net/core/pktgen.c | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-)
Callers of __pktgen_NN_threads() only check whether a pktgen_dev was
found. After the RCU lookup they never dereference the returned
pointer, so returning it past rcu_read_unlock() is confusing.
Return bool instead and keep the pktgen_dev pointer local to the
RCU critical section.
Suggested-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
This is a net-next follow-up to
https://lore.kernel.org/netdev/20260824152331.216494-1-nicoyip.dev@gmail.com/
net/core/pktgen.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)
diff --git a/net/core/pktgen.c b/net/core/pktgen.c
index 4fb1853589b3..9985b30c5a42 100644
--- a/net/core/pktgen.c
+++ b/net/core/pktgen.c
@@ -2024,11 +2024,11 @@ static const struct proc_ops pktgen_thread_proc_ops = {
};
/* Think find or remove for NN */
-static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
- const char *ifname, int remove)
+static bool __pktgen_NN_threads(const struct pktgen_net *pn,
+ const char *ifname, int remove)
{
struct pktgen_thread *t;
- struct pktgen_dev *pkt_dev = NULL;
+ struct pktgen_dev *pkt_dev;
bool exact = (remove == FIND);
list_for_each_entry(t, &pn->pktgen_threads, th_list) {
@@ -2042,9 +2042,9 @@ static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
}
rcu_read_unlock();
if (pkt_dev)
- break;
+ return true;
}
- return pkt_dev;
+ return false;
}
/*
@@ -2052,7 +2052,6 @@ static struct pktgen_dev *__pktgen_NN_threads(const struct pktgen_net *pn,
*/
static void pktgen_mark_device(const struct pktgen_net *pn, const char *ifname)
{
- struct pktgen_dev *pkt_dev = NULL;
const int max_tries = 10, msec_per_try = 125;
int i = 0;
@@ -2061,8 +2060,7 @@ static void pktgen_mark_device(const struct pktgen_net *pn, const char *ifname)
while (1) {
- pkt_dev = __pktgen_NN_threads(pn, ifname, REMOVE);
- if (pkt_dev == NULL)
+ if (!__pktgen_NN_threads(pn, ifname, REMOVE))
break; /* success */
mutex_unlock(&pktgen_thread_lock);
@@ -3836,8 +3834,7 @@ static int pktgen_add_device(struct pktgen_thread *t, const char *ifname)
/* We don't allow a device to be on several threads */
- pkt_dev = __pktgen_NN_threads(t->net, ifname, FIND);
- if (pkt_dev) {
+ if (__pktgen_NN_threads(t->net, ifname, FIND)) {
pr_err("ERROR: interface already used\n");
return -EBUSY;
}
--
2.43.0
On 8/25/26 8:53 PM, Chengfeng Ye wrote: > Callers of __pktgen_NN_threads() only check whether a pktgen_dev was > found. After the RCU lookup they never dereference the returned > pointer, so returning it past rcu_read_unlock() is confusing. > > Return bool instead and keep the pktgen_dev pointer local to the > RCU critical section. > > Suggested-by: Paolo Abeni <pabeni@redhat.com> > Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com> ## Form letter - net-next-closed net-next pull request for v7.3 has already been merged, and therefore the net-next tree is closed for new drivers, features, code refactoring and optimizations. We are currently accepting bug fixes only. Please repost when net-next reopens after Aug 31st. RFC patches sent for review only are obviously welcome at any time. See: https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle -- pw-bot: defer pv-bot: closed
On Thu, Aug 27, 2026 at 4:16 PM Paolo Abeni <pabeni@redhat.com> wrote: > > On 8/25/26 8:53 PM, Chengfeng Ye wrote: > > Callers of __pktgen_NN_threads() only check whether a pktgen_dev was > > found. After the RCU lookup they never dereference the returned > > pointer, so returning it past rcu_read_unlock() is confusing. > > > > Return bool instead and keep the pktgen_dev pointer local to the > > RCU critical section. > > > > Suggested-by: Paolo Abeni <pabeni@redhat.com> > > Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com> > ## Form letter - net-next-closed > > net-next pull request for v7.3 has already been merged, and therefore > the net-next tree is closed for new drivers, features, code refactoring > and optimizations. We are currently accepting bug fixes only. > > Please repost when net-next reopens after Aug 31st. > > RFC patches sent for review only are obviously welcome at any time. > > See: > https://www.kernel.org/doc/html/next/process/maintainer-netdev.html#development-cycle > -- > pw-bot: defer > pv-bot: closed > Hi Paolo, Sorry for the late reply. I have reposted the boolean-return cleanup as v2, rebased directly onto net-next. https://lore.kernel.org/r/20260927135406.3969970-1-nicoyip.dev@gmail.com/ The original UAF fix still applies cleanly to net and has Eric’s Reviewed-by. Could it be picked up from the existing submission, or would you prefer a resend? https://lore.kernel.org/r/20260824152331.216494-1-nicoyip.dev@gmail.com/ Best regards, Chengfeng
© 2016 - 2026 Red Hat, Inc.