From: Tony Nguyen <anthony.l.nguyen@intel.com>
To: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com,
edumazet@kernel.org, andrew+netdev@lunn.ch,
netdev@vger.kernel.org
Cc: Emil Tantilov <emil.s.tantilov@intel.com>,
anthony.l.nguyen@intel.com, luoxuanqiang@kylinos.cn,
bryan.fraschetti@canonical.com, tristan@talencesecurity.com,
tomasz.lichwala@linux.intel.com, david.butler@appgate.com,
horms@kernel.org, Joshua Hay <joshua.a.hay@intel.com>,
Samuel Salin <Samuel.salin@intel.com>
Subject: [PATCH net 1/6] idpf: fix possible race on remove during a reset
Date: Mon, 28 Sep 2026 16:04:22 -0700 [thread overview]
Message-ID: <20260928230429.495442-2-anthony.l.nguyen@intel.com> (raw)
In-Reply-To: <20260928230429.495442-1-anthony.l.nguyen@intel.com>
From: Emil Tantilov <emil.s.tantilov@intel.com>
Reset and remove can race, leaving NAPI registered and enabled:
modprobe idpf& sleep 1; ip link set eth0 up& rmmod idpf
[145561.805104] WARNING: net/core/dev.c:7699 at __netif_napi_del_locked+0x11a/0x130, CPU#30: rmmod/22393
...
[145561.810238] RIP: 0010:__netif_napi_del_locked+0x11a/0x130
...
[145561.817678] Call Trace:
[145561.818125] <TASK>
[145561.818653] free_netdev+0x110/0x2a0
[145561.819109] idpf_vport_dealloc+0x452/0x460 [idpf]
[145561.819668] ? enable_work+0x9f/0x100
[145561.820133] idpf_deinit_task+0x51/0x70 [idpf]
[145561.820694] idpf_vc_core_deinit+0x32/0x170 [idpf]
[145561.821193] idpf_remove+0x40/0x200 [idpf]
[145561.821667] pci_device_remove+0x40/0xa0
[145561.822132] device_release_driver_internal+0x1a9/0x210
[145561.822691] driver_detach+0x4b/0x90
[145561.823161] bus_remove_driver+0x70/0x100
[145561.823721] pci_unregister_driver+0x2e/0xb0
[145561.824207] __do_sys_delete_module.constprop.0+0x190/0x2e0
[145561.824715] ? kmem_cache_free+0x312/0x550
[145561.825213] do_syscall_64+0xc8/0x6b0
[145561.825709] ? clear_bhb_loop+0x30/0x80
[145561.826216] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[145561.826602] RIP: 0033:0x7fe628130beb
Make sure to call idpf_vport_stop() in idpf_stop(), irrespective of the
IDPF_REMOVE_IN_PROG state, to allow a reset racing with remove to tear
down NAPI in idpf_detach_and_close(), which runs under RTNL lock.
Fixes: 2e281e1155fc ("idpf: detach and close netdevs while handling a reset")
Signed-off-by: Emil Tantilov <emil.s.tantilov@intel.com>
Reviewed-by: Joshua Hay <joshua.a.hay@intel.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Tested-by: Samuel Salin <Samuel.salin@intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
---
drivers/net/ethernet/intel/idpf/idpf_lib.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/net/ethernet/intel/idpf/idpf_lib.c b/drivers/net/ethernet/intel/idpf/idpf_lib.c
index 827c795afcb6..2c148377540c 100644
--- a/drivers/net/ethernet/intel/idpf/idpf_lib.c
+++ b/drivers/net/ethernet/intel/idpf/idpf_lib.c
@@ -1033,12 +1033,8 @@ static void idpf_vport_stop(struct idpf_vport *vport, bool rtnl)
*/
static int idpf_stop(struct net_device *netdev)
{
- struct idpf_netdev_priv *np = netdev_priv(netdev);
struct idpf_vport *vport;
- if (test_bit(IDPF_REMOVE_IN_PROG, np->adapter->flags))
- return 0;
-
idpf_vport_ctrl_lock(netdev);
vport = idpf_netdev_to_vport(netdev);
--
2.47.1
next prev parent reply other threads:[~2026-09-28 23:04 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 23:04 [PATCH net 0/6][pull request] Intel Wired LAN Driver Updates 2026-09-28 (idpf, ice, iavf) Tony Nguyen
2026-09-28 23:04 ` Tony Nguyen [this message]
2026-09-30 0:58 ` [PATCH net 1/6] idpf: fix possible race on remove during a reset netdev-bot+sashiko
2026-10-01 23:40 ` Tantilov, Emil S
2026-09-28 23:04 ` [PATCH net 2/6] ice: fix use-after-free in dynamic port cleanup Tony Nguyen
2026-09-28 23:04 ` [PATCH net 3/6] ice: Restore Ordered MMIO Writes for Tx Doorbells Tony Nguyen
2026-09-30 0:58 ` netdev-bot+sashiko
2026-10-01 16:35 ` Tony Nguyen
2026-09-28 23:04 ` [PATCH net 4/6] ice: fix metadata_dst refcount handling on representor teardown Tony Nguyen
2026-09-28 23:04 ` [PATCH net 5/6] iavf: fix VF stats not updating due to PTP command preemption Tony Nguyen
2026-09-30 0:58 ` netdev-bot+sashiko
2026-09-30 15:07 ` Tomasz Lichwala
2026-09-28 23:04 ` [PATCH net 6/6] iavf: cap advertised max_pkt_size at the single-buffer HW limit Tony Nguyen
2026-09-29 16:18 ` Alexander Lobakin
2026-09-29 20:32 ` Dave Butler
2026-09-30 11:32 ` Alexander Lobakin
2026-09-30 0:58 ` netdev-bot+sashiko
2026-09-30 6:02 ` Dave Butler
[not found] ` <IA3PR05MB22078430E404FAD12912A706298B892@IA3PR05MB220784.namprd05.prod.outlook.com>
[not found] ` <CANm61jc37jivo=XmRwN8ic8PNJFXZK+6Gsw5VRy=b-oZKpMsMA@mail.gmail.com>
2026-10-02 21:09 ` Fw: " David Butler
2026-09-28 23:10 ` [PATCH net 0/6][pull request] Intel Wired LAN Driver Updates 2026-09-28 (idpf, ice, iavf) netdev-bot+sinfo
2026-09-29 1:41 ` Dave Butler
[not found] ` <IA3PR05MB22078467309FA5DFF33EF712488B892@IA3PR05MB220784.namprd05.prod.outlook.com>
2026-10-02 21:21 ` Fw: " David Butler
2026-09-29 17:16 ` Tantilov, Emil S
2026-09-30 15:06 ` Tomasz Lichwala
2026-10-01 23:47 ` Tony Nguyen
2026-10-02 20:39 ` Jakub Kicinski
[not found] ` <IA3PR05MB220784D3846E12367B0CA1D3738B892@IA3PR05MB220784.namprd05.prod.outlook.com>
[not found] ` <CANm61jco98RoBmBAtbnjRZCPwqS0Vt6SqXjYAEUwSD4-bWLuZA@mail.gmail.com>
2026-10-02 21:06 ` Fw: " David Butler
2026-10-02 20:50 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928230429.495442-2-anthony.l.nguyen@intel.com \
--to=anthony.l.nguyen@intel.com \
--cc=Samuel.salin@intel.com \
--cc=andrew+netdev@lunn.ch \
--cc=bryan.fraschetti@canonical.com \
--cc=davem@davemloft.net \
--cc=david.butler@appgate.com \
--cc=edumazet@kernel.org \
--cc=emil.s.tantilov@intel.com \
--cc=horms@kernel.org \
--cc=joshua.a.hay@intel.com \
--cc=kuba@kernel.org \
--cc=luoxuanqiang@kylinos.cn \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=tomasz.lichwala@linux.intel.com \
--cc=tristan@talencesecurity.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.