2023-03-16 10:30:12

by Daniil Tatianin

[permalink] [raw]
Subject: [PATCH v2] qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info

We have to make sure that the info returned by the helper is valid
before using it.

Found by Linux Verification Center (linuxtesting.org) with the SVACE
static analysis tool.

Fixes: f990c82c385b ("qed*: Add support for ndo_set_vf_trust")
Fixes: 733def6a04bf ("qed*: IOV link control")
Signed-off-by: Daniil Tatianin <[email protected]>
---
Changes since v1:
- Add a vf check to qed_iov_handle_trust_change as well
---
drivers/net/ethernet/qlogic/qed/qed_sriov.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/qlogic/qed/qed_sriov.c b/drivers/net/ethernet/qlogic/qed/qed_sriov.c
index 2bf18748581d..fa167b1aa019 100644
--- a/drivers/net/ethernet/qlogic/qed/qed_sriov.c
+++ b/drivers/net/ethernet/qlogic/qed/qed_sriov.c
@@ -4404,6 +4404,9 @@ qed_iov_configure_min_tx_rate(struct qed_dev *cdev, int vfid, u32 rate)
}

vf = qed_iov_get_vf_info(QED_LEADING_HWFN(cdev), (u16)vfid, true);
+ if (!vf)
+ return -EINVAL;
+
vport_id = vf->vport_id;

return qed_configure_vport_wfq(cdev, vport_id, rate);
@@ -5152,7 +5155,7 @@ static void qed_iov_handle_trust_change(struct qed_hwfn *hwfn)

/* Validate that the VF has a configured vport */
vf = qed_iov_get_vf_info(hwfn, i, true);
- if (!vf->vport_instance)
+ if (!vf || !vf->vport_instance)
continue;

memset(&params, 0, sizeof(params));
--
2.25.1



2023-03-16 10:48:34

by Michal Swiatkowski

[permalink] [raw]
Subject: Re: [PATCH v2] qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info

On Thu, Mar 16, 2023 at 01:29:21PM +0300, Daniil Tatianin wrote:
> We have to make sure that the info returned by the helper is valid
> before using it.
>
> Found by Linux Verification Center (linuxtesting.org) with the SVACE
> static analysis tool.
>
> Fixes: f990c82c385b ("qed*: Add support for ndo_set_vf_trust")
> Fixes: 733def6a04bf ("qed*: IOV link control")
> Signed-off-by: Daniil Tatianin <[email protected]>
> ---
> Changes since v1:
> - Add a vf check to qed_iov_handle_trust_change as well
> ---
> drivers/net/ethernet/qlogic/qed/qed_sriov.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/qlogic/qed/qed_sriov.c b/drivers/net/ethernet/qlogic/qed/qed_sriov.c
> index 2bf18748581d..fa167b1aa019 100644
> --- a/drivers/net/ethernet/qlogic/qed/qed_sriov.c
> +++ b/drivers/net/ethernet/qlogic/qed/qed_sriov.c
> @@ -4404,6 +4404,9 @@ qed_iov_configure_min_tx_rate(struct qed_dev *cdev, int vfid, u32 rate)
> }
>
> vf = qed_iov_get_vf_info(QED_LEADING_HWFN(cdev), (u16)vfid, true);
> + if (!vf)
> + return -EINVAL;
> +
> vport_id = vf->vport_id;
>
> return qed_configure_vport_wfq(cdev, vport_id, rate);
> @@ -5152,7 +5155,7 @@ static void qed_iov_handle_trust_change(struct qed_hwfn *hwfn)
>
> /* Validate that the VF has a configured vport */
> vf = qed_iov_get_vf_info(hwfn, i, true);
> - if (!vf->vport_instance)
> + if (!vf || !vf->vport_instance)
> continue;
>
> memset(&params, 0, sizeof(params));
> --
> 2.25.1
>

Thanks,
Reviewed-by: Michal Swiatkowski <[email protected]>


2023-03-19 08:50:26

by patchwork-bot+netdevbpf

[permalink] [raw]
Subject: Re: [PATCH v2] qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info

Hello:

This patch was applied to netdev/net.git (main)
by David S. Miller <[email protected]>:

On Thu, 16 Mar 2023 13:29:21 +0300 you wrote:
> We have to make sure that the info returned by the helper is valid
> before using it.
>
> Found by Linux Verification Center (linuxtesting.org) with the SVACE
> static analysis tool.
>
> Fixes: f990c82c385b ("qed*: Add support for ndo_set_vf_trust")
> Fixes: 733def6a04bf ("qed*: IOV link control")
> Signed-off-by: Daniil Tatianin <[email protected]>
>
> [...]

Here is the summary with links:
- [v2] qed/qed_sriov: guard against NULL derefs from qed_iov_get_vf_info
https://git.kernel.org/netdev/net/c/25143b6a01d0

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html