From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 2C5E8A0542 for ; Fri, 28 Oct 2022 13:32:31 +0200 (CEST) Received: from [217.70.189.124] (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 1A97540146; Fri, 28 Oct 2022 13:32:31 +0200 (CEST) Received: from EUR03-AM7-obe.outbound.protection.outlook.com (mail-am7eur03on2086.outbound.protection.outlook.com [40.107.105.86]) by mails.dpdk.org (Postfix) with ESMTP id 8FEA8400D5 for ; Fri, 28 Oct 2022 13:32:29 +0200 (CEST) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Dmqa+JoOKCIRtrLveXB2ZaCEx2+5Qz0zxLnZJchL7JyhAA6vfWBpuBI56cZeyJAU4TX5VP++dlyTLqcyqEdA7MXZFM2uO7Magm849aERK3MKaQG85rEBeWFR8JAdn4YpfvmitU4Broloicbw2lJOHWHRDx9N94OdehbBfYgvQguVQntCBei4JghwWFyWal8PguDjyC53aG/IYSeLc8ObHGftnDk+NopUh6/qL1BgTRTRzB/oMuQggTneyRz1s3cVWYxIMDwew5Br2vufifpYO89x/xjy+V8thH6lumIArIjiGmDZK4PUH+DrVBoegyDygxA9ipK8eowwayKGQm6oPQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=S2BiHdLOPPCyTH2VvjeLG1Yi/BpspUTONCdZEy8N4K8=; b=e0top4zxPQCPrn9Z9LgsVRp9Cyh3enX/lLbQoFEvOEXOHe8Y+7cltpcA+zel2LtKqeTJq3rg+sS2/FEAufSCPQdiZ0R37uyaLxvxrQKpmGDEM2K/1zH89AhQFsbGAXEprZZKOvpkmrbz7B+lV0H6TKhzZK7IvThqEM8hhQfdKY4lmK9JNwuVUl4RzZZY8FTZSfsvTdO/4duVBDjcS/D50dA8ADkV96E/7r4JKd+h3AFyJ332sdy/pyDmF1Ru7kKpJyT9KhPosmJBQrWGC92pQeohSDFIF05qLlFUSjXur89Z155cnJdUHS2BkMT6YnudqhgNvi8wILMt13uwvhsZPQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nxp.com; dmarc=pass action=none header.from=nxp.com; dkim=pass header.d=nxp.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nxp.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=S2BiHdLOPPCyTH2VvjeLG1Yi/BpspUTONCdZEy8N4K8=; b=sDhZmodHtX7kMflKPEiXth001220nnm2i/ry/xJWvmQ8dfRpijemwnOgdZuC8EFr4Kb1pg0G0YZ1fGhAfxx6ERxjYLlvhwTilMTlpUV0PxMMsx8AUKphLJu1FLlDQuB1v5QtTSr7GS/QkMwod7CupE86HuKIj2e+IIJEHXjKJqU= Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nxp.com; Received: from AS8PR04MB8198.eurprd04.prod.outlook.com (2603:10a6:20b:3b0::14) by AS8PR04MB8532.eurprd04.prod.outlook.com (2603:10a6:20b:423::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5769.15; Fri, 28 Oct 2022 11:32:28 +0000 Received: from AS8PR04MB8198.eurprd04.prod.outlook.com ([fe80::d0b5:8ee9:ca90:2e49]) by AS8PR04MB8198.eurprd04.prod.outlook.com ([fe80::d0b5:8ee9:ca90:2e49%5]) with mapi id 15.20.5769.014; Fri, 28 Oct 2022 11:32:28 +0000 From: Gagandeep Singh To: ktraynor@redhat.com, stable@dpdk.org Cc: Gagandeep Singh , Hemant Agrawal Subject: [PATCH 21.11 2/4] net/dpaa: fix buffer freeing on SG Tx Date: Fri, 28 Oct 2022 17:02:03 +0530 Message-Id: <20221028113205.2349198-2-g.singh@nxp.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20221028113205.2349198-1-g.singh@nxp.com> References: <20221028113205.2349198-1-g.singh@nxp.com> Content-Transfer-Encoding: 8bit Content-Type: text/plain X-ClientProxiedBy: SI2PR04CA0010.apcprd04.prod.outlook.com (2603:1096:4:197::11) To AS8PR04MB8198.eurprd04.prod.outlook.com (2603:10a6:20b:3b0::14) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR04MB8198:EE_|AS8PR04MB8532:EE_ X-MS-Office365-Filtering-Correlation-Id: 1deaa642-29cd-46a3-cf8b-08dab8d81823 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: H76z8JexzPSwWGcmye+55AqmvuYsqJx7kVUJpQlOYPoHuipCLU/MG5ppwb9dQ6lOxwtPEwGPdUVROkwtDFHG2PB5zBCG+Ike0uJr7yn7h7ZH0L0JMpag8RNiqfT/c9k7cymi7L5yv9QHZ1oL8HBMhjl2HkBDQLgpnQS9hKAbnNCbvy3GXWEvKM+qCksaGZhIRLKbcLlofWF/FKd8l3uRooRkTu4GbEDVWpCbRgzDBomWzzoLv/OMHiS7eS6vWkpo7sDENmNxzrri1wYYGakBVp8WTGE/mLiasxSmPc6oBVZLcPmK6GM97j8st0nA+wsNhNP3XFERqBEMb6Hx5op/d/4236Bu0pFDn/V5nq02/28OOzPWiBTI8rwNUCuPJm0vswc6fueK8VCS0PfW8nxIh5C2n7CTsOgnh/h2QyShER6KMlyKJn+8165T2z+Jl+Vll+ZLEPFi6R1XLLWvk6K74J3oMC7ibBfpO3nW/jn0O/+RWKbQcsD46z8odpkfuClkXOaEmrYskwzksBTq+/QsOhpnP3Ij+4M/KBEmggekvbKGzyHtHas2x5orxIcDUsqucrBapZYgnKx0o9opkhBiXjehpB0Bny40+X3VSUXhyA3lBBE3YQ3hHT3aZkqlr3LZrNausvB1hHkkhplBjOTFkU3tWUXOl1mHUo2pnJ4WH5AQcQhC772pUOieWsYi9sJUu7UCFCnEFwwDuIqoKIJ2KTjRgQVKOM3ozCwlfQ/M6LF+6pkgFJGGVVIoxZZg71pvtcPq3PJ3vStC10tmYDKcnw== X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:AS8PR04MB8198.eurprd04.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(136003)(366004)(396003)(39860400002)(346002)(376002)(451199015)(83380400001)(86362001)(38350700002)(38100700002)(2906002)(5660300002)(66946007)(4326008)(66556008)(66476007)(8676002)(41300700001)(8936002)(6506007)(52116002)(6666004)(1076003)(26005)(2616005)(186003)(6512007)(316002)(54906003)(6486002)(478600001)(36756003); DIR:OUT; SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?Ra9lbqoM30LThmmTmGVpqSn+bIOnhfMBOfGk2NUslzqoccJULdtGJCHleH4U?= =?us-ascii?Q?8x9R0v1xSSGr5gPwUd+RKMp4mtaO5hmRoIQynSTHSEIszjB+FiLHoZ7KZtBN?= =?us-ascii?Q?TU1rfdhAo6hXhIJ1AYiOObTAgtxJ02K9pdI/iFYWlZV9ut9HGbLwTHcGT8IJ?= =?us-ascii?Q?Aq2uuVxdlGNiDhHwlMfMAnvL4yKhyItV5aX49/1kIBqfXOIQf9KSBqHH/8gM?= =?us-ascii?Q?nn+cxCZlYhi7heGIO0x1+S0Mss9gEddvH3xDfywBOT5S3AWb5LgLdSjb9dwe?= =?us-ascii?Q?0NCKJFD/bw1Luk7mjs3V2i0MSVtyXL4sfLEYzWVSQdJIc3ul+kfMpjzZX4VR?= =?us-ascii?Q?4MP45MmWAKulOoZ7WtDtRCeVUOnFCVevFJDPu+tNddx8rrcQ5i16cJC6IKFG?= =?us-ascii?Q?4DP4pLSwsg0BPQl37jrt2e7QpKU5PnlkQW3MQ6b7C97uZi82ZFQgd2iVga5R?= =?us-ascii?Q?IC05i86G8bwpZu7TfgkpvWtsnWYqwPvOazuIUgJ3a0ihjjc3Uq4/SnXk51i4?= =?us-ascii?Q?guBXxWK9Z5PiBFMtS3TjdOOVZmlbMkq3HlZ9UCW60JXba2Goa9LS9BhvpLLX?= =?us-ascii?Q?8vIXTbyM66DWtr2DjuOUuKevXnY8caYOaHF28D9BbilcIevfnJzPuvFFgqTg?= =?us-ascii?Q?oZNv+g/nJ6uTAINX6fOWusSOJWVuxGDuqs147glOqT58h382LQm1X3DGeVq8?= =?us-ascii?Q?TgOoJEYrp4SI1GksMrohzKXs3IwjFiXaWUkn3lbElzt7JBx4mZflI0bt+tzH?= =?us-ascii?Q?4KlVnImsosUVEPS2mCtjatv0kFJLTIqksWMV6zbuQVzN+RXaFD9iMhiot2on?= =?us-ascii?Q?ND4h8qTP7QheOyrbCS1tcqQKBze+rjazJJepmeGYXLyeLCGhF7fsulRObvHt?= =?us-ascii?Q?pRlJpUa7TLisvhV4cP769CeQwVM/xvXuL8dIzu041SP/g7eaJpA3LUwlTglg?= =?us-ascii?Q?MK3utz4/eY0FRhgzrIr0rtvVBRSDVSAvZ1Dwb/dDKTBXnhZ4iI4ITN0TLDcW?= =?us-ascii?Q?Acr97DnFxaLNSI2CLepmOyy1QrYXNH4jHoLkXNzp8lic7gADL8we4IbLioDl?= =?us-ascii?Q?OxsMGHskoVUZTYvhCfpcxD+MArDJrOnrthrfAwv6EM5yOCG1obGWZM8rW5h0?= =?us-ascii?Q?qjHX4i9Uv+xYtCgYd0mz8yfn7urDtebeG2JLwuDif97fHbyNzySeDfM03wLj?= =?us-ascii?Q?2KlRt0p62yYqSsvom3sgwxnXgUGrSmS8+fVe0RwME4HD5s94crCsg/B9QBIs?= =?us-ascii?Q?wEjNL6AIqW7PCFxrJq8UQehUAzzG+8KOZVUfNA0a6DXYD1aZLhpoq347Fr7Z?= =?us-ascii?Q?IoKzMrRA+0wGnQhbXWKPYZodAko3m+Jw2YRJq12LAh3T0qQ2RTNkGSU03wOE?= =?us-ascii?Q?9iS5HOZfQP0Qom2uETyQMGLBHg7KOfE0x4OFlfTFlp91VQRMKTdQKohRPqvX?= =?us-ascii?Q?qkfPKlpFdJvBDSaSDjqLA+ewsiCcY75pbY13gCdtbIe4sdCGMUYBsxk7s5GX?= =?us-ascii?Q?82Clkj3kX5ttOixq514TIepgAKyqsdQj/AveOVNa/UDBBTFiU8EZG0ucD8VF?= =?us-ascii?Q?0axKs0vnyLaByUrreNBBP1LTc9dvDI5y3l5N1ksx?= X-OriginatorOrg: nxp.com X-MS-Exchange-CrossTenant-Network-Message-Id: 1deaa642-29cd-46a3-cf8b-08dab8d81823 X-MS-Exchange-CrossTenant-AuthSource: AS8PR04MB8198.eurprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 28 Oct 2022 11:32:28.5511 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 686ea1d3-bc2b-4c6f-a92c-d99c5c301635 X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: eAdJ6mlAbTtFUdnDuJP9xOK7BrN+UaVvOccvscjkoG8Mj6nd8YQJY/m01LM2sfMo X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR04MB8532 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org [ upstream commit 8716c0ec06e2bb58273184ebfa9f951565fa9ce2 ] When using SG list to TX with external and direct buffers, HW free direct buffers and driver free external buffers. Software scans the complete SG mbuf list to find the external buffers to free, but this is wrong as hardware can free the direct buffers if any present in the list and same can be re-allocated for other purpose in multi thread or high speed running traffic environment with new data in it. So the software which is scanning the SG mbuf list, if that list has any direct buffer present then that direct buffer's next pointer can give wrong pointer value, if already freed by hardware which can do the mempool corruption or memory leak. In this patch instead of relying on user given SG mbuf list we are storing the buffers in an internal list which will be scanned by driver after transmit to free non-direct buffers. This patch also fixes below issues. Driver is freeing complete SG list by checking external buffer flag in first segment only, but external buffer can be attached to any of the segment. Because of this, driver either can double free buffers or there can be memory leak. In case of indirect buffers, driver is modifying the original buffer list to free the indirect buffers but this original buffer list is being used by driver even after transmit packets for non-direct buffer cleanup. This can cause the buffer leak issue. Fixes: f191d5abda54 ("net/dpaa: support external buffers in Tx") Signed-off-by: Gagandeep Singh Acked-by: Hemant Agrawal --- drivers/net/dpaa/dpaa_ethdev.h | 10 ++++++ drivers/net/dpaa/dpaa_rxtx.c | 61 ++++++++++++++++++++++------------ 2 files changed, 49 insertions(+), 22 deletions(-) diff --git a/drivers/net/dpaa/dpaa_ethdev.h b/drivers/net/dpaa/dpaa_ethdev.h index f9c0554530..502c1c88b8 100644 --- a/drivers/net/dpaa/dpaa_ethdev.h +++ b/drivers/net/dpaa/dpaa_ethdev.h @@ -112,6 +112,16 @@ extern struct rte_mempool *dpaa_tx_sg_pool; +/* structure to free external and indirect + * buffers. + */ +struct dpaa_sw_buf_free { + /* To which packet this segment belongs */ + uint16_t pkt_id; + /* The actual segment */ + struct rte_mbuf *seg; +}; + /* Each network interface is represented by one of these */ struct dpaa_if { int valid; diff --git a/drivers/net/dpaa/dpaa_rxtx.c b/drivers/net/dpaa/dpaa_rxtx.c index e0aa268645..d06e128338 100644 --- a/drivers/net/dpaa/dpaa_rxtx.c +++ b/drivers/net/dpaa/dpaa_rxtx.c @@ -793,9 +793,12 @@ uint16_t dpaa_eth_queue_rx(void *q, static int dpaa_eth_mbuf_to_sg_fd(struct rte_mbuf *mbuf, - struct qm_fd *fd) + struct qm_fd *fd, + struct dpaa_sw_buf_free *free_buf, + uint32_t *free_count, + uint32_t pkt_id) { - struct rte_mbuf *cur_seg = mbuf, *prev_seg = NULL; + struct rte_mbuf *cur_seg = mbuf; struct rte_mbuf *temp, *mi; struct qm_sg_entry *sg_temp, *sgt; int i = 0; @@ -859,10 +862,11 @@ dpaa_eth_mbuf_to_sg_fd(struct rte_mbuf *mbuf, sg_temp->bpid = DPAA_MEMPOOL_TO_BPID(cur_seg->pool); } - cur_seg = cur_seg->next; } else if (RTE_MBUF_HAS_EXTBUF(cur_seg)) { + free_buf[*free_count].seg = cur_seg; + free_buf[*free_count].pkt_id = pkt_id; + ++*free_count; sg_temp->bpid = 0xff; - cur_seg = cur_seg->next; } else { /* Get owner MBUF from indirect buffer */ mi = rte_mbuf_from_indirect(cur_seg); @@ -875,11 +879,11 @@ dpaa_eth_mbuf_to_sg_fd(struct rte_mbuf *mbuf, sg_temp->bpid = DPAA_MEMPOOL_TO_BPID(mi->pool); rte_mbuf_refcnt_update(mi, 1); } - prev_seg = cur_seg; - cur_seg = cur_seg->next; - prev_seg->next = NULL; - rte_pktmbuf_free(prev_seg); + free_buf[*free_count].seg = cur_seg; + free_buf[*free_count].pkt_id = pkt_id; + ++*free_count; } + cur_seg = cur_seg->next; if (cur_seg == NULL) { sg_temp->final = 1; cpu_to_hw_sg(sg_temp); @@ -894,7 +898,10 @@ dpaa_eth_mbuf_to_sg_fd(struct rte_mbuf *mbuf, static inline void tx_on_dpaa_pool_unsegmented(struct rte_mbuf *mbuf, struct dpaa_bp_info *bp_info, - struct qm_fd *fd_arr) + struct qm_fd *fd_arr, + struct dpaa_sw_buf_free *buf_to_free, + uint32_t *free_count, + uint32_t pkt_id) { struct rte_mbuf *mi = NULL; @@ -913,6 +920,9 @@ tx_on_dpaa_pool_unsegmented(struct rte_mbuf *mbuf, DPAA_MBUF_TO_CONTIG_FD(mbuf, fd_arr, bp_info->bpid); } } else if (RTE_MBUF_HAS_EXTBUF(mbuf)) { + buf_to_free[*free_count].seg = mbuf; + buf_to_free[*free_count].pkt_id = pkt_id; + ++*free_count; DPAA_MBUF_TO_CONTIG_FD(mbuf, fd_arr, bp_info ? bp_info->bpid : 0xff); } else { @@ -936,7 +946,9 @@ tx_on_dpaa_pool_unsegmented(struct rte_mbuf *mbuf, DPAA_MBUF_TO_CONTIG_FD(mbuf, fd_arr, bp_info ? bp_info->bpid : 0xff); } - rte_pktmbuf_free(mbuf); + buf_to_free[*free_count].seg = mbuf; + buf_to_free[*free_count].pkt_id = pkt_id; + ++*free_count; } if (mbuf->ol_flags & DPAA_TX_CKSUM_OFFLOAD_MASK) @@ -947,16 +959,21 @@ tx_on_dpaa_pool_unsegmented(struct rte_mbuf *mbuf, static inline uint16_t tx_on_dpaa_pool(struct rte_mbuf *mbuf, struct dpaa_bp_info *bp_info, - struct qm_fd *fd_arr) + struct qm_fd *fd_arr, + struct dpaa_sw_buf_free *buf_to_free, + uint32_t *free_count, + uint32_t pkt_id) { DPAA_DP_LOG(DEBUG, "BMAN offloaded buffer, mbuf: %p", mbuf); if (mbuf->nb_segs == 1) { /* Case for non-segmented buffers */ - tx_on_dpaa_pool_unsegmented(mbuf, bp_info, fd_arr); + tx_on_dpaa_pool_unsegmented(mbuf, bp_info, fd_arr, + buf_to_free, free_count, pkt_id); } else if (mbuf->nb_segs > 1 && mbuf->nb_segs <= DPAA_SGT_MAX_ENTRIES) { - if (dpaa_eth_mbuf_to_sg_fd(mbuf, fd_arr)) { + if (dpaa_eth_mbuf_to_sg_fd(mbuf, fd_arr, buf_to_free, + free_count, pkt_id)) { DPAA_PMD_DEBUG("Unable to create Scatter Gather FD"); return 1; } @@ -1060,7 +1077,8 @@ dpaa_eth_queue_tx(void *q, struct rte_mbuf **bufs, uint16_t nb_bufs) uint16_t state; int ret, realloc_mbuf = 0; uint32_t seqn, index, flags[DPAA_TX_BURST_SIZE] = {0}; - struct rte_mbuf **orig_bufs = bufs; + struct dpaa_sw_buf_free buf_to_free[DPAA_MAX_SGS * DPAA_MAX_DEQUEUE_NUM_FRAMES]; + uint32_t free_count = 0; if (unlikely(!DPAA_PER_LCORE_PORTAL)) { ret = rte_dpaa_portal_init((void *)0); @@ -1143,7 +1161,10 @@ dpaa_eth_queue_tx(void *q, struct rte_mbuf **bufs, uint16_t nb_bufs) } indirect_buf: state = tx_on_dpaa_pool(mbuf, bp_info, - &fd_arr[loop]); + &fd_arr[loop], + buf_to_free, + &free_count, + loop); if (unlikely(state)) { /* Set frames_to_send & nb_bufs so * that packets are transmitted till @@ -1168,13 +1189,9 @@ dpaa_eth_queue_tx(void *q, struct rte_mbuf **bufs, uint16_t nb_bufs) DPAA_DP_LOG(DEBUG, "Transmitted %d buffers on queue: %p", sent, q); - - loop = 0; - while (loop < sent) { - if (unlikely(RTE_MBUF_HAS_EXTBUF(*orig_bufs))) - rte_pktmbuf_free(*orig_bufs); - orig_bufs++; - loop++; + for (loop = 0; loop < free_count; loop++) { + if (buf_to_free[loop].pkt_id < sent) + rte_pktmbuf_free_seg(buf_to_free[loop].seg); } return sent; -- 2.25.1