From: Michal Kubiak <[email protected]>

Due to some kernel bugs the Tx timeout event may be false-positive.
For example, the kernel commit 95ecba62e2fd ("net: fix races in
netdev_tx_sent_queue()/dev_watchdog()") fixes race conditions that can
also occur during the ice driver initialization.

In case of such false-positive Tx timeouts there can be no real Tx
transaction started, so the SKB pointer can be NULL. Therefore, the call
devlink_fmsg_dump_skb() can crash because of NULL-ptr dereference.

Fix that by checking the SKB pointer before dereferencing it.

Fixes: 2a82874a3b7b ("ice: add Tx hang devlink health reporter")
Cc: [email protected]
Signed-off-by: Michal Kubiak <[email protected]>
Signed-off-by: Aleksandr Loktionov <[email protected]>
---

 drivers/net/ethernet/intel/ice/devlink/health.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/ice/devlink/health.c 
b/drivers/net/ethernet/intel/ice/devlink/health.c
index 8e9a8a8..4275329 100644
--- a/drivers/net/ethernet/intel/ice/devlink/health.c
+++ b/drivers/net/ethernet/intel/ice/devlink/health.c
@@ -409,7 +409,8 @@ static int ice_tx_hang_reporter_dump(struct 
devlink_health_reporter *reporter,
        ice_fmsg_put_ptr(fmsg, "skb-ptr", skb);
        devlink_fmsg_binary_pair_put(fmsg, "desc", event->tx_ring->desc,
                                     event->tx_ring->count * sizeof(struct 
ice_tx_desc));
-       devlink_fmsg_dump_skb(fmsg, skb);
+       if (skb)
+               devlink_fmsg_dump_skb(fmsg, skb);
        devlink_fmsg_obj_nest_end(fmsg);
 
        return 0;
-- 
2.52.0

Reply via email to