|SUCCESS| net/bnxt: fix memory corruption in tunnel entry list

dpdklab at iol.unh.edu dpdklab at iol.unh.edu
Tue Oct 6 02:22:13 CEST 2026


Test-Label: ai-code-review
Test-Status: SUCCESS
https://dpdk.org/patch/170619

_AI Code Review_

=== Patch Review: series.patch (via Claude) ===
Review date: 2026-10-06

## DPDK Patch Review

### Summary
This patch fixes a memory corruption bug in the bnxt driver's tunnel entry list management. The fix correctly increments the reference count for the matching tunnel entry instead of an incorrect index.

---

## Errors

None.

---

## Warnings

None.

---

## Info

**Correctness Bug Fixed (Original Code)**

The original code increments `tun_ent_list[free_entry].ref_cnt` when a matching tunnel entry is found at index `i`. When all tunnel table entries have non-zero `ref_cnt` (table is full), `free_entry` ends up as -1, causing an out-of-bounds access to `tun_ent_list[-1]`. This is undefined behavior that corrupts memory before the array.

The patch correctly changes this to `tun_ent_list[i].ref_cnt++`, incrementing the reference count for the entry that was actually matched. This is the correct fix.

**Code Context Analysis**

Looking at the function structure:
- The function searches for a matching tunnel entry in `tun_ent_list`
- When a match is found at index `i`, it should increment the reference count of that entry
- `free_entry` tracks the first available slot (ref_cnt == 0), which is unrelated to the matched entry
- The bug manifests when the table is full (no free entries), making `free_entry` invalid

The fix is minimal, targeted, and correct for an LTS-eligible bug fix.

**No Additional Issues Found**

The patch itself introduces no new code quality, style, or correctness issues. It is a simple one-line fix that addresses the described bug.

---

## Recommendations

None. The patch is correct as written.


More information about the test-report mailing list