Thread (8 messages) read the whole thread 8 messages, 3 authors, 2d ago

Re: [PATCH net-next v2 1/3] net: atlantic: free stranded TX buffers on ring deinit

From: Paolo Abeni <pabeni@redhat.com>
Date: 2026-07-30 10:13:18
Also in: bpf, lkml, stable

On 7/24/26 11:01 AM, Yangyu Chen wrote:
aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean()
call, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and
stops at hw_head, which no longer moves once aq_vec_stop() has stopped
the hardware and NAPI. Completed descriptors beyond the budget and
everything still posted in [hw_head, sw_tail) keep their skb or
xdp_frame when the interface goes down: aq_vec_ring_free() then frees
the buffer ring and the references are lost for good.

Today this is a silent memory leak on every interface down under
TX/XDP_TX load. With the following conversion of the RX path to
page_pool it becomes much more visible: XDP_TX frames carry fragment
references on the RX ring's page_pool, so a single stranded frame
keeps the pool's inflight count above zero forever. page_pool_destroy()
then never completes, the pool is leaked together with its pages, and
"page_pool_release_retry() stalled pool shutdown" is warned every 60
seconds from that point on, on every ifdown, XDP detach or ring resize
under XDP_TX load.

Bring back aq_ring_tx_deinit() as it was before the removal and use it
for teardown again, with one extension: TX rings can hold xdp_frames
nowadays, so release those too. They are returned with
xdp_return_frame() since this runs in process context.

Fixes: eb36bedf28be ("net: aquantia: remove function aq_ring_tx_deinit")
Cc: stable@vger.kernel.org # v4.11+
Assisted-by: Claude:claude-fable-5
Signed-off-by: Yangyu Chen <redacted>
You missed a relevant point from Mina's feedback: this is 'net'
material. We don't want fixes tag in net-next addressing bug in previous
releases.

You need to send this to 'net', wait for the commit to reach net-next
and resend patches 2 and 3 after that.

/P
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help