All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ido Schimmel <idosch@nvidia.com>
To: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Cc: netdev@vger.kernel.org, dsahern@kernel.org, davem@davemloft.net,
	edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
	horms@kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] ipv6: release fib6_null_entry on subtree failure
Date: Wed, 29 Jul 2026 15:44:00 +0300	[thread overview]
Message-ID: <20260729124400.GA1365523@shredder> (raw)
In-Reply-To: <20260727185339.1545169-1-shuangpeng.kernel@gmail.com>

On Mon, Jul 27, 2026 at 02:53:39PM -0400, Shuangpeng Bai wrote:
> When adding a source-specific route creates a new subtree, fib6_add()
> installs fib6_null_entry as the temporary leaf of the new subtree root
> and takes a fib6_info reference for that holder.
> 
> If adding the first source leaf fails, the code frees the just allocated
> subtree root but leaves that hold behind. fib6_null_entry is a per-netns
> sentinel and is freed directly at netns teardown, so this does not keep
> the object alive. However, it leaves its visible refcount permanently
> elevated and can eventually saturate the refcount on repeated failures.
> 
> Drop the null-entry reference before freeing the unlinked subtree root.
> 
> Fixes: 5ea715289af6 ("ipv6: broadly use fib6_info_hold() helper")

Should be:

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")

> Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>

Reviewed-by: Ido Schimmel <idosch@nvidia.com>

      reply	other threads:[~2026-07-29 12:44 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 18:53 [PATCH net] ipv6: release fib6_null_entry on subtree failure Shuangpeng Bai
2026-07-29 12:44 ` Ido Schimmel [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260729124400.GA1365523@shredder \
    --to=idosch@nvidia.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=shuangpeng.kernel@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.