From: Sven Eckelmann <sven@narfation.org>
To: b.a.t.m.a.n@lists.open-mesh.org
Cc: Sven Eckelmann <sven@narfation.org>
Subject: [PATCH batadv v5 06/20] batman-adv: tt: transition NEW local entries only under lock
Date: Sat, 29 Aug 2026 08:18:17 +0200 [thread overview]
Message-ID: <20260829-tt-fixes-v5-6-88fce8fd683d@narfation.org> (raw)
In-Reply-To: <20260829-tt-fixes-v5-0-88fce8fd683d@narfation.org>
The batadv_tt_local_size_inc() must never be called for an entry which was
already removed from the list. Otherwise the removal from the hash cannot
correctly determine if the batadv_tt_local_size_dec() needs to be called or
not.
This assumption is broken by the use of rcu_read_lock() in
batadv_tt_local_transition_new() because it might still see entries in the
list which were already removed by a different context from the list. If it
then increments the size counter, nothing will reduce the counter again.
Simply because the removal (responsible for the decrement) already
happened.
Over the whole time, the actual hash list spinlock must be held when
transitioning NEW local entries to avoid list manipulations.
Signed-off-by: Sven Eckelmann <sven@narfation.org>
---
net/batman-adv/translation-table.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/net/batman-adv/translation-table.c b/net/batman-adv/translation-table.c
index 0513f899..431d1b7f 100644
--- a/net/batman-adv/translation-table.c
+++ b/net/batman-adv/translation-table.c
@@ -382,6 +382,10 @@ static void batadv_tt_local_size_mod(struct batadv_priv *bat_priv,
* given vid
* @bat_priv: the bat priv with all the mesh interface information
* @vid: the VLAN identifier
+ *
+ * It must only be called when removing the NEW flag of a
+ * batadv_tt_local_entry while it is still part of the bat_priv->tt.local_hash.
+ * It must therefore be checked under the specific list_locks[i].
*/
static void batadv_tt_local_size_inc(struct batadv_priv *bat_priv,
unsigned short vid)
@@ -3989,6 +3993,7 @@ void batadv_tt_free(struct batadv_priv *bat_priv)
*/
static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
{
+ spinlock_t *list_lock; /* protects write access to the hash lists */
struct batadv_hashtable *hash = bat_priv->tt.local_hash;
struct batadv_tt_common_entry *tt_common_entry;
struct hlist_head *head;
@@ -3999,10 +4004,10 @@ static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
for (i = 0; i < hash->size; i++) {
head = &hash->table[i];
+ list_lock = &hash->list_locks[i];
- rcu_read_lock();
- hlist_for_each_entry_rcu(tt_common_entry,
- head, hash_entry) {
+ spin_lock_bh(list_lock);
+ hlist_for_each_entry(tt_common_entry, head, hash_entry) {
bool cont = false;
scoped_guard(spinlock_bh, &tt_common_entry->flags_lock) {
@@ -4020,7 +4025,7 @@ static void batadv_tt_local_transition_new(struct batadv_priv *bat_priv)
batadv_tt_local_size_inc(bat_priv,
tt_common_entry->vid);
}
- rcu_read_unlock();
+ spin_unlock_bh(list_lock);
}
}
--
2.47.3
next prev parent reply other threads:[~2026-08-29 6:22 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-29 6:18 [PATCH batadv v5 00/20] batman-adv: tt: atomic sashiko fixes Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 01/20] batman-adv: tt: remove only the entry which was looked up from the hash Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 02/20] batman-adv: tt: extract code handling a roam on add Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 03/20] batman-adv: tt: simplify NEW flag transition code Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 04/20] batman-adv: tt: drop unnecessary cleanup goto in helpers Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 05/20] batman-adv: tt: use protected flag modifications Sven Eckelmann
2026-08-29 6:18 ` Sven Eckelmann [this message]
2026-08-29 6:18 ` [PATCH batadv v5 07/20] batman-adv: tt: don't uncount never committed clients on pending purge Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 08/20] batman-adv: tt: decrement count for committed client on local_remove Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 09/20] batman-adv: tt: look up wifi state of incoming interface in helper Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 10/20] batman-adv: tt: extract allocation of new local entries Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 11/20] batman-adv: tt: replace forward gotos in batadv_tt_local_add() Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 12/20] batman-adv: tt: extract refresh of existing local entries Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 13/20] batman-adv: tt: extract update of dynamic client flags Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 14/20] batman-adv: tt: extract allocation of new global entries Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 15/20] batman-adv: tt: extract merging of flags into existing " Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 16/20] batman-adv: tt: replace add_orig_entry goto in batadv_tt_global_add() Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 17/20] batman-adv: tt: extract removal of the superseded local entry Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 18/20] batman-adv: tt: extract marking of a removed " Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 19/20] batman-adv: tt: extract immediate purge of a " Sven Eckelmann
2026-08-29 6:18 ` [PATCH batadv v5 20/20] batman-adv: tt: drop the cleanup label from batadv_tt_local_remove() Sven Eckelmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260829-tt-fixes-v5-6-88fce8fd683d@narfation.org \
--to=sven@narfation.org \
--cc=b.a.t.m.a.n@lists.open-mesh.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox