* [PATCH net] usbnet: fix EVENT_RX_PAUSED race in usbnet_skb_return()
@ 2026-10-04 22:37 Ömer Mete Kaya
2026-10-04 22:43 ` netdev-bot+sinfo
0 siblings, 1 reply; 3+ messages in thread
From: Ömer Mete Kaya @ 2026-10-04 22:37 UTC (permalink / raw)
To: netdev
Cc: oneukum, andrew+netdev, davem, edumazet, kuba, pabeni, linux-usb,
linux-kernel, syzbot+04cd90bb99c6ef81a65d, Ömer Mete Kaya
usbnet_resume_rx() uses local_bh_disable() to synchronize with
usbnet_skb_return(), but local_bh_disable() only affects the local CPU.
On SMP, usbnet_skb_return() on CPU0 can pass the test_bit() check while
CPU1 runs usbnet_resume_rx(), clears the flag and drains the queue,
leaving the skb stranded in rxq_pause until the next MTU change or
device stop.
Fix with a double-check pattern under rxq_pause.lock: normal RX avoids
the lock via an unlocked test_bit() fast path; on the slow path the lock
is taken and the flag rechecked before enqueuing. Move clear_bit() in
usbnet_resume_rx() under the same lock to make the flag and queue
transitions atomic.
Fixes: 43daa96b166c ("usbnet: Stop RX Q on MTU change")
Signed-off-by: Ömer Mete Kaya <omermetekaya0@gmail.com>
---
drivers/net/usb/usbnet.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/drivers/net/usb/usbnet.c b/drivers/net/usb/usbnet.c
index 0288d89e1d13..5eba2cef8bac 100644
--- a/drivers/net/usb/usbnet.c
+++ b/drivers/net/usb/usbnet.c
@@ -329,13 +329,15 @@ void usbnet_skb_return(struct usbnet *dev, struct sk_buff *skb)
unsigned long flags;
int status;
- spin_lock_bh(&dev->rxq_pause.lock);
- if (test_bit(EVENT_RX_PAUSED, &dev->flags)) {
- __skb_queue_tail(&dev->rxq_pause, skb);
+ if (unlikely(test_bit(EVENT_RX_PAUSED, &dev->flags))) {
+ spin_lock_bh(&dev->rxq_pause.lock);
+ if (test_bit(EVENT_RX_PAUSED, &dev->flags)) {
+ __skb_queue_tail(&dev->rxq_pause, skb);
+ spin_unlock_bh(&dev->rxq_pause.lock);
+ return;
+ }
spin_unlock_bh(&dev->rxq_pause.lock);
- return;
}
- spin_unlock_bh(&dev->rxq_pause.lock);
/* only update if unset to allow minidriver rx_fixup override */
if (skb->protocol == 0)
--
2.55.0
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH net] usbnet: fix EVENT_RX_PAUSED race in usbnet_skb_return()
2026-10-04 22:37 [PATCH net] usbnet: fix EVENT_RX_PAUSED race in usbnet_skb_return() Ömer Mete Kaya
@ 2026-10-04 22:43 ` netdev-bot+sinfo
2026-10-04 22:44 ` Ömer Mete Kaya
0 siblings, 1 reply; 3+ messages in thread
From: netdev-bot+sinfo @ 2026-10-04 22:43 UTC (permalink / raw)
To: Ömer Mete Kaya
Cc: netdev, oneukum, andrew+netdev, davem, edumazet, kuba, pabeni,
linux-usb, linux-kernel, syzbot+04cd90bb99c6ef81a65d
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] usbnet: fix EVENT_RX_PAUSED race in usbnet_skb_return()
2026-10-04 22:43 ` netdev-bot+sinfo
@ 2026-10-04 22:44 ` Ömer Mete Kaya
0 siblings, 0 replies; 3+ messages in thread
From: Ömer Mete Kaya @ 2026-10-04 22:44 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: netdev, oneukum, andrew+netdev, davem, edumazet, kuba, pabeni,
linux-usb, linux-kernel, syzbot+04cd90bb99c6ef81a65d
On 10/5/26 01:43, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - How the issue was discovered, e.g. hit in production, hit during
> development, syzbot report, manual code inspection, LLM or static
> analysis tool scan.
Sashiko pointed it out.
> - Whether the issue was actually triggered, or is only theoretical
> (e.g. found by code inspection). If it was triggered please include
> the symptoms, like the stack trace or error messages.
Theoretical.
> Please do not repost the series just to address the above. Instead,
> reply to this email with the missing information, so that reviewers
> can take it into account. If the series needs another revision for
> other reasons, please include the information in the commit messages
> then.
>
> The evaluation is done by an LLM so it may be wrong, if you think
> that is the case please reply and explain.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-04 22:44 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-04 22:37 [PATCH net] usbnet: fix EVENT_RX_PAUSED race in usbnet_skb_return() Ömer Mete Kaya
2026-10-04 22:43 ` netdev-bot+sinfo
2026-10-04 22:44 ` Ömer Mete Kaya
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®