From: Jakub Kicinski <kuba@kernel.org>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, edumazet@google.com, pabeni@redhat.com,
andrew+netdev@lunn.ch, horms@kernel.org,
florian.fainelli@broadcom.com, jonas.gorski@gmail.com,
andrew@lunn.ch, olteanv@gmail.com,
Jakub Kicinski <kuba@kernel.org>, VEGA <vega@nebusec.ai>,
leitao@debian.org, louis.peens@corigine.com,
yinjun.zhang@corigine.com, oss-drivers@corigine.com
Subject: [PATCH net 2/5] eth: nfp: bound the ntuple rule dump by the caller's buffer size
Date: Wed, 2 Sep 2026 20:26:08 -0700 [thread overview]
Message-ID: <20260903032611.3000029-3-kuba@kernel.org> (raw)
In-Reply-To: <20260903032611.3000029-1-kuba@kernel.org>
nfp_net_get_fs_loc() dumps every entry of nn->fs.list into rule_locs[]
without consulting cmd->rule_cnt, which is how many entries the caller
had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the
ioctl sizes the buffer from the rule_cnt userspace passes in, so once an
admin has installed flow steering rules any user can ask for fewer slots
than there are rules and run off the end of the allocation. A rule_cnt
of 0 leaves the buffer pointer NULL and the walk dereferences it.
Bail out with -EMSGSIZE when the buffer fills up, the way the other
ntuple capable drivers do, and report how many locations were filled so
a shrinking rule list does not leave the caller reading stale slots.
Reported-by: VEGA <vega@nebusec.ai>
Fixes: 9eb03bb1c035 ("nfp: add ethtool flow steering callbacks")
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
---
CC: leitao@debian.org
CC: louis.peens@corigine.com
CC: yinjun.zhang@corigine.com
CC: oss-drivers@corigine.com
---
drivers/net/ethernet/netronome/nfp/nfp_net_ethtool.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/netronome/nfp/nfp_net_ethtool.c b/drivers/net/ethernet/netronome/nfp/nfp_net_ethtool.c
index a2a89d48e3ca..9419e1ed8466 100644
--- a/drivers/net/ethernet/netronome/nfp/nfp_net_ethtool.c
+++ b/drivers/net/ethernet/netronome/nfp/nfp_net_ethtool.c
@@ -1421,7 +1421,8 @@ static int nfp_net_get_fs_rule(struct nfp_net *nn, struct ethtool_rxnfc *cmd)
return -ENOENT;
}
-static int nfp_net_get_fs_loc(struct nfp_net *nn, u32 *rule_locs)
+static int nfp_net_get_fs_loc(struct nfp_net *nn, struct ethtool_rxnfc *cmd,
+ u32 *rule_locs)
{
struct nfp_fs_entry *entry;
u32 count = 0;
@@ -1429,8 +1430,12 @@ static int nfp_net_get_fs_loc(struct nfp_net *nn, u32 *rule_locs)
if (!(nn->cap_w1 & NFP_NET_CFG_CTRL_FLOW_STEER))
return -EOPNOTSUPP;
- list_for_each_entry(entry, &nn->fs.list, node)
+ list_for_each_entry(entry, &nn->fs.list, node) {
+ if (count == cmd->rule_cnt)
+ return -EMSGSIZE;
rule_locs[count++] = entry->loc;
+ }
+ cmd->rule_cnt = count;
return 0;
}
@@ -1455,7 +1460,7 @@ static int nfp_net_get_rxnfc(struct net_device *netdev,
return nfp_net_get_fs_rule(nn, cmd);
case ETHTOOL_GRXCLSRLALL:
cmd->data = NFP_FS_MAX_ENTRY;
- return nfp_net_get_fs_loc(nn, rule_locs);
+ return nfp_net_get_fs_loc(nn, cmd, rule_locs);
default:
return -EOPNOTSUPP;
}
--
2.55.0
next prev parent reply other threads:[~2026-09-03 3:26 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 3:26 [PATCH net 0/5] eth: fix bugs in ntuple filter reporting Jakub Kicinski
2026-09-03 3:26 ` [PATCH net 1/5] net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size Jakub Kicinski
2026-09-03 8:30 ` Jonas Gorski
2026-09-03 15:24 ` Florian Fainelli
2026-09-03 20:12 ` Joe Damato
2026-09-03 3:26 ` Jakub Kicinski [this message]
2026-09-03 20:14 ` [PATCH net 2/5] eth: nfp: bound the ntuple " Joe Damato
2026-09-03 3:26 ` [PATCH net 3/5] eth: nfp: drop the replaced rule from the list when reprogramming fails Jakub Kicinski
2026-09-03 20:32 ` Joe Damato
2026-09-03 3:26 ` [PATCH net 4/5] net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size Jakub Kicinski
2026-09-03 20:20 ` Joe Damato
2026-09-03 3:26 ` [PATCH net 5/5] ethtool: document that GRXCLSRLALL rule_cnt is a caller-provided limit Jakub Kicinski
2026-09-03 20:16 ` Joe Damato
2026-09-04 22:30 ` [PATCH net 0/5] eth: fix bugs in ntuple filter reporting patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903032611.3000029-3-kuba@kernel.org \
--to=kuba@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=andrew@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=florian.fainelli@broadcom.com \
--cc=horms@kernel.org \
--cc=jonas.gorski@gmail.com \
--cc=leitao@debian.org \
--cc=louis.peens@corigine.com \
--cc=netdev@vger.kernel.org \
--cc=olteanv@gmail.com \
--cc=oss-drivers@corigine.com \
--cc=pabeni@redhat.com \
--cc=vega@nebusec.ai \
--cc=yinjun.zhang@corigine.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.