In setup_nic_devices(), the netdev is allocated using alloc_etherdev_mq().
However, the pointer to this structure is stored in oct->props[i].netdev
only after the calls to netif_set_real_num_rx_queues() and
netif_set_real_num_tx_queues().
If either of these functions fails, setup_nic_devices() returns an error
without freeing the allocated netdev. Since oct->props[i].netdev is still
NULL at this point, the cleanup function liquidio_destroy_nic_device()
will fail to find and free the netdev, resulting in a memory leak.
Fix this by initializing oct->props[i].netdev before calling the queue
setup functions. This ensures that the netdev is properly accessible for
cleanup in case of errors.
Compile tested only. Issue found using a prototype static analysis tool
and code review.
Fixes: c33c997346c3 ("liquidio: enhanced ethtool --set-channels feature")
Signed-off-by: Zilin Guan <redacted>
---
.../net/ethernet/cavium/liquidio/lio_main.c | 20 +++++++++----------
1 file changed, 10 insertions(+), 10 deletions(-)
From: Simon Horman <horms@kernel.org> Date: 2026-01-23 17:21:15
On Thu, Jan 22, 2026 at 07:29:33AM +0000, Zilin Guan wrote:
In setup_nic_devices(), the netdev is allocated using alloc_etherdev_mq().
However, the pointer to this structure is stored in oct->props[i].netdev
only after the calls to netif_set_real_num_rx_queues() and
netif_set_real_num_tx_queues().
If either of these functions fails, setup_nic_devices() returns an error
without freeing the allocated netdev. Since oct->props[i].netdev is still
NULL at this point, the cleanup function liquidio_destroy_nic_device()
will fail to find and free the netdev, resulting in a memory leak.
Fix this by initializing oct->props[i].netdev before calling the queue
setup functions. This ensures that the netdev is properly accessible for
cleanup in case of errors.
Compile tested only. Issue found using a prototype static analysis tool
and code review.
Fixes: c33c997346c3 ("liquidio: enhanced ethtool --set-channels feature")
Signed-off-by: Zilin Guan <redacted>
Thanks Zilin,
I agree with your analysis, and proposed fix.
And that the problem appears to have been introduced in the cited commit.
But I am wondering if we also need the following, probably as a separate
commit, to ensure that liquidio_destroy_nic_device is called for the
element of props[i] whose assingment your patch addresses.
Also compile tested only.
On Fri, Jan 23, 2026 at 05:21:11PM +0000, Simon Horman wrote:
quoted hunk
Thanks Zilin,
I agree with your analysis, and proposed fix.
And that the problem appears to have been introduced in the cited commit.
But I am wondering if we also need the following, probably as a separate
commit, to ensure that liquidio_destroy_nic_device is called for the
element of props[i] whose assingment your patch addresses.
Also compile tested only.
Hi Simon,
Thanks for the review and the suggestion.
I agree with you. The current while (i--) loop indeed skips the cleanup
for the device index i that actually failed. I also noticed that
lio_vf_main.c shares the exact same issues.
I'll send a v2 series to correct both files, and I'll include the loop fix
as a separate commit as you suggested.
Best regards,
Zilin