All of lore.kernel.org
 help / color / mirror / Atom feed
From: syzbot <syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Forwarded: [PATCH] netdevsim: update rxq->napi pointer during queue reset
Date: Thu, 13 Aug 2026 19:50:03 -0700	[thread overview]
Message-ID: <6a7e825b.ec5dc6cc.21cb3f.00c1.GAE@google.com> (raw)
In-Reply-To: <6a74a76c.ec7c9571.3ac9bb.0054.GAE@google.com>

For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.

***

Subject: [PATCH] netdevsim: update rxq->napi pointer during queue reset
Author: subasris1210@gmail.com

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git a59f57e2aa127c5354168d2ec4bac920df1be4f4

In netdevsim, when queue reset is performed using debugfs, it triggers
these sequence of operations: nsim_queue_stop() -> nsim_queue_start()
-> nsim_queue_mem_free(). nsim_queue_mem_free() frees the old
nsim_rq struct which embeds the napi_struct. But the rxq->napi pointer
in the struct netdev_rx_queue still points to the old nsim_rq's embedded
napi_struct. So, any subsequent xsk_bind() which reads rxq->napi->napi_id
after a queue reset is a use-after-free.

Add netif_queue_set_napi() calls to nsim_queue_stop() and
nsim_queue_start() which clears the rxq->napi during stop
and sets it to the new napi instance during start.

KASAN report:

Call Trace:
 kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
 xsk_bind+0x1582/0x16c0 net/xdp/xsk.c:1758
 __sys_bind_socket net/socket.c:1920 [inline]
 __sys_bind_socket net/socket.c:1912 [inline]
 __sys_bind+0x1a9/0x260 net/socket.c:1951

Allocated by task 5622:
 nsim_queue_alloc+0x3c/0x140 drivers/net/netdevsim/netdev.c:715
 nsim_queue_init drivers/net/netdevsim/netdev.c:1012 [inline]
 nsim_init_netdevsim drivers/net/netdevsim/netdev.c:1059 [inline]
 nsim_create+0xb13/0x1420 drivers/net/netdevsim/netdev.c:1152
 __nsim_dev_port_add+0x3ba/0x8f0 drivers/net/netdevsim/dev.c:1509
 nsim_dev_port_add_all drivers/net/netdevsim/dev.c:1570 [inline]
 nsim_drv_probe+0xdbd/0x13a0 drivers/net/netdevsim/dev.c:1731

Freed by task 5659:
 slab_free mm/slub.c:6377 [inline]
 kfree+0x22b/0x6c0 mm/slub.c:6692
 nsim_queue_mem_free+0xfe/0x190 drivers/net/netdevsim/netdev.c:796
 netdev_rx_queue_reconfig+0x405/0x630 net/core/netdev_rx_queue.c:144
 netdev_rx_queue_restart+0x8f/0xc0 net/core/netdev_rx_queue.c:183
 nsim_qreset_write+0x2e3/0x410 drivers/net/netdevsim/netdev.c:887

Reported-by: syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=c06674caba265dc61d46
Fixes: 5bc8e8dbef27 ("netdevsim: add queue management API support")
Tested-by: syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com
Signed-off-by: Subasri S <subasris1210@gmail.com>
---
 drivers/net/netdevsim/netdev.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/netdevsim/netdev.c b/drivers/net/netdevsim/netdev.c
index 4e9d7e10b527..291d34718b2e 100644
--- a/drivers/net/netdevsim/netdev.c
+++ b/drivers/net/netdevsim/netdev.c
@@ -808,6 +808,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg,
 
 	if (ns->rq_reset_mode == 1) {
 		ns->rq[idx]->page_pool = qmem->pp;
+		netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX,
+				     &ns->rq[idx]->napi);
 		napi_enable_locked(&ns->rq[idx]->napi);
 		return 0;
 	}
@@ -826,6 +828,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg,
 	}
 
 	ns->rq[idx] = qmem->rq;
+	netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX,
+			     &ns->rq[idx]->napi);
 	napi_enable_locked(&ns->rq[idx]->napi);
 
 	return 0;
@@ -838,6 +842,7 @@ static int nsim_queue_stop(struct net_device *dev, void *per_queue_mem, int idx)
 
 	netdev_assert_locked(dev);
 
+	netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX, NULL);
 	napi_disable_locked(&ns->rq[idx]->napi);
 
 	if (ns->rq_reset_mode == 1) {
-- 
2.43.0


      parent reply	other threads:[~2026-08-14  2:50 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 15:25 [syzbot] [net?] [bpf?] KASAN: slab-use-after-free Read in xsk_bind syzbot
2026-08-08  6:01 ` Forwarded: [PATCH] sync napi pointer during qreset syzbot
2026-08-08 10:51 ` syzbot
2026-08-14  2:50 ` syzbot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a7e825b.ec5dc6cc.21cb3f.00c1.GAE@google.com \
    --to=syzbot+c06674caba265dc61d46@syzkaller.appspotmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller-bugs@googlegroups.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.