From: Koichiro Den <den@valinux.co.jp>
To: Jon Mason <jdmason@kudzu.us>, Dave Jiang <dave.jiang@intel.com>,
Allen Hubbe <allenbh@gmail.com>, Frank Li <Frank.Li@kernel.org>,
Logan Gunthorpe <logang@deltatee.com>
Cc: fuyuanli <fuyuanli0722@gmail.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Nicholas Bellinger <nab@linux-iscsi.org>,
Joey Zhang <joey.zhang@microchip.com>,
ntb@lists.linux.dev, linux-kernel@vger.kernel.org,
stable@vger.kernel.org
Subject: [PATCH v3 06/15] NTB: ntb_transport: Avoid losing QP link-up requests
Date: Tue, 29 Sep 2026 00:25:41 +0900 [thread overview]
Message-ID: <20260928152550.3354675-7-den@valinux.co.jp> (raw)
In-Reply-To: <20260928152550.3354675-1-den@valinux.co.jp>
ntb_netdev_open() can call ntb_transport_link_up() while the transport
worker is completing setup on another CPU. Concurrent transport setup
and a client link-up request can both read the other's flag as false and
leave QP link work unqueued. The QP then stays down until another link
event or client link-up request.
This is the store-buffering pattern described in
tools/memory-model/Documentation/recipes.txt ("Store buffering").
Add a full barrier between the store and load on each side.
Fixes: fce8a7bb5b4b ("PCI-Express Non-Transparent Bridge Support")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://lore.kernel.org/r/20260907144701.702E41F00A3A@smtp.kernel.org/
Signed-off-by: Koichiro Den <den@valinux.co.jp>
---
Changes in v3:
- Drop the *_ONCE changes. client_ready is now atomic_t.
v2: https://lore.kernel.org/r/20260910040836.3792333-6-den@valinux.co.jp/
drivers/ntb/ntb_transport.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
index 51d9e9969065..d290e5869c21 100644
--- a/drivers/ntb/ntb_transport.c
+++ b/drivers/ntb/ntb_transport.c
@@ -1101,6 +1101,12 @@ static void ntb_transport_link_work(struct work_struct *work)
/* Publish the link only after every QP has been set up. */
atomic_set_release(&nt->link_is_up, true);
+ /*
+ * Prevent both sides from missing each other's flag. Pairs with
+ * the barrier in ntb_transport_link_up().
+ */
+ smp_mb();
+
for (i = 0; i < nt->qp_count; i++) {
struct ntb_transport_qp *qp = &nt->qp_vec[i];
@@ -2400,6 +2406,9 @@ void ntb_transport_link_up(struct ntb_transport_qp *qp)
atomic_set(&qp->client_ready, true);
+ /* Pairs with the barrier in ntb_transport_link_work(). */
+ smp_mb();
+
ntb_transport_schedule_qp_link(qp, 0);
}
EXPORT_SYMBOL_GPL(ntb_transport_link_up);
--
2.51.0
next prev parent reply other threads:[~2026-09-28 15:26 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 15:25 [PATCH v3 00/15] NTB: ntb_transport: Miscellaneous fixes Koichiro Den
2026-09-28 15:25 ` [PATCH v3 01/15] NTB: ntb_transport: Remove the device debugfs directory Koichiro Den
2026-09-28 15:25 ` [PATCH v3 02/15] NTB: ntb_transport: Start TX offload thread after queue setup Koichiro Den
2026-09-28 15:25 ` [PATCH v3 03/15] NTB: ntb_transport: Make link setup flags atomic Koichiro Den
2026-09-28 15:53 ` Logan Gunthorpe
2026-09-28 15:25 ` [PATCH v3 04/15] NTB: ntb_transport: Avoid deadlock when cancelling link work Koichiro Den
2026-09-28 15:25 ` [PATCH v3 05/15] NTB: ntb_transport: Publish link state after QP setup Koichiro Den
2026-09-28 15:25 ` Koichiro Den [this message]
2026-09-28 16:57 ` [PATCH v3 06/15] NTB: ntb_transport: Avoid losing QP link-up requests Logan Gunthorpe
2026-09-29 1:43 ` Koichiro Den
2026-09-28 15:25 ` [PATCH v3 07/15] NTB: ntb_transport: Clear link state before QP cleanup Koichiro Den
2026-09-28 15:25 ` [PATCH v3 08/15] NTB: ntb_transport: Stop QP work before freeing a queue Koichiro Den
2026-09-28 15:25 ` [PATCH v3 09/15] NTB: ntb_transport: Stop RX tasklet scheduling " Koichiro Den
2026-09-28 15:25 ` [PATCH v3 10/15] NTB: ntb_transport: Drain RX tasklets during link cleanup Koichiro Den
2026-09-28 15:25 ` [PATCH v3 11/15] NTB: ntb_transport: Wait for RX completions before resetting a QP Koichiro Den
2026-09-28 15:25 ` [PATCH v3 12/15] NTB: ntb_transport: Prepare remote RX info accesses for MW teardown Koichiro Den
2026-09-28 15:25 ` [PATCH v3 13/15] NTB: ntb_transport: Clear QP pointers when freeing an MW Koichiro Den
2026-09-28 15:25 ` [PATCH v3 14/15] NTB: ntb_transport: Abort link setup on QP MW allocation failure Koichiro Den
2026-09-28 15:25 ` [PATCH v3 15/15] NTB: ntb_transport: Remove clients before freeing transport resources Koichiro Den
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928152550.3354675-7-den@valinux.co.jp \
--to=den@valinux.co.jp \
--cc=Frank.Li@kernel.org \
--cc=allenbh@gmail.com \
--cc=dave.jiang@intel.com \
--cc=fuyuanli0722@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=jdmason@kudzu.us \
--cc=joey.zhang@microchip.com \
--cc=linux-kernel@vger.kernel.org \
--cc=logang@deltatee.com \
--cc=nab@linux-iscsi.org \
--cc=ntb@lists.linux.dev \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®