DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Roman Khromenok <roma55592@yandex.ru>
To: dev@dpdk.org
Cc: Stephen Hemminger <stephen@networkplumber.org>,
	Thomas Monjalon <thomas@monjalon.net>,
	Andrew Rybchenko <andrew.rybchenko@oktetlabs.ru>,
	stable@dpdk.org
Subject: [PATCH v3 1/6] ethdev: fix out-of-bounds read of SFF-8636 thresholds
Date: Tue, 29 Sep 2026 09:07:29 +0200	[thread overview]
Message-ID: <20260929070734.1106134-2-roma55592@yandex.ru> (raw)
In-Reply-To: <20260929070734.1106134-1-roma55592@yandex.ru>

The SFF-8636 decoder reads the alarm and warning thresholds
from page 03h (offsets 0x200 to 0x247) unconditionally,
but they are printed only if the EEPROM data is 640 bytes long.

The telemetry command /ethdev/module_eeprom allocates exactly
the length reported by the driver, and several drivers report
256 bytes for QSFP modules, for example i40e for SFF-8436
and bnxt for flat memory QSFP28.
On such ports, the command reads past the end of the heap buffer.

Read the thresholds only when they are going to be printed.

Fixes: c42754fd581a ("ethdev: support SFF-8636 module telemetry")
Cc: stable@dpdk.org

Signed-off-by: Roman Khromenok <roma55592@yandex.ru>
---
v3: new patch, split from the length checks to be backported

 .mailmap              |  1 +
 lib/ethdev/sff_8636.c | 52 ++++++++++++++++++++++---------------------
 2 files changed, 28 insertions(+), 25 deletions(-)

diff --git a/.mailmap b/.mailmap
index 57f7a9f87a..45d4e92fbd 100644
--- a/.mailmap
+++ b/.mailmap
@@ -1445,6 +1445,7 @@ Romain Delhomel <romain.delhomel@6wind.com>
 Roman Dementiev <roman.dementiev@intel.com>
 Roman Fridlyand <roman.fridlyand@intel.com>
 Roman Kapl <rka@sysgo.com>
+Roman Khromenok <roma55592@yandex.ru>
 Roman Korynkevych <romanx.korynkevych@intel.com>
 Roman Storozhenko <roman.storozhenko@intel.com>
 Roman Zhukov <roman.zhukov@arknetworks.am> <roman.zhukov@oktetlabs.ru>
diff --git a/lib/ethdev/sff_8636.c b/lib/ethdev/sff_8636.c
index 6b65f47efe..9dfff41a3b 100644
--- a/lib/ethdev/sff_8636.c
+++ b/lib/ethdev/sff_8636.c
@@ -600,34 +600,36 @@ static void sff_8636_dom_parse(const uint8_t *data, struct sff_diags *sd)
 {
 	int i = 0;
 
-	/* Monitoring Thresholds for Alarms and Warnings */
 	sd->sfp_voltage[SFF_MCURR] = SFF_OFFSET_TO_U16(SFF_8636_VCC_CURR);
-	sd->sfp_voltage[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_VCC_HALRM);
-	sd->sfp_voltage[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_VCC_LALRM);
-	sd->sfp_voltage[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_VCC_HWARN);
-	sd->sfp_voltage[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_VCC_LWARN);
-
 	sd->sfp_temp[SFF_MCURR] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_CURR);
-	sd->sfp_temp[SFF_HALRM] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_HALRM);
-	sd->sfp_temp[SFF_LALRM] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_LALRM);
-	sd->sfp_temp[SFF_HWARN] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_HWARN);
-	sd->sfp_temp[SFF_LWARN] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_LWARN);
-
-	sd->bias_cur[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_HALRM);
-	sd->bias_cur[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_LALRM);
-	sd->bias_cur[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_HWARN);
-	sd->bias_cur[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_LWARN);
-
-	sd->tx_power[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_HALRM);
-	sd->tx_power[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_LALRM);
-	sd->tx_power[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_HWARN);
-	sd->tx_power[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_LWARN);
-
-	sd->rx_power[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_HALRM);
-	sd->rx_power[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_LALRM);
-	sd->rx_power[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_HWARN);
-	sd->rx_power[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_LWARN);
 
+	/* Monitoring Thresholds for Alarms and Warnings are in page 03h */
+	if (sd->supports_alarms) {
+		sd->sfp_voltage[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_VCC_HALRM);
+		sd->sfp_voltage[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_VCC_LALRM);
+		sd->sfp_voltage[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_VCC_HWARN);
+		sd->sfp_voltage[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_VCC_LWARN);
+
+		sd->sfp_temp[SFF_HALRM] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_HALRM);
+		sd->sfp_temp[SFF_LALRM] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_LALRM);
+		sd->sfp_temp[SFF_HWARN] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_HWARN);
+		sd->sfp_temp[SFF_LWARN] = SFF_8636_OFFSET_TO_TEMP(SFF_8636_TEMP_LWARN);
+
+		sd->bias_cur[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_HALRM);
+		sd->bias_cur[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_LALRM);
+		sd->bias_cur[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_HWARN);
+		sd->bias_cur[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_BIAS_LWARN);
+
+		sd->tx_power[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_HALRM);
+		sd->tx_power[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_LALRM);
+		sd->tx_power[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_HWARN);
+		sd->tx_power[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_TX_PWR_LWARN);
+
+		sd->rx_power[SFF_HALRM] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_HALRM);
+		sd->rx_power[SFF_LALRM] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_LALRM);
+		sd->rx_power[SFF_HWARN] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_HWARN);
+		sd->rx_power[SFF_LWARN] = SFF_OFFSET_TO_U16(SFF_8636_RX_PWR_LWARN);
+	}
 
 	/* Channel Specific Data */
 	for (i = 0; i < SFF_MAX_CHANNEL_NUM; i++) {
-- 
2.47.3


  reply	other threads:[~2026-09-29  7:08 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-27 11:20 [PATCH 0/4] ethdev: add API to decode module EEPROM Roman Khromenok
2026-09-27 11:20 ` [PATCH 1/4] ethdev: decouple SFF module EEPROM decoders from telemetry Roman Khromenok
2026-09-27 11:20 ` [PATCH 2/4] ethdev: check module EEPROM length before decoding Roman Khromenok
2026-09-27 11:20 ` [PATCH 3/4] ethdev: add API to decode module EEPROM Roman Khromenok
2026-09-27 11:20 ` [PATCH 4/4] test: add ethdev module EEPROM decoding tests Roman Khromenok
2026-09-28  8:47 ` [PATCH v2 0/4] ethdev: add API to decode module EEPROM Roman Khromenok
2026-09-28  8:47   ` [PATCH v2 1/4] ethdev: decouple SFF module EEPROM decoders from telemetry Roman Khromenok
2026-09-28  8:47   ` [PATCH v2 2/4] ethdev: check module EEPROM length before decoding Roman Khromenok
2026-09-28  8:47   ` [PATCH v2 3/4] ethdev: add API to decode module EEPROM Roman Khromenok
2026-09-28  8:47   ` [PATCH v2 4/4] test: add ethdev module EEPROM decoding tests Roman Khromenok
2026-09-28 18:11   ` [PATCH v2 0/4] ethdev: add API to decode module EEPROM Stephen Hemminger
2026-09-29  7:07 ` [PATCH v3 0/6] " Roman Khromenok
2026-09-29  7:07   ` Roman Khromenok [this message]
2026-09-29  7:07   ` [PATCH v3 2/6] ethdev: decouple SFF module EEPROM decoders from telemetry Roman Khromenok
2026-09-29  7:07   ` [PATCH v3 3/6] ethdev: check module EEPROM length before decoding Roman Khromenok
2026-09-29  7:07   ` [PATCH v3 4/6] ethdev: avoid unaligned access in SFF-8472 decoder Roman Khromenok
2026-09-29  7:07   ` [PATCH v3 5/6] ethdev: add API to decode module EEPROM Roman Khromenok
2026-09-29  7:07   ` [PATCH v3 6/6] test: add ethdev module EEPROM decoding tests Roman Khromenok
2026-09-29 16:02   ` [PATCH v3 0/6] ethdev: add API to decode module EEPROM Stephen Hemminger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929070734.1106134-2-roma55592@yandex.ru \
    --to=roma55592@yandex.ru \
    --cc=andrew.rybchenko@oktetlabs.ru \
    --cc=dev@dpdk.org \
    --cc=stable@dpdk.org \
    --cc=stephen@networkplumber.org \
    --cc=thomas@monjalon.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox