Re: [PATCH net] ppp: fix race conditions in ppp_fill_forward_path
Qingfang Deng <[email protected]> Mon, 11 Aug 2025 17:35:32 +0800
| Newsgroups | gmane.linux.ppp,gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <CALW65jZ-uBWOkxPVMQc3Yg-KEoVRdPQYVC3+q5MiQbvpDZBKTQ@mail.gmail.com> |
On Mon, Aug 11, 2025 at 5:19 PM Eric Dumazet <[email protected]> wrote: > > On Mon, Aug 11, 2025 at 1:44 AM Qingfang Deng <[email protected]> wrote: > It is unclear if rcu_read_lock() is held at this point. > > list_first_or_null_rcu() does not have a builtin __list_check_rcu() ndo_fill_forward_path() is called by nf_tables chains, which is inside an RCU critical section. > > chan = pch->chan; > > chan = READ_ONCE(pch->chan); > > And add a WRITE_ONCE(pch->chan, NULL) in ppp_unregister_channel() > > And/or add __rcu to pch->chan Should I add {READ,WRITE}_ONCE to all occurrences of pch->chan or only to ppp_unregister_channel? > > > + synchronize_rcu(); > > synchronize_net() is preferred. > Noted. Thanks!