On Sun, 9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote:
cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev matches the TC netdev the classifier is being
attached to. This let a program loaded with prog_ifindex for device A be
attached via cls_bpf + skip_sw to device B; deleting device A then
destroyed the program's offload state while it was still attached to
device B, triggering a netdevsim WARN (panic with panic_on_warn=1).
maybe netdevsim has a bug then.
Mirror the XDP attach path (net/core/dev.c) and reject the attach with
-EINVAL when a dev-bound program's bound device does not match the
target device.
Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
This commit in itself is fine, nfp checks that the offload matches:
https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579
Maybe the bound-devs got extended for JIT / descriptor access, and
that added some extra risk here. So either this is netdevsim-only
(and not worth the Fixes tag), or the Fixes tag is wrong..