Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:

Pre-existing issues:
- [High] Failure to restore `apc->bpf_prog` on error path causes Use-After-Free.
--

commit 26086af444af1d715f516a007146a7dd00ce97c6
Author: Muhammad Falak R Wani <[email protected]>

net: mana: remove unreachable dead code in mana_bpf()

This commit cleans up mana_bpf() by removing an unreachable return statement
after a switch statement that already unconditionally returns.

Link: https://lore.kernel.org/netdev/[email protected]/

> diff --git a/drivers/net/ethernet/microsoft/mana/mana_bpf.c 
> b/drivers/net/ethernet/microsoft/mana/mana_bpf.c
> index 53308e139cbe9..70bb8c9dc3413 100644
> --- a/drivers/net/ethernet/microsoft/mana/mana_bpf.c
> +++ b/drivers/net/ethernet/microsoft/mana/mana_bpf.c
[ ... ]

This is a pre-existing issue, but while reviewing this patch I noticed a
potential problem in the adjacent mana_xdp_set() function when it handles
allocation failures:

drivers/net/ethernet/microsoft/mana/mana_bpf.c:mana_xdp_set() {
        ...
        apc->bpf_prog = prog;

        if (apc->port_is_up) {
                ...
                err = mana_pre_alloc_rxbufs(apc, ndev->mtu, apc->num_queues);
                if (err) {
                        NL_SET_ERR_MSG_MOD(extack,
                                           "XDP: Insufficient memory for tx/rx 
re-config");
                        return err;
                }
        ...
}

[Severity: High]
Does this error path leave a dangling pointer in apc->bpf_prog?

It appears that if mana_pre_alloc_rxbufs() fails, the function returns
immediately without restoring apc->bpf_prog = old_prog. The generic XDP caller
will see the failure, assume the driver rejected the program, and drop its BPF
program reference.

Could this leave a freed pointer in apc->bpf_prog that might be dereferenced
when the interface is later restarted or accessed?

> @@ -253,7 +253,6 @@ static int mana_xdp_set(struct net_device *ndev, struct 
> bpf_prog *prog,
>  int mana_bpf(struct net_device *ndev, struct netdev_bpf *bpf)
>  {
>       struct netlink_ext_ack *extack = bpf->extack;
> -     int ret;
>  
>       switch (bpf->command) {
>       case XDP_SETUP_PROG:
[ ... ]

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/3d8b67307df6fefdc18743274cef3de4fca0e7de.1788339612.git.falakre...@gmail.com?part=1

Reply via email to