From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CEE145187CB; Wed, 30 Sep 2026 17:09:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788182; cv=none; b=kVyTqYDEOVSbpp7fBr7cVPO/WUS/ySAhRwTDrq/Qt3v7n4B5XIqHG8dVq4ekNYoYSkaoc0vX2vpqzukfKrWKK+rZ4wQEKIedcYgV5ZBOnlXBNV40sKcEdksszYnhdQLZyiLL6J7vuhYU1FFiM5/WJgP+KETiGJglE4V9ydblRIU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788182; c=relaxed/simple; bh=jX/JivMNIF7n9+e3gywCxRzyoN3fz0LTxJKTsiNCjCI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=m8qZWMpNGDCui9KszpLaEtwUMEKMoyP0ao2urbyU+13NIhMt1P8jC/zgOCh8gPXmhpt19HbZHdqgabQ8YvhTgx1tZd1dKy3FB0eyiZ+nIyf4lFcHgwD/odlJJXaEGr9QXeOjmF5m7moNO1XCDS8VGnR2zzeNGp6RlKQGvxonmwU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=U2A3GpRP; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="U2A3GpRP" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 336601F000FF; Wed, 30 Sep 2026 17:09:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788180; bh=7+Aa8LMkmw1dt9DxoztxsMfS4/N3uv0WVxgjfXMRVCw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=U2A3GpRPhMob8W6/j/DKY+tVEbKzBdV+V50pHLGMkygpaw9UbcRgSV28Hk1DgX4X0 SSbrh4QFr1wrx2EZTBQxpOI6fhw/+jSEd4t9XKva6JLWvr3uQlKfbrivMr16pNNB13 nvQcY/6JBGQCKIM1ae0GzgAPmQEdx5q0R6vimGDY= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com, Krystian Kaniewski , Leon Romanovsky , Sasha Levin Subject: [PATCH 6.12 034/877] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Date: Wed, 30 Sep 2026 17:15:45 +0200 Message-ID: <20260930152415.479479665@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Krystian Kaniewski [ Upstream commit ef9fbe1b93f3b617b96e86d5cd76b3fa44514cb5 ] ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct net_device allocated, but does not guarantee that the device remains operational. ib_get_eth_speed() uses the returned device operationally by invoking its ethtool callback. Although that call is made under RTNL, the function does not verify the registration state first. An asynchronous RDMA port query can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit have completed. Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a device which is being unregistered. Keeping RTNL across the check and the ethtool operation prevents unregister from starting between them. Keep the speed fallback and warning under RTNL as well, so the warning can safely read netdev->name. Drop the netdev reference before releasing RTNL once all accesses to the device are complete. Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed from netdev") Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=5fe14f2ff4ccbace9a26 Signed-off-by: Krystian Kaniewski Link: https://patch.msgid.link/20260812081708.32468-1-krystianmkaniewski@gmail.com Signed-off-by: Leon Romanovsky Signed-off-by: Sasha Levin --- drivers/infiniband/core/verbs.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c index d0bd57ac7c6aa..d6fd7db5cbbd7 100644 --- a/drivers/infiniband/core/verbs.c +++ b/drivers/infiniband/core/verbs.c @@ -2000,11 +2000,13 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width) return -ENODEV; rtnl_lock(); - rc = __ethtool_get_link_ksettings(netdev, &lksettings); - rtnl_unlock(); - - dev_put(netdev); + if (READ_ONCE(netdev->reg_state) != NETREG_REGISTERED) { + dev_put(netdev); + rtnl_unlock(); + return -ENODEV; + } + rc = __ethtool_get_link_ksettings(netdev, &lksettings); if (!rc && lksettings.base.speed != (u32)SPEED_UNKNOWN) { netdev_speed = lksettings.base.speed; } else { @@ -2013,6 +2015,8 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_num, u16 *speed, u8 *width) pr_warn("%s speed is unknown, defaulting to %u\n", netdev->name, netdev_speed); } + dev_put(netdev); + rtnl_unlock(); ib_get_width_and_speed(netdev_speed, lksettings.lanes, speed, width); -- 2.53.0