Re: [PATCH net] ice: fix metadata_dst refcount handling on representor teardown

Simon Horman <[email protected]>
Newsgroups org.osuosl.intel-wired-lan,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <[email protected]>
On Sun, Aug 16, 2026 at 01:55:10PM +0000, Tristan Madani wrote:
> From: Tristan Madani <[email protected]>
> 
> ice_eswitch_release_repr() uses metadata_dst_free() to release the
> representor's metadata_dst.  metadata_dst_free() directly frees the
> underlying memory without checking the dst_entry refcount.
> 
> When ice_eswitch_port_start_xmit() processes a packet, it takes a
> reference via dst_hold() and attaches the metadata_dst to the skb.
> If the representor is torn down while packets are still queued on
> the lower device (e.g. in a qdisc), the metadata_dst is freed while
> references are still held.
> 
> Use dst_release() instead, which correctly decrements the refcount
> and only frees the object when all references are dropped.  The dst
> subsystem already handles metadata_dst cleanup in dst_destroy() when
> DST_METADATA is set.
> 
> Other drivers sharing this pattern (nfp, airoha, bnxt) already use
> dst_release() for their metadata_dst lifecycle.
> 
> Fixes: f5396b8a663f7 ("ice: switchdev slow path")
> Cc: [email protected]
> Signed-off-by: Tristan Madani <[email protected]>

Reviewed-by: Simon Horman <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.