[lvc-project] [PATCH 5.10] iavf: use internal state to free traffic IRQs
Victoria Votokina
Victoria.Votokina at kaspersky.com
Tue Sep 1 16:16:33 MSK 2026
From: Victoria.Votokina at kaspersky.com
From: Ahmed Zaki <ahmed.zaki at intel.com>
[ Upstream commit a77ed5c5b768e9649be240a2d864e5cd9c6a2015 ]
If the system tries to close the netdev while iavf_reset_task() is
running, __LINK_STATE_START will be cleared and netif_running() will
return false in iavf_reinit_interrupt_scheme(). This will result in
iavf_free_traffic_irqs() not being called and a leak as follows:
[7632.489326] remove_proc_entry: removing non-empty directory 'irq/999', leaking at least 'iavf-enp24s0f0v0-TxRx-0'
[7632.490214] WARNING: CPU: 0 PID: 10 at fs/proc/generic.c:718 remove_proc_entry+0x19b/0x1b0
is shown when pci_disable_msix() is later called. Fix by using the
internal adapter state. The traffic IRQs will always exist if
state == __IAVF_RUNNING.
Fixes: 5b36e8d04b44 ("i40evf: Enable VF to request an alternate queue allocation")
Signed-off-by: Ahmed Zaki <ahmed.zaki at intel.com>
Tested-by: Rafal Romanowski <rafal.romanowski at intel.com>
Signed-off-by: Tony Nguyen <anthony.l.nguyen at intel.com>
Signed-off-by: Sasha Levin <sashal at kernel.org>
[Victoria: In version 5.10, the IAVF_FLAG_REINIT_MSIX_NEEDED flag is missing,
so iavf_reinit_interrupt_scheme goes only after IAVF_FLAG_REINIT_ITR_NEEDED]
Signed-off-by: Victoria Votokina <Victoria.Votokina at kaspersky.com>
---
Backport fix for CVE-2024-50121
drivers/net/ethernet/intel/iavf/iavf_main.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/net/ethernet/intel/iavf/iavf_main.c b/drivers/net/ethernet/intel/iavf/iavf_main.c
index 4ed93c7f81d2..4edb0a1fdaac 100644
--- a/drivers/net/ethernet/intel/iavf/iavf_main.c
+++ b/drivers/net/ethernet/intel/iavf/iavf_main.c
@@ -1478,15 +1478,16 @@ static void iavf_free_rss(struct iavf_adapter *adapter)
/**
* iavf_reinit_interrupt_scheme - Reallocate queues and vectors
* @adapter: board private structure
+ * @running: true if adapter->state == __IAVF_RUNNING
*
* Returns 0 on success, negative on failure
**/
-static int iavf_reinit_interrupt_scheme(struct iavf_adapter *adapter)
+static int iavf_reinit_interrupt_scheme(struct iavf_adapter *adapter, bool running)
{
struct net_device *netdev = adapter->netdev;
int err;
- if (netif_running(netdev))
+ if (running)
iavf_free_traffic_irqs(adapter);
iavf_free_misc_irq(adapter);
iavf_reset_interrupt_capability(adapter);
@@ -2177,7 +2178,7 @@ static void iavf_reset_task(struct work_struct *work)
adapter->aq_required = 0;
if (adapter->flags & IAVF_FLAG_REINIT_ITR_NEEDED) {
- err = iavf_reinit_interrupt_scheme(adapter);
+ err = iavf_reinit_interrupt_scheme(adapter, running);
if (err)
goto reset_err;
}
--
2.43.0
More information about the lvc-project
mailing list