git: 5aa5bfd3f99c - main - fixup! mlx5ib: Add drop flow steering rule support

From: Konstantin Belousov <kib_at_FreeBSD.org>
Date: Wed, 16 Sep 2026 14:12:46 UTC
The branch main has been updated by kib:

URL: https://cgit.FreeBSD.org/src/commit/?id=5aa5bfd3f99cde0da68c27da3e3be8506c829efe

commit 5aa5bfd3f99cde0da68c27da3e3be8506c829efe
Author:     Ariel Ehrenberg <aehrenberg@nvidia.com>
AuthorDate: 2026-07-28 12:02:39 +0000
Commit:     Konstantin Belousov <kib@FreeBSD.org>
CommitDate: 2026-09-16 14:12:07 +0000

    fixup! mlx5ib: Add drop flow steering rule support
    
    Fix is based on upstream Linux commit a22ed86cff36 ("IB/mlx5: Add drop
    flow steering rule support").
    
    Initialise is_drop to false so a non-DROP flow cannot inherit stack
    garbage, and pass no destination to mlx5_add_flow_rules() for drop rules
    instead of one with num_dest = 1, which the flow steering core
    dereferences.  Both were lost in the original backport.
    
    Derive the destination count from dst as well, so the dont-trap path,
    which calls create_flow_rule() with a NULL destination, no longer asks the
    core to walk a destination array that is not there.
    
    Sponsored by:   NVidia networking
    MFC after:      1 month
---
 sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c | 14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

diff --git a/sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c b/sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
index 462306465a8e..e598291685d7 100644
--- a/sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
+++ b/sys/dev/mlx5/mlx5_ib/mlx5_ib_main.c
@@ -2250,12 +2250,14 @@ static struct mlx5_ib_flow_handler *create_flow_rule(struct mlx5_ib_dev *dev,
 	struct mlx5_flow_table	*ft = ft_prio->flow_table;
 	struct mlx5_ib_flow_handler *handler;
 	struct mlx5_flow_spec *spec;
+	struct mlx5_flow_destination *rule_dst = dst;
 	const void *ib_flow = (const void *)flow_attr + sizeof(*flow_attr);
 	unsigned int spec_index;
 	struct mlx5_flow_act flow_act = {};
-	bool is_drop;
+	bool is_drop = false;
 	u32 action;
 	int err = 0;
+	int dest_num = dst ? 1 : 0;
 
 	if (!is_valid_attr(flow_attr))
 		return ERR_PTR(-EINVAL);
@@ -2282,12 +2284,16 @@ static struct mlx5_ib_flow_handler *create_flow_rule(struct mlx5_ib_dev *dev,
 	}
 
 	spec->match_criteria_enable = get_match_criteria_enable(spec->match_criteria);
-	if (is_drop)
+	if (is_drop) {
 		action = MLX5_FLOW_CONTEXT_ACTION_DROP;
-	else
+		rule_dst = NULL;
+		dest_num = 0;
+	} else {
 		action = dst ? MLX5_FLOW_CONTEXT_ACTION_FWD_DEST : 0;
+	}
 	flow_act.action = action;
-	handler->rule = mlx5_add_flow_rules(ft, spec, &flow_act, dst, 1);
+	handler->rule = mlx5_add_flow_rules(ft, spec, &flow_act, rule_dst,
+					    dest_num);
 
 	if (IS_ERR(handler->rule)) {
 		err = PTR_ERR(handler->rule);