From: Jamal Hadi Salim <jhs@mojatatu.com>
To: netdev@vger.kernel.org
Cc: Jamal Hadi Salim <jhs@mojatatu.com>,
stable@vger.kernel.org, Jiri Pirko <jiri@resnulli.us>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>, Vlad Buslov <vladbu@nvidia.com>,
Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>,
hybris <hybris@mojatatu.ai>,
sashiko-bot@kernel.org
Subject: [PATCH net 1/2] net/sched: act_api: reject duplicate actions in a batch
Date: Tue, 22 Sep 2026 07:50:54 -0400 [thread overview]
Message-ID: <QDISC-K1TH.v1.20260922072206@mojatatu.com> (raw)
tca_action_gd() builds actions[] with one tcf_action_get_1() per nested
TCA_ACT_TAB entry. Each successful lookup takes its own reference to the
resolved action, so repeated TCA_ACT_INDEX entries in one request yield
the same pointer in multiple slots.
For RTM_DELACTION, tcf_action_delete() then consumes two references per
slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A
duplicate therefore drives the refcount to zero mid-walk -- the delete
frees the action and removes its IDR slot -- and the next slot calls
tcf_action_put() on the freed action:
refcount_t: underflow; use-after-free.
WARNING: lib/refcount.c:87 at refcount_dec_not_one
refcount_dec_and_mutex_lock
__tcf_action_put
tca_action_gd
Three duplicate entries are enough. Reject a repeated action while a
delete batch is built, dropping the reference the extra lookup took, and
return -EINVAL. RTM_GETACTION balances its own references and keeps
accepting duplicate entries.
Conditions to recreate the bug:
tc actions add action gact index 100
tc actions delete action gact index 100 action gact index 100 \
action gact index 100
Fixes: 16af6067392c ("net: sched: implement reference counted action release")
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/act_api.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index e45a63be397c..a9323c42a69a 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -2026,7 +2026,7 @@ static int
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
u32 portid, int event, struct netlink_ext_ack *extack)
{
- int i, ret;
+ int i, j, ret;
struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
struct tc_action *act;
size_t attr_size = 0;
@@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
ret = PTR_ERR(act);
goto err;
}
+
+ /* A delete consumes two references per slot (tcf_action_put()
+ * and tcf_idr_delete_index()) but each entry takes one, so a
+ * repeated action would hit zero mid-walk. GET balances its
+ * own references and keeps accepting duplicates.
+ */
+ if (event == RTM_DELACTION) {
+ for (j = 0; j < i - 1; j++) {
+ if (actions[j] != act)
+ continue;
+
+ tcf_action_put(act);
+ NL_SET_ERR_MSG(extack,
+ "Duplicate TC action in a delete batch");
+ ret = -EINVAL;
+ goto err;
+ }
+ }
+
attr_size += tcf_action_fill_size(act);
actions[i - 1] = act;
}
--
2.43.0
WARNING: multiple messages have this Message-ID (diff)
From: Jamal Hadi Salim <jhs@mojatatu.com>
To: netdev@vger.kernel.org
Cc: Jamal Hadi Salim <jhs@mojatatu.com>,
stable@vger.kernel.org, Jiri Pirko <jiri@resnulli.us>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Victor Nogueira <victor@mojatatu.com>,
Vlad Buslov <vladbu@nvidia.com>,
Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>,
hybris <hybris@mojatatu.ai>,
sashiko-bot@kernel.org
Subject: [PATCH net 1/2 repost] net/sched: act_api: reject duplicate actions in a batch
Date: Fri, 25 Sep 2026 04:22:37 -0400 [thread overview]
Message-ID: <QDISC-K1TH.v1.20260922072206@mojatatu.com> (raw)
Message-ID: <20260925082237.xktTTrRQRmp_V8OKNBxFnnUlj6a452UO12AQPOXYlPc@z> (raw)
tca_action_gd() builds actions[] with one tcf_action_get_1() per nested
TCA_ACT_TAB entry. Each successful lookup takes its own reference to the
resolved action, so repeated TCA_ACT_INDEX entries in one request yield
the same pointer in multiple slots.
For RTM_DELACTION, tcf_action_delete() then consumes two references per
slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A
duplicate therefore drives the refcount to zero mid-walk -- the delete
frees the action and removes its IDR slot -- and the next slot calls
tcf_action_put() on the freed action:
refcount_t: underflow; use-after-free.
WARNING: lib/refcount.c:87 at refcount_dec_not_one
refcount_dec_and_mutex_lock
__tcf_action_put
tca_action_gd
Three duplicate entries are enough. Reject a repeated action while a
delete batch is built, dropping the reference the extra lookup took, and
return -EINVAL. RTM_GETACTION balances its own references and keeps
accepting duplicate entries.
Conditions to recreate the bug:
tc actions add action gact index 100
tc actions delete action gact index 100 action gact index 100 \
action gact index 100
Fixes: 16af6067392c ("net: sched: implement reference counted action release")
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Tested-by: hybris <hybris@mojatatu.ai>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/act_api.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index e45a63be397c..a9323c42a69a 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -2026,7 +2026,7 @@ static int
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
u32 portid, int event, struct netlink_ext_ack *extack)
{
- int i, ret;
+ int i, j, ret;
struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
struct tc_action *act;
size_t attr_size = 0;
@@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
ret = PTR_ERR(act);
goto err;
}
+
+ /* A delete consumes two references per slot (tcf_action_put()
+ * and tcf_idr_delete_index()) but each entry takes one, so a
+ * repeated action would hit zero mid-walk. GET balances its
+ * own references and keeps accepting duplicates.
+ */
+ if (event == RTM_DELACTION) {
+ for (j = 0; j < i - 1; j++) {
+ if (actions[j] != act)
+ continue;
+
+ tcf_action_put(act);
+ NL_SET_ERR_MSG(extack,
+ "Duplicate TC action in a delete batch");
+ ret = -EINVAL;
+ goto err;
+ }
+ }
+
attr_size += tcf_action_fill_size(act);
actions[i - 1] = act;
}
--
2.43.0
WARNING: multiple messages have this Message-ID (diff)
From: Jamal Hadi Salim <jhs@mojatatu.com>
To: netdev@vger.kernel.org
Cc: Jamal Hadi Salim <jhs@mojatatu.com>,
stable@vger.kernel.org, Jiri Pirko <jiri@resnulli.us>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Victor Nogueira <victor@mojatatu.com>,
Vlad Buslov <vladbu@nvidia.com>,
Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>,
hybris <hybris@mojatatu.ai>,
sashiko-bot@kernel.org
Subject: [PATCH net 1/2 repost2] net/sched: act_api: reject duplicate actions in a batch
Date: Sat, 3 Oct 2026 05:54:53 -0400 [thread overview]
Message-ID: <QDISC-K1TH.v1.20260922072206@mojatatu.com> (raw)
Message-ID: <20261003095453.4jiXbPK5mkXck0VOLiLu3sM9l-NGfDiZ4G96YKNDV-0@z> (raw)
tca_action_gd() builds actions[] with one tcf_action_get_1() per nested
TCA_ACT_TAB entry. Each successful lookup takes its own reference to the
resolved action, so repeated TCA_ACT_INDEX entries in one request yield
the same pointer in multiple slots.
For RTM_DELACTION, tcf_action_delete() then consumes two references per
slot: one in tcf_action_put() and one in tcf_idr_delete_index(). A
duplicate therefore drives the refcount to zero mid-walk -- the delete
frees the action and removes its IDR slot -- and the next slot calls
tcf_action_put() on the freed action:
refcount_t: underflow; use-after-free.
WARNING: lib/refcount.c:87 at refcount_dec_not_one
refcount_dec_and_mutex_lock
__tcf_action_put
tca_action_gd
Three duplicate entries are enough. Reject a repeated action while a
delete batch is built, dropping the reference the extra lookup took, and
return -EINVAL. RTM_GETACTION balances its own references and keeps
accepting duplicate entries.
Conditions to recreate the bug:
tc actions add action gact index 100
tc actions delete action gact index 100 action gact index 100 \
action gact index 100
Fixes: 16af6067392c ("net: sched: implement reference counted action release")
Reported-by: Sashiko (gemini) <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260824153903.4143642-1-victor@mojatatu.com
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
---
net/sched/act_api.c | 21 ++++++++++++++++++++-
1 file changed, 20 insertions(+), 1 deletion(-)
diff --git a/net/sched/act_api.c b/net/sched/act_api.c
index e45a63be397c..a9323c42a69a 100644
--- a/net/sched/act_api.c
+++ b/net/sched/act_api.c
@@ -2026,7 +2026,7 @@ static int
tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
u32 portid, int event, struct netlink_ext_ack *extack)
{
- int i, ret;
+ int i, j, ret;
struct nlattr *tb[TCA_ACT_MAX_PRIO + 1];
struct tc_action *act;
size_t attr_size = 0;
@@ -2051,6 +2051,25 @@ tca_action_gd(struct net *net, struct nlattr *nla, struct nlmsghdr *n,
ret = PTR_ERR(act);
goto err;
}
+
+ /* A delete consumes two references per slot (tcf_action_put()
+ * and tcf_idr_delete_index()) but each entry takes one, so a
+ * repeated action would hit zero mid-walk. GET balances its
+ * own references and keeps accepting duplicates.
+ */
+ if (event == RTM_DELACTION) {
+ for (j = 0; j < i - 1; j++) {
+ if (actions[j] != act)
+ continue;
+
+ tcf_action_put(act);
+ NL_SET_ERR_MSG(extack,
+ "Duplicate TC action in a delete batch");
+ ret = -EINVAL;
+ goto err;
+ }
+ }
+
attr_size += tcf_action_fill_size(act);
actions[i - 1] = act;
}
--
2.43.0
next reply other threads:[~2026-09-22 11:50 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 11:50 Jamal Hadi Salim [this message]
2026-10-03 9:54 ` [PATCH net 1/2 repost2] net/sched: act_api: reject duplicate actions in a batch Jamal Hadi Salim
2026-09-25 8:22 ` [PATCH net 1/2 repost] " Jamal Hadi Salim
2026-09-24 17:29 ` [PATCH net 1/2] " Jakub Kicinski
-- strict thread matches above, loose matches on Subject: below --
2026-09-22 16:33 [PATCH net 2/2] selftests: tc-testing: add duplicate action delete batch test Jamal Hadi Salim
2026-10-03 9:54 ` [PATCH net 2/2 repost2] " Jamal Hadi Salim
2026-09-25 8:22 ` [PATCH net 2/2 repost] " Jamal Hadi Salim
2026-09-24 17:32 ` [PATCH net 2/2] " Jakub Kicinski
2026-09-24 20:09 ` Jamal Hadi Salim
2026-09-24 20:42 ` Jakub Kicinski
2026-09-25 8:15 ` Jamal Hadi Salim
2026-09-28 23:40 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=QDISC-K1TH.v1.20260922072206@mojatatu.com \
--to=jhs@mojatatu.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=hybris@mojatatu.ai \
--cc=jiri@resnulli.us \
--cc=kuba@kernel.org \
--cc=marcelo.leitner@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sashiko-bot@kernel.org \
--cc=stable@vger.kernel.org \
--cc=vladbu@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.