Devicetree
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Luo Jie" <jie.luo@oss.qualcomm.com>
Cc: conor+dt@kernel.org, devicetree@vger.kernel.org, robh@kernel.org
Subject: Re: [PATCH net-next 07/11] net: ethernet: qualcomm: ppe: Add IPQ5424 QM configuration
Date: Fri, 09 Oct 2026 14:52:12 +0000	[thread overview]
Message-ID: <sashiko-outbox-165734@kernel.org> (raw)
In-Reply-To: <20261008-qcom_ipq5424_ppe-v1-7-16caf43e44ee@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] ppe: debugfs queue counter iteration reads nonexistent queues on IPQ5424 causing bus errors
--

commit 4fb437e4b3cf979efa2cd54481de8f5ac5e4963f
Author: Luo Jie <jie.luo@oss.qualcomm.com>

net: ethernet: qualcomm: ppe: Add IPQ5424 QM configuration

This commit adds the Quality of Service (QM) configuration for the
IPQ5424 PPE. It configures the unicast and multicast queues, noting
that IPQ5424 has fewer PPE ports and thus lacks multicast queues
284 to 299.

> diff --git a/drivers/net/ethernet/qualcomm/ppe/ppe_config.c b/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> index 3afa571193238..dec8eed772539 100644
> --- a/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> +++ b/drivers/net/ethernet/qualcomm/ppe/ppe_config.c
> @@ -314,6 +314,37 @@ static const struct ppe_qm_queue_config ipq9574_ppe_qm_queue_config[] = {
>  	},
>  };
>  
> +/* Multicast queues are dedicated per PPE port. IPQ5424 has only 3 physical
> + * PPE ports, versus IPQ9574's 6 PPE ports, so multicast queues 284 to 299
> + * are not available on IPQ5424, and the buffer pool assigned to the general
> + * 'group0' is larger here, 2010 versus IPQ9574's 2000.
> + */

[Severity: High]
Since multicast queues 284 to 299 are not available on IPQ5424, will reading
or writing the debugfs counters for these queues cause a bus error?

In drivers/net/ethernet/qualcomm/ppe/ppe_debugfs.c:ppe_queue_counter_get(),
the code loops up to PPE_QUEUE_TX_COUNTER_TBL_ENTRIES (300):

	for (i = 0; i < PPE_QUEUE_TX_COUNTER_TBL_ENTRIES; i++) {
		...
		} else {
			int mq_offset = i - PPE_AC_UNICAST_QUEUE_CFG_TBL_ENTRIES;
			...
			if (mq_offset < PPE_P0_MULTICAST_QUEUE_NUM) {
				reg = PPE_CPU_PORT_MULTICAST_FORCE_DROP_CNT_TBL_ADDR(mq_offset);
			} else {
				mq_offset -= PPE_P0_MULTICAST_QUEUE_NUM;

				reg = PPE_P1_MULTICAST_DROP_CNT_TBL_ADDR;
				reg += (mq_offset / PPE_MULTICAST_QUEUE_NUM) *
					PPE_MULTICAST_QUEUE_PORT_ADDR_INC;

For queues 284-299, this calculates an MMIO address for non-existent logical
ports 4, 5, and 6 on IPQ5424.  Does this lead to an unmapped register access
and a kernel panic when a user reads the 'qm' debugfs file?

A similar unconditional loop occurs in ppe_packet_counter_write() up to queue
299:

	case PPE_CNT_QM:
		for (i = 0; i < PPE_QUEUE_TX_COUNTER_TBL_ENTRIES; i++) {

Could this also trigger a panic when writing to the 'qm' debugfs file?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008-qcom_ipq5424_ppe-v1-0-16caf43e44ee@oss.qualcomm.com?part=7

  reply	other threads:[~2026-10-09 14:52 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08 14:51 [PATCH net-next 00/11] net: ethernet: qualcomm: ppe: Add support for IPQ5424 SoC Luo Jie
2026-10-08 14:51 ` [PATCH net-next 01/11] dt-bindings: net: qcom,ipq9574-ppe: Split EDMA reset into sys and apb Luo Jie
2026-10-08 19:49   ` Rob Herring (Arm)
2026-10-08 14:51 ` [PATCH net-next 02/11] net: ethernet: qualcomm: ppe: Fix multicast queue config table index Luo Jie
2026-10-09 14:52   ` sashiko-bot
2026-10-08 14:51 ` [PATCH net-next 03/11] dt-bindings: net: qcom,ipq9574-ppe: Add IPQ5424 PPE support Luo Jie
2026-10-08 20:08   ` Rob Herring (Arm)
2026-10-09 14:52   ` sashiko-bot
2026-10-08 14:51 ` [PATCH net-next 04/11] docs: networking: Document IPQ5424 as a supported SoC Luo Jie
2026-10-08 14:51 ` [PATCH net-next 05/11] net: ethernet: qualcomm: ppe: Add platform support for IPQ5424 Luo Jie
2026-10-08 14:51 ` [PATCH net-next 06/11] net: ethernet: qualcomm: ppe: Add IPQ5424 BM buffer configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 07/11] net: ethernet: qualcomm: ppe: Add IPQ5424 QM configuration Luo Jie
2026-10-09 14:52   ` sashiko-bot [this message]
2026-10-08 14:51 ` [PATCH net-next 08/11] net: ethernet: qualcomm: ppe: Add IPQ5424 scheduler resource configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 09/11] net: ethernet: qualcomm: ppe: Add IPQ5424 scheduler configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 10/11] net: ethernet: qualcomm: ppe: Add IPQ5424 service code configuration Luo Jie
2026-10-08 14:51 ` [PATCH net-next 11/11] net: ethernet: qualcomm: ppe: Add IPQ5424 counter debugfs support Luo Jie
2026-10-08 14:54 ` [PATCH net-next 00/11] net: ethernet: qualcomm: ppe: Add support for IPQ5424 SoC netdev-bot+sinfo
2026-10-09  3:42   ` Jie Luo
2026-10-08 19:07 ` Andrew Lunn
2026-10-09  3:31   ` Jie Luo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-165734@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=jie.luo@oss.qualcomm.com \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox