From: Simon Horman <horms@kernel.org>
To: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Cc: intel-wired-lan@lists.osuosl.org, anthony.l.nguyen@intel.com,
netdev@vger.kernel.org, Kiran Patil <kiran.patil@intel.com>
Subject: Re: [PATCH iwl-net v2 1/5] iavf: fix null pointer dereference in iavf_detect_recover_hung
Date: Fri, 18 Sep 2026 16:11:25 +0100 [thread overview]
Message-ID: <20260918151125.GK51261@horms.kernel.org> (raw)
In-Reply-To: <20260915125551.3976068-2-aleksandr.loktionov@intel.com>
On Tue, Sep 15, 2026 at 02:55:47PM +0200, Aleksandr Loktionov wrote:
> From: Kiran Patil <kiran.patil@intel.com>
>
> iavf_watchdog_task() and iavf_reset_task() both run as work items on the
> same ordered adapter->wq, so they can't race with each other. However,
> iavf_set_ringparam() (and other ethtool ops) call iavf_reset_step()
> directly from process context under the netdev instance lock, without
> going through that workqueue at all. iavf_reset_step() can free and
> reallocate adapter->tx_rings and the q_vectors array via
> iavf_reinit_interrupt_scheme() while adapter->state still reads
> __IAVF_RUNNING, so the watchdog task can concurrently call
> iavf_detect_recover_hung() and dereference a NULL q_vector inside
> iavf_force_wb(), or index into a NULL tx_rings array, causing a crash.
I am concerned that iavf_reset_step() is also called from
iavf_set_channels(). And in that case the netdev instance lock is not held.
>
> Guard against this by:
> - returning early if vsi->back->tx_rings itself is NULL, since
> num_active_queues can still be nonzero while the array is being
> reallocated;
> - skipping rings whose q_vector is NULL;
> - reading tx_ring->q_vector once with READ_ONCE() into a local variable
> and reusing that same value for both the NULL check and the
> iavf_force_wb() call, instead of re-reading the field right before
> use, which would leave a window for the concurrent reset to swap it
> from underneath us in between.
>
> Also move the tx_ring declaration into the loop body and drop the
> redundant outer NULL initialisation, which the compiler can never
> observe since an array-element address is always non-NULL.
>
> Fixes: 07d44190a389 ("i40e/i40evf: Detect and recover hung queue scenario")
> Cc: stable@vger.kernel.org
> Signed-off-by: Kiran Patil <kiran.patil@intel.com>
> Signed-off-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
...
next prev parent reply other threads:[~2026-09-18 15:11 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 12:55 [PATCH iwl-net v2 0/5] iavf: five correctness fixes Aleksandr Loktionov
2026-09-15 12:55 ` [PATCH iwl-net v2 1/5] iavf: fix null pointer dereference in iavf_detect_recover_hung Aleksandr Loktionov
2026-09-18 15:11 ` Simon Horman [this message]
2026-10-09 16:29 ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 2/5] iavf: fix error path in iavf_request_misc_irq Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 3/5] iavf: prevent VSI corruption when ring params changed during reset Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-10-09 16:28 ` Loktionov, Aleksandr
2026-09-15 12:55 ` [PATCH iwl-net v2 4/5] iavf: fix TC boundary check in iavf_handle_tclass Aleksandr Loktionov
2026-09-18 15:12 ` Simon Horman
2026-09-15 12:55 ` [PATCH iwl-net v2 5/5] iavf: return 0 when TC flower filter not found after qdisc teardown Aleksandr Loktionov
2026-09-18 15:13 ` Simon Horman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918151125.GK51261@horms.kernel.org \
--to=horms@kernel.org \
--cc=aleksandr.loktionov@intel.com \
--cc=anthony.l.nguyen@intel.com \
--cc=intel-wired-lan@lists.osuosl.org \
--cc=kiran.patil@intel.com \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox