Page MenuHomeFreeBSD

gve: fix kernel panic on attach failure
ClosedPublic

Authored by jtranoleary_google.com on Mon, Oct 5, 10:02 PM.
Tags
None
Referenced Files
F175111460: D60385.id188963.diff
Thu, Oct 8, 8:28 AM
F175110765: D60385.id188759.diff
Thu, Oct 8, 8:21 AM
F175109857: D60385.diff
Thu, Oct 8, 8:11 AM
F175089873: D60385.diff
Thu, Oct 8, 4:51 AM
F175028146: D60385.id188759.diff
Wed, Oct 7, 6:09 PM
F175024844: D60385.id.diff
Wed, Oct 7, 5:32 PM
Unknown Object (File)
Wed, Oct 7, 1:31 PM
Unknown Object (File)
Wed, Oct 7, 1:31 PM

Details

Summary

When device initialization fails during attach (for instance, if device
resource configuration or firmware negotiation fails), the driver aborts
and unrolls partial state via its detach routine. However, the teardown
path assumes transmit and receive queues have already been created. If
attach aborts before queue allocation, tearing down the uninitialized
queues triggers a NULL pointer dereference and panics the kernel during
boot.

Guard queue teardown against uninitialized queue state so that early
attach failures unwind safely, allowing the driver to report the failure
gracefully without crashing the operating system.

Signed-off-by: Jasper Tran O'Leary <jtranoleary@google.com>

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77741
Build 74624: arc lint + arc unit