On Fri, Oct 09, 2026 at 02:43:41AM +0200, Andrea Mayer wrote:
One possibility would be to split it into two functions, conceptually
similar to ip6_route_output_flags() and ip6_route_output_flags_noref(): a
noref primitive for the callers in the seg6local input path, and a
refcounted wrapper around the primitive, which bpf_push_seg6_encap() would
call. The split would put the contract in the name and fix the
use-after-free above.
Thanks for reproducing it with KASAN. I agree, and v2 will do that
split: seg6_lookup_nexthop() will still attach a refcounted dst to the
skb for filter.c, and only the seg6local input actions will use the
noref variant. The lifetime of the dst from the exported helper then
does not change, so its declarations need no update. The commit
message of patch 1/2 will also drop the claim that every caller runs
in the receive path.
pw-bot: cr