* [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending
@ 2026-10-01 4:22 Haishuang Yan
2026-10-06 14:59 ` Simon Horman
2026-10-07 0:20 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 3+ messages in thread
From: Haishuang Yan @ 2026-10-01 4:22 UTC (permalink / raw)
To: netdev
Cc: Jiri Pirko, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, linux-kernel, Haishuang Yan
devlink_rel_nested_in_notify_work_schedule() takes a reference on the
devlink_rel for the notify work and then queues the work, ignoring the
return value of schedule_delayed_work(). If the work is already pending,
nothing new is queued, the work runs only once and drops only one
reference, so the extra one is leaked together with the devlink_rel and
its index in devlink_rels.
This is easy to hit. devl_register() of a nested instance queues the
work, and if the instance is unregistered before the work has run,
devlink_rel_put() queues it again while it is still pending. The work
also keeps rescheduling itself for as long as the parent devlink lock
cannot be taken, which widens the window. Registering and unregistering
a nested devlink instance 100 times while holding the parent lock leaks
all 100 devlink_rel objects.
The reschedule path in devlink_rel_nested_in_notify_work() has the same
problem: if the work was queued again while it was running, the
reference it holds is never dropped.
Drop the reference in both places when the work was already pending.
The pending work holds its own reference, so this can not be the last
one.
Fixes: c137743bce02 ("devlink: introduce object and nested devlink relationship infra")
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
net/devlink/core.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/net/devlink/core.c b/net/devlink/core.c
index c53a42e17a58..bddbbbf000fe 100644
--- a/net/devlink/core.c
+++ b/net/devlink/core.c
@@ -112,13 +112,19 @@ static void devlink_rel_nested_in_notify_work(struct work_struct *work)
return;
reschedule_work:
- schedule_delayed_work(&rel->nested_in.notify_work, 1);
+ /* The work may have been queued again meanwhile, which took its own
+ * reference. Drop ours in that case.
+ */
+ if (!schedule_delayed_work(&rel->nested_in.notify_work, 1))
+ __devlink_rel_put(rel);
}
static void devlink_rel_nested_in_notify_work_schedule(struct devlink_rel *rel)
{
__devlink_rel_get(rel);
- schedule_delayed_work(&rel->nested_in.notify_work, 0);
+ /* The pending work holds a reference already, drop the new one. */
+ if (!schedule_delayed_work(&rel->nested_in.notify_work, 0))
+ __devlink_rel_put(rel);
}
static struct devlink_rel *devlink_rel_alloc(void)
--
2.43.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending
2026-10-01 4:22 [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending Haishuang Yan
@ 2026-10-06 14:59 ` Simon Horman
2026-10-07 0:20 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: Simon Horman @ 2026-10-06 14:59 UTC (permalink / raw)
To: Haishuang Yan
Cc: netdev, Jiri Pirko, David S . Miller, Eric Dumazet,
Jakub Kicinski, Paolo Abeni, linux-kernel
On Thu, Oct 01, 2026 at 12:22:32PM +0800, Haishuang Yan wrote:
> devlink_rel_nested_in_notify_work_schedule() takes a reference on the
> devlink_rel for the notify work and then queues the work, ignoring the
> return value of schedule_delayed_work(). If the work is already pending,
> nothing new is queued, the work runs only once and drops only one
> reference, so the extra one is leaked together with the devlink_rel and
> its index in devlink_rels.
>
> This is easy to hit. devl_register() of a nested instance queues the
> work, and if the instance is unregistered before the work has run,
> devlink_rel_put() queues it again while it is still pending. The work
> also keeps rescheduling itself for as long as the parent devlink lock
> cannot be taken, which widens the window. Registering and unregistering
> a nested devlink instance 100 times while holding the parent lock leaks
> all 100 devlink_rel objects.
>
> The reschedule path in devlink_rel_nested_in_notify_work() has the same
> problem: if the work was queued again while it was running, the
> reference it holds is never dropped.
>
> Drop the reference in both places when the work was already pending.
> The pending work holds its own reference, so this can not be the last
> one.
>
> Fixes: c137743bce02 ("devlink: introduce object and nested devlink relationship infra")
> Assisted-by: LLM
> Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
Reviewed-by: Simon Horman <horms@kernel.org>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending
2026-10-01 4:22 [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending Haishuang Yan
2026-10-06 14:59 ` Simon Horman
@ 2026-10-07 0:20 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-07 0:20 UTC (permalink / raw)
To: Haishuang Yan
Cc: netdev, jiri, davem, edumazet, kuba, pabeni, horms, linux-kernel
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Thu, 1 Oct 2026 12:22:32 +0800 you wrote:
> devlink_rel_nested_in_notify_work_schedule() takes a reference on the
> devlink_rel for the notify work and then queues the work, ignoring the
> return value of schedule_delayed_work(). If the work is already pending,
> nothing new is queued, the work runs only once and drops only one
> reference, so the extra one is leaked together with the devlink_rel and
> its index in devlink_rels.
>
> [...]
Here is the summary with links:
- [net] devlink: fix devlink_rel reference leak when notify work is pending
https://git.kernel.org/netdev/net/c/c5381ae1cd14
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-07 0:20 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 4:22 [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending Haishuang Yan
2026-10-06 14:59 ` Simon Horman
2026-10-07 0:20 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®