From: Manish Kurup <manish.kurup@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com, stable@dpdk.org
Subject: [PATCH] net/bnxt: fix TruFlow CPM pool-use list insertion
Date: Mon, 5 Oct 2026 10:16:39 -0500 [thread overview]
Message-ID: <20261005151639.1705792-1-manish.kurup@broadcom.com> (raw)
cpm_insert_pool_id() builds the initial list entry when a pool is
registered (tfc_cpm_set_cmm_inst()). It contains two bugs in the
loop/insert logic.
Bug 1: prev advances in lockstep with pool_use. prev is supposed to
track the node *before* pool_use so that the "within list" case can
insert between them. Instead, after each iteration prev == pool_use
(both point to the same node), but the more damaging case occurs when
the loop exhausts the list: pool_use advances to NULL, and then prev
is set to that NULL too, instead of pointing to the last real node.
This caused the "empty list" branch to fire even on a non-empty list,
overwriting cpm->pool_use_list and silently losing all existing nodes
(a list-head clobber on tail insert). Add an explicit "insert at tail"
case to fix this.
Bug 2: missing backward link in the "within list" case. pool_use->prev
was left pointing at prev (the old predecessor) instead of being
updated to new_pool_use, corrupting the backward linkage of the list.
Fixes: 80317ff6adfd ("net/bnxt/tf_core: support Thor2")
Cc: stable@dpdk.org
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_core/v3/tfc_cpm.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/net/bnxt/tf_core/v3/tfc_cpm.c b/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
index 8d95a0c205..f2c14fa8b8 100644
--- a/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
+++ b/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
@@ -83,8 +83,8 @@ static int cpm_insert_pool_id(struct tfc_cpm *cpm, uint16_t pool_id)
if (cpm->pools[pool_use->pool_id].valid &&
cpm->pools[pool_use->pool_id].used_count >
pool->used_count) {
- pool_use = pool_use->next;
prev = pool_use;
+ pool_use = pool_use->next;
} else {
break;
}
@@ -101,16 +101,20 @@ static int cpm_insert_pool_id(struct tfc_cpm *cpm, uint16_t pool_id)
new_pool_use->next = NULL;
pool->pool_use = new_pool_use;
- if (pool_use == NULL) { /* Empty list */
+ if (pool_use == NULL && prev == NULL) { /* Empty list */
cpm->pool_use_list = new_pool_use;
- } else if (prev == NULL) { /* Start of list */
+ } else if (pool_use == NULL) { /* Insert at tail */
+ prev->next = new_pool_use;
+ new_pool_use->prev = prev;
+ } else if (prev == NULL) { /* Insert at head */
cpm->pool_use_list = new_pool_use;
new_pool_use->next = pool_use;
pool_use->prev = new_pool_use;
- } else { /* Within list */
+ } else { /* Insert in middle */
prev->next = new_pool_use;
new_pool_use->next = pool_use;
new_pool_use->prev = prev;
+ pool_use->prev = new_pool_use;
}
cpm->available_pool_id = cpm->pool_use_list->pool_id;
--
2.31.1
reply other threads:[~2026-10-05 15:16 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005151639.1705792-1-manish.kurup@broadcom.com \
--to=manish.kurup@broadcom.com \
--cc=dev@dpdk.org \
--cc=kishore.padmanabha@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox