From: sashiko-bot@kernel.org
To: "Daniel Zahka" <daniel.zahka@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next v2 5/8] eth: mpnic: start and stop the Tx HW queues
Date: Sat, 26 Sep 2026 00:36:00 +0000 [thread overview]
Message-ID: <20260926003601.14DA31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924-linux-mpnic-v2-5-4badc9b58b9e@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] eth: mpnic: swallowed queue idle timeout allows DMA UAF
--
commit 9b058fd2b1d09b6f8ce72863ddb8a3c9c658d5a3
Author: Daniel Zahka <daniel.zahka@gmail.com>
eth: mpnic: start and stop the Tx HW queues
This commit adds the routines to start and stop the transmit hardware queues
for the mpnic device. It provides functions to point the hardware at the
descriptor rings and wait for the DMA engines to become idle during teardown.
> diff --git a/drivers/net/ethernet/meta/mpnic/mpnic_txrx.c b/drivers/net/ethernet/meta/mpnic/mpnic_txrx.c
> index 853976e11b032..aaa3a3e99a138 100644
> --- a/drivers/net/ethernet/meta/mpnic/mpnic_txrx.c
> +++ b/drivers/net/ethernet/meta/mpnic/mpnic_txrx.c
[ ... ]
> +void mpnic_wait_all_queues_idle(struct mpnic_dev *mpd)
> +{
> + static const struct mpnic_idle_regs queues[] = {
> + { MPNIC_TWQ_IDLE(0), MPNIC_TWQ_IDLE_CNT, "TWQ" },
> + { MPNIC_TQS_IDLE(0), MPNIC_TQS_IDLE_CNT, "TQS" },
> + { MPNIC_TDE_IDLE(0), MPNIC_TDE_IDLE_CNT, "TDE" },
> + { MPNIC_TCQ_IDLE(0), MPNIC_TCQ_IDLE_CNT, "TCQ" },
> + };
> + u32 non_idle_bitmap;
> + int err;
> +
> + err = read_poll_timeout(mpnic_non_idle_queues, non_idle_bitmap,
> + !non_idle_bitmap, 20, 500000, false, mpd,
> + queues, ARRAY_SIZE(queues));
> + if (err)
> + mpnic_idle_dump(mpd, queues, ARRAY_SIZE(queues),
> + non_idle_bitmap, err);
[Severity: High]
Does this code silently ignore the timeout from read_poll_timeout()?
If the hardware is stalled or under heavy load, read_poll_timeout() times out
after 500ms. Because mpnic_wait_all_queues_idle() returns void, it logs the
error but hides it from the caller during interface teardown.
Could the caller blindly proceed to free the ring memory back to the page
allocator while the active hardware is still performing DMA transfers into it,
causing a DMA use-after-free?
Should the error be propagated so the driver can leak the memory or trigger
a hardware reset rather than risking memory corruption?
> +}
> +
> +void mpnic_flush(struct mpnic_net *mpn)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260924-linux-mpnic-v2-0-4badc9b58b9e@gmail.com?part=5
next prev parent reply other threads:[~2026-09-26 0:36 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 0:35 [PATCH net-next v2 0/8] eth: mpnic: initial support for Meta Platforms NIC Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 1/8] eth: mpnic: add scaffolding " Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 12:13 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 2/8] eth: mpnic: add register init for the device Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 12:14 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 3/8] eth: mpnic: allocate MSI-X vectors Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 16:01 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 4/8] eth: mpnic: implement Tx queue allocation and cleanup Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 14:46 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 5/8] eth: mpnic: start and stop the Tx HW queues Daniel Zahka
2026-09-26 0:36 ` sashiko-bot [this message]
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:00 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 6/8] eth: mpnic: add a netdevice and basic Tx handling Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:10 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 7/8] eth: mpnic: implement Rx queue allocation and cleanup Daniel Zahka
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:11 ` Daniel Zahka
2026-09-25 0:35 ` [PATCH net-next v2 8/8] eth: mpnic: add basic Rx handling Daniel Zahka
2026-09-26 0:36 ` sashiko-bot
2026-09-28 0:01 ` netdev-bot+sashiko
2026-09-28 15:17 ` Daniel Zahka
2026-09-29 2:03 ` Jakub Kicinski
2026-09-28 18:16 ` [PATCH net-next v2 0/8] eth: mpnic: initial support for Meta Platforms NIC Daniel Zahka
2026-09-29 8:50 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926003601.14DA31F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel.zahka@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.