From: "Ömer Mete Kaya" <omermetekaya0@gmail.com>
To: netdev@vger.kernel.org
Cc: oneukum@suse.com, andrew+netdev@lunn.ch, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org,
david.laight.linux@gmail.com,
"Ömer Mete Kaya" <omermetekaya0@gmail.com>,
syzbot+04cd90bb99c6ef81a65d@syzkaller.appspotmail.com
Subject: [PATCH net v4] usbnet: fix smp_processor_id() use in preemptible context
Date: Tue, 8 Sep 2026 00:45:12 +0300 [thread overview]
Message-ID: <20260907214727.692307-1-omermetekaya0@gmail.com> (raw)
In-Reply-To: <20260907212308.420701cf@pumpkin>
usbnet_skb_return() and tx_complete() call this_cpu_ptr() before
disabling preemption, which triggers a BUG when running with PREEMPT_FULL:
BUG: using smp_processor_id() in preemptible code in tx_complete
Fix by using get_cpu_ptr()/put_cpu_ptr() which disable preemption
and return the per-CPU pointer atomically.
Fixes: 43daa96b166c ("usbnet: Stop RX Q on MTU change")
Reported-by: syzbot+04cd90bb99c6ef81a65d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=04cd90bb99c6ef81a65d
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
---
v4: Use get_cpu_ptr()/put_cpu_ptr() as suggested by David Laight.
drivers/net/usb/usbnet.c | 18 ++++++++++--------
1 file changed, 10 insertions(+), 8 deletions(-)
diff --git a/drivers/net/usb/usbnet.c b/drivers/net/usb/usbnet.c
index a19ecf718f36..3df72b0c6bcf 100644
--- a/drivers/net/usb/usbnet.c
+++ b/drivers/net/usb/usbnet.c
@@ -325,8 +325,7 @@ static void __usbnet_status_stop_force(struct usbnet *dev)
*/
void usbnet_skb_return(struct usbnet *dev, struct sk_buff *skb)
{
- struct pcpu_sw_netstats *stats64 = this_cpu_ptr(dev->net->tstats);
- unsigned long flags;
+ struct pcpu_sw_netstats *stats64;
int status;
if (test_bit(EVENT_RX_PAUSED, &dev->flags)) {
@@ -338,10 +337,12 @@ void usbnet_skb_return(struct usbnet *dev, struct sk_buff *skb)
if (skb->protocol == 0)
skb->protocol = eth_type_trans(skb, dev->net);
- flags = u64_stats_update_begin_irqsave(&stats64->syncp);
+ stats64 = get_cpu_ptr(dev->net->tstats);
+ u64_stats_update_begin(&stats64->syncp);
u64_stats_inc(&stats64->rx_packets);
u64_stats_add(&stats64->rx_bytes, skb->len);
- u64_stats_update_end_irqrestore(&stats64->syncp, flags);
+ u64_stats_update_end(&stats64->syncp);
+ put_cpu_ptr(dev->net->tstats);
netif_dbg(dev, rx_status, dev->net, "< rx, len %zu, type 0x%x\n",
skb->len + sizeof(struct ethhdr), skb->protocol);
@@ -1298,13 +1299,14 @@ static void tx_complete(struct urb *urb)
struct usbnet *dev = entry->dev;
if (urb->status == 0) {
- struct pcpu_sw_netstats *stats64 = this_cpu_ptr(dev->net->tstats);
- unsigned long flags;
+ struct pcpu_sw_netstats *stats64;
- flags = u64_stats_update_begin_irqsave(&stats64->syncp);
+ stats64 = get_cpu_ptr(dev->net->tstats);
+ u64_stats_update_begin(&stats64->syncp);
u64_stats_add(&stats64->tx_packets, entry->packets);
u64_stats_add(&stats64->tx_bytes, entry->length);
- u64_stats_update_end_irqrestore(&stats64->syncp, flags);
+ u64_stats_update_end(&stats64->syncp);
+ put_cpu_ptr(dev->net->tstats);
} else {
dev->net->stats.tx_errors++;
--
2.55.0
next prev parent reply other threads:[~2026-09-07 21:47 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 16:54 [PATCH] usbnet: fix smp_processor_id() use in preemptible context Ömer Mete Kaya
2026-09-05 22:45 ` [PATCH net v2] " Ömer Mete Kaya
2026-09-07 11:38 ` Oliver Neukum
2026-09-07 18:52 ` Ömer Mete Kaya
2026-09-07 20:23 ` David Laight
2026-09-07 21:45 ` Ömer Mete Kaya [this message]
2026-09-09 21:47 ` [PATCH net v4] " netdev-bot+sashiko
2026-09-10 9:01 ` David Laight
2026-09-07 19:05 ` [PATCH] " Ömer Mete Kaya
2026-09-08 3:43 ` [PATCH net v2] " netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907214727.692307-1-omermetekaya0@gmail.com \
--to=omermetekaya0@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=david.laight.linux@gmail.com \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=oneukum@suse.com \
--cc=pabeni@redhat.com \
--cc=syzbot+04cd90bb99c6ef81a65d@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.