[PATCH v2 4/4] RDMA/rxe: Do not force cleanup on pool timeout

From: Dongliang Qin

Date: Mon Sep 28 2026 - 13:28:03 EST


The sleepable pool cleanup path waits up to 50 seconds for the last
reference and then continues cleanup anyway. If a reference is still
held, that turns a lifetime bug into a use-after-free.

Wait for completion instead. A stuck object is easier to diagnose than
a stale pointer; the existing non-sleepable path is unchanged.

Fixes: 215d0a755e1b ("RDMA/rxe: Stop lookup of partially built objects")

Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Dongliang Qin <cccccccccccc777777@xxxxxxxxx>
---
drivers/infiniband/sw/rxe/rxe_pool.c | 14 ++------------
1 file changed, 2 insertions(+), 12 deletions(-)

diff --git a/drivers/infiniband/sw/rxe/rxe_pool.c b/drivers/infiniband/sw/rxe/rxe_pool.c
index d9cb682fd71f8..d5ff5d453f5f8 100644
--- a/drivers/infiniband/sw/rxe/rxe_pool.c
+++ b/drivers/infiniband/sw/rxe/rxe_pool.c
@@ -178,7 +178,7 @@ int __rxe_cleanup(struct rxe_pool_elem *elem, bool sleepable)
{
struct rxe_pool *pool = elem->pool;
struct xarray *xa = &pool->xa;
- int ret, err = 0;
+ int err = 0;
void *xa_ret;

if (sleepable)
@@ -201,17 +201,7 @@ int __rxe_cleanup(struct rxe_pool_elem *elem, bool sleepable)
* return to rdma-core
*/
if (sleepable) {
- if (!completion_done(&elem->complete)) {
- ret = wait_for_completion_timeout(&elem->complete,
- msecs_to_jiffies(50000));
-
- /* Shouldn't happen. There are still references to
- * the object but, rather than deadlock, free the
- * object or pass back to rdma-core.
- */
- if (WARN_ON(!ret))
- err = -ETIMEDOUT;
- }
+ wait_for_completion(&elem->complete);
} else {
unsigned long until = jiffies + RXE_POOL_TIMEOUT;

--
2.43.0