* [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown
@ 2026-10-04 18:36 Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Daehyeon Ko @ 2026-10-04 18:36 UTC (permalink / raw)
To: David Ahern, Ido Schimmel
Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, netdev, linux-kernel, Daehyeon Ko
The first patch serializes address publication with device teardown by
taking idev->lock before the address hash lock, as suggested by Ido. It
rechecks both dead and disable_ipv6 before publishing.
The second patch fixes the related NETDEV_DOWN case, where the idev is
not marked dead. An address added after the initial hash scan can still
be captured by the per-device list snapshot. Remove it from the hash
before marking it dead, notifying listeners and dropping the list
reference.
The deterministic v1 test did not add delays to addrconf.c. A diagnostic
module used kprobes and atomic rendezvous at existing instruction
boundaries to force the interleaving. Separate, unmodified RA/MTU stress
did not win the race; the ambiguous sentence was removed from patch 1.
Changes in v2:
- Reverse the nested lock order, protect the dead indication with
idev->lock, and recheck dead and disable_ipv6 before publication.
- Add a second patch for the NETDEV_DOWN WARN identified by Ido.
- Change patch 1's Fixes tag to 8814c4b53381.
- Clarify how the forced interleaving was produced.
Link: https://lore.kernel.org/r/20261001052150.136559-1-4ncienth@gmail.com
Daehyeon Ko (2):
ipv6: serialize address publication with device teardown
ipv6: remove ifaddr from hash during ifdown list cleanup
net/ipv6/addrconf.c | 20 +++++++++++++++++---
1 file changed, 17 insertions(+), 3 deletions(-)
base-commit: 6dc989ea46b96ce170840174b4a38c4a387fb005
--
2.55.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net v2 1/2] ipv6: serialize address publication with device teardown
2026-10-04 18:36 [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Daehyeon Ko
@ 2026-10-04 18:36 ` Daehyeon Ko
2026-10-05 18:39 ` netdev-bot+sashiko
2026-10-04 18:36 ` [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup Daehyeon Ko
2026-10-05 23:57 ` [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Jakub Kicinski
2 siblings, 1 reply; 6+ messages in thread
From: Daehyeon Ko @ 2026-10-04 18:36 UTC (permalink / raw)
To: David Ahern, Ido Schimmel
Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, netdev, linux-kernel, Daehyeon Ko
ipv6_add_addr() checks idev state before allocating an ifaddr, but
publishes the object later. addrconf_ifdown() can mark and detach the
idev between the check and publication.
This happens when a non-loopback device MTU falls below IPV6_MIN_MTU. A
forced interleaving published an address on a dead idev, and later device
deletion waited indefinitely for the leaked references.
Protect the dead indication with idev->lock and keep that lock across
both hash and device-list publication. Recheck both dead and
disable_ipv6 before publishing. If teardown wins, reject the unpublished
object.
Fixes: 8814c4b53381 ("[IPV6] ADDRCONF: Convert addrconf_lock to RCU.")
Cc: stable@vger.kernel.org
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
net/ipv6/addrconf.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index c90ee6dd7446cd..426739abb07440 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -1168,14 +1168,20 @@ ipv6_add_addr(struct inet6_dev *idev, struct ifa6_config *cfg,
rcu_read_lock();
- err = ipv6_add_addr_hash(idev->dev, ifa);
+ write_lock_bh(&idev->lock);
+
+ if (idev->dead)
+ err = -ENODEV;
+ else if (READ_ONCE(idev->cnf.disable_ipv6))
+ err = -EACCES;
+ else
+ err = ipv6_add_addr_hash(idev->dev, ifa);
if (err < 0) {
+ write_unlock_bh(&idev->lock);
rcu_read_unlock();
goto out;
}
- write_lock_bh(&idev->lock);
-
/* Add to inet6_dev unicast addr list. */
ipv6_link_dev_addr(idev, ifa);
@@ -3897,7 +3903,9 @@ static int addrconf_ifdown(struct net_device *dev, bool unregister)
* Do not dev_put!
*/
if (unregister) {
+ write_lock_bh(&idev->lock);
WRITE_ONCE(idev->dead, 1);
+ write_unlock_bh(&idev->lock);
/* protected by rtnl_lock */
RCU_INIT_POINTER(dev->ip6_ptr, NULL);
--
2.55.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup
2026-10-04 18:36 [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
@ 2026-10-04 18:36 ` Daehyeon Ko
2026-10-05 23:57 ` [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Jakub Kicinski
2 siblings, 0 replies; 6+ messages in thread
From: Daehyeon Ko @ 2026-10-04 18:36 UTC (permalink / raw)
To: David Ahern, Ido Schimmel
Cc: David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, netdev, linux-kernel, Daehyeon Ko
addrconf_ifdown() clears the address hash before snapshotting the
per-device address list. When the device is not unregistered, a
concurrent ipv6_add_addr() can publish an address after the hash scan and
before the list snapshot.
The ifdown path then removes the address from the device list and drops
its last reference while it is still linked in the hash. This triggers
the WARN_ON() in inet6_ifa_finish_destroy().
Remove each non-kept address from the hash before marking it dead,
notifying listeners and removing it from the device list.
hlist_del_init_rcu() is safe when the earlier hash scan already removed
the address.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Reported-by: Ido Schimmel <idosch@nvidia.com>
Link: https://lore.kernel.org/r/20261004135117.GA206930@shredder
Suggested-by: Ido Schimmel <idosch@nvidia.com>
Assisted-by: LLM
Signed-off-by: Daehyeon Ko <4ncienth@gmail.com>
---
net/ipv6/addrconf.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
index 426739abb07440..309c49b2141563 100644
--- a/net/ipv6/addrconf.c
+++ b/net/ipv6/addrconf.c
@@ -3996,6 +3996,12 @@ static int addrconf_ifdown(struct net_device *dev, bool unregister)
keep = keep_addr && (ifa->flags & IFA_F_PERMANENT) &&
!addr_is_local(&ifa->addr);
+ if (!keep) {
+ spin_lock_bh(&net->ipv6.addrconf_hash_lock);
+ hlist_del_init_rcu(&ifa->addr_lst);
+ spin_unlock_bh(&net->ipv6.addrconf_hash_lock);
+ }
+
spin_lock_bh(&ifa->lock);
if (keep) {
--
2.55.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net v2 1/2] ipv6: serialize address publication with device teardown
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
@ 2026-10-05 18:39 ` netdev-bot+sashiko
0 siblings, 0 replies; 6+ messages in thread
From: netdev-bot+sashiko @ 2026-10-05 18:39 UTC (permalink / raw)
To: 4ncienth
Cc: dsahern, idosch, davem, edumazet, kuba, pabeni, horms, netdev,
linux-kernel
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.
Critical: 0 · High: 1 · Medium: 0 · Low: 0
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [High] The patch leaves a teardown race open that leaks a reference and
has the same symptom it sets out to fix.
--
ipv6: serialize address publication with device teardown
This patch takes idev->lock around the write of idev->dead in
addrconf_ifdown(). In ipv6_add_addr() it holds idev->lock across both the
hash and the device-list publication, and rechecks dead and disable_ipv6
before publishing. The goal is to stop an address being published on a
dead idev, which leaks references and makes device deletion hang.
> diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c
> index c90ee6dd7446c..426739abb0744 100644
> --- a/net/ipv6/addrconf.c
> +++ b/net/ipv6/addrconf.c
> @@ -1168,14 +1168,20 @@ ipv6_add_addr(struct inet6_dev *idev, struct ifa6_config *cfg,
>
> rcu_read_lock();
>
> - err = ipv6_add_addr_hash(idev->dev, ifa);
> + write_lock_bh(&idev->lock);
> +
> + if (idev->dead)
> + err = -ENODEV;
> + else if (READ_ONCE(idev->cnf.disable_ipv6))
> + err = -EACCES;
> + else
> + err = ipv6_add_addr_hash(idev->dev, ifa);
> if (err < 0) {
> + write_unlock_bh(&idev->lock);
> rcu_read_unlock();
> goto out;
> }
>
> - write_lock_bh(&idev->lock);
> -
> /* Add to inet6_dev unicast addr list. */
> ipv6_link_dev_addr(idev, ifa);
>
[Severity: High]
Can the same kind of leak still happen for temporary addresses after this
change?
The new critical section ends in ipv6_add_addr() once the address is on the
hash, addr_list and tempaddr_list:
net/ipv6/addrconf.c:ipv6_add_addr() {
...
in6_ifa_hold(ifa);
write_unlock_bh(&idev->lock);
rcu_read_unlock();
inet6addr_notifier_call_chain(NETDEV_UP, ifa);
...
}
The ifp reference held by ipv6_create_tempaddr() is handed to the new
address only after ipv6_add_addr() returns:
net/ipv6/addrconf.c:ipv6_create_tempaddr() {
...
ift = ipv6_add_addr(idev, &cfg, block, NULL);
...
spin_lock_bh(&ift->lock);
ift->ifpub = ifp;
ift->cstamp = now;
...
addrconf_dad_start(ift);
in6_ifa_put(ift);
...
}
On the RA path, ipv6_create_tempaddr() runs in softirq without RTNL:
ndisc_router_discovery()
addrconf_prefix_rcv()
addrconf_prefix_rcv_add_addr()
manage_tempaddrs()
ipv6_create_tempaddr(ifp, false)
Meanwhile, addrconf_notify() handles NETDEV_CHANGEMTU with
dev->mtu < IPV6_MIN_MTU by calling addrconf_ifdown(dev, true). The device
is still up and keeps receiving RAs. This is the same trigger the commit
message cites.
Suppose addrconf_ifdown() takes idev->lock right after ipv6_add_addr()
drops it. It sets dead, and the new recheck can't help because the address
is already published. Step 3 then sees ift on tempaddr_list with ifpub
still NULL, so it has nothing to drop:
net/ipv6/addrconf.c:addrconf_ifdown() {
...
if (ifa->ifpub) {
in6_ifa_put(ifa->ifpub);
ifa->ifpub = NULL;
}
...
}
The rest of the loop marks ift DEAD, unlinks it and puts it. Then
ipv6_create_tempaddr() stores ifp in ift->ifpub. addrconf_dad_start() does
nothing because ift is DEAD, and in6_ifa_put(ift) drops the last reference.
inet6_ifa_finish_destroy() never releases ifpub. Only ipv6_del_addr() and
Step 3 of addrconf_ifdown() do, and only while the address is still on
tempaddr_list.
If so, the public ifp stays pinned. That pins its idev, and the idev pins
the net_device through dev_tracker. Later device deletion would then wait
forever in netdev_wait_allrefs_any(), which is the symptom described in the
commit message.
Would it make sense to set ifpub inside the idev->lock publication section,
for example by passing it into ipv6_add_addr()? Another option would be a
teardown or destroy path that releases an ifpub attached this late.
> @@ -3897,7 +3903,9 @@ static int addrconf_ifdown(struct net_device *dev, bool unregister)
> * Do not dev_put!
> */
> if (unregister) {
> + write_lock_bh(&idev->lock);
> WRITE_ONCE(idev->dead, 1);
> + write_unlock_bh(&idev->lock);
>
> /* protected by rtnl_lock */
> RCU_INIT_POINTER(dev->ip6_ptr, NULL);
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261004183639.3773498-1-4ncienth%40gmail.com
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown
2026-10-04 18:36 [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup Daehyeon Ko
@ 2026-10-05 23:57 ` Jakub Kicinski
2026-10-06 0:17 ` Jakub Kicinski
2 siblings, 1 reply; 6+ messages in thread
From: Jakub Kicinski @ 2026-10-05 23:57 UTC (permalink / raw)
To: Daehyeon Ko
Cc: David Ahern, Ido Schimmel, David S . Miller, Eric Dumazet,
Paolo Abeni, Simon Horman, netdev, linux-kernel
On Mon, 5 Oct 2026 03:36:37 +0900 Daehyeon Ko wrote:
> The first patch serializes address publication with device teardown by
> taking idev->lock before the address hash lock, as suggested by Ido. It
> rechecks both dead and disable_ipv6 before publishing.
Please slow down. We don't want to see more than 10 outstanding patches
from random "LLM people" in the review queue. Please look at your
outstanding patches here:
https://patchwork.kernel.org/project/netdevbpf/list/?submitter=223024
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown
2026-10-05 23:57 ` [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Jakub Kicinski
@ 2026-10-06 0:17 ` Jakub Kicinski
0 siblings, 0 replies; 6+ messages in thread
From: Jakub Kicinski @ 2026-10-06 0:17 UTC (permalink / raw)
To: Daehyeon Ko
Cc: David Ahern, Ido Schimmel, David S . Miller, Eric Dumazet,
Paolo Abeni, Simon Horman, netdev, linux-kernel
On Mon, 5 Oct 2026 16:57:06 -0700 Jakub Kicinski wrote:
> On Mon, 5 Oct 2026 03:36:37 +0900 Daehyeon Ko wrote:
> > The first patch serializes address publication with device teardown by
> > taking idev->lock before the address hash lock, as suggested by Ido. It
> > rechecks both dead and disable_ipv6 before publishing.
>
> Please slow down. We don't want to see more than 10 outstanding patches
> from random "LLM people" in the review queue. Please look at your
> outstanding patches here:
> https://patchwork.kernel.org/project/netdevbpf/list/?submitter=223024
Herm, you seem to also have a tendency to make minor adjustments
to the subject. Please try to avoid that unless really necessary.
It breaks the quite naive version tracking kernel.org infra does
for us.
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2026-10-06 0:17 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-04 18:36 [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Daehyeon Ko
2026-10-04 18:36 ` [PATCH net v2 1/2] ipv6: serialize address publication with device teardown Daehyeon Ko
2026-10-05 18:39 ` netdev-bot+sashiko
2026-10-04 18:36 ` [PATCH net v2 2/2] ipv6: remove ifaddr from hash during ifdown list cleanup Daehyeon Ko
2026-10-05 23:57 ` [PATCH net v2 0/2] ipv6: fix address publication races with addrconf_ifdown Jakub Kicinski
2026-10-06 0:17 ` Jakub Kicinski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®