On Mon, Sep 21, 2026 at 08:50:07PM -0400, Jaidev Shastri via B4 Relay wrote:
> [You don't often get email from [email protected]. 
> Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
> 
> From: Jaidev Shastri <[email protected]>
> 
> dpaa2_io_create() adds the new object to dpio_list and dpio_by_cpu[]
> under dpio_list_lock, but service_select_by_cpu() reads dpio_by_cpu[]
> without the lock on behalf of dpaa2_io_service_select() and
> dpaa2_io_service_register().
> 
> obj->dev is assigned after the lock is dropped, so a reader can pick the
> object up and pass a NULL supplier to device_link_add(), which fails
> with -EINVAL and fails the consumer's probe. The publication is a plain
> store, so a reader that does not take the lock is also not ordered
> against the stores that set obj->swp, the notification list and the
> object's spinlocks.
> 
> dpaa2-eth probes from the deferred probe worker and retries whenever
> another device binds, so it runs while the remaining DPIO objects are
> still being created on multi-core LS2 and LX2 parts.
> 
> Finish the object before publishing it and store dpio_by_cpu[] with
> smp_store_release(), paired with smp_load_acquire() in
> service_select_by_cpu(). service_select() takes the lock and is
> unchanged.
> 
> Found with MBCheck, a static herd7-based memory consistency checker.
> 
> Signed-off-by: Jaidev Shastri <[email protected]>

Could you please amend the commit message so that you incorporate
Jaidev's feedback and submit a v2?

With that,

Reviewed-by: Ioana Ciornei <[email protected]>

Reply via email to