net/mlx5: Fix rev_entry reference leak in mlx5_tc_ct_shared_counter_get()

When the reverse entry is found but its counter is already being
released, refcount_inc_not_zero() fails and the reference taken by
mlx5_tc_ct_entry_get() is never dropped before falling through to
create_counter.  Drop it so the reverse entry is not kept alive forever
by a shared counter lookup that did not use it.

Fixes: 1edae2335a ("net/mlx5e: CT: Use the same counter for both directions")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260917113131.2149024-1-vulab@iscas.ac.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Wentao Liang 2026-09-17 11:31:31 +00:00 committed by Jakub Kicinski
parent 1c34493df9
commit 0bf6bb567f

View File

@ -1082,6 +1082,9 @@ mlx5_tc_ct_shared_counter_get(struct mlx5_tc_ct_priv *ct_priv,
spin_unlock_bh(&ct_priv->ht_lock);
if (rev_entry)
mlx5_tc_ct_entry_put(rev_entry);
create_counter:
shared_counter = mlx5_tc_ct_counter_create(ct_priv);