From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 397095226A6; Fri, 9 Oct 2026 18:33:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791570836; cv=none; b=WOltWDXTR+3qAO7w0pNJe+5ZEBmxwmoQpRjUslgYXWC6ej+z4MUy1cEFACxpoEKBx67qQ3FYSf8tJPRsi9tzwfkdjod05pgnNO574Irr1Qdooo2UlZ1Ewq1tPdYgu1wypIHGj4Xf8w1ccrbz9Qs7O3S3yNxcj4JVMIhTfEqBXrI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791570836; c=relaxed/simple; bh=k2rl3WMxxUX5AOO1je3EYT+sDLRU5TMhoOTBHdpMeM0=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=dCJPuo5WqEpgfyvIBxC2kVpxT4zTkoszgYIaRQi7X1sOmZGA/Hllh/ESlMkBpAG5tPdhhHfYHFVEyr2BD/W2siFmm08aJ82ghNcXzsY7pkXmvopjMCSuqWwwqFG8z3N82zW28SHb0aSQb3R+bMcMJDHkm/Y/9DrXgGb2dm+s5II= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=amjHZmyF; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="amjHZmyF" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 699Ha6a9736803; Fri, 9 Oct 2026 18:33:30 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=gn7JSjxEO2oxEeDJR A/Ey+Hi+F3HFkQlEvslONYvAwY=; b=amjHZmyFvr5iUjTKCH8nUJMN2mfr+Kxje TxCtS0KHmhCX0Hs6AwVcGr09S9azmofBeJ3peNvFzM5nPjezWcuFnz+v0yERXBsr X6+wKWEtIiUQYY1Tr+b+T/47A4fyQPIS+UElqxZaqeWSVlu8W8phmQabQnhbdtyJ fUGT4nDJ0GO5C/xtMX9Ywxyhkq63bQLE8nMG9YB3C5sj7FLeo03v9TqOhqAP/1b2 0cgHN0Y9hIF54wwMBeYNKHBJ0JFWb+BX+1yTFheVWrQBYuEGlaUzLdily5TU0ksE 4rfmzZ15ChYtd751JcONWU2Nepa5YbXGg8Ra7b9sqXhPXsLCTslCA== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4h74tdr90p-1 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Fri, 09 Oct 2026 18:33:29 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.11/8.18.1.11) with ESMTP id 699HND0X1169831; Fri, 9 Oct 2026 18:33:29 GMT Received: from smtprelay07.wdc07v.mail.ibm.com ([172.16.1.74]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4h5s351xgm-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 09 Oct 2026 18:33:29 +0000 (GMT) Received: from smtpav02.dal12v.mail.ibm.com (smtpav02.dal12v.mail.ibm.com [10.241.53.101]) by smtprelay07.wdc07v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 699IXQ9Q23396924 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 9 Oct 2026 18:33:27 GMT Received: from smtpav02.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id B447D5805E; Fri, 9 Oct 2026 18:33:26 +0000 (GMT) Received: from smtpav02.dal12v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 655975805C; Fri, 9 Oct 2026 18:33:24 +0000 (GMT) Received: from localhost.localdomain (unknown [9.67.110.242]) by smtpav02.dal12v.mail.ibm.com (Postfix) with ESMTP; Fri, 9 Oct 2026 18:33:24 +0000 (GMT) From: Mingming Cao To: netdev@vger.kernel.org Cc: maddy@linux.ibm.com, mpe@ellerman.id.au, npiggin@gmail.com, chleroy@kernel.org, ritesh.list@gmail.com, sshegde@linux.ibm.com, nnac123@linux.ibm.com, andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org, pabeni@redhat.com, linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org, horms@kernel.org, davemarq@linux.ibm.com, bjking1@linux.ibm.com, jeff@garzik.org Subject: [PATCH net-next v3 5/8] ibmveth: release the pool kobjects when probe fails Date: Fri, 9 Oct 2026 11:32:55 -0700 Message-Id: <20261009183258.18624-6-mmc@linux.ibm.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20261009183258.18624-1-mmc@linux.ibm.com> References: <20261009183258.18624-1-mmc@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Authority-Analysis: v=2.4 cv=JL6uIMKb c=1 sm=1 tr=0 ts=6ac9337a cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=660iZSQnnn4A:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=9zeWAwZ5pCssfL0I92cA:9 X-Proofpoint-ORIG-GUID: vZ7cfTOn4LUFqb4oh5Mur_Sq0muIrJWc X-Proofpoint-GUID: V0lwbDMOIanBZ7Mp5B3BKBJBtzVJje6c X-Proofpoint-Spam-Info: AW1haW4tMjYxMDA5MDA3MiBTYWx0ZWRfX8yn2K8Gkg+XW FKENPbesoporWuc6Iivm1OfDx3+Cd24+D7DcJ0yyLKDq71Nh8PUGQwiqYemBEyQucCP2i3z3PAC CGWRan54dDaK3zScxCPvxyO1gtR6W1U= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYxMDA5MDA3MiBTYWx0ZWRfX3YmkkRBP+IXI 8Rq70Z4fbjQq/X4GVrGwDdX9+xLVboNGBcA3Jw5c9FyjCXBqsPErzyWiGWq1JGM8KUfW/6FE6CJ GPrekkj44/fJFPXAJELa1AMfvCGoVEKyIs9o9Wx2gJwerFp6/jteSM4Buascl3x0Ad6u4vip8RH b4m7SCtQ0Tcx3aB7A5bh6w1Vg6MB3EcPl2CKdqAAD4P15oOFB43xbhbOcNKr2YSXF4mK2Ni1B0F qAkgM2ZtAjpBiPi6rJdDdTxgaF6RK+K10qJMF3SO8MVk5wJIE7PBqn8wGp6H8YUea9sUoptGcTj mzbdTxOf8thmlFfyrRf3sUhKhgstSq2fb5Z5WHx9FV0U13HTV2ws3EKGVgY6VPXc87Uw0lt7tNe CeJV7JKlI6UPacSirTn+txs7x4SqRi5Ta207opUc4pkdp4n/I1FGc39bWaWldF40bxKTRzGiFXg kfGNQSrr+muJxGgo2PQ== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-10-09_05,2026-10-09_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 spamscore=0 bulkscore=0 impostorscore=0 adultscore=0 lowpriorityscore=0 priorityscore=1501 clxscore=1015 malwarescore=0 phishscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2610080000 definitions=main-2610090072 If register_netdev() fails in ibmveth_probe(), for example with -EINTR when the binding task is killed, probe frees the netdev but leaves the pool%d kobjects embedded in it registered in sysfs. Reading /sys/devices/vio//pool0/num is then a use-after-free, and the next probe cannot add pool0. Put the kobjects before freeing the netdev, as ibmveth_remove() does, on this path and on the netif_set_real_num_tx_queues() one. The kobjects also have no release(). With CONFIG_DEBUG_KOBJECT_RELEASE, kobject_put() defers their cleanup, including removing the sysfs files, to a work item, so free_netdev() can free them first, here and in remove(). Add a release() that signals a per-pool completion, and wait for it in both places before free_netdev(). Without that config, release() runs from kobject_put() and the wait returns at once. Found by AI-assisted review of the ibmveth multi-queue RX series and confirmed by code inspection; the release() part was raised by the Sashiko AI review of the first version. Tested on a POWER10 LPAR with register_netdev() forced to fail with -EINTR by a test-only module parameter (not part of this patch): no pool%d directories remain and the device binds again. No kernel selftests cover ibmveth. Fixes: 860f242eb534 ("[PATCH] ibmveth change buffer pools dynamically") Signed-off-by: Mingming Cao --- Changes in v2: - give the pool kobjects a release() that signals a per-pool completion, and wait for it before free_netdev() in probe and remove(); with CONFIG_DEBUG_KOBJECT_RELEASE the deferred cleanup could run after the free (Sashiko review of v1) - put the kobjects through one helper, ibmveth_put_pool_kobjs(), and an err_put_pools label for both probe failure paths drivers/net/ethernet/ibm/ibmveth.c | 52 +++++++++++++++++++++++++----- drivers/net/ethernet/ibm/ibmveth.h | 3 ++ 2 files changed, 47 insertions(+), 8 deletions(-) diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c index 55c0b5d6e0a9..dc5e63b7369e 100644 --- a/drivers/net/ethernet/ibm/ibmveth.c +++ b/drivers/net/ethernet/ibm/ibmveth.c @@ -1890,6 +1890,40 @@ static const struct net_device_ops ibmveth_netdev_ops = { .ndo_features_check = ibmveth_features_check, }; +/** + * ibmveth_pool_kobj_release - Mark a pool kobject finished + * @kobj: kobject embedded in the pool + * + * The pool kobjects live in netdev_priv(), so the last put must wait + * for this before free_netdev(). + */ +static void ibmveth_pool_kobj_release(struct kobject *kobj) +{ + struct ibmveth_buff_pool *pool = container_of(kobj, + struct ibmveth_buff_pool, + kobj); + + complete(&pool->released); +} + +/** + * ibmveth_put_pool_kobjs - Drop the pool kobjects and wait for release + * @adapter: ibmveth adapter + * + * With CONFIG_DEBUG_KOBJECT_RELEASE the cleanup, including removing the + * sysfs files, runs later from a work item in the kobject; wait for it + * so free_netdev() cannot free the pools first. + */ +static void ibmveth_put_pool_kobjs(struct ibmveth_adapter *adapter) +{ + int i; + + for (i = 0; i < IBMVETH_NUM_BUFF_POOLS; i++) + kobject_put(&adapter->rx_buff_pool[i].kobj); + for (i = 0; i < IBMVETH_NUM_BUFF_POOLS; i++) + wait_for_completion(&adapter->rx_buff_pool[i].released); +} + static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) { int rc, i, mac_len; @@ -2000,6 +2034,7 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) ibmveth_init_buffer_pool(&adapter->rx_buff_pool[i], i, pool_count[i], pool_size[i], pool_active[i]); + init_completion(&adapter->rx_buff_pool[i].released); error = kobject_init_and_add(kobj, &ktype_veth_pool, &dev->dev.kobj, "pool%d", i); if (!error) @@ -2011,8 +2046,7 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) if (rc) { netdev_dbg(netdev, "failed to set number of tx queues rc=%d\n", rc); - free_netdev(netdev); - return rc; + goto err_put_pools; } adapter->tx_ltb_size = PAGE_ALIGN(IBMVETH_MAX_TX_BUF_SIZE); for (i = 0; i < IBMVETH_MAX_QUEUES; i++) @@ -2027,25 +2061,27 @@ static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id) if (rc) { netdev_dbg(netdev, "failed to register netdev rc=%d\n", rc); - free_netdev(netdev); - return rc; + goto err_put_pools; } netdev_dbg(netdev, "registered\n"); return 0; + +err_put_pools: + ibmveth_put_pool_kobjs(adapter); + free_netdev(netdev); + return rc; } static void ibmveth_remove(struct vio_dev *dev) { struct net_device *netdev = dev_get_drvdata(&dev->dev); struct ibmveth_adapter *adapter = netdev_priv(netdev); - int i; disable_work_sync(&adapter->work); - for (i = 0; i < IBMVETH_NUM_BUFF_POOLS; i++) - kobject_put(&adapter->rx_buff_pool[i].kobj); + ibmveth_put_pool_kobjs(adapter); unregister_netdev(netdev); @@ -2221,7 +2257,7 @@ static const struct sysfs_ops veth_pool_ops = { }; static struct kobj_type ktype_veth_pool = { - .release = NULL, + .release = ibmveth_pool_kobj_release, .sysfs_ops = &veth_pool_ops, .default_groups = veth_pool_groups, }; diff --git a/drivers/net/ethernet/ibm/ibmveth.h b/drivers/net/ethernet/ibm/ibmveth.h index 3f2240823f6a..be0939caa328 100644 --- a/drivers/net/ethernet/ibm/ibmveth.h +++ b/drivers/net/ethernet/ibm/ibmveth.h @@ -14,6 +14,8 @@ #ifndef _IBMVETH_H #define _IBMVETH_H +#include + /* constants for H_MULTICAST_CTRL */ #define IbmVethMcastReceptionModifyBit 0x80000UL #define IbmVethMcastReceptionEnableBit 0x20000UL @@ -143,6 +145,7 @@ struct ibmveth_buff_pool { struct sk_buff **skbuff; int active; struct kobject kobj; + struct completion released; }; struct ibmveth_rx_q { -- 2.50.1 (Apple Git-155)