Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] net: mana: Use-After-Free of CQ during queue teardown due to missing RCU grace period --
commit 50d2c3c4bc7f5e569d234a68a7842e4c466d0022 Author: Long Li <[email protected]> net: mana: prepare HWC ownership for safe reinitialization Dynamic HWC queue sizing tears down the bootstrap queues and establishes a second channel before publishing it. Prepare the existing HWC ownership and teardown paths so that sequence cannot free or reuse state still reachable by either the PF or an EQ handler. Link: https://lore.kernel.org/r/[email protected] Link: https://lore.kernel.org/r/[email protected] Link: https://lore.kernel.org/r/[email protected] > diff --git a/drivers/net/ethernet/microsoft/mana/gdma_main.c > b/drivers/net/ethernet/microsoft/mana/gdma_main.c > index 8e9bfc1d6a2ae..f63e236d4d190 100644 > --- a/drivers/net/ethernet/microsoft/mana/gdma_main.c > +++ b/drivers/net/ethernet/microsoft/mana/gdma_main.c [ ... ] > @@ -922,11 +923,16 @@ static void mana_gd_process_eqe(struct gdma_queue *eq) > switch (type) { > case GDMA_EQE_COMPLETION: > cq_id = eqe->details[0] & 0xFFFFFF; > - if (WARN_ON_ONCE(cq_id >= gc->max_num_cqs)) > + /* The IRQ handler's RCU read-side section protects the table > + * until HWC teardown has fenced its EQ and waited for readers. > + */ > + cq_table = smp_load_acquire(&gc->cq_table); > + if (!cq_table || cq_id >= READ_ONCE(gc->max_num_cqs)) > break; > > - cq = gc->cq_table[cq_id]; > - if (WARN_ON_ONCE(!cq || cq->type != GDMA_CQ || cq->id != cq_id)) > + cq = READ_ONCE(cq_table[cq_id]); > + if (!cq || WARN_ON_ONCE(cq->type != GDMA_CQ || > + cq->id != cq_id)) [Severity: High] Can this dereference of cq race with mana_gd_destroy_queue() and cause a use-after-free? When the network device is detached (e.g., driver unload or suspend), mana_dealloc_queues() destroys Ethernet CQs via mana_destroy_rxqs() and mana_destroy_txq() before destroying the Ethernet EQs via mana_destroy_eq(). Because the Ethernet EQ handler is still active, its IRQ handler (mana_gd_process_eqe()) can run concurrently. Inside the RCU read-side critical section, mana_gd_process_eqe() reads the CQ pointer from cq_table. If the pointer is read just before it is unpublished, the subsequent cq->type dereference will access memory that is immediately freed by mana_gd_destroy_queue(): drivers/net/ethernet/microsoft/mana/gdma_main.c:mana_gd_destroy_queue() { ... mana_gd_free_memory(gmi); kfree(queue); } The kfree(queue) here doesn't wait for an RCU grace period (via synchronize_rcu() or kfree_rcu()), allowing the active EQ handler to access freed memory. > break; > > if (cq->cq.callback) -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
