From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by inbox.dpdk.org (Postfix) with ESMTP id CEEEF432DA for ; Wed, 8 Nov 2023 20:26:11 +0100 (CET) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id C8809406A2; Wed, 8 Nov 2023 20:26:11 +0100 (CET) Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) by mails.dpdk.org (Postfix) with ESMTP id E68B440395 for ; Wed, 8 Nov 2023 20:26:10 +0100 (CET) Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-40907b82ab9so7405735e9.1 for ; Wed, 08 Nov 2023 11:26:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1699471570; x=1700076370; darn=dpdk.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=nld82sc75gAQLt3zkw/U99bDWy44mM1+nM1tMbWPUF0=; b=ETINphVC7/agIUoYdW4OOswp4Fz+v1tcWGBU5atehVF+2wdLjB0JH2ddC4Dc130xU7 JIKDTO9qFJjZtlgc37ANJR8/05QkmIfRNP37xzNex4YXEEYQOF8DkK+cVf/SDnALpXj5 9RjVNHWqmPKJ8svu/bgv567UQj0FSY09CMKd3qEz8THqrAk9RWay1Noo/K7HIStQgLb9 vYZGQvVWi18RxYSg/fVzuqx1fFvuioTEBfJZMWSiBM0RVo8QstCOX6k6sHkp5OUVxH2n ItI24L918Jzns37jE3Z6VSYczwXxGYjW+nxHxu03kwrhTk4iMzA6f+1Pmo3ZX1pnogTv PzJQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1699471570; x=1700076370; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nld82sc75gAQLt3zkw/U99bDWy44mM1+nM1tMbWPUF0=; b=Bm74O0WnksutoqWy0AuiLeVNB95qW+8VER0tx07yH9HwTSigkhItdRfmgGCKKKyNzs y8cosXXKg9df/nZ7rCBoe7ZqfLrDdaTBsSIifcqwhKG6c85GR8uUHfmEN1ZJNTLRvZyH ErMZ9I8NJF6gWp/JlkiZqE1UjF19S1S0UVDQwflQO1/Xj9Yqjj0Na1zDhEPR48c3Zrwr 9LSb9E/YAyPjH2GZbYgktIUygKYhgWo8IYLZ7nFS8f2Tribk34Nmb8No6BVVBcaJ4+5y aA9nt2Knes5XB2l3bSsylcah8pz+Bogd9eHnmy4a9LuyvdhPEd8g4bCtnIzEVJ8TzVfP Za6A== X-Gm-Message-State: AOJu0YwfxtPpB7xbsnBgHfa7cbqzjXVNNJ1V1rnV4iWtXN5tEz2WPSAa EOpmNpct8+h1BA0Ha+qV4Q7jqWr2xBVXAw== X-Google-Smtp-Source: AGHT+IHHxaoAnmo3DJ+gXHo9t0XawKkjv+oEDAhiT79VB2eRw1VKLlg2jwbzG73An+nrY2nfLiNeng== X-Received: by 2002:a05:600c:45c6:b0:3ff:516b:5c4c with SMTP id s6-20020a05600c45c600b003ff516b5c4cmr3476686wmo.18.1699471570416; Wed, 08 Nov 2023 11:26:10 -0800 (PST) Received: from localhost ([2a01:4b00:d307:1000:f1d3:eb5e:11f4:a7d9]) by smtp.gmail.com with ESMTPSA id f6-20020a05600c4e8600b003fefb94ccc9sm20748993wmq.11.2023.11.08.11.26.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Nov 2023 11:26:09 -0800 (PST) From: luca.boccassi@gmail.com To: Huisong Li Cc: dpdk stable Subject: patch 'net/hns3: fix crash for NEON and SVE' has been queued to stable release 20.11.10 Date: Wed, 8 Nov 2023 19:25:09 +0000 Message-Id: <20231108192535.922238-11-luca.boccassi@gmail.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20231108192535.922238-1-luca.boccassi@gmail.com> References: <20231018235930.3144-41-luca.boccassi@gmail.com> <20231108192535.922238-1-luca.boccassi@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Hi, FYI, your patch has been queued to stable release 20.11.10 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 11/10/23. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/bluca/dpdk-stable This queued commit can be viewed at: https://github.com/bluca/dpdk-stable/commit/ce4857d3dc4602b75d034e4df9f8f261fac9a92c Thanks. Luca Boccassi --- >From ce4857d3dc4602b75d034e4df9f8f261fac9a92c Mon Sep 17 00:00:00 2001 From: Huisong Li Date: Fri, 27 Oct 2023 14:09:41 +0800 Subject: [PATCH] net/hns3: fix crash for NEON and SVE [ upstream commit 01843ab2f2fc8c3137258ec39b2cb6f62ba7b8a2 ] Driver may fail to allocate bulk mbufs for Neon and SVE when rearm mbuf. Currently, driver keeps going to handle packets even if there isn't available descriptors to receive packets at this moment. As a result, driver probably fills the mbufs with invalid data to application and accesses to illegal address because of the VLD bit of the descriptor at the "rx_rearm_start" position still being set. So driver has to clear VLD bit for this descriptor in this scenario in case of receiving packets later. In addition, it is possible that the sum of the "rx_rearm_nb" and "rx_rearm_start" is greater than total descriptor number of Rx queue in the above scenario. So the index of rxq->sw_ring[] to set mbuf pointer to NULL should also be fixed to avoid out-of-bounds memory access. Fixes: a3d4f4d291d7 ("net/hns3: support NEON Rx") Fixes: f81a18f49152 ("net/hns3: fix mbuf leakage when RxQ started after reset") Signed-off-by: Huisong Li --- drivers/net/hns3/hns3_rxtx.c | 2 +- drivers/net/hns3/hns3_rxtx_vec.c | 5 +++++ drivers/net/hns3/hns3_rxtx_vec_sve.c | 5 +++++ 3 files changed, 11 insertions(+), 1 deletion(-) diff --git a/drivers/net/hns3/hns3_rxtx.c b/drivers/net/hns3/hns3_rxtx.c index e0abcce695..4f1354fb19 100644 --- a/drivers/net/hns3/hns3_rxtx.c +++ b/drivers/net/hns3/hns3_rxtx.c @@ -55,7 +55,7 @@ hns3_rx_queue_release_mbufs(struct hns3_rx_queue *rxq) } } for (i = 0; i < rxq->rx_rearm_nb; i++) - rxq->sw_ring[rxq->rx_rearm_start + i].mbuf = NULL; + rxq->sw_ring[(rxq->rx_rearm_start + i) % rxq->nb_rx_desc].mbuf = NULL; } for (i = 0; i < rxq->bulk_mbuf_num; i++) diff --git a/drivers/net/hns3/hns3_rxtx_vec.c b/drivers/net/hns3/hns3_rxtx_vec.c index 63f910165e..a3c81005f0 100644 --- a/drivers/net/hns3/hns3_rxtx_vec.c +++ b/drivers/net/hns3/hns3_rxtx_vec.c @@ -57,6 +57,11 @@ hns3_rxq_rearm_mbuf(struct hns3_rx_queue *rxq) if (unlikely(rte_mempool_get_bulk(rxq->mb_pool, (void *)rxep, HNS3_DEFAULT_RXQ_REARM_THRESH) < 0)) { + /* + * Clear VLD bit for the first descriptor rearmed in case + * of going to receive packets later. + */ + rxdp[0].rx.bd_base_info = 0; rte_eth_devices[rxq->port_id].data->rx_mbuf_alloc_failed++; return; } diff --git a/drivers/net/hns3/hns3_rxtx_vec_sve.c b/drivers/net/hns3/hns3_rxtx_vec_sve.c index 888008d73f..37d4029412 100644 --- a/drivers/net/hns3/hns3_rxtx_vec_sve.c +++ b/drivers/net/hns3/hns3_rxtx_vec_sve.c @@ -243,6 +243,11 @@ hns3_rxq_rearm_mbuf_sve(struct hns3_rx_queue *rxq) if (unlikely(rte_mempool_get_bulk(rxq->mb_pool, (void *)rxep, HNS3_DEFAULT_RXQ_REARM_THRESH) < 0)) { + /* + * Clear VLD bit for the first descriptor rearmed in case + * of going to receive packets later. + */ + rxdp[0].rx.bd_base_info = 0; rte_eth_devices[rxq->port_id].data->rx_mbuf_alloc_failed++; return; } -- 2.39.2 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2023-11-08 19:23:52.501435963 +0000 +++ 0011-net-hns3-fix-crash-for-NEON-and-SVE.patch 2023-11-08 19:23:51.757395961 +0000 @@ -1 +1 @@ -From 01843ab2f2fc8c3137258ec39b2cb6f62ba7b8a2 Mon Sep 17 00:00:00 2001 +From ce4857d3dc4602b75d034e4df9f8f261fac9a92c Mon Sep 17 00:00:00 2001 @@ -5,0 +6,2 @@ +[ upstream commit 01843ab2f2fc8c3137258ec39b2cb6f62ba7b8a2 ] + @@ -23 +24,0 @@ -Cc: stable@dpdk.org @@ -27,3 +28,4 @@ - drivers/net/hns3/hns3_rxtx.c | 2 +- - drivers/net/hns3/hns3_rxtx_vec.h | 5 +++++ - 2 files changed, 6 insertions(+), 1 deletion(-) + drivers/net/hns3/hns3_rxtx.c | 2 +- + drivers/net/hns3/hns3_rxtx_vec.c | 5 +++++ + drivers/net/hns3/hns3_rxtx_vec_sve.c | 5 +++++ + 3 files changed, 11 insertions(+), 1 deletion(-) @@ -32 +34 @@ -index 13214d02d5..f28ca040be 100644 +index e0abcce695..4f1354fb19 100644 @@ -35 +37 @@ -@@ -51,7 +51,7 @@ hns3_rx_queue_release_mbufs(struct hns3_rx_queue *rxq) +@@ -55,7 +55,7 @@ hns3_rx_queue_release_mbufs(struct hns3_rx_queue *rxq) @@ -44,5 +46,21 @@ -diff --git a/drivers/net/hns3/hns3_rxtx_vec.h b/drivers/net/hns3/hns3_rxtx_vec.h -index a9a6774294..9018e79c2f 100644 ---- a/drivers/net/hns3/hns3_rxtx_vec.h -+++ b/drivers/net/hns3/hns3_rxtx_vec.h -@@ -106,6 +106,11 @@ hns3_rxq_rearm_mbuf(struct hns3_rx_queue *rxq) +diff --git a/drivers/net/hns3/hns3_rxtx_vec.c b/drivers/net/hns3/hns3_rxtx_vec.c +index 63f910165e..a3c81005f0 100644 +--- a/drivers/net/hns3/hns3_rxtx_vec.c ++++ b/drivers/net/hns3/hns3_rxtx_vec.c +@@ -57,6 +57,11 @@ hns3_rxq_rearm_mbuf(struct hns3_rx_queue *rxq) + + if (unlikely(rte_mempool_get_bulk(rxq->mb_pool, (void *)rxep, + HNS3_DEFAULT_RXQ_REARM_THRESH) < 0)) { ++ /* ++ * Clear VLD bit for the first descriptor rearmed in case ++ * of going to receive packets later. ++ */ ++ rxdp[0].rx.bd_base_info = 0; + rte_eth_devices[rxq->port_id].data->rx_mbuf_alloc_failed++; + return; + } +diff --git a/drivers/net/hns3/hns3_rxtx_vec_sve.c b/drivers/net/hns3/hns3_rxtx_vec_sve.c +index 888008d73f..37d4029412 100644 +--- a/drivers/net/hns3/hns3_rxtx_vec_sve.c ++++ b/drivers/net/hns3/hns3_rxtx_vec_sve.c +@@ -243,6 +243,11 @@ hns3_rxq_rearm_mbuf_sve(struct hns3_rx_queue *rxq)