mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v3 0/2] xfrm: iptfs: fix queued receive state lifetime
@ 2026-09-30  5:03 Roshan Kumar
  2026-09-30  5:03 ` [PATCH net v3 1/2] xfrm: iptfs: track independent drop deadlines Roshan Kumar
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Roshan Kumar @ 2026-09-30  5:03 UTC (permalink / raw)
  To: netdev
  Cc: steffen.klassert, herbert, davem, edumazet, kuba, pabeni, horms,
	chopps, linux-kernel, lilly, shubham, gio, robert, paolo,
	Roshan Kumar

IP-TFS can retain received skbs in its reorder window and reassembly state.
Two lifetime problems interact in these paths: the shared drop timer
does not track the two states independently, and retained skbs do not
keep their input net_device alive.

Patch 1 gives reassembly and reorder state separate deadlines and
always arms their shared timer for the earliest one. Patch 2 holds a
device reference for every retained skb until ordered processing or
destruction is complete.

The unpatched base reproduces the device use-after-free under KASAN.
The final series passes the reorder, reassembly, SA deletion/expiry,
clean teardown, and unprivileged user-namespace regression cases,
including a timer-overlap test for stale deadlines.

Testing on x86-64 at the base commit plus this series:
- KASAN + NET_DEV_REFCNT_TRACKER: the 10-case lifecycle matrix passed on
  both the regular and lockdep/RCU-debug kernels;
- stale-deadline overlap regression: 5.155 second close delay (minimum 4s);
- runt-created reassembly regression: 5.152 second close delay
  (minimum 4s);
- PREEMPT=full, lockdep, RCU, atomic-sleep, debug-object, and ref-tracker
  scans were clean;
- GCC 13.3 and Clang 18.1 W=1 object builds passed;
- x86-32 and arm64 cross-compiled W=1 object builds passed;
- allnoconfig W=1 full build passed;
- allmodconfig and allyesconfig W=1 xfrm_iptfs.o builds passed. The
  full builds stop on the same unrelated lockdep_proc.c and callthunks.c
  GCC diagnostics reproduced on the unpatched base.

Changes in v3:
- split the shared-timer correction into a prerequisite patch;
- keep the reassembly reference through xfrm_input();
- track reassembly and reorder deadlines independently and arm runt-created
  reassembly;
- cover all reorder, completion, abort, timeout, and destruction paths;
- use netdev_hold()/netdev_put() and document reference ownership;
- remove the incorrect bounded-lifetime claim and self Reported-by trailer;
- add the required AI-assistance disclosure.

Changes in v2:
- add reassembly queue coverage and state-destruction cleanup;
- add the Fixes tag and independent reporting team credit.

Roshan Kumar (2):
  xfrm: iptfs: track independent drop deadlines
  xfrm: iptfs: hold a device reference while packets are queued

 net/xfrm/xfrm_iptfs.c | 151 ++++++++++++++++++++++++++++++------------
 1 file changed, 108 insertions(+), 43 deletions(-)


base-commit: a7bfaba4823e3c165bb2004c74eff7c096672bc7
-- 
2.43.0

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-30  5:09 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30  5:03 [PATCH net v3 0/2] xfrm: iptfs: fix queued receive state lifetime Roshan Kumar
2026-09-30  5:03 ` [PATCH net v3 1/2] xfrm: iptfs: track independent drop deadlines Roshan Kumar
2026-09-30  5:03 ` [PATCH net v3 2/2] xfrm: iptfs: hold a device reference while packets are queued Roshan Kumar
2026-09-30  5:09 ` [PATCH net v3 0/2] xfrm: iptfs: fix queued receive state lifetime netdev-bot+sinfo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®