RDMA/mlx5: Drop FRMR pool handle on UMR revoke failure

When UMR revoke fails during MR cleanup, the handle is left in an
unknown state and cannot be returned to the pool. The driver already
destroys the mkey via the fallback path, but the pool's in_use counter
is never decremented, drifting upward over time.

Call ib_frmr_pool_drop on the revoke-failure path so the pool's
accounting stays consistent with the handles it has handed out.

Fixes: 36680ef7bc ("RDMA/mlx5: Switch from MR cache to FRMR pools")
Link: https://patch.msgid.link/r/20260610000145.820592-10-michaelgur@nvidia.com
Signed-off-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
This commit is contained in:
Michael Guralnik 2026-06-10 03:01:45 +03:00 committed by Jason Gunthorpe
parent ddbc251be1
commit c37d79dd96

View File

@ -1398,9 +1398,11 @@ static int mlx5r_handle_mkey_cleanup(struct mlx5_ib_mr *mr)
bool is_odp = is_odp_mr(mr);
int ret;
if (mr->ibmr.frmr.pool && !mlx5_umr_revoke_mr_with_lock(mr)) {
ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr);
return 0;
if (mr->ibmr.frmr.pool) {
if (!mlx5_umr_revoke_mr_with_lock(mr)) {
ib_frmr_pool_push(mr->ibmr.device, &mr->ibmr);
return 0;
}
}
if (is_odp)
@ -1422,6 +1424,10 @@ static int mlx5r_handle_mkey_cleanup(struct mlx5_ib_mr *mr)
dma_resv_unlock(
to_ib_umem_dmabuf(mr->umem)->attach->dmabuf->resv);
}
if (mr->ibmr.frmr.pool && !ret)
ib_frmr_pool_drop(&mr->ibmr);
return ret;
}