Allow the comp_handler callback implementation to call ib_poll_cq(). A call to ib_poll_cq() calls rxe_poll_cq() with the rdma_rxe driver. And rxe_poll_cq() locks cq->cq_lock. That leads to a spinlock deadlock. The Mellanox and Intel drivers allow a comp_handler callback implementation to call ib_poll_cq(). Avoid the deadlock by calling the comp_handler callback without holding cq->cq_lock. Changelog: v1: https://lore.kernel.org/all/20250806123921.633410-1-philipp.reisner@xxxxxxxxxx/ v1 -> v2: - Only reset cq->notify to 0 when invoking the comp_handler ==================== Signed-off-by: Philipp Reisner <philipp.reisner@xxxxxxxxxx> Reviewed-by: Zhu Yanjun <yanjun.zhu@xxxxxxxxx> --- drivers/infiniband/sw/rxe/rxe_cq.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/infiniband/sw/rxe/rxe_cq.c b/drivers/infiniband/sw/rxe/rxe_cq.c index fffd144d509e..95652001665d 100644 --- a/drivers/infiniband/sw/rxe/rxe_cq.c +++ b/drivers/infiniband/sw/rxe/rxe_cq.c @@ -88,6 +88,7 @@ int rxe_cq_post(struct rxe_cq *cq, struct rxe_cqe *cqe, int solicited) int full; void *addr; unsigned long flags; + bool invoke_handler = false; spin_lock_irqsave(&cq->cq_lock, flags); @@ -113,11 +114,14 @@ int rxe_cq_post(struct rxe_cq *cq, struct rxe_cqe *cqe, int solicited) if ((cq->notify & IB_CQ_NEXT_COMP) || (cq->notify & IB_CQ_SOLICITED && solicited)) { cq->notify = 0; - cq->ibcq.comp_handler(&cq->ibcq, cq->ibcq.cq_context); + invoke_handler = true; } spin_unlock_irqrestore(&cq->cq_lock, flags); + if (invoke_handler) + cq->ibcq.comp_handler(&cq->ibcq, cq->ibcq.cq_context); + return 0; } -- 2.50.1