Netdev List
 help / color / mirror / Atom feed
From: Breno Leitao <leitao@debian.org>
To: Gustavo Luiz Duarte <gustavold@gmail.com>
Cc: Eric Dumazet <edumazet@kernel.org>,
	 Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	 Jakub Kicinski <kuba@kernel.org>,
	Paolo Abeni <pabeni@redhat.com>,
	netdev@vger.kernel.org,  linux-kernel@vger.kernel.org,
	Sashiko <netdev-bot+sashiko@kernel.org>
Subject: Re: [PATCH net-next 1/2] netconsole: avoid printing partially updated target attributes
Date: Fri, 9 Oct 2026 05:35:45 -0700	[thread overview]
Message-ID: <asjfY79OetvGy4an@gmail.com> (raw)
In-Reply-To: <CAGSyskUE2CM_i_+o2Dtf+_OriRyad+UzG4S-rzOeTL18LnZheQ@mail.gmail.com>

On Thu, Oct 08, 2026 at 08:55:40PM +0100, Gustavo Luiz Duarte wrote:
> Hi Eric, thanks for the review!
> 
> On Tue, Oct 6, 2026 at 9:35 PM Eric Dumazet <edumazet@kernel.org> wrote:
> >
> >
> >
> > On 10/6/26 20:58, Gustavo Luiz Duarte wrote:
> > > The configfs store callbacks all serialize on dynamic_netconsole_mutex
> > > but not on the read side, so reading an attribute while it is being
> > > written returns a partially updated value.
> > >
> > > Hold dynamic_netconsole_mutex on *_show() callbacks to avoid racing with
> > > writers.
> > >
> > > The dev_name_show() callback can also race with
> > > netconsole_netdev_event() writing to np.dev_name due to
> > > NETDEV_CHANGENAME. So it needs to hold RTNL in addition to
> > > dynamic_netconsole_mutex.
> > >
> > > Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
> > > Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260814-netcons_ipv6-v3-7-bc0915e8c75f@gmail.com
> > > Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928-netcons-fixes-v1-0-bb5ffe5e698a%40gmail.com
> > > Signed-off-by: Gustavo Luiz Duarte <gustavold@gmail.com>
> > > ---
> > >   drivers/net/netconsole.c | 62 +++++++++++++++++++++++++++++++++++++++---------
> > >   1 file changed, 51 insertions(+), 11 deletions(-)
> > >
> > > diff --git a/drivers/net/netconsole.c b/drivers/net/netconsole.c
> > > index 267254f046de..188beacb308d 100644
> > > --- a/drivers/net/netconsole.c
> > > +++ b/drivers/net/netconsole.c
> > > @@ -859,7 +859,19 @@ static ssize_t release_show(struct config_item *item, char *buf)
> > >
> > >   static ssize_t dev_name_show(struct config_item *item, char *buf)
> > >   {
> > > -     return sysfs_emit(buf, "%s\n", to_target(item)->np.dev_name);
> > > +     struct netconsole_target *nt = to_target(item);
> > > +     int ret;
> > > +
> > > +     dynamic_netconsole_mutex_lock();
> > > +     /* Hold RTNL to prevent racing against netconsole_netdev_event()
> > > +      * changing np.dev_name.
> > > +      */
> > > +     rtnl_lock();
> > > +     ret = sysfs_emit(buf, "%s\n", nt->np.dev_name);
> > > +     rtnl_unlock();
> > > +     dynamic_netconsole_mutex_unlock();
> > > +
> > > +     return ret;
> > >   }
> >
> > Please do not add rtnl_lock() in a _show() sysfs handler unless there is
> > no other way?
> >
> > Something like:
> >
> >      dynamic_netconsole_mutex_lock();
> >      strscpy(name, nt->np.dev_name, sizeof(name));
> >      if (nt->state == STATE_ENABLED) {
> >          struct net_device *dev = nt->np.dev;
> >
> >          if (dev)
> >              netdev_copy_name(dev, name);
> 
> This could lead to a use-after-free if we race with NETDEV_UNREGISTER
> and 'dev' gets freed.

Any chance you can get the lock (either dynamic_netconsole_mutex or
target_list_lock) in netdev notifiers, so, it doens't conflict with this
one?


  reply	other threads:[~2026-10-09 12:35 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 18:58 [PATCH net-next 0/2] netconsole: add locking to configfs _show callbacks Gustavo Luiz Duarte
2026-10-06 18:58 ` [PATCH net-next 1/2] netconsole: avoid printing partially updated target attributes Gustavo Luiz Duarte
2026-10-06 20:35   ` Eric Dumazet
2026-10-08 19:55     ` Gustavo Luiz Duarte
2026-10-09 12:35       ` Breno Leitao [this message]
2026-10-09  7:00   ` netdev-bot+sashiko
2026-10-06 18:58 ` [PATCH net-next 2/2] netconsole: remove unnecessary target refcounting from the netdev notifier Gustavo Luiz Duarte
2026-10-06 19:06 ` [PATCH net-next 0/2] netconsole: add locking to configfs _show callbacks netdev-bot+sinfo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asjfY79OetvGy4an@gmail.com \
    --to=leitao@debian.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=gustavold@gmail.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev-bot+sashiko@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox