[PATCH] net/iavf: fix null pointer dereference in eCPRI FDIR pattern

[email protected]
Newsgroups org.dpdk.dev
Message-ID <[email protected]>
From: Sandeep Penigalapati <[email protected]>

In iavf_fdir_parse_pattern(), the RTE_FLOW_ITEM_TYPE_ECPRI case reads
ecpri_spec->hdr.common.u32 before checking that ecpri_spec is non-null.
A wildcard eCPRI flow item (no spec) with a queue or drop action, which
routes the rule to the FDIR engine, leaves item->spec as null, so the
unconditional dereference crashes the application at rule creation.

Move the ecpri_common read inside the existing
"if (ecpri_spec && ecpri_mask)" guard, mirroring the other pattern items
and the RSS-hash parser in iavf_hash.c which already handles a null
eCPRI spec. The rule is then rejected cleanly with -EINVAL.

Fixes: 6c37927479be ("net/iavf: support eCPRI message type 0 for flow director")
Cc: [email protected]
Signed-off-by: Sandeep Penigalapati <[email protected]>
---
 drivers/net/intel/iavf/iavf_fdir.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/net/intel/iavf/iavf_fdir.c b/drivers/net/intel/iavf/iavf_fdir.c
index ea620863ca..67003183bb 100644
--- a/drivers/net/intel/iavf/iavf_fdir.c
+++ b/drivers/net/intel/iavf/iavf_fdir.c
@@ -1271,13 +1271,13 @@ iavf_fdir_parse_pattern(__rte_unused struct iavf_adapter *ad,
 			ecpri_spec = item->spec;
 			ecpri_mask = item->mask;
 
-			ecpri_common.u32 = rte_be_to_cpu_32(ecpri_spec->hdr.common.u32);
-
 			hdr = &hdrs->proto_hdr[layer];
 
 			VIRTCHNL_SET_PROTO_HDR_TYPE(hdr, ECPRI);
 
 			if (ecpri_spec && ecpri_mask) {
+				ecpri_common.u32 = rte_be_to_cpu_32(ecpri_spec->hdr.common.u32);
+
 				if (ecpri_common.type == RTE_ECPRI_MSG_TYPE_IQ_DATA &&
 						ecpri_mask->hdr.type0.pc_id == UINT16_MAX) {
 					input_set |= IAVF_ECPRI_PC_RTC_ID;
-- 
2.27.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.