Linux kernel -stable discussions
 help / color / mirror / Atom feed
From: Amelia Crate <acrate@waldn.net>
To: stable@vger.kernel.org
Cc: dimitri.ledkov@surgut.co.uk, ecree.xilinx@gmail.com
Subject: [PATCH 4/4] sfc: fix NULL dereferences in ef100_process_design_param()
Date: Wed, 29 Oct 2025 17:27:52 -0500	[thread overview]
Message-ID: <fee57ade-3564-44cf-b14c-c505de03087c@waldn.net> (raw)
In-Reply-To: <9415e0e3-77b6-4a9b-a26e-1def9e2bc5d5@waldn.net>

From b352b49724e0bc21ba8679a5a8aaf4d8adb660d0 Mon Sep 17 00:00:00 2001
From: Edward Cree <ecree.xilinx@gmail.com>
Date: Tue, 1 Apr 2025 23:54:39 +0100
Subject: [PATCH 4/4] sfc: fix NULL dereferences in
 ef100_process_design_param()

[ Upstream commit 8241ecec1cdc6699ae197d52d58e76bddd995fa5 ]

Since cited commit, ef100_probe_main() and hence also
 ef100_check_design_params() run before efx->net_dev is created;
 consequently, we cannot netif_set_tso_max_size() or _segs() at this
 point.
Move those netif calls to ef100_probe_netdev(), and also replace
 netif_err within the design params code with pci_err.

Reported-by: Kyungwook Boo <bookyungwook@gmail.com>
Fixes: 98ff4c7c8ac7 ("sfc: Separate netdev probe/remove from PCI probe/remove")
Signed-off-by: Edward Cree <ecree.xilinx@gmail.com>
Reviewed-by: Michal Swiatkowski <michal.swiatkowski@linux.intel.com>
Link: https://patch.msgid.link/20250401225439.2401047-1-edward.cree@amd.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Amelia Crate <acrate@waldn.net>
---
 drivers/net/ethernet/sfc/ef100_netdev.c |  6 ++--
 drivers/net/ethernet/sfc/ef100_nic.c    | 47 +++++++++++--------------
 2 files changed, 24 insertions(+), 29 deletions(-)

diff --git a/drivers/net/ethernet/sfc/ef100_netdev.c b/drivers/net/ethernet/sfc/ef100_netdev.c
index 7f7d560cb2b4..14dcca4ffb33 100644
--- a/drivers/net/ethernet/sfc/ef100_netdev.c
+++ b/drivers/net/ethernet/sfc/ef100_netdev.c
@@ -450,8 +450,9 @@ int ef100_probe_netdev(struct efx_probe_data *probe_data)
     net_dev->hw_enc_features |= efx->type->offload_features;
     net_dev->vlan_features |= NETIF_F_HW_CSUM | NETIF_F_SG |
                   NETIF_F_HIGHDMA | NETIF_F_ALL_TSO;
-    netif_set_tso_max_segs(net_dev,
-                   ESE_EF100_DP_GZ_TSO_MAX_HDR_NUM_SEGS_DEFAULT);
+    nic_data = efx->nic_data;
+    netif_set_tso_max_size(efx->net_dev, nic_data->tso_max_payload_len);
+    netif_set_tso_max_segs(efx->net_dev, nic_data->tso_max_payload_num_segs);
     efx->mdio.dev = net_dev;

     rc = efx_ef100_init_datapath_caps(efx);
@@ -478,7 +479,6 @@ int ef100_probe_netdev(struct efx_probe_data *probe_data)
     /* Don't fail init if RSS setup doesn't work. */
     efx_mcdi_push_default_indir_table(efx, efx->n_rx_channels);

-    nic_data = efx->nic_data;
     rc = ef100_get_mac_address(efx, net_dev->perm_addr, CLIENT_HANDLE_SELF,
                    efx->type->is_vf);
     if (rc)
diff --git a/drivers/net/ethernet/sfc/ef100_nic.c b/drivers/net/ethernet/sfc/ef100_nic.c
index 6da06931187d..5b1bdcac81d9 100644
--- a/drivers/net/ethernet/sfc/ef100_nic.c
+++ b/drivers/net/ethernet/sfc/ef100_nic.c
@@ -887,8 +887,7 @@ static int ef100_process_design_param(struct efx_nic *efx,
     case ESE_EF100_DP_GZ_TSO_MAX_HDR_NUM_SEGS:
         /* We always put HDR_NUM_SEGS=1 in our TSO descriptors */
         if (!reader->value) {
-            netif_err(efx, probe, efx->net_dev,
-                  "TSO_MAX_HDR_NUM_SEGS < 1\n");
+            pci_err(efx->pci_dev, "TSO_MAX_HDR_NUM_SEGS < 1\n");
             return -EOPNOTSUPP;
         }
         return 0;
@@ -901,32 +900,28 @@ static int ef100_process_design_param(struct efx_nic *efx,
          */
         if (!reader->value || reader->value > EFX_MIN_DMAQ_SIZE ||
             EFX_MIN_DMAQ_SIZE % (u32)reader->value) {
-            netif_err(efx, probe, efx->net_dev,
-                  "%s size granularity is %llu, can't guarantee safety\n",
-                  reader->type == ESE_EF100_DP_GZ_RXQ_SIZE_GRANULARITY ? "RXQ" : "TXQ",
-                  reader->value);
+            pci_err(efx->pci_dev,
+                "%s size granularity is %llu, can't guarantee safety\n",
+                reader->type == ESE_EF100_DP_GZ_RXQ_SIZE_GRANULARITY ? "RXQ" : "TXQ",
+                reader->value);
             return -EOPNOTSUPP;
         }
         return 0;
     case ESE_EF100_DP_GZ_TSO_MAX_PAYLOAD_LEN:
         nic_data->tso_max_payload_len = min_t(u64, reader->value,
                               GSO_LEGACY_MAX_SIZE);
-        netif_set_tso_max_size(efx->net_dev,
-                       nic_data->tso_max_payload_len);
         return 0;
     case ESE_EF100_DP_GZ_TSO_MAX_PAYLOAD_NUM_SEGS:
         nic_data->tso_max_payload_num_segs = min_t(u64, reader->value, 0xffff);
-        netif_set_tso_max_segs(efx->net_dev,
-                       nic_data->tso_max_payload_num_segs);
         return 0;
     case ESE_EF100_DP_GZ_TSO_MAX_NUM_FRAMES:
         nic_data->tso_max_frames = min_t(u64, reader->value, 0xffff);
         return 0;
     case ESE_EF100_DP_GZ_COMPAT:
         if (reader->value) {
-            netif_err(efx, probe, efx->net_dev,
-                  "DP_COMPAT has unknown bits %#llx, driver not compatible with this hw\n",
-                  reader->value);
+            pci_err(efx->pci_dev,
+                "DP_COMPAT has unknown bits %#llx, driver not compatible with this hw\n",
+                reader->value);
             return -EOPNOTSUPP;
         }
         return 0;
@@ -946,10 +941,10 @@ static int ef100_process_design_param(struct efx_nic *efx,
          * So the value of this shouldn't matter.
          */
         if (reader->value != ESE_EF100_DP_GZ_VI_STRIDES_DEFAULT)
-            netif_dbg(efx, probe, efx->net_dev,
-                  "NIC has other than default VI_STRIDES (mask "
-                  "%#llx), early probing might use wrong one\n",
-                  reader->value);
+            pci_dbg(efx->pci_dev,
+                "NIC has other than default VI_STRIDES (mask "
+                "%#llx), early probing might use wrong one\n",
+                reader->value);
         return 0;
     case ESE_EF100_DP_GZ_RX_MAX_RUNT:
         /* Driver doesn't look at L2_STATUS:LEN_ERR bit, so we don't
@@ -961,9 +956,9 @@ static int ef100_process_design_param(struct efx_nic *efx,
         /* Host interface says "Drivers should ignore design parameters
          * that they do not recognise."
          */
-        netif_dbg(efx, probe, efx->net_dev,
-              "Ignoring unrecognised design parameter %u\n",
-              reader->type);
+        pci_dbg(efx->pci_dev,
+            "Ignoring unrecognised design parameter %u\n",
+            reader->type);
         return 0;
     }
 }
@@ -999,13 +994,13 @@ static int ef100_check_design_params(struct efx_nic *efx)
      */
     if (reader.state != EF100_TLV_TYPE) {
         if (reader.state == EF100_TLV_TYPE_CONT)
-            netif_err(efx, probe, efx->net_dev,
-                  "truncated design parameter (incomplete type %u)\n",
-                  reader.type);
+            pci_err(efx->pci_dev,
+                "truncated design parameter (incomplete type %u)\n",
+                reader.type);
         else
-            netif_err(efx, probe, efx->net_dev,
-                  "truncated design parameter %u\n",
-                  reader.type);
+            pci_err(efx->pci_dev,
+                "truncated design parameter %u\n",
+                reader.type);
         rc = -EIO;
     }
 out:
--
2.50.1

  reply	other threads:[~2025-10-29 22:27 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-10-29 22:24 [PATCH 0/4] Backport CVE fixes to 6.12.y Amelia Crate
2025-10-29 22:25 ` [PATCH 1/4] iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE Amelia Crate
2025-10-29 22:26   ` [PATCH 2/4] udmabuf: fix a buf size overflow issue during udmabuf creation Amelia Crate
2025-10-29 22:27     ` [PATCH 3/4] wifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev() Amelia Crate
2025-10-29 22:27       ` Amelia Crate [this message]
2025-10-30  5:26 ` [PATCH 0/4] Backport CVE fixes to 6.12.y Greg KH
2025-10-30 16:08   ` [PATCH v2 " Amelia Crate
2025-10-30 16:08     ` [PATCH v2 1/4] iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE Amelia Crate
2025-10-30 16:08     ` [PATCH v2 2/4] udmabuf: fix a buf size overflow issue during udmabuf creation Amelia Crate
2025-10-30 16:08     ` [PATCH v2 3/4] wifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev() Amelia Crate
2025-10-30 16:08     ` [PATCH v2 4/4] sfc: fix NULL dereferences in ef100_process_design_param() Amelia Crate

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=fee57ade-3564-44cf-b14c-c505de03087c@waldn.net \
    --to=acrate@waldn.net \
    --cc=dimitri.ledkov@surgut.co.uk \
    --cc=ecree.xilinx@gmail.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox