RE: [EXTERNAL] [PATCH 2/2] net/mana: fix double free of mbuf on Rx WQE post failure

Long Li <[email protected]>
Newsgroups org.dpdk.dev
Message-ID <SA1PR21MB6683F7326CDBC7A36A660318CED22@SA1PR21MB6683.namprd21.prod.outlook.com>
> mana_post_rx_wqe() frees the mbuf when mana_alloc_pmd_mr() fails, but the
> caller already frees the un-posted range starting at that same mbuf via
> rte_pktmbuf_free_bulk(&mbufs[i], batch_count - i), so the mbuf is returned to
> the mempool twice and can be handed out to two consumers at once.
> 
> The free was correct before the bulk allocation rework, when this function
> allocated the mbuf itself. Now that the caller owns it, leave the mbuf to the
> caller on every error path.
> 
> Fixes: eeb37809601b ("net/mana: use bulk mbuf allocation for Rx WQEs")
> Cc: [email protected]
> Signed-off-by: Rita Ruvinsky <[email protected]>

Reviewed-by: Long Li <[email protected]>


> ---
>  drivers/net/mana/rx.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/mana/rx.c b/drivers/net/mana/rx.c index
> f196d43aee..2bca004dfa 100644
> --- a/drivers/net/mana/rx.c
> +++ b/drivers/net/mana/rx.c
> @@ -68,10 +68,10 @@ mana_post_rx_wqe(struct mana_rxq *rxq, struct
> rte_mbuf *mbuf)
>         int ret;
>         struct mana_mr_cache *mr;
> 
> +       /* Don't free mbuf on error: the caller bulk-frees it from
> + &mbufs[i]. */
>         mr = mana_alloc_pmd_mr(&rxq->mr_btree, priv, mbuf);
>         if (!mr) {
>                 DP_LOG(ERR, "failed to register RX MR");
> -               rte_pktmbuf_free(mbuf);
>                 return -ENOMEM;
>         }
> 
> --
> 2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.