Re: [PATCH v2 net] octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()
From: Simon Horman
Date: Mon Aug 24 2026 - 09:39:39 EST
On Fri, Aug 21, 2026 at 03:53:37PM +0530, Ratheesh Kannoth wrote:
> From: Sai Krishna <saikrishnag@xxxxxxxxxxx>
>
> rvu_mbox_init() is called separately for AF-PF mailboxes during probe
> and for AF-VF mailboxes when SR-IOV is enabled. Each call used to
> allocate a new ng_rvu object, leaking the first allocation when the
> pointer was overwritten on the second call.
>
> Sharing one ng_rvu across both paths exposed several teardown bugs:
> the error path freed all cn20k mailbox DMA and kfree()d ng_rvu even
> when only the failing init type should be unwound, leaving live AF-PF
> mailbox memory in use after an AF-VF init failure. mutex_init() was
> also re-run on the AF-VF path while AF-PF mailbox handlers could still
> hold rvu->mbox_lock. Probe and SR-IOV failure paths did not release
> cn20k mailbox DMA either, since cleanup only happened in rvu_remove().
>
> Allocate ng_rvu once with devm_kzalloc(), initialize mbox_lock in the
> same block, unwind only the mailbox memory for the failing init type,
> and free cn20k mailbox DMA from the probe and pci_enable_sriov()
> error paths.
>
> Fixes: e53ee4acb220 ("octeontx2-af: CN20k basic mbox operations and structures")
> Signed-off-by: Sai Krishna <saikrishnag@xxxxxxxxxxx>
> Signed-off-by: Ratheesh Kannoth <rkannoth@xxxxxxxxxxx>
>
> ---
> v1 -> v2: Addressed sashiko comments
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260820053656.2614614-1-rkannoth%40marvell.com
Reviewed-by: Simon Horman <horms@xxxxxxxxxx>