* [PATCH net] net/mlx5: return error in case of lag device allocation failure
@ 2026-02-05 11:42 Ваторопин Андрей
2026-02-09 6:36 ` Shay Drori
0 siblings, 1 reply; 2+ messages in thread
From: Ваторопин Андрей @ 2026-02-05 11:42 UTC (permalink / raw)
To: Saeed Mahameed
Cc: Ваторопин Андрей,
Leon Romanovsky, Tariq Toukan, Mark Bloch, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Shay Drory, Gal Pressman, Patrisious Haddad, Gerd Bayer,
Mark Zhang, netdev@vger.kernel.org, linux-rdma@vger.kernel.org,
linux-kernel@vger.kernel.org, lvc-project@linuxtesting.org,
stable@vger.kernel.org
From: Andrey Vatoropin <a.vatoropin@crpt.ru>
The function __mlx5_lag_dev_add_mdev() attempts to allocate memory for the
pointer ldev by calling the function mlx5_lag_dev_alloc(). If the memory
allocation fails, mlx5_lag_dev_alloc() returns NULL and the
__mlx5_lag_dev_add_mdev() returns 0. Later in the debugfs handlers there is
an attempt to dereference the ldev pointer.
Change the return value to "-ENOMEM" to avoid NULL pointer using. When
"-ENOMEM" is returned __mlx5_lag_dev_add_mdev() will attempt to
reallocate memory for ldev after a sleep interval.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: cac1eb2cf2e3 ("net/mlx5: Lag, properly lock eswitch if needed")
Cc: stable@vger.kernel.org
Signed-off-by: Andrey Vatoropin <a.vatoropin@crpt.ru>
---
drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
index a459a30f36ca..6e914472a2d7 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
@@ -1392,7 +1392,7 @@ static int __mlx5_lag_dev_add_mdev(struct mlx5_core_dev *dev)
ldev = mlx5_lag_dev_alloc(dev);
if (!ldev) {
mlx5_core_err(dev, "Failed to alloc lag dev\n");
- return 0;
+ return -ENOMEM;
}
mlx5_ldev_add_mdev(ldev, dev);
return 0;
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH net] net/mlx5: return error in case of lag device allocation failure
2026-02-05 11:42 [PATCH net] net/mlx5: return error in case of lag device allocation failure Ваторопин Андрей
@ 2026-02-09 6:36 ` Shay Drori
0 siblings, 0 replies; 2+ messages in thread
From: Shay Drori @ 2026-02-09 6:36 UTC (permalink / raw)
To: Ваторопин Андрей,
Saeed Mahameed
Cc: Leon Romanovsky, Tariq Toukan, Mark Bloch, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Gal Pressman, Patrisious Haddad, Gerd Bayer,
Mark Zhang (Networking SW), netdev@vger.kernel.org,
linux-rdma@vger.kernel.org, linux-kernel@vger.kernel.org,
lvc-project@linuxtesting.org, stable@vger.kernel.org
On 05/02/2026 13:42, Ваторопин Андрей wrote:
> External email: Use caution opening links or attachments
>
>
> From: Andrey Vatoropin <a.vatoropin@crpt.ru>
>
> The function __mlx5_lag_dev_add_mdev() attempts to allocate memory for the
> pointer ldev by calling the function mlx5_lag_dev_alloc(). If the memory
> allocation fails, mlx5_lag_dev_alloc() returns NULL and the
> __mlx5_lag_dev_add_mdev() returns 0. Later in the debugfs handlers there is
> an attempt to dereference the ldev pointer.
>
> Change the return value to "-ENOMEM" to avoid NULL pointer using. When
> "-ENOMEM" is returned __mlx5_lag_dev_add_mdev() will attempt to
> reallocate memory for ldev after a sleep interval.
first, mlx5 treat LAG failures as non-critical. e.g.: if LAG is failing
or isn't supported, the driver won't stop loading.
Second, we have a fix in the pipeline that fixes this by adding
a check in the debugfs creation function, can you wait for it?
>
> Found by Linux Verification Center (linuxtesting.org) with SVACE.
>
> Fixes: cac1eb2cf2e3 ("net/mlx5: Lag, properly lock eswitch if needed")> Cc: stable@vger.kernel.org
> Signed-off-by: Andrey Vatoropin <a.vatoropin@crpt.ru>
> ---
> drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
> index a459a30f36ca..6e914472a2d7 100644
> --- a/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
> +++ b/drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c
> @@ -1392,7 +1392,7 @@ static int __mlx5_lag_dev_add_mdev(struct mlx5_core_dev *dev)
> ldev = mlx5_lag_dev_alloc(dev);
> if (!ldev) {
> mlx5_core_err(dev, "Failed to alloc lag dev\n");
> - return 0;
> + return -ENOMEM;
Also, This change could lead to endless loop in mlx5_lag_add_mdev().
> }
> mlx5_ldev_add_mdev(ldev, dev);
> return 0;
> --
> 2.43.0
Thanks
Shay
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-02-09 6:36 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-02-05 11:42 [PATCH net] net/mlx5: return error in case of lag device allocation failure Ваторопин Андрей
2026-02-09 6:36 ` Shay Drori
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox