All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: anthony.l.nguyen@intel.com
Cc: Simon Horman <horms@kernel.org>,
	davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
	edumazet@google.com, andrew+netdev@lunn.ch,
	netdev@vger.kernel.org, larysa.zaremba@intel.com,
	przemyslaw.kitszel@intel.com, aleksander.lobakin@intel.com,
	sridhar.samudrala@intel.com, michal.swiatkowski@linux.intel.com,
	maciej.fijalkowski@intel.com, emil.s.tantilov@intel.com,
	madhu.chittim@intel.com, joshua.a.hay@intel.com,
	jacob.e.keller@intel.com, jayaprakash.shanmugam@intel.com,
	jiri@resnulli.us, corbet@lwn.net, richardcochran@gmail.com,
	skhan@linuxfoundation.org, linux-doc@vger.kernel.org,
	Bharath.r@intel.com
Subject: Re: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs
Date: Wed, 22 Jul 2026 17:13:52 +0100	[thread overview]
Message-ID: <20260722161352.543079-1-horms@kernel.org> (raw)
In-Reply-To: <20260715180042.1972010-9-anthony.l.nguyen@intel.com>

This is an AI-generated review of your patch. The human sending this
email has considered the AI review valid, or at least plausible.
https://sashiko.dev/#/patchset/20260715180042.1972010-2-anthony.l.nguyen@intel.com?part=8
---
--- Patch [8]: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs ---
commit 131cbea6d4e2fb71f297aa7df605c1576a8704cf
Author: Pavan Kumar Linga <pavan.kumar.linga@intel.com>
Subject: idpf: refactor idpf to use libie_pci APIs

This commit refactors the idpf driver to use the libie_pci initialization
and MMIO APIs. It updates register accesses across various components like
control queues and virtchnl messages to rely on the libie_ctlq_ctx
structure.

> diff --git a/drivers/net/ethernet/intel/idpf/idpf.h b/drivers/net/ethernet/intel/idpf/idpf.h
> index c5e47e79a6411..92a120aadfcd2 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf.h

[ ... ]

> @@ -945,7 +884,8 @@ static inline bool idpf_is_reset_detected(struct idpf_adapter *adapter)
>  	if (!adapter->hw.arq)
>  		return true;
>  
> -	return !(readl(idpf_get_mbx_reg_addr(adapter, adapter->hw.arq->reg.len)) &
> +	return !(readl(libie_pci_get_mmio_addr(&adapter->ctlq_ctx.mmio_info,
> +					       adapter->hw.arq->reg.len)) &
>  		 adapter->hw.arq->reg.len_mask);
>  }

[Severity: High]
This isn't a bug introduced by this patch, but does the transition to
libie_pci_get_mmio_addr() expose us to linked-list corruption here?

The old code performed an array access, but libie_pci_get_mmio_addr()
traverses the mmio_info->mmio_list. This traversal appears to be lockless
in asynchronous paths like idpf_is_reset_detected() in idpf.h and
idpf_ctlq_send() in idpf_controlq.c.

At the same time, driver teardown (idpf_remove) or hardware reset
(idpf_init_hard_reset) can call idpf_decfg_lan_memory_regions(), which
uses libie_pci_unmap_fltr_regs() to concurrently modify and free items
from this same list using list_del() and kvfree().

Since idpf_vc_xn_shutdown() doesn't wait for in-flight transactions
to drain, could a concurrent ethtool or interface operation preempt
during this list traversal and cause a use-after-free or list corruption?

> diff --git a/drivers/net/ethernet/intel/idpf/idpf_controlq.h b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> index de4ece40c2ff3..acf595e9265f5 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> @@ -109,8 +109,6 @@ struct idpf_mmio_reg {
>   * Align to ctlq_hw_info
>   */
>  struct idpf_hw {
> -	struct idpf_mmio_reg mbx;
> -	struct idpf_mmio_reg rstat;
>  	/* Array of remaining LAN BAR regions */
>  	int num_lan_regs;
>  	struct idpf_mmio_reg *lan_regs;

[Severity: Low]
Are these num_lan_regs and lan_regs fields still needed?

It looks like the new libie_pci API uses 
adapter->ctlq_ctx.mmio_info.mmio_list for LAN memory regions, and all
allocations and references to these array fields have been successfully
removed from the source files.

  parent reply	other threads:[~2026-07-22 16:14 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15 18:00 [PATCH net-next v5 00/15][pull request] Introduce iXD driver Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 01/15] virtchnl: move virtchnl and virtchnl2 headers to 'include/linux/net/intel' Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 02/15] libie: add PCI device initialization helpers to libie Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 03/15] libeth: allow to create fill queues without NAPI Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 04/15] libie: add control queue support Tony Nguyen
2026-07-20 16:17   ` Larysa Zaremba
2026-07-22 15:54   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 05/15] libie: add bookkeeping support for control queue messages Tony Nguyen
2026-07-20 16:07   ` Larysa Zaremba
2026-07-22 15:55   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 06/15] idpf: remove 'vport_params_reqd' field Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 07/15] idpf: remove unused code for getting RSS info from device Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs Tony Nguyen
2026-07-20 16:09   ` Larysa Zaremba
2026-07-22 16:13   ` Simon Horman [this message]
2026-07-15 18:00 ` [PATCH net-next v5 09/15] idpf: refactor idpf to use libie control queues Tony Nguyen
2026-07-20 16:11   ` Larysa Zaremba
2026-07-22 16:16   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 10/15] idpf: make mbx_task queueing and cancelling more consistent Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 11/15] idpf: print a debug message and bail in case of non-event ctlq message Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 12/15] ixd: add basic driver framework for Intel(R) Control Plane Function Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 13/15] ixd: add reset checks and initialize the mailbox Tony Nguyen
2026-07-22 16:17   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 14/15] ixd: add the core initialization Tony Nguyen
2026-07-20 16:14   ` Larysa Zaremba
2026-07-22 16:18   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 15/15] ixd: add devlink support Tony Nguyen
2026-07-20 16:24 ` [PATCH net-next v5 00/15][pull request] Introduce iXD driver Larysa Zaremba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722161352.543079-1-horms@kernel.org \
    --to=horms@kernel.org \
    --cc=Bharath.r@intel.com \
    --cc=aleksander.lobakin@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=corbet@lwn.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=emil.s.tantilov@intel.com \
    --cc=jacob.e.keller@intel.com \
    --cc=jayaprakash.shanmugam@intel.com \
    --cc=jiri@resnulli.us \
    --cc=joshua.a.hay@intel.com \
    --cc=kuba@kernel.org \
    --cc=larysa.zaremba@intel.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=maciej.fijalkowski@intel.com \
    --cc=madhu.chittim@intel.com \
    --cc=michal.swiatkowski@linux.intel.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=richardcochran@gmail.com \
    --cc=skhan@linuxfoundation.org \
    --cc=sridhar.samudrala@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.