Netdev List
 help / color / mirror / Atom feed
From: Julian Anastasov <ja@ssi.bg>
To: netdev-bot+sashiko@kernel.org
Cc: zihanx@nebusec.ai, horms@verge.net.au, pablo@netfilter.org,
	fw@strlen.de, phil@nwl.cc, davem@davemloft.net,
	edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
	netdev@vger.kernel.org, lvs-devel@vger.kernel.org,
	netfilter-devel@vger.kernel.org, coreteam@netfilter.org,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net v2 1/2] ipvs: avoid stack overflow from recursive connection expiration
Date: Mon, 21 Sep 2026 09:50:48 +0300 (EEST)	[thread overview]
Message-ID: <e1efae34-24a7-3b24-22b0-6a838aa93d52@ssi.bg> (raw)
In-Reply-To: <178996076640.2160803.16028832049809238100@kernel.org>

[-- Attachment #1: Type: text/plain, Size: 2050 bytes --]


	Hello,

On Mon, 21 Sep 2026, netdev-bot+sashiko@kernel.org wrote:

> Thank you for your contribution! Sashiko AI review found 2 potential
> issue(s) to consider.
> 
> Critical: 0 · High: 1 (1) · Medium: 0 · Low: 1
> 
> If you believe none of the issues are legitimate, please reply to each
> issue of Medium severity or higher and explain why the AI is wrong.
> If any of them are legitimate and you plan to respin, please let patchwork
> know by including "pw-bot: cr" as a separate line at the end of your reply
> (one such reply per series is enough).
> 
> - [High] ipvs: use-after-free in ip_vs_conn_expire() due to timer re-
>   arming race
> - [Low] ip_vs_conn_del_put() (net/netfilter/ipvs/ip_vs_conn.c:1333-1346)
>   keeps its old comment "Try to delete connection while holding…
> 
> Pre-existing issues:
> - [High] ip_vs_conn_del_put() (net/netfilter/ipvs/ip_vs_conn.c:1336-1341)
>   cancels the controller's timer, drops the caller's only reference on…
> 
> --
> 
> ipvs: avoid stack overflow from recursive connection expiration
> 
> This changes ip_vs_conn_del_put() to return whether it managed to delete
> the controller's timer, and makes ip_vs_conn_expire() loop back with the
> controller instead of recursing into itself.  The stated goal is to keep
> chain cleanup synchronous while using a single stack frame.
> 
> v1 Link: https://lore.kernel.org/all/cover.1789110326.git.zihanx@nebusec.ai/

	Zihan, IPVS has conn refcounting which does not look
natural: the hash table has reference and the timer callback
has no reference. Let me try today to change the refcounting,
so that unhashing occurs after last reference is dropped,
the conn lookups already use inc_not_zero, so we will try
to consider the timer_delete as successful stealing of
the refcnt from the timer callback (yes, the callback should
hold refcnt, not the hashing). But first let me try if the
idea would be successful. As result, your change should
be small as before, we should be able to delete conns safely.

Regards

--
Julian Anastasov <ja@ssi.bg>

  reply	other threads:[~2026-09-21  6:50 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  3:02 [PATCH net v2 0/2] ipvs: avoid stack overflow from recursive connection expiration Zihan Xi
2026-09-17  3:02 ` [PATCH net v2 1/2] " Zihan Xi
2026-09-18 16:49   ` Julian Anastasov
2026-09-19 10:06     ` Julian Anastasov
2026-09-21  3:19   ` netdev-bot+sashiko
2026-09-21  6:50     ` Julian Anastasov [this message]
2026-09-21  7:10       ` zihan xi
2026-09-17  3:02 ` [PATCH net v2 2/2] ipvs: reject FTP control ports as data ports Zihan Xi
2026-09-18 16:54   ` Julian Anastasov
2026-09-19 10:08     ` Julian Anastasov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e1efae34-24a7-3b24-22b0-6a838aa93d52@ssi.bg \
    --to=ja@ssi.bg \
    --cc=coreteam@netfilter.org \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=fw@strlen.de \
    --cc=horms@verge.net.au \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lvs-devel@vger.kernel.org \
    --cc=netdev-bot+sashiko@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=pablo@netfilter.org \
    --cc=phil@nwl.cc \
    --cc=zihanx@nebusec.ai \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox