* [PATCH net-next 1/2] hsr: annotate data-race around hsr->sequence_nr
2026-09-16 13:28 [PATCH net-next 0/2] hsr: lockless hsr_fill_info() Eric Dumazet
@ 2026-09-16 13:28 ` Eric Dumazet
2026-09-16 13:28 ` [PATCH net-next 2/2] hsr: no longer rely on RTNL in hsr_fill_info() Eric Dumazet
2026-09-19 0:10 ` [PATCH net-next 0/2] hsr: lockless hsr_fill_info() patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-09-16 13:28 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Kuniyuki Iwashima, Andrew Lunn, netdev,
eric.dumazet, Eric Dumazet
hsr->sequence_nr is incremented from the transmit paths under
hsr->seqnr_lock, but hsr_fill_info() reads it without holding
this lock.
Use WRITE_ONCE() in the two writers, so that a matching
READ_ONCE() can be used in hsr_fill_info().
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
net/hsr/hsr_device.c | 2 +-
net/hsr/hsr_forward.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/hsr/hsr_device.c b/net/hsr/hsr_device.c
index d14de44e14b7a9f451cf24fdd20b70d77eb623b7..fc512204600cd83b08bcaaff28bcaf44ea044f1d 100644
--- a/net/hsr/hsr_device.c
+++ b/net/hsr/hsr_device.c
@@ -333,7 +333,7 @@ static void send_hsr_supervision_frame(struct hsr_port *port,
hsr->sup_sequence_nr++;
} else {
hsr_stag->sequence_nr = htons(hsr->sequence_nr);
- hsr->sequence_nr++;
+ WRITE_ONCE(hsr->sequence_nr, hsr->sequence_nr + 1);
}
hsr_stag->tlv.HSR_TLV_type = type;
diff --git a/net/hsr/hsr_forward.c b/net/hsr/hsr_forward.c
index 7734a521a96c23f6a9c18c03ae239fb12e55bee0..44f6d9c83180a6316b06afef1af9bbdb2e340f75 100644
--- a/net/hsr/hsr_forward.c
+++ b/net/hsr/hsr_forward.c
@@ -645,7 +645,7 @@ static void handle_std_frame(struct sk_buff *skb,
/* Sequence nr for the master/interlink node */
lockdep_assert_held(&hsr->seqnr_lock);
frame->sequence_nr = hsr->sequence_nr;
- hsr->sequence_nr++;
+ WRITE_ONCE(hsr->sequence_nr, hsr->sequence_nr + 1);
}
}
--
2.55.0.1032.g73a4cd73de-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH net-next 2/2] hsr: no longer rely on RTNL in hsr_fill_info()
2026-09-16 13:28 [PATCH net-next 0/2] hsr: lockless hsr_fill_info() Eric Dumazet
2026-09-16 13:28 ` [PATCH net-next 1/2] hsr: annotate data-race around hsr->sequence_nr Eric Dumazet
@ 2026-09-16 13:28 ` Eric Dumazet
2026-09-19 0:10 ` [PATCH net-next 0/2] hsr: lockless hsr_fill_info() patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: Eric Dumazet @ 2026-09-16 13:28 UTC (permalink / raw)
To: David S . Miller, Jakub Kicinski, Paolo Abeni
Cc: Simon Horman, Kuniyuki Iwashima, Andrew Lunn, netdev,
eric.dumazet, Eric Dumazet
hsr_fill_info() used hsr_port_get_hsr(), which walks hsr->ports
with hsr_for_each_port_rtnl(), forcing "ip link show" dumps to
hold RTNL.
hsr->ports is an RCU protected list: ports are added with
list_add_tail_rcu(), removed with list_del_rcu() and freed with
kfree_rcu(), and the data path already iterates over it with
hsr_for_each_port().
Add a local RCU variant of hsr_port_get_hsr() and use it from
hsr_fill_info() under rcu_read_lock().
The remaining fields (sup_multicast_addr, prot_version) are set
once at device creation. hsr->sequence_nr is now read with
READ_ONCE(), since the transmit paths increment it under
hsr->seqnr_lock only.
Also add missing const qualifiers.
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
net/hsr/hsr_netlink.c | 35 ++++++++++++++++++++++++++---------
1 file changed, 26 insertions(+), 9 deletions(-)
diff --git a/net/hsr/hsr_netlink.c b/net/hsr/hsr_netlink.c
index 88940e8014b24f35d6a54f49fb7ac82956aed383..fc7820eae884132dbd5f4e62a4397d2c6d1bf79d 100644
--- a/net/hsr/hsr_netlink.c
+++ b/net/hsr/hsr_netlink.c
@@ -147,44 +147,61 @@ static void hsr_dellink(struct net_device *dev, struct list_head *head)
unregister_netdevice_queue(dev, head);
}
+/* RCU variant of hsr_port_get_hsr() */
+static struct hsr_port *hsr_port_get_hsr_rcu(const struct hsr_priv *hsr,
+ enum hsr_port_type pt)
+{
+ struct hsr_port *port;
+
+ hsr_for_each_port(hsr, port)
+ if (port->type == pt)
+ return port;
+ return NULL;
+}
+
static int hsr_fill_info(struct sk_buff *skb, const struct net_device *dev)
{
- struct hsr_priv *hsr = netdev_priv(dev);
+ const struct hsr_priv *hsr = netdev_priv(dev);
+ const struct hsr_port *port;
u8 proto = HSR_PROTOCOL_HSR;
- struct hsr_port *port;
- port = hsr_port_get_hsr(hsr, HSR_PT_SLAVE_A);
+ rcu_read_lock();
+
+ port = hsr_port_get_hsr_rcu(hsr, HSR_PT_SLAVE_A);
if (port) {
if (nla_put_u32(skb, IFLA_HSR_SLAVE1, port->dev->ifindex))
goto nla_put_failure;
}
- port = hsr_port_get_hsr(hsr, HSR_PT_SLAVE_B);
+ port = hsr_port_get_hsr_rcu(hsr, HSR_PT_SLAVE_B);
if (port) {
if (nla_put_u32(skb, IFLA_HSR_SLAVE2, port->dev->ifindex))
goto nla_put_failure;
}
- port = hsr_port_get_hsr(hsr, HSR_PT_INTERLINK);
+ port = hsr_port_get_hsr_rcu(hsr, HSR_PT_INTERLINK);
if (port) {
if (nla_put_u32(skb, IFLA_HSR_INTERLINK, port->dev->ifindex))
goto nla_put_failure;
}
+ rcu_read_unlock();
+
if (nla_put(skb, IFLA_HSR_SUPERVISION_ADDR, ETH_ALEN,
hsr->sup_multicast_addr) ||
- nla_put_u16(skb, IFLA_HSR_SEQ_NR, hsr->sequence_nr))
- goto nla_put_failure;
+ nla_put_u16(skb, IFLA_HSR_SEQ_NR, READ_ONCE(hsr->sequence_nr)))
+ return -EMSGSIZE;
if (hsr->prot_version == PRP_V1)
proto = HSR_PROTOCOL_PRP;
else if (nla_put_u8(skb, IFLA_HSR_VERSION, hsr->prot_version))
- goto nla_put_failure;
+ return -EMSGSIZE;
if (nla_put_u8(skb, IFLA_HSR_PROTOCOL, proto))
- goto nla_put_failure;
+ return -EMSGSIZE;
return 0;
nla_put_failure:
+ rcu_read_unlock();
return -EMSGSIZE;
}
--
2.55.0.1032.g73a4cd73de-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH net-next 0/2] hsr: lockless hsr_fill_info()
2026-09-16 13:28 [PATCH net-next 0/2] hsr: lockless hsr_fill_info() Eric Dumazet
2026-09-16 13:28 ` [PATCH net-next 1/2] hsr: annotate data-race around hsr->sequence_nr Eric Dumazet
2026-09-16 13:28 ` [PATCH net-next 2/2] hsr: no longer rely on RTNL in hsr_fill_info() Eric Dumazet
@ 2026-09-19 0:10 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 4+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-19 0:10 UTC (permalink / raw)
To: Eric Dumazet
Cc: davem, kuba, pabeni, horms, kuniyu, andrew+netdev, netdev,
eric.dumazet
Hello:
This series was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Wed, 16 Sep 2026 13:28:20 +0000 you wrote:
> hsr_fill_info() currently relies on RTNL being held, because
> hsr_port_get_hsr() walks hsr->ports with hsr_for_each_port_rtnl().
>
> - Patch 1 annotates the data-race around hsr->sequence_nr, which
> is incremented from the transmit paths under hsr->seqnr_lock but
> read without it.
>
> [...]
Here is the summary with links:
- [net-next,1/2] hsr: annotate data-race around hsr->sequence_nr
https://git.kernel.org/netdev/net-next/c/41c57cf05068
- [net-next,2/2] hsr: no longer rely on RTNL in hsr_fill_info()
https://git.kernel.org/netdev/net-next/c/9f8b888ced9d
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 4+ messages in thread