From: Michael Chan <michael.chan@broadcom.com>
To: davem@davemloft.net
Cc: netdev@vger.kernel.org, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, andrew+netdev@lunn.ch,
pavan.chebbi@broadcom.com, andrew.gospodarek@broadcom.com,
joe@dama.to
Subject: [PATCH net v2 1/9] bnxt_en: Clear bp->total_irqs in bnxt_init_int_mode() during error
Date: Sun, 27 Sep 2026 21:17:04 -0700 [thread overview]
Message-ID: <20260928041712.3467803-2-michael.chan@broadcom.com> (raw)
In-Reply-To: <20260928041712.3467803-1-michael.chan@broadcom.com>
During error, bnxt_init_int_mode() will free bp->irq_tbl but
bp->total_irqs retains the old value. If a subsequent
reinitialization happens, bnxt_reserve_rings() may see that
bp->total_irqs does not match a new irqs_required. It will then
try to adjust if dynamic MSI-X is supported and call
bnxt_change_msix(). It will then crash when dereferencing the NULL
bp->irq_tbl.
Fix it by clearing bp->total_irqs when freeing bp->irq_tbl. Dynamic
MSI-X adjustments should only proceed if bp->irq_tbl is valid which
means that MSI-X has been initialized and can be adjusted.
Add a bp->irq_tbl_size to prevent OOB bp->irq_tbl[] array access in
case MSI-X capabilities change during re-init. For dynamic MSI-X,
allocate the biggest bp->irq_tbl that is not clamped by CP/NQ rings
to allow dynamic MSI-X to grow to the max.
In the AER path, if MSI-X capabilities change, bnxt_reserve_rings()
will initialize MSI-X if BNXT_NEW_RM() is true. Add a check in
bnxt_io_resume() to skip doing it again later.
Fixes: e68256c8a73c ("bnxt_en: Support dynamic MSIX")
Reviewed-by: Andy Gospodarek <andrew.gospodarek@broadcom.com>
Signed-off-by: Michael Chan <michael.chan@broadcom.com>
---
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 18 ++++++++++++++----
drivers/net/ethernet/broadcom/bnxt/bnxt.h | 1 +
2 files changed, 15 insertions(+), 4 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
index d7728d0c5b6e..51557ee6c9ad 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c
@@ -11511,6 +11511,12 @@ static int bnxt_change_msix(struct bnxt *bp, int total)
struct msi_map map;
int i;
+ if (!bp->irq_tbl)
+ return 0;
+
+ if (total > bp->irq_tbl_size)
+ return bp->total_irqs;
+
/* add MSIX to the end if needed */
for (i = bp->total_irqs; i < total; i++) {
map = pci_msix_alloc_irq_at(bp->pdev, i, NULL);
@@ -11653,12 +11659,13 @@ static int bnxt_init_int_mode(struct bnxt *bp)
tbl_size = total_vecs;
if (pci_msix_can_alloc_dyn(bp->pdev))
- tbl_size = max;
+ tbl_size = bp->hw_resc.max_irqs;
bp->irq_tbl = kzalloc_objs(*bp->irq_tbl, tbl_size);
if (!bp->irq_tbl) {
rc = -ENOMEM;
goto msix_setup_exit;
}
+ bp->irq_tbl_size = tbl_size;
for (i = 0; i < total_vecs; i++)
bp->irq_tbl[i].vector = pci_irq_vector(bp->pdev, i);
@@ -11681,6 +11688,8 @@ static int bnxt_init_int_mode(struct bnxt *bp)
netdev_err(bp->dev, "bnxt_init_int_mode err: %x\n", rc);
kfree(bp->irq_tbl);
bp->irq_tbl = NULL;
+ bp->total_irqs = 0;
+ bp->irq_tbl_size = 0;
pci_free_irq_vectors(bp->pdev);
return rc;
}
@@ -11691,6 +11700,7 @@ static void bnxt_clear_int_mode(struct bnxt *bp)
kfree(bp->irq_tbl);
bp->irq_tbl = NULL;
+ bp->irq_tbl_size = 0;
}
int bnxt_reserve_rings(struct bnxt *bp, bool irq_re_init)
@@ -11717,7 +11727,7 @@ int bnxt_reserve_rings(struct bnxt *bp, bool irq_re_init)
if (irq_re_init && BNXT_NEW_RM(bp) && irqs_required != bp->total_irqs) {
irq_change = true;
- if (!pci_msix_can_alloc_dyn(bp->pdev)) {
+ if (!pci_msix_can_alloc_dyn(bp->pdev) || !bp->irq_tbl) {
bnxt_ulp_irq_stop(bp);
bnxt_clear_int_mode(bp);
irq_cleared = true;
@@ -15081,7 +15091,7 @@ int bnxt_check_rings(struct bnxt *bp, int tx, int rx, bool sh, int tcs,
hwr.cp += bnxt_get_ulp_msix_num(bp);
hwr.cp = min_t(int, hwr.cp, bnxt_get_max_func_irqs(bp));
}
- if (hwr.cp > bp->total_irqs) {
+ if (bp->irq_tbl && hwr.cp > bp->total_irqs) {
int total_msix = bnxt_change_msix(bp, hwr.cp);
if (total_msix < hwr.cp) {
@@ -17692,7 +17702,7 @@ static void bnxt_io_resume(struct pci_dev *pdev)
err = bnxt_open(netdev);
} else {
err = bnxt_reserve_rings(bp, true);
- if (!err)
+ if (!err && !bp->irq_tbl)
err = bnxt_init_int_mode(bp);
}
}
diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.h b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
index c673b2ce4a0d..a757d8258f71 100644
--- a/drivers/net/ethernet/broadcom/bnxt/bnxt.h
+++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.h
@@ -2490,6 +2490,7 @@ struct bnxt {
*/
unsigned long *ring_affinity_set;
int max_irqs;
+ int irq_tbl_size;
int total_irqs;
int ulp_num_msix_want;
u8 mac_addr[ETH_ALEN];
--
2.51.0
next prev parent reply other threads:[~2026-09-28 4:19 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 4:17 [PATCH net v2 0/9] bnxt_en: Bug fixes Michael Chan
2026-09-28 4:17 ` Michael Chan [this message]
2026-10-01 1:01 ` [PATCH net v2 1/9] bnxt_en: Clear bp->total_irqs in bnxt_init_int_mode() during error netdev-bot+sashiko
2026-09-28 4:17 ` [PATCH net v2 2/9] bnxt_en: Fix bnxt_reinit_features() when irq_re_init is true Michael Chan
2026-09-28 4:17 ` [PATCH net v2 3/9] bnxt_en: Refactor RSS table check logic Michael Chan
2026-09-28 4:17 ` [PATCH net v2 4/9] bnxt_en: Refactor IRQs required logic Michael Chan
2026-09-28 4:17 ` [PATCH net v2 5/9] bnxt_en: Reinit IRQ when configuring LRO/GRO/HDS Michael Chan
2026-09-28 4:17 ` [PATCH net v2 6/9] bnxt_en: Fix ring accounting and validation when rings are constrained Michael Chan
2026-10-01 1:01 ` netdev-bot+sashiko
2026-09-28 4:17 ` [PATCH net v2 7/9] bnxt_en: Add bnxt_clear_bars() helper Michael Chan
2026-09-28 4:17 ` [PATCH net v2 8/9] bnxt_en: Fix driver init in kdump kernel Michael Chan
2026-10-01 1:01 ` netdev-bot+sashiko
2026-09-28 4:17 ` [PATCH net v2 9/9] bnxt_en: Re-write the BARs following any type of PCIe errors Michael Chan
2026-10-01 1:01 ` netdev-bot+sashiko
2026-10-01 9:26 ` Pavan Chebbi
2026-09-28 4:25 ` [PATCH net v2 0/9] bnxt_en: Bug fixes netdev-bot+sinfo
2026-10-01 1:03 ` Jakub Kicinski
2026-10-01 19:22 ` Michael Chan
2026-10-02 17:24 ` Jakub Kicinski
2026-10-03 14:08 ` Pavan Chebbi
2026-10-02 17:24 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928041712.3467803-2-michael.chan@broadcom.com \
--to=michael.chan@broadcom.com \
--cc=andrew+netdev@lunn.ch \
--cc=andrew.gospodarek@broadcom.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=joe@dama.to \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pavan.chebbi@broadcom.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox