Thread (23 messages) 23 messages, 3 authors, 2d ago

Re: [PATCH net-next v4 03/10] NTB: ntb_transport: Order RX entry completion

flat view

From: Koichiro Den <hidden>
Date: 2026-09-19 12:53:44
Also in: lkml

On Fri, Sep 18, 2026 at 06:10:39PM -0700, Joe Damato wrote:
On Mon, Sep 14, 2026 at 05:48:31PM +0900, Koichiro Den wrote:
quoted
RX entries are added to rx_post_q before their fields are filled in.
The overflow path sets DONE without a write barrier, and
ntb_complete_rxc() has no read barrier after checking DONE. A concurrent
completion can therefore consume stale entry fields.

Publish DONE with release ordering and check it with acquire ordering in
ntb_complete_rxc(). Use the same publication rule in the copy callback.

Fixes: da2e5ae56164 ("NTB: Fix ntb_transport out-of-order RX update")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260904052134.2970111-1-den%40valinux.co.jp?part=3
Signed-off-by: Koichiro Den <redacted>
---
Changes in v4:
  - New patch (Sashiko)

 drivers/ntb/ntb_transport.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
index 3f497a62673f..b69e8ac8047d 100644
--- a/drivers/ntb/ntb_transport.c
+++ b/drivers/ntb/ntb_transport.c
[...]
quoted
-	entry->flags |= DESC_DONE_FLAG;
+	/* Pair with the acquire load in ntb_complete_rxc(). */
+	smp_store_release(&entry->flags, entry->flags | DESC_DONE_FLAG);
                                          ^^^^^^^^^^^

quoted
 
 	ntb_complete_rxc(entry->qp);
 }
@@ -1664,7 +1666,8 @@ static int ntb_process_rxc(struct ntb_transport_qp *qp)
 		qp->rx_err_oflow++;
 
 		entry->len = -EIO;
-		entry->flags |= DESC_DONE_FLAG;
+		/* Pair with the acquire load in ntb_complete_rxc(). */
+		smp_store_release(&entry->flags, entry->flags | DESC_DONE_FLAG);
                                                 ^^^^^^^^^^^^

are these two smp_store_release lines right? i am asking because it looks like
they do a load ? i honestly have no idea if there is a race here but it looks
sus to me
There are no concurrent writers to entry->flags here, so I think the plain load
on the right hand side is fine.

Best regards,
Koichiro
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help