]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
net: don't try to ops lock uninitialized devs
authorJakub Kicinski <kuba@kernel.org>
Tue, 15 Apr 2025 15:15:52 +0000 (08:15 -0700)
committerJakub Kicinski <kuba@kernel.org>
Thu, 17 Apr 2025 01:28:11 +0000 (18:28 -0700)
We need to be careful when operating on dev while in rtnl_create_link().
Some devices (vxlan) initialize netdev_ops in ->newlink, so later on.
Avoid using netdev_lock_ops(), the device isn't registered so we
cannot legally call its ops or generate any notifications for it.

netdev_ops_assert_locked_or_invisible() is safe to use, it checks
registration status first.

Reported-by: syzbot+de1c7d68a10e3f123bdd@syzkaller.appspotmail.com
Fixes: 04efcee6ef8d ("net: hold instance lock during NETDEV_CHANGE")
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Reviewed-by: Kuniyuki Iwashima <kuniyu@amazon.com>
Link: https://patch.msgid.link/20250415151552.768373-1-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/core/dev.c
net/core/rtnetlink.c

index 5fcbc66d865e2fb1bf0b8192d40893ade4fa7bbd..1be7cb73a6024fda6797b6dfc895e4ce25f43251 100644 (file)
@@ -1520,6 +1520,8 @@ EXPORT_SYMBOL(netdev_features_change);
 
 void netif_state_change(struct net_device *dev)
 {
+       netdev_ops_assert_locked_or_invisible(dev);
+
        if (dev->flags & IFF_UP) {
                struct netdev_notifier_change_info change_info = {
                        .info.dev = dev,
index 39a5b72e861f683bfdc56f857303670be524c37f..c5a7f41982a57560ea7f2c483903198c22597152 100644 (file)
@@ -3676,11 +3676,8 @@ struct net_device *rtnl_create_link(struct net *net, const char *ifname,
                                nla_len(tb[IFLA_BROADCAST]));
        if (tb[IFLA_TXQLEN])
                dev->tx_queue_len = nla_get_u32(tb[IFLA_TXQLEN]);
-       if (tb[IFLA_OPERSTATE]) {
-               netdev_lock_ops(dev);
+       if (tb[IFLA_OPERSTATE])
                set_operstate(dev, nla_get_u8(tb[IFLA_OPERSTATE]));
-               netdev_unlock_ops(dev);
-       }
        if (tb[IFLA_LINKMODE])
                dev->link_mode = nla_get_u8(tb[IFLA_LINKMODE]);
        if (tb[IFLA_GROUP])