]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
nfp: Check resource mutex allocation
authorRuoyu Wang <ruoyuw560@gmail.com>
Wed, 8 Jul 2026 14:34:08 +0000 (22:34 +0800)
committerPaolo Abeni <pabeni@redhat.com>
Tue, 21 Jul 2026 11:06:40 +0000 (13:06 +0200)
nfp_cpp_resource_find() allocates a CPP mutex handle for the matching
resource-table entry and then reports success.  nfp_resource_try_acquire()
immediately passes that handle to nfp_cpp_mutex_trylock().

However, nfp_cpp_mutex_alloc() returns NULL on failure.  If that happens
for a matching table entry, the resource lookup still returns success and
the following trylock dereferences a NULL mutex pointer while opening the
resource.

nfp_resource_acquire() already treats failure to allocate the table mutex
as -ENOMEM.  Do the same for the resource mutex and fail the lookup before
publishing the rest of the resource handle.

This issue was found by a static analysis checker and confirmed by
manual source review.

Fixes: f01a2161577d ("nfp: add support for resources")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260708143408.3168425-1-ruoyuw560@gmail.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
drivers/net/ethernet/netronome/nfp/nfpcore/nfp_resource.c

index 6d5833479d123f5397b945c7fbdd875d2a8aaccd..237300b82b91326f380ef724f6fe8cb7a1dcae04 100644 (file)
@@ -96,6 +96,9 @@ static int nfp_cpp_resource_find(struct nfp_cpp *cpp, struct nfp_resource *res)
                res->mutex =
                        nfp_cpp_mutex_alloc(cpp,
                                            NFP_RESOURCE_TBL_TARGET, addr, key);
+               if (!res->mutex)
+                       return -ENOMEM;
+
                res->cpp_id = NFP_CPP_ID(entry.region.cpp_target,
                                         entry.region.cpp_action,
                                         entry.region.cpp_token);