From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9BCD03DCDA4 for ; Fri, 9 Oct 2026 05:41:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.42 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791524466; cv=none; b=dWWmu2DWZxfU/a8qVxRnROpNyZiwJUk/3dJidHtmIVDa1frpGKnXk7+pv1HkqcdnacyaAogsMjfNigpiMeX/w6GXn1u/vEcILAFAVXw9ePJ3G8+h8ilhLtjQyYnpps174oGkVJD3AwTrFlRaeQxpi6yCol2EP1u48GjXlUoaAaQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791524466; c=relaxed/simple; bh=ryJiLdCZYKDRrZJ0GmbFPL6IPmKh0Xv95mN8BwKTmSE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kqF3VVf7cliioSXf6OV5IcxDNREBTc4iBktrLDlESTwXn/D0jIiA0wvJAbKUYKxMWhdlR0qnx+QcHUiWTI1uK5ouAbUtbD7Tex9YdCvUXavEcilK8BN0Vip8G+ayeLa0iokZJvtW2WpfzVG63OxqXrB3IYhYCe55bxZvqMO9BdE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=dHTNId88; arc=none smtp.client-ip=209.85.216.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="dHTNId88" Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-3a80d1c98f5so3637432a91.0 for ; Thu, 08 Oct 2026 22:41:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791524465; x=1792129265; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UYqAcwLoVqq9IZplP9tc0FEh/RKvgixApCPDYec8LCo=; b=dHTNId88jy9U2vKLeH7Q6VD5HZ2+/nNpWi4cTYd8WMRHOuZKmOJJj6rZsm1QAD1o+M n1BMxHd8ncPugVIPy6d55iiICSVsYCEycBKLCf4/K/pDxLyubd+mXlUzQOc6yn/tyUl0 EkCg7aEKDjG5GefyhUbPie70okg1rae1Sp6PozmXCBuOyjqKyTAkwXazjFLVgmXpV+iM NKDXyzmcLgV4wKONPI9x5l/PQShNY+Yj7xRcgh/oX+eM3sxZI0I8F+mAiyho+0NkkqYC ilSzxJuWSPRfhw3dODtpyzeZlEnLk96750dhnYWERrDH+U1dpOQKfQFEufPndnFPWJ5X CM5w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791524465; x=1792129265; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UYqAcwLoVqq9IZplP9tc0FEh/RKvgixApCPDYec8LCo=; b=wGYJBbo7LdJBN99cFxCOFPyFNFbKtNI/GzvypQlZvXoEmeBiv2LimtPm/QxCT90h6N 5dWyi49KAvMN7XZp+Bs1DwvkoSNTv5LkjQk+gAjZ5S6zPX3JDCkZXxxAgLpDcYDkXYPH 6FwlsqGVEGZZKXOK3ih1TtLA0IYC2teGJ/gMyVtFEvPmFB3Z/FK/pl1WiEdYZebE0dpg te0NDLjZ/6B0laltpKW21lpr18kNk+bsNyE7iByLm42NkrcWcNwPnGn36a63umo50YHu ID3H+vYzlgu0dwuk6p7ITJYgE4L1C9U37vhWAVlq5SkhgcBEo3CbKJx9RBGjfRd49COO GAwg== X-Forwarded-Encrypted: i=1; AKwUvBxOoey7gQDl2rTnyr+mQfhe2kzkys0ThANWoyGl2PtTg2/Oa46Kdse6DzupSv/FRFcPBe4nqshbZLit4H0=@vger.kernel.org X-Gm-Message-State: AFq9FYKO2jUUQbVtFOEhFZj9QvhP5sjdpuNSQxwaxCLS/FuxHw1t9M9b kvAe9vUrEj1LHIKgra6R0pd58v+lPd2UV2y95SW29wQAoNJPO1Y02mcdEWuHe3Ro X-Gm-Gg: AYBFou2ur9dYhDARHhag/coPIrpDtq9/VdxW66ysCMQwmM2q3KpO3jAwSs+lIAYNHJX 0USDTuqGfDHeC1WBzp/1kF2fVUeWr4cMe4E3ROXQQY1F/Xre4UMbfhusSr79woCcGWkK7bLMREE QIgkuAqkJtMd83o8IRxMwIB4JnnBrqkcnJbvrWYa9JmmobNiJQ/02ggdj+cN7mBttLvwYZVXPSl Nx01m8ZwMu2m2eoFq1CFNYP6b6IiQ8Kl7wH+LSZLhNiVM2vMz9pMasDPF6z+XvBowEpRKp6mJIM 7PaaO4EieN08fRzbQUzko40zJYfQ6V/GldZxfvyoaULuKI+AK++SWkEDmtnpoDBzNIfeaAsk3sK hLw5IK312FyXuIIEJw7NfT/eZVbP3AwgBZqjG0M5PMM+QF2hjbFWOIlI5/BUGcqZDDAv+yi5YDK BCmXvdIYi2QnrSP5JjIwovUe3nWLozznFktYWtW+QqCjrmaOjN7jpAYCWNzY9h7+VYeuc0d3xYd TAkaz2ea/k= X-Received: by 2002:a17:90b:384c:b0:3ab:189b:6985 with SMTP id 98e67ed59e1d1-3ab3a9a8d5bmr914195a91.35.1791524464909; Thu, 08 Oct 2026 22:41:04 -0700 (PDT) Received: from ancienth-X870E-Nova-WiFi ([125.186.72.2]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3ab3690474esm2028695a91.0.2026.10.08.22.41.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 08 Oct 2026 22:41:04 -0700 (PDT) From: Daehyeon Ko <4ncienth@gmail.com> To: David Ahern , Ido Schimmel Cc: "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Daehyeon Ko <4ncienth@gmail.com> Subject: [PATCH net v3 3/3] ipv6: initialize temporary ifaddr before publication Date: Fri, 9 Oct 2026 14:40:42 +0900 Message-ID: <20261009054042.272944-4-4ncienth@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20261009054042.272944-1-4ncienth@gmail.com> References: <20261009054042.272944-1-4ncienth@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ipv6_create_tempaddr() holds a reference to the public ifaddr, publishes the new temporary address through ipv6_add_addr(), and only then stores the reference in ifpub. addrconf_ifdown() can remove the temporary address between publication and that store. It then observes a NULL ifpub and cannot drop the public ifaddr reference. The later store survives until the temporary ifaddr is destroyed, pinning the public ifaddr, inet6_dev and net_device. Later device deletion can wait indefinitely for these references. Pass the public ifaddr in ifa6_config and initialize ifpub before adding the temporary address to either the hash or per-device lists. On success the existing reference transfers to the temporary ifaddr. On error it remains owned and released by ipv6_create_tempaddr(). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Reported-by: Sashiko Closes: https://lore.kernel.org/r/179122559913.434549.12720841717630168470@kernel.org Link: https://lore.kernel.org/r/20261007164548.GA1153540@shredder Suggested-by: Ido Schimmel Assisted-by: LLM Signed-off-by: Daehyeon Ko <4ncienth@gmail.com> --- include/net/addrconf.h | 1 + net/ipv6/addrconf.c | 3 ++- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/include/net/addrconf.h b/include/net/addrconf.h index e6764245995f25..848bed306ec98f 100644 --- a/include/net/addrconf.h +++ b/include/net/addrconf.h @@ -81,6 +81,7 @@ struct ifa6_config { u8 ifa_proto; const struct in6_addr *peer_pfx; + struct inet6_ifaddr *ifpub; u32 rt_priority; u32 ifa_flags; diff --git a/net/ipv6/addrconf.c b/net/ipv6/addrconf.c index 5a7e7129d43466..699d058f5c7868 100644 --- a/net/ipv6/addrconf.c +++ b/net/ipv6/addrconf.c @@ -1159,6 +1159,7 @@ ipv6_add_addr(struct inet6_dev *idev, struct ifa6_config *cfg, ifa->tokenized = false; ifa->rt = f6i; + ifa->ifpub = cfg->ifpub; ifa->idev = idev; in6_dev_hold(idev); @@ -1493,6 +1494,7 @@ static int ipv6_create_tempaddr(struct inet6_ifaddr *ifp, bool block) cfg.pfx = &addr; cfg.scope = ipv6_addr_scope(cfg.pfx); + cfg.ifpub = ifp; ift = ipv6_add_addr(idev, &cfg, block, NULL); if (IS_ERR(ift)) { @@ -1504,7 +1506,6 @@ static int ipv6_create_tempaddr(struct inet6_ifaddr *ifp, bool block) } spin_lock_bh(&ift->lock); - ift->ifpub = ifp; ift->cstamp = now; ift->tstamp = tmp_tstamp; spin_unlock_bh(&ift->lock); -- 2.55.0