On Mon,  5 Oct 2026 14:23:10 +0530
Hemant Agrawal <[email protected]> wrote:

> This series collects a set of fixes and enhancements for the NXP DPAA
> bus, mempool, dma, crypto and net drivers targeting 26.11.
> 
> It includes memory-leak and resource-cleanup fixes on the device
> remove/close paths, more robust frame queue and congestion-group
> shutdown, secondary-process safety guards, BPID and cgrid lifecycle
> handling, and several new features: offline (O/H) port device support,
> enhanced virtual storage profile (VSP) port support, fmcless Rx queue
> configuration via devargs, Rx/Tx taildrop threshold devargs, non
> fmX-macY shared Ethernet naming, and DMA scatter-gather and
> errata-workaround devargs. Documentation and release notes are updated
> accordingly.
> 
> v20:
> * net/dpaa: propagate the dpaa_port_fmc_init() error instead of
>   returning success with no Rx queues, as a separate fix with a
>   Fixes tag so it can be backported.
> * drivers: drop the unused rte_dpaa_bus_oldev_enabled() and add
>   rte_pmd_dpaa_oldev.h to doc/api/doxy-api-index.md.
> * drivers: use qman_pending_fq_by_cgrid_range() over the whole Rx
>   and Tx CGRID range, so a port close costs two FQID space scans
>   rather than one per congestion group.
> * doc: name the new experimental offline port functions in the
>   release notes, document that drv_oldev switches the bus to
>   allowlist mode, and log an over-long drv_sh_if_name.
> 

Still lots more AI comments. As always, AI is not always right!

Error
-----

Patch 11/27: free_rx/free_tx can crash on a CGR that was never
  created.  If qman_create_cgr() fails in dpaa_rx_queue_init(), it
  goes to without_cgr and can still return 0.  The caller then
  counts the CGR anyway:

        if (dpaa_intf->cgr_rx)
                nb_rx_cgr++;

  A later probe failure calls qman_delete_cgr() on it.
  qman_create_cgr() set cgr->chan before failing, so the channel
  check passes, and list_del(&cgr->node) runs on a node zeroed by
  rte_zmalloc():

        (i)->next->prev = (i)->prev;

  next is NULL.  dpaa_tx_queue_init() has the same shape.  Return
  the qman_create_cgr() failure, or report back to the caller
  whether the CGR was created.

Warning
-------

Patch 04/27: The commit message says the tx_conf_queues leak is
  fixed for every probe failure after the allocation, but three
  such paths still jump past it.  The tx_conf_queues, cgr_tx and Tx
  qman_alloc_cgrid_range() failures all do "goto free_rx", and
  free_rx frees neither tx_queues nor tx_conf_queues.  Make them
  goto free_tx; nb_tx_cgr is 0 and tx_cgrid_allocated is false at
  those points.

Patch 12/27: The second paragraph of the commit message, and the
  new comment in qman_shutdown_fq(), describe dropping an "old
  affinity check" against p->config->channel.  The function this
  patch modifies has no such check.  Remove both.

Patch 18/27: The commit message says dma_pool_alloc() now accepts
  a NULL phy_addr.  The patch does not touch it, and it still does:

        *phy_addr = rte_mem_virt2iova(virt_addr);

Patch 22/27: The first paragraph of the commit message describes
  replacing the hardcoded 8 with FSL_BM_BURST_MAX.  That change is
  in 17/27; this patch has none of it.

Patch 25/27: dpaa_oldev_queues_release() shuts down and rte_free()s
  the Rx and Tx FQs, but never releases them.  Both were created
  with QMAN_FQ_FLAG_DYNAMIC_FQID, so qman_create_fq() allocated an
  FQID and, on 64-bit, a lookup-table entry for each.  Every
  probe/close cycle leaks two of each.  26/27 releases its FQIDs
  after shutdown; do the same here.

Info
----

Patch 01/27: The commit message says "propagate the close status".
  The code logs the dpaa_eth_dev_close() result, then overwrites
  ret with rte_eth_dev_release_port().

Patch 02/27: "num_rx_fqs = 0;" is a dead store.  free_rx reads
  num_rx_fqs only under rx_cgrid_allocated, which is false on this
  path.

Patch 10/27: The commit message says dpaa_sec and the offline port
  now drain on the right portal.  Those callers arrive in 25/27 and
  26/27.

Patch 11/27: qman_release_fqid_range() is exported here, but its
  first user is 26/27.

Patch 15/27: DPAA_1G_MAC_START_IDX and DPAA_2_5G_MAC_START_IDX are
  now unused.

Patch 17/27: RTE_PRIORITY_104 is a driver-local define in the RTE_
  namespace.

Patch 19/27, 20/27: The devarg value is narrowed before the range
  check:

        td_threshold = (unsigned int)td_val;

  so 4294967296 becomes 0 and silently disables taildrop.  The same
  happens with "num_rx_fqs = (int)fmcless_rxq;".  Parse errors are
  also dropped, because callers only test "== 1".  Range-check the
  long first.

Patch 22/27: HI16_OF_U48() and LO32_OF_U48() are moved into
  fsl_bman.h but have no users left.

Patch 25/27: The ioctl error paths log strerror(errno) and then
  return -errno, but the log call can clobber errno.  Save errno
  first.

Pre-existing, not introduced here: in FMCLESS mode net/dpaa never
releases the Rx FQIDs it gets from qman_alloc_fqid_range().  No
DPAA driver calls qman_destroy_fq().

Reply via email to