|SUCCESS| net/bnxt: fix memory corruption in tunnel entry list
dpdklab at iol.unh.edu
dpdklab at iol.unh.edu
Tue Oct 6 02:22:13 CEST 2026
Test-Label: ai-code-review
Test-Status: SUCCESS
https://dpdk.org/patch/170619
_AI Code Review_
=== Patch Review: series.patch (via Claude) ===
Review date: 2026-10-06
## DPDK Patch Review
### Summary
This patch fixes a memory corruption bug in the bnxt driver's tunnel entry list management. The fix correctly increments the reference count for the matching tunnel entry instead of an incorrect index.
---
## Errors
None.
---
## Warnings
None.
---
## Info
**Correctness Bug Fixed (Original Code)**
The original code increments `tun_ent_list[free_entry].ref_cnt` when a matching tunnel entry is found at index `i`. When all tunnel table entries have non-zero `ref_cnt` (table is full), `free_entry` ends up as -1, causing an out-of-bounds access to `tun_ent_list[-1]`. This is undefined behavior that corrupts memory before the array.
The patch correctly changes this to `tun_ent_list[i].ref_cnt++`, incrementing the reference count for the entry that was actually matched. This is the correct fix.
**Code Context Analysis**
Looking at the function structure:
- The function searches for a matching tunnel entry in `tun_ent_list`
- When a match is found at index `i`, it should increment the reference count of that entry
- `free_entry` tracks the first available slot (ref_cnt == 0), which is unrelated to the matched entry
- The bug manifests when the table is full (no free entries), making `free_entry` invalid
The fix is minimal, targeted, and correct for an LTS-eligible bug fix.
**No Additional Issues Found**
The patch itself introduces no new code quality, style, or correctness issues. It is a simple one-line fix that addresses the described bug.
---
## Recommendations
None. The patch is correct as written.
More information about the test-report
mailing list