mana_post_rx_wqe() frees the mbuf when mana_alloc_pmd_mr() fails, but
the caller already frees the un-posted range starting at that same
mbuf via rte_pktmbuf_free_bulk(&mbufs[i], batch_count - i), so the
mbuf is returned to the mempool twice and can be handed out to two
consumers at once.

The free was correct before the bulk allocation rework, when this
function allocated the mbuf itself. Now that the caller owns it, leave
the mbuf to the caller on every error path.

Fixes: eeb37809601b ("net/mana: use bulk mbuf allocation for Rx WQEs")
Cc: [email protected]
Signed-off-by: Rita Ruvinsky <[email protected]>
---
 drivers/net/mana/rx.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/mana/rx.c b/drivers/net/mana/rx.c
index f196d43aee..2bca004dfa 100644
--- a/drivers/net/mana/rx.c
+++ b/drivers/net/mana/rx.c
@@ -68,10 +68,10 @@ mana_post_rx_wqe(struct mana_rxq *rxq, struct rte_mbuf 
*mbuf)
        int ret;
        struct mana_mr_cache *mr;
 
+       /* Don't free mbuf on error: the caller bulk-frees it from &mbufs[i]. */
        mr = mana_alloc_pmd_mr(&rxq->mr_btree, priv, mbuf);
        if (!mr) {
                DP_LOG(ERR, "failed to register RX MR");
-               rte_pktmbuf_free(mbuf);
                return -ENOMEM;
        }
 
-- 
2.43.0

Reply via email to