All of lore.kernel.org
 help / color / mirror / Atom feed
From: Leon Romanovsky <leon@kernel.org>
To: Ding Hui <dinghui@sangfor.com.cn>
Cc: Kalesh Anakkur Purayil <kalesh-anakkur.purayil@broadcom.com>,
	selvin.xavier@broadcom.com, jgg@ziepe.ca,
	saravanan.vajravel@broadcom.com,
	vasuthevan.maheswaran@broadcom.com, linux-rdma@vger.kernel.org,
	linux-kernel@vger.kernel.org, zhengyingying@sangfor.com.cn
Subject: Re: [RFC PATCH] RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats()
Date: Mon, 22 Dec 2025 10:56:27 +0200	[thread overview]
Message-ID: <20251222085627.GB13529@unreal> (raw)
In-Reply-To: <51ecb35a-4caf-43c6-b5ac-bc4b94462577@sangfor.com.cn>

On Mon, Dec 22, 2025 at 02:33:59PM +0800, Ding Hui wrote:
> On 2025/12/21 23:47, Kalesh Anakkur Purayil wrote:
> > On Mon, Dec 8, 2025 at 12:52 PM Ding Hui <dinghui@sangfor.com.cn> wrote:
> > > 
> > > Recently we encountered an OOB write issue on BCM957414A4142CC with outbox
> > > NetXtreme-E-235.1.160.0 driver from broadcom. After a litte research,
> > > we found the inbox driver from upstream maybe have the same issue.
> > > 
> > > The commit ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters
> > > update") introduced 3 counters, and appended after BNXT_RE_OUT_OF_SEQ_ERR.
> > > 
> > > However, BNXT_RE_OUT_OF_SEQ_ERR serves as a boundary marker for allocating
> > > hw stats with different num_counters for chip_gen_p5_p7 hardware.
> > > 
> > > For BNXT_RE_NUM_STD_COUNTERS allocated hw_stats, leading to an
> > > out-of-bounds write in bnxt_re_copy_err_stats().
> > > 
> > > It seems like that the BNXT_RE_REQ_CQE_ERROR, BNXT_RE_RESP_CQE_ERROR,
> > > and BNXT_RE_RESP_REMOTE_ACCESS_ERRS can be updated for generic hardware,
> > > not only for p5/p7 hardware.
> > > 
> > > Fix this by moving them before BNXT_RE_OUT_OF_SEQ_ERR so they become
> > > part of the generic counter.
> > > 
> > > Compile tested only.
> > > 
> > > Fixes: ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters update")
> > > Reported-by: Yingying Zheng <zhengyingying@sangfor.com.cn>
> > > Signed-off-by: Ding Hui <dinghui@sangfor.com.cn>
> > 
> > Thank you Ding, the fix looks good to me and I have verified it locally.
> > 
> 
> Thanks for confirming.
> 
> Do I need to resend the patch without RFC prefix and update some commit log,
> such as getting rid of the first paragraph about the outbox driver?

No, there is no need. I'll fix it locally.

Thanks

> 
> > Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
> > Tested-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
> > 
> 
> -- 
> Thanks,
> - Ding Hui
> 

  reply	other threads:[~2025-12-22  8:56 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-12-08  7:21 [RFC PATCH] RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats() Ding Hui
2025-12-18  2:16 ` Ding Hui
2025-12-21  8:00   ` Leon Romanovsky
2025-12-21 11:18     ` Kalesh Anakkur Purayil
2025-12-21 15:47 ` Kalesh Anakkur Purayil
2025-12-22  6:33   ` Ding Hui
2025-12-22  8:56     ` Leon Romanovsky [this message]
2025-12-22  8:58 ` Leon Romanovsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251222085627.GB13529@unreal \
    --to=leon@kernel.org \
    --cc=dinghui@sangfor.com.cn \
    --cc=jgg@ziepe.ca \
    --cc=kalesh-anakkur.purayil@broadcom.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=saravanan.vajravel@broadcom.com \
    --cc=selvin.xavier@broadcom.com \
    --cc=vasuthevan.maheswaran@broadcom.com \
    --cc=zhengyingying@sangfor.com.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.