From: Andrew Lunn <andrew@lunn.ch>
To: "Жамбакиев Радий Рикардинович" <r.zhambakiev@prosoftsystems.ru>
Cc: "Andrew Lunn" <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
"Eric Dumazet" <edumazet@google.com>,
"Jakub Kicinski" <kuba@kernel.org>,
"Paolo Abeni" <pabeni@redhat.com>,
"Michael Grzeschik" <mgr@kernel.org>,
"Jijie Shao" <shaojijie@huawei.com>,
"Aleksandr Loktionov" <aleksandr.loktionov@intel.com>,
"Denis Benato" <benato.denis96@gmail.com>,
"Uwe Kleine-König (The Capable Hub)"
<u.kleine-koenig@baylibre.com>,
"netdev@vger.kernel.org" <netdev@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
"lvc-project@linuxtesting.org" <lvc-project@linuxtesting.org>,
"stable@vger.kernel.org" <stable@vger.kernel.org>
Subject: Re: [PATCH net v2 3/3] net: fealnx: allocate the card index from an IDA
Date: Fri, 2 Oct 2026 22:28:48 +0200 [thread overview]
Message-ID: <72ab97f0-b688-4227-a0ab-bfcdec29022f@lunn.ch> (raw)
In-Reply-To: <20261002140954.261779-4-r.zhambakiev@prosoftsystems.ru>
On Fri, Oct 02, 2026 at 02:10:10PM +0000, Жамбакиев Радий Рикардинович wrote:
> From: Radiy Zhambakiev <r.zhambakiev@prosoftsystems.ru>
>
> card_idx is a static counter that is incremented on every probe.
> It can overflow and wrap to a negative value, which then indexes
> options[] and full_duplex[] out of bounds. Large values also no
> longer fit in the 12-byte boardname[] buffer.
>
> Allocate the card index from an IDA and free it on probe failure and
> remove. The IDA reuses ids on re-add, preserving the options[] and
> full_duplex[] mapping by probe order.
>
> Store the id in the driver-private data so fealnx_remove_one() can
> free it, and size boardname to hold a full 32-bit id.
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
How have you tested this?
The advantage of the KISS approach is it is stupid, so unlikely to be
wrong. The complexity here is much higher, so it is more likely to be
wrong. That is something we have to considered.
Have you put it into a loop, and probed it 10342432341 times, on real
hardware?
Andrew
next prev parent reply other threads:[~2026-10-02 20:29 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 14:10 [PATCH net v2 0/3] net: fealnx: fix card-index overflow and PCI device teardown Жамбакиев Радий Рикардинович
2026-10-02 14:10 ` [PATCH net v2 1/3] net: fealnx: fix teardown order in remove Жамбакиев Радий Рикардинович
2026-10-02 14:18 ` Loktionov, Aleksandr
2026-10-02 14:18 ` Loktionov, Aleksandr
2026-10-06 14:31 ` netdev-bot+sashiko
2026-10-02 14:10 ` [PATCH net v2 2/3] net: fealnx: disable the PCI device on remove and probe failure Жамбакиев Радий Рикардинович
2026-10-02 14:10 ` [PATCH net v2 3/3] net: fealnx: allocate the card index from an IDA Жамбакиев Радий Рикардинович
2026-10-02 20:28 ` Andrew Lunn [this message]
2026-10-06 14:31 ` netdev-bot+sashiko
2026-10-02 14:13 ` [PATCH net v2 0/3] net: fealnx: fix card-index overflow and PCI device teardown netdev-bot+sinfo
2026-10-02 14:20 ` Жамбакиев Радий Рикардинович
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=72ab97f0-b688-4227-a0ab-bfcdec29022f@lunn.ch \
--to=andrew@lunn.ch \
--cc=aleksandr.loktionov@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=benato.denis96@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lvc-project@linuxtesting.org \
--cc=mgr@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=r.zhambakiev@prosoftsystems.ru \
--cc=shaojijie@huawei.com \
--cc=stable@vger.kernel.org \
--cc=u.kleine-koenig@baylibre.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®