BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Vaibhav Nagare" <vnagare@redhat.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net v2] bnxt_en: don't leave an XDP program installed when the open fails
Date: Thu, 01 Oct 2026 07:09:27 +0000	[thread overview]
Message-ID: <20261001070927.EF93A1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930070901.1218980-1-vnagare@redhat.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: bnxt_en XDP detach memory leak and state desynchronization on NIC open failure
--

commit a5efe83c5d84fe92f5143236d2e982d0ce3eaec4
Author: Vaibhav Nagare <vnagare@redhat.com>

bnxt_en: don't leave an XDP program installed when the open fails

This commit restores the previous XDP program and ring configuration when
bnxt_open_nic() fails. This prevents the driver from leaving a freed program
in bp->xdp_prog on a failed XDP update.

Cc: stable@vger.kernel.org

> diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c b/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c
> index 9e5009be8e989..edfd751a601ab 100644
> --- a/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c
> +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c
[ ... ]
> @@ -418,25 +438,21 @@ static int bnxt_xdp_set(struct bnxt *bp, struct bpf_prog *prog)
>  	if (netif_running(dev))
>  		bnxt_close_nic(bp, true, false);
>  
> +	old_tx_xdp = bp->tx_nr_rings_xdp;
>  	old = xchg(&bp->xdp_prog, prog);
> +	bnxt_xdp_apply_cfg(bp, tx_xdp);
> +
> +	if (netif_running(dev)) {
> +		rc = bnxt_open_nic(bp, true, false);
> +		if (rc) {
> +			WRITE_ONCE(bp->xdp_prog, old);
> +			bnxt_xdp_apply_cfg(bp, old_tx_xdp);
> +			return rc;

[Severity: High]
Does this error path introduce a memory leak and state desynchronization if
the user was trying to detach the XDP program?

If bnxt_open_nic() fails during a detach operation where prog is NULL, the
core stack's dev_xdp_detach_link() ignores the error returned by the driver
and forcefully unlinks the program anyway:

net/core/dev.c:dev_xdp_detach_link() {
    ...
    WARN_ON(dev_xdp_install(dev, mode, bpf_op, NULL, 0, NULL));
    dev_xdp_set_link(dev, mode, NULL);
    ...
}

Because this error path restores old to bp->xdp_prog and returns early
without calling bpf_prog_put(old), does the driver maintain a leaked
reference to the BPF program? 

Would this cause the driver to continue executing a 'detached' XDP program
when the NIC is brought up later, while the core stack considers it fully
detached?

> +		}
>  	}
>  
> -	if (old)
> -		bpf_prog_put(old);
>  
>  	return 0;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930070901.1218980-1-vnagare@redhat.com?part=1

  reply	other threads:[~2026-10-01  7:09 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  7:09 [PATCH net v2] bnxt_en: don't leave an XDP program installed when the open fails Vaibhav Nagare
2026-10-01  7:09 ` sashiko-bot [this message]
2026-10-04  7:23 ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261001070927.EF93A1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=vnagare@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox