* [PATCH v1] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
@ 2025-04-05 10:00 Henry Martin
2025-04-07 8:34 ` [PATCH] " Markus Elfring
2025-04-08 9:53 ` [PATCH v1] " Paolo Abeni
0 siblings, 2 replies; 7+ messages in thread
From: Henry Martin @ 2025-04-05 10:00 UTC (permalink / raw)
To: saeedm, leon, tariqt
Cc: andrew+netdev, davem, edumazet, kuba, pabeni, amirtz, ayal,
bsdhenrymartin, netdev, linux-rdma, linux-kernel
Add NULL check for mlx5_get_flow_namespace() returns in
mlx5_create_inner_ttc_table() to prevent NULL pointer dereference.
Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
---
drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
index eb3bd9c7f66e..4e964ca5367e 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
@@ -655,6 +655,8 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
}
ns = mlx5_get_flow_namespace(dev, params->ns_type);
+ if (!ns)
+ return ERR_PTR(-EOPNOTSUPP);
groups = use_l4_type ? &inner_ttc_groups[TTC_GROUPS_USE_L4_TYPE] :
&inner_ttc_groups[TTC_GROUPS_DEFAULT];
--
2.34.1
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-05 10:00 [PATCH v1] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table() Henry Martin
@ 2025-04-07 8:34 ` Markus Elfring
2025-04-08 9:53 ` [PATCH v1] " Paolo Abeni
1 sibling, 0 replies; 7+ messages in thread
From: Markus Elfring @ 2025-04-07 8:34 UTC (permalink / raw)
To: Henry Martin, linux-rdma, netdev
Cc: LKML, Amir Tzin, Andrew Lunn, Aya Levin, David S. Miller,
Eric Dumazet, Jakub Kicinski, Leon Romanovsky, Paolo Abeni,
Saeed Mahameed, Simon Horman, Tariq Toukan
> Add NULL check for mlx5_get_flow_namespace() returns in
> mlx5_create_inner_ttc_table() to prevent NULL pointer dereference.
* You would like to adjust the error handling in some function implementations
from a common subdirectory.
How do you think about to offer such changes in a corresponding patch series?
* Can any other summary phrase variant become more desirable accordingly?
* Would any blank lines become also desirable after added statements?
Regards,
Markus
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v1] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-05 10:00 [PATCH v1] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table() Henry Martin
2025-04-07 8:34 ` [PATCH] " Markus Elfring
@ 2025-04-08 9:53 ` Paolo Abeni
2025-04-08 12:25 ` [PATCH] " Markus Elfring
1 sibling, 1 reply; 7+ messages in thread
From: Paolo Abeni @ 2025-04-08 9:53 UTC (permalink / raw)
To: Henry Martin, saeedm, leon, tariqt
Cc: andrew+netdev, davem, edumazet, kuba, amirtz, ayal, netdev,
linux-rdma, linux-kernel
On 4/5/25 12:00 PM, Henry Martin wrote:
> Add NULL check for mlx5_get_flow_namespace() returns in
> mlx5_create_inner_ttc_table() to prevent NULL pointer dereference.
>
> Fixes: 137f3d50ad2a ("net/mlx5: Support matching on l4_type for ttc_table")
> Signed-off-by: Henry Martin <bsdhenrymartin@gmail.com>
> ---
> drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> index eb3bd9c7f66e..4e964ca5367e 100644
> --- a/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> @@ -655,6 +655,8 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
> }
>
> ns = mlx5_get_flow_namespace(dev, params->ns_type);
> + if (!ns)
> + return ERR_PTR(-EOPNOTSUPP);
I suspect the ns_type the caller always sets a valid 'ns_type', so the
NULL ptr is not really possible here.
At very least an empty line after the return statement will make the
code more readable and the commit message should be rewritten to better
describe the issue.
Similar considerations apply to the other mlx5 fixes.
Thanks,
Paolo
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-08 9:53 ` [PATCH v1] " Paolo Abeni
@ 2025-04-08 12:25 ` Markus Elfring
2025-04-08 15:01 ` Mark Bloch
0 siblings, 1 reply; 7+ messages in thread
From: Markus Elfring @ 2025-04-08 12:25 UTC (permalink / raw)
To: Paolo Abeni, Henry Martin, linux-rdma, netdev
Cc: LKML, Amir Tzin, Andrew Lunn, Aya Levin, David S. Miller,
Eric Dumazet, Jakub Kicinski, Leon Romanovsky, Saeed Mahameed,
Simon Horman, Tariq Toukan
…
> > +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> > @@ -655,6 +655,8 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
> > }
> >
> > ns = mlx5_get_flow_namespace(dev, params->ns_type);
> > + if (!ns)
> > + return ERR_PTR(-EOPNOTSUPP);
>
> I suspect the ns_type the caller always sets a valid 'ns_type', so the
> NULL ptr is not really possible here.
Is there a need to mark such a check result as “unlikely”?
Regards,
Markus
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-08 12:25 ` [PATCH] " Markus Elfring
@ 2025-04-08 15:01 ` Mark Bloch
2025-04-08 15:20 ` henry martin
0 siblings, 1 reply; 7+ messages in thread
From: Mark Bloch @ 2025-04-08 15:01 UTC (permalink / raw)
To: Markus Elfring, Paolo Abeni, Henry Martin, linux-rdma, netdev
Cc: LKML, Amir Tzin, Andrew Lunn, Aya Levin, David S. Miller,
Eric Dumazet, Jakub Kicinski, Leon Romanovsky, Saeed Mahameed,
Simon Horman, Tariq Toukan
On 08/04/2025 15:25, Markus Elfring wrote:
> …
>>> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
>>> @@ -655,6 +655,8 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
>>> }
>>>
>>> ns = mlx5_get_flow_namespace(dev, params->ns_type);
>>> + if (!ns)
>>> + return ERR_PTR(-EOPNOTSUPP);
>>
>> I suspect the ns_type the caller always sets a valid 'ns_type', so the
>> NULL ptr is not really possible here.
>
> Is there a need to mark such a check result as “unlikely”?
>
Please don't. I'm fine with simply adding the check, as
Paolo suggested. When TTC was originally introduced, its
functionality was more limited, and reaching this point in the driver
meant we could be certain the namespace existed. Now that TTC has
become more advanced, adding this check makes sense and I'm okay with
it.
Mark
> Regards,
> Markus
>
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-08 15:01 ` Mark Bloch
@ 2025-04-08 15:20 ` henry martin
2025-04-08 16:42 ` Markus Elfring
0 siblings, 1 reply; 7+ messages in thread
From: henry martin @ 2025-04-08 15:20 UTC (permalink / raw)
To: Mark Bloch
Cc: Markus Elfring, Paolo Abeni, linux-rdma, netdev, LKML, Amir Tzin,
Andrew Lunn, Aya Levin, David S. Miller, Eric Dumazet,
Jakub Kicinski, Leon Romanovsky, Saeed Mahameed, Simon Horman,
Tariq Toukan
Thank you for the review. This check will be kept, and I'll follow Paolo's
suggestion about adding a blank line before the return statements in the v2.
Mark Bloch <mbloch@nvidia.com> 于2025年4月8日周二 23:01写道:
>
>
>
> On 08/04/2025 15:25, Markus Elfring wrote:
> > …
> >>> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lib/fs_ttc.c
> >>> @@ -655,6 +655,8 @@ struct mlx5_ttc_table *mlx5_create_inner_ttc_table(struct mlx5_core_dev *dev,
> >>> }
> >>>
> >>> ns = mlx5_get_flow_namespace(dev, params->ns_type);
> >>> + if (!ns)
> >>> + return ERR_PTR(-EOPNOTSUPP);
> >>
> >> I suspect the ns_type the caller always sets a valid 'ns_type', so the
> >> NULL ptr is not really possible here.
> >
> > Is there a need to mark such a check result as “unlikely”?
> >
>
> Please don't. I'm fine with simply adding the check, as
> Paolo suggested. When TTC was originally introduced, its
> functionality was more limited, and reaching this point in the driver
> meant we could be certain the namespace existed. Now that TTC has
> become more advanced, adding this check makes sense and I'm okay with
> it.
>
> Mark
>
> > Regards,
> > Markus
> >
>
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table()
2025-04-08 15:20 ` henry martin
@ 2025-04-08 16:42 ` Markus Elfring
0 siblings, 0 replies; 7+ messages in thread
From: Markus Elfring @ 2025-04-08 16:42 UTC (permalink / raw)
To: Henry Martin, linux-rdma, netdev
Cc: LKML, Amir Tzin, Andrew Lunn, Aya Levin, David S. Miller,
Eric Dumazet, Jakub Kicinski, Leon Romanovsky, Mark Bloch,
Paolo Abeni, Saeed Mahameed, Simon Horman, Tariq Toukan
> Thank you for the review. This check will be kept, and I'll follow Paolo's
> suggestion about adding a blank line before the return statements in the v2.
after?
Regards,
Markus
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2025-04-08 16:42 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-04-05 10:00 [PATCH v1] net/mlx5: Fix null-ptr-deref in mlx5_create_inner_ttc_table() Henry Martin
2025-04-07 8:34 ` [PATCH] " Markus Elfring
2025-04-08 9:53 ` [PATCH v1] " Paolo Abeni
2025-04-08 12:25 ` [PATCH] " Markus Elfring
2025-04-08 15:01 ` Mark Bloch
2025-04-08 15:20 ` henry martin
2025-04-08 16:42 ` Markus Elfring
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®