[PATCH net-next] net: pktgen: return bool from __pktgen_NN_threads()

Chengfeng Ye posted 1 patch 1 month ago
There is a newer version of this series
net/core/pktgen.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)
[PATCH net-next] net: pktgen: return bool from __pktgen_NN_threads()
Posted by Chengfeng Ye 1 month ago
Callers of __pktgen_NN_threads() only check whether a pktgen_dev was
found. After the RCU lookup they never dereference the returned
pointer, so returning it past rcu_read_unlock() is confusing.

Return bool instead and keep the pktgen_dev pointer local to the
RCU critical section.

Suggested-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
This is a net-next follow-up to
https://lore.kernel.org/netdev/20260824152331.216494-1-nicoyip.dev@gmail.com/

 net/core/pktgen.c | 17 +++++++----------
 1 file changed, 7 insertions(+), 10 deletions(-)

diff --git a/net/core/pktgen.c b/net/core/pktgen.c
index 4fb1853589b3..9985b30c5a42 100644
--- a/net/core/pktgen.c
+++ b/net/core/pktgen.c
@@ -2024,11 +2024,11 @@ static const struct proc_ops pktgen_thread_proc_ops = {
 };
 
 /* Think find or remove for NN */
-static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
-					      const char *ifname, int remove)
+static bool __pktgen_NN_threads(const struct pktgen_net *pn,
+				const char *ifname, int remove)
 {
 	struct pktgen_thread *t;
-	struct pktgen_dev *pkt_dev = NULL;
+	struct pktgen_dev *pkt_dev;
 	bool exact = (remove == FIND);
 
 	list_for_each_entry(t, &pn->pktgen_threads, th_list) {
@@ -2042,9 +2042,9 @@ static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
 		}
 		rcu_read_unlock();
 		if (pkt_dev)
-			break;
+			return true;
 	}
-	return pkt_dev;
+	return false;
 }
 
 /*
@@ -2052,7 +2052,6 @@ static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
  */
 static void pktgen_mark_device(const struct pktgen_net *pn, const char *ifname)
 {
-	struct pktgen_dev *pkt_dev = NULL;
 	const int max_tries = 10, msec_per_try = 125;
 	int i = 0;
 
@@ -2061,8 +2060,7 @@ static void pktgen_mark_device(const struct pktgen_net *pn, const char *ifname)
 
 	while (1) {
 
-		pkt_dev = __pktgen_NN_threads(pn, ifname, REMOVE);
-		if (pkt_dev == NULL)
+		if (!__pktgen_NN_threads(pn, ifname, REMOVE))
 			break;	/* success */
 
 		mutex_unlock(&pktgen_thread_lock);
@@ -3836,8 +3834,7 @@ static int pktgen_add_device(struct pktgen_thread *t, const char *ifname)
 
 	/* We don't allow a device to be on several threads */
 
-	pkt_dev = __pktgen_NN_threads(t->net, ifname, FIND);
-	if (pkt_dev) {
+	if (__pktgen_NN_threads(t->net, ifname, FIND)) {
 		pr_err("ERROR: interface already used\n");
 		return -EBUSY;
 	}
-- 
2.43.0
Re: [PATCH net-next] net: pktgen: return bool from __pktgen_NN_threads()
Posted by Paolo Abeni 1 month ago
On 8/25/26 8:53 PM, Chengfeng Ye wrote:
> Callers of __pktgen_NN_threads() only check whether a pktgen_dev was
> found. After the RCU lookup they never dereference the returned
> pointer, so returning it past rcu_read_unlock() is confusing.
> 
> Return bool instead and keep the pktgen_dev pointer local to the
> RCU critical section.
> 
> Suggested-by: Paolo Abeni <pabeni@redhat.com>
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
## Form letter - net-next-closed

net-next pull request for v7.3 has already been merged, and therefore
the net-next tree is closed for new drivers, features, code refactoring
and optimizations. We are currently accepting bug fixes only.

Please repost when net-next reopens after Aug 31st.

RFC patches sent for review only are obviously welcome at any time.

See:
https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle
-- 
pw-bot: defer
pv-bot: closed
Re: [PATCH net-next] net: pktgen: return bool from __pktgen_NN_threads()
Posted by Chengfeng Ye 14 hours ago
On Thu, Aug 27, 2026 at 4:16 PM Paolo Abeni <pabeni@redhat.com> wrote:
>
> On 8/25/26 8:53 PM, Chengfeng Ye wrote:
> > Callers of __pktgen_NN_threads() only check whether a pktgen_dev was
> > found. After the RCU lookup they never dereference the returned
> > pointer, so returning it past rcu_read_unlock() is confusing.
> >
> > Return bool instead and keep the pktgen_dev pointer local to the
> > RCU critical section.
> >
> > Suggested-by: Paolo Abeni <pabeni@redhat.com>
> > Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> ## Form letter - net-next-closed
>
> net-next pull request for v7.3 has already been merged, and therefore
> the net-next tree is closed for new drivers, features, code refactoring
> and optimizations. We are currently accepting bug fixes only.
>
> Please repost when net-next reopens after Aug 31st.
>
> RFC patches sent for review only are obviously welcome at any time.
>
> See:
> https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle
> --
> pw-bot: defer
> pv-bot: closed
>

Hi Paolo,

Sorry for the late reply. I have reposted the boolean-return cleanup
as v2, rebased directly onto net-next.
https://lore.kernel.org/r/20260927135406.3969970-1-nicoyip.dev@gmail.com/

The original UAF fix still applies cleanly to net and has Eric’s
Reviewed-by. Could it be picked up from the existing submission, or
would you prefer a resend?
https://lore.kernel.org/r/20260824152331.216494-1-nicoyip.dev@gmail.com/

Best regards,
Chengfeng