From: Mina Almasry <almasrymina@google.com>
To: Jakub Kicinski <kuba@kernel.org>,
Mina Almasry <almasrymina@google.com>, David Wei <dw@davidwei.uk>,
Pavel Begunkov <asml.silence@gmail.com>,
Taehee Yoo <ap420073@gmail.com>,
Stanislav Fomichev <sdf@fomichev.me>,
Paolo Abeni <pabeni@redhat.com>,
Kaiyuan Zhang <kaiyuanz@google.com>,
Bobby Eshleman <bobbyeshleman@meta.com>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org, linux-media@vger.kernel.org,
dri-devel@lists.freedesktop.org
Cc: "Andrew Lunn" <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
"Eric Dumazet" <edumazet@kernel.org>,
"Simon Horman" <horms@kernel.org>,
"Shuah Khan" <shuah@kernel.org>,
"Sumit Semwal" <sumit.semwal@linaro.org>,
"Christian König" <christian.koenig@amd.com>,
"Daniel Borkmann" <daniel@iogearbox.net>,
"Nikolay Aleksandrov" <razor@blackwall.org>,
"Tariq Toukan" <tariqt@nvidia.com>,
"Kaifeng Wang" <kaifengw@google.com>
Subject: [PATCH net v1 4/4] selftests: net: add devmem RX and TX netdev unregister tests
Date: Sat, 10 Oct 2026 02:55:16 +0000 [thread overview]
Message-ID: <20261010025532.839559-5-almasrymina@google.com> (raw)
In-Reply-To: <20261010025532.839559-1-almasrymina@google.com>
Add devmem_bind_rx_unregister_check and devmem_bind_tx_unregister_check
to nl_netdev.py to verify that unregistering a netdevsim device while a
netlink socket holds an active RX or TX devmem binding synchronously
detaches the dma_buf attachment and cleanly closes the netlink socket
without use-after-free or page faults.
Cc: Tariq Toukan <tariqt@nvidia.com>
Cc: Kaifeng Wang <kaifengw@google.com>
Signed-off-by: Mina Almasry <almasrymina@google.com>
---
tools/testing/selftests/net/nl_netdev.py | 108 ++++++++++++++++++++++-
1 file changed, 105 insertions(+), 3 deletions(-)
diff --git a/tools/testing/selftests/net/nl_netdev.py b/tools/testing/selftests/net/nl_netdev.py
index ceb44c8e1fec5..bad230ee9dcd2 100755
--- a/tools/testing/selftests/net/nl_netdev.py
+++ b/tools/testing/selftests/net/nl_netdev.py
@@ -6,10 +6,14 @@ Tests for the netdev netlink family.
"""
import errno
+import fcntl
+import mmap
+import os
+import struct
from os import system
-from lib.py import ksft_run, ksft_exit
+from lib.py import ksft_run, ksft_exit, KsftSkipEx
from lib.py import ksft_eq, ksft_ge, ksft_ne, ksft_raises, ksft_busy_wait
-from lib.py import NetdevFamily, NetdevSimDev, NlError, defer, ip
+from lib.py import EthtoolFamily, NetdevFamily, NetdevSimDev, NlError, defer, ip
def empty_check(nf) -> None:
@@ -366,6 +370,102 @@ def page_pool_stats_ifindex_check(nf) -> None:
ksft_eq(cm.exception.nl_msg.extack['bad-attr'], '.info.id')
+def _create_udmabuf(num_pages=64) -> int:
+ """Create a sealed memfd-backed udmabuf fd for devmem tests."""
+ if not os.path.exists("/dev/udmabuf"):
+ raise KsftSkipEx("/dev/udmabuf is not available")
+
+ size = num_pages * mmap.PAGESIZE
+ memfd = os.memfd_create("devmem-ksft", os.MFD_ALLOW_SEALING)
+ os.ftruncate(memfd, size)
+ fcntl.fcntl(memfd, 1033, 0x0002) # F_ADD_SEALS, F_SEAL_SHRINK
+ devfd = os.open("/dev/udmabuf", os.O_RDWR)
+ req = bytearray(struct.pack("IIQQ", memfd, 0, 0, size))
+ dmabuf_fd = fcntl.ioctl(devfd, 0x40187542, req) # UDMABUF_CREATE
+ os.close(devfd)
+ os.close(memfd)
+ return dmabuf_fd
+
+
+def _dmabuf_attached_devs():
+ """Return attached device names from debugfs dma_buf/bufinfo if available."""
+ path = "/sys/kernel/debug/dma_buf/bufinfo"
+ if not os.path.exists(path):
+ return None
+ with open(path, "r", encoding="utf-8") as f:
+ text = f.read()
+ attached = []
+ in_attached = False
+ for line in text.splitlines():
+ if line.strip() == "Attached Devices:":
+ in_attached = True
+ continue
+ if in_attached:
+ if line.startswith("\t") and line.strip():
+ attached.append(line.strip())
+ else:
+ in_attached = False
+ return attached
+
+
+def devmem_bind_rx_unregister_check(_nf) -> None:
+ """Verify RX devmem bindings detach dma_buf synchronously on netdev unregister."""
+ dmabuf_fd = _create_udmabuf()
+ nf_priv = NetdevFamily()
+ ef = EthtoolFamily()
+ nsimdev = NetdevSimDev(queue_count=2)
+ nsim = nsimdev.nsims[0]
+
+ ip(f"link set dev {nsim.ifname} up")
+ ef.rings_set({"header": {"dev-index": nsim.ifindex},
+ "tcp-data-split": "enabled"})
+ nf_priv.bind_rx({
+ "ifindex": nsim.ifindex,
+ "fd": dmabuf_fd,
+ "queues": [{"id": 1, "type": "rx"}],
+ })
+
+ attached = _dmabuf_attached_devs()
+ if attached is not None:
+ ksft_ge(len(attached), 1)
+
+ nsimdev.remove()
+
+ attached = _dmabuf_attached_devs()
+ if attached is not None:
+ ksft_eq(len(attached), 0)
+
+ del nf_priv
+ os.close(dmabuf_fd)
+
+
+def devmem_bind_tx_unregister_check(_nf) -> None:
+ """Verify TX devmem bindings detach cleanly on netdev unregister without UAF."""
+ dmabuf_fd = _create_udmabuf()
+ nf_priv = NetdevFamily()
+ nsimdev = NetdevSimDev(queue_count=2)
+ nsim = nsimdev.nsims[0]
+
+ ip(f"link set dev {nsim.ifname} up")
+ nf_priv.bind_tx({
+ "ifindex": nsim.ifindex,
+ "fd": dmabuf_fd,
+ })
+
+ attached = _dmabuf_attached_devs()
+ if attached is not None:
+ ksft_ge(len(attached), 1)
+
+ nsimdev.remove()
+
+ attached = _dmabuf_attached_devs()
+ if attached is not None:
+ ksft_eq(len(attached), 0)
+
+ del nf_priv
+ os.close(dmabuf_fd)
+
+
def main() -> None:
""" Ksft boiler plate main """
nf = NetdevFamily()
@@ -379,7 +479,9 @@ def main() -> None:
page_pool_check,
page_pool_dump_ifindex,
page_pool_ifindex_leak_check,
- page_pool_stats_ifindex_check
+ page_pool_stats_ifindex_check,
+ devmem_bind_rx_unregister_check,
+ devmem_bind_tx_unregister_check
],
args=(nf, ))
ksft_exit()
--
2.56.0.385.gd3acb90ef8-goog
prev parent reply other threads:[~2026-10-10 2:55 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-10 2:55 [PATCH net v1 0/4] net: devmem: fix RX and TX binding teardown on device unregistration Mina Almasry
2026-10-10 2:55 ` [PATCH net v1 1/4] net: devmem: unmap dma_buf synchronously on queue uninstall Mina Almasry
2026-10-10 14:02 ` Pavel Begunkov
2026-10-10 2:55 ` [PATCH net v1 2/4] net: devmem: detach TX bindings on NETDEV_UNREGISTER Mina Almasry
2026-10-10 2:55 ` [PATCH net v1 3/4] netdevsim: support devmem RX and TX bindings Mina Almasry
2026-10-10 2:55 ` Mina Almasry [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261010025532.839559-5-almasrymina@google.com \
--to=almasrymina@google.com \
--cc=andrew+netdev@lunn.ch \
--cc=ap420073@gmail.com \
--cc=asml.silence@gmail.com \
--cc=bobbyeshleman@meta.com \
--cc=christian.koenig@amd.com \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=dri-devel@lists.freedesktop.org \
--cc=dw@davidwei.uk \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kaifengw@google.com \
--cc=kaiyuanz@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=razor@blackwall.org \
--cc=sdf@fomichev.me \
--cc=shuah@kernel.org \
--cc=sumit.semwal@linaro.org \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®