[PATCH rdma-next 3/4] RDMA/mthca: Use unsigned comparison in the CQ cleanup loop

From: Edward Srouji

Date: Tue Sep 15 2026 - 12:03:27 EST


From: Yishai Hadas <yishaih@xxxxxxxxxx>

mthca_cq_clean() sweeps the CQ backwards from the producer index
down to the consumer index:

while ((int) --prod_index - (int) cq->cons_index >= 0)

Both indexes are free running u32 counters, so the comparison has to
be done modulo 2^32. Casting each operand to int and subtracting
does not do that: the subtraction overflows whenever the two indexes
straddle 2^31, which is undefined behaviour, and a compiler that
assumes signed overflow cannot occur is free to discard the
subtraction and fold the expression into a plain signed comparison.
That comparison is not wraparound safe.

The kernel is built with -fno-strict-overflow, so gcc and clang both
retain the subtraction today and the generated code is unaffected;
there is no known user-visible impact from the current code. Still,
correctness here shouldn't depend on that build flag.

Replace the loop with a plain unsigned equality check instead:

while (prod_index != cq->cons_index) {
--prod_index;
...

The preceding forward scan starts prod_index at cons_index and stops no
later than cons_index + cq->ibcq.cqe, so the two indexes are at most
cq->ibcq.cqe apart. Decrementing prod_index reaches cons_index in
exactly that many iterations regardless of whether either counter has
wrapped, because the loop no longer compares magnitudes at all.

Signed-off-by: Yishai Hadas <yishaih@xxxxxxxxxx>
Signed-off-by: Edward Srouji <edwards@xxxxxxxxxx>
---
drivers/infiniband/hw/mthca/mthca_cq.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mthca/mthca_cq.c b/drivers/infiniband/hw/mthca/mthca_cq.c
index 26c3408dcacaea9a0187257cc16de1b90f43fa40..39d4ff15849e7f8c2c3d47b4504306a4a4431c5d 100644
--- a/drivers/infiniband/hw/mthca/mthca_cq.c
+++ b/drivers/infiniband/hw/mthca/mthca_cq.c
@@ -300,7 +300,8 @@ void mthca_cq_clean(struct mthca_dev *dev, struct mthca_cq *cq, u32 qpn,
* Now sweep backwards through the CQ, removing CQ entries
* that match our QP by copying older entries on top of them.
*/
- while ((int) --prod_index - (int) cq->cons_index >= 0) {
+ while (prod_index != cq->cons_index) {
+ --prod_index;
cqe = get_cqe(cq, prod_index & cq->ibcq.cqe);
if (cqe->my_qpn == cpu_to_be32(qpn)) {
if (srq && is_recv_cqe(cqe))

--
2.49.0