Netdev List
 help / color / mirror / Atom feed
From: Linkui Xiao <xiaolinkui@126.com>
To: anthony.l.nguyen@intel.com, przemyslaw.kitszel@intel.com,
	andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
	kuba@kernel.org, pabeni@redhat.com
Cc: intel-wired-lan@lists.osuosl.org, netdev@vger.kernel.org,
	linux-kernel@vger.kernel.org, Linkui Xiao <xiaolinkui@kylinos.cn>
Subject: [Intel-wired-lan] [PATCH net v2] ixgbe: fix incomplete ACI command buffer backup on retry
Date: Thu, 17 Sep 2026 19:54:39 +0800	[thread overview]
Message-ID: <20260917115439.1323766-1-xiaolinkui@126.com> (raw)

From: Linkui Xiao <xiaolinkui@kylinos.cn>

ixgbe_aci_send_cmd() saves only the first byte of the caller's buffer
before an EBUSY retry, using kmalloc() plus a single-byte store. When
retries are exhausted, the caller's output buffer is filled with
uninitialized slab bytes, because only the first byte was saved before
the retry. The firmware itself does not see this data, since the
retryable opcodes do not set LIBIE_AQ_FLAG_RD, but the caller still
receives garbage in its output buffer.

Replace the kmalloc() plus single-byte store with kmemdup() so the whole
indirect command buffer is saved before an EBUSY retry, skip the backup
when buf_size is 0, and key the restore off buf_cpy instead of buf,
exactly like ice_sq_send_cmd_retry() already does.

Fixes: c9e563cae19e ("ixgbe: add support for devlink reload")
Reviewed-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>
Signed-off-by: Linkui Xiao <xiaolinkui@kylinos.cn>
---
V1: https://lore.kernel.org/all/20260912013403.2818191-1-xiaolinkui@126.com/

V2:
- reword the impact description: the firmware does not see the
  uninitialized slab bytes, only the caller's output buffer does, since
  the retryable opcodes do not set LIBIE_AQ_FLAG_RD (Sashiko)
- fix the ice function reference: the kmemdup()-based backup lives in
  ice_sq_send_cmd_retry(), not ice_sq_send_cmd() (Sashiko)

 drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c | 7 +++----
 1 file changed, 3 insertions(+), 4 deletions(-)

diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
index 4d8ae5b56145..5dd88ee7ea58 100644
--- a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
+++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
@@ -214,11 +214,10 @@ int ixgbe_aci_send_cmd(struct ixgbe_hw *hw, struct libie_aq_desc *desc,
 
 	is_cmd_for_retry = ixgbe_should_retry_aci_send_cmd_execute(opcode);
 	if (is_cmd_for_retry) {
-		if (buf) {
-			buf_cpy = kmalloc(buf_size, GFP_KERNEL);
+		if (buf && buf_size) {
+			buf_cpy = kmemdup(buf, buf_size, GFP_KERNEL);
 			if (!buf_cpy)
 				return -ENOMEM;
-			*buf_cpy = *(u8 *)buf;
 		}
 		desc_cpy = *desc;
 	}
@@ -234,7 +233,7 @@ int ixgbe_aci_send_cmd(struct ixgbe_hw *hw, struct libie_aq_desc *desc,
 		    last_status != LIBIE_AQ_RC_EBUSY)
 			break;
 
-		if (buf)
+		if (buf_cpy)
 			memcpy(buf, buf_cpy, buf_size);
 		*desc = desc_cpy;
 
-- 
2.25.1


             reply	other threads:[~2026-09-17 11:55 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 11:54 Linkui Xiao [this message]
2026-09-17 13:27 ` [Intel-wired-lan] [PATCH net v2] ixgbe: fix incomplete ACI command buffer backup on retry Loktionov, Aleksandr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917115439.1323766-1-xiaolinkui@126.com \
    --to=xiaolinkui@126.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=intel-wired-lan@lists.osuosl.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=xiaolinkui@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox