Re: [PATCH v2 09/14] NTB: ntb_transport: Drain RX tasklets during link cleanup

From: Koichiro Den

Date: Mon Sep 28 2026 - 01:35:07 EST


On Thu, Sep 24, 2026 at 08:53:35AM -0700, Dave Jiang wrote:
>
>
> On 9/24/26 8:51 AM, Dave Jiang wrote:
> >
> >
> > On 9/9/26 9:08 PM, Koichiro Den wrote:
> >> ntb_qp_link_cleanup() cancels QP link work but does not wait for the RX
> >> tasklet. The tasklet can still be processing the ring while cleanup
> >> resets the QP, and transport link cleanup can free the MW before the
> >> tasklet finishes.
> >>
> >> Clear active under rx_sched_lock and drain the tasklet before resetting
> >> the QP. Temporarily disable QP link work so a concurrent client link-up
> >> request cannot reactivate RX during cleanup, then re-enable it for the
> >> existing link setup paths.
> >>
> >> This does not drain RX DMA transfers or their completion callbacks.
> >
> > Is this something that we should handle?
>
> Ah I see you are handling it in the next patch. I would add a comment to say that is being handled follow on.
>
> Reviewed-by: Dave Jiang <dave.jiang@xxxxxxxxx>

Yes, I'll add a note in v3. Thanks for the review!

Best regards,
Koichiro Den

>
> >
> > DJ
> >
> >>
> >> Fixes: 9143595a7e05 ("NTB: ntb_transport: Free MWs in ntb_transport_link_cleanup()")
> >> Cc: stable@xxxxxxxxxxxxxxx
> >> Signed-off-by: Koichiro Den <den@xxxxxxxxxxxxx>
> >> ---
> >> Changes in v2:
> >> - No changes.
> >>
> >> drivers/ntb/ntb_transport.c | 7 ++++++-
> >> 1 file changed, 6 insertions(+), 1 deletion(-)
> >>
> >> diff --git a/drivers/ntb/ntb_transport.c b/drivers/ntb/ntb_transport.c
> >> index 45d4365becac..36797ea3ff45 100644
> >> --- a/drivers/ntb/ntb_transport.c
> >> +++ b/drivers/ntb/ntb_transport.c
> >> @@ -956,11 +956,16 @@ static void ntb_qp_link_cleanup(struct ntb_transport_qp *qp)
> >>
> >> dev_info(&pdev->dev, "qp %d: Link Cleanup\n", qp->qp_num);
> >>
> >> - cancel_delayed_work_sync(&qp->link_work);
> >> + disable_delayed_work_sync(&qp->link_work);
> >> + ntb_transport_set_qp_active(qp, false);
> >> + tasklet_kill(&qp->rxc_db_work);
> >> +
> >> ntb_qp_link_down_reset(qp);
> >>
> >> if (qp->event_handler)
> >> qp->event_handler(qp->cb_data, qp->link_is_up);
> >> +
> >> + enable_delayed_work(&qp->link_work);
> >> }
> >>
> >> static void ntb_qp_link_cleanup_work(struct work_struct *work)
> >
>