BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jamal Hadi Salim" <jhs@mojatatu.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 1/2] net/sched: act_gate: reject oversized dumps instead of wrapping them
Date: Thu, 08 Oct 2026 10:29:45 +0000	[thread overview]
Message-ID: <sashiko-outbox-164016@kernel.org> (raw)
In-Reply-To: <QDISC-H19Z.v2.20261007062551-2@mojatatu.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] net/sched: action leaks in IDR when tcf_add_notify fails
--

commit c1aaa71f5e62d0438d19f3c77432158d3dd8ca67
Author: Jamal Hadi Salim <jhs@mojatatu.com>

net/sched: act_gate: reject oversized dumps instead of wrapping them

This patch limits oversized action dumps by closing wrap-capable nests with
nla_nest_end_safe(). It prevents structural corruption of Netlink messages
by failing with -EMSGSIZE instead of writing a wrapped length above U16_MAX.

Link: https://lore.kernel.org/netdev/QDISC-H19Z.v1.20261001053234@mojatatu.com/
Link: https://lore.kernel.org/netdev/179111893181.434549.13449660670267048994@kernel.org/

> diff --git a/net/sched/act_api.c b/net/sched/act_api.c
> index 6e48b4bc2d75d..747d91ae6446a 100644
> --- a/net/sched/act_api.c
> +++ b/net/sched/act_api.c
[ ... ]
> @@ -1279,7 +1280,9 @@ int tcf_action_dump(struct sk_buff *skb, struct tc_action *actions[],
>  			tcf_action_dump_1(skb, a, bind, ref);
>  		if (err < 0)
>  			goto errout;
> -		nla_nest_end(skb, nest);
> +		err = nla_nest_end_safe(skb, nest);
> +		if (err < 0)
> +			goto errout;
>  	}
>  
>  	return 0;

[Severity: Medium]
If tcf_add_notify() fails due to the new -EMSGSIZE limit introduced here
for oversized dumps, tcf_action_add() propagates the error to its caller.

However, in tcf_action_add(), tca_put_bound_many() explicitly skips
cleaning up actions where init_res[i] == ACT_P_CREATED:

	ret = tcf_add_notify(net, n, actions, portid, attr_size, extack);

	/* only put bound actions */
	tca_put_bound_many(actions, init_res);

	return ret;

This appears to leave the newly created actions fully instantiated in the IDR
with an active reference, while userspace receives an error and assumes the
creation failed.

Does this regression cause ACT_P_CREATED actions to leak in the IDR?

The commit message acknowledges this serialization failure on the action-add
side, but leaves the necessary follow-up fix out of this patch series. Could
this state inconsistency be triggered by userspace to leak actions before
the follow-up patch is merged?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/QDISC-H19Z.v2.20261007062551@mojatatu.com?part=1

      reply	other threads:[~2026-10-08 10:29 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <QDISC-H19Z.v2.20261007062551@mojatatu.com>
2026-10-07 10:29 ` [PATCH net-next 1/2] net/sched: act_gate: reject oversized dumps instead of wrapping them Jamal Hadi Salim
2026-10-08 10:29   ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-164016@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=jhs@mojatatu.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox