From: Bruce Richardson <bruce.richardson@intel.com>
To: "Mandal, Anurag" <anurag.mandal@intel.com>
Cc: "Burakov, Anatoly" <anatoly.burakov@intel.com>,
"dev@dpdk.org" <dev@dpdk.org>
Subject: Re: [PATCH] net/ice: fix unchecked Tx time context allocation
Date: Tue, 6 Oct 2026 11:47:10 +0100 [thread overview]
Message-ID: <asTRrur4gQF2Bbj_@bricha3-mobl1.ger.corp.intel.com> (raw)
In-Reply-To: <AT6PR11MB0445268173D71C808640CEF8A2E4952@AT6PR11MB044526.namprd11.prod.outlook.com>
On Tue, Oct 06, 2026 at 11:36:54AM +0100, Mandal, Anurag wrote:
>
> > -----Original Message-----
> > From: Burakov, Anatoly <anatoly.burakov@intel.com>
> > Sent: 06 October 2026 15:33
> > To: Mandal, Anurag <anurag.mandal@intel.com>; dev@dpdk.org
> > Cc: Richardson, Bruce <bruce.richardson@intel.com>; stable@dpdk.org
> > Subject: Re: [PATCH] net/ice: fix unchecked Tx time context allocation
> >
> > On 10/2/2026 4:19 AM, Anurag Mandal wrote:
> > > ice_tx_queue_start() dereferences the Tx time queue context buffer
> > > returned by ice_malloc() without NULL check.
> > > On allocation failure, the E830 send-on-timestamp path therefore
> > > crashes instead of reporting "No Memory" error, and also the already
> > > allocated txq_elem buffer gets leaked.
> > >
> > > Added the necessary allocation failure check and freed txq_elem buffer
> > > in case of failure to avoid the memory leak.
> > >
> > > Fixes: 0b6ff09a1f19 ("net/intel: support Tx packet pacing for E830")
> > > Cc: stable@dpdk.org
> > >
> > > Signed-off-by: Anurag Mandal <anurag.mandal@intel.com>
> > > ---
> > > drivers/net/intel/ice/ice_rxtx.c | 4 ++++
> > > 1 file changed, 4 insertions(+)
> > >
> > > diff --git a/drivers/net/intel/ice/ice_rxtx.c
> > > b/drivers/net/intel/ice/ice_rxtx.c
> > > index b333444cbf..873aca0100 100644
> > > --- a/drivers/net/intel/ice/ice_rxtx.c
> > > +++ b/drivers/net/intel/ice/ice_rxtx.c
> > > @@ -898,6 +898,10 @@ ice_tx_queue_start(struct rte_eth_dev *dev,
> > uint16_t tx_queue_id)
> > > u8 ts_buf_len = ice_struct_size(ts_elem, txtimeqs, 1);
> > >
> > > ts_elem = ice_malloc(hw, ts_buf_len);
> > > + if (!ts_elem) {
> > > + rte_free(txq_elem);
> > > + return -ENOMEM;
> > > + }
> > > ice_setup_txtime_ctx(txq, &txtime_ctx, true);
> > > ice_set_ctx(hw, (u8 *)&txtime_ctx,
> > > ts_elem->txtimeqs[0].txtime_ctx,
> >
> > I don't particularly like the fact that we're allocating using `ice_malloc` but
> > freeing using `rte_free`. This works only accidentally (because `ice_malloc`
> > resolves to `rte_malloc`).
> >
> > Not a blocker for this patch, as this is following established convention in this
> > function, but IMO this code could benefit from a separate patch replacing
> > direct `rte_free` calls with `ice_free`.
> >
> > Acked-by: Anatoly Burakov <anatoly.burakov@intel.com>
> >
>
> I will be sending a separate patch to change replacing direct `rte_free` calls with `ice_free`for buffers allocated via 'ice_malloc'
>
That would be great. I think I'd prefer to take that patch first, so can
you put it in a 2-patch set with this one (reworked to use ice_free)?
prev parent reply other threads:[~2026-10-06 10:47 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 2:19 [PATCH] net/ice: fix unchecked Tx time context allocation Anurag Mandal
2026-10-06 10:02 ` Burakov, Anatoly
2026-10-06 10:36 ` Mandal, Anurag
2026-10-06 10:47 ` Bruce Richardson [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asTRrur4gQF2Bbj_@bricha3-mobl1.ger.corp.intel.com \
--to=bruce.richardson@intel.com \
--cc=anatoly.burakov@intel.com \
--cc=anurag.mandal@intel.com \
--cc=dev@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox