linux/include/rdma
Or Har-Toov a44a3f175e RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency
Commit 51976c6cd7 ("RDMA/core: Provide rdma_user_mmap_disassociate()
to disassociate mmap pages") introduced disassociation_lock to protect
new mmap registrations against uverbs_user_mmap_disassociate(), but
created an ABBA deadlock:

  Thread A (mmap / fork):
    mmap_lock -> disassociation_lock

  Thread B (disassociate):
    disassociation_lock -> mmap_lock

Fix by removing disassociation_lock entirely and using the pre-existing
hw_destroy_rwsem instead. hw_destroy_rwsem already provides the same
protection: rdma_umap_open() and ib_uverbs_mmap() both use
down_read_trylock() before registering a new VMA, so holding hw_destroy_rwsem
in uverbs_user_mmap_disassociate() is sufficient to block new registrations.
trylock is used in both mmap paths (not blocking down_read) because
mmap_lock is already held on entry, and uverbs_user_mmap_disassociate()
acquires mmap_lock internally — a blocking read would recreate the same
deadlock.

The only caller that was not taking hw_destroy_rwsem for write was
rdma_user_mmap_disassociate(). Fix it to take the rwsem per-ufile while
iterating under lists_mutex.  This is safe because ib_uverbs_close()
releases hw_destroy_rwsem entirely before acquiring lists_mutex, so the
two locks are never held simultaneously.

lockdep warning:

 [  776.654252] ======================================================
 [  776.655214] WARNING: possible circular locking dependency detected
 [  776.656167] 6.18.0for-upstream_debug_94e244d9ccab #1 Not tainted
 [  776.657114] ------------------------------------------------------
 [  776.658087] devlink/14824 is trying to acquire lock:
 [  776.658879] ffff88811170c800 (&mm->mmap_lock){++++}-{4:4}, at: uverbs_user_mmap_disassociate+0x168/0x780 [ib_uverbs]
 [  776.660479]
 [  776.660479] but task is already holding lock:
 [  776.661460] ffff888142d92b08 (&file->disassociation_lock){+.+.}-{4:4}, at: uverbs_user_mmap_disassociate+0x39/0x780 [ib_uverbs]
 [  776.663177]
 [  776.663177] which lock already depends on the new lock.
 [  776.663177]
 [  776.664525]
 [  776.664525] the existing dependency chain (in reverse order) is:
 [  776.665724]
 [  776.665724] -> #2 (&file->disassociation_lock){+.+.}-{4:4}:
 [  776.666887]        __mutex_lock+0x16d/0x2330
 [  776.667633]        rdma_umap_open+0x129/0x280 [ib_uverbs]
 [  776.668489]        dup_mmap+0xa40/0x1790
 [  776.669170]        copy_process+0x5dd2/0x6170
 [  776.669933]        kernel_clone+0xb6/0x610
 [  776.670636]        __do_sys_clone+0xb5/0xf0
 [  776.671354]        do_syscall_64+0x70/0x12e0
 [  776.672083]        entry_SYSCALL_64_after_hwframe+0x4b/0x53
 [  776.672940]
 [  776.672940] -> #1 (&mm->mmap_lock/1){+.+.}-{4:4}:
 [  776.673985]        down_write_nested+0x90/0x1e0
 [  776.674751]        dup_mmap+0x201/0x1790
 [  776.675448]        copy_process+0x5dd2/0x6170
 [  776.676180]        kernel_clone+0xb6/0x610
 [  776.676904]        __do_sys_clone+0xb5/0xf0
 [  776.677615]        do_syscall_64+0x70/0x12e0
 [  776.678351]        entry_SYSCALL_64_after_hwframe+0x4b/0x53
 [  776.679239]
 [  776.679239] -> #0 (&mm->mmap_lock){++++}-{4:4}:
 [  776.680253]        __lock_acquire+0x18c6/0x2ec0
 [  776.681018]        lock_acquire+0x10e/0x2e0
 [  776.681742]        down_read+0x95/0x430
 [  776.682395]        uverbs_user_mmap_disassociate+0x168/0x780 [ib_uverbs]
 [  776.683436]        uverbs_destroy_ufile_hw+0x1ae/0x270 [ib_uverbs]
 [  776.684416]        ib_uverbs_remove_one+0x22b/0x420 [ib_uverbs]
 [  776.685371]        remove_client_context+0xa6/0xf0 [ib_core]
 [  776.686342]        disable_device+0x12b/0x240 [ib_core]
 [  776.687249]        __ib_unregister_device+0x269/0x460 [ib_core]
 [  776.688233]        ib_unregister_device+0x21/0x30 [ib_core]
 [  776.689140]        mlx5r_remove+0xd0/0x170 [mlx5_ib]
 [  776.689999]        device_release_driver_internal+0x3b2/0x560
 [  776.694876]        bus_remove_device+0x1f5/0x3e0
 [  776.695638]        device_del+0x3b9/0x990
 [  776.696329]        mlx5_detach_device+0x17e/0x350 [mlx5_core]
 [  776.697429]        mlx5_unload_one_devl_locked+0x3f/0xb0 [mlx5_core]
 [  776.698578]        mlx5_devlink_reload_down+0x1f9/0x550 [mlx5_core]
 [  776.699712]        devlink_reload+0x13e/0x680
 [  776.700456]        devlink_nl_reload_doit+0xc29/0x1160
 [  776.701293]        genl_family_rcv_msg_doit+0x1c9/0x2a0
 [  776.702135]        genl_rcv_msg+0x3f0/0x6b0
 [  776.702854]        netlink_rcv_skb+0x11d/0x370
 [  776.703605]        genl_rcv+0x24/0x40
 [  776.704236]        netlink_unicast+0x5b4/0x970
 [  776.704984]        netlink_sendmsg+0x730/0xbf0
 [  776.705748]        __sock_sendmsg+0xc5/0x190
 [  776.706461]        __sys_sendto+0x201/0x2f0
 [  776.707188]        __x64_sys_sendto+0xdc/0x1b0
 [  776.707931]        do_syscall_64+0x70/0x12e0
 [  776.708643]        entry_SYSCALL_64_after_hwframe+0x4b/0x53
 [  776.709546]
 [  776.709546] other info that might help us debug this:
 [  776.709546]
 [  776.710910] Chain exists of:
 [  776.710910]   &mm->mmap_lock --> &mm->mmap_lock/1 --> &file->disassociation_lock
 [  776.710910]
 [  776.712805]  Possible unsafe locking scenario:
 [  776.712805]
 [  776.713828]        CPU0                    CPU1
 [  776.714589]        ----                    ----
 [  776.715347]   lock(&file->disassociation_lock);
 [  776.716097]                                lock(&mm->mmap_lock/1);
 [  776.717067]                                lock(&file->disassociation_lock);
 [  776.718199]   rlock(&mm->mmap_lock);
 [  776.718857]
 [  776.718857]  *** DEADLOCK ***

Fixes: 51976c6cd7 ("RDMA/core: Provide rdma_user_mmap_disassociate() to disassociate mmap pages")
Signed-off-by: Or Har-Toov <ohartoov@nvidia.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260811-fix-mmap-lockdep-v1-1-1151b41063b4@nvidia.com
Acked-by: Junxian Huang <huangjunxian6@hisilicon.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
2026-09-01 10:03:08 -04:00
..
frmr_pools.h RDMA/core: Add ib_frmr_pool_drop for unrecoverable handles 2026-06-11 15:36:09 -03:00
ib_addr.h RDMA/cma: Always set static rate to 0 for RoCE 2023-06-11 11:26:02 +03:00
ib_cache.h IB/cache: avoid kernel-doc warnings 2026-02-24 05:38:45 -05:00
ib_cm.h RDMA/cm: Correct typedef and bad line warnings 2025-11-12 04:39:12 -05:00
ib_hdrs.h move asm/unaligned.h to linux/unaligned.h 2024-10-02 17:23:23 -04:00
ib_mad.h RDMA/sa_query: Support IB service records resolution 2025-08-13 06:15:56 -04:00
ib_marshall.h RDMA/core: Remove unused ib_copy_path_rec_from_user 2024-12-24 05:00:42 -05:00
ib_pack.h RDMA/core: Remove unused ib_ud_header_unpack 2024-12-24 05:00:42 -05:00
ib_pma.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
ib_sa.h RDMA/sa_query: Support IB service records resolution 2025-08-13 06:15:56 -04:00
ib_smi.h RDMA/mad: Delete duplicated init_query_mad functions 2022-01-05 15:18:36 -04:00
ib_sysfs.h RDMA: Change ops->init_port to ops->port_groups 2021-06-16 20:58:31 -03:00
ib_ucaps.h RDMA/core: Move ucaps into ib_uverbs_support.ko 2026-05-26 10:11:43 -03:00
ib_umem_odp.h RDMA/core: Convert UMEM ODP DMA mapping to caching IOVA and page linkage 2025-05-12 06:06:51 -04:00
ib_umem.h RDMA/mlx5: Constify struct ib_frmr_pool_ops and dma_buf_attach_ops 2026-07-20 09:00:39 -04:00
ib_verbs.h RDMA/core: Add Completion Counters to resource tracking 2026-07-22 05:45:47 -04:00
ib.h uaccess: remove CONFIG_SET_FS 2022-02-25 09:36:06 +01:00
iba.h move asm/unaligned.h to linux/unaligned.h 2024-10-02 17:23:23 -04:00
ibta_vol1_c12.h RDMA/cm: Add Enhanced Connection Establishment (ECE) bits 2020-05-27 16:05:05 -03:00
iter.h RDMA: Move DMA block iterator logic into dedicated files 2026-02-25 08:15:30 -05:00
iw_cm.h RDMA/iwcm: fix some kernel-doc issues in iw_cm.h 2026-02-24 05:39:13 -05:00
iw_portmap.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
lag.h RDMA/core: Add LAG functionality 2020-05-02 20:19:54 -03:00
mr_pool.h Linux 5.2-rc6 2019-06-28 21:18:23 -03:00
opa_addr.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
opa_port_info.h RDMA/OPA: Update OPA link speed list 2026-03-11 15:17:28 -04:00
opa_smi.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
rdma_cm_ib.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
rdma_cm.h RDMA/core: Check id_priv->restricted_node_type in cma_listen_on_dev() 2026-02-25 07:50:10 -05:00
rdma_counter.h RDMA/core: Pass port to counter bind/unbind operations 2025-03-18 06:18:46 -04:00
rdma_netlink.h RDMA/nldev: Add dellink function pointer 2026-03-30 13:47:43 -04:00
rdma_vt.h RDMA/hfi1: Open-code rvt_set_ibdev_name() 2026-06-05 12:38:42 -03:00
rdmavt_cq.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
rdmavt_mr.h RDMA/include: Replace license text with SPDX tags 2020-07-29 14:48:36 -03:00
rdmavt_qp.h IB/rdmavt: rdmavt_qp.h: clean up kernel-doc comments 2025-11-06 02:23:23 -05:00
restrack.h RDMA/core: Add Completion Counters to resource tracking 2026-07-22 05:45:47 -04:00
rw.h RDMA/core: add rdma_rw_max_sge() helper for SQ sizing 2026-01-28 05:54:53 -05:00
signature.h RDMA: Make most headers compile stand alone 2019-07-25 13:58:47 -03:00
tid_rdma_defs.h IB/hfi1: Build TID RDMA WRITE request 2019-02-05 18:07:43 -05:00
uverbs_ioctl.h RDMA/core: Add ib_no_udata_io() helper 2026-07-12 04:30:38 -04:00
uverbs_named_ioctl.h RDMA/uverbs: Make UVERBS_OBJECT_METHODS to consider line number 2021-04-13 19:36:35 -03:00
uverbs_std_types.h RDMA/uverbs: Propagate errors from rdma_lookup_get_uobject() 2025-03-13 08:26:37 -04:00
uverbs_types.h RDMA/uverbs: Fix mmap_lock/disassociation_lock circular dependency 2026-09-01 10:03:08 -04:00