From: netdev-bot+sashiko@kernel.org
To: kuba@kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, edumazet@google.com,
pabeni@redhat.com, andrew+netdev@lunn.ch, horms@kernel.org,
jiri@resnulli.us, tariqt@nvidia.com, moshe@nvidia.com,
donald.hunter@gmail.com
Subject: Re: [PATCH net-next v2 9/9] devlink: validate the port index in the rate set request
Date: Wed, 16 Sep 2026 19:15:26 +0000 [thread overview]
Message-ID: <178958612602.22033.8655238125047770212@kernel.org> (raw)
In-Reply-To: <20260915161341.1053476-10-kuba@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider:
Critical: 0 · High: 0 · Medium: 0 · Low: 1
- [Low] Commit-message characterization / missing `Fixes:` tag.
--
devlink: validate the port index in the rate set request
This adds port-index to the rate-set request attribute list in the devlink
YAML spec and adds the matching NLA_U32 entry to the generated
devlink_rate_set_nl_policy. rate-new is deliberately left unchanged since
it resolves rate nodes by name.
> diff --git a/net/devlink/netlink_gen.c b/net/devlink/netlink_gen.c
> index 43ef6864d462f..9e1b4c081a7b3 100644
> --- a/net/devlink/netlink_gen.c
> +++ b/net/devlink/netlink_gen.c
> @@ -618,6 +618,7 @@ static const struct nla_policy devlink_rate_set_nl_policy[DEVLINK_ATTR_PARENT_DE
> [DEVLINK_ATTR_BUS_NAME] = { .type = NLA_NUL_STRING, },
> [DEVLINK_ATTR_DEV_NAME] = { .type = NLA_NUL_STRING, },
> [DEVLINK_ATTR_INDEX] = NLA_POLICY_FULL_RANGE(NLA_UINT, &devlink_attr_index_range),
> + [DEVLINK_ATTR_PORT_INDEX] = { .type = NLA_U32, },
[Severity: Low]
This isn't a bug in the change itself, but should this carry a Fixes tag?
The missing policy slot looks bisectable to f2f9dd164db0 ("netlink: specs:
devlink: add the remaining command to generate complete split_ops"), which
moved DEVLINK_CMD_RATE_SET out of small_ops into split_ops. The old
small_ops path used the global devlink_nl_policy in net/devlink/netlink.c,
which does declare:
[DEVLINK_ATTR_PORT_INDEX] = { .type = NLA_U32 },
so before that conversion a short port-index was rejected, and afterwards
it is not.
The commit message says:
Since we're reading a linear skb the OOB read is still
within the same memory allocation, it's just garbage. We also do not
echo the garbage back to the user so it's not an info leak either.
Hence not treating this is a real bug fix.
That reasoning checks out, and the op is GENL_ADMIN_PERM so only a caller
that can already reconfigure any port reaches it. The one remaining effect
is behavioural rather than memory-safety related: with the zeroed policy
slot plus GENL_DONT_VALIDATE_STRICT, a zero-length port-index passes
validation, devlink_rate_get_from_info() picks the leaf path purely on
attribute presence:
net/devlink/rate.c:devlink_rate_get_from_info() {
if (attrs[DEVLINK_ATTR_PORT_INDEX])
return devlink_rate_leaf_get_from_info(devlink, info);
...
}
and devlink_port_get_from_attrs() then reads past the payload:
net/devlink/port.c:devlink_port_get_from_attrs() {
u32 port_index = nla_get_u32(attrs[DEVLINK_ATTR_PORT_INDEX]);
...
}
If those four bytes happen to name a registered port,
devlink_nl_rate_set_doit() goes on to change that leaf's rate settings
instead of returning -EINVAL. Would a Fixes tag help stable/backport
tooling identify the trees (v6.7 onward) where a malformed rate-set request
is acted upon rather than rejected?
> [DEVLINK_ATTR_RATE_NODE_NAME] = { .type = NLA_NUL_STRING, },
> [DEVLINK_ATTR_RATE_TX_SHARE] = { .type = NLA_U64, },
> [DEVLINK_ATTR_RATE_TX_MAX] = { .type = NLA_U64, },
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260915161341.1053476-1-kuba%40kernel.org
next prev parent reply other threads:[~2026-09-16 19:15 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 16:13 [PATCH net-next v2 0/9] devlink: netlink spec fixes Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 1/9] devlink: fix the enum behind DEVLINK_ATTR_RELOAD_LIMITS Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-18 1:19 ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 2/9] netlink: specs: devlink: drop the stale port dump reply value Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 3/9] netlink: specs: devlink: describe DEVLINK_ATTR_NESTED_DEVLINK Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-18 1:21 ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 4/9] netlink: specs: devlink: complete the port function nest Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-15 16:13 ` [PATCH net-next v2 5/9] devlink: generate the port function policy from the spec Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 6/9] netlink: specs: devlink: populate multi-attr attrs for region read and line card Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-15 16:13 ` [PATCH net-next v2 7/9] netlink: specs: devlink: describe the netns id in the parent-dev nest Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-18 1:23 ` Jakub Kicinski
2026-09-15 16:13 ` [PATCH net-next v2 8/9] netlink: specs: devlink: add pad to the subsets carrying padded u64s Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko
2026-09-15 16:13 ` [PATCH net-next v2 9/9] devlink: validate the port index in the rate set request Jakub Kicinski
2026-09-16 19:15 ` netdev-bot+sashiko [this message]
2026-09-18 1:40 ` [PATCH net-next v2 0/9] devlink: netlink spec fixes patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=178958612602.22033.8655238125047770212@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=donald.hunter@gmail.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=jiri@resnulli.us \
--cc=kuba@kernel.org \
--cc=moshe@nvidia.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox