On Wed, Dec 13, 2023 at 5:57 PM Jamal Hadi Salim [off-list ref] wrote:
quoted hunk ↗ jump to hunk
It is possible to compute a band of 3. Doing so will overrun array
q->band_pkt_count[0-2] boundaries.
Fixes: 29f834aa326e ("net_sched: sch_fq: add 3 bands and WRR scheduling")
Reported-by: Coverity Scan <redacted>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/sch_fq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/sched/sch_fq.c b/net/sched/sch_fq.c
index 3a31c47fea9b..217c430343df 100644
--- a/net/sched/sch_fq.c
+++ b/net/sched/sch_fq.c
@@ -159,7 +159,7 @@ struct fq_sched_data {
/* return the i-th 2-bit value ("crumb") */
static u8 fq_prio2band(const u8 *prio2band, unsigned int prio)
{
- return (prio2band[prio / 4] >> (2 * (prio & 0x3))) & 0x3;
+ return (prio2band[prio / 4] >> (2 * (prio & 0x3))) % 0x3;
}
Are you sure this is needed ?
fq_load_priomap() makes sure this can not happen...