* Re: [PATCH net-next v16 1/6] net: dsa: add devlink flash_update callback to dsa_switch_ops
@ 2026-09-17 16:11 netdev-bot+sashiko
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sashiko @ 2026-09-17 16:11 UTC (permalink / raw)
To: daniel
Cc: jiri, davem, edumazet, kuba, pabeni, horms, corbet, skhan,
rdunlap, gregkh, rafael, dakr, andrew, olteanv, netdev,
linux-doc, linux-kernel, driver-core
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider:
Critical: 0 · High: 0 · Medium: 0 · Low: 1
- [Low] Installing `.flash_update = dsa_devlink_flash_update`
unconditionally in the single shared `dsa_devlink_ops` removes the…
--
net: dsa: add devlink flash_update callback to dsa_switch_ops
This adds a devlink_flash_update callback to dsa_switch_ops and a
trampoline in net/dsa/devlink.c that forwards to it, returning
-EOPNOTSUPP when the driver does not implement the callback. The
.flash_update op is installed unconditionally in the shared
dsa_devlink_ops table.
> diff --git a/net/dsa/devlink.c b/net/dsa/devlink.c
> index ed342f345692b..25311a87cbc56 100644
> --- a/net/dsa/devlink.c
> +++ b/net/dsa/devlink.c
> @@ -20,6 +20,18 @@ static int dsa_devlink_info_get(struct devlink *dl,
> return -EOPNOTSUPP;
> }
>
> +static int dsa_devlink_flash_update(struct devlink *dl,
> + struct devlink_flash_update_params *params,
> + struct netlink_ext_ack *extack)
> +{
> + struct dsa_switch *ds = dsa_devlink_to_ds(dl);
> +
> + if (!ds->ops->devlink_flash_update)
> + return -EOPNOTSUPP;
> +
> + return ds->ops->devlink_flash_update(ds, params, extack);
> +}
> +
[ ... ]
> @@ -169,6 +181,7 @@ dsa_devlink_sb_occ_tc_port_bind_get(struct devlink_port *dlp,
>
> static const struct devlink_ops dsa_devlink_ops = {
> .info_get = dsa_devlink_info_get,
> + .flash_update = dsa_devlink_flash_update,
[Severity: Low]
This isn't a bug as such, since the commit message states the trade-off,
but is the full extent of the behaviour change on switches without the
callback covered?
Since dsa_devlink_ops is shared by every DSA switch, the core gate in
devlink_nl_flash_update_doit() now always passes:
net/devlink/dev.c:devlink_nl_flash_update_doit() {
if (!devlink->ops->flash_update)
return -EOPNOTSUPP;
...
file_name = nla_data(nla_file_name);
ret = request_firmware_direct(¶ms.fw, file_name, devlink->dev);
...
devlink_flash_update_begin_notify(devlink);
ret = devlink->ops->flash_update(devlink, ¶ms, info->extack);
devlink_flash_update_end_notify(devlink);
}
So on a switch that does not set ds->ops->devlink_flash_update, a flash
request now reads the entire userspace-named file from the firmware search
paths into kernel memory before dsa_devlink_flash_update() gets to return
-EOPNOTSUPP.
Beyond the -ENOENT versus -EOPNOTSUPP change already described, does this
also mean that on such switches a flash request becomes a file-existence
probe of the firmware search paths, performs an unbounded read of a
/lib/firmware file into kernel memory, and emits a FLASH_UPDATE /
FLASH_UPDATE_END pair to devlink monitors for an operation that can never
succeed?
For reference, path traversal is not a concern here:
_request_firmware() rejects names containing ".." via
name_contains_dotdot(), and the operation requires CAP_NET_ADMIN.
Would it be worth mentioning the firmware read and the notifications for
switches without the callback in the commit message, in addition to the
errno change?
> .sb_pool_get = dsa_devlink_sb_pool_get,
> .sb_pool_set = dsa_devlink_sb_pool_set,
> .sb_port_pool_get = dsa_devlink_sb_port_pool_get,
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/cover.1789477568.git.daniel%40makrotopia.org
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH net-next v16 1/6] net: dsa: add devlink flash_update callback to dsa_switch_ops
2026-09-15 13:09 [PATCH net-next v16 0/6] net: dsa: mxl862xx: devlink flash and rescue Daniel Golle
@ 2026-09-15 13:09 ` Daniel Golle
0 siblings, 0 replies; 2+ messages in thread
From: Daniel Golle @ 2026-09-15 13:09 UTC (permalink / raw)
To: Jiri Pirko, David S. Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Jonathan Corbet, Shuah Khan,
Randy Dunlap, Daniel Golle, Greg Kroah-Hartman,
Rafael J. Wysocki, Danilo Krummrich, Andrew Lunn,
Vladimir Oltean, netdev, linux-doc, linux-kernel, driver-core
Add a devlink_flash_update callback to dsa_switch_ops so that DSA
drivers can support devlink dev flash without open-coding the devlink
plumbing. Like the other trampolines in net/dsa/devlink.c, the op
returns -EOPNOTSUPP when the driver does not implement the callback.
The devlink core takes a non-NULL ops->flash_update as the capability
gate, so on a switch without the callback a flash request now fetches
the firmware file first: a missing file fails with -ENOENT instead of
-EOPNOTSUPP, and a file that is found reaches the trampoline inside a
FLASH_UPDATE/FLASH_UPDATE_END notification pair. Both are acceptable
for an operation as infrequent as a firmware update.
The devlink core calls the op with the devlink instance lock held and
without rtnl_lock, whereas DSA serialises its switch and port ops
under rtnl_lock, so a driver has to serialise a flash against its own
ops itself.
Signed-off-by: Daniel Golle <daniel@makrotopia.org>
Reviewed-by: Andrew Lunn <andrew@lunn.ch>
---
v16:
- commit message: name the errno and the notifications the shared ops
table changes for switches without the callback (found by Sashiko
AI review)
- commit message: a missing firmware file fails before the
notification pair, which wraps only the call into the trampoline
v15: no changes
v14: no changes, picked up Andrew's v13 Reviewed-by
v13: no changes
v12: no changes
v11: no changes
v10: no changes
v9: install the flash_update op unconditionally and return -EOPNOTSUPP
from the trampoline like the other DSA devlink trampolines,
instead of a second devlink_ops permutation (Andrew Lunn)
v8:
- retitled: this patch adds the callback, its first user is patch 3
- describe the op's calling context in the commit message
v7: no changes
v6: no changes
v5: no changes
v4: only install the flash_update op for drivers implementing the
callback so the devlink core keeps rejecting unsupported flash
requests before fetching the firmware file
v3: no changes
v2: align continuation lines with the open parenthesis
include/net/dsa.h | 3 +++
net/dsa/devlink.c | 13 +++++++++++++
2 files changed, 16 insertions(+)
diff --git a/include/net/dsa.h b/include/net/dsa.h
index 7507d632e7c6..9babab92a0fc 100644
--- a/include/net/dsa.h
+++ b/include/net/dsa.h
@@ -1174,6 +1174,9 @@ struct dsa_switch_ops {
int (*devlink_info_get)(struct dsa_switch *ds,
struct devlink_info_req *req,
struct netlink_ext_ack *extack);
+ int (*devlink_flash_update)(struct dsa_switch *ds,
+ struct devlink_flash_update_params *params,
+ struct netlink_ext_ack *extack);
int (*devlink_sb_pool_get)(struct dsa_switch *ds,
unsigned int sb_index, u16 pool_index,
struct devlink_sb_pool_info *pool_info);
diff --git a/net/dsa/devlink.c b/net/dsa/devlink.c
index ed342f345692..25311a87cbc5 100644
--- a/net/dsa/devlink.c
+++ b/net/dsa/devlink.c
@@ -20,6 +20,18 @@ static int dsa_devlink_info_get(struct devlink *dl,
return -EOPNOTSUPP;
}
+static int dsa_devlink_flash_update(struct devlink *dl,
+ struct devlink_flash_update_params *params,
+ struct netlink_ext_ack *extack)
+{
+ struct dsa_switch *ds = dsa_devlink_to_ds(dl);
+
+ if (!ds->ops->devlink_flash_update)
+ return -EOPNOTSUPP;
+
+ return ds->ops->devlink_flash_update(ds, params, extack);
+}
+
static int dsa_devlink_sb_pool_get(struct devlink *dl,
unsigned int sb_index, u16 pool_index,
struct devlink_sb_pool_info *pool_info)
@@ -169,6 +181,7 @@ dsa_devlink_sb_occ_tc_port_bind_get(struct devlink_port *dlp,
static const struct devlink_ops dsa_devlink_ops = {
.info_get = dsa_devlink_info_get,
+ .flash_update = dsa_devlink_flash_update,
.sb_pool_get = dsa_devlink_sb_pool_get,
.sb_pool_set = dsa_devlink_sb_pool_set,
.sb_port_pool_get = dsa_devlink_sb_port_pool_get,
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-17 16:11 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 16:11 [PATCH net-next v16 1/6] net: dsa: add devlink flash_update callback to dsa_switch_ops netdev-bot+sashiko
-- strict thread matches above, loose matches on Subject: below --
2026-09-15 13:09 [PATCH net-next v16 0/6] net: dsa: mxl862xx: devlink flash and rescue Daniel Golle
2026-09-15 13:09 ` [PATCH net-next v16 1/6] net: dsa: add devlink flash_update callback to dsa_switch_ops Daniel Golle
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®