* [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool
@ 2026-09-13 17:38 bugzilla
2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson
0 siblings, 1 reply; 6+ messages in thread
From: bugzilla @ 2026-09-13 17:38 UTC (permalink / raw)
To: dev
https://bugs.dpdk.org/show_bug.cgi?id=2042
Bug ID: 2042
Summary: net/intel/idpf and net/intel/cpfl: four byte store
into a bool
Product: DPDK
Version: 26.11
Hardware: All
OS: All
Status: UNCONFIRMED
Severity: normal
Priority: Normal
Component: ethdev
Assignee: dev@dpdk.org
Reporter: stephen@networkplumber.org
Target Milestone: ---
drivers/net/intel/idpf/idpf_ethdev.c:1248
drivers/net/intel/cpfl/cpfl_ethdev.c (same handler, copied)
parse_bool() stores an int:
int *i = args;
...
*i = num;
Both callers in each driver pass the address of a bool:
drivers/net/intel/idpf/idpf_common_device.h:104
bool is_tx_singleq;
bool is_rx_singleq;
so "tx_single=1" or "rx_single=1" writes four bytes into a one byte field.
Fixes: 549343c25db8 ("net/idpf: support device initialization")
Fixes: 2d823ecd671c ("net/cpfl: support device initialization")
--
You are receiving this mail because:
You are the assignee for the bug.
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings
2026-09-13 17:38 [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool bugzilla
@ 2026-09-14 16:22 ` Bruce Richardson
2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson
2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen
0 siblings, 2 replies; 6+ messages in thread
From: Bruce Richardson @ 2026-09-14 16:22 UTC (permalink / raw)
To: dev; +Cc: Bruce Richardson, stable
The Rx and Tx single queue settings in idpf driver are both boolean
values, but the parse_bool function writes to them as int. This causes
an extra 3 bytes to be written beyond the variable itself.
Fix by changing store type to bool.
Bugzilla ID: 2042
Fixes: 549343c25db8 ("net/idpf: support device initialization")
Cc: stable@dpdk.org
Signed-off-by: Bruce Richardson <bruce.richardson@intel.com>
===
Note: this fix is superceded by the kvargs numeric args patchset [1].
However, that patchset relies on new kvargs features unlikely to be
backported, so this standalone fix is useful for backporting or if the
whole other set doesn't make the 26.11 release.
[1] https://patches.dpdk.org/project/dpdk/list/?series=39247
---
drivers/net/intel/idpf/idpf_ethdev.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c
index c13505416a..9fd5b28adb 100644
--- a/drivers/net/intel/idpf/idpf_ethdev.c
+++ b/drivers/net/intel/idpf/idpf_ethdev.c
@@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args)
static int
parse_bool(const char *key, const char *value, void *args)
{
- int *i = args;
+ bool *i = args;
char *end;
int num;
@@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args)
return -EINVAL;
}
- *i = num;
+ *i = (num == 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH 2/2] net/cpfl: fix overflow on store of single-queue settings
2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson
@ 2026-09-14 16:22 ` Bruce Richardson
2026-09-15 10:42 ` Shetty, Praveen
2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen
1 sibling, 1 reply; 6+ messages in thread
From: Bruce Richardson @ 2026-09-14 16:22 UTC (permalink / raw)
To: dev; +Cc: Bruce Richardson, stable
The Rx and Tx single queue settings in cpfl driver are both boolean
values, but the parse_bool function writes to them as int. This causes
an extra 3 bytes to be written beyond the variable itself.
Fix by changing store type to bool.
Bugzilla ID: 2042
Fixes: 2d823ecd671c ("net/cpfl: support device initialization")
Cc: stable@dpdk.org
Signed-off-by: Bruce Richardson <bruce.richardson@intel.com>
===
Note: this fix is superceded by the kvargs numeric args patchset [1].
However, that patchset relies on new kvargs features unlikely to be
backported, so this standalone fix is useful for backporting or if the
whole other set doesn't make the 26.11 release.
[1] https://patches.dpdk.org/project/dpdk/list/?series=39247
---
drivers/net/intel/cpfl/cpfl_ethdev.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/intel/cpfl/cpfl_ethdev.c b/drivers/net/intel/cpfl/cpfl_ethdev.c
index 4315adb68c..b1b7637f48 100644
--- a/drivers/net/intel/cpfl/cpfl_ethdev.c
+++ b/drivers/net/intel/cpfl/cpfl_ethdev.c
@@ -1448,7 +1448,7 @@ parse_vport(const char *key, const char *value, void *args)
static int
parse_bool(const char *key, const char *value, void *args)
{
- int *i = args;
+ bool *i = args;
char *end;
int num;
@@ -1462,7 +1462,7 @@ parse_bool(const char *key, const char *value, void *args)
return -EINVAL;
}
- *i = num;
+ *i = (num == 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings
2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson
2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson
@ 2026-09-15 10:41 ` Shetty, Praveen
2026-09-18 14:47 ` Bruce Richardson
1 sibling, 1 reply; 6+ messages in thread
From: Shetty, Praveen @ 2026-09-15 10:41 UTC (permalink / raw)
To: Richardson, Bruce; +Cc: Richardson, Bruce, stable@dpdk.org, dev@dpdk.org
The Rx and Tx single queue settings in idpf driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself.
Fix by changing store type to bool.
Bugzilla ID: 2042
Fixes: 549343c25db8 ("net/idpf: support device initialization")
Cc: stable@dpdk.org
Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> ===
Note: this fix is superceded by the kvargs numeric args patchset [1].
However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release.
[1] https://patches.dpdk.org/project/dpdk/list/?series=39247
---
drivers/net/intel/idpf/idpf_ethdev.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c
index c13505416a..9fd5b28adb 100644
--- a/drivers/net/intel/idpf/idpf_ethdev.c
+++ b/drivers/net/intel/idpf/idpf_ethdev.c
@@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) {
- int *i = args;
+ bool *i = args;
char *end;
int num;
@@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args)
return -EINVAL;
}
- *i = num;
+ *i = (num == 1);
return 0;
}
--
Looks good to me,
Acked-by: Praveen Shetty <praveen.shetty@intel.com>
2.53.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* RE: [PATCH 2/2] net/cpfl: fix overflow on store of single-queue settings
2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson
@ 2026-09-15 10:42 ` Shetty, Praveen
0 siblings, 0 replies; 6+ messages in thread
From: Shetty, Praveen @ 2026-09-15 10:42 UTC (permalink / raw)
To: Richardson, Bruce; +Cc: Richardson, Bruce, stable@dpdk.org, dev@dpdk.org
The Rx and Tx single queue settings in cpfl driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself.
Fix by changing store type to bool.
Bugzilla ID: 2042
Fixes: 2d823ecd671c ("net/cpfl: support device initialization")
Cc: stable@dpdk.org
Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> ===
Note: this fix is superceded by the kvargs numeric args patchset [1].
However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release.
[1] https://patches.dpdk.org/project/dpdk/list/?series=39247
---
drivers/net/intel/cpfl/cpfl_ethdev.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/intel/cpfl/cpfl_ethdev.c b/drivers/net/intel/cpfl/cpfl_ethdev.c
index 4315adb68c..b1b7637f48 100644
--- a/drivers/net/intel/cpfl/cpfl_ethdev.c
+++ b/drivers/net/intel/cpfl/cpfl_ethdev.c
@@ -1448,7 +1448,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) {
- int *i = args;
+ bool *i = args;
char *end;
int num;
@@ -1462,7 +1462,7 @@ parse_bool(const char *key, const char *value, void *args)
return -EINVAL;
}
- *i = num;
+ *i = (num == 1);
return 0;
}
--
Looks good to me,
Acked-by: Praveen Shetty <praveen.shetty@intel.com>
2.53.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings
2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen
@ 2026-09-18 14:47 ` Bruce Richardson
0 siblings, 0 replies; 6+ messages in thread
From: Bruce Richardson @ 2026-09-18 14:47 UTC (permalink / raw)
To: Shetty, Praveen; +Cc: stable@dpdk.org, dev@dpdk.org
On Tue, Sep 15, 2026 at 11:41:32AM +0100, Shetty, Praveen wrote:
> The Rx and Tx single queue settings in idpf driver are both boolean values, but the parse_bool function writes to them as int. This causes an extra 3 bytes to be written beyond the variable itself.
> Fix by changing store type to bool.
>
> Bugzilla ID: 2042
> Fixes: 549343c25db8 ("net/idpf: support device initialization")
> Cc: stable@dpdk.org
>
> Signed-off-by: Bruce Richardson <bruce.richardson@intel.com> ===
> Note: this fix is superceded by the kvargs numeric args patchset [1].
> However, that patchset relies on new kvargs features unlikely to be backported, so this standalone fix is useful for backporting or if the whole other set doesn't make the 26.11 release.
>
> [1] https://patches.dpdk.org/project/dpdk/list/?series=39247
> ---
> drivers/net/intel/idpf/idpf_ethdev.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/intel/idpf/idpf_ethdev.c b/drivers/net/intel/idpf/idpf_ethdev.c
> index c13505416a..9fd5b28adb 100644
> --- a/drivers/net/intel/idpf/idpf_ethdev.c
> +++ b/drivers/net/intel/idpf/idpf_ethdev.c
> @@ -1247,7 +1247,7 @@ parse_vport(const char *key, const char *value, void *args) static int parse_bool(const char *key, const char *value, void *args) {
> - int *i = args;
> + bool *i = args;
> char *end;
> int num;
>
> @@ -1261,7 +1261,7 @@ parse_bool(const char *key, const char *value, void *args)
> return -EINVAL;
> }
>
> - *i = num;
> + *i = (num == 1);
> return 0;
> }
>
> --
>
> Looks good to me,
> Acked-by: Praveen Shetty <praveen.shetty@intel.com>
>
Thanks.
Both patches squashed into one and applied to dpdk-next-net-intel.
/Bruce
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-18 14:47 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-13 17:38 [DPDK/ethdev Bug 2042] net/intel/idpf and net/intel/cpfl: four byte store into a bool bugzilla
2026-09-14 16:22 ` [PATCH 1/2] net/idpf: fix overflow on store of single-queue settings Bruce Richardson
2026-09-14 16:22 ` [PATCH 2/2] net/cpfl: " Bruce Richardson
2026-09-15 10:42 ` Shetty, Praveen
2026-09-15 10:41 ` [PATCH 1/2] net/idpf: " Shetty, Praveen
2026-09-18 14:47 ` Bruce Richardson
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox