mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
bnxt_en: Bound SW TPA IDs to prevent crashes
FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commitec4d8e7cf0("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a software ID which is used to index rxr->rx_tpa, and to generate a mapping between FW IDs and the wrapped software ID. On a 57608 with firmware version 233, the firmware advertises 32 concurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC is set to 32. If the software ID from bnxt_alloc_agg_idx is above 31, this results in an invalid address being loaded on this line: tpa_info = &rxr->rx_tpa[agg_id]; because rx_tpa is allocated with only bp->max_tpa (32) entries. Writes to tpa_info later in the code are out of bounds. This bug results in a crash at boot: Oops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [#1] SMP NOPTI RIP: 0010:bnxt_rx_pkt+0xc0/0x1560 RSP: 0018:ffffc900009b8c78 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516 RDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0 RBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048 R10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516 R13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680 FS: 0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0 PKRU: 55555554 Call Trace: <IRQ> ? __netif_receive_skb_list_core+0x1ca/0x250 __bnxt_poll_work+0x152/0x280 bnxt_poll_p5+0x1cd/0x480 __napi_poll+0x30/0x180 net_rx_action+0x20b/0x3b0 ? note_gp_changes+0x53/0xe0 ? tick_setup_sched_timer+0x180/0x180 ? __napi_schedule+0x9a/0xb0 ? bnxt_msix+0x24/0x30 handle_softirqs+0xdd/0x2c0 __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0 common_interrupt+0x85/0x90 </IRQ> <TASK> asm_common_interrupt+0x22/0x40 This stack trace is from a crash triggered when an out of bounds rx_tpa is dereferenced. The invalid write mentioned above is silent in this particular crash. Fix this by allocating rx_tpa with bp->max_tpa rounded up to the next power of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID with that size, so the wrapped ID can never index past the end of the array. Fixes:54c28fab2f("bnxt_en: Set bp->max_tpa according to what the FW supports") Reported-by: Raphael Cardoso Fernandes <raphaelcf@meta.com> Suggested-by: Michael Chan <michael.chan@broadcom.com> Cc: stable@vger.kernel.org Signed-off-by: Joe Damato <joe@dama.to> Link: https://patch.msgid.link/20260902015652.2421609-7-joe@dama.to Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
8e6a850c07
commit
c0aceaf65b
|
|
@ -1534,14 +1534,16 @@ static int bnxt_discard_rx(struct bnxt *bp, struct bnxt_cp_ring_info *cpr,
|
|||
return 0;
|
||||
}
|
||||
|
||||
static u16 bnxt_alloc_agg_idx(struct bnxt_rx_ring_info *rxr, u16 agg_id)
|
||||
static u16 bnxt_alloc_agg_idx(struct bnxt *bp, struct bnxt_rx_ring_info *rxr,
|
||||
u16 agg_id)
|
||||
{
|
||||
struct bnxt_tpa_idx_map *map = rxr->rx_tpa_idx_map;
|
||||
u16 idx = agg_id & MAX_TPA_P5_MASK;
|
||||
u16 idx = agg_id & (bp->max_tpa_roundup_size - 1);
|
||||
|
||||
if (test_bit(idx, map->agg_idx_bmap)) {
|
||||
idx = find_first_zero_bit(map->agg_idx_bmap, MAX_TPA_P5);
|
||||
if (idx >= MAX_TPA_P5)
|
||||
idx = find_first_zero_bit(map->agg_idx_bmap,
|
||||
bp->max_tpa_roundup_size);
|
||||
if (idx >= bp->max_tpa_roundup_size)
|
||||
return INVALID_HW_RING_ID;
|
||||
}
|
||||
__set_bit(idx, map->agg_idx_bmap);
|
||||
|
|
@ -1606,7 +1608,7 @@ static void bnxt_tpa_start(struct bnxt *bp, struct bnxt_rx_ring_info *rxr,
|
|||
|
||||
if (bp->flags & BNXT_FLAG_CHIP_P5_PLUS) {
|
||||
agg_id = TPA_START_AGG_ID_P5(tpa_start);
|
||||
agg_id = bnxt_alloc_agg_idx(rxr, agg_id);
|
||||
agg_id = bnxt_alloc_agg_idx(bp, rxr, agg_id);
|
||||
if (unlikely(agg_id == INVALID_HW_RING_ID)) {
|
||||
netdev_warn(bp->dev, "Unable to allocate agg ID for ring %d, agg 0x%x\n",
|
||||
rxr->bnapi->index,
|
||||
|
|
@ -3604,7 +3606,7 @@ static void bnxt_free_one_tpa_info_data(struct bnxt *bp,
|
|||
{
|
||||
int i;
|
||||
|
||||
for (i = 0; i < bp->max_tpa; i++) {
|
||||
for (i = 0; i < bp->max_tpa_roundup_size; i++) {
|
||||
struct bnxt_tpa_info *tpa_info = &rxr->rx_tpa[i];
|
||||
u8 *data = tpa_info->data;
|
||||
|
||||
|
|
@ -3801,7 +3803,7 @@ static void bnxt_free_one_tpa_info(struct bnxt *bp,
|
|||
kfree(rxr->rx_tpa_idx_map);
|
||||
rxr->rx_tpa_idx_map = NULL;
|
||||
if (rxr->rx_tpa) {
|
||||
for (i = 0; i < bp->max_tpa; i++) {
|
||||
for (i = 0; i < bp->max_tpa_roundup_size; i++) {
|
||||
kfree(rxr->rx_tpa[i].agg_arr);
|
||||
rxr->rx_tpa[i].agg_arr = NULL;
|
||||
}
|
||||
|
|
@ -3827,13 +3829,14 @@ static int bnxt_alloc_one_tpa_info(struct bnxt *bp,
|
|||
struct rx_agg_cmp *agg;
|
||||
int i;
|
||||
|
||||
rxr->rx_tpa = kzalloc_objs(struct bnxt_tpa_info, bp->max_tpa);
|
||||
rxr->rx_tpa = kzalloc_objs(struct bnxt_tpa_info,
|
||||
bp->max_tpa_roundup_size);
|
||||
if (!rxr->rx_tpa)
|
||||
return -ENOMEM;
|
||||
|
||||
if (!(bp->flags & BNXT_FLAG_CHIP_P5_PLUS))
|
||||
return 0;
|
||||
for (i = 0; i < bp->max_tpa; i++) {
|
||||
for (i = 0; i < bp->max_tpa_roundup_size; i++) {
|
||||
agg = kzalloc_objs(*agg, MAX_SKB_FRAGS);
|
||||
if (!agg)
|
||||
return -ENOMEM;
|
||||
|
|
@ -3852,6 +3855,9 @@ static int bnxt_alloc_tpa_info(struct bnxt *bp)
|
|||
|
||||
bp->max_tpa = MAX_TPA;
|
||||
if (bp->flags & BNXT_FLAG_CHIP_P5_PLUS) {
|
||||
/* TPA is not supported at all, so there is nothing to
|
||||
* allocate.
|
||||
*/
|
||||
if (!bp->max_tpa_v2)
|
||||
return 0;
|
||||
bp->max_tpa = min_t(u16, bp->max_tpa_v2, MAX_TPA_P5);
|
||||
|
|
@ -3859,6 +3865,7 @@ static int bnxt_alloc_tpa_info(struct bnxt *bp)
|
|||
if (bp->max_tpa <= 32 && BNXT_CHIP_P5(bp) && !BNXT_NPAR(bp))
|
||||
bp->max_tpa = MAX_TPA_P5;
|
||||
}
|
||||
bp->max_tpa_roundup_size = roundup_pow_of_two(bp->max_tpa);
|
||||
|
||||
for (i = 0; i < bp->rx_nr_rings; i++) {
|
||||
struct bnxt_rx_ring_info *rxr = &bp->rx_ring[i];
|
||||
|
|
@ -4571,7 +4578,7 @@ static int bnxt_alloc_one_tpa_info_data(struct bnxt *bp,
|
|||
u8 *data;
|
||||
int i;
|
||||
|
||||
for (i = 0; i < bp->max_tpa; i++) {
|
||||
for (i = 0; i < bp->max_tpa_roundup_size; i++) {
|
||||
data = __bnxt_alloc_rx_frag(bp, &mapping, rxr,
|
||||
GFP_KERNEL);
|
||||
if (!data)
|
||||
|
|
|
|||
|
|
@ -789,7 +789,6 @@ struct nqe_cn {
|
|||
|
||||
#define MAX_TPA 64
|
||||
#define MAX_TPA_P5 256
|
||||
#define MAX_TPA_P5_MASK (MAX_TPA_P5 - 1)
|
||||
#define MAX_TPA_SEGS_P5 0x3f
|
||||
|
||||
#if (BNXT_PAGE_SHIFT == 16)
|
||||
|
|
@ -2381,6 +2380,7 @@ struct bnxt {
|
|||
|
||||
u16 max_tpa_v2;
|
||||
u16 max_tpa;
|
||||
u16 max_tpa_roundup_size;
|
||||
u32 rx_buf_size;
|
||||
u32 rx_buf_use_size; /* useable size */
|
||||
u16 rx_offset;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user