From: netdev-bot+sashiko@kernel.org
To: gustavold@gmail.com
Cc: leitao@debian.org, andrew+netdev@lunn.ch, davem@davemloft.net,
edumazet@kernel.org, kuba@kernel.org, pabeni@redhat.com,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH net-next 1/2] netconsole: avoid printing partially updated target attributes
Date: Fri, 09 Oct 2026 07:00:45 +0000 [thread overview]
Message-ID: <179152924550.434549.6528431556113648959@kernel.org> (raw)
In-Reply-To: <20261006-netcons-fixes-next-v1-1-231cd26f8c51@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential
issue(s) to consider.
Critical: 0 · High: 1 · Medium: 0 · Low: 1
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [High] The patch is meant to stop *_show() callbacks from racing with
writers, but local_mac_show() in drivers/net/netconsole.c is still…
- [Low] The commit fixes a user-visible race: reading local_ip,
remote_ip, dev_name, remote_mac or userdatum value while it is being…
--
netconsole: avoid printing partially updated target attributes
This commit takes dynamic_netconsole_mutex in several configfs *_show()
callbacks so that reads are serialized against the store callbacks. It
also takes RTNL in dev_name_show() so the read cannot race with
netconsole_netdev_event() updating np.dev_name on NETDEV_CHANGENAME.
> Reported-by: Sashiko <netdev-bot+sashiko@kernel.org>
> Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260814-netcons_ipv6-v3-7-bc0915e8c75f@gmail.com
> Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928-netcons-fixes-v1-0-bb5ffe5e698a%40gmail.com
> Signed-off-by: Gustavo Luiz Duarte <gustavold@gmail.com>
[Severity: Low]
This fixes a race that users can see, but the trailers have no Fixes: tag.
Should one be added so stable and backport tooling can tell which trees
need the fix?
The family-dependent formatting in local_ip_show() and remote_ip_show()
(the AF_UNSPEC and AF_INET6 branches) came from these commits:
46b3f9e7e761 ("netconsole: use the address family instead of the ipv6 flag")
56ddc8d48e75 ("netconsole: show empty string for an unset IP address")
The first Closes: link points at that netcons_ipv6 series.
The lockless reads in dev_name_show() and remote_mac_show() go back to:
0bcc1816188e ("[NET] netconsole: Support dynamic reconfiguration using configfs")
> diff --git a/drivers/net/netconsole.c b/drivers/net/netconsole.c
> index 267254f046de9..188beacb308d7 100644
> --- a/drivers/net/netconsole.c
> +++ b/drivers/net/netconsole.c
> @@ -859,7 +859,19 @@ static ssize_t release_show(struct config_item *item, char *buf)
>
> static ssize_t dev_name_show(struct config_item *item, char *buf)
> {
> - return sysfs_emit(buf, "%s\n", to_target(item)->np.dev_name);
> + struct netconsole_target *nt = to_target(item);
> + int ret;
> +
> + dynamic_netconsole_mutex_lock();
> + /* Hold RTNL to prevent racing against netconsole_netdev_event()
> + * changing np.dev_name.
> + */
> + rtnl_lock();
> + ret = sysfs_emit(buf, "%s\n", nt->np.dev_name);
> + rtnl_unlock();
> + dynamic_netconsole_mutex_unlock();
> +
> + return ret;
> }
[ ... ]
> @@ -906,7 +932,14 @@ static ssize_t local_mac_show(struct config_item *item, char *buf)
>
> static ssize_t remote_mac_show(struct config_item *item, char *buf)
> {
> - return sysfs_emit(buf, "%pM\n", to_target(item)->remote_mac);
> + struct netconsole_target *nt = to_target(item);
> + int ret;
> +
> + dynamic_netconsole_mutex_lock();
> + ret = sysfs_emit(buf, "%pM\n", nt->remote_mac);
> + dynamic_netconsole_mutex_unlock();
> +
> + return ret;
> }
[Severity: High]
local_mac_show(), just above this hunk, still has no locking. Is it still
open to the same race the commit message describes?
drivers/net/netconsole.c:local_mac_show() {
struct net_device *dev = to_target(item)->np.dev;
static const u8 bcast[ETH_ALEN] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
return sysfs_emit(buf, "%pM\n", dev ? dev->dev_addr : bcast);
}
It loads np.dev and dereferences dev->dev_addr without holding
dynamic_netconsole_mutex, without RTNL, and without a netdev reference.
The netdev notifier can clear np.dev and drop its reference while holding
only RTNL:
netconsole_netdev_event(NETDEV_UNREGISTER)
netconsole_process_cleanups_core() /* ASSERT_RTNL() */
netcons_release_dev()
do_netpoll_cleanup()
netdev_put(np->dev, &np->dev_tracker);
np->dev = NULL;
enabled_store() also reaches this cleanup, under the mutex.
Suppose a reader of local_mac (world-readable through CONFIGFS_ATTR_RO)
loads a non-NULL dev and is then preempted while the device is
unregistered and freed. Could sysfs_emit() then read dev->dev_addr from a
freed net_device?
Even without unregistration, dev->dev_addr is rewritten under RTNL when
the MAC address changes. A lockless read could then print a mix of old
and new bytes.
dev_name_show() already takes RTNL because of the notifier-side writer.
Would taking dynamic_netconsole_mutex and then rtnl_lock() around both the
np.dev load and the sysfs_emit() call in local_mac_show() cover both
cases?
The later commit in this series, "netconsole: remove unnecessary target
refcounting from the netdev notifier", does not touch local_mac_show(). So
the problem still seems to be there at the end of the series.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261006-netcons-fixes-next-v1-0-231cd26f8c51%40gmail.com
next prev parent reply other threads:[~2026-10-09 7:00 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 18:58 [PATCH net-next 0/2] netconsole: add locking to configfs _show callbacks Gustavo Luiz Duarte
2026-10-06 18:58 ` [PATCH net-next 1/2] netconsole: avoid printing partially updated target attributes Gustavo Luiz Duarte
2026-10-06 20:35 ` Eric Dumazet
2026-10-08 19:55 ` Gustavo Luiz Duarte
2026-10-09 12:35 ` Breno Leitao
2026-10-09 20:19 ` Gustavo Luiz Duarte
2026-10-09 7:00 ` netdev-bot+sashiko [this message]
2026-10-06 18:58 ` [PATCH net-next 2/2] netconsole: remove unnecessary target refcounting from the netdev notifier Gustavo Luiz Duarte
2026-10-06 19:06 ` [PATCH net-next 0/2] netconsole: add locking to configfs _show callbacks netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179152924550.434549.6528431556113648959@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=gustavold@gmail.com \
--cc=kuba@kernel.org \
--cc=leitao@debian.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®