From: sashiko-bot@kernel.org
To: "Long Li" <longli@microsoft.com>
Cc: linux-hyperv@vger.kernel.org
Subject: Re: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild
Date: Fri, 14 Aug 2026 05:05:19 +0000 [thread overview]
Message-ID: <20260814050519.BE2051F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260813050418.2906468-12-longli@microsoft.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Medium] Desynchronization between `apc->indir_table_sz` and the actual heap allocation size of `apc->indir_table` during device reset leads to heap out-of-bounds read and write.
--
--- Patch [11]: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild ---
commit e2bf133521a3f8f376f19cc855758c1eb53a195b
Author: Long Li <longli@microsoft.com>
net: mana: keep a user-configured RSS table across a queue rebuild
A queue rebuild regenerates the RSS indirection table from the driver default.
This patch updates the driver to carry the user-configured table over instead
when the queue count is unchanged.
> diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
> index 7c43c2f9043ba..6e77b59cfcf90 100644
> --- a/drivers/net/ethernet/microsoft/mana/mana_en.c
> +++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
[ ... ]
> +static bool mana_rss_table_keep(struct mana_port_context *apc,
> + unsigned int num_queues, bool *lost)
> +{
> + u32 i;
> +
> + *lost = false;
> +
> + if (!netif_is_rxfh_configured(apc->ndev))
> + return false;
> +
> + for (i = 0; i < apc->indir_table_sz; i++) {
> + if (apc->indir_table[i] >= num_queues) {
[Severity: Medium]
This is a pre-existing issue, but can this loop perform an out-of-bounds
read on apc->indir_table?
During a device reset, mana_init_port() re-queries the hardware and updates
apc->indir_table_sz directly:
mana_init_port() {
...
err = mana_query_vport_cfg(apc, port_idx, &max_txq, &max_rxq,
&apc->indir_table_sz);
...
}
If the hardware returns a larger size than what was originally allocated
for apc->indir_table, does the driver reallocate the array to match the
new apc->indir_table_sz? If not, this loop might read past the end of
the existing heap allocation, which this patch extends into the new
mana_rss_table_keep() function.
> + *lost = true;
> + return false;
> + }
> + }
> +
> + return true;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813050418.2906468-1-longli@microsoft.com?part=11
next prev parent reply other threads:[~2026-08-14 5:05 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 5:04 [PATCH net-next v2 00/13] net: mana: reconfigure by replacing the queue set Long Li
2026-08-13 5:04 ` [PATCH net-next v2 01/13] net: mana: add queue-set allocation and teardown helpers Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 02/13] net: mana: swap queue sets in mana_set_channels Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 03/13] net: mana: swap queue sets in mana_set_ringparam Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 04/13] net: mana: swap queue sets in mana_set_priv_flags Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 05/13] net: mana: swap queue sets in mana_change_mtu Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 06/13] net: mana: swap queue sets in mana_xdp_set Long Li
2026-08-13 5:04 ` [PATCH net-next v2 07/13] net: mana: do not bail out of mana_detach on dealloc failure Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 08/13] net: mana: keep per-queue statistics in the port context Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 09/13] net: mana: share the EQ pool across a queue-set swap Long Li
2026-08-13 5:04 ` [PATCH net-next v2 10/13] net: mana: release EQs left idle by a channel-count reduction Long Li
2026-08-13 5:04 ` [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild Long Li
2026-08-14 5:05 ` sashiko-bot [this message]
2026-08-13 5:04 ` [PATCH net-next v2 12/13] net: mana: keep the surviving queues when the channel count is reduced Long Li
2026-08-13 5:04 ` [PATCH net-next v2 13/13] net: mana: keep the existing queues when the channel count is raised Long Li
-- strict thread matches above, loose matches on Subject: below --
2026-08-11 6:35 [PATCH net-next v2 01/13] net: mana: add queue-set allocation and teardown helpers Long Li
2026-08-11 6:35 ` [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild Long Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814050519.BE2051F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.