[PATCH] net: korina: remove busy skb free

Subsystems: networking drivers, the rest

STALE2097d

9 messages, 4 authors, 2020-12-16 · open the first message on its own page

[PATCH] net: korina: remove busy skb free

From: Vincent Stehlé <hidden>
Date: 2020-12-13 17:27:15

The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Fix the korina_send_packet() function
accordingly.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Florian Fainelli <redacted>
---
 drivers/net/ethernet/korina.c | 1 -
 1 file changed, 1 deletion(-)
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..9d84191de6824 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -216,7 +216,6 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			netif_stop_queue(dev);
 		else {
 			dev->stats.tx_dropped++;
-			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
 			return NETDEV_TX_BUSY;
-- 
2.29.2

Re: [PATCH] net: korina: remove busy skb free

From: Julian Wiedmann <hidden>
Date: 2020-12-14 10:04:55

On 13.12.20 18:20, Vincent Stehlé wrote:
quoted hunk
The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Fix the korina_send_packet() function
accordingly.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: Florian Fainelli <redacted>
---
 drivers/net/ethernet/korina.c | 1 -
 1 file changed, 1 deletion(-)
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..9d84191de6824 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -216,7 +216,6 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			netif_stop_queue(dev);
 		else {
 			dev->stats.tx_dropped++;
-			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
 			return NETDEV_TX_BUSY;
As this skb is returned to the stack (and not dropped), the tx_dropped
statistics increment looks bogus too.

Re: [PATCH] net: korina: remove busy skb free

From: Jakub Kicinski <kuba@kernel.org>
Date: 2020-12-14 21:09:42

On Mon, 14 Dec 2020 11:03:12 +0100 Julian Wiedmann wrote:
quoted
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..9d84191de6824 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -216,7 +216,6 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			netif_stop_queue(dev);
 		else {
 			dev->stats.tx_dropped++;
-			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
 			return NETDEV_TX_BUSY;
  
As this skb is returned to the stack (and not dropped), the tx_dropped
statistics increment looks bogus too.
Since this is clearly an ugly use after free, and nobody complained we
can assume that the driver correctly stops its TX queue ahead of time.
So perhaps we can change the return value to NETDEV_TX_OK instead.

Re: [PATCH] net: korina: remove busy skb free

From: Vincent Stehlé <hidden>
Date: 2020-12-14 21:21:07

On Mon, Dec 14, 2020 at 11:03:12AM +0100, Julian Wiedmann wrote:
On 13.12.20 18:20, Vincent Stehlé wrote:
...
quoted
@@ -216,7 +216,6 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			netif_stop_queue(dev);
 		else {
 			dev->stats.tx_dropped++;
-			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
 			return NETDEV_TX_BUSY;
As this skb is returned to the stack (and not dropped), the tx_dropped
statistics increment looks bogus too.
Hi Julian,

Thanks for the review.
I will respin the patch to remove the statistics increment as well.

Best regards,
Vincent.

Re: [PATCH] net: korina: remove busy skb free

From: Vincent Stehlé <hidden>
Date: 2020-12-14 21:33:37

On Mon, Dec 14, 2020 at 01:08:32PM -0800, Jakub Kicinski wrote:
On Mon, 14 Dec 2020 11:03:12 +0100 Julian Wiedmann wrote:
quoted
quoted
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..9d84191de6824 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -216,7 +216,6 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			netif_stop_queue(dev);
 		else {
 			dev->stats.tx_dropped++;
-			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
 			return NETDEV_TX_BUSY;
  
As this skb is returned to the stack (and not dropped), the tx_dropped
statistics increment looks bogus too.
Since this is clearly an ugly use after free, and nobody complained we
can assume that the driver correctly stops its TX queue ahead of time.
So perhaps we can change the return value to NETDEV_TX_OK instead.
Hi Jakub,

Thanks for the review.

Ok, if this is the preferred fix I will respin the patch this way.

Best regards,
Vincent.

[PATCH v2] net: korina: fix return value

From: Vincent Stehlé <hidden>
Date: 2020-12-14 22:16:48

The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Therefore, make sure the
korina_send_packet() function returns NETDEV_TX_OK when it frees a packet.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Florian Fainelli <redacted>
---


Changes since v1:
- Keep freeing the packet but return NETDEV_TX_OK, as suggested by Jakub


 drivers/net/ethernet/korina.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..925161959b9ba 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -219,7 +219,7 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
-			return NETDEV_TX_BUSY;
+			return NETDEV_TX_OK;
 		}
 	}
 
-- 
2.29.2

Re: [PATCH v2] net: korina: fix return value

From: Jakub Kicinski <kuba@kernel.org>
Date: 2020-12-16 20:44:42

On Mon, 14 Dec 2020 23:09:52 +0100 Vincent Stehlé wrote:
The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Therefore, make sure the
korina_send_packet() function returns NETDEV_TX_OK when it frees a packet.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Florian Fainelli <redacted>
Let me CC Florian's more recent email just in case he wants to review.
quoted hunk
Changes since v1:
- Keep freeing the packet but return NETDEV_TX_OK, as suggested by Jakub


 drivers/net/ethernet/korina.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/korina.c b/drivers/net/ethernet/korina.c
index bf48f0ded9c7d..925161959b9ba 100644
--- a/drivers/net/ethernet/korina.c
+++ b/drivers/net/ethernet/korina.c
@@ -219,7 +219,7 @@ static int korina_send_packet(struct sk_buff *skb, struct net_device *dev)
 			dev_kfree_skb_any(skb);
 			spin_unlock_irqrestore(&lp->lock, flags);
 
-			return NETDEV_TX_BUSY;
+			return NETDEV_TX_OK;
 		}
 	}
 

Re: [PATCH v2] net: korina: fix return value

From: Florian Fainelli <f.fainelli@gmail.com>
Date: 2020-12-16 21:33:24

On 12/16/20 12:43 PM, Jakub Kicinski wrote:
On Mon, 14 Dec 2020 23:09:52 +0100 Vincent Stehlé wrote:
quoted
The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Therefore, make sure the
korina_send_packet() function returns NETDEV_TX_OK when it frees a packet.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Florian Fainelli <redacted>
Let me CC Florian's more recent email just in case he wants to review.
Acked-by: Florian Fainelli <f.fainelli@gmail.com>
-- 
Florian

Re: [PATCH v2] net: korina: fix return value

From: Jakub Kicinski <kuba@kernel.org>
Date: 2020-12-16 23:03:03

On Wed, 16 Dec 2020 13:32:26 -0800 Florian Fainelli wrote:
On 12/16/20 12:43 PM, Jakub Kicinski wrote:
quoted
On Mon, 14 Dec 2020 23:09:52 +0100 Vincent Stehlé wrote:  
quoted
The ndo_start_xmit() method must not attempt to free the skb to transmit
when returning NETDEV_TX_BUSY. Therefore, make sure the
korina_send_packet() function returns NETDEV_TX_OK when it frees a packet.

Fixes: ef11291bcd5f ("Add support the Korina (IDT RC32434) Ethernet MAC")
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Vincent Stehlé <redacted>
Cc: David S. Miller <davem@davemloft.net>
Cc: Florian Fainelli <redacted>  
Let me CC Florian's more recent email just in case he wants to review.  
Acked-by: Florian Fainelli <f.fainelli@gmail.com>
😬

Applied, thanks!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help