* Re: [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size
2026-09-22 6:12 ` [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size Selvin Xavier
@ 2026-09-22 1:01 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:01 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> The PD and DPI bitmaps were sized as max >> 3 (bytes),
> but bitmap ops (set_bit(), clear_bit(), find_first_bit(),
> test_and_set_bit()) operate on whole unsigned long words,
> so whenever max isn't a multiple of BITS_PER_LONG,
> the buffer under-allocates and the top word's bitops
> read/write past the end of the kmalloc()'d buffer.
> Most exposed on the DPI table, since dpit->max comes from the
> firmware-reported dev_attr->max_dpi with no alignment guarantee.
>
> Fix the size of both allocations with
> BITS_TO_LONGS(max) * sizeof(unsigned long).
>
> Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=7
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
2026-09-22 6:12 ` [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv() Selvin Xavier
@ 2026-09-22 1:02 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:02 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> wqe is declared once above the WR loop and never zeroed, so
> wqe.flags holds indeterminate stack contents on the first WR and the
> previous WR's stale value thereafter. This propagates straight into
> the hardware-visible srqe->flags in bnxt_qplib_post_srq_recv().
>
> Most values of the wqe struct is set except flags. So initialize
> flags also.
>
> Fixes: 37cb11acf1f7 ("RDMA/bnxt_re: Add SRQ support for Broadcom adapters")
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=4
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier
2026-09-22 6:12 ` [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier Selvin Xavier
@ 2026-09-22 1:05 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:05 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> bnxt_re_async_notifier() runs in NAPI/softirq context via bnxt_en's
> RCU-protected ULP ops dispatch, never under rtnl_lock, so it isn't
> serialized against bnxt_re_uninit_dcb_wq() destroying rdev->dcb_wq.
> A concurrent notifier call can queue_work() on a workqueue that is
> being, or has just been, destroyed.
>
> Add a spinlock scoped to dcb_wq: the notifier takes it before
> checking dcb_wq and queuing work, and bnxt_re_uninit_dcb_wq() takes
> it to atomically clear dcb_wq before destroying it. Initialize the
> lock at rdev allocation so it is valid on every teardown path,
> including bnxt_re_dev_init()'s early failure labels.
>
> Fixes: 51dc5312dcd9 ("RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event")
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=6
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
2026-09-22 6:12 ` [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection Selvin Xavier
@ 2026-09-22 1:06 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:06 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> Selecting between BNXT_RE_NUM_EXT_COUNTERS and
> BNXT_RE_NUM_STD_COUNTERS relied only on
> bnxt_qplib_is_chip_gen_p5_p7(), which doesn't account for the
> extended stats capability flag or the PF/VF restriction. Use
> bnxt_ext_stats_supported() instead, matching the check already
> used to populate the extended stats, so the counter count stays
> consistent with what gets filled in.
>
> Fixes: 8238c7bd8420 ("RDMA/bnxt_re: Fix the statistics for Gen P7 VF")
> Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=8
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time
2026-09-22 6:12 ` [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time Selvin Xavier
@ 2026-09-22 1:07 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:07 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] bnxt_re: format string mismatch prints u32 as signed
--
commit c1caa6b4fbeb062c8f585d11a5ad5310dce0f434
Author: Selvin Xavier <selvin.xavier@broadcom.com>
RDMA/bnxt_re: Validate SRQ max_sge at create time
bnxt_re_create_srq() stored attr.max_sge into srq->qplib_srq.max_sge
unvalidated, which defeats the num_sge check in
bnxt_re_post_srq_recv() since that check compares against this same
attacker-chosen value. Reject max_sge > dev_attr->max_srq_sges at
create time, and clamp dev_attr->max_srq_sges to BNXT_STATIC_MAX_SGE
since SRQ WQEs use the fixed-size SGE array.
> diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> index 081230fcb059e..911ac780c89bb 100644
> --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> @@ -2236,6 +2236,14 @@ int bnxt_re_create_srq(struct ib_srq *ib_srq,
> goto exit;
> }
>
> + if (srq_init_attr->attr.max_sge > dev_attr->max_srq_sges) {
> + ibdev_err(&rdev->ibdev,
> + "Create SRQ failed - max_sge %d exceeds supported %d",
> + srq_init_attr->attr.max_sge, dev_attr->max_srq_sges);
[Severity: Low]
Will this print confusing error logs when an invalid size is passed?
Since both srq_init_attr->attr.max_sge and dev_attr->max_srq_sges are u32,
the %d format specifier will interpret them as signed integers. This means
large invalid values (like those >= 0x80000000) will be logged as negative
numbers rather than their actual unsigned magnitude. Should these be printed
with %u instead?
> + rc = -EINVAL;
> + goto exit;
> + }
> +
> if (srq_init_attr->srq_type != IB_SRQT_BASIC) {
> rc = -EOPNOTSUPP;
> goto exit;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=3
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
2026-09-22 6:12 ` [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge " Selvin Xavier
@ 2026-09-22 1:07 ` sashiko-bot
2026-09-22 4:39 ` Selvin Xavier
0 siblings, 1 reply; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:07 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rdma/bnxt_re: un-ratelimited error log in spinlock allows DoS
--
commit bb7479cd7b3a22e9b0e6b2862ab2b9133790528b
Author: Selvin Xavier <selvin.xavier@broadcom.com>
RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
Add a check if max sge for SRQ is exceeding the device maximum.
> diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> index c35ed6ed03516..3cccef8e2e837 100644
> --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> @@ -2399,6 +2399,13 @@ int bnxt_re_post_srq_recv(struct ib_srq *ib_srq, const struct ib_recv_wr *wr,
> /* Transcribe each ib_recv_wr to qplib_swqe */
> wqe.flags = 0;
> wqe.num_sge = wr->num_sge;
> + if (wr->num_sge > srq->qplib_srq.max_sge) {
> + ibdev_err(&srq->rdev->ibdev,
> + "Limit exceeded for SRQ Receive SGEs");
[Severity: High]
Is it safe to use an un-ratelimited ibdev_err() here while holding the
srq->lock spinlock with interrupts disabled in bnxt_re_post_srq_recv()?
Since an unprivileged user can repeatedly invoke the RDMA uverbs API with a
wr->num_sge larger than srq->qplib_srq.max_sge, could this regression allow a
local user to flood the kernel log buffer and potentially cause soft lockups?
> + rc = -EINVAL;
> + *bad_wr = wr;
> + break;
> + }
> bnxt_re_build_sgl(wr->sg_list, wqe.sg_list, wr->num_sge);
> wqe.wr_id = wr->wr_id;
> wqe.type = BNXT_QPLIB_SWQE_TYPE_RECV;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=5
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline
2026-09-22 6:12 ` [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline Selvin Xavier
@ 2026-09-22 1:08 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:08 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> Avoid handling wrong sge_len by adding extra check
> to see if the passed length is more than the inline
> size supported.
>
> Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
> Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=2
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation
2026-09-22 6:12 ` [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation Selvin Xavier
@ 2026-09-22 1:09 ` sashiko-bot
0 siblings, 0 replies; 23+ messages in thread
From: sashiko-bot @ 2026-09-22 1:09 UTC (permalink / raw)
To: Selvin Xavier; +Cc: linux-rdma
> bnxt_re_build_sgl() summed SGE lengths into a signed int, which could
> overflow. Make it return u32, and have bnxt_re_copy_wr_payload() report
> the size via a u32 out-parameter with the return value carrying only
> the error status, instead of overloading a signed int with both.
>
> Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
> Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=1
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
2026-09-22 1:07 ` sashiko-bot
@ 2026-09-22 4:39 ` Selvin Xavier
2026-09-29 8:33 ` Leon Romanovsky
0 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 4:39 UTC (permalink / raw)
To: sashiko-reviews; +Cc: linux-rdma
[-- Attachment #1: Type: text/plain, Size: 2281 bytes --]
On Tue, Sep 22, 2026 at 6:37 AM <sashiko-bot@kernel.org> wrote:
>
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] rdma/bnxt_re: un-ratelimited error log in spinlock allows DoS
> --
>
> commit bb7479cd7b3a22e9b0e6b2862ab2b9133790528b
> Author: Selvin Xavier <selvin.xavier@broadcom.com>
>
> RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
>
> Add a check if max sge for SRQ is exceeding the device maximum.
>
> > diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > index c35ed6ed03516..3cccef8e2e837 100644
> > --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > @@ -2399,6 +2399,13 @@ int bnxt_re_post_srq_recv(struct ib_srq *ib_srq, const struct ib_recv_wr *wr,
> > /* Transcribe each ib_recv_wr to qplib_swqe */
> > wqe.flags = 0;
> > wqe.num_sge = wr->num_sge;
> > + if (wr->num_sge > srq->qplib_srq.max_sge) {
> > + ibdev_err(&srq->rdev->ibdev,
> > + "Limit exceeded for SRQ Receive SGEs");
>
> [Severity: High]
> Is it safe to use an un-ratelimited ibdev_err() here while holding the
> srq->lock spinlock with interrupts disabled in bnxt_re_post_srq_recv()?
>
> Since an unprivileged user can repeatedly invoke the RDMA uverbs API with a
> wr->num_sge larger than srq->qplib_srq.max_sge, could this regression allow a
> local user to flood the kernel log buffer and potentially cause soft lockups?
It is possible to reach the kernel driver using an under privilaged
user, but there is no support in rdma-core/libbnxt_re to call
ibv_cmd_post_srq_recv and this code path will not be reached as of
now. So I think this can be ignored.
>
> > + rc = -EINVAL;
> > + *bad_wr = wr;
> > + break;
> > + }
> > bnxt_re_build_sgl(wr->sg_list, wqe.sg_list, wr->num_sge);
> > wqe.wr_id = wr->wr_id;
> > wqe.type = BNXT_QPLIB_SWQE_TYPE_RECV;
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=5
[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 5473 bytes --]
^ permalink raw reply [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and
@ 2026-09-22 6:12 Selvin Xavier
2026-09-22 6:12 ` [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation Selvin Xavier
` (10 more replies)
0 siblings, 11 replies; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
This series fixes some of the bugs found while auditing bnxt_re's
handling of user-supplied values and some generic bug fixes
Please review and apply the series.
Thanks,
Selvin Xavier
v2 -> v3:
- Drop the VM_MAYEXEC clearing patch from this series. Will work on a
core level series which implements this in other drivers also
- Dropped rdev lifetime race patch from v2 series as it is reporting
few more review comments to be handled
- New fix to serialize dcb_wq against async notifier
- Removed is_in_used flags related patch to be posted as a separate rcfw
series
v1 -> v2:
- Handle review comment about clearing VM_MAYEXEC vma flag
Selvin Xavier (8):
RDMA/bnxt_re: Fix integer overflow in send payload size computation
RDMA/bnxt_re: Detect wrong sge_len passed for inline
RDMA/bnxt_re: Validate SRQ max_sge at create time
RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
RDMA/bnxt_re: Serialize dcb_wq access against async notifier
RDMA/bnxt_re: Fix the PD and DPI table size
RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
drivers/infiniband/hw/bnxt_re/bnxt_re.h | 4 ++
drivers/infiniband/hw/bnxt_re/hw_counters.c | 6 +-
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 65 ++++++++++++++-------
drivers/infiniband/hw/bnxt_re/main.c | 24 ++++++--
drivers/infiniband/hw/bnxt_re/qplib_res.c | 9 +--
drivers/infiniband/hw/bnxt_re/qplib_sp.c | 2 +-
6 files changed, 77 insertions(+), 33 deletions(-)
--
2.39.3
^ permalink raw reply [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:09 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline Selvin Xavier
` (9 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
bnxt_re_build_sgl() summed SGE lengths into a signed int, which could
overflow. Make it return u32, and have bnxt_re_copy_wr_payload() report
the size via a u32 out-parameter with the return value carrying only
the error status, instead of overloading a signed int with both.
Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 44 +++++++++++++-----------
1 file changed, 24 insertions(+), 20 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index ccd2702db78b..9775a22b8d0d 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -165,10 +165,11 @@ static void bnxt_re_check_and_set_relaxed_ordering(struct bnxt_re_dev *rdev,
qplib_mr->flags |= CMDQ_REGISTER_MR_FLAGS_ENABLE_RO;
}
-static int bnxt_re_build_sgl(struct ib_sge *ib_sg_list,
+static u32 bnxt_re_build_sgl(struct ib_sge *ib_sg_list,
struct bnxt_qplib_sge *sg_list, int num)
{
- int i, total = 0;
+ u32 total = 0;
+ int i;
for (i = 0; i < num; i++) {
sg_list[i].addr = ib_sg_list[i].addr;
@@ -3185,17 +3186,22 @@ static int bnxt_re_copy_inline_data(struct bnxt_re_dev *rdev,
static int bnxt_re_copy_wr_payload(struct bnxt_re_dev *rdev,
const struct ib_send_wr *wr,
- struct bnxt_qplib_swqe *wqe)
+ struct bnxt_qplib_swqe *wqe,
+ u32 *payload_sz)
{
- int payload_sz = 0;
+ int rc;
- if (wr->send_flags & IB_SEND_INLINE)
- payload_sz = bnxt_re_copy_inline_data(rdev, wr, wqe);
- else
- payload_sz = bnxt_re_build_sgl(wr->sg_list, wqe->sg_list,
- wqe->num_sge);
+ if (wr->send_flags & IB_SEND_INLINE) {
+ rc = bnxt_re_copy_inline_data(rdev, wr, wqe);
+ if (rc < 0)
+ return rc;
+ *payload_sz = rc;
+ } else {
+ *payload_sz = bnxt_re_build_sgl(wr->sg_list, wqe->sg_list,
+ wqe->num_sge);
+ }
- return payload_sz;
+ return 0;
}
static void bnxt_ud_qp_hw_stall_workaround(struct bnxt_re_qp *qp)
@@ -3218,7 +3224,8 @@ static int bnxt_re_post_send_shadow_qp(struct bnxt_re_dev *rdev,
struct bnxt_re_qp *qp,
const struct ib_send_wr *wr)
{
- int rc = 0, payload_sz = 0;
+ int rc = 0;
+ u32 payload_sz = 0;
unsigned long flags;
spin_lock_irqsave(&qp->sq_lock, flags);
@@ -3234,11 +3241,9 @@ static int bnxt_re_post_send_shadow_qp(struct bnxt_re_dev *rdev,
goto bad;
}
- payload_sz = bnxt_re_copy_wr_payload(qp->rdev, wr, &wqe);
- if (payload_sz < 0) {
- rc = -EINVAL;
+ rc = bnxt_re_copy_wr_payload(qp->rdev, wr, &wqe, &payload_sz);
+ if (rc)
goto bad;
- }
wqe.wr_id = wr->wr_id;
wqe.type = BNXT_QPLIB_SWQE_TYPE_SEND;
@@ -3279,7 +3284,8 @@ int bnxt_re_post_send(struct ib_qp *ib_qp, const struct ib_send_wr *wr,
{
struct bnxt_re_qp *qp = container_of(ib_qp, struct bnxt_re_qp, ib_qp);
struct bnxt_qplib_swqe wqe;
- int rc = 0, payload_sz = 0;
+ int rc = 0;
+ u32 payload_sz = 0;
unsigned long flags;
spin_lock_irqsave(&qp->sq_lock, flags);
@@ -3296,11 +3302,9 @@ int bnxt_re_post_send(struct ib_qp *ib_qp, const struct ib_send_wr *wr,
goto bad;
}
- payload_sz = bnxt_re_copy_wr_payload(qp->rdev, wr, &wqe);
- if (payload_sz < 0) {
- rc = -EINVAL;
+ rc = bnxt_re_copy_wr_payload(qp->rdev, wr, &wqe, &payload_sz);
+ if (rc)
goto bad;
- }
wqe.wr_id = wr->wr_id;
switch (wr->opcode) {
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
2026-09-22 6:12 ` [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:08 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time Selvin Xavier
` (8 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
Avoid handling wrong sge_len by adding extra check
to see if the passed length is more than the inline
size supported.
Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 9775a22b8d0d..c293c30da13e 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -3169,8 +3169,9 @@ static int bnxt_re_copy_inline_data(struct bnxt_re_dev *rdev,
wr->sg_list[i].addr;
sge_len = wr->sg_list[i].length;
- if ((sge_len + wqe->inline_len) >
- BNXT_QPLIB_SWQE_MAX_INLINE_LENGTH) {
+ if (sge_len > BNXT_QPLIB_SWQE_MAX_INLINE_LENGTH ||
+ ((sge_len + wqe->inline_len) >
+ BNXT_QPLIB_SWQE_MAX_INLINE_LENGTH)) {
ibdev_err(&rdev->ibdev,
"Inline data size requested > supported value");
return -EINVAL;
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
2026-09-22 6:12 ` [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation Selvin Xavier
2026-09-22 6:12 ` [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:07 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv() Selvin Xavier
` (7 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
bnxt_re_create_srq() stored attr.max_sge into srq->qplib_srq.max_sge
unvalidated, which defeats the num_sge check in
bnxt_re_post_srq_recv() since that check compares against this same
attacker-chosen value. Reject max_sge > dev_attr->max_srq_sges at
create time, and clamp dev_attr->max_srq_sges to BNXT_STATIC_MAX_SGE
since SRQ WQEs use the fixed-size SGE array.
Fixes: 37cb11acf1f7 ("RDMA/bnxt_re: Add SRQ support for Broadcom adapters")
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 8 ++++++++
drivers/infiniband/hw/bnxt_re/qplib_sp.c | 2 +-
2 files changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index c293c30da13e..f81490fab0d1 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -2236,6 +2236,14 @@ int bnxt_re_create_srq(struct ib_srq *ib_srq,
goto exit;
}
+ if (srq_init_attr->attr.max_sge > dev_attr->max_srq_sges) {
+ ibdev_err(&rdev->ibdev,
+ "Create SRQ failed - max_sge %d exceeds supported %d",
+ srq_init_attr->attr.max_sge, dev_attr->max_srq_sges);
+ rc = -EINVAL;
+ goto exit;
+ }
+
if (srq_init_attr->srq_type != IB_SRQT_BASIC) {
rc = -EOPNOTSUPP;
goto exit;
diff --git a/drivers/infiniband/hw/bnxt_re/qplib_sp.c b/drivers/infiniband/hw/bnxt_re/qplib_sp.c
index ec9eb52a8ebf..9aaa2b5204b8 100644
--- a/drivers/infiniband/hw/bnxt_re/qplib_sp.c
+++ b/drivers/infiniband/hw/bnxt_re/qplib_sp.c
@@ -160,7 +160,7 @@ int bnxt_qplib_get_dev_attr(struct bnxt_qplib_rcfw *rcfw)
attr->max_srq = le16_to_cpu(sb->max_srq);
attr->max_srq_wqes = le32_to_cpu(sb->max_srq_wr) - 1;
- attr->max_srq_sges = sb->max_srq_sge;
+ attr->max_srq_sges = min_t(u32, sb->max_srq_sge, BNXT_STATIC_MAX_SGE);
attr->max_pkey = 1;
attr->max_inline_data = attr->max_qp_sges * sizeof(struct sq_sge);
if (!bnxt_qplib_is_chip_gen_p7(rcfw->res->cctx))
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (2 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:02 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge " Selvin Xavier
` (6 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
wqe is declared once above the WR loop and never zeroed, so
wqe.flags holds indeterminate stack contents on the first WR and the
previous WR's stale value thereafter. This propagates straight into
the hardware-visible srqe->flags in bnxt_qplib_post_srq_recv().
Most values of the wqe struct is set except flags. So initialize
flags also.
Fixes: 37cb11acf1f7 ("RDMA/bnxt_re: Add SRQ support for Broadcom adapters")
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index f81490fab0d1..22583d2d361d 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -2397,6 +2397,7 @@ int bnxt_re_post_srq_recv(struct ib_srq *ib_srq, const struct ib_recv_wr *wr,
spin_lock_irqsave(&srq->lock, flags);
while (wr) {
/* Transcribe each ib_recv_wr to qplib_swqe */
+ wqe.flags = 0;
wqe.num_sge = wr->num_sge;
bnxt_re_build_sgl(wr->sg_list, wqe.sg_list, wr->num_sge);
wqe.wr_id = wr->wr_id;
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (3 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv() Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:07 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier Selvin Xavier
` (5 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
Add a check if max sge for SRQ is exceeding the device
maximum.
Fixes: 37cb11acf1f7 ("RDMA/bnxt_re: Add SRQ support for Broadcom adapters")
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 22583d2d361d..e744a3cae3a2 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -2399,6 +2399,13 @@ int bnxt_re_post_srq_recv(struct ib_srq *ib_srq, const struct ib_recv_wr *wr,
/* Transcribe each ib_recv_wr to qplib_swqe */
wqe.flags = 0;
wqe.num_sge = wr->num_sge;
+ if (wr->num_sge > srq->qplib_srq.max_sge) {
+ ibdev_err(&srq->rdev->ibdev,
+ "Limit exceeded for SRQ Receive SGEs");
+ rc = -EINVAL;
+ *bad_wr = wr;
+ break;
+ }
bnxt_re_build_sgl(wr->sg_list, wqe.sg_list, wr->num_sge);
wqe.wr_id = wr->wr_id;
wqe.type = BNXT_QPLIB_SWQE_TYPE_RECV;
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (4 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge " Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:05 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size Selvin Xavier
` (4 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
bnxt_re_async_notifier() runs in NAPI/softirq context via bnxt_en's
RCU-protected ULP ops dispatch, never under rtnl_lock, so it isn't
serialized against bnxt_re_uninit_dcb_wq() destroying rdev->dcb_wq.
A concurrent notifier call can queue_work() on a workqueue that is
being, or has just been, destroyed.
Add a spinlock scoped to dcb_wq: the notifier takes it before
checking dcb_wq and queuing work, and bnxt_re_uninit_dcb_wq() takes
it to atomically clear dcb_wq before destroying it. Initialize the
lock at rdev allocation so it is valid on every teardown path,
including bnxt_re_dev_init()'s early failure labels.
Fixes: 51dc5312dcd9 ("RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event")
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/bnxt_re.h | 4 ++++
drivers/infiniband/hw/bnxt_re/main.c | 24 ++++++++++++++++++++----
2 files changed, 24 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/bnxt_re.h b/drivers/infiniband/hw/bnxt_re/bnxt_re.h
index a43e678151d3..da471c63a3ba 100644
--- a/drivers/infiniband/hw/bnxt_re/bnxt_re.h
+++ b/drivers/infiniband/hw/bnxt_re/bnxt_re.h
@@ -216,6 +216,10 @@ struct bnxt_re_dev {
unsigned long event_bitmap;
struct bnxt_qplib_cc_param cc_param;
struct workqueue_struct *dcb_wq;
+ /* Protects dcb_wq against bnxt_re_uninit_dcb_wq() destroying it
+ * concurrently with bnxt_re_async_notifier() queuing work on it.
+ */
+ spinlock_t dcb_lock;
struct dentry *cc_config;
struct bnxt_re_dbg_cc_config_params *cc_config_params;
struct dentry *cq_coal_cfg;
diff --git a/drivers/infiniband/hw/bnxt_re/main.c b/drivers/infiniband/hw/bnxt_re/main.c
index 17654a9e23fe..fa0e1323a326 100644
--- a/drivers/infiniband/hw/bnxt_re/main.c
+++ b/drivers/infiniband/hw/bnxt_re/main.c
@@ -367,9 +367,15 @@ static int bnxt_re_init_dcb_wq(struct bnxt_re_dev *rdev)
static void bnxt_re_uninit_dcb_wq(struct bnxt_re_dev *rdev)
{
- if (!rdev->dcb_wq)
- return;
- destroy_workqueue(rdev->dcb_wq);
+ struct workqueue_struct *dcb_wq;
+
+ spin_lock_bh(&rdev->dcb_lock);
+ dcb_wq = rdev->dcb_wq;
+ rdev->dcb_wq = NULL;
+ spin_unlock_bh(&rdev->dcb_lock);
+
+ if (dcb_wq)
+ destroy_workqueue(dcb_wq);
}
static void bnxt_re_dcb_wq_task(struct work_struct *work)
@@ -424,14 +430,23 @@ static void bnxt_re_async_notifier(void *handle, struct hwrm_async_event_cmpl *c
switch (event_id) {
case ASYNC_EVENT_CMPL_EVENT_ID_DCB_CONFIG_CHANGE:
+ spin_lock(&rdev->dcb_lock);
+ if (!rdev->dcb_wq) {
+ spin_unlock(&rdev->dcb_lock);
+ break;
+ }
+
dcb_work = kzalloc_obj(*dcb_work, GFP_ATOMIC);
- if (!dcb_work)
+ if (!dcb_work) {
+ spin_unlock(&rdev->dcb_lock);
break;
+ }
dcb_work->rdev = rdev;
memcpy(&dcb_work->cmpl, cmpl, sizeof(*cmpl));
INIT_WORK(&dcb_work->work, bnxt_re_dcb_wq_task);
queue_work(rdev->dcb_wq, &dcb_work->work);
+ spin_unlock(&rdev->dcb_lock);
break;
default:
break;
@@ -1448,6 +1463,7 @@ static struct bnxt_re_dev *bnxt_re_dev_add(struct auxiliary_device *adev,
INIT_LIST_HEAD(&rdev->qp_list);
mutex_init(&rdev->qp_lock);
mutex_init(&rdev->pacing.dbq_lock);
+ spin_lock_init(&rdev->dcb_lock);
atomic_set(&rdev->stats.res.qp_count, 0);
atomic_set(&rdev->stats.res.cq_count, 0);
atomic_set(&rdev->stats.res.srq_count, 0);
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (5 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:01 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection Selvin Xavier
` (3 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
The PD and DPI bitmaps were sized as max >> 3 (bytes),
but bitmap ops (set_bit(), clear_bit(), find_first_bit(),
test_and_set_bit()) operate on whole unsigned long words,
so whenever max isn't a multiple of BITS_PER_LONG,
the buffer under-allocates and the top word's bitops
read/write past the end of the kmalloc()'d buffer.
Most exposed on the DPI table, since dpit->max comes from the
firmware-reported dev_attr->max_dpi with no alignment guarantee.
Fix the size of both allocations with
BITS_TO_LONGS(max) * sizeof(unsigned long).
Fixes: 1ac5a4047975 ("RDMA/bnxt_re: Add bnxt_re RoCE driver")
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/qplib_res.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/qplib_res.c b/drivers/infiniband/hw/bnxt_re/qplib_res.c
index 756f8b5f042a..7ff587ce9126 100644
--- a/drivers/infiniband/hw/bnxt_re/qplib_res.c
+++ b/drivers/infiniband/hw/bnxt_re/qplib_res.c
@@ -45,6 +45,7 @@
#include <linux/dma-mapping.h>
#include <linux/if_vlan.h>
#include <linux/vmalloc.h>
+#include <linux/bitops.h>
#include <rdma/ib_verbs.h>
#include <rdma/iter.h>
@@ -668,9 +669,9 @@ static int bnxt_qplib_alloc_pd_tbl(struct bnxt_qplib_res *res,
{
u32 bytes;
- bytes = max >> 3;
+ bytes = BITS_TO_LONGS(max) * sizeof(unsigned long);
if (!bytes)
- bytes = 1;
+ bytes = sizeof(unsigned long);
pdt->tbl = kmalloc(bytes, GFP_KERNEL);
if (!pdt->tbl)
return -ENOMEM;
@@ -848,9 +849,9 @@ static int bnxt_qplib_alloc_dpi_tbl(struct bnxt_qplib_res *res,
if (!dpit->app_tbl)
return -ENOMEM;
- bytes = dpit->max >> 3;
+ bytes = BITS_TO_LONGS(dpit->max) * sizeof(unsigned long);
if (!bytes)
- bytes = 1;
+ bytes = sizeof(unsigned long);
dpit->tbl = kmalloc(bytes, GFP_KERNEL);
if (!dpit->tbl) {
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (6 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size Selvin Xavier
@ 2026-09-22 6:12 ` Selvin Xavier
2026-09-22 1:06 ` sashiko-bot
2026-09-29 8:34 ` (subset) [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Leon Romanovsky
` (2 subsequent siblings)
10 siblings, 1 reply; 23+ messages in thread
From: Selvin Xavier @ 2026-09-22 6:12 UTC (permalink / raw)
To: leon, jgg
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil,
Selvin Xavier
Selecting between BNXT_RE_NUM_EXT_COUNTERS and
BNXT_RE_NUM_STD_COUNTERS relied only on
bnxt_qplib_is_chip_gen_p5_p7(), which doesn't account for the
extended stats capability flag or the PF/VF restriction. Use
bnxt_ext_stats_supported() instead, matching the check already
used to populate the extended stats, so the counter count stays
consistent with what gets filled in.
Fixes: 8238c7bd8420 ("RDMA/bnxt_re: Fix the statistics for Gen P7 VF")
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
---
drivers/infiniband/hw/bnxt_re/hw_counters.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/hw_counters.c b/drivers/infiniband/hw/bnxt_re/hw_counters.c
index 651cf9d0e0c7..575b97030587 100644
--- a/drivers/infiniband/hw/bnxt_re/hw_counters.c
+++ b/drivers/infiniband/hw/bnxt_re/hw_counters.c
@@ -413,7 +413,8 @@ int bnxt_re_ib_get_hw_stats(struct ib_device *ibdev,
}
done:
- return bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx) ?
+ return bnxt_ext_stats_supported(rdev->chip_ctx, rdev->dev_attr->dev_cap_flags,
+ rdev->is_virtfn) ?
BNXT_RE_NUM_EXT_COUNTERS : BNXT_RE_NUM_STD_COUNTERS;
}
@@ -423,7 +424,8 @@ struct rdma_hw_stats *bnxt_re_ib_alloc_hw_port_stats(struct ib_device *ibdev,
struct bnxt_re_dev *rdev = to_bnxt_re_dev(ibdev, ibdev);
int num_counters = 0;
- if (bnxt_qplib_is_chip_gen_p5_p7(rdev->chip_ctx))
+ if (bnxt_ext_stats_supported(rdev->chip_ctx, rdev->dev_attr->dev_cap_flags,
+ rdev->is_virtfn))
num_counters = BNXT_RE_NUM_EXT_COUNTERS;
else
num_counters = BNXT_RE_NUM_STD_COUNTERS;
--
2.39.3
^ permalink raw reply related [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
2026-09-22 4:39 ` Selvin Xavier
@ 2026-09-29 8:33 ` Leon Romanovsky
0 siblings, 0 replies; 23+ messages in thread
From: Leon Romanovsky @ 2026-09-29 8:33 UTC (permalink / raw)
To: Selvin Xavier; +Cc: sashiko-reviews, linux-rdma
On Tue, Sep 22, 2026 at 10:09:52AM +0530, Selvin Xavier wrote:
> On Tue, Sep 22, 2026 at 6:37 AM <sashiko-bot@kernel.org> wrote:
> >
> > Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> > - [High] rdma/bnxt_re: un-ratelimited error log in spinlock allows DoS
> > --
> >
> > commit bb7479cd7b3a22e9b0e6b2862ab2b9133790528b
> > Author: Selvin Xavier <selvin.xavier@broadcom.com>
> >
> > RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
> >
> > Add a check if max sge for SRQ is exceeding the device maximum.
> >
> > > diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > > index c35ed6ed03516..3cccef8e2e837 100644
> > > --- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > > +++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
> > > @@ -2399,6 +2399,13 @@ int bnxt_re_post_srq_recv(struct ib_srq *ib_srq, const struct ib_recv_wr *wr,
> > > /* Transcribe each ib_recv_wr to qplib_swqe */
> > > wqe.flags = 0;
> > > wqe.num_sge = wr->num_sge;
> > > + if (wr->num_sge > srq->qplib_srq.max_sge) {
> > > + ibdev_err(&srq->rdev->ibdev,
> > > + "Limit exceeded for SRQ Receive SGEs");
> >
> > [Severity: High]
> > Is it safe to use an un-ratelimited ibdev_err() here while holding the
> > srq->lock spinlock with interrupts disabled in bnxt_re_post_srq_recv()?
> >
> > Since an unprivileged user can repeatedly invoke the RDMA uverbs API with a
> > wr->num_sge larger than srq->qplib_srq.max_sge, could this regression allow a
> > local user to flood the kernel log buffer and potentially cause soft lockups?
> It is possible to reach the kernel driver using an under privilaged
> user, but there is no support in rdma-core/libbnxt_re to call
> ibv_cmd_post_srq_recv and this code path will not be reached as of
> now. So I think this can be ignored.
We cannot assume that rdma-core is trusted. Anyone can build it locally and use it
to interact with the kernel. In addition, syzkaller uses our UAPI structures
and commands directly, without involving rdma-core.
Thanks
> >
> > > + rc = -EINVAL;
> > > + *bad_wr = wr;
> > > + break;
> > > + }
> > > bnxt_re_build_sgl(wr->sg_list, wqe.sg_list, wr->num_sge);
> > > wqe.wr_id = wr->wr_id;
> > > wqe.type = BNXT_QPLIB_SWQE_TYPE_RECV;
> >
> > --
> > Sashiko AI review · https://sashiko.dev/#/patchset/20260922061230.7909-1-selvin.xavier@broadcom.com?part=5
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: (subset) [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (7 preceding siblings ...)
2026-09-22 6:12 ` [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection Selvin Xavier
@ 2026-09-29 8:34 ` Leon Romanovsky
2026-09-29 8:36 ` Leon Romanovsky
2026-09-29 8:42 ` (subset) " Leon Romanovsky
10 siblings, 0 replies; 23+ messages in thread
From: Leon Romanovsky @ 2026-09-29 8:34 UTC (permalink / raw)
To: leon, jgg, Selvin Xavier
Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil
On Mon, 21 Sep 2026 23:12:22 -0700, Selvin Xavier wrote:
> This series fixes some of the bugs found while auditing bnxt_re's
> handling of user-supplied values and some generic bug fixes
>
> Please review and apply the series.
>
> Thanks,
> Selvin Xavier
>
> [...]
Applied, thanks!
[1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation
https://git.kernel.org/rdma/rdma/c/2cb09585a33dd5
[2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline
https://git.kernel.org/rdma/rdma/c/30fb34c69bd3b6
[3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time
https://git.kernel.org/rdma/rdma/c/ebd9388a1180e3
[4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
https://git.kernel.org/rdma/rdma/c/41c2d60d7fee40
[6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier
https://git.kernel.org/rdma/rdma/c/9254983623f7ff
[7/8] RDMA/bnxt_re: Fix the PD and DPI table size
https://git.kernel.org/rdma/rdma/c/a99861b65221f9
[8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
https://git.kernel.org/rdma/rdma/c/856bfaa78cce2c
Best regards,
--
Leon Romanovsky <leonro@nvidia.com>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (8 preceding siblings ...)
2026-09-29 8:34 ` (subset) [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Leon Romanovsky
@ 2026-09-29 8:36 ` Leon Romanovsky
2026-10-01 5:21 ` Selvin Xavier
2026-09-29 8:42 ` (subset) " Leon Romanovsky
10 siblings, 1 reply; 23+ messages in thread
From: Leon Romanovsky @ 2026-09-29 8:36 UTC (permalink / raw)
To: Selvin Xavier; +Cc: jgg, linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil
On Mon, Sep 21, 2026 at 11:12:22PM -0700, Selvin Xavier wrote:
> This series fixes some of the bugs found while auditing bnxt_re's
> handling of user-supplied values and some generic bug fixes
>
> Please review and apply the series.
>
> Thanks,
> Selvin Xavier
>
> v2 -> v3:
> - Drop the VM_MAYEXEC clearing patch from this series. Will work on a
> core level series which implements this in other drivers also
> - Dropped rdev lifetime race patch from v2 series as it is reporting
> few more review comments to be handled
> - New fix to serialize dcb_wq against async notifier
> - Removed is_in_used flags related patch to be posted as a separate rcfw
> series
> v1 -> v2:
> - Handle review comment about clearing VM_MAYEXEC vma flag
>
> Selvin Xavier (8):
> RDMA/bnxt_re: Fix integer overflow in send payload size computation
> RDMA/bnxt_re: Detect wrong sge_len passed for inline
> RDMA/bnxt_re: Validate SRQ max_sge at create time
> RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
> RDMA/bnxt_re: Serialize dcb_wq access against async notifier
> RDMA/bnxt_re: Fix the PD and DPI table size
> RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
I have applied all the patches above.
> RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
This needs some more work. It can be improved commit message, or code to
make sashiko happy.
Thanks
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: (subset) [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
` (9 preceding siblings ...)
2026-09-29 8:36 ` Leon Romanovsky
@ 2026-09-29 8:42 ` Leon Romanovsky
10 siblings, 0 replies; 23+ messages in thread
From: Leon Romanovsky @ 2026-09-29 8:42 UTC (permalink / raw)
To: jgg, Selvin Xavier; +Cc: linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil
On Mon, 21 Sep 2026 23:12:22 -0700, Selvin Xavier wrote:
> This series fixes some of the bugs found while auditing bnxt_re's
> handling of user-supplied values and some generic bug fixes
>
> Please review and apply the series.
>
> Thanks,
> Selvin Xavier
>
> [...]
Applied, thanks!
[1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation
https://git.kernel.org/rdma/rdma/c/3483cbbd748716
[2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline
https://git.kernel.org/rdma/rdma/c/81551ece0864c3
[3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time
https://git.kernel.org/rdma/rdma/c/1894ed9a664d19
[4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
https://git.kernel.org/rdma/rdma/c/4d8168a3b7c933
[6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier
https://git.kernel.org/rdma/rdma/c/81caf9240dfb08
[7/8] RDMA/bnxt_re: Fix the PD and DPI table size
https://git.kernel.org/rdma/rdma/c/aa6c2ef821a6ba
[8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
https://git.kernel.org/rdma/rdma/c/7cc8ccb157a476
Best regards,
--
Leon Romanovsky <leon@kernel.org>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and
2026-09-29 8:36 ` Leon Romanovsky
@ 2026-10-01 5:21 ` Selvin Xavier
0 siblings, 0 replies; 23+ messages in thread
From: Selvin Xavier @ 2026-10-01 5:21 UTC (permalink / raw)
To: Leon Romanovsky
Cc: jgg, linux-rdma, andrew.gospodarek, kalesh-anakkur.purayil
[-- Attachment #1: Type: text/plain, Size: 1633 bytes --]
On Tue, Sep 29, 2026 at 2:06 PM Leon Romanovsky <leon@kernel.org> wrote:
>
> On Mon, Sep 21, 2026 at 11:12:22PM -0700, Selvin Xavier wrote:
> > This series fixes some of the bugs found while auditing bnxt_re's
> > handling of user-supplied values and some generic bug fixes
> >
> > Please review and apply the series.
> >
> > Thanks,
> > Selvin Xavier
> >
> > v2 -> v3:
> > - Drop the VM_MAYEXEC clearing patch from this series. Will work on a
> > core level series which implements this in other drivers also
> > - Dropped rdev lifetime race patch from v2 series as it is reporting
> > few more review comments to be handled
> > - New fix to serialize dcb_wq against async notifier
> > - Removed is_in_used flags related patch to be posted as a separate rcfw
> > series
> > v1 -> v2:
> > - Handle review comment about clearing VM_MAYEXEC vma flag
> >
> > Selvin Xavier (8):
> > RDMA/bnxt_re: Fix integer overflow in send payload size computation
> > RDMA/bnxt_re: Detect wrong sge_len passed for inline
> > RDMA/bnxt_re: Validate SRQ max_sge at create time
> > RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv()
> > RDMA/bnxt_re: Serialize dcb_wq access against async notifier
> > RDMA/bnxt_re: Fix the PD and DPI table size
> > RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection
>
> I have applied all the patches above.
>
> > RDMA/bnxt_re: Validate num_sge in bnxt_re_post_srq_recv()
>
> This needs some more work. It can be improved commit message, or code to
> make sashiko happy.
>
> Thanks
Sure. will repost it.
[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 5473 bytes --]
^ permalink raw reply [flat|nested] 23+ messages in thread
end of thread, other threads:[~2026-10-01 5:21 UTC | newest]
Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 6:12 [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Selvin Xavier
2026-09-22 6:12 ` [PATCH for-rc v3 1/8] RDMA/bnxt_re: Fix integer overflow in send payload size computation Selvin Xavier
2026-09-22 1:09 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 2/8] RDMA/bnxt_re: Detect wrong sge_len passed for inline Selvin Xavier
2026-09-22 1:08 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 3/8] RDMA/bnxt_re: Validate SRQ max_sge at create time Selvin Xavier
2026-09-22 1:07 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 4/8] RDMA/bnxt_re: Initialize wqe.flags in bnxt_re_post_srq_recv() Selvin Xavier
2026-09-22 1:02 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 5/8] RDMA/bnxt_re: Validate num_sge " Selvin Xavier
2026-09-22 1:07 ` sashiko-bot
2026-09-22 4:39 ` Selvin Xavier
2026-09-29 8:33 ` Leon Romanovsky
2026-09-22 6:12 ` [PATCH for-rc v3 6/8] RDMA/bnxt_re: Serialize dcb_wq access against async notifier Selvin Xavier
2026-09-22 1:05 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 7/8] RDMA/bnxt_re: Fix the PD and DPI table size Selvin Xavier
2026-09-22 1:01 ` sashiko-bot
2026-09-22 6:12 ` [PATCH for-rc v3 8/8] RDMA/bnxt_re: Use bnxt_ext_stats_supported for counter count selection Selvin Xavier
2026-09-22 1:06 ` sashiko-bot
2026-09-29 8:34 ` (subset) [PATCH for-rc v3 0/8] RDMA/bnxt_re: Fix input validation and Leon Romanovsky
2026-09-29 8:36 ` Leon Romanovsky
2026-10-01 5:21 ` Selvin Xavier
2026-09-29 8:42 ` (subset) " Leon Romanovsky
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox