DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
	Chenna Arnoori <chenna.arnoori@broadcom.com>,
	stable@dpdk.org,
	Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
Subject: [PATCH 4/5] net/bnxt: fix bounds in MAC pool index and flow parsing
Date: Thu, 17 Sep 2026 21:27:51 -0600	[thread overview]
Message-ID: <20260918032752.763408-5-Mohammad-Shuab.Siddique@broadcom.com> (raw)
In-Reply-To: <20260918032752.763408-1-Mohammad-Shuab.Siddique@broadcom.com>

From: Chenna Arnoori <chenna.arnoori@broadcom.com>

Two independent out-of-bounds issues in the driver:

- bnxt_mac_addr_add_op() indexed bp->vnic_info[pool] with a
  caller-supplied pool before validating it against bp->max_vnics, and
  before checking bp->vnic_info was even allocated yet (it is NULL
  until the port is started). The existing "if (!vnic)" check was
  always false, since vnic held the address of an array element and
  is never NULL. Reorder to check dev_started/vnic_info first, then
  bounds-check pool against max_vnics before indexing.

- bnxt_flow_non_void_item()/bnxt_flow_non_void_action() looped
  unconditionally until a non-VOID item/action was found, walking off
  the end of a pattern/actions array that lacked a terminating END
  item. Bound the skip loop and stop advancing once the limit is hit.

Fixes: 51fafb89a9a ("net/bnxt: get rid of ff pools and use VNIC info array")
Fixes: 5c1171c972 ("net/bnxt: refactor filter/flow")
Cc: stable@dpdk.org

Signed-off-by: Chenna Arnoori <chenna.arnoori@broadcom.com>
Signed-off-by: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
---
 drivers/net/bnxt/bnxt_ethdev.c | 16 ++++++++++------
 drivers/net/bnxt/bnxt_flow.c   | 28 ++++++++++++++++++++--------
 2 files changed, 30 insertions(+), 14 deletions(-)

diff --git a/drivers/net/bnxt/bnxt_ethdev.c b/drivers/net/bnxt/bnxt_ethdev.c
index 27cf67c04f..db9b49238a 100644
--- a/drivers/net/bnxt/bnxt_ethdev.c
+++ b/drivers/net/bnxt/bnxt_ethdev.c
@@ -2113,7 +2113,7 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 				uint32_t index, uint32_t pool)
 {
 	struct bnxt *bp = eth_dev->data->dev_private;
-	struct bnxt_vnic_info *vnic = &bp->vnic_info[pool];
+	struct bnxt_vnic_info *vnic;
 	int rc = 0;
 
 	rc = is_bnxt_in_error(bp);
@@ -2125,15 +2125,19 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 		return -ENOTSUP;
 	}
 
-	if (!vnic) {
-		PMD_DRV_LOG_LINE(ERR, "VNIC not found for pool %d!", pool);
-		return -EINVAL;
-	}
-
 	/* Filter settings will get applied when port is started */
 	if (!eth_dev->data->dev_started)
 		return 0;
 
+	if (bp->vnic_info == NULL)
+		return 0;
+
+	if (pool >= bp->max_vnics) {
+		PMD_DRV_LOG_LINE(ERR, "Pool %u exceeds VNIC count %u!", pool, bp->max_vnics);
+		return -EINVAL;
+	}
+	vnic = &bp->vnic_info[pool];
+
 	rc = bnxt_add_mac_filter(bp, vnic, mac_addr, index, pool);
 
 	return rc;
diff --git a/drivers/net/bnxt/bnxt_flow.c b/drivers/net/bnxt/bnxt_flow.c
index a2e590540b..14d52e1818 100644
--- a/drivers/net/bnxt/bnxt_flow.c
+++ b/drivers/net/bnxt/bnxt_flow.c
@@ -58,24 +58,36 @@ bnxt_flow_args_validate(const struct rte_flow_attr *attr,
 	return 0;
 }
 
+#define BNXT_MAX_FLOW_ITEMS 256
+
 static const struct rte_flow_item *
 bnxt_flow_non_void_item(const struct rte_flow_item *cur)
 {
-	while (1) {
-		if (cur->type != RTE_FLOW_ITEM_TYPE_VOID)
-			return cur;
+	int i = 0;
+
+	if (!cur)
+		return NULL;
+
+	while (cur->type == RTE_FLOW_ITEM_TYPE_VOID && i < BNXT_MAX_FLOW_ITEMS) {
 		cur++;
+		i++;
 	}
+	return cur;
 }
 
 static const struct rte_flow_action *
 bnxt_flow_non_void_action(const struct rte_flow_action *cur)
 {
-	while (1) {
-		if (cur->type != RTE_FLOW_ACTION_TYPE_VOID)
-			return cur;
+	int i = 0;
+
+	if (!cur)
+		return NULL;
+
+	while (cur->type == RTE_FLOW_ACTION_TYPE_VOID && i < BNXT_MAX_FLOW_ITEMS) {
 		cur++;
+		i++;
 	}
+	return cur;
 }
 
 static int
@@ -109,7 +121,7 @@ bnxt_filter_type_check(const struct rte_flow_item pattern[],
 			PMD_DRV_LOG_LINE(DEBUG, "Unknown Flow type");
 			use_ntuple |= 0;
 		}
-		item++;
+		item = bnxt_flow_non_void_item(item + 1);
 	}
 
 	if (has_vlan && use_ntuple) {
@@ -680,7 +692,7 @@ bnxt_validate_and_parse_flow_type(const struct rte_flow_attr *attr,
 		default:
 			break;
 		}
-		item++;
+		item = bnxt_flow_non_void_item(item + 1);
 	}
 	filter->enables = en;
 	filter->valid_flags = valid_flags;
-- 
2.47.3


  parent reply	other threads:[~2026-09-18  3:25 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18  3:27 [PATCH 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 2/5] net/bnxt: fix bounds on TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-18  3:27 ` Mohammad Shuab Siddique [this message]
2026-09-18  3:27 ` [PATCH 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique
2026-09-21  2:24 ` [PATCH v2 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 2/5] net/bnxt: fix bounds on TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-21 15:49     ` Stephen Hemminger
2026-09-21  2:24   ` [PATCH v2 4/5] net/bnxt: fix bounds in MAC pool index and flow parsing Mohammad Shuab Siddique
2026-09-21 15:50     ` Stephen Hemminger
2026-09-21  2:24   ` [PATCH v2 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique
2026-09-29  0:24 ` [PATCH v3 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 2/5] net/bnxt: validate TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 4/5] net/bnxt: fix bounds in MAC address pool index Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918032752.763408-5-Mohammad-Shuab.Siddique@broadcom.com \
    --to=mohammad-shuab.siddique@broadcom.com \
    --cc=chenna.arnoori@broadcom.com \
    --cc=dev@dpdk.org \
    --cc=kishore.padmanabha@broadcom.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox