From: sashiko-bot@kernel.org
To: "Luo Jie" <jie.luo@oss.qualcomm.com>
Cc: devicetree@vger.kernel.org, conor+dt@kernel.org, robh@kernel.org
Subject: Re: [PATCH net-next 02/11] net: ethernet: qualcomm: ppe: Fix multicast queue config table index
Date: Fri, 09 Oct 2026 14:52:11 +0000 [thread overview]
Message-ID: <sashiko-outbox-165731@kernel.org> (raw)
In-Reply-To: <20261008-qcom_ipq5424_ppe-v1-2-16caf43e44ee@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] net: ethernet: qualcomm: out-of-bounds regmap access due to incorrect multicast_queue_cfg size
--
commit e63c30c06634bbba4d742f77aae5726bcf70fb62
Author: Luo Jie <jie.luo@oss.qualcomm.com>
net: ethernet: qualcomm: ppe: Fix multicast queue config table index
PPE queues 0-255 are unicast queues and queues from 256 onwards are
multicast queues. The multicast queue configuration table has its own
index, starting from 0 for the first multicast queue. The driver previously
used the absolute queue ID as the index, which was out of range. This commit
fixes it by converting the queue ID to the correct multicast table index.
> diff --git a/drivers/net/ethernet/qualcomm/ppe/ppe_config.c b/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> index 125b73be92b13..8a553902ffad1 100644
> --- a/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> +++ b/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> @@ -1530,8 +1530,13 @@ static int ppe_config_qm(struct ppe_device *ppe_dev)
> if (ret)
> goto qm_config_fail;
> } else {
> + /* The multicast queue table is indexed from 0 for
> + * the first multicast queue, which follows the
> + * unicast queues.
> + */
> reg = PPE_AC_MULTICAST_QUEUE_CFG_TBL_ADDR +
> - PPE_AC_MULTICAST_QUEUE_CFG_TBL_INC * queue_id;
> + PPE_AC_MULTICAST_QUEUE_CFG_TBL_INC *
> + (queue_id - PPE_AC_UNICAST_QUEUE_CFG_TBL_ENTRIES);
>
> ret = regmap_bulk_read(ppe_dev->regmap, reg,
> multicast_queue_cfg,
> ARRAY_SIZE(multicast_queue_cfg));
[Severity: Medium]
In ppe_config_qm(), multicast_queue_cfg is declared as a 5-element array:
u32 multicast_queue_cfg[5];
This means ARRAY_SIZE(multicast_queue_cfg) evaluates to 5 words (20 bytes).
However, the hardware table entry increment
(PPE_AC_MULTICAST_QUEUE_CFG_TBL_INC) is only 4 words (16 bytes).
Since this patch changes the index to correctly target the multicast queue
configuration table, does this regmap_bulk_read() over-read by 1 word into
the next queue's entry?
Additionally, a few lines later, regmap_bulk_write() also writes 5 words:
ret = regmap_bulk_write(ppe_dev->regmap, reg,
multicast_queue_cfg,
ARRAY_SIZE(multicast_queue_cfg));
For the final queue in the loop, wouldn't writing 20 bytes overflow the
16-byte boundary and write 4 bytes past the end of the entire multicast
queue configuration table?
Can this out-of-bounds register access trigger a bus error or system abort
on the SoC?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261008-qcom_ipq5424_ppe-v1-0-16caf43e44ee@oss.qualcomm.com?part=2
next prev parent reply other threads:[~2026-10-09 14:52 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 14:51 [PATCH net-next 00/11] net: ethernet: qualcomm: ppe: Add support for IPQ5424 SoC Luo Jie
2026-10-08 14:51 ` [PATCH net-next 01/11] dt-bindings: net: qcom,ipq9574-ppe: Split EDMA reset into sys and apb Luo Jie
2026-10-08 19:49 ` Rob Herring (Arm)
2026-10-08 14:51 ` [PATCH net-next 02/11] net: ethernet: qualcomm: ppe: Fix multicast queue config table index Luo Jie
2026-10-09 14:52 ` sashiko-bot [this message]
2026-10-08 14:51 ` [PATCH net-next 03/11] dt-bindings: net: qcom,ipq9574-ppe: Add IPQ5424 PPE support Luo Jie
2026-10-08 20:08 ` Rob Herring (Arm)
2026-10-09 14:52 ` sashiko-bot
2026-10-08 14:51 ` [PATCH net-next 04/11] docs: networking: Document IPQ5424 as a supported SoC Luo Jie
2026-10-08 14:51 ` [PATCH net-next 05/11] net: ethernet: qualcomm: ppe: Add platform support for IPQ5424 Luo Jie
2026-10-08 14:51 ` [PATCH net-next 06/11] net: ethernet: qualcomm: ppe: Add IPQ5424 BM buffer configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 07/11] net: ethernet: qualcomm: ppe: Add IPQ5424 QM configuration Luo Jie
2026-10-09 14:52 ` sashiko-bot
2026-10-08 14:51 ` [PATCH net-next 08/11] net: ethernet: qualcomm: ppe: Add IPQ5424 scheduler resource configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 09/11] net: ethernet: qualcomm: ppe: Add IPQ5424 scheduler configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 10/11] net: ethernet: qualcomm: ppe: Add IPQ5424 service code configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 11/11] net: ethernet: qualcomm: ppe: Add IPQ5424 counter debugfs support Luo Jie
2026-10-08 14:54 ` [PATCH net-next 00/11] net: ethernet: qualcomm: ppe: Add support for IPQ5424 SoC netdev-bot+sinfo
2026-10-09 3:42 ` Jie Luo
2026-10-08 19:07 ` Andrew Lunn
2026-10-09 3:31 ` Jie Luo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-165731@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=jie.luo@oss.qualcomm.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox