From: Mingming Cao <mmc@linux.ibm.com>
To: netdev@vger.kernel.org
Cc: horms@kernel.org, davemarq@linux.ibm.com, bjking1@linux.ibm.com,
Mingming Cao <mmc@linux.ibm.com>,
nnac123@linux.ibm.com, maddy@linux.ibm.com, mpe@ellerman.id.au,
npiggin@gmail.com, chleroy@kernel.org, ritesh.list@gmail.com,
sshegde@linux.ibm.com, andrew+netdev@lunn.ch,
davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
pabeni@redhat.com, santil@us.ibm.com, jeff@garzik.org,
stephen@networkplumber.org, linuxppc-dev@lists.ozlabs.org,
linux-kernel@vger.kernel.org
Subject: [PATCH net-next v2 1/8] ibmveth: fix netpoll races with RX replenish
Date: Sun, 4 Oct 2026 23:06:02 -0700 [thread overview]
Message-ID: <c193ccda2af0b2e91e839d5caa9928274b80f498.1791178212.git.mmc@linux.ibm.com> (raw)
In-Reply-To: <cover.1791178212.git.mmc@linux.ibm.com>
ibmveth_poll_controller() runs RX replenish outside NAPI and without
a lock, racing NAPI's replenish on another CPU. Both can fill the
same slot, so an skb and its DMA mapping leak and PHYP can write
into an unmapped buffer. netpoll calls it from netconsole and from
netpoll-enabled bonds.
ibmveth_open() also enables NAPI before the RX resources exist.
ibmveth_change_mtu(), veth_pool_store(), ibmveth_set_csum_offload()
and ibmveth_set_tso() call close() and open() directly, so while
open() is still setting up, netpoll and the direct ibmveth_interrupt()
calls can replenish NULL pools and read freed memory.
Remove the callback, as Eric Dumazet did for many drivers after
commit ac3d9dd034e5 ("netpoll: make ndo_poll_controller() optional"),
including ibmvnic in commit 0c3b9d1b37df ("ibmvnic: remove
ndo_poll_controller"). netpoll then polls NAPI itself with budget 0.
napi->poll_owner serializes that with NAPI, but not with a NAPI poll
that was already running when netpoll was set up, so skip RX
replenish at budget 0, which netpoll uses for TX only. TX completes
synchronously, so ibmveth_poll() has nothing else to do for netpoll.
Enable NAPI just before request_irq(), once everything
ibmveth_poll() touches exists.
Found by AI-assisted review of the ibmveth multi-queue RX series and
confirmed by code inspection of poll_one_napi() and the direct
close()/open() callers; neither race was reproduced. Tested on a POWER10
LPAR with netconsole over ibmveth: a ping flood (678,470 packets, no
loss) during a printk flood, and MTU changes and buffer pool toggles
under traffic, with no warnings. No kernel selftests cover ibmveth.
Fixes: 6b4223748895 ("[PATCH] ibmveth: Add netpoll function")
Fixes: bea3348eef27 ("[NET]: Make NAPI polling independent of struct net_device objects.")
Signed-off-by: Mingming Cao <mmc@linux.ibm.com>
---
Changes in v2:
- skip RX replenish when ibmveth_poll() runs with budget 0:
napi->poll_owner does not serialize netpoll with a NAPI poll
that was already running when netpoll was set up
drivers/net/ethernet/ibm/ibmveth.c | 28 +++++++++++++---------------
1 file changed, 13 insertions(+), 15 deletions(-)
diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
index 73e051d26b9d..33af8e57be6e 100644
--- a/drivers/net/ethernet/ibm/ibmveth.c
+++ b/drivers/net/ethernet/ibm/ibmveth.c
@@ -623,8 +623,6 @@ static int ibmveth_open(struct net_device *netdev)
netdev_dbg(netdev, "open starting\n");
- napi_enable(&adapter->napi);
-
for(i = 0; i < IBMVETH_NUM_BUFF_POOLS; i++)
rxq_entries += adapter->rx_buff_pool[i].size;
@@ -712,10 +710,18 @@ static int ibmveth_open(struct net_device *netdev)
}
}
+ /* NAPI can run as soon as it is enabled, from netpoll during the
+ * direct close()/open() pairs or from a direct ibmveth_interrupt()
+ * call, so enable it only once everything ibmveth_poll() touches
+ * exists.
+ */
+ napi_enable(&adapter->napi);
+
netdev_dbg(netdev, "registering irq 0x%x\n", netdev->irq);
rc = request_irq(netdev->irq, ibmveth_interrupt, 0, netdev->name,
netdev);
if (rc != 0) {
+ napi_disable(&adapter->napi);
netdev_err(netdev, "unable to request irq 0x%x, rc %d\n",
netdev->irq, rc);
do {
@@ -763,7 +769,6 @@ static int ibmveth_open(struct net_device *netdev)
out_free_buffer_list:
free_page((unsigned long)adapter->buffer_list_addr);
out:
- napi_disable(&adapter->napi);
return rc;
}
@@ -1540,7 +1545,11 @@ static int ibmveth_poll(struct napi_struct *napi, int budget)
}
}
- ibmveth_replenish_task(adapter);
+ /* netpoll polls with budget 0 for TX only, and is not serialized
+ * with a NAPI poll that was already running when it was set up
+ */
+ if (budget)
+ ibmveth_replenish_task(adapter);
if (frames_processed == budget)
goto out;
@@ -1680,14 +1689,6 @@ static int ibmveth_change_mtu(struct net_device *dev, int new_mtu)
return -EINVAL;
}
-#ifdef CONFIG_NET_POLL_CONTROLLER
-static void ibmveth_poll_controller(struct net_device *dev)
-{
- ibmveth_replenish_task(netdev_priv(dev));
- ibmveth_interrupt(dev->irq, dev);
-}
-#endif
-
/**
* ibmveth_get_desired_dma - Calculate IO memory desired by the driver
*
@@ -1789,9 +1790,6 @@ static const struct net_device_ops ibmveth_netdev_ops = {
.ndo_validate_addr = eth_validate_addr,
.ndo_set_mac_address = ibmveth_set_mac_addr,
.ndo_features_check = ibmveth_features_check,
-#ifdef CONFIG_NET_POLL_CONTROLLER
- .ndo_poll_controller = ibmveth_poll_controller,
-#endif
};
static int ibmveth_probe(struct vio_dev *dev, const struct vio_device_id *id)
--
2.39.3 (Apple Git-146)
next parent reply other threads:[~2026-10-05 6:07 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <cover.1791178212.git.mmc@linux.ibm.com>
2026-10-05 6:06 ` Mingming Cao [this message]
2026-10-05 6:06 ` [PATCH net-next v2 2/8] ibmveth: do not close twice after a failed reopen Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 3/8] ibmveth: disable the reset work before unregister in remove Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 4/8] ibmveth: step past bad RX correlators instead of spinning or oopsing Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 5/8] ibmveth: release the pool kobjects when probe fails Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 6/8] ibmveth: return the error when set_channels cannot add TX queues Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 7/8] ibmveth: wait for in-flight transmits in ibmveth_close() Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 8/8] ibmveth: wait for the RX poll to return before freeing the RX queue Mingming Cao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c193ccda2af0b2e91e839d5caa9928274b80f498.1791178212.git.mmc@linux.ibm.com \
--to=mmc@linux.ibm.com \
--cc=andrew+netdev@lunn.ch \
--cc=bjking1@linux.ibm.com \
--cc=chleroy@kernel.org \
--cc=davem@davemloft.net \
--cc=davemarq@linux.ibm.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=jeff@garzik.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=netdev@vger.kernel.org \
--cc=nnac123@linux.ibm.com \
--cc=npiggin@gmail.com \
--cc=pabeni@redhat.com \
--cc=ritesh.list@gmail.com \
--cc=santil@us.ibm.com \
--cc=sshegde@linux.ibm.com \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®