| From ccb7276a6d26d6f8416e315b43b45e15ee7f29e2 Mon Sep 17 00:00:00 2001 |
| From: Andy Strohman <andrew@andrewstrohman.com> |
| Date: Thu, 9 Jan 2025 02:27:56 +0000 |
| Subject: batman-adv: fix panic during interface removal |
| |
| From: Andy Strohman <andrew@andrewstrohman.com> |
| |
| commit ccb7276a6d26d6f8416e315b43b45e15ee7f29e2 upstream. |
| |
| Reference counting is used to ensure that |
| batadv_hardif_neigh_node and batadv_hard_iface |
| are not freed before/during |
| batadv_v_elp_throughput_metric_update work is |
| finished. |
| |
| But there isn't a guarantee that the hard if will |
| remain associated with a soft interface up until |
| the work is finished. |
| |
| This fixes a crash triggered by reboot that looks |
| like this: |
| |
| Call trace: |
| batadv_v_mesh_free+0xd0/0x4dc [batman_adv] |
| batadv_v_elp_throughput_metric_update+0x1c/0xa4 |
| process_one_work+0x178/0x398 |
| worker_thread+0x2e8/0x4d0 |
| kthread+0xd8/0xdc |
| ret_from_fork+0x10/0x20 |
| |
| (the batadv_v_mesh_free call is misleading, |
| and does not actually happen) |
| |
| I was able to make the issue happen more reliably |
| by changing hardif_neigh->bat_v.metric_work work |
| to be delayed work. This allowed me to track down |
| and confirm the fix. |
| |
| Cc: stable@vger.kernel.org |
| Fixes: c833484e5f38 ("batman-adv: ELP - compute the metric based on the estimated throughput") |
| Signed-off-by: Andy Strohman <andrew@andrewstrohman.com> |
| [sven@narfation.org: prevent entering batadv_v_elp_get_throughput without |
| soft_iface] |
| Signed-off-by: Sven Eckelmann <sven@narfation.org> |
| Signed-off-by: Simon Wunderlich <sw@simonwunderlich.de> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| net/batman-adv/bat_v_elp.c | 9 ++++++++- |
| 1 file changed, 8 insertions(+), 1 deletion(-) |
| |
| --- a/net/batman-adv/bat_v_elp.c |
| +++ b/net/batman-adv/bat_v_elp.c |
| @@ -66,12 +66,19 @@ static void batadv_v_elp_start_timer(str |
| static u32 batadv_v_elp_get_throughput(struct batadv_hardif_neigh_node *neigh) |
| { |
| struct batadv_hard_iface *hard_iface = neigh->if_incoming; |
| + struct net_device *soft_iface = hard_iface->soft_iface; |
| struct ethtool_link_ksettings link_settings; |
| struct net_device *real_netdev; |
| struct station_info sinfo; |
| u32 throughput; |
| int ret; |
| |
| + /* don't query throughput when no longer associated with any |
| + * batman-adv interface |
| + */ |
| + if (!soft_iface) |
| + return BATADV_THROUGHPUT_DEFAULT_VALUE; |
| + |
| /* if the user specified a customised value for this interface, then |
| * return it directly |
| */ |
| @@ -141,7 +148,7 @@ static u32 batadv_v_elp_get_throughput(s |
| |
| default_throughput: |
| if (!(hard_iface->bat_v.flags & BATADV_WARNING_DEFAULT)) { |
| - batadv_info(hard_iface->soft_iface, |
| + batadv_info(soft_iface, |
| "WiFi driver or ethtool info does not provide information about link speeds on interface %s, therefore defaulting to hardcoded throughput values of %u.%1u Mbps. Consider overriding the throughput manually or checking your driver.\n", |
| hard_iface->net_dev->name, |
| BATADV_THROUGHPUT_DEFAULT_VALUE / 10, |