On Mon, Aug 24, 2026 at 01:18:10PM +0000, Loktionov, Aleksandr wrote:
> 
> 
> > -----Original Message-----
> > From: Simon Horman <[email protected]>

...

> Good day, Simon
> 
> The clamp math is off, for the record: pkt_buf is ICE_PARSER_MAX_PKT_LEN + 
> ICE_PARSER_PKT_REV = 536 bytes, so sizeof(rt->pkt_buf) - ICE_GPR_HV_SIZE is 
> 504, not 488.
> 
> That said, the actual point stands: ice_parser_rt_pktbuf_set() stores the 
> unclamped caller pkt_len into rt->pkt_len, and both raw RSS and raw FDIR VF 
> paths can pass up to VIRTCHNL_MAX_SIZE_RAW_PACKET (1024) > 
> ICE_PARSER_MAX_PKT_LEN (504). After this fix HO can't exceed 504 either, so 
> HO >= pkt_len stops being a reliable exit for those inputs. Doesn't look like 
> a guaranteed infinite loop to me - the graph's is_last_round action still 
> ends parsing independent of HO - but there's no reason to leave a dangling 
> bound in a bounds-fix patch. I'll send v2 that also stores the clamped length 
> in rt->pkt_len, same Fixes: tag.

Thanks, much appreciated.

> 
> The DDP-table-index and FDIR IRQ-context points from Sashiko are unrelated to 
> this patch - different code, different trust boundary (signed firmware 
> package vs. VF input). 
> I think it should not block this fix.

Yes, agreed.

Reply via email to