From: Ido Schimmel <idosch@nvidia.com>
To: Daehyeon Ko <4ncienth@gmail.com>
Cc: David Ahern <dsahern@kernel.org>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup
Date: Wed, 7 Oct 2026 19:46:35 +0300 [thread overview]
Message-ID: <20261007164635.GC1153540@shredder> (raw)
In-Reply-To: <20261004183639.3773498-3-4ncienth@gmail.com>
On Mon, Oct 05, 2026 at 03:36:39AM +0900, Daehyeon Ko wrote:
> addrconf_ifdown() clears the address hash before snapshotting the
> per-device address list. When the device is not unregistered, a
> concurrent ipv6_add_addr() can publish an address after the hash scan and
> before the list snapshot.
>
> The ifdown path then removes the address from the device list and drops
> its last reference while it is still linked in the hash. This triggers
> the WARN_ON() in inet6_ifa_finish_destroy().
>
> Remove each non-kept address from the hash before marking it dead,
> notifying listeners and removing it from the device list.
> hlist_del_init_rcu() is safe when the earlier hash scan already removed
> the address.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Doesn't matter in practice, but blaming commit 73a8bd74e261 ("ipv6:
Revert 'administrative down' address handling changes.") is more
appropriate.
> Cc: stable@vger.kernel.org
> Reported-by: Ido Schimmel <idosch@nvidia.com>
> Link: https://lore.kernel.org/r/20261004135117.GA206930@shredder
> Suggested-by: Ido Schimmel <idosch@nvidia.com>
> Assisted-by: LLM
> Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
> ---
> net/ipv6/addrconf.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
> index 426739abb07440..309c49b2141563 100644
> --- a/net/ipv6/addrconf.c
> +++ b/net/ipv6/addrconf.c
> @@ -3996,6 +3996,12 @@ static int addrconf_ifdown(struct net_device *dev, bool unregister)
> keep = keep_addr && (ifa->flags & IFA_F_PERMANENT) &&
> !addr_is_local(&ifa->addr);
>
> + if (!keep) {
There's already such a check below where address is removed from the
per-idev list. Why not move this there like I suggested in [1]?
[1] https://lore.kernel.org/all/20261004135117.GA206930@shredder/
> + spin_lock_bh(&net->ipv6.addrconf_hash_lock);
> + hlist_del_init_rcu(&ifa->addr_lst);
> + spin_unlock_bh(&net->ipv6.addrconf_hash_lock);
> + }
> +
> spin_lock_bh(&ifa->lock);
>
> if (keep) {
> --
> 2.55.0
>
next prev parent reply other threads:[~2026-10-07 16:46 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 18:36 [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
2026-10-05 18:39 ` netdev-bot+sashiko
2026-10-07 16:45 ` Ido Schimmel
2026-10-07 19:20 ` Ido Schimmel
2026-10-09 5:39 ` Daehyeon Ko
2026-10-07 16:46 ` Ido Schimmel
2026-10-04 18:36 ` [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup Daehyeon Ko
2026-10-07 16:46 ` Ido Schimmel [this message]
2026-10-05 23:57 ` [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Jakub Kicinski
2026-10-06 0:17 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007164635.GC1153540@shredder \
--to=idosch@nvidia.com \
--cc=4ncienth@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.