All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: wei.fang@oss.nxp.com
Cc: Frank.Li@kernel.org, imx@lists.linux.dev
Subject: Re: [PATCH RESEND v4 net-next 14/14] net: enetc: use kzalloc_flex() for enetc_psfp_gate allocation
Date: Tue, 21 Jul 2026 02:13:33 +0000	[thread overview]
Message-ID: <20260721021333.621631F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260720014317.1059359-15-wei.fang@oss.nxp.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] List modifications in enetc_psfp_destroy_clsflower lack spinlock protection, leading to race conditions and potential Use-After-Free.
--

--- Patch [14]: [PATCH RESEND v4 net-next 14/14] net: enetc: use kzalloc_flex() for enetc_psfp_gate allocation ---
commit ac1613be27ea215665e4d0f49e1b480f054aa27f
Author: Wei Fang <wei.fang@nxp.com>

net: enetc: use kzalloc_flex() for enetc_psfp_gate allocation

This commit replaces the open-coded struct_size() + kzalloc() pattern with
the kzalloc_flex() helper when allocating struct enetc_psfp_gate. This
removes the intermediate entries_size local variable.

> diff --git a/drivers/net/ethernet/freescale/enetc/enetc_qos.c b/drivers/net/ethernet/freescale/enetc/enetc_qos.c
> index 7b17bca24f260..2aa0fcaafcd23 100644
> --- a/drivers/net/ethernet/freescale/enetc/enetc_qos.c
> +++ b/drivers/net/ethernet/freescale/enetc/enetc_qos.c

[ ... ]

> @@ -1242,8 +1241,7 @@ static int enetc_psfp_parse_clsflower(struct enetc_ndev_priv *priv,
>  		goto free_filter;
>  	}
>  
> -	entries_size = struct_size(sgi, entries, entryg->gate.num_entries);
> -	sgi = kzalloc(entries_size, GFP_KERNEL);
> +	sgi = kzalloc_flex(*sgi, entries, entryg->gate.num_entries);

[Severity: High]
This is a pre-existing issue, but is it possible for concurrent TC commands
to cause a use-after-free with the shared epsfp lists?

In enetc_psfp_destroy_clsflower(), remove_one_chain() is called:

    remove_one_chain(priv, filter);

This executes hlist_del(&filter->node) and kfree(filter) on the globally
shared epsfp.stream_list without acquiring epsfp.psfp_lock.

Concurrently, enetc_psfp_get_stats() iterates this list locklessly:

    filter = enetc_get_stream_by_index(f->common.chain_index);

If a user issues "tc -s filter show" concurrently with "tc filter del",
could the lockless iteration in enetc_psfp_get_stats() access the filter
freed by remove_one_chain(), leading to memory corruption?

Additionally, does the unlocked deletion race with locked insertions in
enetc_psfp_parse_clsflower() causing list corruption?

>  	if (!sgi) {
>  		err = -ENOMEM;
>  		goto free_filter;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260720014317.1059359-1-wei.fang@oss.nxp.com?part=14

      parent reply	other threads:[~2026-07-21  2:13 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20  1:43 [PATCH RESEND v4 net-next 00/14] net: enetc: cleanups and improvements wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 01/14] net: enetc: extract common helpers for MAC promiscuous mode setting wei.fang
2026-07-20 14:02   ` Joe Damato
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 02/14] net: enetc: extract common helpers for MAC hash filter configuration wei.fang
2026-07-21  2:13   ` sashiko-bot
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 03/14] net: enetc: convert ndo_set_rx_mode() to ndo_set_rx_mode_async() wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 04/14] net: enetc: improve MAFT entry management with bitmap tracking wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 05/14] net: enetc: use PCI device name for debugfs directory wei.fang
2026-07-20 13:46   ` Joe Damato
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 06/14] net: enetc: simplify enetc4_set_port_speed() wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 07/14] net: enetc: differentiate phylink capabilities for pseudo-MAC and standalone MAC wei.fang
2026-07-21  2:13   ` sashiko-bot
2026-07-21  5:46     ` Wei Fang (OSS)
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 08/14] net: enetc: remove invalid code from enetc4_pl_mac_link_up() wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 09/14] net: enetc: open-code enetc4_set_default_si_vlan_promisc() wei.fang
2026-07-20 15:26   ` Joe Damato
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 10/14] net: enetc: refactor SI VLAN promiscuous mode configuration wei.fang
2026-07-22 13:25   ` Joe Damato
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 11/14] net: enetc: move enetc_set_si_vlan_promisc() to enetc_pf_common.c wei.fang
2026-07-20 15:28   ` Joe Damato
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 12/14] net: enetc: remove redundant num_vsi field from enetc_port_caps wei.fang
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 13/14] net: enetc: use alloc_etherdev_mqs() to create netdev for VF driver wei.fang
2026-07-20 17:36   ` Joe Damato
2026-07-21  2:01     ` Wei Fang (OSS)
2026-07-21  2:13   ` sashiko-bot
2026-07-21  5:54     ` Wei Fang (OSS)
2026-07-20  1:43 ` [PATCH RESEND v4 net-next 14/14] net: enetc: use kzalloc_flex() for enetc_psfp_gate allocation wei.fang
2026-07-20 13:48   ` Joe Damato
2026-07-21  2:13   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260721021333.621631F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=Frank.Li@kernel.org \
    --cc=imx@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wei.fang@oss.nxp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.