Re: [PATCH net v2] bnxt_en: Handle partially initialized auxiliary devices

From: Pavan Chebbi

Date: Sun Jul 12 2026 - 22:30:09 EST


On Sat, Jul 11, 2026 at 10:07 PM Ruoyu Wang <ruoyuw560@xxxxxxxxx> wrote:
>
> bnxt_aux_devices_init() calls auxiliary_device_init() before all fields
> used by bnxt_aux_dev_release() are initialized. After
> auxiliary_device_init() succeeds, later errors must unwind with
> auxiliary_device_uninit(), which invokes the release callback.
>
> The release callback assumes that aux_priv->id, aux_priv->edev,
> edev->net and edev->ulp_tbl are all populated. If allocation fails
> after auxiliary_device_init(), the release path can otherwise dereference
> or clear partially initialized state.
>
> Allocate and attach the bnxt_en_dev and ULP table before calling
> auxiliary_device_init(), so the release callback only sees a fully
> initialized auxiliary private object. If auxiliary_device_init() itself
> fails, free those allocations directly because device_initialize() has not
> run and the release callback will not be invoked.
>
> This issue was found by a static analysis checker and confirmed by manual
> source review.
>
> Fixes: 194fad5b2781 ("bnxt_en: Refactor bnxt_rdma_aux_device_init/uninit functions")
> Signed-off-by: Ruoyu Wang <ruoyuw560@xxxxxxxxx>
> ---
> v2:
> - Allocate edev and ulp before auxiliary_device_init(), as suggested by
> Pavan Chebbi.
> v1: https://lore.kernel.org/netdev/20260708143401.3167477-1-ruoyuw560@xxxxxxxxx/
>
> drivers/net/ethernet/broadcom/bnxt/bnxt_ulp.c | 39 ++++++++++---------
> 1 file changed, 20 insertions(+), 19 deletions(-)
>

Reviewed-by: Pavan Chebbi <pavan.chebbi@xxxxxxxxxxxx>
Thank you.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature