mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
@ 2026-09-28 10:56 Nicolai Buchwitz
  2026-09-28 10:59 ` netdev-bot+sinfo
  2026-09-28 17:29 ` Florian Fainelli
  0 siblings, 2 replies; 4+ messages in thread
From: Nicolai Buchwitz @ 2026-09-28 10:56 UTC (permalink / raw)
  To: Doug Berger, Florian Fainelli, Nicolai Buchwitz,
	Broadcom internal kernel review list, Andrew Lunn,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
  Cc: Justin Chen, Florian Fainelli, netdev, linux-kernel

The Rx ring priv and index are only set in bcmgenet_init_rx_ring(),
which runs at open. Setting the Rx coalescing parameters on an interface
that was never opened, e.g. "ethtool -C eth0 rx-usecs 50", dereferences
a NULL ring->priv. The oops happens with RTNL held, so networking
stays stuck until a reboot:

  Unable to handle kernel paging request at virtual address 0000000000002788
  pc : bcmgenet_set_rx_coalesce.isra.0+0x10/0x88
  lr : bcmgenet_set_coalesce+0xe8/0x180
  Call trace:
   bcmgenet_set_rx_coalesce.isra.0+0x10/0x88 (P)
   __ethnl_set_coalesce.isra.0+0x490/0x570
   ethnl_set_coalesce+0x48/0xc0
   ethnl_default_set_doit+0xf4/0x230
   genl_family_rcv_msg_doit+0xe8/0x160
   genl_rcv_msg+0x220/0x2a0
   netlink_rcv_skb+0x68/0x140
   genl_rcv+0x40/0x60
   netlink_unicast+0x338/0x3c0
   netlink_sendmsg+0x19c/0x3f8
   __sock_sendmsg+0x64/0xc0
   __sys_sendto+0x124/0x198
   __arm64_sys_sendto+0x30/0x48

Set priv and index at probe. Writing the registers while the interface
is down is harmless because open resets the MAC and
bcmgenet_init_rx_coalesce() reapplies the stored values.

Fixes: 9f4ca05827a2 ("net: bcmgenet: Add support for adaptive RX coalescing")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
---
 drivers/net/ethernet/broadcom/genet/bcmgenet.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index f725d26e6020..e8908916558b 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -4151,8 +4151,11 @@ static int bcmgenet_probe(struct platform_device *pdev)
 	netif_set_real_num_rx_queues(priv->dev, priv->hw_params->rx_queues + 1);
 
 	/* Set default coalescing parameters */
-	for (i = 0; i <= priv->hw_params->rx_queues; i++)
+	for (i = 0; i <= priv->hw_params->rx_queues; i++) {
+		priv->rx_rings[i].priv = priv;
+		priv->rx_rings[i].index = i;
 		priv->rx_rings[i].rx_max_coalesced_frames = 1;
+	}
 
 	/* Initialize u64 stats seq counter for 32bit machines */
 	for (i = 0; i <= GENET_MAX_MQ_CNT; i++) {
-- 
2.53.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
  2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
@ 2026-09-28 10:59 ` netdev-bot+sinfo
  2026-09-28 11:03   ` Nicolai Buchwitz
  2026-09-28 17:29 ` Florian Fainelli
  1 sibling, 1 reply; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 10:59 UTC (permalink / raw)
  To: Nicolai Buchwitz
  Cc: Doug Berger, Florian Fainelli,
	Broadcom internal kernel review list, Andrew Lunn,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Justin Chen, Florian Fainelli, netdev, linux-kernel

Hi!

This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:

 - What hardware the change was tested on. For driver fixes please
   mention the device (and if relevant firmware version) used for
   testing, or say that the change was not tested on real hardware.

Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.

The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
  2026-09-28 10:59 ` netdev-bot+sinfo
@ 2026-09-28 11:03   ` Nicolai Buchwitz
  0 siblings, 0 replies; 4+ messages in thread
From: Nicolai Buchwitz @ 2026-09-28 11:03 UTC (permalink / raw)
  To: netdev-bot+sinfo
  Cc: Doug Berger, Florian Fainelli,
	Broadcom internal kernel review list, Andrew Lunn,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Justin Chen, Florian Fainelli, netdev, linux-kernel

On 28.9.2026 12:59, netdev-bot+sinfo@kernel.org wrote:
> Hi!
> 
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
> 
>  - What hardware the change was tested on. For driver fixes please
>    mention the device (and if relevant firmware version) used for
>    testing, or say that the change was not tested on real hardware.

It was observed on a Raspberry Pi CM4, but should apply to all other
genet devices ...

> [...]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
  2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
  2026-09-28 10:59 ` netdev-bot+sinfo
@ 2026-09-28 17:29 ` Florian Fainelli
  1 sibling, 0 replies; 4+ messages in thread
From: Florian Fainelli @ 2026-09-28 17:29 UTC (permalink / raw)
  To: Nicolai Buchwitz, Doug Berger,
	Broadcom internal kernel review list, Andrew Lunn,
	David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
  Cc: Justin Chen, Florian Fainelli, netdev, linux-kernel

On 9/28/26 03:56, Nicolai Buchwitz wrote:
> The Rx ring priv and index are only set in bcmgenet_init_rx_ring(),
> which runs at open. Setting the Rx coalescing parameters on an interface
> that was never opened, e.g. "ethtool -C eth0 rx-usecs 50", dereferences
> a NULL ring->priv. The oops happens with RTNL held, so networking
> stays stuck until a reboot:
> 
>    Unable to handle kernel paging request at virtual address 0000000000002788
>    pc : bcmgenet_set_rx_coalesce.isra.0+0x10/0x88
>    lr : bcmgenet_set_coalesce+0xe8/0x180
>    Call trace:
>     bcmgenet_set_rx_coalesce.isra.0+0x10/0x88 (P)
>     __ethnl_set_coalesce.isra.0+0x490/0x570
>     ethnl_set_coalesce+0x48/0xc0
>     ethnl_default_set_doit+0xf4/0x230
>     genl_family_rcv_msg_doit+0xe8/0x160
>     genl_rcv_msg+0x220/0x2a0
>     netlink_rcv_skb+0x68/0x140
>     genl_rcv+0x40/0x60
>     netlink_unicast+0x338/0x3c0
>     netlink_sendmsg+0x19c/0x3f8
>     __sock_sendmsg+0x64/0xc0
>     __sys_sendto+0x124/0x198
>     __arm64_sys_sendto+0x30/0x48
> 
> Set priv and index at probe. Writing the registers while the interface
> is down is harmless because open resets the MAC and
> bcmgenet_init_rx_coalesce() reapplies the stored values.
> 
> Fixes: 9f4ca05827a2 ("net: bcmgenet: Add support for adaptive RX coalescing")
> Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>

Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>

Thanks Nicolai!
-- 
Florian

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-28 17:29 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
2026-09-28 10:59 ` netdev-bot+sinfo
2026-09-28 11:03   ` Nicolai Buchwitz
2026-09-28 17:29 ` Florian Fainelli

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®