* [PATCH net] net: bgmac: clear TX slots when freeing the ring
@ 2026-10-10 7:04 Rosen Penev
2026-10-10 7:09 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Rosen Penev @ 2026-10-10 7:04 UTC (permalink / raw)
To: netdev
Cc: Rafał Miłecki, Broadcom internal kernel review list,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Felix Fietkau, open list
bgmac_dma_tx_ring_free() frees the skbs of pending TX slots but leaves
slot->skb and slot->dma_addr set. The slots survive a down/up cycle,
and bgmac_dma_tx_add() only sets slot->skb on the last slot of a
packet. If a slot with a stale pointer is later used for the head or a
fragment of a scatter/gather packet, bgmac_dma_tx_free() frees the old
skb a second time when that slot completes.
The function also picks dma_unmap_single() or dma_unmap_page() by
looking at slot->skb, which is set on the last slot of a packet, while
the head was mapped with dma_map_single() and the fragments with
skb_frag_dma_map(). Use the SOF flag of the descriptor instead, like
bgmac_dma_tx_free() does.
Unmap before freeing, and clear both fields.
Fixes: 9cde94506eac ("bgmac: implement scatter/gather support")
Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
drivers/net/ethernet/broadcom/bgmac.c | 20 +++++++++++---------
1 file changed, 11 insertions(+), 9 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/bgmac.c b/drivers/net/ethernet/broadcom/bgmac.c
index ebc4b3bf6c4a..f40fde1d6bce 100644
--- a/drivers/net/ethernet/broadcom/bgmac.c
+++ b/drivers/net/ethernet/broadcom/bgmac.c
@@ -534,17 +534,19 @@ static void bgmac_dma_tx_ring_free(struct bgmac *bgmac,
unsigned int len = ctl1 & BGMAC_DESC_CTL1_LEN;
slot = &ring->slots[i];
- dev_kfree_skb(slot->skb);
- if (!slot->dma_addr)
- continue;
+ if (slot->dma_addr) {
+ if (le32_to_cpu(dma_desc[i].ctl0) & BGMAC_DESC_CTL0_SOF)
+ dma_unmap_single(dma_dev, slot->dma_addr,
+ len, DMA_TO_DEVICE);
+ else
+ dma_unmap_page(dma_dev, slot->dma_addr,
+ len, DMA_TO_DEVICE);
+ slot->dma_addr = 0;
+ }
- if (slot->skb)
- dma_unmap_single(dma_dev, slot->dma_addr,
- len, DMA_TO_DEVICE);
- else
- dma_unmap_page(dma_dev, slot->dma_addr,
- len, DMA_TO_DEVICE);
+ dev_kfree_skb(slot->skb);
+ slot->skb = NULL;
}
}
--
2.56.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH net] net: bgmac: clear TX slots when freeing the ring
2026-10-10 7:04 [PATCH net] net: bgmac: clear TX slots when freeing the ring Rosen Penev
@ 2026-10-10 7:09 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-10-10 7:09 UTC (permalink / raw)
To: Rosen Penev
Cc: netdev, Rafał Miłecki,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Felix Fietkau, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-10 7:09 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 7:04 [PATCH net] net: bgmac: clear TX slots when freeing the ring Rosen Penev
2026-10-10 7:09 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®