From mboxrd@z Thu Jan 1 00:00:00 1970 From: John Daley Subject: [PATCH v4 1/2] enic: fix seg fault when releasing queues Date: Sat, 11 Jun 2016 10:27:04 -0700 Message-ID: <1465666025-10159-1-git-send-email-johndale@cisco.com> References: <20160610092236.GA11860@bricha3-MOBL3> Cc: dev@dpdk.org, John Daley To: bruce.richardson@intel.com Return-path: Received: from alln-iport-7.cisco.com (alln-iport-7.cisco.com [173.37.142.94]) by dpdk.org (Postfix) with ESMTP id 55A1B2C64 for ; Sat, 11 Jun 2016 19:27:40 +0200 (CEST) In-Reply-To: <20160610092236.GA11860@bricha3-MOBL3> List-Id: patches and discussions about DPDK List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" If device configuration failed due to a lack of resources, such as if more queues are requested than are available, the queue release functions are called with NULL pointers which were being dereferenced. Skip releasing queues if they are NULL pointers. Fixes: fefed3d1e62c ("enic: new driver") Signed-off-by: John Daley --- v4: fix check for NULL before pointer is set drivers/net/enic/enic_main.c | 18 ++++++++++++++---- 1 file changed, 14 insertions(+), 4 deletions(-) diff --git a/drivers/net/enic/enic_main.c b/drivers/net/enic/enic_main.c index 996f999..738792e 100644 --- a/drivers/net/enic/enic_main.c +++ b/drivers/net/enic/enic_main.c @@ -426,9 +426,14 @@ int enic_alloc_intr_resources(struct enic *enic) void enic_free_rq(void *rxq) { - struct vnic_rq *rq = (struct vnic_rq *)rxq; - struct enic *enic = vnic_dev_priv(rq->vdev); + struct vnic_rq *rq; + struct enic *enic; + if (rxq == NULL) + return; + + rq = (struct vnic_rq *)rxq; + enic = vnic_dev_priv(rq->vdev); enic_rxmbuf_queue_release(enic, rq); rte_free(rq->mbuf_ring); rq->mbuf_ring = NULL; @@ -514,9 +519,14 @@ err_exit: void enic_free_wq(void *txq) { - struct vnic_wq *wq = (struct vnic_wq *)txq; - struct enic *enic = vnic_dev_priv(wq->vdev); + struct vnic_wq *wq; + struct enic *enic; + + if (txq == NULL) + return; + wq = (struct vnic_wq *)txq; + enic = vnic_dev_priv(wq->vdev); rte_memzone_free(wq->cqmsg_rz); vnic_wq_free(wq); vnic_cq_free(&enic->cq[enic->rq_count + wq->index]); -- 2.7.0