Re: [PATCH net] ppp: fix race conditions in ppp_fill_forward_path

Qingfang Deng <[email protected]> Mon, 11 Aug 2025 17:35:32 +0800
Newsgroups org.kernel.vger.linux-ppp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <CALW65jZ-uBWOkxPVMQc3Yg-KEoVRdPQYVC3+q5MiQbvpDZBKTQ@mail.gmail.com>
On Mon, Aug 11, 2025 at 5:19 PM Eric Dumazet <[email protected]> wrote:
>
> On Mon, Aug 11, 2025 at 1:44 AM Qingfang Deng <[email protected]> wrote:
> It is unclear if rcu_read_lock() is held at this point.
>
> list_first_or_null_rcu() does not have a builtin __list_check_rcu()

ndo_fill_forward_path() is called by nf_tables chains, which is inside
an RCU critical section.

> >         chan = pch->chan;
>
> chan = READ_ONCE(pch->chan);
>
> And add a WRITE_ONCE(pch->chan, NULL) in ppp_unregister_channel()
>
> And/or add __rcu to pch->chan

Should I add {READ,WRITE}_ONCE to all occurrences of pch->chan or only
to ppp_unregister_channel?

>

> > +               synchronize_rcu();
>
> synchronize_net() is preferred.
>

Noted.

Thanks!