All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sven Eckelmann <sven@narfation.org>
To: sashiko-reviews@lists.linux.dev
Cc: sw@simonwunderlich.de, antonio@mandelbit.com,
	marek.lindner@mailbox.org, netdev@vger.kernel.org
Subject: Re: [PATCH net-next 08/15] batman-adv: tt: replace add_orig_entry goto in batadv_tt_global_add()
Date: Tue, 08 Sep 2026 11:22:33 +0200	[thread overview]
Message-ID: <2363912.iZASKD2KPV@ripper> (raw)
In-Reply-To: <20260908082701.B6CCD1F00A3A@smtp.kernel.org>

[-- Attachment #1: Type: text/plain, Size: 2625 bytes --]

On Tuesday, 8 September 2026 10:27:01 CEST sashiko-bot@kernel.org wrote:
[...]
> This commit refactors batadv_tt_global_add() by removing the add_orig_entry
> label and turning the flag merging and list purging logic into a more
> direct if/else structure.
> 
> > diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
> > index 67e4ade5ae997..760acc7be973e 100644
> > --- a/net/batman-adv/translation-table.c
> > +++ b/net/batman-adv/translation-table.c
> > @@ -2021,15 +2021,16 @@ static bool batadv_tt_global_add(struct batadv_priv *bat_priv,
> >  			if (batadv_tt_global_entry_has_orig(tt_global_entry,
> >  							    orig_node, NULL))
> >  				goto out_remove;
> > -			batadv_tt_global_del_orig_list(tt_global_entry);
> > -			goto add_orig_entry;
> > +
> > +			delete = true;
> > +		} else {
> > +			delete = batadv_tt_global_merge_flags(tt_global_entry, flags);
> >  		}
> >  
> > -		delete = batadv_tt_global_merge_flags(tt_global_entry, flags);
> >  		if (delete)
> >  			batadv_tt_global_del_orig_list(tt_global_entry);
> 
> [Severity: High]
> This is a pre-existing issue, but this patch preserves and refactors the
> vulnerable code structure without resolving an underlying race condition.
> 
> Could this lead to a Time-of-Check to Time-of-Use race that permanently
> drops a valid originator from the global translation table? 
> 
> For example, if two CPUs concurrently execute batadv_tt_global_add() for the
> same translation table entry:
> 
> CPU 0 (adding a temporary client):
> Evaluates global_flags without locking and sets delete = true.
> 
> CPU 1 (adding a non-temporary client):
> Merges its non-temporary flags, clears the TEMP flag, purges the list, and
> adds its non-temporary originator.
> 
> CPU 0 (resuming based on its stale delete snapshot):
> Incorrectly purges CPU 1's newly added non-temporary originator and adds
> its own temporary one.
> 
> Because the TEMP flag was cleared by CPU 1, the entry might never timeout or
> update correctly, potentially causing a permanent routing blackhole for the
> affected client.
> 
> A similar race appears to exist between two non-temporary additions. If CPU 1
> is preempted after batadv_tt_global_merge_flags() returns true, CPU 2 might
> return false from the merge and add its originator. When CPU 1 resumes, it
> would purge CPU 2's originator based on the stale delete boolean.
> 
> Is additional synchronization needed around the delete decision and the list
> purging to prevent these concurrent additions from stepping on each other?

Same as last time: https://www.open-mesh.org/issues/474

Regards,
	Sven

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

  parent reply	other threads:[~2026-09-08  9:22 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07  8:18 [PATCH net-next 00/15] pull request for net-next: batman-adv 2026-09-07 Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 01/15] batman-adv: tt: look up wifi state of incoming interface in helper Simon Wunderlich
2026-09-11  1:10   ` patchwork-bot+netdevbpf
2026-09-07  8:18 ` [PATCH net-next 02/15] batman-adv: tt: extract allocation of new local entries Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 03/15] batman-adv: tt: replace forward gotos in batadv_tt_local_add() Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 04/15] batman-adv: tt: extract refresh of existing local entries Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 05/15] batman-adv: tt: extract update of dynamic client flags Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 06/15] batman-adv: tt: extract allocation of new global entries Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 07/15] batman-adv: tt: extract merging of flags into existing " Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 08/15] batman-adv: tt: replace add_orig_entry goto in batadv_tt_global_add() Simon Wunderlich
     [not found]   ` <20260908082701.B6CCD1F00A3A@smtp.kernel.org>
2026-09-08  9:22     ` Sven Eckelmann [this message]
2026-09-07  8:18 ` [PATCH net-next 09/15] batman-adv: tt: extract removal of the superseded local entry Simon Wunderlich
2026-09-08 17:26   ` Sven Eckelmann
2026-09-07  8:18 ` [PATCH net-next 10/15] batman-adv: tt: extract marking of a removed " Simon Wunderlich
2026-09-08 17:26   ` Sven Eckelmann
2026-09-07  8:18 ` [PATCH net-next 11/15] batman-adv: tt: extract immediate purge of a " Simon Wunderlich
2026-09-08 17:26   ` Sven Eckelmann
2026-09-07  8:18 ` [PATCH net-next 12/15] batman-adv: tt: drop the cleanup label from batadv_tt_local_remove() Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 13/15] batman-adv: tt: clarify kernel doc for batadv_tt_local_set_pending_event() Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 14/15] batman-adv: bat_iv: fix ogm_neigh_is_sob parameters references Simon Wunderlich
2026-09-07  8:18 ` [PATCH net-next 15/15] batman-adv: correct batadv_hash_remove kdoc return type Simon Wunderlich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2363912.iZASKD2KPV@ripper \
    --to=sven@narfation.org \
    --cc=antonio@mandelbit.com \
    --cc=marek.lindner@mailbox.org \
    --cc=netdev@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sw@simonwunderlich.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.