From: Jun Yang <[email protected]>

Two bugs fixed in the QDMA dequeue path:

1. Array-bounds warning: qdma_cntx_idx_ring_eq advanced the ring tail
   one element at a time in a loop, which triggered a GCC -Warray-bounds
   diagnostic because the compiler could not prove the tail stayed in
   bounds. Replace the loop with a two-part memcpy (head region plus
   wrap-around region when needed) and advance ring->tail by the full
   count in one step, eliminating the warning.

2. SG FD double-put: in dpaa2_qdma_dq_fd() the fle_sdd pointer was
   stored into fle_elem[] and the counter incremented before checking
   the qdma_cntx_idx_ring_eq return value. On -ENOSPC the function
   returned without putting fle_sdd back to fle_pool, causing a double-
   free when the pool was later destroyed. Fix by calling
   rte_mempool_put() before returning -ENOSPC, and moving the
   fle_elem[]/counter update to after ring_eq succeeds.
Fixes: 388e888dc082 ("dma/dpaa2: support short FD")
Cc: [email protected]
Cc: [email protected]
Signed-off-by: Jun Yang <[email protected]>
---
 drivers/dma/dpaa2/dpaa2_qdma.c | 23 ++++++++++++++---------
 1 file changed, 14 insertions(+), 9 deletions(-)

diff --git a/drivers/dma/dpaa2/dpaa2_qdma.c b/drivers/dma/dpaa2/dpaa2_qdma.c
index f7d94bb799..3b272f6593 100644
--- a/drivers/dma/dpaa2/dpaa2_qdma.c
+++ b/drivers/dma/dpaa2/dpaa2_qdma.c
@@ -66,16 +66,19 @@ qdma_cntx_idx_ring_eq(struct qdma_cntx_idx_ring *ring,
        const uint16_t *elem, uint16_t nb,
        uint16_t *free_space)
 {
-       uint16_t i;
+       uint16_t first;
 
        if (unlikely(nb > ring->free_space))
                return 0;
 
-       for (i = 0; i < nb; i++) {
-               ring->cntx_idx_ring[ring->tail] = elem[i];
-               ring->tail = (ring->tail + 1) &
-                       (DPAA2_QDMA_MAX_DESC - 1);
-       }
+       first = RTE_MIN(nb, (uint16_t)(DPAA2_QDMA_MAX_DESC - ring->tail));
+       memcpy(&ring->cntx_idx_ring[ring->tail], elem,
+               first * sizeof(uint16_t));
+       if (nb > first)
+               memcpy(&ring->cntx_idx_ring[0], &elem[first],
+                       (nb - first) * sizeof(uint16_t));
+
+       ring->tail = (ring->tail + nb) & (DPAA2_QDMA_MAX_DESC - 1);
        ring->free_space -= nb;
        ring->nb_in_ring += nb;
 
@@ -962,15 +965,17 @@ dpaa2_qdma_dq_fd(const struct qbman_fd *fd,
        }
        if (type == DPAA2_QDMA_FD_SG) {
                fle_sdd = (void *)(uintptr_t)DPAA2_GET_FD_FLC(fd);
-               qdma_vq->fle_elem[*fle_elem_nb] = fle_sdd;
-               (*fle_elem_nb)++;
                cntx_sg = container_of(fle_sdd,
                                struct qdma_cntx_sg, fle_sdd);
                ret = qdma_cntx_idx_ring_eq(qdma_vq->ring_cntx_idx,
                                cntx_sg->cntx_idx,
                                cntx_sg->job_nb, free_space);
-               if (unlikely(ret < cntx_sg->job_nb))
+               if (unlikely(ret < cntx_sg->job_nb)) {
+                       rte_mempool_put(qdma_vq->fle_pool, fle_sdd);
                        return -ENOSPC;
+               }
+               qdma_vq->fle_elem[*fle_elem_nb] = fle_sdd;
+               (*fle_elem_nb)++;
 
                return 0;
        }

Reply via email to