From: Simon Horman <horms@kernel.org>
To: Chengfeng Ye <nicoyip.dev@gmail.com>
Cc: David Howells <dhowells@redhat.com>,
Marc Dionne <marc.dionne@auristor.com>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
linux-afs@lists.infradead.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] rxrpc: Take write lock when publishing the initial RxGK key
Date: Thu, 3 Sep 2026 10:07:35 +0100 [thread overview]
Message-ID: <20260903090735.GJ396647@horms.kernel.org> (raw)
In-Reply-To: <20260824150220.216067-1-nicoyip.dev@gmail.com>
On Mon, Aug 24, 2026 at 11:02:20PM +0800, Chengfeng Ye wrote:
> rxgk_rekey() updates the transport-key ring under security_use_lock,
> and rxgk_get_key() takes a reference under the corresponding read
> lock. The initial publication in rxgk_init_connection_security()
> writes conn->rxgk.enctype and conn->rxgk.keys[] without the write
> lock.
>
> On a client connection, a second sendmsg can observe
> RXRPC_CONN_CLIENT through a lockless load of conn->state, skip
> rxrpc_init_client_conn_security(), and call rxgk_get_key() without
> ever acquiring security_lock. Because the initializer never took
> the write lock, the reader's read lock provides neither exclusion
> nor a matching acquire-release pair.
>
> Concurrent RxGK key consumers were observed in a two-sender
> workload. KCSAN reported:
>
> BUG: KCSAN: data-race in rxgk_get_key / rxgk_secure_packet
>
> write to 0xffff8aef4023c318 of 8 bytes by task 1968 on cpu 0:
> rxgk_secure_packet+0x46c/0x820
> rxrpc_send_data+0x562/0x1a20
> rxrpc_do_sendmsg+0x976/0xa80
> rxrpc_sendmsg+0x20f/0x2a0
>
> read to 0xffff8aef4023c318 of 8 bytes by task 1969 on cpu 1:
> rxgk_get_key+0x209/0x5e0
> rxgk_alloc_txbuf+0xa4/0x2a0
> rxrpc_send_data+0x8e2/0x1a20
> rxrpc_do_sendmsg+0x976/0xa80
> rxrpc_sendmsg+0x20f/0x2a0
>
> value changed: 0x7fffffffffffffff -> 0x7fffffffffffffee
>
> That report is on the key context's byte counter rather than the
> initial publication, but it shows that lookup and secured transmit
> already overlap on the same connection.
>
> Take security_use_lock for writing while publishing the initial
> enctype and transport key, matching the locking used when rekeying.
>
I think a Fixes tag is needed here, citing the patch where
this problem first manifested.
You can simply post it in response to this email.
But if you do re-post for some other reason note that
there should not be a blank line between the Fixes and
Signed-off-by tags (or between any other tags).
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
...
next prev parent reply other threads:[~2026-09-03 9:07 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 15:02 [PATCH net] rxrpc: Take write lock when publishing the initial RxGK key Chengfeng Ye
2026-09-03 9:07 ` Simon Horman [this message]
2026-09-03 15:04 ` Chengfeng Ye
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903090735.GJ396647@horms.kernel.org \
--to=horms@kernel.org \
--cc=davem@davemloft.net \
--cc=dhowells@redhat.com \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-afs@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=marc.dionne@auristor.com \
--cc=netdev@vger.kernel.org \
--cc=nicoyip.dev@gmail.com \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.