From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f169.google.com (mail-pl1-f169.google.com [209.85.214.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DFFDE31A56D for ; Sat, 15 Aug 2026 09:54:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786787686; cv=none; b=C/0FIhcks/CoA3vMdVXvij/vrxDsBlw6o9iTsUEuBGKcvSkr55iSgqxCOB6KDcglkd8cyqo70EhpRcZZcAG8FiC8myUztugKyzsDkrzurvq1CgraLTKOez2sxgLvfH2TrZ0EzMPVlGu6OCHKqlwEEi8U3o1x9VU/q2VTf6/UzX0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786787686; c=relaxed/simple; bh=M7iRHTBJPb2PRUhzJpwM2pWCP7DsDz6g+JsmfNbD8NM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=mtOc+DxDuEOSqya8aZBWkehrDkTGBw503h1V0U8pMlsbwFyfMFBjkO7Npz/tUZ/9yfGhBHyMtvLJ8h4OYrl8L/t4Ldqod/COw+AE0C5bmphMXxsCu8Gw+FRmH6DV2hS17aoKBl+GuVNb6QCfa07qMJGfsLTrvVPRWEKPv52RwfU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BWhtpDv5; arc=none smtp.client-ip=209.85.214.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BWhtpDv5" Received: by mail-pl1-f169.google.com with SMTP id d9443c01a7336-2ce98cb8165so18137535ad.1 for ; Sat, 15 Aug 2026 02:54:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786787684; x=1787392484; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:sender:from:to:cc:subject:date:message-id:reply-to :content-type; bh=3F6IAQ4pKsreYQprgJ/5sDlA3ah7ieVyFMiRIBIZuFw=; b=BWhtpDv55GzXL7G/r+wNpARgJVWNYb5teTfADde/7Hi2qHLIdg/BHtUa16MNJk+ZDj AiB5QshqVeOytky9RbxmH2Y+DvRul+6mN0WFoCkbA1aOPdYZu9kSeK0wc/qxXsftQb9L HvBjtIccTGWYYDBAfFogr1yqe2To5CkK6GNAdxk0+TUPfdBbekPXwCYL5I0xsQm04OB9 Kl6JMCvXKIBSKCNBY4jZrg0SK2+ePFwIKd/NarvTBov/D/LXvMqzZkimhpCaFZo9SfxE 11VOwDmtz0JC1gC3DpGAPkQgC8xGd0gV6sjY6PDI7ycN4fRxqYmN7YA+x4ojOpBieIaw 4W5g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786787684; x=1787392484; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:sender:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3F6IAQ4pKsreYQprgJ/5sDlA3ah7ieVyFMiRIBIZuFw=; b=XaNZ4WnXqoVYb0Q7noFbisYDoCgvODRNhi6RFnGqmAPtPJL4EoENNet1L4J/nQ8lZF KBzZqr1irI0npLq5t7zAEdnuidGFE72AWP30GENHk1nUF+EV5C06zlrcGQrEJIf9ZUzo zy/LmclWA/I2OsmS8e6OxbqRnNckKvhcWS6DZ6kvZCbdT8KI+d9cuEAvksbtS7UyqjH5 xg5gR9b9ZgbumOTx3zpO8Q86B/pFOzsEy0lj+xQcwgrlmDY6LQM+HRYzCTov6vgFr2J4 f8H69H5EXN0aISpXfw9Ac9Fz7KpGT2i+CkvXkB0kqoEwCRd2bP2KsN09eqQjM8XMeoH6 /fjQ== X-Forwarded-Encrypted: i=1; AHgh+RrvGqx/6vHwNfSWBX34a9F2s9fJZ+yuqmOEJg1ajMrGUV4FHwLNBSnbKZ+y4wJtTRTBwzAjLNAIoGRxd+Q=@vger.kernel.org X-Gm-Message-State: AOJu0Yxee7z9uv5t//g/pDnpzwFsD+ROoMBd271ww2jDTMF7xqwXw8qJ gHfaxRc0j92QMUjk49MZN/S6kHUbf/LfXTzQ6JixGXWenyULe+5sD1Ju X-Gm-Gg: AR+sD11moY7V+qg2VAfNuWI3fwD+AuBaHsd0C5TQjII88dhTlXqeKrrxKxHQoeQ+LWN 3U7Cg8W6k2DBTra5++WaBNhGlduibz0zy1Gj3nxk5uWIj2TAMSdoUyzAvmQG9r0Sk3iMhz7MeEc IbE6Otbk9zdc9PBK2RiKDhAbQ/k+xIo23DS+yL6HAr67hAqb5ANpw0qO/cGbW5G0dcC7JP/UeWJ uVPNJ06LeGgzcOvtGaUMpYYeifeLa1K/nWeUg3J2aprQkIbw2PSkcppSKCEYCMq3Jd8FYlvSPj1 nIzLMA93rdMj9YYoI5f/szhONSeYQ8n4XRTu3uhr+3dp3+hMfu21vv/HQw5lXbj86JMG5uIZua8 YQDNuUAuYb0Z/5oMF5BSI3r8hXFNPp/bB81qJAx3I7ZCjCPI4uvh2D3BpSWI0dKklXCMKq7uxui bhF9XRmR/GmpapoIoNsZu1aiHf3ZRNqkVEczqok0mDJ4mmVZskaTIR6/krxBn6C2IUmEMezSXED Fz9lDufjTpBDVc2GjELKmeZ6V4XiGM4OeslSA4Esxq0mm+yhQ== X-Received: by 2002:a17:902:ce83:b0:2ca:e496:5f19 with SMTP id d9443c01a7336-2d3b0043318mr99627235ad.19.1786787684016; Sat, 15 Aug 2026 02:54:44 -0700 (PDT) Received: from m-upc-A520M-HDV.flets-east.jp ([2400:2410:3f60:500:959f:bb81:fb2:a537]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d3ae7d16e8sm18107435ad.31.2026.08.15.02.54.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 15 Aug 2026 02:54:42 -0700 (PDT) Sender: Yuyang Huang From: Yuyang Huang To: Yuyang Huang Cc: "David S. Miller" , Amit Cohen , David Ahern , Eric Dumazet , Ido Schimmel , Jakub Kicinski , Paolo Abeni , Simon Horman , linux-kernel@vger.kernel.org, netdev@vger.kernel.org Subject: [PATCH net-next] ipv6: Serialize hardware flag notifications Date: Sat, 15 Aug 2026 18:54:36 +0900 Message-ID: <20260815095436.90534-1-sigefriedhyy@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit fib6_info_hw_flags_set() first performs a lockless check of fib6_node. It then allocates a notification skb with GFP_KERNEL, which can sleep. A concurrent route deletion can remove the route, set fib6_node to NULL, and emit RTM_DELROUTE while the allocation sleeps. When the thread wakes up, it can emit RTM_NEWROUTE for the already deleted route. This can cause userspace routing daemons to receive RTM_DELROUTE followed by RTM_NEWROUTE and incorrectly believe that the deleted route still exists in the kernel. Allocate the skb before taking tb6_lock, then recheck fib6_node while holding the lock. Keep the lock until RTM_NEWROUTE is published. If route deletion wins the race, the recheck sees NULL and drops the notification. Otherwise, deletion cannot remove the route until RTM_NEWROUTE has been published, preserving notification order. RTM_DELROUTE is sent by fib6_del_route() with tb6_lock held, so publishing RTM_NEWROUTE under the same lock is sufficient to guarantee ordering. rt6_fill_node() does not sleep in this path, and the notification uses GFP_ATOMIC, matching inet6_rt_notify() which already broadcasts under tb6_lock. The race was found by Sashiko during code review. Fixes: 907eea486888 ("net: ipv6: Emit notification when fib hardware flags are changed") Signed-off-by: Yuyang Huang --- net/ipv6/route.c | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/net/ipv6/route.c b/net/ipv6/route.c index 16dfac54a259..73db4f630dcc 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c @@ -6463,6 +6463,7 @@ void fib6_info_hw_flags_set(struct net *net, struct fib6_info *f6i, bool offload, bool trap, bool offload_failed) { u8 fib_notify_on_flag_change; + struct fib6_table *table; struct sk_buff *skb; int err; @@ -6491,22 +6492,33 @@ void fib6_info_hw_flags_set(struct net *net, struct fib6_info *f6i, if (!fib_notify_on_flag_change) return; + table = f6i->fib6_table; skb = nlmsg_new(rt6_nlmsg_size(f6i), GFP_KERNEL); if (!skb) { err = -ENOBUFS; goto errout; } + spin_lock_bh(&table->tb6_lock); + if (!rcu_dereference_protected(f6i->fib6_node, + lockdep_is_held(&table->tb6_lock))) { + spin_unlock_bh(&table->tb6_lock); + kfree_skb(skb); + return; + } + err = rt6_fill_node(net, skb, f6i, NULL, NULL, NULL, 0, RTM_NEWROUTE, 0, 0, 0, RT_DEL_REASON_UNSPEC); if (err < 0) { /* -EMSGSIZE implies BUG in rt6_nlmsg_size() */ WARN_ON(err == -EMSGSIZE); + spin_unlock_bh(&table->tb6_lock); kfree_skb(skb); goto errout; } - rtnl_notify(skb, net, 0, RTNLGRP_IPV6_ROUTE, NULL, GFP_KERNEL); + rtnl_notify(skb, net, 0, RTNLGRP_IPV6_ROUTE, NULL, GFP_ATOMIC); + spin_unlock_bh(&table->tb6_lock); return; errout: -- 2.43.0