From nobody Mon Sep 28 21:55:59 2026 Received: from mta0.migadu.com (out-124.mta0.migadu.com [91.218.175.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2B5043BBFA1 for ; Mon, 17 Aug 2026 08:33:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786955609; cv=none; b=PxZxsGtaACFVZWYUUk1s8thlXTiS1u0Uh2QhONJhSFCk+eyDRVpJr+zO6oDjp33BjduJ0/KNtd/cgUBTuP2qsD/9MIw8tr3e2Tz1mgaCfCYbNi/MlXKVIIIflA3tXUP3k5UG3zzcR+B59JqOsCjg4/X6mAtBuFPCPRANpAs+Z1I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786955609; c=relaxed/simple; bh=ko7PXWqMcrRP4/P2+KkGqXsnI2xugaZyuPnhK3xtdNE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=cJEdWVX6vOoBnhTC8UIRzmZr/Yo+G2JORZlyOOOMQJIpg8/d9W4zsO1J35YFItgytecegXCsc48pcQ2k0jIwVPmiqIaSay6IqPeUxtRVG9RfKQQD12CShWKZKw1O1RcExo8sxr00I3zOAaRuymPPwVpIZFGCJjYhfiglwocdQfE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=eNPj/Yrr; arc=none smtp.client-ip=91.218.175.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="eNPj/Yrr" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=ko7PXWqMcrRP4/P2+KkGqXsnI2xugaZyuPnhK3xtdNE=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786955604; v=1; x=1787560404; b=eNPj/Yrr4K8yECwQkBIspQmkJnGfDFZwvRshPJWWdf+AOvqCPVUYzmGhTgas+2+Mid0GQa/6 dn5St+WNUEGB6AFGsQcjOnV/RY6gQB8yvFeNssgkMk+7YYCRwCnNKtwqbqQBywID/+0UwdPC+lE bs5fn2JnQG7eaJ/e8R0LaNrw= X-Envelope-To: linux-kernel@vger.kernel.org Received: from [192.168.110.119] (216.236.36.150) by smtp.migadu.com with ESMTPS id 1a03b180869e9275; Mon, 17 Aug 2026 08:33:24 +0000 X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Mon, 17 Aug 2026 16:32:36 +0800 Subject: [PATCH 1/2] bonding: 3ad: fix NULL pointer dereference in ad_mux_machine() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260817-bond_rcu-v1-1-acf067cf45fe@kylinos.cn> References: <20260817-bond_rcu-v1-0-acf067cf45fe@kylinos.cn> In-Reply-To: <20260817-bond_rcu-v1-0-acf067cf45fe@kylinos.cn> To: Jay Vosburgh , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Hangbin Liu , stable@vger.kernel.org X-Mailer: b4 0.14.3 From: Hangbin Liu In bond_3ad_state_machine_handler(), ad_port_selection_logic() runs before ad_mux_machine() for each port. When ad_port_selection_logic() detaches a port from its current aggregator but fails to find a suitable replacement, it returns early, leaving port->aggregator as NULL. The subsequent call to ad_mux_machine() then dereferences the NULL aggregator in multiple switch branches, triggering a kernel oops. Add a NULL check for the aggregator at the top of ad_mux_machine() and return early. This avoids needing null guards in later branches. Detected by AI code review. Fixes: c4f050ce06c5 ("bonding: 3ad: implement proper RCU rules for port->ag= gregator") Cc: stable@vger.kernel.org Signed-off-by: Hangbin Liu --- drivers/net/bonding/bond_3ad.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/net/bonding/bond_3ad.c b/drivers/net/bonding/bond_3ad.c index acbba08dbdfa..196830fca4a4 100644 --- a/drivers/net/bonding/bond_3ad.c +++ b/drivers/net/bonding/bond_3ad.c @@ -1053,6 +1053,9 @@ static void ad_mux_machine(struct port *port, bool *u= pdate_slave_arr) last_state =3D port->sm_mux_state; =20 aggregator =3D rcu_dereference(port->aggregator); + if (!aggregator) + return; + if (port->sm_vars & AD_PORT_BEGIN) { port->sm_mux_state =3D AD_MUX_DETACHED; } else { --=20 2.55.0 From nobody Mon Sep 28 21:55:59 2026 Received: from mta1.migadu.com (out-60.mta1.migadu.com [95.215.58.60]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CE65E5477E for ; Mon, 17 Aug 2026 08:33:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=95.215.58.60 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786955616; cv=none; b=ujBSrvABfOEwu+ENqCjd0+T3TZPewtSw1mWJ6XbLS10htpYwEe5LWGXc7Gihcut/KojoaOPef2j2FD12SIH4YeIFo3boHTZRwMZ40YIydnlAVd0I9dQFZIzqoWKAH4sV4UBJBuip90XNsZipt5/xw+LhFtQneebAYbco35sJPrY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786955616; c=relaxed/simple; bh=Me9mOV+BwEv4PJ9PCsw9WW3c6SO6Hiy+WMiXP3LnMno=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=J+rEeLpZ5i1s2QqPrOGH4Jj+gFClukQ3qXKpBXGq+zwfJ54S0uBLDxlbm3kJhh4aC3q8bGOmKldap86E8ixvegXvbuQgIJm3USzoYucon0rwrm0pwOs8qJbRa5ljFCnmsZM509EvCIoo3LNJE6qe0ujIL3vlHpAPFqeIpHNVYEk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=BoIlukUQ; arc=none smtp.client-ip=95.215.58.60 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="BoIlukUQ" X-Envelope-To: linux-kernel@vger.kernel.org DKIM-Signature: a=rsa-sha256; bh=Me9mOV+BwEv4PJ9PCsw9WW3c6SO6Hiy+WMiXP3LnMno=; c=simple/simple; d=linux.dev; h=from:to:subject:date:message-id:mime-version:content-type; s=key1; t=1786955613; v=1; x=1787560413; b=BoIlukUQxdsvfzWtlOkyHE1aZf6ktZYuKWETukRiqzltUMRri2SA277uc8E0CpdmivsqdgWE 6TXcObjm2jAivBVzOGguBlgO6pzSitW2PYtXVdSJMrWJ3pH/eehACW5RiTKLHy/BYBaVcpUq++X o5ms2PDqHUikLzvoAxqRbHis= X-Envelope-To: linux-kernel@vger.kernel.org Received: from [192.168.110.119] (216.236.36.150) by smtp.migadu.com with ESMTPS id 7fb4c39416823aba; Mon, 17 Aug 2026 08:33:32 +0000 X-Migadu-Flow: FLOW_OUT From: Hangbin Liu Date: Mon, 17 Aug 2026 16:32:37 +0800 Subject: [PATCH 2/2] bonding: 3ad: use RCU_INIT_POINTER for rcu pointer initialization Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260817-bond_rcu-v1-2-acf067cf45fe@kylinos.cn> References: <20260817-bond_rcu-v1-0-acf067cf45fe@kylinos.cn> In-Reply-To: <20260817-bond_rcu-v1-0-acf067cf45fe@kylinos.cn> To: Jay Vosburgh , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: Hangbin Liu , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Hangbin Liu X-Mailer: b4 0.14.3 From: Hangbin Liu Use RCU_INIT_POINTER() for initializing port->aggregator to NULL. Fixes: c4f050ce06c5 ("bonding: 3ad: implement proper RCU rules for port->ag= gregator") Signed-off-by: Hangbin Liu --- drivers/net/bonding/bond_3ad.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/net/bonding/bond_3ad.c b/drivers/net/bonding/bond_3ad.c index 196830fca4a4..c4dfcafcff26 100644 --- a/drivers/net/bonding/bond_3ad.c +++ b/drivers/net/bonding/bond_3ad.c @@ -2075,7 +2075,7 @@ static void ad_initialize_port(struct port *port, con= st struct bond_params *bond port->sm_mux_state =3D 0; port->sm_mux_timer_counter =3D 0; port->sm_tx_state =3D 0; - port->aggregator =3D NULL; + RCU_INIT_POINTER(port->aggregator, NULL); port->next_port_in_aggregator =3D NULL; port->transaction_id =3D 0; =20 --=20 2.55.0