[PATCH net] netlabel: check register_netdevice_notifier() error in netlbl_unlabel_init()

Paul Moore paul at paul-moore.com
Tue Jul 28 22:36:40 UTC 2026


On Mon, Jul 27, 2026 at 11:10 PM Minhong He <heminhong at kylinos.cn> wrote:
>
> netlbl_unlabel_init() installs the unlabeled connection hash table and
> registers a netdevice notifier, but ignores notifier registration errors
> and always returns success.
>
> Check the error and unwind the hash table allocation on failure.
>
> Signed-off-by: Minhong He <heminhong at kylinos.cn>
> ---
>  net/netlabel/netlabel_unlabeled.c | 12 +++++++++++-
>  1 file changed, 11 insertions(+), 1 deletion(-)
>
> diff --git a/net/netlabel/netlabel_unlabeled.c b/net/netlabel/netlabel_unlabeled.c
> index 47bae5e48db6..34704f6eb1d8 100644
> --- a/net/netlabel/netlabel_unlabeled.c
> +++ b/net/netlabel/netlabel_unlabeled.c
> @@ -1397,6 +1397,7 @@ static struct notifier_block netlbl_unlhsh_netdev_notifier = {
>   */
>  int __init netlbl_unlabel_init(u32 size)
>  {
> +       int err;
>         u32 iter;
>         struct netlbl_unlhsh_tbl *hsh_tbl;
>
> @@ -1419,7 +1420,16 @@ int __init netlbl_unlabel_init(u32 size)
>         rcu_assign_pointer(netlbl_unlhsh, hsh_tbl);
>         spin_unlock(&netlbl_unlhsh_lock);
>
> -       register_netdevice_notifier(&netlbl_unlhsh_netdev_notifier);
> +       err = register_netdevice_notifier(&netlbl_unlhsh_netdev_notifier);
> +       if (err) {
> +               spin_lock(&netlbl_unlhsh_lock);
> +               RCU_INIT_POINTER(netlbl_unlhsh, NULL);

I'd probably just use rcu_assign_pointer() like earlier in this
function; whatever tiny performance bump you get from
RCU_INIT_POINTER() is wasted as the kernel is going to soon panic in
this case (look at netlbl_init()).  If you make this change you can
add my ACK to the v2 patch.

Acked-by: Paul Moore <paul at paul-moore.com>

> +               spin_unlock(&netlbl_unlhsh_lock);
> +               synchronize_rcu();
> +               kfree(hsh_tbl->tbl);
> +               kfree(hsh_tbl);
> +               return err;
> +       }
>
>         return 0;
>  }
> --
> 2.25.1

-- 
paul-moore.com



More information about the Linux-security-module-archive mailing list