Netdev List
 help / color / mirror / Atom feed
* [PATCH iwl-net v2 0/5] iavf: five correctness fixes
@ 2026-09-15 12:55 Aleksandr Loktionov
  2026-09-15 12:55 ` [PATCH iwl-net v2 1/5] iavf: fix null pointer dereference in iavf_detect_recover_hung Aleksandr Loktionov
                   ` (4 more replies)
  0 siblings, 5 replies; 13+ messages in thread
From: Aleksandr Loktionov @ 2026-09-15 12:55 UTC (permalink / raw)
  To: intel-wired-lan, anthony.l.nguyen, aleksandr.loktionov; +Cc: netdev

Small batch of iavf bug fixes. Patches address a NULL-pointer dereference
crash in the hung-tx detector, a spurious free_irq() call in the misc-IRQ
error path, a VSI-state-corruption race when ethtool changes ring
parameters during an active reset, an inverted TC-boundary comparison
that silently steered frames to non-existing traffic classes, and an
-EINVAL that confused upper layers when a TC flower filter was looked up
after its qdisc had already been torn down.

All five are genuine correctness fixes with no functional changes for the
common path. All five are marked for stable given the crash/corruption/
kernel-warning/misdirection/error-reporting impact on shipping kernels.

This series was originally posted in April without a version tag and
stalled without being picked up. Re-posting as v2 with the fixes Simon
Horman requested in review, carrying forward the Tested-by tags collected
on the unchanged patches.

Changes since v1:
- Patch 1: Fixed the Fixes tag, which pointed at an unrelated i40e-only
  commit (9c6c12595b73); the function was actually introduced into the
  iavf lineage by 07d44190a389. Simplified the misleading NULL check on
  tx_ring (an array-element address, never NULL) to a check on
  tx_ring->q_vector instead, and read it with READ_ONCE() so the watchdog
  can't observe a torn/re-read value while a concurrent reset swaps it.
- Patch 4: Reworked the boundary comparison. `tc > adapter->num_tc` still
  let every in-range tc skip the destination-port requirement and let an
  out-of-range tc with a destination port fall through and return 0.
  Now explicitly rejects tc >= adapter->num_tc before checking for a
  destination port.
- Patches 2, 3 and 5 are unchanged from v1.
- Added Cc: stable@vger.kernel.org to all five patches.

Signed-off-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>

Kiran Patil (2):
  iavf: fix null pointer dereference in iavf_detect_recover_hung
  iavf: return 0 when TC flower filter not found after qdisc teardown

Piotr Gardocki (1):
  iavf: fix error path in iavf_request_misc_irq

Sylwester Dziedziuch (1):
  iavf: prevent VSI corruption when ring params changed during reset

Avinash Dayanand (1):
  iavf: fix TC boundary check in iavf_handle_tclass

 drivers/net/ethernet/intel/iavf/iavf_ethtool.c |  5 +++
 drivers/net/ethernet/intel/iavf/iavf_main.c    | 19 ++++----
 drivers/net/ethernet/intel/iavf/iavf_txrx.c    | 50 +++++++++++++------------
 3 files changed, 45 insertions(+), 29 deletions(-)

-- 
2.52.0


^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-10-09 16:29 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15 12:55 [PATCH iwl-net v2 0/5] iavf: five correctness fixes Aleksandr Loktionov
2026-09-15 12:55 ` [PATCH iwl-net v2 1/5] iavf: fix null pointer dereference in iavf_detect_recover_hung Aleksandr Loktionov
2026-09-18 15:11   ` Simon Horman
2026-10-09 16:29     ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 2/5] iavf: fix error path in iavf_request_misc_irq Aleksandr Loktionov
2026-09-18 15:12   ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 3/5] iavf: prevent VSI corruption when ring params changed during reset Aleksandr Loktionov
2026-09-18 15:12   ` Simon Horman
2026-10-09 16:28     ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 4/5] iavf: fix TC boundary check in iavf_handle_tclass Aleksandr Loktionov
2026-09-18 15:12   ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 5/5] iavf: return 0 when TC flower filter not found after qdisc teardown Aleksandr Loktionov
2026-09-18 15:13   ` Simon Horman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox