From: Jiayuan Chen <jiayuan.chen@linux.dev>
To: netdev@vger.kernel.org
Cc: Jiayuan Chen <jiayuan.chen@linux.dev>,
Jakub Kicinski <kuba@kernel.org>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Paolo Abeni <pabeni@redhat.com>, Petr Machata <petrm@nvidia.com>,
Willem de Bruijn <willemb@google.com>,
linux-kernel@vger.kernel.org
Subject: [PATCH net v2] netdevsim: fix panic when NETIF_F_LOOPBACK is set on a VF port
Date: Tue, 1 Sep 2026 14:18:50 +0800 [thread overview]
Message-ID: <20260901061851.61734-1-jiayuan.chen@linux.dev> (raw)
A netdevsim VF port cannot process incoming data. It never runs
nsim_queue_init(), so ns->rq is NULL, and nsim_vf_netdev_ops has no
->ndo_open, so its NAPI is never set up either.
nsim_setup() offers NETIF_F_LOOPBACK to both PF and VF ports. Turning
it on for a VF makes nsim_start_xmit() take ns itself as peer_ns and
dereference peer_ns->rq[], which panics.
A VF cannot deliver packets at all: it can't be linked as a peer either,
since netdev_is_nsim() only matches the PF netdev_ops, so ns->peer is
always NULL and every skb ends up dropped. Give VF ports a dedicated
xmit that just drops the traffic, so VFs no longer depend on PF-only
state in nsim_start_xmit().
Reproduce in qemu:
modprobe netdevsim
echo "90 1" > /sys/bus/netdevsim/new_device
echo 2 > /sys/bus/netdevsim/devices/netdevsim90/sriov_numvfs
devlink dev eswitch set netdevsim/netdevsim90 mode switchdev
ethtool -K eth2 loopback on # eth2 is the vfnum 0 port
ip link set eth2 up
Panic:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 0 UID: 0 PID: 141 Comm: kworker/0:3 Not tainted 7.2.0+ #338 PREEMPT
Workqueue: mld mld_ifc_work
RIP: 0010:nsim_start_xmit (drivers/net/netdevsim/netdev.c:159)
dev_hard_start_xmit ( net/core/dev.c:3953)
sch_direct_xmit (net/sched/sch_generic.c:372)
__dev_queue_xmit (net/core/dev.c:4262 net/core/dev.c:4884)
neigh_resolve_output (net/core/neighbour.c:1616)
ip6_finish_output2 (net/ipv6/ip6_output.c:138)
ip6_finish_output (net/ipv6/ip6_output.c:221)
ip6_output (net/ipv6/ip6_output.c:248)
......
Fixes: 358008f41d9b ("netdevsim: add loopback support")
Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev>
---
v2: use a dedicated drop-only xmit for VF ports instead of clearing
NETIF_F_LOOPBACK, per Jakub
v1: https://lore.kernel.org/netdev/20260831042221.137137-1-jiayuan.chen@linux.dev/
---
drivers/net/netdevsim/netdev.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/net/netdevsim/netdev.c b/drivers/net/netdevsim/netdev.c
index b4a99f3ceac6..eebc02ccc4a9 100644
--- a/drivers/net/netdevsim/netdev.c
+++ b/drivers/net/netdevsim/netdev.c
@@ -185,6 +185,14 @@ static netdev_tx_t nsim_start_xmit(struct sk_buff *skb, struct net_device *dev)
return NETDEV_TX_OK;
}
+static netdev_tx_t nsim_start_xmit_vf(struct sk_buff *skb,
+ struct net_device *dev)
+{
+ dev_dstats_tx_dropped(dev);
+ kfree_skb(skb);
+ return NETDEV_TX_OK;
+}
+
static int nsim_set_rx_mode(struct net_device *dev,
struct netdev_hw_addr_list *uc,
struct netdev_hw_addr_list *mc)
@@ -651,7 +659,7 @@ static const struct net_device_ops nsim_netdev_ops = {
};
static const struct net_device_ops nsim_vf_netdev_ops = {
- .ndo_start_xmit = nsim_start_xmit,
+ .ndo_start_xmit = nsim_start_xmit_vf,
.ndo_set_rx_mode_async = nsim_set_rx_mode,
.ndo_set_mac_address = eth_mac_addr,
.ndo_validate_addr = eth_validate_addr,
--
2.43.0
next reply other threads:[~2026-09-01 6:19 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 6:18 Jiayuan Chen [this message]
2026-09-03 1:40 ` [PATCH net v2] netdevsim: fix panic when NETIF_F_LOOPBACK is set on a VF port patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901061851.61734-1-jiayuan.chen@linux.dev \
--to=jiayuan.chen@linux.dev \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=petrm@nvidia.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.