On Mon, 5 Oct 2026 14:23:10 +0530
Hemant Agrawal <[email protected]> wrote:
> This series collects a set of fixes and enhancements for the NXP DPAA
> bus, mempool, dma, crypto and net drivers targeting 26.11.
>
> It includes memory-leak and resource-cleanup fixes on the device
> remove/close paths, more robust frame queue and congestion-group
> shutdown, secondary-process safety guards, BPID and cgrid lifecycle
> handling, and several new features: offline (O/H) port device support,
> enhanced virtual storage profile (VSP) port support, fmcless Rx queue
> configuration via devargs, Rx/Tx taildrop threshold devargs, non
> fmX-macY shared Ethernet naming, and DMA scatter-gather and
> errata-workaround devargs. Documentation and release notes are updated
> accordingly.
>
> v20:
> * net/dpaa: propagate the dpaa_port_fmc_init() error instead of
> returning success with no Rx queues, as a separate fix with a
> Fixes tag so it can be backported.
> * drivers: drop the unused rte_dpaa_bus_oldev_enabled() and add
> rte_pmd_dpaa_oldev.h to doc/api/doxy-api-index.md.
> * drivers: use qman_pending_fq_by_cgrid_range() over the whole Rx
> and Tx CGRID range, so a port close costs two FQID space scans
> rather than one per congestion group.
> * doc: name the new experimental offline port functions in the
> release notes, document that drv_oldev switches the bus to
> allowlist mode, and log an over-long drv_sh_if_name.
>
Still lots more AI comments. As always, AI is not always right!
Error
-----
Patch 11/27: free_rx/free_tx can crash on a CGR that was never
created. If qman_create_cgr() fails in dpaa_rx_queue_init(), it
goes to without_cgr and can still return 0. The caller then
counts the CGR anyway:
if (dpaa_intf->cgr_rx)
nb_rx_cgr++;
A later probe failure calls qman_delete_cgr() on it.
qman_create_cgr() set cgr->chan before failing, so the channel
check passes, and list_del(&cgr->node) runs on a node zeroed by
rte_zmalloc():
(i)->next->prev = (i)->prev;
next is NULL. dpaa_tx_queue_init() has the same shape. Return
the qman_create_cgr() failure, or report back to the caller
whether the CGR was created.
Warning
-------
Patch 04/27: The commit message says the tx_conf_queues leak is
fixed for every probe failure after the allocation, but three
such paths still jump past it. The tx_conf_queues, cgr_tx and Tx
qman_alloc_cgrid_range() failures all do "goto free_rx", and
free_rx frees neither tx_queues nor tx_conf_queues. Make them
goto free_tx; nb_tx_cgr is 0 and tx_cgrid_allocated is false at
those points.
Patch 12/27: The second paragraph of the commit message, and the
new comment in qman_shutdown_fq(), describe dropping an "old
affinity check" against p->config->channel. The function this
patch modifies has no such check. Remove both.
Patch 18/27: The commit message says dma_pool_alloc() now accepts
a NULL phy_addr. The patch does not touch it, and it still does:
*phy_addr = rte_mem_virt2iova(virt_addr);
Patch 22/27: The first paragraph of the commit message describes
replacing the hardcoded 8 with FSL_BM_BURST_MAX. That change is
in 17/27; this patch has none of it.
Patch 25/27: dpaa_oldev_queues_release() shuts down and rte_free()s
the Rx and Tx FQs, but never releases them. Both were created
with QMAN_FQ_FLAG_DYNAMIC_FQID, so qman_create_fq() allocated an
FQID and, on 64-bit, a lookup-table entry for each. Every
probe/close cycle leaks two of each. 26/27 releases its FQIDs
after shutdown; do the same here.
Info
----
Patch 01/27: The commit message says "propagate the close status".
The code logs the dpaa_eth_dev_close() result, then overwrites
ret with rte_eth_dev_release_port().
Patch 02/27: "num_rx_fqs = 0;" is a dead store. free_rx reads
num_rx_fqs only under rx_cgrid_allocated, which is false on this
path.
Patch 10/27: The commit message says dpaa_sec and the offline port
now drain on the right portal. Those callers arrive in 25/27 and
26/27.
Patch 11/27: qman_release_fqid_range() is exported here, but its
first user is 26/27.
Patch 15/27: DPAA_1G_MAC_START_IDX and DPAA_2_5G_MAC_START_IDX are
now unused.
Patch 17/27: RTE_PRIORITY_104 is a driver-local define in the RTE_
namespace.
Patch 19/27, 20/27: The devarg value is narrowed before the range
check:
td_threshold = (unsigned int)td_val;
so 4294967296 becomes 0 and silently disables taildrop. The same
happens with "num_rx_fqs = (int)fmcless_rxq;". Parse errors are
also dropped, because callers only test "== 1". Range-check the
long first.
Patch 22/27: HI16_OF_U48() and LO32_OF_U48() are moved into
fsl_bman.h but have no users left.
Patch 25/27: The ioctl error paths log strerror(errno) and then
return -errno, but the log call can clobber errno. Save errno
first.
Pre-existing, not introduced here: in FMCLESS mode net/dpaa never
releases the Rx FQIDs it gets from qman_alloc_fqid_range(). No
DPAA driver calls qman_destroy_fq().