Re: [PATCH rdma] RDMA/mlx5: Cancel deferred page-fault EQ work before teardown

From: Chenguang Zhao

Date: Thu Oct 08 2026 - 01:47:16 EST


On Thu, Oct 08, 2026 at 12:42:11AM +0100, Prathamesh Deshpande wrote:
> Page-fault EQ work can remain queued after the notifier is disabled.
> Destroying the EQ before cancelling that work can let the worker access
> freed EQ memory.
>
> Cancel the deferred work before destroying the EQ.
>
> Fixes: d5d284b829a6 ("{net,IB}/mlx5: Move Page fault EQ and ODP logic to RDMA")
> Signed-off-by: Prathamesh Deshpande <prathameshdeshpande7@xxxxxxxxx>
> ---
> drivers/infiniband/hw/mlx5/odp.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/infiniband/hw/mlx5/odp.c b/drivers/infiniband/hw/mlx5/odp.c
> index b8618610737a..1f28c30095dc 100644
> --- a/drivers/infiniband/hw/mlx5/odp.c
> +++ b/drivers/infiniband/hw/mlx5/odp.c
> @@ -1885,8 +1885,8 @@ mlx5_ib_odp_destroy_eq(struct mlx5_ib_dev *dev, struct mlx5_ib_pf_eq *eq)
> if (!eq->core)
> return 0;
> mlx5_eq_disable(dev->mdev, eq->core, &eq->irq_nb);
> - err = mlx5_eq_destroy_generic(dev->mdev, eq->core);
> cancel_work_sync(&eq->work);
> + err = mlx5_eq_destroy_generic(dev->mdev, eq->core);
> destroy_workqueue(eq->wq);
> mempool_destroy(eq->pool);
>
> --
> 2.43.0
>

Looks correct.

Reviewed-by: Chenguang Zhao <zhaochenguang@xxxxxxxxxx>