]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
net: Defer netdev KOBJ_ADD uevent until the device is published
authorDragos Tatulea <dtatulea@nvidia.com>
Thu, 6 Aug 2026 08:07:58 +0000 (11:07 +0300)
committerJakub Kicinski <kuba@kernel.org>
Thu, 6 Aug 2026 16:36:18 +0000 (09:36 -0700)
netdev_register_kobject() calls device_add(), which emits KOBJ_ADD and
wakes udev, but register_netdevice() only makes the device findable by
name later, in list_netdevice().  A udev worker that reacts to the uevent
can therefore run against a device that no lookup can find yet.

This used to be harmless because the ethtool ioctl took the rtnl_lock
when looking the device up, and register_netdevice() runs under rtnl, so
the worker simply blocked until registration finished. The commit in the
fixes tag moved the lookup out from under rtnl for ops-locked drivers.
Now there is a short window in register_netdevice() between
netdev_register_kobject() until list_netdevice() when the device is not
findable by name.

This was reproduced with the mlx5 driver on a kernel with KASAN enabled
during devlink reload: systemd-udevd's net_driver builtin gets -ENODEV
from ETHTOOL_GDRVINFO, which was preventing interface renaming.

Suppress the uevent in netdev_register_kobject() and emit it from
register_netdevice() next to rtmsg_ifinfo(). This is the last point in
register_netdevice() where no error can happen, so only fully registered
devices are announced: the registration error paths never reach it, and
the device_del() that unwinds them stays silent as well, leaving
userspace with neither an add nor a remove.

Fixes: f994752b1127 ("net: ethtool: optionally skip rtnl_lock on IOCTL path")
Signed-off-by: Dragos Tatulea <dtatulea@nvidia.com>
Reviewed-by: Shahar Shitrit <shshitrit@nvidia.com>
Link: https://patch.msgid.link/20260806080758.2039586-2-dtatulea@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/core/dev.c
net/core/net-sysfs.c
net/core/net-sysfs.h

index 5933c5dab09ee1f8fdde3f79d0da87531193bdcd..c49d2ce51285103161c2580af5ba6839eb52bb0c 100644 (file)
@@ -11494,6 +11494,7 @@ int register_netdevice(struct net_device *dev)
         *      Prevent userspace races by waiting until the network
         *      device is fully setup before sending notifications.
         */
+       netdev_uevent_add(dev);
        if (!(dev->rtnl_link_ops && dev->rtnl_link_initializing))
                rtmsg_ifinfo(RTM_NEWLINK, dev, ~0U, GFP_KERNEL, 0, NULL);
 
index 0e71c9ed41e81d85af33a4339f556a0c5d760243..25546deacec8024eb6b05c4a926c1c4c64ccb266 100644 (file)
@@ -2334,6 +2334,9 @@ int netdev_register_kobject(struct net_device *ndev)
                *groups++ = &wireless_group;
 #endif /* CONFIG_SYSFS */
 
+       /* Hold back the KOBJ_ADD uevent until the device is listed. */
+       dev_set_uevent_suppress(dev, 1);
+
        error = device_add(dev);
        if (error)
                return error;
@@ -2349,6 +2352,17 @@ int netdev_register_kobject(struct net_device *ndev)
        return error;
 }
 
+/* Announce a fully registered device to userspace. This pairs with the uevent
+ * suppression from netdev_register_kobject().
+ */
+void netdev_uevent_add(struct net_device *ndev)
+{
+       struct device *dev = &ndev->dev;
+
+       dev_set_uevent_suppress(dev, 0);
+       kobject_uevent(&dev->kobj, KOBJ_ADD);
+}
+
 /* Change owner for sysfs entries when moving network devices across network
  * namespaces owned by different user namespaces.
  */
index 38e2e3ffd0bdc4ccea2f6c7636c1bbc7d0f46af5..2f41a4dee866226d64fab37eb2fc9323c76578cd 100644 (file)
@@ -4,6 +4,7 @@
 
 int __init netdev_kobject_init(void);
 int netdev_register_kobject(struct net_device *);
+void netdev_uevent_add(struct net_device *dev);
 void netdev_unregister_kobject(struct net_device *);
 int net_rx_queue_update_kobjects(struct net_device *, int old_num, int new_num);
 int netdev_queue_update_kobjects(struct net_device *net,