|WARNING| [v1,1/1] net/iavf: fix resource leak on IPsec init fail

dpdklab at iol.unh.edu dpdklab at iol.unh.edu
Tue Sep 15 11:46:22 CEST 2026


Test-Label: ai-code-review
Test-Status: WARNING
https://dpdk.org/patch/169563

_AI Code Review_

=== Patch Review: series.patch (via Claude) ===
Review date: 2026-09-15

# DPDK Patch Review

## Summary

The patch fixes a resource leak in the iavf driver's `dev_init` function where flow engines are not cleaned up when IPsec security initialization fails. The fix is correct and addresses a real bug.

---

## Errors

None.

---

## Warnings

**Missing cleanup on new error path** (Warning)

The new `security_init_err` label calls `iavf_security_ctx_destroy(adapter)` followed by `iavf_flow_uninit(adapter)`, then falls through to `flow_init_err`. However, `flow_init_err` contains additional cleanup that is not shown in the patch context. If `flow_init_err` performs cleanup that should NOT be executed after `iavf_security_ctx_destroy()` and `iavf_flow_uninit()` have already run, the fall-through may be incorrect.

Please verify that falling through to `flow_init_err` after the security cleanup is the intended behavior, or add a `return ret;` after `iavf_flow_uninit(adapter)` if the subsequent cleanup in `flow_init_err` would duplicate or conflict with what was already done.

```c
security_init_err:
	iavf_security_ctx_destroy(adapter);
	iavf_flow_uninit(adapter);
	return ret;  /* If flow_init_err cleanup should not run */
```

---

## Info

**Correct fix for resource leak** (Info)

The patch correctly identifies that when `iavf_security_ctx_create()` or `iavf_security_init()` fails, the code was jumping to `flow_init_err` without cleaning up the security context created earlier. The addition of `iavf_flow_uninit(adapter)` at the `security_init_err` label ensures flow engines are properly uninitialized on this error path.

---

## Notes

1. The Fixes tag and Cc: stable tag are appropriate for a backportable bug fix
2. The change is minimal and focused on the specific issue
3. The patch description clearly explains the problem and the solution
4. No forbidden tokens, style violations, or deprecated API usage detected
5. No ABI changes or new API introduced


More information about the test-report mailing list