[PATCH net v2] net: hip04: use 16-bit byte order for HI13X1 TX fields

From: Pengpeng Hou

Date: Sat Sep 19 2026 - 23:37:52 EST


The HI13X1 TX descriptor stores send_size and data_offset in 16-bit
fields, unlike the 32-bit send_size field in the other descriptor
layout. The transmit path nevertheless converts both HI13X1 fields with
cpu_to_be32() before assigning them to u16 members.

On a little-endian CPU, the conversion moves these small values into the
upper half of the 32-bit result and the assignment discards that half.
The descriptor consequently loses the packet size and cache-line offset.

Use cpu_to_be16() for the two HI13X1 fields. Leave the other layout's
32-bit size conversion unchanged.

The issue was found by our static-analysis tool.

Fixes: d413779cdd93 ("net: hisilicon: Add an tx_desc to adapt HI13X1_GMAC")
Reviewed-by: Simon Horman <horms@xxxxxxxxxx>
Reviewed-by: Jijie Shao <shaojijie@xxxxxxxxxx>
Assisted-by: gpt 5
Signed-off-by: Pengpeng Hou <hppiscas@xxxxxxx>
---
Changes since v1:
https://lore.kernel.org/all/20260905132958.63085-1-hppiscas@xxxxxxx/
Use the full author name. Clarify the HI13X1/little-endian scope in
response to Simon. The finding came from source analysis; there is no
established explanation for why it remained unnoticed since 2019.

drivers/net/ethernet/hisilicon/hip04_eth.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/net/ethernet/hisilicon/hip04_eth.c b/drivers/net/ethernet/hisilicon/hip04_eth.c
index fc2c47dcfaab..2920985144bf 100644
--- a/drivers/net/ethernet/hisilicon/hip04_eth.c
+++ b/drivers/net/ethernet/hisilicon/hip04_eth.c
@@ -527,13 +527,14 @@ hip04_mac_start_xmit(struct sk_buff *skb, struct net_device *ndev)
priv->tx_skb[tx_head] = skb;
priv->tx_phys[tx_head] = phys;

- desc->send_size = (__force u32)cpu_to_be32(skb->len);
#if defined(CONFIG_HI13X1_GMAC)
+ desc->send_size = (__force u16)cpu_to_be16(skb->len);
desc->cfg = (__force u32)cpu_to_be32(TX_CLEAR_WB | TX_FINISH_CACHE_INV
| TX_RELEASE_TO_PPE | priv->port << TX_POOL_SHIFT);
- desc->data_offset = (__force u32)cpu_to_be32(phys & SOC_CACHE_LINE_MASK);
+ desc->data_offset = (__force u16)cpu_to_be16(phys & SOC_CACHE_LINE_MASK);
desc->send_addr = (__force u32)cpu_to_be32(phys & ~SOC_CACHE_LINE_MASK);
#else
+ desc->send_size = (__force u32)cpu_to_be32(skb->len);
desc->cfg = (__force u32)cpu_to_be32(TX_CLEAR_WB | TX_FINISH_CACHE_INV);
desc->send_addr = (__force u32)cpu_to_be32(phys);
#endif

base-commit: 518e5b794c06c0f0eb40df3e202274a66202c137
--
2.50.1 (Apple Git-155)