Linux s390 Architecture development
 help / color / mirror / Atom feed
* [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev()
       [not found] <arn3qTu_SeM8Yrjj@1wt.eu>
@ 2026-09-28  6:24 ` Atharva Vartak
  2026-09-28  6:31   ` netdev-bot+sinfo
                     ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Atharva Vartak @ 2026-09-28  6:24 UTC (permalink / raw)
  To: security
  Cc: alibuda, dust.li, mjambigi, sidraya, w, tonylu, guwen, linux-rdma,
	linux-s390, netdev

pnet_find_base_ndev() resolves the base net_device for stacked devices
under RTNL, then drops the lock and returns the raw pointer without
taking a reference.  All three callers dereference the pointer after
RTNL has been released, creating a use-after-free window if the device
is concurrently unregistered.

Take dev_hold() before dropping RTNL and add the matching dev_put() in
every return path of the three callers:

  - smc_pnet_add_eth()
  - smc_pnet_find_roce_by_pnetid()
  - smc_pnet_find_ism_by_pnetid()

Fixes: 0afff91c6f5e ("net/smc: add pnetid support")
Fixes: 1619f770589a ("net/smc: add pnetid support for SMC-D and ISM")
Cc: "D. Wythe" <alibuda@linux.alibaba.com>
Cc: Dust Li <dust.li@linux.alibaba.com>
Cc: Sidraya Jayagond <sidraya@linux.ibm.com>
Cc: Mahanta Jambigi <mjambigi@linux.ibm.com>
Cc: Tony Lu <tonylu@linux.alibaba.com>
Cc: Wen Gu <guwen@linux.alibaba.com>
Cc: Willy Tarreau <w@1wt.eu>
Cc: linux-rdma@vger.kernel.org
Cc: linux-s390@vger.kernel.org
Cc: netdev@vger.kernel.org
Signed-off-by: Atharva Vartak <atharva.a.vartak@gmail.com>
---
Apologies for not Cc'ing the maintainers on the initial report, will
follow the process properly going forward.

Based on v7.3-rc5. Passes checkpatch and compiles cleanly.

 net/smc/smc_pnet.c | 14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

diff --git a/net/smc/smc_pnet.c b/net/smc/smc_pnet.c
index ff9c9c35c..d6e2f4454 100644
--- a/net/smc/smc_pnet.c
+++ b/net/smc/smc_pnet.c
@@ -367,8 +367,11 @@ static int smc_pnet_add_eth(struct smc_pnettable *pnettable, struct net *net,
 	if (ndev) {
 		base_ndev = pnet_find_base_ndev(ndev);
 		if (!smc_pnetid_by_dev_port(base_ndev->dev.parent,
-					    base_ndev->dev_port, ndev_pnetid))
+					    base_ndev->dev_port, ndev_pnetid)) {
+			dev_put(base_ndev);
 			goto out_put;
+		}
+		dev_put(base_ndev);
 	}
 
 	/* add a new netdev entry to the pnet table if there isn't one */
@@ -949,6 +952,8 @@ static struct net_device *pnet_find_base_ndev(struct net_device *ndev)
 {
 	rtnl_lock();
 	ndev = __pnet_find_base_ndev(ndev);
+	/* keep ndev alive after dropping RTNL, callers must dev_put() */
+	dev_hold(ndev);
 	rtnl_unlock();
 	return ndev;
 }
@@ -1094,8 +1099,10 @@ static void smc_pnet_find_roce_by_pnetid(struct net_device *ndev,
 	    smc_pnet_find_ndev_pnetid_by_table(base_ndev, ndev_pnetid) &&
 	    smc_pnet_find_ndev_pnetid_by_table(ndev, ndev_pnetid)) {
 		smc_pnet_find_rdma_dev(base_ndev, ini);
+		dev_put(base_ndev);
 		return; /* pnetid could not be determined */
 	}
+	dev_put(base_ndev);
 	_smc_pnet_find_roce_by_pnetid(ndev_pnetid, ini, NULL, net);
 }
 
@@ -1108,8 +1115,10 @@ static void smc_pnet_find_ism_by_pnetid(struct net_device *ndev,
 	ndev = pnet_find_base_ndev(ndev);
 	if (smc_pnetid_by_dev_port(ndev->dev.parent, ndev->dev_port,
 				   ndev_pnetid) &&
-	    smc_pnet_find_ndev_pnetid_by_table(ndev, ndev_pnetid))
+	    smc_pnet_find_ndev_pnetid_by_table(ndev, ndev_pnetid)) {
+		dev_put(ndev);
 		return; /* pnetid could not be determined */
+	}
 
 	mutex_lock(&smcd_dev_list.mutex);
 	list_for_each_entry(ismdev, &smcd_dev_list.list, list) {
@@ -1123,6 +1132,7 @@ static void smc_pnet_find_ism_by_pnetid(struct net_device *ndev,
 		}
 	}
 	mutex_unlock(&smcd_dev_list.mutex);
+	dev_put(ndev);
 }
 
 /* PNET table analysis for a given sock:
-- 
2.54.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev()
  2026-09-28  6:24 ` [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev() Atharva Vartak
@ 2026-09-28  6:31   ` netdev-bot+sinfo
  2026-09-28  6:37   ` sashiko-bot
  2026-10-02  0:13   ` Jakub Kicinski
  2 siblings, 0 replies; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28  6:31 UTC (permalink / raw)
  To: Atharva Vartak
  Cc: security, alibuda, dust.li, mjambigi, sidraya, w, tonylu, guwen,
	linux-rdma, linux-s390, netdev

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - How the issue was discovered, e.g. hit in production, hit during
   development, syzbot report, manual code inspection, LLM or static
   analysis tool scan.

 - Whether the issue was actually triggered, or is only theoretical
   (e.g. found by code inspection). If it was triggered please include
   the symptoms, like the stack trace or error messages.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev()
  2026-09-28  6:24 ` [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev() Atharva Vartak
  2026-09-28  6:31   ` netdev-bot+sinfo
@ 2026-09-28  6:37   ` sashiko-bot
  2026-10-02  0:13   ` Jakub Kicinski
  2 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-28  6:37 UTC (permalink / raw)
  To: Atharva Vartak
  Cc: Heiko Carstens, Vasily Gorbik, linux-s390, linux-rdma,
	Alexander Gordeev, Christian Borntraeger

> pnet_find_base_ndev() resolves the base net_device for stacked devices
> under RTNL, then drops the lock and returns the raw pointer without
> taking a reference.  All three callers dereference the pointer after
> RTNL has been released, creating a use-after-free window if the device
> is concurrently unregistered.
> 
> Take dev_hold() before dropping RTNL and add the matching dev_put() in
> every return path of the three callers:
> 
>   - smc_pnet_add_eth()
>   - smc_pnet_find_roce_by_pnetid()
>   - smc_pnet_find_ism_by_pnetid()
> 
> Fixes: 0afff91c6f5e ("net/smc: add pnetid support")
> Fixes: 1619f770589a ("net/smc: add pnetid support for SMC-D and ISM")
> Cc: "D. Wythe" <alibuda@linux.alibaba.com>
> Cc: Dust Li <dust.li@linux.alibaba.com>
> Cc: Sidraya Jayagond <sidraya@linux.ibm.com>
> Cc: Mahanta Jambigi <mjambigi@linux.ibm.com>
> Cc: Tony Lu <tonylu@linux.alibaba.com>
> Cc: Wen Gu <guwen@linux.alibaba.com>
> Cc: Willy Tarreau <w@1wt.eu>
> Cc: linux-rdma@vger.kernel.org
> Cc: linux-s390@vger.kernel.org
> Cc: netdev@vger.kernel.org
> Signed-off-by: Atharva Vartak <atharva.a.vartak@gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/6aba080c.b933486d.297b72.5042@mx.google.com?part=1


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev()
  2026-09-28  6:24 ` [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev() Atharva Vartak
  2026-09-28  6:31   ` netdev-bot+sinfo
  2026-09-28  6:37   ` sashiko-bot
@ 2026-10-02  0:13   ` Jakub Kicinski
  2 siblings, 0 replies; 4+ messages in thread
From: Jakub Kicinski @ 2026-10-02  0:13 UTC (permalink / raw)
  To: Atharva Vartak
  Cc: security, alibuda, dust.li, mjambigi, sidraya, w, tonylu, guwen,
	linux-rdma, linux-s390, netdev

On Sun, 27 Sep 2026 23:24:12 -0700 (PDT) Atharva Vartak wrote:
> @@ -949,6 +952,8 @@ static struct net_device *pnet_find_base_ndev(struct net_device *ndev)
>  {
>  	rtnl_lock();
>  	ndev = __pnet_find_base_ndev(ndev);
> +	/* keep ndev alive after dropping RTNL, callers must dev_put() */
> +	dev_hold(ndev);
>  	rtnl_unlock();
>  	return ndev;

dev_hold() is deprecated, please use netdev_hold() with a correctly
populated ref tracker.
-- 
pw-bot: cr

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-02  0:13 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <arn3qTu_SeM8Yrjj@1wt.eu>
2026-09-28  6:24 ` [PATCH] net/smc: hold a reference on net_device returned by pnet_find_base_ndev() Atharva Vartak
2026-09-28  6:31   ` netdev-bot+sinfo
2026-09-28  6:37   ` sashiko-bot
2026-10-02  0:13   ` Jakub Kicinski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox