Re: [PATCH net-next v3] net/ionic: avoid OOB TX partner lookup for hwstamp RXQ

"Creeley, Brett" <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>

On 8/13/2026 1:37 AM, Anand Khoje wrote:
> Caution: This message originated from an External Source. Use proper caution when opening attachments, clicking links, or responding.
>
>
> The dedicated hardware timestamp RX queue is allocated with q->index
> equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only
> contains the regular queue pairs, so using that index to set rxq->partner
> can read one entry past txqcqs[] and then write through the derived
> pointer.
> Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp
> RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue
> has no TX partner.
>
> Fixes: 8eeed8373e1c ("ionic: Add XDP_TX support")
> Signed-off-by: Anand Khoje <[email protected]>
> Reviewed-by: Si-Wei Liu <[email protected]>
> Reviewed-by: Shannon Nelson <[email protected]>
> Cc: [email protected]
> ---
> v3:
>   Use dev_err() and return -ENXIO for a missing normal TX partner.
>
> v2:
>   Correct the Fixes tag.
>
>   drivers/net/ethernet/pensando/ionic/ionic_lif.c | 17 +++++++++++++++--
>   .../net/ethernet/pensando/ionic/ionic_txrx.c    |  7 ++++++-
>   2 files changed, 21 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/net/ethernet/pensando/ionic/ionic_lif.c b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> index fd3ee98..abc8e35 100644
> --- a/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> +++ b/drivers/net/ethernet/pensando/ionic/ionic_lif.c
> @@ -920,8 +920,21 @@ static int ionic_lif_rxq_init(struct ionic_lif *lif, struct ionic_qcq *qcq)
>          };
>          int err;
>
> -       q->partner = &lif->txqcqs[q->index]->q;
> -       q->partner->partner = q;
> +       q->partner = NULL;
> +
> +       /* Only normal RX queues have matching TX queue partners. */
> +       if (q->index < lif->nxqs) {
> +               if (!lif->txqcqs ||
> +                   q->index >= lif->ionic->ntxqs_per_lif ||
> +                   !lif->txqcqs[q->index]) {
> +                       dev_err(dev, "missing TX queue partner for RX queue %u\n",
> +                               q->index);
> +                       return -ENXIO;
> +               }
> +
> +               q->partner = &lif->txqcqs[q->index]->q;
> +               q->partner->partner = q;
> +       }
>
>          if (!lif->xdp_prog ||
>              (lif->xdp_prog->aux && lif->xdp_prog->aux->xdp_has_frags))
> diff --git a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> index 301ebee..73998d6 100644
> --- a/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> +++ b/drivers/net/ethernet/pensando/ionic/ionic_txrx.c
> @@ -545,13 +545,18 @@ static bool ionic_run_xdp(struct ionic_rx_stats *stats,
>                  break;
>
>          case XDP_TX:
> +               txq = rxq->partner;
> +               if (unlikely(!txq)) {
> +                       err = -EIO;
> +                       break;
> +               }
> +
>                  xdpf = xdp_convert_buff_to_frame(&xdp_buf);
>                  if (!xdpf) {
>                          err = -ENOSPC;
>                          break;
>                  }
>
> -               txq = rxq->partner;
>                  nq = netdev_get_tx_queue(netdev, txq->index);
>                  __netif_tx_lock(nq, smp_processor_id());
>                  txq_trans_cond_update(nq);

LGTM. Thanks for the fix.

Reviewed-by: Brett Creeley <[email protected]>
> --
> 2.52.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.