* [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool
@ 2026-09-13 17:38 bugzilla
2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson
0 siblings, 1 reply; 6+ messages in thread
From: bugzilla @ 2026-09-13 17:38 UTC (permalink / raw)
To: dev
https://bugs.dpdk.org/show_bug.cgi?id=2042
Bug ID: 2042
Summary: net/intel/idpf and net/intel/cpfl: four byte store
into a bool
Product: DPDK
Version: 26.11
Hardware: All
OS: All
Status: UNCONFIRMED
Severity: normal
Priority: Normal
Component: ethdev
Assignee: dev@dpdk.org
Reporter: stephen@networkplumber.org
Target Milestone: ---
drivers/net/intel/idpf/idpf_ethdev.c:1248
drivers/net/intel/cpfl/cpfl_ethdev.c (same handler, copied)
parse_bool() stores an int:
int *i = args;
...
*i = num;
Both callers in each driver pass the address of a bool:
drivers/net/intel/idpf/idpf_common_device.h:104
bool is_tx_singleq;
bool is_rx_singleq;
so "tx_single=1" or "rx_single=1" writes four bytes into a one byte field.
Fixes: 549343c25db8 ("net/idpf: support device initialization")
Fixes: 2d823ecd671c ("net/cpfl: support device initialization")
--
You are receiving this mail because:
You are the assignee for the bug.
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings 2026-09-13 17:38 [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool bugzilla @ 2026-09-14 16:22 ` Bruce Richardson 2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson 2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen 0 siblings, 2 replies; 6+ messages in thread From: Bruce Richardson @ 2026-09-14 16:22 UTC (permalink / raw) To: dev; +Cc: Bruce Richardson, stable The Rx and Tx single queue settings in idpf driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself. Fix by changing store type to bool. Bugzilla ID: 2042 Fixes: 549343c25db8 ("net/idpf: support device initialization") Cc: stable@dpdk.org Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> === Note: this fix is superceded by the kvargs numeric args patchset [1]. However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release. [1] https://patches.dpdk.org/project/dpdk/list/?series=39247 --- drivers/net/intel/idpf/idpf_ethdev.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c index c13505416a..9fd5b28adb 100644 --- a/drivers/net/intel/idpf/idpf_ethdev.c +++ b/drivers/net/intel/idpf/idpf_ethdev.c @@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) { - int *i = args; + bool *i = args; char *end; int num; @@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args) return -EINVAL; } - *i = num; + *i = (num == 1); return 0; } -- 2.53.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/2] net/cpfl: fix overflow on store of single-queue settings 2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson @ 2026-09-14 16:22 ` Bruce Richardson 2026-09-15 10:42 ` Shetty, Praveen 2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen 1 sibling, 1 reply; 6+ messages in thread From: Bruce Richardson @ 2026-09-14 16:22 UTC (permalink / raw) To: dev; +Cc: Bruce Richardson, stable The Rx and Tx single queue settings in cpfl driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself. Fix by changing store type to bool. Bugzilla ID: 2042 Fixes: 2d823ecd671c ("net/cpfl: support device initialization") Cc: stable@dpdk.org Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> === Note: this fix is superceded by the kvargs numeric args patchset [1]. However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release. [1] https://patches.dpdk.org/project/dpdk/list/?series=39247 --- drivers/net/intel/cpfl/cpfl_ethdev.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/net/intel/cpfl/cpfl_ethdev.c b/drivers/net/intel/cpfl/cpfl_ethdev.c index 4315adb68c..b1b7637f48 100644 --- a/drivers/net/intel/cpfl/cpfl_ethdev.c +++ b/drivers/net/intel/cpfl/cpfl_ethdev.c @@ -1448,7 +1448,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) { - int *i = args; + bool *i = args; char *end; int num; @@ -1462,7 +1462,7 @@ parse_bool(const char *key, const char *value, void *args) return -EINVAL; } - *i = num; + *i = (num == 1); return 0; } -- 2.53.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: [PATCH 2/2] net/cpfl: fix overflow on store of single-queue settings 2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson @ 2026-09-15 10:42 ` Shetty, Praveen 0 siblings, 0 replies; 6+ messages in thread From: Shetty, Praveen @ 2026-09-15 10:42 UTC (permalink / raw) To: Richardson, Bruce; +Cc: Richardson, Bruce, stable@dpdk.org, dev@dpdk.org The Rx and Tx single queue settings in cpfl driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself. Fix by changing store type to bool. Bugzilla ID: 2042 Fixes: 2d823ecd671c ("net/cpfl: support device initialization") Cc: stable@dpdk.org Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> === Note: this fix is superceded by the kvargs numeric args patchset [1]. However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release. [1] https://patches.dpdk.org/project/dpdk/list/?series=39247 --- drivers/net/intel/cpfl/cpfl_ethdev.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/net/intel/cpfl/cpfl_ethdev.c b/drivers/net/intel/cpfl/cpfl_ethdev.c index 4315adb68c..b1b7637f48 100644 --- a/drivers/net/intel/cpfl/cpfl_ethdev.c +++ b/drivers/net/intel/cpfl/cpfl_ethdev.c @@ -1448,7 +1448,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) { - int *i = args; + bool *i = args; char *end; int num; @@ -1462,7 +1462,7 @@ parse_bool(const char *key, const char *value, void *args) return -EINVAL; } - *i = num; + *i = (num == 1); return 0; } -- Looks good to me, Acked-by: Praveen Shetty <praveen.shetty@intel.com> 2.53.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings 2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson 2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson @ 2026-09-15 10:41 ` Shetty, Praveen 2026-09-18 14:47 ` Bruce Richardson 1 sibling, 1 reply; 6+ messages in thread From: Shetty, Praveen @ 2026-09-15 10:41 UTC (permalink / raw) To: Richardson, Bruce; +Cc: Richardson, Bruce, stable@dpdk.org, dev@dpdk.org The Rx and Tx single queue settings in idpf driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself. Fix by changing store type to bool. Bugzilla ID: 2042 Fixes: 549343c25db8 ("net/idpf: support device initialization") Cc: stable@dpdk.org Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> === Note: this fix is superceded by the kvargs numeric args patchset [1]. However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release. [1] https://patches.dpdk.org/project/dpdk/list/?series=39247 --- drivers/net/intel/idpf/idpf_ethdev.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c index c13505416a..9fd5b28adb 100644 --- a/drivers/net/intel/idpf/idpf_ethdev.c +++ b/drivers/net/intel/idpf/idpf_ethdev.c @@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) { - int *i = args; + bool *i = args; char *end; int num; @@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args) return -EINVAL; } - *i = num; + *i = (num == 1); return 0; } -- Looks good to me, Acked-by: Praveen Shetty <praveen.shetty@intel.com> 2.53.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings 2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen @ 2026-09-18 14:47 ` Bruce Richardson 0 siblings, 0 replies; 6+ messages in thread From: Bruce Richardson @ 2026-09-18 14:47 UTC (permalink / raw) To: Shetty, Praveen; +Cc: stable@dpdk.org, dev@dpdk.org On Tue, Sep 15, 2026 at 11:41:32AM +0100, Shetty, Praveen wrote: > The Rx and Tx single queue settings in idpf driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself. > Fix by changing store type to bool. > > Bugzilla ID: 2042 > Fixes: 549343c25db8 ("net/idpf: support device initialization") > Cc: stable@dpdk.org > > Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> === > Note: this fix is superceded by the kvargs numeric args patchset [1]. > However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release. > > [1] https://patches.dpdk.org/project/dpdk/list/?series=39247 > --- > drivers/net/intel/idpf/idpf_ethdev.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c > index c13505416a..9fd5b28adb 100644 > --- a/drivers/net/intel/idpf/idpf_ethdev.c > +++ b/drivers/net/intel/idpf/idpf_ethdev.c > @@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) { > - int *i = args; > + bool *i = args; > char *end; > int num; > > @@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args) > return -EINVAL; > } > > - *i = num; > + *i = (num == 1); > return 0; > } > > -- > > Looks good to me, > Acked-by: Praveen Shetty <praveen.shetty@intel.com> > Thanks. Both patches squashed into one and applied to dpdk-next-net-intel. /Bruce ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-18 14:47 UTC | newest] Thread overview: 6+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-13 17:38 [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool bugzilla 2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson 2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson 2026-09-15 10:42 ` Shetty, Praveen 2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen 2026-09-18 14:47 ` Bruce Richardson
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox