DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] net/bnxt: fix TruFlow CPM pool-use list insertion
@ 2026-10-05 15:16 Manish Kurup
  0 siblings, 0 replies; only message in thread
From: Manish Kurup @ 2026-10-05 15:16 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha, stable

cpm_insert_pool_id() builds the initial list entry when a pool is
registered (tfc_cpm_set_cmm_inst()). It contains two bugs in the
loop/insert logic.

Bug 1: prev advances in lockstep with pool_use. prev is supposed to
track the node *before* pool_use so that the "within list" case can
insert between them. Instead, after each iteration prev == pool_use
(both point to the same node), but the more damaging case occurs when
the loop exhausts the list: pool_use advances to NULL, and then prev
is set to that NULL too, instead of pointing to the last real node.
This caused the "empty list" branch to fire even on a non-empty list,
overwriting cpm->pool_use_list and silently losing all existing nodes
(a list-head clobber on tail insert). Add an explicit "insert at tail"
case to fix this.

Bug 2: missing backward link in the "within list" case. pool_use->prev
was left pointing at prev (the old predecessor) instead of being
updated to new_pool_use, corrupting the backward linkage of the list.

Fixes: 80317ff6adfd ("net/bnxt/tf_core: support Thor2")
Cc: stable@dpdk.org

Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_core/v3/tfc_cpm.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/net/bnxt/tf_core/v3/tfc_cpm.c b/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
index 8d95a0c205..f2c14fa8b8 100644
--- a/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
+++ b/drivers/net/bnxt/tf_core/v3/tfc_cpm.c
@@ -83,8 +83,8 @@ static int cpm_insert_pool_id(struct tfc_cpm *cpm, uint16_t pool_id)
 		if (cpm->pools[pool_use->pool_id].valid &&
 			cpm->pools[pool_use->pool_id].used_count >
 			pool->used_count) {
-			pool_use = pool_use->next;
 			prev =	pool_use;
+			pool_use = pool_use->next;
 		} else {
 			break;
 		}
@@ -101,16 +101,20 @@ static int cpm_insert_pool_id(struct tfc_cpm *cpm, uint16_t pool_id)
 	new_pool_use->next = NULL;
 	pool->pool_use = new_pool_use;
 
-	if (pool_use == NULL) { /* Empty list */
+	if (pool_use == NULL && prev == NULL) { /* Empty list */
 		cpm->pool_use_list = new_pool_use;
-	} else if (prev == NULL) { /* Start of list */
+	} else if (pool_use == NULL) { /* Insert at tail */
+		prev->next = new_pool_use;
+		new_pool_use->prev = prev;
+	} else if (prev == NULL) { /* Insert at head */
 		cpm->pool_use_list = new_pool_use;
 		new_pool_use->next = pool_use;
 		pool_use->prev = new_pool_use;
-	} else { /* Within list */
+	} else { /* Insert in middle */
 		prev->next = new_pool_use;
 		new_pool_use->next = pool_use;
 		new_pool_use->prev = prev;
+		pool_use->prev = new_pool_use;
 	}
 
 	cpm->available_pool_id = cpm->pool_use_list->pool_id;
-- 
2.31.1


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-05 15:16 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 15:16 [PATCH] net/bnxt: fix TruFlow CPM pool-use list insertion Manish Kurup

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox