From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f181.google.com (mail-qk1-f181.google.com [209.85.222.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 42CFA3EEAEB for ; Wed, 5 Aug 2026 10:25:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785925518; cv=none; b=bocyN7f2Z3Xu/9B6br3cMP9p8k/fEGpmYBCK1plfReI2ytmLxs3QtLOq/fkYw9ZnceHqS63+akEpGb+9U0oXdwNdXBHOeIP36Fl38fKrFKu8Yjra7IePKGw+I+FPCIoSdCCdFwg6nqSwW+gWlpi/wLl6TKR8Xx2M3OIEvFkHuR4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785925518; c=relaxed/simple; bh=Ar2VSFfOX9Y3NHy+gCdt76XnYbYIFnThMiDcS2J/SHk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Fehi0yU+oAEL/5XEG/+uRnyeG/fS9ylrz5foFIZAkUay6sqMPNb8oJanKBsgMkXz1eJ3mljdVFRofqULYxs82rM/D65xOC3Ava6sEt77lEwbYhGzKd+HnHAGrCDrqLsRLbWfU/gNT48bycL6dafd9BvfDS8mgSy7CUFtfnHuvRs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=PYhp1sGQ; arc=none smtp.client-ip=209.85.222.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="PYhp1sGQ" Received: by mail-qk1-f181.google.com with SMTP id af79cd13be357-92f03daaa97so47137485a.2 for ; Wed, 05 Aug 2026 03:25:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785925516; x=1786530316; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=uBFdOOeUVBY1Qp0eWq07UF7DoGLXPhkRtG5vT8+QMKs=; b=PYhp1sGQtJ3DEZAoUlztW08B9vnfubJCd4+6Uw5GxN94Zb2T/0rsk+HrCnReeRS302 Jp13zLSDGFi+R3Ua69l2YBHPbg3ZEKsVAng9BmiRHhu2aGh05ExLiHNQSd8Pbpe5W6ry bPGSoTTi2ceGQDr3l1tbeA0xQNrKDmdMSdyQs6hLHI9b5ePICr7HHshkeicBiZvLhL/f uUpjv6UH3ge0AIwZgJ1tQitF0C7Z6gbAO0t7s7EpCNGFQSpRH9zuuKtkkEFJq5Gida6w MeOw/shCCIKK8zK62+N/+mDR/8bD9yMfpr/GqvwKDVMNvIhBu4Vrd8ycLMq71zdlJhT4 lS+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785925516; x=1786530316; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uBFdOOeUVBY1Qp0eWq07UF7DoGLXPhkRtG5vT8+QMKs=; b=GmBJzCSMQYu3WQ4m39a66SD7sGHRrFSwJ4b2ZuJfaginnuc45jxl0ZjHfV+I69zGuf vEmGmaO8ocR6NxPsQaqG5OINWQ72H3odLTr7hOgh6+WOM4NoOTWYkaWEwRhGw4ToaZOY J8hUVishDCr8/0J2SHl3Fcbt68DAUsvzFbszXAAGdM9Y5ybTeDBr9xDsjEDBMfMG8IuK cHjyJ3QT71LZkIl39pT1KgxCNLokdTbBqN7eE11/U4DxD6p+ElX+5lpxwngshFv5Ewfq zDQLfKk16tpr+nohG6Fswib0wVv7mYTQ94F64ZJCLFHQStgGYoGIMQ+1krxU6/G5qIGi eCKA== X-Forwarded-Encrypted: i=1; AHgh+RqsEagc+5A5G1SyflzLyaEEtkB1r+omL5xZG1+fDgfSHtr9BIDK96jSYE7mV1GyEyQl/12epxlHuYZ+yKo=@vger.kernel.org X-Gm-Message-State: AOJu0YxGfgfqo8PZV6s5aWIHoVnjyxcLCSuDDce8oSxErWjYJTm3SMVn EgKzPkuILrrSbzU0i5zE/MFBt8+eCKYFo5bsVJ5DKr5E4wDzRxwiFS+sv0NgRP3jpXw= X-Gm-Gg: AR+sD12K+tRVURTeY4LAMtMHgGkc1np2dxb5QXNzhvXdT4OYhRcS/CgkDfkxwTL8Swm 0VvEvkujPqjQr6DfL4+tHJ4q9vrldwBJ9QdMgAOkF111H3VAib1yUgA4G+54DkSTwRPULC6gLq4 FhSKoWcsRrcd/QmIRk3HaiitwVYiiRwrRc2ygUvH4zZRWGwcvvxQW1G0Clc6K4SaIpxzKZbi7GQ F0pqPb69S3V0YZkRZ0I/v9ad0qaeRx5k4U9U8q2eoXmMz74HoAee9mXeprN0xhp4/KT5MWM2VVm F+Bd70ZnDfT0pfDWfJeyiGkU2QBrOAQuKa5lxb4OFtaVp0PVTQCUHv9hxfVFI+B1VyAqiSljQRY DVqgqok3Ldr6KF5PU18lAS5r5YO+sheGkYXPvrkZEu52U9D616SrOyfl3O+R23kpPB0gLpFrqce 4sFy0P4T75QUCAz5jEK3oMO3eEP7u6zCS8nlJ3eURcrMfwTYMk5fBBHX2v06kBDbidLw== X-Received: by 2002:a05:620a:a003:b0:932:fd59:3e57 with SMTP id af79cd13be357-93649148855mr447772285a.41.1785925516159; Wed, 05 Aug 2026 03:25:16 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id af79cd13be357-9364a597e2asm119983285a.43.2026.08.05.03.25.15 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 05 Aug 2026 03:25:15 -0700 (PDT) From: David Lee To: vinicius.gomes@intel.com, jhs@mojatatu.com, jiri@resnulli.us, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , horms@kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Lee Subject: [PATCH net] net/sched: sch_taprio: do not requeue a deactivated qdisc Date: Wed, 5 Aug 2026 10:25:14 +0000 Message-ID: <20260805102514.740834-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Kyle Zeng Root qdisc replacement and deletion call dev_deactivate() without resetting the old qdisc. This marks the qdisc deactivated and waits for existing runs to finish, but leaves TAPRIO's private hrtimer active. advance_sched() can therefore requeue the old root after the final busy check, allowing a new run to overlap reset and destruction. Do not schedule TAPRIO after its root has been deactivated. Keep the test in the existing RCU read-side critical section so that it pairs with the synchronize_net() in dev_deactivate_many(): a callback which observes an active qdisc must finish before the final busy check, while a later callback observes the deactivated state and skips the requeue. Fixes: 5a781ccbd19e ("tc: Add support for configuring the taprio scheduler") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber Signed-off-by: Kyle Zeng Co-developed-by: David Lee Signed-off-by: David Lee --- Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. The supplied v7.2-rc3 trace contains a KASAN use-after-free. The reproducer did not trigger a sanitizer report in the current v7.2-rc5 campaign and can be shared if needed. net/sched/sch_taprio.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/net/sched/sch_taprio.c b/net/sched/sch_taprio.c index 299234a5f..2cf76df43 100644 --- a/net/sched/sch_taprio.c +++ b/net/sched/sch_taprio.c @@ -990,7 +990,8 @@ static enum hrtimer_restart advance_sched(struct hrtimer *timer) hrtimer_set_expires(&q->advance_timer, end_time); rcu_read_lock(); - __netif_schedule(sch); + if (!test_bit(__QDISC_STATE_DEACTIVATED, &sch->state)) + __netif_schedule(sch); rcu_read_unlock(); return HRTIMER_RESTART; -- 2.53.0