All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ratheesh Kannoth" <rkannoth@marvell.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH v12 net-next] octeontx2-pf: add mqprio bandwidth offload for NIX TX schedulers
Date: Fri, 04 Sep 2026 02:34:18 +0000	[thread overview]
Message-ID: <20260904023419.055601F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903023324.3078284-1-rkannoth@marvell.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Divide-by-zero in SMQ lookup during MQPRIO rollback
--

commit ba1788f860ad0c3ea2631aca0bfc1b979830add7
Author: Ratheesh Kannoth <rkannoth@marvell.com>
Subject: octeontx2-pf: add mqprio bandwidth offload for NIX TX schedulers

This commit adds TC_SETUP_QDISC_MQPRIO offload for channel-mode mqprio using
the NIX TX scheduler mailbox. It programs per-queue MDQ shapers and handles
mqprio setup, replacement, and teardown by restarting the netdev and
caching active rates.

> diff --git a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
> --- a/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
> +++ b/drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c
[ ... ]
> +static int otx2_mqprio_restore_old(struct otx2_nic *pfvf)
> +{
[ ... ]
> +	if (otx2_mqprio_mdq_allocated(pfvf)) {
> +		err = otx2_nix_tm_clear_queue_shaper(pfvf);
> +		if (err)
> +			return err;
> +	}
> +
> +	/* otx2_mqprio_restart_netdev() clears rate_limit when ndo_open() fails. */
> +	pfvf->mqprio.rate_limit = true;
> +
> +	err = otx2_mqprio_up(pfvf);

[Severity: High]
Can this lead to a divide-by-zero if ndo_open() fails during the replacement?

In otx2_setup_tc_mqprio(), if otx2_mqprio_restart_netdev() fails (e.g., due
to an allocation failure), the interface is left stopped and the TX schedulers
are freed, setting pfvf->hw.txschq_cnt[NIX_TXSCH_LVL_SMQ] to 0.

The error path then calls this function, otx2_mqprio_restore_old(), which
unconditionally sets rate_limit to true and calls otx2_mqprio_up() to restore
the shapers.

otx2_mqprio_up() calls otx2_nix_tm_set_queue_shaper(), which eventually
invokes otx2_get_smq_idx():

otx2_common.h:otx2_get_smq_idx() {
    ...
    idx = qidx % pfvf->hw.txschq_cnt[NIX_TXSCH_LVL_SMQ];
    smq = pfvf->hw.txschq_list[NIX_TXSCH_LVL_SMQ][idx];
    ...
}

Since txschq_cnt is 0, won't this cause a divide-by-zero panic, or silently
evaluate to an out-of-bounds index on architectures that do not trap on
integer division, leading to malformed configuration commands being sent
to the hardware?

> +	if (err)
> +		return err;
> +
> +	otx2_mqprio_snap_free(pfvf, &pfvf->cur_mq_snap);
> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903023324.3078284-1-rkannoth@marvell.com?part=1

  reply	other threads:[~2026-09-04  2:34 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  2:33 [PATCH v12 net-next] octeontx2-pf: add mqprio bandwidth offload for NIX TX schedulers Ratheesh Kannoth
2026-09-04  2:34 ` sashiko-bot [this message]
2026-09-04  3:12 ` Ratheesh Kannoth
2026-09-04 21:21   ` Jakub Kicinski
2026-09-08  8:34 ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260904023419.055601F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=rkannoth@marvell.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.