[PATCH] net/bnxt: prevent overflow in alarm timeout calculation
Kishore Padmanabha
kishore.padmanabha at broadcom.com
Mon Sep 21 21:11:31 CEST 2026
This change is already added as part of
https://git.dpdk.org/next/dpdk-next-net-brcm/commit/?id=c2b39669f47956d015d490dfa6e405d4272c08d2
On Tue, Sep 15, 2026 at 4:55 AM Evgeny Sokolov <Evgeny.Sokolov at infotecs.ru>
wrote:
> From: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>
>
> The alarm timeout is calculated by multiplying wait_msec by
> US_PER_MS before passing the value to rte_eal_alarm_set().
>
> Since wait_msec is a uint32_t, the multiplication may overflow
> when performed using 32-bit arithmetic for large timeout values.
>
> Cast wait_msec to uint64_t to ensure the multiplication is
> performed in 64-bit arithmetic.
>
> Signed-off-by: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>
> Cc: stable at dpdk.org
> ---
> drivers/net/bnxt/bnxt_ethdev.c | 6 +++---
> 1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/net/bnxt/bnxt_ethdev.c
> b/drivers/net/bnxt/bnxt_ethdev.c
> index a2429561b9..16a65f9770 100644
> --- a/drivers/net/bnxt/bnxt_ethdev.c
> +++ b/drivers/net/bnxt/bnxt_ethdev.c
> @@ -4855,7 +4855,7 @@ static void bnxt_check_fw_health(void *arg)
>
> info->last_reset_counter = val;
>
> - rte_eal_alarm_set(US_PER_MS * info->driver_polling_freq,
> + rte_eal_alarm_set(US_PER_MS * (uint64_t)info->driver_polling_freq,
> bnxt_check_fw_health, (void *)bp);
>
> return;
> @@ -4877,7 +4877,7 @@ static void bnxt_check_fw_health(void *arg)
> else
> wait_msec = info->normal_func_wait_period;
>
> - rte_eal_alarm_set(US_PER_MS * wait_msec,
> + rte_eal_alarm_set(US_PER_MS * (uint64_t)wait_msec,
> bnxt_fw_reset_cb, (void *)bp);
> }
>
> @@ -4895,7 +4895,7 @@ void bnxt_schedule_fw_health_check(struct bnxt *bp)
>
> polling_freq = bp->recovery_info->driver_polling_freq;
>
> - rte_eal_alarm_set(US_PER_MS * polling_freq,
> + rte_eal_alarm_set(US_PER_MS * (uint64_t)polling_freq,
> bnxt_check_fw_health, (void *)bp);
> bp->flags |= BNXT_FLAG_FW_HEALTH_CHECK_SCHEDULED;
>
> --
> 2.30.2
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mails.dpdk.org/archives/stable/attachments/20260921/748da8ff/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5493 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://mails.dpdk.org/archives/stable/attachments/20260921/748da8ff/attachment.bin>
More information about the stable
mailing list