[PATCH 1/2] ethdev: keep fast-path ops valid after port stop
From: Maxime Leroy <hidden>
Date: 2026-06-16 09:43:13
Subsystem:
library code, the rest · Maintainers:
Andrew Morton, Linus Torvalds
eth_dev_fp_ops_reset() restores a port's fast-path ops on stop/release
via a compound literal, so every field it omits is zeroed to NULL. It
sets only rx_pkt_burst/tx_pkt_burst (and the rxq/txq data), leaving
rx_queue_count, tx_queue_count, rx/tx_descriptor_status, tx_pkt_prepare
and the recycle callbacks NULL.
In non-debug builds these ops are reached through an unguarded indirect
call (the NULL check exists only under RTE_ETHDEV_DEBUG_RX/TX). So a
thread calling e.g. rte_eth_rx_queue_count() on a port being stopped
dereferences NULL and crashes, while the same race on rte_eth_rx_burst()
is harmless because the burst ops are reset to dummies. A poll-mode
worker re-checking rx_queue_count before arming the Rx interrupt and
sleeping hits exactly this.
Reset these non-burst ops to the same dummies eth_dev_set_dummy_fops()
installs, so a stopped port behaves like a freshly allocated one: every
fast-path op is a safe no-op, none is NULL.
Fixes: 066f3d9cc21c ("ethdev: remove callback checks from fast path")
Cc: stable@dpdk.org
Signed-off-by: Maxime Leroy <redacted>
Acked-by: Morten Brørup <redacted>
---
lib/ethdev/ethdev_private.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/lib/ethdev/ethdev_private.c b/lib/ethdev/ethdev_private.c
index 72a0723846..75ea3eedff 100644
--- a/lib/ethdev/ethdev_private.c
+++ b/lib/ethdev/ethdev_private.c@@ -263,6 +263,13 @@ eth_dev_fp_ops_reset(struct rte_eth_fp_ops *fpo) *fpo = (struct rte_eth_fp_ops) { .rx_pkt_burst = dummy_eth_rx_burst, .tx_pkt_burst = dummy_eth_tx_burst, + .tx_pkt_prepare = rte_eth_tx_pkt_prepare_dummy, + .rx_queue_count = rte_eth_queue_count_dummy, + .tx_queue_count = rte_eth_queue_count_dummy, + .rx_descriptor_status = rte_eth_descriptor_status_dummy, + .tx_descriptor_status = rte_eth_descriptor_status_dummy, + .recycle_tx_mbufs_reuse = rte_eth_recycle_tx_mbufs_reuse_dummy, + .recycle_rx_descriptors_refill = rte_eth_recycle_rx_descriptors_refill_dummy, .rxq = { .data = (void **)&dummy_queues_array[port_id], .clbk = dummy_data,
--
2.43.0