All of lore.kernel.org
 help / color / mirror / Atom feed
From: Saeed Mahameed <saeed@kernel.org>
To: "David S. Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Eric Dumazet <edumazet@google.com>
Cc: Saeed Mahameed <saeedm@nvidia.com>,
	netdev@vger.kernel.org, Tariq Toukan <tariqt@nvidia.com>,
	Dust Li <dust.li@linux.alibaba.com>,
	Cruz Zhao <cruzzhao@linux.alibaba.com>,
	Tianchen Ding <dtcccc@linux.alibaba.com>,
	Wojciech Drewek <wojciech.drewek@intel.com>
Subject: [net 05/17] net/mlx5e: fix double free of encap_header
Date: Mon, 13 Nov 2023 13:08:14 -0800	[thread overview]
Message-ID: <20231113210826.47593-6-saeed@kernel.org> (raw)
In-Reply-To: <20231113210826.47593-1-saeed@kernel.org>

From: Dust Li <dust.li@linux.alibaba.com>

When mlx5_packet_reformat_alloc() fails, the encap_header allocated in
mlx5e_tc_tun_create_header_ipv4{6} will be released within it. However,
e->encap_header is already set to the previously freed encap_header
before mlx5_packet_reformat_alloc(). As a result, the later
mlx5e_encap_put() will free e->encap_header again, causing a double free
issue.

mlx5e_encap_put()
    --> mlx5e_encap_dealloc()
        --> kfree(e->encap_header)

This happens when cmd: MLX5_CMD_OP_ALLOC_PACKET_REFORMAT_CONTEXT fail.

This patch fix it by not setting e->encap_header until
mlx5_packet_reformat_alloc() success.

Fixes: d589e785baf5e("net/mlx5e: Allow concurrent creation of encap entries")
Reported-by: Cruz Zhao <cruzzhao@linux.alibaba.com>
Reported-by: Tianchen Ding <dtcccc@linux.alibaba.com>
Signed-off-by: Dust Li <dust.li@linux.alibaba.com>
Reviewed-by: Wojciech Drewek <wojciech.drewek@intel.com>
Signed-off-by: Saeed Mahameed <saeedm@nvidia.com>
---
 drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun.c | 10 ++++------
 1 file changed, 4 insertions(+), 6 deletions(-)

diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun.c b/drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun.c
index 00a04fdd756f..8bca696b6658 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en/tc_tun.c
@@ -300,9 +300,6 @@ int mlx5e_tc_tun_create_header_ipv4(struct mlx5e_priv *priv,
 	if (err)
 		goto destroy_neigh_entry;
 
-	e->encap_size = ipv4_encap_size;
-	e->encap_header = encap_header;
-
 	if (!(nud_state & NUD_VALID)) {
 		neigh_event_send(attr.n, NULL);
 		/* the encap entry will be made valid on neigh update event
@@ -322,6 +319,8 @@ int mlx5e_tc_tun_create_header_ipv4(struct mlx5e_priv *priv,
 		goto destroy_neigh_entry;
 	}
 
+	e->encap_size = ipv4_encap_size;
+	e->encap_header = encap_header;
 	e->flags |= MLX5_ENCAP_ENTRY_VALID;
 	mlx5e_rep_queue_neigh_stats_work(netdev_priv(attr.out_dev));
 	mlx5e_route_lookup_ipv4_put(&attr);
@@ -568,9 +567,6 @@ int mlx5e_tc_tun_create_header_ipv6(struct mlx5e_priv *priv,
 	if (err)
 		goto destroy_neigh_entry;
 
-	e->encap_size = ipv6_encap_size;
-	e->encap_header = encap_header;
-
 	if (!(nud_state & NUD_VALID)) {
 		neigh_event_send(attr.n, NULL);
 		/* the encap entry will be made valid on neigh update event
@@ -590,6 +586,8 @@ int mlx5e_tc_tun_create_header_ipv6(struct mlx5e_priv *priv,
 		goto destroy_neigh_entry;
 	}
 
+	e->encap_size = ipv6_encap_size;
+	e->encap_header = encap_header;
 	e->flags |= MLX5_ENCAP_ENTRY_VALID;
 	mlx5e_rep_queue_neigh_stats_work(netdev_priv(attr.out_dev));
 	mlx5e_route_lookup_ipv6_put(&attr);
-- 
2.41.0


  parent reply	other threads:[~2023-11-13 21:08 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-11-13 21:08 [pull request][net 00/17] mlx5 fixes 2023-11-13 Saeed Mahameed
2023-11-13 21:08 ` [net 01/17] Revert "net/mlx5: DR, Supporting inline WQE when possible" Saeed Mahameed
2023-11-13 21:08 ` [net 02/17] net/mlx5: Free used cpus mask when an IRQ is released Saeed Mahameed
2023-11-13 21:08 ` [net 03/17] net/mlx5: DR, Allow old devices to use multi destination FTE Saeed Mahameed
2023-11-13 21:08 ` [net 04/17] net/mlx5: Decouple PHC .adjtime and .adjphase implementations Saeed Mahameed
2023-11-13 21:08 ` Saeed Mahameed [this message]
2023-11-13 21:08 ` [net 06/17] net/mlx5e: fix double free of encap_header in update funcs Saeed Mahameed
2023-11-13 21:08 ` [net 07/17] net/mlx5e: Fix pedit endianness Saeed Mahameed
2023-11-13 21:08 ` [net 08/17] net/mlx5e: TC, Don't offload post action rule if not supported Saeed Mahameed
2023-11-13 21:08 ` [net 09/17] net/mlx5e: Don't modify the peer sent-to-vport rules for IPSec offload Saeed Mahameed
2023-11-13 21:08 ` [net 10/17] net/mlx5e: Avoid referencing skb after free-ing in drop path of mlx5e_sq_xmit_wqe Saeed Mahameed
2023-11-13 21:08 ` [net 11/17] net/mlx5e: Track xmit submission to PTP WQ after populating metadata map Saeed Mahameed
2023-11-13 21:08 ` [net 12/17] net/mlx5e: Update doorbell for port timestamping CQ before the software counter Saeed Mahameed
2023-11-13 21:08 ` [net 13/17] net/mlx5: Fix a NULL vs IS_ERR() check Saeed Mahameed
2023-11-13 21:08 ` [net 14/17] net/mlx5: Increase size of irq name buffer Saeed Mahameed
2023-11-13 21:08 ` [net 15/17] net/mlx5e: Reduce the size of icosq_str Saeed Mahameed
2023-11-13 21:08 ` [net 16/17] net/mlx5e: Check return value of snprintf writing to fw_version buffer Saeed Mahameed
2023-11-13 21:08 ` [net 17/17] net/mlx5e: Check return value of snprintf writing to fw_version buffer for representors Saeed Mahameed
2023-11-14  5:02 ` [pull request][net 00/17] mlx5 fixes 2023-11-13 Jakub Kicinski

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20231113210826.47593-6-saeed@kernel.org \
    --to=saeed@kernel.org \
    --cc=cruzzhao@linux.alibaba.com \
    --cc=davem@davemloft.net \
    --cc=dtcccc@linux.alibaba.com \
    --cc=dust.li@linux.alibaba.com \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=saeedm@nvidia.com \
    --cc=tariqt@nvidia.com \
    --cc=wojciech.drewek@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.