From: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
To: intel-wired-lan@lists.osuosl.org, anthony.l.nguyen@intel.com,
aleksandr.loktionov@intel.com
Cc: netdev@vger.kernel.org
Subject: [PATCH iwl-net v2 0/5] iavf: five correctness fixes
Date: Tue, 15 Sep 2026 14:55:46 +0200 [thread overview]
Message-ID: <20260915125551.3976068-1-aleksandr.loktionov@intel.com> (raw)
Small batch of iavf bug fixes. Patches address a NULL-pointer dereference
crash in the hung-tx detector, a spurious free_irq() call in the misc-IRQ
error path, a VSI-state-corruption race when ethtool changes ring
parameters during an active reset, an inverted TC-boundary comparison
that silently steered frames to non-existing traffic classes, and an
-EINVAL that confused upper layers when a TC flower filter was looked up
after its qdisc had already been torn down.
All five are genuine correctness fixes with no functional changes for the
common path. All five are marked for stable given the crash/corruption/
kernel-warning/misdirection/error-reporting impact on shipping kernels.
This series was originally posted in April without a version tag and
stalled without being picked up. Re-posting as v2 with the fixes Simon
Horman requested in review, carrying forward the Tested-by tags collected
on the unchanged patches.
Changes since v1:
- Patch 1: Fixed the Fixes tag, which pointed at an unrelated i40e-only
commit (9c6c12595b73); the function was actually introduced into the
iavf lineage by 07d44190a389. Simplified the misleading NULL check on
tx_ring (an array-element address, never NULL) to a check on
tx_ring->q_vector instead, and read it with READ_ONCE() so the watchdog
can't observe a torn/re-read value while a concurrent reset swaps it.
- Patch 4: Reworked the boundary comparison. `tc > adapter->num_tc` still
let every in-range tc skip the destination-port requirement and let an
out-of-range tc with a destination port fall through and return 0.
Now explicitly rejects tc >= adapter->num_tc before checking for a
destination port.
- Patches 2, 3 and 5 are unchanged from v1.
- Added Cc: stable@vger.kernel.org to all five patches.
Signed-off-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Kiran Patil (2):
iavf: fix null pointer dereference in iavf_detect_recover_hung
iavf: return 0 when TC flower filter not found after qdisc teardown
Piotr Gardocki (1):
iavf: fix error path in iavf_request_misc_irq
Sylwester Dziedziuch (1):
iavf: prevent VSI corruption when ring params changed during reset
Avinash Dayanand (1):
iavf: fix TC boundary check in iavf_handle_tclass
drivers/net/ethernet/intel/iavf/iavf_ethtool.c | 5 +++
drivers/net/ethernet/intel/iavf/iavf_main.c | 19 ++++----
drivers/net/ethernet/intel/iavf/iavf_txrx.c | 50 +++++++++++++------------
3 files changed, 45 insertions(+), 29 deletions(-)
--
2.52.0
next reply other threads:[~2026-09-15 12:56 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 12:55 Aleksandr Loktionov [this message]
2026-09-15 12:55 ` [PATCH iwl-net v2 1/5] iavf: fix null pointer dereference in iavf_detect_recover_hung Aleksandr Loktionov
2026-09-18 15:11 ` Simon Horman
2026-10-09 16:29 ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 2/5] iavf: fix error path in iavf_request_misc_irq Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 3/5] iavf: prevent VSI corruption when ring params changed during reset Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-10-09 16:28 ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 4/5] iavf: fix TC boundary check in iavf_handle_tclass Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 5/5] iavf: return 0 when TC flower filter not found after qdisc teardown Aleksandr Loktionov
2026-09-18 15:13 ` Simon Horman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915125551.3976068-1-aleksandr.loktionov@intel.com \
--to=aleksandr.loktionov@intel.com \
--cc=anthony.l.nguyen@intel.com \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox