From: Tony Nguyen <anthony.l.nguyen@intel.com>
To: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
edumazet@google.com, andrew+netdev@lunn.ch,
netdev@vger.kernel.org
Cc: Przemek Kitszel <przemyslaw.kitszel@intel.com>,
anthony.l.nguyen@intel.com, mschmidt@redhat.com,
poros@redhat.com, aleksandr.loktionov@intel.com,
horms@kernel.org
Subject: [PATCH net v4 4/5] ice: rebuild ring stats arrays instead of reallocating them in place
Date: Mon, 21 Sep 2026 11:21:03 -0700 [thread overview]
Message-ID: <20260921182106.1015019-5-anthony.l.nguyen@intel.com> (raw)
In-Reply-To: <20260921182106.1015019-1-anthony.l.nguyen@intel.com>
From: Przemek Kitszel <przemyslaw.kitszel@intel.com>
ice_vsi_realloc_stat_arrays() resized the ring stats arrays in place
with krealloc_array(), sizing them from vsi->req_txq/req_rxq. That is
not what ice_vsi_set_num_qs() computes later in ice_vsi_cfg_def(), so
after a rebuild the arrays could end up shorter than vsi->alloc_txq /
vsi->alloc_rxq, and ice_vsi_alloc_ring_stats() then walked past their
end. Requesting fewer queues than the PF pool can hand out was enough
to trigger it.
Replace it with ice_vsi_resize_stat_arrays(), which allocates a fresh
struct ice_vsi_stats instead, sized with ice_vsi_get_num_qs() and the
queues ice_vsi_decfg() is about to return to the PF pool, which is
exactly what ice_vsi_set_num_qs() will compute once they are back
there. Copy the surviving entry pointers over and install the new
structure, all before ice_vsi_decfg() runs. The entries that did not
fit are freed together with the old container, via
__ice_vsi_free_stats() with @free_entries set to false.
Doing the allocation up front also means the failure path is a plain
unlock and return, with the VSI still fully configured, rather than a
half-torn-down VSI to unwind.
While at it, skip the stats handling for ICE_VSI_CHNL, which has no
entry in pf->vsi_stats[] to begin with.
Signed-off-by: Przemek Kitszel <przemyslaw.kitszel@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
---
drivers/net/ethernet/intel/ice/ice_lib.c | 118 +++++++++++++----------
1 file changed, 69 insertions(+), 49 deletions(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_lib.c b/drivers/net/ethernet/intel/ice/ice_lib.c
index c6023c11eed3..c6166ff44fc9 100644
--- a/drivers/net/ethernet/intel/ice/ice_lib.c
+++ b/drivers/net/ethernet/intel/ice/ice_lib.c
@@ -2956,6 +2956,51 @@ ice_vsi_rebuild_get_coalesce(struct ice_vsi *vsi,
return vsi->num_q_vectors;
}
+static void ice_vsi_free_unused_stat_arrays(struct ice_vsi_stats *vsi_stat,
+ struct ice_vsi_stats *new_vsi_stat)
+{
+ int new_txq = new_vsi_stat->tx_ring_stats_len;
+ int new_rxq = new_vsi_stat->rx_ring_stats_len;
+ int prev_txq = vsi_stat->tx_ring_stats_len;
+ int prev_rxq = vsi_stat->rx_ring_stats_len;
+
+ for (int i = new_txq; i < prev_txq; i++) {
+ if (vsi_stat->tx_ring_stats[i]) {
+ kfree_rcu(vsi_stat->tx_ring_stats[i], rcu);
+ WRITE_ONCE(vsi_stat->tx_ring_stats[i], NULL);
+ }
+ }
+ for (int i = new_rxq; i < prev_rxq; i++) {
+ if (vsi_stat->rx_ring_stats[i]) {
+ kfree_rcu(vsi_stat->rx_ring_stats[i], rcu);
+ WRITE_ONCE(vsi_stat->rx_ring_stats[i], NULL);
+ }
+ }
+}
+
+static void ice_vsi_set_stat_arrays(struct ice_vsi *vsi,
+ struct ice_vsi_stats *new_vsi_stat)
+{
+ u16 new_txq, new_rxq, prev_txq, prev_rxq;
+ struct ice_vsi_stats *vsi_stat;
+ struct ice_pf *pf = vsi->back;
+
+ new_txq = new_vsi_stat->tx_ring_stats_len;
+ new_rxq = new_vsi_stat->rx_ring_stats_len;
+ vsi_stat = pf->vsi_stats[vsi->idx];
+ pf->vsi_stats[vsi->idx] = new_vsi_stat;
+ if (!vsi_stat)
+ return; /* don't copy if there is no source */
+
+ prev_txq = vsi_stat->tx_ring_stats_len;
+ prev_rxq = vsi_stat->rx_ring_stats_len;
+
+ memcpy(new_vsi_stat->tx_ring_stats, vsi_stat->tx_ring_stats,
+ sizeof(*vsi_stat->tx_ring_stats) * min(prev_txq, new_txq));
+ memcpy(new_vsi_stat->rx_ring_stats, vsi_stat->rx_ring_stats,
+ sizeof(*vsi_stat->rx_ring_stats) * min(prev_rxq, new_rxq));
+}
+
/**
* ice_vsi_rebuild_set_coalesce - set coalesce from earlier saved arrays
* @vsi: VSI connected with q_vectors
@@ -3042,63 +3087,38 @@ ice_vsi_rebuild_set_coalesce(struct ice_vsi *vsi,
}
/**
- * ice_vsi_realloc_stat_arrays - Frees unused stat structures or alloc new ones
- * @vsi: VSI pointer
+ * ice_vsi_resize_stat_arrays - resize ring stats arrays for new queue count
+ * @vsi: VSI to swap the ring stats arrays of
+ *
+ * Call while @vsi still owns its queues and before ice_vsi_decfg() returns them
+ * to the PF pool, so that the new size is what ice_vsi_set_num_qs() will compute
+ * afterwards. Surviving entries are carried over, the rest is freed.
+ *
+ * Return: 0 on success and negative value on failure
*/
-static int
-ice_vsi_realloc_stat_arrays(struct ice_vsi *vsi)
+static int ice_vsi_resize_stat_arrays(struct ice_vsi *vsi)
{
- u16 req_txq = vsi->req_txq ? vsi->req_txq : vsi->alloc_txq;
- u16 req_rxq = vsi->req_rxq ? vsi->req_rxq : vsi->alloc_rxq;
- struct ice_ring_stats **tx_ring_stats;
- struct ice_ring_stats **rx_ring_stats;
- struct ice_vsi_stats *vsi_stat;
+ struct ice_vsi_alloc_queues_params qs;
+ struct ice_vsi_stats *old_stat;
+ struct ice_vsi_stats *new_stat;
struct ice_pf *pf = vsi->back;
- u16 prev_txq = vsi->alloc_txq;
- u16 prev_rxq = vsi->alloc_rxq;
- int i;
- vsi_stat = pf->vsi_stats[vsi->idx];
+ if (vsi->type == ICE_VSI_CHNL)
+ return 0;
- if (req_txq < prev_txq) {
- for (i = req_txq; i < prev_txq; i++) {
- if (vsi_stat->tx_ring_stats[i]) {
- kfree_rcu(vsi_stat->tx_ring_stats[i], rcu);
- WRITE_ONCE(vsi_stat->tx_ring_stats[i], NULL);
- }
- }
- }
+ qs = ice_vsi_get_num_qs(vsi, vsi->alloc_txq + vsi->num_xdp_txq,
+ vsi->alloc_rxq);
- tx_ring_stats = vsi_stat->tx_ring_stats;
- vsi_stat->tx_ring_stats =
- krealloc_array(vsi_stat->tx_ring_stats, req_txq,
- sizeof(*vsi_stat->tx_ring_stats),
- GFP_KERNEL | __GFP_ZERO);
- if (!vsi_stat->tx_ring_stats) {
- vsi_stat->tx_ring_stats = tx_ring_stats;
+ new_stat = ice_vsi_new_stat_arrays(qs.alloc_txq, qs.alloc_rxq);
+ if (!new_stat)
return -ENOMEM;
- }
- vsi_stat->tx_ring_stats_len = req_txq;
-
- if (req_rxq < prev_rxq) {
- for (i = req_rxq; i < prev_rxq; i++) {
- if (vsi_stat->rx_ring_stats[i]) {
- kfree_rcu(vsi_stat->rx_ring_stats[i], rcu);
- WRITE_ONCE(vsi_stat->rx_ring_stats[i], NULL);
- }
- }
- }
- rx_ring_stats = vsi_stat->rx_ring_stats;
- vsi_stat->rx_ring_stats =
- krealloc_array(vsi_stat->rx_ring_stats, req_rxq,
- sizeof(*vsi_stat->rx_ring_stats),
- GFP_KERNEL | __GFP_ZERO);
- if (!vsi_stat->rx_ring_stats) {
- vsi_stat->rx_ring_stats = rx_ring_stats;
- return -ENOMEM;
+ old_stat = pf->vsi_stats[vsi->idx];
+ ice_vsi_set_stat_arrays(vsi, new_stat);
+ if (old_stat) {
+ ice_vsi_free_unused_stat_arrays(old_stat, new_stat);
+ __ice_vsi_free_stats(old_stat, false);
}
- vsi_stat->rx_ring_stats_len = req_rxq;
return 0;
}
@@ -3130,7 +3150,7 @@ int ice_vsi_rebuild(struct ice_vsi *vsi, u32 vsi_flags)
mutex_lock(&vsi->xdp_state_lock);
- ret = ice_vsi_realloc_stat_arrays(vsi);
+ ret = ice_vsi_resize_stat_arrays(vsi);
if (ret)
goto unlock;
--
2.47.1
next prev parent reply other threads:[~2026-09-21 18:21 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 18:20 [PATCH net v4 0/5][pull request] ice: fix stats array overflow via proper realloc Tony Nguyen
2026-09-21 18:21 ` [PATCH net v4 1/5] ice: extract __ice_vsi_free_stats() Tony Nguyen
2026-09-24 12:23 ` netdev-bot+sashiko
2026-09-21 18:21 ` [PATCH net v4 2/5] ice: extract ice_vsi_new_stat_arrays() Tony Nguyen
2026-09-21 18:21 ` [PATCH net v4 3/5] ice: extract ice_vsi_get_num_qs() Tony Nguyen
2026-09-21 18:21 ` Tony Nguyen [this message]
2026-09-24 12:23 ` [PATCH net v4 4/5] ice: rebuild ring stats arrays instead of reallocating them in place netdev-bot+sashiko
2026-09-21 18:21 ` [PATCH net v4 5/5] ice: fix stats array overflow when VF requests more queues Tony Nguyen
2026-09-24 12:23 ` netdev-bot+sashiko
2026-09-25 7:12 ` Przemek Kitszel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921182106.1015019-5-anthony.l.nguyen@intel.com \
--to=anthony.l.nguyen@intel.com \
--cc=aleksandr.loktionov@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=mschmidt@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=poros@redhat.com \
--cc=przemyslaw.kitszel@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox