DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
	Chenna Arnoori <chenna.arnoori@broadcom.com>,
	stable@dpdk.org,
	Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
Subject: [PATCH v3 4/5] net/bnxt: fix bounds in MAC address pool index
Date: Mon, 28 Sep 2026 18:24:41 -0600	[thread overview]
Message-ID: <20260929002442.1208481-5-Mohammad-Shuab.Siddique@broadcom.com> (raw)
In-Reply-To: <20260929002442.1208481-1-Mohammad-Shuab.Siddique@broadcom.com>

From: Chenna Arnoori <chenna.arnoori@broadcom.com>

bnxt_mac_addr_add_op() indexed bp->vnic_info[pool] with a
caller-supplied pool before validating it against bp->max_vnics, and
before checking bp->vnic_info was even allocated yet (it is NULL
until the port is started). The existing "if (!vnic)" check was
always false, since vnic held the address of an array element and
is never NULL. bp->max_vnics is known from probe onward, so the pool
bound is checked first and unconditionally; the dev_started and
vnic_info checks, which gate whether there is anything to index yet,
follow it.

Fixes: 51fafb89a9a0 ("net/bnxt: get rid of ff pools and use VNIC info array")
Cc: stable@dpdk.org

Signed-off-by: Chenna Arnoori <chenna.arnoori@broadcom.com>
Signed-off-by: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
---
v3:
* Retitled from "fix bounds in MAC pool index and flow parsing" and
  dropped the flow-parsing half entirely (the bounded VOID-item skip
  in bnxt_flow_non_void_item()/bnxt_flow_non_void_action()) --
  Stephen Hemminger pointed out rte_flow patterns/actions are always
  END-terminated by API contract, so that bound did not guard a
  reachable path; reverted to the original unbounded skip loop
  rather than keep unnecessary defensive code. Dropped the
  corresponding Fixes: 5c1171c97216 tag.
* Reordered the remaining MAC-pool fix so the pool-vs-max_vnics bound
  check runs before the dev_started/vnic_info checks, not after --
  also per Stephen Hemminger.

 drivers/net/bnxt/bnxt_ethdev.c | 11 ++++++++---
 drivers/net/bnxt/bnxt_flow.c   |  1 +
 2 files changed, 9 insertions(+), 3 deletions(-)

diff --git a/drivers/net/bnxt/bnxt_ethdev.c b/drivers/net/bnxt/bnxt_ethdev.c
index 11e8f7908d..20084826d3 100644
--- a/drivers/net/bnxt/bnxt_ethdev.c
+++ b/drivers/net/bnxt/bnxt_ethdev.c
@@ -2105,7 +2105,7 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 				uint32_t index, uint32_t pool)
 {
 	struct bnxt *bp = eth_dev->data->dev_private;
-	struct bnxt_vnic_info *vnic = &bp->vnic_info[pool];
+	struct bnxt_vnic_info *vnic;
 	int rc = 0;
 
 	rc = is_bnxt_in_error(bp);
@@ -2117,8 +2117,8 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 		return -ENOTSUP;
 	}
 
-	if (!vnic) {
-		PMD_DRV_LOG_LINE(ERR, "VNIC not found for pool %d!", pool);
+	if (pool >= bp->max_vnics) {
+		PMD_DRV_LOG_LINE(ERR, "Pool %u exceeds VNIC count %u!", pool, bp->max_vnics);
 		return -EINVAL;
 	}
 
@@ -2126,6 +2126,11 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 	if (!eth_dev->data->dev_started)
 		return 0;
 
+	if (bp->vnic_info == NULL)
+		return 0;
+
+	vnic = &bp->vnic_info[pool];
+
 	rc = bnxt_add_mac_filter(bp, vnic, mac_addr, index, pool);
 
 	return rc;
diff --git a/drivers/net/bnxt/bnxt_flow.c b/drivers/net/bnxt/bnxt_flow.c
index 4bf38043b5..7b27d62697 100644
--- a/drivers/net/bnxt/bnxt_flow.c
+++ b/drivers/net/bnxt/bnxt_flow.c
@@ -1697,6 +1697,7 @@ bnxt_validate_and_parse_flow(struct rte_eth_dev *dev,
 	while (act->type != RTE_FLOW_ACTION_TYPE_END)
 		goto start;
 
+
 	return rc;
 ret:
 
-- 
2.47.3


  parent reply	other threads:[~2026-09-29  0:22 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18  3:27 [PATCH 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 2/5] net/bnxt: fix bounds on TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 4/5] net/bnxt: fix bounds in MAC pool index and flow parsing Mohammad Shuab Siddique
2026-09-18  3:27 ` [PATCH 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique
2026-09-21  2:24 ` [PATCH v2 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 2/5] net/bnxt: fix bounds on TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-21  2:24   ` [PATCH v2 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-21 15:49     ` Stephen Hemminger
2026-09-21  2:24   ` [PATCH v2 4/5] net/bnxt: fix bounds in MAC pool index and flow parsing Mohammad Shuab Siddique
2026-09-21 15:50     ` Stephen Hemminger
2026-09-21  2:24   ` [PATCH v2 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique
2026-09-29  0:24 ` [PATCH v3 0/5] net/bnxt: fix flow, Rx and naming bounds issues Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 1/5] net/bnxt: fix stack exhaustion in flow stats Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 2/5] net/bnxt: validate TPA aggregation ID from completions Mohammad Shuab Siddique
2026-09-29  0:24   ` [PATCH v3 3/5] net/bnxt: harden sprintf bounds for device memory names Mohammad Shuab Siddique
2026-09-29  0:24   ` Mohammad Shuab Siddique [this message]
2026-09-29  0:24   ` [PATCH v3 5/5] net/bnxt: fix TPA agg Rx descriptor and VNIC query bounds Mohammad Shuab Siddique

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929002442.1208481-5-Mohammad-Shuab.Siddique@broadcom.com \
    --to=mohammad-shuab.siddique@broadcom.com \
    --cc=chenna.arnoori@broadcom.com \
    --cc=dev@dpdk.org \
    --cc=kishore.padmanabha@broadcom.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox