Re: [PATCH nf] netfilter: ipset: let destroy callbacks adjust ext mem size

Jozsef Kadlecsik <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <[email protected]>
On Thu, 6 Aug 2026, Florian Westphal wrote:

> For bitmap this change makes no difference, because destructors are
> called synchronously.
> 
> List type however calls them via call_rcu() so accounting decrement can
> happen after list_set_flush() set ext_size to 0.
> 
> 'set->elements = 0' can be removed for the same reason in the list type
> case, it calls 'set->elements--' for each element.
> 
> Fixes: 9e41f26a505c ("netfilter: ipset: Count non-static extension memory for userspace")
> Suggested-by: Jozsef Kadlecsik <[email protected]>
> Signed-off-by: Florian Westphal <[email protected]>

Acked-by: Jozsef Kadlecsik <[email protected]>

Best regards,
Jozsef
> ---
>  sashiko: list_set_uadd() may call list_set_replace() and
>  then erronously increments set->elements, causing a counter
>  drift. This bug will be resolved in a different patch.
> 
>  net/netfilter/ipset/ip_set_bitmap_gen.h | 2 +-
>  net/netfilter/ipset/ip_set_list_set.c   | 3 +--
>  2 files changed, 2 insertions(+), 3 deletions(-)
> 
> diff --git a/net/netfilter/ipset/ip_set_bitmap_gen.h b/net/netfilter/ipset/ip_set_bitmap_gen.h
> index 226fdf17b683..d6a7e6604542 100644
> --- a/net/netfilter/ipset/ip_set_bitmap_gen.h
> +++ b/net/netfilter/ipset/ip_set_bitmap_gen.h
> @@ -77,7 +77,7 @@ mtype_flush(struct ip_set *set)
>  		mtype_ext_cleanup(set);
>  	bitmap_zero(map->members, map->elements);
>  	set->elements = 0;
> -	atomic64_set(&set->ext_size, 0);
> +	DEBUG_NET_WARN_ON_ONCE(atomic64_read(&set->ext_size) > 0);
>  }
>  
>  /* Calculate the actual memory size of the set data */
> diff --git a/net/netfilter/ipset/ip_set_list_set.c b/net/netfilter/ipset/ip_set_list_set.c
> index 56626f4943a9..b4967a9d82b0 100644
> --- a/net/netfilter/ipset/ip_set_list_set.c
> +++ b/net/netfilter/ipset/ip_set_list_set.c
> @@ -423,8 +423,7 @@ list_set_flush(struct ip_set *set)
>  
>  	list_for_each_entry_safe(e, n, &map->members, list)
>  		list_set_del(set, e);
> -	set->elements = 0;
> -	atomic64_set(&set->ext_size, 0);
> +	DEBUG_NET_WARN_ON_ONCE(set->elements > 0);
>  }
>  
>  static void
> -- 
> 2.54.0
> 
> 

-- 
E-mail : [email protected], [email protected], [email protected]
Address: Wigner Research Centre for Physics
         H-1525 Budapest 114, POB. 49, Hungary
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.