summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorEric Dumazet <edumazet@google.com>2026-06-03 18:08:31 +0000
committerJakub Kicinski <kuba@kernel.org>2026-06-04 18:16:14 -0700
commitf3c496105472f353ff7428569ea4b6a6a61caf8e (patch)
tree47606edc07f229040eaf42deb8440e7c99009cfd
parentc1424df7ff82598a6deba11a63c433b645ab19bb (diff)
downloadlinux-f3c496105472f353ff7428569ea4b6a6a61caf8e.tar.gz
linux-f3c496105472f353ff7428569ea4b6a6a61caf8e.zip
rtnetlink: use dev_isalive() in rtnl_getlink()
rtnl_getlink() uses an RCU lookup to get the netdevice pointer. When/If rtnl_lock() is used, we should check if the netdevice is not being dismantled before potentially perform illegal actions. Move dev_isalive() out of net/core/net-sysfs.c and make it available in net/core/dev.h. Return -ENODEV if rtnl_getlink() finds a device which is currently being dismantled and RTNL is requested. Fixes: e896e5c0734b ("rtnetlink: do not acquire RTNL in rtnl_getlink() with RTEXT_FILTER_NAME_ONLY") Signed-off-by: Eric Dumazet <edumazet@google.com> Suggested-by: Jakub Kicinski <kuba@kernel.org> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev> Link: https://patch.msgid.link/20260603180831.1024716-1-edumazet@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
-rw-r--r--net/core/dev.h6
-rw-r--r--net/core/net-sysfs.c6
-rw-r--r--net/core/rtnetlink.c6
3 files changed, 12 insertions, 6 deletions
diff --git a/net/core/dev.h b/net/core/dev.h
index 0cf24b8f5008..9e9431440869 100644
--- a/net/core/dev.h
+++ b/net/core/dev.h
@@ -396,4 +396,10 @@ int dev_get_hwtstamp_phylib(struct net_device *dev,
struct kernel_hwtstamp_config *cfg);
int net_hwtstamp_validate(const struct kernel_hwtstamp_config *cfg);
+/* Caller holds RTNL, netdev->lock or RCU */
+static inline bool dev_isalive(const struct net_device *dev)
+{
+ return READ_ONCE(dev->reg_state) <= NETREG_REGISTERED;
+}
+
#endif
diff --git a/net/core/net-sysfs.c b/net/core/net-sysfs.c
index 3318b5666e43..0e71c9ed41e8 100644
--- a/net/core/net-sysfs.c
+++ b/net/core/net-sysfs.c
@@ -37,12 +37,6 @@ static const char fmt_uint[] = "%u\n";
static const char fmt_ulong[] = "%lu\n";
static const char fmt_u64[] = "%llu\n";
-/* Caller holds RTNL, netdev->lock or RCU */
-static inline int dev_isalive(const struct net_device *dev)
-{
- return READ_ONCE(dev->reg_state) <= NETREG_REGISTERED;
-}
-
/* There is a possible ABBA deadlock between rtnl_lock and kernfs_node->active,
* when unregistering a net device and accessing associated sysfs files. The
* potential deadlock is as follow:
diff --git a/net/core/rtnetlink.c b/net/core/rtnetlink.c
index 652dd008955a..61d095ce1b3b 100644
--- a/net/core/rtnetlink.c
+++ b/net/core/rtnetlink.c
@@ -4265,6 +4265,11 @@ static int rtnl_getlink(struct sk_buff *skb, struct nlmsghdr *nlh,
retry:
if (need_rtnl) {
rtnl_lock();
+ if (!dev_isalive(dev)) {
+ err = -ENODEV;
+ nskb = NULL;
+ goto unlock;
+ }
/* Synchronize the carrier state so we don't report a state
* that we're not actually going to honour immediately; if
* the driver just did a carrier off->on transition, we can
@@ -4282,6 +4287,7 @@ retry:
nlh->nlmsg_seq, 0, 0, ext_filter_mask,
0, NULL, 0, netnsid, GFP_KERNEL);
+unlock:
if (need_rtnl)
rtnl_unlock();