[PATCH net] net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
Chintan Vankar
c-vankar at ti.com
Sun Aug 9 13:27:08 PDT 2026
On 07/08/26 16:47, Siddharth Vadapalli wrote:
> On the packet reception path, the ID of the MAC Port on which the packet
> was received, is embedded in the RX DMA Descriptor's metadata. The ID is
> extracted using the helper function cppi5_desc_get_tags_ids() which fills
> in the 16-bit Source Tag into the 'port_id' variable. However, it is only
> the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,
> while the upper 8-bits are Hardware-Reserved and carry an arbitrary value.
> With the existing logic, sporadic kernel crash is observed due to the
> subsequent driver code accessing out-of-bound memory because of an invalid
> port_id.
>
> Hence, fix the port_id extraction logic to use only the lower 8-bits of the
> Source Tag as the MAC Port ID.
>
> Fixes: 93a76530316a ("net: ethernet: ti: introduce am65x/j721e gigabit eth subsystem driver")
> Signed-off-by: Siddharth Vadapalli <s-vadapalli at ti.com>
> ---
>
> Hello,
>
> This patch is based on commit
> f9a2394a2348 Merge tag 'mm-hotfixes-stable-2026-08-06-18-44' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
> of Mainline Linux.
>
> I have observed it in practice that the RESERVED field contains non-zero
> value (such as 0xFF on one instance) causing port_id to be set to an
> invalid value (such as 0xFF01 in that instance) resulting in the subsequent
> driver code accessing out-of-bound / incorrect memory and corrupting it and
> causing a kernel crash. To summarize, this patch is fixing a real issue and
> not a hypothetical one.
>
> Regards,
> Siddharth.
>
> drivers/net/ethernet/ti/am65-cpsw-nuss.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/net/ethernet/ti/am65-cpsw-nuss.c b/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> index 434a31080855..6330540979d7 100644
> --- a/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> +++ b/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> @@ -1310,6 +1310,8 @@ static int am65_cpsw_nuss_rx_packets(struct am65_cpsw_rx_flow *flow,
> k3_udma_glue_rx_cppi5_to_dma_addr(rx_chn->rx_chn, &buf_dma);
> pkt_len = cppi5_hdesc_get_pktlen(desc_rx);
> cppi5_desc_get_tags_ids(&desc_rx->hdr, &port_id, NULL);
> + /* Port ID is contained in the lower 8-bits of the 16-bit Source Tag */
> + port_id &= 0xFF;
> dev_dbg(dev, "%s rx port_id:%d\n", __func__, port_id);
> port = am65_common_get_port(common, port_id);
> ndev = port->ndev;
Reviewed-by: Chintan Vankar <c-vankar at ti.com>
Regards,
Chintan.
More information about the linux-arm-kernel
mailing list