Re: [PATCH bpf v2] bpf: cpumap: fix use-after-free of dev_rx on netdev unregister
From: Alexei Starovoitov
Date: Thu Sep 24 2026 - 10:27:15 EST
On Thu, Sep 24, 2026 at 04:18 PM Jiayuan Chen <jiayuan.chen@xxxxxxxxx> wrote:
> The notifier has to ask every entry, a cpumap entry is not tied to a
> netns and any device can feed it. So an unregister anywhere drains
> every ring in the system, once per device, with RTNL held. That is
> bounded: qsize is capped at 16384, each entry consumes at most one
> ring plus a GRO flush, and the kthreads do it in parallel. Those
> frames had to be consumed anyway. Nothing changes on the hot path,
> the kthread reads one field per batch.
The code is the same as in v2. Only the commit log changed.
The number of frames is bounded. The time is not.
wait_event() has no timeout and sleeps with rtnl held until
every cpumap kthread in the system gets cpu, including the ones
with an empty ring.
flush_all_backlogs() had the same problem. See
commit 2de79ee27fdb ("net: try to avoid unneeded backlog flush").
The bug needs a kthread that doesn't get cpu during unregister.
With this patch such kthread blocks unregister of every netdev
in every netns while rtnl is held.
pw-bot: cr