From nobody Tue Sep 29 08:31:07 2026 Received: from mail-ed1-f52.google.com (mail-ed1-f52.google.com [209.85.208.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EE3842D12EE for ; Mon, 10 Aug 2026 13:31:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786368694; cv=none; b=FjF8HIED6AZWT92/4A3ns5CX4sOIWWvIlxPm11xffNYNBPWZ2sntCL0J7QR/Dxu6/AwNoMKPzOtvgnnIrqb3sImSDN30RNjj+ZYDpubc2INHCkT1GVfksuPQhGh/6js4k72W4okJnbbkI+k0jV7gRT36MR/rMpeOXkmjCjEVm4U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786368694; c=relaxed/simple; bh=RM/YxQY456kcmYEcHSeOs3p3taT/I9NV7N68DWW7lIg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Fe7r1+/Qy12tGU1fKu46Lhj8E7V17lbhcdR++pIq5fxSILMWKTp+3kSIlalMN+xByWZ3SQgbhd1vbuNtHoLmovuAt6yjKwRKv345AwEv3WAM1nZyUwOiiicQIzxVlwSE+tZV/WB0tIBY45fMaymT9T0ZLoz0jvq0h5cMIYCiy2E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=jGRvA1mL; arc=none smtp.client-ip=209.85.208.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="jGRvA1mL" Received: by mail-ed1-f52.google.com with SMTP id 4fb4d7f45d1cf-6a0a4a17f91so2922618a12.1 for ; Mon, 10 Aug 2026 06:31:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786368691; x=1786973491; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=TOePn93cV2ug+wSXgzsoigDXykI/2Vl/iaRlUy5tOD0=; b=jGRvA1mLer/yGp3RpNo8hRx3xE8blIsfLQlctahWprV30dKF8qPsvsqqfcbtieab6u Kb2lFp9/Z1E44mCvIhf9+Eh4YwKTmZmmP0hOe+OBO0+0EyK+4t9VH4pYbX7yDert7yfg I0Clh+q4x4ua8q0qgjFW4ykq7ob5P0+Vf4bGxoiYyeYNczwY/X0s38kMw8ZlfQEHtr+v oCNvVXr7MXBM5jhFIQfVQAMJpxKhK9T+O3QKsbu5ig4jZR+bBsomtVl0WJM6R3AzaoAR Ztfi9wRU57NmAgdj160mrJ9zLrDY06OqZ+mxh0mmglaBK9aU0usOXSxLyfxDMVNx2wd3 aXbg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786368691; x=1786973491; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TOePn93cV2ug+wSXgzsoigDXykI/2Vl/iaRlUy5tOD0=; b=sX+Irn0Iefj+dU9c2GQXrE/3rSuemXY/+reQTSznSBobJfajK0VIv9nXIB8E7uO/wm PUVnAFzDIO9OtiZfTu1dOyCl1svgvAycOhcAKxoVezy3zDdqb2CthJV2ZJkf22UB93K/ K8cguKXN800DQ6mD5qyyN4Hp9Vgse/4opV+ua7Im0T+cmpGDwraq64mGp7ni4dEl6wEO qDLVbejQcB8zeq6V2Y0iieo2B7MAqGrfgSiZPd0khvGSwHsN4wPaavhUZJvG+sXBjQ2T KYfsqg85AdwttSewuy6j8p0oY9g8hfiAEqBQjA0F6V6Zm/4bpn6aOXxGmpDkC4j/Qypb Y+yA== X-Forwarded-Encrypted: i=1; AHgh+RoN/kNMSww/oZ8m7ZQZI5OeHk8aLGxKS7i3YuvUdcsYg9P4H/2T2Ft8X3y+TIThnjbq9u6ovIuNJinjxMM=@vger.kernel.org X-Gm-Message-State: AOJu0YzkS54WaGyF+q6d0h6qL4qZB/uX0J7Z/NbfbPdLLeKweKwB53Vp SFxA8dx6Vj8D66XO5RtL7BN8G7CHKj3AZ0qSfT1yx3OpQN2kiYQLiwo7 X-Gm-Gg: AR+sD11BOMJeafzeMDXW/My0zdqmc6piiQ4GIhhV5uHR1g8I10ZPz0NKXEATha8aik1 DRA49torJGRooGbWLBT/DlxUJZIol6+PE/ATPi+nZNd5FmBeCgr7ui1X9Qz6+4iyJs4lVOHYmNH l/EL45gWzsEFIH8ILsXYr1CQTJy5viuZ7ZIJiRXCVh4fdwScvM7hAGin0U3+BVlCoElm1kl++br b61xcwv/oanjjy9wLkKv3no+wHF+uCOFRI1xOQ3CN6GHvabLWlJmOGmCstCXg97nbhwRhoxDo7Q pbdSaM/kolkH+NzAlwVQbxsn8CxiB40eLM4bHLJu7zOLgETLw59ZnBvdX40VOkEUOBB9yKaknwH O2sbKXV/HKCljmWtWuqE6bUGn49pZ3NXRCknErP1wVvKmMJyi9Ix/++H7pf6rCFOlHyD8o29cP2 W2A1wtIUa9yGE7gBvkwBGD8dtUGUJ66oN+LSpxWWFJREZo9tcAV11lxnxbN76vAtsKGa5Bn2rWs dCA7gJVH89SXmilpwY0nZKbnkhSoq8xrCa0Gq6i4chZg+gLMOosPpKPpyx7P63aUxd2NVS1v/v2 OEWQILpb2MliAJGpdH5D841kqK3CXyjzWZSdrw== X-Received: by 2002:a05:6402:350b:b0:698:e595:a5c with SMTP id 4fb4d7f45d1cf-6a355d8abb9mr1045288a12.6.1786368690814; Mon, 10 Aug 2026 06:31:30 -0700 (PDT) Received: from Ubuntu.ts.net (87-205-15-91.static.ip.netia.com.pl. [87.205.15.91]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-6a1e7d48f8dsm4198679a12.17.2026.08.10.06.31.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 06:31:29 -0700 (PDT) From: Krystian Kaniewski To: Jason Gunthorpe , Leon Romanovsky , linux-rdma@vger.kernel.org Cc: Andrew Lunn , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com, syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com Subject: [PATCH net v3] RDMA/core: Reject unregistering netdevs in ib_get_eth_speed Date: Mon, 10 Aug 2026 15:31:20 +0200 Message-ID: <20260810133124.44513-1-krystianmkaniewski@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ib_device_get_netdev() intentionally returns a referenced net_device even when it is unregistering, so matching and cleanup callers can still find the association. The reference keeps struct net_device allocated, but does not guarantee that the device remains operational. ib_get_eth_speed() uses the returned device operationally by invoking its ethtool callback. Although that call is made under RTNL, the function does not verify the registration state first. An asynchronous RDMA port query can therefore call into a netdev after NETDEV_UNREGISTER and ndo_uninit have completed. Check for NETREG_REGISTERED while holding RTNL and return -ENODEV for a device which is being unregistered. Keeping RTNL across the check and the ethtool operation prevents unregister from starting between them. Also copy the device name before dropping the reference, since the warning path currently dereferences netdev after dev_put(). Fixes: d41861942fc5 ("IB/core: Add generic function to extract IB speed fro= m netdev") Reported-by: syzbot+5fe14f2ff4ccbace9a26@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D5fe14f2ff4ccbace9a26 Signed-off-by: Krystian Kaniewski --- v3: - Reworked the fix following Jakub Kicinski's review: a netdev reference protects the allocation, not the operational lifetime. - Moved the fix from ipvlan to the operational RDMA caller. - Check NETREG_REGISTERED under RTNL before invoking ethtool. - Avoid dereferencing netdev after dev_put() in the warning path. - Added the RDMA maintainers and mailing list. v2: https://lore.kernel.org/all/20260803121140.261329-1-krystianmkaniewski@= gmail.com/ drivers/infiniband/core/verbs.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verb= s.c index 86811d31092c..d50e761be4c8 100644 --- a/drivers/infiniband/core/verbs.c +++ b/drivers/infiniband/core/verbs.c @@ -2040,6 +2040,7 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_= num, u16 *speed, u8 *width) u32 netdev_speed; struct net_device *netdev; struct ethtool_link_ksettings lksettings =3D {}; + char name[IFNAMSIZ]; =20 if (rdma_port_get_link_layer(dev, port_num) !=3D IB_LINK_LAYER_ETHERNET) return -EINVAL; @@ -2049,7 +2050,15 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port= _num, u16 *speed, u8 *width) return -ENODEV; =20 rtnl_lock(); + if (READ_ONCE(netdev->reg_state) !=3D NETREG_REGISTERED) { + dev_put(netdev); + rtnl_unlock(); + return -ENODEV; + } + rc =3D __ethtool_get_link_ksettings(netdev, &lksettings); + if (rc) + strscpy(name, netdev->name, sizeof(name)); rtnl_unlock(); =20 dev_put(netdev); @@ -2060,7 +2069,7 @@ int ib_get_eth_speed(struct ib_device *dev, u32 port_= num, u16 *speed, u8 *width) netdev_speed =3D SPEED_1000; if (rc) pr_warn("%s speed is unknown, defaulting to %u\n", - netdev->name, netdev_speed); + name, netdev_speed); } =20 ib_get_width_and_speed(netdev_speed, lksettings.lanes, --=20 2.53.0