Skip to content

Commit b3c9e65

Browse files
edumazetdavem330
authored andcommitted
net: hsr: remove seqnr_lock
syzbot found a new splat [1]. Instead of adding yet another spin_lock_bh(&hsr->seqnr_lock) / spin_unlock_bh(&hsr->seqnr_lock) pair, remove seqnr_lock and use atomic_t for hsr->sequence_nr and hsr->sup_sequence_nr. This also avoid a race in hsr_fill_info(). Also remove interlink_sequence_nr which is unused. [1] WARNING: CPU: 1 PID: 9723 at net/hsr/hsr_forward.c:602 handle_std_frame+0x247/0x2c0 net/hsr/hsr_forward.c:602 Modules linked in: CPU: 1 UID: 0 PID: 9723 Comm: syz.0.1657 Not tainted 6.11.0-rc6-syzkaller-00026-g88fac17500f4 #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 RIP: 0010:handle_std_frame+0x247/0x2c0 net/hsr/hsr_forward.c:602 Code: 49 8d bd b0 01 00 00 be ff ff ff ff e8 e2 58 25 00 31 ff 89 c5 89 c6 e8 47 53 a8 f6 85 ed 0f 85 5a ff ff ff e8 fa 50 a8 f6 90 <0f> 0b 90 e9 4c ff ff ff e8 cc e7 06 f7 e9 8f fe ff ff e8 52 e8 06 RSP: 0018:ffffc90000598598 EFLAGS: 00010246 RAX: 0000000000000000 RBX: ffffc90000598670 RCX: ffffffff8ae2c919 RDX: ffff888024e94880 RSI: ffffffff8ae2c926 RDI: 0000000000000005 RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000003 R13: ffff8880627a8cc0 R14: 0000000000000000 R15: ffff888012b03c3a FS: 0000000000000000(0000) GS:ffff88802b700000(0063) knlGS:00000000f5696b40 CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033 CR2: 0000000020010000 CR3: 00000000768b4000 CR4: 0000000000350ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <IRQ> hsr_fill_frame_info+0x2c8/0x360 net/hsr/hsr_forward.c:630 fill_frame_info net/hsr/hsr_forward.c:700 [inline] hsr_forward_skb+0x7df/0x25c0 net/hsr/hsr_forward.c:715 hsr_handle_frame+0x603/0x850 net/hsr/hsr_slave.c:70 __netif_receive_skb_core.constprop.0+0xa3d/0x4330 net/core/dev.c:5555 __netif_receive_skb_list_core+0x357/0x950 net/core/dev.c:5737 __netif_receive_skb_list net/core/dev.c:5804 [inline] netif_receive_skb_list_internal+0x753/0xda0 net/core/dev.c:5896 gro_normal_list include/net/gro.h:515 [inline] gro_normal_list include/net/gro.h:511 [inline] napi_complete_done+0x23f/0x9a0 net/core/dev.c:6247 gro_cell_poll+0x162/0x210 net/core/gro_cells.c:66 __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6772 napi_poll net/core/dev.c:6841 [inline] net_rx_action+0xa92/0x1010 net/core/dev.c:6963 handle_softirqs+0x216/0x8f0 kernel/softirq.c:554 do_softirq kernel/softirq.c:455 [inline] do_softirq+0xb2/0xf0 kernel/softirq.c:442 </IRQ> <TASK> Fixes: 06afd2c ("hsr: Synchronize sending frames to have always incremented outgoing seq nr.") Fixes: f421436 ("net/hsr: Add support for the High-availability Seamless Redundancy protocol (HSRv0)") Reported-by: syzbot <[email protected]> Signed-off-by: Eric Dumazet <[email protected]> Cc: Sebastian Andrzej Siewior <[email protected]> Reviewed-by: Simon Horman <[email protected]> Signed-off-by: David S. Miller <[email protected]>
1 parent d759ee2 commit b3c9e65

File tree

4 files changed

+14
-33
lines changed

4 files changed

+14
-33
lines changed

net/hsr/hsr_device.c

Lines changed: 10 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -231,9 +231,7 @@ static netdev_tx_t hsr_dev_xmit(struct sk_buff *skb, struct net_device *dev)
231231
skb->dev = master->dev;
232232
skb_reset_mac_header(skb);
233233
skb_reset_mac_len(skb);
234-
spin_lock_bh(&hsr->seqnr_lock);
235234
hsr_forward_skb(skb, master);
236-
spin_unlock_bh(&hsr->seqnr_lock);
237235
} else {
238236
dev_core_stats_tx_dropped_inc(dev);
239237
dev_kfree_skb_any(skb);
@@ -314,14 +312,10 @@ static void send_hsr_supervision_frame(struct hsr_port *port,
314312
set_hsr_stag_HSR_ver(hsr_stag, hsr->prot_version);
315313

316314
/* From HSRv1 on we have separate supervision sequence numbers. */
317-
spin_lock_bh(&hsr->seqnr_lock);
318-
if (hsr->prot_version > 0) {
319-
hsr_stag->sequence_nr = htons(hsr->sup_sequence_nr);
320-
hsr->sup_sequence_nr++;
321-
} else {
322-
hsr_stag->sequence_nr = htons(hsr->sequence_nr);
323-
hsr->sequence_nr++;
324-
}
315+
if (hsr->prot_version > 0)
316+
hsr_stag->sequence_nr = htons(atomic_inc_return(&hsr->sup_sequence_nr));
317+
else
318+
hsr_stag->sequence_nr = htons(atomic_inc_return(&hsr->sequence_nr));
325319

326320
hsr_stag->tlv.HSR_TLV_type = type;
327321
/* TODO: Why 12 in HSRv0? */
@@ -343,13 +337,11 @@ static void send_hsr_supervision_frame(struct hsr_port *port,
343337
ether_addr_copy(hsr_sp->macaddress_A, hsr->macaddress_redbox);
344338
}
345339

346-
if (skb_put_padto(skb, ETH_ZLEN)) {
347-
spin_unlock_bh(&hsr->seqnr_lock);
340+
if (skb_put_padto(skb, ETH_ZLEN))
348341
return;
349-
}
350342

351343
hsr_forward_skb(skb, port);
352-
spin_unlock_bh(&hsr->seqnr_lock);
344+
353345
return;
354346
}
355347

@@ -374,23 +366,18 @@ static void send_prp_supervision_frame(struct hsr_port *master,
374366
set_hsr_stag_HSR_ver(hsr_stag, (hsr->prot_version ? 1 : 0));
375367

376368
/* From HSRv1 on we have separate supervision sequence numbers. */
377-
spin_lock_bh(&hsr->seqnr_lock);
378-
hsr_stag->sequence_nr = htons(hsr->sup_sequence_nr);
379-
hsr->sup_sequence_nr++;
369+
hsr_stag->sequence_nr = htons(atomic_inc_return(&hsr->sup_sequence_nr));
380370
hsr_stag->tlv.HSR_TLV_type = PRP_TLV_LIFE_CHECK_DD;
381371
hsr_stag->tlv.HSR_TLV_length = sizeof(struct hsr_sup_payload);
382372

383373
/* Payload: MacAddressA */
384374
hsr_sp = skb_put(skb, sizeof(struct hsr_sup_payload));
385375
ether_addr_copy(hsr_sp->macaddress_A, master->dev->dev_addr);
386376

387-
if (skb_put_padto(skb, ETH_ZLEN)) {
388-
spin_unlock_bh(&hsr->seqnr_lock);
377+
if (skb_put_padto(skb, ETH_ZLEN))
389378
return;
390-
}
391379

392380
hsr_forward_skb(skb, master);
393-
spin_unlock_bh(&hsr->seqnr_lock);
394381
}
395382

396383
/* Announce (supervision frame) timer function
@@ -621,11 +608,9 @@ int hsr_dev_finalize(struct net_device *hsr_dev, struct net_device *slave[2],
621608
if (res < 0)
622609
return res;
623610

624-
spin_lock_init(&hsr->seqnr_lock);
625611
/* Overflow soon to find bugs easier: */
626-
hsr->sequence_nr = HSR_SEQNR_START;
627-
hsr->sup_sequence_nr = HSR_SUP_SEQNR_START;
628-
hsr->interlink_sequence_nr = HSR_SEQNR_START;
612+
atomic_set(&hsr->sequence_nr, HSR_SEQNR_START);
613+
atomic_set(&hsr->sup_sequence_nr, HSR_SUP_SEQNR_START);
629614

630615
timer_setup(&hsr->announce_timer, hsr_announce, 0);
631616
timer_setup(&hsr->prune_timer, hsr_prune_nodes, 0);

net/hsr/hsr_forward.c

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -599,9 +599,7 @@ static void handle_std_frame(struct sk_buff *skb,
599599
if (port->type == HSR_PT_MASTER ||
600600
port->type == HSR_PT_INTERLINK) {
601601
/* Sequence nr for the master/interlink node */
602-
lockdep_assert_held(&hsr->seqnr_lock);
603-
frame->sequence_nr = hsr->sequence_nr;
604-
hsr->sequence_nr++;
602+
frame->sequence_nr = atomic_inc_return(&hsr->sequence_nr);
605603
}
606604
}
607605

net/hsr/hsr_main.h

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -202,11 +202,9 @@ struct hsr_priv {
202202
struct timer_list prune_timer;
203203
struct timer_list prune_proxy_timer;
204204
int announce_count;
205-
u16 sequence_nr;
206-
u16 interlink_sequence_nr; /* Interlink port seq_nr */
207-
u16 sup_sequence_nr; /* For HSRv1 separate seq_nr for supervision */
205+
atomic_t sequence_nr;
206+
atomic_t sup_sequence_nr; /* For HSRv1 separate seq_nr for supervision */
208207
enum hsr_version prot_version; /* Indicate if HSRv0, HSRv1 or PRPv1 */
209-
spinlock_t seqnr_lock; /* locking for sequence_nr */
210208
spinlock_t list_lock; /* locking for node list */
211209
struct hsr_proto_ops *proto_ops;
212210
#define PRP_LAN_ID 0x5 /* 0x1010 for A and 0x1011 for B. Bit 0 is set

net/hsr/hsr_netlink.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,7 @@ static int hsr_fill_info(struct sk_buff *skb, const struct net_device *dev)
163163

164164
if (nla_put(skb, IFLA_HSR_SUPERVISION_ADDR, ETH_ALEN,
165165
hsr->sup_multicast_addr) ||
166-
nla_put_u16(skb, IFLA_HSR_SEQ_NR, hsr->sequence_nr))
166+
nla_put_u16(skb, IFLA_HSR_SEQ_NR, atomic_read(&hsr->sequence_nr)))
167167
goto nla_put_failure;
168168
if (hsr->prot_version == PRP_V1)
169169
proto = HSR_PROTOCOL_PRP;

0 commit comments

Comments
 (0)