On Fri, Sep 04, 2026 at 01:26:40PM -0700, Long Li wrote:
> mana_xdp_set() publishes the new program into apc->bpf_prog before it
> allocates anything, because mana_pre_alloc_rxbufs() sizes the buffers
> from it via mana_get_rxbuf_cfg(). When that allocation fails the
> function returns the error directly, skipping the err_dealloc_rxbuffs
> label which is the only place that restores the previous pointer.
>
> The attach is reported as failed, so the BPF core drops the reference it
> held for the caller and the program can be freed, while apc->bpf_prog
> still points at it. The next consumer of mana_xdp_get() - typically
> mana_chn_setxdp() from mana_alloc_queues() on the following ifup, or
> after a TX timeout reset - then calls bpf_prog_add() on freed memory.
>
> This is reachable from an ordinary "ip link set dev ethX xdp obj ..."
> whenever the per-queue RX buffer pre-allocation cannot be satisfied.
>
> Restore the previous program on that error path.
>
> Fixes: 730ff06d3f5c ("net: mana: Use page pool fragments for RX buffers
> instead of full pages to improve memory efficiency.")
> Signed-off-by: Long Li <[email protected]>
Reviewed-by: Simon Horman <[email protected]>