From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f178.google.com (mail-yw1-f178.google.com [209.85.128.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 337D636EA93 for ; Mon, 24 Aug 2026 15:21:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787584867; cv=none; b=vBCPOW1F2gn2R3lBfcwmoK1dOUJLZHsXPhdGDYlG/SPo5ITYJ3pu7XwTVMRnU8rRrWolTuyAmwgN3Vencol4WbupxCUNlFyL+OoFb76NE/xiAFGLqjeMOb6a35LIt3mqpd2F++AOgEhD4UFYNdGY2AdvHHv5UttwRtl9IJdwvZA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787584867; c=relaxed/simple; bh=XY2OgZaePqMnmpH5RREj5/3sAFhLh/26g3/Ol4N3ewo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=aoVgjJ7U5hfq/vxFpXUaSZsuRBqODQicOWhIdG2lj3HqFoY2E1Kl7ap3VqVe3dL4G5TcCKCv+6W7seCkF2DRx3jCvSA1Jk5h4KBk8MOA2xsiWZXCnrES39HVAznHpJFP6Qr0AoCY4FeqLhMhFCqCrbQWCCgmx+cWvwZz9rAGFqI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RALPA1WH; arc=none smtp.client-ip=209.85.128.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RALPA1WH" Received: by mail-yw1-f178.google.com with SMTP id 00721157ae682-836c4d3fa28so2007327b3.0 for ; Mon, 24 Aug 2026 08:21:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787584865; x=1788189665; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=d5uQFclyHynCG/0FLEAf23P/Cd+g9q80jm8OGZqPvec=; b=RALPA1WHSXLP1JkVHUcJDsei1iEPqgWD0iiFuxtwm4WM7nrvQXlWkNENjFaObGAzSU r9McLzOd33bgGf5Uc2yr1VeqDSrKWLl/zluKCrSCZe9P5vddqgYi7nr9PvUnE94oI1et 1XF8IGUEnIM8vhD3GOXE3/B/Bl/Q6XTMN2f1/cUvATabIkVV3Wjd7XVdiPfqukfUOB4w lTHL5V+mYlFz5a2Ci6vJmCIXsAq6TBdk6y4CEMhk80TMsMRSXJ4GmUGxtI6skml9jjG5 1s7J7nHMoGC2hDnntkL0h3EpCQ9oytzOU9JL+TqUyxmTs9aRTb/fmsOZTf99Lh0j0tzb MzTA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787584865; x=1788189665; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d5uQFclyHynCG/0FLEAf23P/Cd+g9q80jm8OGZqPvec=; b=YfRCixqH/gslb85ZAoh+qWoggyhfao6b+bvtKpABwAnvXpW2/N7clBi/3XXzbi9T8n FMcoQaV7x5rGyuJfvDe+O9j5QUYvvNwlbn8P/EitCMVBcxhtOf7/IjM0MTeMrJUuoD+a k9ILJwPpO+A4E7NGE8tr6h2Iq9KB3vQE2SrZ1kecI3aHZ3I6qaSxi2G9CcRlG2PyevBn ru47BFLoyUxSjo6BfwVve00siTh7FrUaDA0Hlo90RUD1PPDSHbW0Jd8sunwH9UUGHJJ8 GWdKMVhQbJUhgMIhRGI2LfNLzDhcpfOxhQWLwTDeM0dDZGLwSrjaTQQ3piC4xO0q73tZ B/rw== X-Forwarded-Encrypted: i=1; AHgh+Rq9SQf1bk4B6uvsQmy1AKn27x4xrQJtPBbKtmnrzWOYyRlm6s/U1mrgrZdhdQNPfZyHZvuxwhTJlQQEguQ=@vger.kernel.org X-Gm-Message-State: AFuF++mwSMn1pcWpW6YEJ+5NvVjjnvvN07BLD2jwaUXxyZj+sU06Q82F og03MLcLfsjsE0lXlEh1QvwQHIeBp2R/3BX3VSukOoDkCl3hvBS5DZrHPPUiFa5kYtSdaA== X-Gm-Gg: AR+sD10XAudkJu5ifPH34DM+CHfG+gyPBf46KvQXsy22Xn2W89ULgoc1/oUuklZnbCE FUhVTEIGWa2OC6ruBT21ZUSgtcwb/LFQUSTrddnPLKv+xo4X4O0NFWqohTfHd+iWJGLlyRr0X05 4j/FdosEOr12GE4D7uNvwQYBvaO2d3vYmCzCZv4WTYT3UVDq0JIBlSooAwi/oMC3Mmkj3TLsJba IFXW1T0DulOi4mNG+PWuZKYSf1CZHuQkPW/7oqwA3d4LoRthZycd7qXlX4XKOIgahIxNXfvxiqJ VX4KcaW2kI3WepXVJSu1MmTLqGR1XGPIuQZBoEPfpCXKZMEW3Yvk+Vk2gLmSgte2AQL3CX2aWDM oojxC35GAGmrpL1bUMld8VjvAzuHpJsVWzZ/XVmBWfQ50GB8IFn70Sw4vmY706QUI0w3MVfQAth zSi0tMqN2jhu+sHuAt/+j+jCr3P3h+7BVBPVt4xYbmaj6RzwpnjphVYFGOgyQyr0DRO2/eV6Shm PWzfVAVjmBzurVYL1a1ztBea3nGU47ioMCu9oaIESuPz/iCcKBeXlMRrXng4Qzm5g== X-Received: by 2002:a05:690c:4f82:10b0:853:bc96:d834 with SMTP id 00721157ae682-853bc96ea4emr10826257b3.2.1787584864959; Mon, 24 Aug 2026 08:21:04 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 00721157ae682-84cacac4e25sm35572937b3.47.2026.08.24.08.21.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 08:21:04 -0700 (PDT) From: Chengfeng Ye To: Steffen Klassert , Herbert Xu , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Florian Westphal Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH net] xfrm: retry inexact policy lookup after node reinsertion Date: Mon, 24 Aug 2026 23:20:57 +0800 Message-ID: <20260824152057.216329-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit When a newly inserted inexact policy covers multiple existing nodes, xfrm_policy_inexact_node_merge() removes each policy from the old node with hlist_del_rcu(). xfrm_policy_inexact_list_reinsert() then immediately adds the same bydst node to another hlist. hlist_del_rcu() leaves ->next intact for readers already at the removed entry, but the add overwrites it before an RCU grace period. This permits the following interleaving: CPU 0 CPU 1 ----- ----- reach policy P in the old hlist delete P from the old hlist add P to the new hlist follow P->next into the new hlist The lookup can then skip a matching policy and make an incorrect IPsec decision. During concurrent policy insertion and route lookup, KCSAN reported: BUG: KCSAN: data-race in __xfrm_policy_link / xfrm_lookup_with_ifid write to ... by task 92 on cpu 0: __xfrm_policy_link xfrm_policy_insert xfrm_add_policy read to ... by task 91 on cpu 1: xfrm_lookup_with_ifid xfrm_lookup_route ip_route_output_flow The per-bin sequence counter already brackets inexact tree changes, including node merges. Snapshot it before candidate discovery and retry after evaluating all candidate lists if it changed. This rejects results from any traversal overlapping reinsertion while leaving stable lookup order and locking unchanged. Fixes: 9cf545ebd591 ("xfrm: policy: store inexact policies in a tree ordered by destination address") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/xfrm/xfrm_policy.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c index 932a313b9460..5d4e863863df 100644 --- a/net/xfrm/xfrm_policy.c +++ b/net/xfrm/xfrm_policy.c @@ -2157,6 +2157,7 @@ static struct xfrm_policy *xfrm_policy_lookup_bytype(struct net *net, u8 type, struct xfrm_pol_inexact_bin *bin; struct xfrm_policy *pol, *ret; struct hlist_head *chain; + unsigned int inexact_sequence; unsigned int sequence; int err; @@ -2191,12 +2192,18 @@ static struct xfrm_policy *xfrm_policy_lookup_bytype(struct net *net, u8 type, goto skip_inexact; bin = xfrm_policy_inexact_lookup_rcu(net, type, family, dir, if_id); - if (!bin || !xfrm_policy_find_inexact_candidates(&cand, bin, saddr, - daddr)) + if (!bin) + goto skip_inexact; + + inexact_sequence = read_seqcount_begin(&bin->count); + if (!xfrm_policy_find_inexact_candidates(&cand, bin, saddr, daddr)) goto skip_inexact; pol = xfrm_policy_eval_candidates(&cand, ret, fl, type, family, if_id); + if (read_seqcount_retry(&bin->count, inexact_sequence)) + goto retry; + if (pol) { ret = pol; if (IS_ERR(pol)) -- 2.43.0