lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <aXHhekHJSpTZzHXy@horms.kernel.org>
Date: Thu, 22 Jan 2026 08:36:10 +0000
From: Simon Horman <horms@...nel.org>
To: Ratheesh Kannoth <rkannoth@...vell.com>
Cc: netdev@...r.kernel.org, linux-kernel@...r.kernel.org,
	sgoutham@...vell.com, davem@...emloft.net, edumazet@...gle.com,
	kuba@...nel.org, pabeni@...hat.com, andrew+netdev@...n.ch
Subject: Re: [PATCH net-next v4 07/13] octeontx2-af: npc: cn20k: Prepare for
 new SoC

On Tue, Jan 13, 2026 at 03:46:52PM +0530, Ratheesh Kannoth wrote:

...

> diff --git a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc_fs.c b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc_fs.c
> index 508233876fc1..d73e447bedca 100644
> --- a/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc_fs.c
> +++ b/drivers/net/ethernet/marvell/octeontx2/af/rvu_npc_fs.c
> @@ -903,11 +903,12 @@ static int npc_check_unsupported_flows(struct rvu *rvu, u64 features, u8 intf)
>   * dont care.
>   */
>  void npc_update_entry(struct rvu *rvu, enum key_fields type,
> -		      struct mcam_entry *entry, u64 val_lo,
> +		      struct mcam_entry_mdata *mdata, u64 val_lo,
>  		      u64 val_hi, u64 mask_lo, u64 mask_hi, u8 intf)
>  {
>  	struct npc_mcam *mcam = &rvu->hw->mcam;
>  	struct mcam_entry dummy = { {0} };
> +	u64 *kw, *kw_mask, *val, *mask;
>  	struct npc_key_field *field;
>  	u64 kw1, kw2, kw3;
>  	int i, max_kw;
> @@ -920,10 +921,9 @@ void npc_update_entry(struct rvu *rvu, enum key_fields type,
>  	if (!field->nr_kws)
>  		return;
>  
> -	if (is_cn20k(rvu->pdev))
> -		max_kw = NPC_MAX_KWS_IN_KEY;
> -	else
> -		max_kw = NPC_MAX_KWS_IN_KEY - 1;
> +	max_kw = NPC_MAX_KWS_IN_KEY;
> +	kw = dummy.kw;
> +	kw_mask = dummy.kw_mask;
>  
>  	for (i = 0; i < max_kw; i++) {
>  		if (!field->kw_mask[i])
> @@ -932,10 +932,10 @@ void npc_update_entry(struct rvu *rvu, enum key_fields type,
>  		shift = __ffs64(field->kw_mask[i]);
>  		/* update entry value */
>  		kw1 = (val_lo << shift) & field->kw_mask[i];
> -		dummy.kw[i] = kw1;
> +		kw[i] = kw1;
>  		/* update entry mask */
>  		kw1 = (mask_lo << shift) & field->kw_mask[i];
> -		dummy.kw_mask[i] = kw1;
> +		kw_mask[i] = kw1;
>  
>  		if (field->nr_kws == 1)
>  			break;
> @@ -945,12 +945,12 @@ void npc_update_entry(struct rvu *rvu, enum key_fields type,
>  			kw2 = shift ? val_lo >> (64 - shift) : 0;
>  			kw2 |= (val_hi << shift);
>  			kw2 &= field->kw_mask[i + 1];
> -			dummy.kw[i + 1] = kw2;
> +			kw[i + 1] = kw2;

Hi Ratheesh,

It's not a problem introduced by this patch.
But it seems that this could overrun kw if i is max_kw - 1.
Likewise elsewhere in this loop.

Flagged by Smatch.

>  			/* update entry mask */
>  			kw2 = shift ? mask_lo >> (64 - shift) : 0;
>  			kw2 |= (mask_hi << shift);
>  			kw2 &= field->kw_mask[i + 1];
> -			dummy.kw_mask[i + 1] = kw2;
> +			kw_mask[i + 1] = kw2;
>  			break;
>  		}
>  		/* place remaining bits of key value in kw[x + 1], kw[x + 2] */
> @@ -961,34 +961,40 @@ void npc_update_entry(struct rvu *rvu, enum key_fields type,
>  			kw2 &= field->kw_mask[i + 1];
>  			kw3 = shift ? val_hi >> (64 - shift) : 0;
>  			kw3 &= field->kw_mask[i + 2];
> -			dummy.kw[i + 1] = kw2;
> -			dummy.kw[i + 2] = kw3;
> +			kw[i + 1] = kw2;
> +			kw[i + 2] = kw3;
>  			/* update entry mask */
>  			kw2 = shift ? mask_lo >> (64 - shift) : 0;
>  			kw2 |= (mask_hi << shift);
>  			kw2 &= field->kw_mask[i + 1];
>  			kw3 = shift ? mask_hi >> (64 - shift) : 0;
>  			kw3 &= field->kw_mask[i + 2];
> -			dummy.kw_mask[i + 1] = kw2;
> -			dummy.kw_mask[i + 2] = kw3;
> +			kw_mask[i + 1] = kw2;
> +			kw_mask[i + 2] = kw3;
>  			break;
>  		}
>  	}

...

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ