| From 864ca0bf8c04953e746abdb8ac20b5c1efbbd45b Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 1 Nov 2019 14:00:17 +0000 |
| Subject: ice: fix potential infinite loop because loop counter being too small |
| |
| From: Colin Ian King <colin.king@canonical.com> |
| |
| [ Upstream commit 615457a226f042bffc3a1532afb244cab37460d4 ] |
| |
| Currently the for-loop counter i is a u8 however it is being checked |
| against a maximum value hw->num_tx_sched_layers which is a u16. Hence |
| there is a potential wrap-around of counter i back to zero if |
| hw->num_tx_sched_layers is greater than 255. Fix this by making i |
| a u16. |
| |
| Addresses-Coverity: ("Infinite loop") |
| Fixes: b36c598c999c ("ice: Updates to Tx scheduler code") |
| Signed-off-by: Colin Ian King <colin.king@canonical.com> |
| Tested-by: Andrew Bowers <andrewx.bowers@intel.com> |
| Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/net/ethernet/intel/ice/ice_sched.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/drivers/net/ethernet/intel/ice/ice_sched.c b/drivers/net/ethernet/intel/ice/ice_sched.c |
| index 2a232504379d2..602b0fd84c29e 100644 |
| --- a/drivers/net/ethernet/intel/ice/ice_sched.c |
| +++ b/drivers/net/ethernet/intel/ice/ice_sched.c |
| @@ -1052,7 +1052,7 @@ enum ice_status ice_sched_query_res_alloc(struct ice_hw *hw) |
| struct ice_aqc_query_txsched_res_resp *buf; |
| enum ice_status status = 0; |
| __le16 max_sibl; |
| - u8 i; |
| + u16 i; |
| |
| if (hw->layer_info) |
| return status; |
| -- |
| 2.20.1 |
| |