[PATCH net-next v5 16/19] xsk: allow drivers to retain DMA mappings independently of pools

From: James Hilliard

Date: Sun Sep 27 2026 - 18:04:50 EST


An unsuccessful device shutdown does not make its DMA memory safe to
unmap. AF_XDP pool removal must nevertheless complete: the last socket
release invokes the driver detach callback and then destroys the pool,
regardless of the callback's return value.

Provide an independent reference to the existing DMA mapping and its
UMEM pages. A driver can take it while installing rings and release it
after DMA has actually stopped. Retain the pool and buffer-head storage
separately from the pool users reference which triggers teardown. This
lets a driver keep DMA-owned frames out of the reusable free list even
after socket teardown has released its fill and completion rings.

Return retained buffers only after DMA shutdown, before dropping the DMA
reference. Keeping pages pinned alone does not prevent an active pool
from recycling a frame still reachable by hardware. The retained metadata
does not permit other pool operations after detach.

Keep the DMA device and the mapping's netdev lookup key allocated,
without taking a netdev usage reference that would prevent unregister.
Save the mapping attributes and unmap before dropping the last retained
UMEM reference. Mapping reference operations are serialized by RTNL,
like the existing mapping list operations.

Signed-off-by: James Hilliard <james.hilliard1@xxxxxxxxx>
---
Changes in v5:
- Retain pool/head storage independently of socket users so DMA-owned
frames need not be returned to the free list during pool removal.
- Keep the saved mapping in a separate reference object, since detach
clears the pool's device and DMA lookup state.
---
include/net/xdp_sock_drv.h | 25 +++++++++++++++++
include/net/xsk_buff_pool.h | 7 +++++
net/xdp/xsk_buff_pool.c | 67 +++++++++++++++++++++++++++++++++++++++++++--
3 files changed, 96 insertions(+), 3 deletions(-)

diff --git a/include/net/xdp_sock_drv.h b/include/net/xdp_sock_drv.h
index d94aeb506379..a39768b1c00f 100644
--- a/include/net/xdp_sock_drv.h
+++ b/include/net/xdp_sock_drv.h
@@ -95,6 +95,22 @@ static inline void xsk_pool_dma_unmap(struct xsk_buff_pool *pool,
xp_dma_unmap(pool, attrs);
}

+/* RTNL must be held. Retain mappings, pages and buffer metadata without
+ * postponing the socket's detach callback. Do not return DMA-owned buffers
+ * with xsk_buff_free() until hardware has stopped, even after pool removal.
+ * Afterwards, free those buffers before putting the reference. This does not
+ * retain the FILL/COMPLETION rings or allow other pool operations after detach.
+ */
+static inline struct xsk_dma_ref *xsk_pool_dma_get(struct xsk_buff_pool *pool)
+{
+ return xp_dma_get(pool);
+}
+
+static inline void xsk_pool_dma_put(struct xsk_dma_ref *ref)
+{
+ xp_dma_put(ref);
+}
+
static inline int xsk_pool_dma_map(struct xsk_buff_pool *pool,
struct device *dev, unsigned long attrs)
{
@@ -432,6 +448,15 @@ static inline void xsk_pool_dma_unmap(struct xsk_buff_pool *pool,
{
}

+static inline struct xsk_dma_ref *xsk_pool_dma_get(struct xsk_buff_pool *pool)
+{
+ return NULL;
+}
+
+static inline void xsk_pool_dma_put(struct xsk_dma_ref *ref)
+{
+}
+
static inline int xsk_pool_dma_map(struct xsk_buff_pool *pool,
struct device *dev, unsigned long attrs)
{
diff --git a/include/net/xsk_buff_pool.h b/include/net/xsk_buff_pool.h
index a7df573784fd..df7e20fe5ae3 100644
--- a/include/net/xsk_buff_pool.h
+++ b/include/net/xsk_buff_pool.h
@@ -11,6 +11,7 @@
#include <net/xdp.h>

struct xsk_buff_pool;
+struct xsk_dma_ref;
struct xdp_rxq_info;
struct xsk_cb_desc;
struct xsk_queue;
@@ -38,6 +39,8 @@ struct xsk_dma_map {
dma_addr_t *dma_pages;
struct device *dev;
struct net_device *netdev;
+ struct xdp_umem *umem;
+ unsigned long attrs;
refcount_t users;
struct list_head list; /* Protected by the RTNL_LOCK */
u32 dma_pages_cnt;
@@ -52,6 +55,8 @@ struct xsk_buff_pool {
spinlock_t xsk_tx_list_lock;
refcount_t users;
struct xdp_umem *umem;
+ /* Pool/head storage; DMA references must not postpone socket teardown. */
+ refcount_t refs;
struct work_struct work;
/* Protects generic receive in shared and non-shared umem mode. */
spinlock_t rx_lock;
@@ -143,6 +148,8 @@ void xp_fill_cb(struct xsk_buff_pool *pool, struct xsk_cb_desc *desc);
int xp_dma_map(struct xsk_buff_pool *pool, struct device *dev,
unsigned long attrs, struct page **pages, u32 nr_pages);
void xp_dma_unmap(struct xsk_buff_pool *pool, unsigned long attrs);
+struct xsk_dma_ref *xp_dma_get(struct xsk_buff_pool *pool);
+void xp_dma_put(struct xsk_dma_ref *ref);
struct xdp_buff *xp_alloc(struct xsk_buff_pool *pool);
u32 xp_alloc_batch(struct xsk_buff_pool *pool, struct xdp_buff **xdp, u32 max);
bool xp_can_alloc(struct xsk_buff_pool *pool, u32 count);
diff --git a/net/xdp/xsk_buff_pool.c b/net/xdp/xsk_buff_pool.c
index c58f56f24a9c..8c71974494c9 100644
--- a/net/xdp/xsk_buff_pool.c
+++ b/net/xdp/xsk_buff_pool.c
@@ -12,6 +12,11 @@

#define ETH_PAD_LEN (ETH_HLEN + 2 * VLAN_HLEN + ETH_FCS_LEN)

+struct xsk_dma_ref {
+ struct xsk_dma_map *dma_map;
+ struct xsk_buff_pool *pool;
+};
+
void xp_add_xsk(struct xsk_buff_pool *pool, struct xdp_sock *xs)
{
if (!xs->tx)
@@ -34,7 +39,7 @@ void xp_del_xsk(struct xsk_buff_pool *pool, struct xdp_sock *xs)

void xp_destroy(struct xsk_buff_pool *pool)
{
- if (!pool)
+ if (!pool || !refcount_dec_and_test(&pool->refs))
return;

kvfree(pool->tx_descs);
@@ -68,6 +73,7 @@ struct xsk_buff_pool *xp_create_and_assign_umem(struct xdp_sock *xs,
pool = kvzalloc_flex(*pool, free_heads, entries);
if (!pool)
goto out;
+ refcount_set(&pool->refs, 1);

pool->heads = kvzalloc_objs(*pool->heads, umem->chunks);
if (!pool->heads)
@@ -360,7 +366,8 @@ static struct xsk_dma_map *xp_find_dma_map(struct xsk_buff_pool *pool)
}

static struct xsk_dma_map *xp_create_dma_map(struct device *dev, struct net_device *netdev,
- u32 nr_pages, struct xdp_umem *umem)
+ u32 nr_pages, struct xdp_umem *umem,
+ unsigned long attrs)
{
struct xsk_dma_map *dma_map;

@@ -376,6 +383,8 @@ static struct xsk_dma_map *xp_create_dma_map(struct device *dev, struct net_devi

dma_map->netdev = netdev;
dma_map->dev = dev;
+ dma_map->umem = umem;
+ dma_map->attrs = attrs;
dma_map->dma_pages_cnt = nr_pages;
refcount_set(&dma_map->users, 1);
list_add(&dma_map->list, &umem->xsk_dma_list);
@@ -430,6 +439,58 @@ void xp_dma_unmap(struct xsk_buff_pool *pool, unsigned long attrs)
}
EXPORT_SYMBOL(xp_dma_unmap);

+struct xsk_dma_ref *xp_dma_get(struct xsk_buff_pool *pool)
+{
+ struct xsk_dma_map *dma_map;
+ struct xsk_dma_ref *ref;
+
+ ASSERT_RTNL();
+ if (!pool->dma_pages)
+ return NULL;
+ dma_map = xp_find_dma_map(pool);
+ if (WARN_ON_ONCE(!dma_map))
+ return NULL;
+
+ ref = kmalloc_obj(*ref);
+ if (!ref)
+ return NULL;
+ ref->dma_map = dma_map;
+ ref->pool = pool;
+ refcount_inc(&pool->refs);
+ refcount_inc(&dma_map->users);
+ xdp_get_umem(dma_map->umem);
+ get_device(dma_map->dev);
+ /* Keep the mapping's lookup key alive without preventing unregister. */
+ get_device(&dma_map->netdev->dev);
+ return ref;
+}
+EXPORT_SYMBOL_GPL(xp_dma_get);
+
+void xp_dma_put(struct xsk_dma_ref *ref)
+{
+ struct xsk_dma_map *dma_map;
+ struct net_device *netdev;
+ struct xdp_umem *umem;
+ struct device *dev;
+
+ ASSERT_RTNL();
+ if (!ref)
+ return;
+ dma_map = ref->dma_map;
+ dev = dma_map->dev;
+ netdev = dma_map->netdev;
+ umem = dma_map->umem;
+ if (refcount_dec_and_test(&dma_map->users))
+ __xp_dma_unmap(dma_map, dma_map->attrs);
+ /* Unmap before the final reference can unpin the UMEM pages. */
+ xdp_put_umem(umem, false);
+ put_device(&netdev->dev);
+ put_device(dev);
+ xp_destroy(ref->pool);
+ kfree(ref);
+}
+EXPORT_SYMBOL_GPL(xp_dma_put);
+
static void xp_check_dma_contiguity(struct xsk_dma_map *dma_map)
{
u32 i;
@@ -487,7 +548,7 @@ int xp_dma_map(struct xsk_buff_pool *pool, struct device *dev,
return 0;
}

- dma_map = xp_create_dma_map(dev, pool->netdev, nr_pages, pool->umem);
+ dma_map = xp_create_dma_map(dev, pool->netdev, nr_pages, pool->umem, attrs);
if (!dma_map)
return -ENOMEM;


--
2.53.0