From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 888014E430B; Thu, 17 Sep 2026 15:52:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660367; cv=none; b=UzqnLPAiroM5TE+7SNR9tI8uSAq35609vlUEi4lx6HuuTHkIx3YBtWPZqjp+YihJU2ZohTkPu0GcPSK75w0arvJuQynhKZYuCtB88qNiOVT9vNZ2/QpBXjXljkLpHh91G2DoRL7LciG5PMjD4ViW+1q0T2tqblCWjGnAKI/wKgU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660367; c=relaxed/simple; bh=gfCnQkZmHRCb4se7rOrBy4gwiOa0zS1Lz0dqhGngPOQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BlLMP4DSIH4k9Z2o2UeDdL9s2EOCCjwLgrB8QJ5H35puq/86zXTFsOvJFdRLUEufTyfxl1rOQbc3ELoXsRGCBPatwdHZY7eKXs0IDdlhM08zQb7Up2wIdC4cknqd0ComfV0V9D1JxECJjHcVFWrpITowhgSvqOoGgn2pFzPgKak= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=zeyG19Vb; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="zeyG19Vb" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9CB5A1F000FF; Thu, 17 Sep 2026 15:52:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660366; bh=/sTMMa3Pz94ORpJR6qZ9mSXbxm0aIkOrpmj5wADRxMM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=zeyG19VbhyMvG55cj29jvbpHaXPPKYmIw4PnlQ1Y2LVGPZWHkEh7NOQqG708DVG1T ozJggFlcQBttKZAriSGTJbMugdQBsdsJN4/qeutWuyRTQQQXt3qYKGlfZX2573sGIP IJwBs4YJtaDRBxRkE+p0+WagWjwUVrONddfgvBqE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Vega , Ido Schimmel , Zihan Xi , Petr Vorel , Jakub Kicinski Subject: [PATCH 7.2 567/733] ipv4: fib: bound automatic table ID allocation Date: Thu, 17 Sep 2026 16:14:35 +0100 Message-ID: <20260917151406.466776259@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Zihan Xi commit efdfb1e27a3328085b79540dfe781d537b576ea1 upstream. fib_empty_table() probes every table ID from 1 until it finds a free one. IPv4 tables are stored in a 256-bucket hash table, so a dense set of IDs makes each probe walk a growing hash chain while RTNL is held. Automatic table assignment ("ip rule ... table 0") is an IPv4-only legacy path. Bound the automatically allocated ID to 4096 so the RTNL hold stays bounded, without changing lookups of explicitly specified table IDs. This changes user-visible behavior. A table-0 rule previously received the lowest free ID in 1..RT_TABLE_MAX (0xFFFFFFFF). After this patch the search stops at 4096 and the rule add fails with ENOBUFS if that range is fully occupied. Explicit table IDs above 4096 remain usable. The automatic path is unused in practice: it is IPv4-only, not documented by ip-rule, uncovered by kernel selftests, and both NetworkManager and systemd refuse table 0. Fixes: b801f54917b7 ("[NET]: Increate RT_TABLE_MAX to 2^32") Cc: stable@vger.kernel.org Reported-by: Vega Suggested-by: Ido Schimmel Signed-off-by: Zihan Xi Reviewed-by: Ido Schimmel Reviewed-by: Petr Vorel Link: https://patch.msgid.link/6f2f2a7a136aee005512a2e1ac8ede62ac8c7bb6.1788258884.git.zihanx@nebusec.ai Signed-off-by: Jakub Kicinski Signed-off-by: Greg Kroah-Hartman --- net/ipv4/fib_rules.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) --- a/net/ipv4/fib_rules.c +++ b/net/ipv4/fib_rules.c @@ -214,6 +214,8 @@ INDIRECT_CALLABLE_SCOPE int fib4_rule_ma return 1; } +#define FIB_MAX_AUTO_TABLE_ID 4096 + static struct fib_table *fib_empty_table(struct net *net) { u32 id = 1; @@ -222,7 +224,7 @@ static struct fib_table *fib_empty_table if (!fib_get_table(net, id)) return fib_new_table(net, id); - if (id++ == RT_TABLE_MAX) + if (id++ == FIB_MAX_AUTO_TABLE_ID) break; } return NULL;