Re: [PATCH net v2 6/6] net: bcmasp: fix network filter lookup and wake filter pair allocation
From: Nicolai Buchwitz
Date: Fri Oct 09 2026 - 04:55:24 EST
Hi Florian
On 8.10.2026 23:06, Florian Fainelli wrote:
In bcmasp_netfilt_get_init(), when looking up an existing filter (!init)
for a specified location, if the filter at loc was not claimed, the
previous loop continued searching higher indices and could return an
arbitrary unrelated filter belonging to the port. This caused flow get or
delete operations on an empty rule location to return or delete an
unintended filter.
Fix this by checking only the requested location on lookup and rejecting
RX_CLS_LOC_ANY when !init. In addition, harden wake filter allocation
and release by ensuring wake filter pair searches stay on even boundaries
where both entries are free, checking that loc + 1 is free for positioned
wake filters, and validating parity and bounds on release.
Fixes: c5d511c49587 ("net: bcmasp: Add support for wake on net filters")
Assisted-by: LLM
Signed-off-by: Florian Fainelli <florian.fainelli@xxxxxxxxxxxx>
---
drivers/net/ethernet/broadcom/asp2/bcmasp.c | 121 +++++++++++---------
1 file changed, 70 insertions(+), 51 deletions(-)
diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp.c b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
index 972474893a6b..b6a201982080 100644
--- a/drivers/net/ethernet/broadcom/asp2/bcmasp.c
+++ b/drivers/net/ethernet/broadcom/asp2/bcmasp.c
@@ -511,6 +511,13 @@ static int bcmasp_netfilt_wr_to_hw(struct bcmasp_priv *priv,
return 0;
}
+static inline bool bcmasp_netfilt_is_companion(struct bcmasp_priv *priv, int i)
nit: Does it need to be inline? Usually the compiler takes care of this automatically.
+{
+ return i > 0 && (i % 2) &&
+ priv->net_filters[i].wake_filter &&
+ priv->net_filters[i - 1].wake_filter;
+}
[...]
Reviewed-by: Nicolai Buchwitz <nb@xxxxxxxxxxx>
Thanks,
Nicolai