Thread (6 messages) 6 messages, 3 authors, 15h ago

Re: [PATCH net-next 1/2] seg6: skip the route refcount in seg6_lookup_any_nexthop()

flat view

From: Yuya Kusakabe <hidden>
Date: 2026-10-09 05:39:57
Also in: lkml

On Fri, Oct 09, 2026 at 02:43:41AM +0200, Andrea Mayer wrote:
One possibility would be to split it into two functions, conceptually
similar to ip6_route_output_flags() and ip6_route_output_flags_noref(): a
noref primitive for the callers in the seg6local input path, and a
refcounted wrapper around the primitive, which bpf_push_seg6_encap() would
call. The split would put the contract in the name and fix the
use-after-free above.
Thanks for reproducing it with KASAN.  I agree, and v2 will do that
split: seg6_lookup_nexthop() will still attach a refcounted dst to the
skb for filter.c, and only the seg6local input actions will use the
noref variant.  The lifetime of the dst from the exported helper then
does not change, so its declarations need no update.  The commit
message of patch 1/2 will also drop the claim that every caller runs
in the receive path.

pw-bot: cr
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help