* [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
@ 2026-09-28 10:56 Nicolai Buchwitz
2026-09-28 10:59 ` netdev-bot+sinfo
2026-09-28 17:29 ` Florian Fainelli
0 siblings, 2 replies; 4+ messages in thread
From: Nicolai Buchwitz @ 2026-09-28 10:56 UTC (permalink / raw)
To: Doug Berger, Florian Fainelli, Nicolai Buchwitz,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
Cc: Justin Chen, Florian Fainelli, netdev, linux-kernel
The Rx ring priv and index are only set in bcmgenet_init_rx_ring(),
which runs at open. Setting the Rx coalescing parameters on an interface
that was never opened, e.g. "ethtool -C eth0 rx-usecs 50", dereferences
a NULL ring->priv. The oops happens with RTNL held, so networking
stays stuck until a reboot:
Unable to handle kernel paging request at virtual address 0000000000002788
pc : bcmgenet_set_rx_coalesce.isra.0+0x10/0x88
lr : bcmgenet_set_coalesce+0xe8/0x180
Call trace:
bcmgenet_set_rx_coalesce.isra.0+0x10/0x88 (P)
__ethnl_set_coalesce.isra.0+0x490/0x570
ethnl_set_coalesce+0x48/0xc0
ethnl_default_set_doit+0xf4/0x230
genl_family_rcv_msg_doit+0xe8/0x160
genl_rcv_msg+0x220/0x2a0
netlink_rcv_skb+0x68/0x140
genl_rcv+0x40/0x60
netlink_unicast+0x338/0x3c0
netlink_sendmsg+0x19c/0x3f8
__sock_sendmsg+0x64/0xc0
__sys_sendto+0x124/0x198
__arm64_sys_sendto+0x30/0x48
Set priv and index at probe. Writing the registers while the interface
is down is harmless because open resets the MAC and
bcmgenet_init_rx_coalesce() reapplies the stored values.
Fixes: 9f4ca05827a2 ("net: bcmgenet: Add support for adaptive RX coalescing")
Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
---
drivers/net/ethernet/broadcom/genet/bcmgenet.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/broadcom/genet/bcmgenet.c b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
index f725d26e6020..e8908916558b 100644
--- a/drivers/net/ethernet/broadcom/genet/bcmgenet.c
+++ b/drivers/net/ethernet/broadcom/genet/bcmgenet.c
@@ -4151,8 +4151,11 @@ static int bcmgenet_probe(struct platform_device *pdev)
netif_set_real_num_rx_queues(priv->dev, priv->hw_params->rx_queues + 1);
/* Set default coalescing parameters */
- for (i = 0; i <= priv->hw_params->rx_queues; i++)
+ for (i = 0; i <= priv->hw_params->rx_queues; i++) {
+ priv->rx_rings[i].priv = priv;
+ priv->rx_rings[i].index = i;
priv->rx_rings[i].rx_max_coalesced_frames = 1;
+ }
/* Initialize u64 stats seq counter for 32bit machines */
for (i = 0; i <= GENET_MAX_MQ_CNT; i++) {
--
2.53.0
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
@ 2026-09-28 10:59 ` netdev-bot+sinfo
2026-09-28 11:03 ` Nicolai Buchwitz
2026-09-28 17:29 ` Florian Fainelli
1 sibling, 1 reply; 4+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 10:59 UTC (permalink / raw)
To: Nicolai Buchwitz
Cc: Doug Berger, Florian Fainelli,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Justin Chen, Florian Fainelli, netdev, linux-kernel
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- What hardware the change was tested on. For driver fixes please
mention the device (and if relevant firmware version) used for
testing, or say that the change was not tested on real hardware.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
2026-09-28 10:59 ` netdev-bot+sinfo
@ 2026-09-28 11:03 ` Nicolai Buchwitz
0 siblings, 0 replies; 4+ messages in thread
From: Nicolai Buchwitz @ 2026-09-28 11:03 UTC (permalink / raw)
To: netdev-bot+sinfo
Cc: Doug Berger, Florian Fainelli,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Justin Chen, Florian Fainelli, netdev, linux-kernel
On 28.9.2026 12:59, netdev-bot+sinfo@kernel.org wrote:
> Hi!
>
> This is an automated message. This series looks like a fix, but its
> commit messages seem to be missing some information:
>
> - What hardware the change was tested on. For driver fixes please
> mention the device (and if relevant firmware version) used for
> testing, or say that the change was not tested on real hardware.
It was observed on a Raspberry Pi CM4, but should apply to all other
genet devices ...
> [...]
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open
2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
2026-09-28 10:59 ` netdev-bot+sinfo
@ 2026-09-28 17:29 ` Florian Fainelli
1 sibling, 0 replies; 4+ messages in thread
From: Florian Fainelli @ 2026-09-28 17:29 UTC (permalink / raw)
To: Nicolai Buchwitz, Doug Berger,
Broadcom internal kernel review list, Andrew Lunn,
David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni
Cc: Justin Chen, Florian Fainelli, netdev, linux-kernel
On 9/28/26 03:56, Nicolai Buchwitz wrote:
> The Rx ring priv and index are only set in bcmgenet_init_rx_ring(),
> which runs at open. Setting the Rx coalescing parameters on an interface
> that was never opened, e.g. "ethtool -C eth0 rx-usecs 50", dereferences
> a NULL ring->priv. The oops happens with RTNL held, so networking
> stays stuck until a reboot:
>
> Unable to handle kernel paging request at virtual address 0000000000002788
> pc : bcmgenet_set_rx_coalesce.isra.0+0x10/0x88
> lr : bcmgenet_set_coalesce+0xe8/0x180
> Call trace:
> bcmgenet_set_rx_coalesce.isra.0+0x10/0x88 (P)
> __ethnl_set_coalesce.isra.0+0x490/0x570
> ethnl_set_coalesce+0x48/0xc0
> ethnl_default_set_doit+0xf4/0x230
> genl_family_rcv_msg_doit+0xe8/0x160
> genl_rcv_msg+0x220/0x2a0
> netlink_rcv_skb+0x68/0x140
> genl_rcv+0x40/0x60
> netlink_unicast+0x338/0x3c0
> netlink_sendmsg+0x19c/0x3f8
> __sock_sendmsg+0x64/0xc0
> __sys_sendto+0x124/0x198
> __arm64_sys_sendto+0x30/0x48
>
> Set priv and index at probe. Writing the registers while the interface
> is down is harmless because open resets the MAC and
> bcmgenet_init_rx_coalesce() reapplies the stored values.
>
> Fixes: 9f4ca05827a2 ("net: bcmgenet: Add support for adaptive RX coalescing")
> Signed-off-by: Nicolai Buchwitz <nb@tipi-net.de>
Reviewed-by: Florian Fainelli <florian.fainelli@broadcom.com>
Thanks Nicolai!
--
Florian
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-28 17:29 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 10:56 [PATCH net] net: bcmgenet: fix NULL dereference in set_coalesce before first open Nicolai Buchwitz
2026-09-28 10:59 ` netdev-bot+sinfo
2026-09-28 11:03 ` Nicolai Buchwitz
2026-09-28 17:29 ` Florian Fainelli
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®