|SUCCESS| net/bnxt: fix memory corruption in tunnel entry list

dpdklab at iol.unh.edu dpdklab at iol.unh.edu
Tue Oct 6 02:55:36 CEST 2026


Test-Label: ai-code-review
Test-Status: SUCCESS
https://dpdk.org/patch/170619

_AI Code Review_

=== Patch Review: series.patch (via Claude) ===
Review date: 2026-10-06

# DPDK Patch Review

## Patch: net/bnxt: fix memory corruption in tunnel entry list

---

## Summary

This patch fixes an index bug where `free_entry` is used instead of the loop index `i` when incrementing a reference counter. The fix is correct.

---

## Errors

None.

---

## Warnings

None.

---

## Info

None.

---

## Analysis

### Correctness
The patch addresses a real bug. The code increments the reference count of the wrong tunnel entry when a matching entry is found. The fix is straightforward and correct:

**Before**: `tun_ent_list[free_entry].ref_cnt++` (wrong index)  
**After**: `tun_ent_list[i].ref_cnt++` (correct index)

When the tunnel table is full, all entries have non-zero `ref_cnt`, so `free_entry` remains at its initial value of -1. Using `free_entry` as an array index in this state produces undefined behavior (negative array index).

### Code Style
- The patch follows DPDK coding conventions
- The change is minimal and focused on the fix
- No style violations introduced

### Process Compliance
- Properly tagged with `Fixes:` and the original commit
- Includes `Cc: stable at dpdk.org` for backporting
- Commit message clearly describes the problem and the fix

---

## Conclusion

This is a good bugfix patch. The correctness issue is real and the fix is appropriate. No further changes needed.


More information about the test-report mailing list