Thread (28 messages) flat view 28 messages, 5 authors, 7d ago

Re: [PATCH net-next 0/9] sit: convert configuration to RCU and lockless fill_info

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-09-11 01:41:08

Hello:

This series was applied to netdev/net-next.git (main)
by Jakub Kicinski [off-list ref]:

On Mon,  7 Sep 2026 07:58:37 +0000 you wrote:
SIT (IPv6-in-IPv4) tunnel configuration and status reporting have
historically relied on the RTNL lock for synchronization. Consequently,
netlink dumps via ipip6_fill_info() had to run with RTNL held, adding
contention during network device dumps.

At the same time, the transmit path (dev->lltx == true), tunnel lookups,
and error handling run locklessly and can race with configuration
updates. This can result in torn reads of multi-word fields (such as the
128-bit 6RD IPv6 prefix) or transiently zeroed encapsulation parameters.
Furthermore, ipip6_tunnel_update() currently unhashes, re-hashes, and
calls synchronize_net() unconditionally, even when the tunnel endpoint
addresses (saddr and daddr) have not changed.

[...]
Here is the summary with links:
  - [net-next,1/9] sit: fix UAF in ipip6_tunnel_del_prl()
    https://git.kernel.org/netdev/net-next/c/5145bb6a2c26
  - [net-next,2/9] sit: charge ip_tunnel_prl_entry allocations to memcg
    https://git.kernel.org/netdev/net-next/c/40a2b90f5190
  - [net-next,3/9] ip_tunnel: use WRITE_ONCE in ip_tunnel_encap_setup
    https://git.kernel.org/netdev/net-next/c/88b84cae6b94
  - [net-next,4/9] sit: annotate data-races around tunnel->fwmark
    https://git.kernel.org/netdev/net-next/c/b5e8eadb1c8a
  - [net-next,5/9] sit: convert 6RD configuration to RCU protection
    https://git.kernel.org/netdev/net-next/c/eaa2098a94cd
  - [net-next,6/9] sit: implement ipip6_get_iflink()
    https://git.kernel.org/netdev/net-next/c/e3434672b7ad
  - [net-next,7/9] sit: dynamically allocate struct ip_tunnel_parm_kern
    https://git.kernel.org/netdev/net-next/c/3cd52b7c0bbf
  - [net-next,8/9] sit: convert configuration to RCU protection
    https://git.kernel.org/netdev/net-next/c/0301127e4d98
  - [net-next,9/9] sit: no longer rely on RTNL in ipip6_fill_info()
    https://git.kernel.org/netdev/net-next/c/f712bf6f17d8

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help