* [PATCH net v2 0/6] net: bcmasp: Collection of fixes
@ 2026-10-08 21:06 Florian Fainelli
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
` (5 more replies)
0 siblings, 6 replies; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
This patch series is a collection of bug fixes accumulated during a LLM
coding session. Thanks to Justin for the internal review and helping
with the last patch.
Changes in v2:
- address Sashiko's feedback and correct the commit messages and code
accordingly
- add Nicolai's R-b tag where collected
Florian Fainelli (6):
net: bcmasp: fix mib counters struct alignment with ethtool stats
net: bcmasp: unmap previous DMA mappings on TX map failure
net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll()
net: bcmasp: fix OF node reference leak for phy_dn
net: bcmasp: account for offload header in TX short packet padding
net: bcmasp: fix network filter lookup and wake filter pair allocation
drivers/net/ethernet/broadcom/asp2/bcmasp.c | 121 ++++++++++--------
drivers/net/ethernet/broadcom/asp2/bcmasp.h | 4 -
.../net/ethernet/broadcom/asp2/bcmasp_intf.c | 32 ++++-
3 files changed, 95 insertions(+), 62 deletions(-)
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
@ 2026-10-08 21:06 ` Florian Fainelli
2026-10-09 8:42 ` Nicolai Buchwitz
2026-10-09 18:35 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure Florian Fainelli
` (4 subsequent siblings)
5 siblings, 2 replies; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
When EDPKT stats were removed in commit e9f31435ee7d ("net: bcmasp: Add
support for asp-v3.0"), the corresponding entries were removed from
bcmasp_gstrings_stats in bcmasp_ethtool.c, but the edpkt_* fields were
left at the beginning of struct bcmasp_mib_counters in bcmasp.h.
Because bcmasp_update_mib_counters() and bcmasp_get_ethtool_stats() index
into struct bcmasp_mib_counters sequentially based on the order of
bcmasp_gstrings_stats, this 16-byte offset caused ethtool to read from
shifted offsets: the first four software counters read unused fields and
reported 0, the next four software counters reported the values of
alloc_rx_skb_failed, tx_dma_failed, mc_filters_full_cnt, and
uc_filters_full_cnt, while filters_combine_cnt, promisc_filters_cnt,
tx_realloc_offload_failed, and tx_timeout_cnt were never reported.
Remove the obsolete edpkt_* fields from struct bcmasp_mib_counters so
that it aligns with bcmasp_gstrings_stats.
Fixes: e9f31435ee7d ("net: bcmasp: Add support for asp-v3.0")
Assisted-by: LLM
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
---
drivers/net/ethernet/broadcom/asp2/bcmasp.h | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp.h b/drivers/net/ethernet/broadcom/asp2/bcmasp.h
index 8c8ffaeadc79..9c9721da1662 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp.h
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp.h
@@ -250,10 +250,6 @@ struct bcmasp_intf_stats64 {
};
struct bcmasp_mib_counters {
- u32 edpkt_ts;
- u32 edpkt_rx_pkt_cnt;
- u32 edpkt_hdr_ext_cnt;
- u32 edpkt_hdr_out_cnt;
u32 umac_frm_cnt;
u32 fb_frm_cnt;
u32 fb_rx_fifo_depth;
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
@ 2026-10-08 21:06 ` Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll() Florian Fainelli
` (3 subsequent siblings)
5 siblings, 1 reply; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Nicolai Buchwitz, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list
When mapping an skb with fragments for transmission in bcmasp_xmit(),
if mapping fails on fragment i > 0, the error handler calls
bcmasp_clean_txcb() for previous iterations j < i. However,
bcmasp_clean_txcb() only zeroes the control block fields without
unmapping the DMA buffers, leaking the DMA mappings allocated for the
head and earlier fragments.
Call dma_unmap_single() before calling bcmasp_clean_txcb() in the error
cleanup loop.
Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
Assisted-by: LLM
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
---
drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
index f2176ef3a127..9ad5a982542f 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
@@ -285,6 +285,11 @@ static netdev_tx_t bcmasp_xmit(struct sk_buff *skb, struct net_device *dev)
intf->mib.tx_dma_failed++;
spb_index = intf->tx_spb_index;
for (j = 0; j < i; j++) {
+ txcb = &intf->tx_cbs[spb_index];
+ dma_unmap_single(kdev,
+ dma_unmap_addr(txcb, dma_addr),
+ dma_unmap_len(txcb, dma_len),
+ DMA_TO_DEVICE);
bcmasp_clean_txcb(intf, spb_index);
spb_index = incr_ring(spb_index,
DESC_RING_COUNT);
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll()
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
2026-10-08 21:06 ` [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure Florian Fainelli
@ 2026-10-08 21:06 ` Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn Florian Fainelli
` (2 subsequent siblings)
5 siblings, 1 reply; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
In bcmasp_rx_poll(), the driver removes a 2-byte alignment pad and
optionally strips the ETH_FCS_LEN CRC from received packets before
passing them to eth_type_trans().
If the hardware reports a descriptor size smaller than the sum of the
2-byte pad, the Ethernet header (ETH_HLEN), and optional CRC
(ETH_FCS_LEN), subtracting the pad and CRC lengths underflows u32 len.
This adds ~4 GiB to rx_bytes statistics, while the undersized frame
reaches eth_type_trans(), which reads past skb->len into stale buffer
data.
Check that desc->size is at least (2 + ETH_HLEN + (crc_fwd ? ETH_FCS_LEN
: 0)) before proceeding to process the descriptor.
Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
Assisted-by: LLM
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
---
drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
index 9ad5a982542f..d679c796c8c2 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
@@ -523,6 +523,12 @@ static int bcmasp_rx_poll(struct napi_struct *napi, int budget)
DMA_FROM_DEVICE);
len = desc->size;
+ if (unlikely(len < 2 + ETH_HLEN + (intf->crc_fwd ? ETH_FCS_LEN : 0))) {
+ u64_stats_update_begin(&stats->syncp);
+ u64_stats_inc(&stats->rx_dropped);
+ u64_stats_update_end(&stats->syncp);
+ goto next;
+ }
/* Allocate a page pool page as the SKB data area so the
* kernel can recycle it efficiently after the packet is
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
` (2 preceding siblings ...)
2026-10-08 21:06 ` [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll() Florian Fainelli
@ 2026-10-08 21:06 ` Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation Florian Fainelli
[not found] ` <20261008210621.1374785-6-florian.fainelli@broadcom.com>
5 siblings, 1 reply; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Nicolai Buchwitz, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list
In bcmasp_interface_create(), intf->phy_dn is obtained via
of_parse_phandle() or assigned ndev_dn. of_parse_phandle() returns a
node reference with its refcount incremented, but of_node_put() was
never called on intf->phy_dn in bcmasp_interface_destroy() or the
error unwind path in bcmasp_interface_create().
Acquire a reference on ndev_dn for the fixed-link case as well so that
intf->phy_dn consistently holds a reference, and release it with
of_node_put() on teardown and error.
Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
Assisted-by: LLM
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
---
drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
index d679c796c8c2..693e8cdfe960 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c
@@ -1298,7 +1298,7 @@ struct bcmasp_intf *bcmasp_interface_create(struct bcmasp_priv *priv,
ndev_dn->name);
goto err_free_netdev;
}
- intf->phy_dn = ndev_dn;
+ intf->phy_dn = of_node_get(ndev_dn);
}
/* Map resource */
@@ -1338,6 +1338,7 @@ struct bcmasp_intf *bcmasp_interface_create(struct bcmasp_priv *priv,
err_deregister_fixed_link:
if (of_phy_is_fixed_link(ndev_dn))
of_phy_deregister_fixed_link(ndev_dn);
+ of_node_put(intf->phy_dn);
err_free_netdev:
free_netdev(ndev);
err:
@@ -1350,6 +1351,7 @@ void bcmasp_interface_destroy(struct bcmasp_intf *intf)
unregister_netdev(intf->ndev);
if (of_phy_is_fixed_link(intf->ndev_dn))
of_phy_deregister_fixed_link(intf->ndev_dn);
+ of_node_put(intf->phy_dn);
free_netdev(intf->ndev);
}
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
` (3 preceding siblings ...)
2026-10-08 21:06 ` [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn Florian Fainelli
@ 2026-10-08 21:06 ` Florian Fainelli
2026-10-09 8:55 ` Nicolai Buchwitz
2026-10-09 18:37 ` Justin Chen
[not found] ` <20261008210621.1374785-6-florian.fainelli@broadcom.com>
5 siblings, 2 replies; 14+ messages in thread
From: Florian Fainelli @ 2026-10-08 21:06 UTC (permalink / raw)
To: netdev
Cc: Florian Fainelli, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
In bcmasp_netfilt_get_init(), when looking up an existing filter (!init)
for a specified location, if the filter at loc was not claimed, the
previous loop continued searching higher indices and could return an
arbitrary unrelated filter belonging to the port. This caused flow get or
delete operations on an empty rule location to return or delete an
unintended filter.
Fix this by checking only the requested location on lookup and rejecting
RX_CLS_LOC_ANY when !init. In addition, harden wake filter allocation
and release by ensuring wake filter pair searches stay on even boundaries
where both entries are free, checking that loc + 1 is free for positioned
wake filters, and validating parity and bounds on release.
Fixes: c5d511c49587 ("net: bcmasp: Add support for wake on net filters")
Assisted-by: LLM
Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
---
drivers/net/ethernet/broadcom/asp2/bcmasp.c | 121 +++++++++++---------
1 file changed, 70 insertions(+), 51 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp.c b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
index 972474893a6b..b6a201982080 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp.c
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
@@ -511,6 +511,13 @@ static int bcmasp_netfilt_wr_to_hw(struct bcmasp_priv *priv,
return 0;
}
+static inline bool bcmasp_netfilt_is_companion(struct bcmasp_priv *priv, int i)
+{
+ return i > 0 && (i % 2) &&
+ priv->net_filters[i].wake_filter &&
+ priv->net_filters[i - 1].wake_filter;
+}
+
void bcmasp_netfilt_suspend(struct bcmasp_intf *intf)
{
struct bcmasp_priv *priv = intf->parent;
@@ -524,9 +531,7 @@ void bcmasp_netfilt_suspend(struct bcmasp_intf *intf)
priv->net_filters[i].port != intf->port)
continue;
- if (i > 0 && (i % 2) &&
- priv->net_filters[i].wake_filter &&
- priv->net_filters[i - 1].wake_filter)
+ if (bcmasp_netfilt_is_companion(priv, i))
continue;
ret = bcmasp_netfilt_wr_to_hw(priv, &priv->net_filters[i]);
@@ -556,9 +561,7 @@ int bcmasp_netfilt_get_all_active(struct bcmasp_intf *intf, u32 *rule_locs,
priv->net_filters[i].port != intf->port)
continue;
- if (i > 0 && (i % 2) &&
- priv->net_filters[i].wake_filter &&
- priv->net_filters[i - 1].wake_filter)
+ if (bcmasp_netfilt_is_companion(priv, i))
continue;
if (j == *rule_cnt)
@@ -583,9 +586,7 @@ int bcmasp_netfilt_get_active(struct bcmasp_intf *intf)
continue;
/* Skip over a wake filter pair */
- if (i > 0 && (i % 2) &&
- priv->net_filters[i].wake_filter &&
- priv->net_filters[i - 1].wake_filter)
+ if (bcmasp_netfilt_is_companion(priv, i))
continue;
cnt++;
@@ -607,6 +608,9 @@ bool bcmasp_netfilt_check_dup(struct bcmasp_intf *intf,
priv->net_filters[i].port != intf->port)
continue;
+ if (bcmasp_netfilt_is_companion(priv, i))
+ continue;
+
cur = &priv->net_filters[i].fs;
if (cur->flow_type != fs->flow_type ||
@@ -659,7 +663,7 @@ bool bcmasp_netfilt_check_dup(struct bcmasp_intf *intf,
}
/* If no network filter found, return open filter.
- * If no more open filters return NULL
+ * If no more open filters return error.
*/
struct bcmasp_net_filter *bcmasp_netfilt_get_init(struct bcmasp_intf *intf,
u32 loc, bool wake_filter,
@@ -669,45 +673,55 @@ struct bcmasp_net_filter *bcmasp_netfilt_get_init(struct bcmasp_intf *intf,
struct bcmasp_priv *priv = intf->parent;
int i, open_index = -1;
- /* Check whether we exceed the filter table capacity */
+ if (!init) {
+ if (loc == RX_CLS_LOC_ANY || loc >= priv->num_net_filters)
+ return ERR_PTR(-EINVAL);
+
+ if (priv->net_filters[loc].claimed &&
+ priv->net_filters[loc].port == intf->port &&
+ !bcmasp_netfilt_is_companion(priv, loc))
+ return &priv->net_filters[loc];
+
+ return ERR_PTR(-ENOENT);
+ }
+
if (loc != RX_CLS_LOC_ANY && loc >= priv->num_net_filters)
return ERR_PTR(-EINVAL);
/* If the filter location is busy (already claimed) and we are initializing
* the filter (insertion), return a busy error code.
*/
- if (loc != RX_CLS_LOC_ANY && init && priv->net_filters[loc].claimed)
- return ERR_PTR(-EBUSY);
-
- /* We need two filters for wake-up, so we cannot use an odd filter */
- if (wake_filter && loc != RX_CLS_LOC_ANY && (loc % 2))
- return ERR_PTR(-EINVAL);
-
- /* Initialize the loop index based on the desired location or from 0 */
- i = loc == RX_CLS_LOC_ANY ? 0 : loc;
-
- for ( ; i < priv->num_net_filters; i++) {
- /* Found matching network filter */
- if (!init &&
- priv->net_filters[i].claimed &&
- priv->net_filters[i].hw_index == i &&
- priv->net_filters[i].port == intf->port)
- return &priv->net_filters[i];
-
- /* If we don't need a new filter or new filter already found */
- if (!init || open_index >= 0)
- continue;
-
- /* Wake filter conslidates two filters to cover more bytes
- * Wake filter is open if...
- * 1. It is an even filter
- * 2. The current and next filter is not claimed
- */
- if (wake_filter && !(i % 2) && !priv->net_filters[i].claimed &&
- !priv->net_filters[i + 1].claimed)
- open_index = i;
- else if (!priv->net_filters[i].claimed)
- open_index = i;
+ if (loc != RX_CLS_LOC_ANY) {
+ if (priv->net_filters[loc].claimed)
+ return ERR_PTR(-EBUSY);
+
+ /* We need two filters for wake-up, so we cannot use an odd filter */
+ if (wake_filter) {
+ if ((loc % 2) || loc + 1 >= priv->num_net_filters)
+ return ERR_PTR(-EINVAL);
+ if (priv->net_filters[loc + 1].claimed)
+ return ERR_PTR(-EBUSY);
+ }
+ open_index = loc;
+ } else {
+ for (i = 0; i < priv->num_net_filters; i++) {
+ /* Wake filter consolidates two filters to cover more bytes.
+ * Wake filter is open if:
+ * 1. It is an even filter
+ * 2. The current and next filter is not claimed
+ */
+ if (wake_filter) {
+ if (!(i % 2) && (i + 1 < priv->num_net_filters) &&
+ !priv->net_filters[i].claimed &&
+ !priv->net_filters[i + 1].claimed) {
+ open_index = i;
+ break;
+ }
+ } else if (!priv->net_filters[i].claimed) {
+ open_index = i;
+ break;
+ }
+ }
}
if (open_index >= 0) {
@@ -716,16 +730,20 @@ struct bcmasp_net_filter *bcmasp_netfilt_get_init(struct bcmasp_intf *intf,
nfilter->port = intf->port;
nfilter->ch = intf->channel + priv->tx_chan_offset;
nfilter->hw_index = open_index;
- }
- if (wake_filter && open_index >= 0) {
- /* Claim next filter */
- priv->net_filters[open_index + 1].claimed = true;
- priv->net_filters[open_index + 1].wake_filter = true;
- nfilter->wake_filter = true;
+ if (wake_filter) {
+ /* Claim next filter */
+ priv->net_filters[open_index + 1].claimed = true;
+ priv->net_filters[open_index + 1].wake_filter = true;
+ priv->net_filters[open_index + 1].hw_index = open_index + 1;
+ priv->net_filters[open_index + 1].port = intf->port;
+ priv->net_filters[open_index + 1].ch = intf->channel +
+ priv->tx_chan_offset;
+ nfilter->wake_filter = true;
+ }
}
- return nfilter ? nfilter : ERR_PTR(-EINVAL);
+ return nfilter ? nfilter : ERR_PTR(-ENOSPC);
}
void bcmasp_netfilt_release(struct bcmasp_intf *intf,
@@ -733,7 +751,8 @@ void bcmasp_netfilt_release(struct bcmasp_intf *intf,
{
struct bcmasp_priv *priv = intf->parent;
- if (nfilt->wake_filter) {
+ if (nfilt->wake_filter && !(nfilt->hw_index % 2) &&
+ nfilt->hw_index + 1 < priv->num_net_filters) {
memset(&priv->net_filters[nfilt->hw_index + 1], 0,
sizeof(struct bcmasp_net_filter));
}
--
2.34.1
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
@ 2026-10-09 8:42 ` Nicolai Buchwitz
2026-10-09 18:35 ` Justin Chen
1 sibling, 0 replies; 14+ messages in thread
From: Nicolai Buchwitz @ 2026-10-09 8:42 UTC (permalink / raw)
To: Florian Fainelli
Cc: netdev, Doug Berger, Broadcom internal kernel review list,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Zak Kemble, Simon Horman, Ryo Takakura,
linux-kernel
On 8.10.2026 23:06, Florian Fainelli wrote:
> When EDPKT stats were removed in commit e9f31435ee7d ("net: bcmasp: Add
> support for asp-v3.0"), the corresponding entries were removed from
> bcmasp_gstrings_stats in bcmasp_ethtool.c, but the edpkt_* fields were
> left at the beginning of struct bcmasp_mib_counters in bcmasp.h.
>
> Because bcmasp_update_mib_counters() and bcmasp_get_ethtool_stats()
> index
> into struct bcmasp_mib_counters sequentially based on the order of
> bcmasp_gstrings_stats, this 16-byte offset caused ethtool to read from
> shifted offsets: the first four software counters read unused fields
> and
> reported 0, the next four software counters reported the values of
> alloc_rx_skb_failed, tx_dma_failed, mc_filters_full_cnt, and
> uc_filters_full_cnt, while filters_combine_cnt, promisc_filters_cnt,
> tx_realloc_offload_failed, and tx_timeout_cnt were never reported.
>
> Remove the obsolete edpkt_* fields from struct bcmasp_mib_counters so
> that it aligns with bcmasp_gstrings_stats.
>
> Fixes: e9f31435ee7d ("net: bcmasp: Add support for asp-v3.0")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
> ---
> drivers/net/ethernet/broadcom/asp2/bcmasp.h | 4 ----
> 1 file changed, 4 deletions(-)
>
> diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp.h
> b/drivers/net/ethernet/broadcom/asp2/bcmasp.h
> index 8c8ffaeadc79..9c9721da1662 100644
> --- a/drivers/net/ethernet/broadcom/asp2/bcmasp.h
> +++ b/drivers/net/ethernet/broadcom/asp2/bcmasp.h
> @@ -250,10 +250,6 @@ struct bcmasp_intf_stats64 {
> };
>
> struct bcmasp_mib_counters {
> - u32 edpkt_ts;
> - u32 edpkt_rx_pkt_cnt;
> - u32 edpkt_hdr_ext_cnt;
> - u32 edpkt_hdr_out_cnt;
> u32 umac_frm_cnt;
> u32 fb_frm_cnt;
> u32 fb_rx_fifo_depth;
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Thanks,
Nicolai
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation
2026-10-08 21:06 ` [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation Florian Fainelli
@ 2026-10-09 8:55 ` Nicolai Buchwitz
2026-10-09 18:37 ` Justin Chen
1 sibling, 0 replies; 14+ messages in thread
From: Nicolai Buchwitz @ 2026-10-09 8:55 UTC (permalink / raw)
To: Florian Fainelli
Cc: netdev, Doug Berger, Broadcom internal kernel review list,
Andrew Lunn, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Zak Kemble, Simon Horman, Ryo Takakura,
linux-kernel
Hi Florian
On 8.10.2026 23:06, Florian Fainelli wrote:
> In bcmasp_netfilt_get_init(), when looking up an existing filter
> (!init)
> for a specified location, if the filter at loc was not claimed, the
> previous loop continued searching higher indices and could return an
> arbitrary unrelated filter belonging to the port. This caused flow get
> or
> delete operations on an empty rule location to return or delete an
> unintended filter.
>
> Fix this by checking only the requested location on lookup and
> rejecting
> RX_CLS_LOC_ANY when !init. In addition, harden wake filter allocation
> and release by ensuring wake filter pair searches stay on even
> boundaries
> where both entries are free, checking that loc + 1 is free for
> positioned
> wake filters, and validating parity and bounds on release.
>
> Fixes: c5d511c49587 ("net: bcmasp: Add support for wake on net
> filters")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
> ---
> drivers/net/ethernet/broadcom/asp2/bcmasp.c | 121 +++++++++++---------
> 1 file changed, 70 insertions(+), 51 deletions(-)
>
> diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp.c
> b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
> index 972474893a6b..b6a201982080 100644
> --- a/drivers/net/ethernet/broadcom/asp2/bcmasp.c
> +++ b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
> @@ -511,6 +511,13 @@ static int bcmasp_netfilt_wr_to_hw(struct
> bcmasp_priv *priv,
> return 0;
> }
>
> +static inline bool bcmasp_netfilt_is_companion(struct bcmasp_priv
> *priv, int i)
nit: Does it need to be inline? Usually the compiler takes care of this
automatically.
> +{
> + return i > 0 && (i % 2) &&
> + priv->net_filters[i].wake_filter &&
> + priv->net_filters[i - 1].wake_filter;
> +}
> [...]
Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
Thanks,
Nicolai
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
2026-10-09 8:42 ` Nicolai Buchwitz
@ 2026-10-09 18:35 ` Justin Chen
1 sibling, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:35 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Doug Berger, Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> When EDPKT stats were removed in commit e9f31435ee7d ("net: bcmasp: Add
> support for asp-v3.0"), the corresponding entries were removed from
> bcmasp_gstrings_stats in bcmasp_ethtool.c, but the edpkt_* fields were
> left at the beginning of struct bcmasp_mib_counters in bcmasp.h.
>
> Because bcmasp_update_mib_counters() and bcmasp_get_ethtool_stats() index
> into struct bcmasp_mib_counters sequentially based on the order of
> bcmasp_gstrings_stats, this 16-byte offset caused ethtool to read from
> shifted offsets: the first four software counters read unused fields and
> reported 0, the next four software counters reported the values of
> alloc_rx_skb_failed, tx_dma_failed, mc_filters_full_cnt, and
> uc_filters_full_cnt, while filters_combine_cnt, promisc_filters_cnt,
> tx_realloc_offload_failed, and tx_timeout_cnt were never reported.
>
> Remove the obsolete edpkt_* fields from struct bcmasp_mib_counters so
> that it aligns with bcmasp_gstrings_stats.
>
> Fixes: e9f31435ee7d ("net: bcmasp: Add support for asp-v3.0")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure
2026-10-08 21:06 ` [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure Florian Fainelli
@ 2026-10-09 18:36 ` Justin Chen
0 siblings, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:36 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Nicolai Buchwitz, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> When mapping an skb with fragments for transmission in bcmasp_xmit(),
> if mapping fails on fragment i > 0, the error handler calls
> bcmasp_clean_txcb() for previous iterations j < i. However,
> bcmasp_clean_txcb() only zeroes the control block fields without
> unmapping the DMA buffers, leaking the DMA mappings allocated for the
> head and earlier fragments.
>
> Call dma_unmap_single() before calling bcmasp_clean_txcb() in the error
> cleanup loop.
>
> Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
> Assisted-by: LLM
> Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll()
2026-10-08 21:06 ` [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll() Florian Fainelli
@ 2026-10-09 18:36 ` Justin Chen
0 siblings, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:36 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Doug Berger, Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> In bcmasp_rx_poll(), the driver removes a 2-byte alignment pad and
> optionally strips the ETH_FCS_LEN CRC from received packets before
> passing them to eth_type_trans().
>
> If the hardware reports a descriptor size smaller than the sum of the
> 2-byte pad, the Ethernet header (ETH_HLEN), and optional CRC
> (ETH_FCS_LEN), subtracting the pad and CRC lengths underflows u32 len.
> This adds ~4 GiB to rx_bytes statistics, while the undersized frame
> reaches eth_type_trans(), which reads past skb->len into stale buffer
> data.
>
> Check that desc->size is at least (2 + ETH_HLEN + (crc_fwd ? ETH_FCS_LEN
> : 0)) before proceeding to process the descriptor.
>
> Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn
2026-10-08 21:06 ` [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn Florian Fainelli
@ 2026-10-09 18:36 ` Justin Chen
0 siblings, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:36 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Nicolai Buchwitz, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> In bcmasp_interface_create(), intf->phy_dn is obtained via
> of_parse_phandle() or assigned ndev_dn. of_parse_phandle() returns a
> node reference with its refcount incremented, but of_node_put() was
> never called on intf->phy_dn in bcmasp_interface_destroy() or the
> error unwind path in bcmasp_interface_create().
>
> Acquire a reference on ndev_dn for the fixed-link case as well so that
> intf->phy_dn consistently holds a reference, and release it with
> of_node_put() on teardown and error.
>
> Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
> Assisted-by: LLM
> Reviewed-by: Nicolai Buchwitz <nb@tipi-net.de>
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 5/6] net: bcmasp: account for offload header in TX short packet padding
[not found] ` <20261008210621.1374785-6-florian.fainelli@broadcom.com>
@ 2026-10-09 18:36 ` Justin Chen
0 siblings, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:36 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Doug Berger, Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> When hardware checksum offload is enabled for an skb,
> bcmasp_csum_offload() prepends a struct bcmasp_pkt_offload header
> (20 bytes) to the skb via skb_push(). This increases skb->len and
> skb_headlen(skb) by sizeof(struct bcmasp_pkt_offload).
>
> Because the hardware descriptor processor strips this offload header
> before transmitting the packet on the wire, the wire packet length is
> smaller by sizeof(struct bcmasp_pkt_offload). The padding calculation
> must account for this extra header; otherwise, short frames are sent on
> the wire smaller than the minimum Ethernet frame size (ETH_ZLEN +
> ETH_FCS_LEN).
>
> Furthermore, small frames with payload in page fragments (such as small
> TCP segments with CHECKSUM_PARTIAL) have nr_frags > 0 and were skipping
> padding entirely because the padding check was restricted to
> nr_frags == 0.
>
> Perform the padding check on skb->len before the descriptor loop using
> skb_put_padto(), adding sizeof(struct bcmasp_pkt_offload) to min_size
> when checksum offload is enabled, and re-read nr_frags after padding in
> case the skb was linearized.
>
> Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
* Re: [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation
2026-10-08 21:06 ` [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation Florian Fainelli
2026-10-09 8:55 ` Nicolai Buchwitz
@ 2026-10-09 18:37 ` Justin Chen
1 sibling, 0 replies; 14+ messages in thread
From: Justin Chen @ 2026-10-09 18:37 UTC (permalink / raw)
To: Florian Fainelli, netdev
Cc: Doug Berger, Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Zak Kemble, Simon Horman, Ryo Takakura, open list,
Nicolai Buchwitz
On 10/8/26 2:06 PM, Florian Fainelli wrote:
> In bcmasp_netfilt_get_init(), when looking up an existing filter (!init)
> for a specified location, if the filter at loc was not claimed, the
> previous loop continued searching higher indices and could return an
> arbitrary unrelated filter belonging to the port. This caused flow get or
> delete operations on an empty rule location to return or delete an
> unintended filter.
>
> Fix this by checking only the requested location on lookup and rejecting
> RX_CLS_LOC_ANY when !init. In addition, harden wake filter allocation
> and release by ensuring wake filter pair searches stay on even boundaries
> where both entries are free, checking that loc + 1 is free for positioned
> wake filters, and validating parity and bounds on release.
>
> Fixes: c5d511c49587 ("net: bcmasp: Add support for wake on net filters")
> Assisted-by: LLM
> Signed-off-by: Florian Fainelli <florian.fainelli@broadcom.com>
Reviewed-by: Justin Chen <justin.chen@broadcom.com>
^ permalink raw reply [flat|nested] 14+ messages in thread
end of thread, other threads:[~2026-10-09 18:37 UTC | newest]
Thread overview: 14+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 21:06 [PATCH net v2 0/6] net: bcmasp: Collection of fixes Florian Fainelli
2026-10-08 21:06 ` [PATCH net v2 1/6] net: bcmasp: fix mib counters struct alignment with ethtool stats Florian Fainelli
2026-10-09 8:42 ` Nicolai Buchwitz
2026-10-09 18:35 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 2/6] net: bcmasp: unmap previous DMA mappings on TX map failure Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll() Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 4/6] net: bcmasp: fix OF node reference leak for phy_dn Florian Fainelli
2026-10-09 18:36 ` Justin Chen
2026-10-08 21:06 ` [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation Florian Fainelli
2026-10-09 8:55 ` Nicolai Buchwitz
2026-10-09 18:37 ` Justin Chen
[not found] ` <20261008210621.1374785-6-florian.fainelli@broadcom.com>
2026-10-09 18:36 ` [PATCH net v2 5/6] net: bcmasp: account for offload header in TX short packet padding Justin Chen
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®