From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 10AD75372FF; Wed, 23 Sep 2026 14:41:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174503; cv=none; b=MKczqTqRW0EqAXP89IBxpoXObpmb9BU+S765Dx992qCsa0xwwgMbIaNZmuYxCawWirhd+Z4R5an382lS5eMVBsEzz+1NarBtjRQfGJuDU9Qde1xSf97FcZ8gChDbvMZa+/qb6Ciyo7O8yl03gm0CUxNxL1TKSOHa9LFlFCo1Ci8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790174503; c=relaxed/simple; bh=7+gYXHqQl7JL+cOm3U34OU3WwJVcFH2zxgwx68gTCPs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OV26JJJFG2RXQxTym6zM9CyP5NNSg3tKgEgMz7uV9HG0iM20Sm9JY7kIkKdzS0nL0jqOm83p7B+4ofRnNx+GUJ4MHDv2/7a44+1mUeplSNudsh94hEEg3KJEiLxBVcwZgxsKND6jGPZB2XJgynmfphUEvQ0RItrAVB6j3TWOTmY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=FuMVXn2R; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="FuMVXn2R" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3D15F1F000FF; Wed, 23 Sep 2026 14:41:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790174501; bh=Ko1InH+6wcig7yxP+tJLJ96B0jRo5ljANAp+2VIeqio=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FuMVXn2R8bsZXO3pL/uyL1pgrWGft0JeV+bmc8UJg4jdqAbxKKbJmu9eczdsHlYn/ EHFs4tAV9RPheG3i47Wqt25J0Wqwh4rcJIvYVg6ScIY+/DllCgspSZM/uATNR0KPY1 u1nAEi4OtxGz1mmRksDfGX+HyzMdU6k0dvlLEdsw= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Nikolay Aleksandrov , Ido Schimmel , Paolo Abeni , Sasha Levin Subject: [PATCH 6.18 134/398] net: bridge: mst: move switchdev call outside rcu Date: Wed, 23 Sep 2026 16:03:28 +0200 Message-ID: <20260923140646.909008005@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Nikolay Aleksandrov [ Upstream commit 18a6fe05fb6e18de29fa90d388bb34044114b3d8 ] This is a follow-up of one of sashiko's pre-existing bug reports. br_mst_set_state() calls switchdev_port_attr_set() for nonzero MSTIs while holding rcu_read_lock() which invokes the blocking switchdev notifier chain and may sleep. Nonzero MSTI changes come from netlink with rtnl held. Move the switchdev call before entering the rcu section and assert that rtnl is held. The call cannot be deferred because netlink needs its error and extack. Also DSA reads the old bridge MST state during the callback and checks it. A deferred callback will be late and will see the updated state. Fixes: 3a7c1661ae13 ("net: bridge: mst: fix vlan use-after-free") Signed-off-by: Nikolay Aleksandrov Reviewed-by: Ido Schimmel Link: https://patch.msgid.link/20260911105021.1385934-1-razor@blackwall.org Signed-off-by: Paolo Abeni Signed-off-by: Sasha Levin --- net/bridge/br_mst.c | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/net/bridge/br_mst.c b/net/bridge/br_mst.c index 43a300ae6bfaf..1654efd3045b0 100644 --- a/net/bridge/br_mst.c +++ b/net/bridge/br_mst.c @@ -107,21 +107,24 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state, struct net_bridge_vlan *v; int err = 0; - rcu_read_lock(); - vg = nbp_vlan_group_rcu(p); - if (!vg) - goto out; - /* MSTI 0 (CST) state changes are notified via the regular - * SWITCHDEV_ATTR_ID_PORT_STP_STATE. + * SWITCHDEV_ATTR_ID_PORT_STP_STATE. All other MSTIs are handled via + * netlink with RTNL held */ if (msti) { + ASSERT_RTNL(); + err = switchdev_port_attr_set(p->dev, &attr, extack); if (err && err != -EOPNOTSUPP) goto out; + err = 0; } - err = 0; + rcu_read_lock(); + vg = nbp_vlan_group_rcu(p); + if (!vg) + goto out_rcu_unlock; + list_for_each_entry_rcu(v, &vg->vlan_list, vlist) { if (v->brvlan->msti != msti) continue; @@ -129,8 +132,9 @@ int br_mst_set_state(struct net_bridge_port *p, u16 msti, u8 state, br_mst_vlan_set_state(vg, v, state); } -out: +out_rcu_unlock: rcu_read_unlock(); +out: return err; } -- 2.53.0