git: a2fb16e3c788 - main - fixup! libmlx5: External memory binding for HW resources

From: Konstantin Belousov <kib_at_FreeBSD.org>
Date: Wed, 16 Sep 2026 14:13:08 UTC
The branch main has been updated by kib:

URL: https://cgit.FreeBSD.org/src/commit/?id=a2fb16e3c7881556b84de969f423420ca7c1177a

commit a2fb16e3c7881556b84de969f423420ca7c1177a
Author:     Ariel Ehrenberg <aehrenberg@nvidia.com>
AuthorDate: 2026-07-28 10:39:04 +0000
Commit:     Konstantin Belousov <kib@FreeBSD.org>
CommitDate: 2026-09-16 14:12:08 +0000

    fixup! libmlx5: External memory binding for HW resources
    
    Match a doorbell to its page with a range check instead of a page-boundary
    mask, so mlx5_free_db() also works for external allocations that are not
    page aligned and no longer leaks the doorbell page.
    
    Sponsored by:   NVidia networking
    MFC after:      1 month
---
 contrib/ofed/libmlx5/dbrec.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/contrib/ofed/libmlx5/dbrec.c b/contrib/ofed/libmlx5/dbrec.c
index 17aee0ba20ee..f4df9a079c07 100644
--- a/contrib/ofed/libmlx5/dbrec.c
+++ b/contrib/ofed/libmlx5/dbrec.c
@@ -126,9 +126,12 @@ void mlx5_free_db(struct mlx5_context *context, __be32 *db)
 
 	pthread_mutex_lock(&context->db_list_mutex);
 
-	for (page = context->db_list; page; page = page->next)
-		if (((uintptr_t) db & ~(ps - 1)) == (uintptr_t) page->buf.buf)
+	for (page = context->db_list; page; page = page->next) {
+		uintptr_t base = (uintptr_t) page->buf.buf;
+
+		if ((uintptr_t) db >= base && (uintptr_t) db - base < ps)
 			break;
+	}
 
 	if (!page)
 		goto out;