Skip to content

Commit b324327

Browse files
jakemoroniSasha Levin
authored andcommitted
RDMA/umem: Fix double dma_buf_unpin in failure path
[ Upstream commit 104016eb671e19709721c1b0048dd912dc2e96be ] In ib_umem_dmabuf_get_pinned_with_dma_device(), the call to ib_umem_dmabuf_map_pages() can fail. If this occurs, the dmabuf is immediately unpinned but the umem_dmabuf->pinned flag is still set. Then, when ib_umem_release() is called, it calls ib_umem_dmabuf_revoke() which will call dma_buf_unpin() again. Fix this by removing the immediate unpin upon failure and just let the ib_umem_release/revoke path handle it. This also ensures the proper unmap-unpin unwind ordering if the dmabuf_map_pages call happened to fail due to dma_resv_wait_timeout (and therefore has a non-NULL umem_dmabuf->sgt). Fixes: 1e4df4a ("RDMA/umem: Allow pinned dmabuf umem usage") Signed-off-by: Jacob Moroni <jmoroni@google.com> Link: https://patch.msgid.link/20260224234153.1207849-1-jmoroni@google.com Signed-off-by: Leon Romanovsky <leon@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org>
1 parent 35854ed commit b324327

1 file changed

Lines changed: 1 addition & 3 deletions

File tree

drivers/infiniband/core/umem_dmabuf.c

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -205,13 +205,11 @@ struct ib_umem_dmabuf *ib_umem_dmabuf_get_pinned(struct ib_device *device,
205205

206206
err = ib_umem_dmabuf_map_pages(umem_dmabuf);
207207
if (err)
208-
goto err_unpin;
208+
goto err_release;
209209
dma_resv_unlock(umem_dmabuf->attach->dmabuf->resv);
210210

211211
return umem_dmabuf;
212212

213-
err_unpin:
214-
dma_buf_unpin(umem_dmabuf->attach);
215213
err_release:
216214
dma_resv_unlock(umem_dmabuf->attach->dmabuf->resv);
217215
ib_umem_release(&umem_dmabuf->umem);

0 commit comments

Comments
 (0)