Netdev List
 help / color / mirror / Atom feed
From: Simon Horman <horms@kernel.org>
To: anthony.l.nguyen@intel.com
Cc: Simon Horman <horms@kernel.org>,
	davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
	edumazet@google.com, andrew+netdev@lunn.ch,
	netdev@vger.kernel.org, larysa.zaremba@intel.com,
	przemyslaw.kitszel@intel.com, aleksander.lobakin@intel.com,
	sridhar.samudrala@intel.com, michal.swiatkowski@linux.intel.com,
	maciej.fijalkowski@intel.com, emil.s.tantilov@intel.com,
	madhu.chittim@intel.com, joshua.a.hay@intel.com,
	jacob.e.keller@intel.com, jayaprakash.shanmugam@intel.com,
	jiri@resnulli.us, corbet@lwn.net, richardcochran@gmail.com,
	skhan@linuxfoundation.org, linux-doc@vger.kernel.org,
	Bharath.r@intel.com
Subject: Re: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs
Date: Wed, 22 Jul 2026 17:13:52 +0100	[thread overview]
Message-ID: <20260722161352.543079-1-horms@kernel.org> (raw)
In-Reply-To: <20260715180042.1972010-9-anthony.l.nguyen@intel.com>

This is an AI-generated review of your patch. The human sending this
email has considered the AI review valid, or at least plausible.
https://sashiko.dev/#/patchset/20260715180042.1972010-2-anthony.l.nguyen@intel.com?part=8
---
--- Patch [8]: [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs ---
commit 131cbea6d4e2fb71f297aa7df605c1576a8704cf
Author: Pavan Kumar Linga <pavan.kumar.linga@intel.com>
Subject: idpf: refactor idpf to use libie_pci APIs

This commit refactors the idpf driver to use the libie_pci initialization
and MMIO APIs. It updates register accesses across various components like
control queues and virtchnl messages to rely on the libie_ctlq_ctx
structure.

> diff --git a/drivers/net/ethernet/intel/idpf/idpf.h b/drivers/net/ethernet/intel/idpf/idpf.h
> index c5e47e79a6411..92a120aadfcd2 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf.h

[ ... ]

> @@ -945,7 +884,8 @@ static inline bool idpf_is_reset_detected(struct idpf_adapter *adapter)
>  	if (!adapter->hw.arq)
>  		return true;
>  
> -	return !(readl(idpf_get_mbx_reg_addr(adapter, adapter->hw.arq->reg.len)) &
> +	return !(readl(libie_pci_get_mmio_addr(&adapter->ctlq_ctx.mmio_info,
> +					       adapter->hw.arq->reg.len)) &
>  		 adapter->hw.arq->reg.len_mask);
>  }

[Severity: High]
This isn't a bug introduced by this patch, but does the transition to
libie_pci_get_mmio_addr() expose us to linked-list corruption here?

The old code performed an array access, but libie_pci_get_mmio_addr()
traverses the mmio_info->mmio_list. This traversal appears to be lockless
in asynchronous paths like idpf_is_reset_detected() in idpf.h and
idpf_ctlq_send() in idpf_controlq.c.

At the same time, driver teardown (idpf_remove) or hardware reset
(idpf_init_hard_reset) can call idpf_decfg_lan_memory_regions(), which
uses libie_pci_unmap_fltr_regs() to concurrently modify and free items
from this same list using list_del() and kvfree().

Since idpf_vc_xn_shutdown() doesn't wait for in-flight transactions
to drain, could a concurrent ethtool or interface operation preempt
during this list traversal and cause a use-after-free or list corruption?

> diff --git a/drivers/net/ethernet/intel/idpf/idpf_controlq.h b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> index de4ece40c2ff3..acf595e9265f5 100644
> --- a/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> +++ b/drivers/net/ethernet/intel/idpf/idpf_controlq.h
> @@ -109,8 +109,6 @@ struct idpf_mmio_reg {
>   * Align to ctlq_hw_info
>   */
>  struct idpf_hw {
> -	struct idpf_mmio_reg mbx;
> -	struct idpf_mmio_reg rstat;
>  	/* Array of remaining LAN BAR regions */
>  	int num_lan_regs;
>  	struct idpf_mmio_reg *lan_regs;

[Severity: Low]
Are these num_lan_regs and lan_regs fields still needed?

It looks like the new libie_pci API uses 
adapter->ctlq_ctx.mmio_info.mmio_list for LAN memory regions, and all
allocations and references to these array fields have been successfully
removed from the source files.

  parent reply	other threads:[~2026-07-22 16:14 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15 18:00 [PATCH net-next v5 00/15][pull request] Introduce iXD driver Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 01/15] virtchnl: move virtchnl and virtchnl2 headers to 'include/linux/net/intel' Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 02/15] libie: add PCI device initialization helpers to libie Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 03/15] libeth: allow to create fill queues without NAPI Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 04/15] libie: add control queue support Tony Nguyen
2026-07-20 16:17   ` Larysa Zaremba
2026-07-22 15:54   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 05/15] libie: add bookkeeping support for control queue messages Tony Nguyen
2026-07-20 16:07   ` Larysa Zaremba
2026-07-22 15:55   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 06/15] idpf: remove 'vport_params_reqd' field Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 07/15] idpf: remove unused code for getting RSS info from device Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 08/15] idpf: refactor idpf to use libie_pci APIs Tony Nguyen
2026-07-20 16:09   ` Larysa Zaremba
2026-07-22 16:13   ` Simon Horman [this message]
2026-07-15 18:00 ` [PATCH net-next v5 09/15] idpf: refactor idpf to use libie control queues Tony Nguyen
2026-07-20 16:11   ` Larysa Zaremba
2026-07-22 16:16   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 10/15] idpf: make mbx_task queueing and cancelling more consistent Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 11/15] idpf: print a debug message and bail in case of non-event ctlq message Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 12/15] ixd: add basic driver framework for Intel(R) Control Plane Function Tony Nguyen
2026-07-15 18:00 ` [PATCH net-next v5 13/15] ixd: add reset checks and initialize the mailbox Tony Nguyen
2026-07-22 16:17   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 14/15] ixd: add the core initialization Tony Nguyen
2026-07-20 16:14   ` Larysa Zaremba
2026-07-22 16:18   ` Simon Horman
2026-07-15 18:00 ` [PATCH net-next v5 15/15] ixd: add devlink support Tony Nguyen
2026-07-20 16:24 ` [PATCH net-next v5 00/15][pull request] Introduce iXD driver Larysa Zaremba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722161352.543079-1-horms@kernel.org \
    --to=horms@kernel.org \
    --cc=Bharath.r@intel.com \
    --cc=aleksander.lobakin@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=corbet@lwn.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=emil.s.tantilov@intel.com \
    --cc=jacob.e.keller@intel.com \
    --cc=jayaprakash.shanmugam@intel.com \
    --cc=jiri@resnulli.us \
    --cc=joshua.a.hay@intel.com \
    --cc=kuba@kernel.org \
    --cc=larysa.zaremba@intel.com \
    --cc=linux-doc@vger.kernel.org \
    --cc=maciej.fijalkowski@intel.com \
    --cc=madhu.chittim@intel.com \
    --cc=michal.swiatkowski@linux.intel.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=richardcochran@gmail.com \
    --cc=skhan@linuxfoundation.org \
    --cc=sridhar.samudrala@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox