Re: [PATCH nf] netfilter: ipset: let destroy callbacks adjust ext mem size
Jozsef Kadlecsik <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 6 Aug 2026, Florian Westphal wrote:
> For bitmap this change makes no difference, because destructors are
> called synchronously.
>
> List type however calls them via call_rcu() so accounting decrement can
> happen after list_set_flush() set ext_size to 0.
>
> 'set->elements = 0' can be removed for the same reason in the list type
> case, it calls 'set->elements--' for each element.
>
> Fixes: 9e41f26a505c ("netfilter: ipset: Count non-static extension memory for userspace")
> Suggested-by: Jozsef Kadlecsik <[email protected]>
> Signed-off-by: Florian Westphal <[email protected]>
Acked-by: Jozsef Kadlecsik <[email protected]>
Best regards,
Jozsef
> ---
> sashiko: list_set_uadd() may call list_set_replace() and
> then erronously increments set->elements, causing a counter
> drift. This bug will be resolved in a different patch.
>
> net/netfilter/ipset/ip_set_bitmap_gen.h | 2 +-
> net/netfilter/ipset/ip_set_list_set.c | 3 +--
> 2 files changed, 2 insertions(+), 3 deletions(-)
>
> diff --git a/net/netfilter/ipset/ip_set_bitmap_gen.h b/net/netfilter/ipset/ip_set_bitmap_gen.h
> index 226fdf17b683..d6a7e6604542 100644
> --- a/net/netfilter/ipset/ip_set_bitmap_gen.h
> +++ b/net/netfilter/ipset/ip_set_bitmap_gen.h
> @@ -77,7 +77,7 @@ mtype_flush(struct ip_set *set)
> mtype_ext_cleanup(set);
> bitmap_zero(map->members, map->elements);
> set->elements = 0;
> - atomic64_set(&set->ext_size, 0);
> + DEBUG_NET_WARN_ON_ONCE(atomic64_read(&set->ext_size) > 0);
> }
>
> /* Calculate the actual memory size of the set data */
> diff --git a/net/netfilter/ipset/ip_set_list_set.c b/net/netfilter/ipset/ip_set_list_set.c
> index 56626f4943a9..b4967a9d82b0 100644
> --- a/net/netfilter/ipset/ip_set_list_set.c
> +++ b/net/netfilter/ipset/ip_set_list_set.c
> @@ -423,8 +423,7 @@ list_set_flush(struct ip_set *set)
>
> list_for_each_entry_safe(e, n, &map->members, list)
> list_set_del(set, e);
> - set->elements = 0;
> - atomic64_set(&set->ext_size, 0);
> + DEBUG_NET_WARN_ON_ONCE(set->elements > 0);
> }
>
> static void
> --
> 2.54.0
>
>
--
E-mail : [email protected], [email protected], [email protected]
Address: Wigner Research Centre for Physics
H-1525 Budapest 114, POB. 49, Hungary