Netdev List
 help / color / mirror / Atom feed
From: Ratheesh Kannoth <rkannoth@marvell.com>
To: <linux-kernel@vger.kernel.org>, <linux-rdma@vger.kernel.org>,
	<netdev@vger.kernel.org>, <oss-drivers@corigine.com>
Cc: <akiyano@amazon.com>, <andrew+netdev@lunn.ch>,
	<anthony.l.nguyen@intel.com>, <arkadiusz.kubalewski@intel.com>,
	<brett.creeley@amd.com>, <darinzon@amazon.com>,
	<davem@davemloft.net>, <donald.hunter@gmail.com>,
	<edumazet@google.com>, <horms@kernel.org>, <idosch@nvidia.com>,
	<ivecera@redhat.com>, <jiri@resnulli.us>, <kuba@kernel.org>,
	<leon@kernel.org>, <mbloch@nvidia.com>,
	<michael.chan@broadcom.com>, <pabeni@redhat.com>,
	<pavan.chebbi@broadcom.com>, <petrm@nvidia.com>,
	<Prathosh.Satish@microchip.com>, <przemyslaw.kitszel@intel.com>,
	<saeedm@nvidia.com>, <sgoutham@marvell.com>, <tariqt@nvidia.com>,
	<vadim.fedorenko@linux.dev>
Subject: Re: [PATCH v15 net-next 6/9] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle
Date: Thu, 21 May 2026 09:03:07 +0530	[thread overview]
Message-ID: <ag5884G9AcnQaaO5@rkannoth-OptiPlex-7090> (raw)
In-Reply-To: <20260520020939.1457231-7-rkannoth@marvell.com>

On 2026-05-20 at 07:39:36, Ratheesh Kannoth (rkannoth@marvell.com) wrote:
> Add NIX_LF_DONT_FREE_DFT_IDXS so the PF can send NIX LF free during hw
> reinit or teardown without the AF freeing CN20K default NPC rule indexes
> while the driver still owns that state (otx2_init_hw_resources and
> otx2_free_hw_resources).

>
>>  	/* Alloc NIX RQ HW context memory and config the base */
>>  	hwctx_size = 1UL << ((ctx_cfg >> 4) & 0xF);
>> -	err = qmem_alloc(rvu->dev, &pfvf->rq_ctx, req->rq_cnt, hwctx_size);
>> -	if (err)
>> +	rc = qmem_alloc(rvu->dev, &pfvf->rq_ctx, req->rq_cnt, hwctx_size);
>> +	if (rc)
>>  		goto free_mem;
>This isn't a bug introduced by this patch, but can repeated NIX_LF_ALLOC
>mailbox messages cause an unbounded memory leak of host DMA and heap memory?
>The function rvu_mbox_handler_nix_lf_alloc() handles the NIX_LF_ALLOC
>mailbox request by allocating memory for several context structures via
>qmem_alloc() and context bitmaps via kcalloc(). The pointers to these new
>allocations are written directly to the pfvf structure.
>However, there appears to be no check to ensure the contexts have not been
>allocated already, nor are existing allocations freed. Can a guest VM (VF)
>trigger this by repeatedly sending the NIX_LF_ALLOC message, constantly
>triggering new allocations while abandoning the previous pointers? This
>might leak host memory (especially dma_alloc_attrs space used in
>qmem_alloc()), potentially leading to host memory exhaustion.

The number of available NIX LFs is
structurally finite and bounded by the hardware topology. A VF/PF cannot
arbitrarily trigger allocations without successfully provisioned LF
resources. Furthermore, the NIX_LF_FREE mailbox path guarantees the
complete rollback and freeing of all hardware context memories (via
qmem_free) and bitmaps allocated during NIX_LF_ALLOC.

Repeated calls to NIX_LF_ALLOC on an already active/
allocated LF context are rejected earlier in the pipeline by validation
checks verifying block provisioning status, preventing dangling pointers or
unbounded heap leaks in nominal operation.

this patch strictly unifies the error return code
variable from 'err' to 'rc' to match driver-wide conventions. Addressing
secondary, pre-existing hardening improvements for the allocation path falls
outside the scope of this transactional fix and is better suited as a
separate hardening patch targeted at net-next.

  reply	other threads:[~2026-05-21  3:33 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-20  2:09 [PATCH v15 net-next 0/9] octeontx2-af: npc: Enhancements Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 1/9] octeontx2-af: npc: cn20k: debugfs enhancements Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 2/9] net/mlx5e: Reduce stack use reading PCIe congestion thresholds Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 3/9] devlink: pass param values by pointer Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 4/9] devlink: Implement devlink param multi attribute nested data values Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 5/9] octeontx2-af: npc: cn20k: add subbank search order control Ratheesh Kannoth
2026-05-21  3:31   ` Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 6/9] octeontx2: cn20k: Coordinate default rules with NIX LF lifecycle Ratheesh Kannoth
2026-05-21  3:33   ` Ratheesh Kannoth [this message]
2026-05-20  2:09 ` [PATCH v15 net-next 7/9] octeontx2-af: npc: Support for custom KPU profile from filesystem Ratheesh Kannoth
2026-05-21  3:34   ` Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 8/9] octeontx2: cn20k: Respect NPC MCAM X2/X4 profile in flows and DFT alloc Ratheesh Kannoth
2026-05-21  3:37   ` Ratheesh Kannoth
2026-05-20  2:09 ` [PATCH v15 net-next 9/9] octeontx2-af: npc: cn20k: Allocate npc_priv and dstats dynamically Ratheesh Kannoth
2026-05-21  3:38   ` Ratheesh Kannoth

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ag5884G9AcnQaaO5@rkannoth-OptiPlex-7090 \
    --to=rkannoth@marvell.com \
    --cc=Prathosh.Satish@microchip.com \
    --cc=akiyano@amazon.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=anthony.l.nguyen@intel.com \
    --cc=arkadiusz.kubalewski@intel.com \
    --cc=brett.creeley@amd.com \
    --cc=darinzon@amazon.com \
    --cc=davem@davemloft.net \
    --cc=donald.hunter@gmail.com \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=ivecera@redhat.com \
    --cc=jiri@resnulli.us \
    --cc=kuba@kernel.org \
    --cc=leon@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=mbloch@nvidia.com \
    --cc=michael.chan@broadcom.com \
    --cc=netdev@vger.kernel.org \
    --cc=oss-drivers@corigine.com \
    --cc=pabeni@redhat.com \
    --cc=pavan.chebbi@broadcom.com \
    --cc=petrm@nvidia.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=saeedm@nvidia.com \
    --cc=sgoutham@marvell.com \
    --cc=tariqt@nvidia.com \
    --cc=vadim.fedorenko@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox