From: sashiko-bot@kernel.org
To: "Suraj Gupta" <suraj.gupta2@amd.com>
Cc: robh@kernel.org, conor+dt@kernel.org, devicetree@vger.kernel.org
Subject: Re: [PATCH net-next v2 6/7] net: xilinx: axienet: Dispatch statistics through axienet_config ops
Date: Fri, 07 Aug 2026 18:13:16 +0000 [thread overview]
Message-ID: <20260807181317.21E391F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260806181153.1213996-7-suraj.gupta2@amd.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] `axienet_1g_get_ethtool_stats` writes hardware statistics out-of-bounds of the `data` array allocated by the ethtool core.
--
--- Patch [6]: [PATCH net-next v2 6/7] net: xilinx: axienet: Dispatch statistics through axienet_config ops ---
commit dd40493ec0a25e2800677d93923a2097ca0c48e3
Author: Suraj Gupta <suraj.gupta2@amd.com>
net: xilinx: axienet: Dispatch statistics through axienet_config ops
The commit refactors hardware statistic callbacks to use function pointers
in struct axienet_config. This avoids conditional branching for different
MAC types by populating operations like get_ethtool_stats via an
axienet_1g_config structure.
> diff --git a/drivers/net/ethernet/xilinx/xilinx_axienet_main.c b/drivers/net/ethernet/xilinx/xilinx_axienet_main.c
> index 1892d87ebaaea..6e4b3a073e733 100644
> --- a/drivers/net/ethernet/xilinx/xilinx_axienet_main.c
> +++ b/drivers/net/ethernet/xilinx/xilinx_axienet_main.c
[ ... ]
> @@ -2360,11 +2369,8 @@ static int axienet_ethtools_nway_reset(struct net_device *dev)
> return phylink_ethtool_nway_reset(lp->phylink);
> }
>
> -static void axienet_ethtools_get_ethtool_stats(struct net_device *dev,
> - struct ethtool_stats *stats,
> - u64 *data)
> +static void axienet_1g_get_ethtool_stats(struct axienet_local *lp, u64 *data)
> {
> - struct axienet_local *lp = netdev_priv(dev);
> unsigned int start;
>
> do {
[Severity: High]
This isn't a bug introduced by this patch, but does this function write
hardware statistics out-of-bounds of the data array allocated by the ethtool
core?
The ethtool core allocates memory based on axienet_1g_get_sset_count, which
returns 9 for the size of axienet_ethtool_stats_strings. However, this
function writes to data[8], data[9], and data[10], skipping data[4] and
data[5]:
axienet_1g_get_ethtool_stats() {
...
data[7] = axienet_stat(lp, STAT_RX_PFC_FRAMES);
data[8] = axienet_stat(lp, STAT_USER_DEFINED0);
data[9] = axienet_stat(lp, STAT_USER_DEFINED1);
data[10] = axienet_stat(lp, STAT_USER_DEFINED2);
...
}
Could this lead to a heap buffer overflow and memory corruption when a user
requests statistics with ethtool -S?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260806181153.1213996-1-suraj.gupta2@amd.com?part=6
next prev parent reply other threads:[~2026-08-07 18:13 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 12:38 [PATCH net-next 0/7] net: xilinx: axienet: Add 10G/25G (XXV) ethernet support Suraj Gupta
2026-07-23 12:38 ` [PATCH net-next 1/7] clk: Add devm_clk_bulk_get_enable() Suraj Gupta
2026-07-23 15:04 ` Brian Masney
2026-07-24 14:17 ` sashiko-bot
2026-07-23 12:38 ` [PATCH net-next 2/7] net: xilinx: axienet: Introduce axienet_config for MAC-specific ops Suraj Gupta
2026-07-24 14:17 ` sashiko-bot
2026-07-23 12:38 ` [PATCH net-next 3/7] dt-bindings: net: xlnx,axi-ethernet: Add 10G/25G (XXV) ethernet Suraj Gupta
2026-07-24 13:16 ` Rob Herring (Arm)
2026-07-28 13:56 ` Rob Herring
2026-07-23 12:38 ` [PATCH net-next 4/7] net: xilinx: axienet: Add 10G/25G (XXV) ethernet support Suraj Gupta
2026-07-24 14:17 ` sashiko-bot
2026-07-23 12:38 ` [PATCH net-next 5/7] net: xilinx: axienet: Make axienet_rmon_ranges non-static for reuse Suraj Gupta
2026-07-23 12:38 ` [PATCH net-next 6/7] net: xilinx: axienet: Dispatch statistics through axienet_config ops Suraj Gupta
2026-07-24 14:17 ` sashiko-bot
2026-07-23 12:38 ` [PATCH net-next 7/7] net: xilinx: axienet: Add statistics support for XXV ethernet Suraj Gupta
2026-08-06 18:11 ` [PATCH net-next v2 0/7] net: xilinx: axienet: Add 10G/25G (XXV) ethernet support Suraj Gupta
2026-08-06 18:11 ` [PATCH net-next v2 1/7] clk: Add devm_clk_bulk_get_enable() Suraj Gupta
2026-08-07 18:13 ` sashiko-bot
2026-08-06 18:11 ` [PATCH net-next v2 2/7] net: xilinx: axienet: Introduce axienet_config for MAC-specific ops Suraj Gupta
2026-08-07 18:13 ` sashiko-bot
2026-08-06 18:11 ` [PATCH net-next v2 3/7] dt-bindings: net: xlnx,xxv-ethernet: Add Xilinx XXV 10G/25G Ethernet Suraj Gupta
2026-08-12 3:09 ` Rob Herring (Arm)
2026-08-06 18:11 ` [PATCH net-next v2 4/7] net: xilinx: axienet: Add 10G/25G (XXV) ethernet support Suraj Gupta
2026-08-07 18:13 ` sashiko-bot
2026-08-06 18:11 ` [PATCH net-next v2 5/7] net: xilinx: axienet: Make axienet_rmon_ranges non-static for reuse Suraj Gupta
2026-08-06 18:11 ` [PATCH net-next v2 6/7] net: xilinx: axienet: Dispatch statistics through axienet_config ops Suraj Gupta
2026-08-07 18:13 ` sashiko-bot [this message]
2026-08-06 18:11 ` [PATCH net-next v2 7/7] net: xilinx: axienet: Add statistics support for XXV ethernet Suraj Gupta
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260807181317.21E391F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=suraj.gupta2@amd.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.