Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] netvsc: unconditional xdp_rxq_info_unreg() on uninitialized structs 
triggers WARN
--

commit 961e2b6c1ed96f0ba554ff4b714af09658ea0cc8
Author: Emerson Busson <[email protected]>

hv: netvsc: use kvzalloc for device state

This commit modifies alloc_net_device() to use kvzalloc_obj() instead of
kzalloc_obj() for allocating the netvsc_device. It updates the cleanup path
in __free_netvsc_device() to use kvfree() for releasing the memory, allowing
allocations to safely fall back to vmalloc.

> diff --git a/drivers/net/hyperv/netvsc.c b/drivers/net/hyperv/netvsc.c
> index 0d017f836b9eb..8ea7c993baac0 100644
> --- a/drivers/net/hyperv/netvsc.c
> +++ b/drivers/net/hyperv/netvsc.c
> @@ -140,8 +140,8 @@ static void __free_netvsc_device(struct netvsc_device 
> *nvdev)
>       for (i = 0; i < VRSS_CHANNEL_MAX; i++) {
>               xdp_rxq_info_unreg(&nvdev->chan_table[i].xdp_rxq);

[Severity: Medium]
Does this loop unconditionally call xdp_rxq_info_unreg() on uninitialized
structs during error cleanup, triggering a warning splat?

If channel setup fails after alloc_net_device() zero-initializes the device,
__free_netvsc_device() loops over all channels and calls xdp_rxq_info_unreg().

Because the uninitialized structs have a state of REG_STATE_NEW (0), passing
them to xdp_rxq_info_unreg() bypasses the registered state check and triggers
the following warning in xdp_rxq_info_unreg_mem_model() in net/core/xdp.c:

WARN(1, "Missing register, driver bug");

>               kfree(nvdev->chan_table[i].recv_buf);
>               vfree(nvdev->chan_table[i].mrc.slots);
>       }
>  
> -     kfree(nvdev);
> +     kvfree(nvdev);
>  }

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=14

Reply via email to