From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9219F33F8C1 for ; Wed, 2 Sep 2026 01:57:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314242; cv=none; b=gxGusujAVUHM2Lk2GVVJtmLxM7N/IpiiuotGSgK1g9f8PGEcP/ECwaPhJniZboTWvt476YFLLufokTGQv/iojTp5wY5PqZIr3QHz5hS8NjS3PhmGUni5rEe9+CMPYPwXyldMFuWYlH+8GnlHy3hIN6z9j+Jk+me4PmohHWjmGe4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314242; c=relaxed/simple; bh=kjynEym4JkM4qLFWRtB6GBT9eT/13ERJsjb/5ssDOQI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=eo4plkNpTojnsUF0asU9F7GQ5oiPkQ4N9DRIjjsdA8iyuYDXrNaV02du+EzJ20xuogttYZE3SUKb+zl2FyzzFZ+A4Q5ohz7ElNfZqsDhaSX4IAjbKg92IaZ8nhTQ6abZ8z4W4CJzxuVODxBCQaEz15nA2eMcJl1oqhrDT+pLL9s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=neuNbo44; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="neuNbo44" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-39927410578so969723a91.1 for ; Tue, 01 Sep 2026 18:57:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314234; x=1788919034; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+2ASlAu8y5yvnOMRkejZNi7wm/1MZgn7xMNUrYUfQtI=; b=neuNbo44bMNUajm357LiSzKnzPxriyzf3VQtr1yrdq5+8LYsxqaz7V9REmNxf03Xkz OHqxnbS1CLxomdb//e+Rs7Ip/1t5n3qYfwLabG0J/oHZSxQhf1uWerbrPTeFUBesMSli Kd5K+xcf04yV/xtMzdqBewpFFDfc4CHUdMCKPD0ekp1XeUfj4m3RAqsiTsIp2bJECUsa GgFcTT/CNo9O/CZrUPUCmF7Hp1o0bNx5puZ7SgxfXADOFBMzbI9Hw4m5WIk6+Q/niJhC 8ml3F+oYNfBZqvq2TzgCh3CpE+QNttvN5llDk9yBO6OF2hQ1VmJ2pGZSizNkwtRSZwZf s4SA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314234; x=1788919034; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+2ASlAu8y5yvnOMRkejZNi7wm/1MZgn7xMNUrYUfQtI=; b=hA//jH4YrFGra6BFG0A2vpz7tf+HA+/VrEdqM5I6kal1Rtwk2pTPe6J134Vlu3lIUc aeiHV5yhK7pqyUT603jWJ6s9RLlQsjQdYAmj3/yW6GSiRbqY+SigkeRqdNmRW24tMBeR NpeOIFw0O+EMXOXj8BcAjVTmj1fxiJl9Y0OX+HF67DiNmp/4JHqJg8kekmME1JAzIfG1 ioJryWWhA7HFTgbG7xAlKRFZ+6svHOAEgmH2cZQolgKLNhResbnIkYFzdGOvqvvAIS3Y Fm94wIqT91CyqGEd2qmSUbeKd7h3DNgQnHx/8dR9VznJF9zw2IKoPAlDRQFXJ0A0Owvg NtAg== X-Forwarded-Encrypted: i=1; AKwUvBzpNnqkfKJPn00TXUXdy2vEq83RreUaNgXJgefjQRQ7JXmHmcYK6zzHZcbmaxv1MaQviYsMXafAOnz4BdY=@vger.kernel.org X-Gm-Message-State: AFuF++l0C9H+1WTDir0uefpnSTAef6ZMNKLCYQRyMODtOjeBTO9dHqaf 3rgzhlcRoUYqSqGCVA0rQoRpi+i3HHccR2ZGLke/yuHWu7onr84Dynd7Fh03iSN4HHI= X-Gm-Gg: AYBFou0szG9aIOIbfwUu8sWqM5zP/T/HvE8be9WEwPdNsVlqPFgXYnCsZAJG8LsZ3hp T46QWj7/Qcly+VEAS1t7qqLZcrD36oZeDdkpZ95I7KDXILKUtxCVFJsrA8ZJnjVPlcMICfF410G 8Do6WOEVzh+SJGszABzBKDfLJk73As026Aft/AJU0h8Pt5Druze+fV8F/QSDlzH0Xy7LnR5zTVI WTd1OCI/bmKhVdrZkvsWQ73qLH4Q0O4e6LKZ8ds+vZSAsOQf3T6k+GPVhxvhThcUs4mHIihB/1S Bz7IOmfko9j7WjNhjIorP1IeJyTdOWYVlOtZoEYOJ9HYm5snubgGODbOjQ3zCSfmaNbZ9qI2Qnv BPKVQyR1yVOUgY6y8uYEJYhzKx7LyiNt/bdVd0FhZeyUfyQKrpdv2PMNj/8GxbaUlRCYryhH+U4 ek7JISK9dRbAhcenVKfNP/oVE1EvDMIdeZthKbypaBzOqzdaaAJZWy X-Received: by 2002:a17:90b:4c52:b0:38e:6aa7:68ad with SMTP id 98e67ed59e1d1-39aedf7c6aemr1801505a91.5.1788314233810; Tue, 01 Sep 2026 18:57:13 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:5a::]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39ae380d7a9sm2252710a91.12.2026.09.01.18.57.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:13 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Somnath Kotur Cc: horms@kernel.org, kalesh-anakkur.purayil@broadcom.com, colin.winegarden@broadcom.com, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , Sashiko , stable@vger.kernel.org Subject: [PATCH net v5 1/6] bnxt_en: Only restore LRO if the device supports TPA Date: Tue, 1 Sep 2026 18:56:44 -0700 Message-ID: <20260902015652.2421609-2-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" With a P5+ device with firmware that reports max_aggs_supported =3D=3D 0, i= t is possible to make LRO settable by attaching and detaching an XDP program even though the device does not support TPA. Fix this by testing BNXT_SUPPORTS_TPA before restoring the feature bit. Fixes: f0aa6a37a3db ("eth: bnxt: always recalculate features after XDP clea= ring, fix null-deref") Reported-by: Sashiko Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.17= 67611-1-joe%40dama.to Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- drivers/net/ethernet/broadcom/bnxt/bnxt.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index d59bcca73a2b..0e5c2a48f313 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -5006,7 +5006,8 @@ void bnxt_set_rx_skb_mode(struct bnxt *bp, bool page_= mode) bnxt_get_max_rings(bp, &rx, &tx, true); if (rx > 1) { bp->flags &=3D ~BNXT_FLAG_NO_AGG_RINGS; - bp->dev->hw_features |=3D NETIF_F_LRO; + if (BNXT_SUPPORTS_TPA(bp)) + bp->dev->hw_features |=3D NETIF_F_LRO; } } =20 --=20 2.53.0-Meta From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pf1-f180.google.com (mail-pf1-f180.google.com [209.85.210.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 80E8D363C6F for ; Wed, 2 Sep 2026 01:57:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; cv=none; b=o0TWnk85AX/IMgcXiD3wq0bYa65P66pkvFrngx5GZDMhDxIRnBu2fGleMANCeXr0sh8dvbjiGvI7kZYPuWQKaET9UYX26QwqnuMZ/gPINa7blbO+2JsR9nX+/NN3A16SN0Lvwcu0XWNi5jPFRStH/jZdWpFUCAbiCiYeu5C/0ho= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; c=relaxed/simple; bh=OO2BGXWS3mSpTcM1EDr/idHgcRwBEfKjIKRjo8GuBro=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EXEQwgc3U2+AbR0OK0iEqdj+RlsFtvNoAo12MX4nRFr0mDeGqBtht8F3bIgpy1epfCb71AoNt2gWKBNVduTvQiJ9DPjikSkixTSRndcUQkTH5zRtfIkq/W+r8vPIN4Rw3F2DV6I6lIcOtgRmBkq783JaJpWRPD6zhZJvSGls32A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=gLBepBaj; arc=none smtp.client-ip=209.85.210.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="gLBepBaj" Received: by mail-pf1-f180.google.com with SMTP id d2e1a72fcca58-84f38f3b36eso436007b3a.1 for ; Tue, 01 Sep 2026 18:57:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314236; x=1788919036; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yQv53l+2Rw8gT5LYIk2AL0drTQ3KamOD30iQa8HJxtU=; b=gLBepBajF+Xh3kyYQ+5Bd+J6eBhFhs/ER2YOdlsgxKs5QnsToRIWEkB4n8Gx+N3vUp FCR2oXAHq00B5f2/wG899jbozk8aG4QZgsRQKBbtdtWD5fAlC0E0PoJyLqW+mtipIuGt Z6kbp0dGGNOLtuSlw56hHuIBg7MW+FfepMeNia+mR3peSD8XWjGXowQDGVKwMzhuNIiV EzzOIMX/rt5PeNPHZ5B8tqAVOuuJo6QOkdW4IgDQbkjx6BymSrh4UgnyUIbp1LVTPxNM LlNPGXHbo4nAo5g+0y7ynIvp5bS03Df70y2PqiNP52KtEUCYVpIL7oaYhPwojt9IZ00v yGyQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314236; x=1788919036; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yQv53l+2Rw8gT5LYIk2AL0drTQ3KamOD30iQa8HJxtU=; b=daa8Ktw+a3XQ7gwSxaVoB6iPYUGK92Tw6DS7yBbUg5jsqUosdQJzr4J9/nq/H3kUW+ aqpvdBZ3UIEy6sVdvQWYdHutIKbhdokSvHbyuUSVBm4O9RQolwahceRv5DRoMHqUI+8S 6FbyL1LRIkrsm50+vnLVdzv8BmQ7Ysf5LozsxVvoB0okl2yNCeEYVlQWPQoHUJXQQP5I vFz62OS05hQAaGP1PYVZaRuxH2Jxz7vIRIfe3+l+88YA3GgxXbDZZMLmvwBpZiT4cAiX i0N4BNNX879ljiyPP3z+OWtKuuRt29G9OozgTgi+ThWkf/Efcrdv1rICgXf2WkQYSW7V 8zgg== X-Forwarded-Encrypted: i=1; AKwUvBxiHJNNE4Ms9PRMVrh7TGdWyzrgGXoD/Ic6KEtue95BDU8CD2ZIwMmz3udPgRuy59xc/eitil2TjYSsLCY=@vger.kernel.org X-Gm-Message-State: AFuF++m/51MCfvOnfc5fQ85VEPr0aoUO1/2Bye2nsz17tHGYgZS7aokS JIGfMwLmaRu5XxFaUd5OiqkaW2dEck7LDb8FKr5JIuUiG+UjfpnaA6W+FWo4MxhGT/U= X-Gm-Gg: AYBFou3NDfAcfU7SLzhXwCsLBNy/7nXUDIB5ZCQxaH4CHA60J9hSe2qTRt2XPH9M8aK CSEyPlHPnRiQzoThzQof/1vdHd22xk7n8dcXpddH0iMr3E5dcg6MJ/grObCLXNOnHqPu5vTsmqm bEZtuzVJuGa+os5fcvhbPoGGZwiT0LMj8IFT35j3yRqponNxt2MLq1LmsslcGl0UHYZzcBpUCNf LWKY0UjLlrRt6e3BoEFvoNUIiErUy2itzEYZF+LFFPpKK1LeK3GYTtaK3ubagSif30FS4Oea0NU 2vDuz/ZsItvqX3oS531L1sdtfVq8nwSVDYZ2xh10WBgTUrXftSL/p+h2HHl65daiC00fFfxxE4i jbUgIDXxiNRxt3CNqSb+rZQqLWu2xPc/q3GYT38RMopXZc/VuxXRDdgQcvSkwnXVEfaa/TCqv5T EjGU/OIW28IvHMVNqdBoetZ2qYfBg1P0asSAq2GVCquC/re503l3ds X-Received: by 2002:a05:6a00:bd8a:b0:857:7317:cff2 with SMTP id d2e1a72fcca58-85ed444a110mr3184790b3a.19.1788314235666; Tue, 01 Sep 2026 18:57:15 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:4f::]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-85dc07157e0sm549385b3a.43.2026.09.01.18.57.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:15 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , David Wei Cc: horms@kernel.org, kalesh-anakkur.purayil@broadcom.com, colin.winegarden@broadcom.com, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , Sashiko , stable@vger.kernel.org Subject: [PATCH net v5 2/6] bnxt_en: Don't free the live ring's TPA state on queue restart failure Date: Tue, 1 Sep 2026 18:56:45 -0700 Message-ID: <20260902015652.2421609-3-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" bnxt_queue_mem_alloc() shallow copies the live RX ring into the clone: memcpy(clone, rxr, sizeof(*rxr)); the code currently clears pointers that the clone owns (such as rx_agg_bmap), but rx_tpa and rx_tpa_idx_map are left pointing at memory of the live ring that was cloned. If an allocation failure happens later and the err_free_tpa_info label is taken, the live ring's memory can be freed while still in use. Fix this by initializing the clone's pointers to NULL to prevent live ring state from being freed inadvertently. Fixes: bd649c5cc958 ("bnxt_en: handle tpa_info in queue API implementation") Reported-by: Sashiko Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.17= 67611-1-joe%40dama.to Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- drivers/net/ethernet/broadcom/bnxt/bnxt.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index 0e5c2a48f313..f44a23c8a590 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -16333,6 +16333,8 @@ static int bnxt_queue_mem_alloc(struct net_device *= dev, clone->need_head_pool =3D false; clone->rx_page_size =3D qcfg->rx_page_size; clone->rx_agg_bmap =3D NULL; + clone->rx_tpa =3D NULL; + clone->rx_tpa_idx_map =3D NULL; =20 rc =3D bnxt_alloc_rx_page_pool(bp, clone, rxr->page_pool->p.nid); if (rc) --=20 2.53.0-Meta From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A722533F5B0 for ; Wed, 2 Sep 2026 01:57:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314246; cv=none; b=Z4i0Moe8YwZtrUHDCFzJPhRB0fnGYOevbJNyaEiusCAA0I+ZLDDU63aiUa99l8govSCbunmMOLstZvHDPfzjA/cUABzm53suF1z8gQSsSvghtXF4DFFXo806/QbKyg6SdUCXcWzWYXnK80X//J26DEblX6QPgCfJudcO1j/QRpg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314246; c=relaxed/simple; bh=bMFLT2hd1hgF7+PT38bLPmDwKJnBhytafbJhxitvRbU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=B+EJq9jTXvhmGrmlGS8+xfxVdetdAZom8rXBeEz741t9eR57KZHUuCwjRuOLskKQsvpctS8MOnUM7s8sQf/5+AAWYONnqYL+sX6gjpggaZc/fDS2RFEuoho8LI8MbSJJBtdNFKahAw/xwvrMHMdpXeIUttIm5mVqFV0QqFakUII= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=hnlTxdUa; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="hnlTxdUa" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2d01663d816so4117795ad.1 for ; Tue, 01 Sep 2026 18:57:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314237; x=1788919037; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=24B4a/9ThhnK86I6tiKZdFQ0uGyx0+7AN1IThAG1aFQ=; b=hnlTxdUaTABgt+Dr91k5xaxbTnzqZ8WafnMaUN5j3D3qizjd31MAQm/cw9uxXbxZr9 Dv4pc4BmOA6csckTPVE3NnGxDZlMuG1kPiJhto7zK6f6YBfDmMcJZk494afI4uMtuX4o JH00h785k62lgBIG+IpZwFLZ2tfkfgefsvqPCUUjj8nRLOapdFWTumTHctueqhk4kWgz uaL0V/46xdxs0Ia6jp3Z+zPhT+atgmyn0sovgZA8lhCxjlx6cDWcKeATaQ2lt5XEAwAX cbBQ4jty4Vq3HjI4s6ArUCZuOXLgIzM+DVpY5XcG0bXAB5CF06Jn6WIZO5UPbBz7O7ej gjrQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314237; x=1788919037; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=24B4a/9ThhnK86I6tiKZdFQ0uGyx0+7AN1IThAG1aFQ=; b=cOhDBEqLHszWUF7Z2+qtYpPeIxX5vXnUeOgymSbtfjQp8SgJCClpfJevEt4WMTR7p5 nNlHKGGFfFQN76WUHkGUYvrS+ZViIxAXjozgqJsftSX1/tAtRa6DM7g8QNzQ6WaZYD21 BObZLLNS23on14FSybpZougiI1gBIVwm9mzvgsFiLMeu7JD5kO93AHjLvMRBr1jLcaLC IgPZHXGc4UrsjkYQvSZroykALrkwdqmLsY6YL3VOONUvpSj0niSf4jmzGSuUfYrJ4cNn JvEQn90+d4YhFwWpxTdCemwa6hVmSDmYHSJdcFb6h+Y8U16haBGlNwaZIrDzUt+79kFd f40g== X-Forwarded-Encrypted: i=1; AKwUvBwnEWyIK+jFiIb253UKHExv5IWQwfx7KvY7/gsov8fplIOHL+oIHNcysKT7uRrsIOhIGo6BxPcRrx8CXac=@vger.kernel.org X-Gm-Message-State: AFuF++mhVnlUbaCMojmjoxtVfuPQ+sKKc/7f2aN7XxaYvnBNFHmYAw5a b+LW1mnWzpcqv0mZrD5NNcv2x+hYUtMUEh+bUwV69prclm6a3AM9r3B6PL2tg/8liU4= X-Gm-Gg: AYBFou2IWHIA88fh0lxyNGVGesgMG00h8RZ14QjRrx/uix3oz3QVtEZC4joT8yV/Bth t+MR5bhzlKOf1UXeKHRHpxcWI62bbPWouyTddUnSQbYA3b6vcyZCftAd3P+lF65fS+TlsPkcQT1 FO/ZA75ZelYLVd9uxNefRLra8AkedcOiWrcFEHBI4JhmsYs5+Cwneo+eHwuRH11yN/sZJQGYNuG P5+Z1+Kgmrh1XRZhqd8f0U09aOuno/sNNeNa3Zk9bsNkJdPAsYSB5fJODetJWpGqgUkj+77y9OJ aTukpL9yPA9R/+fHctSvskxixYJdd6i49IW7V71H3XLP1nBODkmllf/mDdSZcPCR7arN+OcfmT8 TnFJ1eIBXD8D/Ssu61NkMro/jX5Ikqp/QDTe2OH130Ng9RAVierI9XCaU9AUe3nwb1s1jKtpIOt 4aK8IQx1aS4JaR11jnQ28f8EJbPjlFi0cKq999KdNjOg== X-Received: by 2002:a17:90b:4b89:b0:398:c3ca:1ebc with SMTP id 98e67ed59e1d1-39aee105a46mr1643584a91.18.1788314237407; Tue, 01 Sep 2026 18:57:17 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:5a::]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39ae0dfeff4sm2473024a91.4.2026.09.01.18.57.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:16 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , David Wei Cc: horms@kernel.org, kalesh-anakkur.purayil@broadcom.com, colin.winegarden@broadcom.com, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , Sashiko , stable@vger.kernel.org Subject: [PATCH net v5 3/6] bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() Date: Tue, 1 Sep 2026 18:56:46 -0700 Message-ID: <20260902015652.2421609-4-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" bnxt_alloc_one_tpa_info_data() returns -ENOMEM as soon as one allocation fails. This leaves the remaining rxr->rx_tpa[] entries zeroed. bnxt_queue_mem_alloc() discards that return value, so the partially initialized ring is installed by bnxt_queue_start(). Since the agg_id is picked by the hardware and bnxt_alloc_agg_idx maps it to a SW index in rxr->rx_tpa[], it is possible that an uninitialized slot can be chosen which would hand a zero DMA address to the device. Fix this by checking the return value of bnxt_alloc_one_tpa_info_data and unwinding, freeing the ring buffers. Fixes: bd649c5cc958 ("bnxt_en: handle tpa_info in queue API implementation") Reported-by: Sashiko Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.17= 67611-1-joe%40dama.to Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- drivers/net/ethernet/broadcom/bnxt/bnxt.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index f44a23c8a590..3755a30f8d40 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -16378,11 +16378,16 @@ static int bnxt_queue_mem_alloc(struct net_device= *dev, bnxt_alloc_one_rx_ring_skb(bp, clone, idx); if (bp->flags & BNXT_FLAG_AGG_RINGS) bnxt_alloc_one_rx_ring_netmem(bp, clone, idx); - if (bp->flags & BNXT_FLAG_TPA) - bnxt_alloc_one_tpa_info_data(bp, clone); + if (bp->flags & BNXT_FLAG_TPA) { + rc =3D bnxt_alloc_one_tpa_info_data(bp, clone); + if (rc) + goto err_free_rx_ring_skbs; + } =20 return 0; =20 +err_free_rx_ring_skbs: + bnxt_free_one_rx_ring_skbs(bp, clone); err_free_tpa_info: bnxt_free_one_tpa_info(bp, clone); err_free_rx_agg_ring: --=20 2.53.0-Meta From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 41AC7363C5F for ; Wed, 2 Sep 2026 01:57:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; cv=none; b=Xoy1kkjhENcwiat5O8pTFjYolpJf5DoTgC1LPACiaR4JXlpgP7yjb0m092XUtMUjaT6NVnbwZoylPclp5wQ6GzBPGC0pZkbQWmgghaqXc2ZFJ+0z2fmmGuOcJqw+iJKNYCcDYMsxCBMWLUwbd60xS1iooA4DC+dT8F8iSHgEi3U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; c=relaxed/simple; bh=Ik8QSbgXP5buhxF8hVJJ2LX4PPnIIT1KbX8G1W+E0SA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=liMLUdEpbatFgoi/ZDjmiDPMqlRX/562xxEPH/tdQ0595umhIkLbL/8Jsr4ePD7M2rpaVI5Ol3EAzZR3gcoWWCWZftVwN532OewBHDN4xT55lHgCY6CHrSHffRxebG7ALCzGXxxswVXCIh5q0bFG8tHV3XWxOeRvMn461wHopxo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=Lgy4n7fc; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="Lgy4n7fc" Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-2d5335cf904so4380605ad.2 for ; Tue, 01 Sep 2026 18:57:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314239; x=1788919039; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=t8NexaY5OOI9G959hLH28cElmfzdE2NH8o0S1EDtR7Y=; b=Lgy4n7fctmLm0VRdGB0LQd3y29ORZSxGQdnw5PrQ+Xwc/RVzHoPyoscLCqWSCL/cV0 t5o50+BopFN/QtF56t7uzdshXY38OfQprnUGRu1fomkWM7eOFnVKsm6wXlrHyymhNba3 LiPGbyzGPIfTMQeI+kPyXPcgqFrnWWeVEyoNdMl9ilaBTkA/dEY69qt7qD876dnDLdWd At8gHvXLs805Voihj5n1yRCUJaVLO41HGPj+T8yYwXrej+MfTQkMeV9DDogXdVLpf0DA WhSu/jlarygTuwN0ZPLq83SRSX2x26TCJDA7W+DjXt2280ZFaajbwmPY0C4EjkhbjD4j +ttA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314240; x=1788919040; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=t8NexaY5OOI9G959hLH28cElmfzdE2NH8o0S1EDtR7Y=; b=RNFeNt89J/LXyeHw1zI5D1Tsgx2xdwqgUuGZUquj0C6HWrAbuGjAs/JGOrGeK5IOy+ 6aIiqnEoSOAR7c1zhKfLzg/XnFh9u9R3MkvNB98jtDznPBAw/GX/jIYe7sAHDBm5Del3 8hag4KVD7HOVZbAMhUM7C5O0Te+DPG+cCdVYCpZdAf/X0ltTGlVW5x3A6Jz62fFzWsUw cfcGKPq7EdMimIdLsaFGy4vV1isNjdOK0sVgklBCLzkFL7RxxRYzM3YpzJsi6ZA6t4Or Begl8GLddKytwxtx1AkAOjVPbPOj3WcH+dghthCI3oGKqRMG5X1JuUT4HM9U8fMRl3+j Tm6Q== X-Forwarded-Encrypted: i=1; AKwUvByRD05Kdw9bhzneaKK2OLu8ztPiy+67uH7A2uDnr7NzBoJTQB78xW++zbiX/fcCbF8WXtMPdQYslvOfVjg=@vger.kernel.org X-Gm-Message-State: AFuF++kYFaEuk+cuK0flWpv/7LxZmb98CcpcFQwAFhPYdDBokeDN4Xzu SAKobk73+czNDcr/k4tm8NQteJ9qj1X2T2x8c0+j8ICnCD6BwUh8bIVbj+IUXXecFw4= X-Gm-Gg: AYBFou3UOk7zKvlLmgtRMe0idUXKFPiaXwoG9Dhp8VcL3NTTQew+UNkN2p8qGNwRYGT pBGFf4RmBT0o8x6j9BslZKdpgfUVDbYKegZtLKf47hrxpfr3UE0gnPC4Lj6lgsSbZ/+zv3qDxlu 1m+sV4WVDBxBTqM2tExCXcvpLb6EgWOeThkQI1Km7QRkHvVGc34yjwYbK9W7e85S0ueQqZg3j8o qpH3ZKmlPJU1npBIl08IUh5IqA3IgEnr24eGIN8UJ7M1yTkToGrxnJvn3O/b455I0Yd4JUMtDdN FzEcRX3yQpyb7p/2dyFdX7QtPhMUw1MwuW6VXACOmGr4Oo3vjrFGt8TGpHfEmsJIdIwYFmZat12 OolLKzyUCkbhPMjEKMB2+IeieZkJCBtUGq8KEU5cRgakhFfU2QMukNy/uVoUUt4nMA8SQL7k68q vpIOz4ZikJACA5MBPGkTgDNH1ia/yAbzTZBSk4OU+FdHk= X-Received: by 2002:a17:90b:524c:b0:390:8361:a532 with SMTP id 98e67ed59e1d1-39aedfb8ebcmr1991272a91.7.1788314239469; Tue, 01 Sep 2026 18:57:19 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:71::]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39ae0dfe6b6sm2346061a91.1.2026.09.01.18.57.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:18 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Edwin Peer Cc: horms@kernel.org, kalesh-anakkur.purayil@broadcom.com, colin.winegarden@broadcom.com, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , Sashiko , stable@vger.kernel.org Subject: [PATCH net v5 4/6] bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() Date: Tue, 1 Sep 2026 18:56:47 -0700 Message-ID: <20260902015652.2421609-5-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" bnxt_rx_ring_reset() frees the ring buffers and then reallocates them, ignoring the result. bnxt_alloc_one_rx_ring() can fail in bnxt_alloc_one_tpa_info_data(), which returns -ENOMEM on the first failed allocation and leaves the remaining rxr->rx_tpa[] entries zeroed. The error isn't propagated up, so the loop in bnxt_rx_ring_reset continues and at the end the code re-enables TPA with partially unallocated rx_tpa array. This means that when the agg_id from hardware is mapped to a SW index in rxr->rx_tpa[], an uninitialized slot can be chosen which would hand a zero DMA address to the device. Fix this by falling back to a global reset, which is what the existing code already does when other functions fail, but unlike the other failure cases this particular failure has to return because TPA can't be re-enabled since the allocation failed. Fixes: 8fbf58e17dce ("bnxt_en: Implement RX ring reset in response to buffe= r errors.") Reported-by: Sashiko Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.17= 67611-1-joe%40dama.to Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- drivers/net/ethernet/broadcom/bnxt/bnxt.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index 3755a30f8d40..a8e5fdfcdf59 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -14604,7 +14604,14 @@ static void bnxt_rx_ring_reset(struct bnxt *bp) rxr->rx_sw_agg_prod =3D 0; rxr->rx_next_cons =3D 0; rxr->bnapi->in_reset =3D false; - bnxt_alloc_one_rx_ring(bp, i); + rc =3D bnxt_alloc_one_rx_ring(bp, i); + if (rc) { + netdev_warn(bp->dev, "RX ring reset failed to allocate buffers, rc =3D = %d, falling back to global reset\n", + rc); + bnxt_reset_task(bp, true); + bnxt_rtnl_unlock_sp(bp); + return; + } cpr =3D &rxr->bnapi->cp_ring; cpr->sw_stats->rx.rx_resets++; if (bp->flags & BNXT_FLAG_AGG_RINGS) --=20 2.53.0-Meta From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87CF135C6A4 for ; Wed, 2 Sep 2026 01:57:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; cv=none; b=nnkFP1yPaAwA7ncwb5KloPEnb4yA4iKA9tX1zdStIYgdyj/3YB/V+7rBlBXFV4HL84ySCqPeMRH9c0g2vsdxbzsfM/JKFlHkFPqgF8tgnb5uPr5jRkWxMSLauoRhWufYZcMZCYapny9drADm85CTkvitRHKs09b7saSy1SaPE3U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314248; c=relaxed/simple; bh=gccopKJo6AMNY10hGDCTCtkumpeREXXBiisLLwf1er4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=KSbXIDN7KcqQ9GT89gP547EacQyX57h/bP+VpP5LPNJGjvxEJ+NoFVMU1bgMuSb58+t7FdA6iuRCxsrxycK8gnxCQVLqaG2fJ77FcUYLD/HbTJX3SWD0DCYYydOzFvPWsvWfQmdsvelrcWwmV3jauknAFT2BzFWkejEFW2YjlQ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=TTXXe5Xu; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="TTXXe5Xu" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2d53197d8b5so4375925ad.3 for ; Tue, 01 Sep 2026 18:57:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314241; x=1788919041; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2wimfaoY+1kK1sxo3NPrBDMOhhGsT7Wm36ytAjDSTIU=; b=TTXXe5XuttfR+yczz59mBqblBnFMovbkhBNBNs2hUIzuscgXSpmhjGT+ulevxYL98Z MpDOIZf3SEURftEF98mP/Qy6Lw5steBzYsHOUV0iJD1MtYsmrrX7+eVERc8o6tMBXoIG T0E9GrLaFVED2X1JGEI5iMCe0sgZ/udgE6OIqYejugYS/ORNSlDav4EIl3pYwxbdy8JK sW+tgob18UM8zkfroNZLZieT/R+0LH2yY/iFGiMO4vrCRys6k8Gj1HPJ17Il5z0hb7Mo zviVK7aKWDK0htuxC0pVpd4M47+ZYWtaDGJ0Tr9xT8u1lmRpCEGWOcb8gu3iq19ayH5F RtJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314241; x=1788919041; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=2wimfaoY+1kK1sxo3NPrBDMOhhGsT7Wm36ytAjDSTIU=; b=ah4G4PVwS966czG1RRwIutOn+5RtF8QnDiPwWUHZ6mJ81ChvzwCu4KE75EgCiLnXZM Z0AjkkBiHcYwgKABNBDJnEt3Rp3MGdBwYukaos9XZhRYEglht0MaxOMVpoRBDvsSaYth 31XRhbYetEzbZRTQZtgI/n2LKaufFOBUgPXzURt/jSE7WmAxjEYCS5bdgjXqSKgTL9nw 7C7tIi4mcB4mS6hhn3kuRPVXOcw1WHw7trTAvn0YZzrX53ystyb8J0wGQKPhXH4DbFSE tprzsJOlULakL5ZHrZESEHu9wG6INx7DqCeTNaa2IUfrWkXv272UAUNi0nMhpCPGB/i7 Vl/w== X-Forwarded-Encrypted: i=1; AKwUvBzgU601gHyveYcWq+3P3S+ARi3szYHdKWlFqEfUQQTg918qeNX7oHEIQT18+KGt1GqwuXGqPm5flZMX8Hs=@vger.kernel.org X-Gm-Message-State: AFuF++ku+3KmIt1yLxoWV07qF+5z2xsf1NPiKQrmZocoudEhvo6bRzB6 zVpSAagd0RYUp0VKdD97U/+cBKjgmTpQgEdpx6o1nuKePMFlDQbA7pIJqcq2bzcDKJlL6qNKN/T PZfM8XmY= X-Gm-Gg: AYBFou1ynG1drFMu92lMrJxm5kWEvMsG7kVo3uE1dgaP74yIPLghNxPX+AsQ0dNggAL 2/5j9cjI4zrmdJmAwTsdyFndVy6fCszvPy7+FuCPO1BmrgnP9/qsYbskNpE+ppcFKlpKCc/Wog5 j4rpotNryf93xXRvhEyj7ypaZmUJC98LkwtTqr9lMZRXiLLeSETI0+vgx9+Gp2VNofCsyARgs6u y4FJZ70iDW+ANaCTJIqy7V6+kkOroATK75j4LQT8cdz4rn2BLGH1XbXaO0RenEwQcTJvhogcB1V ScYCcFqFBB2+lHcKhIMTONLHFh9vOIXzjzTgyB72izK/PfM9FUL+fa2BQlAMp4pAYZHXVEQtGI+ K/ryShOlMPDGu7SQSC9jCsXXNgb0DRXV8toAICt5tsrTXg6JcJh8WGi8l4+DS1/hgIf6I5eBgdb a+1KtDi6cE86D4ed2W/zMVbm4IbwY83+4WfzxCFOXjgjMJ1t93qMHO X-Received: by 2002:a17:902:e544:b0:2d8:d4d1:313a with SMTP id d9443c01a7336-2daec77411emr18790655ad.17.1788314241319; Tue, 01 Sep 2026 18:57:21 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:56::]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2dadd488d18sm5198245ad.45.2026.09.01.18.57.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:20 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Prashant Sreedharan , Eddie Wai , Jeffrey Huang Cc: horms@kernel.org, kalesh-anakkur.purayil@broadcom.com, colin.winegarden@broadcom.com, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , Sashiko , stable@vger.kernel.org Subject: [PATCH net v5 5/6] bnxt_en: Propagate RX ring init failures in bnxt_init_nic() Date: Tue, 1 Sep 2026 18:56:48 -0700 Message-ID: <20260902015652.2421609-6-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" bnxt_init_rx_rings() returns an error when bnxt_alloc_one_rx_ring() fails, but bnxt_init_nic() discards that return value and calls bnxt_init_chip(), which enables TPA. If an allocation fails, this could leave rxr->rx_tpa[] partially zeroed and TPA would be enabled over an array with zeroed entries. This would lead to a zeroed DMA address being handed out if the agg_idx is translated to a SW index at a zeroed entry. Fix this by propagating the error out of bnxt_init_nic(). Both callers already check its return value and unwind with bnxt_free_skbs() and bnxt_free_mem(), which tolerate a partially initialized RX ring. Fixes: c0c050c58d84 ("bnxt_en: New Broadcom ethernet driver.") Reported-by: Sashiko Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.17= 67611-1-joe%40dama.to Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- drivers/net/ethernet/broadcom/bnxt/bnxt.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index a8e5fdfcdf59..d2943de1b62a 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -11341,8 +11341,13 @@ static int bnxt_shutdown_nic(struct bnxt *bp, bool= irq_re_init) =20 static int bnxt_init_nic(struct bnxt *bp, bool irq_re_init) { + int rc; + bnxt_init_cp_rings(bp); - bnxt_init_rx_rings(bp); + rc =3D bnxt_init_rx_rings(bp); + if (rc) + return rc; + bnxt_init_tx_rings(bp); bnxt_init_ring_grps(bp, irq_re_init); bnxt_init_vnics(bp); --=20 2.53.0-Meta From nobody Sat Sep 26 11:47:17 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2F697341660 for ; Wed, 2 Sep 2026 01:57:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314253; cv=none; b=TFawL4DAdvDx92iVYWJpO6e6AF13briEf4nREWxLfF8IjzMT0wNIuM2HO0PqCmeUs7E/feAjEQUOSaKmq0MPCzDNw2Ajc/VABdzrEKH1ZitdpJ0Sqg54JLMSCcLXszNutzzXL213y9F9RCcf3mhXq5Z477PMORR3k/ABQzNpVl8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788314253; c=relaxed/simple; bh=nNFtUFgC/p/K4K6LX995cICjDodLLrWxvJtEwtyVtZo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=K9MIwQ0YaG1ktUsr8UBYd7k+fYSTQV97c9tOgtRpxRAr3EikDn43fFNWSmWHuNB749oBk4bMt+92EYVxKIGGiS6SftDG+l6l0HswQ/2RdkJEXcFm7a5jFC7eWPPKzJLMOskthPXgaCWWIurkDiTHQIi3MJ/QFtY6Vbn7yhCmnO4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to; spf=none smtp.mailfrom=dama.to; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b=pbj6n1Mn; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=dama.to Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=dama.to Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=dama-to.20251104.gappssmtp.com header.i=@dama-to.20251104.gappssmtp.com header.b="pbj6n1Mn" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2ceab75934dso5625975ad.2 for ; Tue, 01 Sep 2026 18:57:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dama-to.20251104.gappssmtp.com; s=20251104; t=1788314243; x=1788919043; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=O2+yr/LF5kIYJw79OBD8uWpDfnVTI0CymWIi9oO6fGg=; b=pbj6n1Mnp7kainZQovS0x4vow1t2efIXU79khXi88nIfaJzO3+ftcmSFyFnShUE8at x0TChwUe8bU4Sg7tNeyEmTmKyVJX3/WUNtgYGEnrzAsokZ6B0IPSDyqvBAloo5BjcJhV MX9x2Crcww5bXwAlvbHM7eYsKEG0SKcsKiJoGZEH1bcmknh6OTtSHTqwpxZclNE4Feqc qEAwVIl2hovbCC+JL6S7vDfphmalEx0DVFddX52HQZxlSm3YC9RnY9PzuhPRUEtf3M2m d+vddqelbENFMHvPHCBU9zm+2eqIJMqWk+MZI1kmANGxpbfaotfic1xO7r0Jm9QQWVor 6OPQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788314243; x=1788919043; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=O2+yr/LF5kIYJw79OBD8uWpDfnVTI0CymWIi9oO6fGg=; b=gfl9S9ADwZ/K9+03xi21jZcrSvGP4w+Ay0Z8cZ758Bv/QrTaxx4x9bIknvr9msYado s9U0bkGWSBUYW+DI/qaTX4WayARQqkbuhrNkz+NC866kOvKwzP7vrGWRbROA91dx9xZI vD1ZO19iV3+40kCNZ8I8m2ZGUE1yY3FE+TnQaAttQR/Pf8PZ+29AXySCuimoJNqinAk4 TFZ7bxVMdJND7xYl2deIC1FGNIxzHw+a4cTxoUeiav6JbMz8eJQkUiHuTFE4X78hblI8 u9VsJ+uisIRvcgczgXrmwLpdWdgDTM4cVSmCKhUshPTk8NrnfnWa8EaiL5zKBXoauC/Z 4elg== X-Forwarded-Encrypted: i=1; AHgh+Rr1ZeLhKu8CdCdwrFSr0auMm9lEvAF9GL6nhQkCw4DWTm8cw1AkhEPzhQr1ZyK4PcCm2WkSGGO9vo3XK7I=@vger.kernel.org X-Gm-Message-State: AFuF++mrVG5TogvimhWI0qW6EkHZqrn8YYxlYI1YYvm/vRvRtbxdeYo4 /96yD1oPERPcZQYKBqItKFo5aZ4FOhl5YYqeCfEhUzJM9T7mw0uisfDNO4tXPff1O6o= X-Gm-Gg: AR+sD135kH6wHF1NN+VPcAKCX2eFfO4J+NyYwH8ZQCgZmtZETG1m8BgEK3rAnt6l6Bp D3QyiMCwcyzk867/eOtRLCbmwkOziybycKvoThh76iG0jT69sSXALnqbfag331Xb7H7iHPEW19z uH9PsjR0b7xNYTkuEXM2YHlKnK7dh0eTEhnVW1eyPhMxfa4ZWQs3MaC8WmmYuaJELqceeCRpVcH fXimSc4Y5nLrVdHwqssW2zmsoTN3T3XN9OJWRc+QLmKT6/UxkOaDd87QURpJ7gZbyWdaM4N0A4M jT31f2ogbRvLuhnYy7lSE2kikuH2qG2Ipe4KFdoZEI5MUylTgs7EHxgMCEWzwSLjVl4O8nnI9oU 3KwpI+WcFjEVTfvHpY/m7GTNrx/AdXDtctmAosiSM9vZ8phPb9uDhSjFdjiVVWdnp7fvmH8Zrx0 DGVaKaJ0CFwozC9hhSJyYPBAM4uIzZFnf4kFGFlyNm X-Received: by 2002:a17:903:3910:b0:2d9:464f:d45f with SMTP id d9443c01a7336-2daec5dfb40mr22503425ad.5.1788314243448; Tue, 01 Sep 2026 18:57:23 -0700 (PDT) Received: from localhost ([2a03:2880:2ff:4::]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2dadd356dc8sm5221595ad.8.2026.09.01.18.57.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 01 Sep 2026 18:57:22 -0700 (PDT) From: Joe Damato To: netdev@vger.kernel.org, Michael Chan , Pavan Chebbi , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , Colin Winegarden , Kalesh AP Cc: horms@kernel.org, rukhsana.ansari@broadcom.com, linux-kernel@vger.kernel.org, raphaelcf@meta.com, Joe Damato , stable@vger.kernel.org, llvm@lists.linux.dev Subject: [PATCH net v5 6/6] bnxt_en: Bound SW TPA IDs to prevent crashes Date: Tue, 1 Sep 2026 18:56:49 -0700 Message-ID: <20260902015652.2421609-7-joe@dama.to> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260902015652.2421609-1-joe@dama.to> References: <20260902015652.2421609-1-joe@dama.to> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" FW supports up to 1024 concurrent TPAs, so the FW TPA ID is in the range 0..1023 (see commit ec4d8e7cf024 ("bnxt_en: Add TPA ID mapping logic for 57500 chips.")). bnxt_alloc_agg_idx is intended to wrap the FW ID down to a software ID which is used to index rxr->rx_tpa, and to generate a mapping between FW IDs and the wrapped software ID. On a 57608 with firmware version 233, the firmware advertises 32 concurrent TPAs. As of the commit under fixes, bp->max_tpa on this NIC is set to 32. If the software ID from bnxt_alloc_agg_idx is above 31, this results in an invalid address being loaded on this line: tpa_info =3D &rxr->rx_tpa[agg_id]; because rx_tpa is allocated with only bp->max_tpa (32) entries. Writes to tpa_info later in the code are out of bounds. This bug results in a crash at boot: Oops: general protection fault, kernel NULL pointer dereference 0x8: 0000 [= #1] SMP NOPTI RIP: 0010:bnxt_rx_pkt+0xc0/0x1560 RSP: 0018:ffffc900009b8c78 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000048 RCX: 0000000206682516 RDX: ffffc900009b8db4 RSI: 0000000000000000 RDI: 01ffffff038fe1c0 RBP: ffffc9006e687480 R08: ffffc9006e687000 R09: 0000000000003048 R10: 0000000000000480 R11: ffff8881c6083900 R12: 0000000006682516 R13: ffff8881c6095400 R14: 0000000000000016 R15: ffff8881c6b66680 FS: 0000000000000000(0000) GS:ffff88fef3c77000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc8bda40584 CR3: 000000807c812001 CR4: 0000000008772ef0 PKRU: 55555554 Call Trace: ? __netif_receive_skb_list_core+0x1ca/0x250 __bnxt_poll_work+0x152/0x280 bnxt_poll_p5+0x1cd/0x480 __napi_poll+0x30/0x180 net_rx_action+0x20b/0x3b0 ? note_gp_changes+0x53/0xe0 ? tick_setup_sched_timer+0x180/0x180 ? __napi_schedule+0x9a/0xb0 ? bnxt_msix+0x24/0x30 handle_softirqs+0xdd/0x2c0 __irq_exit_rcu.llvm.3171231171502365008+0x47/0xf0 common_interrupt+0x85/0x90 asm_common_interrupt+0x22/0x40 This stack trace is from a crash triggered when an out of bounds rx_tpa is dereferenced. The invalid write mentioned above is silent in this particular crash. Fix this by allocating rx_tpa with bp->max_tpa rounded up to the next power of 2 (bp->max_tpa_roundup_size) entries and masking the FW TPA ID with that size, so the wrapped ID can never index past the end of the array. Fixes: 54c28fab2fa5 ("bnxt_en: Set bp->max_tpa according to what the FW sup= ports") Reported-by: Raphael Cardoso Fernandes Suggested-by: Michael Chan Cc: stable@vger.kernel.org Signed-off-by: Joe Damato --- v5: - Updated the commit message to mention where the 0..1023 range comes fro= m. - Updated the comment in the code now that a previous commit in this seri= es addresses the LRO issue. v4: https://lore.kernel.org/all/20260828190900.1767611-1-joe@dama.to/ - Moved bp->max_tpa_roundup_size init out of the early return path and documented that TPA is unsupported there, as suggested by Michael. v3: https://lore.kernel.org/netdev/20260827185700.2157164-1-joe@dama.to/ - Addressed an issue Sashiko pointed out, where max_tpa_roundup_size may = be left unset if bnxt_alloc_tpa_info returns early, which would lead to out of bounds access. - The other pre-existing issues Sashiko pointed out are unrelated to this patch and would need different Fixes tags, so they are better served wi= th separate patches in the future. v2: https://lore.kernel.org/netdev/20260825001842.2501798-1-joe@dama.to/ - Followed Michael's suggestion on the v1 to increase the size of the tpa array so that wrapping indexes into the array is a simple mask. - Add Suggested-by because the approach was suggested by Michael. - Add a Reported-by so that Raphael gets credit for reporting this bug. - Boot tested on a machine with a 57608 and the crash did not reproduce. v1: https://lore.kernel.org/netdev/20260821233549.3134699-1-joe@dama.to/ drivers/net/ethernet/broadcom/bnxt/bnxt.c | 27 ++++++++++++++--------- drivers/net/ethernet/broadcom/bnxt/bnxt.h | 2 +- 2 files changed, 18 insertions(+), 11 deletions(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.c b/drivers/net/ethern= et/broadcom/bnxt/bnxt.c index d2943de1b62a..b2ce5b4e5e6a 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.c @@ -1514,14 +1514,16 @@ static int bnxt_discard_rx(struct bnxt *bp, struct = bnxt_cp_ring_info *cpr, return 0; } =20 -static u16 bnxt_alloc_agg_idx(struct bnxt_rx_ring_info *rxr, u16 agg_id) +static u16 bnxt_alloc_agg_idx(struct bnxt *bp, struct bnxt_rx_ring_info *r= xr, + u16 agg_id) { struct bnxt_tpa_idx_map *map =3D rxr->rx_tpa_idx_map; - u16 idx =3D agg_id & MAX_TPA_P5_MASK; + u16 idx =3D agg_id & (bp->max_tpa_roundup_size - 1); =20 if (test_bit(idx, map->agg_idx_bmap)) { - idx =3D find_first_zero_bit(map->agg_idx_bmap, MAX_TPA_P5); - if (idx >=3D MAX_TPA_P5) + idx =3D find_first_zero_bit(map->agg_idx_bmap, + bp->max_tpa_roundup_size); + if (idx >=3D bp->max_tpa_roundup_size) return INVALID_HW_RING_ID; } __set_bit(idx, map->agg_idx_bmap); @@ -1586,7 +1588,7 @@ static void bnxt_tpa_start(struct bnxt *bp, struct bn= xt_rx_ring_info *rxr, =20 if (bp->flags & BNXT_FLAG_CHIP_P5_PLUS) { agg_id =3D TPA_START_AGG_ID_P5(tpa_start); - agg_id =3D bnxt_alloc_agg_idx(rxr, agg_id); + agg_id =3D bnxt_alloc_agg_idx(bp, rxr, agg_id); if (unlikely(agg_id =3D=3D INVALID_HW_RING_ID)) { netdev_warn(bp->dev, "Unable to allocate agg ID for ring %d, agg 0x%x\n= ", rxr->bnapi->index, @@ -3584,7 +3586,7 @@ static void bnxt_free_one_tpa_info_data(struct bnxt *= bp, { int i; =20 - for (i =3D 0; i < bp->max_tpa; i++) { + for (i =3D 0; i < bp->max_tpa_roundup_size; i++) { struct bnxt_tpa_info *tpa_info =3D &rxr->rx_tpa[i]; u8 *data =3D tpa_info->data; =20 @@ -3781,7 +3783,7 @@ static void bnxt_free_one_tpa_info(struct bnxt *bp, kfree(rxr->rx_tpa_idx_map); rxr->rx_tpa_idx_map =3D NULL; if (rxr->rx_tpa) { - for (i =3D 0; i < bp->max_tpa; i++) { + for (i =3D 0; i < bp->max_tpa_roundup_size; i++) { kfree(rxr->rx_tpa[i].agg_arr); rxr->rx_tpa[i].agg_arr =3D NULL; } @@ -3807,13 +3809,14 @@ static int bnxt_alloc_one_tpa_info(struct bnxt *bp, struct rx_agg_cmp *agg; int i; =20 - rxr->rx_tpa =3D kzalloc_objs(struct bnxt_tpa_info, bp->max_tpa); + rxr->rx_tpa =3D kzalloc_objs(struct bnxt_tpa_info, + bp->max_tpa_roundup_size); if (!rxr->rx_tpa) return -ENOMEM; =20 if (!(bp->flags & BNXT_FLAG_CHIP_P5_PLUS)) return 0; - for (i =3D 0; i < bp->max_tpa; i++) { + for (i =3D 0; i < bp->max_tpa_roundup_size; i++) { agg =3D kzalloc_objs(*agg, MAX_SKB_FRAGS); if (!agg) return -ENOMEM; @@ -3832,6 +3835,9 @@ static int bnxt_alloc_tpa_info(struct bnxt *bp) =20 bp->max_tpa =3D MAX_TPA; if (bp->flags & BNXT_FLAG_CHIP_P5_PLUS) { + /* TPA is not supported at all, so there is nothing to + * allocate. + */ if (!bp->max_tpa_v2) return 0; bp->max_tpa =3D min_t(u16, bp->max_tpa_v2, MAX_TPA_P5); @@ -3839,6 +3845,7 @@ static int bnxt_alloc_tpa_info(struct bnxt *bp) if (bp->max_tpa <=3D 32 && BNXT_CHIP_P5(bp) && !BNXT_NPAR(bp)) bp->max_tpa =3D MAX_TPA_P5; } + bp->max_tpa_roundup_size =3D roundup_pow_of_two(bp->max_tpa); =20 for (i =3D 0; i < bp->rx_nr_rings; i++) { struct bnxt_rx_ring_info *rxr =3D &bp->rx_ring[i]; @@ -4551,7 +4558,7 @@ static int bnxt_alloc_one_tpa_info_data(struct bnxt *= bp, u8 *data; int i; =20 - for (i =3D 0; i < bp->max_tpa; i++) { + for (i =3D 0; i < bp->max_tpa_roundup_size; i++) { data =3D __bnxt_alloc_rx_frag(bp, &mapping, rxr, GFP_KERNEL); if (!data) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt.h b/drivers/net/ethern= et/broadcom/bnxt/bnxt.h index ab894f8addef..de46b42d7c98 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt.h +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt.h @@ -789,7 +789,6 @@ struct nqe_cn { =20 #define MAX_TPA 64 #define MAX_TPA_P5 256 -#define MAX_TPA_P5_MASK (MAX_TPA_P5 - 1) #define MAX_TPA_SEGS_P5 0x3f =20 #if (BNXT_PAGE_SHIFT =3D=3D 16) @@ -2380,6 +2379,7 @@ struct bnxt { =20 u16 max_tpa_v2; u16 max_tpa; + u16 max_tpa_roundup_size; u32 rx_buf_size; u32 rx_buf_use_size; /* useable size */ u16 rx_offset; --=20 2.53.0-Meta