Re: [PATCH net] net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain

Jamal Hadi Salim <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <CAM0EoMmQi03B+t8MyUsXp6-QOcOWRJvbji2etp9jjV1gU5V=XQ@mail.gmail.com>
On Mon, Aug 10, 2026 at 7:45 PM Jakub Kicinski <[email protected]> wrote:
>
> On Sun,  9 Aug 2026 05:09:28 -0400 Jamal Hadi Salim wrote:
> > tcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking
> > rcu_access_pointer(a->goto_chain) and then calling
> > tcf_action_goto_chain_exec(), which does a second, independent
> > rcu_dereference_bh(a->goto_chain) read and immediately dereferences
> > chain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact
> > replace path) can clear a->goto_chain between the two reads, so the second
> > read returns NULL and tcf_action_goto_chain_exec() dereferences NULL.
>
> FWIW *shiko suggests another tweak but looks orthogonal, LMK if you
> disagree:
>
> https://netdev-ai.bots.linux.dev/sashiko/#/patchset/[email protected]
>
> (the patch is "too fresh" for me to apply right now anyway)

The concern is valid but pre-existing and orthogonal to this patch
(and a lot less severe than the posted fix)
I had this discussion with Paolo: When the sashikos raise a concern on
"pre-existing" issues, what should be the reaction?
In general the conclusion was to follow up later if worth it; however,
sometimes we need to make a judgement call - if the pointed to issue
is serious (and yes, the AI bots are now reading what Sashikos are
saying  and constructing bug reports) then a v2 is needed.
In this case, I was planning to follow up. I will start more actively
looking at sashiko reports and analyzing if worth a followup or a v2.
I dont know how to do these pw signals, but in case i see it as "needs
v2" it won't be worth waiting for one of you guys to comment.

Do we need a written policy somewhere?

cheers,
jamal
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.