leonro@nvidia.com \
    --cc=linux-rdma@vger.kernel.org \
    --cc=mbloch@nvidia.com \
    --cc=netdev-bot+sinfo@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=saeedm@nvidia.com \
    --cc=tariqt@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox