[PATCH] net: ethernet: ti: cpsw: fix NULL pointer dereference in switch mode

Subsystems: networking drivers, the rest, ti ethernet switch driver (cpsw)

STALE3487d

3 messages, 3 authors, 2017-02-01 · open the first message on its own page

[PATCH] net: ethernet: ti: cpsw: fix NULL pointer dereference in switch mode

From: Grygorii Strashko <grygorii.strashko@ti.com>
Date: 2017-01-31 20:04:46

In switch mode on struct cpsw_slave->ndev field will be initialized with
proper value only for the one cpsw slave port, as result
cpsw_get_usage_count() will generate "Unable to handle kernel NULL pointer
dereference" exception when first ethernet interface is opening
cpsw_ndo_open(). This issue causes boot regression on AM335x EVM and
reproducible on am57xx-evm (switch mode).
Fix it by adding additional check for !cpsw->slaves[i].ndev in
cpsw_get_usage_count().

Cc: Ivan Khoronzhuk <redacted>
fixes: 03fd01ad0eea ("net: ethernet: ti: cpsw: don't duplicate ndev_running")
Signed-off-by: Grygorii Strashko <grygorii.strashko@ti.com>
---
 drivers/net/ethernet/ti/cpsw.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index 67b7323..35a95dc 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -677,7 +677,7 @@ static int cpsw_get_usage_count(struct cpsw_common *cpsw)
 	u32 usage_count = 0;
 
 	for (i = 0; i < cpsw->data.slaves; i++)
-		if (netif_running(cpsw->slaves[i].ndev))
+		if (cpsw->slaves[i].ndev && netif_running(cpsw->slaves[i].ndev))
 			usage_count++;
 
 	return usage_count;
-- 
2.10.1.dirty

Re: [PATCH] net: ethernet: ti: cpsw: fix NULL pointer dereference in switch mode

From: Ivan Khoronzhuk <hidden>
Date: 2017-02-01 16:30:57

On Tue, Jan 31, 2017 at 02:04:04PM -0600, Grygorii Strashko wrote:
In switch mode on struct cpsw_slave->ndev field will be initialized with
proper value only for the one cpsw slave port, as result
cpsw_get_usage_count() will generate "Unable to handle kernel NULL pointer
dereference" exception when first ethernet interface is opening
cpsw_ndo_open(). This issue causes boot regression on AM335x EVM and
reproducible on am57xx-evm (switch mode).
Fix it by adding additional check for !cpsw->slaves[i].ndev in
cpsw_get_usage_count().

Cc: Ivan Khoronzhuk <redacted>
fixes: 03fd01ad0eea ("net: ethernet: ti: cpsw: don't duplicate ndev_running")
Signed-off-by: Grygorii Strashko <grygorii.strashko@ti.com>
---
Yes, unfortunately forgot to add it. Thanks.
Reviewed-by: Ivan Khoronzhuk <redacted>

quoted hunk
 drivers/net/ethernet/ti/cpsw.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/ti/cpsw.c b/drivers/net/ethernet/ti/cpsw.c
index 67b7323..35a95dc 100644
--- a/drivers/net/ethernet/ti/cpsw.c
+++ b/drivers/net/ethernet/ti/cpsw.c
@@ -677,7 +677,7 @@ static int cpsw_get_usage_count(struct cpsw_common *cpsw)
 	u32 usage_count = 0;
 
 	for (i = 0; i < cpsw->data.slaves; i++)
-		if (netif_running(cpsw->slaves[i].ndev))
+		if (cpsw->slaves[i].ndev && netif_running(cpsw->slaves[i].ndev))
 			usage_count++;
 
 	return usage_count;
-- 
2.10.1.dirty

Re: [PATCH] net: ethernet: ti: cpsw: fix NULL pointer dereference in switch mode

From: David Miller <davem@davemloft.net>
Date: 2017-02-01 17:06:27

From: Grygorii Strashko <grygorii.strashko@ti.com>
Date: Tue, 31 Jan 2017 14:04:04 -0600
In switch mode on struct cpsw_slave->ndev field will be initialized with
proper value only for the one cpsw slave port, as result
cpsw_get_usage_count() will generate "Unable to handle kernel NULL pointer
dereference" exception when first ethernet interface is opening
cpsw_ndo_open(). This issue causes boot regression on AM335x EVM and
reproducible on am57xx-evm (switch mode).
Fix it by adding additional check for !cpsw->slaves[i].ndev in
cpsw_get_usage_count().

Cc: Ivan Khoronzhuk <redacted>
fixes: 03fd01ad0eea ("net: ethernet: ti: cpsw: don't duplicate ndev_running")
Please capitalize "Fixes: " in the future.
Signed-off-by: Grygorii Strashko <grygorii.strashko@ti.com>
Applied, thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help