Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

xfrm: use net device refcount tracker helpers

xfrm4_fill_dst() and xfrm6_fill_dst() build dst,
getting a device reference that will likely be released
by standard dst_release() code.

We have to track these references or risk a warning if
CONFIG_NET_DEV_REFCNT_TRACKER=y

Note to XFRM maintainers :

Error path in xfrm6_fill_dst() releases the reference,
but does not clear xdst->u.dst.dev, so I wonder
if this could lead to double dev_put() in some cases,
where a dst_release() _is_ called by the callers in their
error path.

This extra dev_put() was added in commit 84c4a9dfbf430 ("xfrm6:
release dev before returning error")

Fixes: 9038c320001d ("net: dst: add net device refcount tracking to dst_entry")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Cong Wang <amwang@redhat.com>
Acked-by: Steffen Klassert <steffen.klassert@secunet.com>
Link: https://lore.kernel.org/r/20211207193203.2706158-1-eric.dumazet@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>

authored by

Eric Dumazet and committed by
Jakub Kicinski
4177e496 5092fb44

+3 -3
+1 -1
net/ipv4/xfrm4_policy.c
··· 77 77 xdst->u.rt.rt_iif = fl4->flowi4_iif; 78 78 79 79 xdst->u.dst.dev = dev; 80 - dev_hold(dev); 80 + dev_hold_track(dev, &xdst->u.dst.dev_tracker, GFP_ATOMIC); 81 81 82 82 /* Sheit... I remember I did this right. Apparently, 83 83 * it was magically lost, so this code needs audit */
+2 -2
net/ipv6/xfrm6_policy.c
··· 74 74 struct rt6_info *rt = (struct rt6_info *)xdst->route; 75 75 76 76 xdst->u.dst.dev = dev; 77 - dev_hold(dev); 77 + dev_hold_track(dev, &xdst->u.dst.dev_tracker, GFP_ATOMIC); 78 78 79 79 xdst->u.rt6.rt6i_idev = in6_dev_get(dev); 80 80 if (!xdst->u.rt6.rt6i_idev) { 81 - dev_put(dev); 81 + dev_put_track(dev, &xdst->u.dst.dev_tracker); 82 82 return -ENODEV; 83 83 } 84 84