Re: [PATCH net v4] bnxt_en: Bound SW TPA IDs to prevent crashes
From: Paolo Abeni
Date: Thu Sep 03 2026 - 05:46:18 EST
Hi,
sorry for the latency here.
On 9/1/26 5:03 PM, Joe Damato wrote:
> On Tue, Sep 01, 2026 at 02:10:04PM +0200, Paolo Abeni wrote:
>> On 9/1/26 1:57 PM, Joe Damato wrote:
>>> On Tue, Sep 01, 2026 at 10:16:54AM +0200, Paolo Abeni wrote:
>>>> On 8/28/26 9:08 PM, Joe Damato wrote:
>>>>> - Moved bp->max_tpa_roundup_size init out of the early return path and
>>>>> documented that TPA is unsupported there, as suggested by Michael.
>>>>
>>>> Clashiko quite convincingly elaborates that the above is not enough:
>>>>
>>>> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260828190900.1767611-1-joe%40dama.to
>>>>
>>>> Could you please have a look?
>> [...]
>>> 3.) "The new assignment sits after the max_tpa_v2 == 0 early return, so on a P5+
>>> device whose firmware reports max_aggs_supported == 0, does
>>> bp->max_tpa_roundup_size stay 0 while BNXT_FLAG_TPA is set? ..."
>>>
>>> Michael commented in the v3 that this is a false positive, hence why I changed
>>> the code from what it was in the v3 to this.
>>
>> This is the comment I referred to.
>>
>> AFAICS the problem is that the driver sets
>>
>> bp->dev->hw_features |= NETIF_F_LRO;
>>
>> regardless of the supported capabilities, and that seams to disagree
>> with Michael.
>
> OK, after re-reading this here's what I see: NETIF_F_LRO gets added with no
> capability check and bnxt_fix_features() won't strip it afterwards. I think
> the fix there is to add a BNXT_SUPPORTS_TPA() test, as a Fixes for
> f0aa6a37a3db ("eth: bnxt: always recalculate features after XDP clearing, fix
> null-deref").
>
> I can send a separate patch for that, but it is unrelated to this patch which
> fixes a crash on boot for Thor2 devices.
With my limited knowledge of this driver, I thought the report being
more strictly related to this patch, and the fix for them should land
together.
I'm fine with v5 approach.
/P