All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kuniyuki Iwashima <kuniyu@google.com>
To: David Ahern <dsahern@kernel.org>,
	Ido Schimmel <idosch@nvidia.com>,
	 Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S . Miller" <davem@davemloft.net>,
	 Eric Dumazet <edumazet@kernel.org>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
	Chris J Arges <carges@cloudflare.com>,
	 Kuniyuki Iwashima <kuniyu@google.com>,
	Kuniyuki Iwashima <kuni1840@gmail.com>,
	netdev@vger.kernel.org,
	 Fernando Fernandez Mancera <fmancera@suse.de>
Subject: [PATCH v3 net-next 1/6] net: Order blackhole_netdev_init(), inet_init(), and inet6_init().
Date: Thu,  1 Oct 2026 20:47:13 +0000	[thread overview]
Message-ID: <20261001204752.2572265-2-kuniyu@google.com> (raw)
In-Reply-To: <20261001204752.2572265-1-kuniyu@google.com>

Commit 309b905deee5 ("ipv6: convert CONFIG_IPV6 to built-in
only and clean up Kconfigs") started to call inet6_init() as
device_initcall().

It explains the reason as a race condition on IPv6 addrconf,
but this is not accurate.

The change initially used fs_initcall() but switched to
device_initcall() due to the null-ptr-deref stack trace in
the link below.

It happened because blackhole_netdev_init() uses device_initcall()
and blackhole_netdev was NULL when addrconf_init() called
ipv6_add_dev(blackhole_netdev).

Due to the order in Kbuild,

  $ cat -n Kbuild | grep -E "(drivers|net)"
     111	obj-y			+= drivers/
     114	obj-$(CONFIG_NET)	+= net/

using device_initcall() for IPv6 allows built-in drivers to
be initialised earlier, which requires unnecessary NULL checks.

For the same ordering reason, IPv4 uses late_initcall() to
initialise blackhole_netdev.

Given loopback_net_ops is registered in net_dev_init() at
subsys_initcall(), blackhole_netdev_init() can be called
after that.

In addition, some places assume that IPv4 must be initialised
before IPv6.  For example, mptcp_proto_v6_init() copies
mptcp_prot to mptcp_v6_prot, which would otherwise have NULL
mptcp_v6_prot.h.hashinfo.

Let's explicitly order blackhole_netdev_init() -> inet_init()
-> inet6_init() before device_initcall() with 3 different
initcall levels:

  subsys_initcall      : 4  : net_dev_init()
  subsys_initcall_sync : 4s : blackhole_netdev_init()
  fs_initcall          : 5  : inet_init()
  fs_initcall_sync     : 5s : inet6_init()
  device_initcall      : 6  : built-in drivers

Note that both IPv4 and IPv6 can still use fs_initcall() thanks
to the order in net/Makefile, but explicit ordering would be
less error-prone.

  $ cat -n net/Makefile | grep ipv
      17	obj-$(CONFIG_INET)		+= ipv4/
      22	obj-y				+= ipv6/

Link: https://lore.kernel.org/netdev/20260309074758.0ea95a18@kernel.org/
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
---
Cc: Fernando Fernandez Mancera <fmancera@suse.de>
---
 drivers/net/loopback.c | 2 +-
 net/ipv6/af_inet6.c    | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/net/loopback.c b/drivers/net/loopback.c
index 1fb6ce6843ad..55ecd5ebac0f 100644
--- a/drivers/net/loopback.c
+++ b/drivers/net/loopback.c
@@ -289,4 +289,4 @@ static int __init blackhole_netdev_init(void)
 	return 0;
 }
 
-device_initcall(blackhole_netdev_init);
+subsys_initcall_sync(blackhole_netdev_init);
diff --git a/net/ipv6/af_inet6.c b/net/ipv6/af_inet6.c
index f0efdc13baf4..a9b8b4b42a1a 100644
--- a/net/ipv6/af_inet6.c
+++ b/net/ipv6/af_inet6.c
@@ -1217,4 +1217,4 @@ static int __init inet6_init(void)
 	proto_unregister(&tcpv6_prot);
 	goto out;
 }
-device_initcall(inet6_init);
+fs_initcall_sync(inet6_init);
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


  reply	other threads:[~2026-10-01 20:47 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-01 20:47 [PATCH v3 net-next 0/6] ip: Batch flushing uncached routes per batched device unregistration Kuniyuki Iwashima
2026-10-01 20:47 ` Kuniyuki Iwashima [this message]
2026-10-05 12:18   ` [PATCH v3 net-next 1/6] net: Order blackhole_netdev_init(), inet_init(), and inet6_init() Fernando Fernandez Mancera
2026-10-01 20:47 ` [PATCH v3 net-next 2/6] ipv4: Inline inet_blackhole_dev_init() to devinet_init() Kuniyuki Iwashima
2026-10-04 23:02   ` netdev-bot+sashiko
2026-10-01 20:47 ` [PATCH v3 net-next 3/6] net: Rename dev_isalive() to netif_is_alive() Kuniyuki Iwashima
2026-10-01 20:47 ` [PATCH v3 net-next 4/6] xfrm: Check netif_is_alive() in xfrm_bundle_create() and xfrm_create_dummy_bundle() Kuniyuki Iwashima
2026-10-01 20:47 ` [PATCH v3 net-next 5/6] ipv4: Batch rt_flush_dev() in netdev_run_todo() Kuniyuki Iwashima
2026-10-04 23:02   ` netdev-bot+sashiko
2026-10-05  0:51     ` Kuniyuki Iwashima
2026-10-01 20:47 ` [PATCH v3 net-next 6/6] ipv6: Batch rt6_uncached_list_flush_dev() " Kuniyuki Iwashima
2026-10-04 23:02   ` netdev-bot+sashiko
2026-10-05  0:49     ` Kuniyuki Iwashima
2026-10-06  8:12 ` [PATCH v3 net-next 0/6] ip: Batch flushing uncached routes per batched device unregistration Ido Schimmel
2026-10-06 17:45   ` Kuniyuki Iwashima
2026-10-06 20:07 ` Chris Arges
2026-10-06 23:10 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001204752.2572265-2-kuniyu@google.com \
    --to=kuniyu@google.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=carges@cloudflare.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@kernel.org \
    --cc=fmancera@suse.de \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=kuba@kernel.org \
    --cc=kuni1840@gmail.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.