]> git.hungrycats.org Git - linux/commit
pds_core: fix auxiliary device add/del races
authorNikhil P. Rao <nikhil.rao@amd.com>
Tue, 14 Jul 2026 21:07:45 +0000 (21:07 +0000)
committerJakub Kicinski <kuba@kernel.org>
Tue, 21 Jul 2026 19:46:43 +0000 (12:46 -0700)
commitbfa33cd513c7ceb93c5a4c30e5662acd73c0a916
treeeecfa85f1eb1a7a625c42fbf18868948e11cc7f6
parentdd6b1cc748cd28147c113f9daa76393916ad9494
pds_core: fix auxiliary device add/del races

Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's
pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler.
They serialize on config_lock, but neither guards the slot under it
correctly.

add() registers and stores a new auxiliary device without first checking
the slot, so a second add of an already-populated slot leaks the first
device. del() makes that check outside config_lock, so two concurrent
dels can both pass it; the first clears the slot, and the second
dereferences a NULL pointer.

Check and update the slot under config_lock in both paths.

Fixes: b699bdc720c0 ("pds_core: specify auxiliary_device to be created")
Reported-by: sashiko-bot@kernel.org # Running on a local machine
Signed-off-by: Nikhil P. Rao <nikhil.rao@amd.com>
Reviewed-by: Brett Creeley <brett.creeley@amd.com>
Reviewed-by: Pavan Chebbi <pavan.chebbi@broadcom.com>
Link: https://patch.msgid.link/20260714210745.1785625-1-nikhil.rao@amd.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/amd/pds_core/auxbus.c