Thread (31 messages) flat view 31 messages, 3 authors, 18d ago

Re: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild

From: sashiko-bot@kernel.org
Date: 2026-08-14 05:05:19

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Medium] Desynchronization between `apc->indir_table_sz` and the actual heap allocation size of `apc->indir_table` during device reset leads to heap out-of-bounds read and write.
--
--- Patch [11]: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild ---
commit e2bf133521a3f8f376f19cc855758c1eb53a195b
Author: Long Li [off-list ref]
net: mana: keep a user-configured RSS table across a queue rebuild

A queue rebuild regenerates the RSS indirection table from the driver default.
This patch updates the driver to carry the user-configured table over instead
when the queue count is unchanged.
quoted hunk ↗ jump to hunk
diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
index 7c43c2f9043ba..6e77b59cfcf90 100644
--- a/drivers/net/ethernet/microsoft/mana/mana_en.c
+++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
[ ... ]
+static bool mana_rss_table_keep(struct mana_port_context *apc,
+				unsigned int num_queues, bool *lost)
+{
+	u32 i;
+
+	*lost = false;
+
+	if (!netif_is_rxfh_configured(apc->ndev))
+		return false;
+
+	for (i = 0; i < apc->indir_table_sz; i++) {
+		if (apc->indir_table[i] >= num_queues) {
[Severity: Medium]
This is a pre-existing issue, but can this loop perform an out-of-bounds
read on apc->indir_table?

During a device reset, mana_init_port() re-queries the hardware and updates
apc->indir_table_sz directly:

mana_init_port() {
	...
	err = mana_query_vport_cfg(apc, port_idx, &max_txq, &max_rxq,
				   &apc->indir_table_sz);
	...
}

If the hardware returns a larger size than what was originally allocated
for apc->indir_table, does the driver reallocate the array to match the
new apc->indir_table_sz? If not, this loop might read past the end of
the existing heap allocation, which this patch extends into the new
mana_rss_table_keep() function.
+			*lost = true;
+			return false;
+		}
+	}
+
+	return true;
+}
-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260813050418.2906468-1-longli@microsoft.com?part=11
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help