* [PATCH net] net: bridge: mst: move switchdev call outside rcu
@ 2026-09-11 10:50 Nikolay Aleksandrov
2026-09-14 6:15 ` Ido Schimmel
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Nikolay Aleksandrov @ 2026-09-11 10:50 UTC (permalink / raw)
To: netdev
Cc: idosch, davem, edumazet, kuba, pabeni, horms, tobias, bridge,
Nikolay Aleksandrov
This is a follow-up of one of sashiko's pre-existing bug reports.
br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
while holding rcu_read_lock() which invokes the blocking switchdev
notifier chain and may sleep. Nonzero MSTI changes come from netlink
with rtnl held. Move the switchdev call before entering the rcu section and
assert that rtnl is held.
The call cannot be deferred because netlink needs its error and extack.
Also DSA reads the old bridge MST state during the callback and checks it.
A deferred callback will be late and will see the updated state.
Fixes: 7ae9147f4312 ("net: bridge: mst: Notify switchdev drivers of MST state changes")
Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
---
net/bridge/br_mst.c | 20 ++++++++++++--------
1 file changed, 12 insertions(+), 8 deletions(-)
diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c
index 43a300ae6bfa..ce537cb71fe8 100644
--- a/net/bridge/br_mst.c
+++ b/net/bridge/br_mst.c
@@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
struct net_bridge_vlan *v;
int err = 0;
- rcu_read_lock();
- vg = nbp_vlan_group_rcu(p);
- if (!vg)
- goto out;
-
/* MSTI 0 (CST) state changes are notified via the regular
- * SWITCHDEV_ATTR_ID_PORT_STP_STATE.
+ * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via
+ * netlink with RTNL held
*/
if (msti) {
+ ASSERT_RTNL();
+
err = switchdev_port_attr_set(p->dev, &attr, extack);
if (err && err != -EOPNOTSUPP)
goto out;
+ err = 0;
}
- err = 0;
+ rcu_read_lock();
+ vg = nbp_vlan_group_rcu(p);
+ if (!vg)
+ goto out_rcu_unlock;
+
list_for_each_entry_rcu(v, &vg->vlan_list, vlist) {
if (v->brvlan->msti != msti)
continue;
@@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state,
br_mst_vlan_set_state(vg, v, state);
}
-out:
+out_rcu_unlock:
rcu_read_unlock();
+out:
return err;
}
--
2.47.3
^ permalink raw reply related [flat|nested] 6+ messages in thread* Re: [PATCH net] net: bridge: mst: move switchdev call outside rcu
2026-09-11 10:50 [PATCH net] net: bridge: mst: move switchdev call outside rcu Nikolay Aleksandrov
@ 2026-09-14 6:15 ` Ido Schimmel
2026-09-15 10:23 ` Paolo Abeni
2026-09-15 10:30 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: Ido Schimmel @ 2026-09-14 6:15 UTC (permalink / raw)
To: Nikolay Aleksandrov
Cc: netdev, davem, edumazet, kuba, pabeni, horms, tobias, bridge
On Fri, Sep 11, 2026 at 01:50:21PM +0300, Nikolay Aleksandrov wrote:
> This is a follow-up of one of sashiko's pre-existing bug reports.
> br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
> while holding rcu_read_lock() which invokes the blocking switchdev
> notifier chain and may sleep. Nonzero MSTI changes come from netlink
> with rtnl held. Move the switchdev call before entering the rcu section and
> assert that rtnl is held.
>
> The call cannot be deferred because netlink needs its error and extack.
> Also DSA reads the old bridge MST state during the callback and checks it.
> A deferred callback will be late and will see the updated state.
>
> Fixes: 7ae9147f4312 ("net: bridge: mst: Notify switchdev drivers of MST state changes")
Nit: blaming 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free")
would be more accurate, but in practice it doesn't matter since this
commit blamed ec7328b59176 that is present in the same release as
7ae9147f4312.
> Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH net] net: bridge: mst: move switchdev call outside rcu
2026-09-11 10:50 [PATCH net] net: bridge: mst: move switchdev call outside rcu Nikolay Aleksandrov
2026-09-14 6:15 ` Ido Schimmel
@ 2026-09-15 10:23 ` Paolo Abeni
2026-09-15 10:25 ` Nikolay Aleksandrov
2026-09-15 10:30 ` patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Paolo Abeni @ 2026-09-15 10:23 UTC (permalink / raw)
To: Nikolay Aleksandrov, netdev
Cc: idosch, davem, edumazet, kuba, horms, tobias, bridge
On 9/11/26 12:50 PM, Nikolay Aleksandrov wrote:
> This is a follow-up of one of sashiko's pre-existing bug reports.
> br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
> while holding rcu_read_lock() which invokes the blocking switchdev
> notifier chain and may sleep. Nonzero MSTI changes come from netlink
> with rtnl held. Move the switchdev call before entering the rcu section and
> assert that rtnl is held.
>
> The call cannot be deferred because netlink needs its error and extack.
> Also DSA reads the old bridge MST state during the callback and checks it.
> A deferred callback will be late and will see the updated state.
>
> Fixes: 7ae9147f4312 ("net: bridge: mst: Notify switchdev drivers of MST state changes")
> Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
Clashiko noted that the fixes tag looks inaccurate, should be:
Fixes: 3a7c1661ae1383 ("net: bridge: mst: fix vlan use-after-free")
do you agree? I can fix the tag while applying the patch no need to repost.
/P
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH net] net: bridge: mst: move switchdev call outside rcu
2026-09-15 10:23 ` Paolo Abeni
@ 2026-09-15 10:25 ` Nikolay Aleksandrov
2026-09-15 10:26 ` Nikolay Aleksandrov
0 siblings, 1 reply; 6+ messages in thread
From: Nikolay Aleksandrov @ 2026-09-15 10:25 UTC (permalink / raw)
To: Paolo Abeni, netdev; +Cc: idosch, davem, edumazet, kuba, horms, tobias, bridge
On 15/09/2026 13:23, Paolo Abeni wrote:
> On 9/11/26 12:50 PM, Nikolay Aleksandrov wrote:
>> This is a follow-up of one of sashiko's pre-existing bug reports.
>> br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
>> while holding rcu_read_lock() which invokes the blocking switchdev
>> notifier chain and may sleep. Nonzero MSTI changes come from netlink
>> with rtnl held. Move the switchdev call before entering the rcu section and
>> assert that rtnl is held.
>>
>> The call cannot be deferred because netlink needs its error and extack.
>> Also DSA reads the old bridge MST state during the callback and checks it.
>> A deferred callback will be late and will see the updated state.
>>
>> Fixes: 7ae9147f4312 ("net: bridge: mst: Notify switchdev drivers of MST state changes")
>> Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
> Clashiko noted that the fixes tag looks inaccurate, should be:
>
> Fixes: 3a7c1661ae1383 ("net: bridge: mst: fix vlan use-after-free")
>
> do you agree? I can fix the tag while applying the patch no need to repost.
>
> /P
>
Yeah, I agree. As Ido also noted, that is the correct commit id but it is
from the same set. :)
Thank you for taking care of this.
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [PATCH net] net: bridge: mst: move switchdev call outside rcu
2026-09-15 10:25 ` Nikolay Aleksandrov
@ 2026-09-15 10:26 ` Nikolay Aleksandrov
0 siblings, 0 replies; 6+ messages in thread
From: Nikolay Aleksandrov @ 2026-09-15 10:26 UTC (permalink / raw)
To: Paolo Abeni, netdev; +Cc: idosch, davem, edumazet, kuba, horms, tobias, bridge
On 15/09/2026 13:25, Nikolay Aleksandrov wrote:
> On 15/09/2026 13:23, Paolo Abeni wrote:
>> On 9/11/26 12:50 PM, Nikolay Aleksandrov wrote:
>>> This is a follow-up of one of sashiko's pre-existing bug reports.
>>> br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
>>> while holding rcu_read_lock() which invokes the blocking switchdev
>>> notifier chain and may sleep. Nonzero MSTI changes come from netlink
>>> with rtnl held. Move the switchdev call before entering the rcu section and
>>> assert that rtnl is held.
>>>
>>> The call cannot be deferred because netlink needs its error and extack.
>>> Also DSA reads the old bridge MST state during the callback and checks it.
>>> A deferred callback will be late and will see the updated state.
>>>
>>> Fixes: 7ae9147f4312 ("net: bridge: mst: Notify switchdev drivers of MST state changes")
>>> Signed-off-by: Nikolay Aleksandrov <razor@blackwall.org>
>> Clashiko noted that the fixes tag looks inaccurate, should be:
>>
>> Fixes: 3a7c1661ae1383 ("net: bridge: mst: fix vlan use-after-free")
>>
>> do you agree? I can fix the tag while applying the patch no need to repost.
>>
>> /P
>>
>
> Yeah, I agree. As Ido also noted, that is the correct commit id but it is
> from the same set. :)
err, I meant same release
> Thank you for taking care of this.
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net] net: bridge: mst: move switchdev call outside rcu
2026-09-11 10:50 [PATCH net] net: bridge: mst: move switchdev call outside rcu Nikolay Aleksandrov
2026-09-14 6:15 ` Ido Schimmel
2026-09-15 10:23 ` Paolo Abeni
@ 2026-09-15 10:30 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-15 10:30 UTC (permalink / raw)
To: Nikolay Aleksandrov
Cc: netdev, idosch, davem, edumazet, kuba, pabeni, horms, tobias,
bridge
Hello:
This patch was applied to netdev/net.git (main)
by Paolo Abeni <pabeni@redhat.com>:
On Fri, 11 Sep 2026 13:50:21 +0300 you wrote:
> This is a follow-up of one of sashiko's pre-existing bug reports.
> br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs
> while holding rcu_read_lock() which invokes the blocking switchdev
> notifier chain and may sleep. Nonzero MSTI changes come from netlink
> with rtnl held. Move the switchdev call before entering the rcu section and
> assert that rtnl is held.
>
> [...]
Here is the summary with links:
- [net] net: bridge: mst: move switchdev call outside rcu
https://git.kernel.org/netdev/net/c/18a6fe05fb6e
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-09-15 10:31 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 10:50 [PATCH net] net: bridge: mst: move switchdev call outside rcu Nikolay Aleksandrov
2026-09-14 6:15 ` Ido Schimmel
2026-09-15 10:23 ` Paolo Abeni
2026-09-15 10:25 ` Nikolay Aleksandrov
2026-09-15 10:26 ` Nikolay Aleksandrov
2026-09-15 10:30 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox