Netdev List
 help / color / mirror / Atom feed
From: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>
To: Eric Dumazet <edumazet@google.com>
Cc: "David S . Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	Ido Schimmel <idosch@nvidia.com>,
	Kuniyuki Iwashima <kuniyu@google.com>,
	Artem Lytkin <iprintercanon@gmail.com>,
	netdev@vger.kernel.org, eric.dumazet@gmail.com
Subject: Re: [PATCH net-next 8/9] sit: convert configuration to RCU protection
Date: Mon, 7 Sep 2026 16:32:54 +0200	[thread overview]
Message-ID: <ap7LFmE1Ykohf-eM@lore-desk> (raw)
In-Reply-To: <20260907075846.2913645-9-edumazet@google.com>

[-- Attachment #1: Type: text/plain, Size: 21008 bytes --]

> Now that SIT parameters are dynamically allocated, convert
> tunnel->sit_parms to an RCU-protected pointer.
> 
> Updates in ipip6_tunnel_update() allocate a new parameter block,
> publish it using rcu_assign_pointer(), and free the old one
> via kfree_rcu().
> 
> We only need to unlink and re-link the tunnel in the hash table
> if either saddr or daddr changed. When neither address changes,
> the unhash/re-hash and synchronize_net() can be completely skipped.
> 
> Readers in ipip6_tunnel_lookup(), ipip6_tunnel_xmit(), ipip6_err(),
> and ipip6_rcv() now safely dereference tunnel->sit_parms under RCU.

I think this patch is fine, I am just wondering if we can use more generic name
with respect to 'sit_parms' since I guess we have the same issue for IPIP and
IP6IP6 tunnels. Do you prefer to have dedicated pointers for them?

Acked-by: Lorenzo Bianconi <lorenzo.bianconi@oss.qualcomm.com>

Regards,
Lorenzo

> 
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> ---
>  include/net/ip_tunnels.h |   3 +-
>  net/ipv6/sit.c           | 245 +++++++++++++++++++++++++--------------
>  2 files changed, 157 insertions(+), 91 deletions(-)
> 
> diff --git a/include/net/ip_tunnels.h b/include/net/ip_tunnels.h
> index f464c4480edaf35f9ace1c5081c564ce51fed636..be4cc10f88ed64114cebac7f2e01bea21f5419da 100644
> --- a/include/net/ip_tunnels.h
> +++ b/include/net/ip_tunnels.h
> @@ -149,6 +149,7 @@ struct ip_tunnel_parm_kern {
>  	__be32			o_key;
>  	int			link;
>  	struct iphdr		iph;
> +	struct rcu_head		rcu;
>  };
>  
>  struct ip_tunnel {
> @@ -190,7 +191,7 @@ struct ip_tunnel {
>  #endif
>  	struct ip_tunnel_prl_entry __rcu *prl;	/* potential router list */
>  	unsigned int		prl_count;	/* # of entries in PRL */
> -	struct ip_tunnel_parm_kern *sit_parms;
> +	struct ip_tunnel_parm_kern __rcu *sit_parms;
>  	unsigned int		ip_tnl_net_id;
>  	struct gro_cells	gro_cells;
>  	__u32			fwmark;
> diff --git a/net/ipv6/sit.c b/net/ipv6/sit.c
> index dc37c7109af5324f2ced0301b289e7622dd1a55f..c9049ab87e010eed5f53a342460ed10006083cd7 100644
> --- a/net/ipv6/sit.c
> +++ b/net/ipv6/sit.c
> @@ -108,24 +108,33 @@ static struct ip_tunnel *ipip6_tunnel_lookup(struct net *net,
>  	int ifindex = dev ? dev->ifindex : 0;
>  
>  	for_each_ip_tunnel_rcu(t, sitn->tunnels_r_l[h0 ^ h1]) {
> -		if (local == t->sit_parms->iph.saddr &&
> -		    remote == t->sit_parms->iph.daddr &&
> -		    (!dev || !t->sit_parms->link || ifindex == t->sit_parms->link ||
> -		     sifindex == t->sit_parms->link) &&
> +		const struct ip_tunnel_parm_kern *parms;
> +
> +		parms = rcu_dereference(t->sit_parms);
> +		if (local == parms->iph.saddr &&
> +		    remote == parms->iph.daddr &&
> +		    (!dev || !parms->link || ifindex == parms->link ||
> +		     sifindex == parms->link) &&
>  		    (t->dev->flags & IFF_UP))
>  			return t;
>  	}
>  	for_each_ip_tunnel_rcu(t, sitn->tunnels_r[h0]) {
> -		if (remote == t->sit_parms->iph.daddr &&
> -		    (!dev || !t->sit_parms->link || ifindex == t->sit_parms->link ||
> -		     sifindex == t->sit_parms->link) &&
> +		const struct ip_tunnel_parm_kern *parms;
> +
> +		parms = rcu_dereference(t->sit_parms);
> +		if (remote == parms->iph.daddr &&
> +		    (!dev || !parms->link || ifindex == parms->link ||
> +		     sifindex == parms->link) &&
>  		    (t->dev->flags & IFF_UP))
>  			return t;
>  	}
>  	for_each_ip_tunnel_rcu(t, sitn->tunnels_l[h1]) {
> -		if (local == t->sit_parms->iph.saddr &&
> -		    (!dev || !t->sit_parms->link || ifindex == t->sit_parms->link ||
> -		     sifindex == t->sit_parms->link) &&
> +		const struct ip_tunnel_parm_kern *parms;
> +
> +		parms = rcu_dereference(t->sit_parms);
> +		if (local == parms->iph.saddr &&
> +		    (!dev || !parms->link || ifindex == parms->link ||
> +		     sifindex == parms->link) &&
>  		    (t->dev->flags & IFF_UP))
>  			return t;
>  	}
> @@ -157,7 +166,7 @@ __ipip6_bucket(struct sit_net *sitn, struct ip_tunnel_parm_kern *parms)
>  static inline struct ip_tunnel __rcu **ipip6_bucket(struct sit_net *sitn,
>  		struct ip_tunnel *t)
>  {
> -	return __ipip6_bucket(sitn, t->sit_parms);
> +	return __ipip6_bucket(sitn, rtnl_dereference(t->sit_parms));
>  }
>  
>  static void ipip6_tunnel_unlink(struct sit_net *sitn, struct ip_tunnel *t)
> @@ -230,17 +239,19 @@ static int ipip6_tunnel_create(struct net_device *dev)
>  {
>  	struct ip_tunnel *t = netdev_priv(dev);
>  	struct sit_net *sitn = net_generic(t->net, sit_net_id);
> +	struct ip_tunnel_parm_kern *parms;
>  	int err;
>  
>  	err = ipip6_tunnel_clone_6rd(dev, sitn);
>  	if (err < 0)
>  		goto out;
>  
> -	t->parms = *t->sit_parms;
> -	__dev_addr_set(dev, &t->sit_parms->iph.saddr, 4);
> -	memcpy(dev->broadcast, &t->sit_parms->iph.daddr, 4);
> +	parms = rtnl_dereference(t->sit_parms);
> +	t->parms = *parms;
> +	__dev_addr_set(dev, &parms->iph.saddr, 4);
> +	memcpy(dev->broadcast, &parms->iph.daddr, 4);
>  
> -	if (test_bit(IP_TUNNEL_SIT_ISATAP_BIT, t->sit_parms->i_flags))
> +	if (test_bit(IP_TUNNEL_SIT_ISATAP_BIT, parms->i_flags))
>  		dev->priv_flags |= IFF_ISATAP;
>  
>  	dev->rtnl_link_ops = &sit_link_ops;
> @@ -264,6 +275,7 @@ static struct ip_tunnel *ipip6_tunnel_locate(struct net *net,
>  	__be32 local = parms->iph.saddr;
>  	struct ip_tunnel *t, *nt;
>  	struct ip_tunnel __rcu **tp;
> +	struct ip_tunnel_parm_kern *nt_parms;
>  	struct net_device *dev;
>  	char name[IFNAMSIZ];
>  	struct sit_net *sitn = net_generic(net, sit_net_id);
> @@ -271,9 +283,12 @@ static struct ip_tunnel *ipip6_tunnel_locate(struct net *net,
>  	for (tp = __ipip6_bucket(sitn, parms);
>  	    (t = rtnl_dereference(*tp)) != NULL;
>  	     tp = &t->next) {
> -		if (local == t->sit_parms->iph.saddr &&
> -		    remote == t->sit_parms->iph.daddr &&
> -		    parms->link == t->sit_parms->link) {
> +		const struct ip_tunnel_parm_kern *tparms;
> +
> +		tparms = rtnl_dereference(t->sit_parms);
> +		if (local == tparms->iph.saddr &&
> +		    remote == tparms->iph.daddr &&
> +		    parms->link == tparms->link) {
>  			if (create)
>  				return NULL;
>  			else
> @@ -300,10 +315,11 @@ static struct ip_tunnel *ipip6_tunnel_locate(struct net *net,
>  	nt = netdev_priv(dev);
>  
>  	nt->net = net;
> -	nt->sit_parms = kmalloc_obj(*nt->sit_parms);
> -	if (!nt->sit_parms)
> +	nt_parms = kmalloc_obj(*nt_parms);
> +	if (!nt_parms)
>  		goto failed_free;
> -	*nt->sit_parms = *parms;
> +	*nt_parms = *parms;
> +	rcu_assign_pointer(nt->sit_parms, nt_parms);
>  	if (ipip6_tunnel_create(dev) < 0)
>  		goto failed_free;
>  
> @@ -599,41 +615,45 @@ static int ipip6_err(struct sk_buff *skb, u32 info)
>  	err = -ENOENT;
>  
>  	sifindex = netif_is_l3_master(skb->dev) ? IPCB(skb)->iif : 0;
> +	rcu_read_lock();
>  	t = ipip6_tunnel_lookup(dev_net(skb->dev), skb->dev,
>  				iph->daddr, iph->saddr, sifindex);
> -	if (!t)
> -		goto out;
> +	if (t) {
> +		const struct ip_tunnel_parm_kern *parms;
>  
> -	if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) {
> -		ipv4_update_pmtu(skb, dev_net(skb->dev), info,
> -				 t->sit_parms->link, iph->protocol);
> -		err = 0;
> -		goto out;
> -	}
> -	if (type == ICMP_REDIRECT) {
> -		ipv4_redirect(skb, dev_net(skb->dev), t->sit_parms->link,
> -			      iph->protocol);
> -		err = 0;
> -		goto out;
> -	}
> +		parms = rcu_dereference(t->sit_parms);
> +		if (type == ICMP_DEST_UNREACH && code == ICMP_FRAG_NEEDED) {
> +			ipv4_update_pmtu(skb, dev_net(skb->dev), info,
> +					 parms->link, iph->protocol);
> +			err = 0;
> +			goto out;
> +		}
> +		if (type == ICMP_REDIRECT) {
> +			ipv4_redirect(skb, dev_net(skb->dev), parms->link,
> +				      iph->protocol);
> +			err = 0;
> +			goto out;
> +		}
>  
> -	err = 0;
> -	if (__in6_dev_get(skb->dev) &&
> -	    !ip6_err_gen_icmpv6_unreach(skb, iph->ihl * 4, type, data_len))
> -		goto out;
> +		err = 0;
> +		if (__in6_dev_get(skb->dev) &&
> +		    !ip6_err_gen_icmpv6_unreach(skb, iph->ihl * 4, type, data_len))
> +			goto out;
>  
> -	if (t->sit_parms->iph.daddr == 0)
> -		goto out;
> +		if (parms->iph.daddr == 0)
> +			goto out;
>  
> -	if (t->sit_parms->iph.ttl == 0 && type == ICMP_TIME_EXCEEDED)
> -		goto out;
> +		if (parms->iph.ttl == 0 && type == ICMP_TIME_EXCEEDED)
> +			goto out;
>  
> -	if (time_before(jiffies, READ_ONCE(t->err_time) + IPTUNNEL_ERR_TIMEO))
> -		WRITE_ONCE(t->err_count, READ_ONCE(t->err_count) + 1);
> -	else
> -		WRITE_ONCE(t->err_count, 1);
> -	WRITE_ONCE(t->err_time, jiffies);
> +		if (time_before(jiffies, READ_ONCE(t->err_time) + IPTUNNEL_ERR_TIMEO))
> +			WRITE_ONCE(t->err_count, READ_ONCE(t->err_count) + 1);
> +		else
> +			WRITE_ONCE(t->err_count, 1);
> +		WRITE_ONCE(t->err_time, jiffies);
> +	}
>  out:
> +	rcu_read_unlock();
>  	return err;
>  }
>  
> @@ -726,8 +746,11 @@ static int ipip6_rcv(struct sk_buff *skb)
>  	tunnel = ipip6_tunnel_lookup(dev_net(skb->dev), skb->dev,
>  				     iph->saddr, iph->daddr, sifindex);
>  	if (tunnel) {
> -		if (tunnel->sit_parms->iph.protocol != IPPROTO_IPV6 &&
> -		    tunnel->sit_parms->iph.protocol != 0)
> +		const struct ip_tunnel_parm_kern *parms;
> +
> +		parms = rcu_dereference(tunnel->sit_parms);
> +		if (parms->iph.protocol != IPPROTO_IPV6 &&
> +		    parms->iph.protocol != 0)
>  			goto out;
>  
>  		skb->mac_header = skb->network_header;
> @@ -800,10 +823,12 @@ static int sit_tunnel_rcv(struct sk_buff *skb, u8 ipproto)
>  	tunnel = ipip6_tunnel_lookup(dev_net(skb->dev), skb->dev,
>  				     iph->saddr, iph->daddr, sifindex);
>  	if (tunnel) {
> +		const struct ip_tunnel_parm_kern *parms;
>  		const struct tnl_ptk_info *tpi;
>  
> -		if (tunnel->sit_parms->iph.protocol != ipproto &&
> -		    tunnel->sit_parms->iph.protocol != 0)
> +		parms = rcu_dereference(tunnel->sit_parms);
> +		if (parms->iph.protocol != ipproto &&
> +		    parms->iph.protocol != 0)
>  			goto drop;
>  
>  		if (!xfrm4_policy_check(NULL, XFRM_POLICY_IN, skb))
> @@ -942,20 +967,27 @@ static netdev_tx_t ipip6_tunnel_xmit(struct sk_buff *skb,
>  				     struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> -	const struct iphdr  *tiph = &tunnel->sit_parms->iph;
> +	const struct ip_tunnel_parm_kern *parms;
> +	const struct iphdr  *tiph;
>  	const struct ipv6hdr *iph6 = ipv6_hdr(skb);
> -	u8     tos = tunnel->sit_parms->iph.tos;
> -	__be16 df = tiph->frag_off;
> +	u8     tos;
> +	__be16 df;
>  	struct rtable *rt;		/* Route to the other host */
>  	struct net_device *tdev;	/* Device to other host */
>  	unsigned int max_headroom;	/* The extra header space needed */
> -	__be32 dst = tiph->daddr;
> +	__be32 dst;
>  	int err_count, mtu;
>  	struct flowi4 fl4;
>  	u8 ttl;
>  	u8 protocol = IPPROTO_IPV6;
>  	int t_hlen = tunnel->hlen + sizeof(struct iphdr);
>  
> +	parms = rcu_dereference(tunnel->sit_parms);
> +	tiph = &parms->iph;
> +	tos = parms->iph.tos;
> +	df = tiph->frag_off;
> +	dst = tiph->daddr;
> +
>  	if (tos == 1)
>  		tos = ipv6_get_dsfield(iph6);
>  
> @@ -970,7 +1002,7 @@ static netdev_tx_t ipip6_tunnel_xmit(struct sk_buff *skb,
>  	if (!dst && !ipip6_tunnel_dst_find(skb, &dst, false))
>  		goto tx_error;
>  
> -	flowi4_init_output(&fl4, tunnel->sit_parms->link, READ_ONCE(tunnel->fwmark),
> +	flowi4_init_output(&fl4, parms->link, READ_ONCE(tunnel->fwmark),
>  			   tos & INET_DSCP_MASK, RT_SCOPE_UNIVERSE,
>  			   IPPROTO_IPV6, 0, dst, tiph->saddr, 0, 0,
>  			   sock_net_uid(tunnel->net, NULL));
> @@ -1018,7 +1050,7 @@ static netdev_tx_t ipip6_tunnel_xmit(struct sk_buff *skb,
>  			df = 0;
>  		}
>  
> -		if (tunnel->sit_parms->iph.daddr)
> +		if (parms->iph.daddr)
>  			skb_dst_update_pmtu_no_confirm(skb, mtu);
>  
>  		if (skb->len > mtu && !skb_is_gso(skb)) {
> @@ -1087,13 +1119,17 @@ static netdev_tx_t sit_tunnel_xmit__(struct sk_buff *skb,
>  				     struct net_device *dev, u8 ipproto)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> -	const struct iphdr  *tiph = &tunnel->sit_parms->iph;
> +	const struct ip_tunnel_parm_kern *parms;
> +	const struct iphdr  *tiph;
>  
>  	if (iptunnel_handle_offloads(skb, SKB_GSO_IPXIP4))
>  		goto tx_error;
>  
>  	skb_set_inner_ipproto(skb, ipproto);
>  
> +	parms = rcu_dereference(tunnel->sit_parms);
> +	tiph = &parms->iph;
> +
>  	ip_tunnel_xmit(skb, dev, tiph, ipproto);
>  	return NETDEV_TX_OK;
>  tx_error:
> @@ -1108,6 +1144,7 @@ static netdev_tx_t sit_tunnel_xmit(struct sk_buff *skb,
>  	if (!pskb_inet_may_pull(skb))
>  		goto tx_err;
>  
> +	rcu_read_lock();
>  	switch (skb->protocol) {
>  	case htons(ETH_P_IP):
>  		sit_tunnel_xmit__(skb, dev, IPPROTO_IPIP);
> @@ -1121,8 +1158,10 @@ static netdev_tx_t sit_tunnel_xmit(struct sk_buff *skb,
>  		break;
>  #endif
>  	default:
> +		rcu_read_unlock();
>  		goto tx_err;
>  	}
> +	rcu_read_unlock();
>  
>  	return NETDEV_TX_OK;
>  
> @@ -1130,19 +1169,20 @@ static netdev_tx_t sit_tunnel_xmit(struct sk_buff *skb,
>  	DEV_STATS_INC(dev, tx_errors);
>  	kfree_skb(skb);
>  	return NETDEV_TX_OK;
> -
>  }
>  
>  static void ipip6_tunnel_bind_dev(struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
>  	int t_hlen = tunnel->hlen + sizeof(struct iphdr);
> +	const struct ip_tunnel_parm_kern *parms;
>  	struct net_device *tdev = NULL;
>  	int hlen = LL_MAX_HEADER;
>  	const struct iphdr *iph;
>  	struct flowi4 fl4;
>  
> -	iph = &tunnel->sit_parms->iph;
> +	parms = rtnl_dereference(tunnel->sit_parms);
> +	iph = &parms->iph;
>  
>  	if (iph->daddr) {
>  		struct rtable *rt = ip_route_output_ports(tunnel->net, &fl4,
> @@ -1151,7 +1191,7 @@ static void ipip6_tunnel_bind_dev(struct net_device *dev)
>  							  0, 0,
>  							  IPPROTO_IPV6,
>  							  iph->tos & INET_DSCP_MASK,
> -							  tunnel->sit_parms->link);
> +							  parms->link);
>  
>  		if (!IS_ERR(rt)) {
>  			tdev = rt->dst.dev;
> @@ -1160,8 +1200,8 @@ static void ipip6_tunnel_bind_dev(struct net_device *dev)
>  		dev->flags |= IFF_POINTOPOINT;
>  	}
>  
> -	if (!tdev && tunnel->sit_parms->link)
> -		tdev = __dev_get_by_index(tunnel->net, tunnel->sit_parms->link);
> +	if (!tdev && parms->link)
> +		tdev = __dev_get_by_index(tunnel->net, parms->link);
>  
>  	if (tdev && !netif_is_l3_master(tdev)) {
>  		int mtu;
> @@ -1182,8 +1222,9 @@ static int ipip6_tunnel_update(struct ip_tunnel *t,
>  	struct net *net = t->net;
>  	struct sit_net *sitn = net_generic(net, sit_net_id);
>  	struct ip_tunnel_parm_kern *new_p, *old_p;
> +	bool move;
>  
> -	old_p = t->sit_parms;
> +	old_p = rtnl_dereference(t->sit_parms);
>  	new_p = kmalloc_obj(*new_p);
>  	if (!new_p)
>  		return -ENOMEM;
> @@ -1194,21 +1235,29 @@ static int ipip6_tunnel_update(struct ip_tunnel *t,
>  	new_p->iph.tos = p->iph.tos;
>  	new_p->iph.frag_off = p->iph.frag_off;
>  	new_p->link = p->link;
> -	ipip6_tunnel_unlink(sitn, t);
> -	synchronize_net();
> -	t->sit_parms = new_p;
> +	move = old_p->iph.saddr != p->iph.saddr ||
> +	       old_p->iph.daddr != p->iph.daddr;
> +
> +	if (move)
> +		ipip6_tunnel_unlink(sitn, t);
> +
>  	t->parms.iph = new_p->iph;
>  	WRITE_ONCE(t->parms.link, new_p->link);
> -	__dev_addr_set(t->dev, &p->iph.saddr, 4);
> -	memcpy(t->dev->broadcast, &p->iph.daddr, 4);
> -	ipip6_tunnel_link(sitn, t);
> +	rcu_assign_pointer(t->sit_parms, new_p);
> +
> +	if (move) {
> +		synchronize_net();
> +		__dev_addr_set(t->dev, &p->iph.saddr, 4);
> +		memcpy(t->dev->broadcast, &p->iph.daddr, 4);
> +		ipip6_tunnel_link(sitn, t);
> +	}
>  	if (old_p->link != p->link || t->fwmark != fwmark) {
>  		WRITE_ONCE(t->fwmark, fwmark);
>  		ipip6_tunnel_bind_dev(t->dev);
>  	}
>  	dst_cache_reset(&t->dst_cache);
>  	netdev_state_change(t->dev);
> -	kfree(old_p);
> +	kfree_rcu(old_p, rcu);
>  	return 0;
>  }
>  
> @@ -1336,12 +1385,14 @@ static int
>  ipip6_tunnel_get(struct net_device *dev, struct ip_tunnel_parm_kern *p)
>  {
>  	struct ip_tunnel *t = netdev_priv(dev);
> +	const struct ip_tunnel_parm_kern *parms;
>  
>  	if (dev == dev_to_sit_net(dev)->fb_tunnel_dev)
>  		t = ipip6_tunnel_locate(t->net, p, 0);
>  	if (!t)
>  		t = netdev_priv(dev);
> -	memcpy(p, t->sit_parms, sizeof(*p));
> +	parms = rtnl_dereference(t->sit_parms);
> +	memcpy(p, parms, sizeof(*p));
>  	return 0;
>  }
>  
> @@ -1464,8 +1515,15 @@ ipip6_tunnel_siocdevprivate(struct net_device *dev, struct ifreq *ifr,
>  static int ipip6_get_iflink(const struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> +	const struct ip_tunnel_parm_kern *parms;
> +	int link;
>  
> -	return READ_ONCE(tunnel->sit_parms->link);
> +	rcu_read_lock();
> +	parms = rcu_dereference(tunnel->sit_parms);
> +	link = parms ? parms->link : 0;
> +	rcu_read_unlock();
> +
> +	return link;
>  }
>  
>  static const struct net_device_ops ipip6_netdev_ops = {
> @@ -1480,6 +1538,7 @@ static const struct net_device_ops ipip6_netdev_ops = {
>  static void ipip6_dev_free(struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> +	struct ip_tunnel_parm_kern *parms;
>  #ifdef CONFIG_IPV6_SIT_6RD
>  	struct ip_tunnel_6rd_parm *ip6rd;
>  
> @@ -1487,8 +1546,9 @@ static void ipip6_dev_free(struct net_device *dev)
>  	RCU_INIT_POINTER(tunnel->ip6rd, NULL);
>  	kfree(ip6rd);
>  #endif
> -	kfree(tunnel->sit_parms);
> -	tunnel->sit_parms = NULL;
> +	parms = rcu_dereference_protected(tunnel->sit_parms, 1);
> +	RCU_INIT_POINTER(tunnel->sit_parms, NULL);
> +	kfree(parms);
>  	if (tunnel->dst_cache.cache) {
>  		dst_cache_destroy(&tunnel->dst_cache);
>  		tunnel->dst_cache.cache = NULL;
> @@ -1528,10 +1588,12 @@ static void ipip6_tunnel_setup(struct net_device *dev)
>  static int ipip6_tunnel_init(struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> +	struct ip_tunnel_parm_kern *parms;
>  	int err;
>  
>  	tunnel->dev = dev;
> -	strscpy(tunnel->sit_parms->name, dev->name);
> +	parms = rtnl_dereference(tunnel->sit_parms);
> +	strscpy(parms->name, dev->name);
>  
>  	ipip6_tunnel_bind_dev(dev);
>  
> @@ -1549,7 +1611,6 @@ static void __net_init ipip6_fb_tunnel_init(struct net_device *dev)
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
>  	struct net *net = dev_net(dev);
>  	struct sit_net *sitn = net_generic(net, sit_net_id);
> -
>  	rcu_assign_pointer(sitn->tunnels_wc[0], tunnel);
>  }
>  
> @@ -1636,6 +1697,7 @@ static int ipip6_newlink(struct net_device *dev,
>  #ifdef CONFIG_IPV6_SIT_6RD
>  	struct ip_tunnel_6rd ip6rd;
>  #endif
> +	struct ip_tunnel_parm_kern *nt_parms;
>  	struct ip_tunnel_parm_kern p;
>  	struct net *net;
>  	int err;
> @@ -1655,10 +1717,11 @@ static int ipip6_newlink(struct net_device *dev,
>  	if (ipip6_tunnel_locate(net, &p, 0))
>  		return -EEXIST;
>  
> -	nt->sit_parms = kmalloc_obj(*nt->sit_parms);
> -	if (!nt->sit_parms)
> +	nt_parms = kmalloc_obj(*nt_parms);
> +	if (!nt_parms)
>  		return -ENOMEM;
> -	*nt->sit_parms = p;
> +	*nt_parms = p;
> +	rcu_assign_pointer(nt->sit_parms, nt_parms);
>  
>  	err = ipip6_tunnel_create(dev);
>  	if (err < 0) {
> @@ -1783,7 +1846,7 @@ static size_t ipip6_get_size(const struct net_device *dev)
>  static int ipip6_fill_info(struct sk_buff *skb, const struct net_device *dev)
>  {
>  	struct ip_tunnel *tunnel = netdev_priv(dev);
> -	struct ip_tunnel_parm_kern *parm = tunnel->sit_parms;
> +	const struct ip_tunnel_parm_kern *parm = rtnl_dereference(tunnel->sit_parms);
>  #ifdef CONFIG_IPV6_SIT_6RD
>  	const struct ip_tunnel_6rd_parm *ip6rd;
>  #endif
> @@ -1929,6 +1992,7 @@ static void __net_exit sit_exit_rtnl_net(struct net *net, struct list_head *head
>  static int __net_init sit_init_net(struct net *net)
>  {
>  	struct sit_net *sitn = net_generic(net, sit_net_id);
> +	struct ip_tunnel_parm_kern *nt_parms;
>  	struct ip_tunnel *t;
>  	int err;
>  
> @@ -1956,17 +2020,18 @@ static int __net_init sit_init_net(struct net *net)
>  
>  	t = netdev_priv(sitn->fb_tunnel_dev);
>  	t->net = net;
> -	t->sit_parms = kzalloc_obj(*t->sit_parms);
> -	if (!t->sit_parms) {
> +	nt_parms = kzalloc_obj(*nt_parms);
> +	if (!nt_parms) {
>  		err = -ENOMEM;
>  		goto err_reg_dev;
>  	}
> -	t->sit_parms->iph.version	= 4;
> -	t->sit_parms->iph.protocol	= IPPROTO_IPV6;
> -	t->sit_parms->iph.ihl		= 5;
> -	t->sit_parms->iph.ttl		= 64;
> -	strscpy(t->sit_parms->name, sitn->fb_tunnel_dev->name);
> -	t->parms = *t->sit_parms;
> +	nt_parms->iph.version	= 4;
> +	nt_parms->iph.protocol	= IPPROTO_IPV6;
> +	nt_parms->iph.ihl	= 5;
> +	nt_parms->iph.ttl	= 64;
> +	strscpy(nt_parms->name, sitn->fb_tunnel_dev->name);
> +	t->parms = *nt_parms;
> +	rcu_assign_pointer(t->sit_parms, nt_parms);
>  
>  	err = ipip6_tunnel_clone_6rd(sitn->fb_tunnel_dev, sitn);
>  	if (err < 0)
> -- 
> 2.55.0.979.g7e5102b832-goog
> 

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 228 bytes --]

  reply	other threads:[~2026-09-07 14:33 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07  7:58 [PATCH net-next 0/9] sit: convert configuration to RCU and lockless fill_info Eric Dumazet
2026-09-07  7:58 ` [PATCH net-next 1/9] sit: fix UAF in ipip6_tunnel_del_prl() Eric Dumazet
2026-09-07 12:28   ` Lorenzo Bianconi
2026-09-07  7:58 ` [PATCH net-next 2/9] sit: charge ip_tunnel_prl_entry allocations to memcg Eric Dumazet
2026-09-07 12:35   ` Lorenzo Bianconi
2026-09-07  7:58 ` [PATCH net-next 3/9] ip_tunnel: use WRITE_ONCE in ip_tunnel_encap_setup Eric Dumazet
2026-09-07 15:12   ` Lorenzo Bianconi
2026-09-08 11:00   ` netdev-bot+sashiko
2026-09-07  7:58 ` [PATCH net-next 4/9] sit: annotate data-races around tunnel->fwmark Eric Dumazet
2026-09-07 15:12   ` Lorenzo Bianconi
2026-09-08 11:00   ` netdev-bot+sashiko
2026-09-07  7:58 ` [PATCH net-next 5/9] sit: convert 6RD configuration to RCU protection Eric Dumazet
2026-09-07 13:00   ` Lorenzo Bianconi
2026-09-08 11:00   ` netdev-bot+sashiko
2026-09-07  7:58 ` [PATCH net-next 6/9] sit: implement ipip6_get_iflink() Eric Dumazet
2026-09-07 13:01   ` Lorenzo Bianconi
2026-09-07  7:58 ` [PATCH net-next 7/9] sit: dynamically allocate struct ip_tunnel_parm_kern Eric Dumazet
2026-09-07 13:16   ` Lorenzo Bianconi
2026-09-07 13:34   ` Artem Lytkin
2026-09-07 13:48     ` Eric Dumazet
2026-09-08 11:00   ` netdev-bot+sashiko
2026-09-07  7:58 ` [PATCH net-next 8/9] sit: convert configuration to RCU protection Eric Dumazet
2026-09-07 14:32   ` Lorenzo Bianconi [this message]
2026-09-07 14:42     ` Eric Dumazet
2026-09-08 11:00   ` netdev-bot+sashiko
2026-09-07  7:58 ` [PATCH net-next 9/9] sit: no longer rely on RTNL in ipip6_fill_info() Eric Dumazet
2026-09-07 15:04   ` Lorenzo Bianconi
2026-09-11  1:40 ` [PATCH net-next 0/9] sit: convert configuration to RCU and lockless fill_info patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ap7LFmE1Ykohf-eM@lore-desk \
    --to=lorenzo.bianconi@oss.qualcomm.com \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=eric.dumazet@gmail.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=iprintercanon@gmail.com \
    --cc=kuba@kernel.org \
    --cc=kuniyu@google.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox