All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jiayuan Chen <jiayuan.chen@linux.dev>
To: netdev@vger.kernel.org
Cc: Jiayuan Chen <jiayuan.chen@linux.dev>,
	Jakub Kicinski <kuba@kernel.org>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Paolo Abeni <pabeni@redhat.com>, Petr Machata <petrm@nvidia.com>,
	Willem de Bruijn <willemb@google.com>,
	linux-kernel@vger.kernel.org
Subject: [PATCH net v2] netdevsim: fix panic when NETIF_F_LOOPBACK is set on a VF port
Date: Tue,  1 Sep 2026 14:18:50 +0800	[thread overview]
Message-ID: <20260901061851.61734-1-jiayuan.chen@linux.dev> (raw)

A netdevsim VF port cannot process incoming data.  It never runs
nsim_queue_init(), so ns->rq is NULL, and nsim_vf_netdev_ops has no
->ndo_open, so its NAPI is never set up either.

nsim_setup() offers NETIF_F_LOOPBACK to both PF and VF ports.  Turning
it on for a VF makes nsim_start_xmit() take ns itself as peer_ns and
dereference peer_ns->rq[], which panics.

A VF cannot deliver packets at all: it can't be linked as a peer either,
since netdev_is_nsim() only matches the PF netdev_ops, so ns->peer is
always NULL and every skb ends up dropped.  Give VF ports a dedicated
xmit that just drops the traffic, so VFs no longer depend on PF-only
state in nsim_start_xmit().

Reproduce in qemu:
  modprobe netdevsim
  echo "90 1" > /sys/bus/netdevsim/new_device
  echo 2 > /sys/bus/netdevsim/devices/netdevsim90/sriov_numvfs
  devlink dev eswitch set netdevsim/netdevsim90 mode switchdev
  ethtool -K eth2 loopback on   # eth2 is the vfnum 0 port
  ip link set eth2 up

Panic:
  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
  CPU: 0 UID: 0 PID: 141 Comm: kworker/0:3 Not tainted 7.2.0+ #338 PREEMPT
  Workqueue: mld mld_ifc_work
  RIP: 0010:nsim_start_xmit (drivers/net/netdevsim/netdev.c:159)
  dev_hard_start_xmit ( net/core/dev.c:3953)
  sch_direct_xmit (net/sched/sch_generic.c:372)
  __dev_queue_xmit (net/core/dev.c:4262 net/core/dev.c:4884)
  neigh_resolve_output (net/core/neighbour.c:1616)
  ip6_finish_output2 (net/ipv6/ip6_output.c:138)
  ip6_finish_output (net/ipv6/ip6_output.c:221)
  ip6_output (net/ipv6/ip6_output.c:248)
  ......

Fixes: 358008f41d9b ("netdevsim: add loopback support")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>

---
v2: use a dedicated drop-only xmit for VF ports instead of clearing
    NETIF_F_LOOPBACK, per Jakub
v1: https://lore.kernel.org/netdev/20260831042221.137137-1-jiayuan.chen@linux.dev/
---
 drivers/net/netdevsim/netdev.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

diff --git a/drivers/net/netdevsim/netdev.c b/drivers/net/netdevsim/netdev.c
index b4a99f3ceac6..eebc02ccc4a9 100644
--- a/drivers/net/netdevsim/netdev.c
+++ b/drivers/net/netdevsim/netdev.c
@@ -185,6 +185,14 @@ static netdev_tx_t nsim_start_xmit(struct sk_buff *skb, struct net_device *dev)
 	return NETDEV_TX_OK;
 }
 
+static netdev_tx_t nsim_start_xmit_vf(struct sk_buff *skb,
+				      struct net_device *dev)
+{
+	dev_dstats_tx_dropped(dev);
+	kfree_skb(skb);
+	return NETDEV_TX_OK;
+}
+
 static int nsim_set_rx_mode(struct net_device *dev,
 			    struct netdev_hw_addr_list *uc,
 			    struct netdev_hw_addr_list *mc)
@@ -651,7 +659,7 @@ static const struct net_device_ops nsim_netdev_ops = {
 };
 
 static const struct net_device_ops nsim_vf_netdev_ops = {
-	.ndo_start_xmit		= nsim_start_xmit,
+	.ndo_start_xmit		= nsim_start_xmit_vf,
 	.ndo_set_rx_mode_async	= nsim_set_rx_mode,
 	.ndo_set_mac_address	= eth_mac_addr,
 	.ndo_validate_addr	= eth_validate_addr,
-- 
2.43.0


             reply	other threads:[~2026-09-01  6:19 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-01  6:18 Jiayuan Chen [this message]
2026-09-03  1:40 ` [PATCH net v2] netdevsim: fix panic when NETIF_F_LOOPBACK is set on a VF port patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260901061851.61734-1-jiayuan.chen@linux.dev \
    --to=jiayuan.chen@linux.dev \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=petrm@nvidia.com \
    --cc=willemb@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.