[PATCH net] bnx2: Fix bug in bnx2_free_tx_skbs().

Subsystems: broadcom bnx2 gigabit ethernet driver, networking drivers, the rest

STALE5151d REVIEWED: 1 (0M)

1 review trailer.

2 messages, 2 authors, 2012-07-11 · open the first message on its own page

[PATCH net] bnx2: Fix bug in bnx2_free_tx_skbs().

From: "Michael Chan" <mchan@broadcom.com>
Date: 2012-07-10 19:53:14

In rare cases, bnx2x_free_tx_skbs() can unmap the wrong DMA address
when it gets to the last entry of the tx ring.  We were not using
the proper macro to skip the last entry when advancing the tx index.

Reported-by: Zongyun Lai <redacted>
Reviewed-by: Jeffrey Huang <redacted>
Signed-off-by: Michael Chan <mchan@broadcom.com>
---
 drivers/net/ethernet/broadcom/bnx2.c |    6 +++---
 1 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bnx2.c b/drivers/net/ethernet/broadcom/bnx2.c
index ac7b744..1fa4927 100644
--- a/drivers/net/ethernet/broadcom/bnx2.c
+++ b/drivers/net/ethernet/broadcom/bnx2.c
@@ -5372,7 +5372,7 @@ bnx2_free_tx_skbs(struct bnx2 *bp)
 			int k, last;
 
 			if (skb == NULL) {
-				j++;
+				j = NEXT_TX_BD(j);
 				continue;
 			}
 
@@ -5384,8 +5384,8 @@ bnx2_free_tx_skbs(struct bnx2 *bp)
 			tx_buf->skb = NULL;
 
 			last = tx_buf->nr_frags;
-			j++;
-			for (k = 0; k < last; k++, j++) {
+			j = NEXT_TX_BD(j);
+			for (k = 0; k < last; k++, j = NEXT_TX_BD(j)) {
 				tx_buf = &txr->tx_buf_ring[TX_RING_IDX(j)];
 				dma_unmap_page(&bp->pdev->dev,
 					dma_unmap_addr(tx_buf, mapping),
-- 
1.7.1

Re: [PATCH net] bnx2: Fix bug in bnx2_free_tx_skbs().

From: David Miller <davem@davemloft.net>
Date: 2012-07-11 06:37:35

From: "Michael Chan" <mchan@broadcom.com>
Date: Tue, 10 Jul 2012 13:04:40 -0700
In rare cases, bnx2x_free_tx_skbs() can unmap the wrong DMA address
when it gets to the last entry of the tx ring.  We were not using
the proper macro to skip the last entry when advancing the tx index.

Reported-by: Zongyun Lai <redacted>
Reviewed-by: Jeffrey Huang <redacted>
Signed-off-by: Michael Chan <mchan@broadcom.com>
Applied and queued up for -stable.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help