From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 069D13E5EF8 for ; Wed, 30 Sep 2026 07:09:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790752155; cv=none; b=StF3PLAj1wKb76/tTeLWLt2iKcZjjGnbmFuCqas1B3Kbk5X8qUe0LKmY7JnBbzdR9CcnRIkAO7sDlRKqL5mmh1sE49df8GBloh4LulKj5FJkCn/S02tcuCHykIRoneeBkimvcZysMxTVjJzUu65rYR/bwlSFNI7xlXVtALE15W4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790752155; c=relaxed/simple; bh=kUJ6AZwh1W1UbN+W0pIvxx+NYxdVnJ7wO2p2cLzdAzw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=De4PQNoHPCpu09k16ErDLIBfg+1RLlnUUQb7IDqpS5tZaOro+MICf2y+yGg1kXFzX3PaN//suIY1cpKaNArZAGRoa5FnN1cZOjhcbIOMsWPQMMmMh2ET8hEk7XAnhx93+Osug5vMtGpO7AqqEQKZ4mnR6F8mB3xTlq4wkhYTa1A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=H957+iZL; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="H957+iZL" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790752152; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=g2+MnM/YIgixxkMmTeuWBOIVUrZVmFR9eLMZG/rNhnQ=; b=H957+iZLmUjZK6OWcxOlGUFFyPsol821CMajzb2TR+p0o42LSmSK0Hd9vrNMkc6C1SxO2B t9Mn8cpi72t7UgMAJmJfCUDqw7nFT7mp3k3Mq+KDejYZ7hb49H0yMjhthZyYhHeNmImP6/ pZgCIOJnPFRHNwRJ2EKEvv3OzHLqjYg= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-14-HqjLmjYlNGKACq-MU47iYg-1; Wed, 30 Sep 2026 03:09:09 -0400 X-MC-Unique: HqjLmjYlNGKACq-MU47iYg-1 X-Mimecast-MFC-AGG-ID: HqjLmjYlNGKACq-MU47iYg_1790752146 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5522B1955EAB; Wed, 30 Sep 2026 07:09:06 +0000 (UTC) Received: from localhost (unknown [10.74.80.98]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 21A9C180035F; Wed, 30 Sep 2026 07:09:04 +0000 (UTC) From: Vaibhav Nagare To: davem@davemloft.net, kuba@kernel.org, pabeni@redhat.com, edumazet@google.com, michael.chan@broadcom.com, pavan.chebbi@broadcom.com Cc: ast@kernel.org, daniel@iogearbox.net, hawk@kernel.org, john.fastabend@gmail.com, sdf@fomichev.me, andrew+netdev@lunn.ch, netdev@vger.kernel.org, bpf@vger.kernel.org, linux-kernel@vger.kernel.org, nagarevaibhav@gmail.com, Vaibhav Nagare , stable@vger.kernel.org Subject: [PATCH net v2] bnxt_en: don't leave an XDP program installed when the open fails Date: Wed, 30 Sep 2026 12:39:01 +0530 Message-ID: <20260930070901.1218980-1-vnagare@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 bnxt_xdp_set() stores the new program and drops the reference on the old one before reopening the NIC. If bnxt_open_nic() then fails, ndo_bpf() returns an error with the new program still in bp->xdp_prog. The caller treats the error as "nothing was installed" and drops its own reference, so bp->xdp_prog is left pointing at a freed program and the next XDP update dereferences it: BUG: unable to handle page fault for address: ff78ecc80ddd1038 RIP: 0010:__bpf_prog_put+0x5/0x80 Call Trace: bnxt_xdp_set+0xad/0x1b0 [bnxt_en] dev_xdp_propagate+0x36/0xa0 bond_xdp_set+0xeb/0x2d0 [bonding] dev_xdp_install+0x1b1/0x350 bpf_xdp_link_update+0xc5/0x1b0 link_update+0x104/0x1e0 __sys_bpf+0x662/0xcf0 Seen on a 6.12 based kernel after bnxt_alloc_mem() failed an order-4 allocation on a fragmented host: bnxt_en 0000:a0:00.1 ens4f1np1: nic open fail (rc: fffffff4) bond1: (slave ens4f1np1): Error -12 calling ndo_bpf Bonding is not required to hit this; a plain XDP attach on a bnxt interface takes the same path. Restore the previous program when the open fails and release it only once the change has been committed. Also restore the ring and feature configuration that was in service before the change: without it a failed detach leaves bp->xdp_prog set while page mode is off, so bnxt_init_one_rx_ring() never assigns rxr->xdp_prog on a later open and the program is reported as attached while no packet ever reaches it. Fixes: c6d30e8391b8 ("bnxt_en: Add basic XDP support.") Cc: stable@vger.kernel.org Signed-off-by: Vaibhav Nagare --- v2: - also restore the ring and feature configuration on the error path, not just bp->xdp_prog, so a later successful open cannot bring the device up with the driver state and the XDP program out of sync (Michael Chan) - v1: https://lore.kernel.org/netdev/20260928131458.1012180-1-vnagare@redhat.com/ drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c | 48 ++++++++++++------- 1 file changed, 32 insertions(+), 16 deletions(-) diff --git a/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c b/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c index 9e5009be8e98..edfd751a601a 100644 --- a/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c +++ b/drivers/net/ethernet/broadcom/bnxt/bnxt_xdp.c @@ -381,11 +381,31 @@ int bnxt_xdp_xmit(struct net_device *dev, int num_frames, return nxmit; } +static void bnxt_xdp_apply_cfg(struct bnxt *bp, int tx_xdp) +{ + struct net_device *dev = bp->dev; + int tc = bp->num_tc ? : 1; + + if (bp->xdp_prog) { + bnxt_set_rx_skb_mode(bp, true); + xdp_features_set_redirect_target_locked(dev, true); + } else { + xdp_features_clear_redirect_target_locked(dev); + bnxt_set_rx_skb_mode(bp, false); + } + bp->tx_nr_rings_xdp = tx_xdp; + bp->tx_nr_rings = bp->tx_nr_rings_per_tc * tc + tx_xdp; + bnxt_set_cp_rings(bp, true); + bnxt_set_tpa_flags(bp); + bnxt_set_ring_params(bp); +} + static int bnxt_xdp_set(struct bnxt *bp, struct bpf_prog *prog) { struct net_device *dev = bp->dev; int tx_xdp = 0, rc, tc; struct bpf_prog *old; + int old_tx_xdp; netdev_assert_locked(dev); @@ -418,25 +438,21 @@ static int bnxt_xdp_set(struct bnxt *bp, struct bpf_prog *prog) if (netif_running(dev)) bnxt_close_nic(bp, true, false); + old_tx_xdp = bp->tx_nr_rings_xdp; old = xchg(&bp->xdp_prog, prog); - if (old) - bpf_prog_put(old); - - if (prog) { - bnxt_set_rx_skb_mode(bp, true); - xdp_features_set_redirect_target_locked(dev, true); - } else { - xdp_features_clear_redirect_target_locked(dev); - bnxt_set_rx_skb_mode(bp, false); + bnxt_xdp_apply_cfg(bp, tx_xdp); + + if (netif_running(dev)) { + rc = bnxt_open_nic(bp, true, false); + if (rc) { + WRITE_ONCE(bp->xdp_prog, old); + bnxt_xdp_apply_cfg(bp, old_tx_xdp); + return rc; + } } - bp->tx_nr_rings_xdp = tx_xdp; - bp->tx_nr_rings = bp->tx_nr_rings_per_tc * tc + tx_xdp; - bnxt_set_cp_rings(bp, true); - bnxt_set_tpa_flags(bp); - bnxt_set_ring_params(bp); - if (netif_running(dev)) - return bnxt_open_nic(bp, true, false); + if (old) + bpf_prog_put(old); return 0; } -- 2.55.0