From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mo4-p00-ob.smtp.rzone.de (mo4-p00-ob.smtp.rzone.de [81.169.146.217]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D25837C0F8 for ; Wed, 19 Aug 2026 16:14:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=pass smtp.client-ip=81.169.146.217 ARC-Seal:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787156089; cv=pass; b=mPkLmH5L8LlZqjY6/ZE+KN1nVG96tqbFLJQGuwJibWfmHADaYMKummKFZNHSbeIe0IORA8eizcZuoz4KynO0lJxVxSu3yiby9b0gp03NjjDG94sxac7qanc1Yeqjh5QaSo87WP3uw6zxAxNA9ZTQf6nF+Zx6c0m/0fXgq5zxSto= ARC-Message-Signature:i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787156089; c=relaxed/simple; bh=J9fzd7Ex0irvRDirGULUJyvIdyXmnQN6+gXI1cqpEUc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=gCpEUDDXx6PZk5Vn4wUJ/xAc/LHlhVaGjiJqjIIvtiC8DXygYICL9uX6gCtSkounSdOfG/kKBtHJWGDkv//vBpP3xfKdlbx9WzrvFBlYCD+n8LSR7AG+3W/elLTOgxC3VuWUeBuZ94xkFT3iHYr5TwIjqnl94GpCfE/kLeI7fgQ= ARC-Authentication-Results:i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=hartkopp.net; spf=fail smtp.mailfrom=hartkopp.net; dkim=pass (2048-bit key) header.d=hartkopp.net header.i=@hartkopp.net header.b=oyZBkxxX; dkim=permerror (0-bit key) header.d=hartkopp.net header.i=@hartkopp.net header.b=MVcsJpFw; arc=pass smtp.client-ip=81.169.146.217 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=hartkopp.net Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=hartkopp.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=hartkopp.net header.i=@hartkopp.net header.b="oyZBkxxX"; dkim=permerror (0-bit key) header.d=hartkopp.net header.i=@hartkopp.net header.b="MVcsJpFw" ARC-Seal: i=1; a=rsa-sha256; t=1787155713; cv=none; d=strato.com; s=strato-dkim-0002; b=Jq0Ns9+Jxpzs1LWmqSloN1l7W0J8c7Hxr3tkItiX6Fdvs3YxZqaDeD3fMzxXphXSUf PY0fZh1t7f7wtQhrltuzOx76QbR3XCcReSBkv7hnk9HjchXtuzB5qc2rNma5u4DRP7w9 qoC+B9udbxQcU32YW0m6sv8Yk8sPwGuUl3JVYmSBy7ABOLIdxnRKqb4wMtRPtyByrj1o 0Hbl/J73icitjzciXJPsjpkMzS3kR3sti7f3pVhlzZdz6C6k0KHQvHezwR31OMm5ACNm 0305+YlMVc7B0W5LHhjuo4TRv/bvrjU/d5uzNH6qiwtwwgT9yng2bTIWvD3lXV7noSX/ QMjA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; t=1787155713; s=strato-dkim-0002; d=strato.com; h=Message-ID:Date:Subject:Cc:To:From:Cc:Date:From:Subject:Sender; bh=TyfCT7DpoNECh8rjqlbzzrYKqqJgDdSCTlsyPG9mfKw=; b=JAYOykQMF4QVIjf7rjoM8TeTrd1cyn/p4jBRge4NjIoufdQKr57CHrWP8BPucv4S8A mmxSykFBXF1HiKuY1LfD2JhCfC+Vl5JFlhJBbEZDWYlxLS6zYFrDzPu8rrGd8y/qaPlT wvdk4xrsCpl0E1IEZ5oEQIIGKa3ZEEo2PZN+tIU+ruWpzY/1ZiS0pihP+i+s+rI5iXtV v9/68Xs4P8uJDAui6ztREV/1hsHVfC5sIxWTHDN/RyWyBjzXvfUrIITLIC3TMnVcjxCN hEOKypphsnZsyi88iHL/xugydNmM1rhz0x/RoCBOeSoLL/JVX8TP1gQjdvt3sAJjlMq/ yrhQ== ARC-Authentication-Results: i=1; strato.com; arc=none; dkim=none X-RZG-CLASS-ID: mo00 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1787155713; s=strato-dkim-0002; d=hartkopp.net; h=Message-ID:Date:Subject:Cc:To:From:Cc:Date:From:Subject:Sender; bh=TyfCT7DpoNECh8rjqlbzzrYKqqJgDdSCTlsyPG9mfKw=; b=oyZBkxxXMx73pn0bu+4Hhv195E7MMcYwDH5zbEv/VCAgTsdfAnCLRzkkpYM7s6i1+0 3Duii9XvSzDApJck5+B+TyUgY5+hp6NNTpFpQal1CwUedrX7osDY/MXUY+ijV7CVsmCx v/ykHUKTe+676ZRJAwG2znyEqbI2JRq++8IQqqFvsJm2/vMBlvIMQBRfv7bDSBUW9YD3 8HH3EoI6/jwTMWjjDeeXzAjfBi6kxvGk/r8gp6k2zZgKNLS/sqDrAD4lb9Gu0WfYQzzl wglcTUqH5NPCxOxKSscVJxq8bnvjJJK2Sfv6oHGTDWxOqx71oxDCvwhANFl2pmqFOfzd 2JzQ== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; t=1787155713; s=strato-dkim-0003; d=hartkopp.net; h=Message-ID:Date:Subject:Cc:To:From:Cc:Date:From:Subject:Sender; bh=TyfCT7DpoNECh8rjqlbzzrYKqqJgDdSCTlsyPG9mfKw=; b=MVcsJpFwWm56OlVZHik9QCnO1Qxfm6ykn51Iyomjrykstph+7sxVJd9jqqqiF3r5Bc UydJLgchLXykrv1po/DQ== X-RZG-AUTH: ":P2MHfkW8eP4Mre39l357AZT/I7AY/7nT2yrDxb8mjH4JKvMdQv2tTUsMrZpkO3Mw3lZ/t54cFxeEQ7s8bDup0Q==" Received: from vivo.lan by smtp.strato.de (RZmta 55.6.2 AUTH) with ESMTPSA id K171b727JG8XMXw (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256 bits)) (Client did not present a certificate); Wed, 19 Aug 2026 18:08:33 +0200 (CEST) From: Oliver Hartkopp To: linux-can@vger.kernel.org Cc: Oliver Hartkopp , stable@kernel.org, Oleksij Rempel Subject: [PATCH] can: convert unreliable ARPHRD_CAN type checks to robust can_get_ml_priv() Date: Wed, 19 Aug 2026 18:08:22 +0200 Message-ID: <20260819160822.8256-1-socketcan@hartkopp.net> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-can@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain; charset="us-ascii" Commit 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device") introduced an explicit way to assign the midlayer private pointer (dev->ml_priv) to named users like ML_PRIV_CAN. With this extension the CAN device specific ml_priv assignment became a robust indicator to identify a valid CAN device, when can_get_ml_priv() returns a valid pointer. This has been used directly by the referenced commit in the CAN specific j1939 and proc code but not in the other parts of the CAN subsystem. With the TUN/TAP driver a device's ARPHRD type can be controlled by userspace independently of its midlayer private data (ml_priv). The TUNSETLINK ioctl allows a down TUN/TAP device to overwrite its hardware type to become ARPHRD_CAN while dev->ml_priv remains NULL (uninitialized). Instead of checking dev->type being the unreliable ARPHRD_CAN value convert the missing "valid CAN devices" checks to can_get_ml_priv(). Fixes: 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device") Cc: stable@kernel.org Cc: Oleksij Rempel Signed-off-by: Oliver Hartkopp --- net/can/af_can.c | 12 ++++++------ net/can/bcm.c | 7 ++++--- net/can/gw.c | 7 ++++--- net/can/isotp.c | 5 +++-- net/can/raw.c | 4 ++-- 5 files changed, 19 insertions(+), 16 deletions(-) diff --git a/net/can/af_can.c b/net/can/af_can.c index be0661679ef8..1d30a622063c 100644 --- a/net/can/af_can.c +++ b/net/can/af_can.c @@ -224,11 +224,11 @@ int can_send(struct sk_buff *skb, int loop) if (unlikely(skb->len > READ_ONCE(skb->dev->mtu))) { err = -EMSGSIZE; goto inval_skb; } - if (unlikely(skb->dev->type != ARPHRD_CAN)) { + if (unlikely(!can_get_ml_priv(skb->dev))) { err = -EPERM; goto inval_skb; } if (unlikely(!(skb->dev->flags & IFF_UP))) { @@ -450,11 +450,11 @@ int can_rx_register(struct net *net, struct net_device *dev, canid_t can_id, struct can_dev_rcv_lists *dev_rcv_lists; struct can_rcv_lists_stats *rcv_lists_stats = net->can.rcv_lists_stats; /* insert new receiver (dev,canid,mask) -> (func,data) */ - if (dev && (dev->type != ARPHRD_CAN || !can_get_ml_priv(dev))) + if (dev && !can_get_ml_priv(dev)) return -ENODEV; if (dev && !net_eq(net, dev_net(dev))) return -ENODEV; @@ -517,11 +517,11 @@ void can_rx_unregister(struct net *net, struct net_device *dev, canid_t can_id, struct receiver *rcv = NULL; struct hlist_head *rcv_list; struct can_rcv_lists_stats *rcv_lists_stats = net->can.rcv_lists_stats; struct can_dev_rcv_lists *dev_rcv_lists; - if (dev && dev->type != ARPHRD_CAN) + if (dev && !can_get_ml_priv(dev)) return; if (dev && !net_eq(net, dev_net(dev))) return; @@ -685,11 +685,11 @@ static void can_receive(struct sk_buff *skb, struct net_device *dev) } static int can_rcv(struct sk_buff *skb, struct net_device *dev, struct packet_type *pt, struct net_device *orig_dev) { - if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) || + if (unlikely(!can_get_ml_priv(dev) || !can_skb_ext_find(skb) || !can_is_can_skb(skb))) { pr_warn_once("PF_CAN: dropped non conform CAN skbuff: dev type %d, len %d\n", dev->type, skb->len); kfree_skb_reason(skb, SKB_DROP_REASON_CAN_RX_INVALID_FRAME); @@ -701,11 +701,11 @@ static int can_rcv(struct sk_buff *skb, struct net_device *dev, } static int canfd_rcv(struct sk_buff *skb, struct net_device *dev, struct packet_type *pt, struct net_device *orig_dev) { - if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) || + if (unlikely(!can_get_ml_priv(dev) || !can_skb_ext_find(skb) || !can_is_canfd_skb(skb))) { pr_warn_once("PF_CAN: dropped non conform CAN FD skbuff: dev type %d, len %d\n", dev->type, skb->len); kfree_skb_reason(skb, SKB_DROP_REASON_CANFD_RX_INVALID_FRAME); @@ -717,11 +717,11 @@ static int canfd_rcv(struct sk_buff *skb, struct net_device *dev, } static int canxl_rcv(struct sk_buff *skb, struct net_device *dev, struct packet_type *pt, struct net_device *orig_dev) { - if (unlikely(dev->type != ARPHRD_CAN || !can_get_ml_priv(dev) || + if (unlikely(!can_get_ml_priv(dev) || !can_skb_ext_find(skb) || !can_is_canxl_skb(skb))) { pr_warn_once("PF_CAN: dropped non conform CAN XL skbuff: dev type %d, len %d\n", dev->type, skb->len); kfree_skb_reason(skb, SKB_DROP_REASON_CANXL_RX_INVALID_FRAME); diff --git a/net/can/bcm.c b/net/can/bcm.c index dff8fab6b402..2f261c438f52 100644 --- a/net/can/bcm.c +++ b/net/can/bcm.c @@ -52,10 +52,11 @@ #include #include #include #include #include +#include #include #include #include #include #include @@ -1716,11 +1717,11 @@ static int bcm_sendmsg(struct socket *sock, struct msghdr *msg, size_t size) if (!dev) { ret = -ENODEV; goto out_release; } - if (dev->type != ARPHRD_CAN) { + if (!can_get_ml_priv(dev)) { dev_put(dev); ret = -ENODEV; goto out_release; } @@ -1864,11 +1865,11 @@ static void bcm_notify(struct bcm_sock *bo, unsigned long msg, static int bcm_notifier(struct notifier_block *nb, unsigned long msg, void *ptr) { struct net_device *dev = netdev_notifier_info_to_dev(ptr); - if (dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(dev)) return NOTIFY_DONE; if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN) return NOTIFY_DONE; if (unlikely(bcm_busy_notifier)) /* Check for reentrant bug. */ return NOTIFY_DONE; @@ -2021,11 +2022,11 @@ static int bcm_connect(struct socket *sock, struct sockaddr_unsized *uaddr, int dev = dev_get_by_index(net, addr->can_ifindex); if (!dev) { ret = -ENODEV; goto fail; } - if (dev->type != ARPHRD_CAN) { + if (!can_get_ml_priv(dev)) { dev_put(dev); ret = -ENODEV; goto fail; } diff --git a/net/can/gw.c b/net/can/gw.c index f1f59c0c6fd6..b946da2d0a60 100644 --- a/net/can/gw.c +++ b/net/can/gw.c @@ -50,10 +50,11 @@ #include #include #include #include #include +#include #include #include #include #include #include @@ -607,11 +608,11 @@ static int cgw_notifier(struct notifier_block *nb, unsigned long msg, void *ptr) { struct net_device *dev = netdev_notifier_info_to_dev(ptr); struct net *net = dev_net(dev); - if (dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(dev)) return NOTIFY_DONE; if (msg == NETDEV_UNREGISTER) { struct cgw_job *gwj = NULL; struct hlist_node *nx; @@ -1158,19 +1159,19 @@ static int cgw_create_job(struct sk_buff *skb, struct nlmsghdr *nlh, gwj->src.dev = __dev_get_by_index(net, gwj->ccgw.src_idx); if (!gwj->src.dev) goto out; - if (gwj->src.dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(gwj->src.dev)) goto out; gwj->dst.dev = __dev_get_by_index(net, gwj->ccgw.dst_idx); if (!gwj->dst.dev) goto out; - if (gwj->dst.dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(gwj->dst.dev)) goto out; /* is sending the skb back to the incoming interface intended? */ if (gwj->src.dev == gwj->dst.dev && !(gwj->flags & CGW_FLAGS_CAN_IIF_TX_OK)) { diff --git a/net/can/isotp.c b/net/can/isotp.c index 35ae4f51a525..130a0dbec78c 100644 --- a/net/can/isotp.c +++ b/net/can/isotp.c @@ -63,10 +63,11 @@ #include #include #include #include #include +#include #include #include #include #include #include @@ -1604,11 +1605,11 @@ static int isotp_bind(struct socket *sock, struct sockaddr_unsized *uaddr, int l dev = dev_get_by_index(net, addr->can_ifindex); if (!dev) { err = -ENODEV; goto out; } - if (dev->type != ARPHRD_CAN) { + if (!can_get_ml_priv(dev)) { err = -ENODEV; goto out_put_dev; } if (READ_ONCE(dev->mtu) < so->ll.mtu) { err = -EINVAL; @@ -1891,11 +1892,11 @@ static void isotp_notify(struct isotp_sock *so, unsigned long msg, static int isotp_notifier(struct notifier_block *nb, unsigned long msg, void *ptr) { struct net_device *dev = netdev_notifier_info_to_dev(ptr); - if (dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(dev)) return NOTIFY_DONE; if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN) return NOTIFY_DONE; if (unlikely(isotp_busy_notifier)) /* Check for reentrant bug. */ return NOTIFY_DONE; diff --git a/net/can/raw.c b/net/can/raw.c index 0a8b7c2fb4c9..b700e5fde07a 100644 --- a/net/can/raw.c +++ b/net/can/raw.c @@ -342,11 +342,11 @@ static void raw_notify(struct raw_sock *ro, unsigned long msg, static int raw_notifier(struct notifier_block *nb, unsigned long msg, void *ptr) { struct net_device *dev = netdev_notifier_info_to_dev(ptr); - if (dev->type != ARPHRD_CAN) + if (!can_get_ml_priv(dev)) return NOTIFY_DONE; if (msg != NETDEV_UNREGISTER && msg != NETDEV_DOWN) return NOTIFY_DONE; if (unlikely(raw_busy_notifier)) /* Check for reentrant bug. */ return NOTIFY_DONE; @@ -485,11 +485,11 @@ static int raw_bind(struct socket *sock, struct sockaddr_unsized *uaddr, int len dev = dev_get_by_index(sock_net(sk), addr->can_ifindex); if (!dev) { err = -ENODEV; goto out; } - if (dev->type != ARPHRD_CAN) { + if (!can_get_ml_priv(dev)) { err = -ENODEV; goto out_put_dev; } if (!(dev->flags & IFF_UP)) -- 2.53.0