From: Martin Habets <habetsm.xilinx@gmail.com>
To: Jiasheng Jiang <jiasheng@iscas.ac.cn>
Cc: ecree.xilinx@gmail.com, davem@davemloft.net, kuba@kernel.org,
ast@kernel.org, daniel@iogearbox.net, hawk@kernel.org,
john.fastabend@gmail.com, andrii@kernel.org, kafai@fb.com,
songliubraving@fb.com, yhs@fb.com, kpsingh@kernel.org,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
bpf@vger.kernel.org
Subject: Re: [PATCH v4] sfc: potential dereference null pointer of rx_queue->page_ring
Date: Mon, 20 Dec 2021 11:20:16 +0000 [thread overview]
Message-ID: <20211220112016.skhopsmnu6a4eapd@gmail.com> (raw)
In-Reply-To: <20211220023715.746815-1-jiasheng@iscas.ac.cn>
On Mon, Dec 20, 2021 at 10:37:15AM +0800, Jiasheng Jiang wrote:
> The return value of kcalloc() needs to be checked.
Maybe my previous reply against v2 crossed with your later versions.
Your predicate is wrong. The code that uses rx_queue->page_ring
can deal with it being NULL.
The only thing you might want to do is set rx_queue->page_ptr_mask
to 0.
It is a mask, never use a signed value for it.
Martin
> To avoid dereference of null pointer in case of the failure of alloc,
> such as efx_fini_rx_recycle_ring().
> Therefore, it should be better to change the definition of page_ptr_mask
> to signed int and then assign the page_ptr_mask to -1 when page_ring is
> NULL, in order to avoid the use in the loop.
>
> Fixes: 5a6681e22c14 ("sfc: separate out SFC4000 ("Falcon") support into new sfc-falcon driver")
> Signed-off-by: Jiasheng Jiang <jiasheng@iscas.ac.cn>
> ---
> Changelog:
>
> v3 -> v4
>
> *Change 1. Casade return -ENOMEM when alloc fails and deal with the
> error.
> *Change 2. Set size to -1 instead of return error.
> *Change 3. Change the Fixes tag.
> ---
> drivers/net/ethernet/sfc/net_driver.h | 2 +-
> drivers/net/ethernet/sfc/rx_common.c | 5 ++++-
> 2 files changed, 5 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/ethernet/sfc/net_driver.h b/drivers/net/ethernet/sfc/net_driver.h
> index 9b4b25704271..beba3e0a6027 100644
> --- a/drivers/net/ethernet/sfc/net_driver.h
> +++ b/drivers/net/ethernet/sfc/net_driver.h
> @@ -407,7 +407,7 @@ struct efx_rx_queue {
> unsigned int page_recycle_count;
> unsigned int page_recycle_failed;
> unsigned int page_recycle_full;
> - unsigned int page_ptr_mask;
> + int page_ptr_mask;
> unsigned int max_fill;
> unsigned int fast_fill_trigger;
> unsigned int min_fill;
> diff --git a/drivers/net/ethernet/sfc/rx_common.c b/drivers/net/ethernet/sfc/rx_common.c
> index 68fc7d317693..d9d0a5805f1c 100644
> --- a/drivers/net/ethernet/sfc/rx_common.c
> +++ b/drivers/net/ethernet/sfc/rx_common.c
> @@ -150,7 +150,10 @@ static void efx_init_rx_recycle_ring(struct efx_rx_queue *rx_queue)
> efx->rx_bufs_per_page);
> rx_queue->page_ring = kcalloc(page_ring_size,
> sizeof(*rx_queue->page_ring), GFP_KERNEL);
> - rx_queue->page_ptr_mask = page_ring_size - 1;
> + if (!rx_queue->page_ring)
> + rx_queue->page_ptr_mask = -1;
> + else
> + rx_queue->page_ptr_mask = page_ring_size - 1;
> }
>
> static void efx_fini_rx_recycle_ring(struct efx_rx_queue *rx_queue)
> --
> 2.25.1
prev parent reply other threads:[~2021-12-20 11:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-12-20 2:37 [PATCH v4] sfc: potential dereference null pointer of rx_queue->page_ring Jiasheng Jiang
2021-12-20 11:20 ` Martin Habets [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211220112016.skhopsmnu6a4eapd@gmail.com \
--to=habetsm.xilinx@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=ecree.xilinx@gmail.com \
--cc=hawk@kernel.org \
--cc=jiasheng@iscas.ac.cn \
--cc=john.fastabend@gmail.com \
--cc=kafai@fb.com \
--cc=kpsingh@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=songliubraving@fb.com \
--cc=yhs@fb.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.