All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jay Vosburgh <jv@jvosburgh.net>
To: Eric Dumazet <edumazet@google.com>
Cc: "David S . Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	netdev@vger.kernel.org, eric.dumazet@gmail.com
Subject: Re: [PATCH net] bonding: do not clear curr_active_slave prematurely when releasing all slaves
Date: Tue, 01 Sep 2026 17:16:45 -0700	[thread overview]
Message-ID: <588602.1788308205@famine> (raw)
In-Reply-To: <20260831203042.164466-1-edumazet@google.com>

Eric Dumazet <edumazet@google.com> wrote:

>When releasing all slaves during bond destruction (all == true),
>__bond_release_one() unconditionally clears bond->curr_active_slave to
>NULL in every iteration.
>
>If a backup slave is released before the active slave,
>bond_alb_deinit_slave() triggers rlb_teach_disabled_mac_on_primary(),
>which increments the active slave dev promiscuity counter and sets
>bond_info->primary_is_promisc = 1.
>
>Because bond->curr_active_slave was prematurely cleared to NULL when
>releasing the backup slave, the subsequent iteration releasing the active
>slave evaluates oldcurrent as NULL, so bond_change_active_slave(bond, NULL)
>is skipped. Consequently, bond_alb_handle_active_change() is never called
>to decrement the promiscuity counter, permanently leaking promiscuous
>mode on the physical device after bond teardown.
>
>When oldcurrent == slave, bond_change_active_slave(bond, NULL) already sets
>bond->curr_active_slave to NULL. We only need to avoid selecting a new
>active slave when all == true. Replace the if (all) branch with
>if (!all && oldcurrent == slave).
>
>Fixes: 0896341a44bf ("bonding: fix bond_release_all inconsistencies")
>Signed-off-by: Eric Dumazet <edumazet@google.com>

	Complicated failure path, but looks correct.

Acked-by: Jay Vosburgh <jv@jvosburgh.net>

	-J


>---
>Cc: Jay Vosburgh <jv@jvosburgh.net>
>---
> drivers/net/bonding/bond_main.c | 4 +---
> 1 file changed, 1 insertion(+), 3 deletions(-)
>
>diff --git a/drivers/net/bonding/bond_main.c b/drivers/net/bonding/bond_main.c
>index c23cf18a996a..1e5ab3454872 100644
>--- a/drivers/net/bonding/bond_main.c
>+++ b/drivers/net/bonding/bond_main.c
>@@ -2517,9 +2517,7 @@ static int __bond_release_one(struct net_device *bond_dev,
> 		bond_alb_deinit_slave(bond, slave);
> 	}
> 
>-	if (all) {
>-		RCU_INIT_POINTER(bond->curr_active_slave, NULL);
>-	} else if (oldcurrent == slave) {
>+	if (!all && oldcurrent == slave) {
> 		/* Note that we hold RTNL over this sequence, so there
> 		 * is no concern that another slave add/remove event
> 		 * will interfere.
>-- 
>2.55.0.970.g62bdec98f9-goog
>

---
	-Jay Vosburgh, jv@jvosburgh.net

  reply	other threads:[~2026-09-02  0:16 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 20:30 [PATCH net] bonding: do not clear curr_active_slave prematurely when releasing all slaves Eric Dumazet
2026-09-02  0:16 ` Jay Vosburgh [this message]
2026-09-02  7:40 ` Nikolay Aleksandrov
2026-09-03  1:30 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=588602.1788308205@famine \
    --to=jv@jvosburgh.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=eric.dumazet@gmail.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.