From: Simon Horman <horms@kernel.org>
To: anthony.l.nguyen@intel.com
Cc: Simon Horman <horms@kernel.org>,
davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
edumazet@google.com, andrew+netdev@lunn.ch,
netdev@vger.kernel.org, larysa.zaremba@intel.com,
przemyslaw.kitszel@intel.com, aleksander.lobakin@intel.com,
sridhar.samudrala@intel.com, michal.swiatkowski@linux.intel.com,
maciej.fijalkowski@intel.com, emil.s.tantilov@intel.com,
madhu.chittim@intel.com, joshua.a.hay@intel.com,
jacob.e.keller@intel.com, jayaprakash.shanmugam@intel.com,
jiri@resnulli.us, corbet@lwn.net, richardcochran@gmail.com,
skhan@linuxfoundation.org, linux-doc@vger.kernel.org,
Bharath.r@intel.com
Subject: Re: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs
Date: Wed, 22 Jul 2026 17:13:52 +0100 [thread overview]
Message-ID: <20260722161352.543079-1-horms@kernel.org> (raw)
In-Reply-To: <20260715180042.1972010-9-anthony.l.nguyen@intel.com>
This is an AI-generated review of your patch. The human sending this
email has considered the AI review valid, or at least plausible.
https://sashiko.dev/#/patchset/20260715180042.1972010-2-anthony.l.nguyen@intel.com?part=8
---
--- Patch [8]: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs ---
commit 131cbea6d4e2fb71f297aa7df605c1576a8704cf
Author: Pavan Kumar Linga <pavan.kumar.linga@intel.com>
Subject: idpf: refactor idpf to use libie_pci APIs
This commit refactors the idpf driver to use the libie_pci initialization
and MMIO APIs. It updates register accesses across various components like
control queues and virtchnl messages to rely on the libie_ctlq_ctx
structure.
> diff --git a/drivers/net/ethernet/intel/idpf/idpf.h b/drivers/net/ethernet/intel/idpf/idpf.h
> index c5e47e79a6411..92a120aadfcd2 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf.h
[ ... ]
> @@ -945,7 +884,8 @@ static inline bool idpf_is_reset_detected(struct idpf_adapter *adapter)
> if (!adapter->hw.arq)
> return true;
>
> - return !(readl(idpf_get_mbx_reg_addr(adapter, adapter->hw.arq->reg.len)) &
> + return !(readl(libie_pci_get_mmio_addr(&adapter->ctlq_ctx.mmio_info,
> + adapter->hw.arq->reg.len)) &
> adapter->hw.arq->reg.len_mask);
> }
[Severity: High]
This isn't a bug introduced by this patch, but does the transition to
libie_pci_get_mmio_addr() expose us to linked-list corruption here?
The old code performed an array access, but libie_pci_get_mmio_addr()
traverses the mmio_info->mmio_list. This traversal appears to be lockless
in asynchronous paths like idpf_is_reset_detected() in idpf.h and
idpf_ctlq_send() in idpf_controlq.c.
At the same time, driver teardown (idpf_remove) or hardware reset
(idpf_init_hard_reset) can call idpf_decfg_lan_memory_regions(), which
uses libie_pci_unmap_fltr_regs() to concurrently modify and free items
from this same list using list_del() and kvfree().
Since idpf_vc_xn_shutdown() doesn't wait for in-flight transactions
to drain, could a concurrent ethtool or interface operation preempt
during this list traversal and cause a use-after-free or list corruption?
> diff --git a/drivers/net/ethernet/intel/idpf/idpf_controlq.h b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> index de4ece40c2ff3..acf595e9265f5 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> @@ -109,8 +109,6 @@ struct idpf_mmio_reg {
> * Align to ctlq_hw_info
> */
> struct idpf_hw {
> - struct idpf_mmio_reg mbx;
> - struct idpf_mmio_reg rstat;
> /* Array of remaining LAN BAR regions */
> int num_lan_regs;
> struct idpf_mmio_reg *lan_regs;
[Severity: Low]
Are these num_lan_regs and lan_regs fields still needed?
It looks like the new libie_pci API uses
adapter->ctlq_ctx.mmio_info.mmio_list for LAN memory regions, and all
allocations and references to these array fields have been successfully
removed from the source files.
next prev parent reply other threads:[~2026-07-22 16:14 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-15 18:00 [PATCH net-next v5 00/15][pull request] Introduce iXD driver Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 01/15] virtchnl: move virtchnl and virtchnl2 headers to 'include/linux/net/intel' Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 02/15] libie: add PCI device initialization helpers to libie Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 03/15] libeth: allow to create fill queues without NAPI Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 04/15] libie: add control queue support Tony Nguyen
2026-07-20 16:17 ` Larysa Zaremba
2026-07-22 15:54 ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 05/15] libie: add bookkeeping support for control queue messages Tony Nguyen
2026-07-20 16:07 ` Larysa Zaremba
2026-07-22 15:55 ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 06/15] idpf: remove 'vport_params_reqd' field Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 07/15] idpf: remove unused code for getting RSS info from device Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs Tony Nguyen
2026-07-20 16:09 ` Larysa Zaremba
2026-07-22 16:13 ` Simon Horman [this message]
2026-07-15 18:00 ` [PATCH net-next v5 09/15] idpf: refactor idpf to use libie control queues Tony Nguyen
2026-07-20 16:11 ` Larysa Zaremba
2026-07-22 16:16 ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 10/15] idpf: make mbx_task queueing and cancelling more consistent Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 11/15] idpf: print a debug message and bail in case of non-event ctlq message Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 12/15] ixd: add basic driver framework for Intel(R) Control Plane Function Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 13/15] ixd: add reset checks and initialize the mailbox Tony Nguyen
2026-07-22 16:17 ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 14/15] ixd: add the core initialization Tony Nguyen
2026-07-20 16:14 ` Larysa Zaremba
2026-07-22 16:18 ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 15/15] ixd: add devlink support Tony Nguyen
2026-07-20 16:24 ` [PATCH net-next v5 00/15][pull request] Introduce iXD driver Larysa Zaremba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260722161352.543079-1-horms@kernel.org \
--to=horms@kernel.org \
--cc=Bharath.r@intel.com \
--cc=aleksander.lobakin@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=anthony.l.nguyen@intel.com \
--cc=corbet@lwn.net \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=emil.s.tantilov@intel.com \
--cc=jacob.e.keller@intel.com \
--cc=jayaprakash.shanmugam@intel.com \
--cc=jiri@resnulli.us \
--cc=joshua.a.hay@intel.com \
--cc=kuba@kernel.org \
--cc=larysa.zaremba@intel.com \
--cc=linux-doc@vger.kernel.org \
--cc=maciej.fijalkowski@intel.com \
--cc=madhu.chittim@intel.com \
--cc=michal.swiatkowski@linux.intel.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=przemyslaw.kitszel@intel.com \
--cc=richardcochran@gmail.com \
--cc=skhan@linuxfoundation.org \
--cc=sridhar.samudrala@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox