Re: [PATCH net] devlink: fix devlink_rel reference leak when notify work is pending

From: Simon Horman

Date: Tue Oct 06 2026 - 11:03:23 EST


On Thu, Oct 01, 2026 at 12:22:32PM +0800, Haishuang Yan wrote:
> devlink_rel_nested_in_notify_work_schedule() takes a reference on the
> devlink_rel for the notify work and then queues the work, ignoring the
> return value of schedule_delayed_work(). If the work is already pending,
> nothing new is queued, the work runs only once and drops only one
> reference, so the extra one is leaked together with the devlink_rel and
> its index in devlink_rels.
>
> This is easy to hit. devl_register() of a nested instance queues the
> work, and if the instance is unregistered before the work has run,
> devlink_rel_put() queues it again while it is still pending. The work
> also keeps rescheduling itself for as long as the parent devlink lock
> cannot be taken, which widens the window. Registering and unregistering
> a nested devlink instance 100 times while holding the parent lock leaks
> all 100 devlink_rel objects.
>
> The reschedule path in devlink_rel_nested_in_notify_work() has the same
> problem: if the work was queued again while it was running, the
> reference it holds is never dropped.
>
> Drop the reference in both places when the work was already pending.
> The pending work holds its own reference, so this can not be the last
> one.
>
> Fixes: c137743bce02 ("devlink: introduce object and nested devlink relationship infra")
> Assisted-by: LLM
> Signed-off-by: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>

Reviewed-by: Simon Horman <horms@xxxxxxxxxx>