From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@google.com
Subject: Re: [PATCH net 5/6] netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()
Date: Thu, 11 Apr 2024 12:03:43 +0200 [thread overview]
Message-ID: <Zhe1f1yfaFQDnLvM@calendula> (raw)
In-Reply-To: <20240404104334.1627-6-pablo@netfilter.org>
On Thu, Apr 04, 2024 at 12:43:33PM +0200, Pablo Neira Ayuso wrote:
> From: Ziyang Xuan <william.xuanziyang@huawei.com>
>
> nft_unregister_flowtable_type() within nf_flow_inet_module_exit() can
> concurrent with __nft_flowtable_type_get() within nf_tables_newflowtable().
> And thhere is not any protection when iterate over nf_tables_flowtables
> list in __nft_flowtable_type_get(). Therefore, there is pertential
> data-race of nf_tables_flowtables list entry.
>
> Use list_for_each_entry_rcu() to iterate over nf_tables_flowtables list
> in __nft_flowtable_type_get(), and use rcu_read_lock() in the caller
> nft_flowtable_type_get() to protect the entire type query process.
Applied to nf, thanks
next prev parent reply other threads:[~2024-04-11 10:03 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-04-04 10:43 [PATCH net 0/6] Netfilter fixes for net Pablo Neira Ayuso
2024-04-04 10:43 ` [PATCH net 1/6] netfilter: nf_tables: release batch on table validation from abort path Pablo Neira Ayuso
2024-04-04 16:50 ` patchwork-bot+netdevbpf
2024-04-04 10:43 ` [PATCH net 2/6] netfilter: nf_tables: release mutex after nft_gc_seq_end " Pablo Neira Ayuso
2024-04-04 10:43 ` [PATCH net 3/6] netfilter: nf_tables: flush pending destroy work before exit_net release Pablo Neira Ayuso
2024-04-04 10:43 ` [PATCH net 4/6] netfilter: nf_tables: reject new basechain after table flag update Pablo Neira Ayuso
2024-04-04 10:43 ` [PATCH net 5/6] netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get() Pablo Neira Ayuso
2024-04-11 10:03 ` Pablo Neira Ayuso [this message]
2024-04-04 10:43 ` [PATCH net 6/6] netfilter: nf_tables: discard table flag update with pending basechain deletion Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Zhe1f1yfaFQDnLvM@calendula \
--to=pablo@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.