[PATCH v2] netdevsim: update rxq->napi pointer during queue reset

Subasri S <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
In netdevsim, when queue reset is performed using debugfs, it triggers
these sequence of operations: nsim_queue_stop() -> nsim_queue_start()
-> nsim_queue_mem_free(). nsim_queue_mem_free() frees the old
nsim_rq struct which embeds the napi_struct. But the rxq->napi pointer
in the struct netdev_rx_queue still points to the old nsim_rq's embedded
napi_struct. So, any subsequent xsk_bind() which reads rxq->napi->napi_id
after a queue reset is a use-after-free.

Add netif_queue_set_napi() calls to nsim_queue_stop() and
nsim_queue_start() which clears the rxq->napi during stop
and sets it to the new napi instance during start.

KASAN report:

Call Trace:
 kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
 xsk_bind+0x1582/0x16c0 net/xdp/xsk.c:1758
 __sys_bind_socket net/socket.c:1920 [inline]
 __sys_bind_socket net/socket.c:1912 [inline]
 __sys_bind+0x1a9/0x260 net/socket.c:1951

Allocated by task 5622:
 nsim_queue_alloc+0x3c/0x140 drivers/net/netdevsim/netdev.c:715
 nsim_queue_init drivers/net/netdevsim/netdev.c:1012 [inline]
 nsim_init_netdevsim drivers/net/netdevsim/netdev.c:1059 [inline]
 nsim_create+0xb13/0x1420 drivers/net/netdevsim/netdev.c:1152
 __nsim_dev_port_add+0x3ba/0x8f0 drivers/net/netdevsim/dev.c:1509
 nsim_dev_port_add_all drivers/net/netdevsim/dev.c:1570 [inline]
 nsim_drv_probe+0xdbd/0x13a0 drivers/net/netdevsim/dev.c:1731

Freed by task 5659:
 slab_free mm/slub.c:6377 [inline]
 kfree+0x22b/0x6c0 mm/slub.c:6692
 nsim_queue_mem_free+0xfe/0x190 drivers/net/netdevsim/netdev.c:796
 netdev_rx_queue_reconfig+0x405/0x630 net/core/netdev_rx_queue.c:144
 netdev_rx_queue_restart+0x8f/0xc0 net/core/netdev_rx_queue.c:183
 nsim_qreset_write+0x2e3/0x410 drivers/net/netdevsim/netdev.c:887

Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=c06674caba265dc61d46
Fixes: 5bc8e8dbef27 ("netdevsim: add queue management API support")
Tested-by: [email protected]
Signed-off-by: Subasri S <[email protected]>
---
Changes in v2:
- Restore rxq->napi when reset mode is 1
- Link to v1: https://lore.kernel.org/r/[email protected]
---
 drivers/net/netdevsim/netdev.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/net/netdevsim/netdev.c b/drivers/net/netdevsim/netdev.c
index 4e9d7e10b527..291d34718b2e 100644
--- a/drivers/net/netdevsim/netdev.c
+++ b/drivers/net/netdevsim/netdev.c
@@ -808,6 +808,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg,
 
 	if (ns->rq_reset_mode == 1) {
 		ns->rq[idx]->page_pool = qmem->pp;
+		netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX,
+				     &ns->rq[idx]->napi);
 		napi_enable_locked(&ns->rq[idx]->napi);
 		return 0;
 	}
@@ -826,6 +828,8 @@ nsim_queue_start(struct net_device *dev, struct netdev_queue_config *qcfg,
 	}
 
 	ns->rq[idx] = qmem->rq;
+	netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX,
+			     &ns->rq[idx]->napi);
 	napi_enable_locked(&ns->rq[idx]->napi);
 
 	return 0;
@@ -838,6 +842,7 @@ static int nsim_queue_stop(struct net_device *dev, void *per_queue_mem, int idx)
 
 	netdev_assert_locked(dev);
 
+	netif_queue_set_napi(dev, idx, NETDEV_QUEUE_TYPE_RX, NULL);
 	napi_disable_locked(&ns->rq[idx]->napi);
 
 	if (ns->rq_reset_mode == 1) {

---
base-commit: a59f57e2aa127c5354168d2ec4bac920df1be4f4
change-id: 20260812-net-netdevsim-aad6100834dd

Best regards,
-- 
Subasri S <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.