|WARNING| net/bnxt: fix bit allocator out of bounds read
dpdklab at iol.unh.edu
dpdklab at iol.unh.edu
Tue Oct 6 00:53:20 CEST 2026
Test-Label: ai-code-review
Test-Status: WARNING
https://dpdk.org/patch/170611
_AI Code Review_
=== Patch Review: series.patch (via Claude) ===
Review date: 2026-10-05
# DPDK Patch Review
## PATCH: net/bnxt: fix bit allocator out of bounds read
---
## Summary
This patch fixes an out-of-bounds array read in the bnxt driver's bit allocator. The original do-while loop could increment the index past the array bounds before checking the condition. The refactored while loop checks the bound before indexing.
---
## Errors
None identified.
---
## Warnings
None identified.
---
## Info
### 1. Logic Correctness
**Good:** The refactored loop correctly eliminates the out-of-bounds read:
- Original code: reads `blist->bdata[idx++]` then checks `idx <= bsize_64`, allowing read at index `bsize_64`
- Fixed code: checks `idx < bsize_64` before reading `blist->bdata[idx]`
The index calculation is also corrected:
- Original: `*index = ((idx - 1) * ULP_INDEX_BITMAP_SIZE) + jdx` (compensating for post-increment)
- Fixed: `*index = (idx * ULP_INDEX_BITMAP_SIZE) + jdx` (clearer logic)
### 2. Early Exit Optimization
The refactored loop correctly handles both the search and allocation in one pass. When `bentry != -1UL` (a slot with available bits is found), it immediately allocates and returns. The post-loop error path is only reached when all entries are `-1UL` (fully allocated).
### 3. Off-by-One Check
The original condition used `<=` where the correct bound is `<`. The array is indexed `0` to `bsize_64 - 1`, so `idx < bsize_64` is correct. The patch fixes this.
---
## Conclusion
**This patch is correct and ready for merge.**
The refactoring properly eliminates the out-of-bounds read vulnerability while maintaining equivalent functional behavior. The loop logic is clearer and the index arithmetic is simplified.
More information about the test-report
mailing list