Re: [PATCH net] net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain

Jakub Kicinski <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <[email protected]>
On Tue, 11 Aug 2026 06:43:32 -0400 Jamal Hadi Salim wrote:
> On Mon, Aug 10, 2026 at 7:45 PM Jakub Kicinski <[email protected]> wrote:
> >
> > On Sun,  9 Aug 2026 05:09:28 -0400 Jamal Hadi Salim wrote:  
> > > tcf_action_exec() handles TC_ACT_GOTO_CHAIN by first checking
> > > rcu_access_pointer(a->goto_chain) and then calling
> > > tcf_action_goto_chain_exec(), which does a second, independent
> > > rcu_dereference_bh(a->goto_chain) read and immediately dereferences
> > > chain->filter_chain. A concurrent tcf_action_set_ctrlact() (e.g. the gact
> > > replace path) can clear a->goto_chain between the two reads, so the second
> > > read returns NULL and tcf_action_goto_chain_exec() dereferences NULL.  
> >
> > FWIW *shiko suggests another tweak but looks orthogonal, LMK if you
> > disagree:
> >
> > https://netdev-ai.bots.linux.dev/sashiko/#/patchset/[email protected]
> >
> > (the patch is "too fresh" for me to apply right now anyway)  
> 
> The concern is valid but pre-existing and orthogonal to this patch
> (and a lot less severe than the posted fix)
> I had this discussion with Paolo: When the sashikos raise a concern on
> "pre-existing" issues, what should be the reaction?
> In general the conclusion was to follow up later if worth it; however,
> sometimes we need to make a judgement call - if the pointed to issue
> is serious (and yes, the AI bots are now reading what Sashikos are
> saying  and constructing bug reports) then a v2 is needed.
> In this case, I was planning to follow up. I will start more actively
> looking at sashiko reports and analyzing if worth a followup or a v2.
> I dont know how to do these pw signals, but in case i see it as "needs
> v2" it won't be worth waiting for one of you guys to comment.

Right, I was hoping my question was clear enough. I don't think v2 was
needed here either. But we had time to confirm...

> Do we need a written policy somewhere?

The only written policy should be that everyone who asks for a written
policy in this rapidly changing environment owes maintainers a beer :)

More seriously I tried to float two written policies recently - for net
vs net-next and requirements for information in fixes. And each time
there was a long discussion and questions. So y'all need to either
stop making written policies so painful, or stop asking for the
policies. *%$#.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.