Netdev List
 help / color / mirror / Atom feed
From: "Жамбакиев Радий Рикардинович" <r.zhambakiev@prosoftsystems.ru>
To: Andrew Lunn <andrew+netdev@lunn.ch>
Cc: "Жамбакиев Радий Рикардинович" <r.zhambakiev@prosoftsystems.ru>,
	"David S. Miller" <davem@davemloft.net>,
	"Eric Dumazet" <edumazet@google.com>,
	"Jakub Kicinski" <kuba@kernel.org>,
	"Paolo Abeni" <pabeni@redhat.com>,
	"Michael Grzeschik" <mgr@kernel.org>,
	"Jijie Shao" <shaojijie@huawei.com>,
	"Aleksandr Loktionov" <aleksandr.loktionov@intel.com>,
	"Denis Benato" <benato.denis96@gmail.com>,
	"Uwe Kleine-König (The Capable Hub)"
	<u.kleine-koenig@baylibre.com>,
	"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"lvc-project@linuxtesting.org" <lvc-project@linuxtesting.org>,
	"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: [PATCH net v2 3/3] net: fealnx: allocate the card index from an IDA
Date: Fri, 2 Oct 2026 14:10:10 +0000	[thread overview]
Message-ID: <20261002140954.261779-4-r.zhambakiev@prosoftsystems.ru> (raw)
In-Reply-To: <20261002140954.261779-1-r.zhambakiev@prosoftsystems.ru>

From: Radiy Zhambakiev <r.zhambakiev@prosoftsystems.ru>

card_idx is a static counter that is incremented on every probe.
It can overflow and wrap to a negative value, which then indexes
options[] and full_duplex[] out of bounds. Large values also no
longer fit in the 12-byte boardname[] buffer.

Allocate the card index from an IDA and free it on probe failure and
remove. The IDA reuses ids on re-add, preserving the options[] and
full_duplex[] mapping by probe order.

Store the id in the driver-private data so fealnx_remove_one() can
free it, and size boardname to hold a full 32-bit id.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Signed-off-by: Radiy Zhambakiev <r.zhambakiev@prosoftsystems.ru>
---
Note on the IDA approach:

I really would like to go that way, as the proposed KISS way does
not really fix the main problem of infinitely incremented static
counter.

Constraining the probe to some arbitrary value also does not feel
right to me.

card_idx is incremented at the top of the probe, so even failing
probes will increment it. A failing device will eventually 
exhaust this counter at its retry rate.

 drivers/net/ethernet/fealnx.c | 25 +++++++++++++++++++------
 1 file changed, 19 insertions(+), 6 deletions(-)

diff --git a/drivers/net/ethernet/fealnx.c b/drivers/net/ethernet/fealnx.c
index b5e96c7037f3..627e570fd399 100644
--- a/drivers/net/ethernet/fealnx.c
+++ b/drivers/net/ethernet/fealnx.c
@@ -83,6 +83,7 @@ static int full_duplex[MAX_UNITS] = { -1, -1, -1, -1, -1, -1, -1, -1 };
 #include <linux/crc32.h>
 #include <linux/delay.h>
 #include <linux/bitops.h>
+#include <linux/idr.h>
 
 #include <asm/processor.h>	/* Processor type for cache alignment. */
 #include <asm/io.h>
@@ -143,6 +144,8 @@ struct chip_info {
 	int flags;
 };
 
+static DEFINE_IDA(fealnx_ida);
+
 static const struct chip_info skel_netdrv_tbl[] = {
 	{ "100/10M Ethernet PCI Adapter",	HAS_MII_XCVR },
 	{ "100/10M Ethernet PCI Adapter",	HAS_CHIP_XCVR },
@@ -411,6 +414,8 @@ struct netdev_private {
 	unsigned char phys[2];	/* MII device addresses. */
 	struct mii_if_info mii;
 	void __iomem *mem;
+
+	int card_idx;
 };
 
 
@@ -473,9 +478,8 @@ static int fealnx_init_one(struct pci_dev *pdev,
 			   const struct pci_device_id *ent)
 {
 	struct netdev_private *np;
-	int i, option, err, irq;
-	static int card_idx = -1;
-	char boardname[12];
+	int option, err, irq, i;
+	char boardname[18];
 	void __iomem *ioaddr;
 	unsigned long len;
 	unsigned int chip_id = ent->driver_data;
@@ -483,19 +487,24 @@ static int fealnx_init_one(struct pci_dev *pdev,
 	void *ring_space;
 	dma_addr_t ring_dma;
 	u8 addr[ETH_ALEN];
+	int card_idx;
 #ifdef USE_IO_OPS
 	int bar = 0;
 #else
 	int bar = 1;
 #endif
 
-	card_idx++;
+	card_idx = ida_alloc(&fealnx_ida, GFP_KERNEL);
+	if (card_idx < 0)
+		return card_idx;
+
 	sprintf(boardname, "fealnx%d", card_idx);
 
 	option = card_idx < MAX_UNITS ? options[card_idx] : 0;
 
-	i = pci_enable_device(pdev);
-	if (i) return i;
+	err = pci_enable_device(pdev);
+	if (err)
+		goto err_out_ida;
 	pci_set_master(pdev);
 
 	len = pci_resource_len(pdev, bar);
@@ -535,6 +544,7 @@ static int fealnx_init_one(struct pci_dev *pdev,
 
 	/* Make certain the descriptor lists are aligned. */
 	np = netdev_priv(dev);
+	np->card_idx = card_idx;
 	np->mem = ioaddr;
 	spin_lock_init(&np->lock);
 	np->pci_dev = pdev;
@@ -674,6 +684,8 @@ static int fealnx_init_one(struct pci_dev *pdev,
 	pci_release_regions(pdev);
 err_out_disable:
 	pci_disable_device(pdev);
+err_out_ida:
+	ida_free(&fealnx_ida, card_idx);
 	return err;
 }
 
@@ -691,6 +703,7 @@ static void fealnx_remove_one(struct pci_dev *pdev)
 		dma_free_coherent(&pdev->dev, RX_TOTAL_SIZE, np->rx_ring,
 				  np->rx_ring_dma);
 		pci_iounmap(pdev, np->mem);
+		ida_free(&fealnx_ida, np->card_idx);
 		free_netdev(dev);
 		pci_release_regions(pdev);
 		pci_disable_device(pdev);
-- 
2.53.0

  parent reply	other threads:[~2026-10-02 14:10 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 14:10 [PATCH net v2 0/3] net: fealnx: fix card-index overflow and PCI device teardown Жамбакиев Радий Рикардинович
2026-10-02 14:10 ` [PATCH net v2 1/3] net: fealnx: fix teardown order in remove Жамбакиев Радий Рикардинович
2026-10-02 14:18   ` Loktionov, Aleksandr
2026-10-02 14:18   ` Loktionov, Aleksandr
2026-10-06 14:31   ` netdev-bot+sashiko
2026-10-02 14:10 ` [PATCH net v2 2/3] net: fealnx: disable the PCI device on remove and probe failure Жамбакиев Радий Рикардинович
2026-10-02 14:10 ` Жамбакиев Радий Рикардинович [this message]
2026-10-02 20:28   ` [PATCH net v2 3/3] net: fealnx: allocate the card index from an IDA Andrew Lunn
2026-10-06 14:31   ` netdev-bot+sashiko
2026-10-02 14:13 ` [PATCH net v2 0/3] net: fealnx: fix card-index overflow and PCI device teardown netdev-bot+sinfo
2026-10-02 14:20   ` Жамбакиев Радий Рикардинович

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002140954.261779-4-r.zhambakiev@prosoftsystems.ru \
    --to=r.zhambakiev@prosoftsystems.ru \
    --cc=aleksandr.loktionov@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=benato.denis96@gmail.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lvc-project@linuxtesting.org \
    --cc=mgr@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=shaojijie@huawei.com \
    --cc=stable@vger.kernel.org \
    --cc=u.kleine-koenig@baylibre.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox