[PATCH v3 4/5] net/bnxt: fix bounds in MAC address pool index

Mohammad Shuab Siddique mohammad-shuab.siddique at broadcom.com
Tue Sep 29 02:24:41 CEST 2026


From: Chenna Arnoori <chenna.arnoori at broadcom.com>

bnxt_mac_addr_add_op() indexed bp->vnic_info[pool] with a
caller-supplied pool before validating it against bp->max_vnics, and
before checking bp->vnic_info was even allocated yet (it is NULL
until the port is started). The existing "if (!vnic)" check was
always false, since vnic held the address of an array element and
is never NULL. bp->max_vnics is known from probe onward, so the pool
bound is checked first and unconditionally; the dev_started and
vnic_info checks, which gate whether there is anything to index yet,
follow it.

Fixes: 51fafb89a9a0 ("net/bnxt: get rid of ff pools and use VNIC info array")
Cc: stable at dpdk.org

Signed-off-by: Chenna Arnoori <chenna.arnoori at broadcom.com>
Signed-off-by: Mohammad Shuab Siddique <mohammad-shuab.siddique at broadcom.com>
---
v3:
* Retitled from "fix bounds in MAC pool index and flow parsing" and
  dropped the flow-parsing half entirely (the bounded VOID-item skip
  in bnxt_flow_non_void_item()/bnxt_flow_non_void_action()) --
  Stephen Hemminger pointed out rte_flow patterns/actions are always
  END-terminated by API contract, so that bound did not guard a
  reachable path; reverted to the original unbounded skip loop
  rather than keep unnecessary defensive code. Dropped the
  corresponding Fixes: 5c1171c97216 tag.
* Reordered the remaining MAC-pool fix so the pool-vs-max_vnics bound
  check runs before the dev_started/vnic_info checks, not after --
  also per Stephen Hemminger.

 drivers/net/bnxt/bnxt_ethdev.c | 11 ++++++++---
 drivers/net/bnxt/bnxt_flow.c   |  1 +
 2 files changed, 9 insertions(+), 3 deletions(-)

diff --git a/drivers/net/bnxt/bnxt_ethdev.c b/drivers/net/bnxt/bnxt_ethdev.c
index 11e8f7908d..20084826d3 100644
--- a/drivers/net/bnxt/bnxt_ethdev.c
+++ b/drivers/net/bnxt/bnxt_ethdev.c
@@ -2105,7 +2105,7 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 				uint32_t index, uint32_t pool)
 {
 	struct bnxt *bp = eth_dev->data->dev_private;
-	struct bnxt_vnic_info *vnic = &bp->vnic_info[pool];
+	struct bnxt_vnic_info *vnic;
 	int rc = 0;
 
 	rc = is_bnxt_in_error(bp);
@@ -2117,8 +2117,8 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 		return -ENOTSUP;
 	}
 
-	if (!vnic) {
-		PMD_DRV_LOG_LINE(ERR, "VNIC not found for pool %d!", pool);
+	if (pool >= bp->max_vnics) {
+		PMD_DRV_LOG_LINE(ERR, "Pool %u exceeds VNIC count %u!", pool, bp->max_vnics);
 		return -EINVAL;
 	}
 
@@ -2126,6 +2126,11 @@ static int bnxt_mac_addr_add_op(struct rte_eth_dev *eth_dev,
 	if (!eth_dev->data->dev_started)
 		return 0;
 
+	if (bp->vnic_info == NULL)
+		return 0;
+
+	vnic = &bp->vnic_info[pool];
+
 	rc = bnxt_add_mac_filter(bp, vnic, mac_addr, index, pool);
 
 	return rc;
diff --git a/drivers/net/bnxt/bnxt_flow.c b/drivers/net/bnxt/bnxt_flow.c
index 4bf38043b5..7b27d62697 100644
--- a/drivers/net/bnxt/bnxt_flow.c
+++ b/drivers/net/bnxt/bnxt_flow.c
@@ -1697,6 +1697,7 @@ bnxt_validate_and_parse_flow(struct rte_eth_dev *dev,
 	while (act->type != RTE_FLOW_ACTION_TYPE_END)
 		goto start;
 
+
 	return rc;
 ret:
 
-- 
2.47.3



More information about the stable mailing list