On Wed, Mar 31, 2021 at 8:00 AM Eric Dumazet [off-list ref] wrote:
On Tue, Mar 30, 2021 at 8:45 AM Eric Dumazet [off-list ref] wrote:
quoted
From: Eric Dumazet <redacted>
Same reasons than for the previous commits :
6289a98f0817 ("sit: proper dev_{hold|put} in ndo_[un]init methods")
40cb881b5aaa ("ip6_vti: proper dev_{hold|put} in ndo_[un]init methods")
7f700334be9a ("ip6_gre: proper dev_{hold|put} in ndo_[un]init methods")
After adopting CONFIG_PCPU_DEV_REFCNT=n option, syzbot was able to trigger
a warning [1]
Issue here is that:
- all dev_put() should be paired with a corresponding prior dev_hold().
- A driver doing a dev_put() in its ndo_uninit() MUST also
do a dev_hold() in its ndo_init(), only when ndo_init()
is returning 0.
Otherwise, register_netdevice() would call ndo_uninit()
in its error path and release a refcount too soon.
Note to David & Jakub
Can you merge this patch so that I can send my global fix for fallback
tunnels, with a correct Fixes: tag for this patch ?
Thanks !
Forgot to attach what the global fix would look like :