From: Leon Romanovsky <leon@kernel.org>
To: Ding Hui <dinghui@sangfor.com.cn>,
selvin.xavier@broadcom.com, kalesh-anakkur.purayil@broadcom.com,
saravanan.vajravel@broadcom.com,
vasuthevan.maheswaran@broadcom.com
Cc: linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org,
zhengyingying@sangfor.com.cn, jgg@ziepe.ca
Subject: Re: [RFC PATCH] RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats()
Date: Sun, 21 Dec 2025 10:00:59 +0200 [thread overview]
Message-ID: <20251221080059.GB13030@unreal> (raw)
In-Reply-To: <022b32b6-6ed5-465d-af01-a52deea16d62@sangfor.com.cn>
On Thu, Dec 18, 2025 at 10:16:02AM +0800, Ding Hui wrote:
> Friendly ping.
I'm waiting for some sort of response from Broadcom people.
Thanks
>
> On 2025/12/8 15:21, Ding Hui wrote:
> > Recently we encountered an OOB write issue on BCM957414A4142CC with outbox
> > NetXtreme-E-235.1.160.0 driver from broadcom. After a litte research,
> > we found the inbox driver from upstream maybe have the same issue.
> >
> > The commit ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters
> > update") introduced 3 counters, and appended after BNXT_RE_OUT_OF_SEQ_ERR.
> >
> > However, BNXT_RE_OUT_OF_SEQ_ERR serves as a boundary marker for allocating
> > hw stats with different num_counters for chip_gen_p5_p7 hardware.
> >
> > For BNXT_RE_NUM_STD_COUNTERS allocated hw_stats, leading to an
> > out-of-bounds write in bnxt_re_copy_err_stats().
> >
> > It seems like that the BNXT_RE_REQ_CQE_ERROR, BNXT_RE_RESP_CQE_ERROR,
> > and BNXT_RE_RESP_REMOTE_ACCESS_ERRS can be updated for generic hardware,
> > not only for p5/p7 hardware.
> >
> > Fix this by moving them before BNXT_RE_OUT_OF_SEQ_ERR so they become
> > part of the generic counter.
> >
> > Compile tested only.
> >
> > Fixes: ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters update")
> > Reported-by: Yingying Zheng <zhengyingying@sangfor.com.cn>
> > Signed-off-by: Ding Hui <dinghui@sangfor.com.cn>
> > ---
> > drivers/infiniband/hw/bnxt_re/hw_counters.h | 6 +++---
> > 1 file changed, 3 insertions(+), 3 deletions(-)
> >
> > diff --git a/drivers/infiniband/hw/bnxt_re/hw_counters.h b/drivers/infiniband/hw/bnxt_re/hw_counters.h
> > index 09d371d442aa..cebec033f4a0 100644
> > --- a/drivers/infiniband/hw/bnxt_re/hw_counters.h
> > +++ b/drivers/infiniband/hw/bnxt_re/hw_counters.h
> > @@ -89,6 +89,9 @@ enum bnxt_re_hw_stats {
> > BNXT_RE_RES_SRQ_LOAD_ERR,
> > BNXT_RE_RES_TX_PCI_ERR,
> > BNXT_RE_RES_RX_PCI_ERR,
> > + BNXT_RE_REQ_CQE_ERROR,
> > + BNXT_RE_RESP_CQE_ERROR,
> > + BNXT_RE_RESP_REMOTE_ACCESS_ERRS,
> > BNXT_RE_OUT_OF_SEQ_ERR,
> > BNXT_RE_TX_ATOMIC_REQ,
> > BNXT_RE_TX_READ_REQ,
> > @@ -110,9 +113,6 @@ enum bnxt_re_hw_stats {
> > BNXT_RE_TX_CNP,
> > BNXT_RE_RX_CNP,
> > BNXT_RE_RX_ECN,
> > - BNXT_RE_REQ_CQE_ERROR,
> > - BNXT_RE_RESP_CQE_ERROR,
> > - BNXT_RE_RESP_REMOTE_ACCESS_ERRS,
> > BNXT_RE_NUM_EXT_COUNTERS
> > };
>
> --
> Thanks,
> - Ding Hui
>
>
next prev parent reply other threads:[~2025-12-21 8:01 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-12-08 7:21 [RFC PATCH] RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats() Ding Hui
2025-12-18 2:16 ` Ding Hui
2025-12-21 8:00 ` Leon Romanovsky [this message]
2025-12-21 11:18 ` Kalesh Anakkur Purayil
2025-12-21 15:47 ` Kalesh Anakkur Purayil
2025-12-22 6:33 ` Ding Hui
2025-12-22 8:56 ` Leon Romanovsky
2025-12-22 8:58 ` Leon Romanovsky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251221080059.GB13030@unreal \
--to=leon@kernel.org \
--cc=dinghui@sangfor.com.cn \
--cc=jgg@ziepe.ca \
--cc=kalesh-anakkur.purayil@broadcom.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rdma@vger.kernel.org \
--cc=saravanan.vajravel@broadcom.com \
--cc=selvin.xavier@broadcom.com \
--cc=vasuthevan.maheswaran@broadcom.com \
--cc=zhengyingying@sangfor.com.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.