From: sashiko-bot@kernel.org
To: "James Hilliard" <james.hilliard1@gmail.com>
Cc: linux-sunxi@lists.linux.dev, bpf@vger.kernel.org
Subject: Re: [PATCH net-next v5 17/19] net: stmmac: retain DMA memory until hardware shutdown completes
Date: Mon, 28 Sep 2026 22:00:28 +0000 [thread overview]
Message-ID: <20260928220028.D0DC51F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260927-submit-stmmac-reset-fixes-v1-v5-17-feec6c14dd06@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] stmmac: DMA ring bounds overflow due to missing END_RING bit
--
commit 36cb013886a764ed37b1ecca4a71af772e7620a5
Author: James Hilliard <james.hilliard1@gmail.com>
net: stmmac: retain DMA memory until hardware shutdown completes
This commit modifies the stmmac driver to retain DMA memory and configurations
until hardware shutdown completes. It adds idle wait checks for DMA engines
and defers error recovery to process context to prevent memory corruption
from in-flight frames after stop requests.
> diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
> index f5060924dae86..98dbc873e1c81 100644
> --- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
> +++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
[ ... ]
> +static int stmmac_reinit_dma_desc(struct stmmac_priv *priv)
> +{
[ ... ]
> + /* Writeback format contains status, not buffer addresses. Rebuild
> + * read format from software ownership before publishing any OWN.
> + */
> + memset(stmmac_get_rx_desc(priv, rx_q, 0), 0,
> + stmmac_get_rx_desc_size(priv) * dma_conf->dma_rx_size);
> + if (rx_q->xsk_pool) {
> + dma_free_rx_xskbufs(priv, dma_conf, queue);
> + /* Empty FILL rings are valid, including TX-only sockets. */
> + stmmac_alloc_rx_buffers_zc(priv, dma_conf, queue);
> + } else {
[ ... ]
> + if (priv->descriptor_mode == STMMAC_CHAIN_MODE)
> + stmmac_mode_init(priv, stmmac_get_rx_desc(priv, rx_q, 0),
> + rx_q->dma_rx_phy, dma_conf->dma_rx_size,
> + priv->extend_desc);
> +
> + dma_wmb();
> + for (i = 0; i < rx_q->buf_alloc_num; i++)
> + stmmac_init_rx_desc(priv, stmmac_get_rx_desc(priv, rx_q, i),
> + priv->use_riwt, priv->descriptor_mode,
> + i == dma_conf->dma_rx_size - 1,
> + dma_conf->dma_buf_sz);
[Severity: High]
Does this loop leave the end-of-ring marker uninitialized if the ring is only
partially filled?
When stmmac_reinit_dma_desc() is called to rebuild descriptors, such as
during a suspend and resume cycle, and the interface uses AF_XDP sockets in
ring mode, the fill ring might be partially populated or empty.
Because the preceding memset() zeroes the entire descriptor array, any
previous end-of-ring bits are erased. Since this loop terminates at
buf_alloc_num instead of dma_rx_size, the final descriptor boundary marker
is never set when buf_alloc_num is less than dma_rx_size.
If the socket later refills the remainder of the ring via
stmmac_rx_refill_zc(), it sets the ownership bit but not the end-of-ring bit.
Could this cause the hardware DMA engine to increment its ring pointer past
the end of the allocated ring buffer, leading to out-of-bounds memory
corruption?
> + }
> +
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260927-submit-stmmac-reset-fixes-v1-v5-0-feec6c14dd06@gmail.com?part=17
next prev parent reply other threads:[~2026-09-28 22:00 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 21:59 [PATCH net-next v5 00/19] net: stmmac: preserve datapath state across MTU and resume failures James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 01/19] net: stmmac: unwind the WoL IRQ after a safety IRQ request failure James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 02/19] net: stmmac: request the MDIO reset GPIO only once James Hilliard
2026-09-27 23:35 ` Linus Walleij
2026-09-27 23:49 ` James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 03/19] net: phylink: allow stopping a suspended instance James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 04/19] xsk: freeze deferred pool teardown during system sleep James Hilliard
2026-09-28 12:16 ` Björn Töpel
2026-09-27 21:59 ` [PATCH net-next v5 05/19] net: stmmac: embed struct stmmac_est in stmmac_priv struct James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 06/19] net: stmmac: pass the desired EST enable state to est_configure() James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 07/19] net: stmmac: re-apply taprio offload in __stmmac_open() and stmmac_resume() James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 08/19] net: stmmac: serialize and retain PHC configuration across reset James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 09/19] net: stmmac: leave the datapath running for normal-size MTU changes James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 10/19] net: stmmac: fix error path cleanup in DMA descriptor ring allocation James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 11/19] net: stmmac: complete DMA configuration allocation unwind James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 12/19] net: stmmac: keep DMA configurations at stable addresses James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 13/19] net: stmmac: track datapath and power ownership across failed reopening James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 14/19] net: stmmac: use the tracked datapath restart for XSK pool changes James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 15/19] net: stmmac: restore TC offloads before restarting DMA James Hilliard
2026-09-28 22:00 ` sashiko-bot
2026-09-27 21:59 ` [PATCH net-next v5 16/19] xsk: allow drivers to retain DMA mappings independently of pools James Hilliard
2026-09-28 12:22 ` Björn Töpel
2026-09-27 21:59 ` [PATCH net-next v5 17/19] net: stmmac: retain DMA memory until hardware shutdown completes James Hilliard
2026-09-28 22:00 ` sashiko-bot [this message]
2026-09-27 21:59 ` [PATCH net-next v5 18/19] net: stmmac: prepare device-local DMA interrupt quiescence James Hilliard
2026-09-27 21:59 ` [PATCH net-next v5 19/19] net: stmmac: retain DMA resources across MTU changes James Hilliard
2026-09-27 22:10 ` [PATCH net-next v5 00/19] net: stmmac: preserve datapath state across MTU and resume failures Jakub Kicinski
2026-09-27 23:15 ` James Hilliard
2026-09-28 6:50 ` Maxime Chevallier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928220028.D0DC51F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=james.hilliard1@gmail.com \
--cc=linux-sunxi@lists.linux.dev \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox