Re: [PATCH net] ppp: fix race conditions in ppp_fill_forward_path

Qingfang Deng <[email protected]> Tue, 12 Aug 2025 17:38:02 +0800
Newsgroups org.kernel.vger.linux-ppp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <CALW65jYNMNArwzmpHhYj3fpfL0Oz2fRYsJz0JMDUnyByu-8z3w@mail.gmail.com>
On Mon, Aug 11, 2025 at 5:35 PM Qingfang Deng <[email protected]> wrote:
>
> On Mon, Aug 11, 2025 at 5:19 PM Eric Dumazet <[email protected]> wrote:
> >
> > On Mon, Aug 11, 2025 at 1:44 AM Qingfang Deng <[email protected]> wrote:
> > It is unclear if rcu_read_lock() is held at this point.
> >
> > list_first_or_null_rcu() does not have a builtin __list_check_rcu()
>
> ndo_fill_forward_path() is called by nf_tables chains, which is inside
> an RCU critical section.

Update: mtk_flow_get_wdma_info() in mtk_ppe_offload.c calls
dev_fill_forward_path() in process context without RCU, so
ppp_fill_forward_path() can be called from two different contexts.
Should I add rcu_read_lock() to mtk_flow_get_wdma_info() or
ppp_fill_forward_path()?