From: Kuniyuki Iwashima <kuniyu@google.com>
To: David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>,
Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Kuniyuki Iwashima <kuniyu@google.com>,
Kuniyuki Iwashima <kuni1840@gmail.com>,
netdev@vger.kernel.org
Subject: [PATCH v1 net-next] ipv6: Remove FIB6_EXCEPTION_BUCKET_FLUSHED.
Date: Sat, 26 Sep 2026 03:33:52 +0000 [thread overview]
Message-ID: <20260926033355.3295550-1-kuniyu@google.com> (raw)
The FIB6_EXCEPTION_BUCKET_FLUSHED logic has been dead since added.
Commit 0346ec2f080b ("ipv6: Prevent rt6_insert_exception() for
dying fib6_info.") restored the original race protection in
rt6_insert_exception() by reusing fib6_info.fib6_destroying.
The flag now prevents two races for per-cpu and exception routes.
Let's remove FIB6_EXCEPTION_BUCKET_FLUSHED and set fib6_destroying
in fib6_purge_rt().
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
---
net/ipv6/ip6_fib.c | 14 +++++++-------
net/ipv6/route.c | 45 ---------------------------------------------
2 files changed, 7 insertions(+), 52 deletions(-)
diff --git a/net/ipv6/ip6_fib.c b/net/ipv6/ip6_fib.c
index 9ff761962b45..0dc6ebee6e56 100644
--- a/net/ipv6/ip6_fib.c
+++ b/net/ipv6/ip6_fib.c
@@ -1019,12 +1019,6 @@ static int fib6_nh_drop_pcpu_from(struct fib6_nh *nh, void *_arg)
static void fib6_drop_pcpu_from(struct fib6_info *f6i)
{
- /* Make sure rt6_make_pcpu_route() wont add other percpu routes
- * while we are cleaning them here.
- */
- f6i->fib6_destroying = 1;
- mb(); /* paired with the cmpxchg() in rt6_make_pcpu_route() */
-
if (f6i->nh) {
rcu_read_lock();
nexthop_for_each_fib6_nh(f6i->nh, fib6_nh_drop_pcpu_from, f6i);
@@ -1042,7 +1036,13 @@ static void fib6_purge_rt(struct fib6_info *rt, struct fib6_node *fn,
{
struct fib6_table *table = rt->fib6_table;
- /* Flush all cached dst in exception table */
+ /* Make sure rt6_make_pcpu_route() / rt6_insert_exception()
+ * will not add other percpu / exception routes after cleaning
+ * them up in __fib6_drop_pcpu_from() / rt6_flush_exceptions().
+ */
+ rt->fib6_destroying = 1;
+ mb(); /* paired with the cmpxchg() in rt6_make_pcpu_route() */
+
fib6_drop_pcpu_from(rt);
rt6_flush_exceptions(rt);
diff --git a/net/ipv6/route.c b/net/ipv6/route.c
index 475ced827ec5..a76869ff87cd 100644
--- a/net/ipv6/route.c
+++ b/net/ipv6/route.c
@@ -1663,13 +1663,6 @@ static unsigned int fib6_mtu(const struct fib6_result *res)
return mtu - lwtunnel_headroom(nh->fib_nh_lws, mtu);
}
-#define FIB6_EXCEPTION_BUCKET_FLUSHED 0x1UL
-
-/* used when the flushed bit is not relevant, only access to the bucket
- * (ie., all bucket users except rt6_insert_exception);
- *
- * called under rcu lock; sometimes called with rt6_exception_lock held
- */
static
struct rt6_exception_bucket *fib6_nh_get_excptn_bucket(const struct fib6_nh *nh,
spinlock_t *lock)
@@ -1682,40 +1675,9 @@ struct rt6_exception_bucket *fib6_nh_get_excptn_bucket(const struct fib6_nh *nh,
else
bucket = rcu_dereference(nh->rt6i_exception_bucket);
- /* remove bucket flushed bit if set */
- if (bucket) {
- unsigned long p = (unsigned long)bucket;
-
- p &= ~FIB6_EXCEPTION_BUCKET_FLUSHED;
- bucket = (struct rt6_exception_bucket *)p;
- }
-
return bucket;
}
-static bool fib6_nh_excptn_bucket_flushed(struct rt6_exception_bucket *bucket)
-{
- unsigned long p = (unsigned long)bucket;
-
- return !!(p & FIB6_EXCEPTION_BUCKET_FLUSHED);
-}
-
-/* called with rt6_exception_lock held */
-static void fib6_nh_excptn_bucket_set_flushed(struct fib6_nh *nh,
- spinlock_t *lock)
-{
- struct rt6_exception_bucket *bucket;
- unsigned long p;
-
- bucket = rcu_dereference_protected(nh->rt6i_exception_bucket,
- lockdep_is_held(lock));
-
- p = (unsigned long)bucket;
- p |= FIB6_EXCEPTION_BUCKET_FLUSHED;
- bucket = (struct rt6_exception_bucket *)p;
- rcu_assign_pointer(nh->rt6i_exception_bucket, bucket);
-}
-
static int rt6_insert_exception(struct rt6_info *nrt,
const struct fib6_result *res)
{
@@ -1745,9 +1707,6 @@ static int rt6_insert_exception(struct rt6_info *nrt,
goto out;
}
rcu_assign_pointer(nh->rt6i_exception_bucket, bucket);
- } else if (fib6_nh_excptn_bucket_flushed(bucket)) {
- err = -EINVAL;
- goto out;
}
#ifdef CONFIG_IPV6_SUBTREES
@@ -1818,10 +1777,6 @@ static void fib6_nh_flush_exceptions(struct fib6_nh *nh, struct fib6_info *from)
if (!bucket)
goto out;
- /* Prevent rt6_insert_exception() to recreate the bucket list */
- if (!from)
- fib6_nh_excptn_bucket_set_flushed(nh, &rt6_exception_lock);
-
for (i = 0; i < FIB6_EXCEPTION_BUCKET_SIZE; i++) {
hlist_for_each_entry_safe(rt6_ex, tmp, &bucket->chain, hlist) {
if (!from ||
--
2.56.0.rc1.315.gc6ed9934b7-goog
next reply other threads:[~2026-09-26 3:33 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 3:33 Kuniyuki Iwashima [this message]
2026-09-28 6:27 ` [PATCH v1 net-next] ipv6: Remove FIB6_EXCEPTION_BUCKET_FLUSHED Ido Schimmel
2026-09-29 2:40 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926033355.3295550-1-kuniyu@google.com \
--to=kuniyu@google.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=kuni1840@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox