From: sashiko-bot@kernel.org
To: "Long Li" <longli@microsoft.com>
Cc: linux-hyperv@vger.kernel.org
Subject: Re: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild
Date: Fri, 14 Aug 2026 05:05:19 +0000 [thread overview]
Message-ID: <20260814050519.BE2051F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260813050418.2906468-12-longli@microsoft.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Medium] Desynchronization between `apc->indir_table_sz` and the actual heap allocation size of `apc->indir_table` during device reset leads to heap out-of-bounds read and write.
--
--- Patch [11]: [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild ---
commit e2bf133521a3f8f376f19cc855758c1eb53a195b
Author: Long Li <longli@microsoft.com>
net: mana: keep a user-configured RSS table across a queue rebuild
A queue rebuild regenerates the RSS indirection table from the driver default.
This patch updates the driver to carry the user-configured table over instead
when the queue count is unchanged.
> diff --git a/drivers/net/ethernet/microsoft/mana/mana_en.c b/drivers/net/ethernet/microsoft/mana/mana_en.c
> index 7c43c2f9043ba..6e77b59cfcf90 100644
> --- a/drivers/net/ethernet/microsoft/mana/mana_en.c
> +++ b/drivers/net/ethernet/microsoft/mana/mana_en.c
[ ... ]
> +static bool mana_rss_table_keep(struct mana_port_context *apc,
> + unsigned int num_queues, bool *lost)
> +{
> + u32 i;
> +
> + *lost = false;
> +
> + if (!netif_is_rxfh_configured(apc->ndev))
> + return false;
> +
> + for (i = 0; i < apc->indir_table_sz; i++) {
> + if (apc->indir_table[i] >= num_queues) {
[Severity: Medium]
This is a pre-existing issue, but can this loop perform an out-of-bounds
read on apc->indir_table?
During a device reset, mana_init_port() re-queries the hardware and updates
apc->indir_table_sz directly:
mana_init_port() {
...
err = mana_query_vport_cfg(apc, port_idx, &max_txq, &max_rxq,
&apc->indir_table_sz);
...
}
If the hardware returns a larger size than what was originally allocated
for apc->indir_table, does the driver reallocate the array to match the
new apc->indir_table_sz? If not, this loop might read past the end of
the existing heap allocation, which this patch extends into the new
mana_rss_table_keep() function.
> + *lost = true;
> + return false;
> + }
> + }
> +
> + return true;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260813050418.2906468-1-longli@microsoft.com?part=11
next prev parent reply other threads:[~2026-08-14 5:05 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-13 5:04 [PATCH net-next v2 00/13] net: mana: reconfigure by replacing the queue set Long Li
2026-08-13 5:04 ` [PATCH net-next v2 01/13] net: mana: add queue-set allocation and teardown helpers Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 02/13] net: mana: swap queue sets in mana_set_channels Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 03/13] net: mana: swap queue sets in mana_set_ringparam Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 04/13] net: mana: swap queue sets in mana_set_priv_flags Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 05/13] net: mana: swap queue sets in mana_change_mtu Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 06/13] net: mana: swap queue sets in mana_xdp_set Long Li
2026-08-13 5:04 ` [PATCH net-next v2 07/13] net: mana: do not bail out of mana_detach on dealloc failure Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 08/13] net: mana: keep per-queue statistics in the port context Long Li
2026-08-14 5:05 ` sashiko-bot
2026-08-13 5:04 ` [PATCH net-next v2 09/13] net: mana: share the EQ pool across a queue-set swap Long Li
2026-08-13 5:04 ` [PATCH net-next v2 10/13] net: mana: release EQs left idle by a channel-count reduction Long Li
2026-08-13 5:04 ` [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild Long Li
2026-08-14 5:05 ` sashiko-bot [this message]
2026-08-13 5:04 ` [PATCH net-next v2 12/13] net: mana: keep the surviving queues when the channel count is reduced Long Li
2026-08-13 5:04 ` [PATCH net-next v2 13/13] net: mana: keep the existing queues when the channel count is raised Long Li
-- strict thread matches above, loose matches on Subject: below --
2026-08-11 6:35 [PATCH net-next v2 01/13] net: mana: add queue-set allocation and teardown helpers Long Li
2026-08-11 6:35 ` [PATCH net-next v2 11/13] net: mana: keep a user-configured RSS table across a queue rebuild Long Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814050519.BE2051F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox