Thread (3 messages) 3 messages, 2 authors, 19d ago

RE: [Intel-wired-lan] [PATCH iwl-net v2] ice: add missing xa_destroy for sched_node_ids

From: Loktionov, Aleksandr <hidden>
Date: 2026-07-07 13:31:22
Also in: intel-wired-lan

-----Original Message-----
From: Intel-wired-lan <redacted> On Behalf
Of Jacob Keller
Sent: Tuesday, July 7, 2026 1:31 AM
To: Nguyen, Anthony L <anthony.l.nguyen@intel.com>; Kitszel,
Przemyslaw [off-list ref]
Cc: intel-wired-lan@lists.osuosl.org; netdev@vger.kernel.org; Keller,
Jacob E [off-list ref]
Subject: [Intel-wired-lan] [PATCH iwl-net v2] ice: add missing
xa_destroy for sched_node_ids

Commit 16dfa49406bc ("ice: Introduce new parameters in
ice_sched_node") added a sched_node_ids xarray to the port info
structure, but never called xa_destroy on it.

Since xarrays can allocate internal memory, this can result in a
memory leak even if every element in the xarray has been removed.

The xarray is currently embedded in the port_info structure. This
appears to have been done because its use is within functions that
take the port_info as a primary argument.

However, this complicates managing the lifecycle of the field. The
port_info structure is allocated in ice_init_hw() using devm, and it
is not released until the devm cleanup when the driver is unloaded.

The ice_init_hw() function is called in many places, including devlink
reload, and possibly during DDP load after updating the Tx scheduler
layout.

Adding a call of xa_destroy to the ice_deinit_hw() causes Sashiko to
raise multiple concerns due to potential ordering issues and possible
ways that port_info could be a dangling reference.

To handle this, move the sched_node_ids out of port_info and into the
hw structure. All users of the array already have a pointer to hw
anyways, and there is only one sched_node_ids per adapter. While here,
remove the overly verbose comment explaining the nature of the
sched_node_ids xarray.

Add the missing xa_destroy to the cleanup path and to ice_deinit_hw(),
ensuring that we properly release the xarray memory.

This was caught by Sashiko during development of unrelated code.

Fixes: 16dfa49406bc ("ice: Introduce new parameters in
ice_sched_node")
Signed-off-by: Jacob Keller <jacob.e.keller@intel.com>
Reviewed-by: Aleksandr Loktionov <redacted>
quoted hunk ↗ jump to hunk
---
Changes in v2:
- Move sched_node_ids out of port_into into hw.
- Link to v1: https://patch.msgid.link/20260514-jk-fix-missing-xa-
destroy-v1-1-de437bf52347@intel.com
---
 drivers/net/ethernet/intel/ice/ice_type.h   | 2 +-
 drivers/net/ethernet/intel/ice/ice_common.c | 9 ++++++---
drivers/net/ethernet/intel/ice/ice_sched.c  | 4 ++--
 3 files changed, 9 insertions(+), 6 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_type.h
b/drivers/net/ethernet/intel/ice/ice_type.h
index d9a5c1aae7c2..cf147a212707 100644
--- a/drivers/net/ethernet/intel/ice/ice_type.h
+++ b/drivers/net/ethernet/intel/ice/ice_type.h
@@ -765,7 +765,6 @@ struct ice_port_info {
 	/* List contain profile ID(s) and other params per layer */
 	struct list_head rl_prof_list[ICE_AQC_TOPO_MAX_LEVEL_NUM];
 	struct ice_qos_cfg qos_cfg;
...
 				  GFP_KERNEL);
 		if (status) {
 			ice_debug(hw, ICE_DBG_SCHED, "xa_alloc failed for
sched node status =%d\n",

---
base-commit: 9e05e91a9a847ed57926414bd7c2c5e54d6c56c6
change-id: 20260514-jk-fix-missing-xa-destroy-d3f90f3711be

Best regards,
--
Jacob Keller [off-list ref]
  
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help