Re: [PATCH net] net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain
Jamal Hadi Salim <[email protected]>
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAM0EoMmQi03B+t8MyUsXp6-QOcOWRJvbji2etp9jjV1gU5V=XQ@mail.gmail.com> |
On Mon, Aug 10, 2026 at 7:45 PM Jakub Kicinski <[email protected]> wrote: > > On Sun, 9 Aug 2026 05:09:28 -0400 Jamal Hadi Salim wrote: > > tcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking > > rcu_access_pointer(a->goto_chain) and then calling > > tcf_action_goto_chain_exec(), which does a second, independent > > rcu_dereference_bh(a->goto_chain) read and immediately dereferences > > chain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact > > replace path) can clear a->goto_chain between the two reads, so the second > > read returns NULL and tcf_action_goto_chain_exec() dereferences NULL. > > FWIW *shiko suggests another tweak but looks orthogonal, LMK if you > disagree: > > https://netdev-ai.bots.linux.dev/sashiko/#/patchset/[email protected] > > (the patch is "too fresh" for me to apply right now anyway) The concern is valid but pre-existing and orthogonal to this patch (and a lot less severe than the posted fix) I had this discussion with Paolo: When the sashikos raise a concern on "pre-existing" issues, what should be the reaction? In general the conclusion was to follow up later if worth it; however, sometimes we need to make a judgement call - if the pointed to issue is serious (and yes, the AI bots are now reading what Sashikos are saying and constructing bug reports) then a v2 is needed. In this case, I was planning to follow up. I will start more actively looking at sashiko reports and analyzing if worth a followup or a v2. I dont know how to do these pw signals, but in case i see it as "needs v2" it won't be worth waiting for one of you guys to comment. Do we need a written policy somewhere? cheers, jamal