ndo_bpf() takes over the reference it is passed only on success, the caller puts it back itself on failure. netvsc_xdp_set() takes that one plus num_chn - 1 more for its channels, and the rollback after the VF refuses the program clears the channels again, putting all num_chn of them. dev_xdp_install() then puts the one it passed in a second time, and the program can be freed while the fd which loaded it still points at it.
The VF refuses a program netvsc has already committed to when the program is single-buffer and the VF has header-data split enabled, when the VF has a memory provider bound, or when the VF's driver has conditions of its own. Reported by Sashiko during core rework. Unverified and untested. Cc: [email protected] # untested fix to unlikely driver error path Fixes: 184367dce4f7 ("hv_netvsc: Fix XDP refcnt for synthetic and VF NICs") Signed-off-by: Jakub Kicinski <[email protected]> --- drivers/net/hyperv/netvsc_bpf.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/net/hyperv/netvsc_bpf.c b/drivers/net/hyperv/netvsc_bpf.c index 1dd3755d9e6d..731bb7721fe2 100644 --- a/drivers/net/hyperv/netvsc_bpf.c +++ b/drivers/net/hyperv/netvsc_bpf.c @@ -216,6 +216,13 @@ int netvsc_bpf(struct net_device *dev, struct netdev_bpf *bpf) netdev_err(dev, "vf_setxdp failed:%d\n", ret); NL_SET_ERR_MSG_MOD(extack, "vf_setxdp failed"); + /* Since we haven't completed the installation + * of bpf->prog the reference core implicitly + * transfers to us on success isn't ours. + * Take a reference to balance the accounting. + */ + if (bpf->prog) + bpf_prog_inc(bpf->prog); netvsc_xdp_set(dev, NULL, extack, nvdev); } -- 2.55.0
