From: Stephen Hemminger <stephen@networkplumber.org>
To: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
Cc: dev@dpdk.org, kishore.padmanabha@broadcom.com,
Joseph Wong <joseph.wong@broadcom.com>,
stable@dpdk.org
Subject: Re: [PATCH v2 2/5] net/bnxt: fix bounds on firmware-reported resource counts
Date: Mon, 21 Sep 2026 08:47:27 -0700 [thread overview]
Message-ID: <20260921084727.6d55953f@phoenix.local> (raw)
In-Reply-To: <20260921022002.1033815-3-Mohammad-Shuab.Siddique@broadcom.com>
On Sun, 20 Sep 2026 20:19:59 -0600
Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com> wrote:
> From: Joseph Wong <joseph.wong@broadcom.com>
>
> When parsing max_ring_grps and max_l2_ctx values from firmware, clamp
> values if they exceed a 16-bit value. max_hw_ring_grps is received as
> 32-bit in __bnxt_hwrm_func_qcaps() (the func_qcaps response) but cast
> to 16-bit when used; add the clamp there and, as defense-in-depth,
> also in bnxt_hwrm_func_resc_qcaps() in case that response's field ever
> widens. max_l2_ctx is 16-bit in both responses, but its post-read
> addition with max_rx_em_flows can overflow a 16-bit sum; widen the
> addition to 32-bit and clamp the result.
>
> Fixes: 2691827e82c0 ("net/bnxt: add HWRM VNIC alloc")
> Fixes: 80bf6811fa0f ("net/bnxt: fix L2 context calculation for Thor")
> Cc: stable@dpdk.org
>
> Signed-off-by: Joseph Wong <joseph.wong@broadcom.com>
> Signed-off-by: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
> ---
Better AI review flagged:
[PATCH v2 2/5] net/bnxt: fix bounds on firmware-reported resource
counts
Warning: in bnxt_hwrm_func_resc_qcaps(), resp->max_hw_ring_grps is
uint16_t in hwrm_func_resource_qcaps_output but is read with
rte_le_to_cpu_32(). On little endian the new clamp is dead code. On
big endian the 32-bit swap of a 16-bit field yields value << 16,
which the clamp turns into 65535. The fix is rte_le_to_cpu_16(); the
"in case the field ever widens" clamp should go.
next prev parent reply other threads:[~2026-09-21 15:54 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 3:27 [PATCH 0/5] net/bnxt: fix VF and firmware-facing bounds/leak issues Mohammad Shuab Siddique
2026-09-18 3:27 ` [PATCH 1/5] net/bnxt: add VF ID boundary check before usage Mohammad Shuab Siddique
2026-09-18 3:27 ` [PATCH 2/5] net/bnxt: fix bounds on firmware-reported resource counts Mohammad Shuab Siddique
2026-09-18 3:27 ` [PATCH 3/5] net/bnxt: fix use-after-free in VNIC filter cleanup Mohammad Shuab Siddique
2026-09-18 3:27 ` [PATCH 4/5] net/bnxt: fix memory leak in VF VNIC query error path Mohammad Shuab Siddique
2026-09-18 3:27 ` [PATCH 5/5] net/bnxt: fix VF info alloc error path memory leak Mohammad Shuab Siddique
2026-09-21 2:19 ` [PATCH v2 0/5] net/bnxt: fix VF and firmware-facing bounds/leak issues Mohammad Shuab Siddique
2026-09-21 2:19 ` [PATCH v2 1/5] net/bnxt: add VF ID boundary check before usage Mohammad Shuab Siddique
2026-09-21 2:19 ` [PATCH v2 2/5] net/bnxt: fix bounds on firmware-reported resource counts Mohammad Shuab Siddique
2026-09-21 15:47 ` Stephen Hemminger [this message]
2026-09-21 2:20 ` [PATCH v2 3/5] net/bnxt: fix use-after-free in VNIC filter cleanup Mohammad Shuab Siddique
2026-09-21 15:48 ` Stephen Hemminger
2026-09-21 2:20 ` [PATCH v2 4/5] net/bnxt: fix memory leak in VF VNIC query error path Mohammad Shuab Siddique
2026-09-21 2:20 ` [PATCH v2 5/5] net/bnxt: fix VF info alloc error path memory leak Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 0/5] net/bnxt: fix VF and firmware-facing bounds/leak issues Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 1/5] net/bnxt: add VF ID boundary check before usage Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 2/5] net/bnxt: fix bounds on firmware-reported resource counts Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 3/5] net/bnxt: fix VNIC filter list walk stopping early Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 4/5] net/bnxt: fix memory leak in VF VNIC query error path Mohammad Shuab Siddique
2026-09-29 0:24 ` [PATCH v3 5/5] net/bnxt: fix VF info alloc error path memory leak Mohammad Shuab Siddique
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921084727.6d55953f@phoenix.local \
--to=stephen@networkplumber.org \
--cc=dev@dpdk.org \
--cc=joseph.wong@broadcom.com \
--cc=kishore.padmanabha@broadcom.com \
--cc=mohammad-shuab.siddique@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox