All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Wunderlich <sw@simonwunderlich.de>
To: netdev@vger.kernel.org
Cc: "David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	b.a.t.m.a.n@lists.open-mesh.org,
	Sven Eckelmann <sven@narfation.org>,
	Simon Wunderlich <sw@simonwunderlich.de>
Subject: [PATCH net-next 13/15] batman-adv: tt: transition NEW local entries only under lock
Date: Mon, 31 Aug 2026 15:51:15 +0200	[thread overview]
Message-ID: <20260831135117.574836-14-sw@simonwunderlich.de> (raw)
In-Reply-To: <20260831135117.574836-1-sw@simonwunderlich.de>

From: Sven Eckelmann <sven@narfation.org>

The batadv_tt_local_size_inc() must never be called for an entry which was
already removed from the list. Otherwise the removal from the hash cannot
correctly determine if the batadv_tt_local_size_dec() needs to be called or
not.

This assumption is broken by the use of rcu_read_lock() in
batadv_tt_local_transition_new() because it might still see entries in the
list which were already removed by a different context from the list. If it
then increments the size counter, nothing will reduce the counter again.
Simply because the removal (responsible for the decrement) already
happened.

Over the whole time, the actual hash list spinlock must be held when
transitioning NEW local entries to avoid list manipulations.

Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Simon Wunderlich <sw@simonwunderlich.de>
---
 net/batman-adv/translation-table.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
index 163f909623069..a870d9a97e329 100644
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -333,6 +333,10 @@ static void batadv_tt_local_size_mod(struct batadv_priv *bat_priv,
  *  given vid
  * @bat_priv: the bat priv with all the mesh interface information
  * @vid: the VLAN identifier
+ *
+ * It must only be called when removing the NEW flag of a
+ * batadv_tt_local_entry while it is still part of the bat_priv->tt.local_hash.
+ * It must therefore be checked under the specific list_locks[i].
  */
 static void batadv_tt_local_size_inc(struct batadv_priv *bat_priv,
 				     unsigned short vid)
@@ -3938,6 +3942,7 @@ void batadv_tt_free(struct batadv_priv *bat_priv)
  */
 static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
 {
+	spinlock_t *list_lock; /* protects write access to the hash lists */
 	struct batadv_hashtable *hash = bat_priv->tt.local_hash;
 	struct batadv_tt_common_entry *tt_common_entry;
 	struct hlist_head *head;
@@ -3948,10 +3953,10 @@ static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
 
 	for (i = 0; i < hash->size; i++) {
 		head = &hash->table[i];
+		list_lock = &hash->list_locks[i];
 
-		rcu_read_lock();
-		hlist_for_each_entry_rcu(tt_common_entry,
-					 head, hash_entry) {
+		spin_lock_bh(list_lock);
+		hlist_for_each_entry(tt_common_entry, head, hash_entry) {
 			bool cont = false;
 
 			scoped_guard(spinlock_bh, &tt_common_entry->flags_lock) {
@@ -3969,7 +3974,7 @@ static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
 			batadv_tt_local_size_inc(bat_priv,
 						 tt_common_entry->vid);
 		}
-		rcu_read_unlock();
+		spin_unlock_bh(list_lock);
 	}
 }
 
-- 
2.47.3


  parent reply	other threads:[~2026-08-31 13:51 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 13:51 [PATCH net-next 00/15] pull request for net-next: batman-adv 2026-08-31 Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 01/15] batman-adv: dat: fix printing of unknown 4addr subtype Simon Wunderlich
2026-09-01 17:03   ` Sven Eckelmann
2026-09-04 22:51   ` patchwork-bot+netdevbpf
2026-08-31 13:51 ` [PATCH net-next 02/15] batman-adv: drop direction in _batadv_is_ap_isolated kernel-doc Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 03/15] batman-adv: bat_v: fix bonding candidate selection Simon Wunderlich
     [not found]   ` <20260901135959.23F6C1F000E9@smtp.kernel.org>
2026-09-01 16:58     ` Sven Eckelmann
2026-09-01 17:10   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 04/15] batman-adv: clarify cut-off in batadv_v_neigh_is_sob kernel-doc Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 05/15] batman-adv: use more descriptive var names for is_similar_or_better Simon Wunderlich
2026-09-01 17:20   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 06/15] batman-adv: ensure u16 aligned mac address arrays on stack Simon Wunderlich
     [not found]   ` <20260901140000.035F51F000E9@smtp.kernel.org>
2026-09-01 16:59     ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 07/15] batman-adv: ensure u16 aligned mac address in structs Simon Wunderlich
2026-09-01 17:24   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 08/15] batman-adv: tt: remove only the entry which was looked up from the hash Simon Wunderlich
     [not found]   ` <20260901140001.59CD41F000E9@smtp.kernel.org>
2026-09-01 16:59     ` Sven Eckelmann
2026-09-01 18:11   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 09/15] batman-adv: tt: extract code handling a roam on add Simon Wunderlich
     [not found]   ` <20260901140002.533041F000E9@smtp.kernel.org>
2026-09-01 16:58     ` Sven Eckelmann
2026-09-01 18:14   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 10/15] batman-adv: tt: simplify NEW flag transition code Simon Wunderlich
2026-09-01 18:18   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 11/15] batman-adv: tt: drop unnecessary cleanup goto in helpers Simon Wunderlich
2026-08-31 13:51 ` [PATCH net-next 12/15] batman-adv: tt: use protected flag modifications Simon Wunderlich
     [not found]   ` <20260901140003.62B041F000E9@smtp.kernel.org>
2026-09-01 16:58     ` Sven Eckelmann
2026-09-01 19:21   ` Sven Eckelmann
2026-08-31 13:51 ` Simon Wunderlich [this message]
2026-09-01 19:31   ` [PATCH net-next 13/15] batman-adv: tt: transition NEW local entries only under lock Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 14/15] batman-adv: tt: don't uncount never committed clients on pending purge Simon Wunderlich
2026-09-01 19:33   ` Sven Eckelmann
2026-08-31 13:51 ` [PATCH net-next 15/15] batman-adv: tt: decrement count for committed client on local_remove Simon Wunderlich
2026-09-01 19:36   ` Sven Eckelmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831135117.574836-14-sw@simonwunderlich.de \
    --to=sw@simonwunderlich.de \
    --cc=b.a.t.m.a.n@lists.open-mesh.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sven@narfation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.