Thread (6 messages) flat view 6 messages, 3 authors, 1d ago

Re: [PATCH 2/2] ice: clear Flow Director entries before reset cleanup

From: Przemek Kitszel <przemyslaw.kitszel@intel.com>
Date: 2026-09-04 15:09:06
Also in: intel-wired-lan, lkml

On 9/3/26 9:47 AM, Aaron Ma wrote:
Flow Director profiles retain handles to generic flow entries. Reset calls
ice_clear_hw_tbls() to free those entries, but leaves the Flow Director
handles unchanged until replay replaces them.

If rebuild fails before replay completes, later driver removal follows a
stale handle and dereferences a freed flow entry in ice_flow_rem_entry().
KASAN reports a wild access to list poison from
ice_fdir_erase_flow_from_hw().

The failure is reported as:

   KASAN: maybe wild-memory-access in range [0xdead000000000108-...]
   RIP: ice_flow_rem_entry+0xaf/0x170 [ice]
   ice_fdir_erase_flow_from_hw+0x1ee/0x420 [ice]

Clear the Flow Director handles before the hardware tables free their
entries. A successful replay installs new handles, while a failed rebuild
leaves them invalid for later cleanup.

Fixes: 148beb612031 ("ice: Initialize Flow Director resources")
Signed-off-by: Aaron Ma <redacted>
makes sense, thank you!
Reviewed-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help