From: Mingming Cao <mmc@linux.ibm.com>
To: netdev@vger.kernel.org
Cc: horms@kernel.org, davemarq@linux.ibm.com, bjking1@linux.ibm.com,
Mingming Cao <mmc@linux.ibm.com>,
nnac123@linux.ibm.com, maddy@linux.ibm.com, mpe@ellerman.id.au,
npiggin@gmail.com, chleroy@kernel.org, ritesh.list@gmail.com,
sshegde@linux.ibm.com, andrew+netdev@lunn.ch,
davem@davemloft.net, edumazet@kernel.org, kuba@kernel.org,
pabeni@redhat.com, jeff@garzik.org,
linuxppc-dev@lists.ozlabs.org, linux-kernel@vger.kernel.org
Subject: [PATCH net-next v2 2/8] ibmveth: do not close twice after a failed reopen
Date: Sun, 4 Oct 2026 23:06:03 -0700 [thread overview]
Message-ID: <f9f424944b0ed249ea5288e728832867cd945e1d.1791178212.git.mmc@linux.ibm.com> (raw)
In-Reply-To: <cover.1791178212.git.mmc@linux.ibm.com>
ibmveth_change_mtu(), veth_pool_store(), ibmveth_set_csum_offload()
and ibmveth_set_tso() call close() and open() directly. If open() fails,
NAPI is left disabled while IFF_UP stays set, so the next close()
(ifdown, unregister or another reconfiguration) calls napi_disable()
again and waits forever with RTNL held. Networking and shutdown
hang; only a reboot recovers. ethtool -L in that state also wakes
queues that have no TX buffer and dereferences NULL in
ibmveth_start_xmit().
Any open() failure on those paths triggers it, for example an
allocation failure on an MTU change to jumbo frames.
Track a successful open in adapter->opened. close() returns early
when it is clear, and set_channels() checks it instead of IFF_UP.
The open() error-path leaks are fixed separately in net by
commit af0524bf4ce1 ("ibmveth: h_free logical LAN on open-fail after
register") and commit 84bec0bf0352 ("ibmveth: fix TX LTB and filter
unwind on open-fail"); this patch does not depend on them. Without
them, the TX buffers and the logical LAN registration that a failed
open() leaves behind stay in place after the early return, as they
did before this patch.
Found by AI-assisted review of the ibmveth multi-queue RX series and
confirmed by code inspection. Tested on a POWER10 LPAR with
ibmveth_open() forced to fail by a test-only module parameter (not part
of this patch): 'ip link set dev eth1 mtu 9000' fails, then 'ip link set
dev eth1 down' returns at once and 'ip link set dev eth1 up' recovers
the interface. No kernel selftests cover ibmveth.
Fixes: 860f242eb534 ("[PATCH] ibmveth change buffer pools dynamically")
Signed-off-by: Mingming Cao <mmc@linux.ibm.com>
---
Changes in v2:
- commit message: say what a failed open() leaves behind without the
two net fixes
drivers/net/ethernet/ibm/ibmveth.c | 24 +++++++++++++++++-------
drivers/net/ethernet/ibm/ibmveth.h | 2 ++
2 files changed, 19 insertions(+), 7 deletions(-)
diff --git a/drivers/net/ethernet/ibm/ibmveth.c b/drivers/net/ethernet/ibm/ibmveth.c
index 33af8e57be6e..dab571fe8dde 100644
--- a/drivers/net/ethernet/ibm/ibmveth.c
+++ b/drivers/net/ethernet/ibm/ibmveth.c
@@ -738,6 +738,7 @@ static int ibmveth_open(struct net_device *netdev)
netif_tx_start_all_queues(netdev);
+ adapter->opened = true;
netdev_dbg(netdev, "open complete\n");
return 0;
@@ -779,6 +780,14 @@ static int ibmveth_close(struct net_device *netdev)
long lpar_rc;
int i;
+ /* change_mtu, pool sysfs, set_csum and set_tso call close() and
+ * open() directly. If that open() fails, IFF_UP stays set and
+ * NAPI is disabled; a second close() would hang in napi_disable().
+ */
+ if (!adapter->opened)
+ return 0;
+ adapter->opened = false;
+
netdev_dbg(netdev, "close starting\n");
napi_disable(&adapter->napi);
@@ -830,10 +839,10 @@ static int ibmveth_close(struct net_device *netdev)
*
* @w: pointer to work_struct embedded in adapter structure
*
- * Context: This routine acquires rtnl_mutex and disables its NAPI through
- * ibmveth_close. It can't be called directly in a context that has
- * already acquired rtnl_mutex or disabled its NAPI, or directly from
- * a poll routine.
+ * Context: This routine acquires rtnl_mutex and, if the device is open,
+ * disables its NAPI through ibmveth_close. It can't be called
+ * directly in a context that has already acquired rtnl_mutex or
+ * disabled its NAPI, or directly from a poll routine.
*
* Return: void
*/
@@ -1127,10 +1136,11 @@ static int ibmveth_set_channels(struct net_device *netdev,
goal = channels->tx_count;
int rc, i;
- /* If ndo_open has not been called yet then don't allocate, just set
- * desired netdev_queue's and return
+ /* If the device is not open (including a failed close/open with
+ * IFF_UP still set) then don't allocate, just set desired
+ * netdev_queue's and return
*/
- if (!(netdev->flags & IFF_UP))
+ if (!adapter->opened)
return netif_set_real_num_tx_queues(netdev, goal);
/* We have IBMVETH_MAX_QUEUES netdev_queue's allocated
diff --git a/drivers/net/ethernet/ibm/ibmveth.h b/drivers/net/ethernet/ibm/ibmveth.h
index d87713668ed3..3f2240823f6a 100644
--- a/drivers/net/ethernet/ibm/ibmveth.h
+++ b/drivers/net/ethernet/ibm/ibmveth.h
@@ -172,6 +172,8 @@ struct ibmveth_adapter {
int rx_csum;
int large_send;
bool is_active_trunk;
+ /* Set by a successful ibmveth_open(), cleared by ibmveth_close(). */
+ bool opened;
unsigned int rx_buffers_per_hcall;
u64 fw_ipv6_csum_support;
--
2.39.3 (Apple Git-146)
next prev parent reply other threads:[~2026-10-05 6:08 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <cover.1791178212.git.mmc@linux.ibm.com>
2026-10-05 6:06 ` [PATCH net-next v2 1/8] ibmveth: fix netpoll races with RX replenish Mingming Cao
2026-10-05 6:06 ` Mingming Cao [this message]
2026-10-05 6:06 ` [PATCH net-next v2 3/8] ibmveth: disable the reset work before unregister in remove Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 4/8] ibmveth: step past bad RX correlators instead of spinning or oopsing Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 5/8] ibmveth: release the pool kobjects when probe fails Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 6/8] ibmveth: return the error when set_channels cannot add TX queues Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 7/8] ibmveth: wait for in-flight transmits in ibmveth_close() Mingming Cao
2026-10-05 6:06 ` [PATCH net-next v2 8/8] ibmveth: wait for the RX poll to return before freeing the RX queue Mingming Cao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f9f424944b0ed249ea5288e728832867cd945e1d.1791178212.git.mmc@linux.ibm.com \
--to=mmc@linux.ibm.com \
--cc=andrew+netdev@lunn.ch \
--cc=bjking1@linux.ibm.com \
--cc=chleroy@kernel.org \
--cc=davem@davemloft.net \
--cc=davemarq@linux.ibm.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=jeff@garzik.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=maddy@linux.ibm.com \
--cc=mpe@ellerman.id.au \
--cc=netdev@vger.kernel.org \
--cc=nnac123@linux.ibm.com \
--cc=npiggin@gmail.com \
--cc=pabeni@redhat.com \
--cc=ritesh.list@gmail.com \
--cc=sshegde@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®