[PATCH 1/1] drivers: fix CN20K mbuf size truncation

Morten Brørup mb at smartsharesystems.com
Wed Sep 9 20:18:02 CEST 2026


There where there already.

The patch only changes the size of some local variables.

 

Venlig hilsen / Kind regards,

-Morten Brørup

 

From: Stephen Hemminger [mailto:stephen at networkplumber.org] 
Sent: Wednesday, 9 September 2026 19.16
To: Randy L Tice
Cc: dev; stable; Thomas Monjalon; Pavan Nikhilesh; Shijith Thotton; Nithin Dabilpuram; Kiran Kumar K; Sunil Kumar Kori; Satha Rao; Harman Kalra; rbhansali at marvell.com
Subject: Re: [PATCH 1/1] drivers: fix CN20K mbuf size truncation

 

stop "cargo culting" use of always inline attribute. that attribute should only be used in special cases where code breaks compilation without it. it is not a go faster flag

 

On Wed, Sep 9, 2026, 09:06 Randy L Tice <rtice at cisco.com> wrote:

	CN20K inline security receive paths recover the packet mbuf by
	subtracting sizeof(struct rte_mbuf) from a pointer stored in
	completion metadata.
	
	The size is currently kept in a uint8_t local variable before
	that subtraction. This truncates the value when the mbuf structure
	grows beyond 255 bytes, and can recover the wrong mbuf address.
	
	Use a uint32_t local value for the mbuf byte size so larger mbuf
	layouts are handled correctly.
	
	Fixes: 5856f23129bb ("net/cnxk: support CN20K inline IPsec Rx")
	Fixes: edd0d5f3c299 ("event/cnxk: support CN20K inline IPsec Rx")
	Cc: stable at dpdk.org
	
	Signed-off-by: Randy L Tice <rtice at cisco.com>
	---
	 .mailmap                          | 1 +
	 drivers/event/cnxk/cn20k_worker.h | 4 ++--
	 drivers/net/cnxk/cn20k_rx.h       | 4 ++--
	 3 files changed, 5 insertions(+), 4 deletions(-)
	
	diff --git a/.mailmap b/.mailmap
	index fcb3d1bb3f..2a8b54ea23 100644
	--- a/.mailmap
	+++ b/.mailmap
	@@ -1379,6 +1379,7 @@ Rakesh Kudurumalla <rkudurumalla at marvell.com> <rkudurumalla at caviumnetworks.com>
	 Ralf Hoffmann <ralf.hoffmann at allegro-packets.com>
	 Rami Rosen <ramirose at gmail.com> <rami.rosen at intel.com>
	 Rami Rosen <ramirose at gmail.com> <roszenrami at gmail.com>
	+Randy L Tice <rtice at cisco.com>
	 Randy Schacher <stuart.schacher at broadcom.com>
	 Rani Sharoni <ranish at nvidia.com>
	 Ranjit Menon <ranjit.menon at intel.com>
	diff --git a/drivers/event/cnxk/cn20k_worker.h b/drivers/event/cnxk/cn20k_worker.h
	index 6442113e09..5723a6eabb 100644
	--- a/drivers/event/cnxk/cn20k_worker.h
	+++ b/drivers/event/cnxk/cn20k_worker.h
	@@ -48,7 +48,7 @@ cn20k_process_vwqe(uintptr_t vwqe, uint16_t port_id, const uint32_t flags, struc
	 {
	        uint64_t mbuf_init = 0x100010000ULL | RTE_PKTMBUF_HEADROOM;
	        struct cnxk_timesync_info *tstamp = ws->tstamp[port_id];
	-       uint8_t m_sz = sizeof(struct rte_mbuf);
	+       const uint32_t m_sz = sizeof(struct rte_mbuf);
	        void *lookup_mem = ws->lookup_mem;
	        uint64_t meta_aura = 0, laddr = 0;
	        uintptr_t lbase = ws->lmt_base;
	@@ -165,7 +165,7 @@ cn20k_process_vwqe(uintptr_t vwqe, uint16_t port_id, const uint32_t flags, struc
	 static __rte_always_inline void
	 cn20k_sso_hws_post_process(struct cn20k_sso_hws *ws, uint64_t *u64, const uint32_t flags)
	 {
	-       uint8_t m_sz = sizeof(struct rte_mbuf);
	+       const uint32_t m_sz = sizeof(struct rte_mbuf);
	        uintptr_t sa_base = 0;
	
	        u64[0] = (u64[0] & (0x3ull << 32)) << 6 | (u64[0] & (0x3FFull << 36)) << 4 |
	diff --git a/drivers/net/cnxk/cn20k_rx.h b/drivers/net/cnxk/cn20k_rx.h
	index f8fa6de2b9..b544868c03 100644
	--- a/drivers/net/cnxk/cn20k_rx.h
	+++ b/drivers/net/cnxk/cn20k_rx.h
	@@ -702,7 +702,7 @@ cn20k_nix_recv_pkts(void *rx_queue, struct rte_mbuf **rx_pkts, uint16_t pkts, co
	        uint64_t mbuf_init = rxq->mbuf_initializer;
	        const void *lookup_mem = rxq->lookup_mem;
	        const uint64_t data_off = rxq->data_off;
	-       uint8_t m_sz = sizeof(struct rte_mbuf);
	+       const uint32_t m_sz = sizeof(struct rte_mbuf);
	        const uint64_t wdata = rxq->wdata;
	        const uint32_t qmask = rxq->qmask;
	        const uintptr_t desc = rxq->desc;
	@@ -815,7 +815,7 @@ cn20k_nix_flush_recv_pkts(void *rx_queue, struct rte_mbuf **rx_pkts, uint16_t pk
	        uint64_t mbuf_init = rxq->mbuf_initializer;
	        const void *lookup_mem = rxq->lookup_mem;
	        const uint64_t data_off = rxq->data_off;
	-       uint8_t m_sz = sizeof(struct rte_mbuf);
	+       const uint32_t m_sz = sizeof(struct rte_mbuf);
	        const uint64_t wdata = rxq->wdata;
	        const uint32_t qmask = rxq->qmask;
	        const uintptr_t desc = rxq->desc;
	-- 
	2.35.6

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mails.dpdk.org/archives/stable/attachments/20260909/8baca8b5/attachment.htm>


More information about the stable mailing list