Netdev List
 help / color / mirror / Atom feed
* [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info()
@ 2026-09-16 11:19 Eric Dumazet
  2026-09-16 12:54 ` Daniel Borkmann
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-09-16 11:19 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, Kuniyuki Iwashima, Andrew Lunn, netdev,
	eric.dumazet, Eric Dumazet, Daniel Borkmann, Nikolay Aleksandrov

netkit_fill_info() used rtnl_dereference() to fetch nk->peer,
and thus required RTNL.

nk->peer is already an RCU protected pointer, updated with
rcu_assign_pointer() and read from the fast path with
rcu_dereference(). Simply use rcu_dereference() under
rcu_read_lock() instead.

While at it, use READ_ONCE() when reading nk->policy, because
netkit_change_link() can change it at any time (it already uses
WRITE_ONCE()).

Other fields (primary, mode, pair, scrub) are only set from
netkit_new_link(), before the device is visible to dumps.

Also add missing const qualifiers.

Signed-off-by: Eric Dumazet <edumazet@google.com>
---
Cc: Daniel Borkmann <daniel@iogearbox.net>
Cc: Nikolay Aleksandrov <razor@blackwall.org>
---
 drivers/net/netkit.c | 17 +++++++++++------
 1 file changed, 11 insertions(+), 6 deletions(-)

diff --git a/drivers/net/netkit.c b/drivers/net/netkit.c
index a3931cd821321c3e4888edf86efc414199127bcf..82e608e733d9ee70f71c374570211c73da76ae2c 100644
--- a/drivers/net/netkit.c
+++ b/drivers/net/netkit.c
@@ -1209,12 +1209,12 @@ static size_t netkit_get_size(const struct net_device *dev)
 
 static int netkit_fill_info(struct sk_buff *skb, const struct net_device *dev)
 {
-	struct netkit *nk = netkit_priv(dev);
-	struct net_device *peer = rtnl_dereference(nk->peer);
+	const struct netkit *nk = netkit_priv(dev);
+	const struct net_device *peer;
 
 	if (nla_put_u8(skb, IFLA_NETKIT_PRIMARY, nk->primary))
 		return -EMSGSIZE;
-	if (nla_put_u32(skb, IFLA_NETKIT_POLICY, nk->policy))
+	if (nla_put_u32(skb, IFLA_NETKIT_POLICY, READ_ONCE(nk->policy)))
 		return -EMSGSIZE;
 	if (nla_put_u32(skb, IFLA_NETKIT_MODE, nk->mode))
 		return -EMSGSIZE;
@@ -1228,13 +1228,18 @@ static int netkit_fill_info(struct sk_buff *skb, const struct net_device *dev)
 	if (nla_put_u32(skb, IFLA_NETKIT_PAIRING, nk->pair))
 		return -EMSGSIZE;
 
+	rcu_read_lock();
+	peer = rcu_dereference(nk->peer);
 	if (peer) {
 		nk = netkit_priv(peer);
-		if (nla_put_u32(skb, IFLA_NETKIT_PEER_POLICY, nk->policy))
-			return -EMSGSIZE;
-		if (nla_put_u32(skb, IFLA_NETKIT_PEER_SCRUB, nk->scrub))
+		if (nla_put_u32(skb, IFLA_NETKIT_PEER_POLICY,
+				READ_ONCE(nk->policy)) ||
+		    nla_put_u32(skb, IFLA_NETKIT_PEER_SCRUB, nk->scrub)) {
+			rcu_read_unlock();
 			return -EMSGSIZE;
+		}
 	}
+	rcu_read_unlock();
 
 	return 0;
 }
-- 
2.55.0.1032.g73a4cd73de-goog


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info()
  2026-09-16 11:19 [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info() Eric Dumazet
@ 2026-09-16 12:54 ` Daniel Borkmann
  2026-09-16 13:33 ` Nikolay Aleksandrov
  2026-09-18  0:00 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Daniel Borkmann @ 2026-09-16 12:54 UTC (permalink / raw)
  To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, Kuniyuki Iwashima, Andrew Lunn, netdev,
	eric.dumazet, Nikolay Aleksandrov

On 9/16/26 1:19 PM, Eric Dumazet wrote:
> netkit_fill_info() used rtnl_dereference() to fetch nk->peer,
> and thus required RTNL.
> 
> nk->peer is already an RCU protected pointer, updated with
> rcu_assign_pointer() and read from the fast path with
> rcu_dereference(). Simply use rcu_dereference() under
> rcu_read_lock() instead.
> 
> While at it, use READ_ONCE() when reading nk->policy, because
> netkit_change_link() can change it at any time (it already uses
> WRITE_ONCE()).
> 
> Other fields (primary, mode, pair, scrub) are only set from
> netkit_new_link(), before the device is visible to dumps.
> 
> Also add missing const qualifiers.
> 
> Signed-off-by: Eric Dumazet <edumazet@google.com>

Acked-by: Daniel Borkmann <daniel@iogearbox.net>

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info()
  2026-09-16 11:19 [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info() Eric Dumazet
  2026-09-16 12:54 ` Daniel Borkmann
@ 2026-09-16 13:33 ` Nikolay Aleksandrov
  2026-09-18  0:00 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: Nikolay Aleksandrov @ 2026-09-16 13:33 UTC (permalink / raw)
  To: Eric Dumazet, David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, Kuniyuki Iwashima, Andrew Lunn, netdev,
	eric.dumazet, Daniel Borkmann

On 16/09/2026 14:19, Eric Dumazet wrote:
> netkit_fill_info() used rtnl_dereference() to fetch nk->peer,
> and thus required RTNL.
> 
> nk->peer is already an RCU protected pointer, updated with
> rcu_assign_pointer() and read from the fast path with
> rcu_dereference(). Simply use rcu_dereference() under
> rcu_read_lock() instead.
> 
> While at it, use READ_ONCE() when reading nk->policy, because
> netkit_change_link() can change it at any time (it already uses
> WRITE_ONCE()).
> 
> Other fields (primary, mode, pair, scrub) are only set from
> netkit_new_link(), before the device is visible to dumps.
> 
> Also add missing const qualifiers.
> 
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> ---
> Cc: Daniel Borkmann <daniel@iogearbox.net>
> Cc: Nikolay Aleksandrov <razor@blackwall.org>
> ---
>   drivers/net/netkit.c | 17 +++++++++++------
>   1 file changed, 11 insertions(+), 6 deletions(-)
> 
> diff --git a/drivers/net/netkit.c b/drivers/net/netkit.c
> index a3931cd821321c3e4888edf86efc414199127bcf..82e608e733d9ee70f71c374570211c73da76ae2c 100644
> --- a/drivers/net/netkit.c
> +++ b/drivers/net/netkit.c
> @@ -1209,12 +1209,12 @@ static size_t netkit_get_size(const struct net_device *dev)
>   
>   static int netkit_fill_info(struct sk_buff *skb, const struct net_device *dev)
>   {
> -	struct netkit *nk = netkit_priv(dev);
> -	struct net_device *peer = rtnl_dereference(nk->peer);
> +	const struct netkit *nk = netkit_priv(dev);
> +	const struct net_device *peer;
>   
>   	if (nla_put_u8(skb, IFLA_NETKIT_PRIMARY, nk->primary))
>   		return -EMSGSIZE;
> -	if (nla_put_u32(skb, IFLA_NETKIT_POLICY, nk->policy))
> +	if (nla_put_u32(skb, IFLA_NETKIT_POLICY, READ_ONCE(nk->policy)))
>   		return -EMSGSIZE;
>   	if (nla_put_u32(skb, IFLA_NETKIT_MODE, nk->mode))
>   		return -EMSGSIZE;
> @@ -1228,13 +1228,18 @@ static int netkit_fill_info(struct sk_buff *skb, const struct net_device *dev)
>   	if (nla_put_u32(skb, IFLA_NETKIT_PAIRING, nk->pair))
>   		return -EMSGSIZE;
>   
> +	rcu_read_lock();
> +	peer = rcu_dereference(nk->peer);
>   	if (peer) {
>   		nk = netkit_priv(peer);
> -		if (nla_put_u32(skb, IFLA_NETKIT_PEER_POLICY, nk->policy))
> -			return -EMSGSIZE;
> -		if (nla_put_u32(skb, IFLA_NETKIT_PEER_SCRUB, nk->scrub))
> +		if (nla_put_u32(skb, IFLA_NETKIT_PEER_POLICY,
> +				READ_ONCE(nk->policy)) ||
> +		    nla_put_u32(skb, IFLA_NETKIT_PEER_SCRUB, nk->scrub)) {
> +			rcu_read_unlock();
>   			return -EMSGSIZE;
> +		}
>   	}
> +	rcu_read_unlock();
>   
>   	return 0;
>   }

Thanks!
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info()
  2026-09-16 11:19 [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info() Eric Dumazet
  2026-09-16 12:54 ` Daniel Borkmann
  2026-09-16 13:33 ` Nikolay Aleksandrov
@ 2026-09-18  0:00 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-18  0:00 UTC (permalink / raw)
  To: Eric Dumazet
  Cc: davem, kuba, pabeni, horms, kuniyu, andrew+netdev, netdev,
	eric.dumazet, daniel, razor

Hello:

This patch was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed, 16 Sep 2026 11:19:53 +0000 you wrote:
> netkit_fill_info() used rtnl_dereference() to fetch nk->peer,
> and thus required RTNL.
> 
> nk->peer is already an RCU protected pointer, updated with
> rcu_assign_pointer() and read from the fast path with
> rcu_dereference(). Simply use rcu_dereference() under
> rcu_read_lock() instead.
> 
> [...]

Here is the summary with links:
  - [net-next] netkit: no longer rely on RTNL in netkit_fill_info()
    https://git.kernel.org/netdev/net-next/c/aea70e81be7f

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-18  0:01 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 11:19 [PATCH net-next] netkit: no longer rely on RTNL in netkit_fill_info() Eric Dumazet
2026-09-16 12:54 ` Daniel Borkmann
2026-09-16 13:33 ` Nikolay Aleksandrov
2026-09-18  0:00 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox