DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Bruce Richardson <bruce.richardson@intel.com>
To: "Mandal, Anurag" <anurag.mandal@intel.com>
Cc: "Burakov, Anatoly" <anatoly.burakov@intel.com>,
	"dev@dpdk.org" <dev@dpdk.org>
Subject: Re: [PATCH] net/ice: fix unchecked Tx time context allocation
Date: Tue, 6 Oct 2026 11:47:10 +0100	[thread overview]
Message-ID: <asTRrur4gQF2Bbj_@bricha3-mobl1.ger.corp.intel.com> (raw)
In-Reply-To: <AT6PR11MB0445268173D71C808640CEF8A2E4952@AT6PR11MB044526.namprd11.prod.outlook.com>

On Tue, Oct 06, 2026 at 11:36:54AM +0100, Mandal, Anurag wrote:
> 
> > -----Original Message-----
> > From: Burakov, Anatoly <anatoly.burakov@intel.com>
> > Sent: 06 October 2026 15:33
> > To: Mandal, Anurag <anurag.mandal@intel.com>; dev@dpdk.org
> > Cc: Richardson, Bruce <bruce.richardson@intel.com>; stable@dpdk.org
> > Subject: Re: [PATCH] net/ice: fix unchecked Tx time context allocation
> > 
> > On 10/2/2026 4:19 AM, Anurag Mandal wrote:
> > > ice_tx_queue_start() dereferences the Tx time queue context buffer
> > > returned by ice_malloc() without NULL check.
> > > On allocation failure, the E830 send-on-timestamp path therefore
> > > crashes instead of reporting "No Memory" error, and also the already
> > > allocated txq_elem buffer gets leaked.
> > >
> > > Added the necessary allocation failure check and freed txq_elem buffer
> > > in case of failure to avoid the memory leak.
> > >
> > > Fixes: 0b6ff09a1f19 ("net/intel: support Tx packet pacing for E830")
> > > Cc: stable@dpdk.org
> > >
> > > Signed-off-by: Anurag Mandal <anurag.mandal@intel.com>
> > > ---
> > >   drivers/net/intel/ice/ice_rxtx.c | 4 ++++
> > >   1 file changed, 4 insertions(+)
> > >
> > > diff --git a/drivers/net/intel/ice/ice_rxtx.c
> > > b/drivers/net/intel/ice/ice_rxtx.c
> > > index b333444cbf..873aca0100 100644
> > > --- a/drivers/net/intel/ice/ice_rxtx.c
> > > +++ b/drivers/net/intel/ice/ice_rxtx.c
> > > @@ -898,6 +898,10 @@ ice_tx_queue_start(struct rte_eth_dev *dev,
> > uint16_t tx_queue_id)
> > >   		u8 ts_buf_len = ice_struct_size(ts_elem, txtimeqs, 1);
> > >
> > >   		ts_elem = ice_malloc(hw, ts_buf_len);
> > > +		if (!ts_elem) {
> > > +			rte_free(txq_elem);
> > > +			return -ENOMEM;
> > > +		}
> > >   		ice_setup_txtime_ctx(txq, &txtime_ctx, true);
> > >   		ice_set_ctx(hw, (u8 *)&txtime_ctx,
> > >   				ts_elem->txtimeqs[0].txtime_ctx,
> > 
> > I don't particularly like the fact that we're allocating using `ice_malloc` but
> > freeing using `rte_free`. This works only accidentally (because `ice_malloc`
> > resolves to `rte_malloc`).
> > 
> > Not a blocker for this patch, as this is following established convention in this
> > function, but IMO this code could benefit from a separate patch replacing
> > direct `rte_free` calls with `ice_free`.
> > 
> > Acked-by: Anatoly Burakov <anatoly.burakov@intel.com>
> > 
> 
> I will be sending a separate patch to change replacing direct `rte_free` calls with `ice_free`for buffers allocated via 'ice_malloc'
> 
That would be great. I think I'd prefer to take that patch first, so can
you put it in a 2-patch set with this one (reworked to use ice_free)?

      reply	other threads:[~2026-10-06 10:47 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02  2:19 [PATCH] net/ice: fix unchecked Tx time context allocation Anurag Mandal
2026-10-06 10:02 ` Burakov, Anatoly
2026-10-06 10:36   ` Mandal, Anurag
2026-10-06 10:47     ` Bruce Richardson [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asTRrur4gQF2Bbj_@bricha3-mobl1.ger.corp.intel.com \
    --to=bruce.richardson@intel.com \
    --cc=anatoly.burakov@intel.com \
    --cc=anurag.mandal@intel.com \
    --cc=dev@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox