Commit 4c62ddf7 authored by Ido Schimmel's avatar Ido Schimmel Committed by Sasha Levin

switchdev: Require RTNL mutex to be held when sending FDB notifications

[ Upstream commit 4f2c6ae5 ]

When switchdev drivers process FDB notifications from the underlying
device they resolve the netdev to which the entry points to and notify
the bridge using the switchdev notifier.

However, since the RTNL mutex is not held there is nothing preventing
the netdev from disappearing in the middle, which will cause
br_switchdev_event() to dereference a non-existing netdev.

Make switchdev drivers hold the lock at the beginning of the
notification processing session and release it once it ends, after
notifying the bridge.

Also, remove switchdev_mutex and fdb_lock, as they are no longer needed
when RTNL mutex is held.

Fixes: 03bf0c28 ("switchdev: introduce switchdev notifier")
Signed-off-by: default avatarIdo Schimmel <idosch@mellanox.com>
Signed-off-by: default avatarJiri Pirko <jiri@mellanox.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarSasha Levin <sasha.levin@oracle.com>
parent 257a0478
...@@ -3384,12 +3384,14 @@ static void rocker_port_fdb_learn_work(struct work_struct *work) ...@@ -3384,12 +3384,14 @@ static void rocker_port_fdb_learn_work(struct work_struct *work)
info.addr = lw->addr; info.addr = lw->addr;
info.vid = lw->vid; info.vid = lw->vid;
rtnl_lock();
if (learned && removing) if (learned && removing)
call_netdev_switch_notifiers(NETDEV_SWITCH_FDB_DEL, call_netdev_switch_notifiers(NETDEV_SWITCH_FDB_DEL,
lw->dev, &info.info); lw->dev, &info.info);
else if (learned && !removing) else if (learned && !removing)
call_netdev_switch_notifiers(NETDEV_SWITCH_FDB_ADD, call_netdev_switch_notifiers(NETDEV_SWITCH_FDB_ADD,
lw->dev, &info.info); lw->dev, &info.info);
rtnl_unlock();
kfree(work); kfree(work);
} }
......
...@@ -121,6 +121,7 @@ static struct notifier_block br_device_notifier = { ...@@ -121,6 +121,7 @@ static struct notifier_block br_device_notifier = {
.notifier_call = br_device_event .notifier_call = br_device_event
}; };
/* called with RTNL */
static int br_netdev_switch_event(struct notifier_block *unused, static int br_netdev_switch_event(struct notifier_block *unused,
unsigned long event, void *ptr) unsigned long event, void *ptr)
{ {
...@@ -130,7 +131,6 @@ static int br_netdev_switch_event(struct notifier_block *unused, ...@@ -130,7 +131,6 @@ static int br_netdev_switch_event(struct notifier_block *unused,
struct netdev_switch_notifier_fdb_info *fdb_info; struct netdev_switch_notifier_fdb_info *fdb_info;
int err = NOTIFY_DONE; int err = NOTIFY_DONE;
rtnl_lock();
p = br_port_get_rtnl(dev); p = br_port_get_rtnl(dev);
if (!p) if (!p)
goto out; goto out;
...@@ -155,7 +155,6 @@ static int br_netdev_switch_event(struct notifier_block *unused, ...@@ -155,7 +155,6 @@ static int br_netdev_switch_event(struct notifier_block *unused,
} }
out: out:
rtnl_unlock();
return err; return err;
} }
......
...@@ -15,6 +15,7 @@ ...@@ -15,6 +15,7 @@
#include <linux/mutex.h> #include <linux/mutex.h>
#include <linux/notifier.h> #include <linux/notifier.h>
#include <linux/netdevice.h> #include <linux/netdevice.h>
#include <linux/rtnetlink.h>
#include <net/ip_fib.h> #include <net/ip_fib.h>
#include <net/switchdev.h> #include <net/switchdev.h>
...@@ -64,7 +65,6 @@ int netdev_switch_port_stp_update(struct net_device *dev, u8 state) ...@@ -64,7 +65,6 @@ int netdev_switch_port_stp_update(struct net_device *dev, u8 state)
} }
EXPORT_SYMBOL_GPL(netdev_switch_port_stp_update); EXPORT_SYMBOL_GPL(netdev_switch_port_stp_update);
static DEFINE_MUTEX(netdev_switch_mutex);
static RAW_NOTIFIER_HEAD(netdev_switch_notif_chain); static RAW_NOTIFIER_HEAD(netdev_switch_notif_chain);
/** /**
...@@ -79,9 +79,9 @@ int register_netdev_switch_notifier(struct notifier_block *nb) ...@@ -79,9 +79,9 @@ int register_netdev_switch_notifier(struct notifier_block *nb)
{ {
int err; int err;
mutex_lock(&netdev_switch_mutex); rtnl_lock();
err = raw_notifier_chain_register(&netdev_switch_notif_chain, nb); err = raw_notifier_chain_register(&netdev_switch_notif_chain, nb);
mutex_unlock(&netdev_switch_mutex); rtnl_unlock();
return err; return err;
} }
EXPORT_SYMBOL_GPL(register_netdev_switch_notifier); EXPORT_SYMBOL_GPL(register_netdev_switch_notifier);
...@@ -97,9 +97,9 @@ int unregister_netdev_switch_notifier(struct notifier_block *nb) ...@@ -97,9 +97,9 @@ int unregister_netdev_switch_notifier(struct notifier_block *nb)
{ {
int err; int err;
mutex_lock(&netdev_switch_mutex); rtnl_lock();
err = raw_notifier_chain_unregister(&netdev_switch_notif_chain, nb); err = raw_notifier_chain_unregister(&netdev_switch_notif_chain, nb);
mutex_unlock(&netdev_switch_mutex); rtnl_unlock();
return err; return err;
} }
EXPORT_SYMBOL_GPL(unregister_netdev_switch_notifier); EXPORT_SYMBOL_GPL(unregister_netdev_switch_notifier);
...@@ -113,16 +113,17 @@ EXPORT_SYMBOL_GPL(unregister_netdev_switch_notifier); ...@@ -113,16 +113,17 @@ EXPORT_SYMBOL_GPL(unregister_netdev_switch_notifier);
* Call all network notifier blocks. This should be called by driver * Call all network notifier blocks. This should be called by driver
* when it needs to propagate hardware event. * when it needs to propagate hardware event.
* Return values are same as for atomic_notifier_call_chain(). * Return values are same as for atomic_notifier_call_chain().
* rtnl_lock must be held.
*/ */
int call_netdev_switch_notifiers(unsigned long val, struct net_device *dev, int call_netdev_switch_notifiers(unsigned long val, struct net_device *dev,
struct netdev_switch_notifier_info *info) struct netdev_switch_notifier_info *info)
{ {
int err; int err;
ASSERT_RTNL();
info->dev = dev; info->dev = dev;
mutex_lock(&netdev_switch_mutex);
err = raw_notifier_call_chain(&netdev_switch_notif_chain, val, info); err = raw_notifier_call_chain(&netdev_switch_notif_chain, val, info);
mutex_unlock(&netdev_switch_mutex);
return err; return err;
} }
EXPORT_SYMBOL_GPL(call_netdev_switch_notifiers); EXPORT_SYMBOL_GPL(call_netdev_switch_notifiers);
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment