From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pz2-f43.google.com (mail-pz2-f43.google.com [74.125.228.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6E67A348C52 for ; Sun, 20 Sep 2026 16:17:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789921066; cv=none; b=XJnNXVg5aM7n35VU0IVWlNFMxPjcGjacMzpttJBNY8Z5K2nBG2ux2Dl6niUIxangQjGlyN7nlBzVeI7gbjwq7a1ZNO98+i7V39r7q11/Z29zTQXI7C0D0J2MwH2oA2ciorBl0cAIa2LNghY+JqMSJcxN5GNyH73LM2Sse1RZbdA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789921066; c=relaxed/simple; bh=q3+uLqBCNGSzkE7tv6YmXIvrM+sKuNRFRAZZq6awJKM=; h=Content-Type:Date:Message-Id:Subject:From:To:Cc:In-Reply-To: References:MIME-Version; b=pMF2TBJ6V7R4uUi5ZLHtHbaOzhUmOgd9V1GYs+erB+3oIvRfcwCpOt5lcmBfxrbqtc9BLEY2QygzFMpH9R1MuURm1MLgzPUgwCy3kExLWPl7Ug8sVvbgPHLxYl5d97H7xe1rI7DouKzBBgcRY6CZtU+UwV7HgqR6M38f6Bg58B0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=duKHX4Dt; arc=none smtp.client-ip=74.125.228.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="duKHX4Dt" Received: by mail-pz2-f43.google.com with SMTP id d2e1a72fcca58-85469a33c9cso3031952b3a.0 for ; Sun, 20 Sep 2026 09:17:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789921065; x=1790525865; darn=vger.kernel.org; h=mime-version:content-transfer-encoding:references:in-reply-to:cc:to :from:subject:message-id:date:content-type:from:to:cc:subject:date :message-id:reply-to:content-type; bh=eDlZ0Axn1IVbcM7wq+/bUYuF1RFbaZNrtATk3Wq6DJU=; b=duKHX4Dt8MebFrNKOBbwKA2zHIAc5hYGd4rZx9EIq/TFka+FWnjzmOfANMEadtVZaa kz1z3TP7YwkYEGG+UFUA//LL3YuQesxIUkNWyvhnr9MS6c6SMrQfRMBdUHX74hHb2Kbu VRbcwEfgS5YO9rD0BTR4oujohJt+MsTbwrY1WYxSPuC//gjd2GN3zUQa+W2bpytcV2bq mUv4FIBOMPlg4SkpDrHihSaZdEQlMpdHxo4e+2i4HS0XRv3tDxjEHFCx/M4otdm5ZElU zUkjvPY1Z26Zppry1wxFyP2neIN1nfe1jGkQGzPHCEkV5UYRRLO2WHX3gx5iO9Ee6g6X InkQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789921065; x=1790525865; h=mime-version:content-transfer-encoding:references:in-reply-to:cc:to :from:subject:message-id:date:content-type:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=eDlZ0Axn1IVbcM7wq+/bUYuF1RFbaZNrtATk3Wq6DJU=; b=AD4hwK28re/HeyFabwpDH5jeuCpc8FV33N7gin2rRCOaEoCgml5PHbzp/BB9rruvcC jUwzU4P/uvdW8oGMqb+PovAwBcXYr0bEwF8/WoHxdkrQw1Em2ghoJof8/cyQ/DXqsihu ViAFgna/mMWE6VSj+u3XqAMOPVDejaT6+RyGQmdbYlB4d3my+raSv1Zp4bx1aFoyVz8r 9c3db9RL+T65LguV4anTe79JPW+iwkPK3Jrov7iqGr5R+TWFI+x0vPM6DBLKK/GP+yp5 +pFy3PuKmqQaHqZ7ywtgpub0BLISnzT5EAnhPZZU2eyUlr8R4GjWeNS7dfceinpPaLbJ mTWg== X-Forwarded-Encrypted: i=1; AKwUvByF3is40se/pfEytWPqUh2SIeO+QejhoLRor3tNurkSnltW6pC0d5nLHbdhCtPk/xyUhk9PlUA=@vger.kernel.org X-Gm-Message-State: AFuF++miYfWkrDe89aMVECHDgefOLiW6SeDLKX67g4aS0fGASRtvorJr UMq5MRsQICQqOK0Wp6PUb/1CiB+s4cnEPGKgsK7JO8s0b6q4cFgLmWIi X-Gm-Gg: AYBFou03WdFbfv4uPvWQ0dOj0h+gW395Puv1OnosIWZzPhY6R6nCyL+xYlPokyPxoFx mew420fZ4eWhIGgdjPExR65d2BehOf/c1t6TMlwYSH1NUdQ4LqHkMbKY5SWSGdnqahR+R6mLhif EUDALNqAeGIJdTw7Ltfb3pcujZ75NLhPtOhSLzxXndq8j+e08qkiqWiWy1YH+PAp2Dx9y9nn++s zANgxFJCMTsWuXNv5XFrxKHYFHoq+IWcDQ6pQK4aHFMN+VlnM90OhYjeULUHvSy5aAqzFSxLJxc Xx63P4hI+QoMabZMtGK7XTbgfFc1LfhxhNxzsPU29XaM0I+iF9rnW9R7jj6lPVe3OrjwiGr9aoA RVUay9iE+6tLEd8/aPB5+1qP5hPDn2imhMifYKcRdXa2d14TpjRy6i/8rIjBgLHLKGl9/FAFDxJ bwN+AN6dCCShanrpJ1wZLdmYxTSls7S1YM3OYRcpaouUernTfWSZCpDqURm+PdjXeshKp7nCAGh uaeSh7EAWbNUQRM1PYVoypj+4Lxok1gk6bBAiGbc1iglvccaMu5kmjdbMmjka8HufTYCGa6xxrJ NR7M X-Received: by 2002:a05:6a00:4b01:b0:848:4faa:480b with SMTP id d2e1a72fcca58-874dccf8702mr13211565b3a.12.1789921064613; Sun, 20 Sep 2026 09:17:44 -0700 (PDT) Received: from localhost ([153.61.198.250]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-877aa6fd3ecsm2107269b3a.59.2026.09.20.09.17.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 20 Sep 2026 09:17:44 -0700 (PDT) Content-Type: text/plain; charset=UTF-8 Date: Sun, 20 Sep 2026 16:17:43 +0000 Message-Id: Subject: Re: [PATCH net v1] bpf: cpumap: fix use-after-free of dev_rx on netdev unregister From: "Alexei Starovoitov" To: "Jiayuan Chen" , Cc: "Daniel Borkmann" , "David S. Miller" , "Jakub Kicinski" , "Jesper Dangaard Brouer" , "John Fastabend" , "Stanislav Fomichev" , "Andrii Nakryiko" , "Eduard Zingerman" , "Kumar Kartikeya Dwivedi" , "Martin KaFai Lau" , "Song Liu" , "Yonghong Song" , "Jiri Olsa" , "Emil Tsalapatis" , "Ihor Solodrai" , , In-Reply-To: <20260920133017.248620-1-jiayuan.chen@linux.dev> References: <20260920133017.248620-1-jiayuan.chen@linux.dev> X-Mailer: mkdraft (claude review draft; edit before sending) Content-Transfer-Encoding: 8bit Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Sun, Sep 20, 2026 at 09:30 PM Jiayuan Chen wrote: > So do what the softnet backlog does and use the netdev notifier: > > 1. On NETDEV_UNREGISTER, take the ring size and ask the kthread to > consume that many frames, or until the ring is empty. After that, > every frame that was in the ring has been handled by the stack or > dropped. The device is closed, so no new frames for it can show up. That's not what the backlog does. flush_backlog() unlinks only the skbs with skb->dev->reg_state == NETREG_UNREGISTERING and frees them. It doesn't feed them to the stack, doesn't touch packets of other devices, and flush_all_backlogs() runs once per unregister_netdevice_many(), not once per device. > @@ -528,6 +576,11 @@ static void __cpu_map_entry_free(struct work_struct *work) > */ > rcpu = container_of(to_rcu_work(work), struct bpf_cpu_map_entry, free_work); > > + /* Unlink first, so the notifier can't wait on a kthread we stop */ > + mutex_lock(&cpu_map_mutex); > + list_del(&rcpu->list); > + mutex_unlock(&cpu_map_mutex); > + > /* kthread_stop will wake_up_process and wait for it to complete. After list_del() the ring still has frames and the kthread has to be scheduled to consume them. kthread_stop() only wakes it up. When the device is unregistered in that window the notifier doesn't see the entry, doesn't wait, the netdev is freed and the kthread hits the same eth_type_trans() UAF. pw-bot: cr