netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: "Kadosh, MoriyaX" <moriyax.kadosh@intel.com>
To: "Ruinskiy, Dima" <dima.ruinskiy@intel.com>,
	"Loktionov, Aleksandr" <aleksandr.loktionov@intel.com>,
	Ivy Lopez <skunkolee@gmail.com>,
	"Nguyen, Anthony L" <anthony.l.nguyen@intel.com>,
	"Kitszel, Przemyslaw" <przemyslaw.kitszel@intel.com>
Cc: "andrew+netdev@lunn.ch" <andrew+netdev@lunn.ch>,
	"davem@davemloft.net" <davem@davemloft.net>,
	"edumazet@google.com" <edumazet@google.com>,
	"kuba@kernel.org" <kuba@kernel.org>,
	"pabeni@redhat.com" <pabeni@redhat.com>,
	"intel-wired-lan@lists.osuosl.org"
	<intel-wired-lan@lists.osuosl.org>,
	"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: [Intel-wired-lan] [PATCH] e1000e: fix incorrect modified flag check in e1000_read_nvm_spt()
Date: Sun, 16 Aug 2026 13:05:48 +0300	[thread overview]
Message-ID: <71733617-814a-497d-a43e-421b688539da@intel.com> (raw)
In-Reply-To: <835dad4a-6873-4983-af3b-ea7b58f93a12@intel.com>



On 09/08/2026 12:21, Ruinskiy, Dima wrote:
> On 07/08/2026 13:56, Loktionov, Aleksandr wrote:
>>
>>
>>> -----Original Message-----
>>> From: Intel-wired-lan <intel-wired-lan-bounces@osuosl.org> On Behalf
>>> Of Ivy Lopez
>>> Sent: Thursday, August 6, 2026 7:25 PM
>>> To: Nguyen, Anthony L <anthony.l.nguyen@intel.com>; Kitszel,
>>> Przemyslaw <przemyslaw.kitszel@intel.com>
>>> Cc: andrew+netdev@lunn.ch; davem@davemloft.net; edumazet@google.com;
>>> kuba@kernel.org; pabeni@redhat.com; intel-wired-lan@lists.osuosl.org;
>>> netdev@vger.kernel.org; linux-kernel@vger.kernel.org; Ivy Lopez
>>> <skunkolee@gmail.com>
>>> Subject: [Intel-wired-lan] [PATCH] e1000e: fix incorrect modified flag
>>> check in e1000_read_nvm_spt()
>>>
>>> e1000_read_nvm_spt() reads two adjacent 16-bit NVM words as one 32-bit
>>> dword for efficiency. When deciding whether to use the shadow RAM
>>> value for the high word (data[i + 1]), it incorrectly checks the
>>> "modified" flag of the low word (shadow_ram[offset + i]) instead of
>>> the high word's own flag (shadow_ram[offset + i + 1]).
>>>
>>> This can cause silent NVM shadow RAM corruption:
>>>   - if only the high word is marked modified, its pending write is
>>>     lost and the stale flash value is returned instead
>>>   - if only the low word is marked modified, the high word is
>>>     incorrectly overwritten with the low word's shadow value
>>>
>>> This function is used on all PCH chips from SPT onward (SPT, CNP, TGP,
>>> ADP, MTP, etc). The bug has been present since the dword-read
>>> optimization was introduced for these chips.
>>>
>>> Note: this was found via code review while investigating a separate
>>> reproducible packet loss issue on I219-LM (SPT+ PCH). Testing showed
>>> this fix does not resolve that particular symptom, but the flag check
>>> is still a genuine logic bug that can corrupt shadow RAM contents and
>>> should be fixed regardless.
>>>
>>> Fixes: 79849ebc0e06 ("e1000e: initial support for i219")
>>> Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
>>> ---
>>>   drivers/net/ethernet/intel/e1000e/ich8lan.c | 2 +-
>>>   1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/drivers/net/ethernet/intel/e1000e/ich8lan.c
>>> b/drivers/net/ethernet/intel/e1000e/ich8lan.c
>>> index aa90e0ce8aca..87cd1cdc6f10 100644
>>> --- a/drivers/net/ethernet/intel/e1000e/ich8lan.c
>>> +++ b/drivers/net/ethernet/intel/e1000e/ich8lan.c
>>> @@ -3473,7 +3473,7 @@ static s32 e1000_read_nvm_spt(struct e1000_hw
>>> *hw, u16 offset, u16 words,
>>>                       dev_spec->shadow_ram[offset + i].value;
>>>               else
>>>                   data[i] = (u16)(dword & 0xFFFF);
>>> -            if (dev_spec->shadow_ram[offset + i].modified)
>>> +            if (dev_spec->shadow_ram[offset + i +
>>> 1].modified)
>>>                   data[i + 1] =
>>>                       dev_spec->shadow_ram[offset + i +
>>> 1].value;
>>>               else
>>> -- 
>>> 2.55.0
>>
>> Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
>>
> Reviewed-by: Dima Ruinskiy <dima.ruinskiy@intel.com>
> 
Tested-by: Moriya Kadosh <moriyax.kadosh@intel.com>


      reply	other threads:[~2026-08-16 10:06 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 17:24 [PATCH] e1000e: fix incorrect modified flag check in e1000_read_nvm_spt() Ivy Lopez
2026-08-07 10:56 ` [Intel-wired-lan] " Loktionov, Aleksandr
2026-08-09  9:21   ` Ruinskiy, Dima
2026-08-16 10:05     ` Kadosh, MoriyaX [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=71733617-814a-497d-a43e-421b688539da@intel.com \
    --to=moriyax.kadosh@intel.com \
    --cc=aleksandr.loktionov@intel.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=davem@davemloft.net \
    --cc=dima.ruinskiy@intel.com \
    --cc=edumazet@google.com \
    --cc=intel-wired-lan@lists.osuosl.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=skunkolee@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).