ndo_bpf() takes over the reference it is passed only on success, the
caller puts it back itself on failure. netvsc_xdp_set() takes that one
plus num_chn - 1 more for its channels, and the rollback after the VF
refuses the program clears the channels again, putting all num_chn of
them. dev_xdp_install() then puts the one it passed in a second time,
and the program can be freed while the fd which loaded it still points
at it.

The VF refuses a program netvsc has already committed to when the
program is single-buffer and the VF has header-data split enabled, when
the VF has a memory provider bound, or when the VF's driver has
conditions of its own.

Reported by Sashiko during core rework. Unverified and untested.

Cc: [email protected] # untested fix to unlikely driver error path
Fixes: 184367dce4f7 ("hv_netvsc: Fix XDP refcnt for synthetic and VF NICs")
Signed-off-by: Jakub Kicinski <[email protected]>
---
 drivers/net/hyperv/netvsc_bpf.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/drivers/net/hyperv/netvsc_bpf.c b/drivers/net/hyperv/netvsc_bpf.c
index 1dd3755d9e6d..731bb7721fe2 100644
--- a/drivers/net/hyperv/netvsc_bpf.c
+++ b/drivers/net/hyperv/netvsc_bpf.c
@@ -216,6 +216,13 @@ int netvsc_bpf(struct net_device *dev, struct netdev_bpf 
*bpf)
                        netdev_err(dev, "vf_setxdp failed:%d\n", ret);
                        NL_SET_ERR_MSG_MOD(extack, "vf_setxdp failed");
 
+                       /* Since we haven't completed the installation
+                        * of bpf->prog the reference core implicitly
+                        * transfers to us on success isn't ours.
+                        * Take a reference to balance the accounting.
+                        */
+                       if (bpf->prog)
+                               bpf_prog_inc(bpf->prog);
                        netvsc_xdp_set(dev, NULL, extack, nvdev);
                }
 
-- 
2.55.0


Reply via email to