Netdev List
 help / color / mirror / Atom feed
From: "Жамбакиев Радий Рикардинович" <r.zhambakiev@prosoftsystems.ru>
To: Andrew Lunn <andrew+netdev@lunn.ch>
Cc: "Жамбакиев Радий Рикардинович" <r.zhambakiev@prosoftsystems.ru>,
	"David S. Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	"Denis Benato" <benato.denis96@gmail.com>,
	"Jacob Keller" <jacob.e.keller@intel.com>,
	"Petr Machata" <petrm@nvidia.com>,
	"Uwe Kleine-König (The Capable Hub)"
	<u.kleine-koenig@baylibre.com>,
	"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"lvc-project@linuxtesting.org" <lvc-project@linuxtesting.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: [PATCH net 3/3] net: fealnx: allocate the card index from an IDA
Date: Thu, 24 Sep 2026 10:44:25 +0000	[thread overview]
Message-ID: <20260924104231.110576-3-r.zhambakiev@prosoftsystems.ru> (raw)
In-Reply-To: <20260924104231.110576-1-r.zhambakiev@prosoftsystems.ru>

From: Radiy Zhambakiev <r.zhambakiev@prosoftsystems.ru>

card_idx is a static counter that is incremented on every probe.
It can overflow and wrap to a negative value, which then indexes
options[] and full_duplex[] out of bounds. Large values also no
longer fit in the 12-byte boardname[] buffer.

Allocate the card index from an IDA and free it on probe failure and
remove. The IDA reuses ids on re-add, preserving the options[] and
full_duplex[] mapping by probe order.

Store the id in the driver-private data so fealnx_remove_one() can
free it, and size boardname to hold a full 32-bit id.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Radiy Zhambakiev <r.zhambakiev@prosoftsystems.ru>
---
 drivers/net/ethernet/fealnx.c | 22 +++++++++++++++++-----
 1 file changed, 17 insertions(+), 5 deletions(-)

diff --git a/drivers/net/ethernet/fealnx.c b/drivers/net/ethernet/fealnx.c
index 46a40d00b59a..c474dd5ac4c6 100644
--- a/drivers/net/ethernet/fealnx.c
+++ b/drivers/net/ethernet/fealnx.c
@@ -83,6 +83,7 @@ static int full_duplex[MAX_UNITS] = { -1, -1, -1, -1, -1, -1, -1, -1 };
 #include <linux/crc32.h>
 #include <linux/delay.h>
 #include <linux/bitops.h>
+#include <linux/idr.h>
 
 #include <asm/processor.h>	/* Processor type for cache alignment. */
 #include <asm/io.h>
@@ -143,6 +144,8 @@ struct chip_info {
 	int flags;
 };
 
+static DEFINE_IDA(fealnx_ida);
+
 static const struct chip_info skel_netdrv_tbl[] = {
 	{ "100/10M Ethernet PCI Adapter",	HAS_MII_XCVR },
 	{ "100/10M Ethernet PCI Adapter",	HAS_CHIP_XCVR },
@@ -411,6 +414,8 @@ struct netdev_private {
 	unsigned char phys[2];	/* MII device addresses. */
 	struct mii_if_info mii;
 	void __iomem *mem;
+
+	int card_idx;
 };
 
 
@@ -473,9 +478,8 @@ static int fealnx_init_one(struct pci_dev *pdev,
 			   const struct pci_device_id *ent)
 {
 	struct netdev_private *np;
-	int i, option, err, irq;
-	static int card_idx = -1;
-	char boardname[12];
+	int option, err, irq, i;
+	char boardname[18];
 	void __iomem *ioaddr;
 	unsigned long len;
 	unsigned int chip_id = ent->driver_data;
@@ -483,20 +487,24 @@ static int fealnx_init_one(struct pci_dev *pdev,
 	void *ring_space;
 	dma_addr_t ring_dma;
 	u8 addr[ETH_ALEN];
+	int card_idx;
 #ifdef USE_IO_OPS
 	int bar = 0;
 #else
 	int bar = 1;
 #endif
 
-	card_idx++;
+	card_idx = ida_alloc(&fealnx_ida, GFP_KERNEL);
+	if (card_idx < 0)
+		return card_idx;
+
 	sprintf(boardname, "fealnx%d", card_idx);
 
 	option = card_idx < MAX_UNITS ? options[card_idx] : 0;
 
 	err = pci_enable_device(pdev);
 	if (err)
-		return err;
+		goto err_out_ida;
 	pci_set_master(pdev);
 
 	len = pci_resource_len(pdev, bar);
@@ -536,6 +544,7 @@ static int fealnx_init_one(struct pci_dev *pdev,
 
 	/* Make certain the descriptor lists are aligned. */
 	np = netdev_priv(dev);
+	np->card_idx = card_idx;
 	np->mem = ioaddr;
 	spin_lock_init(&np->lock);
 	np->pci_dev = pdev;
@@ -675,6 +684,8 @@ static int fealnx_init_one(struct pci_dev *pdev,
 	pci_release_regions(pdev);
 err_out_disable:
 	pci_disable_device(pdev);
+err_out_ida:
+	ida_free(&fealnx_ida, card_idx);
 	return err;
 }
 
@@ -699,6 +710,7 @@ static void fealnx_remove_one(struct pci_dev *pdev)
 	pci_iounmap(pdev, np->mem);
 	pci_release_regions(pdev);
 	pci_disable_device(pdev);
+	ida_free(&fealnx_ida, np->card_idx);
 	free_netdev(dev);
 }
 
-- 
2.53.0

  parent reply	other threads:[~2026-09-24 10:44 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 10:44 [PATCH net 1/3] net: fealnx: fix teardown order in remove Жамбакиев Радий Рикардинович
2026-09-24 10:44 ` [PATCH net 2/3] net: fealnx: disable the PCI device on remove and probe failure Жамбакиев Радий Рикардинович
2026-09-24 21:52   ` Francois Romieu
2026-09-24 10:44 ` Жамбакиев Радий Рикардинович [this message]
2026-09-24 16:50   ` [PATCH net 3/3] net: fealnx: allocate the card index from an IDA Andrew Lunn
2026-09-24 16:43 ` [PATCH net 1/3] net: fealnx: fix teardown order in remove Andrew Lunn
2026-09-28 12:31   ` Жамбакиев Радий Рикардинович
2026-09-24 21:51 ` Francois Romieu
2026-09-28 12:32   ` Жамбакиев Радий Рикардинович
2026-09-30 22:37     ` Francois Romieu
2026-09-25 10:46 ` netdev-bot+sashiko
2026-09-28 13:08   ` Жамбакиев Радий Рикардинович

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924104231.110576-3-r.zhambakiev@prosoftsystems.ru \
    --to=r.zhambakiev@prosoftsystems.ru \
    --cc=andrew+netdev@lunn.ch \
    --cc=benato.denis96@gmail.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=jacob.e.keller@intel.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lvc-project@linuxtesting.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=petrm@nvidia.com \
    --cc=stable@vger.kernel.org \
    --cc=u.kleine-koenig@baylibre.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox