Page MenuHomeFreeBSD

if_bnxt: Fix HWRM mailbox/DMA teardown race on detach
ClosedPublic

Authored by sumit.saxena_broadcom.com on Aug 3 2026, 12:19 PM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Oct 6, 4:12 PM
Unknown Object (File)
Tue, Oct 6, 2:15 PM
Unknown Object (File)
Tue, Oct 6, 1:41 PM
Unknown Object (File)
Mon, Oct 5, 11:09 AM
Unknown Object (File)
Sat, Oct 3, 5:29 PM
Unknown Object (File)
Sat, Oct 3, 3:48 AM
Unknown Object (File)
Sat, Oct 3, 12:23 AM
Unknown Object (File)
Fri, Oct 2, 6:51 AM
Subscribers

Details

Summary

iflib's generic device-deregister path never drains the admin task
before calling IFDI_DETACH, so bnxt_update_admin_status() (scheduled
once/sec) could still run concurrently with bnxt_detach(), racing on
softc->hwrm_lock and the shared HWRM request/response DMA buffer that
bnxt_detach() destroys. That race could leave the firmware-side HWRM
mailbox inconsistent, surfacing as "Timeout sending HWRM_VER_GET" on
the next module load.

Add a softc->detached guard: set it as the first statement in
bnxt_detach(), and bail out of bnxt_update_admin_status() immediately
when it's set.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

This revision is now accepted and ready to land.Aug 4 2026, 8:08 PM

AI scan fixes:

  • softc->detached was a plain bool, written from bnxt_detach() and polled from bnxt_update_admin_status(), which run on different threads with no lock in common at those two points. A plain bool gives no cross-thread visibility or ordering guarantee, so the reader could still observe a stale false well after the writer's store, narrowing the race this commit describes rather than closing it. Change the field to volatile int and access it via atomic_store_rel_int()/atomic_load_acq_int() at both sites.
This revision now requires review to proceed.Tue, Sep 29, 9:40 AM

Note that this may no longer be needed as iflib_device_deregister() drains the private taskqueue before IFDI_DETACH since commit ba353c8950d5

This revision is now accepted and ready to land.Tue, Sep 29, 4:50 PM