Re: [PATCH net 01/13] netfilter: ipset: fix refcount race between list:set GC and swap

[email protected]
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network
Message-ID <178649882389.1230679.84745710900451719.git-patchwork-notify@kernel.org>
Hello:

This series was applied to netdev/net.git (main)
by Pablo Neira Ayuso <[email protected]>:

On Mon, 10 Aug 2026 21:06:09 +0200 you wrote:
> From: "Xiang Mei (Microsoft)" <[email protected]>
> 
> __ip_set_put_byindex() resolved the index to a set pointer under RCU,
> then took ip_set_ref_lock in __ip_set_put() to decrement set->ref.
> ip_set_swap() holds that same lock while swapping both the ip_set_list
> slots and the two sets' ref counters, so it can interleave between the
> dereference and the lock acquisition, leaving the caller to decrement a
> set whose reference already moved to the other index and hit
> BUG_ON(set->ref == 0). list_set_gc() reaches this from timer softirq,
> which the nfnl mutex does not serialize against swap: an expiring
> list:set member calls list_set_del() -> ip_set_put_byindex() while
> IPSET_CMD_SWAP runs on the referenced sets.
> 
> [...]

Here is the summary with links:
  - [net,01/13] netfilter: ipset: fix refcount race between list:set GC and swap
    https://git.kernel.org/netdev/net/c/0c8886827165
  - [net,02/13] netfilter: bridge: release template ct on non-IP path
    https://git.kernel.org/netdev/net/c/d45cc8020d7c
  - [net,03/13] ipvs: add totalconns for dest
    https://git.kernel.org/netdev/net/c/04d2feaed8d0
  - [net,04/13] ipvs: properly update the overload flag on dest edit
    https://git.kernel.org/netdev/net/c/8f843441c4e7
  - [net,05/13] ipvs: separate destination availability state
    https://git.kernel.org/netdev/net/c/cdcc4e46180d
  - [net,06/13] netfilter: nf_conntrack: defer invalid log until after unlock
    https://git.kernel.org/netdev/net/c/2d19b95c9723
  - [net,07/13] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state
    https://git.kernel.org/netdev/net/c/33d1469b0124
  - [net,08/13] ipvs: clear IPv4 options after rebasing tunnel ICMP errors
    https://git.kernel.org/netdev/net/c/e0ba936287df
  - [net,09/13] ipvs: revalidate ihl to prevent out-of-bounds access
    https://git.kernel.org/netdev/net/c/d93660df4dd1
  - [net,10/13] netfilter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path
    https://git.kernel.org/netdev/net/c/d02f59206434
  - [net,11/13] netfilter: flowtable: publish GC-visible tuple last
    https://git.kernel.org/netdev/net/c/2014ac62df9d
  - [net,12/13] netfilter: ipset: fix list type element drift bug
    https://git.kernel.org/netdev/net/c/4cbd69766b35
  - [net,13/13] netfilter: ipset: let destroy callbacks adjust ext mem size
    https://git.kernel.org/netdev/net/c/490937b88cb5

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.