From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id 1ACD4A0545 for ; Mon, 20 Jun 2022 11:48:14 +0200 (CEST) Received: from [217.70.189.124] (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 15D1A427F7; Mon, 20 Jun 2022 11:48:14 +0200 (CEST) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by mails.dpdk.org (Postfix) with ESMTP id BAD08427F7 for ; Mon, 20 Jun 2022 11:48:12 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1655718492; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Dau/v6i6/PbrDiD3S25i/BcWylqQOYHSiHbPW5tJojg=; b=Fpm5FroATjgeLApKaHB6rsP2c/UgsWDtic9ipccFHiWjuLFPIt6Xew49SEuNuWca3/fPSC eEQkHLCe4KzdLit/M/eoMmgeA8uA97Z9GCPu6w5osncNh1iMkZeoGEgjG1WHakq7aZSVE/ d28Rfj2QcHfdaaOUrwkWckwi0fwnJFY= Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-316-u6HnTI8zOiWFafmYUxjQyA-1; Mon, 20 Jun 2022 05:48:08 -0400 X-MC-Unique: u6HnTI8zOiWFafmYUxjQyA-1 Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.rdu2.redhat.com [10.11.54.2]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 79492101AA48; Mon, 20 Jun 2022 09:48:08 +0000 (UTC) Received: from rh.redhat.com (unknown [10.39.194.217]) by smtp.corp.redhat.com (Postfix) with ESMTP id 3A1CD400F3FF; Mon, 20 Jun 2022 09:48:06 +0000 (UTC) From: Kevin Traynor To: Yunjian Wang Cc: Andrew Rybchenko , dpdk stable Subject: patch 'net/failsafe: fix device freeing' has been queued to stable release 21.11.2 Date: Mon, 20 Jun 2022 10:47:41 +0100 Message-Id: <20220620094752.1027299-8-ktraynor@redhat.com> In-Reply-To: <20220620094752.1027299-1-ktraynor@redhat.com> References: <20220620094752.1027299-1-ktraynor@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.84 on 10.11.54.2 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=ktraynor@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="US-ASCII"; x-default=true X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Hi, FYI, your patch has been queued to stable release 21.11.2 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 06/23/22. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/kevintraynor/dpdk-stable This queued commit can be viewed at: https://github.com/kevintraynor/dpdk-stable/commit/63bb35c3f358a75067f775d549fa82b68a28c08f Thanks. Kevin --- >From 63bb35c3f358a75067f775d549fa82b68a28c08f Mon Sep 17 00:00:00 2001 From: Yunjian Wang Date: Tue, 7 Jun 2022 14:50:49 +0800 Subject: [PATCH] net/failsafe: fix device freeing [ upstream commit fd819cad0a266421ca9872570e923c2a7ae68183 ] The PMD destroy function was calling the release function, which frees dev->data->dev_private, and then tries to free PRIV(dev)->intr_handle, which causes the heap use after free issue. The free can be moved to before the release function is called. Fixes: d61138d4f0e ("drivers: remove direct access to interrupt handle") Signed-off-by: Yunjian Wang Reviewed-by: Andrew Rybchenko --- drivers/net/failsafe/failsafe.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/failsafe/failsafe.c b/drivers/net/failsafe/failsafe.c index 3c754a5f66..05cf533896 100644 --- a/drivers/net/failsafe/failsafe.c +++ b/drivers/net/failsafe/failsafe.c @@ -309,6 +309,6 @@ fs_rte_eth_free(const char *name) return 0; /* port already released */ ret = failsafe_eth_dev_close(dev); - rte_eth_dev_release_port(dev); rte_intr_instance_free(PRIV(dev)->intr_handle); + rte_eth_dev_release_port(dev); return ret; } -- 2.34.3 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2022-06-20 10:46:27.967483912 +0100 +++ 0008-net-failsafe-fix-device-freeing.patch 2022-06-20 10:46:27.783146830 +0100 @@ -1 +1 @@ -From fd819cad0a266421ca9872570e923c2a7ae68183 Mon Sep 17 00:00:00 2001 +From 63bb35c3f358a75067f775d549fa82b68a28c08f Mon Sep 17 00:00:00 2001 @@ -5,0 +6,2 @@ +[ upstream commit fd819cad0a266421ca9872570e923c2a7ae68183 ] + @@ -13 +14,0 @@ -Cc: stable@dpdk.org