[PATCH] app/testpmd: fix segfault in flow rule parser

Mohammad Shuab Siddique mohammad-shuab.siddique at broadcom.com
Tue Jul 21 19:44:15 CEST 2026


From: Artin Davari <artin.davari at broadcom.com>

Replace temporary stack arrays in the flow rule parser with static
arrays in three parse functions - prefix spec, RSS type, and RSS
queue handling - to prevent invalid pointer access during parsing
of complex flow rules.

Fixes: c439a84f1a ("app/testpmd: fix build with MSVC on non-constant initializer")
Cc: stable at dpdk.org

Signed-off-by: Artin Davari <artin.davari at broadcom.com>
---
 app/test-pmd/cmdline_flow.c | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

diff --git a/app/test-pmd/cmdline_flow.c b/app/test-pmd/cmdline_flow.c
index fbbe36233b..661a05f59f 100644
--- a/app/test-pmd/cmdline_flow.c
+++ b/app/test-pmd/cmdline_flow.c
@@ -8859,6 +8859,7 @@ parse_vc_spec(struct context *ctx, const struct token *token,
 	      const char *str, unsigned int len,
 	      void *buf, unsigned int size)
 {
+	static const enum index next_prefix[] = { COMMON_PREFIX, ZERO };
 	struct buffer *out = buf;
 	struct rte_flow_item *item;
 	uint32_t data_size;
@@ -8885,7 +8886,7 @@ parse_vc_spec(struct context *ctx, const struct token *token,
 		/* Modify next token to expect a prefix. */
 		if (ctx->next_num < 2)
 			return -1;
-		ctx->next[ctx->next_num - 2] = NEXT_ENTRY(COMMON_PREFIX);
+		ctx->next[ctx->next_num - 2] = next_prefix;
 		/* Fall through. */
 	case ITEM_PARAM_MASK:
 		index = 2;
@@ -9327,6 +9328,7 @@ parse_vc_action_rss_type(struct context *ctx, const struct token *token,
 			  const char *str, unsigned int len,
 			  void *buf, unsigned int size)
 {
+	static const enum index next_rss_type[] = { ACTION_RSS_TYPE, ZERO };
 	struct action_rss_data *action_rss_data;
 	unsigned int i;
 
@@ -9352,7 +9354,7 @@ parse_vc_action_rss_type(struct context *ctx, const struct token *token,
 	/* Repeat token. */
 	if (ctx->next_num == RTE_DIM(ctx->next))
 		return -1;
-	ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_TYPE);
+	ctx->next[ctx->next_num++] = next_rss_type;
 	if (!ctx->object)
 		return len;
 	action_rss_data = ctx->object;
@@ -9370,6 +9372,7 @@ parse_vc_action_rss_queue(struct context *ctx, const struct token *token,
 			  const char *str, unsigned int len,
 			  void *buf, unsigned int size)
 {
+	static const enum index next_rss_queue[] = { ACTION_RSS_QUEUE, ZERO };
 	struct action_rss_data *action_rss_data;
 	const struct arg *arg;
 	int ret;
@@ -9402,7 +9405,7 @@ parse_vc_action_rss_queue(struct context *ctx, const struct token *token,
 	/* Repeat token. */
 	if (ctx->next_num == RTE_DIM(ctx->next))
 		return -1;
-	ctx->next[ctx->next_num++] = NEXT_ENTRY(ACTION_RSS_QUEUE);
+	ctx->next[ctx->next_num++] = next_rss_queue;
 end:
 	if (!ctx->object)
 		return len;
-- 
2.47.3



More information about the dev mailing list