]> git.hungrycats.org Git - linux/commit
net/mlx5e: Prevent concurrent access to IPSec ASO context
authorJianbo Liu <jianbol@nvidia.com>
Mon, 16 Mar 2026 09:46:02 +0000 (11:46 +0200)
committerJakub Kicinski <kuba@kernel.org>
Thu, 19 Mar 2026 00:54:53 +0000 (17:54 -0700)
commit99b36850d881e2d65912b2520a1c80d0fcc9429a
treee6e42f29042078d6567bcb11e7f52e53dde6e6d0
parentb7e3a5d9c0d66b7fb44f63aef3bd734821afa0c8
net/mlx5e: Prevent concurrent access to IPSec ASO context

The query or updating IPSec offload object is through Access ASO WQE.
The driver uses a single mlx5e_ipsec_aso struct for each PF, which
contains a shared DMA-mapped context for all ASO operations.

A race condition exists because the ASO spinlock is released before
the hardware has finished processing WQE. If a second operation is
initiated immediately after, it overwrites the shared context in the
DMA area.

When the first operation's completion is processed later, it reads
this corrupted context, leading to unexpected behavior and incorrect
results.

This commit fixes the race by introducing a private context within
each IPSec offload object. The shared ASO context is now copied to
this private context while the ASO spinlock is held. Subsequent
processing uses this saved, per-object context, ensuring its integrity
is maintained.

Fixes: 1ed78fc03307 ("net/mlx5e: Update IPsec soft and hard limits")
Signed-off-by: Jianbo Liu <jianbol@nvidia.com>
Reviewed-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260316094603.6999-3-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec.h
drivers/net/ethernet/mellanox/mlx5/core/en_accel/ipsec_offload.c